jit_compiler_rv64_static.S 26 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235
  1. /*
  2. Copyright (c) 2023 tevador <tevador@gmail.com>
  3. All rights reserved.
  4. Redistribution and use in source and binary forms, with or without
  5. modification, are permitted provided that the following conditions are met:
  6. * Redistributions of source code must retain the above copyright
  7. notice, this list of conditions and the following disclaimer.
  8. * Redistributions in binary form must reproduce the above copyright
  9. notice, this list of conditions and the following disclaimer in the
  10. documentation and/or other materials provided with the distribution.
  11. * Neither the name of the copyright holder nor the
  12. names of its contributors may be used to endorse or promote products
  13. derived from this software without specific prior written permission.
  14. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
  15. ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
  16. WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  17. DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
  18. FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
  19. DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
  20. SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  21. CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
  22. OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
  23. OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  24. */
  25. #define DECL(x) x
  26. .text
  27. .option rvc
  28. #include "configuration.h"
  29. .global DECL(randomx_riscv64_literals)
  30. .global DECL(randomx_riscv64_literals_end)
  31. .global DECL(randomx_riscv64_data_init)
  32. .global DECL(randomx_riscv64_fix_data_call)
  33. .global DECL(randomx_riscv64_prologue)
  34. .global DECL(randomx_riscv64_loop_begin)
  35. .global DECL(randomx_riscv64_data_read)
  36. .global DECL(randomx_riscv64_data_read_light)
  37. .global DECL(randomx_riscv64_fix_loop_call)
  38. .global DECL(randomx_riscv64_spad_store)
  39. .global DECL(randomx_riscv64_spad_store_hardaes)
  40. .global DECL(randomx_riscv64_spad_store_softaes)
  41. .global DECL(randomx_riscv64_loop_end)
  42. .global DECL(randomx_riscv64_fix_continue_loop)
  43. .global DECL(randomx_riscv64_epilogue)
  44. .global DECL(randomx_riscv64_softaes)
  45. .global DECL(randomx_riscv64_program_end)
  46. .global DECL(randomx_riscv64_ssh_init)
  47. .global DECL(randomx_riscv64_ssh_load)
  48. .global DECL(randomx_riscv64_ssh_prefetch)
  49. .global DECL(randomx_riscv64_ssh_end)
  50. /* The literal pool can fit at most 494 IMUL_RCP literals */
  51. #if RANDOMX_PROGRAM_SIZE > 494
  52. #error RANDOMX_PROGRAM_SIZE larger than 494 is not supported.
  53. #endif
  54. #define RANDOMX_CACHE_MASK (RANDOMX_ARGON_MEMORY*16-1)
  55. /* shared literal pool: 4 KB */
  56. /* space for 256 IMUL_RCP literals -2048 */
  57. /* filled by JIT compiler */
  58. DECL(randomx_riscv64_literals):
  59. literal_pool:
  60. /* SuperscalarHash constants +0 */
  61. .dword 6364136223846793005
  62. .dword 9298411001130361340
  63. .dword 12065312585734608966
  64. .dword 9306329213124626780
  65. .dword 5281919268842080866
  66. .dword 10536153434571861004
  67. .dword 3398623926847679864
  68. .dword 9549104520008361294
  69. /* CFROUND lookup table +64 */
  70. .word 0x00000000 /* RTN */
  71. .word 0x00000002 /* RDN */
  72. .word 0x00000003 /* RUP */
  73. .word 0x00000001 /* RTZ */
  74. /* mask literals +80,+84,+88,+92,+96,+104 */
  75. .word (RANDOMX_SCRATCHPAD_L1-8)
  76. .word (RANDOMX_SCRATCHPAD_L2-8)
  77. .word (RANDOMX_SCRATCHPAD_L3-64)
  78. .word (RANDOMX_DATASET_BASE_SIZE-64)
  79. .dword 0x80f0000000000000
  80. .dword 0x00ffffffffffffff
  81. DECL(randomx_riscv64_literals_end):
  82. /* E reg. set masks, +112,+120 */
  83. .dword 0 /* filled by JIT compiler */
  84. .dword 0 /* filled by JIT compiler */
  85. /* soft AES table addresses, +128,+136 */
  86. .dword 0 /* filled by JIT compiler */
  87. .dword 0 /* filled by JIT compiler */
  88. /* space for 238 IMUL_RCP literals, +144 */
  89. .fill 238,8,0 /* filled by JIT compiler */
  90. /* ================================= */
  91. /* Dataset init function entry point */
  92. /* ================================= */
  93. /* Register allocation:
  94. ----------------------
  95. x0 -> zero
  96. x1 -> temp/return address
  97. x2 -> stack pointer (sp)
  98. x3 -> literal pool pointer
  99. x5 -> dataset pointer
  100. x6 -> cache pointer
  101. x7 -> temp/itemNumber
  102. x8-x15 -> SuperscalarHash registers
  103. x16 -> itemNumber
  104. x17 -> endItem
  105. x28-x31 -> temp
  106. Stack layout:
  107. ------------------------
  108. sp+
  109. 0 -> return address
  110. 8 -> saved x3
  111. 16 -> saved x8-x9
  112. 32 -> caller stack
  113. */
  114. DECL(randomx_riscv64_data_init):
  115. addi sp, sp, -32
  116. /* dataset ptr */
  117. mv x5, x11
  118. /* cache->memory */
  119. ld x6, 0(x10)
  120. /* callee saved registers */
  121. sd x1, 0(sp)
  122. sd x3, 8(sp)
  123. /* literal pool */
  124. lla x3, literal_pool
  125. sd x8, 16(sp)
  126. sd x9, 24(sp)
  127. /* startItem */
  128. mv x16, x12
  129. /* endItem */
  130. mv x17, x13
  131. init_item:
  132. mv x7, x16
  133. DECL(randomx_riscv64_fix_data_call):
  134. jal superscalar_hash /* JIT compiler will adjust the offset */
  135. sd x8, 0(x5)
  136. sd x9, 8(x5)
  137. sd x10, 16(x5)
  138. sd x11, 24(x5)
  139. sd x12, 32(x5)
  140. sd x13, 40(x5)
  141. sd x14, 48(x5)
  142. sd x15, 56(x5)
  143. addi x5, x5, 64
  144. addi x16, x16, 1
  145. bltu x16, x17, init_item
  146. ld x1, 0(sp)
  147. ld x3, 8(sp)
  148. ld x8, 16(sp)
  149. ld x9, 24(sp)
  150. addi sp, sp, 32
  151. ret
  152. /* ====================================== */
  153. /* Program execution function entry point */
  154. /* ====================================== */
  155. /* Register allocation:
  156. ----------------------
  157. x0 -> zero
  158. x1 -> temp/scratchpad L3 mask
  159. x2 -> stack pointer (sp)
  160. x3 -> literal pool pointer
  161. x5 -> scratchpad pointer
  162. x6 -> dataset/cache pointer
  163. x7 -> temp/next dataset access
  164. x8 -> temp
  165. x9 -> temp
  166. x10 -> scratchpad L1 mask (0x0000000000003ff8)
  167. x11 -> scratchpad L2 mask (0x000000000003fff8)
  168. x12 -> FSCAL_R mask (0x80f0000000000000)
  169. x13 -> E reg. clear mask (0x00ffffffffffffff)
  170. x14 -> E reg. set mask (0x3*00000000******)
  171. x15 -> E reg. set mask (0x3*00000000******)
  172. x16-x23 -> VM registers "r0"-"r7"
  173. x24 -> iteration counter "ic"
  174. x25 -> VM registers "mx", "ma"
  175. x26 -> spAddr0
  176. x27 -> spAddr1
  177. x28-x31 -> temp/literals for IMUL_RCP (4x)
  178. (Note: We avoid using x4 because it breaks debugging with gdb.)
  179. f0-f7 -> VM registers "f0"-"f3"
  180. f8-f15 -> VM registers "e0"-"e3"
  181. f16-f23 -> VM registers "a0"-"a3"
  182. f24-f25 -> temp
  183. f26-f31 -> literals for IMUL_RCP (6x)
  184. Stack layout:
  185. ------------------------
  186. sp+
  187. 0 -> return address
  188. 8 -> register file ptr
  189. 16 -> saved x3-x4
  190. 32 -> saved x8-x9
  191. 48 -> saved x18-x27
  192. 128 -> saved f8-f9
  193. 144 -> saved f18-f27
  194. 224 -> caller stack
  195. */
  196. DECL(randomx_riscv64_prologue):
  197. addi sp, sp, -224
  198. /* scratchpad pointer */
  199. mv x5, x12
  200. /* register file pointer */
  201. sd x10, 8(sp)
  202. /* callee saved registers */
  203. sd x3, 16(sp)
  204. sd x8, 32(sp)
  205. sd x9, 40(sp)
  206. sd x18, 48(sp)
  207. sd x19, 56(sp)
  208. sd x20, 64(sp)
  209. sd x21, 72(sp)
  210. sd x22, 80(sp)
  211. sd x23, 88(sp)
  212. sd x24, 96(sp)
  213. sd x25, 104(sp)
  214. sd x26, 112(sp)
  215. sd x27, 120(sp)
  216. fsd f8, 128(sp)
  217. fsd f9, 136(sp)
  218. fsd f18, 144(sp)
  219. fsd f19, 152(sp)
  220. fsd f20, 160(sp)
  221. fsd f21, 168(sp)
  222. fsd f22, 176(sp)
  223. fsd f23, 184(sp)
  224. fsd f24, 192(sp)
  225. fsd f25, 200(sp)
  226. fsd f26, 208(sp)
  227. fsd f27, 216(sp)
  228. /* iteration counter */
  229. mv x24, x13
  230. /* return address */
  231. sd x1, 0(sp)
  232. /* literal pool */
  233. lla x3, literal_pool
  234. /* load (ma, mx) */
  235. ld x25, 0(x11)
  236. /* dataset ptr */
  237. ld x6, 8(x11)
  238. /* load dataset mask */
  239. lwu x1, 92(x3)
  240. /* zero registers r0-r3, load a0-a1 */
  241. li x16, 0
  242. fld f16, 192(x10)
  243. li x17, 0
  244. fld f17, 200(x10)
  245. srli x7, x25, 32 /* x7 = ma */
  246. li x18, 0
  247. fld f18, 208(x10)
  248. mv x27, x7 /* x27 = ma */
  249. li x19, 0
  250. fld f19, 216(x10)
  251. /* set dataset read address */
  252. and x7, x7, x1
  253. add x7, x7, x6
  254. /* zero registers r4-r7, load a2-a3 */
  255. li x20, 0
  256. fld f20, 224(x10)
  257. li x21, 0
  258. fld f21, 232(x10)
  259. li x22, 0
  260. fld f22, 240(x10)
  261. li x23, 0
  262. fld f23, 248(x10)
  263. /* load L3 mask */
  264. lwu x1, 88(x3)
  265. /* load scratchpad masks */
  266. lwu x10, 80(x3)
  267. lwu x11, 84(x3)
  268. /* set spAddr0, spAddr1 */
  269. and x26, x25, x1
  270. and x27, x27, x1
  271. add x26, x26, x5
  272. add x27, x27, x5
  273. /* align L3 mask */
  274. addi x1, x1, 56
  275. /* FSCAL, E reg. masks */
  276. ld x12, 96(x3)
  277. ld x13, 104(x3)
  278. ld x14, 112(x3)
  279. ld x15, 120(x3)
  280. /* IMUL_RCP literals */
  281. fld f26, 176(x3)
  282. fld f27, 184(x3)
  283. fld f28, 192(x3)
  284. fld f29, 200(x3)
  285. fld f30, 208(x3)
  286. fld f31, 216(x3)
  287. .balign 4
  288. DECL(randomx_riscv64_loop_begin):
  289. loop_begin:
  290. /* mix integer registers */
  291. ld x8, 0(x26)
  292. ld x9, 8(x26)
  293. ld x30, 16(x26)
  294. ld x31, 24(x26)
  295. xor x16, x16, x8
  296. ld x8, 32(x26)
  297. xor x17, x17, x9
  298. ld x9, 40(x26)
  299. xor x18, x18, x30
  300. ld x30, 48(x26)
  301. xor x19, x19, x31
  302. ld x31, 56(x26)
  303. xor x20, x20, x8
  304. lw x8, 0(x27)
  305. xor x21, x21, x9
  306. lw x9, 4(x27)
  307. xor x22, x22, x30
  308. lw x30, 8(x27)
  309. xor x23, x23, x31
  310. lw x31, 12(x27)
  311. /* load F registers */
  312. fcvt.d.w f0, x8
  313. lw x8, 16(x27)
  314. fcvt.d.w f1, x9
  315. lw x9, 20(x27)
  316. fcvt.d.w f2, x30
  317. lw x30, 24(x27)
  318. fcvt.d.w f3, x31
  319. lw x31, 28(x27)
  320. fcvt.d.w f4, x8
  321. lw x8, 32(x27)
  322. fcvt.d.w f5, x9
  323. lw x9, 36(x27)
  324. fcvt.d.w f6, x30
  325. lw x30, 40(x27)
  326. fcvt.d.w f7, x31
  327. lw x31, 44(x27)
  328. /* load E registers */
  329. fcvt.d.w f8, x8
  330. lw x8, 48(x27)
  331. fcvt.d.w f9, x9
  332. lw x9, 52(x27)
  333. fcvt.d.w f10, x30
  334. lw x30, 56(x27)
  335. fcvt.d.w f11, x31
  336. lw x31, 60(x27)
  337. fcvt.d.w f12, x8
  338. fmv.x.d x8, f8
  339. fcvt.d.w f13, x9
  340. fmv.x.d x9, f9
  341. fcvt.d.w f14, x30
  342. fmv.x.d x30, f10
  343. fcvt.d.w f15, x31
  344. fmv.x.d x31, f11
  345. and x8, x8, x13
  346. and x9, x9, x13
  347. or x8, x8, x14
  348. or x9, x9, x15
  349. and x30, x30, x13
  350. and x31, x31, x13
  351. or x30, x30, x14
  352. or x31, x31, x15
  353. fmv.d.x f8, x8
  354. fmv.d.x f9, x9
  355. fmv.d.x f10, x30
  356. fmv.d.x f11, x31
  357. fmv.x.d x8, f12
  358. fmv.x.d x9, f13
  359. fmv.x.d x30, f14
  360. fmv.x.d x31, f15
  361. and x8, x8, x13
  362. and x9, x9, x13
  363. or x8, x8, x14
  364. or x9, x9, x15
  365. fmv.d.x f12, x8
  366. fmv.d.x f13, x9
  367. and x30, x30, x13
  368. and x31, x31, x13
  369. or x30, x30, x14
  370. or x31, x31, x15
  371. fmv.d.x f14, x30
  372. fmv.d.x f15, x31
  373. /* reload clobbered IMUL_RCP regs */
  374. ld x28, 144(x3)
  375. ld x29, 152(x3)
  376. ld x30, 160(x3)
  377. ld x31, 168(x3)
  378. DECL(randomx_riscv64_data_read):
  379. xor x8, x20, x22 /* JIT compiler will adjust the registers */
  380. /* load dataset mask */
  381. lwu x1, 92(x3)
  382. /* zero-extend x8 */
  383. #ifdef __riscv_zba
  384. zext.w x8, x8
  385. #else
  386. slli x8, x8, 32
  387. srli x8, x8, 32
  388. #endif
  389. /* update "mx" */
  390. xor x25, x25, x8
  391. /* read dataset and update registers */
  392. ld x8, 0(x7)
  393. ld x9, 8(x7)
  394. ld x30, 16(x7)
  395. ld x31, 24(x7)
  396. xor x16, x16, x8
  397. ld x8, 32(x7)
  398. xor x17, x17, x9
  399. ld x9, 40(x7)
  400. xor x18, x18, x30
  401. ld x30, 48(x7)
  402. xor x19, x19, x31
  403. ld x31, 56(x7)
  404. xor x20, x20, x8
  405. /* calculate the next dataset address */
  406. and x7, x25, x1
  407. xor x21, x21, x9
  408. add x7, x7, x6
  409. xor x22, x22, x30
  410. /* prefetch - doesn't seem to have any effect */
  411. /* ld x0, 0(x7) */
  412. xor x23, x23, x31
  413. /* swap mx <-> ma */
  414. #ifdef __riscv_zbb
  415. rori x25, x25, 32
  416. #else
  417. srli x9, x25, 32
  418. slli x25, x25, 32
  419. or x25, x25, x9
  420. #endif
  421. DECL(randomx_riscv64_data_read_light):
  422. xor x8, x20, x22 /* JIT compiler will adjust the registers */
  423. /* load dataset offset */
  424. lui x9, 0x02000 /* JIT compiler will adjust the immediate */
  425. addi x9, x9, -64
  426. /* load dataset mask */
  427. lwu x1, 92(x3)
  428. /* swap mx <-> ma */
  429. #ifdef __riscv_zbb
  430. rori x25, x25, 32
  431. #else
  432. srli x31, x25, 32
  433. slli x25, x25, 32
  434. or x25, x25, x31
  435. #endif
  436. slli x8, x8, 32
  437. /* update "mx" */
  438. xor x25, x25, x8
  439. /* the next dataset item */
  440. and x7, x25, x1
  441. srli x7, x7, 6
  442. add x7, x7, x9
  443. DECL(randomx_riscv64_fix_loop_call):
  444. jal superscalar_hash /* JIT compiler will adjust the offset */
  445. xor x16, x16, x8
  446. xor x17, x17, x9
  447. xor x18, x18, x10
  448. xor x19, x19, x11
  449. xor x20, x20, x12
  450. xor x21, x21, x13
  451. xor x22, x22, x14
  452. xor x23, x23, x15
  453. /* restore clobbered registers */
  454. lwu x10, 80(x3)
  455. lwu x11, 84(x3)
  456. ld x12, 96(x3)
  457. ld x13, 104(x3)
  458. ld x14, 112(x3)
  459. ld x15, 120(x3)
  460. DECL(randomx_riscv64_spad_store):
  461. /* store integer registers */
  462. sd x16, 0(x27)
  463. sd x17, 8(x27)
  464. sd x18, 16(x27)
  465. sd x19, 24(x27)
  466. sd x20, 32(x27)
  467. sd x21, 40(x27)
  468. sd x22, 48(x27)
  469. sd x23, 56(x27)
  470. /* XOR and store f0,e0 */
  471. fmv.x.d x8, f0
  472. fmv.x.d x9, f8
  473. fmv.x.d x30, f1
  474. fmv.x.d x31, f9
  475. xor x8, x8, x9
  476. xor x30, x30, x31
  477. sd x8, 0(x26)
  478. fmv.d.x f0, x8
  479. sd x30, 8(x26)
  480. fmv.d.x f1, x30
  481. /* XOR and store f1,e1 */
  482. fmv.x.d x8, f2
  483. fmv.x.d x9, f10
  484. fmv.x.d x30, f3
  485. fmv.x.d x31, f11
  486. xor x8, x8, x9
  487. xor x30, x30, x31
  488. sd x8, 16(x26)
  489. fmv.d.x f2, x8
  490. sd x30, 24(x26)
  491. fmv.d.x f3, x30
  492. /* XOR and store f2,e2 */
  493. fmv.x.d x8, f4
  494. fmv.x.d x9, f12
  495. fmv.x.d x30, f5
  496. fmv.x.d x31, f13
  497. xor x8, x8, x9
  498. xor x30, x30, x31
  499. sd x8, 32(x26)
  500. fmv.d.x f4, x8
  501. sd x30, 40(x26)
  502. fmv.d.x f5, x30
  503. /* XOR and store f3,e3 */
  504. fmv.x.d x8, f6
  505. fmv.x.d x9, f14
  506. fmv.x.d x30, f7
  507. fmv.x.d x31, f15
  508. xor x8, x8, x9
  509. xor x30, x30, x31
  510. sd x8, 48(x26)
  511. fmv.d.x f6, x8
  512. sd x30, 56(x26)
  513. fmv.d.x f7, x30
  514. DECL(randomx_riscv64_spad_store_hardaes):
  515. nop /* not implemented */
  516. DECL(randomx_riscv64_spad_store_softaes):
  517. /* store integer registers */
  518. sd x16, 0(x27)
  519. sd x17, 8(x27)
  520. sd x18, 16(x27)
  521. sd x19, 24(x27)
  522. sd x20, 32(x27)
  523. sd x21, 40(x27)
  524. sd x22, 48(x27)
  525. sd x23, 56(x27)
  526. /* process f0 with 4 AES rounds */
  527. fmv.x.d x8, f8
  528. fmv.x.d x10, f9
  529. fmv.x.d x30, f0
  530. fmv.x.d x31, f1
  531. jal softaes_enc
  532. fmv.x.d x8, f10
  533. fmv.x.d x10, f11
  534. jal softaes_enc
  535. fmv.x.d x8, f12
  536. fmv.x.d x10, f13
  537. jal softaes_enc
  538. fmv.x.d x8, f14
  539. fmv.x.d x10, f15
  540. jal softaes_enc
  541. sd x30, 0(x26)
  542. fmv.d.x f0, x30
  543. sd x31, 8(x26)
  544. fmv.d.x f1, x31
  545. /* process f1 with 4 AES rounds */
  546. fmv.x.d x8, f8
  547. fmv.x.d x10, f9
  548. fmv.x.d x30, f2
  549. fmv.x.d x31, f3
  550. jal softaes_dec
  551. fmv.x.d x8, f10
  552. fmv.x.d x10, f11
  553. jal softaes_dec
  554. fmv.x.d x8, f12
  555. fmv.x.d x10, f13
  556. jal softaes_dec
  557. fmv.x.d x8, f14
  558. fmv.x.d x10, f15
  559. jal softaes_dec
  560. sd x30, 16(x26)
  561. fmv.d.x f2, x30
  562. sd x31, 24(x26)
  563. fmv.d.x f3, x31
  564. /* process f2 with 4 AES rounds */
  565. fmv.x.d x8, f8
  566. fmv.x.d x10, f9
  567. fmv.x.d x30, f4
  568. fmv.x.d x31, f5
  569. jal softaes_enc
  570. fmv.x.d x8, f10
  571. fmv.x.d x10, f11
  572. jal softaes_enc
  573. fmv.x.d x8, f12
  574. fmv.x.d x10, f13
  575. jal softaes_enc
  576. fmv.x.d x8, f14
  577. fmv.x.d x10, f15
  578. jal softaes_enc
  579. sd x30, 32(x26)
  580. fmv.d.x f4, x30
  581. sd x31, 40(x26)
  582. fmv.d.x f5, x31
  583. /* process f3 with 4 AES rounds */
  584. fmv.x.d x8, f8
  585. fmv.x.d x10, f9
  586. fmv.x.d x30, f6
  587. fmv.x.d x31, f7
  588. jal softaes_dec
  589. fmv.x.d x8, f10
  590. fmv.x.d x10, f11
  591. jal softaes_dec
  592. fmv.x.d x8, f12
  593. fmv.x.d x10, f13
  594. jal softaes_dec
  595. fmv.x.d x8, f14
  596. fmv.x.d x10, f15
  597. jal softaes_dec
  598. sd x30, 48(x26)
  599. fmv.d.x f6, x30
  600. sd x31, 56(x26)
  601. fmv.d.x f7, x31
  602. /* restore clobbered registers */
  603. lwu x10, 80(x3)
  604. lwu x11, 84(x3)
  605. ld x12, 96(x3)
  606. ld x13, 104(x3)
  607. ld x14, 112(x3)
  608. ld x15, 120(x3)
  609. DECL(randomx_riscv64_loop_end):
  610. xor x26, x16, x18 /* JIT compiler will adjust the registers */
  611. /* load L3 mask */
  612. lwu x1, 88(x3)
  613. addi x24, x24, -1
  614. srli x27, x26, 32
  615. /* set spAddr0, spAddr1 */
  616. and x26, x26, x1
  617. and x27, x27, x1
  618. add x26, x26, x5
  619. add x27, x27, x5
  620. /* align L3 mask */
  621. addi x1, x1, 56
  622. /* conditional branch doesn't have sufficient range */
  623. j condition_check
  624. DECL(randomx_riscv64_fix_continue_loop):
  625. continue_loop:
  626. .word 0 /* JIT compiler will write a jump to loop_begin */
  627. condition_check:
  628. bnez x24, continue_loop
  629. DECL(randomx_riscv64_epilogue):
  630. /* restore callee saved registers */
  631. ld x10, 8(sp)
  632. ld x1, 0(sp)
  633. ld x3, 16(sp)
  634. ld x8, 32(sp)
  635. ld x9, 40(sp)
  636. ld x24, 96(sp)
  637. ld x25, 104(sp)
  638. ld x26, 112(sp)
  639. ld x27, 120(sp)
  640. fld f18, 144(sp)
  641. fld f19, 152(sp)
  642. fld f20, 160(sp)
  643. fld f21, 168(sp)
  644. fld f22, 176(sp)
  645. fld f23, 184(sp)
  646. fld f24, 192(sp)
  647. fld f25, 200(sp)
  648. fld f26, 208(sp)
  649. fld f27, 216(sp)
  650. /* save VM registers */
  651. sd x16, 0(x10)
  652. sd x17, 8(x10)
  653. sd x18, 16(x10)
  654. sd x19, 24(x10)
  655. sd x20, 32(x10)
  656. sd x21, 40(x10)
  657. sd x22, 48(x10)
  658. sd x23, 56(x10)
  659. fsd f0, 64(x10)
  660. fsd f1, 72(x10)
  661. fsd f2, 80(x10)
  662. fsd f3, 88(x10)
  663. fsd f4, 96(x10)
  664. fsd f5, 104(x10)
  665. fsd f6, 112(x10)
  666. fsd f7, 120(x10)
  667. fsd f8, 128(x10)
  668. fsd f9, 136(x10)
  669. fsd f10, 144(x10)
  670. fsd f11, 152(x10)
  671. fsd f12, 160(x10)
  672. fsd f13, 168(x10)
  673. fsd f14, 176(x10)
  674. fsd f15, 184(x10)
  675. /* restore callee saved registers */
  676. ld x18, 48(sp)
  677. ld x19, 56(sp)
  678. ld x20, 64(sp)
  679. ld x21, 72(sp)
  680. ld x22, 80(sp)
  681. ld x23, 88(sp)
  682. fld f8, 128(sp)
  683. fld f9, 136(sp)
  684. /* restore stack pointer */
  685. addi sp, sp, 224
  686. /* return */
  687. ret
  688. /*
  689. Soft AES subroutines
  690. in:
  691. x3 = literal pool
  692. x8, x10 = round key
  693. x30, x31 = plaintext
  694. out:
  695. x30, x31 = ciphertext
  696. clobbers:
  697. x8-x11 (limbs)
  698. x12-x13 (LUTs)
  699. x14-x15 (temp)
  700. */
  701. DECL(randomx_riscv64_softaes):
  702. softaes_enc:
  703. /* enc. lookup table */
  704. ld x13, 128(x3)
  705. /* load the round key into x8, x9, x10, x11 */
  706. srli x9, x8, 32
  707. srli x11, x10, 32
  708. #ifdef __riscv_zba
  709. zext.w x8, x8
  710. zext.w x10, x10
  711. #else
  712. slli x8, x8, 32
  713. slli x10, x10, 32
  714. srli x8, x8, 32
  715. srli x10, x10, 32
  716. #endif
  717. /* byte 0 */
  718. andi x14, x30, 255
  719. srli x30, x30, 8
  720. addi x12, x13, -2048
  721. #ifdef __riscv_zba
  722. sh2add x14, x14, x13
  723. #else
  724. slli x14, x14, 2
  725. add x14, x14, x13
  726. #endif
  727. lwu x14, -2048(x14)
  728. /* byte 1 */
  729. andi x15, x30, 255
  730. srli x30, x30, 8
  731. #ifdef __riscv_zba
  732. sh2add x15, x15, x12
  733. #else
  734. slli x15, x15, 2
  735. add x15, x15, x12
  736. #endif
  737. lwu x15, 1024(x15)
  738. xor x8, x8, x14
  739. /* byte 2 */
  740. andi x14, x30, 255
  741. srli x30, x30, 8
  742. #ifdef __riscv_zba
  743. sh2add x14, x14, x13
  744. #else
  745. slli x14, x14, 2
  746. add x14, x14, x13
  747. #endif
  748. lwu x14, 0(x14)
  749. xor x11, x11, x15
  750. /* byte 3 */
  751. andi x15, x30, 255
  752. srli x30, x30, 8
  753. #ifdef __riscv_zba
  754. sh2add x15, x15, x13
  755. #else
  756. slli x15, x15, 2
  757. add x15, x15, x13
  758. #endif
  759. lwu x15, 1024(x15)
  760. xor x10, x10, x14
  761. /* byte 4 */
  762. andi x14, x30, 255
  763. srli x30, x30, 8
  764. #ifdef __riscv_zba
  765. sh2add x14, x14, x12
  766. #else
  767. slli x14, x14, 2
  768. add x14, x14, x12
  769. #endif
  770. lwu x14, 0(x14)
  771. xor x9, x9, x15
  772. /* byte 5 */
  773. andi x15, x30, 255
  774. srli x30, x30, 8
  775. #ifdef __riscv_zba
  776. sh2add x15, x15, x12
  777. #else
  778. slli x15, x15, 2
  779. add x15, x15, x12
  780. #endif
  781. lwu x15, 1024(x15)
  782. xor x9, x9, x14
  783. /* byte 6 */
  784. andi x14, x30, 255
  785. srli x30, x30, 8
  786. #ifdef __riscv_zba
  787. sh2add x14, x14, x13
  788. #else
  789. slli x14, x14, 2
  790. add x14, x14, x13
  791. #endif
  792. lwu x14, 0(x14)
  793. xor x8, x8, x15
  794. /* byte 7 */
  795. andi x15, x30, 255
  796. #ifdef __riscv_zba
  797. sh2add x15, x15, x13
  798. #else
  799. slli x15, x15, 2
  800. add x15, x15, x13
  801. #endif
  802. lwu x15, 1024(x15)
  803. xor x11, x11, x14
  804. /* byte 8 */
  805. andi x14, x31, 255
  806. srli x31, x31, 8
  807. #ifdef __riscv_zba
  808. sh2add x14, x14, x12
  809. #else
  810. slli x14, x14, 2
  811. add x14, x14, x12
  812. #endif
  813. lwu x14, 0(x14)
  814. xor x10, x10, x15
  815. /* byte 9 */
  816. andi x15, x31, 255
  817. srli x31, x31, 8
  818. #ifdef __riscv_zba
  819. sh2add x15, x15, x12
  820. #else
  821. slli x15, x15, 2
  822. add x15, x15, x12
  823. #endif
  824. lwu x15, 1024(x15)
  825. xor x10, x10, x14
  826. /* byte 10 */
  827. andi x14, x31, 255
  828. srli x31, x31, 8
  829. #ifdef __riscv_zba
  830. sh2add x14, x14, x13
  831. #else
  832. slli x14, x14, 2
  833. add x14, x14, x13
  834. #endif
  835. lwu x14, 0(x14)
  836. xor x9, x9, x15
  837. /* byte 11 */
  838. andi x15, x31, 255
  839. srli x31, x31, 8
  840. #ifdef __riscv_zba
  841. sh2add x15, x15, x13
  842. #else
  843. slli x15, x15, 2
  844. add x15, x15, x13
  845. #endif
  846. lwu x15, 1024(x15)
  847. xor x8, x8, x14
  848. /* byte 12 */
  849. andi x14, x31, 255
  850. srli x31, x31, 8
  851. #ifdef __riscv_zba
  852. sh2add x14, x14, x12
  853. #else
  854. slli x14, x14, 2
  855. add x14, x14, x12
  856. #endif
  857. lwu x14, 0(x14)
  858. xor x11, x11, x15
  859. /* byte 13 */
  860. andi x15, x31, 255
  861. srli x31, x31, 8
  862. #ifdef __riscv_zba
  863. sh2add x15, x15, x12
  864. #else
  865. slli x15, x15, 2
  866. add x15, x15, x12
  867. #endif
  868. lwu x15, 1024(x15)
  869. xor x11, x11, x14
  870. /* byte 14 */
  871. andi x14, x31, 255
  872. srli x31, x31, 8
  873. #ifdef __riscv_zba
  874. sh2add x14, x14, x13
  875. #else
  876. slli x14, x14, 2
  877. add x14, x14, x13
  878. #endif
  879. lwu x14, 0(x14)
  880. xor x10, x10, x15
  881. /* byte 15 */
  882. andi x15, x31, 255
  883. #ifdef __riscv_zba
  884. sh2add x15, x15, x13
  885. #else
  886. slli x15, x15, 2
  887. add x15, x15, x13
  888. #endif
  889. lwu x15, 1024(x15)
  890. xor x9, x9, x14
  891. slli x11, x11, 32
  892. slli x9, x9, 32
  893. or x30, x8, x9
  894. or x31, x10, x11
  895. xor x30, x30, x15
  896. ret
  897. softaes_dec:
  898. /* dec. lookup table */
  899. ld x13, 136(x3)
  900. /* load the round key into x8, x9, x10, x11 */
  901. srli x9, x8, 32
  902. srli x11, x10, 32
  903. #ifdef __riscv_zba
  904. zext.w x8, x8
  905. zext.w x10, x10
  906. #else
  907. slli x8, x8, 32
  908. slli x10, x10, 32
  909. srli x8, x8, 32
  910. srli x10, x10, 32
  911. #endif
  912. /* byte 0 */
  913. andi x14, x30, 255
  914. srli x30, x30, 8
  915. addi x12, x13, -2048
  916. #ifdef __riscv_zba
  917. sh2add x14, x14, x13
  918. #else
  919. slli x14, x14, 2
  920. add x14, x14, x13
  921. #endif
  922. lwu x14, -2048(x14)
  923. /* byte 1 */
  924. andi x15, x30, 255
  925. srli x30, x30, 8
  926. #ifdef __riscv_zba
  927. sh2add x15, x15, x12
  928. #else
  929. slli x15, x15, 2
  930. add x15, x15, x12
  931. #endif
  932. lwu x15, 1024(x15)
  933. xor x8, x8, x14
  934. /* byte 2 */
  935. andi x14, x30, 255
  936. srli x30, x30, 8
  937. #ifdef __riscv_zba
  938. sh2add x14, x14, x13
  939. #else
  940. slli x14, x14, 2
  941. add x14, x14, x13
  942. #endif
  943. lwu x14, 0(x14)
  944. xor x9, x9, x15
  945. /* byte 3 */
  946. andi x15, x30, 255
  947. srli x30, x30, 8
  948. #ifdef __riscv_zba
  949. sh2add x15, x15, x13
  950. #else
  951. slli x15, x15, 2
  952. add x15, x15, x13
  953. #endif
  954. lwu x15, 1024(x15)
  955. xor x10, x10, x14
  956. /* byte 4 */
  957. andi x14, x30, 255
  958. srli x30, x30, 8
  959. #ifdef __riscv_zba
  960. sh2add x14, x14, x12
  961. #else
  962. slli x14, x14, 2
  963. add x14, x14, x12
  964. #endif
  965. lwu x14, 0(x14)
  966. xor x11, x11, x15
  967. /* byte 5 */
  968. andi x15, x30, 255
  969. srli x30, x30, 8
  970. #ifdef __riscv_zba
  971. sh2add x15, x15, x12
  972. #else
  973. slli x15, x15, 2
  974. add x15, x15, x12
  975. #endif
  976. lwu x15, 1024(x15)
  977. xor x9, x9, x14
  978. /* byte 6 */
  979. andi x14, x30, 255
  980. srli x30, x30, 8
  981. #ifdef __riscv_zba
  982. sh2add x14, x14, x13
  983. #else
  984. slli x14, x14, 2
  985. add x14, x14, x13
  986. #endif
  987. lwu x14, 0(x14)
  988. xor x10, x10, x15
  989. /* byte 7 */
  990. andi x15, x30, 255
  991. #ifdef __riscv_zba
  992. sh2add x15, x15, x13
  993. #else
  994. slli x15, x15, 2
  995. add x15, x15, x13
  996. #endif
  997. lwu x15, 1024(x15)
  998. xor x11, x11, x14
  999. /* byte 8 */
  1000. andi x14, x31, 255
  1001. srli x31, x31, 8
  1002. #ifdef __riscv_zba
  1003. sh2add x14, x14, x12
  1004. #else
  1005. slli x14, x14, 2
  1006. add x14, x14, x12
  1007. #endif
  1008. lwu x14, 0(x14)
  1009. xor x8, x8, x15
  1010. /* byte 9 */
  1011. andi x15, x31, 255
  1012. srli x31, x31, 8
  1013. #ifdef __riscv_zba
  1014. sh2add x15, x15, x12
  1015. #else
  1016. slli x15, x15, 2
  1017. add x15, x15, x12
  1018. #endif
  1019. lwu x15, 1024(x15)
  1020. xor x10, x10, x14
  1021. /* byte 10 */
  1022. andi x14, x31, 255
  1023. srli x31, x31, 8
  1024. #ifdef __riscv_zba
  1025. sh2add x14, x14, x13
  1026. #else
  1027. slli x14, x14, 2
  1028. add x14, x14, x13
  1029. #endif
  1030. lwu x14, 0(x14)
  1031. xor x11, x11, x15
  1032. /* byte 11 */
  1033. andi x15, x31, 255
  1034. srli x31, x31, 8
  1035. #ifdef __riscv_zba
  1036. sh2add x15, x15, x13
  1037. #else
  1038. slli x15, x15, 2
  1039. add x15, x15, x13
  1040. #endif
  1041. lwu x15, 1024(x15)
  1042. xor x8, x8, x14
  1043. /* byte 12 */
  1044. andi x14, x31, 255
  1045. srli x31, x31, 8
  1046. #ifdef __riscv_zba
  1047. sh2add x14, x14, x12
  1048. #else
  1049. slli x14, x14, 2
  1050. add x14, x14, x12
  1051. #endif
  1052. lwu x14, 0(x14)
  1053. xor x9, x9, x15
  1054. /* byte 13 */
  1055. andi x15, x31, 255
  1056. srli x31, x31, 8
  1057. #ifdef __riscv_zba
  1058. sh2add x15, x15, x12
  1059. #else
  1060. slli x15, x15, 2
  1061. add x15, x15, x12
  1062. #endif
  1063. lwu x15, 1024(x15)
  1064. xor x11, x11, x14
  1065. /* byte 14 */
  1066. andi x14, x31, 255
  1067. srli x31, x31, 8
  1068. #ifdef __riscv_zba
  1069. sh2add x14, x14, x13
  1070. #else
  1071. slli x14, x14, 2
  1072. add x14, x14, x13
  1073. #endif
  1074. lwu x14, 0(x14)
  1075. xor x8, x8, x15
  1076. /* byte 15 */
  1077. andi x15, x31, 255
  1078. #ifdef __riscv_zba
  1079. sh2add x15, x15, x13
  1080. #else
  1081. slli x15, x15, 2
  1082. add x15, x15, x13
  1083. #endif
  1084. lwu x15, 1024(x15)
  1085. xor x9, x9, x14
  1086. slli x11, x11, 32
  1087. slli x9, x9, 32
  1088. or x30, x8, x9
  1089. or x31, x10, x11
  1090. xor x31, x31, x15
  1091. ret
  1092. DECL(randomx_riscv64_program_end):
  1093. nop
  1094. /* literal pool for SuperscalarHash */
  1095. /* space for remaining IMUL_RCP literals */
  1096. ssh_literal_pool:
  1097. /* space for 256 IMUL_RCP literals */
  1098. .fill 256,8,0
  1099. /*
  1100. SuperscalarHash subroutine
  1101. in:
  1102. x3 = literal pool
  1103. x6 = cache
  1104. x7 = itemNumber
  1105. out:
  1106. x8-x15 = 64-byte hash
  1107. clobbers:
  1108. x7, x28-x31
  1109. */
  1110. DECL(randomx_riscv64_ssh_init):
  1111. superscalar_hash:
  1112. ld x30, 0(x3) /* superscalarMul0 */
  1113. addi x8, x7, 1
  1114. ld x9, 8(x3)
  1115. li x31, RANDOMX_CACHE_MASK
  1116. ld x10, 16(x3)
  1117. ld x11, 24(x3)
  1118. mul x8, x8, x30
  1119. ld x12, 32(x3)
  1120. ld x13, 40(x3)
  1121. lla x30, ssh_literal_pool
  1122. ld x14, 48(x3)
  1123. and x7, x7, x31
  1124. ld x15, 56(x3)
  1125. slli x7, x7, 6
  1126. xor x9, x9, x8
  1127. add x7, x7, x6
  1128. xor x10, x10, x8
  1129. /* load the first IMUL_RCP literal */
  1130. ld x31, 2040(x30)
  1131. xor x11, x11, x8
  1132. xor x12, x12, x8
  1133. xor x13, x13, x8
  1134. xor x14, x14, x8
  1135. xor x15, x15, x8
  1136. DECL(randomx_riscv64_ssh_load):
  1137. ld x28, 0(x7)
  1138. ld x29, 8(x7)
  1139. xor x8, x8, x28
  1140. ld x28, 16(x7)
  1141. xor x9, x9, x29
  1142. ld x29, 24(x7)
  1143. xor x10, x10, x28
  1144. ld x28, 32(x7)
  1145. xor x11, x11, x29
  1146. ld x29, 40(x7)
  1147. xor x12, x12, x28
  1148. ld x28, 48(x7)
  1149. xor x13, x13, x29
  1150. ld x29, 56(x7)
  1151. xor x14, x14, x28
  1152. li x7, RANDOMX_CACHE_MASK
  1153. xor x15, x15, x29
  1154. DECL(randomx_riscv64_ssh_prefetch):
  1155. and x7, x8, x7 /* JIT compiler will adjust the register */
  1156. slli x7, x7, 6
  1157. add x7, x7, x6
  1158. /* prefetch - doesn't seem to have any effect */
  1159. /* ld x0, 0(x7) */
  1160. DECL(randomx_riscv64_ssh_end):
  1161. nop