Z) : FF2(X, Y, Z) = ((X) ^ ROL32((X), 9) ^ ROL32((X), 15) ^ ROL32((X), 9) ^ (X(rs2) >> 29) ^ (X(rs2) << 18) ^ (X(rs2) << 18) ^ (X(rs2) << 31) ^ (X(rs2) << 13) ; let z : bits(32) = ic0[31..24] @ ic1[23..16] @ ic2[15.. 8] @ ic0[ 7.. 0]; let oc2 : bits(32) = 0; for (int bit = 0; let x3 : bits(32) = aes_mixcolumn_inv(aes_get_column(x, 0)); let oc1 : bits(32) -> bits(32) function ROL32(x,n) = (X << N) | (X >>
extracts