Lines Matching refs:s0
4622 int64_t s0 = kBottom21Bits & load_3(s); in x25519_sc_reduce() local
4787 s0 += s12 * 666643; in x25519_sc_reduce()
4795 carry0 = (s0 + (1 << 20)) >> 21; in x25519_sc_reduce()
4797 s0 -= carry0 * (1 << 21); in x25519_sc_reduce()
4833 s0 += s12 * 666643; in x25519_sc_reduce()
4841 carry0 = s0 >> 21; in x25519_sc_reduce()
4843 s0 -= carry0 * (1 << 21); in x25519_sc_reduce()
4878 s0 += s12 * 666643; in x25519_sc_reduce()
4886 carry0 = s0 >> 21; in x25519_sc_reduce()
4888 s0 -= carry0 * (1 << 21); in x25519_sc_reduce()
4920 s[ 0] = (uint8_t) (s0 >> 0); in x25519_sc_reduce()
4921 s[ 1] = (uint8_t) (s0 >> 8); in x25519_sc_reduce()
4922 s[ 2] = (uint8_t)((s0 >> 16) | (s1 << 5)); in x25519_sc_reduce()
5003 int64_t s0; in sc_muladd() local
5051 s0 = c0 + a0 * b0; in sc_muladd()
5076 carry0 = (s0 + (1 << 20)) >> 21; in sc_muladd()
5078 s0 -= carry0 * (1 << 21); in sc_muladd()
5270 s0 += s12 * 666643; in sc_muladd()
5278 carry0 = (s0 + (1 << 20)) >> 21; in sc_muladd()
5280 s0 -= carry0 * (1 << 21); in sc_muladd()
5316 s0 += s12 * 666643; in sc_muladd()
5324 carry0 = s0 >> 21; in sc_muladd()
5326 s0 -= carry0 * (1 << 21); in sc_muladd()
5361 s0 += s12 * 666643; in sc_muladd()
5369 carry0 = s0 >> 21; in sc_muladd()
5371 s0 -= carry0 * (1 << 21); in sc_muladd()
5403 s[ 0] = (uint8_t) (s0 >> 0); in sc_muladd()
5404 s[ 1] = (uint8_t) (s0 >> 8); in sc_muladd()
5405 s[ 2] = (uint8_t)((s0 >> 16) | (s1 << 5)); in sc_muladd()