]> www.wagner.pp.ru Git - openssl-gost/engine.git/blob - ecp_id_GostR3410_2001_CryptoPro_B_ParamSet.c
[ecp] validation with coverity
[openssl-gost/engine.git] / ecp_id_GostR3410_2001_CryptoPro_B_ParamSet.c
1 /* Autogenerated: ECCKiila https://gitlab.com/nisec/ecckiila */
2 /*-
3  * MIT License
4  * 
5  * Copyright (c) 2020 Luis Rivera-Zamarripa, Jesús-Javier Chi-Domínguez, Billy Bob Brumley
6  * 
7  * Permission is hereby granted, free of charge, to any person obtaining a copy
8  * of this software and associated documentation files (the "Software"), to deal
9  * in the Software without restriction, including without limitation the rights
10  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
11  * copies of the Software, and to permit persons to whom the Software is
12  * furnished to do so, subject to the following conditions:
13  * 
14  * The above copyright notice and this permission notice shall be included in all
15  * copies or substantial portions of the Software.
16  * 
17  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
18  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
19  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
20  * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
21  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
22  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
23  * SOFTWARE.
24  */
25 #if defined(__SIZEOF_INT128__) && !defined(PEDANTIC)
26
27 #include <stdint.h>
28 #include <string.h>
29 #define LIMB_BITS 64
30 #define LIMB_CNT 4
31 /* Field elements */
32 typedef uint64_t fe_t[LIMB_CNT];
33 typedef uint64_t limb_t;
34
35 #ifdef OPENSSL_NO_ASM
36 #define FIAT_ID_GOSTR3410_2001_CRYPTOPRO_B_PARAMSET_NO_ASM
37 #endif
38
39 #define fe_copy(d, s) memcpy(d, s, sizeof(fe_t))
40 #define fe_set_zero(d) memset(d, 0, sizeof(fe_t))
41
42 /* Projective points */
43 typedef struct {
44     fe_t X;
45     fe_t Y;
46     fe_t Z;
47 } pt_prj_t;
48
49 /* Affine points */
50 typedef struct {
51     fe_t X;
52     fe_t Y;
53 } pt_aff_t;
54
55 /* BEGIN verbatim fiat code https://github.com/mit-plv/fiat-crypto */
56 /*-
57  * MIT License
58  *
59  * Copyright (c) 2020 the fiat-crypto authors (see the AUTHORS file)
60  *
61  * Permission is hereby granted, free of charge, to any person obtaining a copy
62  * of this software and associated documentation files (the "Software"), to deal
63  * in the Software without restriction, including without limitation the rights
64  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
65  * copies of the Software, and to permit persons to whom the Software is
66  * furnished to do so, subject to the following conditions:
67  *
68  * The above copyright notice and this permission notice shall be included in
69  * all copies or substantial portions of the Software.
70  *
71  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
72  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
73  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
74  * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
75  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
76  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
77  * SOFTWARE.
78  */
79
80 /* Autogenerated: word_by_word_montgomery --static --use-value-barrier id_GostR3410_2001_CryptoPro_B_ParamSet 64 '2^255 + 3225' */
81 /* curve description: id_GostR3410_2001_CryptoPro_B_ParamSet */
82 /* machine_wordsize = 64 (from "64") */
83 /* requested operations: (all) */
84 /* m = 0x8000000000000000000000000000000000000000000000000000000000000c99 (from "2^255 + 3225") */
85 /*                                                                    */
86 /* NOTE: In addition to the bounds specified above each function, all */
87 /*   functions synthesized for this Montgomery arithmetic require the */
88 /*   input to be strictly less than the prime modulus (m), and also   */
89 /*   require the input to be in the unique saturated representation.  */
90 /*   All functions also ensure that these two properties are true of  */
91 /*   return values.                                                   */
92 /*  */
93 /* Computed values: */
94 /* eval z = z[0] + (z[1] << 64) + (z[2] << 128) + (z[3] << 192) */
95 /* bytes_eval z = z[0] + (z[1] << 8) + (z[2] << 16) + (z[3] << 24) + (z[4] << 32) + (z[5] << 40) + (z[6] << 48) + (z[7] << 56) + (z[8] << 64) + (z[9] << 72) + (z[10] << 80) + (z[11] << 88) + (z[12] << 96) + (z[13] << 104) + (z[14] << 112) + (z[15] << 120) + (z[16] << 128) + (z[17] << 136) + (z[18] << 144) + (z[19] << 152) + (z[20] << 160) + (z[21] << 168) + (z[22] << 176) + (z[23] << 184) + (z[24] << 192) + (z[25] << 200) + (z[26] << 208) + (z[27] << 216) + (z[28] << 224) + (z[29] << 232) + (z[30] << 240) + (z[31] << 248) */
96
97 #include <stdint.h>
98 typedef unsigned char fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1;
99 typedef signed char fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1;
100 typedef signed __int128 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int128;
101 typedef unsigned __int128 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint128;
102
103 #if (-1 & 3) != 3
104 #error "This code only works on a two's complement system"
105 #endif
106
107 #if !defined(FIAT_ID_GOSTR3410_2001_CRYPTOPRO_B_PARAMSET_NO_ASM) && \
108     (defined(__GNUC__) || defined(__clang__))
109 static __inline__ uint64_t
110 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u64(uint64_t a) {
111     __asm__("" : "+r"(a) : /* no inputs */);
112     return a;
113 }
114 #else
115 #define fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u64(x) (x)
116 #endif
117
118 /*
119  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64 is an addition with carry.
120  * Postconditions:
121  *   out1 = (arg1 + arg2 + arg3) mod 2^64
122  *   out2 = ⌊(arg1 + arg2 + arg3) / 2^64⌋
123  *
124  * Input Bounds:
125  *   arg1: [0x0 ~> 0x1]
126  *   arg2: [0x0 ~> 0xffffffffffffffff]
127  *   arg3: [0x0 ~> 0xffffffffffffffff]
128  * Output Bounds:
129  *   out1: [0x0 ~> 0xffffffffffffffff]
130  *   out2: [0x0 ~> 0x1]
131  */
132 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
133     uint64_t *out1, fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 *out2,
134     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1, uint64_t arg2,
135     uint64_t arg3) {
136     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint128 x1;
137     uint64_t x2;
138     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x3;
139     x1 = ((arg1 + (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint128)arg2) +
140           arg3);
141     x2 = (uint64_t)(x1 & UINT64_C(0xffffffffffffffff));
142     x3 = (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1)(x1 >> 64);
143     *out1 = x2;
144     *out2 = x3;
145 }
146
147 /*
148  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64 is a subtraction with borrow.
149  * Postconditions:
150  *   out1 = (-arg1 + arg2 + -arg3) mod 2^64
151  *   out2 = -⌊(-arg1 + arg2 + -arg3) / 2^64⌋
152  *
153  * Input Bounds:
154  *   arg1: [0x0 ~> 0x1]
155  *   arg2: [0x0 ~> 0xffffffffffffffff]
156  *   arg3: [0x0 ~> 0xffffffffffffffff]
157  * Output Bounds:
158  *   out1: [0x0 ~> 0xffffffffffffffff]
159  *   out2: [0x0 ~> 0x1]
160  */
161 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
162     uint64_t *out1, fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 *out2,
163     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1, uint64_t arg2,
164     uint64_t arg3) {
165     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int128 x1;
166     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1 x2;
167     uint64_t x3;
168     x1 = ((arg2 - (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int128)arg1) -
169           arg3);
170     x2 = (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1)(x1 >> 64);
171     x3 = (uint64_t)(x1 & UINT64_C(0xffffffffffffffff));
172     *out1 = x3;
173     *out2 = (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1)(0x0 - x2);
174 }
175
176 /*
177  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64 is a multiplication, returning the full double-width result.
178  * Postconditions:
179  *   out1 = (arg1 * arg2) mod 2^64
180  *   out2 = ⌊arg1 * arg2 / 2^64⌋
181  *
182  * Input Bounds:
183  *   arg1: [0x0 ~> 0xffffffffffffffff]
184  *   arg2: [0x0 ~> 0xffffffffffffffff]
185  * Output Bounds:
186  *   out1: [0x0 ~> 0xffffffffffffffff]
187  *   out2: [0x0 ~> 0xffffffffffffffff]
188  */
189 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
190     uint64_t *out1, uint64_t *out2, uint64_t arg1, uint64_t arg2) {
191     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint128 x1;
192     uint64_t x2;
193     uint64_t x3;
194     x1 = ((fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint128)arg1 * arg2);
195     x2 = (uint64_t)(x1 & UINT64_C(0xffffffffffffffff));
196     x3 = (uint64_t)(x1 >> 64);
197     *out1 = x2;
198     *out2 = x3;
199 }
200
201 /*
202  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64 is a single-word conditional move.
203  * Postconditions:
204  *   out1 = (if arg1 = 0 then arg2 else arg3)
205  *
206  * Input Bounds:
207  *   arg1: [0x0 ~> 0x1]
208  *   arg2: [0x0 ~> 0xffffffffffffffff]
209  *   arg3: [0x0 ~> 0xffffffffffffffff]
210  * Output Bounds:
211  *   out1: [0x0 ~> 0xffffffffffffffff]
212  */
213 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
214     uint64_t *out1, fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1,
215     uint64_t arg2, uint64_t arg3) {
216     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x1;
217     uint64_t x2;
218     uint64_t x3;
219     x1 = (!(!arg1));
220     x2 = ((fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1)(0x0 - x1) &
221           UINT64_C(0xffffffffffffffff));
222     x3 =
223         ((fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u64(x2) &
224           arg3) |
225          (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u64((~x2)) &
226           arg2));
227     *out1 = x3;
228 }
229
230 /*
231  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul multiplies two field elements in the Montgomery domain.
232  * Preconditions:
233  *   0 ≤ eval arg1 < m
234  *   0 ≤ eval arg2 < m
235  * Postconditions:
236  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) * eval (from_montgomery arg2)) mod m
237  *   0 ≤ eval out1 < m
238  *
239  * Input Bounds:
240  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
241  *   arg2: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
242  * Output Bounds:
243  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
244  */
245 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(
246     uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
247     uint64_t x1;
248     uint64_t x2;
249     uint64_t x3;
250     uint64_t x4;
251     uint64_t x5;
252     uint64_t x6;
253     uint64_t x7;
254     uint64_t x8;
255     uint64_t x9;
256     uint64_t x10;
257     uint64_t x11;
258     uint64_t x12;
259     uint64_t x13;
260     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
261     uint64_t x15;
262     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x16;
263     uint64_t x17;
264     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x18;
265     uint64_t x19;
266     uint64_t x20;
267     uint64_t x21;
268     uint64_t x22;
269     uint64_t x23;
270     uint64_t x24;
271     uint64_t x25;
272     uint64_t x26;
273     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x27;
274     uint64_t x28;
275     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x29;
276     uint64_t x30;
277     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x31;
278     uint64_t x32;
279     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x33;
280     uint64_t x34;
281     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x35;
282     uint64_t x36;
283     uint64_t x37;
284     uint64_t x38;
285     uint64_t x39;
286     uint64_t x40;
287     uint64_t x41;
288     uint64_t x42;
289     uint64_t x43;
290     uint64_t x44;
291     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x45;
292     uint64_t x46;
293     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x47;
294     uint64_t x48;
295     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x49;
296     uint64_t x50;
297     uint64_t x51;
298     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x52;
299     uint64_t x53;
300     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x54;
301     uint64_t x55;
302     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x56;
303     uint64_t x57;
304     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x58;
305     uint64_t x59;
306     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x60;
307     uint64_t x61;
308     uint64_t x62;
309     uint64_t x63;
310     uint64_t x64;
311     uint64_t x65;
312     uint64_t x66;
313     uint64_t x67;
314     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x68;
315     uint64_t x69;
316     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x70;
317     uint64_t x71;
318     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x72;
319     uint64_t x73;
320     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x74;
321     uint64_t x75;
322     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x76;
323     uint64_t x77;
324     uint64_t x78;
325     uint64_t x79;
326     uint64_t x80;
327     uint64_t x81;
328     uint64_t x82;
329     uint64_t x83;
330     uint64_t x84;
331     uint64_t x85;
332     uint64_t x86;
333     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x87;
334     uint64_t x88;
335     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x89;
336     uint64_t x90;
337     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x91;
338     uint64_t x92;
339     uint64_t x93;
340     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x94;
341     uint64_t x95;
342     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x96;
343     uint64_t x97;
344     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x98;
345     uint64_t x99;
346     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x100;
347     uint64_t x101;
348     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x102;
349     uint64_t x103;
350     uint64_t x104;
351     uint64_t x105;
352     uint64_t x106;
353     uint64_t x107;
354     uint64_t x108;
355     uint64_t x109;
356     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x110;
357     uint64_t x111;
358     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x112;
359     uint64_t x113;
360     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x114;
361     uint64_t x115;
362     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x116;
363     uint64_t x117;
364     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x118;
365     uint64_t x119;
366     uint64_t x120;
367     uint64_t x121;
368     uint64_t x122;
369     uint64_t x123;
370     uint64_t x124;
371     uint64_t x125;
372     uint64_t x126;
373     uint64_t x127;
374     uint64_t x128;
375     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x129;
376     uint64_t x130;
377     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x131;
378     uint64_t x132;
379     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x133;
380     uint64_t x134;
381     uint64_t x135;
382     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x136;
383     uint64_t x137;
384     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x138;
385     uint64_t x139;
386     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x140;
387     uint64_t x141;
388     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x142;
389     uint64_t x143;
390     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x144;
391     uint64_t x145;
392     uint64_t x146;
393     uint64_t x147;
394     uint64_t x148;
395     uint64_t x149;
396     uint64_t x150;
397     uint64_t x151;
398     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x152;
399     uint64_t x153;
400     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x154;
401     uint64_t x155;
402     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x156;
403     uint64_t x157;
404     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x158;
405     uint64_t x159;
406     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x160;
407     uint64_t x161;
408     uint64_t x162;
409     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x163;
410     uint64_t x164;
411     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x165;
412     uint64_t x166;
413     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x167;
414     uint64_t x168;
415     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x169;
416     uint64_t x170;
417     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x171;
418     uint64_t x172;
419     uint64_t x173;
420     uint64_t x174;
421     uint64_t x175;
422     x1 = (arg1[1]);
423     x2 = (arg1[2]);
424     x3 = (arg1[3]);
425     x4 = (arg1[0]);
426     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x5, &x6, x4,
427                                                          (arg2[3]));
428     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x7, &x8, x4,
429                                                          (arg2[2]));
430     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x9, &x10, x4,
431                                                          (arg2[1]));
432     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x11, &x12, x4,
433                                                          (arg2[0]));
434     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x13, &x14, 0x0,
435                                                               x12, x9);
436     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x15, &x16, x14,
437                                                               x10, x7);
438     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x17, &x18, x16,
439                                                               x8, x5);
440     x19 = (x18 + x6);
441     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
442         &x20, &x21, x11, UINT64_C(0xbd667ab8a3347857));
443     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
444         &x22, &x23, x20, UINT64_C(0x8000000000000000));
445     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x24, &x25, x20,
446                                                          UINT16_C(0xc99));
447     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x26, &x27, 0x0,
448                                                               x11, x24);
449     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x28, &x29, x27,
450                                                               x13, x25);
451     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x30, &x31, x29,
452                                                               x15, 0x0);
453     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x32, &x33, x31,
454                                                               x17, x22);
455     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x34, &x35, x33,
456                                                               x19, x23);
457     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x36, &x37, x1,
458                                                          (arg2[3]));
459     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x38, &x39, x1,
460                                                          (arg2[2]));
461     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x40, &x41, x1,
462                                                          (arg2[1]));
463     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x42, &x43, x1,
464                                                          (arg2[0]));
465     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x44, &x45, 0x0,
466                                                               x43, x40);
467     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x46, &x47, x45,
468                                                               x41, x38);
469     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x48, &x49, x47,
470                                                               x39, x36);
471     x50 = (x49 + x37);
472     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x51, &x52, 0x0,
473                                                               x28, x42);
474     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x53, &x54, x52,
475                                                               x30, x44);
476     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x55, &x56, x54,
477                                                               x32, x46);
478     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x57, &x58, x56,
479                                                               x34, x48);
480     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x59, &x60, x58,
481                                                               x35, x50);
482     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
483         &x61, &x62, x51, UINT64_C(0xbd667ab8a3347857));
484     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
485         &x63, &x64, x61, UINT64_C(0x8000000000000000));
486     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x65, &x66, x61,
487                                                          UINT16_C(0xc99));
488     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x67, &x68, 0x0,
489                                                               x51, x65);
490     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x69, &x70, x68,
491                                                               x53, x66);
492     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x71, &x72, x70,
493                                                               x55, 0x0);
494     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x73, &x74, x72,
495                                                               x57, x63);
496     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x75, &x76, x74,
497                                                               x59, x64);
498     x77 = ((uint64_t)x76 + x60);
499     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x78, &x79, x2,
500                                                          (arg2[3]));
501     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x80, &x81, x2,
502                                                          (arg2[2]));
503     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x82, &x83, x2,
504                                                          (arg2[1]));
505     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x84, &x85, x2,
506                                                          (arg2[0]));
507     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x86, &x87, 0x0,
508                                                               x85, x82);
509     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x88, &x89, x87,
510                                                               x83, x80);
511     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x90, &x91, x89,
512                                                               x81, x78);
513     x92 = (x91 + x79);
514     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x93, &x94, 0x0,
515                                                               x69, x84);
516     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x95, &x96, x94,
517                                                               x71, x86);
518     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x97, &x98, x96,
519                                                               x73, x88);
520     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x99, &x100, x98,
521                                                               x75, x90);
522     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x101, &x102,
523                                                               x100, x77, x92);
524     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
525         &x103, &x104, x93, UINT64_C(0xbd667ab8a3347857));
526     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
527         &x105, &x106, x103, UINT64_C(0x8000000000000000));
528     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x107, &x108, x103,
529                                                          UINT16_C(0xc99));
530     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x109, &x110, 0x0,
531                                                               x93, x107);
532     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x111, &x112,
533                                                               x110, x95, x108);
534     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x113, &x114,
535                                                               x112, x97, 0x0);
536     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x115, &x116,
537                                                               x114, x99, x105);
538     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x117, &x118,
539                                                               x116, x101, x106);
540     x119 = ((uint64_t)x118 + x102);
541     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x120, &x121, x3,
542                                                          (arg2[3]));
543     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x122, &x123, x3,
544                                                          (arg2[2]));
545     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x124, &x125, x3,
546                                                          (arg2[1]));
547     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x126, &x127, x3,
548                                                          (arg2[0]));
549     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x128, &x129, 0x0,
550                                                               x127, x124);
551     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x130, &x131,
552                                                               x129, x125, x122);
553     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x132, &x133,
554                                                               x131, x123, x120);
555     x134 = (x133 + x121);
556     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x135, &x136, 0x0,
557                                                               x111, x126);
558     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x137, &x138,
559                                                               x136, x113, x128);
560     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x139, &x140,
561                                                               x138, x115, x130);
562     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x141, &x142,
563                                                               x140, x117, x132);
564     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x143, &x144,
565                                                               x142, x119, x134);
566     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
567         &x145, &x146, x135, UINT64_C(0xbd667ab8a3347857));
568     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
569         &x147, &x148, x145, UINT64_C(0x8000000000000000));
570     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x149, &x150, x145,
571                                                          UINT16_C(0xc99));
572     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x151, &x152, 0x0,
573                                                               x135, x149);
574     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x153, &x154,
575                                                               x152, x137, x150);
576     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x155, &x156,
577                                                               x154, x139, 0x0);
578     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x157, &x158,
579                                                               x156, x141, x147);
580     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x159, &x160,
581                                                               x158, x143, x148);
582     x161 = ((uint64_t)x160 + x144);
583     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
584         &x162, &x163, 0x0, x153, UINT16_C(0xc99));
585     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x164, &x165,
586                                                                x163, x155, 0x0);
587     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x166, &x167,
588                                                                x165, x157, 0x0);
589     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
590         &x168, &x169, x167, x159, UINT64_C(0x8000000000000000));
591     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x170, &x171,
592                                                                x169, x161, 0x0);
593     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x172, x171, x162,
594                                                             x153);
595     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x173, x171, x164,
596                                                             x155);
597     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x174, x171, x166,
598                                                             x157);
599     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x175, x171, x168,
600                                                             x159);
601     out1[0] = x172;
602     out1[1] = x173;
603     out1[2] = x174;
604     out1[3] = x175;
605 }
606
607 /*
608  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square squares a field element in the Montgomery domain.
609  * Preconditions:
610  *   0 ≤ eval arg1 < m
611  * Postconditions:
612  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) * eval (from_montgomery arg1)) mod m
613  *   0 ≤ eval out1 < m
614  *
615  * Input Bounds:
616  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
617  * Output Bounds:
618  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
619  */
620 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(
621     uint64_t out1[4], const uint64_t arg1[4]) {
622     uint64_t x1;
623     uint64_t x2;
624     uint64_t x3;
625     uint64_t x4;
626     uint64_t x5;
627     uint64_t x6;
628     uint64_t x7;
629     uint64_t x8;
630     uint64_t x9;
631     uint64_t x10;
632     uint64_t x11;
633     uint64_t x12;
634     uint64_t x13;
635     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
636     uint64_t x15;
637     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x16;
638     uint64_t x17;
639     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x18;
640     uint64_t x19;
641     uint64_t x20;
642     uint64_t x21;
643     uint64_t x22;
644     uint64_t x23;
645     uint64_t x24;
646     uint64_t x25;
647     uint64_t x26;
648     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x27;
649     uint64_t x28;
650     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x29;
651     uint64_t x30;
652     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x31;
653     uint64_t x32;
654     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x33;
655     uint64_t x34;
656     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x35;
657     uint64_t x36;
658     uint64_t x37;
659     uint64_t x38;
660     uint64_t x39;
661     uint64_t x40;
662     uint64_t x41;
663     uint64_t x42;
664     uint64_t x43;
665     uint64_t x44;
666     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x45;
667     uint64_t x46;
668     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x47;
669     uint64_t x48;
670     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x49;
671     uint64_t x50;
672     uint64_t x51;
673     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x52;
674     uint64_t x53;
675     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x54;
676     uint64_t x55;
677     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x56;
678     uint64_t x57;
679     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x58;
680     uint64_t x59;
681     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x60;
682     uint64_t x61;
683     uint64_t x62;
684     uint64_t x63;
685     uint64_t x64;
686     uint64_t x65;
687     uint64_t x66;
688     uint64_t x67;
689     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x68;
690     uint64_t x69;
691     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x70;
692     uint64_t x71;
693     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x72;
694     uint64_t x73;
695     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x74;
696     uint64_t x75;
697     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x76;
698     uint64_t x77;
699     uint64_t x78;
700     uint64_t x79;
701     uint64_t x80;
702     uint64_t x81;
703     uint64_t x82;
704     uint64_t x83;
705     uint64_t x84;
706     uint64_t x85;
707     uint64_t x86;
708     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x87;
709     uint64_t x88;
710     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x89;
711     uint64_t x90;
712     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x91;
713     uint64_t x92;
714     uint64_t x93;
715     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x94;
716     uint64_t x95;
717     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x96;
718     uint64_t x97;
719     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x98;
720     uint64_t x99;
721     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x100;
722     uint64_t x101;
723     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x102;
724     uint64_t x103;
725     uint64_t x104;
726     uint64_t x105;
727     uint64_t x106;
728     uint64_t x107;
729     uint64_t x108;
730     uint64_t x109;
731     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x110;
732     uint64_t x111;
733     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x112;
734     uint64_t x113;
735     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x114;
736     uint64_t x115;
737     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x116;
738     uint64_t x117;
739     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x118;
740     uint64_t x119;
741     uint64_t x120;
742     uint64_t x121;
743     uint64_t x122;
744     uint64_t x123;
745     uint64_t x124;
746     uint64_t x125;
747     uint64_t x126;
748     uint64_t x127;
749     uint64_t x128;
750     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x129;
751     uint64_t x130;
752     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x131;
753     uint64_t x132;
754     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x133;
755     uint64_t x134;
756     uint64_t x135;
757     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x136;
758     uint64_t x137;
759     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x138;
760     uint64_t x139;
761     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x140;
762     uint64_t x141;
763     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x142;
764     uint64_t x143;
765     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x144;
766     uint64_t x145;
767     uint64_t x146;
768     uint64_t x147;
769     uint64_t x148;
770     uint64_t x149;
771     uint64_t x150;
772     uint64_t x151;
773     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x152;
774     uint64_t x153;
775     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x154;
776     uint64_t x155;
777     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x156;
778     uint64_t x157;
779     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x158;
780     uint64_t x159;
781     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x160;
782     uint64_t x161;
783     uint64_t x162;
784     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x163;
785     uint64_t x164;
786     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x165;
787     uint64_t x166;
788     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x167;
789     uint64_t x168;
790     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x169;
791     uint64_t x170;
792     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x171;
793     uint64_t x172;
794     uint64_t x173;
795     uint64_t x174;
796     uint64_t x175;
797     x1 = (arg1[1]);
798     x2 = (arg1[2]);
799     x3 = (arg1[3]);
800     x4 = (arg1[0]);
801     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x5, &x6, x4,
802                                                          (arg1[3]));
803     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x7, &x8, x4,
804                                                          (arg1[2]));
805     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x9, &x10, x4,
806                                                          (arg1[1]));
807     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x11, &x12, x4,
808                                                          (arg1[0]));
809     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x13, &x14, 0x0,
810                                                               x12, x9);
811     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x15, &x16, x14,
812                                                               x10, x7);
813     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x17, &x18, x16,
814                                                               x8, x5);
815     x19 = (x18 + x6);
816     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
817         &x20, &x21, x11, UINT64_C(0xbd667ab8a3347857));
818     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
819         &x22, &x23, x20, UINT64_C(0x8000000000000000));
820     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x24, &x25, x20,
821                                                          UINT16_C(0xc99));
822     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x26, &x27, 0x0,
823                                                               x11, x24);
824     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x28, &x29, x27,
825                                                               x13, x25);
826     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x30, &x31, x29,
827                                                               x15, 0x0);
828     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x32, &x33, x31,
829                                                               x17, x22);
830     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x34, &x35, x33,
831                                                               x19, x23);
832     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x36, &x37, x1,
833                                                          (arg1[3]));
834     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x38, &x39, x1,
835                                                          (arg1[2]));
836     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x40, &x41, x1,
837                                                          (arg1[1]));
838     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x42, &x43, x1,
839                                                          (arg1[0]));
840     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x44, &x45, 0x0,
841                                                               x43, x40);
842     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x46, &x47, x45,
843                                                               x41, x38);
844     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x48, &x49, x47,
845                                                               x39, x36);
846     x50 = (x49 + x37);
847     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x51, &x52, 0x0,
848                                                               x28, x42);
849     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x53, &x54, x52,
850                                                               x30, x44);
851     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x55, &x56, x54,
852                                                               x32, x46);
853     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x57, &x58, x56,
854                                                               x34, x48);
855     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x59, &x60, x58,
856                                                               x35, x50);
857     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
858         &x61, &x62, x51, UINT64_C(0xbd667ab8a3347857));
859     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
860         &x63, &x64, x61, UINT64_C(0x8000000000000000));
861     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x65, &x66, x61,
862                                                          UINT16_C(0xc99));
863     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x67, &x68, 0x0,
864                                                               x51, x65);
865     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x69, &x70, x68,
866                                                               x53, x66);
867     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x71, &x72, x70,
868                                                               x55, 0x0);
869     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x73, &x74, x72,
870                                                               x57, x63);
871     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x75, &x76, x74,
872                                                               x59, x64);
873     x77 = ((uint64_t)x76 + x60);
874     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x78, &x79, x2,
875                                                          (arg1[3]));
876     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x80, &x81, x2,
877                                                          (arg1[2]));
878     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x82, &x83, x2,
879                                                          (arg1[1]));
880     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x84, &x85, x2,
881                                                          (arg1[0]));
882     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x86, &x87, 0x0,
883                                                               x85, x82);
884     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x88, &x89, x87,
885                                                               x83, x80);
886     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x90, &x91, x89,
887                                                               x81, x78);
888     x92 = (x91 + x79);
889     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x93, &x94, 0x0,
890                                                               x69, x84);
891     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x95, &x96, x94,
892                                                               x71, x86);
893     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x97, &x98, x96,
894                                                               x73, x88);
895     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x99, &x100, x98,
896                                                               x75, x90);
897     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x101, &x102,
898                                                               x100, x77, x92);
899     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
900         &x103, &x104, x93, UINT64_C(0xbd667ab8a3347857));
901     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
902         &x105, &x106, x103, UINT64_C(0x8000000000000000));
903     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x107, &x108, x103,
904                                                          UINT16_C(0xc99));
905     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x109, &x110, 0x0,
906                                                               x93, x107);
907     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x111, &x112,
908                                                               x110, x95, x108);
909     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x113, &x114,
910                                                               x112, x97, 0x0);
911     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x115, &x116,
912                                                               x114, x99, x105);
913     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x117, &x118,
914                                                               x116, x101, x106);
915     x119 = ((uint64_t)x118 + x102);
916     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x120, &x121, x3,
917                                                          (arg1[3]));
918     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x122, &x123, x3,
919                                                          (arg1[2]));
920     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x124, &x125, x3,
921                                                          (arg1[1]));
922     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x126, &x127, x3,
923                                                          (arg1[0]));
924     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x128, &x129, 0x0,
925                                                               x127, x124);
926     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x130, &x131,
927                                                               x129, x125, x122);
928     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x132, &x133,
929                                                               x131, x123, x120);
930     x134 = (x133 + x121);
931     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x135, &x136, 0x0,
932                                                               x111, x126);
933     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x137, &x138,
934                                                               x136, x113, x128);
935     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x139, &x140,
936                                                               x138, x115, x130);
937     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x141, &x142,
938                                                               x140, x117, x132);
939     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x143, &x144,
940                                                               x142, x119, x134);
941     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
942         &x145, &x146, x135, UINT64_C(0xbd667ab8a3347857));
943     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
944         &x147, &x148, x145, UINT64_C(0x8000000000000000));
945     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x149, &x150, x145,
946                                                          UINT16_C(0xc99));
947     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x151, &x152, 0x0,
948                                                               x135, x149);
949     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x153, &x154,
950                                                               x152, x137, x150);
951     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x155, &x156,
952                                                               x154, x139, 0x0);
953     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x157, &x158,
954                                                               x156, x141, x147);
955     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x159, &x160,
956                                                               x158, x143, x148);
957     x161 = ((uint64_t)x160 + x144);
958     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
959         &x162, &x163, 0x0, x153, UINT16_C(0xc99));
960     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x164, &x165,
961                                                                x163, x155, 0x0);
962     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x166, &x167,
963                                                                x165, x157, 0x0);
964     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
965         &x168, &x169, x167, x159, UINT64_C(0x8000000000000000));
966     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x170, &x171,
967                                                                x169, x161, 0x0);
968     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x172, x171, x162,
969                                                             x153);
970     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x173, x171, x164,
971                                                             x155);
972     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x174, x171, x166,
973                                                             x157);
974     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x175, x171, x168,
975                                                             x159);
976     out1[0] = x172;
977     out1[1] = x173;
978     out1[2] = x174;
979     out1[3] = x175;
980 }
981
982 /*
983  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add adds two field elements in the Montgomery domain.
984  * Preconditions:
985  *   0 ≤ eval arg1 < m
986  *   0 ≤ eval arg2 < m
987  * Postconditions:
988  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) + eval (from_montgomery arg2)) mod m
989  *   0 ≤ eval out1 < m
990  *
991  * Input Bounds:
992  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
993  *   arg2: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
994  * Output Bounds:
995  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
996  */
997 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(
998     uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
999     uint64_t x1;
1000     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x2;
1001     uint64_t x3;
1002     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x4;
1003     uint64_t x5;
1004     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x6;
1005     uint64_t x7;
1006     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x8;
1007     uint64_t x9;
1008     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x10;
1009     uint64_t x11;
1010     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x12;
1011     uint64_t x13;
1012     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
1013     uint64_t x15;
1014     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x16;
1015     uint64_t x17;
1016     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x18;
1017     uint64_t x19;
1018     uint64_t x20;
1019     uint64_t x21;
1020     uint64_t x22;
1021     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1022         &x1, &x2, 0x0, (arg1[0]), (arg2[0]));
1023     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1024         &x3, &x4, x2, (arg1[1]), (arg2[1]));
1025     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1026         &x5, &x6, x4, (arg1[2]), (arg2[2]));
1027     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1028         &x7, &x8, x6, (arg1[3]), (arg2[3]));
1029     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1030         &x9, &x10, 0x0, x1, UINT16_C(0xc99));
1031     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x11, &x12, x10,
1032                                                                x3, 0x0);
1033     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x13, &x14, x12,
1034                                                                x5, 0x0);
1035     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1036         &x15, &x16, x14, x7, UINT64_C(0x8000000000000000));
1037     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x17, &x18, x16,
1038                                                                x8, 0x0);
1039     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x19, x18, x9, x1);
1040     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x20, x18, x11, x3);
1041     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x21, x18, x13, x5);
1042     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x22, x18, x15, x7);
1043     out1[0] = x19;
1044     out1[1] = x20;
1045     out1[2] = x21;
1046     out1[3] = x22;
1047 }
1048
1049 /*
1050  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub subtracts two field elements in the Montgomery domain.
1051  * Preconditions:
1052  *   0 ≤ eval arg1 < m
1053  *   0 ≤ eval arg2 < m
1054  * Postconditions:
1055  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) - eval (from_montgomery arg2)) mod m
1056  *   0 ≤ eval out1 < m
1057  *
1058  * Input Bounds:
1059  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1060  *   arg2: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1061  * Output Bounds:
1062  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1063  */
1064 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(
1065     uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
1066     uint64_t x1;
1067     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x2;
1068     uint64_t x3;
1069     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x4;
1070     uint64_t x5;
1071     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x6;
1072     uint64_t x7;
1073     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x8;
1074     uint64_t x9;
1075     uint64_t x10;
1076     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x11;
1077     uint64_t x12;
1078     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x13;
1079     uint64_t x14;
1080     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x15;
1081     uint64_t x16;
1082     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x17;
1083     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1084         &x1, &x2, 0x0, (arg1[0]), (arg2[0]));
1085     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1086         &x3, &x4, x2, (arg1[1]), (arg2[1]));
1087     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1088         &x5, &x6, x4, (arg1[2]), (arg2[2]));
1089     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1090         &x7, &x8, x6, (arg1[3]), (arg2[3]));
1091     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
1092         &x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
1093     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1094         &x10, &x11, 0x0, x1, (x9 & UINT16_C(0xc99)));
1095     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x12, &x13, x11,
1096                                                               x3, 0x0);
1097     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x14, &x15, x13,
1098                                                               x5, 0x0);
1099     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1100         &x16, &x17, x15, x7, (x9 & UINT64_C(0x8000000000000000)));
1101     out1[0] = x10;
1102     out1[1] = x12;
1103     out1[2] = x14;
1104     out1[3] = x16;
1105 }
1106
1107 /*
1108  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp negates a field element in the Montgomery domain.
1109  * Preconditions:
1110  *   0 ≤ eval arg1 < m
1111  * Postconditions:
1112  *   eval (from_montgomery out1) mod m = -eval (from_montgomery arg1) mod m
1113  *   0 ≤ eval out1 < m
1114  *
1115  * Input Bounds:
1116  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1117  * Output Bounds:
1118  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1119  */
1120 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(
1121     uint64_t out1[4], const uint64_t arg1[4]) {
1122     uint64_t x1;
1123     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x2;
1124     uint64_t x3;
1125     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x4;
1126     uint64_t x5;
1127     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x6;
1128     uint64_t x7;
1129     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x8;
1130     uint64_t x9;
1131     uint64_t x10;
1132     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x11;
1133     uint64_t x12;
1134     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x13;
1135     uint64_t x14;
1136     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x15;
1137     uint64_t x16;
1138     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x17;
1139     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x1, &x2, 0x0,
1140                                                                0x0, (arg1[0]));
1141     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x3, &x4, x2,
1142                                                                0x0, (arg1[1]));
1143     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x5, &x6, x4,
1144                                                                0x0, (arg1[2]));
1145     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x7, &x8, x6,
1146                                                                0x0, (arg1[3]));
1147     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
1148         &x9, x8, 0x0, UINT64_C(0xffffffffffffffff));
1149     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1150         &x10, &x11, 0x0, x1, (x9 & UINT16_C(0xc99)));
1151     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x12, &x13, x11,
1152                                                               x3, 0x0);
1153     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x14, &x15, x13,
1154                                                               x5, 0x0);
1155     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1156         &x16, &x17, x15, x7, (x9 & UINT64_C(0x8000000000000000)));
1157     out1[0] = x10;
1158     out1[1] = x12;
1159     out1[2] = x14;
1160     out1[3] = x16;
1161 }
1162
1163 /*
1164  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery translates a field element out of the Montgomery domain.
1165  * Preconditions:
1166  *   0 ≤ eval arg1 < m
1167  * Postconditions:
1168  *   eval out1 mod m = (eval arg1 * ((2^64)⁻¹ mod m)^4) mod m
1169  *   0 ≤ eval out1 < m
1170  *
1171  * Input Bounds:
1172  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1173  * Output Bounds:
1174  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1175  */
1176 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(
1177     uint64_t out1[4], const uint64_t arg1[4]) {
1178     uint64_t x1;
1179     uint64_t x2;
1180     uint64_t x3;
1181     uint64_t x4;
1182     uint64_t x5;
1183     uint64_t x6;
1184     uint64_t x7;
1185     uint64_t x8;
1186     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x9;
1187     uint64_t x10;
1188     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x11;
1189     uint64_t x12;
1190     uint64_t x13;
1191     uint64_t x14;
1192     uint64_t x15;
1193     uint64_t x16;
1194     uint64_t x17;
1195     uint64_t x18;
1196     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x19;
1197     uint64_t x20;
1198     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x21;
1199     uint64_t x22;
1200     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x23;
1201     uint64_t x24;
1202     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x25;
1203     uint64_t x26;
1204     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x27;
1205     uint64_t x28;
1206     uint64_t x29;
1207     uint64_t x30;
1208     uint64_t x31;
1209     uint64_t x32;
1210     uint64_t x33;
1211     uint64_t x34;
1212     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x35;
1213     uint64_t x36;
1214     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x37;
1215     uint64_t x38;
1216     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x39;
1217     uint64_t x40;
1218     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x41;
1219     uint64_t x42;
1220     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x43;
1221     uint64_t x44;
1222     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x45;
1223     uint64_t x46;
1224     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x47;
1225     uint64_t x48;
1226     uint64_t x49;
1227     uint64_t x50;
1228     uint64_t x51;
1229     uint64_t x52;
1230     uint64_t x53;
1231     uint64_t x54;
1232     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x55;
1233     uint64_t x56;
1234     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x57;
1235     uint64_t x58;
1236     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x59;
1237     uint64_t x60;
1238     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x61;
1239     uint64_t x62;
1240     uint64_t x63;
1241     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x64;
1242     uint64_t x65;
1243     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x66;
1244     uint64_t x67;
1245     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x68;
1246     uint64_t x69;
1247     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x70;
1248     uint64_t x71;
1249     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x72;
1250     uint64_t x73;
1251     uint64_t x74;
1252     uint64_t x75;
1253     uint64_t x76;
1254     x1 = (arg1[0]);
1255     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1256         &x2, &x3, x1, UINT64_C(0xbd667ab8a3347857));
1257     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1258         &x4, &x5, x2, UINT64_C(0x8000000000000000));
1259     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x6, &x7, x2,
1260                                                          UINT16_C(0xc99));
1261     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x8, &x9, 0x0, x1,
1262                                                               x6);
1263     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1264         &x10, &x11, 0x0, (x9 + x7), (arg1[1]));
1265     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1266         &x12, &x13, x10, UINT64_C(0xbd667ab8a3347857));
1267     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1268         &x14, &x15, x12, UINT64_C(0x8000000000000000));
1269     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x16, &x17, x12,
1270                                                          UINT16_C(0xc99));
1271     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x18, &x19, 0x0,
1272                                                               x5, x14);
1273     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x20, &x21, 0x0,
1274                                                               x10, x16);
1275     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1276         &x22, &x23, 0x0, (((uint64_t)x21 + x11) + x17), (arg1[2]));
1277     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x24, &x25, x23,
1278                                                               x4, 0x0);
1279     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x26, &x27, x25,
1280                                                               x18, 0x0);
1281     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1282         &x28, &x29, x22, UINT64_C(0xbd667ab8a3347857));
1283     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1284         &x30, &x31, x28, UINT64_C(0x8000000000000000));
1285     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x32, &x33, x28,
1286                                                          UINT16_C(0xc99));
1287     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x34, &x35, 0x0,
1288                                                               x22, x32);
1289     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x36, &x37, x35,
1290                                                               x24, x33);
1291     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x38, &x39, x37,
1292                                                               x26, 0x0);
1293     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1294         &x40, &x41, x39, (x27 + (x19 + x15)), x30);
1295     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x42, &x43, 0x0,
1296                                                               x36, (arg1[3]));
1297     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x44, &x45, x43,
1298                                                               x38, 0x0);
1299     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x46, &x47, x45,
1300                                                               x40, 0x0);
1301     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1302         &x48, &x49, x42, UINT64_C(0xbd667ab8a3347857));
1303     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1304         &x50, &x51, x48, UINT64_C(0x8000000000000000));
1305     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x52, &x53, x48,
1306                                                          UINT16_C(0xc99));
1307     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x54, &x55, 0x0,
1308                                                               x42, x52);
1309     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x56, &x57, x55,
1310                                                               x44, x53);
1311     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x58, &x59, x57,
1312                                                               x46, 0x0);
1313     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1314         &x60, &x61, x59, (x47 + (x41 + x31)), x50);
1315     x62 = (x61 + x51);
1316     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1317         &x63, &x64, 0x0, x56, UINT16_C(0xc99));
1318     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x65, &x66, x64,
1319                                                                x58, 0x0);
1320     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x67, &x68, x66,
1321                                                                x60, 0x0);
1322     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1323         &x69, &x70, x68, x62, UINT64_C(0x8000000000000000));
1324     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x71, &x72, x70,
1325                                                                0x0, 0x0);
1326     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x73, x72, x63,
1327                                                             x56);
1328     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x74, x72, x65,
1329                                                             x58);
1330     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x75, x72, x67,
1331                                                             x60);
1332     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x76, x72, x69,
1333                                                             x62);
1334     out1[0] = x73;
1335     out1[1] = x74;
1336     out1[2] = x75;
1337     out1[3] = x76;
1338 }
1339
1340 /*
1341  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery translates a field element into the Montgomery domain.
1342  * Preconditions:
1343  *   0 ≤ eval arg1 < m
1344  * Postconditions:
1345  *   eval (from_montgomery out1) mod m = eval arg1 mod m
1346  *   0 ≤ eval out1 < m
1347  *
1348  * Input Bounds:
1349  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1350  * Output Bounds:
1351  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1352  */
1353 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(
1354     uint64_t out1[4], const uint64_t arg1[4]) {
1355     uint64_t x1;
1356     uint64_t x2;
1357     uint64_t x3;
1358     uint64_t x4;
1359     uint64_t x5;
1360     uint64_t x6;
1361     uint64_t x7;
1362     uint64_t x8;
1363     uint64_t x9;
1364     uint64_t x10;
1365     uint64_t x11;
1366     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x12;
1367     uint64_t x13;
1368     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
1369     uint64_t x15;
1370     uint64_t x16;
1371     uint64_t x17;
1372     uint64_t x18;
1373     uint64_t x19;
1374     uint64_t x20;
1375     uint64_t x21;
1376     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x22;
1377     uint64_t x23;
1378     uint64_t x24;
1379     uint64_t x25;
1380     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x26;
1381     uint64_t x27;
1382     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x28;
1383     uint64_t x29;
1384     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x30;
1385     uint64_t x31;
1386     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x32;
1387     uint64_t x33;
1388     uint64_t x34;
1389     uint64_t x35;
1390     uint64_t x36;
1391     uint64_t x37;
1392     uint64_t x38;
1393     uint64_t x39;
1394     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x40;
1395     uint64_t x41;
1396     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x42;
1397     uint64_t x43;
1398     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x44;
1399     uint64_t x45;
1400     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x46;
1401     uint64_t x47;
1402     uint64_t x48;
1403     uint64_t x49;
1404     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x50;
1405     uint64_t x51;
1406     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x52;
1407     uint64_t x53;
1408     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x54;
1409     uint64_t x55;
1410     uint64_t x56;
1411     uint64_t x57;
1412     uint64_t x58;
1413     uint64_t x59;
1414     uint64_t x60;
1415     uint64_t x61;
1416     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x62;
1417     uint64_t x63;
1418     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x64;
1419     uint64_t x65;
1420     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x66;
1421     uint64_t x67;
1422     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x68;
1423     uint64_t x69;
1424     uint64_t x70;
1425     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x71;
1426     uint64_t x72;
1427     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x73;
1428     uint64_t x74;
1429     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x75;
1430     uint64_t x76;
1431     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x77;
1432     uint64_t x78;
1433     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x79;
1434     uint64_t x80;
1435     uint64_t x81;
1436     uint64_t x82;
1437     uint64_t x83;
1438     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x1, &x2, (arg1[0]),
1439                                                          UINT32_C(0x27acdc4));
1440     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1441         &x3, &x4, x1, UINT64_C(0xbd667ab8a3347857));
1442     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1443         &x5, &x6, x3, UINT64_C(0x8000000000000000));
1444     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x7, &x8, x3,
1445                                                          UINT16_C(0xc99));
1446     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x9, &x10, (arg1[1]),
1447                                                          UINT32_C(0x27acdc4));
1448     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x11, &x12, 0x0,
1449                                                               x1, x7);
1450     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1451         &x13, &x14, 0x0, ((x12 + x2) + x8), x9);
1452     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1453         &x15, &x16, x13, UINT64_C(0xbd667ab8a3347857));
1454     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1455         &x17, &x18, x15, UINT64_C(0x8000000000000000));
1456     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x19, &x20, x15,
1457                                                          UINT16_C(0xc99));
1458     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x21, &x22, 0x0,
1459                                                               x6, x17);
1460     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x23, &x24, (arg1[2]),
1461                                                          UINT32_C(0x27acdc4));
1462     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x25, &x26, 0x0,
1463                                                               x13, x19);
1464     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1465         &x27, &x28, 0x0, ((x26 + (x14 + x10)) + x20), x23);
1466     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x29, &x30, x28,
1467                                                               x5, x24);
1468     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x31, &x32, x30,
1469                                                               x21, 0x0);
1470     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1471         &x33, &x34, x27, UINT64_C(0xbd667ab8a3347857));
1472     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1473         &x35, &x36, x33, UINT64_C(0x8000000000000000));
1474     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x37, &x38, x33,
1475                                                          UINT16_C(0xc99));
1476     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x39, &x40, 0x0,
1477                                                               x27, x37);
1478     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x41, &x42, x40,
1479                                                               x29, x38);
1480     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x43, &x44, x42,
1481                                                               x31, 0x0);
1482     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1483         &x45, &x46, x44, (x32 + (x22 + x18)), x35);
1484     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x47, &x48, (arg1[3]),
1485                                                          UINT32_C(0x27acdc4));
1486     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x49, &x50, 0x0,
1487                                                               x41, x47);
1488     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x51, &x52, x50,
1489                                                               x43, x48);
1490     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x53, &x54, x52,
1491                                                               x45, 0x0);
1492     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1493         &x55, &x56, x49, UINT64_C(0xbd667ab8a3347857));
1494     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(
1495         &x57, &x58, x55, UINT64_C(0x8000000000000000));
1496     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u64(&x59, &x60, x55,
1497                                                          UINT16_C(0xc99));
1498     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x61, &x62, 0x0,
1499                                                               x49, x59);
1500     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x63, &x64, x62,
1501                                                               x51, x60);
1502     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(&x65, &x66, x64,
1503                                                               x53, 0x0);
1504     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u64(
1505         &x67, &x68, x66, (x54 + (x46 + x36)), x57);
1506     x69 = (x68 + x58);
1507     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1508         &x70, &x71, 0x0, x63, UINT16_C(0xc99));
1509     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x72, &x73, x71,
1510                                                                x65, 0x0);
1511     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x74, &x75, x73,
1512                                                                x67, 0x0);
1513     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(
1514         &x76, &x77, x75, x69, UINT64_C(0x8000000000000000));
1515     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u64(&x78, &x79, x77,
1516                                                                0x0, 0x0);
1517     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x80, x79, x70,
1518                                                             x63);
1519     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x81, x79, x72,
1520                                                             x65);
1521     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x82, x79, x74,
1522                                                             x67);
1523     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(&x83, x79, x76,
1524                                                             x69);
1525     out1[0] = x80;
1526     out1[1] = x81;
1527     out1[2] = x82;
1528     out1[3] = x83;
1529 }
1530
1531 /*
1532  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_nonzero outputs a single non-zero word if the input is non-zero and zero otherwise.
1533  * Preconditions:
1534  *   0 ≤ eval arg1 < m
1535  * Postconditions:
1536  *   out1 = 0 ↔ eval (from_montgomery arg1) mod m = 0
1537  *
1538  * Input Bounds:
1539  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1540  * Output Bounds:
1541  *   out1: [0x0 ~> 0xffffffffffffffff]
1542  */
1543 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_nonzero(
1544     uint64_t *out1, const uint64_t arg1[4]) {
1545     uint64_t x1;
1546     x1 = ((arg1[0]) | ((arg1[1]) | ((arg1[2]) | (arg1[3]))));
1547     *out1 = x1;
1548 }
1549
1550 /*
1551  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz is a multi-limb conditional select.
1552  * Postconditions:
1553  *   eval out1 = (if arg1 = 0 then eval arg2 else eval arg3)
1554  *
1555  * Input Bounds:
1556  *   arg1: [0x0 ~> 0x1]
1557  *   arg2: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1558  *   arg3: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1559  * Output Bounds:
1560  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1561  */
1562 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
1563     uint64_t out1[4], fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1,
1564     const uint64_t arg2[4], const uint64_t arg3[4]) {
1565     uint64_t x1;
1566     uint64_t x2;
1567     uint64_t x3;
1568     uint64_t x4;
1569     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
1570         &x1, arg1, (arg2[0]), (arg3[0]));
1571     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
1572         &x2, arg1, (arg2[1]), (arg3[1]));
1573     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
1574         &x3, arg1, (arg2[2]), (arg3[2]));
1575     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u64(
1576         &x4, arg1, (arg2[3]), (arg3[3]));
1577     out1[0] = x1;
1578     out1[1] = x2;
1579     out1[2] = x3;
1580     out1[3] = x4;
1581 }
1582
1583 /*
1584  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes serializes a field element NOT in the Montgomery domain to bytes in little-endian order.
1585  * Preconditions:
1586  *   0 ≤ eval arg1 < m
1587  * Postconditions:
1588  *   out1 = map (λ x, ⌊((eval arg1 mod m) mod 2^(8 * (x + 1))) / 2^(8 * x)⌋) [0..31]
1589  *
1590  * Input Bounds:
1591  *   arg1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1592  * Output Bounds:
1593  *   out1: [[0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff]]
1594  */
1595 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(
1596     uint8_t out1[32], const uint64_t arg1[4]) {
1597     uint64_t x1;
1598     uint64_t x2;
1599     uint64_t x3;
1600     uint64_t x4;
1601     uint8_t x5;
1602     uint64_t x6;
1603     uint8_t x7;
1604     uint64_t x8;
1605     uint8_t x9;
1606     uint64_t x10;
1607     uint8_t x11;
1608     uint64_t x12;
1609     uint8_t x13;
1610     uint64_t x14;
1611     uint8_t x15;
1612     uint64_t x16;
1613     uint8_t x17;
1614     uint8_t x18;
1615     uint8_t x19;
1616     uint64_t x20;
1617     uint8_t x21;
1618     uint64_t x22;
1619     uint8_t x23;
1620     uint64_t x24;
1621     uint8_t x25;
1622     uint64_t x26;
1623     uint8_t x27;
1624     uint64_t x28;
1625     uint8_t x29;
1626     uint64_t x30;
1627     uint8_t x31;
1628     uint8_t x32;
1629     uint8_t x33;
1630     uint64_t x34;
1631     uint8_t x35;
1632     uint64_t x36;
1633     uint8_t x37;
1634     uint64_t x38;
1635     uint8_t x39;
1636     uint64_t x40;
1637     uint8_t x41;
1638     uint64_t x42;
1639     uint8_t x43;
1640     uint64_t x44;
1641     uint8_t x45;
1642     uint8_t x46;
1643     uint8_t x47;
1644     uint64_t x48;
1645     uint8_t x49;
1646     uint64_t x50;
1647     uint8_t x51;
1648     uint64_t x52;
1649     uint8_t x53;
1650     uint64_t x54;
1651     uint8_t x55;
1652     uint64_t x56;
1653     uint8_t x57;
1654     uint64_t x58;
1655     uint8_t x59;
1656     uint8_t x60;
1657     x1 = (arg1[3]);
1658     x2 = (arg1[2]);
1659     x3 = (arg1[1]);
1660     x4 = (arg1[0]);
1661     x5 = (uint8_t)(x4 & UINT8_C(0xff));
1662     x6 = (x4 >> 8);
1663     x7 = (uint8_t)(x6 & UINT8_C(0xff));
1664     x8 = (x6 >> 8);
1665     x9 = (uint8_t)(x8 & UINT8_C(0xff));
1666     x10 = (x8 >> 8);
1667     x11 = (uint8_t)(x10 & UINT8_C(0xff));
1668     x12 = (x10 >> 8);
1669     x13 = (uint8_t)(x12 & UINT8_C(0xff));
1670     x14 = (x12 >> 8);
1671     x15 = (uint8_t)(x14 & UINT8_C(0xff));
1672     x16 = (x14 >> 8);
1673     x17 = (uint8_t)(x16 & UINT8_C(0xff));
1674     x18 = (uint8_t)(x16 >> 8);
1675     x19 = (uint8_t)(x3 & UINT8_C(0xff));
1676     x20 = (x3 >> 8);
1677     x21 = (uint8_t)(x20 & UINT8_C(0xff));
1678     x22 = (x20 >> 8);
1679     x23 = (uint8_t)(x22 & UINT8_C(0xff));
1680     x24 = (x22 >> 8);
1681     x25 = (uint8_t)(x24 & UINT8_C(0xff));
1682     x26 = (x24 >> 8);
1683     x27 = (uint8_t)(x26 & UINT8_C(0xff));
1684     x28 = (x26 >> 8);
1685     x29 = (uint8_t)(x28 & UINT8_C(0xff));
1686     x30 = (x28 >> 8);
1687     x31 = (uint8_t)(x30 & UINT8_C(0xff));
1688     x32 = (uint8_t)(x30 >> 8);
1689     x33 = (uint8_t)(x2 & UINT8_C(0xff));
1690     x34 = (x2 >> 8);
1691     x35 = (uint8_t)(x34 & UINT8_C(0xff));
1692     x36 = (x34 >> 8);
1693     x37 = (uint8_t)(x36 & UINT8_C(0xff));
1694     x38 = (x36 >> 8);
1695     x39 = (uint8_t)(x38 & UINT8_C(0xff));
1696     x40 = (x38 >> 8);
1697     x41 = (uint8_t)(x40 & UINT8_C(0xff));
1698     x42 = (x40 >> 8);
1699     x43 = (uint8_t)(x42 & UINT8_C(0xff));
1700     x44 = (x42 >> 8);
1701     x45 = (uint8_t)(x44 & UINT8_C(0xff));
1702     x46 = (uint8_t)(x44 >> 8);
1703     x47 = (uint8_t)(x1 & UINT8_C(0xff));
1704     x48 = (x1 >> 8);
1705     x49 = (uint8_t)(x48 & UINT8_C(0xff));
1706     x50 = (x48 >> 8);
1707     x51 = (uint8_t)(x50 & UINT8_C(0xff));
1708     x52 = (x50 >> 8);
1709     x53 = (uint8_t)(x52 & UINT8_C(0xff));
1710     x54 = (x52 >> 8);
1711     x55 = (uint8_t)(x54 & UINT8_C(0xff));
1712     x56 = (x54 >> 8);
1713     x57 = (uint8_t)(x56 & UINT8_C(0xff));
1714     x58 = (x56 >> 8);
1715     x59 = (uint8_t)(x58 & UINT8_C(0xff));
1716     x60 = (uint8_t)(x58 >> 8);
1717     out1[0] = x5;
1718     out1[1] = x7;
1719     out1[2] = x9;
1720     out1[3] = x11;
1721     out1[4] = x13;
1722     out1[5] = x15;
1723     out1[6] = x17;
1724     out1[7] = x18;
1725     out1[8] = x19;
1726     out1[9] = x21;
1727     out1[10] = x23;
1728     out1[11] = x25;
1729     out1[12] = x27;
1730     out1[13] = x29;
1731     out1[14] = x31;
1732     out1[15] = x32;
1733     out1[16] = x33;
1734     out1[17] = x35;
1735     out1[18] = x37;
1736     out1[19] = x39;
1737     out1[20] = x41;
1738     out1[21] = x43;
1739     out1[22] = x45;
1740     out1[23] = x46;
1741     out1[24] = x47;
1742     out1[25] = x49;
1743     out1[26] = x51;
1744     out1[27] = x53;
1745     out1[28] = x55;
1746     out1[29] = x57;
1747     out1[30] = x59;
1748     out1[31] = x60;
1749 }
1750
1751 /*
1752  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes deserializes a field element NOT in the Montgomery domain from bytes in little-endian order.
1753  * Preconditions:
1754  *   0 ≤ bytes_eval arg1 < m
1755  * Postconditions:
1756  *   eval out1 mod m = bytes_eval arg1 mod m
1757  *   0 ≤ eval out1 < m
1758  *
1759  * Input Bounds:
1760  *   arg1: [[0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff]]
1761  * Output Bounds:
1762  *   out1: [[0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff], [0x0 ~> 0xffffffffffffffff]]
1763  */
1764 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(
1765     uint64_t out1[4], const uint8_t arg1[32]) {
1766     uint64_t x1;
1767     uint64_t x2;
1768     uint64_t x3;
1769     uint64_t x4;
1770     uint64_t x5;
1771     uint64_t x6;
1772     uint64_t x7;
1773     uint8_t x8;
1774     uint64_t x9;
1775     uint64_t x10;
1776     uint64_t x11;
1777     uint64_t x12;
1778     uint64_t x13;
1779     uint64_t x14;
1780     uint64_t x15;
1781     uint8_t x16;
1782     uint64_t x17;
1783     uint64_t x18;
1784     uint64_t x19;
1785     uint64_t x20;
1786     uint64_t x21;
1787     uint64_t x22;
1788     uint64_t x23;
1789     uint8_t x24;
1790     uint64_t x25;
1791     uint64_t x26;
1792     uint64_t x27;
1793     uint64_t x28;
1794     uint64_t x29;
1795     uint64_t x30;
1796     uint64_t x31;
1797     uint8_t x32;
1798     uint64_t x33;
1799     uint64_t x34;
1800     uint64_t x35;
1801     uint64_t x36;
1802     uint64_t x37;
1803     uint64_t x38;
1804     uint64_t x39;
1805     uint64_t x40;
1806     uint64_t x41;
1807     uint64_t x42;
1808     uint64_t x43;
1809     uint64_t x44;
1810     uint64_t x45;
1811     uint64_t x46;
1812     uint64_t x47;
1813     uint64_t x48;
1814     uint64_t x49;
1815     uint64_t x50;
1816     uint64_t x51;
1817     uint64_t x52;
1818     uint64_t x53;
1819     uint64_t x54;
1820     uint64_t x55;
1821     uint64_t x56;
1822     uint64_t x57;
1823     uint64_t x58;
1824     uint64_t x59;
1825     uint64_t x60;
1826     x1 = ((uint64_t)(arg1[31]) << 56);
1827     x2 = ((uint64_t)(arg1[30]) << 48);
1828     x3 = ((uint64_t)(arg1[29]) << 40);
1829     x4 = ((uint64_t)(arg1[28]) << 32);
1830     x5 = ((uint64_t)(arg1[27]) << 24);
1831     x6 = ((uint64_t)(arg1[26]) << 16);
1832     x7 = ((uint64_t)(arg1[25]) << 8);
1833     x8 = (arg1[24]);
1834     x9 = ((uint64_t)(arg1[23]) << 56);
1835     x10 = ((uint64_t)(arg1[22]) << 48);
1836     x11 = ((uint64_t)(arg1[21]) << 40);
1837     x12 = ((uint64_t)(arg1[20]) << 32);
1838     x13 = ((uint64_t)(arg1[19]) << 24);
1839     x14 = ((uint64_t)(arg1[18]) << 16);
1840     x15 = ((uint64_t)(arg1[17]) << 8);
1841     x16 = (arg1[16]);
1842     x17 = ((uint64_t)(arg1[15]) << 56);
1843     x18 = ((uint64_t)(arg1[14]) << 48);
1844     x19 = ((uint64_t)(arg1[13]) << 40);
1845     x20 = ((uint64_t)(arg1[12]) << 32);
1846     x21 = ((uint64_t)(arg1[11]) << 24);
1847     x22 = ((uint64_t)(arg1[10]) << 16);
1848     x23 = ((uint64_t)(arg1[9]) << 8);
1849     x24 = (arg1[8]);
1850     x25 = ((uint64_t)(arg1[7]) << 56);
1851     x26 = ((uint64_t)(arg1[6]) << 48);
1852     x27 = ((uint64_t)(arg1[5]) << 40);
1853     x28 = ((uint64_t)(arg1[4]) << 32);
1854     x29 = ((uint64_t)(arg1[3]) << 24);
1855     x30 = ((uint64_t)(arg1[2]) << 16);
1856     x31 = ((uint64_t)(arg1[1]) << 8);
1857     x32 = (arg1[0]);
1858     x33 = (x31 + (uint64_t)x32);
1859     x34 = (x30 + x33);
1860     x35 = (x29 + x34);
1861     x36 = (x28 + x35);
1862     x37 = (x27 + x36);
1863     x38 = (x26 + x37);
1864     x39 = (x25 + x38);
1865     x40 = (x23 + (uint64_t)x24);
1866     x41 = (x22 + x40);
1867     x42 = (x21 + x41);
1868     x43 = (x20 + x42);
1869     x44 = (x19 + x43);
1870     x45 = (x18 + x44);
1871     x46 = (x17 + x45);
1872     x47 = (x15 + (uint64_t)x16);
1873     x48 = (x14 + x47);
1874     x49 = (x13 + x48);
1875     x50 = (x12 + x49);
1876     x51 = (x11 + x50);
1877     x52 = (x10 + x51);
1878     x53 = (x9 + x52);
1879     x54 = (x7 + (uint64_t)x8);
1880     x55 = (x6 + x54);
1881     x56 = (x5 + x55);
1882     x57 = (x4 + x56);
1883     x58 = (x3 + x57);
1884     x59 = (x2 + x58);
1885     x60 = (x1 + x59);
1886     out1[0] = x39;
1887     out1[1] = x46;
1888     out1[2] = x53;
1889     out1[3] = x60;
1890 }
1891
1892 /* END verbatim fiat code */
1893
1894 /*-
1895  * Finite field inversion via FLT.
1896  * NB: this is not a real Fiat function, just named that way for consistency.
1897  * Autogenerated: ecp/id_GostR3410_2001_CryptoPro_B_ParamSet/fe_inv.op3
1898  * sliding window w=5
1899  */
1900 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(fe_t output,
1901                                                             const fe_t t1) {
1902     int i;
1903     /* temporary variables */
1904     fe_t acc, t23, t25;
1905
1906     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, t1);
1907     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t25, t1, acc);
1908     for (i = 0; i < 9; i++)
1909         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t25, t25, acc);
1910     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t23, t25, acc);
1911     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t25, t23, acc);
1912     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, t1);
1913     for (i = 0; i < 247; i++)
1914         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, acc);
1915     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(acc, acc, t25);
1916     for (i = 0; i < 7; i++)
1917         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, acc);
1918     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(output, acc, t23);
1919 }
1920
1921 /* curve coefficient constants */
1922
1923 static const limb_t const_one[4] = {
1924     UINT64_C(0xFFFFFFFFFFFFF367), UINT64_C(0xFFFFFFFFFFFFFFFF),
1925     UINT64_C(0xFFFFFFFFFFFFFFFF), UINT64_C(0x7FFFFFFFFFFFFFFF)};
1926
1927 static const limb_t const_b[4] = {
1928     UINT64_C(0x8DCC455AA9C5A084), UINT64_C(0x91AB42DF6CF438A8),
1929     UINT64_C(0x8F8AA907EEAC7D11), UINT64_C(0x3CE5D221F6285375)};
1930
1931 /* LUT for scalar multiplication by comb interleaving */
1932 static const pt_aff_t lut_cmb[27][16] = {
1933     {
1934         {{UINT64_C(0xFFFFFFFFFFFFF367), UINT64_C(0xFFFFFFFFFFFFFFFF),
1935           UINT64_C(0xFFFFFFFFFFFFFFFF), UINT64_C(0x7FFFFFFFFFFFFFFF)},
1936          {UINT64_C(0xDDDC64B3570C7410), UINT64_C(0xA7B0992513172887),
1937           UINT64_C(0x0C4E5C4C4B6382DB), UINT64_C(0x2763DB0F124768DE)}},
1938         {{UINT64_C(0xCD3E57B68457D15D), UINT64_C(0xEB688F7FBEA56E83),
1939           UINT64_C(0x235A123C6A13C5CE), UINT64_C(0x0CD7EB9D50F57A6D)},
1940          {UINT64_C(0xC0124E91544C1965), UINT64_C(0x4D9C172962AFA35E),
1941           UINT64_C(0x0F92F2C30037C554), UINT64_C(0x1D8998680A3F2665)}},
1942         {{UINT64_C(0x9DE4B21355F43EFF), UINT64_C(0x2E110A425C9E63F5),
1943           UINT64_C(0x9350A9C31CE5A6DF), UINT64_C(0x377CBF0BA332315E)},
1944          {UINT64_C(0x2805DD4820F0D1B5), UINT64_C(0x3B1975660F9723E5),
1945           UINT64_C(0xA1CCA78C84B79937), UINT64_C(0x4F87BB1B94D5E03D)}},
1946         {{UINT64_C(0xE428FBFB5652C96F), UINT64_C(0x2E9A14D2D261BDD1),
1947           UINT64_C(0x082D82967453B76A), UINT64_C(0x61EA580E7AC87B02)},
1948          {UINT64_C(0xA0F8C2BACF368FDB), UINT64_C(0xDF093380D73B2A28),
1949           UINT64_C(0xFA0928B2EA8FE5D2), UINT64_C(0x77A674925F86D38A)}},
1950         {{UINT64_C(0xDFFAB41027670451), UINT64_C(0xEBC3D0171200AD3A),
1951           UINT64_C(0xF68324F325F4F6C4), UINT64_C(0x4A24CD5F7D0EAFD0)},
1952          {UINT64_C(0xF8FBD489D3F6BD1C), UINT64_C(0x0F6B56D567B473DE),
1953           UINT64_C(0x6FB063DECACF0D6B), UINT64_C(0x27F2E7E996DC574B)}},
1954         {{UINT64_C(0xA6A1064593937228), UINT64_C(0xAB7550B4A9165BBB),
1955           UINT64_C(0xD682D4F1CB0EDBE8), UINT64_C(0x2261FCEC40E5AD8D)},
1956          {UINT64_C(0x9F2119C6CCBD4E18), UINT64_C(0x2FD094E9AAB09697),
1957           UINT64_C(0x00331713E700929E), UINT64_C(0x6C5F2EFE54338FE1)}},
1958         {{UINT64_C(0xD631401742FFF78A), UINT64_C(0x38F23A912087E055),
1959           UINT64_C(0xE30E809C10EF1CAC), UINT64_C(0x3BCB0A542432FF74)},
1960          {UINT64_C(0x2B4B5B97B31509E6), UINT64_C(0x117FE9D73E54AF47),
1961           UINT64_C(0xE513C0BE52F63ACA), UINT64_C(0x41ED8ADAB1C80A6B)}},
1962         {{UINT64_C(0x61A31837E0A79FCD), UINT64_C(0x8F742B5751D3DE38),
1963           UINT64_C(0x10635FCD41354B55), UINT64_C(0x61F30C61946510BE)},
1964          {UINT64_C(0x9183D6776C416DAC), UINT64_C(0x391B7B42345431CB),
1965           UINT64_C(0xE3D6F0847C254A8D), UINT64_C(0x777E1F6219D320D8)}},
1966         {{UINT64_C(0x090E633FF05BD85D), UINT64_C(0x546C41A0240392ED),
1967           UINT64_C(0x6BBCF15D9F4139CA), UINT64_C(0x73F5B6577FFDA5DA)},
1968          {UINT64_C(0xBC04E353E0622A57), UINT64_C(0xCBD8F01E6E6414F4),
1969           UINT64_C(0x53377C0B8C3C0CC5), UINT64_C(0x6D302331E0A14548)}},
1970         {{UINT64_C(0x235487F83D6D456E), UINT64_C(0xBD92203DB3FDCDCF),
1971           UINT64_C(0x15B13D60CFFDA977), UINT64_C(0x22DCB48731A1C4B5)},
1972          {UINT64_C(0xA367FB4EC76ED9A2), UINT64_C(0x1E4F7956C0C86AF4),
1973           UINT64_C(0x6F087C495B012AD7), UINT64_C(0x33437E4A4949B444)}},
1974         {{UINT64_C(0x261B44FEB7CDDB38), UINT64_C(0xDCE2FE47419216AD),
1975           UINT64_C(0xA4CE17FF9428657B), UINT64_C(0x7CE64F48F8329049)},
1976          {UINT64_C(0x4CE742117289C114), UINT64_C(0x0E6224098C212A23),
1977           UINT64_C(0xCF75BF452096719D), UINT64_C(0x6F5535817BDC1600)}},
1978         {{UINT64_C(0xE776AA0CB941CBC9), UINT64_C(0x16D670E0951AAED3),
1979           UINT64_C(0x79C019DF4B1EC097), UINT64_C(0x635A66BB12266D30)},
1980          {UINT64_C(0x030D843E023AAFD2), UINT64_C(0x10FB61576466108F),
1981           UINT64_C(0x93774BEC08D568D5), UINT64_C(0x29D2796204C1EE73)}},
1982         {{UINT64_C(0x6F0F4C2EE00BBC21), UINT64_C(0x9EB34C58A30AB92F),
1983           UINT64_C(0x2153D901AE34908B), UINT64_C(0x136A7E1F4EDC188F)},
1984          {UINT64_C(0xF709BF5D8BC45EE4), UINT64_C(0xEA6984E44FAD9A54),
1985           UINT64_C(0xFC8E6F8AAF5140EB), UINT64_C(0x25EBF0DE87756E47)}},
1986         {{UINT64_C(0x5C2A97265B1D4B9F), UINT64_C(0xBE235DFD68E93FC7),
1987           UINT64_C(0x7766BDB9471A4EA0), UINT64_C(0x476D17CCD9909CD9)},
1988          {UINT64_C(0x4960E5B47B398BC4), UINT64_C(0x909D0F170F58F328),
1989           UINT64_C(0x1ABF7E02230EF508), UINT64_C(0x6DE6B3E1D29239C9)}},
1990         {{UINT64_C(0xCCF0AA2885A6DBE3), UINT64_C(0xA5E4B325823C606C),
1991           UINT64_C(0xADE98B2A15505FC6), UINT64_C(0x4D4E770302E20C3B)},
1992          {UINT64_C(0x241964174730DF64), UINT64_C(0x3DD47817A914A59D),
1993           UINT64_C(0x4D7A317EC4FDFD97), UINT64_C(0x3767E545BE12AA72)}},
1994         {{UINT64_C(0xA0C2A028165C7BF4), UINT64_C(0xCD4DA6EA36A0B483),
1995           UINT64_C(0x1E1E63323AF53195), UINT64_C(0x7A025E238D77188F)},
1996          {UINT64_C(0xB3CF03B908D2CEF2), UINT64_C(0x8FEE9BB825A0AFA6),
1997           UINT64_C(0x855340E088111895), UINT64_C(0x32E3EF014FB8F8A3)}},
1998     },
1999     {
2000         {{UINT64_C(0x33EBE39DEBF87807), UINT64_C(0xB048F96CDBDEFF76),
2001           UINT64_C(0xA0496C3C342A3087), UINT64_C(0x7623E19250953679)},
2002          {UINT64_C(0x12F767114B932390), UINT64_C(0xF80851EAACECE2F7),
2003           UINT64_C(0xE447465BE5B280EA), UINT64_C(0x0412ADE811115958)}},
2004         {{UINT64_C(0x982F1AC8B5EB0DC2), UINT64_C(0x8464E052BBBCC880),
2005           UINT64_C(0xC927B59601335D53), UINT64_C(0x4B0C6F5A4DA4D80B)},
2006          {UINT64_C(0x101E1878E04783AF), UINT64_C(0x50458FFC41D8A690),
2007           UINT64_C(0x11499D881B77DFBF), UINT64_C(0x46DC7D221F77A937)}},
2008         {{UINT64_C(0xE9AD22CE620E52C0), UINT64_C(0x0990D6AA4140F356),
2009           UINT64_C(0x0F6B2EF70CBBEEE5), UINT64_C(0x2C67DC80EAD414C6)},
2010          {UINT64_C(0xE17182BC23D4CD20), UINT64_C(0xFC8FE3CBC13DDEA9),
2011           UINT64_C(0xD1E4A7B83BABC06D), UINT64_C(0x52EA05CC71C06DB7)}},
2012         {{UINT64_C(0xF8ABB7700D022B5B), UINT64_C(0x362B8059199DC689),
2013           UINT64_C(0x5D887A4D26BBDEC8), UINT64_C(0x7835F183F7FC2A01)},
2014          {UINT64_C(0xEEDE12F5DE99DF34), UINT64_C(0xBE952638A3082301),
2015           UINT64_C(0x829FDF804C35A162), UINT64_C(0x205A2252C2B9645E)}},
2016         {{UINT64_C(0xDE284DA91356E14C), UINT64_C(0xE40CEFE0C37415FE),
2017           UINT64_C(0x62BE93E947F6016E), UINT64_C(0x2DD989045DBFE2F6)},
2018          {UINT64_C(0x195B0E982EBC70F9), UINT64_C(0x7E52840DF01F4D43),
2019           UINT64_C(0x1AFB1FDF4B1F6AB4), UINT64_C(0x050AABB820B3E491)}},
2020         {{UINT64_C(0xC59E1EDBC645DAD4), UINT64_C(0x5AF6B2DC565A286D),
2021           UINT64_C(0xC399A48A13076366), UINT64_C(0x19F4881F4AC0E5B9)},
2022          {UINT64_C(0xC07D02A1CD5AC339), UINT64_C(0x18FBD088ED628A55),
2023           UINT64_C(0x2D33C6F4FFA4788E), UINT64_C(0x52E9AE42CCB832E7)}},
2024         {{UINT64_C(0xA47091AE4E5E934E), UINT64_C(0x2542CE1391CED3C6),
2025           UINT64_C(0xDDE01FD58FC47857), UINT64_C(0x6BA6E5694304EAA9)},
2026          {UINT64_C(0x2FF0278BE24091A9), UINT64_C(0xB895F0AB782BBCE0),
2027           UINT64_C(0xA80CCC97AB8B8828), UINT64_C(0x6A54B96168A7D8FE)}},
2028         {{UINT64_C(0x15E1F5ADBAC4581A), UINT64_C(0x91620EF0D4BAA751),
2029           UINT64_C(0x4E65731FC7273C4D), UINT64_C(0x14B166CB7EEE33B5)},
2030          {UINT64_C(0x7B0EFFA53CD06080), UINT64_C(0x4491156A8CF95FF9),
2031           UINT64_C(0xC8C64C39E2258574), UINT64_C(0x3D48DA9D13315CE9)}},
2032         {{UINT64_C(0x97A098A399866CE5), UINT64_C(0xF4CCDB40023A1167),
2033           UINT64_C(0x4BB32981F8094782), UINT64_C(0x7342CC98C7D5FD13)},
2034          {UINT64_C(0x3C1C5B1878B99D4E), UINT64_C(0x1277668FF4762AC9),
2035           UINT64_C(0x612431D76AE50E4F), UINT64_C(0x36C174E036F9071C)}},
2036         {{UINT64_C(0x39194E879327BA7F), UINT64_C(0xC4D251FF7237FA1A),
2037           UINT64_C(0x55ED3CD42BA5EB8D), UINT64_C(0x0263AF07BA590188)},
2038          {UINT64_C(0xB4853127EFA82CF3), UINT64_C(0x2CC2D2202B8E761D),
2039           UINT64_C(0x4582B81E2722B490), UINT64_C(0x1DA7680A610AA621)}},
2040         {{UINT64_C(0x06A669EE30D297D4), UINT64_C(0xC336B048E133D393),
2041           UINT64_C(0xB733A2C493B7B41B), UINT64_C(0x427CC233C7A8E721)},
2042          {UINT64_C(0x727C14F12867BB00), UINT64_C(0x756F4C7AA736035E),
2043           UINT64_C(0xB72A3EDE26327A22), UINT64_C(0x4AEDE2BB77F73F28)}},
2044         {{UINT64_C(0xC8A3612FA7282ED0), UINT64_C(0xE4AD8B40B0150579),
2045           UINT64_C(0xAB1DE11D0C3FEE4B), UINT64_C(0x613AAD4833B31F23)},
2046          {UINT64_C(0xE74AB8565C91BD21), UINT64_C(0x499177357953D695),
2047           UINT64_C(0x3831EB601A53D74F), UINT64_C(0x245977A054DEB1A6)}},
2048         {{UINT64_C(0x15972E4DFFFC1468), UINT64_C(0xA758D9CB141DC24C),
2049           UINT64_C(0x5E76FCDFED8694C5), UINT64_C(0x5F9DAF35069B7A5E)},
2050          {UINT64_C(0xFE50FCE4501B5415), UINT64_C(0x6442CF6758CFDE50),
2051           UINT64_C(0xA89C6DB438E5F4D0), UINT64_C(0x21F012DBF5D4FEFC)}},
2052         {{UINT64_C(0x2A1170AD98CB9A81), UINT64_C(0x934BD9D5036C5E45),
2053           UINT64_C(0x27DF152ECA5095B1), UINT64_C(0x682698DBCCEEE508)},
2054          {UINT64_C(0x1F4FE3A2B973FB5F), UINT64_C(0xD33CBEBE792C7D4D),
2055           UINT64_C(0x99D37961E7B33A8F), UINT64_C(0x46B8993B7B6D015D)}},
2056         {{UINT64_C(0x93A3809B6FBAC8F7), UINT64_C(0x84861BF097C55DC4),
2057           UINT64_C(0xA6F89EEA15BB65E3), UINT64_C(0x66AE1C5DA6E531D1)},
2058          {UINT64_C(0x643A14FCFD83DAEA), UINT64_C(0xA7A46D0DC585947B),
2059           UINT64_C(0xFA20CF074FBA1274), UINT64_C(0x5999ED7B93578A7D)}},
2060         {{UINT64_C(0x36C8B6ED78E7C6CE), UINT64_C(0x6D400CA55E325F44),
2061           UINT64_C(0xC6AE09B320B7AA5C), UINT64_C(0x1AF261C189EABC17)},
2062          {UINT64_C(0x64D6FFBBB9E778E4), UINT64_C(0x1C9E223E7FC64BEB),
2063           UINT64_C(0x4D68B5205D75E6C0), UINT64_C(0x5A72B1D976677A06)}},
2064     },
2065     {
2066         {{UINT64_C(0x62DB66406F08BB17), UINT64_C(0xC34F29DFAE75BB73),
2067           UINT64_C(0xD501293D7DBD4851), UINT64_C(0x5EAA94CAAD1F604B)},
2068          {UINT64_C(0x39CFE9D1094408A8), UINT64_C(0xC0F6544CE8A476F2),
2069           UINT64_C(0x9F6308B6A42D7607), UINT64_C(0x17F82949D727018F)}},
2070         {{UINT64_C(0xC44453CD9C4C4BD2), UINT64_C(0xA895E247EBD0B947),
2071           UINT64_C(0x0AEB7AFCAEBC27F4), UINT64_C(0x2472FD08F04ABFAC)},
2072          {UINT64_C(0x319EC67D73E6E994), UINT64_C(0xD6533E4C798C5FC0),
2073           UINT64_C(0xF4C3B24D3FB9AA89), UINT64_C(0x3EC580820A3B376B)}},
2074         {{UINT64_C(0x79732D6F144ACF7A), UINT64_C(0xFDD630C3911342DD),
2075           UINT64_C(0xC577C4B34A630649), UINT64_C(0x14956A17BBA999D6)},
2076          {UINT64_C(0x523D3CC8A435A559), UINT64_C(0x488DC690ACDA8861),
2077           UINT64_C(0x4CF70928F051C69A), UINT64_C(0x2D98D573955394CB)}},
2078         {{UINT64_C(0xEDB7BA2A23A4B840), UINT64_C(0x725EC496F6C2D93B),
2079           UINT64_C(0x0C94818B8833BB3F), UINT64_C(0x51281A31B142B12A)},
2080          {UINT64_C(0x2A8A5706659EDA83), UINT64_C(0x3098F7507F9D6877),
2081           UINT64_C(0x87AD0FDF2171F69F), UINT64_C(0x6B7067C31A6F2F28)}},
2082         {{UINT64_C(0x3B52107412B1E36F), UINT64_C(0x727A2432F81E4733),
2083           UINT64_C(0xB75A2F3553F2CBBD), UINT64_C(0x46DE933854960EB0)},
2084          {UINT64_C(0xAC5344F8E561D908), UINT64_C(0x4BD40ECB12C67430),
2085           UINT64_C(0x1698FD62EF499F97), UINT64_C(0x29EBD7AE6AE9FBD1)}},
2086         {{UINT64_C(0x9DEC249B1EC8110D), UINT64_C(0x2D19053AFD2F5C39),
2087           UINT64_C(0xB1189807E01522DF), UINT64_C(0x24A04C16C1424C77)},
2088          {UINT64_C(0xA4FC7C7D24F72226), UINT64_C(0x763405FBA8322501),
2089           UINT64_C(0xC5443C9A18F015E0), UINT64_C(0x6DEDA19BC55D6CEA)}},
2090         {{UINT64_C(0x4EF309769EAE2FF9), UINT64_C(0x2549B7F25741B21B),
2091           UINT64_C(0x859ACD103BC23F01), UINT64_C(0x05C0358FBF5FB0D7)},
2092          {UINT64_C(0x85E53AA8FB6AB34C), UINT64_C(0x8DAAAA698FD2FD20),
2093           UINT64_C(0xBE6D4D3416096FC9), UINT64_C(0x27572C88F8B8B831)}},
2094         {{UINT64_C(0xADB98DC547D56A25), UINT64_C(0x0CC764328B8E1DC6),
2095           UINT64_C(0x032C738EBE48C4A1), UINT64_C(0x31372DAD94FC9CF0)},
2096          {UINT64_C(0x8E646A0C78A7DCB2), UINT64_C(0xA32F3E9C6ECD9885),
2097           UINT64_C(0x280BB4AD6A3AD963), UINT64_C(0x7DEE1BC4817D4327)}},
2098         {{UINT64_C(0x1AE6A27BF8A7C1E1), UINT64_C(0x558C652FCBC527C7),
2099           UINT64_C(0x4084B56EA65056F6), UINT64_C(0x3FD454596D4C838B)},
2100          {UINT64_C(0xF5C15AFD56DE792A), UINT64_C(0xF656FAA488959282),
2101           UINT64_C(0x7F0D8EF41C07D63F), UINT64_C(0x44EFFF7DCD841ACC)}},
2102         {{UINT64_C(0xAC28F2A68D3695D8), UINT64_C(0x94959EB83F91E781),
2103           UINT64_C(0x7693FFF7FEDD6E1F), UINT64_C(0x2512E6E1A9A699EF)},
2104          {UINT64_C(0x823400EB7955FAB7), UINT64_C(0xCF109EF994924C08),
2105           UINT64_C(0x12E087793A709F32), UINT64_C(0x187D04139CC6484C)}},
2106         {{UINT64_C(0xD3932AFBEBDE477F), UINT64_C(0x9D5A542244538D8A),
2107           UINT64_C(0x40B0B159166A87AF), UINT64_C(0x31294B3D41D5E078)},
2108          {UINT64_C(0x6C49C853E8C48222), UINT64_C(0x8FBE6620DCD0D611),
2109           UINT64_C(0x9DDC7EE2F611007B), UINT64_C(0x12289A60E6652172)}},
2110         {{UINT64_C(0x8B85475BDACF80F7), UINT64_C(0xADBAB3539B5CAEF2),
2111           UINT64_C(0x7C4090A38D2A7707), UINT64_C(0x271FA4F1DAB97830)},
2112          {UINT64_C(0x141B725253173E04), UINT64_C(0x4B483D6406D0B127),
2113           UINT64_C(0x8FD15BCF063A7AF8), UINT64_C(0x59B19EAFE580F34C)}},
2114         {{UINT64_C(0xA7EEA8C49C0D79B6), UINT64_C(0x766FA113B9185109),
2115           UINT64_C(0xB42D74F34642CC64), UINT64_C(0x51D0127BBB817476)},
2116          {UINT64_C(0x6DA097F58AB71448), UINT64_C(0x145872E5F95AD0C7),
2117           UINT64_C(0xB7E934F3F1759436), UINT64_C(0x4EA883F93160ED1F)}},
2118         {{UINT64_C(0x30DC39B70CEABAE1), UINT64_C(0x49EC5EE8A606D766),
2119           UINT64_C(0x230E276297FC46AF), UINT64_C(0x079A531F5BE79B8D)},
2120          {UINT64_C(0x48253BC2EF08C93F), UINT64_C(0x2D32AF02F124D043),
2121           UINT64_C(0x85796D0DAF34D231), UINT64_C(0x06A6205C15F8CECD)}},
2122         {{UINT64_C(0x1FA77AFD47B00D1A), UINT64_C(0x429717B0E48CE97A),
2123           UINT64_C(0x38FEF11D57433697), UINT64_C(0x3E91BED67D426687)},
2124          {UINT64_C(0x95919BF72AB4BFE9), UINT64_C(0x7A3F33FC97096B3A),
2125           UINT64_C(0x0E0BBAC33DD8C82E), UINT64_C(0x2CE9EFCBF8EDB675)}},
2126         {{UINT64_C(0x2D44E99843D8B81D), UINT64_C(0x8ABFF4196D68A95C),
2127           UINT64_C(0x639000A03B2A18DD), UINT64_C(0x7CD15413871E3ED3)},
2128          {UINT64_C(0xC059855B148F0378), UINT64_C(0x50147459616B62BF),
2129           UINT64_C(0x53B699AF4D461110), UINT64_C(0x6A0D0EC7EC29E48D)}},
2130     },
2131     {
2132         {{UINT64_C(0x5173322115797F35), UINT64_C(0x2F2982144BBE6644),
2133           UINT64_C(0x7BC8FEC64A5EF621), UINT64_C(0x3D2BE7857F472F05)},
2134          {UINT64_C(0xA1C3A1C92765C427), UINT64_C(0xBACF08FE24155ACF),
2135           UINT64_C(0xA9CC1A179D229948), UINT64_C(0x1918C97F27039FD8)}},
2136         {{UINT64_C(0x2CF393387843FF7B), UINT64_C(0x5FCBDE65258997F2),
2137           UINT64_C(0x3980BF90165A98A3), UINT64_C(0x2E80607DBF9458E5)},
2138          {UINT64_C(0x5F646EB67019165C), UINT64_C(0xFA091FBEDDE34205),
2139           UINT64_C(0x695348B669267AE3), UINT64_C(0x385B0B6AABC22051)}},
2140         {{UINT64_C(0x3CAE0756B537F78C), UINT64_C(0x3012A9588BE30367),
2141           UINT64_C(0x32D26C06981A22C3), UINT64_C(0x7D091FAB2950E833)},
2142          {UINT64_C(0xD8E1B638797ACAAF), UINT64_C(0xE7021C8549F2EA10),
2143           UINT64_C(0xCA382BC117A7AF3B), UINT64_C(0x08A5A81DBB809976)}},
2144         {{UINT64_C(0x00F499FD4287BB97), UINT64_C(0xFB6791CADAA9DAF2),
2145           UINT64_C(0x9A19E4F3057B2B98), UINT64_C(0x6968D2FFC53C0223)},
2146          {UINT64_C(0xDC741EF5CE88509C), UINT64_C(0x38AE355D306A0570),
2147           UINT64_C(0xFECF6589C23AF46B), UINT64_C(0x6C0E6ED16AD48836)}},
2148         {{UINT64_C(0x22B68698E363495D), UINT64_C(0x120005D039AF2BE3),
2149           UINT64_C(0xE37B19650BF4BA69), UINT64_C(0x3B416E9326E64AE7)},
2150          {UINT64_C(0xFAED5088DEAC5C59), UINT64_C(0x67436ACCEB2518A5),
2151           UINT64_C(0x636B52F891FA788D), UINT64_C(0x10B2A57A655153D1)}},
2152         {{UINT64_C(0xB18060A7833A984C), UINT64_C(0x7EF8374674833BAD),
2153           UINT64_C(0xCBFAF742C5B3BC88), UINT64_C(0x7981DC36A1A7F135)},
2154          {UINT64_C(0xE70CCAFA5D076280), UINT64_C(0xEBA80EB707009D85),
2155           UINT64_C(0x7D99D24C73778DE2), UINT64_C(0x1EFEE1BBA7262D50)}},
2156         {{UINT64_C(0xBC47F4A26A7CAB32), UINT64_C(0x53F290A7DD6E48A3),
2157           UINT64_C(0x82257A1B92F35F9E), UINT64_C(0x73D17B318BB0AAB0)},
2158          {UINT64_C(0xBBD4522AC2DFFE96), UINT64_C(0x9C37DAA1E6EB0501),
2159           UINT64_C(0xF4D4D568453DB6BE), UINT64_C(0x2868CBF5642AD2E4)}},
2160         {{UINT64_C(0x40A988E6ABE30C59), UINT64_C(0x5ADED92993057DEC),
2161           UINT64_C(0x18FD7E04DACD37B0), UINT64_C(0x6E3FB81E8228ACA5)},
2162          {UINT64_C(0xFF3EEFE64104B0C9), UINT64_C(0xD7DD05E731CA120A),
2163           UINT64_C(0xAFD3CF1CD01C1CF8), UINT64_C(0x4D0CD264831BC4E9)}},
2164         {{UINT64_C(0x2641B32182CAC14A), UINT64_C(0x34EB149570990E6C),
2165           UINT64_C(0x3E5AF58FA1C74CA6), UINT64_C(0x11B50821616B7A2D)},
2166          {UINT64_C(0x891636E3C4FA9719), UINT64_C(0xAEE84C27107DD719),
2167           UINT64_C(0xA2B0D83EC1872E75), UINT64_C(0x7DD62CBC7383069E)}},
2168         {{UINT64_C(0xEBA4A024C81B7E15), UINT64_C(0x1CC37E0804516070),
2169           UINT64_C(0xEF1F0401F90CE59D), UINT64_C(0x3B4259D5E062E133)},
2170          {UINT64_C(0x87A1DBFACF2CA1DD), UINT64_C(0xCFBFB15F61FD1AFB),
2171           UINT64_C(0xFBFD9899ECF4C7BA), UINT64_C(0x57C84CEE2725FA50)}},
2172         {{UINT64_C(0x8B0B7414EFA6E3D0), UINT64_C(0xD9725C5EB3D04224),
2173           UINT64_C(0x670E6C508A91371E), UINT64_C(0x4D1304679B25BD3B)},
2174          {UINT64_C(0x18D77D155CF18D4F), UINT64_C(0xEF80DC411CA09677),
2175           UINT64_C(0x6F3A961BB9A05CF9), UINT64_C(0x0BB8A5187C1433A4)}},
2176         {{UINT64_C(0xAC0CF52AB33FCF05), UINT64_C(0xAD03692F1CDC7782),
2177           UINT64_C(0xB345BAE6AA02B77E), UINT64_C(0x05096694456FCFA9)},
2178          {UINT64_C(0xA898444825D4CF32), UINT64_C(0xD76393E315184188),
2179           UINT64_C(0x7D4A8C0CEA069BED), UINT64_C(0x4D22268D11E18347)}},
2180         {{UINT64_C(0xC2A0BB753CB3C0F1), UINT64_C(0x61F4EC4C8EBA58C6),
2181           UINT64_C(0x5D3F0D44DFC4A903), UINT64_C(0x0B6CE81BF9B6F79A)},
2182          {UINT64_C(0xF694A44A94E49623), UINT64_C(0xCFCBB7E11BDF75E0),
2183           UINT64_C(0x20CEE1BDE0337E13), UINT64_C(0x694EA40BDFF02E18)}},
2184         {{UINT64_C(0xC21BE0FA78D1DC2E), UINT64_C(0x08B4D9A5ED0E49E0),
2185           UINT64_C(0x676731AB827F0B4C), UINT64_C(0x674ECC79EBAB5894)},
2186          {UINT64_C(0xB29BD0D439ABB148), UINT64_C(0x8207A8F82378A63A),
2187           UINT64_C(0xE36A549D1E4C29C2), UINT64_C(0x380D48DE3F1C255B)}},
2188         {{UINT64_C(0x6AB6F887E5F2C87E), UINT64_C(0xE92C7345A01AEC86),
2189           UINT64_C(0x697F45208660C26F), UINT64_C(0x4F2488E09B58015B)},
2190          {UINT64_C(0xB2410B3EBB41900C), UINT64_C(0x31267500BE1A8A39),
2191           UINT64_C(0xA7C9997CB9140554), UINT64_C(0x335B18061CD41524)}},
2192         {{UINT64_C(0xB836FD9F14873270), UINT64_C(0x1AE0F512E3243EC5),
2193           UINT64_C(0xA743E30483B9AB74), UINT64_C(0x1569C30D3A5758C7)},
2194          {UINT64_C(0x003CEF9A9E8F9E52), UINT64_C(0x557AFB4A8C22119E),
2195           UINT64_C(0x66F2487EF223A966), UINT64_C(0x7FA00273A519378F)}},
2196     },
2197     {
2198         {{UINT64_C(0x812C024F7B08C1C4), UINT64_C(0xC6017986ADBA8AD9),
2199           UINT64_C(0x59C7B16C0601BD82), UINT64_C(0x41B6A45C0CFA5622)},
2200          {UINT64_C(0x353A67D583C1E3E8), UINT64_C(0x9A83438EC65F5059),
2201           UINT64_C(0x9995037786EEA346), UINT64_C(0x74E2F4BD330D2570)}},
2202         {{UINT64_C(0xDB8E53C1B4A8BDA8), UINT64_C(0xA850047E2C003C77),
2203           UINT64_C(0xFFD48A731B018831), UINT64_C(0x24F96CB68B325062)},
2204          {UINT64_C(0x3779CA4DCD2B821B), UINT64_C(0xC2AFBF6EC3159CE7),
2205           UINT64_C(0x8A580B1A10F18DE9), UINT64_C(0x37043D0D8CF75334)}},
2206         {{UINT64_C(0x0451DCDAECCCF2E8), UINT64_C(0xCF7A3AD9752A134F),
2207           UINT64_C(0xD5754596FBDAE56C), UINT64_C(0x15237D73F4CDCF6A)},
2208          {UINT64_C(0x1DF5912CECA37967), UINT64_C(0x60934339336CD97E),
2209           UINT64_C(0xA4E523FE434DDC01), UINT64_C(0x24E81DC679DBE24C)}},
2210         {{UINT64_C(0x28F0D73BC83B2B7C), UINT64_C(0x45BE220F7B5DE1AA),
2211           UINT64_C(0x1B785230B136A877), UINT64_C(0x5A94122AAEFF115B)},
2212          {UINT64_C(0xEF895F0C8E598998), UINT64_C(0xCEE32B3EF4C622C3),
2213           UINT64_C(0x2D080B1DB256CFD0), UINT64_C(0x672686D621075E15)}},
2214         {{UINT64_C(0xE85FB5759F9F26FE), UINT64_C(0x1DE57B8393A7966E),
2215           UINT64_C(0xA9948DE8DD8CB696), UINT64_C(0x226C95A6758E685D)},
2216          {UINT64_C(0x38B0753B3729C663), UINT64_C(0xD46CA4D9410E4884),
2217           UINT64_C(0x1D6FA5F977516FA4), UINT64_C(0x09A0FDB8696CFAFC)}},
2218         {{UINT64_C(0xD1DAD8E9CC7F6FD8), UINT64_C(0x7BB9F606022195A2),
2219           UINT64_C(0x1B997396223A9346), UINT64_C(0x6ACD6F7C88DCFB04)},
2220          {UINT64_C(0x9029E5EB3AC52F65), UINT64_C(0xED1D7A0F935A39DE),
2221           UINT64_C(0xF1D58C3A538D8914), UINT64_C(0x19153569B36B8342)}},
2222         {{UINT64_C(0xFF600354E2502156), UINT64_C(0xE386A20F733DA5EC),
2223           UINT64_C(0xD6FBCBBB9D24D11D), UINT64_C(0x0B57498C0B06C843)},
2224          {UINT64_C(0x98F1FFF87A834667), UINT64_C(0x4AEB8788C7DF05F5),
2225           UINT64_C(0x8CFA3B01C2681DA4), UINT64_C(0x1AECC0E82FA2FAEA)}},
2226         {{UINT64_C(0x3827886594C5CBC5), UINT64_C(0x9ADA7CAB041A755A),
2227           UINT64_C(0xB38F762A8D891640), UINT64_C(0x28F6FBB200AD88F0)},
2228          {UINT64_C(0x3F9629E33709CD6D), UINT64_C(0xD2435A554912F483),
2229           UINT64_C(0x305BEA64DFF5AB69), UINT64_C(0x4D29041A663BB0D9)}},
2230         {{UINT64_C(0xDC4BC9D4E2FD9338), UINT64_C(0x5389390DBA7938FC),
2231           UINT64_C(0xC42B812DF329B218), UINT64_C(0x5E809B5EFA9F1956)},
2232          {UINT64_C(0xE2A89BAA523D74C3), UINT64_C(0x97CD9FFB78CBA7B5),
2233           UINT64_C(0x25F953015B07BCD2), UINT64_C(0x4042C7052064BB3A)}},
2234         {{UINT64_C(0xD8B6ADA428D53BF9), UINT64_C(0x5E922CA5A4210F2D),
2235           UINT64_C(0x9501F46AF05A1629), UINT64_C(0x28094E54C6CD71CD)},
2236          {UINT64_C(0x8D5484D5811285AD), UINT64_C(0xFB2168F41593EE86),
2237           UINT64_C(0x693D3B32AC54A41D), UINT64_C(0x3DAFEC0728A5425C)}},
2238         {{UINT64_C(0x0E4CF0D0D12837A8), UINT64_C(0x19FA2CC9CF5273BB),
2239           UINT64_C(0x56346BAE116A20C4), UINT64_C(0x4F3597FE0E436A36)},
2240          {UINT64_C(0x459D3FFBE8EB1B85), UINT64_C(0x7C7186725AE04130),
2241           UINT64_C(0xA37C258660302740), UINT64_C(0x2871AF37913072D8)}},
2242         {{UINT64_C(0xD77249B78590319D), UINT64_C(0x73F7A684EB06B813),
2243           UINT64_C(0x4C9DC5B971D1D580), UINT64_C(0x7C91A9F55A50A95B)},
2244          {UINT64_C(0x4F8F2E890475F161), UINT64_C(0xF34EC1DD538B7F94),
2245           UINT64_C(0xB8FF6C65D46F2575), UINT64_C(0x79A2CE2C64433C80)}},
2246         {{UINT64_C(0x38448A531AEB7039), UINT64_C(0xF5EC03F7417189EC),
2247           UINT64_C(0xFA095CA1EB92FF2B), UINT64_C(0x4612F720E4FCAEDB)},
2248          {UINT64_C(0xC945E966F30AAE0E), UINT64_C(0xF61CFE85340A7A1D),
2249           UINT64_C(0xA2560BC6E42D7920), UINT64_C(0x07D7B321A692E9C7)}},
2250         {{UINT64_C(0xB9C26307592C60C5), UINT64_C(0xCECBC6C30F59D966),
2251           UINT64_C(0x8BA31FD65459D89E), UINT64_C(0x1A4AF6B147C7FAE8)},
2252          {UINT64_C(0x66487766B431D720), UINT64_C(0x5D5973095108B845),
2253           UINT64_C(0xA3B94FD7CA8E6E0D), UINT64_C(0x639519E355C6A48D)}},
2254         {{UINT64_C(0xAD3EE167052DC195), UINT64_C(0x4DF2BFC70947816B),
2255           UINT64_C(0x5D463469ABADBB3C), UINT64_C(0x6F7AA885C33D4F96)},
2256          {UINT64_C(0x3DD27536FE06133C), UINT64_C(0x27A557B22796E7ED),
2257           UINT64_C(0x1117CCB73D314A4F), UINT64_C(0x6F0C0AE023968946)}},
2258         {{UINT64_C(0x0A3D4DAEE2110C00), UINT64_C(0x0389D3A54C633A23),
2259           UINT64_C(0xE167BDFA83AEC172), UINT64_C(0x067070CEFB38E8F1)},
2260          {UINT64_C(0x411373674DF220C5), UINT64_C(0xB255E5D359C39F05),
2261           UINT64_C(0xE437984E043C75B3), UINT64_C(0x01DCD7716A22994A)}},
2262     },
2263     {
2264         {{UINT64_C(0xD2880DF24C6FDDCF), UINT64_C(0x76A28FF28A00D80F),
2265           UINT64_C(0x257CB1F80792F82C), UINT64_C(0x07938ABC605703EA)},
2266          {UINT64_C(0xD99F0AC95F61B0FE), UINT64_C(0x440DC63C8EC15433),
2267           UINT64_C(0xD9BDDFF186AB5DDB), UINT64_C(0x3B8875DC744755EA)}},
2268         {{UINT64_C(0x01D904404938C9FB), UINT64_C(0x900657FD8DB6A890),
2269           UINT64_C(0xDCC5068AF60A173A), UINT64_C(0x5F3EB242857C7B2A)},
2270          {UINT64_C(0x634240BDA4F0EB9E), UINT64_C(0xACDDA6C444E85C70),
2271           UINT64_C(0x753F02AB0AABE4C5), UINT64_C(0x33D89D21C1D034E1)}},
2272         {{UINT64_C(0x4596B52D1279B25B), UINT64_C(0x494669D9A48014AE),
2273           UINT64_C(0x9A26B6FC4FD22150), UINT64_C(0x394DE0BBF07D5A3F)},
2274          {UINT64_C(0x12DFE5A6634C1733), UINT64_C(0x33EC21D21EBC5177),
2275           UINT64_C(0x454B4930527514CC), UINT64_C(0x7F23BD0F41405532)}},
2276         {{UINT64_C(0xB2879E7FBAC9DD30), UINT64_C(0x259BB1CB06CE7672),
2277           UINT64_C(0x201DB42EBB97BE10), UINT64_C(0x112D60792EA35A8E)},
2278          {UINT64_C(0x7CC756D46B3B9933), UINT64_C(0x4BD24810781CE4DD),
2279           UINT64_C(0x53CB4E388733247E), UINT64_C(0x47BD6A309DA66787)}},
2280         {{UINT64_C(0x8A700953BA600C8E), UINT64_C(0xD466F11DCF388C0D),
2281           UINT64_C(0xD485F341E4A17A8E), UINT64_C(0x63278918234FC16D)},
2282          {UINT64_C(0xF4DDA875BB82046D), UINT64_C(0xD61E4E582945470A),
2283           UINT64_C(0xCDB6C5BD6D0F8976), UINT64_C(0x44CD9E4D10A004A2)}},
2284         {{UINT64_C(0x595CD94249C4AA6E), UINT64_C(0xE5A901363DE400C8),
2285           UINT64_C(0x4BCED3BD9DD12D9E), UINT64_C(0x3700CF9278E3D5E4)},
2286          {UINT64_C(0xECFFF49875A32D1A), UINT64_C(0xC28DDE373C4A54B2),
2287           UINT64_C(0x8DC22352993CAE6D), UINT64_C(0x46CB540852ED7019)}},
2288         {{UINT64_C(0x71FFAED0EA94E7BF), UINT64_C(0xC0817D2CD5AE6185),
2289           UINT64_C(0x7B72B8B95CF23687), UINT64_C(0x61DDE59960A450E1)},
2290          {UINT64_C(0x17CF0B10D13870E6), UINT64_C(0x7D08E1FB5F2930BB),
2291           UINT64_C(0x8D0F4F5583807C14), UINT64_C(0x61EBFC1A6E6DB701)}},
2292         {{UINT64_C(0x247A3F650FCAFE68), UINT64_C(0x575480357AC2A25E),
2293           UINT64_C(0xB7466CA53CD0FE06), UINT64_C(0x7B0D8B36BCC31AB3)},
2294          {UINT64_C(0x2FAAF49CA6D4358C), UINT64_C(0xD9E5E2FE3E9B4E31),
2295           UINT64_C(0xA6A859A0F6086336), UINT64_C(0x0C2A442AA9C19F84)}},
2296         {{UINT64_C(0x66FEA8413BC0AD7D), UINT64_C(0xCD3A546C32C9158E),
2297           UINT64_C(0xACD2EE7F8FE1DF7F), UINT64_C(0x10F58C0AEBE9621E)},
2298          {UINT64_C(0x80047C54478B667D), UINT64_C(0x9EAE5FAA89870DCE),
2299           UINT64_C(0xC05BEB330520A005), UINT64_C(0x2CFBC921352AC891)}},
2300         {{UINT64_C(0x6842E6B8632F6D73), UINT64_C(0x6F2B57242B9FFAEA),
2301           UINT64_C(0x7ACCC9829341D2FA), UINT64_C(0x6DAD9A1188809B65)},
2302          {UINT64_C(0x3411850CB6CC2240), UINT64_C(0x8547BCAFB64937E1),
2303           UINT64_C(0x49AEDD5F6978F636), UINT64_C(0x38F5975285A53D2A)}},
2304         {{UINT64_C(0x5C38EB49F5F5A2D0), UINT64_C(0xE028121BE3BF779C),
2305           UINT64_C(0x649997C8A783D5E3), UINT64_C(0x04DE984A2C06CC0F)},
2306          {UINT64_C(0x52C834B0A49D6239), UINT64_C(0x070A1B09628413AC),
2307           UINT64_C(0x2FBE0CA5A8624A1E), UINT64_C(0x687D93C3268D930A)}},
2308         {{UINT64_C(0xC7CD6805314C47A4), UINT64_C(0x8BD0C630CE7A9A6D),
2309           UINT64_C(0xCDB2DAD534F727BA), UINT64_C(0x7814C41425DB0189)},
2310          {UINT64_C(0xD7F9C5DC7DD9CAEE), UINT64_C(0xDA6EACC8798690E4),
2311           UINT64_C(0x705794E36B675E01), UINT64_C(0x4A31D71475C5EC38)}},
2312         {{UINT64_C(0xC162A3EA0519D5F2), UINT64_C(0x92146A782958FABF),
2313           UINT64_C(0x1E63CBE46CB31EB0), UINT64_C(0x77CE5AADFBC5AD0F)},
2314          {UINT64_C(0x3631E47032605DC6), UINT64_C(0xC7D1C72F43413DD3),
2315           UINT64_C(0x171A37940DF6B7C9), UINT64_C(0x6D7117432B5A08BC)}},
2316         {{UINT64_C(0xDDC8057D509EF0F2), UINT64_C(0x05C0B92B6CABB486),
2317           UINT64_C(0xD49692B64244D919), UINT64_C(0x4E181744D297F56E)},
2318          {UINT64_C(0x902F6E73F8CBB897), UINT64_C(0xC3B21FE156D01382),
2319           UINT64_C(0xA858ABE146890F6D), UINT64_C(0x46B5E2C9506858AF)}},
2320         {{UINT64_C(0x30441281F4DEDE56), UINT64_C(0x13F06FBBA195AEDE),
2321           UINT64_C(0xAD5F575B2FDD3BFF), UINT64_C(0x680F656D32ACB590)},
2322          {UINT64_C(0xFB60A8E1E3FAABA7), UINT64_C(0xC8FBC1E489A14827),
2323           UINT64_C(0x5835453FA8616136), UINT64_C(0x02826A47E6F4926F)}},
2324         {{UINT64_C(0xAF4319A174F32180), UINT64_C(0x4C9FDD166C2C1712),
2325           UINT64_C(0x59CA4FD4AC7E14A7), UINT64_C(0x07AA6E2FABBD4EA4)},
2326          {UINT64_C(0xB4BD441CFE9F121F), UINT64_C(0xDEBB4356CDA452C5),
2327           UINT64_C(0xC29F1CFA51C9F451), UINT64_C(0x7E1EEF4C83F598D8)}},
2328     },
2329     {
2330         {{UINT64_C(0xFC41A3215014135F), UINT64_C(0xBE95F9BA3EEADF3F),
2331           UINT64_C(0x054B12123203A540), UINT64_C(0x6DD2FD173721C745)},
2332          {UINT64_C(0xF86B85785A682B59), UINT64_C(0x872AA481BE801F7D),
2333           UINT64_C(0x64C1600C14F865F2), UINT64_C(0x4BDD47AA25365449)}},
2334         {{UINT64_C(0xC96A964CF3A3469F), UINT64_C(0x273C5C859F7DA0E3),
2335           UINT64_C(0x88EDC4AC4C1A9DCD), UINT64_C(0x77623444B48E4CAA)},
2336          {UINT64_C(0x7AF34A9C31581FF7), UINT64_C(0x23328C37BB57F7CC),
2337           UINT64_C(0xE920D8E98B7C86AB), UINT64_C(0x1C7A7A409DE6D64C)}},
2338         {{UINT64_C(0x0BCDCD2279B9451C), UINT64_C(0x2920B43558F5241B),
2339           UINT64_C(0xC24DF7159B33EF3D), UINT64_C(0x15252C5BF2600224)},
2340          {UINT64_C(0xF9C8D8A69A9160B6), UINT64_C(0x3186F2F9A6B9A6B8),
2341           UINT64_C(0xC37267DCA377E98A), UINT64_C(0x71319A0A37957189)}},
2342         {{UINT64_C(0x48E5033F6BAF6AE5), UINT64_C(0x72379B2EA460FCE9),
2343           UINT64_C(0xFC753D47F3D2FA46), UINT64_C(0x3B67685AED9EDF72)},
2344          {UINT64_C(0x1608E304F712500F), UINT64_C(0xDFA358A49EE1B42A),
2345           UINT64_C(0xE7A4B37634B8345C), UINT64_C(0x7D0E0BF306753C17)}},
2346         {{UINT64_C(0xA88526A68FA62042), UINT64_C(0xD6F32BB5393006BD),
2347           UINT64_C(0x14804978A5DD5045), UINT64_C(0x34C02662BF0C5E13)},
2348          {UINT64_C(0xF9BEEBF9376E3E3D), UINT64_C(0xFD7740415923DC61),
2349           UINT64_C(0xFE77BDFAF9735CF5), UINT64_C(0x2E476E224077CFCC)}},
2350         {{UINT64_C(0xAB8E52EB9BA457EF), UINT64_C(0x95F6C5FE0ABED212),
2351           UINT64_C(0x7204B1A6386620FF), UINT64_C(0x463B7474DD180719)},
2352          {UINT64_C(0x7F7D27AAF991D8EE), UINT64_C(0xA7EB10858F67722D),
2353           UINT64_C(0x78D7095BE331480A), UINT64_C(0x1DCC8C1266A1C8FA)}},
2354         {{UINT64_C(0xD4C39C183E6A04C1), UINT64_C(0x73DB1C4DB598ABEE),
2355           UINT64_C(0x381F9780DF4A7D42), UINT64_C(0x3C19A23152F860CD)},
2356          {UINT64_C(0x7EC899343EF00740), UINT64_C(0x50867788F37FE0D5),
2357           UINT64_C(0x502D870B43E84D4A), UINT64_C(0x5F8A84138F744749)}},
2358         {{UINT64_C(0x1C41AAADFAECCFE4), UINT64_C(0xC324F3B921461F41),
2359           UINT64_C(0x165ABA3F4E90C0AB), UINT64_C(0x2F96CED55F88E7D3)},
2360          {UINT64_C(0x8CA366FCC0E52768), UINT64_C(0x6CCA017CA55249A7),
2361           UINT64_C(0x41ED002F0F7EBCA2), UINT64_C(0x0C33B371A2BAF655)}},
2362         {{UINT64_C(0x3B94CD9C62B928CE), UINT64_C(0x5BC43A6A39729345),
2363           UINT64_C(0x044D0C0FC47D223C), UINT64_C(0x3B64B38DB0493367)},
2364          {UINT64_C(0x82AFB645EB74A6C2), UINT64_C(0x0CB01E22D876D71C),
2365           UINT64_C(0xCE2A7DCC29C6BCD0), UINT64_C(0x4753DE1CDFD644EC)}},
2366         {{UINT64_C(0xE69FC90362188792), UINT64_C(0xD91DB9BC4914328B),
2367           UINT64_C(0x44953F4D3B68F8D0), UINT64_C(0x2950435D0654B283)},
2368          {UINT64_C(0xE599A4AEBE88F609), UINT64_C(0xF801CD9090F5D10E),
2369           UINT64_C(0x0AB78DB1D4F1D3D9), UINT64_C(0x3ED9666AC0F71ECB)}},
2370         {{UINT64_C(0x6046A505E1E73E59), UINT64_C(0x8723A3ECF3B5C2E0),
2371           UINT64_C(0x4BD95BF6E22C1555), UINT64_C(0x50DC33DB6DA421E9)},
2372          {UINT64_C(0xCFB51E95F1B01327), UINT64_C(0xE7013F2A199A8765),
2373           UINT64_C(0xF486FEA777504B0B), UINT64_C(0x2AF0F7E9F9BA61C6)}},
2374         {{UINT64_C(0x9DBA1A02BE00B841), UINT64_C(0x488BA4558BED5F08),
2375           UINT64_C(0xF6814A6467F1040E), UINT64_C(0x23AC4762DC252336)},
2376          {UINT64_C(0x25040F02F0ED0577), UINT64_C(0x65209B22C6FFAE9C),
2377           UINT64_C(0xCC441A8C485AA0AC), UINT64_C(0x10DFACB659D63A8A)}},
2378         {{UINT64_C(0xBF4A0569C7D86B28), UINT64_C(0x5CDA94C4DBDA9DA4),
2379           UINT64_C(0x2235C4CE69058335), UINT64_C(0x68FA5E7CD30C89E2)},
2380          {UINT64_C(0xBB286D3959097B5B), UINT64_C(0x87DA80BB9A20BA7E),
2381           UINT64_C(0x85EF865E56F47E54), UINT64_C(0x5BB8786774ABFA5B)}},
2382         {{UINT64_C(0x5DB14FABDE2FA36E), UINT64_C(0x84E3B54677775F09),
2383           UINT64_C(0xDA734523DA951D99), UINT64_C(0x04A890973975026E)},
2384          {UINT64_C(0xB5753599C0D12BE1), UINT64_C(0x05670CE9FB864D61),
2385           UINT64_C(0xB7153502305BF3CF), UINT64_C(0x7A9BB3572E60AF62)}},
2386         {{UINT64_C(0xF43CDA07C7566DA5), UINT64_C(0x7FC4C7FC53FA4196),
2387           UINT64_C(0x1E20E0ED88DCC9F3), UINT64_C(0x7317C7E5FEE23DDA)},
2388          {UINT64_C(0x0305E13F43017070), UINT64_C(0x5568410C6B1CA7C0),
2389           UINT64_C(0x0E5D55BA104BA029), UINT64_C(0x118B284E90FD49F8)}},
2390         {{UINT64_C(0xCA0F7B5B8F3C6D8A), UINT64_C(0xAF72DEE0AF7ECBF6),
2391           UINT64_C(0x21C86D85BB0EC4F1), UINT64_C(0x0303BC47F0525D17)},
2392          {UINT64_C(0x6ADCAB9F896FFCC0), UINT64_C(0x65764C4524E970CA),
2393           UINT64_C(0x0000F14C1C3CA718), UINT64_C(0x01CF1DDBD0292587)}},
2394     },
2395     {
2396         {{UINT64_C(0xEC4FABCC86111EBA), UINT64_C(0x599C20B6BBBB793F),
2397           UINT64_C(0xF74AE7475657668F), UINT64_C(0x24AF29B277BAE892)},
2398          {UINT64_C(0x47D6876BCFAC9D5E), UINT64_C(0xCACF9F5024369E14),
2399           UINT64_C(0x8A231D746F9CAFEF), UINT64_C(0x57645A4EB69AAE58)}},
2400         {{UINT64_C(0x440A3B15489900F6), UINT64_C(0x4B642FD3961AC3C2),
2401           UINT64_C(0x3D668599C265B973), UINT64_C(0x5FA0E65D1139CE78)},
2402          {UINT64_C(0x3FF15AF41FAA710E), UINT64_C(0xE45D35CEA9422FC0),
2403           UINT64_C(0x56904C06BD7BB349), UINT64_C(0x40C5BEE0E529989D)}},
2404         {{UINT64_C(0x8FA4686170B20298), UINT64_C(0xEC6295384838A136),
2405           UINT64_C(0x23ADE0F6137F66D6), UINT64_C(0x1A92E05C8EA53E76)},
2406          {UINT64_C(0x51728E279D51EB7A), UINT64_C(0xA6B0B758C4352E35),
2407           UINT64_C(0x84C5933137A11B35), UINT64_C(0x3933EFC1F66B75C7)}},
2408         {{UINT64_C(0x7FB68D6266916D0A), UINT64_C(0x3325D42EF28A9B14),
2409           UINT64_C(0x75E83A658592B544), UINT64_C(0x524D1CE02718628F)},
2410          {UINT64_C(0x88A110EA3C584D76), UINT64_C(0x6B034AC44AC09AAC),
2411           UINT64_C(0x0648863584FD3A36), UINT64_C(0x516F0EB087D944E1)}},
2412         {{UINT64_C(0xE2016DA0DF11D0BB), UINT64_C(0xB34EB471B01F6540),
2413           UINT64_C(0x13E3D330165CBB24), UINT64_C(0x3E755D117CF7F676)},
2414          {UINT64_C(0xD70CF4F84FEA9A69), UINT64_C(0x98F59E0AD18F4337),
2415           UINT64_C(0x7CCE7CE6826344BA), UINT64_C(0x30D129D7F4004BBE)}},
2416         {{UINT64_C(0x016EF317BA9CB975), UINT64_C(0x8EEBED19E4B3AB4D),
2417           UINT64_C(0x8C597DF0170A2570), UINT64_C(0x451538D85BE6DE70)},
2418          {UINT64_C(0x6C711DAC7A64792F), UINT64_C(0x8F1896EB217EC8FB),
2419           UINT64_C(0x82E9C20B7FE18DED), UINT64_C(0x6CEBF4A7B0C5F622)}},
2420         {{UINT64_C(0xD9403EB549CCC64F), UINT64_C(0x807EBD5628B8A3FD),
2421           UINT64_C(0xF08BB6590F291E12), UINT64_C(0x020D13E39C3F4432)},
2422          {UINT64_C(0xDA247896752BB92E), UINT64_C(0x9954179486EAFA7A),
2423           UINT64_C(0x213E94BA274E36AD), UINT64_C(0x4CC0F1FB61A71333)}},
2424         {{UINT64_C(0x19CC11BD06478801), UINT64_C(0x1251562A6D18216A),
2425           UINT64_C(0x7A5F06BBCDD307FC), UINT64_C(0x4285F6ABFAA9CA2A)},
2426          {UINT64_C(0x5A92283181258996), UINT64_C(0x8F7CF8EE27B8B018),
2427           UINT64_C(0xF030BEF37F81A62D), UINT64_C(0x417ACBC1CD4FD4E7)}},
2428         {{UINT64_C(0xCFB0EA58EC64412F), UINT64_C(0x9547B64A6091E621),
2429           UINT64_C(0x5EA49C7EFD0C9815), UINT64_C(0x6789055AE78B355C)},
2430          {UINT64_C(0x8D743E9877E9A73A), UINT64_C(0xB032EA6A2EA3FA49),
2431           UINT64_C(0x52EA3801CEAAA33A), UINT64_C(0x73B3BB8DF2C3E22B)}},
2432         {{UINT64_C(0xAA2A12917DB9E301), UINT64_C(0x7F29770FA1293DD7),
2433           UINT64_C(0x3135BB2159683DEC), UINT64_C(0x070F8DF77785B505)},
2434          {UINT64_C(0x8F2158EA37F53677), UINT64_C(0x96CC7B9DABE1AF1C),
2435           UINT64_C(0x7F9779156D6477D6), UINT64_C(0x55DB3922DF370EAF)}},
2436         {{UINT64_C(0x3028C03AA9DAC7AE), UINT64_C(0x16F7DF0DBAE06BE0),
2437           UINT64_C(0x09548398410D57D9), UINT64_C(0x5E9C7F431510D51F)},
2438          {UINT64_C(0x033B9BE2D07717B3), UINT64_C(0x0D5D8116EF08AB91),
2439           UINT64_C(0xD5A172B1EEEFE88F), UINT64_C(0x72B1D29F0996294E)}},
2440         {{UINT64_C(0x9E2B79FBE4D0965C), UINT64_C(0x01F403EEF49D8B8E),
2441           UINT64_C(0xBD4D2D48CEB12D6A), UINT64_C(0x4D04DD9A11FB24FB)},
2442          {UINT64_C(0x7E613EC5E5C8D24C), UINT64_C(0x568BEFE8B918E543),
2443           UINT64_C(0xD6456D1EE966DF28), UINT64_C(0x2DDEAD63BAFC71E2)}},
2444         {{UINT64_C(0x1D794F92448D72E9), UINT64_C(0x3978052EE7E62BF2),
2445           UINT64_C(0xF6C7A72EE2B92538), UINT64_C(0x43879A886EF321F0)},
2446          {UINT64_C(0x2A82314034F6FFBC), UINT64_C(0x26F84E5135F4C485),
2447           UINT64_C(0xDEE65540028BFA7E), UINT64_C(0x56216E9D5F033058)}},
2448         {{UINT64_C(0x31CA5470CBC772EE), UINT64_C(0xD3621E11811BB5D0),
2449           UINT64_C(0x501C4C4770863D71), UINT64_C(0x0564518ED28D6BDD)},
2450          {UINT64_C(0x60E3B89BD35B64B9), UINT64_C(0xB4F2599A6621A688),
2451           UINT64_C(0x1A8C45083B5E116D), UINT64_C(0x633EF5CCFABF3125)}},
2452         {{UINT64_C(0x0DB1D2515D4FF62A), UINT64_C(0x6CBD00EB4B17D658),
2453           UINT64_C(0x2FA38212FA1DB737), UINT64_C(0x07B18CB893A7FA03)},
2454          {UINT64_C(0x531E47EF548E5F82), UINT64_C(0xAE7B94FD8276963C),
2455           UINT64_C(0x8055D82A6181A13A), UINT64_C(0x5725B51223B6E361)}},
2456         {{UINT64_C(0xD84C70416D8B1FFE), UINT64_C(0xF68ACA0B5D994200),
2457           UINT64_C(0x32BF99446BB908E2), UINT64_C(0x1240A3E61AD88DB1)},
2458          {UINT64_C(0xB0BE96AAA92B6472), UINT64_C(0xEF88A155A1B7726C),
2459           UINT64_C(0x000FD9ED9349F496), UINT64_C(0x377DCBAD454A05D9)}},
2460     },
2461     {
2462         {{UINT64_C(0xD0A092CDC04111D2), UINT64_C(0x5C43A94C338F06D6),
2463           UINT64_C(0x697B4C2625E964F3), UINT64_C(0x2CD5A0597572CCFD)},
2464          {UINT64_C(0xA09FC4D4B5B523E4), UINT64_C(0x7D8141E84E1E9042),
2465           UINT64_C(0x2462512BD637409E), UINT64_C(0x503F032F7CB2CE75)}},
2466         {{UINT64_C(0xC56F38E3BCBF1450), UINT64_C(0x09F4FC77CF2E5594),
2467           UINT64_C(0xF449C3E60FCB653A), UINT64_C(0x6A1FE75264A53C65)},
2468          {UINT64_C(0xFF366FED7C039488), UINT64_C(0x23F58BA58C99A6CB),
2469           UINT64_C(0x4B5546C68D67F6D6), UINT64_C(0x03405C85178B1668)}},
2470         {{UINT64_C(0x969F1B33C0C86696), UINT64_C(0x9346D06C13746468),
2471           UINT64_C(0x68AED3C8AE0C6D62), UINT64_C(0x7B3D536174FE63D5)},
2472          {UINT64_C(0xFEE8416BC4F4B65D), UINT64_C(0xC79BF488554C6D0A),
2473           UINT64_C(0x191D5D27DC402BB0), UINT64_C(0x31B00167E087EB9F)}},
2474         {{UINT64_C(0xD5FE0979E05D281F), UINT64_C(0x8373AB503485446B),
2475           UINT64_C(0xCE5258BA9223681F), UINT64_C(0x5F82843EA37BF244)},
2476          {UINT64_C(0x94ED780BCFC16536), UINT64_C(0x6A9739B3BD477733),
2477           UINT64_C(0x137D68F2A04A4195), UINT64_C(0x3A0F27E80032BFCE)}},
2478         {{UINT64_C(0x7EADE421358382F9), UINT64_C(0x490B9CA692E3D912),
2479           UINT64_C(0x040CE73EF1AFBC2A), UINT64_C(0x5745D47311AE91BA)},
2480          {UINT64_C(0x625BED61CE303B77), UINT64_C(0x85B2A1EB85B03A1D),
2481           UINT64_C(0x764F62E43D7C02E0), UINT64_C(0x22C2D16FA7AF6DDE)}},
2482         {{UINT64_C(0x5B985DE6D19377BE), UINT64_C(0x0AF85A06D8E43A10),
2483           UINT64_C(0x1465E5040519F4C6), UINT64_C(0x5DA01665E3E20BA3)},
2484          {UINT64_C(0xCD9B8E9B675D9E2A), UINT64_C(0x4C77E1AD6448A2CD),
2485           UINT64_C(0xD6094BAD1E5D4465), UINT64_C(0x4C352951C50DB788)}},
2486         {{UINT64_C(0x42581152EE5AB903), UINT64_C(0xDAD2DBC963311418),
2487           UINT64_C(0xBCA4F70BB885E56A), UINT64_C(0x1F5DD363B94E0876)},
2488          {UINT64_C(0xF9AD5D043FFF479E), UINT64_C(0xEF1176E5FE06AD2B),
2489           UINT64_C(0x46ACB00A216F77AF), UINT64_C(0x709CF4EB857C4F78)}},
2490         {{UINT64_C(0x70CD666ED0D2FF1C), UINT64_C(0x4BAD4A6AE7EFE4AD),
2491           UINT64_C(0xB43F6C2D0FA72024), UINT64_C(0x0D78F8E2E90C0617)},
2492          {UINT64_C(0x543B9662F80DCAA7), UINT64_C(0xB02FB3BCF28ADFAF),
2493           UINT64_C(0x26C17651C51C54C3), UINT64_C(0x0815F6373D648D88)}},
2494         {{UINT64_C(0xAC4F43C1AEA98FA6), UINT64_C(0x2D223416AC4398C6),
2495           UINT64_C(0x48B2EEADDA5C5070), UINT64_C(0x632B65F1BE666F70)},
2496          {UINT64_C(0x971D3BC0952021BE), UINT64_C(0x9FDCB7E023B2C578),
2497           UINT64_C(0x476D47153CC21796), UINT64_C(0x4015565F95832A94)}},
2498         {{UINT64_C(0x8913AFAC13CA725C), UINT64_C(0xA56DC461DC18F0D9),
2499           UINT64_C(0xAC3AC72010F3AAFE), UINT64_C(0x5D75567EC628D69C)},
2500          {UINT64_C(0xC11BE9DCEEEA4BF7), UINT64_C(0xAD97FBCA1C193BD5),
2501           UINT64_C(0xD1EC5BCEC58123E8), UINT64_C(0x0F6DF9309C73D4E5)}},
2502         {{UINT64_C(0xE80A0ADAFD759FFD), UINT64_C(0xE52DF94B239CAFC0),
2503           UINT64_C(0x59640161FE7A43E9), UINT64_C(0x7A96995CDB1A38F0)},
2504          {UINT64_C(0xA46A15037CD5011B), UINT64_C(0x75CFB637AC0E9689),
2505           UINT64_C(0x27B740CA97AAD2BA), UINT64_C(0x64A0748BEAD2F776)}},
2506         {{UINT64_C(0xB67E5BB50625B3B1), UINT64_C(0x2FE19FFBC66D2832),
2507           UINT64_C(0x47815666F70C07CF), UINT64_C(0x5A1AA24AA43E52AB)},
2508          {UINT64_C(0x04EE11F84CAC0E66), UINT64_C(0x51E515833A3A4836),
2509           UINT64_C(0x46755F49B44F6DEC), UINT64_C(0x6388408BC1E9B282)}},
2510         {{UINT64_C(0xD47AA9A69DE7A6A7), UINT64_C(0xEC94AD9B189BC9D2),
2511           UINT64_C(0xFA89099D8EC0E950), UINT64_C(0x1B9FC2069F64D27F)},
2512          {UINT64_C(0x765724840B729DE1), UINT64_C(0xFE9E8E714BE22EB8),
2513           UINT64_C(0x910F0456F9DB5942), UINT64_C(0x4D018459C617D82B)}},
2514         {{UINT64_C(0xB082B58AF5516C6F), UINT64_C(0xFFBA0E73567A8CF5),
2515           UINT64_C(0x08FF64CE8A6DD4A0), UINT64_C(0x6CF3C89C69A9F66A)},
2516          {UINT64_C(0x356782BA62FEB0A7), UINT64_C(0x1A18720D3E2907F9),
2517           UINT64_C(0xF840FFA30BBD9D92), UINT64_C(0x41D9EECA20926421)}},
2518         {{UINT64_C(0xCF2E8AACB6B08321), UINT64_C(0xC76FBE12010D91C0),
2519           UINT64_C(0x5492475068E35E02), UINT64_C(0x74DBA2E19AEE00F8)},
2520          {UINT64_C(0x94C70D6DC5504E82), UINT64_C(0x0BDF415FEA1770F7),
2521           UINT64_C(0xDA45B7003CA6DB0A), UINT64_C(0x473C6A04E133A980)}},
2522         {{UINT64_C(0xD1FF6C1E1E188071), UINT64_C(0x621A7D3CEA3F16F8),
2523           UINT64_C(0x604673076A160F47), UINT64_C(0x37CA7D3D32DC84EE)},
2524          {UINT64_C(0x54F5F7F667DDFDB5), UINT64_C(0x3A8482F9921BA04B),
2525           UINT64_C(0x842F49501A28E238), UINT64_C(0x3A4DC9177214FAFD)}},
2526     },
2527     {
2528         {{UINT64_C(0xEDD8360CEEA25E82), UINT64_C(0x3DB6D933FB7B7ED0),
2529           UINT64_C(0x882F3C0BABF15199), UINT64_C(0x228664A2516E349D)},
2530          {UINT64_C(0x96E6DCF7E88173DF), UINT64_C(0x382C8D3BD7EC0BC3),
2531           UINT64_C(0xFBFF6D216FA5FA58), UINT64_C(0x780039802F41C959)}},
2532         {{UINT64_C(0x713BA43B9D9ACF9C), UINT64_C(0xF59A252D94876559),
2533           UINT64_C(0x8B310954437B8ED5), UINT64_C(0x76A83790E474E98E)},
2534          {UINT64_C(0x84C1386AF6040B05), UINT64_C(0x69FA9F43BF3D8189),
2535           UINT64_C(0x5584164CA98D4866), UINT64_C(0x6C89CE1D3B9045D0)}},
2536         {{UINT64_C(0xD6EF7540B522FB28), UINT64_C(0xDB561B56BB28D745),
2537           UINT64_C(0xC9F7543EEFA58B87), UINT64_C(0x5F02A23BE9062979)},
2538          {UINT64_C(0xFD3C0C196809D624), UINT64_C(0x94481554A92EB229),
2539           UINT64_C(0x72D8EC53F5147EFB), UINT64_C(0x143026610D1BA626)}},
2540         {{UINT64_C(0x0B35BD5989020800), UINT64_C(0x3C6F1527430D7DEB),
2541           UINT64_C(0x9BEB3C8E2FFFA0E0), UINT64_C(0x7E181B78AFD09A19)},
2542          {UINT64_C(0xE82FD9573B2F0B49), UINT64_C(0x4C9461B10BC0F9DA),
2543           UINT64_C(0x87D78C412B1C8B85), UINT64_C(0x775BED20C1F5BDA1)}},
2544         {{UINT64_C(0x883AE89B16350593), UINT64_C(0x85D429CB0C19FEC8),
2545           UINT64_C(0x5938BDEC5742C36D), UINT64_C(0x2DDBC7EBDA8A21B7)},
2546          {UINT64_C(0xA249BDE407A2E700), UINT64_C(0x42A3897CE8BD6215),
2547           UINT64_C(0x87F30BA7732FF181), UINT64_C(0x5385D7091B912C57)}},
2548         {{UINT64_C(0x2B5C555B288041F5), UINT64_C(0xD3D900401F425866),
2549           UINT64_C(0x37E40CD202E0FA71), UINT64_C(0x08B37F263A386038)},
2550          {UINT64_C(0x165BD7FB5DE1ED78), UINT64_C(0x22949E810829ECC9),
2551           UINT64_C(0xBB8705CCBCE3D01F), UINT64_C(0x7961BE851D233CDF)}},
2552         {{UINT64_C(0x5D3DBC6B7659B477), UINT64_C(0xFD86577950EF08EB),
2553           UINT64_C(0x502729E8F34EA1A5), UINT64_C(0x1548526ED2B64602)},
2554          {UINT64_C(0xB13632FDB91D2675), UINT64_C(0x09A42003F7B37397),
2555           UINT64_C(0x37D18F37CCFC4532), UINT64_C(0x3FAEF63B73C7082C)}},
2556         {{UINT64_C(0x3365445FE666DB6D), UINT64_C(0x9051FFF5339A0076),
2557           UINT64_C(0x6167FB769BD6D01D), UINT64_C(0x09737137CA087B41)},
2558          {UINT64_C(0xCA2193AEB3270BA7), UINT64_C(0xEF0744C28F2217B3),
2559           UINT64_C(0x3E030D58F0DD10D8), UINT64_C(0x667246DBCCB4F2F9)}},
2560         {{UINT64_C(0x31F3030E3773EC8C), UINT64_C(0xAF2B31235AD56010),
2561           UINT64_C(0xFC118587B37E9062), UINT64_C(0x52840C2C9C2D5406)},
2562          {UINT64_C(0xA96D3DFF6670ACBB), UINT64_C(0xF469982F772EC6D3),
2563           UINT64_C(0x5BE20628A9DF4C88), UINT64_C(0x59D01479673633BC)}},
2564         {{UINT64_C(0xC9223750AFB5083B), UINT64_C(0xF1EB451E191C2160),
2565           UINT64_C(0x0D913794A38EC005), UINT64_C(0x31062E9E83FD1D18)},
2566          {UINT64_C(0x070538F55F4816AD), UINT64_C(0x90D4855D925F5DA1),
2567           UINT64_C(0xC0BBA87B22F455B6), UINT64_C(0x517B5F80F48D2AE5)}},
2568         {{UINT64_C(0x0D8B670A3F4FA7CA), UINT64_C(0xE29C88493D114EB2),
2569           UINT64_C(0x1823780D916A187E), UINT64_C(0x6961C48365EE66A0)},
2570          {UINT64_C(0x2F6FB20A62FDC12C), UINT64_C(0x51414E5F0CFDDE0C),
2571           UINT64_C(0x16BD56A7DCA39073), UINT64_C(0x0CFE6DAF648FFD43)}},
2572         {{UINT64_C(0x3789F4CAAEBA9241), UINT64_C(0xE8056BC6107777C6),
2573           UINT64_C(0x6EE564C33CB20826), UINT64_C(0x5DF3634745448C69)},
2574          {UINT64_C(0xFD0FA84BB22CE624), UINT64_C(0x2AA19672AC753D50),
2575           UINT64_C(0x29A1464F677CC0D0), UINT64_C(0x7C2237B13CEF5493)}},
2576         {{UINT64_C(0x87C2587C24255918), UINT64_C(0x9AA89A0B90B35A37),
2577           UINT64_C(0x9932EB7810E7CAEF), UINT64_C(0x49278F16CDE31568)},
2578          {UINT64_C(0xA4D33C6141188ED9), UINT64_C(0xC587BDE005AC3A1D),
2579           UINT64_C(0x2A5C5ACC7248B5E0), UINT64_C(0x60026A1D8510D2CB)}},
2580         {{UINT64_C(0xE57CB0C96BAF603C), UINT64_C(0x527F28A6AB770AF0),
2581           UINT64_C(0x2850D8E6016F2BC1), UINT64_C(0x0EC2A46C936DC2EC)},
2582          {UINT64_C(0xA0BC5306D4F23FC2), UINT64_C(0x6DBEDA2653A0130F),
2583           UINT64_C(0xB1D52F87EE3314B7), UINT64_C(0x17168B126C234CF5)}},
2584         {{UINT64_C(0x8B8BC181DADF17D5), UINT64_C(0x31EC3CADFAFFA918),
2585           UINT64_C(0x4611A482274E4658), UINT64_C(0x5A9E365273D35EAD)},
2586          {UINT64_C(0xBA68825BF4028FC7), UINT64_C(0x142859D562E203F5),
2587           UINT64_C(0xCE516AC41C817A9E), UINT64_C(0x4201468257223F8D)}},
2588         {{UINT64_C(0x51FBFB2EB4B66798), UINT64_C(0x3A3F15910EA9C4EF),
2589           UINT64_C(0x3FD3D026E8814805), UINT64_C(0x3CA531E4B0C8DFD0)},
2590          {UINT64_C(0x69A6B3F8E585A960), UINT64_C(0x1627CC77BD3F567D),
2591           UINT64_C(0x6F4EF4305DB9CFD0), UINT64_C(0x05B567078D02278A)}},
2592     },
2593     {
2594         {{UINT64_C(0x6663F2F310B96338), UINT64_C(0x69373D1FCE8CA31C),
2595           UINT64_C(0x3D31C5CFD67AEC10), UINT64_C(0x2FAF554516F2547E)},
2596          {UINT64_C(0xF6E397D51EA2EA64), UINT64_C(0x2281A0DFEEAEBE7A),
2597           UINT64_C(0x72E53254FA2527EC), UINT64_C(0x660D059A76432155)}},
2598         {{UINT64_C(0xD3CA8B132C66D937), UINT64_C(0xC6F34B08CD2DF849),
2599           UINT64_C(0x9AF2C9E3A23A9F73), UINT64_C(0x24D44BD9702388E9)},
2600          {UINT64_C(0x8DA4D6A4D1B3DA10), UINT64_C(0xB9FAFBF440B93B10),
2601           UINT64_C(0xBBE51BB3EFCFD2A3), UINT64_C(0x68BE03951844581D)}},
2602         {{UINT64_C(0xDECABD8C0EA1FAE1), UINT64_C(0xA7499225FDFED7C2),
2603           UINT64_C(0x08489E35FB468B83), UINT64_C(0x5B68934443D95F9C)},
2604          {UINT64_C(0x9FC8364A9D2F522E), UINT64_C(0x114DB31A3A5D27A4),
2605           UINT64_C(0xC6A35992E33A9EC8), UINT64_C(0x6FE9EC3BDC9ACAF6)}},
2606         {{UINT64_C(0x98AE2D66DEAFC64C), UINT64_C(0x95AAC8EFABE706B7),
2607           UINT64_C(0xB15A6604223DFA3B), UINT64_C(0x77DBC24AE24B43CB)},
2608          {UINT64_C(0x65D6F8718542FA2A), UINT64_C(0x1093B2735D326A1A),
2609           UINT64_C(0xBA82D607F137AFEF), UINT64_C(0x502B32E3B9DEA6A7)}},
2610         {{UINT64_C(0x88906BD6885CA6CE), UINT64_C(0x136ADF9A1D36BFEE),
2611           UINT64_C(0xF844088C09AA61E3), UINT64_C(0x4E508EA351BAC299)},
2612          {UINT64_C(0x251ACD26EB821936), UINT64_C(0xDF6AD7D543D90E10),
2613           UINT64_C(0xEBCD7046DE7F14B9), UINT64_C(0x1DB258B1AB503259)}},
2614         {{UINT64_C(0x348E301890AD5D55), UINT64_C(0x0EF6BE737067806A),
2615           UINT64_C(0x072C113441627FCC), UINT64_C(0x48EE7606E904F823)},
2616          {UINT64_C(0xEE6AB582D9FD5EF3), UINT64_C(0x57765D0317AB50BC),
2617           UINT64_C(0x1CCFB407FB7DEC68), UINT64_C(0x2E1771C7141DF51D)}},
2618         {{UINT64_C(0xCBDD6235A013284B), UINT64_C(0x4D93FD8720D07125),
2619           UINT64_C(0xB3D055B3D485418E), UINT64_C(0x4EFB8763C67ADD2D)},
2620          {UINT64_C(0xEC3693821B2DF427), UINT64_C(0x2500979164D0DDF4),
2621           UINT64_C(0x9BD42FFC163056C8), UINT64_C(0x605277925B88BEBA)}},
2622         {{UINT64_C(0x6D5D6A869D82DADF), UINT64_C(0xC3BA9A167C24A1CA),
2623           UINT64_C(0x838167EC2E6981CC), UINT64_C(0x7FB5D8577E1E4237)},
2624          {UINT64_C(0x83B2C2FC86A40BC7), UINT64_C(0x679D2DFC6F9AC4FB),
2625           UINT64_C(0x0B3714CDE45455EF), UINT64_C(0x1C8D833D394A7797)}},
2626         {{UINT64_C(0x1FBF89614E641C9D), UINT64_C(0x3330DAB0D951DFC8),
2627           UINT64_C(0x9D4EBA4D051D96DB), UINT64_C(0x27C6DBF023066924)},
2628          {UINT64_C(0xB950C648DA5D1D79), UINT64_C(0x544D46BA5E9CD783),
2629           UINT64_C(0xFA77226FE69BA3EF), UINT64_C(0x0A93D219E4DA8423)}},
2630         {{UINT64_C(0x7C377CC65BDCA76B), UINT64_C(0x7DF505D7DC58D194),
2631           UINT64_C(0x18A24C0B13E389E1), UINT64_C(0x5E0782DD6C3972FD)},
2632          {UINT64_C(0x97AD477E6680FCE1), UINT64_C(0x6B07BF223CBAB792),
2633           UINT64_C(0xB8DF3C73DC68C9E2), UINT64_C(0x33AB5A4CC04B2749)}},
2634         {{UINT64_C(0xD151C7627E79B5A7), UINT64_C(0xA4356B79C82C7B8A),
2635           UINT64_C(0x931DDDE896E0A2E2), UINT64_C(0x40378EB252C54FDC)},
2636          {UINT64_C(0xA6BBD5E340C24003), UINT64_C(0xB4F3246E65C34FEA),
2637           UINT64_C(0x780B21ED9C767A23), UINT64_C(0x5F1E95FE52BD7E83)}},
2638         {{UINT64_C(0x4F3453DFCF39F9C4), UINT64_C(0xA3E1CFD1B8CC2CA6),
2639           UINT64_C(0xE49BC49C4B898859), UINT64_C(0x4FFD7BD66C0BF055)},
2640          {UINT64_C(0x7DE7604CD139AD1B), UINT64_C(0x6973F5EB2A3CE8FE),
2641           UINT64_C(0xAC66FF97F9501ECC), UINT64_C(0x3D96F1E2A97D46CD)}},
2642         {{UINT64_C(0x70D5A0D06106EB96), UINT64_C(0x938E038F398C1FD9),
2643           UINT64_C(0xE66B70071F3A1AA9), UINT64_C(0x42BDB264F5BD9308)},
2644          {UINT64_C(0x4B3FD7545AF84957), UINT64_C(0x9E3E17FA4E27DC6B),
2645           UINT64_C(0x384FCACD51D8560B), UINT64_C(0x42F00D11F8068C09)}},
2646         {{UINT64_C(0x794C1E6A7D5897D5), UINT64_C(0x4901097FDF72DCA0),
2647           UINT64_C(0xDED5B1920B01E4C4), UINT64_C(0x364FF58226DD41E9)},
2648          {UINT64_C(0xA3F92DCC32FCA925), UINT64_C(0x8A1FB329207AA09A),
2649           UINT64_C(0xA9274BD3F512AE3A), UINT64_C(0x161C82BCC47B9007)}},
2650         {{UINT64_C(0x482ECE3B7AE1175F), UINT64_C(0x97CAC7E8BDD5DC6C),
2651           UINT64_C(0x562253099FDA910D), UINT64_C(0x52A9893B9FC206B9)},
2652          {UINT64_C(0xAD9F2A9205BB5ACA), UINT64_C(0xB9EEFB5BA3B65716),
2653           UINT64_C(0xE7BC173B8DB5A8D4), UINT64_C(0x6715EC64399DAE9E)}},
2654         {{UINT64_C(0x780796D15E41AC75), UINT64_C(0x3E165C784FB3A0B4),
2655           UINT64_C(0x198599BA237103E9), UINT64_C(0x2C04C3F5FA7ED86B)},
2656          {UINT64_C(0x29547DA8AC9356F0), UINT64_C(0xCB345AB479EADA37),
2657           UINT64_C(0x1D15D377A295BF2D), UINT64_C(0x10292C9D2FDC8131)}},
2658     },
2659     {
2660         {{UINT64_C(0xADF3B54740E1DC7E), UINT64_C(0x420CE2DD1C345D14),
2661           UINT64_C(0xC08E3CBE21DC5C2D), UINT64_C(0x79FDC0006F8FCE80)},
2662          {UINT64_C(0x23EBDF7FCB105CE7), UINT64_C(0x793FC99D7C6794A8),
2663           UINT64_C(0x4CA3FB21293E3575), UINT64_C(0x7FB2ACB97BF73CC8)}},
2664         {{UINT64_C(0x67DB6C900FC8FCD4), UINT64_C(0x22A3DF5F7EE3B705),
2665           UINT64_C(0xD50EBF8BC7B2EDFF), UINT64_C(0x0C70104599522FB7)},
2666          {UINT64_C(0x1420CF02AD4F9044), UINT64_C(0xD78DBA23E5B59451),
2667           UINT64_C(0xDFDC1C7F6AEFD853), UINT64_C(0x560DEE94DEA1DAAB)}},
2668         {{UINT64_C(0x0F2355132167A78B), UINT64_C(0xCF4637029F441927),
2669           UINT64_C(0xD0AE2723A3D1505C), UINT64_C(0x3149D858CD9FBFF4)},
2670          {UINT64_C(0x2A73913AF79240FA), UINT64_C(0xC904A575252A958B),
2671           UINT64_C(0x10D1819078473D97), UINT64_C(0x42CE7A38203BC8C4)}},
2672         {{UINT64_C(0x1D2AD4F2FA59BB8B), UINT64_C(0x8234964C79F137DD),
2673           UINT64_C(0x00B63A305D02679E), UINT64_C(0x506C45BE5DD7543D)},
2674          {UINT64_C(0x4378F900776BF80C), UINT64_C(0x179558B2B312F2BB),
2675           UINT64_C(0x5B15368CEA37C183), UINT64_C(0x7593B19FB198E42D)}},
2676         {{UINT64_C(0xED723535DEFA1F48), UINT64_C(0x0DAFC48B87F96EE5),
2677           UINT64_C(0x0AEFA3BA91B1B52C), UINT64_C(0x56BA1B33A1ADBEA4)},
2678          {UINT64_C(0x8A0B617030A6C905), UINT64_C(0xC5BA3518B272D12E),
2679           UINT64_C(0x782100CF4B6643A9), UINT64_C(0x12DEE80385C5BD2B)}},
2680         {{UINT64_C(0xDD07D2D578FCADD6), UINT64_C(0x8CB8E8A83B25C523),
2681           UINT64_C(0x25063508530919CF), UINT64_C(0x45D3DD541E24F7A1)},
2682          {UINT64_C(0x296AE89349DDAF96), UINT64_C(0x7EF3CDE0ACE559F5),
2683           UINT64_C(0x9CDF22E40D36F87B), UINT64_C(0x196847654AC9A845)}},
2684         {{UINT64_C(0x3955B5ABC597B7AE), UINT64_C(0x59F3BA053AB49731),
2685           UINT64_C(0xBCA5B117F525C6C8), UINT64_C(0x4969C13432050B8D)},
2686          {UINT64_C(0x353183D9970E8E49), UINT64_C(0x3D005213E95300CF),
2687           UINT64_C(0x595F9C8E09022378), UINT64_C(0x70FA8B471A445C28)}},
2688         {{UINT64_C(0xECC88EE3BADB79EA), UINT64_C(0x5BDAF68CFBD8464E),
2689           UINT64_C(0x24AF6A4CB4280334), UINT64_C(0x17A5DE8B398E5BBE)},
2690          {UINT64_C(0x300B6DEB92999E18), UINT64_C(0xA076691867DEFC2F),
2691           UINT64_C(0x4E904450B19F87FF), UINT64_C(0x3010AD94C2871056)}},
2692         {{UINT64_C(0x72E747A1461EFCC3), UINT64_C(0x329EDF18562F923E),
2693           UINT64_C(0x65E021D4D081A4E7), UINT64_C(0x4B2DBFFFB727B6F4)},
2694          {UINT64_C(0x5A597A809C8505AC), UINT64_C(0x13486480562B82D2),
2695           UINT64_C(0x477FD480CC8234C3), UINT64_C(0x6045ABA404800C00)}},
2696         {{UINT64_C(0x3E0874399C541035), UINT64_C(0x389AA76C6D9D8B6A),
2697           UINT64_C(0x68FE5E8336A21299), UINT64_C(0x67AC313D402A32CF)},
2698          {UINT64_C(0x996131D225501A53), UINT64_C(0x5C1B89DEA77A85F4),
2699           UINT64_C(0xA9822C84ED6702AD), UINT64_C(0x50F014A456609EA0)}},
2700         {{UINT64_C(0xF0F8B4E6E5A8E91E), UINT64_C(0x734CFF081A2FFEFD),
2701           UINT64_C(0x9724EE0B27BCB163), UINT64_C(0x6AF3808B30B8EF68)},
2702          {UINT64_C(0xE5B3829F126E88FC), UINT64_C(0x0F441EE34EE5FD4B),
2703           UINT64_C(0x534D2F8CBFEC4D34), UINT64_C(0x3E1F16DE076E6737)}},
2704         {{UINT64_C(0x4DB53E8A4ED36E6A), UINT64_C(0x49A9EFE94352B22F),
2705           UINT64_C(0x7829605C39CF005C), UINT64_C(0x190A8E16D85DB959)},
2706          {UINT64_C(0x699810699B073AB3), UINT64_C(0x8C264B878C141AA1),
2707           UINT64_C(0x7F614282603ED47C), UINT64_C(0x21FD2E7A9F9B0940)}},
2708         {{UINT64_C(0xC5CA10A01EC6BB3D), UINT64_C(0x9403E3F527A9B02B),
2709           UINT64_C(0x9D3D186DFB43F790), UINT64_C(0x7855276E67DC0C00)},
2710          {UINT64_C(0x053DBB2AFFFFB14C), UINT64_C(0x2674666343ACC0A6),
2711           UINT64_C(0x1EE7A9467FFC1C68), UINT64_C(0x14BFAF0156DBB0DE)}},
2712         {{UINT64_C(0x11C89A47849EA674), UINT64_C(0x194FAAF094A540E6),
2713           UINT64_C(0xE61163F86050E4C0), UINT64_C(0x6939A166B1A07B76)},
2714          {UINT64_C(0x8166CA8E2EF18325), UINT64_C(0x96112E6530C042E2),
2715           UINT64_C(0xA805CAE05A394C25), UINT64_C(0x45A0DE010392E6BB)}},
2716         {{UINT64_C(0xB89CEE96B4FAAA56), UINT64_C(0x7A7DC8AE529736DE),
2717           UINT64_C(0x9158AA49A727FCF7), UINT64_C(0x621B8B311896B9DA)},
2718          {UINT64_C(0x875930D603BEC74B), UINT64_C(0x1056DB45A7A50309),
2719           UINT64_C(0xEE713E04B5657B0E), UINT64_C(0x2D68155E6FCAD967)}},
2720         {{UINT64_C(0x3BB1E9E365B1E2B3), UINT64_C(0x2A61567088425BAB),
2721           UINT64_C(0x22F4F32F62F1BA4A), UINT64_C(0x7B5EC25088A59642)},
2722          {UINT64_C(0x7B5BA12A42D30049), UINT64_C(0x4E6AC05586995BE6),
2723           UINT64_C(0x04431A0445EC87AC), UINT64_C(0x28974ED7ED94823D)}},
2724     },
2725     {
2726         {{UINT64_C(0x5925805712BB5555), UINT64_C(0x03141CD8BB7608EE),
2727           UINT64_C(0x84EBDC49EF77714B), UINT64_C(0x6A45FC3AB5DC1A5F)},
2728          {UINT64_C(0x1F6DC2052FBEEC76), UINT64_C(0x17EB733BA920C554),
2729           UINT64_C(0xDB022C217A28ACDF), UINT64_C(0x6AF16156A9B62BF1)}},
2730         {{UINT64_C(0x9379D6A880B472CC), UINT64_C(0x6CB08CB07BD92F27),
2731           UINT64_C(0x19B3C353147E6E12), UINT64_C(0x3C26CB2F26827839)},
2732          {UINT64_C(0x98AAC9A70CC571E4), UINT64_C(0x075D05F2C3C8FC04),
2733           UINT64_C(0x718B55A0D79621AC), UINT64_C(0x149FEECF5B94B41B)}},
2734         {{UINT64_C(0x6A150A64783F9C81), UINT64_C(0x5950C2DF0FB18827),
2735           UINT64_C(0xF5D75504F15E3A89), UINT64_C(0x5F92F2F7FCB4406B)},
2736          {UINT64_C(0x665F31E76123E858), UINT64_C(0x4E568EA9A95184A3),
2737           UINT64_C(0x851EEADC505FF0AD), UINT64_C(0x62AD5BA6542C3EF8)}},
2738         {{UINT64_C(0x1103859DC55C23FD), UINT64_C(0x06AB0BD6695E4E9B),
2739           UINT64_C(0x2CD00D76DD734990), UINT64_C(0x5D59C693B06460E4)},
2740          {UINT64_C(0x3BA8F2F01F9C76DA), UINT64_C(0x08E4A7EC960F5C0E),
2741           UINT64_C(0x79C82AD9E4AAB060), UINT64_C(0x093D322C0DF95C43)}},
2742         {{UINT64_C(0x88AF12580C627547), UINT64_C(0x81E5F197889A5E12),
2743           UINT64_C(0x99E0E1917CBD84FD), UINT64_C(0x3024BCE8DB0B9711)},
2744          {UINT64_C(0x04075C80DB93B1A2), UINT64_C(0x12F30AF8628B0E63),
2745           UINT64_C(0xA3514F26EB25A4ED), UINT64_C(0x3D42E4897BCD0873)}},
2746         {{UINT64_C(0x0F1C16C6754B236F), UINT64_C(0x717CE487594F5D3D),
2747           UINT64_C(0x7679C7DAAFAD77B1), UINT64_C(0x51AFD0146F3E724C)},
2748          {UINT64_C(0xAFC9745C3AF6938F), UINT64_C(0xCA12BFA9C4E61CB4),
2749           UINT64_C(0x943B56969425CCA7), UINT64_C(0x5BD3E65EB6E48A69)}},
2750         {{UINT64_C(0x2D23CF78DEAE74B1), UINT64_C(0xA686767E043BF2F1),
2751           UINT64_C(0x3AFED34DE464ADE9), UINT64_C(0x1E4620735A6AE80B)},
2752          {UINT64_C(0xA86AA408737F7B66), UINT64_C(0xD67A0B49EAB3B6CE),
2753           UINT64_C(0x6FF3CA4F275355F3), UINT64_C(0x6F385576688F99AB)}},
2754         {{UINT64_C(0xC9B63343FD2F9A72), UINT64_C(0xBD0A126DAC267E8A),
2755           UINT64_C(0x818BD5D85D2839B5), UINT64_C(0x1BBAB4CE0BF5AFCE)},
2756          {UINT64_C(0x2827B24A4D8B67DE), UINT64_C(0x841F6BD3C34E6642),
2757           UINT64_C(0xE9F5C1C25E4A34D4), UINT64_C(0x4E98795CFDA4177C)}},
2758         {{UINT64_C(0x3C9FF1C20763AB04), UINT64_C(0x4FC1BE619832FCFD),
2759           UINT64_C(0x5FA50C388BD0363A), UINT64_C(0x14C9BB2FF26206BE)},
2760          {UINT64_C(0xAD1A96EB1D31880C), UINT64_C(0xF0A37BC465DFCF8A),
2761           UINT64_C(0x389627293D048FE4), UINT64_C(0x017125C06480B254)}},
2762         {{UINT64_C(0x01E819F598D4BAC6), UINT64_C(0xD3686E0436B99D30),
2763           UINT64_C(0x0C2876FB200A4A9D), UINT64_C(0x45D50C2FE65782D5)},
2764          {UINT64_C(0xB8316ECE865B7A21), UINT64_C(0xA3ADB90FCC875503),
2765           UINT64_C(0xD72E864E98468FB4), UINT64_C(0x13BB23FDDED21F40)}},
2766         {{UINT64_C(0x653C3C15C6B96368), UINT64_C(0x9A42FC2C2B9C381F),
2767           UINT64_C(0xF06B41B969534D92), UINT64_C(0x46F7292E3FB7BED2)},
2768          {UINT64_C(0x14A2C42097D1875E), UINT64_C(0x45DFA824D3B2DF55),
2769           UINT64_C(0x59CB7E593F2BA72D), UINT64_C(0x2EEC65C9D7D96C98)}},
2770         {{UINT64_C(0x907CD4C849650405), UINT64_C(0xFC29320A37E05E06),
2771           UINT64_C(0x99B4C1DF09E29619), UINT64_C(0x74E69BF834DE993F)},
2772          {UINT64_C(0x62C0F296509D9797), UINT64_C(0x2E6BD4E65F1EF554),
2773           UINT64_C(0xE30506410D0B71B8), UINT64_C(0x29DA0C9D235DDE6C)}},
2774         {{UINT64_C(0x3CFBCA4B689398C1), UINT64_C(0x11E5880440C9DF13),
2775           UINT64_C(0x3923A39BBCDF2489), UINT64_C(0x3805CCC7387C8089)},
2776          {UINT64_C(0xC1B4EB4870319AFA), UINT64_C(0x0A6A5FA4CA089604),
2777           UINT64_C(0x16ABDE5473139A20), UINT64_C(0x7C0055E094BD61B5)}},
2778         {{UINT64_C(0xA5AB5CEFCB05A02A), UINT64_C(0xC0B4E1B40BFE903B),
2779           UINT64_C(0xBA528329EAC9E7E8), UINT64_C(0x0266C5A70A2456B6)},
2780          {UINT64_C(0x507E9A415E216EEC), UINT64_C(0xFCC06B0AD0F1E440),
2781           UINT64_C(0x6FAEFC8EE5C7B26F), UINT64_C(0x4744CF2EB02F85C1)}},
2782         {{UINT64_C(0xF5E2B8121C291BFC), UINT64_C(0xC18E791D2CDCBF7A),
2783           UINT64_C(0xC386B96246554345), UINT64_C(0x373E00FB067518CD)},
2784          {UINT64_C(0xC9BA9DF9E950051B), UINT64_C(0x182CB132DD6133EE),
2785           UINT64_C(0xD6D7F81570A3C71C), UINT64_C(0x44C5AEBC7FAFE307)}},
2786         {{UINT64_C(0x6C7CE359A9D16080), UINT64_C(0xA874386D1E8B643E),
2787           UINT64_C(0xA064812907F48E10), UINT64_C(0x2A40220193E4D619)},
2788          {UINT64_C(0x8B429545BD383EA6), UINT64_C(0xC096D593F2880536),
2789           UINT64_C(0xB4057D6C20E299B9), UINT64_C(0x303962CE38A825FA)}},
2790     },
2791     {
2792         {{UINT64_C(0x9E426EBF1E1D70D0), UINT64_C(0x6AEA4DDCB83529CA),
2793           UINT64_C(0xF3ECD4627CC9A07C), UINT64_C(0x7F255C86C364772E)},
2794          {UINT64_C(0x0DF212CF5613BEF0), UINT64_C(0x771F02A91309F9D0),
2795           UINT64_C(0xE97BEE39805FE1F5), UINT64_C(0x54A43430D93522B9)}},
2796         {{UINT64_C(0xC01553BDCDE4EBBE), UINT64_C(0xB1928DDCA02E56C1),
2797           UINT64_C(0xB91004BA94A1A417), UINT64_C(0x44F74BE656CB9C88)},
2798          {UINT64_C(0x6A7E3E9B921B62E5), UINT64_C(0xF2BF553B5FBF13C4),
2799           UINT64_C(0x51CB776D86D55641), UINT64_C(0x71826BC56425A3AD)}},
2800         {{UINT64_C(0xD6D49F90C6D70EF9), UINT64_C(0x5BD0DA6929EBA0DD),
2801           UINT64_C(0x0BBA7571803233EF), UINT64_C(0x0EB0959E679A17D5)},
2802          {UINT64_C(0x97818DC2B8A3D6EC), UINT64_C(0x09497FB0C687EAA2),
2803           UINT64_C(0x2E2707EAA65FA4C0), UINT64_C(0x6A74D4C67542F472)}},
2804         {{UINT64_C(0x0D1930061EE0BC40), UINT64_C(0x7D7BEE196DC98BA8),
2805           UINT64_C(0x1AD37C98447C38D2), UINT64_C(0x3E163AE1B6B4550A)},
2806          {UINT64_C(0x734E36C95BC93243), UINT64_C(0x54E217FD986C35A8),
2807           UINT64_C(0xF0576FF09E3285E3), UINT64_C(0x65C950C8186EE7EB)}},
2808         {{UINT64_C(0x1AB12C042012D277), UINT64_C(0x97CAB84B83872384),
2809           UINT64_C(0x479C9CF51C66FCFD), UINT64_C(0x70ABC8B4F276933E)},
2810          {UINT64_C(0xE6B15BF7BA4D14F0), UINT64_C(0xF4060ED322E2F5D5),
2811           UINT64_C(0xA53F3CA0CDC5462C), UINT64_C(0x593219D4C6FC3854)}},
2812         {{UINT64_C(0x9DE6993472B6F8A1), UINT64_C(0xECABAEEE19E16B3F),
2813           UINT64_C(0x0B537CA5EDA68D7B), UINT64_C(0x744628BDD3CE55B7)},
2814          {UINT64_C(0x3A5B2D8E98A95308), UINT64_C(0x74D0CEF16758C6C8),
2815           UINT64_C(0x7538198ADA204834), UINT64_C(0x1E166AAAA644E880)}},
2816         {{UINT64_C(0xE76EE7124674ACF0), UINT64_C(0x40A6F6DEDF9DFB4C),
2817           UINT64_C(0x91B0034C40C65721), UINT64_C(0x54FE8B8BF8E0F5E5)},
2818          {UINT64_C(0x6322CA0F75891895), UINT64_C(0x3D1C821E7D20C522),
2819           UINT64_C(0x1691407F08043786), UINT64_C(0x02C3083814847D58)}},
2820         {{UINT64_C(0x57DEF069B8F0C372), UINT64_C(0x50375DC30D5ABF2C),
2821           UINT64_C(0x2290381475EDFBC9), UINT64_C(0x56E39BD7AE37695A)},
2822          {UINT64_C(0xAB74B187463D13F2), UINT64_C(0xC50CB8A23CDE8886),
2823           UINT64_C(0x1EFBD1CFB35F7D59), UINT64_C(0x1296C4821057AE42)}},
2824         {{UINT64_C(0xA350B57BC347E3FB), UINT64_C(0x4312EB75ADF65129),
2825           UINT64_C(0xD9A7E2F47F9A6C9E), UINT64_C(0x5493AF7B9BFDCB4D)},
2826          {UINT64_C(0x90A443DD9AC0E58E), UINT64_C(0x9777D58AC6F3BEEF),
2827           UINT64_C(0x12F00913965EC900), UINT64_C(0x2F6C5B59480126DA)}},
2828         {{UINT64_C(0x70B907FCBAD8C051), UINT64_C(0x54492D6AD3B4F608),
2829           UINT64_C(0xE3B46F1B2E096D9F), UINT64_C(0x522AD6D1747D472A)},
2830          {UINT64_C(0x8FCD161602DAB5E5), UINT64_C(0xD3BA292F357B1C85),
2831           UINT64_C(0xA6DB50CD2704F072), UINT64_C(0x63488DDF8341AA73)}},
2832         {{UINT64_C(0x99100A3D0FE2AAAB), UINT64_C(0x7D30C4E98EA44560),
2833           UINT64_C(0xBA458C672B4C776D), UINT64_C(0x2EC11420BBA4D85E)},
2834          {UINT64_C(0xB1D9FBA27A7AEC55), UINT64_C(0x432AB2AA7665AAE5),
2835           UINT64_C(0xD2755948F3BC7043), UINT64_C(0x2FC331BB82510EAD)}},
2836         {{UINT64_C(0xAAF11CF946253DB1), UINT64_C(0xEB025AEDB0DF307C),
2837           UINT64_C(0xCB7C22A57A82ADEE), UINT64_C(0x7316C3909C5FA97B)},
2838          {UINT64_C(0x91620554F518067C), UINT64_C(0x20A438AE3C96A804),
2839           UINT64_C(0xC4F9DCDF5B0C090C), UINT64_C(0x77C512DB6E5C1B45)}},
2840         {{UINT64_C(0xC981E682FDD09EDE), UINT64_C(0xC3EB36B7BBB3F57D),
2841           UINT64_C(0xA07369C6D12BF450), UINT64_C(0x16627566CE017845)},
2842          {UINT64_C(0xFD8DEC909494AF62), UINT64_C(0x7E79309653FD4B22),
2843           UINT64_C(0x21B8E665C8AAEAE9), UINT64_C(0x526FA31818BC33C0)}},
2844         {{UINT64_C(0xF55D32BF853A2647), UINT64_C(0xD873ED6CCDAEE8FE),
2845           UINT64_C(0xA3579E2B80E52622), UINT64_C(0x03871ABA33D16FE8)},
2846          {UINT64_C(0x714804AC69925EDF), UINT64_C(0x0340755FF2B964FF),
2847           UINT64_C(0x93830F98DA0D1A07), UINT64_C(0x2CAB201EF7FB1E16)}},
2848         {{UINT64_C(0x26DE3A3A22A8AF77), UINT64_C(0x0E77C3DCB45BA630),
2849           UINT64_C(0x34F00017FC86E7D1), UINT64_C(0x796ABE2F1B62F7F2)},
2850          {UINT64_C(0x9FA092771663B5B1), UINT64_C(0xFFFDC93F9B2FB9AC),
2851           UINT64_C(0x03AECD1A6B340D75), UINT64_C(0x5D55A168314DCCEA)}},
2852         {{UINT64_C(0x678AEF02747DBD0C), UINT64_C(0xF0D47C1CD47A6C09),
2853           UINT64_C(0x6C2AC72F3FDD1681), UINT64_C(0x750E70646D789D3A)},
2854          {UINT64_C(0x3F970AFEAEBEDD58), UINT64_C(0x6BBA7956E3540951),
2855           UINT64_C(0x7CC461B23E71F6AF), UINT64_C(0x7E51E548C45FED28)}},
2856     },
2857     {
2858         {{UINT64_C(0x4A598EFB2CE2CBE5), UINT64_C(0x774CDE0A89C9A51B),
2859           UINT64_C(0x2D003680CA907F34), UINT64_C(0x62C32DCA9D3C7D97)},
2860          {UINT64_C(0x37B3A90FB3054D17), UINT64_C(0x1423574C67E58A5A),
2861           UINT64_C(0xF1D3BB1A4859FA49), UINT64_C(0x25F0AF1C3F5AFA63)}},
2862         {{UINT64_C(0xD3BF7F621FE53AC9), UINT64_C(0xCE2B67C3CBCE6164),
2863           UINT64_C(0xE081C57695341024), UINT64_C(0x32B0EF5D9A70ECAB)},
2864          {UINT64_C(0x3EC93C853BE1E5CE), UINT64_C(0xE25F54EDA0CB7DCD),
2865           UINT64_C(0x9D6B57D7517965B2), UINT64_C(0x159F7AB0129B0B27)}},
2866         {{UINT64_C(0xAEF88E95EEFB67F3), UINT64_C(0xEAEB2889E0316AB2),
2867           UINT64_C(0x1491881FC2CB6753), UINT64_C(0x67DCDF28702789D0)},
2868          {UINT64_C(0x8282E0A711C0F3FD), UINT64_C(0x9CDCFDB801BA273D),
2869           UINT64_C(0x6BF1E04326279B95), UINT64_C(0x0D42AAC685852777)}},
2870         {{UINT64_C(0xC4CE393E608981AB), UINT64_C(0x210E20F852141CB0),
2871           UINT64_C(0x22C2586D6B9234B5), UINT64_C(0x52F1B3664366750E)},
2872          {UINT64_C(0xE38ED0D9760AFA55), UINT64_C(0xA43FF25AB5D61A08),
2873           UINT64_C(0x0BE3A406B5E21691), UINT64_C(0x37B47A28FD4E17B0)}},
2874         {{UINT64_C(0xC46DC6D44C2C65C2), UINT64_C(0x2A0B452CC54BE778),
2875           UINT64_C(0xAF113693F727070E), UINT64_C(0x7B229CD8C68D13A3)},
2876          {UINT64_C(0x0F63097E02D43E4B), UINT64_C(0x912F8D3355627FD8),
2877           UINT64_C(0x1EBF39612A0DD9AE), UINT64_C(0x7FD33FDEF0294B2D)}},
2878         {{UINT64_C(0xC72411F5D0CC6D9F), UINT64_C(0x66E04C909B92FF84),
2879           UINT64_C(0x0678B4F8E1C033B6), UINT64_C(0x5A99F270E49A972A)},
2880          {UINT64_C(0x3743BCD8D265A4DF), UINT64_C(0x7BD6DDF4CE0404C3),
2881           UINT64_C(0x4043767F131750A5), UINT64_C(0x4A7D89839DD65652)}},
2882         {{UINT64_C(0x535BC78412B7822D), UINT64_C(0xDD32DD67F1F9B703),
2883           UINT64_C(0xFFDBF0EB2EAA2A1C), UINT64_C(0x497C09FAF64E9822)},
2884          {UINT64_C(0x18E717E932EE2A36), UINT64_C(0xF01CC4F5583949B1),
2885           UINT64_C(0x222EE9740A168755), UINT64_C(0x0CD14CD500C81EC9)}},
2886         {{UINT64_C(0x7AE0BD1114C79CDC), UINT64_C(0x67323D1A6DC08C80),
2887           UINT64_C(0x2FD1ABC70EF32432), UINT64_C(0x65923246B0E08EBF)},
2888          {UINT64_C(0x0A9FD3D7C0754ECE), UINT64_C(0xE76B26245F8644FA),
2889           UINT64_C(0xF1F0BEBA0F8BB385), UINT64_C(0x73251F03FC96778F)}},
2890         {{UINT64_C(0x197150DED08795A9), UINT64_C(0xAD6935AEFBB8B9CF),
2891           UINT64_C(0x721186823B2B9EFB), UINT64_C(0x265B288DBC2B7240)},
2892          {UINT64_C(0x7BF2EB362F78C431), UINT64_C(0xF03B83CAF2A6E469),
2893           UINT64_C(0x211592564740E74B), UINT64_C(0x35BE57350490F0B9)}},
2894         {{UINT64_C(0x207F33B2806C1CAE), UINT64_C(0x04249127DAC5ADE0),
2895           UINT64_C(0xC4CCF33E1CC59DE7), UINT64_C(0x2A17B520272BD6D7)},
2896          {UINT64_C(0xC36F6B3CB48F6585), UINT64_C(0xD32A73790861ACF5),
2897           UINT64_C(0x28A12ECB2C3291C6), UINT64_C(0x0E945F95F02A88D0)}},
2898         {{UINT64_C(0x4836EC01D3B3117B), UINT64_C(0x4C197454A4C2FD72),
2899           UINT64_C(0x96FCED51F9897721), UINT64_C(0x142028585828C97D)},
2900          {UINT64_C(0xCA7ACED8774755B9), UINT64_C(0x460FF58297252559),
2901           UINT64_C(0xAAE457765796DD63), UINT64_C(0x711C916E346DDBF5)}},
2902         {{UINT64_C(0xA60E2E7B5E203692), UINT64_C(0xCFC72FEAF3BF2A45),
2903           UINT64_C(0x78729D2872AC0436), UINT64_C(0x3E16DD8B29ABF199)},
2904          {UINT64_C(0xB1705AA615A41F3D), UINT64_C(0x8C7512FE308AB87C),
2905           UINT64_C(0xA27411C503995381), UINT64_C(0x3142403CA780CED3)}},
2906         {{UINT64_C(0xE4473E94F1718C7F), UINT64_C(0x601BC194A3CAB6CB),
2907           UINT64_C(0x8F3540F8581D491D), UINT64_C(0x456A9B7C43C15321)},
2908          {UINT64_C(0x6F335A2D593BB7ED), UINT64_C(0xB6D5A23F7D791514),
2909           UINT64_C(0x976D2F8379235EAD), UINT64_C(0x7D02EA0F44775C97)}},
2910         {{UINT64_C(0x322DBC8CE5EC268E), UINT64_C(0x1F2F6050BE14BF5C),
2911           UINT64_C(0x58AC6397EACF6A50), UINT64_C(0x4167CBD5A5401081)},
2912          {UINT64_C(0x8E6F06A1EE5B4BF5), UINT64_C(0x1A6073D56B2F790F),
2913           UINT64_C(0x1C09FF3D4F901250), UINT64_C(0x286AF8D7E6B40DF4)}},
2914         {{UINT64_C(0xF74C805706BD53FF), UINT64_C(0x4FCE7281E5788F0D),
2915           UINT64_C(0xD6A867AC3D015E6B), UINT64_C(0x04AEC38D6E185A42)},
2916          {UINT64_C(0x8DC12B74083D65CB), UINT64_C(0xDB1AA8AC82966668),
2917           UINT64_C(0xBD2233BF28AF1B90), UINT64_C(0x544569A7172CCA11)}},
2918         {{UINT64_C(0x9C56FCA8149BD0BD), UINT64_C(0x2B4EC788A05F8E44),
2919           UINT64_C(0x1569CF6D92478943), UINT64_C(0x67E373E857380986)},
2920          {UINT64_C(0xF5CC8232ED3C14DB), UINT64_C(0xE3D184B0F52EAF83),
2921           UINT64_C(0x195D41370BC64038), UINT64_C(0x77994388778C3C20)}},
2922     },
2923     {
2924         {{UINT64_C(0x3DAA0C47A0CC77AA), UINT64_C(0xB9794E747C69CDF0),
2925           UINT64_C(0x3610E50B4549F5D4), UINT64_C(0x262CA564B8A112CA)},
2926          {UINT64_C(0xD5EC795E554E8714), UINT64_C(0x73EE5502717EBEF3),
2927           UINT64_C(0xE36E8A1A1947A478), UINT64_C(0x3FBE43A342ADC59D)}},
2928         {{UINT64_C(0x4DE78909021FBCBE), UINT64_C(0xA76A5EE20BBBB324),
2929           UINT64_C(0x5B86519ACD67810B), UINT64_C(0x4CCA44A23710A4EE)},
2930          {UINT64_C(0xD79A121DCD1F8BEC), UINT64_C(0x2E12A772DC9CA10E),
2931           UINT64_C(0xE301CA3B8C9E9640), UINT64_C(0x4B25FE18B731A957)}},
2932         {{UINT64_C(0xA05DA2CDF4AD7264), UINT64_C(0x31336489076977A5),
2933           UINT64_C(0xC1D269BEF2E576A8), UINT64_C(0x1E877ADC7532203F)},
2934          {UINT64_C(0x9C9961BC8B92972C), UINT64_C(0x7BA072726A14D810),
2935           UINT64_C(0xE51095A906913136), UINT64_C(0x4674896930E0EA8C)}},
2936         {{UINT64_C(0xDB8EF3463C73BA49), UINT64_C(0xBF2213123720570D),
2937           UINT64_C(0xC07B3639605DB0D6), UINT64_C(0x44FCEFA6300336A3)},
2938          {UINT64_C(0x121FAC5C2D234592), UINT64_C(0x901DEE8844E367D7),
2939           UINT64_C(0x5B5F3DD61CAA6A3A), UINT64_C(0x72E474ECAC2F6E64)}},
2940         {{UINT64_C(0x15690BEEF55BE61C), UINT64_C(0xE42B945EDF2678A2),
2941           UINT64_C(0x60A5C8AA3B7B1776), UINT64_C(0x16103FBCEB9AB938)},
2942          {UINT64_C(0x79722A1E87AD06AB), UINT64_C(0xD7B509F6D6B632A2),
2943           UINT64_C(0x8C4E8B2E3B69EB40), UINT64_C(0x6A50958314DB2225)}},
2944         {{UINT64_C(0x169F35D893B78659), UINT64_C(0x989B04D28EFF83AD),
2945           UINT64_C(0x72CF7338A6AE4806), UINT64_C(0x6E156C84F4AAA524)},
2946          {UINT64_C(0x33A608EDA1ED5CB2), UINT64_C(0xCE274A64C3D28716),
2947           UINT64_C(0xFCF1B17045F0435F), UINT64_C(0x101D1BDB1653D6F6)}},
2948         {{UINT64_C(0x45BC931D2E5A67D9), UINT64_C(0xAFF02C11697DA479),
2949           UINT64_C(0x7C7972A32EA3E6E1), UINT64_C(0x71A17D505E97BB90)},
2950          {UINT64_C(0x962E84F219AD4C5E), UINT64_C(0xBB8C9FC7692020BE),
2951           UINT64_C(0xA78FDF2CE7B36665), UINT64_C(0x7AC84ED426F92E33)}},
2952         {{UINT64_C(0xBD85A9EEC3C9E5C1), UINT64_C(0x72030BAA6ED2FD6A),
2953           UINT64_C(0xB67185AB39CFFB89), UINT64_C(0x3E2E51A4833BF770)},
2954          {UINT64_C(0x248FA3485E27D5BB), UINT64_C(0xF8D435962E6D3DCF),
2955           UINT64_C(0x07F5B93C0C8DAF81), UINT64_C(0x6A7FFA1DAD2FC97D)}},
2956         {{UINT64_C(0xFF308FAEFAEA33F1), UINT64_C(0x5F29DFFB3CC4C7CF),
2957           UINT64_C(0xB9AD4527ECC5A2B9), UINT64_C(0x08B95AF6048D4B38)},
2958          {UINT64_C(0x56BC43A8DEC152BB), UINT64_C(0xD1147B9A3849D869),
2959           UINT64_C(0xFE5020C2D02AF3B7), UINT64_C(0x54C02B44B918496E)}},
2960         {{UINT64_C(0x1611ECFD0B27468D), UINT64_C(0x4AFCE3290513A562),
2961           UINT64_C(0x982782FD2FE74EED), UINT64_C(0x66AC58BF17ADD2EA)},
2962          {UINT64_C(0x8277BC2D613581D4), UINT64_C(0x0BF5BF0C988D1498),
2963           UINT64_C(0x8A37134D55C984CB), UINT64_C(0x409A79CC92211390)}},
2964         {{UINT64_C(0x8C0081AE816F0462), UINT64_C(0xB431DC245A68BFC2),
2965           UINT64_C(0x25C769C65F78C8A1), UINT64_C(0x3BE0458DB382AF14)},
2966          {UINT64_C(0x10583083A171ADF2), UINT64_C(0xBA5D532537F7C39F),
2967           UINT64_C(0x76B03B945EAC7585), UINT64_C(0x76159AAC9C2DF2C6)}},
2968         {{UINT64_C(0x886C73BA918E0332), UINT64_C(0xF6FEC62AD24B5B52),
2969           UINT64_C(0xB98759B436B4D23A), UINT64_C(0x5EC5B3FE5480ACF3)},
2970          {UINT64_C(0x30FF297D6DD175BF), UINT64_C(0x501DE74475F2B9C3),
2971           UINT64_C(0xDEBE47CAF19230C5), UINT64_C(0x7401F20932BBBB62)}},
2972         {{UINT64_C(0x80712E4722496D1E), UINT64_C(0x36A0EF37DA80AF1D),
2973           UINT64_C(0xAF6CA51C940E5E9F), UINT64_C(0x74E17B6F722D9D22)},
2974          {UINT64_C(0xCB70B878B8B3AE1B), UINT64_C(0xBF8B9A0B07DF974C),
2975           UINT64_C(0x89FCC996F68A4BF4), UINT64_C(0x46F581E86EB0FB2E)}},
2976         {{UINT64_C(0xBCE0BD6C67137153), UINT64_C(0xAD3E92B375F64B78),
2977           UINT64_C(0x6454CD1DFD047DD9), UINT64_C(0x181C93EB612AE472)},
2978          {UINT64_C(0xE575307E23A529C3), UINT64_C(0xB9C43A0B59C09EB5),
2979           UINT64_C(0xFD233A68AA805840), UINT64_C(0x067C442EA122FFB9)}},
2980         {{UINT64_C(0xE1F3F76F2CD6762E), UINT64_C(0xFB68650F9764B53A),
2981           UINT64_C(0x4E90AC72F1224580), UINT64_C(0x2BF68F01127EED48)},
2982          {UINT64_C(0xE6B4B40994D389A0), UINT64_C(0xD7BC8108D44593D6),
2983           UINT64_C(0xDCF0399148A86677), UINT64_C(0x4A52D961CEBCE3C7)}},
2984         {{UINT64_C(0x55734AB5BAA873EA), UINT64_C(0x506DE4CF7871F323),
2985           UINT64_C(0x7C3F8B00578612C0), UINT64_C(0x730D4B8A9243C9E8)},
2986          {UINT64_C(0xA3290689D385F6BD), UINT64_C(0xAF688C6A913596F5),
2987           UINT64_C(0x0A2D89B5B646BE23), UINT64_C(0x31891165F63A6029)}},
2988     },
2989     {
2990         {{UINT64_C(0x331F9E57579583C0), UINT64_C(0xE92ABADF69C65DA2),
2991           UINT64_C(0xC796FBECA5B8B057), UINT64_C(0x52E6F9C9312D1E89)},
2992          {UINT64_C(0x0318B1DFDA68DFD3), UINT64_C(0x8BAA2EB3A1CAC4F1),
2993           UINT64_C(0x0CDC89A2BEE7D6E1), UINT64_C(0x6102DE7A22AB50F4)}},
2994         {{UINT64_C(0x02003D83E20C707A), UINT64_C(0xD819249C28289D89),
2995           UINT64_C(0x3FBC00B172053FF8), UINT64_C(0x0249C43CDF40D261)},
2996          {UINT64_C(0x8794EEACD8F064AF), UINT64_C(0xE2359E70DC9F0631),
2997           UINT64_C(0xD1603647ADA310D0), UINT64_C(0x6A9E3785EDC888EC)}},
2998         {{UINT64_C(0xF332B384EC41908E), UINT64_C(0xF3274472BDE4760B),
2999           UINT64_C(0x96185E89140D0EF4), UINT64_C(0x5646208990E698E7)},
3000          {UINT64_C(0x841A31C5F2E64396), UINT64_C(0x8F494CA503C4118F),
3001           UINT64_C(0x0C98A4C31A188305), UINT64_C(0x1C4B5F6298AAB1AB)}},
3002         {{UINT64_C(0xDDEEEBF85D0D8381), UINT64_C(0xD1616F4889044363),
3003           UINT64_C(0x2EE41D4721616A13), UINT64_C(0x2DCE61104BC769FC)},
3004          {UINT64_C(0xE3707A0116C1C468), UINT64_C(0x3B674187969AF612),
3005           UINT64_C(0xB64BD4D71E0671CC), UINT64_C(0x7EF01DBAB98C297C)}},
3006         {{UINT64_C(0x91DCBF99815381AC), UINT64_C(0x8D711F5838B67B97),
3007           UINT64_C(0x9C11F5959C6E322C), UINT64_C(0x4A688D0BE31A782F)},
3008          {UINT64_C(0x1297D9F3DCE93F5B), UINT64_C(0xA79561947C1DC62A),
3009           UINT64_C(0x340F217A5F718F63), UINT64_C(0x71F84529FCC0EF6A)}},
3010         {{UINT64_C(0x0D968E503DD00963), UINT64_C(0x5E696D79D7FF66C3),
3011           UINT64_C(0xAA52D60D499A9BE2), UINT64_C(0x72482C45CDC289DE)},
3012          {UINT64_C(0xC84968F57FFAAD3A), UINT64_C(0xEE91304CF7CD5BED),
3013           UINT64_C(0x684936760A7CC7C0), UINT64_C(0x3411AFA780023968)}},
3014         {{UINT64_C(0xA0AEBC706E3294C0), UINT64_C(0x93263942DC385E50),
3015           UINT64_C(0x7B90C0028467FB06), UINT64_C(0x29477CA438CFD0FF)},
3016          {UINT64_C(0xADC04D8192A748D5), UINT64_C(0xAE4F309D76CF3AE5),
3017           UINT64_C(0xBDA34BF04BB2C2FF), UINT64_C(0x65138897368536E4)}},
3018         {{UINT64_C(0x9CB8F7D66FE6D4D6), UINT64_C(0x6C2FFBF5AF246792),
3019           UINT64_C(0xD5A4F34981524707), UINT64_C(0x3AFE45CE36766D5E)},
3020          {UINT64_C(0x41991B49513BA267), UINT64_C(0x06EF1EEA6C18AA5E),
3021           UINT64_C(0x0A51763588EA2099), UINT64_C(0x32D2B5E2D245B88B)}},
3022         {{UINT64_C(0xAE38CDD53F517C5B), UINT64_C(0x1C94FDC5D878FEEE),
3023           UINT64_C(0xABF7A41DBEFCE107), UINT64_C(0x33BF3FE9D408DFE8)},
3024          {UINT64_C(0x4F2E6FF0947CB8C4), UINT64_C(0x3A8E86ABF998C5A0),
3025           UINT64_C(0x3ADC6ABAE359209F), UINT64_C(0x37A2DE1BD9A50051)}},
3026         {{UINT64_C(0x424F4E34E718F6B9), UINT64_C(0x50B1A03B75C58EB6),
3027           UINT64_C(0xB949531491390E27), UINT64_C(0x4AE0CC3A880E78D8)},
3028          {UINT64_C(0x10331AFAF1E4413C), UINT64_C(0xE7A3E554DDFCD2F0),
3029           UINT64_C(0x44F6DE850EBF484B), UINT64_C(0x6A762A7E895D0F54)}},
3030         {{UINT64_C(0x8E606B0A8D0558F6), UINT64_C(0xAADA76045C4DD930),
3031           UINT64_C(0x5B2FC7ADEF4ACAD0), UINT64_C(0x0D969AD087F5B6E2)},
3032          {UINT64_C(0xF9A182B25974E67B), UINT64_C(0xCD8232E723B4009A),
3033           UINT64_C(0x3D8F5DDD285BCC3F), UINT64_C(0x114AC56FEEE1B9BF)}},
3034         {{UINT64_C(0xD3EA1B56AA45085A), UINT64_C(0x5DE7BB70D314CEDF),
3035           UINT64_C(0x8A74384C7BCCDCFD), UINT64_C(0x64B80F8A8E0E0367)},
3036          {UINT64_C(0xA9EA432B48884ED1), UINT64_C(0x51957A8F8C0BA810),
3037           UINT64_C(0x9E88340039E810E3), UINT64_C(0x0A73ED5A28B2051C)}},
3038         {{UINT64_C(0x655212A313C30826), UINT64_C(0xAE53668EB73E8660),
3039           UINT64_C(0x6C33B649FF108CCE), UINT64_C(0x39E0B11821D49681)},
3040          {UINT64_C(0xFE4D215270525312), UINT64_C(0x2EDCE32BFFD18749),
3041           UINT64_C(0xFED19B1CB04D3FB8), UINT64_C(0x4DFE216B2B225A9D)}},
3042         {{UINT64_C(0x583E8A6C4C70F8A8), UINT64_C(0xC8206231954A9AE1),
3043           UINT64_C(0x9360B592B76517B1), UINT64_C(0x362C5C5CEED10CCA)},
3044          {UINT64_C(0x3DBA95953D607921), UINT64_C(0x0188A5D65A6ECC40),
3045           UINT64_C(0x0EAB43C16CFF4ADE), UINT64_C(0x1F3673AEDE3347E0)}},
3046         {{UINT64_C(0x7300C4B3796593EE), UINT64_C(0x607E7E76D8D926C3),
3047           UINT64_C(0x1762CE2677F9FD06), UINT64_C(0x0D0478B3CEA891EB)},
3048          {UINT64_C(0xB11297912618B09E), UINT64_C(0x5F9D290D33F928C9),
3049           UINT64_C(0xE3192631E6178DB0), UINT64_C(0x21260AC808576D3F)}},
3050         {{UINT64_C(0x899DAF2A76968E1C), UINT64_C(0x0519DEA9F9C2B3E7),
3051           UINT64_C(0x5FDADC3893D0BD4E), UINT64_C(0x0467BFF743B4D98F)},
3052          {UINT64_C(0x651C316C6F3936C9), UINT64_C(0xE757689AAF27DF8B),
3053           UINT64_C(0x3AB037EAA0FA9188), UINT64_C(0x2F8B039BD927B60A)}},
3054     },
3055     {
3056         {{UINT64_C(0x72211BF5DE876A70), UINT64_C(0xA836163173D121CE),
3057           UINT64_C(0x2385272123D419E4), UINT64_C(0x3F56D47EDBD03345)},
3058          {UINT64_C(0xFB0E91A5D6F05BAC), UINT64_C(0xA0E02BF6AC9D0F46),
3059           UINT64_C(0x5ED9EA2C97F1812F), UINT64_C(0x172F564FEBD5DB5A)}},
3060         {{UINT64_C(0xC790E91281F11E58), UINT64_C(0x14A1763099A5DFF7),
3061           UINT64_C(0xF6F30F2F1627516D), UINT64_C(0x522CAD8FEFCF43B7)},
3062          {UINT64_C(0xFFADD45E6EA01128), UINT64_C(0x5D23234CD61D1964),
3063           UINT64_C(0xE9212C852802DF86), UINT64_C(0x0A3D237B92AA8DA3)}},
3064         {{UINT64_C(0x2CED05F4E50ED356), UINT64_C(0x1CBC7FB1BFFEEF3A),
3065           UINT64_C(0x885991B1BE19F0F0), UINT64_C(0x6DED0794DE44A492)},
3066          {UINT64_C(0x9967E83444CBECFC), UINT64_C(0xB0674A8D6A792ED1),
3067           UINT64_C(0x360E2DE4B7DDD557), UINT64_C(0x26852A7470E95D26)}},
3068         {{UINT64_C(0x8CBC15203A6E2116), UINT64_C(0xF09327DFBF285BBE),
3069           UINT64_C(0x8C7D9AD54A54D3C5), UINT64_C(0x778F54E66BD2768F)},
3070          {UINT64_C(0x09B489F88FF3DBC0), UINT64_C(0x0A0FA7FBD2871932),
3071           UINT64_C(0xABB9DC38E0A8CEC4), UINT64_C(0x2EE092D821E37A50)}},
3072         {{UINT64_C(0xBB9256E7AF6D88D8), UINT64_C(0x3CDCB1CB0A218927),
3073           UINT64_C(0x8E5B744AF216D6E6), UINT64_C(0x6F0617F2BC885AFD)},
3074          {UINT64_C(0xFBA9CDA7268397D5), UINT64_C(0xC61547165D4C75D8),
3075           UINT64_C(0x9ED8D17B43FB2CD2), UINT64_C(0x4D0CE3FBBE45BC5C)}},
3076         {{UINT64_C(0x4259BB02A38472F5), UINT64_C(0xFAFAAE0315107D0E),
3077           UINT64_C(0x2B8E450ECF0CF2B6), UINT64_C(0x788674C3ED887C3A)},
3078          {UINT64_C(0x1F3EBD594B3D2EAC), UINT64_C(0x82CB568475E41B55),
3079           UINT64_C(0x005AB76BC02BE49A), UINT64_C(0x6F13ADD2F5F90FEE)}},
3080         {{UINT64_C(0x0116374A7AFA7161), UINT64_C(0x8A1AE4482DB7F824),
3081           UINT64_C(0xD3C0DA12DB656A22), UINT64_C(0x7B095B95B989204D)},
3082          {UINT64_C(0x24C35202EF8F21CA), UINT64_C(0x91088DA72DA5A5A1),
3083           UINT64_C(0xAAF1944BE3F97D68), UINT64_C(0x245D28487C884134)}},
3084         {{UINT64_C(0xD80C65D668F5C702), UINT64_C(0xE2FE245F021A2974),
3085           UINT64_C(0xFB8520E03A11899C), UINT64_C(0x4806D1FA2BE6BF88)},
3086          {UINT64_C(0xF6F8C11A20ED235F), UINT64_C(0x52AC14247F0D651E),
3087           UINT64_C(0x44C3C89FDB9CF6D6), UINT64_C(0x6762516DB2E2E41F)}},
3088         {{UINT64_C(0x2743D874FDE91600), UINT64_C(0x60975FD5CDF00100),
3089           UINT64_C(0x78ACC8642D2954F4), UINT64_C(0x46B9E60256373454)},
3090          {UINT64_C(0x7586A9706F0FB867), UINT64_C(0x888E3677242DF35A),
3091           UINT64_C(0x5A639E79F1460F62), UINT64_C(0x1256517E55297DBC)}},
3092         {{UINT64_C(0x3F78339B7B9294C3), UINT64_C(0x5BA765D1BCE77012),
3093           UINT64_C(0xA88E0CD8512E39E2), UINT64_C(0x2D63E14BF6BA6A6A)},
3094          {UINT64_C(0xF849A163EA29071B), UINT64_C(0xF32519B74C0A2E22),
3095           UINT64_C(0xEA5D1315561C35F5), UINT64_C(0x7041F515D9267DCA)}},
3096         {{UINT64_C(0xE01E839F1FE56E6B), UINT64_C(0x3E473D8C4A93CE88),
3097           UINT64_C(0xC4846ECF89AAFDAE), UINT64_C(0x4111D97A07D946EA)},
3098          {UINT64_C(0xC20881F651A45F02), UINT64_C(0x14C2AC95B9CD841A),
3099           UINT64_C(0x2FBE8329F2CBD929), UINT64_C(0x1E8B7469C812608B)}},
3100         {{UINT64_C(0xB36A5D03007F0A5D), UINT64_C(0xA7E7A1A85DCF7AF4),
3101           UINT64_C(0x7227F4C5BEB12AFB), UINT64_C(0x462277924D276783)},
3102          {UINT64_C(0x9EA64D4C48403B93), UINT64_C(0x58EA31BC0B333ED5),
3103           UINT64_C(0x2D6DD219C5C93119), UINT64_C(0x385023A745069280)}},
3104         {{UINT64_C(0x8AB9B9EAF60C46AF), UINT64_C(0xFA1D3F08E8B827C2),
3105           UINT64_C(0x78C6BFBC1BAD41DB), UINT64_C(0x527A0BED23BE0C1E)},
3106          {UINT64_C(0x66212FD26ACCE641), UINT64_C(0x86125B0DEE6F78E7),
3107           UINT64_C(0xA2A0271858552A8C), UINT64_C(0x594F2B777E9605C5)}},
3108         {{UINT64_C(0x3FB1F6CF88A27989), UINT64_C(0xBC4962F7D96268B8),
3109           UINT64_C(0xBD8761E9B95E2A36), UINT64_C(0x64AB934A046DEC63)},
3110          {UINT64_C(0xC64D1C592E53CF1A), UINT64_C(0xC9865A9B578C5E8C),
3111           UINT64_C(0x5ECA62327A0359DE), UINT64_C(0x127DD136FB4685E5)}},
3112         {{UINT64_C(0xB0F7B0711AE320C9), UINT64_C(0x09BF89BB52525203),
3113           UINT64_C(0x97B20027709C5692), UINT64_C(0x16A62485EDBF6175)},
3114          {UINT64_C(0x32C18836394C50F9), UINT64_C(0x7D99468FD3B98C19),
3115           UINT64_C(0x8EBE50962E8D2729), UINT64_C(0x4E75B3CCE655F093)}},
3116         {{UINT64_C(0xCBEFD1A29EAE827E), UINT64_C(0xDE2D1234FBF4630D),
3117           UINT64_C(0x1B3ADCF896086CDA), UINT64_C(0x43D3960E2EA6CBA7)},
3118          {UINT64_C(0x18321D1D1CB5A0F7), UINT64_C(0xDC94C6F947BEABB4),
3119           UINT64_C(0xFBACC6D575AF6AB7), UINT64_C(0x0EE5D35789B98E86)}},
3120     },
3121     {
3122         {{UINT64_C(0x3F01B4AA062E0994), UINT64_C(0x994B28B05C952259),
3123           UINT64_C(0x2678F8B80CDEEC70), UINT64_C(0x4D06AF84212436F3)},
3124          {UINT64_C(0xE9DF52FD1CF27A98), UINT64_C(0xD56B9FD10B7718F7),
3125           UINT64_C(0x728BE624D9AEDA0D), UINT64_C(0x098710881A646888)}},
3126         {{UINT64_C(0xB1BC922D9B586B13), UINT64_C(0x6C084C543CA3B1BA),
3127           UINT64_C(0x54D196C7CF322698), UINT64_C(0x06EC3A5585D527E1)},
3128          {UINT64_C(0x069187102A57CAA1), UINT64_C(0x6AEAC07D65FD0F6B),
3129           UINT64_C(0xB66A34D70F512F84), UINT64_C(0x3860C002A44E6452)}},
3130         {{UINT64_C(0x17263B260881608A), UINT64_C(0x78D556AA56C18A7A),
3131           UINT64_C(0xA0826A1CAC3A47AB), UINT64_C(0x61686A58B6933FF5)},
3132          {UINT64_C(0xEA9D8771DBCF2C4F), UINT64_C(0x1C66EB026AB00426),
3133           UINT64_C(0xF8DAED2B401C466A), UINT64_C(0x1ED0A99ADAAE8040)}},
3134         {{UINT64_C(0x31EFFC4B7208E58A), UINT64_C(0x28868456B4E4319E),
3135           UINT64_C(0x1059C249D46AC4DA), UINT64_C(0x3589D2122279B362)},
3136          {UINT64_C(0xB28B8FAD45552E92), UINT64_C(0xC9E32541C3AB8098),
3137           UINT64_C(0x82604904F14B35A1), UINT64_C(0x1E64A89FDB68C214)}},
3138         {{UINT64_C(0xDF0E223DAB6947AF), UINT64_C(0xE74EF1D6771670D0),
3139           UINT64_C(0x70A9AD21F429F03B), UINT64_C(0x7CB1FA1F1385B8DC)},
3140          {UINT64_C(0x25ABC0A769053D24), UINT64_C(0x207FE30A6369D02E),
3141           UINT64_C(0x57B76E3CC6E4EC2C), UINT64_C(0x2E03D2E3B927CAB2)}},
3142         {{UINT64_C(0xEFA377FF622D57AE), UINT64_C(0x41532F56A885951A),
3143           UINT64_C(0x5ED89AA7CC69B9A8), UINT64_C(0x60BFF2EC295F5E84)},
3144          {UINT64_C(0x411D65C31E5C3041), UINT64_C(0xDB533F8B4B7772F8),
3145           UINT64_C(0x72CADEB63BDD4AEA), UINT64_C(0x0EC79DF27C49E454)}},
3146         {{UINT64_C(0x0C39332C81D0B84B), UINT64_C(0xA76A9A3A95FF472B),
3147           UINT64_C(0xD12FEB9931DB2BA6), UINT64_C(0x4AAB92223683E53A)},
3148          {UINT64_C(0x56CB18AF24FC6271), UINT64_C(0x671581D62544C72D),
3149           UINT64_C(0xCD136492FBD6F4D1), UINT64_C(0x6C2023183579EE09)}},
3150         {{UINT64_C(0xEDC5AF02C103C348), UINT64_C(0xDA32344E155A103D),
3151           UINT64_C(0xFF3A7679B0D1377E), UINT64_C(0x1609197268F02750)},
3152          {UINT64_C(0xD4C6360DD9E9C143), UINT64_C(0xE0ABA0EF968EE990),
3153           UINT64_C(0x5781687897E4C9AE), UINT64_C(0x5A4D167B9D63E32D)}},
3154         {{UINT64_C(0xB04BA52550E25802), UINT64_C(0x011DA36E66912F15),
3155           UINT64_C(0x08D8B68019E0A182), UINT64_C(0x66AA4AE82E462B0F)},
3156          {UINT64_C(0x3227C3A6E0B9D283), UINT64_C(0x9BF8C4D0F2B2B096),
3157           UINT64_C(0x1E51416CBA809EB7), UINT64_C(0x68411B752A67D346)}},
3158         {{UINT64_C(0xE55B134837A67F3B), UINT64_C(0x5E32D73C96484391),
3159           UINT64_C(0xC3F804D56256B91E), UINT64_C(0x67F17A4703B0783B)},
3160          {UINT64_C(0x2010EFEBDD2334AD), UINT64_C(0xBD9965B5B10FF052),
3161           UINT64_C(0x519CDA6DF58ACA52), UINT64_C(0x045BEEBE2FD3D394)}},
3162         {{UINT64_C(0x81722E2CEA271BCD), UINT64_C(0x393C082E0A4F1342),
3163           UINT64_C(0x573F7CD553B345CE), UINT64_C(0x7AD71FE23D7B4292)},
3164          {UINT64_C(0xDA406D0ADA8BECB8), UINT64_C(0x14FD41CA82FE66BC),
3165           UINT64_C(0x80A410620A91DFFC), UINT64_C(0x33E38E10F4F0CDEB)}},
3166         {{UINT64_C(0x0234BF382529532C), UINT64_C(0x9F5D6342A76CAE3B),
3167           UINT64_C(0xC9944CB3B3C50442), UINT64_C(0x51752DF08ABFAF17)},
3168          {UINT64_C(0x2BFA58C4A37B13FB), UINT64_C(0x19F80FDEDDB14951),
3169           UINT64_C(0xDC7026AA7DCB927B), UINT64_C(0x57907272AAB9FCBA)}},
3170         {{UINT64_C(0xCE38712DF3C046C2), UINT64_C(0x21D1FDB047B29D0E),
3171           UINT64_C(0x7F746E0ECD96D414), UINT64_C(0x72F07B52636CFEA4)},
3172          {UINT64_C(0x0D8FE94FECE6382D), UINT64_C(0x9BFB4CBA24229CA4),
3173           UINT64_C(0xFAE55B77E54388B0), UINT64_C(0x074EBC32A188299F)}},
3174         {{UINT64_C(0x8AF2EBCDE21DCCA2), UINT64_C(0x9916A6B6377487F2),
3175           UINT64_C(0x607DC19AD8051D40), UINT64_C(0x7DFD53F4419DDE12)},
3176          {UINT64_C(0xD17D0D619AD07924), UINT64_C(0x14F7CE0F173E266B),
3177           UINT64_C(0x687FB8530281C9EB), UINT64_C(0x6B35CC1A3361B273)}},
3178         {{UINT64_C(0x7CD6369E16E02DE3), UINT64_C(0x118EE0B11F35DFBC),
3179           UINT64_C(0x7D8C8DBD98B3EE60), UINT64_C(0x039806FC8D29EA17)},
3180          {UINT64_C(0x3C473872EC2C2597), UINT64_C(0x81294AF45E4EF521),
3181           UINT64_C(0x5ED048DBC22A9D7C), UINT64_C(0x3879E95B0A08C4D4)}},
3182         {{UINT64_C(0x0206E47F96A864FE), UINT64_C(0xC94F137AA55D0631),
3183           UINT64_C(0x9C1B3D298E8408F8), UINT64_C(0x150A4046B9193A5E)},
3184          {UINT64_C(0x4E8F9345CB1ADF21), UINT64_C(0x6ED14D8A7BD5E1F9),
3185           UINT64_C(0x7082532960809F68), UINT64_C(0x0D2F1C3BFA85A06C)}},
3186     },
3187     {
3188         {{UINT64_C(0x3C5ABE75B5C810C3), UINT64_C(0xEA2C3EF9E28F1E26),
3189           UINT64_C(0xEEB1C5688BF68280), UINT64_C(0x5A165CEB7AE69110)},
3190          {UINT64_C(0xE36C646044550DF1), UINT64_C(0x6FB4B108DB909258),
3191           UINT64_C(0xBFA1427717D4D8C5), UINT64_C(0x744CAF23927976D8)}},
3192         {{UINT64_C(0xCBE70DF947EA55C7), UINT64_C(0x8F8119AE535457AE),
3193           UINT64_C(0x1E3C69EC7DAFD732), UINT64_C(0x1A2E162D39D409A2)},
3194          {UINT64_C(0xBD7576A15F81C227), UINT64_C(0xA040AF9EC86AC2C3),
3195           UINT64_C(0x5690C059C10FC749), UINT64_C(0x20B26E8849CFAEC6)}},
3196         {{UINT64_C(0x87AEBD1EE3EF781E), UINT64_C(0xBC794A621609A1F0),
3197           UINT64_C(0x96D8314226E7F61B), UINT64_C(0x5198577FFC51D17D)},
3198          {UINT64_C(0xBFB5FAE28E6D0124), UINT64_C(0x91A7172BFFD5BD72),
3199           UINT64_C(0x474B015402832847), UINT64_C(0x4BAF0B4C59827FEB)}},
3200         {{UINT64_C(0x5EADAA8EBA090294), UINT64_C(0x51401BC911A6E9FA),
3201           UINT64_C(0x78F117581D2594CD), UINT64_C(0x1811AD3082D203C2)},
3202          {UINT64_C(0x554CC39A53FD07CC), UINT64_C(0x055FC983C7A05601),
3203           UINT64_C(0xB3B34E95D5A80B4B), UINT64_C(0x72B4CF941819BC16)}},
3204         {{UINT64_C(0x0750E4F0514FAFD0), UINT64_C(0x297D27E6AD61C7B1),
3205           UINT64_C(0x701D743FA2D5D410), UINT64_C(0x535DD97BC83B55C9)},
3206          {UINT64_C(0x2EE96DDE1CB11BB0), UINT64_C(0xECEA32EA0914450F),
3207           UINT64_C(0x4FB812364CDBDA6A), UINT64_C(0x5B75B6B2233C8063)}},
3208         {{UINT64_C(0xF0A934A6D69D6C6A), UINT64_C(0x313E89773CC80AC9),
3209           UINT64_C(0x74692B171E428B71), UINT64_C(0x0474FEFCE1BE662D)},
3210          {UINT64_C(0xAA2FF6DBAFFBF61B), UINT64_C(0xCE1594E1776983AF),
3211           UINT64_C(0xF00C665B4D5A2596), UINT64_C(0x30DD24497D414B9A)}},
3212         {{UINT64_C(0xEF862DA2ACC44AB3), UINT64_C(0xBAD6857F6EE7A44A),
3213           UINT64_C(0x57674BF9D2F9027E), UINT64_C(0x4D771CC32ABF816E)},
3214          {UINT64_C(0x27BEFC18AC0F1348), UINT64_C(0xD83112EF5E4F1202),
3215           UINT64_C(0x3571BDE38E9AAAE5), UINT64_C(0x07284830C1379B13)}},
3216         {{UINT64_C(0xA4C2F36F72A8890C), UINT64_C(0x22DF0E815824B392),
3217           UINT64_C(0x50FAD77F5E720240), UINT64_C(0x1D152A6903278F96)},
3218          {UINT64_C(0x25A3E92EA7D80F17), UINT64_C(0xBBF85B327EF32666),
3219           UINT64_C(0xBBB5568727222E52), UINT64_C(0x756D22A67582FE42)}},
3220         {{UINT64_C(0x0AE7493A9BC9EAED), UINT64_C(0x9185F53F0DDBB275),
3221           UINT64_C(0x1585D068C3DFDBA7), UINT64_C(0x543208A1562E2455)},
3222          {UINT64_C(0x4C417D81CBCF9535), UINT64_C(0xD2DC38D3E35DD6ED),
3223           UINT64_C(0x9DF1E014346F03A4), UINT64_C(0x65736E3FF0E772A6)}},
3224         {{UINT64_C(0x58684A7BCFB7FF06), UINT64_C(0x72CC4AFEC58E6316),
3225           UINT64_C(0x2CA9BF30A8BB508A), UINT64_C(0x61576519E2044C8C)},
3226          {UINT64_C(0xE78FAD3D8FF6D2B5), UINT64_C(0x6E5B839FA934C7B2),
3227           UINT64_C(0xC1F3D367FAFA9F9B), UINT64_C(0x637CC398F8B2AFA4)}},
3228         {{UINT64_C(0xD6FC1806FE2B2639), UINT64_C(0x1DB199B49E98A7F2),
3229           UINT64_C(0x0508763DC794F900), UINT64_C(0x363F1F7D3232E5AC)},
3230          {UINT64_C(0xDCF2AD74BBDBB351), UINT64_C(0x91F2EAF15A506BC6),
3231           UINT64_C(0xBDE8459EB850088B), UINT64_C(0x52DF883B3E1135AF)}},
3232         {{UINT64_C(0x12FD053AF93779DC), UINT64_C(0x3E3D87289E319E46),
3233           UINT64_C(0x4D631005E5E360AE), UINT64_C(0x4A8B5683B1B29A30)},
3234          {UINT64_C(0x305E5E53A8CA45EF), UINT64_C(0x59EACB45C2914843),
3235           UINT64_C(0x83677B7A1988ECEA), UINT64_C(0x63D9CD36D6FD53E8)}},
3236         {{UINT64_C(0xDF2DACF2B77EB45F), UINT64_C(0x3C1303E355BBA70E),
3237           UINT64_C(0x5AB8EB424526A06C), UINT64_C(0x4D4FD2167FE06BBC)},
3238          {UINT64_C(0x98C5ADCFE1486ABC), UINT64_C(0x9A503BFF07F86F3A),
3239           UINT64_C(0x7CEBAECB56282E44), UINT64_C(0x4FB090371F230DA0)}},
3240         {{UINT64_C(0xD1A3738427210752), UINT64_C(0xD10794D602CF1C74),
3241           UINT64_C(0x48A2095A820CC08C), UINT64_C(0x6DCDDE2EE3284B9D)},
3242          {UINT64_C(0xB8C7203E5D40510D), UINT64_C(0x957E89825385E3A7),
3243           UINT64_C(0xD220BE2FE27D7C13), UINT64_C(0x2D104AC57B471B5B)}},
3244         {{UINT64_C(0x3B31D52BBA0AFA8D), UINT64_C(0xFA9639F5DCC85F88),
3245           UINT64_C(0x150146378861DDD7), UINT64_C(0x31C222DB7B5443B0)},
3246          {UINT64_C(0xE2618546C3CDD689), UINT64_C(0x7F3FB754D528A130),
3247           UINT64_C(0xA0915810AC5FAF99), UINT64_C(0x3863B890E9899CE5)}},
3248         {{UINT64_C(0xBDD42CA3579C4353), UINT64_C(0xAD30567D4D65CB5B),
3249           UINT64_C(0x0E343F216D91810B), UINT64_C(0x65E0092D42E19816)},
3250          {UINT64_C(0x76154DCCF84E8C8E), UINT64_C(0xBA147CA80BA4AE59),
3251           UINT64_C(0xCA8085E756A1A71E), UINT64_C(0x1D90B4B01A158536)}},
3252     },
3253     {
3254         {{UINT64_C(0x5C4B7438F8B6C26A), UINT64_C(0x0C17A41B645BBE80),
3255           UINT64_C(0xA386062D40CF3D85), UINT64_C(0x563E42D2E78F776D)},
3256          {UINT64_C(0x4BB8E3561F07459B), UINT64_C(0xF01A24B775D222CD),
3257           UINT64_C(0xBE3D032B24CF3F61), UINT64_C(0x759B01670AD5F3A3)}},
3258         {{UINT64_C(0x2F5AEBD17D201AAB), UINT64_C(0x7B14CBEEC0AE02AD),
3259           UINT64_C(0xB9B54430EDC6388B), UINT64_C(0x69E713FBB622E01F)},
3260          {UINT64_C(0x4630EE8EC5361565), UINT64_C(0x6705961E5C8FB479),
3261           UINT64_C(0x125CC97E07C2AA45), UINT64_C(0x4BC459F425AE3B12)}},
3262         {{UINT64_C(0xEF02549628CF94E4), UINT64_C(0x04CFAB259DB24DE6),
3263           UINT64_C(0x52B8C734C62254EF), UINT64_C(0x0F2FE922568AB164)},
3264          {UINT64_C(0x48551A05E3F39B40), UINT64_C(0x4A36865F31A7C7F6),
3265           UINT64_C(0x4486512C840441AE), UINT64_C(0x559C6CAF8C7C4B4D)}},
3266         {{UINT64_C(0xFCC0D1DA0F103030), UINT64_C(0x7A9F1D5539CD584E),
3267           UINT64_C(0x3EFB9B94681D0D37), UINT64_C(0x3AE97CCD4D842332)},
3268          {UINT64_C(0x85A8ECE13C03676B), UINT64_C(0x030F87753AD435A1),
3269           UINT64_C(0xF6019B4D7F2D73B5), UINT64_C(0x6B77E31A2F14F911)}},
3270         {{UINT64_C(0x65C8161B9186C671), UINT64_C(0x412C3CC7CDFF2F8C),
3271           UINT64_C(0xBFFC17192C2FEA33), UINT64_C(0x75DCF68BC3675845)},
3272          {UINT64_C(0x0476AFBF3B23D576), UINT64_C(0xB20CAEE219315F79),
3273           UINT64_C(0x1BC2A8590885471A), UINT64_C(0x410FF6CFC328279C)}},
3274         {{UINT64_C(0x327394D960569D94), UINT64_C(0xFF2AEB6A6EA39D95),
3275           UINT64_C(0x1BED71E8EA0CA3AE), UINT64_C(0x1000A81E21072A94)},
3276          {UINT64_C(0x368EA22973C02416), UINT64_C(0xDF5B2A420A4941BC),
3277           UINT64_C(0x4FFDC7B8D0D40B3A), UINT64_C(0x7B2C73F148ABAB4E)}},
3278         {{UINT64_C(0x90FE34E481EE1072), UINT64_C(0xAE7A2FF4310E13D8),
3279           UINT64_C(0x6213D3B1CAB3927C), UINT64_C(0x44936FBD7DC7E9EF)},
3280          {UINT64_C(0x3B898EF323A1BDBE), UINT64_C(0x3FA6C6A054CC7B1D),
3281           UINT64_C(0x41BCC3B5C6AC54F2), UINT64_C(0x1AB5D168DC10AE39)}},
3282         {{UINT64_C(0x1AED113CFEAF67A6), UINT64_C(0x04E3C7A1342AC459),
3283           UINT64_C(0x65A392787A99DFBC), UINT64_C(0x03ECBC6B642329FF)},
3284          {UINT64_C(0x799F4EC5A6A4421A), UINT64_C(0x44522C26BEE18B3C),
3285           UINT64_C(0x1C7BFF151975C4BB), UINT64_C(0x0FAA03BEE6A27857)}},
3286         {{UINT64_C(0x173AB9E00743FF7B), UINT64_C(0xB11187AE2CFC95AE),
3287           UINT64_C(0xCA81BB2E9C112049), UINT64_C(0x6B811DB6C03555D5)},
3288          {UINT64_C(0x76C1FC144FE32256), UINT64_C(0xDA8C5A96D0E47C4E),
3289           UINT64_C(0xB645D41329FDB01C), UINT64_C(0x78898447AC39502A)}},
3290         {{UINT64_C(0x4285FF329BF44B35), UINT64_C(0x207F9029E3358C7F),
3291           UINT64_C(0x0FE8F03263BAF4CE), UINT64_C(0x698A0398FF15E1F7)},
3292          {UINT64_C(0x548748437E572DF6), UINT64_C(0x746835199F43C07B),
3293           UINT64_C(0x47BAB49E0A433D6A), UINT64_C(0x09ED8740FAB5C858)}},
3294         {{UINT64_C(0x8AA5E5C91F6CA820), UINT64_C(0xAD290A94D3C25BEC),
3295           UINT64_C(0xDC4C67BF3BA255F0), UINT64_C(0x0D7EF7D91DEDD8A9)},
3296          {UINT64_C(0x0831A26F5EEFD1C3), UINT64_C(0x78CA66F504483E0C),
3297           UINT64_C(0x9D5A56122FAAC15A), UINT64_C(0x43B0C7E75D6FACDB)}},
3298         {{UINT64_C(0x34BA537C4503899D), UINT64_C(0x9DEBC8F52AF8ED3B),
3299           UINT64_C(0x396995E984F416E6), UINT64_C(0x77F10FEDC7BCE392)},
3300          {UINT64_C(0x065CCB721F8AF262), UINT64_C(0xE220ED60D2F00FC4),
3301           UINT64_C(0x41A5FB065EE25B46), UINT64_C(0x22505574DD9070B1)}},
3302         {{UINT64_C(0x571FF15144BFC5C0), UINT64_C(0xBE2558B83138363C),
3303           UINT64_C(0xB2211ABD605E356C), UINT64_C(0x0B6435DA176C5F53)},
3304          {UINT64_C(0xF18C917C8DCF484E), UINT64_C(0x45D4120CCD93D65F),
3305           UINT64_C(0xEBB0BF9C190AE7F8), UINT64_C(0x3D403DE28D8C8D5A)}},
3306         {{UINT64_C(0xCDE760B4BE656644), UINT64_C(0x99DC5E6D2D21DBC5),
3307           UINT64_C(0x644FCAF3B6232D08), UINT64_C(0x52955488859341E3)},
3308          {UINT64_C(0x3AB4580D25763919), UINT64_C(0x82AB0C534EF66999),
3309           UINT64_C(0xBD395C740180663E), UINT64_C(0x07974F1AB4756474)}},
3310         {{UINT64_C(0x8C15CFE731588EA6), UINT64_C(0x9629060EF36C882D),
3311           UINT64_C(0xDF8E8E9E862B080D), UINT64_C(0x0BD36B48D7A0C5BE)},
3312          {UINT64_C(0xEBD0C6C976DA047B), UINT64_C(0x4F0F08ABBB94FD5A),
3313           UINT64_C(0x33D41A4E74910D9F), UINT64_C(0x3D6F8D0BA9583754)}},
3314         {{UINT64_C(0xEC4C896E4E4FC72E), UINT64_C(0xB111210C002ECE31),
3315           UINT64_C(0x7204D9372AF11E21), UINT64_C(0x59B9C1EC5D0509E9)},
3316          {UINT64_C(0xBC97644CF9D5BBC0), UINT64_C(0x25B123AF31B4E869),
3317           UINT64_C(0x091D7AEC5A6CAAB0), UINT64_C(0x340B9E80ECC911C4)}},
3318     },
3319     {
3320         {{UINT64_C(0xE8036B20EC208406), UINT64_C(0xAF46A05A214CEB5A),
3321           UINT64_C(0x8672084A46CC8379), UINT64_C(0x7DE0A42F04BA7885)},
3322          {UINT64_C(0xB772BEDCC9D3F32A), UINT64_C(0x7DAE3680534B1520),
3323           UINT64_C(0x04CD6203EC7120CC), UINT64_C(0x032F88E3B4E99780)}},
3324         {{UINT64_C(0xB34BDA5CE4A0897E), UINT64_C(0xF7748B26379B2480),
3325           UINT64_C(0xF47F6646B2D97522), UINT64_C(0x66AD8DE1F9641DB9)},
3326          {UINT64_C(0x0F8EB919D1BF09C0), UINT64_C(0x7853BB4EB95DC052),
3327           UINT64_C(0xBE7EE13D62B1FD4A), UINT64_C(0x2FF7EDC5DC7CE53E)}},
3328         {{UINT64_C(0xE1009AA0EE81DF35), UINT64_C(0x14972F0261D0798B),
3329           UINT64_C(0x5A6831A0F1EA1A6A), UINT64_C(0x1DBABA3D0CAB301A)},
3330          {UINT64_C(0x421270E2157D5213), UINT64_C(0xA37BEA956407B790),
3331           UINT64_C(0xEAD56B1F103A6073), UINT64_C(0x27534624BAD909F1)}},
3332         {{UINT64_C(0xC92D2209C2621EF1), UINT64_C(0x450710C31D3AD3F3),
3333           UINT64_C(0x8CFB8D6C19E481AD), UINT64_C(0x35CACDAEE6DB01BD)},
3334          {UINT64_C(0x2DA4A1D87CDD5B01), UINT64_C(0x3E40C7510F55BA11),
3335           UINT64_C(0xA91D9EE7B15C162D), UINT64_C(0x13AD3BE511DBA157)}},
3336         {{UINT64_C(0xAE417DB0E72F64F5), UINT64_C(0x40822279F13352BA),
3337           UINT64_C(0xEC43AFD91F2B75B9), UINT64_C(0x14D4BB2BC9CF2972)},
3338          {UINT64_C(0x4A55718A0761B2F1), UINT64_C(0xDAFBF756D81A9307),
3339           UINT64_C(0x2DCDFC1C5D3E5A07), UINT64_C(0x696E42ED2EBBDF28)}},
3340         {{UINT64_C(0xF473939968705410), UINT64_C(0xFD581005AF5FFC88),
3341           UINT64_C(0x5490A69490A9F517), UINT64_C(0x4A5C8C2E8CF8327E)},
3342          {UINT64_C(0xC203CD35F7D83DA6), UINT64_C(0xECAA6B907282368D),
3343           UINT64_C(0x365BB5712AF7EC42), UINT64_C(0x112E7ACDD4099316)}},
3344         {{UINT64_C(0x9ABDE0603AE3C25C), UINT64_C(0xE4C03DADEB9925B2),
3345           UINT64_C(0x3C28DCB19E03388B), UINT64_C(0x2337A7CF52B63C06)},
3346          {UINT64_C(0x74DC0F134E1AF2EA), UINT64_C(0xA010E4E3CD0D59AA),
3347           UINT64_C(0x6E4DB7BA9FA14C96), UINT64_C(0x5B2C3862557F7CDE)}},
3348         {{UINT64_C(0xC826E567C8C79CA9), UINT64_C(0xE7D110CAE851BE0C),
3349           UINT64_C(0xFFD57057A3606499), UINT64_C(0x2E9DBC40C6482504)},
3350          {UINT64_C(0xC9F0C3C2F784D9AF), UINT64_C(0xDD982A05B755172E),
3351           UINT64_C(0x6BC6C19DA023997F), UINT64_C(0x4AC177BEE34493C6)}},
3352         {{UINT64_C(0x21C3E0874FA4F134), UINT64_C(0x66E10C3486F9722F),
3353           UINT64_C(0xD2927B017398579A), UINT64_C(0x7135B6380352C3D3)},
3354          {UINT64_C(0x2DA620073BB5EE11), UINT64_C(0x8B64F13C3A946236),
3355           UINT64_C(0x3A83C85430EAE6DF), UINT64_C(0x31114E2A0EB6F749)}},
3356         {{UINT64_C(0x2C7B52E735BFC72B), UINT64_C(0x6DD29EBD2B0D4C2C),
3357           UINT64_C(0xE90D39886C92E82D), UINT64_C(0x0A9249013864D94D)},
3358          {UINT64_C(0x630508249BEE9E78), UINT64_C(0x7929FD62003DD5CF),
3359           UINT64_C(0xD04F832CE57507D1), UINT64_C(0x61078BDC37D2C32E)}},
3360         {{UINT64_C(0xB118AFDD2E75264A), UINT64_C(0x3AB692EAEFD65114),
3361           UINT64_C(0x58D2CE248B0A2128), UINT64_C(0x4316E6C282ED6D5F)},
3362          {UINT64_C(0x97766FFF46345BE4), UINT64_C(0xD7FF30140A7451AA),
3363           UINT64_C(0x078A423FAACE2E37), UINT64_C(0x7F1F90C2A6A78919)}},
3364         {{UINT64_C(0x988FCCB08E9E3D4D), UINT64_C(0xBD003FC0B95C9731),
3365           UINT64_C(0x74E40076B0A84E58), UINT64_C(0x5FD1DBE61DF7FDD0)},
3366          {UINT64_C(0xD2C700C74E6CE2FA), UINT64_C(0xA6E042E2903C5AE7),
3367           UINT64_C(0x561CC25F3C73822E), UINT64_C(0x651A79392A6A0C0C)}},
3368         {{UINT64_C(0x103E9EC688CD7642), UINT64_C(0x65ED52183C3C86CE),
3369           UINT64_C(0x16BAB00282785C8B), UINT64_C(0x0B5C18BBF34723C5)},
3370          {UINT64_C(0x528B0546E724D144), UINT64_C(0x5E582A6B780EEF9E),
3371           UINT64_C(0xC08283B8122F17AD), UINT64_C(0x0300EDCD1C22F32D)}},
3372         {{UINT64_C(0x03AC716A38DCFD39), UINT64_C(0xCD88474C94F12C74),
3373           UINT64_C(0xB5E8641EE9042CA8), UINT64_C(0x1D5746CC40D10558)},
3374          {UINT64_C(0x7869F45ECB4BB408), UINT64_C(0x28FB091D569489C3),
3375           UINT64_C(0xEA371EEC50A46306), UINT64_C(0x2802579675AA224C)}},
3376         {{UINT64_C(0x4EAFA44EF7A5923A), UINT64_C(0xD2427C306B69FD8B),
3377           UINT64_C(0x4C4E884A393D83F9), UINT64_C(0x2D34890A6236AB65)},
3378          {UINT64_C(0x80038D4035CC97F5), UINT64_C(0x4FE43C8497897472),
3379           UINT64_C(0xE5F56243BEF161AF), UINT64_C(0x3E1BDD6F9372E631)}},
3380         {{UINT64_C(0x06A2B2875732669F), UINT64_C(0x92D00397CDF4D2C0),
3381           UINT64_C(0xCD9A25F0454A57F5), UINT64_C(0x23ADB7242F0CDB0B)},
3382          {UINT64_C(0x504DA603FF0F8CB0), UINT64_C(0x14EF9D30D3E24181),
3383           UINT64_C(0xB1B1328E47FC1E66), UINT64_C(0x319B2A846C60354D)}},
3384     },
3385     {
3386         {{UINT64_C(0xBBF5542EF1D56038), UINT64_C(0xEDE3E637DD71CFC3),
3387           UINT64_C(0xFAA81D212E9F6C8B), UINT64_C(0x4DD2D44B69FBD060)},
3388          {UINT64_C(0x71FB623314366A20), UINT64_C(0x155E486F9575451D),
3389           UINT64_C(0x001106F0EC7807D9), UINT64_C(0x1C80E5ABC617034C)}},
3390         {{UINT64_C(0xD3E478DB8619F5F4), UINT64_C(0x1DF5C367F68170C2),
3391           UINT64_C(0xEAB095243430DE1D), UINT64_C(0x48F09361C3CD4C24)},
3392          {UINT64_C(0xE49DEA4B60644FED), UINT64_C(0x47170F1C758C3679),
3393           UINT64_C(0x4CC1E6E8B0382A84), UINT64_C(0x2DBDB9DA10A4465E)}},
3394         {{UINT64_C(0x67BAA79AC8400A4C), UINT64_C(0xFA30675301D28ECE),
3395           UINT64_C(0x29DB5B1C6F33289C), UINT64_C(0x4475757326A8FCB4)},
3396          {UINT64_C(0x59616219E1B0A795), UINT64_C(0x3032D939C5B32FA0),
3397           UINT64_C(0x3010C9177C3CEA2C), UINT64_C(0x5CF83EF19892BDF4)}},
3398         {{UINT64_C(0x55DE11413C7E83E6), UINT64_C(0x9D03929C74EA0366),
3399           UINT64_C(0x5CA60C5083BAF3FE), UINT64_C(0x3D9BCA587F70E905)},
3400          {UINT64_C(0xDB79DF5AFCC5AB59), UINT64_C(0x03CFCF0653F68D30),
3401           UINT64_C(0xBE101A784FCFA5F1), UINT64_C(0x115D7078B49E493C)}},
3402         {{UINT64_C(0xF14023AA76A0CCBD), UINT64_C(0x4287F0BC086F2E50),
3403           UINT64_C(0xC5EAA559F79A37E7), UINT64_C(0x5D527C0904E4F2A2)},
3404          {UINT64_C(0xEC91461651DAA504), UINT64_C(0x250D90C6EEF1DC95),
3405           UINT64_C(0x1B0AA868A50330B2), UINT64_C(0x7B45A78354189BBE)}},
3406         {{UINT64_C(0x0D602E05F019D6FF), UINT64_C(0x563E3893DD1800BA),
3407           UINT64_C(0x7146727EF3C7F7E5), UINT64_C(0x59641D984B026635)},
3408          {UINT64_C(0x50BCF90FE91DDBB8), UINT64_C(0x5D43E78E7F8397A6),
3409           UINT64_C(0x8734A261EB15896E), UINT64_C(0x4AD1E8649FF6B361)}},
3410         {{UINT64_C(0x1A9B601F320322F1), UINT64_C(0x606D40B391F611C4),
3411           UINT64_C(0xB984958BA19C918F), UINT64_C(0x67BFB045776F834E)},
3412          {UINT64_C(0xC59E556968DD85F0), UINT64_C(0xB5642834D4067875),
3413           UINT64_C(0x247E7D65CB138DF3), UINT64_C(0x73640A035CB9281D)}},
3414         {{UINT64_C(0xC7C34CCC88639889), UINT64_C(0xD9E44E07A785C707),
3415           UINT64_C(0x1BE68EFE32F83073), UINT64_C(0x249902DAAE5317CE)},
3416          {UINT64_C(0xF1F0B86A76CA92FF), UINT64_C(0xA7F502CFC01CB06B),
3417           UINT64_C(0x0A8B4766595AA185), UINT64_C(0x614135AAB792DE49)}},
3418         {{UINT64_C(0x5392CAA7564F2BC8), UINT64_C(0x1CDDA684CC894FCD),
3419           UINT64_C(0x10AC2378A4EBF82F), UINT64_C(0x6211EA465051BFF9)},
3420          {UINT64_C(0xE53B017430E8E210), UINT64_C(0x2374FEC302C0E381),
3421           UINT64_C(0xF8B1506B4DA07224), UINT64_C(0x4E451E0154DA7A08)}},
3422         {{UINT64_C(0xA8404D9C241FC7FB), UINT64_C(0x1D6DBF6EC4406332),
3423           UINT64_C(0xFE14231930162118), UINT64_C(0x69DE75CCA7EF5EF5)},
3424          {UINT64_C(0x008D4D09856E26A5), UINT64_C(0x2BC64B65C588ECF6),
3425           UINT64_C(0x7A523D0BAA01EE19), UINT64_C(0x213EF390932F0B95)}},
3426         {{UINT64_C(0xA42FE5131CD716FA), UINT64_C(0xFB13B3C60E8001B6),
3427           UINT64_C(0xBFDC7998D8F530CB), UINT64_C(0x04F9C05BF1C61761)},
3428          {UINT64_C(0xFB57396FAFED9D64), UINT64_C(0x28CCEE3A421AC123),
3429           UINT64_C(0x32590C9BF6C21ACC), UINT64_C(0x503B97CBBCA75AE3)}},
3430         {{UINT64_C(0x745208BC366946ED), UINT64_C(0xA75D88E94C906596),
3431           UINT64_C(0x03A30C7EEE043530), UINT64_C(0x5C67C151D11BF4D5)},
3432          {UINT64_C(0x04F75DFAE7AE4BB3), UINT64_C(0xA08136067F8D7404),
3433           UINT64_C(0x8B9F921019D68F64), UINT64_C(0x5AB6797106F73B55)}},
3434         {{UINT64_C(0x08064C4AB0687095), UINT64_C(0x27E30DDDB0106DF4),
3435           UINT64_C(0x31D29C708482524A), UINT64_C(0x65DD5896D86FDACD)},
3436          {UINT64_C(0x081C013DC647197E), UINT64_C(0x51C10B9ED7A53A45),
3437           UINT64_C(0xACB9A4DE0DD7FC53), UINT64_C(0x639997A2F646220B)}},
3438         {{UINT64_C(0x97CCF8251FB93B43), UINT64_C(0xB7D7713DE488D786),
3439           UINT64_C(0x4F7595663E4DBB33), UINT64_C(0x13B5D8A1E0F09964)},
3440          {UINT64_C(0xFFDDAD74316CDD97), UINT64_C(0x67C5578252C92EE9),
3441           UINT64_C(0x03B50F940AC5D6FD), UINT64_C(0x56C5C0091484DF88)}},
3442         {{UINT64_C(0xDCE199E31778D303), UINT64_C(0x53A2A4C60F1DD4EC),
3443           UINT64_C(0x7CC5EE9E370A7B99), UINT64_C(0x4403202B2598744E)},
3444          {UINT64_C(0xCCFAA978228247B6), UINT64_C(0xF50D14BD4A1D0E27),
3445           UINT64_C(0x6669506180723ABC), UINT64_C(0x750CCB6A742C0015)}},
3446         {{UINT64_C(0x7B04693681A109F1), UINT64_C(0x6414D9A3D4C1AFE5),
3447           UINT64_C(0x35070548DD14AC1F), UINT64_C(0x27172F39DEC0D3F0)},
3448          {UINT64_C(0x4EE0A7BFF2E273F0), UINT64_C(0x028C7813EC82B8E6),
3449           UINT64_C(0x907BF09F2081EAE2), UINT64_C(0x72E4C3D3414D6421)}},
3450     },
3451     {
3452         {{UINT64_C(0x2064097EA073711C), UINT64_C(0x980D830A5A65EC25),
3453           UINT64_C(0x7906A87CF0877567), UINT64_C(0x3E5EAE10F1980A3A)},
3454          {UINT64_C(0x5F51023A9272CE32), UINT64_C(0x71D69E68A437C974),
3455           UINT64_C(0x32006EA1D0B579FF), UINT64_C(0x191935FFA436E129)}},
3456         {{UINT64_C(0xE5FE290991C1474C), UINT64_C(0x7350B9FA1F0B10F5),
3457           UINT64_C(0x2006F41D6B4AB128), UINT64_C(0x4EBDA6CFCD95FA42)},
3458          {UINT64_C(0x450289385DA9A7F4), UINT64_C(0xD8129DE457FB462B),
3459           UINT64_C(0x4F2BF2C9E592EF90), UINT64_C(0x14A1A16BD6751DCC)}},
3460         {{UINT64_C(0x7460BB84DE0CD47A), UINT64_C(0x261F24D6468CBA3D),
3461           UINT64_C(0x229D31811E3C2D8A), UINT64_C(0x4AE520C91D19E059)},
3462          {UINT64_C(0x5AC3AEE7DF8DC66E), UINT64_C(0xCB417060299697EE),
3463           UINT64_C(0x227C1497CE97514F), UINT64_C(0x2589B8032E991FDE)}},
3464         {{UINT64_C(0x7FE9D585A97A5D03), UINT64_C(0x7333A1EF10D58157),
3465           UINT64_C(0x54C1CCD2C94C3DF6), UINT64_C(0x25C1B25228073B4E)},
3466          {UINT64_C(0xEEB29AF90635AD79), UINT64_C(0x880019C19AA38848),
3467           UINT64_C(0x1A85994230A9A497), UINT64_C(0x57EDCC2D92B25ABA)}},
3468         {{UINT64_C(0xA98DAE7D65E19DE6), UINT64_C(0x8007DD1746AD8696),
3469           UINT64_C(0x61F2E2CFA7F3BBAD), UINT64_C(0x1EFCD38754193858)},
3470          {UINT64_C(0xFB54FD6011666ECF), UINT64_C(0xD97EA5DF36E7D371),
3471           UINT64_C(0x944CA1703B9371FF), UINT64_C(0x32A52CAC05DE7FB0)}},
3472         {{UINT64_C(0xB960FFF619ED8B5E), UINT64_C(0xFD6B4C3E660354BB),
3473           UINT64_C(0xF8ECAADA1C9E95F0), UINT64_C(0x687A6D29A8E08CC7)},
3474          {UINT64_C(0xD38B7670C6A83D12), UINT64_C(0x1646064C1265BF30),
3475           UINT64_C(0x7DE19FFE2464892D), UINT64_C(0x05B57E081BDBB729)}},
3476         {{UINT64_C(0xF3586B04FFB7A98A), UINT64_C(0xF1850CDCCB072826),
3477           UINT64_C(0xFA3E66A4CF53BFB0), UINT64_C(0x7C78E56706E07221)},
3478          {UINT64_C(0x21E6F2453B4E72AE), UINT64_C(0x10A0D78BC6A3DBE8),
3479           UINT64_C(0xB9FC6D77D618DDAB), UINT64_C(0x33092D1376951DE5)}},
3480         {{UINT64_C(0xCAA1BF9D5A0257CB), UINT64_C(0x1044E224866C505F),
3481           UINT64_C(0x9B51410781482E7D), UINT64_C(0x538CB86788940BFB)},
3482          {UINT64_C(0xACE68B78AC21DCC1), UINT64_C(0x57942F3C1609BF8C),
3483           UINT64_C(0x30A47F3266E48C7A), UINT64_C(0x170D301DB0DA341F)}},
3484         {{UINT64_C(0x19643EB218ED9863), UINT64_C(0xBBE55BCCD9104F33),
3485           UINT64_C(0x77008B6CA15B283C), UINT64_C(0x2A6E0B41873A6A02)},
3486          {UINT64_C(0x517410DF3CB9A225), UINT64_C(0x20D76E38F538730A),
3487           UINT64_C(0x76C9CAD69F8724F0), UINT64_C(0x588BA1066BE9A035)}},
3488         {{UINT64_C(0xA059DBECF842F66C), UINT64_C(0x59CA186DB3ED0481),
3489           UINT64_C(0xA5B2ABCBD454490F), UINT64_C(0x4A0F600402624902)},
3490          {UINT64_C(0x45AF7B514D2F605F), UINT64_C(0x57E8FE0FC368030F),
3491           UINT64_C(0x23B745570C0727AE), UINT64_C(0x7E91EC772B603EC4)}},
3492         {{UINT64_C(0xEDD284CFFD582BE8), UINT64_C(0x3077CB2381093CDA),
3493           UINT64_C(0xB1934840FDEA4FCE), UINT64_C(0x00F9B9D1D7F01C9A)},
3494          {UINT64_C(0xA55E5C5B0A1C707B), UINT64_C(0x05CD73CB2F8618A5),
3495           UINT64_C(0x7327CECB512EEA05), UINT64_C(0x5130A0998BF2A4D5)}},
3496         {{UINT64_C(0x34D18880FA7A1C7B), UINT64_C(0x5E0D6C53FD4E043F),
3497           UINT64_C(0xB4DD80101B4442AE), UINT64_C(0x59D9183E78ED7563)},
3498          {UINT64_C(0x624DDAFCF1FAE158), UINT64_C(0xC08C36535C4C1E92),
3499           UINT64_C(0x452FD71FCE3E42EF), UINT64_C(0x175B490820B902EC)}},
3500         {{UINT64_C(0x5F0FDF2418F4CE34), UINT64_C(0xA64A30119B7E61B8),
3501           UINT64_C(0x8109ACD5663362E2), UINT64_C(0x4D02F82497F3DF44)},
3502          {UINT64_C(0x2CE27CCE3A4F916A), UINT64_C(0x4A4E6CBB3B85B146),
3503           UINT64_C(0xFE7A6199DB8C9E5E), UINT64_C(0x53F5D620D94B8D23)}},
3504         {{UINT64_C(0x37FEBEC3E77610A9), UINT64_C(0xE82D8EAC92245CB0),
3505           UINT64_C(0x3FD2CEEAF79A31BC), UINT64_C(0x277ACF32B446850C)},
3506          {UINT64_C(0xD89FF4C7CE1A2786), UINT64_C(0x441781E5FFD3A23C),
3507           UINT64_C(0x7876EFC507E85496), UINT64_C(0x0F306C7BE6F41B30)}},
3508         {{UINT64_C(0x3BF2BFD15AB1B92B), UINT64_C(0xDCC3F5A6F373FCF2),
3509           UINT64_C(0x27CFC4A6DA53C229), UINT64_C(0x5885737C508E677F)},
3510          {UINT64_C(0x1275D0F17B829F24), UINT64_C(0xBD3C0B024991B75B),
3511           UINT64_C(0x3F82ACDFE581C569), UINT64_C(0x123294353F28904E)}},
3512         {{UINT64_C(0xCF7BDCCC99C3A09B), UINT64_C(0x191911075F7D601A),
3513           UINT64_C(0xA82F746039FBAA22), UINT64_C(0x3105A6FCD75B5786)},
3514          {UINT64_C(0x9673DAC4932F69A6), UINT64_C(0xF5664B25B57D6EE6),
3515           UINT64_C(0x1EDAC1120A3CDD3E), UINT64_C(0x3CF84F8C42778563)}},
3516     },
3517     {
3518         {{UINT64_C(0xE36FD1B765DE3040), UINT64_C(0x240EADEA8AA0D3FE),
3519           UINT64_C(0x769714317F77F804), UINT64_C(0x6FCC933E591E9694)},
3520          {UINT64_C(0x3218D92B18F48742), UINT64_C(0x215F13E95E1B4001),
3521           UINT64_C(0xCDF333CD7A8D69B9), UINT64_C(0x14F159B1D2FD134F)}},
3522         {{UINT64_C(0x2D1228D607A50C16), UINT64_C(0x0DFD80F629AE42FD),
3523           UINT64_C(0x6C18B122BB8F3512), UINT64_C(0x0FE61243303F3DCA)},
3524          {UINT64_C(0x43A29F4DDA50709B), UINT64_C(0x3FF58C084B92BF7B),
3525           UINT64_C(0x62DC6B41DFCEF797), UINT64_C(0x43F9525AC7B83F32)}},
3526         {{UINT64_C(0x17EBBC9A15F08F5B), UINT64_C(0xBCD3B6408BB3E932),
3527           UINT64_C(0xD46FBB9F510BBD36), UINT64_C(0x389ABBA8CF65442B)},
3528          {UINT64_C(0x3A3DAFE4B575545C), UINT64_C(0x6AB985ECE1D0994D),
3529           UINT64_C(0xCC2A697B69E1DB27), UINT64_C(0x0D483E18271581DC)}},
3530         {{UINT64_C(0x380D4095C046D968), UINT64_C(0x5303975555D3318B),
3531           UINT64_C(0x57FA762991CE6FFC), UINT64_C(0x0A0F2885A4ADB641)},
3532          {UINT64_C(0x8B99AF1B6E5C2909), UINT64_C(0xBDFE7FFDB8794175),
3533           UINT64_C(0x2CFB948A795ED786), UINT64_C(0x11FE74650FD0DF66)}},
3534         {{UINT64_C(0xFC2CC2BD22E152E2), UINT64_C(0xCF6AB96BE30BCEB3),
3535           UINT64_C(0xAE89C041BC89B689), UINT64_C(0x6813430CE7523AB6)},
3536          {UINT64_C(0x3F49E72840A4FA33), UINT64_C(0x025DE1B7857CB0C9),
3537           UINT64_C(0x6D71465A11EA5EA5), UINT64_C(0x6651F7B946C8D7CB)}},
3538         {{UINT64_C(0xD05F1DCE5268098F), UINT64_C(0x891DBB680DC75030),
3539           UINT64_C(0xD939E428EA916291), UINT64_C(0x5F8EECCCEA37D060)},
3540          {UINT64_C(0x885F1EA88DC5D544), UINT64_C(0xFD3B3D1757E7448F),
3541           UINT64_C(0x5FC791A879531DE0), UINT64_C(0x780C1AAF42E66DAA)}},
3542         {{UINT64_C(0x19697778397BB28F), UINT64_C(0x5EC31D44AAA9069D),
3543           UINT64_C(0xDC2DFEAA3CA24A6F), UINT64_C(0x3F66CFCA80BED770)},
3544          {UINT64_C(0x2B6B82151A102662), UINT64_C(0x44B4D7A4C5D34CEB),
3545           UINT64_C(0x17E0FDE688AFECF2), UINT64_C(0x0DEFA14BCFF8D214)}},
3546         {{UINT64_C(0x14035AA48365CA84), UINT64_C(0x309CEEF0197CE2B7),
3547           UINT64_C(0x21305426ED39AF37), UINT64_C(0x10D01D11D2EA583A)},
3548          {UINT64_C(0x3F2E97499FA5C766), UINT64_C(0x98357584D70549D4),
3549           UINT64_C(0x8FF80803D279946D), UINT64_C(0x53DBC43399DF1253)}},
3550         {{UINT64_C(0x1D0D9EFA5329F12F), UINT64_C(0xBC9F74CFBE1F007F),
3551           UINT64_C(0xD7F2AA9A18EE4DBC), UINT64_C(0x634BF4CF3A792753)},
3552          {UINT64_C(0xD5DC72AD2FA6255A), UINT64_C(0xEE69EA43F3BC00C5),
3553           UINT64_C(0xEA930F61D8147A1A), UINT64_C(0x25E1368DF4E9AD37)}},
3554         {{UINT64_C(0x9422AAF7B7C955EC), UINT64_C(0x7C7107616A74D634),
3555           UINT64_C(0x4ED89932305EE420), UINT64_C(0x07E422122E937289)},
3556          {UINT64_C(0x7EBB231328566C88), UINT64_C(0xC7ED9C7AC27ED656),
3557           UINT64_C(0xF77F3873BF14FB3B), UINT64_C(0x447AA1E5EB957520)}},
3558         {{UINT64_C(0x3E3CEC7EB5C5E016), UINT64_C(0xB33DDFF7BDE44D26),
3559           UINT64_C(0x2056E9C766E820DD), UINT64_C(0x21A9E5D4F8196FE2)},
3560          {UINT64_C(0x86CB0A1788040C97), UINT64_C(0x18AD8AE7FF515D49),
3561           UINT64_C(0xCB8A564A226A400A), UINT64_C(0x6DB489798B72A0D2)}},
3562         {{UINT64_C(0x4365074B6324DED2), UINT64_C(0x9EFB5CC6AEDAF0F8),
3563           UINT64_C(0xCF952C3CC0792B14), UINT64_C(0x70B82AB997ED965E)},
3564          {UINT64_C(0x931B98863ACEBCE7), UINT64_C(0xDA85049118C2425A),
3565           UINT64_C(0xD88E1E27E499F7FB), UINT64_C(0x61D3F246960981DE)}},
3566         {{UINT64_C(0x1D8EA2278393EB0A), UINT64_C(0x9DCC23D27863FB53),
3567           UINT64_C(0x961B2337D5EBD297), UINT64_C(0x0A96F8B25BFED1E9)},
3568          {UINT64_C(0x39EA1803FE7DD2B7), UINT64_C(0x7E4817BBE5F7772A),
3569           UINT64_C(0x3668C5FFD44A41EF), UINT64_C(0x78227653E11F8E11)}},
3570         {{UINT64_C(0x272D6933D024880B), UINT64_C(0x733C029FF236FD8A),
3571           UINT64_C(0xBA5C20BD604868F0), UINT64_C(0x33F211AE321175C2)},
3572          {UINT64_C(0xE40010FB9FD79FE3), UINT64_C(0x9C6EA1DCA685A59F),
3573           UINT64_C(0x79963FFC8EB9889D), UINT64_C(0x15434E7D5F67108D)}},
3574         {{UINT64_C(0x42C14BBFD68B670F), UINT64_C(0x2021AC9D23F1AA69),
3575           UINT64_C(0xBF4C6D74AEA04636), UINT64_C(0x1E4D2F8EBD1FB11D)},
3576          {UINT64_C(0x4B0CF0E337911AA6), UINT64_C(0x7542D9282C484507),
3577           UINT64_C(0x68836751889542DC), UINT64_C(0x05F229F7FE2282A0)}},
3578         {{UINT64_C(0xAF269E8B409B2067), UINT64_C(0x6C749952A860F075),
3579           UINT64_C(0xCB7492DA5DF7C7F6), UINT64_C(0x2B010A7FE8E591E1)},
3580          {UINT64_C(0xF744657704D9E871), UINT64_C(0xC2E0A2A35E68408E),
3581           UINT64_C(0xD512E9A6D0F0BAAD), UINT64_C(0x3E2F73E1C6BE34A3)}},
3582     },
3583     {
3584         {{UINT64_C(0x6C466C8E2EC65BB4), UINT64_C(0x912FFAE5B1FC8F92),
3585           UINT64_C(0x7587BE5DB50A522D), UINT64_C(0x15939FF7649847CF)},
3586          {UINT64_C(0x69E81D63F464794E), UINT64_C(0x7BB6EEE36D3F858E),
3587           UINT64_C(0x24FE5C0110813BBB), UINT64_C(0x0C491F976D80756C)}},
3588         {{UINT64_C(0xBAD1C256A5FF3510), UINT64_C(0xF06F38A299C1B7B2),
3589           UINT64_C(0xF7C0F164049312D6), UINT64_C(0x073C53745749B3E4)},
3590          {UINT64_C(0xD676148055211A81), UINT64_C(0xF34CB5DBDFA98F45),
3591           UINT64_C(0xAF59FA47B4AA4967), UINT64_C(0x116935B98214BE48)}},
3592         {{UINT64_C(0x1D86FA009FE10E46), UINT64_C(0x73B8099C0B5B8494),
3593           UINT64_C(0x9A6EA98DA1102BE7), UINT64_C(0x3DE1948B5514CA21)},
3594          {UINT64_C(0x5D18ED69D0AAAA53), UINT64_C(0x17BF7DFF3C952B98),
3595           UINT64_C(0xC60143FE7DDBD937), UINT64_C(0x214F2F556F2F10C4)}},
3596         {{UINT64_C(0xB2F2869502F047D0), UINT64_C(0x80952DFE923F52BF),
3597           UINT64_C(0x56F3306BA5017C3E), UINT64_C(0x5DD62F07052DADFB)},
3598          {UINT64_C(0xDD11592DD5274F90), UINT64_C(0x40632FF3E471965B),
3599           UINT64_C(0xAD1939A87E618430), UINT64_C(0x5DD9CAD233F19556)}},
3600         {{UINT64_C(0x7B0AA88CC1094747), UINT64_C(0xCFA6B95DF6753A0C),
3601           UINT64_C(0xE81AFADA2A252A4D), UINT64_C(0x364CAB7CD3770570)},
3602          {UINT64_C(0xE99D8252B4610A19), UINT64_C(0xB22B2FEC55ED9AD3),
3603           UINT64_C(0x328ACBDDBEBE7FED), UINT64_C(0x1D379D61FBEDFE84)}},
3604         {{UINT64_C(0xD9EFFFFA5EDF8C9C), UINT64_C(0x9BAA71810CE548EC),
3605           UINT64_C(0xEB458AEB5FA8FEEB), UINT64_C(0x18C5E6910904D841)},
3606          {UINT64_C(0xFCEFAE288F33D2E5), UINT64_C(0xB3CF853E6FAFDA18),
3607           UINT64_C(0x05DE94BA427D6218), UINT64_C(0x021D8AED3731D3E9)}},
3608         {{UINT64_C(0x06C8C318E92719DA), UINT64_C(0x1F7CDE121A65DFDB),
3609           UINT64_C(0x9B4D531E4B672A2D), UINT64_C(0x3E39CC63115FAF11)},
3610          {UINT64_C(0xC9C3F3390037AF60), UINT64_C(0xC1C6758702B43D27),
3611           UINT64_C(0x46B77CDDC42DF26B), UINT64_C(0x7235F2B0EBFA97A7)}},
3612         {{UINT64_C(0xAF7FFC9AE898094E), UINT64_C(0x8D18AB93146A27E3),
3613           UINT64_C(0x1376B7978AEC0416), UINT64_C(0x746A1B1C8D91C25E)},
3614          {UINT64_C(0x16DCCCC10EBDE2E3), UINT64_C(0xFE4ABD418CE7D61E),
3615           UINT64_C(0xB9830395E25F1551), UINT64_C(0x543493D7B885A943)}},
3616         {{UINT64_C(0x52C659E624EBCFC0), UINT64_C(0x72E3CA91D38367A4),
3617           UINT64_C(0xA3086AAC4D168F4F), UINT64_C(0x656ACFEE5D64207B)},
3618          {UINT64_C(0xBE697CBABA196A9E), UINT64_C(0x6A737ACC97DFFEC2),
3619           UINT64_C(0x393E266154F04DBD), UINT64_C(0x4FFF7C244B0E92BD)}},
3620         {{UINT64_C(0xC709CC59828EC659), UINT64_C(0xB275AC8CCBDEACB3),
3621           UINT64_C(0xA8D08921F7922523), UINT64_C(0x68B92F96400A6459)},
3622          {UINT64_C(0x45803EC2DFBECB97), UINT64_C(0x49464E057515D696),
3623           UINT64_C(0xF39CA9618F03E969), UINT64_C(0x605065A11CD7C79F)}},
3624         {{UINT64_C(0xB91C03DC97F1A97A), UINT64_C(0x2F6D50BB201FFB53),
3625           UINT64_C(0x39D67D4046241856), UINT64_C(0x0A2C025674D04805)},
3626          {UINT64_C(0xD289B94C28374A6D), UINT64_C(0x1176C73A10EDD6FC),
3627           UINT64_C(0x890E9C3956AE631E), UINT64_C(0x30451CF16027F549)}},
3628         {{UINT64_C(0x0CB33FDCDF8F4DDB), UINT64_C(0xD9C540DE87FF6E63),
3629           UINT64_C(0xD844573255A1D8E4), UINT64_C(0x1497403D8AC403A6)},
3630          {UINT64_C(0xA2591C406A4BAAC6), UINT64_C(0xF493CF1F48DD3E5D),
3631           UINT64_C(0x7B9AE39FB69AF047), UINT64_C(0x293123C03782B110)}},
3632         {{UINT64_C(0x14921836B7A36B62), UINT64_C(0x5AC824304CA3AA39),
3633           UINT64_C(0x01303AA652F601CA), UINT64_C(0x7EE1E6C72B43BB72)},
3634          {UINT64_C(0x7F82B37B64D44957), UINT64_C(0x840D0654DA4A6FEC),
3635           UINT64_C(0xFC806FA10290F75D), UINT64_C(0x3027FE4A4C62F0E8)}},
3636         {{UINT64_C(0x34E68AB5CD0D3AC0), UINT64_C(0xE6B0B8C1E9BC85BD),
3637           UINT64_C(0xE00F505299533831), UINT64_C(0x11327DA7CDC83750)},
3638          {UINT64_C(0x6D991DF04656A428), UINT64_C(0x6A7BE34986228F26),
3639           UINT64_C(0x6BF85E3D3019CDC5), UINT64_C(0x42200D2F576913A4)}},
3640         {{UINT64_C(0x420D9259707B940F), UINT64_C(0x1BB1FFE13C5E39BB),
3641           UINT64_C(0x83D6BA36E40D018E), UINT64_C(0x139BD842044EC576)},
3642          {UINT64_C(0x3C79F8D2C6DE63E8), UINT64_C(0x49150B1D96F1FB0B),
3643           UINT64_C(0x666160531358A13B), UINT64_C(0x187CA3CFD5DDFD9F)}},
3644         {{UINT64_C(0x0675370F8D5AEE84), UINT64_C(0x30AA7D65DC269114),
3645           UINT64_C(0x295F7FE85AFC6DC1), UINT64_C(0x4945202955674339)},
3646          {UINT64_C(0x7EB1926BA6F209EC), UINT64_C(0x5232B9D1DC72C3E3),
3647           UINT64_C(0xCD788D79AB52141B), UINT64_C(0x3EB561BEFDD9611F)}},
3648     },
3649     {
3650         {{UINT64_C(0x09DB342CE22241AD), UINT64_C(0x2EAB852F2A566653),
3651           UINT64_C(0x970843EDCA6E59F3), UINT64_C(0x6490013EA18C2D89)},
3652          {UINT64_C(0x52293350C7A691CC), UINT64_C(0x6544B49DB2079F14),
3653           UINT64_C(0xC49C559852DCF090), UINT64_C(0x4069B6FC8817A2C7)}},
3654         {{UINT64_C(0x0E4A4B0CC86B40F4), UINT64_C(0x2B5350E151F6F853),
3655           UINT64_C(0xDE26FDE21033BEC4), UINT64_C(0x4DE9D2E7C0E9B971)},
3656          {UINT64_C(0x716605FDD315AD57), UINT64_C(0x5627D732392B101A),
3657           UINT64_C(0x628EDFC681A9F40A), UINT64_C(0x4BD2A96C5AB9C99D)}},
3658         {{UINT64_C(0x2C8DF2A1BFBD288A), UINT64_C(0x260C4F1EF4CF7C09),
3659           UINT64_C(0x88A2618690E796CB), UINT64_C(0x105ACC3A323E0702)},
3660          {UINT64_C(0xA8ADA467667664CF), UINT64_C(0x41144C1B3B518622),
3661           UINT64_C(0x4A532B87D8B99FE1), UINT64_C(0x4A51C2892289C308)}},
3662         {{UINT64_C(0x201DDA611D6F6880), UINT64_C(0x47A964D462029898),
3663           UINT64_C(0xE44E2EEE426C8CA5), UINT64_C(0x02A5182109625DBA)},
3664          {UINT64_C(0x170C626EB45B3DFB), UINT64_C(0xFC7F1F715C8343A9),
3665           UINT64_C(0xE6CF246FE549F040), UINT64_C(0x4ACF60AE2F903ACE)}},
3666         {{UINT64_C(0x9171535281C807EC), UINT64_C(0x72AC60C347174A58),
3667           UINT64_C(0xAD62D06FA0F12F61), UINT64_C(0x325C2792AA899C0D)},
3668          {UINT64_C(0x53A1E3929D8BA267), UINT64_C(0x5DC088A5CDACCB05),
3669           UINT64_C(0x5BB9127F5025CB69), UINT64_C(0x25D2B42E69214616)}},
3670         {{UINT64_C(0x4DE5D58ADDB55121), UINT64_C(0x688AA2F584DE0677),
3671           UINT64_C(0xF7925A3963AA25E0), UINT64_C(0x4FB42FC785D4DEA5)},
3672          {UINT64_C(0x957B933B8F134390), UINT64_C(0xB360DD2C4B9BF8C2),
3673           UINT64_C(0x45E6767FFFFF96CD), UINT64_C(0x26D0A6A91E01D5C3)}},
3674         {{UINT64_C(0xC7FC57145A0A98EA), UINT64_C(0xDBB06F30E7535AF6),
3675           UINT64_C(0x555B22E3DF4ACD0D), UINT64_C(0x3A011AAF2EFD2FBE)},
3676          {UINT64_C(0x341C7733E9166B20), UINT64_C(0x84619E8EFB19590A),
3677           UINT64_C(0x8EF989FD10574C96), UINT64_C(0x61ACFAAE0F55F9A2)}},
3678         {{UINT64_C(0x8C8A33F26DEAB094), UINT64_C(0x4A8E5D9F96022EBC),
3679           UINT64_C(0xA10DF82C7DDA92E8), UINT64_C(0x33A19462D1CF3815)},
3680          {UINT64_C(0xE3FF8E43A489D67F), UINT64_C(0xD4B6136F225064AA),
3681           UINT64_C(0xE1721D2A92F5E662), UINT64_C(0x4C4F03D7A90A33C6)}},
3682         {{UINT64_C(0x70885B35A3463B4A), UINT64_C(0x974BC40EDF9D0194),
3683           UINT64_C(0x1AF71E18273957F4), UINT64_C(0x58EF684B9900CB0D)},
3684          {UINT64_C(0xB09970C820A49A4A), UINT64_C(0x3F28403F42067458),
3685           UINT64_C(0x153FF2C4BD7D1AD5), UINT64_C(0x7912CC2EE97A90F7)}},
3686         {{UINT64_C(0xF653DF598F034D9F), UINT64_C(0xCA1671771C409CCF),
3687           UINT64_C(0x21F47005175F3583), UINT64_C(0x13B8A94BFAAFB66F)},
3688          {UINT64_C(0x64534EE396052C8D), UINT64_C(0x09304DD18D674024),
3689           UINT64_C(0xEB468AC30D7A7E2A), UINT64_C(0x40347256CD62052C)}},
3690         {{UINT64_C(0x0F089165FFF11C0E), UINT64_C(0x383562C98D69A45C),
3691           UINT64_C(0x7AB3EF9D3125FE61), UINT64_C(0x32C042BCE0735F3A)},
3692          {UINT64_C(0x420077C84E268D91), UINT64_C(0x7FB4208244695B4F),
3693           UINT64_C(0xFA83216F448A133E), UINT64_C(0x1C66060793062EB3)}},
3694         {{UINT64_C(0xA0FCBACAEF9E04DE), UINT64_C(0xAEF9EECB5B86F69A),
3695           UINT64_C(0x73D2E95FC39D4C99), UINT64_C(0x098C74F7923A5BA8)},
3696          {UINT64_C(0x5B8C95C84F68DECF), UINT64_C(0xCFF2E10158976551),
3697           UINT64_C(0x5032AE48BE5CAF91), UINT64_C(0x5CCB9008E09BC8AE)}},
3698         {{UINT64_C(0x41A38F203714D3BF), UINT64_C(0x2413653317366520),
3699           UINT64_C(0xF12F314CFAE17B01), UINT64_C(0x4AA0C969FC9AD43B)},
3700          {UINT64_C(0xD8AB5F728BBAC026), UINT64_C(0x35128269526992DC),
3701           UINT64_C(0xA2EF6E44D19880AA), UINT64_C(0x28BB3623DBF47628)}},
3702         {{UINT64_C(0x294742BA3BA25C35), UINT64_C(0x39D3BC9B061555B7),
3703           UINT64_C(0x944E3ABCDE6EA1A0), UINT64_C(0x4FDC641557EBD394)},
3704          {UINT64_C(0xB615C1DAE981E649), UINT64_C(0xAF7EDB348BE3C95F),
3705           UINT64_C(0x38573AE871F7221F), UINT64_C(0x1B30FF04668CF414)}},
3706         {{UINT64_C(0x48EFF6A2A57A9A4E), UINT64_C(0x04BA2F7374A59C19),
3707           UINT64_C(0x5FDE389D6779C5DA), UINT64_C(0x258E2B246612F160)},
3708          {UINT64_C(0xCE8D7A0B6D116D41), UINT64_C(0xAF660436EE2706C8),
3709           UINT64_C(0xFFAD6FE9F81D6398), UINT64_C(0x4FE5EC5414BA128A)}},
3710         {{UINT64_C(0x7D5E8299BD4B886C), UINT64_C(0x5403A46EDB0DB148),
3711           UINT64_C(0x32F49FC076A808D7), UINT64_C(0x6D483FD7D3B9A641)},
3712          {UINT64_C(0x731DF1223952C70F), UINT64_C(0xB5CABAC1CB5E6081),
3713           UINT64_C(0x12FA297D7AFA8F59), UINT64_C(0x3272360A6AC91952)}},
3714     }};
3715
3716 /*-
3717  * Q := 2P, both projective, Q and P same pointers OK
3718  * Autogenerated: op3/dbl_proj.op3
3719  * https://eprint.iacr.org/2015/1060 Alg 6
3720  * ASSERT: a = -3
3721  */
3722 static void point_double(pt_prj_t *Q, const pt_prj_t *P) {
3723     /* temporary variables */
3724     fe_t t0, t1, t2, t3, t4;
3725     /* constants */
3726     const limb_t *b = const_b;
3727     /* set pointers for legacy curve arith */
3728     const limb_t *X = P->X;
3729     const limb_t *Y = P->Y;
3730     const limb_t *Z = P->Z;
3731     limb_t *X3 = Q->X;
3732     limb_t *Y3 = Q->Y;
3733     limb_t *Z3 = Q->Z;
3734
3735     /* the curve arith formula */
3736     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(t0, X);
3737     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(t1, Y);
3738     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(t2, Z);
3739     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t3, X, Y);
3740     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, t3, t3);
3741     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t4, Y, Z);
3742     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, X, Z);
3743     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, Z3);
3744     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, b, t2);
3745     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, Z3);
3746     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, Y3, Y3);
3747     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, X3, Y3);
3748     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, t1, Y3);
3749     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t1, Y3);
3750     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X3, Y3);
3751     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, X3, t3);
3752     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, t2, t2);
3753     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t2, t2, t3);
3754     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, b, Z3);
3755     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, Z3, t2);
3756     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, Z3, t0);
3757     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, Z3, Z3);
3758     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, t3);
3759     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, t0, t0);
3760     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t3, t0);
3761     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t0, t0, t2);
3762     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t0, t0, Z3);
3763     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, t0);
3764     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t4, t4);
3765     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t0, Z3);
3766     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, X3, Z3);
3767     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t0, t1);
3768     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, Z3);
3769     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, Z3);
3770 }
3771
3772 /*-
3773  * R := Q + P where R and Q are projective, P affine.
3774  * R and Q same pointers OK
3775  * R and P same pointers not OK
3776  * Autogenerated: op3/add_mixed.op3
3777  * https://eprint.iacr.org/2015/1060 Alg 5
3778  * ASSERT: a = -3
3779  */
3780 static void point_add_mixed(pt_prj_t *R, const pt_prj_t *Q, const pt_aff_t *P) {
3781     /* temporary variables */
3782     fe_t t0, t1, t2, t3, t4;
3783     /* constants */
3784     const limb_t *b = const_b;
3785     /* set pointers for legacy curve arith */
3786     const limb_t *X1 = Q->X;
3787     const limb_t *Y1 = Q->Y;
3788     const limb_t *Z1 = Q->Z;
3789     const limb_t *X2 = P->X;
3790     const limb_t *Y2 = P->Y;
3791     fe_t X3;
3792     fe_t Y3;
3793     fe_t Z3;
3794     limb_t nz;
3795
3796     /* check P for affine inf */
3797     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_nonzero(&nz, P->Y);
3798
3799     /* the curve arith formula */
3800     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t0, X1, X2);
3801     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, Y1, Y2);
3802     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, X2, Y2);
3803     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, X1, Y1);
3804     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t3, t3, t4);
3805     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, t0, t1);
3806     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t3, t3, t4);
3807     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t4, Y2, Z1);
3808     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, t4, Y1);
3809     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X2, Z1);
3810     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, X1);
3811     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, b, Z1);
3812     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, Y3, Z3);
3813     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, X3, X3);
3814     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, X3, Z3);
3815     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, t1, X3);
3816     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, t1, X3);
3817     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, b, Y3);
3818     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, Z1, Z1);
3819     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t2, t1, Z1);
3820     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t2);
3821     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t0);
3822     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, Y3, Y3);
3823     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t1, Y3);
3824     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, t0, t0);
3825     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t1, t0);
3826     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t0, t0, t2);
3827     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t4, Y3);
3828     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t2, t0, Y3);
3829     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X3, Z3);
3830     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, t2);
3831     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, t3, X3);
3832     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, X3, t1);
3833     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t4, Z3);
3834     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t3, t0);
3835     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, t1);
3836
3837     /* if P is inf, throw all that away and take Q */
3838     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(R->X, nz, Q->X, X3);
3839     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(R->Y, nz, Q->Y, Y3);
3840     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(R->Z, nz, Q->Z, Z3);
3841 }
3842
3843 /*-
3844  * R := Q + P all projective.
3845  * R and Q same pointers OK
3846  * R and P same pointers not OK
3847  * Autogenerated: op3/add_proj.op3
3848  * https://eprint.iacr.org/2015/1060 Alg 4
3849  * ASSERT: a = -3
3850  */
3851 static void point_add_proj(pt_prj_t *R, const pt_prj_t *Q, const pt_prj_t *P) {
3852     /* temporary variables */
3853     fe_t t0, t1, t2, t3, t4, t5;
3854     /* constants */
3855     const limb_t *b = const_b;
3856     /* set pointers for legacy curve arith */
3857     const limb_t *X1 = Q->X;
3858     const limb_t *Y1 = Q->Y;
3859     const limb_t *Z1 = Q->Z;
3860     const limb_t *X2 = P->X;
3861     const limb_t *Y2 = P->Y;
3862     const limb_t *Z2 = P->Z;
3863     limb_t *X3 = R->X;
3864     limb_t *Y3 = R->Y;
3865     limb_t *Z3 = R->Z;
3866
3867     /* the curve arith formula */
3868     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t0, X1, X2);
3869     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, Y1, Y2);
3870     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t2, Z1, Z2);
3871     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, X1, Y1);
3872     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, X2, Y2);
3873     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t3, t3, t4);
3874     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, t0, t1);
3875     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t3, t3, t4);
3876     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, Y1, Z1);
3877     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t5, Y2, Z2);
3878     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t4, t4, t5);
3879     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t5, t1, t2);
3880     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t4, t4, t5);
3881     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, X1, Z1);
3882     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, X2, Z2);
3883     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, X3, Y3);
3884     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t0, t2);
3885     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, X3, Y3);
3886     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, b, t2);
3887     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, Y3, Z3);
3888     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, X3, X3);
3889     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, X3, Z3);
3890     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, t1, X3);
3891     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, t1, X3);
3892     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, b, Y3);
3893     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, t2, t2);
3894     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t2, t1, t2);
3895     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t2);
3896     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t0);
3897     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, Y3, Y3);
3898     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t1, Y3);
3899     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, t0, t0);
3900     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t1, t0);
3901     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t0, t0, t2);
3902     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t4, Y3);
3903     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t2, t0, Y3);
3904     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X3, Z3);
3905     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, t2);
3906     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, t3, X3);
3907     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, X3, t1);
3908     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t4, Z3);
3909     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t3, t0);
3910     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, t1);
3911 }
3912
3913 /* constants */
3914 #define RADIX 5
3915 #define DRADIX (1 << RADIX)
3916 #define DRADIX_WNAF ((DRADIX) << 1)
3917
3918 /*-
3919  * precomp for wnaf scalar multiplication:
3920  * precomp[0] = 1P
3921  * precomp[1] = 3P
3922  * precomp[2] = 5P
3923  * precomp[3] = 7P
3924  * precomp[4] = 9P
3925  * ...
3926  */
3927 static void precomp_wnaf(pt_prj_t precomp[DRADIX / 2], const pt_aff_t *P) {
3928     int i;
3929
3930     fe_copy(precomp[0].X, P->X);
3931     fe_copy(precomp[0].Y, P->Y);
3932     fe_copy(precomp[0].Z, const_one);
3933     point_double(&precomp[DRADIX / 2 - 1], &precomp[0]);
3934
3935     for (i = 1; i < DRADIX / 2; i++)
3936         point_add_proj(&precomp[i], &precomp[DRADIX / 2 - 1], &precomp[i - 1]);
3937 }
3938
3939 /* fetch a scalar bit */
3940 static int scalar_get_bit(const unsigned char in[32], int idx) {
3941     int widx, rshift;
3942
3943     widx = idx >> 3;
3944     rshift = idx & 0x7;
3945
3946     if (idx < 0 || widx >= 32) return 0;
3947
3948     return (in[widx] >> rshift) & 0x1;
3949 }
3950
3951 /*-
3952  * Compute "regular" wnaf representation of a scalar.
3953  * See "Exponent Recoding and Regular Exponentiation Algorithms",
3954  * Tunstall et al., AfricaCrypt 2009, Alg 6.
3955  * It forces an odd scalar and outputs digits in
3956  * {\pm 1, \pm 3, \pm 5, \pm 7, \pm 9, ...}
3957  * i.e. signed odd digits with _no zeroes_ -- that makes it "regular".
3958  */
3959 static void scalar_rwnaf(int8_t out[52], const unsigned char in[32]) {
3960     int i;
3961     int8_t window, d;
3962
3963     window = (in[0] & (DRADIX_WNAF - 1)) | 1;
3964     for (i = 0; i < 51; i++) {
3965         d = (window & (DRADIX_WNAF - 1)) - DRADIX;
3966         out[i] = d;
3967         window = (window - d) >> RADIX;
3968         window += scalar_get_bit(in, (i + 1) * RADIX + 1) << 1;
3969         window += scalar_get_bit(in, (i + 1) * RADIX + 2) << 2;
3970         window += scalar_get_bit(in, (i + 1) * RADIX + 3) << 3;
3971         window += scalar_get_bit(in, (i + 1) * RADIX + 4) << 4;
3972         window += scalar_get_bit(in, (i + 1) * RADIX + 5) << 5;
3973     }
3974     out[i] = window;
3975 }
3976
3977 /*-
3978  * Compute "textbook" wnaf representation of a scalar.
3979  * NB: not constant time
3980  */
3981 static void scalar_wnaf(int8_t out[257], const unsigned char in[32]) {
3982     int i;
3983     int8_t window, d;
3984
3985     window = in[0] & (DRADIX_WNAF - 1);
3986     for (i = 0; i < 257; i++) {
3987         d = 0;
3988         if ((window & 1) && ((d = window & (DRADIX_WNAF - 1)) & DRADIX))
3989             d -= DRADIX_WNAF;
3990         out[i] = d;
3991         window = (window - d) >> 1;
3992         window += scalar_get_bit(in, i + 1 + RADIX) << RADIX;
3993     }
3994 }
3995
3996 /*-
3997  * Simultaneous scalar multiplication: interleaved "textbook" wnaf.
3998  * NB: not constant time
3999  */
4000 static void var_smul_wnaf_two(pt_aff_t *out, const unsigned char a[32],
4001                               const unsigned char b[32], const pt_aff_t *P) {
4002     int i, d, is_neg, is_inf = 1, flipped = 0;
4003     int8_t anaf[257] = {0};
4004     int8_t bnaf[257] = {0};
4005     pt_prj_t Q = {0};
4006     pt_prj_t precomp[DRADIX / 2];
4007
4008     precomp_wnaf(precomp, P);
4009     scalar_wnaf(anaf, a);
4010     scalar_wnaf(bnaf, b);
4011
4012     for (i = 256; i >= 0; i--) {
4013         if (!is_inf) point_double(&Q, &Q);
4014         if ((d = bnaf[i])) {
4015             if ((is_neg = d < 0) != flipped) {
4016                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(Q.Y, Q.Y);
4017                 flipped ^= 1;
4018             }
4019             d = (is_neg) ? (-d - 1) >> 1 : (d - 1) >> 1;
4020             if (is_inf) {
4021                 /* initialize accumulator */
4022                 fe_copy(Q.X, &precomp[d].X);
4023                 fe_copy(Q.Y, &precomp[d].Y);
4024                 fe_copy(Q.Z, &precomp[d].Z);
4025                 is_inf = 0;
4026             } else
4027                 point_add_proj(&Q, &Q, &precomp[d]);
4028         }
4029         if ((d = anaf[i])) {
4030             if ((is_neg = d < 0) != flipped) {
4031                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(Q.Y, Q.Y);
4032                 flipped ^= 1;
4033             }
4034             d = (is_neg) ? (-d - 1) >> 1 : (d - 1) >> 1;
4035             if (is_inf) {
4036                 /* initialize accumulator */
4037                 fe_copy(Q.X, &lut_cmb[0][d].X);
4038                 fe_copy(Q.Y, &lut_cmb[0][d].Y);
4039                 fe_copy(Q.Z, const_one);
4040                 is_inf = 0;
4041             } else
4042                 point_add_mixed(&Q, &Q, &lut_cmb[0][d]);
4043         }
4044     }
4045
4046     if (is_inf) {
4047         /* initialize accumulator to inf: all-zero scalars */
4048         fe_set_zero(Q.X);
4049         fe_copy(Q.Y, const_one);
4050         fe_set_zero(Q.Z);
4051     }
4052
4053     if (flipped) {
4054         /* correct sign */
4055         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(Q.Y, Q.Y);
4056     }
4057
4058     /* convert to affine -- NB depends on coordinate system */
4059     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(Q.Z, Q.Z);
4060     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->X, Q.X, Q.Z);
4061     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->Y, Q.Y, Q.Z);
4062 }
4063
4064 /*-
4065  * Variable point scalar multiplication with "regular" wnaf.
4066  */
4067 static void var_smul_rwnaf(pt_aff_t *out, const unsigned char scalar[32],
4068                            const pt_aff_t *P) {
4069     int i, j, d, diff, is_neg;
4070     int8_t rnaf[52] = {0};
4071     pt_prj_t Q = {0}, lut = {0};
4072     pt_prj_t precomp[DRADIX / 2];
4073
4074     precomp_wnaf(precomp, P);
4075     scalar_rwnaf(rnaf, scalar);
4076
4077 #if defined(_MSC_VER)
4078     /* result still unsigned: yes we know */
4079 #pragma warning(push)
4080 #pragma warning(disable : 4146)
4081 #endif
4082
4083     /* initialize accumulator to high digit */
4084     d = (rnaf[51] - 1) >> 1;
4085     for (j = 0; j < DRADIX / 2; j++) {
4086         diff = (1 - (-(d ^ j) >> (8 * sizeof(int) - 1))) & 1;
4087         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.X, diff, Q.X,
4088                                                               precomp[j].X);
4089         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Y, diff, Q.Y,
4090                                                               precomp[j].Y);
4091         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Z, diff, Q.Z,
4092                                                               precomp[j].Z);
4093     }
4094
4095     for (i = 50; i >= 0; i--) {
4096         for (j = 0; j < RADIX; j++) point_double(&Q, &Q);
4097         d = rnaf[i];
4098         /* is_neg = (d < 0) ? 1 : 0 */
4099         is_neg = (d >> (8 * sizeof(int) - 1)) & 1;
4100         /* d = abs(d) */
4101         d = (d ^ -is_neg) + is_neg;
4102         d = (d - 1) >> 1;
4103         for (j = 0; j < DRADIX / 2; j++) {
4104             diff = (1 - (-(d ^ j) >> (8 * sizeof(int) - 1))) & 1;
4105             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
4106                 lut.X, diff, lut.X, precomp[j].X);
4107             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
4108                 lut.Y, diff, lut.Y, precomp[j].Y);
4109             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
4110                 lut.Z, diff, lut.Z, precomp[j].Z);
4111         }
4112         /* negate lut point if digit is negative */
4113         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(out->Y, lut.Y);
4114         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(lut.Y, is_neg,
4115                                                               lut.Y, out->Y);
4116         point_add_proj(&Q, &Q, &lut);
4117     }
4118
4119 #if defined(_MSC_VER)
4120 #pragma warning(pop)
4121 #endif
4122
4123     /* conditionally subtract P if the scalar was even */
4124     fe_copy(lut.X, precomp[0].X);
4125     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(lut.Y, precomp[0].Y);
4126     fe_copy(lut.Z, precomp[0].Z);
4127     point_add_proj(&lut, &lut, &Q);
4128     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.X, scalar[0] & 1,
4129                                                           lut.X, Q.X);
4130     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Y, scalar[0] & 1,
4131                                                           lut.Y, Q.Y);
4132     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Z, scalar[0] & 1,
4133                                                           lut.Z, Q.Z);
4134
4135     /* convert to affine -- NB depends on coordinate system */
4136     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(Q.Z, Q.Z);
4137     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->X, Q.X, Q.Z);
4138     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->Y, Q.Y, Q.Z);
4139 }
4140
4141 /*-
4142  * Fixed scalar multiplication: comb with interleaving.
4143  */
4144 static void fixed_smul_cmb(pt_aff_t *out, const unsigned char scalar[32]) {
4145     int i, j, k, d, diff, is_neg = 0;
4146     int8_t rnaf[52] = {0};
4147     pt_prj_t Q = {0}, R = {0};
4148     pt_aff_t lut = {0};
4149
4150     scalar_rwnaf(rnaf, scalar);
4151
4152     /* initalize accumulator to inf */
4153     fe_set_zero(Q.X);
4154     fe_copy(Q.Y, const_one);
4155     fe_set_zero(Q.Z);
4156
4157 #if defined(_MSC_VER)
4158     /* result still unsigned: yes we know */
4159 #pragma warning(push)
4160 #pragma warning(disable : 4146)
4161 #endif
4162
4163     for (i = 1; i >= 0; i--) {
4164         for (j = 0; i != 1 && j < RADIX; j++) point_double(&Q, &Q);
4165         for (j = 0; j < 27; j++) {
4166             if (j * 2 + i > 51) continue;
4167             d = rnaf[j * 2 + i];
4168             /* is_neg = (d < 0) ? 1 : 0 */
4169             is_neg = (d >> (8 * sizeof(int) - 1)) & 1;
4170             /* d = abs(d) */
4171             d = (d ^ -is_neg) + is_neg;
4172             d = (d - 1) >> 1;
4173             for (k = 0; k < DRADIX / 2; k++) {
4174                 diff = (1 - (-(d ^ k) >> (8 * sizeof(int) - 1))) & 1;
4175                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
4176                     lut.X, diff, lut.X, lut_cmb[j][k].X);
4177                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
4178                     lut.Y, diff, lut.Y, lut_cmb[j][k].Y);
4179             }
4180             /* negate lut point if digit is negative */
4181             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(out->Y, lut.Y);
4182             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
4183                 lut.Y, is_neg, lut.Y, out->Y);
4184             point_add_mixed(&Q, &Q, &lut);
4185         }
4186     }
4187
4188 #if defined(_MSC_VER)
4189 #pragma warning(pop)
4190 #endif
4191
4192     /* conditionally subtract P if the scalar was even */
4193     fe_copy(lut.X, lut_cmb[0][0].X);
4194     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(lut.Y, lut_cmb[0][0].Y);
4195     point_add_mixed(&R, &Q, &lut);
4196     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.X, scalar[0] & 1,
4197                                                           R.X, Q.X);
4198     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Y, scalar[0] & 1,
4199                                                           R.Y, Q.Y);
4200     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Z, scalar[0] & 1,
4201                                                           R.Z, Q.Z);
4202
4203     /* convert to affine -- NB depends on coordinate system */
4204     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(Q.Z, Q.Z);
4205     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->X, Q.X, Q.Z);
4206     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->Y, Q.Y, Q.Z);
4207 }
4208
4209 /*-
4210  * Wrapper: simultaneous scalar mutiplication.
4211  * outx, outy := a * G + b * P
4212  * where P = (inx, iny).
4213  * Everything is LE byte ordering.
4214  */
4215 static void point_mul_two(unsigned char outx[32], unsigned char outy[32],
4216                           const unsigned char a[32], const unsigned char b[32],
4217                           const unsigned char inx[32],
4218                           const unsigned char iny[32]) {
4219     pt_aff_t P;
4220
4221     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.X, inx);
4222     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.Y, iny);
4223     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.X, P.X);
4224     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.Y, P.Y);
4225     /* simultaneous scalar multiplication */
4226     var_smul_wnaf_two(&P, a, b, &P);
4227
4228     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.X, P.X);
4229     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.Y, P.Y);
4230     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outx, P.X);
4231     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outy, P.Y);
4232 }
4233
4234 /*-
4235  * Wrapper: fixed scalar mutiplication.
4236  * outx, outy := scalar * G
4237  * Everything is LE byte ordering.
4238  */
4239 static void point_mul_g(unsigned char outx[32], unsigned char outy[32],
4240                         const unsigned char scalar[32]) {
4241     pt_aff_t P;
4242
4243     /* fixed scmul function */
4244     fixed_smul_cmb(&P, scalar);
4245     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.X, P.X);
4246     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.Y, P.Y);
4247     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outx, P.X);
4248     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outy, P.Y);
4249 }
4250
4251 /*-
4252  * Wrapper: variable point scalar mutiplication.
4253  * outx, outy := scalar * P
4254  * where P = (inx, iny).
4255  * Everything is LE byte ordering.
4256  */
4257 static void point_mul(unsigned char outx[32], unsigned char outy[32],
4258                       const unsigned char scalar[32],
4259                       const unsigned char inx[32],
4260                       const unsigned char iny[32]) {
4261     pt_aff_t P;
4262
4263     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.X, inx);
4264     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.Y, iny);
4265     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.X, P.X);
4266     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.Y, P.Y);
4267     /* var scmul function */
4268     var_smul_rwnaf(&P, scalar, &P);
4269     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.X, P.X);
4270     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.Y, P.Y);
4271     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outx, P.X);
4272     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outy, P.Y);
4273 }
4274
4275
4276 #include <openssl/ec.h>
4277
4278 /* the zero field element */
4279 static const unsigned char const_zb[32] = {0};
4280
4281 /*-
4282  * An OpenSSL wrapper for simultaneous scalar multiplication.
4283  * r := n * G + m * q
4284  */
4285     int
4286     point_mul_two_id_GostR3410_2001_CryptoPro_B_ParamSet(
4287         const EC_GROUP *group, EC_POINT *r, const BIGNUM *n, const EC_POINT *q,
4288         const BIGNUM *m, BN_CTX *ctx) {
4289     int ret = 0;
4290     unsigned char b_x[32];
4291     unsigned char b_y[32];
4292     unsigned char b_n[32];
4293     unsigned char b_m[32];
4294     BIGNUM *x = NULL, *y = NULL;
4295
4296     BN_CTX_start(ctx);
4297     x = BN_CTX_get(ctx);
4298     if ((y = BN_CTX_get(ctx)) == NULL
4299         /* pull out coords as bytes */
4300         || !EC_POINT_get_affine_coordinates(group, q, x, y, ctx) ||
4301         BN_bn2lebinpad(x, b_x, 32) != 32 || BN_bn2lebinpad(y, b_y, 32) != 32 ||
4302         BN_bn2lebinpad(n, b_n, 32) != 32 || BN_bn2lebinpad(m, b_m, 32) != 32)
4303         goto err;
4304     /* do the simultaneous scalar multiplication */
4305     point_mul_two(b_x, b_y, b_n, b_m, b_x, b_y);
4306     /* check for infinity */
4307     if (CRYPTO_memcmp(const_zb, b_x, 32) == 0 &&
4308         CRYPTO_memcmp(const_zb, b_y, 32) == 0) {
4309         if (!EC_POINT_set_to_infinity(group, r)) goto err;
4310     } else {
4311         /* otherwise, pack the bytes into the result */
4312         if (BN_lebin2bn(b_x, 32, x) == NULL ||
4313             BN_lebin2bn(b_y, 32, y) == NULL ||
4314             !EC_POINT_set_affine_coordinates(group, r, x, y, ctx))
4315             goto err;
4316     }
4317     ret = 1;
4318 err:
4319     BN_CTX_end(ctx);
4320     return ret;
4321 }
4322
4323 /*-
4324  * An OpenSSL wrapper for variable point scalar multiplication.
4325  * r := m * q
4326  */
4327     int
4328     point_mul_id_GostR3410_2001_CryptoPro_B_ParamSet(const EC_GROUP *group,
4329                                                      EC_POINT *r,
4330                                                      const EC_POINT *q,
4331                                                      const BIGNUM *m,
4332                                                      BN_CTX *ctx) {
4333     int ret = 0;
4334     unsigned char b_x[32];
4335     unsigned char b_y[32];
4336     unsigned char b_m[32];
4337     BIGNUM *x = NULL, *y = NULL;
4338
4339     BN_CTX_start(ctx);
4340     x = BN_CTX_get(ctx);
4341     if ((y = BN_CTX_get(ctx)) == NULL
4342         /* pull out coords as bytes */
4343         || !EC_POINT_get_affine_coordinates(group, q, x, y, ctx) ||
4344         BN_bn2lebinpad(x, b_x, 32) != 32 || BN_bn2lebinpad(y, b_y, 32) != 32 ||
4345         BN_bn2lebinpad(m, b_m, 32) != 32)
4346         goto err;
4347     /* do the variable scalar multiplication */
4348     point_mul(b_x, b_y, b_m, b_x, b_y);
4349     /* check for infinity */
4350     if (CRYPTO_memcmp(const_zb, b_x, 32) == 0 &&
4351         CRYPTO_memcmp(const_zb, b_y, 32) == 0) {
4352         if (!EC_POINT_set_to_infinity(group, r)) goto err;
4353     } else {
4354         /* otherwise, pack the bytes into the result */
4355         if (BN_lebin2bn(b_x, 32, x) == NULL ||
4356             BN_lebin2bn(b_y, 32, y) == NULL ||
4357             !EC_POINT_set_affine_coordinates(group, r, x, y, ctx))
4358             goto err;
4359     }
4360     ret = 1;
4361 err:
4362     BN_CTX_end(ctx);
4363     return ret;
4364 }
4365
4366 /*-
4367  * An OpenSSL wrapper for fixed scalar multiplication.
4368  * r := n * G
4369  */
4370     int
4371     point_mul_g_id_GostR3410_2001_CryptoPro_B_ParamSet(const EC_GROUP *group,
4372                                                        EC_POINT *r,
4373                                                        const BIGNUM *n,
4374                                                        BN_CTX *ctx) {
4375     int ret = 0;
4376     unsigned char b_x[32];
4377     unsigned char b_y[32];
4378     unsigned char b_n[32];
4379     BIGNUM *x = NULL, *y = NULL;
4380
4381     BN_CTX_start(ctx);
4382     x = BN_CTX_get(ctx);
4383     if ((y = BN_CTX_get(ctx)) == NULL || BN_bn2lebinpad(n, b_n, 32) != 32)
4384         goto err;
4385     /* do the fixed scalar multiplication */
4386     point_mul_g(b_x, b_y, b_n);
4387     /* check for infinity */
4388     if (CRYPTO_memcmp(const_zb, b_x, 32) == 0 &&
4389         CRYPTO_memcmp(const_zb, b_y, 32) == 0) {
4390         if (!EC_POINT_set_to_infinity(group, r)) goto err;
4391     } else {
4392         /* otherwise, pack the bytes into the result */
4393         if (BN_lebin2bn(b_x, 32, x) == NULL ||
4394             BN_lebin2bn(b_y, 32, y) == NULL ||
4395             !EC_POINT_set_affine_coordinates(group, r, x, y, ctx))
4396             goto err;
4397     }
4398     ret = 1;
4399 err:
4400     BN_CTX_end(ctx);
4401     return ret;
4402 }
4403
4404
4405
4406 #else /* __SIZEOF_INT128__ */
4407
4408 #include <stdint.h>
4409 #include <string.h>
4410 #define LIMB_BITS 32
4411 #define LIMB_CNT 8
4412 /* Field elements */
4413 typedef uint32_t fe_t[LIMB_CNT];
4414 typedef uint32_t limb_t;
4415
4416 #ifdef OPENSSL_NO_ASM
4417 #define FIAT_ID_GOSTR3410_2001_CRYPTOPRO_B_PARAMSET_NO_ASM
4418 #endif
4419
4420 #define fe_copy(d, s) memcpy(d, s, sizeof(fe_t))
4421 #define fe_set_zero(d) memset(d, 0, sizeof(fe_t))
4422
4423 /* Projective points */
4424 typedef struct {
4425     fe_t X;
4426     fe_t Y;
4427     fe_t Z;
4428 } pt_prj_t;
4429
4430 /* Affine points */
4431 typedef struct {
4432     fe_t X;
4433     fe_t Y;
4434 } pt_aff_t;
4435
4436 /* BEGIN verbatim fiat code https://github.com/mit-plv/fiat-crypto */
4437 /*-
4438  * MIT License
4439  *
4440  * Copyright (c) 2020 the fiat-crypto authors (see the AUTHORS file)
4441  *
4442  * Permission is hereby granted, free of charge, to any person obtaining a copy
4443  * of this software and associated documentation files (the "Software"), to deal
4444  * in the Software without restriction, including without limitation the rights
4445  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
4446  * copies of the Software, and to permit persons to whom the Software is
4447  * furnished to do so, subject to the following conditions:
4448  *
4449  * The above copyright notice and this permission notice shall be included in
4450  * all copies or substantial portions of the Software.
4451  *
4452  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
4453  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
4454  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
4455  * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
4456  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
4457  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
4458  * SOFTWARE.
4459  */
4460
4461 /* Autogenerated: word_by_word_montgomery --static --use-value-barrier id_GostR3410_2001_CryptoPro_B_ParamSet 32 '2^255 + 3225' */
4462 /* curve description: id_GostR3410_2001_CryptoPro_B_ParamSet */
4463 /* machine_wordsize = 32 (from "32") */
4464 /* requested operations: (all) */
4465 /* m = 0x8000000000000000000000000000000000000000000000000000000000000c99 (from "2^255 + 3225") */
4466 /*                                                                    */
4467 /* NOTE: In addition to the bounds specified above each function, all */
4468 /*   functions synthesized for this Montgomery arithmetic require the */
4469 /*   input to be strictly less than the prime modulus (m), and also   */
4470 /*   require the input to be in the unique saturated representation.  */
4471 /*   All functions also ensure that these two properties are true of  */
4472 /*   return values.                                                   */
4473 /*  */
4474 /* Computed values: */
4475 /* eval z = z[0] + (z[1] << 32) + (z[2] << 64) + (z[3] << 96) + (z[4] << 128) + (z[5] << 160) + (z[6] << 192) + (z[7] << 224) */
4476 /* bytes_eval z = z[0] + (z[1] << 8) + (z[2] << 16) + (z[3] << 24) + (z[4] << 32) + (z[5] << 40) + (z[6] << 48) + (z[7] << 56) + (z[8] << 64) + (z[9] << 72) + (z[10] << 80) + (z[11] << 88) + (z[12] << 96) + (z[13] << 104) + (z[14] << 112) + (z[15] << 120) + (z[16] << 128) + (z[17] << 136) + (z[18] << 144) + (z[19] << 152) + (z[20] << 160) + (z[21] << 168) + (z[22] << 176) + (z[23] << 184) + (z[24] << 192) + (z[25] << 200) + (z[26] << 208) + (z[27] << 216) + (z[28] << 224) + (z[29] << 232) + (z[30] << 240) + (z[31] << 248) */
4477
4478 #include <stdint.h>
4479 typedef unsigned char fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1;
4480 typedef signed char fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1;
4481
4482 #if (-1 & 3) != 3
4483 #error "This code only works on a two's complement system"
4484 #endif
4485
4486 #if !defined(FIAT_ID_GOSTR3410_2001_CRYPTOPRO_B_PARAMSET_NO_ASM) && \
4487     (defined(__GNUC__) || defined(__clang__))
4488 static __inline__ uint32_t
4489 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u32(uint32_t a) {
4490     __asm__("" : "+r"(a) : /* no inputs */);
4491     return a;
4492 }
4493 #else
4494 #define fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u32(x) (x)
4495 #endif
4496
4497 /*
4498  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32 is an addition with carry.
4499  * Postconditions:
4500  *   out1 = (arg1 + arg2 + arg3) mod 2^32
4501  *   out2 = ⌊(arg1 + arg2 + arg3) / 2^32⌋
4502  *
4503  * Input Bounds:
4504  *   arg1: [0x0 ~> 0x1]
4505  *   arg2: [0x0 ~> 0xffffffff]
4506  *   arg3: [0x0 ~> 0xffffffff]
4507  * Output Bounds:
4508  *   out1: [0x0 ~> 0xffffffff]
4509  *   out2: [0x0 ~> 0x1]
4510  */
4511 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
4512     uint32_t *out1, fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 *out2,
4513     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1, uint32_t arg2,
4514     uint32_t arg3) {
4515     uint64_t x1;
4516     uint32_t x2;
4517     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x3;
4518     x1 = ((arg1 + (uint64_t)arg2) + arg3);
4519     x2 = (uint32_t)(x1 & UINT32_C(0xffffffff));
4520     x3 = (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1)(x1 >> 32);
4521     *out1 = x2;
4522     *out2 = x3;
4523 }
4524
4525 /*
4526  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32 is a subtraction with borrow.
4527  * Postconditions:
4528  *   out1 = (-arg1 + arg2 + -arg3) mod 2^32
4529  *   out2 = -⌊(-arg1 + arg2 + -arg3) / 2^32⌋
4530  *
4531  * Input Bounds:
4532  *   arg1: [0x0 ~> 0x1]
4533  *   arg2: [0x0 ~> 0xffffffff]
4534  *   arg3: [0x0 ~> 0xffffffff]
4535  * Output Bounds:
4536  *   out1: [0x0 ~> 0xffffffff]
4537  *   out2: [0x0 ~> 0x1]
4538  */
4539 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
4540     uint32_t *out1, fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 *out2,
4541     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1, uint32_t arg2,
4542     uint32_t arg3) {
4543     int64_t x1;
4544     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1 x2;
4545     uint32_t x3;
4546     x1 = ((arg2 - (int64_t)arg1) - arg3);
4547     x2 = (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1)(x1 >> 32);
4548     x3 = (uint32_t)(x1 & UINT32_C(0xffffffff));
4549     *out1 = x3;
4550     *out2 = (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1)(0x0 - x2);
4551 }
4552
4553 /*
4554  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32 is a multiplication, returning the full double-width result.
4555  * Postconditions:
4556  *   out1 = (arg1 * arg2) mod 2^32
4557  *   out2 = ⌊arg1 * arg2 / 2^32⌋
4558  *
4559  * Input Bounds:
4560  *   arg1: [0x0 ~> 0xffffffff]
4561  *   arg2: [0x0 ~> 0xffffffff]
4562  * Output Bounds:
4563  *   out1: [0x0 ~> 0xffffffff]
4564  *   out2: [0x0 ~> 0xffffffff]
4565  */
4566 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(
4567     uint32_t *out1, uint32_t *out2, uint32_t arg1, uint32_t arg2) {
4568     uint64_t x1;
4569     uint32_t x2;
4570     uint32_t x3;
4571     x1 = ((uint64_t)arg1 * arg2);
4572     x2 = (uint32_t)(x1 & UINT32_C(0xffffffff));
4573     x3 = (uint32_t)(x1 >> 32);
4574     *out1 = x2;
4575     *out2 = x3;
4576 }
4577
4578 /*
4579  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32 is a single-word conditional move.
4580  * Postconditions:
4581  *   out1 = (if arg1 = 0 then arg2 else arg3)
4582  *
4583  * Input Bounds:
4584  *   arg1: [0x0 ~> 0x1]
4585  *   arg2: [0x0 ~> 0xffffffff]
4586  *   arg3: [0x0 ~> 0xffffffff]
4587  * Output Bounds:
4588  *   out1: [0x0 ~> 0xffffffff]
4589  */
4590 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
4591     uint32_t *out1, fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1,
4592     uint32_t arg2, uint32_t arg3) {
4593     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x1;
4594     uint32_t x2;
4595     uint32_t x3;
4596     x1 = (!(!arg1));
4597     x2 = ((fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_int1)(0x0 - x1) &
4598           UINT32_C(0xffffffff));
4599     x3 =
4600         ((fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u32(x2) &
4601           arg3) |
4602          (fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_value_barrier_u32((~x2)) &
4603           arg2));
4604     *out1 = x3;
4605 }
4606
4607 /*
4608  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul multiplies two field elements in the Montgomery domain.
4609  * Preconditions:
4610  *   0 ≤ eval arg1 < m
4611  *   0 ≤ eval arg2 < m
4612  * Postconditions:
4613  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) * eval (from_montgomery arg2)) mod m
4614  *   0 ≤ eval out1 < m
4615  *
4616  * Input Bounds:
4617  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
4618  *   arg2: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
4619  * Output Bounds:
4620  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
4621  */
4622 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(
4623     uint32_t out1[8], const uint32_t arg1[8], const uint32_t arg2[8]) {
4624     uint32_t x1;
4625     uint32_t x2;
4626     uint32_t x3;
4627     uint32_t x4;
4628     uint32_t x5;
4629     uint32_t x6;
4630     uint32_t x7;
4631     uint32_t x8;
4632     uint32_t x9;
4633     uint32_t x10;
4634     uint32_t x11;
4635     uint32_t x12;
4636     uint32_t x13;
4637     uint32_t x14;
4638     uint32_t x15;
4639     uint32_t x16;
4640     uint32_t x17;
4641     uint32_t x18;
4642     uint32_t x19;
4643     uint32_t x20;
4644     uint32_t x21;
4645     uint32_t x22;
4646     uint32_t x23;
4647     uint32_t x24;
4648     uint32_t x25;
4649     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x26;
4650     uint32_t x27;
4651     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x28;
4652     uint32_t x29;
4653     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x30;
4654     uint32_t x31;
4655     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x32;
4656     uint32_t x33;
4657     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x34;
4658     uint32_t x35;
4659     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x36;
4660     uint32_t x37;
4661     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x38;
4662     uint32_t x39;
4663     uint32_t x40;
4664     uint32_t x41;
4665     uint32_t x42;
4666     uint32_t x43;
4667     uint32_t x44;
4668     uint32_t x45;
4669     uint32_t x46;
4670     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x47;
4671     uint32_t x48;
4672     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x49;
4673     uint32_t x50;
4674     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x51;
4675     uint32_t x52;
4676     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x53;
4677     uint32_t x54;
4678     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x55;
4679     uint32_t x56;
4680     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x57;
4681     uint32_t x58;
4682     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x59;
4683     uint32_t x60;
4684     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x61;
4685     uint32_t x62;
4686     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x63;
4687     uint32_t x64;
4688     uint32_t x65;
4689     uint32_t x66;
4690     uint32_t x67;
4691     uint32_t x68;
4692     uint32_t x69;
4693     uint32_t x70;
4694     uint32_t x71;
4695     uint32_t x72;
4696     uint32_t x73;
4697     uint32_t x74;
4698     uint32_t x75;
4699     uint32_t x76;
4700     uint32_t x77;
4701     uint32_t x78;
4702     uint32_t x79;
4703     uint32_t x80;
4704     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x81;
4705     uint32_t x82;
4706     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x83;
4707     uint32_t x84;
4708     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x85;
4709     uint32_t x86;
4710     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x87;
4711     uint32_t x88;
4712     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x89;
4713     uint32_t x90;
4714     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x91;
4715     uint32_t x92;
4716     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x93;
4717     uint32_t x94;
4718     uint32_t x95;
4719     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x96;
4720     uint32_t x97;
4721     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x98;
4722     uint32_t x99;
4723     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x100;
4724     uint32_t x101;
4725     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x102;
4726     uint32_t x103;
4727     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x104;
4728     uint32_t x105;
4729     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x106;
4730     uint32_t x107;
4731     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x108;
4732     uint32_t x109;
4733     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x110;
4734     uint32_t x111;
4735     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x112;
4736     uint32_t x113;
4737     uint32_t x114;
4738     uint32_t x115;
4739     uint32_t x116;
4740     uint32_t x117;
4741     uint32_t x118;
4742     uint32_t x119;
4743     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x120;
4744     uint32_t x121;
4745     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x122;
4746     uint32_t x123;
4747     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x124;
4748     uint32_t x125;
4749     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x126;
4750     uint32_t x127;
4751     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x128;
4752     uint32_t x129;
4753     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x130;
4754     uint32_t x131;
4755     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x132;
4756     uint32_t x133;
4757     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x134;
4758     uint32_t x135;
4759     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x136;
4760     uint32_t x137;
4761     uint32_t x138;
4762     uint32_t x139;
4763     uint32_t x140;
4764     uint32_t x141;
4765     uint32_t x142;
4766     uint32_t x143;
4767     uint32_t x144;
4768     uint32_t x145;
4769     uint32_t x146;
4770     uint32_t x147;
4771     uint32_t x148;
4772     uint32_t x149;
4773     uint32_t x150;
4774     uint32_t x151;
4775     uint32_t x152;
4776     uint32_t x153;
4777     uint32_t x154;
4778     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x155;
4779     uint32_t x156;
4780     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x157;
4781     uint32_t x158;
4782     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x159;
4783     uint32_t x160;
4784     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x161;
4785     uint32_t x162;
4786     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x163;
4787     uint32_t x164;
4788     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x165;
4789     uint32_t x166;
4790     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x167;
4791     uint32_t x168;
4792     uint32_t x169;
4793     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x170;
4794     uint32_t x171;
4795     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x172;
4796     uint32_t x173;
4797     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x174;
4798     uint32_t x175;
4799     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x176;
4800     uint32_t x177;
4801     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x178;
4802     uint32_t x179;
4803     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x180;
4804     uint32_t x181;
4805     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x182;
4806     uint32_t x183;
4807     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x184;
4808     uint32_t x185;
4809     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x186;
4810     uint32_t x187;
4811     uint32_t x188;
4812     uint32_t x189;
4813     uint32_t x190;
4814     uint32_t x191;
4815     uint32_t x192;
4816     uint32_t x193;
4817     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x194;
4818     uint32_t x195;
4819     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x196;
4820     uint32_t x197;
4821     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x198;
4822     uint32_t x199;
4823     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x200;
4824     uint32_t x201;
4825     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x202;
4826     uint32_t x203;
4827     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x204;
4828     uint32_t x205;
4829     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x206;
4830     uint32_t x207;
4831     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x208;
4832     uint32_t x209;
4833     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x210;
4834     uint32_t x211;
4835     uint32_t x212;
4836     uint32_t x213;
4837     uint32_t x214;
4838     uint32_t x215;
4839     uint32_t x216;
4840     uint32_t x217;
4841     uint32_t x218;
4842     uint32_t x219;
4843     uint32_t x220;
4844     uint32_t x221;
4845     uint32_t x222;
4846     uint32_t x223;
4847     uint32_t x224;
4848     uint32_t x225;
4849     uint32_t x226;
4850     uint32_t x227;
4851     uint32_t x228;
4852     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x229;
4853     uint32_t x230;
4854     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x231;
4855     uint32_t x232;
4856     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x233;
4857     uint32_t x234;
4858     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x235;
4859     uint32_t x236;
4860     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x237;
4861     uint32_t x238;
4862     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x239;
4863     uint32_t x240;
4864     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x241;
4865     uint32_t x242;
4866     uint32_t x243;
4867     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x244;
4868     uint32_t x245;
4869     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x246;
4870     uint32_t x247;
4871     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x248;
4872     uint32_t x249;
4873     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x250;
4874     uint32_t x251;
4875     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x252;
4876     uint32_t x253;
4877     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x254;
4878     uint32_t x255;
4879     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x256;
4880     uint32_t x257;
4881     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x258;
4882     uint32_t x259;
4883     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x260;
4884     uint32_t x261;
4885     uint32_t x262;
4886     uint32_t x263;
4887     uint32_t x264;
4888     uint32_t x265;
4889     uint32_t x266;
4890     uint32_t x267;
4891     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x268;
4892     uint32_t x269;
4893     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x270;
4894     uint32_t x271;
4895     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x272;
4896     uint32_t x273;
4897     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x274;
4898     uint32_t x275;
4899     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x276;
4900     uint32_t x277;
4901     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x278;
4902     uint32_t x279;
4903     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x280;
4904     uint32_t x281;
4905     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x282;
4906     uint32_t x283;
4907     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x284;
4908     uint32_t x285;
4909     uint32_t x286;
4910     uint32_t x287;
4911     uint32_t x288;
4912     uint32_t x289;
4913     uint32_t x290;
4914     uint32_t x291;
4915     uint32_t x292;
4916     uint32_t x293;
4917     uint32_t x294;
4918     uint32_t x295;
4919     uint32_t x296;
4920     uint32_t x297;
4921     uint32_t x298;
4922     uint32_t x299;
4923     uint32_t x300;
4924     uint32_t x301;
4925     uint32_t x302;
4926     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x303;
4927     uint32_t x304;
4928     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x305;
4929     uint32_t x306;
4930     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x307;
4931     uint32_t x308;
4932     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x309;
4933     uint32_t x310;
4934     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x311;
4935     uint32_t x312;
4936     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x313;
4937     uint32_t x314;
4938     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x315;
4939     uint32_t x316;
4940     uint32_t x317;
4941     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x318;
4942     uint32_t x319;
4943     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x320;
4944     uint32_t x321;
4945     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x322;
4946     uint32_t x323;
4947     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x324;
4948     uint32_t x325;
4949     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x326;
4950     uint32_t x327;
4951     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x328;
4952     uint32_t x329;
4953     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x330;
4954     uint32_t x331;
4955     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x332;
4956     uint32_t x333;
4957     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x334;
4958     uint32_t x335;
4959     uint32_t x336;
4960     uint32_t x337;
4961     uint32_t x338;
4962     uint32_t x339;
4963     uint32_t x340;
4964     uint32_t x341;
4965     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x342;
4966     uint32_t x343;
4967     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x344;
4968     uint32_t x345;
4969     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x346;
4970     uint32_t x347;
4971     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x348;
4972     uint32_t x349;
4973     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x350;
4974     uint32_t x351;
4975     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x352;
4976     uint32_t x353;
4977     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x354;
4978     uint32_t x355;
4979     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x356;
4980     uint32_t x357;
4981     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x358;
4982     uint32_t x359;
4983     uint32_t x360;
4984     uint32_t x361;
4985     uint32_t x362;
4986     uint32_t x363;
4987     uint32_t x364;
4988     uint32_t x365;
4989     uint32_t x366;
4990     uint32_t x367;
4991     uint32_t x368;
4992     uint32_t x369;
4993     uint32_t x370;
4994     uint32_t x371;
4995     uint32_t x372;
4996     uint32_t x373;
4997     uint32_t x374;
4998     uint32_t x375;
4999     uint32_t x376;
5000     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x377;
5001     uint32_t x378;
5002     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x379;
5003     uint32_t x380;
5004     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x381;
5005     uint32_t x382;
5006     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x383;
5007     uint32_t x384;
5008     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x385;
5009     uint32_t x386;
5010     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x387;
5011     uint32_t x388;
5012     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x389;
5013     uint32_t x390;
5014     uint32_t x391;
5015     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x392;
5016     uint32_t x393;
5017     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x394;
5018     uint32_t x395;
5019     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x396;
5020     uint32_t x397;
5021     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x398;
5022     uint32_t x399;
5023     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x400;
5024     uint32_t x401;
5025     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x402;
5026     uint32_t x403;
5027     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x404;
5028     uint32_t x405;
5029     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x406;
5030     uint32_t x407;
5031     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x408;
5032     uint32_t x409;
5033     uint32_t x410;
5034     uint32_t x411;
5035     uint32_t x412;
5036     uint32_t x413;
5037     uint32_t x414;
5038     uint32_t x415;
5039     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x416;
5040     uint32_t x417;
5041     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x418;
5042     uint32_t x419;
5043     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x420;
5044     uint32_t x421;
5045     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x422;
5046     uint32_t x423;
5047     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x424;
5048     uint32_t x425;
5049     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x426;
5050     uint32_t x427;
5051     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x428;
5052     uint32_t x429;
5053     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x430;
5054     uint32_t x431;
5055     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x432;
5056     uint32_t x433;
5057     uint32_t x434;
5058     uint32_t x435;
5059     uint32_t x436;
5060     uint32_t x437;
5061     uint32_t x438;
5062     uint32_t x439;
5063     uint32_t x440;
5064     uint32_t x441;
5065     uint32_t x442;
5066     uint32_t x443;
5067     uint32_t x444;
5068     uint32_t x445;
5069     uint32_t x446;
5070     uint32_t x447;
5071     uint32_t x448;
5072     uint32_t x449;
5073     uint32_t x450;
5074     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x451;
5075     uint32_t x452;
5076     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x453;
5077     uint32_t x454;
5078     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x455;
5079     uint32_t x456;
5080     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x457;
5081     uint32_t x458;
5082     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x459;
5083     uint32_t x460;
5084     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x461;
5085     uint32_t x462;
5086     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x463;
5087     uint32_t x464;
5088     uint32_t x465;
5089     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x466;
5090     uint32_t x467;
5091     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x468;
5092     uint32_t x469;
5093     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x470;
5094     uint32_t x471;
5095     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x472;
5096     uint32_t x473;
5097     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x474;
5098     uint32_t x475;
5099     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x476;
5100     uint32_t x477;
5101     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x478;
5102     uint32_t x479;
5103     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x480;
5104     uint32_t x481;
5105     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x482;
5106     uint32_t x483;
5107     uint32_t x484;
5108     uint32_t x485;
5109     uint32_t x486;
5110     uint32_t x487;
5111     uint32_t x488;
5112     uint32_t x489;
5113     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x490;
5114     uint32_t x491;
5115     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x492;
5116     uint32_t x493;
5117     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x494;
5118     uint32_t x495;
5119     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x496;
5120     uint32_t x497;
5121     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x498;
5122     uint32_t x499;
5123     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x500;
5124     uint32_t x501;
5125     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x502;
5126     uint32_t x503;
5127     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x504;
5128     uint32_t x505;
5129     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x506;
5130     uint32_t x507;
5131     uint32_t x508;
5132     uint32_t x509;
5133     uint32_t x510;
5134     uint32_t x511;
5135     uint32_t x512;
5136     uint32_t x513;
5137     uint32_t x514;
5138     uint32_t x515;
5139     uint32_t x516;
5140     uint32_t x517;
5141     uint32_t x518;
5142     uint32_t x519;
5143     uint32_t x520;
5144     uint32_t x521;
5145     uint32_t x522;
5146     uint32_t x523;
5147     uint32_t x524;
5148     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x525;
5149     uint32_t x526;
5150     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x527;
5151     uint32_t x528;
5152     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x529;
5153     uint32_t x530;
5154     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x531;
5155     uint32_t x532;
5156     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x533;
5157     uint32_t x534;
5158     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x535;
5159     uint32_t x536;
5160     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x537;
5161     uint32_t x538;
5162     uint32_t x539;
5163     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x540;
5164     uint32_t x541;
5165     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x542;
5166     uint32_t x543;
5167     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x544;
5168     uint32_t x545;
5169     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x546;
5170     uint32_t x547;
5171     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x548;
5172     uint32_t x549;
5173     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x550;
5174     uint32_t x551;
5175     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x552;
5176     uint32_t x553;
5177     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x554;
5178     uint32_t x555;
5179     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x556;
5180     uint32_t x557;
5181     uint32_t x558;
5182     uint32_t x559;
5183     uint32_t x560;
5184     uint32_t x561;
5185     uint32_t x562;
5186     uint32_t x563;
5187     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x564;
5188     uint32_t x565;
5189     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x566;
5190     uint32_t x567;
5191     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x568;
5192     uint32_t x569;
5193     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x570;
5194     uint32_t x571;
5195     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x572;
5196     uint32_t x573;
5197     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x574;
5198     uint32_t x575;
5199     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x576;
5200     uint32_t x577;
5201     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x578;
5202     uint32_t x579;
5203     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x580;
5204     uint32_t x581;
5205     uint32_t x582;
5206     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x583;
5207     uint32_t x584;
5208     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x585;
5209     uint32_t x586;
5210     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x587;
5211     uint32_t x588;
5212     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x589;
5213     uint32_t x590;
5214     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x591;
5215     uint32_t x592;
5216     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x593;
5217     uint32_t x594;
5218     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x595;
5219     uint32_t x596;
5220     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x597;
5221     uint32_t x598;
5222     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x599;
5223     uint32_t x600;
5224     uint32_t x601;
5225     uint32_t x602;
5226     uint32_t x603;
5227     uint32_t x604;
5228     uint32_t x605;
5229     uint32_t x606;
5230     uint32_t x607;
5231     x1 = (arg1[1]);
5232     x2 = (arg1[2]);
5233     x3 = (arg1[3]);
5234     x4 = (arg1[4]);
5235     x5 = (arg1[5]);
5236     x6 = (arg1[6]);
5237     x7 = (arg1[7]);
5238     x8 = (arg1[0]);
5239     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x9, &x10, x8,
5240                                                          (arg2[7]));
5241     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x11, &x12, x8,
5242                                                          (arg2[6]));
5243     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x13, &x14, x8,
5244                                                          (arg2[5]));
5245     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x15, &x16, x8,
5246                                                          (arg2[4]));
5247     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x17, &x18, x8,
5248                                                          (arg2[3]));
5249     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x19, &x20, x8,
5250                                                          (arg2[2]));
5251     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x21, &x22, x8,
5252                                                          (arg2[1]));
5253     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x23, &x24, x8,
5254                                                          (arg2[0]));
5255     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x25, &x26, 0x0,
5256                                                               x24, x21);
5257     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x27, &x28, x26,
5258                                                               x22, x19);
5259     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x29, &x30, x28,
5260                                                               x20, x17);
5261     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x31, &x32, x30,
5262                                                               x18, x15);
5263     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x33, &x34, x32,
5264                                                               x16, x13);
5265     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x35, &x36, x34,
5266                                                               x14, x11);
5267     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x37, &x38, x36,
5268                                                               x12, x9);
5269     x39 = (x38 + x10);
5270     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x40, &x41, x23,
5271                                                          UINT32_C(0xa3347857));
5272     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x42, &x43, x40,
5273                                                          UINT32_C(0x80000000));
5274     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x44, &x45, x40,
5275                                                          UINT16_C(0xc99));
5276     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x46, &x47, 0x0,
5277                                                               x23, x44);
5278     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x48, &x49, x47,
5279                                                               x25, x45);
5280     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x50, &x51, x49,
5281                                                               x27, 0x0);
5282     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x52, &x53, x51,
5283                                                               x29, 0x0);
5284     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x54, &x55, x53,
5285                                                               x31, 0x0);
5286     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x56, &x57, x55,
5287                                                               x33, 0x0);
5288     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x58, &x59, x57,
5289                                                               x35, 0x0);
5290     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x60, &x61, x59,
5291                                                               x37, x42);
5292     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x62, &x63, x61,
5293                                                               x39, x43);
5294     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x64, &x65, x1,
5295                                                          (arg2[7]));
5296     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x66, &x67, x1,
5297                                                          (arg2[6]));
5298     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x68, &x69, x1,
5299                                                          (arg2[5]));
5300     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x70, &x71, x1,
5301                                                          (arg2[4]));
5302     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x72, &x73, x1,
5303                                                          (arg2[3]));
5304     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x74, &x75, x1,
5305                                                          (arg2[2]));
5306     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x76, &x77, x1,
5307                                                          (arg2[1]));
5308     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x78, &x79, x1,
5309                                                          (arg2[0]));
5310     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x80, &x81, 0x0,
5311                                                               x79, x76);
5312     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x82, &x83, x81,
5313                                                               x77, x74);
5314     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x84, &x85, x83,
5315                                                               x75, x72);
5316     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x86, &x87, x85,
5317                                                               x73, x70);
5318     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x88, &x89, x87,
5319                                                               x71, x68);
5320     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x90, &x91, x89,
5321                                                               x69, x66);
5322     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x92, &x93, x91,
5323                                                               x67, x64);
5324     x94 = (x93 + x65);
5325     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x95, &x96, 0x0,
5326                                                               x48, x78);
5327     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x97, &x98, x96,
5328                                                               x50, x80);
5329     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x99, &x100, x98,
5330                                                               x52, x82);
5331     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x101, &x102,
5332                                                               x100, x54, x84);
5333     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x103, &x104,
5334                                                               x102, x56, x86);
5335     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x105, &x106,
5336                                                               x104, x58, x88);
5337     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x107, &x108,
5338                                                               x106, x60, x90);
5339     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x109, &x110,
5340                                                               x108, x62, x92);
5341     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x111, &x112,
5342                                                               x110, x63, x94);
5343     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x113, &x114, x95,
5344                                                          UINT32_C(0xa3347857));
5345     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x115, &x116, x113,
5346                                                          UINT32_C(0x80000000));
5347     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x117, &x118, x113,
5348                                                          UINT16_C(0xc99));
5349     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x119, &x120, 0x0,
5350                                                               x95, x117);
5351     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x121, &x122,
5352                                                               x120, x97, x118);
5353     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x123, &x124,
5354                                                               x122, x99, 0x0);
5355     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x125, &x126,
5356                                                               x124, x101, 0x0);
5357     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x127, &x128,
5358                                                               x126, x103, 0x0);
5359     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x129, &x130,
5360                                                               x128, x105, 0x0);
5361     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x131, &x132,
5362                                                               x130, x107, 0x0);
5363     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x133, &x134,
5364                                                               x132, x109, x115);
5365     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x135, &x136,
5366                                                               x134, x111, x116);
5367     x137 = ((uint32_t)x136 + x112);
5368     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x138, &x139, x2,
5369                                                          (arg2[7]));
5370     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x140, &x141, x2,
5371                                                          (arg2[6]));
5372     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x142, &x143, x2,
5373                                                          (arg2[5]));
5374     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x144, &x145, x2,
5375                                                          (arg2[4]));
5376     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x146, &x147, x2,
5377                                                          (arg2[3]));
5378     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x148, &x149, x2,
5379                                                          (arg2[2]));
5380     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x150, &x151, x2,
5381                                                          (arg2[1]));
5382     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x152, &x153, x2,
5383                                                          (arg2[0]));
5384     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x154, &x155, 0x0,
5385                                                               x153, x150);
5386     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x156, &x157,
5387                                                               x155, x151, x148);
5388     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x158, &x159,
5389                                                               x157, x149, x146);
5390     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x160, &x161,
5391                                                               x159, x147, x144);
5392     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x162, &x163,
5393                                                               x161, x145, x142);
5394     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x164, &x165,
5395                                                               x163, x143, x140);
5396     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x166, &x167,
5397                                                               x165, x141, x138);
5398     x168 = (x167 + x139);
5399     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x169, &x170, 0x0,
5400                                                               x121, x152);
5401     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x171, &x172,
5402                                                               x170, x123, x154);
5403     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x173, &x174,
5404                                                               x172, x125, x156);
5405     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x175, &x176,
5406                                                               x174, x127, x158);
5407     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x177, &x178,
5408                                                               x176, x129, x160);
5409     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x179, &x180,
5410                                                               x178, x131, x162);
5411     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x181, &x182,
5412                                                               x180, x133, x164);
5413     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x183, &x184,
5414                                                               x182, x135, x166);
5415     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x185, &x186,
5416                                                               x184, x137, x168);
5417     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x187, &x188, x169,
5418                                                          UINT32_C(0xa3347857));
5419     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x189, &x190, x187,
5420                                                          UINT32_C(0x80000000));
5421     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x191, &x192, x187,
5422                                                          UINT16_C(0xc99));
5423     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x193, &x194, 0x0,
5424                                                               x169, x191);
5425     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x195, &x196,
5426                                                               x194, x171, x192);
5427     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x197, &x198,
5428                                                               x196, x173, 0x0);
5429     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x199, &x200,
5430                                                               x198, x175, 0x0);
5431     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x201, &x202,
5432                                                               x200, x177, 0x0);
5433     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x203, &x204,
5434                                                               x202, x179, 0x0);
5435     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x205, &x206,
5436                                                               x204, x181, 0x0);
5437     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x207, &x208,
5438                                                               x206, x183, x189);
5439     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x209, &x210,
5440                                                               x208, x185, x190);
5441     x211 = ((uint32_t)x210 + x186);
5442     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x212, &x213, x3,
5443                                                          (arg2[7]));
5444     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x214, &x215, x3,
5445                                                          (arg2[6]));
5446     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x216, &x217, x3,
5447                                                          (arg2[5]));
5448     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x218, &x219, x3,
5449                                                          (arg2[4]));
5450     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x220, &x221, x3,
5451                                                          (arg2[3]));
5452     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x222, &x223, x3,
5453                                                          (arg2[2]));
5454     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x224, &x225, x3,
5455                                                          (arg2[1]));
5456     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x226, &x227, x3,
5457                                                          (arg2[0]));
5458     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x228, &x229, 0x0,
5459                                                               x227, x224);
5460     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x230, &x231,
5461                                                               x229, x225, x222);
5462     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x232, &x233,
5463                                                               x231, x223, x220);
5464     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x234, &x235,
5465                                                               x233, x221, x218);
5466     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x236, &x237,
5467                                                               x235, x219, x216);
5468     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x238, &x239,
5469                                                               x237, x217, x214);
5470     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x240, &x241,
5471                                                               x239, x215, x212);
5472     x242 = (x241 + x213);
5473     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x243, &x244, 0x0,
5474                                                               x195, x226);
5475     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x245, &x246,
5476                                                               x244, x197, x228);
5477     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x247, &x248,
5478                                                               x246, x199, x230);
5479     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x249, &x250,
5480                                                               x248, x201, x232);
5481     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x251, &x252,
5482                                                               x250, x203, x234);
5483     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x253, &x254,
5484                                                               x252, x205, x236);
5485     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x255, &x256,
5486                                                               x254, x207, x238);
5487     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x257, &x258,
5488                                                               x256, x209, x240);
5489     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x259, &x260,
5490                                                               x258, x211, x242);
5491     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x261, &x262, x243,
5492                                                          UINT32_C(0xa3347857));
5493     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x263, &x264, x261,
5494                                                          UINT32_C(0x80000000));
5495     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x265, &x266, x261,
5496                                                          UINT16_C(0xc99));
5497     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x267, &x268, 0x0,
5498                                                               x243, x265);
5499     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x269, &x270,
5500                                                               x268, x245, x266);
5501     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x271, &x272,
5502                                                               x270, x247, 0x0);
5503     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x273, &x274,
5504                                                               x272, x249, 0x0);
5505     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x275, &x276,
5506                                                               x274, x251, 0x0);
5507     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x277, &x278,
5508                                                               x276, x253, 0x0);
5509     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x279, &x280,
5510                                                               x278, x255, 0x0);
5511     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x281, &x282,
5512                                                               x280, x257, x263);
5513     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x283, &x284,
5514                                                               x282, x259, x264);
5515     x285 = ((uint32_t)x284 + x260);
5516     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x286, &x287, x4,
5517                                                          (arg2[7]));
5518     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x288, &x289, x4,
5519                                                          (arg2[6]));
5520     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x290, &x291, x4,
5521                                                          (arg2[5]));
5522     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x292, &x293, x4,
5523                                                          (arg2[4]));
5524     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x294, &x295, x4,
5525                                                          (arg2[3]));
5526     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x296, &x297, x4,
5527                                                          (arg2[2]));
5528     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x298, &x299, x4,
5529                                                          (arg2[1]));
5530     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x300, &x301, x4,
5531                                                          (arg2[0]));
5532     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x302, &x303, 0x0,
5533                                                               x301, x298);
5534     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x304, &x305,
5535                                                               x303, x299, x296);
5536     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x306, &x307,
5537                                                               x305, x297, x294);
5538     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x308, &x309,
5539                                                               x307, x295, x292);
5540     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x310, &x311,
5541                                                               x309, x293, x290);
5542     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x312, &x313,
5543                                                               x311, x291, x288);
5544     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x314, &x315,
5545                                                               x313, x289, x286);
5546     x316 = (x315 + x287);
5547     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x317, &x318, 0x0,
5548                                                               x269, x300);
5549     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x319, &x320,
5550                                                               x318, x271, x302);
5551     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x321, &x322,
5552                                                               x320, x273, x304);
5553     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x323, &x324,
5554                                                               x322, x275, x306);
5555     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x325, &x326,
5556                                                               x324, x277, x308);
5557     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x327, &x328,
5558                                                               x326, x279, x310);
5559     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x329, &x330,
5560                                                               x328, x281, x312);
5561     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x331, &x332,
5562                                                               x330, x283, x314);
5563     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x333, &x334,
5564                                                               x332, x285, x316);
5565     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x335, &x336, x317,
5566                                                          UINT32_C(0xa3347857));
5567     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x337, &x338, x335,
5568                                                          UINT32_C(0x80000000));
5569     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x339, &x340, x335,
5570                                                          UINT16_C(0xc99));
5571     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x341, &x342, 0x0,
5572                                                               x317, x339);
5573     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x343, &x344,
5574                                                               x342, x319, x340);
5575     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x345, &x346,
5576                                                               x344, x321, 0x0);
5577     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x347, &x348,
5578                                                               x346, x323, 0x0);
5579     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x349, &x350,
5580                                                               x348, x325, 0x0);
5581     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x351, &x352,
5582                                                               x350, x327, 0x0);
5583     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x353, &x354,
5584                                                               x352, x329, 0x0);
5585     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x355, &x356,
5586                                                               x354, x331, x337);
5587     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x357, &x358,
5588                                                               x356, x333, x338);
5589     x359 = ((uint32_t)x358 + x334);
5590     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x360, &x361, x5,
5591                                                          (arg2[7]));
5592     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x362, &x363, x5,
5593                                                          (arg2[6]));
5594     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x364, &x365, x5,
5595                                                          (arg2[5]));
5596     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x366, &x367, x5,
5597                                                          (arg2[4]));
5598     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x368, &x369, x5,
5599                                                          (arg2[3]));
5600     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x370, &x371, x5,
5601                                                          (arg2[2]));
5602     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x372, &x373, x5,
5603                                                          (arg2[1]));
5604     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x374, &x375, x5,
5605                                                          (arg2[0]));
5606     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x376, &x377, 0x0,
5607                                                               x375, x372);
5608     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x378, &x379,
5609                                                               x377, x373, x370);
5610     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x380, &x381,
5611                                                               x379, x371, x368);
5612     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x382, &x383,
5613                                                               x381, x369, x366);
5614     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x384, &x385,
5615                                                               x383, x367, x364);
5616     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x386, &x387,
5617                                                               x385, x365, x362);
5618     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x388, &x389,
5619                                                               x387, x363, x360);
5620     x390 = (x389 + x361);
5621     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x391, &x392, 0x0,
5622                                                               x343, x374);
5623     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x393, &x394,
5624                                                               x392, x345, x376);
5625     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x395, &x396,
5626                                                               x394, x347, x378);
5627     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x397, &x398,
5628                                                               x396, x349, x380);
5629     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x399, &x400,
5630                                                               x398, x351, x382);
5631     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x401, &x402,
5632                                                               x400, x353, x384);
5633     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x403, &x404,
5634                                                               x402, x355, x386);
5635     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x405, &x406,
5636                                                               x404, x357, x388);
5637     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x407, &x408,
5638                                                               x406, x359, x390);
5639     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x409, &x410, x391,
5640                                                          UINT32_C(0xa3347857));
5641     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x411, &x412, x409,
5642                                                          UINT32_C(0x80000000));
5643     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x413, &x414, x409,
5644                                                          UINT16_C(0xc99));
5645     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x415, &x416, 0x0,
5646                                                               x391, x413);
5647     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x417, &x418,
5648                                                               x416, x393, x414);
5649     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x419, &x420,
5650                                                               x418, x395, 0x0);
5651     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x421, &x422,
5652                                                               x420, x397, 0x0);
5653     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x423, &x424,
5654                                                               x422, x399, 0x0);
5655     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x425, &x426,
5656                                                               x424, x401, 0x0);
5657     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x427, &x428,
5658                                                               x426, x403, 0x0);
5659     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x429, &x430,
5660                                                               x428, x405, x411);
5661     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x431, &x432,
5662                                                               x430, x407, x412);
5663     x433 = ((uint32_t)x432 + x408);
5664     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x434, &x435, x6,
5665                                                          (arg2[7]));
5666     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x436, &x437, x6,
5667                                                          (arg2[6]));
5668     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x438, &x439, x6,
5669                                                          (arg2[5]));
5670     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x440, &x441, x6,
5671                                                          (arg2[4]));
5672     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x442, &x443, x6,
5673                                                          (arg2[3]));
5674     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x444, &x445, x6,
5675                                                          (arg2[2]));
5676     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x446, &x447, x6,
5677                                                          (arg2[1]));
5678     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x448, &x449, x6,
5679                                                          (arg2[0]));
5680     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x450, &x451, 0x0,
5681                                                               x449, x446);
5682     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x452, &x453,
5683                                                               x451, x447, x444);
5684     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x454, &x455,
5685                                                               x453, x445, x442);
5686     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x456, &x457,
5687                                                               x455, x443, x440);
5688     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x458, &x459,
5689                                                               x457, x441, x438);
5690     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x460, &x461,
5691                                                               x459, x439, x436);
5692     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x462, &x463,
5693                                                               x461, x437, x434);
5694     x464 = (x463 + x435);
5695     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x465, &x466, 0x0,
5696                                                               x417, x448);
5697     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x467, &x468,
5698                                                               x466, x419, x450);
5699     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x469, &x470,
5700                                                               x468, x421, x452);
5701     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x471, &x472,
5702                                                               x470, x423, x454);
5703     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x473, &x474,
5704                                                               x472, x425, x456);
5705     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x475, &x476,
5706                                                               x474, x427, x458);
5707     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x477, &x478,
5708                                                               x476, x429, x460);
5709     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x479, &x480,
5710                                                               x478, x431, x462);
5711     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x481, &x482,
5712                                                               x480, x433, x464);
5713     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x483, &x484, x465,
5714                                                          UINT32_C(0xa3347857));
5715     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x485, &x486, x483,
5716                                                          UINT32_C(0x80000000));
5717     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x487, &x488, x483,
5718                                                          UINT16_C(0xc99));
5719     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x489, &x490, 0x0,
5720                                                               x465, x487);
5721     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x491, &x492,
5722                                                               x490, x467, x488);
5723     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x493, &x494,
5724                                                               x492, x469, 0x0);
5725     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x495, &x496,
5726                                                               x494, x471, 0x0);
5727     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x497, &x498,
5728                                                               x496, x473, 0x0);
5729     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x499, &x500,
5730                                                               x498, x475, 0x0);
5731     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x501, &x502,
5732                                                               x500, x477, 0x0);
5733     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x503, &x504,
5734                                                               x502, x479, x485);
5735     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x505, &x506,
5736                                                               x504, x481, x486);
5737     x507 = ((uint32_t)x506 + x482);
5738     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x508, &x509, x7,
5739                                                          (arg2[7]));
5740     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x510, &x511, x7,
5741                                                          (arg2[6]));
5742     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x512, &x513, x7,
5743                                                          (arg2[5]));
5744     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x514, &x515, x7,
5745                                                          (arg2[4]));
5746     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x516, &x517, x7,
5747                                                          (arg2[3]));
5748     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x518, &x519, x7,
5749                                                          (arg2[2]));
5750     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x520, &x521, x7,
5751                                                          (arg2[1]));
5752     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x522, &x523, x7,
5753                                                          (arg2[0]));
5754     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x524, &x525, 0x0,
5755                                                               x523, x520);
5756     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x526, &x527,
5757                                                               x525, x521, x518);
5758     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x528, &x529,
5759                                                               x527, x519, x516);
5760     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x530, &x531,
5761                                                               x529, x517, x514);
5762     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x532, &x533,
5763                                                               x531, x515, x512);
5764     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x534, &x535,
5765                                                               x533, x513, x510);
5766     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x536, &x537,
5767                                                               x535, x511, x508);
5768     x538 = (x537 + x509);
5769     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x539, &x540, 0x0,
5770                                                               x491, x522);
5771     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x541, &x542,
5772                                                               x540, x493, x524);
5773     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x543, &x544,
5774                                                               x542, x495, x526);
5775     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x545, &x546,
5776                                                               x544, x497, x528);
5777     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x547, &x548,
5778                                                               x546, x499, x530);
5779     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x549, &x550,
5780                                                               x548, x501, x532);
5781     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x551, &x552,
5782                                                               x550, x503, x534);
5783     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x553, &x554,
5784                                                               x552, x505, x536);
5785     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x555, &x556,
5786                                                               x554, x507, x538);
5787     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x557, &x558, x539,
5788                                                          UINT32_C(0xa3347857));
5789     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x559, &x560, x557,
5790                                                          UINT32_C(0x80000000));
5791     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x561, &x562, x557,
5792                                                          UINT16_C(0xc99));
5793     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x563, &x564, 0x0,
5794                                                               x539, x561);
5795     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x565, &x566,
5796                                                               x564, x541, x562);
5797     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x567, &x568,
5798                                                               x566, x543, 0x0);
5799     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x569, &x570,
5800                                                               x568, x545, 0x0);
5801     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x571, &x572,
5802                                                               x570, x547, 0x0);
5803     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x573, &x574,
5804                                                               x572, x549, 0x0);
5805     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x575, &x576,
5806                                                               x574, x551, 0x0);
5807     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x577, &x578,
5808                                                               x576, x553, x559);
5809     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x579, &x580,
5810                                                               x578, x555, x560);
5811     x581 = ((uint32_t)x580 + x556);
5812     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
5813         &x582, &x583, 0x0, x565, UINT16_C(0xc99));
5814     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x584, &x585,
5815                                                                x583, x567, 0x0);
5816     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x586, &x587,
5817                                                                x585, x569, 0x0);
5818     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x588, &x589,
5819                                                                x587, x571, 0x0);
5820     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x590, &x591,
5821                                                                x589, x573, 0x0);
5822     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x592, &x593,
5823                                                                x591, x575, 0x0);
5824     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x594, &x595,
5825                                                                x593, x577, 0x0);
5826     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
5827         &x596, &x597, x595, x579, UINT32_C(0x80000000));
5828     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x598, &x599,
5829                                                                x597, x581, 0x0);
5830     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x600, x599, x582,
5831                                                             x565);
5832     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x601, x599, x584,
5833                                                             x567);
5834     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x602, x599, x586,
5835                                                             x569);
5836     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x603, x599, x588,
5837                                                             x571);
5838     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x604, x599, x590,
5839                                                             x573);
5840     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x605, x599, x592,
5841                                                             x575);
5842     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x606, x599, x594,
5843                                                             x577);
5844     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x607, x599, x596,
5845                                                             x579);
5846     out1[0] = x600;
5847     out1[1] = x601;
5848     out1[2] = x602;
5849     out1[3] = x603;
5850     out1[4] = x604;
5851     out1[5] = x605;
5852     out1[6] = x606;
5853     out1[7] = x607;
5854 }
5855
5856 /*
5857  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square squares a field element in the Montgomery domain.
5858  * Preconditions:
5859  *   0 ≤ eval arg1 < m
5860  * Postconditions:
5861  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) * eval (from_montgomery arg1)) mod m
5862  *   0 ≤ eval out1 < m
5863  *
5864  * Input Bounds:
5865  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
5866  * Output Bounds:
5867  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
5868  */
5869 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(
5870     uint32_t out1[8], const uint32_t arg1[8]) {
5871     uint32_t x1;
5872     uint32_t x2;
5873     uint32_t x3;
5874     uint32_t x4;
5875     uint32_t x5;
5876     uint32_t x6;
5877     uint32_t x7;
5878     uint32_t x8;
5879     uint32_t x9;
5880     uint32_t x10;
5881     uint32_t x11;
5882     uint32_t x12;
5883     uint32_t x13;
5884     uint32_t x14;
5885     uint32_t x15;
5886     uint32_t x16;
5887     uint32_t x17;
5888     uint32_t x18;
5889     uint32_t x19;
5890     uint32_t x20;
5891     uint32_t x21;
5892     uint32_t x22;
5893     uint32_t x23;
5894     uint32_t x24;
5895     uint32_t x25;
5896     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x26;
5897     uint32_t x27;
5898     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x28;
5899     uint32_t x29;
5900     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x30;
5901     uint32_t x31;
5902     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x32;
5903     uint32_t x33;
5904     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x34;
5905     uint32_t x35;
5906     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x36;
5907     uint32_t x37;
5908     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x38;
5909     uint32_t x39;
5910     uint32_t x40;
5911     uint32_t x41;
5912     uint32_t x42;
5913     uint32_t x43;
5914     uint32_t x44;
5915     uint32_t x45;
5916     uint32_t x46;
5917     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x47;
5918     uint32_t x48;
5919     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x49;
5920     uint32_t x50;
5921     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x51;
5922     uint32_t x52;
5923     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x53;
5924     uint32_t x54;
5925     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x55;
5926     uint32_t x56;
5927     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x57;
5928     uint32_t x58;
5929     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x59;
5930     uint32_t x60;
5931     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x61;
5932     uint32_t x62;
5933     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x63;
5934     uint32_t x64;
5935     uint32_t x65;
5936     uint32_t x66;
5937     uint32_t x67;
5938     uint32_t x68;
5939     uint32_t x69;
5940     uint32_t x70;
5941     uint32_t x71;
5942     uint32_t x72;
5943     uint32_t x73;
5944     uint32_t x74;
5945     uint32_t x75;
5946     uint32_t x76;
5947     uint32_t x77;
5948     uint32_t x78;
5949     uint32_t x79;
5950     uint32_t x80;
5951     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x81;
5952     uint32_t x82;
5953     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x83;
5954     uint32_t x84;
5955     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x85;
5956     uint32_t x86;
5957     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x87;
5958     uint32_t x88;
5959     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x89;
5960     uint32_t x90;
5961     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x91;
5962     uint32_t x92;
5963     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x93;
5964     uint32_t x94;
5965     uint32_t x95;
5966     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x96;
5967     uint32_t x97;
5968     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x98;
5969     uint32_t x99;
5970     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x100;
5971     uint32_t x101;
5972     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x102;
5973     uint32_t x103;
5974     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x104;
5975     uint32_t x105;
5976     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x106;
5977     uint32_t x107;
5978     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x108;
5979     uint32_t x109;
5980     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x110;
5981     uint32_t x111;
5982     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x112;
5983     uint32_t x113;
5984     uint32_t x114;
5985     uint32_t x115;
5986     uint32_t x116;
5987     uint32_t x117;
5988     uint32_t x118;
5989     uint32_t x119;
5990     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x120;
5991     uint32_t x121;
5992     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x122;
5993     uint32_t x123;
5994     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x124;
5995     uint32_t x125;
5996     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x126;
5997     uint32_t x127;
5998     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x128;
5999     uint32_t x129;
6000     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x130;
6001     uint32_t x131;
6002     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x132;
6003     uint32_t x133;
6004     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x134;
6005     uint32_t x135;
6006     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x136;
6007     uint32_t x137;
6008     uint32_t x138;
6009     uint32_t x139;
6010     uint32_t x140;
6011     uint32_t x141;
6012     uint32_t x142;
6013     uint32_t x143;
6014     uint32_t x144;
6015     uint32_t x145;
6016     uint32_t x146;
6017     uint32_t x147;
6018     uint32_t x148;
6019     uint32_t x149;
6020     uint32_t x150;
6021     uint32_t x151;
6022     uint32_t x152;
6023     uint32_t x153;
6024     uint32_t x154;
6025     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x155;
6026     uint32_t x156;
6027     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x157;
6028     uint32_t x158;
6029     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x159;
6030     uint32_t x160;
6031     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x161;
6032     uint32_t x162;
6033     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x163;
6034     uint32_t x164;
6035     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x165;
6036     uint32_t x166;
6037     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x167;
6038     uint32_t x168;
6039     uint32_t x169;
6040     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x170;
6041     uint32_t x171;
6042     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x172;
6043     uint32_t x173;
6044     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x174;
6045     uint32_t x175;
6046     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x176;
6047     uint32_t x177;
6048     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x178;
6049     uint32_t x179;
6050     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x180;
6051     uint32_t x181;
6052     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x182;
6053     uint32_t x183;
6054     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x184;
6055     uint32_t x185;
6056     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x186;
6057     uint32_t x187;
6058     uint32_t x188;
6059     uint32_t x189;
6060     uint32_t x190;
6061     uint32_t x191;
6062     uint32_t x192;
6063     uint32_t x193;
6064     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x194;
6065     uint32_t x195;
6066     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x196;
6067     uint32_t x197;
6068     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x198;
6069     uint32_t x199;
6070     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x200;
6071     uint32_t x201;
6072     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x202;
6073     uint32_t x203;
6074     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x204;
6075     uint32_t x205;
6076     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x206;
6077     uint32_t x207;
6078     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x208;
6079     uint32_t x209;
6080     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x210;
6081     uint32_t x211;
6082     uint32_t x212;
6083     uint32_t x213;
6084     uint32_t x214;
6085     uint32_t x215;
6086     uint32_t x216;
6087     uint32_t x217;
6088     uint32_t x218;
6089     uint32_t x219;
6090     uint32_t x220;
6091     uint32_t x221;
6092     uint32_t x222;
6093     uint32_t x223;
6094     uint32_t x224;
6095     uint32_t x225;
6096     uint32_t x226;
6097     uint32_t x227;
6098     uint32_t x228;
6099     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x229;
6100     uint32_t x230;
6101     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x231;
6102     uint32_t x232;
6103     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x233;
6104     uint32_t x234;
6105     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x235;
6106     uint32_t x236;
6107     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x237;
6108     uint32_t x238;
6109     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x239;
6110     uint32_t x240;
6111     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x241;
6112     uint32_t x242;
6113     uint32_t x243;
6114     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x244;
6115     uint32_t x245;
6116     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x246;
6117     uint32_t x247;
6118     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x248;
6119     uint32_t x249;
6120     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x250;
6121     uint32_t x251;
6122     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x252;
6123     uint32_t x253;
6124     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x254;
6125     uint32_t x255;
6126     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x256;
6127     uint32_t x257;
6128     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x258;
6129     uint32_t x259;
6130     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x260;
6131     uint32_t x261;
6132     uint32_t x262;
6133     uint32_t x263;
6134     uint32_t x264;
6135     uint32_t x265;
6136     uint32_t x266;
6137     uint32_t x267;
6138     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x268;
6139     uint32_t x269;
6140     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x270;
6141     uint32_t x271;
6142     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x272;
6143     uint32_t x273;
6144     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x274;
6145     uint32_t x275;
6146     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x276;
6147     uint32_t x277;
6148     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x278;
6149     uint32_t x279;
6150     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x280;
6151     uint32_t x281;
6152     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x282;
6153     uint32_t x283;
6154     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x284;
6155     uint32_t x285;
6156     uint32_t x286;
6157     uint32_t x287;
6158     uint32_t x288;
6159     uint32_t x289;
6160     uint32_t x290;
6161     uint32_t x291;
6162     uint32_t x292;
6163     uint32_t x293;
6164     uint32_t x294;
6165     uint32_t x295;
6166     uint32_t x296;
6167     uint32_t x297;
6168     uint32_t x298;
6169     uint32_t x299;
6170     uint32_t x300;
6171     uint32_t x301;
6172     uint32_t x302;
6173     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x303;
6174     uint32_t x304;
6175     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x305;
6176     uint32_t x306;
6177     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x307;
6178     uint32_t x308;
6179     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x309;
6180     uint32_t x310;
6181     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x311;
6182     uint32_t x312;
6183     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x313;
6184     uint32_t x314;
6185     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x315;
6186     uint32_t x316;
6187     uint32_t x317;
6188     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x318;
6189     uint32_t x319;
6190     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x320;
6191     uint32_t x321;
6192     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x322;
6193     uint32_t x323;
6194     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x324;
6195     uint32_t x325;
6196     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x326;
6197     uint32_t x327;
6198     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x328;
6199     uint32_t x329;
6200     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x330;
6201     uint32_t x331;
6202     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x332;
6203     uint32_t x333;
6204     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x334;
6205     uint32_t x335;
6206     uint32_t x336;
6207     uint32_t x337;
6208     uint32_t x338;
6209     uint32_t x339;
6210     uint32_t x340;
6211     uint32_t x341;
6212     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x342;
6213     uint32_t x343;
6214     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x344;
6215     uint32_t x345;
6216     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x346;
6217     uint32_t x347;
6218     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x348;
6219     uint32_t x349;
6220     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x350;
6221     uint32_t x351;
6222     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x352;
6223     uint32_t x353;
6224     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x354;
6225     uint32_t x355;
6226     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x356;
6227     uint32_t x357;
6228     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x358;
6229     uint32_t x359;
6230     uint32_t x360;
6231     uint32_t x361;
6232     uint32_t x362;
6233     uint32_t x363;
6234     uint32_t x364;
6235     uint32_t x365;
6236     uint32_t x366;
6237     uint32_t x367;
6238     uint32_t x368;
6239     uint32_t x369;
6240     uint32_t x370;
6241     uint32_t x371;
6242     uint32_t x372;
6243     uint32_t x373;
6244     uint32_t x374;
6245     uint32_t x375;
6246     uint32_t x376;
6247     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x377;
6248     uint32_t x378;
6249     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x379;
6250     uint32_t x380;
6251     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x381;
6252     uint32_t x382;
6253     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x383;
6254     uint32_t x384;
6255     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x385;
6256     uint32_t x386;
6257     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x387;
6258     uint32_t x388;
6259     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x389;
6260     uint32_t x390;
6261     uint32_t x391;
6262     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x392;
6263     uint32_t x393;
6264     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x394;
6265     uint32_t x395;
6266     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x396;
6267     uint32_t x397;
6268     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x398;
6269     uint32_t x399;
6270     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x400;
6271     uint32_t x401;
6272     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x402;
6273     uint32_t x403;
6274     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x404;
6275     uint32_t x405;
6276     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x406;
6277     uint32_t x407;
6278     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x408;
6279     uint32_t x409;
6280     uint32_t x410;
6281     uint32_t x411;
6282     uint32_t x412;
6283     uint32_t x413;
6284     uint32_t x414;
6285     uint32_t x415;
6286     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x416;
6287     uint32_t x417;
6288     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x418;
6289     uint32_t x419;
6290     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x420;
6291     uint32_t x421;
6292     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x422;
6293     uint32_t x423;
6294     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x424;
6295     uint32_t x425;
6296     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x426;
6297     uint32_t x427;
6298     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x428;
6299     uint32_t x429;
6300     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x430;
6301     uint32_t x431;
6302     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x432;
6303     uint32_t x433;
6304     uint32_t x434;
6305     uint32_t x435;
6306     uint32_t x436;
6307     uint32_t x437;
6308     uint32_t x438;
6309     uint32_t x439;
6310     uint32_t x440;
6311     uint32_t x441;
6312     uint32_t x442;
6313     uint32_t x443;
6314     uint32_t x444;
6315     uint32_t x445;
6316     uint32_t x446;
6317     uint32_t x447;
6318     uint32_t x448;
6319     uint32_t x449;
6320     uint32_t x450;
6321     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x451;
6322     uint32_t x452;
6323     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x453;
6324     uint32_t x454;
6325     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x455;
6326     uint32_t x456;
6327     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x457;
6328     uint32_t x458;
6329     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x459;
6330     uint32_t x460;
6331     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x461;
6332     uint32_t x462;
6333     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x463;
6334     uint32_t x464;
6335     uint32_t x465;
6336     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x466;
6337     uint32_t x467;
6338     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x468;
6339     uint32_t x469;
6340     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x470;
6341     uint32_t x471;
6342     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x472;
6343     uint32_t x473;
6344     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x474;
6345     uint32_t x475;
6346     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x476;
6347     uint32_t x477;
6348     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x478;
6349     uint32_t x479;
6350     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x480;
6351     uint32_t x481;
6352     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x482;
6353     uint32_t x483;
6354     uint32_t x484;
6355     uint32_t x485;
6356     uint32_t x486;
6357     uint32_t x487;
6358     uint32_t x488;
6359     uint32_t x489;
6360     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x490;
6361     uint32_t x491;
6362     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x492;
6363     uint32_t x493;
6364     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x494;
6365     uint32_t x495;
6366     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x496;
6367     uint32_t x497;
6368     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x498;
6369     uint32_t x499;
6370     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x500;
6371     uint32_t x501;
6372     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x502;
6373     uint32_t x503;
6374     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x504;
6375     uint32_t x505;
6376     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x506;
6377     uint32_t x507;
6378     uint32_t x508;
6379     uint32_t x509;
6380     uint32_t x510;
6381     uint32_t x511;
6382     uint32_t x512;
6383     uint32_t x513;
6384     uint32_t x514;
6385     uint32_t x515;
6386     uint32_t x516;
6387     uint32_t x517;
6388     uint32_t x518;
6389     uint32_t x519;
6390     uint32_t x520;
6391     uint32_t x521;
6392     uint32_t x522;
6393     uint32_t x523;
6394     uint32_t x524;
6395     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x525;
6396     uint32_t x526;
6397     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x527;
6398     uint32_t x528;
6399     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x529;
6400     uint32_t x530;
6401     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x531;
6402     uint32_t x532;
6403     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x533;
6404     uint32_t x534;
6405     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x535;
6406     uint32_t x536;
6407     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x537;
6408     uint32_t x538;
6409     uint32_t x539;
6410     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x540;
6411     uint32_t x541;
6412     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x542;
6413     uint32_t x543;
6414     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x544;
6415     uint32_t x545;
6416     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x546;
6417     uint32_t x547;
6418     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x548;
6419     uint32_t x549;
6420     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x550;
6421     uint32_t x551;
6422     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x552;
6423     uint32_t x553;
6424     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x554;
6425     uint32_t x555;
6426     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x556;
6427     uint32_t x557;
6428     uint32_t x558;
6429     uint32_t x559;
6430     uint32_t x560;
6431     uint32_t x561;
6432     uint32_t x562;
6433     uint32_t x563;
6434     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x564;
6435     uint32_t x565;
6436     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x566;
6437     uint32_t x567;
6438     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x568;
6439     uint32_t x569;
6440     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x570;
6441     uint32_t x571;
6442     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x572;
6443     uint32_t x573;
6444     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x574;
6445     uint32_t x575;
6446     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x576;
6447     uint32_t x577;
6448     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x578;
6449     uint32_t x579;
6450     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x580;
6451     uint32_t x581;
6452     uint32_t x582;
6453     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x583;
6454     uint32_t x584;
6455     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x585;
6456     uint32_t x586;
6457     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x587;
6458     uint32_t x588;
6459     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x589;
6460     uint32_t x590;
6461     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x591;
6462     uint32_t x592;
6463     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x593;
6464     uint32_t x594;
6465     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x595;
6466     uint32_t x596;
6467     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x597;
6468     uint32_t x598;
6469     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x599;
6470     uint32_t x600;
6471     uint32_t x601;
6472     uint32_t x602;
6473     uint32_t x603;
6474     uint32_t x604;
6475     uint32_t x605;
6476     uint32_t x606;
6477     uint32_t x607;
6478     x1 = (arg1[1]);
6479     x2 = (arg1[2]);
6480     x3 = (arg1[3]);
6481     x4 = (arg1[4]);
6482     x5 = (arg1[5]);
6483     x6 = (arg1[6]);
6484     x7 = (arg1[7]);
6485     x8 = (arg1[0]);
6486     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x9, &x10, x8,
6487                                                          (arg1[7]));
6488     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x11, &x12, x8,
6489                                                          (arg1[6]));
6490     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x13, &x14, x8,
6491                                                          (arg1[5]));
6492     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x15, &x16, x8,
6493                                                          (arg1[4]));
6494     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x17, &x18, x8,
6495                                                          (arg1[3]));
6496     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x19, &x20, x8,
6497                                                          (arg1[2]));
6498     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x21, &x22, x8,
6499                                                          (arg1[1]));
6500     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x23, &x24, x8,
6501                                                          (arg1[0]));
6502     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x25, &x26, 0x0,
6503                                                               x24, x21);
6504     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x27, &x28, x26,
6505                                                               x22, x19);
6506     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x29, &x30, x28,
6507                                                               x20, x17);
6508     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x31, &x32, x30,
6509                                                               x18, x15);
6510     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x33, &x34, x32,
6511                                                               x16, x13);
6512     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x35, &x36, x34,
6513                                                               x14, x11);
6514     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x37, &x38, x36,
6515                                                               x12, x9);
6516     x39 = (x38 + x10);
6517     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x40, &x41, x23,
6518                                                          UINT32_C(0xa3347857));
6519     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x42, &x43, x40,
6520                                                          UINT32_C(0x80000000));
6521     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x44, &x45, x40,
6522                                                          UINT16_C(0xc99));
6523     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x46, &x47, 0x0,
6524                                                               x23, x44);
6525     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x48, &x49, x47,
6526                                                               x25, x45);
6527     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x50, &x51, x49,
6528                                                               x27, 0x0);
6529     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x52, &x53, x51,
6530                                                               x29, 0x0);
6531     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x54, &x55, x53,
6532                                                               x31, 0x0);
6533     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x56, &x57, x55,
6534                                                               x33, 0x0);
6535     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x58, &x59, x57,
6536                                                               x35, 0x0);
6537     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x60, &x61, x59,
6538                                                               x37, x42);
6539     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x62, &x63, x61,
6540                                                               x39, x43);
6541     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x64, &x65, x1,
6542                                                          (arg1[7]));
6543     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x66, &x67, x1,
6544                                                          (arg1[6]));
6545     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x68, &x69, x1,
6546                                                          (arg1[5]));
6547     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x70, &x71, x1,
6548                                                          (arg1[4]));
6549     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x72, &x73, x1,
6550                                                          (arg1[3]));
6551     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x74, &x75, x1,
6552                                                          (arg1[2]));
6553     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x76, &x77, x1,
6554                                                          (arg1[1]));
6555     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x78, &x79, x1,
6556                                                          (arg1[0]));
6557     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x80, &x81, 0x0,
6558                                                               x79, x76);
6559     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x82, &x83, x81,
6560                                                               x77, x74);
6561     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x84, &x85, x83,
6562                                                               x75, x72);
6563     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x86, &x87, x85,
6564                                                               x73, x70);
6565     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x88, &x89, x87,
6566                                                               x71, x68);
6567     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x90, &x91, x89,
6568                                                               x69, x66);
6569     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x92, &x93, x91,
6570                                                               x67, x64);
6571     x94 = (x93 + x65);
6572     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x95, &x96, 0x0,
6573                                                               x48, x78);
6574     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x97, &x98, x96,
6575                                                               x50, x80);
6576     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x99, &x100, x98,
6577                                                               x52, x82);
6578     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x101, &x102,
6579                                                               x100, x54, x84);
6580     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x103, &x104,
6581                                                               x102, x56, x86);
6582     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x105, &x106,
6583                                                               x104, x58, x88);
6584     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x107, &x108,
6585                                                               x106, x60, x90);
6586     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x109, &x110,
6587                                                               x108, x62, x92);
6588     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x111, &x112,
6589                                                               x110, x63, x94);
6590     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x113, &x114, x95,
6591                                                          UINT32_C(0xa3347857));
6592     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x115, &x116, x113,
6593                                                          UINT32_C(0x80000000));
6594     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x117, &x118, x113,
6595                                                          UINT16_C(0xc99));
6596     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x119, &x120, 0x0,
6597                                                               x95, x117);
6598     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x121, &x122,
6599                                                               x120, x97, x118);
6600     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x123, &x124,
6601                                                               x122, x99, 0x0);
6602     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x125, &x126,
6603                                                               x124, x101, 0x0);
6604     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x127, &x128,
6605                                                               x126, x103, 0x0);
6606     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x129, &x130,
6607                                                               x128, x105, 0x0);
6608     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x131, &x132,
6609                                                               x130, x107, 0x0);
6610     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x133, &x134,
6611                                                               x132, x109, x115);
6612     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x135, &x136,
6613                                                               x134, x111, x116);
6614     x137 = ((uint32_t)x136 + x112);
6615     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x138, &x139, x2,
6616                                                          (arg1[7]));
6617     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x140, &x141, x2,
6618                                                          (arg1[6]));
6619     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x142, &x143, x2,
6620                                                          (arg1[5]));
6621     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x144, &x145, x2,
6622                                                          (arg1[4]));
6623     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x146, &x147, x2,
6624                                                          (arg1[3]));
6625     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x148, &x149, x2,
6626                                                          (arg1[2]));
6627     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x150, &x151, x2,
6628                                                          (arg1[1]));
6629     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x152, &x153, x2,
6630                                                          (arg1[0]));
6631     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x154, &x155, 0x0,
6632                                                               x153, x150);
6633     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x156, &x157,
6634                                                               x155, x151, x148);
6635     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x158, &x159,
6636                                                               x157, x149, x146);
6637     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x160, &x161,
6638                                                               x159, x147, x144);
6639     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x162, &x163,
6640                                                               x161, x145, x142);
6641     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x164, &x165,
6642                                                               x163, x143, x140);
6643     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x166, &x167,
6644                                                               x165, x141, x138);
6645     x168 = (x167 + x139);
6646     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x169, &x170, 0x0,
6647                                                               x121, x152);
6648     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x171, &x172,
6649                                                               x170, x123, x154);
6650     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x173, &x174,
6651                                                               x172, x125, x156);
6652     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x175, &x176,
6653                                                               x174, x127, x158);
6654     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x177, &x178,
6655                                                               x176, x129, x160);
6656     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x179, &x180,
6657                                                               x178, x131, x162);
6658     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x181, &x182,
6659                                                               x180, x133, x164);
6660     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x183, &x184,
6661                                                               x182, x135, x166);
6662     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x185, &x186,
6663                                                               x184, x137, x168);
6664     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x187, &x188, x169,
6665                                                          UINT32_C(0xa3347857));
6666     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x189, &x190, x187,
6667                                                          UINT32_C(0x80000000));
6668     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x191, &x192, x187,
6669                                                          UINT16_C(0xc99));
6670     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x193, &x194, 0x0,
6671                                                               x169, x191);
6672     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x195, &x196,
6673                                                               x194, x171, x192);
6674     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x197, &x198,
6675                                                               x196, x173, 0x0);
6676     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x199, &x200,
6677                                                               x198, x175, 0x0);
6678     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x201, &x202,
6679                                                               x200, x177, 0x0);
6680     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x203, &x204,
6681                                                               x202, x179, 0x0);
6682     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x205, &x206,
6683                                                               x204, x181, 0x0);
6684     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x207, &x208,
6685                                                               x206, x183, x189);
6686     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x209, &x210,
6687                                                               x208, x185, x190);
6688     x211 = ((uint32_t)x210 + x186);
6689     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x212, &x213, x3,
6690                                                          (arg1[7]));
6691     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x214, &x215, x3,
6692                                                          (arg1[6]));
6693     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x216, &x217, x3,
6694                                                          (arg1[5]));
6695     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x218, &x219, x3,
6696                                                          (arg1[4]));
6697     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x220, &x221, x3,
6698                                                          (arg1[3]));
6699     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x222, &x223, x3,
6700                                                          (arg1[2]));
6701     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x224, &x225, x3,
6702                                                          (arg1[1]));
6703     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x226, &x227, x3,
6704                                                          (arg1[0]));
6705     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x228, &x229, 0x0,
6706                                                               x227, x224);
6707     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x230, &x231,
6708                                                               x229, x225, x222);
6709     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x232, &x233,
6710                                                               x231, x223, x220);
6711     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x234, &x235,
6712                                                               x233, x221, x218);
6713     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x236, &x237,
6714                                                               x235, x219, x216);
6715     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x238, &x239,
6716                                                               x237, x217, x214);
6717     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x240, &x241,
6718                                                               x239, x215, x212);
6719     x242 = (x241 + x213);
6720     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x243, &x244, 0x0,
6721                                                               x195, x226);
6722     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x245, &x246,
6723                                                               x244, x197, x228);
6724     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x247, &x248,
6725                                                               x246, x199, x230);
6726     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x249, &x250,
6727                                                               x248, x201, x232);
6728     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x251, &x252,
6729                                                               x250, x203, x234);
6730     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x253, &x254,
6731                                                               x252, x205, x236);
6732     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x255, &x256,
6733                                                               x254, x207, x238);
6734     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x257, &x258,
6735                                                               x256, x209, x240);
6736     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x259, &x260,
6737                                                               x258, x211, x242);
6738     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x261, &x262, x243,
6739                                                          UINT32_C(0xa3347857));
6740     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x263, &x264, x261,
6741                                                          UINT32_C(0x80000000));
6742     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x265, &x266, x261,
6743                                                          UINT16_C(0xc99));
6744     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x267, &x268, 0x0,
6745                                                               x243, x265);
6746     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x269, &x270,
6747                                                               x268, x245, x266);
6748     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x271, &x272,
6749                                                               x270, x247, 0x0);
6750     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x273, &x274,
6751                                                               x272, x249, 0x0);
6752     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x275, &x276,
6753                                                               x274, x251, 0x0);
6754     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x277, &x278,
6755                                                               x276, x253, 0x0);
6756     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x279, &x280,
6757                                                               x278, x255, 0x0);
6758     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x281, &x282,
6759                                                               x280, x257, x263);
6760     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x283, &x284,
6761                                                               x282, x259, x264);
6762     x285 = ((uint32_t)x284 + x260);
6763     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x286, &x287, x4,
6764                                                          (arg1[7]));
6765     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x288, &x289, x4,
6766                                                          (arg1[6]));
6767     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x290, &x291, x4,
6768                                                          (arg1[5]));
6769     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x292, &x293, x4,
6770                                                          (arg1[4]));
6771     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x294, &x295, x4,
6772                                                          (arg1[3]));
6773     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x296, &x297, x4,
6774                                                          (arg1[2]));
6775     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x298, &x299, x4,
6776                                                          (arg1[1]));
6777     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x300, &x301, x4,
6778                                                          (arg1[0]));
6779     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x302, &x303, 0x0,
6780                                                               x301, x298);
6781     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x304, &x305,
6782                                                               x303, x299, x296);
6783     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x306, &x307,
6784                                                               x305, x297, x294);
6785     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x308, &x309,
6786                                                               x307, x295, x292);
6787     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x310, &x311,
6788                                                               x309, x293, x290);
6789     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x312, &x313,
6790                                                               x311, x291, x288);
6791     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x314, &x315,
6792                                                               x313, x289, x286);
6793     x316 = (x315 + x287);
6794     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x317, &x318, 0x0,
6795                                                               x269, x300);
6796     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x319, &x320,
6797                                                               x318, x271, x302);
6798     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x321, &x322,
6799                                                               x320, x273, x304);
6800     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x323, &x324,
6801                                                               x322, x275, x306);
6802     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x325, &x326,
6803                                                               x324, x277, x308);
6804     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x327, &x328,
6805                                                               x326, x279, x310);
6806     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x329, &x330,
6807                                                               x328, x281, x312);
6808     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x331, &x332,
6809                                                               x330, x283, x314);
6810     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x333, &x334,
6811                                                               x332, x285, x316);
6812     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x335, &x336, x317,
6813                                                          UINT32_C(0xa3347857));
6814     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x337, &x338, x335,
6815                                                          UINT32_C(0x80000000));
6816     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x339, &x340, x335,
6817                                                          UINT16_C(0xc99));
6818     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x341, &x342, 0x0,
6819                                                               x317, x339);
6820     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x343, &x344,
6821                                                               x342, x319, x340);
6822     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x345, &x346,
6823                                                               x344, x321, 0x0);
6824     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x347, &x348,
6825                                                               x346, x323, 0x0);
6826     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x349, &x350,
6827                                                               x348, x325, 0x0);
6828     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x351, &x352,
6829                                                               x350, x327, 0x0);
6830     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x353, &x354,
6831                                                               x352, x329, 0x0);
6832     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x355, &x356,
6833                                                               x354, x331, x337);
6834     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x357, &x358,
6835                                                               x356, x333, x338);
6836     x359 = ((uint32_t)x358 + x334);
6837     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x360, &x361, x5,
6838                                                          (arg1[7]));
6839     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x362, &x363, x5,
6840                                                          (arg1[6]));
6841     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x364, &x365, x5,
6842                                                          (arg1[5]));
6843     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x366, &x367, x5,
6844                                                          (arg1[4]));
6845     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x368, &x369, x5,
6846                                                          (arg1[3]));
6847     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x370, &x371, x5,
6848                                                          (arg1[2]));
6849     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x372, &x373, x5,
6850                                                          (arg1[1]));
6851     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x374, &x375, x5,
6852                                                          (arg1[0]));
6853     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x376, &x377, 0x0,
6854                                                               x375, x372);
6855     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x378, &x379,
6856                                                               x377, x373, x370);
6857     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x380, &x381,
6858                                                               x379, x371, x368);
6859     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x382, &x383,
6860                                                               x381, x369, x366);
6861     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x384, &x385,
6862                                                               x383, x367, x364);
6863     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x386, &x387,
6864                                                               x385, x365, x362);
6865     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x388, &x389,
6866                                                               x387, x363, x360);
6867     x390 = (x389 + x361);
6868     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x391, &x392, 0x0,
6869                                                               x343, x374);
6870     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x393, &x394,
6871                                                               x392, x345, x376);
6872     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x395, &x396,
6873                                                               x394, x347, x378);
6874     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x397, &x398,
6875                                                               x396, x349, x380);
6876     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x399, &x400,
6877                                                               x398, x351, x382);
6878     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x401, &x402,
6879                                                               x400, x353, x384);
6880     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x403, &x404,
6881                                                               x402, x355, x386);
6882     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x405, &x406,
6883                                                               x404, x357, x388);
6884     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x407, &x408,
6885                                                               x406, x359, x390);
6886     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x409, &x410, x391,
6887                                                          UINT32_C(0xa3347857));
6888     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x411, &x412, x409,
6889                                                          UINT32_C(0x80000000));
6890     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x413, &x414, x409,
6891                                                          UINT16_C(0xc99));
6892     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x415, &x416, 0x0,
6893                                                               x391, x413);
6894     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x417, &x418,
6895                                                               x416, x393, x414);
6896     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x419, &x420,
6897                                                               x418, x395, 0x0);
6898     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x421, &x422,
6899                                                               x420, x397, 0x0);
6900     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x423, &x424,
6901                                                               x422, x399, 0x0);
6902     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x425, &x426,
6903                                                               x424, x401, 0x0);
6904     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x427, &x428,
6905                                                               x426, x403, 0x0);
6906     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x429, &x430,
6907                                                               x428, x405, x411);
6908     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x431, &x432,
6909                                                               x430, x407, x412);
6910     x433 = ((uint32_t)x432 + x408);
6911     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x434, &x435, x6,
6912                                                          (arg1[7]));
6913     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x436, &x437, x6,
6914                                                          (arg1[6]));
6915     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x438, &x439, x6,
6916                                                          (arg1[5]));
6917     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x440, &x441, x6,
6918                                                          (arg1[4]));
6919     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x442, &x443, x6,
6920                                                          (arg1[3]));
6921     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x444, &x445, x6,
6922                                                          (arg1[2]));
6923     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x446, &x447, x6,
6924                                                          (arg1[1]));
6925     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x448, &x449, x6,
6926                                                          (arg1[0]));
6927     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x450, &x451, 0x0,
6928                                                               x449, x446);
6929     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x452, &x453,
6930                                                               x451, x447, x444);
6931     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x454, &x455,
6932                                                               x453, x445, x442);
6933     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x456, &x457,
6934                                                               x455, x443, x440);
6935     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x458, &x459,
6936                                                               x457, x441, x438);
6937     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x460, &x461,
6938                                                               x459, x439, x436);
6939     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x462, &x463,
6940                                                               x461, x437, x434);
6941     x464 = (x463 + x435);
6942     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x465, &x466, 0x0,
6943                                                               x417, x448);
6944     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x467, &x468,
6945                                                               x466, x419, x450);
6946     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x469, &x470,
6947                                                               x468, x421, x452);
6948     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x471, &x472,
6949                                                               x470, x423, x454);
6950     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x473, &x474,
6951                                                               x472, x425, x456);
6952     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x475, &x476,
6953                                                               x474, x427, x458);
6954     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x477, &x478,
6955                                                               x476, x429, x460);
6956     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x479, &x480,
6957                                                               x478, x431, x462);
6958     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x481, &x482,
6959                                                               x480, x433, x464);
6960     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x483, &x484, x465,
6961                                                          UINT32_C(0xa3347857));
6962     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x485, &x486, x483,
6963                                                          UINT32_C(0x80000000));
6964     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x487, &x488, x483,
6965                                                          UINT16_C(0xc99));
6966     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x489, &x490, 0x0,
6967                                                               x465, x487);
6968     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x491, &x492,
6969                                                               x490, x467, x488);
6970     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x493, &x494,
6971                                                               x492, x469, 0x0);
6972     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x495, &x496,
6973                                                               x494, x471, 0x0);
6974     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x497, &x498,
6975                                                               x496, x473, 0x0);
6976     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x499, &x500,
6977                                                               x498, x475, 0x0);
6978     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x501, &x502,
6979                                                               x500, x477, 0x0);
6980     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x503, &x504,
6981                                                               x502, x479, x485);
6982     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x505, &x506,
6983                                                               x504, x481, x486);
6984     x507 = ((uint32_t)x506 + x482);
6985     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x508, &x509, x7,
6986                                                          (arg1[7]));
6987     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x510, &x511, x7,
6988                                                          (arg1[6]));
6989     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x512, &x513, x7,
6990                                                          (arg1[5]));
6991     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x514, &x515, x7,
6992                                                          (arg1[4]));
6993     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x516, &x517, x7,
6994                                                          (arg1[3]));
6995     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x518, &x519, x7,
6996                                                          (arg1[2]));
6997     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x520, &x521, x7,
6998                                                          (arg1[1]));
6999     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x522, &x523, x7,
7000                                                          (arg1[0]));
7001     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x524, &x525, 0x0,
7002                                                               x523, x520);
7003     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x526, &x527,
7004                                                               x525, x521, x518);
7005     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x528, &x529,
7006                                                               x527, x519, x516);
7007     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x530, &x531,
7008                                                               x529, x517, x514);
7009     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x532, &x533,
7010                                                               x531, x515, x512);
7011     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x534, &x535,
7012                                                               x533, x513, x510);
7013     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x536, &x537,
7014                                                               x535, x511, x508);
7015     x538 = (x537 + x509);
7016     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x539, &x540, 0x0,
7017                                                               x491, x522);
7018     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x541, &x542,
7019                                                               x540, x493, x524);
7020     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x543, &x544,
7021                                                               x542, x495, x526);
7022     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x545, &x546,
7023                                                               x544, x497, x528);
7024     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x547, &x548,
7025                                                               x546, x499, x530);
7026     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x549, &x550,
7027                                                               x548, x501, x532);
7028     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x551, &x552,
7029                                                               x550, x503, x534);
7030     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x553, &x554,
7031                                                               x552, x505, x536);
7032     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x555, &x556,
7033                                                               x554, x507, x538);
7034     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x557, &x558, x539,
7035                                                          UINT32_C(0xa3347857));
7036     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x559, &x560, x557,
7037                                                          UINT32_C(0x80000000));
7038     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x561, &x562, x557,
7039                                                          UINT16_C(0xc99));
7040     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x563, &x564, 0x0,
7041                                                               x539, x561);
7042     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x565, &x566,
7043                                                               x564, x541, x562);
7044     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x567, &x568,
7045                                                               x566, x543, 0x0);
7046     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x569, &x570,
7047                                                               x568, x545, 0x0);
7048     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x571, &x572,
7049                                                               x570, x547, 0x0);
7050     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x573, &x574,
7051                                                               x572, x549, 0x0);
7052     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x575, &x576,
7053                                                               x574, x551, 0x0);
7054     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x577, &x578,
7055                                                               x576, x553, x559);
7056     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x579, &x580,
7057                                                               x578, x555, x560);
7058     x581 = ((uint32_t)x580 + x556);
7059     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7060         &x582, &x583, 0x0, x565, UINT16_C(0xc99));
7061     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x584, &x585,
7062                                                                x583, x567, 0x0);
7063     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x586, &x587,
7064                                                                x585, x569, 0x0);
7065     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x588, &x589,
7066                                                                x587, x571, 0x0);
7067     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x590, &x591,
7068                                                                x589, x573, 0x0);
7069     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x592, &x593,
7070                                                                x591, x575, 0x0);
7071     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x594, &x595,
7072                                                                x593, x577, 0x0);
7073     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7074         &x596, &x597, x595, x579, UINT32_C(0x80000000));
7075     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x598, &x599,
7076                                                                x597, x581, 0x0);
7077     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x600, x599, x582,
7078                                                             x565);
7079     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x601, x599, x584,
7080                                                             x567);
7081     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x602, x599, x586,
7082                                                             x569);
7083     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x603, x599, x588,
7084                                                             x571);
7085     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x604, x599, x590,
7086                                                             x573);
7087     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x605, x599, x592,
7088                                                             x575);
7089     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x606, x599, x594,
7090                                                             x577);
7091     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x607, x599, x596,
7092                                                             x579);
7093     out1[0] = x600;
7094     out1[1] = x601;
7095     out1[2] = x602;
7096     out1[3] = x603;
7097     out1[4] = x604;
7098     out1[5] = x605;
7099     out1[6] = x606;
7100     out1[7] = x607;
7101 }
7102
7103 /*
7104  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add adds two field elements in the Montgomery domain.
7105  * Preconditions:
7106  *   0 ≤ eval arg1 < m
7107  *   0 ≤ eval arg2 < m
7108  * Postconditions:
7109  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) + eval (from_montgomery arg2)) mod m
7110  *   0 ≤ eval out1 < m
7111  *
7112  * Input Bounds:
7113  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7114  *   arg2: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7115  * Output Bounds:
7116  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7117  */
7118 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(
7119     uint32_t out1[8], const uint32_t arg1[8], const uint32_t arg2[8]) {
7120     uint32_t x1;
7121     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x2;
7122     uint32_t x3;
7123     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x4;
7124     uint32_t x5;
7125     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x6;
7126     uint32_t x7;
7127     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x8;
7128     uint32_t x9;
7129     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x10;
7130     uint32_t x11;
7131     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x12;
7132     uint32_t x13;
7133     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
7134     uint32_t x15;
7135     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x16;
7136     uint32_t x17;
7137     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x18;
7138     uint32_t x19;
7139     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x20;
7140     uint32_t x21;
7141     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x22;
7142     uint32_t x23;
7143     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x24;
7144     uint32_t x25;
7145     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x26;
7146     uint32_t x27;
7147     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x28;
7148     uint32_t x29;
7149     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x30;
7150     uint32_t x31;
7151     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x32;
7152     uint32_t x33;
7153     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x34;
7154     uint32_t x35;
7155     uint32_t x36;
7156     uint32_t x37;
7157     uint32_t x38;
7158     uint32_t x39;
7159     uint32_t x40;
7160     uint32_t x41;
7161     uint32_t x42;
7162     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7163         &x1, &x2, 0x0, (arg1[0]), (arg2[0]));
7164     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7165         &x3, &x4, x2, (arg1[1]), (arg2[1]));
7166     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7167         &x5, &x6, x4, (arg1[2]), (arg2[2]));
7168     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7169         &x7, &x8, x6, (arg1[3]), (arg2[3]));
7170     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7171         &x9, &x10, x8, (arg1[4]), (arg2[4]));
7172     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7173         &x11, &x12, x10, (arg1[5]), (arg2[5]));
7174     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7175         &x13, &x14, x12, (arg1[6]), (arg2[6]));
7176     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7177         &x15, &x16, x14, (arg1[7]), (arg2[7]));
7178     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7179         &x17, &x18, 0x0, x1, UINT16_C(0xc99));
7180     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x19, &x20, x18,
7181                                                                x3, 0x0);
7182     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x21, &x22, x20,
7183                                                                x5, 0x0);
7184     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x23, &x24, x22,
7185                                                                x7, 0x0);
7186     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x25, &x26, x24,
7187                                                                x9, 0x0);
7188     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x27, &x28, x26,
7189                                                                x11, 0x0);
7190     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x29, &x30, x28,
7191                                                                x13, 0x0);
7192     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7193         &x31, &x32, x30, x15, UINT32_C(0x80000000));
7194     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x33, &x34, x32,
7195                                                                x16, 0x0);
7196     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x35, x34, x17, x1);
7197     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x36, x34, x19, x3);
7198     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x37, x34, x21, x5);
7199     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x38, x34, x23, x7);
7200     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x39, x34, x25, x9);
7201     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x40, x34, x27,
7202                                                             x11);
7203     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x41, x34, x29,
7204                                                             x13);
7205     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x42, x34, x31,
7206                                                             x15);
7207     out1[0] = x35;
7208     out1[1] = x36;
7209     out1[2] = x37;
7210     out1[3] = x38;
7211     out1[4] = x39;
7212     out1[5] = x40;
7213     out1[6] = x41;
7214     out1[7] = x42;
7215 }
7216
7217 /*
7218  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub subtracts two field elements in the Montgomery domain.
7219  * Preconditions:
7220  *   0 ≤ eval arg1 < m
7221  *   0 ≤ eval arg2 < m
7222  * Postconditions:
7223  *   eval (from_montgomery out1) mod m = (eval (from_montgomery arg1) - eval (from_montgomery arg2)) mod m
7224  *   0 ≤ eval out1 < m
7225  *
7226  * Input Bounds:
7227  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7228  *   arg2: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7229  * Output Bounds:
7230  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7231  */
7232 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(
7233     uint32_t out1[8], const uint32_t arg1[8], const uint32_t arg2[8]) {
7234     uint32_t x1;
7235     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x2;
7236     uint32_t x3;
7237     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x4;
7238     uint32_t x5;
7239     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x6;
7240     uint32_t x7;
7241     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x8;
7242     uint32_t x9;
7243     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x10;
7244     uint32_t x11;
7245     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x12;
7246     uint32_t x13;
7247     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
7248     uint32_t x15;
7249     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x16;
7250     uint32_t x17;
7251     uint32_t x18;
7252     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x19;
7253     uint32_t x20;
7254     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x21;
7255     uint32_t x22;
7256     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x23;
7257     uint32_t x24;
7258     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x25;
7259     uint32_t x26;
7260     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x27;
7261     uint32_t x28;
7262     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x29;
7263     uint32_t x30;
7264     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x31;
7265     uint32_t x32;
7266     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x33;
7267     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7268         &x1, &x2, 0x0, (arg1[0]), (arg2[0]));
7269     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7270         &x3, &x4, x2, (arg1[1]), (arg2[1]));
7271     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7272         &x5, &x6, x4, (arg1[2]), (arg2[2]));
7273     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7274         &x7, &x8, x6, (arg1[3]), (arg2[3]));
7275     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7276         &x9, &x10, x8, (arg1[4]), (arg2[4]));
7277     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7278         &x11, &x12, x10, (arg1[5]), (arg2[5]));
7279     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7280         &x13, &x14, x12, (arg1[6]), (arg2[6]));
7281     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7282         &x15, &x16, x14, (arg1[7]), (arg2[7]));
7283     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
7284         &x17, x16, 0x0, UINT32_C(0xffffffff));
7285     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7286         &x18, &x19, 0x0, x1, (x17 & UINT16_C(0xc99)));
7287     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x20, &x21, x19,
7288                                                               x3, 0x0);
7289     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x22, &x23, x21,
7290                                                               x5, 0x0);
7291     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x24, &x25, x23,
7292                                                               x7, 0x0);
7293     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x26, &x27, x25,
7294                                                               x9, 0x0);
7295     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x28, &x29, x27,
7296                                                               x11, 0x0);
7297     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x30, &x31, x29,
7298                                                               x13, 0x0);
7299     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7300         &x32, &x33, x31, x15, (x17 & UINT32_C(0x80000000)));
7301     out1[0] = x18;
7302     out1[1] = x20;
7303     out1[2] = x22;
7304     out1[3] = x24;
7305     out1[4] = x26;
7306     out1[5] = x28;
7307     out1[6] = x30;
7308     out1[7] = x32;
7309 }
7310
7311 /*
7312  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp negates a field element in the Montgomery domain.
7313  * Preconditions:
7314  *   0 ≤ eval arg1 < m
7315  * Postconditions:
7316  *   eval (from_montgomery out1) mod m = -eval (from_montgomery arg1) mod m
7317  *   0 ≤ eval out1 < m
7318  *
7319  * Input Bounds:
7320  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7321  * Output Bounds:
7322  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7323  */
7324 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(
7325     uint32_t out1[8], const uint32_t arg1[8]) {
7326     uint32_t x1;
7327     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x2;
7328     uint32_t x3;
7329     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x4;
7330     uint32_t x5;
7331     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x6;
7332     uint32_t x7;
7333     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x8;
7334     uint32_t x9;
7335     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x10;
7336     uint32_t x11;
7337     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x12;
7338     uint32_t x13;
7339     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
7340     uint32_t x15;
7341     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x16;
7342     uint32_t x17;
7343     uint32_t x18;
7344     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x19;
7345     uint32_t x20;
7346     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x21;
7347     uint32_t x22;
7348     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x23;
7349     uint32_t x24;
7350     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x25;
7351     uint32_t x26;
7352     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x27;
7353     uint32_t x28;
7354     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x29;
7355     uint32_t x30;
7356     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x31;
7357     uint32_t x32;
7358     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x33;
7359     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x1, &x2, 0x0,
7360                                                                0x0, (arg1[0]));
7361     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x3, &x4, x2,
7362                                                                0x0, (arg1[1]));
7363     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x5, &x6, x4,
7364                                                                0x0, (arg1[2]));
7365     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x7, &x8, x6,
7366                                                                0x0, (arg1[3]));
7367     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x9, &x10, x8,
7368                                                                0x0, (arg1[4]));
7369     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x11, &x12, x10,
7370                                                                0x0, (arg1[5]));
7371     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x13, &x14, x12,
7372                                                                0x0, (arg1[6]));
7373     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x15, &x16, x14,
7374                                                                0x0, (arg1[7]));
7375     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
7376         &x17, x16, 0x0, UINT32_C(0xffffffff));
7377     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7378         &x18, &x19, 0x0, x1, (x17 & UINT16_C(0xc99)));
7379     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x20, &x21, x19,
7380                                                               x3, 0x0);
7381     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x22, &x23, x21,
7382                                                               x5, 0x0);
7383     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x24, &x25, x23,
7384                                                               x7, 0x0);
7385     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x26, &x27, x25,
7386                                                               x9, 0x0);
7387     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x28, &x29, x27,
7388                                                               x11, 0x0);
7389     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x30, &x31, x29,
7390                                                               x13, 0x0);
7391     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7392         &x32, &x33, x31, x15, (x17 & UINT32_C(0x80000000)));
7393     out1[0] = x18;
7394     out1[1] = x20;
7395     out1[2] = x22;
7396     out1[3] = x24;
7397     out1[4] = x26;
7398     out1[5] = x28;
7399     out1[6] = x30;
7400     out1[7] = x32;
7401 }
7402
7403 /*
7404  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery translates a field element out of the Montgomery domain.
7405  * Preconditions:
7406  *   0 ≤ eval arg1 < m
7407  * Postconditions:
7408  *   eval out1 mod m = (eval arg1 * ((2^32)⁻¹ mod m)^8) mod m
7409  *   0 ≤ eval out1 < m
7410  *
7411  * Input Bounds:
7412  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7413  * Output Bounds:
7414  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7415  */
7416 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(
7417     uint32_t out1[8], const uint32_t arg1[8]) {
7418     uint32_t x1;
7419     uint32_t x2;
7420     uint32_t x3;
7421     uint32_t x4;
7422     uint32_t x5;
7423     uint32_t x6;
7424     uint32_t x7;
7425     uint32_t x8;
7426     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x9;
7427     uint32_t x10;
7428     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x11;
7429     uint32_t x12;
7430     uint32_t x13;
7431     uint32_t x14;
7432     uint32_t x15;
7433     uint32_t x16;
7434     uint32_t x17;
7435     uint32_t x18;
7436     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x19;
7437     uint32_t x20;
7438     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x21;
7439     uint32_t x22;
7440     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x23;
7441     uint32_t x24;
7442     uint32_t x25;
7443     uint32_t x26;
7444     uint32_t x27;
7445     uint32_t x28;
7446     uint32_t x29;
7447     uint32_t x30;
7448     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x31;
7449     uint32_t x32;
7450     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x33;
7451     uint32_t x34;
7452     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x35;
7453     uint32_t x36;
7454     uint32_t x37;
7455     uint32_t x38;
7456     uint32_t x39;
7457     uint32_t x40;
7458     uint32_t x41;
7459     uint32_t x42;
7460     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x43;
7461     uint32_t x44;
7462     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x45;
7463     uint32_t x46;
7464     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x47;
7465     uint32_t x48;
7466     uint32_t x49;
7467     uint32_t x50;
7468     uint32_t x51;
7469     uint32_t x52;
7470     uint32_t x53;
7471     uint32_t x54;
7472     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x55;
7473     uint32_t x56;
7474     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x57;
7475     uint32_t x58;
7476     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x59;
7477     uint32_t x60;
7478     uint32_t x61;
7479     uint32_t x62;
7480     uint32_t x63;
7481     uint32_t x64;
7482     uint32_t x65;
7483     uint32_t x66;
7484     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x67;
7485     uint32_t x68;
7486     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x69;
7487     uint32_t x70;
7488     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x71;
7489     uint32_t x72;
7490     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x73;
7491     uint32_t x74;
7492     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x75;
7493     uint32_t x76;
7494     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x77;
7495     uint32_t x78;
7496     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x79;
7497     uint32_t x80;
7498     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x81;
7499     uint32_t x82;
7500     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x83;
7501     uint32_t x84;
7502     uint32_t x85;
7503     uint32_t x86;
7504     uint32_t x87;
7505     uint32_t x88;
7506     uint32_t x89;
7507     uint32_t x90;
7508     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x91;
7509     uint32_t x92;
7510     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x93;
7511     uint32_t x94;
7512     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x95;
7513     uint32_t x96;
7514     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x97;
7515     uint32_t x98;
7516     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x99;
7517     uint32_t x100;
7518     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x101;
7519     uint32_t x102;
7520     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x103;
7521     uint32_t x104;
7522     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x105;
7523     uint32_t x106;
7524     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x107;
7525     uint32_t x108;
7526     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x109;
7527     uint32_t x110;
7528     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x111;
7529     uint32_t x112;
7530     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x113;
7531     uint32_t x114;
7532     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x115;
7533     uint32_t x116;
7534     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x117;
7535     uint32_t x118;
7536     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x119;
7537     uint32_t x120;
7538     uint32_t x121;
7539     uint32_t x122;
7540     uint32_t x123;
7541     uint32_t x124;
7542     uint32_t x125;
7543     uint32_t x126;
7544     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x127;
7545     uint32_t x128;
7546     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x129;
7547     uint32_t x130;
7548     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x131;
7549     uint32_t x132;
7550     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x133;
7551     uint32_t x134;
7552     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x135;
7553     uint32_t x136;
7554     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x137;
7555     uint32_t x138;
7556     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x139;
7557     uint32_t x140;
7558     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x141;
7559     uint32_t x142;
7560     uint32_t x143;
7561     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x144;
7562     uint32_t x145;
7563     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x146;
7564     uint32_t x147;
7565     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x148;
7566     uint32_t x149;
7567     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x150;
7568     uint32_t x151;
7569     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x152;
7570     uint32_t x153;
7571     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x154;
7572     uint32_t x155;
7573     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x156;
7574     uint32_t x157;
7575     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x158;
7576     uint32_t x159;
7577     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x160;
7578     uint32_t x161;
7579     uint32_t x162;
7580     uint32_t x163;
7581     uint32_t x164;
7582     uint32_t x165;
7583     uint32_t x166;
7584     uint32_t x167;
7585     uint32_t x168;
7586     x1 = (arg1[0]);
7587     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x2, &x3, x1,
7588                                                          UINT32_C(0xa3347857));
7589     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x4, &x5, x2,
7590                                                          UINT32_C(0x80000000));
7591     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x6, &x7, x2,
7592                                                          UINT16_C(0xc99));
7593     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x8, &x9, 0x0, x1,
7594                                                               x6);
7595     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7596         &x10, &x11, 0x0, (x9 + x7), (arg1[1]));
7597     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x12, &x13, x10,
7598                                                          UINT32_C(0xa3347857));
7599     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x14, &x15, x12,
7600                                                          UINT32_C(0x80000000));
7601     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x16, &x17, x12,
7602                                                          UINT16_C(0xc99));
7603     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x18, &x19, 0x0,
7604                                                               x5, x14);
7605     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x20, &x21, 0x0,
7606                                                               x10, x16);
7607     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7608         &x22, &x23, 0x0, (((uint32_t)x21 + x11) + x17), (arg1[2]));
7609     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x24, &x25, x22,
7610                                                          UINT32_C(0xa3347857));
7611     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x26, &x27, x24,
7612                                                          UINT32_C(0x80000000));
7613     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x28, &x29, x24,
7614                                                          UINT16_C(0xc99));
7615     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x30, &x31, 0x0,
7616                                                               (x19 + x15), x26);
7617     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x32, &x33, 0x0,
7618                                                               x22, x28);
7619     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7620         &x34, &x35, 0x0, (((uint32_t)x33 + x23) + x29), (arg1[3]));
7621     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x36, &x37, x34,
7622                                                          UINT32_C(0xa3347857));
7623     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x38, &x39, x36,
7624                                                          UINT32_C(0x80000000));
7625     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x40, &x41, x36,
7626                                                          UINT16_C(0xc99));
7627     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x42, &x43, 0x0,
7628                                                               (x31 + x27), x38);
7629     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x44, &x45, 0x0,
7630                                                               x34, x40);
7631     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7632         &x46, &x47, 0x0, (((uint32_t)x45 + x35) + x41), (arg1[4]));
7633     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x48, &x49, x46,
7634                                                          UINT32_C(0xa3347857));
7635     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x50, &x51, x48,
7636                                                          UINT32_C(0x80000000));
7637     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x52, &x53, x48,
7638                                                          UINT16_C(0xc99));
7639     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x54, &x55, 0x0,
7640                                                               (x43 + x39), x50);
7641     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x56, &x57, 0x0,
7642                                                               x46, x52);
7643     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7644         &x58, &x59, 0x0, (((uint32_t)x57 + x47) + x53), (arg1[5]));
7645     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x60, &x61, x58,
7646                                                          UINT32_C(0xa3347857));
7647     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x62, &x63, x60,
7648                                                          UINT32_C(0x80000000));
7649     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x64, &x65, x60,
7650                                                          UINT16_C(0xc99));
7651     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x66, &x67, 0x0,
7652                                                               (x55 + x51), x62);
7653     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x68, &x69, 0x0,
7654                                                               x58, x64);
7655     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7656         &x70, &x71, 0x0, (((uint32_t)x69 + x59) + x65), (arg1[6]));
7657     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x72, &x73, x71,
7658                                                               x4, 0x0);
7659     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x74, &x75, x73,
7660                                                               x18, 0x0);
7661     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x76, &x77, x75,
7662                                                               x30, 0x0);
7663     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x78, &x79, x77,
7664                                                               x42, 0x0);
7665     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x80, &x81, x79,
7666                                                               x54, 0x0);
7667     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x82, &x83, x81,
7668                                                               x66, 0x0);
7669     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x84, &x85, x70,
7670                                                          UINT32_C(0xa3347857));
7671     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x86, &x87, x84,
7672                                                          UINT32_C(0x80000000));
7673     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x88, &x89, x84,
7674                                                          UINT16_C(0xc99));
7675     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x90, &x91, 0x0,
7676                                                               x70, x88);
7677     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x92, &x93, x91,
7678                                                               x72, x89);
7679     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x94, &x95, x93,
7680                                                               x74, 0x0);
7681     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x96, &x97, x95,
7682                                                               x76, 0x0);
7683     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x98, &x99, x97,
7684                                                               x78, 0x0);
7685     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x100, &x101, x99,
7686                                                               x80, 0x0);
7687     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x102, &x103,
7688                                                               x101, x82, 0x0);
7689     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7690         &x104, &x105, x103, (x83 + (x67 + x63)), x86);
7691     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x106, &x107, 0x0,
7692                                                               x92, (arg1[7]));
7693     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x108, &x109,
7694                                                               x107, x94, 0x0);
7695     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x110, &x111,
7696                                                               x109, x96, 0x0);
7697     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x112, &x113,
7698                                                               x111, x98, 0x0);
7699     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x114, &x115,
7700                                                               x113, x100, 0x0);
7701     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x116, &x117,
7702                                                               x115, x102, 0x0);
7703     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x118, &x119,
7704                                                               x117, x104, 0x0);
7705     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x120, &x121, x106,
7706                                                          UINT32_C(0xa3347857));
7707     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x122, &x123, x120,
7708                                                          UINT32_C(0x80000000));
7709     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x124, &x125, x120,
7710                                                          UINT16_C(0xc99));
7711     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x126, &x127, 0x0,
7712                                                               x106, x124);
7713     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x128, &x129,
7714                                                               x127, x108, x125);
7715     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x130, &x131,
7716                                                               x129, x110, 0x0);
7717     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x132, &x133,
7718                                                               x131, x112, 0x0);
7719     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x134, &x135,
7720                                                               x133, x114, 0x0);
7721     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x136, &x137,
7722                                                               x135, x116, 0x0);
7723     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x138, &x139,
7724                                                               x137, x118, 0x0);
7725     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7726         &x140, &x141, x139, (x119 + (x105 + x87)), x122);
7727     x142 = (x141 + x123);
7728     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7729         &x143, &x144, 0x0, x128, UINT16_C(0xc99));
7730     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x145, &x146,
7731                                                                x144, x130, 0x0);
7732     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x147, &x148,
7733                                                                x146, x132, 0x0);
7734     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x149, &x150,
7735                                                                x148, x134, 0x0);
7736     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x151, &x152,
7737                                                                x150, x136, 0x0);
7738     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x153, &x154,
7739                                                                x152, x138, 0x0);
7740     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x155, &x156,
7741                                                                x154, x140, 0x0);
7742     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
7743         &x157, &x158, x156, x142, UINT32_C(0x80000000));
7744     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x159, &x160,
7745                                                                x158, 0x0, 0x0);
7746     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x161, x160, x143,
7747                                                             x128);
7748     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x162, x160, x145,
7749                                                             x130);
7750     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x163, x160, x147,
7751                                                             x132);
7752     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x164, x160, x149,
7753                                                             x134);
7754     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x165, x160, x151,
7755                                                             x136);
7756     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x166, x160, x153,
7757                                                             x138);
7758     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x167, x160, x155,
7759                                                             x140);
7760     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x168, x160, x157,
7761                                                             x142);
7762     out1[0] = x161;
7763     out1[1] = x162;
7764     out1[2] = x163;
7765     out1[3] = x164;
7766     out1[4] = x165;
7767     out1[5] = x166;
7768     out1[6] = x167;
7769     out1[7] = x168;
7770 }
7771
7772 /*
7773  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery translates a field element into the Montgomery domain.
7774  * Preconditions:
7775  *   0 ≤ eval arg1 < m
7776  * Postconditions:
7777  *   eval (from_montgomery out1) mod m = eval arg1 mod m
7778  *   0 ≤ eval out1 < m
7779  *
7780  * Input Bounds:
7781  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7782  * Output Bounds:
7783  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
7784  */
7785 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(
7786     uint32_t out1[8], const uint32_t arg1[8]) {
7787     uint32_t x1;
7788     uint32_t x2;
7789     uint32_t x3;
7790     uint32_t x4;
7791     uint32_t x5;
7792     uint32_t x6;
7793     uint32_t x7;
7794     uint32_t x8;
7795     uint32_t x9;
7796     uint32_t x10;
7797     uint32_t x11;
7798     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x12;
7799     uint32_t x13;
7800     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x14;
7801     uint32_t x15;
7802     uint32_t x16;
7803     uint32_t x17;
7804     uint32_t x18;
7805     uint32_t x19;
7806     uint32_t x20;
7807     uint32_t x21;
7808     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x22;
7809     uint32_t x23;
7810     uint32_t x24;
7811     uint32_t x25;
7812     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x26;
7813     uint32_t x27;
7814     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x28;
7815     uint32_t x29;
7816     uint32_t x30;
7817     uint32_t x31;
7818     uint32_t x32;
7819     uint32_t x33;
7820     uint32_t x34;
7821     uint32_t x35;
7822     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x36;
7823     uint32_t x37;
7824     uint32_t x38;
7825     uint32_t x39;
7826     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x40;
7827     uint32_t x41;
7828     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x42;
7829     uint32_t x43;
7830     uint32_t x44;
7831     uint32_t x45;
7832     uint32_t x46;
7833     uint32_t x47;
7834     uint32_t x48;
7835     uint32_t x49;
7836     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x50;
7837     uint32_t x51;
7838     uint32_t x52;
7839     uint32_t x53;
7840     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x54;
7841     uint32_t x55;
7842     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x56;
7843     uint32_t x57;
7844     uint32_t x58;
7845     uint32_t x59;
7846     uint32_t x60;
7847     uint32_t x61;
7848     uint32_t x62;
7849     uint32_t x63;
7850     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x64;
7851     uint32_t x65;
7852     uint32_t x66;
7853     uint32_t x67;
7854     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x68;
7855     uint32_t x69;
7856     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x70;
7857     uint32_t x71;
7858     uint32_t x72;
7859     uint32_t x73;
7860     uint32_t x74;
7861     uint32_t x75;
7862     uint32_t x76;
7863     uint32_t x77;
7864     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x78;
7865     uint32_t x79;
7866     uint32_t x80;
7867     uint32_t x81;
7868     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x82;
7869     uint32_t x83;
7870     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x84;
7871     uint32_t x85;
7872     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x86;
7873     uint32_t x87;
7874     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x88;
7875     uint32_t x89;
7876     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x90;
7877     uint32_t x91;
7878     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x92;
7879     uint32_t x93;
7880     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x94;
7881     uint32_t x95;
7882     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x96;
7883     uint32_t x97;
7884     uint32_t x98;
7885     uint32_t x99;
7886     uint32_t x100;
7887     uint32_t x101;
7888     uint32_t x102;
7889     uint32_t x103;
7890     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x104;
7891     uint32_t x105;
7892     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x106;
7893     uint32_t x107;
7894     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x108;
7895     uint32_t x109;
7896     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x110;
7897     uint32_t x111;
7898     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x112;
7899     uint32_t x113;
7900     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x114;
7901     uint32_t x115;
7902     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x116;
7903     uint32_t x117;
7904     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x118;
7905     uint32_t x119;
7906     uint32_t x120;
7907     uint32_t x121;
7908     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x122;
7909     uint32_t x123;
7910     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x124;
7911     uint32_t x125;
7912     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x126;
7913     uint32_t x127;
7914     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x128;
7915     uint32_t x129;
7916     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x130;
7917     uint32_t x131;
7918     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x132;
7919     uint32_t x133;
7920     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x134;
7921     uint32_t x135;
7922     uint32_t x136;
7923     uint32_t x137;
7924     uint32_t x138;
7925     uint32_t x139;
7926     uint32_t x140;
7927     uint32_t x141;
7928     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x142;
7929     uint32_t x143;
7930     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x144;
7931     uint32_t x145;
7932     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x146;
7933     uint32_t x147;
7934     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x148;
7935     uint32_t x149;
7936     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x150;
7937     uint32_t x151;
7938     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x152;
7939     uint32_t x153;
7940     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x154;
7941     uint32_t x155;
7942     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x156;
7943     uint32_t x157;
7944     uint32_t x158;
7945     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x159;
7946     uint32_t x160;
7947     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x161;
7948     uint32_t x162;
7949     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x163;
7950     uint32_t x164;
7951     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x165;
7952     uint32_t x166;
7953     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x167;
7954     uint32_t x168;
7955     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x169;
7956     uint32_t x170;
7957     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x171;
7958     uint32_t x172;
7959     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x173;
7960     uint32_t x174;
7961     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 x175;
7962     uint32_t x176;
7963     uint32_t x177;
7964     uint32_t x178;
7965     uint32_t x179;
7966     uint32_t x180;
7967     uint32_t x181;
7968     uint32_t x182;
7969     uint32_t x183;
7970     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x1, &x2, (arg1[0]),
7971                                                          UINT32_C(0x27acdc4));
7972     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x3, &x4, x1,
7973                                                          UINT32_C(0xa3347857));
7974     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x5, &x6, x3,
7975                                                          UINT32_C(0x80000000));
7976     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x7, &x8, x3,
7977                                                          UINT16_C(0xc99));
7978     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x9, &x10, (arg1[1]),
7979                                                          UINT32_C(0x27acdc4));
7980     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x11, &x12, 0x0,
7981                                                               x1, x7);
7982     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7983         &x13, &x14, 0x0, ((x12 + x2) + x8), x9);
7984     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x15, &x16, x13,
7985                                                          UINT32_C(0xa3347857));
7986     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x17, &x18, x15,
7987                                                          UINT32_C(0x80000000));
7988     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x19, &x20, x15,
7989                                                          UINT16_C(0xc99));
7990     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x21, &x22, 0x0,
7991                                                               x6, x17);
7992     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x23, &x24, (arg1[2]),
7993                                                          UINT32_C(0x27acdc4));
7994     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x25, &x26, 0x0,
7995                                                               x13, x19);
7996     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
7997         &x27, &x28, 0x0, ((x26 + (x14 + x10)) + x20), x23);
7998     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x29, &x30, x27,
7999                                                          UINT32_C(0xa3347857));
8000     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x31, &x32, x29,
8001                                                          UINT32_C(0x80000000));
8002     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x33, &x34, x29,
8003                                                          UINT16_C(0xc99));
8004     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x35, &x36, 0x0,
8005                                                               (x22 + x18), x31);
8006     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x37, &x38, (arg1[3]),
8007                                                          UINT32_C(0x27acdc4));
8008     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x39, &x40, 0x0,
8009                                                               x27, x33);
8010     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
8011         &x41, &x42, 0x0, ((x40 + (x28 + x24)) + x34), x37);
8012     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x43, &x44, x41,
8013                                                          UINT32_C(0xa3347857));
8014     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x45, &x46, x43,
8015                                                          UINT32_C(0x80000000));
8016     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x47, &x48, x43,
8017                                                          UINT16_C(0xc99));
8018     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x49, &x50, 0x0,
8019                                                               (x36 + x32), x45);
8020     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x51, &x52, (arg1[4]),
8021                                                          UINT32_C(0x27acdc4));
8022     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x53, &x54, 0x0,
8023                                                               x41, x47);
8024     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
8025         &x55, &x56, 0x0, ((x54 + (x42 + x38)) + x48), x51);
8026     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x57, &x58, x55,
8027                                                          UINT32_C(0xa3347857));
8028     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x59, &x60, x57,
8029                                                          UINT32_C(0x80000000));
8030     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x61, &x62, x57,
8031                                                          UINT16_C(0xc99));
8032     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x63, &x64, 0x0,
8033                                                               (x50 + x46), x59);
8034     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x65, &x66, (arg1[5]),
8035                                                          UINT32_C(0x27acdc4));
8036     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x67, &x68, 0x0,
8037                                                               x55, x61);
8038     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
8039         &x69, &x70, 0x0, ((x68 + (x56 + x52)) + x62), x65);
8040     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x71, &x72, x69,
8041                                                          UINT32_C(0xa3347857));
8042     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x73, &x74, x71,
8043                                                          UINT32_C(0x80000000));
8044     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x75, &x76, x71,
8045                                                          UINT16_C(0xc99));
8046     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x77, &x78, 0x0,
8047                                                               (x64 + x60), x73);
8048     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x79, &x80, (arg1[6]),
8049                                                          UINT32_C(0x27acdc4));
8050     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x81, &x82, 0x0,
8051                                                               x69, x75);
8052     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
8053         &x83, &x84, 0x0, ((x82 + (x70 + x66)) + x76), x79);
8054     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x85, &x86, x84,
8055                                                               x5, x80);
8056     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x87, &x88, x86,
8057                                                               x21, 0x0);
8058     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x89, &x90, x88,
8059                                                               x35, 0x0);
8060     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x91, &x92, x90,
8061                                                               x49, 0x0);
8062     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x93, &x94, x92,
8063                                                               x63, 0x0);
8064     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x95, &x96, x94,
8065                                                               x77, 0x0);
8066     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x97, &x98, x83,
8067                                                          UINT32_C(0xa3347857));
8068     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x99, &x100, x97,
8069                                                          UINT32_C(0x80000000));
8070     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x101, &x102, x97,
8071                                                          UINT16_C(0xc99));
8072     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x103, &x104, 0x0,
8073                                                               x83, x101);
8074     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x105, &x106,
8075                                                               x104, x85, x102);
8076     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x107, &x108,
8077                                                               x106, x87, 0x0);
8078     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x109, &x110,
8079                                                               x108, x89, 0x0);
8080     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x111, &x112,
8081                                                               x110, x91, 0x0);
8082     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x113, &x114,
8083                                                               x112, x93, 0x0);
8084     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x115, &x116,
8085                                                               x114, x95, 0x0);
8086     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
8087         &x117, &x118, x116, (x96 + (x78 + x74)), x99);
8088     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(
8089         &x119, &x120, (arg1[7]), UINT32_C(0x27acdc4));
8090     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x121, &x122, 0x0,
8091                                                               x105, x119);
8092     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x123, &x124,
8093                                                               x122, x107, x120);
8094     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x125, &x126,
8095                                                               x124, x109, 0x0);
8096     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x127, &x128,
8097                                                               x126, x111, 0x0);
8098     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x129, &x130,
8099                                                               x128, x113, 0x0);
8100     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x131, &x132,
8101                                                               x130, x115, 0x0);
8102     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x133, &x134,
8103                                                               x132, x117, 0x0);
8104     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x135, &x136, x121,
8105                                                          UINT32_C(0xa3347857));
8106     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x137, &x138, x135,
8107                                                          UINT32_C(0x80000000));
8108     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mulx_u32(&x139, &x140, x135,
8109                                                          UINT16_C(0xc99));
8110     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x141, &x142, 0x0,
8111                                                               x121, x139);
8112     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x143, &x144,
8113                                                               x142, x123, x140);
8114     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x145, &x146,
8115                                                               x144, x125, 0x0);
8116     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x147, &x148,
8117                                                               x146, x127, 0x0);
8118     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x149, &x150,
8119                                                               x148, x129, 0x0);
8120     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x151, &x152,
8121                                                               x150, x131, 0x0);
8122     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(&x153, &x154,
8123                                                               x152, x133, 0x0);
8124     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_addcarryx_u32(
8125         &x155, &x156, x154, (x134 + (x118 + x100)), x137);
8126     x157 = (x156 + x138);
8127     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
8128         &x158, &x159, 0x0, x143, UINT16_C(0xc99));
8129     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x160, &x161,
8130                                                                x159, x145, 0x0);
8131     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x162, &x163,
8132                                                                x161, x147, 0x0);
8133     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x164, &x165,
8134                                                                x163, x149, 0x0);
8135     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x166, &x167,
8136                                                                x165, x151, 0x0);
8137     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x168, &x169,
8138                                                                x167, x153, 0x0);
8139     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x170, &x171,
8140                                                                x169, x155, 0x0);
8141     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(
8142         &x172, &x173, x171, x157, UINT32_C(0x80000000));
8143     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_subborrowx_u32(&x174, &x175,
8144                                                                x173, 0x0, 0x0);
8145     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x176, x175, x158,
8146                                                             x143);
8147     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x177, x175, x160,
8148                                                             x145);
8149     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x178, x175, x162,
8150                                                             x147);
8151     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x179, x175, x164,
8152                                                             x149);
8153     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x180, x175, x166,
8154                                                             x151);
8155     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x181, x175, x168,
8156                                                             x153);
8157     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x182, x175, x170,
8158                                                             x155);
8159     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(&x183, x175, x172,
8160                                                             x157);
8161     out1[0] = x176;
8162     out1[1] = x177;
8163     out1[2] = x178;
8164     out1[3] = x179;
8165     out1[4] = x180;
8166     out1[5] = x181;
8167     out1[6] = x182;
8168     out1[7] = x183;
8169 }
8170
8171 /*
8172  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_nonzero outputs a single non-zero word if the input is non-zero and zero otherwise.
8173  * Preconditions:
8174  *   0 ≤ eval arg1 < m
8175  * Postconditions:
8176  *   out1 = 0 ↔ eval (from_montgomery arg1) mod m = 0
8177  *
8178  * Input Bounds:
8179  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
8180  * Output Bounds:
8181  *   out1: [0x0 ~> 0xffffffff]
8182  */
8183 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_nonzero(
8184     uint32_t *out1, const uint32_t arg1[8]) {
8185     uint32_t x1;
8186     x1 =
8187         ((arg1[0]) |
8188          ((arg1[1]) |
8189           ((arg1[2]) |
8190            ((arg1[3]) | ((arg1[4]) | ((arg1[5]) | ((arg1[6]) | (arg1[7]))))))));
8191     *out1 = x1;
8192 }
8193
8194 /*
8195  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz is a multi-limb conditional select.
8196  * Postconditions:
8197  *   eval out1 = (if arg1 = 0 then eval arg2 else eval arg3)
8198  *
8199  * Input Bounds:
8200  *   arg1: [0x0 ~> 0x1]
8201  *   arg2: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
8202  *   arg3: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
8203  * Output Bounds:
8204  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
8205  */
8206 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
8207     uint32_t out1[8], fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_uint1 arg1,
8208     const uint32_t arg2[8], const uint32_t arg3[8]) {
8209     uint32_t x1;
8210     uint32_t x2;
8211     uint32_t x3;
8212     uint32_t x4;
8213     uint32_t x5;
8214     uint32_t x6;
8215     uint32_t x7;
8216     uint32_t x8;
8217     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8218         &x1, arg1, (arg2[0]), (arg3[0]));
8219     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8220         &x2, arg1, (arg2[1]), (arg3[1]));
8221     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8222         &x3, arg1, (arg2[2]), (arg3[2]));
8223     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8224         &x4, arg1, (arg2[3]), (arg3[3]));
8225     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8226         &x5, arg1, (arg2[4]), (arg3[4]));
8227     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8228         &x6, arg1, (arg2[5]), (arg3[5]));
8229     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8230         &x7, arg1, (arg2[6]), (arg3[6]));
8231     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_cmovznz_u32(
8232         &x8, arg1, (arg2[7]), (arg3[7]));
8233     out1[0] = x1;
8234     out1[1] = x2;
8235     out1[2] = x3;
8236     out1[3] = x4;
8237     out1[4] = x5;
8238     out1[5] = x6;
8239     out1[6] = x7;
8240     out1[7] = x8;
8241 }
8242
8243 /*
8244  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes serializes a field element NOT in the Montgomery domain to bytes in little-endian order.
8245  * Preconditions:
8246  *   0 ≤ eval arg1 < m
8247  * Postconditions:
8248  *   out1 = map (λ x, ⌊((eval arg1 mod m) mod 2^(8 * (x + 1))) / 2^(8 * x)⌋) [0..31]
8249  *
8250  * Input Bounds:
8251  *   arg1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
8252  * Output Bounds:
8253  *   out1: [[0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff]]
8254  */
8255 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(
8256     uint8_t out1[32], const uint32_t arg1[8]) {
8257     uint32_t x1;
8258     uint32_t x2;
8259     uint32_t x3;
8260     uint32_t x4;
8261     uint32_t x5;
8262     uint32_t x6;
8263     uint32_t x7;
8264     uint32_t x8;
8265     uint8_t x9;
8266     uint32_t x10;
8267     uint8_t x11;
8268     uint32_t x12;
8269     uint8_t x13;
8270     uint8_t x14;
8271     uint8_t x15;
8272     uint32_t x16;
8273     uint8_t x17;
8274     uint32_t x18;
8275     uint8_t x19;
8276     uint8_t x20;
8277     uint8_t x21;
8278     uint32_t x22;
8279     uint8_t x23;
8280     uint32_t x24;
8281     uint8_t x25;
8282     uint8_t x26;
8283     uint8_t x27;
8284     uint32_t x28;
8285     uint8_t x29;
8286     uint32_t x30;
8287     uint8_t x31;
8288     uint8_t x32;
8289     uint8_t x33;
8290     uint32_t x34;
8291     uint8_t x35;
8292     uint32_t x36;
8293     uint8_t x37;
8294     uint8_t x38;
8295     uint8_t x39;
8296     uint32_t x40;
8297     uint8_t x41;
8298     uint32_t x42;
8299     uint8_t x43;
8300     uint8_t x44;
8301     uint8_t x45;
8302     uint32_t x46;
8303     uint8_t x47;
8304     uint32_t x48;
8305     uint8_t x49;
8306     uint8_t x50;
8307     uint8_t x51;
8308     uint32_t x52;
8309     uint8_t x53;
8310     uint32_t x54;
8311     uint8_t x55;
8312     uint8_t x56;
8313     x1 = (arg1[7]);
8314     x2 = (arg1[6]);
8315     x3 = (arg1[5]);
8316     x4 = (arg1[4]);
8317     x5 = (arg1[3]);
8318     x6 = (arg1[2]);
8319     x7 = (arg1[1]);
8320     x8 = (arg1[0]);
8321     x9 = (uint8_t)(x8 & UINT8_C(0xff));
8322     x10 = (x8 >> 8);
8323     x11 = (uint8_t)(x10 & UINT8_C(0xff));
8324     x12 = (x10 >> 8);
8325     x13 = (uint8_t)(x12 & UINT8_C(0xff));
8326     x14 = (uint8_t)(x12 >> 8);
8327     x15 = (uint8_t)(x7 & UINT8_C(0xff));
8328     x16 = (x7 >> 8);
8329     x17 = (uint8_t)(x16 & UINT8_C(0xff));
8330     x18 = (x16 >> 8);
8331     x19 = (uint8_t)(x18 & UINT8_C(0xff));
8332     x20 = (uint8_t)(x18 >> 8);
8333     x21 = (uint8_t)(x6 & UINT8_C(0xff));
8334     x22 = (x6 >> 8);
8335     x23 = (uint8_t)(x22 & UINT8_C(0xff));
8336     x24 = (x22 >> 8);
8337     x25 = (uint8_t)(x24 & UINT8_C(0xff));
8338     x26 = (uint8_t)(x24 >> 8);
8339     x27 = (uint8_t)(x5 & UINT8_C(0xff));
8340     x28 = (x5 >> 8);
8341     x29 = (uint8_t)(x28 & UINT8_C(0xff));
8342     x30 = (x28 >> 8);
8343     x31 = (uint8_t)(x30 & UINT8_C(0xff));
8344     x32 = (uint8_t)(x30 >> 8);
8345     x33 = (uint8_t)(x4 & UINT8_C(0xff));
8346     x34 = (x4 >> 8);
8347     x35 = (uint8_t)(x34 & UINT8_C(0xff));
8348     x36 = (x34 >> 8);
8349     x37 = (uint8_t)(x36 & UINT8_C(0xff));
8350     x38 = (uint8_t)(x36 >> 8);
8351     x39 = (uint8_t)(x3 & UINT8_C(0xff));
8352     x40 = (x3 >> 8);
8353     x41 = (uint8_t)(x40 & UINT8_C(0xff));
8354     x42 = (x40 >> 8);
8355     x43 = (uint8_t)(x42 & UINT8_C(0xff));
8356     x44 = (uint8_t)(x42 >> 8);
8357     x45 = (uint8_t)(x2 & UINT8_C(0xff));
8358     x46 = (x2 >> 8);
8359     x47 = (uint8_t)(x46 & UINT8_C(0xff));
8360     x48 = (x46 >> 8);
8361     x49 = (uint8_t)(x48 & UINT8_C(0xff));
8362     x50 = (uint8_t)(x48 >> 8);
8363     x51 = (uint8_t)(x1 & UINT8_C(0xff));
8364     x52 = (x1 >> 8);
8365     x53 = (uint8_t)(x52 & UINT8_C(0xff));
8366     x54 = (x52 >> 8);
8367     x55 = (uint8_t)(x54 & UINT8_C(0xff));
8368     x56 = (uint8_t)(x54 >> 8);
8369     out1[0] = x9;
8370     out1[1] = x11;
8371     out1[2] = x13;
8372     out1[3] = x14;
8373     out1[4] = x15;
8374     out1[5] = x17;
8375     out1[6] = x19;
8376     out1[7] = x20;
8377     out1[8] = x21;
8378     out1[9] = x23;
8379     out1[10] = x25;
8380     out1[11] = x26;
8381     out1[12] = x27;
8382     out1[13] = x29;
8383     out1[14] = x31;
8384     out1[15] = x32;
8385     out1[16] = x33;
8386     out1[17] = x35;
8387     out1[18] = x37;
8388     out1[19] = x38;
8389     out1[20] = x39;
8390     out1[21] = x41;
8391     out1[22] = x43;
8392     out1[23] = x44;
8393     out1[24] = x45;
8394     out1[25] = x47;
8395     out1[26] = x49;
8396     out1[27] = x50;
8397     out1[28] = x51;
8398     out1[29] = x53;
8399     out1[30] = x55;
8400     out1[31] = x56;
8401 }
8402
8403 /*
8404  * The function fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes deserializes a field element NOT in the Montgomery domain from bytes in little-endian order.
8405  * Preconditions:
8406  *   0 ≤ bytes_eval arg1 < m
8407  * Postconditions:
8408  *   eval out1 mod m = bytes_eval arg1 mod m
8409  *   0 ≤ eval out1 < m
8410  *
8411  * Input Bounds:
8412  *   arg1: [[0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff], [0x0 ~> 0xff]]
8413  * Output Bounds:
8414  *   out1: [[0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff], [0x0 ~> 0xffffffff]]
8415  */
8416 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(
8417     uint32_t out1[8], const uint8_t arg1[32]) {
8418     uint32_t x1;
8419     uint32_t x2;
8420     uint32_t x3;
8421     uint8_t x4;
8422     uint32_t x5;
8423     uint32_t x6;
8424     uint32_t x7;
8425     uint8_t x8;
8426     uint32_t x9;
8427     uint32_t x10;
8428     uint32_t x11;
8429     uint8_t x12;
8430     uint32_t x13;
8431     uint32_t x14;
8432     uint32_t x15;
8433     uint8_t x16;
8434     uint32_t x17;
8435     uint32_t x18;
8436     uint32_t x19;
8437     uint8_t x20;
8438     uint32_t x21;
8439     uint32_t x22;
8440     uint32_t x23;
8441     uint8_t x24;
8442     uint32_t x25;
8443     uint32_t x26;
8444     uint32_t x27;
8445     uint8_t x28;
8446     uint32_t x29;
8447     uint32_t x30;
8448     uint32_t x31;
8449     uint8_t x32;
8450     uint32_t x33;
8451     uint32_t x34;
8452     uint32_t x35;
8453     uint32_t x36;
8454     uint32_t x37;
8455     uint32_t x38;
8456     uint32_t x39;
8457     uint32_t x40;
8458     uint32_t x41;
8459     uint32_t x42;
8460     uint32_t x43;
8461     uint32_t x44;
8462     uint32_t x45;
8463     uint32_t x46;
8464     uint32_t x47;
8465     uint32_t x48;
8466     uint32_t x49;
8467     uint32_t x50;
8468     uint32_t x51;
8469     uint32_t x52;
8470     uint32_t x53;
8471     uint32_t x54;
8472     uint32_t x55;
8473     uint32_t x56;
8474     x1 = ((uint32_t)(arg1[31]) << 24);
8475     x2 = ((uint32_t)(arg1[30]) << 16);
8476     x3 = ((uint32_t)(arg1[29]) << 8);
8477     x4 = (arg1[28]);
8478     x5 = ((uint32_t)(arg1[27]) << 24);
8479     x6 = ((uint32_t)(arg1[26]) << 16);
8480     x7 = ((uint32_t)(arg1[25]) << 8);
8481     x8 = (arg1[24]);
8482     x9 = ((uint32_t)(arg1[23]) << 24);
8483     x10 = ((uint32_t)(arg1[22]) << 16);
8484     x11 = ((uint32_t)(arg1[21]) << 8);
8485     x12 = (arg1[20]);
8486     x13 = ((uint32_t)(arg1[19]) << 24);
8487     x14 = ((uint32_t)(arg1[18]) << 16);
8488     x15 = ((uint32_t)(arg1[17]) << 8);
8489     x16 = (arg1[16]);
8490     x17 = ((uint32_t)(arg1[15]) << 24);
8491     x18 = ((uint32_t)(arg1[14]) << 16);
8492     x19 = ((uint32_t)(arg1[13]) << 8);
8493     x20 = (arg1[12]);
8494     x21 = ((uint32_t)(arg1[11]) << 24);
8495     x22 = ((uint32_t)(arg1[10]) << 16);
8496     x23 = ((uint32_t)(arg1[9]) << 8);
8497     x24 = (arg1[8]);
8498     x25 = ((uint32_t)(arg1[7]) << 24);
8499     x26 = ((uint32_t)(arg1[6]) << 16);
8500     x27 = ((uint32_t)(arg1[5]) << 8);
8501     x28 = (arg1[4]);
8502     x29 = ((uint32_t)(arg1[3]) << 24);
8503     x30 = ((uint32_t)(arg1[2]) << 16);
8504     x31 = ((uint32_t)(arg1[1]) << 8);
8505     x32 = (arg1[0]);
8506     x33 = (x31 + (uint32_t)x32);
8507     x34 = (x30 + x33);
8508     x35 = (x29 + x34);
8509     x36 = (x27 + (uint32_t)x28);
8510     x37 = (x26 + x36);
8511     x38 = (x25 + x37);
8512     x39 = (x23 + (uint32_t)x24);
8513     x40 = (x22 + x39);
8514     x41 = (x21 + x40);
8515     x42 = (x19 + (uint32_t)x20);
8516     x43 = (x18 + x42);
8517     x44 = (x17 + x43);
8518     x45 = (x15 + (uint32_t)x16);
8519     x46 = (x14 + x45);
8520     x47 = (x13 + x46);
8521     x48 = (x11 + (uint32_t)x12);
8522     x49 = (x10 + x48);
8523     x50 = (x9 + x49);
8524     x51 = (x7 + (uint32_t)x8);
8525     x52 = (x6 + x51);
8526     x53 = (x5 + x52);
8527     x54 = (x3 + (uint32_t)x4);
8528     x55 = (x2 + x54);
8529     x56 = (x1 + x55);
8530     out1[0] = x35;
8531     out1[1] = x38;
8532     out1[2] = x41;
8533     out1[3] = x44;
8534     out1[4] = x47;
8535     out1[5] = x50;
8536     out1[6] = x53;
8537     out1[7] = x56;
8538 }
8539
8540 /* END verbatim fiat code */
8541
8542 /*-
8543  * Finite field inversion via FLT.
8544  * NB: this is not a real Fiat function, just named that way for consistency.
8545  * Autogenerated: ecp/id_GostR3410_2001_CryptoPro_B_ParamSet/fe_inv.op3
8546  * sliding window w=5
8547  */
8548 static void fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(fe_t output,
8549                                                             const fe_t t1) {
8550     int i;
8551     /* temporary variables */
8552     fe_t acc, t23, t25;
8553
8554     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, t1);
8555     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t25, t1, acc);
8556     for (i = 0; i < 9; i++)
8557         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t25, t25, acc);
8558     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t23, t25, acc);
8559     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t25, t23, acc);
8560     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, t1);
8561     for (i = 0; i < 247; i++)
8562         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, acc);
8563     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(acc, acc, t25);
8564     for (i = 0; i < 7; i++)
8565         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(acc, acc);
8566     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(output, acc, t23);
8567 }
8568
8569 /* curve coefficient constants */
8570
8571 static const limb_t const_one[8] = {UINT32_C(0xFFFFF367), UINT32_C(0xFFFFFFFF),
8572                                     UINT32_C(0xFFFFFFFF), UINT32_C(0xFFFFFFFF),
8573                                     UINT32_C(0xFFFFFFFF), UINT32_C(0xFFFFFFFF),
8574                                     UINT32_C(0xFFFFFFFF), UINT32_C(0x7FFFFFFF)};
8575
8576 static const limb_t const_b[8] = {UINT32_C(0xA9C5A084), UINT32_C(0x8DCC455A),
8577                                   UINT32_C(0x6CF438A8), UINT32_C(0x91AB42DF),
8578                                   UINT32_C(0xEEAC7D11), UINT32_C(0x8F8AA907),
8579                                   UINT32_C(0xF6285375), UINT32_C(0x3CE5D221)};
8580
8581 /* LUT for scalar multiplication by comb interleaving */
8582 static const pt_aff_t lut_cmb[27][16] = {
8583     {
8584         {{UINT32_C(0xFFFFF367), UINT32_C(0xFFFFFFFF), UINT32_C(0xFFFFFFFF),
8585           UINT32_C(0xFFFFFFFF), UINT32_C(0xFFFFFFFF), UINT32_C(0xFFFFFFFF),
8586           UINT32_C(0xFFFFFFFF), UINT32_C(0x7FFFFFFF)},
8587          {UINT32_C(0x570C7410), UINT32_C(0xDDDC64B3), UINT32_C(0x13172887),
8588           UINT32_C(0xA7B09925), UINT32_C(0x4B6382DB), UINT32_C(0x0C4E5C4C),
8589           UINT32_C(0x124768DE), UINT32_C(0x2763DB0F)}},
8590         {{UINT32_C(0x8457D15D), UINT32_C(0xCD3E57B6), UINT32_C(0xBEA56E83),
8591           UINT32_C(0xEB688F7F), UINT32_C(0x6A13C5CE), UINT32_C(0x235A123C),
8592           UINT32_C(0x50F57A6D), UINT32_C(0x0CD7EB9D)},
8593          {UINT32_C(0x544C1965), UINT32_C(0xC0124E91), UINT32_C(0x62AFA35E),
8594           UINT32_C(0x4D9C1729), UINT32_C(0x0037C554), UINT32_C(0x0F92F2C3),
8595           UINT32_C(0x0A3F2665), UINT32_C(0x1D899868)}},
8596         {{UINT32_C(0x55F43EFF), UINT32_C(0x9DE4B213), UINT32_C(0x5C9E63F5),
8597           UINT32_C(0x2E110A42), UINT32_C(0x1CE5A6DF), UINT32_C(0x9350A9C3),
8598           UINT32_C(0xA332315E), UINT32_C(0x377CBF0B)},
8599          {UINT32_C(0x20F0D1B5), UINT32_C(0x2805DD48), UINT32_C(0x0F9723E5),
8600           UINT32_C(0x3B197566), UINT32_C(0x84B79937), UINT32_C(0xA1CCA78C),
8601           UINT32_C(0x94D5E03D), UINT32_C(0x4F87BB1B)}},
8602         {{UINT32_C(0x5652C96F), UINT32_C(0xE428FBFB), UINT32_C(0xD261BDD1),
8603           UINT32_C(0x2E9A14D2), UINT32_C(0x7453B76A), UINT32_C(0x082D8296),
8604           UINT32_C(0x7AC87B02), UINT32_C(0x61EA580E)},
8605          {UINT32_C(0xCF368FDB), UINT32_C(0xA0F8C2BA), UINT32_C(0xD73B2A28),
8606           UINT32_C(0xDF093380), UINT32_C(0xEA8FE5D2), UINT32_C(0xFA0928B2),
8607           UINT32_C(0x5F86D38A), UINT32_C(0x77A67492)}},
8608         {{UINT32_C(0x27670451), UINT32_C(0xDFFAB410), UINT32_C(0x1200AD3A),
8609           UINT32_C(0xEBC3D017), UINT32_C(0x25F4F6C4), UINT32_C(0xF68324F3),
8610           UINT32_C(0x7D0EAFD0), UINT32_C(0x4A24CD5F)},
8611          {UINT32_C(0xD3F6BD1C), UINT32_C(0xF8FBD489), UINT32_C(0x67B473DE),
8612           UINT32_C(0x0F6B56D5), UINT32_C(0xCACF0D6B), UINT32_C(0x6FB063DE),
8613           UINT32_C(0x96DC574B), UINT32_C(0x27F2E7E9)}},
8614         {{UINT32_C(0x93937228), UINT32_C(0xA6A10645), UINT32_C(0xA9165BBB),
8615           UINT32_C(0xAB7550B4), UINT32_C(0xCB0EDBE8), UINT32_C(0xD682D4F1),
8616           UINT32_C(0x40E5AD8D), UINT32_C(0x2261FCEC)},
8617          {UINT32_C(0xCCBD4E18), UINT32_C(0x9F2119C6), UINT32_C(0xAAB09697),
8618           UINT32_C(0x2FD094E9), UINT32_C(0xE700929E), UINT32_C(0x00331713),
8619           UINT32_C(0x54338FE1), UINT32_C(0x6C5F2EFE)}},
8620         {{UINT32_C(0x42FFF78A), UINT32_C(0xD6314017), UINT32_C(0x2087E055),
8621           UINT32_C(0x38F23A91), UINT32_C(0x10EF1CAC), UINT32_C(0xE30E809C),
8622           UINT32_C(0x2432FF74), UINT32_C(0x3BCB0A54)},
8623          {UINT32_C(0xB31509E6), UINT32_C(0x2B4B5B97), UINT32_C(0x3E54AF47),
8624           UINT32_C(0x117FE9D7), UINT32_C(0x52F63ACA), UINT32_C(0xE513C0BE),
8625           UINT32_C(0xB1C80A6B), UINT32_C(0x41ED8ADA)}},
8626         {{UINT32_C(0xE0A79FCD), UINT32_C(0x61A31837), UINT32_C(0x51D3DE38),
8627           UINT32_C(0x8F742B57), UINT32_C(0x41354B55), UINT32_C(0x10635FCD),
8628           UINT32_C(0x946510BE), UINT32_C(0x61F30C61)},
8629          {UINT32_C(0x6C416DAC), UINT32_C(0x9183D677), UINT32_C(0x345431CB),
8630           UINT32_C(0x391B7B42), UINT32_C(0x7C254A8D), UINT32_C(0xE3D6F084),
8631           UINT32_C(0x19D320D8), UINT32_C(0x777E1F62)}},
8632         {{UINT32_C(0xF05BD85D), UINT32_C(0x090E633F), UINT32_C(0x240392ED),
8633           UINT32_C(0x546C41A0), UINT32_C(0x9F4139CA), UINT32_C(0x6BBCF15D),
8634           UINT32_C(0x7FFDA5DA), UINT32_C(0x73F5B657)},
8635          {UINT32_C(0xE0622A57), UINT32_C(0xBC04E353), UINT32_C(0x6E6414F4),
8636           UINT32_C(0xCBD8F01E), UINT32_C(0x8C3C0CC5), UINT32_C(0x53377C0B),
8637           UINT32_C(0xE0A14548), UINT32_C(0x6D302331)}},
8638         {{UINT32_C(0x3D6D456E), UINT32_C(0x235487F8), UINT32_C(0xB3FDCDCF),
8639           UINT32_C(0xBD92203D), UINT32_C(0xCFFDA977), UINT32_C(0x15B13D60),
8640           UINT32_C(0x31A1C4B5), UINT32_C(0x22DCB487)},
8641          {UINT32_C(0xC76ED9A2), UINT32_C(0xA367FB4E), UINT32_C(0xC0C86AF4),
8642           UINT32_C(0x1E4F7956), UINT32_C(0x5B012AD7), UINT32_C(0x6F087C49),
8643           UINT32_C(0x4949B444), UINT32_C(0x33437E4A)}},
8644         {{UINT32_C(0xB7CDDB38), UINT32_C(0x261B44FE), UINT32_C(0x419216AD),
8645           UINT32_C(0xDCE2FE47), UINT32_C(0x9428657B), UINT32_C(0xA4CE17FF),
8646           UINT32_C(0xF8329049), UINT32_C(0x7CE64F48)},
8647          {UINT32_C(0x7289C114), UINT32_C(0x4CE74211), UINT32_C(0x8C212A23),
8648           UINT32_C(0x0E622409), UINT32_C(0x2096719D), UINT32_C(0xCF75BF45),
8649           UINT32_C(0x7BDC1600), UINT32_C(0x6F553581)}},
8650         {{UINT32_C(0xB941CBC9), UINT32_C(0xE776AA0C), UINT32_C(0x951AAED3),
8651           UINT32_C(0x16D670E0), UINT32_C(0x4B1EC097), UINT32_C(0x79C019DF),
8652           UINT32_C(0x12266D30), UINT32_C(0x635A66BB)},
8653          {UINT32_C(0x023AAFD2), UINT32_C(0x030D843E), UINT32_C(0x6466108F),
8654           UINT32_C(0x10FB6157), UINT32_C(0x08D568D5), UINT32_C(0x93774BEC),
8655           UINT32_C(0x04C1EE73), UINT32_C(0x29D27962)}},
8656         {{UINT32_C(0xE00BBC21), UINT32_C(0x6F0F4C2E), UINT32_C(0xA30AB92F),
8657           UINT32_C(0x9EB34C58), UINT32_C(0xAE34908B), UINT32_C(0x2153D901),
8658           UINT32_C(0x4EDC188F), UINT32_C(0x136A7E1F)},
8659          {UINT32_C(0x8BC45EE4), UINT32_C(0xF709BF5D), UINT32_C(0x4FAD9A54),
8660           UINT32_C(0xEA6984E4), UINT32_C(0xAF5140EB), UINT32_C(0xFC8E6F8A),
8661           UINT32_C(0x87756E47), UINT32_C(0x25EBF0DE)}},
8662         {{UINT32_C(0x5B1D4B9F), UINT32_C(0x5C2A9726), UINT32_C(0x68E93FC7),
8663           UINT32_C(0xBE235DFD), UINT32_C(0x471A4EA0), UINT32_C(0x7766BDB9),
8664           UINT32_C(0xD9909CD9), UINT32_C(0x476D17CC)},
8665          {UINT32_C(0x7B398BC4), UINT32_C(0x4960E5B4), UINT32_C(0x0F58F328),
8666           UINT32_C(0x909D0F17), UINT32_C(0x230EF508), UINT32_C(0x1ABF7E02),
8667           UINT32_C(0xD29239C9), UINT32_C(0x6DE6B3E1)}},
8668         {{UINT32_C(0x85A6DBE3), UINT32_C(0xCCF0AA28), UINT32_C(0x823C606C),
8669           UINT32_C(0xA5E4B325), UINT32_C(0x15505FC6), UINT32_C(0xADE98B2A),
8670           UINT32_C(0x02E20C3B), UINT32_C(0x4D4E7703)},
8671          {UINT32_C(0x4730DF64), UINT32_C(0x24196417), UINT32_C(0xA914A59D),
8672           UINT32_C(0x3DD47817), UINT32_C(0xC4FDFD97), UINT32_C(0x4D7A317E),
8673           UINT32_C(0xBE12AA72), UINT32_C(0x3767E545)}},
8674         {{UINT32_C(0x165C7BF4), UINT32_C(0xA0C2A028), UINT32_C(0x36A0B483),
8675           UINT32_C(0xCD4DA6EA), UINT32_C(0x3AF53195), UINT32_C(0x1E1E6332),
8676           UINT32_C(0x8D77188F), UINT32_C(0x7A025E23)},
8677          {UINT32_C(0x08D2CEF2), UINT32_C(0xB3CF03B9), UINT32_C(0x25A0AFA6),
8678           UINT32_C(0x8FEE9BB8), UINT32_C(0x88111895), UINT32_C(0x855340E0),
8679           UINT32_C(0x4FB8F8A3), UINT32_C(0x32E3EF01)}},
8680     },
8681     {
8682         {{UINT32_C(0xEBF87807), UINT32_C(0x33EBE39D), UINT32_C(0xDBDEFF76),
8683           UINT32_C(0xB048F96C), UINT32_C(0x342A3087), UINT32_C(0xA0496C3C),
8684           UINT32_C(0x50953679), UINT32_C(0x7623E192)},
8685          {UINT32_C(0x4B932390), UINT32_C(0x12F76711), UINT32_C(0xACECE2F7),
8686           UINT32_C(0xF80851EA), UINT32_C(0xE5B280EA), UINT32_C(0xE447465B),
8687           UINT32_C(0x11115958), UINT32_C(0x0412ADE8)}},
8688         {{UINT32_C(0xB5EB0DC2), UINT32_C(0x982F1AC8), UINT32_C(0xBBBCC880),
8689           UINT32_C(0x8464E052), UINT32_C(0x01335D53), UINT32_C(0xC927B596),
8690           UINT32_C(0x4DA4D80B), UINT32_C(0x4B0C6F5A)},
8691          {UINT32_C(0xE04783AF), UINT32_C(0x101E1878), UINT32_C(0x41D8A690),
8692           UINT32_C(0x50458FFC), UINT32_C(0x1B77DFBF), UINT32_C(0x11499D88),
8693           UINT32_C(0x1F77A937), UINT32_C(0x46DC7D22)}},
8694         {{UINT32_C(0x620E52C0), UINT32_C(0xE9AD22CE), UINT32_C(0x4140F356),
8695           UINT32_C(0x0990D6AA), UINT32_C(0x0CBBEEE5), UINT32_C(0x0F6B2EF7),
8696           UINT32_C(0xEAD414C6), UINT32_C(0x2C67DC80)},
8697          {UINT32_C(0x23D4CD20), UINT32_C(0xE17182BC), UINT32_C(0xC13DDEA9),
8698           UINT32_C(0xFC8FE3CB), UINT32_C(0x3BABC06D), UINT32_C(0xD1E4A7B8),
8699           UINT32_C(0x71C06DB7), UINT32_C(0x52EA05CC)}},
8700         {{UINT32_C(0x0D022B5B), UINT32_C(0xF8ABB770), UINT32_C(0x199DC689),
8701           UINT32_C(0x362B8059), UINT32_C(0x26BBDEC8), UINT32_C(0x5D887A4D),
8702           UINT32_C(0xF7FC2A01), UINT32_C(0x7835F183)},
8703          {UINT32_C(0xDE99DF34), UINT32_C(0xEEDE12F5), UINT32_C(0xA3082301),
8704           UINT32_C(0xBE952638), UINT32_C(0x4C35A162), UINT32_C(0x829FDF80),
8705           UINT32_C(0xC2B9645E), UINT32_C(0x205A2252)}},
8706         {{UINT32_C(0x1356E14C), UINT32_C(0xDE284DA9), UINT32_C(0xC37415FE),
8707           UINT32_C(0xE40CEFE0), UINT32_C(0x47F6016E), UINT32_C(0x62BE93E9),
8708           UINT32_C(0x5DBFE2F6), UINT32_C(0x2DD98904)},
8709          {UINT32_C(0x2EBC70F9), UINT32_C(0x195B0E98), UINT32_C(0xF01F4D43),
8710           UINT32_C(0x7E52840D), UINT32_C(0x4B1F6AB4), UINT32_C(0x1AFB1FDF),
8711           UINT32_C(0x20B3E491), UINT32_C(0x050AABB8)}},
8712         {{UINT32_C(0xC645DAD4), UINT32_C(0xC59E1EDB), UINT32_C(0x565A286D),
8713           UINT32_C(0x5AF6B2DC), UINT32_C(0x13076366), UINT32_C(0xC399A48A),
8714           UINT32_C(0x4AC0E5B9), UINT32_C(0x19F4881F)},
8715          {UINT32_C(0xCD5AC339), UINT32_C(0xC07D02A1), UINT32_C(0xED628A55),
8716           UINT32_C(0x18FBD088), UINT32_C(0xFFA4788E), UINT32_C(0x2D33C6F4),
8717           UINT32_C(0xCCB832E7), UINT32_C(0x52E9AE42)}},
8718         {{UINT32_C(0x4E5E934E), UINT32_C(0xA47091AE), UINT32_C(0x91CED3C6),
8719           UINT32_C(0x2542CE13), UINT32_C(0x8FC47857), UINT32_C(0xDDE01FD5),
8720           UINT32_C(0x4304EAA9), UINT32_C(0x6BA6E569)},
8721          {UINT32_C(0xE24091A9), UINT32_C(0x2FF0278B), UINT32_C(0x782BBCE0),
8722           UINT32_C(0xB895F0AB), UINT32_C(0xAB8B8828), UINT32_C(0xA80CCC97),
8723           UINT32_C(0x68A7D8FE), UINT32_C(0x6A54B961)}},
8724         {{UINT32_C(0xBAC4581A), UINT32_C(0x15E1F5AD), UINT32_C(0xD4BAA751),
8725           UINT32_C(0x91620EF0), UINT32_C(0xC7273C4D), UINT32_C(0x4E65731F),
8726           UINT32_C(0x7EEE33B5), UINT32_C(0x14B166CB)},
8727          {UINT32_C(0x3CD06080), UINT32_C(0x7B0EFFA5), UINT32_C(0x8CF95FF9),
8728           UINT32_C(0x4491156A), UINT32_C(0xE2258574), UINT32_C(0xC8C64C39),
8729           UINT32_C(0x13315CE9), UINT32_C(0x3D48DA9D)}},
8730         {{UINT32_C(0x99866CE5), UINT32_C(0x97A098A3), UINT32_C(0x023A1167),
8731           UINT32_C(0xF4CCDB40), UINT32_C(0xF8094782), UINT32_C(0x4BB32981),
8732           UINT32_C(0xC7D5FD13), UINT32_C(0x7342CC98)},
8733          {UINT32_C(0x78B99D4E), UINT32_C(0x3C1C5B18), UINT32_C(0xF4762AC9),
8734           UINT32_C(0x1277668F), UINT32_C(0x6AE50E4F), UINT32_C(0x612431D7),
8735           UINT32_C(0x36F9071C), UINT32_C(0x36C174E0)}},
8736         {{UINT32_C(0x9327BA7F), UINT32_C(0x39194E87), UINT32_C(0x7237FA1A),
8737           UINT32_C(0xC4D251FF), UINT32_C(0x2BA5EB8D), UINT32_C(0x55ED3CD4),
8738           UINT32_C(0xBA590188), UINT32_C(0x0263AF07)},
8739          {UINT32_C(0xEFA82CF3), UINT32_C(0xB4853127), UINT32_C(0x2B8E761D),
8740           UINT32_C(0x2CC2D220), UINT32_C(0x2722B490), UINT32_C(0x4582B81E),
8741           UINT32_C(0x610AA621), UINT32_C(0x1DA7680A)}},
8742         {{UINT32_C(0x30D297D4), UINT32_C(0x06A669EE), UINT32_C(0xE133D393),
8743           UINT32_C(0xC336B048), UINT32_C(0x93B7B41B), UINT32_C(0xB733A2C4),
8744           UINT32_C(0xC7A8E721), UINT32_C(0x427CC233)},
8745          {UINT32_C(0x2867BB00), UINT32_C(0x727C14F1), UINT32_C(0xA736035E),
8746           UINT32_C(0x756F4C7A), UINT32_C(0x26327A22), UINT32_C(0xB72A3EDE),
8747           UINT32_C(0x77F73F28), UINT32_C(0x4AEDE2BB)}},
8748         {{UINT32_C(0xA7282ED0), UINT32_C(0xC8A3612F), UINT32_C(0xB0150579),
8749           UINT32_C(0xE4AD8B40), UINT32_C(0x0C3FEE4B), UINT32_C(0xAB1DE11D),
8750           UINT32_C(0x33B31F23), UINT32_C(0x613AAD48)},
8751          {UINT32_C(0x5C91BD21), UINT32_C(0xE74AB856), UINT32_C(0x7953D695),
8752           UINT32_C(0x49917735), UINT32_C(0x1A53D74F), UINT32_C(0x3831EB60),
8753           UINT32_C(0x54DEB1A6), UINT32_C(0x245977A0)}},
8754         {{UINT32_C(0xFFFC1468), UINT32_C(0x15972E4D), UINT32_C(0x141DC24C),
8755           UINT32_C(0xA758D9CB), UINT32_C(0xED8694C5), UINT32_C(0x5E76FCDF),
8756           UINT32_C(0x069B7A5E), UINT32_C(0x5F9DAF35)},
8757          {UINT32_C(0x501B5415), UINT32_C(0xFE50FCE4), UINT32_C(0x58CFDE50),
8758           UINT32_C(0x6442CF67), UINT32_C(0x38E5F4D0), UINT32_C(0xA89C6DB4),
8759           UINT32_C(0xF5D4FEFC), UINT32_C(0x21F012DB)}},
8760         {{UINT32_C(0x98CB9A81), UINT32_C(0x2A1170AD), UINT32_C(0x036C5E45),
8761           UINT32_C(0x934BD9D5), UINT32_C(0xCA5095B1), UINT32_C(0x27DF152E),
8762           UINT32_C(0xCCEEE508), UINT32_C(0x682698DB)},
8763          {UINT32_C(0xB973FB5F), UINT32_C(0x1F4FE3A2), UINT32_C(0x792C7D4D),
8764           UINT32_C(0xD33CBEBE), UINT32_C(0xE7B33A8F), UINT32_C(0x99D37961),
8765           UINT32_C(0x7B6D015D), UINT32_C(0x46B8993B)}},
8766         {{UINT32_C(0x6FBAC8F7), UINT32_C(0x93A3809B), UINT32_C(0x97C55DC4),
8767           UINT32_C(0x84861BF0), UINT32_C(0x15BB65E3), UINT32_C(0xA6F89EEA),
8768           UINT32_C(0xA6E531D1), UINT32_C(0x66AE1C5D)},
8769          {UINT32_C(0xFD83DAEA), UINT32_C(0x643A14FC), UINT32_C(0xC585947B),
8770           UINT32_C(0xA7A46D0D), UINT32_C(0x4FBA1274), UINT32_C(0xFA20CF07),
8771           UINT32_C(0x93578A7D), UINT32_C(0x5999ED7B)}},
8772         {{UINT32_C(0x78E7C6CE), UINT32_C(0x36C8B6ED), UINT32_C(0x5E325F44),
8773           UINT32_C(0x6D400CA5), UINT32_C(0x20B7AA5C), UINT32_C(0xC6AE09B3),
8774           UINT32_C(0x89EABC17), UINT32_C(0x1AF261C1)},
8775          {UINT32_C(0xB9E778E4), UINT32_C(0x64D6FFBB), UINT32_C(0x7FC64BEB),
8776           UINT32_C(0x1C9E223E), UINT32_C(0x5D75E6C0), UINT32_C(0x4D68B520),
8777           UINT32_C(0x76677A06), UINT32_C(0x5A72B1D9)}},
8778     },
8779     {
8780         {{UINT32_C(0x6F08BB17), UINT32_C(0x62DB6640), UINT32_C(0xAE75BB73),
8781           UINT32_C(0xC34F29DF), UINT32_C(0x7DBD4851), UINT32_C(0xD501293D),
8782           UINT32_C(0xAD1F604B), UINT32_C(0x5EAA94CA)},
8783          {UINT32_C(0x094408A8), UINT32_C(0x39CFE9D1), UINT32_C(0xE8A476F2),
8784           UINT32_C(0xC0F6544C), UINT32_C(0xA42D7607), UINT32_C(0x9F6308B6),
8785           UINT32_C(0xD727018F), UINT32_C(0x17F82949)}},
8786         {{UINT32_C(0x9C4C4BD2), UINT32_C(0xC44453CD), UINT32_C(0xEBD0B947),
8787           UINT32_C(0xA895E247), UINT32_C(0xAEBC27F4), UINT32_C(0x0AEB7AFC),
8788           UINT32_C(0xF04ABFAC), UINT32_C(0x2472FD08)},
8789          {UINT32_C(0x73E6E994), UINT32_C(0x319EC67D), UINT32_C(0x798C5FC0),
8790           UINT32_C(0xD6533E4C), UINT32_C(0x3FB9AA89), UINT32_C(0xF4C3B24D),
8791           UINT32_C(0x0A3B376B), UINT32_C(0x3EC58082)}},
8792         {{UINT32_C(0x144ACF7A), UINT32_C(0x79732D6F), UINT32_C(0x911342DD),
8793           UINT32_C(0xFDD630C3), UINT32_C(0x4A630649), UINT32_C(0xC577C4B3),
8794           UINT32_C(0xBBA999D6), UINT32_C(0x14956A17)},
8795          {UINT32_C(0xA435A559), UINT32_C(0x523D3CC8), UINT32_C(0xACDA8861),
8796           UINT32_C(0x488DC690), UINT32_C(0xF051C69A), UINT32_C(0x4CF70928),
8797           UINT32_C(0x955394CB), UINT32_C(0x2D98D573)}},
8798         {{UINT32_C(0x23A4B840), UINT32_C(0xEDB7BA2A), UINT32_C(0xF6C2D93B),
8799           UINT32_C(0x725EC496), UINT32_C(0x8833BB3F), UINT32_C(0x0C94818B),
8800           UINT32_C(0xB142B12A), UINT32_C(0x51281A31)},
8801          {UINT32_C(0x659EDA83), UINT32_C(0x2A8A5706), UINT32_C(0x7F9D6877),
8802           UINT32_C(0x3098F750), UINT32_C(0x2171F69F), UINT32_C(0x87AD0FDF),
8803           UINT32_C(0x1A6F2F28), UINT32_C(0x6B7067C3)}},
8804         {{UINT32_C(0x12B1E36F), UINT32_C(0x3B521074), UINT32_C(0xF81E4733),
8805           UINT32_C(0x727A2432), UINT32_C(0x53F2CBBD), UINT32_C(0xB75A2F35),
8806           UINT32_C(0x54960EB0), UINT32_C(0x46DE9338)},
8807          {UINT32_C(0xE561D908), UINT32_C(0xAC5344F8), UINT32_C(0x12C67430),
8808           UINT32_C(0x4BD40ECB), UINT32_C(0xEF499F97), UINT32_C(0x1698FD62),
8809           UINT32_C(0x6AE9FBD1), UINT32_C(0x29EBD7AE)}},
8810         {{UINT32_C(0x1EC8110D), UINT32_C(0x9DEC249B), UINT32_C(0xFD2F5C39),
8811           UINT32_C(0x2D19053A), UINT32_C(0xE01522DF), UINT32_C(0xB1189807),
8812           UINT32_C(0xC1424C77), UINT32_C(0x24A04C16)},
8813          {UINT32_C(0x24F72226), UINT32_C(0xA4FC7C7D), UINT32_C(0xA8322501),
8814           UINT32_C(0x763405FB), UINT32_C(0x18F015E0), UINT32_C(0xC5443C9A),
8815           UINT32_C(0xC55D6CEA), UINT32_C(0x6DEDA19B)}},
8816         {{UINT32_C(0x9EAE2FF9), UINT32_C(0x4EF30976), UINT32_C(0x5741B21B),
8817           UINT32_C(0x2549B7F2), UINT32_C(0x3BC23F01), UINT32_C(0x859ACD10),
8818           UINT32_C(0xBF5FB0D7), UINT32_C(0x05C0358F)},
8819          {UINT32_C(0xFB6AB34C), UINT32_C(0x85E53AA8), UINT32_C(0x8FD2FD20),
8820           UINT32_C(0x8DAAAA69), UINT32_C(0x16096FC9), UINT32_C(0xBE6D4D34),
8821           UINT32_C(0xF8B8B831), UINT32_C(0x27572C88)}},
8822         {{UINT32_C(0x47D56A25), UINT32_C(0xADB98DC5), UINT32_C(0x8B8E1DC6),
8823           UINT32_C(0x0CC76432), UINT32_C(0xBE48C4A1), UINT32_C(0x032C738E),
8824           UINT32_C(0x94FC9CF0), UINT32_C(0x31372DAD)},
8825          {UINT32_C(0x78A7DCB2), UINT32_C(0x8E646A0C), UINT32_C(0x6ECD9885),
8826           UINT32_C(0xA32F3E9C), UINT32_C(0x6A3AD963), UINT32_C(0x280BB4AD),
8827           UINT32_C(0x817D4327), UINT32_C(0x7DEE1BC4)}},
8828         {{UINT32_C(0xF8A7C1E1), UINT32_C(0x1AE6A27B), UINT32_C(0xCBC527C7),
8829           UINT32_C(0x558C652F), UINT32_C(0xA65056F6), UINT32_C(0x4084B56E),
8830           UINT32_C(0x6D4C838B), UINT32_C(0x3FD45459)},
8831          {UINT32_C(0x56DE792A), UINT32_C(0xF5C15AFD), UINT32_C(0x88959282),
8832           UINT32_C(0xF656FAA4), UINT32_C(0x1C07D63F), UINT32_C(0x7F0D8EF4),
8833           UINT32_C(0xCD841ACC), UINT32_C(0x44EFFF7D)}},
8834         {{UINT32_C(0x8D3695D8), UINT32_C(0xAC28F2A6), UINT32_C(0x3F91E781),
8835           UINT32_C(0x94959EB8), UINT32_C(0xFEDD6E1F), UINT32_C(0x7693FFF7),
8836           UINT32_C(0xA9A699EF), UINT32_C(0x2512E6E1)},
8837          {UINT32_C(0x7955FAB7), UINT32_C(0x823400EB), UINT32_C(0x94924C08),
8838           UINT32_C(0xCF109EF9), UINT32_C(0x3A709F32), UINT32_C(0x12E08779),
8839           UINT32_C(0x9CC6484C), UINT32_C(0x187D0413)}},
8840         {{UINT32_C(0xEBDE477F), UINT32_C(0xD3932AFB), UINT32_C(0x44538D8A),
8841           UINT32_C(0x9D5A5422), UINT32_C(0x166A87AF), UINT32_C(0x40B0B159),
8842           UINT32_C(0x41D5E078), UINT32_C(0x31294B3D)},
8843          {UINT32_C(0xE8C48222), UINT32_C(0x6C49C853), UINT32_C(0xDCD0D611),
8844           UINT32_C(0x8FBE6620), UINT32_C(0xF611007B), UINT32_C(0x9DDC7EE2),
8845           UINT32_C(0xE6652172), UINT32_C(0x12289A60)}},
8846         {{UINT32_C(0xDACF80F7), UINT32_C(0x8B85475B), UINT32_C(0x9B5CAEF2),
8847           UINT32_C(0xADBAB353), UINT32_C(0x8D2A7707), UINT32_C(0x7C4090A3),
8848           UINT32_C(0xDAB97830), UINT32_C(0x271FA4F1)},
8849          {UINT32_C(0x53173E04), UINT32_C(0x141B7252), UINT32_C(0x06D0B127),
8850           UINT32_C(0x4B483D64), UINT32_C(0x063A7AF8), UINT32_C(0x8FD15BCF),
8851           UINT32_C(0xE580F34C), UINT32_C(0x59B19EAF)}},
8852         {{UINT32_C(0x9C0D79B6), UINT32_C(0xA7EEA8C4), UINT32_C(0xB9185109),
8853           UINT32_C(0x766FA113), UINT32_C(0x4642CC64), UINT32_C(0xB42D74F3),
8854           UINT32_C(0xBB817476), UINT32_C(0x51D0127B)},
8855          {UINT32_C(0x8AB71448), UINT32_C(0x6DA097F5), UINT32_C(0xF95AD0C7),
8856           UINT32_C(0x145872E5), UINT32_C(0xF1759436), UINT32_C(0xB7E934F3),
8857           UINT32_C(0x3160ED1F), UINT32_C(0x4EA883F9)}},
8858         {{UINT32_C(0x0CEABAE1), UINT32_C(0x30DC39B7), UINT32_C(0xA606D766),
8859           UINT32_C(0x49EC5EE8), UINT32_C(0x97FC46AF), UINT32_C(0x230E2762),
8860           UINT32_C(0x5BE79B8D), UINT32_C(0x079A531F)},
8861          {UINT32_C(0xEF08C93F), UINT32_C(0x48253BC2), UINT32_C(0xF124D043),
8862           UINT32_C(0x2D32AF02), UINT32_C(0xAF34D231), UINT32_C(0x85796D0D),
8863           UINT32_C(0x15F8CECD), UINT32_C(0x06A6205C)}},
8864         {{UINT32_C(0x47B00D1A), UINT32_C(0x1FA77AFD), UINT32_C(0xE48CE97A),
8865           UINT32_C(0x429717B0), UINT32_C(0x57433697), UINT32_C(0x38FEF11D),
8866           UINT32_C(0x7D426687), UINT32_C(0x3E91BED6)},
8867          {UINT32_C(0x2AB4BFE9), UINT32_C(0x95919BF7), UINT32_C(0x97096B3A),
8868           UINT32_C(0x7A3F33FC), UINT32_C(0x3DD8C82E), UINT32_C(0x0E0BBAC3),
8869           UINT32_C(0xF8EDB675), UINT32_C(0x2CE9EFCB)}},
8870         {{UINT32_C(0x43D8B81D), UINT32_C(0x2D44E998), UINT32_C(0x6D68A95C),
8871           UINT32_C(0x8ABFF419), UINT32_C(0x3B2A18DD), UINT32_C(0x639000A0),
8872           UINT32_C(0x871E3ED3), UINT32_C(0x7CD15413)},
8873          {UINT32_C(0x148F0378), UINT32_C(0xC059855B), UINT32_C(0x616B62BF),
8874           UINT32_C(0x50147459), UINT32_C(0x4D461110), UINT32_C(0x53B699AF),
8875           UINT32_C(0xEC29E48D), UINT32_C(0x6A0D0EC7)}},
8876     },
8877     {
8878         {{UINT32_C(0x15797F35), UINT32_C(0x51733221), UINT32_C(0x4BBE6644),
8879           UINT32_C(0x2F298214), UINT32_C(0x4A5EF621), UINT32_C(0x7BC8FEC6),
8880           UINT32_C(0x7F472F05), UINT32_C(0x3D2BE785)},
8881          {UINT32_C(0x2765C427), UINT32_C(0xA1C3A1C9), UINT32_C(0x24155ACF),
8882           UINT32_C(0xBACF08FE), UINT32_C(0x9D229948), UINT32_C(0xA9CC1A17),
8883           UINT32_C(0x27039FD8), UINT32_C(0x1918C97F)}},
8884         {{UINT32_C(0x7843FF7B), UINT32_C(0x2CF39338), UINT32_C(0x258997F2),
8885           UINT32_C(0x5FCBDE65), UINT32_C(0x165A98A3), UINT32_C(0x3980BF90),
8886           UINT32_C(0xBF9458E5), UINT32_C(0x2E80607D)},
8887          {UINT32_C(0x7019165C), UINT32_C(0x5F646EB6), UINT32_C(0xDDE34205),
8888           UINT32_C(0xFA091FBE), UINT32_C(0x69267AE3), UINT32_C(0x695348B6),
8889           UINT32_C(0xABC22051), UINT32_C(0x385B0B6A)}},
8890         {{UINT32_C(0xB537F78C), UINT32_C(0x3CAE0756), UINT32_C(0x8BE30367),
8891           UINT32_C(0x3012A958), UINT32_C(0x981A22C3), UINT32_C(0x32D26C06),
8892           UINT32_C(0x2950E833), UINT32_C(0x7D091FAB)},
8893          {UINT32_C(0x797ACAAF), UINT32_C(0xD8E1B638), UINT32_C(0x49F2EA10),
8894           UINT32_C(0xE7021C85), UINT32_C(0x17A7AF3B), UINT32_C(0xCA382BC1),
8895           UINT32_C(0xBB809976), UINT32_C(0x08A5A81D)}},
8896         {{UINT32_C(0x4287BB97), UINT32_C(0x00F499FD), UINT32_C(0xDAA9DAF2),
8897           UINT32_C(0xFB6791CA), UINT32_C(0x057B2B98), UINT32_C(0x9A19E4F3),
8898           UINT32_C(0xC53C0223), UINT32_C(0x6968D2FF)},
8899          {UINT32_C(0xCE88509C), UINT32_C(0xDC741EF5), UINT32_C(0x306A0570),
8900           UINT32_C(0x38AE355D), UINT32_C(0xC23AF46B), UINT32_C(0xFECF6589),
8901           UINT32_C(0x6AD48836), UINT32_C(0x6C0E6ED1)}},
8902         {{UINT32_C(0xE363495D), UINT32_C(0x22B68698), UINT32_C(0x39AF2BE3),
8903           UINT32_C(0x120005D0), UINT32_C(0x0BF4BA69), UINT32_C(0xE37B1965),
8904           UINT32_C(0x26E64AE7), UINT32_C(0x3B416E93)},
8905          {UINT32_C(0xDEAC5C59), UINT32_C(0xFAED5088), UINT32_C(0xEB2518A5),
8906           UINT32_C(0x67436ACC), UINT32_C(0x91FA788D), UINT32_C(0x636B52F8),
8907           UINT32_C(0x655153D1), UINT32_C(0x10B2A57A)}},
8908         {{UINT32_C(0x833A984C), UINT32_C(0xB18060A7), UINT32_C(0x74833BAD),
8909           UINT32_C(0x7EF83746), UINT32_C(0xC5B3BC88), UINT32_C(0xCBFAF742),
8910           UINT32_C(0xA1A7F135), UINT32_C(0x7981DC36)},
8911          {UINT32_C(0x5D076280), UINT32_C(0xE70CCAFA), UINT32_C(0x07009D85),
8912           UINT32_C(0xEBA80EB7), UINT32_C(0x73778DE2), UINT32_C(0x7D99D24C),
8913           UINT32_C(0xA7262D50), UINT32_C(0x1EFEE1BB)}},
8914         {{UINT32_C(0x6A7CAB32), UINT32_C(0xBC47F4A2), UINT32_C(0xDD6E48A3),
8915           UINT32_C(0x53F290A7), UINT32_C(0x92F35F9E), UINT32_C(0x82257A1B),
8916           UINT32_C(0x8BB0AAB0), UINT32_C(0x73D17B31)},
8917          {UINT32_C(0xC2DFFE96), UINT32_C(0xBBD4522A), UINT32_C(0xE6EB0501),
8918           UINT32_C(0x9C37DAA1), UINT32_C(0x453DB6BE), UINT32_C(0xF4D4D568),
8919           UINT32_C(0x642AD2E4), UINT32_C(0x2868CBF5)}},
8920         {{UINT32_C(0xABE30C59), UINT32_C(0x40A988E6), UINT32_C(0x93057DEC),
8921           UINT32_C(0x5ADED929), UINT32_C(0xDACD37B0), UINT32_C(0x18FD7E04),
8922           UINT32_C(0x8228ACA5), UINT32_C(0x6E3FB81E)},
8923          {UINT32_C(0x4104B0C9), UINT32_C(0xFF3EEFE6), UINT32_C(0x31CA120A),
8924           UINT32_C(0xD7DD05E7), UINT32_C(0xD01C1CF8), UINT32_C(0xAFD3CF1C),
8925           UINT32_C(0x831BC4E9), UINT32_C(0x4D0CD264)}},
8926         {{UINT32_C(0x82CAC14A), UINT32_C(0x2641B321), UINT32_C(0x70990E6C),
8927           UINT32_C(0x34EB1495), UINT32_C(0xA1C74CA6), UINT32_C(0x3E5AF58F),
8928           UINT32_C(0x616B7A2D), UINT32_C(0x11B50821)},
8929          {UINT32_C(0xC4FA9719), UINT32_C(0x891636E3), UINT32_C(0x107DD719),
8930           UINT32_C(0xAEE84C27), UINT32_C(0xC1872E75), UINT32_C(0xA2B0D83E),
8931           UINT32_C(0x7383069E), UINT32_C(0x7DD62CBC)}},
8932         {{UINT32_C(0xC81B7E15), UINT32_C(0xEBA4A024), UINT32_C(0x04516070),
8933           UINT32_C(0x1CC37E08), UINT32_C(0xF90CE59D), UINT32_C(0xEF1F0401),
8934           UINT32_C(0xE062E133), UINT32_C(0x3B4259D5)},
8935          {UINT32_C(0xCF2CA1DD), UINT32_C(0x87A1DBFA), UINT32_C(0x61FD1AFB),
8936           UINT32_C(0xCFBFB15F), UINT32_C(0xECF4C7BA), UINT32_C(0xFBFD9899),
8937           UINT32_C(0x2725FA50), UINT32_C(0x57C84CEE)}},
8938         {{UINT32_C(0xEFA6E3D0), UINT32_C(0x8B0B7414), UINT32_C(0xB3D04224),
8939           UINT32_C(0xD9725C5E), UINT32_C(0x8A91371E), UINT32_C(0x670E6C50),
8940           UINT32_C(0x9B25BD3B), UINT32_C(0x4D130467)},
8941          {UINT32_C(0x5CF18D4F), UINT32_C(0x18D77D15), UINT32_C(0x1CA09677),
8942           UINT32_C(0xEF80DC41), UINT32_C(0xB9A05CF9), UINT32_C(0x6F3A961B),
8943           UINT32_C(0x7C1433A4), UINT32_C(0x0BB8A518)}},
8944         {{UINT32_C(0xB33FCF05), UINT32_C(0xAC0CF52A), UINT32_C(0x1CDC7782),
8945           UINT32_C(0xAD03692F), UINT32_C(0xAA02B77E), UINT32_C(0xB345BAE6),
8946           UINT32_C(0x456FCFA9), UINT32_C(0x05096694)},
8947          {UINT32_C(0x25D4CF32), UINT32_C(0xA8984448), UINT32_C(0x15184188),
8948           UINT32_C(0xD76393E3), UINT32_C(0xEA069BED), UINT32_C(0x7D4A8C0C),
8949           UINT32_C(0x11E18347), UINT32_C(0x4D22268D)}},
8950         {{UINT32_C(0x3CB3C0F1), UINT32_C(0xC2A0BB75), UINT32_C(0x8EBA58C6),
8951           UINT32_C(0x61F4EC4C), UINT32_C(0xDFC4A903), UINT32_C(0x5D3F0D44),
8952           UINT32_C(0xF9B6F79A), UINT32_C(0x0B6CE81B)},
8953          {UINT32_C(0x94E49623), UINT32_C(0xF694A44A), UINT32_C(0x1BDF75E0),
8954           UINT32_C(0xCFCBB7E1), UINT32_C(0xE0337E13), UINT32_C(0x20CEE1BD),
8955           UINT32_C(0xDFF02E18), UINT32_C(0x694EA40B)}},
8956         {{UINT32_C(0x78D1DC2E), UINT32_C(0xC21BE0FA), UINT32_C(0xED0E49E0),
8957           UINT32_C(0x08B4D9A5), UINT32_C(0x827F0B4C), UINT32_C(0x676731AB),
8958           UINT32_C(0xEBAB5894), UINT32_C(0x674ECC79)},
8959          {UINT32_C(0x39ABB148), UINT32_C(0xB29BD0D4), UINT32_C(0x2378A63A),
8960           UINT32_C(0x8207A8F8), UINT32_C(0x1E4C29C2), UINT32_C(0xE36A549D),
8961           UINT32_C(0x3F1C255B), UINT32_C(0x380D48DE)}},
8962         {{UINT32_C(0xE5F2C87E), UINT32_C(0x6AB6F887), UINT32_C(0xA01AEC86),
8963           UINT32_C(0xE92C7345), UINT32_C(0x8660C26F), UINT32_C(0x697F4520),
8964           UINT32_C(0x9B58015B), UINT32_C(0x4F2488E0)},
8965          {UINT32_C(0xBB41900C), UINT32_C(0xB2410B3E), UINT32_C(0xBE1A8A39),
8966           UINT32_C(0x31267500), UINT32_C(0xB9140554), UINT32_C(0xA7C9997C),
8967           UINT32_C(0x1CD41524), UINT32_C(0x335B1806)}},
8968         {{UINT32_C(0x14873270), UINT32_C(0xB836FD9F), UINT32_C(0xE3243EC5),
8969           UINT32_C(0x1AE0F512), UINT32_C(0x83B9AB74), UINT32_C(0xA743E304),
8970           UINT32_C(0x3A5758C7), UINT32_C(0x1569C30D)},
8971          {UINT32_C(0x9E8F9E52), UINT32_C(0x003CEF9A), UINT32_C(0x8C22119E),
8972           UINT32_C(0x557AFB4A), UINT32_C(0xF223A966), UINT32_C(0x66F2487E),
8973           UINT32_C(0xA519378F), UINT32_C(0x7FA00273)}},
8974     },
8975     {
8976         {{UINT32_C(0x7B08C1C4), UINT32_C(0x812C024F), UINT32_C(0xADBA8AD9),
8977           UINT32_C(0xC6017986), UINT32_C(0x0601BD82), UINT32_C(0x59C7B16C),
8978           UINT32_C(0x0CFA5622), UINT32_C(0x41B6A45C)},
8979          {UINT32_C(0x83C1E3E8), UINT32_C(0x353A67D5), UINT32_C(0xC65F5059),
8980           UINT32_C(0x9A83438E), UINT32_C(0x86EEA346), UINT32_C(0x99950377),
8981           UINT32_C(0x330D2570), UINT32_C(0x74E2F4BD)}},
8982         {{UINT32_C(0xB4A8BDA8), UINT32_C(0xDB8E53C1), UINT32_C(0x2C003C77),
8983           UINT32_C(0xA850047E), UINT32_C(0x1B018831), UINT32_C(0xFFD48A73),
8984           UINT32_C(0x8B325062), UINT32_C(0x24F96CB6)},
8985          {UINT32_C(0xCD2B821B), UINT32_C(0x3779CA4D), UINT32_C(0xC3159CE7),
8986           UINT32_C(0xC2AFBF6E), UINT32_C(0x10F18DE9), UINT32_C(0x8A580B1A),
8987           UINT32_C(0x8CF75334), UINT32_C(0x37043D0D)}},
8988         {{UINT32_C(0xECCCF2E8), UINT32_C(0x0451DCDA), UINT32_C(0x752A134F),
8989           UINT32_C(0xCF7A3AD9), UINT32_C(0xFBDAE56C), UINT32_C(0xD5754596),
8990           UINT32_C(0xF4CDCF6A), UINT32_C(0x15237D73)},
8991          {UINT32_C(0xECA37967), UINT32_C(0x1DF5912C), UINT32_C(0x336CD97E),
8992           UINT32_C(0x60934339), UINT32_C(0x434DDC01), UINT32_C(0xA4E523FE),
8993           UINT32_C(0x79DBE24C), UINT32_C(0x24E81DC6)}},
8994         {{UINT32_C(0xC83B2B7C), UINT32_C(0x28F0D73B), UINT32_C(0x7B5DE1AA),
8995           UINT32_C(0x45BE220F), UINT32_C(0xB136A877), UINT32_C(0x1B785230),
8996           UINT32_C(0xAEFF115B), UINT32_C(0x5A94122A)},
8997          {UINT32_C(0x8E598998), UINT32_C(0xEF895F0C), UINT32_C(0xF4C622C3),
8998           UINT32_C(0xCEE32B3E), UINT32_C(0xB256CFD0), UINT32_C(0x2D080B1D),
8999           UINT32_C(0x21075E15), UINT32_C(0x672686D6)}},
9000         {{UINT32_C(0x9F9F26FE), UINT32_C(0xE85FB575), UINT32_C(0x93A7966E),
9001           UINT32_C(0x1DE57B83), UINT32_C(0xDD8CB696), UINT32_C(0xA9948DE8),
9002           UINT32_C(0x758E685D), UINT32_C(0x226C95A6)},
9003          {UINT32_C(0x3729C663), UINT32_C(0x38B0753B), UINT32_C(0x410E4884),
9004           UINT32_C(0xD46CA4D9), UINT32_C(0x77516FA4), UINT32_C(0x1D6FA5F9),
9005           UINT32_C(0x696CFAFC), UINT32_C(0x09A0FDB8)}},
9006         {{UINT32_C(0xCC7F6FD8), UINT32_C(0xD1DAD8E9), UINT32_C(0x022195A2),
9007           UINT32_C(0x7BB9F606), UINT32_C(0x223A9346), UINT32_C(0x1B997396),
9008           UINT32_C(0x88DCFB04), UINT32_C(0x6ACD6F7C)},
9009          {UINT32_C(0x3AC52F65), UINT32_C(0x9029E5EB), UINT32_C(0x935A39DE),
9010           UINT32_C(0xED1D7A0F), UINT32_C(0x538D8914), UINT32_C(0xF1D58C3A),
9011           UINT32_C(0xB36B8342), UINT32_C(0x19153569)}},
9012         {{UINT32_C(0xE2502156), UINT32_C(0xFF600354), UINT32_C(0x733DA5EC),
9013           UINT32_C(0xE386A20F), UINT32_C(0x9D24D11D), UINT32_C(0xD6FBCBBB),
9014           UINT32_C(0x0B06C843), UINT32_C(0x0B57498C)},
9015          {UINT32_C(0x7A834667), UINT32_C(0x98F1FFF8), UINT32_C(0xC7DF05F5),
9016           UINT32_C(0x4AEB8788), UINT32_C(0xC2681DA4), UINT32_C(0x8CFA3B01),
9017           UINT32_C(0x2FA2FAEA), UINT32_C(0x1AECC0E8)}},
9018         {{UINT32_C(0x94C5CBC5), UINT32_C(0x38278865), UINT32_C(0x041A755A),
9019           UINT32_C(0x9ADA7CAB), UINT32_C(0x8D891640), UINT32_C(0xB38F762A),
9020           UINT32_C(0x00AD88F0), UINT32_C(0x28F6FBB2)},
9021          {UINT32_C(0x3709CD6D), UINT32_C(0x3F9629E3), UINT32_C(0x4912F483),
9022           UINT32_C(0xD2435A55), UINT32_C(0xDFF5AB69), UINT32_C(0x305BEA64),
9023           UINT32_C(0x663BB0D9), UINT32_C(0x4D29041A)}},
9024         {{UINT32_C(0xE2FD9338), UINT32_C(0xDC4BC9D4), UINT32_C(0xBA7938FC),
9025           UINT32_C(0x5389390D), UINT32_C(0xF329B218), UINT32_C(0xC42B812D),
9026           UINT32_C(0xFA9F1956), UINT32_C(0x5E809B5E)},
9027          {UINT32_C(0x523D74C3), UINT32_C(0xE2A89BAA), UINT32_C(0x78CBA7B5),
9028           UINT32_C(0x97CD9FFB), UINT32_C(0x5B07BCD2), UINT32_C(0x25F95301),
9029           UINT32_C(0x2064BB3A), UINT32_C(0x4042C705)}},
9030         {{UINT32_C(0x28D53BF9), UINT32_C(0xD8B6ADA4), UINT32_C(0xA4210F2D),
9031           UINT32_C(0x5E922CA5), UINT32_C(0xF05A1629), UINT32_C(0x9501F46A),
9032           UINT32_C(0xC6CD71CD), UINT32_C(0x28094E54)},
9033          {UINT32_C(0x811285AD), UINT32_C(0x8D5484D5), UINT32_C(0x1593EE86),
9034           UINT32_C(0xFB2168F4), UINT32_C(0xAC54A41D), UINT32_C(0x693D3B32),
9035           UINT32_C(0x28A5425C), UINT32_C(0x3DAFEC07)}},
9036         {{UINT32_C(0xD12837A8), UINT32_C(0x0E4CF0D0), UINT32_C(0xCF5273BB),
9037           UINT32_C(0x19FA2CC9), UINT32_C(0x116A20C4), UINT32_C(0x56346BAE),
9038           UINT32_C(0x0E436A36), UINT32_C(0x4F3597FE)},
9039          {UINT32_C(0xE8EB1B85), UINT32_C(0x459D3FFB), UINT32_C(0x5AE04130),
9040           UINT32_C(0x7C718672), UINT32_C(0x60302740), UINT32_C(0xA37C2586),
9041           UINT32_C(0x913072D8), UINT32_C(0x2871AF37)}},
9042         {{UINT32_C(0x8590319D), UINT32_C(0xD77249B7), UINT32_C(0xEB06B813),
9043           UINT32_C(0x73F7A684), UINT32_C(0x71D1D580), UINT32_C(0x4C9DC5B9),
9044           UINT32_C(0x5A50A95B), UINT32_C(0x7C91A9F5)},
9045          {UINT32_C(0x0475F161), UINT32_C(0x4F8F2E89), UINT32_C(0x538B7F94),
9046           UINT32_C(0xF34EC1DD), UINT32_C(0xD46F2575), UINT32_C(0xB8FF6C65),
9047           UINT32_C(0x64433C80), UINT32_C(0x79A2CE2C)}},
9048         {{UINT32_C(0x1AEB7039), UINT32_C(0x38448A53), UINT32_C(0x417189EC),
9049           UINT32_C(0xF5EC03F7), UINT32_C(0xEB92FF2B), UINT32_C(0xFA095CA1),
9050           UINT32_C(0xE4FCAEDB), UINT32_C(0x4612F720)},
9051          {UINT32_C(0xF30AAE0E), UINT32_C(0xC945E966), UINT32_C(0x340A7A1D),
9052           UINT32_C(0xF61CFE85), UINT32_C(0xE42D7920), UINT32_C(0xA2560BC6),
9053           UINT32_C(0xA692E9C7), UINT32_C(0x07D7B321)}},
9054         {{UINT32_C(0x592C60C5), UINT32_C(0xB9C26307), UINT32_C(0x0F59D966),
9055           UINT32_C(0xCECBC6C3), UINT32_C(0x5459D89E), UINT32_C(0x8BA31FD6),
9056           UINT32_C(0x47C7FAE8), UINT32_C(0x1A4AF6B1)},
9057          {UINT32_C(0xB431D720), UINT32_C(0x66487766), UINT32_C(0x5108B845),
9058           UINT32_C(0x5D597309), UINT32_C(0xCA8E6E0D), UINT32_C(0xA3B94FD7),
9059           UINT32_C(0x55C6A48D), UINT32_C(0x639519E3)}},
9060         {{UINT32_C(0x052DC195), UINT32_C(0xAD3EE167), UINT32_C(0x0947816B),
9061           UINT32_C(0x4DF2BFC7), UINT32_C(0xABADBB3C), UINT32_C(0x5D463469),
9062           UINT32_C(0xC33D4F96), UINT32_C(0x6F7AA885)},
9063          {UINT32_C(0xFE06133C), UINT32_C(0x3DD27536), UINT32_C(0x2796E7ED),
9064           UINT32_C(0x27A557B2), UINT32_C(0x3D314A4F), UINT32_C(0x1117CCB7),
9065           UINT32_C(0x23968946), UINT32_C(0x6F0C0AE0)}},
9066         {{UINT32_C(0xE2110C00), UINT32_C(0x0A3D4DAE), UINT32_C(0x4C633A23),
9067           UINT32_C(0x0389D3A5), UINT32_C(0x83AEC172), UINT32_C(0xE167BDFA),
9068           UINT32_C(0xFB38E8F1), UINT32_C(0x067070CE)},
9069          {UINT32_C(0x4DF220C5), UINT32_C(0x41137367), UINT32_C(0x59C39F05),
9070           UINT32_C(0xB255E5D3), UINT32_C(0x043C75B3), UINT32_C(0xE437984E),
9071           UINT32_C(0x6A22994A), UINT32_C(0x01DCD771)}},
9072     },
9073     {
9074         {{UINT32_C(0x4C6FDDCF), UINT32_C(0xD2880DF2), UINT32_C(0x8A00D80F),
9075           UINT32_C(0x76A28FF2), UINT32_C(0x0792F82C), UINT32_C(0x257CB1F8),
9076           UINT32_C(0x605703EA), UINT32_C(0x07938ABC)},
9077          {UINT32_C(0x5F61B0FE), UINT32_C(0xD99F0AC9), UINT32_C(0x8EC15433),
9078           UINT32_C(0x440DC63C), UINT32_C(0x86AB5DDB), UINT32_C(0xD9BDDFF1),
9079           UINT32_C(0x744755EA), UINT32_C(0x3B8875DC)}},
9080         {{UINT32_C(0x4938C9FB), UINT32_C(0x01D90440), UINT32_C(0x8DB6A890),
9081           UINT32_C(0x900657FD), UINT32_C(0xF60A173A), UINT32_C(0xDCC5068A),
9082           UINT32_C(0x857C7B2A), UINT32_C(0x5F3EB242)},
9083          {UINT32_C(0xA4F0EB9E), UINT32_C(0x634240BD), UINT32_C(0x44E85C70),
9084           UINT32_C(0xACDDA6C4), UINT32_C(0x0AABE4C5), UINT32_C(0x753F02AB),
9085           UINT32_C(0xC1D034E1), UINT32_C(0x33D89D21)}},
9086         {{UINT32_C(0x1279B25B), UINT32_C(0x4596B52D), UINT32_C(0xA48014AE),
9087           UINT32_C(0x494669D9), UINT32_C(0x4FD22150), UINT32_C(0x9A26B6FC),
9088           UINT32_C(0xF07D5A3F), UINT32_C(0x394DE0BB)},
9089          {UINT32_C(0x634C1733), UINT32_C(0x12DFE5A6), UINT32_C(0x1EBC5177),
9090           UINT32_C(0x33EC21D2), UINT32_C(0x527514CC), UINT32_C(0x454B4930),
9091           UINT32_C(0x41405532), UINT32_C(0x7F23BD0F)}},
9092         {{UINT32_C(0xBAC9DD30), UINT32_C(0xB2879E7F), UINT32_C(0x06CE7672),
9093           UINT32_C(0x259BB1CB), UINT32_C(0xBB97BE10), UINT32_C(0x201DB42E),
9094           UINT32_C(0x2EA35A8E), UINT32_C(0x112D6079)},
9095          {UINT32_C(0x6B3B9933), UINT32_C(0x7CC756D4), UINT32_C(0x781CE4DD),
9096           UINT32_C(0x4BD24810), UINT32_C(0x8733247E), UINT32_C(0x53CB4E38),
9097           UINT32_C(0x9DA66787), UINT32_C(0x47BD6A30)}},
9098         {{UINT32_C(0xBA600C8E), UINT32_C(0x8A700953), UINT32_C(0xCF388C0D),
9099           UINT32_C(0xD466F11D), UINT32_C(0xE4A17A8E), UINT32_C(0xD485F341),
9100           UINT32_C(0x234FC16D), UINT32_C(0x63278918)},
9101          {UINT32_C(0xBB82046D), UINT32_C(0xF4DDA875), UINT32_C(0x2945470A),
9102           UINT32_C(0xD61E4E58), UINT32_C(0x6D0F8976), UINT32_C(0xCDB6C5BD),
9103           UINT32_C(0x10A004A2), UINT32_C(0x44CD9E4D)}},
9104         {{UINT32_C(0x49C4AA6E), UINT32_C(0x595CD942), UINT32_C(0x3DE400C8),
9105           UINT32_C(0xE5A90136), UINT32_C(0x9DD12D9E), UINT32_C(0x4BCED3BD),
9106           UINT32_C(0x78E3D5E4), UINT32_C(0x3700CF92)},
9107          {UINT32_C(0x75A32D1A), UINT32_C(0xECFFF498), UINT32_C(0x3C4A54B2),
9108           UINT32_C(0xC28DDE37), UINT32_C(0x993CAE6D), UINT32_C(0x8DC22352),
9109           UINT32_C(0x52ED7019), UINT32_C(0x46CB5408)}},
9110         {{UINT32_C(0xEA94E7BF), UINT32_C(0x71FFAED0), UINT32_C(0xD5AE6185),
9111           UINT32_C(0xC0817D2C), UINT32_C(0x5CF23687), UINT32_C(0x7B72B8B9),
9112           UINT32_C(0x60A450E1), UINT32_C(0x61DDE599)},
9113          {UINT32_C(0xD13870E6), UINT32_C(0x17CF0B10), UINT32_C(0x5F2930BB),
9114           UINT32_C(0x7D08E1FB), UINT32_C(0x83807C14), UINT32_C(0x8D0F4F55),
9115           UINT32_C(0x6E6DB701), UINT32_C(0x61EBFC1A)}},
9116         {{UINT32_C(0x0FCAFE68), UINT32_C(0x247A3F65), UINT32_C(0x7AC2A25E),
9117           UINT32_C(0x57548035), UINT32_C(0x3CD0FE06), UINT32_C(0xB7466CA5),
9118           UINT32_C(0xBCC31AB3), UINT32_C(0x7B0D8B36)},
9119          {UINT32_C(0xA6D4358C), UINT32_C(0x2FAAF49C), UINT32_C(0x3E9B4E31),
9120           UINT32_C(0xD9E5E2FE), UINT32_C(0xF6086336), UINT32_C(0xA6A859A0),
9121           UINT32_C(0xA9C19F84), UINT32_C(0x0C2A442A)}},
9122         {{UINT32_C(0x3BC0AD7D), UINT32_C(0x66FEA841), UINT32_C(0x32C9158E),
9123           UINT32_C(0xCD3A546C), UINT32_C(0x8FE1DF7F), UINT32_C(0xACD2EE7F),
9124           UINT32_C(0xEBE9621E), UINT32_C(0x10F58C0A)},
9125          {UINT32_C(0x478B667D), UINT32_C(0x80047C54), UINT32_C(0x89870DCE),
9126           UINT32_C(0x9EAE5FAA), UINT32_C(0x0520A005), UINT32_C(0xC05BEB33),
9127           UINT32_C(0x352AC891), UINT32_C(0x2CFBC921)}},
9128         {{UINT32_C(0x632F6D73), UINT32_C(0x6842E6B8), UINT32_C(0x2B9FFAEA),
9129           UINT32_C(0x6F2B5724), UINT32_C(0x9341D2FA), UINT32_C(0x7ACCC982),
9130           UINT32_C(0x88809B65), UINT32_C(0x6DAD9A11)},
9131          {UINT32_C(0xB6CC2240), UINT32_C(0x3411850C), UINT32_C(0xB64937E1),
9132           UINT32_C(0x8547BCAF), UINT32_C(0x6978F636), UINT32_C(0x49AEDD5F),
9133           UINT32_C(0x85A53D2A), UINT32_C(0x38F59752)}},
9134         {{UINT32_C(0xF5F5A2D0), UINT32_C(0x5C38EB49), UINT32_C(0xE3BF779C),
9135           UINT32_C(0xE028121B), UINT32_C(0xA783D5E3), UINT32_C(0x649997C8),
9136           UINT32_C(0x2C06CC0F), UINT32_C(0x04DE984A)},
9137          {UINT32_C(0xA49D6239), UINT32_C(0x52C834B0), UINT32_C(0x628413AC),
9138           UINT32_C(0x070A1B09), UINT32_C(0xA8624A1E), UINT32_C(0x2FBE0CA5),
9139           UINT32_C(0x268D930A), UINT32_C(0x687D93C3)}},
9140         {{UINT32_C(0x314C47A4), UINT32_C(0xC7CD6805), UINT32_C(0xCE7A9A6D),
9141           UINT32_C(0x8BD0C630), UINT32_C(0x34F727BA), UINT32_C(0xCDB2DAD5),
9142           UINT32_C(0x25DB0189), UINT32_C(0x7814C414)},
9143          {UINT32_C(0x7DD9CAEE), UINT32_C(0xD7F9C5DC), UINT32_C(0x798690E4),
9144           UINT32_C(0xDA6EACC8), UINT32_C(0x6B675E01), UINT32_C(0x705794E3),
9145           UINT32_C(0x75C5EC38), UINT32_C(0x4A31D714)}},
9146         {{UINT32_C(0x0519D5F2), UINT32_C(0xC162A3EA), UINT32_C(0x2958FABF),
9147           UINT32_C(0x92146A78), UINT32_C(0x6CB31EB0), UINT32_C(0x1E63CBE4),
9148           UINT32_C(0xFBC5AD0F), UINT32_C(0x77CE5AAD)},
9149          {UINT32_C(0x32605DC6), UINT32_C(0x3631E470), UINT32_C(0x43413DD3),
9150           UINT32_C(0xC7D1C72F), UINT32_C(0x0DF6B7C9), UINT32_C(0x171A3794),
9151           UINT32_C(0x2B5A08BC), UINT32_C(0x6D711743)}},
9152         {{UINT32_C(0x509EF0F2), UINT32_C(0xDDC8057D), UINT32_C(0x6CABB486),
9153           UINT32_C(0x05C0B92B), UINT32_C(0x4244D919), UINT32_C(0xD49692B6),
9154           UINT32_C(0xD297F56E), UINT32_C(0x4E181744)},
9155          {UINT32_C(0xF8CBB897), UINT32_C(0x902F6E73), UINT32_C(0x56D01382),
9156           UINT32_C(0xC3B21FE1), UINT32_C(0x46890F6D), UINT32_C(0xA858ABE1),
9157           UINT32_C(0x506858AF), UINT32_C(0x46B5E2C9)}},
9158         {{UINT32_C(0xF4DEDE56), UINT32_C(0x30441281), UINT32_C(0xA195AEDE),
9159           UINT32_C(0x13F06FBB), UINT32_C(0x2FDD3BFF), UINT32_C(0xAD5F575B),
9160           UINT32_C(0x32ACB590), UINT32_C(0x680F656D)},
9161          {UINT32_C(0xE3FAABA7), UINT32_C(0xFB60A8E1), UINT32_C(0x89A14827),
9162           UINT32_C(0xC8FBC1E4), UINT32_C(0xA8616136), UINT32_C(0x5835453F),
9163           UINT32_C(0xE6F4926F), UINT32_C(0x02826A47)}},
9164         {{UINT32_C(0x74F32180), UINT32_C(0xAF4319A1), UINT32_C(0x6C2C1712),
9165           UINT32_C(0x4C9FDD16), UINT32_C(0xAC7E14A7), UINT32_C(0x59CA4FD4),
9166           UINT32_C(0xABBD4EA4), UINT32_C(0x07AA6E2F)},
9167          {UINT32_C(0xFE9F121F), UINT32_C(0xB4BD441C), UINT32_C(0xCDA452C5),
9168           UINT32_C(0xDEBB4356), UINT32_C(0x51C9F451), UINT32_C(0xC29F1CFA),
9169           UINT32_C(0x83F598D8), UINT32_C(0x7E1EEF4C)}},
9170     },
9171     {
9172         {{UINT32_C(0x5014135F), UINT32_C(0xFC41A321), UINT32_C(0x3EEADF3F),
9173           UINT32_C(0xBE95F9BA), UINT32_C(0x3203A540), UINT32_C(0x054B1212),
9174           UINT32_C(0x3721C745), UINT32_C(0x6DD2FD17)},
9175          {UINT32_C(0x5A682B59), UINT32_C(0xF86B8578), UINT32_C(0xBE801F7D),
9176           UINT32_C(0x872AA481), UINT32_C(0x14F865F2), UINT32_C(0x64C1600C),
9177           UINT32_C(0x25365449), UINT32_C(0x4BDD47AA)}},
9178         {{UINT32_C(0xF3A3469F), UINT32_C(0xC96A964C), UINT32_C(0x9F7DA0E3),
9179           UINT32_C(0x273C5C85), UINT32_C(0x4C1A9DCD), UINT32_C(0x88EDC4AC),
9180           UINT32_C(0xB48E4CAA), UINT32_C(0x77623444)},
9181          {UINT32_C(0x31581FF7), UINT32_C(0x7AF34A9C), UINT32_C(0xBB57F7CC),
9182           UINT32_C(0x23328C37), UINT32_C(0x8B7C86AB), UINT32_C(0xE920D8E9),
9183           UINT32_C(0x9DE6D64C), UINT32_C(0x1C7A7A40)}},
9184         {{UINT32_C(0x79B9451C), UINT32_C(0x0BCDCD22), UINT32_C(0x58F5241B),
9185           UINT32_C(0x2920B435), UINT32_C(0x9B33EF3D), UINT32_C(0xC24DF715),
9186           UINT32_C(0xF2600224), UINT32_C(0x15252C5B)},
9187          {UINT32_C(0x9A9160B6), UINT32_C(0xF9C8D8A6), UINT32_C(0xA6B9A6B8),
9188           UINT32_C(0x3186F2F9), UINT32_C(0xA377E98A), UINT32_C(0xC37267DC),
9189           UINT32_C(0x37957189), UINT32_C(0x71319A0A)}},
9190         {{UINT32_C(0x6BAF6AE5), UINT32_C(0x48E5033F), UINT32_C(0xA460FCE9),
9191           UINT32_C(0x72379B2E), UINT32_C(0xF3D2FA46), UINT32_C(0xFC753D47),
9192           UINT32_C(0xED9EDF72), UINT32_C(0x3B67685A)},
9193          {UINT32_C(0xF712500F), UINT32_C(0x1608E304), UINT32_C(0x9EE1B42A),
9194           UINT32_C(0xDFA358A4), UINT32_C(0x34B8345C), UINT32_C(0xE7A4B376),
9195           UINT32_C(0x06753C17), UINT32_C(0x7D0E0BF3)}},
9196         {{UINT32_C(0x8FA62042), UINT32_C(0xA88526A6), UINT32_C(0x393006BD),
9197           UINT32_C(0xD6F32BB5), UINT32_C(0xA5DD5045), UINT32_C(0x14804978),
9198           UINT32_C(0xBF0C5E13), UINT32_C(0x34C02662)},
9199          {UINT32_C(0x376E3E3D), UINT32_C(0xF9BEEBF9), UINT32_C(0x5923DC61),
9200           UINT32_C(0xFD774041), UINT32_C(0xF9735CF5), UINT32_C(0xFE77BDFA),
9201           UINT32_C(0x4077CFCC), UINT32_C(0x2E476E22)}},
9202         {{UINT32_C(0x9BA457EF), UINT32_C(0xAB8E52EB), UINT32_C(0x0ABED212),
9203           UINT32_C(0x95F6C5FE), UINT32_C(0x386620FF), UINT32_C(0x7204B1A6),
9204           UINT32_C(0xDD180719), UINT32_C(0x463B7474)},
9205          {UINT32_C(0xF991D8EE), UINT32_C(0x7F7D27AA), UINT32_C(0x8F67722D),
9206           UINT32_C(0xA7EB1085), UINT32_C(0xE331480A), UINT32_C(0x78D7095B),
9207           UINT32_C(0x66A1C8FA), UINT32_C(0x1DCC8C12)}},
9208         {{UINT32_C(0x3E6A04C1), UINT32_C(0xD4C39C18), UINT32_C(0xB598ABEE),
9209           UINT32_C(0x73DB1C4D), UINT32_C(0xDF4A7D42), UINT32_C(0x381F9780),
9210           UINT32_C(0x52F860CD), UINT32_C(0x3C19A231)},
9211          {UINT32_C(0x3EF00740), UINT32_C(0x7EC89934), UINT32_C(0xF37FE0D5),
9212           UINT32_C(0x50867788), UINT32_C(0x43E84D4A), UINT32_C(0x502D870B),
9213           UINT32_C(0x8F744749), UINT32_C(0x5F8A8413)}},
9214         {{UINT32_C(0xFAECCFE4), UINT32_C(0x1C41AAAD), UINT32_C(0x21461F41),
9215           UINT32_C(0xC324F3B9), UINT32_C(0x4E90C0AB), UINT32_C(0x165ABA3F),
9216           UINT32_C(0x5F88E7D3), UINT32_C(0x2F96CED5)},
9217          {UINT32_C(0xC0E52768), UINT32_C(0x8CA366FC), UINT32_C(0xA55249A7),
9218           UINT32_C(0x6CCA017C), UINT32_C(0x0F7EBCA2), UINT32_C(0x41ED002F),
9219           UINT32_C(0xA2BAF655), UINT32_C(0x0C33B371)}},
9220         {{UINT32_C(0x62B928CE), UINT32_C(0x3B94CD9C), UINT32_C(0x39729345),
9221           UINT32_C(0x5BC43A6A), UINT32_C(0xC47D223C), UINT32_C(0x044D0C0F),
9222           UINT32_C(0xB0493367), UINT32_C(0x3B64B38D)},
9223          {UINT32_C(0xEB74A6C2), UINT32_C(0x82AFB645), UINT32_C(0xD876D71C),
9224           UINT32_C(0x0CB01E22), UINT32_C(0x29C6BCD0), UINT32_C(0xCE2A7DCC),
9225           UINT32_C(0xDFD644EC), UINT32_C(0x4753DE1C)}},
9226         {{UINT32_C(0x62188792), UINT32_C(0xE69FC903), UINT32_C(0x4914328B),
9227           UINT32_C(0xD91DB9BC), UINT32_C(0x3B68F8D0), UINT32_C(0x44953F4D),
9228           UINT32_C(0x0654B283), UINT32_C(0x2950435D)},
9229          {UINT32_C(0xBE88F609), UINT32_C(0xE599A4AE), UINT32_C(0x90F5D10E),
9230           UINT32_C(0xF801CD90), UINT32_C(0xD4F1D3D9), UINT32_C(0x0AB78DB1),
9231           UINT32_C(0xC0F71ECB), UINT32_C(0x3ED9666A)}},
9232         {{UINT32_C(0xE1E73E59), UINT32_C(0x6046A505), UINT32_C(0xF3B5C2E0),
9233           UINT32_C(0x8723A3EC), UINT32_C(0xE22C1555), UINT32_C(0x4BD95BF6),
9234           UINT32_C(0x6DA421E9), UINT32_C(0x50DC33DB)},
9235          {UINT32_C(0xF1B01327), UINT32_C(0xCFB51E95), UINT32_C(0x199A8765),
9236           UINT32_C(0xE7013F2A), UINT32_C(0x77504B0B), UINT32_C(0xF486FEA7),
9237           UINT32_C(0xF9BA61C6), UINT32_C(0x2AF0F7E9)}},
9238         {{UINT32_C(0xBE00B841), UINT32_C(0x9DBA1A02), UINT32_C(0x8BED5F08),
9239           UINT32_C(0x488BA455), UINT32_C(0x67F1040E), UINT32_C(0xF6814A64),
9240           UINT32_C(0xDC252336), UINT32_C(0x23AC4762)},
9241          {UINT32_C(0xF0ED0577), UINT32_C(0x25040F02), UINT32_C(0xC6FFAE9C),
9242           UINT32_C(0x65209B22), UINT32_C(0x485AA0AC), UINT32_C(0xCC441A8C),
9243           UINT32_C(0x59D63A8A), UINT32_C(0x10DFACB6)}},
9244         {{UINT32_C(0xC7D86B28), UINT32_C(0xBF4A0569), UINT32_C(0xDBDA9DA4),
9245           UINT32_C(0x5CDA94C4), UINT32_C(0x69058335), UINT32_C(0x2235C4CE),
9246           UINT32_C(0xD30C89E2), UINT32_C(0x68FA5E7C)},
9247          {UINT32_C(0x59097B5B), UINT32_C(0xBB286D39), UINT32_C(0x9A20BA7E),
9248           UINT32_C(0x87DA80BB), UINT32_C(0x56F47E54), UINT32_C(0x85EF865E),
9249           UINT32_C(0x74ABFA5B), UINT32_C(0x5BB87867)}},
9250         {{UINT32_C(0xDE2FA36E), UINT32_C(0x5DB14FAB), UINT32_C(0x77775F09),
9251           UINT32_C(0x84E3B546), UINT32_C(0xDA951D99), UINT32_C(0xDA734523),
9252           UINT32_C(0x3975026E), UINT32_C(0x04A89097)},
9253          {UINT32_C(0xC0D12BE1), UINT32_C(0xB5753599), UINT32_C(0xFB864D61),
9254           UINT32_C(0x05670CE9), UINT32_C(0x305BF3CF), UINT32_C(0xB7153502),
9255           UINT32_C(0x2E60AF62), UINT32_C(0x7A9BB357)}},
9256         {{UINT32_C(0xC7566DA5), UINT32_C(0xF43CDA07), UINT32_C(0x53FA4196),
9257           UINT32_C(0x7FC4C7FC), UINT32_C(0x88DCC9F3), UINT32_C(0x1E20E0ED),
9258           UINT32_C(0xFEE23DDA), UINT32_C(0x7317C7E5)},
9259          {UINT32_C(0x43017070), UINT32_C(0x0305E13F), UINT32_C(0x6B1CA7C0),
9260           UINT32_C(0x5568410C), UINT32_C(0x104BA029), UINT32_C(0x0E5D55BA),
9261           UINT32_C(0x90FD49F8), UINT32_C(0x118B284E)}},
9262         {{UINT32_C(0x8F3C6D8A), UINT32_C(0xCA0F7B5B), UINT32_C(0xAF7ECBF6),
9263           UINT32_C(0xAF72DEE0), UINT32_C(0xBB0EC4F1), UINT32_C(0x21C86D85),
9264           UINT32_C(0xF0525D17), UINT32_C(0x0303BC47)},
9265          {UINT32_C(0x896FFCC0), UINT32_C(0x6ADCAB9F), UINT32_C(0x24E970CA),
9266           UINT32_C(0x65764C45), UINT32_C(0x1C3CA718), UINT32_C(0x0000F14C),
9267           UINT32_C(0xD0292587), UINT32_C(0x01CF1DDB)}},
9268     },
9269     {
9270         {{UINT32_C(0x86111EBA), UINT32_C(0xEC4FABCC), UINT32_C(0xBBBB793F),
9271           UINT32_C(0x599C20B6), UINT32_C(0x5657668F), UINT32_C(0xF74AE747),
9272           UINT32_C(0x77BAE892), UINT32_C(0x24AF29B2)},
9273          {UINT32_C(0xCFAC9D5E), UINT32_C(0x47D6876B), UINT32_C(0x24369E14),
9274           UINT32_C(0xCACF9F50), UINT32_C(0x6F9CAFEF), UINT32_C(0x8A231D74),
9275           UINT32_C(0xB69AAE58), UINT32_C(0x57645A4E)}},
9276         {{UINT32_C(0x489900F6), UINT32_C(0x440A3B15), UINT32_C(0x961AC3C2),
9277           UINT32_C(0x4B642FD3), UINT32_C(0xC265B973), UINT32_C(0x3D668599),
9278           UINT32_C(0x1139CE78), UINT32_C(0x5FA0E65D)},
9279          {UINT32_C(0x1FAA710E), UINT32_C(0x3FF15AF4), UINT32_C(0xA9422FC0),
9280           UINT32_C(0xE45D35CE), UINT32_C(0xBD7BB349), UINT32_C(0x56904C06),
9281           UINT32_C(0xE529989D), UINT32_C(0x40C5BEE0)}},
9282         {{UINT32_C(0x70B20298), UINT32_C(0x8FA46861), UINT32_C(0x4838A136),
9283           UINT32_C(0xEC629538), UINT32_C(0x137F66D6), UINT32_C(0x23ADE0F6),
9284           UINT32_C(0x8EA53E76), UINT32_C(0x1A92E05C)},
9285          {UINT32_C(0x9D51EB7A), UINT32_C(0x51728E27), UINT32_C(0xC4352E35),
9286           UINT32_C(0xA6B0B758), UINT32_C(0x37A11B35), UINT32_C(0x84C59331),
9287           UINT32_C(0xF66B75C7), UINT32_C(0x3933EFC1)}},
9288         {{UINT32_C(0x66916D0A), UINT32_C(0x7FB68D62), UINT32_C(0xF28A9B14),
9289           UINT32_C(0x3325D42E), UINT32_C(0x8592B544), UINT32_C(0x75E83A65),
9290           UINT32_C(0x2718628F), UINT32_C(0x524D1CE0)},
9291          {UINT32_C(0x3C584D76), UINT32_C(0x88A110EA), UINT32_C(0x4AC09AAC),
9292           UINT32_C(0x6B034AC4), UINT32_C(0x84FD3A36), UINT32_C(0x06488635),
9293           UINT32_C(0x87D944E1), UINT32_C(0x516F0EB0)}},
9294         {{UINT32_C(0xDF11D0BB), UINT32_C(0xE2016DA0), UINT32_C(0xB01F6540),
9295           UINT32_C(0xB34EB471), UINT32_C(0x165CBB24), UINT32_C(0x13E3D330),
9296           UINT32_C(0x7CF7F676), UINT32_C(0x3E755D11)},
9297          {UINT32_C(0x4FEA9A69), UINT32_C(0xD70CF4F8), UINT32_C(0xD18F4337),
9298           UINT32_C(0x98F59E0A), UINT32_C(0x826344BA), UINT32_C(0x7CCE7CE6),
9299           UINT32_C(0xF4004BBE), UINT32_C(0x30D129D7)}},
9300         {{UINT32_C(0xBA9CB975), UINT32_C(0x016EF317), UINT32_C(0xE4B3AB4D),
9301           UINT32_C(0x8EEBED19), UINT32_C(0x170A2570), UINT32_C(0x8C597DF0),
9302           UINT32_C(0x5BE6DE70), UINT32_C(0x451538D8)},
9303          {UINT32_C(0x7A64792F), UINT32_C(0x6C711DAC), UINT32_C(0x217EC8FB),
9304           UINT32_C(0x8F1896EB), UINT32_C(0x7FE18DED), UINT32_C(0x82E9C20B),
9305           UINT32_C(0xB0C5F622), UINT32_C(0x6CEBF4A7)}},
9306         {{UINT32_C(0x49CCC64F), UINT32_C(0xD9403EB5), UINT32_C(0x28B8A3FD),
9307           UINT32_C(0x807EBD56), UINT32_C(0x0F291E12), UINT32_C(0xF08BB659),
9308           UINT32_C(0x9C3F4432), UINT32_C(0x020D13E3)},
9309          {UINT32_C(0x752BB92E), UINT32_C(0xDA247896), UINT32_C(0x86EAFA7A),
9310           UINT32_C(0x99541794), UINT32_C(0x274E36AD), UINT32_C(0x213E94BA),
9311           UINT32_C(0x61A71333), UINT32_C(0x4CC0F1FB)}},
9312         {{UINT32_C(0x06478801), UINT32_C(0x19CC11BD), UINT32_C(0x6D18216A),
9313           UINT32_C(0x1251562A), UINT32_C(0xCDD307FC), UINT32_C(0x7A5F06BB),
9314           UINT32_C(0xFAA9CA2A), UINT32_C(0x4285F6AB)},
9315          {UINT32_C(0x81258996), UINT32_C(0x5A922831), UINT32_C(0x27B8B018),
9316           UINT32_C(0x8F7CF8EE), UINT32_C(0x7F81A62D), UINT32_C(0xF030BEF3),
9317           UINT32_C(0xCD4FD4E7), UINT32_C(0x417ACBC1)}},
9318         {{UINT32_C(0xEC64412F), UINT32_C(0xCFB0EA58), UINT32_C(0x6091E621),
9319           UINT32_C(0x9547B64A), UINT32_C(0xFD0C9815), UINT32_C(0x5EA49C7E),
9320           UINT32_C(0xE78B355C), UINT32_C(0x6789055A)},
9321          {UINT32_C(0x77E9A73A), UINT32_C(0x8D743E98), UINT32_C(0x2EA3FA49),
9322           UINT32_C(0xB032EA6A), UINT32_C(0xCEAAA33A), UINT32_C(0x52EA3801),
9323           UINT32_C(0xF2C3E22B), UINT32_C(0x73B3BB8D)}},
9324         {{UINT32_C(0x7DB9E301), UINT32_C(0xAA2A1291), UINT32_C(0xA1293DD7),
9325           UINT32_C(0x7F29770F), UINT32_C(0x59683DEC), UINT32_C(0x3135BB21),
9326           UINT32_C(0x7785B505), UINT32_C(0x070F8DF7)},
9327          {UINT32_C(0x37F53677), UINT32_C(0x8F2158EA), UINT32_C(0xABE1AF1C),
9328           UINT32_C(0x96CC7B9D), UINT32_C(0x6D6477D6), UINT32_C(0x7F977915),
9329           UINT32_C(0xDF370EAF), UINT32_C(0x55DB3922)}},
9330         {{UINT32_C(0xA9DAC7AE), UINT32_C(0x3028C03A), UINT32_C(0xBAE06BE0),
9331           UINT32_C(0x16F7DF0D), UINT32_C(0x410D57D9), UINT32_C(0x09548398),
9332           UINT32_C(0x1510D51F), UINT32_C(0x5E9C7F43)},
9333          {UINT32_C(0xD07717B3), UINT32_C(0x033B9BE2), UINT32_C(0xEF08AB91),
9334           UINT32_C(0x0D5D8116), UINT32_C(0xEEEFE88F), UINT32_C(0xD5A172B1),
9335           UINT32_C(0x0996294E), UINT32_C(0x72B1D29F)}},
9336         {{UINT32_C(0xE4D0965C), UINT32_C(0x9E2B79FB), UINT32_C(0xF49D8B8E),
9337           UINT32_C(0x01F403EE), UINT32_C(0xCEB12D6A), UINT32_C(0xBD4D2D48),
9338           UINT32_C(0x11FB24FB), UINT32_C(0x4D04DD9A)},
9339          {UINT32_C(0xE5C8D24C), UINT32_C(0x7E613EC5), UINT32_C(0xB918E543),
9340           UINT32_C(0x568BEFE8), UINT32_C(0xE966DF28), UINT32_C(0xD6456D1E),
9341           UINT32_C(0xBAFC71E2), UINT32_C(0x2DDEAD63)}},
9342         {{UINT32_C(0x448D72E9), UINT32_C(0x1D794F92), UINT32_C(0xE7E62BF2),
9343           UINT32_C(0x3978052E), UINT32_C(0xE2B92538), UINT32_C(0xF6C7A72E),
9344           UINT32_C(0x6EF321F0), UINT32_C(0x43879A88)},
9345          {UINT32_C(0x34F6FFBC), UINT32_C(0x2A823140), UINT32_C(0x35F4C485),
9346           UINT32_C(0x26F84E51), UINT32_C(0x028BFA7E), UINT32_C(0xDEE65540),
9347           UINT32_C(0x5F033058), UINT32_C(0x56216E9D)}},
9348         {{UINT32_C(0xCBC772EE), UINT32_C(0x31CA5470), UINT32_C(0x811BB5D0),
9349           UINT32_C(0xD3621E11), UINT32_C(0x70863D71), UINT32_C(0x501C4C47),
9350           UINT32_C(0xD28D6BDD), UINT32_C(0x0564518E)},
9351          {UINT32_C(0xD35B64B9), UINT32_C(0x60E3B89B), UINT32_C(0x6621A688),
9352           UINT32_C(0xB4F2599A), UINT32_C(0x3B5E116D), UINT32_C(0x1A8C4508),
9353           UINT32_C(0xFABF3125), UINT32_C(0x633EF5CC)}},
9354         {{UINT32_C(0x5D4FF62A), UINT32_C(0x0DB1D251), UINT32_C(0x4B17D658),
9355           UINT32_C(0x6CBD00EB), UINT32_C(0xFA1DB737), UINT32_C(0x2FA38212),
9356           UINT32_C(0x93A7FA03), UINT32_C(0x07B18CB8)},
9357          {UINT32_C(0x548E5F82), UINT32_C(0x531E47EF), UINT32_C(0x8276963C),
9358           UINT32_C(0xAE7B94FD), UINT32_C(0x6181A13A), UINT32_C(0x8055D82A),
9359           UINT32_C(0x23B6E361), UINT32_C(0x5725B512)}},
9360         {{UINT32_C(0x6D8B1FFE), UINT32_C(0xD84C7041), UINT32_C(0x5D994200),
9361           UINT32_C(0xF68ACA0B), UINT32_C(0x6BB908E2), UINT32_C(0x32BF9944),
9362           UINT32_C(0x1AD88DB1), UINT32_C(0x1240A3E6)},
9363          {UINT32_C(0xA92B6472), UINT32_C(0xB0BE96AA), UINT32_C(0xA1B7726C),
9364           UINT32_C(0xEF88A155), UINT32_C(0x9349F496), UINT32_C(0x000FD9ED),
9365           UINT32_C(0x454A05D9), UINT32_C(0x377DCBAD)}},
9366     },
9367     {
9368         {{UINT32_C(0xC04111D2), UINT32_C(0xD0A092CD), UINT32_C(0x338F06D6),
9369           UINT32_C(0x5C43A94C), UINT32_C(0x25E964F3), UINT32_C(0x697B4C26),
9370           UINT32_C(0x7572CCFD), UINT32_C(0x2CD5A059)},
9371          {UINT32_C(0xB5B523E4), UINT32_C(0xA09FC4D4), UINT32_C(0x4E1E9042),
9372           UINT32_C(0x7D8141E8), UINT32_C(0xD637409E), UINT32_C(0x2462512B),
9373           UINT32_C(0x7CB2CE75), UINT32_C(0x503F032F)}},
9374         {{UINT32_C(0xBCBF1450), UINT32_C(0xC56F38E3), UINT32_C(0xCF2E5594),
9375           UINT32_C(0x09F4FC77), UINT32_C(0x0FCB653A), UINT32_C(0xF449C3E6),
9376           UINT32_C(0x64A53C65), UINT32_C(0x6A1FE752)},
9377          {UINT32_C(0x7C039488), UINT32_C(0xFF366FED), UINT32_C(0x8C99A6CB),
9378           UINT32_C(0x23F58BA5), UINT32_C(0x8D67F6D6), UINT32_C(0x4B5546C6),
9379           UINT32_C(0x178B1668), UINT32_C(0x03405C85)}},
9380         {{UINT32_C(0xC0C86696), UINT32_C(0x969F1B33), UINT32_C(0x13746468),
9381           UINT32_C(0x9346D06C), UINT32_C(0xAE0C6D62), UINT32_C(0x68AED3C8),
9382           UINT32_C(0x74FE63D5), UINT32_C(0x7B3D5361)},
9383          {UINT32_C(0xC4F4B65D), UINT32_C(0xFEE8416B), UINT32_C(0x554C6D0A),
9384           UINT32_C(0xC79BF488), UINT32_C(0xDC402BB0), UINT32_C(0x191D5D27),
9385           UINT32_C(0xE087EB9F), UINT32_C(0x31B00167)}},
9386         {{UINT32_C(0xE05D281F), UINT32_C(0xD5FE0979), UINT32_C(0x3485446B),
9387           UINT32_C(0x8373AB50), UINT32_C(0x9223681F), UINT32_C(0xCE5258BA),
9388           UINT32_C(0xA37BF244), UINT32_C(0x5F82843E)},
9389          {UINT32_C(0xCFC16536), UINT32_C(0x94ED780B), UINT32_C(0xBD477733),
9390           UINT32_C(0x6A9739B3), UINT32_C(0xA04A4195), UINT32_C(0x137D68F2),
9391           UINT32_C(0x0032BFCE), UINT32_C(0x3A0F27E8)}},
9392         {{UINT32_C(0x358382F9), UINT32_C(0x7EADE421), UINT32_C(0x92E3D912),
9393           UINT32_C(0x490B9CA6), UINT32_C(0xF1AFBC2A), UINT32_C(0x040CE73E),
9394           UINT32_C(0x11AE91BA), UINT32_C(0x5745D473)},
9395          {UINT32_C(0xCE303B77), UINT32_C(0x625BED61), UINT32_C(0x85B03A1D),
9396           UINT32_C(0x85B2A1EB), UINT32_C(0x3D7C02E0), UINT32_C(0x764F62E4),
9397           UINT32_C(0xA7AF6DDE), UINT32_C(0x22C2D16F)}},
9398         {{UINT32_C(0xD19377BE), UINT32_C(0x5B985DE6), UINT32_C(0xD8E43A10),
9399           UINT32_C(0x0AF85A06), UINT32_C(0x0519F4C6), UINT32_C(0x1465E504),
9400           UINT32_C(0xE3E20BA3), UINT32_C(0x5DA01665)},
9401          {UINT32_C(0x675D9E2A), UINT32_C(0xCD9B8E9B), UINT32_C(0x6448A2CD),
9402           UINT32_C(0x4C77E1AD), UINT32_C(0x1E5D4465), UINT32_C(0xD6094BAD),
9403           UINT32_C(0xC50DB788), UINT32_C(0x4C352951)}},
9404         {{UINT32_C(0xEE5AB903), UINT32_C(0x42581152), UINT32_C(0x63311418),
9405           UINT32_C(0xDAD2DBC9), UINT32_C(0xB885E56A), UINT32_C(0xBCA4F70B),
9406           UINT32_C(0xB94E0876), UINT32_C(0x1F5DD363)},
9407          {UINT32_C(0x3FFF479E), UINT32_C(0xF9AD5D04), UINT32_C(0xFE06AD2B),
9408           UINT32_C(0xEF1176E5), UINT32_C(0x216F77AF), UINT32_C(0x46ACB00A),
9409           UINT32_C(0x857C4F78), UINT32_C(0x709CF4EB)}},
9410         {{UINT32_C(0xD0D2FF1C), UINT32_C(0x70CD666E), UINT32_C(0xE7EFE4AD),
9411           UINT32_C(0x4BAD4A6A), UINT32_C(0x0FA72024), UINT32_C(0xB43F6C2D),
9412           UINT32_C(0xE90C0617), UINT32_C(0x0D78F8E2)},
9413          {UINT32_C(0xF80DCAA7), UINT32_C(0x543B9662), UINT32_C(0xF28ADFAF),
9414           UINT32_C(0xB02FB3BC), UINT32_C(0xC51C54C3), UINT32_C(0x26C17651),
9415           UINT32_C(0x3D648D88), UINT32_C(0x0815F637)}},
9416         {{UINT32_C(0xAEA98FA6), UINT32_C(0xAC4F43C1), UINT32_C(0xAC4398C6),
9417           UINT32_C(0x2D223416), UINT32_C(0xDA5C5070), UINT32_C(0x48B2EEAD),
9418           UINT32_C(0xBE666F70), UINT32_C(0x632B65F1)},
9419          {UINT32_C(0x952021BE), UINT32_C(0x971D3BC0), UINT32_C(0x23B2C578),
9420           UINT32_C(0x9FDCB7E0), UINT32_C(0x3CC21796), UINT32_C(0x476D4715),
9421           UINT32_C(0x95832A94), UINT32_C(0x4015565F)}},
9422         {{UINT32_C(0x13CA725C), UINT32_C(0x8913AFAC), UINT32_C(0xDC18F0D9),
9423           UINT32_C(0xA56DC461), UINT32_C(0x10F3AAFE), UINT32_C(0xAC3AC720),
9424           UINT32_C(0xC628D69C), UINT32_C(0x5D75567E)},
9425          {UINT32_C(0xEEEA4BF7), UINT32_C(0xC11BE9DC), UINT32_C(0x1C193BD5),
9426           UINT32_C(0xAD97FBCA), UINT32_C(0xC58123E8), UINT32_C(0xD1EC5BCE),
9427           UINT32_C(0x9C73D4E5), UINT32_C(0x0F6DF930)}},
9428         {{UINT32_C(0xFD759FFD), UINT32_C(0xE80A0ADA), UINT32_C(0x239CAFC0),
9429           UINT32_C(0xE52DF94B), UINT32_C(0xFE7A43E9), UINT32_C(0x59640161),
9430           UINT32_C(0xDB1A38F0), UINT32_C(0x7A96995C)},
9431          {UINT32_C(0x7CD5011B), UINT32_C(0xA46A1503), UINT32_C(0xAC0E9689),
9432           UINT32_C(0x75CFB637), UINT32_C(0x97AAD2BA), UINT32_C(0x27B740CA),
9433           UINT32_C(0xEAD2F776), UINT32_C(0x64A0748B)}},
9434         {{UINT32_C(0x0625B3B1), UINT32_C(0xB67E5BB5), UINT32_C(0xC66D2832),
9435           UINT32_C(0x2FE19FFB), UINT32_C(0xF70C07CF), UINT32_C(0x47815666),
9436           UINT32_C(0xA43E52AB), UINT32_C(0x5A1AA24A)},
9437          {UINT32_C(0x4CAC0E66), UINT32_C(0x04EE11F8), UINT32_C(0x3A3A4836),
9438           UINT32_C(0x51E51583), UINT32_C(0xB44F6DEC), UINT32_C(0x46755F49),
9439           UINT32_C(0xC1E9B282), UINT32_C(0x6388408B)}},
9440         {{UINT32_C(0x9DE7A6A7), UINT32_C(0xD47AA9A6), UINT32_C(0x189BC9D2),
9441           UINT32_C(0xEC94AD9B), UINT32_C(0x8EC0E950), UINT32_C(0xFA89099D),
9442           UINT32_C(0x9F64D27F), UINT32_C(0x1B9FC206)},
9443          {UINT32_C(0x0B729DE1), UINT32_C(0x76572484), UINT32_C(0x4BE22EB8),
9444           UINT32_C(0xFE9E8E71), UINT32_C(0xF9DB5942), UINT32_C(0x910F0456),
9445           UINT32_C(0xC617D82B), UINT32_C(0x4D018459)}},
9446         {{UINT32_C(0xF5516C6F), UINT32_C(0xB082B58A), UINT32_C(0x567A8CF5),
9447           UINT32_C(0xFFBA0E73), UINT32_C(0x8A6DD4A0), UINT32_C(0x08FF64CE),
9448           UINT32_C(0x69A9F66A), UINT32_C(0x6CF3C89C)},
9449          {UINT32_C(0x62FEB0A7), UINT32_C(0x356782BA), UINT32_C(0x3E2907F9),
9450           UINT32_C(0x1A18720D), UINT32_C(0x0BBD9D92), UINT32_C(0xF840FFA3),
9451           UINT32_C(0x20926421), UINT32_C(0x41D9EECA)}},
9452         {{UINT32_C(0xB6B08321), UINT32_C(0xCF2E8AAC), UINT32_C(0x010D91C0),
9453           UINT32_C(0xC76FBE12), UINT32_C(0x68E35E02), UINT32_C(0x54924750),
9454           UINT32_C(0x9AEE00F8), UINT32_C(0x74DBA2E1)},
9455          {UINT32_C(0xC5504E82), UINT32_C(0x94C70D6D), UINT32_C(0xEA1770F7),
9456           UINT32_C(0x0BDF415F), UINT32_C(0x3CA6DB0A), UINT32_C(0xDA45B700),
9457           UINT32_C(0xE133A980), UINT32_C(0x473C6A04)}},
9458         {{UINT32_C(0x1E188071), UINT32_C(0xD1FF6C1E), UINT32_C(0xEA3F16F8),
9459           UINT32_C(0x621A7D3C), UINT32_C(0x6A160F47), UINT32_C(0x60467307),
9460           UINT32_C(0x32DC84EE), UINT32_C(0x37CA7D3D)},
9461          {UINT32_C(0x67DDFDB5), UINT32_C(0x54F5F7F6), UINT32_C(0x921BA04B),
9462           UINT32_C(0x3A8482F9), UINT32_C(0x1A28E238), UINT32_C(0x842F4950),
9463           UINT32_C(0x7214FAFD), UINT32_C(0x3A4DC917)}},
9464     },
9465     {
9466         {{UINT32_C(0xEEA25E82), UINT32_C(0xEDD8360C), UINT32_C(0xFB7B7ED0),
9467           UINT32_C(0x3DB6D933), UINT32_C(0xABF15199), UINT32_C(0x882F3C0B),
9468           UINT32_C(0x516E349D), UINT32_C(0x228664A2)},
9469          {UINT32_C(0xE88173DF), UINT32_C(0x96E6DCF7), UINT32_C(0xD7EC0BC3),
9470           UINT32_C(0x382C8D3B), UINT32_C(0x6FA5FA58), UINT32_C(0xFBFF6D21),
9471           UINT32_C(0x2F41C959), UINT32_C(0x78003980)}},
9472         {{UINT32_C(0x9D9ACF9C), UINT32_C(0x713BA43B), UINT32_C(0x94876559),
9473           UINT32_C(0xF59A252D), UINT32_C(0x437B8ED5), UINT32_C(0x8B310954),
9474           UINT32_C(0xE474E98E), UINT32_C(0x76A83790)},
9475          {UINT32_C(0xF6040B05), UINT32_C(0x84C1386A), UINT32_C(0xBF3D8189),
9476           UINT32_C(0x69FA9F43), UINT32_C(0xA98D4866), UINT32_C(0x5584164C),
9477           UINT32_C(0x3B9045D0), UINT32_C(0x6C89CE1D)}},
9478         {{UINT32_C(0xB522FB28), UINT32_C(0xD6EF7540), UINT32_C(0xBB28D745),
9479           UINT32_C(0xDB561B56), UINT32_C(0xEFA58B87), UINT32_C(0xC9F7543E),
9480           UINT32_C(0xE9062979), UINT32_C(0x5F02A23B)},
9481          {UINT32_C(0x6809D624), UINT32_C(0xFD3C0C19), UINT32_C(0xA92EB229),
9482           UINT32_C(0x94481554), UINT32_C(0xF5147EFB), UINT32_C(0x72D8EC53),
9483           UINT32_C(0x0D1BA626), UINT32_C(0x14302661)}},
9484         {{UINT32_C(0x89020800), UINT32_C(0x0B35BD59), UINT32_C(0x430D7DEB),
9485           UINT32_C(0x3C6F1527), UINT32_C(0x2FFFA0E0), UINT32_C(0x9BEB3C8E),
9486           UINT32_C(0xAFD09A19), UINT32_C(0x7E181B78)},
9487          {UINT32_C(0x3B2F0B49), UINT32_C(0xE82FD957), UINT32_C(0x0BC0F9DA),
9488           UINT32_C(0x4C9461B1), UINT32_C(0x2B1C8B85), UINT32_C(0x87D78C41),
9489           UINT32_C(0xC1F5BDA1), UINT32_C(0x775BED20)}},
9490         {{UINT32_C(0x16350593), UINT32_C(0x883AE89B), UINT32_C(0x0C19FEC8),
9491           UINT32_C(0x85D429CB), UINT32_C(0x5742C36D), UINT32_C(0x5938BDEC),
9492           UINT32_C(0xDA8A21B7), UINT32_C(0x2DDBC7EB)},
9493          {UINT32_C(0x07A2E700), UINT32_C(0xA249BDE4), UINT32_C(0xE8BD6215),
9494           UINT32_C(0x42A3897C), UINT32_C(0x732FF181), UINT32_C(0x87F30BA7),
9495           UINT32_C(0x1B912C57), UINT32_C(0x5385D709)}},
9496         {{UINT32_C(0x288041F5), UINT32_C(0x2B5C555B), UINT32_C(0x1F425866),
9497           UINT32_C(0xD3D90040), UINT32_C(0x02E0FA71), UINT32_C(0x37E40CD2),
9498           UINT32_C(0x3A386038), UINT32_C(0x08B37F26)},
9499          {UINT32_C(0x5DE1ED78), UINT32_C(0x165BD7FB), UINT32_C(0x0829ECC9),
9500           UINT32_C(0x22949E81), UINT32_C(0xBCE3D01F), UINT32_C(0xBB8705CC),
9501           UINT32_C(0x1D233CDF), UINT32_C(0x7961BE85)}},
9502         {{UINT32_C(0x7659B477), UINT32_C(0x5D3DBC6B), UINT32_C(0x50EF08EB),
9503           UINT32_C(0xFD865779), UINT32_C(0xF34EA1A5), UINT32_C(0x502729E8),
9504           UINT32_C(0xD2B64602), UINT32_C(0x1548526E)},
9505          {UINT32_C(0xB91D2675), UINT32_C(0xB13632FD), UINT32_C(0xF7B37397),
9506           UINT32_C(0x09A42003), UINT32_C(0xCCFC4532), UINT32_C(0x37D18F37),
9507           UINT32_C(0x73C7082C), UINT32_C(0x3FAEF63B)}},
9508         {{UINT32_C(0xE666DB6D), UINT32_C(0x3365445F), UINT32_C(0x339A0076),
9509           UINT32_C(0x9051FFF5), UINT32_C(0x9BD6D01D), UINT32_C(0x6167FB76),
9510           UINT32_C(0xCA087B41), UINT32_C(0x09737137)},
9511          {UINT32_C(0xB3270BA7), UINT32_C(0xCA2193AE), UINT32_C(0x8F2217B3),
9512           UINT32_C(0xEF0744C2), UINT32_C(0xF0DD10D8), UINT32_C(0x3E030D58),
9513           UINT32_C(0xCCB4F2F9), UINT32_C(0x667246DB)}},
9514         {{UINT32_C(0x3773EC8C), UINT32_C(0x31F3030E), UINT32_C(0x5AD56010),
9515           UINT32_C(0xAF2B3123), UINT32_C(0xB37E9062), UINT32_C(0xFC118587),
9516           UINT32_C(0x9C2D5406), UINT32_C(0x52840C2C)},
9517          {UINT32_C(0x6670ACBB), UINT32_C(0xA96D3DFF), UINT32_C(0x772EC6D3),
9518           UINT32_C(0xF469982F), UINT32_C(0xA9DF4C88), UINT32_C(0x5BE20628),
9519           UINT32_C(0x673633BC), UINT32_C(0x59D01479)}},
9520         {{UINT32_C(0xAFB5083B), UINT32_C(0xC9223750), UINT32_C(0x191C2160),
9521           UINT32_C(0xF1EB451E), UINT32_C(0xA38EC005), UINT32_C(0x0D913794),
9522           UINT32_C(0x83FD1D18), UINT32_C(0x31062E9E)},
9523          {UINT32_C(0x5F4816AD), UINT32_C(0x070538F5), UINT32_C(0x925F5DA1),
9524           UINT32_C(0x90D4855D), UINT32_C(0x22F455B6), UINT32_C(0xC0BBA87B),
9525           UINT32_C(0xF48D2AE5), UINT32_C(0x517B5F80)}},
9526         {{UINT32_C(0x3F4FA7CA), UINT32_C(0x0D8B670A), UINT32_C(0x3D114EB2),
9527           UINT32_C(0xE29C8849), UINT32_C(0x916A187E), UINT32_C(0x1823780D),
9528           UINT32_C(0x65EE66A0), UINT32_C(0x6961C483)},
9529          {UINT32_C(0x62FDC12C), UINT32_C(0x2F6FB20A), UINT32_C(0x0CFDDE0C),
9530           UINT32_C(0x51414E5F), UINT32_C(0xDCA39073), UINT32_C(0x16BD56A7),
9531           UINT32_C(0x648FFD43), UINT32_C(0x0CFE6DAF)}},
9532         {{UINT32_C(0xAEBA9241), UINT32_C(0x3789F4CA), UINT32_C(0x107777C6),
9533           UINT32_C(0xE8056BC6), UINT32_C(0x3CB20826), UINT32_C(0x6EE564C3),
9534           UINT32_C(0x45448C69), UINT32_C(0x5DF36347)},
9535          {UINT32_C(0xB22CE624), UINT32_C(0xFD0FA84B), UINT32_C(0xAC753D50),
9536           UINT32_C(0x2AA19672), UINT32_C(0x677CC0D0), UINT32_C(0x29A1464F),
9537           UINT32_C(0x3CEF5493), UINT32_C(0x7C2237B1)}},
9538         {{UINT32_C(0x24255918), UINT32_C(0x87C2587C), UINT32_C(0x90B35A37),
9539           UINT32_C(0x9AA89A0B), UINT32_C(0x10E7CAEF), UINT32_C(0x9932EB78),
9540           UINT32_C(0xCDE31568), UINT32_C(0x49278F16)},
9541          {UINT32_C(0x41188ED9), UINT32_C(0xA4D33C61), UINT32_C(0x05AC3A1D),
9542           UINT32_C(0xC587BDE0), UINT32_C(0x7248B5E0), UINT32_C(0x2A5C5ACC),
9543           UINT32_C(0x8510D2CB), UINT32_C(0x60026A1D)}},
9544         {{UINT32_C(0x6BAF603C), UINT32_C(0xE57CB0C9), UINT32_C(0xAB770AF0),
9545           UINT32_C(0x527F28A6), UINT32_C(0x016F2BC1), UINT32_C(0x2850D8E6),
9546           UINT32_C(0x936DC2EC), UINT32_C(0x0EC2A46C)},
9547          {UINT32_C(0xD4F23FC2), UINT32_C(0xA0BC5306), UINT32_C(0x53A0130F),
9548           UINT32_C(0x6DBEDA26), UINT32_C(0xEE3314B7), UINT32_C(0xB1D52F87),
9549           UINT32_C(0x6C234CF5), UINT32_C(0x17168B12)}},
9550         {{UINT32_C(0xDADF17D5), UINT32_C(0x8B8BC181), UINT32_C(0xFAFFA918),
9551           UINT32_C(0x31EC3CAD), UINT32_C(0x274E4658), UINT32_C(0x4611A482),
9552           UINT32_C(0x73D35EAD), UINT32_C(0x5A9E3652)},
9553          {UINT32_C(0xF4028FC7), UINT32_C(0xBA68825B), UINT32_C(0x62E203F5),
9554           UINT32_C(0x142859D5), UINT32_C(0x1C817A9E), UINT32_C(0xCE516AC4),
9555           UINT32_C(0x57223F8D), UINT32_C(0x42014682)}},
9556         {{UINT32_C(0xB4B66798), UINT32_C(0x51FBFB2E), UINT32_C(0x0EA9C4EF),
9557           UINT32_C(0x3A3F1591), UINT32_C(0xE8814805), UINT32_C(0x3FD3D026),
9558           UINT32_C(0xB0C8DFD0), UINT32_C(0x3CA531E4)},
9559          {UINT32_C(0xE585A960), UINT32_C(0x69A6B3F8), UINT32_C(0xBD3F567D),
9560           UINT32_C(0x1627CC77), UINT32_C(0x5DB9CFD0), UINT32_C(0x6F4EF430),
9561           UINT32_C(0x8D02278A), UINT32_C(0x05B56707)}},
9562     },
9563     {
9564         {{UINT32_C(0x10B96338), UINT32_C(0x6663F2F3), UINT32_C(0xCE8CA31C),
9565           UINT32_C(0x69373D1F), UINT32_C(0xD67AEC10), UINT32_C(0x3D31C5CF),
9566           UINT32_C(0x16F2547E), UINT32_C(0x2FAF5545)},
9567          {UINT32_C(0x1EA2EA64), UINT32_C(0xF6E397D5), UINT32_C(0xEEAEBE7A),
9568           UINT32_C(0x2281A0DF), UINT32_C(0xFA2527EC), UINT32_C(0x72E53254),
9569           UINT32_C(0x76432155), UINT32_C(0x660D059A)}},
9570         {{UINT32_C(0x2C66D937), UINT32_C(0xD3CA8B13), UINT32_C(0xCD2DF849),
9571           UINT32_C(0xC6F34B08), UINT32_C(0xA23A9F73), UINT32_C(0x9AF2C9E3),
9572           UINT32_C(0x702388E9), UINT32_C(0x24D44BD9)},
9573          {UINT32_C(0xD1B3DA10), UINT32_C(0x8DA4D6A4), UINT32_C(0x40B93B10),
9574           UINT32_C(0xB9FAFBF4), UINT32_C(0xEFCFD2A3), UINT32_C(0xBBE51BB3),
9575           UINT32_C(0x1844581D), UINT32_C(0x68BE0395)}},
9576         {{UINT32_C(0x0EA1FAE1), UINT32_C(0xDECABD8C), UINT32_C(0xFDFED7C2),
9577           UINT32_C(0xA7499225), UINT32_C(0xFB468B83), UINT32_C(0x08489E35),
9578           UINT32_C(0x43D95F9C), UINT32_C(0x5B689344)},
9579          {UINT32_C(0x9D2F522E), UINT32_C(0x9FC8364A), UINT32_C(0x3A5D27A4),
9580           UINT32_C(0x114DB31A), UINT32_C(0xE33A9EC8), UINT32_C(0xC6A35992),
9581           UINT32_C(0xDC9ACAF6), UINT32_C(0x6FE9EC3B)}},
9582         {{UINT32_C(0xDEAFC64C), UINT32_C(0x98AE2D66), UINT32_C(0xABE706B7),
9583           UINT32_C(0x95AAC8EF), UINT32_C(0x223DFA3B), UINT32_C(0xB15A6604),
9584           UINT32_C(0xE24B43CB), UINT32_C(0x77DBC24A)},
9585          {UINT32_C(0x8542FA2A), UINT32_C(0x65D6F871), UINT32_C(0x5D326A1A),
9586           UINT32_C(0x1093B273), UINT32_C(0xF137AFEF), UINT32_C(0xBA82D607),
9587           UINT32_C(0xB9DEA6A7), UINT32_C(0x502B32E3)}},
9588         {{UINT32_C(0x885CA6CE), UINT32_C(0x88906BD6), UINT32_C(0x1D36BFEE),
9589           UINT32_C(0x136ADF9A), UINT32_C(0x09AA61E3), UINT32_C(0xF844088C),
9590           UINT32_C(0x51BAC299), UINT32_C(0x4E508EA3)},
9591          {UINT32_C(0xEB821936), UINT32_C(0x251ACD26), UINT32_C(0x43D90E10),
9592           UINT32_C(0xDF6AD7D5), UINT32_C(0xDE7F14B9), UINT32_C(0xEBCD7046),
9593           UINT32_C(0xAB503259), UINT32_C(0x1DB258B1)}},
9594         {{UINT32_C(0x90AD5D55), UINT32_C(0x348E3018), UINT32_C(0x7067806A),
9595           UINT32_C(0x0EF6BE73), UINT32_C(0x41627FCC), UINT32_C(0x072C1134),
9596           UINT32_C(0xE904F823), UINT32_C(0x48EE7606)},
9597          {UINT32_C(0xD9FD5EF3), UINT32_C(0xEE6AB582), UINT32_C(0x17AB50BC),
9598           UINT32_C(0x57765D03), UINT32_C(0xFB7DEC68), UINT32_C(0x1CCFB407),
9599           UINT32_C(0x141DF51D), UINT32_C(0x2E1771C7)}},
9600         {{UINT32_C(0xA013284B), UINT32_C(0xCBDD6235), UINT32_C(0x20D07125),
9601           UINT32_C(0x4D93FD87), UINT32_C(0xD485418E), UINT32_C(0xB3D055B3),
9602           UINT32_C(0xC67ADD2D), UINT32_C(0x4EFB8763)},
9603          {UINT32_C(0x1B2DF427), UINT32_C(0xEC369382), UINT32_C(0x64D0DDF4),
9604           UINT32_C(0x25009791), UINT32_C(0x163056C8), UINT32_C(0x9BD42FFC),
9605           UINT32_C(0x5B88BEBA), UINT32_C(0x60527792)}},
9606         {{UINT32_C(0x9D82DADF), UINT32_C(0x6D5D6A86), UINT32_C(0x7C24A1CA),
9607           UINT32_C(0xC3BA9A16), UINT32_C(0x2E6981CC), UINT32_C(0x838167EC),
9608           UINT32_C(0x7E1E4237), UINT32_C(0x7FB5D857)},
9609          {UINT32_C(0x86A40BC7), UINT32_C(0x83B2C2FC), UINT32_C(0x6F9AC4FB),
9610           UINT32_C(0x679D2DFC), UINT32_C(0xE45455EF), UINT32_C(0x0B3714CD),
9611           UINT32_C(0x394A7797), UINT32_C(0x1C8D833D)}},
9612         {{UINT32_C(0x4E641C9D), UINT32_C(0x1FBF8961), UINT32_C(0xD951DFC8),
9613           UINT32_C(0x3330DAB0), UINT32_C(0x051D96DB), UINT32_C(0x9D4EBA4D),
9614           UINT32_C(0x23066924), UINT32_C(0x27C6DBF0)},
9615          {UINT32_C(0xDA5D1D79), UINT32_C(0xB950C648), UINT32_C(0x5E9CD783),
9616           UINT32_C(0x544D46BA), UINT32_C(0xE69BA3EF), UINT32_C(0xFA77226F),
9617           UINT32_C(0xE4DA8423), UINT32_C(0x0A93D219)}},
9618         {{UINT32_C(0x5BDCA76B), UINT32_C(0x7C377CC6), UINT32_C(0xDC58D194),
9619           UINT32_C(0x7DF505D7), UINT32_C(0x13E389E1), UINT32_C(0x18A24C0B),
9620           UINT32_C(0x6C3972FD), UINT32_C(0x5E0782DD)},
9621          {UINT32_C(0x6680FCE1), UINT32_C(0x97AD477E), UINT32_C(0x3CBAB792),
9622           UINT32_C(0x6B07BF22), UINT32_C(0xDC68C9E2), UINT32_C(0xB8DF3C73),
9623           UINT32_C(0xC04B2749), UINT32_C(0x33AB5A4C)}},
9624         {{UINT32_C(0x7E79B5A7), UINT32_C(0xD151C762), UINT32_C(0xC82C7B8A),
9625           UINT32_C(0xA4356B79), UINT32_C(0x96E0A2E2), UINT32_C(0x931DDDE8),
9626           UINT32_C(0x52C54FDC), UINT32_C(0x40378EB2)},
9627          {UINT32_C(0x40C24003), UINT32_C(0xA6BBD5E3), UINT32_C(0x65C34FEA),
9628           UINT32_C(0xB4F3246E), UINT32_C(0x9C767A23), UINT32_C(0x780B21ED),
9629           UINT32_C(0x52BD7E83), UINT32_C(0x5F1E95FE)}},
9630         {{UINT32_C(0xCF39F9C4), UINT32_C(0x4F3453DF), UINT32_C(0xB8CC2CA6),
9631           UINT32_C(0xA3E1CFD1), UINT32_C(0x4B898859), UINT32_C(0xE49BC49C),
9632           UINT32_C(0x6C0BF055), UINT32_C(0x4FFD7BD6)},
9633          {UINT32_C(0xD139AD1B), UINT32_C(0x7DE7604C), UINT32_C(0x2A3CE8FE),
9634           UINT32_C(0x6973F5EB), UINT32_C(0xF9501ECC), UINT32_C(0xAC66FF97),
9635           UINT32_C(0xA97D46CD), UINT32_C(0x3D96F1E2)}},
9636         {{UINT32_C(0x6106EB96), UINT32_C(0x70D5A0D0), UINT32_C(0x398C1FD9),
9637           UINT32_C(0x938E038F), UINT32_C(0x1F3A1AA9), UINT32_C(0xE66B7007),
9638           UINT32_C(0xF5BD9308), UINT32_C(0x42BDB264)},
9639          {UINT32_C(0x5AF84957), UINT32_C(0x4B3FD754), UINT32_C(0x4E27DC6B),
9640           UINT32_C(0x9E3E17FA), UINT32_C(0x51D8560B), UINT32_C(0x384FCACD),
9641           UINT32_C(0xF8068C09), UINT32_C(0x42F00D11)}},
9642         {{UINT32_C(0x7D5897D5), UINT32_C(0x794C1E6A), UINT32_C(0xDF72DCA0),
9643           UINT32_C(0x4901097F), UINT32_C(0x0B01E4C4), UINT32_C(0xDED5B192),
9644           UINT32_C(0x26DD41E9), UINT32_C(0x364FF582)},
9645          {UINT32_C(0x32FCA925), UINT32_C(0xA3F92DCC), UINT32_C(0x207AA09A),
9646           UINT32_C(0x8A1FB329), UINT32_C(0xF512AE3A), UINT32_C(0xA9274BD3),
9647           UINT32_C(0xC47B9007), UINT32_C(0x161C82BC)}},
9648         {{UINT32_C(0x7AE1175F), UINT32_C(0x482ECE3B), UINT32_C(0xBDD5DC6C),
9649           UINT32_C(0x97CAC7E8), UINT32_C(0x9FDA910D), UINT32_C(0x56225309),
9650           UINT32_C(0x9FC206B9), UINT32_C(0x52A9893B)},
9651          {UINT32_C(0x05BB5ACA), UINT32_C(0xAD9F2A92), UINT32_C(0xA3B65716),
9652           UINT32_C(0xB9EEFB5B), UINT32_C(0x8DB5A8D4), UINT32_C(0xE7BC173B),
9653           UINT32_C(0x399DAE9E), UINT32_C(0x6715EC64)}},
9654         {{UINT32_C(0x5E41AC75), UINT32_C(0x780796D1), UINT32_C(0x4FB3A0B4),
9655           UINT32_C(0x3E165C78), UINT32_C(0x237103E9), UINT32_C(0x198599BA),
9656           UINT32_C(0xFA7ED86B), UINT32_C(0x2C04C3F5)},
9657          {UINT32_C(0xAC9356F0), UINT32_C(0x29547DA8), UINT32_C(0x79EADA37),
9658           UINT32_C(0xCB345AB4), UINT32_C(0xA295BF2D), UINT32_C(0x1D15D377),
9659           UINT32_C(0x2FDC8131), UINT32_C(0x10292C9D)}},
9660     },
9661     {
9662         {{UINT32_C(0x40E1DC7E), UINT32_C(0xADF3B547), UINT32_C(0x1C345D14),
9663           UINT32_C(0x420CE2DD), UINT32_C(0x21DC5C2D), UINT32_C(0xC08E3CBE),
9664           UINT32_C(0x6F8FCE80), UINT32_C(0x79FDC000)},
9665          {UINT32_C(0xCB105CE7), UINT32_C(0x23EBDF7F), UINT32_C(0x7C6794A8),
9666           UINT32_C(0x793FC99D), UINT32_C(0x293E3575), UINT32_C(0x4CA3FB21),
9667           UINT32_C(0x7BF73CC8), UINT32_C(0x7FB2ACB9)}},
9668         {{UINT32_C(0x0FC8FCD4), UINT32_C(0x67DB6C90), UINT32_C(0x7EE3B705),
9669           UINT32_C(0x22A3DF5F), UINT32_C(0xC7B2EDFF), UINT32_C(0xD50EBF8B),
9670           UINT32_C(0x99522FB7), UINT32_C(0x0C701045)},
9671          {UINT32_C(0xAD4F9044), UINT32_C(0x1420CF02), UINT32_C(0xE5B59451),
9672           UINT32_C(0xD78DBA23), UINT32_C(0x6AEFD853), UINT32_C(0xDFDC1C7F),
9673           UINT32_C(0xDEA1DAAB), UINT32_C(0x560DEE94)}},
9674         {{UINT32_C(0x2167A78B), UINT32_C(0x0F235513), UINT32_C(0x9F441927),
9675           UINT32_C(0xCF463702), UINT32_C(0xA3D1505C), UINT32_C(0xD0AE2723),
9676           UINT32_C(0xCD9FBFF4), UINT32_C(0x3149D858)},
9677          {UINT32_C(0xF79240FA), UINT32_C(0x2A73913A), UINT32_C(0x252A958B),
9678           UINT32_C(0xC904A575), UINT32_C(0x78473D97), UINT32_C(0x10D18190),
9679           UINT32_C(0x203BC8C4), UINT32_C(0x42CE7A38)}},
9680         {{UINT32_C(0xFA59BB8B), UINT32_C(0x1D2AD4F2), UINT32_C(0x79F137DD),
9681           UINT32_C(0x8234964C), UINT32_C(0x5D02679E), UINT32_C(0x00B63A30),
9682           UINT32_C(0x5DD7543D), UINT32_C(0x506C45BE)},
9683          {UINT32_C(0x776BF80C), UINT32_C(0x4378F900), UINT32_C(0xB312F2BB),
9684           UINT32_C(0x179558B2), UINT32_C(0xEA37C183), UINT32_C(0x5B15368C),
9685           UINT32_C(0xB198E42D), UINT32_C(0x7593B19F)}},
9686         {{UINT32_C(0xDEFA1F48), UINT32_C(0xED723535), UINT32_C(0x87F96EE5),
9687           UINT32_C(0x0DAFC48B), UINT32_C(0x91B1B52C), UINT32_C(0x0AEFA3BA),
9688           UINT32_C(0xA1ADBEA4), UINT32_C(0x56BA1B33)},
9689          {UINT32_C(0x30A6C905), UINT32_C(0x8A0B6170), UINT32_C(0xB272D12E),
9690           UINT32_C(0xC5BA3518), UINT32_C(0x4B6643A9), UINT32_C(0x782100CF),
9691           UINT32_C(0x85C5BD2B), UINT32_C(0x12DEE803)}},
9692         {{UINT32_C(0x78FCADD6), UINT32_C(0xDD07D2D5), UINT32_C(0x3B25C523),
9693           UINT32_C(0x8CB8E8A8), UINT32_C(0x530919CF), UINT32_C(0x25063508),
9694           UINT32_C(0x1E24F7A1), UINT32_C(0x45D3DD54)},
9695          {UINT32_C(0x49DDAF96), UINT32_C(0x296AE893), UINT32_C(0xACE559F5),
9696           UINT32_C(0x7EF3CDE0), UINT32_C(0x0D36F87B), UINT32_C(0x9CDF22E4),
9697           UINT32_C(0x4AC9A845), UINT32_C(0x19684765)}},
9698         {{UINT32_C(0xC597B7AE), UINT32_C(0x3955B5AB), UINT32_C(0x3AB49731),
9699           UINT32_C(0x59F3BA05), UINT32_C(0xF525C6C8), UINT32_C(0xBCA5B117),
9700           UINT32_C(0x32050B8D), UINT32_C(0x4969C134)},
9701          {UINT32_C(0x970E8E49), UINT32_C(0x353183D9), UINT32_C(0xE95300CF),
9702           UINT32_C(0x3D005213), UINT32_C(0x09022378), UINT32_C(0x595F9C8E),
9703           UINT32_C(0x1A445C28), UINT32_C(0x70FA8B47)}},
9704         {{UINT32_C(0xBADB79EA), UINT32_C(0xECC88EE3), UINT32_C(0xFBD8464E),
9705           UINT32_C(0x5BDAF68C), UINT32_C(0xB4280334), UINT32_C(0x24AF6A4C),
9706           UINT32_C(0x398E5BBE), UINT32_C(0x17A5DE8B)},
9707          {UINT32_C(0x92999E18), UINT32_C(0x300B6DEB), UINT32_C(0x67DEFC2F),
9708           UINT32_C(0xA0766918), UINT32_C(0xB19F87FF), UINT32_C(0x4E904450),
9709           UINT32_C(0xC2871056), UINT32_C(0x3010AD94)}},
9710         {{UINT32_C(0x461EFCC3), UINT32_C(0x72E747A1), UINT32_C(0x562F923E),
9711           UINT32_C(0x329EDF18), UINT32_C(0xD081A4E7), UINT32_C(0x65E021D4),
9712           UINT32_C(0xB727B6F4), UINT32_C(0x4B2DBFFF)},
9713          {UINT32_C(0x9C8505AC), UINT32_C(0x5A597A80), UINT32_C(0x562B82D2),
9714           UINT32_C(0x13486480), UINT32_C(0xCC8234C3), UINT32_C(0x477FD480),
9715           UINT32_C(0x04800C00), UINT32_C(0x6045ABA4)}},
9716         {{UINT32_C(0x9C541035), UINT32_C(0x3E087439), UINT32_C(0x6D9D8B6A),
9717           UINT32_C(0x389AA76C), UINT32_C(0x36A21299), UINT32_C(0x68FE5E83),
9718           UINT32_C(0x402A32CF), UINT32_C(0x67AC313D)},
9719          {UINT32_C(0x25501A53), UINT32_C(0x996131D2), UINT32_C(0xA77A85F4),
9720           UINT32_C(0x5C1B89DE), UINT32_C(0xED6702AD), UINT32_C(0xA9822C84),
9721           UINT32_C(0x56609EA0), UINT32_C(0x50F014A4)}},
9722         {{UINT32_C(0xE5A8E91E), UINT32_C(0xF0F8B4E6), UINT32_C(0x1A2FFEFD),
9723           UINT32_C(0x734CFF08), UINT32_C(0x27BCB163), UINT32_C(0x9724EE0B),
9724           UINT32_C(0x30B8EF68), UINT32_C(0x6AF3808B)},
9725          {UINT32_C(0x126E88FC), UINT32_C(0xE5B3829F), UINT32_C(0x4EE5FD4B),
9726           UINT32_C(0x0F441EE3), UINT32_C(0xBFEC4D34), UINT32_C(0x534D2F8C),
9727           UINT32_C(0x076E6737), UINT32_C(0x3E1F16DE)}},
9728         {{UINT32_C(0x4ED36E6A), UINT32_C(0x4DB53E8A), UINT32_C(0x4352B22F),
9729           UINT32_C(0x49A9EFE9), UINT32_C(0x39CF005C), UINT32_C(0x7829605C),
9730           UINT32_C(0xD85DB959), UINT32_C(0x190A8E16)},
9731          {UINT32_C(0x9B073AB3), UINT32_C(0x69981069), UINT32_C(0x8C141AA1),
9732           UINT32_C(0x8C264B87), UINT32_C(0x603ED47C), UINT32_C(0x7F614282),
9733           UINT32_C(0x9F9B0940), UINT32_C(0x21FD2E7A)}},
9734         {{UINT32_C(0x1EC6BB3D), UINT32_C(0xC5CA10A0), UINT32_C(0x27A9B02B),
9735           UINT32_C(0x9403E3F5), UINT32_C(0xFB43F790), UINT32_C(0x9D3D186D),
9736           UINT32_C(0x67DC0C00), UINT32_C(0x7855276E)},
9737          {UINT32_C(0xFFFFB14C), UINT32_C(0x053DBB2A), UINT32_C(0x43ACC0A6),
9738           UINT32_C(0x26746663), UINT32_C(0x7FFC1C68), UINT32_C(0x1EE7A946),
9739           UINT32_C(0x56DBB0DE), UINT32_C(0x14BFAF01)}},
9740         {{UINT32_C(0x849EA674), UINT32_C(0x11C89A47), UINT32_C(0x94A540E6),
9741           UINT32_C(0x194FAAF0), UINT32_C(0x6050E4C0), UINT32_C(0xE61163F8),
9742           UINT32_C(0xB1A07B76), UINT32_C(0x6939A166)},
9743          {UINT32_C(0x2EF18325), UINT32_C(0x8166CA8E), UINT32_C(0x30C042E2),
9744           UINT32_C(0x96112E65), UINT32_C(0x5A394C25), UINT32_C(0xA805CAE0),
9745           UINT32_C(0x0392E6BB), UINT32_C(0x45A0DE01)}},
9746         {{UINT32_C(0xB4FAAA56), UINT32_C(0xB89CEE96), UINT32_C(0x529736DE),
9747           UINT32_C(0x7A7DC8AE), UINT32_C(0xA727FCF7), UINT32_C(0x9158AA49),
9748           UINT32_C(0x1896B9DA), UINT32_C(0x621B8B31)},
9749          {UINT32_C(0x03BEC74B), UINT32_C(0x875930D6), UINT32_C(0xA7A50309),
9750           UINT32_C(0x1056DB45), UINT32_C(0xB5657B0E), UINT32_C(0xEE713E04),
9751           UINT32_C(0x6FCAD967), UINT32_C(0x2D68155E)}},
9752         {{UINT32_C(0x65B1E2B3), UINT32_C(0x3BB1E9E3), UINT32_C(0x88425BAB),
9753           UINT32_C(0x2A615670), UINT32_C(0x62F1BA4A), UINT32_C(0x22F4F32F),
9754           UINT32_C(0x88A59642), UINT32_C(0x7B5EC250)},
9755          {UINT32_C(0x42D30049), UINT32_C(0x7B5BA12A), UINT32_C(0x86995BE6),
9756           UINT32_C(0x4E6AC055), UINT32_C(0x45EC87AC), UINT32_C(0x04431A04),
9757           UINT32_C(0xED94823D), UINT32_C(0x28974ED7)}},
9758     },
9759     {
9760         {{UINT32_C(0x12BB5555), UINT32_C(0x59258057), UINT32_C(0xBB7608EE),
9761           UINT32_C(0x03141CD8), UINT32_C(0xEF77714B), UINT32_C(0x84EBDC49),
9762           UINT32_C(0xB5DC1A5F), UINT32_C(0x6A45FC3A)},
9763          {UINT32_C(0x2FBEEC76), UINT32_C(0x1F6DC205), UINT32_C(0xA920C554),
9764           UINT32_C(0x17EB733B), UINT32_C(0x7A28ACDF), UINT32_C(0xDB022C21),
9765           UINT32_C(0xA9B62BF1), UINT32_C(0x6AF16156)}},
9766         {{UINT32_C(0x80B472CC), UINT32_C(0x9379D6A8), UINT32_C(0x7BD92F27),
9767           UINT32_C(0x6CB08CB0), UINT32_C(0x147E6E12), UINT32_C(0x19B3C353),
9768           UINT32_C(0x26827839), UINT32_C(0x3C26CB2F)},
9769          {UINT32_C(0x0CC571E4), UINT32_C(0x98AAC9A7), UINT32_C(0xC3C8FC04),
9770           UINT32_C(0x075D05F2), UINT32_C(0xD79621AC), UINT32_C(0x718B55A0),
9771           UINT32_C(0x5B94B41B), UINT32_C(0x149FEECF)}},
9772         {{UINT32_C(0x783F9C81), UINT32_C(0x6A150A64), UINT32_C(0x0FB18827),
9773           UINT32_C(0x5950C2DF), UINT32_C(0xF15E3A89), UINT32_C(0xF5D75504),
9774           UINT32_C(0xFCB4406B), UINT32_C(0x5F92F2F7)},
9775          {UINT32_C(0x6123E858), UINT32_C(0x665F31E7), UINT32_C(0xA95184A3),
9776           UINT32_C(0x4E568EA9), UINT32_C(0x505FF0AD), UINT32_C(0x851EEADC),
9777           UINT32_C(0x542C3EF8), UINT32_C(0x62AD5BA6)}},
9778         {{UINT32_C(0xC55C23FD), UINT32_C(0x1103859D), UINT32_C(0x695E4E9B),
9779           UINT32_C(0x06AB0BD6), UINT32_C(0xDD734990), UINT32_C(0x2CD00D76),
9780           UINT32_C(0xB06460E4), UINT32_C(0x5D59C693)},
9781          {UINT32_C(0x1F9C76DA), UINT32_C(0x3BA8F2F0), UINT32_C(0x960F5C0E),
9782           UINT32_C(0x08E4A7EC), UINT32_C(0xE4AAB060), UINT32_C(0x79C82AD9),
9783           UINT32_C(0x0DF95C43), UINT32_C(0x093D322C)}},
9784         {{UINT32_C(0x0C627547), UINT32_C(0x88AF1258), UINT32_C(0x889A5E12),
9785           UINT32_C(0x81E5F197), UINT32_C(0x7CBD84FD), UINT32_C(0x99E0E191),
9786           UINT32_C(0xDB0B9711), UINT32_C(0x3024BCE8)},
9787          {UINT32_C(0xDB93B1A2), UINT32_C(0x04075C80), UINT32_C(0x628B0E63),
9788           UINT32_C(0x12F30AF8), UINT32_C(0xEB25A4ED), UINT32_C(0xA3514F26),
9789           UINT32_C(0x7BCD0873), UINT32_C(0x3D42E489)}},
9790         {{UINT32_C(0x754B236F), UINT32_C(0x0F1C16C6), UINT32_C(0x594F5D3D),
9791           UINT32_C(0x717CE487), UINT32_C(0xAFAD77B1), UINT32_C(0x7679C7DA),
9792           UINT32_C(0x6F3E724C), UINT32_C(0x51AFD014)},
9793          {UINT32_C(0x3AF6938F), UINT32_C(0xAFC9745C), UINT32_C(0xC4E61CB4),
9794           UINT32_C(0xCA12BFA9), UINT32_C(0x9425CCA7), UINT32_C(0x943B5696),
9795           UINT32_C(0xB6E48A69), UINT32_C(0x5BD3E65E)}},
9796         {{UINT32_C(0xDEAE74B1), UINT32_C(0x2D23CF78), UINT32_C(0x043BF2F1),
9797           UINT32_C(0xA686767E), UINT32_C(0xE464ADE9), UINT32_C(0x3AFED34D),
9798           UINT32_C(0x5A6AE80B), UINT32_C(0x1E462073)},
9799          {UINT32_C(0x737F7B66), UINT32_C(0xA86AA408), UINT32_C(0xEAB3B6CE),
9800           UINT32_C(0xD67A0B49), UINT32_C(0x275355F3), UINT32_C(0x6FF3CA4F),
9801           UINT32_C(0x688F99AB), UINT32_C(0x6F385576)}},
9802         {{UINT32_C(0xFD2F9A72), UINT32_C(0xC9B63343), UINT32_C(0xAC267E8A),
9803           UINT32_C(0xBD0A126D), UINT32_C(0x5D2839B5), UINT32_C(0x818BD5D8),
9804           UINT32_C(0x0BF5AFCE), UINT32_C(0x1BBAB4CE)},
9805          {UINT32_C(0x4D8B67DE), UINT32_C(0x2827B24A), UINT32_C(0xC34E6642),
9806           UINT32_C(0x841F6BD3), UINT32_C(0x5E4A34D4), UINT32_C(0xE9F5C1C2),
9807           UINT32_C(0xFDA4177C), UINT32_C(0x4E98795C)}},
9808         {{UINT32_C(0x0763AB04), UINT32_C(0x3C9FF1C2), UINT32_C(0x9832FCFD),
9809           UINT32_C(0x4FC1BE61), UINT32_C(0x8BD0363A), UINT32_C(0x5FA50C38),
9810           UINT32_C(0xF26206BE), UINT32_C(0x14C9BB2F)},
9811          {UINT32_C(0x1D31880C), UINT32_C(0xAD1A96EB), UINT32_C(0x65DFCF8A),
9812           UINT32_C(0xF0A37BC4), UINT32_C(0x3D048FE4), UINT32_C(0x38962729),
9813           UINT32_C(0x6480B254), UINT32_C(0x017125C0)}},
9814         {{UINT32_C(0x98D4BAC6), UINT32_C(0x01E819F5), UINT32_C(0x36B99D30),
9815           UINT32_C(0xD3686E04), UINT32_C(0x200A4A9D), UINT32_C(0x0C2876FB),
9816           UINT32_C(0xE65782D5), UINT32_C(0x45D50C2F)},
9817          {UINT32_C(0x865B7A21), UINT32_C(0xB8316ECE), UINT32_C(0xCC875503),
9818           UINT32_C(0xA3ADB90F), UINT32_C(0x98468FB4), UINT32_C(0xD72E864E),
9819           UINT32_C(0xDED21F40), UINT32_C(0x13BB23FD)}},
9820         {{UINT32_C(0xC6B96368), UINT32_C(0x653C3C15), UINT32_C(0x2B9C381F),
9821           UINT32_C(0x9A42FC2C), UINT32_C(0x69534D92), UINT32_C(0xF06B41B9),
9822           UINT32_C(0x3FB7BED2), UINT32_C(0x46F7292E)},
9823          {UINT32_C(0x97D1875E), UINT32_C(0x14A2C420), UINT32_C(0xD3B2DF55),
9824           UINT32_C(0x45DFA824), UINT32_C(0x3F2BA72D), UINT32_C(0x59CB7E59),
9825           UINT32_C(0xD7D96C98), UINT32_C(0x2EEC65C9)}},
9826         {{UINT32_C(0x49650405), UINT32_C(0x907CD4C8), UINT32_C(0x37E05E06),
9827           UINT32_C(0xFC29320A), UINT32_C(0x09E29619), UINT32_C(0x99B4C1DF),
9828           UINT32_C(0x34DE993F), UINT32_C(0x74E69BF8)},
9829          {UINT32_C(0x509D9797), UINT32_C(0x62C0F296), UINT32_C(0x5F1EF554),
9830           UINT32_C(0x2E6BD4E6), UINT32_C(0x0D0B71B8), UINT32_C(0xE3050641),
9831           UINT32_C(0x235DDE6C), UINT32_C(0x29DA0C9D)}},
9832         {{UINT32_C(0x689398C1), UINT32_C(0x3CFBCA4B), UINT32_C(0x40C9DF13),
9833           UINT32_C(0x11E58804), UINT32_C(0xBCDF2489), UINT32_C(0x3923A39B),
9834           UINT32_C(0x387C8089), UINT32_C(0x3805CCC7)},
9835          {UINT32_C(0x70319AFA), UINT32_C(0xC1B4EB48), UINT32_C(0xCA089604),
9836           UINT32_C(0x0A6A5FA4), UINT32_C(0x73139A20), UINT32_C(0x16ABDE54),
9837           UINT32_C(0x94BD61B5), UINT32_C(0x7C0055E0)}},
9838         {{UINT32_C(0xCB05A02A), UINT32_C(0xA5AB5CEF), UINT32_C(0x0BFE903B),
9839           UINT32_C(0xC0B4E1B4), UINT32_C(0xEAC9E7E8), UINT32_C(0xBA528329),
9840           UINT32_C(0x0A2456B6), UINT32_C(0x0266C5A7)},
9841          {UINT32_C(0x5E216EEC), UINT32_C(0x507E9A41), UINT32_C(0xD0F1E440),
9842           UINT32_C(0xFCC06B0A), UINT32_C(0xE5C7B26F), UINT32_C(0x6FAEFC8E),
9843           UINT32_C(0xB02F85C1), UINT32_C(0x4744CF2E)}},
9844         {{UINT32_C(0x1C291BFC), UINT32_C(0xF5E2B812), UINT32_C(0x2CDCBF7A),
9845           UINT32_C(0xC18E791D), UINT32_C(0x46554345), UINT32_C(0xC386B962),
9846           UINT32_C(0x067518CD), UINT32_C(0x373E00FB)},
9847          {UINT32_C(0xE950051B), UINT32_C(0xC9BA9DF9), UINT32_C(0xDD6133EE),
9848           UINT32_C(0x182CB132), UINT32_C(0x70A3C71C), UINT32_C(0xD6D7F815),
9849           UINT32_C(0x7FAFE307), UINT32_C(0x44C5AEBC)}},
9850         {{UINT32_C(0xA9D16080), UINT32_C(0x6C7CE359), UINT32_C(0x1E8B643E),
9851           UINT32_C(0xA874386D), UINT32_C(0x07F48E10), UINT32_C(0xA0648129),
9852           UINT32_C(0x93E4D619), UINT32_C(0x2A402201)},
9853          {UINT32_C(0xBD383EA6), UINT32_C(0x8B429545), UINT32_C(0xF2880536),
9854           UINT32_C(0xC096D593), UINT32_C(0x20E299B9), UINT32_C(0xB4057D6C),
9855           UINT32_C(0x38A825FA), UINT32_C(0x303962CE)}},
9856     },
9857     {
9858         {{UINT32_C(0x1E1D70D0), UINT32_C(0x9E426EBF), UINT32_C(0xB83529CA),
9859           UINT32_C(0x6AEA4DDC), UINT32_C(0x7CC9A07C), UINT32_C(0xF3ECD462),
9860           UINT32_C(0xC364772E), UINT32_C(0x7F255C86)},
9861          {UINT32_C(0x5613BEF0), UINT32_C(0x0DF212CF), UINT32_C(0x1309F9D0),
9862           UINT32_C(0x771F02A9), UINT32_C(0x805FE1F5), UINT32_C(0xE97BEE39),
9863           UINT32_C(0xD93522B9), UINT32_C(0x54A43430)}},
9864         {{UINT32_C(0xCDE4EBBE), UINT32_C(0xC01553BD), UINT32_C(0xA02E56C1),
9865           UINT32_C(0xB1928DDC), UINT32_C(0x94A1A417), UINT32_C(0xB91004BA),
9866           UINT32_C(0x56CB9C88), UINT32_C(0x44F74BE6)},
9867          {UINT32_C(0x921B62E5), UINT32_C(0x6A7E3E9B), UINT32_C(0x5FBF13C4),
9868           UINT32_C(0xF2BF553B), UINT32_C(0x86D55641), UINT32_C(0x51CB776D),
9869           UINT32_C(0x6425A3AD), UINT32_C(0x71826BC5)}},
9870         {{UINT32_C(0xC6D70EF9), UINT32_C(0xD6D49F90), UINT32_C(0x29EBA0DD),
9871           UINT32_C(0x5BD0DA69), UINT32_C(0x803233EF), UINT32_C(0x0BBA7571),
9872           UINT32_C(0x679A17D5), UINT32_C(0x0EB0959E)},
9873          {UINT32_C(0xB8A3D6EC), UINT32_C(0x97818DC2), UINT32_C(0xC687EAA2),
9874           UINT32_C(0x09497FB0), UINT32_C(0xA65FA4C0), UINT32_C(0x2E2707EA),
9875           UINT32_C(0x7542F472), UINT32_C(0x6A74D4C6)}},
9876         {{UINT32_C(0x1EE0BC40), UINT32_C(0x0D193006), UINT32_C(0x6DC98BA8),
9877           UINT32_C(0x7D7BEE19), UINT32_C(0x447C38D2), UINT32_C(0x1AD37C98),
9878           UINT32_C(0xB6B4550A), UINT32_C(0x3E163AE1)},
9879          {UINT32_C(0x5BC93243), UINT32_C(0x734E36C9), UINT32_C(0x986C35A8),
9880           UINT32_C(0x54E217FD), UINT32_C(0x9E3285E3), UINT32_C(0xF0576FF0),
9881           UINT32_C(0x186EE7EB), UINT32_C(0x65C950C8)}},
9882         {{UINT32_C(0x2012D277), UINT32_C(0x1AB12C04), UINT32_C(0x83872384),
9883           UINT32_C(0x97CAB84B), UINT32_C(0x1C66FCFD), UINT32_C(0x479C9CF5),
9884           UINT32_C(0xF276933E), UINT32_C(0x70ABC8B4)},
9885          {UINT32_C(0xBA4D14F0), UINT32_C(0xE6B15BF7), UINT32_C(0x22E2F5D5),
9886           UINT32_C(0xF4060ED3), UINT32_C(0xCDC5462C), UINT32_C(0xA53F3CA0),
9887           UINT32_C(0xC6FC3854), UINT32_C(0x593219D4)}},
9888         {{UINT32_C(0x72B6F8A1), UINT32_C(0x9DE69934), UINT32_C(0x19E16B3F),
9889           UINT32_C(0xECABAEEE), UINT32_C(0xEDA68D7B), UINT32_C(0x0B537CA5),
9890           UINT32_C(0xD3CE55B7), UINT32_C(0x744628BD)},
9891          {UINT32_C(0x98A95308), UINT32_C(0x3A5B2D8E), UINT32_C(0x6758C6C8),
9892           UINT32_C(0x74D0CEF1), UINT32_C(0xDA204834), UINT32_C(0x7538198A),
9893           UINT32_C(0xA644E880), UINT32_C(0x1E166AAA)}},
9894         {{UINT32_C(0x4674ACF0), UINT32_C(0xE76EE712), UINT32_C(0xDF9DFB4C),
9895           UINT32_C(0x40A6F6DE), UINT32_C(0x40C65721), UINT32_C(0x91B0034C),
9896           UINT32_C(0xF8E0F5E5), UINT32_C(0x54FE8B8B)},
9897          {UINT32_C(0x75891895), UINT32_C(0x6322CA0F), UINT32_C(0x7D20C522),
9898           UINT32_C(0x3D1C821E), UINT32_C(0x08043786), UINT32_C(0x1691407F),
9899           UINT32_C(0x14847D58), UINT32_C(0x02C30838)}},
9900         {{UINT32_C(0xB8F0C372), UINT32_C(0x57DEF069), UINT32_C(0x0D5ABF2C),
9901           UINT32_C(0x50375DC3), UINT32_C(0x75EDFBC9), UINT32_C(0x22903814),
9902           UINT32_C(0xAE37695A), UINT32_C(0x56E39BD7)},
9903          {UINT32_C(0x463D13F2), UINT32_C(0xAB74B187), UINT32_C(0x3CDE8886),
9904           UINT32_C(0xC50CB8A2), UINT32_C(0xB35F7D59), UINT32_C(0x1EFBD1CF),
9905           UINT32_C(0x1057AE42), UINT32_C(0x1296C482)}},
9906         {{UINT32_C(0xC347E3FB), UINT32_C(0xA350B57B), UINT32_C(0xADF65129),
9907           UINT32_C(0x4312EB75), UINT32_C(0x7F9A6C9E), UINT32_C(0xD9A7E2F4),
9908           UINT32_C(0x9BFDCB4D), UINT32_C(0x5493AF7B)},
9909          {UINT32_C(0x9AC0E58E), UINT32_C(0x90A443DD), UINT32_C(0xC6F3BEEF),
9910           UINT32_C(0x9777D58A), UINT32_C(0x965EC900), UINT32_C(0x12F00913),
9911           UINT32_C(0x480126DA), UINT32_C(0x2F6C5B59)}},
9912         {{UINT32_C(0xBAD8C051), UINT32_C(0x70B907FC), UINT32_C(0xD3B4F608),
9913           UINT32_C(0x54492D6A), UINT32_C(0x2E096D9F), UINT32_C(0xE3B46F1B),
9914           UINT32_C(0x747D472A), UINT32_C(0x522AD6D1)},
9915          {UINT32_C(0x02DAB5E5), UINT32_C(0x8FCD1616), UINT32_C(0x357B1C85),
9916           UINT32_C(0xD3BA292F), UINT32_C(0x2704F072), UINT32_C(0xA6DB50CD),
9917           UINT32_C(0x8341AA73), UINT32_C(0x63488DDF)}},
9918         {{UINT32_C(0x0FE2AAAB), UINT32_C(0x99100A3D), UINT32_C(0x8EA44560),
9919           UINT32_C(0x7D30C4E9), UINT32_C(0x2B4C776D), UINT32_C(0xBA458C67),
9920           UINT32_C(0xBBA4D85E), UINT32_C(0x2EC11420)},
9921          {UINT32_C(0x7A7AEC55), UINT32_C(0xB1D9FBA2), UINT32_C(0x7665AAE5),
9922           UINT32_C(0x432AB2AA), UINT32_C(0xF3BC7043), UINT32_C(0xD2755948),
9923           UINT32_C(0x82510EAD), UINT32_C(0x2FC331BB)}},
9924         {{UINT32_C(0x46253DB1), UINT32_C(0xAAF11CF9), UINT32_C(0xB0DF307C),
9925           UINT32_C(0xEB025AED), UINT32_C(0x7A82ADEE), UINT32_C(0xCB7C22A5),
9926           UINT32_C(0x9C5FA97B), UINT32_C(0x7316C390)},
9927          {UINT32_C(0xF518067C), UINT32_C(0x91620554), UINT32_C(0x3C96A804),
9928           UINT32_C(0x20A438AE), UINT32_C(0x5B0C090C), UINT32_C(0xC4F9DCDF),
9929           UINT32_C(0x6E5C1B45), UINT32_C(0x77C512DB)}},
9930         {{UINT32_C(0xFDD09EDE), UINT32_C(0xC981E682), UINT32_C(0xBBB3F57D),
9931           UINT32_C(0xC3EB36B7), UINT32_C(0xD12BF450), UINT32_C(0xA07369C6),
9932           UINT32_C(0xCE017845), UINT32_C(0x16627566)},
9933          {UINT32_C(0x9494AF62), UINT32_C(0xFD8DEC90), UINT32_C(0x53FD4B22),
9934           UINT32_C(0x7E793096), UINT32_C(0xC8AAEAE9), UINT32_C(0x21B8E665),
9935           UINT32_C(0x18BC33C0), UINT32_C(0x526FA318)}},
9936         {{UINT32_C(0x853A2647), UINT32_C(0xF55D32BF), UINT32_C(0xCDAEE8FE),
9937           UINT32_C(0xD873ED6C), UINT32_C(0x80E52622), UINT32_C(0xA3579E2B),
9938           UINT32_C(0x33D16FE8), UINT32_C(0x03871ABA)},
9939          {UINT32_C(0x69925EDF), UINT32_C(0x714804AC), UINT32_C(0xF2B964FF),
9940           UINT32_C(0x0340755F), UINT32_C(0xDA0D1A07), UINT32_C(0x93830F98),
9941           UINT32_C(0xF7FB1E16), UINT32_C(0x2CAB201E)}},
9942         {{UINT32_C(0x22A8AF77), UINT32_C(0x26DE3A3A), UINT32_C(0xB45BA630),
9943           UINT32_C(0x0E77C3DC), UINT32_C(0xFC86E7D1), UINT32_C(0x34F00017),
9944           UINT32_C(0x1B62F7F2), UINT32_C(0x796ABE2F)},
9945          {UINT32_C(0x1663B5B1), UINT32_C(0x9FA09277), UINT32_C(0x9B2FB9AC),
9946           UINT32_C(0xFFFDC93F), UINT32_C(0x6B340D75), UINT32_C(0x03AECD1A),
9947           UINT32_C(0x314DCCEA), UINT32_C(0x5D55A168)}},
9948         {{UINT32_C(0x747DBD0C), UINT32_C(0x678AEF02), UINT32_C(0xD47A6C09),
9949           UINT32_C(0xF0D47C1C), UINT32_C(0x3FDD1681), UINT32_C(0x6C2AC72F),
9950           UINT32_C(0x6D789D3A), UINT32_C(0x750E7064)},
9951          {UINT32_C(0xAEBEDD58), UINT32_C(0x3F970AFE), UINT32_C(0xE3540951),
9952           UINT32_C(0x6BBA7956), UINT32_C(0x3E71F6AF), UINT32_C(0x7CC461B2),
9953           UINT32_C(0xC45FED28), UINT32_C(0x7E51E548)}},
9954     },
9955     {
9956         {{UINT32_C(0x2CE2CBE5), UINT32_C(0x4A598EFB), UINT32_C(0x89C9A51B),
9957           UINT32_C(0x774CDE0A), UINT32_C(0xCA907F34), UINT32_C(0x2D003680),
9958           UINT32_C(0x9D3C7D97), UINT32_C(0x62C32DCA)},
9959          {UINT32_C(0xB3054D17), UINT32_C(0x37B3A90F), UINT32_C(0x67E58A5A),
9960           UINT32_C(0x1423574C), UINT32_C(0x4859FA49), UINT32_C(0xF1D3BB1A),
9961           UINT32_C(0x3F5AFA63), UINT32_C(0x25F0AF1C)}},
9962         {{UINT32_C(0x1FE53AC9), UINT32_C(0xD3BF7F62), UINT32_C(0xCBCE6164),
9963           UINT32_C(0xCE2B67C3), UINT32_C(0x95341024), UINT32_C(0xE081C576),
9964           UINT32_C(0x9A70ECAB), UINT32_C(0x32B0EF5D)},
9965          {UINT32_C(0x3BE1E5CE), UINT32_C(0x3EC93C85), UINT32_C(0xA0CB7DCD),
9966           UINT32_C(0xE25F54ED), UINT32_C(0x517965B2), UINT32_C(0x9D6B57D7),
9967           UINT32_C(0x129B0B27), UINT32_C(0x159F7AB0)}},
9968         {{UINT32_C(0xEEFB67F3), UINT32_C(0xAEF88E95), UINT32_C(0xE0316AB2),
9969           UINT32_C(0xEAEB2889), UINT32_C(0xC2CB6753), UINT32_C(0x1491881F),
9970           UINT32_C(0x702789D0), UINT32_C(0x67DCDF28)},
9971          {UINT32_C(0x11C0F3FD), UINT32_C(0x8282E0A7), UINT32_C(0x01BA273D),
9972           UINT32_C(0x9CDCFDB8), UINT32_C(0x26279B95), UINT32_C(0x6BF1E043),
9973           UINT32_C(0x85852777), UINT32_C(0x0D42AAC6)}},
9974         {{UINT32_C(0x608981AB), UINT32_C(0xC4CE393E), UINT32_C(0x52141CB0),
9975           UINT32_C(0x210E20F8), UINT32_C(0x6B9234B5), UINT32_C(0x22C2586D),
9976           UINT32_C(0x4366750E), UINT32_C(0x52F1B366)},
9977          {UINT32_C(0x760AFA55), UINT32_C(0xE38ED0D9), UINT32_C(0xB5D61A08),
9978           UINT32_C(0xA43FF25A), UINT32_C(0xB5E21691), UINT32_C(0x0BE3A406),
9979           UINT32_C(0xFD4E17B0), UINT32_C(0x37B47A28)}},
9980         {{UINT32_C(0x4C2C65C2), UINT32_C(0xC46DC6D4), UINT32_C(0xC54BE778),
9981           UINT32_C(0x2A0B452C), UINT32_C(0xF727070E), UINT32_C(0xAF113693),
9982           UINT32_C(0xC68D13A3), UINT32_C(0x7B229CD8)},
9983          {UINT32_C(0x02D43E4B), UINT32_C(0x0F63097E), UINT32_C(0x55627FD8),
9984           UINT32_C(0x912F8D33), UINT32_C(0x2A0DD9AE), UINT32_C(0x1EBF3961),
9985           UINT32_C(0xF0294B2D), UINT32_C(0x7FD33FDE)}},
9986         {{UINT32_C(0xD0CC6D9F), UINT32_C(0xC72411F5), UINT32_C(0x9B92FF84),
9987           UINT32_C(0x66E04C90), UINT32_C(0xE1C033B6), UINT32_C(0x0678B4F8),
9988           UINT32_C(0xE49A972A), UINT32_C(0x5A99F270)},
9989          {UINT32_C(0xD265A4DF), UINT32_C(0x3743BCD8), UINT32_C(0xCE0404C3),
9990           UINT32_C(0x7BD6DDF4), UINT32_C(0x131750A5), UINT32_C(0x4043767F),
9991           UINT32_C(0x9DD65652), UINT32_C(0x4A7D8983)}},
9992         {{UINT32_C(0x12B7822D), UINT32_C(0x535BC784), UINT32_C(0xF1F9B703),
9993           UINT32_C(0xDD32DD67), UINT32_C(0x2EAA2A1C), UINT32_C(0xFFDBF0EB),
9994           UINT32_C(0xF64E9822), UINT32_C(0x497C09FA)},
9995          {UINT32_C(0x32EE2A36), UINT32_C(0x18E717E9), UINT32_C(0x583949B1),
9996           UINT32_C(0xF01CC4F5), UINT32_C(0x0A168755), UINT32_C(0x222EE974),
9997           UINT32_C(0x00C81EC9), UINT32_C(0x0CD14CD5)}},
9998         {{UINT32_C(0x14C79CDC), UINT32_C(0x7AE0BD11), UINT32_C(0x6DC08C80),
9999           UINT32_C(0x67323D1A), UINT32_C(0x0EF32432), UINT32_C(0x2FD1ABC7),
10000           UINT32_C(0xB0E08EBF), UINT32_C(0x65923246)},
10001          {UINT32_C(0xC0754ECE), UINT32_C(0x0A9FD3D7), UINT32_C(0x5F8644FA),
10002           UINT32_C(0xE76B2624), UINT32_C(0x0F8BB385), UINT32_C(0xF1F0BEBA),
10003           UINT32_C(0xFC96778F), UINT32_C(0x73251F03)}},
10004         {{UINT32_C(0xD08795A9), UINT32_C(0x197150DE), UINT32_C(0xFBB8B9CF),
10005           UINT32_C(0xAD6935AE), UINT32_C(0x3B2B9EFB), UINT32_C(0x72118682),
10006           UINT32_C(0xBC2B7240), UINT32_C(0x265B288D)},
10007          {UINT32_C(0x2F78C431), UINT32_C(0x7BF2EB36), UINT32_C(0xF2A6E469),
10008           UINT32_C(0xF03B83CA), UINT32_C(0x4740E74B), UINT32_C(0x21159256),
10009           UINT32_C(0x0490F0B9), UINT32_C(0x35BE5735)}},
10010         {{UINT32_C(0x806C1CAE), UINT32_C(0x207F33B2), UINT32_C(0xDAC5ADE0),
10011           UINT32_C(0x04249127), UINT32_C(0x1CC59DE7), UINT32_C(0xC4CCF33E),
10012           UINT32_C(0x272BD6D7), UINT32_C(0x2A17B520)},
10013          {UINT32_C(0xB48F6585), UINT32_C(0xC36F6B3C), UINT32_C(0x0861ACF5),
10014           UINT32_C(0xD32A7379), UINT32_C(0x2C3291C6), UINT32_C(0x28A12ECB),
10015           UINT32_C(0xF02A88D0), UINT32_C(0x0E945F95)}},
10016         {{UINT32_C(0xD3B3117B), UINT32_C(0x4836EC01), UINT32_C(0xA4C2FD72),
10017           UINT32_C(0x4C197454), UINT32_C(0xF9897721), UINT32_C(0x96FCED51),
10018           UINT32_C(0x5828C97D), UINT32_C(0x14202858)},
10019          {UINT32_C(0x774755B9), UINT32_C(0xCA7ACED8), UINT32_C(0x97252559),
10020           UINT32_C(0x460FF582), UINT32_C(0x5796DD63), UINT32_C(0xAAE45776),
10021           UINT32_C(0x346DDBF5), UINT32_C(0x711C916E)}},
10022         {{UINT32_C(0x5E203692), UINT32_C(0xA60E2E7B), UINT32_C(0xF3BF2A45),
10023           UINT32_C(0xCFC72FEA), UINT32_C(0x72AC0436), UINT32_C(0x78729D28),
10024           UINT32_C(0x29ABF199), UINT32_C(0x3E16DD8B)},
10025          {UINT32_C(0x15A41F3D), UINT32_C(0xB1705AA6), UINT32_C(0x308AB87C),
10026           UINT32_C(0x8C7512FE), UINT32_C(0x03995381), UINT32_C(0xA27411C5),
10027           UINT32_C(0xA780CED3), UINT32_C(0x3142403C)}},
10028         {{UINT32_C(0xF1718C7F), UINT32_C(0xE4473E94), UINT32_C(0xA3CAB6CB),
10029           UINT32_C(0x601BC194), UINT32_C(0x581D491D), UINT32_C(0x8F3540F8),
10030           UINT32_C(0x43C15321), UINT32_C(0x456A9B7C)},
10031          {UINT32_C(0x593BB7ED), UINT32_C(0x6F335A2D), UINT32_C(0x7D791514),
10032           UINT32_C(0xB6D5A23F), UINT32_C(0x79235EAD), UINT32_C(0x976D2F83),
10033           UINT32_C(0x44775C97), UINT32_C(0x7D02EA0F)}},
10034         {{UINT32_C(0xE5EC268E), UINT32_C(0x322DBC8C), UINT32_C(0xBE14BF5C),
10035           UINT32_C(0x1F2F6050), UINT32_C(0xEACF6A50), UINT32_C(0x58AC6397),
10036           UINT32_C(0xA5401081), UINT32_C(0x4167CBD5)},
10037          {UINT32_C(0xEE5B4BF5), UINT32_C(0x8E6F06A1), UINT32_C(0x6B2F790F),
10038           UINT32_C(0x1A6073D5), UINT32_C(0x4F901250), UINT32_C(0x1C09FF3D),
10039           UINT32_C(0xE6B40DF4), UINT32_C(0x286AF8D7)}},
10040         {{UINT32_C(0x06BD53FF), UINT32_C(0xF74C8057), UINT32_C(0xE5788F0D),
10041           UINT32_C(0x4FCE7281), UINT32_C(0x3D015E6B), UINT32_C(0xD6A867AC),
10042           UINT32_C(0x6E185A42), UINT32_C(0x04AEC38D)},
10043          {UINT32_C(0x083D65CB), UINT32_C(0x8DC12B74), UINT32_C(0x82966668),
10044           UINT32_C(0xDB1AA8AC), UINT32_C(0x28AF1B90), UINT32_C(0xBD2233BF),
10045           UINT32_C(0x172CCA11), UINT32_C(0x544569A7)}},
10046         {{UINT32_C(0x149BD0BD), UINT32_C(0x9C56FCA8), UINT32_C(0xA05F8E44),
10047           UINT32_C(0x2B4EC788), UINT32_C(0x92478943), UINT32_C(0x1569CF6D),
10048           UINT32_C(0x57380986), UINT32_C(0x67E373E8)},
10049          {UINT32_C(0xED3C14DB), UINT32_C(0xF5CC8232), UINT32_C(0xF52EAF83),
10050           UINT32_C(0xE3D184B0), UINT32_C(0x0BC64038), UINT32_C(0x195D4137),
10051           UINT32_C(0x778C3C20), UINT32_C(0x77994388)}},
10052     },
10053     {
10054         {{UINT32_C(0xA0CC77AA), UINT32_C(0x3DAA0C47), UINT32_C(0x7C69CDF0),
10055           UINT32_C(0xB9794E74), UINT32_C(0x4549F5D4), UINT32_C(0x3610E50B),
10056           UINT32_C(0xB8A112CA), UINT32_C(0x262CA564)},
10057          {UINT32_C(0x554E8714), UINT32_C(0xD5EC795E), UINT32_C(0x717EBEF3),
10058           UINT32_C(0x73EE5502), UINT32_C(0x1947A478), UINT32_C(0xE36E8A1A),
10059           UINT32_C(0x42ADC59D), UINT32_C(0x3FBE43A3)}},
10060         {{UINT32_C(0x021FBCBE), UINT32_C(0x4DE78909), UINT32_C(0x0BBBB324),
10061           UINT32_C(0xA76A5EE2), UINT32_C(0xCD67810B), UINT32_C(0x5B86519A),
10062           UINT32_C(0x3710A4EE), UINT32_C(0x4CCA44A2)},
10063          {UINT32_C(0xCD1F8BEC), UINT32_C(0xD79A121D), UINT32_C(0xDC9CA10E),
10064           UINT32_C(0x2E12A772), UINT32_C(0x8C9E9640), UINT32_C(0xE301CA3B),
10065           UINT32_C(0xB731A957), UINT32_C(0x4B25FE18)}},
10066         {{UINT32_C(0xF4AD7264), UINT32_C(0xA05DA2CD), UINT32_C(0x076977A5),
10067           UINT32_C(0x31336489), UINT32_C(0xF2E576A8), UINT32_C(0xC1D269BE),
10068           UINT32_C(0x7532203F), UINT32_C(0x1E877ADC)},
10069          {UINT32_C(0x8B92972C), UINT32_C(0x9C9961BC), UINT32_C(0x6A14D810),
10070           UINT32_C(0x7BA07272), UINT32_C(0x06913136), UINT32_C(0xE51095A9),
10071           UINT32_C(0x30E0EA8C), UINT32_C(0x46748969)}},
10072         {{UINT32_C(0x3C73BA49), UINT32_C(0xDB8EF346), UINT32_C(0x3720570D),
10073           UINT32_C(0xBF221312), UINT32_C(0x605DB0D6), UINT32_C(0xC07B3639),
10074           UINT32_C(0x300336A3), UINT32_C(0x44FCEFA6)},
10075          {UINT32_C(0x2D234592), UINT32_C(0x121FAC5C), UINT32_C(0x44E367D7),
10076           UINT32_C(0x901DEE88), UINT32_C(0x1CAA6A3A), UINT32_C(0x5B5F3DD6),
10077           UINT32_C(0xAC2F6E64), UINT32_C(0x72E474EC)}},
10078         {{UINT32_C(0xF55BE61C), UINT32_C(0x15690BEE), UINT32_C(0xDF2678A2),
10079           UINT32_C(0xE42B945E), UINT32_C(0x3B7B1776), UINT32_C(0x60A5C8AA),
10080           UINT32_C(0xEB9AB938), UINT32_C(0x16103FBC)},
10081          {UINT32_C(0x87AD06AB), UINT32_C(0x79722A1E), UINT32_C(0xD6B632A2),
10082           UINT32_C(0xD7B509F6), UINT32_C(0x3B69EB40), UINT32_C(0x8C4E8B2E),
10083           UINT32_C(0x14DB2225), UINT32_C(0x6A509583)}},
10084         {{UINT32_C(0x93B78659), UINT32_C(0x169F35D8), UINT32_C(0x8EFF83AD),
10085           UINT32_C(0x989B04D2), UINT32_C(0xA6AE4806), UINT32_C(0x72CF7338),
10086           UINT32_C(0xF4AAA524), UINT32_C(0x6E156C84)},
10087          {UINT32_C(0xA1ED5CB2), UINT32_C(0x33A608ED), UINT32_C(0xC3D28716),
10088           UINT32_C(0xCE274A64), UINT32_C(0x45F0435F), UINT32_C(0xFCF1B170),
10089           UINT32_C(0x1653D6F6), UINT32_C(0x101D1BDB)}},
10090         {{UINT32_C(0x2E5A67D9), UINT32_C(0x45BC931D), UINT32_C(0x697DA479),
10091           UINT32_C(0xAFF02C11), UINT32_C(0x2EA3E6E1), UINT32_C(0x7C7972A3),
10092           UINT32_C(0x5E97BB90), UINT32_C(0x71A17D50)},
10093          {UINT32_C(0x19AD4C5E), UINT32_C(0x962E84F2), UINT32_C(0x692020BE),
10094           UINT32_C(0xBB8C9FC7), UINT32_C(0xE7B36665), UINT32_C(0xA78FDF2C),
10095           UINT32_C(0x26F92E33), UINT32_C(0x7AC84ED4)}},
10096         {{UINT32_C(0xC3C9E5C1), UINT32_C(0xBD85A9EE), UINT32_C(0x6ED2FD6A),
10097           UINT32_C(0x72030BAA), UINT32_C(0x39CFFB89), UINT32_C(0xB67185AB),
10098           UINT32_C(0x833BF770), UINT32_C(0x3E2E51A4)},
10099          {UINT32_C(0x5E27D5BB), UINT32_C(0x248FA348), UINT32_C(0x2E6D3DCF),
10100           UINT32_C(0xF8D43596), UINT32_C(0x0C8DAF81), UINT32_C(0x07F5B93C),
10101           UINT32_C(0xAD2FC97D), UINT32_C(0x6A7FFA1D)}},
10102         {{UINT32_C(0xFAEA33F1), UINT32_C(0xFF308FAE), UINT32_C(0x3CC4C7CF),
10103           UINT32_C(0x5F29DFFB), UINT32_C(0xECC5A2B9), UINT32_C(0xB9AD4527),
10104           UINT32_C(0x048D4B38), UINT32_C(0x08B95AF6)},
10105          {UINT32_C(0xDEC152BB), UINT32_C(0x56BC43A8), UINT32_C(0x3849D869),
10106           UINT32_C(0xD1147B9A), UINT32_C(0xD02AF3B7), UINT32_C(0xFE5020C2),
10107           UINT32_C(0xB918496E), UINT32_C(0x54C02B44)}},
10108         {{UINT32_C(0x0B27468D), UINT32_C(0x1611ECFD), UINT32_C(0x0513A562),
10109           UINT32_C(0x4AFCE329), UINT32_C(0x2FE74EED), UINT32_C(0x982782FD),
10110           UINT32_C(0x17ADD2EA), UINT32_C(0x66AC58BF)},
10111          {UINT32_C(0x613581D4), UINT32_C(0x8277BC2D), UINT32_C(0x988D1498),
10112           UINT32_C(0x0BF5BF0C), UINT32_C(0x55C984CB), UINT32_C(0x8A37134D),
10113           UINT32_C(0x92211390), UINT32_C(0x409A79CC)}},
10114         {{UINT32_C(0x816F0462), UINT32_C(0x8C0081AE), UINT32_C(0x5A68BFC2),
10115           UINT32_C(0xB431DC24), UINT32_C(0x5F78C8A1), UINT32_C(0x25C769C6),
10116           UINT32_C(0xB382AF14), UINT32_C(0x3BE0458D)},
10117          {UINT32_C(0xA171ADF2), UINT32_C(0x10583083), UINT32_C(0x37F7C39F),
10118           UINT32_C(0xBA5D5325), UINT32_C(0x5EAC7585), UINT32_C(0x76B03B94),
10119           UINT32_C(0x9C2DF2C6), UINT32_C(0x76159AAC)}},
10120         {{UINT32_C(0x918E0332), UINT32_C(0x886C73BA), UINT32_C(0xD24B5B52),
10121           UINT32_C(0xF6FEC62A), UINT32_C(0x36B4D23A), UINT32_C(0xB98759B4),
10122           UINT32_C(0x5480ACF3), UINT32_C(0x5EC5B3FE)},
10123          {UINT32_C(0x6DD175BF), UINT32_C(0x30FF297D), UINT32_C(0x75F2B9C3),
10124           UINT32_C(0x501DE744), UINT32_C(0xF19230C5), UINT32_C(0xDEBE47CA),
10125           UINT32_C(0x32BBBB62), UINT32_C(0x7401F209)}},
10126         {{UINT32_C(0x22496D1E), UINT32_C(0x80712E47), UINT32_C(0xDA80AF1D),
10127           UINT32_C(0x36A0EF37), UINT32_C(0x940E5E9F), UINT32_C(0xAF6CA51C),
10128           UINT32_C(0x722D9D22), UINT32_C(0x74E17B6F)},
10129          {UINT32_C(0xB8B3AE1B), UINT32_C(0xCB70B878), UINT32_C(0x07DF974C),
10130           UINT32_C(0xBF8B9A0B), UINT32_C(0xF68A4BF4), UINT32_C(0x89FCC996),
10131           UINT32_C(0x6EB0FB2E), UINT32_C(0x46F581E8)}},
10132         {{UINT32_C(0x67137153), UINT32_C(0xBCE0BD6C), UINT32_C(0x75F64B78),
10133           UINT32_C(0xAD3E92B3), UINT32_C(0xFD047DD9), UINT32_C(0x6454CD1D),
10134           UINT32_C(0x612AE472), UINT32_C(0x181C93EB)},
10135          {UINT32_C(0x23A529C3), UINT32_C(0xE575307E), UINT32_C(0x59C09EB5),
10136           UINT32_C(0xB9C43A0B), UINT32_C(0xAA805840), UINT32_C(0xFD233A68),
10137           UINT32_C(0xA122FFB9), UINT32_C(0x067C442E)}},
10138         {{UINT32_C(0x2CD6762E), UINT32_C(0xE1F3F76F), UINT32_C(0x9764B53A),
10139           UINT32_C(0xFB68650F), UINT32_C(0xF1224580), UINT32_C(0x4E90AC72),
10140           UINT32_C(0x127EED48), UINT32_C(0x2BF68F01)},
10141          {UINT32_C(0x94D389A0), UINT32_C(0xE6B4B409), UINT32_C(0xD44593D6),
10142           UINT32_C(0xD7BC8108), UINT32_C(0x48A86677), UINT32_C(0xDCF03991),
10143           UINT32_C(0xCEBCE3C7), UINT32_C(0x4A52D961)}},
10144         {{UINT32_C(0xBAA873EA), UINT32_C(0x55734AB5), UINT32_C(0x7871F323),
10145           UINT32_C(0x506DE4CF), UINT32_C(0x578612C0), UINT32_C(0x7C3F8B00),
10146           UINT32_C(0x9243C9E8), UINT32_C(0x730D4B8A)},
10147          {UINT32_C(0xD385F6BD), UINT32_C(0xA3290689), UINT32_C(0x913596F5),
10148           UINT32_C(0xAF688C6A), UINT32_C(0xB646BE23), UINT32_C(0x0A2D89B5),
10149           UINT32_C(0xF63A6029), UINT32_C(0x31891165)}},
10150     },
10151     {
10152         {{UINT32_C(0x579583C0), UINT32_C(0x331F9E57), UINT32_C(0x69C65DA2),
10153           UINT32_C(0xE92ABADF), UINT32_C(0xA5B8B057), UINT32_C(0xC796FBEC),
10154           UINT32_C(0x312D1E89), UINT32_C(0x52E6F9C9)},
10155          {UINT32_C(0xDA68DFD3), UINT32_C(0x0318B1DF), UINT32_C(0xA1CAC4F1),
10156           UINT32_C(0x8BAA2EB3), UINT32_C(0xBEE7D6E1), UINT32_C(0x0CDC89A2),
10157           UINT32_C(0x22AB50F4), UINT32_C(0x6102DE7A)}},
10158         {{UINT32_C(0xE20C707A), UINT32_C(0x02003D83), UINT32_C(0x28289D89),
10159           UINT32_C(0xD819249C), UINT32_C(0x72053FF8), UINT32_C(0x3FBC00B1),
10160           UINT32_C(0xDF40D261), UINT32_C(0x0249C43C)},
10161          {UINT32_C(0xD8F064AF), UINT32_C(0x8794EEAC), UINT32_C(0xDC9F0631),
10162           UINT32_C(0xE2359E70), UINT32_C(0xADA310D0), UINT32_C(0xD1603647),
10163           UINT32_C(0xEDC888EC), UINT32_C(0x6A9E3785)}},
10164         {{UINT32_C(0xEC41908E), UINT32_C(0xF332B384), UINT32_C(0xBDE4760B),
10165           UINT32_C(0xF3274472), UINT32_C(0x140D0EF4), UINT32_C(0x96185E89),
10166           UINT32_C(0x90E698E7), UINT32_C(0x56462089)},
10167          {UINT32_C(0xF2E64396), UINT32_C(0x841A31C5), UINT32_C(0x03C4118F),
10168           UINT32_C(0x8F494CA5), UINT32_C(0x1A188305), UINT32_C(0x0C98A4C3),
10169           UINT32_C(0x98AAB1AB), UINT32_C(0x1C4B5F62)}},
10170         {{UINT32_C(0x5D0D8381), UINT32_C(0xDDEEEBF8), UINT32_C(0x89044363),
10171           UINT32_C(0xD1616F48), UINT32_C(0x21616A13), UINT32_C(0x2EE41D47),
10172           UINT32_C(0x4BC769FC), UINT32_C(0x2DCE6110)},
10173          {UINT32_C(0x16C1C468), UINT32_C(0xE3707A01), UINT32_C(0x969AF612),
10174           UINT32_C(0x3B674187), UINT32_C(0x1E0671CC), UINT32_C(0xB64BD4D7),
10175           UINT32_C(0xB98C297C), UINT32_C(0x7EF01DBA)}},
10176         {{UINT32_C(0x815381AC), UINT32_C(0x91DCBF99), UINT32_C(0x38B67B97),
10177           UINT32_C(0x8D711F58), UINT32_C(0x9C6E322C), UINT32_C(0x9C11F595),
10178           UINT32_C(0xE31A782F), UINT32_C(0x4A688D0B)},
10179          {UINT32_C(0xDCE93F5B), UINT32_C(0x1297D9F3), UINT32_C(0x7C1DC62A),
10180           UINT32_C(0xA7956194), UINT32_C(0x5F718F63), UINT32_C(0x340F217A),
10181           UINT32_C(0xFCC0EF6A), UINT32_C(0x71F84529)}},
10182         {{UINT32_C(0x3DD00963), UINT32_C(0x0D968E50), UINT32_C(0xD7FF66C3),
10183           UINT32_C(0x5E696D79), UINT32_C(0x499A9BE2), UINT32_C(0xAA52D60D),
10184           UINT32_C(0xCDC289DE), UINT32_C(0x72482C45)},
10185          {UINT32_C(0x7FFAAD3A), UINT32_C(0xC84968F5), UINT32_C(0xF7CD5BED),
10186           UINT32_C(0xEE91304C), UINT32_C(0x0A7CC7C0), UINT32_C(0x68493676),
10187           UINT32_C(0x80023968), UINT32_C(0x3411AFA7)}},
10188         {{UINT32_C(0x6E3294C0), UINT32_C(0xA0AEBC70), UINT32_C(0xDC385E50),
10189           UINT32_C(0x93263942), UINT32_C(0x8467FB06), UINT32_C(0x7B90C002),
10190           UINT32_C(0x38CFD0FF), UINT32_C(0x29477CA4)},
10191          {UINT32_C(0x92A748D5), UINT32_C(0xADC04D81), UINT32_C(0x76CF3AE5),
10192           UINT32_C(0xAE4F309D), UINT32_C(0x4BB2C2FF), UINT32_C(0xBDA34BF0),
10193           UINT32_C(0x368536E4), UINT32_C(0x65138897)}},
10194         {{UINT32_C(0x6FE6D4D6), UINT32_C(0x9CB8F7D6), UINT32_C(0xAF246792),
10195           UINT32_C(0x6C2FFBF5), UINT32_C(0x81524707), UINT32_C(0xD5A4F349),
10196           UINT32_C(0x36766D5E), UINT32_C(0x3AFE45CE)},
10197          {UINT32_C(0x513BA267), UINT32_C(0x41991B49), UINT32_C(0x6C18AA5E),
10198           UINT32_C(0x06EF1EEA), UINT32_C(0x88EA2099), UINT32_C(0x0A517635),
10199           UINT32_C(0xD245B88B), UINT32_C(0x32D2B5E2)}},
10200         {{UINT32_C(0x3F517C5B), UINT32_C(0xAE38CDD5), UINT32_C(0xD878FEEE),
10201           UINT32_C(0x1C94FDC5), UINT32_C(0xBEFCE107), UINT32_C(0xABF7A41D),
10202           UINT32_C(0xD408DFE8), UINT32_C(0x33BF3FE9)},
10203          {UINT32_C(0x947CB8C4), UINT32_C(0x4F2E6FF0), UINT32_C(0xF998C5A0),
10204           UINT32_C(0x3A8E86AB), UINT32_C(0xE359209F), UINT32_C(0x3ADC6ABA),
10205           UINT32_C(0xD9A50051), UINT32_C(0x37A2DE1B)}},
10206         {{UINT32_C(0xE718F6B9), UINT32_C(0x424F4E34), UINT32_C(0x75C58EB6),
10207           UINT32_C(0x50B1A03B), UINT32_C(0x91390E27), UINT32_C(0xB9495314),
10208           UINT32_C(0x880E78D8), UINT32_C(0x4AE0CC3A)},
10209          {UINT32_C(0xF1E4413C), UINT32_C(0x10331AFA), UINT32_C(0xDDFCD2F0),
10210           UINT32_C(0xE7A3E554), UINT32_C(0x0EBF484B), UINT32_C(0x44F6DE85),
10211           UINT32_C(0x895D0F54), UINT32_C(0x6A762A7E)}},
10212         {{UINT32_C(0x8D0558F6), UINT32_C(0x8E606B0A), UINT32_C(0x5C4DD930),
10213           UINT32_C(0xAADA7604), UINT32_C(0xEF4ACAD0), UINT32_C(0x5B2FC7AD),
10214           UINT32_C(0x87F5B6E2), UINT32_C(0x0D969AD0)},
10215          {UINT32_C(0x5974E67B), UINT32_C(0xF9A182B2), UINT32_C(0x23B4009A),
10216           UINT32_C(0xCD8232E7), UINT32_C(0x285BCC3F), UINT32_C(0x3D8F5DDD),
10217           UINT32_C(0xEEE1B9BF), UINT32_C(0x114AC56F)}},
10218         {{UINT32_C(0xAA45085A), UINT32_C(0xD3EA1B56), UINT32_C(0xD314CEDF),
10219           UINT32_C(0x5DE7BB70), UINT32_C(0x7BCCDCFD), UINT32_C(0x8A74384C),
10220           UINT32_C(0x8E0E0367), UINT32_C(0x64B80F8A)},
10221          {UINT32_C(0x48884ED1), UINT32_C(0xA9EA432B), UINT32_C(0x8C0BA810),
10222           UINT32_C(0x51957A8F), UINT32_C(0x39E810E3), UINT32_C(0x9E883400),
10223           UINT32_C(0x28B2051C), UINT32_C(0x0A73ED5A)}},
10224         {{UINT32_C(0x13C30826), UINT32_C(0x655212A3), UINT32_C(0xB73E8660),
10225           UINT32_C(0xAE53668E), UINT32_C(0xFF108CCE), UINT32_C(0x6C33B649),
10226           UINT32_C(0x21D49681), UINT32_C(0x39E0B118)},
10227          {UINT32_C(0x70525312), UINT32_C(0xFE4D2152), UINT32_C(0xFFD18749),
10228           UINT32_C(0x2EDCE32B), UINT32_C(0xB04D3FB8), UINT32_C(0xFED19B1C),
10229           UINT32_C(0x2B225A9D), UINT32_C(0x4DFE216B)}},
10230         {{UINT32_C(0x4C70F8A8), UINT32_C(0x583E8A6C), UINT32_C(0x954A9AE1),
10231           UINT32_C(0xC8206231), UINT32_C(0xB76517B1), UINT32_C(0x9360B592),
10232           UINT32_C(0xEED10CCA), UINT32_C(0x362C5C5C)},
10233          {UINT32_C(0x3D607921), UINT32_C(0x3DBA9595), UINT32_C(0x5A6ECC40),
10234           UINT32_C(0x0188A5D6), UINT32_C(0x6CFF4ADE), UINT32_C(0x0EAB43C1),
10235           UINT32_C(0xDE3347E0), UINT32_C(0x1F3673AE)}},
10236         {{UINT32_C(0x796593EE), UINT32_C(0x7300C4B3), UINT32_C(0xD8D926C3),
10237           UINT32_C(0x607E7E76), UINT32_C(0x77F9FD06), UINT32_C(0x1762CE26),
10238           UINT32_C(0xCEA891EB), UINT32_C(0x0D0478B3)},
10239          {UINT32_C(0x2618B09E), UINT32_C(0xB1129791), UINT32_C(0x33F928C9),
10240           UINT32_C(0x5F9D290D), UINT32_C(0xE6178DB0), UINT32_C(0xE3192631),
10241           UINT32_C(0x08576D3F), UINT32_C(0x21260AC8)}},
10242         {{UINT32_C(0x76968E1C), UINT32_C(0x899DAF2A), UINT32_C(0xF9C2B3E7),
10243           UINT32_C(0x0519DEA9), UINT32_C(0x93D0BD4E), UINT32_C(0x5FDADC38),
10244           UINT32_C(0x43B4D98F), UINT32_C(0x0467BFF7)},
10245          {UINT32_C(0x6F3936C9), UINT32_C(0x651C316C), UINT32_C(0xAF27DF8B),
10246           UINT32_C(0xE757689A), UINT32_C(0xA0FA9188), UINT32_C(0x3AB037EA),
10247           UINT32_C(0xD927B60A), UINT32_C(0x2F8B039B)}},
10248     },
10249     {
10250         {{UINT32_C(0xDE876A70), UINT32_C(0x72211BF5), UINT32_C(0x73D121CE),
10251           UINT32_C(0xA8361631), UINT32_C(0x23D419E4), UINT32_C(0x23852721),
10252           UINT32_C(0xDBD03345), UINT32_C(0x3F56D47E)},
10253          {UINT32_C(0xD6F05BAC), UINT32_C(0xFB0E91A5), UINT32_C(0xAC9D0F46),
10254           UINT32_C(0xA0E02BF6), UINT32_C(0x97F1812F), UINT32_C(0x5ED9EA2C),
10255           UINT32_C(0xEBD5DB5A), UINT32_C(0x172F564F)}},
10256         {{UINT32_C(0x81F11E58), UINT32_C(0xC790E912), UINT32_C(0x99A5DFF7),
10257           UINT32_C(0x14A17630), UINT32_C(0x1627516D), UINT32_C(0xF6F30F2F),
10258           UINT32_C(0xEFCF43B7), UINT32_C(0x522CAD8F)},
10259          {UINT32_C(0x6EA01128), UINT32_C(0xFFADD45E), UINT32_C(0xD61D1964),
10260           UINT32_C(0x5D23234C), UINT32_C(0x2802DF86), UINT32_C(0xE9212C85),
10261           UINT32_C(0x92AA8DA3), UINT32_C(0x0A3D237B)}},
10262         {{UINT32_C(0xE50ED356), UINT32_C(0x2CED05F4), UINT32_C(0xBFFEEF3A),
10263           UINT32_C(0x1CBC7FB1), UINT32_C(0xBE19F0F0), UINT32_C(0x885991B1),
10264           UINT32_C(0xDE44A492), UINT32_C(0x6DED0794)},
10265          {UINT32_C(0x44CBECFC), UINT32_C(0x9967E834), UINT32_C(0x6A792ED1),
10266           UINT32_C(0xB0674A8D), UINT32_C(0xB7DDD557), UINT32_C(0x360E2DE4),
10267           UINT32_C(0x70E95D26), UINT32_C(0x26852A74)}},
10268         {{UINT32_C(0x3A6E2116), UINT32_C(0x8CBC1520), UINT32_C(0xBF285BBE),
10269           UINT32_C(0xF09327DF), UINT32_C(0x4A54D3C5), UINT32_C(0x8C7D9AD5),
10270           UINT32_C(0x6BD2768F), UINT32_C(0x778F54E6)},
10271          {UINT32_C(0x8FF3DBC0), UINT32_C(0x09B489F8), UINT32_C(0xD2871932),
10272           UINT32_C(0x0A0FA7FB), UINT32_C(0xE0A8CEC4), UINT32_C(0xABB9DC38),
10273           UINT32_C(0x21E37A50), UINT32_C(0x2EE092D8)}},
10274         {{UINT32_C(0xAF6D88D8), UINT32_C(0xBB9256E7), UINT32_C(0x0A218927),
10275           UINT32_C(0x3CDCB1CB), UINT32_C(0xF216D6E6), UINT32_C(0x8E5B744A),
10276           UINT32_C(0xBC885AFD), UINT32_C(0x6F0617F2)},
10277          {UINT32_C(0x268397D5), UINT32_C(0xFBA9CDA7), UINT32_C(0x5D4C75D8),
10278           UINT32_C(0xC6154716), UINT32_C(0x43FB2CD2), UINT32_C(0x9ED8D17B),
10279           UINT32_C(0xBE45BC5C), UINT32_C(0x4D0CE3FB)}},
10280         {{UINT32_C(0xA38472F5), UINT32_C(0x4259BB02), UINT32_C(0x15107D0E),
10281           UINT32_C(0xFAFAAE03), UINT32_C(0xCF0CF2B6), UINT32_C(0x2B8E450E),
10282           UINT32_C(0xED887C3A), UINT32_C(0x788674C3)},
10283          {UINT32_C(0x4B3D2EAC), UINT32_C(0x1F3EBD59), UINT32_C(0x75E41B55),
10284           UINT32_C(0x82CB5684), UINT32_C(0xC02BE49A), UINT32_C(0x005AB76B),
10285           UINT32_C(0xF5F90FEE), UINT32_C(0x6F13ADD2)}},
10286         {{UINT32_C(0x7AFA7161), UINT32_C(0x0116374A), UINT32_C(0x2DB7F824),
10287           UINT32_C(0x8A1AE448), UINT32_C(0xDB656A22), UINT32_C(0xD3C0DA12),
10288           UINT32_C(0xB989204D), UINT32_C(0x7B095B95)},
10289          {UINT32_C(0xEF8F21CA), UINT32_C(0x24C35202), UINT32_C(0x2DA5A5A1),
10290           UINT32_C(0x91088DA7), UINT32_C(0xE3F97D68), UINT32_C(0xAAF1944B),
10291           UINT32_C(0x7C884134), UINT32_C(0x245D2848)}},
10292         {{UINT32_C(0x68F5C702), UINT32_C(0xD80C65D6), UINT32_C(0x021A2974),
10293           UINT32_C(0xE2FE245F), UINT32_C(0x3A11899C), UINT32_C(0xFB8520E0),
10294           UINT32_C(0x2BE6BF88), UINT32_C(0x4806D1FA)},
10295          {UINT32_C(0x20ED235F), UINT32_C(0xF6F8C11A), UINT32_C(0x7F0D651E),
10296           UINT32_C(0x52AC1424), UINT32_C(0xDB9CF6D6), UINT32_C(0x44C3C89F),
10297           UINT32_C(0xB2E2E41F), UINT32_C(0x6762516D)}},
10298         {{UINT32_C(0xFDE91600), UINT32_C(0x2743D874), UINT32_C(0xCDF00100),
10299           UINT32_C(0x60975FD5), UINT32_C(0x2D2954F4), UINT32_C(0x78ACC864),
10300           UINT32_C(0x56373454), UINT32_C(0x46B9E602)},
10301          {UINT32_C(0x6F0FB867), UINT32_C(0x7586A970), UINT32_C(0x242DF35A),
10302           UINT32_C(0x888E3677), UINT32_C(0xF1460F62), UINT32_C(0x5A639E79),
10303           UINT32_C(0x55297DBC), UINT32_C(0x1256517E)}},
10304         {{UINT32_C(0x7B9294C3), UINT32_C(0x3F78339B), UINT32_C(0xBCE77012),
10305           UINT32_C(0x5BA765D1), UINT32_C(0x512E39E2), UINT32_C(0xA88E0CD8),
10306           UINT32_C(0xF6BA6A6A), UINT32_C(0x2D63E14B)},
10307          {UINT32_C(0xEA29071B), UINT32_C(0xF849A163), UINT32_C(0x4C0A2E22),
10308           UINT32_C(0xF32519B7), UINT32_C(0x561C35F5), UINT32_C(0xEA5D1315),
10309           UINT32_C(0xD9267DCA), UINT32_C(0x7041F515)}},
10310         {{UINT32_C(0x1FE56E6B), UINT32_C(0xE01E839F), UINT32_C(0x4A93CE88),
10311           UINT32_C(0x3E473D8C), UINT32_C(0x89AAFDAE), UINT32_C(0xC4846ECF),
10312           UINT32_C(0x07D946EA), UINT32_C(0x4111D97A)},
10313          {UINT32_C(0x51A45F02), UINT32_C(0xC20881F6), UINT32_C(0xB9CD841A),
10314           UINT32_C(0x14C2AC95), UINT32_C(0xF2CBD929), UINT32_C(0x2FBE8329),
10315           UINT32_C(0xC812608B), UINT32_C(0x1E8B7469)}},
10316         {{UINT32_C(0x007F0A5D), UINT32_C(0xB36A5D03), UINT32_C(0x5DCF7AF4),
10317           UINT32_C(0xA7E7A1A8), UINT32_C(0xBEB12AFB), UINT32_C(0x7227F4C5),
10318           UINT32_C(0x4D276783), UINT32_C(0x46227792)},
10319          {UINT32_C(0x48403B93), UINT32_C(0x9EA64D4C), UINT32_C(0x0B333ED5),
10320           UINT32_C(0x58EA31BC), UINT32_C(0xC5C93119), UINT32_C(0x2D6DD219),
10321           UINT32_C(0x45069280), UINT32_C(0x385023A7)}},
10322         {{UINT32_C(0xF60C46AF), UINT32_C(0x8AB9B9EA), UINT32_C(0xE8B827C2),
10323           UINT32_C(0xFA1D3F08), UINT32_C(0x1BAD41DB), UINT32_C(0x78C6BFBC),
10324           UINT32_C(0x23BE0C1E), UINT32_C(0x527A0BED)},
10325          {UINT32_C(0x6ACCE641), UINT32_C(0x66212FD2), UINT32_C(0xEE6F78E7),
10326           UINT32_C(0x86125B0D), UINT32_C(0x58552A8C), UINT32_C(0xA2A02718),
10327           UINT32_C(0x7E9605C5), UINT32_C(0x594F2B77)}},
10328         {{UINT32_C(0x88A27989), UINT32_C(0x3FB1F6CF), UINT32_C(0xD96268B8),
10329           UINT32_C(0xBC4962F7), UINT32_C(0xB95E2A36), UINT32_C(0xBD8761E9),
10330           UINT32_C(0x046DEC63), UINT32_C(0x64AB934A)},
10331          {UINT32_C(0x2E53CF1A), UINT32_C(0xC64D1C59), UINT32_C(0x578C5E8C),
10332           UINT32_C(0xC9865A9B), UINT32_C(0x7A0359DE), UINT32_C(0x5ECA6232),
10333           UINT32_C(0xFB4685E5), UINT32_C(0x127DD136)}},
10334         {{UINT32_C(0x1AE320C9), UINT32_C(0xB0F7B071), UINT32_C(0x52525203),
10335           UINT32_C(0x09BF89BB), UINT32_C(0x709C5692), UINT32_C(0x97B20027),
10336           UINT32_C(0xEDBF6175), UINT32_C(0x16A62485)},
10337          {UINT32_C(0x394C50F9), UINT32_C(0x32C18836), UINT32_C(0xD3B98C19),
10338           UINT32_C(0x7D99468F), UINT32_C(0x2E8D2729), UINT32_C(0x8EBE5096),
10339           UINT32_C(0xE655F093), UINT32_C(0x4E75B3CC)}},
10340         {{UINT32_C(0x9EAE827E), UINT32_C(0xCBEFD1A2), UINT32_C(0xFBF4630D),
10341           UINT32_C(0xDE2D1234), UINT32_C(0x96086CDA), UINT32_C(0x1B3ADCF8),
10342           UINT32_C(0x2EA6CBA7), UINT32_C(0x43D3960E)},
10343          {UINT32_C(0x1CB5A0F7), UINT32_C(0x18321D1D), UINT32_C(0x47BEABB4),
10344           UINT32_C(0xDC94C6F9), UINT32_C(0x75AF6AB7), UINT32_C(0xFBACC6D5),
10345           UINT32_C(0x89B98E86), UINT32_C(0x0EE5D357)}},
10346     },
10347     {
10348         {{UINT32_C(0x062E0994), UINT32_C(0x3F01B4AA), UINT32_C(0x5C952259),
10349           UINT32_C(0x994B28B0), UINT32_C(0x0CDEEC70), UINT32_C(0x2678F8B8),
10350           UINT32_C(0x212436F3), UINT32_C(0x4D06AF84)},
10351          {UINT32_C(0x1CF27A98), UINT32_C(0xE9DF52FD), UINT32_C(0x0B7718F7),
10352           UINT32_C(0xD56B9FD1), UINT32_C(0xD9AEDA0D), UINT32_C(0x728BE624),
10353           UINT32_C(0x1A646888), UINT32_C(0x09871088)}},
10354         {{UINT32_C(0x9B586B13), UINT32_C(0xB1BC922D), UINT32_C(0x3CA3B1BA),
10355           UINT32_C(0x6C084C54), UINT32_C(0xCF322698), UINT32_C(0x54D196C7),
10356           UINT32_C(0x85D527E1), UINT32_C(0x06EC3A55)},
10357          {UINT32_C(0x2A57CAA1), UINT32_C(0x06918710), UINT32_C(0x65FD0F6B),
10358           UINT32_C(0x6AEAC07D), UINT32_C(0x0F512F84), UINT32_C(0xB66A34D7),
10359           UINT32_C(0xA44E6452), UINT32_C(0x3860C002)}},
10360         {{UINT32_C(0x0881608A), UINT32_C(0x17263B26), UINT32_C(0x56C18A7A),
10361           UINT32_C(0x78D556AA), UINT32_C(0xAC3A47AB), UINT32_C(0xA0826A1C),
10362           UINT32_C(0xB6933FF5), UINT32_C(0x61686A58)},
10363          {UINT32_C(0xDBCF2C4F), UINT32_C(0xEA9D8771), UINT32_C(0x6AB00426),
10364           UINT32_C(0x1C66EB02), UINT32_C(0x401C466A), UINT32_C(0xF8DAED2B),
10365           UINT32_C(0xDAAE8040), UINT32_C(0x1ED0A99A)}},
10366         {{UINT32_C(0x7208E58A), UINT32_C(0x31EFFC4B), UINT32_C(0xB4E4319E),
10367           UINT32_C(0x28868456), UINT32_C(0xD46AC4DA), UINT32_C(0x1059C249),
10368           UINT32_C(0x2279B362), UINT32_C(0x3589D212)},
10369          {UINT32_C(0x45552E92), UINT32_C(0xB28B8FAD), UINT32_C(0xC3AB8098),
10370           UINT32_C(0xC9E32541), UINT32_C(0xF14B35A1), UINT32_C(0x82604904),
10371           UINT32_C(0xDB68C214), UINT32_C(0x1E64A89F)}},
10372         {{UINT32_C(0xAB6947AF), UINT32_C(0xDF0E223D), UINT32_C(0x771670D0),
10373           UINT32_C(0xE74EF1D6), UINT32_C(0xF429F03B), UINT32_C(0x70A9AD21),
10374           UINT32_C(0x1385B8DC), UINT32_C(0x7CB1FA1F)},
10375          {UINT32_C(0x69053D24), UINT32_C(0x25ABC0A7), UINT32_C(0x6369D02E),
10376           UINT32_C(0x207FE30A), UINT32_C(0xC6E4EC2C), UINT32_C(0x57B76E3C),
10377           UINT32_C(0xB927CAB2), UINT32_C(0x2E03D2E3)}},
10378         {{UINT32_C(0x622D57AE), UINT32_C(0xEFA377FF), UINT32_C(0xA885951A),
10379           UINT32_C(0x41532F56), UINT32_C(0xCC69B9A8), UINT32_C(0x5ED89AA7),
10380           UINT32_C(0x295F5E84), UINT32_C(0x60BFF2EC)},
10381          {UINT32_C(0x1E5C3041), UINT32_C(0x411D65C3), UINT32_C(0x4B7772F8),
10382           UINT32_C(0xDB533F8B), UINT32_C(0x3BDD4AEA), UINT32_C(0x72CADEB6),
10383           UINT32_C(0x7C49E454), UINT32_C(0x0EC79DF2)}},
10384         {{UINT32_C(0x81D0B84B), UINT32_C(0x0C39332C), UINT32_C(0x95FF472B),
10385           UINT32_C(0xA76A9A3A), UINT32_C(0x31DB2BA6), UINT32_C(0xD12FEB99),
10386           UINT32_C(0x3683E53A), UINT32_C(0x4AAB9222)},
10387          {UINT32_C(0x24FC6271), UINT32_C(0x56CB18AF), UINT32_C(0x2544C72D),
10388           UINT32_C(0x671581D6), UINT32_C(0xFBD6F4D1), UINT32_C(0xCD136492),
10389           UINT32_C(0x3579EE09), UINT32_C(0x6C202318)}},
10390         {{UINT32_C(0xC103C348), UINT32_C(0xEDC5AF02), UINT32_C(0x155A103D),
10391           UINT32_C(0xDA32344E), UINT32_C(0xB0D1377E), UINT32_C(0xFF3A7679),
10392           UINT32_C(0x68F02750), UINT32_C(0x16091972)},
10393          {UINT32_C(0xD9E9C143), UINT32_C(0xD4C6360D), UINT32_C(0x968EE990),
10394           UINT32_C(0xE0ABA0EF), UINT32_C(0x97E4C9AE), UINT32_C(0x57816878),
10395           UINT32_C(0x9D63E32D), UINT32_C(0x5A4D167B)}},
10396         {{UINT32_C(0x50E25802), UINT32_C(0xB04BA525), UINT32_C(0x66912F15),
10397           UINT32_C(0x011DA36E), UINT32_C(0x19E0A182), UINT32_C(0x08D8B680),
10398           UINT32_C(0x2E462B0F), UINT32_C(0x66AA4AE8)},
10399          {UINT32_C(0xE0B9D283), UINT32_C(0x3227C3A6), UINT32_C(0xF2B2B096),
10400           UINT32_C(0x9BF8C4D0), UINT32_C(0xBA809EB7), UINT32_C(0x1E51416C),
10401           UINT32_C(0x2A67D346), UINT32_C(0x68411B75)}},
10402         {{UINT32_C(0x37A67F3B), UINT32_C(0xE55B1348), UINT32_C(0x96484391),
10403           UINT32_C(0x5E32D73C), UINT32_C(0x6256B91E), UINT32_C(0xC3F804D5),
10404           UINT32_C(0x03B0783B), UINT32_C(0x67F17A47)},
10405          {UINT32_C(0xDD2334AD), UINT32_C(0x2010EFEB), UINT32_C(0xB10FF052),
10406           UINT32_C(0xBD9965B5), UINT32_C(0xF58ACA52), UINT32_C(0x519CDA6D),
10407           UINT32_C(0x2FD3D394), UINT32_C(0x045BEEBE)}},
10408         {{UINT32_C(0xEA271BCD), UINT32_C(0x81722E2C), UINT32_C(0x0A4F1342),
10409           UINT32_C(0x393C082E), UINT32_C(0x53B345CE), UINT32_C(0x573F7CD5),
10410           UINT32_C(0x3D7B4292), UINT32_C(0x7AD71FE2)},
10411          {UINT32_C(0xDA8BECB8), UINT32_C(0xDA406D0A), UINT32_C(0x82FE66BC),
10412           UINT32_C(0x14FD41CA), UINT32_C(0x0A91DFFC), UINT32_C(0x80A41062),
10413           UINT32_C(0xF4F0CDEB), UINT32_C(0x33E38E10)}},
10414         {{UINT32_C(0x2529532C), UINT32_C(0x0234BF38), UINT32_C(0xA76CAE3B),
10415           UINT32_C(0x9F5D6342), UINT32_C(0xB3C50442), UINT32_C(0xC9944CB3),
10416           UINT32_C(0x8ABFAF17), UINT32_C(0x51752DF0)},
10417          {UINT32_C(0xA37B13FB), UINT32_C(0x2BFA58C4), UINT32_C(0xDDB14951),
10418           UINT32_C(0x19F80FDE), UINT32_C(0x7DCB927B), UINT32_C(0xDC7026AA),
10419           UINT32_C(0xAAB9FCBA), UINT32_C(0x57907272)}},
10420         {{UINT32_C(0xF3C046C2), UINT32_C(0xCE38712D), UINT32_C(0x47B29D0E),
10421           UINT32_C(0x21D1FDB0), UINT32_C(0xCD96D414), UINT32_C(0x7F746E0E),
10422           UINT32_C(0x636CFEA4), UINT32_C(0x72F07B52)},
10423          {UINT32_C(0xECE6382D), UINT32_C(0x0D8FE94F), UINT32_C(0x24229CA4),
10424           UINT32_C(0x9BFB4CBA), UINT32_C(0xE54388B0), UINT32_C(0xFAE55B77),
10425           UINT32_C(0xA188299F), UINT32_C(0x074EBC32)}},
10426         {{UINT32_C(0xE21DCCA2), UINT32_C(0x8AF2EBCD), UINT32_C(0x377487F2),
10427           UINT32_C(0x9916A6B6), UINT32_C(0xD8051D40), UINT32_C(0x607DC19A),
10428           UINT32_C(0x419DDE12), UINT32_C(0x7DFD53F4)},
10429          {UINT32_C(0x9AD07924), UINT32_C(0xD17D0D61), UINT32_C(0x173E266B),
10430           UINT32_C(0x14F7CE0F), UINT32_C(0x0281C9EB), UINT32_C(0x687FB853),
10431           UINT32_C(0x3361B273), UINT32_C(0x6B35CC1A)}},
10432         {{UINT32_C(0x16E02DE3), UINT32_C(0x7CD6369E), UINT32_C(0x1F35DFBC),
10433           UINT32_C(0x118EE0B1), UINT32_C(0x98B3EE60), UINT32_C(0x7D8C8DBD),
10434           UINT32_C(0x8D29EA17), UINT32_C(0x039806FC)},
10435          {UINT32_C(0xEC2C2597), UINT32_C(0x3C473872), UINT32_C(0x5E4EF521),
10436           UINT32_C(0x81294AF4), UINT32_C(0xC22A9D7C), UINT32_C(0x5ED048DB),
10437           UINT32_C(0x0A08C4D4), UINT32_C(0x3879E95B)}},
10438         {{UINT32_C(0x96A864FE), UINT32_C(0x0206E47F), UINT32_C(0xA55D0631),
10439           UINT32_C(0xC94F137A), UINT32_C(0x8E8408F8), UINT32_C(0x9C1B3D29),
10440           UINT32_C(0xB9193A5E), UINT32_C(0x150A4046)},
10441          {UINT32_C(0xCB1ADF21), UINT32_C(0x4E8F9345), UINT32_C(0x7BD5E1F9),
10442           UINT32_C(0x6ED14D8A), UINT32_C(0x60809F68), UINT32_C(0x70825329),
10443           UINT32_C(0xFA85A06C), UINT32_C(0x0D2F1C3B)}},
10444     },
10445     {
10446         {{UINT32_C(0xB5C810C3), UINT32_C(0x3C5ABE75), UINT32_C(0xE28F1E26),
10447           UINT32_C(0xEA2C3EF9), UINT32_C(0x8BF68280), UINT32_C(0xEEB1C568),
10448           UINT32_C(0x7AE69110), UINT32_C(0x5A165CEB)},
10449          {UINT32_C(0x44550DF1), UINT32_C(0xE36C6460), UINT32_C(0xDB909258),
10450           UINT32_C(0x6FB4B108), UINT32_C(0x17D4D8C5), UINT32_C(0xBFA14277),
10451           UINT32_C(0x927976D8), UINT32_C(0x744CAF23)}},
10452         {{UINT32_C(0x47EA55C7), UINT32_C(0xCBE70DF9), UINT32_C(0x535457AE),
10453           UINT32_C(0x8F8119AE), UINT32_C(0x7DAFD732), UINT32_C(0x1E3C69EC),
10454           UINT32_C(0x39D409A2), UINT32_C(0x1A2E162D)},
10455          {UINT32_C(0x5F81C227), UINT32_C(0xBD7576A1), UINT32_C(0xC86AC2C3),
10456           UINT32_C(0xA040AF9E), UINT32_C(0xC10FC749), UINT32_C(0x5690C059),
10457           UINT32_C(0x49CFAEC6), UINT32_C(0x20B26E88)}},
10458         {{UINT32_C(0xE3EF781E), UINT32_C(0x87AEBD1E), UINT32_C(0x1609A1F0),
10459           UINT32_C(0xBC794A62), UINT32_C(0x26E7F61B), UINT32_C(0x96D83142),
10460           UINT32_C(0xFC51D17D), UINT32_C(0x5198577F)},
10461          {UINT32_C(0x8E6D0124), UINT32_C(0xBFB5FAE2), UINT32_C(0xFFD5BD72),
10462           UINT32_C(0x91A7172B), UINT32_C(0x02832847), UINT32_C(0x474B0154),
10463           UINT32_C(0x59827FEB), UINT32_C(0x4BAF0B4C)}},
10464         {{UINT32_C(0xBA090294), UINT32_C(0x5EADAA8E), UINT32_C(0x11A6E9FA),
10465           UINT32_C(0x51401BC9), UINT32_C(0x1D2594CD), UINT32_C(0x78F11758),
10466           UINT32_C(0x82D203C2), UINT32_C(0x1811AD30)},
10467          {UINT32_C(0x53FD07CC), UINT32_C(0x554CC39A), UINT32_C(0xC7A05601),
10468           UINT32_C(0x055FC983), UINT32_C(0xD5A80B4B), UINT32_C(0xB3B34E95),
10469           UINT32_C(0x1819BC16), UINT32_C(0x72B4CF94)}},
10470         {{UINT32_C(0x514FAFD0), UINT32_C(0x0750E4F0), UINT32_C(0xAD61C7B1),
10471           UINT32_C(0x297D27E6), UINT32_C(0xA2D5D410), UINT32_C(0x701D743F),
10472           UINT32_C(0xC83B55C9), UINT32_C(0x535DD97B)},
10473          {UINT32_C(0x1CB11BB0), UINT32_C(0x2EE96DDE), UINT32_C(0x0914450F),
10474           UINT32_C(0xECEA32EA), UINT32_C(0x4CDBDA6A), UINT32_C(0x4FB81236),
10475           UINT32_C(0x233C8063), UINT32_C(0x5B75B6B2)}},
10476         {{UINT32_C(0xD69D6C6A), UINT32_C(0xF0A934A6), UINT32_C(0x3CC80AC9),
10477           UINT32_C(0x313E8977), UINT32_C(0x1E428B71), UINT32_C(0x74692B17),
10478           UINT32_C(0xE1BE662D), UINT32_C(0x0474FEFC)},
10479          {UINT32_C(0xAFFBF61B), UINT32_C(0xAA2FF6DB), UINT32_C(0x776983AF),
10480           UINT32_C(0xCE1594E1), UINT32_C(0x4D5A2596), UINT32_C(0xF00C665B),
10481           UINT32_C(0x7D414B9A), UINT32_C(0x30DD2449)}},
10482         {{UINT32_C(0xACC44AB3), UINT32_C(0xEF862DA2), UINT32_C(0x6EE7A44A),
10483           UINT32_C(0xBAD6857F), UINT32_C(0xD2F9027E), UINT32_C(0x57674BF9),
10484           UINT32_C(0x2ABF816E), UINT32_C(0x4D771CC3)},
10485          {UINT32_C(0xAC0F1348), UINT32_C(0x27BEFC18), UINT32_C(0x5E4F1202),
10486           UINT32_C(0xD83112EF), UINT32_C(0x8E9AAAE5), UINT32_C(0x3571BDE3),
10487           UINT32_C(0xC1379B13), UINT32_C(0x07284830)}},
10488         {{UINT32_C(0x72A8890C), UINT32_C(0xA4C2F36F), UINT32_C(0x5824B392),
10489           UINT32_C(0x22DF0E81), UINT32_C(0x5E720240), UINT32_C(0x50FAD77F),
10490           UINT32_C(0x03278F96), UINT32_C(0x1D152A69)},
10491          {UINT32_C(0xA7D80F17), UINT32_C(0x25A3E92E), UINT32_C(0x7EF32666),
10492           UINT32_C(0xBBF85B32), UINT32_C(0x27222E52), UINT32_C(0xBBB55687),
10493           UINT32_C(0x7582FE42), UINT32_C(0x756D22A6)}},
10494         {{UINT32_C(0x9BC9EAED), UINT32_C(0x0AE7493A), UINT32_C(0x0DDBB275),
10495           UINT32_C(0x9185F53F), UINT32_C(0xC3DFDBA7), UINT32_C(0x1585D068),
10496           UINT32_C(0x562E2455), UINT32_C(0x543208A1)},
10497          {UINT32_C(0xCBCF9535), UINT32_C(0x4C417D81), UINT32_C(0xE35DD6ED),
10498           UINT32_C(0xD2DC38D3), UINT32_C(0x346F03A4), UINT32_C(0x9DF1E014),
10499           UINT32_C(0xF0E772A6), UINT32_C(0x65736E3F)}},
10500         {{UINT32_C(0xCFB7FF06), UINT32_C(0x58684A7B), UINT32_C(0xC58E6316),
10501           UINT32_C(0x72CC4AFE), UINT32_C(0xA8BB508A), UINT32_C(0x2CA9BF30),
10502           UINT32_C(0xE2044C8C), UINT32_C(0x61576519)},
10503          {UINT32_C(0x8FF6D2B5), UINT32_C(0xE78FAD3D), UINT32_C(0xA934C7B2),
10504           UINT32_C(0x6E5B839F), UINT32_C(0xFAFA9F9B), UINT32_C(0xC1F3D367),
10505           UINT32_C(0xF8B2AFA4), UINT32_C(0x637CC398)}},
10506         {{UINT32_C(0xFE2B2639), UINT32_C(0xD6FC1806), UINT32_C(0x9E98A7F2),
10507           UINT32_C(0x1DB199B4), UINT32_C(0xC794F900), UINT32_C(0x0508763D),
10508           UINT32_C(0x3232E5AC), UINT32_C(0x363F1F7D)},
10509          {UINT32_C(0xBBDBB351), UINT32_C(0xDCF2AD74), UINT32_C(0x5A506BC6),
10510           UINT32_C(0x91F2EAF1), UINT32_C(0xB850088B), UINT32_C(0xBDE8459E),
10511           UINT32_C(0x3E1135AF), UINT32_C(0x52DF883B)}},
10512         {{UINT32_C(0xF93779DC), UINT32_C(0x12FD053A), UINT32_C(0x9E319E46),
10513           UINT32_C(0x3E3D8728), UINT32_C(0xE5E360AE), UINT32_C(0x4D631005),
10514           UINT32_C(0xB1B29A30), UINT32_C(0x4A8B5683)},
10515          {UINT32_C(0xA8CA45EF), UINT32_C(0x305E5E53), UINT32_C(0xC2914843),
10516           UINT32_C(0x59EACB45), UINT32_C(0x1988ECEA), UINT32_C(0x83677B7A),
10517           UINT32_C(0xD6FD53E8), UINT32_C(0x63D9CD36)}},
10518         {{UINT32_C(0xB77EB45F), UINT32_C(0xDF2DACF2), UINT32_C(0x55BBA70E),
10519           UINT32_C(0x3C1303E3), UINT32_C(0x4526A06C), UINT32_C(0x5AB8EB42),
10520           UINT32_C(0x7FE06BBC), UINT32_C(0x4D4FD216)},
10521          {UINT32_C(0xE1486ABC), UINT32_C(0x98C5ADCF), UINT32_C(0x07F86F3A),
10522           UINT32_C(0x9A503BFF), UINT32_C(0x56282E44), UINT32_C(0x7CEBAECB),
10523           UINT32_C(0x1F230DA0), UINT32_C(0x4FB09037)}},
10524         {{UINT32_C(0x27210752), UINT32_C(0xD1A37384), UINT32_C(0x02CF1C74),
10525           UINT32_C(0xD10794D6), UINT32_C(0x820CC08C), UINT32_C(0x48A2095A),
10526           UINT32_C(0xE3284B9D), UINT32_C(0x6DCDDE2E)},
10527          {UINT32_C(0x5D40510D), UINT32_C(0xB8C7203E), UINT32_C(0x5385E3A7),
10528           UINT32_C(0x957E8982), UINT32_C(0xE27D7C13), UINT32_C(0xD220BE2F),
10529           UINT32_C(0x7B471B5B), UINT32_C(0x2D104AC5)}},
10530         {{UINT32_C(0xBA0AFA8D), UINT32_C(0x3B31D52B), UINT32_C(0xDCC85F88),
10531           UINT32_C(0xFA9639F5), UINT32_C(0x8861DDD7), UINT32_C(0x15014637),
10532           UINT32_C(0x7B5443B0), UINT32_C(0x31C222DB)},
10533          {UINT32_C(0xC3CDD689), UINT32_C(0xE2618546), UINT32_C(0xD528A130),
10534           UINT32_C(0x7F3FB754), UINT32_C(0xAC5FAF99), UINT32_C(0xA0915810),
10535           UINT32_C(0xE9899CE5), UINT32_C(0x3863B890)}},
10536         {{UINT32_C(0x579C4353), UINT32_C(0xBDD42CA3), UINT32_C(0x4D65CB5B),
10537           UINT32_C(0xAD30567D), UINT32_C(0x6D91810B), UINT32_C(0x0E343F21),
10538           UINT32_C(0x42E19816), UINT32_C(0x65E0092D)},
10539          {UINT32_C(0xF84E8C8E), UINT32_C(0x76154DCC), UINT32_C(0x0BA4AE59),
10540           UINT32_C(0xBA147CA8), UINT32_C(0x56A1A71E), UINT32_C(0xCA8085E7),
10541           UINT32_C(0x1A158536), UINT32_C(0x1D90B4B0)}},
10542     },
10543     {
10544         {{UINT32_C(0xF8B6C26A), UINT32_C(0x5C4B7438), UINT32_C(0x645BBE80),
10545           UINT32_C(0x0C17A41B), UINT32_C(0x40CF3D85), UINT32_C(0xA386062D),
10546           UINT32_C(0xE78F776D), UINT32_C(0x563E42D2)},
10547          {UINT32_C(0x1F07459B), UINT32_C(0x4BB8E356), UINT32_C(0x75D222CD),
10548           UINT32_C(0xF01A24B7), UINT32_C(0x24CF3F61), UINT32_C(0xBE3D032B),
10549           UINT32_C(0x0AD5F3A3), UINT32_C(0x759B0167)}},
10550         {{UINT32_C(0x7D201AAB), UINT32_C(0x2F5AEBD1), UINT32_C(0xC0AE02AD),
10551           UINT32_C(0x7B14CBEE), UINT32_C(0xEDC6388B), UINT32_C(0xB9B54430),
10552           UINT32_C(0xB622E01F), UINT32_C(0x69E713FB)},
10553          {UINT32_C(0xC5361565), UINT32_C(0x4630EE8E), UINT32_C(0x5C8FB479),
10554           UINT32_C(0x6705961E), UINT32_C(0x07C2AA45), UINT32_C(0x125CC97E),
10555           UINT32_C(0x25AE3B12), UINT32_C(0x4BC459F4)}},
10556         {{UINT32_C(0x28CF94E4), UINT32_C(0xEF025496), UINT32_C(0x9DB24DE6),
10557           UINT32_C(0x04CFAB25), UINT32_C(0xC62254EF), UINT32_C(0x52B8C734),
10558           UINT32_C(0x568AB164), UINT32_C(0x0F2FE922)},
10559          {UINT32_C(0xE3F39B40), UINT32_C(0x48551A05), UINT32_C(0x31A7C7F6),
10560           UINT32_C(0x4A36865F), UINT32_C(0x840441AE), UINT32_C(0x4486512C),
10561           UINT32_C(0x8C7C4B4D), UINT32_C(0x559C6CAF)}},
10562         {{UINT32_C(0x0F103030), UINT32_C(0xFCC0D1DA), UINT32_C(0x39CD584E),
10563           UINT32_C(0x7A9F1D55), UINT32_C(0x681D0D37), UINT32_C(0x3EFB9B94),
10564           UINT32_C(0x4D842332), UINT32_C(0x3AE97CCD)},
10565          {UINT32_C(0x3C03676B), UINT32_C(0x85A8ECE1), UINT32_C(0x3AD435A1),
10566           UINT32_C(0x030F8775), UINT32_C(0x7F2D73B5), UINT32_C(0xF6019B4D),
10567           UINT32_C(0x2F14F911), UINT32_C(0x6B77E31A)}},
10568         {{UINT32_C(0x9186C671), UINT32_C(0x65C8161B), UINT32_C(0xCDFF2F8C),
10569           UINT32_C(0x412C3CC7), UINT32_C(0x2C2FEA33), UINT32_C(0xBFFC1719),
10570           UINT32_C(0xC3675845), UINT32_C(0x75DCF68B)},
10571          {UINT32_C(0x3B23D576), UINT32_C(0x0476AFBF), UINT32_C(0x19315F79),
10572           UINT32_C(0xB20CAEE2), UINT32_C(0x0885471A), UINT32_C(0x1BC2A859),
10573           UINT32_C(0xC328279C), UINT32_C(0x410FF6CF)}},
10574         {{UINT32_C(0x60569D94), UINT32_C(0x327394D9), UINT32_C(0x6EA39D95),
10575           UINT32_C(0xFF2AEB6A), UINT32_C(0xEA0CA3AE), UINT32_C(0x1BED71E8),
10576           UINT32_C(0x21072A94), UINT32_C(0x1000A81E)},
10577          {UINT32_C(0x73C02416), UINT32_C(0x368EA229), UINT32_C(0x0A4941BC),
10578           UINT32_C(0xDF5B2A42), UINT32_C(0xD0D40B3A), UINT32_C(0x4FFDC7B8),
10579           UINT32_C(0x48ABAB4E), UINT32_C(0x7B2C73F1)}},
10580         {{UINT32_C(0x81EE1072), UINT32_C(0x90FE34E4), UINT32_C(0x310E13D8),
10581           UINT32_C(0xAE7A2FF4), UINT32_C(0xCAB3927C), UINT32_C(0x6213D3B1),
10582           UINT32_C(0x7DC7E9EF), UINT32_C(0x44936FBD)},
10583          {UINT32_C(0x23A1BDBE), UINT32_C(0x3B898EF3), UINT32_C(0x54CC7B1D),
10584           UINT32_C(0x3FA6C6A0), UINT32_C(0xC6AC54F2), UINT32_C(0x41BCC3B5),
10585           UINT32_C(0xDC10AE39), UINT32_C(0x1AB5D168)}},
10586         {{UINT32_C(0xFEAF67A6), UINT32_C(0x1AED113C), UINT32_C(0x342AC459),
10587           UINT32_C(0x04E3C7A1), UINT32_C(0x7A99DFBC), UINT32_C(0x65A39278),
10588           UINT32_C(0x642329FF), UINT32_C(0x03ECBC6B)},
10589          {UINT32_C(0xA6A4421A), UINT32_C(0x799F4EC5), UINT32_C(0xBEE18B3C),
10590           UINT32_C(0x44522C26), UINT32_C(0x1975C4BB), UINT32_C(0x1C7BFF15),
10591           UINT32_C(0xE6A27857), UINT32_C(0x0FAA03BE)}},
10592         {{UINT32_C(0x0743FF7B), UINT32_C(0x173AB9E0), UINT32_C(0x2CFC95AE),
10593           UINT32_C(0xB11187AE), UINT32_C(0x9C112049), UINT32_C(0xCA81BB2E),
10594           UINT32_C(0xC03555D5), UINT32_C(0x6B811DB6)},
10595          {UINT32_C(0x4FE32256), UINT32_C(0x76C1FC14), UINT32_C(0xD0E47C4E),
10596           UINT32_C(0xDA8C5A96), UINT32_C(0x29FDB01C), UINT32_C(0xB645D413),
10597           UINT32_C(0xAC39502A), UINT32_C(0x78898447)}},
10598         {{UINT32_C(0x9BF44B35), UINT32_C(0x4285FF32), UINT32_C(0xE3358C7F),
10599           UINT32_C(0x207F9029), UINT32_C(0x63BAF4CE), UINT32_C(0x0FE8F032),
10600           UINT32_C(0xFF15E1F7), UINT32_C(0x698A0398)},
10601          {UINT32_C(0x7E572DF6), UINT32_C(0x54874843), UINT32_C(0x9F43C07B),
10602           UINT32_C(0x74683519), UINT32_C(0x0A433D6A), UINT32_C(0x47BAB49E),
10603           UINT32_C(0xFAB5C858), UINT32_C(0x09ED8740)}},
10604         {{UINT32_C(0x1F6CA820), UINT32_C(0x8AA5E5C9), UINT32_C(0xD3C25BEC),
10605           UINT32_C(0xAD290A94), UINT32_C(0x3BA255F0), UINT32_C(0xDC4C67BF),
10606           UINT32_C(0x1DEDD8A9), UINT32_C(0x0D7EF7D9)},
10607          {UINT32_C(0x5EEFD1C3), UINT32_C(0x0831A26F), UINT32_C(0x04483E0C),
10608           UINT32_C(0x78CA66F5), UINT32_C(0x2FAAC15A), UINT32_C(0x9D5A5612),
10609           UINT32_C(0x5D6FACDB), UINT32_C(0x43B0C7E7)}},
10610         {{UINT32_C(0x4503899D), UINT32_C(0x34BA537C), UINT32_C(0x2AF8ED3B),
10611           UINT32_C(0x9DEBC8F5), UINT32_C(0x84F416E6), UINT32_C(0x396995E9),
10612           UINT32_C(0xC7BCE392), UINT32_C(0x77F10FED)},
10613          {UINT32_C(0x1F8AF262), UINT32_C(0x065CCB72), UINT32_C(0xD2F00FC4),
10614           UINT32_C(0xE220ED60), UINT32_C(0x5EE25B46), UINT32_C(0x41A5FB06),
10615           UINT32_C(0xDD9070B1), UINT32_C(0x22505574)}},
10616         {{UINT32_C(0x44BFC5C0), UINT32_C(0x571FF151), UINT32_C(0x3138363C),
10617           UINT32_C(0xBE2558B8), UINT32_C(0x605E356C), UINT32_C(0xB2211ABD),
10618           UINT32_C(0x176C5F53), UINT32_C(0x0B6435DA)},
10619          {UINT32_C(0x8DCF484E), UINT32_C(0xF18C917C), UINT32_C(0xCD93D65F),
10620           UINT32_C(0x45D4120C), UINT32_C(0x190AE7F8), UINT32_C(0xEBB0BF9C),
10621           UINT32_C(0x8D8C8D5A), UINT32_C(0x3D403DE2)}},
10622         {{UINT32_C(0xBE656644), UINT32_C(0xCDE760B4), UINT32_C(0x2D21DBC5),
10623           UINT32_C(0x99DC5E6D), UINT32_C(0xB6232D08), UINT32_C(0x644FCAF3),
10624           UINT32_C(0x859341E3), UINT32_C(0x52955488)},
10625          {UINT32_C(0x25763919), UINT32_C(0x3AB4580D), UINT32_C(0x4EF66999),
10626           UINT32_C(0x82AB0C53), UINT32_C(0x0180663E), UINT32_C(0xBD395C74),
10627           UINT32_C(0xB4756474), UINT32_C(0x07974F1A)}},
10628         {{UINT32_C(0x31588EA6), UINT32_C(0x8C15CFE7), UINT32_C(0xF36C882D),
10629           UINT32_C(0x9629060E), UINT32_C(0x862B080D), UINT32_C(0xDF8E8E9E),
10630           UINT32_C(0xD7A0C5BE), UINT32_C(0x0BD36B48)},
10631          {UINT32_C(0x76DA047B), UINT32_C(0xEBD0C6C9), UINT32_C(0xBB94FD5A),
10632           UINT32_C(0x4F0F08AB), UINT32_C(0x74910D9F), UINT32_C(0x33D41A4E),
10633           UINT32_C(0xA9583754), UINT32_C(0x3D6F8D0B)}},
10634         {{UINT32_C(0x4E4FC72E), UINT32_C(0xEC4C896E), UINT32_C(0x002ECE31),
10635           UINT32_C(0xB111210C), UINT32_C(0x2AF11E21), UINT32_C(0x7204D937),
10636           UINT32_C(0x5D0509E9), UINT32_C(0x59B9C1EC)},
10637          {UINT32_C(0xF9D5BBC0), UINT32_C(0xBC97644C), UINT32_C(0x31B4E869),
10638           UINT32_C(0x25B123AF), UINT32_C(0x5A6CAAB0), UINT32_C(0x091D7AEC),
10639           UINT32_C(0xECC911C4), UINT32_C(0x340B9E80)}},
10640     },
10641     {
10642         {{UINT32_C(0xEC208406), UINT32_C(0xE8036B20), UINT32_C(0x214CEB5A),
10643           UINT32_C(0xAF46A05A), UINT32_C(0x46CC8379), UINT32_C(0x8672084A),
10644           UINT32_C(0x04BA7885), UINT32_C(0x7DE0A42F)},
10645          {UINT32_C(0xC9D3F32A), UINT32_C(0xB772BEDC), UINT32_C(0x534B1520),
10646           UINT32_C(0x7DAE3680), UINT32_C(0xEC7120CC), UINT32_C(0x04CD6203),
10647           UINT32_C(0xB4E99780), UINT32_C(0x032F88E3)}},
10648         {{UINT32_C(0xE4A0897E), UINT32_C(0xB34BDA5C), UINT32_C(0x379B2480),
10649           UINT32_C(0xF7748B26), UINT32_C(0xB2D97522), UINT32_C(0xF47F6646),
10650           UINT32_C(0xF9641DB9), UINT32_C(0x66AD8DE1)},
10651          {UINT32_C(0xD1BF09C0), UINT32_C(0x0F8EB919), UINT32_C(0xB95DC052),
10652           UINT32_C(0x7853BB4E), UINT32_C(0x62B1FD4A), UINT32_C(0xBE7EE13D),
10653           UINT32_C(0xDC7CE53E), UINT32_C(0x2FF7EDC5)}},
10654         {{UINT32_C(0xEE81DF35), UINT32_C(0xE1009AA0), UINT32_C(0x61D0798B),
10655           UINT32_C(0x14972F02), UINT32_C(0xF1EA1A6A), UINT32_C(0x5A6831A0),
10656           UINT32_C(0x0CAB301A), UINT32_C(0x1DBABA3D)},
10657          {UINT32_C(0x157D5213), UINT32_C(0x421270E2), UINT32_C(0x6407B790),
10658           UINT32_C(0xA37BEA95), UINT32_C(0x103A6073), UINT32_C(0xEAD56B1F),
10659           UINT32_C(0xBAD909F1), UINT32_C(0x27534624)}},
10660         {{UINT32_C(0xC2621EF1), UINT32_C(0xC92D2209), UINT32_C(0x1D3AD3F3),
10661           UINT32_C(0x450710C3), UINT32_C(0x19E481AD), UINT32_C(0x8CFB8D6C),
10662           UINT32_C(0xE6DB01BD), UINT32_C(0x35CACDAE)},
10663          {UINT32_C(0x7CDD5B01), UINT32_C(0x2DA4A1D8), UINT32_C(0x0F55BA11),
10664           UINT32_C(0x3E40C751), UINT32_C(0xB15C162D), UINT32_C(0xA91D9EE7),
10665           UINT32_C(0x11DBA157), UINT32_C(0x13AD3BE5)}},
10666         {{UINT32_C(0xE72F64F5), UINT32_C(0xAE417DB0), UINT32_C(0xF13352BA),
10667           UINT32_C(0x40822279), UINT32_C(0x1F2B75B9), UINT32_C(0xEC43AFD9),
10668           UINT32_C(0xC9CF2972), UINT32_C(0x14D4BB2B)},
10669          {UINT32_C(0x0761B2F1), UINT32_C(0x4A55718A), UINT32_C(0xD81A9307),
10670           UINT32_C(0xDAFBF756), UINT32_C(0x5D3E5A07), UINT32_C(0x2DCDFC1C),
10671           UINT32_C(0x2EBBDF28), UINT32_C(0x696E42ED)}},
10672         {{UINT32_C(0x68705410), UINT32_C(0xF4739399), UINT32_C(0xAF5FFC88),
10673           UINT32_C(0xFD581005), UINT32_C(0x90A9F517), UINT32_C(0x5490A694),
10674           UINT32_C(0x8CF8327E), UINT32_C(0x4A5C8C2E)},
10675          {UINT32_C(0xF7D83DA6), UINT32_C(0xC203CD35), UINT32_C(0x7282368D),
10676           UINT32_C(0xECAA6B90), UINT32_C(0x2AF7EC42), UINT32_C(0x365BB571),
10677           UINT32_C(0xD4099316), UINT32_C(0x112E7ACD)}},
10678         {{UINT32_C(0x3AE3C25C), UINT32_C(0x9ABDE060), UINT32_C(0xEB9925B2),
10679           UINT32_C(0xE4C03DAD), UINT32_C(0x9E03388B), UINT32_C(0x3C28DCB1),
10680           UINT32_C(0x52B63C06), UINT32_C(0x2337A7CF)},
10681          {UINT32_C(0x4E1AF2EA), UINT32_C(0x74DC0F13), UINT32_C(0xCD0D59AA),
10682           UINT32_C(0xA010E4E3), UINT32_C(0x9FA14C96), UINT32_C(0x6E4DB7BA),
10683           UINT32_C(0x557F7CDE), UINT32_C(0x5B2C3862)}},
10684         {{UINT32_C(0xC8C79CA9), UINT32_C(0xC826E567), UINT32_C(0xE851BE0C),
10685           UINT32_C(0xE7D110CA), UINT32_C(0xA3606499), UINT32_C(0xFFD57057),
10686           UINT32_C(0xC6482504), UINT32_C(0x2E9DBC40)},
10687          {UINT32_C(0xF784D9AF), UINT32_C(0xC9F0C3C2), UINT32_C(0xB755172E),
10688           UINT32_C(0xDD982A05), UINT32_C(0xA023997F), UINT32_C(0x6BC6C19D),
10689           UINT32_C(0xE34493C6), UINT32_C(0x4AC177BE)}},
10690         {{UINT32_C(0x4FA4F134), UINT32_C(0x21C3E087), UINT32_C(0x86F9722F),
10691           UINT32_C(0x66E10C34), UINT32_C(0x7398579A), UINT32_C(0xD2927B01),
10692           UINT32_C(0x0352C3D3), UINT32_C(0x7135B638)},
10693          {UINT32_C(0x3BB5EE11), UINT32_C(0x2DA62007), UINT32_C(0x3A946236),
10694           UINT32_C(0x8B64F13C), UINT32_C(0x30EAE6DF), UINT32_C(0x3A83C854),
10695           UINT32_C(0x0EB6F749), UINT32_C(0x31114E2A)}},
10696         {{UINT32_C(0x35BFC72B), UINT32_C(0x2C7B52E7), UINT32_C(0x2B0D4C2C),
10697           UINT32_C(0x6DD29EBD), UINT32_C(0x6C92E82D), UINT32_C(0xE90D3988),
10698           UINT32_C(0x3864D94D), UINT32_C(0x0A924901)},
10699          {UINT32_C(0x9BEE9E78), UINT32_C(0x63050824), UINT32_C(0x003DD5CF),
10700           UINT32_C(0x7929FD62), UINT32_C(0xE57507D1), UINT32_C(0xD04F832C),
10701           UINT32_C(0x37D2C32E), UINT32_C(0x61078BDC)}},
10702         {{UINT32_C(0x2E75264A), UINT32_C(0xB118AFDD), UINT32_C(0xEFD65114),
10703           UINT32_C(0x3AB692EA), UINT32_C(0x8B0A2128), UINT32_C(0x58D2CE24),
10704           UINT32_C(0x82ED6D5F), UINT32_C(0x4316E6C2)},
10705          {UINT32_C(0x46345BE4), UINT32_C(0x97766FFF), UINT32_C(0x0A7451AA),
10706           UINT32_C(0xD7FF3014), UINT32_C(0xAACE2E37), UINT32_C(0x078A423F),
10707           UINT32_C(0xA6A78919), UINT32_C(0x7F1F90C2)}},
10708         {{UINT32_C(0x8E9E3D4D), UINT32_C(0x988FCCB0), UINT32_C(0xB95C9731),
10709           UINT32_C(0xBD003FC0), UINT32_C(0xB0A84E58), UINT32_C(0x74E40076),
10710           UINT32_C(0x1DF7FDD0), UINT32_C(0x5FD1DBE6)},
10711          {UINT32_C(0x4E6CE2FA), UINT32_C(0xD2C700C7), UINT32_C(0x903C5AE7),
10712           UINT32_C(0xA6E042E2), UINT32_C(0x3C73822E), UINT32_C(0x561CC25F),
10713           UINT32_C(0x2A6A0C0C), UINT32_C(0x651A7939)}},
10714         {{UINT32_C(0x88CD7642), UINT32_C(0x103E9EC6), UINT32_C(0x3C3C86CE),
10715           UINT32_C(0x65ED5218), UINT32_C(0x82785C8B), UINT32_C(0x16BAB002),
10716           UINT32_C(0xF34723C5), UINT32_C(0x0B5C18BB)},
10717          {UINT32_C(0xE724D144), UINT32_C(0x528B0546), UINT32_C(0x780EEF9E),
10718           UINT32_C(0x5E582A6B), UINT32_C(0x122F17AD), UINT32_C(0xC08283B8),
10719           UINT32_C(0x1C22F32D), UINT32_C(0x0300EDCD)}},
10720         {{UINT32_C(0x38DCFD39), UINT32_C(0x03AC716A), UINT32_C(0x94F12C74),
10721           UINT32_C(0xCD88474C), UINT32_C(0xE9042CA8), UINT32_C(0xB5E8641E),
10722           UINT32_C(0x40D10558), UINT32_C(0x1D5746CC)},
10723          {UINT32_C(0xCB4BB408), UINT32_C(0x7869F45E), UINT32_C(0x569489C3),
10724           UINT32_C(0x28FB091D), UINT32_C(0x50A46306), UINT32_C(0xEA371EEC),
10725           UINT32_C(0x75AA224C), UINT32_C(0x28025796)}},
10726         {{UINT32_C(0xF7A5923A), UINT32_C(0x4EAFA44E), UINT32_C(0x6B69FD8B),
10727           UINT32_C(0xD2427C30), UINT32_C(0x393D83F9), UINT32_C(0x4C4E884A),
10728           UINT32_C(0x6236AB65), UINT32_C(0x2D34890A)},
10729          {UINT32_C(0x35CC97F5), UINT32_C(0x80038D40), UINT32_C(0x97897472),
10730           UINT32_C(0x4FE43C84), UINT32_C(0xBEF161AF), UINT32_C(0xE5F56243),
10731           UINT32_C(0x9372E631), UINT32_C(0x3E1BDD6F)}},
10732         {{UINT32_C(0x5732669F), UINT32_C(0x06A2B287), UINT32_C(0xCDF4D2C0),
10733           UINT32_C(0x92D00397), UINT32_C(0x454A57F5), UINT32_C(0xCD9A25F0),
10734           UINT32_C(0x2F0CDB0B), UINT32_C(0x23ADB724)},
10735          {UINT32_C(0xFF0F8CB0), UINT32_C(0x504DA603), UINT32_C(0xD3E24181),
10736           UINT32_C(0x14EF9D30), UINT32_C(0x47FC1E66), UINT32_C(0xB1B1328E),
10737           UINT32_C(0x6C60354D), UINT32_C(0x319B2A84)}},
10738     },
10739     {
10740         {{UINT32_C(0xF1D56038), UINT32_C(0xBBF5542E), UINT32_C(0xDD71CFC3),
10741           UINT32_C(0xEDE3E637), UINT32_C(0x2E9F6C8B), UINT32_C(0xFAA81D21),
10742           UINT32_C(0x69FBD060), UINT32_C(0x4DD2D44B)},
10743          {UINT32_C(0x14366A20), UINT32_C(0x71FB6233), UINT32_C(0x9575451D),
10744           UINT32_C(0x155E486F), UINT32_C(0xEC7807D9), UINT32_C(0x001106F0),
10745           UINT32_C(0xC617034C), UINT32_C(0x1C80E5AB)}},
10746         {{UINT32_C(0x8619F5F4), UINT32_C(0xD3E478DB), UINT32_C(0xF68170C2),
10747           UINT32_C(0x1DF5C367), UINT32_C(0x3430DE1D), UINT32_C(0xEAB09524),
10748           UINT32_C(0xC3CD4C24), UINT32_C(0x48F09361)},
10749          {UINT32_C(0x60644FED), UINT32_C(0xE49DEA4B), UINT32_C(0x758C3679),
10750           UINT32_C(0x47170F1C), UINT32_C(0xB0382A84), UINT32_C(0x4CC1E6E8),
10751           UINT32_C(0x10A4465E), UINT32_C(0x2DBDB9DA)}},
10752         {{UINT32_C(0xC8400A4C), UINT32_C(0x67BAA79A), UINT32_C(0x01D28ECE),
10753           UINT32_C(0xFA306753), UINT32_C(0x6F33289C), UINT32_C(0x29DB5B1C),
10754           UINT32_C(0x26A8FCB4), UINT32_C(0x44757573)},
10755          {UINT32_C(0xE1B0A795), UINT32_C(0x59616219), UINT32_C(0xC5B32FA0),
10756           UINT32_C(0x3032D939), UINT32_C(0x7C3CEA2C), UINT32_C(0x3010C917),
10757           UINT32_C(0x9892BDF4), UINT32_C(0x5CF83EF1)}},
10758         {{UINT32_C(0x3C7E83E6), UINT32_C(0x55DE1141), UINT32_C(0x74EA0366),
10759           UINT32_C(0x9D03929C), UINT32_C(0x83BAF3FE), UINT32_C(0x5CA60C50),
10760           UINT32_C(0x7F70E905), UINT32_C(0x3D9BCA58)},
10761          {UINT32_C(0xFCC5AB59), UINT32_C(0xDB79DF5A), UINT32_C(0x53F68D30),
10762           UINT32_C(0x03CFCF06), UINT32_C(0x4FCFA5F1), UINT32_C(0xBE101A78),
10763           UINT32_C(0xB49E493C), UINT32_C(0x115D7078)}},
10764         {{UINT32_C(0x76A0CCBD), UINT32_C(0xF14023AA), UINT32_C(0x086F2E50),
10765           UINT32_C(0x4287F0BC), UINT32_C(0xF79A37E7), UINT32_C(0xC5EAA559),
10766           UINT32_C(0x04E4F2A2), UINT32_C(0x5D527C09)},
10767          {UINT32_C(0x51DAA504), UINT32_C(0xEC914616), UINT32_C(0xEEF1DC95),
10768           UINT32_C(0x250D90C6), UINT32_C(0xA50330B2), UINT32_C(0x1B0AA868),
10769           UINT32_C(0x54189BBE), UINT32_C(0x7B45A783)}},
10770         {{UINT32_C(0xF019D6FF), UINT32_C(0x0D602E05), UINT32_C(0xDD1800BA),
10771           UINT32_C(0x563E3893), UINT32_C(0xF3C7F7E5), UINT32_C(0x7146727E),
10772           UINT32_C(0x4B026635), UINT32_C(0x59641D98)},
10773          {UINT32_C(0xE91DDBB8), UINT32_C(0x50BCF90F), UINT32_C(0x7F8397A6),
10774           UINT32_C(0x5D43E78E), UINT32_C(0xEB15896E), UINT32_C(0x8734A261),
10775           UINT32_C(0x9FF6B361), UINT32_C(0x4AD1E864)}},
10776         {{UINT32_C(0x320322F1), UINT32_C(0x1A9B601F), UINT32_C(0x91F611C4),
10777           UINT32_C(0x606D40B3), UINT32_C(0xA19C918F), UINT32_C(0xB984958B),
10778           UINT32_C(0x776F834E), UINT32_C(0x67BFB045)},
10779          {UINT32_C(0x68DD85F0), UINT32_C(0xC59E5569), UINT32_C(0xD4067875),
10780           UINT32_C(0xB5642834), UINT32_C(0xCB138DF3), UINT32_C(0x247E7D65),
10781           UINT32_C(0x5CB9281D), UINT32_C(0x73640A03)}},
10782         {{UINT32_C(0x88639889), UINT32_C(0xC7C34CCC), UINT32_C(0xA785C707),
10783           UINT32_C(0xD9E44E07), UINT32_C(0x32F83073), UINT32_C(0x1BE68EFE),
10784           UINT32_C(0xAE5317CE), UINT32_C(0x249902DA)},
10785          {UINT32_C(0x76CA92FF), UINT32_C(0xF1F0B86A), UINT32_C(0xC01CB06B),
10786           UINT32_C(0xA7F502CF), UINT32_C(0x595AA185), UINT32_C(0x0A8B4766),
10787           UINT32_C(0xB792DE49), UINT32_C(0x614135AA)}},
10788         {{UINT32_C(0x564F2BC8), UINT32_C(0x5392CAA7), UINT32_C(0xCC894FCD),
10789           UINT32_C(0x1CDDA684), UINT32_C(0xA4EBF82F), UINT32_C(0x10AC2378),
10790           UINT32_C(0x5051BFF9), UINT32_C(0x6211EA46)},
10791          {UINT32_C(0x30E8E210), UINT32_C(0xE53B0174), UINT32_C(0x02C0E381),
10792           UINT32_C(0x2374FEC3), UINT32_C(0x4DA07224), UINT32_C(0xF8B1506B),
10793           UINT32_C(0x54DA7A08), UINT32_C(0x4E451E01)}},
10794         {{UINT32_C(0x241FC7FB), UINT32_C(0xA8404D9C), UINT32_C(0xC4406332),
10795           UINT32_C(0x1D6DBF6E), UINT32_C(0x30162118), UINT32_C(0xFE142319),
10796           UINT32_C(0xA7EF5EF5), UINT32_C(0x69DE75CC)},
10797          {UINT32_C(0x856E26A5), UINT32_C(0x008D4D09), UINT32_C(0xC588ECF6),
10798           UINT32_C(0x2BC64B65), UINT32_C(0xAA01EE19), UINT32_C(0x7A523D0B),
10799           UINT32_C(0x932F0B95), UINT32_C(0x213EF390)}},
10800         {{UINT32_C(0x1CD716FA), UINT32_C(0xA42FE513), UINT32_C(0x0E8001B6),
10801           UINT32_C(0xFB13B3C6), UINT32_C(0xD8F530CB), UINT32_C(0xBFDC7998),
10802           UINT32_C(0xF1C61761), UINT32_C(0x04F9C05B)},
10803          {UINT32_C(0xAFED9D64), UINT32_C(0xFB57396F), UINT32_C(0x421AC123),
10804           UINT32_C(0x28CCEE3A), UINT32_C(0xF6C21ACC), UINT32_C(0x32590C9B),
10805           UINT32_C(0xBCA75AE3), UINT32_C(0x503B97CB)}},
10806         {{UINT32_C(0x366946ED), UINT32_C(0x745208BC), UINT32_C(0x4C906596),
10807           UINT32_C(0xA75D88E9), UINT32_C(0xEE043530), UINT32_C(0x03A30C7E),
10808           UINT32_C(0xD11BF4D5), UINT32_C(0x5C67C151)},
10809          {UINT32_C(0xE7AE4BB3), UINT32_C(0x04F75DFA), UINT32_C(0x7F8D7404),
10810           UINT32_C(0xA0813606), UINT32_C(0x19D68F64), UINT32_C(0x8B9F9210),
10811           UINT32_C(0x06F73B55), UINT32_C(0x5AB67971)}},
10812         {{UINT32_C(0xB0687095), UINT32_C(0x08064C4A), UINT32_C(0xB0106DF4),
10813           UINT32_C(0x27E30DDD), UINT32_C(0x8482524A), UINT32_C(0x31D29C70),
10814           UINT32_C(0xD86FDACD), UINT32_C(0x65DD5896)},
10815          {UINT32_C(0xC647197E), UINT32_C(0x081C013D), UINT32_C(0xD7A53A45),
10816           UINT32_C(0x51C10B9E), UINT32_C(0x0DD7FC53), UINT32_C(0xACB9A4DE),
10817           UINT32_C(0xF646220B), UINT32_C(0x639997A2)}},
10818         {{UINT32_C(0x1FB93B43), UINT32_C(0x97CCF825), UINT32_C(0xE488D786),
10819           UINT32_C(0xB7D7713D), UINT32_C(0x3E4DBB33), UINT32_C(0x4F759566),
10820           UINT32_C(0xE0F09964), UINT32_C(0x13B5D8A1)},
10821          {UINT32_C(0x316CDD97), UINT32_C(0xFFDDAD74), UINT32_C(0x52C92EE9),
10822           UINT32_C(0x67C55782), UINT32_C(0x0AC5D6FD), UINT32_C(0x03B50F94),
10823           UINT32_C(0x1484DF88), UINT32_C(0x56C5C009)}},
10824         {{UINT32_C(0x1778D303), UINT32_C(0xDCE199E3), UINT32_C(0x0F1DD4EC),
10825           UINT32_C(0x53A2A4C6), UINT32_C(0x370A7B99), UINT32_C(0x7CC5EE9E),
10826           UINT32_C(0x2598744E), UINT32_C(0x4403202B)},
10827          {UINT32_C(0x228247B6), UINT32_C(0xCCFAA978), UINT32_C(0x4A1D0E27),
10828           UINT32_C(0xF50D14BD), UINT32_C(0x80723ABC), UINT32_C(0x66695061),
10829           UINT32_C(0x742C0015), UINT32_C(0x750CCB6A)}},
10830         {{UINT32_C(0x81A109F1), UINT32_C(0x7B046936), UINT32_C(0xD4C1AFE5),
10831           UINT32_C(0x6414D9A3), UINT32_C(0xDD14AC1F), UINT32_C(0x35070548),
10832           UINT32_C(0xDEC0D3F0), UINT32_C(0x27172F39)},
10833          {UINT32_C(0xF2E273F0), UINT32_C(0x4EE0A7BF), UINT32_C(0xEC82B8E6),
10834           UINT32_C(0x028C7813), UINT32_C(0x2081EAE2), UINT32_C(0x907BF09F),
10835           UINT32_C(0x414D6421), UINT32_C(0x72E4C3D3)}},
10836     },
10837     {
10838         {{UINT32_C(0xA073711C), UINT32_C(0x2064097E), UINT32_C(0x5A65EC25),
10839           UINT32_C(0x980D830A), UINT32_C(0xF0877567), UINT32_C(0x7906A87C),
10840           UINT32_C(0xF1980A3A), UINT32_C(0x3E5EAE10)},
10841          {UINT32_C(0x9272CE32), UINT32_C(0x5F51023A), UINT32_C(0xA437C974),
10842           UINT32_C(0x71D69E68), UINT32_C(0xD0B579FF), UINT32_C(0x32006EA1),
10843           UINT32_C(0xA436E129), UINT32_C(0x191935FF)}},
10844         {{UINT32_C(0x91C1474C), UINT32_C(0xE5FE2909), UINT32_C(0x1F0B10F5),
10845           UINT32_C(0x7350B9FA), UINT32_C(0x6B4AB128), UINT32_C(0x2006F41D),
10846           UINT32_C(0xCD95FA42), UINT32_C(0x4EBDA6CF)},
10847          {UINT32_C(0x5DA9A7F4), UINT32_C(0x45028938), UINT32_C(0x57FB462B),
10848           UINT32_C(0xD8129DE4), UINT32_C(0xE592EF90), UINT32_C(0x4F2BF2C9),
10849           UINT32_C(0xD6751DCC), UINT32_C(0x14A1A16B)}},
10850         {{UINT32_C(0xDE0CD47A), UINT32_C(0x7460BB84), UINT32_C(0x468CBA3D),
10851           UINT32_C(0x261F24D6), UINT32_C(0x1E3C2D8A), UINT32_C(0x229D3181),
10852           UINT32_C(0x1D19E059), UINT32_C(0x4AE520C9)},
10853          {UINT32_C(0xDF8DC66E), UINT32_C(0x5AC3AEE7), UINT32_C(0x299697EE),
10854           UINT32_C(0xCB417060), UINT32_C(0xCE97514F), UINT32_C(0x227C1497),
10855           UINT32_C(0x2E991FDE), UINT32_C(0x2589B803)}},
10856         {{UINT32_C(0xA97A5D03), UINT32_C(0x7FE9D585), UINT32_C(0x10D58157),
10857           UINT32_C(0x7333A1EF), UINT32_C(0xC94C3DF6), UINT32_C(0x54C1CCD2),
10858           UINT32_C(0x28073B4E), UINT32_C(0x25C1B252)},
10859          {UINT32_C(0x0635AD79), UINT32_C(0xEEB29AF9), UINT32_C(0x9AA38848),
10860           UINT32_C(0x880019C1), UINT32_C(0x30A9A497), UINT32_C(0x1A859942),
10861           UINT32_C(0x92B25ABA), UINT32_C(0x57EDCC2D)}},
10862         {{UINT32_C(0x65E19DE6), UINT32_C(0xA98DAE7D), UINT32_C(0x46AD8696),
10863           UINT32_C(0x8007DD17), UINT32_C(0xA7F3BBAD), UINT32_C(0x61F2E2CF),
10864           UINT32_C(0x54193858), UINT32_C(0x1EFCD387)},
10865          {UINT32_C(0x11666ECF), UINT32_C(0xFB54FD60), UINT32_C(0x36E7D371),
10866           UINT32_C(0xD97EA5DF), UINT32_C(0x3B9371FF), UINT32_C(0x944CA170),
10867           UINT32_C(0x05DE7FB0), UINT32_C(0x32A52CAC)}},
10868         {{UINT32_C(0x19ED8B5E), UINT32_C(0xB960FFF6), UINT32_C(0x660354BB),
10869           UINT32_C(0xFD6B4C3E), UINT32_C(0x1C9E95F0), UINT32_C(0xF8ECAADA),
10870           UINT32_C(0xA8E08CC7), UINT32_C(0x687A6D29)},
10871          {UINT32_C(0xC6A83D12), UINT32_C(0xD38B7670), UINT32_C(0x1265BF30),
10872           UINT32_C(0x1646064C), UINT32_C(0x2464892D), UINT32_C(0x7DE19FFE),
10873           UINT32_C(0x1BDBB729), UINT32_C(0x05B57E08)}},
10874         {{UINT32_C(0xFFB7A98A), UINT32_C(0xF3586B04), UINT32_C(0xCB072826),
10875           UINT32_C(0xF1850CDC), UINT32_C(0xCF53BFB0), UINT32_C(0xFA3E66A4),
10876           UINT32_C(0x06E07221), UINT32_C(0x7C78E567)},
10877          {UINT32_C(0x3B4E72AE), UINT32_C(0x21E6F245), UINT32_C(0xC6A3DBE8),
10878           UINT32_C(0x10A0D78B), UINT32_C(0xD618DDAB), UINT32_C(0xB9FC6D77),
10879           UINT32_C(0x76951DE5), UINT32_C(0x33092D13)}},
10880         {{UINT32_C(0x5A0257CB), UINT32_C(0xCAA1BF9D), UINT32_C(0x866C505F),
10881           UINT32_C(0x1044E224), UINT32_C(0x81482E7D), UINT32_C(0x9B514107),
10882           UINT32_C(0x88940BFB), UINT32_C(0x538CB867)},
10883          {UINT32_C(0xAC21DCC1), UINT32_C(0xACE68B78), UINT32_C(0x1609BF8C),
10884           UINT32_C(0x57942F3C), UINT32_C(0x66E48C7A), UINT32_C(0x30A47F32),
10885           UINT32_C(0xB0DA341F), UINT32_C(0x170D301D)}},
10886         {{UINT32_C(0x18ED9863), UINT32_C(0x19643EB2), UINT32_C(0xD9104F33),
10887           UINT32_C(0xBBE55BCC), UINT32_C(0xA15B283C), UINT32_C(0x77008B6C),
10888           UINT32_C(0x873A6A02), UINT32_C(0x2A6E0B41)},
10889          {UINT32_C(0x3CB9A225), UINT32_C(0x517410DF), UINT32_C(0xF538730A),
10890           UINT32_C(0x20D76E38), UINT32_C(0x9F8724F0), UINT32_C(0x76C9CAD6),
10891           UINT32_C(0x6BE9A035), UINT32_C(0x588BA106)}},
10892         {{UINT32_C(0xF842F66C), UINT32_C(0xA059DBEC), UINT32_C(0xB3ED0481),
10893           UINT32_C(0x59CA186D), UINT32_C(0xD454490F), UINT32_C(0xA5B2ABCB),
10894           UINT32_C(0x02624902), UINT32_C(0x4A0F6004)},
10895          {UINT32_C(0x4D2F605F), UINT32_C(0x45AF7B51), UINT32_C(0xC368030F),
10896           UINT32_C(0x57E8FE0F), UINT32_C(0x0C0727AE), UINT32_C(0x23B74557),
10897           UINT32_C(0x2B603EC4), UINT32_C(0x7E91EC77)}},
10898         {{UINT32_C(0xFD582BE8), UINT32_C(0xEDD284CF), UINT32_C(0x81093CDA),
10899           UINT32_C(0x3077CB23), UINT32_C(0xFDEA4FCE), UINT32_C(0xB1934840),
10900           UINT32_C(0xD7F01C9A), UINT32_C(0x00F9B9D1)},
10901          {UINT32_C(0x0A1C707B), UINT32_C(0xA55E5C5B), UINT32_C(0x2F8618A5),
10902           UINT32_C(0x05CD73CB), UINT32_C(0x512EEA05), UINT32_C(0x7327CECB),
10903           UINT32_C(0x8BF2A4D5), UINT32_C(0x5130A099)}},
10904         {{UINT32_C(0xFA7A1C7B), UINT32_C(0x34D18880), UINT32_C(0xFD4E043F),
10905           UINT32_C(0x5E0D6C53), UINT32_C(0x1B4442AE), UINT32_C(0xB4DD8010),
10906           UINT32_C(0x78ED7563), UINT32_C(0x59D9183E)},
10907          {UINT32_C(0xF1FAE158), UINT32_C(0x624DDAFC), UINT32_C(0x5C4C1E92),
10908           UINT32_C(0xC08C3653), UINT32_C(0xCE3E42EF), UINT32_C(0x452FD71F),
10909           UINT32_C(0x20B902EC), UINT32_C(0x175B4908)}},
10910         {{UINT32_C(0x18F4CE34), UINT32_C(0x5F0FDF24), UINT32_C(0x9B7E61B8),
10911           UINT32_C(0xA64A3011), UINT32_C(0x663362E2), UINT32_C(0x8109ACD5),
10912           UINT32_C(0x97F3DF44), UINT32_C(0x4D02F824)},
10913          {UINT32_C(0x3A4F916A), UINT32_C(0x2CE27CCE), UINT32_C(0x3B85B146),
10914           UINT32_C(0x4A4E6CBB), UINT32_C(0xDB8C9E5E), UINT32_C(0xFE7A6199),
10915           UINT32_C(0xD94B8D23), UINT32_C(0x53F5D620)}},
10916         {{UINT32_C(0xE77610A9), UINT32_C(0x37FEBEC3), UINT32_C(0x92245CB0),
10917           UINT32_C(0xE82D8EAC), UINT32_C(0xF79A31BC), UINT32_C(0x3FD2CEEA),
10918           UINT32_C(0xB446850C), UINT32_C(0x277ACF32)},
10919          {UINT32_C(0xCE1A2786), UINT32_C(0xD89FF4C7), UINT32_C(0xFFD3A23C),
10920           UINT32_C(0x441781E5), UINT32_C(0x07E85496), UINT32_C(0x7876EFC5),
10921           UINT32_C(0xE6F41B30), UINT32_C(0x0F306C7B)}},
10922         {{UINT32_C(0x5AB1B92B), UINT32_C(0x3BF2BFD1), UINT32_C(0xF373FCF2),
10923           UINT32_C(0xDCC3F5A6), UINT32_C(0xDA53C229), UINT32_C(0x27CFC4A6),
10924           UINT32_C(0x508E677F), UINT32_C(0x5885737C)},
10925          {UINT32_C(0x7B829F24), UINT32_C(0x1275D0F1), UINT32_C(0x4991B75B),
10926           UINT32_C(0xBD3C0B02), UINT32_C(0xE581C569), UINT32_C(0x3F82ACDF),
10927           UINT32_C(0x3F28904E), UINT32_C(0x12329435)}},
10928         {{UINT32_C(0x99C3A09B), UINT32_C(0xCF7BDCCC), UINT32_C(0x5F7D601A),
10929           UINT32_C(0x19191107), UINT32_C(0x39FBAA22), UINT32_C(0xA82F7460),
10930           UINT32_C(0xD75B5786), UINT32_C(0x3105A6FC)},
10931          {UINT32_C(0x932F69A6), UINT32_C(0x9673DAC4), UINT32_C(0xB57D6EE6),
10932           UINT32_C(0xF5664B25), UINT32_C(0x0A3CDD3E), UINT32_C(0x1EDAC112),
10933           UINT32_C(0x42778563), UINT32_C(0x3CF84F8C)}},
10934     },
10935     {
10936         {{UINT32_C(0x65DE3040), UINT32_C(0xE36FD1B7), UINT32_C(0x8AA0D3FE),
10937           UINT32_C(0x240EADEA), UINT32_C(0x7F77F804), UINT32_C(0x76971431),
10938           UINT32_C(0x591E9694), UINT32_C(0x6FCC933E)},
10939          {UINT32_C(0x18F48742), UINT32_C(0x3218D92B), UINT32_C(0x5E1B4001),
10940           UINT32_C(0x215F13E9), UINT32_C(0x7A8D69B9), UINT32_C(0xCDF333CD),
10941           UINT32_C(0xD2FD134F), UINT32_C(0x14F159B1)}},
10942         {{UINT32_C(0x07A50C16), UINT32_C(0x2D1228D6), UINT32_C(0x29AE42FD),
10943           UINT32_C(0x0DFD80F6), UINT32_C(0xBB8F3512), UINT32_C(0x6C18B122),
10944           UINT32_C(0x303F3DCA), UINT32_C(0x0FE61243)},
10945          {UINT32_C(0xDA50709B), UINT32_C(0x43A29F4D), UINT32_C(0x4B92BF7B),
10946           UINT32_C(0x3FF58C08), UINT32_C(0xDFCEF797), UINT32_C(0x62DC6B41),
10947           UINT32_C(0xC7B83F32), UINT32_C(0x43F9525A)}},
10948         {{UINT32_C(0x15F08F5B), UINT32_C(0x17EBBC9A), UINT32_C(0x8BB3E932),
10949           UINT32_C(0xBCD3B640), UINT32_C(0x510BBD36), UINT32_C(0xD46FBB9F),
10950           UINT32_C(0xCF65442B), UINT32_C(0x389ABBA8)},
10951          {UINT32_C(0xB575545C), UINT32_C(0x3A3DAFE4), UINT32_C(0xE1D0994D),
10952           UINT32_C(0x6AB985EC), UINT32_C(0x69E1DB27), UINT32_C(0xCC2A697B),
10953           UINT32_C(0x271581DC), UINT32_C(0x0D483E18)}},
10954         {{UINT32_C(0xC046D968), UINT32_C(0x380D4095), UINT32_C(0x55D3318B),
10955           UINT32_C(0x53039755), UINT32_C(0x91CE6FFC), UINT32_C(0x57FA7629),
10956           UINT32_C(0xA4ADB641), UINT32_C(0x0A0F2885)},
10957          {UINT32_C(0x6E5C2909), UINT32_C(0x8B99AF1B), UINT32_C(0xB8794175),
10958           UINT32_C(0xBDFE7FFD), UINT32_C(0x795ED786), UINT32_C(0x2CFB948A),
10959           UINT32_C(0x0FD0DF66), UINT32_C(0x11FE7465)}},
10960         {{UINT32_C(0x22E152E2), UINT32_C(0xFC2CC2BD), UINT32_C(0xE30BCEB3),
10961           UINT32_C(0xCF6AB96B), UINT32_C(0xBC89B689), UINT32_C(0xAE89C041),
10962           UINT32_C(0xE7523AB6), UINT32_C(0x6813430C)},
10963          {UINT32_C(0x40A4FA33), UINT32_C(0x3F49E728), UINT32_C(0x857CB0C9),
10964           UINT32_C(0x025DE1B7), UINT32_C(0x11EA5EA5), UINT32_C(0x6D71465A),
10965           UINT32_C(0x46C8D7CB), UINT32_C(0x6651F7B9)}},
10966         {{UINT32_C(0x5268098F), UINT32_C(0xD05F1DCE), UINT32_C(0x0DC75030),
10967           UINT32_C(0x891DBB68), UINT32_C(0xEA916291), UINT32_C(0xD939E428),
10968           UINT32_C(0xEA37D060), UINT32_C(0x5F8EECCC)},
10969          {UINT32_C(0x8DC5D544), UINT32_C(0x885F1EA8), UINT32_C(0x57E7448F),
10970           UINT32_C(0xFD3B3D17), UINT32_C(0x79531DE0), UINT32_C(0x5FC791A8),
10971           UINT32_C(0x42E66DAA), UINT32_C(0x780C1AAF)}},
10972         {{UINT32_C(0x397BB28F), UINT32_C(0x19697778), UINT32_C(0xAAA9069D),
10973           UINT32_C(0x5EC31D44), UINT32_C(0x3CA24A6F), UINT32_C(0xDC2DFEAA),
10974           UINT32_C(0x80BED770), UINT32_C(0x3F66CFCA)},
10975          {UINT32_C(0x1A102662), UINT32_C(0x2B6B8215), UINT32_C(0xC5D34CEB),
10976           UINT32_C(0x44B4D7A4), UINT32_C(0x88AFECF2), UINT32_C(0x17E0FDE6),
10977           UINT32_C(0xCFF8D214), UINT32_C(0x0DEFA14B)}},
10978         {{UINT32_C(0x8365CA84), UINT32_C(0x14035AA4), UINT32_C(0x197CE2B7),
10979           UINT32_C(0x309CEEF0), UINT32_C(0xED39AF37), UINT32_C(0x21305426),
10980           UINT32_C(0xD2EA583A), UINT32_C(0x10D01D11)},
10981          {UINT32_C(0x9FA5C766), UINT32_C(0x3F2E9749), UINT32_C(0xD70549D4),
10982           UINT32_C(0x98357584), UINT32_C(0xD279946D), UINT32_C(0x8FF80803),
10983           UINT32_C(0x99DF1253), UINT32_C(0x53DBC433)}},
10984         {{UINT32_C(0x5329F12F), UINT32_C(0x1D0D9EFA), UINT32_C(0xBE1F007F),
10985           UINT32_C(0xBC9F74CF), UINT32_C(0x18EE4DBC), UINT32_C(0xD7F2AA9A),
10986           UINT32_C(0x3A792753), UINT32_C(0x634BF4CF)},
10987          {UINT32_C(0x2FA6255A), UINT32_C(0xD5DC72AD), UINT32_C(0xF3BC00C5),
10988           UINT32_C(0xEE69EA43), UINT32_C(0xD8147A1A), UINT32_C(0xEA930F61),
10989           UINT32_C(0xF4E9AD37), UINT32_C(0x25E1368D)}},
10990         {{UINT32_C(0xB7C955EC), UINT32_C(0x9422AAF7), UINT32_C(0x6A74D634),
10991           UINT32_C(0x7C710761), UINT32_C(0x305EE420), UINT32_C(0x4ED89932),
10992           UINT32_C(0x2E937289), UINT32_C(0x07E42212)},
10993          {UINT32_C(0x28566C88), UINT32_C(0x7EBB2313), UINT32_C(0xC27ED656),
10994           UINT32_C(0xC7ED9C7A), UINT32_C(0xBF14FB3B), UINT32_C(0xF77F3873),
10995           UINT32_C(0xEB957520), UINT32_C(0x447AA1E5)}},
10996         {{UINT32_C(0xB5C5E016), UINT32_C(0x3E3CEC7E), UINT32_C(0xBDE44D26),
10997           UINT32_C(0xB33DDFF7), UINT32_C(0x66E820DD), UINT32_C(0x2056E9C7),
10998           UINT32_C(0xF8196FE2), UINT32_C(0x21A9E5D4)},
10999          {UINT32_C(0x88040C97), UINT32_C(0x86CB0A17), UINT32_C(0xFF515D49),
11000           UINT32_C(0x18AD8AE7), UINT32_C(0x226A400A), UINT32_C(0xCB8A564A),
11001           UINT32_C(0x8B72A0D2), UINT32_C(0x6DB48979)}},
11002         {{UINT32_C(0x6324DED2), UINT32_C(0x4365074B), UINT32_C(0xAEDAF0F8),
11003           UINT32_C(0x9EFB5CC6), UINT32_C(0xC0792B14), UINT32_C(0xCF952C3C),
11004           UINT32_C(0x97ED965E), UINT32_C(0x70B82AB9)},
11005          {UINT32_C(0x3ACEBCE7), UINT32_C(0x931B9886), UINT32_C(0x18C2425A),
11006           UINT32_C(0xDA850491), UINT32_C(0xE499F7FB), UINT32_C(0xD88E1E27),
11007           UINT32_C(0x960981DE), UINT32_C(0x61D3F246)}},
11008         {{UINT32_C(0x8393EB0A), UINT32_C(0x1D8EA227), UINT32_C(0x7863FB53),
11009           UINT32_C(0x9DCC23D2), UINT32_C(0xD5EBD297), UINT32_C(0x961B2337),
11010           UINT32_C(0x5BFED1E9), UINT32_C(0x0A96F8B2)},
11011          {UINT32_C(0xFE7DD2B7), UINT32_C(0x39EA1803), UINT32_C(0xE5F7772A),
11012           UINT32_C(0x7E4817BB), UINT32_C(0xD44A41EF), UINT32_C(0x3668C5FF),
11013           UINT32_C(0xE11F8E11), UINT32_C(0x78227653)}},
11014         {{UINT32_C(0xD024880B), UINT32_C(0x272D6933), UINT32_C(0xF236FD8A),
11015           UINT32_C(0x733C029F), UINT32_C(0x604868F0), UINT32_C(0xBA5C20BD),
11016           UINT32_C(0x321175C2), UINT32_C(0x33F211AE)},
11017          {UINT32_C(0x9FD79FE3), UINT32_C(0xE40010FB), UINT32_C(0xA685A59F),
11018           UINT32_C(0x9C6EA1DC), UINT32_C(0x8EB9889D), UINT32_C(0x79963FFC),
11019           UINT32_C(0x5F67108D), UINT32_C(0x15434E7D)}},
11020         {{UINT32_C(0xD68B670F), UINT32_C(0x42C14BBF), UINT32_C(0x23F1AA69),
11021           UINT32_C(0x2021AC9D), UINT32_C(0xAEA04636), UINT32_C(0xBF4C6D74),
11022           UINT32_C(0xBD1FB11D), UINT32_C(0x1E4D2F8E)},
11023          {UINT32_C(0x37911AA6), UINT32_C(0x4B0CF0E3), UINT32_C(0x2C484507),
11024           UINT32_C(0x7542D928), UINT32_C(0x889542DC), UINT32_C(0x68836751),
11025           UINT32_C(0xFE2282A0), UINT32_C(0x05F229F7)}},
11026         {{UINT32_C(0x409B2067), UINT32_C(0xAF269E8B), UINT32_C(0xA860F075),
11027           UINT32_C(0x6C749952), UINT32_C(0x5DF7C7F6), UINT32_C(0xCB7492DA),
11028           UINT32_C(0xE8E591E1), UINT32_C(0x2B010A7F)},
11029          {UINT32_C(0x04D9E871), UINT32_C(0xF7446577), UINT32_C(0x5E68408E),
11030           UINT32_C(0xC2E0A2A3), UINT32_C(0xD0F0BAAD), UINT32_C(0xD512E9A6),
11031           UINT32_C(0xC6BE34A3), UINT32_C(0x3E2F73E1)}},
11032     },
11033     {
11034         {{UINT32_C(0x2EC65BB4), UINT32_C(0x6C466C8E), UINT32_C(0xB1FC8F92),
11035           UINT32_C(0x912FFAE5), UINT32_C(0xB50A522D), UINT32_C(0x7587BE5D),
11036           UINT32_C(0x649847CF), UINT32_C(0x15939FF7)},
11037          {UINT32_C(0xF464794E), UINT32_C(0x69E81D63), UINT32_C(0x6D3F858E),
11038           UINT32_C(0x7BB6EEE3), UINT32_C(0x10813BBB), UINT32_C(0x24FE5C01),
11039           UINT32_C(0x6D80756C), UINT32_C(0x0C491F97)}},
11040         {{UINT32_C(0xA5FF3510), UINT32_C(0xBAD1C256), UINT32_C(0x99C1B7B2),
11041           UINT32_C(0xF06F38A2), UINT32_C(0x049312D6), UINT32_C(0xF7C0F164),
11042           UINT32_C(0x5749B3E4), UINT32_C(0x073C5374)},
11043          {UINT32_C(0x55211A81), UINT32_C(0xD6761480), UINT32_C(0xDFA98F45),
11044           UINT32_C(0xF34CB5DB), UINT32_C(0xB4AA4967), UINT32_C(0xAF59FA47),
11045           UINT32_C(0x8214BE48), UINT32_C(0x116935B9)}},
11046         {{UINT32_C(0x9FE10E46), UINT32_C(0x1D86FA00), UINT32_C(0x0B5B8494),
11047           UINT32_C(0x73B8099C), UINT32_C(0xA1102BE7), UINT32_C(0x9A6EA98D),
11048           UINT32_C(0x5514CA21), UINT32_C(0x3DE1948B)},
11049          {UINT32_C(0xD0AAAA53), UINT32_C(0x5D18ED69), UINT32_C(0x3C952B98),
11050           UINT32_C(0x17BF7DFF), UINT32_C(0x7DDBD937), UINT32_C(0xC60143FE),
11051           UINT32_C(0x6F2F10C4), UINT32_C(0x214F2F55)}},
11052         {{UINT32_C(0x02F047D0), UINT32_C(0xB2F28695), UINT32_C(0x923F52BF),
11053           UINT32_C(0x80952DFE), UINT32_C(0xA5017C3E), UINT32_C(0x56F3306B),
11054           UINT32_C(0x052DADFB), UINT32_C(0x5DD62F07)},
11055          {UINT32_C(0xD5274F90), UINT32_C(0xDD11592D), UINT32_C(0xE471965B),
11056           UINT32_C(0x40632FF3), UINT32_C(0x7E618430), UINT32_C(0xAD1939A8),
11057           UINT32_C(0x33F19556), UINT32_C(0x5DD9CAD2)}},
11058         {{UINT32_C(0xC1094747), UINT32_C(0x7B0AA88C), UINT32_C(0xF6753A0C),
11059           UINT32_C(0xCFA6B95D), UINT32_C(0x2A252A4D), UINT32_C(0xE81AFADA),
11060           UINT32_C(0xD3770570), UINT32_C(0x364CAB7C)},
11061          {UINT32_C(0xB4610A19), UINT32_C(0xE99D8252), UINT32_C(0x55ED9AD3),
11062           UINT32_C(0xB22B2FEC), UINT32_C(0xBEBE7FED), UINT32_C(0x328ACBDD),
11063           UINT32_C(0xFBEDFE84), UINT32_C(0x1D379D61)}},
11064         {{UINT32_C(0x5EDF8C9C), UINT32_C(0xD9EFFFFA), UINT32_C(0x0CE548EC),
11065           UINT32_C(0x9BAA7181), UINT32_C(0x5FA8FEEB), UINT32_C(0xEB458AEB),
11066           UINT32_C(0x0904D841), UINT32_C(0x18C5E691)},
11067          {UINT32_C(0x8F33D2E5), UINT32_C(0xFCEFAE28), UINT32_C(0x6FAFDA18),
11068           UINT32_C(0xB3CF853E), UINT32_C(0x427D6218), UINT32_C(0x05DE94BA),
11069           UINT32_C(0x3731D3E9), UINT32_C(0x021D8AED)}},
11070         {{UINT32_C(0xE92719DA), UINT32_C(0x06C8C318), UINT32_C(0x1A65DFDB),
11071           UINT32_C(0x1F7CDE12), UINT32_C(0x4B672A2D), UINT32_C(0x9B4D531E),
11072           UINT32_C(0x115FAF11), UINT32_C(0x3E39CC63)},
11073          {UINT32_C(0x0037AF60), UINT32_C(0xC9C3F339), UINT32_C(0x02B43D27),
11074           UINT32_C(0xC1C67587), UINT32_C(0xC42DF26B), UINT32_C(0x46B77CDD),
11075           UINT32_C(0xEBFA97A7), UINT32_C(0x7235F2B0)}},
11076         {{UINT32_C(0xE898094E), UINT32_C(0xAF7FFC9A), UINT32_C(0x146A27E3),
11077           UINT32_C(0x8D18AB93), UINT32_C(0x8AEC0416), UINT32_C(0x1376B797),
11078           UINT32_C(0x8D91C25E), UINT32_C(0x746A1B1C)},
11079          {UINT32_C(0x0EBDE2E3), UINT32_C(0x16DCCCC1), UINT32_C(0x8CE7D61E),
11080           UINT32_C(0xFE4ABD41), UINT32_C(0xE25F1551), UINT32_C(0xB9830395),
11081           UINT32_C(0xB885A943), UINT32_C(0x543493D7)}},
11082         {{UINT32_C(0x24EBCFC0), UINT32_C(0x52C659E6), UINT32_C(0xD38367A4),
11083           UINT32_C(0x72E3CA91), UINT32_C(0x4D168F4F), UINT32_C(0xA3086AAC),
11084           UINT32_C(0x5D64207B), UINT32_C(0x656ACFEE)},
11085          {UINT32_C(0xBA196A9E), UINT32_C(0xBE697CBA), UINT32_C(0x97DFFEC2),
11086           UINT32_C(0x6A737ACC), UINT32_C(0x54F04DBD), UINT32_C(0x393E2661),
11087           UINT32_C(0x4B0E92BD), UINT32_C(0x4FFF7C24)}},
11088         {{UINT32_C(0x828EC659), UINT32_C(0xC709CC59), UINT32_C(0xCBDEACB3),
11089           UINT32_C(0xB275AC8C), UINT32_C(0xF7922523), UINT32_C(0xA8D08921),
11090           UINT32_C(0x400A6459), UINT32_C(0x68B92F96)},
11091          {UINT32_C(0xDFBECB97), UINT32_C(0x45803EC2), UINT32_C(0x7515D696),
11092           UINT32_C(0x49464E05), UINT32_C(0x8F03E969), UINT32_C(0xF39CA961),
11093           UINT32_C(0x1CD7C79F), UINT32_C(0x605065A1)}},
11094         {{UINT32_C(0x97F1A97A), UINT32_C(0xB91C03DC), UINT32_C(0x201FFB53),
11095           UINT32_C(0x2F6D50BB), UINT32_C(0x46241856), UINT32_C(0x39D67D40),
11096           UINT32_C(0x74D04805), UINT32_C(0x0A2C0256)},
11097          {UINT32_C(0x28374A6D), UINT32_C(0xD289B94C), UINT32_C(0x10EDD6FC),
11098           UINT32_C(0x1176C73A), UINT32_C(0x56AE631E), UINT32_C(0x890E9C39),
11099           UINT32_C(0x6027F549), UINT32_C(0x30451CF1)}},
11100         {{UINT32_C(0xDF8F4DDB), UINT32_C(0x0CB33FDC), UINT32_C(0x87FF6E63),
11101           UINT32_C(0xD9C540DE), UINT32_C(0x55A1D8E4), UINT32_C(0xD8445732),
11102           UINT32_C(0x8AC403A6), UINT32_C(0x1497403D)},
11103          {UINT32_C(0x6A4BAAC6), UINT32_C(0xA2591C40), UINT32_C(0x48DD3E5D),
11104           UINT32_C(0xF493CF1F), UINT32_C(0xB69AF047), UINT32_C(0x7B9AE39F),
11105           UINT32_C(0x3782B110), UINT32_C(0x293123C0)}},
11106         {{UINT32_C(0xB7A36B62), UINT32_C(0x14921836), UINT32_C(0x4CA3AA39),
11107           UINT32_C(0x5AC82430), UINT32_C(0x52F601CA), UINT32_C(0x01303AA6),
11108           UINT32_C(0x2B43BB72), UINT32_C(0x7EE1E6C7)},
11109          {UINT32_C(0x64D44957), UINT32_C(0x7F82B37B), UINT32_C(0xDA4A6FEC),
11110           UINT32_C(0x840D0654), UINT32_C(0x0290F75D), UINT32_C(0xFC806FA1),
11111           UINT32_C(0x4C62F0E8), UINT32_C(0x3027FE4A)}},
11112         {{UINT32_C(0xCD0D3AC0), UINT32_C(0x34E68AB5), UINT32_C(0xE9BC85BD),
11113           UINT32_C(0xE6B0B8C1), UINT32_C(0x99533831), UINT32_C(0xE00F5052),
11114           UINT32_C(0xCDC83750), UINT32_C(0x11327DA7)},
11115          {UINT32_C(0x4656A428), UINT32_C(0x6D991DF0), UINT32_C(0x86228F26),
11116           UINT32_C(0x6A7BE349), UINT32_C(0x3019CDC5), UINT32_C(0x6BF85E3D),
11117           UINT32_C(0x576913A4), UINT32_C(0x42200D2F)}},
11118         {{UINT32_C(0x707B940F), UINT32_C(0x420D9259), UINT32_C(0x3C5E39BB),
11119           UINT32_C(0x1BB1FFE1), UINT32_C(0xE40D018E), UINT32_C(0x83D6BA36),
11120           UINT32_C(0x044EC576), UINT32_C(0x139BD842)},
11121          {UINT32_C(0xC6DE63E8), UINT32_C(0x3C79F8D2), UINT32_C(0x96F1FB0B),
11122           UINT32_C(0x49150B1D), UINT32_C(0x1358A13B), UINT32_C(0x66616053),
11123           UINT32_C(0xD5DDFD9F), UINT32_C(0x187CA3CF)}},
11124         {{UINT32_C(0x8D5AEE84), UINT32_C(0x0675370F), UINT32_C(0xDC269114),
11125           UINT32_C(0x30AA7D65), UINT32_C(0x5AFC6DC1), UINT32_C(0x295F7FE8),
11126           UINT32_C(0x55674339), UINT32_C(0x49452029)},
11127          {UINT32_C(0xA6F209EC), UINT32_C(0x7EB1926B), UINT32_C(0xDC72C3E3),
11128           UINT32_C(0x5232B9D1), UINT32_C(0xAB52141B), UINT32_C(0xCD788D79),
11129           UINT32_C(0xFDD9611F), UINT32_C(0x3EB561BE)}},
11130     },
11131     {
11132         {{UINT32_C(0xE22241AD), UINT32_C(0x09DB342C), UINT32_C(0x2A566653),
11133           UINT32_C(0x2EAB852F), UINT32_C(0xCA6E59F3), UINT32_C(0x970843ED),
11134           UINT32_C(0xA18C2D89), UINT32_C(0x6490013E)},
11135          {UINT32_C(0xC7A691CC), UINT32_C(0x52293350), UINT32_C(0xB2079F14),
11136           UINT32_C(0x6544B49D), UINT32_C(0x52DCF090), UINT32_C(0xC49C5598),
11137           UINT32_C(0x8817A2C7), UINT32_C(0x4069B6FC)}},
11138         {{UINT32_C(0xC86B40F4), UINT32_C(0x0E4A4B0C), UINT32_C(0x51F6F853),
11139           UINT32_C(0x2B5350E1), UINT32_C(0x1033BEC4), UINT32_C(0xDE26FDE2),
11140           UINT32_C(0xC0E9B971), UINT32_C(0x4DE9D2E7)},
11141          {UINT32_C(0xD315AD57), UINT32_C(0x716605FD), UINT32_C(0x392B101A),
11142           UINT32_C(0x5627D732), UINT32_C(0x81A9F40A), UINT32_C(0x628EDFC6),
11143           UINT32_C(0x5AB9C99D), UINT32_C(0x4BD2A96C)}},
11144         {{UINT32_C(0xBFBD288A), UINT32_C(0x2C8DF2A1), UINT32_C(0xF4CF7C09),
11145           UINT32_C(0x260C4F1E), UINT32_C(0x90E796CB), UINT32_C(0x88A26186),
11146           UINT32_C(0x323E0702), UINT32_C(0x105ACC3A)},
11147          {UINT32_C(0x667664CF), UINT32_C(0xA8ADA467), UINT32_C(0x3B518622),
11148           UINT32_C(0x41144C1B), UINT32_C(0xD8B99FE1), UINT32_C(0x4A532B87),
11149           UINT32_C(0x2289C308), UINT32_C(0x4A51C289)}},
11150         {{UINT32_C(0x1D6F6880), UINT32_C(0x201DDA61), UINT32_C(0x62029898),
11151           UINT32_C(0x47A964D4), UINT32_C(0x426C8CA5), UINT32_C(0xE44E2EEE),
11152           UINT32_C(0x09625DBA), UINT32_C(0x02A51821)},
11153          {UINT32_C(0xB45B3DFB), UINT32_C(0x170C626E), UINT32_C(0x5C8343A9),
11154           UINT32_C(0xFC7F1F71), UINT32_C(0xE549F040), UINT32_C(0xE6CF246F),
11155           UINT32_C(0x2F903ACE), UINT32_C(0x4ACF60AE)}},
11156         {{UINT32_C(0x81C807EC), UINT32_C(0x91715352), UINT32_C(0x47174A58),
11157           UINT32_C(0x72AC60C3), UINT32_C(0xA0F12F61), UINT32_C(0xAD62D06F),
11158           UINT32_C(0xAA899C0D), UINT32_C(0x325C2792)},
11159          {UINT32_C(0x9D8BA267), UINT32_C(0x53A1E392), UINT32_C(0xCDACCB05),
11160           UINT32_C(0x5DC088A5), UINT32_C(0x5025CB69), UINT32_C(0x5BB9127F),
11161           UINT32_C(0x69214616), UINT32_C(0x25D2B42E)}},
11162         {{UINT32_C(0xDDB55121), UINT32_C(0x4DE5D58A), UINT32_C(0x84DE0677),
11163           UINT32_C(0x688AA2F5), UINT32_C(0x63AA25E0), UINT32_C(0xF7925A39),
11164           UINT32_C(0x85D4DEA5), UINT32_C(0x4FB42FC7)},
11165          {UINT32_C(0x8F134390), UINT32_C(0x957B933B), UINT32_C(0x4B9BF8C2),
11166           UINT32_C(0xB360DD2C), UINT32_C(0xFFFF96CD), UINT32_C(0x45E6767F),
11167           UINT32_C(0x1E01D5C3), UINT32_C(0x26D0A6A9)}},
11168         {{UINT32_C(0x5A0A98EA), UINT32_C(0xC7FC5714), UINT32_C(0xE7535AF6),
11169           UINT32_C(0xDBB06F30), UINT32_C(0xDF4ACD0D), UINT32_C(0x555B22E3),
11170           UINT32_C(0x2EFD2FBE), UINT32_C(0x3A011AAF)},
11171          {UINT32_C(0xE9166B20), UINT32_C(0x341C7733), UINT32_C(0xFB19590A),
11172           UINT32_C(0x84619E8E), UINT32_C(0x10574C96), UINT32_C(0x8EF989FD),
11173           UINT32_C(0x0F55F9A2), UINT32_C(0x61ACFAAE)}},
11174         {{UINT32_C(0x6DEAB094), UINT32_C(0x8C8A33F2), UINT32_C(0x96022EBC),
11175           UINT32_C(0x4A8E5D9F), UINT32_C(0x7DDA92E8), UINT32_C(0xA10DF82C),
11176           UINT32_C(0xD1CF3815), UINT32_C(0x33A19462)},
11177          {UINT32_C(0xA489D67F), UINT32_C(0xE3FF8E43), UINT32_C(0x225064AA),
11178           UINT32_C(0xD4B6136F), UINT32_C(0x92F5E662), UINT32_C(0xE1721D2A),
11179           UINT32_C(0xA90A33C6), UINT32_C(0x4C4F03D7)}},
11180         {{UINT32_C(0xA3463B4A), UINT32_C(0x70885B35), UINT32_C(0xDF9D0194),
11181           UINT32_C(0x974BC40E), UINT32_C(0x273957F4), UINT32_C(0x1AF71E18),
11182           UINT32_C(0x9900CB0D), UINT32_C(0x58EF684B)},
11183          {UINT32_C(0x20A49A4A), UINT32_C(0xB09970C8), UINT32_C(0x42067458),
11184           UINT32_C(0x3F28403F), UINT32_C(0xBD7D1AD5), UINT32_C(0x153FF2C4),
11185           UINT32_C(0xE97A90F7), UINT32_C(0x7912CC2E)}},
11186         {{UINT32_C(0x8F034D9F), UINT32_C(0xF653DF59), UINT32_C(0x1C409CCF),
11187           UINT32_C(0xCA167177), UINT32_C(0x175F3583), UINT32_C(0x21F47005),
11188           UINT32_C(0xFAAFB66F), UINT32_C(0x13B8A94B)},
11189          {UINT32_C(0x96052C8D), UINT32_C(0x64534EE3), UINT32_C(0x8D674024),
11190           UINT32_C(0x09304DD1), UINT32_C(0x0D7A7E2A), UINT32_C(0xEB468AC3),
11191           UINT32_C(0xCD62052C), UINT32_C(0x40347256)}},
11192         {{UINT32_C(0xFFF11C0E), UINT32_C(0x0F089165), UINT32_C(0x8D69A45C),
11193           UINT32_C(0x383562C9), UINT32_C(0x3125FE61), UINT32_C(0x7AB3EF9D),
11194           UINT32_C(0xE0735F3A), UINT32_C(0x32C042BC)},
11195          {UINT32_C(0x4E268D91), UINT32_C(0x420077C8), UINT32_C(0x44695B4F),
11196           UINT32_C(0x7FB42082), UINT32_C(0x448A133E), UINT32_C(0xFA83216F),
11197           UINT32_C(0x93062EB3), UINT32_C(0x1C660607)}},
11198         {{UINT32_C(0xEF9E04DE), UINT32_C(0xA0FCBACA), UINT32_C(0x5B86F69A),
11199           UINT32_C(0xAEF9EECB), UINT32_C(0xC39D4C99), UINT32_C(0x73D2E95F),
11200           UINT32_C(0x923A5BA8), UINT32_C(0x098C74F7)},
11201          {UINT32_C(0x4F68DECF), UINT32_C(0x5B8C95C8), UINT32_C(0x58976551),
11202           UINT32_C(0xCFF2E101), UINT32_C(0xBE5CAF91), UINT32_C(0x5032AE48),
11203           UINT32_C(0xE09BC8AE), UINT32_C(0x5CCB9008)}},
11204         {{UINT32_C(0x3714D3BF), UINT32_C(0x41A38F20), UINT32_C(0x17366520),
11205           UINT32_C(0x24136533), UINT32_C(0xFAE17B01), UINT32_C(0xF12F314C),
11206           UINT32_C(0xFC9AD43B), UINT32_C(0x4AA0C969)},
11207          {UINT32_C(0x8BBAC026), UINT32_C(0xD8AB5F72), UINT32_C(0x526992DC),
11208           UINT32_C(0x35128269), UINT32_C(0xD19880AA), UINT32_C(0xA2EF6E44),
11209           UINT32_C(0xDBF47628), UINT32_C(0x28BB3623)}},
11210         {{UINT32_C(0x3BA25C35), UINT32_C(0x294742BA), UINT32_C(0x061555B7),
11211           UINT32_C(0x39D3BC9B), UINT32_C(0xDE6EA1A0), UINT32_C(0x944E3ABC),
11212           UINT32_C(0x57EBD394), UINT32_C(0x4FDC6415)},
11213          {UINT32_C(0xE981E649), UINT32_C(0xB615C1DA), UINT32_C(0x8BE3C95F),
11214           UINT32_C(0xAF7EDB34), UINT32_C(0x71F7221F), UINT32_C(0x38573AE8),
11215           UINT32_C(0x668CF414), UINT32_C(0x1B30FF04)}},
11216         {{UINT32_C(0xA57A9A4E), UINT32_C(0x48EFF6A2), UINT32_C(0x74A59C19),
11217           UINT32_C(0x04BA2F73), UINT32_C(0x6779C5DA), UINT32_C(0x5FDE389D),
11218           UINT32_C(0x6612F160), UINT32_C(0x258E2B24)},
11219          {UINT32_C(0x6D116D41), UINT32_C(0xCE8D7A0B), UINT32_C(0xEE2706C8),
11220           UINT32_C(0xAF660436), UINT32_C(0xF81D6398), UINT32_C(0xFFAD6FE9),
11221           UINT32_C(0x14BA128A), UINT32_C(0x4FE5EC54)}},
11222         {{UINT32_C(0xBD4B886C), UINT32_C(0x7D5E8299), UINT32_C(0xDB0DB148),
11223           UINT32_C(0x5403A46E), UINT32_C(0x76A808D7), UINT32_C(0x32F49FC0),
11224           UINT32_C(0xD3B9A641), UINT32_C(0x6D483FD7)},
11225          {UINT32_C(0x3952C70F), UINT32_C(0x731DF122), UINT32_C(0xCB5E6081),
11226           UINT32_C(0xB5CABAC1), UINT32_C(0x7AFA8F59), UINT32_C(0x12FA297D),
11227           UINT32_C(0x6AC91952), UINT32_C(0x3272360A)}},
11228     }};
11229
11230 /*-
11231  * Q := 2P, both projective, Q and P same pointers OK
11232  * Autogenerated: op3/dbl_proj.op3
11233  * https://eprint.iacr.org/2015/1060 Alg 6
11234  * ASSERT: a = -3
11235  */
11236 static void point_double(pt_prj_t *Q, const pt_prj_t *P) {
11237     /* temporary variables */
11238     fe_t t0, t1, t2, t3, t4;
11239     /* constants */
11240     const limb_t *b = const_b;
11241     /* set pointers for legacy curve arith */
11242     const limb_t *X = P->X;
11243     const limb_t *Y = P->Y;
11244     const limb_t *Z = P->Z;
11245     limb_t *X3 = Q->X;
11246     limb_t *Y3 = Q->Y;
11247     limb_t *Z3 = Q->Z;
11248
11249     /* the curve arith formula */
11250     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(t0, X);
11251     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(t1, Y);
11252     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_square(t2, Z);
11253     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t3, X, Y);
11254     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, t3, t3);
11255     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t4, Y, Z);
11256     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, X, Z);
11257     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, Z3);
11258     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, b, t2);
11259     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, Z3);
11260     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, Y3, Y3);
11261     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, X3, Y3);
11262     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, t1, Y3);
11263     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t1, Y3);
11264     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X3, Y3);
11265     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, X3, t3);
11266     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, t2, t2);
11267     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t2, t2, t3);
11268     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, b, Z3);
11269     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, Z3, t2);
11270     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, Z3, t0);
11271     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, Z3, Z3);
11272     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, t3);
11273     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, t0, t0);
11274     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t3, t0);
11275     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t0, t0, t2);
11276     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t0, t0, Z3);
11277     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, t0);
11278     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t4, t4);
11279     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t0, Z3);
11280     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, X3, Z3);
11281     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t0, t1);
11282     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, Z3);
11283     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, Z3);
11284 }
11285
11286 /*-
11287  * R := Q + P where R and Q are projective, P affine.
11288  * R and Q same pointers OK
11289  * R and P same pointers not OK
11290  * Autogenerated: op3/add_mixed.op3
11291  * https://eprint.iacr.org/2015/1060 Alg 5
11292  * ASSERT: a = -3
11293  */
11294 static void point_add_mixed(pt_prj_t *R, const pt_prj_t *Q, const pt_aff_t *P) {
11295     /* temporary variables */
11296     fe_t t0, t1, t2, t3, t4;
11297     /* constants */
11298     const limb_t *b = const_b;
11299     /* set pointers for legacy curve arith */
11300     const limb_t *X1 = Q->X;
11301     const limb_t *Y1 = Q->Y;
11302     const limb_t *Z1 = Q->Z;
11303     const limb_t *X2 = P->X;
11304     const limb_t *Y2 = P->Y;
11305     fe_t X3;
11306     fe_t Y3;
11307     fe_t Z3;
11308     limb_t nz;
11309
11310     /* check P for affine inf */
11311     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_nonzero(&nz, P->Y);
11312
11313     /* the curve arith formula */
11314     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t0, X1, X2);
11315     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, Y1, Y2);
11316     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, X2, Y2);
11317     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, X1, Y1);
11318     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t3, t3, t4);
11319     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, t0, t1);
11320     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t3, t3, t4);
11321     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t4, Y2, Z1);
11322     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, t4, Y1);
11323     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X2, Z1);
11324     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, X1);
11325     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, b, Z1);
11326     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, Y3, Z3);
11327     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, X3, X3);
11328     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, X3, Z3);
11329     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, t1, X3);
11330     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, t1, X3);
11331     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, b, Y3);
11332     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, Z1, Z1);
11333     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t2, t1, Z1);
11334     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t2);
11335     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t0);
11336     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, Y3, Y3);
11337     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t1, Y3);
11338     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, t0, t0);
11339     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t1, t0);
11340     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t0, t0, t2);
11341     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t4, Y3);
11342     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t2, t0, Y3);
11343     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X3, Z3);
11344     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, t2);
11345     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, t3, X3);
11346     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, X3, t1);
11347     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t4, Z3);
11348     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t3, t0);
11349     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, t1);
11350
11351     /* if P is inf, throw all that away and take Q */
11352     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(R->X, nz, Q->X, X3);
11353     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(R->Y, nz, Q->Y, Y3);
11354     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(R->Z, nz, Q->Z, Z3);
11355 }
11356
11357 /*-
11358  * R := Q + P all projective.
11359  * R and Q same pointers OK
11360  * R and P same pointers not OK
11361  * Autogenerated: op3/add_proj.op3
11362  * https://eprint.iacr.org/2015/1060 Alg 4
11363  * ASSERT: a = -3
11364  */
11365 static void point_add_proj(pt_prj_t *R, const pt_prj_t *Q, const pt_prj_t *P) {
11366     /* temporary variables */
11367     fe_t t0, t1, t2, t3, t4, t5;
11368     /* constants */
11369     const limb_t *b = const_b;
11370     /* set pointers for legacy curve arith */
11371     const limb_t *X1 = Q->X;
11372     const limb_t *Y1 = Q->Y;
11373     const limb_t *Z1 = Q->Z;
11374     const limb_t *X2 = P->X;
11375     const limb_t *Y2 = P->Y;
11376     const limb_t *Z2 = P->Z;
11377     limb_t *X3 = R->X;
11378     limb_t *Y3 = R->Y;
11379     limb_t *Z3 = R->Z;
11380
11381     /* the curve arith formula */
11382     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t0, X1, X2);
11383     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, Y1, Y2);
11384     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t2, Z1, Z2);
11385     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t3, X1, Y1);
11386     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, X2, Y2);
11387     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t3, t3, t4);
11388     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, t0, t1);
11389     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t3, t3, t4);
11390     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t4, Y1, Z1);
11391     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t5, Y2, Z2);
11392     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t4, t4, t5);
11393     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t5, t1, t2);
11394     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t4, t4, t5);
11395     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, X1, Z1);
11396     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, X2, Z2);
11397     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, X3, Y3);
11398     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t0, t2);
11399     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, X3, Y3);
11400     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, b, t2);
11401     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, Y3, Z3);
11402     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, X3, X3);
11403     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, X3, Z3);
11404     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Z3, t1, X3);
11405     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(X3, t1, X3);
11406     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, b, Y3);
11407     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, t2, t2);
11408     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t2, t1, t2);
11409     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t2);
11410     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(Y3, Y3, t0);
11411     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, Y3, Y3);
11412     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, t1, Y3);
11413     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t1, t0, t0);
11414     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(t0, t1, t0);
11415     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(t0, t0, t2);
11416     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t4, Y3);
11417     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t2, t0, Y3);
11418     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Y3, X3, Z3);
11419     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Y3, Y3, t2);
11420     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(X3, t3, X3);
11421     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_sub(X3, X3, t1);
11422     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(Z3, t4, Z3);
11423     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(t1, t3, t0);
11424     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_add(Z3, Z3, t1);
11425 }
11426
11427 /* constants */
11428 #define RADIX 5
11429 #define DRADIX (1 << RADIX)
11430 #define DRADIX_WNAF ((DRADIX) << 1)
11431
11432 /*-
11433  * precomp for wnaf scalar multiplication:
11434  * precomp[0] = 1P
11435  * precomp[1] = 3P
11436  * precomp[2] = 5P
11437  * precomp[3] = 7P
11438  * precomp[4] = 9P
11439  * ...
11440  */
11441 static void precomp_wnaf(pt_prj_t precomp[DRADIX / 2], const pt_aff_t *P) {
11442     int i;
11443
11444     fe_copy(precomp[0].X, P->X);
11445     fe_copy(precomp[0].Y, P->Y);
11446     fe_copy(precomp[0].Z, const_one);
11447     point_double(&precomp[DRADIX / 2 - 1], &precomp[0]);
11448
11449     for (i = 1; i < DRADIX / 2; i++)
11450         point_add_proj(&precomp[i], &precomp[DRADIX / 2 - 1], &precomp[i - 1]);
11451 }
11452
11453 /* fetch a scalar bit */
11454 static int scalar_get_bit(const unsigned char in[32], int idx) {
11455     int widx, rshift;
11456
11457     widx = idx >> 3;
11458     rshift = idx & 0x7;
11459
11460     if (idx < 0 || widx >= 32) return 0;
11461
11462     return (in[widx] >> rshift) & 0x1;
11463 }
11464
11465 /*-
11466  * Compute "regular" wnaf representation of a scalar.
11467  * See "Exponent Recoding and Regular Exponentiation Algorithms",
11468  * Tunstall et al., AfricaCrypt 2009, Alg 6.
11469  * It forces an odd scalar and outputs digits in
11470  * {\pm 1, \pm 3, \pm 5, \pm 7, \pm 9, ...}
11471  * i.e. signed odd digits with _no zeroes_ -- that makes it "regular".
11472  */
11473 static void scalar_rwnaf(int8_t out[52], const unsigned char in[32]) {
11474     int i;
11475     int8_t window, d;
11476
11477     window = (in[0] & (DRADIX_WNAF - 1)) | 1;
11478     for (i = 0; i < 51; i++) {
11479         d = (window & (DRADIX_WNAF - 1)) - DRADIX;
11480         out[i] = d;
11481         window = (window - d) >> RADIX;
11482         window += scalar_get_bit(in, (i + 1) * RADIX + 1) << 1;
11483         window += scalar_get_bit(in, (i + 1) * RADIX + 2) << 2;
11484         window += scalar_get_bit(in, (i + 1) * RADIX + 3) << 3;
11485         window += scalar_get_bit(in, (i + 1) * RADIX + 4) << 4;
11486         window += scalar_get_bit(in, (i + 1) * RADIX + 5) << 5;
11487     }
11488     out[i] = window;
11489 }
11490
11491 /*-
11492  * Compute "textbook" wnaf representation of a scalar.
11493  * NB: not constant time
11494  */
11495 static void scalar_wnaf(int8_t out[257], const unsigned char in[32]) {
11496     int i;
11497     int8_t window, d;
11498
11499     window = in[0] & (DRADIX_WNAF - 1);
11500     for (i = 0; i < 257; i++) {
11501         d = 0;
11502         if ((window & 1) && ((d = window & (DRADIX_WNAF - 1)) & DRADIX))
11503             d -= DRADIX_WNAF;
11504         out[i] = d;
11505         window = (window - d) >> 1;
11506         window += scalar_get_bit(in, i + 1 + RADIX) << RADIX;
11507     }
11508 }
11509
11510 /*-
11511  * Simultaneous scalar multiplication: interleaved "textbook" wnaf.
11512  * NB: not constant time
11513  */
11514 static void var_smul_wnaf_two(pt_aff_t *out, const unsigned char a[32],
11515                               const unsigned char b[32], const pt_aff_t *P) {
11516     int i, d, is_neg, is_inf = 1, flipped = 0;
11517     int8_t anaf[257] = {0};
11518     int8_t bnaf[257] = {0};
11519     pt_prj_t Q = {0};
11520     pt_prj_t precomp[DRADIX / 2];
11521
11522     precomp_wnaf(precomp, P);
11523     scalar_wnaf(anaf, a);
11524     scalar_wnaf(bnaf, b);
11525
11526     for (i = 256; i >= 0; i--) {
11527         if (!is_inf) point_double(&Q, &Q);
11528         if ((d = bnaf[i])) {
11529             if ((is_neg = d < 0) != flipped) {
11530                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(Q.Y, Q.Y);
11531                 flipped ^= 1;
11532             }
11533             d = (is_neg) ? (-d - 1) >> 1 : (d - 1) >> 1;
11534             if (is_inf) {
11535                 /* initialize accumulator */
11536                 fe_copy(Q.X, &precomp[d].X);
11537                 fe_copy(Q.Y, &precomp[d].Y);
11538                 fe_copy(Q.Z, &precomp[d].Z);
11539                 is_inf = 0;
11540             } else
11541                 point_add_proj(&Q, &Q, &precomp[d]);
11542         }
11543         if ((d = anaf[i])) {
11544             if ((is_neg = d < 0) != flipped) {
11545                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(Q.Y, Q.Y);
11546                 flipped ^= 1;
11547             }
11548             d = (is_neg) ? (-d - 1) >> 1 : (d - 1) >> 1;
11549             if (is_inf) {
11550                 /* initialize accumulator */
11551                 fe_copy(Q.X, &lut_cmb[0][d].X);
11552                 fe_copy(Q.Y, &lut_cmb[0][d].Y);
11553                 fe_copy(Q.Z, const_one);
11554                 is_inf = 0;
11555             } else
11556                 point_add_mixed(&Q, &Q, &lut_cmb[0][d]);
11557         }
11558     }
11559
11560     if (is_inf) {
11561         /* initialize accumulator to inf: all-zero scalars */
11562         fe_set_zero(Q.X);
11563         fe_copy(Q.Y, const_one);
11564         fe_set_zero(Q.Z);
11565     }
11566
11567     if (flipped) {
11568         /* correct sign */
11569         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(Q.Y, Q.Y);
11570     }
11571
11572     /* convert to affine -- NB depends on coordinate system */
11573     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(Q.Z, Q.Z);
11574     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->X, Q.X, Q.Z);
11575     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->Y, Q.Y, Q.Z);
11576 }
11577
11578 /*-
11579  * Variable point scalar multiplication with "regular" wnaf.
11580  */
11581 static void var_smul_rwnaf(pt_aff_t *out, const unsigned char scalar[32],
11582                            const pt_aff_t *P) {
11583     int i, j, d, diff, is_neg;
11584     int8_t rnaf[52] = {0};
11585     pt_prj_t Q = {0}, lut = {0};
11586     pt_prj_t precomp[DRADIX / 2];
11587
11588     precomp_wnaf(precomp, P);
11589     scalar_rwnaf(rnaf, scalar);
11590
11591 #if defined(_MSC_VER)
11592     /* result still unsigned: yes we know */
11593 #pragma warning(push)
11594 #pragma warning(disable : 4146)
11595 #endif
11596
11597     /* initialize accumulator to high digit */
11598     d = (rnaf[51] - 1) >> 1;
11599     for (j = 0; j < DRADIX / 2; j++) {
11600         diff = (1 - (-(d ^ j) >> (8 * sizeof(int) - 1))) & 1;
11601         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.X, diff, Q.X,
11602                                                               precomp[j].X);
11603         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Y, diff, Q.Y,
11604                                                               precomp[j].Y);
11605         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Z, diff, Q.Z,
11606                                                               precomp[j].Z);
11607     }
11608
11609     for (i = 50; i >= 0; i--) {
11610         for (j = 0; j < RADIX; j++) point_double(&Q, &Q);
11611         d = rnaf[i];
11612         /* is_neg = (d < 0) ? 1 : 0 */
11613         is_neg = (d >> (8 * sizeof(int) - 1)) & 1;
11614         /* d = abs(d) */
11615         d = (d ^ -is_neg) + is_neg;
11616         d = (d - 1) >> 1;
11617         for (j = 0; j < DRADIX / 2; j++) {
11618             diff = (1 - (-(d ^ j) >> (8 * sizeof(int) - 1))) & 1;
11619             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
11620                 lut.X, diff, lut.X, precomp[j].X);
11621             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
11622                 lut.Y, diff, lut.Y, precomp[j].Y);
11623             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
11624                 lut.Z, diff, lut.Z, precomp[j].Z);
11625         }
11626         /* negate lut point if digit is negative */
11627         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(out->Y, lut.Y);
11628         fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(lut.Y, is_neg,
11629                                                               lut.Y, out->Y);
11630         point_add_proj(&Q, &Q, &lut);
11631     }
11632
11633 #if defined(_MSC_VER)
11634 #pragma warning(pop)
11635 #endif
11636
11637     /* conditionally subtract P if the scalar was even */
11638     fe_copy(lut.X, precomp[0].X);
11639     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(lut.Y, precomp[0].Y);
11640     fe_copy(lut.Z, precomp[0].Z);
11641     point_add_proj(&lut, &lut, &Q);
11642     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.X, scalar[0] & 1,
11643                                                           lut.X, Q.X);
11644     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Y, scalar[0] & 1,
11645                                                           lut.Y, Q.Y);
11646     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Z, scalar[0] & 1,
11647                                                           lut.Z, Q.Z);
11648
11649     /* convert to affine -- NB depends on coordinate system */
11650     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(Q.Z, Q.Z);
11651     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->X, Q.X, Q.Z);
11652     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->Y, Q.Y, Q.Z);
11653 }
11654
11655 /*-
11656  * Fixed scalar multiplication: comb with interleaving.
11657  */
11658 static void fixed_smul_cmb(pt_aff_t *out, const unsigned char scalar[32]) {
11659     int i, j, k, d, diff, is_neg = 0;
11660     int8_t rnaf[52] = {0};
11661     pt_prj_t Q = {0}, R = {0};
11662     pt_aff_t lut = {0};
11663
11664     scalar_rwnaf(rnaf, scalar);
11665
11666     /* initalize accumulator to inf */
11667     fe_set_zero(Q.X);
11668     fe_copy(Q.Y, const_one);
11669     fe_set_zero(Q.Z);
11670
11671 #if defined(_MSC_VER)
11672     /* result still unsigned: yes we know */
11673 #pragma warning(push)
11674 #pragma warning(disable : 4146)
11675 #endif
11676
11677     for (i = 1; i >= 0; i--) {
11678         for (j = 0; i != 1 && j < RADIX; j++) point_double(&Q, &Q);
11679         for (j = 0; j < 27; j++) {
11680             if (j * 2 + i > 51) continue;
11681             d = rnaf[j * 2 + i];
11682             /* is_neg = (d < 0) ? 1 : 0 */
11683             is_neg = (d >> (8 * sizeof(int) - 1)) & 1;
11684             /* d = abs(d) */
11685             d = (d ^ -is_neg) + is_neg;
11686             d = (d - 1) >> 1;
11687             for (k = 0; k < DRADIX / 2; k++) {
11688                 diff = (1 - (-(d ^ k) >> (8 * sizeof(int) - 1))) & 1;
11689                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
11690                     lut.X, diff, lut.X, lut_cmb[j][k].X);
11691                 fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
11692                     lut.Y, diff, lut.Y, lut_cmb[j][k].Y);
11693             }
11694             /* negate lut point if digit is negative */
11695             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(out->Y, lut.Y);
11696             fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(
11697                 lut.Y, is_neg, lut.Y, out->Y);
11698             point_add_mixed(&Q, &Q, &lut);
11699         }
11700     }
11701
11702 #if defined(_MSC_VER)
11703 #pragma warning(pop)
11704 #endif
11705
11706     /* conditionally subtract P if the scalar was even */
11707     fe_copy(lut.X, lut_cmb[0][0].X);
11708     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_opp(lut.Y, lut_cmb[0][0].Y);
11709     point_add_mixed(&R, &Q, &lut);
11710     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.X, scalar[0] & 1,
11711                                                           R.X, Q.X);
11712     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Y, scalar[0] & 1,
11713                                                           R.Y, Q.Y);
11714     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_selectznz(Q.Z, scalar[0] & 1,
11715                                                           R.Z, Q.Z);
11716
11717     /* convert to affine -- NB depends on coordinate system */
11718     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_inv(Q.Z, Q.Z);
11719     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->X, Q.X, Q.Z);
11720     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_mul(out->Y, Q.Y, Q.Z);
11721 }
11722
11723 /*-
11724  * Wrapper: simultaneous scalar mutiplication.
11725  * outx, outy := a * G + b * P
11726  * where P = (inx, iny).
11727  * Everything is LE byte ordering.
11728  */
11729 static void point_mul_two(unsigned char outx[32], unsigned char outy[32],
11730                           const unsigned char a[32], const unsigned char b[32],
11731                           const unsigned char inx[32],
11732                           const unsigned char iny[32]) {
11733     pt_aff_t P;
11734
11735     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.X, inx);
11736     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.Y, iny);
11737     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.X, P.X);
11738     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.Y, P.Y);
11739     /* simultaneous scalar multiplication */
11740     var_smul_wnaf_two(&P, a, b, &P);
11741
11742     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.X, P.X);
11743     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.Y, P.Y);
11744     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outx, P.X);
11745     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outy, P.Y);
11746 }
11747
11748 /*-
11749  * Wrapper: fixed scalar mutiplication.
11750  * outx, outy := scalar * G
11751  * Everything is LE byte ordering.
11752  */
11753 static void point_mul_g(unsigned char outx[32], unsigned char outy[32],
11754                         const unsigned char scalar[32]) {
11755     pt_aff_t P;
11756
11757     /* fixed scmul function */
11758     fixed_smul_cmb(&P, scalar);
11759     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.X, P.X);
11760     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.Y, P.Y);
11761     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outx, P.X);
11762     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outy, P.Y);
11763 }
11764
11765 /*-
11766  * Wrapper: variable point scalar mutiplication.
11767  * outx, outy := scalar * P
11768  * where P = (inx, iny).
11769  * Everything is LE byte ordering.
11770  */
11771 static void point_mul(unsigned char outx[32], unsigned char outy[32],
11772                       const unsigned char scalar[32],
11773                       const unsigned char inx[32],
11774                       const unsigned char iny[32]) {
11775     pt_aff_t P;
11776
11777     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.X, inx);
11778     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_bytes(P.Y, iny);
11779     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.X, P.X);
11780     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_montgomery(P.Y, P.Y);
11781     /* var scmul function */
11782     var_smul_rwnaf(&P, scalar, &P);
11783     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.X, P.X);
11784     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_from_montgomery(P.Y, P.Y);
11785     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outx, P.X);
11786     fiat_id_GostR3410_2001_CryptoPro_B_ParamSet_to_bytes(outy, P.Y);
11787 }
11788
11789
11790 #include <openssl/ec.h>
11791
11792 /* the zero field element */
11793 static const unsigned char const_zb[32] = {0};
11794
11795 /*-
11796  * An OpenSSL wrapper for simultaneous scalar multiplication.
11797  * r := n * G + m * q
11798  */
11799     int
11800     point_mul_two_id_GostR3410_2001_CryptoPro_B_ParamSet(
11801         const EC_GROUP *group, EC_POINT *r, const BIGNUM *n, const EC_POINT *q,
11802         const BIGNUM *m, BN_CTX *ctx) {
11803     int ret = 0;
11804     unsigned char b_x[32];
11805     unsigned char b_y[32];
11806     unsigned char b_n[32];
11807     unsigned char b_m[32];
11808     BIGNUM *x = NULL, *y = NULL;
11809
11810     BN_CTX_start(ctx);
11811     x = BN_CTX_get(ctx);
11812     if ((y = BN_CTX_get(ctx)) == NULL
11813         /* pull out coords as bytes */
11814         || !EC_POINT_get_affine_coordinates(group, q, x, y, ctx) ||
11815         BN_bn2lebinpad(x, b_x, 32) != 32 || BN_bn2lebinpad(y, b_y, 32) != 32 ||
11816         BN_bn2lebinpad(n, b_n, 32) != 32 || BN_bn2lebinpad(m, b_m, 32) != 32)
11817         goto err;
11818     /* do the simultaneous scalar multiplication */
11819     point_mul_two(b_x, b_y, b_n, b_m, b_x, b_y);
11820     /* check for infinity */
11821     if (CRYPTO_memcmp(const_zb, b_x, 32) == 0 &&
11822         CRYPTO_memcmp(const_zb, b_y, 32) == 0) {
11823         if (!EC_POINT_set_to_infinity(group, r)) goto err;
11824     } else {
11825         /* otherwise, pack the bytes into the result */
11826         if (BN_lebin2bn(b_x, 32, x) == NULL ||
11827             BN_lebin2bn(b_y, 32, y) == NULL ||
11828             !EC_POINT_set_affine_coordinates(group, r, x, y, ctx))
11829             goto err;
11830     }
11831     ret = 1;
11832 err:
11833     BN_CTX_end(ctx);
11834     return ret;
11835 }
11836
11837 /*-
11838  * An OpenSSL wrapper for variable point scalar multiplication.
11839  * r := m * q
11840  */
11841     int
11842     point_mul_id_GostR3410_2001_CryptoPro_B_ParamSet(const EC_GROUP *group,
11843                                                      EC_POINT *r,
11844                                                      const EC_POINT *q,
11845                                                      const BIGNUM *m,
11846                                                      BN_CTX *ctx) {
11847     int ret = 0;
11848     unsigned char b_x[32];
11849     unsigned char b_y[32];
11850     unsigned char b_m[32];
11851     BIGNUM *x = NULL, *y = NULL;
11852
11853     BN_CTX_start(ctx);
11854     x = BN_CTX_get(ctx);
11855     if ((y = BN_CTX_get(ctx)) == NULL
11856         /* pull out coords as bytes */
11857         || !EC_POINT_get_affine_coordinates(group, q, x, y, ctx) ||
11858         BN_bn2lebinpad(x, b_x, 32) != 32 || BN_bn2lebinpad(y, b_y, 32) != 32 ||
11859         BN_bn2lebinpad(m, b_m, 32) != 32)
11860         goto err;
11861     /* do the variable scalar multiplication */
11862     point_mul(b_x, b_y, b_m, b_x, b_y);
11863     /* check for infinity */
11864     if (CRYPTO_memcmp(const_zb, b_x, 32) == 0 &&
11865         CRYPTO_memcmp(const_zb, b_y, 32) == 0) {
11866         if (!EC_POINT_set_to_infinity(group, r)) goto err;
11867     } else {
11868         /* otherwise, pack the bytes into the result */
11869         if (BN_lebin2bn(b_x, 32, x) == NULL ||
11870             BN_lebin2bn(b_y, 32, y) == NULL ||
11871             !EC_POINT_set_affine_coordinates(group, r, x, y, ctx))
11872             goto err;
11873     }
11874     ret = 1;
11875 err:
11876     BN_CTX_end(ctx);
11877     return ret;
11878 }
11879
11880 /*-
11881  * An OpenSSL wrapper for fixed scalar multiplication.
11882  * r := n * G
11883  */
11884     int
11885     point_mul_g_id_GostR3410_2001_CryptoPro_B_ParamSet(const EC_GROUP *group,
11886                                                        EC_POINT *r,
11887                                                        const BIGNUM *n,
11888                                                        BN_CTX *ctx) {
11889     int ret = 0;
11890     unsigned char b_x[32];
11891     unsigned char b_y[32];
11892     unsigned char b_n[32];
11893     BIGNUM *x = NULL, *y = NULL;
11894
11895     BN_CTX_start(ctx);
11896     x = BN_CTX_get(ctx);
11897     if ((y = BN_CTX_get(ctx)) == NULL || BN_bn2lebinpad(n, b_n, 32) != 32)
11898         goto err;
11899     /* do the fixed scalar multiplication */
11900     point_mul_g(b_x, b_y, b_n);
11901     /* check for infinity */
11902     if (CRYPTO_memcmp(const_zb, b_x, 32) == 0 &&
11903         CRYPTO_memcmp(const_zb, b_y, 32) == 0) {
11904         if (!EC_POINT_set_to_infinity(group, r)) goto err;
11905     } else {
11906         /* otherwise, pack the bytes into the result */
11907         if (BN_lebin2bn(b_x, 32, x) == NULL ||
11908             BN_lebin2bn(b_y, 32, y) == NULL ||
11909             !EC_POINT_set_affine_coordinates(group, r, x, y, ctx))
11910             goto err;
11911     }
11912     ret = 1;
11913 err:
11914     BN_CTX_end(ctx);
11915     return ret;
11916 }
11917
11918
11919
11920 #endif /* __SIZEOF_INT128__ */