import Base import ../../lib/logic.bend as L import ../../lib/nat.bend as N import ../../../src/crypto/aes/types.bend as T import ../../../src/crypto/subtle.bend as Subtle import ../../../spec/crypto/aes/aes.bend as S import ../../../spec/crypto/aes/gcm.bend as G import ../../../spec/crypto/subtle.bend as Eq import ../subtle/laws.bend as EqLaws import ../subtle/proof.bend as EqProof # Generated by tools/generators/aes/aead.py. # AEAD correctness of the specification (SP 800-38D GCM over FIPS 197): # opening a sealed message gives the message back, and opening C || T with # a T other than the tag of C gives None. The implementation equals the # specification (gcm.bend), so both carry over to it (laws.bend). def bxor_inv(+x: Bool, +y: Bool) -> {Bool.xor(Bool.xor(x, y), y) == x : Bool}: match x y: case True{} True{}: {==} case True{} False{}: {==} case False{} True{}: {==} case False{} False{}: {==} def word_xor_inv(+n: Nat, +a: Word(n), +b: Word(n)) -> {Word.xor(n, Word.xor(n, a, b), b) == a : Word(n)}: match n a b: case 0n WNil{} WNil{}: {==} case 1n+p WCon{x, s} WCon{y, t}: %word_xor_inv(p, s, t) : {WCon{Bool.xor(Bool.xor(x, y), y), Word.xor(p, Word.xor(p, s, t), t)} == WCon{x, _} : Word(1n+p)} %bxor_inv(x, y) : {WCon{Bool.xor(Bool.xor(x, y), y), Word.xor(p, Word.xor(p, s, t), t)} == WCon{_, Word.xor(p, Word.xor(p, s, t), t)} : Word(1n+p)} {==} def xor_inv(+x: U32, +k: U32) -> {U32.xor(U32.xor(x, k), k) == x : U32}: match x k: case U32{a} U32{b}: Equal.cong(Word(32n), U32, w => U32{w}, Word.xor(32n, Word.xor(32n, a, b), b), a, word_xor_inv(32n, a, b)) def ks_ok(+st: T.State) -> {S.bytes_of(st) == [S.nth_byte(S.bytes_of(st), 0n), S.nth_byte(S.bytes_of(st), 1n), S.nth_byte(S.bytes_of(st), 2n), S.nth_byte(S.bytes_of(st), 3n), S.nth_byte(S.bytes_of(st), 4n), S.nth_byte(S.bytes_of(st), 5n), S.nth_byte(S.bytes_of(st), 6n), S.nth_byte(S.bytes_of(st), 7n), S.nth_byte(S.bytes_of(st), 8n), S.nth_byte(S.bytes_of(st), 9n), S.nth_byte(S.bytes_of(st), 10n), S.nth_byte(S.bytes_of(st), 11n), S.nth_byte(S.bytes_of(st), 12n), S.nth_byte(S.bytes_of(st), 13n), S.nth_byte(S.bytes_of(st), 14n), S.nth_byte(S.bytes_of(st), 15n)] : List<&2, U32>}: match st: case T.S{T.W{a0, a1, a2, a3}, T.W{a4, a5, a6, a7}, T.W{a8, a9, a10, a11}, T.W{a12, a13, a14, a15}}: {==} # Byte i of the keystream block of counter block cb. def kb(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +cb: List<&2, U32>, +i: Nat) -> U32: S.nth_byte(G.ciph(nk, nr, key, cb), i) # (x xor k) xor k == x, position by position. def cancel16(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +x13: U32, +x14: U32, +x15: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32, +k10: U32, +k11: U32, +k12: U32, +k13: U32, +k14: U32, +k15: U32, +r1: List<&2, U32>, +r2: List<&2, U32>, +e: {r1 == r2 : List<&2, U32>}) -> {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r2 : List<&2, U32>}: %e : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> _ : List<&2, U32>} %xor_inv(x0, k0) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == _ <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x1, k1) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> _ <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x2, k2) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> _ <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x3, k3) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> _ <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x4, k4) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> _ <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x5, k5) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> _ <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x6, k6) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> _ <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x7, k7) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> _ <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x8, k8) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> _ <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x9, k9) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> _ <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x10, k10) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> _ <> x11 <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x11, k11) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> _ <> x12 <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x12, k12) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> _ <> x13 <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x13, k13) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> _ <> x14 <> x15 <> r1 : List<&2, U32>} %xor_inv(x14, k14) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> _ <> x15 <> r1 : List<&2, U32>} %xor_inv(x15, k15) : {U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> U32.xor(U32.xor(x15, k15), k15) <> r1 == U32.xor(U32.xor(x0, k0), k0) <> U32.xor(U32.xor(x1, k1), k1) <> U32.xor(U32.xor(x2, k2), k2) <> U32.xor(U32.xor(x3, k3), k3) <> U32.xor(U32.xor(x4, k4), k4) <> U32.xor(U32.xor(x5, k5), k5) <> U32.xor(U32.xor(x6, k6), k6) <> U32.xor(U32.xor(x7, k7), k7) <> U32.xor(U32.xor(x8, k8), k8) <> U32.xor(U32.xor(x9, k9), k9) <> U32.xor(U32.xor(x10, k10), k10) <> U32.xor(U32.xor(x11, k11), k11) <> U32.xor(U32.xor(x12, k12), k12) <> U32.xor(U32.xor(x13, k13), k13) <> U32.xor(U32.xor(x14, k14), k14) <> _ <> r1 : List<&2, U32>} {==} def cancel1(+x0: U32, +k0: U32) -> {[U32.xor(U32.xor(x0, k0), k0)] == [x0] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0)] == [_] : List<&2, U32>} {==} def cancel2(+x0: U32, +x1: U32, +k0: U32, +k1: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1)] == [x0, x1] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1)] == [_, x1] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1)] == [U32.xor(U32.xor(x0, k0), k0), _] : List<&2, U32>} {==} def cancel3(+x0: U32, +x1: U32, +x2: U32, +k0: U32, +k1: U32, +k2: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2)] == [x0, x1, x2] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2)] == [_, x1, x2] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2)] == [U32.xor(U32.xor(x0, k0), k0), _, x2] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _] : List<&2, U32>} {==} def cancel4(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3)] == [x0, x1, x2, x3] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3)] == [_, x1, x2, x3] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _] : List<&2, U32>} {==} def cancel5(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4)] == [x0, x1, x2, x3, x4] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4)] == [_, x1, x2, x3, x4] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _] : List<&2, U32>} {==} def cancel6(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [x0, x1, x2, x3, x4, x5] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [_, x1, x2, x3, x4, x5] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _] : List<&2, U32>} {==} def cancel7(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [x0, x1, x2, x3, x4, x5, x6] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [_, x1, x2, x3, x4, x5, x6] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _] : List<&2, U32>} {==} def cancel8(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [x0, x1, x2, x3, x4, x5, x6, x7] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [_, x1, x2, x3, x4, x5, x6, x7] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _] : List<&2, U32>} {==} def cancel9(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [_, x1, x2, x3, x4, x5, x6, x7, x8] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _] : List<&2, U32>} {==} def cancel10(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [_, x1, x2, x3, x4, x5, x6, x7, x8, x9] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8, x9] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8, x9] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8, x9] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8, x9] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8, x9] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8, x9] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8, x9] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _, x9] : List<&2, U32>} %xor_inv(x9, k9) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), _] : List<&2, U32>} {==} def cancel11(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32, +k10: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [_, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8, x9, x10] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8, x9, x10] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _, x9, x10] : List<&2, U32>} %xor_inv(x9, k9) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), _, x10] : List<&2, U32>} %xor_inv(x10, k10) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), _] : List<&2, U32>} {==} def cancel12(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32, +k10: U32, +k11: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [_, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8, x9, x10, x11] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _, x9, x10, x11] : List<&2, U32>} %xor_inv(x9, k9) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), _, x10, x11] : List<&2, U32>} %xor_inv(x10, k10) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), _, x11] : List<&2, U32>} %xor_inv(x11, k11) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), _] : List<&2, U32>} {==} def cancel13(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32, +k10: U32, +k11: U32, +k12: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [_, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _, x9, x10, x11, x12] : List<&2, U32>} %xor_inv(x9, k9) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), _, x10, x11, x12] : List<&2, U32>} %xor_inv(x10, k10) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), _, x11, x12] : List<&2, U32>} %xor_inv(x11, k11) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), _, x12] : List<&2, U32>} %xor_inv(x12, k12) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), _] : List<&2, U32>} {==} def cancel14(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +x13: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32, +k10: U32, +k11: U32, +k12: U32, +k13: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [_, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _, x9, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x9, k9) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), _, x10, x11, x12, x13] : List<&2, U32>} %xor_inv(x10, k10) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), _, x11, x12, x13] : List<&2, U32>} %xor_inv(x11, k11) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), _, x12, x13] : List<&2, U32>} %xor_inv(x12, k12) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), _, x13] : List<&2, U32>} %xor_inv(x13, k13) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), _] : List<&2, U32>} {==} def cancel15(+x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +x13: U32, +x14: U32, +k0: U32, +k1: U32, +k2: U32, +k3: U32, +k4: U32, +k5: U32, +k6: U32, +k7: U32, +k8: U32, +k9: U32, +k10: U32, +k11: U32, +k12: U32, +k13: U32, +k14: U32) -> {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>}: %xor_inv(x0, k0) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [_, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x1, k1) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), _, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x2, k2) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), _, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x3, k3) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), _, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x4, k4) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), _, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x5, k5) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), _, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x6, k6) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), _, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x7, k7) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), _, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x8, k8) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), _, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x9, k9) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), _, x10, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x10, k10) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), _, x11, x12, x13, x14] : List<&2, U32>} %xor_inv(x11, k11) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), _, x12, x13, x14] : List<&2, U32>} %xor_inv(x12, k12) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), _, x13, x14] : List<&2, U32>} %xor_inv(x13, k13) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), _, x14] : List<&2, U32>} %xor_inv(x14, k14) : {[U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), U32.xor(U32.xor(x14, k14), k14)] == [U32.xor(U32.xor(x0, k0), k0), U32.xor(U32.xor(x1, k1), k1), U32.xor(U32.xor(x2, k2), k2), U32.xor(U32.xor(x3, k3), k3), U32.xor(U32.xor(x4, k4), k4), U32.xor(U32.xor(x5, k5), k5), U32.xor(U32.xor(x6, k6), k6), U32.xor(U32.xor(x7, k7), k7), U32.xor(U32.xor(x8, k8), k8), U32.xor(U32.xor(x9, k9), k9), U32.xor(U32.xor(x10, k10), k10), U32.xor(U32.xor(x11, k11), k11), U32.xor(U32.xor(x12, k12), k12), U32.xor(U32.xor(x13, k13), k13), _] : List<&2, U32>} {==} # One whole block of counter mode. def gctr_block(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +x13: U32, +x14: U32, +x15: U32, +rest: List<&2, U32>, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> rest, cb) == U32.xor(x0, kb(nk, nr, key, cb, 0n)) <> U32.xor(x1, kb(nk, nr, key, cb, 1n)) <> U32.xor(x2, kb(nk, nr, key, cb, 2n)) <> U32.xor(x3, kb(nk, nr, key, cb, 3n)) <> U32.xor(x4, kb(nk, nr, key, cb, 4n)) <> U32.xor(x5, kb(nk, nr, key, cb, 5n)) <> U32.xor(x6, kb(nk, nr, key, cb, 6n)) <> U32.xor(x7, kb(nk, nr, key, cb, 7n)) <> U32.xor(x8, kb(nk, nr, key, cb, 8n)) <> U32.xor(x9, kb(nk, nr, key, cb, 9n)) <> U32.xor(x10, kb(nk, nr, key, cb, 10n)) <> U32.xor(x11, kb(nk, nr, key, cb, 11n)) <> U32.xor(x12, kb(nk, nr, key, cb, 12n)) <> U32.xor(x13, kb(nk, nr, key, cb, 13n)) <> U32.xor(x14, kb(nk, nr, key, cb, 14n)) <> U32.xor(x15, kb(nk, nr, key, cb, 15n)) <> G.gctr(nk, nr, key, rest, G.inc32(cb)) : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {List.append(&2, U32, G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15], _), G.gctr(nk, nr, key, rest, G.inc32(cb))) == U32.xor(x0, kb(nk, nr, key, cb, 0n)) <> U32.xor(x1, kb(nk, nr, key, cb, 1n)) <> U32.xor(x2, kb(nk, nr, key, cb, 2n)) <> U32.xor(x3, kb(nk, nr, key, cb, 3n)) <> U32.xor(x4, kb(nk, nr, key, cb, 4n)) <> U32.xor(x5, kb(nk, nr, key, cb, 5n)) <> U32.xor(x6, kb(nk, nr, key, cb, 6n)) <> U32.xor(x7, kb(nk, nr, key, cb, 7n)) <> U32.xor(x8, kb(nk, nr, key, cb, 8n)) <> U32.xor(x9, kb(nk, nr, key, cb, 9n)) <> U32.xor(x10, kb(nk, nr, key, cb, 10n)) <> U32.xor(x11, kb(nk, nr, key, cb, 11n)) <> U32.xor(x12, kb(nk, nr, key, cb, 12n)) <> U32.xor(x13, kb(nk, nr, key, cb, 13n)) <> U32.xor(x14, kb(nk, nr, key, cb, 14n)) <> U32.xor(x15, kb(nk, nr, key, cb, 15n)) <> G.gctr(nk, nr, key, rest, G.inc32(cb)) : List<&2, U32>} {==} def gctr_part1(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n))] : List<&2, U32>} {==} def gctr_part2(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n))] : List<&2, U32>} {==} def gctr_part3(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n))] : List<&2, U32>} {==} def gctr_part4(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n))] : List<&2, U32>} {==} def gctr_part5(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n))] : List<&2, U32>} {==} def gctr_part6(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n))] : List<&2, U32>} {==} def gctr_part7(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n))] : List<&2, U32>} {==} def gctr_part8(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n))] : List<&2, U32>} {==} def gctr_part9(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n))] : List<&2, U32>} {==} def gctr_part10(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n))] : List<&2, U32>} {==} def gctr_part11(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n))] : List<&2, U32>} {==} def gctr_part12(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n))] : List<&2, U32>} {==} def gctr_part13(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n))] : List<&2, U32>} {==} def gctr_part14(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +x13: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n))] : List<&2, U32>} {==} def gctr_part15(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +x0: U32, +x1: U32, +x2: U32, +x3: U32, +x4: U32, +x5: U32, +x6: U32, +x7: U32, +x8: U32, +x9: U32, +x10: U32, +x11: U32, +x12: U32, +x13: U32, +x14: U32, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14], cb) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), U32.xor(x14, kb(nk, nr, key, cb, 14n))] : List<&2, U32>}: %Equal.sym(List<&2, U32>, S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), [S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 0n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 1n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 2n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 3n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 4n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 5n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 6n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 7n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 8n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 9n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 10n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 11n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 12n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 13n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 14n), S.nth_byte(S.bytes_of(S.encrypt(nk, nr, key, S.state_of(cb))), 15n)], ks_ok(S.encrypt(nk, nr, key, S.state_of(cb)))) : {G.xor_bytes([x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14], _) == [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), U32.xor(x14, kb(nk, nr, key, cb, 14n))] : List<&2, U32>} {==} # Counter mode is an involution (the keystream is XORed twice). def gctr_inv(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +xs: List<&2, U32>, +cb: List<&2, U32>) -> {G.gctr(nk, nr, key, G.gctr(nk, nr, key, xs, cb), cb) == xs : List<&2, U32>}: match xs: case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> rest: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> rest, cb), U32.xor(x0, kb(nk, nr, key, cb, 0n)) <> U32.xor(x1, kb(nk, nr, key, cb, 1n)) <> U32.xor(x2, kb(nk, nr, key, cb, 2n)) <> U32.xor(x3, kb(nk, nr, key, cb, 3n)) <> U32.xor(x4, kb(nk, nr, key, cb, 4n)) <> U32.xor(x5, kb(nk, nr, key, cb, 5n)) <> U32.xor(x6, kb(nk, nr, key, cb, 6n)) <> U32.xor(x7, kb(nk, nr, key, cb, 7n)) <> U32.xor(x8, kb(nk, nr, key, cb, 8n)) <> U32.xor(x9, kb(nk, nr, key, cb, 9n)) <> U32.xor(x10, kb(nk, nr, key, cb, 10n)) <> U32.xor(x11, kb(nk, nr, key, cb, 11n)) <> U32.xor(x12, kb(nk, nr, key, cb, 12n)) <> U32.xor(x13, kb(nk, nr, key, cb, 13n)) <> U32.xor(x14, kb(nk, nr, key, cb, 14n)) <> U32.xor(x15, kb(nk, nr, key, cb, 15n)) <> G.gctr(nk, nr, key, rest, G.inc32(cb)), gctr_block(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15, rest, cb)) : {G.gctr(nk, nr, key, _, cb) == x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> rest : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)) <> U32.xor(x1, kb(nk, nr, key, cb, 1n)) <> U32.xor(x2, kb(nk, nr, key, cb, 2n)) <> U32.xor(x3, kb(nk, nr, key, cb, 3n)) <> U32.xor(x4, kb(nk, nr, key, cb, 4n)) <> U32.xor(x5, kb(nk, nr, key, cb, 5n)) <> U32.xor(x6, kb(nk, nr, key, cb, 6n)) <> U32.xor(x7, kb(nk, nr, key, cb, 7n)) <> U32.xor(x8, kb(nk, nr, key, cb, 8n)) <> U32.xor(x9, kb(nk, nr, key, cb, 9n)) <> U32.xor(x10, kb(nk, nr, key, cb, 10n)) <> U32.xor(x11, kb(nk, nr, key, cb, 11n)) <> U32.xor(x12, kb(nk, nr, key, cb, 12n)) <> U32.xor(x13, kb(nk, nr, key, cb, 13n)) <> U32.xor(x14, kb(nk, nr, key, cb, 14n)) <> U32.xor(x15, kb(nk, nr, key, cb, 15n)) <> G.gctr(nk, nr, key, rest, G.inc32(cb)), cb), U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)) <> U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)) <> U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)) <> U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)) <> U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)) <> U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)) <> U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)) <> U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)) <> U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)) <> U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n)) <> U32.xor(U32.xor(x10, kb(nk, nr, key, cb, 10n)), kb(nk, nr, key, cb, 10n)) <> U32.xor(U32.xor(x11, kb(nk, nr, key, cb, 11n)), kb(nk, nr, key, cb, 11n)) <> U32.xor(U32.xor(x12, kb(nk, nr, key, cb, 12n)), kb(nk, nr, key, cb, 12n)) <> U32.xor(U32.xor(x13, kb(nk, nr, key, cb, 13n)), kb(nk, nr, key, cb, 13n)) <> U32.xor(U32.xor(x14, kb(nk, nr, key, cb, 14n)), kb(nk, nr, key, cb, 14n)) <> U32.xor(U32.xor(x15, kb(nk, nr, key, cb, 15n)), kb(nk, nr, key, cb, 15n)) <> G.gctr(nk, nr, key, G.gctr(nk, nr, key, rest, G.inc32(cb)), G.inc32(cb)), gctr_block(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), U32.xor(x14, kb(nk, nr, key, cb, 14n)), U32.xor(x15, kb(nk, nr, key, cb, 15n)), G.gctr(nk, nr, key, rest, G.inc32(cb)), cb)) : {_ == x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> x15 <> rest : List<&2, U32>} cancel16(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n), kb(nk, nr, key, cb, 10n), kb(nk, nr, key, cb, 11n), kb(nk, nr, key, cb, 12n), kb(nk, nr, key, cb, 13n), kb(nk, nr, key, cb, 14n), kb(nk, nr, key, cb, 15n), G.gctr(nk, nr, key, G.gctr(nk, nr, key, rest, G.inc32(cb)), G.inc32(cb)), rest, gctr_inv(nk, nr, key, rest, G.inc32(cb))) case Nil{}: {==} case x0 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n))], gctr_part1(nk, nr, key, x0, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n))], gctr_part1(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), cb)) : {_ == [x0] : List<&2, U32>} cancel1(x0, kb(nk, nr, key, cb, 0n)) case x0 <> x1 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n))], gctr_part2(nk, nr, key, x0, x1, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n))], gctr_part2(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), cb)) : {_ == [x0, x1] : List<&2, U32>} cancel2(x0, x1, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n)) case x0 <> x1 <> x2 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n))], gctr_part3(nk, nr, key, x0, x1, x2, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n))], gctr_part3(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), cb)) : {_ == [x0, x1, x2] : List<&2, U32>} cancel3(x0, x1, x2, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n)) case x0 <> x1 <> x2 <> x3 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n))], gctr_part4(nk, nr, key, x0, x1, x2, x3, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n))], gctr_part4(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), cb)) : {_ == [x0, x1, x2, x3] : List<&2, U32>} cancel4(x0, x1, x2, x3, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n)) case x0 <> x1 <> x2 <> x3 <> x4 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n))], gctr_part5(nk, nr, key, x0, x1, x2, x3, x4, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n))], gctr_part5(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), cb)) : {_ == [x0, x1, x2, x3, x4] : List<&2, U32>} cancel5(x0, x1, x2, x3, x4, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n))], gctr_part6(nk, nr, key, x0, x1, x2, x3, x4, x5, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n))], gctr_part6(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5] : List<&2, U32>} cancel6(x0, x1, x2, x3, x4, x5, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n))], gctr_part7(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n))], gctr_part7(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6] : List<&2, U32>} cancel7(x0, x1, x2, x3, x4, x5, x6, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n))], gctr_part8(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n))], gctr_part8(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7] : List<&2, U32>} cancel8(x0, x1, x2, x3, x4, x5, x6, x7, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n))], gctr_part9(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n))], gctr_part9(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8] : List<&2, U32>} cancel9(x0, x1, x2, x3, x4, x5, x6, x7, x8, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n))], gctr_part10(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)), U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n))], gctr_part10(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9] : List<&2, U32>} cancel10(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n))], gctr_part11(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)), U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n)), U32.xor(U32.xor(x10, kb(nk, nr, key, cb, 10n)), kb(nk, nr, key, cb, 10n))], gctr_part11(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10] : List<&2, U32>} cancel11(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n), kb(nk, nr, key, cb, 10n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n))], gctr_part12(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)), U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n)), U32.xor(U32.xor(x10, kb(nk, nr, key, cb, 10n)), kb(nk, nr, key, cb, 10n)), U32.xor(U32.xor(x11, kb(nk, nr, key, cb, 11n)), kb(nk, nr, key, cb, 11n))], gctr_part12(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11] : List<&2, U32>} cancel12(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n), kb(nk, nr, key, cb, 10n), kb(nk, nr, key, cb, 11n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n))], gctr_part13(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)), U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n)), U32.xor(U32.xor(x10, kb(nk, nr, key, cb, 10n)), kb(nk, nr, key, cb, 10n)), U32.xor(U32.xor(x11, kb(nk, nr, key, cb, 11n)), kb(nk, nr, key, cb, 11n)), U32.xor(U32.xor(x12, kb(nk, nr, key, cb, 12n)), kb(nk, nr, key, cb, 12n))], gctr_part13(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12] : List<&2, U32>} cancel13(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n), kb(nk, nr, key, cb, 10n), kb(nk, nr, key, cb, 11n), kb(nk, nr, key, cb, 12n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n))], gctr_part14(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)), U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n)), U32.xor(U32.xor(x10, kb(nk, nr, key, cb, 10n)), kb(nk, nr, key, cb, 10n)), U32.xor(U32.xor(x11, kb(nk, nr, key, cb, 11n)), kb(nk, nr, key, cb, 11n)), U32.xor(U32.xor(x12, kb(nk, nr, key, cb, 12n)), kb(nk, nr, key, cb, 12n)), U32.xor(U32.xor(x13, kb(nk, nr, key, cb, 13n)), kb(nk, nr, key, cb, 13n))], gctr_part14(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13] : List<&2, U32>} cancel14(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n), kb(nk, nr, key, cb, 10n), kb(nk, nr, key, cb, 11n), kb(nk, nr, key, cb, 12n), kb(nk, nr, key, cb, 13n)) case x0 <> x1 <> x2 <> x3 <> x4 <> x5 <> x6 <> x7 <> x8 <> x9 <> x10 <> x11 <> x12 <> x13 <> x14 <> Nil{}: %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14], cb), [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), U32.xor(x14, kb(nk, nr, key, cb, 14n))], gctr_part15(nk, nr, key, x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, cb)) : {G.gctr(nk, nr, key, _, cb) == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, [U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), U32.xor(x14, kb(nk, nr, key, cb, 14n))], cb), [U32.xor(U32.xor(x0, kb(nk, nr, key, cb, 0n)), kb(nk, nr, key, cb, 0n)), U32.xor(U32.xor(x1, kb(nk, nr, key, cb, 1n)), kb(nk, nr, key, cb, 1n)), U32.xor(U32.xor(x2, kb(nk, nr, key, cb, 2n)), kb(nk, nr, key, cb, 2n)), U32.xor(U32.xor(x3, kb(nk, nr, key, cb, 3n)), kb(nk, nr, key, cb, 3n)), U32.xor(U32.xor(x4, kb(nk, nr, key, cb, 4n)), kb(nk, nr, key, cb, 4n)), U32.xor(U32.xor(x5, kb(nk, nr, key, cb, 5n)), kb(nk, nr, key, cb, 5n)), U32.xor(U32.xor(x6, kb(nk, nr, key, cb, 6n)), kb(nk, nr, key, cb, 6n)), U32.xor(U32.xor(x7, kb(nk, nr, key, cb, 7n)), kb(nk, nr, key, cb, 7n)), U32.xor(U32.xor(x8, kb(nk, nr, key, cb, 8n)), kb(nk, nr, key, cb, 8n)), U32.xor(U32.xor(x9, kb(nk, nr, key, cb, 9n)), kb(nk, nr, key, cb, 9n)), U32.xor(U32.xor(x10, kb(nk, nr, key, cb, 10n)), kb(nk, nr, key, cb, 10n)), U32.xor(U32.xor(x11, kb(nk, nr, key, cb, 11n)), kb(nk, nr, key, cb, 11n)), U32.xor(U32.xor(x12, kb(nk, nr, key, cb, 12n)), kb(nk, nr, key, cb, 12n)), U32.xor(U32.xor(x13, kb(nk, nr, key, cb, 13n)), kb(nk, nr, key, cb, 13n)), U32.xor(U32.xor(x14, kb(nk, nr, key, cb, 14n)), kb(nk, nr, key, cb, 14n))], gctr_part15(nk, nr, key, U32.xor(x0, kb(nk, nr, key, cb, 0n)), U32.xor(x1, kb(nk, nr, key, cb, 1n)), U32.xor(x2, kb(nk, nr, key, cb, 2n)), U32.xor(x3, kb(nk, nr, key, cb, 3n)), U32.xor(x4, kb(nk, nr, key, cb, 4n)), U32.xor(x5, kb(nk, nr, key, cb, 5n)), U32.xor(x6, kb(nk, nr, key, cb, 6n)), U32.xor(x7, kb(nk, nr, key, cb, 7n)), U32.xor(x8, kb(nk, nr, key, cb, 8n)), U32.xor(x9, kb(nk, nr, key, cb, 9n)), U32.xor(x10, kb(nk, nr, key, cb, 10n)), U32.xor(x11, kb(nk, nr, key, cb, 11n)), U32.xor(x12, kb(nk, nr, key, cb, 12n)), U32.xor(x13, kb(nk, nr, key, cb, 13n)), U32.xor(x14, kb(nk, nr, key, cb, 14n)), cb)) : {_ == [x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14] : List<&2, U32>} cancel15(x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, kb(nk, nr, key, cb, 0n), kb(nk, nr, key, cb, 1n), kb(nk, nr, key, cb, 2n), kb(nk, nr, key, cb, 3n), kb(nk, nr, key, cb, 4n), kb(nk, nr, key, cb, 5n), kb(nk, nr, key, cb, 6n), kb(nk, nr, key, cb, 7n), kb(nk, nr, key, cb, 8n), kb(nk, nr, key, cb, 9n), kb(nk, nr, key, cb, 10n), kb(nk, nr, key, cb, 11n), kb(nk, nr, key, cb, 12n), kb(nk, nr, key, cb, 13n), kb(nk, nr, key, cb, 14n)) def bb16(+w: Word(128n)) -> {G.block_bytes(w) == [S.nth_byte(G.block_bytes(w), 0n), S.nth_byte(G.block_bytes(w), 1n), S.nth_byte(G.block_bytes(w), 2n), S.nth_byte(G.block_bytes(w), 3n), S.nth_byte(G.block_bytes(w), 4n), S.nth_byte(G.block_bytes(w), 5n), S.nth_byte(G.block_bytes(w), 6n), S.nth_byte(G.block_bytes(w), 7n), S.nth_byte(G.block_bytes(w), 8n), S.nth_byte(G.block_bytes(w), 9n), S.nth_byte(G.block_bytes(w), 10n), S.nth_byte(G.block_bytes(w), 11n), S.nth_byte(G.block_bytes(w), 12n), S.nth_byte(G.block_bytes(w), 13n), S.nth_byte(G.block_bytes(w), 14n), S.nth_byte(G.block_bytes(w), 15n)] : List<&2, U32>}: match w: case WCon{w0, WCon{w1, WCon{w2, WCon{w3, WCon{w4, WCon{w5, WCon{w6, WCon{w7, WCon{w8, WCon{w9, WCon{w10, WCon{w11, WCon{w12, WCon{w13, WCon{w14, WCon{w15, WCon{w16, WCon{w17, WCon{w18, WCon{w19, WCon{w20, WCon{w21, WCon{w22, WCon{w23, WCon{w24, WCon{w25, WCon{w26, WCon{w27, WCon{w28, WCon{w29, WCon{w30, WCon{w31, WCon{w32, WCon{w33, WCon{w34, WCon{w35, WCon{w36, WCon{w37, WCon{w38, WCon{w39, WCon{w40, WCon{w41, WCon{w42, WCon{w43, WCon{w44, WCon{w45, WCon{w46, WCon{w47, WCon{w48, WCon{w49, WCon{w50, WCon{w51, WCon{w52, WCon{w53, WCon{w54, WCon{w55, WCon{w56, WCon{w57, WCon{w58, WCon{w59, WCon{w60, WCon{w61, WCon{w62, WCon{w63, WCon{w64, WCon{w65, WCon{w66, WCon{w67, WCon{w68, WCon{w69, WCon{w70, WCon{w71, WCon{w72, WCon{w73, WCon{w74, WCon{w75, WCon{w76, WCon{w77, WCon{w78, WCon{w79, WCon{w80, WCon{w81, WCon{w82, WCon{w83, WCon{w84, WCon{w85, WCon{w86, WCon{w87, WCon{w88, WCon{w89, WCon{w90, WCon{w91, WCon{w92, WCon{w93, WCon{w94, WCon{w95, WCon{w96, WCon{w97, WCon{w98, WCon{w99, WCon{w100, WCon{w101, WCon{w102, WCon{w103, WCon{w104, WCon{w105, WCon{w106, WCon{w107, WCon{w108, WCon{w109, WCon{w110, WCon{w111, WCon{w112, WCon{w113, WCon{w114, WCon{w115, WCon{w116, WCon{w117, WCon{w118, WCon{w119, WCon{w120, WCon{w121, WCon{w122, WCon{w123, WCon{w124, WCon{w125, WCon{w126, WCon{w127, WNil{}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}: {==} # The GHASH block of the tag, as bytes, and byte i of the tag. def hb(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +aad: List<&2, U32>, +c: List<&2, U32>) -> List<&2, U32>: G.block_bytes(G.ghash(G.hash_key(nk, nr, key), List.append(&2, U32, G.pad(aad), List.append(&2, U32, G.pad(c), List.append(&2, U32, G.len64(aad), G.len64(c)))), Word.zero(128n))) def tb(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +iv: List<&2, U32>, +aad: List<&2, U32>, +c: List<&2, U32>, +i: Nat) -> U32: U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), i), kb(nk, nr, key, G.j0(iv), i)) # The tag is a 16-byte list. def tag16(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +iv: List<&2, U32>, +aad: List<&2, U32>, +c: List<&2, U32>) -> {G.tag(nk, nr, key, iv, aad, c) == [tb(nk, nr, key, iv, aad, c, 0n), tb(nk, nr, key, iv, aad, c, 1n), tb(nk, nr, key, iv, aad, c, 2n), tb(nk, nr, key, iv, aad, c, 3n), tb(nk, nr, key, iv, aad, c, 4n), tb(nk, nr, key, iv, aad, c, 5n), tb(nk, nr, key, iv, aad, c, 6n), tb(nk, nr, key, iv, aad, c, 7n), tb(nk, nr, key, iv, aad, c, 8n), tb(nk, nr, key, iv, aad, c, 9n), tb(nk, nr, key, iv, aad, c, 10n), tb(nk, nr, key, iv, aad, c, 11n), tb(nk, nr, key, iv, aad, c, 12n), tb(nk, nr, key, iv, aad, c, 13n), tb(nk, nr, key, iv, aad, c, 14n), tb(nk, nr, key, iv, aad, c, 15n)] : List<&2, U32>}: %Equal.sym(List<&2, U32>, hb(nk, nr, key, aad, c), [S.nth_byte(hb(nk, nr, key, aad, c), 0n), S.nth_byte(hb(nk, nr, key, aad, c), 1n), S.nth_byte(hb(nk, nr, key, aad, c), 2n), S.nth_byte(hb(nk, nr, key, aad, c), 3n), S.nth_byte(hb(nk, nr, key, aad, c), 4n), S.nth_byte(hb(nk, nr, key, aad, c), 5n), S.nth_byte(hb(nk, nr, key, aad, c), 6n), S.nth_byte(hb(nk, nr, key, aad, c), 7n), S.nth_byte(hb(nk, nr, key, aad, c), 8n), S.nth_byte(hb(nk, nr, key, aad, c), 9n), S.nth_byte(hb(nk, nr, key, aad, c), 10n), S.nth_byte(hb(nk, nr, key, aad, c), 11n), S.nth_byte(hb(nk, nr, key, aad, c), 12n), S.nth_byte(hb(nk, nr, key, aad, c), 13n), S.nth_byte(hb(nk, nr, key, aad, c), 14n), S.nth_byte(hb(nk, nr, key, aad, c), 15n)], bb16(G.ghash(G.hash_key(nk, nr, key), List.append(&2, U32, G.pad(aad), List.append(&2, U32, G.pad(c), List.append(&2, U32, G.len64(aad), G.len64(c)))), Word.zero(128n)))) : {G.gctr(nk, nr, key, _, G.j0(iv)) == [tb(nk, nr, key, iv, aad, c, 0n), tb(nk, nr, key, iv, aad, c, 1n), tb(nk, nr, key, iv, aad, c, 2n), tb(nk, nr, key, iv, aad, c, 3n), tb(nk, nr, key, iv, aad, c, 4n), tb(nk, nr, key, iv, aad, c, 5n), tb(nk, nr, key, iv, aad, c, 6n), tb(nk, nr, key, iv, aad, c, 7n), tb(nk, nr, key, iv, aad, c, 8n), tb(nk, nr, key, iv, aad, c, 9n), tb(nk, nr, key, iv, aad, c, 10n), tb(nk, nr, key, iv, aad, c, 11n), tb(nk, nr, key, iv, aad, c, 12n), tb(nk, nr, key, iv, aad, c, 13n), tb(nk, nr, key, iv, aad, c, 14n), tb(nk, nr, key, iv, aad, c, 15n)] : List<&2, U32>} %Equal.sym(List<&2, U32>, G.gctr(nk, nr, key, S.nth_byte(hb(nk, nr, key, aad, c), 0n) <> S.nth_byte(hb(nk, nr, key, aad, c), 1n) <> S.nth_byte(hb(nk, nr, key, aad, c), 2n) <> S.nth_byte(hb(nk, nr, key, aad, c), 3n) <> S.nth_byte(hb(nk, nr, key, aad, c), 4n) <> S.nth_byte(hb(nk, nr, key, aad, c), 5n) <> S.nth_byte(hb(nk, nr, key, aad, c), 6n) <> S.nth_byte(hb(nk, nr, key, aad, c), 7n) <> S.nth_byte(hb(nk, nr, key, aad, c), 8n) <> S.nth_byte(hb(nk, nr, key, aad, c), 9n) <> S.nth_byte(hb(nk, nr, key, aad, c), 10n) <> S.nth_byte(hb(nk, nr, key, aad, c), 11n) <> S.nth_byte(hb(nk, nr, key, aad, c), 12n) <> S.nth_byte(hb(nk, nr, key, aad, c), 13n) <> S.nth_byte(hb(nk, nr, key, aad, c), 14n) <> S.nth_byte(hb(nk, nr, key, aad, c), 15n) <> Nil{}, G.j0(iv)), U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 0n), kb(nk, nr, key, G.j0(iv), 0n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 1n), kb(nk, nr, key, G.j0(iv), 1n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 2n), kb(nk, nr, key, G.j0(iv), 2n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 3n), kb(nk, nr, key, G.j0(iv), 3n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 4n), kb(nk, nr, key, G.j0(iv), 4n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 5n), kb(nk, nr, key, G.j0(iv), 5n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 6n), kb(nk, nr, key, G.j0(iv), 6n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 7n), kb(nk, nr, key, G.j0(iv), 7n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 8n), kb(nk, nr, key, G.j0(iv), 8n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 9n), kb(nk, nr, key, G.j0(iv), 9n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 10n), kb(nk, nr, key, G.j0(iv), 10n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 11n), kb(nk, nr, key, G.j0(iv), 11n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 12n), kb(nk, nr, key, G.j0(iv), 12n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 13n), kb(nk, nr, key, G.j0(iv), 13n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 14n), kb(nk, nr, key, G.j0(iv), 14n)) <> U32.xor(S.nth_byte(hb(nk, nr, key, aad, c), 15n), kb(nk, nr, key, G.j0(iv), 15n)) <> G.gctr(nk, nr, key, Nil{}, G.inc32(G.j0(iv))), gctr_block(nk, nr, key, S.nth_byte(hb(nk, nr, key, aad, c), 0n), S.nth_byte(hb(nk, nr, key, aad, c), 1n), S.nth_byte(hb(nk, nr, key, aad, c), 2n), S.nth_byte(hb(nk, nr, key, aad, c), 3n), S.nth_byte(hb(nk, nr, key, aad, c), 4n), S.nth_byte(hb(nk, nr, key, aad, c), 5n), S.nth_byte(hb(nk, nr, key, aad, c), 6n), S.nth_byte(hb(nk, nr, key, aad, c), 7n), S.nth_byte(hb(nk, nr, key, aad, c), 8n), S.nth_byte(hb(nk, nr, key, aad, c), 9n), S.nth_byte(hb(nk, nr, key, aad, c), 10n), S.nth_byte(hb(nk, nr, key, aad, c), 11n), S.nth_byte(hb(nk, nr, key, aad, c), 12n), S.nth_byte(hb(nk, nr, key, aad, c), 13n), S.nth_byte(hb(nk, nr, key, aad, c), 14n), S.nth_byte(hb(nk, nr, key, aad, c), 15n), Nil{}, G.j0(iv))) : {_ == [tb(nk, nr, key, iv, aad, c, 0n), tb(nk, nr, key, iv, aad, c, 1n), tb(nk, nr, key, iv, aad, c, 2n), tb(nk, nr, key, iv, aad, c, 3n), tb(nk, nr, key, iv, aad, c, 4n), tb(nk, nr, key, iv, aad, c, 5n), tb(nk, nr, key, iv, aad, c, 6n), tb(nk, nr, key, iv, aad, c, 7n), tb(nk, nr, key, iv, aad, c, 8n), tb(nk, nr, key, iv, aad, c, 9n), tb(nk, nr, key, iv, aad, c, 10n), tb(nk, nr, key, iv, aad, c, 11n), tb(nk, nr, key, iv, aad, c, 12n), tb(nk, nr, key, iv, aad, c, 13n), tb(nk, nr, key, iv, aad, c, 14n), tb(nk, nr, key, iv, aad, c, 15n)] : List<&2, U32>} {==} # Splitting C || T (T of 16 bytes) back into C and T. def not_short(+c: List<&2, U32>, +t0: U32, +t1: U32, +t2: U32, +t3: U32, +t4: U32, +t5: U32, +t6: U32, +t7: U32, +t8: U32, +t9: U32, +t10: U32, +t11: U32, +t12: U32, +t13: U32, +t14: U32, +t15: U32) -> {Nat.is_lt(List.length(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n) == False{} : Bool}: match c: case Nil{}: {==} case x <> r: N.le_not_lt(1n+List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n, N.le_trans(16n, List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 1n+List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), N.not_lt_le(List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n, not_short(r, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)), N.le_succ(List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]))))) def sub16(+c: List<&2, U32>, +t0: U32, +t1: U32, +t2: U32, +t3: U32, +t4: U32, +t5: U32, +t6: U32, +t7: U32, +t8: U32, +t9: U32, +t10: U32, +t11: U32, +t12: U32, +t13: U32, +t14: U32, +t15: U32) -> {Nat.sub(List.length(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n) == List.length(&2, U32, c) : Nat}: match c: case Nil{}: {==} case x <> r: %Equal.sym(Nat, Nat.sub(1n+List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n), 1n+Nat.sub(List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n), N.sub_succ_left(List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n, N.not_lt_le(List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n, not_short(r, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)))) : {_ == 1n+List.length(&2, U32, r) : Nat} %sub16(r, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15) : {1n+Nat.sub(List.length(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n) == 1n+_ : Nat} {==} def take_app(+c: List<&2, U32>, +t0: U32, +t1: U32, +t2: U32, +t3: U32, +t4: U32, +t5: U32, +t6: U32, +t7: U32, +t8: U32, +t9: U32, +t10: U32, +t11: U32, +t12: U32, +t13: U32, +t14: U32, +t15: U32) -> {List.take(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, c)) == c : List<&2, U32>}: match c: case Nil{}: {==} case x <> r: %take_app(r, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15) : {x <> List.take(&2, U32, List.append(&2, U32, r, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, r)) == x <> _ : List<&2, U32>} {==} def drop_app(+c: List<&2, U32>, +t0: U32, +t1: U32, +t2: U32, +t3: U32, +t4: U32, +t5: U32, +t6: U32, +t7: U32, +t8: U32, +t9: U32, +t10: U32, +t11: U32, +t12: U32, +t13: U32, +t14: U32, +t15: U32) -> {List.drop(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, c)) == [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15] : List<&2, U32>}: match c: case Nil{}: {==} case x <> r: drop_app(r, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15) def open_append(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +iv: List<&2, U32>, +aad: List<&2, U32>, +c: List<&2, U32>, +t0: U32, +t1: U32, +t2: U32, +t3: U32, +t4: U32, +t5: U32, +t6: U32, +t7: U32, +t8: U32, +t9: U32, +t10: U32, +t11: U32, +t12: U32, +t13: U32, +t14: U32, +t15: U32) -> {G.open(nk, nr, key, iv, aad, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])) == G.open_checked(nk, nr, key, iv, aad, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]) : Maybe<&2, List<&2, U32>>}: %Equal.sym(Bool, Nat.is_lt(List.length(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n), False{}, not_short(c, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)) : {G.open_split(nk, nr, key, iv, aad, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), _) == G.open_checked(nk, nr, key, iv, aad, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]) : Maybe<&2, List<&2, U32>>} %Equal.sym(Nat, Nat.sub(List.length(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), 16n), List.length(&2, U32, c), sub16(c, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)) : {G.open_checked(nk, nr, key, iv, aad, List.take(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), _), List.drop(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), _)) == G.open_checked(nk, nr, key, iv, aad, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]) : Maybe<&2, List<&2, U32>>} %Equal.sym(List<&2, U32>, List.take(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, c)), c, take_app(c, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)) : {G.open_checked(nk, nr, key, iv, aad, _, List.drop(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, c))) == G.open_checked(nk, nr, key, iv, aad, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]) : Maybe<&2, List<&2, U32>>} %Equal.sym(List<&2, U32>, List.drop(&2, U32, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), List.length(&2, U32, c)), [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15], drop_app(c, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)) : {G.open_checked(nk, nr, key, iv, aad, c, _) == G.open_checked(nk, nr, key, iv, aad, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]) : Maybe<&2, List<&2, U32>>} {==} def equal_refl(+xs: List<&2, U32>) -> {Eq.equal(xs, xs) == True{} : Bool}: Equal.trans(Bool, Eq.equal(xs, xs), Subtle.eq(xs, xs), True{}, Equal.sym(Bool, Subtle.eq(xs, xs), Eq.equal(xs, xs), EqLaws.Eq.value(xs, xs)), EqLaws.Eq.refl(xs)) def false_of(+b: Bool, f: {b == True{} : Bool} -> Empty) -> {b == False{} : Bool}: match b: case True{}: Empty.absurd({True{} == False{} : Bool}, f({==})) case False{}: {==} def equal_false(+a: List<&2, U32>, +b: List<&2, U32>, ne: {a != b : List<&2, U32>}) -> {Eq.equal(a, b) == False{} : Bool}: false_of(Eq.equal(a, b), e => ne(EqLaws.Eq.sound(a, b, Equal.trans(Bool, Subtle.eq(a, b), Eq.equal(a, b), True{}, EqLaws.Eq.value(a, b), e)))) # Opening what seal produced gives the plaintext back. def roundtrip(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +iv: List<&2, U32>, +aad: List<&2, U32>, +pt: List<&2, U32>) -> {G.open(nk, nr, key, iv, aad, G.seal(nk, nr, key, iv, aad, pt)) == Some{pt} : Maybe<&2, List<&2, U32>>}: %Equal.sym(List<&2, U32>, G.tag(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv)))), [tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)], tag16(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))))) : {G.open(nk, nr, key, iv, aad, List.append(&2, U32, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), _)) == Some{pt} : Maybe<&2, List<&2, U32>>} %Equal.sym(Maybe<&2, List<&2, U32>>, G.open(nk, nr, key, iv, aad, List.append(&2, U32, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), [tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)])), G.open_checked(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), [tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)]), open_append(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n))) : {_ == Some{pt} : Maybe<&2, List<&2, U32>>} %Equal.sym(List<&2, U32>, G.tag(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv)))), [tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)], tag16(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))))) : {G.accept(Eq.equal([tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)], _), G.gctr(nk, nr, key, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), G.inc32(G.j0(iv)))) == Some{pt} : Maybe<&2, List<&2, U32>>} %Equal.sym(Bool, Eq.equal([tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)], [tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)]), True{}, equal_refl([tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 0n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 1n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 2n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 3n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 4n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 5n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 6n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 7n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 8n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 9n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 10n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 11n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 12n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 13n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 14n), tb(nk, nr, key, iv, aad, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), 15n)])) : {G.accept(_, G.gctr(nk, nr, key, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), G.inc32(G.j0(iv)))) == Some{pt} : Maybe<&2, List<&2, U32>>} %gctr_inv(nk, nr, key, pt, G.inc32(G.j0(iv))) : {Some{G.gctr(nk, nr, key, G.gctr(nk, nr, key, pt, G.inc32(G.j0(iv))), G.inc32(G.j0(iv)))} == Some{_} : Maybe<&2, List<&2, U32>>} {==} # Opening C || T with T other than the tag of C gives None. def forgery(+nk: Nat, +nr: Nat, +key: List<&2, U32>, +iv: List<&2, U32>, +aad: List<&2, U32>, +c: List<&2, U32>, +t0: U32, +t1: U32, +t2: U32, +t3: U32, +t4: U32, +t5: U32, +t6: U32, +t7: U32, +t8: U32, +t9: U32, +t10: U32, +t11: U32, +t12: U32, +t13: U32, +t14: U32, +t15: U32, ne: {[t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15] != G.tag(nk, nr, key, iv, aad, c) : List<&2, U32>}) -> {G.open(nk, nr, key, iv, aad, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])) == None{} : Maybe<&2, List<&2, U32>>}: %Equal.sym(Maybe<&2, List<&2, U32>>, G.open(nk, nr, key, iv, aad, List.append(&2, U32, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15])), G.open_checked(nk, nr, key, iv, aad, c, [t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15]), open_append(nk, nr, key, iv, aad, c, t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15)) : {_ == None{} : Maybe<&2, List<&2, U32>>} %Equal.sym(Bool, Eq.equal([t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15], G.tag(nk, nr, key, iv, aad, c)), False{}, equal_false([t0, t1, t2, t3, t4, t5, t6, t7, t8, t9, t10, t11, t12, t13, t14, t15], G.tag(nk, nr, key, iv, aad, c), ne)) : {G.accept(_, G.gctr(nk, nr, key, c, G.inc32(G.j0(iv)))) == None{} : Maybe<&2, List<&2, U32>>} {==}