aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGravatar Jason Gross <jgross@mit.edu>2019-03-31 14:35:38 -0400
committerGravatar Jason Gross <jgross@mit.edu>2019-03-31 14:35:38 -0400
commit31d31d23fbb6c9b3b7f01bd270cf72328f754594 (patch)
tree8fdff5cec563c20c0e504eb8001bc5271f04b91a
parentbcc7a5f7d3a15c2e8770a530ed3fa0ec45b60725 (diff)
Rebuild .c files
It seems some commutativity has changed
-rw-r--r--curve25519_32.c20
-rw-r--r--curve25519_64.c10
-rw-r--r--p224_32.c1034
-rw-r--r--p224_64.c376
-rw-r--r--p256_32.c1254
-rw-r--r--p256_64.c344
-rw-r--r--p384_32.c3108
-rw-r--r--p384_64.c888
-rw-r--r--p434_64.c1168
-rw-r--r--p448_solinas_64.c16
-rw-r--r--p521_32.c34
-rw-r--r--p521_64.c18
-rw-r--r--secp256k1_32.c1540
-rw-r--r--secp256k1_64.c412
14 files changed, 5111 insertions, 5111 deletions
diff --git a/curve25519_32.c b/curve25519_32.c
index 4d4565689..7daf46a51 100644
--- a/curve25519_32.c
+++ b/curve25519_32.c
@@ -741,34 +741,34 @@ static void fiat_25519_to_bytes(uint8_t out1[32], const uint32_t arg1[10]) {
fiat_25519_cmovznz_u32(&x21, x20, 0x0, UINT32_C(0xffffffff));
uint32_t x22;
fiat_25519_uint1 x23;
- fiat_25519_addcarryx_u26(&x22, &x23, 0x0, (x21 & UINT32_C(0x3ffffed)), x1);
+ fiat_25519_addcarryx_u26(&x22, &x23, 0x0, x1, (x21 & UINT32_C(0x3ffffed)));
uint32_t x24;
fiat_25519_uint1 x25;
- fiat_25519_addcarryx_u25(&x24, &x25, x23, (x21 & UINT32_C(0x1ffffff)), x3);
+ fiat_25519_addcarryx_u25(&x24, &x25, x23, x3, (x21 & UINT32_C(0x1ffffff)));
uint32_t x26;
fiat_25519_uint1 x27;
- fiat_25519_addcarryx_u26(&x26, &x27, x25, (x21 & UINT32_C(0x3ffffff)), x5);
+ fiat_25519_addcarryx_u26(&x26, &x27, x25, x5, (x21 & UINT32_C(0x3ffffff)));
uint32_t x28;
fiat_25519_uint1 x29;
- fiat_25519_addcarryx_u25(&x28, &x29, x27, (x21 & UINT32_C(0x1ffffff)), x7);
+ fiat_25519_addcarryx_u25(&x28, &x29, x27, x7, (x21 & UINT32_C(0x1ffffff)));
uint32_t x30;
fiat_25519_uint1 x31;
- fiat_25519_addcarryx_u26(&x30, &x31, x29, (x21 & UINT32_C(0x3ffffff)), x9);
+ fiat_25519_addcarryx_u26(&x30, &x31, x29, x9, (x21 & UINT32_C(0x3ffffff)));
uint32_t x32;
fiat_25519_uint1 x33;
- fiat_25519_addcarryx_u25(&x32, &x33, x31, (x21 & UINT32_C(0x1ffffff)), x11);
+ fiat_25519_addcarryx_u25(&x32, &x33, x31, x11, (x21 & UINT32_C(0x1ffffff)));
uint32_t x34;
fiat_25519_uint1 x35;
- fiat_25519_addcarryx_u26(&x34, &x35, x33, (x21 & UINT32_C(0x3ffffff)), x13);
+ fiat_25519_addcarryx_u26(&x34, &x35, x33, x13, (x21 & UINT32_C(0x3ffffff)));
uint32_t x36;
fiat_25519_uint1 x37;
- fiat_25519_addcarryx_u25(&x36, &x37, x35, (x21 & UINT32_C(0x1ffffff)), x15);
+ fiat_25519_addcarryx_u25(&x36, &x37, x35, x15, (x21 & UINT32_C(0x1ffffff)));
uint32_t x38;
fiat_25519_uint1 x39;
- fiat_25519_addcarryx_u26(&x38, &x39, x37, (x21 & UINT32_C(0x3ffffff)), x17);
+ fiat_25519_addcarryx_u26(&x38, &x39, x37, x17, (x21 & UINT32_C(0x3ffffff)));
uint32_t x40;
fiat_25519_uint1 x41;
- fiat_25519_addcarryx_u25(&x40, &x41, x39, (x21 & UINT32_C(0x1ffffff)), x19);
+ fiat_25519_addcarryx_u25(&x40, &x41, x39, x19, (x21 & UINT32_C(0x1ffffff)));
uint32_t x42 = (x40 << 6);
uint32_t x43 = (x38 << 4);
uint32_t x44 = (x36 << 3);
diff --git a/curve25519_64.c b/curve25519_64.c
index 5341181f6..37aae3b84 100644
--- a/curve25519_64.c
+++ b/curve25519_64.c
@@ -424,19 +424,19 @@ static void fiat_25519_to_bytes(uint8_t out1[32], const uint64_t arg1[5]) {
fiat_25519_cmovznz_u64(&x11, x10, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x12;
fiat_25519_uint1 x13;
- fiat_25519_addcarryx_u51(&x12, &x13, 0x0, (x11 & UINT64_C(0x7ffffffffffed)), x1);
+ fiat_25519_addcarryx_u51(&x12, &x13, 0x0, x1, (x11 & UINT64_C(0x7ffffffffffed)));
uint64_t x14;
fiat_25519_uint1 x15;
- fiat_25519_addcarryx_u51(&x14, &x15, x13, (x11 & UINT64_C(0x7ffffffffffff)), x3);
+ fiat_25519_addcarryx_u51(&x14, &x15, x13, x3, (x11 & UINT64_C(0x7ffffffffffff)));
uint64_t x16;
fiat_25519_uint1 x17;
- fiat_25519_addcarryx_u51(&x16, &x17, x15, (x11 & UINT64_C(0x7ffffffffffff)), x5);
+ fiat_25519_addcarryx_u51(&x16, &x17, x15, x5, (x11 & UINT64_C(0x7ffffffffffff)));
uint64_t x18;
fiat_25519_uint1 x19;
- fiat_25519_addcarryx_u51(&x18, &x19, x17, (x11 & UINT64_C(0x7ffffffffffff)), x7);
+ fiat_25519_addcarryx_u51(&x18, &x19, x17, x7, (x11 & UINT64_C(0x7ffffffffffff)));
uint64_t x20;
fiat_25519_uint1 x21;
- fiat_25519_addcarryx_u51(&x20, &x21, x19, (x11 & UINT64_C(0x7ffffffffffff)), x9);
+ fiat_25519_addcarryx_u51(&x20, &x21, x19, x9, (x11 & UINT64_C(0x7ffffffffffff)));
uint64_t x22 = (x20 << 4);
uint64_t x23 = (x18 * (uint64_t)0x2);
uint64_t x24 = (x16 << 6);
diff --git a/p224_32.c b/p224_32.c
index 1341276cb..0e0b6ad67 100644
--- a/p224_32.c
+++ b/p224_32.c
@@ -146,25 +146,25 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x20, &x21, x7, (arg2[0]));
uint32_t x22;
fiat_p224_uint1 x23;
- fiat_p224_addcarryx_u32(&x22, &x23, 0x0, x18, x21);
+ fiat_p224_addcarryx_u32(&x22, &x23, 0x0, x21, x18);
uint32_t x24;
fiat_p224_uint1 x25;
- fiat_p224_addcarryx_u32(&x24, &x25, x23, x16, x19);
+ fiat_p224_addcarryx_u32(&x24, &x25, x23, x19, x16);
uint32_t x26;
fiat_p224_uint1 x27;
- fiat_p224_addcarryx_u32(&x26, &x27, x25, x14, x17);
+ fiat_p224_addcarryx_u32(&x26, &x27, x25, x17, x14);
uint32_t x28;
fiat_p224_uint1 x29;
- fiat_p224_addcarryx_u32(&x28, &x29, x27, x12, x15);
+ fiat_p224_addcarryx_u32(&x28, &x29, x27, x15, x12);
uint32_t x30;
fiat_p224_uint1 x31;
- fiat_p224_addcarryx_u32(&x30, &x31, x29, x10, x13);
+ fiat_p224_addcarryx_u32(&x30, &x31, x29, x13, x10);
uint32_t x32;
fiat_p224_uint1 x33;
- fiat_p224_addcarryx_u32(&x32, &x33, x31, x8, x11);
+ fiat_p224_addcarryx_u32(&x32, &x33, x31, x11, x8);
uint32_t x34;
fiat_p224_uint1 x35;
- fiat_p224_addcarryx_u32(&x34, &x35, x33, 0x0, x9);
+ fiat_p224_addcarryx_u32(&x34, &x35, x33, x9, 0x0);
uint32_t x36;
uint32_t x37;
fiat_p224_mulx_u32(&x36, &x37, x20, UINT32_C(0xffffffff));
@@ -182,40 +182,40 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x44, &x45, x36, UINT32_C(0xffffffff));
uint32_t x46;
fiat_p224_uint1 x47;
- fiat_p224_addcarryx_u32(&x46, &x47, 0x0, x42, x45);
+ fiat_p224_addcarryx_u32(&x46, &x47, 0x0, x45, x42);
uint32_t x48;
fiat_p224_uint1 x49;
- fiat_p224_addcarryx_u32(&x48, &x49, x47, x40, x43);
+ fiat_p224_addcarryx_u32(&x48, &x49, x47, x43, x40);
uint32_t x50;
fiat_p224_uint1 x51;
- fiat_p224_addcarryx_u32(&x50, &x51, x49, x38, x41);
+ fiat_p224_addcarryx_u32(&x50, &x51, x49, x41, x38);
uint32_t x52;
fiat_p224_uint1 x53;
- fiat_p224_addcarryx_u32(&x52, &x53, x51, 0x0, x39);
+ fiat_p224_addcarryx_u32(&x52, &x53, x51, x39, 0x0);
uint32_t x54;
fiat_p224_uint1 x55;
- fiat_p224_addcarryx_u32(&x54, &x55, 0x0, x36, x20);
+ fiat_p224_addcarryx_u32(&x54, &x55, 0x0, x20, x36);
uint32_t x56;
fiat_p224_uint1 x57;
- fiat_p224_addcarryx_u32(&x56, &x57, x55, 0x0, x22);
+ fiat_p224_addcarryx_u32(&x56, &x57, x55, x22, 0x0);
uint32_t x58;
fiat_p224_uint1 x59;
- fiat_p224_addcarryx_u32(&x58, &x59, x57, 0x0, x24);
+ fiat_p224_addcarryx_u32(&x58, &x59, x57, x24, 0x0);
uint32_t x60;
fiat_p224_uint1 x61;
- fiat_p224_addcarryx_u32(&x60, &x61, x59, x44, x26);
+ fiat_p224_addcarryx_u32(&x60, &x61, x59, x26, x44);
uint32_t x62;
fiat_p224_uint1 x63;
- fiat_p224_addcarryx_u32(&x62, &x63, x61, x46, x28);
+ fiat_p224_addcarryx_u32(&x62, &x63, x61, x28, x46);
uint32_t x64;
fiat_p224_uint1 x65;
- fiat_p224_addcarryx_u32(&x64, &x65, x63, x48, x30);
+ fiat_p224_addcarryx_u32(&x64, &x65, x63, x30, x48);
uint32_t x66;
fiat_p224_uint1 x67;
- fiat_p224_addcarryx_u32(&x66, &x67, x65, x50, x32);
+ fiat_p224_addcarryx_u32(&x66, &x67, x65, x32, x50);
uint32_t x68;
fiat_p224_uint1 x69;
- fiat_p224_addcarryx_u32(&x68, &x69, x67, x52, x34);
+ fiat_p224_addcarryx_u32(&x68, &x69, x67, x34, x52);
uint32_t x70;
fiat_p224_uint1 x71;
fiat_p224_addcarryx_u32(&x70, &x71, x69, 0x0, 0x0);
@@ -242,49 +242,49 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x84, &x85, x1, (arg2[0]));
uint32_t x86;
fiat_p224_uint1 x87;
- fiat_p224_addcarryx_u32(&x86, &x87, 0x0, x82, x85);
+ fiat_p224_addcarryx_u32(&x86, &x87, 0x0, x85, x82);
uint32_t x88;
fiat_p224_uint1 x89;
- fiat_p224_addcarryx_u32(&x88, &x89, x87, x80, x83);
+ fiat_p224_addcarryx_u32(&x88, &x89, x87, x83, x80);
uint32_t x90;
fiat_p224_uint1 x91;
- fiat_p224_addcarryx_u32(&x90, &x91, x89, x78, x81);
+ fiat_p224_addcarryx_u32(&x90, &x91, x89, x81, x78);
uint32_t x92;
fiat_p224_uint1 x93;
- fiat_p224_addcarryx_u32(&x92, &x93, x91, x76, x79);
+ fiat_p224_addcarryx_u32(&x92, &x93, x91, x79, x76);
uint32_t x94;
fiat_p224_uint1 x95;
- fiat_p224_addcarryx_u32(&x94, &x95, x93, x74, x77);
+ fiat_p224_addcarryx_u32(&x94, &x95, x93, x77, x74);
uint32_t x96;
fiat_p224_uint1 x97;
- fiat_p224_addcarryx_u32(&x96, &x97, x95, x72, x75);
+ fiat_p224_addcarryx_u32(&x96, &x97, x95, x75, x72);
uint32_t x98;
fiat_p224_uint1 x99;
- fiat_p224_addcarryx_u32(&x98, &x99, x97, 0x0, x73);
+ fiat_p224_addcarryx_u32(&x98, &x99, x97, x73, 0x0);
uint32_t x100;
fiat_p224_uint1 x101;
- fiat_p224_addcarryx_u32(&x100, &x101, 0x0, x84, x56);
+ fiat_p224_addcarryx_u32(&x100, &x101, 0x0, x56, x84);
uint32_t x102;
fiat_p224_uint1 x103;
- fiat_p224_addcarryx_u32(&x102, &x103, x101, x86, x58);
+ fiat_p224_addcarryx_u32(&x102, &x103, x101, x58, x86);
uint32_t x104;
fiat_p224_uint1 x105;
- fiat_p224_addcarryx_u32(&x104, &x105, x103, x88, x60);
+ fiat_p224_addcarryx_u32(&x104, &x105, x103, x60, x88);
uint32_t x106;
fiat_p224_uint1 x107;
- fiat_p224_addcarryx_u32(&x106, &x107, x105, x90, x62);
+ fiat_p224_addcarryx_u32(&x106, &x107, x105, x62, x90);
uint32_t x108;
fiat_p224_uint1 x109;
- fiat_p224_addcarryx_u32(&x108, &x109, x107, x92, x64);
+ fiat_p224_addcarryx_u32(&x108, &x109, x107, x64, x92);
uint32_t x110;
fiat_p224_uint1 x111;
- fiat_p224_addcarryx_u32(&x110, &x111, x109, x94, x66);
+ fiat_p224_addcarryx_u32(&x110, &x111, x109, x66, x94);
uint32_t x112;
fiat_p224_uint1 x113;
- fiat_p224_addcarryx_u32(&x112, &x113, x111, x96, x68);
+ fiat_p224_addcarryx_u32(&x112, &x113, x111, x68, x96);
uint32_t x114;
fiat_p224_uint1 x115;
- fiat_p224_addcarryx_u32(&x114, &x115, x113, x98, (fiat_p224_uint1)x70);
+ fiat_p224_addcarryx_u32(&x114, &x115, x113, (fiat_p224_uint1)x70, x98);
uint32_t x116;
uint32_t x117;
fiat_p224_mulx_u32(&x116, &x117, x100, UINT32_C(0xffffffff));
@@ -302,43 +302,43 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x124, &x125, x116, UINT32_C(0xffffffff));
uint32_t x126;
fiat_p224_uint1 x127;
- fiat_p224_addcarryx_u32(&x126, &x127, 0x0, x122, x125);
+ fiat_p224_addcarryx_u32(&x126, &x127, 0x0, x125, x122);
uint32_t x128;
fiat_p224_uint1 x129;
- fiat_p224_addcarryx_u32(&x128, &x129, x127, x120, x123);
+ fiat_p224_addcarryx_u32(&x128, &x129, x127, x123, x120);
uint32_t x130;
fiat_p224_uint1 x131;
- fiat_p224_addcarryx_u32(&x130, &x131, x129, x118, x121);
+ fiat_p224_addcarryx_u32(&x130, &x131, x129, x121, x118);
uint32_t x132;
fiat_p224_uint1 x133;
- fiat_p224_addcarryx_u32(&x132, &x133, x131, 0x0, x119);
+ fiat_p224_addcarryx_u32(&x132, &x133, x131, x119, 0x0);
uint32_t x134;
fiat_p224_uint1 x135;
- fiat_p224_addcarryx_u32(&x134, &x135, 0x0, x116, x100);
+ fiat_p224_addcarryx_u32(&x134, &x135, 0x0, x100, x116);
uint32_t x136;
fiat_p224_uint1 x137;
- fiat_p224_addcarryx_u32(&x136, &x137, x135, 0x0, x102);
+ fiat_p224_addcarryx_u32(&x136, &x137, x135, x102, 0x0);
uint32_t x138;
fiat_p224_uint1 x139;
- fiat_p224_addcarryx_u32(&x138, &x139, x137, 0x0, x104);
+ fiat_p224_addcarryx_u32(&x138, &x139, x137, x104, 0x0);
uint32_t x140;
fiat_p224_uint1 x141;
- fiat_p224_addcarryx_u32(&x140, &x141, x139, x124, x106);
+ fiat_p224_addcarryx_u32(&x140, &x141, x139, x106, x124);
uint32_t x142;
fiat_p224_uint1 x143;
- fiat_p224_addcarryx_u32(&x142, &x143, x141, x126, x108);
+ fiat_p224_addcarryx_u32(&x142, &x143, x141, x108, x126);
uint32_t x144;
fiat_p224_uint1 x145;
- fiat_p224_addcarryx_u32(&x144, &x145, x143, x128, x110);
+ fiat_p224_addcarryx_u32(&x144, &x145, x143, x110, x128);
uint32_t x146;
fiat_p224_uint1 x147;
- fiat_p224_addcarryx_u32(&x146, &x147, x145, x130, x112);
+ fiat_p224_addcarryx_u32(&x146, &x147, x145, x112, x130);
uint32_t x148;
fiat_p224_uint1 x149;
- fiat_p224_addcarryx_u32(&x148, &x149, x147, x132, x114);
+ fiat_p224_addcarryx_u32(&x148, &x149, x147, x114, x132);
uint32_t x150;
fiat_p224_uint1 x151;
- fiat_p224_addcarryx_u32(&x150, &x151, x149, 0x0, x115);
+ fiat_p224_addcarryx_u32(&x150, &x151, x149, x115, 0x0);
uint32_t x152;
uint32_t x153;
fiat_p224_mulx_u32(&x152, &x153, x2, (arg2[6]));
@@ -362,49 +362,49 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x164, &x165, x2, (arg2[0]));
uint32_t x166;
fiat_p224_uint1 x167;
- fiat_p224_addcarryx_u32(&x166, &x167, 0x0, x162, x165);
+ fiat_p224_addcarryx_u32(&x166, &x167, 0x0, x165, x162);
uint32_t x168;
fiat_p224_uint1 x169;
- fiat_p224_addcarryx_u32(&x168, &x169, x167, x160, x163);
+ fiat_p224_addcarryx_u32(&x168, &x169, x167, x163, x160);
uint32_t x170;
fiat_p224_uint1 x171;
- fiat_p224_addcarryx_u32(&x170, &x171, x169, x158, x161);
+ fiat_p224_addcarryx_u32(&x170, &x171, x169, x161, x158);
uint32_t x172;
fiat_p224_uint1 x173;
- fiat_p224_addcarryx_u32(&x172, &x173, x171, x156, x159);
+ fiat_p224_addcarryx_u32(&x172, &x173, x171, x159, x156);
uint32_t x174;
fiat_p224_uint1 x175;
- fiat_p224_addcarryx_u32(&x174, &x175, x173, x154, x157);
+ fiat_p224_addcarryx_u32(&x174, &x175, x173, x157, x154);
uint32_t x176;
fiat_p224_uint1 x177;
- fiat_p224_addcarryx_u32(&x176, &x177, x175, x152, x155);
+ fiat_p224_addcarryx_u32(&x176, &x177, x175, x155, x152);
uint32_t x178;
fiat_p224_uint1 x179;
- fiat_p224_addcarryx_u32(&x178, &x179, x177, 0x0, x153);
+ fiat_p224_addcarryx_u32(&x178, &x179, x177, x153, 0x0);
uint32_t x180;
fiat_p224_uint1 x181;
- fiat_p224_addcarryx_u32(&x180, &x181, 0x0, x164, x136);
+ fiat_p224_addcarryx_u32(&x180, &x181, 0x0, x136, x164);
uint32_t x182;
fiat_p224_uint1 x183;
- fiat_p224_addcarryx_u32(&x182, &x183, x181, x166, x138);
+ fiat_p224_addcarryx_u32(&x182, &x183, x181, x138, x166);
uint32_t x184;
fiat_p224_uint1 x185;
- fiat_p224_addcarryx_u32(&x184, &x185, x183, x168, x140);
+ fiat_p224_addcarryx_u32(&x184, &x185, x183, x140, x168);
uint32_t x186;
fiat_p224_uint1 x187;
- fiat_p224_addcarryx_u32(&x186, &x187, x185, x170, x142);
+ fiat_p224_addcarryx_u32(&x186, &x187, x185, x142, x170);
uint32_t x188;
fiat_p224_uint1 x189;
- fiat_p224_addcarryx_u32(&x188, &x189, x187, x172, x144);
+ fiat_p224_addcarryx_u32(&x188, &x189, x187, x144, x172);
uint32_t x190;
fiat_p224_uint1 x191;
- fiat_p224_addcarryx_u32(&x190, &x191, x189, x174, x146);
+ fiat_p224_addcarryx_u32(&x190, &x191, x189, x146, x174);
uint32_t x192;
fiat_p224_uint1 x193;
- fiat_p224_addcarryx_u32(&x192, &x193, x191, x176, x148);
+ fiat_p224_addcarryx_u32(&x192, &x193, x191, x148, x176);
uint32_t x194;
fiat_p224_uint1 x195;
- fiat_p224_addcarryx_u32(&x194, &x195, x193, x178, x150);
+ fiat_p224_addcarryx_u32(&x194, &x195, x193, x150, x178);
uint32_t x196;
uint32_t x197;
fiat_p224_mulx_u32(&x196, &x197, x180, UINT32_C(0xffffffff));
@@ -422,43 +422,43 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x204, &x205, x196, UINT32_C(0xffffffff));
uint32_t x206;
fiat_p224_uint1 x207;
- fiat_p224_addcarryx_u32(&x206, &x207, 0x0, x202, x205);
+ fiat_p224_addcarryx_u32(&x206, &x207, 0x0, x205, x202);
uint32_t x208;
fiat_p224_uint1 x209;
- fiat_p224_addcarryx_u32(&x208, &x209, x207, x200, x203);
+ fiat_p224_addcarryx_u32(&x208, &x209, x207, x203, x200);
uint32_t x210;
fiat_p224_uint1 x211;
- fiat_p224_addcarryx_u32(&x210, &x211, x209, x198, x201);
+ fiat_p224_addcarryx_u32(&x210, &x211, x209, x201, x198);
uint32_t x212;
fiat_p224_uint1 x213;
- fiat_p224_addcarryx_u32(&x212, &x213, x211, 0x0, x199);
+ fiat_p224_addcarryx_u32(&x212, &x213, x211, x199, 0x0);
uint32_t x214;
fiat_p224_uint1 x215;
- fiat_p224_addcarryx_u32(&x214, &x215, 0x0, x196, x180);
+ fiat_p224_addcarryx_u32(&x214, &x215, 0x0, x180, x196);
uint32_t x216;
fiat_p224_uint1 x217;
- fiat_p224_addcarryx_u32(&x216, &x217, x215, 0x0, x182);
+ fiat_p224_addcarryx_u32(&x216, &x217, x215, x182, 0x0);
uint32_t x218;
fiat_p224_uint1 x219;
- fiat_p224_addcarryx_u32(&x218, &x219, x217, 0x0, x184);
+ fiat_p224_addcarryx_u32(&x218, &x219, x217, x184, 0x0);
uint32_t x220;
fiat_p224_uint1 x221;
- fiat_p224_addcarryx_u32(&x220, &x221, x219, x204, x186);
+ fiat_p224_addcarryx_u32(&x220, &x221, x219, x186, x204);
uint32_t x222;
fiat_p224_uint1 x223;
- fiat_p224_addcarryx_u32(&x222, &x223, x221, x206, x188);
+ fiat_p224_addcarryx_u32(&x222, &x223, x221, x188, x206);
uint32_t x224;
fiat_p224_uint1 x225;
- fiat_p224_addcarryx_u32(&x224, &x225, x223, x208, x190);
+ fiat_p224_addcarryx_u32(&x224, &x225, x223, x190, x208);
uint32_t x226;
fiat_p224_uint1 x227;
- fiat_p224_addcarryx_u32(&x226, &x227, x225, x210, x192);
+ fiat_p224_addcarryx_u32(&x226, &x227, x225, x192, x210);
uint32_t x228;
fiat_p224_uint1 x229;
- fiat_p224_addcarryx_u32(&x228, &x229, x227, x212, x194);
+ fiat_p224_addcarryx_u32(&x228, &x229, x227, x194, x212);
uint32_t x230;
fiat_p224_uint1 x231;
- fiat_p224_addcarryx_u32(&x230, &x231, x229, 0x0, x195);
+ fiat_p224_addcarryx_u32(&x230, &x231, x229, x195, 0x0);
uint32_t x232;
uint32_t x233;
fiat_p224_mulx_u32(&x232, &x233, x3, (arg2[6]));
@@ -482,49 +482,49 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x244, &x245, x3, (arg2[0]));
uint32_t x246;
fiat_p224_uint1 x247;
- fiat_p224_addcarryx_u32(&x246, &x247, 0x0, x242, x245);
+ fiat_p224_addcarryx_u32(&x246, &x247, 0x0, x245, x242);
uint32_t x248;
fiat_p224_uint1 x249;
- fiat_p224_addcarryx_u32(&x248, &x249, x247, x240, x243);
+ fiat_p224_addcarryx_u32(&x248, &x249, x247, x243, x240);
uint32_t x250;
fiat_p224_uint1 x251;
- fiat_p224_addcarryx_u32(&x250, &x251, x249, x238, x241);
+ fiat_p224_addcarryx_u32(&x250, &x251, x249, x241, x238);
uint32_t x252;
fiat_p224_uint1 x253;
- fiat_p224_addcarryx_u32(&x252, &x253, x251, x236, x239);
+ fiat_p224_addcarryx_u32(&x252, &x253, x251, x239, x236);
uint32_t x254;
fiat_p224_uint1 x255;
- fiat_p224_addcarryx_u32(&x254, &x255, x253, x234, x237);
+ fiat_p224_addcarryx_u32(&x254, &x255, x253, x237, x234);
uint32_t x256;
fiat_p224_uint1 x257;
- fiat_p224_addcarryx_u32(&x256, &x257, x255, x232, x235);
+ fiat_p224_addcarryx_u32(&x256, &x257, x255, x235, x232);
uint32_t x258;
fiat_p224_uint1 x259;
- fiat_p224_addcarryx_u32(&x258, &x259, x257, 0x0, x233);
+ fiat_p224_addcarryx_u32(&x258, &x259, x257, x233, 0x0);
uint32_t x260;
fiat_p224_uint1 x261;
- fiat_p224_addcarryx_u32(&x260, &x261, 0x0, x244, x216);
+ fiat_p224_addcarryx_u32(&x260, &x261, 0x0, x216, x244);
uint32_t x262;
fiat_p224_uint1 x263;
- fiat_p224_addcarryx_u32(&x262, &x263, x261, x246, x218);
+ fiat_p224_addcarryx_u32(&x262, &x263, x261, x218, x246);
uint32_t x264;
fiat_p224_uint1 x265;
- fiat_p224_addcarryx_u32(&x264, &x265, x263, x248, x220);
+ fiat_p224_addcarryx_u32(&x264, &x265, x263, x220, x248);
uint32_t x266;
fiat_p224_uint1 x267;
- fiat_p224_addcarryx_u32(&x266, &x267, x265, x250, x222);
+ fiat_p224_addcarryx_u32(&x266, &x267, x265, x222, x250);
uint32_t x268;
fiat_p224_uint1 x269;
- fiat_p224_addcarryx_u32(&x268, &x269, x267, x252, x224);
+ fiat_p224_addcarryx_u32(&x268, &x269, x267, x224, x252);
uint32_t x270;
fiat_p224_uint1 x271;
- fiat_p224_addcarryx_u32(&x270, &x271, x269, x254, x226);
+ fiat_p224_addcarryx_u32(&x270, &x271, x269, x226, x254);
uint32_t x272;
fiat_p224_uint1 x273;
- fiat_p224_addcarryx_u32(&x272, &x273, x271, x256, x228);
+ fiat_p224_addcarryx_u32(&x272, &x273, x271, x228, x256);
uint32_t x274;
fiat_p224_uint1 x275;
- fiat_p224_addcarryx_u32(&x274, &x275, x273, x258, x230);
+ fiat_p224_addcarryx_u32(&x274, &x275, x273, x230, x258);
uint32_t x276;
uint32_t x277;
fiat_p224_mulx_u32(&x276, &x277, x260, UINT32_C(0xffffffff));
@@ -542,43 +542,43 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x284, &x285, x276, UINT32_C(0xffffffff));
uint32_t x286;
fiat_p224_uint1 x287;
- fiat_p224_addcarryx_u32(&x286, &x287, 0x0, x282, x285);
+ fiat_p224_addcarryx_u32(&x286, &x287, 0x0, x285, x282);
uint32_t x288;
fiat_p224_uint1 x289;
- fiat_p224_addcarryx_u32(&x288, &x289, x287, x280, x283);
+ fiat_p224_addcarryx_u32(&x288, &x289, x287, x283, x280);
uint32_t x290;
fiat_p224_uint1 x291;
- fiat_p224_addcarryx_u32(&x290, &x291, x289, x278, x281);
+ fiat_p224_addcarryx_u32(&x290, &x291, x289, x281, x278);
uint32_t x292;
fiat_p224_uint1 x293;
- fiat_p224_addcarryx_u32(&x292, &x293, x291, 0x0, x279);
+ fiat_p224_addcarryx_u32(&x292, &x293, x291, x279, 0x0);
uint32_t x294;
fiat_p224_uint1 x295;
- fiat_p224_addcarryx_u32(&x294, &x295, 0x0, x276, x260);
+ fiat_p224_addcarryx_u32(&x294, &x295, 0x0, x260, x276);
uint32_t x296;
fiat_p224_uint1 x297;
- fiat_p224_addcarryx_u32(&x296, &x297, x295, 0x0, x262);
+ fiat_p224_addcarryx_u32(&x296, &x297, x295, x262, 0x0);
uint32_t x298;
fiat_p224_uint1 x299;
- fiat_p224_addcarryx_u32(&x298, &x299, x297, 0x0, x264);
+ fiat_p224_addcarryx_u32(&x298, &x299, x297, x264, 0x0);
uint32_t x300;
fiat_p224_uint1 x301;
- fiat_p224_addcarryx_u32(&x300, &x301, x299, x284, x266);
+ fiat_p224_addcarryx_u32(&x300, &x301, x299, x266, x284);
uint32_t x302;
fiat_p224_uint1 x303;
- fiat_p224_addcarryx_u32(&x302, &x303, x301, x286, x268);
+ fiat_p224_addcarryx_u32(&x302, &x303, x301, x268, x286);
uint32_t x304;
fiat_p224_uint1 x305;
- fiat_p224_addcarryx_u32(&x304, &x305, x303, x288, x270);
+ fiat_p224_addcarryx_u32(&x304, &x305, x303, x270, x288);
uint32_t x306;
fiat_p224_uint1 x307;
- fiat_p224_addcarryx_u32(&x306, &x307, x305, x290, x272);
+ fiat_p224_addcarryx_u32(&x306, &x307, x305, x272, x290);
uint32_t x308;
fiat_p224_uint1 x309;
- fiat_p224_addcarryx_u32(&x308, &x309, x307, x292, x274);
+ fiat_p224_addcarryx_u32(&x308, &x309, x307, x274, x292);
uint32_t x310;
fiat_p224_uint1 x311;
- fiat_p224_addcarryx_u32(&x310, &x311, x309, 0x0, x275);
+ fiat_p224_addcarryx_u32(&x310, &x311, x309, x275, 0x0);
uint32_t x312;
uint32_t x313;
fiat_p224_mulx_u32(&x312, &x313, x4, (arg2[6]));
@@ -602,49 +602,49 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x324, &x325, x4, (arg2[0]));
uint32_t x326;
fiat_p224_uint1 x327;
- fiat_p224_addcarryx_u32(&x326, &x327, 0x0, x322, x325);
+ fiat_p224_addcarryx_u32(&x326, &x327, 0x0, x325, x322);
uint32_t x328;
fiat_p224_uint1 x329;
- fiat_p224_addcarryx_u32(&x328, &x329, x327, x320, x323);
+ fiat_p224_addcarryx_u32(&x328, &x329, x327, x323, x320);
uint32_t x330;
fiat_p224_uint1 x331;
- fiat_p224_addcarryx_u32(&x330, &x331, x329, x318, x321);
+ fiat_p224_addcarryx_u32(&x330, &x331, x329, x321, x318);
uint32_t x332;
fiat_p224_uint1 x333;
- fiat_p224_addcarryx_u32(&x332, &x333, x331, x316, x319);
+ fiat_p224_addcarryx_u32(&x332, &x333, x331, x319, x316);
uint32_t x334;
fiat_p224_uint1 x335;
- fiat_p224_addcarryx_u32(&x334, &x335, x333, x314, x317);
+ fiat_p224_addcarryx_u32(&x334, &x335, x333, x317, x314);
uint32_t x336;
fiat_p224_uint1 x337;
- fiat_p224_addcarryx_u32(&x336, &x337, x335, x312, x315);
+ fiat_p224_addcarryx_u32(&x336, &x337, x335, x315, x312);
uint32_t x338;
fiat_p224_uint1 x339;
- fiat_p224_addcarryx_u32(&x338, &x339, x337, 0x0, x313);
+ fiat_p224_addcarryx_u32(&x338, &x339, x337, x313, 0x0);
uint32_t x340;
fiat_p224_uint1 x341;
- fiat_p224_addcarryx_u32(&x340, &x341, 0x0, x324, x296);
+ fiat_p224_addcarryx_u32(&x340, &x341, 0x0, x296, x324);
uint32_t x342;
fiat_p224_uint1 x343;
- fiat_p224_addcarryx_u32(&x342, &x343, x341, x326, x298);
+ fiat_p224_addcarryx_u32(&x342, &x343, x341, x298, x326);
uint32_t x344;
fiat_p224_uint1 x345;
- fiat_p224_addcarryx_u32(&x344, &x345, x343, x328, x300);
+ fiat_p224_addcarryx_u32(&x344, &x345, x343, x300, x328);
uint32_t x346;
fiat_p224_uint1 x347;
- fiat_p224_addcarryx_u32(&x346, &x347, x345, x330, x302);
+ fiat_p224_addcarryx_u32(&x346, &x347, x345, x302, x330);
uint32_t x348;
fiat_p224_uint1 x349;
- fiat_p224_addcarryx_u32(&x348, &x349, x347, x332, x304);
+ fiat_p224_addcarryx_u32(&x348, &x349, x347, x304, x332);
uint32_t x350;
fiat_p224_uint1 x351;
- fiat_p224_addcarryx_u32(&x350, &x351, x349, x334, x306);
+ fiat_p224_addcarryx_u32(&x350, &x351, x349, x306, x334);
uint32_t x352;
fiat_p224_uint1 x353;
- fiat_p224_addcarryx_u32(&x352, &x353, x351, x336, x308);
+ fiat_p224_addcarryx_u32(&x352, &x353, x351, x308, x336);
uint32_t x354;
fiat_p224_uint1 x355;
- fiat_p224_addcarryx_u32(&x354, &x355, x353, x338, x310);
+ fiat_p224_addcarryx_u32(&x354, &x355, x353, x310, x338);
uint32_t x356;
uint32_t x357;
fiat_p224_mulx_u32(&x356, &x357, x340, UINT32_C(0xffffffff));
@@ -662,43 +662,43 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x364, &x365, x356, UINT32_C(0xffffffff));
uint32_t x366;
fiat_p224_uint1 x367;
- fiat_p224_addcarryx_u32(&x366, &x367, 0x0, x362, x365);
+ fiat_p224_addcarryx_u32(&x366, &x367, 0x0, x365, x362);
uint32_t x368;
fiat_p224_uint1 x369;
- fiat_p224_addcarryx_u32(&x368, &x369, x367, x360, x363);
+ fiat_p224_addcarryx_u32(&x368, &x369, x367, x363, x360);
uint32_t x370;
fiat_p224_uint1 x371;
- fiat_p224_addcarryx_u32(&x370, &x371, x369, x358, x361);
+ fiat_p224_addcarryx_u32(&x370, &x371, x369, x361, x358);
uint32_t x372;
fiat_p224_uint1 x373;
- fiat_p224_addcarryx_u32(&x372, &x373, x371, 0x0, x359);
+ fiat_p224_addcarryx_u32(&x372, &x373, x371, x359, 0x0);
uint32_t x374;
fiat_p224_uint1 x375;
- fiat_p224_addcarryx_u32(&x374, &x375, 0x0, x356, x340);
+ fiat_p224_addcarryx_u32(&x374, &x375, 0x0, x340, x356);
uint32_t x376;
fiat_p224_uint1 x377;
- fiat_p224_addcarryx_u32(&x376, &x377, x375, 0x0, x342);
+ fiat_p224_addcarryx_u32(&x376, &x377, x375, x342, 0x0);
uint32_t x378;
fiat_p224_uint1 x379;
- fiat_p224_addcarryx_u32(&x378, &x379, x377, 0x0, x344);
+ fiat_p224_addcarryx_u32(&x378, &x379, x377, x344, 0x0);
uint32_t x380;
fiat_p224_uint1 x381;
- fiat_p224_addcarryx_u32(&x380, &x381, x379, x364, x346);
+ fiat_p224_addcarryx_u32(&x380, &x381, x379, x346, x364);
uint32_t x382;
fiat_p224_uint1 x383;
- fiat_p224_addcarryx_u32(&x382, &x383, x381, x366, x348);
+ fiat_p224_addcarryx_u32(&x382, &x383, x381, x348, x366);
uint32_t x384;
fiat_p224_uint1 x385;
- fiat_p224_addcarryx_u32(&x384, &x385, x383, x368, x350);
+ fiat_p224_addcarryx_u32(&x384, &x385, x383, x350, x368);
uint32_t x386;
fiat_p224_uint1 x387;
- fiat_p224_addcarryx_u32(&x386, &x387, x385, x370, x352);
+ fiat_p224_addcarryx_u32(&x386, &x387, x385, x352, x370);
uint32_t x388;
fiat_p224_uint1 x389;
- fiat_p224_addcarryx_u32(&x388, &x389, x387, x372, x354);
+ fiat_p224_addcarryx_u32(&x388, &x389, x387, x354, x372);
uint32_t x390;
fiat_p224_uint1 x391;
- fiat_p224_addcarryx_u32(&x390, &x391, x389, 0x0, x355);
+ fiat_p224_addcarryx_u32(&x390, &x391, x389, x355, 0x0);
uint32_t x392;
uint32_t x393;
fiat_p224_mulx_u32(&x392, &x393, x5, (arg2[6]));
@@ -722,49 +722,49 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x404, &x405, x5, (arg2[0]));
uint32_t x406;
fiat_p224_uint1 x407;
- fiat_p224_addcarryx_u32(&x406, &x407, 0x0, x402, x405);
+ fiat_p224_addcarryx_u32(&x406, &x407, 0x0, x405, x402);
uint32_t x408;
fiat_p224_uint1 x409;
- fiat_p224_addcarryx_u32(&x408, &x409, x407, x400, x403);
+ fiat_p224_addcarryx_u32(&x408, &x409, x407, x403, x400);
uint32_t x410;
fiat_p224_uint1 x411;
- fiat_p224_addcarryx_u32(&x410, &x411, x409, x398, x401);
+ fiat_p224_addcarryx_u32(&x410, &x411, x409, x401, x398);
uint32_t x412;
fiat_p224_uint1 x413;
- fiat_p224_addcarryx_u32(&x412, &x413, x411, x396, x399);
+ fiat_p224_addcarryx_u32(&x412, &x413, x411, x399, x396);
uint32_t x414;
fiat_p224_uint1 x415;
- fiat_p224_addcarryx_u32(&x414, &x415, x413, x394, x397);
+ fiat_p224_addcarryx_u32(&x414, &x415, x413, x397, x394);
uint32_t x416;
fiat_p224_uint1 x417;
- fiat_p224_addcarryx_u32(&x416, &x417, x415, x392, x395);
+ fiat_p224_addcarryx_u32(&x416, &x417, x415, x395, x392);
uint32_t x418;
fiat_p224_uint1 x419;
- fiat_p224_addcarryx_u32(&x418, &x419, x417, 0x0, x393);
+ fiat_p224_addcarryx_u32(&x418, &x419, x417, x393, 0x0);
uint32_t x420;
fiat_p224_uint1 x421;
- fiat_p224_addcarryx_u32(&x420, &x421, 0x0, x404, x376);
+ fiat_p224_addcarryx_u32(&x420, &x421, 0x0, x376, x404);
uint32_t x422;
fiat_p224_uint1 x423;
- fiat_p224_addcarryx_u32(&x422, &x423, x421, x406, x378);
+ fiat_p224_addcarryx_u32(&x422, &x423, x421, x378, x406);
uint32_t x424;
fiat_p224_uint1 x425;
- fiat_p224_addcarryx_u32(&x424, &x425, x423, x408, x380);
+ fiat_p224_addcarryx_u32(&x424, &x425, x423, x380, x408);
uint32_t x426;
fiat_p224_uint1 x427;
- fiat_p224_addcarryx_u32(&x426, &x427, x425, x410, x382);
+ fiat_p224_addcarryx_u32(&x426, &x427, x425, x382, x410);
uint32_t x428;
fiat_p224_uint1 x429;
- fiat_p224_addcarryx_u32(&x428, &x429, x427, x412, x384);
+ fiat_p224_addcarryx_u32(&x428, &x429, x427, x384, x412);
uint32_t x430;
fiat_p224_uint1 x431;
- fiat_p224_addcarryx_u32(&x430, &x431, x429, x414, x386);
+ fiat_p224_addcarryx_u32(&x430, &x431, x429, x386, x414);
uint32_t x432;
fiat_p224_uint1 x433;
- fiat_p224_addcarryx_u32(&x432, &x433, x431, x416, x388);
+ fiat_p224_addcarryx_u32(&x432, &x433, x431, x388, x416);
uint32_t x434;
fiat_p224_uint1 x435;
- fiat_p224_addcarryx_u32(&x434, &x435, x433, x418, x390);
+ fiat_p224_addcarryx_u32(&x434, &x435, x433, x390, x418);
uint32_t x436;
uint32_t x437;
fiat_p224_mulx_u32(&x436, &x437, x420, UINT32_C(0xffffffff));
@@ -782,43 +782,43 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x444, &x445, x436, UINT32_C(0xffffffff));
uint32_t x446;
fiat_p224_uint1 x447;
- fiat_p224_addcarryx_u32(&x446, &x447, 0x0, x442, x445);
+ fiat_p224_addcarryx_u32(&x446, &x447, 0x0, x445, x442);
uint32_t x448;
fiat_p224_uint1 x449;
- fiat_p224_addcarryx_u32(&x448, &x449, x447, x440, x443);
+ fiat_p224_addcarryx_u32(&x448, &x449, x447, x443, x440);
uint32_t x450;
fiat_p224_uint1 x451;
- fiat_p224_addcarryx_u32(&x450, &x451, x449, x438, x441);
+ fiat_p224_addcarryx_u32(&x450, &x451, x449, x441, x438);
uint32_t x452;
fiat_p224_uint1 x453;
- fiat_p224_addcarryx_u32(&x452, &x453, x451, 0x0, x439);
+ fiat_p224_addcarryx_u32(&x452, &x453, x451, x439, 0x0);
uint32_t x454;
fiat_p224_uint1 x455;
- fiat_p224_addcarryx_u32(&x454, &x455, 0x0, x436, x420);
+ fiat_p224_addcarryx_u32(&x454, &x455, 0x0, x420, x436);
uint32_t x456;
fiat_p224_uint1 x457;
- fiat_p224_addcarryx_u32(&x456, &x457, x455, 0x0, x422);
+ fiat_p224_addcarryx_u32(&x456, &x457, x455, x422, 0x0);
uint32_t x458;
fiat_p224_uint1 x459;
- fiat_p224_addcarryx_u32(&x458, &x459, x457, 0x0, x424);
+ fiat_p224_addcarryx_u32(&x458, &x459, x457, x424, 0x0);
uint32_t x460;
fiat_p224_uint1 x461;
- fiat_p224_addcarryx_u32(&x460, &x461, x459, x444, x426);
+ fiat_p224_addcarryx_u32(&x460, &x461, x459, x426, x444);
uint32_t x462;
fiat_p224_uint1 x463;
- fiat_p224_addcarryx_u32(&x462, &x463, x461, x446, x428);
+ fiat_p224_addcarryx_u32(&x462, &x463, x461, x428, x446);
uint32_t x464;
fiat_p224_uint1 x465;
- fiat_p224_addcarryx_u32(&x464, &x465, x463, x448, x430);
+ fiat_p224_addcarryx_u32(&x464, &x465, x463, x430, x448);
uint32_t x466;
fiat_p224_uint1 x467;
- fiat_p224_addcarryx_u32(&x466, &x467, x465, x450, x432);
+ fiat_p224_addcarryx_u32(&x466, &x467, x465, x432, x450);
uint32_t x468;
fiat_p224_uint1 x469;
- fiat_p224_addcarryx_u32(&x468, &x469, x467, x452, x434);
+ fiat_p224_addcarryx_u32(&x468, &x469, x467, x434, x452);
uint32_t x470;
fiat_p224_uint1 x471;
- fiat_p224_addcarryx_u32(&x470, &x471, x469, 0x0, x435);
+ fiat_p224_addcarryx_u32(&x470, &x471, x469, x435, 0x0);
uint32_t x472;
uint32_t x473;
fiat_p224_mulx_u32(&x472, &x473, x6, (arg2[6]));
@@ -842,49 +842,49 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x484, &x485, x6, (arg2[0]));
uint32_t x486;
fiat_p224_uint1 x487;
- fiat_p224_addcarryx_u32(&x486, &x487, 0x0, x482, x485);
+ fiat_p224_addcarryx_u32(&x486, &x487, 0x0, x485, x482);
uint32_t x488;
fiat_p224_uint1 x489;
- fiat_p224_addcarryx_u32(&x488, &x489, x487, x480, x483);
+ fiat_p224_addcarryx_u32(&x488, &x489, x487, x483, x480);
uint32_t x490;
fiat_p224_uint1 x491;
- fiat_p224_addcarryx_u32(&x490, &x491, x489, x478, x481);
+ fiat_p224_addcarryx_u32(&x490, &x491, x489, x481, x478);
uint32_t x492;
fiat_p224_uint1 x493;
- fiat_p224_addcarryx_u32(&x492, &x493, x491, x476, x479);
+ fiat_p224_addcarryx_u32(&x492, &x493, x491, x479, x476);
uint32_t x494;
fiat_p224_uint1 x495;
- fiat_p224_addcarryx_u32(&x494, &x495, x493, x474, x477);
+ fiat_p224_addcarryx_u32(&x494, &x495, x493, x477, x474);
uint32_t x496;
fiat_p224_uint1 x497;
- fiat_p224_addcarryx_u32(&x496, &x497, x495, x472, x475);
+ fiat_p224_addcarryx_u32(&x496, &x497, x495, x475, x472);
uint32_t x498;
fiat_p224_uint1 x499;
- fiat_p224_addcarryx_u32(&x498, &x499, x497, 0x0, x473);
+ fiat_p224_addcarryx_u32(&x498, &x499, x497, x473, 0x0);
uint32_t x500;
fiat_p224_uint1 x501;
- fiat_p224_addcarryx_u32(&x500, &x501, 0x0, x484, x456);
+ fiat_p224_addcarryx_u32(&x500, &x501, 0x0, x456, x484);
uint32_t x502;
fiat_p224_uint1 x503;
- fiat_p224_addcarryx_u32(&x502, &x503, x501, x486, x458);
+ fiat_p224_addcarryx_u32(&x502, &x503, x501, x458, x486);
uint32_t x504;
fiat_p224_uint1 x505;
- fiat_p224_addcarryx_u32(&x504, &x505, x503, x488, x460);
+ fiat_p224_addcarryx_u32(&x504, &x505, x503, x460, x488);
uint32_t x506;
fiat_p224_uint1 x507;
- fiat_p224_addcarryx_u32(&x506, &x507, x505, x490, x462);
+ fiat_p224_addcarryx_u32(&x506, &x507, x505, x462, x490);
uint32_t x508;
fiat_p224_uint1 x509;
- fiat_p224_addcarryx_u32(&x508, &x509, x507, x492, x464);
+ fiat_p224_addcarryx_u32(&x508, &x509, x507, x464, x492);
uint32_t x510;
fiat_p224_uint1 x511;
- fiat_p224_addcarryx_u32(&x510, &x511, x509, x494, x466);
+ fiat_p224_addcarryx_u32(&x510, &x511, x509, x466, x494);
uint32_t x512;
fiat_p224_uint1 x513;
- fiat_p224_addcarryx_u32(&x512, &x513, x511, x496, x468);
+ fiat_p224_addcarryx_u32(&x512, &x513, x511, x468, x496);
uint32_t x514;
fiat_p224_uint1 x515;
- fiat_p224_addcarryx_u32(&x514, &x515, x513, x498, x470);
+ fiat_p224_addcarryx_u32(&x514, &x515, x513, x470, x498);
uint32_t x516;
uint32_t x517;
fiat_p224_mulx_u32(&x516, &x517, x500, UINT32_C(0xffffffff));
@@ -902,43 +902,43 @@ static void fiat_p224_mul(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_mulx_u32(&x524, &x525, x516, UINT32_C(0xffffffff));
uint32_t x526;
fiat_p224_uint1 x527;
- fiat_p224_addcarryx_u32(&x526, &x527, 0x0, x522, x525);
+ fiat_p224_addcarryx_u32(&x526, &x527, 0x0, x525, x522);
uint32_t x528;
fiat_p224_uint1 x529;
- fiat_p224_addcarryx_u32(&x528, &x529, x527, x520, x523);
+ fiat_p224_addcarryx_u32(&x528, &x529, x527, x523, x520);
uint32_t x530;
fiat_p224_uint1 x531;
- fiat_p224_addcarryx_u32(&x530, &x531, x529, x518, x521);
+ fiat_p224_addcarryx_u32(&x530, &x531, x529, x521, x518);
uint32_t x532;
fiat_p224_uint1 x533;
- fiat_p224_addcarryx_u32(&x532, &x533, x531, 0x0, x519);
+ fiat_p224_addcarryx_u32(&x532, &x533, x531, x519, 0x0);
uint32_t x534;
fiat_p224_uint1 x535;
- fiat_p224_addcarryx_u32(&x534, &x535, 0x0, x516, x500);
+ fiat_p224_addcarryx_u32(&x534, &x535, 0x0, x500, x516);
uint32_t x536;
fiat_p224_uint1 x537;
- fiat_p224_addcarryx_u32(&x536, &x537, x535, 0x0, x502);
+ fiat_p224_addcarryx_u32(&x536, &x537, x535, x502, 0x0);
uint32_t x538;
fiat_p224_uint1 x539;
- fiat_p224_addcarryx_u32(&x538, &x539, x537, 0x0, x504);
+ fiat_p224_addcarryx_u32(&x538, &x539, x537, x504, 0x0);
uint32_t x540;
fiat_p224_uint1 x541;
- fiat_p224_addcarryx_u32(&x540, &x541, x539, x524, x506);
+ fiat_p224_addcarryx_u32(&x540, &x541, x539, x506, x524);
uint32_t x542;
fiat_p224_uint1 x543;
- fiat_p224_addcarryx_u32(&x542, &x543, x541, x526, x508);
+ fiat_p224_addcarryx_u32(&x542, &x543, x541, x508, x526);
uint32_t x544;
fiat_p224_uint1 x545;
- fiat_p224_addcarryx_u32(&x544, &x545, x543, x528, x510);
+ fiat_p224_addcarryx_u32(&x544, &x545, x543, x510, x528);
uint32_t x546;
fiat_p224_uint1 x547;
- fiat_p224_addcarryx_u32(&x546, &x547, x545, x530, x512);
+ fiat_p224_addcarryx_u32(&x546, &x547, x545, x512, x530);
uint32_t x548;
fiat_p224_uint1 x549;
- fiat_p224_addcarryx_u32(&x548, &x549, x547, x532, x514);
+ fiat_p224_addcarryx_u32(&x548, &x549, x547, x514, x532);
uint32_t x550;
fiat_p224_uint1 x551;
- fiat_p224_addcarryx_u32(&x550, &x551, x549, 0x0, x515);
+ fiat_p224_addcarryx_u32(&x550, &x551, x549, x515, 0x0);
uint32_t x552;
fiat_p224_uint1 x553;
fiat_p224_subborrowx_u32(&x552, &x553, 0x0, x536, 0x1);
@@ -1030,25 +1030,25 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x20, &x21, x7, (arg1[0]));
uint32_t x22;
fiat_p224_uint1 x23;
- fiat_p224_addcarryx_u32(&x22, &x23, 0x0, x18, x21);
+ fiat_p224_addcarryx_u32(&x22, &x23, 0x0, x21, x18);
uint32_t x24;
fiat_p224_uint1 x25;
- fiat_p224_addcarryx_u32(&x24, &x25, x23, x16, x19);
+ fiat_p224_addcarryx_u32(&x24, &x25, x23, x19, x16);
uint32_t x26;
fiat_p224_uint1 x27;
- fiat_p224_addcarryx_u32(&x26, &x27, x25, x14, x17);
+ fiat_p224_addcarryx_u32(&x26, &x27, x25, x17, x14);
uint32_t x28;
fiat_p224_uint1 x29;
- fiat_p224_addcarryx_u32(&x28, &x29, x27, x12, x15);
+ fiat_p224_addcarryx_u32(&x28, &x29, x27, x15, x12);
uint32_t x30;
fiat_p224_uint1 x31;
- fiat_p224_addcarryx_u32(&x30, &x31, x29, x10, x13);
+ fiat_p224_addcarryx_u32(&x30, &x31, x29, x13, x10);
uint32_t x32;
fiat_p224_uint1 x33;
- fiat_p224_addcarryx_u32(&x32, &x33, x31, x8, x11);
+ fiat_p224_addcarryx_u32(&x32, &x33, x31, x11, x8);
uint32_t x34;
fiat_p224_uint1 x35;
- fiat_p224_addcarryx_u32(&x34, &x35, x33, 0x0, x9);
+ fiat_p224_addcarryx_u32(&x34, &x35, x33, x9, 0x0);
uint32_t x36;
uint32_t x37;
fiat_p224_mulx_u32(&x36, &x37, x20, UINT32_C(0xffffffff));
@@ -1066,40 +1066,40 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x44, &x45, x36, UINT32_C(0xffffffff));
uint32_t x46;
fiat_p224_uint1 x47;
- fiat_p224_addcarryx_u32(&x46, &x47, 0x0, x42, x45);
+ fiat_p224_addcarryx_u32(&x46, &x47, 0x0, x45, x42);
uint32_t x48;
fiat_p224_uint1 x49;
- fiat_p224_addcarryx_u32(&x48, &x49, x47, x40, x43);
+ fiat_p224_addcarryx_u32(&x48, &x49, x47, x43, x40);
uint32_t x50;
fiat_p224_uint1 x51;
- fiat_p224_addcarryx_u32(&x50, &x51, x49, x38, x41);
+ fiat_p224_addcarryx_u32(&x50, &x51, x49, x41, x38);
uint32_t x52;
fiat_p224_uint1 x53;
- fiat_p224_addcarryx_u32(&x52, &x53, x51, 0x0, x39);
+ fiat_p224_addcarryx_u32(&x52, &x53, x51, x39, 0x0);
uint32_t x54;
fiat_p224_uint1 x55;
- fiat_p224_addcarryx_u32(&x54, &x55, 0x0, x36, x20);
+ fiat_p224_addcarryx_u32(&x54, &x55, 0x0, x20, x36);
uint32_t x56;
fiat_p224_uint1 x57;
- fiat_p224_addcarryx_u32(&x56, &x57, x55, 0x0, x22);
+ fiat_p224_addcarryx_u32(&x56, &x57, x55, x22, 0x0);
uint32_t x58;
fiat_p224_uint1 x59;
- fiat_p224_addcarryx_u32(&x58, &x59, x57, 0x0, x24);
+ fiat_p224_addcarryx_u32(&x58, &x59, x57, x24, 0x0);
uint32_t x60;
fiat_p224_uint1 x61;
- fiat_p224_addcarryx_u32(&x60, &x61, x59, x44, x26);
+ fiat_p224_addcarryx_u32(&x60, &x61, x59, x26, x44);
uint32_t x62;
fiat_p224_uint1 x63;
- fiat_p224_addcarryx_u32(&x62, &x63, x61, x46, x28);
+ fiat_p224_addcarryx_u32(&x62, &x63, x61, x28, x46);
uint32_t x64;
fiat_p224_uint1 x65;
- fiat_p224_addcarryx_u32(&x64, &x65, x63, x48, x30);
+ fiat_p224_addcarryx_u32(&x64, &x65, x63, x30, x48);
uint32_t x66;
fiat_p224_uint1 x67;
- fiat_p224_addcarryx_u32(&x66, &x67, x65, x50, x32);
+ fiat_p224_addcarryx_u32(&x66, &x67, x65, x32, x50);
uint32_t x68;
fiat_p224_uint1 x69;
- fiat_p224_addcarryx_u32(&x68, &x69, x67, x52, x34);
+ fiat_p224_addcarryx_u32(&x68, &x69, x67, x34, x52);
uint32_t x70;
fiat_p224_uint1 x71;
fiat_p224_addcarryx_u32(&x70, &x71, x69, 0x0, 0x0);
@@ -1126,49 +1126,49 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x84, &x85, x1, (arg1[0]));
uint32_t x86;
fiat_p224_uint1 x87;
- fiat_p224_addcarryx_u32(&x86, &x87, 0x0, x82, x85);
+ fiat_p224_addcarryx_u32(&x86, &x87, 0x0, x85, x82);
uint32_t x88;
fiat_p224_uint1 x89;
- fiat_p224_addcarryx_u32(&x88, &x89, x87, x80, x83);
+ fiat_p224_addcarryx_u32(&x88, &x89, x87, x83, x80);
uint32_t x90;
fiat_p224_uint1 x91;
- fiat_p224_addcarryx_u32(&x90, &x91, x89, x78, x81);
+ fiat_p224_addcarryx_u32(&x90, &x91, x89, x81, x78);
uint32_t x92;
fiat_p224_uint1 x93;
- fiat_p224_addcarryx_u32(&x92, &x93, x91, x76, x79);
+ fiat_p224_addcarryx_u32(&x92, &x93, x91, x79, x76);
uint32_t x94;
fiat_p224_uint1 x95;
- fiat_p224_addcarryx_u32(&x94, &x95, x93, x74, x77);
+ fiat_p224_addcarryx_u32(&x94, &x95, x93, x77, x74);
uint32_t x96;
fiat_p224_uint1 x97;
- fiat_p224_addcarryx_u32(&x96, &x97, x95, x72, x75);
+ fiat_p224_addcarryx_u32(&x96, &x97, x95, x75, x72);
uint32_t x98;
fiat_p224_uint1 x99;
- fiat_p224_addcarryx_u32(&x98, &x99, x97, 0x0, x73);
+ fiat_p224_addcarryx_u32(&x98, &x99, x97, x73, 0x0);
uint32_t x100;
fiat_p224_uint1 x101;
- fiat_p224_addcarryx_u32(&x100, &x101, 0x0, x84, x56);
+ fiat_p224_addcarryx_u32(&x100, &x101, 0x0, x56, x84);
uint32_t x102;
fiat_p224_uint1 x103;
- fiat_p224_addcarryx_u32(&x102, &x103, x101, x86, x58);
+ fiat_p224_addcarryx_u32(&x102, &x103, x101, x58, x86);
uint32_t x104;
fiat_p224_uint1 x105;
- fiat_p224_addcarryx_u32(&x104, &x105, x103, x88, x60);
+ fiat_p224_addcarryx_u32(&x104, &x105, x103, x60, x88);
uint32_t x106;
fiat_p224_uint1 x107;
- fiat_p224_addcarryx_u32(&x106, &x107, x105, x90, x62);
+ fiat_p224_addcarryx_u32(&x106, &x107, x105, x62, x90);
uint32_t x108;
fiat_p224_uint1 x109;
- fiat_p224_addcarryx_u32(&x108, &x109, x107, x92, x64);
+ fiat_p224_addcarryx_u32(&x108, &x109, x107, x64, x92);
uint32_t x110;
fiat_p224_uint1 x111;
- fiat_p224_addcarryx_u32(&x110, &x111, x109, x94, x66);
+ fiat_p224_addcarryx_u32(&x110, &x111, x109, x66, x94);
uint32_t x112;
fiat_p224_uint1 x113;
- fiat_p224_addcarryx_u32(&x112, &x113, x111, x96, x68);
+ fiat_p224_addcarryx_u32(&x112, &x113, x111, x68, x96);
uint32_t x114;
fiat_p224_uint1 x115;
- fiat_p224_addcarryx_u32(&x114, &x115, x113, x98, (fiat_p224_uint1)x70);
+ fiat_p224_addcarryx_u32(&x114, &x115, x113, (fiat_p224_uint1)x70, x98);
uint32_t x116;
uint32_t x117;
fiat_p224_mulx_u32(&x116, &x117, x100, UINT32_C(0xffffffff));
@@ -1186,43 +1186,43 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x124, &x125, x116, UINT32_C(0xffffffff));
uint32_t x126;
fiat_p224_uint1 x127;
- fiat_p224_addcarryx_u32(&x126, &x127, 0x0, x122, x125);
+ fiat_p224_addcarryx_u32(&x126, &x127, 0x0, x125, x122);
uint32_t x128;
fiat_p224_uint1 x129;
- fiat_p224_addcarryx_u32(&x128, &x129, x127, x120, x123);
+ fiat_p224_addcarryx_u32(&x128, &x129, x127, x123, x120);
uint32_t x130;
fiat_p224_uint1 x131;
- fiat_p224_addcarryx_u32(&x130, &x131, x129, x118, x121);
+ fiat_p224_addcarryx_u32(&x130, &x131, x129, x121, x118);
uint32_t x132;
fiat_p224_uint1 x133;
- fiat_p224_addcarryx_u32(&x132, &x133, x131, 0x0, x119);
+ fiat_p224_addcarryx_u32(&x132, &x133, x131, x119, 0x0);
uint32_t x134;
fiat_p224_uint1 x135;
- fiat_p224_addcarryx_u32(&x134, &x135, 0x0, x116, x100);
+ fiat_p224_addcarryx_u32(&x134, &x135, 0x0, x100, x116);
uint32_t x136;
fiat_p224_uint1 x137;
- fiat_p224_addcarryx_u32(&x136, &x137, x135, 0x0, x102);
+ fiat_p224_addcarryx_u32(&x136, &x137, x135, x102, 0x0);
uint32_t x138;
fiat_p224_uint1 x139;
- fiat_p224_addcarryx_u32(&x138, &x139, x137, 0x0, x104);
+ fiat_p224_addcarryx_u32(&x138, &x139, x137, x104, 0x0);
uint32_t x140;
fiat_p224_uint1 x141;
- fiat_p224_addcarryx_u32(&x140, &x141, x139, x124, x106);
+ fiat_p224_addcarryx_u32(&x140, &x141, x139, x106, x124);
uint32_t x142;
fiat_p224_uint1 x143;
- fiat_p224_addcarryx_u32(&x142, &x143, x141, x126, x108);
+ fiat_p224_addcarryx_u32(&x142, &x143, x141, x108, x126);
uint32_t x144;
fiat_p224_uint1 x145;
- fiat_p224_addcarryx_u32(&x144, &x145, x143, x128, x110);
+ fiat_p224_addcarryx_u32(&x144, &x145, x143, x110, x128);
uint32_t x146;
fiat_p224_uint1 x147;
- fiat_p224_addcarryx_u32(&x146, &x147, x145, x130, x112);
+ fiat_p224_addcarryx_u32(&x146, &x147, x145, x112, x130);
uint32_t x148;
fiat_p224_uint1 x149;
- fiat_p224_addcarryx_u32(&x148, &x149, x147, x132, x114);
+ fiat_p224_addcarryx_u32(&x148, &x149, x147, x114, x132);
uint32_t x150;
fiat_p224_uint1 x151;
- fiat_p224_addcarryx_u32(&x150, &x151, x149, 0x0, x115);
+ fiat_p224_addcarryx_u32(&x150, &x151, x149, x115, 0x0);
uint32_t x152;
uint32_t x153;
fiat_p224_mulx_u32(&x152, &x153, x2, (arg1[6]));
@@ -1246,49 +1246,49 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x164, &x165, x2, (arg1[0]));
uint32_t x166;
fiat_p224_uint1 x167;
- fiat_p224_addcarryx_u32(&x166, &x167, 0x0, x162, x165);
+ fiat_p224_addcarryx_u32(&x166, &x167, 0x0, x165, x162);
uint32_t x168;
fiat_p224_uint1 x169;
- fiat_p224_addcarryx_u32(&x168, &x169, x167, x160, x163);
+ fiat_p224_addcarryx_u32(&x168, &x169, x167, x163, x160);
uint32_t x170;
fiat_p224_uint1 x171;
- fiat_p224_addcarryx_u32(&x170, &x171, x169, x158, x161);
+ fiat_p224_addcarryx_u32(&x170, &x171, x169, x161, x158);
uint32_t x172;
fiat_p224_uint1 x173;
- fiat_p224_addcarryx_u32(&x172, &x173, x171, x156, x159);
+ fiat_p224_addcarryx_u32(&x172, &x173, x171, x159, x156);
uint32_t x174;
fiat_p224_uint1 x175;
- fiat_p224_addcarryx_u32(&x174, &x175, x173, x154, x157);
+ fiat_p224_addcarryx_u32(&x174, &x175, x173, x157, x154);
uint32_t x176;
fiat_p224_uint1 x177;
- fiat_p224_addcarryx_u32(&x176, &x177, x175, x152, x155);
+ fiat_p224_addcarryx_u32(&x176, &x177, x175, x155, x152);
uint32_t x178;
fiat_p224_uint1 x179;
- fiat_p224_addcarryx_u32(&x178, &x179, x177, 0x0, x153);
+ fiat_p224_addcarryx_u32(&x178, &x179, x177, x153, 0x0);
uint32_t x180;
fiat_p224_uint1 x181;
- fiat_p224_addcarryx_u32(&x180, &x181, 0x0, x164, x136);
+ fiat_p224_addcarryx_u32(&x180, &x181, 0x0, x136, x164);
uint32_t x182;
fiat_p224_uint1 x183;
- fiat_p224_addcarryx_u32(&x182, &x183, x181, x166, x138);
+ fiat_p224_addcarryx_u32(&x182, &x183, x181, x138, x166);
uint32_t x184;
fiat_p224_uint1 x185;
- fiat_p224_addcarryx_u32(&x184, &x185, x183, x168, x140);
+ fiat_p224_addcarryx_u32(&x184, &x185, x183, x140, x168);
uint32_t x186;
fiat_p224_uint1 x187;
- fiat_p224_addcarryx_u32(&x186, &x187, x185, x170, x142);
+ fiat_p224_addcarryx_u32(&x186, &x187, x185, x142, x170);
uint32_t x188;
fiat_p224_uint1 x189;
- fiat_p224_addcarryx_u32(&x188, &x189, x187, x172, x144);
+ fiat_p224_addcarryx_u32(&x188, &x189, x187, x144, x172);
uint32_t x190;
fiat_p224_uint1 x191;
- fiat_p224_addcarryx_u32(&x190, &x191, x189, x174, x146);
+ fiat_p224_addcarryx_u32(&x190, &x191, x189, x146, x174);
uint32_t x192;
fiat_p224_uint1 x193;
- fiat_p224_addcarryx_u32(&x192, &x193, x191, x176, x148);
+ fiat_p224_addcarryx_u32(&x192, &x193, x191, x148, x176);
uint32_t x194;
fiat_p224_uint1 x195;
- fiat_p224_addcarryx_u32(&x194, &x195, x193, x178, x150);
+ fiat_p224_addcarryx_u32(&x194, &x195, x193, x150, x178);
uint32_t x196;
uint32_t x197;
fiat_p224_mulx_u32(&x196, &x197, x180, UINT32_C(0xffffffff));
@@ -1306,43 +1306,43 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x204, &x205, x196, UINT32_C(0xffffffff));
uint32_t x206;
fiat_p224_uint1 x207;
- fiat_p224_addcarryx_u32(&x206, &x207, 0x0, x202, x205);
+ fiat_p224_addcarryx_u32(&x206, &x207, 0x0, x205, x202);
uint32_t x208;
fiat_p224_uint1 x209;
- fiat_p224_addcarryx_u32(&x208, &x209, x207, x200, x203);
+ fiat_p224_addcarryx_u32(&x208, &x209, x207, x203, x200);
uint32_t x210;
fiat_p224_uint1 x211;
- fiat_p224_addcarryx_u32(&x210, &x211, x209, x198, x201);
+ fiat_p224_addcarryx_u32(&x210, &x211, x209, x201, x198);
uint32_t x212;
fiat_p224_uint1 x213;
- fiat_p224_addcarryx_u32(&x212, &x213, x211, 0x0, x199);
+ fiat_p224_addcarryx_u32(&x212, &x213, x211, x199, 0x0);
uint32_t x214;
fiat_p224_uint1 x215;
- fiat_p224_addcarryx_u32(&x214, &x215, 0x0, x196, x180);
+ fiat_p224_addcarryx_u32(&x214, &x215, 0x0, x180, x196);
uint32_t x216;
fiat_p224_uint1 x217;
- fiat_p224_addcarryx_u32(&x216, &x217, x215, 0x0, x182);
+ fiat_p224_addcarryx_u32(&x216, &x217, x215, x182, 0x0);
uint32_t x218;
fiat_p224_uint1 x219;
- fiat_p224_addcarryx_u32(&x218, &x219, x217, 0x0, x184);
+ fiat_p224_addcarryx_u32(&x218, &x219, x217, x184, 0x0);
uint32_t x220;
fiat_p224_uint1 x221;
- fiat_p224_addcarryx_u32(&x220, &x221, x219, x204, x186);
+ fiat_p224_addcarryx_u32(&x220, &x221, x219, x186, x204);
uint32_t x222;
fiat_p224_uint1 x223;
- fiat_p224_addcarryx_u32(&x222, &x223, x221, x206, x188);
+ fiat_p224_addcarryx_u32(&x222, &x223, x221, x188, x206);
uint32_t x224;
fiat_p224_uint1 x225;
- fiat_p224_addcarryx_u32(&x224, &x225, x223, x208, x190);
+ fiat_p224_addcarryx_u32(&x224, &x225, x223, x190, x208);
uint32_t x226;
fiat_p224_uint1 x227;
- fiat_p224_addcarryx_u32(&x226, &x227, x225, x210, x192);
+ fiat_p224_addcarryx_u32(&x226, &x227, x225, x192, x210);
uint32_t x228;
fiat_p224_uint1 x229;
- fiat_p224_addcarryx_u32(&x228, &x229, x227, x212, x194);
+ fiat_p224_addcarryx_u32(&x228, &x229, x227, x194, x212);
uint32_t x230;
fiat_p224_uint1 x231;
- fiat_p224_addcarryx_u32(&x230, &x231, x229, 0x0, x195);
+ fiat_p224_addcarryx_u32(&x230, &x231, x229, x195, 0x0);
uint32_t x232;
uint32_t x233;
fiat_p224_mulx_u32(&x232, &x233, x3, (arg1[6]));
@@ -1366,49 +1366,49 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x244, &x245, x3, (arg1[0]));
uint32_t x246;
fiat_p224_uint1 x247;
- fiat_p224_addcarryx_u32(&x246, &x247, 0x0, x242, x245);
+ fiat_p224_addcarryx_u32(&x246, &x247, 0x0, x245, x242);
uint32_t x248;
fiat_p224_uint1 x249;
- fiat_p224_addcarryx_u32(&x248, &x249, x247, x240, x243);
+ fiat_p224_addcarryx_u32(&x248, &x249, x247, x243, x240);
uint32_t x250;
fiat_p224_uint1 x251;
- fiat_p224_addcarryx_u32(&x250, &x251, x249, x238, x241);
+ fiat_p224_addcarryx_u32(&x250, &x251, x249, x241, x238);
uint32_t x252;
fiat_p224_uint1 x253;
- fiat_p224_addcarryx_u32(&x252, &x253, x251, x236, x239);
+ fiat_p224_addcarryx_u32(&x252, &x253, x251, x239, x236);
uint32_t x254;
fiat_p224_uint1 x255;
- fiat_p224_addcarryx_u32(&x254, &x255, x253, x234, x237);
+ fiat_p224_addcarryx_u32(&x254, &x255, x253, x237, x234);
uint32_t x256;
fiat_p224_uint1 x257;
- fiat_p224_addcarryx_u32(&x256, &x257, x255, x232, x235);
+ fiat_p224_addcarryx_u32(&x256, &x257, x255, x235, x232);
uint32_t x258;
fiat_p224_uint1 x259;
- fiat_p224_addcarryx_u32(&x258, &x259, x257, 0x0, x233);
+ fiat_p224_addcarryx_u32(&x258, &x259, x257, x233, 0x0);
uint32_t x260;
fiat_p224_uint1 x261;
- fiat_p224_addcarryx_u32(&x260, &x261, 0x0, x244, x216);
+ fiat_p224_addcarryx_u32(&x260, &x261, 0x0, x216, x244);
uint32_t x262;
fiat_p224_uint1 x263;
- fiat_p224_addcarryx_u32(&x262, &x263, x261, x246, x218);
+ fiat_p224_addcarryx_u32(&x262, &x263, x261, x218, x246);
uint32_t x264;
fiat_p224_uint1 x265;
- fiat_p224_addcarryx_u32(&x264, &x265, x263, x248, x220);
+ fiat_p224_addcarryx_u32(&x264, &x265, x263, x220, x248);
uint32_t x266;
fiat_p224_uint1 x267;
- fiat_p224_addcarryx_u32(&x266, &x267, x265, x250, x222);
+ fiat_p224_addcarryx_u32(&x266, &x267, x265, x222, x250);
uint32_t x268;
fiat_p224_uint1 x269;
- fiat_p224_addcarryx_u32(&x268, &x269, x267, x252, x224);
+ fiat_p224_addcarryx_u32(&x268, &x269, x267, x224, x252);
uint32_t x270;
fiat_p224_uint1 x271;
- fiat_p224_addcarryx_u32(&x270, &x271, x269, x254, x226);
+ fiat_p224_addcarryx_u32(&x270, &x271, x269, x226, x254);
uint32_t x272;
fiat_p224_uint1 x273;
- fiat_p224_addcarryx_u32(&x272, &x273, x271, x256, x228);
+ fiat_p224_addcarryx_u32(&x272, &x273, x271, x228, x256);
uint32_t x274;
fiat_p224_uint1 x275;
- fiat_p224_addcarryx_u32(&x274, &x275, x273, x258, x230);
+ fiat_p224_addcarryx_u32(&x274, &x275, x273, x230, x258);
uint32_t x276;
uint32_t x277;
fiat_p224_mulx_u32(&x276, &x277, x260, UINT32_C(0xffffffff));
@@ -1426,43 +1426,43 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x284, &x285, x276, UINT32_C(0xffffffff));
uint32_t x286;
fiat_p224_uint1 x287;
- fiat_p224_addcarryx_u32(&x286, &x287, 0x0, x282, x285);
+ fiat_p224_addcarryx_u32(&x286, &x287, 0x0, x285, x282);
uint32_t x288;
fiat_p224_uint1 x289;
- fiat_p224_addcarryx_u32(&x288, &x289, x287, x280, x283);
+ fiat_p224_addcarryx_u32(&x288, &x289, x287, x283, x280);
uint32_t x290;
fiat_p224_uint1 x291;
- fiat_p224_addcarryx_u32(&x290, &x291, x289, x278, x281);
+ fiat_p224_addcarryx_u32(&x290, &x291, x289, x281, x278);
uint32_t x292;
fiat_p224_uint1 x293;
- fiat_p224_addcarryx_u32(&x292, &x293, x291, 0x0, x279);
+ fiat_p224_addcarryx_u32(&x292, &x293, x291, x279, 0x0);
uint32_t x294;
fiat_p224_uint1 x295;
- fiat_p224_addcarryx_u32(&x294, &x295, 0x0, x276, x260);
+ fiat_p224_addcarryx_u32(&x294, &x295, 0x0, x260, x276);
uint32_t x296;
fiat_p224_uint1 x297;
- fiat_p224_addcarryx_u32(&x296, &x297, x295, 0x0, x262);
+ fiat_p224_addcarryx_u32(&x296, &x297, x295, x262, 0x0);
uint32_t x298;
fiat_p224_uint1 x299;
- fiat_p224_addcarryx_u32(&x298, &x299, x297, 0x0, x264);
+ fiat_p224_addcarryx_u32(&x298, &x299, x297, x264, 0x0);
uint32_t x300;
fiat_p224_uint1 x301;
- fiat_p224_addcarryx_u32(&x300, &x301, x299, x284, x266);
+ fiat_p224_addcarryx_u32(&x300, &x301, x299, x266, x284);
uint32_t x302;
fiat_p224_uint1 x303;
- fiat_p224_addcarryx_u32(&x302, &x303, x301, x286, x268);
+ fiat_p224_addcarryx_u32(&x302, &x303, x301, x268, x286);
uint32_t x304;
fiat_p224_uint1 x305;
- fiat_p224_addcarryx_u32(&x304, &x305, x303, x288, x270);
+ fiat_p224_addcarryx_u32(&x304, &x305, x303, x270, x288);
uint32_t x306;
fiat_p224_uint1 x307;
- fiat_p224_addcarryx_u32(&x306, &x307, x305, x290, x272);
+ fiat_p224_addcarryx_u32(&x306, &x307, x305, x272, x290);
uint32_t x308;
fiat_p224_uint1 x309;
- fiat_p224_addcarryx_u32(&x308, &x309, x307, x292, x274);
+ fiat_p224_addcarryx_u32(&x308, &x309, x307, x274, x292);
uint32_t x310;
fiat_p224_uint1 x311;
- fiat_p224_addcarryx_u32(&x310, &x311, x309, 0x0, x275);
+ fiat_p224_addcarryx_u32(&x310, &x311, x309, x275, 0x0);
uint32_t x312;
uint32_t x313;
fiat_p224_mulx_u32(&x312, &x313, x4, (arg1[6]));
@@ -1486,49 +1486,49 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x324, &x325, x4, (arg1[0]));
uint32_t x326;
fiat_p224_uint1 x327;
- fiat_p224_addcarryx_u32(&x326, &x327, 0x0, x322, x325);
+ fiat_p224_addcarryx_u32(&x326, &x327, 0x0, x325, x322);
uint32_t x328;
fiat_p224_uint1 x329;
- fiat_p224_addcarryx_u32(&x328, &x329, x327, x320, x323);
+ fiat_p224_addcarryx_u32(&x328, &x329, x327, x323, x320);
uint32_t x330;
fiat_p224_uint1 x331;
- fiat_p224_addcarryx_u32(&x330, &x331, x329, x318, x321);
+ fiat_p224_addcarryx_u32(&x330, &x331, x329, x321, x318);
uint32_t x332;
fiat_p224_uint1 x333;
- fiat_p224_addcarryx_u32(&x332, &x333, x331, x316, x319);
+ fiat_p224_addcarryx_u32(&x332, &x333, x331, x319, x316);
uint32_t x334;
fiat_p224_uint1 x335;
- fiat_p224_addcarryx_u32(&x334, &x335, x333, x314, x317);
+ fiat_p224_addcarryx_u32(&x334, &x335, x333, x317, x314);
uint32_t x336;
fiat_p224_uint1 x337;
- fiat_p224_addcarryx_u32(&x336, &x337, x335, x312, x315);
+ fiat_p224_addcarryx_u32(&x336, &x337, x335, x315, x312);
uint32_t x338;
fiat_p224_uint1 x339;
- fiat_p224_addcarryx_u32(&x338, &x339, x337, 0x0, x313);
+ fiat_p224_addcarryx_u32(&x338, &x339, x337, x313, 0x0);
uint32_t x340;
fiat_p224_uint1 x341;
- fiat_p224_addcarryx_u32(&x340, &x341, 0x0, x324, x296);
+ fiat_p224_addcarryx_u32(&x340, &x341, 0x0, x296, x324);
uint32_t x342;
fiat_p224_uint1 x343;
- fiat_p224_addcarryx_u32(&x342, &x343, x341, x326, x298);
+ fiat_p224_addcarryx_u32(&x342, &x343, x341, x298, x326);
uint32_t x344;
fiat_p224_uint1 x345;
- fiat_p224_addcarryx_u32(&x344, &x345, x343, x328, x300);
+ fiat_p224_addcarryx_u32(&x344, &x345, x343, x300, x328);
uint32_t x346;
fiat_p224_uint1 x347;
- fiat_p224_addcarryx_u32(&x346, &x347, x345, x330, x302);
+ fiat_p224_addcarryx_u32(&x346, &x347, x345, x302, x330);
uint32_t x348;
fiat_p224_uint1 x349;
- fiat_p224_addcarryx_u32(&x348, &x349, x347, x332, x304);
+ fiat_p224_addcarryx_u32(&x348, &x349, x347, x304, x332);
uint32_t x350;
fiat_p224_uint1 x351;
- fiat_p224_addcarryx_u32(&x350, &x351, x349, x334, x306);
+ fiat_p224_addcarryx_u32(&x350, &x351, x349, x306, x334);
uint32_t x352;
fiat_p224_uint1 x353;
- fiat_p224_addcarryx_u32(&x352, &x353, x351, x336, x308);
+ fiat_p224_addcarryx_u32(&x352, &x353, x351, x308, x336);
uint32_t x354;
fiat_p224_uint1 x355;
- fiat_p224_addcarryx_u32(&x354, &x355, x353, x338, x310);
+ fiat_p224_addcarryx_u32(&x354, &x355, x353, x310, x338);
uint32_t x356;
uint32_t x357;
fiat_p224_mulx_u32(&x356, &x357, x340, UINT32_C(0xffffffff));
@@ -1546,43 +1546,43 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x364, &x365, x356, UINT32_C(0xffffffff));
uint32_t x366;
fiat_p224_uint1 x367;
- fiat_p224_addcarryx_u32(&x366, &x367, 0x0, x362, x365);
+ fiat_p224_addcarryx_u32(&x366, &x367, 0x0, x365, x362);
uint32_t x368;
fiat_p224_uint1 x369;
- fiat_p224_addcarryx_u32(&x368, &x369, x367, x360, x363);
+ fiat_p224_addcarryx_u32(&x368, &x369, x367, x363, x360);
uint32_t x370;
fiat_p224_uint1 x371;
- fiat_p224_addcarryx_u32(&x370, &x371, x369, x358, x361);
+ fiat_p224_addcarryx_u32(&x370, &x371, x369, x361, x358);
uint32_t x372;
fiat_p224_uint1 x373;
- fiat_p224_addcarryx_u32(&x372, &x373, x371, 0x0, x359);
+ fiat_p224_addcarryx_u32(&x372, &x373, x371, x359, 0x0);
uint32_t x374;
fiat_p224_uint1 x375;
- fiat_p224_addcarryx_u32(&x374, &x375, 0x0, x356, x340);
+ fiat_p224_addcarryx_u32(&x374, &x375, 0x0, x340, x356);
uint32_t x376;
fiat_p224_uint1 x377;
- fiat_p224_addcarryx_u32(&x376, &x377, x375, 0x0, x342);
+ fiat_p224_addcarryx_u32(&x376, &x377, x375, x342, 0x0);
uint32_t x378;
fiat_p224_uint1 x379;
- fiat_p224_addcarryx_u32(&x378, &x379, x377, 0x0, x344);
+ fiat_p224_addcarryx_u32(&x378, &x379, x377, x344, 0x0);
uint32_t x380;
fiat_p224_uint1 x381;
- fiat_p224_addcarryx_u32(&x380, &x381, x379, x364, x346);
+ fiat_p224_addcarryx_u32(&x380, &x381, x379, x346, x364);
uint32_t x382;
fiat_p224_uint1 x383;
- fiat_p224_addcarryx_u32(&x382, &x383, x381, x366, x348);
+ fiat_p224_addcarryx_u32(&x382, &x383, x381, x348, x366);
uint32_t x384;
fiat_p224_uint1 x385;
- fiat_p224_addcarryx_u32(&x384, &x385, x383, x368, x350);
+ fiat_p224_addcarryx_u32(&x384, &x385, x383, x350, x368);
uint32_t x386;
fiat_p224_uint1 x387;
- fiat_p224_addcarryx_u32(&x386, &x387, x385, x370, x352);
+ fiat_p224_addcarryx_u32(&x386, &x387, x385, x352, x370);
uint32_t x388;
fiat_p224_uint1 x389;
- fiat_p224_addcarryx_u32(&x388, &x389, x387, x372, x354);
+ fiat_p224_addcarryx_u32(&x388, &x389, x387, x354, x372);
uint32_t x390;
fiat_p224_uint1 x391;
- fiat_p224_addcarryx_u32(&x390, &x391, x389, 0x0, x355);
+ fiat_p224_addcarryx_u32(&x390, &x391, x389, x355, 0x0);
uint32_t x392;
uint32_t x393;
fiat_p224_mulx_u32(&x392, &x393, x5, (arg1[6]));
@@ -1606,49 +1606,49 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x404, &x405, x5, (arg1[0]));
uint32_t x406;
fiat_p224_uint1 x407;
- fiat_p224_addcarryx_u32(&x406, &x407, 0x0, x402, x405);
+ fiat_p224_addcarryx_u32(&x406, &x407, 0x0, x405, x402);
uint32_t x408;
fiat_p224_uint1 x409;
- fiat_p224_addcarryx_u32(&x408, &x409, x407, x400, x403);
+ fiat_p224_addcarryx_u32(&x408, &x409, x407, x403, x400);
uint32_t x410;
fiat_p224_uint1 x411;
- fiat_p224_addcarryx_u32(&x410, &x411, x409, x398, x401);
+ fiat_p224_addcarryx_u32(&x410, &x411, x409, x401, x398);
uint32_t x412;
fiat_p224_uint1 x413;
- fiat_p224_addcarryx_u32(&x412, &x413, x411, x396, x399);
+ fiat_p224_addcarryx_u32(&x412, &x413, x411, x399, x396);
uint32_t x414;
fiat_p224_uint1 x415;
- fiat_p224_addcarryx_u32(&x414, &x415, x413, x394, x397);
+ fiat_p224_addcarryx_u32(&x414, &x415, x413, x397, x394);
uint32_t x416;
fiat_p224_uint1 x417;
- fiat_p224_addcarryx_u32(&x416, &x417, x415, x392, x395);
+ fiat_p224_addcarryx_u32(&x416, &x417, x415, x395, x392);
uint32_t x418;
fiat_p224_uint1 x419;
- fiat_p224_addcarryx_u32(&x418, &x419, x417, 0x0, x393);
+ fiat_p224_addcarryx_u32(&x418, &x419, x417, x393, 0x0);
uint32_t x420;
fiat_p224_uint1 x421;
- fiat_p224_addcarryx_u32(&x420, &x421, 0x0, x404, x376);
+ fiat_p224_addcarryx_u32(&x420, &x421, 0x0, x376, x404);
uint32_t x422;
fiat_p224_uint1 x423;
- fiat_p224_addcarryx_u32(&x422, &x423, x421, x406, x378);
+ fiat_p224_addcarryx_u32(&x422, &x423, x421, x378, x406);
uint32_t x424;
fiat_p224_uint1 x425;
- fiat_p224_addcarryx_u32(&x424, &x425, x423, x408, x380);
+ fiat_p224_addcarryx_u32(&x424, &x425, x423, x380, x408);
uint32_t x426;
fiat_p224_uint1 x427;
- fiat_p224_addcarryx_u32(&x426, &x427, x425, x410, x382);
+ fiat_p224_addcarryx_u32(&x426, &x427, x425, x382, x410);
uint32_t x428;
fiat_p224_uint1 x429;
- fiat_p224_addcarryx_u32(&x428, &x429, x427, x412, x384);
+ fiat_p224_addcarryx_u32(&x428, &x429, x427, x384, x412);
uint32_t x430;
fiat_p224_uint1 x431;
- fiat_p224_addcarryx_u32(&x430, &x431, x429, x414, x386);
+ fiat_p224_addcarryx_u32(&x430, &x431, x429, x386, x414);
uint32_t x432;
fiat_p224_uint1 x433;
- fiat_p224_addcarryx_u32(&x432, &x433, x431, x416, x388);
+ fiat_p224_addcarryx_u32(&x432, &x433, x431, x388, x416);
uint32_t x434;
fiat_p224_uint1 x435;
- fiat_p224_addcarryx_u32(&x434, &x435, x433, x418, x390);
+ fiat_p224_addcarryx_u32(&x434, &x435, x433, x390, x418);
uint32_t x436;
uint32_t x437;
fiat_p224_mulx_u32(&x436, &x437, x420, UINT32_C(0xffffffff));
@@ -1666,43 +1666,43 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x444, &x445, x436, UINT32_C(0xffffffff));
uint32_t x446;
fiat_p224_uint1 x447;
- fiat_p224_addcarryx_u32(&x446, &x447, 0x0, x442, x445);
+ fiat_p224_addcarryx_u32(&x446, &x447, 0x0, x445, x442);
uint32_t x448;
fiat_p224_uint1 x449;
- fiat_p224_addcarryx_u32(&x448, &x449, x447, x440, x443);
+ fiat_p224_addcarryx_u32(&x448, &x449, x447, x443, x440);
uint32_t x450;
fiat_p224_uint1 x451;
- fiat_p224_addcarryx_u32(&x450, &x451, x449, x438, x441);
+ fiat_p224_addcarryx_u32(&x450, &x451, x449, x441, x438);
uint32_t x452;
fiat_p224_uint1 x453;
- fiat_p224_addcarryx_u32(&x452, &x453, x451, 0x0, x439);
+ fiat_p224_addcarryx_u32(&x452, &x453, x451, x439, 0x0);
uint32_t x454;
fiat_p224_uint1 x455;
- fiat_p224_addcarryx_u32(&x454, &x455, 0x0, x436, x420);
+ fiat_p224_addcarryx_u32(&x454, &x455, 0x0, x420, x436);
uint32_t x456;
fiat_p224_uint1 x457;
- fiat_p224_addcarryx_u32(&x456, &x457, x455, 0x0, x422);
+ fiat_p224_addcarryx_u32(&x456, &x457, x455, x422, 0x0);
uint32_t x458;
fiat_p224_uint1 x459;
- fiat_p224_addcarryx_u32(&x458, &x459, x457, 0x0, x424);
+ fiat_p224_addcarryx_u32(&x458, &x459, x457, x424, 0x0);
uint32_t x460;
fiat_p224_uint1 x461;
- fiat_p224_addcarryx_u32(&x460, &x461, x459, x444, x426);
+ fiat_p224_addcarryx_u32(&x460, &x461, x459, x426, x444);
uint32_t x462;
fiat_p224_uint1 x463;
- fiat_p224_addcarryx_u32(&x462, &x463, x461, x446, x428);
+ fiat_p224_addcarryx_u32(&x462, &x463, x461, x428, x446);
uint32_t x464;
fiat_p224_uint1 x465;
- fiat_p224_addcarryx_u32(&x464, &x465, x463, x448, x430);
+ fiat_p224_addcarryx_u32(&x464, &x465, x463, x430, x448);
uint32_t x466;
fiat_p224_uint1 x467;
- fiat_p224_addcarryx_u32(&x466, &x467, x465, x450, x432);
+ fiat_p224_addcarryx_u32(&x466, &x467, x465, x432, x450);
uint32_t x468;
fiat_p224_uint1 x469;
- fiat_p224_addcarryx_u32(&x468, &x469, x467, x452, x434);
+ fiat_p224_addcarryx_u32(&x468, &x469, x467, x434, x452);
uint32_t x470;
fiat_p224_uint1 x471;
- fiat_p224_addcarryx_u32(&x470, &x471, x469, 0x0, x435);
+ fiat_p224_addcarryx_u32(&x470, &x471, x469, x435, 0x0);
uint32_t x472;
uint32_t x473;
fiat_p224_mulx_u32(&x472, &x473, x6, (arg1[6]));
@@ -1726,49 +1726,49 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x484, &x485, x6, (arg1[0]));
uint32_t x486;
fiat_p224_uint1 x487;
- fiat_p224_addcarryx_u32(&x486, &x487, 0x0, x482, x485);
+ fiat_p224_addcarryx_u32(&x486, &x487, 0x0, x485, x482);
uint32_t x488;
fiat_p224_uint1 x489;
- fiat_p224_addcarryx_u32(&x488, &x489, x487, x480, x483);
+ fiat_p224_addcarryx_u32(&x488, &x489, x487, x483, x480);
uint32_t x490;
fiat_p224_uint1 x491;
- fiat_p224_addcarryx_u32(&x490, &x491, x489, x478, x481);
+ fiat_p224_addcarryx_u32(&x490, &x491, x489, x481, x478);
uint32_t x492;
fiat_p224_uint1 x493;
- fiat_p224_addcarryx_u32(&x492, &x493, x491, x476, x479);
+ fiat_p224_addcarryx_u32(&x492, &x493, x491, x479, x476);
uint32_t x494;
fiat_p224_uint1 x495;
- fiat_p224_addcarryx_u32(&x494, &x495, x493, x474, x477);
+ fiat_p224_addcarryx_u32(&x494, &x495, x493, x477, x474);
uint32_t x496;
fiat_p224_uint1 x497;
- fiat_p224_addcarryx_u32(&x496, &x497, x495, x472, x475);
+ fiat_p224_addcarryx_u32(&x496, &x497, x495, x475, x472);
uint32_t x498;
fiat_p224_uint1 x499;
- fiat_p224_addcarryx_u32(&x498, &x499, x497, 0x0, x473);
+ fiat_p224_addcarryx_u32(&x498, &x499, x497, x473, 0x0);
uint32_t x500;
fiat_p224_uint1 x501;
- fiat_p224_addcarryx_u32(&x500, &x501, 0x0, x484, x456);
+ fiat_p224_addcarryx_u32(&x500, &x501, 0x0, x456, x484);
uint32_t x502;
fiat_p224_uint1 x503;
- fiat_p224_addcarryx_u32(&x502, &x503, x501, x486, x458);
+ fiat_p224_addcarryx_u32(&x502, &x503, x501, x458, x486);
uint32_t x504;
fiat_p224_uint1 x505;
- fiat_p224_addcarryx_u32(&x504, &x505, x503, x488, x460);
+ fiat_p224_addcarryx_u32(&x504, &x505, x503, x460, x488);
uint32_t x506;
fiat_p224_uint1 x507;
- fiat_p224_addcarryx_u32(&x506, &x507, x505, x490, x462);
+ fiat_p224_addcarryx_u32(&x506, &x507, x505, x462, x490);
uint32_t x508;
fiat_p224_uint1 x509;
- fiat_p224_addcarryx_u32(&x508, &x509, x507, x492, x464);
+ fiat_p224_addcarryx_u32(&x508, &x509, x507, x464, x492);
uint32_t x510;
fiat_p224_uint1 x511;
- fiat_p224_addcarryx_u32(&x510, &x511, x509, x494, x466);
+ fiat_p224_addcarryx_u32(&x510, &x511, x509, x466, x494);
uint32_t x512;
fiat_p224_uint1 x513;
- fiat_p224_addcarryx_u32(&x512, &x513, x511, x496, x468);
+ fiat_p224_addcarryx_u32(&x512, &x513, x511, x468, x496);
uint32_t x514;
fiat_p224_uint1 x515;
- fiat_p224_addcarryx_u32(&x514, &x515, x513, x498, x470);
+ fiat_p224_addcarryx_u32(&x514, &x515, x513, x470, x498);
uint32_t x516;
uint32_t x517;
fiat_p224_mulx_u32(&x516, &x517, x500, UINT32_C(0xffffffff));
@@ -1786,43 +1786,43 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_mulx_u32(&x524, &x525, x516, UINT32_C(0xffffffff));
uint32_t x526;
fiat_p224_uint1 x527;
- fiat_p224_addcarryx_u32(&x526, &x527, 0x0, x522, x525);
+ fiat_p224_addcarryx_u32(&x526, &x527, 0x0, x525, x522);
uint32_t x528;
fiat_p224_uint1 x529;
- fiat_p224_addcarryx_u32(&x528, &x529, x527, x520, x523);
+ fiat_p224_addcarryx_u32(&x528, &x529, x527, x523, x520);
uint32_t x530;
fiat_p224_uint1 x531;
- fiat_p224_addcarryx_u32(&x530, &x531, x529, x518, x521);
+ fiat_p224_addcarryx_u32(&x530, &x531, x529, x521, x518);
uint32_t x532;
fiat_p224_uint1 x533;
- fiat_p224_addcarryx_u32(&x532, &x533, x531, 0x0, x519);
+ fiat_p224_addcarryx_u32(&x532, &x533, x531, x519, 0x0);
uint32_t x534;
fiat_p224_uint1 x535;
- fiat_p224_addcarryx_u32(&x534, &x535, 0x0, x516, x500);
+ fiat_p224_addcarryx_u32(&x534, &x535, 0x0, x500, x516);
uint32_t x536;
fiat_p224_uint1 x537;
- fiat_p224_addcarryx_u32(&x536, &x537, x535, 0x0, x502);
+ fiat_p224_addcarryx_u32(&x536, &x537, x535, x502, 0x0);
uint32_t x538;
fiat_p224_uint1 x539;
- fiat_p224_addcarryx_u32(&x538, &x539, x537, 0x0, x504);
+ fiat_p224_addcarryx_u32(&x538, &x539, x537, x504, 0x0);
uint32_t x540;
fiat_p224_uint1 x541;
- fiat_p224_addcarryx_u32(&x540, &x541, x539, x524, x506);
+ fiat_p224_addcarryx_u32(&x540, &x541, x539, x506, x524);
uint32_t x542;
fiat_p224_uint1 x543;
- fiat_p224_addcarryx_u32(&x542, &x543, x541, x526, x508);
+ fiat_p224_addcarryx_u32(&x542, &x543, x541, x508, x526);
uint32_t x544;
fiat_p224_uint1 x545;
- fiat_p224_addcarryx_u32(&x544, &x545, x543, x528, x510);
+ fiat_p224_addcarryx_u32(&x544, &x545, x543, x510, x528);
uint32_t x546;
fiat_p224_uint1 x547;
- fiat_p224_addcarryx_u32(&x546, &x547, x545, x530, x512);
+ fiat_p224_addcarryx_u32(&x546, &x547, x545, x512, x530);
uint32_t x548;
fiat_p224_uint1 x549;
- fiat_p224_addcarryx_u32(&x548, &x549, x547, x532, x514);
+ fiat_p224_addcarryx_u32(&x548, &x549, x547, x514, x532);
uint32_t x550;
fiat_p224_uint1 x551;
- fiat_p224_addcarryx_u32(&x550, &x551, x549, 0x0, x515);
+ fiat_p224_addcarryx_u32(&x550, &x551, x549, x515, 0x0);
uint32_t x552;
fiat_p224_uint1 x553;
fiat_p224_subborrowx_u32(&x552, &x553, 0x0, x536, 0x1);
@@ -1888,25 +1888,25 @@ static void fiat_p224_square(uint32_t out1[7], const uint32_t arg1[7]) {
static void fiat_p224_add(uint32_t out1[7], const uint32_t arg1[7], const uint32_t arg2[7]) {
uint32_t x1;
fiat_p224_uint1 x2;
- fiat_p224_addcarryx_u32(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p224_addcarryx_u32(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint32_t x3;
fiat_p224_uint1 x4;
- fiat_p224_addcarryx_u32(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p224_addcarryx_u32(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint32_t x5;
fiat_p224_uint1 x6;
- fiat_p224_addcarryx_u32(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p224_addcarryx_u32(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint32_t x7;
fiat_p224_uint1 x8;
- fiat_p224_addcarryx_u32(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p224_addcarryx_u32(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint32_t x9;
fiat_p224_uint1 x10;
- fiat_p224_addcarryx_u32(&x9, &x10, x8, (arg2[4]), (arg1[4]));
+ fiat_p224_addcarryx_u32(&x9, &x10, x8, (arg1[4]), (arg2[4]));
uint32_t x11;
fiat_p224_uint1 x12;
- fiat_p224_addcarryx_u32(&x11, &x12, x10, (arg2[5]), (arg1[5]));
+ fiat_p224_addcarryx_u32(&x11, &x12, x10, (arg1[5]), (arg2[5]));
uint32_t x13;
fiat_p224_uint1 x14;
- fiat_p224_addcarryx_u32(&x13, &x14, x12, (arg2[6]), (arg1[6]));
+ fiat_p224_addcarryx_u32(&x13, &x14, x12, (arg1[6]), (arg2[6]));
uint32_t x15;
fiat_p224_uint1 x16;
fiat_p224_subborrowx_u32(&x15, &x16, 0x0, x1, 0x1);
@@ -1995,25 +1995,25 @@ static void fiat_p224_sub(uint32_t out1[7], const uint32_t arg1[7], const uint32
fiat_p224_cmovznz_u32(&x15, x14, 0x0, UINT32_C(0xffffffff));
uint32_t x16;
fiat_p224_uint1 x17;
- fiat_p224_addcarryx_u32(&x16, &x17, 0x0, (fiat_p224_uint1)(x15 & 0x1), x1);
+ fiat_p224_addcarryx_u32(&x16, &x17, 0x0, x1, (fiat_p224_uint1)(x15 & 0x1));
uint32_t x18;
fiat_p224_uint1 x19;
- fiat_p224_addcarryx_u32(&x18, &x19, x17, 0x0, x3);
+ fiat_p224_addcarryx_u32(&x18, &x19, x17, x3, 0x0);
uint32_t x20;
fiat_p224_uint1 x21;
- fiat_p224_addcarryx_u32(&x20, &x21, x19, 0x0, x5);
+ fiat_p224_addcarryx_u32(&x20, &x21, x19, x5, 0x0);
uint32_t x22;
fiat_p224_uint1 x23;
- fiat_p224_addcarryx_u32(&x22, &x23, x21, (x15 & UINT32_C(0xffffffff)), x7);
+ fiat_p224_addcarryx_u32(&x22, &x23, x21, x7, (x15 & UINT32_C(0xffffffff)));
uint32_t x24;
fiat_p224_uint1 x25;
- fiat_p224_addcarryx_u32(&x24, &x25, x23, (x15 & UINT32_C(0xffffffff)), x9);
+ fiat_p224_addcarryx_u32(&x24, &x25, x23, x9, (x15 & UINT32_C(0xffffffff)));
uint32_t x26;
fiat_p224_uint1 x27;
- fiat_p224_addcarryx_u32(&x26, &x27, x25, (x15 & UINT32_C(0xffffffff)), x11);
+ fiat_p224_addcarryx_u32(&x26, &x27, x25, x11, (x15 & UINT32_C(0xffffffff)));
uint32_t x28;
fiat_p224_uint1 x29;
- fiat_p224_addcarryx_u32(&x28, &x29, x27, (x15 & UINT32_C(0xffffffff)), x13);
+ fiat_p224_addcarryx_u32(&x28, &x29, x27, x13, (x15 & UINT32_C(0xffffffff)));
out1[0] = x16;
out1[1] = x18;
out1[2] = x20;
@@ -2062,25 +2062,25 @@ static void fiat_p224_opp(uint32_t out1[7], const uint32_t arg1[7]) {
fiat_p224_cmovznz_u32(&x15, x14, 0x0, UINT32_C(0xffffffff));
uint32_t x16;
fiat_p224_uint1 x17;
- fiat_p224_addcarryx_u32(&x16, &x17, 0x0, (fiat_p224_uint1)(x15 & 0x1), x1);
+ fiat_p224_addcarryx_u32(&x16, &x17, 0x0, x1, (fiat_p224_uint1)(x15 & 0x1));
uint32_t x18;
fiat_p224_uint1 x19;
- fiat_p224_addcarryx_u32(&x18, &x19, x17, 0x0, x3);
+ fiat_p224_addcarryx_u32(&x18, &x19, x17, x3, 0x0);
uint32_t x20;
fiat_p224_uint1 x21;
- fiat_p224_addcarryx_u32(&x20, &x21, x19, 0x0, x5);
+ fiat_p224_addcarryx_u32(&x20, &x21, x19, x5, 0x0);
uint32_t x22;
fiat_p224_uint1 x23;
- fiat_p224_addcarryx_u32(&x22, &x23, x21, (x15 & UINT32_C(0xffffffff)), x7);
+ fiat_p224_addcarryx_u32(&x22, &x23, x21, x7, (x15 & UINT32_C(0xffffffff)));
uint32_t x24;
fiat_p224_uint1 x25;
- fiat_p224_addcarryx_u32(&x24, &x25, x23, (x15 & UINT32_C(0xffffffff)), x9);
+ fiat_p224_addcarryx_u32(&x24, &x25, x23, x9, (x15 & UINT32_C(0xffffffff)));
uint32_t x26;
fiat_p224_uint1 x27;
- fiat_p224_addcarryx_u32(&x26, &x27, x25, (x15 & UINT32_C(0xffffffff)), x11);
+ fiat_p224_addcarryx_u32(&x26, &x27, x25, x11, (x15 & UINT32_C(0xffffffff)));
uint32_t x28;
fiat_p224_uint1 x29;
- fiat_p224_addcarryx_u32(&x28, &x29, x27, (x15 & UINT32_C(0xffffffff)), x13);
+ fiat_p224_addcarryx_u32(&x28, &x29, x27, x13, (x15 & UINT32_C(0xffffffff)));
out1[0] = x16;
out1[1] = x18;
out1[2] = x20;
@@ -2122,22 +2122,22 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x10, &x11, x2, UINT32_C(0xffffffff));
uint32_t x12;
fiat_p224_uint1 x13;
- fiat_p224_addcarryx_u32(&x12, &x13, 0x0, x8, x11);
+ fiat_p224_addcarryx_u32(&x12, &x13, 0x0, x11, x8);
uint32_t x14;
fiat_p224_uint1 x15;
- fiat_p224_addcarryx_u32(&x14, &x15, x13, x6, x9);
+ fiat_p224_addcarryx_u32(&x14, &x15, x13, x9, x6);
uint32_t x16;
fiat_p224_uint1 x17;
- fiat_p224_addcarryx_u32(&x16, &x17, x15, x4, x7);
+ fiat_p224_addcarryx_u32(&x16, &x17, x15, x7, x4);
uint32_t x18;
fiat_p224_uint1 x19;
- fiat_p224_addcarryx_u32(&x18, &x19, 0x0, x2, x1);
+ fiat_p224_addcarryx_u32(&x18, &x19, 0x0, x1, x2);
uint32_t x20;
fiat_p224_uint1 x21;
fiat_p224_addcarryx_u32(&x20, &x21, x19, 0x0, 0x0);
uint32_t x22;
fiat_p224_uint1 x23;
- fiat_p224_addcarryx_u32(&x22, &x23, 0x0, (arg1[1]), (fiat_p224_uint1)x20);
+ fiat_p224_addcarryx_u32(&x22, &x23, 0x0, (fiat_p224_uint1)x20, (arg1[1]));
uint32_t x24;
uint32_t x25;
fiat_p224_mulx_u32(&x24, &x25, x22, UINT32_C(0xffffffff));
@@ -2155,64 +2155,64 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x32, &x33, x24, UINT32_C(0xffffffff));
uint32_t x34;
fiat_p224_uint1 x35;
- fiat_p224_addcarryx_u32(&x34, &x35, 0x0, x30, x33);
+ fiat_p224_addcarryx_u32(&x34, &x35, 0x0, x33, x30);
uint32_t x36;
fiat_p224_uint1 x37;
- fiat_p224_addcarryx_u32(&x36, &x37, x35, x28, x31);
+ fiat_p224_addcarryx_u32(&x36, &x37, x35, x31, x28);
uint32_t x38;
fiat_p224_uint1 x39;
- fiat_p224_addcarryx_u32(&x38, &x39, x37, x26, x29);
+ fiat_p224_addcarryx_u32(&x38, &x39, x37, x29, x26);
uint32_t x40;
fiat_p224_uint1 x41;
- fiat_p224_addcarryx_u32(&x40, &x41, 0x0, x32, x12);
+ fiat_p224_addcarryx_u32(&x40, &x41, 0x0, x12, x32);
uint32_t x42;
fiat_p224_uint1 x43;
- fiat_p224_addcarryx_u32(&x42, &x43, x41, x34, x14);
+ fiat_p224_addcarryx_u32(&x42, &x43, x41, x14, x34);
uint32_t x44;
fiat_p224_uint1 x45;
- fiat_p224_addcarryx_u32(&x44, &x45, x43, x36, x16);
+ fiat_p224_addcarryx_u32(&x44, &x45, x43, x16, x36);
uint32_t x46;
fiat_p224_uint1 x47;
- fiat_p224_addcarryx_u32(&x46, &x47, x17, 0x0, x5);
+ fiat_p224_addcarryx_u32(&x46, &x47, x17, x5, 0x0);
uint32_t x48;
fiat_p224_uint1 x49;
- fiat_p224_addcarryx_u32(&x48, &x49, x45, x38, x46);
+ fiat_p224_addcarryx_u32(&x48, &x49, x45, x46, x38);
uint32_t x50;
fiat_p224_uint1 x51;
- fiat_p224_addcarryx_u32(&x50, &x51, x39, 0x0, x27);
+ fiat_p224_addcarryx_u32(&x50, &x51, x39, x27, 0x0);
uint32_t x52;
fiat_p224_uint1 x53;
- fiat_p224_addcarryx_u32(&x52, &x53, x49, x50, 0x0);
+ fiat_p224_addcarryx_u32(&x52, &x53, x49, 0x0, x50);
uint32_t x54;
fiat_p224_uint1 x55;
fiat_p224_addcarryx_u32(&x54, &x55, x23, 0x0, 0x0);
uint32_t x56;
fiat_p224_uint1 x57;
- fiat_p224_addcarryx_u32(&x56, &x57, 0x0, x24, x22);
+ fiat_p224_addcarryx_u32(&x56, &x57, 0x0, x22, x24);
uint32_t x58;
fiat_p224_uint1 x59;
- fiat_p224_addcarryx_u32(&x58, &x59, x57, 0x0, (fiat_p224_uint1)x54);
+ fiat_p224_addcarryx_u32(&x58, &x59, x57, (fiat_p224_uint1)x54, 0x0);
uint32_t x60;
fiat_p224_uint1 x61;
- fiat_p224_addcarryx_u32(&x60, &x61, 0x0, (arg1[2]), x58);
+ fiat_p224_addcarryx_u32(&x60, &x61, 0x0, x58, (arg1[2]));
uint32_t x62;
fiat_p224_uint1 x63;
- fiat_p224_addcarryx_u32(&x62, &x63, x61, 0x0, x10);
+ fiat_p224_addcarryx_u32(&x62, &x63, x61, x10, 0x0);
uint32_t x64;
fiat_p224_uint1 x65;
- fiat_p224_addcarryx_u32(&x64, &x65, x63, 0x0, x40);
+ fiat_p224_addcarryx_u32(&x64, &x65, x63, x40, 0x0);
uint32_t x66;
fiat_p224_uint1 x67;
- fiat_p224_addcarryx_u32(&x66, &x67, x65, 0x0, x42);
+ fiat_p224_addcarryx_u32(&x66, &x67, x65, x42, 0x0);
uint32_t x68;
fiat_p224_uint1 x69;
- fiat_p224_addcarryx_u32(&x68, &x69, x67, 0x0, x44);
+ fiat_p224_addcarryx_u32(&x68, &x69, x67, x44, 0x0);
uint32_t x70;
fiat_p224_uint1 x71;
- fiat_p224_addcarryx_u32(&x70, &x71, x69, 0x0, x48);
+ fiat_p224_addcarryx_u32(&x70, &x71, x69, x48, 0x0);
uint32_t x72;
fiat_p224_uint1 x73;
- fiat_p224_addcarryx_u32(&x72, &x73, x71, 0x0, x52);
+ fiat_p224_addcarryx_u32(&x72, &x73, x71, x52, 0x0);
uint32_t x74;
uint32_t x75;
fiat_p224_mulx_u32(&x74, &x75, x60, UINT32_C(0xffffffff));
@@ -2230,67 +2230,67 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x82, &x83, x74, UINT32_C(0xffffffff));
uint32_t x84;
fiat_p224_uint1 x85;
- fiat_p224_addcarryx_u32(&x84, &x85, 0x0, x80, x83);
+ fiat_p224_addcarryx_u32(&x84, &x85, 0x0, x83, x80);
uint32_t x86;
fiat_p224_uint1 x87;
- fiat_p224_addcarryx_u32(&x86, &x87, x85, x78, x81);
+ fiat_p224_addcarryx_u32(&x86, &x87, x85, x81, x78);
uint32_t x88;
fiat_p224_uint1 x89;
- fiat_p224_addcarryx_u32(&x88, &x89, x87, x76, x79);
+ fiat_p224_addcarryx_u32(&x88, &x89, x87, x79, x76);
uint32_t x90;
fiat_p224_uint1 x91;
- fiat_p224_addcarryx_u32(&x90, &x91, 0x0, x74, x60);
+ fiat_p224_addcarryx_u32(&x90, &x91, 0x0, x60, x74);
uint32_t x92;
fiat_p224_uint1 x93;
- fiat_p224_addcarryx_u32(&x92, &x93, x91, 0x0, x62);
+ fiat_p224_addcarryx_u32(&x92, &x93, x91, x62, 0x0);
uint32_t x94;
fiat_p224_uint1 x95;
- fiat_p224_addcarryx_u32(&x94, &x95, x93, 0x0, x64);
+ fiat_p224_addcarryx_u32(&x94, &x95, x93, x64, 0x0);
uint32_t x96;
fiat_p224_uint1 x97;
- fiat_p224_addcarryx_u32(&x96, &x97, x95, x82, x66);
+ fiat_p224_addcarryx_u32(&x96, &x97, x95, x66, x82);
uint32_t x98;
fiat_p224_uint1 x99;
- fiat_p224_addcarryx_u32(&x98, &x99, x97, x84, x68);
+ fiat_p224_addcarryx_u32(&x98, &x99, x97, x68, x84);
uint32_t x100;
fiat_p224_uint1 x101;
- fiat_p224_addcarryx_u32(&x100, &x101, x99, x86, x70);
+ fiat_p224_addcarryx_u32(&x100, &x101, x99, x70, x86);
uint32_t x102;
fiat_p224_uint1 x103;
- fiat_p224_addcarryx_u32(&x102, &x103, x101, x88, x72);
+ fiat_p224_addcarryx_u32(&x102, &x103, x101, x72, x88);
uint32_t x104;
fiat_p224_uint1 x105;
- fiat_p224_addcarryx_u32(&x104, &x105, x53, 0x0, 0x0);
+ fiat_p224_addcarryx_u32(&x104, &x105, x89, x77, 0x0);
uint32_t x106;
fiat_p224_uint1 x107;
- fiat_p224_addcarryx_u32(&x106, &x107, x73, 0x0, (fiat_p224_uint1)x104);
+ fiat_p224_addcarryx_u32(&x106, &x107, x53, 0x0, 0x0);
uint32_t x108;
fiat_p224_uint1 x109;
- fiat_p224_addcarryx_u32(&x108, &x109, x89, 0x0, x77);
+ fiat_p224_addcarryx_u32(&x108, &x109, x73, (fiat_p224_uint1)x106, 0x0);
uint32_t x110;
fiat_p224_uint1 x111;
- fiat_p224_addcarryx_u32(&x110, &x111, x103, x108, x106);
+ fiat_p224_addcarryx_u32(&x110, &x111, x103, x108, x104);
uint32_t x112;
fiat_p224_uint1 x113;
- fiat_p224_addcarryx_u32(&x112, &x113, 0x0, (arg1[3]), x92);
+ fiat_p224_addcarryx_u32(&x112, &x113, 0x0, x92, (arg1[3]));
uint32_t x114;
fiat_p224_uint1 x115;
- fiat_p224_addcarryx_u32(&x114, &x115, x113, 0x0, x94);
+ fiat_p224_addcarryx_u32(&x114, &x115, x113, x94, 0x0);
uint32_t x116;
fiat_p224_uint1 x117;
- fiat_p224_addcarryx_u32(&x116, &x117, x115, 0x0, x96);
+ fiat_p224_addcarryx_u32(&x116, &x117, x115, x96, 0x0);
uint32_t x118;
fiat_p224_uint1 x119;
- fiat_p224_addcarryx_u32(&x118, &x119, x117, 0x0, x98);
+ fiat_p224_addcarryx_u32(&x118, &x119, x117, x98, 0x0);
uint32_t x120;
fiat_p224_uint1 x121;
- fiat_p224_addcarryx_u32(&x120, &x121, x119, 0x0, x100);
+ fiat_p224_addcarryx_u32(&x120, &x121, x119, x100, 0x0);
uint32_t x122;
fiat_p224_uint1 x123;
- fiat_p224_addcarryx_u32(&x122, &x123, x121, 0x0, x102);
+ fiat_p224_addcarryx_u32(&x122, &x123, x121, x102, 0x0);
uint32_t x124;
fiat_p224_uint1 x125;
- fiat_p224_addcarryx_u32(&x124, &x125, x123, 0x0, x110);
+ fiat_p224_addcarryx_u32(&x124, &x125, x123, x110, 0x0);
uint32_t x126;
uint32_t x127;
fiat_p224_mulx_u32(&x126, &x127, x112, UINT32_C(0xffffffff));
@@ -2308,67 +2308,67 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x134, &x135, x126, UINT32_C(0xffffffff));
uint32_t x136;
fiat_p224_uint1 x137;
- fiat_p224_addcarryx_u32(&x136, &x137, 0x0, x132, x135);
+ fiat_p224_addcarryx_u32(&x136, &x137, 0x0, x135, x132);
uint32_t x138;
fiat_p224_uint1 x139;
- fiat_p224_addcarryx_u32(&x138, &x139, x137, x130, x133);
+ fiat_p224_addcarryx_u32(&x138, &x139, x137, x133, x130);
uint32_t x140;
fiat_p224_uint1 x141;
- fiat_p224_addcarryx_u32(&x140, &x141, x139, x128, x131);
+ fiat_p224_addcarryx_u32(&x140, &x141, x139, x131, x128);
uint32_t x142;
fiat_p224_uint1 x143;
- fiat_p224_addcarryx_u32(&x142, &x143, 0x0, x126, x112);
+ fiat_p224_addcarryx_u32(&x142, &x143, 0x0, x112, x126);
uint32_t x144;
fiat_p224_uint1 x145;
- fiat_p224_addcarryx_u32(&x144, &x145, x143, 0x0, x114);
+ fiat_p224_addcarryx_u32(&x144, &x145, x143, x114, 0x0);
uint32_t x146;
fiat_p224_uint1 x147;
- fiat_p224_addcarryx_u32(&x146, &x147, x145, 0x0, x116);
+ fiat_p224_addcarryx_u32(&x146, &x147, x145, x116, 0x0);
uint32_t x148;
fiat_p224_uint1 x149;
- fiat_p224_addcarryx_u32(&x148, &x149, x147, x134, x118);
+ fiat_p224_addcarryx_u32(&x148, &x149, x147, x118, x134);
uint32_t x150;
fiat_p224_uint1 x151;
- fiat_p224_addcarryx_u32(&x150, &x151, x149, x136, x120);
+ fiat_p224_addcarryx_u32(&x150, &x151, x149, x120, x136);
uint32_t x152;
fiat_p224_uint1 x153;
- fiat_p224_addcarryx_u32(&x152, &x153, x151, x138, x122);
+ fiat_p224_addcarryx_u32(&x152, &x153, x151, x122, x138);
uint32_t x154;
fiat_p224_uint1 x155;
- fiat_p224_addcarryx_u32(&x154, &x155, x153, x140, x124);
+ fiat_p224_addcarryx_u32(&x154, &x155, x153, x124, x140);
uint32_t x156;
fiat_p224_uint1 x157;
- fiat_p224_addcarryx_u32(&x156, &x157, x111, 0x0, 0x0);
+ fiat_p224_addcarryx_u32(&x156, &x157, x141, x129, 0x0);
uint32_t x158;
fiat_p224_uint1 x159;
- fiat_p224_addcarryx_u32(&x158, &x159, x125, 0x0, (fiat_p224_uint1)x156);
+ fiat_p224_addcarryx_u32(&x158, &x159, x111, 0x0, 0x0);
uint32_t x160;
fiat_p224_uint1 x161;
- fiat_p224_addcarryx_u32(&x160, &x161, x141, 0x0, x129);
+ fiat_p224_addcarryx_u32(&x160, &x161, x125, (fiat_p224_uint1)x158, 0x0);
uint32_t x162;
fiat_p224_uint1 x163;
- fiat_p224_addcarryx_u32(&x162, &x163, x155, x160, x158);
+ fiat_p224_addcarryx_u32(&x162, &x163, x155, x160, x156);
uint32_t x164;
fiat_p224_uint1 x165;
- fiat_p224_addcarryx_u32(&x164, &x165, 0x0, (arg1[4]), x144);
+ fiat_p224_addcarryx_u32(&x164, &x165, 0x0, x144, (arg1[4]));
uint32_t x166;
fiat_p224_uint1 x167;
- fiat_p224_addcarryx_u32(&x166, &x167, x165, 0x0, x146);
+ fiat_p224_addcarryx_u32(&x166, &x167, x165, x146, 0x0);
uint32_t x168;
fiat_p224_uint1 x169;
- fiat_p224_addcarryx_u32(&x168, &x169, x167, 0x0, x148);
+ fiat_p224_addcarryx_u32(&x168, &x169, x167, x148, 0x0);
uint32_t x170;
fiat_p224_uint1 x171;
- fiat_p224_addcarryx_u32(&x170, &x171, x169, 0x0, x150);
+ fiat_p224_addcarryx_u32(&x170, &x171, x169, x150, 0x0);
uint32_t x172;
fiat_p224_uint1 x173;
- fiat_p224_addcarryx_u32(&x172, &x173, x171, 0x0, x152);
+ fiat_p224_addcarryx_u32(&x172, &x173, x171, x152, 0x0);
uint32_t x174;
fiat_p224_uint1 x175;
- fiat_p224_addcarryx_u32(&x174, &x175, x173, 0x0, x154);
+ fiat_p224_addcarryx_u32(&x174, &x175, x173, x154, 0x0);
uint32_t x176;
fiat_p224_uint1 x177;
- fiat_p224_addcarryx_u32(&x176, &x177, x175, 0x0, x162);
+ fiat_p224_addcarryx_u32(&x176, &x177, x175, x162, 0x0);
uint32_t x178;
uint32_t x179;
fiat_p224_mulx_u32(&x178, &x179, x164, UINT32_C(0xffffffff));
@@ -2386,67 +2386,67 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x186, &x187, x178, UINT32_C(0xffffffff));
uint32_t x188;
fiat_p224_uint1 x189;
- fiat_p224_addcarryx_u32(&x188, &x189, 0x0, x184, x187);
+ fiat_p224_addcarryx_u32(&x188, &x189, 0x0, x187, x184);
uint32_t x190;
fiat_p224_uint1 x191;
- fiat_p224_addcarryx_u32(&x190, &x191, x189, x182, x185);
+ fiat_p224_addcarryx_u32(&x190, &x191, x189, x185, x182);
uint32_t x192;
fiat_p224_uint1 x193;
- fiat_p224_addcarryx_u32(&x192, &x193, x191, x180, x183);
+ fiat_p224_addcarryx_u32(&x192, &x193, x191, x183, x180);
uint32_t x194;
fiat_p224_uint1 x195;
- fiat_p224_addcarryx_u32(&x194, &x195, 0x0, x178, x164);
+ fiat_p224_addcarryx_u32(&x194, &x195, 0x0, x164, x178);
uint32_t x196;
fiat_p224_uint1 x197;
- fiat_p224_addcarryx_u32(&x196, &x197, x195, 0x0, x166);
+ fiat_p224_addcarryx_u32(&x196, &x197, x195, x166, 0x0);
uint32_t x198;
fiat_p224_uint1 x199;
- fiat_p224_addcarryx_u32(&x198, &x199, x197, 0x0, x168);
+ fiat_p224_addcarryx_u32(&x198, &x199, x197, x168, 0x0);
uint32_t x200;
fiat_p224_uint1 x201;
- fiat_p224_addcarryx_u32(&x200, &x201, x199, x186, x170);
+ fiat_p224_addcarryx_u32(&x200, &x201, x199, x170, x186);
uint32_t x202;
fiat_p224_uint1 x203;
- fiat_p224_addcarryx_u32(&x202, &x203, x201, x188, x172);
+ fiat_p224_addcarryx_u32(&x202, &x203, x201, x172, x188);
uint32_t x204;
fiat_p224_uint1 x205;
- fiat_p224_addcarryx_u32(&x204, &x205, x203, x190, x174);
+ fiat_p224_addcarryx_u32(&x204, &x205, x203, x174, x190);
uint32_t x206;
fiat_p224_uint1 x207;
- fiat_p224_addcarryx_u32(&x206, &x207, x205, x192, x176);
+ fiat_p224_addcarryx_u32(&x206, &x207, x205, x176, x192);
uint32_t x208;
fiat_p224_uint1 x209;
- fiat_p224_addcarryx_u32(&x208, &x209, x163, 0x0, 0x0);
+ fiat_p224_addcarryx_u32(&x208, &x209, x193, x181, 0x0);
uint32_t x210;
fiat_p224_uint1 x211;
- fiat_p224_addcarryx_u32(&x210, &x211, x177, 0x0, (fiat_p224_uint1)x208);
+ fiat_p224_addcarryx_u32(&x210, &x211, x163, 0x0, 0x0);
uint32_t x212;
fiat_p224_uint1 x213;
- fiat_p224_addcarryx_u32(&x212, &x213, x193, 0x0, x181);
+ fiat_p224_addcarryx_u32(&x212, &x213, x177, (fiat_p224_uint1)x210, 0x0);
uint32_t x214;
fiat_p224_uint1 x215;
- fiat_p224_addcarryx_u32(&x214, &x215, x207, x212, x210);
+ fiat_p224_addcarryx_u32(&x214, &x215, x207, x212, x208);
uint32_t x216;
fiat_p224_uint1 x217;
- fiat_p224_addcarryx_u32(&x216, &x217, 0x0, (arg1[5]), x196);
+ fiat_p224_addcarryx_u32(&x216, &x217, 0x0, x196, (arg1[5]));
uint32_t x218;
fiat_p224_uint1 x219;
- fiat_p224_addcarryx_u32(&x218, &x219, x217, 0x0, x198);
+ fiat_p224_addcarryx_u32(&x218, &x219, x217, x198, 0x0);
uint32_t x220;
fiat_p224_uint1 x221;
- fiat_p224_addcarryx_u32(&x220, &x221, x219, 0x0, x200);
+ fiat_p224_addcarryx_u32(&x220, &x221, x219, x200, 0x0);
uint32_t x222;
fiat_p224_uint1 x223;
- fiat_p224_addcarryx_u32(&x222, &x223, x221, 0x0, x202);
+ fiat_p224_addcarryx_u32(&x222, &x223, x221, x202, 0x0);
uint32_t x224;
fiat_p224_uint1 x225;
- fiat_p224_addcarryx_u32(&x224, &x225, x223, 0x0, x204);
+ fiat_p224_addcarryx_u32(&x224, &x225, x223, x204, 0x0);
uint32_t x226;
fiat_p224_uint1 x227;
- fiat_p224_addcarryx_u32(&x226, &x227, x225, 0x0, x206);
+ fiat_p224_addcarryx_u32(&x226, &x227, x225, x206, 0x0);
uint32_t x228;
fiat_p224_uint1 x229;
- fiat_p224_addcarryx_u32(&x228, &x229, x227, 0x0, x214);
+ fiat_p224_addcarryx_u32(&x228, &x229, x227, x214, 0x0);
uint32_t x230;
uint32_t x231;
fiat_p224_mulx_u32(&x230, &x231, x216, UINT32_C(0xffffffff));
@@ -2464,67 +2464,67 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x238, &x239, x230, UINT32_C(0xffffffff));
uint32_t x240;
fiat_p224_uint1 x241;
- fiat_p224_addcarryx_u32(&x240, &x241, 0x0, x236, x239);
+ fiat_p224_addcarryx_u32(&x240, &x241, 0x0, x239, x236);
uint32_t x242;
fiat_p224_uint1 x243;
- fiat_p224_addcarryx_u32(&x242, &x243, x241, x234, x237);
+ fiat_p224_addcarryx_u32(&x242, &x243, x241, x237, x234);
uint32_t x244;
fiat_p224_uint1 x245;
- fiat_p224_addcarryx_u32(&x244, &x245, x243, x232, x235);
+ fiat_p224_addcarryx_u32(&x244, &x245, x243, x235, x232);
uint32_t x246;
fiat_p224_uint1 x247;
- fiat_p224_addcarryx_u32(&x246, &x247, 0x0, x230, x216);
+ fiat_p224_addcarryx_u32(&x246, &x247, 0x0, x216, x230);
uint32_t x248;
fiat_p224_uint1 x249;
- fiat_p224_addcarryx_u32(&x248, &x249, x247, 0x0, x218);
+ fiat_p224_addcarryx_u32(&x248, &x249, x247, x218, 0x0);
uint32_t x250;
fiat_p224_uint1 x251;
- fiat_p224_addcarryx_u32(&x250, &x251, x249, 0x0, x220);
+ fiat_p224_addcarryx_u32(&x250, &x251, x249, x220, 0x0);
uint32_t x252;
fiat_p224_uint1 x253;
- fiat_p224_addcarryx_u32(&x252, &x253, x251, x238, x222);
+ fiat_p224_addcarryx_u32(&x252, &x253, x251, x222, x238);
uint32_t x254;
fiat_p224_uint1 x255;
- fiat_p224_addcarryx_u32(&x254, &x255, x253, x240, x224);
+ fiat_p224_addcarryx_u32(&x254, &x255, x253, x224, x240);
uint32_t x256;
fiat_p224_uint1 x257;
- fiat_p224_addcarryx_u32(&x256, &x257, x255, x242, x226);
+ fiat_p224_addcarryx_u32(&x256, &x257, x255, x226, x242);
uint32_t x258;
fiat_p224_uint1 x259;
- fiat_p224_addcarryx_u32(&x258, &x259, x257, x244, x228);
+ fiat_p224_addcarryx_u32(&x258, &x259, x257, x228, x244);
uint32_t x260;
fiat_p224_uint1 x261;
- fiat_p224_addcarryx_u32(&x260, &x261, x215, 0x0, 0x0);
+ fiat_p224_addcarryx_u32(&x260, &x261, x245, x233, 0x0);
uint32_t x262;
fiat_p224_uint1 x263;
- fiat_p224_addcarryx_u32(&x262, &x263, x229, 0x0, (fiat_p224_uint1)x260);
+ fiat_p224_addcarryx_u32(&x262, &x263, x215, 0x0, 0x0);
uint32_t x264;
fiat_p224_uint1 x265;
- fiat_p224_addcarryx_u32(&x264, &x265, x245, 0x0, x233);
+ fiat_p224_addcarryx_u32(&x264, &x265, x229, (fiat_p224_uint1)x262, 0x0);
uint32_t x266;
fiat_p224_uint1 x267;
- fiat_p224_addcarryx_u32(&x266, &x267, x259, x264, x262);
+ fiat_p224_addcarryx_u32(&x266, &x267, x259, x264, x260);
uint32_t x268;
fiat_p224_uint1 x269;
- fiat_p224_addcarryx_u32(&x268, &x269, 0x0, (arg1[6]), x248);
+ fiat_p224_addcarryx_u32(&x268, &x269, 0x0, x248, (arg1[6]));
uint32_t x270;
fiat_p224_uint1 x271;
- fiat_p224_addcarryx_u32(&x270, &x271, x269, 0x0, x250);
+ fiat_p224_addcarryx_u32(&x270, &x271, x269, x250, 0x0);
uint32_t x272;
fiat_p224_uint1 x273;
- fiat_p224_addcarryx_u32(&x272, &x273, x271, 0x0, x252);
+ fiat_p224_addcarryx_u32(&x272, &x273, x271, x252, 0x0);
uint32_t x274;
fiat_p224_uint1 x275;
- fiat_p224_addcarryx_u32(&x274, &x275, x273, 0x0, x254);
+ fiat_p224_addcarryx_u32(&x274, &x275, x273, x254, 0x0);
uint32_t x276;
fiat_p224_uint1 x277;
- fiat_p224_addcarryx_u32(&x276, &x277, x275, 0x0, x256);
+ fiat_p224_addcarryx_u32(&x276, &x277, x275, x256, 0x0);
uint32_t x278;
fiat_p224_uint1 x279;
- fiat_p224_addcarryx_u32(&x278, &x279, x277, 0x0, x258);
+ fiat_p224_addcarryx_u32(&x278, &x279, x277, x258, 0x0);
uint32_t x280;
fiat_p224_uint1 x281;
- fiat_p224_addcarryx_u32(&x280, &x281, x279, 0x0, x266);
+ fiat_p224_addcarryx_u32(&x280, &x281, x279, x266, 0x0);
uint32_t x282;
uint32_t x283;
fiat_p224_mulx_u32(&x282, &x283, x268, UINT32_C(0xffffffff));
@@ -2542,46 +2542,46 @@ static void fiat_p224_from_montgomery(uint32_t out1[7], const uint32_t arg1[7])
fiat_p224_mulx_u32(&x290, &x291, x282, UINT32_C(0xffffffff));
uint32_t x292;
fiat_p224_uint1 x293;
- fiat_p224_addcarryx_u32(&x292, &x293, 0x0, x288, x291);
+ fiat_p224_addcarryx_u32(&x292, &x293, 0x0, x291, x288);
uint32_t x294;
fiat_p224_uint1 x295;
- fiat_p224_addcarryx_u32(&x294, &x295, x293, x286, x289);
+ fiat_p224_addcarryx_u32(&x294, &x295, x293, x289, x286);
uint32_t x296;
fiat_p224_uint1 x297;
- fiat_p224_addcarryx_u32(&x296, &x297, x295, x284, x287);
+ fiat_p224_addcarryx_u32(&x296, &x297, x295, x287, x284);
uint32_t x298;
fiat_p224_uint1 x299;
- fiat_p224_addcarryx_u32(&x298, &x299, 0x0, x282, x268);
+ fiat_p224_addcarryx_u32(&x298, &x299, 0x0, x268, x282);
uint32_t x300;
fiat_p224_uint1 x301;
- fiat_p224_addcarryx_u32(&x300, &x301, x299, 0x0, x270);
+ fiat_p224_addcarryx_u32(&x300, &x301, x299, x270, 0x0);
uint32_t x302;
fiat_p224_uint1 x303;
- fiat_p224_addcarryx_u32(&x302, &x303, x301, 0x0, x272);
+ fiat_p224_addcarryx_u32(&x302, &x303, x301, x272, 0x0);
uint32_t x304;
fiat_p224_uint1 x305;
- fiat_p224_addcarryx_u32(&x304, &x305, x303, x290, x274);
+ fiat_p224_addcarryx_u32(&x304, &x305, x303, x274, x290);
uint32_t x306;
fiat_p224_uint1 x307;
- fiat_p224_addcarryx_u32(&x306, &x307, x305, x292, x276);
+ fiat_p224_addcarryx_u32(&x306, &x307, x305, x276, x292);
uint32_t x308;
fiat_p224_uint1 x309;
- fiat_p224_addcarryx_u32(&x308, &x309, x307, x294, x278);
+ fiat_p224_addcarryx_u32(&x308, &x309, x307, x278, x294);
uint32_t x310;
fiat_p224_uint1 x311;
- fiat_p224_addcarryx_u32(&x310, &x311, x309, x296, x280);
+ fiat_p224_addcarryx_u32(&x310, &x311, x309, x280, x296);
uint32_t x312;
fiat_p224_uint1 x313;
- fiat_p224_addcarryx_u32(&x312, &x313, x267, 0x0, 0x0);
+ fiat_p224_addcarryx_u32(&x312, &x313, x297, x285, 0x0);
uint32_t x314;
fiat_p224_uint1 x315;
- fiat_p224_addcarryx_u32(&x314, &x315, x281, 0x0, (fiat_p224_uint1)x312);
+ fiat_p224_addcarryx_u32(&x314, &x315, x267, 0x0, 0x0);
uint32_t x316;
fiat_p224_uint1 x317;
- fiat_p224_addcarryx_u32(&x316, &x317, x297, 0x0, x285);
+ fiat_p224_addcarryx_u32(&x316, &x317, x281, (fiat_p224_uint1)x314, 0x0);
uint32_t x318;
fiat_p224_uint1 x319;
- fiat_p224_addcarryx_u32(&x318, &x319, x311, x316, x314);
+ fiat_p224_addcarryx_u32(&x318, &x319, x311, x316, x312);
uint32_t x320;
fiat_p224_uint1 x321;
fiat_p224_subborrowx_u32(&x320, &x321, 0x0, x300, 0x1);
diff --git a/p224_64.c b/p224_64.c
index 0dd8edb1c..d862e5802 100644
--- a/p224_64.c
+++ b/p224_64.c
@@ -136,16 +136,16 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x11, &x12, x4, (arg2[0]));
uint64_t x13;
fiat_p224_uint1 x14;
- fiat_p224_addcarryx_u64(&x13, &x14, 0x0, x9, x12);
+ fiat_p224_addcarryx_u64(&x13, &x14, 0x0, x12, x9);
uint64_t x15;
fiat_p224_uint1 x16;
- fiat_p224_addcarryx_u64(&x15, &x16, x14, x7, x10);
+ fiat_p224_addcarryx_u64(&x15, &x16, x14, x10, x7);
uint64_t x17;
fiat_p224_uint1 x18;
- fiat_p224_addcarryx_u64(&x17, &x18, x16, x5, x8);
+ fiat_p224_addcarryx_u64(&x17, &x18, x16, x8, x5);
uint64_t x19;
fiat_p224_uint1 x20;
- fiat_p224_addcarryx_u64(&x19, &x20, x18, 0x0, x6);
+ fiat_p224_addcarryx_u64(&x19, &x20, x18, x6, 0x0);
uint64_t x21;
uint64_t x22;
fiat_p224_mulx_u64(&x21, &x22, x11, UINT64_C(0xffffffffffffffff));
@@ -160,28 +160,28 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x27, &x28, x21, UINT64_C(0xffffffff00000000));
uint64_t x29;
fiat_p224_uint1 x30;
- fiat_p224_addcarryx_u64(&x29, &x30, 0x0, x25, x28);
+ fiat_p224_addcarryx_u64(&x29, &x30, 0x0, x28, x25);
uint64_t x31;
fiat_p224_uint1 x32;
- fiat_p224_addcarryx_u64(&x31, &x32, x30, x23, x26);
+ fiat_p224_addcarryx_u64(&x31, &x32, x30, x26, x23);
uint64_t x33;
fiat_p224_uint1 x34;
- fiat_p224_addcarryx_u64(&x33, &x34, x32, 0x0, x24);
+ fiat_p224_addcarryx_u64(&x33, &x34, x32, x24, 0x0);
uint64_t x35;
fiat_p224_uint1 x36;
- fiat_p224_addcarryx_u64(&x35, &x36, 0x0, x21, x11);
+ fiat_p224_addcarryx_u64(&x35, &x36, 0x0, x11, x21);
uint64_t x37;
fiat_p224_uint1 x38;
- fiat_p224_addcarryx_u64(&x37, &x38, x36, x27, x13);
+ fiat_p224_addcarryx_u64(&x37, &x38, x36, x13, x27);
uint64_t x39;
fiat_p224_uint1 x40;
- fiat_p224_addcarryx_u64(&x39, &x40, x38, x29, x15);
+ fiat_p224_addcarryx_u64(&x39, &x40, x38, x15, x29);
uint64_t x41;
fiat_p224_uint1 x42;
- fiat_p224_addcarryx_u64(&x41, &x42, x40, x31, x17);
+ fiat_p224_addcarryx_u64(&x41, &x42, x40, x17, x31);
uint64_t x43;
fiat_p224_uint1 x44;
- fiat_p224_addcarryx_u64(&x43, &x44, x42, x33, x19);
+ fiat_p224_addcarryx_u64(&x43, &x44, x42, x19, x33);
uint64_t x45;
fiat_p224_uint1 x46;
fiat_p224_addcarryx_u64(&x45, &x46, x44, 0x0, 0x0);
@@ -199,31 +199,31 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x53, &x54, x1, (arg2[0]));
uint64_t x55;
fiat_p224_uint1 x56;
- fiat_p224_addcarryx_u64(&x55, &x56, 0x0, x51, x54);
+ fiat_p224_addcarryx_u64(&x55, &x56, 0x0, x54, x51);
uint64_t x57;
fiat_p224_uint1 x58;
- fiat_p224_addcarryx_u64(&x57, &x58, x56, x49, x52);
+ fiat_p224_addcarryx_u64(&x57, &x58, x56, x52, x49);
uint64_t x59;
fiat_p224_uint1 x60;
- fiat_p224_addcarryx_u64(&x59, &x60, x58, x47, x50);
+ fiat_p224_addcarryx_u64(&x59, &x60, x58, x50, x47);
uint64_t x61;
fiat_p224_uint1 x62;
- fiat_p224_addcarryx_u64(&x61, &x62, x60, 0x0, x48);
+ fiat_p224_addcarryx_u64(&x61, &x62, x60, x48, 0x0);
uint64_t x63;
fiat_p224_uint1 x64;
- fiat_p224_addcarryx_u64(&x63, &x64, 0x0, x53, x37);
+ fiat_p224_addcarryx_u64(&x63, &x64, 0x0, x37, x53);
uint64_t x65;
fiat_p224_uint1 x66;
- fiat_p224_addcarryx_u64(&x65, &x66, x64, x55, x39);
+ fiat_p224_addcarryx_u64(&x65, &x66, x64, x39, x55);
uint64_t x67;
fiat_p224_uint1 x68;
- fiat_p224_addcarryx_u64(&x67, &x68, x66, x57, x41);
+ fiat_p224_addcarryx_u64(&x67, &x68, x66, x41, x57);
uint64_t x69;
fiat_p224_uint1 x70;
- fiat_p224_addcarryx_u64(&x69, &x70, x68, x59, x43);
+ fiat_p224_addcarryx_u64(&x69, &x70, x68, x43, x59);
uint64_t x71;
fiat_p224_uint1 x72;
- fiat_p224_addcarryx_u64(&x71, &x72, x70, x61, (fiat_p224_uint1)x45);
+ fiat_p224_addcarryx_u64(&x71, &x72, x70, (fiat_p224_uint1)x45, x61);
uint64_t x73;
uint64_t x74;
fiat_p224_mulx_u64(&x73, &x74, x63, UINT64_C(0xffffffffffffffff));
@@ -238,31 +238,31 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x79, &x80, x73, UINT64_C(0xffffffff00000000));
uint64_t x81;
fiat_p224_uint1 x82;
- fiat_p224_addcarryx_u64(&x81, &x82, 0x0, x77, x80);
+ fiat_p224_addcarryx_u64(&x81, &x82, 0x0, x80, x77);
uint64_t x83;
fiat_p224_uint1 x84;
- fiat_p224_addcarryx_u64(&x83, &x84, x82, x75, x78);
+ fiat_p224_addcarryx_u64(&x83, &x84, x82, x78, x75);
uint64_t x85;
fiat_p224_uint1 x86;
- fiat_p224_addcarryx_u64(&x85, &x86, x84, 0x0, x76);
+ fiat_p224_addcarryx_u64(&x85, &x86, x84, x76, 0x0);
uint64_t x87;
fiat_p224_uint1 x88;
- fiat_p224_addcarryx_u64(&x87, &x88, 0x0, x73, x63);
+ fiat_p224_addcarryx_u64(&x87, &x88, 0x0, x63, x73);
uint64_t x89;
fiat_p224_uint1 x90;
- fiat_p224_addcarryx_u64(&x89, &x90, x88, x79, x65);
+ fiat_p224_addcarryx_u64(&x89, &x90, x88, x65, x79);
uint64_t x91;
fiat_p224_uint1 x92;
- fiat_p224_addcarryx_u64(&x91, &x92, x90, x81, x67);
+ fiat_p224_addcarryx_u64(&x91, &x92, x90, x67, x81);
uint64_t x93;
fiat_p224_uint1 x94;
- fiat_p224_addcarryx_u64(&x93, &x94, x92, x83, x69);
+ fiat_p224_addcarryx_u64(&x93, &x94, x92, x69, x83);
uint64_t x95;
fiat_p224_uint1 x96;
- fiat_p224_addcarryx_u64(&x95, &x96, x94, x85, x71);
+ fiat_p224_addcarryx_u64(&x95, &x96, x94, x71, x85);
uint64_t x97;
fiat_p224_uint1 x98;
- fiat_p224_addcarryx_u64(&x97, &x98, x96, 0x0, x72);
+ fiat_p224_addcarryx_u64(&x97, &x98, x96, x72, 0x0);
uint64_t x99;
uint64_t x100;
fiat_p224_mulx_u64(&x99, &x100, x2, (arg2[3]));
@@ -277,31 +277,31 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x105, &x106, x2, (arg2[0]));
uint64_t x107;
fiat_p224_uint1 x108;
- fiat_p224_addcarryx_u64(&x107, &x108, 0x0, x103, x106);
+ fiat_p224_addcarryx_u64(&x107, &x108, 0x0, x106, x103);
uint64_t x109;
fiat_p224_uint1 x110;
- fiat_p224_addcarryx_u64(&x109, &x110, x108, x101, x104);
+ fiat_p224_addcarryx_u64(&x109, &x110, x108, x104, x101);
uint64_t x111;
fiat_p224_uint1 x112;
- fiat_p224_addcarryx_u64(&x111, &x112, x110, x99, x102);
+ fiat_p224_addcarryx_u64(&x111, &x112, x110, x102, x99);
uint64_t x113;
fiat_p224_uint1 x114;
- fiat_p224_addcarryx_u64(&x113, &x114, x112, 0x0, x100);
+ fiat_p224_addcarryx_u64(&x113, &x114, x112, x100, 0x0);
uint64_t x115;
fiat_p224_uint1 x116;
- fiat_p224_addcarryx_u64(&x115, &x116, 0x0, x105, x89);
+ fiat_p224_addcarryx_u64(&x115, &x116, 0x0, x89, x105);
uint64_t x117;
fiat_p224_uint1 x118;
- fiat_p224_addcarryx_u64(&x117, &x118, x116, x107, x91);
+ fiat_p224_addcarryx_u64(&x117, &x118, x116, x91, x107);
uint64_t x119;
fiat_p224_uint1 x120;
- fiat_p224_addcarryx_u64(&x119, &x120, x118, x109, x93);
+ fiat_p224_addcarryx_u64(&x119, &x120, x118, x93, x109);
uint64_t x121;
fiat_p224_uint1 x122;
- fiat_p224_addcarryx_u64(&x121, &x122, x120, x111, x95);
+ fiat_p224_addcarryx_u64(&x121, &x122, x120, x95, x111);
uint64_t x123;
fiat_p224_uint1 x124;
- fiat_p224_addcarryx_u64(&x123, &x124, x122, x113, x97);
+ fiat_p224_addcarryx_u64(&x123, &x124, x122, x97, x113);
uint64_t x125;
uint64_t x126;
fiat_p224_mulx_u64(&x125, &x126, x115, UINT64_C(0xffffffffffffffff));
@@ -316,31 +316,31 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x131, &x132, x125, UINT64_C(0xffffffff00000000));
uint64_t x133;
fiat_p224_uint1 x134;
- fiat_p224_addcarryx_u64(&x133, &x134, 0x0, x129, x132);
+ fiat_p224_addcarryx_u64(&x133, &x134, 0x0, x132, x129);
uint64_t x135;
fiat_p224_uint1 x136;
- fiat_p224_addcarryx_u64(&x135, &x136, x134, x127, x130);
+ fiat_p224_addcarryx_u64(&x135, &x136, x134, x130, x127);
uint64_t x137;
fiat_p224_uint1 x138;
- fiat_p224_addcarryx_u64(&x137, &x138, x136, 0x0, x128);
+ fiat_p224_addcarryx_u64(&x137, &x138, x136, x128, 0x0);
uint64_t x139;
fiat_p224_uint1 x140;
- fiat_p224_addcarryx_u64(&x139, &x140, 0x0, x125, x115);
+ fiat_p224_addcarryx_u64(&x139, &x140, 0x0, x115, x125);
uint64_t x141;
fiat_p224_uint1 x142;
- fiat_p224_addcarryx_u64(&x141, &x142, x140, x131, x117);
+ fiat_p224_addcarryx_u64(&x141, &x142, x140, x117, x131);
uint64_t x143;
fiat_p224_uint1 x144;
- fiat_p224_addcarryx_u64(&x143, &x144, x142, x133, x119);
+ fiat_p224_addcarryx_u64(&x143, &x144, x142, x119, x133);
uint64_t x145;
fiat_p224_uint1 x146;
- fiat_p224_addcarryx_u64(&x145, &x146, x144, x135, x121);
+ fiat_p224_addcarryx_u64(&x145, &x146, x144, x121, x135);
uint64_t x147;
fiat_p224_uint1 x148;
- fiat_p224_addcarryx_u64(&x147, &x148, x146, x137, x123);
+ fiat_p224_addcarryx_u64(&x147, &x148, x146, x123, x137);
uint64_t x149;
fiat_p224_uint1 x150;
- fiat_p224_addcarryx_u64(&x149, &x150, x148, 0x0, x124);
+ fiat_p224_addcarryx_u64(&x149, &x150, x148, x124, 0x0);
uint64_t x151;
uint64_t x152;
fiat_p224_mulx_u64(&x151, &x152, x3, (arg2[3]));
@@ -355,31 +355,31 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x157, &x158, x3, (arg2[0]));
uint64_t x159;
fiat_p224_uint1 x160;
- fiat_p224_addcarryx_u64(&x159, &x160, 0x0, x155, x158);
+ fiat_p224_addcarryx_u64(&x159, &x160, 0x0, x158, x155);
uint64_t x161;
fiat_p224_uint1 x162;
- fiat_p224_addcarryx_u64(&x161, &x162, x160, x153, x156);
+ fiat_p224_addcarryx_u64(&x161, &x162, x160, x156, x153);
uint64_t x163;
fiat_p224_uint1 x164;
- fiat_p224_addcarryx_u64(&x163, &x164, x162, x151, x154);
+ fiat_p224_addcarryx_u64(&x163, &x164, x162, x154, x151);
uint64_t x165;
fiat_p224_uint1 x166;
- fiat_p224_addcarryx_u64(&x165, &x166, x164, 0x0, x152);
+ fiat_p224_addcarryx_u64(&x165, &x166, x164, x152, 0x0);
uint64_t x167;
fiat_p224_uint1 x168;
- fiat_p224_addcarryx_u64(&x167, &x168, 0x0, x157, x141);
+ fiat_p224_addcarryx_u64(&x167, &x168, 0x0, x141, x157);
uint64_t x169;
fiat_p224_uint1 x170;
- fiat_p224_addcarryx_u64(&x169, &x170, x168, x159, x143);
+ fiat_p224_addcarryx_u64(&x169, &x170, x168, x143, x159);
uint64_t x171;
fiat_p224_uint1 x172;
- fiat_p224_addcarryx_u64(&x171, &x172, x170, x161, x145);
+ fiat_p224_addcarryx_u64(&x171, &x172, x170, x145, x161);
uint64_t x173;
fiat_p224_uint1 x174;
- fiat_p224_addcarryx_u64(&x173, &x174, x172, x163, x147);
+ fiat_p224_addcarryx_u64(&x173, &x174, x172, x147, x163);
uint64_t x175;
fiat_p224_uint1 x176;
- fiat_p224_addcarryx_u64(&x175, &x176, x174, x165, x149);
+ fiat_p224_addcarryx_u64(&x175, &x176, x174, x149, x165);
uint64_t x177;
uint64_t x178;
fiat_p224_mulx_u64(&x177, &x178, x167, UINT64_C(0xffffffffffffffff));
@@ -394,31 +394,31 @@ static void fiat_p224_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_mulx_u64(&x183, &x184, x177, UINT64_C(0xffffffff00000000));
uint64_t x185;
fiat_p224_uint1 x186;
- fiat_p224_addcarryx_u64(&x185, &x186, 0x0, x181, x184);
+ fiat_p224_addcarryx_u64(&x185, &x186, 0x0, x184, x181);
uint64_t x187;
fiat_p224_uint1 x188;
- fiat_p224_addcarryx_u64(&x187, &x188, x186, x179, x182);
+ fiat_p224_addcarryx_u64(&x187, &x188, x186, x182, x179);
uint64_t x189;
fiat_p224_uint1 x190;
- fiat_p224_addcarryx_u64(&x189, &x190, x188, 0x0, x180);
+ fiat_p224_addcarryx_u64(&x189, &x190, x188, x180, 0x0);
uint64_t x191;
fiat_p224_uint1 x192;
- fiat_p224_addcarryx_u64(&x191, &x192, 0x0, x177, x167);
+ fiat_p224_addcarryx_u64(&x191, &x192, 0x0, x167, x177);
uint64_t x193;
fiat_p224_uint1 x194;
- fiat_p224_addcarryx_u64(&x193, &x194, x192, x183, x169);
+ fiat_p224_addcarryx_u64(&x193, &x194, x192, x169, x183);
uint64_t x195;
fiat_p224_uint1 x196;
- fiat_p224_addcarryx_u64(&x195, &x196, x194, x185, x171);
+ fiat_p224_addcarryx_u64(&x195, &x196, x194, x171, x185);
uint64_t x197;
fiat_p224_uint1 x198;
- fiat_p224_addcarryx_u64(&x197, &x198, x196, x187, x173);
+ fiat_p224_addcarryx_u64(&x197, &x198, x196, x173, x187);
uint64_t x199;
fiat_p224_uint1 x200;
- fiat_p224_addcarryx_u64(&x199, &x200, x198, x189, x175);
+ fiat_p224_addcarryx_u64(&x199, &x200, x198, x175, x189);
uint64_t x201;
fiat_p224_uint1 x202;
- fiat_p224_addcarryx_u64(&x201, &x202, x200, 0x0, x176);
+ fiat_p224_addcarryx_u64(&x201, &x202, x200, x176, 0x0);
uint64_t x203;
fiat_p224_uint1 x204;
fiat_p224_subborrowx_u64(&x203, &x204, 0x0, x193, 0x1);
@@ -480,16 +480,16 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x11, &x12, x4, (arg1[0]));
uint64_t x13;
fiat_p224_uint1 x14;
- fiat_p224_addcarryx_u64(&x13, &x14, 0x0, x9, x12);
+ fiat_p224_addcarryx_u64(&x13, &x14, 0x0, x12, x9);
uint64_t x15;
fiat_p224_uint1 x16;
- fiat_p224_addcarryx_u64(&x15, &x16, x14, x7, x10);
+ fiat_p224_addcarryx_u64(&x15, &x16, x14, x10, x7);
uint64_t x17;
fiat_p224_uint1 x18;
- fiat_p224_addcarryx_u64(&x17, &x18, x16, x5, x8);
+ fiat_p224_addcarryx_u64(&x17, &x18, x16, x8, x5);
uint64_t x19;
fiat_p224_uint1 x20;
- fiat_p224_addcarryx_u64(&x19, &x20, x18, 0x0, x6);
+ fiat_p224_addcarryx_u64(&x19, &x20, x18, x6, 0x0);
uint64_t x21;
uint64_t x22;
fiat_p224_mulx_u64(&x21, &x22, x11, UINT64_C(0xffffffffffffffff));
@@ -504,28 +504,28 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x27, &x28, x21, UINT64_C(0xffffffff00000000));
uint64_t x29;
fiat_p224_uint1 x30;
- fiat_p224_addcarryx_u64(&x29, &x30, 0x0, x25, x28);
+ fiat_p224_addcarryx_u64(&x29, &x30, 0x0, x28, x25);
uint64_t x31;
fiat_p224_uint1 x32;
- fiat_p224_addcarryx_u64(&x31, &x32, x30, x23, x26);
+ fiat_p224_addcarryx_u64(&x31, &x32, x30, x26, x23);
uint64_t x33;
fiat_p224_uint1 x34;
- fiat_p224_addcarryx_u64(&x33, &x34, x32, 0x0, x24);
+ fiat_p224_addcarryx_u64(&x33, &x34, x32, x24, 0x0);
uint64_t x35;
fiat_p224_uint1 x36;
- fiat_p224_addcarryx_u64(&x35, &x36, 0x0, x21, x11);
+ fiat_p224_addcarryx_u64(&x35, &x36, 0x0, x11, x21);
uint64_t x37;
fiat_p224_uint1 x38;
- fiat_p224_addcarryx_u64(&x37, &x38, x36, x27, x13);
+ fiat_p224_addcarryx_u64(&x37, &x38, x36, x13, x27);
uint64_t x39;
fiat_p224_uint1 x40;
- fiat_p224_addcarryx_u64(&x39, &x40, x38, x29, x15);
+ fiat_p224_addcarryx_u64(&x39, &x40, x38, x15, x29);
uint64_t x41;
fiat_p224_uint1 x42;
- fiat_p224_addcarryx_u64(&x41, &x42, x40, x31, x17);
+ fiat_p224_addcarryx_u64(&x41, &x42, x40, x17, x31);
uint64_t x43;
fiat_p224_uint1 x44;
- fiat_p224_addcarryx_u64(&x43, &x44, x42, x33, x19);
+ fiat_p224_addcarryx_u64(&x43, &x44, x42, x19, x33);
uint64_t x45;
fiat_p224_uint1 x46;
fiat_p224_addcarryx_u64(&x45, &x46, x44, 0x0, 0x0);
@@ -543,31 +543,31 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x53, &x54, x1, (arg1[0]));
uint64_t x55;
fiat_p224_uint1 x56;
- fiat_p224_addcarryx_u64(&x55, &x56, 0x0, x51, x54);
+ fiat_p224_addcarryx_u64(&x55, &x56, 0x0, x54, x51);
uint64_t x57;
fiat_p224_uint1 x58;
- fiat_p224_addcarryx_u64(&x57, &x58, x56, x49, x52);
+ fiat_p224_addcarryx_u64(&x57, &x58, x56, x52, x49);
uint64_t x59;
fiat_p224_uint1 x60;
- fiat_p224_addcarryx_u64(&x59, &x60, x58, x47, x50);
+ fiat_p224_addcarryx_u64(&x59, &x60, x58, x50, x47);
uint64_t x61;
fiat_p224_uint1 x62;
- fiat_p224_addcarryx_u64(&x61, &x62, x60, 0x0, x48);
+ fiat_p224_addcarryx_u64(&x61, &x62, x60, x48, 0x0);
uint64_t x63;
fiat_p224_uint1 x64;
- fiat_p224_addcarryx_u64(&x63, &x64, 0x0, x53, x37);
+ fiat_p224_addcarryx_u64(&x63, &x64, 0x0, x37, x53);
uint64_t x65;
fiat_p224_uint1 x66;
- fiat_p224_addcarryx_u64(&x65, &x66, x64, x55, x39);
+ fiat_p224_addcarryx_u64(&x65, &x66, x64, x39, x55);
uint64_t x67;
fiat_p224_uint1 x68;
- fiat_p224_addcarryx_u64(&x67, &x68, x66, x57, x41);
+ fiat_p224_addcarryx_u64(&x67, &x68, x66, x41, x57);
uint64_t x69;
fiat_p224_uint1 x70;
- fiat_p224_addcarryx_u64(&x69, &x70, x68, x59, x43);
+ fiat_p224_addcarryx_u64(&x69, &x70, x68, x43, x59);
uint64_t x71;
fiat_p224_uint1 x72;
- fiat_p224_addcarryx_u64(&x71, &x72, x70, x61, (fiat_p224_uint1)x45);
+ fiat_p224_addcarryx_u64(&x71, &x72, x70, (fiat_p224_uint1)x45, x61);
uint64_t x73;
uint64_t x74;
fiat_p224_mulx_u64(&x73, &x74, x63, UINT64_C(0xffffffffffffffff));
@@ -582,31 +582,31 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x79, &x80, x73, UINT64_C(0xffffffff00000000));
uint64_t x81;
fiat_p224_uint1 x82;
- fiat_p224_addcarryx_u64(&x81, &x82, 0x0, x77, x80);
+ fiat_p224_addcarryx_u64(&x81, &x82, 0x0, x80, x77);
uint64_t x83;
fiat_p224_uint1 x84;
- fiat_p224_addcarryx_u64(&x83, &x84, x82, x75, x78);
+ fiat_p224_addcarryx_u64(&x83, &x84, x82, x78, x75);
uint64_t x85;
fiat_p224_uint1 x86;
- fiat_p224_addcarryx_u64(&x85, &x86, x84, 0x0, x76);
+ fiat_p224_addcarryx_u64(&x85, &x86, x84, x76, 0x0);
uint64_t x87;
fiat_p224_uint1 x88;
- fiat_p224_addcarryx_u64(&x87, &x88, 0x0, x73, x63);
+ fiat_p224_addcarryx_u64(&x87, &x88, 0x0, x63, x73);
uint64_t x89;
fiat_p224_uint1 x90;
- fiat_p224_addcarryx_u64(&x89, &x90, x88, x79, x65);
+ fiat_p224_addcarryx_u64(&x89, &x90, x88, x65, x79);
uint64_t x91;
fiat_p224_uint1 x92;
- fiat_p224_addcarryx_u64(&x91, &x92, x90, x81, x67);
+ fiat_p224_addcarryx_u64(&x91, &x92, x90, x67, x81);
uint64_t x93;
fiat_p224_uint1 x94;
- fiat_p224_addcarryx_u64(&x93, &x94, x92, x83, x69);
+ fiat_p224_addcarryx_u64(&x93, &x94, x92, x69, x83);
uint64_t x95;
fiat_p224_uint1 x96;
- fiat_p224_addcarryx_u64(&x95, &x96, x94, x85, x71);
+ fiat_p224_addcarryx_u64(&x95, &x96, x94, x71, x85);
uint64_t x97;
fiat_p224_uint1 x98;
- fiat_p224_addcarryx_u64(&x97, &x98, x96, 0x0, x72);
+ fiat_p224_addcarryx_u64(&x97, &x98, x96, x72, 0x0);
uint64_t x99;
uint64_t x100;
fiat_p224_mulx_u64(&x99, &x100, x2, (arg1[3]));
@@ -621,31 +621,31 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x105, &x106, x2, (arg1[0]));
uint64_t x107;
fiat_p224_uint1 x108;
- fiat_p224_addcarryx_u64(&x107, &x108, 0x0, x103, x106);
+ fiat_p224_addcarryx_u64(&x107, &x108, 0x0, x106, x103);
uint64_t x109;
fiat_p224_uint1 x110;
- fiat_p224_addcarryx_u64(&x109, &x110, x108, x101, x104);
+ fiat_p224_addcarryx_u64(&x109, &x110, x108, x104, x101);
uint64_t x111;
fiat_p224_uint1 x112;
- fiat_p224_addcarryx_u64(&x111, &x112, x110, x99, x102);
+ fiat_p224_addcarryx_u64(&x111, &x112, x110, x102, x99);
uint64_t x113;
fiat_p224_uint1 x114;
- fiat_p224_addcarryx_u64(&x113, &x114, x112, 0x0, x100);
+ fiat_p224_addcarryx_u64(&x113, &x114, x112, x100, 0x0);
uint64_t x115;
fiat_p224_uint1 x116;
- fiat_p224_addcarryx_u64(&x115, &x116, 0x0, x105, x89);
+ fiat_p224_addcarryx_u64(&x115, &x116, 0x0, x89, x105);
uint64_t x117;
fiat_p224_uint1 x118;
- fiat_p224_addcarryx_u64(&x117, &x118, x116, x107, x91);
+ fiat_p224_addcarryx_u64(&x117, &x118, x116, x91, x107);
uint64_t x119;
fiat_p224_uint1 x120;
- fiat_p224_addcarryx_u64(&x119, &x120, x118, x109, x93);
+ fiat_p224_addcarryx_u64(&x119, &x120, x118, x93, x109);
uint64_t x121;
fiat_p224_uint1 x122;
- fiat_p224_addcarryx_u64(&x121, &x122, x120, x111, x95);
+ fiat_p224_addcarryx_u64(&x121, &x122, x120, x95, x111);
uint64_t x123;
fiat_p224_uint1 x124;
- fiat_p224_addcarryx_u64(&x123, &x124, x122, x113, x97);
+ fiat_p224_addcarryx_u64(&x123, &x124, x122, x97, x113);
uint64_t x125;
uint64_t x126;
fiat_p224_mulx_u64(&x125, &x126, x115, UINT64_C(0xffffffffffffffff));
@@ -660,31 +660,31 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x131, &x132, x125, UINT64_C(0xffffffff00000000));
uint64_t x133;
fiat_p224_uint1 x134;
- fiat_p224_addcarryx_u64(&x133, &x134, 0x0, x129, x132);
+ fiat_p224_addcarryx_u64(&x133, &x134, 0x0, x132, x129);
uint64_t x135;
fiat_p224_uint1 x136;
- fiat_p224_addcarryx_u64(&x135, &x136, x134, x127, x130);
+ fiat_p224_addcarryx_u64(&x135, &x136, x134, x130, x127);
uint64_t x137;
fiat_p224_uint1 x138;
- fiat_p224_addcarryx_u64(&x137, &x138, x136, 0x0, x128);
+ fiat_p224_addcarryx_u64(&x137, &x138, x136, x128, 0x0);
uint64_t x139;
fiat_p224_uint1 x140;
- fiat_p224_addcarryx_u64(&x139, &x140, 0x0, x125, x115);
+ fiat_p224_addcarryx_u64(&x139, &x140, 0x0, x115, x125);
uint64_t x141;
fiat_p224_uint1 x142;
- fiat_p224_addcarryx_u64(&x141, &x142, x140, x131, x117);
+ fiat_p224_addcarryx_u64(&x141, &x142, x140, x117, x131);
uint64_t x143;
fiat_p224_uint1 x144;
- fiat_p224_addcarryx_u64(&x143, &x144, x142, x133, x119);
+ fiat_p224_addcarryx_u64(&x143, &x144, x142, x119, x133);
uint64_t x145;
fiat_p224_uint1 x146;
- fiat_p224_addcarryx_u64(&x145, &x146, x144, x135, x121);
+ fiat_p224_addcarryx_u64(&x145, &x146, x144, x121, x135);
uint64_t x147;
fiat_p224_uint1 x148;
- fiat_p224_addcarryx_u64(&x147, &x148, x146, x137, x123);
+ fiat_p224_addcarryx_u64(&x147, &x148, x146, x123, x137);
uint64_t x149;
fiat_p224_uint1 x150;
- fiat_p224_addcarryx_u64(&x149, &x150, x148, 0x0, x124);
+ fiat_p224_addcarryx_u64(&x149, &x150, x148, x124, 0x0);
uint64_t x151;
uint64_t x152;
fiat_p224_mulx_u64(&x151, &x152, x3, (arg1[3]));
@@ -699,31 +699,31 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x157, &x158, x3, (arg1[0]));
uint64_t x159;
fiat_p224_uint1 x160;
- fiat_p224_addcarryx_u64(&x159, &x160, 0x0, x155, x158);
+ fiat_p224_addcarryx_u64(&x159, &x160, 0x0, x158, x155);
uint64_t x161;
fiat_p224_uint1 x162;
- fiat_p224_addcarryx_u64(&x161, &x162, x160, x153, x156);
+ fiat_p224_addcarryx_u64(&x161, &x162, x160, x156, x153);
uint64_t x163;
fiat_p224_uint1 x164;
- fiat_p224_addcarryx_u64(&x163, &x164, x162, x151, x154);
+ fiat_p224_addcarryx_u64(&x163, &x164, x162, x154, x151);
uint64_t x165;
fiat_p224_uint1 x166;
- fiat_p224_addcarryx_u64(&x165, &x166, x164, 0x0, x152);
+ fiat_p224_addcarryx_u64(&x165, &x166, x164, x152, 0x0);
uint64_t x167;
fiat_p224_uint1 x168;
- fiat_p224_addcarryx_u64(&x167, &x168, 0x0, x157, x141);
+ fiat_p224_addcarryx_u64(&x167, &x168, 0x0, x141, x157);
uint64_t x169;
fiat_p224_uint1 x170;
- fiat_p224_addcarryx_u64(&x169, &x170, x168, x159, x143);
+ fiat_p224_addcarryx_u64(&x169, &x170, x168, x143, x159);
uint64_t x171;
fiat_p224_uint1 x172;
- fiat_p224_addcarryx_u64(&x171, &x172, x170, x161, x145);
+ fiat_p224_addcarryx_u64(&x171, &x172, x170, x145, x161);
uint64_t x173;
fiat_p224_uint1 x174;
- fiat_p224_addcarryx_u64(&x173, &x174, x172, x163, x147);
+ fiat_p224_addcarryx_u64(&x173, &x174, x172, x147, x163);
uint64_t x175;
fiat_p224_uint1 x176;
- fiat_p224_addcarryx_u64(&x175, &x176, x174, x165, x149);
+ fiat_p224_addcarryx_u64(&x175, &x176, x174, x149, x165);
uint64_t x177;
uint64_t x178;
fiat_p224_mulx_u64(&x177, &x178, x167, UINT64_C(0xffffffffffffffff));
@@ -738,31 +738,31 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_mulx_u64(&x183, &x184, x177, UINT64_C(0xffffffff00000000));
uint64_t x185;
fiat_p224_uint1 x186;
- fiat_p224_addcarryx_u64(&x185, &x186, 0x0, x181, x184);
+ fiat_p224_addcarryx_u64(&x185, &x186, 0x0, x184, x181);
uint64_t x187;
fiat_p224_uint1 x188;
- fiat_p224_addcarryx_u64(&x187, &x188, x186, x179, x182);
+ fiat_p224_addcarryx_u64(&x187, &x188, x186, x182, x179);
uint64_t x189;
fiat_p224_uint1 x190;
- fiat_p224_addcarryx_u64(&x189, &x190, x188, 0x0, x180);
+ fiat_p224_addcarryx_u64(&x189, &x190, x188, x180, 0x0);
uint64_t x191;
fiat_p224_uint1 x192;
- fiat_p224_addcarryx_u64(&x191, &x192, 0x0, x177, x167);
+ fiat_p224_addcarryx_u64(&x191, &x192, 0x0, x167, x177);
uint64_t x193;
fiat_p224_uint1 x194;
- fiat_p224_addcarryx_u64(&x193, &x194, x192, x183, x169);
+ fiat_p224_addcarryx_u64(&x193, &x194, x192, x169, x183);
uint64_t x195;
fiat_p224_uint1 x196;
- fiat_p224_addcarryx_u64(&x195, &x196, x194, x185, x171);
+ fiat_p224_addcarryx_u64(&x195, &x196, x194, x171, x185);
uint64_t x197;
fiat_p224_uint1 x198;
- fiat_p224_addcarryx_u64(&x197, &x198, x196, x187, x173);
+ fiat_p224_addcarryx_u64(&x197, &x198, x196, x173, x187);
uint64_t x199;
fiat_p224_uint1 x200;
- fiat_p224_addcarryx_u64(&x199, &x200, x198, x189, x175);
+ fiat_p224_addcarryx_u64(&x199, &x200, x198, x175, x189);
uint64_t x201;
fiat_p224_uint1 x202;
- fiat_p224_addcarryx_u64(&x201, &x202, x200, 0x0, x176);
+ fiat_p224_addcarryx_u64(&x201, &x202, x200, x176, 0x0);
uint64_t x203;
fiat_p224_uint1 x204;
fiat_p224_subborrowx_u64(&x203, &x204, 0x0, x193, 0x1);
@@ -810,16 +810,16 @@ static void fiat_p224_square(uint64_t out1[4], const uint64_t arg1[4]) {
static void fiat_p224_add(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
uint64_t x1;
fiat_p224_uint1 x2;
- fiat_p224_addcarryx_u64(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p224_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint64_t x3;
fiat_p224_uint1 x4;
- fiat_p224_addcarryx_u64(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p224_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint64_t x5;
fiat_p224_uint1 x6;
- fiat_p224_addcarryx_u64(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p224_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint64_t x7;
fiat_p224_uint1 x8;
- fiat_p224_addcarryx_u64(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p224_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint64_t x9;
fiat_p224_uint1 x10;
fiat_p224_subborrowx_u64(&x9, &x10, 0x0, x1, 0x1);
@@ -881,16 +881,16 @@ static void fiat_p224_sub(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p224_cmovznz_u64(&x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x10;
fiat_p224_uint1 x11;
- fiat_p224_addcarryx_u64(&x10, &x11, 0x0, (fiat_p224_uint1)(x9 & 0x1), x1);
+ fiat_p224_addcarryx_u64(&x10, &x11, 0x0, x1, (fiat_p224_uint1)(x9 & 0x1));
uint64_t x12;
fiat_p224_uint1 x13;
- fiat_p224_addcarryx_u64(&x12, &x13, x11, (x9 & UINT64_C(0xffffffff00000000)), x3);
+ fiat_p224_addcarryx_u64(&x12, &x13, x11, x3, (x9 & UINT64_C(0xffffffff00000000)));
uint64_t x14;
fiat_p224_uint1 x15;
- fiat_p224_addcarryx_u64(&x14, &x15, x13, (x9 & UINT64_C(0xffffffffffffffff)), x5);
+ fiat_p224_addcarryx_u64(&x14, &x15, x13, x5, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x16;
fiat_p224_uint1 x17;
- fiat_p224_addcarryx_u64(&x16, &x17, x15, (x9 & UINT32_C(0xffffffff)), x7);
+ fiat_p224_addcarryx_u64(&x16, &x17, x15, x7, (x9 & UINT32_C(0xffffffff)));
out1[0] = x10;
out1[1] = x12;
out1[2] = x14;
@@ -927,16 +927,16 @@ static void fiat_p224_opp(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p224_cmovznz_u64(&x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x10;
fiat_p224_uint1 x11;
- fiat_p224_addcarryx_u64(&x10, &x11, 0x0, (fiat_p224_uint1)(x9 & 0x1), x1);
+ fiat_p224_addcarryx_u64(&x10, &x11, 0x0, x1, (fiat_p224_uint1)(x9 & 0x1));
uint64_t x12;
fiat_p224_uint1 x13;
- fiat_p224_addcarryx_u64(&x12, &x13, x11, (x9 & UINT64_C(0xffffffff00000000)), x3);
+ fiat_p224_addcarryx_u64(&x12, &x13, x11, x3, (x9 & UINT64_C(0xffffffff00000000)));
uint64_t x14;
fiat_p224_uint1 x15;
- fiat_p224_addcarryx_u64(&x14, &x15, x13, (x9 & UINT64_C(0xffffffffffffffff)), x5);
+ fiat_p224_addcarryx_u64(&x14, &x15, x13, x5, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x16;
fiat_p224_uint1 x17;
- fiat_p224_addcarryx_u64(&x16, &x17, x15, (x9 & UINT32_C(0xffffffff)), x7);
+ fiat_p224_addcarryx_u64(&x16, &x17, x15, x7, (x9 & UINT32_C(0xffffffff)));
out1[0] = x10;
out1[1] = x12;
out1[2] = x14;
@@ -972,31 +972,31 @@ static void fiat_p224_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p224_mulx_u64(&x8, &x9, x2, UINT64_C(0xffffffff00000000));
uint64_t x10;
fiat_p224_uint1 x11;
- fiat_p224_addcarryx_u64(&x10, &x11, 0x0, x6, x9);
+ fiat_p224_addcarryx_u64(&x10, &x11, 0x0, x9, x6);
uint64_t x12;
fiat_p224_uint1 x13;
- fiat_p224_addcarryx_u64(&x12, &x13, x11, x4, x7);
+ fiat_p224_addcarryx_u64(&x12, &x13, x11, x7, x4);
uint64_t x14;
fiat_p224_uint1 x15;
- fiat_p224_addcarryx_u64(&x14, &x15, 0x0, x2, x1);
+ fiat_p224_addcarryx_u64(&x14, &x15, 0x0, x1, x2);
uint64_t x16;
fiat_p224_uint1 x17;
- fiat_p224_addcarryx_u64(&x16, &x17, x15, x8, 0x0);
+ fiat_p224_addcarryx_u64(&x16, &x17, x15, 0x0, x8);
uint64_t x18;
fiat_p224_uint1 x19;
- fiat_p224_addcarryx_u64(&x18, &x19, x17, x10, 0x0);
+ fiat_p224_addcarryx_u64(&x18, &x19, x17, 0x0, x10);
uint64_t x20;
fiat_p224_uint1 x21;
- fiat_p224_addcarryx_u64(&x20, &x21, x19, x12, 0x0);
+ fiat_p224_addcarryx_u64(&x20, &x21, x19, 0x0, x12);
uint64_t x22;
fiat_p224_uint1 x23;
- fiat_p224_addcarryx_u64(&x22, &x23, 0x0, (arg1[1]), x16);
+ fiat_p224_addcarryx_u64(&x22, &x23, 0x0, x16, (arg1[1]));
uint64_t x24;
fiat_p224_uint1 x25;
- fiat_p224_addcarryx_u64(&x24, &x25, x23, 0x0, x18);
+ fiat_p224_addcarryx_u64(&x24, &x25, x23, x18, 0x0);
uint64_t x26;
fiat_p224_uint1 x27;
- fiat_p224_addcarryx_u64(&x26, &x27, x25, 0x0, x20);
+ fiat_p224_addcarryx_u64(&x26, &x27, x25, x20, 0x0);
uint64_t x28;
uint64_t x29;
fiat_p224_mulx_u64(&x28, &x29, x22, UINT64_C(0xffffffffffffffff));
@@ -1011,40 +1011,40 @@ static void fiat_p224_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p224_mulx_u64(&x34, &x35, x28, UINT64_C(0xffffffff00000000));
uint64_t x36;
fiat_p224_uint1 x37;
- fiat_p224_addcarryx_u64(&x36, &x37, 0x0, x32, x35);
+ fiat_p224_addcarryx_u64(&x36, &x37, 0x0, x35, x32);
uint64_t x38;
fiat_p224_uint1 x39;
- fiat_p224_addcarryx_u64(&x38, &x39, x37, x30, x33);
+ fiat_p224_addcarryx_u64(&x38, &x39, x37, x33, x30);
uint64_t x40;
fiat_p224_uint1 x41;
- fiat_p224_addcarryx_u64(&x40, &x41, 0x0, x28, x22);
+ fiat_p224_addcarryx_u64(&x40, &x41, 0x0, x22, x28);
uint64_t x42;
fiat_p224_uint1 x43;
- fiat_p224_addcarryx_u64(&x42, &x43, x41, x34, x24);
+ fiat_p224_addcarryx_u64(&x42, &x43, x41, x24, x34);
uint64_t x44;
fiat_p224_uint1 x45;
- fiat_p224_addcarryx_u64(&x44, &x45, x43, x36, x26);
+ fiat_p224_addcarryx_u64(&x44, &x45, x43, x26, x36);
uint64_t x46;
fiat_p224_uint1 x47;
- fiat_p224_addcarryx_u64(&x46, &x47, x13, 0x0, x5);
+ fiat_p224_addcarryx_u64(&x46, &x47, x13, x5, 0x0);
uint64_t x48;
fiat_p224_uint1 x49;
- fiat_p224_addcarryx_u64(&x48, &x49, x21, x46, 0x0);
+ fiat_p224_addcarryx_u64(&x48, &x49, x21, 0x0, x46);
uint64_t x50;
fiat_p224_uint1 x51;
- fiat_p224_addcarryx_u64(&x50, &x51, x27, 0x0, x48);
+ fiat_p224_addcarryx_u64(&x50, &x51, x27, x48, 0x0);
uint64_t x52;
fiat_p224_uint1 x53;
- fiat_p224_addcarryx_u64(&x52, &x53, x45, x38, x50);
+ fiat_p224_addcarryx_u64(&x52, &x53, x45, x50, x38);
uint64_t x54;
fiat_p224_uint1 x55;
- fiat_p224_addcarryx_u64(&x54, &x55, 0x0, (arg1[2]), x42);
+ fiat_p224_addcarryx_u64(&x54, &x55, 0x0, x42, (arg1[2]));
uint64_t x56;
fiat_p224_uint1 x57;
- fiat_p224_addcarryx_u64(&x56, &x57, x55, 0x0, x44);
+ fiat_p224_addcarryx_u64(&x56, &x57, x55, x44, 0x0);
uint64_t x58;
fiat_p224_uint1 x59;
- fiat_p224_addcarryx_u64(&x58, &x59, x57, 0x0, x52);
+ fiat_p224_addcarryx_u64(&x58, &x59, x57, x52, 0x0);
uint64_t x60;
uint64_t x61;
fiat_p224_mulx_u64(&x60, &x61, x54, UINT64_C(0xffffffffffffffff));
@@ -1059,40 +1059,40 @@ static void fiat_p224_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p224_mulx_u64(&x66, &x67, x60, UINT64_C(0xffffffff00000000));
uint64_t x68;
fiat_p224_uint1 x69;
- fiat_p224_addcarryx_u64(&x68, &x69, 0x0, x64, x67);
+ fiat_p224_addcarryx_u64(&x68, &x69, 0x0, x67, x64);
uint64_t x70;
fiat_p224_uint1 x71;
- fiat_p224_addcarryx_u64(&x70, &x71, x69, x62, x65);
+ fiat_p224_addcarryx_u64(&x70, &x71, x69, x65, x62);
uint64_t x72;
fiat_p224_uint1 x73;
- fiat_p224_addcarryx_u64(&x72, &x73, 0x0, x60, x54);
+ fiat_p224_addcarryx_u64(&x72, &x73, 0x0, x54, x60);
uint64_t x74;
fiat_p224_uint1 x75;
- fiat_p224_addcarryx_u64(&x74, &x75, x73, x66, x56);
+ fiat_p224_addcarryx_u64(&x74, &x75, x73, x56, x66);
uint64_t x76;
fiat_p224_uint1 x77;
- fiat_p224_addcarryx_u64(&x76, &x77, x75, x68, x58);
+ fiat_p224_addcarryx_u64(&x76, &x77, x75, x58, x68);
uint64_t x78;
fiat_p224_uint1 x79;
- fiat_p224_addcarryx_u64(&x78, &x79, x39, 0x0, x31);
+ fiat_p224_addcarryx_u64(&x78, &x79, x39, x31, 0x0);
uint64_t x80;
fiat_p224_uint1 x81;
- fiat_p224_addcarryx_u64(&x80, &x81, x53, x78, 0x0);
+ fiat_p224_addcarryx_u64(&x80, &x81, x53, 0x0, x78);
uint64_t x82;
fiat_p224_uint1 x83;
- fiat_p224_addcarryx_u64(&x82, &x83, x59, 0x0, x80);
+ fiat_p224_addcarryx_u64(&x82, &x83, x59, x80, 0x0);
uint64_t x84;
fiat_p224_uint1 x85;
- fiat_p224_addcarryx_u64(&x84, &x85, x77, x70, x82);
+ fiat_p224_addcarryx_u64(&x84, &x85, x77, x82, x70);
uint64_t x86;
fiat_p224_uint1 x87;
- fiat_p224_addcarryx_u64(&x86, &x87, 0x0, (arg1[3]), x74);
+ fiat_p224_addcarryx_u64(&x86, &x87, 0x0, x74, (arg1[3]));
uint64_t x88;
fiat_p224_uint1 x89;
- fiat_p224_addcarryx_u64(&x88, &x89, x87, 0x0, x76);
+ fiat_p224_addcarryx_u64(&x88, &x89, x87, x76, 0x0);
uint64_t x90;
fiat_p224_uint1 x91;
- fiat_p224_addcarryx_u64(&x90, &x91, x89, 0x0, x84);
+ fiat_p224_addcarryx_u64(&x90, &x91, x89, x84, 0x0);
uint64_t x92;
uint64_t x93;
fiat_p224_mulx_u64(&x92, &x93, x86, UINT64_C(0xffffffffffffffff));
@@ -1107,37 +1107,37 @@ static void fiat_p224_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p224_mulx_u64(&x98, &x99, x92, UINT64_C(0xffffffff00000000));
uint64_t x100;
fiat_p224_uint1 x101;
- fiat_p224_addcarryx_u64(&x100, &x101, 0x0, x96, x99);
+ fiat_p224_addcarryx_u64(&x100, &x101, 0x0, x99, x96);
uint64_t x102;
fiat_p224_uint1 x103;
- fiat_p224_addcarryx_u64(&x102, &x103, x101, x94, x97);
+ fiat_p224_addcarryx_u64(&x102, &x103, x101, x97, x94);
uint64_t x104;
fiat_p224_uint1 x105;
- fiat_p224_addcarryx_u64(&x104, &x105, 0x0, x92, x86);
+ fiat_p224_addcarryx_u64(&x104, &x105, 0x0, x86, x92);
uint64_t x106;
fiat_p224_uint1 x107;
- fiat_p224_addcarryx_u64(&x106, &x107, x105, x98, x88);
+ fiat_p224_addcarryx_u64(&x106, &x107, x105, x88, x98);
uint64_t x108;
fiat_p224_uint1 x109;
- fiat_p224_addcarryx_u64(&x108, &x109, x107, x100, x90);
+ fiat_p224_addcarryx_u64(&x108, &x109, x107, x90, x100);
uint64_t x110;
fiat_p224_uint1 x111;
- fiat_p224_addcarryx_u64(&x110, &x111, x71, 0x0, x63);
+ fiat_p224_addcarryx_u64(&x110, &x111, x71, x63, 0x0);
uint64_t x112;
fiat_p224_uint1 x113;
- fiat_p224_addcarryx_u64(&x112, &x113, x85, x110, 0x0);
+ fiat_p224_addcarryx_u64(&x112, &x113, x85, 0x0, x110);
uint64_t x114;
fiat_p224_uint1 x115;
- fiat_p224_addcarryx_u64(&x114, &x115, x91, 0x0, x112);
+ fiat_p224_addcarryx_u64(&x114, &x115, x91, x112, 0x0);
uint64_t x116;
fiat_p224_uint1 x117;
- fiat_p224_addcarryx_u64(&x116, &x117, x109, x102, x114);
+ fiat_p224_addcarryx_u64(&x116, &x117, x109, x114, x102);
uint64_t x118;
fiat_p224_uint1 x119;
- fiat_p224_addcarryx_u64(&x118, &x119, x103, 0x0, x95);
+ fiat_p224_addcarryx_u64(&x118, &x119, x103, x95, 0x0);
uint64_t x120;
fiat_p224_uint1 x121;
- fiat_p224_addcarryx_u64(&x120, &x121, x117, x118, 0x0);
+ fiat_p224_addcarryx_u64(&x120, &x121, x117, 0x0, x118);
uint64_t x122;
fiat_p224_uint1 x123;
fiat_p224_subborrowx_u64(&x122, &x123, 0x0, x106, 0x1);
diff --git a/p256_32.c b/p256_32.c
index 010d78a14..2bb3097c9 100644
--- a/p256_32.c
+++ b/p256_32.c
@@ -150,28 +150,28 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x23, &x24, x8, (arg2[0]));
uint32_t x25;
fiat_p256_uint1 x26;
- fiat_p256_addcarryx_u32(&x25, &x26, 0x0, x21, x24);
+ fiat_p256_addcarryx_u32(&x25, &x26, 0x0, x24, x21);
uint32_t x27;
fiat_p256_uint1 x28;
- fiat_p256_addcarryx_u32(&x27, &x28, x26, x19, x22);
+ fiat_p256_addcarryx_u32(&x27, &x28, x26, x22, x19);
uint32_t x29;
fiat_p256_uint1 x30;
- fiat_p256_addcarryx_u32(&x29, &x30, x28, x17, x20);
+ fiat_p256_addcarryx_u32(&x29, &x30, x28, x20, x17);
uint32_t x31;
fiat_p256_uint1 x32;
- fiat_p256_addcarryx_u32(&x31, &x32, x30, x15, x18);
+ fiat_p256_addcarryx_u32(&x31, &x32, x30, x18, x15);
uint32_t x33;
fiat_p256_uint1 x34;
- fiat_p256_addcarryx_u32(&x33, &x34, x32, x13, x16);
+ fiat_p256_addcarryx_u32(&x33, &x34, x32, x16, x13);
uint32_t x35;
fiat_p256_uint1 x36;
- fiat_p256_addcarryx_u32(&x35, &x36, x34, x11, x14);
+ fiat_p256_addcarryx_u32(&x35, &x36, x34, x14, x11);
uint32_t x37;
fiat_p256_uint1 x38;
- fiat_p256_addcarryx_u32(&x37, &x38, x36, x9, x12);
+ fiat_p256_addcarryx_u32(&x37, &x38, x36, x12, x9);
uint32_t x39;
fiat_p256_uint1 x40;
- fiat_p256_addcarryx_u32(&x39, &x40, x38, 0x0, x10);
+ fiat_p256_addcarryx_u32(&x39, &x40, x38, x10, 0x0);
uint32_t x41;
uint32_t x42;
fiat_p256_mulx_u32(&x41, &x42, x23, UINT32_C(0xffffffff));
@@ -186,40 +186,40 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x47, &x48, x23, UINT32_C(0xffffffff));
uint32_t x49;
fiat_p256_uint1 x50;
- fiat_p256_addcarryx_u32(&x49, &x50, 0x0, x45, x48);
+ fiat_p256_addcarryx_u32(&x49, &x50, 0x0, x48, x45);
uint32_t x51;
fiat_p256_uint1 x52;
- fiat_p256_addcarryx_u32(&x51, &x52, x50, x43, x46);
+ fiat_p256_addcarryx_u32(&x51, &x52, x50, x46, x43);
uint32_t x53;
fiat_p256_uint1 x54;
- fiat_p256_addcarryx_u32(&x53, &x54, x52, 0x0, x44);
+ fiat_p256_addcarryx_u32(&x53, &x54, x52, x44, 0x0);
uint32_t x55;
fiat_p256_uint1 x56;
- fiat_p256_addcarryx_u32(&x55, &x56, 0x0, x47, x23);
+ fiat_p256_addcarryx_u32(&x55, &x56, 0x0, x23, x47);
uint32_t x57;
fiat_p256_uint1 x58;
- fiat_p256_addcarryx_u32(&x57, &x58, x56, x49, x25);
+ fiat_p256_addcarryx_u32(&x57, &x58, x56, x25, x49);
uint32_t x59;
fiat_p256_uint1 x60;
- fiat_p256_addcarryx_u32(&x59, &x60, x58, x51, x27);
+ fiat_p256_addcarryx_u32(&x59, &x60, x58, x27, x51);
uint32_t x61;
fiat_p256_uint1 x62;
- fiat_p256_addcarryx_u32(&x61, &x62, x60, x53, x29);
+ fiat_p256_addcarryx_u32(&x61, &x62, x60, x29, x53);
uint32_t x63;
fiat_p256_uint1 x64;
- fiat_p256_addcarryx_u32(&x63, &x64, x62, 0x0, x31);
+ fiat_p256_addcarryx_u32(&x63, &x64, x62, x31, 0x0);
uint32_t x65;
fiat_p256_uint1 x66;
- fiat_p256_addcarryx_u32(&x65, &x66, x64, 0x0, x33);
+ fiat_p256_addcarryx_u32(&x65, &x66, x64, x33, 0x0);
uint32_t x67;
fiat_p256_uint1 x68;
- fiat_p256_addcarryx_u32(&x67, &x68, x66, x23, x35);
+ fiat_p256_addcarryx_u32(&x67, &x68, x66, x35, x23);
uint32_t x69;
fiat_p256_uint1 x70;
- fiat_p256_addcarryx_u32(&x69, &x70, x68, x41, x37);
+ fiat_p256_addcarryx_u32(&x69, &x70, x68, x37, x41);
uint32_t x71;
fiat_p256_uint1 x72;
- fiat_p256_addcarryx_u32(&x71, &x72, x70, x42, x39);
+ fiat_p256_addcarryx_u32(&x71, &x72, x70, x39, x42);
uint32_t x73;
fiat_p256_uint1 x74;
fiat_p256_addcarryx_u32(&x73, &x74, x72, 0x0, 0x0);
@@ -249,55 +249,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x89, &x90, x1, (arg2[0]));
uint32_t x91;
fiat_p256_uint1 x92;
- fiat_p256_addcarryx_u32(&x91, &x92, 0x0, x87, x90);
+ fiat_p256_addcarryx_u32(&x91, &x92, 0x0, x90, x87);
uint32_t x93;
fiat_p256_uint1 x94;
- fiat_p256_addcarryx_u32(&x93, &x94, x92, x85, x88);
+ fiat_p256_addcarryx_u32(&x93, &x94, x92, x88, x85);
uint32_t x95;
fiat_p256_uint1 x96;
- fiat_p256_addcarryx_u32(&x95, &x96, x94, x83, x86);
+ fiat_p256_addcarryx_u32(&x95, &x96, x94, x86, x83);
uint32_t x97;
fiat_p256_uint1 x98;
- fiat_p256_addcarryx_u32(&x97, &x98, x96, x81, x84);
+ fiat_p256_addcarryx_u32(&x97, &x98, x96, x84, x81);
uint32_t x99;
fiat_p256_uint1 x100;
- fiat_p256_addcarryx_u32(&x99, &x100, x98, x79, x82);
+ fiat_p256_addcarryx_u32(&x99, &x100, x98, x82, x79);
uint32_t x101;
fiat_p256_uint1 x102;
- fiat_p256_addcarryx_u32(&x101, &x102, x100, x77, x80);
+ fiat_p256_addcarryx_u32(&x101, &x102, x100, x80, x77);
uint32_t x103;
fiat_p256_uint1 x104;
- fiat_p256_addcarryx_u32(&x103, &x104, x102, x75, x78);
+ fiat_p256_addcarryx_u32(&x103, &x104, x102, x78, x75);
uint32_t x105;
fiat_p256_uint1 x106;
- fiat_p256_addcarryx_u32(&x105, &x106, x104, 0x0, x76);
+ fiat_p256_addcarryx_u32(&x105, &x106, x104, x76, 0x0);
uint32_t x107;
fiat_p256_uint1 x108;
- fiat_p256_addcarryx_u32(&x107, &x108, 0x0, x89, x57);
+ fiat_p256_addcarryx_u32(&x107, &x108, 0x0, x57, x89);
uint32_t x109;
fiat_p256_uint1 x110;
- fiat_p256_addcarryx_u32(&x109, &x110, x108, x91, x59);
+ fiat_p256_addcarryx_u32(&x109, &x110, x108, x59, x91);
uint32_t x111;
fiat_p256_uint1 x112;
- fiat_p256_addcarryx_u32(&x111, &x112, x110, x93, x61);
+ fiat_p256_addcarryx_u32(&x111, &x112, x110, x61, x93);
uint32_t x113;
fiat_p256_uint1 x114;
- fiat_p256_addcarryx_u32(&x113, &x114, x112, x95, x63);
+ fiat_p256_addcarryx_u32(&x113, &x114, x112, x63, x95);
uint32_t x115;
fiat_p256_uint1 x116;
- fiat_p256_addcarryx_u32(&x115, &x116, x114, x97, x65);
+ fiat_p256_addcarryx_u32(&x115, &x116, x114, x65, x97);
uint32_t x117;
fiat_p256_uint1 x118;
- fiat_p256_addcarryx_u32(&x117, &x118, x116, x99, x67);
+ fiat_p256_addcarryx_u32(&x117, &x118, x116, x67, x99);
uint32_t x119;
fiat_p256_uint1 x120;
- fiat_p256_addcarryx_u32(&x119, &x120, x118, x101, x69);
+ fiat_p256_addcarryx_u32(&x119, &x120, x118, x69, x101);
uint32_t x121;
fiat_p256_uint1 x122;
- fiat_p256_addcarryx_u32(&x121, &x122, x120, x103, x71);
+ fiat_p256_addcarryx_u32(&x121, &x122, x120, x71, x103);
uint32_t x123;
fiat_p256_uint1 x124;
- fiat_p256_addcarryx_u32(&x123, &x124, x122, x105, (fiat_p256_uint1)x73);
+ fiat_p256_addcarryx_u32(&x123, &x124, x122, (fiat_p256_uint1)x73, x105);
uint32_t x125;
uint32_t x126;
fiat_p256_mulx_u32(&x125, &x126, x107, UINT32_C(0xffffffff));
@@ -312,43 +312,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x131, &x132, x107, UINT32_C(0xffffffff));
uint32_t x133;
fiat_p256_uint1 x134;
- fiat_p256_addcarryx_u32(&x133, &x134, 0x0, x129, x132);
+ fiat_p256_addcarryx_u32(&x133, &x134, 0x0, x132, x129);
uint32_t x135;
fiat_p256_uint1 x136;
- fiat_p256_addcarryx_u32(&x135, &x136, x134, x127, x130);
+ fiat_p256_addcarryx_u32(&x135, &x136, x134, x130, x127);
uint32_t x137;
fiat_p256_uint1 x138;
- fiat_p256_addcarryx_u32(&x137, &x138, x136, 0x0, x128);
+ fiat_p256_addcarryx_u32(&x137, &x138, x136, x128, 0x0);
uint32_t x139;
fiat_p256_uint1 x140;
- fiat_p256_addcarryx_u32(&x139, &x140, 0x0, x131, x107);
+ fiat_p256_addcarryx_u32(&x139, &x140, 0x0, x107, x131);
uint32_t x141;
fiat_p256_uint1 x142;
- fiat_p256_addcarryx_u32(&x141, &x142, x140, x133, x109);
+ fiat_p256_addcarryx_u32(&x141, &x142, x140, x109, x133);
uint32_t x143;
fiat_p256_uint1 x144;
- fiat_p256_addcarryx_u32(&x143, &x144, x142, x135, x111);
+ fiat_p256_addcarryx_u32(&x143, &x144, x142, x111, x135);
uint32_t x145;
fiat_p256_uint1 x146;
- fiat_p256_addcarryx_u32(&x145, &x146, x144, x137, x113);
+ fiat_p256_addcarryx_u32(&x145, &x146, x144, x113, x137);
uint32_t x147;
fiat_p256_uint1 x148;
- fiat_p256_addcarryx_u32(&x147, &x148, x146, 0x0, x115);
+ fiat_p256_addcarryx_u32(&x147, &x148, x146, x115, 0x0);
uint32_t x149;
fiat_p256_uint1 x150;
- fiat_p256_addcarryx_u32(&x149, &x150, x148, 0x0, x117);
+ fiat_p256_addcarryx_u32(&x149, &x150, x148, x117, 0x0);
uint32_t x151;
fiat_p256_uint1 x152;
- fiat_p256_addcarryx_u32(&x151, &x152, x150, x107, x119);
+ fiat_p256_addcarryx_u32(&x151, &x152, x150, x119, x107);
uint32_t x153;
fiat_p256_uint1 x154;
- fiat_p256_addcarryx_u32(&x153, &x154, x152, x125, x121);
+ fiat_p256_addcarryx_u32(&x153, &x154, x152, x121, x125);
uint32_t x155;
fiat_p256_uint1 x156;
- fiat_p256_addcarryx_u32(&x155, &x156, x154, x126, x123);
+ fiat_p256_addcarryx_u32(&x155, &x156, x154, x123, x126);
uint32_t x157;
fiat_p256_uint1 x158;
- fiat_p256_addcarryx_u32(&x157, &x158, x156, 0x0, x124);
+ fiat_p256_addcarryx_u32(&x157, &x158, x156, x124, 0x0);
uint32_t x159;
uint32_t x160;
fiat_p256_mulx_u32(&x159, &x160, x2, (arg2[7]));
@@ -375,55 +375,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x173, &x174, x2, (arg2[0]));
uint32_t x175;
fiat_p256_uint1 x176;
- fiat_p256_addcarryx_u32(&x175, &x176, 0x0, x171, x174);
+ fiat_p256_addcarryx_u32(&x175, &x176, 0x0, x174, x171);
uint32_t x177;
fiat_p256_uint1 x178;
- fiat_p256_addcarryx_u32(&x177, &x178, x176, x169, x172);
+ fiat_p256_addcarryx_u32(&x177, &x178, x176, x172, x169);
uint32_t x179;
fiat_p256_uint1 x180;
- fiat_p256_addcarryx_u32(&x179, &x180, x178, x167, x170);
+ fiat_p256_addcarryx_u32(&x179, &x180, x178, x170, x167);
uint32_t x181;
fiat_p256_uint1 x182;
- fiat_p256_addcarryx_u32(&x181, &x182, x180, x165, x168);
+ fiat_p256_addcarryx_u32(&x181, &x182, x180, x168, x165);
uint32_t x183;
fiat_p256_uint1 x184;
- fiat_p256_addcarryx_u32(&x183, &x184, x182, x163, x166);
+ fiat_p256_addcarryx_u32(&x183, &x184, x182, x166, x163);
uint32_t x185;
fiat_p256_uint1 x186;
- fiat_p256_addcarryx_u32(&x185, &x186, x184, x161, x164);
+ fiat_p256_addcarryx_u32(&x185, &x186, x184, x164, x161);
uint32_t x187;
fiat_p256_uint1 x188;
- fiat_p256_addcarryx_u32(&x187, &x188, x186, x159, x162);
+ fiat_p256_addcarryx_u32(&x187, &x188, x186, x162, x159);
uint32_t x189;
fiat_p256_uint1 x190;
- fiat_p256_addcarryx_u32(&x189, &x190, x188, 0x0, x160);
+ fiat_p256_addcarryx_u32(&x189, &x190, x188, x160, 0x0);
uint32_t x191;
fiat_p256_uint1 x192;
- fiat_p256_addcarryx_u32(&x191, &x192, 0x0, x173, x141);
+ fiat_p256_addcarryx_u32(&x191, &x192, 0x0, x141, x173);
uint32_t x193;
fiat_p256_uint1 x194;
- fiat_p256_addcarryx_u32(&x193, &x194, x192, x175, x143);
+ fiat_p256_addcarryx_u32(&x193, &x194, x192, x143, x175);
uint32_t x195;
fiat_p256_uint1 x196;
- fiat_p256_addcarryx_u32(&x195, &x196, x194, x177, x145);
+ fiat_p256_addcarryx_u32(&x195, &x196, x194, x145, x177);
uint32_t x197;
fiat_p256_uint1 x198;
- fiat_p256_addcarryx_u32(&x197, &x198, x196, x179, x147);
+ fiat_p256_addcarryx_u32(&x197, &x198, x196, x147, x179);
uint32_t x199;
fiat_p256_uint1 x200;
- fiat_p256_addcarryx_u32(&x199, &x200, x198, x181, x149);
+ fiat_p256_addcarryx_u32(&x199, &x200, x198, x149, x181);
uint32_t x201;
fiat_p256_uint1 x202;
- fiat_p256_addcarryx_u32(&x201, &x202, x200, x183, x151);
+ fiat_p256_addcarryx_u32(&x201, &x202, x200, x151, x183);
uint32_t x203;
fiat_p256_uint1 x204;
- fiat_p256_addcarryx_u32(&x203, &x204, x202, x185, x153);
+ fiat_p256_addcarryx_u32(&x203, &x204, x202, x153, x185);
uint32_t x205;
fiat_p256_uint1 x206;
- fiat_p256_addcarryx_u32(&x205, &x206, x204, x187, x155);
+ fiat_p256_addcarryx_u32(&x205, &x206, x204, x155, x187);
uint32_t x207;
fiat_p256_uint1 x208;
- fiat_p256_addcarryx_u32(&x207, &x208, x206, x189, x157);
+ fiat_p256_addcarryx_u32(&x207, &x208, x206, x157, x189);
uint32_t x209;
uint32_t x210;
fiat_p256_mulx_u32(&x209, &x210, x191, UINT32_C(0xffffffff));
@@ -438,43 +438,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x215, &x216, x191, UINT32_C(0xffffffff));
uint32_t x217;
fiat_p256_uint1 x218;
- fiat_p256_addcarryx_u32(&x217, &x218, 0x0, x213, x216);
+ fiat_p256_addcarryx_u32(&x217, &x218, 0x0, x216, x213);
uint32_t x219;
fiat_p256_uint1 x220;
- fiat_p256_addcarryx_u32(&x219, &x220, x218, x211, x214);
+ fiat_p256_addcarryx_u32(&x219, &x220, x218, x214, x211);
uint32_t x221;
fiat_p256_uint1 x222;
- fiat_p256_addcarryx_u32(&x221, &x222, x220, 0x0, x212);
+ fiat_p256_addcarryx_u32(&x221, &x222, x220, x212, 0x0);
uint32_t x223;
fiat_p256_uint1 x224;
- fiat_p256_addcarryx_u32(&x223, &x224, 0x0, x215, x191);
+ fiat_p256_addcarryx_u32(&x223, &x224, 0x0, x191, x215);
uint32_t x225;
fiat_p256_uint1 x226;
- fiat_p256_addcarryx_u32(&x225, &x226, x224, x217, x193);
+ fiat_p256_addcarryx_u32(&x225, &x226, x224, x193, x217);
uint32_t x227;
fiat_p256_uint1 x228;
- fiat_p256_addcarryx_u32(&x227, &x228, x226, x219, x195);
+ fiat_p256_addcarryx_u32(&x227, &x228, x226, x195, x219);
uint32_t x229;
fiat_p256_uint1 x230;
- fiat_p256_addcarryx_u32(&x229, &x230, x228, x221, x197);
+ fiat_p256_addcarryx_u32(&x229, &x230, x228, x197, x221);
uint32_t x231;
fiat_p256_uint1 x232;
- fiat_p256_addcarryx_u32(&x231, &x232, x230, 0x0, x199);
+ fiat_p256_addcarryx_u32(&x231, &x232, x230, x199, 0x0);
uint32_t x233;
fiat_p256_uint1 x234;
- fiat_p256_addcarryx_u32(&x233, &x234, x232, 0x0, x201);
+ fiat_p256_addcarryx_u32(&x233, &x234, x232, x201, 0x0);
uint32_t x235;
fiat_p256_uint1 x236;
- fiat_p256_addcarryx_u32(&x235, &x236, x234, x191, x203);
+ fiat_p256_addcarryx_u32(&x235, &x236, x234, x203, x191);
uint32_t x237;
fiat_p256_uint1 x238;
- fiat_p256_addcarryx_u32(&x237, &x238, x236, x209, x205);
+ fiat_p256_addcarryx_u32(&x237, &x238, x236, x205, x209);
uint32_t x239;
fiat_p256_uint1 x240;
- fiat_p256_addcarryx_u32(&x239, &x240, x238, x210, x207);
+ fiat_p256_addcarryx_u32(&x239, &x240, x238, x207, x210);
uint32_t x241;
fiat_p256_uint1 x242;
- fiat_p256_addcarryx_u32(&x241, &x242, x240, 0x0, x208);
+ fiat_p256_addcarryx_u32(&x241, &x242, x240, x208, 0x0);
uint32_t x243;
uint32_t x244;
fiat_p256_mulx_u32(&x243, &x244, x3, (arg2[7]));
@@ -501,55 +501,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x257, &x258, x3, (arg2[0]));
uint32_t x259;
fiat_p256_uint1 x260;
- fiat_p256_addcarryx_u32(&x259, &x260, 0x0, x255, x258);
+ fiat_p256_addcarryx_u32(&x259, &x260, 0x0, x258, x255);
uint32_t x261;
fiat_p256_uint1 x262;
- fiat_p256_addcarryx_u32(&x261, &x262, x260, x253, x256);
+ fiat_p256_addcarryx_u32(&x261, &x262, x260, x256, x253);
uint32_t x263;
fiat_p256_uint1 x264;
- fiat_p256_addcarryx_u32(&x263, &x264, x262, x251, x254);
+ fiat_p256_addcarryx_u32(&x263, &x264, x262, x254, x251);
uint32_t x265;
fiat_p256_uint1 x266;
- fiat_p256_addcarryx_u32(&x265, &x266, x264, x249, x252);
+ fiat_p256_addcarryx_u32(&x265, &x266, x264, x252, x249);
uint32_t x267;
fiat_p256_uint1 x268;
- fiat_p256_addcarryx_u32(&x267, &x268, x266, x247, x250);
+ fiat_p256_addcarryx_u32(&x267, &x268, x266, x250, x247);
uint32_t x269;
fiat_p256_uint1 x270;
- fiat_p256_addcarryx_u32(&x269, &x270, x268, x245, x248);
+ fiat_p256_addcarryx_u32(&x269, &x270, x268, x248, x245);
uint32_t x271;
fiat_p256_uint1 x272;
- fiat_p256_addcarryx_u32(&x271, &x272, x270, x243, x246);
+ fiat_p256_addcarryx_u32(&x271, &x272, x270, x246, x243);
uint32_t x273;
fiat_p256_uint1 x274;
- fiat_p256_addcarryx_u32(&x273, &x274, x272, 0x0, x244);
+ fiat_p256_addcarryx_u32(&x273, &x274, x272, x244, 0x0);
uint32_t x275;
fiat_p256_uint1 x276;
- fiat_p256_addcarryx_u32(&x275, &x276, 0x0, x257, x225);
+ fiat_p256_addcarryx_u32(&x275, &x276, 0x0, x225, x257);
uint32_t x277;
fiat_p256_uint1 x278;
- fiat_p256_addcarryx_u32(&x277, &x278, x276, x259, x227);
+ fiat_p256_addcarryx_u32(&x277, &x278, x276, x227, x259);
uint32_t x279;
fiat_p256_uint1 x280;
- fiat_p256_addcarryx_u32(&x279, &x280, x278, x261, x229);
+ fiat_p256_addcarryx_u32(&x279, &x280, x278, x229, x261);
uint32_t x281;
fiat_p256_uint1 x282;
- fiat_p256_addcarryx_u32(&x281, &x282, x280, x263, x231);
+ fiat_p256_addcarryx_u32(&x281, &x282, x280, x231, x263);
uint32_t x283;
fiat_p256_uint1 x284;
- fiat_p256_addcarryx_u32(&x283, &x284, x282, x265, x233);
+ fiat_p256_addcarryx_u32(&x283, &x284, x282, x233, x265);
uint32_t x285;
fiat_p256_uint1 x286;
- fiat_p256_addcarryx_u32(&x285, &x286, x284, x267, x235);
+ fiat_p256_addcarryx_u32(&x285, &x286, x284, x235, x267);
uint32_t x287;
fiat_p256_uint1 x288;
- fiat_p256_addcarryx_u32(&x287, &x288, x286, x269, x237);
+ fiat_p256_addcarryx_u32(&x287, &x288, x286, x237, x269);
uint32_t x289;
fiat_p256_uint1 x290;
- fiat_p256_addcarryx_u32(&x289, &x290, x288, x271, x239);
+ fiat_p256_addcarryx_u32(&x289, &x290, x288, x239, x271);
uint32_t x291;
fiat_p256_uint1 x292;
- fiat_p256_addcarryx_u32(&x291, &x292, x290, x273, x241);
+ fiat_p256_addcarryx_u32(&x291, &x292, x290, x241, x273);
uint32_t x293;
uint32_t x294;
fiat_p256_mulx_u32(&x293, &x294, x275, UINT32_C(0xffffffff));
@@ -564,43 +564,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x299, &x300, x275, UINT32_C(0xffffffff));
uint32_t x301;
fiat_p256_uint1 x302;
- fiat_p256_addcarryx_u32(&x301, &x302, 0x0, x297, x300);
+ fiat_p256_addcarryx_u32(&x301, &x302, 0x0, x300, x297);
uint32_t x303;
fiat_p256_uint1 x304;
- fiat_p256_addcarryx_u32(&x303, &x304, x302, x295, x298);
+ fiat_p256_addcarryx_u32(&x303, &x304, x302, x298, x295);
uint32_t x305;
fiat_p256_uint1 x306;
- fiat_p256_addcarryx_u32(&x305, &x306, x304, 0x0, x296);
+ fiat_p256_addcarryx_u32(&x305, &x306, x304, x296, 0x0);
uint32_t x307;
fiat_p256_uint1 x308;
- fiat_p256_addcarryx_u32(&x307, &x308, 0x0, x299, x275);
+ fiat_p256_addcarryx_u32(&x307, &x308, 0x0, x275, x299);
uint32_t x309;
fiat_p256_uint1 x310;
- fiat_p256_addcarryx_u32(&x309, &x310, x308, x301, x277);
+ fiat_p256_addcarryx_u32(&x309, &x310, x308, x277, x301);
uint32_t x311;
fiat_p256_uint1 x312;
- fiat_p256_addcarryx_u32(&x311, &x312, x310, x303, x279);
+ fiat_p256_addcarryx_u32(&x311, &x312, x310, x279, x303);
uint32_t x313;
fiat_p256_uint1 x314;
- fiat_p256_addcarryx_u32(&x313, &x314, x312, x305, x281);
+ fiat_p256_addcarryx_u32(&x313, &x314, x312, x281, x305);
uint32_t x315;
fiat_p256_uint1 x316;
- fiat_p256_addcarryx_u32(&x315, &x316, x314, 0x0, x283);
+ fiat_p256_addcarryx_u32(&x315, &x316, x314, x283, 0x0);
uint32_t x317;
fiat_p256_uint1 x318;
- fiat_p256_addcarryx_u32(&x317, &x318, x316, 0x0, x285);
+ fiat_p256_addcarryx_u32(&x317, &x318, x316, x285, 0x0);
uint32_t x319;
fiat_p256_uint1 x320;
- fiat_p256_addcarryx_u32(&x319, &x320, x318, x275, x287);
+ fiat_p256_addcarryx_u32(&x319, &x320, x318, x287, x275);
uint32_t x321;
fiat_p256_uint1 x322;
- fiat_p256_addcarryx_u32(&x321, &x322, x320, x293, x289);
+ fiat_p256_addcarryx_u32(&x321, &x322, x320, x289, x293);
uint32_t x323;
fiat_p256_uint1 x324;
- fiat_p256_addcarryx_u32(&x323, &x324, x322, x294, x291);
+ fiat_p256_addcarryx_u32(&x323, &x324, x322, x291, x294);
uint32_t x325;
fiat_p256_uint1 x326;
- fiat_p256_addcarryx_u32(&x325, &x326, x324, 0x0, x292);
+ fiat_p256_addcarryx_u32(&x325, &x326, x324, x292, 0x0);
uint32_t x327;
uint32_t x328;
fiat_p256_mulx_u32(&x327, &x328, x4, (arg2[7]));
@@ -627,55 +627,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x341, &x342, x4, (arg2[0]));
uint32_t x343;
fiat_p256_uint1 x344;
- fiat_p256_addcarryx_u32(&x343, &x344, 0x0, x339, x342);
+ fiat_p256_addcarryx_u32(&x343, &x344, 0x0, x342, x339);
uint32_t x345;
fiat_p256_uint1 x346;
- fiat_p256_addcarryx_u32(&x345, &x346, x344, x337, x340);
+ fiat_p256_addcarryx_u32(&x345, &x346, x344, x340, x337);
uint32_t x347;
fiat_p256_uint1 x348;
- fiat_p256_addcarryx_u32(&x347, &x348, x346, x335, x338);
+ fiat_p256_addcarryx_u32(&x347, &x348, x346, x338, x335);
uint32_t x349;
fiat_p256_uint1 x350;
- fiat_p256_addcarryx_u32(&x349, &x350, x348, x333, x336);
+ fiat_p256_addcarryx_u32(&x349, &x350, x348, x336, x333);
uint32_t x351;
fiat_p256_uint1 x352;
- fiat_p256_addcarryx_u32(&x351, &x352, x350, x331, x334);
+ fiat_p256_addcarryx_u32(&x351, &x352, x350, x334, x331);
uint32_t x353;
fiat_p256_uint1 x354;
- fiat_p256_addcarryx_u32(&x353, &x354, x352, x329, x332);
+ fiat_p256_addcarryx_u32(&x353, &x354, x352, x332, x329);
uint32_t x355;
fiat_p256_uint1 x356;
- fiat_p256_addcarryx_u32(&x355, &x356, x354, x327, x330);
+ fiat_p256_addcarryx_u32(&x355, &x356, x354, x330, x327);
uint32_t x357;
fiat_p256_uint1 x358;
- fiat_p256_addcarryx_u32(&x357, &x358, x356, 0x0, x328);
+ fiat_p256_addcarryx_u32(&x357, &x358, x356, x328, 0x0);
uint32_t x359;
fiat_p256_uint1 x360;
- fiat_p256_addcarryx_u32(&x359, &x360, 0x0, x341, x309);
+ fiat_p256_addcarryx_u32(&x359, &x360, 0x0, x309, x341);
uint32_t x361;
fiat_p256_uint1 x362;
- fiat_p256_addcarryx_u32(&x361, &x362, x360, x343, x311);
+ fiat_p256_addcarryx_u32(&x361, &x362, x360, x311, x343);
uint32_t x363;
fiat_p256_uint1 x364;
- fiat_p256_addcarryx_u32(&x363, &x364, x362, x345, x313);
+ fiat_p256_addcarryx_u32(&x363, &x364, x362, x313, x345);
uint32_t x365;
fiat_p256_uint1 x366;
- fiat_p256_addcarryx_u32(&x365, &x366, x364, x347, x315);
+ fiat_p256_addcarryx_u32(&x365, &x366, x364, x315, x347);
uint32_t x367;
fiat_p256_uint1 x368;
- fiat_p256_addcarryx_u32(&x367, &x368, x366, x349, x317);
+ fiat_p256_addcarryx_u32(&x367, &x368, x366, x317, x349);
uint32_t x369;
fiat_p256_uint1 x370;
- fiat_p256_addcarryx_u32(&x369, &x370, x368, x351, x319);
+ fiat_p256_addcarryx_u32(&x369, &x370, x368, x319, x351);
uint32_t x371;
fiat_p256_uint1 x372;
- fiat_p256_addcarryx_u32(&x371, &x372, x370, x353, x321);
+ fiat_p256_addcarryx_u32(&x371, &x372, x370, x321, x353);
uint32_t x373;
fiat_p256_uint1 x374;
- fiat_p256_addcarryx_u32(&x373, &x374, x372, x355, x323);
+ fiat_p256_addcarryx_u32(&x373, &x374, x372, x323, x355);
uint32_t x375;
fiat_p256_uint1 x376;
- fiat_p256_addcarryx_u32(&x375, &x376, x374, x357, x325);
+ fiat_p256_addcarryx_u32(&x375, &x376, x374, x325, x357);
uint32_t x377;
uint32_t x378;
fiat_p256_mulx_u32(&x377, &x378, x359, UINT32_C(0xffffffff));
@@ -690,43 +690,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x383, &x384, x359, UINT32_C(0xffffffff));
uint32_t x385;
fiat_p256_uint1 x386;
- fiat_p256_addcarryx_u32(&x385, &x386, 0x0, x381, x384);
+ fiat_p256_addcarryx_u32(&x385, &x386, 0x0, x384, x381);
uint32_t x387;
fiat_p256_uint1 x388;
- fiat_p256_addcarryx_u32(&x387, &x388, x386, x379, x382);
+ fiat_p256_addcarryx_u32(&x387, &x388, x386, x382, x379);
uint32_t x389;
fiat_p256_uint1 x390;
- fiat_p256_addcarryx_u32(&x389, &x390, x388, 0x0, x380);
+ fiat_p256_addcarryx_u32(&x389, &x390, x388, x380, 0x0);
uint32_t x391;
fiat_p256_uint1 x392;
- fiat_p256_addcarryx_u32(&x391, &x392, 0x0, x383, x359);
+ fiat_p256_addcarryx_u32(&x391, &x392, 0x0, x359, x383);
uint32_t x393;
fiat_p256_uint1 x394;
- fiat_p256_addcarryx_u32(&x393, &x394, x392, x385, x361);
+ fiat_p256_addcarryx_u32(&x393, &x394, x392, x361, x385);
uint32_t x395;
fiat_p256_uint1 x396;
- fiat_p256_addcarryx_u32(&x395, &x396, x394, x387, x363);
+ fiat_p256_addcarryx_u32(&x395, &x396, x394, x363, x387);
uint32_t x397;
fiat_p256_uint1 x398;
- fiat_p256_addcarryx_u32(&x397, &x398, x396, x389, x365);
+ fiat_p256_addcarryx_u32(&x397, &x398, x396, x365, x389);
uint32_t x399;
fiat_p256_uint1 x400;
- fiat_p256_addcarryx_u32(&x399, &x400, x398, 0x0, x367);
+ fiat_p256_addcarryx_u32(&x399, &x400, x398, x367, 0x0);
uint32_t x401;
fiat_p256_uint1 x402;
- fiat_p256_addcarryx_u32(&x401, &x402, x400, 0x0, x369);
+ fiat_p256_addcarryx_u32(&x401, &x402, x400, x369, 0x0);
uint32_t x403;
fiat_p256_uint1 x404;
- fiat_p256_addcarryx_u32(&x403, &x404, x402, x359, x371);
+ fiat_p256_addcarryx_u32(&x403, &x404, x402, x371, x359);
uint32_t x405;
fiat_p256_uint1 x406;
- fiat_p256_addcarryx_u32(&x405, &x406, x404, x377, x373);
+ fiat_p256_addcarryx_u32(&x405, &x406, x404, x373, x377);
uint32_t x407;
fiat_p256_uint1 x408;
- fiat_p256_addcarryx_u32(&x407, &x408, x406, x378, x375);
+ fiat_p256_addcarryx_u32(&x407, &x408, x406, x375, x378);
uint32_t x409;
fiat_p256_uint1 x410;
- fiat_p256_addcarryx_u32(&x409, &x410, x408, 0x0, x376);
+ fiat_p256_addcarryx_u32(&x409, &x410, x408, x376, 0x0);
uint32_t x411;
uint32_t x412;
fiat_p256_mulx_u32(&x411, &x412, x5, (arg2[7]));
@@ -753,55 +753,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x425, &x426, x5, (arg2[0]));
uint32_t x427;
fiat_p256_uint1 x428;
- fiat_p256_addcarryx_u32(&x427, &x428, 0x0, x423, x426);
+ fiat_p256_addcarryx_u32(&x427, &x428, 0x0, x426, x423);
uint32_t x429;
fiat_p256_uint1 x430;
- fiat_p256_addcarryx_u32(&x429, &x430, x428, x421, x424);
+ fiat_p256_addcarryx_u32(&x429, &x430, x428, x424, x421);
uint32_t x431;
fiat_p256_uint1 x432;
- fiat_p256_addcarryx_u32(&x431, &x432, x430, x419, x422);
+ fiat_p256_addcarryx_u32(&x431, &x432, x430, x422, x419);
uint32_t x433;
fiat_p256_uint1 x434;
- fiat_p256_addcarryx_u32(&x433, &x434, x432, x417, x420);
+ fiat_p256_addcarryx_u32(&x433, &x434, x432, x420, x417);
uint32_t x435;
fiat_p256_uint1 x436;
- fiat_p256_addcarryx_u32(&x435, &x436, x434, x415, x418);
+ fiat_p256_addcarryx_u32(&x435, &x436, x434, x418, x415);
uint32_t x437;
fiat_p256_uint1 x438;
- fiat_p256_addcarryx_u32(&x437, &x438, x436, x413, x416);
+ fiat_p256_addcarryx_u32(&x437, &x438, x436, x416, x413);
uint32_t x439;
fiat_p256_uint1 x440;
- fiat_p256_addcarryx_u32(&x439, &x440, x438, x411, x414);
+ fiat_p256_addcarryx_u32(&x439, &x440, x438, x414, x411);
uint32_t x441;
fiat_p256_uint1 x442;
- fiat_p256_addcarryx_u32(&x441, &x442, x440, 0x0, x412);
+ fiat_p256_addcarryx_u32(&x441, &x442, x440, x412, 0x0);
uint32_t x443;
fiat_p256_uint1 x444;
- fiat_p256_addcarryx_u32(&x443, &x444, 0x0, x425, x393);
+ fiat_p256_addcarryx_u32(&x443, &x444, 0x0, x393, x425);
uint32_t x445;
fiat_p256_uint1 x446;
- fiat_p256_addcarryx_u32(&x445, &x446, x444, x427, x395);
+ fiat_p256_addcarryx_u32(&x445, &x446, x444, x395, x427);
uint32_t x447;
fiat_p256_uint1 x448;
- fiat_p256_addcarryx_u32(&x447, &x448, x446, x429, x397);
+ fiat_p256_addcarryx_u32(&x447, &x448, x446, x397, x429);
uint32_t x449;
fiat_p256_uint1 x450;
- fiat_p256_addcarryx_u32(&x449, &x450, x448, x431, x399);
+ fiat_p256_addcarryx_u32(&x449, &x450, x448, x399, x431);
uint32_t x451;
fiat_p256_uint1 x452;
- fiat_p256_addcarryx_u32(&x451, &x452, x450, x433, x401);
+ fiat_p256_addcarryx_u32(&x451, &x452, x450, x401, x433);
uint32_t x453;
fiat_p256_uint1 x454;
- fiat_p256_addcarryx_u32(&x453, &x454, x452, x435, x403);
+ fiat_p256_addcarryx_u32(&x453, &x454, x452, x403, x435);
uint32_t x455;
fiat_p256_uint1 x456;
- fiat_p256_addcarryx_u32(&x455, &x456, x454, x437, x405);
+ fiat_p256_addcarryx_u32(&x455, &x456, x454, x405, x437);
uint32_t x457;
fiat_p256_uint1 x458;
- fiat_p256_addcarryx_u32(&x457, &x458, x456, x439, x407);
+ fiat_p256_addcarryx_u32(&x457, &x458, x456, x407, x439);
uint32_t x459;
fiat_p256_uint1 x460;
- fiat_p256_addcarryx_u32(&x459, &x460, x458, x441, x409);
+ fiat_p256_addcarryx_u32(&x459, &x460, x458, x409, x441);
uint32_t x461;
uint32_t x462;
fiat_p256_mulx_u32(&x461, &x462, x443, UINT32_C(0xffffffff));
@@ -816,43 +816,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x467, &x468, x443, UINT32_C(0xffffffff));
uint32_t x469;
fiat_p256_uint1 x470;
- fiat_p256_addcarryx_u32(&x469, &x470, 0x0, x465, x468);
+ fiat_p256_addcarryx_u32(&x469, &x470, 0x0, x468, x465);
uint32_t x471;
fiat_p256_uint1 x472;
- fiat_p256_addcarryx_u32(&x471, &x472, x470, x463, x466);
+ fiat_p256_addcarryx_u32(&x471, &x472, x470, x466, x463);
uint32_t x473;
fiat_p256_uint1 x474;
- fiat_p256_addcarryx_u32(&x473, &x474, x472, 0x0, x464);
+ fiat_p256_addcarryx_u32(&x473, &x474, x472, x464, 0x0);
uint32_t x475;
fiat_p256_uint1 x476;
- fiat_p256_addcarryx_u32(&x475, &x476, 0x0, x467, x443);
+ fiat_p256_addcarryx_u32(&x475, &x476, 0x0, x443, x467);
uint32_t x477;
fiat_p256_uint1 x478;
- fiat_p256_addcarryx_u32(&x477, &x478, x476, x469, x445);
+ fiat_p256_addcarryx_u32(&x477, &x478, x476, x445, x469);
uint32_t x479;
fiat_p256_uint1 x480;
- fiat_p256_addcarryx_u32(&x479, &x480, x478, x471, x447);
+ fiat_p256_addcarryx_u32(&x479, &x480, x478, x447, x471);
uint32_t x481;
fiat_p256_uint1 x482;
- fiat_p256_addcarryx_u32(&x481, &x482, x480, x473, x449);
+ fiat_p256_addcarryx_u32(&x481, &x482, x480, x449, x473);
uint32_t x483;
fiat_p256_uint1 x484;
- fiat_p256_addcarryx_u32(&x483, &x484, x482, 0x0, x451);
+ fiat_p256_addcarryx_u32(&x483, &x484, x482, x451, 0x0);
uint32_t x485;
fiat_p256_uint1 x486;
- fiat_p256_addcarryx_u32(&x485, &x486, x484, 0x0, x453);
+ fiat_p256_addcarryx_u32(&x485, &x486, x484, x453, 0x0);
uint32_t x487;
fiat_p256_uint1 x488;
- fiat_p256_addcarryx_u32(&x487, &x488, x486, x443, x455);
+ fiat_p256_addcarryx_u32(&x487, &x488, x486, x455, x443);
uint32_t x489;
fiat_p256_uint1 x490;
- fiat_p256_addcarryx_u32(&x489, &x490, x488, x461, x457);
+ fiat_p256_addcarryx_u32(&x489, &x490, x488, x457, x461);
uint32_t x491;
fiat_p256_uint1 x492;
- fiat_p256_addcarryx_u32(&x491, &x492, x490, x462, x459);
+ fiat_p256_addcarryx_u32(&x491, &x492, x490, x459, x462);
uint32_t x493;
fiat_p256_uint1 x494;
- fiat_p256_addcarryx_u32(&x493, &x494, x492, 0x0, x460);
+ fiat_p256_addcarryx_u32(&x493, &x494, x492, x460, 0x0);
uint32_t x495;
uint32_t x496;
fiat_p256_mulx_u32(&x495, &x496, x6, (arg2[7]));
@@ -879,55 +879,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x509, &x510, x6, (arg2[0]));
uint32_t x511;
fiat_p256_uint1 x512;
- fiat_p256_addcarryx_u32(&x511, &x512, 0x0, x507, x510);
+ fiat_p256_addcarryx_u32(&x511, &x512, 0x0, x510, x507);
uint32_t x513;
fiat_p256_uint1 x514;
- fiat_p256_addcarryx_u32(&x513, &x514, x512, x505, x508);
+ fiat_p256_addcarryx_u32(&x513, &x514, x512, x508, x505);
uint32_t x515;
fiat_p256_uint1 x516;
- fiat_p256_addcarryx_u32(&x515, &x516, x514, x503, x506);
+ fiat_p256_addcarryx_u32(&x515, &x516, x514, x506, x503);
uint32_t x517;
fiat_p256_uint1 x518;
- fiat_p256_addcarryx_u32(&x517, &x518, x516, x501, x504);
+ fiat_p256_addcarryx_u32(&x517, &x518, x516, x504, x501);
uint32_t x519;
fiat_p256_uint1 x520;
- fiat_p256_addcarryx_u32(&x519, &x520, x518, x499, x502);
+ fiat_p256_addcarryx_u32(&x519, &x520, x518, x502, x499);
uint32_t x521;
fiat_p256_uint1 x522;
- fiat_p256_addcarryx_u32(&x521, &x522, x520, x497, x500);
+ fiat_p256_addcarryx_u32(&x521, &x522, x520, x500, x497);
uint32_t x523;
fiat_p256_uint1 x524;
- fiat_p256_addcarryx_u32(&x523, &x524, x522, x495, x498);
+ fiat_p256_addcarryx_u32(&x523, &x524, x522, x498, x495);
uint32_t x525;
fiat_p256_uint1 x526;
- fiat_p256_addcarryx_u32(&x525, &x526, x524, 0x0, x496);
+ fiat_p256_addcarryx_u32(&x525, &x526, x524, x496, 0x0);
uint32_t x527;
fiat_p256_uint1 x528;
- fiat_p256_addcarryx_u32(&x527, &x528, 0x0, x509, x477);
+ fiat_p256_addcarryx_u32(&x527, &x528, 0x0, x477, x509);
uint32_t x529;
fiat_p256_uint1 x530;
- fiat_p256_addcarryx_u32(&x529, &x530, x528, x511, x479);
+ fiat_p256_addcarryx_u32(&x529, &x530, x528, x479, x511);
uint32_t x531;
fiat_p256_uint1 x532;
- fiat_p256_addcarryx_u32(&x531, &x532, x530, x513, x481);
+ fiat_p256_addcarryx_u32(&x531, &x532, x530, x481, x513);
uint32_t x533;
fiat_p256_uint1 x534;
- fiat_p256_addcarryx_u32(&x533, &x534, x532, x515, x483);
+ fiat_p256_addcarryx_u32(&x533, &x534, x532, x483, x515);
uint32_t x535;
fiat_p256_uint1 x536;
- fiat_p256_addcarryx_u32(&x535, &x536, x534, x517, x485);
+ fiat_p256_addcarryx_u32(&x535, &x536, x534, x485, x517);
uint32_t x537;
fiat_p256_uint1 x538;
- fiat_p256_addcarryx_u32(&x537, &x538, x536, x519, x487);
+ fiat_p256_addcarryx_u32(&x537, &x538, x536, x487, x519);
uint32_t x539;
fiat_p256_uint1 x540;
- fiat_p256_addcarryx_u32(&x539, &x540, x538, x521, x489);
+ fiat_p256_addcarryx_u32(&x539, &x540, x538, x489, x521);
uint32_t x541;
fiat_p256_uint1 x542;
- fiat_p256_addcarryx_u32(&x541, &x542, x540, x523, x491);
+ fiat_p256_addcarryx_u32(&x541, &x542, x540, x491, x523);
uint32_t x543;
fiat_p256_uint1 x544;
- fiat_p256_addcarryx_u32(&x543, &x544, x542, x525, x493);
+ fiat_p256_addcarryx_u32(&x543, &x544, x542, x493, x525);
uint32_t x545;
uint32_t x546;
fiat_p256_mulx_u32(&x545, &x546, x527, UINT32_C(0xffffffff));
@@ -942,43 +942,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x551, &x552, x527, UINT32_C(0xffffffff));
uint32_t x553;
fiat_p256_uint1 x554;
- fiat_p256_addcarryx_u32(&x553, &x554, 0x0, x549, x552);
+ fiat_p256_addcarryx_u32(&x553, &x554, 0x0, x552, x549);
uint32_t x555;
fiat_p256_uint1 x556;
- fiat_p256_addcarryx_u32(&x555, &x556, x554, x547, x550);
+ fiat_p256_addcarryx_u32(&x555, &x556, x554, x550, x547);
uint32_t x557;
fiat_p256_uint1 x558;
- fiat_p256_addcarryx_u32(&x557, &x558, x556, 0x0, x548);
+ fiat_p256_addcarryx_u32(&x557, &x558, x556, x548, 0x0);
uint32_t x559;
fiat_p256_uint1 x560;
- fiat_p256_addcarryx_u32(&x559, &x560, 0x0, x551, x527);
+ fiat_p256_addcarryx_u32(&x559, &x560, 0x0, x527, x551);
uint32_t x561;
fiat_p256_uint1 x562;
- fiat_p256_addcarryx_u32(&x561, &x562, x560, x553, x529);
+ fiat_p256_addcarryx_u32(&x561, &x562, x560, x529, x553);
uint32_t x563;
fiat_p256_uint1 x564;
- fiat_p256_addcarryx_u32(&x563, &x564, x562, x555, x531);
+ fiat_p256_addcarryx_u32(&x563, &x564, x562, x531, x555);
uint32_t x565;
fiat_p256_uint1 x566;
- fiat_p256_addcarryx_u32(&x565, &x566, x564, x557, x533);
+ fiat_p256_addcarryx_u32(&x565, &x566, x564, x533, x557);
uint32_t x567;
fiat_p256_uint1 x568;
- fiat_p256_addcarryx_u32(&x567, &x568, x566, 0x0, x535);
+ fiat_p256_addcarryx_u32(&x567, &x568, x566, x535, 0x0);
uint32_t x569;
fiat_p256_uint1 x570;
- fiat_p256_addcarryx_u32(&x569, &x570, x568, 0x0, x537);
+ fiat_p256_addcarryx_u32(&x569, &x570, x568, x537, 0x0);
uint32_t x571;
fiat_p256_uint1 x572;
- fiat_p256_addcarryx_u32(&x571, &x572, x570, x527, x539);
+ fiat_p256_addcarryx_u32(&x571, &x572, x570, x539, x527);
uint32_t x573;
fiat_p256_uint1 x574;
- fiat_p256_addcarryx_u32(&x573, &x574, x572, x545, x541);
+ fiat_p256_addcarryx_u32(&x573, &x574, x572, x541, x545);
uint32_t x575;
fiat_p256_uint1 x576;
- fiat_p256_addcarryx_u32(&x575, &x576, x574, x546, x543);
+ fiat_p256_addcarryx_u32(&x575, &x576, x574, x543, x546);
uint32_t x577;
fiat_p256_uint1 x578;
- fiat_p256_addcarryx_u32(&x577, &x578, x576, 0x0, x544);
+ fiat_p256_addcarryx_u32(&x577, &x578, x576, x544, 0x0);
uint32_t x579;
uint32_t x580;
fiat_p256_mulx_u32(&x579, &x580, x7, (arg2[7]));
@@ -1005,55 +1005,55 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x593, &x594, x7, (arg2[0]));
uint32_t x595;
fiat_p256_uint1 x596;
- fiat_p256_addcarryx_u32(&x595, &x596, 0x0, x591, x594);
+ fiat_p256_addcarryx_u32(&x595, &x596, 0x0, x594, x591);
uint32_t x597;
fiat_p256_uint1 x598;
- fiat_p256_addcarryx_u32(&x597, &x598, x596, x589, x592);
+ fiat_p256_addcarryx_u32(&x597, &x598, x596, x592, x589);
uint32_t x599;
fiat_p256_uint1 x600;
- fiat_p256_addcarryx_u32(&x599, &x600, x598, x587, x590);
+ fiat_p256_addcarryx_u32(&x599, &x600, x598, x590, x587);
uint32_t x601;
fiat_p256_uint1 x602;
- fiat_p256_addcarryx_u32(&x601, &x602, x600, x585, x588);
+ fiat_p256_addcarryx_u32(&x601, &x602, x600, x588, x585);
uint32_t x603;
fiat_p256_uint1 x604;
- fiat_p256_addcarryx_u32(&x603, &x604, x602, x583, x586);
+ fiat_p256_addcarryx_u32(&x603, &x604, x602, x586, x583);
uint32_t x605;
fiat_p256_uint1 x606;
- fiat_p256_addcarryx_u32(&x605, &x606, x604, x581, x584);
+ fiat_p256_addcarryx_u32(&x605, &x606, x604, x584, x581);
uint32_t x607;
fiat_p256_uint1 x608;
- fiat_p256_addcarryx_u32(&x607, &x608, x606, x579, x582);
+ fiat_p256_addcarryx_u32(&x607, &x608, x606, x582, x579);
uint32_t x609;
fiat_p256_uint1 x610;
- fiat_p256_addcarryx_u32(&x609, &x610, x608, 0x0, x580);
+ fiat_p256_addcarryx_u32(&x609, &x610, x608, x580, 0x0);
uint32_t x611;
fiat_p256_uint1 x612;
- fiat_p256_addcarryx_u32(&x611, &x612, 0x0, x593, x561);
+ fiat_p256_addcarryx_u32(&x611, &x612, 0x0, x561, x593);
uint32_t x613;
fiat_p256_uint1 x614;
- fiat_p256_addcarryx_u32(&x613, &x614, x612, x595, x563);
+ fiat_p256_addcarryx_u32(&x613, &x614, x612, x563, x595);
uint32_t x615;
fiat_p256_uint1 x616;
- fiat_p256_addcarryx_u32(&x615, &x616, x614, x597, x565);
+ fiat_p256_addcarryx_u32(&x615, &x616, x614, x565, x597);
uint32_t x617;
fiat_p256_uint1 x618;
- fiat_p256_addcarryx_u32(&x617, &x618, x616, x599, x567);
+ fiat_p256_addcarryx_u32(&x617, &x618, x616, x567, x599);
uint32_t x619;
fiat_p256_uint1 x620;
- fiat_p256_addcarryx_u32(&x619, &x620, x618, x601, x569);
+ fiat_p256_addcarryx_u32(&x619, &x620, x618, x569, x601);
uint32_t x621;
fiat_p256_uint1 x622;
- fiat_p256_addcarryx_u32(&x621, &x622, x620, x603, x571);
+ fiat_p256_addcarryx_u32(&x621, &x622, x620, x571, x603);
uint32_t x623;
fiat_p256_uint1 x624;
- fiat_p256_addcarryx_u32(&x623, &x624, x622, x605, x573);
+ fiat_p256_addcarryx_u32(&x623, &x624, x622, x573, x605);
uint32_t x625;
fiat_p256_uint1 x626;
- fiat_p256_addcarryx_u32(&x625, &x626, x624, x607, x575);
+ fiat_p256_addcarryx_u32(&x625, &x626, x624, x575, x607);
uint32_t x627;
fiat_p256_uint1 x628;
- fiat_p256_addcarryx_u32(&x627, &x628, x626, x609, x577);
+ fiat_p256_addcarryx_u32(&x627, &x628, x626, x577, x609);
uint32_t x629;
uint32_t x630;
fiat_p256_mulx_u32(&x629, &x630, x611, UINT32_C(0xffffffff));
@@ -1068,43 +1068,43 @@ static void fiat_p256_mul(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_mulx_u32(&x635, &x636, x611, UINT32_C(0xffffffff));
uint32_t x637;
fiat_p256_uint1 x638;
- fiat_p256_addcarryx_u32(&x637, &x638, 0x0, x633, x636);
+ fiat_p256_addcarryx_u32(&x637, &x638, 0x0, x636, x633);
uint32_t x639;
fiat_p256_uint1 x640;
- fiat_p256_addcarryx_u32(&x639, &x640, x638, x631, x634);
+ fiat_p256_addcarryx_u32(&x639, &x640, x638, x634, x631);
uint32_t x641;
fiat_p256_uint1 x642;
- fiat_p256_addcarryx_u32(&x641, &x642, x640, 0x0, x632);
+ fiat_p256_addcarryx_u32(&x641, &x642, x640, x632, 0x0);
uint32_t x643;
fiat_p256_uint1 x644;
- fiat_p256_addcarryx_u32(&x643, &x644, 0x0, x635, x611);
+ fiat_p256_addcarryx_u32(&x643, &x644, 0x0, x611, x635);
uint32_t x645;
fiat_p256_uint1 x646;
- fiat_p256_addcarryx_u32(&x645, &x646, x644, x637, x613);
+ fiat_p256_addcarryx_u32(&x645, &x646, x644, x613, x637);
uint32_t x647;
fiat_p256_uint1 x648;
- fiat_p256_addcarryx_u32(&x647, &x648, x646, x639, x615);
+ fiat_p256_addcarryx_u32(&x647, &x648, x646, x615, x639);
uint32_t x649;
fiat_p256_uint1 x650;
- fiat_p256_addcarryx_u32(&x649, &x650, x648, x641, x617);
+ fiat_p256_addcarryx_u32(&x649, &x650, x648, x617, x641);
uint32_t x651;
fiat_p256_uint1 x652;
- fiat_p256_addcarryx_u32(&x651, &x652, x650, 0x0, x619);
+ fiat_p256_addcarryx_u32(&x651, &x652, x650, x619, 0x0);
uint32_t x653;
fiat_p256_uint1 x654;
- fiat_p256_addcarryx_u32(&x653, &x654, x652, 0x0, x621);
+ fiat_p256_addcarryx_u32(&x653, &x654, x652, x621, 0x0);
uint32_t x655;
fiat_p256_uint1 x656;
- fiat_p256_addcarryx_u32(&x655, &x656, x654, x611, x623);
+ fiat_p256_addcarryx_u32(&x655, &x656, x654, x623, x611);
uint32_t x657;
fiat_p256_uint1 x658;
- fiat_p256_addcarryx_u32(&x657, &x658, x656, x629, x625);
+ fiat_p256_addcarryx_u32(&x657, &x658, x656, x625, x629);
uint32_t x659;
fiat_p256_uint1 x660;
- fiat_p256_addcarryx_u32(&x659, &x660, x658, x630, x627);
+ fiat_p256_addcarryx_u32(&x659, &x660, x658, x627, x630);
uint32_t x661;
fiat_p256_uint1 x662;
- fiat_p256_addcarryx_u32(&x661, &x662, x660, 0x0, x628);
+ fiat_p256_addcarryx_u32(&x661, &x662, x660, x628, 0x0);
uint32_t x663;
fiat_p256_uint1 x664;
fiat_p256_subborrowx_u32(&x663, &x664, 0x0, x645, UINT32_C(0xffffffff));
@@ -1206,28 +1206,28 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x23, &x24, x8, (arg1[0]));
uint32_t x25;
fiat_p256_uint1 x26;
- fiat_p256_addcarryx_u32(&x25, &x26, 0x0, x21, x24);
+ fiat_p256_addcarryx_u32(&x25, &x26, 0x0, x24, x21);
uint32_t x27;
fiat_p256_uint1 x28;
- fiat_p256_addcarryx_u32(&x27, &x28, x26, x19, x22);
+ fiat_p256_addcarryx_u32(&x27, &x28, x26, x22, x19);
uint32_t x29;
fiat_p256_uint1 x30;
- fiat_p256_addcarryx_u32(&x29, &x30, x28, x17, x20);
+ fiat_p256_addcarryx_u32(&x29, &x30, x28, x20, x17);
uint32_t x31;
fiat_p256_uint1 x32;
- fiat_p256_addcarryx_u32(&x31, &x32, x30, x15, x18);
+ fiat_p256_addcarryx_u32(&x31, &x32, x30, x18, x15);
uint32_t x33;
fiat_p256_uint1 x34;
- fiat_p256_addcarryx_u32(&x33, &x34, x32, x13, x16);
+ fiat_p256_addcarryx_u32(&x33, &x34, x32, x16, x13);
uint32_t x35;
fiat_p256_uint1 x36;
- fiat_p256_addcarryx_u32(&x35, &x36, x34, x11, x14);
+ fiat_p256_addcarryx_u32(&x35, &x36, x34, x14, x11);
uint32_t x37;
fiat_p256_uint1 x38;
- fiat_p256_addcarryx_u32(&x37, &x38, x36, x9, x12);
+ fiat_p256_addcarryx_u32(&x37, &x38, x36, x12, x9);
uint32_t x39;
fiat_p256_uint1 x40;
- fiat_p256_addcarryx_u32(&x39, &x40, x38, 0x0, x10);
+ fiat_p256_addcarryx_u32(&x39, &x40, x38, x10, 0x0);
uint32_t x41;
uint32_t x42;
fiat_p256_mulx_u32(&x41, &x42, x23, UINT32_C(0xffffffff));
@@ -1242,40 +1242,40 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x47, &x48, x23, UINT32_C(0xffffffff));
uint32_t x49;
fiat_p256_uint1 x50;
- fiat_p256_addcarryx_u32(&x49, &x50, 0x0, x45, x48);
+ fiat_p256_addcarryx_u32(&x49, &x50, 0x0, x48, x45);
uint32_t x51;
fiat_p256_uint1 x52;
- fiat_p256_addcarryx_u32(&x51, &x52, x50, x43, x46);
+ fiat_p256_addcarryx_u32(&x51, &x52, x50, x46, x43);
uint32_t x53;
fiat_p256_uint1 x54;
- fiat_p256_addcarryx_u32(&x53, &x54, x52, 0x0, x44);
+ fiat_p256_addcarryx_u32(&x53, &x54, x52, x44, 0x0);
uint32_t x55;
fiat_p256_uint1 x56;
- fiat_p256_addcarryx_u32(&x55, &x56, 0x0, x47, x23);
+ fiat_p256_addcarryx_u32(&x55, &x56, 0x0, x23, x47);
uint32_t x57;
fiat_p256_uint1 x58;
- fiat_p256_addcarryx_u32(&x57, &x58, x56, x49, x25);
+ fiat_p256_addcarryx_u32(&x57, &x58, x56, x25, x49);
uint32_t x59;
fiat_p256_uint1 x60;
- fiat_p256_addcarryx_u32(&x59, &x60, x58, x51, x27);
+ fiat_p256_addcarryx_u32(&x59, &x60, x58, x27, x51);
uint32_t x61;
fiat_p256_uint1 x62;
- fiat_p256_addcarryx_u32(&x61, &x62, x60, x53, x29);
+ fiat_p256_addcarryx_u32(&x61, &x62, x60, x29, x53);
uint32_t x63;
fiat_p256_uint1 x64;
- fiat_p256_addcarryx_u32(&x63, &x64, x62, 0x0, x31);
+ fiat_p256_addcarryx_u32(&x63, &x64, x62, x31, 0x0);
uint32_t x65;
fiat_p256_uint1 x66;
- fiat_p256_addcarryx_u32(&x65, &x66, x64, 0x0, x33);
+ fiat_p256_addcarryx_u32(&x65, &x66, x64, x33, 0x0);
uint32_t x67;
fiat_p256_uint1 x68;
- fiat_p256_addcarryx_u32(&x67, &x68, x66, x23, x35);
+ fiat_p256_addcarryx_u32(&x67, &x68, x66, x35, x23);
uint32_t x69;
fiat_p256_uint1 x70;
- fiat_p256_addcarryx_u32(&x69, &x70, x68, x41, x37);
+ fiat_p256_addcarryx_u32(&x69, &x70, x68, x37, x41);
uint32_t x71;
fiat_p256_uint1 x72;
- fiat_p256_addcarryx_u32(&x71, &x72, x70, x42, x39);
+ fiat_p256_addcarryx_u32(&x71, &x72, x70, x39, x42);
uint32_t x73;
fiat_p256_uint1 x74;
fiat_p256_addcarryx_u32(&x73, &x74, x72, 0x0, 0x0);
@@ -1305,55 +1305,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x89, &x90, x1, (arg1[0]));
uint32_t x91;
fiat_p256_uint1 x92;
- fiat_p256_addcarryx_u32(&x91, &x92, 0x0, x87, x90);
+ fiat_p256_addcarryx_u32(&x91, &x92, 0x0, x90, x87);
uint32_t x93;
fiat_p256_uint1 x94;
- fiat_p256_addcarryx_u32(&x93, &x94, x92, x85, x88);
+ fiat_p256_addcarryx_u32(&x93, &x94, x92, x88, x85);
uint32_t x95;
fiat_p256_uint1 x96;
- fiat_p256_addcarryx_u32(&x95, &x96, x94, x83, x86);
+ fiat_p256_addcarryx_u32(&x95, &x96, x94, x86, x83);
uint32_t x97;
fiat_p256_uint1 x98;
- fiat_p256_addcarryx_u32(&x97, &x98, x96, x81, x84);
+ fiat_p256_addcarryx_u32(&x97, &x98, x96, x84, x81);
uint32_t x99;
fiat_p256_uint1 x100;
- fiat_p256_addcarryx_u32(&x99, &x100, x98, x79, x82);
+ fiat_p256_addcarryx_u32(&x99, &x100, x98, x82, x79);
uint32_t x101;
fiat_p256_uint1 x102;
- fiat_p256_addcarryx_u32(&x101, &x102, x100, x77, x80);
+ fiat_p256_addcarryx_u32(&x101, &x102, x100, x80, x77);
uint32_t x103;
fiat_p256_uint1 x104;
- fiat_p256_addcarryx_u32(&x103, &x104, x102, x75, x78);
+ fiat_p256_addcarryx_u32(&x103, &x104, x102, x78, x75);
uint32_t x105;
fiat_p256_uint1 x106;
- fiat_p256_addcarryx_u32(&x105, &x106, x104, 0x0, x76);
+ fiat_p256_addcarryx_u32(&x105, &x106, x104, x76, 0x0);
uint32_t x107;
fiat_p256_uint1 x108;
- fiat_p256_addcarryx_u32(&x107, &x108, 0x0, x89, x57);
+ fiat_p256_addcarryx_u32(&x107, &x108, 0x0, x57, x89);
uint32_t x109;
fiat_p256_uint1 x110;
- fiat_p256_addcarryx_u32(&x109, &x110, x108, x91, x59);
+ fiat_p256_addcarryx_u32(&x109, &x110, x108, x59, x91);
uint32_t x111;
fiat_p256_uint1 x112;
- fiat_p256_addcarryx_u32(&x111, &x112, x110, x93, x61);
+ fiat_p256_addcarryx_u32(&x111, &x112, x110, x61, x93);
uint32_t x113;
fiat_p256_uint1 x114;
- fiat_p256_addcarryx_u32(&x113, &x114, x112, x95, x63);
+ fiat_p256_addcarryx_u32(&x113, &x114, x112, x63, x95);
uint32_t x115;
fiat_p256_uint1 x116;
- fiat_p256_addcarryx_u32(&x115, &x116, x114, x97, x65);
+ fiat_p256_addcarryx_u32(&x115, &x116, x114, x65, x97);
uint32_t x117;
fiat_p256_uint1 x118;
- fiat_p256_addcarryx_u32(&x117, &x118, x116, x99, x67);
+ fiat_p256_addcarryx_u32(&x117, &x118, x116, x67, x99);
uint32_t x119;
fiat_p256_uint1 x120;
- fiat_p256_addcarryx_u32(&x119, &x120, x118, x101, x69);
+ fiat_p256_addcarryx_u32(&x119, &x120, x118, x69, x101);
uint32_t x121;
fiat_p256_uint1 x122;
- fiat_p256_addcarryx_u32(&x121, &x122, x120, x103, x71);
+ fiat_p256_addcarryx_u32(&x121, &x122, x120, x71, x103);
uint32_t x123;
fiat_p256_uint1 x124;
- fiat_p256_addcarryx_u32(&x123, &x124, x122, x105, (fiat_p256_uint1)x73);
+ fiat_p256_addcarryx_u32(&x123, &x124, x122, (fiat_p256_uint1)x73, x105);
uint32_t x125;
uint32_t x126;
fiat_p256_mulx_u32(&x125, &x126, x107, UINT32_C(0xffffffff));
@@ -1368,43 +1368,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x131, &x132, x107, UINT32_C(0xffffffff));
uint32_t x133;
fiat_p256_uint1 x134;
- fiat_p256_addcarryx_u32(&x133, &x134, 0x0, x129, x132);
+ fiat_p256_addcarryx_u32(&x133, &x134, 0x0, x132, x129);
uint32_t x135;
fiat_p256_uint1 x136;
- fiat_p256_addcarryx_u32(&x135, &x136, x134, x127, x130);
+ fiat_p256_addcarryx_u32(&x135, &x136, x134, x130, x127);
uint32_t x137;
fiat_p256_uint1 x138;
- fiat_p256_addcarryx_u32(&x137, &x138, x136, 0x0, x128);
+ fiat_p256_addcarryx_u32(&x137, &x138, x136, x128, 0x0);
uint32_t x139;
fiat_p256_uint1 x140;
- fiat_p256_addcarryx_u32(&x139, &x140, 0x0, x131, x107);
+ fiat_p256_addcarryx_u32(&x139, &x140, 0x0, x107, x131);
uint32_t x141;
fiat_p256_uint1 x142;
- fiat_p256_addcarryx_u32(&x141, &x142, x140, x133, x109);
+ fiat_p256_addcarryx_u32(&x141, &x142, x140, x109, x133);
uint32_t x143;
fiat_p256_uint1 x144;
- fiat_p256_addcarryx_u32(&x143, &x144, x142, x135, x111);
+ fiat_p256_addcarryx_u32(&x143, &x144, x142, x111, x135);
uint32_t x145;
fiat_p256_uint1 x146;
- fiat_p256_addcarryx_u32(&x145, &x146, x144, x137, x113);
+ fiat_p256_addcarryx_u32(&x145, &x146, x144, x113, x137);
uint32_t x147;
fiat_p256_uint1 x148;
- fiat_p256_addcarryx_u32(&x147, &x148, x146, 0x0, x115);
+ fiat_p256_addcarryx_u32(&x147, &x148, x146, x115, 0x0);
uint32_t x149;
fiat_p256_uint1 x150;
- fiat_p256_addcarryx_u32(&x149, &x150, x148, 0x0, x117);
+ fiat_p256_addcarryx_u32(&x149, &x150, x148, x117, 0x0);
uint32_t x151;
fiat_p256_uint1 x152;
- fiat_p256_addcarryx_u32(&x151, &x152, x150, x107, x119);
+ fiat_p256_addcarryx_u32(&x151, &x152, x150, x119, x107);
uint32_t x153;
fiat_p256_uint1 x154;
- fiat_p256_addcarryx_u32(&x153, &x154, x152, x125, x121);
+ fiat_p256_addcarryx_u32(&x153, &x154, x152, x121, x125);
uint32_t x155;
fiat_p256_uint1 x156;
- fiat_p256_addcarryx_u32(&x155, &x156, x154, x126, x123);
+ fiat_p256_addcarryx_u32(&x155, &x156, x154, x123, x126);
uint32_t x157;
fiat_p256_uint1 x158;
- fiat_p256_addcarryx_u32(&x157, &x158, x156, 0x0, x124);
+ fiat_p256_addcarryx_u32(&x157, &x158, x156, x124, 0x0);
uint32_t x159;
uint32_t x160;
fiat_p256_mulx_u32(&x159, &x160, x2, (arg1[7]));
@@ -1431,55 +1431,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x173, &x174, x2, (arg1[0]));
uint32_t x175;
fiat_p256_uint1 x176;
- fiat_p256_addcarryx_u32(&x175, &x176, 0x0, x171, x174);
+ fiat_p256_addcarryx_u32(&x175, &x176, 0x0, x174, x171);
uint32_t x177;
fiat_p256_uint1 x178;
- fiat_p256_addcarryx_u32(&x177, &x178, x176, x169, x172);
+ fiat_p256_addcarryx_u32(&x177, &x178, x176, x172, x169);
uint32_t x179;
fiat_p256_uint1 x180;
- fiat_p256_addcarryx_u32(&x179, &x180, x178, x167, x170);
+ fiat_p256_addcarryx_u32(&x179, &x180, x178, x170, x167);
uint32_t x181;
fiat_p256_uint1 x182;
- fiat_p256_addcarryx_u32(&x181, &x182, x180, x165, x168);
+ fiat_p256_addcarryx_u32(&x181, &x182, x180, x168, x165);
uint32_t x183;
fiat_p256_uint1 x184;
- fiat_p256_addcarryx_u32(&x183, &x184, x182, x163, x166);
+ fiat_p256_addcarryx_u32(&x183, &x184, x182, x166, x163);
uint32_t x185;
fiat_p256_uint1 x186;
- fiat_p256_addcarryx_u32(&x185, &x186, x184, x161, x164);
+ fiat_p256_addcarryx_u32(&x185, &x186, x184, x164, x161);
uint32_t x187;
fiat_p256_uint1 x188;
- fiat_p256_addcarryx_u32(&x187, &x188, x186, x159, x162);
+ fiat_p256_addcarryx_u32(&x187, &x188, x186, x162, x159);
uint32_t x189;
fiat_p256_uint1 x190;
- fiat_p256_addcarryx_u32(&x189, &x190, x188, 0x0, x160);
+ fiat_p256_addcarryx_u32(&x189, &x190, x188, x160, 0x0);
uint32_t x191;
fiat_p256_uint1 x192;
- fiat_p256_addcarryx_u32(&x191, &x192, 0x0, x173, x141);
+ fiat_p256_addcarryx_u32(&x191, &x192, 0x0, x141, x173);
uint32_t x193;
fiat_p256_uint1 x194;
- fiat_p256_addcarryx_u32(&x193, &x194, x192, x175, x143);
+ fiat_p256_addcarryx_u32(&x193, &x194, x192, x143, x175);
uint32_t x195;
fiat_p256_uint1 x196;
- fiat_p256_addcarryx_u32(&x195, &x196, x194, x177, x145);
+ fiat_p256_addcarryx_u32(&x195, &x196, x194, x145, x177);
uint32_t x197;
fiat_p256_uint1 x198;
- fiat_p256_addcarryx_u32(&x197, &x198, x196, x179, x147);
+ fiat_p256_addcarryx_u32(&x197, &x198, x196, x147, x179);
uint32_t x199;
fiat_p256_uint1 x200;
- fiat_p256_addcarryx_u32(&x199, &x200, x198, x181, x149);
+ fiat_p256_addcarryx_u32(&x199, &x200, x198, x149, x181);
uint32_t x201;
fiat_p256_uint1 x202;
- fiat_p256_addcarryx_u32(&x201, &x202, x200, x183, x151);
+ fiat_p256_addcarryx_u32(&x201, &x202, x200, x151, x183);
uint32_t x203;
fiat_p256_uint1 x204;
- fiat_p256_addcarryx_u32(&x203, &x204, x202, x185, x153);
+ fiat_p256_addcarryx_u32(&x203, &x204, x202, x153, x185);
uint32_t x205;
fiat_p256_uint1 x206;
- fiat_p256_addcarryx_u32(&x205, &x206, x204, x187, x155);
+ fiat_p256_addcarryx_u32(&x205, &x206, x204, x155, x187);
uint32_t x207;
fiat_p256_uint1 x208;
- fiat_p256_addcarryx_u32(&x207, &x208, x206, x189, x157);
+ fiat_p256_addcarryx_u32(&x207, &x208, x206, x157, x189);
uint32_t x209;
uint32_t x210;
fiat_p256_mulx_u32(&x209, &x210, x191, UINT32_C(0xffffffff));
@@ -1494,43 +1494,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x215, &x216, x191, UINT32_C(0xffffffff));
uint32_t x217;
fiat_p256_uint1 x218;
- fiat_p256_addcarryx_u32(&x217, &x218, 0x0, x213, x216);
+ fiat_p256_addcarryx_u32(&x217, &x218, 0x0, x216, x213);
uint32_t x219;
fiat_p256_uint1 x220;
- fiat_p256_addcarryx_u32(&x219, &x220, x218, x211, x214);
+ fiat_p256_addcarryx_u32(&x219, &x220, x218, x214, x211);
uint32_t x221;
fiat_p256_uint1 x222;
- fiat_p256_addcarryx_u32(&x221, &x222, x220, 0x0, x212);
+ fiat_p256_addcarryx_u32(&x221, &x222, x220, x212, 0x0);
uint32_t x223;
fiat_p256_uint1 x224;
- fiat_p256_addcarryx_u32(&x223, &x224, 0x0, x215, x191);
+ fiat_p256_addcarryx_u32(&x223, &x224, 0x0, x191, x215);
uint32_t x225;
fiat_p256_uint1 x226;
- fiat_p256_addcarryx_u32(&x225, &x226, x224, x217, x193);
+ fiat_p256_addcarryx_u32(&x225, &x226, x224, x193, x217);
uint32_t x227;
fiat_p256_uint1 x228;
- fiat_p256_addcarryx_u32(&x227, &x228, x226, x219, x195);
+ fiat_p256_addcarryx_u32(&x227, &x228, x226, x195, x219);
uint32_t x229;
fiat_p256_uint1 x230;
- fiat_p256_addcarryx_u32(&x229, &x230, x228, x221, x197);
+ fiat_p256_addcarryx_u32(&x229, &x230, x228, x197, x221);
uint32_t x231;
fiat_p256_uint1 x232;
- fiat_p256_addcarryx_u32(&x231, &x232, x230, 0x0, x199);
+ fiat_p256_addcarryx_u32(&x231, &x232, x230, x199, 0x0);
uint32_t x233;
fiat_p256_uint1 x234;
- fiat_p256_addcarryx_u32(&x233, &x234, x232, 0x0, x201);
+ fiat_p256_addcarryx_u32(&x233, &x234, x232, x201, 0x0);
uint32_t x235;
fiat_p256_uint1 x236;
- fiat_p256_addcarryx_u32(&x235, &x236, x234, x191, x203);
+ fiat_p256_addcarryx_u32(&x235, &x236, x234, x203, x191);
uint32_t x237;
fiat_p256_uint1 x238;
- fiat_p256_addcarryx_u32(&x237, &x238, x236, x209, x205);
+ fiat_p256_addcarryx_u32(&x237, &x238, x236, x205, x209);
uint32_t x239;
fiat_p256_uint1 x240;
- fiat_p256_addcarryx_u32(&x239, &x240, x238, x210, x207);
+ fiat_p256_addcarryx_u32(&x239, &x240, x238, x207, x210);
uint32_t x241;
fiat_p256_uint1 x242;
- fiat_p256_addcarryx_u32(&x241, &x242, x240, 0x0, x208);
+ fiat_p256_addcarryx_u32(&x241, &x242, x240, x208, 0x0);
uint32_t x243;
uint32_t x244;
fiat_p256_mulx_u32(&x243, &x244, x3, (arg1[7]));
@@ -1557,55 +1557,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x257, &x258, x3, (arg1[0]));
uint32_t x259;
fiat_p256_uint1 x260;
- fiat_p256_addcarryx_u32(&x259, &x260, 0x0, x255, x258);
+ fiat_p256_addcarryx_u32(&x259, &x260, 0x0, x258, x255);
uint32_t x261;
fiat_p256_uint1 x262;
- fiat_p256_addcarryx_u32(&x261, &x262, x260, x253, x256);
+ fiat_p256_addcarryx_u32(&x261, &x262, x260, x256, x253);
uint32_t x263;
fiat_p256_uint1 x264;
- fiat_p256_addcarryx_u32(&x263, &x264, x262, x251, x254);
+ fiat_p256_addcarryx_u32(&x263, &x264, x262, x254, x251);
uint32_t x265;
fiat_p256_uint1 x266;
- fiat_p256_addcarryx_u32(&x265, &x266, x264, x249, x252);
+ fiat_p256_addcarryx_u32(&x265, &x266, x264, x252, x249);
uint32_t x267;
fiat_p256_uint1 x268;
- fiat_p256_addcarryx_u32(&x267, &x268, x266, x247, x250);
+ fiat_p256_addcarryx_u32(&x267, &x268, x266, x250, x247);
uint32_t x269;
fiat_p256_uint1 x270;
- fiat_p256_addcarryx_u32(&x269, &x270, x268, x245, x248);
+ fiat_p256_addcarryx_u32(&x269, &x270, x268, x248, x245);
uint32_t x271;
fiat_p256_uint1 x272;
- fiat_p256_addcarryx_u32(&x271, &x272, x270, x243, x246);
+ fiat_p256_addcarryx_u32(&x271, &x272, x270, x246, x243);
uint32_t x273;
fiat_p256_uint1 x274;
- fiat_p256_addcarryx_u32(&x273, &x274, x272, 0x0, x244);
+ fiat_p256_addcarryx_u32(&x273, &x274, x272, x244, 0x0);
uint32_t x275;
fiat_p256_uint1 x276;
- fiat_p256_addcarryx_u32(&x275, &x276, 0x0, x257, x225);
+ fiat_p256_addcarryx_u32(&x275, &x276, 0x0, x225, x257);
uint32_t x277;
fiat_p256_uint1 x278;
- fiat_p256_addcarryx_u32(&x277, &x278, x276, x259, x227);
+ fiat_p256_addcarryx_u32(&x277, &x278, x276, x227, x259);
uint32_t x279;
fiat_p256_uint1 x280;
- fiat_p256_addcarryx_u32(&x279, &x280, x278, x261, x229);
+ fiat_p256_addcarryx_u32(&x279, &x280, x278, x229, x261);
uint32_t x281;
fiat_p256_uint1 x282;
- fiat_p256_addcarryx_u32(&x281, &x282, x280, x263, x231);
+ fiat_p256_addcarryx_u32(&x281, &x282, x280, x231, x263);
uint32_t x283;
fiat_p256_uint1 x284;
- fiat_p256_addcarryx_u32(&x283, &x284, x282, x265, x233);
+ fiat_p256_addcarryx_u32(&x283, &x284, x282, x233, x265);
uint32_t x285;
fiat_p256_uint1 x286;
- fiat_p256_addcarryx_u32(&x285, &x286, x284, x267, x235);
+ fiat_p256_addcarryx_u32(&x285, &x286, x284, x235, x267);
uint32_t x287;
fiat_p256_uint1 x288;
- fiat_p256_addcarryx_u32(&x287, &x288, x286, x269, x237);
+ fiat_p256_addcarryx_u32(&x287, &x288, x286, x237, x269);
uint32_t x289;
fiat_p256_uint1 x290;
- fiat_p256_addcarryx_u32(&x289, &x290, x288, x271, x239);
+ fiat_p256_addcarryx_u32(&x289, &x290, x288, x239, x271);
uint32_t x291;
fiat_p256_uint1 x292;
- fiat_p256_addcarryx_u32(&x291, &x292, x290, x273, x241);
+ fiat_p256_addcarryx_u32(&x291, &x292, x290, x241, x273);
uint32_t x293;
uint32_t x294;
fiat_p256_mulx_u32(&x293, &x294, x275, UINT32_C(0xffffffff));
@@ -1620,43 +1620,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x299, &x300, x275, UINT32_C(0xffffffff));
uint32_t x301;
fiat_p256_uint1 x302;
- fiat_p256_addcarryx_u32(&x301, &x302, 0x0, x297, x300);
+ fiat_p256_addcarryx_u32(&x301, &x302, 0x0, x300, x297);
uint32_t x303;
fiat_p256_uint1 x304;
- fiat_p256_addcarryx_u32(&x303, &x304, x302, x295, x298);
+ fiat_p256_addcarryx_u32(&x303, &x304, x302, x298, x295);
uint32_t x305;
fiat_p256_uint1 x306;
- fiat_p256_addcarryx_u32(&x305, &x306, x304, 0x0, x296);
+ fiat_p256_addcarryx_u32(&x305, &x306, x304, x296, 0x0);
uint32_t x307;
fiat_p256_uint1 x308;
- fiat_p256_addcarryx_u32(&x307, &x308, 0x0, x299, x275);
+ fiat_p256_addcarryx_u32(&x307, &x308, 0x0, x275, x299);
uint32_t x309;
fiat_p256_uint1 x310;
- fiat_p256_addcarryx_u32(&x309, &x310, x308, x301, x277);
+ fiat_p256_addcarryx_u32(&x309, &x310, x308, x277, x301);
uint32_t x311;
fiat_p256_uint1 x312;
- fiat_p256_addcarryx_u32(&x311, &x312, x310, x303, x279);
+ fiat_p256_addcarryx_u32(&x311, &x312, x310, x279, x303);
uint32_t x313;
fiat_p256_uint1 x314;
- fiat_p256_addcarryx_u32(&x313, &x314, x312, x305, x281);
+ fiat_p256_addcarryx_u32(&x313, &x314, x312, x281, x305);
uint32_t x315;
fiat_p256_uint1 x316;
- fiat_p256_addcarryx_u32(&x315, &x316, x314, 0x0, x283);
+ fiat_p256_addcarryx_u32(&x315, &x316, x314, x283, 0x0);
uint32_t x317;
fiat_p256_uint1 x318;
- fiat_p256_addcarryx_u32(&x317, &x318, x316, 0x0, x285);
+ fiat_p256_addcarryx_u32(&x317, &x318, x316, x285, 0x0);
uint32_t x319;
fiat_p256_uint1 x320;
- fiat_p256_addcarryx_u32(&x319, &x320, x318, x275, x287);
+ fiat_p256_addcarryx_u32(&x319, &x320, x318, x287, x275);
uint32_t x321;
fiat_p256_uint1 x322;
- fiat_p256_addcarryx_u32(&x321, &x322, x320, x293, x289);
+ fiat_p256_addcarryx_u32(&x321, &x322, x320, x289, x293);
uint32_t x323;
fiat_p256_uint1 x324;
- fiat_p256_addcarryx_u32(&x323, &x324, x322, x294, x291);
+ fiat_p256_addcarryx_u32(&x323, &x324, x322, x291, x294);
uint32_t x325;
fiat_p256_uint1 x326;
- fiat_p256_addcarryx_u32(&x325, &x326, x324, 0x0, x292);
+ fiat_p256_addcarryx_u32(&x325, &x326, x324, x292, 0x0);
uint32_t x327;
uint32_t x328;
fiat_p256_mulx_u32(&x327, &x328, x4, (arg1[7]));
@@ -1683,55 +1683,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x341, &x342, x4, (arg1[0]));
uint32_t x343;
fiat_p256_uint1 x344;
- fiat_p256_addcarryx_u32(&x343, &x344, 0x0, x339, x342);
+ fiat_p256_addcarryx_u32(&x343, &x344, 0x0, x342, x339);
uint32_t x345;
fiat_p256_uint1 x346;
- fiat_p256_addcarryx_u32(&x345, &x346, x344, x337, x340);
+ fiat_p256_addcarryx_u32(&x345, &x346, x344, x340, x337);
uint32_t x347;
fiat_p256_uint1 x348;
- fiat_p256_addcarryx_u32(&x347, &x348, x346, x335, x338);
+ fiat_p256_addcarryx_u32(&x347, &x348, x346, x338, x335);
uint32_t x349;
fiat_p256_uint1 x350;
- fiat_p256_addcarryx_u32(&x349, &x350, x348, x333, x336);
+ fiat_p256_addcarryx_u32(&x349, &x350, x348, x336, x333);
uint32_t x351;
fiat_p256_uint1 x352;
- fiat_p256_addcarryx_u32(&x351, &x352, x350, x331, x334);
+ fiat_p256_addcarryx_u32(&x351, &x352, x350, x334, x331);
uint32_t x353;
fiat_p256_uint1 x354;
- fiat_p256_addcarryx_u32(&x353, &x354, x352, x329, x332);
+ fiat_p256_addcarryx_u32(&x353, &x354, x352, x332, x329);
uint32_t x355;
fiat_p256_uint1 x356;
- fiat_p256_addcarryx_u32(&x355, &x356, x354, x327, x330);
+ fiat_p256_addcarryx_u32(&x355, &x356, x354, x330, x327);
uint32_t x357;
fiat_p256_uint1 x358;
- fiat_p256_addcarryx_u32(&x357, &x358, x356, 0x0, x328);
+ fiat_p256_addcarryx_u32(&x357, &x358, x356, x328, 0x0);
uint32_t x359;
fiat_p256_uint1 x360;
- fiat_p256_addcarryx_u32(&x359, &x360, 0x0, x341, x309);
+ fiat_p256_addcarryx_u32(&x359, &x360, 0x0, x309, x341);
uint32_t x361;
fiat_p256_uint1 x362;
- fiat_p256_addcarryx_u32(&x361, &x362, x360, x343, x311);
+ fiat_p256_addcarryx_u32(&x361, &x362, x360, x311, x343);
uint32_t x363;
fiat_p256_uint1 x364;
- fiat_p256_addcarryx_u32(&x363, &x364, x362, x345, x313);
+ fiat_p256_addcarryx_u32(&x363, &x364, x362, x313, x345);
uint32_t x365;
fiat_p256_uint1 x366;
- fiat_p256_addcarryx_u32(&x365, &x366, x364, x347, x315);
+ fiat_p256_addcarryx_u32(&x365, &x366, x364, x315, x347);
uint32_t x367;
fiat_p256_uint1 x368;
- fiat_p256_addcarryx_u32(&x367, &x368, x366, x349, x317);
+ fiat_p256_addcarryx_u32(&x367, &x368, x366, x317, x349);
uint32_t x369;
fiat_p256_uint1 x370;
- fiat_p256_addcarryx_u32(&x369, &x370, x368, x351, x319);
+ fiat_p256_addcarryx_u32(&x369, &x370, x368, x319, x351);
uint32_t x371;
fiat_p256_uint1 x372;
- fiat_p256_addcarryx_u32(&x371, &x372, x370, x353, x321);
+ fiat_p256_addcarryx_u32(&x371, &x372, x370, x321, x353);
uint32_t x373;
fiat_p256_uint1 x374;
- fiat_p256_addcarryx_u32(&x373, &x374, x372, x355, x323);
+ fiat_p256_addcarryx_u32(&x373, &x374, x372, x323, x355);
uint32_t x375;
fiat_p256_uint1 x376;
- fiat_p256_addcarryx_u32(&x375, &x376, x374, x357, x325);
+ fiat_p256_addcarryx_u32(&x375, &x376, x374, x325, x357);
uint32_t x377;
uint32_t x378;
fiat_p256_mulx_u32(&x377, &x378, x359, UINT32_C(0xffffffff));
@@ -1746,43 +1746,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x383, &x384, x359, UINT32_C(0xffffffff));
uint32_t x385;
fiat_p256_uint1 x386;
- fiat_p256_addcarryx_u32(&x385, &x386, 0x0, x381, x384);
+ fiat_p256_addcarryx_u32(&x385, &x386, 0x0, x384, x381);
uint32_t x387;
fiat_p256_uint1 x388;
- fiat_p256_addcarryx_u32(&x387, &x388, x386, x379, x382);
+ fiat_p256_addcarryx_u32(&x387, &x388, x386, x382, x379);
uint32_t x389;
fiat_p256_uint1 x390;
- fiat_p256_addcarryx_u32(&x389, &x390, x388, 0x0, x380);
+ fiat_p256_addcarryx_u32(&x389, &x390, x388, x380, 0x0);
uint32_t x391;
fiat_p256_uint1 x392;
- fiat_p256_addcarryx_u32(&x391, &x392, 0x0, x383, x359);
+ fiat_p256_addcarryx_u32(&x391, &x392, 0x0, x359, x383);
uint32_t x393;
fiat_p256_uint1 x394;
- fiat_p256_addcarryx_u32(&x393, &x394, x392, x385, x361);
+ fiat_p256_addcarryx_u32(&x393, &x394, x392, x361, x385);
uint32_t x395;
fiat_p256_uint1 x396;
- fiat_p256_addcarryx_u32(&x395, &x396, x394, x387, x363);
+ fiat_p256_addcarryx_u32(&x395, &x396, x394, x363, x387);
uint32_t x397;
fiat_p256_uint1 x398;
- fiat_p256_addcarryx_u32(&x397, &x398, x396, x389, x365);
+ fiat_p256_addcarryx_u32(&x397, &x398, x396, x365, x389);
uint32_t x399;
fiat_p256_uint1 x400;
- fiat_p256_addcarryx_u32(&x399, &x400, x398, 0x0, x367);
+ fiat_p256_addcarryx_u32(&x399, &x400, x398, x367, 0x0);
uint32_t x401;
fiat_p256_uint1 x402;
- fiat_p256_addcarryx_u32(&x401, &x402, x400, 0x0, x369);
+ fiat_p256_addcarryx_u32(&x401, &x402, x400, x369, 0x0);
uint32_t x403;
fiat_p256_uint1 x404;
- fiat_p256_addcarryx_u32(&x403, &x404, x402, x359, x371);
+ fiat_p256_addcarryx_u32(&x403, &x404, x402, x371, x359);
uint32_t x405;
fiat_p256_uint1 x406;
- fiat_p256_addcarryx_u32(&x405, &x406, x404, x377, x373);
+ fiat_p256_addcarryx_u32(&x405, &x406, x404, x373, x377);
uint32_t x407;
fiat_p256_uint1 x408;
- fiat_p256_addcarryx_u32(&x407, &x408, x406, x378, x375);
+ fiat_p256_addcarryx_u32(&x407, &x408, x406, x375, x378);
uint32_t x409;
fiat_p256_uint1 x410;
- fiat_p256_addcarryx_u32(&x409, &x410, x408, 0x0, x376);
+ fiat_p256_addcarryx_u32(&x409, &x410, x408, x376, 0x0);
uint32_t x411;
uint32_t x412;
fiat_p256_mulx_u32(&x411, &x412, x5, (arg1[7]));
@@ -1809,55 +1809,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x425, &x426, x5, (arg1[0]));
uint32_t x427;
fiat_p256_uint1 x428;
- fiat_p256_addcarryx_u32(&x427, &x428, 0x0, x423, x426);
+ fiat_p256_addcarryx_u32(&x427, &x428, 0x0, x426, x423);
uint32_t x429;
fiat_p256_uint1 x430;
- fiat_p256_addcarryx_u32(&x429, &x430, x428, x421, x424);
+ fiat_p256_addcarryx_u32(&x429, &x430, x428, x424, x421);
uint32_t x431;
fiat_p256_uint1 x432;
- fiat_p256_addcarryx_u32(&x431, &x432, x430, x419, x422);
+ fiat_p256_addcarryx_u32(&x431, &x432, x430, x422, x419);
uint32_t x433;
fiat_p256_uint1 x434;
- fiat_p256_addcarryx_u32(&x433, &x434, x432, x417, x420);
+ fiat_p256_addcarryx_u32(&x433, &x434, x432, x420, x417);
uint32_t x435;
fiat_p256_uint1 x436;
- fiat_p256_addcarryx_u32(&x435, &x436, x434, x415, x418);
+ fiat_p256_addcarryx_u32(&x435, &x436, x434, x418, x415);
uint32_t x437;
fiat_p256_uint1 x438;
- fiat_p256_addcarryx_u32(&x437, &x438, x436, x413, x416);
+ fiat_p256_addcarryx_u32(&x437, &x438, x436, x416, x413);
uint32_t x439;
fiat_p256_uint1 x440;
- fiat_p256_addcarryx_u32(&x439, &x440, x438, x411, x414);
+ fiat_p256_addcarryx_u32(&x439, &x440, x438, x414, x411);
uint32_t x441;
fiat_p256_uint1 x442;
- fiat_p256_addcarryx_u32(&x441, &x442, x440, 0x0, x412);
+ fiat_p256_addcarryx_u32(&x441, &x442, x440, x412, 0x0);
uint32_t x443;
fiat_p256_uint1 x444;
- fiat_p256_addcarryx_u32(&x443, &x444, 0x0, x425, x393);
+ fiat_p256_addcarryx_u32(&x443, &x444, 0x0, x393, x425);
uint32_t x445;
fiat_p256_uint1 x446;
- fiat_p256_addcarryx_u32(&x445, &x446, x444, x427, x395);
+ fiat_p256_addcarryx_u32(&x445, &x446, x444, x395, x427);
uint32_t x447;
fiat_p256_uint1 x448;
- fiat_p256_addcarryx_u32(&x447, &x448, x446, x429, x397);
+ fiat_p256_addcarryx_u32(&x447, &x448, x446, x397, x429);
uint32_t x449;
fiat_p256_uint1 x450;
- fiat_p256_addcarryx_u32(&x449, &x450, x448, x431, x399);
+ fiat_p256_addcarryx_u32(&x449, &x450, x448, x399, x431);
uint32_t x451;
fiat_p256_uint1 x452;
- fiat_p256_addcarryx_u32(&x451, &x452, x450, x433, x401);
+ fiat_p256_addcarryx_u32(&x451, &x452, x450, x401, x433);
uint32_t x453;
fiat_p256_uint1 x454;
- fiat_p256_addcarryx_u32(&x453, &x454, x452, x435, x403);
+ fiat_p256_addcarryx_u32(&x453, &x454, x452, x403, x435);
uint32_t x455;
fiat_p256_uint1 x456;
- fiat_p256_addcarryx_u32(&x455, &x456, x454, x437, x405);
+ fiat_p256_addcarryx_u32(&x455, &x456, x454, x405, x437);
uint32_t x457;
fiat_p256_uint1 x458;
- fiat_p256_addcarryx_u32(&x457, &x458, x456, x439, x407);
+ fiat_p256_addcarryx_u32(&x457, &x458, x456, x407, x439);
uint32_t x459;
fiat_p256_uint1 x460;
- fiat_p256_addcarryx_u32(&x459, &x460, x458, x441, x409);
+ fiat_p256_addcarryx_u32(&x459, &x460, x458, x409, x441);
uint32_t x461;
uint32_t x462;
fiat_p256_mulx_u32(&x461, &x462, x443, UINT32_C(0xffffffff));
@@ -1872,43 +1872,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x467, &x468, x443, UINT32_C(0xffffffff));
uint32_t x469;
fiat_p256_uint1 x470;
- fiat_p256_addcarryx_u32(&x469, &x470, 0x0, x465, x468);
+ fiat_p256_addcarryx_u32(&x469, &x470, 0x0, x468, x465);
uint32_t x471;
fiat_p256_uint1 x472;
- fiat_p256_addcarryx_u32(&x471, &x472, x470, x463, x466);
+ fiat_p256_addcarryx_u32(&x471, &x472, x470, x466, x463);
uint32_t x473;
fiat_p256_uint1 x474;
- fiat_p256_addcarryx_u32(&x473, &x474, x472, 0x0, x464);
+ fiat_p256_addcarryx_u32(&x473, &x474, x472, x464, 0x0);
uint32_t x475;
fiat_p256_uint1 x476;
- fiat_p256_addcarryx_u32(&x475, &x476, 0x0, x467, x443);
+ fiat_p256_addcarryx_u32(&x475, &x476, 0x0, x443, x467);
uint32_t x477;
fiat_p256_uint1 x478;
- fiat_p256_addcarryx_u32(&x477, &x478, x476, x469, x445);
+ fiat_p256_addcarryx_u32(&x477, &x478, x476, x445, x469);
uint32_t x479;
fiat_p256_uint1 x480;
- fiat_p256_addcarryx_u32(&x479, &x480, x478, x471, x447);
+ fiat_p256_addcarryx_u32(&x479, &x480, x478, x447, x471);
uint32_t x481;
fiat_p256_uint1 x482;
- fiat_p256_addcarryx_u32(&x481, &x482, x480, x473, x449);
+ fiat_p256_addcarryx_u32(&x481, &x482, x480, x449, x473);
uint32_t x483;
fiat_p256_uint1 x484;
- fiat_p256_addcarryx_u32(&x483, &x484, x482, 0x0, x451);
+ fiat_p256_addcarryx_u32(&x483, &x484, x482, x451, 0x0);
uint32_t x485;
fiat_p256_uint1 x486;
- fiat_p256_addcarryx_u32(&x485, &x486, x484, 0x0, x453);
+ fiat_p256_addcarryx_u32(&x485, &x486, x484, x453, 0x0);
uint32_t x487;
fiat_p256_uint1 x488;
- fiat_p256_addcarryx_u32(&x487, &x488, x486, x443, x455);
+ fiat_p256_addcarryx_u32(&x487, &x488, x486, x455, x443);
uint32_t x489;
fiat_p256_uint1 x490;
- fiat_p256_addcarryx_u32(&x489, &x490, x488, x461, x457);
+ fiat_p256_addcarryx_u32(&x489, &x490, x488, x457, x461);
uint32_t x491;
fiat_p256_uint1 x492;
- fiat_p256_addcarryx_u32(&x491, &x492, x490, x462, x459);
+ fiat_p256_addcarryx_u32(&x491, &x492, x490, x459, x462);
uint32_t x493;
fiat_p256_uint1 x494;
- fiat_p256_addcarryx_u32(&x493, &x494, x492, 0x0, x460);
+ fiat_p256_addcarryx_u32(&x493, &x494, x492, x460, 0x0);
uint32_t x495;
uint32_t x496;
fiat_p256_mulx_u32(&x495, &x496, x6, (arg1[7]));
@@ -1935,55 +1935,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x509, &x510, x6, (arg1[0]));
uint32_t x511;
fiat_p256_uint1 x512;
- fiat_p256_addcarryx_u32(&x511, &x512, 0x0, x507, x510);
+ fiat_p256_addcarryx_u32(&x511, &x512, 0x0, x510, x507);
uint32_t x513;
fiat_p256_uint1 x514;
- fiat_p256_addcarryx_u32(&x513, &x514, x512, x505, x508);
+ fiat_p256_addcarryx_u32(&x513, &x514, x512, x508, x505);
uint32_t x515;
fiat_p256_uint1 x516;
- fiat_p256_addcarryx_u32(&x515, &x516, x514, x503, x506);
+ fiat_p256_addcarryx_u32(&x515, &x516, x514, x506, x503);
uint32_t x517;
fiat_p256_uint1 x518;
- fiat_p256_addcarryx_u32(&x517, &x518, x516, x501, x504);
+ fiat_p256_addcarryx_u32(&x517, &x518, x516, x504, x501);
uint32_t x519;
fiat_p256_uint1 x520;
- fiat_p256_addcarryx_u32(&x519, &x520, x518, x499, x502);
+ fiat_p256_addcarryx_u32(&x519, &x520, x518, x502, x499);
uint32_t x521;
fiat_p256_uint1 x522;
- fiat_p256_addcarryx_u32(&x521, &x522, x520, x497, x500);
+ fiat_p256_addcarryx_u32(&x521, &x522, x520, x500, x497);
uint32_t x523;
fiat_p256_uint1 x524;
- fiat_p256_addcarryx_u32(&x523, &x524, x522, x495, x498);
+ fiat_p256_addcarryx_u32(&x523, &x524, x522, x498, x495);
uint32_t x525;
fiat_p256_uint1 x526;
- fiat_p256_addcarryx_u32(&x525, &x526, x524, 0x0, x496);
+ fiat_p256_addcarryx_u32(&x525, &x526, x524, x496, 0x0);
uint32_t x527;
fiat_p256_uint1 x528;
- fiat_p256_addcarryx_u32(&x527, &x528, 0x0, x509, x477);
+ fiat_p256_addcarryx_u32(&x527, &x528, 0x0, x477, x509);
uint32_t x529;
fiat_p256_uint1 x530;
- fiat_p256_addcarryx_u32(&x529, &x530, x528, x511, x479);
+ fiat_p256_addcarryx_u32(&x529, &x530, x528, x479, x511);
uint32_t x531;
fiat_p256_uint1 x532;
- fiat_p256_addcarryx_u32(&x531, &x532, x530, x513, x481);
+ fiat_p256_addcarryx_u32(&x531, &x532, x530, x481, x513);
uint32_t x533;
fiat_p256_uint1 x534;
- fiat_p256_addcarryx_u32(&x533, &x534, x532, x515, x483);
+ fiat_p256_addcarryx_u32(&x533, &x534, x532, x483, x515);
uint32_t x535;
fiat_p256_uint1 x536;
- fiat_p256_addcarryx_u32(&x535, &x536, x534, x517, x485);
+ fiat_p256_addcarryx_u32(&x535, &x536, x534, x485, x517);
uint32_t x537;
fiat_p256_uint1 x538;
- fiat_p256_addcarryx_u32(&x537, &x538, x536, x519, x487);
+ fiat_p256_addcarryx_u32(&x537, &x538, x536, x487, x519);
uint32_t x539;
fiat_p256_uint1 x540;
- fiat_p256_addcarryx_u32(&x539, &x540, x538, x521, x489);
+ fiat_p256_addcarryx_u32(&x539, &x540, x538, x489, x521);
uint32_t x541;
fiat_p256_uint1 x542;
- fiat_p256_addcarryx_u32(&x541, &x542, x540, x523, x491);
+ fiat_p256_addcarryx_u32(&x541, &x542, x540, x491, x523);
uint32_t x543;
fiat_p256_uint1 x544;
- fiat_p256_addcarryx_u32(&x543, &x544, x542, x525, x493);
+ fiat_p256_addcarryx_u32(&x543, &x544, x542, x493, x525);
uint32_t x545;
uint32_t x546;
fiat_p256_mulx_u32(&x545, &x546, x527, UINT32_C(0xffffffff));
@@ -1998,43 +1998,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x551, &x552, x527, UINT32_C(0xffffffff));
uint32_t x553;
fiat_p256_uint1 x554;
- fiat_p256_addcarryx_u32(&x553, &x554, 0x0, x549, x552);
+ fiat_p256_addcarryx_u32(&x553, &x554, 0x0, x552, x549);
uint32_t x555;
fiat_p256_uint1 x556;
- fiat_p256_addcarryx_u32(&x555, &x556, x554, x547, x550);
+ fiat_p256_addcarryx_u32(&x555, &x556, x554, x550, x547);
uint32_t x557;
fiat_p256_uint1 x558;
- fiat_p256_addcarryx_u32(&x557, &x558, x556, 0x0, x548);
+ fiat_p256_addcarryx_u32(&x557, &x558, x556, x548, 0x0);
uint32_t x559;
fiat_p256_uint1 x560;
- fiat_p256_addcarryx_u32(&x559, &x560, 0x0, x551, x527);
+ fiat_p256_addcarryx_u32(&x559, &x560, 0x0, x527, x551);
uint32_t x561;
fiat_p256_uint1 x562;
- fiat_p256_addcarryx_u32(&x561, &x562, x560, x553, x529);
+ fiat_p256_addcarryx_u32(&x561, &x562, x560, x529, x553);
uint32_t x563;
fiat_p256_uint1 x564;
- fiat_p256_addcarryx_u32(&x563, &x564, x562, x555, x531);
+ fiat_p256_addcarryx_u32(&x563, &x564, x562, x531, x555);
uint32_t x565;
fiat_p256_uint1 x566;
- fiat_p256_addcarryx_u32(&x565, &x566, x564, x557, x533);
+ fiat_p256_addcarryx_u32(&x565, &x566, x564, x533, x557);
uint32_t x567;
fiat_p256_uint1 x568;
- fiat_p256_addcarryx_u32(&x567, &x568, x566, 0x0, x535);
+ fiat_p256_addcarryx_u32(&x567, &x568, x566, x535, 0x0);
uint32_t x569;
fiat_p256_uint1 x570;
- fiat_p256_addcarryx_u32(&x569, &x570, x568, 0x0, x537);
+ fiat_p256_addcarryx_u32(&x569, &x570, x568, x537, 0x0);
uint32_t x571;
fiat_p256_uint1 x572;
- fiat_p256_addcarryx_u32(&x571, &x572, x570, x527, x539);
+ fiat_p256_addcarryx_u32(&x571, &x572, x570, x539, x527);
uint32_t x573;
fiat_p256_uint1 x574;
- fiat_p256_addcarryx_u32(&x573, &x574, x572, x545, x541);
+ fiat_p256_addcarryx_u32(&x573, &x574, x572, x541, x545);
uint32_t x575;
fiat_p256_uint1 x576;
- fiat_p256_addcarryx_u32(&x575, &x576, x574, x546, x543);
+ fiat_p256_addcarryx_u32(&x575, &x576, x574, x543, x546);
uint32_t x577;
fiat_p256_uint1 x578;
- fiat_p256_addcarryx_u32(&x577, &x578, x576, 0x0, x544);
+ fiat_p256_addcarryx_u32(&x577, &x578, x576, x544, 0x0);
uint32_t x579;
uint32_t x580;
fiat_p256_mulx_u32(&x579, &x580, x7, (arg1[7]));
@@ -2061,55 +2061,55 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x593, &x594, x7, (arg1[0]));
uint32_t x595;
fiat_p256_uint1 x596;
- fiat_p256_addcarryx_u32(&x595, &x596, 0x0, x591, x594);
+ fiat_p256_addcarryx_u32(&x595, &x596, 0x0, x594, x591);
uint32_t x597;
fiat_p256_uint1 x598;
- fiat_p256_addcarryx_u32(&x597, &x598, x596, x589, x592);
+ fiat_p256_addcarryx_u32(&x597, &x598, x596, x592, x589);
uint32_t x599;
fiat_p256_uint1 x600;
- fiat_p256_addcarryx_u32(&x599, &x600, x598, x587, x590);
+ fiat_p256_addcarryx_u32(&x599, &x600, x598, x590, x587);
uint32_t x601;
fiat_p256_uint1 x602;
- fiat_p256_addcarryx_u32(&x601, &x602, x600, x585, x588);
+ fiat_p256_addcarryx_u32(&x601, &x602, x600, x588, x585);
uint32_t x603;
fiat_p256_uint1 x604;
- fiat_p256_addcarryx_u32(&x603, &x604, x602, x583, x586);
+ fiat_p256_addcarryx_u32(&x603, &x604, x602, x586, x583);
uint32_t x605;
fiat_p256_uint1 x606;
- fiat_p256_addcarryx_u32(&x605, &x606, x604, x581, x584);
+ fiat_p256_addcarryx_u32(&x605, &x606, x604, x584, x581);
uint32_t x607;
fiat_p256_uint1 x608;
- fiat_p256_addcarryx_u32(&x607, &x608, x606, x579, x582);
+ fiat_p256_addcarryx_u32(&x607, &x608, x606, x582, x579);
uint32_t x609;
fiat_p256_uint1 x610;
- fiat_p256_addcarryx_u32(&x609, &x610, x608, 0x0, x580);
+ fiat_p256_addcarryx_u32(&x609, &x610, x608, x580, 0x0);
uint32_t x611;
fiat_p256_uint1 x612;
- fiat_p256_addcarryx_u32(&x611, &x612, 0x0, x593, x561);
+ fiat_p256_addcarryx_u32(&x611, &x612, 0x0, x561, x593);
uint32_t x613;
fiat_p256_uint1 x614;
- fiat_p256_addcarryx_u32(&x613, &x614, x612, x595, x563);
+ fiat_p256_addcarryx_u32(&x613, &x614, x612, x563, x595);
uint32_t x615;
fiat_p256_uint1 x616;
- fiat_p256_addcarryx_u32(&x615, &x616, x614, x597, x565);
+ fiat_p256_addcarryx_u32(&x615, &x616, x614, x565, x597);
uint32_t x617;
fiat_p256_uint1 x618;
- fiat_p256_addcarryx_u32(&x617, &x618, x616, x599, x567);
+ fiat_p256_addcarryx_u32(&x617, &x618, x616, x567, x599);
uint32_t x619;
fiat_p256_uint1 x620;
- fiat_p256_addcarryx_u32(&x619, &x620, x618, x601, x569);
+ fiat_p256_addcarryx_u32(&x619, &x620, x618, x569, x601);
uint32_t x621;
fiat_p256_uint1 x622;
- fiat_p256_addcarryx_u32(&x621, &x622, x620, x603, x571);
+ fiat_p256_addcarryx_u32(&x621, &x622, x620, x571, x603);
uint32_t x623;
fiat_p256_uint1 x624;
- fiat_p256_addcarryx_u32(&x623, &x624, x622, x605, x573);
+ fiat_p256_addcarryx_u32(&x623, &x624, x622, x573, x605);
uint32_t x625;
fiat_p256_uint1 x626;
- fiat_p256_addcarryx_u32(&x625, &x626, x624, x607, x575);
+ fiat_p256_addcarryx_u32(&x625, &x626, x624, x575, x607);
uint32_t x627;
fiat_p256_uint1 x628;
- fiat_p256_addcarryx_u32(&x627, &x628, x626, x609, x577);
+ fiat_p256_addcarryx_u32(&x627, &x628, x626, x577, x609);
uint32_t x629;
uint32_t x630;
fiat_p256_mulx_u32(&x629, &x630, x611, UINT32_C(0xffffffff));
@@ -2124,43 +2124,43 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_mulx_u32(&x635, &x636, x611, UINT32_C(0xffffffff));
uint32_t x637;
fiat_p256_uint1 x638;
- fiat_p256_addcarryx_u32(&x637, &x638, 0x0, x633, x636);
+ fiat_p256_addcarryx_u32(&x637, &x638, 0x0, x636, x633);
uint32_t x639;
fiat_p256_uint1 x640;
- fiat_p256_addcarryx_u32(&x639, &x640, x638, x631, x634);
+ fiat_p256_addcarryx_u32(&x639, &x640, x638, x634, x631);
uint32_t x641;
fiat_p256_uint1 x642;
- fiat_p256_addcarryx_u32(&x641, &x642, x640, 0x0, x632);
+ fiat_p256_addcarryx_u32(&x641, &x642, x640, x632, 0x0);
uint32_t x643;
fiat_p256_uint1 x644;
- fiat_p256_addcarryx_u32(&x643, &x644, 0x0, x635, x611);
+ fiat_p256_addcarryx_u32(&x643, &x644, 0x0, x611, x635);
uint32_t x645;
fiat_p256_uint1 x646;
- fiat_p256_addcarryx_u32(&x645, &x646, x644, x637, x613);
+ fiat_p256_addcarryx_u32(&x645, &x646, x644, x613, x637);
uint32_t x647;
fiat_p256_uint1 x648;
- fiat_p256_addcarryx_u32(&x647, &x648, x646, x639, x615);
+ fiat_p256_addcarryx_u32(&x647, &x648, x646, x615, x639);
uint32_t x649;
fiat_p256_uint1 x650;
- fiat_p256_addcarryx_u32(&x649, &x650, x648, x641, x617);
+ fiat_p256_addcarryx_u32(&x649, &x650, x648, x617, x641);
uint32_t x651;
fiat_p256_uint1 x652;
- fiat_p256_addcarryx_u32(&x651, &x652, x650, 0x0, x619);
+ fiat_p256_addcarryx_u32(&x651, &x652, x650, x619, 0x0);
uint32_t x653;
fiat_p256_uint1 x654;
- fiat_p256_addcarryx_u32(&x653, &x654, x652, 0x0, x621);
+ fiat_p256_addcarryx_u32(&x653, &x654, x652, x621, 0x0);
uint32_t x655;
fiat_p256_uint1 x656;
- fiat_p256_addcarryx_u32(&x655, &x656, x654, x611, x623);
+ fiat_p256_addcarryx_u32(&x655, &x656, x654, x623, x611);
uint32_t x657;
fiat_p256_uint1 x658;
- fiat_p256_addcarryx_u32(&x657, &x658, x656, x629, x625);
+ fiat_p256_addcarryx_u32(&x657, &x658, x656, x625, x629);
uint32_t x659;
fiat_p256_uint1 x660;
- fiat_p256_addcarryx_u32(&x659, &x660, x658, x630, x627);
+ fiat_p256_addcarryx_u32(&x659, &x660, x658, x627, x630);
uint32_t x661;
fiat_p256_uint1 x662;
- fiat_p256_addcarryx_u32(&x661, &x662, x660, 0x0, x628);
+ fiat_p256_addcarryx_u32(&x661, &x662, x660, x628, 0x0);
uint32_t x663;
fiat_p256_uint1 x664;
fiat_p256_subborrowx_u32(&x663, &x664, 0x0, x645, UINT32_C(0xffffffff));
@@ -2232,28 +2232,28 @@ static void fiat_p256_square(uint32_t out1[8], const uint32_t arg1[8]) {
static void fiat_p256_add(uint32_t out1[8], const uint32_t arg1[8], const uint32_t arg2[8]) {
uint32_t x1;
fiat_p256_uint1 x2;
- fiat_p256_addcarryx_u32(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p256_addcarryx_u32(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint32_t x3;
fiat_p256_uint1 x4;
- fiat_p256_addcarryx_u32(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p256_addcarryx_u32(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint32_t x5;
fiat_p256_uint1 x6;
- fiat_p256_addcarryx_u32(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p256_addcarryx_u32(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint32_t x7;
fiat_p256_uint1 x8;
- fiat_p256_addcarryx_u32(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p256_addcarryx_u32(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint32_t x9;
fiat_p256_uint1 x10;
- fiat_p256_addcarryx_u32(&x9, &x10, x8, (arg2[4]), (arg1[4]));
+ fiat_p256_addcarryx_u32(&x9, &x10, x8, (arg1[4]), (arg2[4]));
uint32_t x11;
fiat_p256_uint1 x12;
- fiat_p256_addcarryx_u32(&x11, &x12, x10, (arg2[5]), (arg1[5]));
+ fiat_p256_addcarryx_u32(&x11, &x12, x10, (arg1[5]), (arg2[5]));
uint32_t x13;
fiat_p256_uint1 x14;
- fiat_p256_addcarryx_u32(&x13, &x14, x12, (arg2[6]), (arg1[6]));
+ fiat_p256_addcarryx_u32(&x13, &x14, x12, (arg1[6]), (arg2[6]));
uint32_t x15;
fiat_p256_uint1 x16;
- fiat_p256_addcarryx_u32(&x15, &x16, x14, (arg2[7]), (arg1[7]));
+ fiat_p256_addcarryx_u32(&x15, &x16, x14, (arg1[7]), (arg2[7]));
uint32_t x17;
fiat_p256_uint1 x18;
fiat_p256_subborrowx_u32(&x17, &x18, 0x0, x1, UINT32_C(0xffffffff));
@@ -2351,28 +2351,28 @@ static void fiat_p256_sub(uint32_t out1[8], const uint32_t arg1[8], const uint32
fiat_p256_cmovznz_u32(&x17, x16, 0x0, UINT32_C(0xffffffff));
uint32_t x18;
fiat_p256_uint1 x19;
- fiat_p256_addcarryx_u32(&x18, &x19, 0x0, (x17 & UINT32_C(0xffffffff)), x1);
+ fiat_p256_addcarryx_u32(&x18, &x19, 0x0, x1, (x17 & UINT32_C(0xffffffff)));
uint32_t x20;
fiat_p256_uint1 x21;
- fiat_p256_addcarryx_u32(&x20, &x21, x19, (x17 & UINT32_C(0xffffffff)), x3);
+ fiat_p256_addcarryx_u32(&x20, &x21, x19, x3, (x17 & UINT32_C(0xffffffff)));
uint32_t x22;
fiat_p256_uint1 x23;
- fiat_p256_addcarryx_u32(&x22, &x23, x21, (x17 & UINT32_C(0xffffffff)), x5);
+ fiat_p256_addcarryx_u32(&x22, &x23, x21, x5, (x17 & UINT32_C(0xffffffff)));
uint32_t x24;
fiat_p256_uint1 x25;
- fiat_p256_addcarryx_u32(&x24, &x25, x23, 0x0, x7);
+ fiat_p256_addcarryx_u32(&x24, &x25, x23, x7, 0x0);
uint32_t x26;
fiat_p256_uint1 x27;
- fiat_p256_addcarryx_u32(&x26, &x27, x25, 0x0, x9);
+ fiat_p256_addcarryx_u32(&x26, &x27, x25, x9, 0x0);
uint32_t x28;
fiat_p256_uint1 x29;
- fiat_p256_addcarryx_u32(&x28, &x29, x27, 0x0, x11);
+ fiat_p256_addcarryx_u32(&x28, &x29, x27, x11, 0x0);
uint32_t x30;
fiat_p256_uint1 x31;
- fiat_p256_addcarryx_u32(&x30, &x31, x29, (fiat_p256_uint1)(x17 & 0x1), x13);
+ fiat_p256_addcarryx_u32(&x30, &x31, x29, x13, (fiat_p256_uint1)(x17 & 0x1));
uint32_t x32;
fiat_p256_uint1 x33;
- fiat_p256_addcarryx_u32(&x32, &x33, x31, (x17 & UINT32_C(0xffffffff)), x15);
+ fiat_p256_addcarryx_u32(&x32, &x33, x31, x15, (x17 & UINT32_C(0xffffffff)));
out1[0] = x18;
out1[1] = x20;
out1[2] = x22;
@@ -2425,28 +2425,28 @@ static void fiat_p256_opp(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_p256_cmovznz_u32(&x17, x16, 0x0, UINT32_C(0xffffffff));
uint32_t x18;
fiat_p256_uint1 x19;
- fiat_p256_addcarryx_u32(&x18, &x19, 0x0, (x17 & UINT32_C(0xffffffff)), x1);
+ fiat_p256_addcarryx_u32(&x18, &x19, 0x0, x1, (x17 & UINT32_C(0xffffffff)));
uint32_t x20;
fiat_p256_uint1 x21;
- fiat_p256_addcarryx_u32(&x20, &x21, x19, (x17 & UINT32_C(0xffffffff)), x3);
+ fiat_p256_addcarryx_u32(&x20, &x21, x19, x3, (x17 & UINT32_C(0xffffffff)));
uint32_t x22;
fiat_p256_uint1 x23;
- fiat_p256_addcarryx_u32(&x22, &x23, x21, (x17 & UINT32_C(0xffffffff)), x5);
+ fiat_p256_addcarryx_u32(&x22, &x23, x21, x5, (x17 & UINT32_C(0xffffffff)));
uint32_t x24;
fiat_p256_uint1 x25;
- fiat_p256_addcarryx_u32(&x24, &x25, x23, 0x0, x7);
+ fiat_p256_addcarryx_u32(&x24, &x25, x23, x7, 0x0);
uint32_t x26;
fiat_p256_uint1 x27;
- fiat_p256_addcarryx_u32(&x26, &x27, x25, 0x0, x9);
+ fiat_p256_addcarryx_u32(&x26, &x27, x25, x9, 0x0);
uint32_t x28;
fiat_p256_uint1 x29;
- fiat_p256_addcarryx_u32(&x28, &x29, x27, 0x0, x11);
+ fiat_p256_addcarryx_u32(&x28, &x29, x27, x11, 0x0);
uint32_t x30;
fiat_p256_uint1 x31;
- fiat_p256_addcarryx_u32(&x30, &x31, x29, (fiat_p256_uint1)(x17 & 0x1), x13);
+ fiat_p256_addcarryx_u32(&x30, &x31, x29, x13, (fiat_p256_uint1)(x17 & 0x1));
uint32_t x32;
fiat_p256_uint1 x33;
- fiat_p256_addcarryx_u32(&x32, &x33, x31, (x17 & UINT32_C(0xffffffff)), x15);
+ fiat_p256_addcarryx_u32(&x32, &x33, x31, x15, (x17 & UINT32_C(0xffffffff)));
out1[0] = x18;
out1[1] = x20;
out1[2] = x22;
@@ -2486,34 +2486,34 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x8, &x9, x1, UINT32_C(0xffffffff));
uint32_t x10;
fiat_p256_uint1 x11;
- fiat_p256_addcarryx_u32(&x10, &x11, 0x0, x6, x9);
+ fiat_p256_addcarryx_u32(&x10, &x11, 0x0, x9, x6);
uint32_t x12;
fiat_p256_uint1 x13;
- fiat_p256_addcarryx_u32(&x12, &x13, x11, x4, x7);
+ fiat_p256_addcarryx_u32(&x12, &x13, x11, x7, x4);
uint32_t x14;
fiat_p256_uint1 x15;
- fiat_p256_addcarryx_u32(&x14, &x15, 0x0, x8, x1);
+ fiat_p256_addcarryx_u32(&x14, &x15, 0x0, x1, x8);
uint32_t x16;
fiat_p256_uint1 x17;
- fiat_p256_addcarryx_u32(&x16, &x17, x15, x10, 0x0);
+ fiat_p256_addcarryx_u32(&x16, &x17, x15, 0x0, x10);
uint32_t x18;
fiat_p256_uint1 x19;
- fiat_p256_addcarryx_u32(&x18, &x19, x17, x12, 0x0);
+ fiat_p256_addcarryx_u32(&x18, &x19, x17, 0x0, x12);
uint32_t x20;
fiat_p256_uint1 x21;
- fiat_p256_addcarryx_u32(&x20, &x21, x13, 0x0, x5);
+ fiat_p256_addcarryx_u32(&x20, &x21, x13, x5, 0x0);
uint32_t x22;
fiat_p256_uint1 x23;
- fiat_p256_addcarryx_u32(&x22, &x23, x19, x20, 0x0);
+ fiat_p256_addcarryx_u32(&x22, &x23, x19, 0x0, x20);
uint32_t x24;
fiat_p256_uint1 x25;
- fiat_p256_addcarryx_u32(&x24, &x25, 0x0, (arg1[1]), x16);
+ fiat_p256_addcarryx_u32(&x24, &x25, 0x0, x16, (arg1[1]));
uint32_t x26;
fiat_p256_uint1 x27;
- fiat_p256_addcarryx_u32(&x26, &x27, x25, 0x0, x18);
+ fiat_p256_addcarryx_u32(&x26, &x27, x25, x18, 0x0);
uint32_t x28;
fiat_p256_uint1 x29;
- fiat_p256_addcarryx_u32(&x28, &x29, x27, 0x0, x22);
+ fiat_p256_addcarryx_u32(&x28, &x29, x27, x22, 0x0);
uint32_t x30;
uint32_t x31;
fiat_p256_mulx_u32(&x30, &x31, x24, UINT32_C(0xffffffff));
@@ -2528,46 +2528,46 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x36, &x37, x24, UINT32_C(0xffffffff));
uint32_t x38;
fiat_p256_uint1 x39;
- fiat_p256_addcarryx_u32(&x38, &x39, 0x0, x34, x37);
+ fiat_p256_addcarryx_u32(&x38, &x39, 0x0, x37, x34);
uint32_t x40;
fiat_p256_uint1 x41;
- fiat_p256_addcarryx_u32(&x40, &x41, x39, x32, x35);
+ fiat_p256_addcarryx_u32(&x40, &x41, x39, x35, x32);
uint32_t x42;
fiat_p256_uint1 x43;
- fiat_p256_addcarryx_u32(&x42, &x43, 0x0, x36, x24);
+ fiat_p256_addcarryx_u32(&x42, &x43, 0x0, x24, x36);
uint32_t x44;
fiat_p256_uint1 x45;
- fiat_p256_addcarryx_u32(&x44, &x45, x43, x38, x26);
+ fiat_p256_addcarryx_u32(&x44, &x45, x43, x26, x38);
uint32_t x46;
fiat_p256_uint1 x47;
- fiat_p256_addcarryx_u32(&x46, &x47, x45, x40, x28);
+ fiat_p256_addcarryx_u32(&x46, &x47, x45, x28, x40);
uint32_t x48;
fiat_p256_uint1 x49;
- fiat_p256_addcarryx_u32(&x48, &x49, x23, 0x0, 0x0);
+ fiat_p256_addcarryx_u32(&x48, &x49, x41, x33, 0x0);
uint32_t x50;
fiat_p256_uint1 x51;
- fiat_p256_addcarryx_u32(&x50, &x51, x29, 0x0, (fiat_p256_uint1)x48);
+ fiat_p256_addcarryx_u32(&x50, &x51, x23, 0x0, 0x0);
uint32_t x52;
fiat_p256_uint1 x53;
- fiat_p256_addcarryx_u32(&x52, &x53, x41, 0x0, x33);
+ fiat_p256_addcarryx_u32(&x52, &x53, x29, (fiat_p256_uint1)x50, 0x0);
uint32_t x54;
fiat_p256_uint1 x55;
- fiat_p256_addcarryx_u32(&x54, &x55, x47, x52, x50);
+ fiat_p256_addcarryx_u32(&x54, &x55, x47, x52, x48);
uint32_t x56;
fiat_p256_uint1 x57;
- fiat_p256_addcarryx_u32(&x56, &x57, 0x0, x24, x2);
+ fiat_p256_addcarryx_u32(&x56, &x57, 0x0, x2, x24);
uint32_t x58;
fiat_p256_uint1 x59;
- fiat_p256_addcarryx_u32(&x58, &x59, x57, x30, x3);
+ fiat_p256_addcarryx_u32(&x58, &x59, x57, x3, x30);
uint32_t x60;
fiat_p256_uint1 x61;
- fiat_p256_addcarryx_u32(&x60, &x61, 0x0, (arg1[2]), x44);
+ fiat_p256_addcarryx_u32(&x60, &x61, 0x0, x44, (arg1[2]));
uint32_t x62;
fiat_p256_uint1 x63;
- fiat_p256_addcarryx_u32(&x62, &x63, x61, 0x0, x46);
+ fiat_p256_addcarryx_u32(&x62, &x63, x61, x46, 0x0);
uint32_t x64;
fiat_p256_uint1 x65;
- fiat_p256_addcarryx_u32(&x64, &x65, x63, 0x0, x54);
+ fiat_p256_addcarryx_u32(&x64, &x65, x63, x54, 0x0);
uint32_t x66;
uint32_t x67;
fiat_p256_mulx_u32(&x66, &x67, x60, UINT32_C(0xffffffff));
@@ -2582,73 +2582,73 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x72, &x73, x60, UINT32_C(0xffffffff));
uint32_t x74;
fiat_p256_uint1 x75;
- fiat_p256_addcarryx_u32(&x74, &x75, 0x0, x70, x73);
+ fiat_p256_addcarryx_u32(&x74, &x75, 0x0, x73, x70);
uint32_t x76;
fiat_p256_uint1 x77;
- fiat_p256_addcarryx_u32(&x76, &x77, x75, x68, x71);
+ fiat_p256_addcarryx_u32(&x76, &x77, x75, x71, x68);
uint32_t x78;
fiat_p256_uint1 x79;
- fiat_p256_addcarryx_u32(&x78, &x79, 0x0, x72, x60);
+ fiat_p256_addcarryx_u32(&x78, &x79, 0x0, x60, x72);
uint32_t x80;
fiat_p256_uint1 x81;
- fiat_p256_addcarryx_u32(&x80, &x81, x79, x74, x62);
+ fiat_p256_addcarryx_u32(&x80, &x81, x79, x62, x74);
uint32_t x82;
fiat_p256_uint1 x83;
- fiat_p256_addcarryx_u32(&x82, &x83, x81, x76, x64);
+ fiat_p256_addcarryx_u32(&x82, &x83, x81, x64, x76);
uint32_t x84;
fiat_p256_uint1 x85;
- fiat_p256_addcarryx_u32(&x84, &x85, x55, 0x0, 0x0);
+ fiat_p256_addcarryx_u32(&x84, &x85, x77, x69, 0x0);
uint32_t x86;
fiat_p256_uint1 x87;
- fiat_p256_addcarryx_u32(&x86, &x87, x65, 0x0, (fiat_p256_uint1)x84);
+ fiat_p256_addcarryx_u32(&x86, &x87, x55, 0x0, 0x0);
uint32_t x88;
fiat_p256_uint1 x89;
- fiat_p256_addcarryx_u32(&x88, &x89, x77, 0x0, x69);
+ fiat_p256_addcarryx_u32(&x88, &x89, x65, (fiat_p256_uint1)x86, 0x0);
uint32_t x90;
fiat_p256_uint1 x91;
- fiat_p256_addcarryx_u32(&x90, &x91, x83, x88, x86);
+ fiat_p256_addcarryx_u32(&x90, &x91, x83, x88, x84);
uint32_t x92;
fiat_p256_uint1 x93;
- fiat_p256_addcarryx_u32(&x92, &x93, x91, 0x0, x1);
+ fiat_p256_addcarryx_u32(&x92, &x93, x91, x1, 0x0);
uint32_t x94;
fiat_p256_uint1 x95;
- fiat_p256_addcarryx_u32(&x94, &x95, x93, 0x0, x56);
+ fiat_p256_addcarryx_u32(&x94, &x95, x93, x56, 0x0);
uint32_t x96;
fiat_p256_uint1 x97;
- fiat_p256_addcarryx_u32(&x96, &x97, x95, x60, x58);
+ fiat_p256_addcarryx_u32(&x96, &x97, x95, x58, x60);
uint32_t x98;
fiat_p256_uint1 x99;
- fiat_p256_addcarryx_u32(&x98, &x99, x59, x31, 0x0);
+ fiat_p256_addcarryx_u32(&x98, &x99, x59, 0x0, x31);
uint32_t x100;
fiat_p256_uint1 x101;
- fiat_p256_addcarryx_u32(&x100, &x101, x97, x66, x98);
+ fiat_p256_addcarryx_u32(&x100, &x101, x97, x98, x66);
uint32_t x102;
fiat_p256_uint1 x103;
- fiat_p256_addcarryx_u32(&x102, &x103, 0x0, (arg1[3]), x80);
+ fiat_p256_addcarryx_u32(&x102, &x103, 0x0, x80, (arg1[3]));
uint32_t x104;
fiat_p256_uint1 x105;
- fiat_p256_addcarryx_u32(&x104, &x105, x103, 0x0, x82);
+ fiat_p256_addcarryx_u32(&x104, &x105, x103, x82, 0x0);
uint32_t x106;
fiat_p256_uint1 x107;
- fiat_p256_addcarryx_u32(&x106, &x107, x105, 0x0, x90);
+ fiat_p256_addcarryx_u32(&x106, &x107, x105, x90, 0x0);
uint32_t x108;
fiat_p256_uint1 x109;
- fiat_p256_addcarryx_u32(&x108, &x109, x107, 0x0, x92);
+ fiat_p256_addcarryx_u32(&x108, &x109, x107, x92, 0x0);
uint32_t x110;
fiat_p256_uint1 x111;
- fiat_p256_addcarryx_u32(&x110, &x111, x109, 0x0, x94);
+ fiat_p256_addcarryx_u32(&x110, &x111, x109, x94, 0x0);
uint32_t x112;
fiat_p256_uint1 x113;
- fiat_p256_addcarryx_u32(&x112, &x113, x111, 0x0, x96);
+ fiat_p256_addcarryx_u32(&x112, &x113, x111, x96, 0x0);
uint32_t x114;
fiat_p256_uint1 x115;
- fiat_p256_addcarryx_u32(&x114, &x115, x113, 0x0, x100);
+ fiat_p256_addcarryx_u32(&x114, &x115, x113, x100, 0x0);
uint32_t x116;
fiat_p256_uint1 x117;
- fiat_p256_addcarryx_u32(&x116, &x117, x101, x67, 0x0);
+ fiat_p256_addcarryx_u32(&x116, &x117, x101, 0x0, x67);
uint32_t x118;
fiat_p256_uint1 x119;
- fiat_p256_addcarryx_u32(&x118, &x119, x115, 0x0, x116);
+ fiat_p256_addcarryx_u32(&x118, &x119, x115, x116, 0x0);
uint32_t x120;
uint32_t x121;
fiat_p256_mulx_u32(&x120, &x121, x102, UINT32_C(0xffffffff));
@@ -2663,67 +2663,67 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x126, &x127, x102, UINT32_C(0xffffffff));
uint32_t x128;
fiat_p256_uint1 x129;
- fiat_p256_addcarryx_u32(&x128, &x129, 0x0, x124, x127);
+ fiat_p256_addcarryx_u32(&x128, &x129, 0x0, x127, x124);
uint32_t x130;
fiat_p256_uint1 x131;
- fiat_p256_addcarryx_u32(&x130, &x131, x129, x122, x125);
+ fiat_p256_addcarryx_u32(&x130, &x131, x129, x125, x122);
uint32_t x132;
fiat_p256_uint1 x133;
- fiat_p256_addcarryx_u32(&x132, &x133, 0x0, x126, x102);
+ fiat_p256_addcarryx_u32(&x132, &x133, 0x0, x102, x126);
uint32_t x134;
fiat_p256_uint1 x135;
- fiat_p256_addcarryx_u32(&x134, &x135, x133, x128, x104);
+ fiat_p256_addcarryx_u32(&x134, &x135, x133, x104, x128);
uint32_t x136;
fiat_p256_uint1 x137;
- fiat_p256_addcarryx_u32(&x136, &x137, x135, x130, x106);
+ fiat_p256_addcarryx_u32(&x136, &x137, x135, x106, x130);
uint32_t x138;
fiat_p256_uint1 x139;
- fiat_p256_addcarryx_u32(&x138, &x139, x131, 0x0, x123);
+ fiat_p256_addcarryx_u32(&x138, &x139, x131, x123, 0x0);
uint32_t x140;
fiat_p256_uint1 x141;
- fiat_p256_addcarryx_u32(&x140, &x141, x137, x138, x108);
+ fiat_p256_addcarryx_u32(&x140, &x141, x137, x108, x138);
uint32_t x142;
fiat_p256_uint1 x143;
- fiat_p256_addcarryx_u32(&x142, &x143, x141, 0x0, x110);
+ fiat_p256_addcarryx_u32(&x142, &x143, x141, x110, 0x0);
uint32_t x144;
fiat_p256_uint1 x145;
- fiat_p256_addcarryx_u32(&x144, &x145, x143, 0x0, x112);
+ fiat_p256_addcarryx_u32(&x144, &x145, x143, x112, 0x0);
uint32_t x146;
fiat_p256_uint1 x147;
- fiat_p256_addcarryx_u32(&x146, &x147, x145, x102, x114);
+ fiat_p256_addcarryx_u32(&x146, &x147, x145, x114, x102);
uint32_t x148;
fiat_p256_uint1 x149;
- fiat_p256_addcarryx_u32(&x148, &x149, x147, x120, x118);
+ fiat_p256_addcarryx_u32(&x148, &x149, x147, x118, x120);
uint32_t x150;
fiat_p256_uint1 x151;
fiat_p256_addcarryx_u32(&x150, &x151, x119, 0x0, 0x0);
uint32_t x152;
fiat_p256_uint1 x153;
- fiat_p256_addcarryx_u32(&x152, &x153, x149, x121, (fiat_p256_uint1)x150);
+ fiat_p256_addcarryx_u32(&x152, &x153, x149, (fiat_p256_uint1)x150, x121);
uint32_t x154;
fiat_p256_uint1 x155;
- fiat_p256_addcarryx_u32(&x154, &x155, 0x0, (arg1[4]), x134);
+ fiat_p256_addcarryx_u32(&x154, &x155, 0x0, x134, (arg1[4]));
uint32_t x156;
fiat_p256_uint1 x157;
- fiat_p256_addcarryx_u32(&x156, &x157, x155, 0x0, x136);
+ fiat_p256_addcarryx_u32(&x156, &x157, x155, x136, 0x0);
uint32_t x158;
fiat_p256_uint1 x159;
- fiat_p256_addcarryx_u32(&x158, &x159, x157, 0x0, x140);
+ fiat_p256_addcarryx_u32(&x158, &x159, x157, x140, 0x0);
uint32_t x160;
fiat_p256_uint1 x161;
- fiat_p256_addcarryx_u32(&x160, &x161, x159, 0x0, x142);
+ fiat_p256_addcarryx_u32(&x160, &x161, x159, x142, 0x0);
uint32_t x162;
fiat_p256_uint1 x163;
- fiat_p256_addcarryx_u32(&x162, &x163, x161, 0x0, x144);
+ fiat_p256_addcarryx_u32(&x162, &x163, x161, x144, 0x0);
uint32_t x164;
fiat_p256_uint1 x165;
- fiat_p256_addcarryx_u32(&x164, &x165, x163, 0x0, x146);
+ fiat_p256_addcarryx_u32(&x164, &x165, x163, x146, 0x0);
uint32_t x166;
fiat_p256_uint1 x167;
- fiat_p256_addcarryx_u32(&x166, &x167, x165, 0x0, x148);
+ fiat_p256_addcarryx_u32(&x166, &x167, x165, x148, 0x0);
uint32_t x168;
fiat_p256_uint1 x169;
- fiat_p256_addcarryx_u32(&x168, &x169, x167, 0x0, x152);
+ fiat_p256_addcarryx_u32(&x168, &x169, x167, x152, 0x0);
uint32_t x170;
uint32_t x171;
fiat_p256_mulx_u32(&x170, &x171, x154, UINT32_C(0xffffffff));
@@ -2738,70 +2738,70 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x176, &x177, x154, UINT32_C(0xffffffff));
uint32_t x178;
fiat_p256_uint1 x179;
- fiat_p256_addcarryx_u32(&x178, &x179, 0x0, x174, x177);
+ fiat_p256_addcarryx_u32(&x178, &x179, 0x0, x177, x174);
uint32_t x180;
fiat_p256_uint1 x181;
- fiat_p256_addcarryx_u32(&x180, &x181, x179, x172, x175);
+ fiat_p256_addcarryx_u32(&x180, &x181, x179, x175, x172);
uint32_t x182;
fiat_p256_uint1 x183;
- fiat_p256_addcarryx_u32(&x182, &x183, 0x0, x176, x154);
+ fiat_p256_addcarryx_u32(&x182, &x183, 0x0, x154, x176);
uint32_t x184;
fiat_p256_uint1 x185;
- fiat_p256_addcarryx_u32(&x184, &x185, x183, x178, x156);
+ fiat_p256_addcarryx_u32(&x184, &x185, x183, x156, x178);
uint32_t x186;
fiat_p256_uint1 x187;
- fiat_p256_addcarryx_u32(&x186, &x187, x185, x180, x158);
+ fiat_p256_addcarryx_u32(&x186, &x187, x185, x158, x180);
uint32_t x188;
fiat_p256_uint1 x189;
- fiat_p256_addcarryx_u32(&x188, &x189, x181, 0x0, x173);
+ fiat_p256_addcarryx_u32(&x188, &x189, x181, x173, 0x0);
uint32_t x190;
fiat_p256_uint1 x191;
- fiat_p256_addcarryx_u32(&x190, &x191, x187, x188, x160);
+ fiat_p256_addcarryx_u32(&x190, &x191, x187, x160, x188);
uint32_t x192;
fiat_p256_uint1 x193;
- fiat_p256_addcarryx_u32(&x192, &x193, x191, 0x0, x162);
+ fiat_p256_addcarryx_u32(&x192, &x193, x191, x162, 0x0);
uint32_t x194;
fiat_p256_uint1 x195;
- fiat_p256_addcarryx_u32(&x194, &x195, x193, 0x0, x164);
+ fiat_p256_addcarryx_u32(&x194, &x195, x193, x164, 0x0);
uint32_t x196;
fiat_p256_uint1 x197;
- fiat_p256_addcarryx_u32(&x196, &x197, x195, x154, x166);
+ fiat_p256_addcarryx_u32(&x196, &x197, x195, x166, x154);
uint32_t x198;
fiat_p256_uint1 x199;
- fiat_p256_addcarryx_u32(&x198, &x199, x197, x170, x168);
+ fiat_p256_addcarryx_u32(&x198, &x199, x197, x168, x170);
uint32_t x200;
fiat_p256_uint1 x201;
fiat_p256_addcarryx_u32(&x200, &x201, x153, 0x0, 0x0);
uint32_t x202;
fiat_p256_uint1 x203;
- fiat_p256_addcarryx_u32(&x202, &x203, x169, 0x0, (fiat_p256_uint1)x200);
+ fiat_p256_addcarryx_u32(&x202, &x203, x169, (fiat_p256_uint1)x200, 0x0);
uint32_t x204;
fiat_p256_uint1 x205;
- fiat_p256_addcarryx_u32(&x204, &x205, x199, x171, x202);
+ fiat_p256_addcarryx_u32(&x204, &x205, x199, x202, x171);
uint32_t x206;
fiat_p256_uint1 x207;
- fiat_p256_addcarryx_u32(&x206, &x207, 0x0, (arg1[5]), x184);
+ fiat_p256_addcarryx_u32(&x206, &x207, 0x0, x184, (arg1[5]));
uint32_t x208;
fiat_p256_uint1 x209;
- fiat_p256_addcarryx_u32(&x208, &x209, x207, 0x0, x186);
+ fiat_p256_addcarryx_u32(&x208, &x209, x207, x186, 0x0);
uint32_t x210;
fiat_p256_uint1 x211;
- fiat_p256_addcarryx_u32(&x210, &x211, x209, 0x0, x190);
+ fiat_p256_addcarryx_u32(&x210, &x211, x209, x190, 0x0);
uint32_t x212;
fiat_p256_uint1 x213;
- fiat_p256_addcarryx_u32(&x212, &x213, x211, 0x0, x192);
+ fiat_p256_addcarryx_u32(&x212, &x213, x211, x192, 0x0);
uint32_t x214;
fiat_p256_uint1 x215;
- fiat_p256_addcarryx_u32(&x214, &x215, x213, 0x0, x194);
+ fiat_p256_addcarryx_u32(&x214, &x215, x213, x194, 0x0);
uint32_t x216;
fiat_p256_uint1 x217;
- fiat_p256_addcarryx_u32(&x216, &x217, x215, 0x0, x196);
+ fiat_p256_addcarryx_u32(&x216, &x217, x215, x196, 0x0);
uint32_t x218;
fiat_p256_uint1 x219;
- fiat_p256_addcarryx_u32(&x218, &x219, x217, 0x0, x198);
+ fiat_p256_addcarryx_u32(&x218, &x219, x217, x198, 0x0);
uint32_t x220;
fiat_p256_uint1 x221;
- fiat_p256_addcarryx_u32(&x220, &x221, x219, 0x0, x204);
+ fiat_p256_addcarryx_u32(&x220, &x221, x219, x204, 0x0);
uint32_t x222;
uint32_t x223;
fiat_p256_mulx_u32(&x222, &x223, x206, UINT32_C(0xffffffff));
@@ -2816,70 +2816,70 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x228, &x229, x206, UINT32_C(0xffffffff));
uint32_t x230;
fiat_p256_uint1 x231;
- fiat_p256_addcarryx_u32(&x230, &x231, 0x0, x226, x229);
+ fiat_p256_addcarryx_u32(&x230, &x231, 0x0, x229, x226);
uint32_t x232;
fiat_p256_uint1 x233;
- fiat_p256_addcarryx_u32(&x232, &x233, x231, x224, x227);
+ fiat_p256_addcarryx_u32(&x232, &x233, x231, x227, x224);
uint32_t x234;
fiat_p256_uint1 x235;
- fiat_p256_addcarryx_u32(&x234, &x235, 0x0, x228, x206);
+ fiat_p256_addcarryx_u32(&x234, &x235, 0x0, x206, x228);
uint32_t x236;
fiat_p256_uint1 x237;
- fiat_p256_addcarryx_u32(&x236, &x237, x235, x230, x208);
+ fiat_p256_addcarryx_u32(&x236, &x237, x235, x208, x230);
uint32_t x238;
fiat_p256_uint1 x239;
- fiat_p256_addcarryx_u32(&x238, &x239, x237, x232, x210);
+ fiat_p256_addcarryx_u32(&x238, &x239, x237, x210, x232);
uint32_t x240;
fiat_p256_uint1 x241;
- fiat_p256_addcarryx_u32(&x240, &x241, x233, 0x0, x225);
+ fiat_p256_addcarryx_u32(&x240, &x241, x233, x225, 0x0);
uint32_t x242;
fiat_p256_uint1 x243;
- fiat_p256_addcarryx_u32(&x242, &x243, x239, x240, x212);
+ fiat_p256_addcarryx_u32(&x242, &x243, x239, x212, x240);
uint32_t x244;
fiat_p256_uint1 x245;
- fiat_p256_addcarryx_u32(&x244, &x245, x243, 0x0, x214);
+ fiat_p256_addcarryx_u32(&x244, &x245, x243, x214, 0x0);
uint32_t x246;
fiat_p256_uint1 x247;
- fiat_p256_addcarryx_u32(&x246, &x247, x245, 0x0, x216);
+ fiat_p256_addcarryx_u32(&x246, &x247, x245, x216, 0x0);
uint32_t x248;
fiat_p256_uint1 x249;
- fiat_p256_addcarryx_u32(&x248, &x249, x247, x206, x218);
+ fiat_p256_addcarryx_u32(&x248, &x249, x247, x218, x206);
uint32_t x250;
fiat_p256_uint1 x251;
- fiat_p256_addcarryx_u32(&x250, &x251, x249, x222, x220);
+ fiat_p256_addcarryx_u32(&x250, &x251, x249, x220, x222);
uint32_t x252;
fiat_p256_uint1 x253;
fiat_p256_addcarryx_u32(&x252, &x253, x205, 0x0, 0x0);
uint32_t x254;
fiat_p256_uint1 x255;
- fiat_p256_addcarryx_u32(&x254, &x255, x221, 0x0, (fiat_p256_uint1)x252);
+ fiat_p256_addcarryx_u32(&x254, &x255, x221, (fiat_p256_uint1)x252, 0x0);
uint32_t x256;
fiat_p256_uint1 x257;
- fiat_p256_addcarryx_u32(&x256, &x257, x251, x223, x254);
+ fiat_p256_addcarryx_u32(&x256, &x257, x251, x254, x223);
uint32_t x258;
fiat_p256_uint1 x259;
- fiat_p256_addcarryx_u32(&x258, &x259, 0x0, (arg1[6]), x236);
+ fiat_p256_addcarryx_u32(&x258, &x259, 0x0, x236, (arg1[6]));
uint32_t x260;
fiat_p256_uint1 x261;
- fiat_p256_addcarryx_u32(&x260, &x261, x259, 0x0, x238);
+ fiat_p256_addcarryx_u32(&x260, &x261, x259, x238, 0x0);
uint32_t x262;
fiat_p256_uint1 x263;
- fiat_p256_addcarryx_u32(&x262, &x263, x261, 0x0, x242);
+ fiat_p256_addcarryx_u32(&x262, &x263, x261, x242, 0x0);
uint32_t x264;
fiat_p256_uint1 x265;
- fiat_p256_addcarryx_u32(&x264, &x265, x263, 0x0, x244);
+ fiat_p256_addcarryx_u32(&x264, &x265, x263, x244, 0x0);
uint32_t x266;
fiat_p256_uint1 x267;
- fiat_p256_addcarryx_u32(&x266, &x267, x265, 0x0, x246);
+ fiat_p256_addcarryx_u32(&x266, &x267, x265, x246, 0x0);
uint32_t x268;
fiat_p256_uint1 x269;
- fiat_p256_addcarryx_u32(&x268, &x269, x267, 0x0, x248);
+ fiat_p256_addcarryx_u32(&x268, &x269, x267, x248, 0x0);
uint32_t x270;
fiat_p256_uint1 x271;
- fiat_p256_addcarryx_u32(&x270, &x271, x269, 0x0, x250);
+ fiat_p256_addcarryx_u32(&x270, &x271, x269, x250, 0x0);
uint32_t x272;
fiat_p256_uint1 x273;
- fiat_p256_addcarryx_u32(&x272, &x273, x271, 0x0, x256);
+ fiat_p256_addcarryx_u32(&x272, &x273, x271, x256, 0x0);
uint32_t x274;
uint32_t x275;
fiat_p256_mulx_u32(&x274, &x275, x258, UINT32_C(0xffffffff));
@@ -2894,70 +2894,70 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x280, &x281, x258, UINT32_C(0xffffffff));
uint32_t x282;
fiat_p256_uint1 x283;
- fiat_p256_addcarryx_u32(&x282, &x283, 0x0, x278, x281);
+ fiat_p256_addcarryx_u32(&x282, &x283, 0x0, x281, x278);
uint32_t x284;
fiat_p256_uint1 x285;
- fiat_p256_addcarryx_u32(&x284, &x285, x283, x276, x279);
+ fiat_p256_addcarryx_u32(&x284, &x285, x283, x279, x276);
uint32_t x286;
fiat_p256_uint1 x287;
- fiat_p256_addcarryx_u32(&x286, &x287, 0x0, x280, x258);
+ fiat_p256_addcarryx_u32(&x286, &x287, 0x0, x258, x280);
uint32_t x288;
fiat_p256_uint1 x289;
- fiat_p256_addcarryx_u32(&x288, &x289, x287, x282, x260);
+ fiat_p256_addcarryx_u32(&x288, &x289, x287, x260, x282);
uint32_t x290;
fiat_p256_uint1 x291;
- fiat_p256_addcarryx_u32(&x290, &x291, x289, x284, x262);
+ fiat_p256_addcarryx_u32(&x290, &x291, x289, x262, x284);
uint32_t x292;
fiat_p256_uint1 x293;
- fiat_p256_addcarryx_u32(&x292, &x293, x285, 0x0, x277);
+ fiat_p256_addcarryx_u32(&x292, &x293, x285, x277, 0x0);
uint32_t x294;
fiat_p256_uint1 x295;
- fiat_p256_addcarryx_u32(&x294, &x295, x291, x292, x264);
+ fiat_p256_addcarryx_u32(&x294, &x295, x291, x264, x292);
uint32_t x296;
fiat_p256_uint1 x297;
- fiat_p256_addcarryx_u32(&x296, &x297, x295, 0x0, x266);
+ fiat_p256_addcarryx_u32(&x296, &x297, x295, x266, 0x0);
uint32_t x298;
fiat_p256_uint1 x299;
- fiat_p256_addcarryx_u32(&x298, &x299, x297, 0x0, x268);
+ fiat_p256_addcarryx_u32(&x298, &x299, x297, x268, 0x0);
uint32_t x300;
fiat_p256_uint1 x301;
- fiat_p256_addcarryx_u32(&x300, &x301, x299, x258, x270);
+ fiat_p256_addcarryx_u32(&x300, &x301, x299, x270, x258);
uint32_t x302;
fiat_p256_uint1 x303;
- fiat_p256_addcarryx_u32(&x302, &x303, x301, x274, x272);
+ fiat_p256_addcarryx_u32(&x302, &x303, x301, x272, x274);
uint32_t x304;
fiat_p256_uint1 x305;
fiat_p256_addcarryx_u32(&x304, &x305, x257, 0x0, 0x0);
uint32_t x306;
fiat_p256_uint1 x307;
- fiat_p256_addcarryx_u32(&x306, &x307, x273, 0x0, (fiat_p256_uint1)x304);
+ fiat_p256_addcarryx_u32(&x306, &x307, x273, (fiat_p256_uint1)x304, 0x0);
uint32_t x308;
fiat_p256_uint1 x309;
- fiat_p256_addcarryx_u32(&x308, &x309, x303, x275, x306);
+ fiat_p256_addcarryx_u32(&x308, &x309, x303, x306, x275);
uint32_t x310;
fiat_p256_uint1 x311;
- fiat_p256_addcarryx_u32(&x310, &x311, 0x0, (arg1[7]), x288);
+ fiat_p256_addcarryx_u32(&x310, &x311, 0x0, x288, (arg1[7]));
uint32_t x312;
fiat_p256_uint1 x313;
- fiat_p256_addcarryx_u32(&x312, &x313, x311, 0x0, x290);
+ fiat_p256_addcarryx_u32(&x312, &x313, x311, x290, 0x0);
uint32_t x314;
fiat_p256_uint1 x315;
- fiat_p256_addcarryx_u32(&x314, &x315, x313, 0x0, x294);
+ fiat_p256_addcarryx_u32(&x314, &x315, x313, x294, 0x0);
uint32_t x316;
fiat_p256_uint1 x317;
- fiat_p256_addcarryx_u32(&x316, &x317, x315, 0x0, x296);
+ fiat_p256_addcarryx_u32(&x316, &x317, x315, x296, 0x0);
uint32_t x318;
fiat_p256_uint1 x319;
- fiat_p256_addcarryx_u32(&x318, &x319, x317, 0x0, x298);
+ fiat_p256_addcarryx_u32(&x318, &x319, x317, x298, 0x0);
uint32_t x320;
fiat_p256_uint1 x321;
- fiat_p256_addcarryx_u32(&x320, &x321, x319, 0x0, x300);
+ fiat_p256_addcarryx_u32(&x320, &x321, x319, x300, 0x0);
uint32_t x322;
fiat_p256_uint1 x323;
- fiat_p256_addcarryx_u32(&x322, &x323, x321, 0x0, x302);
+ fiat_p256_addcarryx_u32(&x322, &x323, x321, x302, 0x0);
uint32_t x324;
fiat_p256_uint1 x325;
- fiat_p256_addcarryx_u32(&x324, &x325, x323, 0x0, x308);
+ fiat_p256_addcarryx_u32(&x324, &x325, x323, x308, 0x0);
uint32_t x326;
uint32_t x327;
fiat_p256_mulx_u32(&x326, &x327, x310, UINT32_C(0xffffffff));
@@ -2972,46 +2972,46 @@ static void fiat_p256_from_montgomery(uint32_t out1[8], const uint32_t arg1[8])
fiat_p256_mulx_u32(&x332, &x333, x310, UINT32_C(0xffffffff));
uint32_t x334;
fiat_p256_uint1 x335;
- fiat_p256_addcarryx_u32(&x334, &x335, 0x0, x330, x333);
+ fiat_p256_addcarryx_u32(&x334, &x335, 0x0, x333, x330);
uint32_t x336;
fiat_p256_uint1 x337;
- fiat_p256_addcarryx_u32(&x336, &x337, x335, x328, x331);
+ fiat_p256_addcarryx_u32(&x336, &x337, x335, x331, x328);
uint32_t x338;
fiat_p256_uint1 x339;
- fiat_p256_addcarryx_u32(&x338, &x339, 0x0, x332, x310);
+ fiat_p256_addcarryx_u32(&x338, &x339, 0x0, x310, x332);
uint32_t x340;
fiat_p256_uint1 x341;
- fiat_p256_addcarryx_u32(&x340, &x341, x339, x334, x312);
+ fiat_p256_addcarryx_u32(&x340, &x341, x339, x312, x334);
uint32_t x342;
fiat_p256_uint1 x343;
- fiat_p256_addcarryx_u32(&x342, &x343, x341, x336, x314);
+ fiat_p256_addcarryx_u32(&x342, &x343, x341, x314, x336);
uint32_t x344;
fiat_p256_uint1 x345;
- fiat_p256_addcarryx_u32(&x344, &x345, x337, 0x0, x329);
+ fiat_p256_addcarryx_u32(&x344, &x345, x337, x329, 0x0);
uint32_t x346;
fiat_p256_uint1 x347;
- fiat_p256_addcarryx_u32(&x346, &x347, x343, x344, x316);
+ fiat_p256_addcarryx_u32(&x346, &x347, x343, x316, x344);
uint32_t x348;
fiat_p256_uint1 x349;
- fiat_p256_addcarryx_u32(&x348, &x349, x347, 0x0, x318);
+ fiat_p256_addcarryx_u32(&x348, &x349, x347, x318, 0x0);
uint32_t x350;
fiat_p256_uint1 x351;
- fiat_p256_addcarryx_u32(&x350, &x351, x349, 0x0, x320);
+ fiat_p256_addcarryx_u32(&x350, &x351, x349, x320, 0x0);
uint32_t x352;
fiat_p256_uint1 x353;
- fiat_p256_addcarryx_u32(&x352, &x353, x351, x310, x322);
+ fiat_p256_addcarryx_u32(&x352, &x353, x351, x322, x310);
uint32_t x354;
fiat_p256_uint1 x355;
- fiat_p256_addcarryx_u32(&x354, &x355, x353, x326, x324);
+ fiat_p256_addcarryx_u32(&x354, &x355, x353, x324, x326);
uint32_t x356;
fiat_p256_uint1 x357;
fiat_p256_addcarryx_u32(&x356, &x357, x309, 0x0, 0x0);
uint32_t x358;
fiat_p256_uint1 x359;
- fiat_p256_addcarryx_u32(&x358, &x359, x325, 0x0, (fiat_p256_uint1)x356);
+ fiat_p256_addcarryx_u32(&x358, &x359, x325, (fiat_p256_uint1)x356, 0x0);
uint32_t x360;
fiat_p256_uint1 x361;
- fiat_p256_addcarryx_u32(&x360, &x361, x355, x327, x358);
+ fiat_p256_addcarryx_u32(&x360, &x361, x355, x358, x327);
uint32_t x362;
fiat_p256_uint1 x363;
fiat_p256_subborrowx_u32(&x362, &x363, 0x0, x340, UINT32_C(0xffffffff));
diff --git a/p256_64.c b/p256_64.c
index a5ce6ec56..3279a82dc 100644
--- a/p256_64.c
+++ b/p256_64.c
@@ -136,16 +136,16 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x11, &x12, x4, (arg2[0]));
uint64_t x13;
fiat_p256_uint1 x14;
- fiat_p256_addcarryx_u64(&x13, &x14, 0x0, x9, x12);
+ fiat_p256_addcarryx_u64(&x13, &x14, 0x0, x12, x9);
uint64_t x15;
fiat_p256_uint1 x16;
- fiat_p256_addcarryx_u64(&x15, &x16, x14, x7, x10);
+ fiat_p256_addcarryx_u64(&x15, &x16, x14, x10, x7);
uint64_t x17;
fiat_p256_uint1 x18;
- fiat_p256_addcarryx_u64(&x17, &x18, x16, x5, x8);
+ fiat_p256_addcarryx_u64(&x17, &x18, x16, x8, x5);
uint64_t x19;
fiat_p256_uint1 x20;
- fiat_p256_addcarryx_u64(&x19, &x20, x18, 0x0, x6);
+ fiat_p256_addcarryx_u64(&x19, &x20, x18, x6, 0x0);
uint64_t x21;
uint64_t x22;
fiat_p256_mulx_u64(&x21, &x22, x11, UINT64_C(0xffffffff00000001));
@@ -157,25 +157,25 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x25, &x26, x11, UINT64_C(0xffffffffffffffff));
uint64_t x27;
fiat_p256_uint1 x28;
- fiat_p256_addcarryx_u64(&x27, &x28, 0x0, x23, x26);
+ fiat_p256_addcarryx_u64(&x27, &x28, 0x0, x26, x23);
uint64_t x29;
fiat_p256_uint1 x30;
- fiat_p256_addcarryx_u64(&x29, &x30, x28, 0x0, x24);
+ fiat_p256_addcarryx_u64(&x29, &x30, x28, x24, 0x0);
uint64_t x31;
fiat_p256_uint1 x32;
- fiat_p256_addcarryx_u64(&x31, &x32, 0x0, x25, x11);
+ fiat_p256_addcarryx_u64(&x31, &x32, 0x0, x11, x25);
uint64_t x33;
fiat_p256_uint1 x34;
- fiat_p256_addcarryx_u64(&x33, &x34, x32, x27, x13);
+ fiat_p256_addcarryx_u64(&x33, &x34, x32, x13, x27);
uint64_t x35;
fiat_p256_uint1 x36;
- fiat_p256_addcarryx_u64(&x35, &x36, x34, x29, x15);
+ fiat_p256_addcarryx_u64(&x35, &x36, x34, x15, x29);
uint64_t x37;
fiat_p256_uint1 x38;
- fiat_p256_addcarryx_u64(&x37, &x38, x36, x21, x17);
+ fiat_p256_addcarryx_u64(&x37, &x38, x36, x17, x21);
uint64_t x39;
fiat_p256_uint1 x40;
- fiat_p256_addcarryx_u64(&x39, &x40, x38, x22, x19);
+ fiat_p256_addcarryx_u64(&x39, &x40, x38, x19, x22);
uint64_t x41;
fiat_p256_uint1 x42;
fiat_p256_addcarryx_u64(&x41, &x42, x40, 0x0, 0x0);
@@ -193,31 +193,31 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x49, &x50, x1, (arg2[0]));
uint64_t x51;
fiat_p256_uint1 x52;
- fiat_p256_addcarryx_u64(&x51, &x52, 0x0, x47, x50);
+ fiat_p256_addcarryx_u64(&x51, &x52, 0x0, x50, x47);
uint64_t x53;
fiat_p256_uint1 x54;
- fiat_p256_addcarryx_u64(&x53, &x54, x52, x45, x48);
+ fiat_p256_addcarryx_u64(&x53, &x54, x52, x48, x45);
uint64_t x55;
fiat_p256_uint1 x56;
- fiat_p256_addcarryx_u64(&x55, &x56, x54, x43, x46);
+ fiat_p256_addcarryx_u64(&x55, &x56, x54, x46, x43);
uint64_t x57;
fiat_p256_uint1 x58;
- fiat_p256_addcarryx_u64(&x57, &x58, x56, 0x0, x44);
+ fiat_p256_addcarryx_u64(&x57, &x58, x56, x44, 0x0);
uint64_t x59;
fiat_p256_uint1 x60;
- fiat_p256_addcarryx_u64(&x59, &x60, 0x0, x49, x33);
+ fiat_p256_addcarryx_u64(&x59, &x60, 0x0, x33, x49);
uint64_t x61;
fiat_p256_uint1 x62;
- fiat_p256_addcarryx_u64(&x61, &x62, x60, x51, x35);
+ fiat_p256_addcarryx_u64(&x61, &x62, x60, x35, x51);
uint64_t x63;
fiat_p256_uint1 x64;
- fiat_p256_addcarryx_u64(&x63, &x64, x62, x53, x37);
+ fiat_p256_addcarryx_u64(&x63, &x64, x62, x37, x53);
uint64_t x65;
fiat_p256_uint1 x66;
- fiat_p256_addcarryx_u64(&x65, &x66, x64, x55, x39);
+ fiat_p256_addcarryx_u64(&x65, &x66, x64, x39, x55);
uint64_t x67;
fiat_p256_uint1 x68;
- fiat_p256_addcarryx_u64(&x67, &x68, x66, x57, (fiat_p256_uint1)x41);
+ fiat_p256_addcarryx_u64(&x67, &x68, x66, (fiat_p256_uint1)x41, x57);
uint64_t x69;
uint64_t x70;
fiat_p256_mulx_u64(&x69, &x70, x59, UINT64_C(0xffffffff00000001));
@@ -229,28 +229,28 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x73, &x74, x59, UINT64_C(0xffffffffffffffff));
uint64_t x75;
fiat_p256_uint1 x76;
- fiat_p256_addcarryx_u64(&x75, &x76, 0x0, x71, x74);
+ fiat_p256_addcarryx_u64(&x75, &x76, 0x0, x74, x71);
uint64_t x77;
fiat_p256_uint1 x78;
- fiat_p256_addcarryx_u64(&x77, &x78, x76, 0x0, x72);
+ fiat_p256_addcarryx_u64(&x77, &x78, x76, x72, 0x0);
uint64_t x79;
fiat_p256_uint1 x80;
- fiat_p256_addcarryx_u64(&x79, &x80, 0x0, x73, x59);
+ fiat_p256_addcarryx_u64(&x79, &x80, 0x0, x59, x73);
uint64_t x81;
fiat_p256_uint1 x82;
- fiat_p256_addcarryx_u64(&x81, &x82, x80, x75, x61);
+ fiat_p256_addcarryx_u64(&x81, &x82, x80, x61, x75);
uint64_t x83;
fiat_p256_uint1 x84;
- fiat_p256_addcarryx_u64(&x83, &x84, x82, x77, x63);
+ fiat_p256_addcarryx_u64(&x83, &x84, x82, x63, x77);
uint64_t x85;
fiat_p256_uint1 x86;
- fiat_p256_addcarryx_u64(&x85, &x86, x84, x69, x65);
+ fiat_p256_addcarryx_u64(&x85, &x86, x84, x65, x69);
uint64_t x87;
fiat_p256_uint1 x88;
- fiat_p256_addcarryx_u64(&x87, &x88, x86, x70, x67);
+ fiat_p256_addcarryx_u64(&x87, &x88, x86, x67, x70);
uint64_t x89;
fiat_p256_uint1 x90;
- fiat_p256_addcarryx_u64(&x89, &x90, x88, 0x0, x68);
+ fiat_p256_addcarryx_u64(&x89, &x90, x88, x68, 0x0);
uint64_t x91;
uint64_t x92;
fiat_p256_mulx_u64(&x91, &x92, x2, (arg2[3]));
@@ -265,31 +265,31 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x97, &x98, x2, (arg2[0]));
uint64_t x99;
fiat_p256_uint1 x100;
- fiat_p256_addcarryx_u64(&x99, &x100, 0x0, x95, x98);
+ fiat_p256_addcarryx_u64(&x99, &x100, 0x0, x98, x95);
uint64_t x101;
fiat_p256_uint1 x102;
- fiat_p256_addcarryx_u64(&x101, &x102, x100, x93, x96);
+ fiat_p256_addcarryx_u64(&x101, &x102, x100, x96, x93);
uint64_t x103;
fiat_p256_uint1 x104;
- fiat_p256_addcarryx_u64(&x103, &x104, x102, x91, x94);
+ fiat_p256_addcarryx_u64(&x103, &x104, x102, x94, x91);
uint64_t x105;
fiat_p256_uint1 x106;
- fiat_p256_addcarryx_u64(&x105, &x106, x104, 0x0, x92);
+ fiat_p256_addcarryx_u64(&x105, &x106, x104, x92, 0x0);
uint64_t x107;
fiat_p256_uint1 x108;
- fiat_p256_addcarryx_u64(&x107, &x108, 0x0, x97, x81);
+ fiat_p256_addcarryx_u64(&x107, &x108, 0x0, x81, x97);
uint64_t x109;
fiat_p256_uint1 x110;
- fiat_p256_addcarryx_u64(&x109, &x110, x108, x99, x83);
+ fiat_p256_addcarryx_u64(&x109, &x110, x108, x83, x99);
uint64_t x111;
fiat_p256_uint1 x112;
- fiat_p256_addcarryx_u64(&x111, &x112, x110, x101, x85);
+ fiat_p256_addcarryx_u64(&x111, &x112, x110, x85, x101);
uint64_t x113;
fiat_p256_uint1 x114;
- fiat_p256_addcarryx_u64(&x113, &x114, x112, x103, x87);
+ fiat_p256_addcarryx_u64(&x113, &x114, x112, x87, x103);
uint64_t x115;
fiat_p256_uint1 x116;
- fiat_p256_addcarryx_u64(&x115, &x116, x114, x105, x89);
+ fiat_p256_addcarryx_u64(&x115, &x116, x114, x89, x105);
uint64_t x117;
uint64_t x118;
fiat_p256_mulx_u64(&x117, &x118, x107, UINT64_C(0xffffffff00000001));
@@ -301,28 +301,28 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x121, &x122, x107, UINT64_C(0xffffffffffffffff));
uint64_t x123;
fiat_p256_uint1 x124;
- fiat_p256_addcarryx_u64(&x123, &x124, 0x0, x119, x122);
+ fiat_p256_addcarryx_u64(&x123, &x124, 0x0, x122, x119);
uint64_t x125;
fiat_p256_uint1 x126;
- fiat_p256_addcarryx_u64(&x125, &x126, x124, 0x0, x120);
+ fiat_p256_addcarryx_u64(&x125, &x126, x124, x120, 0x0);
uint64_t x127;
fiat_p256_uint1 x128;
- fiat_p256_addcarryx_u64(&x127, &x128, 0x0, x121, x107);
+ fiat_p256_addcarryx_u64(&x127, &x128, 0x0, x107, x121);
uint64_t x129;
fiat_p256_uint1 x130;
- fiat_p256_addcarryx_u64(&x129, &x130, x128, x123, x109);
+ fiat_p256_addcarryx_u64(&x129, &x130, x128, x109, x123);
uint64_t x131;
fiat_p256_uint1 x132;
- fiat_p256_addcarryx_u64(&x131, &x132, x130, x125, x111);
+ fiat_p256_addcarryx_u64(&x131, &x132, x130, x111, x125);
uint64_t x133;
fiat_p256_uint1 x134;
- fiat_p256_addcarryx_u64(&x133, &x134, x132, x117, x113);
+ fiat_p256_addcarryx_u64(&x133, &x134, x132, x113, x117);
uint64_t x135;
fiat_p256_uint1 x136;
- fiat_p256_addcarryx_u64(&x135, &x136, x134, x118, x115);
+ fiat_p256_addcarryx_u64(&x135, &x136, x134, x115, x118);
uint64_t x137;
fiat_p256_uint1 x138;
- fiat_p256_addcarryx_u64(&x137, &x138, x136, 0x0, x116);
+ fiat_p256_addcarryx_u64(&x137, &x138, x136, x116, 0x0);
uint64_t x139;
uint64_t x140;
fiat_p256_mulx_u64(&x139, &x140, x3, (arg2[3]));
@@ -337,31 +337,31 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x145, &x146, x3, (arg2[0]));
uint64_t x147;
fiat_p256_uint1 x148;
- fiat_p256_addcarryx_u64(&x147, &x148, 0x0, x143, x146);
+ fiat_p256_addcarryx_u64(&x147, &x148, 0x0, x146, x143);
uint64_t x149;
fiat_p256_uint1 x150;
- fiat_p256_addcarryx_u64(&x149, &x150, x148, x141, x144);
+ fiat_p256_addcarryx_u64(&x149, &x150, x148, x144, x141);
uint64_t x151;
fiat_p256_uint1 x152;
- fiat_p256_addcarryx_u64(&x151, &x152, x150, x139, x142);
+ fiat_p256_addcarryx_u64(&x151, &x152, x150, x142, x139);
uint64_t x153;
fiat_p256_uint1 x154;
- fiat_p256_addcarryx_u64(&x153, &x154, x152, 0x0, x140);
+ fiat_p256_addcarryx_u64(&x153, &x154, x152, x140, 0x0);
uint64_t x155;
fiat_p256_uint1 x156;
- fiat_p256_addcarryx_u64(&x155, &x156, 0x0, x145, x129);
+ fiat_p256_addcarryx_u64(&x155, &x156, 0x0, x129, x145);
uint64_t x157;
fiat_p256_uint1 x158;
- fiat_p256_addcarryx_u64(&x157, &x158, x156, x147, x131);
+ fiat_p256_addcarryx_u64(&x157, &x158, x156, x131, x147);
uint64_t x159;
fiat_p256_uint1 x160;
- fiat_p256_addcarryx_u64(&x159, &x160, x158, x149, x133);
+ fiat_p256_addcarryx_u64(&x159, &x160, x158, x133, x149);
uint64_t x161;
fiat_p256_uint1 x162;
- fiat_p256_addcarryx_u64(&x161, &x162, x160, x151, x135);
+ fiat_p256_addcarryx_u64(&x161, &x162, x160, x135, x151);
uint64_t x163;
fiat_p256_uint1 x164;
- fiat_p256_addcarryx_u64(&x163, &x164, x162, x153, x137);
+ fiat_p256_addcarryx_u64(&x163, &x164, x162, x137, x153);
uint64_t x165;
uint64_t x166;
fiat_p256_mulx_u64(&x165, &x166, x155, UINT64_C(0xffffffff00000001));
@@ -373,28 +373,28 @@ static void fiat_p256_mul(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_mulx_u64(&x169, &x170, x155, UINT64_C(0xffffffffffffffff));
uint64_t x171;
fiat_p256_uint1 x172;
- fiat_p256_addcarryx_u64(&x171, &x172, 0x0, x167, x170);
+ fiat_p256_addcarryx_u64(&x171, &x172, 0x0, x170, x167);
uint64_t x173;
fiat_p256_uint1 x174;
- fiat_p256_addcarryx_u64(&x173, &x174, x172, 0x0, x168);
+ fiat_p256_addcarryx_u64(&x173, &x174, x172, x168, 0x0);
uint64_t x175;
fiat_p256_uint1 x176;
- fiat_p256_addcarryx_u64(&x175, &x176, 0x0, x169, x155);
+ fiat_p256_addcarryx_u64(&x175, &x176, 0x0, x155, x169);
uint64_t x177;
fiat_p256_uint1 x178;
- fiat_p256_addcarryx_u64(&x177, &x178, x176, x171, x157);
+ fiat_p256_addcarryx_u64(&x177, &x178, x176, x157, x171);
uint64_t x179;
fiat_p256_uint1 x180;
- fiat_p256_addcarryx_u64(&x179, &x180, x178, x173, x159);
+ fiat_p256_addcarryx_u64(&x179, &x180, x178, x159, x173);
uint64_t x181;
fiat_p256_uint1 x182;
- fiat_p256_addcarryx_u64(&x181, &x182, x180, x165, x161);
+ fiat_p256_addcarryx_u64(&x181, &x182, x180, x161, x165);
uint64_t x183;
fiat_p256_uint1 x184;
- fiat_p256_addcarryx_u64(&x183, &x184, x182, x166, x163);
+ fiat_p256_addcarryx_u64(&x183, &x184, x182, x163, x166);
uint64_t x185;
fiat_p256_uint1 x186;
- fiat_p256_addcarryx_u64(&x185, &x186, x184, 0x0, x164);
+ fiat_p256_addcarryx_u64(&x185, &x186, x184, x164, 0x0);
uint64_t x187;
fiat_p256_uint1 x188;
fiat_p256_subborrowx_u64(&x187, &x188, 0x0, x177, UINT64_C(0xffffffffffffffff));
@@ -456,16 +456,16 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x11, &x12, x4, (arg1[0]));
uint64_t x13;
fiat_p256_uint1 x14;
- fiat_p256_addcarryx_u64(&x13, &x14, 0x0, x9, x12);
+ fiat_p256_addcarryx_u64(&x13, &x14, 0x0, x12, x9);
uint64_t x15;
fiat_p256_uint1 x16;
- fiat_p256_addcarryx_u64(&x15, &x16, x14, x7, x10);
+ fiat_p256_addcarryx_u64(&x15, &x16, x14, x10, x7);
uint64_t x17;
fiat_p256_uint1 x18;
- fiat_p256_addcarryx_u64(&x17, &x18, x16, x5, x8);
+ fiat_p256_addcarryx_u64(&x17, &x18, x16, x8, x5);
uint64_t x19;
fiat_p256_uint1 x20;
- fiat_p256_addcarryx_u64(&x19, &x20, x18, 0x0, x6);
+ fiat_p256_addcarryx_u64(&x19, &x20, x18, x6, 0x0);
uint64_t x21;
uint64_t x22;
fiat_p256_mulx_u64(&x21, &x22, x11, UINT64_C(0xffffffff00000001));
@@ -477,25 +477,25 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x25, &x26, x11, UINT64_C(0xffffffffffffffff));
uint64_t x27;
fiat_p256_uint1 x28;
- fiat_p256_addcarryx_u64(&x27, &x28, 0x0, x23, x26);
+ fiat_p256_addcarryx_u64(&x27, &x28, 0x0, x26, x23);
uint64_t x29;
fiat_p256_uint1 x30;
- fiat_p256_addcarryx_u64(&x29, &x30, x28, 0x0, x24);
+ fiat_p256_addcarryx_u64(&x29, &x30, x28, x24, 0x0);
uint64_t x31;
fiat_p256_uint1 x32;
- fiat_p256_addcarryx_u64(&x31, &x32, 0x0, x25, x11);
+ fiat_p256_addcarryx_u64(&x31, &x32, 0x0, x11, x25);
uint64_t x33;
fiat_p256_uint1 x34;
- fiat_p256_addcarryx_u64(&x33, &x34, x32, x27, x13);
+ fiat_p256_addcarryx_u64(&x33, &x34, x32, x13, x27);
uint64_t x35;
fiat_p256_uint1 x36;
- fiat_p256_addcarryx_u64(&x35, &x36, x34, x29, x15);
+ fiat_p256_addcarryx_u64(&x35, &x36, x34, x15, x29);
uint64_t x37;
fiat_p256_uint1 x38;
- fiat_p256_addcarryx_u64(&x37, &x38, x36, x21, x17);
+ fiat_p256_addcarryx_u64(&x37, &x38, x36, x17, x21);
uint64_t x39;
fiat_p256_uint1 x40;
- fiat_p256_addcarryx_u64(&x39, &x40, x38, x22, x19);
+ fiat_p256_addcarryx_u64(&x39, &x40, x38, x19, x22);
uint64_t x41;
fiat_p256_uint1 x42;
fiat_p256_addcarryx_u64(&x41, &x42, x40, 0x0, 0x0);
@@ -513,31 +513,31 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x49, &x50, x1, (arg1[0]));
uint64_t x51;
fiat_p256_uint1 x52;
- fiat_p256_addcarryx_u64(&x51, &x52, 0x0, x47, x50);
+ fiat_p256_addcarryx_u64(&x51, &x52, 0x0, x50, x47);
uint64_t x53;
fiat_p256_uint1 x54;
- fiat_p256_addcarryx_u64(&x53, &x54, x52, x45, x48);
+ fiat_p256_addcarryx_u64(&x53, &x54, x52, x48, x45);
uint64_t x55;
fiat_p256_uint1 x56;
- fiat_p256_addcarryx_u64(&x55, &x56, x54, x43, x46);
+ fiat_p256_addcarryx_u64(&x55, &x56, x54, x46, x43);
uint64_t x57;
fiat_p256_uint1 x58;
- fiat_p256_addcarryx_u64(&x57, &x58, x56, 0x0, x44);
+ fiat_p256_addcarryx_u64(&x57, &x58, x56, x44, 0x0);
uint64_t x59;
fiat_p256_uint1 x60;
- fiat_p256_addcarryx_u64(&x59, &x60, 0x0, x49, x33);
+ fiat_p256_addcarryx_u64(&x59, &x60, 0x0, x33, x49);
uint64_t x61;
fiat_p256_uint1 x62;
- fiat_p256_addcarryx_u64(&x61, &x62, x60, x51, x35);
+ fiat_p256_addcarryx_u64(&x61, &x62, x60, x35, x51);
uint64_t x63;
fiat_p256_uint1 x64;
- fiat_p256_addcarryx_u64(&x63, &x64, x62, x53, x37);
+ fiat_p256_addcarryx_u64(&x63, &x64, x62, x37, x53);
uint64_t x65;
fiat_p256_uint1 x66;
- fiat_p256_addcarryx_u64(&x65, &x66, x64, x55, x39);
+ fiat_p256_addcarryx_u64(&x65, &x66, x64, x39, x55);
uint64_t x67;
fiat_p256_uint1 x68;
- fiat_p256_addcarryx_u64(&x67, &x68, x66, x57, (fiat_p256_uint1)x41);
+ fiat_p256_addcarryx_u64(&x67, &x68, x66, (fiat_p256_uint1)x41, x57);
uint64_t x69;
uint64_t x70;
fiat_p256_mulx_u64(&x69, &x70, x59, UINT64_C(0xffffffff00000001));
@@ -549,28 +549,28 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x73, &x74, x59, UINT64_C(0xffffffffffffffff));
uint64_t x75;
fiat_p256_uint1 x76;
- fiat_p256_addcarryx_u64(&x75, &x76, 0x0, x71, x74);
+ fiat_p256_addcarryx_u64(&x75, &x76, 0x0, x74, x71);
uint64_t x77;
fiat_p256_uint1 x78;
- fiat_p256_addcarryx_u64(&x77, &x78, x76, 0x0, x72);
+ fiat_p256_addcarryx_u64(&x77, &x78, x76, x72, 0x0);
uint64_t x79;
fiat_p256_uint1 x80;
- fiat_p256_addcarryx_u64(&x79, &x80, 0x0, x73, x59);
+ fiat_p256_addcarryx_u64(&x79, &x80, 0x0, x59, x73);
uint64_t x81;
fiat_p256_uint1 x82;
- fiat_p256_addcarryx_u64(&x81, &x82, x80, x75, x61);
+ fiat_p256_addcarryx_u64(&x81, &x82, x80, x61, x75);
uint64_t x83;
fiat_p256_uint1 x84;
- fiat_p256_addcarryx_u64(&x83, &x84, x82, x77, x63);
+ fiat_p256_addcarryx_u64(&x83, &x84, x82, x63, x77);
uint64_t x85;
fiat_p256_uint1 x86;
- fiat_p256_addcarryx_u64(&x85, &x86, x84, x69, x65);
+ fiat_p256_addcarryx_u64(&x85, &x86, x84, x65, x69);
uint64_t x87;
fiat_p256_uint1 x88;
- fiat_p256_addcarryx_u64(&x87, &x88, x86, x70, x67);
+ fiat_p256_addcarryx_u64(&x87, &x88, x86, x67, x70);
uint64_t x89;
fiat_p256_uint1 x90;
- fiat_p256_addcarryx_u64(&x89, &x90, x88, 0x0, x68);
+ fiat_p256_addcarryx_u64(&x89, &x90, x88, x68, 0x0);
uint64_t x91;
uint64_t x92;
fiat_p256_mulx_u64(&x91, &x92, x2, (arg1[3]));
@@ -585,31 +585,31 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x97, &x98, x2, (arg1[0]));
uint64_t x99;
fiat_p256_uint1 x100;
- fiat_p256_addcarryx_u64(&x99, &x100, 0x0, x95, x98);
+ fiat_p256_addcarryx_u64(&x99, &x100, 0x0, x98, x95);
uint64_t x101;
fiat_p256_uint1 x102;
- fiat_p256_addcarryx_u64(&x101, &x102, x100, x93, x96);
+ fiat_p256_addcarryx_u64(&x101, &x102, x100, x96, x93);
uint64_t x103;
fiat_p256_uint1 x104;
- fiat_p256_addcarryx_u64(&x103, &x104, x102, x91, x94);
+ fiat_p256_addcarryx_u64(&x103, &x104, x102, x94, x91);
uint64_t x105;
fiat_p256_uint1 x106;
- fiat_p256_addcarryx_u64(&x105, &x106, x104, 0x0, x92);
+ fiat_p256_addcarryx_u64(&x105, &x106, x104, x92, 0x0);
uint64_t x107;
fiat_p256_uint1 x108;
- fiat_p256_addcarryx_u64(&x107, &x108, 0x0, x97, x81);
+ fiat_p256_addcarryx_u64(&x107, &x108, 0x0, x81, x97);
uint64_t x109;
fiat_p256_uint1 x110;
- fiat_p256_addcarryx_u64(&x109, &x110, x108, x99, x83);
+ fiat_p256_addcarryx_u64(&x109, &x110, x108, x83, x99);
uint64_t x111;
fiat_p256_uint1 x112;
- fiat_p256_addcarryx_u64(&x111, &x112, x110, x101, x85);
+ fiat_p256_addcarryx_u64(&x111, &x112, x110, x85, x101);
uint64_t x113;
fiat_p256_uint1 x114;
- fiat_p256_addcarryx_u64(&x113, &x114, x112, x103, x87);
+ fiat_p256_addcarryx_u64(&x113, &x114, x112, x87, x103);
uint64_t x115;
fiat_p256_uint1 x116;
- fiat_p256_addcarryx_u64(&x115, &x116, x114, x105, x89);
+ fiat_p256_addcarryx_u64(&x115, &x116, x114, x89, x105);
uint64_t x117;
uint64_t x118;
fiat_p256_mulx_u64(&x117, &x118, x107, UINT64_C(0xffffffff00000001));
@@ -621,28 +621,28 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x121, &x122, x107, UINT64_C(0xffffffffffffffff));
uint64_t x123;
fiat_p256_uint1 x124;
- fiat_p256_addcarryx_u64(&x123, &x124, 0x0, x119, x122);
+ fiat_p256_addcarryx_u64(&x123, &x124, 0x0, x122, x119);
uint64_t x125;
fiat_p256_uint1 x126;
- fiat_p256_addcarryx_u64(&x125, &x126, x124, 0x0, x120);
+ fiat_p256_addcarryx_u64(&x125, &x126, x124, x120, 0x0);
uint64_t x127;
fiat_p256_uint1 x128;
- fiat_p256_addcarryx_u64(&x127, &x128, 0x0, x121, x107);
+ fiat_p256_addcarryx_u64(&x127, &x128, 0x0, x107, x121);
uint64_t x129;
fiat_p256_uint1 x130;
- fiat_p256_addcarryx_u64(&x129, &x130, x128, x123, x109);
+ fiat_p256_addcarryx_u64(&x129, &x130, x128, x109, x123);
uint64_t x131;
fiat_p256_uint1 x132;
- fiat_p256_addcarryx_u64(&x131, &x132, x130, x125, x111);
+ fiat_p256_addcarryx_u64(&x131, &x132, x130, x111, x125);
uint64_t x133;
fiat_p256_uint1 x134;
- fiat_p256_addcarryx_u64(&x133, &x134, x132, x117, x113);
+ fiat_p256_addcarryx_u64(&x133, &x134, x132, x113, x117);
uint64_t x135;
fiat_p256_uint1 x136;
- fiat_p256_addcarryx_u64(&x135, &x136, x134, x118, x115);
+ fiat_p256_addcarryx_u64(&x135, &x136, x134, x115, x118);
uint64_t x137;
fiat_p256_uint1 x138;
- fiat_p256_addcarryx_u64(&x137, &x138, x136, 0x0, x116);
+ fiat_p256_addcarryx_u64(&x137, &x138, x136, x116, 0x0);
uint64_t x139;
uint64_t x140;
fiat_p256_mulx_u64(&x139, &x140, x3, (arg1[3]));
@@ -657,31 +657,31 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x145, &x146, x3, (arg1[0]));
uint64_t x147;
fiat_p256_uint1 x148;
- fiat_p256_addcarryx_u64(&x147, &x148, 0x0, x143, x146);
+ fiat_p256_addcarryx_u64(&x147, &x148, 0x0, x146, x143);
uint64_t x149;
fiat_p256_uint1 x150;
- fiat_p256_addcarryx_u64(&x149, &x150, x148, x141, x144);
+ fiat_p256_addcarryx_u64(&x149, &x150, x148, x144, x141);
uint64_t x151;
fiat_p256_uint1 x152;
- fiat_p256_addcarryx_u64(&x151, &x152, x150, x139, x142);
+ fiat_p256_addcarryx_u64(&x151, &x152, x150, x142, x139);
uint64_t x153;
fiat_p256_uint1 x154;
- fiat_p256_addcarryx_u64(&x153, &x154, x152, 0x0, x140);
+ fiat_p256_addcarryx_u64(&x153, &x154, x152, x140, 0x0);
uint64_t x155;
fiat_p256_uint1 x156;
- fiat_p256_addcarryx_u64(&x155, &x156, 0x0, x145, x129);
+ fiat_p256_addcarryx_u64(&x155, &x156, 0x0, x129, x145);
uint64_t x157;
fiat_p256_uint1 x158;
- fiat_p256_addcarryx_u64(&x157, &x158, x156, x147, x131);
+ fiat_p256_addcarryx_u64(&x157, &x158, x156, x131, x147);
uint64_t x159;
fiat_p256_uint1 x160;
- fiat_p256_addcarryx_u64(&x159, &x160, x158, x149, x133);
+ fiat_p256_addcarryx_u64(&x159, &x160, x158, x133, x149);
uint64_t x161;
fiat_p256_uint1 x162;
- fiat_p256_addcarryx_u64(&x161, &x162, x160, x151, x135);
+ fiat_p256_addcarryx_u64(&x161, &x162, x160, x135, x151);
uint64_t x163;
fiat_p256_uint1 x164;
- fiat_p256_addcarryx_u64(&x163, &x164, x162, x153, x137);
+ fiat_p256_addcarryx_u64(&x163, &x164, x162, x137, x153);
uint64_t x165;
uint64_t x166;
fiat_p256_mulx_u64(&x165, &x166, x155, UINT64_C(0xffffffff00000001));
@@ -693,28 +693,28 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_mulx_u64(&x169, &x170, x155, UINT64_C(0xffffffffffffffff));
uint64_t x171;
fiat_p256_uint1 x172;
- fiat_p256_addcarryx_u64(&x171, &x172, 0x0, x167, x170);
+ fiat_p256_addcarryx_u64(&x171, &x172, 0x0, x170, x167);
uint64_t x173;
fiat_p256_uint1 x174;
- fiat_p256_addcarryx_u64(&x173, &x174, x172, 0x0, x168);
+ fiat_p256_addcarryx_u64(&x173, &x174, x172, x168, 0x0);
uint64_t x175;
fiat_p256_uint1 x176;
- fiat_p256_addcarryx_u64(&x175, &x176, 0x0, x169, x155);
+ fiat_p256_addcarryx_u64(&x175, &x176, 0x0, x155, x169);
uint64_t x177;
fiat_p256_uint1 x178;
- fiat_p256_addcarryx_u64(&x177, &x178, x176, x171, x157);
+ fiat_p256_addcarryx_u64(&x177, &x178, x176, x157, x171);
uint64_t x179;
fiat_p256_uint1 x180;
- fiat_p256_addcarryx_u64(&x179, &x180, x178, x173, x159);
+ fiat_p256_addcarryx_u64(&x179, &x180, x178, x159, x173);
uint64_t x181;
fiat_p256_uint1 x182;
- fiat_p256_addcarryx_u64(&x181, &x182, x180, x165, x161);
+ fiat_p256_addcarryx_u64(&x181, &x182, x180, x161, x165);
uint64_t x183;
fiat_p256_uint1 x184;
- fiat_p256_addcarryx_u64(&x183, &x184, x182, x166, x163);
+ fiat_p256_addcarryx_u64(&x183, &x184, x182, x163, x166);
uint64_t x185;
fiat_p256_uint1 x186;
- fiat_p256_addcarryx_u64(&x185, &x186, x184, 0x0, x164);
+ fiat_p256_addcarryx_u64(&x185, &x186, x184, x164, 0x0);
uint64_t x187;
fiat_p256_uint1 x188;
fiat_p256_subborrowx_u64(&x187, &x188, 0x0, x177, UINT64_C(0xffffffffffffffff));
@@ -762,16 +762,16 @@ static void fiat_p256_square(uint64_t out1[4], const uint64_t arg1[4]) {
static void fiat_p256_add(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
uint64_t x1;
fiat_p256_uint1 x2;
- fiat_p256_addcarryx_u64(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p256_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint64_t x3;
fiat_p256_uint1 x4;
- fiat_p256_addcarryx_u64(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p256_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint64_t x5;
fiat_p256_uint1 x6;
- fiat_p256_addcarryx_u64(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p256_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint64_t x7;
fiat_p256_uint1 x8;
- fiat_p256_addcarryx_u64(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p256_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint64_t x9;
fiat_p256_uint1 x10;
fiat_p256_subborrowx_u64(&x9, &x10, 0x0, x1, UINT64_C(0xffffffffffffffff));
@@ -833,16 +833,16 @@ static void fiat_p256_sub(uint64_t out1[4], const uint64_t arg1[4], const uint64
fiat_p256_cmovznz_u64(&x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x10;
fiat_p256_uint1 x11;
- fiat_p256_addcarryx_u64(&x10, &x11, 0x0, (x9 & UINT64_C(0xffffffffffffffff)), x1);
+ fiat_p256_addcarryx_u64(&x10, &x11, 0x0, x1, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x12;
fiat_p256_uint1 x13;
- fiat_p256_addcarryx_u64(&x12, &x13, x11, (x9 & UINT32_C(0xffffffff)), x3);
+ fiat_p256_addcarryx_u64(&x12, &x13, x11, x3, (x9 & UINT32_C(0xffffffff)));
uint64_t x14;
fiat_p256_uint1 x15;
- fiat_p256_addcarryx_u64(&x14, &x15, x13, 0x0, x5);
+ fiat_p256_addcarryx_u64(&x14, &x15, x13, x5, 0x0);
uint64_t x16;
fiat_p256_uint1 x17;
- fiat_p256_addcarryx_u64(&x16, &x17, x15, (x9 & UINT64_C(0xffffffff00000001)), x7);
+ fiat_p256_addcarryx_u64(&x16, &x17, x15, x7, (x9 & UINT64_C(0xffffffff00000001)));
out1[0] = x10;
out1[1] = x12;
out1[2] = x14;
@@ -879,16 +879,16 @@ static void fiat_p256_opp(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_p256_cmovznz_u64(&x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x10;
fiat_p256_uint1 x11;
- fiat_p256_addcarryx_u64(&x10, &x11, 0x0, (x9 & UINT64_C(0xffffffffffffffff)), x1);
+ fiat_p256_addcarryx_u64(&x10, &x11, 0x0, x1, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x12;
fiat_p256_uint1 x13;
- fiat_p256_addcarryx_u64(&x12, &x13, x11, (x9 & UINT32_C(0xffffffff)), x3);
+ fiat_p256_addcarryx_u64(&x12, &x13, x11, x3, (x9 & UINT32_C(0xffffffff)));
uint64_t x14;
fiat_p256_uint1 x15;
- fiat_p256_addcarryx_u64(&x14, &x15, x13, 0x0, x5);
+ fiat_p256_addcarryx_u64(&x14, &x15, x13, x5, 0x0);
uint64_t x16;
fiat_p256_uint1 x17;
- fiat_p256_addcarryx_u64(&x16, &x17, x15, (x9 & UINT64_C(0xffffffff00000001)), x7);
+ fiat_p256_addcarryx_u64(&x16, &x17, x15, x7, (x9 & UINT64_C(0xffffffff00000001)));
out1[0] = x10;
out1[1] = x12;
out1[2] = x14;
@@ -921,16 +921,16 @@ static void fiat_p256_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p256_mulx_u64(&x6, &x7, x1, UINT64_C(0xffffffffffffffff));
uint64_t x8;
fiat_p256_uint1 x9;
- fiat_p256_addcarryx_u64(&x8, &x9, 0x0, x4, x7);
+ fiat_p256_addcarryx_u64(&x8, &x9, 0x0, x7, x4);
uint64_t x10;
fiat_p256_uint1 x11;
- fiat_p256_addcarryx_u64(&x10, &x11, 0x0, x6, x1);
+ fiat_p256_addcarryx_u64(&x10, &x11, 0x0, x1, x6);
uint64_t x12;
fiat_p256_uint1 x13;
- fiat_p256_addcarryx_u64(&x12, &x13, x11, x8, 0x0);
+ fiat_p256_addcarryx_u64(&x12, &x13, x11, 0x0, x8);
uint64_t x14;
fiat_p256_uint1 x15;
- fiat_p256_addcarryx_u64(&x14, &x15, 0x0, (arg1[1]), x12);
+ fiat_p256_addcarryx_u64(&x14, &x15, 0x0, x12, (arg1[1]));
uint64_t x16;
uint64_t x17;
fiat_p256_mulx_u64(&x16, &x17, x14, UINT64_C(0xffffffff00000001));
@@ -942,40 +942,40 @@ static void fiat_p256_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p256_mulx_u64(&x20, &x21, x14, UINT64_C(0xffffffffffffffff));
uint64_t x22;
fiat_p256_uint1 x23;
- fiat_p256_addcarryx_u64(&x22, &x23, 0x0, x18, x21);
+ fiat_p256_addcarryx_u64(&x22, &x23, 0x0, x21, x18);
uint64_t x24;
fiat_p256_uint1 x25;
- fiat_p256_addcarryx_u64(&x24, &x25, x9, 0x0, x5);
+ fiat_p256_addcarryx_u64(&x24, &x25, x9, x5, 0x0);
uint64_t x26;
fiat_p256_uint1 x27;
- fiat_p256_addcarryx_u64(&x26, &x27, x13, x24, 0x0);
+ fiat_p256_addcarryx_u64(&x26, &x27, x13, 0x0, x24);
uint64_t x28;
fiat_p256_uint1 x29;
- fiat_p256_addcarryx_u64(&x28, &x29, x15, 0x0, x26);
+ fiat_p256_addcarryx_u64(&x28, &x29, x15, x26, 0x0);
uint64_t x30;
fiat_p256_uint1 x31;
- fiat_p256_addcarryx_u64(&x30, &x31, 0x0, x20, x14);
+ fiat_p256_addcarryx_u64(&x30, &x31, 0x0, x14, x20);
uint64_t x32;
fiat_p256_uint1 x33;
- fiat_p256_addcarryx_u64(&x32, &x33, x31, x22, x28);
+ fiat_p256_addcarryx_u64(&x32, &x33, x31, x28, x22);
uint64_t x34;
fiat_p256_uint1 x35;
- fiat_p256_addcarryx_u64(&x34, &x35, x23, 0x0, x19);
+ fiat_p256_addcarryx_u64(&x34, &x35, x23, x19, 0x0);
uint64_t x36;
fiat_p256_uint1 x37;
- fiat_p256_addcarryx_u64(&x36, &x37, x33, x34, x2);
+ fiat_p256_addcarryx_u64(&x36, &x37, x33, x2, x34);
uint64_t x38;
fiat_p256_uint1 x39;
- fiat_p256_addcarryx_u64(&x38, &x39, x37, x16, x3);
+ fiat_p256_addcarryx_u64(&x38, &x39, x37, x3, x16);
uint64_t x40;
fiat_p256_uint1 x41;
- fiat_p256_addcarryx_u64(&x40, &x41, 0x0, (arg1[2]), x32);
+ fiat_p256_addcarryx_u64(&x40, &x41, 0x0, x32, (arg1[2]));
uint64_t x42;
fiat_p256_uint1 x43;
- fiat_p256_addcarryx_u64(&x42, &x43, x41, 0x0, x36);
+ fiat_p256_addcarryx_u64(&x42, &x43, x41, x36, 0x0);
uint64_t x44;
fiat_p256_uint1 x45;
- fiat_p256_addcarryx_u64(&x44, &x45, x43, 0x0, x38);
+ fiat_p256_addcarryx_u64(&x44, &x45, x43, x38, 0x0);
uint64_t x46;
uint64_t x47;
fiat_p256_mulx_u64(&x46, &x47, x40, UINT64_C(0xffffffff00000001));
@@ -987,37 +987,37 @@ static void fiat_p256_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p256_mulx_u64(&x50, &x51, x40, UINT64_C(0xffffffffffffffff));
uint64_t x52;
fiat_p256_uint1 x53;
- fiat_p256_addcarryx_u64(&x52, &x53, 0x0, x48, x51);
+ fiat_p256_addcarryx_u64(&x52, &x53, 0x0, x51, x48);
uint64_t x54;
fiat_p256_uint1 x55;
- fiat_p256_addcarryx_u64(&x54, &x55, 0x0, x50, x40);
+ fiat_p256_addcarryx_u64(&x54, &x55, 0x0, x40, x50);
uint64_t x56;
fiat_p256_uint1 x57;
- fiat_p256_addcarryx_u64(&x56, &x57, x55, x52, x42);
+ fiat_p256_addcarryx_u64(&x56, &x57, x55, x42, x52);
uint64_t x58;
fiat_p256_uint1 x59;
- fiat_p256_addcarryx_u64(&x58, &x59, x53, 0x0, x49);
+ fiat_p256_addcarryx_u64(&x58, &x59, x53, x49, 0x0);
uint64_t x60;
fiat_p256_uint1 x61;
- fiat_p256_addcarryx_u64(&x60, &x61, x57, x58, x44);
+ fiat_p256_addcarryx_u64(&x60, &x61, x57, x44, x58);
uint64_t x62;
fiat_p256_uint1 x63;
- fiat_p256_addcarryx_u64(&x62, &x63, x39, x17, 0x0);
+ fiat_p256_addcarryx_u64(&x62, &x63, x39, 0x0, x17);
uint64_t x64;
fiat_p256_uint1 x65;
- fiat_p256_addcarryx_u64(&x64, &x65, x45, 0x0, x62);
+ fiat_p256_addcarryx_u64(&x64, &x65, x45, x62, 0x0);
uint64_t x66;
fiat_p256_uint1 x67;
- fiat_p256_addcarryx_u64(&x66, &x67, x61, x46, x64);
+ fiat_p256_addcarryx_u64(&x66, &x67, x61, x64, x46);
uint64_t x68;
fiat_p256_uint1 x69;
- fiat_p256_addcarryx_u64(&x68, &x69, 0x0, (arg1[3]), x56);
+ fiat_p256_addcarryx_u64(&x68, &x69, 0x0, x56, (arg1[3]));
uint64_t x70;
fiat_p256_uint1 x71;
- fiat_p256_addcarryx_u64(&x70, &x71, x69, 0x0, x60);
+ fiat_p256_addcarryx_u64(&x70, &x71, x69, x60, 0x0);
uint64_t x72;
fiat_p256_uint1 x73;
- fiat_p256_addcarryx_u64(&x72, &x73, x71, 0x0, x66);
+ fiat_p256_addcarryx_u64(&x72, &x73, x71, x66, 0x0);
uint64_t x74;
uint64_t x75;
fiat_p256_mulx_u64(&x74, &x75, x68, UINT64_C(0xffffffff00000001));
@@ -1029,31 +1029,31 @@ static void fiat_p256_from_montgomery(uint64_t out1[4], const uint64_t arg1[4])
fiat_p256_mulx_u64(&x78, &x79, x68, UINT64_C(0xffffffffffffffff));
uint64_t x80;
fiat_p256_uint1 x81;
- fiat_p256_addcarryx_u64(&x80, &x81, 0x0, x76, x79);
+ fiat_p256_addcarryx_u64(&x80, &x81, 0x0, x79, x76);
uint64_t x82;
fiat_p256_uint1 x83;
- fiat_p256_addcarryx_u64(&x82, &x83, 0x0, x78, x68);
+ fiat_p256_addcarryx_u64(&x82, &x83, 0x0, x68, x78);
uint64_t x84;
fiat_p256_uint1 x85;
- fiat_p256_addcarryx_u64(&x84, &x85, x83, x80, x70);
+ fiat_p256_addcarryx_u64(&x84, &x85, x83, x70, x80);
uint64_t x86;
fiat_p256_uint1 x87;
- fiat_p256_addcarryx_u64(&x86, &x87, x81, 0x0, x77);
+ fiat_p256_addcarryx_u64(&x86, &x87, x81, x77, 0x0);
uint64_t x88;
fiat_p256_uint1 x89;
- fiat_p256_addcarryx_u64(&x88, &x89, x85, x86, x72);
+ fiat_p256_addcarryx_u64(&x88, &x89, x85, x72, x86);
uint64_t x90;
fiat_p256_uint1 x91;
- fiat_p256_addcarryx_u64(&x90, &x91, x67, x47, 0x0);
+ fiat_p256_addcarryx_u64(&x90, &x91, x67, 0x0, x47);
uint64_t x92;
fiat_p256_uint1 x93;
- fiat_p256_addcarryx_u64(&x92, &x93, x73, 0x0, x90);
+ fiat_p256_addcarryx_u64(&x92, &x93, x73, x90, 0x0);
uint64_t x94;
fiat_p256_uint1 x95;
- fiat_p256_addcarryx_u64(&x94, &x95, x89, x74, x92);
+ fiat_p256_addcarryx_u64(&x94, &x95, x89, x92, x74);
uint64_t x96;
fiat_p256_uint1 x97;
- fiat_p256_addcarryx_u64(&x96, &x97, x95, x75, 0x0);
+ fiat_p256_addcarryx_u64(&x96, &x97, x95, 0x0, x75);
uint64_t x98;
fiat_p256_uint1 x99;
fiat_p256_subborrowx_u64(&x98, &x99, 0x0, x84, UINT64_C(0xffffffffffffffff));
diff --git a/p384_32.c b/p384_32.c
index c9591bdfc..b959e6389 100644
--- a/p384_32.c
+++ b/p384_32.c
@@ -166,40 +166,40 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x35, &x36, x12, (arg2[0]));
uint32_t x37;
fiat_p384_uint1 x38;
- fiat_p384_addcarryx_u32(&x37, &x38, 0x0, x33, x36);
+ fiat_p384_addcarryx_u32(&x37, &x38, 0x0, x36, x33);
uint32_t x39;
fiat_p384_uint1 x40;
- fiat_p384_addcarryx_u32(&x39, &x40, x38, x31, x34);
+ fiat_p384_addcarryx_u32(&x39, &x40, x38, x34, x31);
uint32_t x41;
fiat_p384_uint1 x42;
- fiat_p384_addcarryx_u32(&x41, &x42, x40, x29, x32);
+ fiat_p384_addcarryx_u32(&x41, &x42, x40, x32, x29);
uint32_t x43;
fiat_p384_uint1 x44;
- fiat_p384_addcarryx_u32(&x43, &x44, x42, x27, x30);
+ fiat_p384_addcarryx_u32(&x43, &x44, x42, x30, x27);
uint32_t x45;
fiat_p384_uint1 x46;
- fiat_p384_addcarryx_u32(&x45, &x46, x44, x25, x28);
+ fiat_p384_addcarryx_u32(&x45, &x46, x44, x28, x25);
uint32_t x47;
fiat_p384_uint1 x48;
- fiat_p384_addcarryx_u32(&x47, &x48, x46, x23, x26);
+ fiat_p384_addcarryx_u32(&x47, &x48, x46, x26, x23);
uint32_t x49;
fiat_p384_uint1 x50;
- fiat_p384_addcarryx_u32(&x49, &x50, x48, x21, x24);
+ fiat_p384_addcarryx_u32(&x49, &x50, x48, x24, x21);
uint32_t x51;
fiat_p384_uint1 x52;
- fiat_p384_addcarryx_u32(&x51, &x52, x50, x19, x22);
+ fiat_p384_addcarryx_u32(&x51, &x52, x50, x22, x19);
uint32_t x53;
fiat_p384_uint1 x54;
- fiat_p384_addcarryx_u32(&x53, &x54, x52, x17, x20);
+ fiat_p384_addcarryx_u32(&x53, &x54, x52, x20, x17);
uint32_t x55;
fiat_p384_uint1 x56;
- fiat_p384_addcarryx_u32(&x55, &x56, x54, x15, x18);
+ fiat_p384_addcarryx_u32(&x55, &x56, x54, x18, x15);
uint32_t x57;
fiat_p384_uint1 x58;
- fiat_p384_addcarryx_u32(&x57, &x58, x56, x13, x16);
+ fiat_p384_addcarryx_u32(&x57, &x58, x56, x16, x13);
uint32_t x59;
fiat_p384_uint1 x60;
- fiat_p384_addcarryx_u32(&x59, &x60, x58, 0x0, x14);
+ fiat_p384_addcarryx_u32(&x59, &x60, x58, x14, 0x0);
uint32_t x61;
uint32_t x62;
fiat_p384_mulx_u32(&x61, &x62, x35, UINT32_C(0xffffffff));
@@ -232,70 +232,70 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x79, &x80, x35, UINT32_C(0xffffffff));
uint32_t x81;
fiat_p384_uint1 x82;
- fiat_p384_addcarryx_u32(&x81, &x82, 0x0, x75, x78);
+ fiat_p384_addcarryx_u32(&x81, &x82, 0x0, x78, x75);
uint32_t x83;
fiat_p384_uint1 x84;
- fiat_p384_addcarryx_u32(&x83, &x84, x82, x73, x76);
+ fiat_p384_addcarryx_u32(&x83, &x84, x82, x76, x73);
uint32_t x85;
fiat_p384_uint1 x86;
- fiat_p384_addcarryx_u32(&x85, &x86, x84, x71, x74);
+ fiat_p384_addcarryx_u32(&x85, &x86, x84, x74, x71);
uint32_t x87;
fiat_p384_uint1 x88;
- fiat_p384_addcarryx_u32(&x87, &x88, x86, x69, x72);
+ fiat_p384_addcarryx_u32(&x87, &x88, x86, x72, x69);
uint32_t x89;
fiat_p384_uint1 x90;
- fiat_p384_addcarryx_u32(&x89, &x90, x88, x67, x70);
+ fiat_p384_addcarryx_u32(&x89, &x90, x88, x70, x67);
uint32_t x91;
fiat_p384_uint1 x92;
- fiat_p384_addcarryx_u32(&x91, &x92, x90, x65, x68);
+ fiat_p384_addcarryx_u32(&x91, &x92, x90, x68, x65);
uint32_t x93;
fiat_p384_uint1 x94;
- fiat_p384_addcarryx_u32(&x93, &x94, x92, x63, x66);
+ fiat_p384_addcarryx_u32(&x93, &x94, x92, x66, x63);
uint32_t x95;
fiat_p384_uint1 x96;
- fiat_p384_addcarryx_u32(&x95, &x96, x94, x61, x64);
+ fiat_p384_addcarryx_u32(&x95, &x96, x94, x64, x61);
uint32_t x97;
fiat_p384_uint1 x98;
- fiat_p384_addcarryx_u32(&x97, &x98, x96, 0x0, x62);
+ fiat_p384_addcarryx_u32(&x97, &x98, x96, x62, 0x0);
uint32_t x99;
fiat_p384_uint1 x100;
- fiat_p384_addcarryx_u32(&x99, &x100, 0x0, x79, x35);
+ fiat_p384_addcarryx_u32(&x99, &x100, 0x0, x35, x79);
uint32_t x101;
fiat_p384_uint1 x102;
- fiat_p384_addcarryx_u32(&x101, &x102, x100, x80, x37);
+ fiat_p384_addcarryx_u32(&x101, &x102, x100, x37, x80);
uint32_t x103;
fiat_p384_uint1 x104;
- fiat_p384_addcarryx_u32(&x103, &x104, x102, 0x0, x39);
+ fiat_p384_addcarryx_u32(&x103, &x104, x102, x39, 0x0);
uint32_t x105;
fiat_p384_uint1 x106;
- fiat_p384_addcarryx_u32(&x105, &x106, x104, x77, x41);
+ fiat_p384_addcarryx_u32(&x105, &x106, x104, x41, x77);
uint32_t x107;
fiat_p384_uint1 x108;
- fiat_p384_addcarryx_u32(&x107, &x108, x106, x81, x43);
+ fiat_p384_addcarryx_u32(&x107, &x108, x106, x43, x81);
uint32_t x109;
fiat_p384_uint1 x110;
- fiat_p384_addcarryx_u32(&x109, &x110, x108, x83, x45);
+ fiat_p384_addcarryx_u32(&x109, &x110, x108, x45, x83);
uint32_t x111;
fiat_p384_uint1 x112;
- fiat_p384_addcarryx_u32(&x111, &x112, x110, x85, x47);
+ fiat_p384_addcarryx_u32(&x111, &x112, x110, x47, x85);
uint32_t x113;
fiat_p384_uint1 x114;
- fiat_p384_addcarryx_u32(&x113, &x114, x112, x87, x49);
+ fiat_p384_addcarryx_u32(&x113, &x114, x112, x49, x87);
uint32_t x115;
fiat_p384_uint1 x116;
- fiat_p384_addcarryx_u32(&x115, &x116, x114, x89, x51);
+ fiat_p384_addcarryx_u32(&x115, &x116, x114, x51, x89);
uint32_t x117;
fiat_p384_uint1 x118;
- fiat_p384_addcarryx_u32(&x117, &x118, x116, x91, x53);
+ fiat_p384_addcarryx_u32(&x117, &x118, x116, x53, x91);
uint32_t x119;
fiat_p384_uint1 x120;
- fiat_p384_addcarryx_u32(&x119, &x120, x118, x93, x55);
+ fiat_p384_addcarryx_u32(&x119, &x120, x118, x55, x93);
uint32_t x121;
fiat_p384_uint1 x122;
- fiat_p384_addcarryx_u32(&x121, &x122, x120, x95, x57);
+ fiat_p384_addcarryx_u32(&x121, &x122, x120, x57, x95);
uint32_t x123;
fiat_p384_uint1 x124;
- fiat_p384_addcarryx_u32(&x123, &x124, x122, x97, x59);
+ fiat_p384_addcarryx_u32(&x123, &x124, x122, x59, x97);
uint32_t x125;
fiat_p384_uint1 x126;
fiat_p384_addcarryx_u32(&x125, &x126, x124, 0x0, 0x0);
@@ -337,79 +337,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x149, &x150, x1, (arg2[0]));
uint32_t x151;
fiat_p384_uint1 x152;
- fiat_p384_addcarryx_u32(&x151, &x152, 0x0, x147, x150);
+ fiat_p384_addcarryx_u32(&x151, &x152, 0x0, x150, x147);
uint32_t x153;
fiat_p384_uint1 x154;
- fiat_p384_addcarryx_u32(&x153, &x154, x152, x145, x148);
+ fiat_p384_addcarryx_u32(&x153, &x154, x152, x148, x145);
uint32_t x155;
fiat_p384_uint1 x156;
- fiat_p384_addcarryx_u32(&x155, &x156, x154, x143, x146);
+ fiat_p384_addcarryx_u32(&x155, &x156, x154, x146, x143);
uint32_t x157;
fiat_p384_uint1 x158;
- fiat_p384_addcarryx_u32(&x157, &x158, x156, x141, x144);
+ fiat_p384_addcarryx_u32(&x157, &x158, x156, x144, x141);
uint32_t x159;
fiat_p384_uint1 x160;
- fiat_p384_addcarryx_u32(&x159, &x160, x158, x139, x142);
+ fiat_p384_addcarryx_u32(&x159, &x160, x158, x142, x139);
uint32_t x161;
fiat_p384_uint1 x162;
- fiat_p384_addcarryx_u32(&x161, &x162, x160, x137, x140);
+ fiat_p384_addcarryx_u32(&x161, &x162, x160, x140, x137);
uint32_t x163;
fiat_p384_uint1 x164;
- fiat_p384_addcarryx_u32(&x163, &x164, x162, x135, x138);
+ fiat_p384_addcarryx_u32(&x163, &x164, x162, x138, x135);
uint32_t x165;
fiat_p384_uint1 x166;
- fiat_p384_addcarryx_u32(&x165, &x166, x164, x133, x136);
+ fiat_p384_addcarryx_u32(&x165, &x166, x164, x136, x133);
uint32_t x167;
fiat_p384_uint1 x168;
- fiat_p384_addcarryx_u32(&x167, &x168, x166, x131, x134);
+ fiat_p384_addcarryx_u32(&x167, &x168, x166, x134, x131);
uint32_t x169;
fiat_p384_uint1 x170;
- fiat_p384_addcarryx_u32(&x169, &x170, x168, x129, x132);
+ fiat_p384_addcarryx_u32(&x169, &x170, x168, x132, x129);
uint32_t x171;
fiat_p384_uint1 x172;
- fiat_p384_addcarryx_u32(&x171, &x172, x170, x127, x130);
+ fiat_p384_addcarryx_u32(&x171, &x172, x170, x130, x127);
uint32_t x173;
fiat_p384_uint1 x174;
- fiat_p384_addcarryx_u32(&x173, &x174, x172, 0x0, x128);
+ fiat_p384_addcarryx_u32(&x173, &x174, x172, x128, 0x0);
uint32_t x175;
fiat_p384_uint1 x176;
- fiat_p384_addcarryx_u32(&x175, &x176, 0x0, x149, x101);
+ fiat_p384_addcarryx_u32(&x175, &x176, 0x0, x101, x149);
uint32_t x177;
fiat_p384_uint1 x178;
- fiat_p384_addcarryx_u32(&x177, &x178, x176, x151, x103);
+ fiat_p384_addcarryx_u32(&x177, &x178, x176, x103, x151);
uint32_t x179;
fiat_p384_uint1 x180;
- fiat_p384_addcarryx_u32(&x179, &x180, x178, x153, x105);
+ fiat_p384_addcarryx_u32(&x179, &x180, x178, x105, x153);
uint32_t x181;
fiat_p384_uint1 x182;
- fiat_p384_addcarryx_u32(&x181, &x182, x180, x155, x107);
+ fiat_p384_addcarryx_u32(&x181, &x182, x180, x107, x155);
uint32_t x183;
fiat_p384_uint1 x184;
- fiat_p384_addcarryx_u32(&x183, &x184, x182, x157, x109);
+ fiat_p384_addcarryx_u32(&x183, &x184, x182, x109, x157);
uint32_t x185;
fiat_p384_uint1 x186;
- fiat_p384_addcarryx_u32(&x185, &x186, x184, x159, x111);
+ fiat_p384_addcarryx_u32(&x185, &x186, x184, x111, x159);
uint32_t x187;
fiat_p384_uint1 x188;
- fiat_p384_addcarryx_u32(&x187, &x188, x186, x161, x113);
+ fiat_p384_addcarryx_u32(&x187, &x188, x186, x113, x161);
uint32_t x189;
fiat_p384_uint1 x190;
- fiat_p384_addcarryx_u32(&x189, &x190, x188, x163, x115);
+ fiat_p384_addcarryx_u32(&x189, &x190, x188, x115, x163);
uint32_t x191;
fiat_p384_uint1 x192;
- fiat_p384_addcarryx_u32(&x191, &x192, x190, x165, x117);
+ fiat_p384_addcarryx_u32(&x191, &x192, x190, x117, x165);
uint32_t x193;
fiat_p384_uint1 x194;
- fiat_p384_addcarryx_u32(&x193, &x194, x192, x167, x119);
+ fiat_p384_addcarryx_u32(&x193, &x194, x192, x119, x167);
uint32_t x195;
fiat_p384_uint1 x196;
- fiat_p384_addcarryx_u32(&x195, &x196, x194, x169, x121);
+ fiat_p384_addcarryx_u32(&x195, &x196, x194, x121, x169);
uint32_t x197;
fiat_p384_uint1 x198;
- fiat_p384_addcarryx_u32(&x197, &x198, x196, x171, x123);
+ fiat_p384_addcarryx_u32(&x197, &x198, x196, x123, x171);
uint32_t x199;
fiat_p384_uint1 x200;
- fiat_p384_addcarryx_u32(&x199, &x200, x198, x173, (fiat_p384_uint1)x125);
+ fiat_p384_addcarryx_u32(&x199, &x200, x198, (fiat_p384_uint1)x125, x173);
uint32_t x201;
uint32_t x202;
fiat_p384_mulx_u32(&x201, &x202, x175, UINT32_C(0xffffffff));
@@ -442,73 +442,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x219, &x220, x175, UINT32_C(0xffffffff));
uint32_t x221;
fiat_p384_uint1 x222;
- fiat_p384_addcarryx_u32(&x221, &x222, 0x0, x215, x218);
+ fiat_p384_addcarryx_u32(&x221, &x222, 0x0, x218, x215);
uint32_t x223;
fiat_p384_uint1 x224;
- fiat_p384_addcarryx_u32(&x223, &x224, x222, x213, x216);
+ fiat_p384_addcarryx_u32(&x223, &x224, x222, x216, x213);
uint32_t x225;
fiat_p384_uint1 x226;
- fiat_p384_addcarryx_u32(&x225, &x226, x224, x211, x214);
+ fiat_p384_addcarryx_u32(&x225, &x226, x224, x214, x211);
uint32_t x227;
fiat_p384_uint1 x228;
- fiat_p384_addcarryx_u32(&x227, &x228, x226, x209, x212);
+ fiat_p384_addcarryx_u32(&x227, &x228, x226, x212, x209);
uint32_t x229;
fiat_p384_uint1 x230;
- fiat_p384_addcarryx_u32(&x229, &x230, x228, x207, x210);
+ fiat_p384_addcarryx_u32(&x229, &x230, x228, x210, x207);
uint32_t x231;
fiat_p384_uint1 x232;
- fiat_p384_addcarryx_u32(&x231, &x232, x230, x205, x208);
+ fiat_p384_addcarryx_u32(&x231, &x232, x230, x208, x205);
uint32_t x233;
fiat_p384_uint1 x234;
- fiat_p384_addcarryx_u32(&x233, &x234, x232, x203, x206);
+ fiat_p384_addcarryx_u32(&x233, &x234, x232, x206, x203);
uint32_t x235;
fiat_p384_uint1 x236;
- fiat_p384_addcarryx_u32(&x235, &x236, x234, x201, x204);
+ fiat_p384_addcarryx_u32(&x235, &x236, x234, x204, x201);
uint32_t x237;
fiat_p384_uint1 x238;
- fiat_p384_addcarryx_u32(&x237, &x238, x236, 0x0, x202);
+ fiat_p384_addcarryx_u32(&x237, &x238, x236, x202, 0x0);
uint32_t x239;
fiat_p384_uint1 x240;
- fiat_p384_addcarryx_u32(&x239, &x240, 0x0, x219, x175);
+ fiat_p384_addcarryx_u32(&x239, &x240, 0x0, x175, x219);
uint32_t x241;
fiat_p384_uint1 x242;
- fiat_p384_addcarryx_u32(&x241, &x242, x240, x220, x177);
+ fiat_p384_addcarryx_u32(&x241, &x242, x240, x177, x220);
uint32_t x243;
fiat_p384_uint1 x244;
- fiat_p384_addcarryx_u32(&x243, &x244, x242, 0x0, x179);
+ fiat_p384_addcarryx_u32(&x243, &x244, x242, x179, 0x0);
uint32_t x245;
fiat_p384_uint1 x246;
- fiat_p384_addcarryx_u32(&x245, &x246, x244, x217, x181);
+ fiat_p384_addcarryx_u32(&x245, &x246, x244, x181, x217);
uint32_t x247;
fiat_p384_uint1 x248;
- fiat_p384_addcarryx_u32(&x247, &x248, x246, x221, x183);
+ fiat_p384_addcarryx_u32(&x247, &x248, x246, x183, x221);
uint32_t x249;
fiat_p384_uint1 x250;
- fiat_p384_addcarryx_u32(&x249, &x250, x248, x223, x185);
+ fiat_p384_addcarryx_u32(&x249, &x250, x248, x185, x223);
uint32_t x251;
fiat_p384_uint1 x252;
- fiat_p384_addcarryx_u32(&x251, &x252, x250, x225, x187);
+ fiat_p384_addcarryx_u32(&x251, &x252, x250, x187, x225);
uint32_t x253;
fiat_p384_uint1 x254;
- fiat_p384_addcarryx_u32(&x253, &x254, x252, x227, x189);
+ fiat_p384_addcarryx_u32(&x253, &x254, x252, x189, x227);
uint32_t x255;
fiat_p384_uint1 x256;
- fiat_p384_addcarryx_u32(&x255, &x256, x254, x229, x191);
+ fiat_p384_addcarryx_u32(&x255, &x256, x254, x191, x229);
uint32_t x257;
fiat_p384_uint1 x258;
- fiat_p384_addcarryx_u32(&x257, &x258, x256, x231, x193);
+ fiat_p384_addcarryx_u32(&x257, &x258, x256, x193, x231);
uint32_t x259;
fiat_p384_uint1 x260;
- fiat_p384_addcarryx_u32(&x259, &x260, x258, x233, x195);
+ fiat_p384_addcarryx_u32(&x259, &x260, x258, x195, x233);
uint32_t x261;
fiat_p384_uint1 x262;
- fiat_p384_addcarryx_u32(&x261, &x262, x260, x235, x197);
+ fiat_p384_addcarryx_u32(&x261, &x262, x260, x197, x235);
uint32_t x263;
fiat_p384_uint1 x264;
- fiat_p384_addcarryx_u32(&x263, &x264, x262, x237, x199);
+ fiat_p384_addcarryx_u32(&x263, &x264, x262, x199, x237);
uint32_t x265;
fiat_p384_uint1 x266;
- fiat_p384_addcarryx_u32(&x265, &x266, x264, 0x0, x200);
+ fiat_p384_addcarryx_u32(&x265, &x266, x264, x200, 0x0);
uint32_t x267;
uint32_t x268;
fiat_p384_mulx_u32(&x267, &x268, x2, (arg2[11]));
@@ -547,79 +547,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x289, &x290, x2, (arg2[0]));
uint32_t x291;
fiat_p384_uint1 x292;
- fiat_p384_addcarryx_u32(&x291, &x292, 0x0, x287, x290);
+ fiat_p384_addcarryx_u32(&x291, &x292, 0x0, x290, x287);
uint32_t x293;
fiat_p384_uint1 x294;
- fiat_p384_addcarryx_u32(&x293, &x294, x292, x285, x288);
+ fiat_p384_addcarryx_u32(&x293, &x294, x292, x288, x285);
uint32_t x295;
fiat_p384_uint1 x296;
- fiat_p384_addcarryx_u32(&x295, &x296, x294, x283, x286);
+ fiat_p384_addcarryx_u32(&x295, &x296, x294, x286, x283);
uint32_t x297;
fiat_p384_uint1 x298;
- fiat_p384_addcarryx_u32(&x297, &x298, x296, x281, x284);
+ fiat_p384_addcarryx_u32(&x297, &x298, x296, x284, x281);
uint32_t x299;
fiat_p384_uint1 x300;
- fiat_p384_addcarryx_u32(&x299, &x300, x298, x279, x282);
+ fiat_p384_addcarryx_u32(&x299, &x300, x298, x282, x279);
uint32_t x301;
fiat_p384_uint1 x302;
- fiat_p384_addcarryx_u32(&x301, &x302, x300, x277, x280);
+ fiat_p384_addcarryx_u32(&x301, &x302, x300, x280, x277);
uint32_t x303;
fiat_p384_uint1 x304;
- fiat_p384_addcarryx_u32(&x303, &x304, x302, x275, x278);
+ fiat_p384_addcarryx_u32(&x303, &x304, x302, x278, x275);
uint32_t x305;
fiat_p384_uint1 x306;
- fiat_p384_addcarryx_u32(&x305, &x306, x304, x273, x276);
+ fiat_p384_addcarryx_u32(&x305, &x306, x304, x276, x273);
uint32_t x307;
fiat_p384_uint1 x308;
- fiat_p384_addcarryx_u32(&x307, &x308, x306, x271, x274);
+ fiat_p384_addcarryx_u32(&x307, &x308, x306, x274, x271);
uint32_t x309;
fiat_p384_uint1 x310;
- fiat_p384_addcarryx_u32(&x309, &x310, x308, x269, x272);
+ fiat_p384_addcarryx_u32(&x309, &x310, x308, x272, x269);
uint32_t x311;
fiat_p384_uint1 x312;
- fiat_p384_addcarryx_u32(&x311, &x312, x310, x267, x270);
+ fiat_p384_addcarryx_u32(&x311, &x312, x310, x270, x267);
uint32_t x313;
fiat_p384_uint1 x314;
- fiat_p384_addcarryx_u32(&x313, &x314, x312, 0x0, x268);
+ fiat_p384_addcarryx_u32(&x313, &x314, x312, x268, 0x0);
uint32_t x315;
fiat_p384_uint1 x316;
- fiat_p384_addcarryx_u32(&x315, &x316, 0x0, x289, x241);
+ fiat_p384_addcarryx_u32(&x315, &x316, 0x0, x241, x289);
uint32_t x317;
fiat_p384_uint1 x318;
- fiat_p384_addcarryx_u32(&x317, &x318, x316, x291, x243);
+ fiat_p384_addcarryx_u32(&x317, &x318, x316, x243, x291);
uint32_t x319;
fiat_p384_uint1 x320;
- fiat_p384_addcarryx_u32(&x319, &x320, x318, x293, x245);
+ fiat_p384_addcarryx_u32(&x319, &x320, x318, x245, x293);
uint32_t x321;
fiat_p384_uint1 x322;
- fiat_p384_addcarryx_u32(&x321, &x322, x320, x295, x247);
+ fiat_p384_addcarryx_u32(&x321, &x322, x320, x247, x295);
uint32_t x323;
fiat_p384_uint1 x324;
- fiat_p384_addcarryx_u32(&x323, &x324, x322, x297, x249);
+ fiat_p384_addcarryx_u32(&x323, &x324, x322, x249, x297);
uint32_t x325;
fiat_p384_uint1 x326;
- fiat_p384_addcarryx_u32(&x325, &x326, x324, x299, x251);
+ fiat_p384_addcarryx_u32(&x325, &x326, x324, x251, x299);
uint32_t x327;
fiat_p384_uint1 x328;
- fiat_p384_addcarryx_u32(&x327, &x328, x326, x301, x253);
+ fiat_p384_addcarryx_u32(&x327, &x328, x326, x253, x301);
uint32_t x329;
fiat_p384_uint1 x330;
- fiat_p384_addcarryx_u32(&x329, &x330, x328, x303, x255);
+ fiat_p384_addcarryx_u32(&x329, &x330, x328, x255, x303);
uint32_t x331;
fiat_p384_uint1 x332;
- fiat_p384_addcarryx_u32(&x331, &x332, x330, x305, x257);
+ fiat_p384_addcarryx_u32(&x331, &x332, x330, x257, x305);
uint32_t x333;
fiat_p384_uint1 x334;
- fiat_p384_addcarryx_u32(&x333, &x334, x332, x307, x259);
+ fiat_p384_addcarryx_u32(&x333, &x334, x332, x259, x307);
uint32_t x335;
fiat_p384_uint1 x336;
- fiat_p384_addcarryx_u32(&x335, &x336, x334, x309, x261);
+ fiat_p384_addcarryx_u32(&x335, &x336, x334, x261, x309);
uint32_t x337;
fiat_p384_uint1 x338;
- fiat_p384_addcarryx_u32(&x337, &x338, x336, x311, x263);
+ fiat_p384_addcarryx_u32(&x337, &x338, x336, x263, x311);
uint32_t x339;
fiat_p384_uint1 x340;
- fiat_p384_addcarryx_u32(&x339, &x340, x338, x313, x265);
+ fiat_p384_addcarryx_u32(&x339, &x340, x338, x265, x313);
uint32_t x341;
uint32_t x342;
fiat_p384_mulx_u32(&x341, &x342, x315, UINT32_C(0xffffffff));
@@ -652,73 +652,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x359, &x360, x315, UINT32_C(0xffffffff));
uint32_t x361;
fiat_p384_uint1 x362;
- fiat_p384_addcarryx_u32(&x361, &x362, 0x0, x355, x358);
+ fiat_p384_addcarryx_u32(&x361, &x362, 0x0, x358, x355);
uint32_t x363;
fiat_p384_uint1 x364;
- fiat_p384_addcarryx_u32(&x363, &x364, x362, x353, x356);
+ fiat_p384_addcarryx_u32(&x363, &x364, x362, x356, x353);
uint32_t x365;
fiat_p384_uint1 x366;
- fiat_p384_addcarryx_u32(&x365, &x366, x364, x351, x354);
+ fiat_p384_addcarryx_u32(&x365, &x366, x364, x354, x351);
uint32_t x367;
fiat_p384_uint1 x368;
- fiat_p384_addcarryx_u32(&x367, &x368, x366, x349, x352);
+ fiat_p384_addcarryx_u32(&x367, &x368, x366, x352, x349);
uint32_t x369;
fiat_p384_uint1 x370;
- fiat_p384_addcarryx_u32(&x369, &x370, x368, x347, x350);
+ fiat_p384_addcarryx_u32(&x369, &x370, x368, x350, x347);
uint32_t x371;
fiat_p384_uint1 x372;
- fiat_p384_addcarryx_u32(&x371, &x372, x370, x345, x348);
+ fiat_p384_addcarryx_u32(&x371, &x372, x370, x348, x345);
uint32_t x373;
fiat_p384_uint1 x374;
- fiat_p384_addcarryx_u32(&x373, &x374, x372, x343, x346);
+ fiat_p384_addcarryx_u32(&x373, &x374, x372, x346, x343);
uint32_t x375;
fiat_p384_uint1 x376;
- fiat_p384_addcarryx_u32(&x375, &x376, x374, x341, x344);
+ fiat_p384_addcarryx_u32(&x375, &x376, x374, x344, x341);
uint32_t x377;
fiat_p384_uint1 x378;
- fiat_p384_addcarryx_u32(&x377, &x378, x376, 0x0, x342);
+ fiat_p384_addcarryx_u32(&x377, &x378, x376, x342, 0x0);
uint32_t x379;
fiat_p384_uint1 x380;
- fiat_p384_addcarryx_u32(&x379, &x380, 0x0, x359, x315);
+ fiat_p384_addcarryx_u32(&x379, &x380, 0x0, x315, x359);
uint32_t x381;
fiat_p384_uint1 x382;
- fiat_p384_addcarryx_u32(&x381, &x382, x380, x360, x317);
+ fiat_p384_addcarryx_u32(&x381, &x382, x380, x317, x360);
uint32_t x383;
fiat_p384_uint1 x384;
- fiat_p384_addcarryx_u32(&x383, &x384, x382, 0x0, x319);
+ fiat_p384_addcarryx_u32(&x383, &x384, x382, x319, 0x0);
uint32_t x385;
fiat_p384_uint1 x386;
- fiat_p384_addcarryx_u32(&x385, &x386, x384, x357, x321);
+ fiat_p384_addcarryx_u32(&x385, &x386, x384, x321, x357);
uint32_t x387;
fiat_p384_uint1 x388;
- fiat_p384_addcarryx_u32(&x387, &x388, x386, x361, x323);
+ fiat_p384_addcarryx_u32(&x387, &x388, x386, x323, x361);
uint32_t x389;
fiat_p384_uint1 x390;
- fiat_p384_addcarryx_u32(&x389, &x390, x388, x363, x325);
+ fiat_p384_addcarryx_u32(&x389, &x390, x388, x325, x363);
uint32_t x391;
fiat_p384_uint1 x392;
- fiat_p384_addcarryx_u32(&x391, &x392, x390, x365, x327);
+ fiat_p384_addcarryx_u32(&x391, &x392, x390, x327, x365);
uint32_t x393;
fiat_p384_uint1 x394;
- fiat_p384_addcarryx_u32(&x393, &x394, x392, x367, x329);
+ fiat_p384_addcarryx_u32(&x393, &x394, x392, x329, x367);
uint32_t x395;
fiat_p384_uint1 x396;
- fiat_p384_addcarryx_u32(&x395, &x396, x394, x369, x331);
+ fiat_p384_addcarryx_u32(&x395, &x396, x394, x331, x369);
uint32_t x397;
fiat_p384_uint1 x398;
- fiat_p384_addcarryx_u32(&x397, &x398, x396, x371, x333);
+ fiat_p384_addcarryx_u32(&x397, &x398, x396, x333, x371);
uint32_t x399;
fiat_p384_uint1 x400;
- fiat_p384_addcarryx_u32(&x399, &x400, x398, x373, x335);
+ fiat_p384_addcarryx_u32(&x399, &x400, x398, x335, x373);
uint32_t x401;
fiat_p384_uint1 x402;
- fiat_p384_addcarryx_u32(&x401, &x402, x400, x375, x337);
+ fiat_p384_addcarryx_u32(&x401, &x402, x400, x337, x375);
uint32_t x403;
fiat_p384_uint1 x404;
- fiat_p384_addcarryx_u32(&x403, &x404, x402, x377, x339);
+ fiat_p384_addcarryx_u32(&x403, &x404, x402, x339, x377);
uint32_t x405;
fiat_p384_uint1 x406;
- fiat_p384_addcarryx_u32(&x405, &x406, x404, 0x0, x340);
+ fiat_p384_addcarryx_u32(&x405, &x406, x404, x340, 0x0);
uint32_t x407;
uint32_t x408;
fiat_p384_mulx_u32(&x407, &x408, x3, (arg2[11]));
@@ -757,79 +757,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x429, &x430, x3, (arg2[0]));
uint32_t x431;
fiat_p384_uint1 x432;
- fiat_p384_addcarryx_u32(&x431, &x432, 0x0, x427, x430);
+ fiat_p384_addcarryx_u32(&x431, &x432, 0x0, x430, x427);
uint32_t x433;
fiat_p384_uint1 x434;
- fiat_p384_addcarryx_u32(&x433, &x434, x432, x425, x428);
+ fiat_p384_addcarryx_u32(&x433, &x434, x432, x428, x425);
uint32_t x435;
fiat_p384_uint1 x436;
- fiat_p384_addcarryx_u32(&x435, &x436, x434, x423, x426);
+ fiat_p384_addcarryx_u32(&x435, &x436, x434, x426, x423);
uint32_t x437;
fiat_p384_uint1 x438;
- fiat_p384_addcarryx_u32(&x437, &x438, x436, x421, x424);
+ fiat_p384_addcarryx_u32(&x437, &x438, x436, x424, x421);
uint32_t x439;
fiat_p384_uint1 x440;
- fiat_p384_addcarryx_u32(&x439, &x440, x438, x419, x422);
+ fiat_p384_addcarryx_u32(&x439, &x440, x438, x422, x419);
uint32_t x441;
fiat_p384_uint1 x442;
- fiat_p384_addcarryx_u32(&x441, &x442, x440, x417, x420);
+ fiat_p384_addcarryx_u32(&x441, &x442, x440, x420, x417);
uint32_t x443;
fiat_p384_uint1 x444;
- fiat_p384_addcarryx_u32(&x443, &x444, x442, x415, x418);
+ fiat_p384_addcarryx_u32(&x443, &x444, x442, x418, x415);
uint32_t x445;
fiat_p384_uint1 x446;
- fiat_p384_addcarryx_u32(&x445, &x446, x444, x413, x416);
+ fiat_p384_addcarryx_u32(&x445, &x446, x444, x416, x413);
uint32_t x447;
fiat_p384_uint1 x448;
- fiat_p384_addcarryx_u32(&x447, &x448, x446, x411, x414);
+ fiat_p384_addcarryx_u32(&x447, &x448, x446, x414, x411);
uint32_t x449;
fiat_p384_uint1 x450;
- fiat_p384_addcarryx_u32(&x449, &x450, x448, x409, x412);
+ fiat_p384_addcarryx_u32(&x449, &x450, x448, x412, x409);
uint32_t x451;
fiat_p384_uint1 x452;
- fiat_p384_addcarryx_u32(&x451, &x452, x450, x407, x410);
+ fiat_p384_addcarryx_u32(&x451, &x452, x450, x410, x407);
uint32_t x453;
fiat_p384_uint1 x454;
- fiat_p384_addcarryx_u32(&x453, &x454, x452, 0x0, x408);
+ fiat_p384_addcarryx_u32(&x453, &x454, x452, x408, 0x0);
uint32_t x455;
fiat_p384_uint1 x456;
- fiat_p384_addcarryx_u32(&x455, &x456, 0x0, x429, x381);
+ fiat_p384_addcarryx_u32(&x455, &x456, 0x0, x381, x429);
uint32_t x457;
fiat_p384_uint1 x458;
- fiat_p384_addcarryx_u32(&x457, &x458, x456, x431, x383);
+ fiat_p384_addcarryx_u32(&x457, &x458, x456, x383, x431);
uint32_t x459;
fiat_p384_uint1 x460;
- fiat_p384_addcarryx_u32(&x459, &x460, x458, x433, x385);
+ fiat_p384_addcarryx_u32(&x459, &x460, x458, x385, x433);
uint32_t x461;
fiat_p384_uint1 x462;
- fiat_p384_addcarryx_u32(&x461, &x462, x460, x435, x387);
+ fiat_p384_addcarryx_u32(&x461, &x462, x460, x387, x435);
uint32_t x463;
fiat_p384_uint1 x464;
- fiat_p384_addcarryx_u32(&x463, &x464, x462, x437, x389);
+ fiat_p384_addcarryx_u32(&x463, &x464, x462, x389, x437);
uint32_t x465;
fiat_p384_uint1 x466;
- fiat_p384_addcarryx_u32(&x465, &x466, x464, x439, x391);
+ fiat_p384_addcarryx_u32(&x465, &x466, x464, x391, x439);
uint32_t x467;
fiat_p384_uint1 x468;
- fiat_p384_addcarryx_u32(&x467, &x468, x466, x441, x393);
+ fiat_p384_addcarryx_u32(&x467, &x468, x466, x393, x441);
uint32_t x469;
fiat_p384_uint1 x470;
- fiat_p384_addcarryx_u32(&x469, &x470, x468, x443, x395);
+ fiat_p384_addcarryx_u32(&x469, &x470, x468, x395, x443);
uint32_t x471;
fiat_p384_uint1 x472;
- fiat_p384_addcarryx_u32(&x471, &x472, x470, x445, x397);
+ fiat_p384_addcarryx_u32(&x471, &x472, x470, x397, x445);
uint32_t x473;
fiat_p384_uint1 x474;
- fiat_p384_addcarryx_u32(&x473, &x474, x472, x447, x399);
+ fiat_p384_addcarryx_u32(&x473, &x474, x472, x399, x447);
uint32_t x475;
fiat_p384_uint1 x476;
- fiat_p384_addcarryx_u32(&x475, &x476, x474, x449, x401);
+ fiat_p384_addcarryx_u32(&x475, &x476, x474, x401, x449);
uint32_t x477;
fiat_p384_uint1 x478;
- fiat_p384_addcarryx_u32(&x477, &x478, x476, x451, x403);
+ fiat_p384_addcarryx_u32(&x477, &x478, x476, x403, x451);
uint32_t x479;
fiat_p384_uint1 x480;
- fiat_p384_addcarryx_u32(&x479, &x480, x478, x453, x405);
+ fiat_p384_addcarryx_u32(&x479, &x480, x478, x405, x453);
uint32_t x481;
uint32_t x482;
fiat_p384_mulx_u32(&x481, &x482, x455, UINT32_C(0xffffffff));
@@ -862,73 +862,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x499, &x500, x455, UINT32_C(0xffffffff));
uint32_t x501;
fiat_p384_uint1 x502;
- fiat_p384_addcarryx_u32(&x501, &x502, 0x0, x495, x498);
+ fiat_p384_addcarryx_u32(&x501, &x502, 0x0, x498, x495);
uint32_t x503;
fiat_p384_uint1 x504;
- fiat_p384_addcarryx_u32(&x503, &x504, x502, x493, x496);
+ fiat_p384_addcarryx_u32(&x503, &x504, x502, x496, x493);
uint32_t x505;
fiat_p384_uint1 x506;
- fiat_p384_addcarryx_u32(&x505, &x506, x504, x491, x494);
+ fiat_p384_addcarryx_u32(&x505, &x506, x504, x494, x491);
uint32_t x507;
fiat_p384_uint1 x508;
- fiat_p384_addcarryx_u32(&x507, &x508, x506, x489, x492);
+ fiat_p384_addcarryx_u32(&x507, &x508, x506, x492, x489);
uint32_t x509;
fiat_p384_uint1 x510;
- fiat_p384_addcarryx_u32(&x509, &x510, x508, x487, x490);
+ fiat_p384_addcarryx_u32(&x509, &x510, x508, x490, x487);
uint32_t x511;
fiat_p384_uint1 x512;
- fiat_p384_addcarryx_u32(&x511, &x512, x510, x485, x488);
+ fiat_p384_addcarryx_u32(&x511, &x512, x510, x488, x485);
uint32_t x513;
fiat_p384_uint1 x514;
- fiat_p384_addcarryx_u32(&x513, &x514, x512, x483, x486);
+ fiat_p384_addcarryx_u32(&x513, &x514, x512, x486, x483);
uint32_t x515;
fiat_p384_uint1 x516;
- fiat_p384_addcarryx_u32(&x515, &x516, x514, x481, x484);
+ fiat_p384_addcarryx_u32(&x515, &x516, x514, x484, x481);
uint32_t x517;
fiat_p384_uint1 x518;
- fiat_p384_addcarryx_u32(&x517, &x518, x516, 0x0, x482);
+ fiat_p384_addcarryx_u32(&x517, &x518, x516, x482, 0x0);
uint32_t x519;
fiat_p384_uint1 x520;
- fiat_p384_addcarryx_u32(&x519, &x520, 0x0, x499, x455);
+ fiat_p384_addcarryx_u32(&x519, &x520, 0x0, x455, x499);
uint32_t x521;
fiat_p384_uint1 x522;
- fiat_p384_addcarryx_u32(&x521, &x522, x520, x500, x457);
+ fiat_p384_addcarryx_u32(&x521, &x522, x520, x457, x500);
uint32_t x523;
fiat_p384_uint1 x524;
- fiat_p384_addcarryx_u32(&x523, &x524, x522, 0x0, x459);
+ fiat_p384_addcarryx_u32(&x523, &x524, x522, x459, 0x0);
uint32_t x525;
fiat_p384_uint1 x526;
- fiat_p384_addcarryx_u32(&x525, &x526, x524, x497, x461);
+ fiat_p384_addcarryx_u32(&x525, &x526, x524, x461, x497);
uint32_t x527;
fiat_p384_uint1 x528;
- fiat_p384_addcarryx_u32(&x527, &x528, x526, x501, x463);
+ fiat_p384_addcarryx_u32(&x527, &x528, x526, x463, x501);
uint32_t x529;
fiat_p384_uint1 x530;
- fiat_p384_addcarryx_u32(&x529, &x530, x528, x503, x465);
+ fiat_p384_addcarryx_u32(&x529, &x530, x528, x465, x503);
uint32_t x531;
fiat_p384_uint1 x532;
- fiat_p384_addcarryx_u32(&x531, &x532, x530, x505, x467);
+ fiat_p384_addcarryx_u32(&x531, &x532, x530, x467, x505);
uint32_t x533;
fiat_p384_uint1 x534;
- fiat_p384_addcarryx_u32(&x533, &x534, x532, x507, x469);
+ fiat_p384_addcarryx_u32(&x533, &x534, x532, x469, x507);
uint32_t x535;
fiat_p384_uint1 x536;
- fiat_p384_addcarryx_u32(&x535, &x536, x534, x509, x471);
+ fiat_p384_addcarryx_u32(&x535, &x536, x534, x471, x509);
uint32_t x537;
fiat_p384_uint1 x538;
- fiat_p384_addcarryx_u32(&x537, &x538, x536, x511, x473);
+ fiat_p384_addcarryx_u32(&x537, &x538, x536, x473, x511);
uint32_t x539;
fiat_p384_uint1 x540;
- fiat_p384_addcarryx_u32(&x539, &x540, x538, x513, x475);
+ fiat_p384_addcarryx_u32(&x539, &x540, x538, x475, x513);
uint32_t x541;
fiat_p384_uint1 x542;
- fiat_p384_addcarryx_u32(&x541, &x542, x540, x515, x477);
+ fiat_p384_addcarryx_u32(&x541, &x542, x540, x477, x515);
uint32_t x543;
fiat_p384_uint1 x544;
- fiat_p384_addcarryx_u32(&x543, &x544, x542, x517, x479);
+ fiat_p384_addcarryx_u32(&x543, &x544, x542, x479, x517);
uint32_t x545;
fiat_p384_uint1 x546;
- fiat_p384_addcarryx_u32(&x545, &x546, x544, 0x0, x480);
+ fiat_p384_addcarryx_u32(&x545, &x546, x544, x480, 0x0);
uint32_t x547;
uint32_t x548;
fiat_p384_mulx_u32(&x547, &x548, x4, (arg2[11]));
@@ -967,79 +967,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x569, &x570, x4, (arg2[0]));
uint32_t x571;
fiat_p384_uint1 x572;
- fiat_p384_addcarryx_u32(&x571, &x572, 0x0, x567, x570);
+ fiat_p384_addcarryx_u32(&x571, &x572, 0x0, x570, x567);
uint32_t x573;
fiat_p384_uint1 x574;
- fiat_p384_addcarryx_u32(&x573, &x574, x572, x565, x568);
+ fiat_p384_addcarryx_u32(&x573, &x574, x572, x568, x565);
uint32_t x575;
fiat_p384_uint1 x576;
- fiat_p384_addcarryx_u32(&x575, &x576, x574, x563, x566);
+ fiat_p384_addcarryx_u32(&x575, &x576, x574, x566, x563);
uint32_t x577;
fiat_p384_uint1 x578;
- fiat_p384_addcarryx_u32(&x577, &x578, x576, x561, x564);
+ fiat_p384_addcarryx_u32(&x577, &x578, x576, x564, x561);
uint32_t x579;
fiat_p384_uint1 x580;
- fiat_p384_addcarryx_u32(&x579, &x580, x578, x559, x562);
+ fiat_p384_addcarryx_u32(&x579, &x580, x578, x562, x559);
uint32_t x581;
fiat_p384_uint1 x582;
- fiat_p384_addcarryx_u32(&x581, &x582, x580, x557, x560);
+ fiat_p384_addcarryx_u32(&x581, &x582, x580, x560, x557);
uint32_t x583;
fiat_p384_uint1 x584;
- fiat_p384_addcarryx_u32(&x583, &x584, x582, x555, x558);
+ fiat_p384_addcarryx_u32(&x583, &x584, x582, x558, x555);
uint32_t x585;
fiat_p384_uint1 x586;
- fiat_p384_addcarryx_u32(&x585, &x586, x584, x553, x556);
+ fiat_p384_addcarryx_u32(&x585, &x586, x584, x556, x553);
uint32_t x587;
fiat_p384_uint1 x588;
- fiat_p384_addcarryx_u32(&x587, &x588, x586, x551, x554);
+ fiat_p384_addcarryx_u32(&x587, &x588, x586, x554, x551);
uint32_t x589;
fiat_p384_uint1 x590;
- fiat_p384_addcarryx_u32(&x589, &x590, x588, x549, x552);
+ fiat_p384_addcarryx_u32(&x589, &x590, x588, x552, x549);
uint32_t x591;
fiat_p384_uint1 x592;
- fiat_p384_addcarryx_u32(&x591, &x592, x590, x547, x550);
+ fiat_p384_addcarryx_u32(&x591, &x592, x590, x550, x547);
uint32_t x593;
fiat_p384_uint1 x594;
- fiat_p384_addcarryx_u32(&x593, &x594, x592, 0x0, x548);
+ fiat_p384_addcarryx_u32(&x593, &x594, x592, x548, 0x0);
uint32_t x595;
fiat_p384_uint1 x596;
- fiat_p384_addcarryx_u32(&x595, &x596, 0x0, x569, x521);
+ fiat_p384_addcarryx_u32(&x595, &x596, 0x0, x521, x569);
uint32_t x597;
fiat_p384_uint1 x598;
- fiat_p384_addcarryx_u32(&x597, &x598, x596, x571, x523);
+ fiat_p384_addcarryx_u32(&x597, &x598, x596, x523, x571);
uint32_t x599;
fiat_p384_uint1 x600;
- fiat_p384_addcarryx_u32(&x599, &x600, x598, x573, x525);
+ fiat_p384_addcarryx_u32(&x599, &x600, x598, x525, x573);
uint32_t x601;
fiat_p384_uint1 x602;
- fiat_p384_addcarryx_u32(&x601, &x602, x600, x575, x527);
+ fiat_p384_addcarryx_u32(&x601, &x602, x600, x527, x575);
uint32_t x603;
fiat_p384_uint1 x604;
- fiat_p384_addcarryx_u32(&x603, &x604, x602, x577, x529);
+ fiat_p384_addcarryx_u32(&x603, &x604, x602, x529, x577);
uint32_t x605;
fiat_p384_uint1 x606;
- fiat_p384_addcarryx_u32(&x605, &x606, x604, x579, x531);
+ fiat_p384_addcarryx_u32(&x605, &x606, x604, x531, x579);
uint32_t x607;
fiat_p384_uint1 x608;
- fiat_p384_addcarryx_u32(&x607, &x608, x606, x581, x533);
+ fiat_p384_addcarryx_u32(&x607, &x608, x606, x533, x581);
uint32_t x609;
fiat_p384_uint1 x610;
- fiat_p384_addcarryx_u32(&x609, &x610, x608, x583, x535);
+ fiat_p384_addcarryx_u32(&x609, &x610, x608, x535, x583);
uint32_t x611;
fiat_p384_uint1 x612;
- fiat_p384_addcarryx_u32(&x611, &x612, x610, x585, x537);
+ fiat_p384_addcarryx_u32(&x611, &x612, x610, x537, x585);
uint32_t x613;
fiat_p384_uint1 x614;
- fiat_p384_addcarryx_u32(&x613, &x614, x612, x587, x539);
+ fiat_p384_addcarryx_u32(&x613, &x614, x612, x539, x587);
uint32_t x615;
fiat_p384_uint1 x616;
- fiat_p384_addcarryx_u32(&x615, &x616, x614, x589, x541);
+ fiat_p384_addcarryx_u32(&x615, &x616, x614, x541, x589);
uint32_t x617;
fiat_p384_uint1 x618;
- fiat_p384_addcarryx_u32(&x617, &x618, x616, x591, x543);
+ fiat_p384_addcarryx_u32(&x617, &x618, x616, x543, x591);
uint32_t x619;
fiat_p384_uint1 x620;
- fiat_p384_addcarryx_u32(&x619, &x620, x618, x593, x545);
+ fiat_p384_addcarryx_u32(&x619, &x620, x618, x545, x593);
uint32_t x621;
uint32_t x622;
fiat_p384_mulx_u32(&x621, &x622, x595, UINT32_C(0xffffffff));
@@ -1072,73 +1072,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x639, &x640, x595, UINT32_C(0xffffffff));
uint32_t x641;
fiat_p384_uint1 x642;
- fiat_p384_addcarryx_u32(&x641, &x642, 0x0, x635, x638);
+ fiat_p384_addcarryx_u32(&x641, &x642, 0x0, x638, x635);
uint32_t x643;
fiat_p384_uint1 x644;
- fiat_p384_addcarryx_u32(&x643, &x644, x642, x633, x636);
+ fiat_p384_addcarryx_u32(&x643, &x644, x642, x636, x633);
uint32_t x645;
fiat_p384_uint1 x646;
- fiat_p384_addcarryx_u32(&x645, &x646, x644, x631, x634);
+ fiat_p384_addcarryx_u32(&x645, &x646, x644, x634, x631);
uint32_t x647;
fiat_p384_uint1 x648;
- fiat_p384_addcarryx_u32(&x647, &x648, x646, x629, x632);
+ fiat_p384_addcarryx_u32(&x647, &x648, x646, x632, x629);
uint32_t x649;
fiat_p384_uint1 x650;
- fiat_p384_addcarryx_u32(&x649, &x650, x648, x627, x630);
+ fiat_p384_addcarryx_u32(&x649, &x650, x648, x630, x627);
uint32_t x651;
fiat_p384_uint1 x652;
- fiat_p384_addcarryx_u32(&x651, &x652, x650, x625, x628);
+ fiat_p384_addcarryx_u32(&x651, &x652, x650, x628, x625);
uint32_t x653;
fiat_p384_uint1 x654;
- fiat_p384_addcarryx_u32(&x653, &x654, x652, x623, x626);
+ fiat_p384_addcarryx_u32(&x653, &x654, x652, x626, x623);
uint32_t x655;
fiat_p384_uint1 x656;
- fiat_p384_addcarryx_u32(&x655, &x656, x654, x621, x624);
+ fiat_p384_addcarryx_u32(&x655, &x656, x654, x624, x621);
uint32_t x657;
fiat_p384_uint1 x658;
- fiat_p384_addcarryx_u32(&x657, &x658, x656, 0x0, x622);
+ fiat_p384_addcarryx_u32(&x657, &x658, x656, x622, 0x0);
uint32_t x659;
fiat_p384_uint1 x660;
- fiat_p384_addcarryx_u32(&x659, &x660, 0x0, x639, x595);
+ fiat_p384_addcarryx_u32(&x659, &x660, 0x0, x595, x639);
uint32_t x661;
fiat_p384_uint1 x662;
- fiat_p384_addcarryx_u32(&x661, &x662, x660, x640, x597);
+ fiat_p384_addcarryx_u32(&x661, &x662, x660, x597, x640);
uint32_t x663;
fiat_p384_uint1 x664;
- fiat_p384_addcarryx_u32(&x663, &x664, x662, 0x0, x599);
+ fiat_p384_addcarryx_u32(&x663, &x664, x662, x599, 0x0);
uint32_t x665;
fiat_p384_uint1 x666;
- fiat_p384_addcarryx_u32(&x665, &x666, x664, x637, x601);
+ fiat_p384_addcarryx_u32(&x665, &x666, x664, x601, x637);
uint32_t x667;
fiat_p384_uint1 x668;
- fiat_p384_addcarryx_u32(&x667, &x668, x666, x641, x603);
+ fiat_p384_addcarryx_u32(&x667, &x668, x666, x603, x641);
uint32_t x669;
fiat_p384_uint1 x670;
- fiat_p384_addcarryx_u32(&x669, &x670, x668, x643, x605);
+ fiat_p384_addcarryx_u32(&x669, &x670, x668, x605, x643);
uint32_t x671;
fiat_p384_uint1 x672;
- fiat_p384_addcarryx_u32(&x671, &x672, x670, x645, x607);
+ fiat_p384_addcarryx_u32(&x671, &x672, x670, x607, x645);
uint32_t x673;
fiat_p384_uint1 x674;
- fiat_p384_addcarryx_u32(&x673, &x674, x672, x647, x609);
+ fiat_p384_addcarryx_u32(&x673, &x674, x672, x609, x647);
uint32_t x675;
fiat_p384_uint1 x676;
- fiat_p384_addcarryx_u32(&x675, &x676, x674, x649, x611);
+ fiat_p384_addcarryx_u32(&x675, &x676, x674, x611, x649);
uint32_t x677;
fiat_p384_uint1 x678;
- fiat_p384_addcarryx_u32(&x677, &x678, x676, x651, x613);
+ fiat_p384_addcarryx_u32(&x677, &x678, x676, x613, x651);
uint32_t x679;
fiat_p384_uint1 x680;
- fiat_p384_addcarryx_u32(&x679, &x680, x678, x653, x615);
+ fiat_p384_addcarryx_u32(&x679, &x680, x678, x615, x653);
uint32_t x681;
fiat_p384_uint1 x682;
- fiat_p384_addcarryx_u32(&x681, &x682, x680, x655, x617);
+ fiat_p384_addcarryx_u32(&x681, &x682, x680, x617, x655);
uint32_t x683;
fiat_p384_uint1 x684;
- fiat_p384_addcarryx_u32(&x683, &x684, x682, x657, x619);
+ fiat_p384_addcarryx_u32(&x683, &x684, x682, x619, x657);
uint32_t x685;
fiat_p384_uint1 x686;
- fiat_p384_addcarryx_u32(&x685, &x686, x684, 0x0, x620);
+ fiat_p384_addcarryx_u32(&x685, &x686, x684, x620, 0x0);
uint32_t x687;
uint32_t x688;
fiat_p384_mulx_u32(&x687, &x688, x5, (arg2[11]));
@@ -1177,79 +1177,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x709, &x710, x5, (arg2[0]));
uint32_t x711;
fiat_p384_uint1 x712;
- fiat_p384_addcarryx_u32(&x711, &x712, 0x0, x707, x710);
+ fiat_p384_addcarryx_u32(&x711, &x712, 0x0, x710, x707);
uint32_t x713;
fiat_p384_uint1 x714;
- fiat_p384_addcarryx_u32(&x713, &x714, x712, x705, x708);
+ fiat_p384_addcarryx_u32(&x713, &x714, x712, x708, x705);
uint32_t x715;
fiat_p384_uint1 x716;
- fiat_p384_addcarryx_u32(&x715, &x716, x714, x703, x706);
+ fiat_p384_addcarryx_u32(&x715, &x716, x714, x706, x703);
uint32_t x717;
fiat_p384_uint1 x718;
- fiat_p384_addcarryx_u32(&x717, &x718, x716, x701, x704);
+ fiat_p384_addcarryx_u32(&x717, &x718, x716, x704, x701);
uint32_t x719;
fiat_p384_uint1 x720;
- fiat_p384_addcarryx_u32(&x719, &x720, x718, x699, x702);
+ fiat_p384_addcarryx_u32(&x719, &x720, x718, x702, x699);
uint32_t x721;
fiat_p384_uint1 x722;
- fiat_p384_addcarryx_u32(&x721, &x722, x720, x697, x700);
+ fiat_p384_addcarryx_u32(&x721, &x722, x720, x700, x697);
uint32_t x723;
fiat_p384_uint1 x724;
- fiat_p384_addcarryx_u32(&x723, &x724, x722, x695, x698);
+ fiat_p384_addcarryx_u32(&x723, &x724, x722, x698, x695);
uint32_t x725;
fiat_p384_uint1 x726;
- fiat_p384_addcarryx_u32(&x725, &x726, x724, x693, x696);
+ fiat_p384_addcarryx_u32(&x725, &x726, x724, x696, x693);
uint32_t x727;
fiat_p384_uint1 x728;
- fiat_p384_addcarryx_u32(&x727, &x728, x726, x691, x694);
+ fiat_p384_addcarryx_u32(&x727, &x728, x726, x694, x691);
uint32_t x729;
fiat_p384_uint1 x730;
- fiat_p384_addcarryx_u32(&x729, &x730, x728, x689, x692);
+ fiat_p384_addcarryx_u32(&x729, &x730, x728, x692, x689);
uint32_t x731;
fiat_p384_uint1 x732;
- fiat_p384_addcarryx_u32(&x731, &x732, x730, x687, x690);
+ fiat_p384_addcarryx_u32(&x731, &x732, x730, x690, x687);
uint32_t x733;
fiat_p384_uint1 x734;
- fiat_p384_addcarryx_u32(&x733, &x734, x732, 0x0, x688);
+ fiat_p384_addcarryx_u32(&x733, &x734, x732, x688, 0x0);
uint32_t x735;
fiat_p384_uint1 x736;
- fiat_p384_addcarryx_u32(&x735, &x736, 0x0, x709, x661);
+ fiat_p384_addcarryx_u32(&x735, &x736, 0x0, x661, x709);
uint32_t x737;
fiat_p384_uint1 x738;
- fiat_p384_addcarryx_u32(&x737, &x738, x736, x711, x663);
+ fiat_p384_addcarryx_u32(&x737, &x738, x736, x663, x711);
uint32_t x739;
fiat_p384_uint1 x740;
- fiat_p384_addcarryx_u32(&x739, &x740, x738, x713, x665);
+ fiat_p384_addcarryx_u32(&x739, &x740, x738, x665, x713);
uint32_t x741;
fiat_p384_uint1 x742;
- fiat_p384_addcarryx_u32(&x741, &x742, x740, x715, x667);
+ fiat_p384_addcarryx_u32(&x741, &x742, x740, x667, x715);
uint32_t x743;
fiat_p384_uint1 x744;
- fiat_p384_addcarryx_u32(&x743, &x744, x742, x717, x669);
+ fiat_p384_addcarryx_u32(&x743, &x744, x742, x669, x717);
uint32_t x745;
fiat_p384_uint1 x746;
- fiat_p384_addcarryx_u32(&x745, &x746, x744, x719, x671);
+ fiat_p384_addcarryx_u32(&x745, &x746, x744, x671, x719);
uint32_t x747;
fiat_p384_uint1 x748;
- fiat_p384_addcarryx_u32(&x747, &x748, x746, x721, x673);
+ fiat_p384_addcarryx_u32(&x747, &x748, x746, x673, x721);
uint32_t x749;
fiat_p384_uint1 x750;
- fiat_p384_addcarryx_u32(&x749, &x750, x748, x723, x675);
+ fiat_p384_addcarryx_u32(&x749, &x750, x748, x675, x723);
uint32_t x751;
fiat_p384_uint1 x752;
- fiat_p384_addcarryx_u32(&x751, &x752, x750, x725, x677);
+ fiat_p384_addcarryx_u32(&x751, &x752, x750, x677, x725);
uint32_t x753;
fiat_p384_uint1 x754;
- fiat_p384_addcarryx_u32(&x753, &x754, x752, x727, x679);
+ fiat_p384_addcarryx_u32(&x753, &x754, x752, x679, x727);
uint32_t x755;
fiat_p384_uint1 x756;
- fiat_p384_addcarryx_u32(&x755, &x756, x754, x729, x681);
+ fiat_p384_addcarryx_u32(&x755, &x756, x754, x681, x729);
uint32_t x757;
fiat_p384_uint1 x758;
- fiat_p384_addcarryx_u32(&x757, &x758, x756, x731, x683);
+ fiat_p384_addcarryx_u32(&x757, &x758, x756, x683, x731);
uint32_t x759;
fiat_p384_uint1 x760;
- fiat_p384_addcarryx_u32(&x759, &x760, x758, x733, x685);
+ fiat_p384_addcarryx_u32(&x759, &x760, x758, x685, x733);
uint32_t x761;
uint32_t x762;
fiat_p384_mulx_u32(&x761, &x762, x735, UINT32_C(0xffffffff));
@@ -1282,73 +1282,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x779, &x780, x735, UINT32_C(0xffffffff));
uint32_t x781;
fiat_p384_uint1 x782;
- fiat_p384_addcarryx_u32(&x781, &x782, 0x0, x775, x778);
+ fiat_p384_addcarryx_u32(&x781, &x782, 0x0, x778, x775);
uint32_t x783;
fiat_p384_uint1 x784;
- fiat_p384_addcarryx_u32(&x783, &x784, x782, x773, x776);
+ fiat_p384_addcarryx_u32(&x783, &x784, x782, x776, x773);
uint32_t x785;
fiat_p384_uint1 x786;
- fiat_p384_addcarryx_u32(&x785, &x786, x784, x771, x774);
+ fiat_p384_addcarryx_u32(&x785, &x786, x784, x774, x771);
uint32_t x787;
fiat_p384_uint1 x788;
- fiat_p384_addcarryx_u32(&x787, &x788, x786, x769, x772);
+ fiat_p384_addcarryx_u32(&x787, &x788, x786, x772, x769);
uint32_t x789;
fiat_p384_uint1 x790;
- fiat_p384_addcarryx_u32(&x789, &x790, x788, x767, x770);
+ fiat_p384_addcarryx_u32(&x789, &x790, x788, x770, x767);
uint32_t x791;
fiat_p384_uint1 x792;
- fiat_p384_addcarryx_u32(&x791, &x792, x790, x765, x768);
+ fiat_p384_addcarryx_u32(&x791, &x792, x790, x768, x765);
uint32_t x793;
fiat_p384_uint1 x794;
- fiat_p384_addcarryx_u32(&x793, &x794, x792, x763, x766);
+ fiat_p384_addcarryx_u32(&x793, &x794, x792, x766, x763);
uint32_t x795;
fiat_p384_uint1 x796;
- fiat_p384_addcarryx_u32(&x795, &x796, x794, x761, x764);
+ fiat_p384_addcarryx_u32(&x795, &x796, x794, x764, x761);
uint32_t x797;
fiat_p384_uint1 x798;
- fiat_p384_addcarryx_u32(&x797, &x798, x796, 0x0, x762);
+ fiat_p384_addcarryx_u32(&x797, &x798, x796, x762, 0x0);
uint32_t x799;
fiat_p384_uint1 x800;
- fiat_p384_addcarryx_u32(&x799, &x800, 0x0, x779, x735);
+ fiat_p384_addcarryx_u32(&x799, &x800, 0x0, x735, x779);
uint32_t x801;
fiat_p384_uint1 x802;
- fiat_p384_addcarryx_u32(&x801, &x802, x800, x780, x737);
+ fiat_p384_addcarryx_u32(&x801, &x802, x800, x737, x780);
uint32_t x803;
fiat_p384_uint1 x804;
- fiat_p384_addcarryx_u32(&x803, &x804, x802, 0x0, x739);
+ fiat_p384_addcarryx_u32(&x803, &x804, x802, x739, 0x0);
uint32_t x805;
fiat_p384_uint1 x806;
- fiat_p384_addcarryx_u32(&x805, &x806, x804, x777, x741);
+ fiat_p384_addcarryx_u32(&x805, &x806, x804, x741, x777);
uint32_t x807;
fiat_p384_uint1 x808;
- fiat_p384_addcarryx_u32(&x807, &x808, x806, x781, x743);
+ fiat_p384_addcarryx_u32(&x807, &x808, x806, x743, x781);
uint32_t x809;
fiat_p384_uint1 x810;
- fiat_p384_addcarryx_u32(&x809, &x810, x808, x783, x745);
+ fiat_p384_addcarryx_u32(&x809, &x810, x808, x745, x783);
uint32_t x811;
fiat_p384_uint1 x812;
- fiat_p384_addcarryx_u32(&x811, &x812, x810, x785, x747);
+ fiat_p384_addcarryx_u32(&x811, &x812, x810, x747, x785);
uint32_t x813;
fiat_p384_uint1 x814;
- fiat_p384_addcarryx_u32(&x813, &x814, x812, x787, x749);
+ fiat_p384_addcarryx_u32(&x813, &x814, x812, x749, x787);
uint32_t x815;
fiat_p384_uint1 x816;
- fiat_p384_addcarryx_u32(&x815, &x816, x814, x789, x751);
+ fiat_p384_addcarryx_u32(&x815, &x816, x814, x751, x789);
uint32_t x817;
fiat_p384_uint1 x818;
- fiat_p384_addcarryx_u32(&x817, &x818, x816, x791, x753);
+ fiat_p384_addcarryx_u32(&x817, &x818, x816, x753, x791);
uint32_t x819;
fiat_p384_uint1 x820;
- fiat_p384_addcarryx_u32(&x819, &x820, x818, x793, x755);
+ fiat_p384_addcarryx_u32(&x819, &x820, x818, x755, x793);
uint32_t x821;
fiat_p384_uint1 x822;
- fiat_p384_addcarryx_u32(&x821, &x822, x820, x795, x757);
+ fiat_p384_addcarryx_u32(&x821, &x822, x820, x757, x795);
uint32_t x823;
fiat_p384_uint1 x824;
- fiat_p384_addcarryx_u32(&x823, &x824, x822, x797, x759);
+ fiat_p384_addcarryx_u32(&x823, &x824, x822, x759, x797);
uint32_t x825;
fiat_p384_uint1 x826;
- fiat_p384_addcarryx_u32(&x825, &x826, x824, 0x0, x760);
+ fiat_p384_addcarryx_u32(&x825, &x826, x824, x760, 0x0);
uint32_t x827;
uint32_t x828;
fiat_p384_mulx_u32(&x827, &x828, x6, (arg2[11]));
@@ -1387,79 +1387,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x849, &x850, x6, (arg2[0]));
uint32_t x851;
fiat_p384_uint1 x852;
- fiat_p384_addcarryx_u32(&x851, &x852, 0x0, x847, x850);
+ fiat_p384_addcarryx_u32(&x851, &x852, 0x0, x850, x847);
uint32_t x853;
fiat_p384_uint1 x854;
- fiat_p384_addcarryx_u32(&x853, &x854, x852, x845, x848);
+ fiat_p384_addcarryx_u32(&x853, &x854, x852, x848, x845);
uint32_t x855;
fiat_p384_uint1 x856;
- fiat_p384_addcarryx_u32(&x855, &x856, x854, x843, x846);
+ fiat_p384_addcarryx_u32(&x855, &x856, x854, x846, x843);
uint32_t x857;
fiat_p384_uint1 x858;
- fiat_p384_addcarryx_u32(&x857, &x858, x856, x841, x844);
+ fiat_p384_addcarryx_u32(&x857, &x858, x856, x844, x841);
uint32_t x859;
fiat_p384_uint1 x860;
- fiat_p384_addcarryx_u32(&x859, &x860, x858, x839, x842);
+ fiat_p384_addcarryx_u32(&x859, &x860, x858, x842, x839);
uint32_t x861;
fiat_p384_uint1 x862;
- fiat_p384_addcarryx_u32(&x861, &x862, x860, x837, x840);
+ fiat_p384_addcarryx_u32(&x861, &x862, x860, x840, x837);
uint32_t x863;
fiat_p384_uint1 x864;
- fiat_p384_addcarryx_u32(&x863, &x864, x862, x835, x838);
+ fiat_p384_addcarryx_u32(&x863, &x864, x862, x838, x835);
uint32_t x865;
fiat_p384_uint1 x866;
- fiat_p384_addcarryx_u32(&x865, &x866, x864, x833, x836);
+ fiat_p384_addcarryx_u32(&x865, &x866, x864, x836, x833);
uint32_t x867;
fiat_p384_uint1 x868;
- fiat_p384_addcarryx_u32(&x867, &x868, x866, x831, x834);
+ fiat_p384_addcarryx_u32(&x867, &x868, x866, x834, x831);
uint32_t x869;
fiat_p384_uint1 x870;
- fiat_p384_addcarryx_u32(&x869, &x870, x868, x829, x832);
+ fiat_p384_addcarryx_u32(&x869, &x870, x868, x832, x829);
uint32_t x871;
fiat_p384_uint1 x872;
- fiat_p384_addcarryx_u32(&x871, &x872, x870, x827, x830);
+ fiat_p384_addcarryx_u32(&x871, &x872, x870, x830, x827);
uint32_t x873;
fiat_p384_uint1 x874;
- fiat_p384_addcarryx_u32(&x873, &x874, x872, 0x0, x828);
+ fiat_p384_addcarryx_u32(&x873, &x874, x872, x828, 0x0);
uint32_t x875;
fiat_p384_uint1 x876;
- fiat_p384_addcarryx_u32(&x875, &x876, 0x0, x849, x801);
+ fiat_p384_addcarryx_u32(&x875, &x876, 0x0, x801, x849);
uint32_t x877;
fiat_p384_uint1 x878;
- fiat_p384_addcarryx_u32(&x877, &x878, x876, x851, x803);
+ fiat_p384_addcarryx_u32(&x877, &x878, x876, x803, x851);
uint32_t x879;
fiat_p384_uint1 x880;
- fiat_p384_addcarryx_u32(&x879, &x880, x878, x853, x805);
+ fiat_p384_addcarryx_u32(&x879, &x880, x878, x805, x853);
uint32_t x881;
fiat_p384_uint1 x882;
- fiat_p384_addcarryx_u32(&x881, &x882, x880, x855, x807);
+ fiat_p384_addcarryx_u32(&x881, &x882, x880, x807, x855);
uint32_t x883;
fiat_p384_uint1 x884;
- fiat_p384_addcarryx_u32(&x883, &x884, x882, x857, x809);
+ fiat_p384_addcarryx_u32(&x883, &x884, x882, x809, x857);
uint32_t x885;
fiat_p384_uint1 x886;
- fiat_p384_addcarryx_u32(&x885, &x886, x884, x859, x811);
+ fiat_p384_addcarryx_u32(&x885, &x886, x884, x811, x859);
uint32_t x887;
fiat_p384_uint1 x888;
- fiat_p384_addcarryx_u32(&x887, &x888, x886, x861, x813);
+ fiat_p384_addcarryx_u32(&x887, &x888, x886, x813, x861);
uint32_t x889;
fiat_p384_uint1 x890;
- fiat_p384_addcarryx_u32(&x889, &x890, x888, x863, x815);
+ fiat_p384_addcarryx_u32(&x889, &x890, x888, x815, x863);
uint32_t x891;
fiat_p384_uint1 x892;
- fiat_p384_addcarryx_u32(&x891, &x892, x890, x865, x817);
+ fiat_p384_addcarryx_u32(&x891, &x892, x890, x817, x865);
uint32_t x893;
fiat_p384_uint1 x894;
- fiat_p384_addcarryx_u32(&x893, &x894, x892, x867, x819);
+ fiat_p384_addcarryx_u32(&x893, &x894, x892, x819, x867);
uint32_t x895;
fiat_p384_uint1 x896;
- fiat_p384_addcarryx_u32(&x895, &x896, x894, x869, x821);
+ fiat_p384_addcarryx_u32(&x895, &x896, x894, x821, x869);
uint32_t x897;
fiat_p384_uint1 x898;
- fiat_p384_addcarryx_u32(&x897, &x898, x896, x871, x823);
+ fiat_p384_addcarryx_u32(&x897, &x898, x896, x823, x871);
uint32_t x899;
fiat_p384_uint1 x900;
- fiat_p384_addcarryx_u32(&x899, &x900, x898, x873, x825);
+ fiat_p384_addcarryx_u32(&x899, &x900, x898, x825, x873);
uint32_t x901;
uint32_t x902;
fiat_p384_mulx_u32(&x901, &x902, x875, UINT32_C(0xffffffff));
@@ -1492,73 +1492,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x919, &x920, x875, UINT32_C(0xffffffff));
uint32_t x921;
fiat_p384_uint1 x922;
- fiat_p384_addcarryx_u32(&x921, &x922, 0x0, x915, x918);
+ fiat_p384_addcarryx_u32(&x921, &x922, 0x0, x918, x915);
uint32_t x923;
fiat_p384_uint1 x924;
- fiat_p384_addcarryx_u32(&x923, &x924, x922, x913, x916);
+ fiat_p384_addcarryx_u32(&x923, &x924, x922, x916, x913);
uint32_t x925;
fiat_p384_uint1 x926;
- fiat_p384_addcarryx_u32(&x925, &x926, x924, x911, x914);
+ fiat_p384_addcarryx_u32(&x925, &x926, x924, x914, x911);
uint32_t x927;
fiat_p384_uint1 x928;
- fiat_p384_addcarryx_u32(&x927, &x928, x926, x909, x912);
+ fiat_p384_addcarryx_u32(&x927, &x928, x926, x912, x909);
uint32_t x929;
fiat_p384_uint1 x930;
- fiat_p384_addcarryx_u32(&x929, &x930, x928, x907, x910);
+ fiat_p384_addcarryx_u32(&x929, &x930, x928, x910, x907);
uint32_t x931;
fiat_p384_uint1 x932;
- fiat_p384_addcarryx_u32(&x931, &x932, x930, x905, x908);
+ fiat_p384_addcarryx_u32(&x931, &x932, x930, x908, x905);
uint32_t x933;
fiat_p384_uint1 x934;
- fiat_p384_addcarryx_u32(&x933, &x934, x932, x903, x906);
+ fiat_p384_addcarryx_u32(&x933, &x934, x932, x906, x903);
uint32_t x935;
fiat_p384_uint1 x936;
- fiat_p384_addcarryx_u32(&x935, &x936, x934, x901, x904);
+ fiat_p384_addcarryx_u32(&x935, &x936, x934, x904, x901);
uint32_t x937;
fiat_p384_uint1 x938;
- fiat_p384_addcarryx_u32(&x937, &x938, x936, 0x0, x902);
+ fiat_p384_addcarryx_u32(&x937, &x938, x936, x902, 0x0);
uint32_t x939;
fiat_p384_uint1 x940;
- fiat_p384_addcarryx_u32(&x939, &x940, 0x0, x919, x875);
+ fiat_p384_addcarryx_u32(&x939, &x940, 0x0, x875, x919);
uint32_t x941;
fiat_p384_uint1 x942;
- fiat_p384_addcarryx_u32(&x941, &x942, x940, x920, x877);
+ fiat_p384_addcarryx_u32(&x941, &x942, x940, x877, x920);
uint32_t x943;
fiat_p384_uint1 x944;
- fiat_p384_addcarryx_u32(&x943, &x944, x942, 0x0, x879);
+ fiat_p384_addcarryx_u32(&x943, &x944, x942, x879, 0x0);
uint32_t x945;
fiat_p384_uint1 x946;
- fiat_p384_addcarryx_u32(&x945, &x946, x944, x917, x881);
+ fiat_p384_addcarryx_u32(&x945, &x946, x944, x881, x917);
uint32_t x947;
fiat_p384_uint1 x948;
- fiat_p384_addcarryx_u32(&x947, &x948, x946, x921, x883);
+ fiat_p384_addcarryx_u32(&x947, &x948, x946, x883, x921);
uint32_t x949;
fiat_p384_uint1 x950;
- fiat_p384_addcarryx_u32(&x949, &x950, x948, x923, x885);
+ fiat_p384_addcarryx_u32(&x949, &x950, x948, x885, x923);
uint32_t x951;
fiat_p384_uint1 x952;
- fiat_p384_addcarryx_u32(&x951, &x952, x950, x925, x887);
+ fiat_p384_addcarryx_u32(&x951, &x952, x950, x887, x925);
uint32_t x953;
fiat_p384_uint1 x954;
- fiat_p384_addcarryx_u32(&x953, &x954, x952, x927, x889);
+ fiat_p384_addcarryx_u32(&x953, &x954, x952, x889, x927);
uint32_t x955;
fiat_p384_uint1 x956;
- fiat_p384_addcarryx_u32(&x955, &x956, x954, x929, x891);
+ fiat_p384_addcarryx_u32(&x955, &x956, x954, x891, x929);
uint32_t x957;
fiat_p384_uint1 x958;
- fiat_p384_addcarryx_u32(&x957, &x958, x956, x931, x893);
+ fiat_p384_addcarryx_u32(&x957, &x958, x956, x893, x931);
uint32_t x959;
fiat_p384_uint1 x960;
- fiat_p384_addcarryx_u32(&x959, &x960, x958, x933, x895);
+ fiat_p384_addcarryx_u32(&x959, &x960, x958, x895, x933);
uint32_t x961;
fiat_p384_uint1 x962;
- fiat_p384_addcarryx_u32(&x961, &x962, x960, x935, x897);
+ fiat_p384_addcarryx_u32(&x961, &x962, x960, x897, x935);
uint32_t x963;
fiat_p384_uint1 x964;
- fiat_p384_addcarryx_u32(&x963, &x964, x962, x937, x899);
+ fiat_p384_addcarryx_u32(&x963, &x964, x962, x899, x937);
uint32_t x965;
fiat_p384_uint1 x966;
- fiat_p384_addcarryx_u32(&x965, &x966, x964, 0x0, x900);
+ fiat_p384_addcarryx_u32(&x965, &x966, x964, x900, 0x0);
uint32_t x967;
uint32_t x968;
fiat_p384_mulx_u32(&x967, &x968, x7, (arg2[11]));
@@ -1597,79 +1597,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x989, &x990, x7, (arg2[0]));
uint32_t x991;
fiat_p384_uint1 x992;
- fiat_p384_addcarryx_u32(&x991, &x992, 0x0, x987, x990);
+ fiat_p384_addcarryx_u32(&x991, &x992, 0x0, x990, x987);
uint32_t x993;
fiat_p384_uint1 x994;
- fiat_p384_addcarryx_u32(&x993, &x994, x992, x985, x988);
+ fiat_p384_addcarryx_u32(&x993, &x994, x992, x988, x985);
uint32_t x995;
fiat_p384_uint1 x996;
- fiat_p384_addcarryx_u32(&x995, &x996, x994, x983, x986);
+ fiat_p384_addcarryx_u32(&x995, &x996, x994, x986, x983);
uint32_t x997;
fiat_p384_uint1 x998;
- fiat_p384_addcarryx_u32(&x997, &x998, x996, x981, x984);
+ fiat_p384_addcarryx_u32(&x997, &x998, x996, x984, x981);
uint32_t x999;
fiat_p384_uint1 x1000;
- fiat_p384_addcarryx_u32(&x999, &x1000, x998, x979, x982);
+ fiat_p384_addcarryx_u32(&x999, &x1000, x998, x982, x979);
uint32_t x1001;
fiat_p384_uint1 x1002;
- fiat_p384_addcarryx_u32(&x1001, &x1002, x1000, x977, x980);
+ fiat_p384_addcarryx_u32(&x1001, &x1002, x1000, x980, x977);
uint32_t x1003;
fiat_p384_uint1 x1004;
- fiat_p384_addcarryx_u32(&x1003, &x1004, x1002, x975, x978);
+ fiat_p384_addcarryx_u32(&x1003, &x1004, x1002, x978, x975);
uint32_t x1005;
fiat_p384_uint1 x1006;
- fiat_p384_addcarryx_u32(&x1005, &x1006, x1004, x973, x976);
+ fiat_p384_addcarryx_u32(&x1005, &x1006, x1004, x976, x973);
uint32_t x1007;
fiat_p384_uint1 x1008;
- fiat_p384_addcarryx_u32(&x1007, &x1008, x1006, x971, x974);
+ fiat_p384_addcarryx_u32(&x1007, &x1008, x1006, x974, x971);
uint32_t x1009;
fiat_p384_uint1 x1010;
- fiat_p384_addcarryx_u32(&x1009, &x1010, x1008, x969, x972);
+ fiat_p384_addcarryx_u32(&x1009, &x1010, x1008, x972, x969);
uint32_t x1011;
fiat_p384_uint1 x1012;
- fiat_p384_addcarryx_u32(&x1011, &x1012, x1010, x967, x970);
+ fiat_p384_addcarryx_u32(&x1011, &x1012, x1010, x970, x967);
uint32_t x1013;
fiat_p384_uint1 x1014;
- fiat_p384_addcarryx_u32(&x1013, &x1014, x1012, 0x0, x968);
+ fiat_p384_addcarryx_u32(&x1013, &x1014, x1012, x968, 0x0);
uint32_t x1015;
fiat_p384_uint1 x1016;
- fiat_p384_addcarryx_u32(&x1015, &x1016, 0x0, x989, x941);
+ fiat_p384_addcarryx_u32(&x1015, &x1016, 0x0, x941, x989);
uint32_t x1017;
fiat_p384_uint1 x1018;
- fiat_p384_addcarryx_u32(&x1017, &x1018, x1016, x991, x943);
+ fiat_p384_addcarryx_u32(&x1017, &x1018, x1016, x943, x991);
uint32_t x1019;
fiat_p384_uint1 x1020;
- fiat_p384_addcarryx_u32(&x1019, &x1020, x1018, x993, x945);
+ fiat_p384_addcarryx_u32(&x1019, &x1020, x1018, x945, x993);
uint32_t x1021;
fiat_p384_uint1 x1022;
- fiat_p384_addcarryx_u32(&x1021, &x1022, x1020, x995, x947);
+ fiat_p384_addcarryx_u32(&x1021, &x1022, x1020, x947, x995);
uint32_t x1023;
fiat_p384_uint1 x1024;
- fiat_p384_addcarryx_u32(&x1023, &x1024, x1022, x997, x949);
+ fiat_p384_addcarryx_u32(&x1023, &x1024, x1022, x949, x997);
uint32_t x1025;
fiat_p384_uint1 x1026;
- fiat_p384_addcarryx_u32(&x1025, &x1026, x1024, x999, x951);
+ fiat_p384_addcarryx_u32(&x1025, &x1026, x1024, x951, x999);
uint32_t x1027;
fiat_p384_uint1 x1028;
- fiat_p384_addcarryx_u32(&x1027, &x1028, x1026, x1001, x953);
+ fiat_p384_addcarryx_u32(&x1027, &x1028, x1026, x953, x1001);
uint32_t x1029;
fiat_p384_uint1 x1030;
- fiat_p384_addcarryx_u32(&x1029, &x1030, x1028, x1003, x955);
+ fiat_p384_addcarryx_u32(&x1029, &x1030, x1028, x955, x1003);
uint32_t x1031;
fiat_p384_uint1 x1032;
- fiat_p384_addcarryx_u32(&x1031, &x1032, x1030, x1005, x957);
+ fiat_p384_addcarryx_u32(&x1031, &x1032, x1030, x957, x1005);
uint32_t x1033;
fiat_p384_uint1 x1034;
- fiat_p384_addcarryx_u32(&x1033, &x1034, x1032, x1007, x959);
+ fiat_p384_addcarryx_u32(&x1033, &x1034, x1032, x959, x1007);
uint32_t x1035;
fiat_p384_uint1 x1036;
- fiat_p384_addcarryx_u32(&x1035, &x1036, x1034, x1009, x961);
+ fiat_p384_addcarryx_u32(&x1035, &x1036, x1034, x961, x1009);
uint32_t x1037;
fiat_p384_uint1 x1038;
- fiat_p384_addcarryx_u32(&x1037, &x1038, x1036, x1011, x963);
+ fiat_p384_addcarryx_u32(&x1037, &x1038, x1036, x963, x1011);
uint32_t x1039;
fiat_p384_uint1 x1040;
- fiat_p384_addcarryx_u32(&x1039, &x1040, x1038, x1013, x965);
+ fiat_p384_addcarryx_u32(&x1039, &x1040, x1038, x965, x1013);
uint32_t x1041;
uint32_t x1042;
fiat_p384_mulx_u32(&x1041, &x1042, x1015, UINT32_C(0xffffffff));
@@ -1702,73 +1702,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1059, &x1060, x1015, UINT32_C(0xffffffff));
uint32_t x1061;
fiat_p384_uint1 x1062;
- fiat_p384_addcarryx_u32(&x1061, &x1062, 0x0, x1055, x1058);
+ fiat_p384_addcarryx_u32(&x1061, &x1062, 0x0, x1058, x1055);
uint32_t x1063;
fiat_p384_uint1 x1064;
- fiat_p384_addcarryx_u32(&x1063, &x1064, x1062, x1053, x1056);
+ fiat_p384_addcarryx_u32(&x1063, &x1064, x1062, x1056, x1053);
uint32_t x1065;
fiat_p384_uint1 x1066;
- fiat_p384_addcarryx_u32(&x1065, &x1066, x1064, x1051, x1054);
+ fiat_p384_addcarryx_u32(&x1065, &x1066, x1064, x1054, x1051);
uint32_t x1067;
fiat_p384_uint1 x1068;
- fiat_p384_addcarryx_u32(&x1067, &x1068, x1066, x1049, x1052);
+ fiat_p384_addcarryx_u32(&x1067, &x1068, x1066, x1052, x1049);
uint32_t x1069;
fiat_p384_uint1 x1070;
- fiat_p384_addcarryx_u32(&x1069, &x1070, x1068, x1047, x1050);
+ fiat_p384_addcarryx_u32(&x1069, &x1070, x1068, x1050, x1047);
uint32_t x1071;
fiat_p384_uint1 x1072;
- fiat_p384_addcarryx_u32(&x1071, &x1072, x1070, x1045, x1048);
+ fiat_p384_addcarryx_u32(&x1071, &x1072, x1070, x1048, x1045);
uint32_t x1073;
fiat_p384_uint1 x1074;
- fiat_p384_addcarryx_u32(&x1073, &x1074, x1072, x1043, x1046);
+ fiat_p384_addcarryx_u32(&x1073, &x1074, x1072, x1046, x1043);
uint32_t x1075;
fiat_p384_uint1 x1076;
- fiat_p384_addcarryx_u32(&x1075, &x1076, x1074, x1041, x1044);
+ fiat_p384_addcarryx_u32(&x1075, &x1076, x1074, x1044, x1041);
uint32_t x1077;
fiat_p384_uint1 x1078;
- fiat_p384_addcarryx_u32(&x1077, &x1078, x1076, 0x0, x1042);
+ fiat_p384_addcarryx_u32(&x1077, &x1078, x1076, x1042, 0x0);
uint32_t x1079;
fiat_p384_uint1 x1080;
- fiat_p384_addcarryx_u32(&x1079, &x1080, 0x0, x1059, x1015);
+ fiat_p384_addcarryx_u32(&x1079, &x1080, 0x0, x1015, x1059);
uint32_t x1081;
fiat_p384_uint1 x1082;
- fiat_p384_addcarryx_u32(&x1081, &x1082, x1080, x1060, x1017);
+ fiat_p384_addcarryx_u32(&x1081, &x1082, x1080, x1017, x1060);
uint32_t x1083;
fiat_p384_uint1 x1084;
- fiat_p384_addcarryx_u32(&x1083, &x1084, x1082, 0x0, x1019);
+ fiat_p384_addcarryx_u32(&x1083, &x1084, x1082, x1019, 0x0);
uint32_t x1085;
fiat_p384_uint1 x1086;
- fiat_p384_addcarryx_u32(&x1085, &x1086, x1084, x1057, x1021);
+ fiat_p384_addcarryx_u32(&x1085, &x1086, x1084, x1021, x1057);
uint32_t x1087;
fiat_p384_uint1 x1088;
- fiat_p384_addcarryx_u32(&x1087, &x1088, x1086, x1061, x1023);
+ fiat_p384_addcarryx_u32(&x1087, &x1088, x1086, x1023, x1061);
uint32_t x1089;
fiat_p384_uint1 x1090;
- fiat_p384_addcarryx_u32(&x1089, &x1090, x1088, x1063, x1025);
+ fiat_p384_addcarryx_u32(&x1089, &x1090, x1088, x1025, x1063);
uint32_t x1091;
fiat_p384_uint1 x1092;
- fiat_p384_addcarryx_u32(&x1091, &x1092, x1090, x1065, x1027);
+ fiat_p384_addcarryx_u32(&x1091, &x1092, x1090, x1027, x1065);
uint32_t x1093;
fiat_p384_uint1 x1094;
- fiat_p384_addcarryx_u32(&x1093, &x1094, x1092, x1067, x1029);
+ fiat_p384_addcarryx_u32(&x1093, &x1094, x1092, x1029, x1067);
uint32_t x1095;
fiat_p384_uint1 x1096;
- fiat_p384_addcarryx_u32(&x1095, &x1096, x1094, x1069, x1031);
+ fiat_p384_addcarryx_u32(&x1095, &x1096, x1094, x1031, x1069);
uint32_t x1097;
fiat_p384_uint1 x1098;
- fiat_p384_addcarryx_u32(&x1097, &x1098, x1096, x1071, x1033);
+ fiat_p384_addcarryx_u32(&x1097, &x1098, x1096, x1033, x1071);
uint32_t x1099;
fiat_p384_uint1 x1100;
- fiat_p384_addcarryx_u32(&x1099, &x1100, x1098, x1073, x1035);
+ fiat_p384_addcarryx_u32(&x1099, &x1100, x1098, x1035, x1073);
uint32_t x1101;
fiat_p384_uint1 x1102;
- fiat_p384_addcarryx_u32(&x1101, &x1102, x1100, x1075, x1037);
+ fiat_p384_addcarryx_u32(&x1101, &x1102, x1100, x1037, x1075);
uint32_t x1103;
fiat_p384_uint1 x1104;
- fiat_p384_addcarryx_u32(&x1103, &x1104, x1102, x1077, x1039);
+ fiat_p384_addcarryx_u32(&x1103, &x1104, x1102, x1039, x1077);
uint32_t x1105;
fiat_p384_uint1 x1106;
- fiat_p384_addcarryx_u32(&x1105, &x1106, x1104, 0x0, x1040);
+ fiat_p384_addcarryx_u32(&x1105, &x1106, x1104, x1040, 0x0);
uint32_t x1107;
uint32_t x1108;
fiat_p384_mulx_u32(&x1107, &x1108, x8, (arg2[11]));
@@ -1807,79 +1807,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1129, &x1130, x8, (arg2[0]));
uint32_t x1131;
fiat_p384_uint1 x1132;
- fiat_p384_addcarryx_u32(&x1131, &x1132, 0x0, x1127, x1130);
+ fiat_p384_addcarryx_u32(&x1131, &x1132, 0x0, x1130, x1127);
uint32_t x1133;
fiat_p384_uint1 x1134;
- fiat_p384_addcarryx_u32(&x1133, &x1134, x1132, x1125, x1128);
+ fiat_p384_addcarryx_u32(&x1133, &x1134, x1132, x1128, x1125);
uint32_t x1135;
fiat_p384_uint1 x1136;
- fiat_p384_addcarryx_u32(&x1135, &x1136, x1134, x1123, x1126);
+ fiat_p384_addcarryx_u32(&x1135, &x1136, x1134, x1126, x1123);
uint32_t x1137;
fiat_p384_uint1 x1138;
- fiat_p384_addcarryx_u32(&x1137, &x1138, x1136, x1121, x1124);
+ fiat_p384_addcarryx_u32(&x1137, &x1138, x1136, x1124, x1121);
uint32_t x1139;
fiat_p384_uint1 x1140;
- fiat_p384_addcarryx_u32(&x1139, &x1140, x1138, x1119, x1122);
+ fiat_p384_addcarryx_u32(&x1139, &x1140, x1138, x1122, x1119);
uint32_t x1141;
fiat_p384_uint1 x1142;
- fiat_p384_addcarryx_u32(&x1141, &x1142, x1140, x1117, x1120);
+ fiat_p384_addcarryx_u32(&x1141, &x1142, x1140, x1120, x1117);
uint32_t x1143;
fiat_p384_uint1 x1144;
- fiat_p384_addcarryx_u32(&x1143, &x1144, x1142, x1115, x1118);
+ fiat_p384_addcarryx_u32(&x1143, &x1144, x1142, x1118, x1115);
uint32_t x1145;
fiat_p384_uint1 x1146;
- fiat_p384_addcarryx_u32(&x1145, &x1146, x1144, x1113, x1116);
+ fiat_p384_addcarryx_u32(&x1145, &x1146, x1144, x1116, x1113);
uint32_t x1147;
fiat_p384_uint1 x1148;
- fiat_p384_addcarryx_u32(&x1147, &x1148, x1146, x1111, x1114);
+ fiat_p384_addcarryx_u32(&x1147, &x1148, x1146, x1114, x1111);
uint32_t x1149;
fiat_p384_uint1 x1150;
- fiat_p384_addcarryx_u32(&x1149, &x1150, x1148, x1109, x1112);
+ fiat_p384_addcarryx_u32(&x1149, &x1150, x1148, x1112, x1109);
uint32_t x1151;
fiat_p384_uint1 x1152;
- fiat_p384_addcarryx_u32(&x1151, &x1152, x1150, x1107, x1110);
+ fiat_p384_addcarryx_u32(&x1151, &x1152, x1150, x1110, x1107);
uint32_t x1153;
fiat_p384_uint1 x1154;
- fiat_p384_addcarryx_u32(&x1153, &x1154, x1152, 0x0, x1108);
+ fiat_p384_addcarryx_u32(&x1153, &x1154, x1152, x1108, 0x0);
uint32_t x1155;
fiat_p384_uint1 x1156;
- fiat_p384_addcarryx_u32(&x1155, &x1156, 0x0, x1129, x1081);
+ fiat_p384_addcarryx_u32(&x1155, &x1156, 0x0, x1081, x1129);
uint32_t x1157;
fiat_p384_uint1 x1158;
- fiat_p384_addcarryx_u32(&x1157, &x1158, x1156, x1131, x1083);
+ fiat_p384_addcarryx_u32(&x1157, &x1158, x1156, x1083, x1131);
uint32_t x1159;
fiat_p384_uint1 x1160;
- fiat_p384_addcarryx_u32(&x1159, &x1160, x1158, x1133, x1085);
+ fiat_p384_addcarryx_u32(&x1159, &x1160, x1158, x1085, x1133);
uint32_t x1161;
fiat_p384_uint1 x1162;
- fiat_p384_addcarryx_u32(&x1161, &x1162, x1160, x1135, x1087);
+ fiat_p384_addcarryx_u32(&x1161, &x1162, x1160, x1087, x1135);
uint32_t x1163;
fiat_p384_uint1 x1164;
- fiat_p384_addcarryx_u32(&x1163, &x1164, x1162, x1137, x1089);
+ fiat_p384_addcarryx_u32(&x1163, &x1164, x1162, x1089, x1137);
uint32_t x1165;
fiat_p384_uint1 x1166;
- fiat_p384_addcarryx_u32(&x1165, &x1166, x1164, x1139, x1091);
+ fiat_p384_addcarryx_u32(&x1165, &x1166, x1164, x1091, x1139);
uint32_t x1167;
fiat_p384_uint1 x1168;
- fiat_p384_addcarryx_u32(&x1167, &x1168, x1166, x1141, x1093);
+ fiat_p384_addcarryx_u32(&x1167, &x1168, x1166, x1093, x1141);
uint32_t x1169;
fiat_p384_uint1 x1170;
- fiat_p384_addcarryx_u32(&x1169, &x1170, x1168, x1143, x1095);
+ fiat_p384_addcarryx_u32(&x1169, &x1170, x1168, x1095, x1143);
uint32_t x1171;
fiat_p384_uint1 x1172;
- fiat_p384_addcarryx_u32(&x1171, &x1172, x1170, x1145, x1097);
+ fiat_p384_addcarryx_u32(&x1171, &x1172, x1170, x1097, x1145);
uint32_t x1173;
fiat_p384_uint1 x1174;
- fiat_p384_addcarryx_u32(&x1173, &x1174, x1172, x1147, x1099);
+ fiat_p384_addcarryx_u32(&x1173, &x1174, x1172, x1099, x1147);
uint32_t x1175;
fiat_p384_uint1 x1176;
- fiat_p384_addcarryx_u32(&x1175, &x1176, x1174, x1149, x1101);
+ fiat_p384_addcarryx_u32(&x1175, &x1176, x1174, x1101, x1149);
uint32_t x1177;
fiat_p384_uint1 x1178;
- fiat_p384_addcarryx_u32(&x1177, &x1178, x1176, x1151, x1103);
+ fiat_p384_addcarryx_u32(&x1177, &x1178, x1176, x1103, x1151);
uint32_t x1179;
fiat_p384_uint1 x1180;
- fiat_p384_addcarryx_u32(&x1179, &x1180, x1178, x1153, x1105);
+ fiat_p384_addcarryx_u32(&x1179, &x1180, x1178, x1105, x1153);
uint32_t x1181;
uint32_t x1182;
fiat_p384_mulx_u32(&x1181, &x1182, x1155, UINT32_C(0xffffffff));
@@ -1912,73 +1912,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1199, &x1200, x1155, UINT32_C(0xffffffff));
uint32_t x1201;
fiat_p384_uint1 x1202;
- fiat_p384_addcarryx_u32(&x1201, &x1202, 0x0, x1195, x1198);
+ fiat_p384_addcarryx_u32(&x1201, &x1202, 0x0, x1198, x1195);
uint32_t x1203;
fiat_p384_uint1 x1204;
- fiat_p384_addcarryx_u32(&x1203, &x1204, x1202, x1193, x1196);
+ fiat_p384_addcarryx_u32(&x1203, &x1204, x1202, x1196, x1193);
uint32_t x1205;
fiat_p384_uint1 x1206;
- fiat_p384_addcarryx_u32(&x1205, &x1206, x1204, x1191, x1194);
+ fiat_p384_addcarryx_u32(&x1205, &x1206, x1204, x1194, x1191);
uint32_t x1207;
fiat_p384_uint1 x1208;
- fiat_p384_addcarryx_u32(&x1207, &x1208, x1206, x1189, x1192);
+ fiat_p384_addcarryx_u32(&x1207, &x1208, x1206, x1192, x1189);
uint32_t x1209;
fiat_p384_uint1 x1210;
- fiat_p384_addcarryx_u32(&x1209, &x1210, x1208, x1187, x1190);
+ fiat_p384_addcarryx_u32(&x1209, &x1210, x1208, x1190, x1187);
uint32_t x1211;
fiat_p384_uint1 x1212;
- fiat_p384_addcarryx_u32(&x1211, &x1212, x1210, x1185, x1188);
+ fiat_p384_addcarryx_u32(&x1211, &x1212, x1210, x1188, x1185);
uint32_t x1213;
fiat_p384_uint1 x1214;
- fiat_p384_addcarryx_u32(&x1213, &x1214, x1212, x1183, x1186);
+ fiat_p384_addcarryx_u32(&x1213, &x1214, x1212, x1186, x1183);
uint32_t x1215;
fiat_p384_uint1 x1216;
- fiat_p384_addcarryx_u32(&x1215, &x1216, x1214, x1181, x1184);
+ fiat_p384_addcarryx_u32(&x1215, &x1216, x1214, x1184, x1181);
uint32_t x1217;
fiat_p384_uint1 x1218;
- fiat_p384_addcarryx_u32(&x1217, &x1218, x1216, 0x0, x1182);
+ fiat_p384_addcarryx_u32(&x1217, &x1218, x1216, x1182, 0x0);
uint32_t x1219;
fiat_p384_uint1 x1220;
- fiat_p384_addcarryx_u32(&x1219, &x1220, 0x0, x1199, x1155);
+ fiat_p384_addcarryx_u32(&x1219, &x1220, 0x0, x1155, x1199);
uint32_t x1221;
fiat_p384_uint1 x1222;
- fiat_p384_addcarryx_u32(&x1221, &x1222, x1220, x1200, x1157);
+ fiat_p384_addcarryx_u32(&x1221, &x1222, x1220, x1157, x1200);
uint32_t x1223;
fiat_p384_uint1 x1224;
- fiat_p384_addcarryx_u32(&x1223, &x1224, x1222, 0x0, x1159);
+ fiat_p384_addcarryx_u32(&x1223, &x1224, x1222, x1159, 0x0);
uint32_t x1225;
fiat_p384_uint1 x1226;
- fiat_p384_addcarryx_u32(&x1225, &x1226, x1224, x1197, x1161);
+ fiat_p384_addcarryx_u32(&x1225, &x1226, x1224, x1161, x1197);
uint32_t x1227;
fiat_p384_uint1 x1228;
- fiat_p384_addcarryx_u32(&x1227, &x1228, x1226, x1201, x1163);
+ fiat_p384_addcarryx_u32(&x1227, &x1228, x1226, x1163, x1201);
uint32_t x1229;
fiat_p384_uint1 x1230;
- fiat_p384_addcarryx_u32(&x1229, &x1230, x1228, x1203, x1165);
+ fiat_p384_addcarryx_u32(&x1229, &x1230, x1228, x1165, x1203);
uint32_t x1231;
fiat_p384_uint1 x1232;
- fiat_p384_addcarryx_u32(&x1231, &x1232, x1230, x1205, x1167);
+ fiat_p384_addcarryx_u32(&x1231, &x1232, x1230, x1167, x1205);
uint32_t x1233;
fiat_p384_uint1 x1234;
- fiat_p384_addcarryx_u32(&x1233, &x1234, x1232, x1207, x1169);
+ fiat_p384_addcarryx_u32(&x1233, &x1234, x1232, x1169, x1207);
uint32_t x1235;
fiat_p384_uint1 x1236;
- fiat_p384_addcarryx_u32(&x1235, &x1236, x1234, x1209, x1171);
+ fiat_p384_addcarryx_u32(&x1235, &x1236, x1234, x1171, x1209);
uint32_t x1237;
fiat_p384_uint1 x1238;
- fiat_p384_addcarryx_u32(&x1237, &x1238, x1236, x1211, x1173);
+ fiat_p384_addcarryx_u32(&x1237, &x1238, x1236, x1173, x1211);
uint32_t x1239;
fiat_p384_uint1 x1240;
- fiat_p384_addcarryx_u32(&x1239, &x1240, x1238, x1213, x1175);
+ fiat_p384_addcarryx_u32(&x1239, &x1240, x1238, x1175, x1213);
uint32_t x1241;
fiat_p384_uint1 x1242;
- fiat_p384_addcarryx_u32(&x1241, &x1242, x1240, x1215, x1177);
+ fiat_p384_addcarryx_u32(&x1241, &x1242, x1240, x1177, x1215);
uint32_t x1243;
fiat_p384_uint1 x1244;
- fiat_p384_addcarryx_u32(&x1243, &x1244, x1242, x1217, x1179);
+ fiat_p384_addcarryx_u32(&x1243, &x1244, x1242, x1179, x1217);
uint32_t x1245;
fiat_p384_uint1 x1246;
- fiat_p384_addcarryx_u32(&x1245, &x1246, x1244, 0x0, x1180);
+ fiat_p384_addcarryx_u32(&x1245, &x1246, x1244, x1180, 0x0);
uint32_t x1247;
uint32_t x1248;
fiat_p384_mulx_u32(&x1247, &x1248, x9, (arg2[11]));
@@ -2017,79 +2017,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1269, &x1270, x9, (arg2[0]));
uint32_t x1271;
fiat_p384_uint1 x1272;
- fiat_p384_addcarryx_u32(&x1271, &x1272, 0x0, x1267, x1270);
+ fiat_p384_addcarryx_u32(&x1271, &x1272, 0x0, x1270, x1267);
uint32_t x1273;
fiat_p384_uint1 x1274;
- fiat_p384_addcarryx_u32(&x1273, &x1274, x1272, x1265, x1268);
+ fiat_p384_addcarryx_u32(&x1273, &x1274, x1272, x1268, x1265);
uint32_t x1275;
fiat_p384_uint1 x1276;
- fiat_p384_addcarryx_u32(&x1275, &x1276, x1274, x1263, x1266);
+ fiat_p384_addcarryx_u32(&x1275, &x1276, x1274, x1266, x1263);
uint32_t x1277;
fiat_p384_uint1 x1278;
- fiat_p384_addcarryx_u32(&x1277, &x1278, x1276, x1261, x1264);
+ fiat_p384_addcarryx_u32(&x1277, &x1278, x1276, x1264, x1261);
uint32_t x1279;
fiat_p384_uint1 x1280;
- fiat_p384_addcarryx_u32(&x1279, &x1280, x1278, x1259, x1262);
+ fiat_p384_addcarryx_u32(&x1279, &x1280, x1278, x1262, x1259);
uint32_t x1281;
fiat_p384_uint1 x1282;
- fiat_p384_addcarryx_u32(&x1281, &x1282, x1280, x1257, x1260);
+ fiat_p384_addcarryx_u32(&x1281, &x1282, x1280, x1260, x1257);
uint32_t x1283;
fiat_p384_uint1 x1284;
- fiat_p384_addcarryx_u32(&x1283, &x1284, x1282, x1255, x1258);
+ fiat_p384_addcarryx_u32(&x1283, &x1284, x1282, x1258, x1255);
uint32_t x1285;
fiat_p384_uint1 x1286;
- fiat_p384_addcarryx_u32(&x1285, &x1286, x1284, x1253, x1256);
+ fiat_p384_addcarryx_u32(&x1285, &x1286, x1284, x1256, x1253);
uint32_t x1287;
fiat_p384_uint1 x1288;
- fiat_p384_addcarryx_u32(&x1287, &x1288, x1286, x1251, x1254);
+ fiat_p384_addcarryx_u32(&x1287, &x1288, x1286, x1254, x1251);
uint32_t x1289;
fiat_p384_uint1 x1290;
- fiat_p384_addcarryx_u32(&x1289, &x1290, x1288, x1249, x1252);
+ fiat_p384_addcarryx_u32(&x1289, &x1290, x1288, x1252, x1249);
uint32_t x1291;
fiat_p384_uint1 x1292;
- fiat_p384_addcarryx_u32(&x1291, &x1292, x1290, x1247, x1250);
+ fiat_p384_addcarryx_u32(&x1291, &x1292, x1290, x1250, x1247);
uint32_t x1293;
fiat_p384_uint1 x1294;
- fiat_p384_addcarryx_u32(&x1293, &x1294, x1292, 0x0, x1248);
+ fiat_p384_addcarryx_u32(&x1293, &x1294, x1292, x1248, 0x0);
uint32_t x1295;
fiat_p384_uint1 x1296;
- fiat_p384_addcarryx_u32(&x1295, &x1296, 0x0, x1269, x1221);
+ fiat_p384_addcarryx_u32(&x1295, &x1296, 0x0, x1221, x1269);
uint32_t x1297;
fiat_p384_uint1 x1298;
- fiat_p384_addcarryx_u32(&x1297, &x1298, x1296, x1271, x1223);
+ fiat_p384_addcarryx_u32(&x1297, &x1298, x1296, x1223, x1271);
uint32_t x1299;
fiat_p384_uint1 x1300;
- fiat_p384_addcarryx_u32(&x1299, &x1300, x1298, x1273, x1225);
+ fiat_p384_addcarryx_u32(&x1299, &x1300, x1298, x1225, x1273);
uint32_t x1301;
fiat_p384_uint1 x1302;
- fiat_p384_addcarryx_u32(&x1301, &x1302, x1300, x1275, x1227);
+ fiat_p384_addcarryx_u32(&x1301, &x1302, x1300, x1227, x1275);
uint32_t x1303;
fiat_p384_uint1 x1304;
- fiat_p384_addcarryx_u32(&x1303, &x1304, x1302, x1277, x1229);
+ fiat_p384_addcarryx_u32(&x1303, &x1304, x1302, x1229, x1277);
uint32_t x1305;
fiat_p384_uint1 x1306;
- fiat_p384_addcarryx_u32(&x1305, &x1306, x1304, x1279, x1231);
+ fiat_p384_addcarryx_u32(&x1305, &x1306, x1304, x1231, x1279);
uint32_t x1307;
fiat_p384_uint1 x1308;
- fiat_p384_addcarryx_u32(&x1307, &x1308, x1306, x1281, x1233);
+ fiat_p384_addcarryx_u32(&x1307, &x1308, x1306, x1233, x1281);
uint32_t x1309;
fiat_p384_uint1 x1310;
- fiat_p384_addcarryx_u32(&x1309, &x1310, x1308, x1283, x1235);
+ fiat_p384_addcarryx_u32(&x1309, &x1310, x1308, x1235, x1283);
uint32_t x1311;
fiat_p384_uint1 x1312;
- fiat_p384_addcarryx_u32(&x1311, &x1312, x1310, x1285, x1237);
+ fiat_p384_addcarryx_u32(&x1311, &x1312, x1310, x1237, x1285);
uint32_t x1313;
fiat_p384_uint1 x1314;
- fiat_p384_addcarryx_u32(&x1313, &x1314, x1312, x1287, x1239);
+ fiat_p384_addcarryx_u32(&x1313, &x1314, x1312, x1239, x1287);
uint32_t x1315;
fiat_p384_uint1 x1316;
- fiat_p384_addcarryx_u32(&x1315, &x1316, x1314, x1289, x1241);
+ fiat_p384_addcarryx_u32(&x1315, &x1316, x1314, x1241, x1289);
uint32_t x1317;
fiat_p384_uint1 x1318;
- fiat_p384_addcarryx_u32(&x1317, &x1318, x1316, x1291, x1243);
+ fiat_p384_addcarryx_u32(&x1317, &x1318, x1316, x1243, x1291);
uint32_t x1319;
fiat_p384_uint1 x1320;
- fiat_p384_addcarryx_u32(&x1319, &x1320, x1318, x1293, x1245);
+ fiat_p384_addcarryx_u32(&x1319, &x1320, x1318, x1245, x1293);
uint32_t x1321;
uint32_t x1322;
fiat_p384_mulx_u32(&x1321, &x1322, x1295, UINT32_C(0xffffffff));
@@ -2122,73 +2122,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1339, &x1340, x1295, UINT32_C(0xffffffff));
uint32_t x1341;
fiat_p384_uint1 x1342;
- fiat_p384_addcarryx_u32(&x1341, &x1342, 0x0, x1335, x1338);
+ fiat_p384_addcarryx_u32(&x1341, &x1342, 0x0, x1338, x1335);
uint32_t x1343;
fiat_p384_uint1 x1344;
- fiat_p384_addcarryx_u32(&x1343, &x1344, x1342, x1333, x1336);
+ fiat_p384_addcarryx_u32(&x1343, &x1344, x1342, x1336, x1333);
uint32_t x1345;
fiat_p384_uint1 x1346;
- fiat_p384_addcarryx_u32(&x1345, &x1346, x1344, x1331, x1334);
+ fiat_p384_addcarryx_u32(&x1345, &x1346, x1344, x1334, x1331);
uint32_t x1347;
fiat_p384_uint1 x1348;
- fiat_p384_addcarryx_u32(&x1347, &x1348, x1346, x1329, x1332);
+ fiat_p384_addcarryx_u32(&x1347, &x1348, x1346, x1332, x1329);
uint32_t x1349;
fiat_p384_uint1 x1350;
- fiat_p384_addcarryx_u32(&x1349, &x1350, x1348, x1327, x1330);
+ fiat_p384_addcarryx_u32(&x1349, &x1350, x1348, x1330, x1327);
uint32_t x1351;
fiat_p384_uint1 x1352;
- fiat_p384_addcarryx_u32(&x1351, &x1352, x1350, x1325, x1328);
+ fiat_p384_addcarryx_u32(&x1351, &x1352, x1350, x1328, x1325);
uint32_t x1353;
fiat_p384_uint1 x1354;
- fiat_p384_addcarryx_u32(&x1353, &x1354, x1352, x1323, x1326);
+ fiat_p384_addcarryx_u32(&x1353, &x1354, x1352, x1326, x1323);
uint32_t x1355;
fiat_p384_uint1 x1356;
- fiat_p384_addcarryx_u32(&x1355, &x1356, x1354, x1321, x1324);
+ fiat_p384_addcarryx_u32(&x1355, &x1356, x1354, x1324, x1321);
uint32_t x1357;
fiat_p384_uint1 x1358;
- fiat_p384_addcarryx_u32(&x1357, &x1358, x1356, 0x0, x1322);
+ fiat_p384_addcarryx_u32(&x1357, &x1358, x1356, x1322, 0x0);
uint32_t x1359;
fiat_p384_uint1 x1360;
- fiat_p384_addcarryx_u32(&x1359, &x1360, 0x0, x1339, x1295);
+ fiat_p384_addcarryx_u32(&x1359, &x1360, 0x0, x1295, x1339);
uint32_t x1361;
fiat_p384_uint1 x1362;
- fiat_p384_addcarryx_u32(&x1361, &x1362, x1360, x1340, x1297);
+ fiat_p384_addcarryx_u32(&x1361, &x1362, x1360, x1297, x1340);
uint32_t x1363;
fiat_p384_uint1 x1364;
- fiat_p384_addcarryx_u32(&x1363, &x1364, x1362, 0x0, x1299);
+ fiat_p384_addcarryx_u32(&x1363, &x1364, x1362, x1299, 0x0);
uint32_t x1365;
fiat_p384_uint1 x1366;
- fiat_p384_addcarryx_u32(&x1365, &x1366, x1364, x1337, x1301);
+ fiat_p384_addcarryx_u32(&x1365, &x1366, x1364, x1301, x1337);
uint32_t x1367;
fiat_p384_uint1 x1368;
- fiat_p384_addcarryx_u32(&x1367, &x1368, x1366, x1341, x1303);
+ fiat_p384_addcarryx_u32(&x1367, &x1368, x1366, x1303, x1341);
uint32_t x1369;
fiat_p384_uint1 x1370;
- fiat_p384_addcarryx_u32(&x1369, &x1370, x1368, x1343, x1305);
+ fiat_p384_addcarryx_u32(&x1369, &x1370, x1368, x1305, x1343);
uint32_t x1371;
fiat_p384_uint1 x1372;
- fiat_p384_addcarryx_u32(&x1371, &x1372, x1370, x1345, x1307);
+ fiat_p384_addcarryx_u32(&x1371, &x1372, x1370, x1307, x1345);
uint32_t x1373;
fiat_p384_uint1 x1374;
- fiat_p384_addcarryx_u32(&x1373, &x1374, x1372, x1347, x1309);
+ fiat_p384_addcarryx_u32(&x1373, &x1374, x1372, x1309, x1347);
uint32_t x1375;
fiat_p384_uint1 x1376;
- fiat_p384_addcarryx_u32(&x1375, &x1376, x1374, x1349, x1311);
+ fiat_p384_addcarryx_u32(&x1375, &x1376, x1374, x1311, x1349);
uint32_t x1377;
fiat_p384_uint1 x1378;
- fiat_p384_addcarryx_u32(&x1377, &x1378, x1376, x1351, x1313);
+ fiat_p384_addcarryx_u32(&x1377, &x1378, x1376, x1313, x1351);
uint32_t x1379;
fiat_p384_uint1 x1380;
- fiat_p384_addcarryx_u32(&x1379, &x1380, x1378, x1353, x1315);
+ fiat_p384_addcarryx_u32(&x1379, &x1380, x1378, x1315, x1353);
uint32_t x1381;
fiat_p384_uint1 x1382;
- fiat_p384_addcarryx_u32(&x1381, &x1382, x1380, x1355, x1317);
+ fiat_p384_addcarryx_u32(&x1381, &x1382, x1380, x1317, x1355);
uint32_t x1383;
fiat_p384_uint1 x1384;
- fiat_p384_addcarryx_u32(&x1383, &x1384, x1382, x1357, x1319);
+ fiat_p384_addcarryx_u32(&x1383, &x1384, x1382, x1319, x1357);
uint32_t x1385;
fiat_p384_uint1 x1386;
- fiat_p384_addcarryx_u32(&x1385, &x1386, x1384, 0x0, x1320);
+ fiat_p384_addcarryx_u32(&x1385, &x1386, x1384, x1320, 0x0);
uint32_t x1387;
uint32_t x1388;
fiat_p384_mulx_u32(&x1387, &x1388, x10, (arg2[11]));
@@ -2227,79 +2227,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1409, &x1410, x10, (arg2[0]));
uint32_t x1411;
fiat_p384_uint1 x1412;
- fiat_p384_addcarryx_u32(&x1411, &x1412, 0x0, x1407, x1410);
+ fiat_p384_addcarryx_u32(&x1411, &x1412, 0x0, x1410, x1407);
uint32_t x1413;
fiat_p384_uint1 x1414;
- fiat_p384_addcarryx_u32(&x1413, &x1414, x1412, x1405, x1408);
+ fiat_p384_addcarryx_u32(&x1413, &x1414, x1412, x1408, x1405);
uint32_t x1415;
fiat_p384_uint1 x1416;
- fiat_p384_addcarryx_u32(&x1415, &x1416, x1414, x1403, x1406);
+ fiat_p384_addcarryx_u32(&x1415, &x1416, x1414, x1406, x1403);
uint32_t x1417;
fiat_p384_uint1 x1418;
- fiat_p384_addcarryx_u32(&x1417, &x1418, x1416, x1401, x1404);
+ fiat_p384_addcarryx_u32(&x1417, &x1418, x1416, x1404, x1401);
uint32_t x1419;
fiat_p384_uint1 x1420;
- fiat_p384_addcarryx_u32(&x1419, &x1420, x1418, x1399, x1402);
+ fiat_p384_addcarryx_u32(&x1419, &x1420, x1418, x1402, x1399);
uint32_t x1421;
fiat_p384_uint1 x1422;
- fiat_p384_addcarryx_u32(&x1421, &x1422, x1420, x1397, x1400);
+ fiat_p384_addcarryx_u32(&x1421, &x1422, x1420, x1400, x1397);
uint32_t x1423;
fiat_p384_uint1 x1424;
- fiat_p384_addcarryx_u32(&x1423, &x1424, x1422, x1395, x1398);
+ fiat_p384_addcarryx_u32(&x1423, &x1424, x1422, x1398, x1395);
uint32_t x1425;
fiat_p384_uint1 x1426;
- fiat_p384_addcarryx_u32(&x1425, &x1426, x1424, x1393, x1396);
+ fiat_p384_addcarryx_u32(&x1425, &x1426, x1424, x1396, x1393);
uint32_t x1427;
fiat_p384_uint1 x1428;
- fiat_p384_addcarryx_u32(&x1427, &x1428, x1426, x1391, x1394);
+ fiat_p384_addcarryx_u32(&x1427, &x1428, x1426, x1394, x1391);
uint32_t x1429;
fiat_p384_uint1 x1430;
- fiat_p384_addcarryx_u32(&x1429, &x1430, x1428, x1389, x1392);
+ fiat_p384_addcarryx_u32(&x1429, &x1430, x1428, x1392, x1389);
uint32_t x1431;
fiat_p384_uint1 x1432;
- fiat_p384_addcarryx_u32(&x1431, &x1432, x1430, x1387, x1390);
+ fiat_p384_addcarryx_u32(&x1431, &x1432, x1430, x1390, x1387);
uint32_t x1433;
fiat_p384_uint1 x1434;
- fiat_p384_addcarryx_u32(&x1433, &x1434, x1432, 0x0, x1388);
+ fiat_p384_addcarryx_u32(&x1433, &x1434, x1432, x1388, 0x0);
uint32_t x1435;
fiat_p384_uint1 x1436;
- fiat_p384_addcarryx_u32(&x1435, &x1436, 0x0, x1409, x1361);
+ fiat_p384_addcarryx_u32(&x1435, &x1436, 0x0, x1361, x1409);
uint32_t x1437;
fiat_p384_uint1 x1438;
- fiat_p384_addcarryx_u32(&x1437, &x1438, x1436, x1411, x1363);
+ fiat_p384_addcarryx_u32(&x1437, &x1438, x1436, x1363, x1411);
uint32_t x1439;
fiat_p384_uint1 x1440;
- fiat_p384_addcarryx_u32(&x1439, &x1440, x1438, x1413, x1365);
+ fiat_p384_addcarryx_u32(&x1439, &x1440, x1438, x1365, x1413);
uint32_t x1441;
fiat_p384_uint1 x1442;
- fiat_p384_addcarryx_u32(&x1441, &x1442, x1440, x1415, x1367);
+ fiat_p384_addcarryx_u32(&x1441, &x1442, x1440, x1367, x1415);
uint32_t x1443;
fiat_p384_uint1 x1444;
- fiat_p384_addcarryx_u32(&x1443, &x1444, x1442, x1417, x1369);
+ fiat_p384_addcarryx_u32(&x1443, &x1444, x1442, x1369, x1417);
uint32_t x1445;
fiat_p384_uint1 x1446;
- fiat_p384_addcarryx_u32(&x1445, &x1446, x1444, x1419, x1371);
+ fiat_p384_addcarryx_u32(&x1445, &x1446, x1444, x1371, x1419);
uint32_t x1447;
fiat_p384_uint1 x1448;
- fiat_p384_addcarryx_u32(&x1447, &x1448, x1446, x1421, x1373);
+ fiat_p384_addcarryx_u32(&x1447, &x1448, x1446, x1373, x1421);
uint32_t x1449;
fiat_p384_uint1 x1450;
- fiat_p384_addcarryx_u32(&x1449, &x1450, x1448, x1423, x1375);
+ fiat_p384_addcarryx_u32(&x1449, &x1450, x1448, x1375, x1423);
uint32_t x1451;
fiat_p384_uint1 x1452;
- fiat_p384_addcarryx_u32(&x1451, &x1452, x1450, x1425, x1377);
+ fiat_p384_addcarryx_u32(&x1451, &x1452, x1450, x1377, x1425);
uint32_t x1453;
fiat_p384_uint1 x1454;
- fiat_p384_addcarryx_u32(&x1453, &x1454, x1452, x1427, x1379);
+ fiat_p384_addcarryx_u32(&x1453, &x1454, x1452, x1379, x1427);
uint32_t x1455;
fiat_p384_uint1 x1456;
- fiat_p384_addcarryx_u32(&x1455, &x1456, x1454, x1429, x1381);
+ fiat_p384_addcarryx_u32(&x1455, &x1456, x1454, x1381, x1429);
uint32_t x1457;
fiat_p384_uint1 x1458;
- fiat_p384_addcarryx_u32(&x1457, &x1458, x1456, x1431, x1383);
+ fiat_p384_addcarryx_u32(&x1457, &x1458, x1456, x1383, x1431);
uint32_t x1459;
fiat_p384_uint1 x1460;
- fiat_p384_addcarryx_u32(&x1459, &x1460, x1458, x1433, x1385);
+ fiat_p384_addcarryx_u32(&x1459, &x1460, x1458, x1385, x1433);
uint32_t x1461;
uint32_t x1462;
fiat_p384_mulx_u32(&x1461, &x1462, x1435, UINT32_C(0xffffffff));
@@ -2332,73 +2332,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1479, &x1480, x1435, UINT32_C(0xffffffff));
uint32_t x1481;
fiat_p384_uint1 x1482;
- fiat_p384_addcarryx_u32(&x1481, &x1482, 0x0, x1475, x1478);
+ fiat_p384_addcarryx_u32(&x1481, &x1482, 0x0, x1478, x1475);
uint32_t x1483;
fiat_p384_uint1 x1484;
- fiat_p384_addcarryx_u32(&x1483, &x1484, x1482, x1473, x1476);
+ fiat_p384_addcarryx_u32(&x1483, &x1484, x1482, x1476, x1473);
uint32_t x1485;
fiat_p384_uint1 x1486;
- fiat_p384_addcarryx_u32(&x1485, &x1486, x1484, x1471, x1474);
+ fiat_p384_addcarryx_u32(&x1485, &x1486, x1484, x1474, x1471);
uint32_t x1487;
fiat_p384_uint1 x1488;
- fiat_p384_addcarryx_u32(&x1487, &x1488, x1486, x1469, x1472);
+ fiat_p384_addcarryx_u32(&x1487, &x1488, x1486, x1472, x1469);
uint32_t x1489;
fiat_p384_uint1 x1490;
- fiat_p384_addcarryx_u32(&x1489, &x1490, x1488, x1467, x1470);
+ fiat_p384_addcarryx_u32(&x1489, &x1490, x1488, x1470, x1467);
uint32_t x1491;
fiat_p384_uint1 x1492;
- fiat_p384_addcarryx_u32(&x1491, &x1492, x1490, x1465, x1468);
+ fiat_p384_addcarryx_u32(&x1491, &x1492, x1490, x1468, x1465);
uint32_t x1493;
fiat_p384_uint1 x1494;
- fiat_p384_addcarryx_u32(&x1493, &x1494, x1492, x1463, x1466);
+ fiat_p384_addcarryx_u32(&x1493, &x1494, x1492, x1466, x1463);
uint32_t x1495;
fiat_p384_uint1 x1496;
- fiat_p384_addcarryx_u32(&x1495, &x1496, x1494, x1461, x1464);
+ fiat_p384_addcarryx_u32(&x1495, &x1496, x1494, x1464, x1461);
uint32_t x1497;
fiat_p384_uint1 x1498;
- fiat_p384_addcarryx_u32(&x1497, &x1498, x1496, 0x0, x1462);
+ fiat_p384_addcarryx_u32(&x1497, &x1498, x1496, x1462, 0x0);
uint32_t x1499;
fiat_p384_uint1 x1500;
- fiat_p384_addcarryx_u32(&x1499, &x1500, 0x0, x1479, x1435);
+ fiat_p384_addcarryx_u32(&x1499, &x1500, 0x0, x1435, x1479);
uint32_t x1501;
fiat_p384_uint1 x1502;
- fiat_p384_addcarryx_u32(&x1501, &x1502, x1500, x1480, x1437);
+ fiat_p384_addcarryx_u32(&x1501, &x1502, x1500, x1437, x1480);
uint32_t x1503;
fiat_p384_uint1 x1504;
- fiat_p384_addcarryx_u32(&x1503, &x1504, x1502, 0x0, x1439);
+ fiat_p384_addcarryx_u32(&x1503, &x1504, x1502, x1439, 0x0);
uint32_t x1505;
fiat_p384_uint1 x1506;
- fiat_p384_addcarryx_u32(&x1505, &x1506, x1504, x1477, x1441);
+ fiat_p384_addcarryx_u32(&x1505, &x1506, x1504, x1441, x1477);
uint32_t x1507;
fiat_p384_uint1 x1508;
- fiat_p384_addcarryx_u32(&x1507, &x1508, x1506, x1481, x1443);
+ fiat_p384_addcarryx_u32(&x1507, &x1508, x1506, x1443, x1481);
uint32_t x1509;
fiat_p384_uint1 x1510;
- fiat_p384_addcarryx_u32(&x1509, &x1510, x1508, x1483, x1445);
+ fiat_p384_addcarryx_u32(&x1509, &x1510, x1508, x1445, x1483);
uint32_t x1511;
fiat_p384_uint1 x1512;
- fiat_p384_addcarryx_u32(&x1511, &x1512, x1510, x1485, x1447);
+ fiat_p384_addcarryx_u32(&x1511, &x1512, x1510, x1447, x1485);
uint32_t x1513;
fiat_p384_uint1 x1514;
- fiat_p384_addcarryx_u32(&x1513, &x1514, x1512, x1487, x1449);
+ fiat_p384_addcarryx_u32(&x1513, &x1514, x1512, x1449, x1487);
uint32_t x1515;
fiat_p384_uint1 x1516;
- fiat_p384_addcarryx_u32(&x1515, &x1516, x1514, x1489, x1451);
+ fiat_p384_addcarryx_u32(&x1515, &x1516, x1514, x1451, x1489);
uint32_t x1517;
fiat_p384_uint1 x1518;
- fiat_p384_addcarryx_u32(&x1517, &x1518, x1516, x1491, x1453);
+ fiat_p384_addcarryx_u32(&x1517, &x1518, x1516, x1453, x1491);
uint32_t x1519;
fiat_p384_uint1 x1520;
- fiat_p384_addcarryx_u32(&x1519, &x1520, x1518, x1493, x1455);
+ fiat_p384_addcarryx_u32(&x1519, &x1520, x1518, x1455, x1493);
uint32_t x1521;
fiat_p384_uint1 x1522;
- fiat_p384_addcarryx_u32(&x1521, &x1522, x1520, x1495, x1457);
+ fiat_p384_addcarryx_u32(&x1521, &x1522, x1520, x1457, x1495);
uint32_t x1523;
fiat_p384_uint1 x1524;
- fiat_p384_addcarryx_u32(&x1523, &x1524, x1522, x1497, x1459);
+ fiat_p384_addcarryx_u32(&x1523, &x1524, x1522, x1459, x1497);
uint32_t x1525;
fiat_p384_uint1 x1526;
- fiat_p384_addcarryx_u32(&x1525, &x1526, x1524, 0x0, x1460);
+ fiat_p384_addcarryx_u32(&x1525, &x1526, x1524, x1460, 0x0);
uint32_t x1527;
uint32_t x1528;
fiat_p384_mulx_u32(&x1527, &x1528, x11, (arg2[11]));
@@ -2437,79 +2437,79 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1549, &x1550, x11, (arg2[0]));
uint32_t x1551;
fiat_p384_uint1 x1552;
- fiat_p384_addcarryx_u32(&x1551, &x1552, 0x0, x1547, x1550);
+ fiat_p384_addcarryx_u32(&x1551, &x1552, 0x0, x1550, x1547);
uint32_t x1553;
fiat_p384_uint1 x1554;
- fiat_p384_addcarryx_u32(&x1553, &x1554, x1552, x1545, x1548);
+ fiat_p384_addcarryx_u32(&x1553, &x1554, x1552, x1548, x1545);
uint32_t x1555;
fiat_p384_uint1 x1556;
- fiat_p384_addcarryx_u32(&x1555, &x1556, x1554, x1543, x1546);
+ fiat_p384_addcarryx_u32(&x1555, &x1556, x1554, x1546, x1543);
uint32_t x1557;
fiat_p384_uint1 x1558;
- fiat_p384_addcarryx_u32(&x1557, &x1558, x1556, x1541, x1544);
+ fiat_p384_addcarryx_u32(&x1557, &x1558, x1556, x1544, x1541);
uint32_t x1559;
fiat_p384_uint1 x1560;
- fiat_p384_addcarryx_u32(&x1559, &x1560, x1558, x1539, x1542);
+ fiat_p384_addcarryx_u32(&x1559, &x1560, x1558, x1542, x1539);
uint32_t x1561;
fiat_p384_uint1 x1562;
- fiat_p384_addcarryx_u32(&x1561, &x1562, x1560, x1537, x1540);
+ fiat_p384_addcarryx_u32(&x1561, &x1562, x1560, x1540, x1537);
uint32_t x1563;
fiat_p384_uint1 x1564;
- fiat_p384_addcarryx_u32(&x1563, &x1564, x1562, x1535, x1538);
+ fiat_p384_addcarryx_u32(&x1563, &x1564, x1562, x1538, x1535);
uint32_t x1565;
fiat_p384_uint1 x1566;
- fiat_p384_addcarryx_u32(&x1565, &x1566, x1564, x1533, x1536);
+ fiat_p384_addcarryx_u32(&x1565, &x1566, x1564, x1536, x1533);
uint32_t x1567;
fiat_p384_uint1 x1568;
- fiat_p384_addcarryx_u32(&x1567, &x1568, x1566, x1531, x1534);
+ fiat_p384_addcarryx_u32(&x1567, &x1568, x1566, x1534, x1531);
uint32_t x1569;
fiat_p384_uint1 x1570;
- fiat_p384_addcarryx_u32(&x1569, &x1570, x1568, x1529, x1532);
+ fiat_p384_addcarryx_u32(&x1569, &x1570, x1568, x1532, x1529);
uint32_t x1571;
fiat_p384_uint1 x1572;
- fiat_p384_addcarryx_u32(&x1571, &x1572, x1570, x1527, x1530);
+ fiat_p384_addcarryx_u32(&x1571, &x1572, x1570, x1530, x1527);
uint32_t x1573;
fiat_p384_uint1 x1574;
- fiat_p384_addcarryx_u32(&x1573, &x1574, x1572, 0x0, x1528);
+ fiat_p384_addcarryx_u32(&x1573, &x1574, x1572, x1528, 0x0);
uint32_t x1575;
fiat_p384_uint1 x1576;
- fiat_p384_addcarryx_u32(&x1575, &x1576, 0x0, x1549, x1501);
+ fiat_p384_addcarryx_u32(&x1575, &x1576, 0x0, x1501, x1549);
uint32_t x1577;
fiat_p384_uint1 x1578;
- fiat_p384_addcarryx_u32(&x1577, &x1578, x1576, x1551, x1503);
+ fiat_p384_addcarryx_u32(&x1577, &x1578, x1576, x1503, x1551);
uint32_t x1579;
fiat_p384_uint1 x1580;
- fiat_p384_addcarryx_u32(&x1579, &x1580, x1578, x1553, x1505);
+ fiat_p384_addcarryx_u32(&x1579, &x1580, x1578, x1505, x1553);
uint32_t x1581;
fiat_p384_uint1 x1582;
- fiat_p384_addcarryx_u32(&x1581, &x1582, x1580, x1555, x1507);
+ fiat_p384_addcarryx_u32(&x1581, &x1582, x1580, x1507, x1555);
uint32_t x1583;
fiat_p384_uint1 x1584;
- fiat_p384_addcarryx_u32(&x1583, &x1584, x1582, x1557, x1509);
+ fiat_p384_addcarryx_u32(&x1583, &x1584, x1582, x1509, x1557);
uint32_t x1585;
fiat_p384_uint1 x1586;
- fiat_p384_addcarryx_u32(&x1585, &x1586, x1584, x1559, x1511);
+ fiat_p384_addcarryx_u32(&x1585, &x1586, x1584, x1511, x1559);
uint32_t x1587;
fiat_p384_uint1 x1588;
- fiat_p384_addcarryx_u32(&x1587, &x1588, x1586, x1561, x1513);
+ fiat_p384_addcarryx_u32(&x1587, &x1588, x1586, x1513, x1561);
uint32_t x1589;
fiat_p384_uint1 x1590;
- fiat_p384_addcarryx_u32(&x1589, &x1590, x1588, x1563, x1515);
+ fiat_p384_addcarryx_u32(&x1589, &x1590, x1588, x1515, x1563);
uint32_t x1591;
fiat_p384_uint1 x1592;
- fiat_p384_addcarryx_u32(&x1591, &x1592, x1590, x1565, x1517);
+ fiat_p384_addcarryx_u32(&x1591, &x1592, x1590, x1517, x1565);
uint32_t x1593;
fiat_p384_uint1 x1594;
- fiat_p384_addcarryx_u32(&x1593, &x1594, x1592, x1567, x1519);
+ fiat_p384_addcarryx_u32(&x1593, &x1594, x1592, x1519, x1567);
uint32_t x1595;
fiat_p384_uint1 x1596;
- fiat_p384_addcarryx_u32(&x1595, &x1596, x1594, x1569, x1521);
+ fiat_p384_addcarryx_u32(&x1595, &x1596, x1594, x1521, x1569);
uint32_t x1597;
fiat_p384_uint1 x1598;
- fiat_p384_addcarryx_u32(&x1597, &x1598, x1596, x1571, x1523);
+ fiat_p384_addcarryx_u32(&x1597, &x1598, x1596, x1523, x1571);
uint32_t x1599;
fiat_p384_uint1 x1600;
- fiat_p384_addcarryx_u32(&x1599, &x1600, x1598, x1573, x1525);
+ fiat_p384_addcarryx_u32(&x1599, &x1600, x1598, x1525, x1573);
uint32_t x1601;
uint32_t x1602;
fiat_p384_mulx_u32(&x1601, &x1602, x1575, UINT32_C(0xffffffff));
@@ -2542,73 +2542,73 @@ static void fiat_p384_mul(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_mulx_u32(&x1619, &x1620, x1575, UINT32_C(0xffffffff));
uint32_t x1621;
fiat_p384_uint1 x1622;
- fiat_p384_addcarryx_u32(&x1621, &x1622, 0x0, x1615, x1618);
+ fiat_p384_addcarryx_u32(&x1621, &x1622, 0x0, x1618, x1615);
uint32_t x1623;
fiat_p384_uint1 x1624;
- fiat_p384_addcarryx_u32(&x1623, &x1624, x1622, x1613, x1616);
+ fiat_p384_addcarryx_u32(&x1623, &x1624, x1622, x1616, x1613);
uint32_t x1625;
fiat_p384_uint1 x1626;
- fiat_p384_addcarryx_u32(&x1625, &x1626, x1624, x1611, x1614);
+ fiat_p384_addcarryx_u32(&x1625, &x1626, x1624, x1614, x1611);
uint32_t x1627;
fiat_p384_uint1 x1628;
- fiat_p384_addcarryx_u32(&x1627, &x1628, x1626, x1609, x1612);
+ fiat_p384_addcarryx_u32(&x1627, &x1628, x1626, x1612, x1609);
uint32_t x1629;
fiat_p384_uint1 x1630;
- fiat_p384_addcarryx_u32(&x1629, &x1630, x1628, x1607, x1610);
+ fiat_p384_addcarryx_u32(&x1629, &x1630, x1628, x1610, x1607);
uint32_t x1631;
fiat_p384_uint1 x1632;
- fiat_p384_addcarryx_u32(&x1631, &x1632, x1630, x1605, x1608);
+ fiat_p384_addcarryx_u32(&x1631, &x1632, x1630, x1608, x1605);
uint32_t x1633;
fiat_p384_uint1 x1634;
- fiat_p384_addcarryx_u32(&x1633, &x1634, x1632, x1603, x1606);
+ fiat_p384_addcarryx_u32(&x1633, &x1634, x1632, x1606, x1603);
uint32_t x1635;
fiat_p384_uint1 x1636;
- fiat_p384_addcarryx_u32(&x1635, &x1636, x1634, x1601, x1604);
+ fiat_p384_addcarryx_u32(&x1635, &x1636, x1634, x1604, x1601);
uint32_t x1637;
fiat_p384_uint1 x1638;
- fiat_p384_addcarryx_u32(&x1637, &x1638, x1636, 0x0, x1602);
+ fiat_p384_addcarryx_u32(&x1637, &x1638, x1636, x1602, 0x0);
uint32_t x1639;
fiat_p384_uint1 x1640;
- fiat_p384_addcarryx_u32(&x1639, &x1640, 0x0, x1619, x1575);
+ fiat_p384_addcarryx_u32(&x1639, &x1640, 0x0, x1575, x1619);
uint32_t x1641;
fiat_p384_uint1 x1642;
- fiat_p384_addcarryx_u32(&x1641, &x1642, x1640, x1620, x1577);
+ fiat_p384_addcarryx_u32(&x1641, &x1642, x1640, x1577, x1620);
uint32_t x1643;
fiat_p384_uint1 x1644;
- fiat_p384_addcarryx_u32(&x1643, &x1644, x1642, 0x0, x1579);
+ fiat_p384_addcarryx_u32(&x1643, &x1644, x1642, x1579, 0x0);
uint32_t x1645;
fiat_p384_uint1 x1646;
- fiat_p384_addcarryx_u32(&x1645, &x1646, x1644, x1617, x1581);
+ fiat_p384_addcarryx_u32(&x1645, &x1646, x1644, x1581, x1617);
uint32_t x1647;
fiat_p384_uint1 x1648;
- fiat_p384_addcarryx_u32(&x1647, &x1648, x1646, x1621, x1583);
+ fiat_p384_addcarryx_u32(&x1647, &x1648, x1646, x1583, x1621);
uint32_t x1649;
fiat_p384_uint1 x1650;
- fiat_p384_addcarryx_u32(&x1649, &x1650, x1648, x1623, x1585);
+ fiat_p384_addcarryx_u32(&x1649, &x1650, x1648, x1585, x1623);
uint32_t x1651;
fiat_p384_uint1 x1652;
- fiat_p384_addcarryx_u32(&x1651, &x1652, x1650, x1625, x1587);
+ fiat_p384_addcarryx_u32(&x1651, &x1652, x1650, x1587, x1625);
uint32_t x1653;
fiat_p384_uint1 x1654;
- fiat_p384_addcarryx_u32(&x1653, &x1654, x1652, x1627, x1589);
+ fiat_p384_addcarryx_u32(&x1653, &x1654, x1652, x1589, x1627);
uint32_t x1655;
fiat_p384_uint1 x1656;
- fiat_p384_addcarryx_u32(&x1655, &x1656, x1654, x1629, x1591);
+ fiat_p384_addcarryx_u32(&x1655, &x1656, x1654, x1591, x1629);
uint32_t x1657;
fiat_p384_uint1 x1658;
- fiat_p384_addcarryx_u32(&x1657, &x1658, x1656, x1631, x1593);
+ fiat_p384_addcarryx_u32(&x1657, &x1658, x1656, x1593, x1631);
uint32_t x1659;
fiat_p384_uint1 x1660;
- fiat_p384_addcarryx_u32(&x1659, &x1660, x1658, x1633, x1595);
+ fiat_p384_addcarryx_u32(&x1659, &x1660, x1658, x1595, x1633);
uint32_t x1661;
fiat_p384_uint1 x1662;
- fiat_p384_addcarryx_u32(&x1661, &x1662, x1660, x1635, x1597);
+ fiat_p384_addcarryx_u32(&x1661, &x1662, x1660, x1597, x1635);
uint32_t x1663;
fiat_p384_uint1 x1664;
- fiat_p384_addcarryx_u32(&x1663, &x1664, x1662, x1637, x1599);
+ fiat_p384_addcarryx_u32(&x1663, &x1664, x1662, x1599, x1637);
uint32_t x1665;
fiat_p384_uint1 x1666;
- fiat_p384_addcarryx_u32(&x1665, &x1666, x1664, 0x0, x1600);
+ fiat_p384_addcarryx_u32(&x1665, &x1666, x1664, x1600, 0x0);
uint32_t x1667;
fiat_p384_uint1 x1668;
fiat_p384_subborrowx_u32(&x1667, &x1668, 0x0, x1641, UINT32_C(0xffffffff));
@@ -2750,40 +2750,40 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x35, &x36, x12, (arg1[0]));
uint32_t x37;
fiat_p384_uint1 x38;
- fiat_p384_addcarryx_u32(&x37, &x38, 0x0, x33, x36);
+ fiat_p384_addcarryx_u32(&x37, &x38, 0x0, x36, x33);
uint32_t x39;
fiat_p384_uint1 x40;
- fiat_p384_addcarryx_u32(&x39, &x40, x38, x31, x34);
+ fiat_p384_addcarryx_u32(&x39, &x40, x38, x34, x31);
uint32_t x41;
fiat_p384_uint1 x42;
- fiat_p384_addcarryx_u32(&x41, &x42, x40, x29, x32);
+ fiat_p384_addcarryx_u32(&x41, &x42, x40, x32, x29);
uint32_t x43;
fiat_p384_uint1 x44;
- fiat_p384_addcarryx_u32(&x43, &x44, x42, x27, x30);
+ fiat_p384_addcarryx_u32(&x43, &x44, x42, x30, x27);
uint32_t x45;
fiat_p384_uint1 x46;
- fiat_p384_addcarryx_u32(&x45, &x46, x44, x25, x28);
+ fiat_p384_addcarryx_u32(&x45, &x46, x44, x28, x25);
uint32_t x47;
fiat_p384_uint1 x48;
- fiat_p384_addcarryx_u32(&x47, &x48, x46, x23, x26);
+ fiat_p384_addcarryx_u32(&x47, &x48, x46, x26, x23);
uint32_t x49;
fiat_p384_uint1 x50;
- fiat_p384_addcarryx_u32(&x49, &x50, x48, x21, x24);
+ fiat_p384_addcarryx_u32(&x49, &x50, x48, x24, x21);
uint32_t x51;
fiat_p384_uint1 x52;
- fiat_p384_addcarryx_u32(&x51, &x52, x50, x19, x22);
+ fiat_p384_addcarryx_u32(&x51, &x52, x50, x22, x19);
uint32_t x53;
fiat_p384_uint1 x54;
- fiat_p384_addcarryx_u32(&x53, &x54, x52, x17, x20);
+ fiat_p384_addcarryx_u32(&x53, &x54, x52, x20, x17);
uint32_t x55;
fiat_p384_uint1 x56;
- fiat_p384_addcarryx_u32(&x55, &x56, x54, x15, x18);
+ fiat_p384_addcarryx_u32(&x55, &x56, x54, x18, x15);
uint32_t x57;
fiat_p384_uint1 x58;
- fiat_p384_addcarryx_u32(&x57, &x58, x56, x13, x16);
+ fiat_p384_addcarryx_u32(&x57, &x58, x56, x16, x13);
uint32_t x59;
fiat_p384_uint1 x60;
- fiat_p384_addcarryx_u32(&x59, &x60, x58, 0x0, x14);
+ fiat_p384_addcarryx_u32(&x59, &x60, x58, x14, 0x0);
uint32_t x61;
uint32_t x62;
fiat_p384_mulx_u32(&x61, &x62, x35, UINT32_C(0xffffffff));
@@ -2816,70 +2816,70 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x79, &x80, x35, UINT32_C(0xffffffff));
uint32_t x81;
fiat_p384_uint1 x82;
- fiat_p384_addcarryx_u32(&x81, &x82, 0x0, x75, x78);
+ fiat_p384_addcarryx_u32(&x81, &x82, 0x0, x78, x75);
uint32_t x83;
fiat_p384_uint1 x84;
- fiat_p384_addcarryx_u32(&x83, &x84, x82, x73, x76);
+ fiat_p384_addcarryx_u32(&x83, &x84, x82, x76, x73);
uint32_t x85;
fiat_p384_uint1 x86;
- fiat_p384_addcarryx_u32(&x85, &x86, x84, x71, x74);
+ fiat_p384_addcarryx_u32(&x85, &x86, x84, x74, x71);
uint32_t x87;
fiat_p384_uint1 x88;
- fiat_p384_addcarryx_u32(&x87, &x88, x86, x69, x72);
+ fiat_p384_addcarryx_u32(&x87, &x88, x86, x72, x69);
uint32_t x89;
fiat_p384_uint1 x90;
- fiat_p384_addcarryx_u32(&x89, &x90, x88, x67, x70);
+ fiat_p384_addcarryx_u32(&x89, &x90, x88, x70, x67);
uint32_t x91;
fiat_p384_uint1 x92;
- fiat_p384_addcarryx_u32(&x91, &x92, x90, x65, x68);
+ fiat_p384_addcarryx_u32(&x91, &x92, x90, x68, x65);
uint32_t x93;
fiat_p384_uint1 x94;
- fiat_p384_addcarryx_u32(&x93, &x94, x92, x63, x66);
+ fiat_p384_addcarryx_u32(&x93, &x94, x92, x66, x63);
uint32_t x95;
fiat_p384_uint1 x96;
- fiat_p384_addcarryx_u32(&x95, &x96, x94, x61, x64);
+ fiat_p384_addcarryx_u32(&x95, &x96, x94, x64, x61);
uint32_t x97;
fiat_p384_uint1 x98;
- fiat_p384_addcarryx_u32(&x97, &x98, x96, 0x0, x62);
+ fiat_p384_addcarryx_u32(&x97, &x98, x96, x62, 0x0);
uint32_t x99;
fiat_p384_uint1 x100;
- fiat_p384_addcarryx_u32(&x99, &x100, 0x0, x79, x35);
+ fiat_p384_addcarryx_u32(&x99, &x100, 0x0, x35, x79);
uint32_t x101;
fiat_p384_uint1 x102;
- fiat_p384_addcarryx_u32(&x101, &x102, x100, x80, x37);
+ fiat_p384_addcarryx_u32(&x101, &x102, x100, x37, x80);
uint32_t x103;
fiat_p384_uint1 x104;
- fiat_p384_addcarryx_u32(&x103, &x104, x102, 0x0, x39);
+ fiat_p384_addcarryx_u32(&x103, &x104, x102, x39, 0x0);
uint32_t x105;
fiat_p384_uint1 x106;
- fiat_p384_addcarryx_u32(&x105, &x106, x104, x77, x41);
+ fiat_p384_addcarryx_u32(&x105, &x106, x104, x41, x77);
uint32_t x107;
fiat_p384_uint1 x108;
- fiat_p384_addcarryx_u32(&x107, &x108, x106, x81, x43);
+ fiat_p384_addcarryx_u32(&x107, &x108, x106, x43, x81);
uint32_t x109;
fiat_p384_uint1 x110;
- fiat_p384_addcarryx_u32(&x109, &x110, x108, x83, x45);
+ fiat_p384_addcarryx_u32(&x109, &x110, x108, x45, x83);
uint32_t x111;
fiat_p384_uint1 x112;
- fiat_p384_addcarryx_u32(&x111, &x112, x110, x85, x47);
+ fiat_p384_addcarryx_u32(&x111, &x112, x110, x47, x85);
uint32_t x113;
fiat_p384_uint1 x114;
- fiat_p384_addcarryx_u32(&x113, &x114, x112, x87, x49);
+ fiat_p384_addcarryx_u32(&x113, &x114, x112, x49, x87);
uint32_t x115;
fiat_p384_uint1 x116;
- fiat_p384_addcarryx_u32(&x115, &x116, x114, x89, x51);
+ fiat_p384_addcarryx_u32(&x115, &x116, x114, x51, x89);
uint32_t x117;
fiat_p384_uint1 x118;
- fiat_p384_addcarryx_u32(&x117, &x118, x116, x91, x53);
+ fiat_p384_addcarryx_u32(&x117, &x118, x116, x53, x91);
uint32_t x119;
fiat_p384_uint1 x120;
- fiat_p384_addcarryx_u32(&x119, &x120, x118, x93, x55);
+ fiat_p384_addcarryx_u32(&x119, &x120, x118, x55, x93);
uint32_t x121;
fiat_p384_uint1 x122;
- fiat_p384_addcarryx_u32(&x121, &x122, x120, x95, x57);
+ fiat_p384_addcarryx_u32(&x121, &x122, x120, x57, x95);
uint32_t x123;
fiat_p384_uint1 x124;
- fiat_p384_addcarryx_u32(&x123, &x124, x122, x97, x59);
+ fiat_p384_addcarryx_u32(&x123, &x124, x122, x59, x97);
uint32_t x125;
fiat_p384_uint1 x126;
fiat_p384_addcarryx_u32(&x125, &x126, x124, 0x0, 0x0);
@@ -2921,79 +2921,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x149, &x150, x1, (arg1[0]));
uint32_t x151;
fiat_p384_uint1 x152;
- fiat_p384_addcarryx_u32(&x151, &x152, 0x0, x147, x150);
+ fiat_p384_addcarryx_u32(&x151, &x152, 0x0, x150, x147);
uint32_t x153;
fiat_p384_uint1 x154;
- fiat_p384_addcarryx_u32(&x153, &x154, x152, x145, x148);
+ fiat_p384_addcarryx_u32(&x153, &x154, x152, x148, x145);
uint32_t x155;
fiat_p384_uint1 x156;
- fiat_p384_addcarryx_u32(&x155, &x156, x154, x143, x146);
+ fiat_p384_addcarryx_u32(&x155, &x156, x154, x146, x143);
uint32_t x157;
fiat_p384_uint1 x158;
- fiat_p384_addcarryx_u32(&x157, &x158, x156, x141, x144);
+ fiat_p384_addcarryx_u32(&x157, &x158, x156, x144, x141);
uint32_t x159;
fiat_p384_uint1 x160;
- fiat_p384_addcarryx_u32(&x159, &x160, x158, x139, x142);
+ fiat_p384_addcarryx_u32(&x159, &x160, x158, x142, x139);
uint32_t x161;
fiat_p384_uint1 x162;
- fiat_p384_addcarryx_u32(&x161, &x162, x160, x137, x140);
+ fiat_p384_addcarryx_u32(&x161, &x162, x160, x140, x137);
uint32_t x163;
fiat_p384_uint1 x164;
- fiat_p384_addcarryx_u32(&x163, &x164, x162, x135, x138);
+ fiat_p384_addcarryx_u32(&x163, &x164, x162, x138, x135);
uint32_t x165;
fiat_p384_uint1 x166;
- fiat_p384_addcarryx_u32(&x165, &x166, x164, x133, x136);
+ fiat_p384_addcarryx_u32(&x165, &x166, x164, x136, x133);
uint32_t x167;
fiat_p384_uint1 x168;
- fiat_p384_addcarryx_u32(&x167, &x168, x166, x131, x134);
+ fiat_p384_addcarryx_u32(&x167, &x168, x166, x134, x131);
uint32_t x169;
fiat_p384_uint1 x170;
- fiat_p384_addcarryx_u32(&x169, &x170, x168, x129, x132);
+ fiat_p384_addcarryx_u32(&x169, &x170, x168, x132, x129);
uint32_t x171;
fiat_p384_uint1 x172;
- fiat_p384_addcarryx_u32(&x171, &x172, x170, x127, x130);
+ fiat_p384_addcarryx_u32(&x171, &x172, x170, x130, x127);
uint32_t x173;
fiat_p384_uint1 x174;
- fiat_p384_addcarryx_u32(&x173, &x174, x172, 0x0, x128);
+ fiat_p384_addcarryx_u32(&x173, &x174, x172, x128, 0x0);
uint32_t x175;
fiat_p384_uint1 x176;
- fiat_p384_addcarryx_u32(&x175, &x176, 0x0, x149, x101);
+ fiat_p384_addcarryx_u32(&x175, &x176, 0x0, x101, x149);
uint32_t x177;
fiat_p384_uint1 x178;
- fiat_p384_addcarryx_u32(&x177, &x178, x176, x151, x103);
+ fiat_p384_addcarryx_u32(&x177, &x178, x176, x103, x151);
uint32_t x179;
fiat_p384_uint1 x180;
- fiat_p384_addcarryx_u32(&x179, &x180, x178, x153, x105);
+ fiat_p384_addcarryx_u32(&x179, &x180, x178, x105, x153);
uint32_t x181;
fiat_p384_uint1 x182;
- fiat_p384_addcarryx_u32(&x181, &x182, x180, x155, x107);
+ fiat_p384_addcarryx_u32(&x181, &x182, x180, x107, x155);
uint32_t x183;
fiat_p384_uint1 x184;
- fiat_p384_addcarryx_u32(&x183, &x184, x182, x157, x109);
+ fiat_p384_addcarryx_u32(&x183, &x184, x182, x109, x157);
uint32_t x185;
fiat_p384_uint1 x186;
- fiat_p384_addcarryx_u32(&x185, &x186, x184, x159, x111);
+ fiat_p384_addcarryx_u32(&x185, &x186, x184, x111, x159);
uint32_t x187;
fiat_p384_uint1 x188;
- fiat_p384_addcarryx_u32(&x187, &x188, x186, x161, x113);
+ fiat_p384_addcarryx_u32(&x187, &x188, x186, x113, x161);
uint32_t x189;
fiat_p384_uint1 x190;
- fiat_p384_addcarryx_u32(&x189, &x190, x188, x163, x115);
+ fiat_p384_addcarryx_u32(&x189, &x190, x188, x115, x163);
uint32_t x191;
fiat_p384_uint1 x192;
- fiat_p384_addcarryx_u32(&x191, &x192, x190, x165, x117);
+ fiat_p384_addcarryx_u32(&x191, &x192, x190, x117, x165);
uint32_t x193;
fiat_p384_uint1 x194;
- fiat_p384_addcarryx_u32(&x193, &x194, x192, x167, x119);
+ fiat_p384_addcarryx_u32(&x193, &x194, x192, x119, x167);
uint32_t x195;
fiat_p384_uint1 x196;
- fiat_p384_addcarryx_u32(&x195, &x196, x194, x169, x121);
+ fiat_p384_addcarryx_u32(&x195, &x196, x194, x121, x169);
uint32_t x197;
fiat_p384_uint1 x198;
- fiat_p384_addcarryx_u32(&x197, &x198, x196, x171, x123);
+ fiat_p384_addcarryx_u32(&x197, &x198, x196, x123, x171);
uint32_t x199;
fiat_p384_uint1 x200;
- fiat_p384_addcarryx_u32(&x199, &x200, x198, x173, (fiat_p384_uint1)x125);
+ fiat_p384_addcarryx_u32(&x199, &x200, x198, (fiat_p384_uint1)x125, x173);
uint32_t x201;
uint32_t x202;
fiat_p384_mulx_u32(&x201, &x202, x175, UINT32_C(0xffffffff));
@@ -3026,73 +3026,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x219, &x220, x175, UINT32_C(0xffffffff));
uint32_t x221;
fiat_p384_uint1 x222;
- fiat_p384_addcarryx_u32(&x221, &x222, 0x0, x215, x218);
+ fiat_p384_addcarryx_u32(&x221, &x222, 0x0, x218, x215);
uint32_t x223;
fiat_p384_uint1 x224;
- fiat_p384_addcarryx_u32(&x223, &x224, x222, x213, x216);
+ fiat_p384_addcarryx_u32(&x223, &x224, x222, x216, x213);
uint32_t x225;
fiat_p384_uint1 x226;
- fiat_p384_addcarryx_u32(&x225, &x226, x224, x211, x214);
+ fiat_p384_addcarryx_u32(&x225, &x226, x224, x214, x211);
uint32_t x227;
fiat_p384_uint1 x228;
- fiat_p384_addcarryx_u32(&x227, &x228, x226, x209, x212);
+ fiat_p384_addcarryx_u32(&x227, &x228, x226, x212, x209);
uint32_t x229;
fiat_p384_uint1 x230;
- fiat_p384_addcarryx_u32(&x229, &x230, x228, x207, x210);
+ fiat_p384_addcarryx_u32(&x229, &x230, x228, x210, x207);
uint32_t x231;
fiat_p384_uint1 x232;
- fiat_p384_addcarryx_u32(&x231, &x232, x230, x205, x208);
+ fiat_p384_addcarryx_u32(&x231, &x232, x230, x208, x205);
uint32_t x233;
fiat_p384_uint1 x234;
- fiat_p384_addcarryx_u32(&x233, &x234, x232, x203, x206);
+ fiat_p384_addcarryx_u32(&x233, &x234, x232, x206, x203);
uint32_t x235;
fiat_p384_uint1 x236;
- fiat_p384_addcarryx_u32(&x235, &x236, x234, x201, x204);
+ fiat_p384_addcarryx_u32(&x235, &x236, x234, x204, x201);
uint32_t x237;
fiat_p384_uint1 x238;
- fiat_p384_addcarryx_u32(&x237, &x238, x236, 0x0, x202);
+ fiat_p384_addcarryx_u32(&x237, &x238, x236, x202, 0x0);
uint32_t x239;
fiat_p384_uint1 x240;
- fiat_p384_addcarryx_u32(&x239, &x240, 0x0, x219, x175);
+ fiat_p384_addcarryx_u32(&x239, &x240, 0x0, x175, x219);
uint32_t x241;
fiat_p384_uint1 x242;
- fiat_p384_addcarryx_u32(&x241, &x242, x240, x220, x177);
+ fiat_p384_addcarryx_u32(&x241, &x242, x240, x177, x220);
uint32_t x243;
fiat_p384_uint1 x244;
- fiat_p384_addcarryx_u32(&x243, &x244, x242, 0x0, x179);
+ fiat_p384_addcarryx_u32(&x243, &x244, x242, x179, 0x0);
uint32_t x245;
fiat_p384_uint1 x246;
- fiat_p384_addcarryx_u32(&x245, &x246, x244, x217, x181);
+ fiat_p384_addcarryx_u32(&x245, &x246, x244, x181, x217);
uint32_t x247;
fiat_p384_uint1 x248;
- fiat_p384_addcarryx_u32(&x247, &x248, x246, x221, x183);
+ fiat_p384_addcarryx_u32(&x247, &x248, x246, x183, x221);
uint32_t x249;
fiat_p384_uint1 x250;
- fiat_p384_addcarryx_u32(&x249, &x250, x248, x223, x185);
+ fiat_p384_addcarryx_u32(&x249, &x250, x248, x185, x223);
uint32_t x251;
fiat_p384_uint1 x252;
- fiat_p384_addcarryx_u32(&x251, &x252, x250, x225, x187);
+ fiat_p384_addcarryx_u32(&x251, &x252, x250, x187, x225);
uint32_t x253;
fiat_p384_uint1 x254;
- fiat_p384_addcarryx_u32(&x253, &x254, x252, x227, x189);
+ fiat_p384_addcarryx_u32(&x253, &x254, x252, x189, x227);
uint32_t x255;
fiat_p384_uint1 x256;
- fiat_p384_addcarryx_u32(&x255, &x256, x254, x229, x191);
+ fiat_p384_addcarryx_u32(&x255, &x256, x254, x191, x229);
uint32_t x257;
fiat_p384_uint1 x258;
- fiat_p384_addcarryx_u32(&x257, &x258, x256, x231, x193);
+ fiat_p384_addcarryx_u32(&x257, &x258, x256, x193, x231);
uint32_t x259;
fiat_p384_uint1 x260;
- fiat_p384_addcarryx_u32(&x259, &x260, x258, x233, x195);
+ fiat_p384_addcarryx_u32(&x259, &x260, x258, x195, x233);
uint32_t x261;
fiat_p384_uint1 x262;
- fiat_p384_addcarryx_u32(&x261, &x262, x260, x235, x197);
+ fiat_p384_addcarryx_u32(&x261, &x262, x260, x197, x235);
uint32_t x263;
fiat_p384_uint1 x264;
- fiat_p384_addcarryx_u32(&x263, &x264, x262, x237, x199);
+ fiat_p384_addcarryx_u32(&x263, &x264, x262, x199, x237);
uint32_t x265;
fiat_p384_uint1 x266;
- fiat_p384_addcarryx_u32(&x265, &x266, x264, 0x0, x200);
+ fiat_p384_addcarryx_u32(&x265, &x266, x264, x200, 0x0);
uint32_t x267;
uint32_t x268;
fiat_p384_mulx_u32(&x267, &x268, x2, (arg1[11]));
@@ -3131,79 +3131,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x289, &x290, x2, (arg1[0]));
uint32_t x291;
fiat_p384_uint1 x292;
- fiat_p384_addcarryx_u32(&x291, &x292, 0x0, x287, x290);
+ fiat_p384_addcarryx_u32(&x291, &x292, 0x0, x290, x287);
uint32_t x293;
fiat_p384_uint1 x294;
- fiat_p384_addcarryx_u32(&x293, &x294, x292, x285, x288);
+ fiat_p384_addcarryx_u32(&x293, &x294, x292, x288, x285);
uint32_t x295;
fiat_p384_uint1 x296;
- fiat_p384_addcarryx_u32(&x295, &x296, x294, x283, x286);
+ fiat_p384_addcarryx_u32(&x295, &x296, x294, x286, x283);
uint32_t x297;
fiat_p384_uint1 x298;
- fiat_p384_addcarryx_u32(&x297, &x298, x296, x281, x284);
+ fiat_p384_addcarryx_u32(&x297, &x298, x296, x284, x281);
uint32_t x299;
fiat_p384_uint1 x300;
- fiat_p384_addcarryx_u32(&x299, &x300, x298, x279, x282);
+ fiat_p384_addcarryx_u32(&x299, &x300, x298, x282, x279);
uint32_t x301;
fiat_p384_uint1 x302;
- fiat_p384_addcarryx_u32(&x301, &x302, x300, x277, x280);
+ fiat_p384_addcarryx_u32(&x301, &x302, x300, x280, x277);
uint32_t x303;
fiat_p384_uint1 x304;
- fiat_p384_addcarryx_u32(&x303, &x304, x302, x275, x278);
+ fiat_p384_addcarryx_u32(&x303, &x304, x302, x278, x275);
uint32_t x305;
fiat_p384_uint1 x306;
- fiat_p384_addcarryx_u32(&x305, &x306, x304, x273, x276);
+ fiat_p384_addcarryx_u32(&x305, &x306, x304, x276, x273);
uint32_t x307;
fiat_p384_uint1 x308;
- fiat_p384_addcarryx_u32(&x307, &x308, x306, x271, x274);
+ fiat_p384_addcarryx_u32(&x307, &x308, x306, x274, x271);
uint32_t x309;
fiat_p384_uint1 x310;
- fiat_p384_addcarryx_u32(&x309, &x310, x308, x269, x272);
+ fiat_p384_addcarryx_u32(&x309, &x310, x308, x272, x269);
uint32_t x311;
fiat_p384_uint1 x312;
- fiat_p384_addcarryx_u32(&x311, &x312, x310, x267, x270);
+ fiat_p384_addcarryx_u32(&x311, &x312, x310, x270, x267);
uint32_t x313;
fiat_p384_uint1 x314;
- fiat_p384_addcarryx_u32(&x313, &x314, x312, 0x0, x268);
+ fiat_p384_addcarryx_u32(&x313, &x314, x312, x268, 0x0);
uint32_t x315;
fiat_p384_uint1 x316;
- fiat_p384_addcarryx_u32(&x315, &x316, 0x0, x289, x241);
+ fiat_p384_addcarryx_u32(&x315, &x316, 0x0, x241, x289);
uint32_t x317;
fiat_p384_uint1 x318;
- fiat_p384_addcarryx_u32(&x317, &x318, x316, x291, x243);
+ fiat_p384_addcarryx_u32(&x317, &x318, x316, x243, x291);
uint32_t x319;
fiat_p384_uint1 x320;
- fiat_p384_addcarryx_u32(&x319, &x320, x318, x293, x245);
+ fiat_p384_addcarryx_u32(&x319, &x320, x318, x245, x293);
uint32_t x321;
fiat_p384_uint1 x322;
- fiat_p384_addcarryx_u32(&x321, &x322, x320, x295, x247);
+ fiat_p384_addcarryx_u32(&x321, &x322, x320, x247, x295);
uint32_t x323;
fiat_p384_uint1 x324;
- fiat_p384_addcarryx_u32(&x323, &x324, x322, x297, x249);
+ fiat_p384_addcarryx_u32(&x323, &x324, x322, x249, x297);
uint32_t x325;
fiat_p384_uint1 x326;
- fiat_p384_addcarryx_u32(&x325, &x326, x324, x299, x251);
+ fiat_p384_addcarryx_u32(&x325, &x326, x324, x251, x299);
uint32_t x327;
fiat_p384_uint1 x328;
- fiat_p384_addcarryx_u32(&x327, &x328, x326, x301, x253);
+ fiat_p384_addcarryx_u32(&x327, &x328, x326, x253, x301);
uint32_t x329;
fiat_p384_uint1 x330;
- fiat_p384_addcarryx_u32(&x329, &x330, x328, x303, x255);
+ fiat_p384_addcarryx_u32(&x329, &x330, x328, x255, x303);
uint32_t x331;
fiat_p384_uint1 x332;
- fiat_p384_addcarryx_u32(&x331, &x332, x330, x305, x257);
+ fiat_p384_addcarryx_u32(&x331, &x332, x330, x257, x305);
uint32_t x333;
fiat_p384_uint1 x334;
- fiat_p384_addcarryx_u32(&x333, &x334, x332, x307, x259);
+ fiat_p384_addcarryx_u32(&x333, &x334, x332, x259, x307);
uint32_t x335;
fiat_p384_uint1 x336;
- fiat_p384_addcarryx_u32(&x335, &x336, x334, x309, x261);
+ fiat_p384_addcarryx_u32(&x335, &x336, x334, x261, x309);
uint32_t x337;
fiat_p384_uint1 x338;
- fiat_p384_addcarryx_u32(&x337, &x338, x336, x311, x263);
+ fiat_p384_addcarryx_u32(&x337, &x338, x336, x263, x311);
uint32_t x339;
fiat_p384_uint1 x340;
- fiat_p384_addcarryx_u32(&x339, &x340, x338, x313, x265);
+ fiat_p384_addcarryx_u32(&x339, &x340, x338, x265, x313);
uint32_t x341;
uint32_t x342;
fiat_p384_mulx_u32(&x341, &x342, x315, UINT32_C(0xffffffff));
@@ -3236,73 +3236,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x359, &x360, x315, UINT32_C(0xffffffff));
uint32_t x361;
fiat_p384_uint1 x362;
- fiat_p384_addcarryx_u32(&x361, &x362, 0x0, x355, x358);
+ fiat_p384_addcarryx_u32(&x361, &x362, 0x0, x358, x355);
uint32_t x363;
fiat_p384_uint1 x364;
- fiat_p384_addcarryx_u32(&x363, &x364, x362, x353, x356);
+ fiat_p384_addcarryx_u32(&x363, &x364, x362, x356, x353);
uint32_t x365;
fiat_p384_uint1 x366;
- fiat_p384_addcarryx_u32(&x365, &x366, x364, x351, x354);
+ fiat_p384_addcarryx_u32(&x365, &x366, x364, x354, x351);
uint32_t x367;
fiat_p384_uint1 x368;
- fiat_p384_addcarryx_u32(&x367, &x368, x366, x349, x352);
+ fiat_p384_addcarryx_u32(&x367, &x368, x366, x352, x349);
uint32_t x369;
fiat_p384_uint1 x370;
- fiat_p384_addcarryx_u32(&x369, &x370, x368, x347, x350);
+ fiat_p384_addcarryx_u32(&x369, &x370, x368, x350, x347);
uint32_t x371;
fiat_p384_uint1 x372;
- fiat_p384_addcarryx_u32(&x371, &x372, x370, x345, x348);
+ fiat_p384_addcarryx_u32(&x371, &x372, x370, x348, x345);
uint32_t x373;
fiat_p384_uint1 x374;
- fiat_p384_addcarryx_u32(&x373, &x374, x372, x343, x346);
+ fiat_p384_addcarryx_u32(&x373, &x374, x372, x346, x343);
uint32_t x375;
fiat_p384_uint1 x376;
- fiat_p384_addcarryx_u32(&x375, &x376, x374, x341, x344);
+ fiat_p384_addcarryx_u32(&x375, &x376, x374, x344, x341);
uint32_t x377;
fiat_p384_uint1 x378;
- fiat_p384_addcarryx_u32(&x377, &x378, x376, 0x0, x342);
+ fiat_p384_addcarryx_u32(&x377, &x378, x376, x342, 0x0);
uint32_t x379;
fiat_p384_uint1 x380;
- fiat_p384_addcarryx_u32(&x379, &x380, 0x0, x359, x315);
+ fiat_p384_addcarryx_u32(&x379, &x380, 0x0, x315, x359);
uint32_t x381;
fiat_p384_uint1 x382;
- fiat_p384_addcarryx_u32(&x381, &x382, x380, x360, x317);
+ fiat_p384_addcarryx_u32(&x381, &x382, x380, x317, x360);
uint32_t x383;
fiat_p384_uint1 x384;
- fiat_p384_addcarryx_u32(&x383, &x384, x382, 0x0, x319);
+ fiat_p384_addcarryx_u32(&x383, &x384, x382, x319, 0x0);
uint32_t x385;
fiat_p384_uint1 x386;
- fiat_p384_addcarryx_u32(&x385, &x386, x384, x357, x321);
+ fiat_p384_addcarryx_u32(&x385, &x386, x384, x321, x357);
uint32_t x387;
fiat_p384_uint1 x388;
- fiat_p384_addcarryx_u32(&x387, &x388, x386, x361, x323);
+ fiat_p384_addcarryx_u32(&x387, &x388, x386, x323, x361);
uint32_t x389;
fiat_p384_uint1 x390;
- fiat_p384_addcarryx_u32(&x389, &x390, x388, x363, x325);
+ fiat_p384_addcarryx_u32(&x389, &x390, x388, x325, x363);
uint32_t x391;
fiat_p384_uint1 x392;
- fiat_p384_addcarryx_u32(&x391, &x392, x390, x365, x327);
+ fiat_p384_addcarryx_u32(&x391, &x392, x390, x327, x365);
uint32_t x393;
fiat_p384_uint1 x394;
- fiat_p384_addcarryx_u32(&x393, &x394, x392, x367, x329);
+ fiat_p384_addcarryx_u32(&x393, &x394, x392, x329, x367);
uint32_t x395;
fiat_p384_uint1 x396;
- fiat_p384_addcarryx_u32(&x395, &x396, x394, x369, x331);
+ fiat_p384_addcarryx_u32(&x395, &x396, x394, x331, x369);
uint32_t x397;
fiat_p384_uint1 x398;
- fiat_p384_addcarryx_u32(&x397, &x398, x396, x371, x333);
+ fiat_p384_addcarryx_u32(&x397, &x398, x396, x333, x371);
uint32_t x399;
fiat_p384_uint1 x400;
- fiat_p384_addcarryx_u32(&x399, &x400, x398, x373, x335);
+ fiat_p384_addcarryx_u32(&x399, &x400, x398, x335, x373);
uint32_t x401;
fiat_p384_uint1 x402;
- fiat_p384_addcarryx_u32(&x401, &x402, x400, x375, x337);
+ fiat_p384_addcarryx_u32(&x401, &x402, x400, x337, x375);
uint32_t x403;
fiat_p384_uint1 x404;
- fiat_p384_addcarryx_u32(&x403, &x404, x402, x377, x339);
+ fiat_p384_addcarryx_u32(&x403, &x404, x402, x339, x377);
uint32_t x405;
fiat_p384_uint1 x406;
- fiat_p384_addcarryx_u32(&x405, &x406, x404, 0x0, x340);
+ fiat_p384_addcarryx_u32(&x405, &x406, x404, x340, 0x0);
uint32_t x407;
uint32_t x408;
fiat_p384_mulx_u32(&x407, &x408, x3, (arg1[11]));
@@ -3341,79 +3341,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x429, &x430, x3, (arg1[0]));
uint32_t x431;
fiat_p384_uint1 x432;
- fiat_p384_addcarryx_u32(&x431, &x432, 0x0, x427, x430);
+ fiat_p384_addcarryx_u32(&x431, &x432, 0x0, x430, x427);
uint32_t x433;
fiat_p384_uint1 x434;
- fiat_p384_addcarryx_u32(&x433, &x434, x432, x425, x428);
+ fiat_p384_addcarryx_u32(&x433, &x434, x432, x428, x425);
uint32_t x435;
fiat_p384_uint1 x436;
- fiat_p384_addcarryx_u32(&x435, &x436, x434, x423, x426);
+ fiat_p384_addcarryx_u32(&x435, &x436, x434, x426, x423);
uint32_t x437;
fiat_p384_uint1 x438;
- fiat_p384_addcarryx_u32(&x437, &x438, x436, x421, x424);
+ fiat_p384_addcarryx_u32(&x437, &x438, x436, x424, x421);
uint32_t x439;
fiat_p384_uint1 x440;
- fiat_p384_addcarryx_u32(&x439, &x440, x438, x419, x422);
+ fiat_p384_addcarryx_u32(&x439, &x440, x438, x422, x419);
uint32_t x441;
fiat_p384_uint1 x442;
- fiat_p384_addcarryx_u32(&x441, &x442, x440, x417, x420);
+ fiat_p384_addcarryx_u32(&x441, &x442, x440, x420, x417);
uint32_t x443;
fiat_p384_uint1 x444;
- fiat_p384_addcarryx_u32(&x443, &x444, x442, x415, x418);
+ fiat_p384_addcarryx_u32(&x443, &x444, x442, x418, x415);
uint32_t x445;
fiat_p384_uint1 x446;
- fiat_p384_addcarryx_u32(&x445, &x446, x444, x413, x416);
+ fiat_p384_addcarryx_u32(&x445, &x446, x444, x416, x413);
uint32_t x447;
fiat_p384_uint1 x448;
- fiat_p384_addcarryx_u32(&x447, &x448, x446, x411, x414);
+ fiat_p384_addcarryx_u32(&x447, &x448, x446, x414, x411);
uint32_t x449;
fiat_p384_uint1 x450;
- fiat_p384_addcarryx_u32(&x449, &x450, x448, x409, x412);
+ fiat_p384_addcarryx_u32(&x449, &x450, x448, x412, x409);
uint32_t x451;
fiat_p384_uint1 x452;
- fiat_p384_addcarryx_u32(&x451, &x452, x450, x407, x410);
+ fiat_p384_addcarryx_u32(&x451, &x452, x450, x410, x407);
uint32_t x453;
fiat_p384_uint1 x454;
- fiat_p384_addcarryx_u32(&x453, &x454, x452, 0x0, x408);
+ fiat_p384_addcarryx_u32(&x453, &x454, x452, x408, 0x0);
uint32_t x455;
fiat_p384_uint1 x456;
- fiat_p384_addcarryx_u32(&x455, &x456, 0x0, x429, x381);
+ fiat_p384_addcarryx_u32(&x455, &x456, 0x0, x381, x429);
uint32_t x457;
fiat_p384_uint1 x458;
- fiat_p384_addcarryx_u32(&x457, &x458, x456, x431, x383);
+ fiat_p384_addcarryx_u32(&x457, &x458, x456, x383, x431);
uint32_t x459;
fiat_p384_uint1 x460;
- fiat_p384_addcarryx_u32(&x459, &x460, x458, x433, x385);
+ fiat_p384_addcarryx_u32(&x459, &x460, x458, x385, x433);
uint32_t x461;
fiat_p384_uint1 x462;
- fiat_p384_addcarryx_u32(&x461, &x462, x460, x435, x387);
+ fiat_p384_addcarryx_u32(&x461, &x462, x460, x387, x435);
uint32_t x463;
fiat_p384_uint1 x464;
- fiat_p384_addcarryx_u32(&x463, &x464, x462, x437, x389);
+ fiat_p384_addcarryx_u32(&x463, &x464, x462, x389, x437);
uint32_t x465;
fiat_p384_uint1 x466;
- fiat_p384_addcarryx_u32(&x465, &x466, x464, x439, x391);
+ fiat_p384_addcarryx_u32(&x465, &x466, x464, x391, x439);
uint32_t x467;
fiat_p384_uint1 x468;
- fiat_p384_addcarryx_u32(&x467, &x468, x466, x441, x393);
+ fiat_p384_addcarryx_u32(&x467, &x468, x466, x393, x441);
uint32_t x469;
fiat_p384_uint1 x470;
- fiat_p384_addcarryx_u32(&x469, &x470, x468, x443, x395);
+ fiat_p384_addcarryx_u32(&x469, &x470, x468, x395, x443);
uint32_t x471;
fiat_p384_uint1 x472;
- fiat_p384_addcarryx_u32(&x471, &x472, x470, x445, x397);
+ fiat_p384_addcarryx_u32(&x471, &x472, x470, x397, x445);
uint32_t x473;
fiat_p384_uint1 x474;
- fiat_p384_addcarryx_u32(&x473, &x474, x472, x447, x399);
+ fiat_p384_addcarryx_u32(&x473, &x474, x472, x399, x447);
uint32_t x475;
fiat_p384_uint1 x476;
- fiat_p384_addcarryx_u32(&x475, &x476, x474, x449, x401);
+ fiat_p384_addcarryx_u32(&x475, &x476, x474, x401, x449);
uint32_t x477;
fiat_p384_uint1 x478;
- fiat_p384_addcarryx_u32(&x477, &x478, x476, x451, x403);
+ fiat_p384_addcarryx_u32(&x477, &x478, x476, x403, x451);
uint32_t x479;
fiat_p384_uint1 x480;
- fiat_p384_addcarryx_u32(&x479, &x480, x478, x453, x405);
+ fiat_p384_addcarryx_u32(&x479, &x480, x478, x405, x453);
uint32_t x481;
uint32_t x482;
fiat_p384_mulx_u32(&x481, &x482, x455, UINT32_C(0xffffffff));
@@ -3446,73 +3446,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x499, &x500, x455, UINT32_C(0xffffffff));
uint32_t x501;
fiat_p384_uint1 x502;
- fiat_p384_addcarryx_u32(&x501, &x502, 0x0, x495, x498);
+ fiat_p384_addcarryx_u32(&x501, &x502, 0x0, x498, x495);
uint32_t x503;
fiat_p384_uint1 x504;
- fiat_p384_addcarryx_u32(&x503, &x504, x502, x493, x496);
+ fiat_p384_addcarryx_u32(&x503, &x504, x502, x496, x493);
uint32_t x505;
fiat_p384_uint1 x506;
- fiat_p384_addcarryx_u32(&x505, &x506, x504, x491, x494);
+ fiat_p384_addcarryx_u32(&x505, &x506, x504, x494, x491);
uint32_t x507;
fiat_p384_uint1 x508;
- fiat_p384_addcarryx_u32(&x507, &x508, x506, x489, x492);
+ fiat_p384_addcarryx_u32(&x507, &x508, x506, x492, x489);
uint32_t x509;
fiat_p384_uint1 x510;
- fiat_p384_addcarryx_u32(&x509, &x510, x508, x487, x490);
+ fiat_p384_addcarryx_u32(&x509, &x510, x508, x490, x487);
uint32_t x511;
fiat_p384_uint1 x512;
- fiat_p384_addcarryx_u32(&x511, &x512, x510, x485, x488);
+ fiat_p384_addcarryx_u32(&x511, &x512, x510, x488, x485);
uint32_t x513;
fiat_p384_uint1 x514;
- fiat_p384_addcarryx_u32(&x513, &x514, x512, x483, x486);
+ fiat_p384_addcarryx_u32(&x513, &x514, x512, x486, x483);
uint32_t x515;
fiat_p384_uint1 x516;
- fiat_p384_addcarryx_u32(&x515, &x516, x514, x481, x484);
+ fiat_p384_addcarryx_u32(&x515, &x516, x514, x484, x481);
uint32_t x517;
fiat_p384_uint1 x518;
- fiat_p384_addcarryx_u32(&x517, &x518, x516, 0x0, x482);
+ fiat_p384_addcarryx_u32(&x517, &x518, x516, x482, 0x0);
uint32_t x519;
fiat_p384_uint1 x520;
- fiat_p384_addcarryx_u32(&x519, &x520, 0x0, x499, x455);
+ fiat_p384_addcarryx_u32(&x519, &x520, 0x0, x455, x499);
uint32_t x521;
fiat_p384_uint1 x522;
- fiat_p384_addcarryx_u32(&x521, &x522, x520, x500, x457);
+ fiat_p384_addcarryx_u32(&x521, &x522, x520, x457, x500);
uint32_t x523;
fiat_p384_uint1 x524;
- fiat_p384_addcarryx_u32(&x523, &x524, x522, 0x0, x459);
+ fiat_p384_addcarryx_u32(&x523, &x524, x522, x459, 0x0);
uint32_t x525;
fiat_p384_uint1 x526;
- fiat_p384_addcarryx_u32(&x525, &x526, x524, x497, x461);
+ fiat_p384_addcarryx_u32(&x525, &x526, x524, x461, x497);
uint32_t x527;
fiat_p384_uint1 x528;
- fiat_p384_addcarryx_u32(&x527, &x528, x526, x501, x463);
+ fiat_p384_addcarryx_u32(&x527, &x528, x526, x463, x501);
uint32_t x529;
fiat_p384_uint1 x530;
- fiat_p384_addcarryx_u32(&x529, &x530, x528, x503, x465);
+ fiat_p384_addcarryx_u32(&x529, &x530, x528, x465, x503);
uint32_t x531;
fiat_p384_uint1 x532;
- fiat_p384_addcarryx_u32(&x531, &x532, x530, x505, x467);
+ fiat_p384_addcarryx_u32(&x531, &x532, x530, x467, x505);
uint32_t x533;
fiat_p384_uint1 x534;
- fiat_p384_addcarryx_u32(&x533, &x534, x532, x507, x469);
+ fiat_p384_addcarryx_u32(&x533, &x534, x532, x469, x507);
uint32_t x535;
fiat_p384_uint1 x536;
- fiat_p384_addcarryx_u32(&x535, &x536, x534, x509, x471);
+ fiat_p384_addcarryx_u32(&x535, &x536, x534, x471, x509);
uint32_t x537;
fiat_p384_uint1 x538;
- fiat_p384_addcarryx_u32(&x537, &x538, x536, x511, x473);
+ fiat_p384_addcarryx_u32(&x537, &x538, x536, x473, x511);
uint32_t x539;
fiat_p384_uint1 x540;
- fiat_p384_addcarryx_u32(&x539, &x540, x538, x513, x475);
+ fiat_p384_addcarryx_u32(&x539, &x540, x538, x475, x513);
uint32_t x541;
fiat_p384_uint1 x542;
- fiat_p384_addcarryx_u32(&x541, &x542, x540, x515, x477);
+ fiat_p384_addcarryx_u32(&x541, &x542, x540, x477, x515);
uint32_t x543;
fiat_p384_uint1 x544;
- fiat_p384_addcarryx_u32(&x543, &x544, x542, x517, x479);
+ fiat_p384_addcarryx_u32(&x543, &x544, x542, x479, x517);
uint32_t x545;
fiat_p384_uint1 x546;
- fiat_p384_addcarryx_u32(&x545, &x546, x544, 0x0, x480);
+ fiat_p384_addcarryx_u32(&x545, &x546, x544, x480, 0x0);
uint32_t x547;
uint32_t x548;
fiat_p384_mulx_u32(&x547, &x548, x4, (arg1[11]));
@@ -3551,79 +3551,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x569, &x570, x4, (arg1[0]));
uint32_t x571;
fiat_p384_uint1 x572;
- fiat_p384_addcarryx_u32(&x571, &x572, 0x0, x567, x570);
+ fiat_p384_addcarryx_u32(&x571, &x572, 0x0, x570, x567);
uint32_t x573;
fiat_p384_uint1 x574;
- fiat_p384_addcarryx_u32(&x573, &x574, x572, x565, x568);
+ fiat_p384_addcarryx_u32(&x573, &x574, x572, x568, x565);
uint32_t x575;
fiat_p384_uint1 x576;
- fiat_p384_addcarryx_u32(&x575, &x576, x574, x563, x566);
+ fiat_p384_addcarryx_u32(&x575, &x576, x574, x566, x563);
uint32_t x577;
fiat_p384_uint1 x578;
- fiat_p384_addcarryx_u32(&x577, &x578, x576, x561, x564);
+ fiat_p384_addcarryx_u32(&x577, &x578, x576, x564, x561);
uint32_t x579;
fiat_p384_uint1 x580;
- fiat_p384_addcarryx_u32(&x579, &x580, x578, x559, x562);
+ fiat_p384_addcarryx_u32(&x579, &x580, x578, x562, x559);
uint32_t x581;
fiat_p384_uint1 x582;
- fiat_p384_addcarryx_u32(&x581, &x582, x580, x557, x560);
+ fiat_p384_addcarryx_u32(&x581, &x582, x580, x560, x557);
uint32_t x583;
fiat_p384_uint1 x584;
- fiat_p384_addcarryx_u32(&x583, &x584, x582, x555, x558);
+ fiat_p384_addcarryx_u32(&x583, &x584, x582, x558, x555);
uint32_t x585;
fiat_p384_uint1 x586;
- fiat_p384_addcarryx_u32(&x585, &x586, x584, x553, x556);
+ fiat_p384_addcarryx_u32(&x585, &x586, x584, x556, x553);
uint32_t x587;
fiat_p384_uint1 x588;
- fiat_p384_addcarryx_u32(&x587, &x588, x586, x551, x554);
+ fiat_p384_addcarryx_u32(&x587, &x588, x586, x554, x551);
uint32_t x589;
fiat_p384_uint1 x590;
- fiat_p384_addcarryx_u32(&x589, &x590, x588, x549, x552);
+ fiat_p384_addcarryx_u32(&x589, &x590, x588, x552, x549);
uint32_t x591;
fiat_p384_uint1 x592;
- fiat_p384_addcarryx_u32(&x591, &x592, x590, x547, x550);
+ fiat_p384_addcarryx_u32(&x591, &x592, x590, x550, x547);
uint32_t x593;
fiat_p384_uint1 x594;
- fiat_p384_addcarryx_u32(&x593, &x594, x592, 0x0, x548);
+ fiat_p384_addcarryx_u32(&x593, &x594, x592, x548, 0x0);
uint32_t x595;
fiat_p384_uint1 x596;
- fiat_p384_addcarryx_u32(&x595, &x596, 0x0, x569, x521);
+ fiat_p384_addcarryx_u32(&x595, &x596, 0x0, x521, x569);
uint32_t x597;
fiat_p384_uint1 x598;
- fiat_p384_addcarryx_u32(&x597, &x598, x596, x571, x523);
+ fiat_p384_addcarryx_u32(&x597, &x598, x596, x523, x571);
uint32_t x599;
fiat_p384_uint1 x600;
- fiat_p384_addcarryx_u32(&x599, &x600, x598, x573, x525);
+ fiat_p384_addcarryx_u32(&x599, &x600, x598, x525, x573);
uint32_t x601;
fiat_p384_uint1 x602;
- fiat_p384_addcarryx_u32(&x601, &x602, x600, x575, x527);
+ fiat_p384_addcarryx_u32(&x601, &x602, x600, x527, x575);
uint32_t x603;
fiat_p384_uint1 x604;
- fiat_p384_addcarryx_u32(&x603, &x604, x602, x577, x529);
+ fiat_p384_addcarryx_u32(&x603, &x604, x602, x529, x577);
uint32_t x605;
fiat_p384_uint1 x606;
- fiat_p384_addcarryx_u32(&x605, &x606, x604, x579, x531);
+ fiat_p384_addcarryx_u32(&x605, &x606, x604, x531, x579);
uint32_t x607;
fiat_p384_uint1 x608;
- fiat_p384_addcarryx_u32(&x607, &x608, x606, x581, x533);
+ fiat_p384_addcarryx_u32(&x607, &x608, x606, x533, x581);
uint32_t x609;
fiat_p384_uint1 x610;
- fiat_p384_addcarryx_u32(&x609, &x610, x608, x583, x535);
+ fiat_p384_addcarryx_u32(&x609, &x610, x608, x535, x583);
uint32_t x611;
fiat_p384_uint1 x612;
- fiat_p384_addcarryx_u32(&x611, &x612, x610, x585, x537);
+ fiat_p384_addcarryx_u32(&x611, &x612, x610, x537, x585);
uint32_t x613;
fiat_p384_uint1 x614;
- fiat_p384_addcarryx_u32(&x613, &x614, x612, x587, x539);
+ fiat_p384_addcarryx_u32(&x613, &x614, x612, x539, x587);
uint32_t x615;
fiat_p384_uint1 x616;
- fiat_p384_addcarryx_u32(&x615, &x616, x614, x589, x541);
+ fiat_p384_addcarryx_u32(&x615, &x616, x614, x541, x589);
uint32_t x617;
fiat_p384_uint1 x618;
- fiat_p384_addcarryx_u32(&x617, &x618, x616, x591, x543);
+ fiat_p384_addcarryx_u32(&x617, &x618, x616, x543, x591);
uint32_t x619;
fiat_p384_uint1 x620;
- fiat_p384_addcarryx_u32(&x619, &x620, x618, x593, x545);
+ fiat_p384_addcarryx_u32(&x619, &x620, x618, x545, x593);
uint32_t x621;
uint32_t x622;
fiat_p384_mulx_u32(&x621, &x622, x595, UINT32_C(0xffffffff));
@@ -3656,73 +3656,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x639, &x640, x595, UINT32_C(0xffffffff));
uint32_t x641;
fiat_p384_uint1 x642;
- fiat_p384_addcarryx_u32(&x641, &x642, 0x0, x635, x638);
+ fiat_p384_addcarryx_u32(&x641, &x642, 0x0, x638, x635);
uint32_t x643;
fiat_p384_uint1 x644;
- fiat_p384_addcarryx_u32(&x643, &x644, x642, x633, x636);
+ fiat_p384_addcarryx_u32(&x643, &x644, x642, x636, x633);
uint32_t x645;
fiat_p384_uint1 x646;
- fiat_p384_addcarryx_u32(&x645, &x646, x644, x631, x634);
+ fiat_p384_addcarryx_u32(&x645, &x646, x644, x634, x631);
uint32_t x647;
fiat_p384_uint1 x648;
- fiat_p384_addcarryx_u32(&x647, &x648, x646, x629, x632);
+ fiat_p384_addcarryx_u32(&x647, &x648, x646, x632, x629);
uint32_t x649;
fiat_p384_uint1 x650;
- fiat_p384_addcarryx_u32(&x649, &x650, x648, x627, x630);
+ fiat_p384_addcarryx_u32(&x649, &x650, x648, x630, x627);
uint32_t x651;
fiat_p384_uint1 x652;
- fiat_p384_addcarryx_u32(&x651, &x652, x650, x625, x628);
+ fiat_p384_addcarryx_u32(&x651, &x652, x650, x628, x625);
uint32_t x653;
fiat_p384_uint1 x654;
- fiat_p384_addcarryx_u32(&x653, &x654, x652, x623, x626);
+ fiat_p384_addcarryx_u32(&x653, &x654, x652, x626, x623);
uint32_t x655;
fiat_p384_uint1 x656;
- fiat_p384_addcarryx_u32(&x655, &x656, x654, x621, x624);
+ fiat_p384_addcarryx_u32(&x655, &x656, x654, x624, x621);
uint32_t x657;
fiat_p384_uint1 x658;
- fiat_p384_addcarryx_u32(&x657, &x658, x656, 0x0, x622);
+ fiat_p384_addcarryx_u32(&x657, &x658, x656, x622, 0x0);
uint32_t x659;
fiat_p384_uint1 x660;
- fiat_p384_addcarryx_u32(&x659, &x660, 0x0, x639, x595);
+ fiat_p384_addcarryx_u32(&x659, &x660, 0x0, x595, x639);
uint32_t x661;
fiat_p384_uint1 x662;
- fiat_p384_addcarryx_u32(&x661, &x662, x660, x640, x597);
+ fiat_p384_addcarryx_u32(&x661, &x662, x660, x597, x640);
uint32_t x663;
fiat_p384_uint1 x664;
- fiat_p384_addcarryx_u32(&x663, &x664, x662, 0x0, x599);
+ fiat_p384_addcarryx_u32(&x663, &x664, x662, x599, 0x0);
uint32_t x665;
fiat_p384_uint1 x666;
- fiat_p384_addcarryx_u32(&x665, &x666, x664, x637, x601);
+ fiat_p384_addcarryx_u32(&x665, &x666, x664, x601, x637);
uint32_t x667;
fiat_p384_uint1 x668;
- fiat_p384_addcarryx_u32(&x667, &x668, x666, x641, x603);
+ fiat_p384_addcarryx_u32(&x667, &x668, x666, x603, x641);
uint32_t x669;
fiat_p384_uint1 x670;
- fiat_p384_addcarryx_u32(&x669, &x670, x668, x643, x605);
+ fiat_p384_addcarryx_u32(&x669, &x670, x668, x605, x643);
uint32_t x671;
fiat_p384_uint1 x672;
- fiat_p384_addcarryx_u32(&x671, &x672, x670, x645, x607);
+ fiat_p384_addcarryx_u32(&x671, &x672, x670, x607, x645);
uint32_t x673;
fiat_p384_uint1 x674;
- fiat_p384_addcarryx_u32(&x673, &x674, x672, x647, x609);
+ fiat_p384_addcarryx_u32(&x673, &x674, x672, x609, x647);
uint32_t x675;
fiat_p384_uint1 x676;
- fiat_p384_addcarryx_u32(&x675, &x676, x674, x649, x611);
+ fiat_p384_addcarryx_u32(&x675, &x676, x674, x611, x649);
uint32_t x677;
fiat_p384_uint1 x678;
- fiat_p384_addcarryx_u32(&x677, &x678, x676, x651, x613);
+ fiat_p384_addcarryx_u32(&x677, &x678, x676, x613, x651);
uint32_t x679;
fiat_p384_uint1 x680;
- fiat_p384_addcarryx_u32(&x679, &x680, x678, x653, x615);
+ fiat_p384_addcarryx_u32(&x679, &x680, x678, x615, x653);
uint32_t x681;
fiat_p384_uint1 x682;
- fiat_p384_addcarryx_u32(&x681, &x682, x680, x655, x617);
+ fiat_p384_addcarryx_u32(&x681, &x682, x680, x617, x655);
uint32_t x683;
fiat_p384_uint1 x684;
- fiat_p384_addcarryx_u32(&x683, &x684, x682, x657, x619);
+ fiat_p384_addcarryx_u32(&x683, &x684, x682, x619, x657);
uint32_t x685;
fiat_p384_uint1 x686;
- fiat_p384_addcarryx_u32(&x685, &x686, x684, 0x0, x620);
+ fiat_p384_addcarryx_u32(&x685, &x686, x684, x620, 0x0);
uint32_t x687;
uint32_t x688;
fiat_p384_mulx_u32(&x687, &x688, x5, (arg1[11]));
@@ -3761,79 +3761,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x709, &x710, x5, (arg1[0]));
uint32_t x711;
fiat_p384_uint1 x712;
- fiat_p384_addcarryx_u32(&x711, &x712, 0x0, x707, x710);
+ fiat_p384_addcarryx_u32(&x711, &x712, 0x0, x710, x707);
uint32_t x713;
fiat_p384_uint1 x714;
- fiat_p384_addcarryx_u32(&x713, &x714, x712, x705, x708);
+ fiat_p384_addcarryx_u32(&x713, &x714, x712, x708, x705);
uint32_t x715;
fiat_p384_uint1 x716;
- fiat_p384_addcarryx_u32(&x715, &x716, x714, x703, x706);
+ fiat_p384_addcarryx_u32(&x715, &x716, x714, x706, x703);
uint32_t x717;
fiat_p384_uint1 x718;
- fiat_p384_addcarryx_u32(&x717, &x718, x716, x701, x704);
+ fiat_p384_addcarryx_u32(&x717, &x718, x716, x704, x701);
uint32_t x719;
fiat_p384_uint1 x720;
- fiat_p384_addcarryx_u32(&x719, &x720, x718, x699, x702);
+ fiat_p384_addcarryx_u32(&x719, &x720, x718, x702, x699);
uint32_t x721;
fiat_p384_uint1 x722;
- fiat_p384_addcarryx_u32(&x721, &x722, x720, x697, x700);
+ fiat_p384_addcarryx_u32(&x721, &x722, x720, x700, x697);
uint32_t x723;
fiat_p384_uint1 x724;
- fiat_p384_addcarryx_u32(&x723, &x724, x722, x695, x698);
+ fiat_p384_addcarryx_u32(&x723, &x724, x722, x698, x695);
uint32_t x725;
fiat_p384_uint1 x726;
- fiat_p384_addcarryx_u32(&x725, &x726, x724, x693, x696);
+ fiat_p384_addcarryx_u32(&x725, &x726, x724, x696, x693);
uint32_t x727;
fiat_p384_uint1 x728;
- fiat_p384_addcarryx_u32(&x727, &x728, x726, x691, x694);
+ fiat_p384_addcarryx_u32(&x727, &x728, x726, x694, x691);
uint32_t x729;
fiat_p384_uint1 x730;
- fiat_p384_addcarryx_u32(&x729, &x730, x728, x689, x692);
+ fiat_p384_addcarryx_u32(&x729, &x730, x728, x692, x689);
uint32_t x731;
fiat_p384_uint1 x732;
- fiat_p384_addcarryx_u32(&x731, &x732, x730, x687, x690);
+ fiat_p384_addcarryx_u32(&x731, &x732, x730, x690, x687);
uint32_t x733;
fiat_p384_uint1 x734;
- fiat_p384_addcarryx_u32(&x733, &x734, x732, 0x0, x688);
+ fiat_p384_addcarryx_u32(&x733, &x734, x732, x688, 0x0);
uint32_t x735;
fiat_p384_uint1 x736;
- fiat_p384_addcarryx_u32(&x735, &x736, 0x0, x709, x661);
+ fiat_p384_addcarryx_u32(&x735, &x736, 0x0, x661, x709);
uint32_t x737;
fiat_p384_uint1 x738;
- fiat_p384_addcarryx_u32(&x737, &x738, x736, x711, x663);
+ fiat_p384_addcarryx_u32(&x737, &x738, x736, x663, x711);
uint32_t x739;
fiat_p384_uint1 x740;
- fiat_p384_addcarryx_u32(&x739, &x740, x738, x713, x665);
+ fiat_p384_addcarryx_u32(&x739, &x740, x738, x665, x713);
uint32_t x741;
fiat_p384_uint1 x742;
- fiat_p384_addcarryx_u32(&x741, &x742, x740, x715, x667);
+ fiat_p384_addcarryx_u32(&x741, &x742, x740, x667, x715);
uint32_t x743;
fiat_p384_uint1 x744;
- fiat_p384_addcarryx_u32(&x743, &x744, x742, x717, x669);
+ fiat_p384_addcarryx_u32(&x743, &x744, x742, x669, x717);
uint32_t x745;
fiat_p384_uint1 x746;
- fiat_p384_addcarryx_u32(&x745, &x746, x744, x719, x671);
+ fiat_p384_addcarryx_u32(&x745, &x746, x744, x671, x719);
uint32_t x747;
fiat_p384_uint1 x748;
- fiat_p384_addcarryx_u32(&x747, &x748, x746, x721, x673);
+ fiat_p384_addcarryx_u32(&x747, &x748, x746, x673, x721);
uint32_t x749;
fiat_p384_uint1 x750;
- fiat_p384_addcarryx_u32(&x749, &x750, x748, x723, x675);
+ fiat_p384_addcarryx_u32(&x749, &x750, x748, x675, x723);
uint32_t x751;
fiat_p384_uint1 x752;
- fiat_p384_addcarryx_u32(&x751, &x752, x750, x725, x677);
+ fiat_p384_addcarryx_u32(&x751, &x752, x750, x677, x725);
uint32_t x753;
fiat_p384_uint1 x754;
- fiat_p384_addcarryx_u32(&x753, &x754, x752, x727, x679);
+ fiat_p384_addcarryx_u32(&x753, &x754, x752, x679, x727);
uint32_t x755;
fiat_p384_uint1 x756;
- fiat_p384_addcarryx_u32(&x755, &x756, x754, x729, x681);
+ fiat_p384_addcarryx_u32(&x755, &x756, x754, x681, x729);
uint32_t x757;
fiat_p384_uint1 x758;
- fiat_p384_addcarryx_u32(&x757, &x758, x756, x731, x683);
+ fiat_p384_addcarryx_u32(&x757, &x758, x756, x683, x731);
uint32_t x759;
fiat_p384_uint1 x760;
- fiat_p384_addcarryx_u32(&x759, &x760, x758, x733, x685);
+ fiat_p384_addcarryx_u32(&x759, &x760, x758, x685, x733);
uint32_t x761;
uint32_t x762;
fiat_p384_mulx_u32(&x761, &x762, x735, UINT32_C(0xffffffff));
@@ -3866,73 +3866,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x779, &x780, x735, UINT32_C(0xffffffff));
uint32_t x781;
fiat_p384_uint1 x782;
- fiat_p384_addcarryx_u32(&x781, &x782, 0x0, x775, x778);
+ fiat_p384_addcarryx_u32(&x781, &x782, 0x0, x778, x775);
uint32_t x783;
fiat_p384_uint1 x784;
- fiat_p384_addcarryx_u32(&x783, &x784, x782, x773, x776);
+ fiat_p384_addcarryx_u32(&x783, &x784, x782, x776, x773);
uint32_t x785;
fiat_p384_uint1 x786;
- fiat_p384_addcarryx_u32(&x785, &x786, x784, x771, x774);
+ fiat_p384_addcarryx_u32(&x785, &x786, x784, x774, x771);
uint32_t x787;
fiat_p384_uint1 x788;
- fiat_p384_addcarryx_u32(&x787, &x788, x786, x769, x772);
+ fiat_p384_addcarryx_u32(&x787, &x788, x786, x772, x769);
uint32_t x789;
fiat_p384_uint1 x790;
- fiat_p384_addcarryx_u32(&x789, &x790, x788, x767, x770);
+ fiat_p384_addcarryx_u32(&x789, &x790, x788, x770, x767);
uint32_t x791;
fiat_p384_uint1 x792;
- fiat_p384_addcarryx_u32(&x791, &x792, x790, x765, x768);
+ fiat_p384_addcarryx_u32(&x791, &x792, x790, x768, x765);
uint32_t x793;
fiat_p384_uint1 x794;
- fiat_p384_addcarryx_u32(&x793, &x794, x792, x763, x766);
+ fiat_p384_addcarryx_u32(&x793, &x794, x792, x766, x763);
uint32_t x795;
fiat_p384_uint1 x796;
- fiat_p384_addcarryx_u32(&x795, &x796, x794, x761, x764);
+ fiat_p384_addcarryx_u32(&x795, &x796, x794, x764, x761);
uint32_t x797;
fiat_p384_uint1 x798;
- fiat_p384_addcarryx_u32(&x797, &x798, x796, 0x0, x762);
+ fiat_p384_addcarryx_u32(&x797, &x798, x796, x762, 0x0);
uint32_t x799;
fiat_p384_uint1 x800;
- fiat_p384_addcarryx_u32(&x799, &x800, 0x0, x779, x735);
+ fiat_p384_addcarryx_u32(&x799, &x800, 0x0, x735, x779);
uint32_t x801;
fiat_p384_uint1 x802;
- fiat_p384_addcarryx_u32(&x801, &x802, x800, x780, x737);
+ fiat_p384_addcarryx_u32(&x801, &x802, x800, x737, x780);
uint32_t x803;
fiat_p384_uint1 x804;
- fiat_p384_addcarryx_u32(&x803, &x804, x802, 0x0, x739);
+ fiat_p384_addcarryx_u32(&x803, &x804, x802, x739, 0x0);
uint32_t x805;
fiat_p384_uint1 x806;
- fiat_p384_addcarryx_u32(&x805, &x806, x804, x777, x741);
+ fiat_p384_addcarryx_u32(&x805, &x806, x804, x741, x777);
uint32_t x807;
fiat_p384_uint1 x808;
- fiat_p384_addcarryx_u32(&x807, &x808, x806, x781, x743);
+ fiat_p384_addcarryx_u32(&x807, &x808, x806, x743, x781);
uint32_t x809;
fiat_p384_uint1 x810;
- fiat_p384_addcarryx_u32(&x809, &x810, x808, x783, x745);
+ fiat_p384_addcarryx_u32(&x809, &x810, x808, x745, x783);
uint32_t x811;
fiat_p384_uint1 x812;
- fiat_p384_addcarryx_u32(&x811, &x812, x810, x785, x747);
+ fiat_p384_addcarryx_u32(&x811, &x812, x810, x747, x785);
uint32_t x813;
fiat_p384_uint1 x814;
- fiat_p384_addcarryx_u32(&x813, &x814, x812, x787, x749);
+ fiat_p384_addcarryx_u32(&x813, &x814, x812, x749, x787);
uint32_t x815;
fiat_p384_uint1 x816;
- fiat_p384_addcarryx_u32(&x815, &x816, x814, x789, x751);
+ fiat_p384_addcarryx_u32(&x815, &x816, x814, x751, x789);
uint32_t x817;
fiat_p384_uint1 x818;
- fiat_p384_addcarryx_u32(&x817, &x818, x816, x791, x753);
+ fiat_p384_addcarryx_u32(&x817, &x818, x816, x753, x791);
uint32_t x819;
fiat_p384_uint1 x820;
- fiat_p384_addcarryx_u32(&x819, &x820, x818, x793, x755);
+ fiat_p384_addcarryx_u32(&x819, &x820, x818, x755, x793);
uint32_t x821;
fiat_p384_uint1 x822;
- fiat_p384_addcarryx_u32(&x821, &x822, x820, x795, x757);
+ fiat_p384_addcarryx_u32(&x821, &x822, x820, x757, x795);
uint32_t x823;
fiat_p384_uint1 x824;
- fiat_p384_addcarryx_u32(&x823, &x824, x822, x797, x759);
+ fiat_p384_addcarryx_u32(&x823, &x824, x822, x759, x797);
uint32_t x825;
fiat_p384_uint1 x826;
- fiat_p384_addcarryx_u32(&x825, &x826, x824, 0x0, x760);
+ fiat_p384_addcarryx_u32(&x825, &x826, x824, x760, 0x0);
uint32_t x827;
uint32_t x828;
fiat_p384_mulx_u32(&x827, &x828, x6, (arg1[11]));
@@ -3971,79 +3971,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x849, &x850, x6, (arg1[0]));
uint32_t x851;
fiat_p384_uint1 x852;
- fiat_p384_addcarryx_u32(&x851, &x852, 0x0, x847, x850);
+ fiat_p384_addcarryx_u32(&x851, &x852, 0x0, x850, x847);
uint32_t x853;
fiat_p384_uint1 x854;
- fiat_p384_addcarryx_u32(&x853, &x854, x852, x845, x848);
+ fiat_p384_addcarryx_u32(&x853, &x854, x852, x848, x845);
uint32_t x855;
fiat_p384_uint1 x856;
- fiat_p384_addcarryx_u32(&x855, &x856, x854, x843, x846);
+ fiat_p384_addcarryx_u32(&x855, &x856, x854, x846, x843);
uint32_t x857;
fiat_p384_uint1 x858;
- fiat_p384_addcarryx_u32(&x857, &x858, x856, x841, x844);
+ fiat_p384_addcarryx_u32(&x857, &x858, x856, x844, x841);
uint32_t x859;
fiat_p384_uint1 x860;
- fiat_p384_addcarryx_u32(&x859, &x860, x858, x839, x842);
+ fiat_p384_addcarryx_u32(&x859, &x860, x858, x842, x839);
uint32_t x861;
fiat_p384_uint1 x862;
- fiat_p384_addcarryx_u32(&x861, &x862, x860, x837, x840);
+ fiat_p384_addcarryx_u32(&x861, &x862, x860, x840, x837);
uint32_t x863;
fiat_p384_uint1 x864;
- fiat_p384_addcarryx_u32(&x863, &x864, x862, x835, x838);
+ fiat_p384_addcarryx_u32(&x863, &x864, x862, x838, x835);
uint32_t x865;
fiat_p384_uint1 x866;
- fiat_p384_addcarryx_u32(&x865, &x866, x864, x833, x836);
+ fiat_p384_addcarryx_u32(&x865, &x866, x864, x836, x833);
uint32_t x867;
fiat_p384_uint1 x868;
- fiat_p384_addcarryx_u32(&x867, &x868, x866, x831, x834);
+ fiat_p384_addcarryx_u32(&x867, &x868, x866, x834, x831);
uint32_t x869;
fiat_p384_uint1 x870;
- fiat_p384_addcarryx_u32(&x869, &x870, x868, x829, x832);
+ fiat_p384_addcarryx_u32(&x869, &x870, x868, x832, x829);
uint32_t x871;
fiat_p384_uint1 x872;
- fiat_p384_addcarryx_u32(&x871, &x872, x870, x827, x830);
+ fiat_p384_addcarryx_u32(&x871, &x872, x870, x830, x827);
uint32_t x873;
fiat_p384_uint1 x874;
- fiat_p384_addcarryx_u32(&x873, &x874, x872, 0x0, x828);
+ fiat_p384_addcarryx_u32(&x873, &x874, x872, x828, 0x0);
uint32_t x875;
fiat_p384_uint1 x876;
- fiat_p384_addcarryx_u32(&x875, &x876, 0x0, x849, x801);
+ fiat_p384_addcarryx_u32(&x875, &x876, 0x0, x801, x849);
uint32_t x877;
fiat_p384_uint1 x878;
- fiat_p384_addcarryx_u32(&x877, &x878, x876, x851, x803);
+ fiat_p384_addcarryx_u32(&x877, &x878, x876, x803, x851);
uint32_t x879;
fiat_p384_uint1 x880;
- fiat_p384_addcarryx_u32(&x879, &x880, x878, x853, x805);
+ fiat_p384_addcarryx_u32(&x879, &x880, x878, x805, x853);
uint32_t x881;
fiat_p384_uint1 x882;
- fiat_p384_addcarryx_u32(&x881, &x882, x880, x855, x807);
+ fiat_p384_addcarryx_u32(&x881, &x882, x880, x807, x855);
uint32_t x883;
fiat_p384_uint1 x884;
- fiat_p384_addcarryx_u32(&x883, &x884, x882, x857, x809);
+ fiat_p384_addcarryx_u32(&x883, &x884, x882, x809, x857);
uint32_t x885;
fiat_p384_uint1 x886;
- fiat_p384_addcarryx_u32(&x885, &x886, x884, x859, x811);
+ fiat_p384_addcarryx_u32(&x885, &x886, x884, x811, x859);
uint32_t x887;
fiat_p384_uint1 x888;
- fiat_p384_addcarryx_u32(&x887, &x888, x886, x861, x813);
+ fiat_p384_addcarryx_u32(&x887, &x888, x886, x813, x861);
uint32_t x889;
fiat_p384_uint1 x890;
- fiat_p384_addcarryx_u32(&x889, &x890, x888, x863, x815);
+ fiat_p384_addcarryx_u32(&x889, &x890, x888, x815, x863);
uint32_t x891;
fiat_p384_uint1 x892;
- fiat_p384_addcarryx_u32(&x891, &x892, x890, x865, x817);
+ fiat_p384_addcarryx_u32(&x891, &x892, x890, x817, x865);
uint32_t x893;
fiat_p384_uint1 x894;
- fiat_p384_addcarryx_u32(&x893, &x894, x892, x867, x819);
+ fiat_p384_addcarryx_u32(&x893, &x894, x892, x819, x867);
uint32_t x895;
fiat_p384_uint1 x896;
- fiat_p384_addcarryx_u32(&x895, &x896, x894, x869, x821);
+ fiat_p384_addcarryx_u32(&x895, &x896, x894, x821, x869);
uint32_t x897;
fiat_p384_uint1 x898;
- fiat_p384_addcarryx_u32(&x897, &x898, x896, x871, x823);
+ fiat_p384_addcarryx_u32(&x897, &x898, x896, x823, x871);
uint32_t x899;
fiat_p384_uint1 x900;
- fiat_p384_addcarryx_u32(&x899, &x900, x898, x873, x825);
+ fiat_p384_addcarryx_u32(&x899, &x900, x898, x825, x873);
uint32_t x901;
uint32_t x902;
fiat_p384_mulx_u32(&x901, &x902, x875, UINT32_C(0xffffffff));
@@ -4076,73 +4076,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x919, &x920, x875, UINT32_C(0xffffffff));
uint32_t x921;
fiat_p384_uint1 x922;
- fiat_p384_addcarryx_u32(&x921, &x922, 0x0, x915, x918);
+ fiat_p384_addcarryx_u32(&x921, &x922, 0x0, x918, x915);
uint32_t x923;
fiat_p384_uint1 x924;
- fiat_p384_addcarryx_u32(&x923, &x924, x922, x913, x916);
+ fiat_p384_addcarryx_u32(&x923, &x924, x922, x916, x913);
uint32_t x925;
fiat_p384_uint1 x926;
- fiat_p384_addcarryx_u32(&x925, &x926, x924, x911, x914);
+ fiat_p384_addcarryx_u32(&x925, &x926, x924, x914, x911);
uint32_t x927;
fiat_p384_uint1 x928;
- fiat_p384_addcarryx_u32(&x927, &x928, x926, x909, x912);
+ fiat_p384_addcarryx_u32(&x927, &x928, x926, x912, x909);
uint32_t x929;
fiat_p384_uint1 x930;
- fiat_p384_addcarryx_u32(&x929, &x930, x928, x907, x910);
+ fiat_p384_addcarryx_u32(&x929, &x930, x928, x910, x907);
uint32_t x931;
fiat_p384_uint1 x932;
- fiat_p384_addcarryx_u32(&x931, &x932, x930, x905, x908);
+ fiat_p384_addcarryx_u32(&x931, &x932, x930, x908, x905);
uint32_t x933;
fiat_p384_uint1 x934;
- fiat_p384_addcarryx_u32(&x933, &x934, x932, x903, x906);
+ fiat_p384_addcarryx_u32(&x933, &x934, x932, x906, x903);
uint32_t x935;
fiat_p384_uint1 x936;
- fiat_p384_addcarryx_u32(&x935, &x936, x934, x901, x904);
+ fiat_p384_addcarryx_u32(&x935, &x936, x934, x904, x901);
uint32_t x937;
fiat_p384_uint1 x938;
- fiat_p384_addcarryx_u32(&x937, &x938, x936, 0x0, x902);
+ fiat_p384_addcarryx_u32(&x937, &x938, x936, x902, 0x0);
uint32_t x939;
fiat_p384_uint1 x940;
- fiat_p384_addcarryx_u32(&x939, &x940, 0x0, x919, x875);
+ fiat_p384_addcarryx_u32(&x939, &x940, 0x0, x875, x919);
uint32_t x941;
fiat_p384_uint1 x942;
- fiat_p384_addcarryx_u32(&x941, &x942, x940, x920, x877);
+ fiat_p384_addcarryx_u32(&x941, &x942, x940, x877, x920);
uint32_t x943;
fiat_p384_uint1 x944;
- fiat_p384_addcarryx_u32(&x943, &x944, x942, 0x0, x879);
+ fiat_p384_addcarryx_u32(&x943, &x944, x942, x879, 0x0);
uint32_t x945;
fiat_p384_uint1 x946;
- fiat_p384_addcarryx_u32(&x945, &x946, x944, x917, x881);
+ fiat_p384_addcarryx_u32(&x945, &x946, x944, x881, x917);
uint32_t x947;
fiat_p384_uint1 x948;
- fiat_p384_addcarryx_u32(&x947, &x948, x946, x921, x883);
+ fiat_p384_addcarryx_u32(&x947, &x948, x946, x883, x921);
uint32_t x949;
fiat_p384_uint1 x950;
- fiat_p384_addcarryx_u32(&x949, &x950, x948, x923, x885);
+ fiat_p384_addcarryx_u32(&x949, &x950, x948, x885, x923);
uint32_t x951;
fiat_p384_uint1 x952;
- fiat_p384_addcarryx_u32(&x951, &x952, x950, x925, x887);
+ fiat_p384_addcarryx_u32(&x951, &x952, x950, x887, x925);
uint32_t x953;
fiat_p384_uint1 x954;
- fiat_p384_addcarryx_u32(&x953, &x954, x952, x927, x889);
+ fiat_p384_addcarryx_u32(&x953, &x954, x952, x889, x927);
uint32_t x955;
fiat_p384_uint1 x956;
- fiat_p384_addcarryx_u32(&x955, &x956, x954, x929, x891);
+ fiat_p384_addcarryx_u32(&x955, &x956, x954, x891, x929);
uint32_t x957;
fiat_p384_uint1 x958;
- fiat_p384_addcarryx_u32(&x957, &x958, x956, x931, x893);
+ fiat_p384_addcarryx_u32(&x957, &x958, x956, x893, x931);
uint32_t x959;
fiat_p384_uint1 x960;
- fiat_p384_addcarryx_u32(&x959, &x960, x958, x933, x895);
+ fiat_p384_addcarryx_u32(&x959, &x960, x958, x895, x933);
uint32_t x961;
fiat_p384_uint1 x962;
- fiat_p384_addcarryx_u32(&x961, &x962, x960, x935, x897);
+ fiat_p384_addcarryx_u32(&x961, &x962, x960, x897, x935);
uint32_t x963;
fiat_p384_uint1 x964;
- fiat_p384_addcarryx_u32(&x963, &x964, x962, x937, x899);
+ fiat_p384_addcarryx_u32(&x963, &x964, x962, x899, x937);
uint32_t x965;
fiat_p384_uint1 x966;
- fiat_p384_addcarryx_u32(&x965, &x966, x964, 0x0, x900);
+ fiat_p384_addcarryx_u32(&x965, &x966, x964, x900, 0x0);
uint32_t x967;
uint32_t x968;
fiat_p384_mulx_u32(&x967, &x968, x7, (arg1[11]));
@@ -4181,79 +4181,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x989, &x990, x7, (arg1[0]));
uint32_t x991;
fiat_p384_uint1 x992;
- fiat_p384_addcarryx_u32(&x991, &x992, 0x0, x987, x990);
+ fiat_p384_addcarryx_u32(&x991, &x992, 0x0, x990, x987);
uint32_t x993;
fiat_p384_uint1 x994;
- fiat_p384_addcarryx_u32(&x993, &x994, x992, x985, x988);
+ fiat_p384_addcarryx_u32(&x993, &x994, x992, x988, x985);
uint32_t x995;
fiat_p384_uint1 x996;
- fiat_p384_addcarryx_u32(&x995, &x996, x994, x983, x986);
+ fiat_p384_addcarryx_u32(&x995, &x996, x994, x986, x983);
uint32_t x997;
fiat_p384_uint1 x998;
- fiat_p384_addcarryx_u32(&x997, &x998, x996, x981, x984);
+ fiat_p384_addcarryx_u32(&x997, &x998, x996, x984, x981);
uint32_t x999;
fiat_p384_uint1 x1000;
- fiat_p384_addcarryx_u32(&x999, &x1000, x998, x979, x982);
+ fiat_p384_addcarryx_u32(&x999, &x1000, x998, x982, x979);
uint32_t x1001;
fiat_p384_uint1 x1002;
- fiat_p384_addcarryx_u32(&x1001, &x1002, x1000, x977, x980);
+ fiat_p384_addcarryx_u32(&x1001, &x1002, x1000, x980, x977);
uint32_t x1003;
fiat_p384_uint1 x1004;
- fiat_p384_addcarryx_u32(&x1003, &x1004, x1002, x975, x978);
+ fiat_p384_addcarryx_u32(&x1003, &x1004, x1002, x978, x975);
uint32_t x1005;
fiat_p384_uint1 x1006;
- fiat_p384_addcarryx_u32(&x1005, &x1006, x1004, x973, x976);
+ fiat_p384_addcarryx_u32(&x1005, &x1006, x1004, x976, x973);
uint32_t x1007;
fiat_p384_uint1 x1008;
- fiat_p384_addcarryx_u32(&x1007, &x1008, x1006, x971, x974);
+ fiat_p384_addcarryx_u32(&x1007, &x1008, x1006, x974, x971);
uint32_t x1009;
fiat_p384_uint1 x1010;
- fiat_p384_addcarryx_u32(&x1009, &x1010, x1008, x969, x972);
+ fiat_p384_addcarryx_u32(&x1009, &x1010, x1008, x972, x969);
uint32_t x1011;
fiat_p384_uint1 x1012;
- fiat_p384_addcarryx_u32(&x1011, &x1012, x1010, x967, x970);
+ fiat_p384_addcarryx_u32(&x1011, &x1012, x1010, x970, x967);
uint32_t x1013;
fiat_p384_uint1 x1014;
- fiat_p384_addcarryx_u32(&x1013, &x1014, x1012, 0x0, x968);
+ fiat_p384_addcarryx_u32(&x1013, &x1014, x1012, x968, 0x0);
uint32_t x1015;
fiat_p384_uint1 x1016;
- fiat_p384_addcarryx_u32(&x1015, &x1016, 0x0, x989, x941);
+ fiat_p384_addcarryx_u32(&x1015, &x1016, 0x0, x941, x989);
uint32_t x1017;
fiat_p384_uint1 x1018;
- fiat_p384_addcarryx_u32(&x1017, &x1018, x1016, x991, x943);
+ fiat_p384_addcarryx_u32(&x1017, &x1018, x1016, x943, x991);
uint32_t x1019;
fiat_p384_uint1 x1020;
- fiat_p384_addcarryx_u32(&x1019, &x1020, x1018, x993, x945);
+ fiat_p384_addcarryx_u32(&x1019, &x1020, x1018, x945, x993);
uint32_t x1021;
fiat_p384_uint1 x1022;
- fiat_p384_addcarryx_u32(&x1021, &x1022, x1020, x995, x947);
+ fiat_p384_addcarryx_u32(&x1021, &x1022, x1020, x947, x995);
uint32_t x1023;
fiat_p384_uint1 x1024;
- fiat_p384_addcarryx_u32(&x1023, &x1024, x1022, x997, x949);
+ fiat_p384_addcarryx_u32(&x1023, &x1024, x1022, x949, x997);
uint32_t x1025;
fiat_p384_uint1 x1026;
- fiat_p384_addcarryx_u32(&x1025, &x1026, x1024, x999, x951);
+ fiat_p384_addcarryx_u32(&x1025, &x1026, x1024, x951, x999);
uint32_t x1027;
fiat_p384_uint1 x1028;
- fiat_p384_addcarryx_u32(&x1027, &x1028, x1026, x1001, x953);
+ fiat_p384_addcarryx_u32(&x1027, &x1028, x1026, x953, x1001);
uint32_t x1029;
fiat_p384_uint1 x1030;
- fiat_p384_addcarryx_u32(&x1029, &x1030, x1028, x1003, x955);
+ fiat_p384_addcarryx_u32(&x1029, &x1030, x1028, x955, x1003);
uint32_t x1031;
fiat_p384_uint1 x1032;
- fiat_p384_addcarryx_u32(&x1031, &x1032, x1030, x1005, x957);
+ fiat_p384_addcarryx_u32(&x1031, &x1032, x1030, x957, x1005);
uint32_t x1033;
fiat_p384_uint1 x1034;
- fiat_p384_addcarryx_u32(&x1033, &x1034, x1032, x1007, x959);
+ fiat_p384_addcarryx_u32(&x1033, &x1034, x1032, x959, x1007);
uint32_t x1035;
fiat_p384_uint1 x1036;
- fiat_p384_addcarryx_u32(&x1035, &x1036, x1034, x1009, x961);
+ fiat_p384_addcarryx_u32(&x1035, &x1036, x1034, x961, x1009);
uint32_t x1037;
fiat_p384_uint1 x1038;
- fiat_p384_addcarryx_u32(&x1037, &x1038, x1036, x1011, x963);
+ fiat_p384_addcarryx_u32(&x1037, &x1038, x1036, x963, x1011);
uint32_t x1039;
fiat_p384_uint1 x1040;
- fiat_p384_addcarryx_u32(&x1039, &x1040, x1038, x1013, x965);
+ fiat_p384_addcarryx_u32(&x1039, &x1040, x1038, x965, x1013);
uint32_t x1041;
uint32_t x1042;
fiat_p384_mulx_u32(&x1041, &x1042, x1015, UINT32_C(0xffffffff));
@@ -4286,73 +4286,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1059, &x1060, x1015, UINT32_C(0xffffffff));
uint32_t x1061;
fiat_p384_uint1 x1062;
- fiat_p384_addcarryx_u32(&x1061, &x1062, 0x0, x1055, x1058);
+ fiat_p384_addcarryx_u32(&x1061, &x1062, 0x0, x1058, x1055);
uint32_t x1063;
fiat_p384_uint1 x1064;
- fiat_p384_addcarryx_u32(&x1063, &x1064, x1062, x1053, x1056);
+ fiat_p384_addcarryx_u32(&x1063, &x1064, x1062, x1056, x1053);
uint32_t x1065;
fiat_p384_uint1 x1066;
- fiat_p384_addcarryx_u32(&x1065, &x1066, x1064, x1051, x1054);
+ fiat_p384_addcarryx_u32(&x1065, &x1066, x1064, x1054, x1051);
uint32_t x1067;
fiat_p384_uint1 x1068;
- fiat_p384_addcarryx_u32(&x1067, &x1068, x1066, x1049, x1052);
+ fiat_p384_addcarryx_u32(&x1067, &x1068, x1066, x1052, x1049);
uint32_t x1069;
fiat_p384_uint1 x1070;
- fiat_p384_addcarryx_u32(&x1069, &x1070, x1068, x1047, x1050);
+ fiat_p384_addcarryx_u32(&x1069, &x1070, x1068, x1050, x1047);
uint32_t x1071;
fiat_p384_uint1 x1072;
- fiat_p384_addcarryx_u32(&x1071, &x1072, x1070, x1045, x1048);
+ fiat_p384_addcarryx_u32(&x1071, &x1072, x1070, x1048, x1045);
uint32_t x1073;
fiat_p384_uint1 x1074;
- fiat_p384_addcarryx_u32(&x1073, &x1074, x1072, x1043, x1046);
+ fiat_p384_addcarryx_u32(&x1073, &x1074, x1072, x1046, x1043);
uint32_t x1075;
fiat_p384_uint1 x1076;
- fiat_p384_addcarryx_u32(&x1075, &x1076, x1074, x1041, x1044);
+ fiat_p384_addcarryx_u32(&x1075, &x1076, x1074, x1044, x1041);
uint32_t x1077;
fiat_p384_uint1 x1078;
- fiat_p384_addcarryx_u32(&x1077, &x1078, x1076, 0x0, x1042);
+ fiat_p384_addcarryx_u32(&x1077, &x1078, x1076, x1042, 0x0);
uint32_t x1079;
fiat_p384_uint1 x1080;
- fiat_p384_addcarryx_u32(&x1079, &x1080, 0x0, x1059, x1015);
+ fiat_p384_addcarryx_u32(&x1079, &x1080, 0x0, x1015, x1059);
uint32_t x1081;
fiat_p384_uint1 x1082;
- fiat_p384_addcarryx_u32(&x1081, &x1082, x1080, x1060, x1017);
+ fiat_p384_addcarryx_u32(&x1081, &x1082, x1080, x1017, x1060);
uint32_t x1083;
fiat_p384_uint1 x1084;
- fiat_p384_addcarryx_u32(&x1083, &x1084, x1082, 0x0, x1019);
+ fiat_p384_addcarryx_u32(&x1083, &x1084, x1082, x1019, 0x0);
uint32_t x1085;
fiat_p384_uint1 x1086;
- fiat_p384_addcarryx_u32(&x1085, &x1086, x1084, x1057, x1021);
+ fiat_p384_addcarryx_u32(&x1085, &x1086, x1084, x1021, x1057);
uint32_t x1087;
fiat_p384_uint1 x1088;
- fiat_p384_addcarryx_u32(&x1087, &x1088, x1086, x1061, x1023);
+ fiat_p384_addcarryx_u32(&x1087, &x1088, x1086, x1023, x1061);
uint32_t x1089;
fiat_p384_uint1 x1090;
- fiat_p384_addcarryx_u32(&x1089, &x1090, x1088, x1063, x1025);
+ fiat_p384_addcarryx_u32(&x1089, &x1090, x1088, x1025, x1063);
uint32_t x1091;
fiat_p384_uint1 x1092;
- fiat_p384_addcarryx_u32(&x1091, &x1092, x1090, x1065, x1027);
+ fiat_p384_addcarryx_u32(&x1091, &x1092, x1090, x1027, x1065);
uint32_t x1093;
fiat_p384_uint1 x1094;
- fiat_p384_addcarryx_u32(&x1093, &x1094, x1092, x1067, x1029);
+ fiat_p384_addcarryx_u32(&x1093, &x1094, x1092, x1029, x1067);
uint32_t x1095;
fiat_p384_uint1 x1096;
- fiat_p384_addcarryx_u32(&x1095, &x1096, x1094, x1069, x1031);
+ fiat_p384_addcarryx_u32(&x1095, &x1096, x1094, x1031, x1069);
uint32_t x1097;
fiat_p384_uint1 x1098;
- fiat_p384_addcarryx_u32(&x1097, &x1098, x1096, x1071, x1033);
+ fiat_p384_addcarryx_u32(&x1097, &x1098, x1096, x1033, x1071);
uint32_t x1099;
fiat_p384_uint1 x1100;
- fiat_p384_addcarryx_u32(&x1099, &x1100, x1098, x1073, x1035);
+ fiat_p384_addcarryx_u32(&x1099, &x1100, x1098, x1035, x1073);
uint32_t x1101;
fiat_p384_uint1 x1102;
- fiat_p384_addcarryx_u32(&x1101, &x1102, x1100, x1075, x1037);
+ fiat_p384_addcarryx_u32(&x1101, &x1102, x1100, x1037, x1075);
uint32_t x1103;
fiat_p384_uint1 x1104;
- fiat_p384_addcarryx_u32(&x1103, &x1104, x1102, x1077, x1039);
+ fiat_p384_addcarryx_u32(&x1103, &x1104, x1102, x1039, x1077);
uint32_t x1105;
fiat_p384_uint1 x1106;
- fiat_p384_addcarryx_u32(&x1105, &x1106, x1104, 0x0, x1040);
+ fiat_p384_addcarryx_u32(&x1105, &x1106, x1104, x1040, 0x0);
uint32_t x1107;
uint32_t x1108;
fiat_p384_mulx_u32(&x1107, &x1108, x8, (arg1[11]));
@@ -4391,79 +4391,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1129, &x1130, x8, (arg1[0]));
uint32_t x1131;
fiat_p384_uint1 x1132;
- fiat_p384_addcarryx_u32(&x1131, &x1132, 0x0, x1127, x1130);
+ fiat_p384_addcarryx_u32(&x1131, &x1132, 0x0, x1130, x1127);
uint32_t x1133;
fiat_p384_uint1 x1134;
- fiat_p384_addcarryx_u32(&x1133, &x1134, x1132, x1125, x1128);
+ fiat_p384_addcarryx_u32(&x1133, &x1134, x1132, x1128, x1125);
uint32_t x1135;
fiat_p384_uint1 x1136;
- fiat_p384_addcarryx_u32(&x1135, &x1136, x1134, x1123, x1126);
+ fiat_p384_addcarryx_u32(&x1135, &x1136, x1134, x1126, x1123);
uint32_t x1137;
fiat_p384_uint1 x1138;
- fiat_p384_addcarryx_u32(&x1137, &x1138, x1136, x1121, x1124);
+ fiat_p384_addcarryx_u32(&x1137, &x1138, x1136, x1124, x1121);
uint32_t x1139;
fiat_p384_uint1 x1140;
- fiat_p384_addcarryx_u32(&x1139, &x1140, x1138, x1119, x1122);
+ fiat_p384_addcarryx_u32(&x1139, &x1140, x1138, x1122, x1119);
uint32_t x1141;
fiat_p384_uint1 x1142;
- fiat_p384_addcarryx_u32(&x1141, &x1142, x1140, x1117, x1120);
+ fiat_p384_addcarryx_u32(&x1141, &x1142, x1140, x1120, x1117);
uint32_t x1143;
fiat_p384_uint1 x1144;
- fiat_p384_addcarryx_u32(&x1143, &x1144, x1142, x1115, x1118);
+ fiat_p384_addcarryx_u32(&x1143, &x1144, x1142, x1118, x1115);
uint32_t x1145;
fiat_p384_uint1 x1146;
- fiat_p384_addcarryx_u32(&x1145, &x1146, x1144, x1113, x1116);
+ fiat_p384_addcarryx_u32(&x1145, &x1146, x1144, x1116, x1113);
uint32_t x1147;
fiat_p384_uint1 x1148;
- fiat_p384_addcarryx_u32(&x1147, &x1148, x1146, x1111, x1114);
+ fiat_p384_addcarryx_u32(&x1147, &x1148, x1146, x1114, x1111);
uint32_t x1149;
fiat_p384_uint1 x1150;
- fiat_p384_addcarryx_u32(&x1149, &x1150, x1148, x1109, x1112);
+ fiat_p384_addcarryx_u32(&x1149, &x1150, x1148, x1112, x1109);
uint32_t x1151;
fiat_p384_uint1 x1152;
- fiat_p384_addcarryx_u32(&x1151, &x1152, x1150, x1107, x1110);
+ fiat_p384_addcarryx_u32(&x1151, &x1152, x1150, x1110, x1107);
uint32_t x1153;
fiat_p384_uint1 x1154;
- fiat_p384_addcarryx_u32(&x1153, &x1154, x1152, 0x0, x1108);
+ fiat_p384_addcarryx_u32(&x1153, &x1154, x1152, x1108, 0x0);
uint32_t x1155;
fiat_p384_uint1 x1156;
- fiat_p384_addcarryx_u32(&x1155, &x1156, 0x0, x1129, x1081);
+ fiat_p384_addcarryx_u32(&x1155, &x1156, 0x0, x1081, x1129);
uint32_t x1157;
fiat_p384_uint1 x1158;
- fiat_p384_addcarryx_u32(&x1157, &x1158, x1156, x1131, x1083);
+ fiat_p384_addcarryx_u32(&x1157, &x1158, x1156, x1083, x1131);
uint32_t x1159;
fiat_p384_uint1 x1160;
- fiat_p384_addcarryx_u32(&x1159, &x1160, x1158, x1133, x1085);
+ fiat_p384_addcarryx_u32(&x1159, &x1160, x1158, x1085, x1133);
uint32_t x1161;
fiat_p384_uint1 x1162;
- fiat_p384_addcarryx_u32(&x1161, &x1162, x1160, x1135, x1087);
+ fiat_p384_addcarryx_u32(&x1161, &x1162, x1160, x1087, x1135);
uint32_t x1163;
fiat_p384_uint1 x1164;
- fiat_p384_addcarryx_u32(&x1163, &x1164, x1162, x1137, x1089);
+ fiat_p384_addcarryx_u32(&x1163, &x1164, x1162, x1089, x1137);
uint32_t x1165;
fiat_p384_uint1 x1166;
- fiat_p384_addcarryx_u32(&x1165, &x1166, x1164, x1139, x1091);
+ fiat_p384_addcarryx_u32(&x1165, &x1166, x1164, x1091, x1139);
uint32_t x1167;
fiat_p384_uint1 x1168;
- fiat_p384_addcarryx_u32(&x1167, &x1168, x1166, x1141, x1093);
+ fiat_p384_addcarryx_u32(&x1167, &x1168, x1166, x1093, x1141);
uint32_t x1169;
fiat_p384_uint1 x1170;
- fiat_p384_addcarryx_u32(&x1169, &x1170, x1168, x1143, x1095);
+ fiat_p384_addcarryx_u32(&x1169, &x1170, x1168, x1095, x1143);
uint32_t x1171;
fiat_p384_uint1 x1172;
- fiat_p384_addcarryx_u32(&x1171, &x1172, x1170, x1145, x1097);
+ fiat_p384_addcarryx_u32(&x1171, &x1172, x1170, x1097, x1145);
uint32_t x1173;
fiat_p384_uint1 x1174;
- fiat_p384_addcarryx_u32(&x1173, &x1174, x1172, x1147, x1099);
+ fiat_p384_addcarryx_u32(&x1173, &x1174, x1172, x1099, x1147);
uint32_t x1175;
fiat_p384_uint1 x1176;
- fiat_p384_addcarryx_u32(&x1175, &x1176, x1174, x1149, x1101);
+ fiat_p384_addcarryx_u32(&x1175, &x1176, x1174, x1101, x1149);
uint32_t x1177;
fiat_p384_uint1 x1178;
- fiat_p384_addcarryx_u32(&x1177, &x1178, x1176, x1151, x1103);
+ fiat_p384_addcarryx_u32(&x1177, &x1178, x1176, x1103, x1151);
uint32_t x1179;
fiat_p384_uint1 x1180;
- fiat_p384_addcarryx_u32(&x1179, &x1180, x1178, x1153, x1105);
+ fiat_p384_addcarryx_u32(&x1179, &x1180, x1178, x1105, x1153);
uint32_t x1181;
uint32_t x1182;
fiat_p384_mulx_u32(&x1181, &x1182, x1155, UINT32_C(0xffffffff));
@@ -4496,73 +4496,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1199, &x1200, x1155, UINT32_C(0xffffffff));
uint32_t x1201;
fiat_p384_uint1 x1202;
- fiat_p384_addcarryx_u32(&x1201, &x1202, 0x0, x1195, x1198);
+ fiat_p384_addcarryx_u32(&x1201, &x1202, 0x0, x1198, x1195);
uint32_t x1203;
fiat_p384_uint1 x1204;
- fiat_p384_addcarryx_u32(&x1203, &x1204, x1202, x1193, x1196);
+ fiat_p384_addcarryx_u32(&x1203, &x1204, x1202, x1196, x1193);
uint32_t x1205;
fiat_p384_uint1 x1206;
- fiat_p384_addcarryx_u32(&x1205, &x1206, x1204, x1191, x1194);
+ fiat_p384_addcarryx_u32(&x1205, &x1206, x1204, x1194, x1191);
uint32_t x1207;
fiat_p384_uint1 x1208;
- fiat_p384_addcarryx_u32(&x1207, &x1208, x1206, x1189, x1192);
+ fiat_p384_addcarryx_u32(&x1207, &x1208, x1206, x1192, x1189);
uint32_t x1209;
fiat_p384_uint1 x1210;
- fiat_p384_addcarryx_u32(&x1209, &x1210, x1208, x1187, x1190);
+ fiat_p384_addcarryx_u32(&x1209, &x1210, x1208, x1190, x1187);
uint32_t x1211;
fiat_p384_uint1 x1212;
- fiat_p384_addcarryx_u32(&x1211, &x1212, x1210, x1185, x1188);
+ fiat_p384_addcarryx_u32(&x1211, &x1212, x1210, x1188, x1185);
uint32_t x1213;
fiat_p384_uint1 x1214;
- fiat_p384_addcarryx_u32(&x1213, &x1214, x1212, x1183, x1186);
+ fiat_p384_addcarryx_u32(&x1213, &x1214, x1212, x1186, x1183);
uint32_t x1215;
fiat_p384_uint1 x1216;
- fiat_p384_addcarryx_u32(&x1215, &x1216, x1214, x1181, x1184);
+ fiat_p384_addcarryx_u32(&x1215, &x1216, x1214, x1184, x1181);
uint32_t x1217;
fiat_p384_uint1 x1218;
- fiat_p384_addcarryx_u32(&x1217, &x1218, x1216, 0x0, x1182);
+ fiat_p384_addcarryx_u32(&x1217, &x1218, x1216, x1182, 0x0);
uint32_t x1219;
fiat_p384_uint1 x1220;
- fiat_p384_addcarryx_u32(&x1219, &x1220, 0x0, x1199, x1155);
+ fiat_p384_addcarryx_u32(&x1219, &x1220, 0x0, x1155, x1199);
uint32_t x1221;
fiat_p384_uint1 x1222;
- fiat_p384_addcarryx_u32(&x1221, &x1222, x1220, x1200, x1157);
+ fiat_p384_addcarryx_u32(&x1221, &x1222, x1220, x1157, x1200);
uint32_t x1223;
fiat_p384_uint1 x1224;
- fiat_p384_addcarryx_u32(&x1223, &x1224, x1222, 0x0, x1159);
+ fiat_p384_addcarryx_u32(&x1223, &x1224, x1222, x1159, 0x0);
uint32_t x1225;
fiat_p384_uint1 x1226;
- fiat_p384_addcarryx_u32(&x1225, &x1226, x1224, x1197, x1161);
+ fiat_p384_addcarryx_u32(&x1225, &x1226, x1224, x1161, x1197);
uint32_t x1227;
fiat_p384_uint1 x1228;
- fiat_p384_addcarryx_u32(&x1227, &x1228, x1226, x1201, x1163);
+ fiat_p384_addcarryx_u32(&x1227, &x1228, x1226, x1163, x1201);
uint32_t x1229;
fiat_p384_uint1 x1230;
- fiat_p384_addcarryx_u32(&x1229, &x1230, x1228, x1203, x1165);
+ fiat_p384_addcarryx_u32(&x1229, &x1230, x1228, x1165, x1203);
uint32_t x1231;
fiat_p384_uint1 x1232;
- fiat_p384_addcarryx_u32(&x1231, &x1232, x1230, x1205, x1167);
+ fiat_p384_addcarryx_u32(&x1231, &x1232, x1230, x1167, x1205);
uint32_t x1233;
fiat_p384_uint1 x1234;
- fiat_p384_addcarryx_u32(&x1233, &x1234, x1232, x1207, x1169);
+ fiat_p384_addcarryx_u32(&x1233, &x1234, x1232, x1169, x1207);
uint32_t x1235;
fiat_p384_uint1 x1236;
- fiat_p384_addcarryx_u32(&x1235, &x1236, x1234, x1209, x1171);
+ fiat_p384_addcarryx_u32(&x1235, &x1236, x1234, x1171, x1209);
uint32_t x1237;
fiat_p384_uint1 x1238;
- fiat_p384_addcarryx_u32(&x1237, &x1238, x1236, x1211, x1173);
+ fiat_p384_addcarryx_u32(&x1237, &x1238, x1236, x1173, x1211);
uint32_t x1239;
fiat_p384_uint1 x1240;
- fiat_p384_addcarryx_u32(&x1239, &x1240, x1238, x1213, x1175);
+ fiat_p384_addcarryx_u32(&x1239, &x1240, x1238, x1175, x1213);
uint32_t x1241;
fiat_p384_uint1 x1242;
- fiat_p384_addcarryx_u32(&x1241, &x1242, x1240, x1215, x1177);
+ fiat_p384_addcarryx_u32(&x1241, &x1242, x1240, x1177, x1215);
uint32_t x1243;
fiat_p384_uint1 x1244;
- fiat_p384_addcarryx_u32(&x1243, &x1244, x1242, x1217, x1179);
+ fiat_p384_addcarryx_u32(&x1243, &x1244, x1242, x1179, x1217);
uint32_t x1245;
fiat_p384_uint1 x1246;
- fiat_p384_addcarryx_u32(&x1245, &x1246, x1244, 0x0, x1180);
+ fiat_p384_addcarryx_u32(&x1245, &x1246, x1244, x1180, 0x0);
uint32_t x1247;
uint32_t x1248;
fiat_p384_mulx_u32(&x1247, &x1248, x9, (arg1[11]));
@@ -4601,79 +4601,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1269, &x1270, x9, (arg1[0]));
uint32_t x1271;
fiat_p384_uint1 x1272;
- fiat_p384_addcarryx_u32(&x1271, &x1272, 0x0, x1267, x1270);
+ fiat_p384_addcarryx_u32(&x1271, &x1272, 0x0, x1270, x1267);
uint32_t x1273;
fiat_p384_uint1 x1274;
- fiat_p384_addcarryx_u32(&x1273, &x1274, x1272, x1265, x1268);
+ fiat_p384_addcarryx_u32(&x1273, &x1274, x1272, x1268, x1265);
uint32_t x1275;
fiat_p384_uint1 x1276;
- fiat_p384_addcarryx_u32(&x1275, &x1276, x1274, x1263, x1266);
+ fiat_p384_addcarryx_u32(&x1275, &x1276, x1274, x1266, x1263);
uint32_t x1277;
fiat_p384_uint1 x1278;
- fiat_p384_addcarryx_u32(&x1277, &x1278, x1276, x1261, x1264);
+ fiat_p384_addcarryx_u32(&x1277, &x1278, x1276, x1264, x1261);
uint32_t x1279;
fiat_p384_uint1 x1280;
- fiat_p384_addcarryx_u32(&x1279, &x1280, x1278, x1259, x1262);
+ fiat_p384_addcarryx_u32(&x1279, &x1280, x1278, x1262, x1259);
uint32_t x1281;
fiat_p384_uint1 x1282;
- fiat_p384_addcarryx_u32(&x1281, &x1282, x1280, x1257, x1260);
+ fiat_p384_addcarryx_u32(&x1281, &x1282, x1280, x1260, x1257);
uint32_t x1283;
fiat_p384_uint1 x1284;
- fiat_p384_addcarryx_u32(&x1283, &x1284, x1282, x1255, x1258);
+ fiat_p384_addcarryx_u32(&x1283, &x1284, x1282, x1258, x1255);
uint32_t x1285;
fiat_p384_uint1 x1286;
- fiat_p384_addcarryx_u32(&x1285, &x1286, x1284, x1253, x1256);
+ fiat_p384_addcarryx_u32(&x1285, &x1286, x1284, x1256, x1253);
uint32_t x1287;
fiat_p384_uint1 x1288;
- fiat_p384_addcarryx_u32(&x1287, &x1288, x1286, x1251, x1254);
+ fiat_p384_addcarryx_u32(&x1287, &x1288, x1286, x1254, x1251);
uint32_t x1289;
fiat_p384_uint1 x1290;
- fiat_p384_addcarryx_u32(&x1289, &x1290, x1288, x1249, x1252);
+ fiat_p384_addcarryx_u32(&x1289, &x1290, x1288, x1252, x1249);
uint32_t x1291;
fiat_p384_uint1 x1292;
- fiat_p384_addcarryx_u32(&x1291, &x1292, x1290, x1247, x1250);
+ fiat_p384_addcarryx_u32(&x1291, &x1292, x1290, x1250, x1247);
uint32_t x1293;
fiat_p384_uint1 x1294;
- fiat_p384_addcarryx_u32(&x1293, &x1294, x1292, 0x0, x1248);
+ fiat_p384_addcarryx_u32(&x1293, &x1294, x1292, x1248, 0x0);
uint32_t x1295;
fiat_p384_uint1 x1296;
- fiat_p384_addcarryx_u32(&x1295, &x1296, 0x0, x1269, x1221);
+ fiat_p384_addcarryx_u32(&x1295, &x1296, 0x0, x1221, x1269);
uint32_t x1297;
fiat_p384_uint1 x1298;
- fiat_p384_addcarryx_u32(&x1297, &x1298, x1296, x1271, x1223);
+ fiat_p384_addcarryx_u32(&x1297, &x1298, x1296, x1223, x1271);
uint32_t x1299;
fiat_p384_uint1 x1300;
- fiat_p384_addcarryx_u32(&x1299, &x1300, x1298, x1273, x1225);
+ fiat_p384_addcarryx_u32(&x1299, &x1300, x1298, x1225, x1273);
uint32_t x1301;
fiat_p384_uint1 x1302;
- fiat_p384_addcarryx_u32(&x1301, &x1302, x1300, x1275, x1227);
+ fiat_p384_addcarryx_u32(&x1301, &x1302, x1300, x1227, x1275);
uint32_t x1303;
fiat_p384_uint1 x1304;
- fiat_p384_addcarryx_u32(&x1303, &x1304, x1302, x1277, x1229);
+ fiat_p384_addcarryx_u32(&x1303, &x1304, x1302, x1229, x1277);
uint32_t x1305;
fiat_p384_uint1 x1306;
- fiat_p384_addcarryx_u32(&x1305, &x1306, x1304, x1279, x1231);
+ fiat_p384_addcarryx_u32(&x1305, &x1306, x1304, x1231, x1279);
uint32_t x1307;
fiat_p384_uint1 x1308;
- fiat_p384_addcarryx_u32(&x1307, &x1308, x1306, x1281, x1233);
+ fiat_p384_addcarryx_u32(&x1307, &x1308, x1306, x1233, x1281);
uint32_t x1309;
fiat_p384_uint1 x1310;
- fiat_p384_addcarryx_u32(&x1309, &x1310, x1308, x1283, x1235);
+ fiat_p384_addcarryx_u32(&x1309, &x1310, x1308, x1235, x1283);
uint32_t x1311;
fiat_p384_uint1 x1312;
- fiat_p384_addcarryx_u32(&x1311, &x1312, x1310, x1285, x1237);
+ fiat_p384_addcarryx_u32(&x1311, &x1312, x1310, x1237, x1285);
uint32_t x1313;
fiat_p384_uint1 x1314;
- fiat_p384_addcarryx_u32(&x1313, &x1314, x1312, x1287, x1239);
+ fiat_p384_addcarryx_u32(&x1313, &x1314, x1312, x1239, x1287);
uint32_t x1315;
fiat_p384_uint1 x1316;
- fiat_p384_addcarryx_u32(&x1315, &x1316, x1314, x1289, x1241);
+ fiat_p384_addcarryx_u32(&x1315, &x1316, x1314, x1241, x1289);
uint32_t x1317;
fiat_p384_uint1 x1318;
- fiat_p384_addcarryx_u32(&x1317, &x1318, x1316, x1291, x1243);
+ fiat_p384_addcarryx_u32(&x1317, &x1318, x1316, x1243, x1291);
uint32_t x1319;
fiat_p384_uint1 x1320;
- fiat_p384_addcarryx_u32(&x1319, &x1320, x1318, x1293, x1245);
+ fiat_p384_addcarryx_u32(&x1319, &x1320, x1318, x1245, x1293);
uint32_t x1321;
uint32_t x1322;
fiat_p384_mulx_u32(&x1321, &x1322, x1295, UINT32_C(0xffffffff));
@@ -4706,73 +4706,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1339, &x1340, x1295, UINT32_C(0xffffffff));
uint32_t x1341;
fiat_p384_uint1 x1342;
- fiat_p384_addcarryx_u32(&x1341, &x1342, 0x0, x1335, x1338);
+ fiat_p384_addcarryx_u32(&x1341, &x1342, 0x0, x1338, x1335);
uint32_t x1343;
fiat_p384_uint1 x1344;
- fiat_p384_addcarryx_u32(&x1343, &x1344, x1342, x1333, x1336);
+ fiat_p384_addcarryx_u32(&x1343, &x1344, x1342, x1336, x1333);
uint32_t x1345;
fiat_p384_uint1 x1346;
- fiat_p384_addcarryx_u32(&x1345, &x1346, x1344, x1331, x1334);
+ fiat_p384_addcarryx_u32(&x1345, &x1346, x1344, x1334, x1331);
uint32_t x1347;
fiat_p384_uint1 x1348;
- fiat_p384_addcarryx_u32(&x1347, &x1348, x1346, x1329, x1332);
+ fiat_p384_addcarryx_u32(&x1347, &x1348, x1346, x1332, x1329);
uint32_t x1349;
fiat_p384_uint1 x1350;
- fiat_p384_addcarryx_u32(&x1349, &x1350, x1348, x1327, x1330);
+ fiat_p384_addcarryx_u32(&x1349, &x1350, x1348, x1330, x1327);
uint32_t x1351;
fiat_p384_uint1 x1352;
- fiat_p384_addcarryx_u32(&x1351, &x1352, x1350, x1325, x1328);
+ fiat_p384_addcarryx_u32(&x1351, &x1352, x1350, x1328, x1325);
uint32_t x1353;
fiat_p384_uint1 x1354;
- fiat_p384_addcarryx_u32(&x1353, &x1354, x1352, x1323, x1326);
+ fiat_p384_addcarryx_u32(&x1353, &x1354, x1352, x1326, x1323);
uint32_t x1355;
fiat_p384_uint1 x1356;
- fiat_p384_addcarryx_u32(&x1355, &x1356, x1354, x1321, x1324);
+ fiat_p384_addcarryx_u32(&x1355, &x1356, x1354, x1324, x1321);
uint32_t x1357;
fiat_p384_uint1 x1358;
- fiat_p384_addcarryx_u32(&x1357, &x1358, x1356, 0x0, x1322);
+ fiat_p384_addcarryx_u32(&x1357, &x1358, x1356, x1322, 0x0);
uint32_t x1359;
fiat_p384_uint1 x1360;
- fiat_p384_addcarryx_u32(&x1359, &x1360, 0x0, x1339, x1295);
+ fiat_p384_addcarryx_u32(&x1359, &x1360, 0x0, x1295, x1339);
uint32_t x1361;
fiat_p384_uint1 x1362;
- fiat_p384_addcarryx_u32(&x1361, &x1362, x1360, x1340, x1297);
+ fiat_p384_addcarryx_u32(&x1361, &x1362, x1360, x1297, x1340);
uint32_t x1363;
fiat_p384_uint1 x1364;
- fiat_p384_addcarryx_u32(&x1363, &x1364, x1362, 0x0, x1299);
+ fiat_p384_addcarryx_u32(&x1363, &x1364, x1362, x1299, 0x0);
uint32_t x1365;
fiat_p384_uint1 x1366;
- fiat_p384_addcarryx_u32(&x1365, &x1366, x1364, x1337, x1301);
+ fiat_p384_addcarryx_u32(&x1365, &x1366, x1364, x1301, x1337);
uint32_t x1367;
fiat_p384_uint1 x1368;
- fiat_p384_addcarryx_u32(&x1367, &x1368, x1366, x1341, x1303);
+ fiat_p384_addcarryx_u32(&x1367, &x1368, x1366, x1303, x1341);
uint32_t x1369;
fiat_p384_uint1 x1370;
- fiat_p384_addcarryx_u32(&x1369, &x1370, x1368, x1343, x1305);
+ fiat_p384_addcarryx_u32(&x1369, &x1370, x1368, x1305, x1343);
uint32_t x1371;
fiat_p384_uint1 x1372;
- fiat_p384_addcarryx_u32(&x1371, &x1372, x1370, x1345, x1307);
+ fiat_p384_addcarryx_u32(&x1371, &x1372, x1370, x1307, x1345);
uint32_t x1373;
fiat_p384_uint1 x1374;
- fiat_p384_addcarryx_u32(&x1373, &x1374, x1372, x1347, x1309);
+ fiat_p384_addcarryx_u32(&x1373, &x1374, x1372, x1309, x1347);
uint32_t x1375;
fiat_p384_uint1 x1376;
- fiat_p384_addcarryx_u32(&x1375, &x1376, x1374, x1349, x1311);
+ fiat_p384_addcarryx_u32(&x1375, &x1376, x1374, x1311, x1349);
uint32_t x1377;
fiat_p384_uint1 x1378;
- fiat_p384_addcarryx_u32(&x1377, &x1378, x1376, x1351, x1313);
+ fiat_p384_addcarryx_u32(&x1377, &x1378, x1376, x1313, x1351);
uint32_t x1379;
fiat_p384_uint1 x1380;
- fiat_p384_addcarryx_u32(&x1379, &x1380, x1378, x1353, x1315);
+ fiat_p384_addcarryx_u32(&x1379, &x1380, x1378, x1315, x1353);
uint32_t x1381;
fiat_p384_uint1 x1382;
- fiat_p384_addcarryx_u32(&x1381, &x1382, x1380, x1355, x1317);
+ fiat_p384_addcarryx_u32(&x1381, &x1382, x1380, x1317, x1355);
uint32_t x1383;
fiat_p384_uint1 x1384;
- fiat_p384_addcarryx_u32(&x1383, &x1384, x1382, x1357, x1319);
+ fiat_p384_addcarryx_u32(&x1383, &x1384, x1382, x1319, x1357);
uint32_t x1385;
fiat_p384_uint1 x1386;
- fiat_p384_addcarryx_u32(&x1385, &x1386, x1384, 0x0, x1320);
+ fiat_p384_addcarryx_u32(&x1385, &x1386, x1384, x1320, 0x0);
uint32_t x1387;
uint32_t x1388;
fiat_p384_mulx_u32(&x1387, &x1388, x10, (arg1[11]));
@@ -4811,79 +4811,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1409, &x1410, x10, (arg1[0]));
uint32_t x1411;
fiat_p384_uint1 x1412;
- fiat_p384_addcarryx_u32(&x1411, &x1412, 0x0, x1407, x1410);
+ fiat_p384_addcarryx_u32(&x1411, &x1412, 0x0, x1410, x1407);
uint32_t x1413;
fiat_p384_uint1 x1414;
- fiat_p384_addcarryx_u32(&x1413, &x1414, x1412, x1405, x1408);
+ fiat_p384_addcarryx_u32(&x1413, &x1414, x1412, x1408, x1405);
uint32_t x1415;
fiat_p384_uint1 x1416;
- fiat_p384_addcarryx_u32(&x1415, &x1416, x1414, x1403, x1406);
+ fiat_p384_addcarryx_u32(&x1415, &x1416, x1414, x1406, x1403);
uint32_t x1417;
fiat_p384_uint1 x1418;
- fiat_p384_addcarryx_u32(&x1417, &x1418, x1416, x1401, x1404);
+ fiat_p384_addcarryx_u32(&x1417, &x1418, x1416, x1404, x1401);
uint32_t x1419;
fiat_p384_uint1 x1420;
- fiat_p384_addcarryx_u32(&x1419, &x1420, x1418, x1399, x1402);
+ fiat_p384_addcarryx_u32(&x1419, &x1420, x1418, x1402, x1399);
uint32_t x1421;
fiat_p384_uint1 x1422;
- fiat_p384_addcarryx_u32(&x1421, &x1422, x1420, x1397, x1400);
+ fiat_p384_addcarryx_u32(&x1421, &x1422, x1420, x1400, x1397);
uint32_t x1423;
fiat_p384_uint1 x1424;
- fiat_p384_addcarryx_u32(&x1423, &x1424, x1422, x1395, x1398);
+ fiat_p384_addcarryx_u32(&x1423, &x1424, x1422, x1398, x1395);
uint32_t x1425;
fiat_p384_uint1 x1426;
- fiat_p384_addcarryx_u32(&x1425, &x1426, x1424, x1393, x1396);
+ fiat_p384_addcarryx_u32(&x1425, &x1426, x1424, x1396, x1393);
uint32_t x1427;
fiat_p384_uint1 x1428;
- fiat_p384_addcarryx_u32(&x1427, &x1428, x1426, x1391, x1394);
+ fiat_p384_addcarryx_u32(&x1427, &x1428, x1426, x1394, x1391);
uint32_t x1429;
fiat_p384_uint1 x1430;
- fiat_p384_addcarryx_u32(&x1429, &x1430, x1428, x1389, x1392);
+ fiat_p384_addcarryx_u32(&x1429, &x1430, x1428, x1392, x1389);
uint32_t x1431;
fiat_p384_uint1 x1432;
- fiat_p384_addcarryx_u32(&x1431, &x1432, x1430, x1387, x1390);
+ fiat_p384_addcarryx_u32(&x1431, &x1432, x1430, x1390, x1387);
uint32_t x1433;
fiat_p384_uint1 x1434;
- fiat_p384_addcarryx_u32(&x1433, &x1434, x1432, 0x0, x1388);
+ fiat_p384_addcarryx_u32(&x1433, &x1434, x1432, x1388, 0x0);
uint32_t x1435;
fiat_p384_uint1 x1436;
- fiat_p384_addcarryx_u32(&x1435, &x1436, 0x0, x1409, x1361);
+ fiat_p384_addcarryx_u32(&x1435, &x1436, 0x0, x1361, x1409);
uint32_t x1437;
fiat_p384_uint1 x1438;
- fiat_p384_addcarryx_u32(&x1437, &x1438, x1436, x1411, x1363);
+ fiat_p384_addcarryx_u32(&x1437, &x1438, x1436, x1363, x1411);
uint32_t x1439;
fiat_p384_uint1 x1440;
- fiat_p384_addcarryx_u32(&x1439, &x1440, x1438, x1413, x1365);
+ fiat_p384_addcarryx_u32(&x1439, &x1440, x1438, x1365, x1413);
uint32_t x1441;
fiat_p384_uint1 x1442;
- fiat_p384_addcarryx_u32(&x1441, &x1442, x1440, x1415, x1367);
+ fiat_p384_addcarryx_u32(&x1441, &x1442, x1440, x1367, x1415);
uint32_t x1443;
fiat_p384_uint1 x1444;
- fiat_p384_addcarryx_u32(&x1443, &x1444, x1442, x1417, x1369);
+ fiat_p384_addcarryx_u32(&x1443, &x1444, x1442, x1369, x1417);
uint32_t x1445;
fiat_p384_uint1 x1446;
- fiat_p384_addcarryx_u32(&x1445, &x1446, x1444, x1419, x1371);
+ fiat_p384_addcarryx_u32(&x1445, &x1446, x1444, x1371, x1419);
uint32_t x1447;
fiat_p384_uint1 x1448;
- fiat_p384_addcarryx_u32(&x1447, &x1448, x1446, x1421, x1373);
+ fiat_p384_addcarryx_u32(&x1447, &x1448, x1446, x1373, x1421);
uint32_t x1449;
fiat_p384_uint1 x1450;
- fiat_p384_addcarryx_u32(&x1449, &x1450, x1448, x1423, x1375);
+ fiat_p384_addcarryx_u32(&x1449, &x1450, x1448, x1375, x1423);
uint32_t x1451;
fiat_p384_uint1 x1452;
- fiat_p384_addcarryx_u32(&x1451, &x1452, x1450, x1425, x1377);
+ fiat_p384_addcarryx_u32(&x1451, &x1452, x1450, x1377, x1425);
uint32_t x1453;
fiat_p384_uint1 x1454;
- fiat_p384_addcarryx_u32(&x1453, &x1454, x1452, x1427, x1379);
+ fiat_p384_addcarryx_u32(&x1453, &x1454, x1452, x1379, x1427);
uint32_t x1455;
fiat_p384_uint1 x1456;
- fiat_p384_addcarryx_u32(&x1455, &x1456, x1454, x1429, x1381);
+ fiat_p384_addcarryx_u32(&x1455, &x1456, x1454, x1381, x1429);
uint32_t x1457;
fiat_p384_uint1 x1458;
- fiat_p384_addcarryx_u32(&x1457, &x1458, x1456, x1431, x1383);
+ fiat_p384_addcarryx_u32(&x1457, &x1458, x1456, x1383, x1431);
uint32_t x1459;
fiat_p384_uint1 x1460;
- fiat_p384_addcarryx_u32(&x1459, &x1460, x1458, x1433, x1385);
+ fiat_p384_addcarryx_u32(&x1459, &x1460, x1458, x1385, x1433);
uint32_t x1461;
uint32_t x1462;
fiat_p384_mulx_u32(&x1461, &x1462, x1435, UINT32_C(0xffffffff));
@@ -4916,73 +4916,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1479, &x1480, x1435, UINT32_C(0xffffffff));
uint32_t x1481;
fiat_p384_uint1 x1482;
- fiat_p384_addcarryx_u32(&x1481, &x1482, 0x0, x1475, x1478);
+ fiat_p384_addcarryx_u32(&x1481, &x1482, 0x0, x1478, x1475);
uint32_t x1483;
fiat_p384_uint1 x1484;
- fiat_p384_addcarryx_u32(&x1483, &x1484, x1482, x1473, x1476);
+ fiat_p384_addcarryx_u32(&x1483, &x1484, x1482, x1476, x1473);
uint32_t x1485;
fiat_p384_uint1 x1486;
- fiat_p384_addcarryx_u32(&x1485, &x1486, x1484, x1471, x1474);
+ fiat_p384_addcarryx_u32(&x1485, &x1486, x1484, x1474, x1471);
uint32_t x1487;
fiat_p384_uint1 x1488;
- fiat_p384_addcarryx_u32(&x1487, &x1488, x1486, x1469, x1472);
+ fiat_p384_addcarryx_u32(&x1487, &x1488, x1486, x1472, x1469);
uint32_t x1489;
fiat_p384_uint1 x1490;
- fiat_p384_addcarryx_u32(&x1489, &x1490, x1488, x1467, x1470);
+ fiat_p384_addcarryx_u32(&x1489, &x1490, x1488, x1470, x1467);
uint32_t x1491;
fiat_p384_uint1 x1492;
- fiat_p384_addcarryx_u32(&x1491, &x1492, x1490, x1465, x1468);
+ fiat_p384_addcarryx_u32(&x1491, &x1492, x1490, x1468, x1465);
uint32_t x1493;
fiat_p384_uint1 x1494;
- fiat_p384_addcarryx_u32(&x1493, &x1494, x1492, x1463, x1466);
+ fiat_p384_addcarryx_u32(&x1493, &x1494, x1492, x1466, x1463);
uint32_t x1495;
fiat_p384_uint1 x1496;
- fiat_p384_addcarryx_u32(&x1495, &x1496, x1494, x1461, x1464);
+ fiat_p384_addcarryx_u32(&x1495, &x1496, x1494, x1464, x1461);
uint32_t x1497;
fiat_p384_uint1 x1498;
- fiat_p384_addcarryx_u32(&x1497, &x1498, x1496, 0x0, x1462);
+ fiat_p384_addcarryx_u32(&x1497, &x1498, x1496, x1462, 0x0);
uint32_t x1499;
fiat_p384_uint1 x1500;
- fiat_p384_addcarryx_u32(&x1499, &x1500, 0x0, x1479, x1435);
+ fiat_p384_addcarryx_u32(&x1499, &x1500, 0x0, x1435, x1479);
uint32_t x1501;
fiat_p384_uint1 x1502;
- fiat_p384_addcarryx_u32(&x1501, &x1502, x1500, x1480, x1437);
+ fiat_p384_addcarryx_u32(&x1501, &x1502, x1500, x1437, x1480);
uint32_t x1503;
fiat_p384_uint1 x1504;
- fiat_p384_addcarryx_u32(&x1503, &x1504, x1502, 0x0, x1439);
+ fiat_p384_addcarryx_u32(&x1503, &x1504, x1502, x1439, 0x0);
uint32_t x1505;
fiat_p384_uint1 x1506;
- fiat_p384_addcarryx_u32(&x1505, &x1506, x1504, x1477, x1441);
+ fiat_p384_addcarryx_u32(&x1505, &x1506, x1504, x1441, x1477);
uint32_t x1507;
fiat_p384_uint1 x1508;
- fiat_p384_addcarryx_u32(&x1507, &x1508, x1506, x1481, x1443);
+ fiat_p384_addcarryx_u32(&x1507, &x1508, x1506, x1443, x1481);
uint32_t x1509;
fiat_p384_uint1 x1510;
- fiat_p384_addcarryx_u32(&x1509, &x1510, x1508, x1483, x1445);
+ fiat_p384_addcarryx_u32(&x1509, &x1510, x1508, x1445, x1483);
uint32_t x1511;
fiat_p384_uint1 x1512;
- fiat_p384_addcarryx_u32(&x1511, &x1512, x1510, x1485, x1447);
+ fiat_p384_addcarryx_u32(&x1511, &x1512, x1510, x1447, x1485);
uint32_t x1513;
fiat_p384_uint1 x1514;
- fiat_p384_addcarryx_u32(&x1513, &x1514, x1512, x1487, x1449);
+ fiat_p384_addcarryx_u32(&x1513, &x1514, x1512, x1449, x1487);
uint32_t x1515;
fiat_p384_uint1 x1516;
- fiat_p384_addcarryx_u32(&x1515, &x1516, x1514, x1489, x1451);
+ fiat_p384_addcarryx_u32(&x1515, &x1516, x1514, x1451, x1489);
uint32_t x1517;
fiat_p384_uint1 x1518;
- fiat_p384_addcarryx_u32(&x1517, &x1518, x1516, x1491, x1453);
+ fiat_p384_addcarryx_u32(&x1517, &x1518, x1516, x1453, x1491);
uint32_t x1519;
fiat_p384_uint1 x1520;
- fiat_p384_addcarryx_u32(&x1519, &x1520, x1518, x1493, x1455);
+ fiat_p384_addcarryx_u32(&x1519, &x1520, x1518, x1455, x1493);
uint32_t x1521;
fiat_p384_uint1 x1522;
- fiat_p384_addcarryx_u32(&x1521, &x1522, x1520, x1495, x1457);
+ fiat_p384_addcarryx_u32(&x1521, &x1522, x1520, x1457, x1495);
uint32_t x1523;
fiat_p384_uint1 x1524;
- fiat_p384_addcarryx_u32(&x1523, &x1524, x1522, x1497, x1459);
+ fiat_p384_addcarryx_u32(&x1523, &x1524, x1522, x1459, x1497);
uint32_t x1525;
fiat_p384_uint1 x1526;
- fiat_p384_addcarryx_u32(&x1525, &x1526, x1524, 0x0, x1460);
+ fiat_p384_addcarryx_u32(&x1525, &x1526, x1524, x1460, 0x0);
uint32_t x1527;
uint32_t x1528;
fiat_p384_mulx_u32(&x1527, &x1528, x11, (arg1[11]));
@@ -5021,79 +5021,79 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1549, &x1550, x11, (arg1[0]));
uint32_t x1551;
fiat_p384_uint1 x1552;
- fiat_p384_addcarryx_u32(&x1551, &x1552, 0x0, x1547, x1550);
+ fiat_p384_addcarryx_u32(&x1551, &x1552, 0x0, x1550, x1547);
uint32_t x1553;
fiat_p384_uint1 x1554;
- fiat_p384_addcarryx_u32(&x1553, &x1554, x1552, x1545, x1548);
+ fiat_p384_addcarryx_u32(&x1553, &x1554, x1552, x1548, x1545);
uint32_t x1555;
fiat_p384_uint1 x1556;
- fiat_p384_addcarryx_u32(&x1555, &x1556, x1554, x1543, x1546);
+ fiat_p384_addcarryx_u32(&x1555, &x1556, x1554, x1546, x1543);
uint32_t x1557;
fiat_p384_uint1 x1558;
- fiat_p384_addcarryx_u32(&x1557, &x1558, x1556, x1541, x1544);
+ fiat_p384_addcarryx_u32(&x1557, &x1558, x1556, x1544, x1541);
uint32_t x1559;
fiat_p384_uint1 x1560;
- fiat_p384_addcarryx_u32(&x1559, &x1560, x1558, x1539, x1542);
+ fiat_p384_addcarryx_u32(&x1559, &x1560, x1558, x1542, x1539);
uint32_t x1561;
fiat_p384_uint1 x1562;
- fiat_p384_addcarryx_u32(&x1561, &x1562, x1560, x1537, x1540);
+ fiat_p384_addcarryx_u32(&x1561, &x1562, x1560, x1540, x1537);
uint32_t x1563;
fiat_p384_uint1 x1564;
- fiat_p384_addcarryx_u32(&x1563, &x1564, x1562, x1535, x1538);
+ fiat_p384_addcarryx_u32(&x1563, &x1564, x1562, x1538, x1535);
uint32_t x1565;
fiat_p384_uint1 x1566;
- fiat_p384_addcarryx_u32(&x1565, &x1566, x1564, x1533, x1536);
+ fiat_p384_addcarryx_u32(&x1565, &x1566, x1564, x1536, x1533);
uint32_t x1567;
fiat_p384_uint1 x1568;
- fiat_p384_addcarryx_u32(&x1567, &x1568, x1566, x1531, x1534);
+ fiat_p384_addcarryx_u32(&x1567, &x1568, x1566, x1534, x1531);
uint32_t x1569;
fiat_p384_uint1 x1570;
- fiat_p384_addcarryx_u32(&x1569, &x1570, x1568, x1529, x1532);
+ fiat_p384_addcarryx_u32(&x1569, &x1570, x1568, x1532, x1529);
uint32_t x1571;
fiat_p384_uint1 x1572;
- fiat_p384_addcarryx_u32(&x1571, &x1572, x1570, x1527, x1530);
+ fiat_p384_addcarryx_u32(&x1571, &x1572, x1570, x1530, x1527);
uint32_t x1573;
fiat_p384_uint1 x1574;
- fiat_p384_addcarryx_u32(&x1573, &x1574, x1572, 0x0, x1528);
+ fiat_p384_addcarryx_u32(&x1573, &x1574, x1572, x1528, 0x0);
uint32_t x1575;
fiat_p384_uint1 x1576;
- fiat_p384_addcarryx_u32(&x1575, &x1576, 0x0, x1549, x1501);
+ fiat_p384_addcarryx_u32(&x1575, &x1576, 0x0, x1501, x1549);
uint32_t x1577;
fiat_p384_uint1 x1578;
- fiat_p384_addcarryx_u32(&x1577, &x1578, x1576, x1551, x1503);
+ fiat_p384_addcarryx_u32(&x1577, &x1578, x1576, x1503, x1551);
uint32_t x1579;
fiat_p384_uint1 x1580;
- fiat_p384_addcarryx_u32(&x1579, &x1580, x1578, x1553, x1505);
+ fiat_p384_addcarryx_u32(&x1579, &x1580, x1578, x1505, x1553);
uint32_t x1581;
fiat_p384_uint1 x1582;
- fiat_p384_addcarryx_u32(&x1581, &x1582, x1580, x1555, x1507);
+ fiat_p384_addcarryx_u32(&x1581, &x1582, x1580, x1507, x1555);
uint32_t x1583;
fiat_p384_uint1 x1584;
- fiat_p384_addcarryx_u32(&x1583, &x1584, x1582, x1557, x1509);
+ fiat_p384_addcarryx_u32(&x1583, &x1584, x1582, x1509, x1557);
uint32_t x1585;
fiat_p384_uint1 x1586;
- fiat_p384_addcarryx_u32(&x1585, &x1586, x1584, x1559, x1511);
+ fiat_p384_addcarryx_u32(&x1585, &x1586, x1584, x1511, x1559);
uint32_t x1587;
fiat_p384_uint1 x1588;
- fiat_p384_addcarryx_u32(&x1587, &x1588, x1586, x1561, x1513);
+ fiat_p384_addcarryx_u32(&x1587, &x1588, x1586, x1513, x1561);
uint32_t x1589;
fiat_p384_uint1 x1590;
- fiat_p384_addcarryx_u32(&x1589, &x1590, x1588, x1563, x1515);
+ fiat_p384_addcarryx_u32(&x1589, &x1590, x1588, x1515, x1563);
uint32_t x1591;
fiat_p384_uint1 x1592;
- fiat_p384_addcarryx_u32(&x1591, &x1592, x1590, x1565, x1517);
+ fiat_p384_addcarryx_u32(&x1591, &x1592, x1590, x1517, x1565);
uint32_t x1593;
fiat_p384_uint1 x1594;
- fiat_p384_addcarryx_u32(&x1593, &x1594, x1592, x1567, x1519);
+ fiat_p384_addcarryx_u32(&x1593, &x1594, x1592, x1519, x1567);
uint32_t x1595;
fiat_p384_uint1 x1596;
- fiat_p384_addcarryx_u32(&x1595, &x1596, x1594, x1569, x1521);
+ fiat_p384_addcarryx_u32(&x1595, &x1596, x1594, x1521, x1569);
uint32_t x1597;
fiat_p384_uint1 x1598;
- fiat_p384_addcarryx_u32(&x1597, &x1598, x1596, x1571, x1523);
+ fiat_p384_addcarryx_u32(&x1597, &x1598, x1596, x1523, x1571);
uint32_t x1599;
fiat_p384_uint1 x1600;
- fiat_p384_addcarryx_u32(&x1599, &x1600, x1598, x1573, x1525);
+ fiat_p384_addcarryx_u32(&x1599, &x1600, x1598, x1525, x1573);
uint32_t x1601;
uint32_t x1602;
fiat_p384_mulx_u32(&x1601, &x1602, x1575, UINT32_C(0xffffffff));
@@ -5126,73 +5126,73 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_mulx_u32(&x1619, &x1620, x1575, UINT32_C(0xffffffff));
uint32_t x1621;
fiat_p384_uint1 x1622;
- fiat_p384_addcarryx_u32(&x1621, &x1622, 0x0, x1615, x1618);
+ fiat_p384_addcarryx_u32(&x1621, &x1622, 0x0, x1618, x1615);
uint32_t x1623;
fiat_p384_uint1 x1624;
- fiat_p384_addcarryx_u32(&x1623, &x1624, x1622, x1613, x1616);
+ fiat_p384_addcarryx_u32(&x1623, &x1624, x1622, x1616, x1613);
uint32_t x1625;
fiat_p384_uint1 x1626;
- fiat_p384_addcarryx_u32(&x1625, &x1626, x1624, x1611, x1614);
+ fiat_p384_addcarryx_u32(&x1625, &x1626, x1624, x1614, x1611);
uint32_t x1627;
fiat_p384_uint1 x1628;
- fiat_p384_addcarryx_u32(&x1627, &x1628, x1626, x1609, x1612);
+ fiat_p384_addcarryx_u32(&x1627, &x1628, x1626, x1612, x1609);
uint32_t x1629;
fiat_p384_uint1 x1630;
- fiat_p384_addcarryx_u32(&x1629, &x1630, x1628, x1607, x1610);
+ fiat_p384_addcarryx_u32(&x1629, &x1630, x1628, x1610, x1607);
uint32_t x1631;
fiat_p384_uint1 x1632;
- fiat_p384_addcarryx_u32(&x1631, &x1632, x1630, x1605, x1608);
+ fiat_p384_addcarryx_u32(&x1631, &x1632, x1630, x1608, x1605);
uint32_t x1633;
fiat_p384_uint1 x1634;
- fiat_p384_addcarryx_u32(&x1633, &x1634, x1632, x1603, x1606);
+ fiat_p384_addcarryx_u32(&x1633, &x1634, x1632, x1606, x1603);
uint32_t x1635;
fiat_p384_uint1 x1636;
- fiat_p384_addcarryx_u32(&x1635, &x1636, x1634, x1601, x1604);
+ fiat_p384_addcarryx_u32(&x1635, &x1636, x1634, x1604, x1601);
uint32_t x1637;
fiat_p384_uint1 x1638;
- fiat_p384_addcarryx_u32(&x1637, &x1638, x1636, 0x0, x1602);
+ fiat_p384_addcarryx_u32(&x1637, &x1638, x1636, x1602, 0x0);
uint32_t x1639;
fiat_p384_uint1 x1640;
- fiat_p384_addcarryx_u32(&x1639, &x1640, 0x0, x1619, x1575);
+ fiat_p384_addcarryx_u32(&x1639, &x1640, 0x0, x1575, x1619);
uint32_t x1641;
fiat_p384_uint1 x1642;
- fiat_p384_addcarryx_u32(&x1641, &x1642, x1640, x1620, x1577);
+ fiat_p384_addcarryx_u32(&x1641, &x1642, x1640, x1577, x1620);
uint32_t x1643;
fiat_p384_uint1 x1644;
- fiat_p384_addcarryx_u32(&x1643, &x1644, x1642, 0x0, x1579);
+ fiat_p384_addcarryx_u32(&x1643, &x1644, x1642, x1579, 0x0);
uint32_t x1645;
fiat_p384_uint1 x1646;
- fiat_p384_addcarryx_u32(&x1645, &x1646, x1644, x1617, x1581);
+ fiat_p384_addcarryx_u32(&x1645, &x1646, x1644, x1581, x1617);
uint32_t x1647;
fiat_p384_uint1 x1648;
- fiat_p384_addcarryx_u32(&x1647, &x1648, x1646, x1621, x1583);
+ fiat_p384_addcarryx_u32(&x1647, &x1648, x1646, x1583, x1621);
uint32_t x1649;
fiat_p384_uint1 x1650;
- fiat_p384_addcarryx_u32(&x1649, &x1650, x1648, x1623, x1585);
+ fiat_p384_addcarryx_u32(&x1649, &x1650, x1648, x1585, x1623);
uint32_t x1651;
fiat_p384_uint1 x1652;
- fiat_p384_addcarryx_u32(&x1651, &x1652, x1650, x1625, x1587);
+ fiat_p384_addcarryx_u32(&x1651, &x1652, x1650, x1587, x1625);
uint32_t x1653;
fiat_p384_uint1 x1654;
- fiat_p384_addcarryx_u32(&x1653, &x1654, x1652, x1627, x1589);
+ fiat_p384_addcarryx_u32(&x1653, &x1654, x1652, x1589, x1627);
uint32_t x1655;
fiat_p384_uint1 x1656;
- fiat_p384_addcarryx_u32(&x1655, &x1656, x1654, x1629, x1591);
+ fiat_p384_addcarryx_u32(&x1655, &x1656, x1654, x1591, x1629);
uint32_t x1657;
fiat_p384_uint1 x1658;
- fiat_p384_addcarryx_u32(&x1657, &x1658, x1656, x1631, x1593);
+ fiat_p384_addcarryx_u32(&x1657, &x1658, x1656, x1593, x1631);
uint32_t x1659;
fiat_p384_uint1 x1660;
- fiat_p384_addcarryx_u32(&x1659, &x1660, x1658, x1633, x1595);
+ fiat_p384_addcarryx_u32(&x1659, &x1660, x1658, x1595, x1633);
uint32_t x1661;
fiat_p384_uint1 x1662;
- fiat_p384_addcarryx_u32(&x1661, &x1662, x1660, x1635, x1597);
+ fiat_p384_addcarryx_u32(&x1661, &x1662, x1660, x1597, x1635);
uint32_t x1663;
fiat_p384_uint1 x1664;
- fiat_p384_addcarryx_u32(&x1663, &x1664, x1662, x1637, x1599);
+ fiat_p384_addcarryx_u32(&x1663, &x1664, x1662, x1599, x1637);
uint32_t x1665;
fiat_p384_uint1 x1666;
- fiat_p384_addcarryx_u32(&x1665, &x1666, x1664, 0x0, x1600);
+ fiat_p384_addcarryx_u32(&x1665, &x1666, x1664, x1600, 0x0);
uint32_t x1667;
fiat_p384_uint1 x1668;
fiat_p384_subborrowx_u32(&x1667, &x1668, 0x0, x1641, UINT32_C(0xffffffff));
@@ -5288,40 +5288,40 @@ static void fiat_p384_square(uint32_t out1[12], const uint32_t arg1[12]) {
static void fiat_p384_add(uint32_t out1[12], const uint32_t arg1[12], const uint32_t arg2[12]) {
uint32_t x1;
fiat_p384_uint1 x2;
- fiat_p384_addcarryx_u32(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p384_addcarryx_u32(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint32_t x3;
fiat_p384_uint1 x4;
- fiat_p384_addcarryx_u32(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p384_addcarryx_u32(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint32_t x5;
fiat_p384_uint1 x6;
- fiat_p384_addcarryx_u32(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p384_addcarryx_u32(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint32_t x7;
fiat_p384_uint1 x8;
- fiat_p384_addcarryx_u32(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p384_addcarryx_u32(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint32_t x9;
fiat_p384_uint1 x10;
- fiat_p384_addcarryx_u32(&x9, &x10, x8, (arg2[4]), (arg1[4]));
+ fiat_p384_addcarryx_u32(&x9, &x10, x8, (arg1[4]), (arg2[4]));
uint32_t x11;
fiat_p384_uint1 x12;
- fiat_p384_addcarryx_u32(&x11, &x12, x10, (arg2[5]), (arg1[5]));
+ fiat_p384_addcarryx_u32(&x11, &x12, x10, (arg1[5]), (arg2[5]));
uint32_t x13;
fiat_p384_uint1 x14;
- fiat_p384_addcarryx_u32(&x13, &x14, x12, (arg2[6]), (arg1[6]));
+ fiat_p384_addcarryx_u32(&x13, &x14, x12, (arg1[6]), (arg2[6]));
uint32_t x15;
fiat_p384_uint1 x16;
- fiat_p384_addcarryx_u32(&x15, &x16, x14, (arg2[7]), (arg1[7]));
+ fiat_p384_addcarryx_u32(&x15, &x16, x14, (arg1[7]), (arg2[7]));
uint32_t x17;
fiat_p384_uint1 x18;
- fiat_p384_addcarryx_u32(&x17, &x18, x16, (arg2[8]), (arg1[8]));
+ fiat_p384_addcarryx_u32(&x17, &x18, x16, (arg1[8]), (arg2[8]));
uint32_t x19;
fiat_p384_uint1 x20;
- fiat_p384_addcarryx_u32(&x19, &x20, x18, (arg2[9]), (arg1[9]));
+ fiat_p384_addcarryx_u32(&x19, &x20, x18, (arg1[9]), (arg2[9]));
uint32_t x21;
fiat_p384_uint1 x22;
- fiat_p384_addcarryx_u32(&x21, &x22, x20, (arg2[10]), (arg1[10]));
+ fiat_p384_addcarryx_u32(&x21, &x22, x20, (arg1[10]), (arg2[10]));
uint32_t x23;
fiat_p384_uint1 x24;
- fiat_p384_addcarryx_u32(&x23, &x24, x22, (arg2[11]), (arg1[11]));
+ fiat_p384_addcarryx_u32(&x23, &x24, x22, (arg1[11]), (arg2[11]));
uint32_t x25;
fiat_p384_uint1 x26;
fiat_p384_subborrowx_u32(&x25, &x26, 0x0, x1, UINT32_C(0xffffffff));
@@ -5455,40 +5455,40 @@ static void fiat_p384_sub(uint32_t out1[12], const uint32_t arg1[12], const uint
fiat_p384_cmovznz_u32(&x25, x24, 0x0, UINT32_C(0xffffffff));
uint32_t x26;
fiat_p384_uint1 x27;
- fiat_p384_addcarryx_u32(&x26, &x27, 0x0, (x25 & UINT32_C(0xffffffff)), x1);
+ fiat_p384_addcarryx_u32(&x26, &x27, 0x0, x1, (x25 & UINT32_C(0xffffffff)));
uint32_t x28;
fiat_p384_uint1 x29;
- fiat_p384_addcarryx_u32(&x28, &x29, x27, 0x0, x3);
+ fiat_p384_addcarryx_u32(&x28, &x29, x27, x3, 0x0);
uint32_t x30;
fiat_p384_uint1 x31;
- fiat_p384_addcarryx_u32(&x30, &x31, x29, 0x0, x5);
+ fiat_p384_addcarryx_u32(&x30, &x31, x29, x5, 0x0);
uint32_t x32;
fiat_p384_uint1 x33;
- fiat_p384_addcarryx_u32(&x32, &x33, x31, (x25 & UINT32_C(0xffffffff)), x7);
+ fiat_p384_addcarryx_u32(&x32, &x33, x31, x7, (x25 & UINT32_C(0xffffffff)));
uint32_t x34;
fiat_p384_uint1 x35;
- fiat_p384_addcarryx_u32(&x34, &x35, x33, (x25 & UINT32_C(0xfffffffe)), x9);
+ fiat_p384_addcarryx_u32(&x34, &x35, x33, x9, (x25 & UINT32_C(0xfffffffe)));
uint32_t x36;
fiat_p384_uint1 x37;
- fiat_p384_addcarryx_u32(&x36, &x37, x35, (x25 & UINT32_C(0xffffffff)), x11);
+ fiat_p384_addcarryx_u32(&x36, &x37, x35, x11, (x25 & UINT32_C(0xffffffff)));
uint32_t x38;
fiat_p384_uint1 x39;
- fiat_p384_addcarryx_u32(&x38, &x39, x37, (x25 & UINT32_C(0xffffffff)), x13);
+ fiat_p384_addcarryx_u32(&x38, &x39, x37, x13, (x25 & UINT32_C(0xffffffff)));
uint32_t x40;
fiat_p384_uint1 x41;
- fiat_p384_addcarryx_u32(&x40, &x41, x39, (x25 & UINT32_C(0xffffffff)), x15);
+ fiat_p384_addcarryx_u32(&x40, &x41, x39, x15, (x25 & UINT32_C(0xffffffff)));
uint32_t x42;
fiat_p384_uint1 x43;
- fiat_p384_addcarryx_u32(&x42, &x43, x41, (x25 & UINT32_C(0xffffffff)), x17);
+ fiat_p384_addcarryx_u32(&x42, &x43, x41, x17, (x25 & UINT32_C(0xffffffff)));
uint32_t x44;
fiat_p384_uint1 x45;
- fiat_p384_addcarryx_u32(&x44, &x45, x43, (x25 & UINT32_C(0xffffffff)), x19);
+ fiat_p384_addcarryx_u32(&x44, &x45, x43, x19, (x25 & UINT32_C(0xffffffff)));
uint32_t x46;
fiat_p384_uint1 x47;
- fiat_p384_addcarryx_u32(&x46, &x47, x45, (x25 & UINT32_C(0xffffffff)), x21);
+ fiat_p384_addcarryx_u32(&x46, &x47, x45, x21, (x25 & UINT32_C(0xffffffff)));
uint32_t x48;
fiat_p384_uint1 x49;
- fiat_p384_addcarryx_u32(&x48, &x49, x47, (x25 & UINT32_C(0xffffffff)), x23);
+ fiat_p384_addcarryx_u32(&x48, &x49, x47, x23, (x25 & UINT32_C(0xffffffff)));
out1[0] = x26;
out1[1] = x28;
out1[2] = x30;
@@ -5557,40 +5557,40 @@ static void fiat_p384_opp(uint32_t out1[12], const uint32_t arg1[12]) {
fiat_p384_cmovznz_u32(&x25, x24, 0x0, UINT32_C(0xffffffff));
uint32_t x26;
fiat_p384_uint1 x27;
- fiat_p384_addcarryx_u32(&x26, &x27, 0x0, (x25 & UINT32_C(0xffffffff)), x1);
+ fiat_p384_addcarryx_u32(&x26, &x27, 0x0, x1, (x25 & UINT32_C(0xffffffff)));
uint32_t x28;
fiat_p384_uint1 x29;
- fiat_p384_addcarryx_u32(&x28, &x29, x27, 0x0, x3);
+ fiat_p384_addcarryx_u32(&x28, &x29, x27, x3, 0x0);
uint32_t x30;
fiat_p384_uint1 x31;
- fiat_p384_addcarryx_u32(&x30, &x31, x29, 0x0, x5);
+ fiat_p384_addcarryx_u32(&x30, &x31, x29, x5, 0x0);
uint32_t x32;
fiat_p384_uint1 x33;
- fiat_p384_addcarryx_u32(&x32, &x33, x31, (x25 & UINT32_C(0xffffffff)), x7);
+ fiat_p384_addcarryx_u32(&x32, &x33, x31, x7, (x25 & UINT32_C(0xffffffff)));
uint32_t x34;
fiat_p384_uint1 x35;
- fiat_p384_addcarryx_u32(&x34, &x35, x33, (x25 & UINT32_C(0xfffffffe)), x9);
+ fiat_p384_addcarryx_u32(&x34, &x35, x33, x9, (x25 & UINT32_C(0xfffffffe)));
uint32_t x36;
fiat_p384_uint1 x37;
- fiat_p384_addcarryx_u32(&x36, &x37, x35, (x25 & UINT32_C(0xffffffff)), x11);
+ fiat_p384_addcarryx_u32(&x36, &x37, x35, x11, (x25 & UINT32_C(0xffffffff)));
uint32_t x38;
fiat_p384_uint1 x39;
- fiat_p384_addcarryx_u32(&x38, &x39, x37, (x25 & UINT32_C(0xffffffff)), x13);
+ fiat_p384_addcarryx_u32(&x38, &x39, x37, x13, (x25 & UINT32_C(0xffffffff)));
uint32_t x40;
fiat_p384_uint1 x41;
- fiat_p384_addcarryx_u32(&x40, &x41, x39, (x25 & UINT32_C(0xffffffff)), x15);
+ fiat_p384_addcarryx_u32(&x40, &x41, x39, x15, (x25 & UINT32_C(0xffffffff)));
uint32_t x42;
fiat_p384_uint1 x43;
- fiat_p384_addcarryx_u32(&x42, &x43, x41, (x25 & UINT32_C(0xffffffff)), x17);
+ fiat_p384_addcarryx_u32(&x42, &x43, x41, x17, (x25 & UINT32_C(0xffffffff)));
uint32_t x44;
fiat_p384_uint1 x45;
- fiat_p384_addcarryx_u32(&x44, &x45, x43, (x25 & UINT32_C(0xffffffff)), x19);
+ fiat_p384_addcarryx_u32(&x44, &x45, x43, x19, (x25 & UINT32_C(0xffffffff)));
uint32_t x46;
fiat_p384_uint1 x47;
- fiat_p384_addcarryx_u32(&x46, &x47, x45, (x25 & UINT32_C(0xffffffff)), x21);
+ fiat_p384_addcarryx_u32(&x46, &x47, x45, x21, (x25 & UINT32_C(0xffffffff)));
uint32_t x48;
fiat_p384_uint1 x49;
- fiat_p384_addcarryx_u32(&x48, &x49, x47, (x25 & UINT32_C(0xffffffff)), x23);
+ fiat_p384_addcarryx_u32(&x48, &x49, x47, x23, (x25 & UINT32_C(0xffffffff)));
out1[0] = x26;
out1[1] = x28;
out1[2] = x30;
@@ -5652,37 +5652,37 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x20, &x21, x1, UINT32_C(0xffffffff));
uint32_t x22;
fiat_p384_uint1 x23;
- fiat_p384_addcarryx_u32(&x22, &x23, 0x0, x16, x19);
+ fiat_p384_addcarryx_u32(&x22, &x23, 0x0, x19, x16);
uint32_t x24;
fiat_p384_uint1 x25;
- fiat_p384_addcarryx_u32(&x24, &x25, x23, x14, x17);
+ fiat_p384_addcarryx_u32(&x24, &x25, x23, x17, x14);
uint32_t x26;
fiat_p384_uint1 x27;
- fiat_p384_addcarryx_u32(&x26, &x27, x25, x12, x15);
+ fiat_p384_addcarryx_u32(&x26, &x27, x25, x15, x12);
uint32_t x28;
fiat_p384_uint1 x29;
- fiat_p384_addcarryx_u32(&x28, &x29, x27, x10, x13);
+ fiat_p384_addcarryx_u32(&x28, &x29, x27, x13, x10);
uint32_t x30;
fiat_p384_uint1 x31;
- fiat_p384_addcarryx_u32(&x30, &x31, x29, x8, x11);
+ fiat_p384_addcarryx_u32(&x30, &x31, x29, x11, x8);
uint32_t x32;
fiat_p384_uint1 x33;
- fiat_p384_addcarryx_u32(&x32, &x33, x31, x6, x9);
+ fiat_p384_addcarryx_u32(&x32, &x33, x31, x9, x6);
uint32_t x34;
fiat_p384_uint1 x35;
- fiat_p384_addcarryx_u32(&x34, &x35, x33, x4, x7);
+ fiat_p384_addcarryx_u32(&x34, &x35, x33, x7, x4);
uint32_t x36;
fiat_p384_uint1 x37;
- fiat_p384_addcarryx_u32(&x36, &x37, x35, x2, x5);
+ fiat_p384_addcarryx_u32(&x36, &x37, x35, x5, x2);
uint32_t x38;
fiat_p384_uint1 x39;
- fiat_p384_addcarryx_u32(&x38, &x39, 0x0, x20, x1);
+ fiat_p384_addcarryx_u32(&x38, &x39, 0x0, x1, x20);
uint32_t x40;
fiat_p384_uint1 x41;
- fiat_p384_addcarryx_u32(&x40, &x41, x39, x21, 0x0);
+ fiat_p384_addcarryx_u32(&x40, &x41, x39, 0x0, x21);
uint32_t x42;
fiat_p384_uint1 x43;
- fiat_p384_addcarryx_u32(&x42, &x43, 0x0, (arg1[1]), x40);
+ fiat_p384_addcarryx_u32(&x42, &x43, 0x0, x40, (arg1[1]));
uint32_t x44;
uint32_t x45;
fiat_p384_mulx_u32(&x44, &x45, x42, UINT32_C(0xffffffff));
@@ -5715,112 +5715,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x62, &x63, x42, UINT32_C(0xffffffff));
uint32_t x64;
fiat_p384_uint1 x65;
- fiat_p384_addcarryx_u32(&x64, &x65, 0x0, x58, x61);
+ fiat_p384_addcarryx_u32(&x64, &x65, 0x0, x61, x58);
uint32_t x66;
fiat_p384_uint1 x67;
- fiat_p384_addcarryx_u32(&x66, &x67, x65, x56, x59);
+ fiat_p384_addcarryx_u32(&x66, &x67, x65, x59, x56);
uint32_t x68;
fiat_p384_uint1 x69;
- fiat_p384_addcarryx_u32(&x68, &x69, x67, x54, x57);
+ fiat_p384_addcarryx_u32(&x68, &x69, x67, x57, x54);
uint32_t x70;
fiat_p384_uint1 x71;
- fiat_p384_addcarryx_u32(&x70, &x71, x69, x52, x55);
+ fiat_p384_addcarryx_u32(&x70, &x71, x69, x55, x52);
uint32_t x72;
fiat_p384_uint1 x73;
- fiat_p384_addcarryx_u32(&x72, &x73, x71, x50, x53);
+ fiat_p384_addcarryx_u32(&x72, &x73, x71, x53, x50);
uint32_t x74;
fiat_p384_uint1 x75;
- fiat_p384_addcarryx_u32(&x74, &x75, x73, x48, x51);
+ fiat_p384_addcarryx_u32(&x74, &x75, x73, x51, x48);
uint32_t x76;
fiat_p384_uint1 x77;
- fiat_p384_addcarryx_u32(&x76, &x77, x75, x46, x49);
+ fiat_p384_addcarryx_u32(&x76, &x77, x75, x49, x46);
uint32_t x78;
fiat_p384_uint1 x79;
- fiat_p384_addcarryx_u32(&x78, &x79, x77, x44, x47);
+ fiat_p384_addcarryx_u32(&x78, &x79, x77, x47, x44);
uint32_t x80;
fiat_p384_uint1 x81;
fiat_p384_addcarryx_u32(&x80, &x81, x43, 0x0, 0x0);
uint32_t x82;
fiat_p384_uint1 x83;
- fiat_p384_addcarryx_u32(&x82, &x83, 0x0, x62, x42);
+ fiat_p384_addcarryx_u32(&x82, &x83, 0x0, x42, x62);
uint32_t x84;
fiat_p384_uint1 x85;
- fiat_p384_addcarryx_u32(&x84, &x85, x83, x63, (fiat_p384_uint1)x80);
+ fiat_p384_addcarryx_u32(&x84, &x85, x83, (fiat_p384_uint1)x80, x63);
uint32_t x86;
fiat_p384_uint1 x87;
- fiat_p384_addcarryx_u32(&x86, &x87, x85, 0x0, x18);
+ fiat_p384_addcarryx_u32(&x86, &x87, x85, x18, 0x0);
uint32_t x88;
fiat_p384_uint1 x89;
- fiat_p384_addcarryx_u32(&x88, &x89, x87, x60, x22);
+ fiat_p384_addcarryx_u32(&x88, &x89, x87, x22, x60);
uint32_t x90;
fiat_p384_uint1 x91;
- fiat_p384_addcarryx_u32(&x90, &x91, x89, x64, x24);
+ fiat_p384_addcarryx_u32(&x90, &x91, x89, x24, x64);
uint32_t x92;
fiat_p384_uint1 x93;
- fiat_p384_addcarryx_u32(&x92, &x93, x91, x66, x26);
+ fiat_p384_addcarryx_u32(&x92, &x93, x91, x26, x66);
uint32_t x94;
fiat_p384_uint1 x95;
- fiat_p384_addcarryx_u32(&x94, &x95, x93, x68, x28);
+ fiat_p384_addcarryx_u32(&x94, &x95, x93, x28, x68);
uint32_t x96;
fiat_p384_uint1 x97;
- fiat_p384_addcarryx_u32(&x96, &x97, x95, x70, x30);
+ fiat_p384_addcarryx_u32(&x96, &x97, x95, x30, x70);
uint32_t x98;
fiat_p384_uint1 x99;
- fiat_p384_addcarryx_u32(&x98, &x99, x97, x72, x32);
+ fiat_p384_addcarryx_u32(&x98, &x99, x97, x32, x72);
uint32_t x100;
fiat_p384_uint1 x101;
- fiat_p384_addcarryx_u32(&x100, &x101, x99, x74, x34);
+ fiat_p384_addcarryx_u32(&x100, &x101, x99, x34, x74);
uint32_t x102;
fiat_p384_uint1 x103;
- fiat_p384_addcarryx_u32(&x102, &x103, x101, x76, x36);
+ fiat_p384_addcarryx_u32(&x102, &x103, x101, x36, x76);
uint32_t x104;
fiat_p384_uint1 x105;
- fiat_p384_addcarryx_u32(&x104, &x105, x37, 0x0, x3);
+ fiat_p384_addcarryx_u32(&x104, &x105, x37, x3, 0x0);
uint32_t x106;
fiat_p384_uint1 x107;
- fiat_p384_addcarryx_u32(&x106, &x107, x103, x78, x104);
+ fiat_p384_addcarryx_u32(&x106, &x107, x103, x104, x78);
uint32_t x108;
fiat_p384_uint1 x109;
- fiat_p384_addcarryx_u32(&x108, &x109, x79, 0x0, x45);
+ fiat_p384_addcarryx_u32(&x108, &x109, x79, x45, 0x0);
uint32_t x110;
fiat_p384_uint1 x111;
- fiat_p384_addcarryx_u32(&x110, &x111, x107, x108, 0x0);
+ fiat_p384_addcarryx_u32(&x110, &x111, x107, 0x0, x108);
uint32_t x112;
fiat_p384_uint1 x113;
- fiat_p384_addcarryx_u32(&x112, &x113, 0x0, (arg1[2]), x84);
+ fiat_p384_addcarryx_u32(&x112, &x113, 0x0, x84, (arg1[2]));
uint32_t x114;
fiat_p384_uint1 x115;
- fiat_p384_addcarryx_u32(&x114, &x115, x113, 0x0, x86);
+ fiat_p384_addcarryx_u32(&x114, &x115, x113, x86, 0x0);
uint32_t x116;
fiat_p384_uint1 x117;
- fiat_p384_addcarryx_u32(&x116, &x117, x115, 0x0, x88);
+ fiat_p384_addcarryx_u32(&x116, &x117, x115, x88, 0x0);
uint32_t x118;
fiat_p384_uint1 x119;
- fiat_p384_addcarryx_u32(&x118, &x119, x117, 0x0, x90);
+ fiat_p384_addcarryx_u32(&x118, &x119, x117, x90, 0x0);
uint32_t x120;
fiat_p384_uint1 x121;
- fiat_p384_addcarryx_u32(&x120, &x121, x119, 0x0, x92);
+ fiat_p384_addcarryx_u32(&x120, &x121, x119, x92, 0x0);
uint32_t x122;
fiat_p384_uint1 x123;
- fiat_p384_addcarryx_u32(&x122, &x123, x121, 0x0, x94);
+ fiat_p384_addcarryx_u32(&x122, &x123, x121, x94, 0x0);
uint32_t x124;
fiat_p384_uint1 x125;
- fiat_p384_addcarryx_u32(&x124, &x125, x123, 0x0, x96);
+ fiat_p384_addcarryx_u32(&x124, &x125, x123, x96, 0x0);
uint32_t x126;
fiat_p384_uint1 x127;
- fiat_p384_addcarryx_u32(&x126, &x127, x125, 0x0, x98);
+ fiat_p384_addcarryx_u32(&x126, &x127, x125, x98, 0x0);
uint32_t x128;
fiat_p384_uint1 x129;
- fiat_p384_addcarryx_u32(&x128, &x129, x127, 0x0, x100);
+ fiat_p384_addcarryx_u32(&x128, &x129, x127, x100, 0x0);
uint32_t x130;
fiat_p384_uint1 x131;
- fiat_p384_addcarryx_u32(&x130, &x131, x129, 0x0, x102);
+ fiat_p384_addcarryx_u32(&x130, &x131, x129, x102, 0x0);
uint32_t x132;
fiat_p384_uint1 x133;
- fiat_p384_addcarryx_u32(&x132, &x133, x131, 0x0, x106);
+ fiat_p384_addcarryx_u32(&x132, &x133, x131, x106, 0x0);
uint32_t x134;
fiat_p384_uint1 x135;
- fiat_p384_addcarryx_u32(&x134, &x135, x133, 0x0, x110);
+ fiat_p384_addcarryx_u32(&x134, &x135, x133, x110, 0x0);
uint32_t x136;
uint32_t x137;
fiat_p384_mulx_u32(&x136, &x137, x112, UINT32_C(0xffffffff));
@@ -5853,112 +5853,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x154, &x155, x112, UINT32_C(0xffffffff));
uint32_t x156;
fiat_p384_uint1 x157;
- fiat_p384_addcarryx_u32(&x156, &x157, 0x0, x150, x153);
+ fiat_p384_addcarryx_u32(&x156, &x157, 0x0, x153, x150);
uint32_t x158;
fiat_p384_uint1 x159;
- fiat_p384_addcarryx_u32(&x158, &x159, x157, x148, x151);
+ fiat_p384_addcarryx_u32(&x158, &x159, x157, x151, x148);
uint32_t x160;
fiat_p384_uint1 x161;
- fiat_p384_addcarryx_u32(&x160, &x161, x159, x146, x149);
+ fiat_p384_addcarryx_u32(&x160, &x161, x159, x149, x146);
uint32_t x162;
fiat_p384_uint1 x163;
- fiat_p384_addcarryx_u32(&x162, &x163, x161, x144, x147);
+ fiat_p384_addcarryx_u32(&x162, &x163, x161, x147, x144);
uint32_t x164;
fiat_p384_uint1 x165;
- fiat_p384_addcarryx_u32(&x164, &x165, x163, x142, x145);
+ fiat_p384_addcarryx_u32(&x164, &x165, x163, x145, x142);
uint32_t x166;
fiat_p384_uint1 x167;
- fiat_p384_addcarryx_u32(&x166, &x167, x165, x140, x143);
+ fiat_p384_addcarryx_u32(&x166, &x167, x165, x143, x140);
uint32_t x168;
fiat_p384_uint1 x169;
- fiat_p384_addcarryx_u32(&x168, &x169, x167, x138, x141);
+ fiat_p384_addcarryx_u32(&x168, &x169, x167, x141, x138);
uint32_t x170;
fiat_p384_uint1 x171;
- fiat_p384_addcarryx_u32(&x170, &x171, x169, x136, x139);
+ fiat_p384_addcarryx_u32(&x170, &x171, x169, x139, x136);
uint32_t x172;
fiat_p384_uint1 x173;
- fiat_p384_addcarryx_u32(&x172, &x173, 0x0, x154, x112);
+ fiat_p384_addcarryx_u32(&x172, &x173, 0x0, x112, x154);
uint32_t x174;
fiat_p384_uint1 x175;
- fiat_p384_addcarryx_u32(&x174, &x175, x173, x155, x114);
+ fiat_p384_addcarryx_u32(&x174, &x175, x173, x114, x155);
uint32_t x176;
fiat_p384_uint1 x177;
- fiat_p384_addcarryx_u32(&x176, &x177, x175, 0x0, x116);
+ fiat_p384_addcarryx_u32(&x176, &x177, x175, x116, 0x0);
uint32_t x178;
fiat_p384_uint1 x179;
- fiat_p384_addcarryx_u32(&x178, &x179, x177, x152, x118);
+ fiat_p384_addcarryx_u32(&x178, &x179, x177, x118, x152);
uint32_t x180;
fiat_p384_uint1 x181;
- fiat_p384_addcarryx_u32(&x180, &x181, x179, x156, x120);
+ fiat_p384_addcarryx_u32(&x180, &x181, x179, x120, x156);
uint32_t x182;
fiat_p384_uint1 x183;
- fiat_p384_addcarryx_u32(&x182, &x183, x181, x158, x122);
+ fiat_p384_addcarryx_u32(&x182, &x183, x181, x122, x158);
uint32_t x184;
fiat_p384_uint1 x185;
- fiat_p384_addcarryx_u32(&x184, &x185, x183, x160, x124);
+ fiat_p384_addcarryx_u32(&x184, &x185, x183, x124, x160);
uint32_t x186;
fiat_p384_uint1 x187;
- fiat_p384_addcarryx_u32(&x186, &x187, x185, x162, x126);
+ fiat_p384_addcarryx_u32(&x186, &x187, x185, x126, x162);
uint32_t x188;
fiat_p384_uint1 x189;
- fiat_p384_addcarryx_u32(&x188, &x189, x187, x164, x128);
+ fiat_p384_addcarryx_u32(&x188, &x189, x187, x128, x164);
uint32_t x190;
fiat_p384_uint1 x191;
- fiat_p384_addcarryx_u32(&x190, &x191, x189, x166, x130);
+ fiat_p384_addcarryx_u32(&x190, &x191, x189, x130, x166);
uint32_t x192;
fiat_p384_uint1 x193;
- fiat_p384_addcarryx_u32(&x192, &x193, x191, x168, x132);
+ fiat_p384_addcarryx_u32(&x192, &x193, x191, x132, x168);
uint32_t x194;
fiat_p384_uint1 x195;
- fiat_p384_addcarryx_u32(&x194, &x195, x193, x170, x134);
+ fiat_p384_addcarryx_u32(&x194, &x195, x193, x134, x170);
uint32_t x196;
fiat_p384_uint1 x197;
- fiat_p384_addcarryx_u32(&x196, &x197, x111, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x196, &x197, x171, x137, 0x0);
uint32_t x198;
fiat_p384_uint1 x199;
- fiat_p384_addcarryx_u32(&x198, &x199, x135, 0x0, (fiat_p384_uint1)x196);
+ fiat_p384_addcarryx_u32(&x198, &x199, x111, 0x0, 0x0);
uint32_t x200;
fiat_p384_uint1 x201;
- fiat_p384_addcarryx_u32(&x200, &x201, x171, 0x0, x137);
+ fiat_p384_addcarryx_u32(&x200, &x201, x135, (fiat_p384_uint1)x198, 0x0);
uint32_t x202;
fiat_p384_uint1 x203;
- fiat_p384_addcarryx_u32(&x202, &x203, x195, x200, x198);
+ fiat_p384_addcarryx_u32(&x202, &x203, x195, x200, x196);
uint32_t x204;
fiat_p384_uint1 x205;
- fiat_p384_addcarryx_u32(&x204, &x205, 0x0, (arg1[3]), x174);
+ fiat_p384_addcarryx_u32(&x204, &x205, 0x0, x174, (arg1[3]));
uint32_t x206;
fiat_p384_uint1 x207;
- fiat_p384_addcarryx_u32(&x206, &x207, x205, 0x0, x176);
+ fiat_p384_addcarryx_u32(&x206, &x207, x205, x176, 0x0);
uint32_t x208;
fiat_p384_uint1 x209;
- fiat_p384_addcarryx_u32(&x208, &x209, x207, 0x0, x178);
+ fiat_p384_addcarryx_u32(&x208, &x209, x207, x178, 0x0);
uint32_t x210;
fiat_p384_uint1 x211;
- fiat_p384_addcarryx_u32(&x210, &x211, x209, 0x0, x180);
+ fiat_p384_addcarryx_u32(&x210, &x211, x209, x180, 0x0);
uint32_t x212;
fiat_p384_uint1 x213;
- fiat_p384_addcarryx_u32(&x212, &x213, x211, 0x0, x182);
+ fiat_p384_addcarryx_u32(&x212, &x213, x211, x182, 0x0);
uint32_t x214;
fiat_p384_uint1 x215;
- fiat_p384_addcarryx_u32(&x214, &x215, x213, 0x0, x184);
+ fiat_p384_addcarryx_u32(&x214, &x215, x213, x184, 0x0);
uint32_t x216;
fiat_p384_uint1 x217;
- fiat_p384_addcarryx_u32(&x216, &x217, x215, 0x0, x186);
+ fiat_p384_addcarryx_u32(&x216, &x217, x215, x186, 0x0);
uint32_t x218;
fiat_p384_uint1 x219;
- fiat_p384_addcarryx_u32(&x218, &x219, x217, 0x0, x188);
+ fiat_p384_addcarryx_u32(&x218, &x219, x217, x188, 0x0);
uint32_t x220;
fiat_p384_uint1 x221;
- fiat_p384_addcarryx_u32(&x220, &x221, x219, 0x0, x190);
+ fiat_p384_addcarryx_u32(&x220, &x221, x219, x190, 0x0);
uint32_t x222;
fiat_p384_uint1 x223;
- fiat_p384_addcarryx_u32(&x222, &x223, x221, 0x0, x192);
+ fiat_p384_addcarryx_u32(&x222, &x223, x221, x192, 0x0);
uint32_t x224;
fiat_p384_uint1 x225;
- fiat_p384_addcarryx_u32(&x224, &x225, x223, 0x0, x194);
+ fiat_p384_addcarryx_u32(&x224, &x225, x223, x194, 0x0);
uint32_t x226;
fiat_p384_uint1 x227;
- fiat_p384_addcarryx_u32(&x226, &x227, x225, 0x0, x202);
+ fiat_p384_addcarryx_u32(&x226, &x227, x225, x202, 0x0);
uint32_t x228;
uint32_t x229;
fiat_p384_mulx_u32(&x228, &x229, x204, UINT32_C(0xffffffff));
@@ -5991,112 +5991,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x246, &x247, x204, UINT32_C(0xffffffff));
uint32_t x248;
fiat_p384_uint1 x249;
- fiat_p384_addcarryx_u32(&x248, &x249, 0x0, x242, x245);
+ fiat_p384_addcarryx_u32(&x248, &x249, 0x0, x245, x242);
uint32_t x250;
fiat_p384_uint1 x251;
- fiat_p384_addcarryx_u32(&x250, &x251, x249, x240, x243);
+ fiat_p384_addcarryx_u32(&x250, &x251, x249, x243, x240);
uint32_t x252;
fiat_p384_uint1 x253;
- fiat_p384_addcarryx_u32(&x252, &x253, x251, x238, x241);
+ fiat_p384_addcarryx_u32(&x252, &x253, x251, x241, x238);
uint32_t x254;
fiat_p384_uint1 x255;
- fiat_p384_addcarryx_u32(&x254, &x255, x253, x236, x239);
+ fiat_p384_addcarryx_u32(&x254, &x255, x253, x239, x236);
uint32_t x256;
fiat_p384_uint1 x257;
- fiat_p384_addcarryx_u32(&x256, &x257, x255, x234, x237);
+ fiat_p384_addcarryx_u32(&x256, &x257, x255, x237, x234);
uint32_t x258;
fiat_p384_uint1 x259;
- fiat_p384_addcarryx_u32(&x258, &x259, x257, x232, x235);
+ fiat_p384_addcarryx_u32(&x258, &x259, x257, x235, x232);
uint32_t x260;
fiat_p384_uint1 x261;
- fiat_p384_addcarryx_u32(&x260, &x261, x259, x230, x233);
+ fiat_p384_addcarryx_u32(&x260, &x261, x259, x233, x230);
uint32_t x262;
fiat_p384_uint1 x263;
- fiat_p384_addcarryx_u32(&x262, &x263, x261, x228, x231);
+ fiat_p384_addcarryx_u32(&x262, &x263, x261, x231, x228);
uint32_t x264;
fiat_p384_uint1 x265;
- fiat_p384_addcarryx_u32(&x264, &x265, 0x0, x246, x204);
+ fiat_p384_addcarryx_u32(&x264, &x265, 0x0, x204, x246);
uint32_t x266;
fiat_p384_uint1 x267;
- fiat_p384_addcarryx_u32(&x266, &x267, x265, x247, x206);
+ fiat_p384_addcarryx_u32(&x266, &x267, x265, x206, x247);
uint32_t x268;
fiat_p384_uint1 x269;
- fiat_p384_addcarryx_u32(&x268, &x269, x267, 0x0, x208);
+ fiat_p384_addcarryx_u32(&x268, &x269, x267, x208, 0x0);
uint32_t x270;
fiat_p384_uint1 x271;
- fiat_p384_addcarryx_u32(&x270, &x271, x269, x244, x210);
+ fiat_p384_addcarryx_u32(&x270, &x271, x269, x210, x244);
uint32_t x272;
fiat_p384_uint1 x273;
- fiat_p384_addcarryx_u32(&x272, &x273, x271, x248, x212);
+ fiat_p384_addcarryx_u32(&x272, &x273, x271, x212, x248);
uint32_t x274;
fiat_p384_uint1 x275;
- fiat_p384_addcarryx_u32(&x274, &x275, x273, x250, x214);
+ fiat_p384_addcarryx_u32(&x274, &x275, x273, x214, x250);
uint32_t x276;
fiat_p384_uint1 x277;
- fiat_p384_addcarryx_u32(&x276, &x277, x275, x252, x216);
+ fiat_p384_addcarryx_u32(&x276, &x277, x275, x216, x252);
uint32_t x278;
fiat_p384_uint1 x279;
- fiat_p384_addcarryx_u32(&x278, &x279, x277, x254, x218);
+ fiat_p384_addcarryx_u32(&x278, &x279, x277, x218, x254);
uint32_t x280;
fiat_p384_uint1 x281;
- fiat_p384_addcarryx_u32(&x280, &x281, x279, x256, x220);
+ fiat_p384_addcarryx_u32(&x280, &x281, x279, x220, x256);
uint32_t x282;
fiat_p384_uint1 x283;
- fiat_p384_addcarryx_u32(&x282, &x283, x281, x258, x222);
+ fiat_p384_addcarryx_u32(&x282, &x283, x281, x222, x258);
uint32_t x284;
fiat_p384_uint1 x285;
- fiat_p384_addcarryx_u32(&x284, &x285, x283, x260, x224);
+ fiat_p384_addcarryx_u32(&x284, &x285, x283, x224, x260);
uint32_t x286;
fiat_p384_uint1 x287;
- fiat_p384_addcarryx_u32(&x286, &x287, x285, x262, x226);
+ fiat_p384_addcarryx_u32(&x286, &x287, x285, x226, x262);
uint32_t x288;
fiat_p384_uint1 x289;
- fiat_p384_addcarryx_u32(&x288, &x289, x203, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x288, &x289, x263, x229, 0x0);
uint32_t x290;
fiat_p384_uint1 x291;
- fiat_p384_addcarryx_u32(&x290, &x291, x227, 0x0, (fiat_p384_uint1)x288);
+ fiat_p384_addcarryx_u32(&x290, &x291, x203, 0x0, 0x0);
uint32_t x292;
fiat_p384_uint1 x293;
- fiat_p384_addcarryx_u32(&x292, &x293, x263, 0x0, x229);
+ fiat_p384_addcarryx_u32(&x292, &x293, x227, (fiat_p384_uint1)x290, 0x0);
uint32_t x294;
fiat_p384_uint1 x295;
- fiat_p384_addcarryx_u32(&x294, &x295, x287, x292, x290);
+ fiat_p384_addcarryx_u32(&x294, &x295, x287, x292, x288);
uint32_t x296;
fiat_p384_uint1 x297;
- fiat_p384_addcarryx_u32(&x296, &x297, 0x0, (arg1[4]), x266);
+ fiat_p384_addcarryx_u32(&x296, &x297, 0x0, x266, (arg1[4]));
uint32_t x298;
fiat_p384_uint1 x299;
- fiat_p384_addcarryx_u32(&x298, &x299, x297, 0x0, x268);
+ fiat_p384_addcarryx_u32(&x298, &x299, x297, x268, 0x0);
uint32_t x300;
fiat_p384_uint1 x301;
- fiat_p384_addcarryx_u32(&x300, &x301, x299, 0x0, x270);
+ fiat_p384_addcarryx_u32(&x300, &x301, x299, x270, 0x0);
uint32_t x302;
fiat_p384_uint1 x303;
- fiat_p384_addcarryx_u32(&x302, &x303, x301, 0x0, x272);
+ fiat_p384_addcarryx_u32(&x302, &x303, x301, x272, 0x0);
uint32_t x304;
fiat_p384_uint1 x305;
- fiat_p384_addcarryx_u32(&x304, &x305, x303, 0x0, x274);
+ fiat_p384_addcarryx_u32(&x304, &x305, x303, x274, 0x0);
uint32_t x306;
fiat_p384_uint1 x307;
- fiat_p384_addcarryx_u32(&x306, &x307, x305, 0x0, x276);
+ fiat_p384_addcarryx_u32(&x306, &x307, x305, x276, 0x0);
uint32_t x308;
fiat_p384_uint1 x309;
- fiat_p384_addcarryx_u32(&x308, &x309, x307, 0x0, x278);
+ fiat_p384_addcarryx_u32(&x308, &x309, x307, x278, 0x0);
uint32_t x310;
fiat_p384_uint1 x311;
- fiat_p384_addcarryx_u32(&x310, &x311, x309, 0x0, x280);
+ fiat_p384_addcarryx_u32(&x310, &x311, x309, x280, 0x0);
uint32_t x312;
fiat_p384_uint1 x313;
- fiat_p384_addcarryx_u32(&x312, &x313, x311, 0x0, x282);
+ fiat_p384_addcarryx_u32(&x312, &x313, x311, x282, 0x0);
uint32_t x314;
fiat_p384_uint1 x315;
- fiat_p384_addcarryx_u32(&x314, &x315, x313, 0x0, x284);
+ fiat_p384_addcarryx_u32(&x314, &x315, x313, x284, 0x0);
uint32_t x316;
fiat_p384_uint1 x317;
- fiat_p384_addcarryx_u32(&x316, &x317, x315, 0x0, x286);
+ fiat_p384_addcarryx_u32(&x316, &x317, x315, x286, 0x0);
uint32_t x318;
fiat_p384_uint1 x319;
- fiat_p384_addcarryx_u32(&x318, &x319, x317, 0x0, x294);
+ fiat_p384_addcarryx_u32(&x318, &x319, x317, x294, 0x0);
uint32_t x320;
uint32_t x321;
fiat_p384_mulx_u32(&x320, &x321, x296, UINT32_C(0xffffffff));
@@ -6129,112 +6129,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x338, &x339, x296, UINT32_C(0xffffffff));
uint32_t x340;
fiat_p384_uint1 x341;
- fiat_p384_addcarryx_u32(&x340, &x341, 0x0, x334, x337);
+ fiat_p384_addcarryx_u32(&x340, &x341, 0x0, x337, x334);
uint32_t x342;
fiat_p384_uint1 x343;
- fiat_p384_addcarryx_u32(&x342, &x343, x341, x332, x335);
+ fiat_p384_addcarryx_u32(&x342, &x343, x341, x335, x332);
uint32_t x344;
fiat_p384_uint1 x345;
- fiat_p384_addcarryx_u32(&x344, &x345, x343, x330, x333);
+ fiat_p384_addcarryx_u32(&x344, &x345, x343, x333, x330);
uint32_t x346;
fiat_p384_uint1 x347;
- fiat_p384_addcarryx_u32(&x346, &x347, x345, x328, x331);
+ fiat_p384_addcarryx_u32(&x346, &x347, x345, x331, x328);
uint32_t x348;
fiat_p384_uint1 x349;
- fiat_p384_addcarryx_u32(&x348, &x349, x347, x326, x329);
+ fiat_p384_addcarryx_u32(&x348, &x349, x347, x329, x326);
uint32_t x350;
fiat_p384_uint1 x351;
- fiat_p384_addcarryx_u32(&x350, &x351, x349, x324, x327);
+ fiat_p384_addcarryx_u32(&x350, &x351, x349, x327, x324);
uint32_t x352;
fiat_p384_uint1 x353;
- fiat_p384_addcarryx_u32(&x352, &x353, x351, x322, x325);
+ fiat_p384_addcarryx_u32(&x352, &x353, x351, x325, x322);
uint32_t x354;
fiat_p384_uint1 x355;
- fiat_p384_addcarryx_u32(&x354, &x355, x353, x320, x323);
+ fiat_p384_addcarryx_u32(&x354, &x355, x353, x323, x320);
uint32_t x356;
fiat_p384_uint1 x357;
- fiat_p384_addcarryx_u32(&x356, &x357, 0x0, x338, x296);
+ fiat_p384_addcarryx_u32(&x356, &x357, 0x0, x296, x338);
uint32_t x358;
fiat_p384_uint1 x359;
- fiat_p384_addcarryx_u32(&x358, &x359, x357, x339, x298);
+ fiat_p384_addcarryx_u32(&x358, &x359, x357, x298, x339);
uint32_t x360;
fiat_p384_uint1 x361;
- fiat_p384_addcarryx_u32(&x360, &x361, x359, 0x0, x300);
+ fiat_p384_addcarryx_u32(&x360, &x361, x359, x300, 0x0);
uint32_t x362;
fiat_p384_uint1 x363;
- fiat_p384_addcarryx_u32(&x362, &x363, x361, x336, x302);
+ fiat_p384_addcarryx_u32(&x362, &x363, x361, x302, x336);
uint32_t x364;
fiat_p384_uint1 x365;
- fiat_p384_addcarryx_u32(&x364, &x365, x363, x340, x304);
+ fiat_p384_addcarryx_u32(&x364, &x365, x363, x304, x340);
uint32_t x366;
fiat_p384_uint1 x367;
- fiat_p384_addcarryx_u32(&x366, &x367, x365, x342, x306);
+ fiat_p384_addcarryx_u32(&x366, &x367, x365, x306, x342);
uint32_t x368;
fiat_p384_uint1 x369;
- fiat_p384_addcarryx_u32(&x368, &x369, x367, x344, x308);
+ fiat_p384_addcarryx_u32(&x368, &x369, x367, x308, x344);
uint32_t x370;
fiat_p384_uint1 x371;
- fiat_p384_addcarryx_u32(&x370, &x371, x369, x346, x310);
+ fiat_p384_addcarryx_u32(&x370, &x371, x369, x310, x346);
uint32_t x372;
fiat_p384_uint1 x373;
- fiat_p384_addcarryx_u32(&x372, &x373, x371, x348, x312);
+ fiat_p384_addcarryx_u32(&x372, &x373, x371, x312, x348);
uint32_t x374;
fiat_p384_uint1 x375;
- fiat_p384_addcarryx_u32(&x374, &x375, x373, x350, x314);
+ fiat_p384_addcarryx_u32(&x374, &x375, x373, x314, x350);
uint32_t x376;
fiat_p384_uint1 x377;
- fiat_p384_addcarryx_u32(&x376, &x377, x375, x352, x316);
+ fiat_p384_addcarryx_u32(&x376, &x377, x375, x316, x352);
uint32_t x378;
fiat_p384_uint1 x379;
- fiat_p384_addcarryx_u32(&x378, &x379, x377, x354, x318);
+ fiat_p384_addcarryx_u32(&x378, &x379, x377, x318, x354);
uint32_t x380;
fiat_p384_uint1 x381;
- fiat_p384_addcarryx_u32(&x380, &x381, x295, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x380, &x381, x355, x321, 0x0);
uint32_t x382;
fiat_p384_uint1 x383;
- fiat_p384_addcarryx_u32(&x382, &x383, x319, 0x0, (fiat_p384_uint1)x380);
+ fiat_p384_addcarryx_u32(&x382, &x383, x295, 0x0, 0x0);
uint32_t x384;
fiat_p384_uint1 x385;
- fiat_p384_addcarryx_u32(&x384, &x385, x355, 0x0, x321);
+ fiat_p384_addcarryx_u32(&x384, &x385, x319, (fiat_p384_uint1)x382, 0x0);
uint32_t x386;
fiat_p384_uint1 x387;
- fiat_p384_addcarryx_u32(&x386, &x387, x379, x384, x382);
+ fiat_p384_addcarryx_u32(&x386, &x387, x379, x384, x380);
uint32_t x388;
fiat_p384_uint1 x389;
- fiat_p384_addcarryx_u32(&x388, &x389, 0x0, (arg1[5]), x358);
+ fiat_p384_addcarryx_u32(&x388, &x389, 0x0, x358, (arg1[5]));
uint32_t x390;
fiat_p384_uint1 x391;
- fiat_p384_addcarryx_u32(&x390, &x391, x389, 0x0, x360);
+ fiat_p384_addcarryx_u32(&x390, &x391, x389, x360, 0x0);
uint32_t x392;
fiat_p384_uint1 x393;
- fiat_p384_addcarryx_u32(&x392, &x393, x391, 0x0, x362);
+ fiat_p384_addcarryx_u32(&x392, &x393, x391, x362, 0x0);
uint32_t x394;
fiat_p384_uint1 x395;
- fiat_p384_addcarryx_u32(&x394, &x395, x393, 0x0, x364);
+ fiat_p384_addcarryx_u32(&x394, &x395, x393, x364, 0x0);
uint32_t x396;
fiat_p384_uint1 x397;
- fiat_p384_addcarryx_u32(&x396, &x397, x395, 0x0, x366);
+ fiat_p384_addcarryx_u32(&x396, &x397, x395, x366, 0x0);
uint32_t x398;
fiat_p384_uint1 x399;
- fiat_p384_addcarryx_u32(&x398, &x399, x397, 0x0, x368);
+ fiat_p384_addcarryx_u32(&x398, &x399, x397, x368, 0x0);
uint32_t x400;
fiat_p384_uint1 x401;
- fiat_p384_addcarryx_u32(&x400, &x401, x399, 0x0, x370);
+ fiat_p384_addcarryx_u32(&x400, &x401, x399, x370, 0x0);
uint32_t x402;
fiat_p384_uint1 x403;
- fiat_p384_addcarryx_u32(&x402, &x403, x401, 0x0, x372);
+ fiat_p384_addcarryx_u32(&x402, &x403, x401, x372, 0x0);
uint32_t x404;
fiat_p384_uint1 x405;
- fiat_p384_addcarryx_u32(&x404, &x405, x403, 0x0, x374);
+ fiat_p384_addcarryx_u32(&x404, &x405, x403, x374, 0x0);
uint32_t x406;
fiat_p384_uint1 x407;
- fiat_p384_addcarryx_u32(&x406, &x407, x405, 0x0, x376);
+ fiat_p384_addcarryx_u32(&x406, &x407, x405, x376, 0x0);
uint32_t x408;
fiat_p384_uint1 x409;
- fiat_p384_addcarryx_u32(&x408, &x409, x407, 0x0, x378);
+ fiat_p384_addcarryx_u32(&x408, &x409, x407, x378, 0x0);
uint32_t x410;
fiat_p384_uint1 x411;
- fiat_p384_addcarryx_u32(&x410, &x411, x409, 0x0, x386);
+ fiat_p384_addcarryx_u32(&x410, &x411, x409, x386, 0x0);
uint32_t x412;
uint32_t x413;
fiat_p384_mulx_u32(&x412, &x413, x388, UINT32_C(0xffffffff));
@@ -6267,112 +6267,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x430, &x431, x388, UINT32_C(0xffffffff));
uint32_t x432;
fiat_p384_uint1 x433;
- fiat_p384_addcarryx_u32(&x432, &x433, 0x0, x426, x429);
+ fiat_p384_addcarryx_u32(&x432, &x433, 0x0, x429, x426);
uint32_t x434;
fiat_p384_uint1 x435;
- fiat_p384_addcarryx_u32(&x434, &x435, x433, x424, x427);
+ fiat_p384_addcarryx_u32(&x434, &x435, x433, x427, x424);
uint32_t x436;
fiat_p384_uint1 x437;
- fiat_p384_addcarryx_u32(&x436, &x437, x435, x422, x425);
+ fiat_p384_addcarryx_u32(&x436, &x437, x435, x425, x422);
uint32_t x438;
fiat_p384_uint1 x439;
- fiat_p384_addcarryx_u32(&x438, &x439, x437, x420, x423);
+ fiat_p384_addcarryx_u32(&x438, &x439, x437, x423, x420);
uint32_t x440;
fiat_p384_uint1 x441;
- fiat_p384_addcarryx_u32(&x440, &x441, x439, x418, x421);
+ fiat_p384_addcarryx_u32(&x440, &x441, x439, x421, x418);
uint32_t x442;
fiat_p384_uint1 x443;
- fiat_p384_addcarryx_u32(&x442, &x443, x441, x416, x419);
+ fiat_p384_addcarryx_u32(&x442, &x443, x441, x419, x416);
uint32_t x444;
fiat_p384_uint1 x445;
- fiat_p384_addcarryx_u32(&x444, &x445, x443, x414, x417);
+ fiat_p384_addcarryx_u32(&x444, &x445, x443, x417, x414);
uint32_t x446;
fiat_p384_uint1 x447;
- fiat_p384_addcarryx_u32(&x446, &x447, x445, x412, x415);
+ fiat_p384_addcarryx_u32(&x446, &x447, x445, x415, x412);
uint32_t x448;
fiat_p384_uint1 x449;
- fiat_p384_addcarryx_u32(&x448, &x449, 0x0, x430, x388);
+ fiat_p384_addcarryx_u32(&x448, &x449, 0x0, x388, x430);
uint32_t x450;
fiat_p384_uint1 x451;
- fiat_p384_addcarryx_u32(&x450, &x451, x449, x431, x390);
+ fiat_p384_addcarryx_u32(&x450, &x451, x449, x390, x431);
uint32_t x452;
fiat_p384_uint1 x453;
- fiat_p384_addcarryx_u32(&x452, &x453, x451, 0x0, x392);
+ fiat_p384_addcarryx_u32(&x452, &x453, x451, x392, 0x0);
uint32_t x454;
fiat_p384_uint1 x455;
- fiat_p384_addcarryx_u32(&x454, &x455, x453, x428, x394);
+ fiat_p384_addcarryx_u32(&x454, &x455, x453, x394, x428);
uint32_t x456;
fiat_p384_uint1 x457;
- fiat_p384_addcarryx_u32(&x456, &x457, x455, x432, x396);
+ fiat_p384_addcarryx_u32(&x456, &x457, x455, x396, x432);
uint32_t x458;
fiat_p384_uint1 x459;
- fiat_p384_addcarryx_u32(&x458, &x459, x457, x434, x398);
+ fiat_p384_addcarryx_u32(&x458, &x459, x457, x398, x434);
uint32_t x460;
fiat_p384_uint1 x461;
- fiat_p384_addcarryx_u32(&x460, &x461, x459, x436, x400);
+ fiat_p384_addcarryx_u32(&x460, &x461, x459, x400, x436);
uint32_t x462;
fiat_p384_uint1 x463;
- fiat_p384_addcarryx_u32(&x462, &x463, x461, x438, x402);
+ fiat_p384_addcarryx_u32(&x462, &x463, x461, x402, x438);
uint32_t x464;
fiat_p384_uint1 x465;
- fiat_p384_addcarryx_u32(&x464, &x465, x463, x440, x404);
+ fiat_p384_addcarryx_u32(&x464, &x465, x463, x404, x440);
uint32_t x466;
fiat_p384_uint1 x467;
- fiat_p384_addcarryx_u32(&x466, &x467, x465, x442, x406);
+ fiat_p384_addcarryx_u32(&x466, &x467, x465, x406, x442);
uint32_t x468;
fiat_p384_uint1 x469;
- fiat_p384_addcarryx_u32(&x468, &x469, x467, x444, x408);
+ fiat_p384_addcarryx_u32(&x468, &x469, x467, x408, x444);
uint32_t x470;
fiat_p384_uint1 x471;
- fiat_p384_addcarryx_u32(&x470, &x471, x469, x446, x410);
+ fiat_p384_addcarryx_u32(&x470, &x471, x469, x410, x446);
uint32_t x472;
fiat_p384_uint1 x473;
- fiat_p384_addcarryx_u32(&x472, &x473, x387, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x472, &x473, x447, x413, 0x0);
uint32_t x474;
fiat_p384_uint1 x475;
- fiat_p384_addcarryx_u32(&x474, &x475, x411, 0x0, (fiat_p384_uint1)x472);
+ fiat_p384_addcarryx_u32(&x474, &x475, x387, 0x0, 0x0);
uint32_t x476;
fiat_p384_uint1 x477;
- fiat_p384_addcarryx_u32(&x476, &x477, x447, 0x0, x413);
+ fiat_p384_addcarryx_u32(&x476, &x477, x411, (fiat_p384_uint1)x474, 0x0);
uint32_t x478;
fiat_p384_uint1 x479;
- fiat_p384_addcarryx_u32(&x478, &x479, x471, x476, x474);
+ fiat_p384_addcarryx_u32(&x478, &x479, x471, x476, x472);
uint32_t x480;
fiat_p384_uint1 x481;
- fiat_p384_addcarryx_u32(&x480, &x481, 0x0, (arg1[6]), x450);
+ fiat_p384_addcarryx_u32(&x480, &x481, 0x0, x450, (arg1[6]));
uint32_t x482;
fiat_p384_uint1 x483;
- fiat_p384_addcarryx_u32(&x482, &x483, x481, 0x0, x452);
+ fiat_p384_addcarryx_u32(&x482, &x483, x481, x452, 0x0);
uint32_t x484;
fiat_p384_uint1 x485;
- fiat_p384_addcarryx_u32(&x484, &x485, x483, 0x0, x454);
+ fiat_p384_addcarryx_u32(&x484, &x485, x483, x454, 0x0);
uint32_t x486;
fiat_p384_uint1 x487;
- fiat_p384_addcarryx_u32(&x486, &x487, x485, 0x0, x456);
+ fiat_p384_addcarryx_u32(&x486, &x487, x485, x456, 0x0);
uint32_t x488;
fiat_p384_uint1 x489;
- fiat_p384_addcarryx_u32(&x488, &x489, x487, 0x0, x458);
+ fiat_p384_addcarryx_u32(&x488, &x489, x487, x458, 0x0);
uint32_t x490;
fiat_p384_uint1 x491;
- fiat_p384_addcarryx_u32(&x490, &x491, x489, 0x0, x460);
+ fiat_p384_addcarryx_u32(&x490, &x491, x489, x460, 0x0);
uint32_t x492;
fiat_p384_uint1 x493;
- fiat_p384_addcarryx_u32(&x492, &x493, x491, 0x0, x462);
+ fiat_p384_addcarryx_u32(&x492, &x493, x491, x462, 0x0);
uint32_t x494;
fiat_p384_uint1 x495;
- fiat_p384_addcarryx_u32(&x494, &x495, x493, 0x0, x464);
+ fiat_p384_addcarryx_u32(&x494, &x495, x493, x464, 0x0);
uint32_t x496;
fiat_p384_uint1 x497;
- fiat_p384_addcarryx_u32(&x496, &x497, x495, 0x0, x466);
+ fiat_p384_addcarryx_u32(&x496, &x497, x495, x466, 0x0);
uint32_t x498;
fiat_p384_uint1 x499;
- fiat_p384_addcarryx_u32(&x498, &x499, x497, 0x0, x468);
+ fiat_p384_addcarryx_u32(&x498, &x499, x497, x468, 0x0);
uint32_t x500;
fiat_p384_uint1 x501;
- fiat_p384_addcarryx_u32(&x500, &x501, x499, 0x0, x470);
+ fiat_p384_addcarryx_u32(&x500, &x501, x499, x470, 0x0);
uint32_t x502;
fiat_p384_uint1 x503;
- fiat_p384_addcarryx_u32(&x502, &x503, x501, 0x0, x478);
+ fiat_p384_addcarryx_u32(&x502, &x503, x501, x478, 0x0);
uint32_t x504;
uint32_t x505;
fiat_p384_mulx_u32(&x504, &x505, x480, UINT32_C(0xffffffff));
@@ -6405,112 +6405,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x522, &x523, x480, UINT32_C(0xffffffff));
uint32_t x524;
fiat_p384_uint1 x525;
- fiat_p384_addcarryx_u32(&x524, &x525, 0x0, x518, x521);
+ fiat_p384_addcarryx_u32(&x524, &x525, 0x0, x521, x518);
uint32_t x526;
fiat_p384_uint1 x527;
- fiat_p384_addcarryx_u32(&x526, &x527, x525, x516, x519);
+ fiat_p384_addcarryx_u32(&x526, &x527, x525, x519, x516);
uint32_t x528;
fiat_p384_uint1 x529;
- fiat_p384_addcarryx_u32(&x528, &x529, x527, x514, x517);
+ fiat_p384_addcarryx_u32(&x528, &x529, x527, x517, x514);
uint32_t x530;
fiat_p384_uint1 x531;
- fiat_p384_addcarryx_u32(&x530, &x531, x529, x512, x515);
+ fiat_p384_addcarryx_u32(&x530, &x531, x529, x515, x512);
uint32_t x532;
fiat_p384_uint1 x533;
- fiat_p384_addcarryx_u32(&x532, &x533, x531, x510, x513);
+ fiat_p384_addcarryx_u32(&x532, &x533, x531, x513, x510);
uint32_t x534;
fiat_p384_uint1 x535;
- fiat_p384_addcarryx_u32(&x534, &x535, x533, x508, x511);
+ fiat_p384_addcarryx_u32(&x534, &x535, x533, x511, x508);
uint32_t x536;
fiat_p384_uint1 x537;
- fiat_p384_addcarryx_u32(&x536, &x537, x535, x506, x509);
+ fiat_p384_addcarryx_u32(&x536, &x537, x535, x509, x506);
uint32_t x538;
fiat_p384_uint1 x539;
- fiat_p384_addcarryx_u32(&x538, &x539, x537, x504, x507);
+ fiat_p384_addcarryx_u32(&x538, &x539, x537, x507, x504);
uint32_t x540;
fiat_p384_uint1 x541;
- fiat_p384_addcarryx_u32(&x540, &x541, 0x0, x522, x480);
+ fiat_p384_addcarryx_u32(&x540, &x541, 0x0, x480, x522);
uint32_t x542;
fiat_p384_uint1 x543;
- fiat_p384_addcarryx_u32(&x542, &x543, x541, x523, x482);
+ fiat_p384_addcarryx_u32(&x542, &x543, x541, x482, x523);
uint32_t x544;
fiat_p384_uint1 x545;
- fiat_p384_addcarryx_u32(&x544, &x545, x543, 0x0, x484);
+ fiat_p384_addcarryx_u32(&x544, &x545, x543, x484, 0x0);
uint32_t x546;
fiat_p384_uint1 x547;
- fiat_p384_addcarryx_u32(&x546, &x547, x545, x520, x486);
+ fiat_p384_addcarryx_u32(&x546, &x547, x545, x486, x520);
uint32_t x548;
fiat_p384_uint1 x549;
- fiat_p384_addcarryx_u32(&x548, &x549, x547, x524, x488);
+ fiat_p384_addcarryx_u32(&x548, &x549, x547, x488, x524);
uint32_t x550;
fiat_p384_uint1 x551;
- fiat_p384_addcarryx_u32(&x550, &x551, x549, x526, x490);
+ fiat_p384_addcarryx_u32(&x550, &x551, x549, x490, x526);
uint32_t x552;
fiat_p384_uint1 x553;
- fiat_p384_addcarryx_u32(&x552, &x553, x551, x528, x492);
+ fiat_p384_addcarryx_u32(&x552, &x553, x551, x492, x528);
uint32_t x554;
fiat_p384_uint1 x555;
- fiat_p384_addcarryx_u32(&x554, &x555, x553, x530, x494);
+ fiat_p384_addcarryx_u32(&x554, &x555, x553, x494, x530);
uint32_t x556;
fiat_p384_uint1 x557;
- fiat_p384_addcarryx_u32(&x556, &x557, x555, x532, x496);
+ fiat_p384_addcarryx_u32(&x556, &x557, x555, x496, x532);
uint32_t x558;
fiat_p384_uint1 x559;
- fiat_p384_addcarryx_u32(&x558, &x559, x557, x534, x498);
+ fiat_p384_addcarryx_u32(&x558, &x559, x557, x498, x534);
uint32_t x560;
fiat_p384_uint1 x561;
- fiat_p384_addcarryx_u32(&x560, &x561, x559, x536, x500);
+ fiat_p384_addcarryx_u32(&x560, &x561, x559, x500, x536);
uint32_t x562;
fiat_p384_uint1 x563;
- fiat_p384_addcarryx_u32(&x562, &x563, x561, x538, x502);
+ fiat_p384_addcarryx_u32(&x562, &x563, x561, x502, x538);
uint32_t x564;
fiat_p384_uint1 x565;
- fiat_p384_addcarryx_u32(&x564, &x565, x479, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x564, &x565, x539, x505, 0x0);
uint32_t x566;
fiat_p384_uint1 x567;
- fiat_p384_addcarryx_u32(&x566, &x567, x503, 0x0, (fiat_p384_uint1)x564);
+ fiat_p384_addcarryx_u32(&x566, &x567, x479, 0x0, 0x0);
uint32_t x568;
fiat_p384_uint1 x569;
- fiat_p384_addcarryx_u32(&x568, &x569, x539, 0x0, x505);
+ fiat_p384_addcarryx_u32(&x568, &x569, x503, (fiat_p384_uint1)x566, 0x0);
uint32_t x570;
fiat_p384_uint1 x571;
- fiat_p384_addcarryx_u32(&x570, &x571, x563, x568, x566);
+ fiat_p384_addcarryx_u32(&x570, &x571, x563, x568, x564);
uint32_t x572;
fiat_p384_uint1 x573;
- fiat_p384_addcarryx_u32(&x572, &x573, 0x0, (arg1[7]), x542);
+ fiat_p384_addcarryx_u32(&x572, &x573, 0x0, x542, (arg1[7]));
uint32_t x574;
fiat_p384_uint1 x575;
- fiat_p384_addcarryx_u32(&x574, &x575, x573, 0x0, x544);
+ fiat_p384_addcarryx_u32(&x574, &x575, x573, x544, 0x0);
uint32_t x576;
fiat_p384_uint1 x577;
- fiat_p384_addcarryx_u32(&x576, &x577, x575, 0x0, x546);
+ fiat_p384_addcarryx_u32(&x576, &x577, x575, x546, 0x0);
uint32_t x578;
fiat_p384_uint1 x579;
- fiat_p384_addcarryx_u32(&x578, &x579, x577, 0x0, x548);
+ fiat_p384_addcarryx_u32(&x578, &x579, x577, x548, 0x0);
uint32_t x580;
fiat_p384_uint1 x581;
- fiat_p384_addcarryx_u32(&x580, &x581, x579, 0x0, x550);
+ fiat_p384_addcarryx_u32(&x580, &x581, x579, x550, 0x0);
uint32_t x582;
fiat_p384_uint1 x583;
- fiat_p384_addcarryx_u32(&x582, &x583, x581, 0x0, x552);
+ fiat_p384_addcarryx_u32(&x582, &x583, x581, x552, 0x0);
uint32_t x584;
fiat_p384_uint1 x585;
- fiat_p384_addcarryx_u32(&x584, &x585, x583, 0x0, x554);
+ fiat_p384_addcarryx_u32(&x584, &x585, x583, x554, 0x0);
uint32_t x586;
fiat_p384_uint1 x587;
- fiat_p384_addcarryx_u32(&x586, &x587, x585, 0x0, x556);
+ fiat_p384_addcarryx_u32(&x586, &x587, x585, x556, 0x0);
uint32_t x588;
fiat_p384_uint1 x589;
- fiat_p384_addcarryx_u32(&x588, &x589, x587, 0x0, x558);
+ fiat_p384_addcarryx_u32(&x588, &x589, x587, x558, 0x0);
uint32_t x590;
fiat_p384_uint1 x591;
- fiat_p384_addcarryx_u32(&x590, &x591, x589, 0x0, x560);
+ fiat_p384_addcarryx_u32(&x590, &x591, x589, x560, 0x0);
uint32_t x592;
fiat_p384_uint1 x593;
- fiat_p384_addcarryx_u32(&x592, &x593, x591, 0x0, x562);
+ fiat_p384_addcarryx_u32(&x592, &x593, x591, x562, 0x0);
uint32_t x594;
fiat_p384_uint1 x595;
- fiat_p384_addcarryx_u32(&x594, &x595, x593, 0x0, x570);
+ fiat_p384_addcarryx_u32(&x594, &x595, x593, x570, 0x0);
uint32_t x596;
uint32_t x597;
fiat_p384_mulx_u32(&x596, &x597, x572, UINT32_C(0xffffffff));
@@ -6543,112 +6543,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x614, &x615, x572, UINT32_C(0xffffffff));
uint32_t x616;
fiat_p384_uint1 x617;
- fiat_p384_addcarryx_u32(&x616, &x617, 0x0, x610, x613);
+ fiat_p384_addcarryx_u32(&x616, &x617, 0x0, x613, x610);
uint32_t x618;
fiat_p384_uint1 x619;
- fiat_p384_addcarryx_u32(&x618, &x619, x617, x608, x611);
+ fiat_p384_addcarryx_u32(&x618, &x619, x617, x611, x608);
uint32_t x620;
fiat_p384_uint1 x621;
- fiat_p384_addcarryx_u32(&x620, &x621, x619, x606, x609);
+ fiat_p384_addcarryx_u32(&x620, &x621, x619, x609, x606);
uint32_t x622;
fiat_p384_uint1 x623;
- fiat_p384_addcarryx_u32(&x622, &x623, x621, x604, x607);
+ fiat_p384_addcarryx_u32(&x622, &x623, x621, x607, x604);
uint32_t x624;
fiat_p384_uint1 x625;
- fiat_p384_addcarryx_u32(&x624, &x625, x623, x602, x605);
+ fiat_p384_addcarryx_u32(&x624, &x625, x623, x605, x602);
uint32_t x626;
fiat_p384_uint1 x627;
- fiat_p384_addcarryx_u32(&x626, &x627, x625, x600, x603);
+ fiat_p384_addcarryx_u32(&x626, &x627, x625, x603, x600);
uint32_t x628;
fiat_p384_uint1 x629;
- fiat_p384_addcarryx_u32(&x628, &x629, x627, x598, x601);
+ fiat_p384_addcarryx_u32(&x628, &x629, x627, x601, x598);
uint32_t x630;
fiat_p384_uint1 x631;
- fiat_p384_addcarryx_u32(&x630, &x631, x629, x596, x599);
+ fiat_p384_addcarryx_u32(&x630, &x631, x629, x599, x596);
uint32_t x632;
fiat_p384_uint1 x633;
- fiat_p384_addcarryx_u32(&x632, &x633, 0x0, x614, x572);
+ fiat_p384_addcarryx_u32(&x632, &x633, 0x0, x572, x614);
uint32_t x634;
fiat_p384_uint1 x635;
- fiat_p384_addcarryx_u32(&x634, &x635, x633, x615, x574);
+ fiat_p384_addcarryx_u32(&x634, &x635, x633, x574, x615);
uint32_t x636;
fiat_p384_uint1 x637;
- fiat_p384_addcarryx_u32(&x636, &x637, x635, 0x0, x576);
+ fiat_p384_addcarryx_u32(&x636, &x637, x635, x576, 0x0);
uint32_t x638;
fiat_p384_uint1 x639;
- fiat_p384_addcarryx_u32(&x638, &x639, x637, x612, x578);
+ fiat_p384_addcarryx_u32(&x638, &x639, x637, x578, x612);
uint32_t x640;
fiat_p384_uint1 x641;
- fiat_p384_addcarryx_u32(&x640, &x641, x639, x616, x580);
+ fiat_p384_addcarryx_u32(&x640, &x641, x639, x580, x616);
uint32_t x642;
fiat_p384_uint1 x643;
- fiat_p384_addcarryx_u32(&x642, &x643, x641, x618, x582);
+ fiat_p384_addcarryx_u32(&x642, &x643, x641, x582, x618);
uint32_t x644;
fiat_p384_uint1 x645;
- fiat_p384_addcarryx_u32(&x644, &x645, x643, x620, x584);
+ fiat_p384_addcarryx_u32(&x644, &x645, x643, x584, x620);
uint32_t x646;
fiat_p384_uint1 x647;
- fiat_p384_addcarryx_u32(&x646, &x647, x645, x622, x586);
+ fiat_p384_addcarryx_u32(&x646, &x647, x645, x586, x622);
uint32_t x648;
fiat_p384_uint1 x649;
- fiat_p384_addcarryx_u32(&x648, &x649, x647, x624, x588);
+ fiat_p384_addcarryx_u32(&x648, &x649, x647, x588, x624);
uint32_t x650;
fiat_p384_uint1 x651;
- fiat_p384_addcarryx_u32(&x650, &x651, x649, x626, x590);
+ fiat_p384_addcarryx_u32(&x650, &x651, x649, x590, x626);
uint32_t x652;
fiat_p384_uint1 x653;
- fiat_p384_addcarryx_u32(&x652, &x653, x651, x628, x592);
+ fiat_p384_addcarryx_u32(&x652, &x653, x651, x592, x628);
uint32_t x654;
fiat_p384_uint1 x655;
- fiat_p384_addcarryx_u32(&x654, &x655, x653, x630, x594);
+ fiat_p384_addcarryx_u32(&x654, &x655, x653, x594, x630);
uint32_t x656;
fiat_p384_uint1 x657;
- fiat_p384_addcarryx_u32(&x656, &x657, x571, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x656, &x657, x631, x597, 0x0);
uint32_t x658;
fiat_p384_uint1 x659;
- fiat_p384_addcarryx_u32(&x658, &x659, x595, 0x0, (fiat_p384_uint1)x656);
+ fiat_p384_addcarryx_u32(&x658, &x659, x571, 0x0, 0x0);
uint32_t x660;
fiat_p384_uint1 x661;
- fiat_p384_addcarryx_u32(&x660, &x661, x631, 0x0, x597);
+ fiat_p384_addcarryx_u32(&x660, &x661, x595, (fiat_p384_uint1)x658, 0x0);
uint32_t x662;
fiat_p384_uint1 x663;
- fiat_p384_addcarryx_u32(&x662, &x663, x655, x660, x658);
+ fiat_p384_addcarryx_u32(&x662, &x663, x655, x660, x656);
uint32_t x664;
fiat_p384_uint1 x665;
- fiat_p384_addcarryx_u32(&x664, &x665, 0x0, (arg1[8]), x634);
+ fiat_p384_addcarryx_u32(&x664, &x665, 0x0, x634, (arg1[8]));
uint32_t x666;
fiat_p384_uint1 x667;
- fiat_p384_addcarryx_u32(&x666, &x667, x665, 0x0, x636);
+ fiat_p384_addcarryx_u32(&x666, &x667, x665, x636, 0x0);
uint32_t x668;
fiat_p384_uint1 x669;
- fiat_p384_addcarryx_u32(&x668, &x669, x667, 0x0, x638);
+ fiat_p384_addcarryx_u32(&x668, &x669, x667, x638, 0x0);
uint32_t x670;
fiat_p384_uint1 x671;
- fiat_p384_addcarryx_u32(&x670, &x671, x669, 0x0, x640);
+ fiat_p384_addcarryx_u32(&x670, &x671, x669, x640, 0x0);
uint32_t x672;
fiat_p384_uint1 x673;
- fiat_p384_addcarryx_u32(&x672, &x673, x671, 0x0, x642);
+ fiat_p384_addcarryx_u32(&x672, &x673, x671, x642, 0x0);
uint32_t x674;
fiat_p384_uint1 x675;
- fiat_p384_addcarryx_u32(&x674, &x675, x673, 0x0, x644);
+ fiat_p384_addcarryx_u32(&x674, &x675, x673, x644, 0x0);
uint32_t x676;
fiat_p384_uint1 x677;
- fiat_p384_addcarryx_u32(&x676, &x677, x675, 0x0, x646);
+ fiat_p384_addcarryx_u32(&x676, &x677, x675, x646, 0x0);
uint32_t x678;
fiat_p384_uint1 x679;
- fiat_p384_addcarryx_u32(&x678, &x679, x677, 0x0, x648);
+ fiat_p384_addcarryx_u32(&x678, &x679, x677, x648, 0x0);
uint32_t x680;
fiat_p384_uint1 x681;
- fiat_p384_addcarryx_u32(&x680, &x681, x679, 0x0, x650);
+ fiat_p384_addcarryx_u32(&x680, &x681, x679, x650, 0x0);
uint32_t x682;
fiat_p384_uint1 x683;
- fiat_p384_addcarryx_u32(&x682, &x683, x681, 0x0, x652);
+ fiat_p384_addcarryx_u32(&x682, &x683, x681, x652, 0x0);
uint32_t x684;
fiat_p384_uint1 x685;
- fiat_p384_addcarryx_u32(&x684, &x685, x683, 0x0, x654);
+ fiat_p384_addcarryx_u32(&x684, &x685, x683, x654, 0x0);
uint32_t x686;
fiat_p384_uint1 x687;
- fiat_p384_addcarryx_u32(&x686, &x687, x685, 0x0, x662);
+ fiat_p384_addcarryx_u32(&x686, &x687, x685, x662, 0x0);
uint32_t x688;
uint32_t x689;
fiat_p384_mulx_u32(&x688, &x689, x664, UINT32_C(0xffffffff));
@@ -6681,112 +6681,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x706, &x707, x664, UINT32_C(0xffffffff));
uint32_t x708;
fiat_p384_uint1 x709;
- fiat_p384_addcarryx_u32(&x708, &x709, 0x0, x702, x705);
+ fiat_p384_addcarryx_u32(&x708, &x709, 0x0, x705, x702);
uint32_t x710;
fiat_p384_uint1 x711;
- fiat_p384_addcarryx_u32(&x710, &x711, x709, x700, x703);
+ fiat_p384_addcarryx_u32(&x710, &x711, x709, x703, x700);
uint32_t x712;
fiat_p384_uint1 x713;
- fiat_p384_addcarryx_u32(&x712, &x713, x711, x698, x701);
+ fiat_p384_addcarryx_u32(&x712, &x713, x711, x701, x698);
uint32_t x714;
fiat_p384_uint1 x715;
- fiat_p384_addcarryx_u32(&x714, &x715, x713, x696, x699);
+ fiat_p384_addcarryx_u32(&x714, &x715, x713, x699, x696);
uint32_t x716;
fiat_p384_uint1 x717;
- fiat_p384_addcarryx_u32(&x716, &x717, x715, x694, x697);
+ fiat_p384_addcarryx_u32(&x716, &x717, x715, x697, x694);
uint32_t x718;
fiat_p384_uint1 x719;
- fiat_p384_addcarryx_u32(&x718, &x719, x717, x692, x695);
+ fiat_p384_addcarryx_u32(&x718, &x719, x717, x695, x692);
uint32_t x720;
fiat_p384_uint1 x721;
- fiat_p384_addcarryx_u32(&x720, &x721, x719, x690, x693);
+ fiat_p384_addcarryx_u32(&x720, &x721, x719, x693, x690);
uint32_t x722;
fiat_p384_uint1 x723;
- fiat_p384_addcarryx_u32(&x722, &x723, x721, x688, x691);
+ fiat_p384_addcarryx_u32(&x722, &x723, x721, x691, x688);
uint32_t x724;
fiat_p384_uint1 x725;
- fiat_p384_addcarryx_u32(&x724, &x725, 0x0, x706, x664);
+ fiat_p384_addcarryx_u32(&x724, &x725, 0x0, x664, x706);
uint32_t x726;
fiat_p384_uint1 x727;
- fiat_p384_addcarryx_u32(&x726, &x727, x725, x707, x666);
+ fiat_p384_addcarryx_u32(&x726, &x727, x725, x666, x707);
uint32_t x728;
fiat_p384_uint1 x729;
- fiat_p384_addcarryx_u32(&x728, &x729, x727, 0x0, x668);
+ fiat_p384_addcarryx_u32(&x728, &x729, x727, x668, 0x0);
uint32_t x730;
fiat_p384_uint1 x731;
- fiat_p384_addcarryx_u32(&x730, &x731, x729, x704, x670);
+ fiat_p384_addcarryx_u32(&x730, &x731, x729, x670, x704);
uint32_t x732;
fiat_p384_uint1 x733;
- fiat_p384_addcarryx_u32(&x732, &x733, x731, x708, x672);
+ fiat_p384_addcarryx_u32(&x732, &x733, x731, x672, x708);
uint32_t x734;
fiat_p384_uint1 x735;
- fiat_p384_addcarryx_u32(&x734, &x735, x733, x710, x674);
+ fiat_p384_addcarryx_u32(&x734, &x735, x733, x674, x710);
uint32_t x736;
fiat_p384_uint1 x737;
- fiat_p384_addcarryx_u32(&x736, &x737, x735, x712, x676);
+ fiat_p384_addcarryx_u32(&x736, &x737, x735, x676, x712);
uint32_t x738;
fiat_p384_uint1 x739;
- fiat_p384_addcarryx_u32(&x738, &x739, x737, x714, x678);
+ fiat_p384_addcarryx_u32(&x738, &x739, x737, x678, x714);
uint32_t x740;
fiat_p384_uint1 x741;
- fiat_p384_addcarryx_u32(&x740, &x741, x739, x716, x680);
+ fiat_p384_addcarryx_u32(&x740, &x741, x739, x680, x716);
uint32_t x742;
fiat_p384_uint1 x743;
- fiat_p384_addcarryx_u32(&x742, &x743, x741, x718, x682);
+ fiat_p384_addcarryx_u32(&x742, &x743, x741, x682, x718);
uint32_t x744;
fiat_p384_uint1 x745;
- fiat_p384_addcarryx_u32(&x744, &x745, x743, x720, x684);
+ fiat_p384_addcarryx_u32(&x744, &x745, x743, x684, x720);
uint32_t x746;
fiat_p384_uint1 x747;
- fiat_p384_addcarryx_u32(&x746, &x747, x745, x722, x686);
+ fiat_p384_addcarryx_u32(&x746, &x747, x745, x686, x722);
uint32_t x748;
fiat_p384_uint1 x749;
- fiat_p384_addcarryx_u32(&x748, &x749, x663, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x748, &x749, x723, x689, 0x0);
uint32_t x750;
fiat_p384_uint1 x751;
- fiat_p384_addcarryx_u32(&x750, &x751, x687, 0x0, (fiat_p384_uint1)x748);
+ fiat_p384_addcarryx_u32(&x750, &x751, x663, 0x0, 0x0);
uint32_t x752;
fiat_p384_uint1 x753;
- fiat_p384_addcarryx_u32(&x752, &x753, x723, 0x0, x689);
+ fiat_p384_addcarryx_u32(&x752, &x753, x687, (fiat_p384_uint1)x750, 0x0);
uint32_t x754;
fiat_p384_uint1 x755;
- fiat_p384_addcarryx_u32(&x754, &x755, x747, x752, x750);
+ fiat_p384_addcarryx_u32(&x754, &x755, x747, x752, x748);
uint32_t x756;
fiat_p384_uint1 x757;
- fiat_p384_addcarryx_u32(&x756, &x757, 0x0, (arg1[9]), x726);
+ fiat_p384_addcarryx_u32(&x756, &x757, 0x0, x726, (arg1[9]));
uint32_t x758;
fiat_p384_uint1 x759;
- fiat_p384_addcarryx_u32(&x758, &x759, x757, 0x0, x728);
+ fiat_p384_addcarryx_u32(&x758, &x759, x757, x728, 0x0);
uint32_t x760;
fiat_p384_uint1 x761;
- fiat_p384_addcarryx_u32(&x760, &x761, x759, 0x0, x730);
+ fiat_p384_addcarryx_u32(&x760, &x761, x759, x730, 0x0);
uint32_t x762;
fiat_p384_uint1 x763;
- fiat_p384_addcarryx_u32(&x762, &x763, x761, 0x0, x732);
+ fiat_p384_addcarryx_u32(&x762, &x763, x761, x732, 0x0);
uint32_t x764;
fiat_p384_uint1 x765;
- fiat_p384_addcarryx_u32(&x764, &x765, x763, 0x0, x734);
+ fiat_p384_addcarryx_u32(&x764, &x765, x763, x734, 0x0);
uint32_t x766;
fiat_p384_uint1 x767;
- fiat_p384_addcarryx_u32(&x766, &x767, x765, 0x0, x736);
+ fiat_p384_addcarryx_u32(&x766, &x767, x765, x736, 0x0);
uint32_t x768;
fiat_p384_uint1 x769;
- fiat_p384_addcarryx_u32(&x768, &x769, x767, 0x0, x738);
+ fiat_p384_addcarryx_u32(&x768, &x769, x767, x738, 0x0);
uint32_t x770;
fiat_p384_uint1 x771;
- fiat_p384_addcarryx_u32(&x770, &x771, x769, 0x0, x740);
+ fiat_p384_addcarryx_u32(&x770, &x771, x769, x740, 0x0);
uint32_t x772;
fiat_p384_uint1 x773;
- fiat_p384_addcarryx_u32(&x772, &x773, x771, 0x0, x742);
+ fiat_p384_addcarryx_u32(&x772, &x773, x771, x742, 0x0);
uint32_t x774;
fiat_p384_uint1 x775;
- fiat_p384_addcarryx_u32(&x774, &x775, x773, 0x0, x744);
+ fiat_p384_addcarryx_u32(&x774, &x775, x773, x744, 0x0);
uint32_t x776;
fiat_p384_uint1 x777;
- fiat_p384_addcarryx_u32(&x776, &x777, x775, 0x0, x746);
+ fiat_p384_addcarryx_u32(&x776, &x777, x775, x746, 0x0);
uint32_t x778;
fiat_p384_uint1 x779;
- fiat_p384_addcarryx_u32(&x778, &x779, x777, 0x0, x754);
+ fiat_p384_addcarryx_u32(&x778, &x779, x777, x754, 0x0);
uint32_t x780;
uint32_t x781;
fiat_p384_mulx_u32(&x780, &x781, x756, UINT32_C(0xffffffff));
@@ -6819,112 +6819,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x798, &x799, x756, UINT32_C(0xffffffff));
uint32_t x800;
fiat_p384_uint1 x801;
- fiat_p384_addcarryx_u32(&x800, &x801, 0x0, x794, x797);
+ fiat_p384_addcarryx_u32(&x800, &x801, 0x0, x797, x794);
uint32_t x802;
fiat_p384_uint1 x803;
- fiat_p384_addcarryx_u32(&x802, &x803, x801, x792, x795);
+ fiat_p384_addcarryx_u32(&x802, &x803, x801, x795, x792);
uint32_t x804;
fiat_p384_uint1 x805;
- fiat_p384_addcarryx_u32(&x804, &x805, x803, x790, x793);
+ fiat_p384_addcarryx_u32(&x804, &x805, x803, x793, x790);
uint32_t x806;
fiat_p384_uint1 x807;
- fiat_p384_addcarryx_u32(&x806, &x807, x805, x788, x791);
+ fiat_p384_addcarryx_u32(&x806, &x807, x805, x791, x788);
uint32_t x808;
fiat_p384_uint1 x809;
- fiat_p384_addcarryx_u32(&x808, &x809, x807, x786, x789);
+ fiat_p384_addcarryx_u32(&x808, &x809, x807, x789, x786);
uint32_t x810;
fiat_p384_uint1 x811;
- fiat_p384_addcarryx_u32(&x810, &x811, x809, x784, x787);
+ fiat_p384_addcarryx_u32(&x810, &x811, x809, x787, x784);
uint32_t x812;
fiat_p384_uint1 x813;
- fiat_p384_addcarryx_u32(&x812, &x813, x811, x782, x785);
+ fiat_p384_addcarryx_u32(&x812, &x813, x811, x785, x782);
uint32_t x814;
fiat_p384_uint1 x815;
- fiat_p384_addcarryx_u32(&x814, &x815, x813, x780, x783);
+ fiat_p384_addcarryx_u32(&x814, &x815, x813, x783, x780);
uint32_t x816;
fiat_p384_uint1 x817;
- fiat_p384_addcarryx_u32(&x816, &x817, 0x0, x798, x756);
+ fiat_p384_addcarryx_u32(&x816, &x817, 0x0, x756, x798);
uint32_t x818;
fiat_p384_uint1 x819;
- fiat_p384_addcarryx_u32(&x818, &x819, x817, x799, x758);
+ fiat_p384_addcarryx_u32(&x818, &x819, x817, x758, x799);
uint32_t x820;
fiat_p384_uint1 x821;
- fiat_p384_addcarryx_u32(&x820, &x821, x819, 0x0, x760);
+ fiat_p384_addcarryx_u32(&x820, &x821, x819, x760, 0x0);
uint32_t x822;
fiat_p384_uint1 x823;
- fiat_p384_addcarryx_u32(&x822, &x823, x821, x796, x762);
+ fiat_p384_addcarryx_u32(&x822, &x823, x821, x762, x796);
uint32_t x824;
fiat_p384_uint1 x825;
- fiat_p384_addcarryx_u32(&x824, &x825, x823, x800, x764);
+ fiat_p384_addcarryx_u32(&x824, &x825, x823, x764, x800);
uint32_t x826;
fiat_p384_uint1 x827;
- fiat_p384_addcarryx_u32(&x826, &x827, x825, x802, x766);
+ fiat_p384_addcarryx_u32(&x826, &x827, x825, x766, x802);
uint32_t x828;
fiat_p384_uint1 x829;
- fiat_p384_addcarryx_u32(&x828, &x829, x827, x804, x768);
+ fiat_p384_addcarryx_u32(&x828, &x829, x827, x768, x804);
uint32_t x830;
fiat_p384_uint1 x831;
- fiat_p384_addcarryx_u32(&x830, &x831, x829, x806, x770);
+ fiat_p384_addcarryx_u32(&x830, &x831, x829, x770, x806);
uint32_t x832;
fiat_p384_uint1 x833;
- fiat_p384_addcarryx_u32(&x832, &x833, x831, x808, x772);
+ fiat_p384_addcarryx_u32(&x832, &x833, x831, x772, x808);
uint32_t x834;
fiat_p384_uint1 x835;
- fiat_p384_addcarryx_u32(&x834, &x835, x833, x810, x774);
+ fiat_p384_addcarryx_u32(&x834, &x835, x833, x774, x810);
uint32_t x836;
fiat_p384_uint1 x837;
- fiat_p384_addcarryx_u32(&x836, &x837, x835, x812, x776);
+ fiat_p384_addcarryx_u32(&x836, &x837, x835, x776, x812);
uint32_t x838;
fiat_p384_uint1 x839;
- fiat_p384_addcarryx_u32(&x838, &x839, x837, x814, x778);
+ fiat_p384_addcarryx_u32(&x838, &x839, x837, x778, x814);
uint32_t x840;
fiat_p384_uint1 x841;
- fiat_p384_addcarryx_u32(&x840, &x841, x755, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x840, &x841, x815, x781, 0x0);
uint32_t x842;
fiat_p384_uint1 x843;
- fiat_p384_addcarryx_u32(&x842, &x843, x779, 0x0, (fiat_p384_uint1)x840);
+ fiat_p384_addcarryx_u32(&x842, &x843, x755, 0x0, 0x0);
uint32_t x844;
fiat_p384_uint1 x845;
- fiat_p384_addcarryx_u32(&x844, &x845, x815, 0x0, x781);
+ fiat_p384_addcarryx_u32(&x844, &x845, x779, (fiat_p384_uint1)x842, 0x0);
uint32_t x846;
fiat_p384_uint1 x847;
- fiat_p384_addcarryx_u32(&x846, &x847, x839, x844, x842);
+ fiat_p384_addcarryx_u32(&x846, &x847, x839, x844, x840);
uint32_t x848;
fiat_p384_uint1 x849;
- fiat_p384_addcarryx_u32(&x848, &x849, 0x0, (arg1[10]), x818);
+ fiat_p384_addcarryx_u32(&x848, &x849, 0x0, x818, (arg1[10]));
uint32_t x850;
fiat_p384_uint1 x851;
- fiat_p384_addcarryx_u32(&x850, &x851, x849, 0x0, x820);
+ fiat_p384_addcarryx_u32(&x850, &x851, x849, x820, 0x0);
uint32_t x852;
fiat_p384_uint1 x853;
- fiat_p384_addcarryx_u32(&x852, &x853, x851, 0x0, x822);
+ fiat_p384_addcarryx_u32(&x852, &x853, x851, x822, 0x0);
uint32_t x854;
fiat_p384_uint1 x855;
- fiat_p384_addcarryx_u32(&x854, &x855, x853, 0x0, x824);
+ fiat_p384_addcarryx_u32(&x854, &x855, x853, x824, 0x0);
uint32_t x856;
fiat_p384_uint1 x857;
- fiat_p384_addcarryx_u32(&x856, &x857, x855, 0x0, x826);
+ fiat_p384_addcarryx_u32(&x856, &x857, x855, x826, 0x0);
uint32_t x858;
fiat_p384_uint1 x859;
- fiat_p384_addcarryx_u32(&x858, &x859, x857, 0x0, x828);
+ fiat_p384_addcarryx_u32(&x858, &x859, x857, x828, 0x0);
uint32_t x860;
fiat_p384_uint1 x861;
- fiat_p384_addcarryx_u32(&x860, &x861, x859, 0x0, x830);
+ fiat_p384_addcarryx_u32(&x860, &x861, x859, x830, 0x0);
uint32_t x862;
fiat_p384_uint1 x863;
- fiat_p384_addcarryx_u32(&x862, &x863, x861, 0x0, x832);
+ fiat_p384_addcarryx_u32(&x862, &x863, x861, x832, 0x0);
uint32_t x864;
fiat_p384_uint1 x865;
- fiat_p384_addcarryx_u32(&x864, &x865, x863, 0x0, x834);
+ fiat_p384_addcarryx_u32(&x864, &x865, x863, x834, 0x0);
uint32_t x866;
fiat_p384_uint1 x867;
- fiat_p384_addcarryx_u32(&x866, &x867, x865, 0x0, x836);
+ fiat_p384_addcarryx_u32(&x866, &x867, x865, x836, 0x0);
uint32_t x868;
fiat_p384_uint1 x869;
- fiat_p384_addcarryx_u32(&x868, &x869, x867, 0x0, x838);
+ fiat_p384_addcarryx_u32(&x868, &x869, x867, x838, 0x0);
uint32_t x870;
fiat_p384_uint1 x871;
- fiat_p384_addcarryx_u32(&x870, &x871, x869, 0x0, x846);
+ fiat_p384_addcarryx_u32(&x870, &x871, x869, x846, 0x0);
uint32_t x872;
uint32_t x873;
fiat_p384_mulx_u32(&x872, &x873, x848, UINT32_C(0xffffffff));
@@ -6957,112 +6957,112 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x890, &x891, x848, UINT32_C(0xffffffff));
uint32_t x892;
fiat_p384_uint1 x893;
- fiat_p384_addcarryx_u32(&x892, &x893, 0x0, x886, x889);
+ fiat_p384_addcarryx_u32(&x892, &x893, 0x0, x889, x886);
uint32_t x894;
fiat_p384_uint1 x895;
- fiat_p384_addcarryx_u32(&x894, &x895, x893, x884, x887);
+ fiat_p384_addcarryx_u32(&x894, &x895, x893, x887, x884);
uint32_t x896;
fiat_p384_uint1 x897;
- fiat_p384_addcarryx_u32(&x896, &x897, x895, x882, x885);
+ fiat_p384_addcarryx_u32(&x896, &x897, x895, x885, x882);
uint32_t x898;
fiat_p384_uint1 x899;
- fiat_p384_addcarryx_u32(&x898, &x899, x897, x880, x883);
+ fiat_p384_addcarryx_u32(&x898, &x899, x897, x883, x880);
uint32_t x900;
fiat_p384_uint1 x901;
- fiat_p384_addcarryx_u32(&x900, &x901, x899, x878, x881);
+ fiat_p384_addcarryx_u32(&x900, &x901, x899, x881, x878);
uint32_t x902;
fiat_p384_uint1 x903;
- fiat_p384_addcarryx_u32(&x902, &x903, x901, x876, x879);
+ fiat_p384_addcarryx_u32(&x902, &x903, x901, x879, x876);
uint32_t x904;
fiat_p384_uint1 x905;
- fiat_p384_addcarryx_u32(&x904, &x905, x903, x874, x877);
+ fiat_p384_addcarryx_u32(&x904, &x905, x903, x877, x874);
uint32_t x906;
fiat_p384_uint1 x907;
- fiat_p384_addcarryx_u32(&x906, &x907, x905, x872, x875);
+ fiat_p384_addcarryx_u32(&x906, &x907, x905, x875, x872);
uint32_t x908;
fiat_p384_uint1 x909;
- fiat_p384_addcarryx_u32(&x908, &x909, 0x0, x890, x848);
+ fiat_p384_addcarryx_u32(&x908, &x909, 0x0, x848, x890);
uint32_t x910;
fiat_p384_uint1 x911;
- fiat_p384_addcarryx_u32(&x910, &x911, x909, x891, x850);
+ fiat_p384_addcarryx_u32(&x910, &x911, x909, x850, x891);
uint32_t x912;
fiat_p384_uint1 x913;
- fiat_p384_addcarryx_u32(&x912, &x913, x911, 0x0, x852);
+ fiat_p384_addcarryx_u32(&x912, &x913, x911, x852, 0x0);
uint32_t x914;
fiat_p384_uint1 x915;
- fiat_p384_addcarryx_u32(&x914, &x915, x913, x888, x854);
+ fiat_p384_addcarryx_u32(&x914, &x915, x913, x854, x888);
uint32_t x916;
fiat_p384_uint1 x917;
- fiat_p384_addcarryx_u32(&x916, &x917, x915, x892, x856);
+ fiat_p384_addcarryx_u32(&x916, &x917, x915, x856, x892);
uint32_t x918;
fiat_p384_uint1 x919;
- fiat_p384_addcarryx_u32(&x918, &x919, x917, x894, x858);
+ fiat_p384_addcarryx_u32(&x918, &x919, x917, x858, x894);
uint32_t x920;
fiat_p384_uint1 x921;
- fiat_p384_addcarryx_u32(&x920, &x921, x919, x896, x860);
+ fiat_p384_addcarryx_u32(&x920, &x921, x919, x860, x896);
uint32_t x922;
fiat_p384_uint1 x923;
- fiat_p384_addcarryx_u32(&x922, &x923, x921, x898, x862);
+ fiat_p384_addcarryx_u32(&x922, &x923, x921, x862, x898);
uint32_t x924;
fiat_p384_uint1 x925;
- fiat_p384_addcarryx_u32(&x924, &x925, x923, x900, x864);
+ fiat_p384_addcarryx_u32(&x924, &x925, x923, x864, x900);
uint32_t x926;
fiat_p384_uint1 x927;
- fiat_p384_addcarryx_u32(&x926, &x927, x925, x902, x866);
+ fiat_p384_addcarryx_u32(&x926, &x927, x925, x866, x902);
uint32_t x928;
fiat_p384_uint1 x929;
- fiat_p384_addcarryx_u32(&x928, &x929, x927, x904, x868);
+ fiat_p384_addcarryx_u32(&x928, &x929, x927, x868, x904);
uint32_t x930;
fiat_p384_uint1 x931;
- fiat_p384_addcarryx_u32(&x930, &x931, x929, x906, x870);
+ fiat_p384_addcarryx_u32(&x930, &x931, x929, x870, x906);
uint32_t x932;
fiat_p384_uint1 x933;
- fiat_p384_addcarryx_u32(&x932, &x933, x847, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x932, &x933, x907, x873, 0x0);
uint32_t x934;
fiat_p384_uint1 x935;
- fiat_p384_addcarryx_u32(&x934, &x935, x871, 0x0, (fiat_p384_uint1)x932);
+ fiat_p384_addcarryx_u32(&x934, &x935, x847, 0x0, 0x0);
uint32_t x936;
fiat_p384_uint1 x937;
- fiat_p384_addcarryx_u32(&x936, &x937, x907, 0x0, x873);
+ fiat_p384_addcarryx_u32(&x936, &x937, x871, (fiat_p384_uint1)x934, 0x0);
uint32_t x938;
fiat_p384_uint1 x939;
- fiat_p384_addcarryx_u32(&x938, &x939, x931, x936, x934);
+ fiat_p384_addcarryx_u32(&x938, &x939, x931, x936, x932);
uint32_t x940;
fiat_p384_uint1 x941;
- fiat_p384_addcarryx_u32(&x940, &x941, 0x0, (arg1[11]), x910);
+ fiat_p384_addcarryx_u32(&x940, &x941, 0x0, x910, (arg1[11]));
uint32_t x942;
fiat_p384_uint1 x943;
- fiat_p384_addcarryx_u32(&x942, &x943, x941, 0x0, x912);
+ fiat_p384_addcarryx_u32(&x942, &x943, x941, x912, 0x0);
uint32_t x944;
fiat_p384_uint1 x945;
- fiat_p384_addcarryx_u32(&x944, &x945, x943, 0x0, x914);
+ fiat_p384_addcarryx_u32(&x944, &x945, x943, x914, 0x0);
uint32_t x946;
fiat_p384_uint1 x947;
- fiat_p384_addcarryx_u32(&x946, &x947, x945, 0x0, x916);
+ fiat_p384_addcarryx_u32(&x946, &x947, x945, x916, 0x0);
uint32_t x948;
fiat_p384_uint1 x949;
- fiat_p384_addcarryx_u32(&x948, &x949, x947, 0x0, x918);
+ fiat_p384_addcarryx_u32(&x948, &x949, x947, x918, 0x0);
uint32_t x950;
fiat_p384_uint1 x951;
- fiat_p384_addcarryx_u32(&x950, &x951, x949, 0x0, x920);
+ fiat_p384_addcarryx_u32(&x950, &x951, x949, x920, 0x0);
uint32_t x952;
fiat_p384_uint1 x953;
- fiat_p384_addcarryx_u32(&x952, &x953, x951, 0x0, x922);
+ fiat_p384_addcarryx_u32(&x952, &x953, x951, x922, 0x0);
uint32_t x954;
fiat_p384_uint1 x955;
- fiat_p384_addcarryx_u32(&x954, &x955, x953, 0x0, x924);
+ fiat_p384_addcarryx_u32(&x954, &x955, x953, x924, 0x0);
uint32_t x956;
fiat_p384_uint1 x957;
- fiat_p384_addcarryx_u32(&x956, &x957, x955, 0x0, x926);
+ fiat_p384_addcarryx_u32(&x956, &x957, x955, x926, 0x0);
uint32_t x958;
fiat_p384_uint1 x959;
- fiat_p384_addcarryx_u32(&x958, &x959, x957, 0x0, x928);
+ fiat_p384_addcarryx_u32(&x958, &x959, x957, x928, 0x0);
uint32_t x960;
fiat_p384_uint1 x961;
- fiat_p384_addcarryx_u32(&x960, &x961, x959, 0x0, x930);
+ fiat_p384_addcarryx_u32(&x960, &x961, x959, x930, 0x0);
uint32_t x962;
fiat_p384_uint1 x963;
- fiat_p384_addcarryx_u32(&x962, &x963, x961, 0x0, x938);
+ fiat_p384_addcarryx_u32(&x962, &x963, x961, x938, 0x0);
uint32_t x964;
uint32_t x965;
fiat_p384_mulx_u32(&x964, &x965, x940, UINT32_C(0xffffffff));
@@ -7095,76 +7095,76 @@ static void fiat_p384_from_montgomery(uint32_t out1[12], const uint32_t arg1[12]
fiat_p384_mulx_u32(&x982, &x983, x940, UINT32_C(0xffffffff));
uint32_t x984;
fiat_p384_uint1 x985;
- fiat_p384_addcarryx_u32(&x984, &x985, 0x0, x978, x981);
+ fiat_p384_addcarryx_u32(&x984, &x985, 0x0, x981, x978);
uint32_t x986;
fiat_p384_uint1 x987;
- fiat_p384_addcarryx_u32(&x986, &x987, x985, x976, x979);
+ fiat_p384_addcarryx_u32(&x986, &x987, x985, x979, x976);
uint32_t x988;
fiat_p384_uint1 x989;
- fiat_p384_addcarryx_u32(&x988, &x989, x987, x974, x977);
+ fiat_p384_addcarryx_u32(&x988, &x989, x987, x977, x974);
uint32_t x990;
fiat_p384_uint1 x991;
- fiat_p384_addcarryx_u32(&x990, &x991, x989, x972, x975);
+ fiat_p384_addcarryx_u32(&x990, &x991, x989, x975, x972);
uint32_t x992;
fiat_p384_uint1 x993;
- fiat_p384_addcarryx_u32(&x992, &x993, x991, x970, x973);
+ fiat_p384_addcarryx_u32(&x992, &x993, x991, x973, x970);
uint32_t x994;
fiat_p384_uint1 x995;
- fiat_p384_addcarryx_u32(&x994, &x995, x993, x968, x971);
+ fiat_p384_addcarryx_u32(&x994, &x995, x993, x971, x968);
uint32_t x996;
fiat_p384_uint1 x997;
- fiat_p384_addcarryx_u32(&x996, &x997, x995, x966, x969);
+ fiat_p384_addcarryx_u32(&x996, &x997, x995, x969, x966);
uint32_t x998;
fiat_p384_uint1 x999;
- fiat_p384_addcarryx_u32(&x998, &x999, x997, x964, x967);
+ fiat_p384_addcarryx_u32(&x998, &x999, x997, x967, x964);
uint32_t x1000;
fiat_p384_uint1 x1001;
- fiat_p384_addcarryx_u32(&x1000, &x1001, 0x0, x982, x940);
+ fiat_p384_addcarryx_u32(&x1000, &x1001, 0x0, x940, x982);
uint32_t x1002;
fiat_p384_uint1 x1003;
- fiat_p384_addcarryx_u32(&x1002, &x1003, x1001, x983, x942);
+ fiat_p384_addcarryx_u32(&x1002, &x1003, x1001, x942, x983);
uint32_t x1004;
fiat_p384_uint1 x1005;
- fiat_p384_addcarryx_u32(&x1004, &x1005, x1003, 0x0, x944);
+ fiat_p384_addcarryx_u32(&x1004, &x1005, x1003, x944, 0x0);
uint32_t x1006;
fiat_p384_uint1 x1007;
- fiat_p384_addcarryx_u32(&x1006, &x1007, x1005, x980, x946);
+ fiat_p384_addcarryx_u32(&x1006, &x1007, x1005, x946, x980);
uint32_t x1008;
fiat_p384_uint1 x1009;
- fiat_p384_addcarryx_u32(&x1008, &x1009, x1007, x984, x948);
+ fiat_p384_addcarryx_u32(&x1008, &x1009, x1007, x948, x984);
uint32_t x1010;
fiat_p384_uint1 x1011;
- fiat_p384_addcarryx_u32(&x1010, &x1011, x1009, x986, x950);
+ fiat_p384_addcarryx_u32(&x1010, &x1011, x1009, x950, x986);
uint32_t x1012;
fiat_p384_uint1 x1013;
- fiat_p384_addcarryx_u32(&x1012, &x1013, x1011, x988, x952);
+ fiat_p384_addcarryx_u32(&x1012, &x1013, x1011, x952, x988);
uint32_t x1014;
fiat_p384_uint1 x1015;
- fiat_p384_addcarryx_u32(&x1014, &x1015, x1013, x990, x954);
+ fiat_p384_addcarryx_u32(&x1014, &x1015, x1013, x954, x990);
uint32_t x1016;
fiat_p384_uint1 x1017;
- fiat_p384_addcarryx_u32(&x1016, &x1017, x1015, x992, x956);
+ fiat_p384_addcarryx_u32(&x1016, &x1017, x1015, x956, x992);
uint32_t x1018;
fiat_p384_uint1 x1019;
- fiat_p384_addcarryx_u32(&x1018, &x1019, x1017, x994, x958);
+ fiat_p384_addcarryx_u32(&x1018, &x1019, x1017, x958, x994);
uint32_t x1020;
fiat_p384_uint1 x1021;
- fiat_p384_addcarryx_u32(&x1020, &x1021, x1019, x996, x960);
+ fiat_p384_addcarryx_u32(&x1020, &x1021, x1019, x960, x996);
uint32_t x1022;
fiat_p384_uint1 x1023;
- fiat_p384_addcarryx_u32(&x1022, &x1023, x1021, x998, x962);
+ fiat_p384_addcarryx_u32(&x1022, &x1023, x1021, x962, x998);
uint32_t x1024;
fiat_p384_uint1 x1025;
- fiat_p384_addcarryx_u32(&x1024, &x1025, x939, 0x0, 0x0);
+ fiat_p384_addcarryx_u32(&x1024, &x1025, x999, x965, 0x0);
uint32_t x1026;
fiat_p384_uint1 x1027;
- fiat_p384_addcarryx_u32(&x1026, &x1027, x963, 0x0, (fiat_p384_uint1)x1024);
+ fiat_p384_addcarryx_u32(&x1026, &x1027, x939, 0x0, 0x0);
uint32_t x1028;
fiat_p384_uint1 x1029;
- fiat_p384_addcarryx_u32(&x1028, &x1029, x999, 0x0, x965);
+ fiat_p384_addcarryx_u32(&x1028, &x1029, x963, (fiat_p384_uint1)x1026, 0x0);
uint32_t x1030;
fiat_p384_uint1 x1031;
- fiat_p384_addcarryx_u32(&x1030, &x1031, x1023, x1028, x1026);
+ fiat_p384_addcarryx_u32(&x1030, &x1031, x1023, x1028, x1024);
uint32_t x1032;
fiat_p384_uint1 x1033;
fiat_p384_subborrowx_u32(&x1032, &x1033, 0x0, x1002, UINT32_C(0xffffffff));
diff --git a/p384_64.c b/p384_64.c
index 49c264b60..e10938f1c 100644
--- a/p384_64.c
+++ b/p384_64.c
@@ -144,22 +144,22 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x17, &x18, x6, (arg2[0]));
uint64_t x19;
fiat_p384_uint1 x20;
- fiat_p384_addcarryx_u64(&x19, &x20, 0x0, x15, x18);
+ fiat_p384_addcarryx_u64(&x19, &x20, 0x0, x18, x15);
uint64_t x21;
fiat_p384_uint1 x22;
- fiat_p384_addcarryx_u64(&x21, &x22, x20, x13, x16);
+ fiat_p384_addcarryx_u64(&x21, &x22, x20, x16, x13);
uint64_t x23;
fiat_p384_uint1 x24;
- fiat_p384_addcarryx_u64(&x23, &x24, x22, x11, x14);
+ fiat_p384_addcarryx_u64(&x23, &x24, x22, x14, x11);
uint64_t x25;
fiat_p384_uint1 x26;
- fiat_p384_addcarryx_u64(&x25, &x26, x24, x9, x12);
+ fiat_p384_addcarryx_u64(&x25, &x26, x24, x12, x9);
uint64_t x27;
fiat_p384_uint1 x28;
- fiat_p384_addcarryx_u64(&x27, &x28, x26, x7, x10);
+ fiat_p384_addcarryx_u64(&x27, &x28, x26, x10, x7);
uint64_t x29;
fiat_p384_uint1 x30;
- fiat_p384_addcarryx_u64(&x29, &x30, x28, 0x0, x8);
+ fiat_p384_addcarryx_u64(&x29, &x30, x28, x8, 0x0);
uint64_t x31;
uint64_t x32;
fiat_p384_mulx_u64(&x31, &x32, x17, UINT64_C(0x100000001));
@@ -183,43 +183,43 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x43, &x44, x31, UINT32_C(0xffffffff));
uint64_t x45;
fiat_p384_uint1 x46;
- fiat_p384_addcarryx_u64(&x45, &x46, 0x0, x41, x44);
+ fiat_p384_addcarryx_u64(&x45, &x46, 0x0, x44, x41);
uint64_t x47;
fiat_p384_uint1 x48;
- fiat_p384_addcarryx_u64(&x47, &x48, x46, x39, x42);
+ fiat_p384_addcarryx_u64(&x47, &x48, x46, x42, x39);
uint64_t x49;
fiat_p384_uint1 x50;
- fiat_p384_addcarryx_u64(&x49, &x50, x48, x37, x40);
+ fiat_p384_addcarryx_u64(&x49, &x50, x48, x40, x37);
uint64_t x51;
fiat_p384_uint1 x52;
- fiat_p384_addcarryx_u64(&x51, &x52, x50, x35, x38);
+ fiat_p384_addcarryx_u64(&x51, &x52, x50, x38, x35);
uint64_t x53;
fiat_p384_uint1 x54;
- fiat_p384_addcarryx_u64(&x53, &x54, x52, x33, x36);
+ fiat_p384_addcarryx_u64(&x53, &x54, x52, x36, x33);
uint64_t x55;
fiat_p384_uint1 x56;
- fiat_p384_addcarryx_u64(&x55, &x56, x54, 0x0, x34);
+ fiat_p384_addcarryx_u64(&x55, &x56, x54, x34, 0x0);
uint64_t x57;
fiat_p384_uint1 x58;
- fiat_p384_addcarryx_u64(&x57, &x58, 0x0, x43, x17);
+ fiat_p384_addcarryx_u64(&x57, &x58, 0x0, x17, x43);
uint64_t x59;
fiat_p384_uint1 x60;
- fiat_p384_addcarryx_u64(&x59, &x60, x58, x45, x19);
+ fiat_p384_addcarryx_u64(&x59, &x60, x58, x19, x45);
uint64_t x61;
fiat_p384_uint1 x62;
- fiat_p384_addcarryx_u64(&x61, &x62, x60, x47, x21);
+ fiat_p384_addcarryx_u64(&x61, &x62, x60, x21, x47);
uint64_t x63;
fiat_p384_uint1 x64;
- fiat_p384_addcarryx_u64(&x63, &x64, x62, x49, x23);
+ fiat_p384_addcarryx_u64(&x63, &x64, x62, x23, x49);
uint64_t x65;
fiat_p384_uint1 x66;
- fiat_p384_addcarryx_u64(&x65, &x66, x64, x51, x25);
+ fiat_p384_addcarryx_u64(&x65, &x66, x64, x25, x51);
uint64_t x67;
fiat_p384_uint1 x68;
- fiat_p384_addcarryx_u64(&x67, &x68, x66, x53, x27);
+ fiat_p384_addcarryx_u64(&x67, &x68, x66, x27, x53);
uint64_t x69;
fiat_p384_uint1 x70;
- fiat_p384_addcarryx_u64(&x69, &x70, x68, x55, x29);
+ fiat_p384_addcarryx_u64(&x69, &x70, x68, x29, x55);
uint64_t x71;
fiat_p384_uint1 x72;
fiat_p384_addcarryx_u64(&x71, &x72, x70, 0x0, 0x0);
@@ -243,43 +243,43 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x83, &x84, x1, (arg2[0]));
uint64_t x85;
fiat_p384_uint1 x86;
- fiat_p384_addcarryx_u64(&x85, &x86, 0x0, x81, x84);
+ fiat_p384_addcarryx_u64(&x85, &x86, 0x0, x84, x81);
uint64_t x87;
fiat_p384_uint1 x88;
- fiat_p384_addcarryx_u64(&x87, &x88, x86, x79, x82);
+ fiat_p384_addcarryx_u64(&x87, &x88, x86, x82, x79);
uint64_t x89;
fiat_p384_uint1 x90;
- fiat_p384_addcarryx_u64(&x89, &x90, x88, x77, x80);
+ fiat_p384_addcarryx_u64(&x89, &x90, x88, x80, x77);
uint64_t x91;
fiat_p384_uint1 x92;
- fiat_p384_addcarryx_u64(&x91, &x92, x90, x75, x78);
+ fiat_p384_addcarryx_u64(&x91, &x92, x90, x78, x75);
uint64_t x93;
fiat_p384_uint1 x94;
- fiat_p384_addcarryx_u64(&x93, &x94, x92, x73, x76);
+ fiat_p384_addcarryx_u64(&x93, &x94, x92, x76, x73);
uint64_t x95;
fiat_p384_uint1 x96;
- fiat_p384_addcarryx_u64(&x95, &x96, x94, 0x0, x74);
+ fiat_p384_addcarryx_u64(&x95, &x96, x94, x74, 0x0);
uint64_t x97;
fiat_p384_uint1 x98;
- fiat_p384_addcarryx_u64(&x97, &x98, 0x0, x83, x59);
+ fiat_p384_addcarryx_u64(&x97, &x98, 0x0, x59, x83);
uint64_t x99;
fiat_p384_uint1 x100;
- fiat_p384_addcarryx_u64(&x99, &x100, x98, x85, x61);
+ fiat_p384_addcarryx_u64(&x99, &x100, x98, x61, x85);
uint64_t x101;
fiat_p384_uint1 x102;
- fiat_p384_addcarryx_u64(&x101, &x102, x100, x87, x63);
+ fiat_p384_addcarryx_u64(&x101, &x102, x100, x63, x87);
uint64_t x103;
fiat_p384_uint1 x104;
- fiat_p384_addcarryx_u64(&x103, &x104, x102, x89, x65);
+ fiat_p384_addcarryx_u64(&x103, &x104, x102, x65, x89);
uint64_t x105;
fiat_p384_uint1 x106;
- fiat_p384_addcarryx_u64(&x105, &x106, x104, x91, x67);
+ fiat_p384_addcarryx_u64(&x105, &x106, x104, x67, x91);
uint64_t x107;
fiat_p384_uint1 x108;
- fiat_p384_addcarryx_u64(&x107, &x108, x106, x93, x69);
+ fiat_p384_addcarryx_u64(&x107, &x108, x106, x69, x93);
uint64_t x109;
fiat_p384_uint1 x110;
- fiat_p384_addcarryx_u64(&x109, &x110, x108, x95, (fiat_p384_uint1)x71);
+ fiat_p384_addcarryx_u64(&x109, &x110, x108, (fiat_p384_uint1)x71, x95);
uint64_t x111;
uint64_t x112;
fiat_p384_mulx_u64(&x111, &x112, x97, UINT64_C(0x100000001));
@@ -303,46 +303,46 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x123, &x124, x111, UINT32_C(0xffffffff));
uint64_t x125;
fiat_p384_uint1 x126;
- fiat_p384_addcarryx_u64(&x125, &x126, 0x0, x121, x124);
+ fiat_p384_addcarryx_u64(&x125, &x126, 0x0, x124, x121);
uint64_t x127;
fiat_p384_uint1 x128;
- fiat_p384_addcarryx_u64(&x127, &x128, x126, x119, x122);
+ fiat_p384_addcarryx_u64(&x127, &x128, x126, x122, x119);
uint64_t x129;
fiat_p384_uint1 x130;
- fiat_p384_addcarryx_u64(&x129, &x130, x128, x117, x120);
+ fiat_p384_addcarryx_u64(&x129, &x130, x128, x120, x117);
uint64_t x131;
fiat_p384_uint1 x132;
- fiat_p384_addcarryx_u64(&x131, &x132, x130, x115, x118);
+ fiat_p384_addcarryx_u64(&x131, &x132, x130, x118, x115);
uint64_t x133;
fiat_p384_uint1 x134;
- fiat_p384_addcarryx_u64(&x133, &x134, x132, x113, x116);
+ fiat_p384_addcarryx_u64(&x133, &x134, x132, x116, x113);
uint64_t x135;
fiat_p384_uint1 x136;
- fiat_p384_addcarryx_u64(&x135, &x136, x134, 0x0, x114);
+ fiat_p384_addcarryx_u64(&x135, &x136, x134, x114, 0x0);
uint64_t x137;
fiat_p384_uint1 x138;
- fiat_p384_addcarryx_u64(&x137, &x138, 0x0, x123, x97);
+ fiat_p384_addcarryx_u64(&x137, &x138, 0x0, x97, x123);
uint64_t x139;
fiat_p384_uint1 x140;
- fiat_p384_addcarryx_u64(&x139, &x140, x138, x125, x99);
+ fiat_p384_addcarryx_u64(&x139, &x140, x138, x99, x125);
uint64_t x141;
fiat_p384_uint1 x142;
- fiat_p384_addcarryx_u64(&x141, &x142, x140, x127, x101);
+ fiat_p384_addcarryx_u64(&x141, &x142, x140, x101, x127);
uint64_t x143;
fiat_p384_uint1 x144;
- fiat_p384_addcarryx_u64(&x143, &x144, x142, x129, x103);
+ fiat_p384_addcarryx_u64(&x143, &x144, x142, x103, x129);
uint64_t x145;
fiat_p384_uint1 x146;
- fiat_p384_addcarryx_u64(&x145, &x146, x144, x131, x105);
+ fiat_p384_addcarryx_u64(&x145, &x146, x144, x105, x131);
uint64_t x147;
fiat_p384_uint1 x148;
- fiat_p384_addcarryx_u64(&x147, &x148, x146, x133, x107);
+ fiat_p384_addcarryx_u64(&x147, &x148, x146, x107, x133);
uint64_t x149;
fiat_p384_uint1 x150;
- fiat_p384_addcarryx_u64(&x149, &x150, x148, x135, x109);
+ fiat_p384_addcarryx_u64(&x149, &x150, x148, x109, x135);
uint64_t x151;
fiat_p384_uint1 x152;
- fiat_p384_addcarryx_u64(&x151, &x152, x150, 0x0, x110);
+ fiat_p384_addcarryx_u64(&x151, &x152, x150, x110, 0x0);
uint64_t x153;
uint64_t x154;
fiat_p384_mulx_u64(&x153, &x154, x2, (arg2[5]));
@@ -363,43 +363,43 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x163, &x164, x2, (arg2[0]));
uint64_t x165;
fiat_p384_uint1 x166;
- fiat_p384_addcarryx_u64(&x165, &x166, 0x0, x161, x164);
+ fiat_p384_addcarryx_u64(&x165, &x166, 0x0, x164, x161);
uint64_t x167;
fiat_p384_uint1 x168;
- fiat_p384_addcarryx_u64(&x167, &x168, x166, x159, x162);
+ fiat_p384_addcarryx_u64(&x167, &x168, x166, x162, x159);
uint64_t x169;
fiat_p384_uint1 x170;
- fiat_p384_addcarryx_u64(&x169, &x170, x168, x157, x160);
+ fiat_p384_addcarryx_u64(&x169, &x170, x168, x160, x157);
uint64_t x171;
fiat_p384_uint1 x172;
- fiat_p384_addcarryx_u64(&x171, &x172, x170, x155, x158);
+ fiat_p384_addcarryx_u64(&x171, &x172, x170, x158, x155);
uint64_t x173;
fiat_p384_uint1 x174;
- fiat_p384_addcarryx_u64(&x173, &x174, x172, x153, x156);
+ fiat_p384_addcarryx_u64(&x173, &x174, x172, x156, x153);
uint64_t x175;
fiat_p384_uint1 x176;
- fiat_p384_addcarryx_u64(&x175, &x176, x174, 0x0, x154);
+ fiat_p384_addcarryx_u64(&x175, &x176, x174, x154, 0x0);
uint64_t x177;
fiat_p384_uint1 x178;
- fiat_p384_addcarryx_u64(&x177, &x178, 0x0, x163, x139);
+ fiat_p384_addcarryx_u64(&x177, &x178, 0x0, x139, x163);
uint64_t x179;
fiat_p384_uint1 x180;
- fiat_p384_addcarryx_u64(&x179, &x180, x178, x165, x141);
+ fiat_p384_addcarryx_u64(&x179, &x180, x178, x141, x165);
uint64_t x181;
fiat_p384_uint1 x182;
- fiat_p384_addcarryx_u64(&x181, &x182, x180, x167, x143);
+ fiat_p384_addcarryx_u64(&x181, &x182, x180, x143, x167);
uint64_t x183;
fiat_p384_uint1 x184;
- fiat_p384_addcarryx_u64(&x183, &x184, x182, x169, x145);
+ fiat_p384_addcarryx_u64(&x183, &x184, x182, x145, x169);
uint64_t x185;
fiat_p384_uint1 x186;
- fiat_p384_addcarryx_u64(&x185, &x186, x184, x171, x147);
+ fiat_p384_addcarryx_u64(&x185, &x186, x184, x147, x171);
uint64_t x187;
fiat_p384_uint1 x188;
- fiat_p384_addcarryx_u64(&x187, &x188, x186, x173, x149);
+ fiat_p384_addcarryx_u64(&x187, &x188, x186, x149, x173);
uint64_t x189;
fiat_p384_uint1 x190;
- fiat_p384_addcarryx_u64(&x189, &x190, x188, x175, x151);
+ fiat_p384_addcarryx_u64(&x189, &x190, x188, x151, x175);
uint64_t x191;
uint64_t x192;
fiat_p384_mulx_u64(&x191, &x192, x177, UINT64_C(0x100000001));
@@ -423,46 +423,46 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x203, &x204, x191, UINT32_C(0xffffffff));
uint64_t x205;
fiat_p384_uint1 x206;
- fiat_p384_addcarryx_u64(&x205, &x206, 0x0, x201, x204);
+ fiat_p384_addcarryx_u64(&x205, &x206, 0x0, x204, x201);
uint64_t x207;
fiat_p384_uint1 x208;
- fiat_p384_addcarryx_u64(&x207, &x208, x206, x199, x202);
+ fiat_p384_addcarryx_u64(&x207, &x208, x206, x202, x199);
uint64_t x209;
fiat_p384_uint1 x210;
- fiat_p384_addcarryx_u64(&x209, &x210, x208, x197, x200);
+ fiat_p384_addcarryx_u64(&x209, &x210, x208, x200, x197);
uint64_t x211;
fiat_p384_uint1 x212;
- fiat_p384_addcarryx_u64(&x211, &x212, x210, x195, x198);
+ fiat_p384_addcarryx_u64(&x211, &x212, x210, x198, x195);
uint64_t x213;
fiat_p384_uint1 x214;
- fiat_p384_addcarryx_u64(&x213, &x214, x212, x193, x196);
+ fiat_p384_addcarryx_u64(&x213, &x214, x212, x196, x193);
uint64_t x215;
fiat_p384_uint1 x216;
- fiat_p384_addcarryx_u64(&x215, &x216, x214, 0x0, x194);
+ fiat_p384_addcarryx_u64(&x215, &x216, x214, x194, 0x0);
uint64_t x217;
fiat_p384_uint1 x218;
- fiat_p384_addcarryx_u64(&x217, &x218, 0x0, x203, x177);
+ fiat_p384_addcarryx_u64(&x217, &x218, 0x0, x177, x203);
uint64_t x219;
fiat_p384_uint1 x220;
- fiat_p384_addcarryx_u64(&x219, &x220, x218, x205, x179);
+ fiat_p384_addcarryx_u64(&x219, &x220, x218, x179, x205);
uint64_t x221;
fiat_p384_uint1 x222;
- fiat_p384_addcarryx_u64(&x221, &x222, x220, x207, x181);
+ fiat_p384_addcarryx_u64(&x221, &x222, x220, x181, x207);
uint64_t x223;
fiat_p384_uint1 x224;
- fiat_p384_addcarryx_u64(&x223, &x224, x222, x209, x183);
+ fiat_p384_addcarryx_u64(&x223, &x224, x222, x183, x209);
uint64_t x225;
fiat_p384_uint1 x226;
- fiat_p384_addcarryx_u64(&x225, &x226, x224, x211, x185);
+ fiat_p384_addcarryx_u64(&x225, &x226, x224, x185, x211);
uint64_t x227;
fiat_p384_uint1 x228;
- fiat_p384_addcarryx_u64(&x227, &x228, x226, x213, x187);
+ fiat_p384_addcarryx_u64(&x227, &x228, x226, x187, x213);
uint64_t x229;
fiat_p384_uint1 x230;
- fiat_p384_addcarryx_u64(&x229, &x230, x228, x215, x189);
+ fiat_p384_addcarryx_u64(&x229, &x230, x228, x189, x215);
uint64_t x231;
fiat_p384_uint1 x232;
- fiat_p384_addcarryx_u64(&x231, &x232, x230, 0x0, x190);
+ fiat_p384_addcarryx_u64(&x231, &x232, x230, x190, 0x0);
uint64_t x233;
uint64_t x234;
fiat_p384_mulx_u64(&x233, &x234, x3, (arg2[5]));
@@ -483,43 +483,43 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x243, &x244, x3, (arg2[0]));
uint64_t x245;
fiat_p384_uint1 x246;
- fiat_p384_addcarryx_u64(&x245, &x246, 0x0, x241, x244);
+ fiat_p384_addcarryx_u64(&x245, &x246, 0x0, x244, x241);
uint64_t x247;
fiat_p384_uint1 x248;
- fiat_p384_addcarryx_u64(&x247, &x248, x246, x239, x242);
+ fiat_p384_addcarryx_u64(&x247, &x248, x246, x242, x239);
uint64_t x249;
fiat_p384_uint1 x250;
- fiat_p384_addcarryx_u64(&x249, &x250, x248, x237, x240);
+ fiat_p384_addcarryx_u64(&x249, &x250, x248, x240, x237);
uint64_t x251;
fiat_p384_uint1 x252;
- fiat_p384_addcarryx_u64(&x251, &x252, x250, x235, x238);
+ fiat_p384_addcarryx_u64(&x251, &x252, x250, x238, x235);
uint64_t x253;
fiat_p384_uint1 x254;
- fiat_p384_addcarryx_u64(&x253, &x254, x252, x233, x236);
+ fiat_p384_addcarryx_u64(&x253, &x254, x252, x236, x233);
uint64_t x255;
fiat_p384_uint1 x256;
- fiat_p384_addcarryx_u64(&x255, &x256, x254, 0x0, x234);
+ fiat_p384_addcarryx_u64(&x255, &x256, x254, x234, 0x0);
uint64_t x257;
fiat_p384_uint1 x258;
- fiat_p384_addcarryx_u64(&x257, &x258, 0x0, x243, x219);
+ fiat_p384_addcarryx_u64(&x257, &x258, 0x0, x219, x243);
uint64_t x259;
fiat_p384_uint1 x260;
- fiat_p384_addcarryx_u64(&x259, &x260, x258, x245, x221);
+ fiat_p384_addcarryx_u64(&x259, &x260, x258, x221, x245);
uint64_t x261;
fiat_p384_uint1 x262;
- fiat_p384_addcarryx_u64(&x261, &x262, x260, x247, x223);
+ fiat_p384_addcarryx_u64(&x261, &x262, x260, x223, x247);
uint64_t x263;
fiat_p384_uint1 x264;
- fiat_p384_addcarryx_u64(&x263, &x264, x262, x249, x225);
+ fiat_p384_addcarryx_u64(&x263, &x264, x262, x225, x249);
uint64_t x265;
fiat_p384_uint1 x266;
- fiat_p384_addcarryx_u64(&x265, &x266, x264, x251, x227);
+ fiat_p384_addcarryx_u64(&x265, &x266, x264, x227, x251);
uint64_t x267;
fiat_p384_uint1 x268;
- fiat_p384_addcarryx_u64(&x267, &x268, x266, x253, x229);
+ fiat_p384_addcarryx_u64(&x267, &x268, x266, x229, x253);
uint64_t x269;
fiat_p384_uint1 x270;
- fiat_p384_addcarryx_u64(&x269, &x270, x268, x255, x231);
+ fiat_p384_addcarryx_u64(&x269, &x270, x268, x231, x255);
uint64_t x271;
uint64_t x272;
fiat_p384_mulx_u64(&x271, &x272, x257, UINT64_C(0x100000001));
@@ -543,46 +543,46 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x283, &x284, x271, UINT32_C(0xffffffff));
uint64_t x285;
fiat_p384_uint1 x286;
- fiat_p384_addcarryx_u64(&x285, &x286, 0x0, x281, x284);
+ fiat_p384_addcarryx_u64(&x285, &x286, 0x0, x284, x281);
uint64_t x287;
fiat_p384_uint1 x288;
- fiat_p384_addcarryx_u64(&x287, &x288, x286, x279, x282);
+ fiat_p384_addcarryx_u64(&x287, &x288, x286, x282, x279);
uint64_t x289;
fiat_p384_uint1 x290;
- fiat_p384_addcarryx_u64(&x289, &x290, x288, x277, x280);
+ fiat_p384_addcarryx_u64(&x289, &x290, x288, x280, x277);
uint64_t x291;
fiat_p384_uint1 x292;
- fiat_p384_addcarryx_u64(&x291, &x292, x290, x275, x278);
+ fiat_p384_addcarryx_u64(&x291, &x292, x290, x278, x275);
uint64_t x293;
fiat_p384_uint1 x294;
- fiat_p384_addcarryx_u64(&x293, &x294, x292, x273, x276);
+ fiat_p384_addcarryx_u64(&x293, &x294, x292, x276, x273);
uint64_t x295;
fiat_p384_uint1 x296;
- fiat_p384_addcarryx_u64(&x295, &x296, x294, 0x0, x274);
+ fiat_p384_addcarryx_u64(&x295, &x296, x294, x274, 0x0);
uint64_t x297;
fiat_p384_uint1 x298;
- fiat_p384_addcarryx_u64(&x297, &x298, 0x0, x283, x257);
+ fiat_p384_addcarryx_u64(&x297, &x298, 0x0, x257, x283);
uint64_t x299;
fiat_p384_uint1 x300;
- fiat_p384_addcarryx_u64(&x299, &x300, x298, x285, x259);
+ fiat_p384_addcarryx_u64(&x299, &x300, x298, x259, x285);
uint64_t x301;
fiat_p384_uint1 x302;
- fiat_p384_addcarryx_u64(&x301, &x302, x300, x287, x261);
+ fiat_p384_addcarryx_u64(&x301, &x302, x300, x261, x287);
uint64_t x303;
fiat_p384_uint1 x304;
- fiat_p384_addcarryx_u64(&x303, &x304, x302, x289, x263);
+ fiat_p384_addcarryx_u64(&x303, &x304, x302, x263, x289);
uint64_t x305;
fiat_p384_uint1 x306;
- fiat_p384_addcarryx_u64(&x305, &x306, x304, x291, x265);
+ fiat_p384_addcarryx_u64(&x305, &x306, x304, x265, x291);
uint64_t x307;
fiat_p384_uint1 x308;
- fiat_p384_addcarryx_u64(&x307, &x308, x306, x293, x267);
+ fiat_p384_addcarryx_u64(&x307, &x308, x306, x267, x293);
uint64_t x309;
fiat_p384_uint1 x310;
- fiat_p384_addcarryx_u64(&x309, &x310, x308, x295, x269);
+ fiat_p384_addcarryx_u64(&x309, &x310, x308, x269, x295);
uint64_t x311;
fiat_p384_uint1 x312;
- fiat_p384_addcarryx_u64(&x311, &x312, x310, 0x0, x270);
+ fiat_p384_addcarryx_u64(&x311, &x312, x310, x270, 0x0);
uint64_t x313;
uint64_t x314;
fiat_p384_mulx_u64(&x313, &x314, x4, (arg2[5]));
@@ -603,43 +603,43 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x323, &x324, x4, (arg2[0]));
uint64_t x325;
fiat_p384_uint1 x326;
- fiat_p384_addcarryx_u64(&x325, &x326, 0x0, x321, x324);
+ fiat_p384_addcarryx_u64(&x325, &x326, 0x0, x324, x321);
uint64_t x327;
fiat_p384_uint1 x328;
- fiat_p384_addcarryx_u64(&x327, &x328, x326, x319, x322);
+ fiat_p384_addcarryx_u64(&x327, &x328, x326, x322, x319);
uint64_t x329;
fiat_p384_uint1 x330;
- fiat_p384_addcarryx_u64(&x329, &x330, x328, x317, x320);
+ fiat_p384_addcarryx_u64(&x329, &x330, x328, x320, x317);
uint64_t x331;
fiat_p384_uint1 x332;
- fiat_p384_addcarryx_u64(&x331, &x332, x330, x315, x318);
+ fiat_p384_addcarryx_u64(&x331, &x332, x330, x318, x315);
uint64_t x333;
fiat_p384_uint1 x334;
- fiat_p384_addcarryx_u64(&x333, &x334, x332, x313, x316);
+ fiat_p384_addcarryx_u64(&x333, &x334, x332, x316, x313);
uint64_t x335;
fiat_p384_uint1 x336;
- fiat_p384_addcarryx_u64(&x335, &x336, x334, 0x0, x314);
+ fiat_p384_addcarryx_u64(&x335, &x336, x334, x314, 0x0);
uint64_t x337;
fiat_p384_uint1 x338;
- fiat_p384_addcarryx_u64(&x337, &x338, 0x0, x323, x299);
+ fiat_p384_addcarryx_u64(&x337, &x338, 0x0, x299, x323);
uint64_t x339;
fiat_p384_uint1 x340;
- fiat_p384_addcarryx_u64(&x339, &x340, x338, x325, x301);
+ fiat_p384_addcarryx_u64(&x339, &x340, x338, x301, x325);
uint64_t x341;
fiat_p384_uint1 x342;
- fiat_p384_addcarryx_u64(&x341, &x342, x340, x327, x303);
+ fiat_p384_addcarryx_u64(&x341, &x342, x340, x303, x327);
uint64_t x343;
fiat_p384_uint1 x344;
- fiat_p384_addcarryx_u64(&x343, &x344, x342, x329, x305);
+ fiat_p384_addcarryx_u64(&x343, &x344, x342, x305, x329);
uint64_t x345;
fiat_p384_uint1 x346;
- fiat_p384_addcarryx_u64(&x345, &x346, x344, x331, x307);
+ fiat_p384_addcarryx_u64(&x345, &x346, x344, x307, x331);
uint64_t x347;
fiat_p384_uint1 x348;
- fiat_p384_addcarryx_u64(&x347, &x348, x346, x333, x309);
+ fiat_p384_addcarryx_u64(&x347, &x348, x346, x309, x333);
uint64_t x349;
fiat_p384_uint1 x350;
- fiat_p384_addcarryx_u64(&x349, &x350, x348, x335, x311);
+ fiat_p384_addcarryx_u64(&x349, &x350, x348, x311, x335);
uint64_t x351;
uint64_t x352;
fiat_p384_mulx_u64(&x351, &x352, x337, UINT64_C(0x100000001));
@@ -663,46 +663,46 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x363, &x364, x351, UINT32_C(0xffffffff));
uint64_t x365;
fiat_p384_uint1 x366;
- fiat_p384_addcarryx_u64(&x365, &x366, 0x0, x361, x364);
+ fiat_p384_addcarryx_u64(&x365, &x366, 0x0, x364, x361);
uint64_t x367;
fiat_p384_uint1 x368;
- fiat_p384_addcarryx_u64(&x367, &x368, x366, x359, x362);
+ fiat_p384_addcarryx_u64(&x367, &x368, x366, x362, x359);
uint64_t x369;
fiat_p384_uint1 x370;
- fiat_p384_addcarryx_u64(&x369, &x370, x368, x357, x360);
+ fiat_p384_addcarryx_u64(&x369, &x370, x368, x360, x357);
uint64_t x371;
fiat_p384_uint1 x372;
- fiat_p384_addcarryx_u64(&x371, &x372, x370, x355, x358);
+ fiat_p384_addcarryx_u64(&x371, &x372, x370, x358, x355);
uint64_t x373;
fiat_p384_uint1 x374;
- fiat_p384_addcarryx_u64(&x373, &x374, x372, x353, x356);
+ fiat_p384_addcarryx_u64(&x373, &x374, x372, x356, x353);
uint64_t x375;
fiat_p384_uint1 x376;
- fiat_p384_addcarryx_u64(&x375, &x376, x374, 0x0, x354);
+ fiat_p384_addcarryx_u64(&x375, &x376, x374, x354, 0x0);
uint64_t x377;
fiat_p384_uint1 x378;
- fiat_p384_addcarryx_u64(&x377, &x378, 0x0, x363, x337);
+ fiat_p384_addcarryx_u64(&x377, &x378, 0x0, x337, x363);
uint64_t x379;
fiat_p384_uint1 x380;
- fiat_p384_addcarryx_u64(&x379, &x380, x378, x365, x339);
+ fiat_p384_addcarryx_u64(&x379, &x380, x378, x339, x365);
uint64_t x381;
fiat_p384_uint1 x382;
- fiat_p384_addcarryx_u64(&x381, &x382, x380, x367, x341);
+ fiat_p384_addcarryx_u64(&x381, &x382, x380, x341, x367);
uint64_t x383;
fiat_p384_uint1 x384;
- fiat_p384_addcarryx_u64(&x383, &x384, x382, x369, x343);
+ fiat_p384_addcarryx_u64(&x383, &x384, x382, x343, x369);
uint64_t x385;
fiat_p384_uint1 x386;
- fiat_p384_addcarryx_u64(&x385, &x386, x384, x371, x345);
+ fiat_p384_addcarryx_u64(&x385, &x386, x384, x345, x371);
uint64_t x387;
fiat_p384_uint1 x388;
- fiat_p384_addcarryx_u64(&x387, &x388, x386, x373, x347);
+ fiat_p384_addcarryx_u64(&x387, &x388, x386, x347, x373);
uint64_t x389;
fiat_p384_uint1 x390;
- fiat_p384_addcarryx_u64(&x389, &x390, x388, x375, x349);
+ fiat_p384_addcarryx_u64(&x389, &x390, x388, x349, x375);
uint64_t x391;
fiat_p384_uint1 x392;
- fiat_p384_addcarryx_u64(&x391, &x392, x390, 0x0, x350);
+ fiat_p384_addcarryx_u64(&x391, &x392, x390, x350, 0x0);
uint64_t x393;
uint64_t x394;
fiat_p384_mulx_u64(&x393, &x394, x5, (arg2[5]));
@@ -723,43 +723,43 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x403, &x404, x5, (arg2[0]));
uint64_t x405;
fiat_p384_uint1 x406;
- fiat_p384_addcarryx_u64(&x405, &x406, 0x0, x401, x404);
+ fiat_p384_addcarryx_u64(&x405, &x406, 0x0, x404, x401);
uint64_t x407;
fiat_p384_uint1 x408;
- fiat_p384_addcarryx_u64(&x407, &x408, x406, x399, x402);
+ fiat_p384_addcarryx_u64(&x407, &x408, x406, x402, x399);
uint64_t x409;
fiat_p384_uint1 x410;
- fiat_p384_addcarryx_u64(&x409, &x410, x408, x397, x400);
+ fiat_p384_addcarryx_u64(&x409, &x410, x408, x400, x397);
uint64_t x411;
fiat_p384_uint1 x412;
- fiat_p384_addcarryx_u64(&x411, &x412, x410, x395, x398);
+ fiat_p384_addcarryx_u64(&x411, &x412, x410, x398, x395);
uint64_t x413;
fiat_p384_uint1 x414;
- fiat_p384_addcarryx_u64(&x413, &x414, x412, x393, x396);
+ fiat_p384_addcarryx_u64(&x413, &x414, x412, x396, x393);
uint64_t x415;
fiat_p384_uint1 x416;
- fiat_p384_addcarryx_u64(&x415, &x416, x414, 0x0, x394);
+ fiat_p384_addcarryx_u64(&x415, &x416, x414, x394, 0x0);
uint64_t x417;
fiat_p384_uint1 x418;
- fiat_p384_addcarryx_u64(&x417, &x418, 0x0, x403, x379);
+ fiat_p384_addcarryx_u64(&x417, &x418, 0x0, x379, x403);
uint64_t x419;
fiat_p384_uint1 x420;
- fiat_p384_addcarryx_u64(&x419, &x420, x418, x405, x381);
+ fiat_p384_addcarryx_u64(&x419, &x420, x418, x381, x405);
uint64_t x421;
fiat_p384_uint1 x422;
- fiat_p384_addcarryx_u64(&x421, &x422, x420, x407, x383);
+ fiat_p384_addcarryx_u64(&x421, &x422, x420, x383, x407);
uint64_t x423;
fiat_p384_uint1 x424;
- fiat_p384_addcarryx_u64(&x423, &x424, x422, x409, x385);
+ fiat_p384_addcarryx_u64(&x423, &x424, x422, x385, x409);
uint64_t x425;
fiat_p384_uint1 x426;
- fiat_p384_addcarryx_u64(&x425, &x426, x424, x411, x387);
+ fiat_p384_addcarryx_u64(&x425, &x426, x424, x387, x411);
uint64_t x427;
fiat_p384_uint1 x428;
- fiat_p384_addcarryx_u64(&x427, &x428, x426, x413, x389);
+ fiat_p384_addcarryx_u64(&x427, &x428, x426, x389, x413);
uint64_t x429;
fiat_p384_uint1 x430;
- fiat_p384_addcarryx_u64(&x429, &x430, x428, x415, x391);
+ fiat_p384_addcarryx_u64(&x429, &x430, x428, x391, x415);
uint64_t x431;
uint64_t x432;
fiat_p384_mulx_u64(&x431, &x432, x417, UINT64_C(0x100000001));
@@ -783,46 +783,46 @@ static void fiat_p384_mul(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_mulx_u64(&x443, &x444, x431, UINT32_C(0xffffffff));
uint64_t x445;
fiat_p384_uint1 x446;
- fiat_p384_addcarryx_u64(&x445, &x446, 0x0, x441, x444);
+ fiat_p384_addcarryx_u64(&x445, &x446, 0x0, x444, x441);
uint64_t x447;
fiat_p384_uint1 x448;
- fiat_p384_addcarryx_u64(&x447, &x448, x446, x439, x442);
+ fiat_p384_addcarryx_u64(&x447, &x448, x446, x442, x439);
uint64_t x449;
fiat_p384_uint1 x450;
- fiat_p384_addcarryx_u64(&x449, &x450, x448, x437, x440);
+ fiat_p384_addcarryx_u64(&x449, &x450, x448, x440, x437);
uint64_t x451;
fiat_p384_uint1 x452;
- fiat_p384_addcarryx_u64(&x451, &x452, x450, x435, x438);
+ fiat_p384_addcarryx_u64(&x451, &x452, x450, x438, x435);
uint64_t x453;
fiat_p384_uint1 x454;
- fiat_p384_addcarryx_u64(&x453, &x454, x452, x433, x436);
+ fiat_p384_addcarryx_u64(&x453, &x454, x452, x436, x433);
uint64_t x455;
fiat_p384_uint1 x456;
- fiat_p384_addcarryx_u64(&x455, &x456, x454, 0x0, x434);
+ fiat_p384_addcarryx_u64(&x455, &x456, x454, x434, 0x0);
uint64_t x457;
fiat_p384_uint1 x458;
- fiat_p384_addcarryx_u64(&x457, &x458, 0x0, x443, x417);
+ fiat_p384_addcarryx_u64(&x457, &x458, 0x0, x417, x443);
uint64_t x459;
fiat_p384_uint1 x460;
- fiat_p384_addcarryx_u64(&x459, &x460, x458, x445, x419);
+ fiat_p384_addcarryx_u64(&x459, &x460, x458, x419, x445);
uint64_t x461;
fiat_p384_uint1 x462;
- fiat_p384_addcarryx_u64(&x461, &x462, x460, x447, x421);
+ fiat_p384_addcarryx_u64(&x461, &x462, x460, x421, x447);
uint64_t x463;
fiat_p384_uint1 x464;
- fiat_p384_addcarryx_u64(&x463, &x464, x462, x449, x423);
+ fiat_p384_addcarryx_u64(&x463, &x464, x462, x423, x449);
uint64_t x465;
fiat_p384_uint1 x466;
- fiat_p384_addcarryx_u64(&x465, &x466, x464, x451, x425);
+ fiat_p384_addcarryx_u64(&x465, &x466, x464, x425, x451);
uint64_t x467;
fiat_p384_uint1 x468;
- fiat_p384_addcarryx_u64(&x467, &x468, x466, x453, x427);
+ fiat_p384_addcarryx_u64(&x467, &x468, x466, x427, x453);
uint64_t x469;
fiat_p384_uint1 x470;
- fiat_p384_addcarryx_u64(&x469, &x470, x468, x455, x429);
+ fiat_p384_addcarryx_u64(&x469, &x470, x468, x429, x455);
uint64_t x471;
fiat_p384_uint1 x472;
- fiat_p384_addcarryx_u64(&x471, &x472, x470, 0x0, x430);
+ fiat_p384_addcarryx_u64(&x471, &x472, x470, x430, 0x0);
uint64_t x473;
fiat_p384_uint1 x474;
fiat_p384_subborrowx_u64(&x473, &x474, 0x0, x459, UINT32_C(0xffffffff));
@@ -904,22 +904,22 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x17, &x18, x6, (arg1[0]));
uint64_t x19;
fiat_p384_uint1 x20;
- fiat_p384_addcarryx_u64(&x19, &x20, 0x0, x15, x18);
+ fiat_p384_addcarryx_u64(&x19, &x20, 0x0, x18, x15);
uint64_t x21;
fiat_p384_uint1 x22;
- fiat_p384_addcarryx_u64(&x21, &x22, x20, x13, x16);
+ fiat_p384_addcarryx_u64(&x21, &x22, x20, x16, x13);
uint64_t x23;
fiat_p384_uint1 x24;
- fiat_p384_addcarryx_u64(&x23, &x24, x22, x11, x14);
+ fiat_p384_addcarryx_u64(&x23, &x24, x22, x14, x11);
uint64_t x25;
fiat_p384_uint1 x26;
- fiat_p384_addcarryx_u64(&x25, &x26, x24, x9, x12);
+ fiat_p384_addcarryx_u64(&x25, &x26, x24, x12, x9);
uint64_t x27;
fiat_p384_uint1 x28;
- fiat_p384_addcarryx_u64(&x27, &x28, x26, x7, x10);
+ fiat_p384_addcarryx_u64(&x27, &x28, x26, x10, x7);
uint64_t x29;
fiat_p384_uint1 x30;
- fiat_p384_addcarryx_u64(&x29, &x30, x28, 0x0, x8);
+ fiat_p384_addcarryx_u64(&x29, &x30, x28, x8, 0x0);
uint64_t x31;
uint64_t x32;
fiat_p384_mulx_u64(&x31, &x32, x17, UINT64_C(0x100000001));
@@ -943,43 +943,43 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x43, &x44, x31, UINT32_C(0xffffffff));
uint64_t x45;
fiat_p384_uint1 x46;
- fiat_p384_addcarryx_u64(&x45, &x46, 0x0, x41, x44);
+ fiat_p384_addcarryx_u64(&x45, &x46, 0x0, x44, x41);
uint64_t x47;
fiat_p384_uint1 x48;
- fiat_p384_addcarryx_u64(&x47, &x48, x46, x39, x42);
+ fiat_p384_addcarryx_u64(&x47, &x48, x46, x42, x39);
uint64_t x49;
fiat_p384_uint1 x50;
- fiat_p384_addcarryx_u64(&x49, &x50, x48, x37, x40);
+ fiat_p384_addcarryx_u64(&x49, &x50, x48, x40, x37);
uint64_t x51;
fiat_p384_uint1 x52;
- fiat_p384_addcarryx_u64(&x51, &x52, x50, x35, x38);
+ fiat_p384_addcarryx_u64(&x51, &x52, x50, x38, x35);
uint64_t x53;
fiat_p384_uint1 x54;
- fiat_p384_addcarryx_u64(&x53, &x54, x52, x33, x36);
+ fiat_p384_addcarryx_u64(&x53, &x54, x52, x36, x33);
uint64_t x55;
fiat_p384_uint1 x56;
- fiat_p384_addcarryx_u64(&x55, &x56, x54, 0x0, x34);
+ fiat_p384_addcarryx_u64(&x55, &x56, x54, x34, 0x0);
uint64_t x57;
fiat_p384_uint1 x58;
- fiat_p384_addcarryx_u64(&x57, &x58, 0x0, x43, x17);
+ fiat_p384_addcarryx_u64(&x57, &x58, 0x0, x17, x43);
uint64_t x59;
fiat_p384_uint1 x60;
- fiat_p384_addcarryx_u64(&x59, &x60, x58, x45, x19);
+ fiat_p384_addcarryx_u64(&x59, &x60, x58, x19, x45);
uint64_t x61;
fiat_p384_uint1 x62;
- fiat_p384_addcarryx_u64(&x61, &x62, x60, x47, x21);
+ fiat_p384_addcarryx_u64(&x61, &x62, x60, x21, x47);
uint64_t x63;
fiat_p384_uint1 x64;
- fiat_p384_addcarryx_u64(&x63, &x64, x62, x49, x23);
+ fiat_p384_addcarryx_u64(&x63, &x64, x62, x23, x49);
uint64_t x65;
fiat_p384_uint1 x66;
- fiat_p384_addcarryx_u64(&x65, &x66, x64, x51, x25);
+ fiat_p384_addcarryx_u64(&x65, &x66, x64, x25, x51);
uint64_t x67;
fiat_p384_uint1 x68;
- fiat_p384_addcarryx_u64(&x67, &x68, x66, x53, x27);
+ fiat_p384_addcarryx_u64(&x67, &x68, x66, x27, x53);
uint64_t x69;
fiat_p384_uint1 x70;
- fiat_p384_addcarryx_u64(&x69, &x70, x68, x55, x29);
+ fiat_p384_addcarryx_u64(&x69, &x70, x68, x29, x55);
uint64_t x71;
fiat_p384_uint1 x72;
fiat_p384_addcarryx_u64(&x71, &x72, x70, 0x0, 0x0);
@@ -1003,43 +1003,43 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x83, &x84, x1, (arg1[0]));
uint64_t x85;
fiat_p384_uint1 x86;
- fiat_p384_addcarryx_u64(&x85, &x86, 0x0, x81, x84);
+ fiat_p384_addcarryx_u64(&x85, &x86, 0x0, x84, x81);
uint64_t x87;
fiat_p384_uint1 x88;
- fiat_p384_addcarryx_u64(&x87, &x88, x86, x79, x82);
+ fiat_p384_addcarryx_u64(&x87, &x88, x86, x82, x79);
uint64_t x89;
fiat_p384_uint1 x90;
- fiat_p384_addcarryx_u64(&x89, &x90, x88, x77, x80);
+ fiat_p384_addcarryx_u64(&x89, &x90, x88, x80, x77);
uint64_t x91;
fiat_p384_uint1 x92;
- fiat_p384_addcarryx_u64(&x91, &x92, x90, x75, x78);
+ fiat_p384_addcarryx_u64(&x91, &x92, x90, x78, x75);
uint64_t x93;
fiat_p384_uint1 x94;
- fiat_p384_addcarryx_u64(&x93, &x94, x92, x73, x76);
+ fiat_p384_addcarryx_u64(&x93, &x94, x92, x76, x73);
uint64_t x95;
fiat_p384_uint1 x96;
- fiat_p384_addcarryx_u64(&x95, &x96, x94, 0x0, x74);
+ fiat_p384_addcarryx_u64(&x95, &x96, x94, x74, 0x0);
uint64_t x97;
fiat_p384_uint1 x98;
- fiat_p384_addcarryx_u64(&x97, &x98, 0x0, x83, x59);
+ fiat_p384_addcarryx_u64(&x97, &x98, 0x0, x59, x83);
uint64_t x99;
fiat_p384_uint1 x100;
- fiat_p384_addcarryx_u64(&x99, &x100, x98, x85, x61);
+ fiat_p384_addcarryx_u64(&x99, &x100, x98, x61, x85);
uint64_t x101;
fiat_p384_uint1 x102;
- fiat_p384_addcarryx_u64(&x101, &x102, x100, x87, x63);
+ fiat_p384_addcarryx_u64(&x101, &x102, x100, x63, x87);
uint64_t x103;
fiat_p384_uint1 x104;
- fiat_p384_addcarryx_u64(&x103, &x104, x102, x89, x65);
+ fiat_p384_addcarryx_u64(&x103, &x104, x102, x65, x89);
uint64_t x105;
fiat_p384_uint1 x106;
- fiat_p384_addcarryx_u64(&x105, &x106, x104, x91, x67);
+ fiat_p384_addcarryx_u64(&x105, &x106, x104, x67, x91);
uint64_t x107;
fiat_p384_uint1 x108;
- fiat_p384_addcarryx_u64(&x107, &x108, x106, x93, x69);
+ fiat_p384_addcarryx_u64(&x107, &x108, x106, x69, x93);
uint64_t x109;
fiat_p384_uint1 x110;
- fiat_p384_addcarryx_u64(&x109, &x110, x108, x95, (fiat_p384_uint1)x71);
+ fiat_p384_addcarryx_u64(&x109, &x110, x108, (fiat_p384_uint1)x71, x95);
uint64_t x111;
uint64_t x112;
fiat_p384_mulx_u64(&x111, &x112, x97, UINT64_C(0x100000001));
@@ -1063,46 +1063,46 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x123, &x124, x111, UINT32_C(0xffffffff));
uint64_t x125;
fiat_p384_uint1 x126;
- fiat_p384_addcarryx_u64(&x125, &x126, 0x0, x121, x124);
+ fiat_p384_addcarryx_u64(&x125, &x126, 0x0, x124, x121);
uint64_t x127;
fiat_p384_uint1 x128;
- fiat_p384_addcarryx_u64(&x127, &x128, x126, x119, x122);
+ fiat_p384_addcarryx_u64(&x127, &x128, x126, x122, x119);
uint64_t x129;
fiat_p384_uint1 x130;
- fiat_p384_addcarryx_u64(&x129, &x130, x128, x117, x120);
+ fiat_p384_addcarryx_u64(&x129, &x130, x128, x120, x117);
uint64_t x131;
fiat_p384_uint1 x132;
- fiat_p384_addcarryx_u64(&x131, &x132, x130, x115, x118);
+ fiat_p384_addcarryx_u64(&x131, &x132, x130, x118, x115);
uint64_t x133;
fiat_p384_uint1 x134;
- fiat_p384_addcarryx_u64(&x133, &x134, x132, x113, x116);
+ fiat_p384_addcarryx_u64(&x133, &x134, x132, x116, x113);
uint64_t x135;
fiat_p384_uint1 x136;
- fiat_p384_addcarryx_u64(&x135, &x136, x134, 0x0, x114);
+ fiat_p384_addcarryx_u64(&x135, &x136, x134, x114, 0x0);
uint64_t x137;
fiat_p384_uint1 x138;
- fiat_p384_addcarryx_u64(&x137, &x138, 0x0, x123, x97);
+ fiat_p384_addcarryx_u64(&x137, &x138, 0x0, x97, x123);
uint64_t x139;
fiat_p384_uint1 x140;
- fiat_p384_addcarryx_u64(&x139, &x140, x138, x125, x99);
+ fiat_p384_addcarryx_u64(&x139, &x140, x138, x99, x125);
uint64_t x141;
fiat_p384_uint1 x142;
- fiat_p384_addcarryx_u64(&x141, &x142, x140, x127, x101);
+ fiat_p384_addcarryx_u64(&x141, &x142, x140, x101, x127);
uint64_t x143;
fiat_p384_uint1 x144;
- fiat_p384_addcarryx_u64(&x143, &x144, x142, x129, x103);
+ fiat_p384_addcarryx_u64(&x143, &x144, x142, x103, x129);
uint64_t x145;
fiat_p384_uint1 x146;
- fiat_p384_addcarryx_u64(&x145, &x146, x144, x131, x105);
+ fiat_p384_addcarryx_u64(&x145, &x146, x144, x105, x131);
uint64_t x147;
fiat_p384_uint1 x148;
- fiat_p384_addcarryx_u64(&x147, &x148, x146, x133, x107);
+ fiat_p384_addcarryx_u64(&x147, &x148, x146, x107, x133);
uint64_t x149;
fiat_p384_uint1 x150;
- fiat_p384_addcarryx_u64(&x149, &x150, x148, x135, x109);
+ fiat_p384_addcarryx_u64(&x149, &x150, x148, x109, x135);
uint64_t x151;
fiat_p384_uint1 x152;
- fiat_p384_addcarryx_u64(&x151, &x152, x150, 0x0, x110);
+ fiat_p384_addcarryx_u64(&x151, &x152, x150, x110, 0x0);
uint64_t x153;
uint64_t x154;
fiat_p384_mulx_u64(&x153, &x154, x2, (arg1[5]));
@@ -1123,43 +1123,43 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x163, &x164, x2, (arg1[0]));
uint64_t x165;
fiat_p384_uint1 x166;
- fiat_p384_addcarryx_u64(&x165, &x166, 0x0, x161, x164);
+ fiat_p384_addcarryx_u64(&x165, &x166, 0x0, x164, x161);
uint64_t x167;
fiat_p384_uint1 x168;
- fiat_p384_addcarryx_u64(&x167, &x168, x166, x159, x162);
+ fiat_p384_addcarryx_u64(&x167, &x168, x166, x162, x159);
uint64_t x169;
fiat_p384_uint1 x170;
- fiat_p384_addcarryx_u64(&x169, &x170, x168, x157, x160);
+ fiat_p384_addcarryx_u64(&x169, &x170, x168, x160, x157);
uint64_t x171;
fiat_p384_uint1 x172;
- fiat_p384_addcarryx_u64(&x171, &x172, x170, x155, x158);
+ fiat_p384_addcarryx_u64(&x171, &x172, x170, x158, x155);
uint64_t x173;
fiat_p384_uint1 x174;
- fiat_p384_addcarryx_u64(&x173, &x174, x172, x153, x156);
+ fiat_p384_addcarryx_u64(&x173, &x174, x172, x156, x153);
uint64_t x175;
fiat_p384_uint1 x176;
- fiat_p384_addcarryx_u64(&x175, &x176, x174, 0x0, x154);
+ fiat_p384_addcarryx_u64(&x175, &x176, x174, x154, 0x0);
uint64_t x177;
fiat_p384_uint1 x178;
- fiat_p384_addcarryx_u64(&x177, &x178, 0x0, x163, x139);
+ fiat_p384_addcarryx_u64(&x177, &x178, 0x0, x139, x163);
uint64_t x179;
fiat_p384_uint1 x180;
- fiat_p384_addcarryx_u64(&x179, &x180, x178, x165, x141);
+ fiat_p384_addcarryx_u64(&x179, &x180, x178, x141, x165);
uint64_t x181;
fiat_p384_uint1 x182;
- fiat_p384_addcarryx_u64(&x181, &x182, x180, x167, x143);
+ fiat_p384_addcarryx_u64(&x181, &x182, x180, x143, x167);
uint64_t x183;
fiat_p384_uint1 x184;
- fiat_p384_addcarryx_u64(&x183, &x184, x182, x169, x145);
+ fiat_p384_addcarryx_u64(&x183, &x184, x182, x145, x169);
uint64_t x185;
fiat_p384_uint1 x186;
- fiat_p384_addcarryx_u64(&x185, &x186, x184, x171, x147);
+ fiat_p384_addcarryx_u64(&x185, &x186, x184, x147, x171);
uint64_t x187;
fiat_p384_uint1 x188;
- fiat_p384_addcarryx_u64(&x187, &x188, x186, x173, x149);
+ fiat_p384_addcarryx_u64(&x187, &x188, x186, x149, x173);
uint64_t x189;
fiat_p384_uint1 x190;
- fiat_p384_addcarryx_u64(&x189, &x190, x188, x175, x151);
+ fiat_p384_addcarryx_u64(&x189, &x190, x188, x151, x175);
uint64_t x191;
uint64_t x192;
fiat_p384_mulx_u64(&x191, &x192, x177, UINT64_C(0x100000001));
@@ -1183,46 +1183,46 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x203, &x204, x191, UINT32_C(0xffffffff));
uint64_t x205;
fiat_p384_uint1 x206;
- fiat_p384_addcarryx_u64(&x205, &x206, 0x0, x201, x204);
+ fiat_p384_addcarryx_u64(&x205, &x206, 0x0, x204, x201);
uint64_t x207;
fiat_p384_uint1 x208;
- fiat_p384_addcarryx_u64(&x207, &x208, x206, x199, x202);
+ fiat_p384_addcarryx_u64(&x207, &x208, x206, x202, x199);
uint64_t x209;
fiat_p384_uint1 x210;
- fiat_p384_addcarryx_u64(&x209, &x210, x208, x197, x200);
+ fiat_p384_addcarryx_u64(&x209, &x210, x208, x200, x197);
uint64_t x211;
fiat_p384_uint1 x212;
- fiat_p384_addcarryx_u64(&x211, &x212, x210, x195, x198);
+ fiat_p384_addcarryx_u64(&x211, &x212, x210, x198, x195);
uint64_t x213;
fiat_p384_uint1 x214;
- fiat_p384_addcarryx_u64(&x213, &x214, x212, x193, x196);
+ fiat_p384_addcarryx_u64(&x213, &x214, x212, x196, x193);
uint64_t x215;
fiat_p384_uint1 x216;
- fiat_p384_addcarryx_u64(&x215, &x216, x214, 0x0, x194);
+ fiat_p384_addcarryx_u64(&x215, &x216, x214, x194, 0x0);
uint64_t x217;
fiat_p384_uint1 x218;
- fiat_p384_addcarryx_u64(&x217, &x218, 0x0, x203, x177);
+ fiat_p384_addcarryx_u64(&x217, &x218, 0x0, x177, x203);
uint64_t x219;
fiat_p384_uint1 x220;
- fiat_p384_addcarryx_u64(&x219, &x220, x218, x205, x179);
+ fiat_p384_addcarryx_u64(&x219, &x220, x218, x179, x205);
uint64_t x221;
fiat_p384_uint1 x222;
- fiat_p384_addcarryx_u64(&x221, &x222, x220, x207, x181);
+ fiat_p384_addcarryx_u64(&x221, &x222, x220, x181, x207);
uint64_t x223;
fiat_p384_uint1 x224;
- fiat_p384_addcarryx_u64(&x223, &x224, x222, x209, x183);
+ fiat_p384_addcarryx_u64(&x223, &x224, x222, x183, x209);
uint64_t x225;
fiat_p384_uint1 x226;
- fiat_p384_addcarryx_u64(&x225, &x226, x224, x211, x185);
+ fiat_p384_addcarryx_u64(&x225, &x226, x224, x185, x211);
uint64_t x227;
fiat_p384_uint1 x228;
- fiat_p384_addcarryx_u64(&x227, &x228, x226, x213, x187);
+ fiat_p384_addcarryx_u64(&x227, &x228, x226, x187, x213);
uint64_t x229;
fiat_p384_uint1 x230;
- fiat_p384_addcarryx_u64(&x229, &x230, x228, x215, x189);
+ fiat_p384_addcarryx_u64(&x229, &x230, x228, x189, x215);
uint64_t x231;
fiat_p384_uint1 x232;
- fiat_p384_addcarryx_u64(&x231, &x232, x230, 0x0, x190);
+ fiat_p384_addcarryx_u64(&x231, &x232, x230, x190, 0x0);
uint64_t x233;
uint64_t x234;
fiat_p384_mulx_u64(&x233, &x234, x3, (arg1[5]));
@@ -1243,43 +1243,43 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x243, &x244, x3, (arg1[0]));
uint64_t x245;
fiat_p384_uint1 x246;
- fiat_p384_addcarryx_u64(&x245, &x246, 0x0, x241, x244);
+ fiat_p384_addcarryx_u64(&x245, &x246, 0x0, x244, x241);
uint64_t x247;
fiat_p384_uint1 x248;
- fiat_p384_addcarryx_u64(&x247, &x248, x246, x239, x242);
+ fiat_p384_addcarryx_u64(&x247, &x248, x246, x242, x239);
uint64_t x249;
fiat_p384_uint1 x250;
- fiat_p384_addcarryx_u64(&x249, &x250, x248, x237, x240);
+ fiat_p384_addcarryx_u64(&x249, &x250, x248, x240, x237);
uint64_t x251;
fiat_p384_uint1 x252;
- fiat_p384_addcarryx_u64(&x251, &x252, x250, x235, x238);
+ fiat_p384_addcarryx_u64(&x251, &x252, x250, x238, x235);
uint64_t x253;
fiat_p384_uint1 x254;
- fiat_p384_addcarryx_u64(&x253, &x254, x252, x233, x236);
+ fiat_p384_addcarryx_u64(&x253, &x254, x252, x236, x233);
uint64_t x255;
fiat_p384_uint1 x256;
- fiat_p384_addcarryx_u64(&x255, &x256, x254, 0x0, x234);
+ fiat_p384_addcarryx_u64(&x255, &x256, x254, x234, 0x0);
uint64_t x257;
fiat_p384_uint1 x258;
- fiat_p384_addcarryx_u64(&x257, &x258, 0x0, x243, x219);
+ fiat_p384_addcarryx_u64(&x257, &x258, 0x0, x219, x243);
uint64_t x259;
fiat_p384_uint1 x260;
- fiat_p384_addcarryx_u64(&x259, &x260, x258, x245, x221);
+ fiat_p384_addcarryx_u64(&x259, &x260, x258, x221, x245);
uint64_t x261;
fiat_p384_uint1 x262;
- fiat_p384_addcarryx_u64(&x261, &x262, x260, x247, x223);
+ fiat_p384_addcarryx_u64(&x261, &x262, x260, x223, x247);
uint64_t x263;
fiat_p384_uint1 x264;
- fiat_p384_addcarryx_u64(&x263, &x264, x262, x249, x225);
+ fiat_p384_addcarryx_u64(&x263, &x264, x262, x225, x249);
uint64_t x265;
fiat_p384_uint1 x266;
- fiat_p384_addcarryx_u64(&x265, &x266, x264, x251, x227);
+ fiat_p384_addcarryx_u64(&x265, &x266, x264, x227, x251);
uint64_t x267;
fiat_p384_uint1 x268;
- fiat_p384_addcarryx_u64(&x267, &x268, x266, x253, x229);
+ fiat_p384_addcarryx_u64(&x267, &x268, x266, x229, x253);
uint64_t x269;
fiat_p384_uint1 x270;
- fiat_p384_addcarryx_u64(&x269, &x270, x268, x255, x231);
+ fiat_p384_addcarryx_u64(&x269, &x270, x268, x231, x255);
uint64_t x271;
uint64_t x272;
fiat_p384_mulx_u64(&x271, &x272, x257, UINT64_C(0x100000001));
@@ -1303,46 +1303,46 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x283, &x284, x271, UINT32_C(0xffffffff));
uint64_t x285;
fiat_p384_uint1 x286;
- fiat_p384_addcarryx_u64(&x285, &x286, 0x0, x281, x284);
+ fiat_p384_addcarryx_u64(&x285, &x286, 0x0, x284, x281);
uint64_t x287;
fiat_p384_uint1 x288;
- fiat_p384_addcarryx_u64(&x287, &x288, x286, x279, x282);
+ fiat_p384_addcarryx_u64(&x287, &x288, x286, x282, x279);
uint64_t x289;
fiat_p384_uint1 x290;
- fiat_p384_addcarryx_u64(&x289, &x290, x288, x277, x280);
+ fiat_p384_addcarryx_u64(&x289, &x290, x288, x280, x277);
uint64_t x291;
fiat_p384_uint1 x292;
- fiat_p384_addcarryx_u64(&x291, &x292, x290, x275, x278);
+ fiat_p384_addcarryx_u64(&x291, &x292, x290, x278, x275);
uint64_t x293;
fiat_p384_uint1 x294;
- fiat_p384_addcarryx_u64(&x293, &x294, x292, x273, x276);
+ fiat_p384_addcarryx_u64(&x293, &x294, x292, x276, x273);
uint64_t x295;
fiat_p384_uint1 x296;
- fiat_p384_addcarryx_u64(&x295, &x296, x294, 0x0, x274);
+ fiat_p384_addcarryx_u64(&x295, &x296, x294, x274, 0x0);
uint64_t x297;
fiat_p384_uint1 x298;
- fiat_p384_addcarryx_u64(&x297, &x298, 0x0, x283, x257);
+ fiat_p384_addcarryx_u64(&x297, &x298, 0x0, x257, x283);
uint64_t x299;
fiat_p384_uint1 x300;
- fiat_p384_addcarryx_u64(&x299, &x300, x298, x285, x259);
+ fiat_p384_addcarryx_u64(&x299, &x300, x298, x259, x285);
uint64_t x301;
fiat_p384_uint1 x302;
- fiat_p384_addcarryx_u64(&x301, &x302, x300, x287, x261);
+ fiat_p384_addcarryx_u64(&x301, &x302, x300, x261, x287);
uint64_t x303;
fiat_p384_uint1 x304;
- fiat_p384_addcarryx_u64(&x303, &x304, x302, x289, x263);
+ fiat_p384_addcarryx_u64(&x303, &x304, x302, x263, x289);
uint64_t x305;
fiat_p384_uint1 x306;
- fiat_p384_addcarryx_u64(&x305, &x306, x304, x291, x265);
+ fiat_p384_addcarryx_u64(&x305, &x306, x304, x265, x291);
uint64_t x307;
fiat_p384_uint1 x308;
- fiat_p384_addcarryx_u64(&x307, &x308, x306, x293, x267);
+ fiat_p384_addcarryx_u64(&x307, &x308, x306, x267, x293);
uint64_t x309;
fiat_p384_uint1 x310;
- fiat_p384_addcarryx_u64(&x309, &x310, x308, x295, x269);
+ fiat_p384_addcarryx_u64(&x309, &x310, x308, x269, x295);
uint64_t x311;
fiat_p384_uint1 x312;
- fiat_p384_addcarryx_u64(&x311, &x312, x310, 0x0, x270);
+ fiat_p384_addcarryx_u64(&x311, &x312, x310, x270, 0x0);
uint64_t x313;
uint64_t x314;
fiat_p384_mulx_u64(&x313, &x314, x4, (arg1[5]));
@@ -1363,43 +1363,43 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x323, &x324, x4, (arg1[0]));
uint64_t x325;
fiat_p384_uint1 x326;
- fiat_p384_addcarryx_u64(&x325, &x326, 0x0, x321, x324);
+ fiat_p384_addcarryx_u64(&x325, &x326, 0x0, x324, x321);
uint64_t x327;
fiat_p384_uint1 x328;
- fiat_p384_addcarryx_u64(&x327, &x328, x326, x319, x322);
+ fiat_p384_addcarryx_u64(&x327, &x328, x326, x322, x319);
uint64_t x329;
fiat_p384_uint1 x330;
- fiat_p384_addcarryx_u64(&x329, &x330, x328, x317, x320);
+ fiat_p384_addcarryx_u64(&x329, &x330, x328, x320, x317);
uint64_t x331;
fiat_p384_uint1 x332;
- fiat_p384_addcarryx_u64(&x331, &x332, x330, x315, x318);
+ fiat_p384_addcarryx_u64(&x331, &x332, x330, x318, x315);
uint64_t x333;
fiat_p384_uint1 x334;
- fiat_p384_addcarryx_u64(&x333, &x334, x332, x313, x316);
+ fiat_p384_addcarryx_u64(&x333, &x334, x332, x316, x313);
uint64_t x335;
fiat_p384_uint1 x336;
- fiat_p384_addcarryx_u64(&x335, &x336, x334, 0x0, x314);
+ fiat_p384_addcarryx_u64(&x335, &x336, x334, x314, 0x0);
uint64_t x337;
fiat_p384_uint1 x338;
- fiat_p384_addcarryx_u64(&x337, &x338, 0x0, x323, x299);
+ fiat_p384_addcarryx_u64(&x337, &x338, 0x0, x299, x323);
uint64_t x339;
fiat_p384_uint1 x340;
- fiat_p384_addcarryx_u64(&x339, &x340, x338, x325, x301);
+ fiat_p384_addcarryx_u64(&x339, &x340, x338, x301, x325);
uint64_t x341;
fiat_p384_uint1 x342;
- fiat_p384_addcarryx_u64(&x341, &x342, x340, x327, x303);
+ fiat_p384_addcarryx_u64(&x341, &x342, x340, x303, x327);
uint64_t x343;
fiat_p384_uint1 x344;
- fiat_p384_addcarryx_u64(&x343, &x344, x342, x329, x305);
+ fiat_p384_addcarryx_u64(&x343, &x344, x342, x305, x329);
uint64_t x345;
fiat_p384_uint1 x346;
- fiat_p384_addcarryx_u64(&x345, &x346, x344, x331, x307);
+ fiat_p384_addcarryx_u64(&x345, &x346, x344, x307, x331);
uint64_t x347;
fiat_p384_uint1 x348;
- fiat_p384_addcarryx_u64(&x347, &x348, x346, x333, x309);
+ fiat_p384_addcarryx_u64(&x347, &x348, x346, x309, x333);
uint64_t x349;
fiat_p384_uint1 x350;
- fiat_p384_addcarryx_u64(&x349, &x350, x348, x335, x311);
+ fiat_p384_addcarryx_u64(&x349, &x350, x348, x311, x335);
uint64_t x351;
uint64_t x352;
fiat_p384_mulx_u64(&x351, &x352, x337, UINT64_C(0x100000001));
@@ -1423,46 +1423,46 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x363, &x364, x351, UINT32_C(0xffffffff));
uint64_t x365;
fiat_p384_uint1 x366;
- fiat_p384_addcarryx_u64(&x365, &x366, 0x0, x361, x364);
+ fiat_p384_addcarryx_u64(&x365, &x366, 0x0, x364, x361);
uint64_t x367;
fiat_p384_uint1 x368;
- fiat_p384_addcarryx_u64(&x367, &x368, x366, x359, x362);
+ fiat_p384_addcarryx_u64(&x367, &x368, x366, x362, x359);
uint64_t x369;
fiat_p384_uint1 x370;
- fiat_p384_addcarryx_u64(&x369, &x370, x368, x357, x360);
+ fiat_p384_addcarryx_u64(&x369, &x370, x368, x360, x357);
uint64_t x371;
fiat_p384_uint1 x372;
- fiat_p384_addcarryx_u64(&x371, &x372, x370, x355, x358);
+ fiat_p384_addcarryx_u64(&x371, &x372, x370, x358, x355);
uint64_t x373;
fiat_p384_uint1 x374;
- fiat_p384_addcarryx_u64(&x373, &x374, x372, x353, x356);
+ fiat_p384_addcarryx_u64(&x373, &x374, x372, x356, x353);
uint64_t x375;
fiat_p384_uint1 x376;
- fiat_p384_addcarryx_u64(&x375, &x376, x374, 0x0, x354);
+ fiat_p384_addcarryx_u64(&x375, &x376, x374, x354, 0x0);
uint64_t x377;
fiat_p384_uint1 x378;
- fiat_p384_addcarryx_u64(&x377, &x378, 0x0, x363, x337);
+ fiat_p384_addcarryx_u64(&x377, &x378, 0x0, x337, x363);
uint64_t x379;
fiat_p384_uint1 x380;
- fiat_p384_addcarryx_u64(&x379, &x380, x378, x365, x339);
+ fiat_p384_addcarryx_u64(&x379, &x380, x378, x339, x365);
uint64_t x381;
fiat_p384_uint1 x382;
- fiat_p384_addcarryx_u64(&x381, &x382, x380, x367, x341);
+ fiat_p384_addcarryx_u64(&x381, &x382, x380, x341, x367);
uint64_t x383;
fiat_p384_uint1 x384;
- fiat_p384_addcarryx_u64(&x383, &x384, x382, x369, x343);
+ fiat_p384_addcarryx_u64(&x383, &x384, x382, x343, x369);
uint64_t x385;
fiat_p384_uint1 x386;
- fiat_p384_addcarryx_u64(&x385, &x386, x384, x371, x345);
+ fiat_p384_addcarryx_u64(&x385, &x386, x384, x345, x371);
uint64_t x387;
fiat_p384_uint1 x388;
- fiat_p384_addcarryx_u64(&x387, &x388, x386, x373, x347);
+ fiat_p384_addcarryx_u64(&x387, &x388, x386, x347, x373);
uint64_t x389;
fiat_p384_uint1 x390;
- fiat_p384_addcarryx_u64(&x389, &x390, x388, x375, x349);
+ fiat_p384_addcarryx_u64(&x389, &x390, x388, x349, x375);
uint64_t x391;
fiat_p384_uint1 x392;
- fiat_p384_addcarryx_u64(&x391, &x392, x390, 0x0, x350);
+ fiat_p384_addcarryx_u64(&x391, &x392, x390, x350, 0x0);
uint64_t x393;
uint64_t x394;
fiat_p384_mulx_u64(&x393, &x394, x5, (arg1[5]));
@@ -1483,43 +1483,43 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x403, &x404, x5, (arg1[0]));
uint64_t x405;
fiat_p384_uint1 x406;
- fiat_p384_addcarryx_u64(&x405, &x406, 0x0, x401, x404);
+ fiat_p384_addcarryx_u64(&x405, &x406, 0x0, x404, x401);
uint64_t x407;
fiat_p384_uint1 x408;
- fiat_p384_addcarryx_u64(&x407, &x408, x406, x399, x402);
+ fiat_p384_addcarryx_u64(&x407, &x408, x406, x402, x399);
uint64_t x409;
fiat_p384_uint1 x410;
- fiat_p384_addcarryx_u64(&x409, &x410, x408, x397, x400);
+ fiat_p384_addcarryx_u64(&x409, &x410, x408, x400, x397);
uint64_t x411;
fiat_p384_uint1 x412;
- fiat_p384_addcarryx_u64(&x411, &x412, x410, x395, x398);
+ fiat_p384_addcarryx_u64(&x411, &x412, x410, x398, x395);
uint64_t x413;
fiat_p384_uint1 x414;
- fiat_p384_addcarryx_u64(&x413, &x414, x412, x393, x396);
+ fiat_p384_addcarryx_u64(&x413, &x414, x412, x396, x393);
uint64_t x415;
fiat_p384_uint1 x416;
- fiat_p384_addcarryx_u64(&x415, &x416, x414, 0x0, x394);
+ fiat_p384_addcarryx_u64(&x415, &x416, x414, x394, 0x0);
uint64_t x417;
fiat_p384_uint1 x418;
- fiat_p384_addcarryx_u64(&x417, &x418, 0x0, x403, x379);
+ fiat_p384_addcarryx_u64(&x417, &x418, 0x0, x379, x403);
uint64_t x419;
fiat_p384_uint1 x420;
- fiat_p384_addcarryx_u64(&x419, &x420, x418, x405, x381);
+ fiat_p384_addcarryx_u64(&x419, &x420, x418, x381, x405);
uint64_t x421;
fiat_p384_uint1 x422;
- fiat_p384_addcarryx_u64(&x421, &x422, x420, x407, x383);
+ fiat_p384_addcarryx_u64(&x421, &x422, x420, x383, x407);
uint64_t x423;
fiat_p384_uint1 x424;
- fiat_p384_addcarryx_u64(&x423, &x424, x422, x409, x385);
+ fiat_p384_addcarryx_u64(&x423, &x424, x422, x385, x409);
uint64_t x425;
fiat_p384_uint1 x426;
- fiat_p384_addcarryx_u64(&x425, &x426, x424, x411, x387);
+ fiat_p384_addcarryx_u64(&x425, &x426, x424, x387, x411);
uint64_t x427;
fiat_p384_uint1 x428;
- fiat_p384_addcarryx_u64(&x427, &x428, x426, x413, x389);
+ fiat_p384_addcarryx_u64(&x427, &x428, x426, x389, x413);
uint64_t x429;
fiat_p384_uint1 x430;
- fiat_p384_addcarryx_u64(&x429, &x430, x428, x415, x391);
+ fiat_p384_addcarryx_u64(&x429, &x430, x428, x391, x415);
uint64_t x431;
uint64_t x432;
fiat_p384_mulx_u64(&x431, &x432, x417, UINT64_C(0x100000001));
@@ -1543,46 +1543,46 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_mulx_u64(&x443, &x444, x431, UINT32_C(0xffffffff));
uint64_t x445;
fiat_p384_uint1 x446;
- fiat_p384_addcarryx_u64(&x445, &x446, 0x0, x441, x444);
+ fiat_p384_addcarryx_u64(&x445, &x446, 0x0, x444, x441);
uint64_t x447;
fiat_p384_uint1 x448;
- fiat_p384_addcarryx_u64(&x447, &x448, x446, x439, x442);
+ fiat_p384_addcarryx_u64(&x447, &x448, x446, x442, x439);
uint64_t x449;
fiat_p384_uint1 x450;
- fiat_p384_addcarryx_u64(&x449, &x450, x448, x437, x440);
+ fiat_p384_addcarryx_u64(&x449, &x450, x448, x440, x437);
uint64_t x451;
fiat_p384_uint1 x452;
- fiat_p384_addcarryx_u64(&x451, &x452, x450, x435, x438);
+ fiat_p384_addcarryx_u64(&x451, &x452, x450, x438, x435);
uint64_t x453;
fiat_p384_uint1 x454;
- fiat_p384_addcarryx_u64(&x453, &x454, x452, x433, x436);
+ fiat_p384_addcarryx_u64(&x453, &x454, x452, x436, x433);
uint64_t x455;
fiat_p384_uint1 x456;
- fiat_p384_addcarryx_u64(&x455, &x456, x454, 0x0, x434);
+ fiat_p384_addcarryx_u64(&x455, &x456, x454, x434, 0x0);
uint64_t x457;
fiat_p384_uint1 x458;
- fiat_p384_addcarryx_u64(&x457, &x458, 0x0, x443, x417);
+ fiat_p384_addcarryx_u64(&x457, &x458, 0x0, x417, x443);
uint64_t x459;
fiat_p384_uint1 x460;
- fiat_p384_addcarryx_u64(&x459, &x460, x458, x445, x419);
+ fiat_p384_addcarryx_u64(&x459, &x460, x458, x419, x445);
uint64_t x461;
fiat_p384_uint1 x462;
- fiat_p384_addcarryx_u64(&x461, &x462, x460, x447, x421);
+ fiat_p384_addcarryx_u64(&x461, &x462, x460, x421, x447);
uint64_t x463;
fiat_p384_uint1 x464;
- fiat_p384_addcarryx_u64(&x463, &x464, x462, x449, x423);
+ fiat_p384_addcarryx_u64(&x463, &x464, x462, x423, x449);
uint64_t x465;
fiat_p384_uint1 x466;
- fiat_p384_addcarryx_u64(&x465, &x466, x464, x451, x425);
+ fiat_p384_addcarryx_u64(&x465, &x466, x464, x425, x451);
uint64_t x467;
fiat_p384_uint1 x468;
- fiat_p384_addcarryx_u64(&x467, &x468, x466, x453, x427);
+ fiat_p384_addcarryx_u64(&x467, &x468, x466, x427, x453);
uint64_t x469;
fiat_p384_uint1 x470;
- fiat_p384_addcarryx_u64(&x469, &x470, x468, x455, x429);
+ fiat_p384_addcarryx_u64(&x469, &x470, x468, x429, x455);
uint64_t x471;
fiat_p384_uint1 x472;
- fiat_p384_addcarryx_u64(&x471, &x472, x470, 0x0, x430);
+ fiat_p384_addcarryx_u64(&x471, &x472, x470, x430, 0x0);
uint64_t x473;
fiat_p384_uint1 x474;
fiat_p384_subborrowx_u64(&x473, &x474, 0x0, x459, UINT32_C(0xffffffff));
@@ -1642,22 +1642,22 @@ static void fiat_p384_square(uint64_t out1[6], const uint64_t arg1[6]) {
static void fiat_p384_add(uint64_t out1[6], const uint64_t arg1[6], const uint64_t arg2[6]) {
uint64_t x1;
fiat_p384_uint1 x2;
- fiat_p384_addcarryx_u64(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p384_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint64_t x3;
fiat_p384_uint1 x4;
- fiat_p384_addcarryx_u64(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p384_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint64_t x5;
fiat_p384_uint1 x6;
- fiat_p384_addcarryx_u64(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p384_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint64_t x7;
fiat_p384_uint1 x8;
- fiat_p384_addcarryx_u64(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p384_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint64_t x9;
fiat_p384_uint1 x10;
- fiat_p384_addcarryx_u64(&x9, &x10, x8, (arg2[4]), (arg1[4]));
+ fiat_p384_addcarryx_u64(&x9, &x10, x8, (arg1[4]), (arg2[4]));
uint64_t x11;
fiat_p384_uint1 x12;
- fiat_p384_addcarryx_u64(&x11, &x12, x10, (arg2[5]), (arg1[5]));
+ fiat_p384_addcarryx_u64(&x11, &x12, x10, (arg1[5]), (arg2[5]));
uint64_t x13;
fiat_p384_uint1 x14;
fiat_p384_subborrowx_u64(&x13, &x14, 0x0, x1, UINT32_C(0xffffffff));
@@ -1737,22 +1737,22 @@ static void fiat_p384_sub(uint64_t out1[6], const uint64_t arg1[6], const uint64
fiat_p384_cmovznz_u64(&x13, x12, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x14;
fiat_p384_uint1 x15;
- fiat_p384_addcarryx_u64(&x14, &x15, 0x0, (x13 & UINT32_C(0xffffffff)), x1);
+ fiat_p384_addcarryx_u64(&x14, &x15, 0x0, x1, (x13 & UINT32_C(0xffffffff)));
uint64_t x16;
fiat_p384_uint1 x17;
- fiat_p384_addcarryx_u64(&x16, &x17, x15, (x13 & UINT64_C(0xffffffff00000000)), x3);
+ fiat_p384_addcarryx_u64(&x16, &x17, x15, x3, (x13 & UINT64_C(0xffffffff00000000)));
uint64_t x18;
fiat_p384_uint1 x19;
- fiat_p384_addcarryx_u64(&x18, &x19, x17, (x13 & UINT64_C(0xfffffffffffffffe)), x5);
+ fiat_p384_addcarryx_u64(&x18, &x19, x17, x5, (x13 & UINT64_C(0xfffffffffffffffe)));
uint64_t x20;
fiat_p384_uint1 x21;
- fiat_p384_addcarryx_u64(&x20, &x21, x19, (x13 & UINT64_C(0xffffffffffffffff)), x7);
+ fiat_p384_addcarryx_u64(&x20, &x21, x19, x7, (x13 & UINT64_C(0xffffffffffffffff)));
uint64_t x22;
fiat_p384_uint1 x23;
- fiat_p384_addcarryx_u64(&x22, &x23, x21, (x13 & UINT64_C(0xffffffffffffffff)), x9);
+ fiat_p384_addcarryx_u64(&x22, &x23, x21, x9, (x13 & UINT64_C(0xffffffffffffffff)));
uint64_t x24;
fiat_p384_uint1 x25;
- fiat_p384_addcarryx_u64(&x24, &x25, x23, (x13 & UINT64_C(0xffffffffffffffff)), x11);
+ fiat_p384_addcarryx_u64(&x24, &x25, x23, x11, (x13 & UINT64_C(0xffffffffffffffff)));
out1[0] = x14;
out1[1] = x16;
out1[2] = x18;
@@ -1797,22 +1797,22 @@ static void fiat_p384_opp(uint64_t out1[6], const uint64_t arg1[6]) {
fiat_p384_cmovznz_u64(&x13, x12, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x14;
fiat_p384_uint1 x15;
- fiat_p384_addcarryx_u64(&x14, &x15, 0x0, (x13 & UINT32_C(0xffffffff)), x1);
+ fiat_p384_addcarryx_u64(&x14, &x15, 0x0, x1, (x13 & UINT32_C(0xffffffff)));
uint64_t x16;
fiat_p384_uint1 x17;
- fiat_p384_addcarryx_u64(&x16, &x17, x15, (x13 & UINT64_C(0xffffffff00000000)), x3);
+ fiat_p384_addcarryx_u64(&x16, &x17, x15, x3, (x13 & UINT64_C(0xffffffff00000000)));
uint64_t x18;
fiat_p384_uint1 x19;
- fiat_p384_addcarryx_u64(&x18, &x19, x17, (x13 & UINT64_C(0xfffffffffffffffe)), x5);
+ fiat_p384_addcarryx_u64(&x18, &x19, x17, x5, (x13 & UINT64_C(0xfffffffffffffffe)));
uint64_t x20;
fiat_p384_uint1 x21;
- fiat_p384_addcarryx_u64(&x20, &x21, x19, (x13 & UINT64_C(0xffffffffffffffff)), x7);
+ fiat_p384_addcarryx_u64(&x20, &x21, x19, x7, (x13 & UINT64_C(0xffffffffffffffff)));
uint64_t x22;
fiat_p384_uint1 x23;
- fiat_p384_addcarryx_u64(&x22, &x23, x21, (x13 & UINT64_C(0xffffffffffffffff)), x9);
+ fiat_p384_addcarryx_u64(&x22, &x23, x21, x9, (x13 & UINT64_C(0xffffffffffffffff)));
uint64_t x24;
fiat_p384_uint1 x25;
- fiat_p384_addcarryx_u64(&x24, &x25, x23, (x13 & UINT64_C(0xffffffffffffffff)), x11);
+ fiat_p384_addcarryx_u64(&x24, &x25, x23, x11, (x13 & UINT64_C(0xffffffffffffffff)));
out1[0] = x14;
out1[1] = x16;
out1[2] = x18;
@@ -1859,61 +1859,61 @@ static void fiat_p384_from_montgomery(uint64_t out1[6], const uint64_t arg1[6])
fiat_p384_mulx_u64(&x14, &x15, x2, UINT32_C(0xffffffff));
uint64_t x16;
fiat_p384_uint1 x17;
- fiat_p384_addcarryx_u64(&x16, &x17, 0x0, x12, x15);
+ fiat_p384_addcarryx_u64(&x16, &x17, 0x0, x15, x12);
uint64_t x18;
fiat_p384_uint1 x19;
- fiat_p384_addcarryx_u64(&x18, &x19, x17, x10, x13);
+ fiat_p384_addcarryx_u64(&x18, &x19, x17, x13, x10);
uint64_t x20;
fiat_p384_uint1 x21;
- fiat_p384_addcarryx_u64(&x20, &x21, x19, x8, x11);
+ fiat_p384_addcarryx_u64(&x20, &x21, x19, x11, x8);
uint64_t x22;
fiat_p384_uint1 x23;
- fiat_p384_addcarryx_u64(&x22, &x23, x21, x6, x9);
+ fiat_p384_addcarryx_u64(&x22, &x23, x21, x9, x6);
uint64_t x24;
fiat_p384_uint1 x25;
- fiat_p384_addcarryx_u64(&x24, &x25, x23, x4, x7);
+ fiat_p384_addcarryx_u64(&x24, &x25, x23, x7, x4);
uint64_t x26;
fiat_p384_uint1 x27;
- fiat_p384_addcarryx_u64(&x26, &x27, 0x0, x14, x1);
+ fiat_p384_addcarryx_u64(&x26, &x27, 0x0, x1, x14);
uint64_t x28;
fiat_p384_uint1 x29;
- fiat_p384_addcarryx_u64(&x28, &x29, x27, x16, 0x0);
+ fiat_p384_addcarryx_u64(&x28, &x29, x27, 0x0, x16);
uint64_t x30;
fiat_p384_uint1 x31;
- fiat_p384_addcarryx_u64(&x30, &x31, x29, x18, 0x0);
+ fiat_p384_addcarryx_u64(&x30, &x31, x29, 0x0, x18);
uint64_t x32;
fiat_p384_uint1 x33;
- fiat_p384_addcarryx_u64(&x32, &x33, x31, x20, 0x0);
+ fiat_p384_addcarryx_u64(&x32, &x33, x31, 0x0, x20);
uint64_t x34;
fiat_p384_uint1 x35;
- fiat_p384_addcarryx_u64(&x34, &x35, x33, x22, 0x0);
+ fiat_p384_addcarryx_u64(&x34, &x35, x33, 0x0, x22);
uint64_t x36;
fiat_p384_uint1 x37;
- fiat_p384_addcarryx_u64(&x36, &x37, x35, x24, 0x0);
+ fiat_p384_addcarryx_u64(&x36, &x37, x35, 0x0, x24);
uint64_t x38;
fiat_p384_uint1 x39;
- fiat_p384_addcarryx_u64(&x38, &x39, x25, 0x0, x5);
+ fiat_p384_addcarryx_u64(&x38, &x39, x25, x5, 0x0);
uint64_t x40;
fiat_p384_uint1 x41;
- fiat_p384_addcarryx_u64(&x40, &x41, x37, x38, 0x0);
+ fiat_p384_addcarryx_u64(&x40, &x41, x37, 0x0, x38);
uint64_t x42;
fiat_p384_uint1 x43;
- fiat_p384_addcarryx_u64(&x42, &x43, 0x0, (arg1[1]), x28);
+ fiat_p384_addcarryx_u64(&x42, &x43, 0x0, x28, (arg1[1]));
uint64_t x44;
fiat_p384_uint1 x45;
- fiat_p384_addcarryx_u64(&x44, &x45, x43, 0x0, x30);
+ fiat_p384_addcarryx_u64(&x44, &x45, x43, x30, 0x0);
uint64_t x46;
fiat_p384_uint1 x47;
- fiat_p384_addcarryx_u64(&x46, &x47, x45, 0x0, x32);
+ fiat_p384_addcarryx_u64(&x46, &x47, x45, x32, 0x0);
uint64_t x48;
fiat_p384_uint1 x49;
- fiat_p384_addcarryx_u64(&x48, &x49, x47, 0x0, x34);
+ fiat_p384_addcarryx_u64(&x48, &x49, x47, x34, 0x0);
uint64_t x50;
fiat_p384_uint1 x51;
- fiat_p384_addcarryx_u64(&x50, &x51, x49, 0x0, x36);
+ fiat_p384_addcarryx_u64(&x50, &x51, x49, x36, 0x0);
uint64_t x52;
fiat_p384_uint1 x53;
- fiat_p384_addcarryx_u64(&x52, &x53, x51, 0x0, x40);
+ fiat_p384_addcarryx_u64(&x52, &x53, x51, x40, 0x0);
uint64_t x54;
uint64_t x55;
fiat_p384_mulx_u64(&x54, &x55, x42, UINT64_C(0x100000001));
@@ -1937,67 +1937,67 @@ static void fiat_p384_from_montgomery(uint64_t out1[6], const uint64_t arg1[6])
fiat_p384_mulx_u64(&x66, &x67, x54, UINT32_C(0xffffffff));
uint64_t x68;
fiat_p384_uint1 x69;
- fiat_p384_addcarryx_u64(&x68, &x69, 0x0, x64, x67);
+ fiat_p384_addcarryx_u64(&x68, &x69, 0x0, x67, x64);
uint64_t x70;
fiat_p384_uint1 x71;
- fiat_p384_addcarryx_u64(&x70, &x71, x69, x62, x65);
+ fiat_p384_addcarryx_u64(&x70, &x71, x69, x65, x62);
uint64_t x72;
fiat_p384_uint1 x73;
- fiat_p384_addcarryx_u64(&x72, &x73, x71, x60, x63);
+ fiat_p384_addcarryx_u64(&x72, &x73, x71, x63, x60);
uint64_t x74;
fiat_p384_uint1 x75;
- fiat_p384_addcarryx_u64(&x74, &x75, x73, x58, x61);
+ fiat_p384_addcarryx_u64(&x74, &x75, x73, x61, x58);
uint64_t x76;
fiat_p384_uint1 x77;
- fiat_p384_addcarryx_u64(&x76, &x77, x75, x56, x59);
+ fiat_p384_addcarryx_u64(&x76, &x77, x75, x59, x56);
uint64_t x78;
fiat_p384_uint1 x79;
- fiat_p384_addcarryx_u64(&x78, &x79, 0x0, x66, x42);
+ fiat_p384_addcarryx_u64(&x78, &x79, 0x0, x42, x66);
uint64_t x80;
fiat_p384_uint1 x81;
- fiat_p384_addcarryx_u64(&x80, &x81, x79, x68, x44);
+ fiat_p384_addcarryx_u64(&x80, &x81, x79, x44, x68);
uint64_t x82;
fiat_p384_uint1 x83;
- fiat_p384_addcarryx_u64(&x82, &x83, x81, x70, x46);
+ fiat_p384_addcarryx_u64(&x82, &x83, x81, x46, x70);
uint64_t x84;
fiat_p384_uint1 x85;
- fiat_p384_addcarryx_u64(&x84, &x85, x83, x72, x48);
+ fiat_p384_addcarryx_u64(&x84, &x85, x83, x48, x72);
uint64_t x86;
fiat_p384_uint1 x87;
- fiat_p384_addcarryx_u64(&x86, &x87, x85, x74, x50);
+ fiat_p384_addcarryx_u64(&x86, &x87, x85, x50, x74);
uint64_t x88;
fiat_p384_uint1 x89;
- fiat_p384_addcarryx_u64(&x88, &x89, x87, x76, x52);
+ fiat_p384_addcarryx_u64(&x88, &x89, x87, x52, x76);
uint64_t x90;
fiat_p384_uint1 x91;
- fiat_p384_addcarryx_u64(&x90, &x91, x41, 0x0, 0x0);
+ fiat_p384_addcarryx_u64(&x90, &x91, x77, x57, 0x0);
uint64_t x92;
fiat_p384_uint1 x93;
- fiat_p384_addcarryx_u64(&x92, &x93, x53, 0x0, (fiat_p384_uint1)x90);
+ fiat_p384_addcarryx_u64(&x92, &x93, x41, 0x0, 0x0);
uint64_t x94;
fiat_p384_uint1 x95;
- fiat_p384_addcarryx_u64(&x94, &x95, x77, 0x0, x57);
+ fiat_p384_addcarryx_u64(&x94, &x95, x53, (fiat_p384_uint1)x92, 0x0);
uint64_t x96;
fiat_p384_uint1 x97;
- fiat_p384_addcarryx_u64(&x96, &x97, x89, x94, x92);
+ fiat_p384_addcarryx_u64(&x96, &x97, x89, x94, x90);
uint64_t x98;
fiat_p384_uint1 x99;
- fiat_p384_addcarryx_u64(&x98, &x99, 0x0, (arg1[2]), x80);
+ fiat_p384_addcarryx_u64(&x98, &x99, 0x0, x80, (arg1[2]));
uint64_t x100;
fiat_p384_uint1 x101;
- fiat_p384_addcarryx_u64(&x100, &x101, x99, 0x0, x82);
+ fiat_p384_addcarryx_u64(&x100, &x101, x99, x82, 0x0);
uint64_t x102;
fiat_p384_uint1 x103;
- fiat_p384_addcarryx_u64(&x102, &x103, x101, 0x0, x84);
+ fiat_p384_addcarryx_u64(&x102, &x103, x101, x84, 0x0);
uint64_t x104;
fiat_p384_uint1 x105;
- fiat_p384_addcarryx_u64(&x104, &x105, x103, 0x0, x86);
+ fiat_p384_addcarryx_u64(&x104, &x105, x103, x86, 0x0);
uint64_t x106;
fiat_p384_uint1 x107;
- fiat_p384_addcarryx_u64(&x106, &x107, x105, 0x0, x88);
+ fiat_p384_addcarryx_u64(&x106, &x107, x105, x88, 0x0);
uint64_t x108;
fiat_p384_uint1 x109;
- fiat_p384_addcarryx_u64(&x108, &x109, x107, 0x0, x96);
+ fiat_p384_addcarryx_u64(&x108, &x109, x107, x96, 0x0);
uint64_t x110;
uint64_t x111;
fiat_p384_mulx_u64(&x110, &x111, x98, UINT64_C(0x100000001));
@@ -2021,67 +2021,67 @@ static void fiat_p384_from_montgomery(uint64_t out1[6], const uint64_t arg1[6])
fiat_p384_mulx_u64(&x122, &x123, x110, UINT32_C(0xffffffff));
uint64_t x124;
fiat_p384_uint1 x125;
- fiat_p384_addcarryx_u64(&x124, &x125, 0x0, x120, x123);
+ fiat_p384_addcarryx_u64(&x124, &x125, 0x0, x123, x120);
uint64_t x126;
fiat_p384_uint1 x127;
- fiat_p384_addcarryx_u64(&x126, &x127, x125, x118, x121);
+ fiat_p384_addcarryx_u64(&x126, &x127, x125, x121, x118);
uint64_t x128;
fiat_p384_uint1 x129;
- fiat_p384_addcarryx_u64(&x128, &x129, x127, x116, x119);
+ fiat_p384_addcarryx_u64(&x128, &x129, x127, x119, x116);
uint64_t x130;
fiat_p384_uint1 x131;
- fiat_p384_addcarryx_u64(&x130, &x131, x129, x114, x117);
+ fiat_p384_addcarryx_u64(&x130, &x131, x129, x117, x114);
uint64_t x132;
fiat_p384_uint1 x133;
- fiat_p384_addcarryx_u64(&x132, &x133, x131, x112, x115);
+ fiat_p384_addcarryx_u64(&x132, &x133, x131, x115, x112);
uint64_t x134;
fiat_p384_uint1 x135;
- fiat_p384_addcarryx_u64(&x134, &x135, 0x0, x122, x98);
+ fiat_p384_addcarryx_u64(&x134, &x135, 0x0, x98, x122);
uint64_t x136;
fiat_p384_uint1 x137;
- fiat_p384_addcarryx_u64(&x136, &x137, x135, x124, x100);
+ fiat_p384_addcarryx_u64(&x136, &x137, x135, x100, x124);
uint64_t x138;
fiat_p384_uint1 x139;
- fiat_p384_addcarryx_u64(&x138, &x139, x137, x126, x102);
+ fiat_p384_addcarryx_u64(&x138, &x139, x137, x102, x126);
uint64_t x140;
fiat_p384_uint1 x141;
- fiat_p384_addcarryx_u64(&x140, &x141, x139, x128, x104);
+ fiat_p384_addcarryx_u64(&x140, &x141, x139, x104, x128);
uint64_t x142;
fiat_p384_uint1 x143;
- fiat_p384_addcarryx_u64(&x142, &x143, x141, x130, x106);
+ fiat_p384_addcarryx_u64(&x142, &x143, x141, x106, x130);
uint64_t x144;
fiat_p384_uint1 x145;
- fiat_p384_addcarryx_u64(&x144, &x145, x143, x132, x108);
+ fiat_p384_addcarryx_u64(&x144, &x145, x143, x108, x132);
uint64_t x146;
fiat_p384_uint1 x147;
- fiat_p384_addcarryx_u64(&x146, &x147, x97, 0x0, 0x0);
+ fiat_p384_addcarryx_u64(&x146, &x147, x133, x113, 0x0);
uint64_t x148;
fiat_p384_uint1 x149;
- fiat_p384_addcarryx_u64(&x148, &x149, x109, 0x0, (fiat_p384_uint1)x146);
+ fiat_p384_addcarryx_u64(&x148, &x149, x97, 0x0, 0x0);
uint64_t x150;
fiat_p384_uint1 x151;
- fiat_p384_addcarryx_u64(&x150, &x151, x133, 0x0, x113);
+ fiat_p384_addcarryx_u64(&x150, &x151, x109, (fiat_p384_uint1)x148, 0x0);
uint64_t x152;
fiat_p384_uint1 x153;
- fiat_p384_addcarryx_u64(&x152, &x153, x145, x150, x148);
+ fiat_p384_addcarryx_u64(&x152, &x153, x145, x150, x146);
uint64_t x154;
fiat_p384_uint1 x155;
- fiat_p384_addcarryx_u64(&x154, &x155, 0x0, (arg1[3]), x136);
+ fiat_p384_addcarryx_u64(&x154, &x155, 0x0, x136, (arg1[3]));
uint64_t x156;
fiat_p384_uint1 x157;
- fiat_p384_addcarryx_u64(&x156, &x157, x155, 0x0, x138);
+ fiat_p384_addcarryx_u64(&x156, &x157, x155, x138, 0x0);
uint64_t x158;
fiat_p384_uint1 x159;
- fiat_p384_addcarryx_u64(&x158, &x159, x157, 0x0, x140);
+ fiat_p384_addcarryx_u64(&x158, &x159, x157, x140, 0x0);
uint64_t x160;
fiat_p384_uint1 x161;
- fiat_p384_addcarryx_u64(&x160, &x161, x159, 0x0, x142);
+ fiat_p384_addcarryx_u64(&x160, &x161, x159, x142, 0x0);
uint64_t x162;
fiat_p384_uint1 x163;
- fiat_p384_addcarryx_u64(&x162, &x163, x161, 0x0, x144);
+ fiat_p384_addcarryx_u64(&x162, &x163, x161, x144, 0x0);
uint64_t x164;
fiat_p384_uint1 x165;
- fiat_p384_addcarryx_u64(&x164, &x165, x163, 0x0, x152);
+ fiat_p384_addcarryx_u64(&x164, &x165, x163, x152, 0x0);
uint64_t x166;
uint64_t x167;
fiat_p384_mulx_u64(&x166, &x167, x154, UINT64_C(0x100000001));
@@ -2105,67 +2105,67 @@ static void fiat_p384_from_montgomery(uint64_t out1[6], const uint64_t arg1[6])
fiat_p384_mulx_u64(&x178, &x179, x166, UINT32_C(0xffffffff));
uint64_t x180;
fiat_p384_uint1 x181;
- fiat_p384_addcarryx_u64(&x180, &x181, 0x0, x176, x179);
+ fiat_p384_addcarryx_u64(&x180, &x181, 0x0, x179, x176);
uint64_t x182;
fiat_p384_uint1 x183;
- fiat_p384_addcarryx_u64(&x182, &x183, x181, x174, x177);
+ fiat_p384_addcarryx_u64(&x182, &x183, x181, x177, x174);
uint64_t x184;
fiat_p384_uint1 x185;
- fiat_p384_addcarryx_u64(&x184, &x185, x183, x172, x175);
+ fiat_p384_addcarryx_u64(&x184, &x185, x183, x175, x172);
uint64_t x186;
fiat_p384_uint1 x187;
- fiat_p384_addcarryx_u64(&x186, &x187, x185, x170, x173);
+ fiat_p384_addcarryx_u64(&x186, &x187, x185, x173, x170);
uint64_t x188;
fiat_p384_uint1 x189;
- fiat_p384_addcarryx_u64(&x188, &x189, x187, x168, x171);
+ fiat_p384_addcarryx_u64(&x188, &x189, x187, x171, x168);
uint64_t x190;
fiat_p384_uint1 x191;
- fiat_p384_addcarryx_u64(&x190, &x191, 0x0, x178, x154);
+ fiat_p384_addcarryx_u64(&x190, &x191, 0x0, x154, x178);
uint64_t x192;
fiat_p384_uint1 x193;
- fiat_p384_addcarryx_u64(&x192, &x193, x191, x180, x156);
+ fiat_p384_addcarryx_u64(&x192, &x193, x191, x156, x180);
uint64_t x194;
fiat_p384_uint1 x195;
- fiat_p384_addcarryx_u64(&x194, &x195, x193, x182, x158);
+ fiat_p384_addcarryx_u64(&x194, &x195, x193, x158, x182);
uint64_t x196;
fiat_p384_uint1 x197;
- fiat_p384_addcarryx_u64(&x196, &x197, x195, x184, x160);
+ fiat_p384_addcarryx_u64(&x196, &x197, x195, x160, x184);
uint64_t x198;
fiat_p384_uint1 x199;
- fiat_p384_addcarryx_u64(&x198, &x199, x197, x186, x162);
+ fiat_p384_addcarryx_u64(&x198, &x199, x197, x162, x186);
uint64_t x200;
fiat_p384_uint1 x201;
- fiat_p384_addcarryx_u64(&x200, &x201, x199, x188, x164);
+ fiat_p384_addcarryx_u64(&x200, &x201, x199, x164, x188);
uint64_t x202;
fiat_p384_uint1 x203;
- fiat_p384_addcarryx_u64(&x202, &x203, x153, 0x0, 0x0);
+ fiat_p384_addcarryx_u64(&x202, &x203, x189, x169, 0x0);
uint64_t x204;
fiat_p384_uint1 x205;
- fiat_p384_addcarryx_u64(&x204, &x205, x165, 0x0, (fiat_p384_uint1)x202);
+ fiat_p384_addcarryx_u64(&x204, &x205, x153, 0x0, 0x0);
uint64_t x206;
fiat_p384_uint1 x207;
- fiat_p384_addcarryx_u64(&x206, &x207, x189, 0x0, x169);
+ fiat_p384_addcarryx_u64(&x206, &x207, x165, (fiat_p384_uint1)x204, 0x0);
uint64_t x208;
fiat_p384_uint1 x209;
- fiat_p384_addcarryx_u64(&x208, &x209, x201, x206, x204);
+ fiat_p384_addcarryx_u64(&x208, &x209, x201, x206, x202);
uint64_t x210;
fiat_p384_uint1 x211;
- fiat_p384_addcarryx_u64(&x210, &x211, 0x0, (arg1[4]), x192);
+ fiat_p384_addcarryx_u64(&x210, &x211, 0x0, x192, (arg1[4]));
uint64_t x212;
fiat_p384_uint1 x213;
- fiat_p384_addcarryx_u64(&x212, &x213, x211, 0x0, x194);
+ fiat_p384_addcarryx_u64(&x212, &x213, x211, x194, 0x0);
uint64_t x214;
fiat_p384_uint1 x215;
- fiat_p384_addcarryx_u64(&x214, &x215, x213, 0x0, x196);
+ fiat_p384_addcarryx_u64(&x214, &x215, x213, x196, 0x0);
uint64_t x216;
fiat_p384_uint1 x217;
- fiat_p384_addcarryx_u64(&x216, &x217, x215, 0x0, x198);
+ fiat_p384_addcarryx_u64(&x216, &x217, x215, x198, 0x0);
uint64_t x218;
fiat_p384_uint1 x219;
- fiat_p384_addcarryx_u64(&x218, &x219, x217, 0x0, x200);
+ fiat_p384_addcarryx_u64(&x218, &x219, x217, x200, 0x0);
uint64_t x220;
fiat_p384_uint1 x221;
- fiat_p384_addcarryx_u64(&x220, &x221, x219, 0x0, x208);
+ fiat_p384_addcarryx_u64(&x220, &x221, x219, x208, 0x0);
uint64_t x222;
uint64_t x223;
fiat_p384_mulx_u64(&x222, &x223, x210, UINT64_C(0x100000001));
@@ -2189,67 +2189,67 @@ static void fiat_p384_from_montgomery(uint64_t out1[6], const uint64_t arg1[6])
fiat_p384_mulx_u64(&x234, &x235, x222, UINT32_C(0xffffffff));
uint64_t x236;
fiat_p384_uint1 x237;
- fiat_p384_addcarryx_u64(&x236, &x237, 0x0, x232, x235);
+ fiat_p384_addcarryx_u64(&x236, &x237, 0x0, x235, x232);
uint64_t x238;
fiat_p384_uint1 x239;
- fiat_p384_addcarryx_u64(&x238, &x239, x237, x230, x233);
+ fiat_p384_addcarryx_u64(&x238, &x239, x237, x233, x230);
uint64_t x240;
fiat_p384_uint1 x241;
- fiat_p384_addcarryx_u64(&x240, &x241, x239, x228, x231);
+ fiat_p384_addcarryx_u64(&x240, &x241, x239, x231, x228);
uint64_t x242;
fiat_p384_uint1 x243;
- fiat_p384_addcarryx_u64(&x242, &x243, x241, x226, x229);
+ fiat_p384_addcarryx_u64(&x242, &x243, x241, x229, x226);
uint64_t x244;
fiat_p384_uint1 x245;
- fiat_p384_addcarryx_u64(&x244, &x245, x243, x224, x227);
+ fiat_p384_addcarryx_u64(&x244, &x245, x243, x227, x224);
uint64_t x246;
fiat_p384_uint1 x247;
- fiat_p384_addcarryx_u64(&x246, &x247, 0x0, x234, x210);
+ fiat_p384_addcarryx_u64(&x246, &x247, 0x0, x210, x234);
uint64_t x248;
fiat_p384_uint1 x249;
- fiat_p384_addcarryx_u64(&x248, &x249, x247, x236, x212);
+ fiat_p384_addcarryx_u64(&x248, &x249, x247, x212, x236);
uint64_t x250;
fiat_p384_uint1 x251;
- fiat_p384_addcarryx_u64(&x250, &x251, x249, x238, x214);
+ fiat_p384_addcarryx_u64(&x250, &x251, x249, x214, x238);
uint64_t x252;
fiat_p384_uint1 x253;
- fiat_p384_addcarryx_u64(&x252, &x253, x251, x240, x216);
+ fiat_p384_addcarryx_u64(&x252, &x253, x251, x216, x240);
uint64_t x254;
fiat_p384_uint1 x255;
- fiat_p384_addcarryx_u64(&x254, &x255, x253, x242, x218);
+ fiat_p384_addcarryx_u64(&x254, &x255, x253, x218, x242);
uint64_t x256;
fiat_p384_uint1 x257;
- fiat_p384_addcarryx_u64(&x256, &x257, x255, x244, x220);
+ fiat_p384_addcarryx_u64(&x256, &x257, x255, x220, x244);
uint64_t x258;
fiat_p384_uint1 x259;
- fiat_p384_addcarryx_u64(&x258, &x259, x209, 0x0, 0x0);
+ fiat_p384_addcarryx_u64(&x258, &x259, x245, x225, 0x0);
uint64_t x260;
fiat_p384_uint1 x261;
- fiat_p384_addcarryx_u64(&x260, &x261, x221, 0x0, (fiat_p384_uint1)x258);
+ fiat_p384_addcarryx_u64(&x260, &x261, x209, 0x0, 0x0);
uint64_t x262;
fiat_p384_uint1 x263;
- fiat_p384_addcarryx_u64(&x262, &x263, x245, 0x0, x225);
+ fiat_p384_addcarryx_u64(&x262, &x263, x221, (fiat_p384_uint1)x260, 0x0);
uint64_t x264;
fiat_p384_uint1 x265;
- fiat_p384_addcarryx_u64(&x264, &x265, x257, x262, x260);
+ fiat_p384_addcarryx_u64(&x264, &x265, x257, x262, x258);
uint64_t x266;
fiat_p384_uint1 x267;
- fiat_p384_addcarryx_u64(&x266, &x267, 0x0, (arg1[5]), x248);
+ fiat_p384_addcarryx_u64(&x266, &x267, 0x0, x248, (arg1[5]));
uint64_t x268;
fiat_p384_uint1 x269;
- fiat_p384_addcarryx_u64(&x268, &x269, x267, 0x0, x250);
+ fiat_p384_addcarryx_u64(&x268, &x269, x267, x250, 0x0);
uint64_t x270;
fiat_p384_uint1 x271;
- fiat_p384_addcarryx_u64(&x270, &x271, x269, 0x0, x252);
+ fiat_p384_addcarryx_u64(&x270, &x271, x269, x252, 0x0);
uint64_t x272;
fiat_p384_uint1 x273;
- fiat_p384_addcarryx_u64(&x272, &x273, x271, 0x0, x254);
+ fiat_p384_addcarryx_u64(&x272, &x273, x271, x254, 0x0);
uint64_t x274;
fiat_p384_uint1 x275;
- fiat_p384_addcarryx_u64(&x274, &x275, x273, 0x0, x256);
+ fiat_p384_addcarryx_u64(&x274, &x275, x273, x256, 0x0);
uint64_t x276;
fiat_p384_uint1 x277;
- fiat_p384_addcarryx_u64(&x276, &x277, x275, 0x0, x264);
+ fiat_p384_addcarryx_u64(&x276, &x277, x275, x264, 0x0);
uint64_t x278;
uint64_t x279;
fiat_p384_mulx_u64(&x278, &x279, x266, UINT64_C(0x100000001));
@@ -2273,49 +2273,49 @@ static void fiat_p384_from_montgomery(uint64_t out1[6], const uint64_t arg1[6])
fiat_p384_mulx_u64(&x290, &x291, x278, UINT32_C(0xffffffff));
uint64_t x292;
fiat_p384_uint1 x293;
- fiat_p384_addcarryx_u64(&x292, &x293, 0x0, x288, x291);
+ fiat_p384_addcarryx_u64(&x292, &x293, 0x0, x291, x288);
uint64_t x294;
fiat_p384_uint1 x295;
- fiat_p384_addcarryx_u64(&x294, &x295, x293, x286, x289);
+ fiat_p384_addcarryx_u64(&x294, &x295, x293, x289, x286);
uint64_t x296;
fiat_p384_uint1 x297;
- fiat_p384_addcarryx_u64(&x296, &x297, x295, x284, x287);
+ fiat_p384_addcarryx_u64(&x296, &x297, x295, x287, x284);
uint64_t x298;
fiat_p384_uint1 x299;
- fiat_p384_addcarryx_u64(&x298, &x299, x297, x282, x285);
+ fiat_p384_addcarryx_u64(&x298, &x299, x297, x285, x282);
uint64_t x300;
fiat_p384_uint1 x301;
- fiat_p384_addcarryx_u64(&x300, &x301, x299, x280, x283);
+ fiat_p384_addcarryx_u64(&x300, &x301, x299, x283, x280);
uint64_t x302;
fiat_p384_uint1 x303;
- fiat_p384_addcarryx_u64(&x302, &x303, 0x0, x290, x266);
+ fiat_p384_addcarryx_u64(&x302, &x303, 0x0, x266, x290);
uint64_t x304;
fiat_p384_uint1 x305;
- fiat_p384_addcarryx_u64(&x304, &x305, x303, x292, x268);
+ fiat_p384_addcarryx_u64(&x304, &x305, x303, x268, x292);
uint64_t x306;
fiat_p384_uint1 x307;
- fiat_p384_addcarryx_u64(&x306, &x307, x305, x294, x270);
+ fiat_p384_addcarryx_u64(&x306, &x307, x305, x270, x294);
uint64_t x308;
fiat_p384_uint1 x309;
- fiat_p384_addcarryx_u64(&x308, &x309, x307, x296, x272);
+ fiat_p384_addcarryx_u64(&x308, &x309, x307, x272, x296);
uint64_t x310;
fiat_p384_uint1 x311;
- fiat_p384_addcarryx_u64(&x310, &x311, x309, x298, x274);
+ fiat_p384_addcarryx_u64(&x310, &x311, x309, x274, x298);
uint64_t x312;
fiat_p384_uint1 x313;
- fiat_p384_addcarryx_u64(&x312, &x313, x311, x300, x276);
+ fiat_p384_addcarryx_u64(&x312, &x313, x311, x276, x300);
uint64_t x314;
fiat_p384_uint1 x315;
- fiat_p384_addcarryx_u64(&x314, &x315, x265, 0x0, 0x0);
+ fiat_p384_addcarryx_u64(&x314, &x315, x301, x281, 0x0);
uint64_t x316;
fiat_p384_uint1 x317;
- fiat_p384_addcarryx_u64(&x316, &x317, x277, 0x0, (fiat_p384_uint1)x314);
+ fiat_p384_addcarryx_u64(&x316, &x317, x265, 0x0, 0x0);
uint64_t x318;
fiat_p384_uint1 x319;
- fiat_p384_addcarryx_u64(&x318, &x319, x301, 0x0, x281);
+ fiat_p384_addcarryx_u64(&x318, &x319, x277, (fiat_p384_uint1)x316, 0x0);
uint64_t x320;
fiat_p384_uint1 x321;
- fiat_p384_addcarryx_u64(&x320, &x321, x313, x318, x316);
+ fiat_p384_addcarryx_u64(&x320, &x321, x313, x318, x314);
uint64_t x322;
fiat_p384_uint1 x323;
fiat_p384_subborrowx_u64(&x322, &x323, 0x0, x304, UINT32_C(0xffffffff));
diff --git a/p434_64.c b/p434_64.c
index ff56cd51d..390af5f95 100644
--- a/p434_64.c
+++ b/p434_64.c
@@ -148,25 +148,25 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x20, &x21, x7, (arg2[0]));
uint64_t x22;
fiat_p434_uint1 x23;
- fiat_p434_addcarryx_u64(&x22, &x23, 0x0, x18, x21);
+ fiat_p434_addcarryx_u64(&x22, &x23, 0x0, x21, x18);
uint64_t x24;
fiat_p434_uint1 x25;
- fiat_p434_addcarryx_u64(&x24, &x25, x23, x16, x19);
+ fiat_p434_addcarryx_u64(&x24, &x25, x23, x19, x16);
uint64_t x26;
fiat_p434_uint1 x27;
- fiat_p434_addcarryx_u64(&x26, &x27, x25, x14, x17);
+ fiat_p434_addcarryx_u64(&x26, &x27, x25, x17, x14);
uint64_t x28;
fiat_p434_uint1 x29;
- fiat_p434_addcarryx_u64(&x28, &x29, x27, x12, x15);
+ fiat_p434_addcarryx_u64(&x28, &x29, x27, x15, x12);
uint64_t x30;
fiat_p434_uint1 x31;
- fiat_p434_addcarryx_u64(&x30, &x31, x29, x10, x13);
+ fiat_p434_addcarryx_u64(&x30, &x31, x29, x13, x10);
uint64_t x32;
fiat_p434_uint1 x33;
- fiat_p434_addcarryx_u64(&x32, &x33, x31, x8, x11);
+ fiat_p434_addcarryx_u64(&x32, &x33, x31, x11, x8);
uint64_t x34;
fiat_p434_uint1 x35;
- fiat_p434_addcarryx_u64(&x34, &x35, x33, 0x0, x9);
+ fiat_p434_addcarryx_u64(&x34, &x35, x33, x9, 0x0);
uint64_t x36;
uint64_t x37;
fiat_p434_mulx_u64(&x36, &x37, x20, UINT64_C(0x2341f27177344));
@@ -190,49 +190,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x48, &x49, x20, UINT64_C(0xffffffffffffffff));
uint64_t x50;
fiat_p434_uint1 x51;
- fiat_p434_addcarryx_u64(&x50, &x51, 0x0, x46, x49);
+ fiat_p434_addcarryx_u64(&x50, &x51, 0x0, x49, x46);
uint64_t x52;
fiat_p434_uint1 x53;
- fiat_p434_addcarryx_u64(&x52, &x53, x51, x44, x47);
+ fiat_p434_addcarryx_u64(&x52, &x53, x51, x47, x44);
uint64_t x54;
fiat_p434_uint1 x55;
- fiat_p434_addcarryx_u64(&x54, &x55, x53, x42, x45);
+ fiat_p434_addcarryx_u64(&x54, &x55, x53, x45, x42);
uint64_t x56;
fiat_p434_uint1 x57;
- fiat_p434_addcarryx_u64(&x56, &x57, x55, x40, x43);
+ fiat_p434_addcarryx_u64(&x56, &x57, x55, x43, x40);
uint64_t x58;
fiat_p434_uint1 x59;
- fiat_p434_addcarryx_u64(&x58, &x59, x57, x38, x41);
+ fiat_p434_addcarryx_u64(&x58, &x59, x57, x41, x38);
uint64_t x60;
fiat_p434_uint1 x61;
- fiat_p434_addcarryx_u64(&x60, &x61, x59, x36, x39);
+ fiat_p434_addcarryx_u64(&x60, &x61, x59, x39, x36);
uint64_t x62;
fiat_p434_uint1 x63;
- fiat_p434_addcarryx_u64(&x62, &x63, x61, 0x0, x37);
+ fiat_p434_addcarryx_u64(&x62, &x63, x61, x37, 0x0);
uint64_t x64;
fiat_p434_uint1 x65;
- fiat_p434_addcarryx_u64(&x64, &x65, 0x0, x48, x20);
+ fiat_p434_addcarryx_u64(&x64, &x65, 0x0, x20, x48);
uint64_t x66;
fiat_p434_uint1 x67;
- fiat_p434_addcarryx_u64(&x66, &x67, x65, x50, x22);
+ fiat_p434_addcarryx_u64(&x66, &x67, x65, x22, x50);
uint64_t x68;
fiat_p434_uint1 x69;
- fiat_p434_addcarryx_u64(&x68, &x69, x67, x52, x24);
+ fiat_p434_addcarryx_u64(&x68, &x69, x67, x24, x52);
uint64_t x70;
fiat_p434_uint1 x71;
- fiat_p434_addcarryx_u64(&x70, &x71, x69, x54, x26);
+ fiat_p434_addcarryx_u64(&x70, &x71, x69, x26, x54);
uint64_t x72;
fiat_p434_uint1 x73;
- fiat_p434_addcarryx_u64(&x72, &x73, x71, x56, x28);
+ fiat_p434_addcarryx_u64(&x72, &x73, x71, x28, x56);
uint64_t x74;
fiat_p434_uint1 x75;
- fiat_p434_addcarryx_u64(&x74, &x75, x73, x58, x30);
+ fiat_p434_addcarryx_u64(&x74, &x75, x73, x30, x58);
uint64_t x76;
fiat_p434_uint1 x77;
- fiat_p434_addcarryx_u64(&x76, &x77, x75, x60, x32);
+ fiat_p434_addcarryx_u64(&x76, &x77, x75, x32, x60);
uint64_t x78;
fiat_p434_uint1 x79;
- fiat_p434_addcarryx_u64(&x78, &x79, x77, x62, x34);
+ fiat_p434_addcarryx_u64(&x78, &x79, x77, x34, x62);
uint64_t x80;
fiat_p434_uint1 x81;
fiat_p434_addcarryx_u64(&x80, &x81, x79, 0x0, 0x0);
@@ -259,49 +259,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x94, &x95, x1, (arg2[0]));
uint64_t x96;
fiat_p434_uint1 x97;
- fiat_p434_addcarryx_u64(&x96, &x97, 0x0, x92, x95);
+ fiat_p434_addcarryx_u64(&x96, &x97, 0x0, x95, x92);
uint64_t x98;
fiat_p434_uint1 x99;
- fiat_p434_addcarryx_u64(&x98, &x99, x97, x90, x93);
+ fiat_p434_addcarryx_u64(&x98, &x99, x97, x93, x90);
uint64_t x100;
fiat_p434_uint1 x101;
- fiat_p434_addcarryx_u64(&x100, &x101, x99, x88, x91);
+ fiat_p434_addcarryx_u64(&x100, &x101, x99, x91, x88);
uint64_t x102;
fiat_p434_uint1 x103;
- fiat_p434_addcarryx_u64(&x102, &x103, x101, x86, x89);
+ fiat_p434_addcarryx_u64(&x102, &x103, x101, x89, x86);
uint64_t x104;
fiat_p434_uint1 x105;
- fiat_p434_addcarryx_u64(&x104, &x105, x103, x84, x87);
+ fiat_p434_addcarryx_u64(&x104, &x105, x103, x87, x84);
uint64_t x106;
fiat_p434_uint1 x107;
- fiat_p434_addcarryx_u64(&x106, &x107, x105, x82, x85);
+ fiat_p434_addcarryx_u64(&x106, &x107, x105, x85, x82);
uint64_t x108;
fiat_p434_uint1 x109;
- fiat_p434_addcarryx_u64(&x108, &x109, x107, 0x0, x83);
+ fiat_p434_addcarryx_u64(&x108, &x109, x107, x83, 0x0);
uint64_t x110;
fiat_p434_uint1 x111;
- fiat_p434_addcarryx_u64(&x110, &x111, 0x0, x94, x66);
+ fiat_p434_addcarryx_u64(&x110, &x111, 0x0, x66, x94);
uint64_t x112;
fiat_p434_uint1 x113;
- fiat_p434_addcarryx_u64(&x112, &x113, x111, x96, x68);
+ fiat_p434_addcarryx_u64(&x112, &x113, x111, x68, x96);
uint64_t x114;
fiat_p434_uint1 x115;
- fiat_p434_addcarryx_u64(&x114, &x115, x113, x98, x70);
+ fiat_p434_addcarryx_u64(&x114, &x115, x113, x70, x98);
uint64_t x116;
fiat_p434_uint1 x117;
- fiat_p434_addcarryx_u64(&x116, &x117, x115, x100, x72);
+ fiat_p434_addcarryx_u64(&x116, &x117, x115, x72, x100);
uint64_t x118;
fiat_p434_uint1 x119;
- fiat_p434_addcarryx_u64(&x118, &x119, x117, x102, x74);
+ fiat_p434_addcarryx_u64(&x118, &x119, x117, x74, x102);
uint64_t x120;
fiat_p434_uint1 x121;
- fiat_p434_addcarryx_u64(&x120, &x121, x119, x104, x76);
+ fiat_p434_addcarryx_u64(&x120, &x121, x119, x76, x104);
uint64_t x122;
fiat_p434_uint1 x123;
- fiat_p434_addcarryx_u64(&x122, &x123, x121, x106, x78);
+ fiat_p434_addcarryx_u64(&x122, &x123, x121, x78, x106);
uint64_t x124;
fiat_p434_uint1 x125;
- fiat_p434_addcarryx_u64(&x124, &x125, x123, x108, (fiat_p434_uint1)x80);
+ fiat_p434_addcarryx_u64(&x124, &x125, x123, (fiat_p434_uint1)x80, x108);
uint64_t x126;
uint64_t x127;
fiat_p434_mulx_u64(&x126, &x127, x110, UINT64_C(0x2341f27177344));
@@ -325,52 +325,52 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x138, &x139, x110, UINT64_C(0xffffffffffffffff));
uint64_t x140;
fiat_p434_uint1 x141;
- fiat_p434_addcarryx_u64(&x140, &x141, 0x0, x136, x139);
+ fiat_p434_addcarryx_u64(&x140, &x141, 0x0, x139, x136);
uint64_t x142;
fiat_p434_uint1 x143;
- fiat_p434_addcarryx_u64(&x142, &x143, x141, x134, x137);
+ fiat_p434_addcarryx_u64(&x142, &x143, x141, x137, x134);
uint64_t x144;
fiat_p434_uint1 x145;
- fiat_p434_addcarryx_u64(&x144, &x145, x143, x132, x135);
+ fiat_p434_addcarryx_u64(&x144, &x145, x143, x135, x132);
uint64_t x146;
fiat_p434_uint1 x147;
- fiat_p434_addcarryx_u64(&x146, &x147, x145, x130, x133);
+ fiat_p434_addcarryx_u64(&x146, &x147, x145, x133, x130);
uint64_t x148;
fiat_p434_uint1 x149;
- fiat_p434_addcarryx_u64(&x148, &x149, x147, x128, x131);
+ fiat_p434_addcarryx_u64(&x148, &x149, x147, x131, x128);
uint64_t x150;
fiat_p434_uint1 x151;
- fiat_p434_addcarryx_u64(&x150, &x151, x149, x126, x129);
+ fiat_p434_addcarryx_u64(&x150, &x151, x149, x129, x126);
uint64_t x152;
fiat_p434_uint1 x153;
- fiat_p434_addcarryx_u64(&x152, &x153, x151, 0x0, x127);
+ fiat_p434_addcarryx_u64(&x152, &x153, x151, x127, 0x0);
uint64_t x154;
fiat_p434_uint1 x155;
- fiat_p434_addcarryx_u64(&x154, &x155, 0x0, x138, x110);
+ fiat_p434_addcarryx_u64(&x154, &x155, 0x0, x110, x138);
uint64_t x156;
fiat_p434_uint1 x157;
- fiat_p434_addcarryx_u64(&x156, &x157, x155, x140, x112);
+ fiat_p434_addcarryx_u64(&x156, &x157, x155, x112, x140);
uint64_t x158;
fiat_p434_uint1 x159;
- fiat_p434_addcarryx_u64(&x158, &x159, x157, x142, x114);
+ fiat_p434_addcarryx_u64(&x158, &x159, x157, x114, x142);
uint64_t x160;
fiat_p434_uint1 x161;
- fiat_p434_addcarryx_u64(&x160, &x161, x159, x144, x116);
+ fiat_p434_addcarryx_u64(&x160, &x161, x159, x116, x144);
uint64_t x162;
fiat_p434_uint1 x163;
- fiat_p434_addcarryx_u64(&x162, &x163, x161, x146, x118);
+ fiat_p434_addcarryx_u64(&x162, &x163, x161, x118, x146);
uint64_t x164;
fiat_p434_uint1 x165;
- fiat_p434_addcarryx_u64(&x164, &x165, x163, x148, x120);
+ fiat_p434_addcarryx_u64(&x164, &x165, x163, x120, x148);
uint64_t x166;
fiat_p434_uint1 x167;
- fiat_p434_addcarryx_u64(&x166, &x167, x165, x150, x122);
+ fiat_p434_addcarryx_u64(&x166, &x167, x165, x122, x150);
uint64_t x168;
fiat_p434_uint1 x169;
- fiat_p434_addcarryx_u64(&x168, &x169, x167, x152, x124);
+ fiat_p434_addcarryx_u64(&x168, &x169, x167, x124, x152);
uint64_t x170;
fiat_p434_uint1 x171;
- fiat_p434_addcarryx_u64(&x170, &x171, x169, 0x0, x125);
+ fiat_p434_addcarryx_u64(&x170, &x171, x169, x125, 0x0);
uint64_t x172;
uint64_t x173;
fiat_p434_mulx_u64(&x172, &x173, x2, (arg2[6]));
@@ -394,49 +394,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x184, &x185, x2, (arg2[0]));
uint64_t x186;
fiat_p434_uint1 x187;
- fiat_p434_addcarryx_u64(&x186, &x187, 0x0, x182, x185);
+ fiat_p434_addcarryx_u64(&x186, &x187, 0x0, x185, x182);
uint64_t x188;
fiat_p434_uint1 x189;
- fiat_p434_addcarryx_u64(&x188, &x189, x187, x180, x183);
+ fiat_p434_addcarryx_u64(&x188, &x189, x187, x183, x180);
uint64_t x190;
fiat_p434_uint1 x191;
- fiat_p434_addcarryx_u64(&x190, &x191, x189, x178, x181);
+ fiat_p434_addcarryx_u64(&x190, &x191, x189, x181, x178);
uint64_t x192;
fiat_p434_uint1 x193;
- fiat_p434_addcarryx_u64(&x192, &x193, x191, x176, x179);
+ fiat_p434_addcarryx_u64(&x192, &x193, x191, x179, x176);
uint64_t x194;
fiat_p434_uint1 x195;
- fiat_p434_addcarryx_u64(&x194, &x195, x193, x174, x177);
+ fiat_p434_addcarryx_u64(&x194, &x195, x193, x177, x174);
uint64_t x196;
fiat_p434_uint1 x197;
- fiat_p434_addcarryx_u64(&x196, &x197, x195, x172, x175);
+ fiat_p434_addcarryx_u64(&x196, &x197, x195, x175, x172);
uint64_t x198;
fiat_p434_uint1 x199;
- fiat_p434_addcarryx_u64(&x198, &x199, x197, 0x0, x173);
+ fiat_p434_addcarryx_u64(&x198, &x199, x197, x173, 0x0);
uint64_t x200;
fiat_p434_uint1 x201;
- fiat_p434_addcarryx_u64(&x200, &x201, 0x0, x184, x156);
+ fiat_p434_addcarryx_u64(&x200, &x201, 0x0, x156, x184);
uint64_t x202;
fiat_p434_uint1 x203;
- fiat_p434_addcarryx_u64(&x202, &x203, x201, x186, x158);
+ fiat_p434_addcarryx_u64(&x202, &x203, x201, x158, x186);
uint64_t x204;
fiat_p434_uint1 x205;
- fiat_p434_addcarryx_u64(&x204, &x205, x203, x188, x160);
+ fiat_p434_addcarryx_u64(&x204, &x205, x203, x160, x188);
uint64_t x206;
fiat_p434_uint1 x207;
- fiat_p434_addcarryx_u64(&x206, &x207, x205, x190, x162);
+ fiat_p434_addcarryx_u64(&x206, &x207, x205, x162, x190);
uint64_t x208;
fiat_p434_uint1 x209;
- fiat_p434_addcarryx_u64(&x208, &x209, x207, x192, x164);
+ fiat_p434_addcarryx_u64(&x208, &x209, x207, x164, x192);
uint64_t x210;
fiat_p434_uint1 x211;
- fiat_p434_addcarryx_u64(&x210, &x211, x209, x194, x166);
+ fiat_p434_addcarryx_u64(&x210, &x211, x209, x166, x194);
uint64_t x212;
fiat_p434_uint1 x213;
- fiat_p434_addcarryx_u64(&x212, &x213, x211, x196, x168);
+ fiat_p434_addcarryx_u64(&x212, &x213, x211, x168, x196);
uint64_t x214;
fiat_p434_uint1 x215;
- fiat_p434_addcarryx_u64(&x214, &x215, x213, x198, x170);
+ fiat_p434_addcarryx_u64(&x214, &x215, x213, x170, x198);
uint64_t x216;
uint64_t x217;
fiat_p434_mulx_u64(&x216, &x217, x200, UINT64_C(0x2341f27177344));
@@ -460,52 +460,52 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x228, &x229, x200, UINT64_C(0xffffffffffffffff));
uint64_t x230;
fiat_p434_uint1 x231;
- fiat_p434_addcarryx_u64(&x230, &x231, 0x0, x226, x229);
+ fiat_p434_addcarryx_u64(&x230, &x231, 0x0, x229, x226);
uint64_t x232;
fiat_p434_uint1 x233;
- fiat_p434_addcarryx_u64(&x232, &x233, x231, x224, x227);
+ fiat_p434_addcarryx_u64(&x232, &x233, x231, x227, x224);
uint64_t x234;
fiat_p434_uint1 x235;
- fiat_p434_addcarryx_u64(&x234, &x235, x233, x222, x225);
+ fiat_p434_addcarryx_u64(&x234, &x235, x233, x225, x222);
uint64_t x236;
fiat_p434_uint1 x237;
- fiat_p434_addcarryx_u64(&x236, &x237, x235, x220, x223);
+ fiat_p434_addcarryx_u64(&x236, &x237, x235, x223, x220);
uint64_t x238;
fiat_p434_uint1 x239;
- fiat_p434_addcarryx_u64(&x238, &x239, x237, x218, x221);
+ fiat_p434_addcarryx_u64(&x238, &x239, x237, x221, x218);
uint64_t x240;
fiat_p434_uint1 x241;
- fiat_p434_addcarryx_u64(&x240, &x241, x239, x216, x219);
+ fiat_p434_addcarryx_u64(&x240, &x241, x239, x219, x216);
uint64_t x242;
fiat_p434_uint1 x243;
- fiat_p434_addcarryx_u64(&x242, &x243, x241, 0x0, x217);
+ fiat_p434_addcarryx_u64(&x242, &x243, x241, x217, 0x0);
uint64_t x244;
fiat_p434_uint1 x245;
- fiat_p434_addcarryx_u64(&x244, &x245, 0x0, x228, x200);
+ fiat_p434_addcarryx_u64(&x244, &x245, 0x0, x200, x228);
uint64_t x246;
fiat_p434_uint1 x247;
- fiat_p434_addcarryx_u64(&x246, &x247, x245, x230, x202);
+ fiat_p434_addcarryx_u64(&x246, &x247, x245, x202, x230);
uint64_t x248;
fiat_p434_uint1 x249;
- fiat_p434_addcarryx_u64(&x248, &x249, x247, x232, x204);
+ fiat_p434_addcarryx_u64(&x248, &x249, x247, x204, x232);
uint64_t x250;
fiat_p434_uint1 x251;
- fiat_p434_addcarryx_u64(&x250, &x251, x249, x234, x206);
+ fiat_p434_addcarryx_u64(&x250, &x251, x249, x206, x234);
uint64_t x252;
fiat_p434_uint1 x253;
- fiat_p434_addcarryx_u64(&x252, &x253, x251, x236, x208);
+ fiat_p434_addcarryx_u64(&x252, &x253, x251, x208, x236);
uint64_t x254;
fiat_p434_uint1 x255;
- fiat_p434_addcarryx_u64(&x254, &x255, x253, x238, x210);
+ fiat_p434_addcarryx_u64(&x254, &x255, x253, x210, x238);
uint64_t x256;
fiat_p434_uint1 x257;
- fiat_p434_addcarryx_u64(&x256, &x257, x255, x240, x212);
+ fiat_p434_addcarryx_u64(&x256, &x257, x255, x212, x240);
uint64_t x258;
fiat_p434_uint1 x259;
- fiat_p434_addcarryx_u64(&x258, &x259, x257, x242, x214);
+ fiat_p434_addcarryx_u64(&x258, &x259, x257, x214, x242);
uint64_t x260;
fiat_p434_uint1 x261;
- fiat_p434_addcarryx_u64(&x260, &x261, x259, 0x0, x215);
+ fiat_p434_addcarryx_u64(&x260, &x261, x259, x215, 0x0);
uint64_t x262;
uint64_t x263;
fiat_p434_mulx_u64(&x262, &x263, x3, (arg2[6]));
@@ -529,49 +529,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x274, &x275, x3, (arg2[0]));
uint64_t x276;
fiat_p434_uint1 x277;
- fiat_p434_addcarryx_u64(&x276, &x277, 0x0, x272, x275);
+ fiat_p434_addcarryx_u64(&x276, &x277, 0x0, x275, x272);
uint64_t x278;
fiat_p434_uint1 x279;
- fiat_p434_addcarryx_u64(&x278, &x279, x277, x270, x273);
+ fiat_p434_addcarryx_u64(&x278, &x279, x277, x273, x270);
uint64_t x280;
fiat_p434_uint1 x281;
- fiat_p434_addcarryx_u64(&x280, &x281, x279, x268, x271);
+ fiat_p434_addcarryx_u64(&x280, &x281, x279, x271, x268);
uint64_t x282;
fiat_p434_uint1 x283;
- fiat_p434_addcarryx_u64(&x282, &x283, x281, x266, x269);
+ fiat_p434_addcarryx_u64(&x282, &x283, x281, x269, x266);
uint64_t x284;
fiat_p434_uint1 x285;
- fiat_p434_addcarryx_u64(&x284, &x285, x283, x264, x267);
+ fiat_p434_addcarryx_u64(&x284, &x285, x283, x267, x264);
uint64_t x286;
fiat_p434_uint1 x287;
- fiat_p434_addcarryx_u64(&x286, &x287, x285, x262, x265);
+ fiat_p434_addcarryx_u64(&x286, &x287, x285, x265, x262);
uint64_t x288;
fiat_p434_uint1 x289;
- fiat_p434_addcarryx_u64(&x288, &x289, x287, 0x0, x263);
+ fiat_p434_addcarryx_u64(&x288, &x289, x287, x263, 0x0);
uint64_t x290;
fiat_p434_uint1 x291;
- fiat_p434_addcarryx_u64(&x290, &x291, 0x0, x274, x246);
+ fiat_p434_addcarryx_u64(&x290, &x291, 0x0, x246, x274);
uint64_t x292;
fiat_p434_uint1 x293;
- fiat_p434_addcarryx_u64(&x292, &x293, x291, x276, x248);
+ fiat_p434_addcarryx_u64(&x292, &x293, x291, x248, x276);
uint64_t x294;
fiat_p434_uint1 x295;
- fiat_p434_addcarryx_u64(&x294, &x295, x293, x278, x250);
+ fiat_p434_addcarryx_u64(&x294, &x295, x293, x250, x278);
uint64_t x296;
fiat_p434_uint1 x297;
- fiat_p434_addcarryx_u64(&x296, &x297, x295, x280, x252);
+ fiat_p434_addcarryx_u64(&x296, &x297, x295, x252, x280);
uint64_t x298;
fiat_p434_uint1 x299;
- fiat_p434_addcarryx_u64(&x298, &x299, x297, x282, x254);
+ fiat_p434_addcarryx_u64(&x298, &x299, x297, x254, x282);
uint64_t x300;
fiat_p434_uint1 x301;
- fiat_p434_addcarryx_u64(&x300, &x301, x299, x284, x256);
+ fiat_p434_addcarryx_u64(&x300, &x301, x299, x256, x284);
uint64_t x302;
fiat_p434_uint1 x303;
- fiat_p434_addcarryx_u64(&x302, &x303, x301, x286, x258);
+ fiat_p434_addcarryx_u64(&x302, &x303, x301, x258, x286);
uint64_t x304;
fiat_p434_uint1 x305;
- fiat_p434_addcarryx_u64(&x304, &x305, x303, x288, x260);
+ fiat_p434_addcarryx_u64(&x304, &x305, x303, x260, x288);
uint64_t x306;
uint64_t x307;
fiat_p434_mulx_u64(&x306, &x307, x290, UINT64_C(0x2341f27177344));
@@ -595,52 +595,52 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x318, &x319, x290, UINT64_C(0xffffffffffffffff));
uint64_t x320;
fiat_p434_uint1 x321;
- fiat_p434_addcarryx_u64(&x320, &x321, 0x0, x316, x319);
+ fiat_p434_addcarryx_u64(&x320, &x321, 0x0, x319, x316);
uint64_t x322;
fiat_p434_uint1 x323;
- fiat_p434_addcarryx_u64(&x322, &x323, x321, x314, x317);
+ fiat_p434_addcarryx_u64(&x322, &x323, x321, x317, x314);
uint64_t x324;
fiat_p434_uint1 x325;
- fiat_p434_addcarryx_u64(&x324, &x325, x323, x312, x315);
+ fiat_p434_addcarryx_u64(&x324, &x325, x323, x315, x312);
uint64_t x326;
fiat_p434_uint1 x327;
- fiat_p434_addcarryx_u64(&x326, &x327, x325, x310, x313);
+ fiat_p434_addcarryx_u64(&x326, &x327, x325, x313, x310);
uint64_t x328;
fiat_p434_uint1 x329;
- fiat_p434_addcarryx_u64(&x328, &x329, x327, x308, x311);
+ fiat_p434_addcarryx_u64(&x328, &x329, x327, x311, x308);
uint64_t x330;
fiat_p434_uint1 x331;
- fiat_p434_addcarryx_u64(&x330, &x331, x329, x306, x309);
+ fiat_p434_addcarryx_u64(&x330, &x331, x329, x309, x306);
uint64_t x332;
fiat_p434_uint1 x333;
- fiat_p434_addcarryx_u64(&x332, &x333, x331, 0x0, x307);
+ fiat_p434_addcarryx_u64(&x332, &x333, x331, x307, 0x0);
uint64_t x334;
fiat_p434_uint1 x335;
- fiat_p434_addcarryx_u64(&x334, &x335, 0x0, x318, x290);
+ fiat_p434_addcarryx_u64(&x334, &x335, 0x0, x290, x318);
uint64_t x336;
fiat_p434_uint1 x337;
- fiat_p434_addcarryx_u64(&x336, &x337, x335, x320, x292);
+ fiat_p434_addcarryx_u64(&x336, &x337, x335, x292, x320);
uint64_t x338;
fiat_p434_uint1 x339;
- fiat_p434_addcarryx_u64(&x338, &x339, x337, x322, x294);
+ fiat_p434_addcarryx_u64(&x338, &x339, x337, x294, x322);
uint64_t x340;
fiat_p434_uint1 x341;
- fiat_p434_addcarryx_u64(&x340, &x341, x339, x324, x296);
+ fiat_p434_addcarryx_u64(&x340, &x341, x339, x296, x324);
uint64_t x342;
fiat_p434_uint1 x343;
- fiat_p434_addcarryx_u64(&x342, &x343, x341, x326, x298);
+ fiat_p434_addcarryx_u64(&x342, &x343, x341, x298, x326);
uint64_t x344;
fiat_p434_uint1 x345;
- fiat_p434_addcarryx_u64(&x344, &x345, x343, x328, x300);
+ fiat_p434_addcarryx_u64(&x344, &x345, x343, x300, x328);
uint64_t x346;
fiat_p434_uint1 x347;
- fiat_p434_addcarryx_u64(&x346, &x347, x345, x330, x302);
+ fiat_p434_addcarryx_u64(&x346, &x347, x345, x302, x330);
uint64_t x348;
fiat_p434_uint1 x349;
- fiat_p434_addcarryx_u64(&x348, &x349, x347, x332, x304);
+ fiat_p434_addcarryx_u64(&x348, &x349, x347, x304, x332);
uint64_t x350;
fiat_p434_uint1 x351;
- fiat_p434_addcarryx_u64(&x350, &x351, x349, 0x0, x305);
+ fiat_p434_addcarryx_u64(&x350, &x351, x349, x305, 0x0);
uint64_t x352;
uint64_t x353;
fiat_p434_mulx_u64(&x352, &x353, x4, (arg2[6]));
@@ -664,49 +664,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x364, &x365, x4, (arg2[0]));
uint64_t x366;
fiat_p434_uint1 x367;
- fiat_p434_addcarryx_u64(&x366, &x367, 0x0, x362, x365);
+ fiat_p434_addcarryx_u64(&x366, &x367, 0x0, x365, x362);
uint64_t x368;
fiat_p434_uint1 x369;
- fiat_p434_addcarryx_u64(&x368, &x369, x367, x360, x363);
+ fiat_p434_addcarryx_u64(&x368, &x369, x367, x363, x360);
uint64_t x370;
fiat_p434_uint1 x371;
- fiat_p434_addcarryx_u64(&x370, &x371, x369, x358, x361);
+ fiat_p434_addcarryx_u64(&x370, &x371, x369, x361, x358);
uint64_t x372;
fiat_p434_uint1 x373;
- fiat_p434_addcarryx_u64(&x372, &x373, x371, x356, x359);
+ fiat_p434_addcarryx_u64(&x372, &x373, x371, x359, x356);
uint64_t x374;
fiat_p434_uint1 x375;
- fiat_p434_addcarryx_u64(&x374, &x375, x373, x354, x357);
+ fiat_p434_addcarryx_u64(&x374, &x375, x373, x357, x354);
uint64_t x376;
fiat_p434_uint1 x377;
- fiat_p434_addcarryx_u64(&x376, &x377, x375, x352, x355);
+ fiat_p434_addcarryx_u64(&x376, &x377, x375, x355, x352);
uint64_t x378;
fiat_p434_uint1 x379;
- fiat_p434_addcarryx_u64(&x378, &x379, x377, 0x0, x353);
+ fiat_p434_addcarryx_u64(&x378, &x379, x377, x353, 0x0);
uint64_t x380;
fiat_p434_uint1 x381;
- fiat_p434_addcarryx_u64(&x380, &x381, 0x0, x364, x336);
+ fiat_p434_addcarryx_u64(&x380, &x381, 0x0, x336, x364);
uint64_t x382;
fiat_p434_uint1 x383;
- fiat_p434_addcarryx_u64(&x382, &x383, x381, x366, x338);
+ fiat_p434_addcarryx_u64(&x382, &x383, x381, x338, x366);
uint64_t x384;
fiat_p434_uint1 x385;
- fiat_p434_addcarryx_u64(&x384, &x385, x383, x368, x340);
+ fiat_p434_addcarryx_u64(&x384, &x385, x383, x340, x368);
uint64_t x386;
fiat_p434_uint1 x387;
- fiat_p434_addcarryx_u64(&x386, &x387, x385, x370, x342);
+ fiat_p434_addcarryx_u64(&x386, &x387, x385, x342, x370);
uint64_t x388;
fiat_p434_uint1 x389;
- fiat_p434_addcarryx_u64(&x388, &x389, x387, x372, x344);
+ fiat_p434_addcarryx_u64(&x388, &x389, x387, x344, x372);
uint64_t x390;
fiat_p434_uint1 x391;
- fiat_p434_addcarryx_u64(&x390, &x391, x389, x374, x346);
+ fiat_p434_addcarryx_u64(&x390, &x391, x389, x346, x374);
uint64_t x392;
fiat_p434_uint1 x393;
- fiat_p434_addcarryx_u64(&x392, &x393, x391, x376, x348);
+ fiat_p434_addcarryx_u64(&x392, &x393, x391, x348, x376);
uint64_t x394;
fiat_p434_uint1 x395;
- fiat_p434_addcarryx_u64(&x394, &x395, x393, x378, x350);
+ fiat_p434_addcarryx_u64(&x394, &x395, x393, x350, x378);
uint64_t x396;
uint64_t x397;
fiat_p434_mulx_u64(&x396, &x397, x380, UINT64_C(0x2341f27177344));
@@ -730,52 +730,52 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x408, &x409, x380, UINT64_C(0xffffffffffffffff));
uint64_t x410;
fiat_p434_uint1 x411;
- fiat_p434_addcarryx_u64(&x410, &x411, 0x0, x406, x409);
+ fiat_p434_addcarryx_u64(&x410, &x411, 0x0, x409, x406);
uint64_t x412;
fiat_p434_uint1 x413;
- fiat_p434_addcarryx_u64(&x412, &x413, x411, x404, x407);
+ fiat_p434_addcarryx_u64(&x412, &x413, x411, x407, x404);
uint64_t x414;
fiat_p434_uint1 x415;
- fiat_p434_addcarryx_u64(&x414, &x415, x413, x402, x405);
+ fiat_p434_addcarryx_u64(&x414, &x415, x413, x405, x402);
uint64_t x416;
fiat_p434_uint1 x417;
- fiat_p434_addcarryx_u64(&x416, &x417, x415, x400, x403);
+ fiat_p434_addcarryx_u64(&x416, &x417, x415, x403, x400);
uint64_t x418;
fiat_p434_uint1 x419;
- fiat_p434_addcarryx_u64(&x418, &x419, x417, x398, x401);
+ fiat_p434_addcarryx_u64(&x418, &x419, x417, x401, x398);
uint64_t x420;
fiat_p434_uint1 x421;
- fiat_p434_addcarryx_u64(&x420, &x421, x419, x396, x399);
+ fiat_p434_addcarryx_u64(&x420, &x421, x419, x399, x396);
uint64_t x422;
fiat_p434_uint1 x423;
- fiat_p434_addcarryx_u64(&x422, &x423, x421, 0x0, x397);
+ fiat_p434_addcarryx_u64(&x422, &x423, x421, x397, 0x0);
uint64_t x424;
fiat_p434_uint1 x425;
- fiat_p434_addcarryx_u64(&x424, &x425, 0x0, x408, x380);
+ fiat_p434_addcarryx_u64(&x424, &x425, 0x0, x380, x408);
uint64_t x426;
fiat_p434_uint1 x427;
- fiat_p434_addcarryx_u64(&x426, &x427, x425, x410, x382);
+ fiat_p434_addcarryx_u64(&x426, &x427, x425, x382, x410);
uint64_t x428;
fiat_p434_uint1 x429;
- fiat_p434_addcarryx_u64(&x428, &x429, x427, x412, x384);
+ fiat_p434_addcarryx_u64(&x428, &x429, x427, x384, x412);
uint64_t x430;
fiat_p434_uint1 x431;
- fiat_p434_addcarryx_u64(&x430, &x431, x429, x414, x386);
+ fiat_p434_addcarryx_u64(&x430, &x431, x429, x386, x414);
uint64_t x432;
fiat_p434_uint1 x433;
- fiat_p434_addcarryx_u64(&x432, &x433, x431, x416, x388);
+ fiat_p434_addcarryx_u64(&x432, &x433, x431, x388, x416);
uint64_t x434;
fiat_p434_uint1 x435;
- fiat_p434_addcarryx_u64(&x434, &x435, x433, x418, x390);
+ fiat_p434_addcarryx_u64(&x434, &x435, x433, x390, x418);
uint64_t x436;
fiat_p434_uint1 x437;
- fiat_p434_addcarryx_u64(&x436, &x437, x435, x420, x392);
+ fiat_p434_addcarryx_u64(&x436, &x437, x435, x392, x420);
uint64_t x438;
fiat_p434_uint1 x439;
- fiat_p434_addcarryx_u64(&x438, &x439, x437, x422, x394);
+ fiat_p434_addcarryx_u64(&x438, &x439, x437, x394, x422);
uint64_t x440;
fiat_p434_uint1 x441;
- fiat_p434_addcarryx_u64(&x440, &x441, x439, 0x0, x395);
+ fiat_p434_addcarryx_u64(&x440, &x441, x439, x395, 0x0);
uint64_t x442;
uint64_t x443;
fiat_p434_mulx_u64(&x442, &x443, x5, (arg2[6]));
@@ -799,49 +799,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x454, &x455, x5, (arg2[0]));
uint64_t x456;
fiat_p434_uint1 x457;
- fiat_p434_addcarryx_u64(&x456, &x457, 0x0, x452, x455);
+ fiat_p434_addcarryx_u64(&x456, &x457, 0x0, x455, x452);
uint64_t x458;
fiat_p434_uint1 x459;
- fiat_p434_addcarryx_u64(&x458, &x459, x457, x450, x453);
+ fiat_p434_addcarryx_u64(&x458, &x459, x457, x453, x450);
uint64_t x460;
fiat_p434_uint1 x461;
- fiat_p434_addcarryx_u64(&x460, &x461, x459, x448, x451);
+ fiat_p434_addcarryx_u64(&x460, &x461, x459, x451, x448);
uint64_t x462;
fiat_p434_uint1 x463;
- fiat_p434_addcarryx_u64(&x462, &x463, x461, x446, x449);
+ fiat_p434_addcarryx_u64(&x462, &x463, x461, x449, x446);
uint64_t x464;
fiat_p434_uint1 x465;
- fiat_p434_addcarryx_u64(&x464, &x465, x463, x444, x447);
+ fiat_p434_addcarryx_u64(&x464, &x465, x463, x447, x444);
uint64_t x466;
fiat_p434_uint1 x467;
- fiat_p434_addcarryx_u64(&x466, &x467, x465, x442, x445);
+ fiat_p434_addcarryx_u64(&x466, &x467, x465, x445, x442);
uint64_t x468;
fiat_p434_uint1 x469;
- fiat_p434_addcarryx_u64(&x468, &x469, x467, 0x0, x443);
+ fiat_p434_addcarryx_u64(&x468, &x469, x467, x443, 0x0);
uint64_t x470;
fiat_p434_uint1 x471;
- fiat_p434_addcarryx_u64(&x470, &x471, 0x0, x454, x426);
+ fiat_p434_addcarryx_u64(&x470, &x471, 0x0, x426, x454);
uint64_t x472;
fiat_p434_uint1 x473;
- fiat_p434_addcarryx_u64(&x472, &x473, x471, x456, x428);
+ fiat_p434_addcarryx_u64(&x472, &x473, x471, x428, x456);
uint64_t x474;
fiat_p434_uint1 x475;
- fiat_p434_addcarryx_u64(&x474, &x475, x473, x458, x430);
+ fiat_p434_addcarryx_u64(&x474, &x475, x473, x430, x458);
uint64_t x476;
fiat_p434_uint1 x477;
- fiat_p434_addcarryx_u64(&x476, &x477, x475, x460, x432);
+ fiat_p434_addcarryx_u64(&x476, &x477, x475, x432, x460);
uint64_t x478;
fiat_p434_uint1 x479;
- fiat_p434_addcarryx_u64(&x478, &x479, x477, x462, x434);
+ fiat_p434_addcarryx_u64(&x478, &x479, x477, x434, x462);
uint64_t x480;
fiat_p434_uint1 x481;
- fiat_p434_addcarryx_u64(&x480, &x481, x479, x464, x436);
+ fiat_p434_addcarryx_u64(&x480, &x481, x479, x436, x464);
uint64_t x482;
fiat_p434_uint1 x483;
- fiat_p434_addcarryx_u64(&x482, &x483, x481, x466, x438);
+ fiat_p434_addcarryx_u64(&x482, &x483, x481, x438, x466);
uint64_t x484;
fiat_p434_uint1 x485;
- fiat_p434_addcarryx_u64(&x484, &x485, x483, x468, x440);
+ fiat_p434_addcarryx_u64(&x484, &x485, x483, x440, x468);
uint64_t x486;
uint64_t x487;
fiat_p434_mulx_u64(&x486, &x487, x470, UINT64_C(0x2341f27177344));
@@ -865,52 +865,52 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x498, &x499, x470, UINT64_C(0xffffffffffffffff));
uint64_t x500;
fiat_p434_uint1 x501;
- fiat_p434_addcarryx_u64(&x500, &x501, 0x0, x496, x499);
+ fiat_p434_addcarryx_u64(&x500, &x501, 0x0, x499, x496);
uint64_t x502;
fiat_p434_uint1 x503;
- fiat_p434_addcarryx_u64(&x502, &x503, x501, x494, x497);
+ fiat_p434_addcarryx_u64(&x502, &x503, x501, x497, x494);
uint64_t x504;
fiat_p434_uint1 x505;
- fiat_p434_addcarryx_u64(&x504, &x505, x503, x492, x495);
+ fiat_p434_addcarryx_u64(&x504, &x505, x503, x495, x492);
uint64_t x506;
fiat_p434_uint1 x507;
- fiat_p434_addcarryx_u64(&x506, &x507, x505, x490, x493);
+ fiat_p434_addcarryx_u64(&x506, &x507, x505, x493, x490);
uint64_t x508;
fiat_p434_uint1 x509;
- fiat_p434_addcarryx_u64(&x508, &x509, x507, x488, x491);
+ fiat_p434_addcarryx_u64(&x508, &x509, x507, x491, x488);
uint64_t x510;
fiat_p434_uint1 x511;
- fiat_p434_addcarryx_u64(&x510, &x511, x509, x486, x489);
+ fiat_p434_addcarryx_u64(&x510, &x511, x509, x489, x486);
uint64_t x512;
fiat_p434_uint1 x513;
- fiat_p434_addcarryx_u64(&x512, &x513, x511, 0x0, x487);
+ fiat_p434_addcarryx_u64(&x512, &x513, x511, x487, 0x0);
uint64_t x514;
fiat_p434_uint1 x515;
- fiat_p434_addcarryx_u64(&x514, &x515, 0x0, x498, x470);
+ fiat_p434_addcarryx_u64(&x514, &x515, 0x0, x470, x498);
uint64_t x516;
fiat_p434_uint1 x517;
- fiat_p434_addcarryx_u64(&x516, &x517, x515, x500, x472);
+ fiat_p434_addcarryx_u64(&x516, &x517, x515, x472, x500);
uint64_t x518;
fiat_p434_uint1 x519;
- fiat_p434_addcarryx_u64(&x518, &x519, x517, x502, x474);
+ fiat_p434_addcarryx_u64(&x518, &x519, x517, x474, x502);
uint64_t x520;
fiat_p434_uint1 x521;
- fiat_p434_addcarryx_u64(&x520, &x521, x519, x504, x476);
+ fiat_p434_addcarryx_u64(&x520, &x521, x519, x476, x504);
uint64_t x522;
fiat_p434_uint1 x523;
- fiat_p434_addcarryx_u64(&x522, &x523, x521, x506, x478);
+ fiat_p434_addcarryx_u64(&x522, &x523, x521, x478, x506);
uint64_t x524;
fiat_p434_uint1 x525;
- fiat_p434_addcarryx_u64(&x524, &x525, x523, x508, x480);
+ fiat_p434_addcarryx_u64(&x524, &x525, x523, x480, x508);
uint64_t x526;
fiat_p434_uint1 x527;
- fiat_p434_addcarryx_u64(&x526, &x527, x525, x510, x482);
+ fiat_p434_addcarryx_u64(&x526, &x527, x525, x482, x510);
uint64_t x528;
fiat_p434_uint1 x529;
- fiat_p434_addcarryx_u64(&x528, &x529, x527, x512, x484);
+ fiat_p434_addcarryx_u64(&x528, &x529, x527, x484, x512);
uint64_t x530;
fiat_p434_uint1 x531;
- fiat_p434_addcarryx_u64(&x530, &x531, x529, 0x0, x485);
+ fiat_p434_addcarryx_u64(&x530, &x531, x529, x485, 0x0);
uint64_t x532;
uint64_t x533;
fiat_p434_mulx_u64(&x532, &x533, x6, (arg2[6]));
@@ -934,49 +934,49 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x544, &x545, x6, (arg2[0]));
uint64_t x546;
fiat_p434_uint1 x547;
- fiat_p434_addcarryx_u64(&x546, &x547, 0x0, x542, x545);
+ fiat_p434_addcarryx_u64(&x546, &x547, 0x0, x545, x542);
uint64_t x548;
fiat_p434_uint1 x549;
- fiat_p434_addcarryx_u64(&x548, &x549, x547, x540, x543);
+ fiat_p434_addcarryx_u64(&x548, &x549, x547, x543, x540);
uint64_t x550;
fiat_p434_uint1 x551;
- fiat_p434_addcarryx_u64(&x550, &x551, x549, x538, x541);
+ fiat_p434_addcarryx_u64(&x550, &x551, x549, x541, x538);
uint64_t x552;
fiat_p434_uint1 x553;
- fiat_p434_addcarryx_u64(&x552, &x553, x551, x536, x539);
+ fiat_p434_addcarryx_u64(&x552, &x553, x551, x539, x536);
uint64_t x554;
fiat_p434_uint1 x555;
- fiat_p434_addcarryx_u64(&x554, &x555, x553, x534, x537);
+ fiat_p434_addcarryx_u64(&x554, &x555, x553, x537, x534);
uint64_t x556;
fiat_p434_uint1 x557;
- fiat_p434_addcarryx_u64(&x556, &x557, x555, x532, x535);
+ fiat_p434_addcarryx_u64(&x556, &x557, x555, x535, x532);
uint64_t x558;
fiat_p434_uint1 x559;
- fiat_p434_addcarryx_u64(&x558, &x559, x557, 0x0, x533);
+ fiat_p434_addcarryx_u64(&x558, &x559, x557, x533, 0x0);
uint64_t x560;
fiat_p434_uint1 x561;
- fiat_p434_addcarryx_u64(&x560, &x561, 0x0, x544, x516);
+ fiat_p434_addcarryx_u64(&x560, &x561, 0x0, x516, x544);
uint64_t x562;
fiat_p434_uint1 x563;
- fiat_p434_addcarryx_u64(&x562, &x563, x561, x546, x518);
+ fiat_p434_addcarryx_u64(&x562, &x563, x561, x518, x546);
uint64_t x564;
fiat_p434_uint1 x565;
- fiat_p434_addcarryx_u64(&x564, &x565, x563, x548, x520);
+ fiat_p434_addcarryx_u64(&x564, &x565, x563, x520, x548);
uint64_t x566;
fiat_p434_uint1 x567;
- fiat_p434_addcarryx_u64(&x566, &x567, x565, x550, x522);
+ fiat_p434_addcarryx_u64(&x566, &x567, x565, x522, x550);
uint64_t x568;
fiat_p434_uint1 x569;
- fiat_p434_addcarryx_u64(&x568, &x569, x567, x552, x524);
+ fiat_p434_addcarryx_u64(&x568, &x569, x567, x524, x552);
uint64_t x570;
fiat_p434_uint1 x571;
- fiat_p434_addcarryx_u64(&x570, &x571, x569, x554, x526);
+ fiat_p434_addcarryx_u64(&x570, &x571, x569, x526, x554);
uint64_t x572;
fiat_p434_uint1 x573;
- fiat_p434_addcarryx_u64(&x572, &x573, x571, x556, x528);
+ fiat_p434_addcarryx_u64(&x572, &x573, x571, x528, x556);
uint64_t x574;
fiat_p434_uint1 x575;
- fiat_p434_addcarryx_u64(&x574, &x575, x573, x558, x530);
+ fiat_p434_addcarryx_u64(&x574, &x575, x573, x530, x558);
uint64_t x576;
uint64_t x577;
fiat_p434_mulx_u64(&x576, &x577, x560, UINT64_C(0x2341f27177344));
@@ -1000,52 +1000,52 @@ static void fiat_p434_mul(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_mulx_u64(&x588, &x589, x560, UINT64_C(0xffffffffffffffff));
uint64_t x590;
fiat_p434_uint1 x591;
- fiat_p434_addcarryx_u64(&x590, &x591, 0x0, x586, x589);
+ fiat_p434_addcarryx_u64(&x590, &x591, 0x0, x589, x586);
uint64_t x592;
fiat_p434_uint1 x593;
- fiat_p434_addcarryx_u64(&x592, &x593, x591, x584, x587);
+ fiat_p434_addcarryx_u64(&x592, &x593, x591, x587, x584);
uint64_t x594;
fiat_p434_uint1 x595;
- fiat_p434_addcarryx_u64(&x594, &x595, x593, x582, x585);
+ fiat_p434_addcarryx_u64(&x594, &x595, x593, x585, x582);
uint64_t x596;
fiat_p434_uint1 x597;
- fiat_p434_addcarryx_u64(&x596, &x597, x595, x580, x583);
+ fiat_p434_addcarryx_u64(&x596, &x597, x595, x583, x580);
uint64_t x598;
fiat_p434_uint1 x599;
- fiat_p434_addcarryx_u64(&x598, &x599, x597, x578, x581);
+ fiat_p434_addcarryx_u64(&x598, &x599, x597, x581, x578);
uint64_t x600;
fiat_p434_uint1 x601;
- fiat_p434_addcarryx_u64(&x600, &x601, x599, x576, x579);
+ fiat_p434_addcarryx_u64(&x600, &x601, x599, x579, x576);
uint64_t x602;
fiat_p434_uint1 x603;
- fiat_p434_addcarryx_u64(&x602, &x603, x601, 0x0, x577);
+ fiat_p434_addcarryx_u64(&x602, &x603, x601, x577, 0x0);
uint64_t x604;
fiat_p434_uint1 x605;
- fiat_p434_addcarryx_u64(&x604, &x605, 0x0, x588, x560);
+ fiat_p434_addcarryx_u64(&x604, &x605, 0x0, x560, x588);
uint64_t x606;
fiat_p434_uint1 x607;
- fiat_p434_addcarryx_u64(&x606, &x607, x605, x590, x562);
+ fiat_p434_addcarryx_u64(&x606, &x607, x605, x562, x590);
uint64_t x608;
fiat_p434_uint1 x609;
- fiat_p434_addcarryx_u64(&x608, &x609, x607, x592, x564);
+ fiat_p434_addcarryx_u64(&x608, &x609, x607, x564, x592);
uint64_t x610;
fiat_p434_uint1 x611;
- fiat_p434_addcarryx_u64(&x610, &x611, x609, x594, x566);
+ fiat_p434_addcarryx_u64(&x610, &x611, x609, x566, x594);
uint64_t x612;
fiat_p434_uint1 x613;
- fiat_p434_addcarryx_u64(&x612, &x613, x611, x596, x568);
+ fiat_p434_addcarryx_u64(&x612, &x613, x611, x568, x596);
uint64_t x614;
fiat_p434_uint1 x615;
- fiat_p434_addcarryx_u64(&x614, &x615, x613, x598, x570);
+ fiat_p434_addcarryx_u64(&x614, &x615, x613, x570, x598);
uint64_t x616;
fiat_p434_uint1 x617;
- fiat_p434_addcarryx_u64(&x616, &x617, x615, x600, x572);
+ fiat_p434_addcarryx_u64(&x616, &x617, x615, x572, x600);
uint64_t x618;
fiat_p434_uint1 x619;
- fiat_p434_addcarryx_u64(&x618, &x619, x617, x602, x574);
+ fiat_p434_addcarryx_u64(&x618, &x619, x617, x574, x602);
uint64_t x620;
fiat_p434_uint1 x621;
- fiat_p434_addcarryx_u64(&x620, &x621, x619, 0x0, x575);
+ fiat_p434_addcarryx_u64(&x620, &x621, x619, x575, 0x0);
uint64_t x622;
fiat_p434_uint1 x623;
fiat_p434_subborrowx_u64(&x622, &x623, 0x0, x606, UINT64_C(0xffffffffffffffff));
@@ -1137,25 +1137,25 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x20, &x21, x7, (arg1[0]));
uint64_t x22;
fiat_p434_uint1 x23;
- fiat_p434_addcarryx_u64(&x22, &x23, 0x0, x18, x21);
+ fiat_p434_addcarryx_u64(&x22, &x23, 0x0, x21, x18);
uint64_t x24;
fiat_p434_uint1 x25;
- fiat_p434_addcarryx_u64(&x24, &x25, x23, x16, x19);
+ fiat_p434_addcarryx_u64(&x24, &x25, x23, x19, x16);
uint64_t x26;
fiat_p434_uint1 x27;
- fiat_p434_addcarryx_u64(&x26, &x27, x25, x14, x17);
+ fiat_p434_addcarryx_u64(&x26, &x27, x25, x17, x14);
uint64_t x28;
fiat_p434_uint1 x29;
- fiat_p434_addcarryx_u64(&x28, &x29, x27, x12, x15);
+ fiat_p434_addcarryx_u64(&x28, &x29, x27, x15, x12);
uint64_t x30;
fiat_p434_uint1 x31;
- fiat_p434_addcarryx_u64(&x30, &x31, x29, x10, x13);
+ fiat_p434_addcarryx_u64(&x30, &x31, x29, x13, x10);
uint64_t x32;
fiat_p434_uint1 x33;
- fiat_p434_addcarryx_u64(&x32, &x33, x31, x8, x11);
+ fiat_p434_addcarryx_u64(&x32, &x33, x31, x11, x8);
uint64_t x34;
fiat_p434_uint1 x35;
- fiat_p434_addcarryx_u64(&x34, &x35, x33, 0x0, x9);
+ fiat_p434_addcarryx_u64(&x34, &x35, x33, x9, 0x0);
uint64_t x36;
uint64_t x37;
fiat_p434_mulx_u64(&x36, &x37, x20, UINT64_C(0x2341f27177344));
@@ -1179,49 +1179,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x48, &x49, x20, UINT64_C(0xffffffffffffffff));
uint64_t x50;
fiat_p434_uint1 x51;
- fiat_p434_addcarryx_u64(&x50, &x51, 0x0, x46, x49);
+ fiat_p434_addcarryx_u64(&x50, &x51, 0x0, x49, x46);
uint64_t x52;
fiat_p434_uint1 x53;
- fiat_p434_addcarryx_u64(&x52, &x53, x51, x44, x47);
+ fiat_p434_addcarryx_u64(&x52, &x53, x51, x47, x44);
uint64_t x54;
fiat_p434_uint1 x55;
- fiat_p434_addcarryx_u64(&x54, &x55, x53, x42, x45);
+ fiat_p434_addcarryx_u64(&x54, &x55, x53, x45, x42);
uint64_t x56;
fiat_p434_uint1 x57;
- fiat_p434_addcarryx_u64(&x56, &x57, x55, x40, x43);
+ fiat_p434_addcarryx_u64(&x56, &x57, x55, x43, x40);
uint64_t x58;
fiat_p434_uint1 x59;
- fiat_p434_addcarryx_u64(&x58, &x59, x57, x38, x41);
+ fiat_p434_addcarryx_u64(&x58, &x59, x57, x41, x38);
uint64_t x60;
fiat_p434_uint1 x61;
- fiat_p434_addcarryx_u64(&x60, &x61, x59, x36, x39);
+ fiat_p434_addcarryx_u64(&x60, &x61, x59, x39, x36);
uint64_t x62;
fiat_p434_uint1 x63;
- fiat_p434_addcarryx_u64(&x62, &x63, x61, 0x0, x37);
+ fiat_p434_addcarryx_u64(&x62, &x63, x61, x37, 0x0);
uint64_t x64;
fiat_p434_uint1 x65;
- fiat_p434_addcarryx_u64(&x64, &x65, 0x0, x48, x20);
+ fiat_p434_addcarryx_u64(&x64, &x65, 0x0, x20, x48);
uint64_t x66;
fiat_p434_uint1 x67;
- fiat_p434_addcarryx_u64(&x66, &x67, x65, x50, x22);
+ fiat_p434_addcarryx_u64(&x66, &x67, x65, x22, x50);
uint64_t x68;
fiat_p434_uint1 x69;
- fiat_p434_addcarryx_u64(&x68, &x69, x67, x52, x24);
+ fiat_p434_addcarryx_u64(&x68, &x69, x67, x24, x52);
uint64_t x70;
fiat_p434_uint1 x71;
- fiat_p434_addcarryx_u64(&x70, &x71, x69, x54, x26);
+ fiat_p434_addcarryx_u64(&x70, &x71, x69, x26, x54);
uint64_t x72;
fiat_p434_uint1 x73;
- fiat_p434_addcarryx_u64(&x72, &x73, x71, x56, x28);
+ fiat_p434_addcarryx_u64(&x72, &x73, x71, x28, x56);
uint64_t x74;
fiat_p434_uint1 x75;
- fiat_p434_addcarryx_u64(&x74, &x75, x73, x58, x30);
+ fiat_p434_addcarryx_u64(&x74, &x75, x73, x30, x58);
uint64_t x76;
fiat_p434_uint1 x77;
- fiat_p434_addcarryx_u64(&x76, &x77, x75, x60, x32);
+ fiat_p434_addcarryx_u64(&x76, &x77, x75, x32, x60);
uint64_t x78;
fiat_p434_uint1 x79;
- fiat_p434_addcarryx_u64(&x78, &x79, x77, x62, x34);
+ fiat_p434_addcarryx_u64(&x78, &x79, x77, x34, x62);
uint64_t x80;
fiat_p434_uint1 x81;
fiat_p434_addcarryx_u64(&x80, &x81, x79, 0x0, 0x0);
@@ -1248,49 +1248,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x94, &x95, x1, (arg1[0]));
uint64_t x96;
fiat_p434_uint1 x97;
- fiat_p434_addcarryx_u64(&x96, &x97, 0x0, x92, x95);
+ fiat_p434_addcarryx_u64(&x96, &x97, 0x0, x95, x92);
uint64_t x98;
fiat_p434_uint1 x99;
- fiat_p434_addcarryx_u64(&x98, &x99, x97, x90, x93);
+ fiat_p434_addcarryx_u64(&x98, &x99, x97, x93, x90);
uint64_t x100;
fiat_p434_uint1 x101;
- fiat_p434_addcarryx_u64(&x100, &x101, x99, x88, x91);
+ fiat_p434_addcarryx_u64(&x100, &x101, x99, x91, x88);
uint64_t x102;
fiat_p434_uint1 x103;
- fiat_p434_addcarryx_u64(&x102, &x103, x101, x86, x89);
+ fiat_p434_addcarryx_u64(&x102, &x103, x101, x89, x86);
uint64_t x104;
fiat_p434_uint1 x105;
- fiat_p434_addcarryx_u64(&x104, &x105, x103, x84, x87);
+ fiat_p434_addcarryx_u64(&x104, &x105, x103, x87, x84);
uint64_t x106;
fiat_p434_uint1 x107;
- fiat_p434_addcarryx_u64(&x106, &x107, x105, x82, x85);
+ fiat_p434_addcarryx_u64(&x106, &x107, x105, x85, x82);
uint64_t x108;
fiat_p434_uint1 x109;
- fiat_p434_addcarryx_u64(&x108, &x109, x107, 0x0, x83);
+ fiat_p434_addcarryx_u64(&x108, &x109, x107, x83, 0x0);
uint64_t x110;
fiat_p434_uint1 x111;
- fiat_p434_addcarryx_u64(&x110, &x111, 0x0, x94, x66);
+ fiat_p434_addcarryx_u64(&x110, &x111, 0x0, x66, x94);
uint64_t x112;
fiat_p434_uint1 x113;
- fiat_p434_addcarryx_u64(&x112, &x113, x111, x96, x68);
+ fiat_p434_addcarryx_u64(&x112, &x113, x111, x68, x96);
uint64_t x114;
fiat_p434_uint1 x115;
- fiat_p434_addcarryx_u64(&x114, &x115, x113, x98, x70);
+ fiat_p434_addcarryx_u64(&x114, &x115, x113, x70, x98);
uint64_t x116;
fiat_p434_uint1 x117;
- fiat_p434_addcarryx_u64(&x116, &x117, x115, x100, x72);
+ fiat_p434_addcarryx_u64(&x116, &x117, x115, x72, x100);
uint64_t x118;
fiat_p434_uint1 x119;
- fiat_p434_addcarryx_u64(&x118, &x119, x117, x102, x74);
+ fiat_p434_addcarryx_u64(&x118, &x119, x117, x74, x102);
uint64_t x120;
fiat_p434_uint1 x121;
- fiat_p434_addcarryx_u64(&x120, &x121, x119, x104, x76);
+ fiat_p434_addcarryx_u64(&x120, &x121, x119, x76, x104);
uint64_t x122;
fiat_p434_uint1 x123;
- fiat_p434_addcarryx_u64(&x122, &x123, x121, x106, x78);
+ fiat_p434_addcarryx_u64(&x122, &x123, x121, x78, x106);
uint64_t x124;
fiat_p434_uint1 x125;
- fiat_p434_addcarryx_u64(&x124, &x125, x123, x108, (fiat_p434_uint1)x80);
+ fiat_p434_addcarryx_u64(&x124, &x125, x123, (fiat_p434_uint1)x80, x108);
uint64_t x126;
uint64_t x127;
fiat_p434_mulx_u64(&x126, &x127, x110, UINT64_C(0x2341f27177344));
@@ -1314,52 +1314,52 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x138, &x139, x110, UINT64_C(0xffffffffffffffff));
uint64_t x140;
fiat_p434_uint1 x141;
- fiat_p434_addcarryx_u64(&x140, &x141, 0x0, x136, x139);
+ fiat_p434_addcarryx_u64(&x140, &x141, 0x0, x139, x136);
uint64_t x142;
fiat_p434_uint1 x143;
- fiat_p434_addcarryx_u64(&x142, &x143, x141, x134, x137);
+ fiat_p434_addcarryx_u64(&x142, &x143, x141, x137, x134);
uint64_t x144;
fiat_p434_uint1 x145;
- fiat_p434_addcarryx_u64(&x144, &x145, x143, x132, x135);
+ fiat_p434_addcarryx_u64(&x144, &x145, x143, x135, x132);
uint64_t x146;
fiat_p434_uint1 x147;
- fiat_p434_addcarryx_u64(&x146, &x147, x145, x130, x133);
+ fiat_p434_addcarryx_u64(&x146, &x147, x145, x133, x130);
uint64_t x148;
fiat_p434_uint1 x149;
- fiat_p434_addcarryx_u64(&x148, &x149, x147, x128, x131);
+ fiat_p434_addcarryx_u64(&x148, &x149, x147, x131, x128);
uint64_t x150;
fiat_p434_uint1 x151;
- fiat_p434_addcarryx_u64(&x150, &x151, x149, x126, x129);
+ fiat_p434_addcarryx_u64(&x150, &x151, x149, x129, x126);
uint64_t x152;
fiat_p434_uint1 x153;
- fiat_p434_addcarryx_u64(&x152, &x153, x151, 0x0, x127);
+ fiat_p434_addcarryx_u64(&x152, &x153, x151, x127, 0x0);
uint64_t x154;
fiat_p434_uint1 x155;
- fiat_p434_addcarryx_u64(&x154, &x155, 0x0, x138, x110);
+ fiat_p434_addcarryx_u64(&x154, &x155, 0x0, x110, x138);
uint64_t x156;
fiat_p434_uint1 x157;
- fiat_p434_addcarryx_u64(&x156, &x157, x155, x140, x112);
+ fiat_p434_addcarryx_u64(&x156, &x157, x155, x112, x140);
uint64_t x158;
fiat_p434_uint1 x159;
- fiat_p434_addcarryx_u64(&x158, &x159, x157, x142, x114);
+ fiat_p434_addcarryx_u64(&x158, &x159, x157, x114, x142);
uint64_t x160;
fiat_p434_uint1 x161;
- fiat_p434_addcarryx_u64(&x160, &x161, x159, x144, x116);
+ fiat_p434_addcarryx_u64(&x160, &x161, x159, x116, x144);
uint64_t x162;
fiat_p434_uint1 x163;
- fiat_p434_addcarryx_u64(&x162, &x163, x161, x146, x118);
+ fiat_p434_addcarryx_u64(&x162, &x163, x161, x118, x146);
uint64_t x164;
fiat_p434_uint1 x165;
- fiat_p434_addcarryx_u64(&x164, &x165, x163, x148, x120);
+ fiat_p434_addcarryx_u64(&x164, &x165, x163, x120, x148);
uint64_t x166;
fiat_p434_uint1 x167;
- fiat_p434_addcarryx_u64(&x166, &x167, x165, x150, x122);
+ fiat_p434_addcarryx_u64(&x166, &x167, x165, x122, x150);
uint64_t x168;
fiat_p434_uint1 x169;
- fiat_p434_addcarryx_u64(&x168, &x169, x167, x152, x124);
+ fiat_p434_addcarryx_u64(&x168, &x169, x167, x124, x152);
uint64_t x170;
fiat_p434_uint1 x171;
- fiat_p434_addcarryx_u64(&x170, &x171, x169, 0x0, x125);
+ fiat_p434_addcarryx_u64(&x170, &x171, x169, x125, 0x0);
uint64_t x172;
uint64_t x173;
fiat_p434_mulx_u64(&x172, &x173, x2, (arg1[6]));
@@ -1383,49 +1383,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x184, &x185, x2, (arg1[0]));
uint64_t x186;
fiat_p434_uint1 x187;
- fiat_p434_addcarryx_u64(&x186, &x187, 0x0, x182, x185);
+ fiat_p434_addcarryx_u64(&x186, &x187, 0x0, x185, x182);
uint64_t x188;
fiat_p434_uint1 x189;
- fiat_p434_addcarryx_u64(&x188, &x189, x187, x180, x183);
+ fiat_p434_addcarryx_u64(&x188, &x189, x187, x183, x180);
uint64_t x190;
fiat_p434_uint1 x191;
- fiat_p434_addcarryx_u64(&x190, &x191, x189, x178, x181);
+ fiat_p434_addcarryx_u64(&x190, &x191, x189, x181, x178);
uint64_t x192;
fiat_p434_uint1 x193;
- fiat_p434_addcarryx_u64(&x192, &x193, x191, x176, x179);
+ fiat_p434_addcarryx_u64(&x192, &x193, x191, x179, x176);
uint64_t x194;
fiat_p434_uint1 x195;
- fiat_p434_addcarryx_u64(&x194, &x195, x193, x174, x177);
+ fiat_p434_addcarryx_u64(&x194, &x195, x193, x177, x174);
uint64_t x196;
fiat_p434_uint1 x197;
- fiat_p434_addcarryx_u64(&x196, &x197, x195, x172, x175);
+ fiat_p434_addcarryx_u64(&x196, &x197, x195, x175, x172);
uint64_t x198;
fiat_p434_uint1 x199;
- fiat_p434_addcarryx_u64(&x198, &x199, x197, 0x0, x173);
+ fiat_p434_addcarryx_u64(&x198, &x199, x197, x173, 0x0);
uint64_t x200;
fiat_p434_uint1 x201;
- fiat_p434_addcarryx_u64(&x200, &x201, 0x0, x184, x156);
+ fiat_p434_addcarryx_u64(&x200, &x201, 0x0, x156, x184);
uint64_t x202;
fiat_p434_uint1 x203;
- fiat_p434_addcarryx_u64(&x202, &x203, x201, x186, x158);
+ fiat_p434_addcarryx_u64(&x202, &x203, x201, x158, x186);
uint64_t x204;
fiat_p434_uint1 x205;
- fiat_p434_addcarryx_u64(&x204, &x205, x203, x188, x160);
+ fiat_p434_addcarryx_u64(&x204, &x205, x203, x160, x188);
uint64_t x206;
fiat_p434_uint1 x207;
- fiat_p434_addcarryx_u64(&x206, &x207, x205, x190, x162);
+ fiat_p434_addcarryx_u64(&x206, &x207, x205, x162, x190);
uint64_t x208;
fiat_p434_uint1 x209;
- fiat_p434_addcarryx_u64(&x208, &x209, x207, x192, x164);
+ fiat_p434_addcarryx_u64(&x208, &x209, x207, x164, x192);
uint64_t x210;
fiat_p434_uint1 x211;
- fiat_p434_addcarryx_u64(&x210, &x211, x209, x194, x166);
+ fiat_p434_addcarryx_u64(&x210, &x211, x209, x166, x194);
uint64_t x212;
fiat_p434_uint1 x213;
- fiat_p434_addcarryx_u64(&x212, &x213, x211, x196, x168);
+ fiat_p434_addcarryx_u64(&x212, &x213, x211, x168, x196);
uint64_t x214;
fiat_p434_uint1 x215;
- fiat_p434_addcarryx_u64(&x214, &x215, x213, x198, x170);
+ fiat_p434_addcarryx_u64(&x214, &x215, x213, x170, x198);
uint64_t x216;
uint64_t x217;
fiat_p434_mulx_u64(&x216, &x217, x200, UINT64_C(0x2341f27177344));
@@ -1449,52 +1449,52 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x228, &x229, x200, UINT64_C(0xffffffffffffffff));
uint64_t x230;
fiat_p434_uint1 x231;
- fiat_p434_addcarryx_u64(&x230, &x231, 0x0, x226, x229);
+ fiat_p434_addcarryx_u64(&x230, &x231, 0x0, x229, x226);
uint64_t x232;
fiat_p434_uint1 x233;
- fiat_p434_addcarryx_u64(&x232, &x233, x231, x224, x227);
+ fiat_p434_addcarryx_u64(&x232, &x233, x231, x227, x224);
uint64_t x234;
fiat_p434_uint1 x235;
- fiat_p434_addcarryx_u64(&x234, &x235, x233, x222, x225);
+ fiat_p434_addcarryx_u64(&x234, &x235, x233, x225, x222);
uint64_t x236;
fiat_p434_uint1 x237;
- fiat_p434_addcarryx_u64(&x236, &x237, x235, x220, x223);
+ fiat_p434_addcarryx_u64(&x236, &x237, x235, x223, x220);
uint64_t x238;
fiat_p434_uint1 x239;
- fiat_p434_addcarryx_u64(&x238, &x239, x237, x218, x221);
+ fiat_p434_addcarryx_u64(&x238, &x239, x237, x221, x218);
uint64_t x240;
fiat_p434_uint1 x241;
- fiat_p434_addcarryx_u64(&x240, &x241, x239, x216, x219);
+ fiat_p434_addcarryx_u64(&x240, &x241, x239, x219, x216);
uint64_t x242;
fiat_p434_uint1 x243;
- fiat_p434_addcarryx_u64(&x242, &x243, x241, 0x0, x217);
+ fiat_p434_addcarryx_u64(&x242, &x243, x241, x217, 0x0);
uint64_t x244;
fiat_p434_uint1 x245;
- fiat_p434_addcarryx_u64(&x244, &x245, 0x0, x228, x200);
+ fiat_p434_addcarryx_u64(&x244, &x245, 0x0, x200, x228);
uint64_t x246;
fiat_p434_uint1 x247;
- fiat_p434_addcarryx_u64(&x246, &x247, x245, x230, x202);
+ fiat_p434_addcarryx_u64(&x246, &x247, x245, x202, x230);
uint64_t x248;
fiat_p434_uint1 x249;
- fiat_p434_addcarryx_u64(&x248, &x249, x247, x232, x204);
+ fiat_p434_addcarryx_u64(&x248, &x249, x247, x204, x232);
uint64_t x250;
fiat_p434_uint1 x251;
- fiat_p434_addcarryx_u64(&x250, &x251, x249, x234, x206);
+ fiat_p434_addcarryx_u64(&x250, &x251, x249, x206, x234);
uint64_t x252;
fiat_p434_uint1 x253;
- fiat_p434_addcarryx_u64(&x252, &x253, x251, x236, x208);
+ fiat_p434_addcarryx_u64(&x252, &x253, x251, x208, x236);
uint64_t x254;
fiat_p434_uint1 x255;
- fiat_p434_addcarryx_u64(&x254, &x255, x253, x238, x210);
+ fiat_p434_addcarryx_u64(&x254, &x255, x253, x210, x238);
uint64_t x256;
fiat_p434_uint1 x257;
- fiat_p434_addcarryx_u64(&x256, &x257, x255, x240, x212);
+ fiat_p434_addcarryx_u64(&x256, &x257, x255, x212, x240);
uint64_t x258;
fiat_p434_uint1 x259;
- fiat_p434_addcarryx_u64(&x258, &x259, x257, x242, x214);
+ fiat_p434_addcarryx_u64(&x258, &x259, x257, x214, x242);
uint64_t x260;
fiat_p434_uint1 x261;
- fiat_p434_addcarryx_u64(&x260, &x261, x259, 0x0, x215);
+ fiat_p434_addcarryx_u64(&x260, &x261, x259, x215, 0x0);
uint64_t x262;
uint64_t x263;
fiat_p434_mulx_u64(&x262, &x263, x3, (arg1[6]));
@@ -1518,49 +1518,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x274, &x275, x3, (arg1[0]));
uint64_t x276;
fiat_p434_uint1 x277;
- fiat_p434_addcarryx_u64(&x276, &x277, 0x0, x272, x275);
+ fiat_p434_addcarryx_u64(&x276, &x277, 0x0, x275, x272);
uint64_t x278;
fiat_p434_uint1 x279;
- fiat_p434_addcarryx_u64(&x278, &x279, x277, x270, x273);
+ fiat_p434_addcarryx_u64(&x278, &x279, x277, x273, x270);
uint64_t x280;
fiat_p434_uint1 x281;
- fiat_p434_addcarryx_u64(&x280, &x281, x279, x268, x271);
+ fiat_p434_addcarryx_u64(&x280, &x281, x279, x271, x268);
uint64_t x282;
fiat_p434_uint1 x283;
- fiat_p434_addcarryx_u64(&x282, &x283, x281, x266, x269);
+ fiat_p434_addcarryx_u64(&x282, &x283, x281, x269, x266);
uint64_t x284;
fiat_p434_uint1 x285;
- fiat_p434_addcarryx_u64(&x284, &x285, x283, x264, x267);
+ fiat_p434_addcarryx_u64(&x284, &x285, x283, x267, x264);
uint64_t x286;
fiat_p434_uint1 x287;
- fiat_p434_addcarryx_u64(&x286, &x287, x285, x262, x265);
+ fiat_p434_addcarryx_u64(&x286, &x287, x285, x265, x262);
uint64_t x288;
fiat_p434_uint1 x289;
- fiat_p434_addcarryx_u64(&x288, &x289, x287, 0x0, x263);
+ fiat_p434_addcarryx_u64(&x288, &x289, x287, x263, 0x0);
uint64_t x290;
fiat_p434_uint1 x291;
- fiat_p434_addcarryx_u64(&x290, &x291, 0x0, x274, x246);
+ fiat_p434_addcarryx_u64(&x290, &x291, 0x0, x246, x274);
uint64_t x292;
fiat_p434_uint1 x293;
- fiat_p434_addcarryx_u64(&x292, &x293, x291, x276, x248);
+ fiat_p434_addcarryx_u64(&x292, &x293, x291, x248, x276);
uint64_t x294;
fiat_p434_uint1 x295;
- fiat_p434_addcarryx_u64(&x294, &x295, x293, x278, x250);
+ fiat_p434_addcarryx_u64(&x294, &x295, x293, x250, x278);
uint64_t x296;
fiat_p434_uint1 x297;
- fiat_p434_addcarryx_u64(&x296, &x297, x295, x280, x252);
+ fiat_p434_addcarryx_u64(&x296, &x297, x295, x252, x280);
uint64_t x298;
fiat_p434_uint1 x299;
- fiat_p434_addcarryx_u64(&x298, &x299, x297, x282, x254);
+ fiat_p434_addcarryx_u64(&x298, &x299, x297, x254, x282);
uint64_t x300;
fiat_p434_uint1 x301;
- fiat_p434_addcarryx_u64(&x300, &x301, x299, x284, x256);
+ fiat_p434_addcarryx_u64(&x300, &x301, x299, x256, x284);
uint64_t x302;
fiat_p434_uint1 x303;
- fiat_p434_addcarryx_u64(&x302, &x303, x301, x286, x258);
+ fiat_p434_addcarryx_u64(&x302, &x303, x301, x258, x286);
uint64_t x304;
fiat_p434_uint1 x305;
- fiat_p434_addcarryx_u64(&x304, &x305, x303, x288, x260);
+ fiat_p434_addcarryx_u64(&x304, &x305, x303, x260, x288);
uint64_t x306;
uint64_t x307;
fiat_p434_mulx_u64(&x306, &x307, x290, UINT64_C(0x2341f27177344));
@@ -1584,52 +1584,52 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x318, &x319, x290, UINT64_C(0xffffffffffffffff));
uint64_t x320;
fiat_p434_uint1 x321;
- fiat_p434_addcarryx_u64(&x320, &x321, 0x0, x316, x319);
+ fiat_p434_addcarryx_u64(&x320, &x321, 0x0, x319, x316);
uint64_t x322;
fiat_p434_uint1 x323;
- fiat_p434_addcarryx_u64(&x322, &x323, x321, x314, x317);
+ fiat_p434_addcarryx_u64(&x322, &x323, x321, x317, x314);
uint64_t x324;
fiat_p434_uint1 x325;
- fiat_p434_addcarryx_u64(&x324, &x325, x323, x312, x315);
+ fiat_p434_addcarryx_u64(&x324, &x325, x323, x315, x312);
uint64_t x326;
fiat_p434_uint1 x327;
- fiat_p434_addcarryx_u64(&x326, &x327, x325, x310, x313);
+ fiat_p434_addcarryx_u64(&x326, &x327, x325, x313, x310);
uint64_t x328;
fiat_p434_uint1 x329;
- fiat_p434_addcarryx_u64(&x328, &x329, x327, x308, x311);
+ fiat_p434_addcarryx_u64(&x328, &x329, x327, x311, x308);
uint64_t x330;
fiat_p434_uint1 x331;
- fiat_p434_addcarryx_u64(&x330, &x331, x329, x306, x309);
+ fiat_p434_addcarryx_u64(&x330, &x331, x329, x309, x306);
uint64_t x332;
fiat_p434_uint1 x333;
- fiat_p434_addcarryx_u64(&x332, &x333, x331, 0x0, x307);
+ fiat_p434_addcarryx_u64(&x332, &x333, x331, x307, 0x0);
uint64_t x334;
fiat_p434_uint1 x335;
- fiat_p434_addcarryx_u64(&x334, &x335, 0x0, x318, x290);
+ fiat_p434_addcarryx_u64(&x334, &x335, 0x0, x290, x318);
uint64_t x336;
fiat_p434_uint1 x337;
- fiat_p434_addcarryx_u64(&x336, &x337, x335, x320, x292);
+ fiat_p434_addcarryx_u64(&x336, &x337, x335, x292, x320);
uint64_t x338;
fiat_p434_uint1 x339;
- fiat_p434_addcarryx_u64(&x338, &x339, x337, x322, x294);
+ fiat_p434_addcarryx_u64(&x338, &x339, x337, x294, x322);
uint64_t x340;
fiat_p434_uint1 x341;
- fiat_p434_addcarryx_u64(&x340, &x341, x339, x324, x296);
+ fiat_p434_addcarryx_u64(&x340, &x341, x339, x296, x324);
uint64_t x342;
fiat_p434_uint1 x343;
- fiat_p434_addcarryx_u64(&x342, &x343, x341, x326, x298);
+ fiat_p434_addcarryx_u64(&x342, &x343, x341, x298, x326);
uint64_t x344;
fiat_p434_uint1 x345;
- fiat_p434_addcarryx_u64(&x344, &x345, x343, x328, x300);
+ fiat_p434_addcarryx_u64(&x344, &x345, x343, x300, x328);
uint64_t x346;
fiat_p434_uint1 x347;
- fiat_p434_addcarryx_u64(&x346, &x347, x345, x330, x302);
+ fiat_p434_addcarryx_u64(&x346, &x347, x345, x302, x330);
uint64_t x348;
fiat_p434_uint1 x349;
- fiat_p434_addcarryx_u64(&x348, &x349, x347, x332, x304);
+ fiat_p434_addcarryx_u64(&x348, &x349, x347, x304, x332);
uint64_t x350;
fiat_p434_uint1 x351;
- fiat_p434_addcarryx_u64(&x350, &x351, x349, 0x0, x305);
+ fiat_p434_addcarryx_u64(&x350, &x351, x349, x305, 0x0);
uint64_t x352;
uint64_t x353;
fiat_p434_mulx_u64(&x352, &x353, x4, (arg1[6]));
@@ -1653,49 +1653,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x364, &x365, x4, (arg1[0]));
uint64_t x366;
fiat_p434_uint1 x367;
- fiat_p434_addcarryx_u64(&x366, &x367, 0x0, x362, x365);
+ fiat_p434_addcarryx_u64(&x366, &x367, 0x0, x365, x362);
uint64_t x368;
fiat_p434_uint1 x369;
- fiat_p434_addcarryx_u64(&x368, &x369, x367, x360, x363);
+ fiat_p434_addcarryx_u64(&x368, &x369, x367, x363, x360);
uint64_t x370;
fiat_p434_uint1 x371;
- fiat_p434_addcarryx_u64(&x370, &x371, x369, x358, x361);
+ fiat_p434_addcarryx_u64(&x370, &x371, x369, x361, x358);
uint64_t x372;
fiat_p434_uint1 x373;
- fiat_p434_addcarryx_u64(&x372, &x373, x371, x356, x359);
+ fiat_p434_addcarryx_u64(&x372, &x373, x371, x359, x356);
uint64_t x374;
fiat_p434_uint1 x375;
- fiat_p434_addcarryx_u64(&x374, &x375, x373, x354, x357);
+ fiat_p434_addcarryx_u64(&x374, &x375, x373, x357, x354);
uint64_t x376;
fiat_p434_uint1 x377;
- fiat_p434_addcarryx_u64(&x376, &x377, x375, x352, x355);
+ fiat_p434_addcarryx_u64(&x376, &x377, x375, x355, x352);
uint64_t x378;
fiat_p434_uint1 x379;
- fiat_p434_addcarryx_u64(&x378, &x379, x377, 0x0, x353);
+ fiat_p434_addcarryx_u64(&x378, &x379, x377, x353, 0x0);
uint64_t x380;
fiat_p434_uint1 x381;
- fiat_p434_addcarryx_u64(&x380, &x381, 0x0, x364, x336);
+ fiat_p434_addcarryx_u64(&x380, &x381, 0x0, x336, x364);
uint64_t x382;
fiat_p434_uint1 x383;
- fiat_p434_addcarryx_u64(&x382, &x383, x381, x366, x338);
+ fiat_p434_addcarryx_u64(&x382, &x383, x381, x338, x366);
uint64_t x384;
fiat_p434_uint1 x385;
- fiat_p434_addcarryx_u64(&x384, &x385, x383, x368, x340);
+ fiat_p434_addcarryx_u64(&x384, &x385, x383, x340, x368);
uint64_t x386;
fiat_p434_uint1 x387;
- fiat_p434_addcarryx_u64(&x386, &x387, x385, x370, x342);
+ fiat_p434_addcarryx_u64(&x386, &x387, x385, x342, x370);
uint64_t x388;
fiat_p434_uint1 x389;
- fiat_p434_addcarryx_u64(&x388, &x389, x387, x372, x344);
+ fiat_p434_addcarryx_u64(&x388, &x389, x387, x344, x372);
uint64_t x390;
fiat_p434_uint1 x391;
- fiat_p434_addcarryx_u64(&x390, &x391, x389, x374, x346);
+ fiat_p434_addcarryx_u64(&x390, &x391, x389, x346, x374);
uint64_t x392;
fiat_p434_uint1 x393;
- fiat_p434_addcarryx_u64(&x392, &x393, x391, x376, x348);
+ fiat_p434_addcarryx_u64(&x392, &x393, x391, x348, x376);
uint64_t x394;
fiat_p434_uint1 x395;
- fiat_p434_addcarryx_u64(&x394, &x395, x393, x378, x350);
+ fiat_p434_addcarryx_u64(&x394, &x395, x393, x350, x378);
uint64_t x396;
uint64_t x397;
fiat_p434_mulx_u64(&x396, &x397, x380, UINT64_C(0x2341f27177344));
@@ -1719,52 +1719,52 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x408, &x409, x380, UINT64_C(0xffffffffffffffff));
uint64_t x410;
fiat_p434_uint1 x411;
- fiat_p434_addcarryx_u64(&x410, &x411, 0x0, x406, x409);
+ fiat_p434_addcarryx_u64(&x410, &x411, 0x0, x409, x406);
uint64_t x412;
fiat_p434_uint1 x413;
- fiat_p434_addcarryx_u64(&x412, &x413, x411, x404, x407);
+ fiat_p434_addcarryx_u64(&x412, &x413, x411, x407, x404);
uint64_t x414;
fiat_p434_uint1 x415;
- fiat_p434_addcarryx_u64(&x414, &x415, x413, x402, x405);
+ fiat_p434_addcarryx_u64(&x414, &x415, x413, x405, x402);
uint64_t x416;
fiat_p434_uint1 x417;
- fiat_p434_addcarryx_u64(&x416, &x417, x415, x400, x403);
+ fiat_p434_addcarryx_u64(&x416, &x417, x415, x403, x400);
uint64_t x418;
fiat_p434_uint1 x419;
- fiat_p434_addcarryx_u64(&x418, &x419, x417, x398, x401);
+ fiat_p434_addcarryx_u64(&x418, &x419, x417, x401, x398);
uint64_t x420;
fiat_p434_uint1 x421;
- fiat_p434_addcarryx_u64(&x420, &x421, x419, x396, x399);
+ fiat_p434_addcarryx_u64(&x420, &x421, x419, x399, x396);
uint64_t x422;
fiat_p434_uint1 x423;
- fiat_p434_addcarryx_u64(&x422, &x423, x421, 0x0, x397);
+ fiat_p434_addcarryx_u64(&x422, &x423, x421, x397, 0x0);
uint64_t x424;
fiat_p434_uint1 x425;
- fiat_p434_addcarryx_u64(&x424, &x425, 0x0, x408, x380);
+ fiat_p434_addcarryx_u64(&x424, &x425, 0x0, x380, x408);
uint64_t x426;
fiat_p434_uint1 x427;
- fiat_p434_addcarryx_u64(&x426, &x427, x425, x410, x382);
+ fiat_p434_addcarryx_u64(&x426, &x427, x425, x382, x410);
uint64_t x428;
fiat_p434_uint1 x429;
- fiat_p434_addcarryx_u64(&x428, &x429, x427, x412, x384);
+ fiat_p434_addcarryx_u64(&x428, &x429, x427, x384, x412);
uint64_t x430;
fiat_p434_uint1 x431;
- fiat_p434_addcarryx_u64(&x430, &x431, x429, x414, x386);
+ fiat_p434_addcarryx_u64(&x430, &x431, x429, x386, x414);
uint64_t x432;
fiat_p434_uint1 x433;
- fiat_p434_addcarryx_u64(&x432, &x433, x431, x416, x388);
+ fiat_p434_addcarryx_u64(&x432, &x433, x431, x388, x416);
uint64_t x434;
fiat_p434_uint1 x435;
- fiat_p434_addcarryx_u64(&x434, &x435, x433, x418, x390);
+ fiat_p434_addcarryx_u64(&x434, &x435, x433, x390, x418);
uint64_t x436;
fiat_p434_uint1 x437;
- fiat_p434_addcarryx_u64(&x436, &x437, x435, x420, x392);
+ fiat_p434_addcarryx_u64(&x436, &x437, x435, x392, x420);
uint64_t x438;
fiat_p434_uint1 x439;
- fiat_p434_addcarryx_u64(&x438, &x439, x437, x422, x394);
+ fiat_p434_addcarryx_u64(&x438, &x439, x437, x394, x422);
uint64_t x440;
fiat_p434_uint1 x441;
- fiat_p434_addcarryx_u64(&x440, &x441, x439, 0x0, x395);
+ fiat_p434_addcarryx_u64(&x440, &x441, x439, x395, 0x0);
uint64_t x442;
uint64_t x443;
fiat_p434_mulx_u64(&x442, &x443, x5, (arg1[6]));
@@ -1788,49 +1788,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x454, &x455, x5, (arg1[0]));
uint64_t x456;
fiat_p434_uint1 x457;
- fiat_p434_addcarryx_u64(&x456, &x457, 0x0, x452, x455);
+ fiat_p434_addcarryx_u64(&x456, &x457, 0x0, x455, x452);
uint64_t x458;
fiat_p434_uint1 x459;
- fiat_p434_addcarryx_u64(&x458, &x459, x457, x450, x453);
+ fiat_p434_addcarryx_u64(&x458, &x459, x457, x453, x450);
uint64_t x460;
fiat_p434_uint1 x461;
- fiat_p434_addcarryx_u64(&x460, &x461, x459, x448, x451);
+ fiat_p434_addcarryx_u64(&x460, &x461, x459, x451, x448);
uint64_t x462;
fiat_p434_uint1 x463;
- fiat_p434_addcarryx_u64(&x462, &x463, x461, x446, x449);
+ fiat_p434_addcarryx_u64(&x462, &x463, x461, x449, x446);
uint64_t x464;
fiat_p434_uint1 x465;
- fiat_p434_addcarryx_u64(&x464, &x465, x463, x444, x447);
+ fiat_p434_addcarryx_u64(&x464, &x465, x463, x447, x444);
uint64_t x466;
fiat_p434_uint1 x467;
- fiat_p434_addcarryx_u64(&x466, &x467, x465, x442, x445);
+ fiat_p434_addcarryx_u64(&x466, &x467, x465, x445, x442);
uint64_t x468;
fiat_p434_uint1 x469;
- fiat_p434_addcarryx_u64(&x468, &x469, x467, 0x0, x443);
+ fiat_p434_addcarryx_u64(&x468, &x469, x467, x443, 0x0);
uint64_t x470;
fiat_p434_uint1 x471;
- fiat_p434_addcarryx_u64(&x470, &x471, 0x0, x454, x426);
+ fiat_p434_addcarryx_u64(&x470, &x471, 0x0, x426, x454);
uint64_t x472;
fiat_p434_uint1 x473;
- fiat_p434_addcarryx_u64(&x472, &x473, x471, x456, x428);
+ fiat_p434_addcarryx_u64(&x472, &x473, x471, x428, x456);
uint64_t x474;
fiat_p434_uint1 x475;
- fiat_p434_addcarryx_u64(&x474, &x475, x473, x458, x430);
+ fiat_p434_addcarryx_u64(&x474, &x475, x473, x430, x458);
uint64_t x476;
fiat_p434_uint1 x477;
- fiat_p434_addcarryx_u64(&x476, &x477, x475, x460, x432);
+ fiat_p434_addcarryx_u64(&x476, &x477, x475, x432, x460);
uint64_t x478;
fiat_p434_uint1 x479;
- fiat_p434_addcarryx_u64(&x478, &x479, x477, x462, x434);
+ fiat_p434_addcarryx_u64(&x478, &x479, x477, x434, x462);
uint64_t x480;
fiat_p434_uint1 x481;
- fiat_p434_addcarryx_u64(&x480, &x481, x479, x464, x436);
+ fiat_p434_addcarryx_u64(&x480, &x481, x479, x436, x464);
uint64_t x482;
fiat_p434_uint1 x483;
- fiat_p434_addcarryx_u64(&x482, &x483, x481, x466, x438);
+ fiat_p434_addcarryx_u64(&x482, &x483, x481, x438, x466);
uint64_t x484;
fiat_p434_uint1 x485;
- fiat_p434_addcarryx_u64(&x484, &x485, x483, x468, x440);
+ fiat_p434_addcarryx_u64(&x484, &x485, x483, x440, x468);
uint64_t x486;
uint64_t x487;
fiat_p434_mulx_u64(&x486, &x487, x470, UINT64_C(0x2341f27177344));
@@ -1854,52 +1854,52 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x498, &x499, x470, UINT64_C(0xffffffffffffffff));
uint64_t x500;
fiat_p434_uint1 x501;
- fiat_p434_addcarryx_u64(&x500, &x501, 0x0, x496, x499);
+ fiat_p434_addcarryx_u64(&x500, &x501, 0x0, x499, x496);
uint64_t x502;
fiat_p434_uint1 x503;
- fiat_p434_addcarryx_u64(&x502, &x503, x501, x494, x497);
+ fiat_p434_addcarryx_u64(&x502, &x503, x501, x497, x494);
uint64_t x504;
fiat_p434_uint1 x505;
- fiat_p434_addcarryx_u64(&x504, &x505, x503, x492, x495);
+ fiat_p434_addcarryx_u64(&x504, &x505, x503, x495, x492);
uint64_t x506;
fiat_p434_uint1 x507;
- fiat_p434_addcarryx_u64(&x506, &x507, x505, x490, x493);
+ fiat_p434_addcarryx_u64(&x506, &x507, x505, x493, x490);
uint64_t x508;
fiat_p434_uint1 x509;
- fiat_p434_addcarryx_u64(&x508, &x509, x507, x488, x491);
+ fiat_p434_addcarryx_u64(&x508, &x509, x507, x491, x488);
uint64_t x510;
fiat_p434_uint1 x511;
- fiat_p434_addcarryx_u64(&x510, &x511, x509, x486, x489);
+ fiat_p434_addcarryx_u64(&x510, &x511, x509, x489, x486);
uint64_t x512;
fiat_p434_uint1 x513;
- fiat_p434_addcarryx_u64(&x512, &x513, x511, 0x0, x487);
+ fiat_p434_addcarryx_u64(&x512, &x513, x511, x487, 0x0);
uint64_t x514;
fiat_p434_uint1 x515;
- fiat_p434_addcarryx_u64(&x514, &x515, 0x0, x498, x470);
+ fiat_p434_addcarryx_u64(&x514, &x515, 0x0, x470, x498);
uint64_t x516;
fiat_p434_uint1 x517;
- fiat_p434_addcarryx_u64(&x516, &x517, x515, x500, x472);
+ fiat_p434_addcarryx_u64(&x516, &x517, x515, x472, x500);
uint64_t x518;
fiat_p434_uint1 x519;
- fiat_p434_addcarryx_u64(&x518, &x519, x517, x502, x474);
+ fiat_p434_addcarryx_u64(&x518, &x519, x517, x474, x502);
uint64_t x520;
fiat_p434_uint1 x521;
- fiat_p434_addcarryx_u64(&x520, &x521, x519, x504, x476);
+ fiat_p434_addcarryx_u64(&x520, &x521, x519, x476, x504);
uint64_t x522;
fiat_p434_uint1 x523;
- fiat_p434_addcarryx_u64(&x522, &x523, x521, x506, x478);
+ fiat_p434_addcarryx_u64(&x522, &x523, x521, x478, x506);
uint64_t x524;
fiat_p434_uint1 x525;
- fiat_p434_addcarryx_u64(&x524, &x525, x523, x508, x480);
+ fiat_p434_addcarryx_u64(&x524, &x525, x523, x480, x508);
uint64_t x526;
fiat_p434_uint1 x527;
- fiat_p434_addcarryx_u64(&x526, &x527, x525, x510, x482);
+ fiat_p434_addcarryx_u64(&x526, &x527, x525, x482, x510);
uint64_t x528;
fiat_p434_uint1 x529;
- fiat_p434_addcarryx_u64(&x528, &x529, x527, x512, x484);
+ fiat_p434_addcarryx_u64(&x528, &x529, x527, x484, x512);
uint64_t x530;
fiat_p434_uint1 x531;
- fiat_p434_addcarryx_u64(&x530, &x531, x529, 0x0, x485);
+ fiat_p434_addcarryx_u64(&x530, &x531, x529, x485, 0x0);
uint64_t x532;
uint64_t x533;
fiat_p434_mulx_u64(&x532, &x533, x6, (arg1[6]));
@@ -1923,49 +1923,49 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x544, &x545, x6, (arg1[0]));
uint64_t x546;
fiat_p434_uint1 x547;
- fiat_p434_addcarryx_u64(&x546, &x547, 0x0, x542, x545);
+ fiat_p434_addcarryx_u64(&x546, &x547, 0x0, x545, x542);
uint64_t x548;
fiat_p434_uint1 x549;
- fiat_p434_addcarryx_u64(&x548, &x549, x547, x540, x543);
+ fiat_p434_addcarryx_u64(&x548, &x549, x547, x543, x540);
uint64_t x550;
fiat_p434_uint1 x551;
- fiat_p434_addcarryx_u64(&x550, &x551, x549, x538, x541);
+ fiat_p434_addcarryx_u64(&x550, &x551, x549, x541, x538);
uint64_t x552;
fiat_p434_uint1 x553;
- fiat_p434_addcarryx_u64(&x552, &x553, x551, x536, x539);
+ fiat_p434_addcarryx_u64(&x552, &x553, x551, x539, x536);
uint64_t x554;
fiat_p434_uint1 x555;
- fiat_p434_addcarryx_u64(&x554, &x555, x553, x534, x537);
+ fiat_p434_addcarryx_u64(&x554, &x555, x553, x537, x534);
uint64_t x556;
fiat_p434_uint1 x557;
- fiat_p434_addcarryx_u64(&x556, &x557, x555, x532, x535);
+ fiat_p434_addcarryx_u64(&x556, &x557, x555, x535, x532);
uint64_t x558;
fiat_p434_uint1 x559;
- fiat_p434_addcarryx_u64(&x558, &x559, x557, 0x0, x533);
+ fiat_p434_addcarryx_u64(&x558, &x559, x557, x533, 0x0);
uint64_t x560;
fiat_p434_uint1 x561;
- fiat_p434_addcarryx_u64(&x560, &x561, 0x0, x544, x516);
+ fiat_p434_addcarryx_u64(&x560, &x561, 0x0, x516, x544);
uint64_t x562;
fiat_p434_uint1 x563;
- fiat_p434_addcarryx_u64(&x562, &x563, x561, x546, x518);
+ fiat_p434_addcarryx_u64(&x562, &x563, x561, x518, x546);
uint64_t x564;
fiat_p434_uint1 x565;
- fiat_p434_addcarryx_u64(&x564, &x565, x563, x548, x520);
+ fiat_p434_addcarryx_u64(&x564, &x565, x563, x520, x548);
uint64_t x566;
fiat_p434_uint1 x567;
- fiat_p434_addcarryx_u64(&x566, &x567, x565, x550, x522);
+ fiat_p434_addcarryx_u64(&x566, &x567, x565, x522, x550);
uint64_t x568;
fiat_p434_uint1 x569;
- fiat_p434_addcarryx_u64(&x568, &x569, x567, x552, x524);
+ fiat_p434_addcarryx_u64(&x568, &x569, x567, x524, x552);
uint64_t x570;
fiat_p434_uint1 x571;
- fiat_p434_addcarryx_u64(&x570, &x571, x569, x554, x526);
+ fiat_p434_addcarryx_u64(&x570, &x571, x569, x526, x554);
uint64_t x572;
fiat_p434_uint1 x573;
- fiat_p434_addcarryx_u64(&x572, &x573, x571, x556, x528);
+ fiat_p434_addcarryx_u64(&x572, &x573, x571, x528, x556);
uint64_t x574;
fiat_p434_uint1 x575;
- fiat_p434_addcarryx_u64(&x574, &x575, x573, x558, x530);
+ fiat_p434_addcarryx_u64(&x574, &x575, x573, x530, x558);
uint64_t x576;
uint64_t x577;
fiat_p434_mulx_u64(&x576, &x577, x560, UINT64_C(0x2341f27177344));
@@ -1989,52 +1989,52 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_mulx_u64(&x588, &x589, x560, UINT64_C(0xffffffffffffffff));
uint64_t x590;
fiat_p434_uint1 x591;
- fiat_p434_addcarryx_u64(&x590, &x591, 0x0, x586, x589);
+ fiat_p434_addcarryx_u64(&x590, &x591, 0x0, x589, x586);
uint64_t x592;
fiat_p434_uint1 x593;
- fiat_p434_addcarryx_u64(&x592, &x593, x591, x584, x587);
+ fiat_p434_addcarryx_u64(&x592, &x593, x591, x587, x584);
uint64_t x594;
fiat_p434_uint1 x595;
- fiat_p434_addcarryx_u64(&x594, &x595, x593, x582, x585);
+ fiat_p434_addcarryx_u64(&x594, &x595, x593, x585, x582);
uint64_t x596;
fiat_p434_uint1 x597;
- fiat_p434_addcarryx_u64(&x596, &x597, x595, x580, x583);
+ fiat_p434_addcarryx_u64(&x596, &x597, x595, x583, x580);
uint64_t x598;
fiat_p434_uint1 x599;
- fiat_p434_addcarryx_u64(&x598, &x599, x597, x578, x581);
+ fiat_p434_addcarryx_u64(&x598, &x599, x597, x581, x578);
uint64_t x600;
fiat_p434_uint1 x601;
- fiat_p434_addcarryx_u64(&x600, &x601, x599, x576, x579);
+ fiat_p434_addcarryx_u64(&x600, &x601, x599, x579, x576);
uint64_t x602;
fiat_p434_uint1 x603;
- fiat_p434_addcarryx_u64(&x602, &x603, x601, 0x0, x577);
+ fiat_p434_addcarryx_u64(&x602, &x603, x601, x577, 0x0);
uint64_t x604;
fiat_p434_uint1 x605;
- fiat_p434_addcarryx_u64(&x604, &x605, 0x0, x588, x560);
+ fiat_p434_addcarryx_u64(&x604, &x605, 0x0, x560, x588);
uint64_t x606;
fiat_p434_uint1 x607;
- fiat_p434_addcarryx_u64(&x606, &x607, x605, x590, x562);
+ fiat_p434_addcarryx_u64(&x606, &x607, x605, x562, x590);
uint64_t x608;
fiat_p434_uint1 x609;
- fiat_p434_addcarryx_u64(&x608, &x609, x607, x592, x564);
+ fiat_p434_addcarryx_u64(&x608, &x609, x607, x564, x592);
uint64_t x610;
fiat_p434_uint1 x611;
- fiat_p434_addcarryx_u64(&x610, &x611, x609, x594, x566);
+ fiat_p434_addcarryx_u64(&x610, &x611, x609, x566, x594);
uint64_t x612;
fiat_p434_uint1 x613;
- fiat_p434_addcarryx_u64(&x612, &x613, x611, x596, x568);
+ fiat_p434_addcarryx_u64(&x612, &x613, x611, x568, x596);
uint64_t x614;
fiat_p434_uint1 x615;
- fiat_p434_addcarryx_u64(&x614, &x615, x613, x598, x570);
+ fiat_p434_addcarryx_u64(&x614, &x615, x613, x570, x598);
uint64_t x616;
fiat_p434_uint1 x617;
- fiat_p434_addcarryx_u64(&x616, &x617, x615, x600, x572);
+ fiat_p434_addcarryx_u64(&x616, &x617, x615, x572, x600);
uint64_t x618;
fiat_p434_uint1 x619;
- fiat_p434_addcarryx_u64(&x618, &x619, x617, x602, x574);
+ fiat_p434_addcarryx_u64(&x618, &x619, x617, x574, x602);
uint64_t x620;
fiat_p434_uint1 x621;
- fiat_p434_addcarryx_u64(&x620, &x621, x619, 0x0, x575);
+ fiat_p434_addcarryx_u64(&x620, &x621, x619, x575, 0x0);
uint64_t x622;
fiat_p434_uint1 x623;
fiat_p434_subborrowx_u64(&x622, &x623, 0x0, x606, UINT64_C(0xffffffffffffffff));
@@ -2100,25 +2100,25 @@ static void fiat_p434_square(uint64_t out1[7], const uint64_t arg1[7]) {
static void fiat_p434_add(uint64_t out1[7], const uint64_t arg1[7], const uint64_t arg2[7]) {
uint64_t x1;
fiat_p434_uint1 x2;
- fiat_p434_addcarryx_u64(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_p434_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint64_t x3;
fiat_p434_uint1 x4;
- fiat_p434_addcarryx_u64(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_p434_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint64_t x5;
fiat_p434_uint1 x6;
- fiat_p434_addcarryx_u64(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_p434_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint64_t x7;
fiat_p434_uint1 x8;
- fiat_p434_addcarryx_u64(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_p434_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint64_t x9;
fiat_p434_uint1 x10;
- fiat_p434_addcarryx_u64(&x9, &x10, x8, (arg2[4]), (arg1[4]));
+ fiat_p434_addcarryx_u64(&x9, &x10, x8, (arg1[4]), (arg2[4]));
uint64_t x11;
fiat_p434_uint1 x12;
- fiat_p434_addcarryx_u64(&x11, &x12, x10, (arg2[5]), (arg1[5]));
+ fiat_p434_addcarryx_u64(&x11, &x12, x10, (arg1[5]), (arg2[5]));
uint64_t x13;
fiat_p434_uint1 x14;
- fiat_p434_addcarryx_u64(&x13, &x14, x12, (arg2[6]), (arg1[6]));
+ fiat_p434_addcarryx_u64(&x13, &x14, x12, (arg1[6]), (arg2[6]));
uint64_t x15;
fiat_p434_uint1 x16;
fiat_p434_subborrowx_u64(&x15, &x16, 0x0, x1, UINT64_C(0xffffffffffffffff));
@@ -2207,25 +2207,25 @@ static void fiat_p434_sub(uint64_t out1[7], const uint64_t arg1[7], const uint64
fiat_p434_cmovznz_u64(&x15, x14, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x16;
fiat_p434_uint1 x17;
- fiat_p434_addcarryx_u64(&x16, &x17, 0x0, (x15 & UINT64_C(0xffffffffffffffff)), x1);
+ fiat_p434_addcarryx_u64(&x16, &x17, 0x0, x1, (x15 & UINT64_C(0xffffffffffffffff)));
uint64_t x18;
fiat_p434_uint1 x19;
- fiat_p434_addcarryx_u64(&x18, &x19, x17, (x15 & UINT64_C(0xffffffffffffffff)), x3);
+ fiat_p434_addcarryx_u64(&x18, &x19, x17, x3, (x15 & UINT64_C(0xffffffffffffffff)));
uint64_t x20;
fiat_p434_uint1 x21;
- fiat_p434_addcarryx_u64(&x20, &x21, x19, (x15 & UINT64_C(0xffffffffffffffff)), x5);
+ fiat_p434_addcarryx_u64(&x20, &x21, x19, x5, (x15 & UINT64_C(0xffffffffffffffff)));
uint64_t x22;
fiat_p434_uint1 x23;
- fiat_p434_addcarryx_u64(&x22, &x23, x21, (x15 & UINT64_C(0xfdc1767ae2ffffff)), x7);
+ fiat_p434_addcarryx_u64(&x22, &x23, x21, x7, (x15 & UINT64_C(0xfdc1767ae2ffffff)));
uint64_t x24;
fiat_p434_uint1 x25;
- fiat_p434_addcarryx_u64(&x24, &x25, x23, (x15 & UINT64_C(0x7bc65c783158aea3)), x9);
+ fiat_p434_addcarryx_u64(&x24, &x25, x23, x9, (x15 & UINT64_C(0x7bc65c783158aea3)));
uint64_t x26;
fiat_p434_uint1 x27;
- fiat_p434_addcarryx_u64(&x26, &x27, x25, (x15 & UINT64_C(0x6cfc5fd681c52056)), x11);
+ fiat_p434_addcarryx_u64(&x26, &x27, x25, x11, (x15 & UINT64_C(0x6cfc5fd681c52056)));
uint64_t x28;
fiat_p434_uint1 x29;
- fiat_p434_addcarryx_u64(&x28, &x29, x27, (x15 & UINT64_C(0x2341f27177344)), x13);
+ fiat_p434_addcarryx_u64(&x28, &x29, x27, x13, (x15 & UINT64_C(0x2341f27177344)));
out1[0] = x16;
out1[1] = x18;
out1[2] = x20;
@@ -2274,25 +2274,25 @@ static void fiat_p434_opp(uint64_t out1[7], const uint64_t arg1[7]) {
fiat_p434_cmovznz_u64(&x15, x14, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x16;
fiat_p434_uint1 x17;
- fiat_p434_addcarryx_u64(&x16, &x17, 0x0, (x15 & UINT64_C(0xffffffffffffffff)), x1);
+ fiat_p434_addcarryx_u64(&x16, &x17, 0x0, x1, (x15 & UINT64_C(0xffffffffffffffff)));
uint64_t x18;
fiat_p434_uint1 x19;
- fiat_p434_addcarryx_u64(&x18, &x19, x17, (x15 & UINT64_C(0xffffffffffffffff)), x3);
+ fiat_p434_addcarryx_u64(&x18, &x19, x17, x3, (x15 & UINT64_C(0xffffffffffffffff)));
uint64_t x20;
fiat_p434_uint1 x21;
- fiat_p434_addcarryx_u64(&x20, &x21, x19, (x15 & UINT64_C(0xffffffffffffffff)), x5);
+ fiat_p434_addcarryx_u64(&x20, &x21, x19, x5, (x15 & UINT64_C(0xffffffffffffffff)));
uint64_t x22;
fiat_p434_uint1 x23;
- fiat_p434_addcarryx_u64(&x22, &x23, x21, (x15 & UINT64_C(0xfdc1767ae2ffffff)), x7);
+ fiat_p434_addcarryx_u64(&x22, &x23, x21, x7, (x15 & UINT64_C(0xfdc1767ae2ffffff)));
uint64_t x24;
fiat_p434_uint1 x25;
- fiat_p434_addcarryx_u64(&x24, &x25, x23, (x15 & UINT64_C(0x7bc65c783158aea3)), x9);
+ fiat_p434_addcarryx_u64(&x24, &x25, x23, x9, (x15 & UINT64_C(0x7bc65c783158aea3)));
uint64_t x26;
fiat_p434_uint1 x27;
- fiat_p434_addcarryx_u64(&x26, &x27, x25, (x15 & UINT64_C(0x6cfc5fd681c52056)), x11);
+ fiat_p434_addcarryx_u64(&x26, &x27, x25, x11, (x15 & UINT64_C(0x6cfc5fd681c52056)));
uint64_t x28;
fiat_p434_uint1 x29;
- fiat_p434_addcarryx_u64(&x28, &x29, x27, (x15 & UINT64_C(0x2341f27177344)), x13);
+ fiat_p434_addcarryx_u64(&x28, &x29, x27, x13, (x15 & UINT64_C(0x2341f27177344)));
out1[0] = x16;
out1[1] = x18;
out1[2] = x20;
@@ -2340,61 +2340,61 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x14, &x15, x1, UINT64_C(0xffffffffffffffff));
uint64_t x16;
fiat_p434_uint1 x17;
- fiat_p434_addcarryx_u64(&x16, &x17, 0x0, x12, x15);
+ fiat_p434_addcarryx_u64(&x16, &x17, 0x0, x15, x12);
uint64_t x18;
fiat_p434_uint1 x19;
- fiat_p434_addcarryx_u64(&x18, &x19, x17, x10, x13);
+ fiat_p434_addcarryx_u64(&x18, &x19, x17, x13, x10);
uint64_t x20;
fiat_p434_uint1 x21;
- fiat_p434_addcarryx_u64(&x20, &x21, x19, x8, x11);
+ fiat_p434_addcarryx_u64(&x20, &x21, x19, x11, x8);
uint64_t x22;
fiat_p434_uint1 x23;
- fiat_p434_addcarryx_u64(&x22, &x23, x21, x6, x9);
+ fiat_p434_addcarryx_u64(&x22, &x23, x21, x9, x6);
uint64_t x24;
fiat_p434_uint1 x25;
- fiat_p434_addcarryx_u64(&x24, &x25, x23, x4, x7);
+ fiat_p434_addcarryx_u64(&x24, &x25, x23, x7, x4);
uint64_t x26;
fiat_p434_uint1 x27;
- fiat_p434_addcarryx_u64(&x26, &x27, x25, x2, x5);
+ fiat_p434_addcarryx_u64(&x26, &x27, x25, x5, x2);
uint64_t x28;
fiat_p434_uint1 x29;
- fiat_p434_addcarryx_u64(&x28, &x29, 0x0, x14, x1);
+ fiat_p434_addcarryx_u64(&x28, &x29, 0x0, x1, x14);
uint64_t x30;
fiat_p434_uint1 x31;
- fiat_p434_addcarryx_u64(&x30, &x31, x29, x16, 0x0);
+ fiat_p434_addcarryx_u64(&x30, &x31, x29, 0x0, x16);
uint64_t x32;
fiat_p434_uint1 x33;
- fiat_p434_addcarryx_u64(&x32, &x33, x31, x18, 0x0);
+ fiat_p434_addcarryx_u64(&x32, &x33, x31, 0x0, x18);
uint64_t x34;
fiat_p434_uint1 x35;
- fiat_p434_addcarryx_u64(&x34, &x35, x33, x20, 0x0);
+ fiat_p434_addcarryx_u64(&x34, &x35, x33, 0x0, x20);
uint64_t x36;
fiat_p434_uint1 x37;
- fiat_p434_addcarryx_u64(&x36, &x37, x35, x22, 0x0);
+ fiat_p434_addcarryx_u64(&x36, &x37, x35, 0x0, x22);
uint64_t x38;
fiat_p434_uint1 x39;
- fiat_p434_addcarryx_u64(&x38, &x39, x37, x24, 0x0);
+ fiat_p434_addcarryx_u64(&x38, &x39, x37, 0x0, x24);
uint64_t x40;
fiat_p434_uint1 x41;
- fiat_p434_addcarryx_u64(&x40, &x41, x39, x26, 0x0);
+ fiat_p434_addcarryx_u64(&x40, &x41, x39, 0x0, x26);
uint64_t x42;
fiat_p434_uint1 x43;
- fiat_p434_addcarryx_u64(&x42, &x43, 0x0, (arg1[1]), x30);
+ fiat_p434_addcarryx_u64(&x42, &x43, 0x0, x30, (arg1[1]));
uint64_t x44;
fiat_p434_uint1 x45;
- fiat_p434_addcarryx_u64(&x44, &x45, x43, 0x0, x32);
+ fiat_p434_addcarryx_u64(&x44, &x45, x43, x32, 0x0);
uint64_t x46;
fiat_p434_uint1 x47;
- fiat_p434_addcarryx_u64(&x46, &x47, x45, 0x0, x34);
+ fiat_p434_addcarryx_u64(&x46, &x47, x45, x34, 0x0);
uint64_t x48;
fiat_p434_uint1 x49;
- fiat_p434_addcarryx_u64(&x48, &x49, x47, 0x0, x36);
+ fiat_p434_addcarryx_u64(&x48, &x49, x47, x36, 0x0);
uint64_t x50;
fiat_p434_uint1 x51;
- fiat_p434_addcarryx_u64(&x50, &x51, x49, 0x0, x38);
+ fiat_p434_addcarryx_u64(&x50, &x51, x49, x38, 0x0);
uint64_t x52;
fiat_p434_uint1 x53;
- fiat_p434_addcarryx_u64(&x52, &x53, x51, 0x0, x40);
+ fiat_p434_addcarryx_u64(&x52, &x53, x51, x40, 0x0);
uint64_t x54;
uint64_t x55;
fiat_p434_mulx_u64(&x54, &x55, x42, UINT64_C(0x2341f27177344));
@@ -2418,70 +2418,70 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x66, &x67, x42, UINT64_C(0xffffffffffffffff));
uint64_t x68;
fiat_p434_uint1 x69;
- fiat_p434_addcarryx_u64(&x68, &x69, 0x0, x64, x67);
+ fiat_p434_addcarryx_u64(&x68, &x69, 0x0, x67, x64);
uint64_t x70;
fiat_p434_uint1 x71;
- fiat_p434_addcarryx_u64(&x70, &x71, x69, x62, x65);
+ fiat_p434_addcarryx_u64(&x70, &x71, x69, x65, x62);
uint64_t x72;
fiat_p434_uint1 x73;
- fiat_p434_addcarryx_u64(&x72, &x73, x71, x60, x63);
+ fiat_p434_addcarryx_u64(&x72, &x73, x71, x63, x60);
uint64_t x74;
fiat_p434_uint1 x75;
- fiat_p434_addcarryx_u64(&x74, &x75, x73, x58, x61);
+ fiat_p434_addcarryx_u64(&x74, &x75, x73, x61, x58);
uint64_t x76;
fiat_p434_uint1 x77;
- fiat_p434_addcarryx_u64(&x76, &x77, x75, x56, x59);
+ fiat_p434_addcarryx_u64(&x76, &x77, x75, x59, x56);
uint64_t x78;
fiat_p434_uint1 x79;
- fiat_p434_addcarryx_u64(&x78, &x79, x77, x54, x57);
+ fiat_p434_addcarryx_u64(&x78, &x79, x77, x57, x54);
uint64_t x80;
fiat_p434_uint1 x81;
- fiat_p434_addcarryx_u64(&x80, &x81, 0x0, x66, x42);
+ fiat_p434_addcarryx_u64(&x80, &x81, 0x0, x42, x66);
uint64_t x82;
fiat_p434_uint1 x83;
- fiat_p434_addcarryx_u64(&x82, &x83, x81, x68, x44);
+ fiat_p434_addcarryx_u64(&x82, &x83, x81, x44, x68);
uint64_t x84;
fiat_p434_uint1 x85;
- fiat_p434_addcarryx_u64(&x84, &x85, x83, x70, x46);
+ fiat_p434_addcarryx_u64(&x84, &x85, x83, x46, x70);
uint64_t x86;
fiat_p434_uint1 x87;
- fiat_p434_addcarryx_u64(&x86, &x87, x85, x72, x48);
+ fiat_p434_addcarryx_u64(&x86, &x87, x85, x48, x72);
uint64_t x88;
fiat_p434_uint1 x89;
- fiat_p434_addcarryx_u64(&x88, &x89, x87, x74, x50);
+ fiat_p434_addcarryx_u64(&x88, &x89, x87, x50, x74);
uint64_t x90;
fiat_p434_uint1 x91;
- fiat_p434_addcarryx_u64(&x90, &x91, x89, x76, x52);
+ fiat_p434_addcarryx_u64(&x90, &x91, x89, x52, x76);
uint64_t x92;
fiat_p434_uint1 x93;
- fiat_p434_addcarryx_u64(&x92, &x93, x27, 0x0, x3);
+ fiat_p434_addcarryx_u64(&x92, &x93, x27, x3, 0x0);
uint64_t x94;
fiat_p434_uint1 x95;
- fiat_p434_addcarryx_u64(&x94, &x95, x41, x92, 0x0);
+ fiat_p434_addcarryx_u64(&x94, &x95, x41, 0x0, x92);
uint64_t x96;
fiat_p434_uint1 x97;
- fiat_p434_addcarryx_u64(&x96, &x97, x53, 0x0, x94);
+ fiat_p434_addcarryx_u64(&x96, &x97, x53, x94, 0x0);
uint64_t x98;
fiat_p434_uint1 x99;
- fiat_p434_addcarryx_u64(&x98, &x99, x91, x78, x96);
+ fiat_p434_addcarryx_u64(&x98, &x99, x91, x96, x78);
uint64_t x100;
fiat_p434_uint1 x101;
- fiat_p434_addcarryx_u64(&x100, &x101, 0x0, (arg1[2]), x82);
+ fiat_p434_addcarryx_u64(&x100, &x101, 0x0, x82, (arg1[2]));
uint64_t x102;
fiat_p434_uint1 x103;
- fiat_p434_addcarryx_u64(&x102, &x103, x101, 0x0, x84);
+ fiat_p434_addcarryx_u64(&x102, &x103, x101, x84, 0x0);
uint64_t x104;
fiat_p434_uint1 x105;
- fiat_p434_addcarryx_u64(&x104, &x105, x103, 0x0, x86);
+ fiat_p434_addcarryx_u64(&x104, &x105, x103, x86, 0x0);
uint64_t x106;
fiat_p434_uint1 x107;
- fiat_p434_addcarryx_u64(&x106, &x107, x105, 0x0, x88);
+ fiat_p434_addcarryx_u64(&x106, &x107, x105, x88, 0x0);
uint64_t x108;
fiat_p434_uint1 x109;
- fiat_p434_addcarryx_u64(&x108, &x109, x107, 0x0, x90);
+ fiat_p434_addcarryx_u64(&x108, &x109, x107, x90, 0x0);
uint64_t x110;
fiat_p434_uint1 x111;
- fiat_p434_addcarryx_u64(&x110, &x111, x109, 0x0, x98);
+ fiat_p434_addcarryx_u64(&x110, &x111, x109, x98, 0x0);
uint64_t x112;
uint64_t x113;
fiat_p434_mulx_u64(&x112, &x113, x100, UINT64_C(0x2341f27177344));
@@ -2505,70 +2505,70 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x124, &x125, x100, UINT64_C(0xffffffffffffffff));
uint64_t x126;
fiat_p434_uint1 x127;
- fiat_p434_addcarryx_u64(&x126, &x127, 0x0, x122, x125);
+ fiat_p434_addcarryx_u64(&x126, &x127, 0x0, x125, x122);
uint64_t x128;
fiat_p434_uint1 x129;
- fiat_p434_addcarryx_u64(&x128, &x129, x127, x120, x123);
+ fiat_p434_addcarryx_u64(&x128, &x129, x127, x123, x120);
uint64_t x130;
fiat_p434_uint1 x131;
- fiat_p434_addcarryx_u64(&x130, &x131, x129, x118, x121);
+ fiat_p434_addcarryx_u64(&x130, &x131, x129, x121, x118);
uint64_t x132;
fiat_p434_uint1 x133;
- fiat_p434_addcarryx_u64(&x132, &x133, x131, x116, x119);
+ fiat_p434_addcarryx_u64(&x132, &x133, x131, x119, x116);
uint64_t x134;
fiat_p434_uint1 x135;
- fiat_p434_addcarryx_u64(&x134, &x135, x133, x114, x117);
+ fiat_p434_addcarryx_u64(&x134, &x135, x133, x117, x114);
uint64_t x136;
fiat_p434_uint1 x137;
- fiat_p434_addcarryx_u64(&x136, &x137, x135, x112, x115);
+ fiat_p434_addcarryx_u64(&x136, &x137, x135, x115, x112);
uint64_t x138;
fiat_p434_uint1 x139;
- fiat_p434_addcarryx_u64(&x138, &x139, 0x0, x124, x100);
+ fiat_p434_addcarryx_u64(&x138, &x139, 0x0, x100, x124);
uint64_t x140;
fiat_p434_uint1 x141;
- fiat_p434_addcarryx_u64(&x140, &x141, x139, x126, x102);
+ fiat_p434_addcarryx_u64(&x140, &x141, x139, x102, x126);
uint64_t x142;
fiat_p434_uint1 x143;
- fiat_p434_addcarryx_u64(&x142, &x143, x141, x128, x104);
+ fiat_p434_addcarryx_u64(&x142, &x143, x141, x104, x128);
uint64_t x144;
fiat_p434_uint1 x145;
- fiat_p434_addcarryx_u64(&x144, &x145, x143, x130, x106);
+ fiat_p434_addcarryx_u64(&x144, &x145, x143, x106, x130);
uint64_t x146;
fiat_p434_uint1 x147;
- fiat_p434_addcarryx_u64(&x146, &x147, x145, x132, x108);
+ fiat_p434_addcarryx_u64(&x146, &x147, x145, x108, x132);
uint64_t x148;
fiat_p434_uint1 x149;
- fiat_p434_addcarryx_u64(&x148, &x149, x147, x134, x110);
+ fiat_p434_addcarryx_u64(&x148, &x149, x147, x110, x134);
uint64_t x150;
fiat_p434_uint1 x151;
- fiat_p434_addcarryx_u64(&x150, &x151, x79, 0x0, x55);
+ fiat_p434_addcarryx_u64(&x150, &x151, x79, x55, 0x0);
uint64_t x152;
fiat_p434_uint1 x153;
- fiat_p434_addcarryx_u64(&x152, &x153, x99, x150, 0x0);
+ fiat_p434_addcarryx_u64(&x152, &x153, x99, 0x0, x150);
uint64_t x154;
fiat_p434_uint1 x155;
- fiat_p434_addcarryx_u64(&x154, &x155, x111, 0x0, x152);
+ fiat_p434_addcarryx_u64(&x154, &x155, x111, x152, 0x0);
uint64_t x156;
fiat_p434_uint1 x157;
- fiat_p434_addcarryx_u64(&x156, &x157, x149, x136, x154);
+ fiat_p434_addcarryx_u64(&x156, &x157, x149, x154, x136);
uint64_t x158;
fiat_p434_uint1 x159;
- fiat_p434_addcarryx_u64(&x158, &x159, 0x0, (arg1[3]), x140);
+ fiat_p434_addcarryx_u64(&x158, &x159, 0x0, x140, (arg1[3]));
uint64_t x160;
fiat_p434_uint1 x161;
- fiat_p434_addcarryx_u64(&x160, &x161, x159, 0x0, x142);
+ fiat_p434_addcarryx_u64(&x160, &x161, x159, x142, 0x0);
uint64_t x162;
fiat_p434_uint1 x163;
- fiat_p434_addcarryx_u64(&x162, &x163, x161, 0x0, x144);
+ fiat_p434_addcarryx_u64(&x162, &x163, x161, x144, 0x0);
uint64_t x164;
fiat_p434_uint1 x165;
- fiat_p434_addcarryx_u64(&x164, &x165, x163, 0x0, x146);
+ fiat_p434_addcarryx_u64(&x164, &x165, x163, x146, 0x0);
uint64_t x166;
fiat_p434_uint1 x167;
- fiat_p434_addcarryx_u64(&x166, &x167, x165, 0x0, x148);
+ fiat_p434_addcarryx_u64(&x166, &x167, x165, x148, 0x0);
uint64_t x168;
fiat_p434_uint1 x169;
- fiat_p434_addcarryx_u64(&x168, &x169, x167, 0x0, x156);
+ fiat_p434_addcarryx_u64(&x168, &x169, x167, x156, 0x0);
uint64_t x170;
uint64_t x171;
fiat_p434_mulx_u64(&x170, &x171, x158, UINT64_C(0x2341f27177344));
@@ -2592,70 +2592,70 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x182, &x183, x158, UINT64_C(0xffffffffffffffff));
uint64_t x184;
fiat_p434_uint1 x185;
- fiat_p434_addcarryx_u64(&x184, &x185, 0x0, x180, x183);
+ fiat_p434_addcarryx_u64(&x184, &x185, 0x0, x183, x180);
uint64_t x186;
fiat_p434_uint1 x187;
- fiat_p434_addcarryx_u64(&x186, &x187, x185, x178, x181);
+ fiat_p434_addcarryx_u64(&x186, &x187, x185, x181, x178);
uint64_t x188;
fiat_p434_uint1 x189;
- fiat_p434_addcarryx_u64(&x188, &x189, x187, x176, x179);
+ fiat_p434_addcarryx_u64(&x188, &x189, x187, x179, x176);
uint64_t x190;
fiat_p434_uint1 x191;
- fiat_p434_addcarryx_u64(&x190, &x191, x189, x174, x177);
+ fiat_p434_addcarryx_u64(&x190, &x191, x189, x177, x174);
uint64_t x192;
fiat_p434_uint1 x193;
- fiat_p434_addcarryx_u64(&x192, &x193, x191, x172, x175);
+ fiat_p434_addcarryx_u64(&x192, &x193, x191, x175, x172);
uint64_t x194;
fiat_p434_uint1 x195;
- fiat_p434_addcarryx_u64(&x194, &x195, x193, x170, x173);
+ fiat_p434_addcarryx_u64(&x194, &x195, x193, x173, x170);
uint64_t x196;
fiat_p434_uint1 x197;
- fiat_p434_addcarryx_u64(&x196, &x197, 0x0, x182, x158);
+ fiat_p434_addcarryx_u64(&x196, &x197, 0x0, x158, x182);
uint64_t x198;
fiat_p434_uint1 x199;
- fiat_p434_addcarryx_u64(&x198, &x199, x197, x184, x160);
+ fiat_p434_addcarryx_u64(&x198, &x199, x197, x160, x184);
uint64_t x200;
fiat_p434_uint1 x201;
- fiat_p434_addcarryx_u64(&x200, &x201, x199, x186, x162);
+ fiat_p434_addcarryx_u64(&x200, &x201, x199, x162, x186);
uint64_t x202;
fiat_p434_uint1 x203;
- fiat_p434_addcarryx_u64(&x202, &x203, x201, x188, x164);
+ fiat_p434_addcarryx_u64(&x202, &x203, x201, x164, x188);
uint64_t x204;
fiat_p434_uint1 x205;
- fiat_p434_addcarryx_u64(&x204, &x205, x203, x190, x166);
+ fiat_p434_addcarryx_u64(&x204, &x205, x203, x166, x190);
uint64_t x206;
fiat_p434_uint1 x207;
- fiat_p434_addcarryx_u64(&x206, &x207, x205, x192, x168);
+ fiat_p434_addcarryx_u64(&x206, &x207, x205, x168, x192);
uint64_t x208;
fiat_p434_uint1 x209;
- fiat_p434_addcarryx_u64(&x208, &x209, x137, 0x0, x113);
+ fiat_p434_addcarryx_u64(&x208, &x209, x137, x113, 0x0);
uint64_t x210;
fiat_p434_uint1 x211;
- fiat_p434_addcarryx_u64(&x210, &x211, x157, x208, 0x0);
+ fiat_p434_addcarryx_u64(&x210, &x211, x157, 0x0, x208);
uint64_t x212;
fiat_p434_uint1 x213;
- fiat_p434_addcarryx_u64(&x212, &x213, x169, 0x0, x210);
+ fiat_p434_addcarryx_u64(&x212, &x213, x169, x210, 0x0);
uint64_t x214;
fiat_p434_uint1 x215;
- fiat_p434_addcarryx_u64(&x214, &x215, x207, x194, x212);
+ fiat_p434_addcarryx_u64(&x214, &x215, x207, x212, x194);
uint64_t x216;
fiat_p434_uint1 x217;
- fiat_p434_addcarryx_u64(&x216, &x217, 0x0, (arg1[4]), x198);
+ fiat_p434_addcarryx_u64(&x216, &x217, 0x0, x198, (arg1[4]));
uint64_t x218;
fiat_p434_uint1 x219;
- fiat_p434_addcarryx_u64(&x218, &x219, x217, 0x0, x200);
+ fiat_p434_addcarryx_u64(&x218, &x219, x217, x200, 0x0);
uint64_t x220;
fiat_p434_uint1 x221;
- fiat_p434_addcarryx_u64(&x220, &x221, x219, 0x0, x202);
+ fiat_p434_addcarryx_u64(&x220, &x221, x219, x202, 0x0);
uint64_t x222;
fiat_p434_uint1 x223;
- fiat_p434_addcarryx_u64(&x222, &x223, x221, 0x0, x204);
+ fiat_p434_addcarryx_u64(&x222, &x223, x221, x204, 0x0);
uint64_t x224;
fiat_p434_uint1 x225;
- fiat_p434_addcarryx_u64(&x224, &x225, x223, 0x0, x206);
+ fiat_p434_addcarryx_u64(&x224, &x225, x223, x206, 0x0);
uint64_t x226;
fiat_p434_uint1 x227;
- fiat_p434_addcarryx_u64(&x226, &x227, x225, 0x0, x214);
+ fiat_p434_addcarryx_u64(&x226, &x227, x225, x214, 0x0);
uint64_t x228;
uint64_t x229;
fiat_p434_mulx_u64(&x228, &x229, x216, UINT64_C(0x2341f27177344));
@@ -2679,70 +2679,70 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x240, &x241, x216, UINT64_C(0xffffffffffffffff));
uint64_t x242;
fiat_p434_uint1 x243;
- fiat_p434_addcarryx_u64(&x242, &x243, 0x0, x238, x241);
+ fiat_p434_addcarryx_u64(&x242, &x243, 0x0, x241, x238);
uint64_t x244;
fiat_p434_uint1 x245;
- fiat_p434_addcarryx_u64(&x244, &x245, x243, x236, x239);
+ fiat_p434_addcarryx_u64(&x244, &x245, x243, x239, x236);
uint64_t x246;
fiat_p434_uint1 x247;
- fiat_p434_addcarryx_u64(&x246, &x247, x245, x234, x237);
+ fiat_p434_addcarryx_u64(&x246, &x247, x245, x237, x234);
uint64_t x248;
fiat_p434_uint1 x249;
- fiat_p434_addcarryx_u64(&x248, &x249, x247, x232, x235);
+ fiat_p434_addcarryx_u64(&x248, &x249, x247, x235, x232);
uint64_t x250;
fiat_p434_uint1 x251;
- fiat_p434_addcarryx_u64(&x250, &x251, x249, x230, x233);
+ fiat_p434_addcarryx_u64(&x250, &x251, x249, x233, x230);
uint64_t x252;
fiat_p434_uint1 x253;
- fiat_p434_addcarryx_u64(&x252, &x253, x251, x228, x231);
+ fiat_p434_addcarryx_u64(&x252, &x253, x251, x231, x228);
uint64_t x254;
fiat_p434_uint1 x255;
- fiat_p434_addcarryx_u64(&x254, &x255, 0x0, x240, x216);
+ fiat_p434_addcarryx_u64(&x254, &x255, 0x0, x216, x240);
uint64_t x256;
fiat_p434_uint1 x257;
- fiat_p434_addcarryx_u64(&x256, &x257, x255, x242, x218);
+ fiat_p434_addcarryx_u64(&x256, &x257, x255, x218, x242);
uint64_t x258;
fiat_p434_uint1 x259;
- fiat_p434_addcarryx_u64(&x258, &x259, x257, x244, x220);
+ fiat_p434_addcarryx_u64(&x258, &x259, x257, x220, x244);
uint64_t x260;
fiat_p434_uint1 x261;
- fiat_p434_addcarryx_u64(&x260, &x261, x259, x246, x222);
+ fiat_p434_addcarryx_u64(&x260, &x261, x259, x222, x246);
uint64_t x262;
fiat_p434_uint1 x263;
- fiat_p434_addcarryx_u64(&x262, &x263, x261, x248, x224);
+ fiat_p434_addcarryx_u64(&x262, &x263, x261, x224, x248);
uint64_t x264;
fiat_p434_uint1 x265;
- fiat_p434_addcarryx_u64(&x264, &x265, x263, x250, x226);
+ fiat_p434_addcarryx_u64(&x264, &x265, x263, x226, x250);
uint64_t x266;
fiat_p434_uint1 x267;
- fiat_p434_addcarryx_u64(&x266, &x267, x195, 0x0, x171);
+ fiat_p434_addcarryx_u64(&x266, &x267, x195, x171, 0x0);
uint64_t x268;
fiat_p434_uint1 x269;
- fiat_p434_addcarryx_u64(&x268, &x269, x215, x266, 0x0);
+ fiat_p434_addcarryx_u64(&x268, &x269, x215, 0x0, x266);
uint64_t x270;
fiat_p434_uint1 x271;
- fiat_p434_addcarryx_u64(&x270, &x271, x227, 0x0, x268);
+ fiat_p434_addcarryx_u64(&x270, &x271, x227, x268, 0x0);
uint64_t x272;
fiat_p434_uint1 x273;
- fiat_p434_addcarryx_u64(&x272, &x273, x265, x252, x270);
+ fiat_p434_addcarryx_u64(&x272, &x273, x265, x270, x252);
uint64_t x274;
fiat_p434_uint1 x275;
- fiat_p434_addcarryx_u64(&x274, &x275, 0x0, (arg1[5]), x256);
+ fiat_p434_addcarryx_u64(&x274, &x275, 0x0, x256, (arg1[5]));
uint64_t x276;
fiat_p434_uint1 x277;
- fiat_p434_addcarryx_u64(&x276, &x277, x275, 0x0, x258);
+ fiat_p434_addcarryx_u64(&x276, &x277, x275, x258, 0x0);
uint64_t x278;
fiat_p434_uint1 x279;
- fiat_p434_addcarryx_u64(&x278, &x279, x277, 0x0, x260);
+ fiat_p434_addcarryx_u64(&x278, &x279, x277, x260, 0x0);
uint64_t x280;
fiat_p434_uint1 x281;
- fiat_p434_addcarryx_u64(&x280, &x281, x279, 0x0, x262);
+ fiat_p434_addcarryx_u64(&x280, &x281, x279, x262, 0x0);
uint64_t x282;
fiat_p434_uint1 x283;
- fiat_p434_addcarryx_u64(&x282, &x283, x281, 0x0, x264);
+ fiat_p434_addcarryx_u64(&x282, &x283, x281, x264, 0x0);
uint64_t x284;
fiat_p434_uint1 x285;
- fiat_p434_addcarryx_u64(&x284, &x285, x283, 0x0, x272);
+ fiat_p434_addcarryx_u64(&x284, &x285, x283, x272, 0x0);
uint64_t x286;
uint64_t x287;
fiat_p434_mulx_u64(&x286, &x287, x274, UINT64_C(0x2341f27177344));
@@ -2766,70 +2766,70 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x298, &x299, x274, UINT64_C(0xffffffffffffffff));
uint64_t x300;
fiat_p434_uint1 x301;
- fiat_p434_addcarryx_u64(&x300, &x301, 0x0, x296, x299);
+ fiat_p434_addcarryx_u64(&x300, &x301, 0x0, x299, x296);
uint64_t x302;
fiat_p434_uint1 x303;
- fiat_p434_addcarryx_u64(&x302, &x303, x301, x294, x297);
+ fiat_p434_addcarryx_u64(&x302, &x303, x301, x297, x294);
uint64_t x304;
fiat_p434_uint1 x305;
- fiat_p434_addcarryx_u64(&x304, &x305, x303, x292, x295);
+ fiat_p434_addcarryx_u64(&x304, &x305, x303, x295, x292);
uint64_t x306;
fiat_p434_uint1 x307;
- fiat_p434_addcarryx_u64(&x306, &x307, x305, x290, x293);
+ fiat_p434_addcarryx_u64(&x306, &x307, x305, x293, x290);
uint64_t x308;
fiat_p434_uint1 x309;
- fiat_p434_addcarryx_u64(&x308, &x309, x307, x288, x291);
+ fiat_p434_addcarryx_u64(&x308, &x309, x307, x291, x288);
uint64_t x310;
fiat_p434_uint1 x311;
- fiat_p434_addcarryx_u64(&x310, &x311, x309, x286, x289);
+ fiat_p434_addcarryx_u64(&x310, &x311, x309, x289, x286);
uint64_t x312;
fiat_p434_uint1 x313;
- fiat_p434_addcarryx_u64(&x312, &x313, 0x0, x298, x274);
+ fiat_p434_addcarryx_u64(&x312, &x313, 0x0, x274, x298);
uint64_t x314;
fiat_p434_uint1 x315;
- fiat_p434_addcarryx_u64(&x314, &x315, x313, x300, x276);
+ fiat_p434_addcarryx_u64(&x314, &x315, x313, x276, x300);
uint64_t x316;
fiat_p434_uint1 x317;
- fiat_p434_addcarryx_u64(&x316, &x317, x315, x302, x278);
+ fiat_p434_addcarryx_u64(&x316, &x317, x315, x278, x302);
uint64_t x318;
fiat_p434_uint1 x319;
- fiat_p434_addcarryx_u64(&x318, &x319, x317, x304, x280);
+ fiat_p434_addcarryx_u64(&x318, &x319, x317, x280, x304);
uint64_t x320;
fiat_p434_uint1 x321;
- fiat_p434_addcarryx_u64(&x320, &x321, x319, x306, x282);
+ fiat_p434_addcarryx_u64(&x320, &x321, x319, x282, x306);
uint64_t x322;
fiat_p434_uint1 x323;
- fiat_p434_addcarryx_u64(&x322, &x323, x321, x308, x284);
+ fiat_p434_addcarryx_u64(&x322, &x323, x321, x284, x308);
uint64_t x324;
fiat_p434_uint1 x325;
- fiat_p434_addcarryx_u64(&x324, &x325, x253, 0x0, x229);
+ fiat_p434_addcarryx_u64(&x324, &x325, x253, x229, 0x0);
uint64_t x326;
fiat_p434_uint1 x327;
- fiat_p434_addcarryx_u64(&x326, &x327, x273, x324, 0x0);
+ fiat_p434_addcarryx_u64(&x326, &x327, x273, 0x0, x324);
uint64_t x328;
fiat_p434_uint1 x329;
- fiat_p434_addcarryx_u64(&x328, &x329, x285, 0x0, x326);
+ fiat_p434_addcarryx_u64(&x328, &x329, x285, x326, 0x0);
uint64_t x330;
fiat_p434_uint1 x331;
- fiat_p434_addcarryx_u64(&x330, &x331, x323, x310, x328);
+ fiat_p434_addcarryx_u64(&x330, &x331, x323, x328, x310);
uint64_t x332;
fiat_p434_uint1 x333;
- fiat_p434_addcarryx_u64(&x332, &x333, 0x0, (arg1[6]), x314);
+ fiat_p434_addcarryx_u64(&x332, &x333, 0x0, x314, (arg1[6]));
uint64_t x334;
fiat_p434_uint1 x335;
- fiat_p434_addcarryx_u64(&x334, &x335, x333, 0x0, x316);
+ fiat_p434_addcarryx_u64(&x334, &x335, x333, x316, 0x0);
uint64_t x336;
fiat_p434_uint1 x337;
- fiat_p434_addcarryx_u64(&x336, &x337, x335, 0x0, x318);
+ fiat_p434_addcarryx_u64(&x336, &x337, x335, x318, 0x0);
uint64_t x338;
fiat_p434_uint1 x339;
- fiat_p434_addcarryx_u64(&x338, &x339, x337, 0x0, x320);
+ fiat_p434_addcarryx_u64(&x338, &x339, x337, x320, 0x0);
uint64_t x340;
fiat_p434_uint1 x341;
- fiat_p434_addcarryx_u64(&x340, &x341, x339, 0x0, x322);
+ fiat_p434_addcarryx_u64(&x340, &x341, x339, x322, 0x0);
uint64_t x342;
fiat_p434_uint1 x343;
- fiat_p434_addcarryx_u64(&x342, &x343, x341, 0x0, x330);
+ fiat_p434_addcarryx_u64(&x342, &x343, x341, x330, 0x0);
uint64_t x344;
uint64_t x345;
fiat_p434_mulx_u64(&x344, &x345, x332, UINT64_C(0x2341f27177344));
@@ -2853,58 +2853,58 @@ static void fiat_p434_from_montgomery(uint64_t out1[7], const uint64_t arg1[7])
fiat_p434_mulx_u64(&x356, &x357, x332, UINT64_C(0xffffffffffffffff));
uint64_t x358;
fiat_p434_uint1 x359;
- fiat_p434_addcarryx_u64(&x358, &x359, 0x0, x354, x357);
+ fiat_p434_addcarryx_u64(&x358, &x359, 0x0, x357, x354);
uint64_t x360;
fiat_p434_uint1 x361;
- fiat_p434_addcarryx_u64(&x360, &x361, x359, x352, x355);
+ fiat_p434_addcarryx_u64(&x360, &x361, x359, x355, x352);
uint64_t x362;
fiat_p434_uint1 x363;
- fiat_p434_addcarryx_u64(&x362, &x363, x361, x350, x353);
+ fiat_p434_addcarryx_u64(&x362, &x363, x361, x353, x350);
uint64_t x364;
fiat_p434_uint1 x365;
- fiat_p434_addcarryx_u64(&x364, &x365, x363, x348, x351);
+ fiat_p434_addcarryx_u64(&x364, &x365, x363, x351, x348);
uint64_t x366;
fiat_p434_uint1 x367;
- fiat_p434_addcarryx_u64(&x366, &x367, x365, x346, x349);
+ fiat_p434_addcarryx_u64(&x366, &x367, x365, x349, x346);
uint64_t x368;
fiat_p434_uint1 x369;
- fiat_p434_addcarryx_u64(&x368, &x369, x367, x344, x347);
+ fiat_p434_addcarryx_u64(&x368, &x369, x367, x347, x344);
uint64_t x370;
fiat_p434_uint1 x371;
- fiat_p434_addcarryx_u64(&x370, &x371, 0x0, x356, x332);
+ fiat_p434_addcarryx_u64(&x370, &x371, 0x0, x332, x356);
uint64_t x372;
fiat_p434_uint1 x373;
- fiat_p434_addcarryx_u64(&x372, &x373, x371, x358, x334);
+ fiat_p434_addcarryx_u64(&x372, &x373, x371, x334, x358);
uint64_t x374;
fiat_p434_uint1 x375;
- fiat_p434_addcarryx_u64(&x374, &x375, x373, x360, x336);
+ fiat_p434_addcarryx_u64(&x374, &x375, x373, x336, x360);
uint64_t x376;
fiat_p434_uint1 x377;
- fiat_p434_addcarryx_u64(&x376, &x377, x375, x362, x338);
+ fiat_p434_addcarryx_u64(&x376, &x377, x375, x338, x362);
uint64_t x378;
fiat_p434_uint1 x379;
- fiat_p434_addcarryx_u64(&x378, &x379, x377, x364, x340);
+ fiat_p434_addcarryx_u64(&x378, &x379, x377, x340, x364);
uint64_t x380;
fiat_p434_uint1 x381;
- fiat_p434_addcarryx_u64(&x380, &x381, x379, x366, x342);
+ fiat_p434_addcarryx_u64(&x380, &x381, x379, x342, x366);
uint64_t x382;
fiat_p434_uint1 x383;
- fiat_p434_addcarryx_u64(&x382, &x383, x311, 0x0, x287);
+ fiat_p434_addcarryx_u64(&x382, &x383, x311, x287, 0x0);
uint64_t x384;
fiat_p434_uint1 x385;
- fiat_p434_addcarryx_u64(&x384, &x385, x331, x382, 0x0);
+ fiat_p434_addcarryx_u64(&x384, &x385, x331, 0x0, x382);
uint64_t x386;
fiat_p434_uint1 x387;
- fiat_p434_addcarryx_u64(&x386, &x387, x343, 0x0, x384);
+ fiat_p434_addcarryx_u64(&x386, &x387, x343, x384, 0x0);
uint64_t x388;
fiat_p434_uint1 x389;
- fiat_p434_addcarryx_u64(&x388, &x389, x381, x368, x386);
+ fiat_p434_addcarryx_u64(&x388, &x389, x381, x386, x368);
uint64_t x390;
fiat_p434_uint1 x391;
- fiat_p434_addcarryx_u64(&x390, &x391, x369, 0x0, x345);
+ fiat_p434_addcarryx_u64(&x390, &x391, x369, x345, 0x0);
uint64_t x392;
fiat_p434_uint1 x393;
- fiat_p434_addcarryx_u64(&x392, &x393, x389, x390, 0x0);
+ fiat_p434_addcarryx_u64(&x392, &x393, x389, 0x0, x390);
uint64_t x394;
fiat_p434_uint1 x395;
fiat_p434_subborrowx_u64(&x394, &x395, 0x0, x372, UINT64_C(0xffffffffffffffff));
diff --git a/p448_solinas_64.c b/p448_solinas_64.c
index 6e5c8066b..9433b2b52 100644
--- a/p448_solinas_64.c
+++ b/p448_solinas_64.c
@@ -599,28 +599,28 @@ static void fiat_p448_to_bytes(uint8_t out1[56], const uint64_t arg1[8]) {
fiat_p448_cmovznz_u64(&x17, x16, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x18;
fiat_p448_uint1 x19;
- fiat_p448_addcarryx_u56(&x18, &x19, 0x0, (x17 & UINT64_C(0xffffffffffffff)), x1);
+ fiat_p448_addcarryx_u56(&x18, &x19, 0x0, x1, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x20;
fiat_p448_uint1 x21;
- fiat_p448_addcarryx_u56(&x20, &x21, x19, (x17 & UINT64_C(0xffffffffffffff)), x3);
+ fiat_p448_addcarryx_u56(&x20, &x21, x19, x3, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x22;
fiat_p448_uint1 x23;
- fiat_p448_addcarryx_u56(&x22, &x23, x21, (x17 & UINT64_C(0xffffffffffffff)), x5);
+ fiat_p448_addcarryx_u56(&x22, &x23, x21, x5, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x24;
fiat_p448_uint1 x25;
- fiat_p448_addcarryx_u56(&x24, &x25, x23, (x17 & UINT64_C(0xffffffffffffff)), x7);
+ fiat_p448_addcarryx_u56(&x24, &x25, x23, x7, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x26;
fiat_p448_uint1 x27;
- fiat_p448_addcarryx_u56(&x26, &x27, x25, (x17 & UINT64_C(0xfffffffffffffe)), x9);
+ fiat_p448_addcarryx_u56(&x26, &x27, x25, x9, (x17 & UINT64_C(0xfffffffffffffe)));
uint64_t x28;
fiat_p448_uint1 x29;
- fiat_p448_addcarryx_u56(&x28, &x29, x27, (x17 & UINT64_C(0xffffffffffffff)), x11);
+ fiat_p448_addcarryx_u56(&x28, &x29, x27, x11, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x30;
fiat_p448_uint1 x31;
- fiat_p448_addcarryx_u56(&x30, &x31, x29, (x17 & UINT64_C(0xffffffffffffff)), x13);
+ fiat_p448_addcarryx_u56(&x30, &x31, x29, x13, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x32;
fiat_p448_uint1 x33;
- fiat_p448_addcarryx_u56(&x32, &x33, x31, (x17 & UINT64_C(0xffffffffffffff)), x15);
+ fiat_p448_addcarryx_u56(&x32, &x33, x31, x15, (x17 & UINT64_C(0xffffffffffffff)));
uint64_t x34 = (x18 >> 8);
uint8_t x35 = (uint8_t)(x18 & UINT8_C(0xff));
uint64_t x36 = (x34 >> 8);
diff --git a/p521_32.c b/p521_32.c
index aa8416aa9..67ab9d882 100644
--- a/p521_32.c
+++ b/p521_32.c
@@ -1147,55 +1147,55 @@ static void fiat_p521_to_bytes(uint8_t out1[66], const uint32_t arg1[17]) {
fiat_p521_cmovznz_u32(&x35, x34, 0x0, UINT32_C(0xffffffff));
uint32_t x36;
fiat_p521_uint1 x37;
- fiat_p521_addcarryx_u31(&x36, &x37, 0x0, (x35 & UINT32_C(0x7fffffff)), x1);
+ fiat_p521_addcarryx_u31(&x36, &x37, 0x0, x1, (x35 & UINT32_C(0x7fffffff)));
uint32_t x38;
fiat_p521_uint1 x39;
- fiat_p521_addcarryx_u31(&x38, &x39, x37, (x35 & UINT32_C(0x7fffffff)), x3);
+ fiat_p521_addcarryx_u31(&x38, &x39, x37, x3, (x35 & UINT32_C(0x7fffffff)));
uint32_t x40;
fiat_p521_uint1 x41;
- fiat_p521_addcarryx_u30(&x40, &x41, x39, (x35 & UINT32_C(0x3fffffff)), x5);
+ fiat_p521_addcarryx_u30(&x40, &x41, x39, x5, (x35 & UINT32_C(0x3fffffff)));
uint32_t x42;
fiat_p521_uint1 x43;
- fiat_p521_addcarryx_u31(&x42, &x43, x41, (x35 & UINT32_C(0x7fffffff)), x7);
+ fiat_p521_addcarryx_u31(&x42, &x43, x41, x7, (x35 & UINT32_C(0x7fffffff)));
uint32_t x44;
fiat_p521_uint1 x45;
- fiat_p521_addcarryx_u31(&x44, &x45, x43, (x35 & UINT32_C(0x7fffffff)), x9);
+ fiat_p521_addcarryx_u31(&x44, &x45, x43, x9, (x35 & UINT32_C(0x7fffffff)));
uint32_t x46;
fiat_p521_uint1 x47;
- fiat_p521_addcarryx_u30(&x46, &x47, x45, (x35 & UINT32_C(0x3fffffff)), x11);
+ fiat_p521_addcarryx_u30(&x46, &x47, x45, x11, (x35 & UINT32_C(0x3fffffff)));
uint32_t x48;
fiat_p521_uint1 x49;
- fiat_p521_addcarryx_u31(&x48, &x49, x47, (x35 & UINT32_C(0x7fffffff)), x13);
+ fiat_p521_addcarryx_u31(&x48, &x49, x47, x13, (x35 & UINT32_C(0x7fffffff)));
uint32_t x50;
fiat_p521_uint1 x51;
- fiat_p521_addcarryx_u31(&x50, &x51, x49, (x35 & UINT32_C(0x7fffffff)), x15);
+ fiat_p521_addcarryx_u31(&x50, &x51, x49, x15, (x35 & UINT32_C(0x7fffffff)));
uint32_t x52;
fiat_p521_uint1 x53;
- fiat_p521_addcarryx_u30(&x52, &x53, x51, (x35 & UINT32_C(0x3fffffff)), x17);
+ fiat_p521_addcarryx_u30(&x52, &x53, x51, x17, (x35 & UINT32_C(0x3fffffff)));
uint32_t x54;
fiat_p521_uint1 x55;
- fiat_p521_addcarryx_u31(&x54, &x55, x53, (x35 & UINT32_C(0x7fffffff)), x19);
+ fiat_p521_addcarryx_u31(&x54, &x55, x53, x19, (x35 & UINT32_C(0x7fffffff)));
uint32_t x56;
fiat_p521_uint1 x57;
- fiat_p521_addcarryx_u31(&x56, &x57, x55, (x35 & UINT32_C(0x7fffffff)), x21);
+ fiat_p521_addcarryx_u31(&x56, &x57, x55, x21, (x35 & UINT32_C(0x7fffffff)));
uint32_t x58;
fiat_p521_uint1 x59;
- fiat_p521_addcarryx_u30(&x58, &x59, x57, (x35 & UINT32_C(0x3fffffff)), x23);
+ fiat_p521_addcarryx_u30(&x58, &x59, x57, x23, (x35 & UINT32_C(0x3fffffff)));
uint32_t x60;
fiat_p521_uint1 x61;
- fiat_p521_addcarryx_u31(&x60, &x61, x59, (x35 & UINT32_C(0x7fffffff)), x25);
+ fiat_p521_addcarryx_u31(&x60, &x61, x59, x25, (x35 & UINT32_C(0x7fffffff)));
uint32_t x62;
fiat_p521_uint1 x63;
- fiat_p521_addcarryx_u31(&x62, &x63, x61, (x35 & UINT32_C(0x7fffffff)), x27);
+ fiat_p521_addcarryx_u31(&x62, &x63, x61, x27, (x35 & UINT32_C(0x7fffffff)));
uint32_t x64;
fiat_p521_uint1 x65;
- fiat_p521_addcarryx_u30(&x64, &x65, x63, (x35 & UINT32_C(0x3fffffff)), x29);
+ fiat_p521_addcarryx_u30(&x64, &x65, x63, x29, (x35 & UINT32_C(0x3fffffff)));
uint32_t x66;
fiat_p521_uint1 x67;
- fiat_p521_addcarryx_u31(&x66, &x67, x65, (x35 & UINT32_C(0x7fffffff)), x31);
+ fiat_p521_addcarryx_u31(&x66, &x67, x65, x31, (x35 & UINT32_C(0x7fffffff)));
uint32_t x68;
fiat_p521_uint1 x69;
- fiat_p521_addcarryx_u30(&x68, &x69, x67, (x35 & UINT32_C(0x3fffffff)), x33);
+ fiat_p521_addcarryx_u30(&x68, &x69, x67, x33, (x35 & UINT32_C(0x3fffffff)));
uint64_t x70 = ((uint64_t)x68 << 3);
uint64_t x71 = ((uint64_t)x66 << 4);
uint64_t x72 = ((uint64_t)x64 << 6);
diff --git a/p521_64.c b/p521_64.c
index 377c99de4..9499fbc9c 100644
--- a/p521_64.c
+++ b/p521_64.c
@@ -615,31 +615,31 @@ static void fiat_p521_to_bytes(uint8_t out1[66], const uint64_t arg1[9]) {
fiat_p521_cmovznz_u64(&x19, x18, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x20;
fiat_p521_uint1 x21;
- fiat_p521_addcarryx_u58(&x20, &x21, 0x0, (x19 & UINT64_C(0x3ffffffffffffff)), x1);
+ fiat_p521_addcarryx_u58(&x20, &x21, 0x0, x1, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x22;
fiat_p521_uint1 x23;
- fiat_p521_addcarryx_u58(&x22, &x23, x21, (x19 & UINT64_C(0x3ffffffffffffff)), x3);
+ fiat_p521_addcarryx_u58(&x22, &x23, x21, x3, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x24;
fiat_p521_uint1 x25;
- fiat_p521_addcarryx_u58(&x24, &x25, x23, (x19 & UINT64_C(0x3ffffffffffffff)), x5);
+ fiat_p521_addcarryx_u58(&x24, &x25, x23, x5, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x26;
fiat_p521_uint1 x27;
- fiat_p521_addcarryx_u58(&x26, &x27, x25, (x19 & UINT64_C(0x3ffffffffffffff)), x7);
+ fiat_p521_addcarryx_u58(&x26, &x27, x25, x7, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x28;
fiat_p521_uint1 x29;
- fiat_p521_addcarryx_u58(&x28, &x29, x27, (x19 & UINT64_C(0x3ffffffffffffff)), x9);
+ fiat_p521_addcarryx_u58(&x28, &x29, x27, x9, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x30;
fiat_p521_uint1 x31;
- fiat_p521_addcarryx_u58(&x30, &x31, x29, (x19 & UINT64_C(0x3ffffffffffffff)), x11);
+ fiat_p521_addcarryx_u58(&x30, &x31, x29, x11, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x32;
fiat_p521_uint1 x33;
- fiat_p521_addcarryx_u58(&x32, &x33, x31, (x19 & UINT64_C(0x3ffffffffffffff)), x13);
+ fiat_p521_addcarryx_u58(&x32, &x33, x31, x13, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x34;
fiat_p521_uint1 x35;
- fiat_p521_addcarryx_u58(&x34, &x35, x33, (x19 & UINT64_C(0x3ffffffffffffff)), x15);
+ fiat_p521_addcarryx_u58(&x34, &x35, x33, x15, (x19 & UINT64_C(0x3ffffffffffffff)));
uint64_t x36;
fiat_p521_uint1 x37;
- fiat_p521_addcarryx_u57(&x36, &x37, x35, (x19 & UINT64_C(0x1ffffffffffffff)), x17);
+ fiat_p521_addcarryx_u57(&x36, &x37, x35, x17, (x19 & UINT64_C(0x1ffffffffffffff)));
uint64_t x38 = (x34 << 6);
uint64_t x39 = (x32 << 4);
uint64_t x40 = (x30 << 2);
diff --git a/secp256k1_32.c b/secp256k1_32.c
index cfa8e76f8..42445af9d 100644
--- a/secp256k1_32.c
+++ b/secp256k1_32.c
@@ -150,28 +150,28 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x23, &x24, x8, (arg2[0]));
uint32_t x25;
fiat_secp256k1_uint1 x26;
- fiat_secp256k1_addcarryx_u32(&x25, &x26, 0x0, x21, x24);
+ fiat_secp256k1_addcarryx_u32(&x25, &x26, 0x0, x24, x21);
uint32_t x27;
fiat_secp256k1_uint1 x28;
- fiat_secp256k1_addcarryx_u32(&x27, &x28, x26, x19, x22);
+ fiat_secp256k1_addcarryx_u32(&x27, &x28, x26, x22, x19);
uint32_t x29;
fiat_secp256k1_uint1 x30;
- fiat_secp256k1_addcarryx_u32(&x29, &x30, x28, x17, x20);
+ fiat_secp256k1_addcarryx_u32(&x29, &x30, x28, x20, x17);
uint32_t x31;
fiat_secp256k1_uint1 x32;
- fiat_secp256k1_addcarryx_u32(&x31, &x32, x30, x15, x18);
+ fiat_secp256k1_addcarryx_u32(&x31, &x32, x30, x18, x15);
uint32_t x33;
fiat_secp256k1_uint1 x34;
- fiat_secp256k1_addcarryx_u32(&x33, &x34, x32, x13, x16);
+ fiat_secp256k1_addcarryx_u32(&x33, &x34, x32, x16, x13);
uint32_t x35;
fiat_secp256k1_uint1 x36;
- fiat_secp256k1_addcarryx_u32(&x35, &x36, x34, x11, x14);
+ fiat_secp256k1_addcarryx_u32(&x35, &x36, x34, x14, x11);
uint32_t x37;
fiat_secp256k1_uint1 x38;
- fiat_secp256k1_addcarryx_u32(&x37, &x38, x36, x9, x12);
+ fiat_secp256k1_addcarryx_u32(&x37, &x38, x36, x12, x9);
uint32_t x39;
fiat_secp256k1_uint1 x40;
- fiat_secp256k1_addcarryx_u32(&x39, &x40, x38, 0x0, x10);
+ fiat_secp256k1_addcarryx_u32(&x39, &x40, x38, x10, 0x0);
uint32_t x41;
uint32_t x42;
fiat_secp256k1_mulx_u32(&x41, &x42, x23, UINT32_C(0xd2253531));
@@ -201,55 +201,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x57, &x58, x41, UINT32_C(0xfffffc2f));
uint32_t x59;
fiat_secp256k1_uint1 x60;
- fiat_secp256k1_addcarryx_u32(&x59, &x60, 0x0, x55, x58);
+ fiat_secp256k1_addcarryx_u32(&x59, &x60, 0x0, x58, x55);
uint32_t x61;
fiat_secp256k1_uint1 x62;
- fiat_secp256k1_addcarryx_u32(&x61, &x62, x60, x53, x56);
+ fiat_secp256k1_addcarryx_u32(&x61, &x62, x60, x56, x53);
uint32_t x63;
fiat_secp256k1_uint1 x64;
- fiat_secp256k1_addcarryx_u32(&x63, &x64, x62, x51, x54);
+ fiat_secp256k1_addcarryx_u32(&x63, &x64, x62, x54, x51);
uint32_t x65;
fiat_secp256k1_uint1 x66;
- fiat_secp256k1_addcarryx_u32(&x65, &x66, x64, x49, x52);
+ fiat_secp256k1_addcarryx_u32(&x65, &x66, x64, x52, x49);
uint32_t x67;
fiat_secp256k1_uint1 x68;
- fiat_secp256k1_addcarryx_u32(&x67, &x68, x66, x47, x50);
+ fiat_secp256k1_addcarryx_u32(&x67, &x68, x66, x50, x47);
uint32_t x69;
fiat_secp256k1_uint1 x70;
- fiat_secp256k1_addcarryx_u32(&x69, &x70, x68, x45, x48);
+ fiat_secp256k1_addcarryx_u32(&x69, &x70, x68, x48, x45);
uint32_t x71;
fiat_secp256k1_uint1 x72;
- fiat_secp256k1_addcarryx_u32(&x71, &x72, x70, x43, x46);
+ fiat_secp256k1_addcarryx_u32(&x71, &x72, x70, x46, x43);
uint32_t x73;
fiat_secp256k1_uint1 x74;
- fiat_secp256k1_addcarryx_u32(&x73, &x74, x72, 0x0, x44);
+ fiat_secp256k1_addcarryx_u32(&x73, &x74, x72, x44, 0x0);
uint32_t x75;
fiat_secp256k1_uint1 x76;
- fiat_secp256k1_addcarryx_u32(&x75, &x76, 0x0, x57, x23);
+ fiat_secp256k1_addcarryx_u32(&x75, &x76, 0x0, x23, x57);
uint32_t x77;
fiat_secp256k1_uint1 x78;
- fiat_secp256k1_addcarryx_u32(&x77, &x78, x76, x59, x25);
+ fiat_secp256k1_addcarryx_u32(&x77, &x78, x76, x25, x59);
uint32_t x79;
fiat_secp256k1_uint1 x80;
- fiat_secp256k1_addcarryx_u32(&x79, &x80, x78, x61, x27);
+ fiat_secp256k1_addcarryx_u32(&x79, &x80, x78, x27, x61);
uint32_t x81;
fiat_secp256k1_uint1 x82;
- fiat_secp256k1_addcarryx_u32(&x81, &x82, x80, x63, x29);
+ fiat_secp256k1_addcarryx_u32(&x81, &x82, x80, x29, x63);
uint32_t x83;
fiat_secp256k1_uint1 x84;
- fiat_secp256k1_addcarryx_u32(&x83, &x84, x82, x65, x31);
+ fiat_secp256k1_addcarryx_u32(&x83, &x84, x82, x31, x65);
uint32_t x85;
fiat_secp256k1_uint1 x86;
- fiat_secp256k1_addcarryx_u32(&x85, &x86, x84, x67, x33);
+ fiat_secp256k1_addcarryx_u32(&x85, &x86, x84, x33, x67);
uint32_t x87;
fiat_secp256k1_uint1 x88;
- fiat_secp256k1_addcarryx_u32(&x87, &x88, x86, x69, x35);
+ fiat_secp256k1_addcarryx_u32(&x87, &x88, x86, x35, x69);
uint32_t x89;
fiat_secp256k1_uint1 x90;
- fiat_secp256k1_addcarryx_u32(&x89, &x90, x88, x71, x37);
+ fiat_secp256k1_addcarryx_u32(&x89, &x90, x88, x37, x71);
uint32_t x91;
fiat_secp256k1_uint1 x92;
- fiat_secp256k1_addcarryx_u32(&x91, &x92, x90, x73, x39);
+ fiat_secp256k1_addcarryx_u32(&x91, &x92, x90, x39, x73);
uint32_t x93;
fiat_secp256k1_uint1 x94;
fiat_secp256k1_addcarryx_u32(&x93, &x94, x92, 0x0, 0x0);
@@ -279,55 +279,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x109, &x110, x1, (arg2[0]));
uint32_t x111;
fiat_secp256k1_uint1 x112;
- fiat_secp256k1_addcarryx_u32(&x111, &x112, 0x0, x107, x110);
+ fiat_secp256k1_addcarryx_u32(&x111, &x112, 0x0, x110, x107);
uint32_t x113;
fiat_secp256k1_uint1 x114;
- fiat_secp256k1_addcarryx_u32(&x113, &x114, x112, x105, x108);
+ fiat_secp256k1_addcarryx_u32(&x113, &x114, x112, x108, x105);
uint32_t x115;
fiat_secp256k1_uint1 x116;
- fiat_secp256k1_addcarryx_u32(&x115, &x116, x114, x103, x106);
+ fiat_secp256k1_addcarryx_u32(&x115, &x116, x114, x106, x103);
uint32_t x117;
fiat_secp256k1_uint1 x118;
- fiat_secp256k1_addcarryx_u32(&x117, &x118, x116, x101, x104);
+ fiat_secp256k1_addcarryx_u32(&x117, &x118, x116, x104, x101);
uint32_t x119;
fiat_secp256k1_uint1 x120;
- fiat_secp256k1_addcarryx_u32(&x119, &x120, x118, x99, x102);
+ fiat_secp256k1_addcarryx_u32(&x119, &x120, x118, x102, x99);
uint32_t x121;
fiat_secp256k1_uint1 x122;
- fiat_secp256k1_addcarryx_u32(&x121, &x122, x120, x97, x100);
+ fiat_secp256k1_addcarryx_u32(&x121, &x122, x120, x100, x97);
uint32_t x123;
fiat_secp256k1_uint1 x124;
- fiat_secp256k1_addcarryx_u32(&x123, &x124, x122, x95, x98);
+ fiat_secp256k1_addcarryx_u32(&x123, &x124, x122, x98, x95);
uint32_t x125;
fiat_secp256k1_uint1 x126;
- fiat_secp256k1_addcarryx_u32(&x125, &x126, x124, 0x0, x96);
+ fiat_secp256k1_addcarryx_u32(&x125, &x126, x124, x96, 0x0);
uint32_t x127;
fiat_secp256k1_uint1 x128;
- fiat_secp256k1_addcarryx_u32(&x127, &x128, 0x0, x109, x77);
+ fiat_secp256k1_addcarryx_u32(&x127, &x128, 0x0, x77, x109);
uint32_t x129;
fiat_secp256k1_uint1 x130;
- fiat_secp256k1_addcarryx_u32(&x129, &x130, x128, x111, x79);
+ fiat_secp256k1_addcarryx_u32(&x129, &x130, x128, x79, x111);
uint32_t x131;
fiat_secp256k1_uint1 x132;
- fiat_secp256k1_addcarryx_u32(&x131, &x132, x130, x113, x81);
+ fiat_secp256k1_addcarryx_u32(&x131, &x132, x130, x81, x113);
uint32_t x133;
fiat_secp256k1_uint1 x134;
- fiat_secp256k1_addcarryx_u32(&x133, &x134, x132, x115, x83);
+ fiat_secp256k1_addcarryx_u32(&x133, &x134, x132, x83, x115);
uint32_t x135;
fiat_secp256k1_uint1 x136;
- fiat_secp256k1_addcarryx_u32(&x135, &x136, x134, x117, x85);
+ fiat_secp256k1_addcarryx_u32(&x135, &x136, x134, x85, x117);
uint32_t x137;
fiat_secp256k1_uint1 x138;
- fiat_secp256k1_addcarryx_u32(&x137, &x138, x136, x119, x87);
+ fiat_secp256k1_addcarryx_u32(&x137, &x138, x136, x87, x119);
uint32_t x139;
fiat_secp256k1_uint1 x140;
- fiat_secp256k1_addcarryx_u32(&x139, &x140, x138, x121, x89);
+ fiat_secp256k1_addcarryx_u32(&x139, &x140, x138, x89, x121);
uint32_t x141;
fiat_secp256k1_uint1 x142;
- fiat_secp256k1_addcarryx_u32(&x141, &x142, x140, x123, x91);
+ fiat_secp256k1_addcarryx_u32(&x141, &x142, x140, x91, x123);
uint32_t x143;
fiat_secp256k1_uint1 x144;
- fiat_secp256k1_addcarryx_u32(&x143, &x144, x142, x125, (fiat_secp256k1_uint1)x93);
+ fiat_secp256k1_addcarryx_u32(&x143, &x144, x142, (fiat_secp256k1_uint1)x93, x125);
uint32_t x145;
uint32_t x146;
fiat_secp256k1_mulx_u32(&x145, &x146, x127, UINT32_C(0xd2253531));
@@ -357,58 +357,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x161, &x162, x145, UINT32_C(0xfffffc2f));
uint32_t x163;
fiat_secp256k1_uint1 x164;
- fiat_secp256k1_addcarryx_u32(&x163, &x164, 0x0, x159, x162);
+ fiat_secp256k1_addcarryx_u32(&x163, &x164, 0x0, x162, x159);
uint32_t x165;
fiat_secp256k1_uint1 x166;
- fiat_secp256k1_addcarryx_u32(&x165, &x166, x164, x157, x160);
+ fiat_secp256k1_addcarryx_u32(&x165, &x166, x164, x160, x157);
uint32_t x167;
fiat_secp256k1_uint1 x168;
- fiat_secp256k1_addcarryx_u32(&x167, &x168, x166, x155, x158);
+ fiat_secp256k1_addcarryx_u32(&x167, &x168, x166, x158, x155);
uint32_t x169;
fiat_secp256k1_uint1 x170;
- fiat_secp256k1_addcarryx_u32(&x169, &x170, x168, x153, x156);
+ fiat_secp256k1_addcarryx_u32(&x169, &x170, x168, x156, x153);
uint32_t x171;
fiat_secp256k1_uint1 x172;
- fiat_secp256k1_addcarryx_u32(&x171, &x172, x170, x151, x154);
+ fiat_secp256k1_addcarryx_u32(&x171, &x172, x170, x154, x151);
uint32_t x173;
fiat_secp256k1_uint1 x174;
- fiat_secp256k1_addcarryx_u32(&x173, &x174, x172, x149, x152);
+ fiat_secp256k1_addcarryx_u32(&x173, &x174, x172, x152, x149);
uint32_t x175;
fiat_secp256k1_uint1 x176;
- fiat_secp256k1_addcarryx_u32(&x175, &x176, x174, x147, x150);
+ fiat_secp256k1_addcarryx_u32(&x175, &x176, x174, x150, x147);
uint32_t x177;
fiat_secp256k1_uint1 x178;
- fiat_secp256k1_addcarryx_u32(&x177, &x178, x176, 0x0, x148);
+ fiat_secp256k1_addcarryx_u32(&x177, &x178, x176, x148, 0x0);
uint32_t x179;
fiat_secp256k1_uint1 x180;
- fiat_secp256k1_addcarryx_u32(&x179, &x180, 0x0, x161, x127);
+ fiat_secp256k1_addcarryx_u32(&x179, &x180, 0x0, x127, x161);
uint32_t x181;
fiat_secp256k1_uint1 x182;
- fiat_secp256k1_addcarryx_u32(&x181, &x182, x180, x163, x129);
+ fiat_secp256k1_addcarryx_u32(&x181, &x182, x180, x129, x163);
uint32_t x183;
fiat_secp256k1_uint1 x184;
- fiat_secp256k1_addcarryx_u32(&x183, &x184, x182, x165, x131);
+ fiat_secp256k1_addcarryx_u32(&x183, &x184, x182, x131, x165);
uint32_t x185;
fiat_secp256k1_uint1 x186;
- fiat_secp256k1_addcarryx_u32(&x185, &x186, x184, x167, x133);
+ fiat_secp256k1_addcarryx_u32(&x185, &x186, x184, x133, x167);
uint32_t x187;
fiat_secp256k1_uint1 x188;
- fiat_secp256k1_addcarryx_u32(&x187, &x188, x186, x169, x135);
+ fiat_secp256k1_addcarryx_u32(&x187, &x188, x186, x135, x169);
uint32_t x189;
fiat_secp256k1_uint1 x190;
- fiat_secp256k1_addcarryx_u32(&x189, &x190, x188, x171, x137);
+ fiat_secp256k1_addcarryx_u32(&x189, &x190, x188, x137, x171);
uint32_t x191;
fiat_secp256k1_uint1 x192;
- fiat_secp256k1_addcarryx_u32(&x191, &x192, x190, x173, x139);
+ fiat_secp256k1_addcarryx_u32(&x191, &x192, x190, x139, x173);
uint32_t x193;
fiat_secp256k1_uint1 x194;
- fiat_secp256k1_addcarryx_u32(&x193, &x194, x192, x175, x141);
+ fiat_secp256k1_addcarryx_u32(&x193, &x194, x192, x141, x175);
uint32_t x195;
fiat_secp256k1_uint1 x196;
- fiat_secp256k1_addcarryx_u32(&x195, &x196, x194, x177, x143);
+ fiat_secp256k1_addcarryx_u32(&x195, &x196, x194, x143, x177);
uint32_t x197;
fiat_secp256k1_uint1 x198;
- fiat_secp256k1_addcarryx_u32(&x197, &x198, x196, 0x0, x144);
+ fiat_secp256k1_addcarryx_u32(&x197, &x198, x196, x144, 0x0);
uint32_t x199;
uint32_t x200;
fiat_secp256k1_mulx_u32(&x199, &x200, x2, (arg2[7]));
@@ -435,55 +435,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x213, &x214, x2, (arg2[0]));
uint32_t x215;
fiat_secp256k1_uint1 x216;
- fiat_secp256k1_addcarryx_u32(&x215, &x216, 0x0, x211, x214);
+ fiat_secp256k1_addcarryx_u32(&x215, &x216, 0x0, x214, x211);
uint32_t x217;
fiat_secp256k1_uint1 x218;
- fiat_secp256k1_addcarryx_u32(&x217, &x218, x216, x209, x212);
+ fiat_secp256k1_addcarryx_u32(&x217, &x218, x216, x212, x209);
uint32_t x219;
fiat_secp256k1_uint1 x220;
- fiat_secp256k1_addcarryx_u32(&x219, &x220, x218, x207, x210);
+ fiat_secp256k1_addcarryx_u32(&x219, &x220, x218, x210, x207);
uint32_t x221;
fiat_secp256k1_uint1 x222;
- fiat_secp256k1_addcarryx_u32(&x221, &x222, x220, x205, x208);
+ fiat_secp256k1_addcarryx_u32(&x221, &x222, x220, x208, x205);
uint32_t x223;
fiat_secp256k1_uint1 x224;
- fiat_secp256k1_addcarryx_u32(&x223, &x224, x222, x203, x206);
+ fiat_secp256k1_addcarryx_u32(&x223, &x224, x222, x206, x203);
uint32_t x225;
fiat_secp256k1_uint1 x226;
- fiat_secp256k1_addcarryx_u32(&x225, &x226, x224, x201, x204);
+ fiat_secp256k1_addcarryx_u32(&x225, &x226, x224, x204, x201);
uint32_t x227;
fiat_secp256k1_uint1 x228;
- fiat_secp256k1_addcarryx_u32(&x227, &x228, x226, x199, x202);
+ fiat_secp256k1_addcarryx_u32(&x227, &x228, x226, x202, x199);
uint32_t x229;
fiat_secp256k1_uint1 x230;
- fiat_secp256k1_addcarryx_u32(&x229, &x230, x228, 0x0, x200);
+ fiat_secp256k1_addcarryx_u32(&x229, &x230, x228, x200, 0x0);
uint32_t x231;
fiat_secp256k1_uint1 x232;
- fiat_secp256k1_addcarryx_u32(&x231, &x232, 0x0, x213, x181);
+ fiat_secp256k1_addcarryx_u32(&x231, &x232, 0x0, x181, x213);
uint32_t x233;
fiat_secp256k1_uint1 x234;
- fiat_secp256k1_addcarryx_u32(&x233, &x234, x232, x215, x183);
+ fiat_secp256k1_addcarryx_u32(&x233, &x234, x232, x183, x215);
uint32_t x235;
fiat_secp256k1_uint1 x236;
- fiat_secp256k1_addcarryx_u32(&x235, &x236, x234, x217, x185);
+ fiat_secp256k1_addcarryx_u32(&x235, &x236, x234, x185, x217);
uint32_t x237;
fiat_secp256k1_uint1 x238;
- fiat_secp256k1_addcarryx_u32(&x237, &x238, x236, x219, x187);
+ fiat_secp256k1_addcarryx_u32(&x237, &x238, x236, x187, x219);
uint32_t x239;
fiat_secp256k1_uint1 x240;
- fiat_secp256k1_addcarryx_u32(&x239, &x240, x238, x221, x189);
+ fiat_secp256k1_addcarryx_u32(&x239, &x240, x238, x189, x221);
uint32_t x241;
fiat_secp256k1_uint1 x242;
- fiat_secp256k1_addcarryx_u32(&x241, &x242, x240, x223, x191);
+ fiat_secp256k1_addcarryx_u32(&x241, &x242, x240, x191, x223);
uint32_t x243;
fiat_secp256k1_uint1 x244;
- fiat_secp256k1_addcarryx_u32(&x243, &x244, x242, x225, x193);
+ fiat_secp256k1_addcarryx_u32(&x243, &x244, x242, x193, x225);
uint32_t x245;
fiat_secp256k1_uint1 x246;
- fiat_secp256k1_addcarryx_u32(&x245, &x246, x244, x227, x195);
+ fiat_secp256k1_addcarryx_u32(&x245, &x246, x244, x195, x227);
uint32_t x247;
fiat_secp256k1_uint1 x248;
- fiat_secp256k1_addcarryx_u32(&x247, &x248, x246, x229, x197);
+ fiat_secp256k1_addcarryx_u32(&x247, &x248, x246, x197, x229);
uint32_t x249;
uint32_t x250;
fiat_secp256k1_mulx_u32(&x249, &x250, x231, UINT32_C(0xd2253531));
@@ -513,58 +513,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x265, &x266, x249, UINT32_C(0xfffffc2f));
uint32_t x267;
fiat_secp256k1_uint1 x268;
- fiat_secp256k1_addcarryx_u32(&x267, &x268, 0x0, x263, x266);
+ fiat_secp256k1_addcarryx_u32(&x267, &x268, 0x0, x266, x263);
uint32_t x269;
fiat_secp256k1_uint1 x270;
- fiat_secp256k1_addcarryx_u32(&x269, &x270, x268, x261, x264);
+ fiat_secp256k1_addcarryx_u32(&x269, &x270, x268, x264, x261);
uint32_t x271;
fiat_secp256k1_uint1 x272;
- fiat_secp256k1_addcarryx_u32(&x271, &x272, x270, x259, x262);
+ fiat_secp256k1_addcarryx_u32(&x271, &x272, x270, x262, x259);
uint32_t x273;
fiat_secp256k1_uint1 x274;
- fiat_secp256k1_addcarryx_u32(&x273, &x274, x272, x257, x260);
+ fiat_secp256k1_addcarryx_u32(&x273, &x274, x272, x260, x257);
uint32_t x275;
fiat_secp256k1_uint1 x276;
- fiat_secp256k1_addcarryx_u32(&x275, &x276, x274, x255, x258);
+ fiat_secp256k1_addcarryx_u32(&x275, &x276, x274, x258, x255);
uint32_t x277;
fiat_secp256k1_uint1 x278;
- fiat_secp256k1_addcarryx_u32(&x277, &x278, x276, x253, x256);
+ fiat_secp256k1_addcarryx_u32(&x277, &x278, x276, x256, x253);
uint32_t x279;
fiat_secp256k1_uint1 x280;
- fiat_secp256k1_addcarryx_u32(&x279, &x280, x278, x251, x254);
+ fiat_secp256k1_addcarryx_u32(&x279, &x280, x278, x254, x251);
uint32_t x281;
fiat_secp256k1_uint1 x282;
- fiat_secp256k1_addcarryx_u32(&x281, &x282, x280, 0x0, x252);
+ fiat_secp256k1_addcarryx_u32(&x281, &x282, x280, x252, 0x0);
uint32_t x283;
fiat_secp256k1_uint1 x284;
- fiat_secp256k1_addcarryx_u32(&x283, &x284, 0x0, x265, x231);
+ fiat_secp256k1_addcarryx_u32(&x283, &x284, 0x0, x231, x265);
uint32_t x285;
fiat_secp256k1_uint1 x286;
- fiat_secp256k1_addcarryx_u32(&x285, &x286, x284, x267, x233);
+ fiat_secp256k1_addcarryx_u32(&x285, &x286, x284, x233, x267);
uint32_t x287;
fiat_secp256k1_uint1 x288;
- fiat_secp256k1_addcarryx_u32(&x287, &x288, x286, x269, x235);
+ fiat_secp256k1_addcarryx_u32(&x287, &x288, x286, x235, x269);
uint32_t x289;
fiat_secp256k1_uint1 x290;
- fiat_secp256k1_addcarryx_u32(&x289, &x290, x288, x271, x237);
+ fiat_secp256k1_addcarryx_u32(&x289, &x290, x288, x237, x271);
uint32_t x291;
fiat_secp256k1_uint1 x292;
- fiat_secp256k1_addcarryx_u32(&x291, &x292, x290, x273, x239);
+ fiat_secp256k1_addcarryx_u32(&x291, &x292, x290, x239, x273);
uint32_t x293;
fiat_secp256k1_uint1 x294;
- fiat_secp256k1_addcarryx_u32(&x293, &x294, x292, x275, x241);
+ fiat_secp256k1_addcarryx_u32(&x293, &x294, x292, x241, x275);
uint32_t x295;
fiat_secp256k1_uint1 x296;
- fiat_secp256k1_addcarryx_u32(&x295, &x296, x294, x277, x243);
+ fiat_secp256k1_addcarryx_u32(&x295, &x296, x294, x243, x277);
uint32_t x297;
fiat_secp256k1_uint1 x298;
- fiat_secp256k1_addcarryx_u32(&x297, &x298, x296, x279, x245);
+ fiat_secp256k1_addcarryx_u32(&x297, &x298, x296, x245, x279);
uint32_t x299;
fiat_secp256k1_uint1 x300;
- fiat_secp256k1_addcarryx_u32(&x299, &x300, x298, x281, x247);
+ fiat_secp256k1_addcarryx_u32(&x299, &x300, x298, x247, x281);
uint32_t x301;
fiat_secp256k1_uint1 x302;
- fiat_secp256k1_addcarryx_u32(&x301, &x302, x300, 0x0, x248);
+ fiat_secp256k1_addcarryx_u32(&x301, &x302, x300, x248, 0x0);
uint32_t x303;
uint32_t x304;
fiat_secp256k1_mulx_u32(&x303, &x304, x3, (arg2[7]));
@@ -591,55 +591,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x317, &x318, x3, (arg2[0]));
uint32_t x319;
fiat_secp256k1_uint1 x320;
- fiat_secp256k1_addcarryx_u32(&x319, &x320, 0x0, x315, x318);
+ fiat_secp256k1_addcarryx_u32(&x319, &x320, 0x0, x318, x315);
uint32_t x321;
fiat_secp256k1_uint1 x322;
- fiat_secp256k1_addcarryx_u32(&x321, &x322, x320, x313, x316);
+ fiat_secp256k1_addcarryx_u32(&x321, &x322, x320, x316, x313);
uint32_t x323;
fiat_secp256k1_uint1 x324;
- fiat_secp256k1_addcarryx_u32(&x323, &x324, x322, x311, x314);
+ fiat_secp256k1_addcarryx_u32(&x323, &x324, x322, x314, x311);
uint32_t x325;
fiat_secp256k1_uint1 x326;
- fiat_secp256k1_addcarryx_u32(&x325, &x326, x324, x309, x312);
+ fiat_secp256k1_addcarryx_u32(&x325, &x326, x324, x312, x309);
uint32_t x327;
fiat_secp256k1_uint1 x328;
- fiat_secp256k1_addcarryx_u32(&x327, &x328, x326, x307, x310);
+ fiat_secp256k1_addcarryx_u32(&x327, &x328, x326, x310, x307);
uint32_t x329;
fiat_secp256k1_uint1 x330;
- fiat_secp256k1_addcarryx_u32(&x329, &x330, x328, x305, x308);
+ fiat_secp256k1_addcarryx_u32(&x329, &x330, x328, x308, x305);
uint32_t x331;
fiat_secp256k1_uint1 x332;
- fiat_secp256k1_addcarryx_u32(&x331, &x332, x330, x303, x306);
+ fiat_secp256k1_addcarryx_u32(&x331, &x332, x330, x306, x303);
uint32_t x333;
fiat_secp256k1_uint1 x334;
- fiat_secp256k1_addcarryx_u32(&x333, &x334, x332, 0x0, x304);
+ fiat_secp256k1_addcarryx_u32(&x333, &x334, x332, x304, 0x0);
uint32_t x335;
fiat_secp256k1_uint1 x336;
- fiat_secp256k1_addcarryx_u32(&x335, &x336, 0x0, x317, x285);
+ fiat_secp256k1_addcarryx_u32(&x335, &x336, 0x0, x285, x317);
uint32_t x337;
fiat_secp256k1_uint1 x338;
- fiat_secp256k1_addcarryx_u32(&x337, &x338, x336, x319, x287);
+ fiat_secp256k1_addcarryx_u32(&x337, &x338, x336, x287, x319);
uint32_t x339;
fiat_secp256k1_uint1 x340;
- fiat_secp256k1_addcarryx_u32(&x339, &x340, x338, x321, x289);
+ fiat_secp256k1_addcarryx_u32(&x339, &x340, x338, x289, x321);
uint32_t x341;
fiat_secp256k1_uint1 x342;
- fiat_secp256k1_addcarryx_u32(&x341, &x342, x340, x323, x291);
+ fiat_secp256k1_addcarryx_u32(&x341, &x342, x340, x291, x323);
uint32_t x343;
fiat_secp256k1_uint1 x344;
- fiat_secp256k1_addcarryx_u32(&x343, &x344, x342, x325, x293);
+ fiat_secp256k1_addcarryx_u32(&x343, &x344, x342, x293, x325);
uint32_t x345;
fiat_secp256k1_uint1 x346;
- fiat_secp256k1_addcarryx_u32(&x345, &x346, x344, x327, x295);
+ fiat_secp256k1_addcarryx_u32(&x345, &x346, x344, x295, x327);
uint32_t x347;
fiat_secp256k1_uint1 x348;
- fiat_secp256k1_addcarryx_u32(&x347, &x348, x346, x329, x297);
+ fiat_secp256k1_addcarryx_u32(&x347, &x348, x346, x297, x329);
uint32_t x349;
fiat_secp256k1_uint1 x350;
- fiat_secp256k1_addcarryx_u32(&x349, &x350, x348, x331, x299);
+ fiat_secp256k1_addcarryx_u32(&x349, &x350, x348, x299, x331);
uint32_t x351;
fiat_secp256k1_uint1 x352;
- fiat_secp256k1_addcarryx_u32(&x351, &x352, x350, x333, x301);
+ fiat_secp256k1_addcarryx_u32(&x351, &x352, x350, x301, x333);
uint32_t x353;
uint32_t x354;
fiat_secp256k1_mulx_u32(&x353, &x354, x335, UINT32_C(0xd2253531));
@@ -669,58 +669,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x369, &x370, x353, UINT32_C(0xfffffc2f));
uint32_t x371;
fiat_secp256k1_uint1 x372;
- fiat_secp256k1_addcarryx_u32(&x371, &x372, 0x0, x367, x370);
+ fiat_secp256k1_addcarryx_u32(&x371, &x372, 0x0, x370, x367);
uint32_t x373;
fiat_secp256k1_uint1 x374;
- fiat_secp256k1_addcarryx_u32(&x373, &x374, x372, x365, x368);
+ fiat_secp256k1_addcarryx_u32(&x373, &x374, x372, x368, x365);
uint32_t x375;
fiat_secp256k1_uint1 x376;
- fiat_secp256k1_addcarryx_u32(&x375, &x376, x374, x363, x366);
+ fiat_secp256k1_addcarryx_u32(&x375, &x376, x374, x366, x363);
uint32_t x377;
fiat_secp256k1_uint1 x378;
- fiat_secp256k1_addcarryx_u32(&x377, &x378, x376, x361, x364);
+ fiat_secp256k1_addcarryx_u32(&x377, &x378, x376, x364, x361);
uint32_t x379;
fiat_secp256k1_uint1 x380;
- fiat_secp256k1_addcarryx_u32(&x379, &x380, x378, x359, x362);
+ fiat_secp256k1_addcarryx_u32(&x379, &x380, x378, x362, x359);
uint32_t x381;
fiat_secp256k1_uint1 x382;
- fiat_secp256k1_addcarryx_u32(&x381, &x382, x380, x357, x360);
+ fiat_secp256k1_addcarryx_u32(&x381, &x382, x380, x360, x357);
uint32_t x383;
fiat_secp256k1_uint1 x384;
- fiat_secp256k1_addcarryx_u32(&x383, &x384, x382, x355, x358);
+ fiat_secp256k1_addcarryx_u32(&x383, &x384, x382, x358, x355);
uint32_t x385;
fiat_secp256k1_uint1 x386;
- fiat_secp256k1_addcarryx_u32(&x385, &x386, x384, 0x0, x356);
+ fiat_secp256k1_addcarryx_u32(&x385, &x386, x384, x356, 0x0);
uint32_t x387;
fiat_secp256k1_uint1 x388;
- fiat_secp256k1_addcarryx_u32(&x387, &x388, 0x0, x369, x335);
+ fiat_secp256k1_addcarryx_u32(&x387, &x388, 0x0, x335, x369);
uint32_t x389;
fiat_secp256k1_uint1 x390;
- fiat_secp256k1_addcarryx_u32(&x389, &x390, x388, x371, x337);
+ fiat_secp256k1_addcarryx_u32(&x389, &x390, x388, x337, x371);
uint32_t x391;
fiat_secp256k1_uint1 x392;
- fiat_secp256k1_addcarryx_u32(&x391, &x392, x390, x373, x339);
+ fiat_secp256k1_addcarryx_u32(&x391, &x392, x390, x339, x373);
uint32_t x393;
fiat_secp256k1_uint1 x394;
- fiat_secp256k1_addcarryx_u32(&x393, &x394, x392, x375, x341);
+ fiat_secp256k1_addcarryx_u32(&x393, &x394, x392, x341, x375);
uint32_t x395;
fiat_secp256k1_uint1 x396;
- fiat_secp256k1_addcarryx_u32(&x395, &x396, x394, x377, x343);
+ fiat_secp256k1_addcarryx_u32(&x395, &x396, x394, x343, x377);
uint32_t x397;
fiat_secp256k1_uint1 x398;
- fiat_secp256k1_addcarryx_u32(&x397, &x398, x396, x379, x345);
+ fiat_secp256k1_addcarryx_u32(&x397, &x398, x396, x345, x379);
uint32_t x399;
fiat_secp256k1_uint1 x400;
- fiat_secp256k1_addcarryx_u32(&x399, &x400, x398, x381, x347);
+ fiat_secp256k1_addcarryx_u32(&x399, &x400, x398, x347, x381);
uint32_t x401;
fiat_secp256k1_uint1 x402;
- fiat_secp256k1_addcarryx_u32(&x401, &x402, x400, x383, x349);
+ fiat_secp256k1_addcarryx_u32(&x401, &x402, x400, x349, x383);
uint32_t x403;
fiat_secp256k1_uint1 x404;
- fiat_secp256k1_addcarryx_u32(&x403, &x404, x402, x385, x351);
+ fiat_secp256k1_addcarryx_u32(&x403, &x404, x402, x351, x385);
uint32_t x405;
fiat_secp256k1_uint1 x406;
- fiat_secp256k1_addcarryx_u32(&x405, &x406, x404, 0x0, x352);
+ fiat_secp256k1_addcarryx_u32(&x405, &x406, x404, x352, 0x0);
uint32_t x407;
uint32_t x408;
fiat_secp256k1_mulx_u32(&x407, &x408, x4, (arg2[7]));
@@ -747,55 +747,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x421, &x422, x4, (arg2[0]));
uint32_t x423;
fiat_secp256k1_uint1 x424;
- fiat_secp256k1_addcarryx_u32(&x423, &x424, 0x0, x419, x422);
+ fiat_secp256k1_addcarryx_u32(&x423, &x424, 0x0, x422, x419);
uint32_t x425;
fiat_secp256k1_uint1 x426;
- fiat_secp256k1_addcarryx_u32(&x425, &x426, x424, x417, x420);
+ fiat_secp256k1_addcarryx_u32(&x425, &x426, x424, x420, x417);
uint32_t x427;
fiat_secp256k1_uint1 x428;
- fiat_secp256k1_addcarryx_u32(&x427, &x428, x426, x415, x418);
+ fiat_secp256k1_addcarryx_u32(&x427, &x428, x426, x418, x415);
uint32_t x429;
fiat_secp256k1_uint1 x430;
- fiat_secp256k1_addcarryx_u32(&x429, &x430, x428, x413, x416);
+ fiat_secp256k1_addcarryx_u32(&x429, &x430, x428, x416, x413);
uint32_t x431;
fiat_secp256k1_uint1 x432;
- fiat_secp256k1_addcarryx_u32(&x431, &x432, x430, x411, x414);
+ fiat_secp256k1_addcarryx_u32(&x431, &x432, x430, x414, x411);
uint32_t x433;
fiat_secp256k1_uint1 x434;
- fiat_secp256k1_addcarryx_u32(&x433, &x434, x432, x409, x412);
+ fiat_secp256k1_addcarryx_u32(&x433, &x434, x432, x412, x409);
uint32_t x435;
fiat_secp256k1_uint1 x436;
- fiat_secp256k1_addcarryx_u32(&x435, &x436, x434, x407, x410);
+ fiat_secp256k1_addcarryx_u32(&x435, &x436, x434, x410, x407);
uint32_t x437;
fiat_secp256k1_uint1 x438;
- fiat_secp256k1_addcarryx_u32(&x437, &x438, x436, 0x0, x408);
+ fiat_secp256k1_addcarryx_u32(&x437, &x438, x436, x408, 0x0);
uint32_t x439;
fiat_secp256k1_uint1 x440;
- fiat_secp256k1_addcarryx_u32(&x439, &x440, 0x0, x421, x389);
+ fiat_secp256k1_addcarryx_u32(&x439, &x440, 0x0, x389, x421);
uint32_t x441;
fiat_secp256k1_uint1 x442;
- fiat_secp256k1_addcarryx_u32(&x441, &x442, x440, x423, x391);
+ fiat_secp256k1_addcarryx_u32(&x441, &x442, x440, x391, x423);
uint32_t x443;
fiat_secp256k1_uint1 x444;
- fiat_secp256k1_addcarryx_u32(&x443, &x444, x442, x425, x393);
+ fiat_secp256k1_addcarryx_u32(&x443, &x444, x442, x393, x425);
uint32_t x445;
fiat_secp256k1_uint1 x446;
- fiat_secp256k1_addcarryx_u32(&x445, &x446, x444, x427, x395);
+ fiat_secp256k1_addcarryx_u32(&x445, &x446, x444, x395, x427);
uint32_t x447;
fiat_secp256k1_uint1 x448;
- fiat_secp256k1_addcarryx_u32(&x447, &x448, x446, x429, x397);
+ fiat_secp256k1_addcarryx_u32(&x447, &x448, x446, x397, x429);
uint32_t x449;
fiat_secp256k1_uint1 x450;
- fiat_secp256k1_addcarryx_u32(&x449, &x450, x448, x431, x399);
+ fiat_secp256k1_addcarryx_u32(&x449, &x450, x448, x399, x431);
uint32_t x451;
fiat_secp256k1_uint1 x452;
- fiat_secp256k1_addcarryx_u32(&x451, &x452, x450, x433, x401);
+ fiat_secp256k1_addcarryx_u32(&x451, &x452, x450, x401, x433);
uint32_t x453;
fiat_secp256k1_uint1 x454;
- fiat_secp256k1_addcarryx_u32(&x453, &x454, x452, x435, x403);
+ fiat_secp256k1_addcarryx_u32(&x453, &x454, x452, x403, x435);
uint32_t x455;
fiat_secp256k1_uint1 x456;
- fiat_secp256k1_addcarryx_u32(&x455, &x456, x454, x437, x405);
+ fiat_secp256k1_addcarryx_u32(&x455, &x456, x454, x405, x437);
uint32_t x457;
uint32_t x458;
fiat_secp256k1_mulx_u32(&x457, &x458, x439, UINT32_C(0xd2253531));
@@ -825,58 +825,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x473, &x474, x457, UINT32_C(0xfffffc2f));
uint32_t x475;
fiat_secp256k1_uint1 x476;
- fiat_secp256k1_addcarryx_u32(&x475, &x476, 0x0, x471, x474);
+ fiat_secp256k1_addcarryx_u32(&x475, &x476, 0x0, x474, x471);
uint32_t x477;
fiat_secp256k1_uint1 x478;
- fiat_secp256k1_addcarryx_u32(&x477, &x478, x476, x469, x472);
+ fiat_secp256k1_addcarryx_u32(&x477, &x478, x476, x472, x469);
uint32_t x479;
fiat_secp256k1_uint1 x480;
- fiat_secp256k1_addcarryx_u32(&x479, &x480, x478, x467, x470);
+ fiat_secp256k1_addcarryx_u32(&x479, &x480, x478, x470, x467);
uint32_t x481;
fiat_secp256k1_uint1 x482;
- fiat_secp256k1_addcarryx_u32(&x481, &x482, x480, x465, x468);
+ fiat_secp256k1_addcarryx_u32(&x481, &x482, x480, x468, x465);
uint32_t x483;
fiat_secp256k1_uint1 x484;
- fiat_secp256k1_addcarryx_u32(&x483, &x484, x482, x463, x466);
+ fiat_secp256k1_addcarryx_u32(&x483, &x484, x482, x466, x463);
uint32_t x485;
fiat_secp256k1_uint1 x486;
- fiat_secp256k1_addcarryx_u32(&x485, &x486, x484, x461, x464);
+ fiat_secp256k1_addcarryx_u32(&x485, &x486, x484, x464, x461);
uint32_t x487;
fiat_secp256k1_uint1 x488;
- fiat_secp256k1_addcarryx_u32(&x487, &x488, x486, x459, x462);
+ fiat_secp256k1_addcarryx_u32(&x487, &x488, x486, x462, x459);
uint32_t x489;
fiat_secp256k1_uint1 x490;
- fiat_secp256k1_addcarryx_u32(&x489, &x490, x488, 0x0, x460);
+ fiat_secp256k1_addcarryx_u32(&x489, &x490, x488, x460, 0x0);
uint32_t x491;
fiat_secp256k1_uint1 x492;
- fiat_secp256k1_addcarryx_u32(&x491, &x492, 0x0, x473, x439);
+ fiat_secp256k1_addcarryx_u32(&x491, &x492, 0x0, x439, x473);
uint32_t x493;
fiat_secp256k1_uint1 x494;
- fiat_secp256k1_addcarryx_u32(&x493, &x494, x492, x475, x441);
+ fiat_secp256k1_addcarryx_u32(&x493, &x494, x492, x441, x475);
uint32_t x495;
fiat_secp256k1_uint1 x496;
- fiat_secp256k1_addcarryx_u32(&x495, &x496, x494, x477, x443);
+ fiat_secp256k1_addcarryx_u32(&x495, &x496, x494, x443, x477);
uint32_t x497;
fiat_secp256k1_uint1 x498;
- fiat_secp256k1_addcarryx_u32(&x497, &x498, x496, x479, x445);
+ fiat_secp256k1_addcarryx_u32(&x497, &x498, x496, x445, x479);
uint32_t x499;
fiat_secp256k1_uint1 x500;
- fiat_secp256k1_addcarryx_u32(&x499, &x500, x498, x481, x447);
+ fiat_secp256k1_addcarryx_u32(&x499, &x500, x498, x447, x481);
uint32_t x501;
fiat_secp256k1_uint1 x502;
- fiat_secp256k1_addcarryx_u32(&x501, &x502, x500, x483, x449);
+ fiat_secp256k1_addcarryx_u32(&x501, &x502, x500, x449, x483);
uint32_t x503;
fiat_secp256k1_uint1 x504;
- fiat_secp256k1_addcarryx_u32(&x503, &x504, x502, x485, x451);
+ fiat_secp256k1_addcarryx_u32(&x503, &x504, x502, x451, x485);
uint32_t x505;
fiat_secp256k1_uint1 x506;
- fiat_secp256k1_addcarryx_u32(&x505, &x506, x504, x487, x453);
+ fiat_secp256k1_addcarryx_u32(&x505, &x506, x504, x453, x487);
uint32_t x507;
fiat_secp256k1_uint1 x508;
- fiat_secp256k1_addcarryx_u32(&x507, &x508, x506, x489, x455);
+ fiat_secp256k1_addcarryx_u32(&x507, &x508, x506, x455, x489);
uint32_t x509;
fiat_secp256k1_uint1 x510;
- fiat_secp256k1_addcarryx_u32(&x509, &x510, x508, 0x0, x456);
+ fiat_secp256k1_addcarryx_u32(&x509, &x510, x508, x456, 0x0);
uint32_t x511;
uint32_t x512;
fiat_secp256k1_mulx_u32(&x511, &x512, x5, (arg2[7]));
@@ -903,55 +903,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x525, &x526, x5, (arg2[0]));
uint32_t x527;
fiat_secp256k1_uint1 x528;
- fiat_secp256k1_addcarryx_u32(&x527, &x528, 0x0, x523, x526);
+ fiat_secp256k1_addcarryx_u32(&x527, &x528, 0x0, x526, x523);
uint32_t x529;
fiat_secp256k1_uint1 x530;
- fiat_secp256k1_addcarryx_u32(&x529, &x530, x528, x521, x524);
+ fiat_secp256k1_addcarryx_u32(&x529, &x530, x528, x524, x521);
uint32_t x531;
fiat_secp256k1_uint1 x532;
- fiat_secp256k1_addcarryx_u32(&x531, &x532, x530, x519, x522);
+ fiat_secp256k1_addcarryx_u32(&x531, &x532, x530, x522, x519);
uint32_t x533;
fiat_secp256k1_uint1 x534;
- fiat_secp256k1_addcarryx_u32(&x533, &x534, x532, x517, x520);
+ fiat_secp256k1_addcarryx_u32(&x533, &x534, x532, x520, x517);
uint32_t x535;
fiat_secp256k1_uint1 x536;
- fiat_secp256k1_addcarryx_u32(&x535, &x536, x534, x515, x518);
+ fiat_secp256k1_addcarryx_u32(&x535, &x536, x534, x518, x515);
uint32_t x537;
fiat_secp256k1_uint1 x538;
- fiat_secp256k1_addcarryx_u32(&x537, &x538, x536, x513, x516);
+ fiat_secp256k1_addcarryx_u32(&x537, &x538, x536, x516, x513);
uint32_t x539;
fiat_secp256k1_uint1 x540;
- fiat_secp256k1_addcarryx_u32(&x539, &x540, x538, x511, x514);
+ fiat_secp256k1_addcarryx_u32(&x539, &x540, x538, x514, x511);
uint32_t x541;
fiat_secp256k1_uint1 x542;
- fiat_secp256k1_addcarryx_u32(&x541, &x542, x540, 0x0, x512);
+ fiat_secp256k1_addcarryx_u32(&x541, &x542, x540, x512, 0x0);
uint32_t x543;
fiat_secp256k1_uint1 x544;
- fiat_secp256k1_addcarryx_u32(&x543, &x544, 0x0, x525, x493);
+ fiat_secp256k1_addcarryx_u32(&x543, &x544, 0x0, x493, x525);
uint32_t x545;
fiat_secp256k1_uint1 x546;
- fiat_secp256k1_addcarryx_u32(&x545, &x546, x544, x527, x495);
+ fiat_secp256k1_addcarryx_u32(&x545, &x546, x544, x495, x527);
uint32_t x547;
fiat_secp256k1_uint1 x548;
- fiat_secp256k1_addcarryx_u32(&x547, &x548, x546, x529, x497);
+ fiat_secp256k1_addcarryx_u32(&x547, &x548, x546, x497, x529);
uint32_t x549;
fiat_secp256k1_uint1 x550;
- fiat_secp256k1_addcarryx_u32(&x549, &x550, x548, x531, x499);
+ fiat_secp256k1_addcarryx_u32(&x549, &x550, x548, x499, x531);
uint32_t x551;
fiat_secp256k1_uint1 x552;
- fiat_secp256k1_addcarryx_u32(&x551, &x552, x550, x533, x501);
+ fiat_secp256k1_addcarryx_u32(&x551, &x552, x550, x501, x533);
uint32_t x553;
fiat_secp256k1_uint1 x554;
- fiat_secp256k1_addcarryx_u32(&x553, &x554, x552, x535, x503);
+ fiat_secp256k1_addcarryx_u32(&x553, &x554, x552, x503, x535);
uint32_t x555;
fiat_secp256k1_uint1 x556;
- fiat_secp256k1_addcarryx_u32(&x555, &x556, x554, x537, x505);
+ fiat_secp256k1_addcarryx_u32(&x555, &x556, x554, x505, x537);
uint32_t x557;
fiat_secp256k1_uint1 x558;
- fiat_secp256k1_addcarryx_u32(&x557, &x558, x556, x539, x507);
+ fiat_secp256k1_addcarryx_u32(&x557, &x558, x556, x507, x539);
uint32_t x559;
fiat_secp256k1_uint1 x560;
- fiat_secp256k1_addcarryx_u32(&x559, &x560, x558, x541, x509);
+ fiat_secp256k1_addcarryx_u32(&x559, &x560, x558, x509, x541);
uint32_t x561;
uint32_t x562;
fiat_secp256k1_mulx_u32(&x561, &x562, x543, UINT32_C(0xd2253531));
@@ -981,58 +981,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x577, &x578, x561, UINT32_C(0xfffffc2f));
uint32_t x579;
fiat_secp256k1_uint1 x580;
- fiat_secp256k1_addcarryx_u32(&x579, &x580, 0x0, x575, x578);
+ fiat_secp256k1_addcarryx_u32(&x579, &x580, 0x0, x578, x575);
uint32_t x581;
fiat_secp256k1_uint1 x582;
- fiat_secp256k1_addcarryx_u32(&x581, &x582, x580, x573, x576);
+ fiat_secp256k1_addcarryx_u32(&x581, &x582, x580, x576, x573);
uint32_t x583;
fiat_secp256k1_uint1 x584;
- fiat_secp256k1_addcarryx_u32(&x583, &x584, x582, x571, x574);
+ fiat_secp256k1_addcarryx_u32(&x583, &x584, x582, x574, x571);
uint32_t x585;
fiat_secp256k1_uint1 x586;
- fiat_secp256k1_addcarryx_u32(&x585, &x586, x584, x569, x572);
+ fiat_secp256k1_addcarryx_u32(&x585, &x586, x584, x572, x569);
uint32_t x587;
fiat_secp256k1_uint1 x588;
- fiat_secp256k1_addcarryx_u32(&x587, &x588, x586, x567, x570);
+ fiat_secp256k1_addcarryx_u32(&x587, &x588, x586, x570, x567);
uint32_t x589;
fiat_secp256k1_uint1 x590;
- fiat_secp256k1_addcarryx_u32(&x589, &x590, x588, x565, x568);
+ fiat_secp256k1_addcarryx_u32(&x589, &x590, x588, x568, x565);
uint32_t x591;
fiat_secp256k1_uint1 x592;
- fiat_secp256k1_addcarryx_u32(&x591, &x592, x590, x563, x566);
+ fiat_secp256k1_addcarryx_u32(&x591, &x592, x590, x566, x563);
uint32_t x593;
fiat_secp256k1_uint1 x594;
- fiat_secp256k1_addcarryx_u32(&x593, &x594, x592, 0x0, x564);
+ fiat_secp256k1_addcarryx_u32(&x593, &x594, x592, x564, 0x0);
uint32_t x595;
fiat_secp256k1_uint1 x596;
- fiat_secp256k1_addcarryx_u32(&x595, &x596, 0x0, x577, x543);
+ fiat_secp256k1_addcarryx_u32(&x595, &x596, 0x0, x543, x577);
uint32_t x597;
fiat_secp256k1_uint1 x598;
- fiat_secp256k1_addcarryx_u32(&x597, &x598, x596, x579, x545);
+ fiat_secp256k1_addcarryx_u32(&x597, &x598, x596, x545, x579);
uint32_t x599;
fiat_secp256k1_uint1 x600;
- fiat_secp256k1_addcarryx_u32(&x599, &x600, x598, x581, x547);
+ fiat_secp256k1_addcarryx_u32(&x599, &x600, x598, x547, x581);
uint32_t x601;
fiat_secp256k1_uint1 x602;
- fiat_secp256k1_addcarryx_u32(&x601, &x602, x600, x583, x549);
+ fiat_secp256k1_addcarryx_u32(&x601, &x602, x600, x549, x583);
uint32_t x603;
fiat_secp256k1_uint1 x604;
- fiat_secp256k1_addcarryx_u32(&x603, &x604, x602, x585, x551);
+ fiat_secp256k1_addcarryx_u32(&x603, &x604, x602, x551, x585);
uint32_t x605;
fiat_secp256k1_uint1 x606;
- fiat_secp256k1_addcarryx_u32(&x605, &x606, x604, x587, x553);
+ fiat_secp256k1_addcarryx_u32(&x605, &x606, x604, x553, x587);
uint32_t x607;
fiat_secp256k1_uint1 x608;
- fiat_secp256k1_addcarryx_u32(&x607, &x608, x606, x589, x555);
+ fiat_secp256k1_addcarryx_u32(&x607, &x608, x606, x555, x589);
uint32_t x609;
fiat_secp256k1_uint1 x610;
- fiat_secp256k1_addcarryx_u32(&x609, &x610, x608, x591, x557);
+ fiat_secp256k1_addcarryx_u32(&x609, &x610, x608, x557, x591);
uint32_t x611;
fiat_secp256k1_uint1 x612;
- fiat_secp256k1_addcarryx_u32(&x611, &x612, x610, x593, x559);
+ fiat_secp256k1_addcarryx_u32(&x611, &x612, x610, x559, x593);
uint32_t x613;
fiat_secp256k1_uint1 x614;
- fiat_secp256k1_addcarryx_u32(&x613, &x614, x612, 0x0, x560);
+ fiat_secp256k1_addcarryx_u32(&x613, &x614, x612, x560, 0x0);
uint32_t x615;
uint32_t x616;
fiat_secp256k1_mulx_u32(&x615, &x616, x6, (arg2[7]));
@@ -1059,55 +1059,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x629, &x630, x6, (arg2[0]));
uint32_t x631;
fiat_secp256k1_uint1 x632;
- fiat_secp256k1_addcarryx_u32(&x631, &x632, 0x0, x627, x630);
+ fiat_secp256k1_addcarryx_u32(&x631, &x632, 0x0, x630, x627);
uint32_t x633;
fiat_secp256k1_uint1 x634;
- fiat_secp256k1_addcarryx_u32(&x633, &x634, x632, x625, x628);
+ fiat_secp256k1_addcarryx_u32(&x633, &x634, x632, x628, x625);
uint32_t x635;
fiat_secp256k1_uint1 x636;
- fiat_secp256k1_addcarryx_u32(&x635, &x636, x634, x623, x626);
+ fiat_secp256k1_addcarryx_u32(&x635, &x636, x634, x626, x623);
uint32_t x637;
fiat_secp256k1_uint1 x638;
- fiat_secp256k1_addcarryx_u32(&x637, &x638, x636, x621, x624);
+ fiat_secp256k1_addcarryx_u32(&x637, &x638, x636, x624, x621);
uint32_t x639;
fiat_secp256k1_uint1 x640;
- fiat_secp256k1_addcarryx_u32(&x639, &x640, x638, x619, x622);
+ fiat_secp256k1_addcarryx_u32(&x639, &x640, x638, x622, x619);
uint32_t x641;
fiat_secp256k1_uint1 x642;
- fiat_secp256k1_addcarryx_u32(&x641, &x642, x640, x617, x620);
+ fiat_secp256k1_addcarryx_u32(&x641, &x642, x640, x620, x617);
uint32_t x643;
fiat_secp256k1_uint1 x644;
- fiat_secp256k1_addcarryx_u32(&x643, &x644, x642, x615, x618);
+ fiat_secp256k1_addcarryx_u32(&x643, &x644, x642, x618, x615);
uint32_t x645;
fiat_secp256k1_uint1 x646;
- fiat_secp256k1_addcarryx_u32(&x645, &x646, x644, 0x0, x616);
+ fiat_secp256k1_addcarryx_u32(&x645, &x646, x644, x616, 0x0);
uint32_t x647;
fiat_secp256k1_uint1 x648;
- fiat_secp256k1_addcarryx_u32(&x647, &x648, 0x0, x629, x597);
+ fiat_secp256k1_addcarryx_u32(&x647, &x648, 0x0, x597, x629);
uint32_t x649;
fiat_secp256k1_uint1 x650;
- fiat_secp256k1_addcarryx_u32(&x649, &x650, x648, x631, x599);
+ fiat_secp256k1_addcarryx_u32(&x649, &x650, x648, x599, x631);
uint32_t x651;
fiat_secp256k1_uint1 x652;
- fiat_secp256k1_addcarryx_u32(&x651, &x652, x650, x633, x601);
+ fiat_secp256k1_addcarryx_u32(&x651, &x652, x650, x601, x633);
uint32_t x653;
fiat_secp256k1_uint1 x654;
- fiat_secp256k1_addcarryx_u32(&x653, &x654, x652, x635, x603);
+ fiat_secp256k1_addcarryx_u32(&x653, &x654, x652, x603, x635);
uint32_t x655;
fiat_secp256k1_uint1 x656;
- fiat_secp256k1_addcarryx_u32(&x655, &x656, x654, x637, x605);
+ fiat_secp256k1_addcarryx_u32(&x655, &x656, x654, x605, x637);
uint32_t x657;
fiat_secp256k1_uint1 x658;
- fiat_secp256k1_addcarryx_u32(&x657, &x658, x656, x639, x607);
+ fiat_secp256k1_addcarryx_u32(&x657, &x658, x656, x607, x639);
uint32_t x659;
fiat_secp256k1_uint1 x660;
- fiat_secp256k1_addcarryx_u32(&x659, &x660, x658, x641, x609);
+ fiat_secp256k1_addcarryx_u32(&x659, &x660, x658, x609, x641);
uint32_t x661;
fiat_secp256k1_uint1 x662;
- fiat_secp256k1_addcarryx_u32(&x661, &x662, x660, x643, x611);
+ fiat_secp256k1_addcarryx_u32(&x661, &x662, x660, x611, x643);
uint32_t x663;
fiat_secp256k1_uint1 x664;
- fiat_secp256k1_addcarryx_u32(&x663, &x664, x662, x645, x613);
+ fiat_secp256k1_addcarryx_u32(&x663, &x664, x662, x613, x645);
uint32_t x665;
uint32_t x666;
fiat_secp256k1_mulx_u32(&x665, &x666, x647, UINT32_C(0xd2253531));
@@ -1137,58 +1137,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x681, &x682, x665, UINT32_C(0xfffffc2f));
uint32_t x683;
fiat_secp256k1_uint1 x684;
- fiat_secp256k1_addcarryx_u32(&x683, &x684, 0x0, x679, x682);
+ fiat_secp256k1_addcarryx_u32(&x683, &x684, 0x0, x682, x679);
uint32_t x685;
fiat_secp256k1_uint1 x686;
- fiat_secp256k1_addcarryx_u32(&x685, &x686, x684, x677, x680);
+ fiat_secp256k1_addcarryx_u32(&x685, &x686, x684, x680, x677);
uint32_t x687;
fiat_secp256k1_uint1 x688;
- fiat_secp256k1_addcarryx_u32(&x687, &x688, x686, x675, x678);
+ fiat_secp256k1_addcarryx_u32(&x687, &x688, x686, x678, x675);
uint32_t x689;
fiat_secp256k1_uint1 x690;
- fiat_secp256k1_addcarryx_u32(&x689, &x690, x688, x673, x676);
+ fiat_secp256k1_addcarryx_u32(&x689, &x690, x688, x676, x673);
uint32_t x691;
fiat_secp256k1_uint1 x692;
- fiat_secp256k1_addcarryx_u32(&x691, &x692, x690, x671, x674);
+ fiat_secp256k1_addcarryx_u32(&x691, &x692, x690, x674, x671);
uint32_t x693;
fiat_secp256k1_uint1 x694;
- fiat_secp256k1_addcarryx_u32(&x693, &x694, x692, x669, x672);
+ fiat_secp256k1_addcarryx_u32(&x693, &x694, x692, x672, x669);
uint32_t x695;
fiat_secp256k1_uint1 x696;
- fiat_secp256k1_addcarryx_u32(&x695, &x696, x694, x667, x670);
+ fiat_secp256k1_addcarryx_u32(&x695, &x696, x694, x670, x667);
uint32_t x697;
fiat_secp256k1_uint1 x698;
- fiat_secp256k1_addcarryx_u32(&x697, &x698, x696, 0x0, x668);
+ fiat_secp256k1_addcarryx_u32(&x697, &x698, x696, x668, 0x0);
uint32_t x699;
fiat_secp256k1_uint1 x700;
- fiat_secp256k1_addcarryx_u32(&x699, &x700, 0x0, x681, x647);
+ fiat_secp256k1_addcarryx_u32(&x699, &x700, 0x0, x647, x681);
uint32_t x701;
fiat_secp256k1_uint1 x702;
- fiat_secp256k1_addcarryx_u32(&x701, &x702, x700, x683, x649);
+ fiat_secp256k1_addcarryx_u32(&x701, &x702, x700, x649, x683);
uint32_t x703;
fiat_secp256k1_uint1 x704;
- fiat_secp256k1_addcarryx_u32(&x703, &x704, x702, x685, x651);
+ fiat_secp256k1_addcarryx_u32(&x703, &x704, x702, x651, x685);
uint32_t x705;
fiat_secp256k1_uint1 x706;
- fiat_secp256k1_addcarryx_u32(&x705, &x706, x704, x687, x653);
+ fiat_secp256k1_addcarryx_u32(&x705, &x706, x704, x653, x687);
uint32_t x707;
fiat_secp256k1_uint1 x708;
- fiat_secp256k1_addcarryx_u32(&x707, &x708, x706, x689, x655);
+ fiat_secp256k1_addcarryx_u32(&x707, &x708, x706, x655, x689);
uint32_t x709;
fiat_secp256k1_uint1 x710;
- fiat_secp256k1_addcarryx_u32(&x709, &x710, x708, x691, x657);
+ fiat_secp256k1_addcarryx_u32(&x709, &x710, x708, x657, x691);
uint32_t x711;
fiat_secp256k1_uint1 x712;
- fiat_secp256k1_addcarryx_u32(&x711, &x712, x710, x693, x659);
+ fiat_secp256k1_addcarryx_u32(&x711, &x712, x710, x659, x693);
uint32_t x713;
fiat_secp256k1_uint1 x714;
- fiat_secp256k1_addcarryx_u32(&x713, &x714, x712, x695, x661);
+ fiat_secp256k1_addcarryx_u32(&x713, &x714, x712, x661, x695);
uint32_t x715;
fiat_secp256k1_uint1 x716;
- fiat_secp256k1_addcarryx_u32(&x715, &x716, x714, x697, x663);
+ fiat_secp256k1_addcarryx_u32(&x715, &x716, x714, x663, x697);
uint32_t x717;
fiat_secp256k1_uint1 x718;
- fiat_secp256k1_addcarryx_u32(&x717, &x718, x716, 0x0, x664);
+ fiat_secp256k1_addcarryx_u32(&x717, &x718, x716, x664, 0x0);
uint32_t x719;
uint32_t x720;
fiat_secp256k1_mulx_u32(&x719, &x720, x7, (arg2[7]));
@@ -1215,55 +1215,55 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x733, &x734, x7, (arg2[0]));
uint32_t x735;
fiat_secp256k1_uint1 x736;
- fiat_secp256k1_addcarryx_u32(&x735, &x736, 0x0, x731, x734);
+ fiat_secp256k1_addcarryx_u32(&x735, &x736, 0x0, x734, x731);
uint32_t x737;
fiat_secp256k1_uint1 x738;
- fiat_secp256k1_addcarryx_u32(&x737, &x738, x736, x729, x732);
+ fiat_secp256k1_addcarryx_u32(&x737, &x738, x736, x732, x729);
uint32_t x739;
fiat_secp256k1_uint1 x740;
- fiat_secp256k1_addcarryx_u32(&x739, &x740, x738, x727, x730);
+ fiat_secp256k1_addcarryx_u32(&x739, &x740, x738, x730, x727);
uint32_t x741;
fiat_secp256k1_uint1 x742;
- fiat_secp256k1_addcarryx_u32(&x741, &x742, x740, x725, x728);
+ fiat_secp256k1_addcarryx_u32(&x741, &x742, x740, x728, x725);
uint32_t x743;
fiat_secp256k1_uint1 x744;
- fiat_secp256k1_addcarryx_u32(&x743, &x744, x742, x723, x726);
+ fiat_secp256k1_addcarryx_u32(&x743, &x744, x742, x726, x723);
uint32_t x745;
fiat_secp256k1_uint1 x746;
- fiat_secp256k1_addcarryx_u32(&x745, &x746, x744, x721, x724);
+ fiat_secp256k1_addcarryx_u32(&x745, &x746, x744, x724, x721);
uint32_t x747;
fiat_secp256k1_uint1 x748;
- fiat_secp256k1_addcarryx_u32(&x747, &x748, x746, x719, x722);
+ fiat_secp256k1_addcarryx_u32(&x747, &x748, x746, x722, x719);
uint32_t x749;
fiat_secp256k1_uint1 x750;
- fiat_secp256k1_addcarryx_u32(&x749, &x750, x748, 0x0, x720);
+ fiat_secp256k1_addcarryx_u32(&x749, &x750, x748, x720, 0x0);
uint32_t x751;
fiat_secp256k1_uint1 x752;
- fiat_secp256k1_addcarryx_u32(&x751, &x752, 0x0, x733, x701);
+ fiat_secp256k1_addcarryx_u32(&x751, &x752, 0x0, x701, x733);
uint32_t x753;
fiat_secp256k1_uint1 x754;
- fiat_secp256k1_addcarryx_u32(&x753, &x754, x752, x735, x703);
+ fiat_secp256k1_addcarryx_u32(&x753, &x754, x752, x703, x735);
uint32_t x755;
fiat_secp256k1_uint1 x756;
- fiat_secp256k1_addcarryx_u32(&x755, &x756, x754, x737, x705);
+ fiat_secp256k1_addcarryx_u32(&x755, &x756, x754, x705, x737);
uint32_t x757;
fiat_secp256k1_uint1 x758;
- fiat_secp256k1_addcarryx_u32(&x757, &x758, x756, x739, x707);
+ fiat_secp256k1_addcarryx_u32(&x757, &x758, x756, x707, x739);
uint32_t x759;
fiat_secp256k1_uint1 x760;
- fiat_secp256k1_addcarryx_u32(&x759, &x760, x758, x741, x709);
+ fiat_secp256k1_addcarryx_u32(&x759, &x760, x758, x709, x741);
uint32_t x761;
fiat_secp256k1_uint1 x762;
- fiat_secp256k1_addcarryx_u32(&x761, &x762, x760, x743, x711);
+ fiat_secp256k1_addcarryx_u32(&x761, &x762, x760, x711, x743);
uint32_t x763;
fiat_secp256k1_uint1 x764;
- fiat_secp256k1_addcarryx_u32(&x763, &x764, x762, x745, x713);
+ fiat_secp256k1_addcarryx_u32(&x763, &x764, x762, x713, x745);
uint32_t x765;
fiat_secp256k1_uint1 x766;
- fiat_secp256k1_addcarryx_u32(&x765, &x766, x764, x747, x715);
+ fiat_secp256k1_addcarryx_u32(&x765, &x766, x764, x715, x747);
uint32_t x767;
fiat_secp256k1_uint1 x768;
- fiat_secp256k1_addcarryx_u32(&x767, &x768, x766, x749, x717);
+ fiat_secp256k1_addcarryx_u32(&x767, &x768, x766, x717, x749);
uint32_t x769;
uint32_t x770;
fiat_secp256k1_mulx_u32(&x769, &x770, x751, UINT32_C(0xd2253531));
@@ -1293,58 +1293,58 @@ static void fiat_secp256k1_mul(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_mulx_u32(&x785, &x786, x769, UINT32_C(0xfffffc2f));
uint32_t x787;
fiat_secp256k1_uint1 x788;
- fiat_secp256k1_addcarryx_u32(&x787, &x788, 0x0, x783, x786);
+ fiat_secp256k1_addcarryx_u32(&x787, &x788, 0x0, x786, x783);
uint32_t x789;
fiat_secp256k1_uint1 x790;
- fiat_secp256k1_addcarryx_u32(&x789, &x790, x788, x781, x784);
+ fiat_secp256k1_addcarryx_u32(&x789, &x790, x788, x784, x781);
uint32_t x791;
fiat_secp256k1_uint1 x792;
- fiat_secp256k1_addcarryx_u32(&x791, &x792, x790, x779, x782);
+ fiat_secp256k1_addcarryx_u32(&x791, &x792, x790, x782, x779);
uint32_t x793;
fiat_secp256k1_uint1 x794;
- fiat_secp256k1_addcarryx_u32(&x793, &x794, x792, x777, x780);
+ fiat_secp256k1_addcarryx_u32(&x793, &x794, x792, x780, x777);
uint32_t x795;
fiat_secp256k1_uint1 x796;
- fiat_secp256k1_addcarryx_u32(&x795, &x796, x794, x775, x778);
+ fiat_secp256k1_addcarryx_u32(&x795, &x796, x794, x778, x775);
uint32_t x797;
fiat_secp256k1_uint1 x798;
- fiat_secp256k1_addcarryx_u32(&x797, &x798, x796, x773, x776);
+ fiat_secp256k1_addcarryx_u32(&x797, &x798, x796, x776, x773);
uint32_t x799;
fiat_secp256k1_uint1 x800;
- fiat_secp256k1_addcarryx_u32(&x799, &x800, x798, x771, x774);
+ fiat_secp256k1_addcarryx_u32(&x799, &x800, x798, x774, x771);
uint32_t x801;
fiat_secp256k1_uint1 x802;
- fiat_secp256k1_addcarryx_u32(&x801, &x802, x800, 0x0, x772);
+ fiat_secp256k1_addcarryx_u32(&x801, &x802, x800, x772, 0x0);
uint32_t x803;
fiat_secp256k1_uint1 x804;
- fiat_secp256k1_addcarryx_u32(&x803, &x804, 0x0, x785, x751);
+ fiat_secp256k1_addcarryx_u32(&x803, &x804, 0x0, x751, x785);
uint32_t x805;
fiat_secp256k1_uint1 x806;
- fiat_secp256k1_addcarryx_u32(&x805, &x806, x804, x787, x753);
+ fiat_secp256k1_addcarryx_u32(&x805, &x806, x804, x753, x787);
uint32_t x807;
fiat_secp256k1_uint1 x808;
- fiat_secp256k1_addcarryx_u32(&x807, &x808, x806, x789, x755);
+ fiat_secp256k1_addcarryx_u32(&x807, &x808, x806, x755, x789);
uint32_t x809;
fiat_secp256k1_uint1 x810;
- fiat_secp256k1_addcarryx_u32(&x809, &x810, x808, x791, x757);
+ fiat_secp256k1_addcarryx_u32(&x809, &x810, x808, x757, x791);
uint32_t x811;
fiat_secp256k1_uint1 x812;
- fiat_secp256k1_addcarryx_u32(&x811, &x812, x810, x793, x759);
+ fiat_secp256k1_addcarryx_u32(&x811, &x812, x810, x759, x793);
uint32_t x813;
fiat_secp256k1_uint1 x814;
- fiat_secp256k1_addcarryx_u32(&x813, &x814, x812, x795, x761);
+ fiat_secp256k1_addcarryx_u32(&x813, &x814, x812, x761, x795);
uint32_t x815;
fiat_secp256k1_uint1 x816;
- fiat_secp256k1_addcarryx_u32(&x815, &x816, x814, x797, x763);
+ fiat_secp256k1_addcarryx_u32(&x815, &x816, x814, x763, x797);
uint32_t x817;
fiat_secp256k1_uint1 x818;
- fiat_secp256k1_addcarryx_u32(&x817, &x818, x816, x799, x765);
+ fiat_secp256k1_addcarryx_u32(&x817, &x818, x816, x765, x799);
uint32_t x819;
fiat_secp256k1_uint1 x820;
- fiat_secp256k1_addcarryx_u32(&x819, &x820, x818, x801, x767);
+ fiat_secp256k1_addcarryx_u32(&x819, &x820, x818, x767, x801);
uint32_t x821;
fiat_secp256k1_uint1 x822;
- fiat_secp256k1_addcarryx_u32(&x821, &x822, x820, 0x0, x768);
+ fiat_secp256k1_addcarryx_u32(&x821, &x822, x820, x768, 0x0);
uint32_t x823;
fiat_secp256k1_uint1 x824;
fiat_secp256k1_subborrowx_u32(&x823, &x824, 0x0, x805, UINT32_C(0xfffffc2f));
@@ -1446,28 +1446,28 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x23, &x24, x8, (arg1[0]));
uint32_t x25;
fiat_secp256k1_uint1 x26;
- fiat_secp256k1_addcarryx_u32(&x25, &x26, 0x0, x21, x24);
+ fiat_secp256k1_addcarryx_u32(&x25, &x26, 0x0, x24, x21);
uint32_t x27;
fiat_secp256k1_uint1 x28;
- fiat_secp256k1_addcarryx_u32(&x27, &x28, x26, x19, x22);
+ fiat_secp256k1_addcarryx_u32(&x27, &x28, x26, x22, x19);
uint32_t x29;
fiat_secp256k1_uint1 x30;
- fiat_secp256k1_addcarryx_u32(&x29, &x30, x28, x17, x20);
+ fiat_secp256k1_addcarryx_u32(&x29, &x30, x28, x20, x17);
uint32_t x31;
fiat_secp256k1_uint1 x32;
- fiat_secp256k1_addcarryx_u32(&x31, &x32, x30, x15, x18);
+ fiat_secp256k1_addcarryx_u32(&x31, &x32, x30, x18, x15);
uint32_t x33;
fiat_secp256k1_uint1 x34;
- fiat_secp256k1_addcarryx_u32(&x33, &x34, x32, x13, x16);
+ fiat_secp256k1_addcarryx_u32(&x33, &x34, x32, x16, x13);
uint32_t x35;
fiat_secp256k1_uint1 x36;
- fiat_secp256k1_addcarryx_u32(&x35, &x36, x34, x11, x14);
+ fiat_secp256k1_addcarryx_u32(&x35, &x36, x34, x14, x11);
uint32_t x37;
fiat_secp256k1_uint1 x38;
- fiat_secp256k1_addcarryx_u32(&x37, &x38, x36, x9, x12);
+ fiat_secp256k1_addcarryx_u32(&x37, &x38, x36, x12, x9);
uint32_t x39;
fiat_secp256k1_uint1 x40;
- fiat_secp256k1_addcarryx_u32(&x39, &x40, x38, 0x0, x10);
+ fiat_secp256k1_addcarryx_u32(&x39, &x40, x38, x10, 0x0);
uint32_t x41;
uint32_t x42;
fiat_secp256k1_mulx_u32(&x41, &x42, x23, UINT32_C(0xd2253531));
@@ -1497,55 +1497,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x57, &x58, x41, UINT32_C(0xfffffc2f));
uint32_t x59;
fiat_secp256k1_uint1 x60;
- fiat_secp256k1_addcarryx_u32(&x59, &x60, 0x0, x55, x58);
+ fiat_secp256k1_addcarryx_u32(&x59, &x60, 0x0, x58, x55);
uint32_t x61;
fiat_secp256k1_uint1 x62;
- fiat_secp256k1_addcarryx_u32(&x61, &x62, x60, x53, x56);
+ fiat_secp256k1_addcarryx_u32(&x61, &x62, x60, x56, x53);
uint32_t x63;
fiat_secp256k1_uint1 x64;
- fiat_secp256k1_addcarryx_u32(&x63, &x64, x62, x51, x54);
+ fiat_secp256k1_addcarryx_u32(&x63, &x64, x62, x54, x51);
uint32_t x65;
fiat_secp256k1_uint1 x66;
- fiat_secp256k1_addcarryx_u32(&x65, &x66, x64, x49, x52);
+ fiat_secp256k1_addcarryx_u32(&x65, &x66, x64, x52, x49);
uint32_t x67;
fiat_secp256k1_uint1 x68;
- fiat_secp256k1_addcarryx_u32(&x67, &x68, x66, x47, x50);
+ fiat_secp256k1_addcarryx_u32(&x67, &x68, x66, x50, x47);
uint32_t x69;
fiat_secp256k1_uint1 x70;
- fiat_secp256k1_addcarryx_u32(&x69, &x70, x68, x45, x48);
+ fiat_secp256k1_addcarryx_u32(&x69, &x70, x68, x48, x45);
uint32_t x71;
fiat_secp256k1_uint1 x72;
- fiat_secp256k1_addcarryx_u32(&x71, &x72, x70, x43, x46);
+ fiat_secp256k1_addcarryx_u32(&x71, &x72, x70, x46, x43);
uint32_t x73;
fiat_secp256k1_uint1 x74;
- fiat_secp256k1_addcarryx_u32(&x73, &x74, x72, 0x0, x44);
+ fiat_secp256k1_addcarryx_u32(&x73, &x74, x72, x44, 0x0);
uint32_t x75;
fiat_secp256k1_uint1 x76;
- fiat_secp256k1_addcarryx_u32(&x75, &x76, 0x0, x57, x23);
+ fiat_secp256k1_addcarryx_u32(&x75, &x76, 0x0, x23, x57);
uint32_t x77;
fiat_secp256k1_uint1 x78;
- fiat_secp256k1_addcarryx_u32(&x77, &x78, x76, x59, x25);
+ fiat_secp256k1_addcarryx_u32(&x77, &x78, x76, x25, x59);
uint32_t x79;
fiat_secp256k1_uint1 x80;
- fiat_secp256k1_addcarryx_u32(&x79, &x80, x78, x61, x27);
+ fiat_secp256k1_addcarryx_u32(&x79, &x80, x78, x27, x61);
uint32_t x81;
fiat_secp256k1_uint1 x82;
- fiat_secp256k1_addcarryx_u32(&x81, &x82, x80, x63, x29);
+ fiat_secp256k1_addcarryx_u32(&x81, &x82, x80, x29, x63);
uint32_t x83;
fiat_secp256k1_uint1 x84;
- fiat_secp256k1_addcarryx_u32(&x83, &x84, x82, x65, x31);
+ fiat_secp256k1_addcarryx_u32(&x83, &x84, x82, x31, x65);
uint32_t x85;
fiat_secp256k1_uint1 x86;
- fiat_secp256k1_addcarryx_u32(&x85, &x86, x84, x67, x33);
+ fiat_secp256k1_addcarryx_u32(&x85, &x86, x84, x33, x67);
uint32_t x87;
fiat_secp256k1_uint1 x88;
- fiat_secp256k1_addcarryx_u32(&x87, &x88, x86, x69, x35);
+ fiat_secp256k1_addcarryx_u32(&x87, &x88, x86, x35, x69);
uint32_t x89;
fiat_secp256k1_uint1 x90;
- fiat_secp256k1_addcarryx_u32(&x89, &x90, x88, x71, x37);
+ fiat_secp256k1_addcarryx_u32(&x89, &x90, x88, x37, x71);
uint32_t x91;
fiat_secp256k1_uint1 x92;
- fiat_secp256k1_addcarryx_u32(&x91, &x92, x90, x73, x39);
+ fiat_secp256k1_addcarryx_u32(&x91, &x92, x90, x39, x73);
uint32_t x93;
fiat_secp256k1_uint1 x94;
fiat_secp256k1_addcarryx_u32(&x93, &x94, x92, 0x0, 0x0);
@@ -1575,55 +1575,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x109, &x110, x1, (arg1[0]));
uint32_t x111;
fiat_secp256k1_uint1 x112;
- fiat_secp256k1_addcarryx_u32(&x111, &x112, 0x0, x107, x110);
+ fiat_secp256k1_addcarryx_u32(&x111, &x112, 0x0, x110, x107);
uint32_t x113;
fiat_secp256k1_uint1 x114;
- fiat_secp256k1_addcarryx_u32(&x113, &x114, x112, x105, x108);
+ fiat_secp256k1_addcarryx_u32(&x113, &x114, x112, x108, x105);
uint32_t x115;
fiat_secp256k1_uint1 x116;
- fiat_secp256k1_addcarryx_u32(&x115, &x116, x114, x103, x106);
+ fiat_secp256k1_addcarryx_u32(&x115, &x116, x114, x106, x103);
uint32_t x117;
fiat_secp256k1_uint1 x118;
- fiat_secp256k1_addcarryx_u32(&x117, &x118, x116, x101, x104);
+ fiat_secp256k1_addcarryx_u32(&x117, &x118, x116, x104, x101);
uint32_t x119;
fiat_secp256k1_uint1 x120;
- fiat_secp256k1_addcarryx_u32(&x119, &x120, x118, x99, x102);
+ fiat_secp256k1_addcarryx_u32(&x119, &x120, x118, x102, x99);
uint32_t x121;
fiat_secp256k1_uint1 x122;
- fiat_secp256k1_addcarryx_u32(&x121, &x122, x120, x97, x100);
+ fiat_secp256k1_addcarryx_u32(&x121, &x122, x120, x100, x97);
uint32_t x123;
fiat_secp256k1_uint1 x124;
- fiat_secp256k1_addcarryx_u32(&x123, &x124, x122, x95, x98);
+ fiat_secp256k1_addcarryx_u32(&x123, &x124, x122, x98, x95);
uint32_t x125;
fiat_secp256k1_uint1 x126;
- fiat_secp256k1_addcarryx_u32(&x125, &x126, x124, 0x0, x96);
+ fiat_secp256k1_addcarryx_u32(&x125, &x126, x124, x96, 0x0);
uint32_t x127;
fiat_secp256k1_uint1 x128;
- fiat_secp256k1_addcarryx_u32(&x127, &x128, 0x0, x109, x77);
+ fiat_secp256k1_addcarryx_u32(&x127, &x128, 0x0, x77, x109);
uint32_t x129;
fiat_secp256k1_uint1 x130;
- fiat_secp256k1_addcarryx_u32(&x129, &x130, x128, x111, x79);
+ fiat_secp256k1_addcarryx_u32(&x129, &x130, x128, x79, x111);
uint32_t x131;
fiat_secp256k1_uint1 x132;
- fiat_secp256k1_addcarryx_u32(&x131, &x132, x130, x113, x81);
+ fiat_secp256k1_addcarryx_u32(&x131, &x132, x130, x81, x113);
uint32_t x133;
fiat_secp256k1_uint1 x134;
- fiat_secp256k1_addcarryx_u32(&x133, &x134, x132, x115, x83);
+ fiat_secp256k1_addcarryx_u32(&x133, &x134, x132, x83, x115);
uint32_t x135;
fiat_secp256k1_uint1 x136;
- fiat_secp256k1_addcarryx_u32(&x135, &x136, x134, x117, x85);
+ fiat_secp256k1_addcarryx_u32(&x135, &x136, x134, x85, x117);
uint32_t x137;
fiat_secp256k1_uint1 x138;
- fiat_secp256k1_addcarryx_u32(&x137, &x138, x136, x119, x87);
+ fiat_secp256k1_addcarryx_u32(&x137, &x138, x136, x87, x119);
uint32_t x139;
fiat_secp256k1_uint1 x140;
- fiat_secp256k1_addcarryx_u32(&x139, &x140, x138, x121, x89);
+ fiat_secp256k1_addcarryx_u32(&x139, &x140, x138, x89, x121);
uint32_t x141;
fiat_secp256k1_uint1 x142;
- fiat_secp256k1_addcarryx_u32(&x141, &x142, x140, x123, x91);
+ fiat_secp256k1_addcarryx_u32(&x141, &x142, x140, x91, x123);
uint32_t x143;
fiat_secp256k1_uint1 x144;
- fiat_secp256k1_addcarryx_u32(&x143, &x144, x142, x125, (fiat_secp256k1_uint1)x93);
+ fiat_secp256k1_addcarryx_u32(&x143, &x144, x142, (fiat_secp256k1_uint1)x93, x125);
uint32_t x145;
uint32_t x146;
fiat_secp256k1_mulx_u32(&x145, &x146, x127, UINT32_C(0xd2253531));
@@ -1653,58 +1653,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x161, &x162, x145, UINT32_C(0xfffffc2f));
uint32_t x163;
fiat_secp256k1_uint1 x164;
- fiat_secp256k1_addcarryx_u32(&x163, &x164, 0x0, x159, x162);
+ fiat_secp256k1_addcarryx_u32(&x163, &x164, 0x0, x162, x159);
uint32_t x165;
fiat_secp256k1_uint1 x166;
- fiat_secp256k1_addcarryx_u32(&x165, &x166, x164, x157, x160);
+ fiat_secp256k1_addcarryx_u32(&x165, &x166, x164, x160, x157);
uint32_t x167;
fiat_secp256k1_uint1 x168;
- fiat_secp256k1_addcarryx_u32(&x167, &x168, x166, x155, x158);
+ fiat_secp256k1_addcarryx_u32(&x167, &x168, x166, x158, x155);
uint32_t x169;
fiat_secp256k1_uint1 x170;
- fiat_secp256k1_addcarryx_u32(&x169, &x170, x168, x153, x156);
+ fiat_secp256k1_addcarryx_u32(&x169, &x170, x168, x156, x153);
uint32_t x171;
fiat_secp256k1_uint1 x172;
- fiat_secp256k1_addcarryx_u32(&x171, &x172, x170, x151, x154);
+ fiat_secp256k1_addcarryx_u32(&x171, &x172, x170, x154, x151);
uint32_t x173;
fiat_secp256k1_uint1 x174;
- fiat_secp256k1_addcarryx_u32(&x173, &x174, x172, x149, x152);
+ fiat_secp256k1_addcarryx_u32(&x173, &x174, x172, x152, x149);
uint32_t x175;
fiat_secp256k1_uint1 x176;
- fiat_secp256k1_addcarryx_u32(&x175, &x176, x174, x147, x150);
+ fiat_secp256k1_addcarryx_u32(&x175, &x176, x174, x150, x147);
uint32_t x177;
fiat_secp256k1_uint1 x178;
- fiat_secp256k1_addcarryx_u32(&x177, &x178, x176, 0x0, x148);
+ fiat_secp256k1_addcarryx_u32(&x177, &x178, x176, x148, 0x0);
uint32_t x179;
fiat_secp256k1_uint1 x180;
- fiat_secp256k1_addcarryx_u32(&x179, &x180, 0x0, x161, x127);
+ fiat_secp256k1_addcarryx_u32(&x179, &x180, 0x0, x127, x161);
uint32_t x181;
fiat_secp256k1_uint1 x182;
- fiat_secp256k1_addcarryx_u32(&x181, &x182, x180, x163, x129);
+ fiat_secp256k1_addcarryx_u32(&x181, &x182, x180, x129, x163);
uint32_t x183;
fiat_secp256k1_uint1 x184;
- fiat_secp256k1_addcarryx_u32(&x183, &x184, x182, x165, x131);
+ fiat_secp256k1_addcarryx_u32(&x183, &x184, x182, x131, x165);
uint32_t x185;
fiat_secp256k1_uint1 x186;
- fiat_secp256k1_addcarryx_u32(&x185, &x186, x184, x167, x133);
+ fiat_secp256k1_addcarryx_u32(&x185, &x186, x184, x133, x167);
uint32_t x187;
fiat_secp256k1_uint1 x188;
- fiat_secp256k1_addcarryx_u32(&x187, &x188, x186, x169, x135);
+ fiat_secp256k1_addcarryx_u32(&x187, &x188, x186, x135, x169);
uint32_t x189;
fiat_secp256k1_uint1 x190;
- fiat_secp256k1_addcarryx_u32(&x189, &x190, x188, x171, x137);
+ fiat_secp256k1_addcarryx_u32(&x189, &x190, x188, x137, x171);
uint32_t x191;
fiat_secp256k1_uint1 x192;
- fiat_secp256k1_addcarryx_u32(&x191, &x192, x190, x173, x139);
+ fiat_secp256k1_addcarryx_u32(&x191, &x192, x190, x139, x173);
uint32_t x193;
fiat_secp256k1_uint1 x194;
- fiat_secp256k1_addcarryx_u32(&x193, &x194, x192, x175, x141);
+ fiat_secp256k1_addcarryx_u32(&x193, &x194, x192, x141, x175);
uint32_t x195;
fiat_secp256k1_uint1 x196;
- fiat_secp256k1_addcarryx_u32(&x195, &x196, x194, x177, x143);
+ fiat_secp256k1_addcarryx_u32(&x195, &x196, x194, x143, x177);
uint32_t x197;
fiat_secp256k1_uint1 x198;
- fiat_secp256k1_addcarryx_u32(&x197, &x198, x196, 0x0, x144);
+ fiat_secp256k1_addcarryx_u32(&x197, &x198, x196, x144, 0x0);
uint32_t x199;
uint32_t x200;
fiat_secp256k1_mulx_u32(&x199, &x200, x2, (arg1[7]));
@@ -1731,55 +1731,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x213, &x214, x2, (arg1[0]));
uint32_t x215;
fiat_secp256k1_uint1 x216;
- fiat_secp256k1_addcarryx_u32(&x215, &x216, 0x0, x211, x214);
+ fiat_secp256k1_addcarryx_u32(&x215, &x216, 0x0, x214, x211);
uint32_t x217;
fiat_secp256k1_uint1 x218;
- fiat_secp256k1_addcarryx_u32(&x217, &x218, x216, x209, x212);
+ fiat_secp256k1_addcarryx_u32(&x217, &x218, x216, x212, x209);
uint32_t x219;
fiat_secp256k1_uint1 x220;
- fiat_secp256k1_addcarryx_u32(&x219, &x220, x218, x207, x210);
+ fiat_secp256k1_addcarryx_u32(&x219, &x220, x218, x210, x207);
uint32_t x221;
fiat_secp256k1_uint1 x222;
- fiat_secp256k1_addcarryx_u32(&x221, &x222, x220, x205, x208);
+ fiat_secp256k1_addcarryx_u32(&x221, &x222, x220, x208, x205);
uint32_t x223;
fiat_secp256k1_uint1 x224;
- fiat_secp256k1_addcarryx_u32(&x223, &x224, x222, x203, x206);
+ fiat_secp256k1_addcarryx_u32(&x223, &x224, x222, x206, x203);
uint32_t x225;
fiat_secp256k1_uint1 x226;
- fiat_secp256k1_addcarryx_u32(&x225, &x226, x224, x201, x204);
+ fiat_secp256k1_addcarryx_u32(&x225, &x226, x224, x204, x201);
uint32_t x227;
fiat_secp256k1_uint1 x228;
- fiat_secp256k1_addcarryx_u32(&x227, &x228, x226, x199, x202);
+ fiat_secp256k1_addcarryx_u32(&x227, &x228, x226, x202, x199);
uint32_t x229;
fiat_secp256k1_uint1 x230;
- fiat_secp256k1_addcarryx_u32(&x229, &x230, x228, 0x0, x200);
+ fiat_secp256k1_addcarryx_u32(&x229, &x230, x228, x200, 0x0);
uint32_t x231;
fiat_secp256k1_uint1 x232;
- fiat_secp256k1_addcarryx_u32(&x231, &x232, 0x0, x213, x181);
+ fiat_secp256k1_addcarryx_u32(&x231, &x232, 0x0, x181, x213);
uint32_t x233;
fiat_secp256k1_uint1 x234;
- fiat_secp256k1_addcarryx_u32(&x233, &x234, x232, x215, x183);
+ fiat_secp256k1_addcarryx_u32(&x233, &x234, x232, x183, x215);
uint32_t x235;
fiat_secp256k1_uint1 x236;
- fiat_secp256k1_addcarryx_u32(&x235, &x236, x234, x217, x185);
+ fiat_secp256k1_addcarryx_u32(&x235, &x236, x234, x185, x217);
uint32_t x237;
fiat_secp256k1_uint1 x238;
- fiat_secp256k1_addcarryx_u32(&x237, &x238, x236, x219, x187);
+ fiat_secp256k1_addcarryx_u32(&x237, &x238, x236, x187, x219);
uint32_t x239;
fiat_secp256k1_uint1 x240;
- fiat_secp256k1_addcarryx_u32(&x239, &x240, x238, x221, x189);
+ fiat_secp256k1_addcarryx_u32(&x239, &x240, x238, x189, x221);
uint32_t x241;
fiat_secp256k1_uint1 x242;
- fiat_secp256k1_addcarryx_u32(&x241, &x242, x240, x223, x191);
+ fiat_secp256k1_addcarryx_u32(&x241, &x242, x240, x191, x223);
uint32_t x243;
fiat_secp256k1_uint1 x244;
- fiat_secp256k1_addcarryx_u32(&x243, &x244, x242, x225, x193);
+ fiat_secp256k1_addcarryx_u32(&x243, &x244, x242, x193, x225);
uint32_t x245;
fiat_secp256k1_uint1 x246;
- fiat_secp256k1_addcarryx_u32(&x245, &x246, x244, x227, x195);
+ fiat_secp256k1_addcarryx_u32(&x245, &x246, x244, x195, x227);
uint32_t x247;
fiat_secp256k1_uint1 x248;
- fiat_secp256k1_addcarryx_u32(&x247, &x248, x246, x229, x197);
+ fiat_secp256k1_addcarryx_u32(&x247, &x248, x246, x197, x229);
uint32_t x249;
uint32_t x250;
fiat_secp256k1_mulx_u32(&x249, &x250, x231, UINT32_C(0xd2253531));
@@ -1809,58 +1809,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x265, &x266, x249, UINT32_C(0xfffffc2f));
uint32_t x267;
fiat_secp256k1_uint1 x268;
- fiat_secp256k1_addcarryx_u32(&x267, &x268, 0x0, x263, x266);
+ fiat_secp256k1_addcarryx_u32(&x267, &x268, 0x0, x266, x263);
uint32_t x269;
fiat_secp256k1_uint1 x270;
- fiat_secp256k1_addcarryx_u32(&x269, &x270, x268, x261, x264);
+ fiat_secp256k1_addcarryx_u32(&x269, &x270, x268, x264, x261);
uint32_t x271;
fiat_secp256k1_uint1 x272;
- fiat_secp256k1_addcarryx_u32(&x271, &x272, x270, x259, x262);
+ fiat_secp256k1_addcarryx_u32(&x271, &x272, x270, x262, x259);
uint32_t x273;
fiat_secp256k1_uint1 x274;
- fiat_secp256k1_addcarryx_u32(&x273, &x274, x272, x257, x260);
+ fiat_secp256k1_addcarryx_u32(&x273, &x274, x272, x260, x257);
uint32_t x275;
fiat_secp256k1_uint1 x276;
- fiat_secp256k1_addcarryx_u32(&x275, &x276, x274, x255, x258);
+ fiat_secp256k1_addcarryx_u32(&x275, &x276, x274, x258, x255);
uint32_t x277;
fiat_secp256k1_uint1 x278;
- fiat_secp256k1_addcarryx_u32(&x277, &x278, x276, x253, x256);
+ fiat_secp256k1_addcarryx_u32(&x277, &x278, x276, x256, x253);
uint32_t x279;
fiat_secp256k1_uint1 x280;
- fiat_secp256k1_addcarryx_u32(&x279, &x280, x278, x251, x254);
+ fiat_secp256k1_addcarryx_u32(&x279, &x280, x278, x254, x251);
uint32_t x281;
fiat_secp256k1_uint1 x282;
- fiat_secp256k1_addcarryx_u32(&x281, &x282, x280, 0x0, x252);
+ fiat_secp256k1_addcarryx_u32(&x281, &x282, x280, x252, 0x0);
uint32_t x283;
fiat_secp256k1_uint1 x284;
- fiat_secp256k1_addcarryx_u32(&x283, &x284, 0x0, x265, x231);
+ fiat_secp256k1_addcarryx_u32(&x283, &x284, 0x0, x231, x265);
uint32_t x285;
fiat_secp256k1_uint1 x286;
- fiat_secp256k1_addcarryx_u32(&x285, &x286, x284, x267, x233);
+ fiat_secp256k1_addcarryx_u32(&x285, &x286, x284, x233, x267);
uint32_t x287;
fiat_secp256k1_uint1 x288;
- fiat_secp256k1_addcarryx_u32(&x287, &x288, x286, x269, x235);
+ fiat_secp256k1_addcarryx_u32(&x287, &x288, x286, x235, x269);
uint32_t x289;
fiat_secp256k1_uint1 x290;
- fiat_secp256k1_addcarryx_u32(&x289, &x290, x288, x271, x237);
+ fiat_secp256k1_addcarryx_u32(&x289, &x290, x288, x237, x271);
uint32_t x291;
fiat_secp256k1_uint1 x292;
- fiat_secp256k1_addcarryx_u32(&x291, &x292, x290, x273, x239);
+ fiat_secp256k1_addcarryx_u32(&x291, &x292, x290, x239, x273);
uint32_t x293;
fiat_secp256k1_uint1 x294;
- fiat_secp256k1_addcarryx_u32(&x293, &x294, x292, x275, x241);
+ fiat_secp256k1_addcarryx_u32(&x293, &x294, x292, x241, x275);
uint32_t x295;
fiat_secp256k1_uint1 x296;
- fiat_secp256k1_addcarryx_u32(&x295, &x296, x294, x277, x243);
+ fiat_secp256k1_addcarryx_u32(&x295, &x296, x294, x243, x277);
uint32_t x297;
fiat_secp256k1_uint1 x298;
- fiat_secp256k1_addcarryx_u32(&x297, &x298, x296, x279, x245);
+ fiat_secp256k1_addcarryx_u32(&x297, &x298, x296, x245, x279);
uint32_t x299;
fiat_secp256k1_uint1 x300;
- fiat_secp256k1_addcarryx_u32(&x299, &x300, x298, x281, x247);
+ fiat_secp256k1_addcarryx_u32(&x299, &x300, x298, x247, x281);
uint32_t x301;
fiat_secp256k1_uint1 x302;
- fiat_secp256k1_addcarryx_u32(&x301, &x302, x300, 0x0, x248);
+ fiat_secp256k1_addcarryx_u32(&x301, &x302, x300, x248, 0x0);
uint32_t x303;
uint32_t x304;
fiat_secp256k1_mulx_u32(&x303, &x304, x3, (arg1[7]));
@@ -1887,55 +1887,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x317, &x318, x3, (arg1[0]));
uint32_t x319;
fiat_secp256k1_uint1 x320;
- fiat_secp256k1_addcarryx_u32(&x319, &x320, 0x0, x315, x318);
+ fiat_secp256k1_addcarryx_u32(&x319, &x320, 0x0, x318, x315);
uint32_t x321;
fiat_secp256k1_uint1 x322;
- fiat_secp256k1_addcarryx_u32(&x321, &x322, x320, x313, x316);
+ fiat_secp256k1_addcarryx_u32(&x321, &x322, x320, x316, x313);
uint32_t x323;
fiat_secp256k1_uint1 x324;
- fiat_secp256k1_addcarryx_u32(&x323, &x324, x322, x311, x314);
+ fiat_secp256k1_addcarryx_u32(&x323, &x324, x322, x314, x311);
uint32_t x325;
fiat_secp256k1_uint1 x326;
- fiat_secp256k1_addcarryx_u32(&x325, &x326, x324, x309, x312);
+ fiat_secp256k1_addcarryx_u32(&x325, &x326, x324, x312, x309);
uint32_t x327;
fiat_secp256k1_uint1 x328;
- fiat_secp256k1_addcarryx_u32(&x327, &x328, x326, x307, x310);
+ fiat_secp256k1_addcarryx_u32(&x327, &x328, x326, x310, x307);
uint32_t x329;
fiat_secp256k1_uint1 x330;
- fiat_secp256k1_addcarryx_u32(&x329, &x330, x328, x305, x308);
+ fiat_secp256k1_addcarryx_u32(&x329, &x330, x328, x308, x305);
uint32_t x331;
fiat_secp256k1_uint1 x332;
- fiat_secp256k1_addcarryx_u32(&x331, &x332, x330, x303, x306);
+ fiat_secp256k1_addcarryx_u32(&x331, &x332, x330, x306, x303);
uint32_t x333;
fiat_secp256k1_uint1 x334;
- fiat_secp256k1_addcarryx_u32(&x333, &x334, x332, 0x0, x304);
+ fiat_secp256k1_addcarryx_u32(&x333, &x334, x332, x304, 0x0);
uint32_t x335;
fiat_secp256k1_uint1 x336;
- fiat_secp256k1_addcarryx_u32(&x335, &x336, 0x0, x317, x285);
+ fiat_secp256k1_addcarryx_u32(&x335, &x336, 0x0, x285, x317);
uint32_t x337;
fiat_secp256k1_uint1 x338;
- fiat_secp256k1_addcarryx_u32(&x337, &x338, x336, x319, x287);
+ fiat_secp256k1_addcarryx_u32(&x337, &x338, x336, x287, x319);
uint32_t x339;
fiat_secp256k1_uint1 x340;
- fiat_secp256k1_addcarryx_u32(&x339, &x340, x338, x321, x289);
+ fiat_secp256k1_addcarryx_u32(&x339, &x340, x338, x289, x321);
uint32_t x341;
fiat_secp256k1_uint1 x342;
- fiat_secp256k1_addcarryx_u32(&x341, &x342, x340, x323, x291);
+ fiat_secp256k1_addcarryx_u32(&x341, &x342, x340, x291, x323);
uint32_t x343;
fiat_secp256k1_uint1 x344;
- fiat_secp256k1_addcarryx_u32(&x343, &x344, x342, x325, x293);
+ fiat_secp256k1_addcarryx_u32(&x343, &x344, x342, x293, x325);
uint32_t x345;
fiat_secp256k1_uint1 x346;
- fiat_secp256k1_addcarryx_u32(&x345, &x346, x344, x327, x295);
+ fiat_secp256k1_addcarryx_u32(&x345, &x346, x344, x295, x327);
uint32_t x347;
fiat_secp256k1_uint1 x348;
- fiat_secp256k1_addcarryx_u32(&x347, &x348, x346, x329, x297);
+ fiat_secp256k1_addcarryx_u32(&x347, &x348, x346, x297, x329);
uint32_t x349;
fiat_secp256k1_uint1 x350;
- fiat_secp256k1_addcarryx_u32(&x349, &x350, x348, x331, x299);
+ fiat_secp256k1_addcarryx_u32(&x349, &x350, x348, x299, x331);
uint32_t x351;
fiat_secp256k1_uint1 x352;
- fiat_secp256k1_addcarryx_u32(&x351, &x352, x350, x333, x301);
+ fiat_secp256k1_addcarryx_u32(&x351, &x352, x350, x301, x333);
uint32_t x353;
uint32_t x354;
fiat_secp256k1_mulx_u32(&x353, &x354, x335, UINT32_C(0xd2253531));
@@ -1965,58 +1965,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x369, &x370, x353, UINT32_C(0xfffffc2f));
uint32_t x371;
fiat_secp256k1_uint1 x372;
- fiat_secp256k1_addcarryx_u32(&x371, &x372, 0x0, x367, x370);
+ fiat_secp256k1_addcarryx_u32(&x371, &x372, 0x0, x370, x367);
uint32_t x373;
fiat_secp256k1_uint1 x374;
- fiat_secp256k1_addcarryx_u32(&x373, &x374, x372, x365, x368);
+ fiat_secp256k1_addcarryx_u32(&x373, &x374, x372, x368, x365);
uint32_t x375;
fiat_secp256k1_uint1 x376;
- fiat_secp256k1_addcarryx_u32(&x375, &x376, x374, x363, x366);
+ fiat_secp256k1_addcarryx_u32(&x375, &x376, x374, x366, x363);
uint32_t x377;
fiat_secp256k1_uint1 x378;
- fiat_secp256k1_addcarryx_u32(&x377, &x378, x376, x361, x364);
+ fiat_secp256k1_addcarryx_u32(&x377, &x378, x376, x364, x361);
uint32_t x379;
fiat_secp256k1_uint1 x380;
- fiat_secp256k1_addcarryx_u32(&x379, &x380, x378, x359, x362);
+ fiat_secp256k1_addcarryx_u32(&x379, &x380, x378, x362, x359);
uint32_t x381;
fiat_secp256k1_uint1 x382;
- fiat_secp256k1_addcarryx_u32(&x381, &x382, x380, x357, x360);
+ fiat_secp256k1_addcarryx_u32(&x381, &x382, x380, x360, x357);
uint32_t x383;
fiat_secp256k1_uint1 x384;
- fiat_secp256k1_addcarryx_u32(&x383, &x384, x382, x355, x358);
+ fiat_secp256k1_addcarryx_u32(&x383, &x384, x382, x358, x355);
uint32_t x385;
fiat_secp256k1_uint1 x386;
- fiat_secp256k1_addcarryx_u32(&x385, &x386, x384, 0x0, x356);
+ fiat_secp256k1_addcarryx_u32(&x385, &x386, x384, x356, 0x0);
uint32_t x387;
fiat_secp256k1_uint1 x388;
- fiat_secp256k1_addcarryx_u32(&x387, &x388, 0x0, x369, x335);
+ fiat_secp256k1_addcarryx_u32(&x387, &x388, 0x0, x335, x369);
uint32_t x389;
fiat_secp256k1_uint1 x390;
- fiat_secp256k1_addcarryx_u32(&x389, &x390, x388, x371, x337);
+ fiat_secp256k1_addcarryx_u32(&x389, &x390, x388, x337, x371);
uint32_t x391;
fiat_secp256k1_uint1 x392;
- fiat_secp256k1_addcarryx_u32(&x391, &x392, x390, x373, x339);
+ fiat_secp256k1_addcarryx_u32(&x391, &x392, x390, x339, x373);
uint32_t x393;
fiat_secp256k1_uint1 x394;
- fiat_secp256k1_addcarryx_u32(&x393, &x394, x392, x375, x341);
+ fiat_secp256k1_addcarryx_u32(&x393, &x394, x392, x341, x375);
uint32_t x395;
fiat_secp256k1_uint1 x396;
- fiat_secp256k1_addcarryx_u32(&x395, &x396, x394, x377, x343);
+ fiat_secp256k1_addcarryx_u32(&x395, &x396, x394, x343, x377);
uint32_t x397;
fiat_secp256k1_uint1 x398;
- fiat_secp256k1_addcarryx_u32(&x397, &x398, x396, x379, x345);
+ fiat_secp256k1_addcarryx_u32(&x397, &x398, x396, x345, x379);
uint32_t x399;
fiat_secp256k1_uint1 x400;
- fiat_secp256k1_addcarryx_u32(&x399, &x400, x398, x381, x347);
+ fiat_secp256k1_addcarryx_u32(&x399, &x400, x398, x347, x381);
uint32_t x401;
fiat_secp256k1_uint1 x402;
- fiat_secp256k1_addcarryx_u32(&x401, &x402, x400, x383, x349);
+ fiat_secp256k1_addcarryx_u32(&x401, &x402, x400, x349, x383);
uint32_t x403;
fiat_secp256k1_uint1 x404;
- fiat_secp256k1_addcarryx_u32(&x403, &x404, x402, x385, x351);
+ fiat_secp256k1_addcarryx_u32(&x403, &x404, x402, x351, x385);
uint32_t x405;
fiat_secp256k1_uint1 x406;
- fiat_secp256k1_addcarryx_u32(&x405, &x406, x404, 0x0, x352);
+ fiat_secp256k1_addcarryx_u32(&x405, &x406, x404, x352, 0x0);
uint32_t x407;
uint32_t x408;
fiat_secp256k1_mulx_u32(&x407, &x408, x4, (arg1[7]));
@@ -2043,55 +2043,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x421, &x422, x4, (arg1[0]));
uint32_t x423;
fiat_secp256k1_uint1 x424;
- fiat_secp256k1_addcarryx_u32(&x423, &x424, 0x0, x419, x422);
+ fiat_secp256k1_addcarryx_u32(&x423, &x424, 0x0, x422, x419);
uint32_t x425;
fiat_secp256k1_uint1 x426;
- fiat_secp256k1_addcarryx_u32(&x425, &x426, x424, x417, x420);
+ fiat_secp256k1_addcarryx_u32(&x425, &x426, x424, x420, x417);
uint32_t x427;
fiat_secp256k1_uint1 x428;
- fiat_secp256k1_addcarryx_u32(&x427, &x428, x426, x415, x418);
+ fiat_secp256k1_addcarryx_u32(&x427, &x428, x426, x418, x415);
uint32_t x429;
fiat_secp256k1_uint1 x430;
- fiat_secp256k1_addcarryx_u32(&x429, &x430, x428, x413, x416);
+ fiat_secp256k1_addcarryx_u32(&x429, &x430, x428, x416, x413);
uint32_t x431;
fiat_secp256k1_uint1 x432;
- fiat_secp256k1_addcarryx_u32(&x431, &x432, x430, x411, x414);
+ fiat_secp256k1_addcarryx_u32(&x431, &x432, x430, x414, x411);
uint32_t x433;
fiat_secp256k1_uint1 x434;
- fiat_secp256k1_addcarryx_u32(&x433, &x434, x432, x409, x412);
+ fiat_secp256k1_addcarryx_u32(&x433, &x434, x432, x412, x409);
uint32_t x435;
fiat_secp256k1_uint1 x436;
- fiat_secp256k1_addcarryx_u32(&x435, &x436, x434, x407, x410);
+ fiat_secp256k1_addcarryx_u32(&x435, &x436, x434, x410, x407);
uint32_t x437;
fiat_secp256k1_uint1 x438;
- fiat_secp256k1_addcarryx_u32(&x437, &x438, x436, 0x0, x408);
+ fiat_secp256k1_addcarryx_u32(&x437, &x438, x436, x408, 0x0);
uint32_t x439;
fiat_secp256k1_uint1 x440;
- fiat_secp256k1_addcarryx_u32(&x439, &x440, 0x0, x421, x389);
+ fiat_secp256k1_addcarryx_u32(&x439, &x440, 0x0, x389, x421);
uint32_t x441;
fiat_secp256k1_uint1 x442;
- fiat_secp256k1_addcarryx_u32(&x441, &x442, x440, x423, x391);
+ fiat_secp256k1_addcarryx_u32(&x441, &x442, x440, x391, x423);
uint32_t x443;
fiat_secp256k1_uint1 x444;
- fiat_secp256k1_addcarryx_u32(&x443, &x444, x442, x425, x393);
+ fiat_secp256k1_addcarryx_u32(&x443, &x444, x442, x393, x425);
uint32_t x445;
fiat_secp256k1_uint1 x446;
- fiat_secp256k1_addcarryx_u32(&x445, &x446, x444, x427, x395);
+ fiat_secp256k1_addcarryx_u32(&x445, &x446, x444, x395, x427);
uint32_t x447;
fiat_secp256k1_uint1 x448;
- fiat_secp256k1_addcarryx_u32(&x447, &x448, x446, x429, x397);
+ fiat_secp256k1_addcarryx_u32(&x447, &x448, x446, x397, x429);
uint32_t x449;
fiat_secp256k1_uint1 x450;
- fiat_secp256k1_addcarryx_u32(&x449, &x450, x448, x431, x399);
+ fiat_secp256k1_addcarryx_u32(&x449, &x450, x448, x399, x431);
uint32_t x451;
fiat_secp256k1_uint1 x452;
- fiat_secp256k1_addcarryx_u32(&x451, &x452, x450, x433, x401);
+ fiat_secp256k1_addcarryx_u32(&x451, &x452, x450, x401, x433);
uint32_t x453;
fiat_secp256k1_uint1 x454;
- fiat_secp256k1_addcarryx_u32(&x453, &x454, x452, x435, x403);
+ fiat_secp256k1_addcarryx_u32(&x453, &x454, x452, x403, x435);
uint32_t x455;
fiat_secp256k1_uint1 x456;
- fiat_secp256k1_addcarryx_u32(&x455, &x456, x454, x437, x405);
+ fiat_secp256k1_addcarryx_u32(&x455, &x456, x454, x405, x437);
uint32_t x457;
uint32_t x458;
fiat_secp256k1_mulx_u32(&x457, &x458, x439, UINT32_C(0xd2253531));
@@ -2121,58 +2121,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x473, &x474, x457, UINT32_C(0xfffffc2f));
uint32_t x475;
fiat_secp256k1_uint1 x476;
- fiat_secp256k1_addcarryx_u32(&x475, &x476, 0x0, x471, x474);
+ fiat_secp256k1_addcarryx_u32(&x475, &x476, 0x0, x474, x471);
uint32_t x477;
fiat_secp256k1_uint1 x478;
- fiat_secp256k1_addcarryx_u32(&x477, &x478, x476, x469, x472);
+ fiat_secp256k1_addcarryx_u32(&x477, &x478, x476, x472, x469);
uint32_t x479;
fiat_secp256k1_uint1 x480;
- fiat_secp256k1_addcarryx_u32(&x479, &x480, x478, x467, x470);
+ fiat_secp256k1_addcarryx_u32(&x479, &x480, x478, x470, x467);
uint32_t x481;
fiat_secp256k1_uint1 x482;
- fiat_secp256k1_addcarryx_u32(&x481, &x482, x480, x465, x468);
+ fiat_secp256k1_addcarryx_u32(&x481, &x482, x480, x468, x465);
uint32_t x483;
fiat_secp256k1_uint1 x484;
- fiat_secp256k1_addcarryx_u32(&x483, &x484, x482, x463, x466);
+ fiat_secp256k1_addcarryx_u32(&x483, &x484, x482, x466, x463);
uint32_t x485;
fiat_secp256k1_uint1 x486;
- fiat_secp256k1_addcarryx_u32(&x485, &x486, x484, x461, x464);
+ fiat_secp256k1_addcarryx_u32(&x485, &x486, x484, x464, x461);
uint32_t x487;
fiat_secp256k1_uint1 x488;
- fiat_secp256k1_addcarryx_u32(&x487, &x488, x486, x459, x462);
+ fiat_secp256k1_addcarryx_u32(&x487, &x488, x486, x462, x459);
uint32_t x489;
fiat_secp256k1_uint1 x490;
- fiat_secp256k1_addcarryx_u32(&x489, &x490, x488, 0x0, x460);
+ fiat_secp256k1_addcarryx_u32(&x489, &x490, x488, x460, 0x0);
uint32_t x491;
fiat_secp256k1_uint1 x492;
- fiat_secp256k1_addcarryx_u32(&x491, &x492, 0x0, x473, x439);
+ fiat_secp256k1_addcarryx_u32(&x491, &x492, 0x0, x439, x473);
uint32_t x493;
fiat_secp256k1_uint1 x494;
- fiat_secp256k1_addcarryx_u32(&x493, &x494, x492, x475, x441);
+ fiat_secp256k1_addcarryx_u32(&x493, &x494, x492, x441, x475);
uint32_t x495;
fiat_secp256k1_uint1 x496;
- fiat_secp256k1_addcarryx_u32(&x495, &x496, x494, x477, x443);
+ fiat_secp256k1_addcarryx_u32(&x495, &x496, x494, x443, x477);
uint32_t x497;
fiat_secp256k1_uint1 x498;
- fiat_secp256k1_addcarryx_u32(&x497, &x498, x496, x479, x445);
+ fiat_secp256k1_addcarryx_u32(&x497, &x498, x496, x445, x479);
uint32_t x499;
fiat_secp256k1_uint1 x500;
- fiat_secp256k1_addcarryx_u32(&x499, &x500, x498, x481, x447);
+ fiat_secp256k1_addcarryx_u32(&x499, &x500, x498, x447, x481);
uint32_t x501;
fiat_secp256k1_uint1 x502;
- fiat_secp256k1_addcarryx_u32(&x501, &x502, x500, x483, x449);
+ fiat_secp256k1_addcarryx_u32(&x501, &x502, x500, x449, x483);
uint32_t x503;
fiat_secp256k1_uint1 x504;
- fiat_secp256k1_addcarryx_u32(&x503, &x504, x502, x485, x451);
+ fiat_secp256k1_addcarryx_u32(&x503, &x504, x502, x451, x485);
uint32_t x505;
fiat_secp256k1_uint1 x506;
- fiat_secp256k1_addcarryx_u32(&x505, &x506, x504, x487, x453);
+ fiat_secp256k1_addcarryx_u32(&x505, &x506, x504, x453, x487);
uint32_t x507;
fiat_secp256k1_uint1 x508;
- fiat_secp256k1_addcarryx_u32(&x507, &x508, x506, x489, x455);
+ fiat_secp256k1_addcarryx_u32(&x507, &x508, x506, x455, x489);
uint32_t x509;
fiat_secp256k1_uint1 x510;
- fiat_secp256k1_addcarryx_u32(&x509, &x510, x508, 0x0, x456);
+ fiat_secp256k1_addcarryx_u32(&x509, &x510, x508, x456, 0x0);
uint32_t x511;
uint32_t x512;
fiat_secp256k1_mulx_u32(&x511, &x512, x5, (arg1[7]));
@@ -2199,55 +2199,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x525, &x526, x5, (arg1[0]));
uint32_t x527;
fiat_secp256k1_uint1 x528;
- fiat_secp256k1_addcarryx_u32(&x527, &x528, 0x0, x523, x526);
+ fiat_secp256k1_addcarryx_u32(&x527, &x528, 0x0, x526, x523);
uint32_t x529;
fiat_secp256k1_uint1 x530;
- fiat_secp256k1_addcarryx_u32(&x529, &x530, x528, x521, x524);
+ fiat_secp256k1_addcarryx_u32(&x529, &x530, x528, x524, x521);
uint32_t x531;
fiat_secp256k1_uint1 x532;
- fiat_secp256k1_addcarryx_u32(&x531, &x532, x530, x519, x522);
+ fiat_secp256k1_addcarryx_u32(&x531, &x532, x530, x522, x519);
uint32_t x533;
fiat_secp256k1_uint1 x534;
- fiat_secp256k1_addcarryx_u32(&x533, &x534, x532, x517, x520);
+ fiat_secp256k1_addcarryx_u32(&x533, &x534, x532, x520, x517);
uint32_t x535;
fiat_secp256k1_uint1 x536;
- fiat_secp256k1_addcarryx_u32(&x535, &x536, x534, x515, x518);
+ fiat_secp256k1_addcarryx_u32(&x535, &x536, x534, x518, x515);
uint32_t x537;
fiat_secp256k1_uint1 x538;
- fiat_secp256k1_addcarryx_u32(&x537, &x538, x536, x513, x516);
+ fiat_secp256k1_addcarryx_u32(&x537, &x538, x536, x516, x513);
uint32_t x539;
fiat_secp256k1_uint1 x540;
- fiat_secp256k1_addcarryx_u32(&x539, &x540, x538, x511, x514);
+ fiat_secp256k1_addcarryx_u32(&x539, &x540, x538, x514, x511);
uint32_t x541;
fiat_secp256k1_uint1 x542;
- fiat_secp256k1_addcarryx_u32(&x541, &x542, x540, 0x0, x512);
+ fiat_secp256k1_addcarryx_u32(&x541, &x542, x540, x512, 0x0);
uint32_t x543;
fiat_secp256k1_uint1 x544;
- fiat_secp256k1_addcarryx_u32(&x543, &x544, 0x0, x525, x493);
+ fiat_secp256k1_addcarryx_u32(&x543, &x544, 0x0, x493, x525);
uint32_t x545;
fiat_secp256k1_uint1 x546;
- fiat_secp256k1_addcarryx_u32(&x545, &x546, x544, x527, x495);
+ fiat_secp256k1_addcarryx_u32(&x545, &x546, x544, x495, x527);
uint32_t x547;
fiat_secp256k1_uint1 x548;
- fiat_secp256k1_addcarryx_u32(&x547, &x548, x546, x529, x497);
+ fiat_secp256k1_addcarryx_u32(&x547, &x548, x546, x497, x529);
uint32_t x549;
fiat_secp256k1_uint1 x550;
- fiat_secp256k1_addcarryx_u32(&x549, &x550, x548, x531, x499);
+ fiat_secp256k1_addcarryx_u32(&x549, &x550, x548, x499, x531);
uint32_t x551;
fiat_secp256k1_uint1 x552;
- fiat_secp256k1_addcarryx_u32(&x551, &x552, x550, x533, x501);
+ fiat_secp256k1_addcarryx_u32(&x551, &x552, x550, x501, x533);
uint32_t x553;
fiat_secp256k1_uint1 x554;
- fiat_secp256k1_addcarryx_u32(&x553, &x554, x552, x535, x503);
+ fiat_secp256k1_addcarryx_u32(&x553, &x554, x552, x503, x535);
uint32_t x555;
fiat_secp256k1_uint1 x556;
- fiat_secp256k1_addcarryx_u32(&x555, &x556, x554, x537, x505);
+ fiat_secp256k1_addcarryx_u32(&x555, &x556, x554, x505, x537);
uint32_t x557;
fiat_secp256k1_uint1 x558;
- fiat_secp256k1_addcarryx_u32(&x557, &x558, x556, x539, x507);
+ fiat_secp256k1_addcarryx_u32(&x557, &x558, x556, x507, x539);
uint32_t x559;
fiat_secp256k1_uint1 x560;
- fiat_secp256k1_addcarryx_u32(&x559, &x560, x558, x541, x509);
+ fiat_secp256k1_addcarryx_u32(&x559, &x560, x558, x509, x541);
uint32_t x561;
uint32_t x562;
fiat_secp256k1_mulx_u32(&x561, &x562, x543, UINT32_C(0xd2253531));
@@ -2277,58 +2277,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x577, &x578, x561, UINT32_C(0xfffffc2f));
uint32_t x579;
fiat_secp256k1_uint1 x580;
- fiat_secp256k1_addcarryx_u32(&x579, &x580, 0x0, x575, x578);
+ fiat_secp256k1_addcarryx_u32(&x579, &x580, 0x0, x578, x575);
uint32_t x581;
fiat_secp256k1_uint1 x582;
- fiat_secp256k1_addcarryx_u32(&x581, &x582, x580, x573, x576);
+ fiat_secp256k1_addcarryx_u32(&x581, &x582, x580, x576, x573);
uint32_t x583;
fiat_secp256k1_uint1 x584;
- fiat_secp256k1_addcarryx_u32(&x583, &x584, x582, x571, x574);
+ fiat_secp256k1_addcarryx_u32(&x583, &x584, x582, x574, x571);
uint32_t x585;
fiat_secp256k1_uint1 x586;
- fiat_secp256k1_addcarryx_u32(&x585, &x586, x584, x569, x572);
+ fiat_secp256k1_addcarryx_u32(&x585, &x586, x584, x572, x569);
uint32_t x587;
fiat_secp256k1_uint1 x588;
- fiat_secp256k1_addcarryx_u32(&x587, &x588, x586, x567, x570);
+ fiat_secp256k1_addcarryx_u32(&x587, &x588, x586, x570, x567);
uint32_t x589;
fiat_secp256k1_uint1 x590;
- fiat_secp256k1_addcarryx_u32(&x589, &x590, x588, x565, x568);
+ fiat_secp256k1_addcarryx_u32(&x589, &x590, x588, x568, x565);
uint32_t x591;
fiat_secp256k1_uint1 x592;
- fiat_secp256k1_addcarryx_u32(&x591, &x592, x590, x563, x566);
+ fiat_secp256k1_addcarryx_u32(&x591, &x592, x590, x566, x563);
uint32_t x593;
fiat_secp256k1_uint1 x594;
- fiat_secp256k1_addcarryx_u32(&x593, &x594, x592, 0x0, x564);
+ fiat_secp256k1_addcarryx_u32(&x593, &x594, x592, x564, 0x0);
uint32_t x595;
fiat_secp256k1_uint1 x596;
- fiat_secp256k1_addcarryx_u32(&x595, &x596, 0x0, x577, x543);
+ fiat_secp256k1_addcarryx_u32(&x595, &x596, 0x0, x543, x577);
uint32_t x597;
fiat_secp256k1_uint1 x598;
- fiat_secp256k1_addcarryx_u32(&x597, &x598, x596, x579, x545);
+ fiat_secp256k1_addcarryx_u32(&x597, &x598, x596, x545, x579);
uint32_t x599;
fiat_secp256k1_uint1 x600;
- fiat_secp256k1_addcarryx_u32(&x599, &x600, x598, x581, x547);
+ fiat_secp256k1_addcarryx_u32(&x599, &x600, x598, x547, x581);
uint32_t x601;
fiat_secp256k1_uint1 x602;
- fiat_secp256k1_addcarryx_u32(&x601, &x602, x600, x583, x549);
+ fiat_secp256k1_addcarryx_u32(&x601, &x602, x600, x549, x583);
uint32_t x603;
fiat_secp256k1_uint1 x604;
- fiat_secp256k1_addcarryx_u32(&x603, &x604, x602, x585, x551);
+ fiat_secp256k1_addcarryx_u32(&x603, &x604, x602, x551, x585);
uint32_t x605;
fiat_secp256k1_uint1 x606;
- fiat_secp256k1_addcarryx_u32(&x605, &x606, x604, x587, x553);
+ fiat_secp256k1_addcarryx_u32(&x605, &x606, x604, x553, x587);
uint32_t x607;
fiat_secp256k1_uint1 x608;
- fiat_secp256k1_addcarryx_u32(&x607, &x608, x606, x589, x555);
+ fiat_secp256k1_addcarryx_u32(&x607, &x608, x606, x555, x589);
uint32_t x609;
fiat_secp256k1_uint1 x610;
- fiat_secp256k1_addcarryx_u32(&x609, &x610, x608, x591, x557);
+ fiat_secp256k1_addcarryx_u32(&x609, &x610, x608, x557, x591);
uint32_t x611;
fiat_secp256k1_uint1 x612;
- fiat_secp256k1_addcarryx_u32(&x611, &x612, x610, x593, x559);
+ fiat_secp256k1_addcarryx_u32(&x611, &x612, x610, x559, x593);
uint32_t x613;
fiat_secp256k1_uint1 x614;
- fiat_secp256k1_addcarryx_u32(&x613, &x614, x612, 0x0, x560);
+ fiat_secp256k1_addcarryx_u32(&x613, &x614, x612, x560, 0x0);
uint32_t x615;
uint32_t x616;
fiat_secp256k1_mulx_u32(&x615, &x616, x6, (arg1[7]));
@@ -2355,55 +2355,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x629, &x630, x6, (arg1[0]));
uint32_t x631;
fiat_secp256k1_uint1 x632;
- fiat_secp256k1_addcarryx_u32(&x631, &x632, 0x0, x627, x630);
+ fiat_secp256k1_addcarryx_u32(&x631, &x632, 0x0, x630, x627);
uint32_t x633;
fiat_secp256k1_uint1 x634;
- fiat_secp256k1_addcarryx_u32(&x633, &x634, x632, x625, x628);
+ fiat_secp256k1_addcarryx_u32(&x633, &x634, x632, x628, x625);
uint32_t x635;
fiat_secp256k1_uint1 x636;
- fiat_secp256k1_addcarryx_u32(&x635, &x636, x634, x623, x626);
+ fiat_secp256k1_addcarryx_u32(&x635, &x636, x634, x626, x623);
uint32_t x637;
fiat_secp256k1_uint1 x638;
- fiat_secp256k1_addcarryx_u32(&x637, &x638, x636, x621, x624);
+ fiat_secp256k1_addcarryx_u32(&x637, &x638, x636, x624, x621);
uint32_t x639;
fiat_secp256k1_uint1 x640;
- fiat_secp256k1_addcarryx_u32(&x639, &x640, x638, x619, x622);
+ fiat_secp256k1_addcarryx_u32(&x639, &x640, x638, x622, x619);
uint32_t x641;
fiat_secp256k1_uint1 x642;
- fiat_secp256k1_addcarryx_u32(&x641, &x642, x640, x617, x620);
+ fiat_secp256k1_addcarryx_u32(&x641, &x642, x640, x620, x617);
uint32_t x643;
fiat_secp256k1_uint1 x644;
- fiat_secp256k1_addcarryx_u32(&x643, &x644, x642, x615, x618);
+ fiat_secp256k1_addcarryx_u32(&x643, &x644, x642, x618, x615);
uint32_t x645;
fiat_secp256k1_uint1 x646;
- fiat_secp256k1_addcarryx_u32(&x645, &x646, x644, 0x0, x616);
+ fiat_secp256k1_addcarryx_u32(&x645, &x646, x644, x616, 0x0);
uint32_t x647;
fiat_secp256k1_uint1 x648;
- fiat_secp256k1_addcarryx_u32(&x647, &x648, 0x0, x629, x597);
+ fiat_secp256k1_addcarryx_u32(&x647, &x648, 0x0, x597, x629);
uint32_t x649;
fiat_secp256k1_uint1 x650;
- fiat_secp256k1_addcarryx_u32(&x649, &x650, x648, x631, x599);
+ fiat_secp256k1_addcarryx_u32(&x649, &x650, x648, x599, x631);
uint32_t x651;
fiat_secp256k1_uint1 x652;
- fiat_secp256k1_addcarryx_u32(&x651, &x652, x650, x633, x601);
+ fiat_secp256k1_addcarryx_u32(&x651, &x652, x650, x601, x633);
uint32_t x653;
fiat_secp256k1_uint1 x654;
- fiat_secp256k1_addcarryx_u32(&x653, &x654, x652, x635, x603);
+ fiat_secp256k1_addcarryx_u32(&x653, &x654, x652, x603, x635);
uint32_t x655;
fiat_secp256k1_uint1 x656;
- fiat_secp256k1_addcarryx_u32(&x655, &x656, x654, x637, x605);
+ fiat_secp256k1_addcarryx_u32(&x655, &x656, x654, x605, x637);
uint32_t x657;
fiat_secp256k1_uint1 x658;
- fiat_secp256k1_addcarryx_u32(&x657, &x658, x656, x639, x607);
+ fiat_secp256k1_addcarryx_u32(&x657, &x658, x656, x607, x639);
uint32_t x659;
fiat_secp256k1_uint1 x660;
- fiat_secp256k1_addcarryx_u32(&x659, &x660, x658, x641, x609);
+ fiat_secp256k1_addcarryx_u32(&x659, &x660, x658, x609, x641);
uint32_t x661;
fiat_secp256k1_uint1 x662;
- fiat_secp256k1_addcarryx_u32(&x661, &x662, x660, x643, x611);
+ fiat_secp256k1_addcarryx_u32(&x661, &x662, x660, x611, x643);
uint32_t x663;
fiat_secp256k1_uint1 x664;
- fiat_secp256k1_addcarryx_u32(&x663, &x664, x662, x645, x613);
+ fiat_secp256k1_addcarryx_u32(&x663, &x664, x662, x613, x645);
uint32_t x665;
uint32_t x666;
fiat_secp256k1_mulx_u32(&x665, &x666, x647, UINT32_C(0xd2253531));
@@ -2433,58 +2433,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x681, &x682, x665, UINT32_C(0xfffffc2f));
uint32_t x683;
fiat_secp256k1_uint1 x684;
- fiat_secp256k1_addcarryx_u32(&x683, &x684, 0x0, x679, x682);
+ fiat_secp256k1_addcarryx_u32(&x683, &x684, 0x0, x682, x679);
uint32_t x685;
fiat_secp256k1_uint1 x686;
- fiat_secp256k1_addcarryx_u32(&x685, &x686, x684, x677, x680);
+ fiat_secp256k1_addcarryx_u32(&x685, &x686, x684, x680, x677);
uint32_t x687;
fiat_secp256k1_uint1 x688;
- fiat_secp256k1_addcarryx_u32(&x687, &x688, x686, x675, x678);
+ fiat_secp256k1_addcarryx_u32(&x687, &x688, x686, x678, x675);
uint32_t x689;
fiat_secp256k1_uint1 x690;
- fiat_secp256k1_addcarryx_u32(&x689, &x690, x688, x673, x676);
+ fiat_secp256k1_addcarryx_u32(&x689, &x690, x688, x676, x673);
uint32_t x691;
fiat_secp256k1_uint1 x692;
- fiat_secp256k1_addcarryx_u32(&x691, &x692, x690, x671, x674);
+ fiat_secp256k1_addcarryx_u32(&x691, &x692, x690, x674, x671);
uint32_t x693;
fiat_secp256k1_uint1 x694;
- fiat_secp256k1_addcarryx_u32(&x693, &x694, x692, x669, x672);
+ fiat_secp256k1_addcarryx_u32(&x693, &x694, x692, x672, x669);
uint32_t x695;
fiat_secp256k1_uint1 x696;
- fiat_secp256k1_addcarryx_u32(&x695, &x696, x694, x667, x670);
+ fiat_secp256k1_addcarryx_u32(&x695, &x696, x694, x670, x667);
uint32_t x697;
fiat_secp256k1_uint1 x698;
- fiat_secp256k1_addcarryx_u32(&x697, &x698, x696, 0x0, x668);
+ fiat_secp256k1_addcarryx_u32(&x697, &x698, x696, x668, 0x0);
uint32_t x699;
fiat_secp256k1_uint1 x700;
- fiat_secp256k1_addcarryx_u32(&x699, &x700, 0x0, x681, x647);
+ fiat_secp256k1_addcarryx_u32(&x699, &x700, 0x0, x647, x681);
uint32_t x701;
fiat_secp256k1_uint1 x702;
- fiat_secp256k1_addcarryx_u32(&x701, &x702, x700, x683, x649);
+ fiat_secp256k1_addcarryx_u32(&x701, &x702, x700, x649, x683);
uint32_t x703;
fiat_secp256k1_uint1 x704;
- fiat_secp256k1_addcarryx_u32(&x703, &x704, x702, x685, x651);
+ fiat_secp256k1_addcarryx_u32(&x703, &x704, x702, x651, x685);
uint32_t x705;
fiat_secp256k1_uint1 x706;
- fiat_secp256k1_addcarryx_u32(&x705, &x706, x704, x687, x653);
+ fiat_secp256k1_addcarryx_u32(&x705, &x706, x704, x653, x687);
uint32_t x707;
fiat_secp256k1_uint1 x708;
- fiat_secp256k1_addcarryx_u32(&x707, &x708, x706, x689, x655);
+ fiat_secp256k1_addcarryx_u32(&x707, &x708, x706, x655, x689);
uint32_t x709;
fiat_secp256k1_uint1 x710;
- fiat_secp256k1_addcarryx_u32(&x709, &x710, x708, x691, x657);
+ fiat_secp256k1_addcarryx_u32(&x709, &x710, x708, x657, x691);
uint32_t x711;
fiat_secp256k1_uint1 x712;
- fiat_secp256k1_addcarryx_u32(&x711, &x712, x710, x693, x659);
+ fiat_secp256k1_addcarryx_u32(&x711, &x712, x710, x659, x693);
uint32_t x713;
fiat_secp256k1_uint1 x714;
- fiat_secp256k1_addcarryx_u32(&x713, &x714, x712, x695, x661);
+ fiat_secp256k1_addcarryx_u32(&x713, &x714, x712, x661, x695);
uint32_t x715;
fiat_secp256k1_uint1 x716;
- fiat_secp256k1_addcarryx_u32(&x715, &x716, x714, x697, x663);
+ fiat_secp256k1_addcarryx_u32(&x715, &x716, x714, x663, x697);
uint32_t x717;
fiat_secp256k1_uint1 x718;
- fiat_secp256k1_addcarryx_u32(&x717, &x718, x716, 0x0, x664);
+ fiat_secp256k1_addcarryx_u32(&x717, &x718, x716, x664, 0x0);
uint32_t x719;
uint32_t x720;
fiat_secp256k1_mulx_u32(&x719, &x720, x7, (arg1[7]));
@@ -2511,55 +2511,55 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x733, &x734, x7, (arg1[0]));
uint32_t x735;
fiat_secp256k1_uint1 x736;
- fiat_secp256k1_addcarryx_u32(&x735, &x736, 0x0, x731, x734);
+ fiat_secp256k1_addcarryx_u32(&x735, &x736, 0x0, x734, x731);
uint32_t x737;
fiat_secp256k1_uint1 x738;
- fiat_secp256k1_addcarryx_u32(&x737, &x738, x736, x729, x732);
+ fiat_secp256k1_addcarryx_u32(&x737, &x738, x736, x732, x729);
uint32_t x739;
fiat_secp256k1_uint1 x740;
- fiat_secp256k1_addcarryx_u32(&x739, &x740, x738, x727, x730);
+ fiat_secp256k1_addcarryx_u32(&x739, &x740, x738, x730, x727);
uint32_t x741;
fiat_secp256k1_uint1 x742;
- fiat_secp256k1_addcarryx_u32(&x741, &x742, x740, x725, x728);
+ fiat_secp256k1_addcarryx_u32(&x741, &x742, x740, x728, x725);
uint32_t x743;
fiat_secp256k1_uint1 x744;
- fiat_secp256k1_addcarryx_u32(&x743, &x744, x742, x723, x726);
+ fiat_secp256k1_addcarryx_u32(&x743, &x744, x742, x726, x723);
uint32_t x745;
fiat_secp256k1_uint1 x746;
- fiat_secp256k1_addcarryx_u32(&x745, &x746, x744, x721, x724);
+ fiat_secp256k1_addcarryx_u32(&x745, &x746, x744, x724, x721);
uint32_t x747;
fiat_secp256k1_uint1 x748;
- fiat_secp256k1_addcarryx_u32(&x747, &x748, x746, x719, x722);
+ fiat_secp256k1_addcarryx_u32(&x747, &x748, x746, x722, x719);
uint32_t x749;
fiat_secp256k1_uint1 x750;
- fiat_secp256k1_addcarryx_u32(&x749, &x750, x748, 0x0, x720);
+ fiat_secp256k1_addcarryx_u32(&x749, &x750, x748, x720, 0x0);
uint32_t x751;
fiat_secp256k1_uint1 x752;
- fiat_secp256k1_addcarryx_u32(&x751, &x752, 0x0, x733, x701);
+ fiat_secp256k1_addcarryx_u32(&x751, &x752, 0x0, x701, x733);
uint32_t x753;
fiat_secp256k1_uint1 x754;
- fiat_secp256k1_addcarryx_u32(&x753, &x754, x752, x735, x703);
+ fiat_secp256k1_addcarryx_u32(&x753, &x754, x752, x703, x735);
uint32_t x755;
fiat_secp256k1_uint1 x756;
- fiat_secp256k1_addcarryx_u32(&x755, &x756, x754, x737, x705);
+ fiat_secp256k1_addcarryx_u32(&x755, &x756, x754, x705, x737);
uint32_t x757;
fiat_secp256k1_uint1 x758;
- fiat_secp256k1_addcarryx_u32(&x757, &x758, x756, x739, x707);
+ fiat_secp256k1_addcarryx_u32(&x757, &x758, x756, x707, x739);
uint32_t x759;
fiat_secp256k1_uint1 x760;
- fiat_secp256k1_addcarryx_u32(&x759, &x760, x758, x741, x709);
+ fiat_secp256k1_addcarryx_u32(&x759, &x760, x758, x709, x741);
uint32_t x761;
fiat_secp256k1_uint1 x762;
- fiat_secp256k1_addcarryx_u32(&x761, &x762, x760, x743, x711);
+ fiat_secp256k1_addcarryx_u32(&x761, &x762, x760, x711, x743);
uint32_t x763;
fiat_secp256k1_uint1 x764;
- fiat_secp256k1_addcarryx_u32(&x763, &x764, x762, x745, x713);
+ fiat_secp256k1_addcarryx_u32(&x763, &x764, x762, x713, x745);
uint32_t x765;
fiat_secp256k1_uint1 x766;
- fiat_secp256k1_addcarryx_u32(&x765, &x766, x764, x747, x715);
+ fiat_secp256k1_addcarryx_u32(&x765, &x766, x764, x715, x747);
uint32_t x767;
fiat_secp256k1_uint1 x768;
- fiat_secp256k1_addcarryx_u32(&x767, &x768, x766, x749, x717);
+ fiat_secp256k1_addcarryx_u32(&x767, &x768, x766, x717, x749);
uint32_t x769;
uint32_t x770;
fiat_secp256k1_mulx_u32(&x769, &x770, x751, UINT32_C(0xd2253531));
@@ -2589,58 +2589,58 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_mulx_u32(&x785, &x786, x769, UINT32_C(0xfffffc2f));
uint32_t x787;
fiat_secp256k1_uint1 x788;
- fiat_secp256k1_addcarryx_u32(&x787, &x788, 0x0, x783, x786);
+ fiat_secp256k1_addcarryx_u32(&x787, &x788, 0x0, x786, x783);
uint32_t x789;
fiat_secp256k1_uint1 x790;
- fiat_secp256k1_addcarryx_u32(&x789, &x790, x788, x781, x784);
+ fiat_secp256k1_addcarryx_u32(&x789, &x790, x788, x784, x781);
uint32_t x791;
fiat_secp256k1_uint1 x792;
- fiat_secp256k1_addcarryx_u32(&x791, &x792, x790, x779, x782);
+ fiat_secp256k1_addcarryx_u32(&x791, &x792, x790, x782, x779);
uint32_t x793;
fiat_secp256k1_uint1 x794;
- fiat_secp256k1_addcarryx_u32(&x793, &x794, x792, x777, x780);
+ fiat_secp256k1_addcarryx_u32(&x793, &x794, x792, x780, x777);
uint32_t x795;
fiat_secp256k1_uint1 x796;
- fiat_secp256k1_addcarryx_u32(&x795, &x796, x794, x775, x778);
+ fiat_secp256k1_addcarryx_u32(&x795, &x796, x794, x778, x775);
uint32_t x797;
fiat_secp256k1_uint1 x798;
- fiat_secp256k1_addcarryx_u32(&x797, &x798, x796, x773, x776);
+ fiat_secp256k1_addcarryx_u32(&x797, &x798, x796, x776, x773);
uint32_t x799;
fiat_secp256k1_uint1 x800;
- fiat_secp256k1_addcarryx_u32(&x799, &x800, x798, x771, x774);
+ fiat_secp256k1_addcarryx_u32(&x799, &x800, x798, x774, x771);
uint32_t x801;
fiat_secp256k1_uint1 x802;
- fiat_secp256k1_addcarryx_u32(&x801, &x802, x800, 0x0, x772);
+ fiat_secp256k1_addcarryx_u32(&x801, &x802, x800, x772, 0x0);
uint32_t x803;
fiat_secp256k1_uint1 x804;
- fiat_secp256k1_addcarryx_u32(&x803, &x804, 0x0, x785, x751);
+ fiat_secp256k1_addcarryx_u32(&x803, &x804, 0x0, x751, x785);
uint32_t x805;
fiat_secp256k1_uint1 x806;
- fiat_secp256k1_addcarryx_u32(&x805, &x806, x804, x787, x753);
+ fiat_secp256k1_addcarryx_u32(&x805, &x806, x804, x753, x787);
uint32_t x807;
fiat_secp256k1_uint1 x808;
- fiat_secp256k1_addcarryx_u32(&x807, &x808, x806, x789, x755);
+ fiat_secp256k1_addcarryx_u32(&x807, &x808, x806, x755, x789);
uint32_t x809;
fiat_secp256k1_uint1 x810;
- fiat_secp256k1_addcarryx_u32(&x809, &x810, x808, x791, x757);
+ fiat_secp256k1_addcarryx_u32(&x809, &x810, x808, x757, x791);
uint32_t x811;
fiat_secp256k1_uint1 x812;
- fiat_secp256k1_addcarryx_u32(&x811, &x812, x810, x793, x759);
+ fiat_secp256k1_addcarryx_u32(&x811, &x812, x810, x759, x793);
uint32_t x813;
fiat_secp256k1_uint1 x814;
- fiat_secp256k1_addcarryx_u32(&x813, &x814, x812, x795, x761);
+ fiat_secp256k1_addcarryx_u32(&x813, &x814, x812, x761, x795);
uint32_t x815;
fiat_secp256k1_uint1 x816;
- fiat_secp256k1_addcarryx_u32(&x815, &x816, x814, x797, x763);
+ fiat_secp256k1_addcarryx_u32(&x815, &x816, x814, x763, x797);
uint32_t x817;
fiat_secp256k1_uint1 x818;
- fiat_secp256k1_addcarryx_u32(&x817, &x818, x816, x799, x765);
+ fiat_secp256k1_addcarryx_u32(&x817, &x818, x816, x765, x799);
uint32_t x819;
fiat_secp256k1_uint1 x820;
- fiat_secp256k1_addcarryx_u32(&x819, &x820, x818, x801, x767);
+ fiat_secp256k1_addcarryx_u32(&x819, &x820, x818, x767, x801);
uint32_t x821;
fiat_secp256k1_uint1 x822;
- fiat_secp256k1_addcarryx_u32(&x821, &x822, x820, 0x0, x768);
+ fiat_secp256k1_addcarryx_u32(&x821, &x822, x820, x768, 0x0);
uint32_t x823;
fiat_secp256k1_uint1 x824;
fiat_secp256k1_subborrowx_u32(&x823, &x824, 0x0, x805, UINT32_C(0xfffffc2f));
@@ -2712,28 +2712,28 @@ static void fiat_secp256k1_square(uint32_t out1[8], const uint32_t arg1[8]) {
static void fiat_secp256k1_add(uint32_t out1[8], const uint32_t arg1[8], const uint32_t arg2[8]) {
uint32_t x1;
fiat_secp256k1_uint1 x2;
- fiat_secp256k1_addcarryx_u32(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_secp256k1_addcarryx_u32(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint32_t x3;
fiat_secp256k1_uint1 x4;
- fiat_secp256k1_addcarryx_u32(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_secp256k1_addcarryx_u32(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint32_t x5;
fiat_secp256k1_uint1 x6;
- fiat_secp256k1_addcarryx_u32(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_secp256k1_addcarryx_u32(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint32_t x7;
fiat_secp256k1_uint1 x8;
- fiat_secp256k1_addcarryx_u32(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_secp256k1_addcarryx_u32(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint32_t x9;
fiat_secp256k1_uint1 x10;
- fiat_secp256k1_addcarryx_u32(&x9, &x10, x8, (arg2[4]), (arg1[4]));
+ fiat_secp256k1_addcarryx_u32(&x9, &x10, x8, (arg1[4]), (arg2[4]));
uint32_t x11;
fiat_secp256k1_uint1 x12;
- fiat_secp256k1_addcarryx_u32(&x11, &x12, x10, (arg2[5]), (arg1[5]));
+ fiat_secp256k1_addcarryx_u32(&x11, &x12, x10, (arg1[5]), (arg2[5]));
uint32_t x13;
fiat_secp256k1_uint1 x14;
- fiat_secp256k1_addcarryx_u32(&x13, &x14, x12, (arg2[6]), (arg1[6]));
+ fiat_secp256k1_addcarryx_u32(&x13, &x14, x12, (arg1[6]), (arg2[6]));
uint32_t x15;
fiat_secp256k1_uint1 x16;
- fiat_secp256k1_addcarryx_u32(&x15, &x16, x14, (arg2[7]), (arg1[7]));
+ fiat_secp256k1_addcarryx_u32(&x15, &x16, x14, (arg1[7]), (arg2[7]));
uint32_t x17;
fiat_secp256k1_uint1 x18;
fiat_secp256k1_subborrowx_u32(&x17, &x18, 0x0, x1, UINT32_C(0xfffffc2f));
@@ -2831,28 +2831,28 @@ static void fiat_secp256k1_sub(uint32_t out1[8], const uint32_t arg1[8], const u
fiat_secp256k1_cmovznz_u32(&x17, x16, 0x0, UINT32_C(0xffffffff));
uint32_t x18;
fiat_secp256k1_uint1 x19;
- fiat_secp256k1_addcarryx_u32(&x18, &x19, 0x0, (x17 & UINT32_C(0xfffffc2f)), x1);
+ fiat_secp256k1_addcarryx_u32(&x18, &x19, 0x0, x1, (x17 & UINT32_C(0xfffffc2f)));
uint32_t x20;
fiat_secp256k1_uint1 x21;
- fiat_secp256k1_addcarryx_u32(&x20, &x21, x19, (x17 & UINT32_C(0xfffffffe)), x3);
+ fiat_secp256k1_addcarryx_u32(&x20, &x21, x19, x3, (x17 & UINT32_C(0xfffffffe)));
uint32_t x22;
fiat_secp256k1_uint1 x23;
- fiat_secp256k1_addcarryx_u32(&x22, &x23, x21, (x17 & UINT32_C(0xffffffff)), x5);
+ fiat_secp256k1_addcarryx_u32(&x22, &x23, x21, x5, (x17 & UINT32_C(0xffffffff)));
uint32_t x24;
fiat_secp256k1_uint1 x25;
- fiat_secp256k1_addcarryx_u32(&x24, &x25, x23, (x17 & UINT32_C(0xffffffff)), x7);
+ fiat_secp256k1_addcarryx_u32(&x24, &x25, x23, x7, (x17 & UINT32_C(0xffffffff)));
uint32_t x26;
fiat_secp256k1_uint1 x27;
- fiat_secp256k1_addcarryx_u32(&x26, &x27, x25, (x17 & UINT32_C(0xffffffff)), x9);
+ fiat_secp256k1_addcarryx_u32(&x26, &x27, x25, x9, (x17 & UINT32_C(0xffffffff)));
uint32_t x28;
fiat_secp256k1_uint1 x29;
- fiat_secp256k1_addcarryx_u32(&x28, &x29, x27, (x17 & UINT32_C(0xffffffff)), x11);
+ fiat_secp256k1_addcarryx_u32(&x28, &x29, x27, x11, (x17 & UINT32_C(0xffffffff)));
uint32_t x30;
fiat_secp256k1_uint1 x31;
- fiat_secp256k1_addcarryx_u32(&x30, &x31, x29, (x17 & UINT32_C(0xffffffff)), x13);
+ fiat_secp256k1_addcarryx_u32(&x30, &x31, x29, x13, (x17 & UINT32_C(0xffffffff)));
uint32_t x32;
fiat_secp256k1_uint1 x33;
- fiat_secp256k1_addcarryx_u32(&x32, &x33, x31, (x17 & UINT32_C(0xffffffff)), x15);
+ fiat_secp256k1_addcarryx_u32(&x32, &x33, x31, x15, (x17 & UINT32_C(0xffffffff)));
out1[0] = x18;
out1[1] = x20;
out1[2] = x22;
@@ -2905,28 +2905,28 @@ static void fiat_secp256k1_opp(uint32_t out1[8], const uint32_t arg1[8]) {
fiat_secp256k1_cmovznz_u32(&x17, x16, 0x0, UINT32_C(0xffffffff));
uint32_t x18;
fiat_secp256k1_uint1 x19;
- fiat_secp256k1_addcarryx_u32(&x18, &x19, 0x0, (x17 & UINT32_C(0xfffffc2f)), x1);
+ fiat_secp256k1_addcarryx_u32(&x18, &x19, 0x0, x1, (x17 & UINT32_C(0xfffffc2f)));
uint32_t x20;
fiat_secp256k1_uint1 x21;
- fiat_secp256k1_addcarryx_u32(&x20, &x21, x19, (x17 & UINT32_C(0xfffffffe)), x3);
+ fiat_secp256k1_addcarryx_u32(&x20, &x21, x19, x3, (x17 & UINT32_C(0xfffffffe)));
uint32_t x22;
fiat_secp256k1_uint1 x23;
- fiat_secp256k1_addcarryx_u32(&x22, &x23, x21, (x17 & UINT32_C(0xffffffff)), x5);
+ fiat_secp256k1_addcarryx_u32(&x22, &x23, x21, x5, (x17 & UINT32_C(0xffffffff)));
uint32_t x24;
fiat_secp256k1_uint1 x25;
- fiat_secp256k1_addcarryx_u32(&x24, &x25, x23, (x17 & UINT32_C(0xffffffff)), x7);
+ fiat_secp256k1_addcarryx_u32(&x24, &x25, x23, x7, (x17 & UINT32_C(0xffffffff)));
uint32_t x26;
fiat_secp256k1_uint1 x27;
- fiat_secp256k1_addcarryx_u32(&x26, &x27, x25, (x17 & UINT32_C(0xffffffff)), x9);
+ fiat_secp256k1_addcarryx_u32(&x26, &x27, x25, x9, (x17 & UINT32_C(0xffffffff)));
uint32_t x28;
fiat_secp256k1_uint1 x29;
- fiat_secp256k1_addcarryx_u32(&x28, &x29, x27, (x17 & UINT32_C(0xffffffff)), x11);
+ fiat_secp256k1_addcarryx_u32(&x28, &x29, x27, x11, (x17 & UINT32_C(0xffffffff)));
uint32_t x30;
fiat_secp256k1_uint1 x31;
- fiat_secp256k1_addcarryx_u32(&x30, &x31, x29, (x17 & UINT32_C(0xffffffff)), x13);
+ fiat_secp256k1_addcarryx_u32(&x30, &x31, x29, x13, (x17 & UINT32_C(0xffffffff)));
uint32_t x32;
fiat_secp256k1_uint1 x33;
- fiat_secp256k1_addcarryx_u32(&x32, &x33, x31, (x17 & UINT32_C(0xffffffff)), x15);
+ fiat_secp256k1_addcarryx_u32(&x32, &x33, x31, x15, (x17 & UINT32_C(0xffffffff)));
out1[0] = x18;
out1[1] = x20;
out1[2] = x22;
@@ -2981,79 +2981,79 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x18, &x19, x2, UINT32_C(0xfffffc2f));
uint32_t x20;
fiat_secp256k1_uint1 x21;
- fiat_secp256k1_addcarryx_u32(&x20, &x21, 0x0, x16, x19);
+ fiat_secp256k1_addcarryx_u32(&x20, &x21, 0x0, x19, x16);
uint32_t x22;
fiat_secp256k1_uint1 x23;
- fiat_secp256k1_addcarryx_u32(&x22, &x23, x21, x14, x17);
+ fiat_secp256k1_addcarryx_u32(&x22, &x23, x21, x17, x14);
uint32_t x24;
fiat_secp256k1_uint1 x25;
- fiat_secp256k1_addcarryx_u32(&x24, &x25, x23, x12, x15);
+ fiat_secp256k1_addcarryx_u32(&x24, &x25, x23, x15, x12);
uint32_t x26;
fiat_secp256k1_uint1 x27;
- fiat_secp256k1_addcarryx_u32(&x26, &x27, x25, x10, x13);
+ fiat_secp256k1_addcarryx_u32(&x26, &x27, x25, x13, x10);
uint32_t x28;
fiat_secp256k1_uint1 x29;
- fiat_secp256k1_addcarryx_u32(&x28, &x29, x27, x8, x11);
+ fiat_secp256k1_addcarryx_u32(&x28, &x29, x27, x11, x8);
uint32_t x30;
fiat_secp256k1_uint1 x31;
- fiat_secp256k1_addcarryx_u32(&x30, &x31, x29, x6, x9);
+ fiat_secp256k1_addcarryx_u32(&x30, &x31, x29, x9, x6);
uint32_t x32;
fiat_secp256k1_uint1 x33;
- fiat_secp256k1_addcarryx_u32(&x32, &x33, x31, x4, x7);
+ fiat_secp256k1_addcarryx_u32(&x32, &x33, x31, x7, x4);
uint32_t x34;
fiat_secp256k1_uint1 x35;
- fiat_secp256k1_addcarryx_u32(&x34, &x35, 0x0, x18, x1);
+ fiat_secp256k1_addcarryx_u32(&x34, &x35, 0x0, x1, x18);
uint32_t x36;
fiat_secp256k1_uint1 x37;
- fiat_secp256k1_addcarryx_u32(&x36, &x37, x35, x20, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x36, &x37, x35, 0x0, x20);
uint32_t x38;
fiat_secp256k1_uint1 x39;
- fiat_secp256k1_addcarryx_u32(&x38, &x39, x37, x22, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x38, &x39, x37, 0x0, x22);
uint32_t x40;
fiat_secp256k1_uint1 x41;
- fiat_secp256k1_addcarryx_u32(&x40, &x41, x39, x24, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x40, &x41, x39, 0x0, x24);
uint32_t x42;
fiat_secp256k1_uint1 x43;
- fiat_secp256k1_addcarryx_u32(&x42, &x43, x41, x26, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x42, &x43, x41, 0x0, x26);
uint32_t x44;
fiat_secp256k1_uint1 x45;
- fiat_secp256k1_addcarryx_u32(&x44, &x45, x43, x28, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x44, &x45, x43, 0x0, x28);
uint32_t x46;
fiat_secp256k1_uint1 x47;
- fiat_secp256k1_addcarryx_u32(&x46, &x47, x45, x30, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x46, &x47, x45, 0x0, x30);
uint32_t x48;
fiat_secp256k1_uint1 x49;
- fiat_secp256k1_addcarryx_u32(&x48, &x49, x47, x32, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x48, &x49, x47, 0x0, x32);
uint32_t x50;
fiat_secp256k1_uint1 x51;
- fiat_secp256k1_addcarryx_u32(&x50, &x51, x33, 0x0, x5);
+ fiat_secp256k1_addcarryx_u32(&x50, &x51, x33, x5, 0x0);
uint32_t x52;
fiat_secp256k1_uint1 x53;
- fiat_secp256k1_addcarryx_u32(&x52, &x53, x49, x50, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x52, &x53, x49, 0x0, x50);
uint32_t x54;
fiat_secp256k1_uint1 x55;
- fiat_secp256k1_addcarryx_u32(&x54, &x55, 0x0, (arg1[1]), x36);
+ fiat_secp256k1_addcarryx_u32(&x54, &x55, 0x0, x36, (arg1[1]));
uint32_t x56;
fiat_secp256k1_uint1 x57;
- fiat_secp256k1_addcarryx_u32(&x56, &x57, x55, 0x0, x38);
+ fiat_secp256k1_addcarryx_u32(&x56, &x57, x55, x38, 0x0);
uint32_t x58;
fiat_secp256k1_uint1 x59;
- fiat_secp256k1_addcarryx_u32(&x58, &x59, x57, 0x0, x40);
+ fiat_secp256k1_addcarryx_u32(&x58, &x59, x57, x40, 0x0);
uint32_t x60;
fiat_secp256k1_uint1 x61;
- fiat_secp256k1_addcarryx_u32(&x60, &x61, x59, 0x0, x42);
+ fiat_secp256k1_addcarryx_u32(&x60, &x61, x59, x42, 0x0);
uint32_t x62;
fiat_secp256k1_uint1 x63;
- fiat_secp256k1_addcarryx_u32(&x62, &x63, x61, 0x0, x44);
+ fiat_secp256k1_addcarryx_u32(&x62, &x63, x61, x44, 0x0);
uint32_t x64;
fiat_secp256k1_uint1 x65;
- fiat_secp256k1_addcarryx_u32(&x64, &x65, x63, 0x0, x46);
+ fiat_secp256k1_addcarryx_u32(&x64, &x65, x63, x46, 0x0);
uint32_t x66;
fiat_secp256k1_uint1 x67;
- fiat_secp256k1_addcarryx_u32(&x66, &x67, x65, 0x0, x48);
+ fiat_secp256k1_addcarryx_u32(&x66, &x67, x65, x48, 0x0);
uint32_t x68;
fiat_secp256k1_uint1 x69;
- fiat_secp256k1_addcarryx_u32(&x68, &x69, x67, 0x0, x52);
+ fiat_secp256k1_addcarryx_u32(&x68, &x69, x67, x52, 0x0);
uint32_t x70;
uint32_t x71;
fiat_secp256k1_mulx_u32(&x70, &x71, x54, UINT32_C(0xd2253531));
@@ -3083,85 +3083,85 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x86, &x87, x70, UINT32_C(0xfffffc2f));
uint32_t x88;
fiat_secp256k1_uint1 x89;
- fiat_secp256k1_addcarryx_u32(&x88, &x89, 0x0, x84, x87);
+ fiat_secp256k1_addcarryx_u32(&x88, &x89, 0x0, x87, x84);
uint32_t x90;
fiat_secp256k1_uint1 x91;
- fiat_secp256k1_addcarryx_u32(&x90, &x91, x89, x82, x85);
+ fiat_secp256k1_addcarryx_u32(&x90, &x91, x89, x85, x82);
uint32_t x92;
fiat_secp256k1_uint1 x93;
- fiat_secp256k1_addcarryx_u32(&x92, &x93, x91, x80, x83);
+ fiat_secp256k1_addcarryx_u32(&x92, &x93, x91, x83, x80);
uint32_t x94;
fiat_secp256k1_uint1 x95;
- fiat_secp256k1_addcarryx_u32(&x94, &x95, x93, x78, x81);
+ fiat_secp256k1_addcarryx_u32(&x94, &x95, x93, x81, x78);
uint32_t x96;
fiat_secp256k1_uint1 x97;
- fiat_secp256k1_addcarryx_u32(&x96, &x97, x95, x76, x79);
+ fiat_secp256k1_addcarryx_u32(&x96, &x97, x95, x79, x76);
uint32_t x98;
fiat_secp256k1_uint1 x99;
- fiat_secp256k1_addcarryx_u32(&x98, &x99, x97, x74, x77);
+ fiat_secp256k1_addcarryx_u32(&x98, &x99, x97, x77, x74);
uint32_t x100;
fiat_secp256k1_uint1 x101;
- fiat_secp256k1_addcarryx_u32(&x100, &x101, x99, x72, x75);
+ fiat_secp256k1_addcarryx_u32(&x100, &x101, x99, x75, x72);
uint32_t x102;
fiat_secp256k1_uint1 x103;
- fiat_secp256k1_addcarryx_u32(&x102, &x103, 0x0, x86, x54);
+ fiat_secp256k1_addcarryx_u32(&x102, &x103, 0x0, x54, x86);
uint32_t x104;
fiat_secp256k1_uint1 x105;
- fiat_secp256k1_addcarryx_u32(&x104, &x105, x103, x88, x56);
+ fiat_secp256k1_addcarryx_u32(&x104, &x105, x103, x56, x88);
uint32_t x106;
fiat_secp256k1_uint1 x107;
- fiat_secp256k1_addcarryx_u32(&x106, &x107, x105, x90, x58);
+ fiat_secp256k1_addcarryx_u32(&x106, &x107, x105, x58, x90);
uint32_t x108;
fiat_secp256k1_uint1 x109;
- fiat_secp256k1_addcarryx_u32(&x108, &x109, x107, x92, x60);
+ fiat_secp256k1_addcarryx_u32(&x108, &x109, x107, x60, x92);
uint32_t x110;
fiat_secp256k1_uint1 x111;
- fiat_secp256k1_addcarryx_u32(&x110, &x111, x109, x94, x62);
+ fiat_secp256k1_addcarryx_u32(&x110, &x111, x109, x62, x94);
uint32_t x112;
fiat_secp256k1_uint1 x113;
- fiat_secp256k1_addcarryx_u32(&x112, &x113, x111, x96, x64);
+ fiat_secp256k1_addcarryx_u32(&x112, &x113, x111, x64, x96);
uint32_t x114;
fiat_secp256k1_uint1 x115;
- fiat_secp256k1_addcarryx_u32(&x114, &x115, x113, x98, x66);
+ fiat_secp256k1_addcarryx_u32(&x114, &x115, x113, x66, x98);
uint32_t x116;
fiat_secp256k1_uint1 x117;
- fiat_secp256k1_addcarryx_u32(&x116, &x117, x115, x100, x68);
+ fiat_secp256k1_addcarryx_u32(&x116, &x117, x115, x68, x100);
uint32_t x118;
fiat_secp256k1_uint1 x119;
- fiat_secp256k1_addcarryx_u32(&x118, &x119, x53, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x118, &x119, x101, x73, 0x0);
uint32_t x120;
fiat_secp256k1_uint1 x121;
- fiat_secp256k1_addcarryx_u32(&x120, &x121, x69, 0x0, (fiat_secp256k1_uint1)x118);
+ fiat_secp256k1_addcarryx_u32(&x120, &x121, x53, 0x0, 0x0);
uint32_t x122;
fiat_secp256k1_uint1 x123;
- fiat_secp256k1_addcarryx_u32(&x122, &x123, x101, 0x0, x73);
+ fiat_secp256k1_addcarryx_u32(&x122, &x123, x69, (fiat_secp256k1_uint1)x120, 0x0);
uint32_t x124;
fiat_secp256k1_uint1 x125;
- fiat_secp256k1_addcarryx_u32(&x124, &x125, x117, x122, x120);
+ fiat_secp256k1_addcarryx_u32(&x124, &x125, x117, x122, x118);
uint32_t x126;
fiat_secp256k1_uint1 x127;
- fiat_secp256k1_addcarryx_u32(&x126, &x127, 0x0, (arg1[2]), x104);
+ fiat_secp256k1_addcarryx_u32(&x126, &x127, 0x0, x104, (arg1[2]));
uint32_t x128;
fiat_secp256k1_uint1 x129;
- fiat_secp256k1_addcarryx_u32(&x128, &x129, x127, 0x0, x106);
+ fiat_secp256k1_addcarryx_u32(&x128, &x129, x127, x106, 0x0);
uint32_t x130;
fiat_secp256k1_uint1 x131;
- fiat_secp256k1_addcarryx_u32(&x130, &x131, x129, 0x0, x108);
+ fiat_secp256k1_addcarryx_u32(&x130, &x131, x129, x108, 0x0);
uint32_t x132;
fiat_secp256k1_uint1 x133;
- fiat_secp256k1_addcarryx_u32(&x132, &x133, x131, 0x0, x110);
+ fiat_secp256k1_addcarryx_u32(&x132, &x133, x131, x110, 0x0);
uint32_t x134;
fiat_secp256k1_uint1 x135;
- fiat_secp256k1_addcarryx_u32(&x134, &x135, x133, 0x0, x112);
+ fiat_secp256k1_addcarryx_u32(&x134, &x135, x133, x112, 0x0);
uint32_t x136;
fiat_secp256k1_uint1 x137;
- fiat_secp256k1_addcarryx_u32(&x136, &x137, x135, 0x0, x114);
+ fiat_secp256k1_addcarryx_u32(&x136, &x137, x135, x114, 0x0);
uint32_t x138;
fiat_secp256k1_uint1 x139;
- fiat_secp256k1_addcarryx_u32(&x138, &x139, x137, 0x0, x116);
+ fiat_secp256k1_addcarryx_u32(&x138, &x139, x137, x116, 0x0);
uint32_t x140;
fiat_secp256k1_uint1 x141;
- fiat_secp256k1_addcarryx_u32(&x140, &x141, x139, 0x0, x124);
+ fiat_secp256k1_addcarryx_u32(&x140, &x141, x139, x124, 0x0);
uint32_t x142;
uint32_t x143;
fiat_secp256k1_mulx_u32(&x142, &x143, x126, UINT32_C(0xd2253531));
@@ -3191,85 +3191,85 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x158, &x159, x142, UINT32_C(0xfffffc2f));
uint32_t x160;
fiat_secp256k1_uint1 x161;
- fiat_secp256k1_addcarryx_u32(&x160, &x161, 0x0, x156, x159);
+ fiat_secp256k1_addcarryx_u32(&x160, &x161, 0x0, x159, x156);
uint32_t x162;
fiat_secp256k1_uint1 x163;
- fiat_secp256k1_addcarryx_u32(&x162, &x163, x161, x154, x157);
+ fiat_secp256k1_addcarryx_u32(&x162, &x163, x161, x157, x154);
uint32_t x164;
fiat_secp256k1_uint1 x165;
- fiat_secp256k1_addcarryx_u32(&x164, &x165, x163, x152, x155);
+ fiat_secp256k1_addcarryx_u32(&x164, &x165, x163, x155, x152);
uint32_t x166;
fiat_secp256k1_uint1 x167;
- fiat_secp256k1_addcarryx_u32(&x166, &x167, x165, x150, x153);
+ fiat_secp256k1_addcarryx_u32(&x166, &x167, x165, x153, x150);
uint32_t x168;
fiat_secp256k1_uint1 x169;
- fiat_secp256k1_addcarryx_u32(&x168, &x169, x167, x148, x151);
+ fiat_secp256k1_addcarryx_u32(&x168, &x169, x167, x151, x148);
uint32_t x170;
fiat_secp256k1_uint1 x171;
- fiat_secp256k1_addcarryx_u32(&x170, &x171, x169, x146, x149);
+ fiat_secp256k1_addcarryx_u32(&x170, &x171, x169, x149, x146);
uint32_t x172;
fiat_secp256k1_uint1 x173;
- fiat_secp256k1_addcarryx_u32(&x172, &x173, x171, x144, x147);
+ fiat_secp256k1_addcarryx_u32(&x172, &x173, x171, x147, x144);
uint32_t x174;
fiat_secp256k1_uint1 x175;
- fiat_secp256k1_addcarryx_u32(&x174, &x175, 0x0, x158, x126);
+ fiat_secp256k1_addcarryx_u32(&x174, &x175, 0x0, x126, x158);
uint32_t x176;
fiat_secp256k1_uint1 x177;
- fiat_secp256k1_addcarryx_u32(&x176, &x177, x175, x160, x128);
+ fiat_secp256k1_addcarryx_u32(&x176, &x177, x175, x128, x160);
uint32_t x178;
fiat_secp256k1_uint1 x179;
- fiat_secp256k1_addcarryx_u32(&x178, &x179, x177, x162, x130);
+ fiat_secp256k1_addcarryx_u32(&x178, &x179, x177, x130, x162);
uint32_t x180;
fiat_secp256k1_uint1 x181;
- fiat_secp256k1_addcarryx_u32(&x180, &x181, x179, x164, x132);
+ fiat_secp256k1_addcarryx_u32(&x180, &x181, x179, x132, x164);
uint32_t x182;
fiat_secp256k1_uint1 x183;
- fiat_secp256k1_addcarryx_u32(&x182, &x183, x181, x166, x134);
+ fiat_secp256k1_addcarryx_u32(&x182, &x183, x181, x134, x166);
uint32_t x184;
fiat_secp256k1_uint1 x185;
- fiat_secp256k1_addcarryx_u32(&x184, &x185, x183, x168, x136);
+ fiat_secp256k1_addcarryx_u32(&x184, &x185, x183, x136, x168);
uint32_t x186;
fiat_secp256k1_uint1 x187;
- fiat_secp256k1_addcarryx_u32(&x186, &x187, x185, x170, x138);
+ fiat_secp256k1_addcarryx_u32(&x186, &x187, x185, x138, x170);
uint32_t x188;
fiat_secp256k1_uint1 x189;
- fiat_secp256k1_addcarryx_u32(&x188, &x189, x187, x172, x140);
+ fiat_secp256k1_addcarryx_u32(&x188, &x189, x187, x140, x172);
uint32_t x190;
fiat_secp256k1_uint1 x191;
- fiat_secp256k1_addcarryx_u32(&x190, &x191, x125, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x190, &x191, x173, x145, 0x0);
uint32_t x192;
fiat_secp256k1_uint1 x193;
- fiat_secp256k1_addcarryx_u32(&x192, &x193, x141, 0x0, (fiat_secp256k1_uint1)x190);
+ fiat_secp256k1_addcarryx_u32(&x192, &x193, x125, 0x0, 0x0);
uint32_t x194;
fiat_secp256k1_uint1 x195;
- fiat_secp256k1_addcarryx_u32(&x194, &x195, x173, 0x0, x145);
+ fiat_secp256k1_addcarryx_u32(&x194, &x195, x141, (fiat_secp256k1_uint1)x192, 0x0);
uint32_t x196;
fiat_secp256k1_uint1 x197;
- fiat_secp256k1_addcarryx_u32(&x196, &x197, x189, x194, x192);
+ fiat_secp256k1_addcarryx_u32(&x196, &x197, x189, x194, x190);
uint32_t x198;
fiat_secp256k1_uint1 x199;
- fiat_secp256k1_addcarryx_u32(&x198, &x199, 0x0, (arg1[3]), x176);
+ fiat_secp256k1_addcarryx_u32(&x198, &x199, 0x0, x176, (arg1[3]));
uint32_t x200;
fiat_secp256k1_uint1 x201;
- fiat_secp256k1_addcarryx_u32(&x200, &x201, x199, 0x0, x178);
+ fiat_secp256k1_addcarryx_u32(&x200, &x201, x199, x178, 0x0);
uint32_t x202;
fiat_secp256k1_uint1 x203;
- fiat_secp256k1_addcarryx_u32(&x202, &x203, x201, 0x0, x180);
+ fiat_secp256k1_addcarryx_u32(&x202, &x203, x201, x180, 0x0);
uint32_t x204;
fiat_secp256k1_uint1 x205;
- fiat_secp256k1_addcarryx_u32(&x204, &x205, x203, 0x0, x182);
+ fiat_secp256k1_addcarryx_u32(&x204, &x205, x203, x182, 0x0);
uint32_t x206;
fiat_secp256k1_uint1 x207;
- fiat_secp256k1_addcarryx_u32(&x206, &x207, x205, 0x0, x184);
+ fiat_secp256k1_addcarryx_u32(&x206, &x207, x205, x184, 0x0);
uint32_t x208;
fiat_secp256k1_uint1 x209;
- fiat_secp256k1_addcarryx_u32(&x208, &x209, x207, 0x0, x186);
+ fiat_secp256k1_addcarryx_u32(&x208, &x209, x207, x186, 0x0);
uint32_t x210;
fiat_secp256k1_uint1 x211;
- fiat_secp256k1_addcarryx_u32(&x210, &x211, x209, 0x0, x188);
+ fiat_secp256k1_addcarryx_u32(&x210, &x211, x209, x188, 0x0);
uint32_t x212;
fiat_secp256k1_uint1 x213;
- fiat_secp256k1_addcarryx_u32(&x212, &x213, x211, 0x0, x196);
+ fiat_secp256k1_addcarryx_u32(&x212, &x213, x211, x196, 0x0);
uint32_t x214;
uint32_t x215;
fiat_secp256k1_mulx_u32(&x214, &x215, x198, UINT32_C(0xd2253531));
@@ -3299,85 +3299,85 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x230, &x231, x214, UINT32_C(0xfffffc2f));
uint32_t x232;
fiat_secp256k1_uint1 x233;
- fiat_secp256k1_addcarryx_u32(&x232, &x233, 0x0, x228, x231);
+ fiat_secp256k1_addcarryx_u32(&x232, &x233, 0x0, x231, x228);
uint32_t x234;
fiat_secp256k1_uint1 x235;
- fiat_secp256k1_addcarryx_u32(&x234, &x235, x233, x226, x229);
+ fiat_secp256k1_addcarryx_u32(&x234, &x235, x233, x229, x226);
uint32_t x236;
fiat_secp256k1_uint1 x237;
- fiat_secp256k1_addcarryx_u32(&x236, &x237, x235, x224, x227);
+ fiat_secp256k1_addcarryx_u32(&x236, &x237, x235, x227, x224);
uint32_t x238;
fiat_secp256k1_uint1 x239;
- fiat_secp256k1_addcarryx_u32(&x238, &x239, x237, x222, x225);
+ fiat_secp256k1_addcarryx_u32(&x238, &x239, x237, x225, x222);
uint32_t x240;
fiat_secp256k1_uint1 x241;
- fiat_secp256k1_addcarryx_u32(&x240, &x241, x239, x220, x223);
+ fiat_secp256k1_addcarryx_u32(&x240, &x241, x239, x223, x220);
uint32_t x242;
fiat_secp256k1_uint1 x243;
- fiat_secp256k1_addcarryx_u32(&x242, &x243, x241, x218, x221);
+ fiat_secp256k1_addcarryx_u32(&x242, &x243, x241, x221, x218);
uint32_t x244;
fiat_secp256k1_uint1 x245;
- fiat_secp256k1_addcarryx_u32(&x244, &x245, x243, x216, x219);
+ fiat_secp256k1_addcarryx_u32(&x244, &x245, x243, x219, x216);
uint32_t x246;
fiat_secp256k1_uint1 x247;
- fiat_secp256k1_addcarryx_u32(&x246, &x247, 0x0, x230, x198);
+ fiat_secp256k1_addcarryx_u32(&x246, &x247, 0x0, x198, x230);
uint32_t x248;
fiat_secp256k1_uint1 x249;
- fiat_secp256k1_addcarryx_u32(&x248, &x249, x247, x232, x200);
+ fiat_secp256k1_addcarryx_u32(&x248, &x249, x247, x200, x232);
uint32_t x250;
fiat_secp256k1_uint1 x251;
- fiat_secp256k1_addcarryx_u32(&x250, &x251, x249, x234, x202);
+ fiat_secp256k1_addcarryx_u32(&x250, &x251, x249, x202, x234);
uint32_t x252;
fiat_secp256k1_uint1 x253;
- fiat_secp256k1_addcarryx_u32(&x252, &x253, x251, x236, x204);
+ fiat_secp256k1_addcarryx_u32(&x252, &x253, x251, x204, x236);
uint32_t x254;
fiat_secp256k1_uint1 x255;
- fiat_secp256k1_addcarryx_u32(&x254, &x255, x253, x238, x206);
+ fiat_secp256k1_addcarryx_u32(&x254, &x255, x253, x206, x238);
uint32_t x256;
fiat_secp256k1_uint1 x257;
- fiat_secp256k1_addcarryx_u32(&x256, &x257, x255, x240, x208);
+ fiat_secp256k1_addcarryx_u32(&x256, &x257, x255, x208, x240);
uint32_t x258;
fiat_secp256k1_uint1 x259;
- fiat_secp256k1_addcarryx_u32(&x258, &x259, x257, x242, x210);
+ fiat_secp256k1_addcarryx_u32(&x258, &x259, x257, x210, x242);
uint32_t x260;
fiat_secp256k1_uint1 x261;
- fiat_secp256k1_addcarryx_u32(&x260, &x261, x259, x244, x212);
+ fiat_secp256k1_addcarryx_u32(&x260, &x261, x259, x212, x244);
uint32_t x262;
fiat_secp256k1_uint1 x263;
- fiat_secp256k1_addcarryx_u32(&x262, &x263, x197, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x262, &x263, x245, x217, 0x0);
uint32_t x264;
fiat_secp256k1_uint1 x265;
- fiat_secp256k1_addcarryx_u32(&x264, &x265, x213, 0x0, (fiat_secp256k1_uint1)x262);
+ fiat_secp256k1_addcarryx_u32(&x264, &x265, x197, 0x0, 0x0);
uint32_t x266;
fiat_secp256k1_uint1 x267;
- fiat_secp256k1_addcarryx_u32(&x266, &x267, x245, 0x0, x217);
+ fiat_secp256k1_addcarryx_u32(&x266, &x267, x213, (fiat_secp256k1_uint1)x264, 0x0);
uint32_t x268;
fiat_secp256k1_uint1 x269;
- fiat_secp256k1_addcarryx_u32(&x268, &x269, x261, x266, x264);
+ fiat_secp256k1_addcarryx_u32(&x268, &x269, x261, x266, x262);
uint32_t x270;
fiat_secp256k1_uint1 x271;
- fiat_secp256k1_addcarryx_u32(&x270, &x271, 0x0, (arg1[4]), x248);
+ fiat_secp256k1_addcarryx_u32(&x270, &x271, 0x0, x248, (arg1[4]));
uint32_t x272;
fiat_secp256k1_uint1 x273;
- fiat_secp256k1_addcarryx_u32(&x272, &x273, x271, 0x0, x250);
+ fiat_secp256k1_addcarryx_u32(&x272, &x273, x271, x250, 0x0);
uint32_t x274;
fiat_secp256k1_uint1 x275;
- fiat_secp256k1_addcarryx_u32(&x274, &x275, x273, 0x0, x252);
+ fiat_secp256k1_addcarryx_u32(&x274, &x275, x273, x252, 0x0);
uint32_t x276;
fiat_secp256k1_uint1 x277;
- fiat_secp256k1_addcarryx_u32(&x276, &x277, x275, 0x0, x254);
+ fiat_secp256k1_addcarryx_u32(&x276, &x277, x275, x254, 0x0);
uint32_t x278;
fiat_secp256k1_uint1 x279;
- fiat_secp256k1_addcarryx_u32(&x278, &x279, x277, 0x0, x256);
+ fiat_secp256k1_addcarryx_u32(&x278, &x279, x277, x256, 0x0);
uint32_t x280;
fiat_secp256k1_uint1 x281;
- fiat_secp256k1_addcarryx_u32(&x280, &x281, x279, 0x0, x258);
+ fiat_secp256k1_addcarryx_u32(&x280, &x281, x279, x258, 0x0);
uint32_t x282;
fiat_secp256k1_uint1 x283;
- fiat_secp256k1_addcarryx_u32(&x282, &x283, x281, 0x0, x260);
+ fiat_secp256k1_addcarryx_u32(&x282, &x283, x281, x260, 0x0);
uint32_t x284;
fiat_secp256k1_uint1 x285;
- fiat_secp256k1_addcarryx_u32(&x284, &x285, x283, 0x0, x268);
+ fiat_secp256k1_addcarryx_u32(&x284, &x285, x283, x268, 0x0);
uint32_t x286;
uint32_t x287;
fiat_secp256k1_mulx_u32(&x286, &x287, x270, UINT32_C(0xd2253531));
@@ -3407,85 +3407,85 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x302, &x303, x286, UINT32_C(0xfffffc2f));
uint32_t x304;
fiat_secp256k1_uint1 x305;
- fiat_secp256k1_addcarryx_u32(&x304, &x305, 0x0, x300, x303);
+ fiat_secp256k1_addcarryx_u32(&x304, &x305, 0x0, x303, x300);
uint32_t x306;
fiat_secp256k1_uint1 x307;
- fiat_secp256k1_addcarryx_u32(&x306, &x307, x305, x298, x301);
+ fiat_secp256k1_addcarryx_u32(&x306, &x307, x305, x301, x298);
uint32_t x308;
fiat_secp256k1_uint1 x309;
- fiat_secp256k1_addcarryx_u32(&x308, &x309, x307, x296, x299);
+ fiat_secp256k1_addcarryx_u32(&x308, &x309, x307, x299, x296);
uint32_t x310;
fiat_secp256k1_uint1 x311;
- fiat_secp256k1_addcarryx_u32(&x310, &x311, x309, x294, x297);
+ fiat_secp256k1_addcarryx_u32(&x310, &x311, x309, x297, x294);
uint32_t x312;
fiat_secp256k1_uint1 x313;
- fiat_secp256k1_addcarryx_u32(&x312, &x313, x311, x292, x295);
+ fiat_secp256k1_addcarryx_u32(&x312, &x313, x311, x295, x292);
uint32_t x314;
fiat_secp256k1_uint1 x315;
- fiat_secp256k1_addcarryx_u32(&x314, &x315, x313, x290, x293);
+ fiat_secp256k1_addcarryx_u32(&x314, &x315, x313, x293, x290);
uint32_t x316;
fiat_secp256k1_uint1 x317;
- fiat_secp256k1_addcarryx_u32(&x316, &x317, x315, x288, x291);
+ fiat_secp256k1_addcarryx_u32(&x316, &x317, x315, x291, x288);
uint32_t x318;
fiat_secp256k1_uint1 x319;
- fiat_secp256k1_addcarryx_u32(&x318, &x319, 0x0, x302, x270);
+ fiat_secp256k1_addcarryx_u32(&x318, &x319, 0x0, x270, x302);
uint32_t x320;
fiat_secp256k1_uint1 x321;
- fiat_secp256k1_addcarryx_u32(&x320, &x321, x319, x304, x272);
+ fiat_secp256k1_addcarryx_u32(&x320, &x321, x319, x272, x304);
uint32_t x322;
fiat_secp256k1_uint1 x323;
- fiat_secp256k1_addcarryx_u32(&x322, &x323, x321, x306, x274);
+ fiat_secp256k1_addcarryx_u32(&x322, &x323, x321, x274, x306);
uint32_t x324;
fiat_secp256k1_uint1 x325;
- fiat_secp256k1_addcarryx_u32(&x324, &x325, x323, x308, x276);
+ fiat_secp256k1_addcarryx_u32(&x324, &x325, x323, x276, x308);
uint32_t x326;
fiat_secp256k1_uint1 x327;
- fiat_secp256k1_addcarryx_u32(&x326, &x327, x325, x310, x278);
+ fiat_secp256k1_addcarryx_u32(&x326, &x327, x325, x278, x310);
uint32_t x328;
fiat_secp256k1_uint1 x329;
- fiat_secp256k1_addcarryx_u32(&x328, &x329, x327, x312, x280);
+ fiat_secp256k1_addcarryx_u32(&x328, &x329, x327, x280, x312);
uint32_t x330;
fiat_secp256k1_uint1 x331;
- fiat_secp256k1_addcarryx_u32(&x330, &x331, x329, x314, x282);
+ fiat_secp256k1_addcarryx_u32(&x330, &x331, x329, x282, x314);
uint32_t x332;
fiat_secp256k1_uint1 x333;
- fiat_secp256k1_addcarryx_u32(&x332, &x333, x331, x316, x284);
+ fiat_secp256k1_addcarryx_u32(&x332, &x333, x331, x284, x316);
uint32_t x334;
fiat_secp256k1_uint1 x335;
- fiat_secp256k1_addcarryx_u32(&x334, &x335, x269, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x334, &x335, x317, x289, 0x0);
uint32_t x336;
fiat_secp256k1_uint1 x337;
- fiat_secp256k1_addcarryx_u32(&x336, &x337, x285, 0x0, (fiat_secp256k1_uint1)x334);
+ fiat_secp256k1_addcarryx_u32(&x336, &x337, x269, 0x0, 0x0);
uint32_t x338;
fiat_secp256k1_uint1 x339;
- fiat_secp256k1_addcarryx_u32(&x338, &x339, x317, 0x0, x289);
+ fiat_secp256k1_addcarryx_u32(&x338, &x339, x285, (fiat_secp256k1_uint1)x336, 0x0);
uint32_t x340;
fiat_secp256k1_uint1 x341;
- fiat_secp256k1_addcarryx_u32(&x340, &x341, x333, x338, x336);
+ fiat_secp256k1_addcarryx_u32(&x340, &x341, x333, x338, x334);
uint32_t x342;
fiat_secp256k1_uint1 x343;
- fiat_secp256k1_addcarryx_u32(&x342, &x343, 0x0, (arg1[5]), x320);
+ fiat_secp256k1_addcarryx_u32(&x342, &x343, 0x0, x320, (arg1[5]));
uint32_t x344;
fiat_secp256k1_uint1 x345;
- fiat_secp256k1_addcarryx_u32(&x344, &x345, x343, 0x0, x322);
+ fiat_secp256k1_addcarryx_u32(&x344, &x345, x343, x322, 0x0);
uint32_t x346;
fiat_secp256k1_uint1 x347;
- fiat_secp256k1_addcarryx_u32(&x346, &x347, x345, 0x0, x324);
+ fiat_secp256k1_addcarryx_u32(&x346, &x347, x345, x324, 0x0);
uint32_t x348;
fiat_secp256k1_uint1 x349;
- fiat_secp256k1_addcarryx_u32(&x348, &x349, x347, 0x0, x326);
+ fiat_secp256k1_addcarryx_u32(&x348, &x349, x347, x326, 0x0);
uint32_t x350;
fiat_secp256k1_uint1 x351;
- fiat_secp256k1_addcarryx_u32(&x350, &x351, x349, 0x0, x328);
+ fiat_secp256k1_addcarryx_u32(&x350, &x351, x349, x328, 0x0);
uint32_t x352;
fiat_secp256k1_uint1 x353;
- fiat_secp256k1_addcarryx_u32(&x352, &x353, x351, 0x0, x330);
+ fiat_secp256k1_addcarryx_u32(&x352, &x353, x351, x330, 0x0);
uint32_t x354;
fiat_secp256k1_uint1 x355;
- fiat_secp256k1_addcarryx_u32(&x354, &x355, x353, 0x0, x332);
+ fiat_secp256k1_addcarryx_u32(&x354, &x355, x353, x332, 0x0);
uint32_t x356;
fiat_secp256k1_uint1 x357;
- fiat_secp256k1_addcarryx_u32(&x356, &x357, x355, 0x0, x340);
+ fiat_secp256k1_addcarryx_u32(&x356, &x357, x355, x340, 0x0);
uint32_t x358;
uint32_t x359;
fiat_secp256k1_mulx_u32(&x358, &x359, x342, UINT32_C(0xd2253531));
@@ -3515,85 +3515,85 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x374, &x375, x358, UINT32_C(0xfffffc2f));
uint32_t x376;
fiat_secp256k1_uint1 x377;
- fiat_secp256k1_addcarryx_u32(&x376, &x377, 0x0, x372, x375);
+ fiat_secp256k1_addcarryx_u32(&x376, &x377, 0x0, x375, x372);
uint32_t x378;
fiat_secp256k1_uint1 x379;
- fiat_secp256k1_addcarryx_u32(&x378, &x379, x377, x370, x373);
+ fiat_secp256k1_addcarryx_u32(&x378, &x379, x377, x373, x370);
uint32_t x380;
fiat_secp256k1_uint1 x381;
- fiat_secp256k1_addcarryx_u32(&x380, &x381, x379, x368, x371);
+ fiat_secp256k1_addcarryx_u32(&x380, &x381, x379, x371, x368);
uint32_t x382;
fiat_secp256k1_uint1 x383;
- fiat_secp256k1_addcarryx_u32(&x382, &x383, x381, x366, x369);
+ fiat_secp256k1_addcarryx_u32(&x382, &x383, x381, x369, x366);
uint32_t x384;
fiat_secp256k1_uint1 x385;
- fiat_secp256k1_addcarryx_u32(&x384, &x385, x383, x364, x367);
+ fiat_secp256k1_addcarryx_u32(&x384, &x385, x383, x367, x364);
uint32_t x386;
fiat_secp256k1_uint1 x387;
- fiat_secp256k1_addcarryx_u32(&x386, &x387, x385, x362, x365);
+ fiat_secp256k1_addcarryx_u32(&x386, &x387, x385, x365, x362);
uint32_t x388;
fiat_secp256k1_uint1 x389;
- fiat_secp256k1_addcarryx_u32(&x388, &x389, x387, x360, x363);
+ fiat_secp256k1_addcarryx_u32(&x388, &x389, x387, x363, x360);
uint32_t x390;
fiat_secp256k1_uint1 x391;
- fiat_secp256k1_addcarryx_u32(&x390, &x391, 0x0, x374, x342);
+ fiat_secp256k1_addcarryx_u32(&x390, &x391, 0x0, x342, x374);
uint32_t x392;
fiat_secp256k1_uint1 x393;
- fiat_secp256k1_addcarryx_u32(&x392, &x393, x391, x376, x344);
+ fiat_secp256k1_addcarryx_u32(&x392, &x393, x391, x344, x376);
uint32_t x394;
fiat_secp256k1_uint1 x395;
- fiat_secp256k1_addcarryx_u32(&x394, &x395, x393, x378, x346);
+ fiat_secp256k1_addcarryx_u32(&x394, &x395, x393, x346, x378);
uint32_t x396;
fiat_secp256k1_uint1 x397;
- fiat_secp256k1_addcarryx_u32(&x396, &x397, x395, x380, x348);
+ fiat_secp256k1_addcarryx_u32(&x396, &x397, x395, x348, x380);
uint32_t x398;
fiat_secp256k1_uint1 x399;
- fiat_secp256k1_addcarryx_u32(&x398, &x399, x397, x382, x350);
+ fiat_secp256k1_addcarryx_u32(&x398, &x399, x397, x350, x382);
uint32_t x400;
fiat_secp256k1_uint1 x401;
- fiat_secp256k1_addcarryx_u32(&x400, &x401, x399, x384, x352);
+ fiat_secp256k1_addcarryx_u32(&x400, &x401, x399, x352, x384);
uint32_t x402;
fiat_secp256k1_uint1 x403;
- fiat_secp256k1_addcarryx_u32(&x402, &x403, x401, x386, x354);
+ fiat_secp256k1_addcarryx_u32(&x402, &x403, x401, x354, x386);
uint32_t x404;
fiat_secp256k1_uint1 x405;
- fiat_secp256k1_addcarryx_u32(&x404, &x405, x403, x388, x356);
+ fiat_secp256k1_addcarryx_u32(&x404, &x405, x403, x356, x388);
uint32_t x406;
fiat_secp256k1_uint1 x407;
- fiat_secp256k1_addcarryx_u32(&x406, &x407, x341, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x406, &x407, x389, x361, 0x0);
uint32_t x408;
fiat_secp256k1_uint1 x409;
- fiat_secp256k1_addcarryx_u32(&x408, &x409, x357, 0x0, (fiat_secp256k1_uint1)x406);
+ fiat_secp256k1_addcarryx_u32(&x408, &x409, x341, 0x0, 0x0);
uint32_t x410;
fiat_secp256k1_uint1 x411;
- fiat_secp256k1_addcarryx_u32(&x410, &x411, x389, 0x0, x361);
+ fiat_secp256k1_addcarryx_u32(&x410, &x411, x357, (fiat_secp256k1_uint1)x408, 0x0);
uint32_t x412;
fiat_secp256k1_uint1 x413;
- fiat_secp256k1_addcarryx_u32(&x412, &x413, x405, x410, x408);
+ fiat_secp256k1_addcarryx_u32(&x412, &x413, x405, x410, x406);
uint32_t x414;
fiat_secp256k1_uint1 x415;
- fiat_secp256k1_addcarryx_u32(&x414, &x415, 0x0, (arg1[6]), x392);
+ fiat_secp256k1_addcarryx_u32(&x414, &x415, 0x0, x392, (arg1[6]));
uint32_t x416;
fiat_secp256k1_uint1 x417;
- fiat_secp256k1_addcarryx_u32(&x416, &x417, x415, 0x0, x394);
+ fiat_secp256k1_addcarryx_u32(&x416, &x417, x415, x394, 0x0);
uint32_t x418;
fiat_secp256k1_uint1 x419;
- fiat_secp256k1_addcarryx_u32(&x418, &x419, x417, 0x0, x396);
+ fiat_secp256k1_addcarryx_u32(&x418, &x419, x417, x396, 0x0);
uint32_t x420;
fiat_secp256k1_uint1 x421;
- fiat_secp256k1_addcarryx_u32(&x420, &x421, x419, 0x0, x398);
+ fiat_secp256k1_addcarryx_u32(&x420, &x421, x419, x398, 0x0);
uint32_t x422;
fiat_secp256k1_uint1 x423;
- fiat_secp256k1_addcarryx_u32(&x422, &x423, x421, 0x0, x400);
+ fiat_secp256k1_addcarryx_u32(&x422, &x423, x421, x400, 0x0);
uint32_t x424;
fiat_secp256k1_uint1 x425;
- fiat_secp256k1_addcarryx_u32(&x424, &x425, x423, 0x0, x402);
+ fiat_secp256k1_addcarryx_u32(&x424, &x425, x423, x402, 0x0);
uint32_t x426;
fiat_secp256k1_uint1 x427;
- fiat_secp256k1_addcarryx_u32(&x426, &x427, x425, 0x0, x404);
+ fiat_secp256k1_addcarryx_u32(&x426, &x427, x425, x404, 0x0);
uint32_t x428;
fiat_secp256k1_uint1 x429;
- fiat_secp256k1_addcarryx_u32(&x428, &x429, x427, 0x0, x412);
+ fiat_secp256k1_addcarryx_u32(&x428, &x429, x427, x412, 0x0);
uint32_t x430;
uint32_t x431;
fiat_secp256k1_mulx_u32(&x430, &x431, x414, UINT32_C(0xd2253531));
@@ -3623,85 +3623,85 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x446, &x447, x430, UINT32_C(0xfffffc2f));
uint32_t x448;
fiat_secp256k1_uint1 x449;
- fiat_secp256k1_addcarryx_u32(&x448, &x449, 0x0, x444, x447);
+ fiat_secp256k1_addcarryx_u32(&x448, &x449, 0x0, x447, x444);
uint32_t x450;
fiat_secp256k1_uint1 x451;
- fiat_secp256k1_addcarryx_u32(&x450, &x451, x449, x442, x445);
+ fiat_secp256k1_addcarryx_u32(&x450, &x451, x449, x445, x442);
uint32_t x452;
fiat_secp256k1_uint1 x453;
- fiat_secp256k1_addcarryx_u32(&x452, &x453, x451, x440, x443);
+ fiat_secp256k1_addcarryx_u32(&x452, &x453, x451, x443, x440);
uint32_t x454;
fiat_secp256k1_uint1 x455;
- fiat_secp256k1_addcarryx_u32(&x454, &x455, x453, x438, x441);
+ fiat_secp256k1_addcarryx_u32(&x454, &x455, x453, x441, x438);
uint32_t x456;
fiat_secp256k1_uint1 x457;
- fiat_secp256k1_addcarryx_u32(&x456, &x457, x455, x436, x439);
+ fiat_secp256k1_addcarryx_u32(&x456, &x457, x455, x439, x436);
uint32_t x458;
fiat_secp256k1_uint1 x459;
- fiat_secp256k1_addcarryx_u32(&x458, &x459, x457, x434, x437);
+ fiat_secp256k1_addcarryx_u32(&x458, &x459, x457, x437, x434);
uint32_t x460;
fiat_secp256k1_uint1 x461;
- fiat_secp256k1_addcarryx_u32(&x460, &x461, x459, x432, x435);
+ fiat_secp256k1_addcarryx_u32(&x460, &x461, x459, x435, x432);
uint32_t x462;
fiat_secp256k1_uint1 x463;
- fiat_secp256k1_addcarryx_u32(&x462, &x463, 0x0, x446, x414);
+ fiat_secp256k1_addcarryx_u32(&x462, &x463, 0x0, x414, x446);
uint32_t x464;
fiat_secp256k1_uint1 x465;
- fiat_secp256k1_addcarryx_u32(&x464, &x465, x463, x448, x416);
+ fiat_secp256k1_addcarryx_u32(&x464, &x465, x463, x416, x448);
uint32_t x466;
fiat_secp256k1_uint1 x467;
- fiat_secp256k1_addcarryx_u32(&x466, &x467, x465, x450, x418);
+ fiat_secp256k1_addcarryx_u32(&x466, &x467, x465, x418, x450);
uint32_t x468;
fiat_secp256k1_uint1 x469;
- fiat_secp256k1_addcarryx_u32(&x468, &x469, x467, x452, x420);
+ fiat_secp256k1_addcarryx_u32(&x468, &x469, x467, x420, x452);
uint32_t x470;
fiat_secp256k1_uint1 x471;
- fiat_secp256k1_addcarryx_u32(&x470, &x471, x469, x454, x422);
+ fiat_secp256k1_addcarryx_u32(&x470, &x471, x469, x422, x454);
uint32_t x472;
fiat_secp256k1_uint1 x473;
- fiat_secp256k1_addcarryx_u32(&x472, &x473, x471, x456, x424);
+ fiat_secp256k1_addcarryx_u32(&x472, &x473, x471, x424, x456);
uint32_t x474;
fiat_secp256k1_uint1 x475;
- fiat_secp256k1_addcarryx_u32(&x474, &x475, x473, x458, x426);
+ fiat_secp256k1_addcarryx_u32(&x474, &x475, x473, x426, x458);
uint32_t x476;
fiat_secp256k1_uint1 x477;
- fiat_secp256k1_addcarryx_u32(&x476, &x477, x475, x460, x428);
+ fiat_secp256k1_addcarryx_u32(&x476, &x477, x475, x428, x460);
uint32_t x478;
fiat_secp256k1_uint1 x479;
- fiat_secp256k1_addcarryx_u32(&x478, &x479, x413, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x478, &x479, x461, x433, 0x0);
uint32_t x480;
fiat_secp256k1_uint1 x481;
- fiat_secp256k1_addcarryx_u32(&x480, &x481, x429, 0x0, (fiat_secp256k1_uint1)x478);
+ fiat_secp256k1_addcarryx_u32(&x480, &x481, x413, 0x0, 0x0);
uint32_t x482;
fiat_secp256k1_uint1 x483;
- fiat_secp256k1_addcarryx_u32(&x482, &x483, x461, 0x0, x433);
+ fiat_secp256k1_addcarryx_u32(&x482, &x483, x429, (fiat_secp256k1_uint1)x480, 0x0);
uint32_t x484;
fiat_secp256k1_uint1 x485;
- fiat_secp256k1_addcarryx_u32(&x484, &x485, x477, x482, x480);
+ fiat_secp256k1_addcarryx_u32(&x484, &x485, x477, x482, x478);
uint32_t x486;
fiat_secp256k1_uint1 x487;
- fiat_secp256k1_addcarryx_u32(&x486, &x487, 0x0, (arg1[7]), x464);
+ fiat_secp256k1_addcarryx_u32(&x486, &x487, 0x0, x464, (arg1[7]));
uint32_t x488;
fiat_secp256k1_uint1 x489;
- fiat_secp256k1_addcarryx_u32(&x488, &x489, x487, 0x0, x466);
+ fiat_secp256k1_addcarryx_u32(&x488, &x489, x487, x466, 0x0);
uint32_t x490;
fiat_secp256k1_uint1 x491;
- fiat_secp256k1_addcarryx_u32(&x490, &x491, x489, 0x0, x468);
+ fiat_secp256k1_addcarryx_u32(&x490, &x491, x489, x468, 0x0);
uint32_t x492;
fiat_secp256k1_uint1 x493;
- fiat_secp256k1_addcarryx_u32(&x492, &x493, x491, 0x0, x470);
+ fiat_secp256k1_addcarryx_u32(&x492, &x493, x491, x470, 0x0);
uint32_t x494;
fiat_secp256k1_uint1 x495;
- fiat_secp256k1_addcarryx_u32(&x494, &x495, x493, 0x0, x472);
+ fiat_secp256k1_addcarryx_u32(&x494, &x495, x493, x472, 0x0);
uint32_t x496;
fiat_secp256k1_uint1 x497;
- fiat_secp256k1_addcarryx_u32(&x496, &x497, x495, 0x0, x474);
+ fiat_secp256k1_addcarryx_u32(&x496, &x497, x495, x474, 0x0);
uint32_t x498;
fiat_secp256k1_uint1 x499;
- fiat_secp256k1_addcarryx_u32(&x498, &x499, x497, 0x0, x476);
+ fiat_secp256k1_addcarryx_u32(&x498, &x499, x497, x476, 0x0);
uint32_t x500;
fiat_secp256k1_uint1 x501;
- fiat_secp256k1_addcarryx_u32(&x500, &x501, x499, 0x0, x484);
+ fiat_secp256k1_addcarryx_u32(&x500, &x501, x499, x484, 0x0);
uint32_t x502;
uint32_t x503;
fiat_secp256k1_mulx_u32(&x502, &x503, x486, UINT32_C(0xd2253531));
@@ -3731,61 +3731,61 @@ static void fiat_secp256k1_from_montgomery(uint32_t out1[8], const uint32_t arg1
fiat_secp256k1_mulx_u32(&x518, &x519, x502, UINT32_C(0xfffffc2f));
uint32_t x520;
fiat_secp256k1_uint1 x521;
- fiat_secp256k1_addcarryx_u32(&x520, &x521, 0x0, x516, x519);
+ fiat_secp256k1_addcarryx_u32(&x520, &x521, 0x0, x519, x516);
uint32_t x522;
fiat_secp256k1_uint1 x523;
- fiat_secp256k1_addcarryx_u32(&x522, &x523, x521, x514, x517);
+ fiat_secp256k1_addcarryx_u32(&x522, &x523, x521, x517, x514);
uint32_t x524;
fiat_secp256k1_uint1 x525;
- fiat_secp256k1_addcarryx_u32(&x524, &x525, x523, x512, x515);
+ fiat_secp256k1_addcarryx_u32(&x524, &x525, x523, x515, x512);
uint32_t x526;
fiat_secp256k1_uint1 x527;
- fiat_secp256k1_addcarryx_u32(&x526, &x527, x525, x510, x513);
+ fiat_secp256k1_addcarryx_u32(&x526, &x527, x525, x513, x510);
uint32_t x528;
fiat_secp256k1_uint1 x529;
- fiat_secp256k1_addcarryx_u32(&x528, &x529, x527, x508, x511);
+ fiat_secp256k1_addcarryx_u32(&x528, &x529, x527, x511, x508);
uint32_t x530;
fiat_secp256k1_uint1 x531;
- fiat_secp256k1_addcarryx_u32(&x530, &x531, x529, x506, x509);
+ fiat_secp256k1_addcarryx_u32(&x530, &x531, x529, x509, x506);
uint32_t x532;
fiat_secp256k1_uint1 x533;
- fiat_secp256k1_addcarryx_u32(&x532, &x533, x531, x504, x507);
+ fiat_secp256k1_addcarryx_u32(&x532, &x533, x531, x507, x504);
uint32_t x534;
fiat_secp256k1_uint1 x535;
- fiat_secp256k1_addcarryx_u32(&x534, &x535, 0x0, x518, x486);
+ fiat_secp256k1_addcarryx_u32(&x534, &x535, 0x0, x486, x518);
uint32_t x536;
fiat_secp256k1_uint1 x537;
- fiat_secp256k1_addcarryx_u32(&x536, &x537, x535, x520, x488);
+ fiat_secp256k1_addcarryx_u32(&x536, &x537, x535, x488, x520);
uint32_t x538;
fiat_secp256k1_uint1 x539;
- fiat_secp256k1_addcarryx_u32(&x538, &x539, x537, x522, x490);
+ fiat_secp256k1_addcarryx_u32(&x538, &x539, x537, x490, x522);
uint32_t x540;
fiat_secp256k1_uint1 x541;
- fiat_secp256k1_addcarryx_u32(&x540, &x541, x539, x524, x492);
+ fiat_secp256k1_addcarryx_u32(&x540, &x541, x539, x492, x524);
uint32_t x542;
fiat_secp256k1_uint1 x543;
- fiat_secp256k1_addcarryx_u32(&x542, &x543, x541, x526, x494);
+ fiat_secp256k1_addcarryx_u32(&x542, &x543, x541, x494, x526);
uint32_t x544;
fiat_secp256k1_uint1 x545;
- fiat_secp256k1_addcarryx_u32(&x544, &x545, x543, x528, x496);
+ fiat_secp256k1_addcarryx_u32(&x544, &x545, x543, x496, x528);
uint32_t x546;
fiat_secp256k1_uint1 x547;
- fiat_secp256k1_addcarryx_u32(&x546, &x547, x545, x530, x498);
+ fiat_secp256k1_addcarryx_u32(&x546, &x547, x545, x498, x530);
uint32_t x548;
fiat_secp256k1_uint1 x549;
- fiat_secp256k1_addcarryx_u32(&x548, &x549, x547, x532, x500);
+ fiat_secp256k1_addcarryx_u32(&x548, &x549, x547, x500, x532);
uint32_t x550;
fiat_secp256k1_uint1 x551;
- fiat_secp256k1_addcarryx_u32(&x550, &x551, x485, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u32(&x550, &x551, x533, x505, 0x0);
uint32_t x552;
fiat_secp256k1_uint1 x553;
- fiat_secp256k1_addcarryx_u32(&x552, &x553, x501, 0x0, (fiat_secp256k1_uint1)x550);
+ fiat_secp256k1_addcarryx_u32(&x552, &x553, x485, 0x0, 0x0);
uint32_t x554;
fiat_secp256k1_uint1 x555;
- fiat_secp256k1_addcarryx_u32(&x554, &x555, x533, 0x0, x505);
+ fiat_secp256k1_addcarryx_u32(&x554, &x555, x501, (fiat_secp256k1_uint1)x552, 0x0);
uint32_t x556;
fiat_secp256k1_uint1 x557;
- fiat_secp256k1_addcarryx_u32(&x556, &x557, x549, x554, x552);
+ fiat_secp256k1_addcarryx_u32(&x556, &x557, x549, x554, x550);
uint32_t x558;
fiat_secp256k1_uint1 x559;
fiat_secp256k1_subborrowx_u32(&x558, &x559, 0x0, x536, UINT32_C(0xfffffc2f));
diff --git a/secp256k1_64.c b/secp256k1_64.c
index 2706759bd..72245e439 100644
--- a/secp256k1_64.c
+++ b/secp256k1_64.c
@@ -136,16 +136,16 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x11, &x12, x4, (arg2[0]));
uint64_t x13;
fiat_secp256k1_uint1 x14;
- fiat_secp256k1_addcarryx_u64(&x13, &x14, 0x0, x9, x12);
+ fiat_secp256k1_addcarryx_u64(&x13, &x14, 0x0, x12, x9);
uint64_t x15;
fiat_secp256k1_uint1 x16;
- fiat_secp256k1_addcarryx_u64(&x15, &x16, x14, x7, x10);
+ fiat_secp256k1_addcarryx_u64(&x15, &x16, x14, x10, x7);
uint64_t x17;
fiat_secp256k1_uint1 x18;
- fiat_secp256k1_addcarryx_u64(&x17, &x18, x16, x5, x8);
+ fiat_secp256k1_addcarryx_u64(&x17, &x18, x16, x8, x5);
uint64_t x19;
fiat_secp256k1_uint1 x20;
- fiat_secp256k1_addcarryx_u64(&x19, &x20, x18, 0x0, x6);
+ fiat_secp256k1_addcarryx_u64(&x19, &x20, x18, x6, 0x0);
uint64_t x21;
uint64_t x22;
fiat_secp256k1_mulx_u64(&x21, &x22, x11, UINT64_C(0xd838091dd2253531));
@@ -163,31 +163,31 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x29, &x30, x21, UINT64_C(0xfffffffefffffc2f));
uint64_t x31;
fiat_secp256k1_uint1 x32;
- fiat_secp256k1_addcarryx_u64(&x31, &x32, 0x0, x27, x30);
+ fiat_secp256k1_addcarryx_u64(&x31, &x32, 0x0, x30, x27);
uint64_t x33;
fiat_secp256k1_uint1 x34;
- fiat_secp256k1_addcarryx_u64(&x33, &x34, x32, x25, x28);
+ fiat_secp256k1_addcarryx_u64(&x33, &x34, x32, x28, x25);
uint64_t x35;
fiat_secp256k1_uint1 x36;
- fiat_secp256k1_addcarryx_u64(&x35, &x36, x34, x23, x26);
+ fiat_secp256k1_addcarryx_u64(&x35, &x36, x34, x26, x23);
uint64_t x37;
fiat_secp256k1_uint1 x38;
- fiat_secp256k1_addcarryx_u64(&x37, &x38, x36, 0x0, x24);
+ fiat_secp256k1_addcarryx_u64(&x37, &x38, x36, x24, 0x0);
uint64_t x39;
fiat_secp256k1_uint1 x40;
- fiat_secp256k1_addcarryx_u64(&x39, &x40, 0x0, x29, x11);
+ fiat_secp256k1_addcarryx_u64(&x39, &x40, 0x0, x11, x29);
uint64_t x41;
fiat_secp256k1_uint1 x42;
- fiat_secp256k1_addcarryx_u64(&x41, &x42, x40, x31, x13);
+ fiat_secp256k1_addcarryx_u64(&x41, &x42, x40, x13, x31);
uint64_t x43;
fiat_secp256k1_uint1 x44;
- fiat_secp256k1_addcarryx_u64(&x43, &x44, x42, x33, x15);
+ fiat_secp256k1_addcarryx_u64(&x43, &x44, x42, x15, x33);
uint64_t x45;
fiat_secp256k1_uint1 x46;
- fiat_secp256k1_addcarryx_u64(&x45, &x46, x44, x35, x17);
+ fiat_secp256k1_addcarryx_u64(&x45, &x46, x44, x17, x35);
uint64_t x47;
fiat_secp256k1_uint1 x48;
- fiat_secp256k1_addcarryx_u64(&x47, &x48, x46, x37, x19);
+ fiat_secp256k1_addcarryx_u64(&x47, &x48, x46, x19, x37);
uint64_t x49;
fiat_secp256k1_uint1 x50;
fiat_secp256k1_addcarryx_u64(&x49, &x50, x48, 0x0, 0x0);
@@ -205,31 +205,31 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x57, &x58, x1, (arg2[0]));
uint64_t x59;
fiat_secp256k1_uint1 x60;
- fiat_secp256k1_addcarryx_u64(&x59, &x60, 0x0, x55, x58);
+ fiat_secp256k1_addcarryx_u64(&x59, &x60, 0x0, x58, x55);
uint64_t x61;
fiat_secp256k1_uint1 x62;
- fiat_secp256k1_addcarryx_u64(&x61, &x62, x60, x53, x56);
+ fiat_secp256k1_addcarryx_u64(&x61, &x62, x60, x56, x53);
uint64_t x63;
fiat_secp256k1_uint1 x64;
- fiat_secp256k1_addcarryx_u64(&x63, &x64, x62, x51, x54);
+ fiat_secp256k1_addcarryx_u64(&x63, &x64, x62, x54, x51);
uint64_t x65;
fiat_secp256k1_uint1 x66;
- fiat_secp256k1_addcarryx_u64(&x65, &x66, x64, 0x0, x52);
+ fiat_secp256k1_addcarryx_u64(&x65, &x66, x64, x52, 0x0);
uint64_t x67;
fiat_secp256k1_uint1 x68;
- fiat_secp256k1_addcarryx_u64(&x67, &x68, 0x0, x57, x41);
+ fiat_secp256k1_addcarryx_u64(&x67, &x68, 0x0, x41, x57);
uint64_t x69;
fiat_secp256k1_uint1 x70;
- fiat_secp256k1_addcarryx_u64(&x69, &x70, x68, x59, x43);
+ fiat_secp256k1_addcarryx_u64(&x69, &x70, x68, x43, x59);
uint64_t x71;
fiat_secp256k1_uint1 x72;
- fiat_secp256k1_addcarryx_u64(&x71, &x72, x70, x61, x45);
+ fiat_secp256k1_addcarryx_u64(&x71, &x72, x70, x45, x61);
uint64_t x73;
fiat_secp256k1_uint1 x74;
- fiat_secp256k1_addcarryx_u64(&x73, &x74, x72, x63, x47);
+ fiat_secp256k1_addcarryx_u64(&x73, &x74, x72, x47, x63);
uint64_t x75;
fiat_secp256k1_uint1 x76;
- fiat_secp256k1_addcarryx_u64(&x75, &x76, x74, x65, (fiat_secp256k1_uint1)x49);
+ fiat_secp256k1_addcarryx_u64(&x75, &x76, x74, (fiat_secp256k1_uint1)x49, x65);
uint64_t x77;
uint64_t x78;
fiat_secp256k1_mulx_u64(&x77, &x78, x67, UINT64_C(0xd838091dd2253531));
@@ -247,34 +247,34 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x85, &x86, x77, UINT64_C(0xfffffffefffffc2f));
uint64_t x87;
fiat_secp256k1_uint1 x88;
- fiat_secp256k1_addcarryx_u64(&x87, &x88, 0x0, x83, x86);
+ fiat_secp256k1_addcarryx_u64(&x87, &x88, 0x0, x86, x83);
uint64_t x89;
fiat_secp256k1_uint1 x90;
- fiat_secp256k1_addcarryx_u64(&x89, &x90, x88, x81, x84);
+ fiat_secp256k1_addcarryx_u64(&x89, &x90, x88, x84, x81);
uint64_t x91;
fiat_secp256k1_uint1 x92;
- fiat_secp256k1_addcarryx_u64(&x91, &x92, x90, x79, x82);
+ fiat_secp256k1_addcarryx_u64(&x91, &x92, x90, x82, x79);
uint64_t x93;
fiat_secp256k1_uint1 x94;
- fiat_secp256k1_addcarryx_u64(&x93, &x94, x92, 0x0, x80);
+ fiat_secp256k1_addcarryx_u64(&x93, &x94, x92, x80, 0x0);
uint64_t x95;
fiat_secp256k1_uint1 x96;
- fiat_secp256k1_addcarryx_u64(&x95, &x96, 0x0, x85, x67);
+ fiat_secp256k1_addcarryx_u64(&x95, &x96, 0x0, x67, x85);
uint64_t x97;
fiat_secp256k1_uint1 x98;
- fiat_secp256k1_addcarryx_u64(&x97, &x98, x96, x87, x69);
+ fiat_secp256k1_addcarryx_u64(&x97, &x98, x96, x69, x87);
uint64_t x99;
fiat_secp256k1_uint1 x100;
- fiat_secp256k1_addcarryx_u64(&x99, &x100, x98, x89, x71);
+ fiat_secp256k1_addcarryx_u64(&x99, &x100, x98, x71, x89);
uint64_t x101;
fiat_secp256k1_uint1 x102;
- fiat_secp256k1_addcarryx_u64(&x101, &x102, x100, x91, x73);
+ fiat_secp256k1_addcarryx_u64(&x101, &x102, x100, x73, x91);
uint64_t x103;
fiat_secp256k1_uint1 x104;
- fiat_secp256k1_addcarryx_u64(&x103, &x104, x102, x93, x75);
+ fiat_secp256k1_addcarryx_u64(&x103, &x104, x102, x75, x93);
uint64_t x105;
fiat_secp256k1_uint1 x106;
- fiat_secp256k1_addcarryx_u64(&x105, &x106, x104, 0x0, x76);
+ fiat_secp256k1_addcarryx_u64(&x105, &x106, x104, x76, 0x0);
uint64_t x107;
uint64_t x108;
fiat_secp256k1_mulx_u64(&x107, &x108, x2, (arg2[3]));
@@ -289,31 +289,31 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x113, &x114, x2, (arg2[0]));
uint64_t x115;
fiat_secp256k1_uint1 x116;
- fiat_secp256k1_addcarryx_u64(&x115, &x116, 0x0, x111, x114);
+ fiat_secp256k1_addcarryx_u64(&x115, &x116, 0x0, x114, x111);
uint64_t x117;
fiat_secp256k1_uint1 x118;
- fiat_secp256k1_addcarryx_u64(&x117, &x118, x116, x109, x112);
+ fiat_secp256k1_addcarryx_u64(&x117, &x118, x116, x112, x109);
uint64_t x119;
fiat_secp256k1_uint1 x120;
- fiat_secp256k1_addcarryx_u64(&x119, &x120, x118, x107, x110);
+ fiat_secp256k1_addcarryx_u64(&x119, &x120, x118, x110, x107);
uint64_t x121;
fiat_secp256k1_uint1 x122;
- fiat_secp256k1_addcarryx_u64(&x121, &x122, x120, 0x0, x108);
+ fiat_secp256k1_addcarryx_u64(&x121, &x122, x120, x108, 0x0);
uint64_t x123;
fiat_secp256k1_uint1 x124;
- fiat_secp256k1_addcarryx_u64(&x123, &x124, 0x0, x113, x97);
+ fiat_secp256k1_addcarryx_u64(&x123, &x124, 0x0, x97, x113);
uint64_t x125;
fiat_secp256k1_uint1 x126;
- fiat_secp256k1_addcarryx_u64(&x125, &x126, x124, x115, x99);
+ fiat_secp256k1_addcarryx_u64(&x125, &x126, x124, x99, x115);
uint64_t x127;
fiat_secp256k1_uint1 x128;
- fiat_secp256k1_addcarryx_u64(&x127, &x128, x126, x117, x101);
+ fiat_secp256k1_addcarryx_u64(&x127, &x128, x126, x101, x117);
uint64_t x129;
fiat_secp256k1_uint1 x130;
- fiat_secp256k1_addcarryx_u64(&x129, &x130, x128, x119, x103);
+ fiat_secp256k1_addcarryx_u64(&x129, &x130, x128, x103, x119);
uint64_t x131;
fiat_secp256k1_uint1 x132;
- fiat_secp256k1_addcarryx_u64(&x131, &x132, x130, x121, x105);
+ fiat_secp256k1_addcarryx_u64(&x131, &x132, x130, x105, x121);
uint64_t x133;
uint64_t x134;
fiat_secp256k1_mulx_u64(&x133, &x134, x123, UINT64_C(0xd838091dd2253531));
@@ -331,34 +331,34 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x141, &x142, x133, UINT64_C(0xfffffffefffffc2f));
uint64_t x143;
fiat_secp256k1_uint1 x144;
- fiat_secp256k1_addcarryx_u64(&x143, &x144, 0x0, x139, x142);
+ fiat_secp256k1_addcarryx_u64(&x143, &x144, 0x0, x142, x139);
uint64_t x145;
fiat_secp256k1_uint1 x146;
- fiat_secp256k1_addcarryx_u64(&x145, &x146, x144, x137, x140);
+ fiat_secp256k1_addcarryx_u64(&x145, &x146, x144, x140, x137);
uint64_t x147;
fiat_secp256k1_uint1 x148;
- fiat_secp256k1_addcarryx_u64(&x147, &x148, x146, x135, x138);
+ fiat_secp256k1_addcarryx_u64(&x147, &x148, x146, x138, x135);
uint64_t x149;
fiat_secp256k1_uint1 x150;
- fiat_secp256k1_addcarryx_u64(&x149, &x150, x148, 0x0, x136);
+ fiat_secp256k1_addcarryx_u64(&x149, &x150, x148, x136, 0x0);
uint64_t x151;
fiat_secp256k1_uint1 x152;
- fiat_secp256k1_addcarryx_u64(&x151, &x152, 0x0, x141, x123);
+ fiat_secp256k1_addcarryx_u64(&x151, &x152, 0x0, x123, x141);
uint64_t x153;
fiat_secp256k1_uint1 x154;
- fiat_secp256k1_addcarryx_u64(&x153, &x154, x152, x143, x125);
+ fiat_secp256k1_addcarryx_u64(&x153, &x154, x152, x125, x143);
uint64_t x155;
fiat_secp256k1_uint1 x156;
- fiat_secp256k1_addcarryx_u64(&x155, &x156, x154, x145, x127);
+ fiat_secp256k1_addcarryx_u64(&x155, &x156, x154, x127, x145);
uint64_t x157;
fiat_secp256k1_uint1 x158;
- fiat_secp256k1_addcarryx_u64(&x157, &x158, x156, x147, x129);
+ fiat_secp256k1_addcarryx_u64(&x157, &x158, x156, x129, x147);
uint64_t x159;
fiat_secp256k1_uint1 x160;
- fiat_secp256k1_addcarryx_u64(&x159, &x160, x158, x149, x131);
+ fiat_secp256k1_addcarryx_u64(&x159, &x160, x158, x131, x149);
uint64_t x161;
fiat_secp256k1_uint1 x162;
- fiat_secp256k1_addcarryx_u64(&x161, &x162, x160, 0x0, x132);
+ fiat_secp256k1_addcarryx_u64(&x161, &x162, x160, x132, 0x0);
uint64_t x163;
uint64_t x164;
fiat_secp256k1_mulx_u64(&x163, &x164, x3, (arg2[3]));
@@ -373,31 +373,31 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x169, &x170, x3, (arg2[0]));
uint64_t x171;
fiat_secp256k1_uint1 x172;
- fiat_secp256k1_addcarryx_u64(&x171, &x172, 0x0, x167, x170);
+ fiat_secp256k1_addcarryx_u64(&x171, &x172, 0x0, x170, x167);
uint64_t x173;
fiat_secp256k1_uint1 x174;
- fiat_secp256k1_addcarryx_u64(&x173, &x174, x172, x165, x168);
+ fiat_secp256k1_addcarryx_u64(&x173, &x174, x172, x168, x165);
uint64_t x175;
fiat_secp256k1_uint1 x176;
- fiat_secp256k1_addcarryx_u64(&x175, &x176, x174, x163, x166);
+ fiat_secp256k1_addcarryx_u64(&x175, &x176, x174, x166, x163);
uint64_t x177;
fiat_secp256k1_uint1 x178;
- fiat_secp256k1_addcarryx_u64(&x177, &x178, x176, 0x0, x164);
+ fiat_secp256k1_addcarryx_u64(&x177, &x178, x176, x164, 0x0);
uint64_t x179;
fiat_secp256k1_uint1 x180;
- fiat_secp256k1_addcarryx_u64(&x179, &x180, 0x0, x169, x153);
+ fiat_secp256k1_addcarryx_u64(&x179, &x180, 0x0, x153, x169);
uint64_t x181;
fiat_secp256k1_uint1 x182;
- fiat_secp256k1_addcarryx_u64(&x181, &x182, x180, x171, x155);
+ fiat_secp256k1_addcarryx_u64(&x181, &x182, x180, x155, x171);
uint64_t x183;
fiat_secp256k1_uint1 x184;
- fiat_secp256k1_addcarryx_u64(&x183, &x184, x182, x173, x157);
+ fiat_secp256k1_addcarryx_u64(&x183, &x184, x182, x157, x173);
uint64_t x185;
fiat_secp256k1_uint1 x186;
- fiat_secp256k1_addcarryx_u64(&x185, &x186, x184, x175, x159);
+ fiat_secp256k1_addcarryx_u64(&x185, &x186, x184, x159, x175);
uint64_t x187;
fiat_secp256k1_uint1 x188;
- fiat_secp256k1_addcarryx_u64(&x187, &x188, x186, x177, x161);
+ fiat_secp256k1_addcarryx_u64(&x187, &x188, x186, x161, x177);
uint64_t x189;
uint64_t x190;
fiat_secp256k1_mulx_u64(&x189, &x190, x179, UINT64_C(0xd838091dd2253531));
@@ -415,34 +415,34 @@ static void fiat_secp256k1_mul(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_mulx_u64(&x197, &x198, x189, UINT64_C(0xfffffffefffffc2f));
uint64_t x199;
fiat_secp256k1_uint1 x200;
- fiat_secp256k1_addcarryx_u64(&x199, &x200, 0x0, x195, x198);
+ fiat_secp256k1_addcarryx_u64(&x199, &x200, 0x0, x198, x195);
uint64_t x201;
fiat_secp256k1_uint1 x202;
- fiat_secp256k1_addcarryx_u64(&x201, &x202, x200, x193, x196);
+ fiat_secp256k1_addcarryx_u64(&x201, &x202, x200, x196, x193);
uint64_t x203;
fiat_secp256k1_uint1 x204;
- fiat_secp256k1_addcarryx_u64(&x203, &x204, x202, x191, x194);
+ fiat_secp256k1_addcarryx_u64(&x203, &x204, x202, x194, x191);
uint64_t x205;
fiat_secp256k1_uint1 x206;
- fiat_secp256k1_addcarryx_u64(&x205, &x206, x204, 0x0, x192);
+ fiat_secp256k1_addcarryx_u64(&x205, &x206, x204, x192, 0x0);
uint64_t x207;
fiat_secp256k1_uint1 x208;
- fiat_secp256k1_addcarryx_u64(&x207, &x208, 0x0, x197, x179);
+ fiat_secp256k1_addcarryx_u64(&x207, &x208, 0x0, x179, x197);
uint64_t x209;
fiat_secp256k1_uint1 x210;
- fiat_secp256k1_addcarryx_u64(&x209, &x210, x208, x199, x181);
+ fiat_secp256k1_addcarryx_u64(&x209, &x210, x208, x181, x199);
uint64_t x211;
fiat_secp256k1_uint1 x212;
- fiat_secp256k1_addcarryx_u64(&x211, &x212, x210, x201, x183);
+ fiat_secp256k1_addcarryx_u64(&x211, &x212, x210, x183, x201);
uint64_t x213;
fiat_secp256k1_uint1 x214;
- fiat_secp256k1_addcarryx_u64(&x213, &x214, x212, x203, x185);
+ fiat_secp256k1_addcarryx_u64(&x213, &x214, x212, x185, x203);
uint64_t x215;
fiat_secp256k1_uint1 x216;
- fiat_secp256k1_addcarryx_u64(&x215, &x216, x214, x205, x187);
+ fiat_secp256k1_addcarryx_u64(&x215, &x216, x214, x187, x205);
uint64_t x217;
fiat_secp256k1_uint1 x218;
- fiat_secp256k1_addcarryx_u64(&x217, &x218, x216, 0x0, x188);
+ fiat_secp256k1_addcarryx_u64(&x217, &x218, x216, x188, 0x0);
uint64_t x219;
fiat_secp256k1_uint1 x220;
fiat_secp256k1_subborrowx_u64(&x219, &x220, 0x0, x209, UINT64_C(0xfffffffefffffc2f));
@@ -504,16 +504,16 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x11, &x12, x4, (arg1[0]));
uint64_t x13;
fiat_secp256k1_uint1 x14;
- fiat_secp256k1_addcarryx_u64(&x13, &x14, 0x0, x9, x12);
+ fiat_secp256k1_addcarryx_u64(&x13, &x14, 0x0, x12, x9);
uint64_t x15;
fiat_secp256k1_uint1 x16;
- fiat_secp256k1_addcarryx_u64(&x15, &x16, x14, x7, x10);
+ fiat_secp256k1_addcarryx_u64(&x15, &x16, x14, x10, x7);
uint64_t x17;
fiat_secp256k1_uint1 x18;
- fiat_secp256k1_addcarryx_u64(&x17, &x18, x16, x5, x8);
+ fiat_secp256k1_addcarryx_u64(&x17, &x18, x16, x8, x5);
uint64_t x19;
fiat_secp256k1_uint1 x20;
- fiat_secp256k1_addcarryx_u64(&x19, &x20, x18, 0x0, x6);
+ fiat_secp256k1_addcarryx_u64(&x19, &x20, x18, x6, 0x0);
uint64_t x21;
uint64_t x22;
fiat_secp256k1_mulx_u64(&x21, &x22, x11, UINT64_C(0xd838091dd2253531));
@@ -531,31 +531,31 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x29, &x30, x21, UINT64_C(0xfffffffefffffc2f));
uint64_t x31;
fiat_secp256k1_uint1 x32;
- fiat_secp256k1_addcarryx_u64(&x31, &x32, 0x0, x27, x30);
+ fiat_secp256k1_addcarryx_u64(&x31, &x32, 0x0, x30, x27);
uint64_t x33;
fiat_secp256k1_uint1 x34;
- fiat_secp256k1_addcarryx_u64(&x33, &x34, x32, x25, x28);
+ fiat_secp256k1_addcarryx_u64(&x33, &x34, x32, x28, x25);
uint64_t x35;
fiat_secp256k1_uint1 x36;
- fiat_secp256k1_addcarryx_u64(&x35, &x36, x34, x23, x26);
+ fiat_secp256k1_addcarryx_u64(&x35, &x36, x34, x26, x23);
uint64_t x37;
fiat_secp256k1_uint1 x38;
- fiat_secp256k1_addcarryx_u64(&x37, &x38, x36, 0x0, x24);
+ fiat_secp256k1_addcarryx_u64(&x37, &x38, x36, x24, 0x0);
uint64_t x39;
fiat_secp256k1_uint1 x40;
- fiat_secp256k1_addcarryx_u64(&x39, &x40, 0x0, x29, x11);
+ fiat_secp256k1_addcarryx_u64(&x39, &x40, 0x0, x11, x29);
uint64_t x41;
fiat_secp256k1_uint1 x42;
- fiat_secp256k1_addcarryx_u64(&x41, &x42, x40, x31, x13);
+ fiat_secp256k1_addcarryx_u64(&x41, &x42, x40, x13, x31);
uint64_t x43;
fiat_secp256k1_uint1 x44;
- fiat_secp256k1_addcarryx_u64(&x43, &x44, x42, x33, x15);
+ fiat_secp256k1_addcarryx_u64(&x43, &x44, x42, x15, x33);
uint64_t x45;
fiat_secp256k1_uint1 x46;
- fiat_secp256k1_addcarryx_u64(&x45, &x46, x44, x35, x17);
+ fiat_secp256k1_addcarryx_u64(&x45, &x46, x44, x17, x35);
uint64_t x47;
fiat_secp256k1_uint1 x48;
- fiat_secp256k1_addcarryx_u64(&x47, &x48, x46, x37, x19);
+ fiat_secp256k1_addcarryx_u64(&x47, &x48, x46, x19, x37);
uint64_t x49;
fiat_secp256k1_uint1 x50;
fiat_secp256k1_addcarryx_u64(&x49, &x50, x48, 0x0, 0x0);
@@ -573,31 +573,31 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x57, &x58, x1, (arg1[0]));
uint64_t x59;
fiat_secp256k1_uint1 x60;
- fiat_secp256k1_addcarryx_u64(&x59, &x60, 0x0, x55, x58);
+ fiat_secp256k1_addcarryx_u64(&x59, &x60, 0x0, x58, x55);
uint64_t x61;
fiat_secp256k1_uint1 x62;
- fiat_secp256k1_addcarryx_u64(&x61, &x62, x60, x53, x56);
+ fiat_secp256k1_addcarryx_u64(&x61, &x62, x60, x56, x53);
uint64_t x63;
fiat_secp256k1_uint1 x64;
- fiat_secp256k1_addcarryx_u64(&x63, &x64, x62, x51, x54);
+ fiat_secp256k1_addcarryx_u64(&x63, &x64, x62, x54, x51);
uint64_t x65;
fiat_secp256k1_uint1 x66;
- fiat_secp256k1_addcarryx_u64(&x65, &x66, x64, 0x0, x52);
+ fiat_secp256k1_addcarryx_u64(&x65, &x66, x64, x52, 0x0);
uint64_t x67;
fiat_secp256k1_uint1 x68;
- fiat_secp256k1_addcarryx_u64(&x67, &x68, 0x0, x57, x41);
+ fiat_secp256k1_addcarryx_u64(&x67, &x68, 0x0, x41, x57);
uint64_t x69;
fiat_secp256k1_uint1 x70;
- fiat_secp256k1_addcarryx_u64(&x69, &x70, x68, x59, x43);
+ fiat_secp256k1_addcarryx_u64(&x69, &x70, x68, x43, x59);
uint64_t x71;
fiat_secp256k1_uint1 x72;
- fiat_secp256k1_addcarryx_u64(&x71, &x72, x70, x61, x45);
+ fiat_secp256k1_addcarryx_u64(&x71, &x72, x70, x45, x61);
uint64_t x73;
fiat_secp256k1_uint1 x74;
- fiat_secp256k1_addcarryx_u64(&x73, &x74, x72, x63, x47);
+ fiat_secp256k1_addcarryx_u64(&x73, &x74, x72, x47, x63);
uint64_t x75;
fiat_secp256k1_uint1 x76;
- fiat_secp256k1_addcarryx_u64(&x75, &x76, x74, x65, (fiat_secp256k1_uint1)x49);
+ fiat_secp256k1_addcarryx_u64(&x75, &x76, x74, (fiat_secp256k1_uint1)x49, x65);
uint64_t x77;
uint64_t x78;
fiat_secp256k1_mulx_u64(&x77, &x78, x67, UINT64_C(0xd838091dd2253531));
@@ -615,34 +615,34 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x85, &x86, x77, UINT64_C(0xfffffffefffffc2f));
uint64_t x87;
fiat_secp256k1_uint1 x88;
- fiat_secp256k1_addcarryx_u64(&x87, &x88, 0x0, x83, x86);
+ fiat_secp256k1_addcarryx_u64(&x87, &x88, 0x0, x86, x83);
uint64_t x89;
fiat_secp256k1_uint1 x90;
- fiat_secp256k1_addcarryx_u64(&x89, &x90, x88, x81, x84);
+ fiat_secp256k1_addcarryx_u64(&x89, &x90, x88, x84, x81);
uint64_t x91;
fiat_secp256k1_uint1 x92;
- fiat_secp256k1_addcarryx_u64(&x91, &x92, x90, x79, x82);
+ fiat_secp256k1_addcarryx_u64(&x91, &x92, x90, x82, x79);
uint64_t x93;
fiat_secp256k1_uint1 x94;
- fiat_secp256k1_addcarryx_u64(&x93, &x94, x92, 0x0, x80);
+ fiat_secp256k1_addcarryx_u64(&x93, &x94, x92, x80, 0x0);
uint64_t x95;
fiat_secp256k1_uint1 x96;
- fiat_secp256k1_addcarryx_u64(&x95, &x96, 0x0, x85, x67);
+ fiat_secp256k1_addcarryx_u64(&x95, &x96, 0x0, x67, x85);
uint64_t x97;
fiat_secp256k1_uint1 x98;
- fiat_secp256k1_addcarryx_u64(&x97, &x98, x96, x87, x69);
+ fiat_secp256k1_addcarryx_u64(&x97, &x98, x96, x69, x87);
uint64_t x99;
fiat_secp256k1_uint1 x100;
- fiat_secp256k1_addcarryx_u64(&x99, &x100, x98, x89, x71);
+ fiat_secp256k1_addcarryx_u64(&x99, &x100, x98, x71, x89);
uint64_t x101;
fiat_secp256k1_uint1 x102;
- fiat_secp256k1_addcarryx_u64(&x101, &x102, x100, x91, x73);
+ fiat_secp256k1_addcarryx_u64(&x101, &x102, x100, x73, x91);
uint64_t x103;
fiat_secp256k1_uint1 x104;
- fiat_secp256k1_addcarryx_u64(&x103, &x104, x102, x93, x75);
+ fiat_secp256k1_addcarryx_u64(&x103, &x104, x102, x75, x93);
uint64_t x105;
fiat_secp256k1_uint1 x106;
- fiat_secp256k1_addcarryx_u64(&x105, &x106, x104, 0x0, x76);
+ fiat_secp256k1_addcarryx_u64(&x105, &x106, x104, x76, 0x0);
uint64_t x107;
uint64_t x108;
fiat_secp256k1_mulx_u64(&x107, &x108, x2, (arg1[3]));
@@ -657,31 +657,31 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x113, &x114, x2, (arg1[0]));
uint64_t x115;
fiat_secp256k1_uint1 x116;
- fiat_secp256k1_addcarryx_u64(&x115, &x116, 0x0, x111, x114);
+ fiat_secp256k1_addcarryx_u64(&x115, &x116, 0x0, x114, x111);
uint64_t x117;
fiat_secp256k1_uint1 x118;
- fiat_secp256k1_addcarryx_u64(&x117, &x118, x116, x109, x112);
+ fiat_secp256k1_addcarryx_u64(&x117, &x118, x116, x112, x109);
uint64_t x119;
fiat_secp256k1_uint1 x120;
- fiat_secp256k1_addcarryx_u64(&x119, &x120, x118, x107, x110);
+ fiat_secp256k1_addcarryx_u64(&x119, &x120, x118, x110, x107);
uint64_t x121;
fiat_secp256k1_uint1 x122;
- fiat_secp256k1_addcarryx_u64(&x121, &x122, x120, 0x0, x108);
+ fiat_secp256k1_addcarryx_u64(&x121, &x122, x120, x108, 0x0);
uint64_t x123;
fiat_secp256k1_uint1 x124;
- fiat_secp256k1_addcarryx_u64(&x123, &x124, 0x0, x113, x97);
+ fiat_secp256k1_addcarryx_u64(&x123, &x124, 0x0, x97, x113);
uint64_t x125;
fiat_secp256k1_uint1 x126;
- fiat_secp256k1_addcarryx_u64(&x125, &x126, x124, x115, x99);
+ fiat_secp256k1_addcarryx_u64(&x125, &x126, x124, x99, x115);
uint64_t x127;
fiat_secp256k1_uint1 x128;
- fiat_secp256k1_addcarryx_u64(&x127, &x128, x126, x117, x101);
+ fiat_secp256k1_addcarryx_u64(&x127, &x128, x126, x101, x117);
uint64_t x129;
fiat_secp256k1_uint1 x130;
- fiat_secp256k1_addcarryx_u64(&x129, &x130, x128, x119, x103);
+ fiat_secp256k1_addcarryx_u64(&x129, &x130, x128, x103, x119);
uint64_t x131;
fiat_secp256k1_uint1 x132;
- fiat_secp256k1_addcarryx_u64(&x131, &x132, x130, x121, x105);
+ fiat_secp256k1_addcarryx_u64(&x131, &x132, x130, x105, x121);
uint64_t x133;
uint64_t x134;
fiat_secp256k1_mulx_u64(&x133, &x134, x123, UINT64_C(0xd838091dd2253531));
@@ -699,34 +699,34 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x141, &x142, x133, UINT64_C(0xfffffffefffffc2f));
uint64_t x143;
fiat_secp256k1_uint1 x144;
- fiat_secp256k1_addcarryx_u64(&x143, &x144, 0x0, x139, x142);
+ fiat_secp256k1_addcarryx_u64(&x143, &x144, 0x0, x142, x139);
uint64_t x145;
fiat_secp256k1_uint1 x146;
- fiat_secp256k1_addcarryx_u64(&x145, &x146, x144, x137, x140);
+ fiat_secp256k1_addcarryx_u64(&x145, &x146, x144, x140, x137);
uint64_t x147;
fiat_secp256k1_uint1 x148;
- fiat_secp256k1_addcarryx_u64(&x147, &x148, x146, x135, x138);
+ fiat_secp256k1_addcarryx_u64(&x147, &x148, x146, x138, x135);
uint64_t x149;
fiat_secp256k1_uint1 x150;
- fiat_secp256k1_addcarryx_u64(&x149, &x150, x148, 0x0, x136);
+ fiat_secp256k1_addcarryx_u64(&x149, &x150, x148, x136, 0x0);
uint64_t x151;
fiat_secp256k1_uint1 x152;
- fiat_secp256k1_addcarryx_u64(&x151, &x152, 0x0, x141, x123);
+ fiat_secp256k1_addcarryx_u64(&x151, &x152, 0x0, x123, x141);
uint64_t x153;
fiat_secp256k1_uint1 x154;
- fiat_secp256k1_addcarryx_u64(&x153, &x154, x152, x143, x125);
+ fiat_secp256k1_addcarryx_u64(&x153, &x154, x152, x125, x143);
uint64_t x155;
fiat_secp256k1_uint1 x156;
- fiat_secp256k1_addcarryx_u64(&x155, &x156, x154, x145, x127);
+ fiat_secp256k1_addcarryx_u64(&x155, &x156, x154, x127, x145);
uint64_t x157;
fiat_secp256k1_uint1 x158;
- fiat_secp256k1_addcarryx_u64(&x157, &x158, x156, x147, x129);
+ fiat_secp256k1_addcarryx_u64(&x157, &x158, x156, x129, x147);
uint64_t x159;
fiat_secp256k1_uint1 x160;
- fiat_secp256k1_addcarryx_u64(&x159, &x160, x158, x149, x131);
+ fiat_secp256k1_addcarryx_u64(&x159, &x160, x158, x131, x149);
uint64_t x161;
fiat_secp256k1_uint1 x162;
- fiat_secp256k1_addcarryx_u64(&x161, &x162, x160, 0x0, x132);
+ fiat_secp256k1_addcarryx_u64(&x161, &x162, x160, x132, 0x0);
uint64_t x163;
uint64_t x164;
fiat_secp256k1_mulx_u64(&x163, &x164, x3, (arg1[3]));
@@ -741,31 +741,31 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x169, &x170, x3, (arg1[0]));
uint64_t x171;
fiat_secp256k1_uint1 x172;
- fiat_secp256k1_addcarryx_u64(&x171, &x172, 0x0, x167, x170);
+ fiat_secp256k1_addcarryx_u64(&x171, &x172, 0x0, x170, x167);
uint64_t x173;
fiat_secp256k1_uint1 x174;
- fiat_secp256k1_addcarryx_u64(&x173, &x174, x172, x165, x168);
+ fiat_secp256k1_addcarryx_u64(&x173, &x174, x172, x168, x165);
uint64_t x175;
fiat_secp256k1_uint1 x176;
- fiat_secp256k1_addcarryx_u64(&x175, &x176, x174, x163, x166);
+ fiat_secp256k1_addcarryx_u64(&x175, &x176, x174, x166, x163);
uint64_t x177;
fiat_secp256k1_uint1 x178;
- fiat_secp256k1_addcarryx_u64(&x177, &x178, x176, 0x0, x164);
+ fiat_secp256k1_addcarryx_u64(&x177, &x178, x176, x164, 0x0);
uint64_t x179;
fiat_secp256k1_uint1 x180;
- fiat_secp256k1_addcarryx_u64(&x179, &x180, 0x0, x169, x153);
+ fiat_secp256k1_addcarryx_u64(&x179, &x180, 0x0, x153, x169);
uint64_t x181;
fiat_secp256k1_uint1 x182;
- fiat_secp256k1_addcarryx_u64(&x181, &x182, x180, x171, x155);
+ fiat_secp256k1_addcarryx_u64(&x181, &x182, x180, x155, x171);
uint64_t x183;
fiat_secp256k1_uint1 x184;
- fiat_secp256k1_addcarryx_u64(&x183, &x184, x182, x173, x157);
+ fiat_secp256k1_addcarryx_u64(&x183, &x184, x182, x157, x173);
uint64_t x185;
fiat_secp256k1_uint1 x186;
- fiat_secp256k1_addcarryx_u64(&x185, &x186, x184, x175, x159);
+ fiat_secp256k1_addcarryx_u64(&x185, &x186, x184, x159, x175);
uint64_t x187;
fiat_secp256k1_uint1 x188;
- fiat_secp256k1_addcarryx_u64(&x187, &x188, x186, x177, x161);
+ fiat_secp256k1_addcarryx_u64(&x187, &x188, x186, x161, x177);
uint64_t x189;
uint64_t x190;
fiat_secp256k1_mulx_u64(&x189, &x190, x179, UINT64_C(0xd838091dd2253531));
@@ -783,34 +783,34 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_mulx_u64(&x197, &x198, x189, UINT64_C(0xfffffffefffffc2f));
uint64_t x199;
fiat_secp256k1_uint1 x200;
- fiat_secp256k1_addcarryx_u64(&x199, &x200, 0x0, x195, x198);
+ fiat_secp256k1_addcarryx_u64(&x199, &x200, 0x0, x198, x195);
uint64_t x201;
fiat_secp256k1_uint1 x202;
- fiat_secp256k1_addcarryx_u64(&x201, &x202, x200, x193, x196);
+ fiat_secp256k1_addcarryx_u64(&x201, &x202, x200, x196, x193);
uint64_t x203;
fiat_secp256k1_uint1 x204;
- fiat_secp256k1_addcarryx_u64(&x203, &x204, x202, x191, x194);
+ fiat_secp256k1_addcarryx_u64(&x203, &x204, x202, x194, x191);
uint64_t x205;
fiat_secp256k1_uint1 x206;
- fiat_secp256k1_addcarryx_u64(&x205, &x206, x204, 0x0, x192);
+ fiat_secp256k1_addcarryx_u64(&x205, &x206, x204, x192, 0x0);
uint64_t x207;
fiat_secp256k1_uint1 x208;
- fiat_secp256k1_addcarryx_u64(&x207, &x208, 0x0, x197, x179);
+ fiat_secp256k1_addcarryx_u64(&x207, &x208, 0x0, x179, x197);
uint64_t x209;
fiat_secp256k1_uint1 x210;
- fiat_secp256k1_addcarryx_u64(&x209, &x210, x208, x199, x181);
+ fiat_secp256k1_addcarryx_u64(&x209, &x210, x208, x181, x199);
uint64_t x211;
fiat_secp256k1_uint1 x212;
- fiat_secp256k1_addcarryx_u64(&x211, &x212, x210, x201, x183);
+ fiat_secp256k1_addcarryx_u64(&x211, &x212, x210, x183, x201);
uint64_t x213;
fiat_secp256k1_uint1 x214;
- fiat_secp256k1_addcarryx_u64(&x213, &x214, x212, x203, x185);
+ fiat_secp256k1_addcarryx_u64(&x213, &x214, x212, x185, x203);
uint64_t x215;
fiat_secp256k1_uint1 x216;
- fiat_secp256k1_addcarryx_u64(&x215, &x216, x214, x205, x187);
+ fiat_secp256k1_addcarryx_u64(&x215, &x216, x214, x187, x205);
uint64_t x217;
fiat_secp256k1_uint1 x218;
- fiat_secp256k1_addcarryx_u64(&x217, &x218, x216, 0x0, x188);
+ fiat_secp256k1_addcarryx_u64(&x217, &x218, x216, x188, 0x0);
uint64_t x219;
fiat_secp256k1_uint1 x220;
fiat_secp256k1_subborrowx_u64(&x219, &x220, 0x0, x209, UINT64_C(0xfffffffefffffc2f));
@@ -858,16 +858,16 @@ static void fiat_secp256k1_square(uint64_t out1[4], const uint64_t arg1[4]) {
static void fiat_secp256k1_add(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
uint64_t x1;
fiat_secp256k1_uint1 x2;
- fiat_secp256k1_addcarryx_u64(&x1, &x2, 0x0, (arg2[0]), (arg1[0]));
+ fiat_secp256k1_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
uint64_t x3;
fiat_secp256k1_uint1 x4;
- fiat_secp256k1_addcarryx_u64(&x3, &x4, x2, (arg2[1]), (arg1[1]));
+ fiat_secp256k1_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
uint64_t x5;
fiat_secp256k1_uint1 x6;
- fiat_secp256k1_addcarryx_u64(&x5, &x6, x4, (arg2[2]), (arg1[2]));
+ fiat_secp256k1_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
uint64_t x7;
fiat_secp256k1_uint1 x8;
- fiat_secp256k1_addcarryx_u64(&x7, &x8, x6, (arg2[3]), (arg1[3]));
+ fiat_secp256k1_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
uint64_t x9;
fiat_secp256k1_uint1 x10;
fiat_secp256k1_subborrowx_u64(&x9, &x10, 0x0, x1, UINT64_C(0xfffffffefffffc2f));
@@ -929,16 +929,16 @@ static void fiat_secp256k1_sub(uint64_t out1[4], const uint64_t arg1[4], const u
fiat_secp256k1_cmovznz_u64(&x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x10;
fiat_secp256k1_uint1 x11;
- fiat_secp256k1_addcarryx_u64(&x10, &x11, 0x0, (x9 & UINT64_C(0xfffffffefffffc2f)), x1);
+ fiat_secp256k1_addcarryx_u64(&x10, &x11, 0x0, x1, (x9 & UINT64_C(0xfffffffefffffc2f)));
uint64_t x12;
fiat_secp256k1_uint1 x13;
- fiat_secp256k1_addcarryx_u64(&x12, &x13, x11, (x9 & UINT64_C(0xffffffffffffffff)), x3);
+ fiat_secp256k1_addcarryx_u64(&x12, &x13, x11, x3, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x14;
fiat_secp256k1_uint1 x15;
- fiat_secp256k1_addcarryx_u64(&x14, &x15, x13, (x9 & UINT64_C(0xffffffffffffffff)), x5);
+ fiat_secp256k1_addcarryx_u64(&x14, &x15, x13, x5, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x16;
fiat_secp256k1_uint1 x17;
- fiat_secp256k1_addcarryx_u64(&x16, &x17, x15, (x9 & UINT64_C(0xffffffffffffffff)), x7);
+ fiat_secp256k1_addcarryx_u64(&x16, &x17, x15, x7, (x9 & UINT64_C(0xffffffffffffffff)));
out1[0] = x10;
out1[1] = x12;
out1[2] = x14;
@@ -975,16 +975,16 @@ static void fiat_secp256k1_opp(uint64_t out1[4], const uint64_t arg1[4]) {
fiat_secp256k1_cmovznz_u64(&x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
uint64_t x10;
fiat_secp256k1_uint1 x11;
- fiat_secp256k1_addcarryx_u64(&x10, &x11, 0x0, (x9 & UINT64_C(0xfffffffefffffc2f)), x1);
+ fiat_secp256k1_addcarryx_u64(&x10, &x11, 0x0, x1, (x9 & UINT64_C(0xfffffffefffffc2f)));
uint64_t x12;
fiat_secp256k1_uint1 x13;
- fiat_secp256k1_addcarryx_u64(&x12, &x13, x11, (x9 & UINT64_C(0xffffffffffffffff)), x3);
+ fiat_secp256k1_addcarryx_u64(&x12, &x13, x11, x3, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x14;
fiat_secp256k1_uint1 x15;
- fiat_secp256k1_addcarryx_u64(&x14, &x15, x13, (x9 & UINT64_C(0xffffffffffffffff)), x5);
+ fiat_secp256k1_addcarryx_u64(&x14, &x15, x13, x5, (x9 & UINT64_C(0xffffffffffffffff)));
uint64_t x16;
fiat_secp256k1_uint1 x17;
- fiat_secp256k1_addcarryx_u64(&x16, &x17, x15, (x9 & UINT64_C(0xffffffffffffffff)), x7);
+ fiat_secp256k1_addcarryx_u64(&x16, &x17, x15, x7, (x9 & UINT64_C(0xffffffffffffffff)));
out1[0] = x10;
out1[1] = x12;
out1[2] = x14;
@@ -1023,43 +1023,43 @@ static void fiat_secp256k1_from_montgomery(uint64_t out1[4], const uint64_t arg1
fiat_secp256k1_mulx_u64(&x10, &x11, x2, UINT64_C(0xfffffffefffffc2f));
uint64_t x12;
fiat_secp256k1_uint1 x13;
- fiat_secp256k1_addcarryx_u64(&x12, &x13, 0x0, x8, x11);
+ fiat_secp256k1_addcarryx_u64(&x12, &x13, 0x0, x11, x8);
uint64_t x14;
fiat_secp256k1_uint1 x15;
- fiat_secp256k1_addcarryx_u64(&x14, &x15, x13, x6, x9);
+ fiat_secp256k1_addcarryx_u64(&x14, &x15, x13, x9, x6);
uint64_t x16;
fiat_secp256k1_uint1 x17;
- fiat_secp256k1_addcarryx_u64(&x16, &x17, x15, x4, x7);
+ fiat_secp256k1_addcarryx_u64(&x16, &x17, x15, x7, x4);
uint64_t x18;
fiat_secp256k1_uint1 x19;
- fiat_secp256k1_addcarryx_u64(&x18, &x19, 0x0, x10, x1);
+ fiat_secp256k1_addcarryx_u64(&x18, &x19, 0x0, x1, x10);
uint64_t x20;
fiat_secp256k1_uint1 x21;
- fiat_secp256k1_addcarryx_u64(&x20, &x21, x19, x12, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x20, &x21, x19, 0x0, x12);
uint64_t x22;
fiat_secp256k1_uint1 x23;
- fiat_secp256k1_addcarryx_u64(&x22, &x23, x21, x14, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x22, &x23, x21, 0x0, x14);
uint64_t x24;
fiat_secp256k1_uint1 x25;
- fiat_secp256k1_addcarryx_u64(&x24, &x25, x23, x16, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x24, &x25, x23, 0x0, x16);
uint64_t x26;
fiat_secp256k1_uint1 x27;
- fiat_secp256k1_addcarryx_u64(&x26, &x27, x17, 0x0, x5);
+ fiat_secp256k1_addcarryx_u64(&x26, &x27, x17, x5, 0x0);
uint64_t x28;
fiat_secp256k1_uint1 x29;
- fiat_secp256k1_addcarryx_u64(&x28, &x29, x25, x26, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x28, &x29, x25, 0x0, x26);
uint64_t x30;
fiat_secp256k1_uint1 x31;
- fiat_secp256k1_addcarryx_u64(&x30, &x31, 0x0, (arg1[1]), x20);
+ fiat_secp256k1_addcarryx_u64(&x30, &x31, 0x0, x20, (arg1[1]));
uint64_t x32;
fiat_secp256k1_uint1 x33;
- fiat_secp256k1_addcarryx_u64(&x32, &x33, x31, 0x0, x22);
+ fiat_secp256k1_addcarryx_u64(&x32, &x33, x31, x22, 0x0);
uint64_t x34;
fiat_secp256k1_uint1 x35;
- fiat_secp256k1_addcarryx_u64(&x34, &x35, x33, 0x0, x24);
+ fiat_secp256k1_addcarryx_u64(&x34, &x35, x33, x24, 0x0);
uint64_t x36;
fiat_secp256k1_uint1 x37;
- fiat_secp256k1_addcarryx_u64(&x36, &x37, x35, 0x0, x28);
+ fiat_secp256k1_addcarryx_u64(&x36, &x37, x35, x28, 0x0);
uint64_t x38;
uint64_t x39;
fiat_secp256k1_mulx_u64(&x38, &x39, x30, UINT64_C(0xd838091dd2253531));
@@ -1077,49 +1077,49 @@ static void fiat_secp256k1_from_montgomery(uint64_t out1[4], const uint64_t arg1
fiat_secp256k1_mulx_u64(&x46, &x47, x38, UINT64_C(0xfffffffefffffc2f));
uint64_t x48;
fiat_secp256k1_uint1 x49;
- fiat_secp256k1_addcarryx_u64(&x48, &x49, 0x0, x44, x47);
+ fiat_secp256k1_addcarryx_u64(&x48, &x49, 0x0, x47, x44);
uint64_t x50;
fiat_secp256k1_uint1 x51;
- fiat_secp256k1_addcarryx_u64(&x50, &x51, x49, x42, x45);
+ fiat_secp256k1_addcarryx_u64(&x50, &x51, x49, x45, x42);
uint64_t x52;
fiat_secp256k1_uint1 x53;
- fiat_secp256k1_addcarryx_u64(&x52, &x53, x51, x40, x43);
+ fiat_secp256k1_addcarryx_u64(&x52, &x53, x51, x43, x40);
uint64_t x54;
fiat_secp256k1_uint1 x55;
- fiat_secp256k1_addcarryx_u64(&x54, &x55, 0x0, x46, x30);
+ fiat_secp256k1_addcarryx_u64(&x54, &x55, 0x0, x30, x46);
uint64_t x56;
fiat_secp256k1_uint1 x57;
- fiat_secp256k1_addcarryx_u64(&x56, &x57, x55, x48, x32);
+ fiat_secp256k1_addcarryx_u64(&x56, &x57, x55, x32, x48);
uint64_t x58;
fiat_secp256k1_uint1 x59;
- fiat_secp256k1_addcarryx_u64(&x58, &x59, x57, x50, x34);
+ fiat_secp256k1_addcarryx_u64(&x58, &x59, x57, x34, x50);
uint64_t x60;
fiat_secp256k1_uint1 x61;
- fiat_secp256k1_addcarryx_u64(&x60, &x61, x59, x52, x36);
+ fiat_secp256k1_addcarryx_u64(&x60, &x61, x59, x36, x52);
uint64_t x62;
fiat_secp256k1_uint1 x63;
- fiat_secp256k1_addcarryx_u64(&x62, &x63, x29, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x62, &x63, x53, x41, 0x0);
uint64_t x64;
fiat_secp256k1_uint1 x65;
- fiat_secp256k1_addcarryx_u64(&x64, &x65, x37, 0x0, (fiat_secp256k1_uint1)x62);
+ fiat_secp256k1_addcarryx_u64(&x64, &x65, x29, 0x0, 0x0);
uint64_t x66;
fiat_secp256k1_uint1 x67;
- fiat_secp256k1_addcarryx_u64(&x66, &x67, x53, 0x0, x41);
+ fiat_secp256k1_addcarryx_u64(&x66, &x67, x37, (fiat_secp256k1_uint1)x64, 0x0);
uint64_t x68;
fiat_secp256k1_uint1 x69;
- fiat_secp256k1_addcarryx_u64(&x68, &x69, x61, x66, x64);
+ fiat_secp256k1_addcarryx_u64(&x68, &x69, x61, x66, x62);
uint64_t x70;
fiat_secp256k1_uint1 x71;
- fiat_secp256k1_addcarryx_u64(&x70, &x71, 0x0, (arg1[2]), x56);
+ fiat_secp256k1_addcarryx_u64(&x70, &x71, 0x0, x56, (arg1[2]));
uint64_t x72;
fiat_secp256k1_uint1 x73;
- fiat_secp256k1_addcarryx_u64(&x72, &x73, x71, 0x0, x58);
+ fiat_secp256k1_addcarryx_u64(&x72, &x73, x71, x58, 0x0);
uint64_t x74;
fiat_secp256k1_uint1 x75;
- fiat_secp256k1_addcarryx_u64(&x74, &x75, x73, 0x0, x60);
+ fiat_secp256k1_addcarryx_u64(&x74, &x75, x73, x60, 0x0);
uint64_t x76;
fiat_secp256k1_uint1 x77;
- fiat_secp256k1_addcarryx_u64(&x76, &x77, x75, 0x0, x68);
+ fiat_secp256k1_addcarryx_u64(&x76, &x77, x75, x68, 0x0);
uint64_t x78;
uint64_t x79;
fiat_secp256k1_mulx_u64(&x78, &x79, x70, UINT64_C(0xd838091dd2253531));
@@ -1137,49 +1137,49 @@ static void fiat_secp256k1_from_montgomery(uint64_t out1[4], const uint64_t arg1
fiat_secp256k1_mulx_u64(&x86, &x87, x78, UINT64_C(0xfffffffefffffc2f));
uint64_t x88;
fiat_secp256k1_uint1 x89;
- fiat_secp256k1_addcarryx_u64(&x88, &x89, 0x0, x84, x87);
+ fiat_secp256k1_addcarryx_u64(&x88, &x89, 0x0, x87, x84);
uint64_t x90;
fiat_secp256k1_uint1 x91;
- fiat_secp256k1_addcarryx_u64(&x90, &x91, x89, x82, x85);
+ fiat_secp256k1_addcarryx_u64(&x90, &x91, x89, x85, x82);
uint64_t x92;
fiat_secp256k1_uint1 x93;
- fiat_secp256k1_addcarryx_u64(&x92, &x93, x91, x80, x83);
+ fiat_secp256k1_addcarryx_u64(&x92, &x93, x91, x83, x80);
uint64_t x94;
fiat_secp256k1_uint1 x95;
- fiat_secp256k1_addcarryx_u64(&x94, &x95, 0x0, x86, x70);
+ fiat_secp256k1_addcarryx_u64(&x94, &x95, 0x0, x70, x86);
uint64_t x96;
fiat_secp256k1_uint1 x97;
- fiat_secp256k1_addcarryx_u64(&x96, &x97, x95, x88, x72);
+ fiat_secp256k1_addcarryx_u64(&x96, &x97, x95, x72, x88);
uint64_t x98;
fiat_secp256k1_uint1 x99;
- fiat_secp256k1_addcarryx_u64(&x98, &x99, x97, x90, x74);
+ fiat_secp256k1_addcarryx_u64(&x98, &x99, x97, x74, x90);
uint64_t x100;
fiat_secp256k1_uint1 x101;
- fiat_secp256k1_addcarryx_u64(&x100, &x101, x99, x92, x76);
+ fiat_secp256k1_addcarryx_u64(&x100, &x101, x99, x76, x92);
uint64_t x102;
fiat_secp256k1_uint1 x103;
- fiat_secp256k1_addcarryx_u64(&x102, &x103, x69, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x102, &x103, x93, x81, 0x0);
uint64_t x104;
fiat_secp256k1_uint1 x105;
- fiat_secp256k1_addcarryx_u64(&x104, &x105, x77, 0x0, (fiat_secp256k1_uint1)x102);
+ fiat_secp256k1_addcarryx_u64(&x104, &x105, x69, 0x0, 0x0);
uint64_t x106;
fiat_secp256k1_uint1 x107;
- fiat_secp256k1_addcarryx_u64(&x106, &x107, x93, 0x0, x81);
+ fiat_secp256k1_addcarryx_u64(&x106, &x107, x77, (fiat_secp256k1_uint1)x104, 0x0);
uint64_t x108;
fiat_secp256k1_uint1 x109;
- fiat_secp256k1_addcarryx_u64(&x108, &x109, x101, x106, x104);
+ fiat_secp256k1_addcarryx_u64(&x108, &x109, x101, x106, x102);
uint64_t x110;
fiat_secp256k1_uint1 x111;
- fiat_secp256k1_addcarryx_u64(&x110, &x111, 0x0, (arg1[3]), x96);
+ fiat_secp256k1_addcarryx_u64(&x110, &x111, 0x0, x96, (arg1[3]));
uint64_t x112;
fiat_secp256k1_uint1 x113;
- fiat_secp256k1_addcarryx_u64(&x112, &x113, x111, 0x0, x98);
+ fiat_secp256k1_addcarryx_u64(&x112, &x113, x111, x98, 0x0);
uint64_t x114;
fiat_secp256k1_uint1 x115;
- fiat_secp256k1_addcarryx_u64(&x114, &x115, x113, 0x0, x100);
+ fiat_secp256k1_addcarryx_u64(&x114, &x115, x113, x100, 0x0);
uint64_t x116;
fiat_secp256k1_uint1 x117;
- fiat_secp256k1_addcarryx_u64(&x116, &x117, x115, 0x0, x108);
+ fiat_secp256k1_addcarryx_u64(&x116, &x117, x115, x108, 0x0);
uint64_t x118;
uint64_t x119;
fiat_secp256k1_mulx_u64(&x118, &x119, x110, UINT64_C(0xd838091dd2253531));
@@ -1197,37 +1197,37 @@ static void fiat_secp256k1_from_montgomery(uint64_t out1[4], const uint64_t arg1
fiat_secp256k1_mulx_u64(&x126, &x127, x118, UINT64_C(0xfffffffefffffc2f));
uint64_t x128;
fiat_secp256k1_uint1 x129;
- fiat_secp256k1_addcarryx_u64(&x128, &x129, 0x0, x124, x127);
+ fiat_secp256k1_addcarryx_u64(&x128, &x129, 0x0, x127, x124);
uint64_t x130;
fiat_secp256k1_uint1 x131;
- fiat_secp256k1_addcarryx_u64(&x130, &x131, x129, x122, x125);
+ fiat_secp256k1_addcarryx_u64(&x130, &x131, x129, x125, x122);
uint64_t x132;
fiat_secp256k1_uint1 x133;
- fiat_secp256k1_addcarryx_u64(&x132, &x133, x131, x120, x123);
+ fiat_secp256k1_addcarryx_u64(&x132, &x133, x131, x123, x120);
uint64_t x134;
fiat_secp256k1_uint1 x135;
- fiat_secp256k1_addcarryx_u64(&x134, &x135, 0x0, x126, x110);
+ fiat_secp256k1_addcarryx_u64(&x134, &x135, 0x0, x110, x126);
uint64_t x136;
fiat_secp256k1_uint1 x137;
- fiat_secp256k1_addcarryx_u64(&x136, &x137, x135, x128, x112);
+ fiat_secp256k1_addcarryx_u64(&x136, &x137, x135, x112, x128);
uint64_t x138;
fiat_secp256k1_uint1 x139;
- fiat_secp256k1_addcarryx_u64(&x138, &x139, x137, x130, x114);
+ fiat_secp256k1_addcarryx_u64(&x138, &x139, x137, x114, x130);
uint64_t x140;
fiat_secp256k1_uint1 x141;
- fiat_secp256k1_addcarryx_u64(&x140, &x141, x139, x132, x116);
+ fiat_secp256k1_addcarryx_u64(&x140, &x141, x139, x116, x132);
uint64_t x142;
fiat_secp256k1_uint1 x143;
- fiat_secp256k1_addcarryx_u64(&x142, &x143, x109, 0x0, 0x0);
+ fiat_secp256k1_addcarryx_u64(&x142, &x143, x133, x121, 0x0);
uint64_t x144;
fiat_secp256k1_uint1 x145;
- fiat_secp256k1_addcarryx_u64(&x144, &x145, x117, 0x0, (fiat_secp256k1_uint1)x142);
+ fiat_secp256k1_addcarryx_u64(&x144, &x145, x109, 0x0, 0x0);
uint64_t x146;
fiat_secp256k1_uint1 x147;
- fiat_secp256k1_addcarryx_u64(&x146, &x147, x133, 0x0, x121);
+ fiat_secp256k1_addcarryx_u64(&x146, &x147, x117, (fiat_secp256k1_uint1)x144, 0x0);
uint64_t x148;
fiat_secp256k1_uint1 x149;
- fiat_secp256k1_addcarryx_u64(&x148, &x149, x141, x146, x144);
+ fiat_secp256k1_addcarryx_u64(&x148, &x149, x141, x146, x142);
uint64_t x150;
fiat_secp256k1_uint1 x151;
fiat_secp256k1_subborrowx_u64(&x150, &x151, 0x0, x136, UINT64_C(0xfffffffefffffc2f));