Lines Matching refs:s11
4638 int64_t s11 = kBottom21Bits & (load_4(s + 28) >> 7); in x25519_sc_reduce() local
4669 s11 += s23 * 666643; in x25519_sc_reduce()
4678 s11 += s22 * 470296; in x25519_sc_reduce()
4687 s11 += s21 * 654183; in x25519_sc_reduce()
4696 s11 -= s20 * 997805; in x25519_sc_reduce()
4705 s11 += s19 * 136657; in x25519_sc_reduce()
4714 s11 -= s18 * 683901; in x25519_sc_reduce()
4724 s11 += carry10; in x25519_sc_reduce()
4742 carry11 = (s11 + (1 << 20)) >> 21; in x25519_sc_reduce()
4744 s11 -= carry11 * (1 << 21); in x25519_sc_reduce()
4816 s11 += carry10; in x25519_sc_reduce()
4834 carry11 = (s11 + (1 << 20)) >> 21; in x25519_sc_reduce()
4836 s11 -= carry11 * (1 << 21); in x25519_sc_reduce()
4877 s11 += carry10; in x25519_sc_reduce()
4879 carry11 = s11 >> 21; in x25519_sc_reduce()
4881 s11 -= carry11 * (1 << 21); in x25519_sc_reduce()
4922 s11 += carry10; in x25519_sc_reduce()
4953 s[28] = (uint8_t)((s10 >> 14) | (s11 << 7)); in x25519_sc_reduce()
4954 s[29] = (uint8_t) (s11 >> 1); in x25519_sc_reduce()
4955 s[30] = (uint8_t) (s11 >> 9); in x25519_sc_reduce()
4956 s[31] = (uint8_t) (s11 >> 17); in x25519_sc_reduce()
5019 int64_t s11; in sc_muladd() local
5067 …s11 = c11 + a0 * b11 + a1 * b10 + a2 * b9 + a3 * b8 + a4 * b7 + a5 * b6 + a6 *… in sc_muladd()
5097 s11 += carry10; in sc_muladd()
5133 carry11 = (s11 + (1 << 20)) >> 21; in sc_muladd()
5135 s11 -= carry11 * (1 << 21); in sc_muladd()
5152 s11 += s23 * 666643; in sc_muladd()
5161 s11 += s22 * 470296; in sc_muladd()
5170 s11 += s21 * 654183; in sc_muladd()
5179 s11 -= s20 * 997805; in sc_muladd()
5188 s11 += s19 * 136657; in sc_muladd()
5197 s11 -= s18 * 683901; in sc_muladd()
5207 s11 += carry10; in sc_muladd()
5225 carry11 = (s11 + (1 << 20)) >> 21; in sc_muladd()
5227 s11 -= carry11 * (1 << 21); in sc_muladd()
5299 s11 += carry10; in sc_muladd()
5317 carry11 = (s11 + (1 << 20)) >> 21; in sc_muladd()
5319 s11 -= carry11 * (1 << 21); in sc_muladd()
5360 s11 += carry10; in sc_muladd()
5362 carry11 = s11 >> 21; in sc_muladd()
5364 s11 -= carry11 * (1 << 21); in sc_muladd()
5405 s11 += carry10; in sc_muladd()
5436 s[28] = (uint8_t)((s10 >> 14) | (s11 << 7)); in sc_muladd()
5437 s[29] = (uint8_t) (s11 >> 1); in sc_muladd()
5438 s[30] = (uint8_t) (s11 >> 9); in sc_muladd()
5439 s[31] = (uint8_t) (s11 >> 17); in sc_muladd()