4 int x25519(unsigned char *q, const unsigned char *n, const unsigned
19 for (i = 0;i < 32;++i) e[i] = n[i];
30 for (pos = 254;pos >= 0;--pos) {
31 b = e[pos / 8] >> (pos & 7);
38 fe_sub(tmp0,x3,z3); /* qhasm: D = X3-Z3 */
39 fe_sub(tmp1,x2,z2); /* qhasm: B = X2-Z2 */
40 fe_add(x2,x2,z2); /* qhasm: A = X2+Z2 */
41 fe_add(z2,x3,z3); /* qhasm: C = X3+Z3 */
42 fe_mul(z3,tmp0,x2); /* qhasm: DA = D*A */
43 fe_mul(z2,z2,tmp1); /* qhasm: CB = C*B */
44 fe_sq(tmp0,tmp1); /* qhasm: BB = B^2 */
45 fe_sq(tmp1,x2); /* qhasm: AA = A^2 */
46 fe_add(x3,z3,z2); /* qhasm: t0 = DA+CB */
47 /* qhasm: assign x3 to t0 */
48 fe_sub(z2,z3,z2); /* qhasm: t1 = DA-CB */
49 fe_mul(x2,tmp1,tmp0); /* qhasm: X4 = AA*BB */
50 fe_sub(tmp1,tmp1,tmp0); /* qhasm: E = AA-BB */
51 fe_sq(z2,z2); /* qhasm: t2 = t1^2 */
52 fe_mul121666(z3,tmp1); /* qhasm: t3 = a24*E */
53 fe_sq(x3,x3); /* qhasm: X5 = t0^2 */
54 fe_add(tmp0,tmp0,z3); /* qhasm: t4 = BB+t3 */
55 fe_mul(z3,x1,z2); /* qhasm: Z5 = X1*t2 */
56 fe_mul(z2,tmp1,tmp0); /* qhasm: Z4 = E*t4 */