~ubuntu-branches/ubuntu/lucid/openssl/lucid-proposed

« back to all changes in this revision

Viewing changes to crypto/sha/asm/sha1-586.pl

  • Committer: Bazaar Package Importer
  • Author(s): Nicolas Valcárcel Scerpella (Canonical)
  • Date: 2009-12-06 20:16:24 UTC
  • mfrom: (11.1.9 sid)
  • Revision ID: james.westby@ubuntu.com-20091206201624-u126qjpqm2n2uuhu
Tags: 0.9.8k-7ubuntu1
* Merge from debian unstable, remaining changes (LP: #493392):
  - Link using -Bsymbolic-functions
  - Add support for lpia
  - Disable SSLv2 during compile
  - Ship documentation in openssl-doc, suggested by the package.
  - Use a different priority for libssl0.9.8/restart-services
    depending on whether a desktop, or server dist-upgrade is being
    performed.
  - Display a system restart required notification bubble on libssl0.9.8
    upgrade.
  - Replace duplicate files in the doc directory with symlinks.
  - Move runtime libraries to /lib, for the benefit of wpasupplicant
* Strip the patches out of the source into quilt patches
* Disable CVE-2009-3555.patch

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
#!/usr/local/bin/perl
2
2
 
 
3
# ====================================================================
 
4
# [Re]written by Andy Polyakov <appro@fy.chalmers.se> for the OpenSSL
 
5
# project. The module is, however, dual licensed under OpenSSL and
 
6
# CRYPTOGAMS licenses depending on where you obtain it. For further
 
7
# details see http://www.openssl.org/~appro/cryptogams/.
 
8
# ====================================================================
 
9
 
 
10
# "[Re]written" was achieved in two major overhauls. In 2004 BODY_*
 
11
# functions were re-implemented to address P4 performance issue [see
 
12
# commentary below], and in 2006 the rest was rewritten in order to
 
13
# gain freedom to liberate licensing terms.
 
14
 
3
15
# It was noted that Intel IA-32 C compiler generates code which
4
16
# performs ~30% *faster* on P4 CPU than original *hand-coded*
5
17
# SHA1 assembler implementation. To address this problem (and
17
29
# improvement on P4 outweights the loss and incorporate this
18
30
# re-tuned code to 0.9.7 and later.
19
31
# ----------------------------------------------------------------
20
 
# Those who for any particular reason absolutely must score on
21
 
# Pentium can replace this module with one from 0.9.6 distribution.
22
 
# This "offer" shall be revoked the moment programming interface to
23
 
# this module is changed, in which case this paragraph should be
24
 
# removed.
25
 
# ----------------------------------------------------------------
26
32
#                                       <appro@fy.chalmers.se>
27
33
 
28
 
$normal=0;
29
 
 
30
 
push(@INC,"perlasm","../../perlasm");
 
34
$0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
 
35
push(@INC,"${dir}","${dir}../../perlasm");
31
36
require "x86asm.pl";
32
37
 
33
38
&asm_init($ARGV[0],"sha1-586.pl",$ARGV[$#ARGV] eq "386");
34
39
 
35
40
$A="eax";
36
 
$B="ecx";
37
 
$C="ebx";
 
41
$B="ebx";
 
42
$C="ecx";
38
43
$D="edx";
39
44
$E="edi";
40
45
$T="esi";
41
46
$tmp1="ebp";
42
47
 
43
 
$off=9*4;
44
 
 
45
 
@K=(0x5a827999,0x6ed9eba1,0x8f1bbcdc,0xca62c1d6);
46
 
 
47
 
&sha1_block_data("sha1_block_asm_data_order");
48
 
 
49
 
&asm_finish();
50
 
 
51
 
sub Nn
52
 
        {
53
 
        local($p)=@_;
54
 
        local(%n)=($A,$T,$B,$A,$C,$B,$D,$C,$E,$D,$T,$E);
55
 
        return($n{$p});
56
 
        }
57
 
 
58
 
sub Np
59
 
        {
60
 
        local($p)=@_;
61
 
        local(%n)=($A,$T,$B,$A,$C,$B,$D,$C,$E,$D,$T,$E);
62
 
        local(%n)=($A,$B,$B,$C,$C,$D,$D,$E,$E,$T,$T,$A);
63
 
        return($n{$p});
64
 
        }
65
 
 
66
 
sub Na
67
 
        {
68
 
        local($n)=@_;
69
 
        return( (($n   )&0x0f),
70
 
                (($n+ 2)&0x0f),
71
 
                (($n+ 8)&0x0f),
72
 
                (($n+13)&0x0f),
73
 
                (($n+ 1)&0x0f));
74
 
        }
75
 
 
76
 
sub X_expand
77
 
        {
78
 
        local($in)=@_;
79
 
 
80
 
        &comment("First, load the words onto the stack in network byte order");
81
 
        for ($i=0; $i<16; $i+=2)
82
 
                {
83
 
                &mov($A,&DWP(($i+0)*4,$in,"",0));# unless $i == 0;
84
 
                 &mov($B,&DWP(($i+1)*4,$in,"",0));
85
 
                &bswap($A);
86
 
                 &bswap($B);
87
 
                &mov(&swtmp($i+0),$A);
88
 
                 &mov(&swtmp($i+1),$B);
89
 
                }
90
 
 
91
 
        &comment("We now have the X array on the stack");
92
 
        &comment("starting at sp-4");
93
 
        }
94
 
 
95
 
# Rules of engagement
96
 
# F is always trashable at the start, the running total.
97
 
# E becomes the next F so it can be trashed after it has been 'accumulated'
98
 
# F becomes A in the next round.  We don't need to access it much.
99
 
# During the X update part, the result ends up in $X[$n0].
 
48
@V=($A,$B,$C,$D,$E,$T);
100
49
 
101
50
sub BODY_00_15
102
51
        {
103
 
        local($pos,$K,$X,$n,$a,$b,$c,$d,$e,$f)=@_;
 
52
        local($n,$a,$b,$c,$d,$e,$f)=@_;
104
53
 
105
54
        &comment("00_15 $n");
106
55
 
109
58
         else        { &mov($a,$tmp1); }
110
59
        &rotl($tmp1,5);                 # tmp1=ROTATE(a,5)
111
60
         &xor($f,$d);
112
 
        &and($f,$b);
113
 
         &add($tmp1,$e);                # tmp1+=e;
114
 
        &mov($e,&swtmp($n));            # e becomes volatile and
115
 
                                        # is loaded with xi
 
61
        &add($tmp1,$e);                 # tmp1+=e;
 
62
         &and($f,$b);
 
63
        &mov($e,&swtmp($n%16));         # e becomes volatile and is loaded
 
64
                                        # with xi, also note that e becomes
 
65
                                        # f in next round...
116
66
         &xor($f,$d);                   # f holds F_00_19(b,c,d)
117
67
        &rotr($b,2);                    # b=ROTATE(b,30)
118
 
         &lea($tmp1,&DWP($K,$tmp1,$e,1));# tmp1+=K_00_19+xi
 
68
         &lea($tmp1,&DWP(0x5a827999,$tmp1,$e)); # tmp1+=K_00_19+xi
119
69
 
120
70
        if ($n==15) { &add($f,$tmp1); } # f+=tmp1
121
 
        else        { &add($tmp1,$f); }
 
71
        else        { &add($tmp1,$f); } # f becomes a in next round
122
72
        }
123
73
 
124
74
sub BODY_16_19
125
75
        {
126
 
        local($pos,$K,$X,$n,$a,$b,$c,$d,$e,$f)=@_;
127
 
        local($n0,$n1,$n2,$n3,$np)=&Na($n);
 
76
        local($n,$a,$b,$c,$d,$e,$f)=@_;
128
77
 
129
78
        &comment("16_19 $n");
130
79
 
131
 
        &mov($f,&swtmp($n1));           # f to hold Xupdate(xi,xa,xb,xc,xd)
 
80
        &mov($f,&swtmp($n%16));         # f to hold Xupdate(xi,xa,xb,xc,xd)
132
81
         &mov($tmp1,$c);                # tmp1 to hold F_00_19(b,c,d)
133
 
        &xor($f,&swtmp($n0));
 
82
        &xor($f,&swtmp(($n+2)%16));
134
83
         &xor($tmp1,$d);
135
 
        &xor($f,&swtmp($n2));
 
84
        &xor($f,&swtmp(($n+8)%16));
136
85
         &and($tmp1,$b);                # tmp1 holds F_00_19(b,c,d)
137
86
        &rotr($b,2);                    # b=ROTATE(b,30)
138
 
         &xor($f,&swtmp($n3));          # f holds xa^xb^xc^xd
139
 
        &rotl($f,1);                    # f=ROATE(f,1)
 
87
         &xor($f,&swtmp(($n+13)%16));   # f holds xa^xb^xc^xd
 
88
        &rotl($f,1);                    # f=ROTATE(f,1)
140
89
         &xor($tmp1,$d);                # tmp1=F_00_19(b,c,d)
141
 
        &mov(&swtmp($n0),$f);           # xi=f
142
 
        &lea($f,&DWP($K,$f,$e,1));      # f+=K_00_19+e
 
90
        &mov(&swtmp($n%16),$f);         # xi=f
 
91
        &lea($f,&DWP(0x5a827999,$f,$e));# f+=K_00_19+e
143
92
         &mov($e,$a);                   # e becomes volatile
144
93
        &rotl($e,5);                    # e=ROTATE(a,5)
145
94
         &add($f,$tmp1);                # f+=F_00_19(b,c,d)
148
97
 
149
98
sub BODY_20_39
150
99
        {
151
 
        local($pos,$K,$X,$n,$a,$b,$c,$d,$e,$f)=@_;
 
100
        local($n,$a,$b,$c,$d,$e,$f)=@_;
 
101
        local $K=($n<40)?0x6ed9eba1:0xca62c1d6;
152
102
 
153
103
        &comment("20_39 $n");
154
 
        local($n0,$n1,$n2,$n3,$np)=&Na($n);
155
104
 
156
105
        &mov($tmp1,$b);                 # tmp1 to hold F_20_39(b,c,d)
157
 
         &mov($f,&swtmp($n0));          # f to hold Xupdate(xi,xa,xb,xc,xd)
 
106
         &mov($f,&swtmp($n%16));        # f to hold Xupdate(xi,xa,xb,xc,xd)
158
107
        &rotr($b,2);                    # b=ROTATE(b,30)
159
 
         &xor($f,&swtmp($n1));
 
108
         &xor($f,&swtmp(($n+2)%16));
160
109
        &xor($tmp1,$c);
161
 
         &xor($f,&swtmp($n2));
 
110
         &xor($f,&swtmp(($n+8)%16));
162
111
        &xor($tmp1,$d);                 # tmp1 holds F_20_39(b,c,d)
163
 
         &xor($f,&swtmp($n3));          # f holds xa^xb^xc^xd
 
112
         &xor($f,&swtmp(($n+13)%16));   # f holds xa^xb^xc^xd
164
113
        &rotl($f,1);                    # f=ROTATE(f,1)
165
114
         &add($tmp1,$e);
166
 
        &mov(&swtmp($n0),$f);           # xi=f
 
115
        &mov(&swtmp($n%16),$f);         # xi=f
167
116
         &mov($e,$a);                   # e becomes volatile
168
117
        &rotl($e,5);                    # e=ROTATE(a,5)
169
 
         &lea($f,&DWP($K,$f,$tmp1,1));  # f+=K_20_39+e
 
118
         &lea($f,&DWP($K,$f,$tmp1));    # f+=K_20_39+e
170
119
        &add($f,$e);                    # f+=ROTATE(a,5)
171
120
        }
172
121
 
173
122
sub BODY_40_59
174
123
        {
175
 
        local($pos,$K,$X,$n,$a,$b,$c,$d,$e,$f)=@_;
 
124
        local($n,$a,$b,$c,$d,$e,$f)=@_;
176
125
 
177
126
        &comment("40_59 $n");
178
 
        local($n0,$n1,$n2,$n3,$np)=&Na($n);
179
127
 
180
 
        &mov($f,&swtmp($n0));           # f to hold Xupdate(xi,xa,xb,xc,xd)
181
 
         &mov($tmp1,&swtmp($n1));
182
 
        &xor($f,$tmp1);
183
 
         &mov($tmp1,&swtmp($n2));
184
 
        &xor($f,$tmp1);
185
 
         &mov($tmp1,&swtmp($n3));
 
128
        &mov($f,&swtmp($n%16));         # f to hold Xupdate(xi,xa,xb,xc,xd)
 
129
         &mov($tmp1,&swtmp(($n+2)%16));
 
130
        &xor($f,$tmp1);
 
131
         &mov($tmp1,&swtmp(($n+8)%16));
 
132
        &xor($f,$tmp1);
 
133
         &mov($tmp1,&swtmp(($n+13)%16));
186
134
        &xor($f,$tmp1);                 # f holds xa^xb^xc^xd
187
135
         &mov($tmp1,$b);                # tmp1 to hold F_40_59(b,c,d)
188
136
        &rotl($f,1);                    # f=ROTATE(f,1)
189
137
         &or($tmp1,$c);
190
 
        &mov(&swtmp($n0),$f);           # xi=f
 
138
        &mov(&swtmp($n%16),$f);         # xi=f
191
139
         &and($tmp1,$d);
192
 
        &lea($f,&DWP($K,$f,$e,1));      # f+=K_40_59+e
 
140
        &lea($f,&DWP(0x8f1bbcdc,$f,$e));# f+=K_40_59+e
193
141
         &mov($e,$b);                   # e becomes volatile and is used
194
142
                                        # to calculate F_40_59(b,c,d)
195
143
        &rotr($b,2);                    # b=ROTATE(b,30)
201
149
        &add($f,$e);                    # f+=ROTATE(a,5)
202
150
        }
203
151
 
204
 
sub BODY_60_79
205
 
        {
206
 
        &BODY_20_39(@_);
207
 
        }
208
 
 
209
 
sub sha1_block_host
210
 
        {
211
 
        local($name, $sclabel)=@_;
212
 
 
213
 
        &function_begin_B($name,"");
214
 
 
215
 
        # parameter 1 is the MD5_CTX structure.
216
 
        # A     0
217
 
        # B     4
218
 
        # C     8
219
 
        # D     12
220
 
        # E     16
221
 
 
222
 
        &mov("ecx",     &wparam(2));
223
 
         &push("esi");
224
 
        &shl("ecx",6);
225
 
         &mov("esi",    &wparam(1));
226
 
        &push("ebp");
227
 
         &add("ecx","esi");     # offset to leave on
228
 
        &push("ebx");
229
 
         &mov("ebp",    &wparam(0));
230
 
        &push("edi");
231
 
         &mov($D,       &DWP(12,"ebp","",0));
232
 
        &stack_push(18+9);
233
 
         &mov($E,       &DWP(16,"ebp","",0));
234
 
        &mov($C,        &DWP( 8,"ebp","",0));
235
 
         &mov(&swtmp(17),"ecx");
236
 
 
237
 
        &comment("First we need to setup the X array");
238
 
 
239
 
        for ($i=0; $i<16; $i+=2)
 
152
&function_begin("sha1_block_data_order");
 
153
        &mov($tmp1,&wparam(0)); # SHA_CTX *c
 
154
        &mov($T,&wparam(1));    # const void *input
 
155
        &mov($A,&wparam(2));    # size_t num
 
156
        &stack_push(16);        # allocate X[16]
 
157
        &shl($A,6);
 
158
        &add($A,$T);
 
159
        &mov(&wparam(2),$A);    # pointer beyond the end of input
 
160
        &mov($E,&DWP(16,$tmp1));# pre-load E
 
161
 
 
162
        &set_label("loop",16);
 
163
 
 
164
        # copy input chunk to X, but reversing byte order!
 
165
        for ($i=0; $i<16; $i+=4)
240
166
                {
241
 
                &mov($A,&DWP(($i+0)*4,"esi","",0));# unless $i == 0;
242
 
                 &mov($B,&DWP(($i+1)*4,"esi","",0));
 
167
                &mov($A,&DWP(4*($i+0),$T));
 
168
                &mov($B,&DWP(4*($i+1),$T));
 
169
                &mov($C,&DWP(4*($i+2),$T));
 
170
                &mov($D,&DWP(4*($i+3),$T));
 
171
                &bswap($A);
 
172
                &bswap($B);
 
173
                &bswap($C);
 
174
                &bswap($D);
243
175
                &mov(&swtmp($i+0),$A);
244
 
                 &mov(&swtmp($i+1),$B);
 
176
                &mov(&swtmp($i+1),$B);
 
177
                &mov(&swtmp($i+2),$C);
 
178
                &mov(&swtmp($i+3),$D);
245
179
                }
246
 
        &jmp($sclabel);
247
 
        &function_end_B($name);
248
 
        }
249
 
 
250
 
 
251
 
sub sha1_block_data
252
 
        {
253
 
        local($name)=@_;
254
 
 
255
 
        &function_begin_B($name,"");
256
 
 
257
 
        # parameter 1 is the MD5_CTX structure.
258
 
        # A     0
259
 
        # B     4
260
 
        # C     8
261
 
        # D     12
262
 
        # E     16
263
 
 
264
 
        &mov("ecx",     &wparam(2));
265
 
         &push("esi");
266
 
        &shl("ecx",6);
267
 
         &mov("esi",    &wparam(1));
268
 
        &push("ebp");
269
 
         &add("ecx","esi");     # offset to leave on
270
 
        &push("ebx");
271
 
         &mov("ebp",    &wparam(0));
272
 
        &push("edi");
273
 
         &mov($D,       &DWP(12,"ebp","",0));
274
 
        &stack_push(18+9);
275
 
         &mov($E,       &DWP(16,"ebp","",0));
276
 
        &mov($C,        &DWP( 8,"ebp","",0));
277
 
         &mov(&swtmp(17),"ecx");
278
 
 
279
 
        &comment("First we need to setup the X array");
280
 
 
281
 
        &set_label("start") unless $normal;
282
 
 
283
 
        &X_expand("esi");
284
 
         &mov(&wparam(1),"esi");
285
 
 
286
 
        &set_label("shortcut", 0, 1);
287
 
        &comment("");
288
 
        &comment("Start processing");
289
 
 
290
 
        # odd start
291
 
        &mov($A,        &DWP( 0,"ebp","",0));
292
 
         &mov($B,       &DWP( 4,"ebp","",0));
293
 
        $X="esp";
294
 
        &BODY_00_15(-2,$K[0],$X, 0,$A,$B,$C,$D,$E,$T);
295
 
        &BODY_00_15( 0,$K[0],$X, 1,$T,$A,$B,$C,$D,$E);
296
 
        &BODY_00_15( 0,$K[0],$X, 2,$E,$T,$A,$B,$C,$D);
297
 
        &BODY_00_15( 0,$K[0],$X, 3,$D,$E,$T,$A,$B,$C);
298
 
        &BODY_00_15( 0,$K[0],$X, 4,$C,$D,$E,$T,$A,$B);
299
 
        &BODY_00_15( 0,$K[0],$X, 5,$B,$C,$D,$E,$T,$A);
300
 
        &BODY_00_15( 0,$K[0],$X, 6,$A,$B,$C,$D,$E,$T);
301
 
        &BODY_00_15( 0,$K[0],$X, 7,$T,$A,$B,$C,$D,$E);
302
 
        &BODY_00_15( 0,$K[0],$X, 8,$E,$T,$A,$B,$C,$D);
303
 
        &BODY_00_15( 0,$K[0],$X, 9,$D,$E,$T,$A,$B,$C);
304
 
        &BODY_00_15( 0,$K[0],$X,10,$C,$D,$E,$T,$A,$B);
305
 
        &BODY_00_15( 0,$K[0],$X,11,$B,$C,$D,$E,$T,$A);
306
 
        &BODY_00_15( 0,$K[0],$X,12,$A,$B,$C,$D,$E,$T);
307
 
        &BODY_00_15( 0,$K[0],$X,13,$T,$A,$B,$C,$D,$E);
308
 
        &BODY_00_15( 0,$K[0],$X,14,$E,$T,$A,$B,$C,$D);
309
 
        &BODY_00_15( 1,$K[0],$X,15,$D,$E,$T,$A,$B,$C);
310
 
        &BODY_16_19(-1,$K[0],$X,16,$C,$D,$E,$T,$A,$B);
311
 
        &BODY_16_19( 0,$K[0],$X,17,$B,$C,$D,$E,$T,$A);
312
 
        &BODY_16_19( 0,$K[0],$X,18,$A,$B,$C,$D,$E,$T);
313
 
        &BODY_16_19( 1,$K[0],$X,19,$T,$A,$B,$C,$D,$E);
314
 
 
315
 
        &BODY_20_39(-1,$K[1],$X,20,$E,$T,$A,$B,$C,$D);
316
 
        &BODY_20_39( 0,$K[1],$X,21,$D,$E,$T,$A,$B,$C);
317
 
        &BODY_20_39( 0,$K[1],$X,22,$C,$D,$E,$T,$A,$B);
318
 
        &BODY_20_39( 0,$K[1],$X,23,$B,$C,$D,$E,$T,$A);
319
 
        &BODY_20_39( 0,$K[1],$X,24,$A,$B,$C,$D,$E,$T);
320
 
        &BODY_20_39( 0,$K[1],$X,25,$T,$A,$B,$C,$D,$E);
321
 
        &BODY_20_39( 0,$K[1],$X,26,$E,$T,$A,$B,$C,$D);
322
 
        &BODY_20_39( 0,$K[1],$X,27,$D,$E,$T,$A,$B,$C);
323
 
        &BODY_20_39( 0,$K[1],$X,28,$C,$D,$E,$T,$A,$B);
324
 
        &BODY_20_39( 0,$K[1],$X,29,$B,$C,$D,$E,$T,$A);
325
 
        &BODY_20_39( 0,$K[1],$X,30,$A,$B,$C,$D,$E,$T);
326
 
        &BODY_20_39( 0,$K[1],$X,31,$T,$A,$B,$C,$D,$E);
327
 
        &BODY_20_39( 0,$K[1],$X,32,$E,$T,$A,$B,$C,$D);
328
 
        &BODY_20_39( 0,$K[1],$X,33,$D,$E,$T,$A,$B,$C);
329
 
        &BODY_20_39( 0,$K[1],$X,34,$C,$D,$E,$T,$A,$B);
330
 
        &BODY_20_39( 0,$K[1],$X,35,$B,$C,$D,$E,$T,$A);
331
 
        &BODY_20_39( 0,$K[1],$X,36,$A,$B,$C,$D,$E,$T);
332
 
        &BODY_20_39( 0,$K[1],$X,37,$T,$A,$B,$C,$D,$E);
333
 
        &BODY_20_39( 0,$K[1],$X,38,$E,$T,$A,$B,$C,$D);
334
 
        &BODY_20_39( 1,$K[1],$X,39,$D,$E,$T,$A,$B,$C);
335
 
 
336
 
        &BODY_40_59(-1,$K[2],$X,40,$C,$D,$E,$T,$A,$B);
337
 
        &BODY_40_59( 0,$K[2],$X,41,$B,$C,$D,$E,$T,$A);
338
 
        &BODY_40_59( 0,$K[2],$X,42,$A,$B,$C,$D,$E,$T);
339
 
        &BODY_40_59( 0,$K[2],$X,43,$T,$A,$B,$C,$D,$E);
340
 
        &BODY_40_59( 0,$K[2],$X,44,$E,$T,$A,$B,$C,$D);
341
 
        &BODY_40_59( 0,$K[2],$X,45,$D,$E,$T,$A,$B,$C);
342
 
        &BODY_40_59( 0,$K[2],$X,46,$C,$D,$E,$T,$A,$B);
343
 
        &BODY_40_59( 0,$K[2],$X,47,$B,$C,$D,$E,$T,$A);
344
 
        &BODY_40_59( 0,$K[2],$X,48,$A,$B,$C,$D,$E,$T);
345
 
        &BODY_40_59( 0,$K[2],$X,49,$T,$A,$B,$C,$D,$E);
346
 
        &BODY_40_59( 0,$K[2],$X,50,$E,$T,$A,$B,$C,$D);
347
 
        &BODY_40_59( 0,$K[2],$X,51,$D,$E,$T,$A,$B,$C);
348
 
        &BODY_40_59( 0,$K[2],$X,52,$C,$D,$E,$T,$A,$B);
349
 
        &BODY_40_59( 0,$K[2],$X,53,$B,$C,$D,$E,$T,$A);
350
 
        &BODY_40_59( 0,$K[2],$X,54,$A,$B,$C,$D,$E,$T);
351
 
        &BODY_40_59( 0,$K[2],$X,55,$T,$A,$B,$C,$D,$E);
352
 
        &BODY_40_59( 0,$K[2],$X,56,$E,$T,$A,$B,$C,$D);
353
 
        &BODY_40_59( 0,$K[2],$X,57,$D,$E,$T,$A,$B,$C);
354
 
        &BODY_40_59( 0,$K[2],$X,58,$C,$D,$E,$T,$A,$B);
355
 
        &BODY_40_59( 1,$K[2],$X,59,$B,$C,$D,$E,$T,$A);
356
 
 
357
 
        &BODY_60_79(-1,$K[3],$X,60,$A,$B,$C,$D,$E,$T);
358
 
        &BODY_60_79( 0,$K[3],$X,61,$T,$A,$B,$C,$D,$E);
359
 
        &BODY_60_79( 0,$K[3],$X,62,$E,$T,$A,$B,$C,$D);
360
 
        &BODY_60_79( 0,$K[3],$X,63,$D,$E,$T,$A,$B,$C);
361
 
        &BODY_60_79( 0,$K[3],$X,64,$C,$D,$E,$T,$A,$B);
362
 
        &BODY_60_79( 0,$K[3],$X,65,$B,$C,$D,$E,$T,$A);
363
 
        &BODY_60_79( 0,$K[3],$X,66,$A,$B,$C,$D,$E,$T);
364
 
        &BODY_60_79( 0,$K[3],$X,67,$T,$A,$B,$C,$D,$E);
365
 
        &BODY_60_79( 0,$K[3],$X,68,$E,$T,$A,$B,$C,$D);
366
 
        &BODY_60_79( 0,$K[3],$X,69,$D,$E,$T,$A,$B,$C);
367
 
        &BODY_60_79( 0,$K[3],$X,70,$C,$D,$E,$T,$A,$B);
368
 
        &BODY_60_79( 0,$K[3],$X,71,$B,$C,$D,$E,$T,$A);
369
 
        &BODY_60_79( 0,$K[3],$X,72,$A,$B,$C,$D,$E,$T);
370
 
        &BODY_60_79( 0,$K[3],$X,73,$T,$A,$B,$C,$D,$E);
371
 
        &BODY_60_79( 0,$K[3],$X,74,$E,$T,$A,$B,$C,$D);
372
 
        &BODY_60_79( 0,$K[3],$X,75,$D,$E,$T,$A,$B,$C);
373
 
        &BODY_60_79( 0,$K[3],$X,76,$C,$D,$E,$T,$A,$B);
374
 
        &BODY_60_79( 0,$K[3],$X,77,$B,$C,$D,$E,$T,$A);
375
 
        &BODY_60_79( 0,$K[3],$X,78,$A,$B,$C,$D,$E,$T);
376
 
        &BODY_60_79( 2,$K[3],$X,79,$T,$A,$B,$C,$D,$E);
377
 
 
378
 
        &comment("End processing");
379
 
        &comment("");
380
 
        # D is the tmp value
381
 
 
382
 
        # E -> A
383
 
        # T -> B
384
 
        # A -> C
385
 
        # B -> D
386
 
        # C -> E
387
 
        # D -> T
388
 
 
389
 
        &mov($tmp1,&wparam(0));
390
 
 
391
 
         &mov($D,       &DWP(12,$tmp1,"",0));
392
 
        &add($D,$B);
393
 
         &mov($B,       &DWP( 4,$tmp1,"",0));
394
 
        &add($B,$T);
395
 
         &mov($T,       $A);
396
 
        &mov($A,        &DWP( 0,$tmp1,"",0));
397
 
         &mov(&DWP(12,$tmp1,"",0),$D);
398
 
 
399
 
        &add($A,$E);
400
 
         &mov($E,       &DWP(16,$tmp1,"",0));
401
 
        &add($E,$C);
402
 
         &mov($C,       &DWP( 8,$tmp1,"",0));
403
 
        &add($C,$T);
404
 
 
405
 
         &mov(&DWP( 0,$tmp1,"",0),$A);
406
 
        &mov("esi",&wparam(1));
407
 
         &mov(&DWP( 8,$tmp1,"",0),$C);
408
 
        &add("esi",64);
409
 
         &mov("eax",&swtmp(17));
410
 
        &mov(&DWP(16,$tmp1,"",0),$E);
411
 
         &cmp("esi","eax");
412
 
        &mov(&DWP( 4,$tmp1,"",0),$B);
413
 
         &jb(&label("start"));
414
 
 
415
 
        &stack_pop(18+9);
416
 
         &pop("edi");
417
 
        &pop("ebx");
418
 
         &pop("ebp");
419
 
        &pop("esi");
420
 
         &ret();
421
 
 
422
 
        # keep a note of shortcut label so it can be used outside
423
 
        # block.
424
 
        my $sclabel = &label("shortcut");
425
 
 
426
 
        &function_end_B($name);
427
 
        # Putting this here avoids problems with MASM in debugging mode
428
 
        &sha1_block_host("sha1_block_asm_host_order", $sclabel);
429
 
        }
430
 
 
 
180
        &mov(&wparam(1),$T);    # redundant in 1st spin
 
181
 
 
182
        &mov($A,&DWP(0,$tmp1)); # load SHA_CTX
 
183
        &mov($B,&DWP(4,$tmp1));
 
184
        &mov($C,&DWP(8,$tmp1));
 
185
        &mov($D,&DWP(12,$tmp1));
 
186
        # E is pre-loaded
 
187
 
 
188
        for($i=0;$i<16;$i++)    { &BODY_00_15($i,@V); unshift(@V,pop(@V)); }
 
189
        for(;$i<20;$i++)        { &BODY_16_19($i,@V); unshift(@V,pop(@V)); }
 
190
        for(;$i<40;$i++)        { &BODY_20_39($i,@V); unshift(@V,pop(@V)); }
 
191
        for(;$i<60;$i++)        { &BODY_40_59($i,@V); unshift(@V,pop(@V)); }
 
192
        for(;$i<80;$i++)        { &BODY_20_39($i,@V); unshift(@V,pop(@V)); }
 
193
 
 
194
        (($V[5] eq $D) and ($V[0] eq $E)) or die;       # double-check
 
195
 
 
196
        &mov($tmp1,&wparam(0)); # re-load SHA_CTX*
 
197
        &mov($D,&wparam(1));    # D is last "T" and is discarded
 
198
 
 
199
        &add($E,&DWP(0,$tmp1)); # E is last "A"...
 
200
        &add($T,&DWP(4,$tmp1));
 
201
        &add($A,&DWP(8,$tmp1));
 
202
        &add($B,&DWP(12,$tmp1));
 
203
        &add($C,&DWP(16,$tmp1));
 
204
 
 
205
        &mov(&DWP(0,$tmp1),$E); # update SHA_CTX
 
206
         &add($D,64);           # advance input pointer
 
207
        &mov(&DWP(4,$tmp1),$T);
 
208
         &cmp($D,&wparam(2));   # have we reached the end yet?
 
209
        &mov(&DWP(8,$tmp1),$A);
 
210
         &mov($E,$C);           # C is last "E" which needs to be "pre-loaded"
 
211
        &mov(&DWP(12,$tmp1),$B);
 
212
         &mov($T,$D);           # input pointer
 
213
        &mov(&DWP(16,$tmp1),$C);
 
214
        &jb(&label("loop"));
 
215
 
 
216
        &stack_pop(16);
 
217
&function_end("sha1_block_data_order");
 
218
 
 
219
&asm_finish();