Lines Matching refs:s6

4628     int64_t s6  = kBottom21Bits & (load_4(s + 15) >> 6);  in x25519_sc_reduce()  local
4704 s6 += s18 * 666643; in x25519_sc_reduce()
4712 carry6 = (s6 + (1 << 20)) >> 21; in x25519_sc_reduce()
4714 s6 -= carry6 * (1 << 21); in x25519_sc_reduce()
4748 s6 += s17 * 470296; in x25519_sc_reduce()
4757 s6 += s16 * 654183; in x25519_sc_reduce()
4766 s6 -= s15 * 997805; in x25519_sc_reduce()
4775 s6 += s14 * 136657; in x25519_sc_reduce()
4784 s6 -= s13 * 683901; in x25519_sc_reduce()
4804 carry6 = (s6 + (1 << 20)) >> 21; in x25519_sc_reduce()
4806 s6 -= carry6 * (1 << 21); in x25519_sc_reduce()
4821 s6 += carry5; in x25519_sc_reduce()
4857 s6 += carry5; in x25519_sc_reduce()
4859 carry6 = s6 >> 21; in x25519_sc_reduce()
4861 s6 -= carry6 * (1 << 21); in x25519_sc_reduce()
4902 s6 += carry5; in x25519_sc_reduce()
4904 carry6 = s6 >> 21; in x25519_sc_reduce()
4906 s6 -= carry6 * (1 << 21); in x25519_sc_reduce()
4935 s[15] = (uint8_t)((s5 >> 15) | (s6 << 6)); in x25519_sc_reduce()
4936 s[16] = (uint8_t) (s6 >> 2); in x25519_sc_reduce()
4937 s[17] = (uint8_t) (s6 >> 10); in x25519_sc_reduce()
4938 s[18] = (uint8_t)((s6 >> 18) | (s7 << 3)); in x25519_sc_reduce()
5009 int64_t s6; in sc_muladd() local
5057s6 = c6 + a0 * b6 + a1 * b5 + a2 * b4 + a3 * b3 + a4 * b2 + a5 * b1 + a6 *… in sc_muladd()
5085 carry6 = (s6 + (1 << 20)) >> 21; in sc_muladd()
5087 s6 -= carry6 * (1 << 21); in sc_muladd()
5120 s6 += carry5; in sc_muladd()
5187 s6 += s18 * 666643; in sc_muladd()
5195 carry6 = (s6 + (1 << 20)) >> 21; in sc_muladd()
5197 s6 -= carry6 * (1 << 21); in sc_muladd()
5231 s6 += s17 * 470296; in sc_muladd()
5240 s6 += s16 * 654183; in sc_muladd()
5249 s6 -= s15 * 997805; in sc_muladd()
5258 s6 += s14 * 136657; in sc_muladd()
5267 s6 -= s13 * 683901; in sc_muladd()
5287 carry6 = (s6 + (1 << 20)) >> 21; in sc_muladd()
5289 s6 -= carry6 * (1 << 21); in sc_muladd()
5304 s6 += carry5; in sc_muladd()
5340 s6 += carry5; in sc_muladd()
5342 carry6 = s6 >> 21; in sc_muladd()
5344 s6 -= carry6 * (1 << 21); in sc_muladd()
5385 s6 += carry5; in sc_muladd()
5387 carry6 = s6 >> 21; in sc_muladd()
5389 s6 -= carry6 * (1 << 21); in sc_muladd()
5418 s[15] = (uint8_t)((s5 >> 15) | (s6 << 6)); in sc_muladd()
5419 s[16] = (uint8_t) (s6 >> 2); in sc_muladd()
5420 s[17] = (uint8_t) (s6 >> 10); in sc_muladd()
5421 s[18] = (uint8_t)((s6 >> 18) | (s7 << 3)); in sc_muladd()