Lines Matching refs:s0
4627 int64_t s0 = kBottom21Bits & load_3(s); in x25519_sc_reduce() local
4792 s0 += s12 * 666643; in x25519_sc_reduce()
4800 carry0 = (s0 + (1 << 20)) >> 21; in x25519_sc_reduce()
4802 s0 -= carry0 * (1 << 21); in x25519_sc_reduce()
4838 s0 += s12 * 666643; in x25519_sc_reduce()
4846 carry0 = s0 >> 21; in x25519_sc_reduce()
4848 s0 -= carry0 * (1 << 21); in x25519_sc_reduce()
4883 s0 += s12 * 666643; in x25519_sc_reduce()
4891 carry0 = s0 >> 21; in x25519_sc_reduce()
4893 s0 -= carry0 * (1 << 21); in x25519_sc_reduce()
4925 s[ 0] = (uint8_t) (s0 >> 0); in x25519_sc_reduce()
4926 s[ 1] = (uint8_t) (s0 >> 8); in x25519_sc_reduce()
4927 s[ 2] = (uint8_t)((s0 >> 16) | (s1 << 5)); in x25519_sc_reduce()
5008 int64_t s0; in sc_muladd() local
5056 s0 = c0 + a0 * b0; in sc_muladd()
5081 carry0 = (s0 + (1 << 20)) >> 21; in sc_muladd()
5083 s0 -= carry0 * (1 << 21); in sc_muladd()
5275 s0 += s12 * 666643; in sc_muladd()
5283 carry0 = (s0 + (1 << 20)) >> 21; in sc_muladd()
5285 s0 -= carry0 * (1 << 21); in sc_muladd()
5321 s0 += s12 * 666643; in sc_muladd()
5329 carry0 = s0 >> 21; in sc_muladd()
5331 s0 -= carry0 * (1 << 21); in sc_muladd()
5366 s0 += s12 * 666643; in sc_muladd()
5374 carry0 = s0 >> 21; in sc_muladd()
5376 s0 -= carry0 * (1 << 21); in sc_muladd()
5408 s[ 0] = (uint8_t) (s0 >> 0); in sc_muladd()
5409 s[ 1] = (uint8_t) (s0 >> 8); in sc_muladd()
5410 s[ 2] = (uint8_t)((s0 >> 16) | (s1 << 5)); in sc_muladd()