1#![allow(unused_parens)]
16#![allow(non_camel_case_types)]
17
18struct IndexConst<T: ?Sized>(T);
22
23impl<'a, T, const N: usize> IndexConst<&'a [T; N]> {
24 #[inline(always)]
25 #[allow(unused)]
26 const fn index(self, i: usize) -> &'a T {
27 &self.0[i]
28 }
29}
30impl<'a, 'b, T, const N: usize> IndexConst<&'a mut &'b mut [T; N]> {
31 #[inline(always)]
32 #[allow(unused)]
33 const fn index_mut(self, i: usize) -> &'a mut T {
34 &mut self.0[i]
35 }
36}
37
38pub type fiat_p521_u1 = u8;
40pub type fiat_p521_i1 = i8;
42pub type fiat_p521_u2 = u8;
44pub type fiat_p521_i2 = i8;
46
47#[derive(Clone, Copy)]
50pub struct fiat_p521_loose_field_element(pub [u64; 9]);
51
52impl core::ops::Index<usize> for fiat_p521_loose_field_element {
53 type Output = u64;
54 #[inline]
55 fn index(&self, index: usize) -> &Self::Output {
56 &self.0[index]
57 }
58}
59
60impl core::ops::IndexMut<usize> for fiat_p521_loose_field_element {
61 #[inline]
62 fn index_mut(&mut self, index: usize) -> &mut Self::Output {
63 &mut self.0[index]
64 }
65}
66
67impl<'a> IndexConst<&'a fiat_p521_loose_field_element> {
68 #[allow(unused)]
69 #[inline(always)]
70 const fn index(self, i: usize) -> &'a u64 {
71 &self.0.0[i]
72 }
73}
74
75impl<'a, 'b> IndexConst<&'a mut &'b mut fiat_p521_loose_field_element> {
76 #[allow(unused)]
77 #[inline(always)]
78 const fn index_mut(self, i: usize) -> &'a mut u64 {
79 &mut self.0.0[i]
80 }
81}
82
83#[derive(Clone, Copy)]
86pub struct fiat_p521_tight_field_element(pub [u64; 9]);
87
88impl core::ops::Index<usize> for fiat_p521_tight_field_element {
89 type Output = u64;
90 #[inline]
91 fn index(&self, index: usize) -> &Self::Output {
92 &self.0[index]
93 }
94}
95
96impl core::ops::IndexMut<usize> for fiat_p521_tight_field_element {
97 #[inline]
98 fn index_mut(&mut self, index: usize) -> &mut Self::Output {
99 &mut self.0[index]
100 }
101}
102
103impl<'a> IndexConst<&'a fiat_p521_tight_field_element> {
104 #[allow(unused)]
105 #[inline(always)]
106 const fn index(self, i: usize) -> &'a u64 {
107 &self.0.0[i]
108 }
109}
110
111impl<'a, 'b> IndexConst<&'a mut &'b mut fiat_p521_tight_field_element> {
112 #[allow(unused)]
113 #[inline(always)]
114 const fn index_mut(self, i: usize) -> &'a mut u64 {
115 &mut self.0.0[i]
116 }
117}
118
119
120#[inline]
134pub const fn fiat_p521_addcarryx_u58(out1: &mut u64, out2: &mut fiat_p521_u1, arg1: fiat_p521_u1, arg2: u64, arg3: u64) {
135 let x1: u64 = (((arg1 as u64) + arg2) + arg3);
136 let x2: u64 = (x1 & 0x3ffffffffffffff);
137 let x3: fiat_p521_u1 = ((x1 >> 58) as fiat_p521_u1);
138 *out1 = x2;
139 *out2 = x3;
140}
141
142#[inline]
156pub const fn fiat_p521_subborrowx_u58(out1: &mut u64, out2: &mut fiat_p521_u1, arg1: fiat_p521_u1, arg2: u64, arg3: u64) {
157 let x1: i64 = ((((((arg2 as i128) - (arg1 as i128)) as i64) as i128) - (arg3 as i128)) as i64);
158 let x2: fiat_p521_i1 = ((x1 >> 58) as fiat_p521_i1);
159 let x3: u64 = (((x1 as i128) & (0x3ffffffffffffff as i128)) as u64);
160 *out1 = x3;
161 *out2 = (((0x0 as fiat_p521_i2) - (x2 as fiat_p521_i2)) as fiat_p521_u1);
162}
163
164#[inline]
178pub const fn fiat_p521_addcarryx_u57(out1: &mut u64, out2: &mut fiat_p521_u1, arg1: fiat_p521_u1, arg2: u64, arg3: u64) {
179 let x1: u64 = (((arg1 as u64) + arg2) + arg3);
180 let x2: u64 = (x1 & 0x1ffffffffffffff);
181 let x3: fiat_p521_u1 = ((x1 >> 57) as fiat_p521_u1);
182 *out1 = x2;
183 *out2 = x3;
184}
185
186#[inline]
200pub const fn fiat_p521_subborrowx_u57(out1: &mut u64, out2: &mut fiat_p521_u1, arg1: fiat_p521_u1, arg2: u64, arg3: u64) {
201 let x1: i64 = ((((((arg2 as i128) - (arg1 as i128)) as i64) as i128) - (arg3 as i128)) as i64);
202 let x2: fiat_p521_i1 = ((x1 >> 57) as fiat_p521_i1);
203 let x3: u64 = (((x1 as i128) & (0x1ffffffffffffff as i128)) as u64);
204 *out1 = x3;
205 *out2 = (((0x0 as fiat_p521_i2) - (x2 as fiat_p521_i2)) as fiat_p521_u1);
206}
207
208#[inline]
220pub const fn fiat_p521_cmovznz_u64(out1: &mut u64, arg1: fiat_p521_u1, arg2: u64, arg3: u64) {
221 let x1: fiat_p521_u1 = (!(!arg1));
222 let x2: u64 = ((((((0x0 as fiat_p521_i2) - (x1 as fiat_p521_i2)) as fiat_p521_i1) as i128) & (0xffffffffffffffff as i128)) as u64);
223 let x3: u64 = ((x2 & arg3) | ((!x2) & arg2));
224 *out1 = x3;
225}
226
227#[inline]
233pub const fn fiat_p521_carry_mul(mut out1: &mut fiat_p521_tight_field_element, arg1: &fiat_p521_loose_field_element, arg2: &fiat_p521_loose_field_element) {
234 let x1: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
235 let x2: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
236 let x3: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(6)) * 0x2) as u128));
237 let x4: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(5)) * 0x2) as u128));
238 let x5: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(4)) * 0x2) as u128));
239 let x6: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(3)) * 0x2) as u128));
240 let x7: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(2)) * 0x2) as u128));
241 let x8: u128 = (((*IndexConst(arg1).index(8)) as u128) * (((*IndexConst(arg2).index(1)) * 0x2) as u128));
242 let x9: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
243 let x10: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
244 let x11: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(6)) * 0x2) as u128));
245 let x12: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(5)) * 0x2) as u128));
246 let x13: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(4)) * 0x2) as u128));
247 let x14: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(3)) * 0x2) as u128));
248 let x15: u128 = (((*IndexConst(arg1).index(7)) as u128) * (((*IndexConst(arg2).index(2)) * 0x2) as u128));
249 let x16: u128 = (((*IndexConst(arg1).index(6)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
250 let x17: u128 = (((*IndexConst(arg1).index(6)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
251 let x18: u128 = (((*IndexConst(arg1).index(6)) as u128) * (((*IndexConst(arg2).index(6)) * 0x2) as u128));
252 let x19: u128 = (((*IndexConst(arg1).index(6)) as u128) * (((*IndexConst(arg2).index(5)) * 0x2) as u128));
253 let x20: u128 = (((*IndexConst(arg1).index(6)) as u128) * (((*IndexConst(arg2).index(4)) * 0x2) as u128));
254 let x21: u128 = (((*IndexConst(arg1).index(6)) as u128) * (((*IndexConst(arg2).index(3)) * 0x2) as u128));
255 let x22: u128 = (((*IndexConst(arg1).index(5)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
256 let x23: u128 = (((*IndexConst(arg1).index(5)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
257 let x24: u128 = (((*IndexConst(arg1).index(5)) as u128) * (((*IndexConst(arg2).index(6)) * 0x2) as u128));
258 let x25: u128 = (((*IndexConst(arg1).index(5)) as u128) * (((*IndexConst(arg2).index(5)) * 0x2) as u128));
259 let x26: u128 = (((*IndexConst(arg1).index(5)) as u128) * (((*IndexConst(arg2).index(4)) * 0x2) as u128));
260 let x27: u128 = (((*IndexConst(arg1).index(4)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
261 let x28: u128 = (((*IndexConst(arg1).index(4)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
262 let x29: u128 = (((*IndexConst(arg1).index(4)) as u128) * (((*IndexConst(arg2).index(6)) * 0x2) as u128));
263 let x30: u128 = (((*IndexConst(arg1).index(4)) as u128) * (((*IndexConst(arg2).index(5)) * 0x2) as u128));
264 let x31: u128 = (((*IndexConst(arg1).index(3)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
265 let x32: u128 = (((*IndexConst(arg1).index(3)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
266 let x33: u128 = (((*IndexConst(arg1).index(3)) as u128) * (((*IndexConst(arg2).index(6)) * 0x2) as u128));
267 let x34: u128 = (((*IndexConst(arg1).index(2)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
268 let x35: u128 = (((*IndexConst(arg1).index(2)) as u128) * (((*IndexConst(arg2).index(7)) * 0x2) as u128));
269 let x36: u128 = (((*IndexConst(arg1).index(1)) as u128) * (((*IndexConst(arg2).index(8)) * 0x2) as u128));
270 let x37: u128 = (((*IndexConst(arg1).index(8)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
271 let x38: u128 = (((*IndexConst(arg1).index(7)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
272 let x39: u128 = (((*IndexConst(arg1).index(7)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
273 let x40: u128 = (((*IndexConst(arg1).index(6)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
274 let x41: u128 = (((*IndexConst(arg1).index(6)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
275 let x42: u128 = (((*IndexConst(arg1).index(6)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
276 let x43: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((*IndexConst(arg2).index(3)) as u128));
277 let x44: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
278 let x45: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
279 let x46: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
280 let x47: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((*IndexConst(arg2).index(4)) as u128));
281 let x48: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((*IndexConst(arg2).index(3)) as u128));
282 let x49: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
283 let x50: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
284 let x51: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
285 let x52: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg2).index(5)) as u128));
286 let x53: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg2).index(4)) as u128));
287 let x54: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg2).index(3)) as u128));
288 let x55: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
289 let x56: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
290 let x57: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
291 let x58: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(6)) as u128));
292 let x59: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(5)) as u128));
293 let x60: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(4)) as u128));
294 let x61: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(3)) as u128));
295 let x62: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
296 let x63: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
297 let x64: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
298 let x65: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(7)) as u128));
299 let x66: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(6)) as u128));
300 let x67: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(5)) as u128));
301 let x68: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(4)) as u128));
302 let x69: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(3)) as u128));
303 let x70: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
304 let x71: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
305 let x72: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
306 let x73: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(8)) as u128));
307 let x74: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(7)) as u128));
308 let x75: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(6)) as u128));
309 let x76: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(5)) as u128));
310 let x77: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(4)) as u128));
311 let x78: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(3)) as u128));
312 let x79: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(2)) as u128));
313 let x80: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(1)) as u128));
314 let x81: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg2).index(0)) as u128));
315 let x82: u128 = (x81 + (x36 + (x35 + (x33 + (x30 + (x26 + (x21 + (x15 + x8))))))));
316 let x83: u128 = (x82 >> 58);
317 let x84: u64 = ((x82 & (0x3ffffffffffffff as u128)) as u64);
318 let x85: u128 = (x73 + (x65 + (x58 + (x52 + (x47 + (x43 + (x40 + (x38 + x37))))))));
319 let x86: u128 = (x74 + (x66 + (x59 + (x53 + (x48 + (x44 + (x41 + (x39 + x1))))))));
320 let x87: u128 = (x75 + (x67 + (x60 + (x54 + (x49 + (x45 + (x42 + (x9 + x2))))))));
321 let x88: u128 = (x76 + (x68 + (x61 + (x55 + (x50 + (x46 + (x16 + (x10 + x3))))))));
322 let x89: u128 = (x77 + (x69 + (x62 + (x56 + (x51 + (x22 + (x17 + (x11 + x4))))))));
323 let x90: u128 = (x78 + (x70 + (x63 + (x57 + (x27 + (x23 + (x18 + (x12 + x5))))))));
324 let x91: u128 = (x79 + (x71 + (x64 + (x31 + (x28 + (x24 + (x19 + (x13 + x6))))))));
325 let x92: u128 = (x80 + (x72 + (x34 + (x32 + (x29 + (x25 + (x20 + (x14 + x7))))))));
326 let x93: u128 = (x83 + x92);
327 let x94: u128 = (x93 >> 58);
328 let x95: u64 = ((x93 & (0x3ffffffffffffff as u128)) as u64);
329 let x96: u128 = (x94 + x91);
330 let x97: u128 = (x96 >> 58);
331 let x98: u64 = ((x96 & (0x3ffffffffffffff as u128)) as u64);
332 let x99: u128 = (x97 + x90);
333 let x100: u128 = (x99 >> 58);
334 let x101: u64 = ((x99 & (0x3ffffffffffffff as u128)) as u64);
335 let x102: u128 = (x100 + x89);
336 let x103: u128 = (x102 >> 58);
337 let x104: u64 = ((x102 & (0x3ffffffffffffff as u128)) as u64);
338 let x105: u128 = (x103 + x88);
339 let x106: u128 = (x105 >> 58);
340 let x107: u64 = ((x105 & (0x3ffffffffffffff as u128)) as u64);
341 let x108: u128 = (x106 + x87);
342 let x109: u128 = (x108 >> 58);
343 let x110: u64 = ((x108 & (0x3ffffffffffffff as u128)) as u64);
344 let x111: u128 = (x109 + x86);
345 let x112: u128 = (x111 >> 58);
346 let x113: u64 = ((x111 & (0x3ffffffffffffff as u128)) as u64);
347 let x114: u128 = (x112 + x85);
348 let x115: u128 = (x114 >> 57);
349 let x116: u64 = ((x114 & (0x1ffffffffffffff as u128)) as u64);
350 let x117: u128 = ((x84 as u128) + x115);
351 let x118: u64 = ((x117 >> 58) as u64);
352 let x119: u64 = ((x117 & (0x3ffffffffffffff as u128)) as u64);
353 let x120: u64 = (x118 + x95);
354 let x121: fiat_p521_u1 = ((x120 >> 58) as fiat_p521_u1);
355 let x122: u64 = (x120 & 0x3ffffffffffffff);
356 let x123: u64 = ((x121 as u64) + x98);
357 *IndexConst(&mut out1).index_mut(0) = x119;
358 *IndexConst(&mut out1).index_mut(1) = x122;
359 *IndexConst(&mut out1).index_mut(2) = x123;
360 *IndexConst(&mut out1).index_mut(3) = x101;
361 *IndexConst(&mut out1).index_mut(4) = x104;
362 *IndexConst(&mut out1).index_mut(5) = x107;
363 *IndexConst(&mut out1).index_mut(6) = x110;
364 *IndexConst(&mut out1).index_mut(7) = x113;
365 *IndexConst(&mut out1).index_mut(8) = x116;
366}
367
368#[inline]
374pub const fn fiat_p521_carry_square(mut out1: &mut fiat_p521_tight_field_element, arg1: &fiat_p521_loose_field_element) {
375 let x1: u64 = (*IndexConst(arg1).index(8));
376 let x2: u64 = (x1 * 0x2);
377 let x3: u64 = ((*IndexConst(arg1).index(8)) * 0x2);
378 let x4: u64 = (*IndexConst(arg1).index(7));
379 let x5: u64 = (x4 * 0x2);
380 let x6: u64 = ((*IndexConst(arg1).index(7)) * 0x2);
381 let x7: u64 = (*IndexConst(arg1).index(6));
382 let x8: u64 = (x7 * 0x2);
383 let x9: u64 = ((*IndexConst(arg1).index(6)) * 0x2);
384 let x10: u64 = (*IndexConst(arg1).index(5));
385 let x11: u64 = (x10 * 0x2);
386 let x12: u64 = ((*IndexConst(arg1).index(5)) * 0x2);
387 let x13: u64 = ((*IndexConst(arg1).index(4)) * 0x2);
388 let x14: u64 = ((*IndexConst(arg1).index(3)) * 0x2);
389 let x15: u64 = ((*IndexConst(arg1).index(2)) * 0x2);
390 let x16: u64 = ((*IndexConst(arg1).index(1)) * 0x2);
391 let x17: u128 = (((*IndexConst(arg1).index(8)) as u128) * ((x1 * 0x2) as u128));
392 let x18: u128 = (((*IndexConst(arg1).index(7)) as u128) * ((x2 * 0x2) as u128));
393 let x19: u128 = (((*IndexConst(arg1).index(7)) as u128) * ((x4 * 0x2) as u128));
394 let x20: u128 = (((*IndexConst(arg1).index(6)) as u128) * ((x2 * 0x2) as u128));
395 let x21: u128 = (((*IndexConst(arg1).index(6)) as u128) * ((x5 * 0x2) as u128));
396 let x22: u128 = (((*IndexConst(arg1).index(6)) as u128) * ((x7 * 0x2) as u128));
397 let x23: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((x2 * 0x2) as u128));
398 let x24: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((x5 * 0x2) as u128));
399 let x25: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((x8 * 0x2) as u128));
400 let x26: u128 = (((*IndexConst(arg1).index(5)) as u128) * ((x10 * 0x2) as u128));
401 let x27: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((x2 * 0x2) as u128));
402 let x28: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((x5 * 0x2) as u128));
403 let x29: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((x8 * 0x2) as u128));
404 let x30: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((x11 * 0x2) as u128));
405 let x31: u128 = (((*IndexConst(arg1).index(4)) as u128) * ((*IndexConst(arg1).index(4)) as u128));
406 let x32: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((x2 * 0x2) as u128));
407 let x33: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((x5 * 0x2) as u128));
408 let x34: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((x8 * 0x2) as u128));
409 let x35: u128 = (((*IndexConst(arg1).index(3)) as u128) * (x12 as u128));
410 let x36: u128 = (((*IndexConst(arg1).index(3)) as u128) * (x13 as u128));
411 let x37: u128 = (((*IndexConst(arg1).index(3)) as u128) * ((*IndexConst(arg1).index(3)) as u128));
412 let x38: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((x2 * 0x2) as u128));
413 let x39: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((x5 * 0x2) as u128));
414 let x40: u128 = (((*IndexConst(arg1).index(2)) as u128) * (x9 as u128));
415 let x41: u128 = (((*IndexConst(arg1).index(2)) as u128) * (x12 as u128));
416 let x42: u128 = (((*IndexConst(arg1).index(2)) as u128) * (x13 as u128));
417 let x43: u128 = (((*IndexConst(arg1).index(2)) as u128) * (x14 as u128));
418 let x44: u128 = (((*IndexConst(arg1).index(2)) as u128) * ((*IndexConst(arg1).index(2)) as u128));
419 let x45: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((x2 * 0x2) as u128));
420 let x46: u128 = (((*IndexConst(arg1).index(1)) as u128) * (x6 as u128));
421 let x47: u128 = (((*IndexConst(arg1).index(1)) as u128) * (x9 as u128));
422 let x48: u128 = (((*IndexConst(arg1).index(1)) as u128) * (x12 as u128));
423 let x49: u128 = (((*IndexConst(arg1).index(1)) as u128) * (x13 as u128));
424 let x50: u128 = (((*IndexConst(arg1).index(1)) as u128) * (x14 as u128));
425 let x51: u128 = (((*IndexConst(arg1).index(1)) as u128) * (x15 as u128));
426 let x52: u128 = (((*IndexConst(arg1).index(1)) as u128) * ((*IndexConst(arg1).index(1)) as u128));
427 let x53: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x3 as u128));
428 let x54: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x6 as u128));
429 let x55: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x9 as u128));
430 let x56: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x12 as u128));
431 let x57: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x13 as u128));
432 let x58: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x14 as u128));
433 let x59: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x15 as u128));
434 let x60: u128 = (((*IndexConst(arg1).index(0)) as u128) * (x16 as u128));
435 let x61: u128 = (((*IndexConst(arg1).index(0)) as u128) * ((*IndexConst(arg1).index(0)) as u128));
436 let x62: u128 = (x61 + (x45 + (x39 + (x34 + x30))));
437 let x63: u128 = (x62 >> 58);
438 let x64: u64 = ((x62 & (0x3ffffffffffffff as u128)) as u64);
439 let x65: u128 = (x53 + (x46 + (x40 + (x35 + x31))));
440 let x66: u128 = (x54 + (x47 + (x41 + (x36 + x17))));
441 let x67: u128 = (x55 + (x48 + (x42 + (x37 + x18))));
442 let x68: u128 = (x56 + (x49 + (x43 + (x20 + x19))));
443 let x69: u128 = (x57 + (x50 + (x44 + (x23 + x21))));
444 let x70: u128 = (x58 + (x51 + (x27 + (x24 + x22))));
445 let x71: u128 = (x59 + (x52 + (x32 + (x28 + x25))));
446 let x72: u128 = (x60 + (x38 + (x33 + (x29 + x26))));
447 let x73: u128 = (x63 + x72);
448 let x74: u128 = (x73 >> 58);
449 let x75: u64 = ((x73 & (0x3ffffffffffffff as u128)) as u64);
450 let x76: u128 = (x74 + x71);
451 let x77: u128 = (x76 >> 58);
452 let x78: u64 = ((x76 & (0x3ffffffffffffff as u128)) as u64);
453 let x79: u128 = (x77 + x70);
454 let x80: u128 = (x79 >> 58);
455 let x81: u64 = ((x79 & (0x3ffffffffffffff as u128)) as u64);
456 let x82: u128 = (x80 + x69);
457 let x83: u128 = (x82 >> 58);
458 let x84: u64 = ((x82 & (0x3ffffffffffffff as u128)) as u64);
459 let x85: u128 = (x83 + x68);
460 let x86: u128 = (x85 >> 58);
461 let x87: u64 = ((x85 & (0x3ffffffffffffff as u128)) as u64);
462 let x88: u128 = (x86 + x67);
463 let x89: u128 = (x88 >> 58);
464 let x90: u64 = ((x88 & (0x3ffffffffffffff as u128)) as u64);
465 let x91: u128 = (x89 + x66);
466 let x92: u128 = (x91 >> 58);
467 let x93: u64 = ((x91 & (0x3ffffffffffffff as u128)) as u64);
468 let x94: u128 = (x92 + x65);
469 let x95: u128 = (x94 >> 57);
470 let x96: u64 = ((x94 & (0x1ffffffffffffff as u128)) as u64);
471 let x97: u128 = ((x64 as u128) + x95);
472 let x98: u64 = ((x97 >> 58) as u64);
473 let x99: u64 = ((x97 & (0x3ffffffffffffff as u128)) as u64);
474 let x100: u64 = (x98 + x75);
475 let x101: fiat_p521_u1 = ((x100 >> 58) as fiat_p521_u1);
476 let x102: u64 = (x100 & 0x3ffffffffffffff);
477 let x103: u64 = ((x101 as u64) + x78);
478 *IndexConst(&mut out1).index_mut(0) = x99;
479 *IndexConst(&mut out1).index_mut(1) = x102;
480 *IndexConst(&mut out1).index_mut(2) = x103;
481 *IndexConst(&mut out1).index_mut(3) = x81;
482 *IndexConst(&mut out1).index_mut(4) = x84;
483 *IndexConst(&mut out1).index_mut(5) = x87;
484 *IndexConst(&mut out1).index_mut(6) = x90;
485 *IndexConst(&mut out1).index_mut(7) = x93;
486 *IndexConst(&mut out1).index_mut(8) = x96;
487}
488
489#[inline]
495pub const fn fiat_p521_carry(mut out1: &mut fiat_p521_tight_field_element, arg1: &fiat_p521_loose_field_element) {
496 let x1: u64 = (*IndexConst(arg1).index(0));
497 let x2: u64 = ((x1 >> 58) + (*IndexConst(arg1).index(1)));
498 let x3: u64 = ((x2 >> 58) + (*IndexConst(arg1).index(2)));
499 let x4: u64 = ((x3 >> 58) + (*IndexConst(arg1).index(3)));
500 let x5: u64 = ((x4 >> 58) + (*IndexConst(arg1).index(4)));
501 let x6: u64 = ((x5 >> 58) + (*IndexConst(arg1).index(5)));
502 let x7: u64 = ((x6 >> 58) + (*IndexConst(arg1).index(6)));
503 let x8: u64 = ((x7 >> 58) + (*IndexConst(arg1).index(7)));
504 let x9: u64 = ((x8 >> 58) + (*IndexConst(arg1).index(8)));
505 let x10: u64 = ((x1 & 0x3ffffffffffffff) + (x9 >> 57));
506 let x11: u64 = ((((x10 >> 58) as fiat_p521_u1) as u64) + (x2 & 0x3ffffffffffffff));
507 let x12: u64 = (x10 & 0x3ffffffffffffff);
508 let x13: u64 = (x11 & 0x3ffffffffffffff);
509 let x14: u64 = ((((x11 >> 58) as fiat_p521_u1) as u64) + (x3 & 0x3ffffffffffffff));
510 let x15: u64 = (x4 & 0x3ffffffffffffff);
511 let x16: u64 = (x5 & 0x3ffffffffffffff);
512 let x17: u64 = (x6 & 0x3ffffffffffffff);
513 let x18: u64 = (x7 & 0x3ffffffffffffff);
514 let x19: u64 = (x8 & 0x3ffffffffffffff);
515 let x20: u64 = (x9 & 0x1ffffffffffffff);
516 *IndexConst(&mut out1).index_mut(0) = x12;
517 *IndexConst(&mut out1).index_mut(1) = x13;
518 *IndexConst(&mut out1).index_mut(2) = x14;
519 *IndexConst(&mut out1).index_mut(3) = x15;
520 *IndexConst(&mut out1).index_mut(4) = x16;
521 *IndexConst(&mut out1).index_mut(5) = x17;
522 *IndexConst(&mut out1).index_mut(6) = x18;
523 *IndexConst(&mut out1).index_mut(7) = x19;
524 *IndexConst(&mut out1).index_mut(8) = x20;
525}
526
527#[inline]
533pub const fn fiat_p521_add(mut out1: &mut fiat_p521_loose_field_element, arg1: &fiat_p521_tight_field_element, arg2: &fiat_p521_tight_field_element) {
534 let x1: u64 = ((*IndexConst(arg1).index(0)) + (*IndexConst(arg2).index(0)));
535 let x2: u64 = ((*IndexConst(arg1).index(1)) + (*IndexConst(arg2).index(1)));
536 let x3: u64 = ((*IndexConst(arg1).index(2)) + (*IndexConst(arg2).index(2)));
537 let x4: u64 = ((*IndexConst(arg1).index(3)) + (*IndexConst(arg2).index(3)));
538 let x5: u64 = ((*IndexConst(arg1).index(4)) + (*IndexConst(arg2).index(4)));
539 let x6: u64 = ((*IndexConst(arg1).index(5)) + (*IndexConst(arg2).index(5)));
540 let x7: u64 = ((*IndexConst(arg1).index(6)) + (*IndexConst(arg2).index(6)));
541 let x8: u64 = ((*IndexConst(arg1).index(7)) + (*IndexConst(arg2).index(7)));
542 let x9: u64 = ((*IndexConst(arg1).index(8)) + (*IndexConst(arg2).index(8)));
543 *IndexConst(&mut out1).index_mut(0) = x1;
544 *IndexConst(&mut out1).index_mut(1) = x2;
545 *IndexConst(&mut out1).index_mut(2) = x3;
546 *IndexConst(&mut out1).index_mut(3) = x4;
547 *IndexConst(&mut out1).index_mut(4) = x5;
548 *IndexConst(&mut out1).index_mut(5) = x6;
549 *IndexConst(&mut out1).index_mut(6) = x7;
550 *IndexConst(&mut out1).index_mut(7) = x8;
551 *IndexConst(&mut out1).index_mut(8) = x9;
552}
553
554#[inline]
560pub const fn fiat_p521_sub(mut out1: &mut fiat_p521_loose_field_element, arg1: &fiat_p521_tight_field_element, arg2: &fiat_p521_tight_field_element) {
561 let x1: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(0))) - (*IndexConst(arg2).index(0)));
562 let x2: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(1))) - (*IndexConst(arg2).index(1)));
563 let x3: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(2))) - (*IndexConst(arg2).index(2)));
564 let x4: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(3))) - (*IndexConst(arg2).index(3)));
565 let x5: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(4))) - (*IndexConst(arg2).index(4)));
566 let x6: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(5))) - (*IndexConst(arg2).index(5)));
567 let x7: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(6))) - (*IndexConst(arg2).index(6)));
568 let x8: u64 = ((0x7fffffffffffffe + (*IndexConst(arg1).index(7))) - (*IndexConst(arg2).index(7)));
569 let x9: u64 = ((0x3fffffffffffffe + (*IndexConst(arg1).index(8))) - (*IndexConst(arg2).index(8)));
570 *IndexConst(&mut out1).index_mut(0) = x1;
571 *IndexConst(&mut out1).index_mut(1) = x2;
572 *IndexConst(&mut out1).index_mut(2) = x3;
573 *IndexConst(&mut out1).index_mut(3) = x4;
574 *IndexConst(&mut out1).index_mut(4) = x5;
575 *IndexConst(&mut out1).index_mut(5) = x6;
576 *IndexConst(&mut out1).index_mut(6) = x7;
577 *IndexConst(&mut out1).index_mut(7) = x8;
578 *IndexConst(&mut out1).index_mut(8) = x9;
579}
580
581#[inline]
587pub const fn fiat_p521_opp(mut out1: &mut fiat_p521_loose_field_element, arg1: &fiat_p521_tight_field_element) {
588 let x1: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(0)));
589 let x2: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(1)));
590 let x3: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(2)));
591 let x4: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(3)));
592 let x5: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(4)));
593 let x6: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(5)));
594 let x7: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(6)));
595 let x8: u64 = (0x7fffffffffffffe - (*IndexConst(arg1).index(7)));
596 let x9: u64 = (0x3fffffffffffffe - (*IndexConst(arg1).index(8)));
597 *IndexConst(&mut out1).index_mut(0) = x1;
598 *IndexConst(&mut out1).index_mut(1) = x2;
599 *IndexConst(&mut out1).index_mut(2) = x3;
600 *IndexConst(&mut out1).index_mut(3) = x4;
601 *IndexConst(&mut out1).index_mut(4) = x5;
602 *IndexConst(&mut out1).index_mut(5) = x6;
603 *IndexConst(&mut out1).index_mut(6) = x7;
604 *IndexConst(&mut out1).index_mut(7) = x8;
605 *IndexConst(&mut out1).index_mut(8) = x9;
606}
607
608#[inline]
620pub const fn fiat_p521_selectznz(mut out1: &mut [u64; 9], arg1: fiat_p521_u1, arg2: &[u64; 9], arg3: &[u64; 9]) {
621 let mut x1: u64 = 0;
622 fiat_p521_cmovznz_u64(&mut x1, arg1, (*IndexConst(arg2).index(0)), (*IndexConst(arg3).index(0)));
623 let mut x2: u64 = 0;
624 fiat_p521_cmovznz_u64(&mut x2, arg1, (*IndexConst(arg2).index(1)), (*IndexConst(arg3).index(1)));
625 let mut x3: u64 = 0;
626 fiat_p521_cmovznz_u64(&mut x3, arg1, (*IndexConst(arg2).index(2)), (*IndexConst(arg3).index(2)));
627 let mut x4: u64 = 0;
628 fiat_p521_cmovznz_u64(&mut x4, arg1, (*IndexConst(arg2).index(3)), (*IndexConst(arg3).index(3)));
629 let mut x5: u64 = 0;
630 fiat_p521_cmovznz_u64(&mut x5, arg1, (*IndexConst(arg2).index(4)), (*IndexConst(arg3).index(4)));
631 let mut x6: u64 = 0;
632 fiat_p521_cmovznz_u64(&mut x6, arg1, (*IndexConst(arg2).index(5)), (*IndexConst(arg3).index(5)));
633 let mut x7: u64 = 0;
634 fiat_p521_cmovznz_u64(&mut x7, arg1, (*IndexConst(arg2).index(6)), (*IndexConst(arg3).index(6)));
635 let mut x8: u64 = 0;
636 fiat_p521_cmovznz_u64(&mut x8, arg1, (*IndexConst(arg2).index(7)), (*IndexConst(arg3).index(7)));
637 let mut x9: u64 = 0;
638 fiat_p521_cmovznz_u64(&mut x9, arg1, (*IndexConst(arg2).index(8)), (*IndexConst(arg3).index(8)));
639 *IndexConst(&mut out1).index_mut(0) = x1;
640 *IndexConst(&mut out1).index_mut(1) = x2;
641 *IndexConst(&mut out1).index_mut(2) = x3;
642 *IndexConst(&mut out1).index_mut(3) = x4;
643 *IndexConst(&mut out1).index_mut(4) = x5;
644 *IndexConst(&mut out1).index_mut(5) = x6;
645 *IndexConst(&mut out1).index_mut(6) = x7;
646 *IndexConst(&mut out1).index_mut(7) = x8;
647 *IndexConst(&mut out1).index_mut(8) = x9;
648}
649
650#[inline]
658pub const fn fiat_p521_to_bytes(mut out1: &mut [u8; 66], arg1: &fiat_p521_tight_field_element) {
659 let mut x1: u64 = 0;
660 let mut x2: fiat_p521_u1 = 0;
661 fiat_p521_subborrowx_u58(&mut x1, &mut x2, 0x0, (*IndexConst(arg1).index(0)), 0x3ffffffffffffff);
662 let mut x3: u64 = 0;
663 let mut x4: fiat_p521_u1 = 0;
664 fiat_p521_subborrowx_u58(&mut x3, &mut x4, x2, (*IndexConst(arg1).index(1)), 0x3ffffffffffffff);
665 let mut x5: u64 = 0;
666 let mut x6: fiat_p521_u1 = 0;
667 fiat_p521_subborrowx_u58(&mut x5, &mut x6, x4, (*IndexConst(arg1).index(2)), 0x3ffffffffffffff);
668 let mut x7: u64 = 0;
669 let mut x8: fiat_p521_u1 = 0;
670 fiat_p521_subborrowx_u58(&mut x7, &mut x8, x6, (*IndexConst(arg1).index(3)), 0x3ffffffffffffff);
671 let mut x9: u64 = 0;
672 let mut x10: fiat_p521_u1 = 0;
673 fiat_p521_subborrowx_u58(&mut x9, &mut x10, x8, (*IndexConst(arg1).index(4)), 0x3ffffffffffffff);
674 let mut x11: u64 = 0;
675 let mut x12: fiat_p521_u1 = 0;
676 fiat_p521_subborrowx_u58(&mut x11, &mut x12, x10, (*IndexConst(arg1).index(5)), 0x3ffffffffffffff);
677 let mut x13: u64 = 0;
678 let mut x14: fiat_p521_u1 = 0;
679 fiat_p521_subborrowx_u58(&mut x13, &mut x14, x12, (*IndexConst(arg1).index(6)), 0x3ffffffffffffff);
680 let mut x15: u64 = 0;
681 let mut x16: fiat_p521_u1 = 0;
682 fiat_p521_subborrowx_u58(&mut x15, &mut x16, x14, (*IndexConst(arg1).index(7)), 0x3ffffffffffffff);
683 let mut x17: u64 = 0;
684 let mut x18: fiat_p521_u1 = 0;
685 fiat_p521_subborrowx_u57(&mut x17, &mut x18, x16, (*IndexConst(arg1).index(8)), 0x1ffffffffffffff);
686 let mut x19: u64 = 0;
687 fiat_p521_cmovznz_u64(&mut x19, x18, (0x0 as u64), 0xffffffffffffffff);
688 let mut x20: u64 = 0;
689 let mut x21: fiat_p521_u1 = 0;
690 fiat_p521_addcarryx_u58(&mut x20, &mut x21, 0x0, x1, (x19 & 0x3ffffffffffffff));
691 let mut x22: u64 = 0;
692 let mut x23: fiat_p521_u1 = 0;
693 fiat_p521_addcarryx_u58(&mut x22, &mut x23, x21, x3, (x19 & 0x3ffffffffffffff));
694 let mut x24: u64 = 0;
695 let mut x25: fiat_p521_u1 = 0;
696 fiat_p521_addcarryx_u58(&mut x24, &mut x25, x23, x5, (x19 & 0x3ffffffffffffff));
697 let mut x26: u64 = 0;
698 let mut x27: fiat_p521_u1 = 0;
699 fiat_p521_addcarryx_u58(&mut x26, &mut x27, x25, x7, (x19 & 0x3ffffffffffffff));
700 let mut x28: u64 = 0;
701 let mut x29: fiat_p521_u1 = 0;
702 fiat_p521_addcarryx_u58(&mut x28, &mut x29, x27, x9, (x19 & 0x3ffffffffffffff));
703 let mut x30: u64 = 0;
704 let mut x31: fiat_p521_u1 = 0;
705 fiat_p521_addcarryx_u58(&mut x30, &mut x31, x29, x11, (x19 & 0x3ffffffffffffff));
706 let mut x32: u64 = 0;
707 let mut x33: fiat_p521_u1 = 0;
708 fiat_p521_addcarryx_u58(&mut x32, &mut x33, x31, x13, (x19 & 0x3ffffffffffffff));
709 let mut x34: u64 = 0;
710 let mut x35: fiat_p521_u1 = 0;
711 fiat_p521_addcarryx_u58(&mut x34, &mut x35, x33, x15, (x19 & 0x3ffffffffffffff));
712 let mut x36: u64 = 0;
713 let mut x37: fiat_p521_u1 = 0;
714 fiat_p521_addcarryx_u57(&mut x36, &mut x37, x35, x17, (x19 & 0x1ffffffffffffff));
715 let x38: u64 = (x34 << 6);
716 let x39: u64 = (x32 << 4);
717 let x40: u64 = (x30 << 2);
718 let x41: u64 = (x26 << 6);
719 let x42: u64 = (x24 << 4);
720 let x43: u64 = (x22 << 2);
721 let x44: u8 = ((x20 & (0xff as u64)) as u8);
722 let x45: u64 = (x20 >> 8);
723 let x46: u8 = ((x45 & (0xff as u64)) as u8);
724 let x47: u64 = (x45 >> 8);
725 let x48: u8 = ((x47 & (0xff as u64)) as u8);
726 let x49: u64 = (x47 >> 8);
727 let x50: u8 = ((x49 & (0xff as u64)) as u8);
728 let x51: u64 = (x49 >> 8);
729 let x52: u8 = ((x51 & (0xff as u64)) as u8);
730 let x53: u64 = (x51 >> 8);
731 let x54: u8 = ((x53 & (0xff as u64)) as u8);
732 let x55: u64 = (x53 >> 8);
733 let x56: u8 = ((x55 & (0xff as u64)) as u8);
734 let x57: u8 = ((x55 >> 8) as u8);
735 let x58: u64 = (x43 + (x57 as u64));
736 let x59: u8 = ((x58 & (0xff as u64)) as u8);
737 let x60: u64 = (x58 >> 8);
738 let x61: u8 = ((x60 & (0xff as u64)) as u8);
739 let x62: u64 = (x60 >> 8);
740 let x63: u8 = ((x62 & (0xff as u64)) as u8);
741 let x64: u64 = (x62 >> 8);
742 let x65: u8 = ((x64 & (0xff as u64)) as u8);
743 let x66: u64 = (x64 >> 8);
744 let x67: u8 = ((x66 & (0xff as u64)) as u8);
745 let x68: u64 = (x66 >> 8);
746 let x69: u8 = ((x68 & (0xff as u64)) as u8);
747 let x70: u64 = (x68 >> 8);
748 let x71: u8 = ((x70 & (0xff as u64)) as u8);
749 let x72: u8 = ((x70 >> 8) as u8);
750 let x73: u64 = (x42 + (x72 as u64));
751 let x74: u8 = ((x73 & (0xff as u64)) as u8);
752 let x75: u64 = (x73 >> 8);
753 let x76: u8 = ((x75 & (0xff as u64)) as u8);
754 let x77: u64 = (x75 >> 8);
755 let x78: u8 = ((x77 & (0xff as u64)) as u8);
756 let x79: u64 = (x77 >> 8);
757 let x80: u8 = ((x79 & (0xff as u64)) as u8);
758 let x81: u64 = (x79 >> 8);
759 let x82: u8 = ((x81 & (0xff as u64)) as u8);
760 let x83: u64 = (x81 >> 8);
761 let x84: u8 = ((x83 & (0xff as u64)) as u8);
762 let x85: u64 = (x83 >> 8);
763 let x86: u8 = ((x85 & (0xff as u64)) as u8);
764 let x87: u8 = ((x85 >> 8) as u8);
765 let x88: u64 = (x41 + (x87 as u64));
766 let x89: u8 = ((x88 & (0xff as u64)) as u8);
767 let x90: u64 = (x88 >> 8);
768 let x91: u8 = ((x90 & (0xff as u64)) as u8);
769 let x92: u64 = (x90 >> 8);
770 let x93: u8 = ((x92 & (0xff as u64)) as u8);
771 let x94: u64 = (x92 >> 8);
772 let x95: u8 = ((x94 & (0xff as u64)) as u8);
773 let x96: u64 = (x94 >> 8);
774 let x97: u8 = ((x96 & (0xff as u64)) as u8);
775 let x98: u64 = (x96 >> 8);
776 let x99: u8 = ((x98 & (0xff as u64)) as u8);
777 let x100: u64 = (x98 >> 8);
778 let x101: u8 = ((x100 & (0xff as u64)) as u8);
779 let x102: u8 = ((x100 >> 8) as u8);
780 let x103: u8 = ((x28 & (0xff as u64)) as u8);
781 let x104: u64 = (x28 >> 8);
782 let x105: u8 = ((x104 & (0xff as u64)) as u8);
783 let x106: u64 = (x104 >> 8);
784 let x107: u8 = ((x106 & (0xff as u64)) as u8);
785 let x108: u64 = (x106 >> 8);
786 let x109: u8 = ((x108 & (0xff as u64)) as u8);
787 let x110: u64 = (x108 >> 8);
788 let x111: u8 = ((x110 & (0xff as u64)) as u8);
789 let x112: u64 = (x110 >> 8);
790 let x113: u8 = ((x112 & (0xff as u64)) as u8);
791 let x114: u64 = (x112 >> 8);
792 let x115: u8 = ((x114 & (0xff as u64)) as u8);
793 let x116: u8 = ((x114 >> 8) as u8);
794 let x117: u64 = (x40 + (x116 as u64));
795 let x118: u8 = ((x117 & (0xff as u64)) as u8);
796 let x119: u64 = (x117 >> 8);
797 let x120: u8 = ((x119 & (0xff as u64)) as u8);
798 let x121: u64 = (x119 >> 8);
799 let x122: u8 = ((x121 & (0xff as u64)) as u8);
800 let x123: u64 = (x121 >> 8);
801 let x124: u8 = ((x123 & (0xff as u64)) as u8);
802 let x125: u64 = (x123 >> 8);
803 let x126: u8 = ((x125 & (0xff as u64)) as u8);
804 let x127: u64 = (x125 >> 8);
805 let x128: u8 = ((x127 & (0xff as u64)) as u8);
806 let x129: u64 = (x127 >> 8);
807 let x130: u8 = ((x129 & (0xff as u64)) as u8);
808 let x131: u8 = ((x129 >> 8) as u8);
809 let x132: u64 = (x39 + (x131 as u64));
810 let x133: u8 = ((x132 & (0xff as u64)) as u8);
811 let x134: u64 = (x132 >> 8);
812 let x135: u8 = ((x134 & (0xff as u64)) as u8);
813 let x136: u64 = (x134 >> 8);
814 let x137: u8 = ((x136 & (0xff as u64)) as u8);
815 let x138: u64 = (x136 >> 8);
816 let x139: u8 = ((x138 & (0xff as u64)) as u8);
817 let x140: u64 = (x138 >> 8);
818 let x141: u8 = ((x140 & (0xff as u64)) as u8);
819 let x142: u64 = (x140 >> 8);
820 let x143: u8 = ((x142 & (0xff as u64)) as u8);
821 let x144: u64 = (x142 >> 8);
822 let x145: u8 = ((x144 & (0xff as u64)) as u8);
823 let x146: u8 = ((x144 >> 8) as u8);
824 let x147: u64 = (x38 + (x146 as u64));
825 let x148: u8 = ((x147 & (0xff as u64)) as u8);
826 let x149: u64 = (x147 >> 8);
827 let x150: u8 = ((x149 & (0xff as u64)) as u8);
828 let x151: u64 = (x149 >> 8);
829 let x152: u8 = ((x151 & (0xff as u64)) as u8);
830 let x153: u64 = (x151 >> 8);
831 let x154: u8 = ((x153 & (0xff as u64)) as u8);
832 let x155: u64 = (x153 >> 8);
833 let x156: u8 = ((x155 & (0xff as u64)) as u8);
834 let x157: u64 = (x155 >> 8);
835 let x158: u8 = ((x157 & (0xff as u64)) as u8);
836 let x159: u64 = (x157 >> 8);
837 let x160: u8 = ((x159 & (0xff as u64)) as u8);
838 let x161: u8 = ((x159 >> 8) as u8);
839 let x162: u8 = ((x36 & (0xff as u64)) as u8);
840 let x163: u64 = (x36 >> 8);
841 let x164: u8 = ((x163 & (0xff as u64)) as u8);
842 let x165: u64 = (x163 >> 8);
843 let x166: u8 = ((x165 & (0xff as u64)) as u8);
844 let x167: u64 = (x165 >> 8);
845 let x168: u8 = ((x167 & (0xff as u64)) as u8);
846 let x169: u64 = (x167 >> 8);
847 let x170: u8 = ((x169 & (0xff as u64)) as u8);
848 let x171: u64 = (x169 >> 8);
849 let x172: u8 = ((x171 & (0xff as u64)) as u8);
850 let x173: u64 = (x171 >> 8);
851 let x174: u8 = ((x173 & (0xff as u64)) as u8);
852 let x175: fiat_p521_u1 = ((x173 >> 8) as fiat_p521_u1);
853 *IndexConst(&mut out1).index_mut(0) = x44;
854 *IndexConst(&mut out1).index_mut(1) = x46;
855 *IndexConst(&mut out1).index_mut(2) = x48;
856 *IndexConst(&mut out1).index_mut(3) = x50;
857 *IndexConst(&mut out1).index_mut(4) = x52;
858 *IndexConst(&mut out1).index_mut(5) = x54;
859 *IndexConst(&mut out1).index_mut(6) = x56;
860 *IndexConst(&mut out1).index_mut(7) = x59;
861 *IndexConst(&mut out1).index_mut(8) = x61;
862 *IndexConst(&mut out1).index_mut(9) = x63;
863 *IndexConst(&mut out1).index_mut(10) = x65;
864 *IndexConst(&mut out1).index_mut(11) = x67;
865 *IndexConst(&mut out1).index_mut(12) = x69;
866 *IndexConst(&mut out1).index_mut(13) = x71;
867 *IndexConst(&mut out1).index_mut(14) = x74;
868 *IndexConst(&mut out1).index_mut(15) = x76;
869 *IndexConst(&mut out1).index_mut(16) = x78;
870 *IndexConst(&mut out1).index_mut(17) = x80;
871 *IndexConst(&mut out1).index_mut(18) = x82;
872 *IndexConst(&mut out1).index_mut(19) = x84;
873 *IndexConst(&mut out1).index_mut(20) = x86;
874 *IndexConst(&mut out1).index_mut(21) = x89;
875 *IndexConst(&mut out1).index_mut(22) = x91;
876 *IndexConst(&mut out1).index_mut(23) = x93;
877 *IndexConst(&mut out1).index_mut(24) = x95;
878 *IndexConst(&mut out1).index_mut(25) = x97;
879 *IndexConst(&mut out1).index_mut(26) = x99;
880 *IndexConst(&mut out1).index_mut(27) = x101;
881 *IndexConst(&mut out1).index_mut(28) = x102;
882 *IndexConst(&mut out1).index_mut(29) = x103;
883 *IndexConst(&mut out1).index_mut(30) = x105;
884 *IndexConst(&mut out1).index_mut(31) = x107;
885 *IndexConst(&mut out1).index_mut(32) = x109;
886 *IndexConst(&mut out1).index_mut(33) = x111;
887 *IndexConst(&mut out1).index_mut(34) = x113;
888 *IndexConst(&mut out1).index_mut(35) = x115;
889 *IndexConst(&mut out1).index_mut(36) = x118;
890 *IndexConst(&mut out1).index_mut(37) = x120;
891 *IndexConst(&mut out1).index_mut(38) = x122;
892 *IndexConst(&mut out1).index_mut(39) = x124;
893 *IndexConst(&mut out1).index_mut(40) = x126;
894 *IndexConst(&mut out1).index_mut(41) = x128;
895 *IndexConst(&mut out1).index_mut(42) = x130;
896 *IndexConst(&mut out1).index_mut(43) = x133;
897 *IndexConst(&mut out1).index_mut(44) = x135;
898 *IndexConst(&mut out1).index_mut(45) = x137;
899 *IndexConst(&mut out1).index_mut(46) = x139;
900 *IndexConst(&mut out1).index_mut(47) = x141;
901 *IndexConst(&mut out1).index_mut(48) = x143;
902 *IndexConst(&mut out1).index_mut(49) = x145;
903 *IndexConst(&mut out1).index_mut(50) = x148;
904 *IndexConst(&mut out1).index_mut(51) = x150;
905 *IndexConst(&mut out1).index_mut(52) = x152;
906 *IndexConst(&mut out1).index_mut(53) = x154;
907 *IndexConst(&mut out1).index_mut(54) = x156;
908 *IndexConst(&mut out1).index_mut(55) = x158;
909 *IndexConst(&mut out1).index_mut(56) = x160;
910 *IndexConst(&mut out1).index_mut(57) = x161;
911 *IndexConst(&mut out1).index_mut(58) = x162;
912 *IndexConst(&mut out1).index_mut(59) = x164;
913 *IndexConst(&mut out1).index_mut(60) = x166;
914 *IndexConst(&mut out1).index_mut(61) = x168;
915 *IndexConst(&mut out1).index_mut(62) = x170;
916 *IndexConst(&mut out1).index_mut(63) = x172;
917 *IndexConst(&mut out1).index_mut(64) = x174;
918 *IndexConst(&mut out1).index_mut(65) = (x175 as u8);
919}
920
921#[inline]
929pub const fn fiat_p521_from_bytes(mut out1: &mut fiat_p521_tight_field_element, arg1: &[u8; 66]) {
930 let x1: u64 = ((((*IndexConst(arg1).index(65)) as fiat_p521_u1) as u64) << 56);
931 let x2: u64 = (((*IndexConst(arg1).index(64)) as u64) << 48);
932 let x3: u64 = (((*IndexConst(arg1).index(63)) as u64) << 40);
933 let x4: u64 = (((*IndexConst(arg1).index(62)) as u64) << 32);
934 let x5: u64 = (((*IndexConst(arg1).index(61)) as u64) << 24);
935 let x6: u64 = (((*IndexConst(arg1).index(60)) as u64) << 16);
936 let x7: u64 = (((*IndexConst(arg1).index(59)) as u64) << 8);
937 let x8: u8 = (*IndexConst(arg1).index(58));
938 let x9: u64 = (((*IndexConst(arg1).index(57)) as u64) << 50);
939 let x10: u64 = (((*IndexConst(arg1).index(56)) as u64) << 42);
940 let x11: u64 = (((*IndexConst(arg1).index(55)) as u64) << 34);
941 let x12: u64 = (((*IndexConst(arg1).index(54)) as u64) << 26);
942 let x13: u64 = (((*IndexConst(arg1).index(53)) as u64) << 18);
943 let x14: u64 = (((*IndexConst(arg1).index(52)) as u64) << 10);
944 let x15: u64 = (((*IndexConst(arg1).index(51)) as u64) << 2);
945 let x16: u64 = (((*IndexConst(arg1).index(50)) as u64) << 52);
946 let x17: u64 = (((*IndexConst(arg1).index(49)) as u64) << 44);
947 let x18: u64 = (((*IndexConst(arg1).index(48)) as u64) << 36);
948 let x19: u64 = (((*IndexConst(arg1).index(47)) as u64) << 28);
949 let x20: u64 = (((*IndexConst(arg1).index(46)) as u64) << 20);
950 let x21: u64 = (((*IndexConst(arg1).index(45)) as u64) << 12);
951 let x22: u64 = (((*IndexConst(arg1).index(44)) as u64) << 4);
952 let x23: u64 = (((*IndexConst(arg1).index(43)) as u64) << 54);
953 let x24: u64 = (((*IndexConst(arg1).index(42)) as u64) << 46);
954 let x25: u64 = (((*IndexConst(arg1).index(41)) as u64) << 38);
955 let x26: u64 = (((*IndexConst(arg1).index(40)) as u64) << 30);
956 let x27: u64 = (((*IndexConst(arg1).index(39)) as u64) << 22);
957 let x28: u64 = (((*IndexConst(arg1).index(38)) as u64) << 14);
958 let x29: u64 = (((*IndexConst(arg1).index(37)) as u64) << 6);
959 let x30: u64 = (((*IndexConst(arg1).index(36)) as u64) << 56);
960 let x31: u64 = (((*IndexConst(arg1).index(35)) as u64) << 48);
961 let x32: u64 = (((*IndexConst(arg1).index(34)) as u64) << 40);
962 let x33: u64 = (((*IndexConst(arg1).index(33)) as u64) << 32);
963 let x34: u64 = (((*IndexConst(arg1).index(32)) as u64) << 24);
964 let x35: u64 = (((*IndexConst(arg1).index(31)) as u64) << 16);
965 let x36: u64 = (((*IndexConst(arg1).index(30)) as u64) << 8);
966 let x37: u8 = (*IndexConst(arg1).index(29));
967 let x38: u64 = (((*IndexConst(arg1).index(28)) as u64) << 50);
968 let x39: u64 = (((*IndexConst(arg1).index(27)) as u64) << 42);
969 let x40: u64 = (((*IndexConst(arg1).index(26)) as u64) << 34);
970 let x41: u64 = (((*IndexConst(arg1).index(25)) as u64) << 26);
971 let x42: u64 = (((*IndexConst(arg1).index(24)) as u64) << 18);
972 let x43: u64 = (((*IndexConst(arg1).index(23)) as u64) << 10);
973 let x44: u64 = (((*IndexConst(arg1).index(22)) as u64) << 2);
974 let x45: u64 = (((*IndexConst(arg1).index(21)) as u64) << 52);
975 let x46: u64 = (((*IndexConst(arg1).index(20)) as u64) << 44);
976 let x47: u64 = (((*IndexConst(arg1).index(19)) as u64) << 36);
977 let x48: u64 = (((*IndexConst(arg1).index(18)) as u64) << 28);
978 let x49: u64 = (((*IndexConst(arg1).index(17)) as u64) << 20);
979 let x50: u64 = (((*IndexConst(arg1).index(16)) as u64) << 12);
980 let x51: u64 = (((*IndexConst(arg1).index(15)) as u64) << 4);
981 let x52: u64 = (((*IndexConst(arg1).index(14)) as u64) << 54);
982 let x53: u64 = (((*IndexConst(arg1).index(13)) as u64) << 46);
983 let x54: u64 = (((*IndexConst(arg1).index(12)) as u64) << 38);
984 let x55: u64 = (((*IndexConst(arg1).index(11)) as u64) << 30);
985 let x56: u64 = (((*IndexConst(arg1).index(10)) as u64) << 22);
986 let x57: u64 = (((*IndexConst(arg1).index(9)) as u64) << 14);
987 let x58: u64 = (((*IndexConst(arg1).index(8)) as u64) << 6);
988 let x59: u64 = (((*IndexConst(arg1).index(7)) as u64) << 56);
989 let x60: u64 = (((*IndexConst(arg1).index(6)) as u64) << 48);
990 let x61: u64 = (((*IndexConst(arg1).index(5)) as u64) << 40);
991 let x62: u64 = (((*IndexConst(arg1).index(4)) as u64) << 32);
992 let x63: u64 = (((*IndexConst(arg1).index(3)) as u64) << 24);
993 let x64: u64 = (((*IndexConst(arg1).index(2)) as u64) << 16);
994 let x65: u64 = (((*IndexConst(arg1).index(1)) as u64) << 8);
995 let x66: u8 = (*IndexConst(arg1).index(0));
996 let x67: u64 = (x65 + (x66 as u64));
997 let x68: u64 = (x64 + x67);
998 let x69: u64 = (x63 + x68);
999 let x70: u64 = (x62 + x69);
1000 let x71: u64 = (x61 + x70);
1001 let x72: u64 = (x60 + x71);
1002 let x73: u64 = (x59 + x72);
1003 let x74: u64 = (x73 & 0x3ffffffffffffff);
1004 let x75: u8 = ((x73 >> 58) as u8);
1005 let x76: u64 = (x58 + (x75 as u64));
1006 let x77: u64 = (x57 + x76);
1007 let x78: u64 = (x56 + x77);
1008 let x79: u64 = (x55 + x78);
1009 let x80: u64 = (x54 + x79);
1010 let x81: u64 = (x53 + x80);
1011 let x82: u64 = (x52 + x81);
1012 let x83: u64 = (x82 & 0x3ffffffffffffff);
1013 let x84: u8 = ((x82 >> 58) as u8);
1014 let x85: u64 = (x51 + (x84 as u64));
1015 let x86: u64 = (x50 + x85);
1016 let x87: u64 = (x49 + x86);
1017 let x88: u64 = (x48 + x87);
1018 let x89: u64 = (x47 + x88);
1019 let x90: u64 = (x46 + x89);
1020 let x91: u64 = (x45 + x90);
1021 let x92: u64 = (x91 & 0x3ffffffffffffff);
1022 let x93: u8 = ((x91 >> 58) as u8);
1023 let x94: u64 = (x44 + (x93 as u64));
1024 let x95: u64 = (x43 + x94);
1025 let x96: u64 = (x42 + x95);
1026 let x97: u64 = (x41 + x96);
1027 let x98: u64 = (x40 + x97);
1028 let x99: u64 = (x39 + x98);
1029 let x100: u64 = (x38 + x99);
1030 let x101: u64 = (x36 + (x37 as u64));
1031 let x102: u64 = (x35 + x101);
1032 let x103: u64 = (x34 + x102);
1033 let x104: u64 = (x33 + x103);
1034 let x105: u64 = (x32 + x104);
1035 let x106: u64 = (x31 + x105);
1036 let x107: u64 = (x30 + x106);
1037 let x108: u64 = (x107 & 0x3ffffffffffffff);
1038 let x109: u8 = ((x107 >> 58) as u8);
1039 let x110: u64 = (x29 + (x109 as u64));
1040 let x111: u64 = (x28 + x110);
1041 let x112: u64 = (x27 + x111);
1042 let x113: u64 = (x26 + x112);
1043 let x114: u64 = (x25 + x113);
1044 let x115: u64 = (x24 + x114);
1045 let x116: u64 = (x23 + x115);
1046 let x117: u64 = (x116 & 0x3ffffffffffffff);
1047 let x118: u8 = ((x116 >> 58) as u8);
1048 let x119: u64 = (x22 + (x118 as u64));
1049 let x120: u64 = (x21 + x119);
1050 let x121: u64 = (x20 + x120);
1051 let x122: u64 = (x19 + x121);
1052 let x123: u64 = (x18 + x122);
1053 let x124: u64 = (x17 + x123);
1054 let x125: u64 = (x16 + x124);
1055 let x126: u64 = (x125 & 0x3ffffffffffffff);
1056 let x127: u8 = ((x125 >> 58) as u8);
1057 let x128: u64 = (x15 + (x127 as u64));
1058 let x129: u64 = (x14 + x128);
1059 let x130: u64 = (x13 + x129);
1060 let x131: u64 = (x12 + x130);
1061 let x132: u64 = (x11 + x131);
1062 let x133: u64 = (x10 + x132);
1063 let x134: u64 = (x9 + x133);
1064 let x135: u64 = (x7 + (x8 as u64));
1065 let x136: u64 = (x6 + x135);
1066 let x137: u64 = (x5 + x136);
1067 let x138: u64 = (x4 + x137);
1068 let x139: u64 = (x3 + x138);
1069 let x140: u64 = (x2 + x139);
1070 let x141: u64 = (x1 + x140);
1071 *IndexConst(&mut out1).index_mut(0) = x74;
1072 *IndexConst(&mut out1).index_mut(1) = x83;
1073 *IndexConst(&mut out1).index_mut(2) = x92;
1074 *IndexConst(&mut out1).index_mut(3) = x100;
1075 *IndexConst(&mut out1).index_mut(4) = x108;
1076 *IndexConst(&mut out1).index_mut(5) = x117;
1077 *IndexConst(&mut out1).index_mut(6) = x126;
1078 *IndexConst(&mut out1).index_mut(7) = x134;
1079 *IndexConst(&mut out1).index_mut(8) = x141;
1080}
1081
1082#[inline]
1088pub const fn fiat_p521_relax(mut out1: &mut fiat_p521_loose_field_element, arg1: &fiat_p521_tight_field_element) {
1089 let x1: u64 = (*IndexConst(arg1).index(0));
1090 let x2: u64 = (*IndexConst(arg1).index(1));
1091 let x3: u64 = (*IndexConst(arg1).index(2));
1092 let x4: u64 = (*IndexConst(arg1).index(3));
1093 let x5: u64 = (*IndexConst(arg1).index(4));
1094 let x6: u64 = (*IndexConst(arg1).index(5));
1095 let x7: u64 = (*IndexConst(arg1).index(6));
1096 let x8: u64 = (*IndexConst(arg1).index(7));
1097 let x9: u64 = (*IndexConst(arg1).index(8));
1098 *IndexConst(&mut out1).index_mut(0) = x1;
1099 *IndexConst(&mut out1).index_mut(1) = x2;
1100 *IndexConst(&mut out1).index_mut(2) = x3;
1101 *IndexConst(&mut out1).index_mut(3) = x4;
1102 *IndexConst(&mut out1).index_mut(4) = x5;
1103 *IndexConst(&mut out1).index_mut(5) = x6;
1104 *IndexConst(&mut out1).index_mut(6) = x7;
1105 *IndexConst(&mut out1).index_mut(7) = x8;
1106 *IndexConst(&mut out1).index_mut(8) = x9;
1107}