Test results for amd64, phoenix, crypto_sign/haetae2
[Page version: 20251223 03:47:22]
Measurements for amd64, phoenix, crypto_sign
Test results for amd64, phoenix, crypto_sign
Test results for crypto_sign/haetae2
Computer: phoenix
Microarchitecture: amd64; Zen 4 (a70f41)
Architecture: amd64
CPU ID: AuthenticAMD-00a70f41-178bfbff
SUPERCOP version: 20251222
Operation: crypto_sign
Primitive: haetae2
| Time | Object size | Test size | Implementation | Compiler | Benchmark date | SUPERCOP version |
| 1270661 | 141525 64 0 | 165348 900 1832 | avx2 | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 1289877 | 132783 64 0 | 156452 900 1832 | avx2 | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 1444118 | 116898 64 0 | 138820 860 1928 | avx2 | gcc -march=native -mtune=native -O3 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 1489424 | 85954 496 0 | 106388 1308 1928 | avx2 | gcc -march=native -mtune=native -O2 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 1506148 | 80571 64 0 | 101174 892 1832 | avx2 | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 1534598 | 87762 64 0 | 107228 900 1768 | avx2 | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 1546919 | 81733 496 0 | 101972 1308 1832 | avx2 | gcc -march=native -mtune=native -O -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 3618404 | 93142 0 0 | 118236 828 1832 | ref | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 3687606 | 87644 0 0 | 112660 828 1832 | ref | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 3696149 | 77504 624 0 | 96180 1428 1800 | avx2 | gcc -march=native -mtune=native -Os -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 3840624 | 34898 0 0 | 56398 820 1832 | ref | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 3911308 | 79424 0 0 | 102412 788 1928 | ref | gcc -march=native -mtune=native -O3 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 3946547 | 77995 0 0 | 104997 828 1768 | ref | clang -mcpu=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 4091819 | 39004 432 0 | 60316 1228 1928 | ref | gcc -march=native -mtune=native -O2 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 4148731 | 40202 0 0 | 60637 828 1768 | ref | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 4333055 | 32321 560 0 | 51836 1348 1800 | ref | gcc -march=native -mtune=native -Os -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
| 5551932 | 35687 432 0 | 56724 1228 1832 | ref | gcc -march=native -mtune=native -O -fwrapv -fPIC -fPIE -gdwarf-4 -Wall | 20251222 | 20251222 |
Compiler output
sampler.c: sampler.c:230:43: warning: variable 'cnt' set but not used [-Wunused-but-set-variable]
sampler.c: 230 | size_t bytecnt = buflen, coefcnt = 0, cnt = 0;
sampler.c: | ^
sampler.c: 1 warning generated.
Number of similar (implementation,compiler) pairs: 9, namely:
| Implementation | Compiler |
| avx2 | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -mcpu=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
Compiler output
aes256ctr.c: aes256ctr.c:91:3: error: '__builtin_ia32_aeskeygenassist128' needs target feature aes
aes256ctr.c: 91 | BLOCK1(0x01);
aes256ctr.c: | ^
aes256ctr.c: aes256ctr.c:72:11: note: expanded from macro 'BLOCK1'
aes256ctr.c: 72 | temp1 = _mm_aeskeygenassist_si128(temp2, IMM); \
aes256ctr.c: | ^
aes256ctr.c: /usr/lib/llvm-19/lib/clang/19/include/__wmmintrin_aes.h:136:13: note: expanded from macro '_mm_aeskeygenassist_si128'
aes256ctr.c: 136 | ((__m128i)__builtin_ia32_aeskeygenassist128((__v2di)(__m128i)(C), (int)(R)))
aes256ctr.c: | ^
aes256ctr.c: aes256ctr.c:92:3: error: '__builtin_ia32_aeskeygenassist128' needs target feature aes
aes256ctr.c: 92 | BLOCK2(0x01);
aes256ctr.c: | ^
aes256ctr.c: aes256ctr.c:82:11: note: expanded from macro 'BLOCK2'
aes256ctr.c: 82 | temp1 = _mm_aeskeygenassist_si128(temp0, IMM); \
aes256ctr.c: | ^
aes256ctr.c: /usr/lib/llvm-19/lib/clang/19/include/__wmmintrin_aes.h:136:13: note: expanded from macro '_mm_aeskeygenassist_si128'
aes256ctr.c: 136 | ((__m128i)__builtin_ia32_aeskeygenassist128((__v2di)(__m128i)(C), (int)(R)))
aes256ctr.c: | ^
aes256ctr.c: aes256ctr.c:94:3: error: '__builtin_ia32_aeskeygenassist128' needs target feature aes
aes256ctr.c: 94 | BLOCK1(0x02);
aes256ctr.c: | ^
aes256ctr.c: aes256ctr.c:72:11: note: expanded from macro 'BLOCK1'
aes256ctr.c: 72 | temp1 = _mm_aeskeygenassist_si128(temp2, IMM); \
aes256ctr.c: | ^
aes256ctr.c: /usr/lib/llvm-19/lib/clang/19/include/__wmmintrin_aes.h:136:13: note: expanded from macro '_mm_aeskeygenassist_si128'
aes256ctr.c: ...
Number of similar (implementation,compiler) pairs: 1, namely:
| Implementation | Compiler |
| avx2 | clang -mcpu=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
Namespace violations
aes256ctr.o cryptolab_haetae_aes256ctr_init T
aes256ctr.o cryptolab_haetae_aes256ctr_squeezeblocks T
consts.o cryptolab_haetae2_qdata R
decompose.o cryptolab_haetae2_decompose_hint T
decompose.o cryptolab_haetae2_decompose_vk T
decompose.o cryptolab_haetae2_decompose_z1 T
encoding.o cryptolab_haetae2_decode_h T
encoding.o cryptolab_haetae2_decode_hb_z1 T
encoding.o cryptolab_haetae2_encode_h T
encoding.o cryptolab_haetae2_encode_hb_z1 T
f1600x4.o haetae_fips202x4_avx2_f1600x4 T
fft.o brv8 R
fft.o complex_fp_sqabs_add T
fft.o fft T
fft.o fft_init_and_bitrev T
fips202.o haetae_fips202_KeccakF_RoundConstants R
fips202.o haetae_fips202_sha3_256 T
fips202.o haetae_fips202_sha3_512 T
fips202.o haetae_fips202_shake128 T
fips202.o haetae_fips202_shake128_absorb T
fips202.o haetae_fips202_shake128_absorb_once T
fips202.o haetae_fips202_shake128_finalize T
fips202.o haetae_fips202_shake128_init T
fips202.o haetae_fips202_shake128_squeeze T
fips202.o haetae_fips202_shake128_squeezeblocks T
fips202.o haetae_fips202_shake256 T
fips202.o haetae_fips202_shake256_absorb T
fips202.o haetae_fips202_shake256_absorb_once T
fips202.o haetae_fips202_shake256_finalize T
fips202.o haetae_fips202_shake256_init T
fips202.o haetae_fips202_shake256_squeeze T
fips202.o haetae_fips202_shake256_squeezeblocks T
fips202x4.o haetae_fips202x4_avx2_shake128x4 T
fips202x4.o haetae_fips202x4_avx2_shake128x4_absorb_once T
fips202x4.o haetae_fips202x4_avx2_shake128x4_squeezeblocks T
fips202x4.o haetae_fips202x4_avx2_shake256x4 T
fips202x4.o haetae_fips202x4_avx2_shake256x4_absorb_once T
fips202x4.o haetae_fips202x4_avx2_shake256x4_squeezeblocks T
fips202x4.o haetae_fips202x4_avx2_shake256x4_squeezeblocks_vec T
fixpoint.o cryptolab_haetae2_fixpoint_add T
fixpoint.o cryptolab_haetae2_fixpoint_mul_rnd13 T
fixpoint.o cryptolab_haetae2_fixpoint_newton_invsqrt T
fixpoint.o cryptolab_haetae2_fixpoint_square T
fixpoint.o start_cube R
fixpoint.o start_times_threehalves R
invntt.o cryptolab_haetae2_invntt_avx T
ntt.o cryptolab_haetae2_ntt_avx T
packing.o cryptolab_haetae2_pack_pk T
packing.o cryptolab_haetae2_pack_sig T
packing.o cryptolab_haetae2_pack_sk T
packing.o cryptolab_haetae2_unpack_pk T
packing.o cryptolab_haetae2_unpack_sig T
packing.o cryptolab_haetae2_unpack_sk T
pointwise.o cryptolab_haetae2_pointwise_acc_avx T
pointwise.o cryptolab_haetae2_pointwise_avx T
poly.o cryptolab_haetae2_poly2eta_pack T
poly.o cryptolab_haetae2_poly2eta_unpack T
poly.o cryptolab_haetae2_poly_add T
poly.o cryptolab_haetae2_poly_challenge T
poly.o cryptolab_haetae2_poly_compose T
poly.o cryptolab_haetae2_poly_decomposed_pack T
poly.o cryptolab_haetae2_poly_decomposed_unpack T
poly.o cryptolab_haetae2_poly_freeze T
poly.o cryptolab_haetae2_poly_freeze2q T
poly.o cryptolab_haetae2_poly_fromcrt T
poly.o cryptolab_haetae2_poly_fromcrt0 T
poly.o cryptolab_haetae2_poly_highbits T
poly.o cryptolab_haetae2_poly_invntt_tomont T
poly.o cryptolab_haetae2_poly_lowbits T
poly.o cryptolab_haetae2_poly_lsb T
poly.o cryptolab_haetae2_poly_ntt T
poly.o cryptolab_haetae2_poly_nttunpack T
poly.o cryptolab_haetae2_poly_pack_highbits T
poly.o cryptolab_haetae2_poly_pack_lsb T
poly.o cryptolab_haetae2_poly_pointwise_montgomery T
poly.o cryptolab_haetae2_poly_reduce2q T
poly.o cryptolab_haetae2_poly_sub T
poly.o cryptolab_haetae2_poly_uniform T
poly.o cryptolab_haetae2_poly_uniform_4x T
poly.o cryptolab_haetae2_poly_uniform_eta T
poly.o cryptolab_haetae2_poly_uniform_eta_4x T
poly.o cryptolab_haetae2_polyeta_pack T
poly.o cryptolab_haetae2_polyeta_unpack T
poly.o cryptolab_haetae2_polyq_pack T
poly.o cryptolab_haetae2_polyq_unpack T
poly.o hammingWeight_8 T
polyfix.o cryptolab_haetae2_polyfix_add T
polyfix.o cryptolab_haetae2_polyfix_round T
polyfix.o cryptolab_haetae2_polyfixfixveck_sub T
polyfix.o cryptolab_haetae2_polyfixfixvecl_sub T
polyfix.o cryptolab_haetae2_polyfixveck_add T
polyfix.o cryptolab_haetae2_polyfixveck_double T
polyfix.o cryptolab_haetae2_polyfixveck_round T
polyfix.o cryptolab_haetae2_polyfixvecl_add T
polyfix.o cryptolab_haetae2_polyfixvecl_double T
polyfix.o cryptolab_haetae2_polyfixvecl_round T
polyfix.o cryptolab_haetae2_polyfixveclk_sample_hyperball T
polyfix.o cryptolab_haetae2_polyfixveclk_sqnorm2 T
polyfix.o polyfixfix_sub T
polymat.o cryptolab_haetae2_polymatkl_double T
polymat.o cryptolab_haetae2_polymatkl_expand T
polymat.o cryptolab_haetae2_polymatkl_pointwise_montgomery T
polymat.o cryptolab_haetae2_polymatkm_expand T
polymat.o cryptolab_haetae2_polymatkm_pointwise_montgomery T
polyvec.o cryptolab_haetae2_polyveck_add T
polyvec.o cryptolab_haetae2_polyveck_caddDQ2ALPHA T
polyvec.o cryptolab_haetae2_polyveck_caddq T
polyvec.o cryptolab_haetae2_polyveck_cneg T
polyvec.o cryptolab_haetae2_polyveck_csubDQ2ALPHA T
polyvec.o cryptolab_haetae2_polyveck_decompose_vk T
polyvec.o cryptolab_haetae2_polyveck_div2 T
polyvec.o cryptolab_haetae2_polyveck_double T
polyvec.o cryptolab_haetae2_polyveck_double_negate T
polyvec.o cryptolab_haetae2_polyveck_expand T
polyvec.o cryptolab_haetae2_polyveck_freeze T
polyvec.o cryptolab_haetae2_polyveck_freeze2q T
polyvec.o cryptolab_haetae2_polyveck_frommont T
polyvec.o cryptolab_haetae2_polyveck_highbits_hint T
polyvec.o cryptolab_haetae2_polyveck_invntt_tomont T
polyvec.o cryptolab_haetae2_polyveck_mul_alpha T
polyvec.o cryptolab_haetae2_polyveck_ntt T
polyvec.o cryptolab_haetae2_polyveck_pack_highbits T
polyvec.o cryptolab_haetae2_polyveck_poly_fromcrt T
polyvec.o cryptolab_haetae2_polyveck_poly_pointwise_montgomery T
polyvec.o cryptolab_haetae2_polyveck_reduce2q T
polyvec.o cryptolab_haetae2_polyveck_sqnorm2 T
polyvec.o cryptolab_haetae2_polyveck_sub T
polyvec.o cryptolab_haetae2_polyvecl_cneg T
polyvec.o cryptolab_haetae2_polyvecl_highbits T
polyvec.o cryptolab_haetae2_polyvecl_lowbits T
polyvec.o cryptolab_haetae2_polyvecl_ntt T
polyvec.o cryptolab_haetae2_polyvecl_pointwise_acc_montgomery T
polyvec.o cryptolab_haetae2_polyvecl_sqnorm2 T
polyvec.o cryptolab_haetae2_polyvecm_ntt T
polyvec.o cryptolab_haetae2_polyvecm_pointwise_acc_montgomery T
polyvec.o cryptolab_haetae2_polyvecmk_sqsing_value T
polyvec.o cryptolab_haetae2_polyvecmk_uniform_eta T
reduce.o cryptolab_haetae2_caddq T
reduce.o cryptolab_haetae2_freeze T
reduce.o cryptolab_haetae2_freeze2q T
reduce.o cryptolab_haetae2_montgomery_reduce T
reduce.o cryptolab_haetae2_reduce32_2q T
sampler.o cryptolab_haetae2_rej_eta T
sampler.o cryptolab_haetae2_rej_uniform T
sampler.o cryptolab_haetae2_sample_gauss_N T
sampler.o sample_gauss T
samplerx4.o cryptolab_haetae2_sample_gauss_N_4x T
shuffle.o cryptolab_haetae2_nttunpack_avx T
sign.o cryptolab_haetae2_signature T
sign.o cryptolab_haetae2_verify T
symmetric-shake.o cryptolab_haetae2_haetae_shake128_stream_init T
symmetric-shake.o cryptolab_haetae2_haetae_shake256_absorb_twice T
symmetric-shake.o cryptolab_haetae2_haetae_shake256_stream_init T
Number of similar (implementation,compiler) pairs: 8, namely:
| Implementation | Compiler |
| avx2 | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| avx2 | gcc -march=native -mtune=native -O2 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| avx2 | gcc -march=native -mtune=native -O3 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| avx2 | gcc -march=native -mtune=native -O -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| avx2 | gcc -march=native -mtune=native -Os -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
Namespace violations
decompose.o cryptolab_haetae2_decompose_hint T
decompose.o cryptolab_haetae2_decompose_vk T
decompose.o cryptolab_haetae2_decompose_z1 T
encoding.o cryptolab_haetae2_decode_h T
encoding.o cryptolab_haetae2_decode_hb_z1 T
encoding.o cryptolab_haetae2_encode_h T
encoding.o cryptolab_haetae2_encode_hb_z1 T
fft.o brv8 R
fft.o complex_fp_sqabs T
fft.o fft T
fft.o fft_init_and_bitrev T
fips202.o haetae_fips202_KeccakF_RoundConstants R
fips202.o haetae_fips202_sha3_256 T
fips202.o haetae_fips202_sha3_512 T
fips202.o haetae_fips202_shake128 T
fips202.o haetae_fips202_shake128_absorb T
fips202.o haetae_fips202_shake128_absorb_once T
fips202.o haetae_fips202_shake128_finalize T
fips202.o haetae_fips202_shake128_init T
fips202.o haetae_fips202_shake128_squeeze T
fips202.o haetae_fips202_shake128_squeezeblocks T
fips202.o haetae_fips202_shake256 T
fips202.o haetae_fips202_shake256_absorb T
fips202.o haetae_fips202_shake256_absorb_once T
fips202.o haetae_fips202_shake256_finalize T
fips202.o haetae_fips202_shake256_init T
fips202.o haetae_fips202_shake256_squeeze T
fips202.o haetae_fips202_shake256_squeezeblocks T
fixpoint.o cryptolab_haetae2_fixpoint_add T
fixpoint.o cryptolab_haetae2_fixpoint_mul_rnd13 T
fixpoint.o cryptolab_haetae2_fixpoint_newton_invsqrt T
fixpoint.o cryptolab_haetae2_fixpoint_square T
fixpoint.o start_cube R
fixpoint.o start_times_threehalves R
ntt.o cryptolab_haetae2_invntt_tomont T
ntt.o cryptolab_haetae2_ntt T
packing.o cryptolab_haetae2_pack_pk T
packing.o cryptolab_haetae2_pack_sig T
packing.o cryptolab_haetae2_pack_sk T
packing.o cryptolab_haetae2_unpack_pk T
packing.o cryptolab_haetae2_unpack_sig T
packing.o cryptolab_haetae2_unpack_sk T
poly.o cryptolab_haetae2_poly2eta_pack T
poly.o cryptolab_haetae2_poly2eta_unpack T
poly.o cryptolab_haetae2_poly_add T
poly.o cryptolab_haetae2_poly_challenge T
poly.o cryptolab_haetae2_poly_compose T
poly.o cryptolab_haetae2_poly_decomposed_pack T
poly.o cryptolab_haetae2_poly_decomposed_unpack T
poly.o cryptolab_haetae2_poly_freeze T
poly.o cryptolab_haetae2_poly_freeze2q T
poly.o cryptolab_haetae2_poly_fromcrt T
poly.o cryptolab_haetae2_poly_fromcrt0 T
poly.o cryptolab_haetae2_poly_highbits T
poly.o cryptolab_haetae2_poly_invntt_tomont T
poly.o cryptolab_haetae2_poly_lowbits T
poly.o cryptolab_haetae2_poly_lsb T
poly.o cryptolab_haetae2_poly_ntt T
poly.o cryptolab_haetae2_poly_pack_highbits T
poly.o cryptolab_haetae2_poly_pack_lsb T
poly.o cryptolab_haetae2_poly_pointwise_montgomery T
poly.o cryptolab_haetae2_poly_reduce2q T
poly.o cryptolab_haetae2_poly_sub T
poly.o cryptolab_haetae2_poly_uniform T
poly.o cryptolab_haetae2_poly_uniform_eta T
poly.o cryptolab_haetae2_polyeta_pack T
poly.o cryptolab_haetae2_polyeta_unpack T
poly.o cryptolab_haetae2_polyq_pack T
poly.o cryptolab_haetae2_polyq_unpack T
poly.o hammingWeight_8 T
polyfix.o cryptolab_haetae2_polyfix_add T
polyfix.o cryptolab_haetae2_polyfix_round T
polyfix.o cryptolab_haetae2_polyfixfixveck_sub T
polyfix.o cryptolab_haetae2_polyfixfixvecl_sub T
polyfix.o cryptolab_haetae2_polyfixveck_add T
polyfix.o cryptolab_haetae2_polyfixveck_double T
polyfix.o cryptolab_haetae2_polyfixveck_round T
polyfix.o cryptolab_haetae2_polyfixvecl_add T
polyfix.o cryptolab_haetae2_polyfixvecl_double T
polyfix.o cryptolab_haetae2_polyfixvecl_round T
polyfix.o cryptolab_haetae2_polyfixveclk_sample_hyperball T
polyfix.o cryptolab_haetae2_polyfixveclk_sqnorm2 T
polyfix.o fix_round T
polyfix.o polyfixfix_sub T
polymat.o cryptolab_haetae2_polymatkl_double T
polymat.o cryptolab_haetae2_polymatkl_expand T
polymat.o cryptolab_haetae2_polymatkl_pointwise_montgomery T
polymat.o cryptolab_haetae2_polymatkm_expand T
polymat.o cryptolab_haetae2_polymatkm_pointwise_montgomery T
polyvec.o cryptolab_haetae2_polyveck_add T
polyvec.o cryptolab_haetae2_polyveck_caddDQ2ALPHA T
polyvec.o cryptolab_haetae2_polyveck_caddq T
polyvec.o cryptolab_haetae2_polyveck_cneg T
polyvec.o cryptolab_haetae2_polyveck_csubDQ2ALPHA T
polyvec.o cryptolab_haetae2_polyveck_decompose_vk T
polyvec.o cryptolab_haetae2_polyveck_div2 T
polyvec.o cryptolab_haetae2_polyveck_double T
polyvec.o cryptolab_haetae2_polyveck_double_negate T
polyvec.o cryptolab_haetae2_polyveck_expand T
polyvec.o cryptolab_haetae2_polyveck_freeze T
polyvec.o cryptolab_haetae2_polyveck_freeze2q T
polyvec.o cryptolab_haetae2_polyveck_frommont T
polyvec.o cryptolab_haetae2_polyveck_highbits_hint T
polyvec.o cryptolab_haetae2_polyveck_invntt_tomont T
polyvec.o cryptolab_haetae2_polyveck_mul_alpha T
polyvec.o cryptolab_haetae2_polyveck_ntt T
polyvec.o cryptolab_haetae2_polyveck_pack_highbits T
polyvec.o cryptolab_haetae2_polyveck_poly_fromcrt T
polyvec.o cryptolab_haetae2_polyveck_poly_pointwise_montgomery T
polyvec.o cryptolab_haetae2_polyveck_reduce2q T
polyvec.o cryptolab_haetae2_polyveck_sqnorm2 T
polyvec.o cryptolab_haetae2_polyveck_sub T
polyvec.o cryptolab_haetae2_polyvecl_cneg T
polyvec.o cryptolab_haetae2_polyvecl_highbits T
polyvec.o cryptolab_haetae2_polyvecl_lowbits T
polyvec.o cryptolab_haetae2_polyvecl_ntt T
polyvec.o cryptolab_haetae2_polyvecl_pointwise_acc_montgomery T
polyvec.o cryptolab_haetae2_polyvecl_sqnorm2 T
polyvec.o cryptolab_haetae2_polyvecm_ntt T
polyvec.o cryptolab_haetae2_polyvecm_pointwise_acc_montgomery T
polyvec.o cryptolab_haetae2_polyvecmk_sqsing_value T
polyvec.o cryptolab_haetae2_polyvecmk_uniform_eta T
reduce.o cryptolab_haetae2_caddq T
reduce.o cryptolab_haetae2_freeze T
reduce.o cryptolab_haetae2_freeze2q T
reduce.o cryptolab_haetae2_montgomery_reduce T
reduce.o cryptolab_haetae2_reduce32_2q T
sampler.o cryptolab_haetae2_rej_eta T
sampler.o cryptolab_haetae2_rej_uniform T
sampler.o cryptolab_haetae2_sample_gauss_N T
sampler.o sample_gauss T
sign.o cryptolab_haetae2_signature T
sign.o cryptolab_haetae2_verify T
symmetric-shake.o cryptolab_haetae2_haetae_shake128_stream_init T
symmetric-shake.o cryptolab_haetae2_haetae_shake256_absorb_twice T
symmetric-shake.o cryptolab_haetae2_haetae_shake256_stream_init T
Number of similar (implementation,compiler) pairs: 9, namely:
| Implementation | Compiler |
| ref | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -mcpu=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | gcc -march=native -mtune=native -O2 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| ref | gcc -march=native -mtune=native -O3 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| ref | gcc -march=native -mtune=native -O -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| ref | gcc -march=native -mtune=native -Os -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10A9AA
at 0x...: core (try-anything.c:61)
by 0x...: salsa20 (try-anything.c:101)
by 0x...: testvector (try-anything.c:124)
by 0x...: myrandom (try-anything.c:132)
by 0x...: test (try.c:124)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O2 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10B484
at 0x...: salsa20 (try-anything.c:90)
by 0x...: canary (try-anything.c:148)
by 0x...: output_prepare (try-anything.c:178)
by 0x...: test (try.c:126)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10A393
at 0x...: core (try-anything.c:64)
by 0x...: salsa20 (try-anything.c:101)
by 0x...: testvector (try-anything.c:124)
by 0x...: myrandom (try-anything.c:132)
by 0x...: test (try.c:124)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -O -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10A20E
at 0x...: core (try-anything.c:64)
by 0x...: salsa20 (try-anything.c:101)
by 0x...: testvector (try-anything.c:124)
by 0x...: myrandom (try-anything.c:132)
by 0x...: test (try.c:124)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
| ref | clang -march=native -Os -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10A204
at 0x...: core (try-anything.c:64)
by 0x...: salsa20.part.0 (try-anything.c:101)
by 0x...: salsa20 (try-anything.c:85)
by 0x...: testvector (try-anything.c:124)
by 0x...: myrandom (try-anything.c:132)
by 0x...: test (try.c:124)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | gcc -march=native -mtune=native -O2 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| ref | gcc -march=native -mtune=native -O2 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10A42A
at 0x...: st32 (try-anything.c:47)
by 0x...: core (try-anything.c:78)
by 0x...: salsa20 (try-anything.c:101)
by 0x...: salsa20 (try-anything.c:81)
by 0x...: testvector (try-anything.c:124)
by 0x...: myrandom (try-anything.c:132)
by 0x...: test (try.c:124)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | gcc -march=native -mtune=native -O3 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| ref | gcc -march=native -mtune=native -O3 -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10AAC6
at 0x...: crypto_sign_haetae2_avx2_constbranchindex_keypair (sign.c:34)
by 0x...: test (try.c:128)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 1, namely:
| Implementation | Compiler |
| avx2 | gcc -march=native -mtune=native -O -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x109FE6
at 0x...: core (try-anything.c:64)
by 0x...: salsa20.part.0 (try-anything.c:101)
by 0x...: salsa20 (try-anything.c:85)
by 0x...: testvector (try-anything.c:124)
by 0x...: myrandom (try-anything.c:132)
by 0x...: test (try.c:124)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 2, namely:
| Implementation | Compiler |
| avx2 | gcc -march=native -mtune=native -Os -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
| ref | gcc -march=native -mtune=native -Os -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x11B3E0
at 0x...: crypto_stream_chacha20_dolbeau_amd64_avx2_constbranchindex_ECRYPT_encrypt_bytes (u16mask.h:114)
by 0x...: crypto_stream_chacha20_dolbeau_amd64_avx2_constbranchindex (include/estream-convert-api.h:83)
by 0x...: crypto_rng_chacha20_ref_constbranchindex (rng.c:23)
by 0x...: randombytes_internal (knownrandombytes.c:37)
by 0x...: randombytes (knownrandombytes.c:56)
by 0x...: crypto_sign_haetae2_ref_constbranchindex_keypair (sign.c:48)
by 0x...: test (try.c:128)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 1, namely:
| Implementation | Compiler |
| ref | clang -mcpu=native -O3 -fwrapv -Qunused-arguments -fPIC -fPIE -gdwarf-4 -Wall (Debian_Clang_19.1.7_(3+b1)) |
TIMECOP error (can be valgrind bug)
error 132
Process terminating with default action of signal 4 (SIGILL)
Illegal opcode at address 0x10AAC2
at 0x...: crypto_sign_haetae2_ref_constbranchindex_keypair (sign.c:34)
by 0x...: test (try.c:128)
by 0x...: main (try-anything.c:345)
Illegal instruction
Number of similar (implementation,compiler) pairs: 1, namely:
| Implementation | Compiler |
| ref | gcc -march=native -mtune=native -O -fwrapv -fPIC -fPIE -gdwarf-4 -Wall (14.2.0) |