-
Notifications
You must be signed in to change notification settings - Fork 49
Expand file tree
/
Copy pathcurve25519_x25519.S
More file actions
2596 lines (2537 loc) · 89.4 KB
/
Copy pathcurve25519_x25519.S
File metadata and controls
2596 lines (2537 loc) · 89.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0
// **********************************************************************
// This code is substantially derived from Emil Lenngren's implementation
//
// https://github.com/Emill/X25519-AArch64/blob/master/X25519_AArch64.pdf
// https://github.com/Emill/X25519-AArch64
//
// and the SLOTHY-based re-engineering of that code by Abdulrahman, Becker,
// Kannwischer and Klein:
//
// https://eprint.iacr.org/2022/1303.pdf
// https://github.com/slothy-optimizer/slothy/tree/main/paper
// **********************************************************************
// ----------------------------------------------------------------------------
// The x25519 function for curve25519
// Inputs scalar[4], point[4]; output res[4]
//
// extern void curve25519_x25519
// (uint64_t res[static 4],const uint64_t scalar[static 4],
// const uint64_t point[static 4]);
//
// Given a scalar n and the X coordinate of an input point P = (X,Y) on
// curve25519 (Y can live in any extension field of characteristic 2^255-19),
// this returns the X coordinate of n * P = (X, Y), or 0 when n * P is the
// point at infinity. Both n and X inputs are first slightly modified/mangled
// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748);
// in particular the lower three bits of n are set to zero. Does not implement
// the zero-check specified in Section 6.1.
//
// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point
// ----------------------------------------------------------------------------
#include "_internal_s2n_bignum_arm.h"
S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519)
S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519)
S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519)
.text
.balign 4
// Pointer-offset pairs for temporaries on stack
#define scalar sp, #0
#define pointx sp, #32
#define mask1 sp, #72
#define mask2 sp, #80
#define tmpa sp, #88
#define tmpb sp, #128
#define xn sp, #128
#define zn sp, #160
#define res sp, #192
#define i sp, #200
#define swap sp, #208
// Total size to reserve on the stack
#define NSPACE 224
#define regsave sp, #NSPACE
S2N_BN_SYMBOL(curve25519_x25519):
CFI_START
// Save registers and make additional room #NSPACE for temporaries.
// We only need to save the low 64-bits of the Q8...Q15 registers
// according to the ABI, so we use a save of the D8...D15 forms.
CFI_DEC_SP(NSPACE+160)
CFI_STACKSAVE2(d8,d9,NSPACE+0)
CFI_STACKSAVE2(d10,d11,NSPACE+16)
CFI_STACKSAVE2(d12,d13,NSPACE+32)
CFI_STACKSAVE2(d14,d15,NSPACE+48)
CFI_STACKSAVE2(x19,x20,NSPACE+64)
CFI_STACKSAVE2(x21,x22,NSPACE+80)
CFI_STACKSAVE2(x23,x24,NSPACE+96)
CFI_STACKSAVE2(x25,x26,NSPACE+112)
CFI_STACKSAVE2(x27,x28,NSPACE+128)
CFI_STACKSAVE2(x29,x30,NSPACE+144)
// Move the output pointer to a stable place
str x0, [res]
// Copy the scalar to the corresponding local variable while
// mangling it. In principle it becomes 01xxx...xxx000 where
// the xxx are the corresponding bits of the original input
// scalar. We actually don't bother forcing the MSB to zero,
// but rather start the main loop below at 254 instead of 255.
ldp x10, x11, [x1]
bic x10, x10, #7
stp x10, x11, [scalar]
ldp x12, x13, [x1, #16]
orr x13, x13, #0x4000000000000000
stp x12, x13, [scalar+16]
// Discard the MSB of the point X coordinate (this is in
// accordance with the RFC, mod 2^255, *not* 2^255-19).
// Then recode it into the unsaturated base 25.5 form.
ldp x0, x1, [x2]
ldp x2, x3, [x2, #16]
lsr x12, x0, #51
lsr x17, x2, #51
orr x12, x12, x1, lsl #13
orr x17, x17, x3, lsl #13
ubfx x8, x3, #12, #26
ubfx x9, x3, #38, #25
ubfx x11, x0, #26, #25
ubfx x13, x1, #13, #25
lsr x14, x1, #38
ubfx x16, x2, #25, #26
and x10, x0, #0x3ffffff
and x12, x12, #0x3ffffff
and x15, x2, #0x1ffffff
and x17, x17, #0x1ffffff
orr x10, x10, x11, lsl #32
orr x11, x12, x13, lsl #32
orr x12, x14, x15, lsl #32
orr x13, x16, x17, lsl #32
orr x14, x8, x9, lsl #32
stp x10, x11, [pointx+0]
stp x12, x13, [pointx+16]
str x14, [pointx+32]
// Initialize (X2,Z2) = (1,0), the identity (projective point at infinity)
mov x1, #1
mov v0.d[0], x1
mov v2.d[0], xzr
mov v4.d[0], xzr
mov v6.d[0], xzr
mov v8.d[0], xzr
mov v1.d[0], xzr
mov v3.d[0], xzr
mov v5.d[0], xzr
mov v7.d[0], xzr
mov v9.d[0], xzr
// Initialize (X3,Z3) = (X,1), projective representation of X
mov v10.d[0], x10
mov v12.d[0], x11
mov v14.d[0], x12
mov v16.d[0], x13
mov v18.d[0], x14
mov v11.d[0], x1
mov v13.d[0], xzr
mov v15.d[0], xzr
mov v17.d[0], xzr
mov v19.d[0], xzr
// Set up some constants used repeatedly in the main loop:
//
// Q31 = 0x1300000013 (two 32-bit copies of 19)
// Q30 = 0x3ffffff0000000003ffffff (two 64-bit copies of 2^26-1)
// Q29 = mask1 = (0x07ffffc,0x07fffffe)
// Q28 = mask2 = (0x07ffffb4,0x07fffffe)
mov w0, #19
add x0, x0, x0, lsl #32
mov v31.d[0], x0
mov v31.d[1], xzr
mov x0, #67108863 // #(1<<26)-1
mov v30.d[0], x0
mov v30.d[1], x0
mov x0, #0x07fffffe07fffffe
sub x1, x0, #74 // #0xfe-0xb4
sub x0, x0, #2
stp x0, x1, [mask1]
ldp d29, d28, [mask1]
// The main loop over (modified) bits from i = 254, ..., i = 0 (inclusive);
// we explicitly skip bit 255 because it should be forced to zero initially.
// This is a classic Montgomery ladder using a "swap" variable.
// It's assumed x0 = i at the start of the loop, but that is volatile and
// needs to be reloaded from memory at the end of the loop.
str xzr, [swap]
mov x0, #254
str x0, [i]
Lcurve25519_x25519_scalarloop:
lsr x1, x0, #6
ldr x2, [sp, x1, lsl #3] // Exploiting scalar = sp exactly
lsr x2, x2, x0
and x2, x2, #1
ldr x0, [swap]
cmp x0, x2
str x2, [swap]
// The following inner loop code is derived closely following Lenngren's
// implementation available at "https://github.com/Emill/X25519-AArch64".
// In particular, the basic dataflow and the organization between integer
// and SIMD units is identical, with only a few minor changes to some
// individual instructions (for miscellaneous reasons). The scheduling
// was redone from scratch by SLOTHY starting from the un-interleaved
// form in the SLOTHY work cited above, and using the same scripts.
//
// The intermediate value annotations were added to provide data that
// is used in the formal proof, indicating which lines assign specific
// digits of the various intermediate results (mainly of field
// operations, sometimes other transformations). The names used for
// the intermediate results are similar but not identical to those in
// the abstract Algorithm 1 description in Lenngren's paper. Almost
// all equations are to be interpreted as field operations, i.e. as
// arithmetic modulo 2^255-19, not simple numeric equalities.
//
// b = x2 - z2
// d = x3 - z3
// a = x2 + z2
// c = x3 + z3
// f = if flip then c else a
// g = if flip then d else b
// aa = f^2
// bb = g^2
// bbalt = bb (change of representation)
// e = aa - bb
// bce = bbalt + 121666 * e
// z4 = bce * e
// bc = b * c
// ad = a * d
// t1 = ad + bc
// t2 = ad - bc
// x5 = t1^2
// t3 = t2^2
// x4 = aa * bb
// z5 = x * t3
//
// Then the main variables are updated for the next iteration as
//
// (x2',z2') = (x4,z4)
// (x3',z3') = (x5,z5)
add v22.2s, v2.2s, v3.2s // ubignum_of_qreglist 1 // INTERMEDIATE a
sub v21.2s, v28.2s, v1.2s
add v25.2s, v0.2s, v1.2s // ubignum_of_qreglist 0 // INTERMEDIATE a
sub v24.2s, v29.2s, v3.2s
add v3.2s, v18.2s, v19.2s // ubignum_of_qreglist 4 // INTERMEDIATE c
add v0.2s, v0.2s, v21.2s // ubignum_of_qreglist 0 // INTERMEDIATE b
sub v20.2s, v29.2s, v15.2s
sub v1.2s, v29.2s, v5.2s
sub v26.2s, v28.2s, v11.2s
sub v21.2s, v29.2s, v19.2s
add v19.2s, v10.2s, v11.2s // ubignum_of_qreglist 0 // INTERMEDIATE c
add v11.2s, v14.2s, v20.2s // ubignum_of_qreglist 2 // INTERMEDIATE d
add v21.2s, v18.2s, v21.2s // ubignum_of_qreglist 4 // INTERMEDIATE d
sub v20.2s, v29.2s, v17.2s
add v18.2s, v2.2s, v24.2s // ubignum_of_qreglist 1 // INTERMEDIATE b
add v14.2s, v14.2s, v15.2s // ubignum_of_qreglist 2 // INTERMEDIATE c
add v15.2s, v16.2s, v17.2s // ubignum_of_qreglist 3 // INTERMEDIATE c
add v2.2s, v16.2s, v20.2s // ubignum_of_qreglist 3 // INTERMEDIATE d
add v24.2s, v12.2s, v13.2s // ubignum_of_qreglist 1 // INTERMEDIATE c
add v26.2s, v10.2s, v26.2s // ubignum_of_qreglist 0 // INTERMEDIATE d
sub v10.2s, v29.2s, v13.2s
sub v13.2s, v29.2s, v7.2s
add v23.2s, v6.2s, v7.2s // ubignum_of_qreglist 3 // INTERMEDIATE a
sub v7.2s, v29.2s, v9.2s
add v27.2s, v12.2s, v10.2s // ubignum_of_qreglist 1 // INTERMEDIATE d
fcsel d20, d22, d24, eq // ubignum_of_qreglist 1 // INTERMEDIATE f
add v28.2s, v4.2s, v5.2s // ubignum_of_qreglist 2 // INTERMEDIATE a
fcsel d12, d23, d15, eq // ubignum_of_qreglist 3 // INTERMEDIATE f
add v7.2s, v8.2s, v7.2s // ubignum_of_qreglist 4 // INTERMEDIATE b
fcsel d16, d25, d19, eq // ubignum_of_qreglist 0 // INTERMEDIATE f
mov x0, v20.d[0]
fcsel d5, d28, d14, eq // ubignum_of_qreglist 2 // INTERMEDIATE f
mov x21, v12.d[0]
fcsel d29, d7, d21, eq // ubignum_of_qreglist 4 // INTERMEDIATE g
mov x5, v16.d[0]
lsr x26, x0, #32
add x29, x21, x21
umull x15, w5, w29
add v13.2s, v6.2s, v13.2s // ubignum_of_qreglist 3 // INTERMEDIATE b
add x12, x26, x26
mov x30, v5.d[0]
fcsel d10, d18, d27, eq // ubignum_of_qreglist 1 // INTERMEDIATE g
lsr x11, x5, #32
lsr x10, x30, #32
trn2 v20.2s, v21.2s, v3.2s
add v9.2s, v8.2s, v9.2s // ubignum_of_qreglist 4 // INTERMEDIATE a
add x14, x11, x11
trn2 v6.2s, v2.2s, v15.2s
trn1 v12.2s, v25.2s, v0.2s
add v1.2s, v4.2s, v1.2s // ubignum_of_qreglist 2 // INTERMEDIATE b
trn1 v16.2s, v23.2s, v13.2s
fcsel d8, d13, d2, eq // ubignum_of_qreglist 3 // INTERMEDIATE g
trn2 v17.2s, v27.2s, v24.2s
str d29, [tmpb+32]
add x17, x10, x10
trn2 v4.2s, v28.2s, v1.2s
trn1 v5.2s, v28.2s, v1.2s
trn1 v28.2s, v2.2s, v15.2s
trn1 v2.2s, v22.2s, v18.2s
fcsel d29, d0, d26, eq // ubignum_of_qreglist 0 // INTERMEDIATE g
trn2 v15.2s, v22.2s, v18.2s
umull v22.2d, v12.2s, v20.2s
umull x22, w30, w17
stp d29, d10, [tmpb+0]
trn2 v10.2s, v23.2s, v13.2s
trn2 v23.2s, v11.2s, v14.2s
trn1 v13.2s, v27.2s, v24.2s
fcsel d27, d1, d11, eq // ubignum_of_qreglist 2 // INTERMEDIATE g
trn1 v14.2s, v11.2s, v14.2s
umlal v22.2d, v2.2s, v6.2s
umull x25, w30, w30
umlal v22.2d, v5.2s, v23.2s
add x3, x30, x30
umlal v22.2d, v16.2s, v17.2s
add w30, w21, w21, lsl #1;
stp d27, d8, [tmpb+16]
add w30, w30, w21, lsl #4
trn1 v11.2s, v26.2s, v19.2s
trn2 v8.2s, v26.2s, v19.2s
trn2 v19.2s, v25.2s, v0.2s
mul v29.2s, v20.2s, v31.2s
ldr x20, [tmpb+24]
umull v25.2d, v19.2s, v6.2s
add x1, x0, x0
umull v27.2d, v19.2s, v23.2s
umull x9, w5, w1
umull v0.2d, v12.2s, v23.2s
lsr x24, x20, #32
mul v20.2s, v23.2s, v31.2s
lsr x16, x21, #32
umlal v25.2d, v15.2s, v23.2s
umaddl x13, w11, w14, x9
umlal v25.2d, v4.2s, v17.2s
umaddl x9, w14, w17, x15
umull v24.2d, v12.2s, v6.2s
add w2, w16, w16, lsl #1;
fcsel d26, d9, d3, eq // ubignum_of_qreglist 4 // INTERMEDIATE f
add w2, w2, w16, lsl #4
trn1 v18.2s, v21.2s, v3.2s
umull v3.2d, v19.2s, v29.2s
umull x28, w5, w3
mul v1.2s, v6.2s, v31.2s
umull x8, w5, w5
umlal v24.2d, v2.2s, v23.2s
umaddl x13, w21, w30, x13
mul v23.2s, v17.2s, v31.2s
umaddl x27, w14, w12, x28
trn2 v6.2s, v9.2s, v7.2s
mov x6, v26.d[0]
umlal v3.2d, v15.2s, v1.2s
add x16, x16, x16
umlal v3.2d, v4.2s, v20.2s
lsr x4, x6, #32
umlal v3.2d, v10.2s, v23.2s
add x7, x6, x6
umull v26.2d, v19.2s, v8.2s
add x23, x4, x4
umaddl x28, w5, w23, x22
trn1 v7.2s, v9.2s, v7.2s
umlal v27.2d, v15.2s, v17.2s
add w15, w4, w4, lsl #1;
umlal v27.2d, v4.2s, v8.2s
add w15, w15, w4, lsl #4
add w22, w10, w10, lsl #1;
umlal v24.2d, v5.2s, v17.2s
add w22, w22, w10, lsl #4
umaddl x10, w11, w7, x28
umlal v25.2d, v10.2s, v8.2s
umull x21, w5, w16
umlal v25.2d, v6.2s, v29.2s
umaddl x23, w15, w23, x25
umlal v27.2d, v10.2s, v29.2s
umull x19, w5, w12
umlal v27.2d, v6.2s, v1.2s
umaddl x25, w11, w29, x21
umlal v0.2d, v2.2s, v17.2s
umaddl x28, w0, w3, x9
shl v21.2d, v25.2d, #1
umaddl x4, w11, w1, x19
umaddl x21, w2, w29, x4
mul v25.2s, v8.2s, v31.2s
umlal v24.2d, v16.2s, v8.2s
umaddl x19, w0, w17, x25
umlal v24.2d, v7.2s, v29.2s
umull x25, w5, w17
umlal v24.2d, v19.2s, v28.2s
umaddl x4, w0, w16, x10
umull v9.2d, v12.2s, v8.2s
umaddl x23, w5, w7, x23
umlal v21.2d, v12.2s, v18.2s
add w10, w6, w6, lsl #1;
shl v27.2d, v27.2d, #1
add w10, w10, w6, lsl #4
umaddl x28, w26, w12, x28
umlal v26.2d, v15.2s, v29.2s
umaddl x9, w14, w16, x23
umlal v9.2d, v2.2s, v29.2s
umaddl x22, w22, w17, x8
umlal v21.2d, v2.2s, v28.2s
umaddl x28, w6, w10, x28
umaddl x27, w0, w0, x27
add x8, x14, x14
umlal v0.2d, v5.2s, v8.2s
umull x5, w5, w14
umlal v9.2d, v5.2s, v1.2s
umaddl x14, w0, w29, x9
umlal v26.2d, v4.2s, v1.2s
umaddl x6, w2, w16, x27
umlal v22.2d, v7.2s, v8.2s
umaddl x5, w30, w17, x5
umaddl x5, w2, w3, x5
add x23, x17, x17
umlal v27.2d, v12.2s, v28.2s
umaddl x13, w2, w23, x13
umlal v26.2d, v10.2s, v20.2s
add x9, x12, x12
umlal v9.2d, v16.2s, v20.2s
umaddl x27, w10, w29, x6
umlal v0.2d, v16.2s, v29.2s
umaddl x6, w11, w3, x25
umlal v22.2d, v19.2s, v18.2s
umaddl x19, w26, w3, x19
mul v18.2s, v18.2s, v31.2s
umaddl x23, w15, w23, x27
umlal v3.2d, v6.2s, v25.2s
umaddl x0, w0, w12, x6
umlal v0.2d, v7.2s, v1.2s
add x11, x16, x16
umlal v9.2d, v7.2s, v23.2s
umaddl x6, w12, w17, x14
umlal v9.2d, v19.2s, v11.2s
umaddl x25, w26, w29, x4
umlal v9.2d, v15.2s, v18.2s
umaddl x14, w10, w3, x13
umull v25.2d, v12.2s, v17.2s
umaddl x27, w10, w16, x0
umlal v26.2d, v6.2s, v23.2s
add x0, x25, x6, lsr #26
mul v23.2s, v28.2s, v31.2s
umaddl x12, w10, w12, x5
shl v3.2d, v3.2d, #1
add x16, x22, x0, lsr #25
umlal v21.2d, v5.2s, v14.2s
bic x22, x0, #0x1ffffff
umlal v3.2d, v12.2s, v11.2s
add x26, x16, x22, lsr #24
umlal v3.2d, v2.2s, v18.2s
umaddl x16, w10, w17, x21
umlal v3.2d, v5.2s, v23.2s
add x22, x26, x22, lsr #21
umlal v9.2d, v4.2s, v23.2s
umaddl x5, w15, w29, x27
umull v17.2d, v19.2s, v17.2s
umaddl x17, w30, w3, x22
umlal v25.2d, v2.2s, v8.2s
umaddl x25, w15, w3, x16
umlal v25.2d, v5.2s, v29.2s
umaddl x26, w15, w7, x19
umlal v0.2d, v19.2s, v14.2s
umaddl x17, w2, w9, x17
umlal v17.2d, v15.2s, v8.2s
ldr x19, [tmpb+0]
umlal v17.2d, v4.2s, v29.2s
ldr x7, [tmpb+8]
shl v29.2d, v26.2d, #1
umaddl x13, w10, w1, x17
umlal v0.2d, v15.2s, v13.2s
lsr x2, x19, #32
umlal v29.2d, v12.2s, v13.2s
umaddl x27, w15, w1, x12
umlal v29.2d, v2.2s, v11.2s
umaddl x30, w15, w8, x13
umlal v29.2d, v5.2s, v18.2s
add x4, x7, x7
umlal v29.2d, v16.2s, v23.2s
umaddl x29, w15, w9, x14
umlal v0.2d, v4.2s, v11.2s
add x17, x27, x30, lsr #26
umlal v0.2d, v10.2s, v18.2s
umaddl x16, w15, w11, x28
umlal v0.2d, v6.2s, v23.2s
add x1, x29, x17, lsr #25
umlal v25.2d, v16.2s, v1.2s
umull x11, w19, w4
ldr x8, [tmpb+32]
mul v26.2s, v14.2s, v31.2s
umlal v17.2d, v10.2s, v1.2s
ldr x15, [tmpb+16]
umlal v17.2d, v6.2s, v20.2s
and x9, x30, #0x3ffffff
bfi x9, x17, #32, #25 // ubignum_of_preglist 0 // INTERMEDIATE aa
add x17, x2, x2
lsr x10, x15, #32
add x27, x25, x1, lsr #26
umlal v25.2d, v7.2s, v20.2s
add x13, x10, x10
umlal v25.2d, v19.2s, v13.2s
add x29, x23, x27, lsr #25
umlal v25.2d, v15.2s, v11.2s
lsr x30, x8, #32
umlal v25.2d, v4.2s, v18.2s
add x23, x5, x29, lsr #26
umlal v25.2d, v10.2s, v23.2s
and x14, x29, #0x3ffffff
umlal v25.2d, v6.2s, v26.2s
add x5, x16, x23, lsr #25
shl v8.2d, v17.2d, #1
umaddl x12, w2, w17, x11
and x29, x5, #0x3ffffff
umull x21, w19, w19
umlal v29.2d, v7.2s, v26.2s
add w16, w10, w10, lsl #1;
umlal v3.2d, v16.2s, v26.2s
add w16, w16, w10, lsl #4
bfi x14, x23, #32, #25 // ubignum_of_preglist 2 // INTERMEDIATE aa
add w10, w24, w24, lsl #1;
add x22, x26, x5, lsr #26
add w10, w10, w24, lsl #4
umlal v8.2d, v12.2s, v14.2s
umaddl x25, w16, w13, x21
umlal v8.2d, v2.2s, v13.2s
bfi x29, x22, #32, #25 // ubignum_of_preglist 3 // INTERMEDIATE aa
umlal v8.2d, v5.2s, v11.2s
add x26, x24, x24
umlal v8.2d, v16.2s, v18.2s
stp x14, x29, [tmpa+16]
umlal v8.2d, v7.2s, v23.2s
add w24, w30, w30, lsl #1;
usra v25.2d, v29.2d, #26
add w24, w24, w30, lsl #4
umull x29, w15, w15
umlal v27.2d, v2.2s, v14.2s
umull x3, w15, w13
umlal v27.2d, v5.2s, v13.2s
add x21, x20, x20
umlal v24.2d, v15.2s, v14.2s
umull x5, w19, w21
umlal v24.2d, v4.2s, v13.2s
and x11, x1, #0x3ffffff
usra v8.2d, v25.2d, #25
and x1, x0, #0x1ffffff
umlal v27.2d, v16.2s, v11.2s
umaddl x23, w17, w13, x5
umlal v27.2d, v7.2s, v18.2s
add x5, x30, x30
usra v0.2d, v8.2d, #26
add x0, x15, x15
umlal v24.2d, v10.2s, v11.2s
umaddl x23, w7, w0, x23
umlal v24.2d, v6.2s, v18.2s
lsr x30, x7, #32
usra v27.2d, v0.2d, #25
add x16, x30, x30
and v20.16b, v8.16b, v30.16b // ubignum_of_hreglist 4 + ubignum_of_lreglist 4 // INTERMEDIATE H|L = bc|ad
umaddl x15, w30, w16, x23
ushr v23.2d, v30.2d, #1
add w23, w8, w8, lsl #1;
usra v24.2d, v27.2d, #26
add w23, w23, w8, lsl #4
umaddl x14, w19, w5, x3
and v8.16b, v27.16b, v30.16b // ubignum_of_hreglist 6 + ubignum_of_lreglist 6 // INTERMEDIATE H|L = bc|ad
add x28, x8, x8
and v27.16b, v0.16b, v23.16b // ubignum_of_hreglist 5 + ubignum_of_lreglist 5 // INTERMEDIATE H|L = bc|ad
umaddl x8, w8, w23, x15
and v5.16b, v24.16b, v23.16b // ubignum_of_hreglist 7 + ubignum_of_lreglist 7 // INTERMEDIATE H|L = bc|ad
umaddl x3, w2, w28, x14
umlal v22.2d, v15.2s, v28.2s
bfi x11, x27, #32, #25 // ubignum_of_preglist 1 // INTERMEDIATE aa
uzp1 v5.4s, v8.4s, v5.4s
umaddl x14, w24, w5, x29
umaddl x5, w19, w28, x14
ldr d18, [mask1]
mov v18.d[1], v18.d[0]
umaddl x15, w7, w26, x3
mul v12.2s, v13.2s, v31.2s
umlal v21.2d, v16.2s, v13.2s
stp x9, x11, [tmpa+0]
umlal v21.2d, v7.2s, v11.2s
umaddl x29, w17, w26, x5
umlal v22.2d, v4.2s, v14.2s
add w14, w20, w20, lsl #1;
umlal v22.2d, v10.2s, v13.2s
add w14, w14, w20, lsl #4
umull x3, w19, w0
umlal v22.2d, v6.2s, v11.2s
umaddl x29, w7, w21, x29
usra v21.2d, v24.2d, #25
umaddl x11, w20, w14, x12
and v0.16b, v25.16b, v23.16b
umaddl x5, w30, w21, x15
and v14.16b, v29.16b, v30.16b
umaddl x12, w16, w13, x29
usra v22.2d, v21.2d, #26
umaddl x29, w17, w16, x3
umlal v3.2d, v7.2s, v12.2s
add x9, x26, x26
and v1.16b, v21.16b, v30.16b // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = bc|ad
add x27, x5, x12, lsr #26
bic v8.16b, v22.16b, v23.16b
umaddl x29, w7, w7, x29
and v17.16b, v22.16b, v23.16b // ubignum_of_hreglist 9 + ubignum_of_lreglist 9 // INTERMEDIATE H|L = bc|ad
add x5, x25, x27, lsr #25
usra v3.2d, v8.2d, #25
umaddl x25, w24, w9, x8
umlal v9.2d, v10.2s, v26.2s
add x8, x13, x13
trn1 v22.4s, v1.4s, v17.4s
umaddl x11, w10, w8, x11
usra v3.2d, v8.2d, #24
umull x20, w19, w16
add v26.2s, v22.2s, v18.2s
ldr d28, [mask2]
umlal v9.2d, v6.2s, v12.2s
umaddl x3, w23, w0, x11
usra v3.2d, v8.2d, #21
umaddl x29, w10, w26, x29
uzp1 v11.4s, v20.4s, v27.4s
umaddl x20, w2, w4, x20
umaddl x9, w10, w21, x20
mov v17.d[0], v22.d[1]
usra v9.2d, v3.2d, #26
umull x15, w19, w13
and v7.16b, v3.16b, v30.16b // ubignum_of_hreglist 0 + ubignum_of_lreglist 0 // INTERMEDIATE H|L = bc|ad
add x11, x16, x16
uzp2 v1.4s, v11.4s, v5.4s
umaddl x20, w23, w13, x9
and v8.16b, v9.16b, v23.16b // ubignum_of_hreglist 1 + ubignum_of_lreglist 1 // INTERMEDIATE H|L = bc|ad
umaddl x9, w2, w0, x15
usra v14.2d, v9.2d, #25
and x6, x6, #0x3ffffff
uzp1 v7.4s, v7.4s, v8.4s
umaddl x29, w23, w21, x29
uzp1 v27.4s, v11.4s, v5.4s
umull x15, w19, w26
usra v0.2d, v14.2d, #26 // ubignum_of_hreglist 3 + ubignum_of_lreglist 3 // INTERMEDIATE H|L = bc|ad
add x6, x6, x22, lsr #25
and v3.16b, v14.16b, v30.16b // ubignum_of_hreglist 2 + ubignum_of_lreglist 2 // INTERMEDIATE H|L = bc|ad
bic x22, x27, #0x1ffffff
sub v2.2s, v26.2s, v17.2s
add v9.2s, v22.2s, v17.2s
uzp1 v14.4s, v3.4s, v0.4s
umaddl x2, w2, w21, x15
add v5.4s, v27.4s, v18.4s
add x5, x5, x22, lsr #24
zip1 v22.2s, v2.2s, v9.2s // ubignum_of_h32reglist 8 + ubignum_of_l32reglist 8 // INTERMEDIATE H|L = t1|t2
mov v18.b[0], v28.b[0]
uzp1 v8.4s, v7.4s, v14.4s
add x22, x5, x22, lsr #21
uzp2 v3.4s, v7.4s, v14.4s
umaddl x5, w7, w16, x9
add v25.4s, v8.4s, v18.4s
umaddl x15, w14, w0, x22
add v12.4s, v27.4s, v1.4s
add x9, x17, x17
sub v14.4s, v5.4s, v1.4s
umull x19, w19, w17
sub v18.4s, v25.4s, v3.4s
ldr x22, [tmpa+8]
add v20.4s, v8.4s, v3.4s
umaddl x15, w10, w11, x15
zip1 v16.4s, v14.4s, v12.4s // ubignum_of_h32reglist 4 + ubignum_of_l32reglist 4 // INTERMEDIATE H|L = t1|t2
umaddl x14, w14, w13, x19
zip2 v14.4s, v14.4s, v12.4s // ubignum_of_h32reglist 6 + ubignum_of_l32reglist 6 // INTERMEDIATE H|L = t1|t2
and x17, x27, #0x1ffffff
zip2 v0.4s, v18.4s, v20.4s // ubignum_of_h32reglist 2 + ubignum_of_l32reglist 2 // INTERMEDIATE H|L = t1|t2
umaddl x15, w23, w4, x15
zip1 v1.4s, v18.4s, v20.4s // ubignum_of_h32reglist 0 + ubignum_of_l32reglist 0 // INTERMEDIATE H|L = t1|t2
umaddl x10, w10, w0, x14
zip2 v5.2s, v2.2s, v9.2s // ubignum_of_h32reglist 9 + ubignum_of_l32reglist 9 // INTERMEDIATE H|L = t1|t2
shl v24.2s, v0.2s, #1
mov v19.d[0], v1.d[1] // ubignum_of_h32reglist 1 + ubignum_of_l32reglist 1 // INTERMEDIATE H|L = t1|t2
shl v26.2s, v22.2s, #1
shl v17.2s, v16.2s, #1
mov v15.d[0], v0.d[1] // ubignum_of_h32reglist 3 + ubignum_of_l32reglist 3 // INTERMEDIATE H|L = t1|t2
shl v7.2s, v5.2s, #1
shl v18.2s, v19.2s, #1
umull v11.2d, v1.2s, v24.2s
umaddl x19, w23, w16, x10
umull v6.2d, v1.2s, v17.2s
umaddl x10, w7, w13, x2
mov v4.d[0], v16.d[1] // ubignum_of_h32reglist 5 + ubignum_of_l32reglist 5 // INTERMEDIATE H|L = t1|t2
mov v10.d[0], v14.d[1] // ubignum_of_h32reglist 7 + ubignum_of_l32reglist 7 // INTERMEDIATE H|L = t1|t2
umull v9.2d, v1.2s, v26.2s
ldr x13, [tmpa+0]
shl v28.2s, v15.2s, #1
shl v3.2s, v10.2s, #1
ldr x14, [tmpa+16]
mul v12.2s, v10.2s, v31.2s
umull v25.2d, v1.2s, v7.2s
ldr x2, [tmpa+24]
umlal v6.2d, v18.2s, v28.2s
umaddl x27, w30, w0, x10
umaddl x16, w24, w0, x20
shl v13.2s, v14.2s, #1
umaddl x5, w23, w26, x5
mul v2.2s, v22.2s, v31.2s
umull v21.2d, v1.2s, v13.2s
umaddl x23, w24, w8, x29
umlal v11.2d, v18.2s, v19.2s
mov x10, #0x07fffffe07fffffe
sub x10, x10, #2
umaddl x26, w24, w21, x5
mul v29.2s, v14.2s, v31.2s
umlal v25.2d, v19.2s, v26.2s
add x7, x1, x6, lsr #26
mul v20.2s, v4.2s, v31.2s
and x6, x6, #0x3ffffff
shl v8.2s, v18.2s, #1
shl v4.2s, v4.2s, #1
umlal v11.2d, v29.2s, v14.2s
bfi x6, x7, #32, #26 // ubignum_of_preglist 4 // INTERMEDIATE aa
umlal v25.2d, v0.2s, v3.2s
umaddl x0, w24, w4, x19
umlal v25.2d, v15.2s, v13.2s
str x6, [tmpa+32]
umlal v21.2d, v18.2s, v4.2s
umaddl x8, w24, w11, x3
umlal v21.2d, v0.2s, v17.2s
ldr x30, [tmpa+32]
mul v14.2s, v5.2s, v31.2s
add x2, x2, x10
shl v5.2s, v28.2s, #1
shl v27.2s, v4.2s, #1
umlal v6.2d, v0.2s, v0.2s
umaddl x11, w24, w9, x15
umlal v6.2d, v12.2s, v3.2s
add x4, x30, x10
umlal v11.2d, v14.2s, v5.2s
add x3, x22, x10
umlal v11.2d, v2.2s, v17.2s
add x6, x0, x11, lsr #26
umlal v11.2d, v12.2s, v27.2s
add x14, x14, x10
umlal v6.2d, v14.2s, v27.2s
add x8, x8, x6, lsr #25
umlal v6.2d, v2.2s, v13.2s
movk x10, #0xffb4
umlal v25.2d, v16.2s, v4.2s
add x29, x16, x8, lsr #26
umull v27.2d, v1.2s, v3.2s
and x11, x11, #0x3ffffff
umlal v9.2d, v18.2s, v3.2s
add x19, x13, x10
umlal v9.2d, v0.2s, v13.2s
and x5, x8, #0x3ffffff
umlal v9.2d, v28.2s, v4.2s
bfi x11, x6, #32, #25 // ubignum_of_preglist 0 // INTERMEDIATE bb
umlal v9.2d, v16.2s, v16.2s
umaddl x30, w24, w28, x27
umlal v9.2d, v14.2s, v7.2s
sub x13, x19, x11
umull v10.2d, v1.2s, v18.2s
add x7, x23, x29, lsr #25
umlal v21.2d, v28.2s, v15.2s
lsr x16, x13, #32 // ubignum_of_wreglist 1 + ubignum_of_wreglist 0 // INTERMEDIATE e
umlal v21.2d, v2.2s, v22.2s
add x0, x26, x7, lsr #26
usra v25.2d, v9.2d, #26
and x20, x7, #0x3ffffff
umull v22.2d, v1.2s, v1.2s
add x8, x25, x0, lsr #25
umull v7.2d, v1.2s, v28.2s
and x1, x29, #0x1ffffff // ubignum_of_xreglist 3 // INTERMEDIATE bbalt
bic v18.16b, v25.16b, v23.16b
and x19, x8, #0x3ffffff
and v16.16b, v9.16b, v30.16b
and x7, x12, #0x3ffffff
usra v22.2d, v18.2d, #25
add x10, x30, x8, lsr #26
umlal v7.2d, v19.2s, v24.2s
bfi x5, x29, #32, #25 // ubignum_of_preglist 1 // INTERMEDIATE bb
and v9.16b, v25.16b, v23.16b
add x27, x7, x10, lsr #25
usra v22.2d, v18.2d, #24
mov x21, #60833
lsl x21, x21, #1
add x15, x17, x27, lsr #26
shl v25.2s, v3.2s, #1
umlal v7.2d, v14.2s, v17.2s
and x29, x27, #0x3ffffff
usra v22.2d, v18.2d, #21
bfi x29, x15, #32, #26 // ubignum_of_preglist 4 // INTERMEDIATE bb // ***SOURCE*** ubignum_of_xreglist 9 // INTERMEDIATE bbalt
umlal v10.2d, v14.2s, v24.2s
and x17, x6, #0x1ffffff // ubignum_of_xreglist 1 // INTERMEDIATE bbalt
umlal v10.2d, v2.2s, v28.2s
sub x6, x3, x5
umlal v10.2d, v12.2s, v17.2s
umaddl x25, w16, w21, x17
umlal v10.2d, v29.2s, v4.2s
mov w12, w5 // ubignum_of_xreglist 2 // INTERMEDIATE bbalt
umlal v22.2d, v20.2s, v4.2s
lsr x26, x6, #32 // ubignum_of_wreglist 3 + ubignum_of_wreglist 2 // INTERMEDIATE e
umlal v22.2d, v14.2s, v8.2s
and x24, x0, #0x1ffffff // ubignum_of_xreglist 5 // INTERMEDIATE bbalt
umlal v22.2d, v2.2s, v24.2s
stp x11, x5, [tmpb+0]
umlal v22.2d, v12.2s, v5.2s
bfi x20, x0, #32, #25 // ubignum_of_preglist 2 // INTERMEDIATE bb
umlal v22.2d, v29.2s, v17.2s
umaddl x12, w6, w21, x12
umull v18.2d, v1.2s, v4.2s
bfi x19, x10, #32, #25 // ubignum_of_preglist 3 // INTERMEDIATE bb
umlal v7.2d, v2.2s, v4.2s
sub x7, x14, x20
umlal v27.2d, v19.2s, v13.2s
mov w8, w20 // ubignum_of_xreglist 4 // INTERMEDIATE bbalt
usra v10.2d, v22.2d, #26
lsr x14, x7, #32 // ubignum_of_wreglist 5 + ubignum_of_wreglist 4 // INTERMEDIATE e
umlal v18.2d, v19.2s, v17.2s
and x28, x10, #0x1ffffff // ubignum_of_xreglist 7 // INTERMEDIATE bbalt
umlal v7.2d, v12.2s, v13.2s
sub x5, x2, x19
usra v11.2d, v10.2d, #25
mov w2, w19 // ubignum_of_xreglist 6 // INTERMEDIATE bbalt
umlal v27.2d, v0.2s, v4.2s
umlal v21.2d, v14.2s, v25.2s
sub x23, x4, x29
usra v7.2d, v11.2d, #26
mov w0, w29 // ubignum_of_xreglist 8 // INTERMEDIATE bbalt
umlal v18.2d, v0.2s, v28.2s
lsr x22, x23, #32 // ubignum_of_wreglist 9 + ubignum_of_wreglist 8 // INTERMEDIATE e
umlal v27.2d, v15.2s, v17.2s
str x29, [tmpb+32]
usra v6.2d, v7.2d, #25
mov w17, w11 // ubignum_of_xreglist 0 // INTERMEDIATE bbalt
and v0.16b, v22.16b, v30.16b // ubignum_of_hreglist 0 + ubignum_of_lreglist 0 // INTERMEDIATE H|L = x5|t3
umaddl x27, w26, w21, x1
umlal v18.2d, v14.2s, v13.2s
umaddl x30, w23, w21, x0
umlal v18.2d, v2.2s, v3.2s
lsr x10, x5, #32 // ubignum_of_wreglist 7 + ubignum_of_wreglist 6 // INTERMEDIATE e
and v4.16b, v6.16b, v30.16b // ubignum_of_hreglist 4 + ubignum_of_lreglist 4 // INTERMEDIATE H|L = x5|t3
and v1.16b, v10.16b, v23.16b // ubignum_of_hreglist 1 + ubignum_of_lreglist 1 // INTERMEDIATE H|L = x5|t3
umaddl x4, w14, w21, x24
ldr x0, [tmpa+0]
mov v0.s[1], w0
lsr x0, x0, #32
mov v1.s[1], w0
umaddl x9, w7, w21, x8
usra v18.2d, v6.2d, #26
umaddl x24, w10, w21, x28
and v3.16b, v7.16b, v23.16b // ubignum_of_hreglist 3 + ubignum_of_lreglist 3 // INTERMEDIATE H|L = x5|t3
umaddl x8, w22, w21, x15
umlal v27.2d, v14.2s, v26.2s
umaddl x15, w13, w21, x17
usra v21.2d, v18.2d, #25
stp x20, x19, [tmpb+16]
and v2.16b, v11.16b, v30.16b // ubignum_of_hreglist 2 + ubignum_of_lreglist 2 // INTERMEDIATE H|L = x5|t3
lsr x29, x8, #25
ldr x3, [tmpb+0]
mov v10.s[1], w3
lsr x3, x3, #32
mov v11.s[1], w3
add x17, x15, x29
usra v27.2d, v21.2d, #26
add x28, x17, x29, lsl #1
and v6.16b, v21.16b, v30.16b // ubignum_of_hreglist 6 + ubignum_of_lreglist 6 // INTERMEDIATE H|L = x5|t3
and x20, x8, #0x1ffffff
and v5.16b, v18.16b, v23.16b // ubignum_of_hreglist 5 + ubignum_of_lreglist 5 // INTERMEDIATE H|L = x5|t3
add x17, x28, x29, lsl #4
and v7.16b, v27.16b, v23.16b // ubignum_of_hreglist 7 + ubignum_of_lreglist 7 // INTERMEDIATE H|L = x5|t3
ldr x3, [tmpb+8]
mov v22.s[1], w3
lsr x3, x3, #32
mov v23.s[1], w3
add x29, x25, x17, lsr #26
ldr x15, [pointx+0]
mov v10.s[0], w15
lsr x15, x15, #32
mov v11.s[0], w15
and x11, x17, #0x3ffffff // ubignum_of_xreglist 0 // INTERMEDIATE bce
usra v16.2d, v27.2d, #25
add x8, x12, x29, lsr #25
ldr x3, [tmpb+16]
mov v14.s[1], w3
lsr x3, x3, #32
mov v15.s[1], w3
and x12, x29, #0x1ffffff // ubignum_of_xreglist 1 // INTERMEDIATE bce
ldr x15, [pointx+8]
mov v22.s[0], w15
lsr x15, x15, #32
mov v23.s[0], w15
add x28, x27, x8, lsr #26
and v8.16b, v16.16b, v30.16b // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = x5|t3
umull x1, w12, w10
ldr x3, [tmpb+24]
mov v17.s[1], w3
lsr x3, x3, #32
mov v18.s[1], w3
add x25, x9, x28, lsr #25
ldr x15, [pointx+16]
mov v14.s[0], w15
lsr x15, x15, #32
mov v15.s[0], w15
umaddl x19, w5, w21, x2
usra v9.2d, v16.2d, #26 // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = x5|t3
add x2, x4, x25, lsr #26
ldr x3, [tmpb+32]
mov v24.s[1], w3
lsr x3, x3, #32
mov v25.s[1], w3
umull x3, w12, w23
ldr x15, [pointx+24]
mov v17.s[0], w15
lsr x15, x15, #32
mov v18.s[0], w15
add x29, x19, x2, lsr #25
umull v26.2d, v0.2s, v23.2s
and x21, x28, #0x1ffffff // ubignum_of_xreglist 3 // INTERMEDIATE bce
ldr x0, [tmpa+8]
mov v2.s[1], w0
lsr x0, x0, #32
mov v3.s[1], w0
umaddl x27, w21, w5, x3
ldr x15, [pointx+32]
mov v24.s[0], w15
lsr x15, x15, #32
mov v25.s[0], w15
add x17, x24, x29, lsr #26
umull v29.2d, v1.2s, v18.2s
and x15, x8, #0x3ffffff // ubignum_of_xreglist 2 // INTERMEDIATE bce
umull v20.2d, v0.2s, v15.2s
add x19, x30, x17, lsr #25
and x3, x17, #0x1ffffff // ubignum_of_xreglist 7 // INTERMEDIATE bce
mul v12.2s, v25.2s, v31.2s
ldr x0, [tmpa+16]
mov v4.s[1], w0
lsr x0, x0, #32
mov v5.s[1], w0
add x4, x20, x19, lsr #26 // ubignum_of_xreglist 9 // INTERMEDIATE bce
umlal v26.2d, v2.2s, v11.2s
add w28, w3, w3, lsl #1;
umlal v20.2d, v2.2s, v23.2s
add w28, w28, w3, lsl #4
umull x8, w12, w5
ldr x0, [tmpa+24]
mov v6.s[1], w0
lsr x0, x0, #32
mov v7.s[1], w0
and x30, x25, #0x3ffffff // ubignum_of_xreglist 4 // INTERMEDIATE bce
mul v16.2s, v18.2s, v31.2s
add w17, w4, w4, lsl #1;
umull v21.2d, v1.2s, v15.2s
add w17, w17, w4, lsl #4
umaddl x25, w21, w7, x8
umlal v20.2d, v4.2s, v11.2s
add w8, w21, w21, lsl #1;
ldr x0, [tmpa+32]
add w8, w8, w21, lsl #4
mov v8.s[1], w0
lsr x0, x0, #32
mov v9.s[1], w0
and x2, x2, #0x1ffffff // ubignum_of_xreglist 5 // INTERMEDIATE bce
umlal v29.2d, v3.2s, v15.2s
umaddl x24, w2, w6, x25
umull v13.2d, v0.2s, v25.2s
umaddl x25, w2, w7, x27
umaddl x0, w3, w6, x25
mul v19.2s, v15.2s, v31.2s
umull v27.2d, v0.2s, v18.2s
umaddl x20, w3, w13, x24
umlal v20.2d, v6.2s, v12.2s
umaddl x24, w21, w14, x1
umlal v13.2d, v2.2s, v18.2s
umaddl x9, w4, w13, x0
umull v25.2d, v0.2s, v11.2s
umaddl x20, w17, w23, x20
umlal v27.2d, v2.2s, v15.2s
umaddl x0, w2, w26, x24
umull v28.2d, v1.2s, v11.2s
umull x24, w17, w5
umlal v29.2d, v5.2s, v23.2s
umaddl x9, w11, w22, x9
umlal v13.2d, v4.2s, v15.2s
umaddl x27, w3, w16, x0
umlal v27.2d, v4.2s, v23.2s
umull x0, w17, w14
umlal v27.2d, v6.2s, v11.2s
umull x4, w12, w14
umlal v27.2d, v8.2s, v12.2s
umaddl x25, w11, w10, x20
umlal v27.2d, v1.2s, v17.2s
umaddl x0, w28, w10, x0
umlal v13.2d, v6.2s, v23.2s
umull x3, w17, w6
umlal v13.2d, v8.2s, v11.2s
umaddl x1, w21, w26, x4
umlal v20.2d, v8.2s, v16.2s
umaddl x4, w2, w13, x24
umlal v28.2d, v3.2s, v12.2s
umaddl x20, w28, w7, x3
umlal v29.2d, v7.2s, v11.2s
and x3, x19, #0x3ffffff // ubignum_of_xreglist 9 // INTERMEDIATE bce