af_alg: Pacify --enable-gcc-warnings
[gnulib.git] / lib / sha512.c
blob852c43495057502a0d344e0206d7091bcf7fe3c4
1 /* sha512.c - Functions to compute SHA512 and SHA384 message digest of files or
2 memory blocks according to the NIST specification FIPS-180-2.
4 Copyright (C) 2005-2006, 2008-2018 Free Software Foundation, Inc.
6 This program is free software: you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation, either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <https://www.gnu.org/licenses/>. */
19 /* Written by David Madore, considerably copypasting from
20 Scott G. Miller's sha1.c
23 #include <config.h>
25 #if HAVE_OPENSSL_SHA512
26 # define GL_OPENSSL_INLINE _GL_EXTERN_INLINE
27 #endif
28 #include "sha512.h"
30 #include <stdalign.h>
31 #include <stdint.h>
32 #include <stdlib.h>
33 #include <string.h>
35 #include "af_alg.h"
37 #if USE_UNLOCKED_IO
38 # include "unlocked-io.h"
39 #endif
41 #ifdef WORDS_BIGENDIAN
42 # define SWAP(n) (n)
43 #else
44 # define SWAP(n) \
45 u64or (u64or (u64or (u64shl (n, 56), \
46 u64shl (u64and (n, u64lo (0x0000ff00)), 40)), \
47 u64or (u64shl (u64and (n, u64lo (0x00ff0000)), 24), \
48 u64shl (u64and (n, u64lo (0xff000000)), 8))), \
49 u64or (u64or (u64and (u64shr (n, 8), u64lo (0xff000000)), \
50 u64and (u64shr (n, 24), u64lo (0x00ff0000))), \
51 u64or (u64and (u64shr (n, 40), u64lo (0x0000ff00)), \
52 u64shr (n, 56))))
53 #endif
55 #define BLOCKSIZE 32768
56 #if BLOCKSIZE % 128 != 0
57 # error "invalid BLOCKSIZE"
58 #endif
60 #if ! HAVE_OPENSSL_SHA512
61 /* This array contains the bytes used to pad the buffer to the next
62 128-byte boundary. */
63 static const unsigned char fillbuf[128] = { 0x80, 0 /* , 0, 0, ... */ };
67 Takes a pointer to a 512 bit block of data (eight 64 bit ints) and
68 initializes it to the start constants of the SHA512 algorithm. This
69 must be called before using hash in the call to sha512_hash
71 void
72 sha512_init_ctx (struct sha512_ctx *ctx)
74 ctx->state[0] = u64hilo (0x6a09e667, 0xf3bcc908);
75 ctx->state[1] = u64hilo (0xbb67ae85, 0x84caa73b);
76 ctx->state[2] = u64hilo (0x3c6ef372, 0xfe94f82b);
77 ctx->state[3] = u64hilo (0xa54ff53a, 0x5f1d36f1);
78 ctx->state[4] = u64hilo (0x510e527f, 0xade682d1);
79 ctx->state[5] = u64hilo (0x9b05688c, 0x2b3e6c1f);
80 ctx->state[6] = u64hilo (0x1f83d9ab, 0xfb41bd6b);
81 ctx->state[7] = u64hilo (0x5be0cd19, 0x137e2179);
83 ctx->total[0] = ctx->total[1] = u64lo (0);
84 ctx->buflen = 0;
87 void
88 sha384_init_ctx (struct sha512_ctx *ctx)
90 ctx->state[0] = u64hilo (0xcbbb9d5d, 0xc1059ed8);
91 ctx->state[1] = u64hilo (0x629a292a, 0x367cd507);
92 ctx->state[2] = u64hilo (0x9159015a, 0x3070dd17);
93 ctx->state[3] = u64hilo (0x152fecd8, 0xf70e5939);
94 ctx->state[4] = u64hilo (0x67332667, 0xffc00b31);
95 ctx->state[5] = u64hilo (0x8eb44a87, 0x68581511);
96 ctx->state[6] = u64hilo (0xdb0c2e0d, 0x64f98fa7);
97 ctx->state[7] = u64hilo (0x47b5481d, 0xbefa4fa4);
99 ctx->total[0] = ctx->total[1] = u64lo (0);
100 ctx->buflen = 0;
103 /* Copy the value from V into the memory location pointed to by *CP,
104 If your architecture allows unaligned access, this is equivalent to
105 * (__typeof__ (v) *) cp = v */
106 static void
107 set_uint64 (char *cp, u64 v)
109 memcpy (cp, &v, sizeof v);
112 /* Put result from CTX in first 64 bytes following RESBUF.
113 The result must be in little endian byte order. */
114 void *
115 sha512_read_ctx (const struct sha512_ctx *ctx, void *resbuf)
117 int i;
118 char *r = resbuf;
120 for (i = 0; i < 8; i++)
121 set_uint64 (r + i * sizeof ctx->state[0], SWAP (ctx->state[i]));
123 return resbuf;
126 void *
127 sha384_read_ctx (const struct sha512_ctx *ctx, void *resbuf)
129 int i;
130 char *r = resbuf;
132 for (i = 0; i < 6; i++)
133 set_uint64 (r + i * sizeof ctx->state[0], SWAP (ctx->state[i]));
135 return resbuf;
138 /* Process the remaining bytes in the internal buffer and the usual
139 prolog according to the standard and write the result to RESBUF. */
140 static void
141 sha512_conclude_ctx (struct sha512_ctx *ctx)
143 /* Take yet unprocessed bytes into account. */
144 size_t bytes = ctx->buflen;
145 size_t size = (bytes < 112) ? 128 / 8 : 128 * 2 / 8;
147 /* Now count remaining bytes. */
148 ctx->total[0] = u64plus (ctx->total[0], u64lo (bytes));
149 if (u64lt (ctx->total[0], u64lo (bytes)))
150 ctx->total[1] = u64plus (ctx->total[1], u64lo (1));
152 /* Put the 128-bit file length in *bits* at the end of the buffer.
153 Use set_uint64 rather than a simple assignment, to avoid risk of
154 unaligned access. */
155 set_uint64 ((char *) &ctx->buffer[size - 2],
156 SWAP (u64or (u64shl (ctx->total[1], 3),
157 u64shr (ctx->total[0], 61))));
158 set_uint64 ((char *) &ctx->buffer[size - 1],
159 SWAP (u64shl (ctx->total[0], 3)));
161 memcpy (&((char *) ctx->buffer)[bytes], fillbuf, (size - 2) * 8 - bytes);
163 /* Process last bytes. */
164 sha512_process_block (ctx->buffer, size * 8, ctx);
167 void *
168 sha512_finish_ctx (struct sha512_ctx *ctx, void *resbuf)
170 sha512_conclude_ctx (ctx);
171 return sha512_read_ctx (ctx, resbuf);
174 void *
175 sha384_finish_ctx (struct sha512_ctx *ctx, void *resbuf)
177 sha512_conclude_ctx (ctx);
178 return sha384_read_ctx (ctx, resbuf);
180 #endif
182 /* Compute message digest for bytes read from STREAM using algorithm ALG.
183 Write the message digest into RESBLOCK, which contains HASHLEN bytes.
184 The initial and finishing operations are INIT_CTX and FINISH_CTX.
185 Return zero if and only if successful. */
186 static int
187 shaxxx_stream (FILE *stream, char const *alg, void *resblock,
188 ssize_t hashlen, void (*init_ctx) (struct sha512_ctx *),
189 void *(*finish_ctx) (struct sha512_ctx *, void *))
191 switch (afalg_stream (stream, alg, resblock, hashlen))
193 case 0: return 0;
194 case -EIO: return 1;
197 char *buffer = malloc (BLOCKSIZE + 72);
198 if (!buffer)
199 return 1;
201 struct sha512_ctx ctx;
202 init_ctx (&ctx);
203 size_t sum;
205 /* Iterate over full file contents. */
206 while (1)
208 /* We read the file in blocks of BLOCKSIZE bytes. One call of the
209 computation function processes the whole buffer so that with the
210 next round of the loop another block can be read. */
211 size_t n;
212 sum = 0;
214 /* Read block. Take care for partial reads. */
215 while (1)
217 n = fread (buffer + sum, 1, BLOCKSIZE - sum, stream);
219 sum += n;
221 if (sum == BLOCKSIZE)
222 break;
224 if (n == 0)
226 /* Check for the error flag IFF N == 0, so that we don't
227 exit the loop after a partial read due to e.g., EAGAIN
228 or EWOULDBLOCK. */
229 if (ferror (stream))
231 free (buffer);
232 return 1;
234 goto process_partial_block;
237 /* We've read at least one byte, so ignore errors. But always
238 check for EOF, since feof may be true even though N > 0.
239 Otherwise, we could end up calling fread after EOF. */
240 if (feof (stream))
241 goto process_partial_block;
244 /* Process buffer with BLOCKSIZE bytes. Note that
245 BLOCKSIZE % 128 == 0
247 sha512_process_block (buffer, BLOCKSIZE, &ctx);
250 process_partial_block:;
252 /* Process any remaining bytes. */
253 if (sum > 0)
254 sha512_process_bytes (buffer, sum, &ctx);
256 /* Construct result in desired memory. */
257 finish_ctx (&ctx, resblock);
258 free (buffer);
259 return 0;
263 sha512_stream (FILE *stream, void *resblock)
265 return shaxxx_stream (stream, "sha512", resblock, SHA512_DIGEST_SIZE,
266 sha512_init_ctx, sha512_finish_ctx);
270 sha384_stream (FILE *stream, void *resblock)
272 return shaxxx_stream (stream, "sha384", resblock, SHA384_DIGEST_SIZE,
273 sha384_init_ctx, sha384_finish_ctx);
276 #if ! HAVE_OPENSSL_SHA512
277 /* Compute SHA512 message digest for LEN bytes beginning at BUFFER. The
278 result is always in little endian byte order, so that a byte-wise
279 output yields to the wanted ASCII representation of the message
280 digest. */
281 void *
282 sha512_buffer (const char *buffer, size_t len, void *resblock)
284 struct sha512_ctx ctx;
286 /* Initialize the computation context. */
287 sha512_init_ctx (&ctx);
289 /* Process whole buffer but last len % 128 bytes. */
290 sha512_process_bytes (buffer, len, &ctx);
292 /* Put result in desired memory area. */
293 return sha512_finish_ctx (&ctx, resblock);
296 void *
297 sha384_buffer (const char *buffer, size_t len, void *resblock)
299 struct sha512_ctx ctx;
301 /* Initialize the computation context. */
302 sha384_init_ctx (&ctx);
304 /* Process whole buffer but last len % 128 bytes. */
305 sha512_process_bytes (buffer, len, &ctx);
307 /* Put result in desired memory area. */
308 return sha384_finish_ctx (&ctx, resblock);
311 void
312 sha512_process_bytes (const void *buffer, size_t len, struct sha512_ctx *ctx)
314 /* When we already have some bits in our internal buffer concatenate
315 both inputs first. */
316 if (ctx->buflen != 0)
318 size_t left_over = ctx->buflen;
319 size_t add = 256 - left_over > len ? len : 256 - left_over;
321 memcpy (&((char *) ctx->buffer)[left_over], buffer, add);
322 ctx->buflen += add;
324 if (ctx->buflen > 128)
326 sha512_process_block (ctx->buffer, ctx->buflen & ~127, ctx);
328 ctx->buflen &= 127;
329 /* The regions in the following copy operation cannot overlap,
330 because ctx->buflen < 128 ≤ (left_over + add) & ~127. */
331 memcpy (ctx->buffer,
332 &((char *) ctx->buffer)[(left_over + add) & ~127],
333 ctx->buflen);
336 buffer = (const char *) buffer + add;
337 len -= add;
340 /* Process available complete blocks. */
341 if (len >= 128)
343 #if !(_STRING_ARCH_unaligned || _STRING_INLINE_unaligned)
344 # define UNALIGNED_P(p) ((uintptr_t) (p) % alignof (u64) != 0)
345 if (UNALIGNED_P (buffer))
346 while (len > 128)
348 sha512_process_block (memcpy (ctx->buffer, buffer, 128), 128, ctx);
349 buffer = (const char *) buffer + 128;
350 len -= 128;
352 else
353 #endif
355 sha512_process_block (buffer, len & ~127, ctx);
356 buffer = (const char *) buffer + (len & ~127);
357 len &= 127;
361 /* Move remaining bytes in internal buffer. */
362 if (len > 0)
364 size_t left_over = ctx->buflen;
366 memcpy (&((char *) ctx->buffer)[left_over], buffer, len);
367 left_over += len;
368 if (left_over >= 128)
370 sha512_process_block (ctx->buffer, 128, ctx);
371 left_over -= 128;
372 /* The regions in the following copy operation cannot overlap,
373 because left_over ≤ 128. */
374 memcpy (ctx->buffer, &ctx->buffer[16], left_over);
376 ctx->buflen = left_over;
380 /* --- Code below is the primary difference between sha1.c and sha512.c --- */
382 /* SHA512 round constants */
383 #define K(I) sha512_round_constants[I]
384 static u64 const sha512_round_constants[80] = {
385 u64init (0x428a2f98, 0xd728ae22), u64init (0x71374491, 0x23ef65cd),
386 u64init (0xb5c0fbcf, 0xec4d3b2f), u64init (0xe9b5dba5, 0x8189dbbc),
387 u64init (0x3956c25b, 0xf348b538), u64init (0x59f111f1, 0xb605d019),
388 u64init (0x923f82a4, 0xaf194f9b), u64init (0xab1c5ed5, 0xda6d8118),
389 u64init (0xd807aa98, 0xa3030242), u64init (0x12835b01, 0x45706fbe),
390 u64init (0x243185be, 0x4ee4b28c), u64init (0x550c7dc3, 0xd5ffb4e2),
391 u64init (0x72be5d74, 0xf27b896f), u64init (0x80deb1fe, 0x3b1696b1),
392 u64init (0x9bdc06a7, 0x25c71235), u64init (0xc19bf174, 0xcf692694),
393 u64init (0xe49b69c1, 0x9ef14ad2), u64init (0xefbe4786, 0x384f25e3),
394 u64init (0x0fc19dc6, 0x8b8cd5b5), u64init (0x240ca1cc, 0x77ac9c65),
395 u64init (0x2de92c6f, 0x592b0275), u64init (0x4a7484aa, 0x6ea6e483),
396 u64init (0x5cb0a9dc, 0xbd41fbd4), u64init (0x76f988da, 0x831153b5),
397 u64init (0x983e5152, 0xee66dfab), u64init (0xa831c66d, 0x2db43210),
398 u64init (0xb00327c8, 0x98fb213f), u64init (0xbf597fc7, 0xbeef0ee4),
399 u64init (0xc6e00bf3, 0x3da88fc2), u64init (0xd5a79147, 0x930aa725),
400 u64init (0x06ca6351, 0xe003826f), u64init (0x14292967, 0x0a0e6e70),
401 u64init (0x27b70a85, 0x46d22ffc), u64init (0x2e1b2138, 0x5c26c926),
402 u64init (0x4d2c6dfc, 0x5ac42aed), u64init (0x53380d13, 0x9d95b3df),
403 u64init (0x650a7354, 0x8baf63de), u64init (0x766a0abb, 0x3c77b2a8),
404 u64init (0x81c2c92e, 0x47edaee6), u64init (0x92722c85, 0x1482353b),
405 u64init (0xa2bfe8a1, 0x4cf10364), u64init (0xa81a664b, 0xbc423001),
406 u64init (0xc24b8b70, 0xd0f89791), u64init (0xc76c51a3, 0x0654be30),
407 u64init (0xd192e819, 0xd6ef5218), u64init (0xd6990624, 0x5565a910),
408 u64init (0xf40e3585, 0x5771202a), u64init (0x106aa070, 0x32bbd1b8),
409 u64init (0x19a4c116, 0xb8d2d0c8), u64init (0x1e376c08, 0x5141ab53),
410 u64init (0x2748774c, 0xdf8eeb99), u64init (0x34b0bcb5, 0xe19b48a8),
411 u64init (0x391c0cb3, 0xc5c95a63), u64init (0x4ed8aa4a, 0xe3418acb),
412 u64init (0x5b9cca4f, 0x7763e373), u64init (0x682e6ff3, 0xd6b2b8a3),
413 u64init (0x748f82ee, 0x5defb2fc), u64init (0x78a5636f, 0x43172f60),
414 u64init (0x84c87814, 0xa1f0ab72), u64init (0x8cc70208, 0x1a6439ec),
415 u64init (0x90befffa, 0x23631e28), u64init (0xa4506ceb, 0xde82bde9),
416 u64init (0xbef9a3f7, 0xb2c67915), u64init (0xc67178f2, 0xe372532b),
417 u64init (0xca273ece, 0xea26619c), u64init (0xd186b8c7, 0x21c0c207),
418 u64init (0xeada7dd6, 0xcde0eb1e), u64init (0xf57d4f7f, 0xee6ed178),
419 u64init (0x06f067aa, 0x72176fba), u64init (0x0a637dc5, 0xa2c898a6),
420 u64init (0x113f9804, 0xbef90dae), u64init (0x1b710b35, 0x131c471b),
421 u64init (0x28db77f5, 0x23047d84), u64init (0x32caab7b, 0x40c72493),
422 u64init (0x3c9ebe0a, 0x15c9bebc), u64init (0x431d67c4, 0x9c100d4c),
423 u64init (0x4cc5d4be, 0xcb3e42b6), u64init (0x597f299c, 0xfc657e2a),
424 u64init (0x5fcb6fab, 0x3ad6faec), u64init (0x6c44198c, 0x4a475817),
427 /* Round functions. */
428 #define F2(A, B, C) u64or (u64and (A, B), u64and (C, u64or (A, B)))
429 #define F1(E, F, G) u64xor (G, u64and (E, u64xor (F, G)))
431 /* Process LEN bytes of BUFFER, accumulating context into CTX.
432 It is assumed that LEN % 128 == 0.
433 Most of this code comes from GnuPG's cipher/sha1.c. */
435 void
436 sha512_process_block (const void *buffer, size_t len, struct sha512_ctx *ctx)
438 u64 const *words = buffer;
439 u64 const *endp = words + len / sizeof (u64);
440 u64 x[16];
441 u64 a = ctx->state[0];
442 u64 b = ctx->state[1];
443 u64 c = ctx->state[2];
444 u64 d = ctx->state[3];
445 u64 e = ctx->state[4];
446 u64 f = ctx->state[5];
447 u64 g = ctx->state[6];
448 u64 h = ctx->state[7];
449 u64 lolen = u64size (len);
451 /* First increment the byte count. FIPS PUB 180-2 specifies the possible
452 length of the file up to 2^128 bits. Here we only compute the
453 number of bytes. Do a double word increment. */
454 ctx->total[0] = u64plus (ctx->total[0], lolen);
455 ctx->total[1] = u64plus (ctx->total[1],
456 u64plus (u64size (len >> 31 >> 31 >> 2),
457 u64lo (u64lt (ctx->total[0], lolen))));
459 #define S0(x) u64xor (u64rol(x, 63), u64xor (u64rol (x, 56), u64shr (x, 7)))
460 #define S1(x) u64xor (u64rol (x, 45), u64xor (u64rol (x, 3), u64shr (x, 6)))
461 #define SS0(x) u64xor (u64rol (x, 36), u64xor (u64rol (x, 30), u64rol (x, 25)))
462 #define SS1(x) u64xor (u64rol(x, 50), u64xor (u64rol (x, 46), u64rol (x, 23)))
464 #define M(I) (x[(I) & 15] \
465 = u64plus (x[(I) & 15], \
466 u64plus (S1 (x[((I) - 2) & 15]), \
467 u64plus (x[((I) - 7) & 15], \
468 S0 (x[((I) - 15) & 15])))))
470 #define R(A, B, C, D, E, F, G, H, K, M) \
471 do \
473 u64 t0 = u64plus (SS0 (A), F2 (A, B, C)); \
474 u64 t1 = \
475 u64plus (H, u64plus (SS1 (E), \
476 u64plus (F1 (E, F, G), u64plus (K, M)))); \
477 D = u64plus (D, t1); \
478 H = u64plus (t0, t1); \
480 while (0)
482 while (words < endp)
484 int t;
485 /* FIXME: see sha1.c for a better implementation. */
486 for (t = 0; t < 16; t++)
488 x[t] = SWAP (*words);
489 words++;
492 R( a, b, c, d, e, f, g, h, K( 0), x[ 0] );
493 R( h, a, b, c, d, e, f, g, K( 1), x[ 1] );
494 R( g, h, a, b, c, d, e, f, K( 2), x[ 2] );
495 R( f, g, h, a, b, c, d, e, K( 3), x[ 3] );
496 R( e, f, g, h, a, b, c, d, K( 4), x[ 4] );
497 R( d, e, f, g, h, a, b, c, K( 5), x[ 5] );
498 R( c, d, e, f, g, h, a, b, K( 6), x[ 6] );
499 R( b, c, d, e, f, g, h, a, K( 7), x[ 7] );
500 R( a, b, c, d, e, f, g, h, K( 8), x[ 8] );
501 R( h, a, b, c, d, e, f, g, K( 9), x[ 9] );
502 R( g, h, a, b, c, d, e, f, K(10), x[10] );
503 R( f, g, h, a, b, c, d, e, K(11), x[11] );
504 R( e, f, g, h, a, b, c, d, K(12), x[12] );
505 R( d, e, f, g, h, a, b, c, K(13), x[13] );
506 R( c, d, e, f, g, h, a, b, K(14), x[14] );
507 R( b, c, d, e, f, g, h, a, K(15), x[15] );
508 R( a, b, c, d, e, f, g, h, K(16), M(16) );
509 R( h, a, b, c, d, e, f, g, K(17), M(17) );
510 R( g, h, a, b, c, d, e, f, K(18), M(18) );
511 R( f, g, h, a, b, c, d, e, K(19), M(19) );
512 R( e, f, g, h, a, b, c, d, K(20), M(20) );
513 R( d, e, f, g, h, a, b, c, K(21), M(21) );
514 R( c, d, e, f, g, h, a, b, K(22), M(22) );
515 R( b, c, d, e, f, g, h, a, K(23), M(23) );
516 R( a, b, c, d, e, f, g, h, K(24), M(24) );
517 R( h, a, b, c, d, e, f, g, K(25), M(25) );
518 R( g, h, a, b, c, d, e, f, K(26), M(26) );
519 R( f, g, h, a, b, c, d, e, K(27), M(27) );
520 R( e, f, g, h, a, b, c, d, K(28), M(28) );
521 R( d, e, f, g, h, a, b, c, K(29), M(29) );
522 R( c, d, e, f, g, h, a, b, K(30), M(30) );
523 R( b, c, d, e, f, g, h, a, K(31), M(31) );
524 R( a, b, c, d, e, f, g, h, K(32), M(32) );
525 R( h, a, b, c, d, e, f, g, K(33), M(33) );
526 R( g, h, a, b, c, d, e, f, K(34), M(34) );
527 R( f, g, h, a, b, c, d, e, K(35), M(35) );
528 R( e, f, g, h, a, b, c, d, K(36), M(36) );
529 R( d, e, f, g, h, a, b, c, K(37), M(37) );
530 R( c, d, e, f, g, h, a, b, K(38), M(38) );
531 R( b, c, d, e, f, g, h, a, K(39), M(39) );
532 R( a, b, c, d, e, f, g, h, K(40), M(40) );
533 R( h, a, b, c, d, e, f, g, K(41), M(41) );
534 R( g, h, a, b, c, d, e, f, K(42), M(42) );
535 R( f, g, h, a, b, c, d, e, K(43), M(43) );
536 R( e, f, g, h, a, b, c, d, K(44), M(44) );
537 R( d, e, f, g, h, a, b, c, K(45), M(45) );
538 R( c, d, e, f, g, h, a, b, K(46), M(46) );
539 R( b, c, d, e, f, g, h, a, K(47), M(47) );
540 R( a, b, c, d, e, f, g, h, K(48), M(48) );
541 R( h, a, b, c, d, e, f, g, K(49), M(49) );
542 R( g, h, a, b, c, d, e, f, K(50), M(50) );
543 R( f, g, h, a, b, c, d, e, K(51), M(51) );
544 R( e, f, g, h, a, b, c, d, K(52), M(52) );
545 R( d, e, f, g, h, a, b, c, K(53), M(53) );
546 R( c, d, e, f, g, h, a, b, K(54), M(54) );
547 R( b, c, d, e, f, g, h, a, K(55), M(55) );
548 R( a, b, c, d, e, f, g, h, K(56), M(56) );
549 R( h, a, b, c, d, e, f, g, K(57), M(57) );
550 R( g, h, a, b, c, d, e, f, K(58), M(58) );
551 R( f, g, h, a, b, c, d, e, K(59), M(59) );
552 R( e, f, g, h, a, b, c, d, K(60), M(60) );
553 R( d, e, f, g, h, a, b, c, K(61), M(61) );
554 R( c, d, e, f, g, h, a, b, K(62), M(62) );
555 R( b, c, d, e, f, g, h, a, K(63), M(63) );
556 R( a, b, c, d, e, f, g, h, K(64), M(64) );
557 R( h, a, b, c, d, e, f, g, K(65), M(65) );
558 R( g, h, a, b, c, d, e, f, K(66), M(66) );
559 R( f, g, h, a, b, c, d, e, K(67), M(67) );
560 R( e, f, g, h, a, b, c, d, K(68), M(68) );
561 R( d, e, f, g, h, a, b, c, K(69), M(69) );
562 R( c, d, e, f, g, h, a, b, K(70), M(70) );
563 R( b, c, d, e, f, g, h, a, K(71), M(71) );
564 R( a, b, c, d, e, f, g, h, K(72), M(72) );
565 R( h, a, b, c, d, e, f, g, K(73), M(73) );
566 R( g, h, a, b, c, d, e, f, K(74), M(74) );
567 R( f, g, h, a, b, c, d, e, K(75), M(75) );
568 R( e, f, g, h, a, b, c, d, K(76), M(76) );
569 R( d, e, f, g, h, a, b, c, K(77), M(77) );
570 R( c, d, e, f, g, h, a, b, K(78), M(78) );
571 R( b, c, d, e, f, g, h, a, K(79), M(79) );
573 a = ctx->state[0] = u64plus (ctx->state[0], a);
574 b = ctx->state[1] = u64plus (ctx->state[1], b);
575 c = ctx->state[2] = u64plus (ctx->state[2], c);
576 d = ctx->state[3] = u64plus (ctx->state[3], d);
577 e = ctx->state[4] = u64plus (ctx->state[4], e);
578 f = ctx->state[5] = u64plus (ctx->state[5], f);
579 g = ctx->state[6] = u64plus (ctx->state[6], g);
580 h = ctx->state[7] = u64plus (ctx->state[7], h);
583 #endif
586 * Hey Emacs!
587 * Local Variables:
588 * coding: utf-8
589 * End: