aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--src/Curves/Montgomery/XZ.v64
-rw-r--r--src/Curves/Montgomery/XZProofs.v7
-rw-r--r--src/Specific/IntegrationTestLadderstep.v42
-rw-r--r--src/Specific/IntegrationTestLadderstepDisplay.log676
4 files changed, 418 insertions, 371 deletions
diff --git a/src/Curves/Montgomery/XZ.v b/src/Curves/Montgomery/XZ.v
index c31fb26c6..735e6ac76 100644
--- a/src/Curves/Montgomery/XZ.v
+++ b/src/Curves/Montgomery/XZ.v
@@ -57,26 +57,54 @@ Module M.
((x2, z2), (x3, z3))%core
end.
- Context {cswap:bool->F*F->F*F->(F*F)*(F*F)}.
+ (* optimized version from curve25519-donna by Adam Langley *)
+ Definition donnaladderstep (x1:F) (Q Q':F*F) : (F*F)*(F*F) :=
+ match Q, Q' with
+ pair x z, pair x' z'=>
+ dlet origx := x in
+ dlet x := x + z in
+ dlet z := origx - z in
+ dlet origx' := x' in
+ dlet x' := x' + z' in
+ dlet z' := origx' - z' in
+ dlet xx' := x' * z in
+ dlet zz' := x * z' in
+ dlet origx' := xx' in
+ dlet xx' := xx' + zz' in
+ dlet zz' := origx' - zz' in
+ dlet x3 := xx'^2 in
+ dlet zzz' := zz'^2 in
+ dlet z3 := zzz' * x1 in
+ dlet xx := x^2 in
+ dlet zz := z^2 in
+ dlet x2 := xx * zz in
+ dlet zz := xx - zz in
+ dlet zzz := zz * a24 in
+ dlet zzz := zzz + xx in
+ dlet z2 := zz * zzz in
+ ((x2, z2), (x3, z3))%core
+ end.
+
+ Context {cswap:bool->F*F->F*F->(F*F)*(F*F)}.
- Local Notation xor := Coq.Init.Datatypes.xorb.
+ Local Notation xor := Coq.Init.Datatypes.xorb.
- (* Ideally, we would verify that this corresponds to x coordinate
- multiplication *)
- Local Open Scope core_scope.
- Definition montladder (bound : positive) (testbit:Z->bool) (u:F) :=
- let '(P1, P2, swap) :=
- for (int i = BinInt.Z.pos bound; i >= 0; i--)
- updating ('(P1, P2, swap) = ((1%F, 0%F), (u, 1%F), false)) {{
- dlet s_i := testbit i in
- dlet swap := xor swap s_i in
- let '(P1, P2) := cswap swap P1 P2 in
- dlet swap := s_i in
- let '(P1, P2) := xzladderstep u P1 P2 in
- (P1, P2, swap)
- }} in
- let '((x, z), _) := cswap swap P1 P2 in
- x * Finv z.
+ (* Ideally, we would verify that this corresponds to x coordinate
+ multiplication *)
+ Local Open Scope core_scope.
+ Definition montladder (bound : positive) (testbit:Z->bool) (u:F) :=
+ let '(P1, P2, swap) :=
+ for (int i = BinInt.Z.pos bound; i >= 0; i--)
+ updating ('(P1, P2, swap) = ((1%F, 0%F), (u, 1%F), false)) {{
+ dlet s_i := testbit i in
+ dlet swap := xor swap s_i in
+ let '(P1, P2) := cswap swap P1 P2 in
+ dlet swap := s_i in
+ let '(P1, P2) := xzladderstep u P1 P2 in
+ (P1, P2, swap)
+ }} in
+ let '((x, z), _) := cswap swap P1 P2 in
+ x * Finv z.
End MontgomeryCurve.
End M.
diff --git a/src/Curves/Montgomery/XZProofs.v b/src/Curves/Montgomery/XZProofs.v
index be0153251..d3fd486d8 100644
--- a/src/Curves/Montgomery/XZProofs.v
+++ b/src/Curves/Montgomery/XZProofs.v
@@ -1,6 +1,7 @@
Require Import Crypto.Algebra.Field.
Require Import Crypto.Util.Sum Crypto.Util.Prod Crypto.Util.LetIn.
Require Import Crypto.Util.Decidable.
+Require Import Crypto.Util.Tuple.
Require Import Crypto.Util.Tactics.SetoidSubst.
Require Import Crypto.Util.Tactics.SpecializeBy.
Require Import Crypto.Util.Tactics.DestructHead.
@@ -32,8 +33,14 @@ Module M.
Local Notation Mopp := (M.opp(a:=a)(b_nonzero:=b_nonzero)).
Local Notation Mpoint := (@M.point F Feq Fadd Fmul a b).
Local Notation xzladderstep := (M.xzladderstep(a24:=a24)(Fadd:=Fadd)(Fsub:=Fsub)(Fmul:=Fmul)).
+ Local Notation donnaladderstep := (M.donnaladderstep(a24:=a24)(Fadd:=Fadd)(Fsub:=Fsub)(Fmul:=Fmul)).
Local Notation to_xz := (M.to_xz(Fzero:=Fzero)(Fone:=Fone)(Feq:=Feq)(Fadd:=Fadd)(Fmul:=Fmul)(a:=a)(b:=b)).
+ Lemma donnaladderstep_ok x1 Q Q' :
+ let eq := fieldwise (n:=2) (fieldwise (n:=2) Feq) in
+ eq (xzladderstep x1 Q Q') (donnaladderstep x1 Q Q').
+ Proof. cbv; break_match; repeat split; fsatz. Qed.
+
Definition projective (P:F*F) :=
if dec (snd P = 0) then fst P <> 0 else True.
Definition eq (P Q:F*F) := fst P * snd Q = fst Q * snd P.
diff --git a/src/Specific/IntegrationTestLadderstep.v b/src/Specific/IntegrationTestLadderstep.v
index 6b92b51b9..06cd4f808 100644
--- a/src/Specific/IntegrationTestLadderstep.v
+++ b/src/Specific/IntegrationTestLadderstep.v
@@ -50,7 +50,7 @@ Section BoundedField25p5.
fun x => B.Positional.Fdecode wt (Tuple.map wordToZ x).
(** TODO(jadep,andreser): Move to NewBaseSystemTest? *)
- Definition FMxzladderstep := @M.xzladderstep (F m) F.add F.sub F.mul.
+ Definition FMxzladderstep := @M.donnaladderstep (F m) F.add F.sub F.mul.
Section with_notations.
Local Infix "+" := (proj1_sig add_sig).
@@ -59,21 +59,29 @@ Section BoundedField25p5.
Local Infix "-" := (proj1_sig sub_sig).
Definition Mxzladderstep a24 x1 Q Q'
:= match Q, Q' with
- | (x, z), (x', z')
- => dlet A := x+z in
- dlet B := x-z in
- dlet AA := A^2 in
- dlet BB := B^2 in
- dlet x2 := AA*BB in
- dlet E := AA-BB in
- dlet z2 := E*(AA + a24*E) in
- dlet C := x'+z' in
- dlet D := x'-z' in
- dlet CB := C*B in
- dlet DA := D*A in
- dlet x3 := (DA+CB)^2 in
- dlet z3 := x1*(DA-CB)^2 in
- ((x2, z2), (x3, z3))%core
+ | (x, z), (x', z') =>
+ dlet origx := x in
+ dlet x := x + z in
+ dlet z := origx - z in
+ dlet origx' := x' in
+ dlet x' := x' + z' in
+ dlet z' := origx' - z' in
+ dlet xx' := x' * z in
+ dlet zz' := x * z' in
+ dlet origx' := xx' in
+ dlet xx' := xx' + zz' in
+ dlet zz' := origx' - zz' in
+ dlet x3 := xx'^2 in
+ dlet zzz' := zz'^2 in
+ dlet z3 := zzz' * x1 in
+ dlet xx := x^2 in
+ dlet zz := z^2 in
+ dlet x2 := xx * zz in
+ dlet zz := xx - zz in
+ dlet zzz := zz * a24 in
+ dlet zzz := zzz + xx in
+ dlet z2 := zz * zzz in
+ ((x2, z2), (x3, z3))%core
end.
End with_notations.
@@ -85,7 +93,7 @@ Section BoundedField25p5.
Proof.
exists Mxzladderstep.
intros.
- cbv [Mxzladderstep FMxzladderstep M.xzladderstep].
+ cbv [Mxzladderstep FMxzladderstep M.donnaladderstep].
destruct Q, Q'; cbv [map map' fst snd Let_In eval].
repeat rewrite ?(proj2_sig add_sig), ?(proj2_sig mul_sig), ?(proj2_sig square_sig), ?(proj2_sig sub_sig), ?(proj2_sig carry_sig).
reflexivity.
diff --git a/src/Specific/IntegrationTestLadderstepDisplay.log b/src/Specific/IntegrationTestLadderstepDisplay.log
index d7db32470..40c93cb59 100644
--- a/src/Specific/IntegrationTestLadderstepDisplay.log
+++ b/src/Specific/IntegrationTestLadderstepDisplay.log
@@ -12,277 +12,277 @@ let (a, b) := Interp-η
uint64_t x60 = 0xffffffffffffe + x24 - x32;
uint64_t x61 = 0xffffffffffffe + x22 - x30;
uint64_t x62 = 0xfffffffffffda + x20 - x28;
- uint64_t x63 = x57 * 0x2;
- uint64_t x64 = x56 * 0x2;
- uint64_t x65 = x55 * 0x2 * 0x13;
- uint64_t x66 = x53 * 0x13;
- uint64_t x67 = x66 * 0x2;
- uint128_t x68 = (uint128_t) x57 * x57 + (uint128_t) x67 * x56 + (uint128_t) x65 * x54;
- uint128_t x69 = (uint128_t) x63 * x56 + (uint128_t) x67 * x55 + (uint128_t) x54 * x54 * 0x13;
- uint128_t x70 = (uint128_t) x63 * x55 + (uint128_t) x56 * x56 + (uint128_t) x67 * x54;
- uint128_t x71 = (uint128_t) x63 * x54 + (uint128_t) x64 * x55 + (uint128_t) x53 * x66;
- uint128_t x72 = (uint128_t) x63 * x53 + (uint128_t) x64 * x54 + (uint128_t) x55 * x55;
- uint64_t x73 = (uint64_t) (x68 >> 0x33);
- uint64_t x74 = (uint64_t) x68 & 0x7ffffffffffff;
- uint128_t x75 = x73 + x69;
- uint64_t x76 = (uint64_t) (x75 >> 0x33);
- uint64_t x77 = (uint64_t) x75 & 0x7ffffffffffff;
- uint128_t x78 = x76 + x70;
- uint64_t x79 = (uint64_t) (x78 >> 0x33);
- uint64_t x80 = (uint64_t) x78 & 0x7ffffffffffff;
- uint128_t x81 = x79 + x71;
- uint64_t x82 = (uint64_t) (x81 >> 0x33);
- uint64_t x83 = (uint64_t) x81 & 0x7ffffffffffff;
- uint128_t x84 = x82 + x72;
- uint64_t x85 = (uint64_t) (x84 >> 0x33);
- uint64_t x86 = (uint64_t) x84 & 0x7ffffffffffff;
- uint64_t x87 = x74 + 0x13 * x85;
- uint64_t x88 = x87 >> 0x33;
- uint64_t x89 = x87 & 0x7ffffffffffff;
- uint64_t x90 = x88 + x77;
- uint64_t x91 = x90 >> 0x33;
- uint64_t x92 = x90 & 0x7ffffffffffff;
- uint64_t x93 = x91 + x80;
- uint64_t x94 = x62 * 0x2;
- uint64_t x95 = x61 * 0x2;
- uint64_t x96 = x60 * 0x2 * 0x13;
- uint64_t x97 = x58 * 0x13;
- uint64_t x98 = x97 * 0x2;
- uint128_t x99 = (uint128_t) x62 * x62 + (uint128_t) x98 * x61 + (uint128_t) x96 * x59;
- uint128_t x100 = (uint128_t) x94 * x61 + (uint128_t) x98 * x60 + (uint128_t) x59 * x59 * 0x13;
- uint128_t x101 = (uint128_t) x94 * x60 + (uint128_t) x61 * x61 + (uint128_t) x98 * x59;
- uint128_t x102 = (uint128_t) x94 * x59 + (uint128_t) x95 * x60 + (uint128_t) x58 * x97;
- uint128_t x103 = (uint128_t) x94 * x58 + (uint128_t) x95 * x59 + (uint128_t) x60 * x60;
- uint64_t x104 = (uint64_t) (x99 >> 0x33);
- uint64_t x105 = (uint64_t) x99 & 0x7ffffffffffff;
- uint128_t x106 = x104 + x100;
- uint64_t x107 = (uint64_t) (x106 >> 0x33);
- uint64_t x108 = (uint64_t) x106 & 0x7ffffffffffff;
- uint128_t x109 = x107 + x101;
- uint64_t x110 = (uint64_t) (x109 >> 0x33);
- uint64_t x111 = (uint64_t) x109 & 0x7ffffffffffff;
- uint128_t x112 = x110 + x102;
- uint64_t x113 = (uint64_t) (x112 >> 0x33);
- uint64_t x114 = (uint64_t) x112 & 0x7ffffffffffff;
- uint128_t x115 = x113 + x103;
- uint64_t x116 = (uint64_t) (x115 >> 0x33);
- uint64_t x117 = (uint64_t) x115 & 0x7ffffffffffff;
- uint64_t x118 = x105 + 0x13 * x116;
- uint64_t x119 = x118 >> 0x33;
- uint64_t x120 = x118 & 0x7ffffffffffff;
- uint64_t x121 = x119 + x108;
- uint64_t x122 = x121 >> 0x33;
- uint64_t x123 = x121 & 0x7ffffffffffff;
- uint64_t x124 = x122 + x111;
- uint128_t x125 = (uint128_t) x89 * x120;
- uint128_t x126 = (uint128_t) x89 * x123 + (uint128_t) x92 * x120;
- uint128_t x127 = (uint128_t) x89 * x124 + (uint128_t) x93 * x120 + (uint128_t) x92 * x123;
- uint128_t x128 = (uint128_t) x89 * x114 + (uint128_t) x83 * x120 + (uint128_t) x92 * x124 + (uint128_t) x93 * x123;
- uint128_t x129 = (uint128_t) x89 * x117 + (uint128_t) x86 * x120 + (uint128_t) x83 * x123 + (uint128_t) x92 * x114 + (uint128_t) x93 * x124;
- uint64_t x130 = x86 * 0x13;
- uint64_t x131 = x92 * 0x13;
- uint64_t x132 = x93 * 0x13;
- uint64_t x133 = x83 * 0x13;
- uint128_t x134 = x125 + (uint128_t) x130 * x123 + (uint128_t) x131 * x117 + (uint128_t) x132 * x114 + (uint128_t) x133 * x124;
- uint128_t x135 = x126 + (uint128_t) x130 * x124 + (uint128_t) x132 * x117 + (uint128_t) x133 * x114;
- uint128_t x136 = x127 + (uint128_t) x130 * x114 + (uint128_t) x133 * x117;
- uint128_t x137 = x128 + (uint128_t) x130 * x117;
- uint64_t x138 = (uint64_t) (x134 >> 0x33);
- uint64_t x139 = (uint64_t) x134 & 0x7ffffffffffff;
- uint128_t x140 = x138 + x135;
- uint64_t x141 = (uint64_t) (x140 >> 0x33);
- uint64_t x142 = (uint64_t) x140 & 0x7ffffffffffff;
- uint128_t x143 = x141 + x136;
- uint64_t x144 = (uint64_t) (x143 >> 0x33);
- uint64_t x145 = (uint64_t) x143 & 0x7ffffffffffff;
- uint128_t x146 = x144 + x137;
- uint64_t x147 = (uint64_t) (x146 >> 0x33);
- uint64_t x148 = (uint64_t) x146 & 0x7ffffffffffff;
- uint128_t x149 = x147 + x129;
- uint64_t x150 = (uint64_t) (x149 >> 0x33);
- uint64_t x151 = (uint64_t) x149 & 0x7ffffffffffff;
- uint64_t x152 = x139 + 0x13 * x150;
- uint64_t x153 = x152 >> 0x33;
- uint64_t x154 = x152 & 0x7ffffffffffff;
- uint64_t x155 = x153 + x142;
- uint64_t x156 = x155 >> 0x33;
- uint64_t x157 = x155 & 0x7ffffffffffff;
- uint64_t x158 = x156 + x145;
- uint64_t x159 = 0xffffffffffffe + x86 - x117;
- uint64_t x160 = 0xffffffffffffe + x83 - x114;
- uint64_t x161 = 0xffffffffffffe + x93 - x124;
- uint64_t x162 = 0xffffffffffffe + x92 - x123;
- uint64_t x163 = 0xfffffffffffda + x89 - x120;
- uint128_t x164 = (uint128_t) 0x1db41 * x163;
- uint128_t x165 = (uint128_t) 0x1db41 * x162;
- uint128_t x166 = (uint128_t) 0x1db41 * x161;
- uint128_t x167 = (uint128_t) 0x1db41 * x160;
- uint128_t x168 = (uint128_t) 0x1db41 * x159;
- uint64_t x169 = (uint64_t) (x164 >> 0x33);
- uint64_t x170 = (uint64_t) x164 & 0x7ffffffffffff;
- uint128_t x171 = x169 + x165;
- uint64_t x172 = (uint64_t) (x171 >> 0x33);
- uint64_t x173 = (uint64_t) x171 & 0x7ffffffffffff;
- uint128_t x174 = x172 + x166;
- uint64_t x175 = (uint64_t) (x174 >> 0x33);
- uint64_t x176 = (uint64_t) x174 & 0x7ffffffffffff;
- uint128_t x177 = x175 + x167;
- uint64_t x178 = (uint64_t) (x177 >> 0x33);
- uint64_t x179 = (uint64_t) x177 & 0x7ffffffffffff;
- uint128_t x180 = x178 + x168;
- uint64_t x181 = (uint64_t) (x180 >> 0x33);
- uint64_t x182 = (uint64_t) x180 & 0x7ffffffffffff;
- uint64_t x183 = x170 + 0x13 * x181;
- uint64_t x184 = x183 >> 0x33;
- uint64_t x185 = x183 & 0x7ffffffffffff;
- uint64_t x186 = x184 + x173;
- uint64_t x187 = x186 >> 0x33;
- uint64_t x188 = x186 & 0x7ffffffffffff;
- uint64_t x189 = x187 + x176;
- uint64_t x190 = x86 + x182;
- uint64_t x191 = x83 + x179;
- uint64_t x192 = x93 + x189;
- uint64_t x193 = x92 + x188;
- uint64_t x194 = x89 + x185;
- uint128_t x195 = (uint128_t) x163 * x194;
- uint128_t x196 = (uint128_t) x163 * x193 + (uint128_t) x162 * x194;
- uint128_t x197 = (uint128_t) x163 * x192 + (uint128_t) x161 * x194 + (uint128_t) x162 * x193;
- uint128_t x198 = (uint128_t) x163 * x191 + (uint128_t) x160 * x194 + (uint128_t) x162 * x192 + (uint128_t) x161 * x193;
- uint128_t x199 = (uint128_t) x163 * x190 + (uint128_t) x159 * x194 + (uint128_t) x160 * x193 + (uint128_t) x162 * x191 + (uint128_t) x161 * x192;
- uint64_t x200 = x159 * 0x13;
- uint64_t x201 = x162 * 0x13;
- uint64_t x202 = x161 * 0x13;
- uint64_t x203 = x160 * 0x13;
- uint128_t x204 = x195 + (uint128_t) x200 * x193 + (uint128_t) x201 * x190 + (uint128_t) x202 * x191 + (uint128_t) x203 * x192;
- uint128_t x205 = x196 + (uint128_t) x200 * x192 + (uint128_t) x202 * x190 + (uint128_t) x203 * x191;
- uint128_t x206 = x197 + (uint128_t) x200 * x191 + (uint128_t) x203 * x190;
- uint128_t x207 = x198 + (uint128_t) x200 * x190;
- uint64_t x208 = (uint64_t) (x204 >> 0x33);
- uint64_t x209 = (uint64_t) x204 & 0x7ffffffffffff;
- uint128_t x210 = x208 + x205;
- uint64_t x211 = (uint64_t) (x210 >> 0x33);
- uint64_t x212 = (uint64_t) x210 & 0x7ffffffffffff;
- uint128_t x213 = x211 + x206;
- uint64_t x214 = (uint64_t) (x213 >> 0x33);
- uint64_t x215 = (uint64_t) x213 & 0x7ffffffffffff;
- uint128_t x216 = x214 + x207;
- uint64_t x217 = (uint64_t) (x216 >> 0x33);
- uint64_t x218 = (uint64_t) x216 & 0x7ffffffffffff;
- uint128_t x219 = x217 + x199;
- uint64_t x220 = (uint64_t) (x219 >> 0x33);
- uint64_t x221 = (uint64_t) x219 & 0x7ffffffffffff;
- uint64_t x222 = x209 + 0x13 * x220;
- uint64_t x223 = x222 >> 0x33;
- uint64_t x224 = x222 & 0x7ffffffffffff;
- uint64_t x225 = x223 + x212;
- uint64_t x226 = x225 >> 0x33;
- uint64_t x227 = x225 & 0x7ffffffffffff;
- uint64_t x228 = x226 + x215;
- uint64_t x229 = x43 + x51;
- uint64_t x230 = x44 + x52;
- uint64_t x231 = x42 + x50;
- uint64_t x232 = x40 + x48;
- uint64_t x233 = x38 + x46;
- uint64_t x234 = 0xffffffffffffe + x43 - x51;
- uint64_t x235 = 0xffffffffffffe + x44 - x52;
- uint64_t x236 = 0xffffffffffffe + x42 - x50;
- uint64_t x237 = 0xffffffffffffe + x40 - x48;
- uint64_t x238 = 0xfffffffffffda + x38 - x46;
- uint128_t x239 = (uint128_t) x233 * x62;
- uint128_t x240 = (uint128_t) x233 * x61 + (uint128_t) x232 * x62;
- uint128_t x241 = (uint128_t) x233 * x60 + (uint128_t) x231 * x62 + (uint128_t) x232 * x61;
- uint128_t x242 = (uint128_t) x233 * x59 + (uint128_t) x230 * x62 + (uint128_t) x232 * x60 + (uint128_t) x231 * x61;
- uint128_t x243 = (uint128_t) x233 * x58 + (uint128_t) x229 * x62 + (uint128_t) x230 * x61 + (uint128_t) x232 * x59 + (uint128_t) x231 * x60;
- uint64_t x244 = x229 * 0x13;
- uint64_t x245 = x232 * 0x13;
- uint64_t x246 = x231 * 0x13;
- uint64_t x247 = x230 * 0x13;
- uint128_t x248 = x239 + (uint128_t) x244 * x61 + (uint128_t) x245 * x58 + (uint128_t) x246 * x59 + (uint128_t) x247 * x60;
- uint128_t x249 = x240 + (uint128_t) x244 * x60 + (uint128_t) x246 * x58 + (uint128_t) x247 * x59;
- uint128_t x250 = x241 + (uint128_t) x244 * x59 + (uint128_t) x247 * x58;
- uint128_t x251 = x242 + (uint128_t) x244 * x58;
- uint64_t x252 = (uint64_t) (x248 >> 0x33);
- uint64_t x253 = (uint64_t) x248 & 0x7ffffffffffff;
- uint128_t x254 = x252 + x249;
- uint64_t x255 = (uint64_t) (x254 >> 0x33);
- uint64_t x256 = (uint64_t) x254 & 0x7ffffffffffff;
- uint128_t x257 = x255 + x250;
- uint64_t x258 = (uint64_t) (x257 >> 0x33);
- uint64_t x259 = (uint64_t) x257 & 0x7ffffffffffff;
- uint128_t x260 = x258 + x251;
- uint64_t x261 = (uint64_t) (x260 >> 0x33);
- uint64_t x262 = (uint64_t) x260 & 0x7ffffffffffff;
- uint128_t x263 = x261 + x243;
- uint64_t x264 = (uint64_t) (x263 >> 0x33);
- uint64_t x265 = (uint64_t) x263 & 0x7ffffffffffff;
- uint64_t x266 = x253 + 0x13 * x264;
- uint64_t x267 = x266 >> 0x33;
- uint64_t x268 = x266 & 0x7ffffffffffff;
- uint64_t x269 = x267 + x256;
- uint64_t x270 = x269 >> 0x33;
- uint64_t x271 = x269 & 0x7ffffffffffff;
- uint64_t x272 = x270 + x259;
- uint128_t x273 = (uint128_t) x238 * x57;
- uint128_t x274 = (uint128_t) x238 * x56 + (uint128_t) x237 * x57;
- uint128_t x275 = (uint128_t) x238 * x55 + (uint128_t) x236 * x57 + (uint128_t) x237 * x56;
- uint128_t x276 = (uint128_t) x238 * x54 + (uint128_t) x235 * x57 + (uint128_t) x237 * x55 + (uint128_t) x236 * x56;
- uint128_t x277 = (uint128_t) x238 * x53 + (uint128_t) x234 * x57 + (uint128_t) x235 * x56 + (uint128_t) x237 * x54 + (uint128_t) x236 * x55;
- uint64_t x278 = x234 * 0x13;
- uint64_t x279 = x237 * 0x13;
- uint64_t x280 = x236 * 0x13;
- uint64_t x281 = x235 * 0x13;
- uint128_t x282 = x273 + (uint128_t) x278 * x56 + (uint128_t) x279 * x53 + (uint128_t) x280 * x54 + (uint128_t) x281 * x55;
- uint128_t x283 = x274 + (uint128_t) x278 * x55 + (uint128_t) x280 * x53 + (uint128_t) x281 * x54;
- uint128_t x284 = x275 + (uint128_t) x278 * x54 + (uint128_t) x281 * x53;
- uint128_t x285 = x276 + (uint128_t) x278 * x53;
- uint64_t x286 = (uint64_t) (x282 >> 0x33);
- uint64_t x287 = (uint64_t) x282 & 0x7ffffffffffff;
- uint128_t x288 = x286 + x283;
- uint64_t x289 = (uint64_t) (x288 >> 0x33);
- uint64_t x290 = (uint64_t) x288 & 0x7ffffffffffff;
- uint128_t x291 = x289 + x284;
- uint64_t x292 = (uint64_t) (x291 >> 0x33);
- uint64_t x293 = (uint64_t) x291 & 0x7ffffffffffff;
- uint128_t x294 = x292 + x285;
- uint64_t x295 = (uint64_t) (x294 >> 0x33);
- uint64_t x296 = (uint64_t) x294 & 0x7ffffffffffff;
- uint128_t x297 = x295 + x277;
- uint64_t x298 = (uint64_t) (x297 >> 0x33);
- uint64_t x299 = (uint64_t) x297 & 0x7ffffffffffff;
- uint64_t x300 = x287 + 0x13 * x298;
- uint64_t x301 = x300 >> 0x33;
- uint64_t x302 = x300 & 0x7ffffffffffff;
- uint64_t x303 = x301 + x290;
- uint64_t x304 = x303 >> 0x33;
- uint64_t x305 = x303 & 0x7ffffffffffff;
- uint64_t x306 = x304 + x293;
- uint64_t x307 = x299 + x265;
- uint64_t x308 = x296 + x262;
- uint64_t x309 = x306 + x272;
- uint64_t x310 = x305 + x271;
- uint64_t x311 = x302 + x268;
- uint64_t x312 = x311 * 0x2;
- uint64_t x313 = x310 * 0x2;
- uint64_t x314 = x309 * 0x2 * 0x13;
- uint64_t x315 = x307 * 0x13;
- uint64_t x316 = x315 * 0x2;
- uint128_t x317 = (uint128_t) x311 * x311 + (uint128_t) x316 * x310 + (uint128_t) x314 * x308;
- uint128_t x318 = (uint128_t) x312 * x310 + (uint128_t) x316 * x309 + (uint128_t) x308 * x308 * 0x13;
- uint128_t x319 = (uint128_t) x312 * x309 + (uint128_t) x310 * x310 + (uint128_t) x316 * x308;
- uint128_t x320 = (uint128_t) x312 * x308 + (uint128_t) x313 * x309 + (uint128_t) x307 * x315;
- uint128_t x321 = (uint128_t) x312 * x307 + (uint128_t) x313 * x308 + (uint128_t) x309 * x309;
- uint64_t x322 = (uint64_t) (x317 >> 0x33);
- uint64_t x323 = (uint64_t) x317 & 0x7ffffffffffff;
- uint128_t x324 = x322 + x318;
+ uint64_t x63 = x43 + x51;
+ uint64_t x64 = x44 + x52;
+ uint64_t x65 = x42 + x50;
+ uint64_t x66 = x40 + x48;
+ uint64_t x67 = x38 + x46;
+ uint64_t x68 = 0xffffffffffffe + x43 - x51;
+ uint64_t x69 = 0xffffffffffffe + x44 - x52;
+ uint64_t x70 = 0xffffffffffffe + x42 - x50;
+ uint64_t x71 = 0xffffffffffffe + x40 - x48;
+ uint64_t x72 = 0xfffffffffffda + x38 - x46;
+ uint128_t x73 = (uint128_t) x67 * x62;
+ uint128_t x74 = (uint128_t) x67 * x61 + (uint128_t) x66 * x62;
+ uint128_t x75 = (uint128_t) x67 * x60 + (uint128_t) x65 * x62 + (uint128_t) x66 * x61;
+ uint128_t x76 = (uint128_t) x67 * x59 + (uint128_t) x64 * x62 + (uint128_t) x66 * x60 + (uint128_t) x65 * x61;
+ uint128_t x77 = (uint128_t) x67 * x58 + (uint128_t) x63 * x62 + (uint128_t) x64 * x61 + (uint128_t) x66 * x59 + (uint128_t) x65 * x60;
+ uint64_t x78 = x63 * 0x13;
+ uint64_t x79 = x66 * 0x13;
+ uint64_t x80 = x65 * 0x13;
+ uint64_t x81 = x64 * 0x13;
+ uint128_t x82 = x73 + (uint128_t) x78 * x61 + (uint128_t) x79 * x58 + (uint128_t) x80 * x59 + (uint128_t) x81 * x60;
+ uint128_t x83 = x74 + (uint128_t) x78 * x60 + (uint128_t) x80 * x58 + (uint128_t) x81 * x59;
+ uint128_t x84 = x75 + (uint128_t) x78 * x59 + (uint128_t) x81 * x58;
+ uint128_t x85 = x76 + (uint128_t) x78 * x58;
+ uint64_t x86 = (uint64_t) (x82 >> 0x33);
+ uint64_t x87 = (uint64_t) x82 & 0x7ffffffffffff;
+ uint128_t x88 = x86 + x83;
+ uint64_t x89 = (uint64_t) (x88 >> 0x33);
+ uint64_t x90 = (uint64_t) x88 & 0x7ffffffffffff;
+ uint128_t x91 = x89 + x84;
+ uint64_t x92 = (uint64_t) (x91 >> 0x33);
+ uint64_t x93 = (uint64_t) x91 & 0x7ffffffffffff;
+ uint128_t x94 = x92 + x85;
+ uint64_t x95 = (uint64_t) (x94 >> 0x33);
+ uint64_t x96 = (uint64_t) x94 & 0x7ffffffffffff;
+ uint128_t x97 = x95 + x77;
+ uint64_t x98 = (uint64_t) (x97 >> 0x33);
+ uint64_t x99 = (uint64_t) x97 & 0x7ffffffffffff;
+ uint64_t x100 = x87 + 0x13 * x98;
+ uint64_t x101 = x100 >> 0x33;
+ uint64_t x102 = x100 & 0x7ffffffffffff;
+ uint64_t x103 = x101 + x90;
+ uint64_t x104 = x103 >> 0x33;
+ uint64_t x105 = x103 & 0x7ffffffffffff;
+ uint64_t x106 = x104 + x93;
+ uint128_t x107 = (uint128_t) x57 * x72;
+ uint128_t x108 = (uint128_t) x57 * x71 + (uint128_t) x56 * x72;
+ uint128_t x109 = (uint128_t) x57 * x70 + (uint128_t) x55 * x72 + (uint128_t) x56 * x71;
+ uint128_t x110 = (uint128_t) x57 * x69 + (uint128_t) x54 * x72 + (uint128_t) x56 * x70 + (uint128_t) x55 * x71;
+ uint128_t x111 = (uint128_t) x57 * x68 + (uint128_t) x53 * x72 + (uint128_t) x54 * x71 + (uint128_t) x56 * x69 + (uint128_t) x55 * x70;
+ uint64_t x112 = x53 * 0x13;
+ uint64_t x113 = x56 * 0x13;
+ uint64_t x114 = x55 * 0x13;
+ uint64_t x115 = x54 * 0x13;
+ uint128_t x116 = x107 + (uint128_t) x112 * x71 + (uint128_t) x113 * x68 + (uint128_t) x114 * x69 + (uint128_t) x115 * x70;
+ uint128_t x117 = x108 + (uint128_t) x112 * x70 + (uint128_t) x114 * x68 + (uint128_t) x115 * x69;
+ uint128_t x118 = x109 + (uint128_t) x112 * x69 + (uint128_t) x115 * x68;
+ uint128_t x119 = x110 + (uint128_t) x112 * x68;
+ uint64_t x120 = (uint64_t) (x116 >> 0x33);
+ uint64_t x121 = (uint64_t) x116 & 0x7ffffffffffff;
+ uint128_t x122 = x120 + x117;
+ uint64_t x123 = (uint64_t) (x122 >> 0x33);
+ uint64_t x124 = (uint64_t) x122 & 0x7ffffffffffff;
+ uint128_t x125 = x123 + x118;
+ uint64_t x126 = (uint64_t) (x125 >> 0x33);
+ uint64_t x127 = (uint64_t) x125 & 0x7ffffffffffff;
+ uint128_t x128 = x126 + x119;
+ uint64_t x129 = (uint64_t) (x128 >> 0x33);
+ uint64_t x130 = (uint64_t) x128 & 0x7ffffffffffff;
+ uint128_t x131 = x129 + x111;
+ uint64_t x132 = (uint64_t) (x131 >> 0x33);
+ uint64_t x133 = (uint64_t) x131 & 0x7ffffffffffff;
+ uint64_t x134 = x121 + 0x13 * x132;
+ uint64_t x135 = x134 >> 0x33;
+ uint64_t x136 = x134 & 0x7ffffffffffff;
+ uint64_t x137 = x135 + x124;
+ uint64_t x138 = x137 >> 0x33;
+ uint64_t x139 = x137 & 0x7ffffffffffff;
+ uint64_t x140 = x138 + x127;
+ uint64_t x141 = x99 + x133;
+ uint64_t x142 = x96 + x130;
+ uint64_t x143 = x106 + x140;
+ uint64_t x144 = x105 + x139;
+ uint64_t x145 = x102 + x136;
+ uint64_t x146 = 0xffffffffffffe + x99 - x133;
+ uint64_t x147 = 0xffffffffffffe + x96 - x130;
+ uint64_t x148 = 0xffffffffffffe + x106 - x140;
+ uint64_t x149 = 0xffffffffffffe + x105 - x139;
+ uint64_t x150 = 0xfffffffffffda + x102 - x136;
+ uint64_t x151 = x145 * 0x2;
+ uint64_t x152 = x144 * 0x2;
+ uint64_t x153 = x143 * 0x2 * 0x13;
+ uint64_t x154 = x141 * 0x13;
+ uint64_t x155 = x154 * 0x2;
+ uint128_t x156 = (uint128_t) x145 * x145 + (uint128_t) x155 * x144 + (uint128_t) x153 * x142;
+ uint128_t x157 = (uint128_t) x151 * x144 + (uint128_t) x155 * x143 + (uint128_t) x142 * x142 * 0x13;
+ uint128_t x158 = (uint128_t) x151 * x143 + (uint128_t) x144 * x144 + (uint128_t) x155 * x142;
+ uint128_t x159 = (uint128_t) x151 * x142 + (uint128_t) x152 * x143 + (uint128_t) x141 * x154;
+ uint128_t x160 = (uint128_t) x151 * x141 + (uint128_t) x152 * x142 + (uint128_t) x143 * x143;
+ uint64_t x161 = (uint64_t) (x156 >> 0x33);
+ uint64_t x162 = (uint64_t) x156 & 0x7ffffffffffff;
+ uint128_t x163 = x161 + x157;
+ uint64_t x164 = (uint64_t) (x163 >> 0x33);
+ uint64_t x165 = (uint64_t) x163 & 0x7ffffffffffff;
+ uint128_t x166 = x164 + x158;
+ uint64_t x167 = (uint64_t) (x166 >> 0x33);
+ uint64_t x168 = (uint64_t) x166 & 0x7ffffffffffff;
+ uint128_t x169 = x167 + x159;
+ uint64_t x170 = (uint64_t) (x169 >> 0x33);
+ uint64_t x171 = (uint64_t) x169 & 0x7ffffffffffff;
+ uint128_t x172 = x170 + x160;
+ uint64_t x173 = (uint64_t) (x172 >> 0x33);
+ uint64_t x174 = (uint64_t) x172 & 0x7ffffffffffff;
+ uint64_t x175 = x162 + 0x13 * x173;
+ uint64_t x176 = x175 >> 0x33;
+ uint64_t x177 = x175 & 0x7ffffffffffff;
+ uint64_t x178 = x176 + x165;
+ uint64_t x179 = x178 >> 0x33;
+ uint64_t x180 = x178 & 0x7ffffffffffff;
+ uint64_t x181 = x179 + x168;
+ uint64_t x182 = x150 * 0x2;
+ uint64_t x183 = x149 * 0x2;
+ uint64_t x184 = x148 * 0x2 * 0x13;
+ uint64_t x185 = x146 * 0x13;
+ uint64_t x186 = x185 * 0x2;
+ uint128_t x187 = (uint128_t) x150 * x150 + (uint128_t) x186 * x149 + (uint128_t) x184 * x147;
+ uint128_t x188 = (uint128_t) x182 * x149 + (uint128_t) x186 * x148 + (uint128_t) x147 * x147 * 0x13;
+ uint128_t x189 = (uint128_t) x182 * x148 + (uint128_t) x149 * x149 + (uint128_t) x186 * x147;
+ uint128_t x190 = (uint128_t) x182 * x147 + (uint128_t) x183 * x148 + (uint128_t) x146 * x185;
+ uint128_t x191 = (uint128_t) x182 * x146 + (uint128_t) x183 * x147 + (uint128_t) x148 * x148;
+ uint64_t x192 = (uint64_t) (x187 >> 0x33);
+ uint64_t x193 = (uint64_t) x187 & 0x7ffffffffffff;
+ uint128_t x194 = x192 + x188;
+ uint64_t x195 = (uint64_t) (x194 >> 0x33);
+ uint64_t x196 = (uint64_t) x194 & 0x7ffffffffffff;
+ uint128_t x197 = x195 + x189;
+ uint64_t x198 = (uint64_t) (x197 >> 0x33);
+ uint64_t x199 = (uint64_t) x197 & 0x7ffffffffffff;
+ uint128_t x200 = x198 + x190;
+ uint64_t x201 = (uint64_t) (x200 >> 0x33);
+ uint64_t x202 = (uint64_t) x200 & 0x7ffffffffffff;
+ uint128_t x203 = x201 + x191;
+ uint64_t x204 = (uint64_t) (x203 >> 0x33);
+ uint64_t x205 = (uint64_t) x203 & 0x7ffffffffffff;
+ uint64_t x206 = x193 + 0x13 * x204;
+ uint64_t x207 = x206 >> 0x33;
+ uint64_t x208 = x206 & 0x7ffffffffffff;
+ uint64_t x209 = x207 + x196;
+ uint64_t x210 = x209 >> 0x33;
+ uint64_t x211 = x209 & 0x7ffffffffffff;
+ uint64_t x212 = x210 + x199;
+ uint128_t x213 = (uint128_t) x208 * x10;
+ uint128_t x214 = (uint128_t) x208 * x12 + (uint128_t) x211 * x10;
+ uint128_t x215 = (uint128_t) x208 * x14 + (uint128_t) x212 * x10 + (uint128_t) x211 * x12;
+ uint128_t x216 = (uint128_t) x208 * x16 + (uint128_t) x202 * x10 + (uint128_t) x211 * x14 + (uint128_t) x212 * x12;
+ uint128_t x217 = (uint128_t) x208 * x15 + (uint128_t) x205 * x10 + (uint128_t) x202 * x12 + (uint128_t) x211 * x16 + (uint128_t) x212 * x14;
+ uint64_t x218 = x205 * 0x13;
+ uint64_t x219 = x211 * 0x13;
+ uint64_t x220 = x212 * 0x13;
+ uint64_t x221 = x202 * 0x13;
+ uint128_t x222 = x213 + (uint128_t) x218 * x12 + (uint128_t) x219 * x15 + (uint128_t) x220 * x16 + (uint128_t) x221 * x14;
+ uint128_t x223 = x214 + (uint128_t) x218 * x14 + (uint128_t) x220 * x15 + (uint128_t) x221 * x16;
+ uint128_t x224 = x215 + (uint128_t) x218 * x16 + (uint128_t) x221 * x15;
+ uint128_t x225 = x216 + (uint128_t) x218 * x15;
+ uint64_t x226 = (uint64_t) (x222 >> 0x33);
+ uint64_t x227 = (uint64_t) x222 & 0x7ffffffffffff;
+ uint128_t x228 = x226 + x223;
+ uint64_t x229 = (uint64_t) (x228 >> 0x33);
+ uint64_t x230 = (uint64_t) x228 & 0x7ffffffffffff;
+ uint128_t x231 = x229 + x224;
+ uint64_t x232 = (uint64_t) (x231 >> 0x33);
+ uint64_t x233 = (uint64_t) x231 & 0x7ffffffffffff;
+ uint128_t x234 = x232 + x225;
+ uint64_t x235 = (uint64_t) (x234 >> 0x33);
+ uint64_t x236 = (uint64_t) x234 & 0x7ffffffffffff;
+ uint128_t x237 = x235 + x217;
+ uint64_t x238 = (uint64_t) (x237 >> 0x33);
+ uint64_t x239 = (uint64_t) x237 & 0x7ffffffffffff;
+ uint64_t x240 = x227 + 0x13 * x238;
+ uint64_t x241 = x240 >> 0x33;
+ uint64_t x242 = x240 & 0x7ffffffffffff;
+ uint64_t x243 = x241 + x230;
+ uint64_t x244 = x243 >> 0x33;
+ uint64_t x245 = x243 & 0x7ffffffffffff;
+ uint64_t x246 = x244 + x233;
+ uint64_t x247 = x57 * 0x2;
+ uint64_t x248 = x56 * 0x2;
+ uint64_t x249 = x55 * 0x2 * 0x13;
+ uint64_t x250 = x53 * 0x13;
+ uint64_t x251 = x250 * 0x2;
+ uint128_t x252 = (uint128_t) x57 * x57 + (uint128_t) x251 * x56 + (uint128_t) x249 * x54;
+ uint128_t x253 = (uint128_t) x247 * x56 + (uint128_t) x251 * x55 + (uint128_t) x54 * x54 * 0x13;
+ uint128_t x254 = (uint128_t) x247 * x55 + (uint128_t) x56 * x56 + (uint128_t) x251 * x54;
+ uint128_t x255 = (uint128_t) x247 * x54 + (uint128_t) x248 * x55 + (uint128_t) x53 * x250;
+ uint128_t x256 = (uint128_t) x247 * x53 + (uint128_t) x248 * x54 + (uint128_t) x55 * x55;
+ uint64_t x257 = (uint64_t) (x252 >> 0x33);
+ uint64_t x258 = (uint64_t) x252 & 0x7ffffffffffff;
+ uint128_t x259 = x257 + x253;
+ uint64_t x260 = (uint64_t) (x259 >> 0x33);
+ uint64_t x261 = (uint64_t) x259 & 0x7ffffffffffff;
+ uint128_t x262 = x260 + x254;
+ uint64_t x263 = (uint64_t) (x262 >> 0x33);
+ uint64_t x264 = (uint64_t) x262 & 0x7ffffffffffff;
+ uint128_t x265 = x263 + x255;
+ uint64_t x266 = (uint64_t) (x265 >> 0x33);
+ uint64_t x267 = (uint64_t) x265 & 0x7ffffffffffff;
+ uint128_t x268 = x266 + x256;
+ uint64_t x269 = (uint64_t) (x268 >> 0x33);
+ uint64_t x270 = (uint64_t) x268 & 0x7ffffffffffff;
+ uint64_t x271 = x258 + 0x13 * x269;
+ uint64_t x272 = x271 >> 0x33;
+ uint64_t x273 = x271 & 0x7ffffffffffff;
+ uint64_t x274 = x272 + x261;
+ uint64_t x275 = x274 >> 0x33;
+ uint64_t x276 = x274 & 0x7ffffffffffff;
+ uint64_t x277 = x275 + x264;
+ uint64_t x278 = x62 * 0x2;
+ uint64_t x279 = x61 * 0x2;
+ uint64_t x280 = x60 * 0x2 * 0x13;
+ uint64_t x281 = x58 * 0x13;
+ uint64_t x282 = x281 * 0x2;
+ uint128_t x283 = (uint128_t) x62 * x62 + (uint128_t) x282 * x61 + (uint128_t) x280 * x59;
+ uint128_t x284 = (uint128_t) x278 * x61 + (uint128_t) x282 * x60 + (uint128_t) x59 * x59 * 0x13;
+ uint128_t x285 = (uint128_t) x278 * x60 + (uint128_t) x61 * x61 + (uint128_t) x282 * x59;
+ uint128_t x286 = (uint128_t) x278 * x59 + (uint128_t) x279 * x60 + (uint128_t) x58 * x281;
+ uint128_t x287 = (uint128_t) x278 * x58 + (uint128_t) x279 * x59 + (uint128_t) x60 * x60;
+ uint64_t x288 = (uint64_t) (x283 >> 0x33);
+ uint64_t x289 = (uint64_t) x283 & 0x7ffffffffffff;
+ uint128_t x290 = x288 + x284;
+ uint64_t x291 = (uint64_t) (x290 >> 0x33);
+ uint64_t x292 = (uint64_t) x290 & 0x7ffffffffffff;
+ uint128_t x293 = x291 + x285;
+ uint64_t x294 = (uint64_t) (x293 >> 0x33);
+ uint64_t x295 = (uint64_t) x293 & 0x7ffffffffffff;
+ uint128_t x296 = x294 + x286;
+ uint64_t x297 = (uint64_t) (x296 >> 0x33);
+ uint64_t x298 = (uint64_t) x296 & 0x7ffffffffffff;
+ uint128_t x299 = x297 + x287;
+ uint64_t x300 = (uint64_t) (x299 >> 0x33);
+ uint64_t x301 = (uint64_t) x299 & 0x7ffffffffffff;
+ uint64_t x302 = x289 + 0x13 * x300;
+ uint64_t x303 = x302 >> 0x33;
+ uint64_t x304 = x302 & 0x7ffffffffffff;
+ uint64_t x305 = x303 + x292;
+ uint64_t x306 = x305 >> 0x33;
+ uint64_t x307 = x305 & 0x7ffffffffffff;
+ uint64_t x308 = x306 + x295;
+ uint128_t x309 = (uint128_t) x273 * x304;
+ uint128_t x310 = (uint128_t) x273 * x307 + (uint128_t) x276 * x304;
+ uint128_t x311 = (uint128_t) x273 * x308 + (uint128_t) x277 * x304 + (uint128_t) x276 * x307;
+ uint128_t x312 = (uint128_t) x273 * x298 + (uint128_t) x267 * x304 + (uint128_t) x276 * x308 + (uint128_t) x277 * x307;
+ uint128_t x313 = (uint128_t) x273 * x301 + (uint128_t) x270 * x304 + (uint128_t) x267 * x307 + (uint128_t) x276 * x298 + (uint128_t) x277 * x308;
+ uint64_t x314 = x270 * 0x13;
+ uint64_t x315 = x276 * 0x13;
+ uint64_t x316 = x277 * 0x13;
+ uint64_t x317 = x267 * 0x13;
+ uint128_t x318 = x309 + (uint128_t) x314 * x307 + (uint128_t) x315 * x301 + (uint128_t) x316 * x298 + (uint128_t) x317 * x308;
+ uint128_t x319 = x310 + (uint128_t) x314 * x308 + (uint128_t) x316 * x301 + (uint128_t) x317 * x298;
+ uint128_t x320 = x311 + (uint128_t) x314 * x298 + (uint128_t) x317 * x301;
+ uint128_t x321 = x312 + (uint128_t) x314 * x301;
+ uint64_t x322 = (uint64_t) (x318 >> 0x33);
+ uint64_t x323 = (uint64_t) x318 & 0x7ffffffffffff;
+ uint128_t x324 = x322 + x319;
uint64_t x325 = (uint64_t) (x324 >> 0x33);
uint64_t x326 = (uint64_t) x324 & 0x7ffffffffffff;
- uint128_t x327 = x325 + x319;
+ uint128_t x327 = x325 + x320;
uint64_t x328 = (uint64_t) (x327 >> 0x33);
uint64_t x329 = (uint64_t) x327 & 0x7ffffffffffff;
- uint128_t x330 = x328 + x320;
+ uint128_t x330 = x328 + x321;
uint64_t x331 = (uint64_t) (x330 >> 0x33);
uint64_t x332 = (uint64_t) x330 & 0x7ffffffffffff;
- uint128_t x333 = x331 + x321;
+ uint128_t x333 = x331 + x313;
uint64_t x334 = (uint64_t) (x333 >> 0x33);
uint64_t x335 = (uint64_t) x333 & 0x7ffffffffffff;
uint64_t x336 = x323 + 0x13 * x334;
@@ -292,77 +292,81 @@ let (a, b) := Interp-η
uint64_t x340 = x339 >> 0x33;
uint64_t x341 = x339 & 0x7ffffffffffff;
uint64_t x342 = x340 + x329;
- uint64_t x343 = 0xffffffffffffe + x299 - x265;
- uint64_t x344 = 0xffffffffffffe + x296 - x262;
- uint64_t x345 = 0xffffffffffffe + x306 - x272;
- uint64_t x346 = 0xffffffffffffe + x305 - x271;
- uint64_t x347 = 0xfffffffffffda + x302 - x268;
- uint64_t x348 = x347 * 0x2;
- uint64_t x349 = x346 * 0x2;
- uint64_t x350 = x345 * 0x2 * 0x13;
- uint64_t x351 = x343 * 0x13;
- uint64_t x352 = x351 * 0x2;
- uint128_t x353 = (uint128_t) x347 * x347 + (uint128_t) x352 * x346 + (uint128_t) x350 * x344;
- uint128_t x354 = (uint128_t) x348 * x346 + (uint128_t) x352 * x345 + (uint128_t) x344 * x344 * 0x13;
- uint128_t x355 = (uint128_t) x348 * x345 + (uint128_t) x346 * x346 + (uint128_t) x352 * x344;
- uint128_t x356 = (uint128_t) x348 * x344 + (uint128_t) x349 * x345 + (uint128_t) x343 * x351;
- uint128_t x357 = (uint128_t) x348 * x343 + (uint128_t) x349 * x344 + (uint128_t) x345 * x345;
- uint64_t x358 = (uint64_t) (x353 >> 0x33);
- uint64_t x359 = (uint64_t) x353 & 0x7ffffffffffff;
- uint128_t x360 = x358 + x354;
- uint64_t x361 = (uint64_t) (x360 >> 0x33);
- uint64_t x362 = (uint64_t) x360 & 0x7ffffffffffff;
- uint128_t x363 = x361 + x355;
- uint64_t x364 = (uint64_t) (x363 >> 0x33);
- uint64_t x365 = (uint64_t) x363 & 0x7ffffffffffff;
- uint128_t x366 = x364 + x356;
- uint64_t x367 = (uint64_t) (x366 >> 0x33);
- uint64_t x368 = (uint64_t) x366 & 0x7ffffffffffff;
- uint128_t x369 = x367 + x357;
- uint64_t x370 = (uint64_t) (x369 >> 0x33);
- uint64_t x371 = (uint64_t) x369 & 0x7ffffffffffff;
- uint64_t x372 = x359 + 0x13 * x370;
- uint64_t x373 = x372 >> 0x33;
- uint64_t x374 = x372 & 0x7ffffffffffff;
- uint64_t x375 = x373 + x362;
- uint64_t x376 = x375 >> 0x33;
- uint64_t x377 = x375 & 0x7ffffffffffff;
- uint64_t x378 = x376 + x365;
- uint128_t x379 = (uint128_t) x10 * x374;
- uint128_t x380 = (uint128_t) x10 * x377 + (uint128_t) x12 * x374;
- uint128_t x381 = (uint128_t) x10 * x378 + (uint128_t) x14 * x374 + (uint128_t) x12 * x377;
- uint128_t x382 = (uint128_t) x10 * x368 + (uint128_t) x16 * x374 + (uint128_t) x12 * x378 + (uint128_t) x14 * x377;
- uint128_t x383 = (uint128_t) x10 * x371 + (uint128_t) x15 * x374 + (uint128_t) x16 * x377 + (uint128_t) x12 * x368 + (uint128_t) x14 * x378;
- uint64_t x384 = x15 * 0x13;
- uint64_t x385 = x12 * 0x13;
- uint64_t x386 = x14 * 0x13;
- uint64_t x387 = x16 * 0x13;
- uint128_t x388 = x379 + (uint128_t) x384 * x377 + (uint128_t) x385 * x371 + (uint128_t) x386 * x368 + (uint128_t) x387 * x378;
- uint128_t x389 = x380 + (uint128_t) x384 * x378 + (uint128_t) x386 * x371 + (uint128_t) x387 * x368;
- uint128_t x390 = x381 + (uint128_t) x384 * x368 + (uint128_t) x387 * x371;
- uint128_t x391 = x382 + (uint128_t) x384 * x371;
- uint64_t x392 = (uint64_t) (x388 >> 0x33);
- uint64_t x393 = (uint64_t) x388 & 0x7ffffffffffff;
- uint128_t x394 = x392 + x389;
- uint64_t x395 = (uint64_t) (x394 >> 0x33);
- uint64_t x396 = (uint64_t) x394 & 0x7ffffffffffff;
- uint128_t x397 = x395 + x390;
- uint64_t x398 = (uint64_t) (x397 >> 0x33);
- uint64_t x399 = (uint64_t) x397 & 0x7ffffffffffff;
- uint128_t x400 = x398 + x391;
- uint64_t x401 = (uint64_t) (x400 >> 0x33);
- uint64_t x402 = (uint64_t) x400 & 0x7ffffffffffff;
- uint128_t x403 = x401 + x383;
- uint64_t x404 = (uint64_t) (x403 >> 0x33);
- uint64_t x405 = (uint64_t) x403 & 0x7ffffffffffff;
- uint64_t x406 = x393 + 0x13 * x404;
- uint64_t x407 = x406 >> 0x33;
- uint64_t x408 = x406 & 0x7ffffffffffff;
- uint64_t x409 = x407 + x396;
- uint64_t x410 = x409 >> 0x33;
- uint64_t x411 = x409 & 0x7ffffffffffff;
- uint64_t x412 = x410 + x399;
- return (Return x151, Return x148, Return x158, Return x157, Return x154, (Return x221, Return x218, Return x228, Return x227, Return x224), (Return x335, Return x332, Return x342, Return x341, Return x338, (Return x405, Return x402, Return x412, Return x411, Return x408))))
+ uint64_t x343 = 0xffffffffffffe + x270 - x301;
+ uint64_t x344 = 0xffffffffffffe + x267 - x298;
+ uint64_t x345 = 0xffffffffffffe + x277 - x308;
+ uint64_t x346 = 0xffffffffffffe + x276 - x307;
+ uint64_t x347 = 0xfffffffffffda + x273 - x304;
+ uint128_t x348 = (uint128_t) x347 * 0x1db41;
+ uint128_t x349 = (uint128_t) x346 * 0x1db41;
+ uint128_t x350 = (uint128_t) x345 * 0x1db41;
+ uint128_t x351 = (uint128_t) x344 * 0x1db41;
+ uint128_t x352 = (uint128_t) x343 * 0x1db41;
+ uint64_t _ = x343 * 0x13;
+ uint64_t _ = x346 * 0x13;
+ uint64_t _ = x345 * 0x13;
+ uint64_t _ = x344 * 0x13;
+ uint64_t x357 = (uint64_t) (x348 >> 0x33);
+ uint64_t x358 = (uint64_t) x348 & 0x7ffffffffffff;
+ uint128_t x359 = x357 + x349;
+ uint64_t x360 = (uint64_t) (x359 >> 0x33);
+ uint64_t x361 = (uint64_t) x359 & 0x7ffffffffffff;
+ uint128_t x362 = x360 + x350;
+ uint64_t x363 = (uint64_t) (x362 >> 0x33);
+ uint64_t x364 = (uint64_t) x362 & 0x7ffffffffffff;
+ uint128_t x365 = x363 + x351;
+ uint64_t x366 = (uint64_t) (x365 >> 0x33);
+ uint64_t x367 = (uint64_t) x365 & 0x7ffffffffffff;
+ uint128_t x368 = x366 + x352;
+ uint64_t x369 = (uint64_t) (x368 >> 0x33);
+ uint64_t x370 = (uint64_t) x368 & 0x7ffffffffffff;
+ uint64_t x371 = x358 + 0x13 * x369;
+ uint64_t x372 = x371 >> 0x33;
+ uint64_t x373 = x371 & 0x7ffffffffffff;
+ uint64_t x374 = x372 + x361;
+ uint64_t x375 = x374 >> 0x33;
+ uint64_t x376 = x374 & 0x7ffffffffffff;
+ uint64_t x377 = x375 + x364;
+ uint64_t x378 = x370 + x270;
+ uint64_t x379 = x367 + x267;
+ uint64_t x380 = x377 + x277;
+ uint64_t x381 = x376 + x276;
+ uint64_t x382 = x373 + x273;
+ uint128_t x383 = (uint128_t) x347 * x382;
+ uint128_t x384 = (uint128_t) x347 * x381 + (uint128_t) x346 * x382;
+ uint128_t x385 = (uint128_t) x347 * x380 + (uint128_t) x345 * x382 + (uint128_t) x346 * x381;
+ uint128_t x386 = (uint128_t) x347 * x379 + (uint128_t) x344 * x382 + (uint128_t) x346 * x380 + (uint128_t) x345 * x381;
+ uint128_t x387 = (uint128_t) x347 * x378 + (uint128_t) x343 * x382 + (uint128_t) x344 * x381 + (uint128_t) x346 * x379 + (uint128_t) x345 * x380;
+ uint64_t x388 = x343 * 0x13;
+ uint64_t x389 = x346 * 0x13;
+ uint64_t x390 = x345 * 0x13;
+ uint64_t x391 = x344 * 0x13;
+ uint128_t x392 = x383 + (uint128_t) x388 * x381 + (uint128_t) x389 * x378 + (uint128_t) x390 * x379 + (uint128_t) x391 * x380;
+ uint128_t x393 = x384 + (uint128_t) x388 * x380 + (uint128_t) x390 * x378 + (uint128_t) x391 * x379;
+ uint128_t x394 = x385 + (uint128_t) x388 * x379 + (uint128_t) x391 * x378;
+ uint128_t x395 = x386 + (uint128_t) x388 * x378;
+ uint64_t x396 = (uint64_t) (x392 >> 0x33);
+ uint64_t x397 = (uint64_t) x392 & 0x7ffffffffffff;
+ uint128_t x398 = x396 + x393;
+ uint64_t x399 = (uint64_t) (x398 >> 0x33);
+ uint64_t x400 = (uint64_t) x398 & 0x7ffffffffffff;
+ uint128_t x401 = x399 + x394;
+ uint64_t x402 = (uint64_t) (x401 >> 0x33);
+ uint64_t x403 = (uint64_t) x401 & 0x7ffffffffffff;
+ uint128_t x404 = x402 + x395;
+ uint64_t x405 = (uint64_t) (x404 >> 0x33);
+ uint64_t x406 = (uint64_t) x404 & 0x7ffffffffffff;
+ uint128_t x407 = x405 + x387;
+ uint64_t x408 = (uint64_t) (x407 >> 0x33);
+ uint64_t x409 = (uint64_t) x407 & 0x7ffffffffffff;
+ uint64_t x410 = x397 + 0x13 * x408;
+ uint64_t x411 = x410 >> 0x33;
+ uint64_t x412 = x410 & 0x7ffffffffffff;
+ uint64_t x413 = x411 + x400;
+ uint64_t x414 = x413 >> 0x33;
+ uint64_t x415 = x413 & 0x7ffffffffffff;
+ uint64_t x416 = x414 + x403;
+ return (Return x335, Return x332, Return x342, Return x341, Return x338, (Return x409, Return x406, Return x416, Return x415, Return x412), (Return x174, Return x171, Return x181, Return x180, Return x177, (Return x239, Return x236, Return x246, Return x245, Return x242))))
(x, (x0, x1), (x2, x3))%core in
(let (a0, b0) := a in
(a0, b0), let (a0, b0) := b in