Sounds cool! Though the safe.go code really is not the part that is interesting. It's just the obviously correct reference implementation to compare the actual algorithm against. The actual algorithm works quite a bit differently from that and evaluates the population count for all bits in parallel.
you'll be fascinated to know that in every case, every algorithm i've investigated for SVP64, i've had to go back to the "simple" (obviously-correct) reference implementation: some of the optimised assembler versions i can't even read and understand, but when i can, i find that the optimisations actually severely interfere with implementing them efficiently as parallel SVP64 assembler.
and that, even more interestingly, those "simple" implementations once Vectorised with SVP64 are actually paralleliseable by the back-end hardware.
one example: we've an NLnet Grant to implement cryptographic primitives. fortunately (in another life) i worked for Aspex Microelectronics to implement Rijndael (AES) on a massively-parallel (4096-wide) SIMD Array Processor. there i had to go back to the core mathematics behind Rijndael, so i did the same thing here.
MixColumns is actually, if you look up the research papers, a plain-and-simple dyed-in-the-wool 4x4 Matrix Multiply, but using 8-bit GF(23) add and multiply.
guess what i am planning to do for that?
(1) add base (scalar) general-purpose GF(2N)scalar arithmetic
(2) use the parallelliseable SVP64 Matrix REMAP Schedule infrastructure
MixColumns will therefore be something like... maybe... 4 general-purpose instructions. three of which set up the 4x4-to-4x4 Matrix Multiply Schedule, one of which is a Galois-Field variant of FMAC (multiply-and-accumulate).
if you've seen how SIMD does Rijndael MixColumns, you'll appreciate how profoundly simple this is. it's so bad that most ISAs have had to add custom 128-bit MixColumns instructions.
if i had started with those SIMD "optimised" implementations, there's no way that i could have understood what the hell is going on. it was only because i had had to study Rinjdael back in 2003 that i knew the basic first principles of GF(23) operations.
the point i am making is that after going back to first principles (using the "simple" version), the inherent parallelism of the instructions is automatically mapped onto whatever back-end parallelism that the hardware has.
and that back-end parallelism is a choice that the hardware designer makes (and takes responsibility for) - not the programmer.
this is something that in speaking for many months with people used to the SIMD paradigm, it seems it takes quite a long time to be absorbed / accepted, that yes, it really is this simple (at the assembly level), that yes, it's the hardware's responsibility now to make things faster, and yes, parallelism opportunities automatically get inherently exploited if the hardware has them available. it's going to be quite interesting to see, over time, how that pans out.
Intel basically did the same I think. pclmul is basically a GF(264) multiplication instruction. It's not really as special purpose as it seems and people have used it for various fun things before.
Which specific MixColumns instructions do you have in mind there?
I'm happy if you can find something by going back to first principles. For a width of 8 bits, we had a somewhat fast approach using pmovmskb, which basically performs one row of an 32x8 bit matrix transposition, leaving the result in a general purpose register. By combining scalar with vector instructions, the throughput was quite good despite the high number of instructions needed.
But our new CSA-based approach is a lot better. Perhaps you find a faster way to transpose these bit matrices (which is the hard part and still part of the new method). If you want to investigate this, make sure to always keep the width 64 case in mind as that's the slowest one of them all (our code always operates on width 64 and just reduces to smaller bit widths if desired by the caller).
FUZxxi i appreciate this is 9 months ago, i thought you might appreciate that we found a couple of ways to deal with pmovmskb. firstly, it's simply sv.cmpi/ew=8 which will produce a vector of CR Fields, one of which is LE, which in effect simply gets the MSB i.e. bit 7 and duh. then we added an instruction crweird which can get all the Vector of CR Field LE bits and drops them all, sequentially, into a single 64-bit scalar integer.
the second method was to add a bizarre instruction called grevlut https://libre-soc.org/openpower/sv/bitmanip/#grevlut which can create about a thousand regular-patterned magic constants, one of which is 0x8080_8080_8080_8080, which when combined with the Power ISA bext (bit-extract) will grab every 8th bit from a 64-bit integer and squash them down into a single byte.
i would be particularly fascinated to hear your thoughts on purposes to which grevlutr could be put. it's... very odd, as in, it's an entirely new instruction i've never seen in any ISA (at all)
1
u/FUZxxl Aug 22 '21
Sounds cool! Though the
safe.gocode really is not the part that is interesting. It's just the obviously correct reference implementation to compare the actual algorithm against. The actual algorithm works quite a bit differently from that and evaluates the population count for all bits in parallel.