aes.asm 11.8 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
	! Benchmarks on my slow sparcstation:	
	! C code	
	! aes128 (ECB encrypt): 14.36s, 0.696MB/s
	! aes128 (ECB decrypt): 17.19s, 0.582MB/s
	! aes128 (CBC encrypt): 16.08s, 0.622MB/s
	! aes128 ((CBC decrypt)): 18.79s, 0.532MB/s
	! 
	! aes192 (ECB encrypt): 16.85s, 0.593MB/s
	! aes192 (ECB decrypt): 19.64s, 0.509MB/s
	! aes192 (CBC encrypt): 18.43s, 0.543MB/s
	! aes192 ((CBC decrypt)): 20.76s, 0.482MB/s
	! 
	! aes256 (ECB encrypt): 19.12s, 0.523MB/s
	! aes256 (ECB decrypt): 22.57s, 0.443MB/s
	! aes256 (CBC encrypt): 20.92s, 0.478MB/s
	! aes256 ((CBC decrypt)): 23.22s, 0.431MB/s

18
19
include(`asm.m4')
	
20
	.file	"aes.asm"
21
22
23
24
	.section	".text"
	.align 4
	.type	key_addition_8to32,#function
	.proc	020
25
26
27
! /* Key addition that also packs every byte in the key to a word rep. */
! static void
! key_addition_8to32(const uint8_t *txt, const uint32_t *keys, uint32_t *out)
28
key_addition_8to32:
29
30
31
32
	! %o0:	txt
	! %o1:	keys
	! %o2:	out
	! i:	%o5
33
	mov	0, %o5
34
35
.Liloop: 
	! val:	%o4
36
	mov	0, %o4
37
	! j:	%o3
38
	mov	0, %o3
39
.Lshiftloop:
40
	ldub	[%o0], %g3
41
	! %g2 = j << 3
42
	sll	%o3, 3, %g2
43
	! %g3 << 0
44
45
46
47
	sll	%g3, %g2, %g3
	add	%o3, 1, %o3
	or	%o4, %g3, %o4
	cmp	%o3, 3
48
	bleu	.Lshiftloop
49
	add	%o0, 1, %o0
50
51
	! val in %o4 now

Niels Möller's avatar
Niels Möller committed
52
	! out[i] = keys[i] ^ val;  i++
53
54
55
56
57
	sll	%o5, 2, %g3
	ld	[%o1+%g3], %g2
	add	%o5, 1, %o5
	xor	%g2, %o4, %g2
	cmp	%o5, 3
58
	bleu	.Liloop
59
	st	%g2, [%o2+%g3]
60

61
62
	retl
	nop
63

64
65
! key_addition32(const uint32_t *txt, const uint32_t *keys, uint32_t *out)

66
67
68
69
70
	.size	key_addition_8to32,.LLfe1-key_addition_8to32
	.align 4
	.type	key_addition32,#function
	.proc	020
key_addition32:
Niels Möller's avatar
Niels Möller committed
71
72
73
74
75
	! Unrolled version
	ld	[%o0], %g2
	ld	[%o1], %g3
	xor	%g2, %g3, %g3
	st	%g3, [%o2]
76

Niels Möller's avatar
Niels Möller committed
77
78
	ld	[%o0+4], %g2
	ld	[%o1+4], %g3
79
	xor	%g2, %g3, %g3
Niels Möller's avatar
Niels Möller committed
80
	st	%g3, [%o2+4]
Niels Möller's avatar
Niels Möller committed
81

Niels Möller's avatar
Niels Möller committed
82
83
84
85
	ld	[%o0+8], %g2
	ld	[%o1+8], %g3
	xor	%g2, %g3, %g3
	st	%g3, [%o2+8]
86

Niels Möller's avatar
Niels Möller committed
87
88
89
90
91
	ld	[%o0+12], %g2
	ld	[%o1+12], %g3
	xor	%g2, %g3, %g3
	retl
	st	%g3, [%o2+12]
92

93

94
95
96
97
98
99
100
101
102
103
104
105
106
107
.LLfe2:
	.size	key_addition32,.LLfe2-key_addition32
	.align 4
	.type	key_addition32to8,#function
	.proc	020
key_addition32to8:
	mov	%o0, %o5
	mov	0, %o4
	sll	%o4, 2, %g2
.LL42:
	ld	[%o1+%g2], %o0
	mov	0, %o3
	ld	[%o5+%g2], %g3
	xor	%g3, %o0, %g3
Niels Möller's avatar
Niels Möller committed
108
	! FIXME:	Unroll inner loop
109
110
111
112
.LL37:
	sll	%o3, 3, %g2
	srl	%g3, %g2, %g2
	stb	%g2, [%o2]
Niels Möller's avatar
Niels Möller committed
113

114
115
	add	%o3, 1, %o3
	cmp	%o3, 3
Niels Möller's avatar
Niels Möller committed
116

117
118
	bleu	.LL37
	add	%o2, 1, %o2
Niels Möller's avatar
Niels Möller committed
119

120
121
122
123
	add	%o4, 1, %o4
	cmp	%o4, 3
	bleu	.LL42
	sll	%o4, 2, %g2
Niels Möller's avatar
Niels Möller committed
124

125
126
127
128
129
130
131
132
133
134
	retl
	nop
.LLFE3:
.LLfe3:
	.size	key_addition32to8,.LLfe3-key_addition32to8
	.section	".rodata"
	.align 4
	.type	idx,#object
	.size	idx,64
idx:
135
136
137
138
139
140
141
142
143
144
145
define(idx_row,
<	.long	$1
	.long	$2
	.long	$3
	.long	$4
>)
idx_row(0, 1, 2, 3)
idx_row(1, 2, 3, 0)
idx_row(2, 3, 0, 1)
idx_row(3, 0, 1, 2)	
	
146
147
148
149
150
	.align 8
.LLC0:
	.asciz	"!(length % 16)"
	.align 8
.LLC1:
Niels Möller's avatar
Niels Möller committed
151
	.asciz	"aes.asm"
152
153
154
155
156
157
158
159
	.align 8
.LLC2:
	.asciz	"aes_encrypt"
	.section	".text"
	.align 4
	.global aes_encrypt
	.type	aes_encrypt,#function
	.proc	020
Niels Möller's avatar
Niels Möller committed
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174

! input parameters
define(ctx,	%i0)
define(length,	%i1)
define(dst,	%i2)
define(src,	%i3)

! locals
define(g_idx, %i5)
	
define(dtbl,	%l1)
define(round,	%l3)
define(txt,	%l5)
define(wtxt,	%l6)

175
176
aes_encrypt:
	save	%sp, -136, %sp
Niels Möller's avatar
Niels Möller committed
177

Niels Möller's avatar
Niels Möller committed
178
	andcc	length, 15, %g0
Niels Möller's avatar
Niels Möller committed
179
	bne	.Lencrypt_fail
Niels Möller's avatar
Niels Möller committed
180
	cmp	length, 0
Niels Möller's avatar
Niels Möller committed
181
	be	.Lencrypt_end
182
	sethi	%hi(idx), %i4
Niels Möller's avatar
Niels Möller committed
183
184
185
	add	%fp, -24, wtxt
	add	%fp, -40, txt
	or	%i4, %lo(idx), g_idx
Niels Möller's avatar
Niels Möller committed
186
.Lencrypt_block:
Niels Möller's avatar
Niels Möller committed
187
188
189
	! key_addition_8to32(src, ctx->keys, wtxt);
	mov	src, %o0
	mov	ctx, %o1
190
	call	key_addition_8to32, 0
Niels Möller's avatar
Niels Möller committed
191
192
193
194
195
196
197
	mov	wtxt, %o2

	! get nrounds
	ld	[ctx+480], %o0
	mov	1, round
	cmp	round, %o0
	bgeu	.Lencrypt_final
198
	sethi	%hi(64512), %o0
Niels Möller's avatar
Niels Möller committed
199

200
	sethi	%hi(_aes_dtbl), %o0
Niels Möller's avatar
Niels Möller committed
201
202
203
204
205
	or	%o0, %lo(_aes_dtbl), dtbl

	mov	txt, %l4
	mov	wtxt, %l0
	! FIXME:	%l7 = idx, seems redundant? 
206
	! or	%i4, %lo(idx), %l7
Niels Möller's avatar
Niels Möller committed
207
208
209
210
	add	ctx, 16, %l2
.Lencrypt_round:
	! j:	%o7
	! 4j:	%g2
211
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
212
	! %g3 = &idx[3][0]
213
	add	g_idx, 48, %g3
Niels Möller's avatar
Niels Möller committed
214
215
.Lencrypt_inner:
	! %o0 = idx[3][0]
216
	ld	[%g3], %o0
Niels Möller's avatar
Niels Möller committed
217
	! %g2 = 4j
218
	sll	%o7, 2, %g2
Niels Möller's avatar
Niels Möller committed
219
	! %o1 = idx[2][0]
220
	ld	[%g3-16], %o1
Niels Möller's avatar
Niels Möller committed
221
	! %o2 = 4 idx[3][0]
222
	sll	%o0, 2, %o0
Niels Möller's avatar
Niels Möller committed
223
	! %o3 = wtxt[idx[3][0]], byte => bits 24-31
224
225
	ldub	[%l0+%o0], %o3
	sll	%o1, 2, %o1
Niels Möller's avatar
Niels Möller committed
226
	! %o4 = wtxt[idx[2][0]], half-word???
227
228
	lduh	[%l0+%o1], %o4
	sll	%o3, 2, %o3
Niels Möller's avatar
Niels Möller committed
229
	! %o0 = idx[1][0]
230
	ld	[%g3-32], %o0
Niels Möller's avatar
Niels Möller committed
231
	! %o4 = (wtxt[idx[2][0]] >> 16) & 0xff => bits 16-23
232
	and	%o4, 255, %o4
Niels Möller's avatar
Niels Möller committed
233
234
235
	! %o2 = dtbl[wtxt[idx[3][0]] >> 24]
	ld	[dtbl+%o3], %o2
	! %o0 = 4 idx[1][0]
236
	sll	%o0, 2, %o0
Niels Möller's avatar
Niels Möller committed
237
	! %o3 = dtbl[wtxt[idx[3][0]] >> 24] >> 24
238
	srl	%o2, 24, %o3
Niels Möller's avatar
Niels Möller committed
239
	! %o4 = 4 ((wtxt[idx[2][0]] >> 16) & 0xff)
240
	sll	%o4, 2, %o4
Niels Möller's avatar
Niels Möller committed
241
	! %o0 = &wtxt[idx[1][0]]
242
	add	%l0, %o0, %o0
Niels Möller's avatar
Niels Möller committed
243
244
245
	! %o1 = dtbl[(wtxt[idx[2][0]] >> 16) & 0xff]
	ld	[dtbl+%o4], %o1
	! %o2 = dtbl[wtxt[idx[3][0]] >> 24] << 8
246
	sll	%o2, 8, %o2
Niels Möller's avatar
Niels Möller committed
247
	! %o5 = (wtxt[idx[1][0]] >> 8) & 0xff
248
	ldub	[%o0+2], %o5
Niels Möller's avatar
Niels Möller committed
249
	! %o2 = ROL(dtbl[wtxt[idx[3][0]] >> 24])
250
	or	%o2, %o3, %o2
Niels Möller's avatar
Niels Möller committed
251
252
	! %o1 = dtbl[(wtxt[idx[2][0]] >> 16) & 0xff] 
	!       ^ ROL(dtbl[wtxt[idx[3][0]] >> 24])  = XX1
253
	xor	%o1, %o2, %o1
Niels Möller's avatar
Niels Möller committed
254
	! %o3 = XX1 >> 24
255
	srl	%o1, 24, %o3
Niels Möller's avatar
Niels Möller committed
256
	! %o5 = 4 ((wtxt[idx[1][0]] >> 8) & 0xff)
257
	sll	%o5, 2, %o5
Niels Möller's avatar
Niels Möller committed
258
	! %o2 = wtxt[j]
259
	ld	[%l0+%g2], %o2
Niels Möller's avatar
Niels Möller committed
260
	! %o1 = XX1 << 8
261
	sll	%o1, 8, %o1
Niels Möller's avatar
Niels Möller committed
262
263
264
	! %o0 = dtbl[(wtxt[idx[1][0]] >> 8) & 0xff]
	ld	[dtbl+%o5], %o0
	! %o1 = ROL(XX1)
265
	or	%o1, %o3, %o1
Niels Möller's avatar
Niels Möller committed
266
	! %o0 = dtbl[(wtxt[idx[1][0]] >> 8) & 0xff] ^ ROL(XX1) = XX2
267
	xor	%o0, %o1, %o0
Niels Möller's avatar
Niels Möller committed
268
	! %o2 = wtxt[j] & 0xff
269
	and	%o2, 255, %o2
Niels Möller's avatar
Niels Möller committed
270
	! %03 = XX2 >> 24
271
	srl	%o0, 24, %o3
Niels Möller's avatar
Niels Möller committed
272
	! %o2 = 4 (wtxt[j] & 0xff)
273
	sll	%o2, 2, %o2
Niels Möller's avatar
Niels Möller committed
274
275
276
	! %o1 = dtbl[wtxt[j] & 0xff]
	ld	[dtbl+%o2], %o1
	! %o0 = XX2 << 8
277
	sll	%o0, 8, %o0
Niels Möller's avatar
Niels Möller committed
278
	! %o0 = ROL(XX2)
279
	or	%o0, %o3, %o0
Niels Möller's avatar
Niels Möller committed
280
	! %o1 = dtbl[wtxt[j] & 0xff] ^ ROL(XX2 = XX3
281
	xor	%o1, %o0, %o1
Niels Möller's avatar
Niels Möller committed
282
	! j++
283
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
284
	! txt[j] (old j) = XX3 
285
	st	%o1, [%l4+%g2]
Niels Möller's avatar
Niels Möller committed
286
	! j <= 3?
287
	cmp	%o7, 3
Niels Möller's avatar
Niels Möller committed
288
289
	bleu	.Lencrypt_inner
	! %g3 = &idx[3][j]
290
	add	%g3, 4, %g3
Niels Möller's avatar
Niels Möller committed
291
292

	! key_addition32(txt, ctx + 16, wtxt)
293
	mov	%l2, %o1
Niels Möller's avatar
Niels Möller committed
294
	mov	txt, %o0
295
	call	key_addition32, 0
Niels Möller's avatar
Niels Möller committed
296
297
298
299
300
301
302
303
304
305
	mov	wtxt, %o2

	! %o0 = nrounds
	! FIXME:	Keep in some register?
	ld	[ctx+480], %o0
	add	round, 1, round
	cmp	round, %o0
	! round < nrounds?
	blu	.Lencrypt_round
	! %l2 = ctx->keys + r*4 
306
	add	%l2, 16, %l2
Niels Möller's avatar
Niels Möller committed
307
	
308
	sethi	%hi(64512), %o0
Niels Möller's avatar
Niels Möller committed
309
310
.Lencrypt_final:
	! %l3 = 0xff00 ???
311
	or	%o0, 768, %l3
Niels Möller's avatar
Niels Möller committed
312
	! %o7 = j = 0
313
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
314
315
316
	! %g3 = wtxt
	mov	wtxt, %g3
	! %l2 = 0xff0000
317
	sethi	%hi(16711680), %l2
Niels Möller's avatar
Niels Möller committed
318
	! %l1 = 0xff000000
319
	sethi	%hi(-16777216), %l1
Niels Möller's avatar
Niels Möller committed
320
321
322
323
	! %l0 = txt 
	mov	txt, %l0
	! %g2 = &idx[3][0]
	add	g_idx, 48, %g2
324
.LL63:
Niels Möller's avatar
Niels Möller committed
325
	! %o0 = idx[1][0]
326
	ld	[%g2-32], %o0
Niels Möller's avatar
Niels Möller committed
327
	! %o5 = 4 j
328
	sll	%o7, 2, %o5
Niels Möller's avatar
Niels Möller committed
329
	! %o2 = idx[2][0]
330
	ld	[%g2-16], %o2
Niels Möller's avatar
Niels Möller committed
331
	! %o0 = 4(idx[1][0])
332
	sll	%o0, 2, %o0
Niels Möller's avatar
Niels Möller committed
333
	! %o3 = wtxt[idx[1][0]]
334
	ld	[%g3+%o0], %o3
Niels Möller's avatar
Niels Möller committed
335
	! %o2 = 4 idx[2][0]
336
	sll	%o2, 2, %o2
Niels Möller's avatar
Niels Möller committed
337
	! %o4 = idx[3][0]
338
	ld	[%g2], %o4
Niels Möller's avatar
Niels Möller committed
339
	! %o3 = wtxt[idx[1][0]] & 0xff00 
340
	and	%o3, %l3, %o3
Niels Möller's avatar
Niels Möller committed
341
	! %o1 = wtxt[idx[2][0]]
342
	ld	[%g3+%o2], %o1
Niels Möller's avatar
Niels Möller committed
343
	! %o4 = 4 idx[3][0]
344
	sll	%o4, 2, %o4
Niels Möller's avatar
Niels Möller committed
345
	! %o0 = wtxt[idx[1][0]]
346
	ld	[%g3+%o5], %o0
Niels Möller's avatar
Niels Möller committed
347
	! %o1 = wtxt[idx[2][0]] & 0xff0000
348
	and	%o1, %l2, %o1
Niels Möller's avatar
Niels Möller committed
349
	! %o2 = wtxt[idx[3][0]]
350
	ld	[%g3+%o4], %o2
Niels Möller's avatar
Niels Möller committed
351
	! %o0 = wtxt[idx[1][0]] & 0xff
352
	and	%o0, 255, %o0
Niels Möller's avatar
Niels Möller committed
353
354
355
356

	! % o0 = wtxt[idx[1][0]] & 0xff
	!        | wtxt[idx[1][0]] & 0xff00
	!        | wtxt[idx[2][0]] & 0xff0000
357
358
	or	%o0, %o3, %o0
	or	%o0, %o1, %o0
Niels Möller's avatar
Niels Möller committed
359
	! %o2 = wtxt[idx[3][0]] & 0xff000000
360
361
	and	%o2, %l1, %o2
	or	%o0, %o2, %o0
Niels Möller's avatar
Niels Möller committed
362
	! j++
363
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
364
	! txt[j] = ... | ... | ... | ... (old j)
365
	st	%o0, [%l0+%o5]
Niels Möller's avatar
Niels Möller committed
366
	! j <= 3?
367
368
	cmp	%o7, 3
	bleu	.LL63
Niels Möller's avatar
Niels Möller committed
369
	! %g2 = &idx[3][j]
370
	add	%g2, 4, %g2
Niels Möller's avatar
Niels Möller committed
371
	
372
373
	sethi	%hi(_aes_sbox), %o0
	or	%o0, %lo(_aes_sbox), %g3
Niels Möller's avatar
Niels Möller committed
374
375
	
	! %o7 = j = 0
376
	mov	0, %o7
Niels Möller's avatar
Niels Möller committed
377
	! %g2 = txt
378
	mov	%l5, %g2
Niels Möller's avatar
Niels Möller committed
379
380
.Lencrypt_sbox:
	! %o5 = 4 j
381
	sll	%o7, 2, %o5
Niels Möller's avatar
Niels Möller committed
382
	! %o3 = txt[j]
383
	ld	[%g2+%o5], %o3
Niels Möller's avatar
Niels Möller committed
384
	! j++
385
	add	%o7, 1, %o7
Niels Möller's avatar
Niels Möller committed
386
	! %o0 = (txt[j] >> 8) & 0xff (old j) 
387
388
	srl	%o3, 8, %o0
	and	%o0, 255, %o0
Niels Möller's avatar
Niels Möller committed
389
	! %o4 = sbox[(txt[j] >> 8) & 0xff]
390
	ldub	[%g3+%o0], %o4
Niels Möller's avatar
Niels Möller committed
391
	! %o2 = (txt[j] >> 16) (old j)
392
	srl	%o3, 16, %o2
Niels Möller's avatar
Niels Möller committed
393
	! %o0 = txt[j] & 0xff
394
	and	%o3, 255, %o0
Niels Möller's avatar
Niels Möller committed
395
	! %o1 = sbox[txt[j] & 0xff]
396
	ldub	[%g3+%o0], %o1
Niels Möller's avatar
Niels Möller committed
397
	! %o2 = (txt[j] >> 16) & 0xff (old j)
398
	and	%o2, 255, %o2
Niels Möller's avatar
Niels Möller committed
399
	! %o0 = sbox[(txt[j] >> 16) & 0xff]
400
	ldub	[%g3+%o2], %o0
Niels Möller's avatar
Niels Möller committed
401
	! %o3 = txt[j] >> 24
402
	srl	%o3, 24, %o3
Niels Möller's avatar
Niels Möller committed
403
	! %o4 = sbox[txt[j] & 0xff] << 8
404
	sll	%o4, 8, %o4
Niels Möller's avatar
Niels Möller committed
405
	! %o2 = sbox[txt[j] >> 24]
406
	ldub	[%g3+%o3], %o2
Niels Möller's avatar
Niels Möller committed
407
408
	! %o1 = sbox[txt[j] & 0xff] 
	!	| sbox[(txt[j] >> 8) & 0xff] << 8
409
	or	%o1, %o4, %o1
Niels Möller's avatar
Niels Möller committed
410
	!	| sbox[(txt[j] >> 16) & 0xff] << 16
411
412
	sll	%o0, 16, %o0
	or	%o1, %o0, %o1
Niels Möller's avatar
Niels Möller committed
413
	!	| sbox[txt[j] >> 24] << 24
414
415
	sll	%o2, 24, %o2
	or	%o1, %o2, %o1
Niels Möller's avatar
Niels Möller committed
416
	! j < 3 
417
	cmp	%o7, 3
Niels Möller's avatar
Niels Möller committed
418
419
	bleu	.Lencrypt_sbox
	! txt[j] = ... | ... | ... | ...
420
	st	%o1, [%g2+%o5]
Niels Möller's avatar
Niels Möller committed
421
422
423
424

	! key_addition32to8(txt, ctx + nrounds * 4, dst,
	ld	[ctx+480], %o1
	mov	dst, %o2
425
	sll	%o1, 4, %o1
Niels Möller's avatar
Niels Möller committed
426
	add	ctx, %o1, %o1
427
428
	call	key_addition32to8, 0
	mov	%l5, %o0
Niels Möller's avatar
Niels Möller committed
429
430
431

	add	src, 16, src
	addcc	length, -16, length
Niels Möller's avatar
Niels Möller committed
432
	bne	.Lencrypt_block
Niels Möller's avatar
Niels Möller committed
433
	add	dst, 16, dst
Niels Möller's avatar
Niels Möller committed
434
435
	b,a	.Lencrypt_end
.Lencrypt_fail:
436
437
438
439
440
441
442
443
	sethi	%hi(.LLC0), %o0
	sethi	%hi(.LLC1), %o1
	sethi	%hi(.LLC2), %o3
	or	%o0, %lo(.LLC0), %o0
	or	%o1, %lo(.LLC1), %o1
	or	%o3, %lo(.LLC2), %o3
	call	__assert_fail, 0
	mov	92, %o2
Niels Möller's avatar
Niels Möller committed
444
.Lencrypt_end:
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
.LLBE5:
	ret
	restore
.LLFE4:
.LLfe4:
	.size	aes_encrypt,.LLfe4-aes_encrypt
	.section	".rodata"
	.align 4
	.type	iidx,#object
	.size	iidx,64
iidx:
	.long	0
	.long	1
	.long	2
	.long	3
	.long	3
	.long	0
	.long	1
	.long	2
	.long	2
	.long	3
	.long	0
	.long	1
	.long	1
	.long	2
	.long	3
	.long	0
	.align 8
.LLC3:
	.asciz	"aes_decrypt"
	.section	".text"
	.align 4
	.global aes_decrypt
	.type	aes_decrypt,#function
	.proc	020
aes_decrypt:
.LLFB5:
	!#PROLOGUE# 0
	save	%sp, -136, %sp
.LLCFI1:
	!#PROLOGUE# 1
.LLBB6:
	andcc	%i1, 15, %g0
	bne	.LL111
	cmp	%i1, 0
	be	.LL106
	sethi	%hi(iidx), %i4
	add	%fp, -24, %l6
	add	%fp, -40, %l5
	add	%i0, 240, %i5
.LL84:
	ld	[%i0+480], %o1
	mov	%i3, %o0
	sll	%o1, 4, %o1
	add	%i0, %o1, %o1
	add	%o1, 240, %o1
	call	key_addition_8to32, 0
	mov	%l6, %o2
	ld	[%i0+480], %o0
	addcc	%o0, -1, %l2
	be	.LL107
	sll	%l2, 4, %o1
	add	%o1, %i0, %o1
	sethi	%hi(_aes_itbl), %o0
	or	%o0, %lo(_aes_itbl), %l1
	add	%o1, 240, %l3
	mov	%l5, %l4
	mov	%l6, %l0
	or	%i4, %lo(iidx), %l7
.LL88:
	mov	0, %o7
	add	%l7, 48, %g3
.LL92:
	ld	[%g3], %o0
	sll	%o7, 2, %g2
	ld	[%g3-16], %o1
	sll	%o0, 2, %o0
	ldub	[%l0+%o0], %o3
	sll	%o1, 2, %o1
	lduh	[%l0+%o1], %o4
	sll	%o3, 2, %o3
	ld	[%g3-32], %o0
	and	%o4, 255, %o4
	ld	[%l1+%o3], %o2
	sll	%o0, 2, %o0
	srl	%o2, 24, %o3
	sll	%o4, 2, %o4
	add	%l0, %o0, %o0
	ld	[%l1+%o4], %o1
	sll	%o2, 8, %o2
	ldub	[%o0+2], %o5
	or	%o2, %o3, %o2
	xor	%o1, %o2, %o1
	srl	%o1, 24, %o3
	sll	%o5, 2, %o5
	ld	[%l0+%g2], %o2
	sll	%o1, 8, %o1
	ld	[%l1+%o5], %o0
	or	%o1, %o3, %o1
	xor	%o0, %o1, %o0
	and	%o2, 255, %o2
	srl	%o0, 24, %o3
	sll	%o2, 2, %o2
	ld	[%l1+%o2], %o1
	sll	%o0, 8, %o0
	or	%o0, %o3, %o0
	xor	%o1, %o0, %o1
	add	%o7, 1, %o7
	st	%o1, [%l4+%g2]
	cmp	%o7, 3
	bleu	.LL92
	add	%g3, 4, %g3
	mov	%l3, %o1
	mov	%l5, %o0
	call	key_addition32, 0
	mov	%l6, %o2
	addcc	%l2, -1, %l2
	bne	.LL88
	add	%l3, -16, %l3
.LL107:
	sethi	%hi(64512), %o0
	or	%o0, 768, %l3
	sethi	%hi(iidx), %o0
	or	%o0, %lo(iidx), %o0
	mov	0, %o7
	mov	%l6, %g3
	sethi	%hi(16711680), %l2
	sethi	%hi(-16777216), %l1
	mov	%l5, %l0
	add	%o0, 48, %g2
.LL98:
	ld	[%g2-32], %o0
	sll	%o7, 2, %o5
	ld	[%g2-16], %o2
	sll	%o0, 2, %o0
	ld	[%g3+%o0], %o3
	sll	%o2, 2, %o2
	ld	[%g2], %o4
	and	%o3, %l3, %o3
	ld	[%g3+%o2], %o1
	sll	%o4, 2, %o4
	ld	[%g3+%o5], %o0
	and	%o1, %l2, %o1
	ld	[%g3+%o4], %o2
	and	%o0, 255, %o0
	or	%o0, %o3, %o0
	or	%o0, %o1, %o0
	and	%o2, %l1, %o2
	or	%o0, %o2, %o0
	add	%o7, 1, %o7
	st	%o0, [%l0+%o5]
	cmp	%o7, 3
	bleu	.LL98
	add	%g2, 4, %g2
	sethi	%hi(_aes_isbox), %o0
	or	%o0, %lo(_aes_isbox), %g3
	mov	0, %o7
	mov	%l5, %g2
.LL103:
	sll	%o7, 2, %o5
	ld	[%g2+%o5], %o3
	add	%o7, 1, %o7
	srl	%o3, 8, %o0
	and	%o0, 255, %o0
	ldub	[%g3+%o0], %o4
	srl	%o3, 16, %o2
	and	%o3, 255, %o0
	ldub	[%g3+%o0], %o1
	and	%o2, 255, %o2
	ldub	[%g3+%o2], %o0
	srl	%o3, 24, %o3
	sll	%o4, 8, %o4
	ldub	[%g3+%o3], %o2
	or	%o1, %o4, %o1
	sll	%o0, 16, %o0
	or	%o1, %o0, %o1
	sll	%o2, 24, %o2
	or	%o1, %o2, %o1
	cmp	%o7, 3
	bleu	.LL103
	st	%o1, [%g2+%o5]
	mov	%i2, %o2
	mov	%l5, %o0
	call	key_addition32to8, 0
	mov	%i5, %o1
	add	%i3, 16, %i3
	addcc	%i1, -16, %i1
	bne	.LL84
	add	%i2, 16, %i2
	b,a	.LL106
.LL111:
	sethi	%hi(.LLC0), %o0
	sethi	%hi(.LLC1), %o1
	sethi	%hi(.LLC3), %o3
	or	%o0, %lo(.LLC0), %o0
	or	%o1, %lo(.LLC1), %o1
	or	%o3, %lo(.LLC3), %o3
	call	__assert_fail, 0
	mov	142, %o2
.LL106:
.LLBE6:
	ret
	restore
.LLFE5:
.LLfe5:
	.size	aes_decrypt,.LLfe5-aes_decrypt