1  /* { dg-do compile } */
       2  /* { dg-options "-Os -Wstack-usage=2500" } */
       3  
       4  #define SHA_LONG64 unsigned long long
       5  #define U64(C)     C##ULL
       6  
       7  #define SHA_LBLOCK      16
       8  #define SHA512_CBLOCK   (SHA_LBLOCK*8)
       9  
      10  typedef struct SHA512state_st {
      11      SHA_LONG64 h[8];
      12      SHA_LONG64 Nl, Nh;
      13      union {
      14          SHA_LONG64 d[SHA_LBLOCK];
      15          unsigned char p[SHA512_CBLOCK];
      16      } u;
      17      unsigned int num, md_len;
      18  } SHA512_CTX;
      19  
      20  static const SHA_LONG64 K512[80] = {
      21      U64(0x428a2f98d728ae22), U64(0x7137449123ef65cd),
      22      U64(0xb5c0fbcfec4d3b2f), U64(0xe9b5dba58189dbbc),
      23      U64(0x3956c25bf348b538), U64(0x59f111f1b605d019),
      24      U64(0x923f82a4af194f9b), U64(0xab1c5ed5da6d8118),
      25      U64(0xd807aa98a3030242), U64(0x12835b0145706fbe),
      26      U64(0x243185be4ee4b28c), U64(0x550c7dc3d5ffb4e2),
      27      U64(0x72be5d74f27b896f), U64(0x80deb1fe3b1696b1),
      28      U64(0x9bdc06a725c71235), U64(0xc19bf174cf692694),
      29      U64(0xe49b69c19ef14ad2), U64(0xefbe4786384f25e3),
      30      U64(0x0fc19dc68b8cd5b5), U64(0x240ca1cc77ac9c65),
      31      U64(0x2de92c6f592b0275), U64(0x4a7484aa6ea6e483),
      32      U64(0x5cb0a9dcbd41fbd4), U64(0x76f988da831153b5),
      33      U64(0x983e5152ee66dfab), U64(0xa831c66d2db43210),
      34      U64(0xb00327c898fb213f), U64(0xbf597fc7beef0ee4),
      35      U64(0xc6e00bf33da88fc2), U64(0xd5a79147930aa725),
      36      U64(0x06ca6351e003826f), U64(0x142929670a0e6e70),
      37      U64(0x27b70a8546d22ffc), U64(0x2e1b21385c26c926),
      38      U64(0x4d2c6dfc5ac42aed), U64(0x53380d139d95b3df),
      39      U64(0x650a73548baf63de), U64(0x766a0abb3c77b2a8),
      40      U64(0x81c2c92e47edaee6), U64(0x92722c851482353b),
      41      U64(0xa2bfe8a14cf10364), U64(0xa81a664bbc423001),
      42      U64(0xc24b8b70d0f89791), U64(0xc76c51a30654be30),
      43      U64(0xd192e819d6ef5218), U64(0xd69906245565a910),
      44      U64(0xf40e35855771202a), U64(0x106aa07032bbd1b8),
      45      U64(0x19a4c116b8d2d0c8), U64(0x1e376c085141ab53),
      46      U64(0x2748774cdf8eeb99), U64(0x34b0bcb5e19b48a8),
      47      U64(0x391c0cb3c5c95a63), U64(0x4ed8aa4ae3418acb),
      48      U64(0x5b9cca4f7763e373), U64(0x682e6ff3d6b2b8a3),
      49      U64(0x748f82ee5defb2fc), U64(0x78a5636f43172f60),
      50      U64(0x84c87814a1f0ab72), U64(0x8cc702081a6439ec),
      51      U64(0x90befffa23631e28), U64(0xa4506cebde82bde9),
      52      U64(0xbef9a3f7b2c67915), U64(0xc67178f2e372532b),
      53      U64(0xca273eceea26619c), U64(0xd186b8c721c0c207),
      54      U64(0xeada7dd6cde0eb1e), U64(0xf57d4f7fee6ed178),
      55      U64(0x06f067aa72176fba), U64(0x0a637dc5a2c898a6),
      56      U64(0x113f9804bef90dae), U64(0x1b710b35131c471b),
      57      U64(0x28db77f523047d84), U64(0x32caab7b40c72493),
      58      U64(0x3c9ebe0a15c9bebc), U64(0x431d67c49c100d4c),
      59      U64(0x4cc5d4becb3e42b6), U64(0x597f299cfc657e2a),
      60      U64(0x5fcb6fab3ad6faec), U64(0x6c44198c4a475817)
      61  };
      62  
      63  #define B(x,j)    (((SHA_LONG64)(*(((const unsigned char *)(&x))+j)))<<((7-j)*8))
      64  #define PULL64(x) (B(x,0)|B(x,1)|B(x,2)|B(x,3)|B(x,4)|B(x,5)|B(x,6)|B(x,7))
      65  #define ROTR(x,s)       (((x)>>s) | (x)<<(64-s))
      66  #define Sigma0(x)       (ROTR((x),28) ^ ROTR((x),34) ^ ROTR((x),39))
      67  #define Sigma1(x)       (ROTR((x),14) ^ ROTR((x),18) ^ ROTR((x),41))
      68  #define sigma0(x)       (ROTR((x),1)  ^ ROTR((x),8)  ^ ((x)>>7))
      69  #define sigma1(x)       (ROTR((x),19) ^ ROTR((x),61) ^ ((x)>>6))
      70  #define Ch(x,y,z)       (((x) & (y)) ^ ((~(x)) & (z)))
      71  #define Maj(x,y,z)      (((x) & (y)) ^ ((x) & (z)) ^ ((y) & (z)))
      72  
      73  #define ROUND_00_15(i,a,b,c,d,e,f,g,h)          do {    \
      74          T1 += h + Sigma1(e) + Ch(e,f,g) + K512[i];      \
      75          h = Sigma0(a) + Maj(a,b,c);                     \
      76          d += T1;        h += T1;                } while (0)
      77  #define ROUND_16_80(i,j,a,b,c,d,e,f,g,h,X)      do {    \
      78          s0 = X[(j+1)&0x0f];     s0 = sigma0(s0);        \
      79          s1 = X[(j+14)&0x0f];    s1 = sigma1(s1);        \
      80          T1 = X[(j)&0x0f] += s0 + s1 + X[(j+9)&0x0f];    \
      81          ROUND_00_15(i+j,a,b,c,d,e,f,g,h);               } while (0)
      82  void sha512_block_data_order(SHA512_CTX *ctx, const void *in,
      83                                      unsigned int num)
      84  {
      85      const SHA_LONG64 *W = in;
      86      SHA_LONG64 a, b, c, d, e, f, g, h, s0, s1, T1;
      87      SHA_LONG64 X[16];
      88      int i;
      89  
      90      while (num--) {
      91  
      92          a = ctx->h[0];
      93          b = ctx->h[1];
      94          c = ctx->h[2];
      95          d = ctx->h[3];
      96          e = ctx->h[4];
      97          f = ctx->h[5];
      98          g = ctx->h[6];
      99          h = ctx->h[7];
     100  
     101          T1 = X[0] = PULL64(W[0]);
     102          ROUND_00_15(0, a, b, c, d, e, f, g, h);
     103          T1 = X[1] = PULL64(W[1]);
     104          ROUND_00_15(1, h, a, b, c, d, e, f, g);
     105          T1 = X[2] = PULL64(W[2]);
     106          ROUND_00_15(2, g, h, a, b, c, d, e, f);
     107          T1 = X[3] = PULL64(W[3]);
     108          ROUND_00_15(3, f, g, h, a, b, c, d, e);
     109          T1 = X[4] = PULL64(W[4]);
     110          ROUND_00_15(4, e, f, g, h, a, b, c, d);
     111          T1 = X[5] = PULL64(W[5]);
     112          ROUND_00_15(5, d, e, f, g, h, a, b, c);
     113          T1 = X[6] = PULL64(W[6]);
     114          ROUND_00_15(6, c, d, e, f, g, h, a, b);
     115          T1 = X[7] = PULL64(W[7]);
     116          ROUND_00_15(7, b, c, d, e, f, g, h, a);
     117          T1 = X[8] = PULL64(W[8]);
     118          ROUND_00_15(8, a, b, c, d, e, f, g, h);
     119          T1 = X[9] = PULL64(W[9]);
     120          ROUND_00_15(9, h, a, b, c, d, e, f, g);
     121          T1 = X[10] = PULL64(W[10]);
     122          ROUND_00_15(10, g, h, a, b, c, d, e, f);
     123          T1 = X[11] = PULL64(W[11]);
     124          ROUND_00_15(11, f, g, h, a, b, c, d, e);
     125          T1 = X[12] = PULL64(W[12]);
     126          ROUND_00_15(12, e, f, g, h, a, b, c, d);
     127          T1 = X[13] = PULL64(W[13]);
     128          ROUND_00_15(13, d, e, f, g, h, a, b, c);
     129          T1 = X[14] = PULL64(W[14]);
     130          ROUND_00_15(14, c, d, e, f, g, h, a, b);
     131          T1 = X[15] = PULL64(W[15]);
     132          ROUND_00_15(15, b, c, d, e, f, g, h, a);
     133  
     134          for (i = 16; i < 80; i += 16) {
     135              ROUND_16_80(i, 0, a, b, c, d, e, f, g, h, X);
     136              ROUND_16_80(i, 1, h, a, b, c, d, e, f, g, X);
     137              ROUND_16_80(i, 2, g, h, a, b, c, d, e, f, X);
     138              ROUND_16_80(i, 3, f, g, h, a, b, c, d, e, X);
     139              ROUND_16_80(i, 4, e, f, g, h, a, b, c, d, X);
     140              ROUND_16_80(i, 5, d, e, f, g, h, a, b, c, X);
     141              ROUND_16_80(i, 6, c, d, e, f, g, h, a, b, X);
     142              ROUND_16_80(i, 7, b, c, d, e, f, g, h, a, X);
     143              ROUND_16_80(i, 8, a, b, c, d, e, f, g, h, X);
     144              ROUND_16_80(i, 9, h, a, b, c, d, e, f, g, X);
     145              ROUND_16_80(i, 10, g, h, a, b, c, d, e, f, X);
     146              ROUND_16_80(i, 11, f, g, h, a, b, c, d, e, X);
     147              ROUND_16_80(i, 12, e, f, g, h, a, b, c, d, X);
     148              ROUND_16_80(i, 13, d, e, f, g, h, a, b, c, X);
     149              ROUND_16_80(i, 14, c, d, e, f, g, h, a, b, X);
     150              ROUND_16_80(i, 15, b, c, d, e, f, g, h, a, X);
     151          }
     152  
     153          ctx->h[0] += a;
     154          ctx->h[1] += b;
     155          ctx->h[2] += c;
     156          ctx->h[3] += d;
     157          ctx->h[4] += e;
     158          ctx->h[5] += f;
     159          ctx->h[6] += g;
     160          ctx->h[7] += h;
     161  
     162          W += SHA_LBLOCK;
     163      }
     164  }