Lines Matching refs:s12
1063 int64_t s12 = 2097151 & (load_4(s + 31) >> 4); in x25519_sc_reduce() local
1094 s12 += s23 * 470296; in x25519_sc_reduce()
1103 s12 += s22 * 654183; in x25519_sc_reduce()
1112 s12 -= s21 * 997805; in x25519_sc_reduce()
1121 s12 += s20 * 136657; in x25519_sc_reduce()
1130 s12 -= s19 * 683901; in x25519_sc_reduce()
1150 carry12 = (s12 + (1 << 20)) >> 21; in x25519_sc_reduce()
1152 s12 -= int64_lshift21(carry12); in x25519_sc_reduce()
1167 s12 += carry11; in x25519_sc_reduce()
1216 s0 += s12 * 666643; in x25519_sc_reduce()
1217 s1 += s12 * 470296; in x25519_sc_reduce()
1218 s2 += s12 * 654183; in x25519_sc_reduce()
1219 s3 -= s12 * 997805; in x25519_sc_reduce()
1220 s4 += s12 * 136657; in x25519_sc_reduce()
1221 s5 -= s12 * 683901; in x25519_sc_reduce()
1222 s12 = 0; in x25519_sc_reduce()
1259 s12 += carry11; in x25519_sc_reduce()
1262 s0 += s12 * 666643; in x25519_sc_reduce()
1263 s1 += s12 * 470296; in x25519_sc_reduce()
1264 s2 += s12 * 654183; in x25519_sc_reduce()
1265 s3 -= s12 * 997805; in x25519_sc_reduce()
1266 s4 += s12 * 136657; in x25519_sc_reduce()
1267 s5 -= s12 * 683901; in x25519_sc_reduce()
1268 s12 = 0; in x25519_sc_reduce()
1304 s12 += carry11; in x25519_sc_reduce()
1307 s0 += s12 * 666643; in x25519_sc_reduce()
1308 s1 += s12 * 470296; in x25519_sc_reduce()
1309 s2 += s12 * 654183; in x25519_sc_reduce()
1310 s3 -= s12 * 997805; in x25519_sc_reduce()
1311 s4 += s12 * 136657; in x25519_sc_reduce()
1312 s5 -= s12 * 683901; in x25519_sc_reduce()
1313 s12 = 0; in x25519_sc_reduce()
1441 int64_t s12; in sc_muladd() local
1494 s12 = a1 * b11 + a2 * b10 + a3 * b9 + a4 * b8 + a5 * b7 + a6 * b6 + a7 * b5 + in sc_muladd()
1529 carry12 = (s12 + (1 << 20)) >> 21; in sc_muladd()
1531 s12 -= int64_lshift21(carry12); in sc_muladd()
1564 s12 += carry11; in sc_muladd()
1583 s12 += s23 * 470296; in sc_muladd()
1592 s12 += s22 * 654183; in sc_muladd()
1601 s12 -= s21 * 997805; in sc_muladd()
1610 s12 += s20 * 136657; in sc_muladd()
1619 s12 -= s19 * 683901; in sc_muladd()
1639 carry12 = (s12 + (1 << 20)) >> 21; in sc_muladd()
1641 s12 -= int64_lshift21(carry12); in sc_muladd()
1656 s12 += carry11; in sc_muladd()
1705 s0 += s12 * 666643; in sc_muladd()
1706 s1 += s12 * 470296; in sc_muladd()
1707 s2 += s12 * 654183; in sc_muladd()
1708 s3 -= s12 * 997805; in sc_muladd()
1709 s4 += s12 * 136657; in sc_muladd()
1710 s5 -= s12 * 683901; in sc_muladd()
1711 s12 = 0; in sc_muladd()
1748 s12 += carry11; in sc_muladd()
1751 s0 += s12 * 666643; in sc_muladd()
1752 s1 += s12 * 470296; in sc_muladd()
1753 s2 += s12 * 654183; in sc_muladd()
1754 s3 -= s12 * 997805; in sc_muladd()
1755 s4 += s12 * 136657; in sc_muladd()
1756 s5 -= s12 * 683901; in sc_muladd()
1757 s12 = 0; in sc_muladd()
1793 s12 += carry11; in sc_muladd()
1796 s0 += s12 * 666643; in sc_muladd()
1797 s1 += s12 * 470296; in sc_muladd()
1798 s2 += s12 * 654183; in sc_muladd()
1799 s3 -= s12 * 997805; in sc_muladd()
1800 s4 += s12 * 136657; in sc_muladd()
1801 s5 -= s12 * 683901; in sc_muladd()
1802 s12 = 0; in sc_muladd()