git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/7] block-sha1: improved SHA1 hashing

From
Linus Torvalds <torvalds@linux-foundation.org>
Date
Aug 6, 2009, 23:25 UTC
Message-ID
<alpine.LFD.2.01.0908061609340.3390@localhost.localdomain>
In-Reply-To
<alpine.LFD.2.01.0908061559120.3390@localhost.localdomain>
On Thu, 6 Aug 2009, Linus Torvalds wrote:
> 
> It was prescott that changed a lot (mostly for the worse - the shifter was 
> one of the few upsides of prescott, although increased frequency often 
> made up for the downsides).

Anyway, since you have a Northwood, I bet that the #1 issue for you is to spread out the shift instructions in a way that simply doesn't matter anywhere else.

In netburst, if I remember the details correcty, a "complex instruction" will basically get the trace cache from the microcode roms. I'm not sure how it interacts with the TC entries around it, but it's entirely possible that it basically disables any instruction scheduling (the microcode traces are presumably "pre-scheduled"), so you'd basically see stalls where there's little out-of-order execution.

That then explains why you see huge differences from what is basically trivial scheduling decisions, and why some random placement of a shift makes a big difference.

Just out of curiosity, does anything change if you change the
	B = SHA_ROR(B,2)
into a
	B = SHA_ROR(SHA_ROR(B,1),1)

instead? It's very possible that it becomes _much_ worse, but I guess it's also possible in theory that a single-bit rotate ends up being a simple instruction and that doing two single-bit ROR's is actually faster than one 2-bit ROR (assuming the second one is microcoded and the first one).

In particular, I'm thinking about the warnign in the intel optimization manual:

	The rotate by immediate and rotate by register instructions are 
	more expensive than a shift. The rotate by 1 instruction has the 
	same latency as a shift.

so it's very possible that "rotate by 1" is much better than other rotates.

			Linus
Previous: Linus TorvaldsNext: Linus Torvalds
Message 25 of 37 in “block-sha1: improved SHA1 hashing”
  1. 0/7 block-sha1: improved SHA1 hashingLinus Torvalds, Aug 6, 2009
  2. 1/7 block-sha1: add new optimized C 'block-sha1' routinesLinus Torvalds, Aug 6, 2009
  3. 2/7 block-sha1: try to use rol/ror appropriatelyLinus Torvalds, Aug 6, 2009
  4. 3/7 block-sha1: make the 'ntohl()' part of the first SHA1 loopLinus Torvalds, Aug 6, 2009
  5. 4/7 block-sha1: re-use the temporary array as we calculate the SHA1Linus Torvalds, Aug 6, 2009
  6. 5/7 block-sha1: macroize the rounds a bit furtherLinus Torvalds, Aug 6, 2009
  7. 6/7 block-sha1: Use '(B&C)+(D&(B^C))' instead of '(B&C)|(D&(B|C))' in round 3Linus Torvalds, Aug 6, 2009
  8. 7/7 block-sha1: get rid of redundant 'lenW' contextLinus Torvalds, Aug 6, 2009
  9. Bert WesargAug 6, 2009
  10. Artur SkawinaAug 6, 2009
  11. Linus TorvaldsAug 6, 2009
  12. Artur SkawinaAug 6, 2009
  13. Linus TorvaldsAug 6, 2009
  14. Artur SkawinaAug 6, 2009
  15. Linus TorvaldsAug 6, 2009
  16. Linus TorvaldsAug 6, 2009
  17. Artur SkawinaAug 6, 2009
  18. Artur SkawinaAug 6, 2009
  19. Linus TorvaldsAug 6, 2009
  20. Linus TorvaldsAug 6, 2009
  21. Artur SkawinaAug 6, 2009
  22. Linus TorvaldsAug 6, 2009
  23. Artur SkawinaAug 6, 2009
  24. Linus TorvaldsAug 6, 2009
  25. Linus TorvaldsAug 6, 2009
  26. Linus TorvaldsAug 7, 2009
  27. Artur SkawinaAug 7, 2009
  28. Linus TorvaldsAug 7, 2009
  29. Artur SkawinaAug 7, 2009
  30. Linus TorvaldsAug 7, 2009
  31. Artur SkawinaAug 7, 2009
  32. Linus TorvaldsAug 8, 2009
  33. Artur SkawinaAug 8, 2009
  34. Linus TorvaldsAug 8, 2009
  35. Artur SkawinaAug 8, 2009
  36. Artur SkawinaAug 8, 2009
  37. Artur SkawinaAug 8, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.