aes.asm 11.6 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
	! Benchmarks on my slow sparcstation:	
	! C code	
	! aes128 (ECB encrypt): 14.36s, 0.696MB/s
	! aes128 (ECB decrypt): 17.19s, 0.582MB/s
	! aes128 (CBC encrypt): 16.08s, 0.622MB/s
	! aes128 ((CBC decrypt)): 18.79s, 0.532MB/s
	! 
	! aes192 (ECB encrypt): 16.85s, 0.593MB/s
	! aes192 (ECB decrypt): 19.64s, 0.509MB/s
	! aes192 (CBC encrypt): 18.43s, 0.543MB/s
	! aes192 ((CBC decrypt)): 20.76s, 0.482MB/s
	! 
	! aes256 (ECB encrypt): 19.12s, 0.523MB/s
	! aes256 (ECB decrypt): 22.57s, 0.443MB/s
	! aes256 (CBC encrypt): 20.92s, 0.478MB/s
	! aes256 ((CBC decrypt)): 23.22s, 0.431MB/s

18
19
include(`asm.m4')
	
20
	.file	"aes.asm"
21
22
23
24
	.section	".text"
	.align 4
	.type	key_addition_8to32,#function
	.proc	020
25
26
27
! /* Key addition that also packs every byte in the key to a word rep. */
! static void
! key_addition_8to32(const uint8_t *txt, const uint32_t *keys, uint32_t *out)
28
key_addition_8to32:
29
30
31
32
	! %o0:	txt
	! %o1:	keys
	! %o2:	out
	! i:	%o5
33
	mov	0, %o5
34
35
.Liloop: 
	! val:	%o4
36
	mov	0, %o4
37
	! j:	%o3
38
	mov	0, %o3
39
.Lshiftloop:
40
	ldub	[%o0], %g3
41
	! %g2 = j << 3
42
	sll	%o3, 3, %g2
43
	! %g3 << 0
44
45
46
47
	sll	%g3, %g2, %g3
	add	%o3, 1, %o3
	or	%o4, %g3, %o4
	cmp	%o3, 3
48
	bleu	.Lshiftloop
49
	add	%o0, 1, %o0
50
51
	! val in %o4 now

Niels Möller's avatar
Niels Möller committed
52
	! out[i] = keys[i] ^ val;  i++
53
54
55
56
57
	sll	%o5, 2, %g3
	ld	[%o1+%g3], %g2
	add	%o5, 1, %o5
	xor	%g2, %o4, %g2
	cmp	%o5, 3
58
	bleu	.Liloop
59
	st	%g2, [%o2+%g3]
60

61
62
	retl
	nop
63

64
65
! key_addition32(const uint32_t *txt, const uint32_t *keys, uint32_t *out)

66
67
68
69
70
	.size	key_addition_8to32,.LLfe1-key_addition_8to32
	.align 4
	.type	key_addition32,#function
	.proc	020
key_addition32:
Niels Möller's avatar
Niels Möller committed
71
72
73
74
75
	! Unrolled version
	ld	[%o0], %g2
	ld	[%o1], %g3
	xor	%g2, %g3, %g3
	st	%g3, [%o2]
76

Niels Möller's avatar
Niels Möller committed
77
78
	ld	[%o0+4], %g2
	ld	[%o1+4], %g3
79
	xor	%g2, %g3, %g3
Niels Möller's avatar
Niels Möller committed
80
	st	%g3, [%o2+4]
Niels Möller's avatar
Niels Möller committed
81

Niels Möller's avatar
Niels Möller committed
82
83
84
85
	ld	[%o0+8], %g2
	ld	[%o1+8], %g3
	xor	%g2, %g3, %g3
	st	%g3, [%o2+8]
86

Niels Möller's avatar
Niels Möller committed
87
88
89
90
91
	ld	[%o0+12], %g2
	ld	[%o1+12], %g3
	xor	%g2, %g3, %g3
	retl
	st	%g3, [%o2+12]
92

93

94
95
96
97
98
99
100
101
102
103
104
105
106
107
.LLfe2:
	.size	key_addition32,.LLfe2-key_addition32
	.align 4
	.type	key_addition32to8,#function
	.proc	020
key_addition32to8:
	mov	%o0, %o5
	mov	0, %o4
	sll	%o4, 2, %g2
.LL42:
	ld	[%o1+%g2], %o0
	mov	0, %o3
	ld	[%o5+%g2], %g3
	xor	%g3, %o0, %g3
Niels Möller's avatar
Niels Möller committed
108
	! FIXME:	Unroll inner loop
109
110
111
112
.LL37:
	sll	%o3, 3, %g2
	srl	%g3, %g2, %g2
	stb	%g2, [%o2]
Niels Möller's avatar
Niels Möller committed
113

114
115
	add	%o3, 1, %o3
	cmp	%o3, 3
Niels Möller's avatar
Niels Möller committed
116

117
118
	bleu	.LL37
	add	%o2, 1, %o2
Niels Möller's avatar
Niels Möller committed
119

120
121
122
123
	add	%o4, 1, %o4
	cmp	%o4, 3
	bleu	.LL42
	sll	%o4, 2, %g2
Niels Möller's avatar
Niels Möller committed
124

125
126
127
128
129
130
131
132
133
134
	retl
	nop
.LLFE3:
.LLfe3:
	.size	key_addition32to8,.LLfe3-key_addition32to8
	.section	".rodata"
	.align 4
	.type	idx,#object
	.size	idx,64
idx:
135
define(idx_row,
136
137
138
139
<	.long	eval(4 * $1)
	.long	eval(4 * $2)
	.long	eval(4 * $3)
	.long	eval(4 * $4)
140
141
142
143
144
145
>)
idx_row(0, 1, 2, 3)
idx_row(1, 2, 3, 0)
idx_row(2, 3, 0, 1)
idx_row(3, 0, 1, 2)	
	
146
147
148
149
150
	.align 8
.LLC0:
	.asciz	"!(length % 16)"
	.align 8
.LLC1:
Niels Möller's avatar
Niels Möller committed
151
	.asciz	"aes.asm"
152
153
154
155
156
157
158
159
	.align 8
.LLC2:
	.asciz	"aes_encrypt"
	.section	".text"
	.align 4
	.global aes_encrypt
	.type	aes_encrypt,#function
	.proc	020
Niels Möller's avatar
Niels Möller committed
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174

! input parameters
define(ctx,	%i0)
define(length,	%i1)
define(dst,	%i2)
define(src,	%i3)

! locals
define(g_idx, %i5)
	
define(dtbl,	%l1)
define(round,	%l3)
define(txt,	%l5)
define(wtxt,	%l6)

175
176
aes_encrypt:
	save	%sp, -136, %sp
Niels Möller's avatar
Niels Möller committed
177

Niels Möller's avatar
Niels Möller committed
178
	andcc	length, 15, %g0
Niels Möller's avatar
Niels Möller committed
179
	bne	.Lencrypt_fail
Niels Möller's avatar
Niels Möller committed
180
	cmp	length, 0
Niels Möller's avatar
Niels Möller committed
181
	be	.Lencrypt_end
182
	sethi	%hi(idx), %i4
Niels Möller's avatar
Niels Möller committed
183
184
185
	add	%fp, -24, wtxt
	add	%fp, -40, txt
	or	%i4, %lo(idx), g_idx
Niels Möller's avatar
Niels Möller committed
186
.Lencrypt_block:
Niels Möller's avatar
Niels Möller committed
187
188
189
	! key_addition_8to32(src, ctx->keys, wtxt);
	mov	src, %o0
	mov	ctx, %o1
190
	call	key_addition_8to32, 0
Niels Möller's avatar
Niels Möller committed
191
192
193
194
195
196
197
	mov	wtxt, %o2

	! get nrounds
	ld	[ctx+480], %o0
	mov	1, round
	cmp	round, %o0
	bgeu	.Lencrypt_final
198
	sethi	%hi(64512), %o0
Niels Möller's avatar
Niels Möller committed
199

200
	sethi	%hi(_aes_dtbl), %o0
Niels Möller's avatar
Niels Möller committed
201
202
203
204
205
	or	%o0, %lo(_aes_dtbl), dtbl

	mov	txt, %l4
	mov	wtxt, %l0
	! FIXME:	%l7 = idx, seems redundant? 
206
	! or	%i4, %lo(idx), %l7
Niels Möller's avatar
Niels Möller committed
207
208
209
210
	add	ctx, 16, %l2
.Lencrypt_round:
	! j:	%o7
	! 4j:	%g2
211
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
212
	! %g3 = &idx[3][0]
213
	add	g_idx, 48, %g3
Niels Möller's avatar
Niels Möller committed
214
215
.Lencrypt_inner:
	! %o0 = idx[3][0]
216
	ld	[%g3], %o0
Niels Möller's avatar
Niels Möller committed
217
	! %g2 = 4j
218
	sll	%o7, 2, %g2
Niels Möller's avatar
Niels Möller committed
219
	! %o1 = idx[2][0]
220
	ld	[%g3-16], %o1
Niels Möller's avatar
Niels Möller committed
221
	! %o3 = wtxt[idx[3][0]], byte => bits 24-31
222
	ldub	[%l0+%o0], %o3
Niels Möller's avatar
Niels Möller committed
223
	! %o4 = wtxt[idx[2][0]], half-word???
224
225
	lduh	[%l0+%o1], %o4
	sll	%o3, 2, %o3
Niels Möller's avatar
Niels Möller committed
226
	! %o0 = idx[1][0]
227
	ld	[%g3-32], %o0
Niels Möller's avatar
Niels Möller committed
228
	! %o4 = (wtxt[idx[2][0]] >> 16) & 0xff => bits 16-23
229
	and	%o4, 255, %o4
Niels Möller's avatar
Niels Möller committed
230
231
232
	! %o2 = dtbl[wtxt[idx[3][0]] >> 24]
	ld	[dtbl+%o3], %o2
	! %o3 = dtbl[wtxt[idx[3][0]] >> 24] >> 24
233
	srl	%o2, 24, %o3
Niels Möller's avatar
Niels Möller committed
234
	! %o4 = 4 ((wtxt[idx[2][0]] >> 16) & 0xff)
235
	sll	%o4, 2, %o4
Niels Möller's avatar
Niels Möller committed
236
	! %o0 = &wtxt[idx[1][0]]
237
	add	%l0, %o0, %o0
Niels Möller's avatar
Niels Möller committed
238
239
240
	! %o1 = dtbl[(wtxt[idx[2][0]] >> 16) & 0xff]
	ld	[dtbl+%o4], %o1
	! %o2 = dtbl[wtxt[idx[3][0]] >> 24] << 8
241
	sll	%o2, 8, %o2
Niels Möller's avatar
Niels Möller committed
242
	! %o5 = (wtxt[idx[1][0]] >> 8) & 0xff
243
	ldub	[%o0+2], %o5
Niels Möller's avatar
Niels Möller committed
244
	! %o2 = ROL(dtbl[wtxt[idx[3][0]] >> 24])
245
	or	%o2, %o3, %o2
Niels Möller's avatar
Niels Möller committed
246
247
	! %o1 = dtbl[(wtxt[idx[2][0]] >> 16) & 0xff] 
	!       ^ ROL(dtbl[wtxt[idx[3][0]] >> 24])  = XX1
248
	xor	%o1, %o2, %o1
Niels Möller's avatar
Niels Möller committed
249
	! %o3 = XX1 >> 24
250
	srl	%o1, 24, %o3
Niels Möller's avatar
Niels Möller committed
251
	! %o5 = 4 ((wtxt[idx[1][0]] >> 8) & 0xff)
252
	sll	%o5, 2, %o5
Niels Möller's avatar
Niels Möller committed
253
	! %o2 = wtxt[j]
254
	ld	[%l0+%g2], %o2
Niels Möller's avatar
Niels Möller committed
255
	! %o1 = XX1 << 8
256
	sll	%o1, 8, %o1
Niels Möller's avatar
Niels Möller committed
257
258
259
	! %o0 = dtbl[(wtxt[idx[1][0]] >> 8) & 0xff]
	ld	[dtbl+%o5], %o0
	! %o1 = ROL(XX1)
260
	or	%o1, %o3, %o1
Niels Möller's avatar
Niels Möller committed
261
	! %o0 = dtbl[(wtxt[idx[1][0]] >> 8) & 0xff] ^ ROL(XX1) = XX2
262
	xor	%o0, %o1, %o0
Niels Möller's avatar
Niels Möller committed
263
	! %o2 = wtxt[j] & 0xff
264
	and	%o2, 255, %o2
Niels Möller's avatar
Niels Möller committed
265
	! %03 = XX2 >> 24
266
	srl	%o0, 24, %o3
Niels Möller's avatar
Niels Möller committed
267
	! %o2 = 4 (wtxt[j] & 0xff)
268
	sll	%o2, 2, %o2
Niels Möller's avatar
Niels Möller committed
269
270
271
	! %o1 = dtbl[wtxt[j] & 0xff]
	ld	[dtbl+%o2], %o1
	! %o0 = XX2 << 8
272
	sll	%o0, 8, %o0
Niels Möller's avatar
Niels Möller committed
273
	! %o0 = ROL(XX2)
274
	or	%o0, %o3, %o0
Niels Möller's avatar
Niels Möller committed
275
	! %o1 = dtbl[wtxt[j] & 0xff] ^ ROL(XX2 = XX3
276
	xor	%o1, %o0, %o1
Niels Möller's avatar
Niels Möller committed
277
	! j++
278
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
279
	! txt[j] (old j) = XX3 
280
	st	%o1, [%l4+%g2]
281

Niels Möller's avatar
Niels Möller committed
282
	! j <= 3?
283
	cmp	%o7, 3
284

Niels Möller's avatar
Niels Möller committed
285
286
	bleu	.Lencrypt_inner
	! %g3 = &idx[3][j]
287
	add	%g3, 4, %g3
Niels Möller's avatar
Niels Möller committed
288
289

	! key_addition32(txt, ctx + 16, wtxt)
290
	mov	%l2, %o1
Niels Möller's avatar
Niels Möller committed
291
	mov	txt, %o0
292
	call	key_addition32, 0
Niels Möller's avatar
Niels Möller committed
293
294
295
296
297
298
299
300
301
302
	mov	wtxt, %o2

	! %o0 = nrounds
	! FIXME:	Keep in some register?
	ld	[ctx+480], %o0
	add	round, 1, round
	cmp	round, %o0
	! round < nrounds?
	blu	.Lencrypt_round
	! %l2 = ctx->keys + r*4 
303
	add	%l2, 16, %l2
Niels Möller's avatar
Niels Möller committed
304
	
305
	sethi	%hi(64512), %o0
Niels Möller's avatar
Niels Möller committed
306
307
.Lencrypt_final:
	! %l3 = 0xff00 ???
308
	or	%o0, 768, %l3
Niels Möller's avatar
Niels Möller committed
309
	! %o7 = j = 0
310
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
311
312
313
	! %g3 = wtxt
	mov	wtxt, %g3
	! %l2 = 0xff0000
314
	sethi	%hi(16711680), %l2
Niels Möller's avatar
Niels Möller committed
315
	! %l1 = 0xff000000
316
	sethi	%hi(-16777216), %l1
Niels Möller's avatar
Niels Möller committed
317
318
319
320
	! %l0 = txt 
	mov	txt, %l0
	! %g2 = &idx[3][0]
	add	g_idx, 48, %g2
321
.Lencrypt_final_inner:
Niels Möller's avatar
Niels Möller committed
322
	! %o0 = idx[1][0]
323
	ld	[%g2-32], %o0
Niels Möller's avatar
Niels Möller committed
324
	! %o5 = 4 j
325
	sll	%o7, 2, %o5
Niels Möller's avatar
Niels Möller committed
326
	! %o2 = idx[2][0]
327
	ld	[%g2-16], %o2
Niels Möller's avatar
Niels Möller committed
328
	! %o3 = wtxt[idx[1][0]]
329
	ld	[%g3+%o0], %o3
Niels Möller's avatar
Niels Möller committed
330
	! %o4 = idx[3][0]
331
	ld	[%g2], %o4
Niels Möller's avatar
Niels Möller committed
332
	! %o3 = wtxt[idx[1][0]] & 0xff00 
333
	and	%o3, %l3, %o3
Niels Möller's avatar
Niels Möller committed
334
	! %o1 = wtxt[idx[2][0]]
335
	ld	[%g3+%o2], %o1
Niels Möller's avatar
Niels Möller committed
336
	! %o0 = wtxt[idx[1][0]]
337
	ld	[%g3+%o5], %o0
Niels Möller's avatar
Niels Möller committed
338
	! %o1 = wtxt[idx[2][0]] & 0xff0000
339
	and	%o1, %l2, %o1
Niels Möller's avatar
Niels Möller committed
340
	! %o2 = wtxt[idx[3][0]]
341
	ld	[%g3+%o4], %o2
Niels Möller's avatar
Niels Möller committed
342
	! %o0 = wtxt[idx[1][0]] & 0xff
343
	and	%o0, 255, %o0
Niels Möller's avatar
Niels Möller committed
344
345
346
347

	! % o0 = wtxt[idx[1][0]] & 0xff
	!        | wtxt[idx[1][0]] & 0xff00
	!        | wtxt[idx[2][0]] & 0xff0000
348
349
	or	%o0, %o3, %o0
	or	%o0, %o1, %o0
Niels Möller's avatar
Niels Möller committed
350
	! %o2 = wtxt[idx[3][0]] & 0xff000000
351
352
	and	%o2, %l1, %o2
	or	%o0, %o2, %o0
Niels Möller's avatar
Niels Möller committed
353
	! j++
354
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
355
	! txt[j] = ... | ... | ... | ... (old j)
356
	st	%o0, [%l0+%o5]
Niels Möller's avatar
Niels Möller committed
357
	! j <= 3?
358
	cmp	%o7, 3
359
	bleu	.Lencrypt_final_inner
Niels Möller's avatar
Niels Möller committed
360
	! %g2 = &idx[3][j]
361
	add	%g2, 4, %g2
Niels Möller's avatar
Niels Möller committed
362
	
363
364
	sethi	%hi(_aes_sbox), %o0
	or	%o0, %lo(_aes_sbox), %g3
Niels Möller's avatar
Niels Möller committed
365
366
	
	! %o7 = j = 0
367
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
368
	! %g2 = txt
369
	mov	%l5, %g2
Niels Möller's avatar
Niels Möller committed
370
371
.Lencrypt_sbox:
	! %o5 = 4 j
372
	sll	%o7, 2, %o5
Niels Möller's avatar
Niels Möller committed
373
	! %o3 = txt[j]
374
	ld	[%g2+%o5], %o3
Niels Möller's avatar
Niels Möller committed
375
	! j++
376
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
377
	! %o0 = (txt[j] >> 8) & 0xff (old j) 
378
379
	srl	%o3, 8, %o0
	and	%o0, 255, %o0
Niels Möller's avatar
Niels Möller committed
380
	! %o4 = sbox[(txt[j] >> 8) & 0xff]
381
	ldub	[%g3+%o0], %o4
Niels Möller's avatar
Niels Möller committed
382
	! %o2 = (txt[j] >> 16) (old j)
383
	srl	%o3, 16, %o2
Niels Möller's avatar
Niels Möller committed
384
	! %o0 = txt[j] & 0xff
385
	and	%o3, 255, %o0
Niels Möller's avatar
Niels Möller committed
386
	! %o1 = sbox[txt[j] & 0xff]
387
	ldub	[%g3+%o0], %o1
Niels Möller's avatar
Niels Möller committed
388
	! %o2 = (txt[j] >> 16) & 0xff (old j)
389
	and	%o2, 255, %o2
Niels Möller's avatar
Niels Möller committed
390
	! %o0 = sbox[(txt[j] >> 16) & 0xff]
391
	ldub	[%g3+%o2], %o0
Niels Möller's avatar
Niels Möller committed
392
	! %o3 = txt[j] >> 24
393
	srl	%o3, 24, %o3
Niels Möller's avatar
Niels Möller committed
394
	! %o4 = sbox[txt[j] & 0xff] << 8
395
	sll	%o4, 8, %o4
Niels Möller's avatar
Niels Möller committed
396
	! %o2 = sbox[txt[j] >> 24]
397
	ldub	[%g3+%o3], %o2
Niels Möller's avatar
Niels Möller committed
398
399
	! %o1 = sbox[txt[j] & 0xff] 
	!	| sbox[(txt[j] >> 8) & 0xff] << 8
400
	or	%o1, %o4, %o1
Niels Möller's avatar
Niels Möller committed
401
	!	| sbox[(txt[j] >> 16) & 0xff] << 16
402
403
	sll	%o0, 16, %o0
	or	%o1, %o0, %o1
Niels Möller's avatar
Niels Möller committed
404
	!	| sbox[txt[j] >> 24] << 24
405
406
	sll	%o2, 24, %o2
	or	%o1, %o2, %o1
Niels Möller's avatar
Niels Möller committed
407
	! j < 3 
408
	cmp	%o7, 3
Niels Möller's avatar
Niels Möller committed
409
410
	bleu	.Lencrypt_sbox
	! txt[j] = ... | ... | ... | ...
411
	st	%o1, [%g2+%o5]
Niels Möller's avatar
Niels Möller committed
412
413
414
415

	! key_addition32to8(txt, ctx + nrounds * 4, dst,
	ld	[ctx+480], %o1
	mov	dst, %o2
416
	sll	%o1, 4, %o1
Niels Möller's avatar
Niels Möller committed
417
	add	ctx, %o1, %o1
418
419
	call	key_addition32to8, 0
	mov	%l5, %o0
Niels Möller's avatar
Niels Möller committed
420
421
422

	add	src, 16, src
	addcc	length, -16, length
Niels Möller's avatar
Niels Möller committed
423
	bne	.Lencrypt_block
Niels Möller's avatar
Niels Möller committed
424
	add	dst, 16, dst
Niels Möller's avatar
Niels Möller committed
425
426
	b,a	.Lencrypt_end
.Lencrypt_fail:
427
428
429
430
431
432
433
434
	sethi	%hi(.LLC0), %o0
	sethi	%hi(.LLC1), %o1
	sethi	%hi(.LLC2), %o3
	or	%o0, %lo(.LLC0), %o0
	or	%o1, %lo(.LLC1), %o1
	or	%o3, %lo(.LLC2), %o3
	call	__assert_fail, 0
	mov	92, %o2
Niels Möller's avatar
Niels Möller committed
435
.Lencrypt_end:
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
.LLBE5:
	ret
	restore
.LLFE4:
.LLfe4:
	.size	aes_encrypt,.LLfe4-aes_encrypt
	.section	".rodata"
	.align 4
	.type	iidx,#object
	.size	iidx,64
iidx:
	.long	0
	.long	1
	.long	2
	.long	3
	.long	3
	.long	0
	.long	1
	.long	2
	.long	2
	.long	3
	.long	0
	.long	1
	.long	1
	.long	2
	.long	3
	.long	0
	.align 8
.LLC3:
	.asciz	"aes_decrypt"
	.section	".text"
	.align 4
	.global aes_decrypt
	.type	aes_decrypt,#function
	.proc	020
aes_decrypt:
.LLFB5:
	!#PROLOGUE# 0
	save	%sp, -136, %sp
.LLCFI1:
	!#PROLOGUE# 1
.LLBB6:
	andcc	%i1, 15, %g0
	bne	.LL111
	cmp	%i1, 0
	be	.LL106
	sethi	%hi(iidx), %i4
	add	%fp, -24, %l6
	add	%fp, -40, %l5
	add	%i0, 240, %i5
.LL84:
	ld	[%i0+480], %o1
	mov	%i3, %o0
	sll	%o1, 4, %o1
	add	%i0, %o1, %o1
	add	%o1, 240, %o1
	call	key_addition_8to32, 0
	mov	%l6, %o2
	ld	[%i0+480], %o0
	addcc	%o0, -1, %l2
	be	.LL107
	sll	%l2, 4, %o1
	add	%o1, %i0, %o1
	sethi	%hi(_aes_itbl), %o0
	or	%o0, %lo(_aes_itbl), %l1
	add	%o1, 240, %l3
	mov	%l5, %l4
	mov	%l6, %l0
	or	%i4, %lo(iidx), %l7
.LL88:
	mov	0, %o7
	add	%l7, 48, %g3
.LL92:
	ld	[%g3], %o0
	sll	%o7, 2, %g2
	ld	[%g3-16], %o1
	sll	%o0, 2, %o0
	ldub	[%l0+%o0], %o3
	sll	%o1, 2, %o1
	lduh	[%l0+%o1], %o4
	sll	%o3, 2, %o3
	ld	[%g3-32], %o0
	and	%o4, 255, %o4
	ld	[%l1+%o3], %o2
	sll	%o0, 2, %o0
	srl	%o2, 24, %o3
	sll	%o4, 2, %o4
	add	%l0, %o0, %o0
	ld	[%l1+%o4], %o1
	sll	%o2, 8, %o2
	ldub	[%o0+2], %o5
	or	%o2, %o3, %o2
	xor	%o1, %o2, %o1
	srl	%o1, 24, %o3
	sll	%o5, 2, %o5
	ld	[%l0+%g2], %o2
	sll	%o1, 8, %o1
	ld	[%l1+%o5], %o0
	or	%o1, %o3, %o1
	xor	%o0, %o1, %o0
	and	%o2, 255, %o2
	srl	%o0, 24, %o3
	sll	%o2, 2, %o2
	ld	[%l1+%o2], %o1
	sll	%o0, 8, %o0
	or	%o0, %o3, %o0
	xor	%o1, %o0, %o1
	add	%o7, 1, %o7
	st	%o1, [%l4+%g2]
	cmp	%o7, 3
	bleu	.LL92
	add	%g3, 4, %g3
	mov	%l3, %o1
	mov	%l5, %o0
	call	key_addition32, 0
	mov	%l6, %o2
	addcc	%l2, -1, %l2
	bne	.LL88
	add	%l3, -16, %l3
.LL107:
	sethi	%hi(64512), %o0
	or	%o0, 768, %l3
	sethi	%hi(iidx), %o0
	or	%o0, %lo(iidx), %o0
	mov	0, %o7
	mov	%l6, %g3
	sethi	%hi(16711680), %l2
	sethi	%hi(-16777216), %l1
	mov	%l5, %l0
	add	%o0, 48, %g2
.LL98:
	ld	[%g2-32], %o0
	sll	%o7, 2, %o5
	ld	[%g2-16], %o2
	sll	%o0, 2, %o0
	ld	[%g3+%o0], %o3
	sll	%o2, 2, %o2
	ld	[%g2], %o4
	and	%o3, %l3, %o3
	ld	[%g3+%o2], %o1
	sll	%o4, 2, %o4
	ld	[%g3+%o5], %o0
	and	%o1, %l2, %o1
	ld	[%g3+%o4], %o2
	and	%o0, 255, %o0
	or	%o0, %o3, %o0
	or	%o0, %o1, %o0
	and	%o2, %l1, %o2
	or	%o0, %o2, %o0
	add	%o7, 1, %o7
	st	%o0, [%l0+%o5]
	cmp	%o7, 3
	bleu	.LL98
	add	%g2, 4, %g2
	sethi	%hi(_aes_isbox), %o0
	or	%o0, %lo(_aes_isbox), %g3
	mov	0, %o7
	mov	%l5, %g2
.LL103:
	sll	%o7, 2, %o5
	ld	[%g2+%o5], %o3
	add	%o7, 1, %o7
	srl	%o3, 8, %o0
	and	%o0, 255, %o0
	ldub	[%g3+%o0], %o4
	srl	%o3, 16, %o2
	and	%o3, 255, %o0
	ldub	[%g3+%o0], %o1
	and	%o2, 255, %o2
	ldub	[%g3+%o2], %o0
	srl	%o3, 24, %o3
	sll	%o4, 8, %o4
	ldub	[%g3+%o3], %o2
	or	%o1, %o4, %o1
	sll	%o0, 16, %o0
	or	%o1, %o0, %o1
	sll	%o2, 24, %o2
	or	%o1, %o2, %o1
	cmp	%o7, 3
	bleu	.LL103
	st	%o1, [%g2+%o5]
	mov	%i2, %o2
	mov	%l5, %o0
	call	key_addition32to8, 0
	mov	%i5, %o1
	add	%i3, 16, %i3
	addcc	%i1, -16, %i1
	bne	.LL84
	add	%i2, 16, %i2
	b,a	.LL106
.LL111:
	sethi	%hi(.LLC0), %o0
	sethi	%hi(.LLC1), %o1
	sethi	%hi(.LLC3), %o3
	or	%o0, %lo(.LLC0), %o0
	or	%o1, %lo(.LLC1), %o1
	or	%o3, %lo(.LLC3), %o3
	call	__assert_fail, 0
	mov	142, %o2
.LL106:
.LLBE6:
	ret
	restore
.LLFE5:
.LLfe5:
	.size	aes_decrypt,.LLfe5-aes_decrypt