aes.asm 11.7 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
	! Benchmarks on my slow sparcstation:	
	! C code	
	! aes128 (ECB encrypt): 14.36s, 0.696MB/s
	! aes128 (ECB decrypt): 17.19s, 0.582MB/s
	! aes128 (CBC encrypt): 16.08s, 0.622MB/s
	! aes128 ((CBC decrypt)): 18.79s, 0.532MB/s
	! 
	! aes192 (ECB encrypt): 16.85s, 0.593MB/s
	! aes192 (ECB decrypt): 19.64s, 0.509MB/s
	! aes192 (CBC encrypt): 18.43s, 0.543MB/s
11
	! aes192 (CBC decrypt): 20.76s, 0.482MB/s
12
13
14
15
	! 
	! aes256 (ECB encrypt): 19.12s, 0.523MB/s
	! aes256 (ECB decrypt): 22.57s, 0.443MB/s
	! aes256 (CBC encrypt): 20.92s, 0.478MB/s
16
	! aes256 (CBC decrypt): 23.22s, 0.431MB/s
17

18
19
	! After unrolling key_addition32, and getting rid of
	! some sll x, 2, x, encryption speed is 0.760 MB/s.
20
21
include(`asm.m4')
	
22
	.file	"aes.asm"
23
24
25
26
	.section	".text"
	.align 4
	.type	key_addition_8to32,#function
	.proc	020
27
28
29
! /* Key addition that also packs every byte in the key to a word rep. */
! static void
! key_addition_8to32(const uint8_t *txt, const uint32_t *keys, uint32_t *out)
30
key_addition_8to32:
31
32
33
34
	! %o0:	txt
	! %o1:	keys
	! %o2:	out
	! i:	%o5
35
	mov	0, %o5
36
37
.Liloop: 
	! val:	%o4
38
	mov	0, %o4
39
	! j:	%o3
40
	mov	0, %o3
41
.Lshiftloop:
42
	ldub	[%o0], %g3
43
	! %g2 = j << 3
44
	sll	%o3, 3, %g2
45
	! %g3 << 0
46
47
48
49
	sll	%g3, %g2, %g3
	add	%o3, 1, %o3
	or	%o4, %g3, %o4
	cmp	%o3, 3
50
	bleu	.Lshiftloop
51
	add	%o0, 1, %o0
52
53
	! val in %o4 now

Niels Möller's avatar
Niels Möller committed
54
	! out[i] = keys[i] ^ val;  i++
55
56
57
58
59
	sll	%o5, 2, %g3
	ld	[%o1+%g3], %g2
	add	%o5, 1, %o5
	xor	%g2, %o4, %g2
	cmp	%o5, 3
60
	bleu	.Liloop
61
	st	%g2, [%o2+%g3]
62

63
64
	retl
	nop
65

66
67
! key_addition32(const uint32_t *txt, const uint32_t *keys, uint32_t *out)

68
69
70
71
72
	.size	key_addition_8to32,.LLfe1-key_addition_8to32
	.align 4
	.type	key_addition32,#function
	.proc	020
key_addition32:
Niels Möller's avatar
Niels Möller committed
73
74
75
76
77
	! Unrolled version
	ld	[%o0], %g2
	ld	[%o1], %g3
	xor	%g2, %g3, %g3
	st	%g3, [%o2]
78

Niels Möller's avatar
Niels Möller committed
79
80
	ld	[%o0+4], %g2
	ld	[%o1+4], %g3
81
	xor	%g2, %g3, %g3
Niels Möller's avatar
Niels Möller committed
82
	st	%g3, [%o2+4]
Niels Möller's avatar
Niels Möller committed
83

Niels Möller's avatar
Niels Möller committed
84
85
86
87
	ld	[%o0+8], %g2
	ld	[%o1+8], %g3
	xor	%g2, %g3, %g3
	st	%g3, [%o2+8]
88

Niels Möller's avatar
Niels Möller committed
89
90
91
92
93
	ld	[%o0+12], %g2
	ld	[%o1+12], %g3
	xor	%g2, %g3, %g3
	retl
	st	%g3, [%o2+12]
94

95

96
97
98
99
100
101
102
103
104
105
106
107
108
109
.LLfe2:
	.size	key_addition32,.LLfe2-key_addition32
	.align 4
	.type	key_addition32to8,#function
	.proc	020
key_addition32to8:
	mov	%o0, %o5
	mov	0, %o4
	sll	%o4, 2, %g2
.LL42:
	ld	[%o1+%g2], %o0
	mov	0, %o3
	ld	[%o5+%g2], %g3
	xor	%g3, %o0, %g3
Niels Möller's avatar
Niels Möller committed
110
	! FIXME:	Unroll inner loop
111
112
113
114
.LL37:
	sll	%o3, 3, %g2
	srl	%g3, %g2, %g2
	stb	%g2, [%o2]
Niels Möller's avatar
Niels Möller committed
115

116
117
	add	%o3, 1, %o3
	cmp	%o3, 3
Niels Möller's avatar
Niels Möller committed
118

119
120
	bleu	.LL37
	add	%o2, 1, %o2
Niels Möller's avatar
Niels Möller committed
121

122
123
124
125
	add	%o4, 1, %o4
	cmp	%o4, 3
	bleu	.LL42
	sll	%o4, 2, %g2
Niels Möller's avatar
Niels Möller committed
126

127
128
129
130
131
132
133
134
135
136
	retl
	nop
.LLFE3:
.LLfe3:
	.size	key_addition32to8,.LLfe3-key_addition32to8
	.section	".rodata"
	.align 4
	.type	idx,#object
	.size	idx,64
idx:
137
define(idx_row,
138
139
140
141
<	.long	eval(4 * $1)
	.long	eval(4 * $2)
	.long	eval(4 * $3)
	.long	eval(4 * $4)
142
143
144
145
146
147
>)
idx_row(0, 1, 2, 3)
idx_row(1, 2, 3, 0)
idx_row(2, 3, 0, 1)
idx_row(3, 0, 1, 2)	
	
148
149
150
151
152
	.align 8
.LLC0:
	.asciz	"!(length % 16)"
	.align 8
.LLC1:
Niels Möller's avatar
Niels Möller committed
153
	.asciz	"aes.asm"
154
155
156
157
158
159
160
161
	.align 8
.LLC2:
	.asciz	"aes_encrypt"
	.section	".text"
	.align 4
	.global aes_encrypt
	.type	aes_encrypt,#function
	.proc	020
Niels Möller's avatar
Niels Möller committed
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176

! input parameters
define(ctx,	%i0)
define(length,	%i1)
define(dst,	%i2)
define(src,	%i3)

! locals
define(g_idx, %i5)
	
define(dtbl,	%l1)
define(round,	%l3)
define(txt,	%l5)
define(wtxt,	%l6)

177
178
aes_encrypt:
	save	%sp, -136, %sp
Niels Möller's avatar
Niels Möller committed
179

Niels Möller's avatar
Niels Möller committed
180
	andcc	length, 15, %g0
Niels Möller's avatar
Niels Möller committed
181
	bne	.Lencrypt_fail
Niels Möller's avatar
Niels Möller committed
182
	cmp	length, 0
Niels Möller's avatar
Niels Möller committed
183
	be	.Lencrypt_end
184
	sethi	%hi(idx), %i4
Niels Möller's avatar
Niels Möller committed
185
186
187
	add	%fp, -24, wtxt
	add	%fp, -40, txt
	or	%i4, %lo(idx), g_idx
Niels Möller's avatar
Niels Möller committed
188
.Lencrypt_block:
Niels Möller's avatar
Niels Möller committed
189
190
191
	! key_addition_8to32(src, ctx->keys, wtxt);
	mov	src, %o0
	mov	ctx, %o1
192
	call	key_addition_8to32, 0
Niels Möller's avatar
Niels Möller committed
193
194
195
196
197
198
199
	mov	wtxt, %o2

	! get nrounds
	ld	[ctx+480], %o0
	mov	1, round
	cmp	round, %o0
	bgeu	.Lencrypt_final
200
	sethi	%hi(64512), %o0
Niels Möller's avatar
Niels Möller committed
201

202
	sethi	%hi(_aes_dtbl), %o0
Niels Möller's avatar
Niels Möller committed
203
204
205
206
207
	or	%o0, %lo(_aes_dtbl), dtbl

	mov	txt, %l4
	mov	wtxt, %l0
	! FIXME:	%l7 = idx, seems redundant? 
208
	! or	%i4, %lo(idx), %l7
Niels Möller's avatar
Niels Möller committed
209
210
211
	add	ctx, 16, %l2
.Lencrypt_round:
	! 4j:	%g2
212
	mov	0, %g2
Niels Möller's avatar
Niels Möller committed
213
	! %g3 = &idx[3][0]
214
	add	g_idx, 48, %g3
Niels Möller's avatar
Niels Möller committed
215
216
.Lencrypt_inner:
	! %o0 = idx[3][0]
217
	ld	[%g3], %o0
Niels Möller's avatar
Niels Möller committed
218
	! %o1 = idx[2][0]
219
	ld	[%g3-16], %o1
Niels Möller's avatar
Niels Möller committed
220
	! %o3 = wtxt[idx[3][0]], byte => bits 24-31
221
	ldub	[%l0+%o0], %o3
Niels Möller's avatar
Niels Möller committed
222
	! %o4 = wtxt[idx[2][0]], half-word???
223
224
	lduh	[%l0+%o1], %o4
	sll	%o3, 2, %o3
Niels Möller's avatar
Niels Möller committed
225
	! %o0 = idx[1][0]
226
	ld	[%g3-32], %o0
Niels Möller's avatar
Niels Möller committed
227
	! %o4 = (wtxt[idx[2][0]] >> 16) & 0xff => bits 16-23
228
	and	%o4, 255, %o4
Niels Möller's avatar
Niels Möller committed
229
230
231
	! %o2 = dtbl[wtxt[idx[3][0]] >> 24]
	ld	[dtbl+%o3], %o2
	! %o3 = dtbl[wtxt[idx[3][0]] >> 24] >> 24
232
	srl	%o2, 24, %o3
Niels Möller's avatar
Niels Möller committed
233
	! %o4 = 4 ((wtxt[idx[2][0]] >> 16) & 0xff)
234
	sll	%o4, 2, %o4
Niels Möller's avatar
Niels Möller committed
235
	! %o0 = &wtxt[idx[1][0]]
236
	add	%l0, %o0, %o0
Niels Möller's avatar
Niels Möller committed
237
238
239
	! %o1 = dtbl[(wtxt[idx[2][0]] >> 16) & 0xff]
	ld	[dtbl+%o4], %o1
	! %o2 = dtbl[wtxt[idx[3][0]] >> 24] << 8
240
	sll	%o2, 8, %o2
Niels Möller's avatar
Niels Möller committed
241
	! %o5 = (wtxt[idx[1][0]] >> 8) & 0xff
242
	ldub	[%o0+2], %o5
Niels Möller's avatar
Niels Möller committed
243
	! %o2 = ROL(dtbl[wtxt[idx[3][0]] >> 24])
244
	or	%o2, %o3, %o2
Niels Möller's avatar
Niels Möller committed
245
246
	! %o1 = dtbl[(wtxt[idx[2][0]] >> 16) & 0xff] 
	!       ^ ROL(dtbl[wtxt[idx[3][0]] >> 24])  = XX1
247
	xor	%o1, %o2, %o1
Niels Möller's avatar
Niels Möller committed
248
	! %o3 = XX1 >> 24
249
	srl	%o1, 24, %o3
Niels Möller's avatar
Niels Möller committed
250
	! %o5 = 4 ((wtxt[idx[1][0]] >> 8) & 0xff)
251
	sll	%o5, 2, %o5
Niels Möller's avatar
Niels Möller committed
252
	! %o2 = wtxt[j]
253
	ld	[%l0+%g2], %o2
Niels Möller's avatar
Niels Möller committed
254
	! %o1 = XX1 << 8
255
	sll	%o1, 8, %o1
Niels Möller's avatar
Niels Möller committed
256
257
258
	! %o0 = dtbl[(wtxt[idx[1][0]] >> 8) & 0xff]
	ld	[dtbl+%o5], %o0
	! %o1 = ROL(XX1)
259
	or	%o1, %o3, %o1
Niels Möller's avatar
Niels Möller committed
260
	! %o0 = dtbl[(wtxt[idx[1][0]] >> 8) & 0xff] ^ ROL(XX1) = XX2
261
	xor	%o0, %o1, %o0
Niels Möller's avatar
Niels Möller committed
262
	! %o2 = wtxt[j] & 0xff
263
	and	%o2, 255, %o2
Niels Möller's avatar
Niels Möller committed
264
	! %03 = XX2 >> 24
265
	srl	%o0, 24, %o3
Niels Möller's avatar
Niels Möller committed
266
	! %o2 = 4 (wtxt[j] & 0xff)
267
	sll	%o2, 2, %o2
Niels Möller's avatar
Niels Möller committed
268
269
270
	! %o1 = dtbl[wtxt[j] & 0xff]
	ld	[dtbl+%o2], %o1
	! %o0 = XX2 << 8
271
	sll	%o0, 8, %o0
Niels Möller's avatar
Niels Möller committed
272
	! %o0 = ROL(XX2)
273
	or	%o0, %o3, %o0
Niels Möller's avatar
Niels Möller committed
274
	! %o1 = dtbl[wtxt[j] & 0xff] ^ ROL(XX2 = XX3
275
	xor	%o1, %o0, %o1
Niels Möller's avatar
Niels Möller committed
276
	! txt[j] (old j) = XX3 
277
	st	%o1, [%l4+%g2]
278

Niels Möller's avatar
Niels Möller committed
279
	! j <= 3?
280
281
282
283
	cmp	%g2, 8
	! j++
	add	%g2, 4, %g2
	
Niels Möller's avatar
Niels Möller committed
284
285
	bleu	.Lencrypt_inner
	! %g3 = &idx[3][j]
286
	add	%g3, 4, %g3
Niels Möller's avatar
Niels Möller committed
287
288

	! key_addition32(txt, ctx + 16, wtxt)
289
	mov	%l2, %o1
Niels Möller's avatar
Niels Möller committed
290
	mov	txt, %o0
291
	call	key_addition32, 0
Niels Möller's avatar
Niels Möller committed
292
293
294
295
296
297
298
299
300
301
	mov	wtxt, %o2

	! %o0 = nrounds
	! FIXME:	Keep in some register?
	ld	[ctx+480], %o0
	add	round, 1, round
	cmp	round, %o0
	! round < nrounds?
	blu	.Lencrypt_round
	! %l2 = ctx->keys + r*4 
302
	add	%l2, 16, %l2
Niels Möller's avatar
Niels Möller committed
303
	
304
	sethi	%hi(64512), %o0
Niels Möller's avatar
Niels Möller committed
305
306
.Lencrypt_final:
	! %l3 = 0xff00 ???
307
	or	%o0, 768, %l3
Niels Möller's avatar
Niels Möller committed
308
	! %o7 = j = 0
309
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
310
311
312
	! %g3 = wtxt
	mov	wtxt, %g3
	! %l2 = 0xff0000
313
	sethi	%hi(16711680), %l2
Niels Möller's avatar
Niels Möller committed
314
	! %l1 = 0xff000000
315
	sethi	%hi(-16777216), %l1
Niels Möller's avatar
Niels Möller committed
316
317
318
319
	! %l0 = txt 
	mov	txt, %l0
	! %g2 = &idx[3][0]
	add	g_idx, 48, %g2
320
.Lencrypt_final_inner:
Niels Möller's avatar
Niels Möller committed
321
	! %o0 = idx[1][0]
322
	ld	[%g2-32], %o0
Niels Möller's avatar
Niels Möller committed
323
	! %o5 = 4 j
324
	sll	%o7, 2, %o5
Niels Möller's avatar
Niels Möller committed
325
	! %o2 = idx[2][0]
326
	ld	[%g2-16], %o2
Niels Möller's avatar
Niels Möller committed
327
	! %o3 = wtxt[idx[1][0]]
328
	ld	[%g3+%o0], %o3
Niels Möller's avatar
Niels Möller committed
329
	! %o4 = idx[3][0]
330
	ld	[%g2], %o4
Niels Möller's avatar
Niels Möller committed
331
	! %o3 = wtxt[idx[1][0]] & 0xff00 
332
	and	%o3, %l3, %o3
Niels Möller's avatar
Niels Möller committed
333
	! %o1 = wtxt[idx[2][0]]
334
	ld	[%g3+%o2], %o1
Niels Möller's avatar
Niels Möller committed
335
	! %o0 = wtxt[idx[1][0]]
336
	ld	[%g3+%o5], %o0
Niels Möller's avatar
Niels Möller committed
337
	! %o1 = wtxt[idx[2][0]] & 0xff0000
338
	and	%o1, %l2, %o1
Niels Möller's avatar
Niels Möller committed
339
	! %o2 = wtxt[idx[3][0]]
340
	ld	[%g3+%o4], %o2
Niels Möller's avatar
Niels Möller committed
341
	! %o0 = wtxt[idx[1][0]] & 0xff
342
	and	%o0, 255, %o0
Niels Möller's avatar
Niels Möller committed
343
344
345
346

	! % o0 = wtxt[idx[1][0]] & 0xff
	!        | wtxt[idx[1][0]] & 0xff00
	!        | wtxt[idx[2][0]] & 0xff0000
347
348
	or	%o0, %o3, %o0
	or	%o0, %o1, %o0
Niels Möller's avatar
Niels Möller committed
349
	! %o2 = wtxt[idx[3][0]] & 0xff000000
350
351
	and	%o2, %l1, %o2
	or	%o0, %o2, %o0
Niels Möller's avatar
Niels Möller committed
352
	! j++
353
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
354
	! txt[j] = ... | ... | ... | ... (old j)
355
	st	%o0, [%l0+%o5]
Niels Möller's avatar
Niels Möller committed
356
	! j <= 3?
357
	cmp	%o7, 3
358
	bleu	.Lencrypt_final_inner
Niels Möller's avatar
Niels Möller committed
359
	! %g2 = &idx[3][j]
360
	add	%g2, 4, %g2
Niels Möller's avatar
Niels Möller committed
361
	
362
363
	sethi	%hi(_aes_sbox), %o0
	or	%o0, %lo(_aes_sbox), %g3
Niels Möller's avatar
Niels Möller committed
364
365
	
	! %o7 = j = 0
366
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
367
	! %g2 = txt
368
	mov	%l5, %g2
Niels Möller's avatar
Niels Möller committed
369
370
.Lencrypt_sbox:
	! %o5 = 4 j
371
	sll	%o7, 2, %o5
Niels Möller's avatar
Niels Möller committed
372
	! %o3 = txt[j]
373
	ld	[%g2+%o5], %o3
Niels Möller's avatar
Niels Möller committed
374
	! j++
375
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
376
	! %o0 = (txt[j] >> 8) & 0xff (old j) 
377
378
	srl	%o3, 8, %o0
	and	%o0, 255, %o0
Niels Möller's avatar
Niels Möller committed
379
	! %o4 = sbox[(txt[j] >> 8) & 0xff]
380
	ldub	[%g3+%o0], %o4
Niels Möller's avatar
Niels Möller committed
381
	! %o2 = (txt[j] >> 16) (old j)
382
	srl	%o3, 16, %o2
Niels Möller's avatar
Niels Möller committed
383
	! %o0 = txt[j] & 0xff
384
	and	%o3, 255, %o0
Niels Möller's avatar
Niels Möller committed
385
	! %o1 = sbox[txt[j] & 0xff]
386
	ldub	[%g3+%o0], %o1
Niels Möller's avatar
Niels Möller committed
387
	! %o2 = (txt[j] >> 16) & 0xff (old j)
388
	and	%o2, 255, %o2
Niels Möller's avatar
Niels Möller committed
389
	! %o0 = sbox[(txt[j] >> 16) & 0xff]
390
	ldub	[%g3+%o2], %o0
Niels Möller's avatar
Niels Möller committed
391
	! %o3 = txt[j] >> 24
392
	srl	%o3, 24, %o3
Niels Möller's avatar
Niels Möller committed
393
	! %o4 = sbox[txt[j] & 0xff] << 8
394
	sll	%o4, 8, %o4
Niels Möller's avatar
Niels Möller committed
395
	! %o2 = sbox[txt[j] >> 24]
396
	ldub	[%g3+%o3], %o2
Niels Möller's avatar
Niels Möller committed
397
398
	! %o1 = sbox[txt[j] & 0xff] 
	!	| sbox[(txt[j] >> 8) & 0xff] << 8
399
	or	%o1, %o4, %o1
Niels Möller's avatar
Niels Möller committed
400
	!	| sbox[(txt[j] >> 16) & 0xff] << 16
401
402
	sll	%o0, 16, %o0
	or	%o1, %o0, %o1
Niels Möller's avatar
Niels Möller committed
403
	!	| sbox[txt[j] >> 24] << 24
404
405
	sll	%o2, 24, %o2
	or	%o1, %o2, %o1
Niels Möller's avatar
Niels Möller committed
406
	! j < 3 
407
	cmp	%o7, 3
Niels Möller's avatar
Niels Möller committed
408
409
	bleu	.Lencrypt_sbox
	! txt[j] = ... | ... | ... | ...
410
	st	%o1, [%g2+%o5]
Niels Möller's avatar
Niels Möller committed
411
412
413
414

	! key_addition32to8(txt, ctx + nrounds * 4, dst,
	ld	[ctx+480], %o1
	mov	dst, %o2
415
	sll	%o1, 4, %o1
Niels Möller's avatar
Niels Möller committed
416
	add	ctx, %o1, %o1
417
418
	call	key_addition32to8, 0
	mov	%l5, %o0
Niels Möller's avatar
Niels Möller committed
419
420
421

	add	src, 16, src
	addcc	length, -16, length
Niels Möller's avatar
Niels Möller committed
422
	bne	.Lencrypt_block
Niels Möller's avatar
Niels Möller committed
423
	add	dst, 16, dst
Niels Möller's avatar
Niels Möller committed
424
425
	b,a	.Lencrypt_end
.Lencrypt_fail:
426
427
428
429
430
431
432
433
	sethi	%hi(.LLC0), %o0
	sethi	%hi(.LLC1), %o1
	sethi	%hi(.LLC2), %o3
	or	%o0, %lo(.LLC0), %o0
	or	%o1, %lo(.LLC1), %o1
	or	%o3, %lo(.LLC2), %o3
	call	__assert_fail, 0
	mov	92, %o2
Niels Möller's avatar
Niels Möller committed
434
.Lencrypt_end:
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
.LLBE5:
	ret
	restore
.LLFE4:
.LLfe4:
	.size	aes_encrypt,.LLfe4-aes_encrypt
	.section	".rodata"
	.align 4
	.type	iidx,#object
	.size	iidx,64
iidx:
	.long	0
	.long	1
	.long	2
	.long	3
	.long	3
	.long	0
	.long	1
	.long	2
	.long	2
	.long	3
	.long	0
	.long	1
	.long	1
	.long	2
	.long	3
	.long	0
	.align 8
.LLC3:
	.asciz	"aes_decrypt"
	.section	".text"
	.align 4
	.global aes_decrypt
	.type	aes_decrypt,#function
	.proc	020
aes_decrypt:
.LLFB5:
	!#PROLOGUE# 0
	save	%sp, -136, %sp
.LLCFI1:
	!#PROLOGUE# 1
.LLBB6:
	andcc	%i1, 15, %g0
	bne	.LL111
	cmp	%i1, 0
	be	.LL106
	sethi	%hi(iidx), %i4
	add	%fp, -24, %l6
	add	%fp, -40, %l5
	add	%i0, 240, %i5
.LL84:
	ld	[%i0+480], %o1
	mov	%i3, %o0
	sll	%o1, 4, %o1
	add	%i0, %o1, %o1
	add	%o1, 240, %o1
	call	key_addition_8to32, 0
	mov	%l6, %o2
	ld	[%i0+480], %o0
	addcc	%o0, -1, %l2
	be	.LL107
	sll	%l2, 4, %o1
	add	%o1, %i0, %o1
	sethi	%hi(_aes_itbl), %o0
	or	%o0, %lo(_aes_itbl), %l1
	add	%o1, 240, %l3
	mov	%l5, %l4
	mov	%l6, %l0
	or	%i4, %lo(iidx), %l7
.LL88:
	mov	0, %o7
	add	%l7, 48, %g3
.LL92:
	ld	[%g3], %o0
	sll	%o7, 2, %g2
	ld	[%g3-16], %o1
	sll	%o0, 2, %o0
	ldub	[%l0+%o0], %o3
	sll	%o1, 2, %o1
	lduh	[%l0+%o1], %o4
	sll	%o3, 2, %o3
	ld	[%g3-32], %o0
	and	%o4, 255, %o4
	ld	[%l1+%o3], %o2
	sll	%o0, 2, %o0
	srl	%o2, 24, %o3
	sll	%o4, 2, %o4
	add	%l0, %o0, %o0
	ld	[%l1+%o4], %o1
	sll	%o2, 8, %o2
	ldub	[%o0+2], %o5
	or	%o2, %o3, %o2
	xor	%o1, %o2, %o1
	srl	%o1, 24, %o3
	sll	%o5, 2, %o5
	ld	[%l0+%g2], %o2
	sll	%o1, 8, %o1
	ld	[%l1+%o5], %o0
	or	%o1, %o3, %o1
	xor	%o0, %o1, %o0
	and	%o2, 255, %o2
	srl	%o0, 24, %o3
	sll	%o2, 2, %o2
	ld	[%l1+%o2], %o1
	sll	%o0, 8, %o0
	or	%o0, %o3, %o0
	xor	%o1, %o0, %o1
	add	%o7, 1, %o7
	st	%o1, [%l4+%g2]
	cmp	%o7, 3
	bleu	.LL92
	add	%g3, 4, %g3
	mov	%l3, %o1
	mov	%l5, %o0
	call	key_addition32, 0
	mov	%l6, %o2
	addcc	%l2, -1, %l2
	bne	.LL88
	add	%l3, -16, %l3
.LL107:
	sethi	%hi(64512), %o0
	or	%o0, 768, %l3
	sethi	%hi(iidx), %o0
	or	%o0, %lo(iidx), %o0
	mov	0, %o7
	mov	%l6, %g3
	sethi	%hi(16711680), %l2
	sethi	%hi(-16777216), %l1
	mov	%l5, %l0
	add	%o0, 48, %g2
.LL98:
	ld	[%g2-32], %o0
	sll	%o7, 2, %o5
	ld	[%g2-16], %o2
	sll	%o0, 2, %o0
	ld	[%g3+%o0], %o3
	sll	%o2, 2, %o2
	ld	[%g2], %o4
	and	%o3, %l3, %o3
	ld	[%g3+%o2], %o1
	sll	%o4, 2, %o4
	ld	[%g3+%o5], %o0
	and	%o1, %l2, %o1
	ld	[%g3+%o4], %o2
	and	%o0, 255, %o0
	or	%o0, %o3, %o0
	or	%o0, %o1, %o0
	and	%o2, %l1, %o2
	or	%o0, %o2, %o0
	add	%o7, 1, %o7
	st	%o0, [%l0+%o5]
	cmp	%o7, 3
	bleu	.LL98
	add	%g2, 4, %g2
	sethi	%hi(_aes_isbox), %o0
	or	%o0, %lo(_aes_isbox), %g3
	mov	0, %o7
	mov	%l5, %g2
.LL103:
	sll	%o7, 2, %o5
	ld	[%g2+%o5], %o3
	add	%o7, 1, %o7
	srl	%o3, 8, %o0
	and	%o0, 255, %o0
	ldub	[%g3+%o0], %o4
	srl	%o3, 16, %o2
	and	%o3, 255, %o0
	ldub	[%g3+%o0], %o1
	and	%o2, 255, %o2
	ldub	[%g3+%o2], %o0
	srl	%o3, 24, %o3
	sll	%o4, 8, %o4
	ldub	[%g3+%o3], %o2
	or	%o1, %o4, %o1
	sll	%o0, 16, %o0
	or	%o1, %o0, %o1
	sll	%o2, 24, %o2
	or	%o1, %o2, %o1
	cmp	%o7, 3
	bleu	.LL103
	st	%o1, [%g2+%o5]
	mov	%i2, %o2
	mov	%l5, %o0
	call	key_addition32to8, 0
	mov	%i5, %o1
	add	%i3, 16, %i3
	addcc	%i1, -16, %i1
	bne	.LL84
	add	%i2, 16, %i2
	b,a	.LL106
.LL111:
	sethi	%hi(.LLC0), %o0
	sethi	%hi(.LLC1), %o1
	sethi	%hi(.LLC3), %o3
	or	%o0, %lo(.LLC0), %o0
	or	%o1, %lo(.LLC1), %o1
	or	%o3, %lo(.LLC3), %o3
	call	__assert_fail, 0
	mov	142, %o2
.LL106:
.LLBE6:
	ret
	restore
.LLFE5:
.LLfe5:
	.size	aes_decrypt,.LLfe5-aes_decrypt