_ZN11ArgsManagerD2Ev:
  130|      2|ArgsManager::~ArgsManager() = default;

_ZN15ChaCha20AlignedD2Ev:
   42|      4|{
   43|      4|    memory_cleanse(input, sizeof(input));
   44|      4|}
_ZN8ChaCha20D2Ev:
  332|      4|{
  333|      4|    memory_cleanse(m_buffer.data(), m_buffer.size());
  334|      4|}

_ZN9ChainCodeD2Ev:
   28|      2|    ~ChainCode() { memory_cleanse(data(), size()); }

_ZN4CKey5CheckEPKh:
  159|  4.20k|bool CKey::Check(const unsigned char *vch) {
  160|  4.20k|    return secp256k1_ec_seckey_verify(secp256k1_context_static, vch);
  161|  4.20k|}
_ZNK4CKey14EllSwiftCreateENSt3__14spanIKSt4byteLm18446744073709551615EEE:
  314|  5.14k|{
  315|  5.14k|    assert(keydata);
  ------------------
  |  Branch (315:5): [True: 5.14k, False: 0]
  ------------------
  316|  5.14k|    assert(ent32.size() == 32);
  ------------------
  |  Branch (316:5): [True: 5.14k, False: 0]
  ------------------
  317|  5.14k|    std::array<std::byte, EllSwiftPubKey::size()> encoded_pubkey;
  318|       |
  319|  5.14k|    auto success = secp256k1_ellswift_create(secp256k1_context_sign,
  320|  5.14k|                                             UCharCast(encoded_pubkey.data()),
  321|  5.14k|                                             keydata->data(),
  322|  5.14k|                                             UCharCast(ent32.data()));
  323|       |
  324|       |    // Should always succeed for valid keys (asserted above).
  325|  5.14k|    assert(success);
  ------------------
  |  Branch (325:5): [True: 5.14k, False: 0]
  ------------------
  326|  5.14k|    return {encoded_pubkey};
  327|  5.14k|}
_ZNK4CKey23ComputeBIP324ECDHSecretERK14EllSwiftPubKeyS2_b:
  330|  5.26k|{
  331|  5.26k|    assert(keydata);
  ------------------
  |  Branch (331:5): [True: 5.26k, False: 0]
  ------------------
  332|       |
  333|  5.26k|    ECDHSecret output;
  334|       |    // BIP324 uses the initiator as party A, and the responder as party B. Remap the inputs
  335|       |    // accordingly:
  336|  5.26k|    bool success = secp256k1_ellswift_xdh(secp256k1_context_static,
  337|  5.26k|                                          UCharCast(output.data()),
  338|  5.26k|                                          UCharCast(initiating ? our_ellswift.data() : their_ellswift.data()),
  ------------------
  |  Branch (338:53): [True: 3.42k, False: 1.84k]
  ------------------
  339|  5.26k|                                          UCharCast(initiating ? their_ellswift.data() : our_ellswift.data()),
  ------------------
  |  Branch (339:53): [True: 3.42k, False: 1.84k]
  ------------------
  340|  5.26k|                                          keydata->data(),
  341|  5.26k|                                          initiating ? 0 : 1,
  ------------------
  |  Branch (341:43): [True: 3.42k, False: 1.84k]
  ------------------
  342|  5.26k|                                          secp256k1_ellswift_xdh_hash_function_bip324,
  343|  5.26k|                                          nullptr);
  344|       |    // Should always succeed for valid keys (assert above).
  345|  5.26k|    assert(success);
  ------------------
  |  Branch (345:5): [True: 5.26k, False: 0]
  ------------------
  346|  5.26k|    return output;
  347|  5.26k|}
_ZN11ECC_ContextD2Ev:
  501|      2|{
  502|      2|    ECC_Stop();
  503|      2|}
key.cpp:_ZL8ECC_Stopv:
  486|      2|static void ECC_Stop() {
  487|      2|    secp256k1_context *ctx = secp256k1_context_sign;
  488|      2|    secp256k1_context_sign = nullptr;
  489|       |
  490|      2|    if (ctx) {
  ------------------
  |  Branch (490:9): [True: 2, False: 0]
  ------------------
  491|      2|        secp256k1_context_destroy(ctx);
  492|      2|    }
  493|      2|}

_ZN4CKey3SetINSt3__111__wrap_iterIPhEEEEvT_S5_b:
  109|  4.20k|    {
  110|  4.20k|        if (size_t(pend - pbegin) != std::tuple_size_v<KeyType>) {
  ------------------
  |  Branch (110:13): [True: 0, False: 4.20k]
  ------------------
  111|      0|            ClearKeyData();
  112|  4.20k|        } else if (Check(UCharCast(&pbegin[0]))) {
  ------------------
  |  Branch (112:20): [True: 3.79k, False: 409]
  ------------------
  113|  3.79k|            MakeKeyData();
  114|  3.79k|            memcpy(keydata->data(), (unsigned char*)&pbegin[0], keydata->size());
  115|  3.79k|            fCompressed = fCompressedIn;
  116|  3.79k|        } else {
  117|    409|            ClearKeyData();
  118|    409|        }
  119|  4.20k|    }
_ZN4CKeyC2Ev:
   79|  4.20k|    CKey() noexcept = default;
_ZN4CKey11MakeKeyDataEv:
   69|  3.79k|    {
   70|  3.79k|        if (!keydata) keydata = make_secure_unique<KeyType>();
  ------------------
  |  Branch (70:13): [True: 3.79k, False: 0]
  ------------------
   71|  3.79k|    }
_ZN4CKey12ClearKeyDataEv:
   74|    409|    {
   75|    409|        keydata.reset();
   76|    409|    }
_ZNK4CKey7IsValidEv:
  128|  4.20k|    bool IsValid() const { return !!keydata; }

_ZN11CNetCleanupD2Ev:
 3676|      2|    {
 3677|       |#ifdef WIN32
 3678|       |        // Shutdown Windows Sockets
 3679|       |        WSACleanup();
 3680|       |#endif
 3681|      2|    }

_ZNK9prevectorILj16EhjiE9is_directEv:
  126|     16|    bool is_direct() const { return _size <= N; }
_ZN9prevectorILj16EhjiED2Ev:
  422|     16|    ~prevector() {
  423|     16|        if (!is_direct()) {
  ------------------
  |  Branch (423:13): [True: 0, False: 16]
  ------------------
  424|      0|            free(_union.indirect_contents.indirect);
  425|      0|            _union.indirect_contents.indirect = nullptr;
  426|      0|        }
  427|     16|    }
_ZNK9prevectorILj36EhjiE9is_directEv:
  126|     18|    bool is_direct() const { return _size <= N; }
_ZN9prevectorILj36EhjiED2Ev:
  422|     18|    ~prevector() {
  423|     18|        if (!is_direct()) {
  ------------------
  |  Branch (423:13): [True: 4, False: 14]
  ------------------
  424|      4|            free(_union.indirect_contents.indirect);
  425|      4|            _union.indirect_contents.indirect = nullptr;
  426|      4|        }
  427|     18|    }

_ZN14EllSwiftPubKeyC2ENSt3__14spanIKSt4byteLm18446744073709551615EEE:
  366|  5.14k|{
  367|  5.14k|    assert(ellswift.size() == SIZE);
  ------------------
  |  Branch (367:5): [True: 5.14k, False: 0]
  ------------------
  368|  5.14k|    std::copy(ellswift.begin(), ellswift.end(), m_pubkey.begin());
  369|  5.14k|}

_ZeqRK14EllSwiftPubKeyS1_:
  337|  5.14k|    {
  338|  5.14k|        return a.m_pubkey == b.m_pubkey;
  339|  5.14k|    }
_ZNK14EllSwiftPubKey4dataEv:
  331|  10.5k|    const std::byte* data() const { return m_pubkey.data(); }

random.cpp:_ZN12_GLOBAL__N_18RNGStateD2Ev:
  367|      2|    ~RNGState() = default;

_ZN20BaseSignatureCheckerD2Ev:
  298|      2|    virtual ~BaseSignatureChecker() = default;

_ZN20BaseSignatureCreatorD2Ev:
   41|      4|    virtual ~BaseSignatureCreator() = default;

_ZN15SigningProviderD2Ev:
  170|      2|    virtual ~SigningProvider() = default;

secp256k1.c:secp256k1_ecmult_const_xonly:
  268|  5.26k|static int secp256k1_ecmult_const_xonly(secp256k1_fe* r, const secp256k1_fe *n, const secp256k1_fe *d, const secp256k1_scalar *q, int known_on_curve) {
  269|       |
  270|       |    /* This algorithm is a generalization of Peter Dettman's technique for
  271|       |     * avoiding the square root in a random-basepoint x-only multiplication
  272|       |     * on a Weierstrass curve:
  273|       |     * https://mailarchive.ietf.org/arch/msg/cfrg/7DyYY6gg32wDgHAhgSb6XxMDlJA/
  274|       |     *
  275|       |     *
  276|       |     * === Background: the effective affine technique ===
  277|       |     *
  278|       |     * Let phi_u be the isomorphism that maps (x, y) on secp256k1 curve y^2 = x^3 + 7 to
  279|       |     * x' = u^2*x, y' = u^3*y on curve y'^2 = x'^3 + u^6*7. This new curve has the same order as
  280|       |     * the original (it is isomorphic), but moreover, has the same addition/doubling formulas, as
  281|       |     * the curve b=7 coefficient does not appear in those formulas (or at least does not appear in
  282|       |     * the formulas implemented in this codebase, both affine and Jacobian). See also Example 9.5.2
  283|       |     * in https://www.math.auckland.ac.nz/~sgal018/crypto-book/ch9.pdf.
  284|       |     *
  285|       |     * This means any linear combination of secp256k1 points can be computed by applying phi_u
  286|       |     * (with non-zero u) on all input points (including the generator, if used), computing the
  287|       |     * linear combination on the isomorphic curve (using the same group laws), and then applying
  288|       |     * phi_u^{-1} to get back to secp256k1.
  289|       |     *
  290|       |     * Switching to Jacobian coordinates, note that phi_u applied to (X, Y, Z) is simply
  291|       |     * (X, Y, Z/u). Thus, if we want to compute (X1, Y1, Z) + (X2, Y2, Z), with identical Z
  292|       |     * coordinates, we can use phi_Z to transform it to (X1, Y1, 1) + (X2, Y2, 1) on an isomorphic
  293|       |     * curve where the affine addition formula can be used instead.
  294|       |     * If (X3, Y3, Z3) = (X1, Y1) + (X2, Y2) on that curve, then our answer on secp256k1 is
  295|       |     * (X3, Y3, Z3*Z).
  296|       |     *
  297|       |     * This is the effective affine technique: if we have a linear combination of group elements
  298|       |     * to compute, and all those group elements have the same Z coordinate, we can simply pretend
  299|       |     * that all those Z coordinates are 1, perform the computation that way, and then multiply the
  300|       |     * original Z coordinate back in.
  301|       |     *
  302|       |     * The technique works on any a=0 short Weierstrass curve. It is possible to generalize it to
  303|       |     * other curves too, but there the isomorphic curves will have different 'a' coefficients,
  304|       |     * which typically does affect the group laws.
  305|       |     *
  306|       |     *
  307|       |     * === Avoiding the square root for x-only point multiplication ===
  308|       |     *
  309|       |     * In this function, we want to compute the X coordinate of q*(n/d, y), for
  310|       |     * y = sqrt((n/d)^3 + 7). Its negation would also be a valid Y coordinate, but by convention
  311|       |     * we pick whatever sqrt returns (which we assume to be a deterministic function).
  312|       |     *
  313|       |     * Let g = y^2*d^3 = n^3 + 7*d^3. This also means y = sqrt(g/d^3).
  314|       |     * Further let v = sqrt(d*g), which must exist as d*g = y^2*d^4 = (y*d^2)^2.
  315|       |     *
  316|       |     * The input point (n/d, y) also has Jacobian coordinates:
  317|       |     *
  318|       |     *     (n/d, y, 1)
  319|       |     *   = (n/d * v^2, y * v^3, v)
  320|       |     *   = (n/d * d*g, y * sqrt(d^3*g^3), v)
  321|       |     *   = (n/d * d*g, sqrt(y^2 * d^3*g^3), v)
  322|       |     *   = (n*g, sqrt(g/d^3 * d^3*g^3), v)
  323|       |     *   = (n*g, sqrt(g^4), v)
  324|       |     *   = (n*g, g^2, v)
  325|       |     *
  326|       |     * It is easy to verify that both (n*g, g^2, v) and its negation (n*g, -g^2, v) have affine X
  327|       |     * coordinate n/d, and this holds even when the square root function doesn't have a
  328|       |     * deterministic sign. We choose the (n*g, g^2, v) version.
  329|       |     *
  330|       |     * Now switch to the effective affine curve using phi_v, where the input point has coordinates
  331|       |     * (n*g, g^2). Compute (X, Y, Z) = q * (n*g, g^2) there.
  332|       |     *
  333|       |     * Back on secp256k1, that means q * (n*g, g^2, v) = (X, Y, v*Z). This last point has affine X
  334|       |     * coordinate X / (v^2*Z^2) = X / (d*g*Z^2). Determining the affine Y coordinate would involve
  335|       |     * a square root, but as long as we only care about the resulting X coordinate, no square root
  336|       |     * is needed anywhere in this computation.
  337|       |     */
  338|       |
  339|  5.26k|    secp256k1_fe g, i;
  340|  5.26k|    secp256k1_ge p;
  341|  5.26k|    secp256k1_gej rj;
  342|       |
  343|       |    /* Compute g = (n^3 + B*d^3). */
  344|  5.26k|    secp256k1_fe_sqr(&g, n);
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  345|  5.26k|    secp256k1_fe_mul(&g, &g, n);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  346|  5.26k|    if (d) {
  ------------------
  |  Branch (346:9): [True: 5.26k, False: 0]
  ------------------
  347|  5.26k|        secp256k1_fe b;
  348|  5.26k|        VERIFY_CHECK(!secp256k1_fe_normalizes_to_zero(d));
  349|  5.26k|        secp256k1_fe_sqr(&b, d);
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  350|  5.26k|        VERIFY_CHECK(SECP256K1_B <= 8); /* magnitude of b will be <= 8 after the next call */
  351|  5.26k|        secp256k1_fe_mul_int(&b, SECP256K1_B);
  ------------------
  |  |  233|  5.26k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|  5.26k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  5.26k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  5.26k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 5.26k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  5.26k|    } \
  |  |  |  |   94|  5.26k|    stmt; \
  |  |  |  |   95|  5.26k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  352|  5.26k|        secp256k1_fe_mul(&b, &b, d);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  353|  5.26k|        secp256k1_fe_add(&g, &b);
  ------------------
  |  |   92|  5.26k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  354|  5.26k|        if (!known_on_curve) {
  ------------------
  |  Branch (354:13): [True: 0, False: 5.26k]
  ------------------
  355|       |            /* We need to determine whether (n/d)^3 + 7 is square.
  356|       |             *
  357|       |             *     is_square((n/d)^3 + 7)
  358|       |             * <=> is_square(((n/d)^3 + 7) * d^4)
  359|       |             * <=> is_square((n^3 + 7*d^3) * d)
  360|       |             * <=> is_square(g * d)
  361|       |             */
  362|      0|            secp256k1_fe c;
  363|      0|            secp256k1_fe_mul(&c, &g, d);
  ------------------
  |  |   93|      0|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  364|      0|            if (!secp256k1_fe_is_square_var(&c)) return 0;
  ------------------
  |  |  103|      0|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  |  Branch (364:17): [True: 0, False: 0]
  ------------------
  365|      0|        }
  366|  5.26k|    } else {
  367|      0|        secp256k1_fe_add_int(&g, SECP256K1_B);
  ------------------
  |  |  102|      0|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                      secp256k1_fe_add_int(&g, SECP256K1_B);
  ------------------
  |  |   73|      0|#define SECP256K1_B 7
  ------------------
  368|      0|        if (!known_on_curve) {
  ------------------
  |  Branch (368:13): [True: 0, False: 0]
  ------------------
  369|       |            /* g at this point equals x^3 + 7. Test if it is square. */
  370|      0|            if (!secp256k1_fe_is_square_var(&g)) return 0;
  ------------------
  |  |  103|      0|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  |  Branch (370:17): [True: 0, False: 0]
  ------------------
  371|      0|        }
  372|      0|    }
  373|       |
  374|  5.26k|    SECP256K1_FE_VERIFY_MAGNITUDE(&g, 2);
  ------------------
  |  |  349|  5.26k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
  375|       |
  376|       |    /* Compute base point P = (n*g, g^2), the effective affine version of
  377|       |     * (n*g, g^2, v), which has corresponding affine X coordinate n/d. */
  378|  5.26k|    {
  379|  5.26k|        secp256k1_fe x, y;
  380|  5.26k|        secp256k1_fe_mul(&x, &g, n);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  381|  5.26k|        secp256k1_fe_sqr(&y, &g);
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  382|  5.26k|        secp256k1_ge_set_xy(&p, &x, &y);
  383|  5.26k|    }
  384|       |
  385|       |    /* Perform x-only EC multiplication of P with q. */
  386|  5.26k|    VERIFY_CHECK(!secp256k1_scalar_is_zero(q));
  387|  5.26k|    secp256k1_ecmult_const(&rj, &p, q);
  388|  5.26k|    VERIFY_CHECK(!secp256k1_gej_is_infinity(&rj));
  389|       |
  390|       |    /* The resulting (X, Y, Z) point on the effective-affine isomorphic curve corresponds to
  391|       |     * (X, Y, Z*v) on the secp256k1 curve. The affine version of that has X coordinate
  392|       |     * (X / (Z^2*d*g)). */
  393|  5.26k|    secp256k1_fe_sqr(&i, &rj.z);
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  394|  5.26k|    secp256k1_fe_mul(&i, &i, &g);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  395|  5.26k|    if (d) secp256k1_fe_mul(&i, &i, d);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  |  Branch (395:9): [True: 5.26k, False: 0]
  ------------------
  396|  5.26k|    secp256k1_fe_inv(&i, &i);
  ------------------
  |  |   98|  5.26k|#  define secp256k1_fe_inv secp256k1_fe_impl_inv
  ------------------
  397|  5.26k|    secp256k1_fe_mul(r, &rj.x, &i);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  398|       |
  399|  5.26k|    return 1;
  400|  5.26k|}
secp256k1.c:secp256k1_ecmult_const:
  122|  5.26k|static void secp256k1_ecmult_const(secp256k1_gej *r, const secp256k1_ge *a, const secp256k1_scalar *q) {
  123|       |    /* The approach below combines the signed-digit logic from Mike Hamburg's
  124|       |     * "Fast and compact elliptic-curve cryptography" (https://eprint.iacr.org/2012/309)
  125|       |     * Section 3.3, with the GLV endomorphism.
  126|       |     *
  127|       |     * The idea there is to interpret the bits of a scalar as signs (1 = +, 0 = -), and compute a
  128|       |     * point multiplication in that fashion. Let v be an n-bit non-negative integer (0 <= v < 2^n),
  129|       |     * and v[i] its i'th bit (so v = sum(v[i] * 2^i, i=0..n-1)). Then define:
  130|       |     *
  131|       |     *   C_l(v, A) = sum((2*v[i] - 1) * 2^i*A, i=0..l-1)
  132|       |     *
  133|       |     * Then it holds that C_l(v, A) = sum((2*v[i] - 1) * 2^i*A, i=0..l-1)
  134|       |     *                              = (2*sum(v[i] * 2^i, i=0..l-1) + 1 - 2^l) * A
  135|       |     *                              = (2*v + 1 - 2^l) * A
  136|       |     *
  137|       |     * Thus, one can compute q*A as C_256((q + 2^256 - 1) / 2, A). This is the basis for the
  138|       |     * paper's signed-digit multi-comb algorithm for multiplication using a precomputed table.
  139|       |     *
  140|       |     * It is appealing to try to combine this with the GLV optimization: the idea that a scalar
  141|       |     * s can be written as s1 + lambda*s2, where lambda is a curve-specific constant such that
  142|       |     * lambda*A is easy to compute, and where s1 and s2 are small. In particular we have the
  143|       |     * secp256k1_scalar_split_lambda function which performs such a split with the resulting s1
  144|       |     * and s2 in range (-2^128, 2^128) mod n. This does work, but is uninteresting:
  145|       |     *
  146|       |     *   To compute q*A:
  147|       |     *   - Let s1, s2 = split_lambda(q)
  148|       |     *   - Let R1 = C_256((s1 + 2^256 - 1) / 2, A)
  149|       |     *   - Let R2 = C_256((s2 + 2^256 - 1) / 2, lambda*A)
  150|       |     *   - Return R1 + R2
  151|       |     *
  152|       |     * The issue is that while s1 and s2 are small-range numbers, (s1 + 2^256 - 1) / 2 (mod n)
  153|       |     * and (s2 + 2^256 - 1) / 2 (mod n) are not, undoing the benefit of the splitting.
  154|       |     *
  155|       |     * To make it work, we want to modify the input scalar q first, before splitting, and then only
  156|       |     * add a 2^128 offset of the split results (so that they end up in the single 129-bit range
  157|       |     * [0,2^129]). A slightly smaller offset would work due to the bounds on the split, but we pick
  158|       |     * 2^128 for simplicity. Let s be the scalar fed to split_lambda, and f(q) the function to
  159|       |     * compute it from q:
  160|       |     *
  161|       |     *   To compute q*A:
  162|       |     *   - Compute s = f(q)
  163|       |     *   - Let s1, s2 = split_lambda(s)
  164|       |     *   - Let v1 = s1 + 2^128 (mod n)
  165|       |     *   - Let v2 = s2 + 2^128 (mod n)
  166|       |     *   - Let R1 = C_l(v1, A)
  167|       |     *   - Let R2 = C_l(v2, lambda*A)
  168|       |     *   - Return R1 + R2
  169|       |     *
  170|       |     * l will thus need to be at least 129, but we may overshoot by a few bits (see
  171|       |     * further), so keep it as a variable.
  172|       |     *
  173|       |     * To solve for s, we reason:
  174|       |     *     q*A  = R1 + R2
  175|       |     * <=> q*A  = C_l(s1 + 2^128, A) + C_l(s2 + 2^128, lambda*A)
  176|       |     * <=> q*A  = (2*(s1 + 2^128) + 1 - 2^l) * A + (2*(s2 + 2^128) + 1 - 2^l) * lambda*A
  177|       |     * <=> q*A  = (2*(s1 + s2*lambda) + (2^129 + 1 - 2^l) * (1 + lambda)) * A
  178|       |     * <=> q    = 2*(s1 + s2*lambda) + (2^129 + 1 - 2^l) * (1 + lambda) (mod n)
  179|       |     * <=> q    = 2*s + (2^129 + 1 - 2^l) * (1 + lambda) (mod n)
  180|       |     * <=> s    = (q + (2^l - 2^129 - 1) * (1 + lambda)) / 2 (mod n)
  181|       |     * <=> f(q) = (q + K) / 2 (mod n)
  182|       |     *            where K = (2^l - 2^129 - 1)*(1 + lambda) (mod n)
  183|       |     *
  184|       |     * We will process the computation of C_l(v1, A) and C_l(v2, lambda*A) in groups of
  185|       |     * ECMULT_CONST_GROUP_SIZE, so we set l to the smallest multiple of ECMULT_CONST_GROUP_SIZE
  186|       |     * that is not less than 129; this equals ECMULT_CONST_BITS.
  187|       |     */
  188|       |
  189|       |    /* The offset to add to s1 and s2 to make them non-negative. Equal to 2^128. */
  190|  5.26k|    static const secp256k1_scalar S_OFFSET = SECP256K1_SCALAR_CONST(0, 0, 0, 1, 0, 0, 0, 0);
  ------------------
  |  |   17|  5.26k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  191|  5.26k|    secp256k1_scalar s, v1, v2;
  192|  5.26k|    secp256k1_ge pre_a[ECMULT_CONST_TABLE_SIZE];
  193|  5.26k|    secp256k1_ge pre_a_lam[ECMULT_CONST_TABLE_SIZE];
  194|  5.26k|    secp256k1_fe global_z;
  195|  5.26k|    int group, i;
  196|       |
  197|       |    /* We're allowed to be non-constant time in the point, and the code below (in particular,
  198|       |     * secp256k1_ecmult_const_odd_multiples_table_globalz) cannot deal with infinity in a
  199|       |     * constant-time manner anyway. */
  200|  5.26k|    if (secp256k1_ge_is_infinity(a)) {
  ------------------
  |  Branch (200:9): [True: 0, False: 5.26k]
  ------------------
  201|      0|        secp256k1_gej_set_infinity(r);
  202|      0|        return;
  203|      0|    }
  204|       |
  205|       |    /* Compute v1 and v2. */
  206|  5.26k|    secp256k1_scalar_add(&s, q, &secp256k1_ecmult_const_K);
  207|  5.26k|    secp256k1_scalar_half(&s, &s);
  208|  5.26k|    secp256k1_scalar_split_lambda(&v1, &v2, &s);
  209|  5.26k|    secp256k1_scalar_add(&v1, &v1, &S_OFFSET);
  210|  5.26k|    secp256k1_scalar_add(&v2, &v2, &S_OFFSET);
  211|       |
  212|       |#ifdef VERIFY
  213|       |    /* Verify that v1 and v2 are in range [0, 2^129-1]. */
  214|       |    for (i = 129; i < 256; ++i) {
  215|       |        VERIFY_CHECK(secp256k1_scalar_get_bits_limb32(&v1, i, 1) == 0);
  216|       |        VERIFY_CHECK(secp256k1_scalar_get_bits_limb32(&v2, i, 1) == 0);
  217|       |    }
  218|       |#endif
  219|       |
  220|       |    /* Calculate odd multiples of A and A*lambda.
  221|       |     * All multiples are brought to the same Z 'denominator', which is stored
  222|       |     * in global_z. Due to secp256k1' isomorphism we can do all operations pretending
  223|       |     * that the Z coordinate was 1, use affine addition formulae, and correct
  224|       |     * the Z coordinate of the result once at the end.
  225|       |     */
  226|  5.26k|    secp256k1_gej_set_ge(r, a);
  227|  5.26k|    secp256k1_ecmult_const_odd_multiples_table_globalz(pre_a, &global_z, r);
  228|  89.4k|    for (i = 0; i < ECMULT_CONST_TABLE_SIZE; i++) {
  ------------------
  |  |   33|  89.4k|#define ECMULT_CONST_TABLE_SIZE (1L << (ECMULT_CONST_GROUP_SIZE - 1))
  |  |  ------------------
  |  |  |  |   30|  89.4k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  ------------------
  |  Branch (228:17): [True: 84.1k, False: 5.26k]
  ------------------
  229|  84.1k|        secp256k1_ge_mul_lambda(&pre_a_lam[i], &pre_a[i]);
  230|  84.1k|    }
  231|       |
  232|       |    /* Next, we compute r = C_l(v1, A) + C_l(v2, lambda*A).
  233|       |     *
  234|       |     * We proceed in groups of ECMULT_CONST_GROUP_SIZE bits, operating on that many bits
  235|       |     * at a time, from high in v1, v2 to low. Call these bits1 (from v1) and bits2 (from v2).
  236|       |     *
  237|       |     * Now note that ECMULT_CONST_TABLE_GET_GE(&t, pre_a, bits1) loads into t a point equal
  238|       |     * to C_{ECMULT_CONST_GROUP_SIZE}(bits1, A), and analogously for pre_lam_a / bits2.
  239|       |     * This means that all we need to do is add these looked up values together, multiplied
  240|       |     * by 2^(ECMULT_GROUP_SIZE * group).
  241|       |     */
  242|   142k|    for (group = ECMULT_CONST_GROUPS - 1; group >= 0; --group) {
  ------------------
  |  |   34|  5.26k|#define ECMULT_CONST_GROUPS ((129 + ECMULT_CONST_GROUP_SIZE - 1) / ECMULT_CONST_GROUP_SIZE)
  |  |  ------------------
  |  |  |  |   30|  5.26k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  |  |               #define ECMULT_CONST_GROUPS ((129 + ECMULT_CONST_GROUP_SIZE - 1) / ECMULT_CONST_GROUP_SIZE)
  |  |  ------------------
  |  |  |  |   30|  5.26k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  ------------------
  |  Branch (242:43): [True: 136k, False: 5.26k]
  ------------------
  243|       |        /* Using the _var get_bits function is ok here, since it's only variable in offset and count, not in the scalar. */
  244|   136k|        unsigned int bits1 = secp256k1_scalar_get_bits_var(&v1, group * ECMULT_CONST_GROUP_SIZE, ECMULT_CONST_GROUP_SIZE);
  ------------------
  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  ------------------
                      unsigned int bits1 = secp256k1_scalar_get_bits_var(&v1, group * ECMULT_CONST_GROUP_SIZE, ECMULT_CONST_GROUP_SIZE);
  ------------------
  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  ------------------
  245|   136k|        unsigned int bits2 = secp256k1_scalar_get_bits_var(&v2, group * ECMULT_CONST_GROUP_SIZE, ECMULT_CONST_GROUP_SIZE);
  ------------------
  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  ------------------
                      unsigned int bits2 = secp256k1_scalar_get_bits_var(&v2, group * ECMULT_CONST_GROUP_SIZE, ECMULT_CONST_GROUP_SIZE);
  ------------------
  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  ------------------
  246|   136k|        secp256k1_ge t;
  247|   136k|        int j;
  248|       |
  249|   136k|        ECMULT_CONST_TABLE_GET_GE(&t, pre_a, bits1);
  ------------------
  |  |   61|   136k|#define ECMULT_CONST_TABLE_GET_GE(r,pre,n) do { \
  |  |   62|   136k|    unsigned int m = 0; \
  |  |   63|   136k|    /* If the top bit of n is 0, we want the negation. */ \
  |  |   64|   136k|    volatile unsigned int negative = ((n) >> (ECMULT_CONST_GROUP_SIZE - 1)) ^ 1; \
  |  |  ------------------
  |  |  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  |  |   65|   136k|    /* Let n[i] be the i-th bit of n, then the index is
  |  |   66|   136k|     *     sum(cnot(n[i]) * 2^i, i=0..l-2)
  |  |   67|   136k|     * where cnot(b) = b if n[l-1] = 1 and 1 - b otherwise.
  |  |   68|   136k|     * For example, if n = 4, in binary 0100, the index is 3, in binary 011.
  |  |   69|   136k|     *
  |  |   70|   136k|     * Proof:
  |  |   71|   136k|     *     Let
  |  |   72|   136k|     *         x = sum((2*n[i] - 1)*2^i, i=0..l-1)
  |  |   73|   136k|     *           = 2*sum(n[i] * 2^i, i=0..l-1) - 2^l + 1
  |  |   74|   136k|     *     be the value represented by n.
  |  |   75|   136k|     *     The index is (x - 1)/2 if x > 0 and -(x + 1)/2 otherwise.
  |  |   76|   136k|     *     Case x > 0:
  |  |   77|   136k|     *         n[l-1] = 1
  |  |   78|   136k|     *         index = sum(n[i] * 2^i, i=0..l-1) - 2^(l-1)
  |  |   79|   136k|     *               = sum(n[i] * 2^i, i=0..l-2)
  |  |   80|   136k|     *     Case x <= 0:
  |  |   81|   136k|     *         n[l-1] = 0
  |  |   82|   136k|     *          index = -(2*sum(n[i] * 2^i, i=0..l-1) - 2^l + 2)/2
  |  |   83|   136k|     *                = 2^(l-1) - 1 - sum(n[i] * 2^i, i=0..l-1)
  |  |   84|   136k|     *                = sum((1 - n[i]) * 2^i, i=0..l-2)
  |  |   85|   136k|     */ \
  |  |   86|   136k|    unsigned int index = ((unsigned int)(-negative) ^ n) & ((1U << (ECMULT_CONST_GROUP_SIZE - 1)) - 1U); \
  |  |  ------------------
  |  |  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  |  |   87|   136k|    secp256k1_fe neg_y; \
  |  |   88|   136k|    VERIFY_CHECK((n) < (1U << ECMULT_CONST_GROUP_SIZE)); \
  |  |   89|   136k|    VERIFY_CHECK(index < (1U << (ECMULT_CONST_GROUP_SIZE - 1))); \
  |  |   90|   136k|    /* Unconditionally set r->x = (pre)[m].x and r->y = (pre)[m].y because it's either the correct one
  |  |   91|   136k|     * or will get replaced in the later iterations, this is needed to make sure `r` is initialized. */ \
  |  |   92|   136k|    secp256k1_ge_set_xy((r), &(pre)[m].x, &(pre)[m].y); \
  |  |   93|  2.18M|    for (m = 1; m < ECMULT_CONST_TABLE_SIZE; m++) { \
  |  |  ------------------
  |  |  |  |   33|  2.18M|#define ECMULT_CONST_TABLE_SIZE (1L << (ECMULT_CONST_GROUP_SIZE - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  2.18M|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (93:17): [True: 2.05M, False: 136k]
  |  |  ------------------
  |  |   94|  2.05M|        /* This loop is used to avoid secret data in array indices. See
  |  |   95|  2.05M|         * the comment in ecmult_gen_impl.h for rationale. */ \
  |  |   96|  2.05M|        secp256k1_fe_cmov(&(r)->x, &(pre)[m].x, m == index); \
  |  |  ------------------
  |  |  |  |   95|  2.05M|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  |  |  ------------------
  |  |   97|  2.05M|        secp256k1_fe_cmov(&(r)->y, &(pre)[m].y, m == index); \
  |  |  ------------------
  |  |  |  |   95|  2.05M|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  |  |  ------------------
  |  |   98|  2.05M|    } \
  |  |   99|   136k|    secp256k1_fe_negate(&neg_y, &(r)->y, 1); \
  |  |  ------------------
  |  |  |  |  211|   136k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  |  |  ------------------
  |  |  |  |  |  |   87|   136k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |  |  |   88|   136k|    switch(42) { \
  |  |  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (90:9): [True: 0, False: 136k]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   91|      0|            break; \
  |  |  |  |  |  |   92|   136k|        default: ; \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (92:9): [True: 136k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   93|   136k|    } \
  |  |  |  |  |  |   94|   136k|    stmt; \
  |  |  |  |  |  |   95|   136k|} while(0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (95:9): [Folded, False: 136k]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  100|   136k|    secp256k1_fe_cmov(&(r)->y, &neg_y, negative); \
  |  |  ------------------
  |  |  |  |   95|   136k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  |  |  ------------------
  |  |  101|   136k|} while(0)
  |  |  ------------------
  |  |  |  Branch (101:9): [Folded, False: 136k]
  |  |  ------------------
  ------------------
  250|   136k|        if (group == ECMULT_CONST_GROUPS - 1) {
  ------------------
  |  |   34|   136k|#define ECMULT_CONST_GROUPS ((129 + ECMULT_CONST_GROUP_SIZE - 1) / ECMULT_CONST_GROUP_SIZE)
  |  |  ------------------
  |  |  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  |  |               #define ECMULT_CONST_GROUPS ((129 + ECMULT_CONST_GROUP_SIZE - 1) / ECMULT_CONST_GROUP_SIZE)
  |  |  ------------------
  |  |  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  ------------------
  |  Branch (250:13): [True: 5.26k, False: 131k]
  ------------------
  251|       |            /* Directly set r in the first iteration. */
  252|  5.26k|            secp256k1_gej_set_ge(r, &t);
  253|   131k|        } else {
  254|       |            /* Shift the result so far up. */
  255|   789k|            for (j = 0; j < ECMULT_CONST_GROUP_SIZE; ++j) {
  ------------------
  |  |   30|   789k|#  define ECMULT_CONST_GROUP_SIZE 5
  ------------------
  |  Branch (255:25): [True: 657k, False: 131k]
  ------------------
  256|   657k|                secp256k1_gej_double(r, r);
  257|   657k|            }
  258|   131k|            secp256k1_gej_add_ge(r, r, &t);
  259|   131k|        }
  260|   136k|        ECMULT_CONST_TABLE_GET_GE(&t, pre_a_lam, bits2);
  ------------------
  |  |   61|   136k|#define ECMULT_CONST_TABLE_GET_GE(r,pre,n) do { \
  |  |   62|   136k|    unsigned int m = 0; \
  |  |   63|   136k|    /* If the top bit of n is 0, we want the negation. */ \
  |  |   64|   136k|    volatile unsigned int negative = ((n) >> (ECMULT_CONST_GROUP_SIZE - 1)) ^ 1; \
  |  |  ------------------
  |  |  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  |  |   65|   136k|    /* Let n[i] be the i-th bit of n, then the index is
  |  |   66|   136k|     *     sum(cnot(n[i]) * 2^i, i=0..l-2)
  |  |   67|   136k|     * where cnot(b) = b if n[l-1] = 1 and 1 - b otherwise.
  |  |   68|   136k|     * For example, if n = 4, in binary 0100, the index is 3, in binary 011.
  |  |   69|   136k|     *
  |  |   70|   136k|     * Proof:
  |  |   71|   136k|     *     Let
  |  |   72|   136k|     *         x = sum((2*n[i] - 1)*2^i, i=0..l-1)
  |  |   73|   136k|     *           = 2*sum(n[i] * 2^i, i=0..l-1) - 2^l + 1
  |  |   74|   136k|     *     be the value represented by n.
  |  |   75|   136k|     *     The index is (x - 1)/2 if x > 0 and -(x + 1)/2 otherwise.
  |  |   76|   136k|     *     Case x > 0:
  |  |   77|   136k|     *         n[l-1] = 1
  |  |   78|   136k|     *         index = sum(n[i] * 2^i, i=0..l-1) - 2^(l-1)
  |  |   79|   136k|     *               = sum(n[i] * 2^i, i=0..l-2)
  |  |   80|   136k|     *     Case x <= 0:
  |  |   81|   136k|     *         n[l-1] = 0
  |  |   82|   136k|     *          index = -(2*sum(n[i] * 2^i, i=0..l-1) - 2^l + 2)/2
  |  |   83|   136k|     *                = 2^(l-1) - 1 - sum(n[i] * 2^i, i=0..l-1)
  |  |   84|   136k|     *                = sum((1 - n[i]) * 2^i, i=0..l-2)
  |  |   85|   136k|     */ \
  |  |   86|   136k|    unsigned int index = ((unsigned int)(-negative) ^ n) & ((1U << (ECMULT_CONST_GROUP_SIZE - 1)) - 1U); \
  |  |  ------------------
  |  |  |  |   30|   136k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  |  |   87|   136k|    secp256k1_fe neg_y; \
  |  |   88|   136k|    VERIFY_CHECK((n) < (1U << ECMULT_CONST_GROUP_SIZE)); \
  |  |   89|   136k|    VERIFY_CHECK(index < (1U << (ECMULT_CONST_GROUP_SIZE - 1))); \
  |  |   90|   136k|    /* Unconditionally set r->x = (pre)[m].x and r->y = (pre)[m].y because it's either the correct one
  |  |   91|   136k|     * or will get replaced in the later iterations, this is needed to make sure `r` is initialized. */ \
  |  |   92|   136k|    secp256k1_ge_set_xy((r), &(pre)[m].x, &(pre)[m].y); \
  |  |   93|  2.18M|    for (m = 1; m < ECMULT_CONST_TABLE_SIZE; m++) { \
  |  |  ------------------
  |  |  |  |   33|  2.18M|#define ECMULT_CONST_TABLE_SIZE (1L << (ECMULT_CONST_GROUP_SIZE - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  2.18M|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (93:17): [True: 2.05M, False: 136k]
  |  |  ------------------
  |  |   94|  2.05M|        /* This loop is used to avoid secret data in array indices. See
  |  |   95|  2.05M|         * the comment in ecmult_gen_impl.h for rationale. */ \
  |  |   96|  2.05M|        secp256k1_fe_cmov(&(r)->x, &(pre)[m].x, m == index); \
  |  |  ------------------
  |  |  |  |   95|  2.05M|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  |  |  ------------------
  |  |   97|  2.05M|        secp256k1_fe_cmov(&(r)->y, &(pre)[m].y, m == index); \
  |  |  ------------------
  |  |  |  |   95|  2.05M|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  |  |  ------------------
  |  |   98|  2.05M|    } \
  |  |   99|   136k|    secp256k1_fe_negate(&neg_y, &(r)->y, 1); \
  |  |  ------------------
  |  |  |  |  211|   136k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  |  |  ------------------
  |  |  |  |  |  |   87|   136k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |  |  |   88|   136k|    switch(42) { \
  |  |  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (90:9): [True: 0, False: 136k]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   91|      0|            break; \
  |  |  |  |  |  |   92|   136k|        default: ; \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (92:9): [True: 136k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   93|   136k|    } \
  |  |  |  |  |  |   94|   136k|    stmt; \
  |  |  |  |  |  |   95|   136k|} while(0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (95:9): [Folded, False: 136k]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  100|   136k|    secp256k1_fe_cmov(&(r)->y, &neg_y, negative); \
  |  |  ------------------
  |  |  |  |   95|   136k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  |  |  ------------------
  |  |  101|   136k|} while(0)
  |  |  ------------------
  |  |  |  Branch (101:9): [Folded, False: 136k]
  |  |  ------------------
  ------------------
  261|   136k|        secp256k1_gej_add_ge(r, r, &t);
  262|   136k|    }
  263|       |
  264|       |    /* Map the result back to the secp256k1 curve from the isomorphic curve. */
  265|  5.26k|    secp256k1_fe_mul(&r->z, &r->z, &global_z);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  266|  5.26k|}
secp256k1.c:secp256k1_ecmult_const_odd_multiples_table_globalz:
   44|  5.26k|static void secp256k1_ecmult_const_odd_multiples_table_globalz(secp256k1_ge *pre, secp256k1_fe *globalz, const secp256k1_gej *a) {
   45|  5.26k|    secp256k1_fe zr[ECMULT_CONST_TABLE_SIZE];
   46|       |
   47|  5.26k|    secp256k1_ecmult_odd_multiples_table(ECMULT_CONST_TABLE_SIZE, pre, zr, globalz, a);
  ------------------
  |  |   33|  5.26k|#define ECMULT_CONST_TABLE_SIZE (1L << (ECMULT_CONST_GROUP_SIZE - 1))
  |  |  ------------------
  |  |  |  |   30|  5.26k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  ------------------
   48|  5.26k|    secp256k1_ge_table_set_globalz(ECMULT_CONST_TABLE_SIZE, pre, zr);
  ------------------
  |  |   33|  5.26k|#define ECMULT_CONST_TABLE_SIZE (1L << (ECMULT_CONST_GROUP_SIZE - 1))
  |  |  ------------------
  |  |  |  |   30|  5.26k|#  define ECMULT_CONST_GROUP_SIZE 5
  |  |  ------------------
  ------------------
   49|  5.26k|}

secp256k1.c:secp256k1_ecmult_gen_context_clear:
   26|      2|static void secp256k1_ecmult_gen_context_clear(secp256k1_ecmult_gen_context *ctx) {
   27|      2|    ctx->built = 0;
   28|      2|    secp256k1_scalar_clear(&ctx->scalar_offset);
   29|      2|    secp256k1_ge_clear(&ctx->ge_offset);
   30|      2|    secp256k1_fe_clear(&ctx->proj_blind);
   31|      2|}
secp256k1.c:secp256k1_ecmult_gen_context_is_built:
   22|  5.14k|static int secp256k1_ecmult_gen_context_is_built(const secp256k1_ecmult_gen_context* ctx) {
   23|  5.14k|    return ctx->built;
   24|  5.14k|}
secp256k1.c:secp256k1_ecmult_gen_gej:
   54|  5.14k|static void secp256k1_ecmult_gen_gej(const secp256k1_ecmult_gen_context *ctx, secp256k1_gej *r, const secp256k1_scalar *gn) {
   55|  5.14k|    uint32_t comb_off;
   56|  5.14k|    secp256k1_ge add;
   57|  5.14k|    secp256k1_fe neg;
   58|  5.14k|    secp256k1_ge_storage adds;
   59|  5.14k|    secp256k1_scalar d;
   60|       |    /* Array of uint32_t values large enough to store COMB_BITS bits. Only the bottom
   61|       |     * 8 are ever nonzero, but having the zero padding at the end if COMB_BITS>256
   62|       |     * avoids the need to deal with out-of-bounds reads from a scalar. */
   63|  5.14k|    uint32_t recoded[(COMB_BITS + 31) >> 5] = {0};
   64|  5.14k|    int first = 1, i;
   65|       |
   66|  5.14k|    memset(&adds, 0, sizeof(adds));
   67|       |
   68|       |    /* We want to compute R = gn*G.
   69|       |     *
   70|       |     * To blind the scalar used in the computation, we rewrite this to be
   71|       |     * R = (gn - b)*G + b*G, with a blinding value b determined by the context.
   72|       |     *
   73|       |     * The multiplication (gn-b)*G will be performed using a signed-digit multi-comb (see Section
   74|       |     * 3.3 of "Fast and compact elliptic-curve cryptography" by Mike Hamburg,
   75|       |     * https://eprint.iacr.org/2012/309).
   76|       |     *
   77|       |     * Let comb(s, P) = sum((2*s[i]-1)*2^i*P for i=0..COMB_BITS-1), where s[i] is the i'th bit of
   78|       |     * the binary representation of scalar s. So the s[i] values determine whether -2^i*P (s[i]=0)
   79|       |     * or +2^i*P (s[i]=1) are added together. COMB_BITS is at least 256, so all bits of s are
   80|       |     * covered. By manipulating:
   81|       |     *
   82|       |     *     comb(s, P) = sum((2*s[i]-1)*2^i*P for i=0..COMB_BITS-1)
   83|       |     * <=> comb(s, P) = sum((2*s[i]-1)*2^i for i=0..COMB_BITS-1) * P
   84|       |     * <=> comb(s, P) = (2*sum(s[i]*2^i for i=0..COMB_BITS-1) - sum(2^i for i=0..COMB_BITS-1)) * P
   85|       |     * <=> comb(s, P) = (2*s - (2^COMB_BITS - 1)) * P
   86|       |     *
   87|       |     * If we wanted to compute (gn-b)*G as comb(s, G), it would need to hold that
   88|       |     *
   89|       |     *     (gn - b) * G = (2*s - (2^COMB_BITS - 1)) * G
   90|       |     * <=> s = (gn - b + (2^COMB_BITS - 1))/2 (mod order)
   91|       |     *
   92|       |     * We use an alternative here that avoids the modular division by two: instead we compute
   93|       |     * (gn-b)*G as comb(d, G/2). For that to hold it must be the case that
   94|       |     *
   95|       |     *     (gn - b) * G = (2*d - (2^COMB_BITS - 1)) * (G/2)
   96|       |     * <=> d = gn - b + (2^COMB_BITS - 1)/2 (mod order)
   97|       |     *
   98|       |     * Adding precomputation, our final equations become:
   99|       |     *
  100|       |     *     ctx->scalar_offset = (2^COMB_BITS - 1)/2 - b (mod order)
  101|       |     *     ctx->ge_offset = b*G
  102|       |     *     d = gn + ctx->scalar_offset (mod order)
  103|       |     *     R = comb(d, G/2) + ctx->ge_offset
  104|       |     *
  105|       |     * comb(d, G/2) function is then computed by summing + or - 2^(i-1)*G, for i=0..COMB_BITS-1,
  106|       |     * depending on the value of the bits d[i] of the binary representation of scalar d.
  107|       |     */
  108|       |
  109|       |    /* Compute the scalar d = (gn + ctx->scalar_offset). */
  110|  5.14k|    secp256k1_scalar_add(&d, &ctx->scalar_offset, gn);
  111|       |    /* Convert to recoded array. */
  112|  46.3k|    for (i = 0; i < 8 && i < ((COMB_BITS + 31) >> 5); ++i) {
  ------------------
  |  |   85|  41.1k|#define COMB_BITS (COMB_BLOCKS * COMB_TEETH * COMB_SPACING)
  |  |  ------------------
  |  |  |  |   79|  41.1k|#define COMB_SPACING CEIL_DIV(COMB_RANGE, COMB_BLOCKS * COMB_TEETH)
  |  |  |  |  ------------------
  |  |  |  |  |  |  190|  41.1k|#define CEIL_DIV(x, y) (1 + ((x) - 1) / (y))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (112:17): [True: 41.1k, False: 5.14k]
  |  Branch (112:26): [True: 41.1k, False: 0]
  ------------------
  113|  41.1k|        recoded[i] = secp256k1_scalar_get_bits_limb32(&d, 32 * i, 32);
  114|  41.1k|    }
  115|  5.14k|    secp256k1_scalar_clear(&d);
  116|       |
  117|       |    /* In secp256k1_ecmult_gen_prec_table we have precomputed sums of the
  118|       |     * (2*d[i]-1) * 2^(i-1) * G points, for various combinations of i positions.
  119|       |     * We rewrite our equation in terms of these table entries.
  120|       |     *
  121|       |     * Let mask(b) = sum(2^((b*COMB_TEETH + t)*COMB_SPACING) for t=0..COMB_TEETH-1),
  122|       |     * with b ranging from 0 to COMB_BLOCKS-1. So for example with COMB_BLOCKS=11,
  123|       |     * COMB_TEETH=6, COMB_SPACING=4, we would have:
  124|       |     *   mask(0)  = 2^0   + 2^4   + 2^8   + 2^12  + 2^16  + 2^20,
  125|       |     *   mask(1)  = 2^24  + 2^28  + 2^32  + 2^36  + 2^40  + 2^44,
  126|       |     *   mask(2)  = 2^48  + 2^52  + 2^56  + 2^60  + 2^64  + 2^68,
  127|       |     *   ...
  128|       |     *   mask(10) = 2^240 + 2^244 + 2^248 + 2^252 + 2^256 + 2^260
  129|       |     *
  130|       |     * We will split up the bits d[i] using these masks. Specifically, each mask is
  131|       |     * used COMB_SPACING times, with different shifts:
  132|       |     *
  133|       |     * d = (d & mask(0)<<0) + (d & mask(1)<<0) + ... + (d & mask(COMB_BLOCKS-1)<<0) +
  134|       |     *     (d & mask(0)<<1) + (d & mask(1)<<1) + ... + (d & mask(COMB_BLOCKS-1)<<1) +
  135|       |     *     ...
  136|       |     *     (d & mask(0)<<(COMB_SPACING-1)) + ...
  137|       |     *
  138|       |     * Now define table(b, m) = (m - mask(b)/2) * G, and we will precompute these values for
  139|       |     * b=0..COMB_BLOCKS-1, and for all values m which (d & mask(b)) can take (so m can take on
  140|       |     * 2^COMB_TEETH distinct values).
  141|       |     *
  142|       |     * If m=(d & mask(b)), then table(b, m) is the sum of 2^i * (2*d[i]-1) * G/2, with i
  143|       |     * iterating over the set bits in mask(b). In our example, table(2, 2^48 + 2^56 + 2^68)
  144|       |     * would equal (2^48 - 2^52 + 2^56 - 2^60 - 2^64 + 2^68) * G/2.
  145|       |     *
  146|       |     * With that, we can rewrite comb(d, G/2) as:
  147|       |     *
  148|       |     *     2^0 * (table(0, d>>0 & mask(0)) + ... + table(COMB_BLOCKS-1, d>>0 & mask(COMP_BLOCKS-1)))
  149|       |     *   + 2^1 * (table(0, d>>1 & mask(0)) + ... + table(COMB_BLOCKS-1, d>>1 & mask(COMP_BLOCKS-1)))
  150|       |     *   + 2^2 * (table(0, d>>2 & mask(0)) + ... + table(COMB_BLOCKS-1, d>>2 & mask(COMP_BLOCKS-1)))
  151|       |     *   + ...
  152|       |     *   + 2^(COMB_SPACING-1) * (table(0, d>>(COMB_SPACING-1) & mask(0)) + ...)
  153|       |     *
  154|       |     * Or more generically as
  155|       |     *
  156|       |     *   sum(2^i * sum(table(b, d>>i & mask(b)), b=0..COMB_BLOCKS-1), i=0..COMB_SPACING-1)
  157|       |     *
  158|       |     * This is implemented using an outer loop that runs in reverse order over the lines of this
  159|       |     * equation, which in each iteration runs an inner loop that adds the terms of that line and
  160|       |     * then doubles the result before proceeding to the next line.
  161|       |     *
  162|       |     * In pseudocode:
  163|       |     *   c = infinity
  164|       |     *   for comb_off in range(COMB_SPACING - 1, -1, -1):
  165|       |     *     for block in range(COMB_BLOCKS):
  166|       |     *       c += table(block, (d >> comb_off) & mask(block))
  167|       |     *     if comb_off > 0:
  168|       |     *       c = 2*c
  169|       |     *   return c
  170|       |     *
  171|       |     * This computes c = comb(d, G/2), and thus finally R = c + ctx->ge_offset. Note that it would
  172|       |     * be possible to apply an initial offset instead of a final offset (moving ge_offset to take
  173|       |     * the place of infinity above), but the chosen approach allows using (in a future improvement)
  174|       |     * an incomplete addition formula for most of the multiplication.
  175|       |     *
  176|       |     * The last question is how to implement the table(b, m) function. For any value of b,
  177|       |     * m=(d & mask(b)) can only take on at most 2^COMB_TEETH possible values (the last one may have
  178|       |     * fewer as there mask(b) may exceed the curve order). So we could create COMB_BLOCK tables
  179|       |     * which contain a value for each such m value.
  180|       |     *
  181|       |     * Now note that if m=(d & mask(b)), then flipping the relevant bits of m results in negating
  182|       |     * the result of table(b, m). This is because table(b,m XOR mask(b)) = table(b, mask(b) - m) =
  183|       |     * (mask(b) - m - mask(b)/2)*G = (-m + mask(b)/2)*G = -(m - mask(b)/2)*G = -table(b, m).
  184|       |     * Because of this it suffices to only store the first half of the m values for every b. If an
  185|       |     * entry from the second half is needed, we look up its bit-flipped version instead, and negate
  186|       |     * it.
  187|       |     *
  188|       |     * secp256k1_ecmult_gen_prec_table[b][index] stores the table(b, m) entries. Index
  189|       |     * is the relevant mask(b) bits of m packed together without gaps. */
  190|       |
  191|       |    /* Outer loop: iterate over comb_off from COMB_SPACING - 1 down to 0. */
  192|  5.14k|    comb_off = COMB_SPACING - 1;
  ------------------
  |  |   79|  5.14k|#define COMB_SPACING CEIL_DIV(COMB_RANGE, COMB_BLOCKS * COMB_TEETH)
  |  |  ------------------
  |  |  |  |  190|  5.14k|#define CEIL_DIV(x, y) (1 + ((x) - 1) / (y))
  |  |  ------------------
  ------------------
  193|  5.14k|    while (1) {
  ------------------
  |  Branch (193:12): [True: 5.14k, Folded]
  ------------------
  194|  5.14k|        uint32_t block;
  195|  5.14k|        uint32_t bit_pos = comb_off;
  196|       |        /* Inner loop: for each block, add table entries to the result. */
  197|   226k|        for (block = 0; block < COMB_BLOCKS; ++block) {
  ------------------
  |  Branch (197:25): [True: 221k, False: 5.14k]
  ------------------
  198|       |            /* Gather the mask(block)-selected bits of d into bits. They're packed:
  199|       |             * bits[tooth] = d[(block*COMB_TEETH + tooth)*COMB_SPACING + comb_off]. */
  200|   221k|            uint32_t bits = 0, sign, abs, index, tooth;
  201|       |            /* Instead of reading individual bits here to construct the bits variable,
  202|       |             * build up the result by xoring rotated reads together. In every iteration,
  203|       |             * one additional bit is made correct, starting at the bottom. The bits
  204|       |             * above that contain junk. This reduces leakage by avoiding computations
  205|       |             * on variables that can have only a low number of possible values (e.g.,
  206|       |             * just two values when reading a single bit into a variable.) See:
  207|       |             * https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-alam.pdf
  208|       |             */
  209|  1.54M|            for (tooth = 0; tooth < COMB_TEETH; ++tooth) {
  ------------------
  |  Branch (209:29): [True: 1.32M, False: 221k]
  ------------------
  210|       |                /* Construct bitdata s.t. the bottom bit is the bit we'd like to read.
  211|       |                 *
  212|       |                 * We could just set bitdata = recoded[bit_pos >> 5] >> (bit_pos & 0x1f)
  213|       |                 * but this would simply discard the bits that fall off at the bottom,
  214|       |                 * and thus, for example, bitdata could still have only two values if we
  215|       |                 * happen to shift by exactly 31 positions. We use a rotation instead,
  216|       |                 * which ensures that bitdata doesn't lose entropy. This relies on the
  217|       |                 * rotation being atomic, i.e., the compiler emitting an actual rot
  218|       |                 * instruction. */
  219|  1.32M|                uint32_t bitdata = secp256k1_rotr32(recoded[bit_pos >> 5], bit_pos & 0x1f);
  220|       |
  221|       |                /* Clear the bit at position tooth, but sssh, don't tell clang. */
  222|  1.32M|                uint32_t volatile vmask = ~(1 << tooth);
  223|  1.32M|                bits &= vmask;
  224|       |
  225|       |                /* Write the bit into position tooth (and junk into higher bits). */
  226|  1.32M|                bits ^= bitdata << tooth;
  227|  1.32M|                bit_pos += COMB_SPACING;
  ------------------
  |  |   79|  1.32M|#define COMB_SPACING CEIL_DIV(COMB_RANGE, COMB_BLOCKS * COMB_TEETH)
  |  |  ------------------
  |  |  |  |  190|  1.32M|#define CEIL_DIV(x, y) (1 + ((x) - 1) / (y))
  |  |  ------------------
  ------------------
  228|  1.32M|            }
  229|       |
  230|       |            /* If the top bit of bits is 1, flip them all (corresponding to looking up
  231|       |             * the negated table value), and remember to negate the result in sign. */
  232|   221k|            sign = (bits >> (COMB_TEETH - 1)) & 1;
  233|   221k|            abs = (bits ^ -sign) & (COMB_POINTS - 1);
  ------------------
  |  |   87|   221k|#define COMB_POINTS (1 << (COMB_TEETH - 1))
  ------------------
  234|   221k|            VERIFY_CHECK(sign == 0 || sign == 1);
  235|   221k|            VERIFY_CHECK(abs < COMB_POINTS);
  236|       |
  237|       |            /** This uses a conditional move to avoid any secret data in array indexes.
  238|       |             *   _Any_ use of secret indexes has been demonstrated to result in timing
  239|       |             *   sidechannels, even when the cache-line access patterns are uniform.
  240|       |             *  See also:
  241|       |             *   "A word of warning", CHES 2013 Rump Session, by Daniel J. Bernstein and Peter Schwabe
  242|       |             *    (https://cryptojedi.org/peter/data/chesrump-20130822.pdf) and
  243|       |             *   "Cache Attacks and Countermeasures: the Case of AES", RSA 2006,
  244|       |             *    by Dag Arne Osvik, Adi Shamir, and Eran Tromer
  245|       |             *    (https://eprint.iacr.org/2005/271.pdf)
  246|       |             */
  247|  7.30M|            for (index = 0; index < COMB_POINTS; ++index) {
  ------------------
  |  |   87|  7.30M|#define COMB_POINTS (1 << (COMB_TEETH - 1))
  ------------------
  |  Branch (247:29): [True: 7.07M, False: 221k]
  ------------------
  248|  7.07M|                secp256k1_ge_storage_cmov(&adds, &secp256k1_ecmult_gen_prec_table[block][index], index == abs);
  249|  7.07M|            }
  250|       |
  251|       |            /* Set add=adds or add=-adds, in constant time, based on sign. */
  252|   221k|            secp256k1_ge_from_storage(&add, &adds);
  253|   221k|            secp256k1_fe_negate(&neg, &add.y, 1);
  ------------------
  |  |  211|   221k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   221k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   221k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 221k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   221k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 221k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   221k|    } \
  |  |  |  |   94|   221k|    stmt; \
  |  |  |  |   95|   221k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 221k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  254|   221k|            secp256k1_fe_cmov(&add.y, &neg, sign);
  ------------------
  |  |   95|   221k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  255|       |
  256|       |            /* Add the looked up and conditionally negated value to r. */
  257|   221k|            if (EXPECT(first, 0)) {
  ------------------
  |  |  146|   221k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 5.14k, False: 216k]
  |  |  ------------------
  ------------------
  258|       |                /* If this is the first table lookup, we can skip addition. */
  259|  5.14k|                secp256k1_gej_set_ge(r, &add);
  260|       |                /* Give the entry a random Z coordinate to blind intermediary results. */
  261|  5.14k|                secp256k1_gej_rescale(r, &ctx->proj_blind);
  262|  5.14k|                first = 0;
  263|   216k|            } else {
  264|   216k|                secp256k1_gej_add_ge(r, r, &add);
  265|   216k|            }
  266|   221k|        }
  267|       |
  268|       |        /* Double the result, except in the last iteration. */
  269|  5.14k|        if (comb_off-- == 0) break;
  ------------------
  |  Branch (269:13): [True: 5.14k, False: 0]
  ------------------
  270|      0|        secp256k1_gej_double(r, r);
  271|      0|    }
  272|       |
  273|       |    /* Correct for the scalar_offset added at the start (ge_offset = b*G, while b was
  274|       |     * subtracted from the input scalar gn). */
  275|  5.14k|    secp256k1_gej_add_ge(r, r, &ctx->ge_offset);
  276|       |
  277|       |    /* Cleanup. */
  278|  5.14k|    secp256k1_fe_clear(&neg);
  279|  5.14k|    secp256k1_ge_clear(&add);
  280|  5.14k|    secp256k1_memclear_explicit(&adds, sizeof(adds));
  281|  5.14k|    secp256k1_memclear_explicit(&recoded, sizeof(recoded));
  282|  5.14k|}
secp256k1.c:secp256k1_ecmult_gen_ge:
  284|  5.14k|SECP256K1_INLINE static void secp256k1_ecmult_gen_ge(const secp256k1_ecmult_gen_context *ctx, secp256k1_ge *r, const secp256k1_scalar *a) {
  285|  5.14k|    secp256k1_gej rj;
  286|  5.14k|    secp256k1_ecmult_gen_gej(ctx, &rj, a);
  287|  5.14k|    secp256k1_ge_set_gej(r, &rj);
  288|       |    /* Jacobian coordinates resulting from our multiplication algorithm could potentially leak
  289|       |     * information about the secret input scalar, so clear the memory out to be on the safe side. */
  290|  5.14k|    secp256k1_gej_clear(&rj);
  291|  5.14k|}

secp256k1.c:secp256k1_ecmult_odd_multiples_table:
   73|  5.26k|static void secp256k1_ecmult_odd_multiples_table(size_t n, secp256k1_ge *pre_a, secp256k1_fe *zr, secp256k1_fe *z, const secp256k1_gej *a) {
   74|  5.26k|    secp256k1_gej d, ai;
   75|  5.26k|    secp256k1_ge d_ge;
   76|  5.26k|    size_t i;
   77|       |
   78|  5.26k|    VERIFY_CHECK(!secp256k1_gej_is_infinity(a));
   79|       |
   80|  5.26k|    secp256k1_gej_double_var(&d, a, NULL);
   81|       |
   82|       |    /*
   83|       |     * Perform the additions using an isomorphic curve Y^2 = X^3 + 7*C^6 where C := d.z.
   84|       |     * The isomorphism, phi, maps a secp256k1 point (x, y) to the point (x*C^2, y*C^3) on the other curve.
   85|       |     * In Jacobian coordinates phi maps (x, y, z) to (x*C^2, y*C^3, z) or, equivalently to (x, y, z/C).
   86|       |     *
   87|       |     *     phi(x, y, z) = (x*C^2, y*C^3, z) = (x, y, z/C)
   88|       |     *   d_ge := phi(d) = (d.x, d.y, 1)
   89|       |     *     ai := phi(a) = (a.x*C^2, a.y*C^3, a.z)
   90|       |     *
   91|       |     * The group addition functions work correctly on these isomorphic curves.
   92|       |     * In particular phi(d) is easy to represent in affine coordinates under this isomorphism.
   93|       |     * This lets us use the faster secp256k1_gej_add_ge_var group addition function that we wouldn't be able to use otherwise.
   94|       |     */
   95|  5.26k|    secp256k1_ge_set_xy(&d_ge, &d.x, &d.y);
   96|  5.26k|    secp256k1_ge_set_gej_zinv(&pre_a[0], a, &d.z);
   97|  5.26k|    secp256k1_gej_set_ge(&ai, &pre_a[0]);
   98|  5.26k|    ai.z = a->z;
   99|       |
  100|       |    /* pre_a[0] is the point (a.x*C^2, a.y*C^3, a.z*C) which is equivalent to a.
  101|       |     * Set zr[0] to C, which is the ratio between the omitted z(pre_a[0]) value and a.z.
  102|       |     */
  103|  5.26k|    zr[0] = d.z;
  104|       |
  105|  84.1k|    for (i = 1; i < n; i++) {
  ------------------
  |  Branch (105:17): [True: 78.9k, False: 5.26k]
  ------------------
  106|  78.9k|        secp256k1_gej_add_ge_var(&ai, &ai, &d_ge, &zr[i]);
  107|  78.9k|        secp256k1_ge_set_xy(&pre_a[i], &ai.x, &ai.y);
  108|  78.9k|    }
  109|       |
  110|       |    /* Multiply the last z-coordinate by C to undo the isomorphism.
  111|       |     * Since the z-coordinates of the pre_a values are implied by the zr array of z-coordinate ratios,
  112|       |     * undoing the isomorphism here undoes the isomorphism for all pre_a values.
  113|       |     */
  114|  5.26k|    secp256k1_fe_mul(z, &ai.z, &d.z);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  115|  5.26k|}

secp256k1.c:secp256k1_fe_impl_sqr:
  317|  7.58M|SECP256K1_FORCE_INLINE static void secp256k1_fe_impl_sqr(secp256k1_fe *r, const secp256k1_fe *a) {
  318|  7.58M|    secp256k1_fe_sqr_inner(r->n, a->n);
  319|  7.58M|}
secp256k1.c:secp256k1_fe_impl_mul:
  313|  6.74M|SECP256K1_FORCE_INLINE static void secp256k1_fe_impl_mul(secp256k1_fe *r, const secp256k1_fe *a, const secp256k1_fe * SECP256K1_RESTRICT b) {
  314|  6.74M|    secp256k1_fe_mul_inner(r->n, a->n, b->n);
  315|  6.74M|}
secp256k1.c:secp256k1_fe_impl_add_int:
  301|  28.3k|SECP256K1_INLINE static void secp256k1_fe_impl_add_int(secp256k1_fe *r, int a) {
  302|  28.3k|    r->n[0] += a;
  303|  28.3k|}
secp256k1.c:secp256k1_fe_impl_is_zero:
  206|  42.3k|SECP256K1_INLINE static int secp256k1_fe_impl_is_zero(const secp256k1_fe *a) {
  207|  42.3k|    const uint64_t *t = a->n;
  208|  42.3k|    return (t[0] | t[1] | t[2] | t[3] | t[4]) == 0;
  209|  42.3k|}
secp256k1.c:secp256k1_fe_impl_add:
  305|  6.70M|SECP256K1_INLINE static void secp256k1_fe_impl_add(secp256k1_fe *r, const secp256k1_fe *a) {
  306|  6.70M|    r->n[0] += a->n[0];
  307|  6.70M|    r->n[1] += a->n[1];
  308|  6.70M|    r->n[2] += a->n[2];
  309|  6.70M|    r->n[3] += a->n[3];
  310|  6.70M|    r->n[4] += a->n[4];
  311|  6.70M|}
secp256k1.c:secp256k1_fe_impl_normalize_weak:
   80|  51.5k|static void secp256k1_fe_impl_normalize_weak(secp256k1_fe *r) {
   81|  51.5k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
   82|       |
   83|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
   84|  51.5k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
   85|       |
   86|       |    /* The first pass ensures the magnitude is 1, ... */
   87|  51.5k|    t0 += x * 0x1000003D1ULL;
   88|  51.5k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
   89|  51.5k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL;
   90|  51.5k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL;
   91|  51.5k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL;
   92|       |
   93|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
   94|  51.5k|    VERIFY_CHECK(t4 >> 49 == 0);
   95|       |
   96|  51.5k|    r->n[0] = t0; r->n[1] = t1; r->n[2] = t2; r->n[3] = t3; r->n[4] = t4;
   97|  51.5k|}
secp256k1.c:secp256k1_fe_impl_negate_unchecked:
  278|  3.58M|SECP256K1_INLINE static void secp256k1_fe_impl_negate_unchecked(secp256k1_fe *r, const secp256k1_fe *a, int m) {
  279|       |    /* For all legal values of m (0..31), the following properties hold: */
  280|  3.58M|    VERIFY_CHECK(0xFFFFEFFFFFC2FULL * 2 * (m + 1) >= 0xFFFFFFFFFFFFFULL * 2 * m);
  281|  3.58M|    VERIFY_CHECK(0xFFFFFFFFFFFFFULL * 2 * (m + 1) >= 0xFFFFFFFFFFFFFULL * 2 * m);
  282|  3.58M|    VERIFY_CHECK(0x0FFFFFFFFFFFFULL * 2 * (m + 1) >= 0x0FFFFFFFFFFFFULL * 2 * m);
  283|       |
  284|       |    /* Due to the properties above, the left hand in the subtractions below is never less than
  285|       |     * the right hand. */
  286|  3.58M|    r->n[0] = 0xFFFFEFFFFFC2FULL * 2 * (m + 1) - a->n[0];
  287|  3.58M|    r->n[1] = 0xFFFFFFFFFFFFFULL * 2 * (m + 1) - a->n[1];
  288|  3.58M|    r->n[2] = 0xFFFFFFFFFFFFFULL * 2 * (m + 1) - a->n[2];
  289|  3.58M|    r->n[3] = 0xFFFFFFFFFFFFFULL * 2 * (m + 1) - a->n[3];
  290|  3.58M|    r->n[4] = 0x0FFFFFFFFFFFFULL * 2 * (m + 1) - a->n[4];
  291|  3.58M|}
secp256k1.c:secp256k1_fe_impl_cmov:
  321|  11.6M|SECP256K1_INLINE static void secp256k1_fe_impl_cmov(secp256k1_fe *r, const secp256k1_fe *a, int flag) {
  322|  11.6M|    uint64_t mask0, mask1;
  323|  11.6M|    volatile int vflag = flag;
  324|  11.6M|    VERIFY_CHECK(flag == 0 || flag == 1);
  325|  11.6M|    SECP256K1_CHECKMEM_CHECK_VERIFY(r->n, sizeof(r->n));
  ------------------
  |  |  114|  11.6M|#define SECP256K1_CHECKMEM_CHECK_VERIFY(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  11.6M|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 11.6M]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  326|  11.6M|    mask0 = vflag + ~((uint64_t)0);
  327|  11.6M|    mask1 = ~mask0;
  328|  11.6M|    r->n[0] = (r->n[0] & mask0) | (a->n[0] & mask1);
  329|  11.6M|    r->n[1] = (r->n[1] & mask0) | (a->n[1] & mask1);
  330|  11.6M|    r->n[2] = (r->n[2] & mask0) | (a->n[2] & mask1);
  331|  11.6M|    r->n[3] = (r->n[3] & mask0) | (a->n[3] & mask1);
  332|  11.6M|    r->n[4] = (r->n[4] & mask0) | (a->n[4] & mask1);
  333|  11.6M|}
secp256k1.c:secp256k1_fe_impl_normalizes_to_zero:
  137|   987k|static int secp256k1_fe_impl_normalizes_to_zero(const secp256k1_fe *r) {
  138|   987k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
  139|       |
  140|       |    /* z0 tracks a possible raw value of 0, z1 tracks a possible raw value of P */
  141|   987k|    uint64_t z0, z1;
  142|       |
  143|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
  144|   987k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
  145|       |
  146|       |    /* The first pass ensures the magnitude is 1, ... */
  147|   987k|    t0 += x * 0x1000003D1ULL;
  148|   987k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL; z0  = t0; z1  = t0 ^ 0x1000003D0ULL;
  149|   987k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; z0 |= t1; z1 &= t1;
  150|   987k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; z0 |= t2; z1 &= t2;
  151|   987k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; z0 |= t3; z1 &= t3;
  152|   987k|                                                z0 |= t4; z1 &= t4 ^ 0xF000000000000ULL;
  153|       |
  154|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
  155|   987k|    VERIFY_CHECK(t4 >> 49 == 0);
  156|       |
  157|   987k|    return (z0 == 0) | (z1 == 0xFFFFFFFFFFFFFULL);
  158|   987k|}
secp256k1.c:secp256k1_fe_impl_set_int:
  201|  26.0k|SECP256K1_INLINE static void secp256k1_fe_impl_set_int(secp256k1_fe *r, int a) {
  202|  26.0k|    r->n[0] = a;
  203|  26.0k|    r->n[1] = r->n[2] = r->n[3] = r->n[4] = 0;
  204|  26.0k|}
secp256k1.c:secp256k1_fe_impl_mul_int_unchecked:
  293|  1.67M|SECP256K1_INLINE static void secp256k1_fe_impl_mul_int_unchecked(secp256k1_fe *r, int a) {
  294|  1.67M|    r->n[0] *= a;
  295|  1.67M|    r->n[1] *= a;
  296|  1.67M|    r->n[2] *= a;
  297|  1.67M|    r->n[3] *= a;
  298|  1.67M|    r->n[4] *= a;
  299|  1.67M|}
secp256k1.c:secp256k1_fe_impl_half:
  335|  1.15M|static SECP256K1_INLINE void secp256k1_fe_impl_half(secp256k1_fe *r) {
  336|  1.15M|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
  337|  1.15M|    uint64_t one = (uint64_t)1;
  338|  1.15M|    uint64_t mask = -(t0 & one) >> 12;
  339|       |
  340|       |    /* Bounds analysis (over the rationals).
  341|       |     *
  342|       |     * Let m = r->magnitude
  343|       |     *     C = 0xFFFFFFFFFFFFFULL * 2
  344|       |     *     D = 0x0FFFFFFFFFFFFULL * 2
  345|       |     *
  346|       |     * Initial bounds: t0..t3 <= C * m
  347|       |     *                     t4 <= D * m
  348|       |     */
  349|       |
  350|  1.15M|    t0 += 0xFFFFEFFFFFC2FULL & mask;
  351|  1.15M|    t1 += mask;
  352|  1.15M|    t2 += mask;
  353|  1.15M|    t3 += mask;
  354|  1.15M|    t4 += mask >> 4;
  355|       |
  356|  1.15M|    VERIFY_CHECK((t0 & one) == 0);
  357|       |
  358|       |    /* t0..t3: added <= C/2
  359|       |     *     t4: added <= D/2
  360|       |     *
  361|       |     * Current bounds: t0..t3 <= C * (m + 1/2)
  362|       |     *                     t4 <= D * (m + 1/2)
  363|       |     */
  364|       |
  365|  1.15M|    r->n[0] = (t0 >> 1) + ((t1 & one) << 51);
  366|  1.15M|    r->n[1] = (t1 >> 1) + ((t2 & one) << 51);
  367|  1.15M|    r->n[2] = (t2 >> 1) + ((t3 & one) << 51);
  368|  1.15M|    r->n[3] = (t3 >> 1) + ((t4 & one) << 51);
  369|  1.15M|    r->n[4] = (t4 >> 1);
  370|       |
  371|       |    /* t0..t3: shifted right and added <= C/4 + 1/2
  372|       |     *     t4: shifted right
  373|       |     *
  374|       |     * Current bounds: t0..t3 <= C * (m/2 + 1/2)
  375|       |     *                     t4 <= D * (m/2 + 1/4)
  376|       |     *
  377|       |     * Therefore the output magnitude (M) has to be set such that:
  378|       |     *     t0..t3: C * M >= C * (m/2 + 1/2)
  379|       |     *         t4: D * M >= D * (m/2 + 1/4)
  380|       |     *
  381|       |     * It suffices for all limbs that, for any input magnitude m:
  382|       |     *     M >= m/2 + 1/2
  383|       |     *
  384|       |     * and since we want the smallest such integer value for M:
  385|       |     *     M == floor(m/2) + 1
  386|       |     */
  387|  1.15M|}
secp256k1.c:secp256k1_fe_impl_inv:
  453|  10.4k|static void secp256k1_fe_impl_inv(secp256k1_fe *r, const secp256k1_fe *x) {
  454|  10.4k|    secp256k1_fe tmp = *x;
  455|  10.4k|    secp256k1_modinv64_signed62 s;
  456|       |
  457|  10.4k|    secp256k1_fe_normalize(&tmp);
  ------------------
  |  |   78|  10.4k|#  define secp256k1_fe_normalize secp256k1_fe_impl_normalize
  ------------------
  458|  10.4k|    secp256k1_fe_to_signed62(&s, &tmp);
  459|  10.4k|    secp256k1_modinv64(&s, &secp256k1_const_modinfo_fe);
  460|  10.4k|    secp256k1_fe_from_signed62(r, &s);
  461|  10.4k|}
secp256k1.c:secp256k1_fe_to_signed62:
  437|  57.9k|static void secp256k1_fe_to_signed62(secp256k1_modinv64_signed62 *r, const secp256k1_fe *a) {
  438|  57.9k|    const uint64_t M62 = UINT64_MAX >> 2;
  439|  57.9k|    const uint64_t a0 = a->n[0], a1 = a->n[1], a2 = a->n[2], a3 = a->n[3], a4 = a->n[4];
  440|       |
  441|  57.9k|    r->v[0] = (a0       | a1 << 52) & M62;
  442|  57.9k|    r->v[1] = (a1 >> 10 | a2 << 42) & M62;
  443|  57.9k|    r->v[2] = (a2 >> 20 | a3 << 32) & M62;
  444|  57.9k|    r->v[3] = (a3 >> 30 | a4 << 22) & M62;
  445|  57.9k|    r->v[4] =  a4 >> 40;
  446|  57.9k|}
secp256k1.c:secp256k1_fe_from_signed62:
  417|  15.5k|static void secp256k1_fe_from_signed62(secp256k1_fe *r, const secp256k1_modinv64_signed62 *a) {
  418|  15.5k|    const uint64_t M52 = UINT64_MAX >> 12;
  419|  15.5k|    const uint64_t a0 = a->v[0], a1 = a->v[1], a2 = a->v[2], a3 = a->v[3], a4 = a->v[4];
  420|       |
  421|       |    /* The output from secp256k1_modinv64{_var} should be normalized to range [0,modulus), and
  422|       |     * have limbs in [0,2^62). The modulus is < 2^256, so the top limb must be below 2^(256-62*4).
  423|       |     */
  424|  15.5k|    VERIFY_CHECK(a0 >> 62 == 0);
  425|  15.5k|    VERIFY_CHECK(a1 >> 62 == 0);
  426|  15.5k|    VERIFY_CHECK(a2 >> 62 == 0);
  427|  15.5k|    VERIFY_CHECK(a3 >> 62 == 0);
  428|  15.5k|    VERIFY_CHECK(a4 >> 8 == 0);
  429|       |
  430|  15.5k|    r->n[0] =  a0                   & M52;
  431|  15.5k|    r->n[1] = (a0 >> 52 | a1 << 10) & M52;
  432|  15.5k|    r->n[2] = (a1 >> 42 | a2 << 20) & M52;
  433|  15.5k|    r->n[3] = (a2 >> 32 | a3 << 30) & M52;
  434|  15.5k|    r->n[4] = (a3 >> 22 | a4 << 40);
  435|  15.5k|}
secp256k1.c:secp256k1_fe_impl_get_b32:
  271|  10.4k|static void secp256k1_fe_impl_get_b32(unsigned char *r, const secp256k1_fe *a) {
  272|  10.4k|    secp256k1_write_be64(&r[0], (a->n[4] << 16) | (a->n[3] >> 36));
  273|  10.4k|    secp256k1_write_be64(&r[8], (a->n[3] << 28) | (a->n[2] >> 24));
  274|  10.4k|    secp256k1_write_be64(&r[16], (a->n[2] << 40) | (a->n[1] >> 12));
  275|  10.4k|    secp256k1_write_be64(&r[24], (a->n[1] << 52) | a->n[0]);
  276|  10.4k|}
secp256k1.c:secp256k1_fe_impl_normalize_var:
   99|  65.7k|static void secp256k1_fe_impl_normalize_var(secp256k1_fe *r) {
  100|  65.7k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
  101|       |
  102|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
  103|  65.7k|    uint64_t m;
  104|  65.7k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
  105|       |
  106|       |    /* The first pass ensures the magnitude is 1, ... */
  107|  65.7k|    t0 += x * 0x1000003D1ULL;
  108|  65.7k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
  109|  65.7k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; m = t1;
  110|  65.7k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; m &= t2;
  111|  65.7k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; m &= t3;
  112|       |
  113|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
  114|  65.7k|    VERIFY_CHECK(t4 >> 49 == 0);
  115|       |
  116|       |    /* At most a single final reduction is needed; check if the value is >= the field characteristic */
  117|  65.7k|    x = (t4 >> 48) | ((t4 == 0x0FFFFFFFFFFFFULL) & (m == 0xFFFFFFFFFFFFFULL)
  118|  65.7k|        & (t0 >= 0xFFFFEFFFFFC2FULL));
  119|       |
  120|  65.7k|    if (x) {
  ------------------
  |  Branch (120:9): [True: 0, False: 65.7k]
  ------------------
  121|      0|        t0 += 0x1000003D1ULL;
  122|      0|        t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
  123|      0|        t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL;
  124|      0|        t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL;
  125|      0|        t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL;
  126|       |
  127|       |        /* If t4 didn't carry to bit 48 already, then it should have after any final reduction */
  128|      0|        VERIFY_CHECK(t4 >> 48 == x);
  129|       |
  130|       |        /* Mask off the possible multiple of 2^256 from the final reduction */
  131|      0|        t4 &= 0x0FFFFFFFFFFFFULL;
  132|      0|    }
  133|       |
  134|  65.7k|    r->n[0] = t0; r->n[1] = t1; r->n[2] = t2; r->n[3] = t3; r->n[4] = t4;
  135|  65.7k|}
secp256k1.c:secp256k1_fe_impl_is_odd:
  211|  10.2k|SECP256K1_INLINE static int secp256k1_fe_impl_is_odd(const secp256k1_fe *a) {
  212|  10.2k|    return a->n[0] & 1;
  213|  10.2k|}
secp256k1.c:secp256k1_fe_impl_from_storage:
  409|   442k|static SECP256K1_INLINE void secp256k1_fe_impl_from_storage(secp256k1_fe *r, const secp256k1_fe_storage *a) {
  410|   442k|    r->n[0] = a->n[0] & 0xFFFFFFFFFFFFFULL;
  411|   442k|    r->n[1] = a->n[0] >> 52 | ((a->n[1] << 12) & 0xFFFFFFFFFFFFFULL);
  412|   442k|    r->n[2] = a->n[1] >> 40 | ((a->n[2] << 24) & 0xFFFFFFFFFFFFFULL);
  413|   442k|    r->n[3] = a->n[2] >> 28 | ((a->n[3] << 36) & 0xFFFFFFFFFFFFFULL);
  414|   442k|    r->n[4] = a->n[3] >> 16;
  415|   442k|}
secp256k1.c:secp256k1_fe_impl_normalizes_to_zero_var:
  160|  99.5k|static int secp256k1_fe_impl_normalizes_to_zero_var(const secp256k1_fe *r) {
  161|  99.5k|    uint64_t t0, t1, t2, t3, t4;
  162|  99.5k|    uint64_t z0, z1;
  163|  99.5k|    uint64_t x;
  164|       |
  165|  99.5k|    t0 = r->n[0];
  166|  99.5k|    t4 = r->n[4];
  167|       |
  168|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
  169|  99.5k|    x = t4 >> 48;
  170|       |
  171|       |    /* The first pass ensures the magnitude is 1, ... */
  172|  99.5k|    t0 += x * 0x1000003D1ULL;
  173|       |
  174|       |    /* z0 tracks a possible raw value of 0, z1 tracks a possible raw value of P */
  175|  99.5k|    z0 = t0 & 0xFFFFFFFFFFFFFULL;
  176|  99.5k|    z1 = z0 ^ 0x1000003D0ULL;
  177|       |
  178|       |    /* Fast return path should catch the majority of cases */
  179|  99.5k|    if ((z0 != 0ULL) & (z1 != 0xFFFFFFFFFFFFFULL)) {
  ------------------
  |  Branch (179:9): [True: 99.5k, False: 0]
  ------------------
  180|  99.5k|        return 0;
  181|  99.5k|    }
  182|       |
  183|      0|    t1 = r->n[1];
  184|      0|    t2 = r->n[2];
  185|      0|    t3 = r->n[3];
  186|       |
  187|      0|    t4 &= 0x0FFFFFFFFFFFFULL;
  188|       |
  189|      0|    t1 += (t0 >> 52);
  190|      0|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; z0 |= t1; z1 &= t1;
  191|      0|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; z0 |= t2; z1 &= t2;
  192|      0|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; z0 |= t3; z1 &= t3;
  193|      0|                                                z0 |= t4; z1 &= t4 ^ 0xF000000000000ULL;
  194|       |
  195|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
  196|      0|    VERIFY_CHECK(t4 >> 49 == 0);
  197|       |
  198|      0|    return (z0 == 0) | (z1 == 0xFFFFFFFFFFFFFULL);
  199|  99.5k|}
secp256k1.c:secp256k1_fe_impl_inv_var:
  463|  5.14k|static void secp256k1_fe_impl_inv_var(secp256k1_fe *r, const secp256k1_fe *x) {
  464|  5.14k|    secp256k1_fe tmp = *x;
  465|  5.14k|    secp256k1_modinv64_signed62 s;
  466|       |
  467|  5.14k|    secp256k1_fe_normalize_var(&tmp);
  ------------------
  |  |   80|  5.14k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  468|  5.14k|    secp256k1_fe_to_signed62(&s, &tmp);
  469|  5.14k|    secp256k1_modinv64_var(&s, &secp256k1_const_modinfo_fe);
  470|  5.14k|    secp256k1_fe_from_signed62(r, &s);
  471|  5.14k|}
secp256k1.c:secp256k1_fe_storage_cmov:
  389|  14.1M|static SECP256K1_INLINE void secp256k1_fe_storage_cmov(secp256k1_fe_storage *r, const secp256k1_fe_storage *a, int flag) {
  390|  14.1M|    uint64_t mask0, mask1;
  391|  14.1M|    volatile int vflag = flag;
  392|  14.1M|    VERIFY_CHECK(flag == 0 || flag == 1);
  393|  14.1M|    SECP256K1_CHECKMEM_CHECK_VERIFY(r->n, sizeof(r->n));
  ------------------
  |  |  114|  14.1M|#define SECP256K1_CHECKMEM_CHECK_VERIFY(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  14.1M|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 14.1M]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  394|  14.1M|    mask0 = vflag + ~((uint64_t)0);
  395|  14.1M|    mask1 = ~mask0;
  396|  14.1M|    r->n[0] = (r->n[0] & mask0) | (a->n[0] & mask1);
  397|  14.1M|    r->n[1] = (r->n[1] & mask0) | (a->n[1] & mask1);
  398|  14.1M|    r->n[2] = (r->n[2] & mask0) | (a->n[2] & mask1);
  399|  14.1M|    r->n[3] = (r->n[3] & mask0) | (a->n[3] & mask1);
  400|  14.1M|}
secp256k1.c:secp256k1_fe_impl_is_square_var:
  473|  42.3k|static int secp256k1_fe_impl_is_square_var(const secp256k1_fe *x) {
  474|  42.3k|    secp256k1_fe tmp;
  475|  42.3k|    secp256k1_modinv64_signed62 s;
  476|  42.3k|    int jac, ret;
  477|       |
  478|  42.3k|    tmp = *x;
  479|  42.3k|    secp256k1_fe_normalize_var(&tmp);
  ------------------
  |  |   80|  42.3k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  480|       |    /* secp256k1_jacobi64_maybe_var cannot deal with input 0. */
  481|  42.3k|    if (secp256k1_fe_is_zero(&tmp)) return 1;
  ------------------
  |  |   84|  42.3k|#  define secp256k1_fe_is_zero secp256k1_fe_impl_is_zero
  ------------------
  |  Branch (481:9): [True: 0, False: 42.3k]
  ------------------
  482|  42.3k|    secp256k1_fe_to_signed62(&s, &tmp);
  483|  42.3k|    jac = secp256k1_jacobi64_maybe_var(&s, &secp256k1_const_modinfo_fe);
  484|  42.3k|    if (jac == 0) {
  ------------------
  |  Branch (484:9): [True: 0, False: 42.3k]
  ------------------
  485|       |        /* secp256k1_jacobi64_maybe_var failed to compute the Jacobi symbol. Fall back
  486|       |         * to computing a square root. This should be extremely rare with random
  487|       |         * input (except in VERIFY mode, where a lower iteration count is used). */
  488|      0|        secp256k1_fe dummy;
  489|      0|        ret = secp256k1_fe_sqrt(&dummy, &tmp);
  490|  42.3k|    } else {
  491|  42.3k|        ret = jac >= 0;
  492|  42.3k|    }
  493|  42.3k|    return ret;
  494|  42.3k|}
secp256k1.c:secp256k1_fe_impl_set_b32_mod:
  228|  33.6k|static void secp256k1_fe_impl_set_b32_mod(secp256k1_fe *r, const unsigned char *a) {
  229|  33.6k|    r->n[0] = (uint64_t)a[31]
  230|  33.6k|            | ((uint64_t)a[30] << 8)
  231|  33.6k|            | ((uint64_t)a[29] << 16)
  232|  33.6k|            | ((uint64_t)a[28] << 24)
  233|  33.6k|            | ((uint64_t)a[27] << 32)
  234|  33.6k|            | ((uint64_t)a[26] << 40)
  235|  33.6k|            | ((uint64_t)(a[25] & 0xF)  << 48);
  236|  33.6k|    r->n[1] = (uint64_t)((a[25] >> 4) & 0xF)
  237|  33.6k|            | ((uint64_t)a[24] << 4)
  238|  33.6k|            | ((uint64_t)a[23] << 12)
  239|  33.6k|            | ((uint64_t)a[22] << 20)
  240|  33.6k|            | ((uint64_t)a[21] << 28)
  241|  33.6k|            | ((uint64_t)a[20] << 36)
  242|  33.6k|            | ((uint64_t)a[19] << 44);
  243|  33.6k|    r->n[2] = (uint64_t)a[18]
  244|  33.6k|            | ((uint64_t)a[17] << 8)
  245|  33.6k|            | ((uint64_t)a[16] << 16)
  246|  33.6k|            | ((uint64_t)a[15] << 24)
  247|  33.6k|            | ((uint64_t)a[14] << 32)
  248|  33.6k|            | ((uint64_t)a[13] << 40)
  249|  33.6k|            | ((uint64_t)(a[12] & 0xF) << 48);
  250|  33.6k|    r->n[3] = (uint64_t)((a[12] >> 4) & 0xF)
  251|  33.6k|            | ((uint64_t)a[11] << 4)
  252|  33.6k|            | ((uint64_t)a[10] << 12)
  253|  33.6k|            | ((uint64_t)a[9]  << 20)
  254|  33.6k|            | ((uint64_t)a[8]  << 28)
  255|  33.6k|            | ((uint64_t)a[7]  << 36)
  256|  33.6k|            | ((uint64_t)a[6]  << 44);
  257|  33.6k|    r->n[4] = (uint64_t)a[5]
  258|  33.6k|            | ((uint64_t)a[4] << 8)
  259|  33.6k|            | ((uint64_t)a[3] << 16)
  260|  33.6k|            | ((uint64_t)a[2] << 24)
  261|  33.6k|            | ((uint64_t)a[1] << 32)
  262|  33.6k|            | ((uint64_t)a[0] << 40);
  263|  33.6k|}
secp256k1.c:secp256k1_fe_impl_normalize:
   43|  15.6k|static void secp256k1_fe_impl_normalize(secp256k1_fe *r) {
   44|  15.6k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
   45|       |
   46|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
   47|  15.6k|    uint64_t m;
   48|  15.6k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
   49|       |
   50|       |    /* The first pass ensures the magnitude is 1, ... */
   51|  15.6k|    t0 += x * 0x1000003D1ULL;
   52|  15.6k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
   53|  15.6k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; m = t1;
   54|  15.6k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; m &= t2;
   55|  15.6k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; m &= t3;
   56|       |
   57|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
   58|  15.6k|    VERIFY_CHECK(t4 >> 49 == 0);
   59|       |
   60|       |    /* At most a single final reduction is needed; check if the value is >= the field characteristic */
   61|  15.6k|    x = (t4 >> 48) | ((t4 == 0x0FFFFFFFFFFFFULL) & (m == 0xFFFFFFFFFFFFFULL)
   62|  15.6k|        & (t0 >= 0xFFFFEFFFFFC2FULL));
   63|       |
   64|       |    /* Apply the final reduction (for constant-time behaviour, we do it always) */
   65|  15.6k|    t0 += x * 0x1000003D1ULL;
   66|  15.6k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
   67|  15.6k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL;
   68|  15.6k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL;
   69|  15.6k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL;
   70|       |
   71|       |    /* If t4 didn't carry to bit 48 already, then it should have after any final reduction */
   72|  15.6k|    VERIFY_CHECK(t4 >> 48 == x);
   73|       |
   74|       |    /* Mask off the possible multiple of 2^256 from the final reduction */
   75|  15.6k|    t4 &= 0x0FFFFFFFFFFFFULL;
   76|       |
   77|  15.6k|    r->n[0] = t0; r->n[1] = t1; r->n[2] = t2; r->n[3] = t3; r->n[4] = t4;
   78|  15.6k|}

secp256k1.c:secp256k1_fe_sqr_inner:
  154|  7.58M|SECP256K1_FORCE_INLINE static void secp256k1_fe_sqr_inner(uint64_t *r, const uint64_t *a) {
  155|  7.58M|    secp256k1_uint128 c, d;
  156|  7.58M|    uint64_t a0 = a[0], a1 = a[1], a2 = a[2], a3 = a[3], a4 = a[4];
  157|  7.58M|    uint64_t t3, t4, tx, u0;
  158|  7.58M|    const uint64_t M = 0xFFFFFFFFFFFFFULL, R = 0x1000003D10ULL;
  159|       |
  160|  7.58M|    VERIFY_BITS(a[0], 56);
  161|  7.58M|    VERIFY_BITS(a[1], 56);
  162|  7.58M|    VERIFY_BITS(a[2], 56);
  163|  7.58M|    VERIFY_BITS(a[3], 56);
  164|  7.58M|    VERIFY_BITS(a[4], 52);
  165|       |
  166|       |    /**  [... a b c] is a shorthand for ... + a<<104 + b<<52 + c<<0 mod n.
  167|       |     *  px is a shorthand for sum(a[i]*a[x-i], i=0..x).
  168|       |     *  Note that [x 0 0 0 0 0] = [x*R].
  169|       |     */
  170|       |
  171|  7.58M|    secp256k1_u128_mul(&d, a0*2, a3);
  172|  7.58M|    secp256k1_u128_accum_mul(&d, a1*2, a2);
  173|  7.58M|    VERIFY_BITS_128(&d, 114);
  174|       |    /* [d 0 0 0] = [p3 0 0 0] */
  175|  7.58M|    secp256k1_u128_mul(&c, a4, a4);
  176|  7.58M|    VERIFY_BITS_128(&c, 112);
  177|       |    /* [c 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
  178|  7.58M|    secp256k1_u128_accum_mul(&d, R, secp256k1_u128_to_u64(&c)); secp256k1_u128_rshift(&c, 64);
  179|  7.58M|    VERIFY_BITS_128(&d, 115);
  180|  7.58M|    VERIFY_BITS_128(&c, 48);
  181|       |    /* [(c<<12) 0 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
  182|  7.58M|    t3 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
  183|  7.58M|    VERIFY_BITS(t3, 52);
  184|  7.58M|    VERIFY_BITS_128(&d, 63);
  185|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
  186|       |
  187|  7.58M|    a4 *= 2;
  188|  7.58M|    secp256k1_u128_accum_mul(&d, a0, a4);
  189|  7.58M|    secp256k1_u128_accum_mul(&d, a1*2, a3);
  190|  7.58M|    secp256k1_u128_accum_mul(&d, a2, a2);
  191|  7.58M|    VERIFY_BITS_128(&d, 115);
  192|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  193|  7.58M|    secp256k1_u128_accum_mul(&d, R << 12, secp256k1_u128_to_u64(&c));
  194|  7.58M|    VERIFY_BITS_128(&d, 116);
  195|       |    /* [d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  196|  7.58M|    t4 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
  197|  7.58M|    VERIFY_BITS(t4, 52);
  198|  7.58M|    VERIFY_BITS_128(&d, 64);
  199|       |    /* [d t4 t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  200|  7.58M|    tx = (t4 >> 48); t4 &= (M >> 4);
  201|  7.58M|    VERIFY_BITS(tx, 4);
  202|  7.58M|    VERIFY_BITS(t4, 48);
  203|       |    /* [d t4+(tx<<48) t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  204|       |
  205|  7.58M|    secp256k1_u128_mul(&c, a0, a0);
  206|  7.58M|    VERIFY_BITS_128(&c, 112);
  207|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 0 p4 p3 0 0 p0] */
  208|  7.58M|    secp256k1_u128_accum_mul(&d, a1, a4);
  209|  7.58M|    secp256k1_u128_accum_mul(&d, a2*2, a3);
  210|  7.58M|    VERIFY_BITS_128(&d, 114);
  211|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  212|  7.58M|    u0 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
  213|  7.58M|    VERIFY_BITS(u0, 52);
  214|  7.58M|    VERIFY_BITS_128(&d, 62);
  215|       |    /* [d u0 t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  216|       |    /* [d 0 t4+(tx<<48)+(u0<<52) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  217|  7.58M|    u0 = (u0 << 4) | tx;
  218|  7.58M|    VERIFY_BITS(u0, 56);
  219|       |    /* [d 0 t4+(u0<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  220|  7.58M|    secp256k1_u128_accum_mul(&c, u0, R >> 4);
  221|  7.58M|    VERIFY_BITS_128(&c, 113);
  222|       |    /* [d 0 t4 t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  223|  7.58M|    r[0] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  224|  7.58M|    VERIFY_BITS(r[0], 52);
  225|  7.58M|    VERIFY_BITS_128(&c, 61);
  226|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 0 p0] */
  227|       |
  228|  7.58M|    a0 *= 2;
  229|  7.58M|    secp256k1_u128_accum_mul(&c, a0, a1);
  230|  7.58M|    VERIFY_BITS_128(&c, 114);
  231|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 p1 p0] */
  232|  7.58M|    secp256k1_u128_accum_mul(&d, a2, a4);
  233|  7.58M|    secp256k1_u128_accum_mul(&d, a3, a3);
  234|  7.58M|    VERIFY_BITS_128(&d, 114);
  235|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  236|  7.58M|    secp256k1_u128_accum_mul(&c, secp256k1_u128_to_u64(&d) & M, R); secp256k1_u128_rshift(&d, 52);
  237|  7.58M|    VERIFY_BITS_128(&c, 115);
  238|  7.58M|    VERIFY_BITS_128(&d, 62);
  239|       |    /* [d 0 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  240|  7.58M|    r[1] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  241|  7.58M|    VERIFY_BITS(r[1], 52);
  242|  7.58M|    VERIFY_BITS_128(&c, 63);
  243|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  244|       |
  245|  7.58M|    secp256k1_u128_accum_mul(&c, a0, a2);
  246|  7.58M|    secp256k1_u128_accum_mul(&c, a1, a1);
  247|  7.58M|    VERIFY_BITS_128(&c, 114);
  248|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 p2 p1 p0] */
  249|  7.58M|    secp256k1_u128_accum_mul(&d, a3, a4);
  250|  7.58M|    VERIFY_BITS_128(&d, 114);
  251|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  252|  7.58M|    secp256k1_u128_accum_mul(&c, R, secp256k1_u128_to_u64(&d)); secp256k1_u128_rshift(&d, 64);
  253|  7.58M|    VERIFY_BITS_128(&c, 115);
  254|  7.58M|    VERIFY_BITS_128(&d, 50);
  255|       |    /* [(d<<12) 0 0 0 t4 t3 c r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  256|  7.58M|    r[2] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  257|  7.58M|    VERIFY_BITS(r[2], 52);
  258|  7.58M|    VERIFY_BITS_128(&c, 63);
  259|       |    /* [(d<<12) 0 0 0 t4 t3+c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  260|       |
  261|  7.58M|    secp256k1_u128_accum_mul(&c, R << 12, secp256k1_u128_to_u64(&d));
  262|  7.58M|    secp256k1_u128_accum_u64(&c, t3);
  263|  7.58M|    VERIFY_BITS_128(&c, 100);
  264|       |    /* [t4 c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  265|  7.58M|    r[3] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  266|  7.58M|    VERIFY_BITS(r[3], 52);
  267|  7.58M|    VERIFY_BITS_128(&c, 48);
  268|       |    /* [t4+c r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  269|  7.58M|    r[4] = secp256k1_u128_to_u64(&c) + t4;
  270|  7.58M|    VERIFY_BITS(r[4], 49);
  271|       |    /* [r4 r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  272|  7.58M|}
secp256k1.c:secp256k1_fe_mul_inner:
   18|  6.74M|SECP256K1_FORCE_INLINE static void secp256k1_fe_mul_inner(uint64_t *r, const uint64_t *a, const uint64_t * SECP256K1_RESTRICT b) {
   19|  6.74M|    secp256k1_uint128 c, d;
   20|  6.74M|    uint64_t t3, t4, tx, u0;
   21|  6.74M|    uint64_t a0 = a[0], a1 = a[1], a2 = a[2], a3 = a[3], a4 = a[4];
   22|  6.74M|    const uint64_t M = 0xFFFFFFFFFFFFFULL, R = 0x1000003D10ULL;
   23|       |
   24|  6.74M|    VERIFY_BITS(a[0], 56);
   25|  6.74M|    VERIFY_BITS(a[1], 56);
   26|  6.74M|    VERIFY_BITS(a[2], 56);
   27|  6.74M|    VERIFY_BITS(a[3], 56);
   28|  6.74M|    VERIFY_BITS(a[4], 52);
   29|  6.74M|    VERIFY_BITS(b[0], 56);
   30|  6.74M|    VERIFY_BITS(b[1], 56);
   31|  6.74M|    VERIFY_BITS(b[2], 56);
   32|  6.74M|    VERIFY_BITS(b[3], 56);
   33|  6.74M|    VERIFY_BITS(b[4], 52);
   34|  6.74M|    VERIFY_CHECK(r != b);
   35|  6.74M|    VERIFY_CHECK(a != b);
   36|       |
   37|       |    /*  [... a b c] is a shorthand for ... + a<<104 + b<<52 + c<<0 mod n.
   38|       |     *  for 0 <= x <= 4, px is a shorthand for sum(a[i]*b[x-i], i=0..x).
   39|       |     *  for 4 <= x <= 8, px is a shorthand for sum(a[i]*b[x-i], i=(x-4)..4)
   40|       |     *  Note that [x 0 0 0 0 0] = [x*R].
   41|       |     */
   42|       |
   43|  6.74M|    secp256k1_u128_mul(&d, a0, b[3]);
   44|  6.74M|    secp256k1_u128_accum_mul(&d, a1, b[2]);
   45|  6.74M|    secp256k1_u128_accum_mul(&d, a2, b[1]);
   46|  6.74M|    secp256k1_u128_accum_mul(&d, a3, b[0]);
   47|  6.74M|    VERIFY_BITS_128(&d, 114);
   48|       |    /* [d 0 0 0] = [p3 0 0 0] */
   49|  6.74M|    secp256k1_u128_mul(&c, a4, b[4]);
   50|  6.74M|    VERIFY_BITS_128(&c, 112);
   51|       |    /* [c 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
   52|  6.74M|    secp256k1_u128_accum_mul(&d, R, secp256k1_u128_to_u64(&c)); secp256k1_u128_rshift(&c, 64);
   53|  6.74M|    VERIFY_BITS_128(&d, 115);
   54|  6.74M|    VERIFY_BITS_128(&c, 48);
   55|       |    /* [(c<<12) 0 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
   56|  6.74M|    t3 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
   57|  6.74M|    VERIFY_BITS(t3, 52);
   58|  6.74M|    VERIFY_BITS_128(&d, 63);
   59|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
   60|       |
   61|  6.74M|    secp256k1_u128_accum_mul(&d, a0, b[4]);
   62|  6.74M|    secp256k1_u128_accum_mul(&d, a1, b[3]);
   63|  6.74M|    secp256k1_u128_accum_mul(&d, a2, b[2]);
   64|  6.74M|    secp256k1_u128_accum_mul(&d, a3, b[1]);
   65|  6.74M|    secp256k1_u128_accum_mul(&d, a4, b[0]);
   66|  6.74M|    VERIFY_BITS_128(&d, 115);
   67|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   68|  6.74M|    secp256k1_u128_accum_mul(&d, R << 12, secp256k1_u128_to_u64(&c));
   69|  6.74M|    VERIFY_BITS_128(&d, 116);
   70|       |    /* [d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   71|  6.74M|    t4 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
   72|  6.74M|    VERIFY_BITS(t4, 52);
   73|  6.74M|    VERIFY_BITS_128(&d, 64);
   74|       |    /* [d t4 t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   75|  6.74M|    tx = (t4 >> 48); t4 &= (M >> 4);
   76|  6.74M|    VERIFY_BITS(tx, 4);
   77|  6.74M|    VERIFY_BITS(t4, 48);
   78|       |    /* [d t4+(tx<<48) t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   79|       |
   80|  6.74M|    secp256k1_u128_mul(&c, a0, b[0]);
   81|  6.74M|    VERIFY_BITS_128(&c, 112);
   82|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 0 p4 p3 0 0 p0] */
   83|  6.74M|    secp256k1_u128_accum_mul(&d, a1, b[4]);
   84|  6.74M|    secp256k1_u128_accum_mul(&d, a2, b[3]);
   85|  6.74M|    secp256k1_u128_accum_mul(&d, a3, b[2]);
   86|  6.74M|    secp256k1_u128_accum_mul(&d, a4, b[1]);
   87|  6.74M|    VERIFY_BITS_128(&d, 114);
   88|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   89|  6.74M|    u0 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
   90|  6.74M|    VERIFY_BITS(u0, 52);
   91|  6.74M|    VERIFY_BITS_128(&d, 62);
   92|       |    /* [d u0 t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   93|       |    /* [d 0 t4+(tx<<48)+(u0<<52) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   94|  6.74M|    u0 = (u0 << 4) | tx;
   95|  6.74M|    VERIFY_BITS(u0, 56);
   96|       |    /* [d 0 t4+(u0<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   97|  6.74M|    secp256k1_u128_accum_mul(&c, u0, R >> 4);
   98|  6.74M|    VERIFY_BITS_128(&c, 113);
   99|       |    /* [d 0 t4 t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  100|  6.74M|    r[0] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  101|  6.74M|    VERIFY_BITS(r[0], 52);
  102|  6.74M|    VERIFY_BITS_128(&c, 61);
  103|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 0 p0] */
  104|       |
  105|  6.74M|    secp256k1_u128_accum_mul(&c, a0, b[1]);
  106|  6.74M|    secp256k1_u128_accum_mul(&c, a1, b[0]);
  107|  6.74M|    VERIFY_BITS_128(&c, 114);
  108|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 p1 p0] */
  109|  6.74M|    secp256k1_u128_accum_mul(&d, a2, b[4]);
  110|  6.74M|    secp256k1_u128_accum_mul(&d, a3, b[3]);
  111|  6.74M|    secp256k1_u128_accum_mul(&d, a4, b[2]);
  112|  6.74M|    VERIFY_BITS_128(&d, 114);
  113|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  114|  6.74M|    secp256k1_u128_accum_mul(&c, secp256k1_u128_to_u64(&d) & M, R); secp256k1_u128_rshift(&d, 52);
  115|  6.74M|    VERIFY_BITS_128(&c, 115);
  116|  6.74M|    VERIFY_BITS_128(&d, 62);
  117|       |    /* [d 0 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  118|  6.74M|    r[1] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  119|  6.74M|    VERIFY_BITS(r[1], 52);
  120|  6.74M|    VERIFY_BITS_128(&c, 63);
  121|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  122|       |
  123|  6.74M|    secp256k1_u128_accum_mul(&c, a0, b[2]);
  124|  6.74M|    secp256k1_u128_accum_mul(&c, a1, b[1]);
  125|  6.74M|    secp256k1_u128_accum_mul(&c, a2, b[0]);
  126|  6.74M|    VERIFY_BITS_128(&c, 114);
  127|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 p2 p1 p0] */
  128|  6.74M|    secp256k1_u128_accum_mul(&d, a3, b[4]);
  129|  6.74M|    secp256k1_u128_accum_mul(&d, a4, b[3]);
  130|  6.74M|    VERIFY_BITS_128(&d, 114);
  131|       |    /* [d 0 0 t4 t3 c t1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  132|  6.74M|    secp256k1_u128_accum_mul(&c, R, secp256k1_u128_to_u64(&d)); secp256k1_u128_rshift(&d, 64);
  133|  6.74M|    VERIFY_BITS_128(&c, 115);
  134|  6.74M|    VERIFY_BITS_128(&d, 50);
  135|       |    /* [(d<<12) 0 0 0 t4 t3 c r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  136|       |
  137|  6.74M|    r[2] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  138|  6.74M|    VERIFY_BITS(r[2], 52);
  139|  6.74M|    VERIFY_BITS_128(&c, 63);
  140|       |    /* [(d<<12) 0 0 0 t4 t3+c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  141|  6.74M|    secp256k1_u128_accum_mul(&c, R << 12, secp256k1_u128_to_u64(&d));
  142|  6.74M|    secp256k1_u128_accum_u64(&c, t3);
  143|  6.74M|    VERIFY_BITS_128(&c, 100);
  144|       |    /* [t4 c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  145|  6.74M|    r[3] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  146|  6.74M|    VERIFY_BITS(r[3], 52);
  147|  6.74M|    VERIFY_BITS_128(&c, 48);
  148|       |    /* [t4+c r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  149|  6.74M|    r[4] = secp256k1_u128_to_u64(&c) + t4;
  150|  6.74M|    VERIFY_BITS(r[4], 49);
  151|       |    /* [r4 r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  152|  6.74M|}

secp256k1.c:secp256k1_fe_verify:
  149|  11.5M|static void secp256k1_fe_verify(const secp256k1_fe *a) { (void)a; }
secp256k1.c:secp256k1_fe_verify_magnitude:
  150|  10.6M|static void secp256k1_fe_verify_magnitude(const secp256k1_fe *a, int m) { (void)a; (void)m; }
secp256k1.c:secp256k1_fe_sqrt:
   37|  8.15k|static int secp256k1_fe_sqrt(secp256k1_fe * SECP256K1_RESTRICT r, const secp256k1_fe * SECP256K1_RESTRICT a) {
   38|       |    /** Given that p is congruent to 3 mod 4, we can compute the square root of
   39|       |     *  a mod p as the (p+1)/4'th power of a.
   40|       |     *
   41|       |     *  As (p+1)/4 is an even number, it will have the same result for a and for
   42|       |     *  (-a). Only one of these two numbers actually has a square root however,
   43|       |     *  so we test at the end by squaring and comparing to the input.
   44|       |     *  Also because (p+1)/4 is an even number, the computed square root is
   45|       |     *  itself always a square (a ** ((p+1)/4) is the square of a ** ((p+1)/8)).
   46|       |     */
   47|  8.15k|    secp256k1_fe x2, x3, x6, x9, x11, x22, x44, x88, x176, x220, x223, t1;
   48|  8.15k|    int j, ret;
   49|       |
   50|  8.15k|    VERIFY_CHECK(r != a);
   51|  8.15k|    SECP256K1_FE_VERIFY(a);
  ------------------
  |  |  345|  8.15k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   52|  8.15k|    SECP256K1_FE_VERIFY_MAGNITUDE(a, 8);
  ------------------
  |  |  349|  8.15k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   53|       |
   54|       |    /** The binary representation of (p + 1)/4 has 3 blocks of 1s, with lengths in
   55|       |     *  { 2, 22, 223 }. Use an addition chain to calculate 2^n - 1 for each block:
   56|       |     *  1, [2], 3, 6, 9, 11, [22], 44, 88, 176, 220, [223]
   57|       |     */
   58|       |
   59|  8.15k|    secp256k1_fe_sqr(&x2, a);
  ------------------
  |  |   94|  8.15k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   60|  8.15k|    secp256k1_fe_mul(&x2, &x2, a);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   61|       |
   62|  8.15k|    secp256k1_fe_sqr(&x3, &x2);
  ------------------
  |  |   94|  8.15k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   63|  8.15k|    secp256k1_fe_mul(&x3, &x3, a);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   64|       |
   65|  8.15k|    x6 = x3;
   66|  32.6k|    for (j=0; j<3; j++) {
  ------------------
  |  Branch (66:15): [True: 24.4k, False: 8.15k]
  ------------------
   67|  24.4k|        secp256k1_fe_sqr(&x6, &x6);
  ------------------
  |  |   94|  24.4k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   68|  24.4k|    }
   69|  8.15k|    secp256k1_fe_mul(&x6, &x6, &x3);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   70|       |
   71|  8.15k|    x9 = x6;
   72|  32.6k|    for (j=0; j<3; j++) {
  ------------------
  |  Branch (72:15): [True: 24.4k, False: 8.15k]
  ------------------
   73|  24.4k|        secp256k1_fe_sqr(&x9, &x9);
  ------------------
  |  |   94|  24.4k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   74|  24.4k|    }
   75|  8.15k|    secp256k1_fe_mul(&x9, &x9, &x3);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   76|       |
   77|  8.15k|    x11 = x9;
   78|  24.4k|    for (j=0; j<2; j++) {
  ------------------
  |  Branch (78:15): [True: 16.3k, False: 8.15k]
  ------------------
   79|  16.3k|        secp256k1_fe_sqr(&x11, &x11);
  ------------------
  |  |   94|  16.3k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   80|  16.3k|    }
   81|  8.15k|    secp256k1_fe_mul(&x11, &x11, &x2);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   82|       |
   83|  8.15k|    x22 = x11;
   84|  97.8k|    for (j=0; j<11; j++) {
  ------------------
  |  Branch (84:15): [True: 89.7k, False: 8.15k]
  ------------------
   85|  89.7k|        secp256k1_fe_sqr(&x22, &x22);
  ------------------
  |  |   94|  89.7k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   86|  89.7k|    }
   87|  8.15k|    secp256k1_fe_mul(&x22, &x22, &x11);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   88|       |
   89|  8.15k|    x44 = x22;
   90|   187k|    for (j=0; j<22; j++) {
  ------------------
  |  Branch (90:15): [True: 179k, False: 8.15k]
  ------------------
   91|   179k|        secp256k1_fe_sqr(&x44, &x44);
  ------------------
  |  |   94|   179k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   92|   179k|    }
   93|  8.15k|    secp256k1_fe_mul(&x44, &x44, &x22);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   94|       |
   95|  8.15k|    x88 = x44;
   96|   366k|    for (j=0; j<44; j++) {
  ------------------
  |  Branch (96:15): [True: 358k, False: 8.15k]
  ------------------
   97|   358k|        secp256k1_fe_sqr(&x88, &x88);
  ------------------
  |  |   94|   358k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   98|   358k|    }
   99|  8.15k|    secp256k1_fe_mul(&x88, &x88, &x44);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  100|       |
  101|  8.15k|    x176 = x88;
  102|   725k|    for (j=0; j<88; j++) {
  ------------------
  |  Branch (102:15): [True: 717k, False: 8.15k]
  ------------------
  103|   717k|        secp256k1_fe_sqr(&x176, &x176);
  ------------------
  |  |   94|   717k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  104|   717k|    }
  105|  8.15k|    secp256k1_fe_mul(&x176, &x176, &x88);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  106|       |
  107|  8.15k|    x220 = x176;
  108|   366k|    for (j=0; j<44; j++) {
  ------------------
  |  Branch (108:15): [True: 358k, False: 8.15k]
  ------------------
  109|   358k|        secp256k1_fe_sqr(&x220, &x220);
  ------------------
  |  |   94|   358k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  110|   358k|    }
  111|  8.15k|    secp256k1_fe_mul(&x220, &x220, &x44);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  112|       |
  113|  8.15k|    x223 = x220;
  114|  32.6k|    for (j=0; j<3; j++) {
  ------------------
  |  Branch (114:15): [True: 24.4k, False: 8.15k]
  ------------------
  115|  24.4k|        secp256k1_fe_sqr(&x223, &x223);
  ------------------
  |  |   94|  24.4k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  116|  24.4k|    }
  117|  8.15k|    secp256k1_fe_mul(&x223, &x223, &x3);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  118|       |
  119|       |    /* The final result is then assembled using a sliding window over the blocks. */
  120|       |
  121|  8.15k|    t1 = x223;
  122|   195k|    for (j=0; j<23; j++) {
  ------------------
  |  Branch (122:15): [True: 187k, False: 8.15k]
  ------------------
  123|   187k|        secp256k1_fe_sqr(&t1, &t1);
  ------------------
  |  |   94|   187k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  124|   187k|    }
  125|  8.15k|    secp256k1_fe_mul(&t1, &t1, &x22);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  126|  57.0k|    for (j=0; j<6; j++) {
  ------------------
  |  Branch (126:15): [True: 48.9k, False: 8.15k]
  ------------------
  127|  48.9k|        secp256k1_fe_sqr(&t1, &t1);
  ------------------
  |  |   94|  48.9k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  128|  48.9k|    }
  129|  8.15k|    secp256k1_fe_mul(&t1, &t1, &x2);
  ------------------
  |  |   93|  8.15k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  130|  8.15k|    secp256k1_fe_sqr(&t1, &t1);
  ------------------
  |  |   94|  8.15k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  131|  8.15k|    secp256k1_fe_sqr(r, &t1);
  ------------------
  |  |   94|  8.15k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  132|       |
  133|       |    /* Check that a square root was actually calculated */
  134|       |
  135|  8.15k|    secp256k1_fe_sqr(&t1, r);
  ------------------
  |  |   94|  8.15k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  136|  8.15k|    ret = secp256k1_fe_equal(&t1, a);
  137|       |
  138|       |#ifdef VERIFY
  139|       |    if (!ret) {
  140|       |        secp256k1_fe_negate(&t1, &t1, 1);
  141|       |        secp256k1_fe_normalize_var(&t1);
  142|       |        VERIFY_CHECK(secp256k1_fe_equal(&t1, a));
  143|       |    }
  144|       |#endif
  145|  8.15k|    return ret;
  146|  8.15k|}
secp256k1.c:secp256k1_fe_equal:
   25|  8.15k|SECP256K1_INLINE static int secp256k1_fe_equal(const secp256k1_fe *a, const secp256k1_fe *b) {
   26|  8.15k|    secp256k1_fe na;
   27|  8.15k|    SECP256K1_FE_VERIFY(a);
  ------------------
  |  |  345|  8.15k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   28|  8.15k|    SECP256K1_FE_VERIFY(b);
  ------------------
  |  |  345|  8.15k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   29|  8.15k|    SECP256K1_FE_VERIFY_MAGNITUDE(a, 1);
  ------------------
  |  |  349|  8.15k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   30|  8.15k|    SECP256K1_FE_VERIFY_MAGNITUDE(b, 30);
  ------------------
  |  |  349|  8.15k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   31|       |
   32|  8.15k|    secp256k1_fe_negate(&na, a, 1);
  ------------------
  |  |  211|  8.15k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  8.15k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  8.15k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 8.15k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  8.15k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 8.15k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  8.15k|    } \
  |  |  |  |   94|  8.15k|    stmt; \
  |  |  |  |   95|  8.15k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 8.15k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   33|  8.15k|    secp256k1_fe_add(&na, b);
  ------------------
  |  |   92|  8.15k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
   34|  8.15k|    return secp256k1_fe_normalizes_to_zero(&na);
  ------------------
  |  |   81|  8.15k|#  define secp256k1_fe_normalizes_to_zero secp256k1_fe_impl_normalizes_to_zero
  ------------------
   35|  8.15k|}
secp256k1.c:secp256k1_fe_clear:
   21|  10.4k|SECP256K1_INLINE static void secp256k1_fe_clear(secp256k1_fe *a) {
   22|  10.4k|    secp256k1_memclear_explicit(a, sizeof(secp256k1_fe));
   23|  10.4k|}

secp256k1.c:secp256k1_ge_set_xy:
  132|   363k|static void secp256k1_ge_set_xy(secp256k1_ge *r, const secp256k1_fe *x, const secp256k1_fe *y) {
  133|   363k|    SECP256K1_FE_VERIFY(x);
  ------------------
  |  |  345|   363k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  134|   363k|    SECP256K1_FE_VERIFY(y);
  ------------------
  |  |  345|   363k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  135|       |
  136|   363k|    r->infinity = 0;
  137|   363k|    r->x = *x;
  138|   363k|    r->y = *y;
  139|       |
  140|   363k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|   363k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  141|   363k|}
secp256k1.c:secp256k1_ge_verify:
   78|  1.51M|static void secp256k1_ge_verify(const secp256k1_ge *a) {
   79|  1.51M|    SECP256K1_FE_VERIFY(&a->x);
  ------------------
  |  |  345|  1.51M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   80|  1.51M|    SECP256K1_FE_VERIFY(&a->y);
  ------------------
  |  |  345|  1.51M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   81|  1.51M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->x, SECP256K1_GE_X_MAGNITUDE_MAX);
  ------------------
  |  |  349|  1.51M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   82|  1.51M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->y, SECP256K1_GE_Y_MAGNITUDE_MAX);
  ------------------
  |  |  349|  1.51M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   83|  1.51M|    VERIFY_CHECK(a->infinity == 0 || a->infinity == 1);
   84|  1.51M|    (void)a;
   85|  1.51M|}
secp256k1.c:secp256k1_ge_clear:
  343|  5.14k|static void secp256k1_ge_clear(secp256k1_ge *r) {
  344|  5.14k|    secp256k1_memclear_explicit(r, sizeof(secp256k1_ge));
  345|  5.14k|}
secp256k1.c:secp256k1_gej_verify:
   87|  2.51M|static void secp256k1_gej_verify(const secp256k1_gej *a) {
   88|  2.51M|    SECP256K1_FE_VERIFY(&a->x);
  ------------------
  |  |  345|  2.51M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   89|  2.51M|    SECP256K1_FE_VERIFY(&a->y);
  ------------------
  |  |  345|  2.51M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   90|  2.51M|    SECP256K1_FE_VERIFY(&a->z);
  ------------------
  |  |  345|  2.51M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   91|  2.51M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->x, SECP256K1_GEJ_X_MAGNITUDE_MAX);
  ------------------
  |  |  349|  2.51M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   92|  2.51M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->y, SECP256K1_GEJ_Y_MAGNITUDE_MAX);
  ------------------
  |  |  349|  2.51M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   93|  2.51M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->z, SECP256K1_GEJ_Z_MAGNITUDE_MAX);
  ------------------
  |  |  349|  2.51M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   94|  2.51M|    VERIFY_CHECK(a->infinity == 0 || a->infinity == 1);
   95|  2.51M|    (void)a;
   96|  2.51M|}
secp256k1.c:secp256k1_gej_add_ge:
  724|   489k|static void secp256k1_gej_add_ge(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b) {
  725|       |    /* Operations: 7 mul, 5 sqr, 21 add/cmov/half/mul_int/negate/normalizes_to_zero */
  726|   489k|    secp256k1_fe zz, u1, u2, s1, s2, t, tt, m, n, q, rr;
  727|   489k|    secp256k1_fe m_alt, rr_alt;
  728|   489k|    int degenerate;
  729|   489k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|   489k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  730|   489k|    SECP256K1_GE_VERIFY(b);
  ------------------
  |  |  212|   489k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  731|   489k|    VERIFY_CHECK(!b->infinity);
  732|       |
  733|       |    /*  In:
  734|       |     *    Eric Brier and Marc Joye, Weierstrass Elliptic Curves and Side-Channel Attacks.
  735|       |     *    In D. Naccache and P. Paillier, Eds., Public Key Cryptography, vol. 2274 of Lecture Notes in Computer Science, pages 335-345. Springer-Verlag, 2002.
  736|       |     *  we find as solution for a unified addition/doubling formula:
  737|       |     *    lambda = ((x1 + x2)^2 - x1 * x2 + a) / (y1 + y2), with a = 0 for secp256k1's curve equation.
  738|       |     *    x3 = lambda^2 - (x1 + x2)
  739|       |     *    2*y3 = lambda * (x1 + x2 - 2 * x3) - (y1 + y2).
  740|       |     *
  741|       |     *  Substituting x_i = Xi / Zi^2 and yi = Yi / Zi^3, for i=1,2,3, gives:
  742|       |     *    U1 = X1*Z2^2, U2 = X2*Z1^2
  743|       |     *    S1 = Y1*Z2^3, S2 = Y2*Z1^3
  744|       |     *    Z = Z1*Z2
  745|       |     *    T = U1+U2
  746|       |     *    M = S1+S2
  747|       |     *    Q = -T*M^2
  748|       |     *    R = T^2-U1*U2
  749|       |     *    X3 = R^2+Q
  750|       |     *    Y3 = -(R*(2*X3+Q)+M^4)/2
  751|       |     *    Z3 = M*Z
  752|       |     *  (Note that the paper uses xi = Xi / Zi and yi = Yi / Zi instead.)
  753|       |     *
  754|       |     *  This formula has the benefit of being the same for both addition
  755|       |     *  of distinct points and doubling. However, it breaks down in the
  756|       |     *  case that either point is infinity, or that y1 = -y2. We handle
  757|       |     *  these cases in the following ways:
  758|       |     *
  759|       |     *    - If b is infinity we simply bail by means of a VERIFY_CHECK.
  760|       |     *
  761|       |     *    - If a is infinity, we detect this, and at the end of the
  762|       |     *      computation replace the result (which will be meaningless,
  763|       |     *      but we compute to be constant-time) with b.x : b.y : 1.
  764|       |     *
  765|       |     *    - If a = -b, we have y1 = -y2, which is a degenerate case.
  766|       |     *      But here the answer is infinity, so we simply set the
  767|       |     *      infinity flag of the result, overriding the computed values
  768|       |     *      without even needing to cmov.
  769|       |     *
  770|       |     *    - If y1 = -y2 but x1 != x2, which does occur thanks to certain
  771|       |     *      properties of our curve (specifically, 1 has nontrivial cube
  772|       |     *      roots in our field, and the curve equation has no x coefficient)
  773|       |     *      then the answer is not infinity but also not given by the above
  774|       |     *      equation. In this case, we cmov in place an alternate expression
  775|       |     *      for lambda. Specifically (y1 - y2)/(x1 - x2). Where both these
  776|       |     *      expressions for lambda are defined, they are equal, and can be
  777|       |     *      obtained from each other by multiplication by (y1 + y2)/(y1 + y2)
  778|       |     *      then substitution of x^3 + 7 for y^2 (using the curve equation).
  779|       |     *      For all pairs of nonzero points (a, b) at least one is defined,
  780|       |     *      so this covers everything.
  781|       |     */
  782|       |
  783|   489k|    secp256k1_fe_sqr(&zz, &a->z);                       /* z = Z1^2 */
  ------------------
  |  |   94|   489k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  784|   489k|    u1 = a->x;                                          /* u1 = U1 = X1*Z2^2 (GEJ_X_M) */
  785|   489k|    secp256k1_fe_mul(&u2, &b->x, &zz);                  /* u2 = U2 = X2*Z1^2 (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  786|   489k|    s1 = a->y;                                          /* s1 = S1 = Y1*Z2^3 (GEJ_Y_M) */
  787|   489k|    secp256k1_fe_mul(&s2, &b->y, &zz);                  /* s2 = Y2*Z1^2 (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  788|   489k|    secp256k1_fe_mul(&s2, &s2, &a->z);                  /* s2 = S2 = Y2*Z1^3 (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  789|   489k|    t = u1; secp256k1_fe_add(&t, &u2);                  /* t = T = U1+U2 (GEJ_X_M+1) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  790|   489k|    m = s1; secp256k1_fe_add(&m, &s2);                  /* m = M = S1+S2 (GEJ_Y_M+1) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  791|   489k|    secp256k1_fe_sqr(&rr, &t);                          /* rr = T^2 (1) */
  ------------------
  |  |   94|   489k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  792|   489k|    secp256k1_fe_negate(&m_alt, &u2, 1);                /* Malt = -X2*Z1^2 (2) */
  ------------------
  |  |  211|   489k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   489k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   489k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 489k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   489k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 489k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   489k|    } \
  |  |  |  |   94|   489k|    stmt; \
  |  |  |  |   95|   489k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 489k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  793|   489k|    secp256k1_fe_mul(&tt, &u1, &m_alt);                 /* tt = -U1*U2 (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  794|   489k|    secp256k1_fe_add(&rr, &tt);                         /* rr = R = T^2-U1*U2 (2) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  795|       |    /* If lambda = R/M = R/0 we have a problem (except in the "trivial"
  796|       |     * case that Z = z1z2 = 0, and this is special-cased later on). */
  797|   489k|    degenerate = secp256k1_fe_normalizes_to_zero(&m);
  ------------------
  |  |   81|   489k|#  define secp256k1_fe_normalizes_to_zero secp256k1_fe_impl_normalizes_to_zero
  ------------------
  798|       |    /* This only occurs when y1 == -y2 and x1^3 == x2^3, but x1 != x2.
  799|       |     * This means either x1 == beta*x2 or beta*x1 == x2, where beta is
  800|       |     * a nontrivial cube root of one. In either case, an alternate
  801|       |     * non-indeterminate expression for lambda is (y1 - y2)/(x1 - x2),
  802|       |     * so we set R/M equal to this. */
  803|   489k|    rr_alt = s1;
  804|   489k|    secp256k1_fe_mul_int(&rr_alt, 2);       /* rr_alt = Y1*Z2^3 - Y2*Z1^3 (GEJ_Y_M*2) */
  ------------------
  |  |  233|   489k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|   489k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   489k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 489k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   489k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 489k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   489k|    } \
  |  |  |  |   94|   489k|    stmt; \
  |  |  |  |   95|   489k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 489k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  805|   489k|    secp256k1_fe_add(&m_alt, &u1);          /* Malt = X1*Z2^2 - X2*Z1^2 (GEJ_X_M+2) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  806|       |
  807|   489k|    secp256k1_fe_cmov(&rr_alt, &rr, !degenerate);       /* rr_alt (GEJ_Y_M*2) */
  ------------------
  |  |   95|   489k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  808|   489k|    secp256k1_fe_cmov(&m_alt, &m, !degenerate);         /* m_alt (GEJ_X_M+2) */
  ------------------
  |  |   95|   489k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  809|       |    /* Now Ralt / Malt = lambda and is guaranteed not to be Ralt / 0.
  810|       |     * From here on out Ralt and Malt represent the numerator
  811|       |     * and denominator of lambda; R and M represent the explicit
  812|       |     * expressions x1^2 + x2^2 + x1x2 and y1 + y2. */
  813|   489k|    secp256k1_fe_sqr(&n, &m_alt);                       /* n = Malt^2 (1) */
  ------------------
  |  |   94|   489k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  814|   489k|    secp256k1_fe_negate(&q, &t,
  ------------------
  |  |  211|   489k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   489k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   489k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 489k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   489k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 489k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   489k|    } \
  |  |  |  |   94|   489k|    stmt; \
  |  |  |  |   95|   489k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 489k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  815|   489k|        SECP256K1_GEJ_X_MAGNITUDE_MAX + 1);             /* q = -T (GEJ_X_M+2) */
  816|   489k|    secp256k1_fe_mul(&q, &q, &n);                       /* q = Q = -T*Malt^2 (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  817|       |    /* These two lines use the observation that either M == Malt or M == 0,
  818|       |     * so M^3 * Malt is either Malt^4 (which is computed by squaring), or
  819|       |     * zero (which is "computed" by cmov). So the cost is one squaring
  820|       |     * versus two multiplications. */
  821|   489k|    secp256k1_fe_sqr(&n, &n);                           /* n = Malt^4 (1) */
  ------------------
  |  |   94|   489k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  822|   489k|    secp256k1_fe_cmov(&n, &m, degenerate);              /* n = M^3 * Malt (GEJ_Y_M+1) */
  ------------------
  |  |   95|   489k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  823|   489k|    secp256k1_fe_sqr(&t, &rr_alt);                      /* t = Ralt^2 (1) */
  ------------------
  |  |   94|   489k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  824|   489k|    secp256k1_fe_mul(&r->z, &a->z, &m_alt);             /* r->z = Z3 = Malt*Z (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  825|   489k|    secp256k1_fe_add(&t, &q);                           /* t = Ralt^2 + Q (2) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  826|   489k|    r->x = t;                                           /* r->x = X3 = Ralt^2 + Q (2) */
  827|   489k|    secp256k1_fe_mul_int(&t, 2);                        /* t = 2*X3 (4) */
  ------------------
  |  |  233|   489k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|   489k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   489k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 489k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   489k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 489k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   489k|    } \
  |  |  |  |   94|   489k|    stmt; \
  |  |  |  |   95|   489k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 489k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  828|   489k|    secp256k1_fe_add(&t, &q);                           /* t = 2*X3 + Q (5) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  829|   489k|    secp256k1_fe_mul(&t, &t, &rr_alt);                  /* t = Ralt*(2*X3 + Q) (1) */
  ------------------
  |  |   93|   489k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  830|   489k|    secp256k1_fe_add(&t, &n);                           /* t = Ralt*(2*X3 + Q) + M^3*Malt (GEJ_Y_M+2) */
  ------------------
  |  |   92|   489k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  831|   489k|    secp256k1_fe_negate(&r->y, &t,
  ------------------
  |  |  211|   489k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   489k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   489k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 489k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   489k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 489k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   489k|    } \
  |  |  |  |   94|   489k|    stmt; \
  |  |  |  |   95|   489k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 489k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  832|   489k|        SECP256K1_GEJ_Y_MAGNITUDE_MAX + 2);             /* r->y = -(Ralt*(2*X3 + Q) + M^3*Malt) (GEJ_Y_M+3) */
  833|   489k|    secp256k1_fe_half(&r->y);                           /* r->y = Y3 = -(Ralt*(2*X3 + Q) + M^3*Malt)/2 ((GEJ_Y_M+3)/2 + 1) */
  ------------------
  |  |  101|   489k|#  define secp256k1_fe_half secp256k1_fe_impl_half
  ------------------
  834|       |
  835|       |    /* In case a->infinity == 1, replace r with (b->x, b->y, 1). */
  836|   489k|    secp256k1_fe_cmov(&r->x, &b->x, a->infinity);
  ------------------
  |  |   95|   489k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  837|   489k|    secp256k1_fe_cmov(&r->y, &b->y, a->infinity);
  ------------------
  |  |   95|   489k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  838|   489k|    secp256k1_fe_cmov(&r->z, &secp256k1_fe_one, a->infinity);
  ------------------
  |  |   95|   489k|#  define secp256k1_fe_cmov secp256k1_fe_impl_cmov
  ------------------
  839|       |
  840|       |    /* Set r->infinity if r->z is 0.
  841|       |     *
  842|       |     * If a->infinity is set, then r->infinity = (r->z == 0) = (1 == 0) = false,
  843|       |     * which is correct because the function assumes that b is not infinity.
  844|       |     *
  845|       |     * Now assume !a->infinity. This implies Z = Z1 != 0.
  846|       |     *
  847|       |     * Case y1 = -y2:
  848|       |     * In this case we could have a = -b, namely if x1 = x2.
  849|       |     * We have degenerate = true, r->z = (x1 - x2) * Z.
  850|       |     * Then r->infinity = ((x1 - x2)Z == 0) = (x1 == x2) = (a == -b).
  851|       |     *
  852|       |     * Case y1 != -y2:
  853|       |     * In this case, we can't have a = -b.
  854|       |     * We have degenerate = false, r->z = (y1 + y2) * Z.
  855|       |     * Then r->infinity = ((y1 + y2)Z == 0) = (y1 == -y2) = false. */
  856|   489k|    r->infinity = secp256k1_fe_normalizes_to_zero(&r->z);
  ------------------
  |  |   81|   489k|#  define secp256k1_fe_normalizes_to_zero secp256k1_fe_impl_normalizes_to_zero
  ------------------
  857|       |
  858|   489k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|   489k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  859|   489k|}
secp256k1.c:secp256k1_ge_set_gej:
  159|  5.14k|static void secp256k1_ge_set_gej(secp256k1_ge *r, secp256k1_gej *a) {
  160|  5.14k|    secp256k1_fe z2, z3;
  161|  5.14k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  5.14k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  162|       |
  163|  5.14k|    r->infinity = a->infinity;
  164|  5.14k|    secp256k1_fe_inv(&a->z, &a->z);
  ------------------
  |  |   98|  5.14k|#  define secp256k1_fe_inv secp256k1_fe_impl_inv
  ------------------
  165|  5.14k|    secp256k1_fe_sqr(&z2, &a->z);
  ------------------
  |  |   94|  5.14k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  166|  5.14k|    secp256k1_fe_mul(&z3, &a->z, &z2);
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  167|  5.14k|    secp256k1_fe_mul(&a->x, &a->x, &z2);
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  168|  5.14k|    secp256k1_fe_mul(&a->y, &a->y, &z3);
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  169|  5.14k|    secp256k1_fe_set_int(&a->z, 1);
  ------------------
  |  |   83|  5.14k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  170|  5.14k|    r->x = a->x;
  171|  5.14k|    r->y = a->y;
  172|       |
  173|  5.14k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  5.14k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  174|  5.14k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  5.14k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  175|  5.14k|}
secp256k1.c:secp256k1_gej_set_ge:
  367|  20.9k|static void secp256k1_gej_set_ge(secp256k1_gej *r, const secp256k1_ge *a) {
  368|  20.9k|   SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  20.9k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  369|       |
  370|  20.9k|   r->infinity = a->infinity;
  371|  20.9k|   r->x = a->x;
  372|  20.9k|   r->y = a->y;
  373|  20.9k|   secp256k1_fe_set_int(&r->z, 1);
  ------------------
  |  |   83|  20.9k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  374|       |
  375|  20.9k|   SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  20.9k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  376|  20.9k|}
secp256k1.c:secp256k1_gej_rescale:
  861|  5.14k|static void secp256k1_gej_rescale(secp256k1_gej *r, const secp256k1_fe *s) {
  862|       |    /* Operations: 4 mul, 1 sqr */
  863|  5.14k|    secp256k1_fe zz;
  864|  5.14k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  5.14k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  865|  5.14k|    SECP256K1_FE_VERIFY(s);
  ------------------
  |  |  345|  5.14k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  866|  5.14k|    VERIFY_CHECK(!secp256k1_fe_normalizes_to_zero_var(s));
  867|       |
  868|  5.14k|    secp256k1_fe_sqr(&zz, s);
  ------------------
  |  |   94|  5.14k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  869|  5.14k|    secp256k1_fe_mul(&r->x, &r->x, &zz);                /* r->x *= s^2 */
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  870|  5.14k|    secp256k1_fe_mul(&r->y, &r->y, &zz);
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  871|  5.14k|    secp256k1_fe_mul(&r->y, &r->y, s);                  /* r->y *= s^3 */
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  872|  5.14k|    secp256k1_fe_mul(&r->z, &r->z, s);                  /* r->z *= s   */
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  873|       |
  874|  5.14k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  5.14k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  875|  5.14k|}
secp256k1.c:secp256k1_ge_set_gej_zinv:
   99|  5.26k|static void secp256k1_ge_set_gej_zinv(secp256k1_ge *r, const secp256k1_gej *a, const secp256k1_fe *zi) {
  100|  5.26k|    secp256k1_fe zi2;
  101|  5.26k|    secp256k1_fe zi3;
  102|  5.26k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  5.26k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  103|  5.26k|    SECP256K1_FE_VERIFY(zi);
  ------------------
  |  |  345|  5.26k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  104|  5.26k|    VERIFY_CHECK(!a->infinity);
  105|       |
  106|  5.26k|    secp256k1_fe_sqr(&zi2, zi);
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  107|  5.26k|    secp256k1_fe_mul(&zi3, &zi2, zi);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  108|  5.26k|    secp256k1_fe_mul(&r->x, &a->x, &zi2);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  109|  5.26k|    secp256k1_fe_mul(&r->y, &a->y, &zi3);
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  110|  5.26k|    r->infinity = a->infinity;
  111|       |
  112|  5.26k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  5.26k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  113|  5.26k|}
secp256k1.c:secp256k1_ge_table_set_globalz:
  289|  5.26k|static void secp256k1_ge_table_set_globalz(size_t len, secp256k1_ge *a, const secp256k1_fe *zr) {
  290|  5.26k|    size_t i;
  291|  5.26k|    secp256k1_fe zs;
  292|       |#ifdef VERIFY
  293|       |    for (i = 0; i < len; i++) {
  294|       |        SECP256K1_GE_VERIFY(&a[i]);
  295|       |        SECP256K1_FE_VERIFY(&zr[i]);
  296|       |    }
  297|       |#endif
  298|       |
  299|  5.26k|    if (len > 0) {
  ------------------
  |  Branch (299:9): [True: 5.26k, False: 0]
  ------------------
  300|  5.26k|        i = len - 1;
  301|       |        /* Ensure all y values are in weak normal form for fast negation of points */
  302|  5.26k|        secp256k1_fe_normalize_weak(&a[i].y);
  ------------------
  |  |   79|  5.26k|#  define secp256k1_fe_normalize_weak secp256k1_fe_impl_normalize_weak
  ------------------
  303|  5.26k|        zs = zr[i];
  304|       |
  305|       |        /* Work our way backwards, using the z-ratios to scale the x/y values. */
  306|  84.1k|        while (i > 0) {
  ------------------
  |  Branch (306:16): [True: 78.9k, False: 5.26k]
  ------------------
  307|  78.9k|            if (i != len - 1) {
  ------------------
  |  Branch (307:17): [True: 73.6k, False: 5.26k]
  ------------------
  308|  73.6k|                secp256k1_fe_mul(&zs, &zs, &zr[i]);
  ------------------
  |  |   93|  73.6k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  309|  73.6k|            }
  310|  78.9k|            i--;
  311|  78.9k|            secp256k1_ge_set_ge_zinv(&a[i], &a[i], &zs);
  312|  78.9k|        }
  313|  5.26k|    }
  314|       |
  315|       |#ifdef VERIFY
  316|       |    for (i = 0; i < len; i++) {
  317|       |        SECP256K1_GE_VERIFY(&a[i]);
  318|       |    }
  319|       |#endif
  320|  5.26k|}
secp256k1.c:secp256k1_ge_set_ge_zinv:
  116|  78.9k|static void secp256k1_ge_set_ge_zinv(secp256k1_ge *r, const secp256k1_ge *a, const secp256k1_fe *zi) {
  117|  78.9k|    secp256k1_fe zi2;
  118|  78.9k|    secp256k1_fe zi3;
  119|  78.9k|    SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  78.9k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  120|  78.9k|    SECP256K1_FE_VERIFY(zi);
  ------------------
  |  |  345|  78.9k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  121|  78.9k|    VERIFY_CHECK(!a->infinity);
  122|       |
  123|  78.9k|    secp256k1_fe_sqr(&zi2, zi);
  ------------------
  |  |   94|  78.9k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  124|  78.9k|    secp256k1_fe_mul(&zi3, &zi2, zi);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  125|  78.9k|    secp256k1_fe_mul(&r->x, &a->x, &zi2);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  126|  78.9k|    secp256k1_fe_mul(&r->y, &a->y, &zi3);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  127|  78.9k|    r->infinity = a->infinity;
  128|       |
  129|  78.9k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  78.9k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  130|  78.9k|}
secp256k1.c:secp256k1_gej_double_var:
  495|  5.26k|static void secp256k1_gej_double_var(secp256k1_gej *r, const secp256k1_gej *a, secp256k1_fe *rzr) {
  496|  5.26k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  5.26k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  497|       |
  498|       |    /** For secp256k1, 2Q is infinity if and only if Q is infinity. This is because if 2Q = infinity,
  499|       |     *  Q must equal -Q, or that Q.y == -(Q.y), or Q.y is 0. For a point on y^2 = x^3 + 7 to have
  500|       |     *  y=0, x^3 must be -7 mod p. However, -7 has no cube root mod p.
  501|       |     *
  502|       |     *  Having said this, if this function receives a point on a sextic twist, e.g. by
  503|       |     *  a fault attack, it is possible for y to be 0. This happens for y^2 = x^3 + 6,
  504|       |     *  since -6 does have a cube root mod p. For this point, this function will not set
  505|       |     *  the infinity flag even though the point doubles to infinity, and the result
  506|       |     *  point will be gibberish (z = 0 but infinity = 0).
  507|       |     */
  508|  5.26k|    if (a->infinity) {
  ------------------
  |  Branch (508:9): [True: 0, False: 5.26k]
  ------------------
  509|      0|        secp256k1_gej_set_infinity(r);
  510|      0|        if (rzr != NULL) {
  ------------------
  |  Branch (510:13): [True: 0, False: 0]
  ------------------
  511|      0|            secp256k1_fe_set_int(rzr, 1);
  ------------------
  |  |   83|      0|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  512|      0|        }
  513|      0|        return;
  514|      0|    }
  515|       |
  516|  5.26k|    if (rzr != NULL) {
  ------------------
  |  Branch (516:9): [True: 0, False: 5.26k]
  ------------------
  517|      0|        *rzr = a->y;
  518|      0|        secp256k1_fe_normalize_weak(rzr);
  ------------------
  |  |   79|      0|#  define secp256k1_fe_normalize_weak secp256k1_fe_impl_normalize_weak
  ------------------
  519|      0|    }
  520|       |
  521|  5.26k|    secp256k1_gej_double(r, a);
  522|       |
  523|  5.26k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  5.26k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  524|  5.26k|}
secp256k1.c:secp256k1_gej_double:
  460|   662k|static SECP256K1_INLINE void secp256k1_gej_double(secp256k1_gej *r, const secp256k1_gej *a) {
  461|       |    /* Operations: 3 mul, 4 sqr, 8 add/half/mul_int/negate */
  462|   662k|    secp256k1_fe l, s, t;
  463|   662k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|   662k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  464|       |
  465|   662k|    r->infinity = a->infinity;
  466|       |
  467|       |    /* Formula used:
  468|       |     * L = (3/2) * X1^2
  469|       |     * S = Y1^2
  470|       |     * T = -X1*S
  471|       |     * X3 = L^2 + 2*T
  472|       |     * Y3 = -(L*(X3 + T) + S^2)
  473|       |     * Z3 = Y1*Z1
  474|       |     */
  475|       |
  476|   662k|    secp256k1_fe_mul(&r->z, &a->z, &a->y); /* Z3 = Y1*Z1 (1) */
  ------------------
  |  |   93|   662k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  477|   662k|    secp256k1_fe_sqr(&s, &a->y);           /* S = Y1^2 (1) */
  ------------------
  |  |   94|   662k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  478|   662k|    secp256k1_fe_sqr(&l, &a->x);           /* L = X1^2 (1) */
  ------------------
  |  |   94|   662k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  479|   662k|    secp256k1_fe_mul_int(&l, 3);           /* L = 3*X1^2 (3) */
  ------------------
  |  |  233|   662k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|   662k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   662k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 662k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   662k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 662k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   662k|    } \
  |  |  |  |   94|   662k|    stmt; \
  |  |  |  |   95|   662k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 662k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  480|   662k|    secp256k1_fe_half(&l);                 /* L = 3/2*X1^2 (2) */
  ------------------
  |  |  101|   662k|#  define secp256k1_fe_half secp256k1_fe_impl_half
  ------------------
  481|   662k|    secp256k1_fe_negate(&t, &s, 1);        /* T = -S (2) */
  ------------------
  |  |  211|   662k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   662k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   662k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 662k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   662k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 662k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   662k|    } \
  |  |  |  |   94|   662k|    stmt; \
  |  |  |  |   95|   662k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 662k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  482|   662k|    secp256k1_fe_mul(&t, &t, &a->x);       /* T = -X1*S (1) */
  ------------------
  |  |   93|   662k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  483|   662k|    secp256k1_fe_sqr(&r->x, &l);           /* X3 = L^2 (1) */
  ------------------
  |  |   94|   662k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  484|   662k|    secp256k1_fe_add(&r->x, &t);           /* X3 = L^2 + T (2) */
  ------------------
  |  |   92|   662k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  485|   662k|    secp256k1_fe_add(&r->x, &t);           /* X3 = L^2 + 2*T (3) */
  ------------------
  |  |   92|   662k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  486|   662k|    secp256k1_fe_sqr(&s, &s);              /* S' = S^2 (1) */
  ------------------
  |  |   94|   662k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  487|   662k|    secp256k1_fe_add(&t, &r->x);           /* T' = X3 + T (4) */
  ------------------
  |  |   92|   662k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  488|   662k|    secp256k1_fe_mul(&r->y, &t, &l);       /* Y3 = L*(X3 + T) (1) */
  ------------------
  |  |   93|   662k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  489|   662k|    secp256k1_fe_add(&r->y, &s);           /* Y3 = L*(X3 + T) + S^2 (2) */
  ------------------
  |  |   92|   662k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  490|   662k|    secp256k1_fe_negate(&r->y, &r->y, 2);  /* Y3 = -(L*(X3 + T) + S^2) (3) */
  ------------------
  |  |  211|   662k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   662k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   662k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 662k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   662k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 662k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   662k|    } \
  |  |  |  |   94|   662k|    stmt; \
  |  |  |  |   95|   662k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 662k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  491|       |
  492|   662k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|   662k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  493|   662k|}
secp256k1.c:secp256k1_ge_from_storage:
  890|   221k|static void secp256k1_ge_from_storage(secp256k1_ge *r, const secp256k1_ge_storage *a) {
  891|   221k|    secp256k1_fe_from_storage(&r->x, &a->x);
  ------------------
  |  |   97|   221k|#  define secp256k1_fe_from_storage secp256k1_fe_impl_from_storage
  ------------------
  892|   221k|    secp256k1_fe_from_storage(&r->y, &a->y);
  ------------------
  |  |   97|   221k|#  define secp256k1_fe_from_storage secp256k1_fe_impl_from_storage
  ------------------
  893|   221k|    r->infinity = 0;
  894|       |
  895|   221k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|   221k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  896|   221k|}
secp256k1.c:secp256k1_ge_is_infinity:
  143|  5.26k|static int secp256k1_ge_is_infinity(const secp256k1_ge *a) {
  144|  5.26k|    SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  5.26k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  145|       |
  146|  5.26k|    return a->infinity;
  147|  5.26k|}
secp256k1.c:secp256k1_ge_mul_lambda:
  917|  84.1k|static void secp256k1_ge_mul_lambda(secp256k1_ge *r, const secp256k1_ge *a) {
  918|  84.1k|    SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  84.1k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  919|       |
  920|  84.1k|    *r = *a;
  921|  84.1k|    secp256k1_fe_mul(&r->x, &r->x, &secp256k1_const_beta);
  ------------------
  |  |   93|  84.1k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  922|       |
  923|  84.1k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  84.1k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  924|  84.1k|}
secp256k1.c:secp256k1_ge_storage_cmov:
  911|  7.07M|static SECP256K1_INLINE void secp256k1_ge_storage_cmov(secp256k1_ge_storage *r, const secp256k1_ge_storage *a, int flag) {
  912|  7.07M|    VERIFY_CHECK(flag == 0 || flag == 1);
  913|  7.07M|    secp256k1_fe_storage_cmov(&r->x, &a->x, flag);
  914|  7.07M|    secp256k1_fe_storage_cmov(&r->y, &a->y, flag);
  915|  7.07M|}
secp256k1.c:secp256k1_gej_clear:
  339|  5.14k|static void secp256k1_gej_clear(secp256k1_gej *r) {
  340|  5.14k|    secp256k1_memclear_explicit(r, sizeof(secp256k1_gej));
  341|  5.14k|}
secp256k1.c:secp256k1_ge_x_on_curve_var:
  950|  11.3k|static int secp256k1_ge_x_on_curve_var(const secp256k1_fe *x) {
  951|  11.3k|    secp256k1_fe c;
  952|  11.3k|    secp256k1_fe_sqr(&c, x);
  ------------------
  |  |   94|  11.3k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  953|  11.3k|    secp256k1_fe_mul(&c, &c, x);
  ------------------
  |  |   93|  11.3k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  954|  11.3k|    secp256k1_fe_add_int(&c, SECP256K1_B);
  ------------------
  |  |  102|  11.3k|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                  secp256k1_fe_add_int(&c, SECP256K1_B);
  ------------------
  |  |   73|  11.3k|#define SECP256K1_B 7
  ------------------
  955|  11.3k|    return secp256k1_fe_is_square_var(&c);
  ------------------
  |  |  103|  11.3k|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  956|  11.3k|}
secp256k1.c:secp256k1_ge_x_frac_on_curve_var:
  958|  7.47k|static int secp256k1_ge_x_frac_on_curve_var(const secp256k1_fe *xn, const secp256k1_fe *xd) {
  959|       |    /* We want to determine whether (xn/xd) is on the curve.
  960|       |     *
  961|       |     * (xn/xd)^3 + 7 is square <=> xd*xn^3 + 7*xd^4 is square (multiplying by xd^4, a square).
  962|       |     */
  963|  7.47k|     secp256k1_fe r, t;
  964|  7.47k|     VERIFY_CHECK(!secp256k1_fe_normalizes_to_zero_var(xd));
  965|       |
  966|  7.47k|     secp256k1_fe_mul(&r, xd, xn); /* r = xd*xn */
  ------------------
  |  |   93|  7.47k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  967|  7.47k|     secp256k1_fe_sqr(&t, xn); /* t = xn^2 */
  ------------------
  |  |   94|  7.47k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  968|  7.47k|     secp256k1_fe_mul(&r, &r, &t); /* r = xd*xn^3 */
  ------------------
  |  |   93|  7.47k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  969|  7.47k|     secp256k1_fe_sqr(&t, xd); /* t = xd^2 */
  ------------------
  |  |   94|  7.47k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  970|  7.47k|     secp256k1_fe_sqr(&t, &t); /* t = xd^4 */
  ------------------
  |  |   94|  7.47k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  971|  7.47k|     VERIFY_CHECK(SECP256K1_B <= 31);
  972|  7.47k|     secp256k1_fe_mul_int(&t, SECP256K1_B); /* t = 7*xd^4 */
  ------------------
  |  |  233|  7.47k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|  7.47k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  7.47k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 7.47k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  7.47k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 7.47k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  7.47k|    } \
  |  |  |  |   94|  7.47k|    stmt; \
  |  |  |  |   95|  7.47k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 7.47k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  973|  7.47k|     secp256k1_fe_add(&r, &t); /* r = xd*xn^3 + 7*xd^4 */
  ------------------
  |  |   92|  7.47k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  974|  7.47k|     return secp256k1_fe_is_square_var(&r);
  ------------------
  |  |  103|  7.47k|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  975|  7.47k|}
secp256k1.c:secp256k1_gej_add_ge_var:
  590|  78.9k|static void secp256k1_gej_add_ge_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, secp256k1_fe *rzr) {
  591|       |    /* Operations: 8 mul, 3 sqr, 11 add/negate/normalizes_to_zero (ignoring special cases) */
  592|  78.9k|    secp256k1_fe z12, u1, u2, s1, s2, h, i, h2, h3, t;
  593|  78.9k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  78.9k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  594|  78.9k|    SECP256K1_GE_VERIFY(b);
  ------------------
  |  |  212|  78.9k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  595|       |
  596|  78.9k|    if (a->infinity) {
  ------------------
  |  Branch (596:9): [True: 0, False: 78.9k]
  ------------------
  597|      0|        VERIFY_CHECK(rzr == NULL);
  598|      0|        secp256k1_gej_set_ge(r, b);
  599|      0|        return;
  600|      0|    }
  601|  78.9k|    if (b->infinity) {
  ------------------
  |  Branch (601:9): [True: 0, False: 78.9k]
  ------------------
  602|      0|        if (rzr != NULL) {
  ------------------
  |  Branch (602:13): [True: 0, False: 0]
  ------------------
  603|      0|            secp256k1_fe_set_int(rzr, 1);
  ------------------
  |  |   83|      0|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  604|      0|        }
  605|      0|        *r = *a;
  606|      0|        return;
  607|      0|    }
  608|       |
  609|  78.9k|    secp256k1_fe_sqr(&z12, &a->z);
  ------------------
  |  |   94|  78.9k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  610|  78.9k|    u1 = a->x;
  611|  78.9k|    secp256k1_fe_mul(&u2, &b->x, &z12);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  612|  78.9k|    s1 = a->y;
  613|  78.9k|    secp256k1_fe_mul(&s2, &b->y, &z12); secp256k1_fe_mul(&s2, &s2, &a->z);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
                  secp256k1_fe_mul(&s2, &b->y, &z12); secp256k1_fe_mul(&s2, &s2, &a->z);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  614|  78.9k|    secp256k1_fe_negate(&h, &u1, SECP256K1_GEJ_X_MAGNITUDE_MAX); secp256k1_fe_add(&h, &u2);
  ------------------
  |  |  211|  78.9k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  78.9k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  78.9k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 78.9k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  78.9k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 78.9k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  78.9k|    } \
  |  |  |  |   94|  78.9k|    stmt; \
  |  |  |  |   95|  78.9k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 78.9k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  secp256k1_fe_negate(&h, &u1, SECP256K1_GEJ_X_MAGNITUDE_MAX); secp256k1_fe_add(&h, &u2);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  615|  78.9k|    secp256k1_fe_negate(&i, &s2, 1); secp256k1_fe_add(&i, &s1);
  ------------------
  |  |  211|  78.9k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  78.9k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  78.9k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 78.9k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  78.9k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 78.9k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  78.9k|    } \
  |  |  |  |   94|  78.9k|    stmt; \
  |  |  |  |   95|  78.9k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 78.9k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  secp256k1_fe_negate(&i, &s2, 1); secp256k1_fe_add(&i, &s1);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  616|  78.9k|    if (secp256k1_fe_normalizes_to_zero_var(&h)) {
  ------------------
  |  |   82|  78.9k|#  define secp256k1_fe_normalizes_to_zero_var secp256k1_fe_impl_normalizes_to_zero_var
  ------------------
  |  Branch (616:9): [True: 0, False: 78.9k]
  ------------------
  617|      0|        if (secp256k1_fe_normalizes_to_zero_var(&i)) {
  ------------------
  |  |   82|      0|#  define secp256k1_fe_normalizes_to_zero_var secp256k1_fe_impl_normalizes_to_zero_var
  ------------------
  |  Branch (617:13): [True: 0, False: 0]
  ------------------
  618|      0|            secp256k1_gej_double_var(r, a, rzr);
  619|      0|        } else {
  620|      0|            if (rzr != NULL) {
  ------------------
  |  Branch (620:17): [True: 0, False: 0]
  ------------------
  621|      0|                secp256k1_fe_set_int(rzr, 0);
  ------------------
  |  |   83|      0|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  622|      0|            }
  623|      0|            secp256k1_gej_set_infinity(r);
  624|      0|        }
  625|      0|        return;
  626|      0|    }
  627|       |
  628|  78.9k|    r->infinity = 0;
  629|  78.9k|    if (rzr != NULL) {
  ------------------
  |  Branch (629:9): [True: 78.9k, False: 0]
  ------------------
  630|  78.9k|        *rzr = h;
  631|  78.9k|    }
  632|  78.9k|    secp256k1_fe_mul(&r->z, &a->z, &h);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  633|       |
  634|  78.9k|    secp256k1_fe_sqr(&h2, &h);
  ------------------
  |  |   94|  78.9k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  635|  78.9k|    secp256k1_fe_negate(&h2, &h2, 1);
  ------------------
  |  |  211|  78.9k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  78.9k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  78.9k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 78.9k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  78.9k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 78.9k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  78.9k|    } \
  |  |  |  |   94|  78.9k|    stmt; \
  |  |  |  |   95|  78.9k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 78.9k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  636|  78.9k|    secp256k1_fe_mul(&h3, &h2, &h);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  637|  78.9k|    secp256k1_fe_mul(&t, &u1, &h2);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  638|       |
  639|  78.9k|    secp256k1_fe_sqr(&r->x, &i);
  ------------------
  |  |   94|  78.9k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  640|  78.9k|    secp256k1_fe_add(&r->x, &h3);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  641|  78.9k|    secp256k1_fe_add(&r->x, &t);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  642|  78.9k|    secp256k1_fe_add(&r->x, &t);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  643|       |
  644|  78.9k|    secp256k1_fe_add(&t, &r->x);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  645|  78.9k|    secp256k1_fe_mul(&r->y, &t, &i);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  646|  78.9k|    secp256k1_fe_mul(&h3, &h3, &s1);
  ------------------
  |  |   93|  78.9k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  647|  78.9k|    secp256k1_fe_add(&r->y, &h3);
  ------------------
  |  |   92|  78.9k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  648|       |
  649|  78.9k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  78.9k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  650|  78.9k|    if (rzr != NULL) SECP256K1_FE_VERIFY(rzr);
  ------------------
  |  |  345|  78.9k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  |  Branch (650:9): [True: 78.9k, False: 0]
  ------------------
  651|  78.9k|}

secp256k1.c:secp256k1_sha256_transform:
  133|  49.2k|static void secp256k1_sha256_transform(uint32_t *state, const unsigned char *blocks64, size_t n_blocks) {
  134|  98.4k|    while (n_blocks--) {
  ------------------
  |  Branch (134:12): [True: 49.2k, False: 49.2k]
  ------------------
  135|  49.2k|        secp256k1_sha256_transform_impl(state, blocks64);
  136|  49.2k|        blocks64 += 64;
  137|  49.2k|    }
  138|  49.2k|}
secp256k1.c:secp256k1_sha256_transform_impl:
   51|  49.2k|static void secp256k1_sha256_transform_impl(uint32_t* s, const unsigned char* buf) {
   52|  49.2k|    uint32_t a = s[0], b = s[1], c = s[2], d = s[3], e = s[4], f = s[5], g = s[6], h = s[7];
   53|  49.2k|    uint32_t w0, w1, w2, w3, w4, w5, w6, w7, w8, w9, w10, w11, w12, w13, w14, w15;
   54|       |
   55|  49.2k|    Round(a, b, c, d, e, f, g, h, 0x428a2f98,  w0 = secp256k1_read_be32(&buf[0]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   56|  49.2k|    Round(h, a, b, c, d, e, f, g, 0x71374491,  w1 = secp256k1_read_be32(&buf[4]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   57|  49.2k|    Round(g, h, a, b, c, d, e, f, 0xb5c0fbcf,  w2 = secp256k1_read_be32(&buf[8]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   58|  49.2k|    Round(f, g, h, a, b, c, d, e, 0xe9b5dba5,  w3 = secp256k1_read_be32(&buf[12]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   59|  49.2k|    Round(e, f, g, h, a, b, c, d, 0x3956c25b,  w4 = secp256k1_read_be32(&buf[16]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   60|  49.2k|    Round(d, e, f, g, h, a, b, c, 0x59f111f1,  w5 = secp256k1_read_be32(&buf[20]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   61|  49.2k|    Round(c, d, e, f, g, h, a, b, 0x923f82a4,  w6 = secp256k1_read_be32(&buf[24]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   62|  49.2k|    Round(b, c, d, e, f, g, h, a, 0xab1c5ed5,  w7 = secp256k1_read_be32(&buf[28]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   63|  49.2k|    Round(a, b, c, d, e, f, g, h, 0xd807aa98,  w8 = secp256k1_read_be32(&buf[32]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   64|  49.2k|    Round(h, a, b, c, d, e, f, g, 0x12835b01,  w9 = secp256k1_read_be32(&buf[36]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   65|  49.2k|    Round(g, h, a, b, c, d, e, f, 0x243185be, w10 = secp256k1_read_be32(&buf[40]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   66|  49.2k|    Round(f, g, h, a, b, c, d, e, 0x550c7dc3, w11 = secp256k1_read_be32(&buf[44]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   67|  49.2k|    Round(e, f, g, h, a, b, c, d, 0x72be5d74, w12 = secp256k1_read_be32(&buf[48]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   68|  49.2k|    Round(d, e, f, g, h, a, b, c, 0x80deb1fe, w13 = secp256k1_read_be32(&buf[52]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   69|  49.2k|    Round(c, d, e, f, g, h, a, b, 0x9bdc06a7, w14 = secp256k1_read_be32(&buf[56]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   70|  49.2k|    Round(b, c, d, e, f, g, h, a, 0xc19bf174, w15 = secp256k1_read_be32(&buf[60]));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   71|       |
   72|  49.2k|    Round(a, b, c, d, e, f, g, h, 0xe49b69c1, w0 += sigma1(w14) + w9 + sigma0(w1));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   73|  49.2k|    Round(h, a, b, c, d, e, f, g, 0xefbe4786, w1 += sigma1(w15) + w10 + sigma0(w2));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   74|  49.2k|    Round(g, h, a, b, c, d, e, f, 0x0fc19dc6, w2 += sigma1(w0) + w11 + sigma0(w3));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   75|  49.2k|    Round(f, g, h, a, b, c, d, e, 0x240ca1cc, w3 += sigma1(w1) + w12 + sigma0(w4));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   76|  49.2k|    Round(e, f, g, h, a, b, c, d, 0x2de92c6f, w4 += sigma1(w2) + w13 + sigma0(w5));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   77|  49.2k|    Round(d, e, f, g, h, a, b, c, 0x4a7484aa, w5 += sigma1(w3) + w14 + sigma0(w6));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   78|  49.2k|    Round(c, d, e, f, g, h, a, b, 0x5cb0a9dc, w6 += sigma1(w4) + w15 + sigma0(w7));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   79|  49.2k|    Round(b, c, d, e, f, g, h, a, 0x76f988da, w7 += sigma1(w5) + w0 + sigma0(w8));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   80|  49.2k|    Round(a, b, c, d, e, f, g, h, 0x983e5152, w8 += sigma1(w6) + w1 + sigma0(w9));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   81|  49.2k|    Round(h, a, b, c, d, e, f, g, 0xa831c66d, w9 += sigma1(w7) + w2 + sigma0(w10));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   82|  49.2k|    Round(g, h, a, b, c, d, e, f, 0xb00327c8, w10 += sigma1(w8) + w3 + sigma0(w11));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   83|  49.2k|    Round(f, g, h, a, b, c, d, e, 0xbf597fc7, w11 += sigma1(w9) + w4 + sigma0(w12));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   84|  49.2k|    Round(e, f, g, h, a, b, c, d, 0xc6e00bf3, w12 += sigma1(w10) + w5 + sigma0(w13));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   85|  49.2k|    Round(d, e, f, g, h, a, b, c, 0xd5a79147, w13 += sigma1(w11) + w6 + sigma0(w14));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   86|  49.2k|    Round(c, d, e, f, g, h, a, b, 0x06ca6351, w14 += sigma1(w12) + w7 + sigma0(w15));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   87|  49.2k|    Round(b, c, d, e, f, g, h, a, 0x14292967, w15 += sigma1(w13) + w8 + sigma0(w0));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   88|       |
   89|  49.2k|    Round(a, b, c, d, e, f, g, h, 0x27b70a85, w0 += sigma1(w14) + w9 + sigma0(w1));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   90|  49.2k|    Round(h, a, b, c, d, e, f, g, 0x2e1b2138, w1 += sigma1(w15) + w10 + sigma0(w2));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   91|  49.2k|    Round(g, h, a, b, c, d, e, f, 0x4d2c6dfc, w2 += sigma1(w0) + w11 + sigma0(w3));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   92|  49.2k|    Round(f, g, h, a, b, c, d, e, 0x53380d13, w3 += sigma1(w1) + w12 + sigma0(w4));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   93|  49.2k|    Round(e, f, g, h, a, b, c, d, 0x650a7354, w4 += sigma1(w2) + w13 + sigma0(w5));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   94|  49.2k|    Round(d, e, f, g, h, a, b, c, 0x766a0abb, w5 += sigma1(w3) + w14 + sigma0(w6));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   95|  49.2k|    Round(c, d, e, f, g, h, a, b, 0x81c2c92e, w6 += sigma1(w4) + w15 + sigma0(w7));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   96|  49.2k|    Round(b, c, d, e, f, g, h, a, 0x92722c85, w7 += sigma1(w5) + w0 + sigma0(w8));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   97|  49.2k|    Round(a, b, c, d, e, f, g, h, 0xa2bfe8a1, w8 += sigma1(w6) + w1 + sigma0(w9));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   98|  49.2k|    Round(h, a, b, c, d, e, f, g, 0xa81a664b, w9 += sigma1(w7) + w2 + sigma0(w10));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
   99|  49.2k|    Round(g, h, a, b, c, d, e, f, 0xc24b8b70, w10 += sigma1(w8) + w3 + sigma0(w11));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  100|  49.2k|    Round(f, g, h, a, b, c, d, e, 0xc76c51a3, w11 += sigma1(w9) + w4 + sigma0(w12));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  101|  49.2k|    Round(e, f, g, h, a, b, c, d, 0xd192e819, w12 += sigma1(w10) + w5 + sigma0(w13));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  102|  49.2k|    Round(d, e, f, g, h, a, b, c, 0xd6990624, w13 += sigma1(w11) + w6 + sigma0(w14));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  103|  49.2k|    Round(c, d, e, f, g, h, a, b, 0xf40e3585, w14 += sigma1(w12) + w7 + sigma0(w15));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  104|  49.2k|    Round(b, c, d, e, f, g, h, a, 0x106aa070, w15 += sigma1(w13) + w8 + sigma0(w0));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  105|       |
  106|  49.2k|    Round(a, b, c, d, e, f, g, h, 0x19a4c116, w0 += sigma1(w14) + w9 + sigma0(w1));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  107|  49.2k|    Round(h, a, b, c, d, e, f, g, 0x1e376c08, w1 += sigma1(w15) + w10 + sigma0(w2));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  108|  49.2k|    Round(g, h, a, b, c, d, e, f, 0x2748774c, w2 += sigma1(w0) + w11 + sigma0(w3));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  109|  49.2k|    Round(f, g, h, a, b, c, d, e, 0x34b0bcb5, w3 += sigma1(w1) + w12 + sigma0(w4));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  110|  49.2k|    Round(e, f, g, h, a, b, c, d, 0x391c0cb3, w4 += sigma1(w2) + w13 + sigma0(w5));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  111|  49.2k|    Round(d, e, f, g, h, a, b, c, 0x4ed8aa4a, w5 += sigma1(w3) + w14 + sigma0(w6));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  112|  49.2k|    Round(c, d, e, f, g, h, a, b, 0x5b9cca4f, w6 += sigma1(w4) + w15 + sigma0(w7));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  113|  49.2k|    Round(b, c, d, e, f, g, h, a, 0x682e6ff3, w7 += sigma1(w5) + w0 + sigma0(w8));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  114|  49.2k|    Round(a, b, c, d, e, f, g, h, 0x748f82ee, w8 += sigma1(w6) + w1 + sigma0(w9));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  115|  49.2k|    Round(h, a, b, c, d, e, f, g, 0x78a5636f, w9 += sigma1(w7) + w2 + sigma0(w10));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  116|  49.2k|    Round(g, h, a, b, c, d, e, f, 0x84c87814, w10 += sigma1(w8) + w3 + sigma0(w11));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  117|  49.2k|    Round(f, g, h, a, b, c, d, e, 0x8cc70208, w11 += sigma1(w9) + w4 + sigma0(w12));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  118|  49.2k|    Round(e, f, g, h, a, b, c, d, 0x90befffa, w12 += sigma1(w10) + w5 + sigma0(w13));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  119|  49.2k|    Round(d, e, f, g, h, a, b, c, 0xa4506ceb, w13 += sigma1(w11) + w6 + sigma0(w14));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  120|  49.2k|    Round(c, d, e, f, g, h, a, b, 0xbef9a3f7, w14 + sigma1(w12) + w7 + sigma0(w15));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  121|  49.2k|    Round(b, c, d, e, f, g, h, a, 0xc67178f2, w15 + sigma1(w13) + w8 + sigma0(w0));
  ------------------
  |  |   24|  49.2k|#define Round(a,b,c,d,e,f,g,h,k,w) do { \
  |  |   25|  49.2k|    uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   20|  49.2k|#define Sigma1(x) (((x) >> 6 | (x) << 26) ^ ((x) >> 11 | (x) << 21) ^ ((x) >> 25 | (x) << 7))
  |  |  ------------------
  |  |                   uint32_t t1 = (h) + Sigma1(e) + Ch((e), (f), (g)) + (k) + (w); \
  |  |  ------------------
  |  |  |  |   17|  49.2k|#define Ch(x,y,z) ((z) ^ ((x) & ((y) ^ (z))))
  |  |  ------------------
  |  |   26|  49.2k|    uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   19|  49.2k|#define Sigma0(x) (((x) >> 2 | (x) << 30) ^ ((x) >> 13 | (x) << 19) ^ ((x) >> 22 | (x) << 10))
  |  |  ------------------
  |  |                   uint32_t t2 = Sigma0(a) + Maj((a), (b), (c)); \
  |  |  ------------------
  |  |  |  |   18|  49.2k|#define Maj(x,y,z) (((x) & (y)) | ((z) & ((x) | (y))))
  |  |  ------------------
  |  |   27|  49.2k|    (d) += t1; \
  |  |   28|  49.2k|    (h) = t1 + t2; \
  |  |   29|  49.2k|} while(0)
  |  |  ------------------
  |  |  |  Branch (29:9): [Folded, False: 49.2k]
  |  |  ------------------
  ------------------
  122|       |
  123|  49.2k|    s[0] += a;
  124|  49.2k|    s[1] += b;
  125|  49.2k|    s[2] += c;
  126|  49.2k|    s[3] += d;
  127|  49.2k|    s[4] += e;
  128|  49.2k|    s[5] += f;
  129|  49.2k|    s[6] += g;
  130|  49.2k|    s[7] += h;
  131|  49.2k|}
secp256k1.c:secp256k1_sha256_write:
  210|   126k|static void secp256k1_sha256_write(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *hash, const unsigned char *data, size_t len) {
  211|   126k|    size_t chunk_len;
  212|   126k|    size_t bufsize = hash->bytes & 0x3F;
  213|   126k|    hash->bytes += len;
  214|   126k|    VERIFY_CHECK(hash->bytes >= len);
  215|   126k|    VERIFY_CHECK(hash_ctx != NULL);
  216|   126k|    VERIFY_CHECK(hash_ctx->fn_sha256_compression != NULL);
  217|       |
  218|       |    /* If we exceed the 64-byte block size with this input, process it and wipe the buffer */
  219|   126k|    chunk_len = 64 - bufsize;
  220|   126k|    if (bufsize && len >= chunk_len) {
  ------------------
  |  Branch (220:9): [True: 100k, False: 26.0k]
  |  Branch (220:20): [True: 38.7k, False: 61.8k]
  ------------------
  221|  38.7k|        memcpy(hash->buf + bufsize, data, chunk_len);
  222|  38.7k|        data += chunk_len;
  223|  38.7k|        len -= chunk_len;
  224|  38.7k|        hash_ctx->fn_sha256_compression(hash->s, hash->buf, 1);
  225|  38.7k|        bufsize = 0;
  226|  38.7k|    }
  227|       |
  228|       |    /* If we still have data to process, invoke compression directly on the input */
  229|   126k|    if (len >= 64) {
  ------------------
  |  Branch (229:9): [True: 10.5k, False: 116k]
  ------------------
  230|  10.5k|        const size_t n_blocks = len / 64;
  231|  10.5k|        const size_t advance = n_blocks * 64;
  232|  10.5k|        hash_ctx->fn_sha256_compression(hash->s, data, n_blocks);
  233|  10.5k|        data += advance;
  234|  10.5k|        len -= advance;
  235|  10.5k|    }
  236|       |
  237|       |    /* Fill the buffer with what remains */
  238|   126k|    if (len) {
  ------------------
  |  Branch (238:9): [True: 77.4k, False: 49.2k]
  ------------------
  239|  77.4k|        memcpy(hash->buf + bufsize, data, len);
  240|  77.4k|    }
  241|   126k|}
secp256k1.c:secp256k1_sha256_finalize:
  243|  33.5k|static void secp256k1_sha256_finalize(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *hash, unsigned char *out32) {
  244|  33.5k|    static const unsigned char pad[64] = {0x80};
  245|  33.5k|    unsigned char sizedesc[8];
  246|  33.5k|    int i;
  247|       |    /* The maximum message size of SHA256 is 2^64-1 bits. */
  248|  33.5k|    VERIFY_CHECK(hash->bytes < ((uint64_t)1 << 61));
  249|  33.5k|    secp256k1_write_be32(&sizedesc[0], hash->bytes >> 29);
  250|  33.5k|    secp256k1_write_be32(&sizedesc[4], hash->bytes << 3);
  251|  33.5k|    secp256k1_sha256_write(hash_ctx, hash, pad, 1 + ((119 - (hash->bytes % 64)) % 64));
  252|  33.5k|    secp256k1_sha256_write(hash_ctx, hash, sizedesc, 8);
  253|   302k|    for (i = 0; i < 8; i++) {
  ------------------
  |  Branch (253:17): [True: 268k, False: 33.5k]
  ------------------
  254|   268k|        secp256k1_write_be32(&out32[4*i], hash->s[i]);
  255|   268k|        hash->s[i] = 0;
  256|   268k|    }
  257|  33.5k|}
secp256k1.c:secp256k1_sha256_clear:
  272|  10.4k|static void secp256k1_sha256_clear(secp256k1_sha256 *hash) {
  273|  10.4k|    secp256k1_memclear_explicit(hash, sizeof(*hash));
  274|  10.4k|}
secp256k1.c:secp256k1_sha256_initialize_midstate:
   43|  10.4k|static void secp256k1_sha256_initialize_midstate(secp256k1_sha256 *hash, uint64_t bytes, const uint32_t state[8]) {
   44|  10.4k|    VERIFY_CHECK((bytes & 0x3F) == 0);
   45|  10.4k|    VERIFY_CHECK(state != NULL);
   46|  10.4k|    memcpy(hash->s, state, sizeof(hash->s));
   47|  10.4k|    hash->bytes = bytes;
   48|  10.4k|}

secp256k1.c:secp256k1_u128_mul:
   11|  42.9M|static SECP256K1_INLINE void secp256k1_u128_mul(secp256k1_uint128 *r, uint64_t a, uint64_t b) {
   12|  42.9M|   *r = (uint128_t)a * b;
   13|  42.9M|}
secp256k1.c:secp256k1_u128_accum_mul:
   15|   325M|static SECP256K1_INLINE void secp256k1_u128_accum_mul(secp256k1_uint128 *r, uint64_t a, uint64_t b) {
   16|   325M|   *r += (uint128_t)a * b;
   17|   325M|}
secp256k1.c:secp256k1_u128_to_u64:
   28|   186M|static SECP256K1_INLINE uint64_t secp256k1_u128_to_u64(const secp256k1_uint128 *a) {
   29|   186M|   return (uint64_t)(*a);
   30|   186M|}
secp256k1.c:secp256k1_u128_rshift:
   23|   143M|static SECP256K1_INLINE void secp256k1_u128_rshift(secp256k1_uint128 *r, unsigned int n) {
   24|   143M|   VERIFY_CHECK(n < 128);
   25|   143M|   *r >>= n;
   26|   143M|}
secp256k1.c:secp256k1_u128_accum_u64:
   19|  15.0M|static SECP256K1_INLINE void secp256k1_u128_accum_u64(secp256k1_uint128 *r, uint64_t a) {
   20|  15.0M|   *r += a;
   21|  15.0M|}
secp256k1.c:secp256k1_u128_from_u64:
   36|   114k|static SECP256K1_INLINE void secp256k1_u128_from_u64(secp256k1_uint128 *r, uint64_t a) {
   37|   114k|   *r = a;
   38|   114k|}
secp256k1.c:secp256k1_i128_mul:
   49|  1.67M|static SECP256K1_INLINE void secp256k1_i128_mul(secp256k1_int128 *r, int64_t a, int64_t b) {
   50|  1.67M|   *r = (int128_t)a * b;
   51|  1.67M|}
secp256k1.c:secp256k1_i128_accum_mul:
   53|  10.3M|static SECP256K1_INLINE void secp256k1_i128_accum_mul(secp256k1_int128 *r, int64_t a, int64_t b) {
   54|  10.3M|   int128_t ab = (int128_t)a * b;
   55|  10.3M|   VERIFY_CHECK(0 <= ab ? *r <= INT128_MAX - ab : INT128_MIN - ab <= *r);
   56|  10.3M|   *r += ab;
   57|  10.3M|}
secp256k1.c:secp256k1_i128_to_u64:
   71|  4.33M|static SECP256K1_INLINE uint64_t secp256k1_i128_to_u64(const secp256k1_int128 *a) {
   72|  4.33M|   return (uint64_t)*a;
   73|  4.33M|}
secp256k1.c:secp256k1_i128_rshift:
   66|  5.71M|static SECP256K1_INLINE void secp256k1_i128_rshift(secp256k1_int128 *r, unsigned int n) {
   67|  5.71M|   VERIFY_CHECK(n < 128);
   68|  5.71M|   *r >>= n;
   69|  5.71M|}
secp256k1.c:secp256k1_i128_to_i64:
   75|  1.67M|static SECP256K1_INLINE int64_t secp256k1_i128_to_i64(const secp256k1_int128 *a) {
   76|  1.67M|   VERIFY_CHECK(INT64_MIN <= *a && *a <= INT64_MAX);
   77|  1.67M|   return *a;
   78|  1.67M|}

secp256k1.c:secp256k1_modinv64_var:
  637|  5.14k|static void secp256k1_modinv64_var(secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo) {
  638|       |    /* Start with d=0, e=1, f=modulus, g=x, eta=-1. */
  639|  5.14k|    secp256k1_modinv64_signed62 d = {{0, 0, 0, 0, 0}};
  640|  5.14k|    secp256k1_modinv64_signed62 e = {{1, 0, 0, 0, 0}};
  641|  5.14k|    secp256k1_modinv64_signed62 f = modinfo->modulus;
  642|  5.14k|    secp256k1_modinv64_signed62 g = *x;
  643|       |#ifdef VERIFY
  644|       |    int i = 0;
  645|       |#endif
  646|  5.14k|    int j, len = 5;
  647|  5.14k|    int64_t eta = -1; /* eta = -delta; delta is initially 1 */
  648|  5.14k|    int64_t cond, fn, gn;
  649|       |
  650|       |    /* Do iterations of 62 divsteps each until g=0. */
  651|  46.3k|    while (1) {
  ------------------
  |  Branch (651:12): [True: 46.3k, Folded]
  ------------------
  652|       |        /* Compute transition matrix and new eta after 62 divsteps. */
  653|  46.3k|        secp256k1_modinv64_trans2x2 t;
  654|  46.3k|        eta = secp256k1_modinv64_divsteps_62_var(eta, f.v[0], g.v[0], &t);
  655|       |        /* Update d,e using that transition matrix. */
  656|  46.3k|        secp256k1_modinv64_update_de_62(&d, &e, &t, modinfo);
  657|       |        /* Update f,g using that transition matrix. */
  658|  46.3k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, -1) > 0); /* f > -modulus */
  659|  46.3k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  660|  46.3k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, -1) > 0); /* g > -modulus */
  661|  46.3k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 1) < 0);  /* g <  modulus */
  662|       |
  663|  46.3k|        secp256k1_modinv64_update_fg_62_var(len, &f, &g, &t);
  664|       |        /* If the bottom limb of g is zero, there is a chance that g=0. */
  665|  46.3k|        if (g.v[0] == 0) {
  ------------------
  |  Branch (665:13): [True: 5.14k, False: 41.1k]
  ------------------
  666|  5.14k|            cond = 0;
  667|       |            /* Check if the other limbs are also 0. */
  668|  5.14k|            for (j = 1; j < len; ++j) {
  ------------------
  |  Branch (668:25): [True: 0, False: 5.14k]
  ------------------
  669|      0|                cond |= g.v[j];
  670|      0|            }
  671|       |            /* If so, we're done. */
  672|  5.14k|            if (cond == 0) break;
  ------------------
  |  Branch (672:17): [True: 5.14k, False: 0]
  ------------------
  673|  5.14k|        }
  674|       |
  675|       |        /* Determine if len>1 and limb (len-1) of both f and g is 0 or -1. */
  676|  41.1k|        fn = f.v[len - 1];
  677|  41.1k|        gn = g.v[len - 1];
  678|  41.1k|        cond = ((int64_t)len - 2) >> 63;
  679|  41.1k|        cond |= fn ^ (fn >> 63);
  680|  41.1k|        cond |= gn ^ (gn >> 63);
  681|       |        /* If so, reduce length, propagating the sign of f and g's top limb into the one below. */
  682|  41.1k|        if (cond == 0) {
  ------------------
  |  Branch (682:13): [True: 20.5k, False: 20.5k]
  ------------------
  683|  20.5k|            f.v[len - 2] |= (uint64_t)fn << 62;
  684|  20.5k|            g.v[len - 2] |= (uint64_t)gn << 62;
  685|  20.5k|            --len;
  686|  20.5k|        }
  687|       |
  688|  41.1k|        VERIFY_CHECK(++i < 12); /* We should never need more than 12*62 = 744 divsteps */
  689|  41.1k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, -1) > 0); /* f > -modulus */
  690|  41.1k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  691|  41.1k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, -1) > 0); /* g > -modulus */
  692|  41.1k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 1) < 0);  /* g <  modulus */
  693|  41.1k|    }
  694|       |
  695|       |    /* At this point g is 0 and (if g was not originally 0) f must now equal +/- GCD of
  696|       |     * the initial f, g values i.e. +/- 1, and d now contains +/- the modular inverse. */
  697|       |
  698|       |    /* g == 0 */
  699|  5.14k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &SECP256K1_SIGNED62_ONE, 0) == 0);
  700|       |    /* |f| == 1, or (x == 0 and d == 0 and f == modulus) */
  701|  5.14k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &SECP256K1_SIGNED62_ONE, -1) == 0 ||
  702|  5.14k|                 secp256k1_modinv64_mul_cmp_62(&f, len, &SECP256K1_SIGNED62_ONE, 1) == 0 ||
  703|  5.14k|                 (secp256k1_modinv64_mul_cmp_62(x, 5, &SECP256K1_SIGNED62_ONE, 0) == 0 &&
  704|  5.14k|                  secp256k1_modinv64_mul_cmp_62(&d, 5, &SECP256K1_SIGNED62_ONE, 0) == 0 &&
  705|  5.14k|                  secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) == 0));
  706|       |
  707|       |    /* Optionally negate d, normalize to [0,modulus), and return it. */
  708|  5.14k|    secp256k1_modinv64_normalize_62(&d, f.v[len - 1], modinfo);
  709|  5.14k|    *x = d;
  710|  5.14k|}
secp256k1.c:secp256k1_modinv64_divsteps_62_var:
  239|  46.3k|static int64_t secp256k1_modinv64_divsteps_62_var(int64_t eta, uint64_t f0, uint64_t g0, secp256k1_modinv64_trans2x2 *t) {
  240|       |    /* Transformation matrix; see comments in secp256k1_modinv64_divsteps_62. */
  241|  46.3k|    uint64_t u = 1, v = 0, q = 0, r = 1;
  242|  46.3k|    uint64_t f = f0, g = g0, m;
  243|  46.3k|    uint32_t w;
  244|  46.3k|    int i = 62, limit, zeros;
  245|       |
  246|   760k|    for (;;) {
  247|       |        /* Use a sentinel bit to count zeros only up to i. */
  248|   760k|        zeros = secp256k1_ctz64_var(g | (UINT64_MAX << i));
  249|       |        /* Perform zeros divsteps at once; they all just divide g by two. */
  250|   760k|        g >>= zeros;
  251|   760k|        u <<= zeros;
  252|   760k|        v <<= zeros;
  253|   760k|        eta -= zeros;
  254|   760k|        i -= zeros;
  255|       |        /* We're done once we've done 62 divsteps. */
  256|   760k|        if (i == 0) break;
  ------------------
  |  Branch (256:13): [True: 46.3k, False: 714k]
  ------------------
  257|   714k|        VERIFY_CHECK((f & 1) == 1);
  258|   714k|        VERIFY_CHECK((g & 1) == 1);
  259|   714k|        VERIFY_CHECK((u * f0 + v * g0) == f << (62 - i));
  260|   714k|        VERIFY_CHECK((q * f0 + r * g0) == g << (62 - i));
  261|       |        /* Bounds on eta that follow from the bounds on iteration count (max 12*62 divsteps). */
  262|   714k|        VERIFY_CHECK(eta >= -745 && eta <= 745);
  263|       |        /* If eta is negative, negate it and replace f,g with g,-f. */
  264|   714k|        if (eta < 0) {
  ------------------
  |  Branch (264:13): [True: 689k, False: 24.9k]
  ------------------
  265|   689k|            uint64_t tmp;
  266|   689k|            eta = -eta;
  267|   689k|            tmp = f; f = g; g = -tmp;
  268|   689k|            tmp = u; u = q; q = -tmp;
  269|   689k|            tmp = v; v = r; r = -tmp;
  270|       |            /* Use a formula to cancel out up to 6 bits of g. Also, no more than i can be cancelled
  271|       |             * out (as we'd be done before that point), and no more than eta+1 can be done as its
  272|       |             * sign will flip again once that happens. */
  273|   689k|            limit = ((int)eta + 1) > i ? i : ((int)eta + 1);
  ------------------
  |  Branch (273:21): [True: 13.2k, False: 676k]
  ------------------
  274|   689k|            VERIFY_CHECK(limit > 0 && limit <= 62);
  275|       |            /* m is a mask for the bottom min(limit, 6) bits. */
  276|   689k|            m = (UINT64_MAX >> (64 - limit)) & 63U;
  277|       |            /* Find what multiple of f must be added to g to cancel its bottom min(limit, 6)
  278|       |             * bits. */
  279|   689k|            w = (f * g * (f * f - 2)) & m;
  280|   689k|        } else {
  281|       |            /* In this branch, use a simpler formula that only lets us cancel up to 4 bits of g, as
  282|       |             * eta tends to be smaller here. */
  283|  24.9k|            limit = ((int)eta + 1) > i ? i : ((int)eta + 1);
  ------------------
  |  Branch (283:21): [True: 113, False: 24.8k]
  ------------------
  284|  24.9k|            VERIFY_CHECK(limit > 0 && limit <= 62);
  285|       |            /* m is a mask for the bottom min(limit, 4) bits. */
  286|  24.9k|            m = (UINT64_MAX >> (64 - limit)) & 15U;
  287|       |            /* Find what multiple of f must be added to g to cancel its bottom min(limit, 4)
  288|       |             * bits. */
  289|  24.9k|            w = f + (((f + 1) & 4) << 1);
  290|  24.9k|            w = (-w * g) & m;
  291|  24.9k|        }
  292|   714k|        g += f * w;
  293|   714k|        q += u * w;
  294|   714k|        r += v * w;
  295|   714k|        VERIFY_CHECK((g & m) == 0);
  296|   714k|    }
  297|       |    /* Return data in t and return value. */
  298|  46.3k|    t->u = (int64_t)u;
  299|  46.3k|    t->v = (int64_t)v;
  300|  46.3k|    t->q = (int64_t)q;
  301|  46.3k|    t->r = (int64_t)r;
  302|       |
  303|       |    /* The determinant of t must be a power of two. This guarantees that multiplication with t
  304|       |     * does not change the gcd of f and g, apart from adding a power-of-2 factor to it (which
  305|       |     * will be divided out again). As each divstep's individual matrix has determinant 2, the
  306|       |     * aggregate of 62 of them will have determinant 2^62. */
  307|  46.3k|    VERIFY_CHECK(secp256k1_modinv64_det_check_pow2(t, 62, 0));
  308|       |
  309|  46.3k|    return eta;
  310|  46.3k|}
secp256k1.c:secp256k1_modinv64_update_de_62:
  411|   150k|static void secp256k1_modinv64_update_de_62(secp256k1_modinv64_signed62 *d, secp256k1_modinv64_signed62 *e, const secp256k1_modinv64_trans2x2 *t, const secp256k1_modinv64_modinfo* modinfo) {
  412|   150k|    const uint64_t M62 = UINT64_MAX >> 2;
  413|   150k|    const int64_t d0 = d->v[0], d1 = d->v[1], d2 = d->v[2], d3 = d->v[3], d4 = d->v[4];
  414|   150k|    const int64_t e0 = e->v[0], e1 = e->v[1], e2 = e->v[2], e3 = e->v[3], e4 = e->v[4];
  415|   150k|    const int64_t u = t->u, v = t->v, q = t->q, r = t->r;
  416|   150k|    int64_t md, me, sd, se;
  417|   150k|    secp256k1_int128 cd, ce;
  418|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, -2) > 0); /* d > -2*modulus */
  419|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, 1) < 0);  /* d <    modulus */
  420|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, -2) > 0); /* e > -2*modulus */
  421|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, 1) < 0);  /* e <    modulus */
  422|   150k|    VERIFY_CHECK(secp256k1_modinv64_abs(u) <= (((int64_t)1 << 62) - secp256k1_modinv64_abs(v))); /* |u|+|v| <= 2^62 */
  423|   150k|    VERIFY_CHECK(secp256k1_modinv64_abs(q) <= (((int64_t)1 << 62) - secp256k1_modinv64_abs(r))); /* |q|+|r| <= 2^62 */
  424|       |
  425|       |    /* [md,me] start as zero; plus [u,q] if d is negative; plus [v,r] if e is negative. */
  426|   150k|    sd = d4 >> 63;
  427|   150k|    se = e4 >> 63;
  428|   150k|    md = (u & sd) + (v & se);
  429|   150k|    me = (q & sd) + (r & se);
  430|       |    /* Begin computing t*[d,e]. */
  431|   150k|    secp256k1_i128_mul(&cd, u, d0);
  432|   150k|    secp256k1_i128_accum_mul(&cd, v, e0);
  433|   150k|    secp256k1_i128_mul(&ce, q, d0);
  434|   150k|    secp256k1_i128_accum_mul(&ce, r, e0);
  435|       |    /* Correct md,me so that t*[d,e]+modulus*[md,me] has 62 zero bottom bits. */
  436|   150k|    md -= (modinfo->modulus_inv62 * secp256k1_i128_to_u64(&cd) + md) & M62;
  437|   150k|    me -= (modinfo->modulus_inv62 * secp256k1_i128_to_u64(&ce) + me) & M62;
  438|       |    /* Update the beginning of computation for t*[d,e]+modulus*[md,me] now md,me are known. */
  439|   150k|    secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[0], md);
  440|   150k|    secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[0], me);
  441|       |    /* Verify that the low 62 bits of the computation are indeed zero, and then throw them away. */
  442|   150k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cd) & M62) == 0); secp256k1_i128_rshift(&cd, 62);
  443|   150k|    VERIFY_CHECK((secp256k1_i128_to_u64(&ce) & M62) == 0); secp256k1_i128_rshift(&ce, 62);
  444|       |    /* Compute limb 1 of t*[d,e]+modulus*[md,me], and store it as output limb 0 (= down shift). */
  445|   150k|    secp256k1_i128_accum_mul(&cd, u, d1);
  446|   150k|    secp256k1_i128_accum_mul(&cd, v, e1);
  447|   150k|    secp256k1_i128_accum_mul(&ce, q, d1);
  448|   150k|    secp256k1_i128_accum_mul(&ce, r, e1);
  449|   150k|    if (modinfo->modulus.v[1]) { /* Optimize for the case where limb of modulus is zero. */
  ------------------
  |  Branch (449:9): [True: 0, False: 150k]
  ------------------
  450|      0|        secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[1], md);
  451|      0|        secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[1], me);
  452|      0|    }
  453|   150k|    d->v[0] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  454|   150k|    e->v[0] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  455|       |    /* Compute limb 2 of t*[d,e]+modulus*[md,me], and store it as output limb 1. */
  456|   150k|    secp256k1_i128_accum_mul(&cd, u, d2);
  457|   150k|    secp256k1_i128_accum_mul(&cd, v, e2);
  458|   150k|    secp256k1_i128_accum_mul(&ce, q, d2);
  459|   150k|    secp256k1_i128_accum_mul(&ce, r, e2);
  460|   150k|    if (modinfo->modulus.v[2]) { /* Optimize for the case where limb of modulus is zero. */
  ------------------
  |  Branch (460:9): [True: 0, False: 150k]
  ------------------
  461|      0|        secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[2], md);
  462|      0|        secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[2], me);
  463|      0|    }
  464|   150k|    d->v[1] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  465|   150k|    e->v[1] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  466|       |    /* Compute limb 3 of t*[d,e]+modulus*[md,me], and store it as output limb 2. */
  467|   150k|    secp256k1_i128_accum_mul(&cd, u, d3);
  468|   150k|    secp256k1_i128_accum_mul(&cd, v, e3);
  469|   150k|    secp256k1_i128_accum_mul(&ce, q, d3);
  470|   150k|    secp256k1_i128_accum_mul(&ce, r, e3);
  471|   150k|    if (modinfo->modulus.v[3]) { /* Optimize for the case where limb of modulus is zero. */
  ------------------
  |  Branch (471:9): [True: 0, False: 150k]
  ------------------
  472|      0|        secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[3], md);
  473|      0|        secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[3], me);
  474|      0|    }
  475|   150k|    d->v[2] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  476|   150k|    e->v[2] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  477|       |    /* Compute limb 4 of t*[d,e]+modulus*[md,me], and store it as output limb 3. */
  478|   150k|    secp256k1_i128_accum_mul(&cd, u, d4);
  479|   150k|    secp256k1_i128_accum_mul(&cd, v, e4);
  480|   150k|    secp256k1_i128_accum_mul(&ce, q, d4);
  481|   150k|    secp256k1_i128_accum_mul(&ce, r, e4);
  482|   150k|    secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[4], md);
  483|   150k|    secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[4], me);
  484|   150k|    d->v[3] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  485|   150k|    e->v[3] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  486|       |    /* What remains is limb 5 of t*[d,e]+modulus*[md,me]; store it as output limb 4. */
  487|   150k|    d->v[4] = secp256k1_i128_to_i64(&cd);
  488|   150k|    e->v[4] = secp256k1_i128_to_i64(&ce);
  489|       |
  490|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, -2) > 0); /* d > -2*modulus */
  491|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, 1) < 0);  /* d <    modulus */
  492|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, -2) > 0); /* e > -2*modulus */
  493|   150k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, 1) < 0);  /* e <    modulus */
  494|   150k|}
secp256k1.c:secp256k1_modinv64_update_fg_62_var:
  553|   582k|static void secp256k1_modinv64_update_fg_62_var(int len, secp256k1_modinv64_signed62 *f, secp256k1_modinv64_signed62 *g, const secp256k1_modinv64_trans2x2 *t) {
  554|   582k|    const uint64_t M62 = UINT64_MAX >> 2;
  555|   582k|    const int64_t u = t->u, v = t->v, q = t->q, r = t->r;
  556|   582k|    int64_t fi, gi;
  557|   582k|    secp256k1_int128 cf, cg;
  558|   582k|    int i;
  559|   582k|    VERIFY_CHECK(len > 0);
  560|       |    /* Start computing t*[f,g]. */
  561|   582k|    fi = f->v[0];
  562|   582k|    gi = g->v[0];
  563|   582k|    secp256k1_i128_mul(&cf, u, fi);
  564|   582k|    secp256k1_i128_accum_mul(&cf, v, gi);
  565|   582k|    secp256k1_i128_mul(&cg, q, fi);
  566|   582k|    secp256k1_i128_accum_mul(&cg, r, gi);
  567|       |    /* Verify that the bottom 62 bits of the result are zero, and then throw them away. */
  568|   582k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cf) & M62) == 0); secp256k1_i128_rshift(&cf, 62);
  569|   582k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cg) & M62) == 0); secp256k1_i128_rshift(&cg, 62);
  570|       |    /* Now iteratively compute limb i=1..len of t*[f,g], and store them in output limb i-1 (shifting
  571|       |     * down by 62 bits). */
  572|  1.58M|    for (i = 1; i < len; ++i) {
  ------------------
  |  Branch (572:17): [True: 1.00M, False: 582k]
  ------------------
  573|  1.00M|        fi = f->v[i];
  574|  1.00M|        gi = g->v[i];
  575|  1.00M|        secp256k1_i128_accum_mul(&cf, u, fi);
  576|  1.00M|        secp256k1_i128_accum_mul(&cf, v, gi);
  577|  1.00M|        secp256k1_i128_accum_mul(&cg, q, fi);
  578|  1.00M|        secp256k1_i128_accum_mul(&cg, r, gi);
  579|  1.00M|        f->v[i - 1] = secp256k1_i128_to_u64(&cf) & M62; secp256k1_i128_rshift(&cf, 62);
  580|  1.00M|        g->v[i - 1] = secp256k1_i128_to_u64(&cg) & M62; secp256k1_i128_rshift(&cg, 62);
  581|  1.00M|    }
  582|       |    /* What remains is limb (len) of t*[f,g]; store it as output limb (len-1). */
  583|   582k|    f->v[len - 1] = secp256k1_i128_to_i64(&cf);
  584|   582k|    g->v[len - 1] = secp256k1_i128_to_i64(&cg);
  585|   582k|}
secp256k1.c:secp256k1_modinv64_normalize_62:
   88|  15.5k|static void secp256k1_modinv64_normalize_62(secp256k1_modinv64_signed62 *r, int64_t sign, const secp256k1_modinv64_modinfo *modinfo) {
   89|  15.5k|    const int64_t M62 = (int64_t)(UINT64_MAX >> 2);
   90|  15.5k|    int64_t r0 = r->v[0], r1 = r->v[1], r2 = r->v[2], r3 = r->v[3], r4 = r->v[4];
   91|  15.5k|    volatile int64_t cond_add, cond_negate;
   92|       |
   93|       |#ifdef VERIFY
   94|       |    /* Verify that all limbs are in range (-2^62,2^62). */
   95|       |    int i;
   96|       |    for (i = 0; i < 5; ++i) {
   97|       |        VERIFY_CHECK(r->v[i] >= -M62);
   98|       |        VERIFY_CHECK(r->v[i] <= M62);
   99|       |    }
  100|       |    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, -2) > 0); /* r > -2*modulus */
  101|       |    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, 1) < 0); /* r < modulus */
  102|       |#endif
  103|       |
  104|       |    /* In a first step, add the modulus if the input is negative, and then negate if requested.
  105|       |     * This brings r from range (-2*modulus,modulus) to range (-modulus,modulus). As all input
  106|       |     * limbs are in range (-2^62,2^62), this cannot overflow an int64_t. Note that the right
  107|       |     * shifts below are signed sign-extending shifts (see assumptions.h for tests that that is
  108|       |     * indeed the behavior of the right shift operator). */
  109|  15.5k|    cond_add = r4 >> 63;
  110|  15.5k|    r0 += modinfo->modulus.v[0] & cond_add;
  111|  15.5k|    r1 += modinfo->modulus.v[1] & cond_add;
  112|  15.5k|    r2 += modinfo->modulus.v[2] & cond_add;
  113|  15.5k|    r3 += modinfo->modulus.v[3] & cond_add;
  114|  15.5k|    r4 += modinfo->modulus.v[4] & cond_add;
  115|  15.5k|    cond_negate = sign >> 63;
  116|  15.5k|    r0 = (r0 ^ cond_negate) - cond_negate;
  117|  15.5k|    r1 = (r1 ^ cond_negate) - cond_negate;
  118|  15.5k|    r2 = (r2 ^ cond_negate) - cond_negate;
  119|  15.5k|    r3 = (r3 ^ cond_negate) - cond_negate;
  120|  15.5k|    r4 = (r4 ^ cond_negate) - cond_negate;
  121|       |    /* Propagate the top bits, to bring limbs back to range (-2^62,2^62). */
  122|  15.5k|    r1 += r0 >> 62; r0 &= M62;
  123|  15.5k|    r2 += r1 >> 62; r1 &= M62;
  124|  15.5k|    r3 += r2 >> 62; r2 &= M62;
  125|  15.5k|    r4 += r3 >> 62; r3 &= M62;
  126|       |
  127|       |    /* In a second step add the modulus again if the result is still negative, bringing
  128|       |     * r to range [0,modulus). */
  129|  15.5k|    cond_add = r4 >> 63;
  130|  15.5k|    r0 += modinfo->modulus.v[0] & cond_add;
  131|  15.5k|    r1 += modinfo->modulus.v[1] & cond_add;
  132|  15.5k|    r2 += modinfo->modulus.v[2] & cond_add;
  133|  15.5k|    r3 += modinfo->modulus.v[3] & cond_add;
  134|  15.5k|    r4 += modinfo->modulus.v[4] & cond_add;
  135|       |    /* And propagate again. */
  136|  15.5k|    r1 += r0 >> 62; r0 &= M62;
  137|  15.5k|    r2 += r1 >> 62; r1 &= M62;
  138|  15.5k|    r3 += r2 >> 62; r2 &= M62;
  139|  15.5k|    r4 += r3 >> 62; r3 &= M62;
  140|       |
  141|  15.5k|    r->v[0] = r0;
  142|  15.5k|    r->v[1] = r1;
  143|  15.5k|    r->v[2] = r2;
  144|  15.5k|    r->v[3] = r3;
  145|  15.5k|    r->v[4] = r4;
  146|       |
  147|  15.5k|    VERIFY_CHECK(r0 >> 62 == 0);
  148|  15.5k|    VERIFY_CHECK(r1 >> 62 == 0);
  149|  15.5k|    VERIFY_CHECK(r2 >> 62 == 0);
  150|  15.5k|    VERIFY_CHECK(r3 >> 62 == 0);
  151|  15.5k|    VERIFY_CHECK(r4 >> 62 == 0);
  152|  15.5k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, 0) >= 0); /* r >= 0 */
  153|  15.5k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, 1) < 0); /* r < modulus */
  154|  15.5k|}
secp256k1.c:secp256k1_modinv64:
  588|  10.4k|static void secp256k1_modinv64(secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo) {
  589|       |    /* Start with d=0, e=1, f=modulus, g=x, zeta=-1. */
  590|  10.4k|    secp256k1_modinv64_signed62 d = {{0, 0, 0, 0, 0}};
  591|  10.4k|    secp256k1_modinv64_signed62 e = {{1, 0, 0, 0, 0}};
  592|  10.4k|    secp256k1_modinv64_signed62 f = modinfo->modulus;
  593|  10.4k|    secp256k1_modinv64_signed62 g = *x;
  594|  10.4k|    int i;
  595|  10.4k|    int64_t zeta = -1; /* zeta = -(delta+1/2); delta starts at 1/2. */
  596|       |
  597|       |    /* Do 10 iterations of 59 divsteps each = 590 divsteps. This suffices for 256-bit inputs. */
  598|   114k|    for (i = 0; i < 10; ++i) {
  ------------------
  |  Branch (598:17): [True: 104k, False: 10.4k]
  ------------------
  599|       |        /* Compute transition matrix and new zeta after 59 divsteps. */
  600|   104k|        secp256k1_modinv64_trans2x2 t;
  601|   104k|        zeta = secp256k1_modinv64_divsteps_59(zeta, f.v[0], g.v[0], &t);
  602|       |        /* Update d,e using that transition matrix. */
  603|   104k|        secp256k1_modinv64_update_de_62(&d, &e, &t, modinfo);
  604|       |        /* Update f,g using that transition matrix. */
  605|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, 5, &modinfo->modulus, -1) > 0); /* f > -modulus */
  606|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, 5, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  607|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, 5, &modinfo->modulus, -1) > 0); /* g > -modulus */
  608|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, 5, &modinfo->modulus, 1) < 0);  /* g <  modulus */
  609|       |
  610|   104k|        secp256k1_modinv64_update_fg_62(&f, &g, &t);
  611|       |
  612|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, 5, &modinfo->modulus, -1) > 0); /* f > -modulus */
  613|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, 5, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  614|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, 5, &modinfo->modulus, -1) > 0); /* g > -modulus */
  615|   104k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, 5, &modinfo->modulus, 1) < 0);  /* g <  modulus */
  616|   104k|    }
  617|       |
  618|       |    /* At this point sufficient iterations have been performed that g must have reached 0
  619|       |     * and (if g was not originally 0) f must now equal +/- GCD of the initial f, g
  620|       |     * values i.e. +/- 1, and d now contains +/- the modular inverse. */
  621|       |
  622|       |    /* g == 0 */
  623|  10.4k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, 5, &SECP256K1_SIGNED62_ONE, 0) == 0);
  624|       |    /* |f| == 1, or (x == 0 and d == 0 and f == modulus) */
  625|  10.4k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, 5, &SECP256K1_SIGNED62_ONE, -1) == 0 ||
  626|  10.4k|                 secp256k1_modinv64_mul_cmp_62(&f, 5, &SECP256K1_SIGNED62_ONE, 1) == 0 ||
  627|  10.4k|                 (secp256k1_modinv64_mul_cmp_62(x, 5, &SECP256K1_SIGNED62_ONE, 0) == 0 &&
  628|  10.4k|                  secp256k1_modinv64_mul_cmp_62(&d, 5, &SECP256K1_SIGNED62_ONE, 0) == 0 &&
  629|  10.4k|                  secp256k1_modinv64_mul_cmp_62(&f, 5, &modinfo->modulus, 1) == 0));
  630|       |
  631|       |    /* Optionally negate d, normalize to [0,modulus), and return it. */
  632|  10.4k|    secp256k1_modinv64_normalize_62(&d, f.v[4], modinfo);
  633|  10.4k|    *x = d;
  634|  10.4k|}
secp256k1.c:secp256k1_modinv64_divsteps_59:
  167|   104k|static int64_t secp256k1_modinv64_divsteps_59(int64_t zeta, uint64_t f0, uint64_t g0, secp256k1_modinv64_trans2x2 *t) {
  168|       |    /* u,v,q,r are the elements of the transformation matrix being built up,
  169|       |     * starting with the identity matrix times 8 (because the caller expects
  170|       |     * a result scaled by 2^62). Semantically they are signed integers
  171|       |     * in range [-2^62,2^62], but here represented as unsigned mod 2^64. This
  172|       |     * permits left shifting (which is UB for negative numbers). The range
  173|       |     * being inside [-2^63,2^63) means that casting to signed works correctly.
  174|       |     */
  175|   104k|    uint64_t u = 8, v = 0, q = 0, r = 8;
  176|   104k|    volatile uint64_t c1, c2;
  177|   104k|    uint64_t mask1, mask2, f = f0, g = g0, x, y, z;
  178|   104k|    int i;
  179|       |
  180|  6.24M|    for (i = 3; i < 62; ++i) {
  ------------------
  |  Branch (180:17): [True: 6.13M, False: 104k]
  ------------------
  181|  6.13M|        VERIFY_CHECK((f & 1) == 1); /* f must always be odd */
  182|  6.13M|        VERIFY_CHECK((u * f0 + v * g0) == f << i);
  183|  6.13M|        VERIFY_CHECK((q * f0 + r * g0) == g << i);
  184|       |        /* Compute conditional masks for (zeta < 0) and for (g & 1). */
  185|  6.13M|        c1 = zeta >> 63;
  186|  6.13M|        mask1 = c1;
  187|  6.13M|        c2 = g & 1;
  188|  6.13M|        mask2 = -c2;
  189|       |        /* Compute x,y,z, conditionally negated versions of f,u,v. */
  190|  6.13M|        x = (f ^ mask1) - mask1;
  191|  6.13M|        y = (u ^ mask1) - mask1;
  192|  6.13M|        z = (v ^ mask1) - mask1;
  193|       |        /* Conditionally add x,y,z to g,q,r. */
  194|  6.13M|        g += x & mask2;
  195|  6.13M|        q += y & mask2;
  196|  6.13M|        r += z & mask2;
  197|       |        /* In what follows, c1 is a condition mask for (zeta < 0) and (g & 1). */
  198|  6.13M|        mask1 &= mask2;
  199|       |        /* Conditionally change zeta into -zeta-2 or zeta-1. */
  200|  6.13M|        zeta = (zeta ^ mask1) - 1;
  201|       |        /* Conditionally add g,q,r to f,u,v. */
  202|  6.13M|        f += g & mask1;
  203|  6.13M|        u += q & mask1;
  204|  6.13M|        v += r & mask1;
  205|       |        /* Shifts */
  206|  6.13M|        g >>= 1;
  207|  6.13M|        u <<= 1;
  208|  6.13M|        v <<= 1;
  209|       |        /* Bounds on zeta that follow from the bounds on iteration count (max 10*59 divsteps). */
  210|  6.13M|        VERIFY_CHECK(zeta >= -591 && zeta <= 591);
  211|  6.13M|    }
  212|       |    /* Return data in t and return value. */
  213|   104k|    t->u = (int64_t)u;
  214|   104k|    t->v = (int64_t)v;
  215|   104k|    t->q = (int64_t)q;
  216|   104k|    t->r = (int64_t)r;
  217|       |
  218|       |    /* The determinant of t must be a power of two. This guarantees that multiplication with t
  219|       |     * does not change the gcd of f and g, apart from adding a power-of-2 factor to it (which
  220|       |     * will be divided out again). As each divstep's individual matrix has determinant 2, the
  221|       |     * aggregate of 59 of them will have determinant 2^59. Multiplying with the initial
  222|       |     * 8*identity (which has determinant 2^6) means the overall outputs has determinant
  223|       |     * 2^65. */
  224|   104k|    VERIFY_CHECK(secp256k1_modinv64_det_check_pow2(t, 65, 0));
  225|       |
  226|   104k|    return zeta;
  227|   104k|}
secp256k1.c:secp256k1_modinv64_update_fg_62:
  500|   104k|static void secp256k1_modinv64_update_fg_62(secp256k1_modinv64_signed62 *f, secp256k1_modinv64_signed62 *g, const secp256k1_modinv64_trans2x2 *t) {
  501|   104k|    const uint64_t M62 = UINT64_MAX >> 2;
  502|   104k|    const int64_t f0 = f->v[0], f1 = f->v[1], f2 = f->v[2], f3 = f->v[3], f4 = f->v[4];
  503|   104k|    const int64_t g0 = g->v[0], g1 = g->v[1], g2 = g->v[2], g3 = g->v[3], g4 = g->v[4];
  504|   104k|    const int64_t u = t->u, v = t->v, q = t->q, r = t->r;
  505|   104k|    secp256k1_int128 cf, cg;
  506|       |    /* Start computing t*[f,g]. */
  507|   104k|    secp256k1_i128_mul(&cf, u, f0);
  508|   104k|    secp256k1_i128_accum_mul(&cf, v, g0);
  509|   104k|    secp256k1_i128_mul(&cg, q, f0);
  510|   104k|    secp256k1_i128_accum_mul(&cg, r, g0);
  511|       |    /* Verify that the bottom 62 bits of the result are zero, and then throw them away. */
  512|   104k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cf) & M62) == 0); secp256k1_i128_rshift(&cf, 62);
  513|   104k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cg) & M62) == 0); secp256k1_i128_rshift(&cg, 62);
  514|       |    /* Compute limb 1 of t*[f,g], and store it as output limb 0 (= down shift). */
  515|   104k|    secp256k1_i128_accum_mul(&cf, u, f1);
  516|   104k|    secp256k1_i128_accum_mul(&cf, v, g1);
  517|   104k|    secp256k1_i128_accum_mul(&cg, q, f1);
  518|   104k|    secp256k1_i128_accum_mul(&cg, r, g1);
  519|   104k|    f->v[0] = secp256k1_i128_to_u64(&cf) & M62; secp256k1_i128_rshift(&cf, 62);
  520|   104k|    g->v[0] = secp256k1_i128_to_u64(&cg) & M62; secp256k1_i128_rshift(&cg, 62);
  521|       |    /* Compute limb 2 of t*[f,g], and store it as output limb 1. */
  522|   104k|    secp256k1_i128_accum_mul(&cf, u, f2);
  523|   104k|    secp256k1_i128_accum_mul(&cf, v, g2);
  524|   104k|    secp256k1_i128_accum_mul(&cg, q, f2);
  525|   104k|    secp256k1_i128_accum_mul(&cg, r, g2);
  526|   104k|    f->v[1] = secp256k1_i128_to_u64(&cf) & M62; secp256k1_i128_rshift(&cf, 62);
  527|   104k|    g->v[1] = secp256k1_i128_to_u64(&cg) & M62; secp256k1_i128_rshift(&cg, 62);
  528|       |    /* Compute limb 3 of t*[f,g], and store it as output limb 2. */
  529|   104k|    secp256k1_i128_accum_mul(&cf, u, f3);
  530|   104k|    secp256k1_i128_accum_mul(&cf, v, g3);
  531|   104k|    secp256k1_i128_accum_mul(&cg, q, f3);
  532|   104k|    secp256k1_i128_accum_mul(&cg, r, g3);
  533|   104k|    f->v[2] = secp256k1_i128_to_u64(&cf) & M62; secp256k1_i128_rshift(&cf, 62);
  534|   104k|    g->v[2] = secp256k1_i128_to_u64(&cg) & M62; secp256k1_i128_rshift(&cg, 62);
  535|       |    /* Compute limb 4 of t*[f,g], and store it as output limb 3. */
  536|   104k|    secp256k1_i128_accum_mul(&cf, u, f4);
  537|   104k|    secp256k1_i128_accum_mul(&cf, v, g4);
  538|   104k|    secp256k1_i128_accum_mul(&cg, q, f4);
  539|   104k|    secp256k1_i128_accum_mul(&cg, r, g4);
  540|   104k|    f->v[3] = secp256k1_i128_to_u64(&cf) & M62; secp256k1_i128_rshift(&cf, 62);
  541|   104k|    g->v[3] = secp256k1_i128_to_u64(&cg) & M62; secp256k1_i128_rshift(&cg, 62);
  542|       |    /* What remains is limb 5 of t*[f,g]; store it as output limb 4. */
  543|   104k|    f->v[4] = secp256k1_i128_to_i64(&cf);
  544|   104k|    g->v[4] = secp256k1_i128_to_i64(&cg);
  545|   104k|}
secp256k1.c:secp256k1_jacobi64_maybe_var:
  721|  42.3k|static int secp256k1_jacobi64_maybe_var(const secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo) {
  722|       |    /* Start with f=modulus, g=x, eta=-1. */
  723|  42.3k|    secp256k1_modinv64_signed62 f = modinfo->modulus;
  724|  42.3k|    secp256k1_modinv64_signed62 g = *x;
  725|  42.3k|    int j, len = 5;
  726|  42.3k|    int64_t eta = -1; /* eta = -delta; delta is initially 1 */
  727|  42.3k|    int64_t cond, fn, gn;
  728|  42.3k|    int jac = 0;
  729|  42.3k|    int count;
  730|       |
  731|       |    /* The input limbs must all be non-negative. */
  732|  42.3k|    VERIFY_CHECK(g.v[0] >= 0 && g.v[1] >= 0 && g.v[2] >= 0 && g.v[3] >= 0 && g.v[4] >= 0);
  733|       |
  734|       |    /* If x > 0, then if the loop below converges, it converges to f=g=gcd(x,modulus). Since we
  735|       |     * require that gcd(x,modulus)=1 and modulus>=3, x cannot be 0. Thus, we must reach f=1 (or
  736|       |     * time out). */
  737|  42.3k|    VERIFY_CHECK((g.v[0] | g.v[1] | g.v[2] | g.v[3] | g.v[4]) != 0);
  738|       |
  739|   536k|    for (count = 0; count < JACOBI64_ITERATIONS; ++count) {
  ------------------
  |  |  717|   536k|#define JACOBI64_ITERATIONS 25
  ------------------
  |  Branch (739:21): [True: 536k, False: 0]
  ------------------
  740|       |        /* Compute transition matrix and new eta after 62 posdivsteps. */
  741|   536k|        secp256k1_modinv64_trans2x2 t;
  742|   536k|        eta = secp256k1_modinv64_posdivsteps_62_var(eta, f.v[0] | ((uint64_t)f.v[1] << 62), g.v[0] | ((uint64_t)g.v[1] << 62), &t, &jac);
  743|       |        /* Update f,g using that transition matrix. */
  744|   536k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 0) > 0); /* f > 0 */
  745|   536k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  746|   536k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 0) > 0); /* g > 0 */
  747|   536k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 1) < 0);  /* g < modulus */
  748|       |
  749|   536k|        secp256k1_modinv64_update_fg_62_var(len, &f, &g, &t);
  750|       |        /* If the bottom limb of f is 1, there is a chance that f=1. */
  751|   536k|        if (f.v[0] == 1) {
  ------------------
  |  Branch (751:13): [True: 42.3k, False: 493k]
  ------------------
  752|  42.3k|            cond = 0;
  753|       |            /* Check if the other limbs are also 0. */
  754|  42.3k|            for (j = 1; j < len; ++j) {
  ------------------
  |  Branch (754:25): [True: 0, False: 42.3k]
  ------------------
  755|      0|                cond |= f.v[j];
  756|      0|            }
  757|       |            /* If so, we're done. When f=1, the Jacobi symbol (g | f)=1. */
  758|  42.3k|            if (cond == 0) return 1 - 2*(jac & 1);
  ------------------
  |  Branch (758:17): [True: 42.3k, False: 0]
  ------------------
  759|  42.3k|        }
  760|       |
  761|       |        /* Determine if len>1 and limb (len-1) of both f and g is 0. */
  762|   493k|        fn = f.v[len - 1];
  763|   493k|        gn = g.v[len - 1];
  764|   493k|        cond = ((int64_t)len - 2) >> 63;
  765|   493k|        cond |= fn;
  766|   493k|        cond |= gn;
  767|       |        /* If so, reduce length. */
  768|   493k|        if (cond == 0) --len;
  ------------------
  |  Branch (768:13): [True: 169k, False: 324k]
  ------------------
  769|       |
  770|   493k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 0) > 0); /* f > 0 */
  771|   493k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  772|   493k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 0) > 0); /* g > 0 */
  773|   493k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 1) < 0);  /* g < modulus */
  774|   493k|    }
  775|       |
  776|       |    /* The loop failed to converge to f=g after 1550 iterations. Return 0, indicating unknown result. */
  777|      0|    return 0;
  778|  42.3k|}
secp256k1.c:secp256k1_modinv64_posdivsteps_62_var:
  325|   536k|static int64_t secp256k1_modinv64_posdivsteps_62_var(int64_t eta, uint64_t f0, uint64_t g0, secp256k1_modinv64_trans2x2 *t, int *jacp) {
  326|       |    /* Transformation matrix; see comments in secp256k1_modinv64_divsteps_62. */
  327|   536k|    uint64_t u = 1, v = 0, q = 0, r = 1;
  328|   536k|    uint64_t f = f0, g = g0, m;
  329|   536k|    uint32_t w;
  330|   536k|    int i = 62, limit, zeros;
  331|   536k|    int jac = *jacp;
  332|       |
  333|  9.42M|    for (;;) {
  334|       |        /* Use a sentinel bit to count zeros only up to i. */
  335|  9.42M|        zeros = secp256k1_ctz64_var(g | (UINT64_MAX << i));
  336|       |        /* Perform zeros divsteps at once; they all just divide g by two. */
  337|  9.42M|        g >>= zeros;
  338|  9.42M|        u <<= zeros;
  339|  9.42M|        v <<= zeros;
  340|  9.42M|        eta -= zeros;
  341|  9.42M|        i -= zeros;
  342|       |        /* Update the bottom bit of jac: when dividing g by an odd power of 2,
  343|       |         * if (f mod 8) is 3 or 5, the Jacobi symbol changes sign. */
  344|  9.42M|        jac ^= (zeros & ((f >> 1) ^ (f >> 2)));
  345|       |        /* We're done once we've done 62 posdivsteps. */
  346|  9.42M|        if (i == 0) break;
  ------------------
  |  Branch (346:13): [True: 536k, False: 8.88M]
  ------------------
  347|  8.88M|        VERIFY_CHECK((f & 1) == 1);
  348|  8.88M|        VERIFY_CHECK((g & 1) == 1);
  349|  8.88M|        VERIFY_CHECK((u * f0 + v * g0) == f << (62 - i));
  350|  8.88M|        VERIFY_CHECK((q * f0 + r * g0) == g << (62 - i));
  351|       |        /* If eta is negative, negate it and replace f,g with g,f. */
  352|  8.88M|        if (eta < 0) {
  ------------------
  |  Branch (352:13): [True: 8.59M, False: 293k]
  ------------------
  353|  8.59M|            uint64_t tmp;
  354|  8.59M|            eta = -eta;
  355|  8.59M|            tmp = f; f = g; g = tmp;
  356|  8.59M|            tmp = u; u = q; q = tmp;
  357|  8.59M|            tmp = v; v = r; r = tmp;
  358|       |            /* Update bottom bit of jac: when swapping f and g, the Jacobi symbol changes sign
  359|       |             * if both f and g are 3 mod 4. */
  360|  8.59M|            jac ^= ((f & g) >> 1);
  361|       |            /* Use a formula to cancel out up to 6 bits of g. Also, no more than i can be cancelled
  362|       |             * out (as we'd be done before that point), and no more than eta+1 can be done as its
  363|       |             * sign will flip again once that happens. */
  364|  8.59M|            limit = ((int)eta + 1) > i ? i : ((int)eta + 1);
  ------------------
  |  Branch (364:21): [True: 165k, False: 8.42M]
  ------------------
  365|  8.59M|            VERIFY_CHECK(limit > 0 && limit <= 62);
  366|       |            /* m is a mask for the bottom min(limit, 6) bits. */
  367|  8.59M|            m = (UINT64_MAX >> (64 - limit)) & 63U;
  368|       |            /* Find what multiple of f must be added to g to cancel its bottom min(limit, 6)
  369|       |             * bits. */
  370|  8.59M|            w = (f * g * (f * f - 2)) & m;
  371|  8.59M|        } else {
  372|       |            /* In this branch, use a simpler formula that only lets us cancel up to 4 bits of g, as
  373|       |             * eta tends to be smaller here. */
  374|   293k|            limit = ((int)eta + 1) > i ? i : ((int)eta + 1);
  ------------------
  |  Branch (374:21): [True: 2.27k, False: 291k]
  ------------------
  375|   293k|            VERIFY_CHECK(limit > 0 && limit <= 62);
  376|       |            /* m is a mask for the bottom min(limit, 4) bits. */
  377|   293k|            m = (UINT64_MAX >> (64 - limit)) & 15U;
  378|       |            /* Find what multiple of f must be added to g to cancel its bottom min(limit, 4)
  379|       |             * bits. */
  380|   293k|            w = f + (((f + 1) & 4) << 1);
  381|   293k|            w = (-w * g) & m;
  382|   293k|        }
  383|  8.88M|        g += f * w;
  384|  8.88M|        q += u * w;
  385|  8.88M|        r += v * w;
  386|  8.88M|        VERIFY_CHECK((g & m) == 0);
  387|  8.88M|    }
  388|       |    /* Return data in t and return value. */
  389|   536k|    t->u = (int64_t)u;
  390|   536k|    t->v = (int64_t)v;
  391|   536k|    t->q = (int64_t)q;
  392|   536k|    t->r = (int64_t)r;
  393|       |
  394|       |    /* The determinant of t must be a power of two. This guarantees that multiplication with t
  395|       |     * does not change the gcd of f and g, apart from adding a power-of-2 factor to it (which
  396|       |     * will be divided out again). As each divstep's individual matrix has determinant 2 or -2,
  397|       |     * the aggregate of 62 of them will have determinant 2^62 or -2^62. */
  398|   536k|    VERIFY_CHECK(secp256k1_modinv64_det_check_pow2(t, 62, 1));
  399|       |
  400|   536k|    *jacp = jac;
  401|   536k|    return eta;
  402|   536k|}

secp256k1_ellswift_create:
  431|  5.14k|int secp256k1_ellswift_create(const secp256k1_context *ctx, unsigned char *ell64, const unsigned char *seckey32, const unsigned char *auxrnd32) {
  432|  5.14k|    secp256k1_ge p;
  433|  5.14k|    secp256k1_fe t;
  434|  5.14k|    secp256k1_sha256 hash;
  435|  5.14k|    secp256k1_scalar seckey_scalar;
  436|  5.14k|    int ret;
  437|  5.14k|    static const unsigned char zero32[32] = {0};
  438|       |
  439|       |    /* Sanity check inputs. */
  440|  5.14k|    VERIFY_CHECK(ctx != NULL);
  441|  5.14k|    ARG_CHECK(ell64 != NULL);
  ------------------
  |  |   45|  5.14k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.14k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.14k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.14k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.14k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.14k]
  |  |  ------------------
  ------------------
  442|  5.14k|    memset(ell64, 0, 64);
  443|  5.14k|    ARG_CHECK(secp256k1_ecmult_gen_context_is_built(&ctx->ecmult_gen_ctx));
  ------------------
  |  |   45|  5.14k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.14k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.14k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.14k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.14k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.14k]
  |  |  ------------------
  ------------------
  444|  5.14k|    ARG_CHECK(seckey32 != NULL);
  ------------------
  |  |   45|  5.14k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.14k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.14k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.14k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.14k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.14k]
  |  |  ------------------
  ------------------
  445|       |
  446|       |    /* Compute (affine) public key */
  447|  5.14k|    ret = secp256k1_ec_pubkey_create_helper(&ctx->ecmult_gen_ctx, &seckey_scalar, &p, seckey32);
  448|  5.14k|    secp256k1_declassify(ctx, &p, sizeof(p)); /* not constant time in produced pubkey */
  449|  5.14k|    secp256k1_fe_normalize_var(&p.x);
  ------------------
  |  |   80|  5.14k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  450|  5.14k|    secp256k1_fe_normalize_var(&p.y);
  ------------------
  |  |   80|  5.14k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  451|       |
  452|       |    /* Set up hasher state. The used RNG is H(seckey32 || "\x00"*32 [|| auxrnd32] || cnt++),
  453|       |     * using BIP340 tagged hash with tag "secp256k1_ellswift_create". */
  454|  5.14k|    secp256k1_ellswift_sha256_init_create(&hash);
  455|  5.14k|    secp256k1_sha256_write(secp256k1_get_hash_context(ctx), &hash, seckey32, 32);
  456|  5.14k|    secp256k1_sha256_write(secp256k1_get_hash_context(ctx), &hash, zero32, sizeof(zero32));
  457|       |    /* Declassify only hash state. seckey32 has been hashed, but copy remains in the hash buffer */
  458|  5.14k|    secp256k1_declassify(ctx, &hash.s, sizeof(hash.s));
  459|  5.14k|    if (auxrnd32) secp256k1_sha256_write(secp256k1_get_hash_context(ctx), &hash, auxrnd32, 32);
  ------------------
  |  Branch (459:9): [True: 5.14k, False: 0]
  ------------------
  460|       |
  461|       |    /* Compute ElligatorSwift encoding and construct output. */
  462|  5.14k|    secp256k1_ellswift_elligatorswift_var(ctx, ell64, &t, &p, &hash); /* puts u in ell64[0..32] */
  463|  5.14k|    secp256k1_fe_get_b32(ell64 + 32, &t); /* puts t in ell64[32..64] */
  ------------------
  |  |   89|  5.14k|#  define secp256k1_fe_get_b32 secp256k1_fe_impl_get_b32
  ------------------
  464|       |
  465|  5.14k|    secp256k1_memczero(ell64, 64, !ret);
  466|  5.14k|    secp256k1_scalar_clear(&seckey_scalar);
  467|  5.14k|    secp256k1_sha256_clear(&hash);
  468|       |
  469|  5.14k|    return ret;
  470|  5.14k|}
secp256k1_ellswift_xdh:
  536|  5.26k|int secp256k1_ellswift_xdh(const secp256k1_context *ctx, unsigned char *output, const unsigned char *ell_a64, const unsigned char *ell_b64, const unsigned char *seckey32, int party, secp256k1_ellswift_xdh_hash_function hashfp, void *data) {
  537|  5.26k|    int ret = 0;
  538|  5.26k|    int overflow;
  539|  5.26k|    secp256k1_scalar s;
  540|  5.26k|    secp256k1_fe xn, xd, px, u, t;
  541|  5.26k|    unsigned char sx[32];
  542|  5.26k|    const unsigned char* theirs64;
  543|       |
  544|  5.26k|    VERIFY_CHECK(ctx != NULL);
  545|  5.26k|    ARG_CHECK(output != NULL);
  ------------------
  |  |   45|  5.26k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.26k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.26k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.26k]
  |  |  ------------------
  ------------------
  546|  5.26k|    ARG_CHECK(ell_a64 != NULL);
  ------------------
  |  |   45|  5.26k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.26k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.26k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.26k]
  |  |  ------------------
  ------------------
  547|  5.26k|    ARG_CHECK(ell_b64 != NULL);
  ------------------
  |  |   45|  5.26k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.26k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.26k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.26k]
  |  |  ------------------
  ------------------
  548|  5.26k|    ARG_CHECK(seckey32 != NULL);
  ------------------
  |  |   45|  5.26k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.26k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.26k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.26k]
  |  |  ------------------
  ------------------
  549|  5.26k|    ARG_CHECK(hashfp != NULL);
  ------------------
  |  |   45|  5.26k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.26k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.26k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.26k]
  |  |  ------------------
  ------------------
  550|       |
  551|       |    /* Load remote public key (as fraction). */
  552|  5.26k|    theirs64 = party ? ell_a64 : ell_b64;
  ------------------
  |  Branch (552:16): [True: 1.84k, False: 3.42k]
  ------------------
  553|  5.26k|    secp256k1_fe_set_b32_mod(&u, theirs64);
  ------------------
  |  |   87|  5.26k|#  define secp256k1_fe_set_b32_mod secp256k1_fe_impl_set_b32_mod
  ------------------
  554|  5.26k|    secp256k1_fe_set_b32_mod(&t, theirs64 + 32);
  ------------------
  |  |   87|  5.26k|#  define secp256k1_fe_set_b32_mod secp256k1_fe_impl_set_b32_mod
  ------------------
  555|  5.26k|    secp256k1_ellswift_xswiftec_frac_var(&xn, &xd, &u, &t);
  556|       |
  557|       |    /* Load private key (using one if invalid). */
  558|  5.26k|    secp256k1_scalar_set_b32(&s, seckey32, &overflow);
  559|  5.26k|    overflow |= secp256k1_scalar_is_zero(&s);
  560|  5.26k|    secp256k1_scalar_cmov(&s, &secp256k1_scalar_one, overflow);
  561|       |
  562|       |    /* Compute shared X coordinate. */
  563|  5.26k|    secp256k1_ecmult_const_xonly(&px, &xn, &xd, &s, 1);
  564|  5.26k|    secp256k1_fe_normalize(&px);
  ------------------
  |  |   78|  5.26k|#  define secp256k1_fe_normalize secp256k1_fe_impl_normalize
  ------------------
  565|  5.26k|    secp256k1_fe_get_b32(sx, &px);
  ------------------
  |  |   89|  5.26k|#  define secp256k1_fe_get_b32 secp256k1_fe_impl_get_b32
  ------------------
  566|       |
  567|       |    /* Invoke hasher. Use ctx-aware function by default */
  568|  5.26k|    if (hashfp == secp256k1_ellswift_xdh_hash_function_bip324) {
  ------------------
  |  Branch (568:9): [True: 5.26k, False: 0]
  ------------------
  569|  5.26k|        ret = ellswift_xdh_hash_function_bip324_impl(secp256k1_get_hash_context(ctx), output, sx, ell_a64, ell_b64, data);
  570|  5.26k|    } else if (hashfp == secp256k1_ellswift_xdh_hash_function_prefix) {
  ------------------
  |  Branch (570:16): [True: 0, False: 0]
  ------------------
  571|      0|        ret = ellswift_xdh_hash_function_prefix_impl(secp256k1_get_hash_context(ctx), output, sx, ell_a64, ell_b64, data);
  572|      0|    } else {
  573|      0|        ret = hashfp(output, sx, ell_a64, ell_b64, data);
  574|      0|    }
  575|       |
  576|  5.26k|    secp256k1_memclear_explicit(sx, sizeof(sx));
  577|  5.26k|    secp256k1_fe_clear(&px);
  578|  5.26k|    secp256k1_scalar_clear(&s);
  579|       |
  580|  5.26k|    return !!ret & !overflow;
  581|  5.26k|}
secp256k1.c:secp256k1_ellswift_elligatorswift_var:
  375|  5.14k|static void secp256k1_ellswift_elligatorswift_var(const secp256k1_context *ctx, unsigned char *u32, secp256k1_fe *t, const secp256k1_ge *p, const secp256k1_sha256 *hasher) {
  376|  5.14k|    secp256k1_ellswift_xelligatorswift_var(ctx, u32, t, &p->x, hasher);
  377|  5.14k|    secp256k1_fe_normalize_var(t);
  ------------------
  |  |   80|  5.14k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  378|  5.14k|    if (secp256k1_fe_is_odd(t) != secp256k1_fe_is_odd(&p->y)) {
  ------------------
  |  |   85|  5.14k|#  define secp256k1_fe_is_odd secp256k1_fe_impl_is_odd
  ------------------
                  if (secp256k1_fe_is_odd(t) != secp256k1_fe_is_odd(&p->y)) {
  ------------------
  |  |   85|  5.14k|#  define secp256k1_fe_is_odd secp256k1_fe_impl_is_odd
  ------------------
  |  Branch (378:9): [True: 2.81k, False: 2.32k]
  ------------------
  379|  2.81k|        secp256k1_fe_negate(t, t, 1);
  ------------------
  |  |  211|  2.81k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  2.81k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  2.81k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 2.81k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  2.81k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 2.81k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  2.81k|    } \
  |  |  |  |   94|  2.81k|    stmt; \
  |  |  |  |   95|  2.81k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 2.81k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  380|  2.81k|        secp256k1_fe_normalize_var(t);
  ------------------
  |  |   80|  2.81k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  381|  2.81k|    }
  382|  5.14k|}
secp256k1.c:secp256k1_ellswift_xelligatorswift_var:
  333|  5.14k|static void secp256k1_ellswift_xelligatorswift_var(const secp256k1_context *ctx, unsigned char *u32, secp256k1_fe *t, const secp256k1_fe *x, const secp256k1_sha256 *hasher) {
  334|       |    /* Pool of 3-bit branch values. */
  335|  5.14k|    unsigned char branch_hash[32];
  336|       |    /* Number of 3-bit values in branch_hash left. */
  337|  5.14k|    int branches_left = 0;
  338|       |    /* Field elements u and branch values are extracted from RNG based on hasher for consecutive
  339|       |     * values of cnt. cnt==0 is first used to populate a pool of 64 4-bit branch values. The 64
  340|       |     * cnt values that follow are used to generate field elements u. cnt==65 (and multiples
  341|       |     * thereof) are used to repopulate the pool and start over, if that were ever necessary.
  342|       |     * On average, 4 iterations are needed. */
  343|  5.14k|    uint32_t cnt = 0;
  344|  23.1k|    while (1) {
  ------------------
  |  Branch (344:12): [True: 23.1k, Folded]
  ------------------
  345|  23.1k|        int branch;
  346|  23.1k|        secp256k1_fe u;
  347|       |        /* If the pool of branch values is empty, populate it. */
  348|  23.1k|        if (branches_left == 0) {
  ------------------
  |  Branch (348:13): [True: 5.16k, False: 17.9k]
  ------------------
  349|  5.16k|            secp256k1_ellswift_prng(secp256k1_get_hash_context(ctx), branch_hash, hasher, cnt++);
  350|  5.16k|            branches_left = 64;
  351|  5.16k|        }
  352|       |        /* Take a 3-bit branch value from the branch pool (top bit is discarded). */
  353|  23.1k|        --branches_left;
  354|  23.1k|        branch = (branch_hash[branches_left >> 1] >> ((branches_left & 1) << 2)) & 7;
  355|       |        /* Compute a new u value by hashing. */
  356|  23.1k|        secp256k1_ellswift_prng(secp256k1_get_hash_context(ctx), u32, hasher, cnt++);
  357|       |        /* overflow is not a problem (we prefer uniform u32 over uniform u). */
  358|  23.1k|        secp256k1_fe_set_b32_mod(&u, u32);
  ------------------
  |  |   87|  23.1k|#  define secp256k1_fe_set_b32_mod secp256k1_fe_impl_set_b32_mod
  ------------------
  359|       |        /* Since u is the output of a hash, it should practically never be 0. We could apply the
  360|       |         * u=0 to u=1 correction here too to deal with that case still, but it's such a low
  361|       |         * probability event that we do not bother. */
  362|  23.1k|        VERIFY_CHECK(!secp256k1_fe_normalizes_to_zero_var(&u));
  363|       |
  364|       |        /* Find a remainder t, and return it if found. */
  365|  23.1k|        if (EXPECT(secp256k1_ellswift_xswiftec_inv_var(t, x, &u, branch), 0)) break;
  ------------------
  |  |  146|  23.1k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 5.14k, False: 17.9k]
  |  |  ------------------
  ------------------
  366|  23.1k|    }
  367|  5.14k|}
secp256k1.c:secp256k1_ellswift_prng:
  310|  28.3k|static void secp256k1_ellswift_prng(const secp256k1_hash_ctx *hash_ctx, unsigned char* out32, const secp256k1_sha256 *hasher, uint32_t cnt) {
  311|  28.3k|    secp256k1_sha256 hash = *hasher;
  312|  28.3k|    unsigned char buf4[4];
  313|       |#ifdef VERIFY
  314|       |    size_t blocks = hash.bytes >> 6;
  315|       |#endif
  316|  28.3k|    buf4[0] = cnt;
  317|  28.3k|    buf4[1] = cnt >> 8;
  318|  28.3k|    buf4[2] = cnt >> 16;
  319|  28.3k|    buf4[3] = cnt >> 24;
  320|  28.3k|    secp256k1_sha256_write(hash_ctx, &hash, buf4, 4);
  321|  28.3k|    secp256k1_sha256_finalize(hash_ctx, &hash, out32);
  322|       |
  323|       |    /* Writing and finalizing together should trigger exactly one SHA256 compression. */
  324|  28.3k|    VERIFY_CHECK(((hash.bytes) >> 6) == (blocks + 1));
  325|  28.3k|}
secp256k1.c:secp256k1_ellswift_xswiftec_inv_var:
  168|  23.1k|static int secp256k1_ellswift_xswiftec_inv_var(secp256k1_fe *t, const secp256k1_fe *x_in, const secp256k1_fe *u_in, int c) {
  169|       |    /* The implemented algorithm is this (all arithmetic, except involving c, is mod p):
  170|       |     *
  171|       |     * - If (c & 2) = 0:
  172|       |     *   - If (-x-u) is a valid X coordinate, fail.
  173|       |     *   - Let s=-(u^3+7)/(u^2+u*x+x^2).
  174|       |     *   - If s is not square, fail.
  175|       |     *   - Let v=x.
  176|       |     * - If (c & 2) = 2:
  177|       |     *   - Let s=x-u.
  178|       |     *   - If s is not square, fail.
  179|       |     *   - Let r=sqrt(-s*(4*(u^3+7)+3*u^2*s)); fail if it doesn't exist.
  180|       |     *   - If (c & 1) = 1 and r = 0, fail.
  181|       |     *   - If s=0, fail.
  182|       |     *   - Let v=(r/s-u)/2.
  183|       |     * - Let w=sqrt(s).
  184|       |     * - If (c & 5) = 0: return -w*(c3*u + v).
  185|       |     * - If (c & 5) = 1: return  w*(c4*u + v).
  186|       |     * - If (c & 5) = 4: return  w*(c3*u + v).
  187|       |     * - If (c & 5) = 5: return -w*(c4*u + v).
  188|       |     */
  189|  23.1k|    secp256k1_fe x = *x_in, u = *u_in, g, v, s, m, r, q;
  190|  23.1k|    int ret;
  191|       |
  192|  23.1k|    secp256k1_fe_normalize_weak(&x);
  ------------------
  |  |   79|  23.1k|#  define secp256k1_fe_normalize_weak secp256k1_fe_impl_normalize_weak
  ------------------
  193|  23.1k|    secp256k1_fe_normalize_weak(&u);
  ------------------
  |  |   79|  23.1k|#  define secp256k1_fe_normalize_weak secp256k1_fe_impl_normalize_weak
  ------------------
  194|       |
  195|  23.1k|    VERIFY_CHECK(c >= 0 && c < 8);
  196|  23.1k|    VERIFY_CHECK(secp256k1_ge_x_on_curve_var(&x));
  197|       |
  198|  23.1k|    if (!(c & 2)) {
  ------------------
  |  Branch (198:9): [True: 11.3k, False: 11.8k]
  ------------------
  199|       |        /* c is in {0, 1, 4, 5}. In this case we look for an inverse under the x1 (if c=0 or
  200|       |         * c=4) formula, or x2 (if c=1 or c=5) formula. */
  201|       |
  202|       |        /* If -u-x is a valid X coordinate, fail. This would yield an encoding that roundtrips
  203|       |         * back under the x3 formula instead (which has priority over x1 and x2, so the decoding
  204|       |         * would not match x). */
  205|  11.3k|        m = x;                                          /* m = x */
  206|  11.3k|        secp256k1_fe_add(&m, &u);                       /* m = u+x */
  ------------------
  |  |   92|  11.3k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  207|  11.3k|        secp256k1_fe_negate(&m, &m, 2);                 /* m = -u-x */
  ------------------
  |  |  211|  11.3k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  11.3k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  11.3k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 11.3k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  11.3k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 11.3k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  11.3k|    } \
  |  |  |  |   94|  11.3k|    stmt; \
  |  |  |  |   95|  11.3k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 11.3k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  208|       |        /* Test if (-u-x) is a valid X coordinate. If so, fail. */
  209|  11.3k|        if (secp256k1_ge_x_on_curve_var(&m)) return 0;
  ------------------
  |  Branch (209:13): [True: 5.78k, False: 5.53k]
  ------------------
  210|       |
  211|       |        /* Let s = -(u^3 + 7)/(u^2 + u*x + x^2) [first part] */
  212|  5.53k|        secp256k1_fe_sqr(&s, &m);                       /* s = (u+x)^2 */
  ------------------
  |  |   94|  5.53k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  213|  5.53k|        secp256k1_fe_negate(&s, &s, 1);                 /* s = -(u+x)^2 */
  ------------------
  |  |  211|  5.53k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  5.53k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  5.53k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 5.53k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  5.53k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 5.53k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  5.53k|    } \
  |  |  |  |   94|  5.53k|    stmt; \
  |  |  |  |   95|  5.53k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 5.53k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  214|  5.53k|        secp256k1_fe_mul(&m, &u, &x);                   /* m = u*x */
  ------------------
  |  |   93|  5.53k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  215|  5.53k|        secp256k1_fe_add(&s, &m);                       /* s = -(u^2 + u*x + x^2) */
  ------------------
  |  |   92|  5.53k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  216|       |
  217|       |        /* Note that at this point, s = 0 is impossible. If it were the case:
  218|       |         *             s = -(u^2 + u*x + x^2) = 0
  219|       |         * =>                 u^2 + u*x + x^2 = 0
  220|       |         * =>   (u + 2*x) * (u^2 + u*x + x^2) = 0
  221|       |         * => 2*x^3 + 3*x^2*u + 3*x*u^2 + u^3 = 0
  222|       |         * =>                 (x + u)^3 + x^3 = 0
  223|       |         * =>                             x^3 = -(x + u)^3
  224|       |         * =>                         x^3 + B = (-u - x)^3 + B
  225|       |         *
  226|       |         * However, we know x^3 + B is square (because x is on the curve) and
  227|       |         * that (-u-x)^3 + B is not square (the secp256k1_ge_x_on_curve_var(&m)
  228|       |         * test above would have failed). This is a contradiction, and thus the
  229|       |         * assumption s=0 is false. */
  230|  5.53k|        VERIFY_CHECK(!secp256k1_fe_normalizes_to_zero_var(&s));
  231|       |
  232|       |        /* If s is not square, fail. We have not fully computed s yet, but s is square iff
  233|       |         * -(u^3+7)*(u^2+u*x+x^2) is square (because a/b is square iff a*b is square and b is
  234|       |         * nonzero). */
  235|  5.53k|        secp256k1_fe_sqr(&g, &u);                       /* g = u^2 */
  ------------------
  |  |   94|  5.53k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  236|  5.53k|        secp256k1_fe_mul(&g, &g, &u);                   /* g = u^3 */
  ------------------
  |  |   93|  5.53k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  237|  5.53k|        secp256k1_fe_add_int(&g, SECP256K1_B);          /* g = u^3+7 */
  ------------------
  |  |  102|  5.53k|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                      secp256k1_fe_add_int(&g, SECP256K1_B);          /* g = u^3+7 */
  ------------------
  |  |   73|  5.53k|#define SECP256K1_B 7
  ------------------
  238|  5.53k|        secp256k1_fe_mul(&m, &s, &g);                   /* m = -(u^3 + 7)*(u^2 + u*x + x^2) */
  ------------------
  |  |   93|  5.53k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  239|  5.53k|        if (!secp256k1_fe_is_square_var(&m)) return 0;
  ------------------
  |  |  103|  5.53k|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  |  Branch (239:13): [True: 3.39k, False: 2.13k]
  ------------------
  240|       |
  241|       |        /* Let s = -(u^3 + 7)/(u^2 + u*x + x^2) [second part] */
  242|  2.13k|        secp256k1_fe_inv_var(&s, &s);                   /* s = -1/(u^2 + u*x + x^2) [no div by 0] */
  ------------------
  |  |   99|  2.13k|#  define secp256k1_fe_inv_var secp256k1_fe_impl_inv_var
  ------------------
  243|  2.13k|        secp256k1_fe_mul(&s, &s, &g);                   /* s = -(u^3 + 7)/(u^2 + u*x + x^2) */
  ------------------
  |  |   93|  2.13k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  244|       |
  245|       |        /* Let v = x. */
  246|  2.13k|        v = x;
  247|  11.8k|    } else {
  248|       |        /* c is in {2, 3, 6, 7}. In this case we look for an inverse under the x3 formula. */
  249|       |
  250|       |        /* Let s = x-u. */
  251|  11.8k|        secp256k1_fe_negate(&m, &u, 1);                 /* m = -u */
  ------------------
  |  |  211|  11.8k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  11.8k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  11.8k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 11.8k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  11.8k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 11.8k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  11.8k|    } \
  |  |  |  |   94|  11.8k|    stmt; \
  |  |  |  |   95|  11.8k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 11.8k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  252|  11.8k|        s = m;                                          /* s = -u */
  253|  11.8k|        secp256k1_fe_add(&s, &x);                       /* s = x-u */
  ------------------
  |  |   92|  11.8k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  254|       |
  255|       |        /* If s is not square, fail. */
  256|  11.8k|        if (!secp256k1_fe_is_square_var(&s)) return 0;
  ------------------
  |  |  103|  11.8k|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  |  Branch (256:13): [True: 5.60k, False: 6.21k]
  ------------------
  257|       |
  258|       |        /* Let r = sqrt(-s*(4*(u^3+7)+3*u^2*s)); fail if it doesn't exist. */
  259|  6.21k|        secp256k1_fe_sqr(&g, &u);                       /* g = u^2 */
  ------------------
  |  |   94|  6.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  260|  6.21k|        secp256k1_fe_mul(&q, &s, &g);                   /* q = s*u^2 */
  ------------------
  |  |   93|  6.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  261|  6.21k|        secp256k1_fe_mul_int(&q, 3);                    /* q = 3*s*u^2 */
  ------------------
  |  |  233|  6.21k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|  6.21k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  6.21k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 6.21k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  6.21k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 6.21k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  6.21k|    } \
  |  |  |  |   94|  6.21k|    stmt; \
  |  |  |  |   95|  6.21k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 6.21k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  262|  6.21k|        secp256k1_fe_mul(&g, &g, &u);                   /* g = u^3 */
  ------------------
  |  |   93|  6.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  263|  6.21k|        secp256k1_fe_mul_int(&g, 4);                    /* g = 4*u^3 */
  ------------------
  |  |  233|  6.21k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|  6.21k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  6.21k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 6.21k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  6.21k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 6.21k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  6.21k|    } \
  |  |  |  |   94|  6.21k|    stmt; \
  |  |  |  |   95|  6.21k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 6.21k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  264|  6.21k|        secp256k1_fe_add_int(&g, 4 * SECP256K1_B);      /* g = 4*(u^3+7) */
  ------------------
  |  |  102|  6.21k|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                      secp256k1_fe_add_int(&g, 4 * SECP256K1_B);      /* g = 4*(u^3+7) */
  ------------------
  |  |   73|  6.21k|#define SECP256K1_B 7
  ------------------
  265|  6.21k|        secp256k1_fe_add(&q, &g);                       /* q = 4*(u^3+7)+3*s*u^2 */
  ------------------
  |  |   92|  6.21k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  266|  6.21k|        secp256k1_fe_mul(&q, &q, &s);                   /* q = s*(4*(u^3+7)+3*u^2*s) */
  ------------------
  |  |   93|  6.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  267|  6.21k|        secp256k1_fe_negate(&q, &q, 1);                 /* q = -s*(4*(u^3+7)+3*u^2*s) */
  ------------------
  |  |  211|  6.21k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  6.21k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  6.21k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 6.21k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  6.21k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 6.21k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  6.21k|    } \
  |  |  |  |   94|  6.21k|    stmt; \
  |  |  |  |   95|  6.21k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 6.21k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  268|  6.21k|        if (!secp256k1_fe_is_square_var(&q)) return 0;
  ------------------
  |  |  103|  6.21k|#  define secp256k1_fe_is_square_var secp256k1_fe_impl_is_square_var
  ------------------
  |  Branch (268:13): [True: 3.20k, False: 3.01k]
  ------------------
  269|  3.01k|        ret = secp256k1_fe_sqrt(&r, &q);                /* r = sqrt(-s*(4*(u^3+7)+3*u^2*s)) */
  270|       |#ifdef VERIFY
  271|       |        VERIFY_CHECK(ret);
  272|       |#else
  273|  3.01k|        (void)ret;
  274|  3.01k|#endif
  275|       |
  276|       |        /* If (c & 1) = 1 and r = 0, fail. */
  277|  3.01k|        if (EXPECT((c & 1) && secp256k1_fe_normalizes_to_zero_var(&r), 0)) return 0;
  ------------------
  |  |  146|  4.81k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 0, False: 3.01k]
  |  |  |  Branch (146:39): [True: 1.80k, False: 1.20k]
  |  |  |  Branch (146:39): [True: 0, False: 1.80k]
  |  |  ------------------
  ------------------
  278|       |
  279|       |        /* If s = 0, fail. */
  280|  3.01k|        if (EXPECT(secp256k1_fe_normalizes_to_zero_var(&s), 0)) return 0;
  ------------------
  |  |  146|  3.01k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 0, False: 3.01k]
  |  |  ------------------
  ------------------
  281|       |
  282|       |        /* Let v = (r/s-u)/2. */
  283|  3.01k|        secp256k1_fe_inv_var(&v, &s);                   /* v = 1/s [no div by 0] */
  ------------------
  |  |   99|  3.01k|#  define secp256k1_fe_inv_var secp256k1_fe_impl_inv_var
  ------------------
  284|  3.01k|        secp256k1_fe_mul(&v, &v, &r);                   /* v = r/s */
  ------------------
  |  |   93|  3.01k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  285|  3.01k|        secp256k1_fe_add(&v, &m);                       /* v = r/s-u */
  ------------------
  |  |   92|  3.01k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  286|  3.01k|        secp256k1_fe_half(&v);                          /* v = (r/s-u)/2 */
  ------------------
  |  |  101|  3.01k|#  define secp256k1_fe_half secp256k1_fe_impl_half
  ------------------
  287|  3.01k|    }
  288|       |
  289|       |    /* Let w = sqrt(s). */
  290|  5.14k|    ret = secp256k1_fe_sqrt(&m, &s);                    /* m = sqrt(s) = w */
  291|  5.14k|    VERIFY_CHECK(ret);
  292|       |
  293|       |    /* Return logic. */
  294|  5.14k|    if ((c & 5) == 0 || (c & 5) == 5) {
  ------------------
  |  Branch (294:9): [True: 1.18k, False: 3.95k]
  |  Branch (294:25): [True: 1.44k, False: 2.51k]
  ------------------
  295|  2.63k|        secp256k1_fe_negate(&m, &m, 1);                 /* m = -w */
  ------------------
  |  |  211|  2.63k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  2.63k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  2.63k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 2.63k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  2.63k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 2.63k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  2.63k|    } \
  |  |  |  |   94|  2.63k|    stmt; \
  |  |  |  |   95|  2.63k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 2.63k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  296|  2.63k|    }
  297|       |    /* Now m = {-w if c&5=0 or c&5=5; w otherwise}. */
  298|  5.14k|    secp256k1_fe_mul(&u, &u, c&1 ? &secp256k1_ellswift_c4 : &secp256k1_ellswift_c3);
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  |  Branch (298:30): [True: 2.88k, False: 2.26k]
  ------------------
  299|       |    /* u = {c4 if c&1=1; c3 otherwise}*u */
  300|  5.14k|    secp256k1_fe_add(&u, &v);                           /* u = {c4 if c&1=1; c3 otherwise}*u + v */
  ------------------
  |  |   92|  5.14k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  301|  5.14k|    secp256k1_fe_mul(t, &m, &u);
  ------------------
  |  |   93|  5.14k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  302|  5.14k|    return 1;
  303|  5.14k|}
secp256k1.c:secp256k1_ellswift_sha256_init_create:
  423|  5.14k|static void secp256k1_ellswift_sha256_init_create(secp256k1_sha256* hash) {
  424|  5.14k|    static const uint32_t midstate[8] = {
  425|  5.14k|        0xd29e1bf5ul, 0xf7025f42ul, 0x9b024773ul, 0x094cb7d5ul,
  426|  5.14k|        0xe59ed789ul, 0x03bc9786ul, 0x68335b35ul, 0x4e363b53ul
  427|  5.14k|    };
  428|  5.14k|    secp256k1_sha256_initialize_midstate(hash, 64, midstate);
  429|  5.14k|}
secp256k1.c:secp256k1_ellswift_xswiftec_frac_var:
   24|  5.26k|static void secp256k1_ellswift_xswiftec_frac_var(secp256k1_fe *xn, secp256k1_fe *xd, const secp256k1_fe *u, const secp256k1_fe *t) {
   25|       |    /* The implemented algorithm is the following (all operations in GF(p)):
   26|       |     *
   27|       |     * - Let c0 = sqrt(-3) = 0xa2d2ba93507f1df233770c2a797962cc61f6d15da14ecd47d8d27ae1cd5f852.
   28|       |     * - If u = 0, set u = 1.
   29|       |     * - If t = 0, set t = 1.
   30|       |     * - If u^3+7+t^2 = 0, set t = 2*t.
   31|       |     * - Let X = (u^3+7-t^2)/(2*t).
   32|       |     * - Let Y = (X+t)/(c0*u).
   33|       |     * - If x3 = u+4*Y^2 is a valid x coordinate, return it.
   34|       |     * - If x2 = (-X/Y-u)/2 is a valid x coordinate, return it.
   35|       |     * - Return x1 = (X/Y-u)/2 (which is now guaranteed to be a valid x coordinate).
   36|       |     *
   37|       |     * Introducing s=t^2, g=u^3+7, and simplifying x1=-(x2+u) we get:
   38|       |     *
   39|       |     * - Let c0 = ...
   40|       |     * - If u = 0, set u = 1.
   41|       |     * - If t = 0, set t = 1.
   42|       |     * - Let s = t^2
   43|       |     * - Let g = u^3+7
   44|       |     * - If g+s = 0, set t = 2*t, s = 4*s
   45|       |     * - Let X = (g-s)/(2*t).
   46|       |     * - Let Y = (X+t)/(c0*u) = (g+s)/(2*c0*t*u).
   47|       |     * - If x3 = u+4*Y^2 is a valid x coordinate, return it.
   48|       |     * - If x2 = (-X/Y-u)/2 is a valid x coordinate, return it.
   49|       |     * - Return x1 = -(x2+u).
   50|       |     *
   51|       |     * Now substitute Y^2 = -(g+s)^2/(12*s*u^2) and X/Y = c0*u*(g-s)/(g+s). This
   52|       |     * means X and Y do not need to be evaluated explicitly anymore.
   53|       |     *
   54|       |     * - ...
   55|       |     * - If g+s = 0, set s = 4*s.
   56|       |     * - If x3 = u-(g+s)^2/(3*s*u^2) is a valid x coordinate, return it.
   57|       |     * - If x2 = (-c0*u*(g-s)/(g+s)-u)/2 is a valid x coordinate, return it.
   58|       |     * - Return x1 = -(x2+u).
   59|       |     *
   60|       |     * Simplifying x2 using 2 additional constants:
   61|       |     *
   62|       |     * - Let c1 = (c0-1)/2 = 0x851695d49a83f8ef919bb86153cbcb16630fb68aed0a766a3ec693d68e6afa40.
   63|       |     * - Let c2 = (-c0-1)/2 = 0x7ae96a2b657c07106e64479eac3434e99cf0497512f58995c1396c28719501ee.
   64|       |     * - ...
   65|       |     * - If x2 = u*(c1*s+c2*g)/(g+s) is a valid x coordinate, return it.
   66|       |     * - ...
   67|       |     *
   68|       |     * Writing x3 as a fraction:
   69|       |     *
   70|       |     * - ...
   71|       |     * - If x3 = (3*s*u^3-(g+s)^2)/(3*s*u^2) ...
   72|       |     * - ...
   73|       |
   74|       |     * Overall, we get:
   75|       |     *
   76|       |     * - Let c1 = 0x851695d49a83f8ef919bb86153cbcb16630fb68aed0a766a3ec693d68e6afa40.
   77|       |     * - Let c2 = 0x7ae96a2b657c07106e64479eac3434e99cf0497512f58995c1396c28719501ee.
   78|       |     * - If u = 0, set u = 1.
   79|       |     * - If t = 0, set s = 1, else set s = t^2.
   80|       |     * - Let g = u^3+7.
   81|       |     * - If g+s = 0, set s = 4*s.
   82|       |     * - If x3 = (3*s*u^3-(g+s)^2)/(3*s*u^2) is a valid x coordinate, return it.
   83|       |     * - If x2 = u*(c1*s+c2*g)/(g+s) is a valid x coordinate, return it.
   84|       |     * - Return x1 = -(x2+u).
   85|       |     */
   86|  5.26k|    secp256k1_fe u1, s, g, p, d, n, l;
   87|  5.26k|    u1 = *u;
   88|  5.26k|    if (EXPECT(secp256k1_fe_normalizes_to_zero_var(&u1), 0)) u1 = secp256k1_fe_one;
  ------------------
  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  ------------------
  ------------------
   89|  5.26k|    secp256k1_fe_sqr(&s, t);
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   90|  5.26k|    if (EXPECT(secp256k1_fe_normalizes_to_zero_var(t), 0)) s = secp256k1_fe_one;
  ------------------
  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  ------------------
  ------------------
   91|  5.26k|    secp256k1_fe_sqr(&l, &u1);                                   /* l = u^2 */
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   92|  5.26k|    secp256k1_fe_mul(&g, &l, &u1);                               /* g = u^3 */
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   93|  5.26k|    secp256k1_fe_add_int(&g, SECP256K1_B);                       /* g = u^3 + 7 */
  ------------------
  |  |  102|  5.26k|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                  secp256k1_fe_add_int(&g, SECP256K1_B);                       /* g = u^3 + 7 */
  ------------------
  |  |   73|  5.26k|#define SECP256K1_B 7
  ------------------
   94|  5.26k|    p = g;                                                       /* p = g */
   95|  5.26k|    secp256k1_fe_add(&p, &s);                                    /* p = g+s */
  ------------------
  |  |   92|  5.26k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
   96|  5.26k|    if (EXPECT(secp256k1_fe_normalizes_to_zero_var(&p), 0)) {
  ------------------
  |  |  146|  5.26k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 0, False: 5.26k]
  |  |  ------------------
  ------------------
   97|      0|        secp256k1_fe_mul_int(&s, 4);
  ------------------
  |  |  233|      0|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|      0|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|      0|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|      0|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|      0|    } \
  |  |  |  |   94|      0|    stmt; \
  |  |  |  |   95|      0|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   98|       |        /* Recompute p = g+s */
   99|      0|        p = g;                                                   /* p = g */
  100|      0|        secp256k1_fe_add(&p, &s);                                /* p = g+s */
  ------------------
  |  |   92|      0|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  101|      0|    }
  102|  5.26k|    secp256k1_fe_mul(&d, &s, &l);                                /* d = s*u^2 */
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  103|  5.26k|    secp256k1_fe_mul_int(&d, 3);                                 /* d = 3*s*u^2 */
  ------------------
  |  |  233|  5.26k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|  5.26k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  5.26k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  5.26k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 5.26k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  5.26k|    } \
  |  |  |  |   94|  5.26k|    stmt; \
  |  |  |  |   95|  5.26k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  104|  5.26k|    secp256k1_fe_sqr(&l, &p);                                    /* l = (g+s)^2 */
  ------------------
  |  |   94|  5.26k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  105|  5.26k|    secp256k1_fe_negate(&l, &l, 1);                              /* l = -(g+s)^2 */
  ------------------
  |  |  211|  5.26k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  5.26k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  5.26k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 5.26k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  5.26k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 5.26k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  5.26k|    } \
  |  |  |  |   94|  5.26k|    stmt; \
  |  |  |  |   95|  5.26k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 5.26k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  106|  5.26k|    secp256k1_fe_mul(&n, &d, &u1);                               /* n = 3*s*u^3 */
  ------------------
  |  |   93|  5.26k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  107|  5.26k|    secp256k1_fe_add(&n, &l);                                    /* n = 3*s*u^3-(g+s)^2 */
  ------------------
  |  |   92|  5.26k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  108|  5.26k|    if (secp256k1_ge_x_frac_on_curve_var(&n, &d)) {
  ------------------
  |  Branch (108:9): [True: 3.04k, False: 2.21k]
  ------------------
  109|       |        /* Return x3 = n/d = (3*s*u^3-(g+s)^2)/(3*s*u^2) */
  110|  3.04k|        *xn = n;
  111|  3.04k|        *xd = d;
  112|  3.04k|        return;
  113|  3.04k|    }
  114|  2.21k|    *xd = p;
  115|  2.21k|    secp256k1_fe_mul(&l, &secp256k1_ellswift_c1, &s);            /* l = c1*s */
  ------------------
  |  |   93|  2.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  116|  2.21k|    secp256k1_fe_mul(&n, &secp256k1_ellswift_c2, &g);            /* n = c2*g */
  ------------------
  |  |   93|  2.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  117|  2.21k|    secp256k1_fe_add(&n, &l);                                    /* n = c1*s+c2*g */
  ------------------
  |  |   92|  2.21k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  118|  2.21k|    secp256k1_fe_mul(&n, &n, &u1);                               /* n = u*(c1*s+c2*g) */
  ------------------
  |  |   93|  2.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  119|       |    /* Possible optimization: in the invocation below, p^2 = (g+s)^2 is computed,
  120|       |     * which we already have computed above. This could be deduplicated. */
  121|  2.21k|    if (secp256k1_ge_x_frac_on_curve_var(&n, &p)) {
  ------------------
  |  Branch (121:9): [True: 1.11k, False: 1.09k]
  ------------------
  122|       |        /* Return x2 = n/p = u*(c1*s+c2*g)/(g+s) */
  123|  1.11k|        *xn = n;
  124|  1.11k|        return;
  125|  1.11k|    }
  126|  1.09k|    secp256k1_fe_mul(&l, &p, &u1);                               /* l = u*(g+s) */
  ------------------
  |  |   93|  1.09k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  127|  1.09k|    secp256k1_fe_add(&n, &l);                                    /* n = u*(c1*s+c2*g)+u*(g+s) */
  ------------------
  |  |   92|  1.09k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  128|  1.09k|    secp256k1_fe_negate(xn, &n, 2);                              /* n = -u*(c1*s+c2*g)-u*(g+s) */
  ------------------
  |  |  211|  1.09k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  1.09k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  1.09k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 1.09k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  1.09k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 1.09k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  1.09k|    } \
  |  |  |  |   94|  1.09k|    stmt; \
  |  |  |  |   95|  1.09k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 1.09k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  129|       |
  130|  1.09k|    VERIFY_CHECK(secp256k1_ge_x_frac_on_curve_var(xn, &p));
  131|       |    /* Return x3 = n/p = -(u*(c1*s+c2*g)/(g+s)+u) */
  132|  1.09k|}
secp256k1.c:ellswift_xdh_hash_function_bip324_impl:
  514|  5.26k|static int ellswift_xdh_hash_function_bip324_impl(const secp256k1_hash_ctx *hash_ctx, unsigned char* output, const unsigned char *x32, const unsigned char *ell_a64, const unsigned char *ell_b64, void *data) {
  515|  5.26k|    secp256k1_sha256 sha;
  516|       |
  517|  5.26k|    (void)data;
  518|       |
  519|  5.26k|    secp256k1_ellswift_sha256_init_bip324(&sha);
  520|  5.26k|    secp256k1_sha256_write(hash_ctx, &sha, ell_a64, 64);
  521|  5.26k|    secp256k1_sha256_write(hash_ctx, &sha, ell_b64, 64);
  522|  5.26k|    secp256k1_sha256_write(hash_ctx, &sha, x32, 32);
  523|  5.26k|    secp256k1_sha256_finalize(hash_ctx, &sha, output);
  524|  5.26k|    secp256k1_sha256_clear(&sha);
  525|       |
  526|  5.26k|    return 1;
  527|  5.26k|}
secp256k1.c:secp256k1_ellswift_sha256_init_bip324:
  506|  5.26k|static void secp256k1_ellswift_sha256_init_bip324(secp256k1_sha256* hash) {
  507|  5.26k|    static const uint32_t midstate[8] = {
  508|  5.26k|        0x8c12d730ul, 0x827bd392ul, 0x9e4fb2eeul, 0x207b373eul,
  509|  5.26k|        0x2292bd7aul, 0xaa5441bcul, 0x15c3779ful, 0xcfb52549ul
  510|  5.26k|    };
  511|  5.26k|    secp256k1_sha256_initialize_midstate(hash, 64, midstate);
  512|  5.26k|}

secp256k1.c:secp256k1_scalar_set_b32:
  147|  14.6k|static void secp256k1_scalar_set_b32(secp256k1_scalar *r, const unsigned char *b32, int *overflow) {
  148|  14.6k|    int over;
  149|  14.6k|    r->d[0] = secp256k1_read_be64(&b32[24]);
  150|  14.6k|    r->d[1] = secp256k1_read_be64(&b32[16]);
  151|  14.6k|    r->d[2] = secp256k1_read_be64(&b32[8]);
  152|  14.6k|    r->d[3] = secp256k1_read_be64(&b32[0]);
  153|  14.6k|    over = secp256k1_scalar_reduce(r, secp256k1_scalar_check_overflow(r));
  154|  14.6k|    if (overflow) {
  ------------------
  |  Branch (154:9): [True: 14.6k, False: 0]
  ------------------
  155|  14.6k|        *overflow = over;
  156|  14.6k|    }
  157|       |
  158|  14.6k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  14.6k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  159|  14.6k|}
secp256k1.c:secp256k1_scalar_reduce:
   76|  61.8k|SECP256K1_INLINE static int secp256k1_scalar_reduce(secp256k1_scalar *r, unsigned int overflow) {
   77|  61.8k|    secp256k1_uint128 t;
   78|  61.8k|    VERIFY_CHECK(overflow <= 1);
   79|       |
   80|  61.8k|    secp256k1_u128_from_u64(&t, r->d[0]);
   81|  61.8k|    secp256k1_u128_accum_u64(&t, overflow * SECP256K1_N_C_0);
  ------------------
  |  |   22|  61.8k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  61.8k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
   82|  61.8k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
   83|  61.8k|    secp256k1_u128_accum_u64(&t, r->d[1]);
   84|  61.8k|    secp256k1_u128_accum_u64(&t, overflow * SECP256K1_N_C_1);
  ------------------
  |  |   23|  61.8k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  61.8k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
   85|  61.8k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
   86|  61.8k|    secp256k1_u128_accum_u64(&t, r->d[2]);
   87|  61.8k|    secp256k1_u128_accum_u64(&t, overflow * SECP256K1_N_C_2);
  ------------------
  |  |   24|  61.8k|#define SECP256K1_N_C_2 (1)
  ------------------
   88|  61.8k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
   89|  61.8k|    secp256k1_u128_accum_u64(&t, r->d[3]);
   90|  61.8k|    r->d[3] = secp256k1_u128_to_u64(&t);
   91|       |
   92|  61.8k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  61.8k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   93|  61.8k|    return overflow;
   94|  61.8k|}
secp256k1.c:secp256k1_scalar_check_overflow:
   64|  61.8k|SECP256K1_INLINE static int secp256k1_scalar_check_overflow(const secp256k1_scalar *a) {
   65|  61.8k|    int yes = 0;
   66|  61.8k|    int no = 0;
   67|  61.8k|    no |= (a->d[3] < SECP256K1_N_3); /* No need for a > check. */
  ------------------
  |  |   19|  61.8k|#define SECP256K1_N_3 ((uint64_t)0xFFFFFFFFFFFFFFFFULL)
  ------------------
   68|  61.8k|    no |= (a->d[2] < SECP256K1_N_2);
  ------------------
  |  |   18|  61.8k|#define SECP256K1_N_2 ((uint64_t)0xFFFFFFFFFFFFFFFEULL)
  ------------------
   69|  61.8k|    yes |= (a->d[2] > SECP256K1_N_2) & ~no;
  ------------------
  |  |   18|  61.8k|#define SECP256K1_N_2 ((uint64_t)0xFFFFFFFFFFFFFFFEULL)
  ------------------
   70|  61.8k|    no |= (a->d[1] < SECP256K1_N_1);
  ------------------
  |  |   17|  61.8k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  ------------------
   71|  61.8k|    yes |= (a->d[1] > SECP256K1_N_1) & ~no;
  ------------------
  |  |   17|  61.8k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  ------------------
   72|  61.8k|    yes |= (a->d[0] >= SECP256K1_N_0) & ~no;
  ------------------
  |  |   16|  61.8k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  ------------------
   73|  61.8k|    return yes;
   74|  61.8k|}
secp256k1.c:secp256k1_scalar_negate:
  176|  5.26k|static void secp256k1_scalar_negate(secp256k1_scalar *r, const secp256k1_scalar *a) {
  177|  5.26k|    uint64_t nonzero = 0xFFFFFFFFFFFFFFFFULL * (secp256k1_scalar_is_zero(a) == 0);
  178|  5.26k|    secp256k1_uint128 t;
  179|  5.26k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  5.26k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  180|       |
  181|  5.26k|    secp256k1_u128_from_u64(&t, ~a->d[0]);
  182|  5.26k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_0 + 1);
  ------------------
  |  |   16|  5.26k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  ------------------
  183|  5.26k|    r->d[0] = secp256k1_u128_to_u64(&t) & nonzero; secp256k1_u128_rshift(&t, 64);
  184|  5.26k|    secp256k1_u128_accum_u64(&t, ~a->d[1]);
  185|  5.26k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_1);
  ------------------
  |  |   17|  5.26k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  ------------------
  186|  5.26k|    r->d[1] = secp256k1_u128_to_u64(&t) & nonzero; secp256k1_u128_rshift(&t, 64);
  187|  5.26k|    secp256k1_u128_accum_u64(&t, ~a->d[2]);
  188|  5.26k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_2);
  ------------------
  |  |   18|  5.26k|#define SECP256K1_N_2 ((uint64_t)0xFFFFFFFFFFFFFFFEULL)
  ------------------
  189|  5.26k|    r->d[2] = secp256k1_u128_to_u64(&t) & nonzero; secp256k1_u128_rshift(&t, 64);
  190|  5.26k|    secp256k1_u128_accum_u64(&t, ~a->d[3]);
  191|  5.26k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_3);
  ------------------
  |  |   19|  5.26k|#define SECP256K1_N_3 ((uint64_t)0xFFFFFFFFFFFFFFFFULL)
  ------------------
  192|  5.26k|    r->d[3] = secp256k1_u128_to_u64(&t) & nonzero;
  193|       |
  194|  5.26k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  5.26k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  195|  5.26k|}
secp256k1.c:secp256k1_scalar_cmov:
  915|  10.4k|static SECP256K1_INLINE void secp256k1_scalar_cmov(secp256k1_scalar *r, const secp256k1_scalar *a, int flag) {
  916|  10.4k|    uint64_t mask0, mask1;
  917|  10.4k|    volatile int vflag = flag;
  918|  10.4k|    VERIFY_CHECK(flag == 0 || flag == 1);
  919|  10.4k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  10.4k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  920|  10.4k|    SECP256K1_CHECKMEM_CHECK_VERIFY(r->d, sizeof(r->d));
  ------------------
  |  |  114|  10.4k|#define SECP256K1_CHECKMEM_CHECK_VERIFY(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  10.4k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 10.4k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  921|       |
  922|  10.4k|    mask0 = vflag + ~((uint64_t)0);
  923|  10.4k|    mask1 = ~mask0;
  924|  10.4k|    r->d[0] = (r->d[0] & mask0) | (a->d[0] & mask1);
  925|  10.4k|    r->d[1] = (r->d[1] & mask0) | (a->d[1] & mask1);
  926|  10.4k|    r->d[2] = (r->d[2] & mask0) | (a->d[2] & mask1);
  927|  10.4k|    r->d[3] = (r->d[3] & mask0) | (a->d[3] & mask1);
  928|       |
  929|  10.4k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  10.4k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  930|  10.4k|}
secp256k1.c:secp256k1_scalar_half:
  197|  5.26k|static void secp256k1_scalar_half(secp256k1_scalar *r, const secp256k1_scalar *a) {
  198|       |    /* Writing `/` for field division and `//` for integer division, we compute
  199|       |     *
  200|       |     *   a/2 = (a - (a&1))/2 + (a&1)/2
  201|       |     *       = (a >> 1) + (a&1 ?    1/2 : 0)
  202|       |     *       = (a >> 1) + (a&1 ? n//2+1 : 0),
  203|       |     *
  204|       |     * where n is the group order and in the last equality we have used 1/2 = n//2+1 (mod n).
  205|       |     * For n//2, we have the constants SECP256K1_N_H_0, ...
  206|       |     *
  207|       |     * This sum does not overflow. The most extreme case is a = -2, the largest odd scalar. Here:
  208|       |     * - the left summand is:  a >> 1 = (a - a&1)/2 = (n-2-1)//2           = (n-3)//2
  209|       |     * - the right summand is: a&1 ? n//2+1 : 0 = n//2+1 = (n-1)//2 + 2//2 = (n+1)//2
  210|       |     * Together they sum to (n-3)//2 + (n+1)//2 = (2n-2)//2 = n - 1, which is less than n.
  211|       |     */
  212|  5.26k|    uint64_t mask = -(uint64_t)(a->d[0] & 1U);
  213|  5.26k|    secp256k1_uint128 t;
  214|  5.26k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  5.26k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  215|       |
  216|  5.26k|    secp256k1_u128_from_u64(&t, (a->d[0] >> 1) | (a->d[1] << 63));
  217|  5.26k|    secp256k1_u128_accum_u64(&t, (SECP256K1_N_H_0 + 1U) & mask);
  ------------------
  |  |   27|  5.26k|#define SECP256K1_N_H_0 ((uint64_t)0xDFE92F46681B20A0ULL)
  ------------------
  218|  5.26k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  219|  5.26k|    secp256k1_u128_accum_u64(&t, (a->d[1] >> 1) | (a->d[2] << 63));
  220|  5.26k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_H_1 & mask);
  ------------------
  |  |   28|  5.26k|#define SECP256K1_N_H_1 ((uint64_t)0x5D576E7357A4501DULL)
  ------------------
  221|  5.26k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  222|  5.26k|    secp256k1_u128_accum_u64(&t, (a->d[2] >> 1) | (a->d[3] << 63));
  223|  5.26k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_H_2 & mask);
  ------------------
  |  |   29|  5.26k|#define SECP256K1_N_H_2 ((uint64_t)0xFFFFFFFFFFFFFFFFULL)
  ------------------
  224|  5.26k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  225|  5.26k|    r->d[3] = secp256k1_u128_to_u64(&t) + (a->d[3] >> 1) + (SECP256K1_N_H_3 & mask);
  ------------------
  |  |   30|  5.26k|#define SECP256K1_N_H_3 ((uint64_t)0x7FFFFFFFFFFFFFFFULL)
  ------------------
  226|       |#ifdef VERIFY
  227|       |    /* The line above only computed the bottom 64 bits of r->d[3]; redo the computation
  228|       |     * in full 128 bits to make sure the top 64 bits are indeed zero. */
  229|       |    secp256k1_u128_accum_u64(&t, a->d[3] >> 1);
  230|       |    secp256k1_u128_accum_u64(&t, SECP256K1_N_H_3 & mask);
  231|       |    secp256k1_u128_rshift(&t, 64);
  232|       |    VERIFY_CHECK(secp256k1_u128_to_u64(&t) == 0);
  233|       |
  234|       |    SECP256K1_SCALAR_VERIFY(r);
  235|       |#endif
  236|  5.26k|}
secp256k1.c:secp256k1_scalar_mul_shift_var:
  893|  10.5k|SECP256K1_INLINE static void secp256k1_scalar_mul_shift_var(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b, unsigned int shift) {
  894|  10.5k|    uint64_t l[8];
  895|  10.5k|    unsigned int shiftlimbs;
  896|  10.5k|    unsigned int shiftlow;
  897|  10.5k|    unsigned int shifthigh;
  898|  10.5k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  10.5k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  899|  10.5k|    SECP256K1_SCALAR_VERIFY(b);
  ------------------
  |  |  103|  10.5k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  900|  10.5k|    VERIFY_CHECK(shift >= 256);
  901|       |
  902|  10.5k|    secp256k1_scalar_mul_512(l, a, b);
  903|  10.5k|    shiftlimbs = shift >> 6;
  904|  10.5k|    shiftlow = shift & 0x3F;
  905|  10.5k|    shifthigh = 64 - shiftlow;
  906|  10.5k|    r->d[0] = shift < 512 ? (l[0 + shiftlimbs] >> shiftlow | (shift < 448 && shiftlow ? (l[1 + shiftlimbs] << shifthigh) : 0)) : 0;
  ------------------
  |  Branch (906:15): [True: 10.5k, False: 0]
  |  Branch (906:63): [True: 10.5k, False: 0]
  |  Branch (906:78): [True: 0, False: 10.5k]
  ------------------
  907|  10.5k|    r->d[1] = shift < 448 ? (l[1 + shiftlimbs] >> shiftlow | (shift < 384 && shiftlow ? (l[2 + shiftlimbs] << shifthigh) : 0)) : 0;
  ------------------
  |  Branch (907:15): [True: 10.5k, False: 0]
  |  Branch (907:63): [True: 0, False: 10.5k]
  |  Branch (907:78): [True: 0, False: 0]
  ------------------
  908|  10.5k|    r->d[2] = shift < 384 ? (l[2 + shiftlimbs] >> shiftlow | (shift < 320 && shiftlow ? (l[3 + shiftlimbs] << shifthigh) : 0)) : 0;
  ------------------
  |  Branch (908:15): [True: 0, False: 10.5k]
  |  Branch (908:63): [True: 0, False: 0]
  |  Branch (908:78): [True: 0, False: 0]
  ------------------
  909|  10.5k|    r->d[3] = shift < 320 ? (l[3 + shiftlimbs] >> shiftlow) : 0;
  ------------------
  |  Branch (909:15): [True: 0, False: 10.5k]
  ------------------
  910|  10.5k|    secp256k1_scalar_cadd_bit(r, 0, (l[(shift - 1) >> 6] >> ((shift - 1) & 0x3f)) & 1);
  911|       |
  912|  10.5k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  10.5k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  913|  10.5k|}
secp256k1.c:secp256k1_scalar_mul_512:
  682|  26.3k|static void secp256k1_scalar_mul_512(uint64_t *l8, const secp256k1_scalar *a, const secp256k1_scalar *b) {
  683|  26.3k|#ifdef USE_ASM_X86_64
  684|  26.3k|    const uint64_t *pb = b->d;
  685|  26.3k|    __asm__ __volatile__(
  686|       |    /* Preload */
  687|  26.3k|    "movq 0(%%rdi), %%r15\n"
  688|  26.3k|    "movq 8(%%rdi), %%rbx\n"
  689|  26.3k|    "movq 16(%%rdi), %%rcx\n"
  690|  26.3k|    "movq 0(%%rdx), %%r11\n"
  691|  26.3k|    "movq 8(%%rdx), %%r12\n"
  692|  26.3k|    "movq 16(%%rdx), %%r13\n"
  693|  26.3k|    "movq 24(%%rdx), %%r14\n"
  694|       |    /* (rax,rdx) = a0 * b0 */
  695|  26.3k|    "movq %%r15, %%rax\n"
  696|  26.3k|    "mulq %%r11\n"
  697|       |    /* Extract l8[0] */
  698|  26.3k|    "movq %%rax, 0(%%rsi)\n"
  699|       |    /* (r8,r9,r10) = (rdx) */
  700|  26.3k|    "movq %%rdx, %%r8\n"
  701|  26.3k|    "xorq %%r9, %%r9\n"
  702|  26.3k|    "xorq %%r10, %%r10\n"
  703|       |    /* (r8,r9,r10) += a0 * b1 */
  704|  26.3k|    "movq %%r15, %%rax\n"
  705|  26.3k|    "mulq %%r12\n"
  706|  26.3k|    "addq %%rax, %%r8\n"
  707|  26.3k|    "adcq %%rdx, %%r9\n"
  708|  26.3k|    "adcq $0, %%r10\n"
  709|       |    /* (r8,r9,r10) += a1 * b0 */
  710|  26.3k|    "movq %%rbx, %%rax\n"
  711|  26.3k|    "mulq %%r11\n"
  712|  26.3k|    "addq %%rax, %%r8\n"
  713|  26.3k|    "adcq %%rdx, %%r9\n"
  714|  26.3k|    "adcq $0, %%r10\n"
  715|       |    /* Extract l8[1] */
  716|  26.3k|    "movq %%r8, 8(%%rsi)\n"
  717|  26.3k|    "xorq %%r8, %%r8\n"
  718|       |    /* (r9,r10,r8) += a0 * b2 */
  719|  26.3k|    "movq %%r15, %%rax\n"
  720|  26.3k|    "mulq %%r13\n"
  721|  26.3k|    "addq %%rax, %%r9\n"
  722|  26.3k|    "adcq %%rdx, %%r10\n"
  723|  26.3k|    "adcq $0, %%r8\n"
  724|       |    /* (r9,r10,r8) += a1 * b1 */
  725|  26.3k|    "movq %%rbx, %%rax\n"
  726|  26.3k|    "mulq %%r12\n"
  727|  26.3k|    "addq %%rax, %%r9\n"
  728|  26.3k|    "adcq %%rdx, %%r10\n"
  729|  26.3k|    "adcq $0, %%r8\n"
  730|       |    /* (r9,r10,r8) += a2 * b0 */
  731|  26.3k|    "movq %%rcx, %%rax\n"
  732|  26.3k|    "mulq %%r11\n"
  733|  26.3k|    "addq %%rax, %%r9\n"
  734|  26.3k|    "adcq %%rdx, %%r10\n"
  735|  26.3k|    "adcq $0, %%r8\n"
  736|       |    /* Extract l8[2] */
  737|  26.3k|    "movq %%r9, 16(%%rsi)\n"
  738|  26.3k|    "xorq %%r9, %%r9\n"
  739|       |    /* (r10,r8,r9) += a0 * b3 */
  740|  26.3k|    "movq %%r15, %%rax\n"
  741|  26.3k|    "mulq %%r14\n"
  742|  26.3k|    "addq %%rax, %%r10\n"
  743|  26.3k|    "adcq %%rdx, %%r8\n"
  744|  26.3k|    "adcq $0, %%r9\n"
  745|       |    /* Preload a3 */
  746|  26.3k|    "movq 24(%%rdi), %%r15\n"
  747|       |    /* (r10,r8,r9) += a1 * b2 */
  748|  26.3k|    "movq %%rbx, %%rax\n"
  749|  26.3k|    "mulq %%r13\n"
  750|  26.3k|    "addq %%rax, %%r10\n"
  751|  26.3k|    "adcq %%rdx, %%r8\n"
  752|  26.3k|    "adcq $0, %%r9\n"
  753|       |    /* (r10,r8,r9) += a2 * b1 */
  754|  26.3k|    "movq %%rcx, %%rax\n"
  755|  26.3k|    "mulq %%r12\n"
  756|  26.3k|    "addq %%rax, %%r10\n"
  757|  26.3k|    "adcq %%rdx, %%r8\n"
  758|  26.3k|    "adcq $0, %%r9\n"
  759|       |    /* (r10,r8,r9) += a3 * b0 */
  760|  26.3k|    "movq %%r15, %%rax\n"
  761|  26.3k|    "mulq %%r11\n"
  762|  26.3k|    "addq %%rax, %%r10\n"
  763|  26.3k|    "adcq %%rdx, %%r8\n"
  764|  26.3k|    "adcq $0, %%r9\n"
  765|       |    /* Extract l8[3] */
  766|  26.3k|    "movq %%r10, 24(%%rsi)\n"
  767|  26.3k|    "xorq %%r10, %%r10\n"
  768|       |    /* (r8,r9,r10) += a1 * b3 */
  769|  26.3k|    "movq %%rbx, %%rax\n"
  770|  26.3k|    "mulq %%r14\n"
  771|  26.3k|    "addq %%rax, %%r8\n"
  772|  26.3k|    "adcq %%rdx, %%r9\n"
  773|  26.3k|    "adcq $0, %%r10\n"
  774|       |    /* (r8,r9,r10) += a2 * b2 */
  775|  26.3k|    "movq %%rcx, %%rax\n"
  776|  26.3k|    "mulq %%r13\n"
  777|  26.3k|    "addq %%rax, %%r8\n"
  778|  26.3k|    "adcq %%rdx, %%r9\n"
  779|  26.3k|    "adcq $0, %%r10\n"
  780|       |    /* (r8,r9,r10) += a3 * b1 */
  781|  26.3k|    "movq %%r15, %%rax\n"
  782|  26.3k|    "mulq %%r12\n"
  783|  26.3k|    "addq %%rax, %%r8\n"
  784|  26.3k|    "adcq %%rdx, %%r9\n"
  785|  26.3k|    "adcq $0, %%r10\n"
  786|       |    /* Extract l8[4] */
  787|  26.3k|    "movq %%r8, 32(%%rsi)\n"
  788|  26.3k|    "xorq %%r8, %%r8\n"
  789|       |    /* (r9,r10,r8) += a2 * b3 */
  790|  26.3k|    "movq %%rcx, %%rax\n"
  791|  26.3k|    "mulq %%r14\n"
  792|  26.3k|    "addq %%rax, %%r9\n"
  793|  26.3k|    "adcq %%rdx, %%r10\n"
  794|  26.3k|    "adcq $0, %%r8\n"
  795|       |    /* (r9,r10,r8) += a3 * b2 */
  796|  26.3k|    "movq %%r15, %%rax\n"
  797|  26.3k|    "mulq %%r13\n"
  798|  26.3k|    "addq %%rax, %%r9\n"
  799|  26.3k|    "adcq %%rdx, %%r10\n"
  800|  26.3k|    "adcq $0, %%r8\n"
  801|       |    /* Extract l8[5] */
  802|  26.3k|    "movq %%r9, 40(%%rsi)\n"
  803|       |    /* (r10,r8) += a3 * b3 */
  804|  26.3k|    "movq %%r15, %%rax\n"
  805|  26.3k|    "mulq %%r14\n"
  806|  26.3k|    "addq %%rax, %%r10\n"
  807|  26.3k|    "adcq %%rdx, %%r8\n"
  808|       |    /* Extract l8[6] */
  809|  26.3k|    "movq %%r10, 48(%%rsi)\n"
  810|       |    /* Extract l8[7] */
  811|  26.3k|    "movq %%r8, 56(%%rsi)\n"
  812|  26.3k|    : "+d"(pb)
  813|  26.3k|    : "S"(l8), "D"(a->d)
  814|  26.3k|    : "rax", "rbx", "rcx", "r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15", "cc", "memory");
  815|       |
  816|  26.3k|    SECP256K1_CHECKMEM_MSAN_DEFINE(l8, sizeof(*l8) * 8);
  ------------------
  |  |   70|  26.3k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  26.3k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 26.3k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  817|       |
  818|       |#else
  819|       |    /* 160 bit accumulator. */
  820|       |    uint64_t c0 = 0, c1 = 0;
  821|       |    uint32_t c2 = 0;
  822|       |
  823|       |    /* l8[0..7] = a[0..3] * b[0..3]. */
  824|       |    muladd_fast(a->d[0], b->d[0]);
  825|       |    extract_fast(l8[0]);
  826|       |    muladd(a->d[0], b->d[1]);
  827|       |    muladd(a->d[1], b->d[0]);
  828|       |    extract(l8[1]);
  829|       |    muladd(a->d[0], b->d[2]);
  830|       |    muladd(a->d[1], b->d[1]);
  831|       |    muladd(a->d[2], b->d[0]);
  832|       |    extract(l8[2]);
  833|       |    muladd(a->d[0], b->d[3]);
  834|       |    muladd(a->d[1], b->d[2]);
  835|       |    muladd(a->d[2], b->d[1]);
  836|       |    muladd(a->d[3], b->d[0]);
  837|       |    extract(l8[3]);
  838|       |    muladd(a->d[1], b->d[3]);
  839|       |    muladd(a->d[2], b->d[2]);
  840|       |    muladd(a->d[3], b->d[1]);
  841|       |    extract(l8[4]);
  842|       |    muladd(a->d[2], b->d[3]);
  843|       |    muladd(a->d[3], b->d[2]);
  844|       |    extract(l8[5]);
  845|       |    muladd_fast(a->d[3], b->d[3]);
  846|       |    extract_fast(l8[6]);
  847|       |    VERIFY_CHECK(c1 == 0);
  848|       |    l8[7] = c0;
  849|       |#endif
  850|  26.3k|}
secp256k1.c:secp256k1_scalar_cadd_bit:
  122|  10.5k|static void secp256k1_scalar_cadd_bit(secp256k1_scalar *r, unsigned int bit, int flag) {
  123|  10.5k|    secp256k1_uint128 t;
  124|  10.5k|    volatile int vflag = flag;
  125|  10.5k|    VERIFY_CHECK(flag == 0 || flag == 1);
  126|  10.5k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  10.5k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  127|  10.5k|    VERIFY_CHECK(bit < 256);
  128|       |
  129|  10.5k|    bit += ((uint32_t) vflag - 1) & 0x100;  /* forcing (bit >> 6) > 3 makes this a noop */
  130|  10.5k|    secp256k1_u128_from_u64(&t, r->d[0]);
  131|  10.5k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 0)) << (bit & 0x3F));
  132|  10.5k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  133|  10.5k|    secp256k1_u128_accum_u64(&t, r->d[1]);
  134|  10.5k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 1)) << (bit & 0x3F));
  135|  10.5k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  136|  10.5k|    secp256k1_u128_accum_u64(&t, r->d[2]);
  137|  10.5k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 2)) << (bit & 0x3F));
  138|  10.5k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  139|  10.5k|    secp256k1_u128_accum_u64(&t, r->d[3]);
  140|  10.5k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 3)) << (bit & 0x3F));
  141|  10.5k|    r->d[3] = secp256k1_u128_to_u64(&t);
  142|       |
  143|  10.5k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  10.5k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  144|  10.5k|    VERIFY_CHECK(secp256k1_u128_hi_u64(&t) == 0);
  145|  10.5k|}
secp256k1.c:secp256k1_scalar_get_bits_limb32:
   41|  41.1k|SECP256K1_INLINE static uint32_t secp256k1_scalar_get_bits_limb32(const secp256k1_scalar *a, unsigned int offset, unsigned int count) {
   42|  41.1k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  41.1k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   43|  41.1k|    VERIFY_CHECK(count > 0 && count <= 32);
   44|  41.1k|    VERIFY_CHECK(offset <= 256 - count);
   45|  41.1k|    VERIFY_CHECK((offset + count - 1) >> 5 == offset >> 5);
   46|       |
   47|  41.1k|    return (a->d[offset >> 6] >> (offset & 0x3F)) & (0xFFFFFFFF >> (32 - count));
   48|  41.1k|}
secp256k1.c:secp256k1_scalar_get_bits_var:
   50|   273k|SECP256K1_INLINE static uint32_t secp256k1_scalar_get_bits_var(const secp256k1_scalar *a, unsigned int offset, unsigned int count) {
   51|   273k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|   273k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   52|   273k|    VERIFY_CHECK(count > 0 && count <= 32);
   53|   273k|    VERIFY_CHECK(offset <= 256 - count);
   54|       |
   55|   273k|    if ((offset + count - 1) >> 6 == offset >> 6) {
  ------------------
  |  Branch (55:9): [True: 252k, False: 21.0k]
  ------------------
   56|   252k|        return (a->d[offset >> 6] >> (offset & 0x3F)) & (0xFFFFFFFF >> (32 - count));
   57|   252k|    } else {
   58|  21.0k|        VERIFY_CHECK((offset >> 6) + 1 < 4);
   59|  21.0k|        VERIFY_CHECK((offset & 0x3F) > 0);
   60|  21.0k|        return ((a->d[offset >> 6] >> (offset & 0x3F)) | (a->d[(offset >> 6) + 1] << (64 - (offset & 0x3F)))) & (0xFFFFFFFF >> (32 - count));
   61|  21.0k|    }
   62|   273k|}
secp256k1.c:secp256k1_scalar_is_zero:
  170|  19.8k|SECP256K1_INLINE static int secp256k1_scalar_is_zero(const secp256k1_scalar *a) {
  171|  19.8k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  19.8k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  172|       |
  173|  19.8k|    return (a->d[0] | a->d[1] | a->d[2] | a->d[3]) == 0;
  174|  19.8k|}
secp256k1.c:secp256k1_scalar_mul:
  859|  15.7k|static void secp256k1_scalar_mul(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b) {
  860|  15.7k|    uint64_t l[8];
  861|  15.7k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  15.7k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  862|  15.7k|    SECP256K1_SCALAR_VERIFY(b);
  ------------------
  |  |  103|  15.7k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  863|       |
  864|  15.7k|    secp256k1_scalar_mul_512(l, a, b);
  865|  15.7k|    secp256k1_scalar_reduce_512(r, l);
  866|       |
  867|  15.7k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  15.7k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  868|  15.7k|}
secp256k1.c:secp256k1_scalar_reduce_512:
  351|  15.7k|static void secp256k1_scalar_reduce_512(secp256k1_scalar *r, const uint64_t *l) {
  352|  15.7k|#ifdef USE_ASM_X86_64
  353|       |    /* Reduce 512 bits into 385. */
  354|  15.7k|    uint64_t m0, m1, m2, m3, m4, m5, m6;
  355|  15.7k|    uint64_t p0, p1, p2, p3, p4;
  356|  15.7k|    uint64_t c;
  357|       |
  358|  15.7k|    __asm__ __volatile__(
  359|       |    /* Preload. */
  360|  15.7k|    "movq 32(%%rsi), %%r11\n"
  361|  15.7k|    "movq 40(%%rsi), %%r12\n"
  362|  15.7k|    "movq 48(%%rsi), %%r13\n"
  363|  15.7k|    "movq 56(%%rsi), %%r14\n"
  364|       |    /* Initialize r8,r9,r10 */
  365|  15.7k|    "movq 0(%%rsi), %%r8\n"
  366|  15.7k|    "xorq %%r9, %%r9\n"
  367|  15.7k|    "xorq %%r10, %%r10\n"
  368|       |    /* (r8,r9) += n0 * c0 */
  369|  15.7k|    "movq %8, %%rax\n"
  370|  15.7k|    "mulq %%r11\n"
  371|  15.7k|    "addq %%rax, %%r8\n"
  372|  15.7k|    "adcq %%rdx, %%r9\n"
  373|       |    /* extract m0 */
  374|  15.7k|    "movq %%r8, %q0\n"
  375|  15.7k|    "xorq %%r8, %%r8\n"
  376|       |    /* (r9,r10) += l1 */
  377|  15.7k|    "addq 8(%%rsi), %%r9\n"
  378|  15.7k|    "adcq $0, %%r10\n"
  379|       |    /* (r9,r10,r8) += n1 * c0 */
  380|  15.7k|    "movq %8, %%rax\n"
  381|  15.7k|    "mulq %%r12\n"
  382|  15.7k|    "addq %%rax, %%r9\n"
  383|  15.7k|    "adcq %%rdx, %%r10\n"
  384|  15.7k|    "adcq $0, %%r8\n"
  385|       |    /* (r9,r10,r8) += n0 * c1 */
  386|  15.7k|    "movq %9, %%rax\n"
  387|  15.7k|    "mulq %%r11\n"
  388|  15.7k|    "addq %%rax, %%r9\n"
  389|  15.7k|    "adcq %%rdx, %%r10\n"
  390|  15.7k|    "adcq $0, %%r8\n"
  391|       |    /* extract m1 */
  392|  15.7k|    "movq %%r9, %q1\n"
  393|  15.7k|    "xorq %%r9, %%r9\n"
  394|       |    /* (r10,r8,r9) += l2 */
  395|  15.7k|    "addq 16(%%rsi), %%r10\n"
  396|  15.7k|    "adcq $0, %%r8\n"
  397|  15.7k|    "adcq $0, %%r9\n"
  398|       |    /* (r10,r8,r9) += n2 * c0 */
  399|  15.7k|    "movq %8, %%rax\n"
  400|  15.7k|    "mulq %%r13\n"
  401|  15.7k|    "addq %%rax, %%r10\n"
  402|  15.7k|    "adcq %%rdx, %%r8\n"
  403|  15.7k|    "adcq $0, %%r9\n"
  404|       |    /* (r10,r8,r9) += n1 * c1 */
  405|  15.7k|    "movq %9, %%rax\n"
  406|  15.7k|    "mulq %%r12\n"
  407|  15.7k|    "addq %%rax, %%r10\n"
  408|  15.7k|    "adcq %%rdx, %%r8\n"
  409|  15.7k|    "adcq $0, %%r9\n"
  410|       |    /* (r10,r8,r9) += n0 */
  411|  15.7k|    "addq %%r11, %%r10\n"
  412|  15.7k|    "adcq $0, %%r8\n"
  413|  15.7k|    "adcq $0, %%r9\n"
  414|       |    /* extract m2 */
  415|  15.7k|    "movq %%r10, %q2\n"
  416|  15.7k|    "xorq %%r10, %%r10\n"
  417|       |    /* (r8,r9,r10) += l3 */
  418|  15.7k|    "addq 24(%%rsi), %%r8\n"
  419|  15.7k|    "adcq $0, %%r9\n"
  420|  15.7k|    "adcq $0, %%r10\n"
  421|       |    /* (r8,r9,r10) += n3 * c0 */
  422|  15.7k|    "movq %8, %%rax\n"
  423|  15.7k|    "mulq %%r14\n"
  424|  15.7k|    "addq %%rax, %%r8\n"
  425|  15.7k|    "adcq %%rdx, %%r9\n"
  426|  15.7k|    "adcq $0, %%r10\n"
  427|       |    /* (r8,r9,r10) += n2 * c1 */
  428|  15.7k|    "movq %9, %%rax\n"
  429|  15.7k|    "mulq %%r13\n"
  430|  15.7k|    "addq %%rax, %%r8\n"
  431|  15.7k|    "adcq %%rdx, %%r9\n"
  432|  15.7k|    "adcq $0, %%r10\n"
  433|       |    /* (r8,r9,r10) += n1 */
  434|  15.7k|    "addq %%r12, %%r8\n"
  435|  15.7k|    "adcq $0, %%r9\n"
  436|  15.7k|    "adcq $0, %%r10\n"
  437|       |    /* extract m3 */
  438|  15.7k|    "movq %%r8, %q3\n"
  439|  15.7k|    "xorq %%r8, %%r8\n"
  440|       |    /* (r9,r10,r8) += n3 * c1 */
  441|  15.7k|    "movq %9, %%rax\n"
  442|  15.7k|    "mulq %%r14\n"
  443|  15.7k|    "addq %%rax, %%r9\n"
  444|  15.7k|    "adcq %%rdx, %%r10\n"
  445|  15.7k|    "adcq $0, %%r8\n"
  446|       |    /* (r9,r10,r8) += n2 */
  447|  15.7k|    "addq %%r13, %%r9\n"
  448|  15.7k|    "adcq $0, %%r10\n"
  449|  15.7k|    "adcq $0, %%r8\n"
  450|       |    /* extract m4 */
  451|  15.7k|    "movq %%r9, %q4\n"
  452|       |    /* (r10,r8) += n3 */
  453|  15.7k|    "addq %%r14, %%r10\n"
  454|  15.7k|    "adcq $0, %%r8\n"
  455|       |    /* extract m5 */
  456|  15.7k|    "movq %%r10, %q5\n"
  457|       |    /* extract m6 */
  458|  15.7k|    "movq %%r8, %q6\n"
  459|  15.7k|    : "=&g"(m0), "=&g"(m1), "=&g"(m2), "=g"(m3), "=g"(m4), "=g"(m5), "=g"(m6)
  460|  15.7k|    : "S"(l), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   22|  15.7k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  15.7k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
                  : "S"(l), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   23|  15.7k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  15.7k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
  461|  15.7k|    : "rax", "rdx", "r8", "r9", "r10", "r11", "r12", "r13", "r14", "cc");
  462|       |
  463|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m0, sizeof(m0));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  464|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m1, sizeof(m1));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  465|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m2, sizeof(m2));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  466|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m3, sizeof(m3));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  467|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m4, sizeof(m4));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  468|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m5, sizeof(m5));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  469|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m6, sizeof(m6));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  470|       |
  471|       |    /* Reduce 385 bits into 258. */
  472|  15.7k|    __asm__ __volatile__(
  473|       |    /* Preload */
  474|  15.7k|    "movq %q9, %%r11\n"
  475|  15.7k|    "movq %q10, %%r12\n"
  476|  15.7k|    "movq %q11, %%r13\n"
  477|       |    /* Initialize (r8,r9,r10) */
  478|  15.7k|    "movq %q5, %%r8\n"
  479|  15.7k|    "xorq %%r9, %%r9\n"
  480|  15.7k|    "xorq %%r10, %%r10\n"
  481|       |    /* (r8,r9) += m4 * c0 */
  482|  15.7k|    "movq %12, %%rax\n"
  483|  15.7k|    "mulq %%r11\n"
  484|  15.7k|    "addq %%rax, %%r8\n"
  485|  15.7k|    "adcq %%rdx, %%r9\n"
  486|       |    /* extract p0 */
  487|  15.7k|    "movq %%r8, %q0\n"
  488|  15.7k|    "xorq %%r8, %%r8\n"
  489|       |    /* (r9,r10) += m1 */
  490|  15.7k|    "addq %q6, %%r9\n"
  491|  15.7k|    "adcq $0, %%r10\n"
  492|       |    /* (r9,r10,r8) += m5 * c0 */
  493|  15.7k|    "movq %12, %%rax\n"
  494|  15.7k|    "mulq %%r12\n"
  495|  15.7k|    "addq %%rax, %%r9\n"
  496|  15.7k|    "adcq %%rdx, %%r10\n"
  497|  15.7k|    "adcq $0, %%r8\n"
  498|       |    /* (r9,r10,r8) += m4 * c1 */
  499|  15.7k|    "movq %13, %%rax\n"
  500|  15.7k|    "mulq %%r11\n"
  501|  15.7k|    "addq %%rax, %%r9\n"
  502|  15.7k|    "adcq %%rdx, %%r10\n"
  503|  15.7k|    "adcq $0, %%r8\n"
  504|       |    /* extract p1 */
  505|  15.7k|    "movq %%r9, %q1\n"
  506|  15.7k|    "xorq %%r9, %%r9\n"
  507|       |    /* (r10,r8,r9) += m2 */
  508|  15.7k|    "addq %q7, %%r10\n"
  509|  15.7k|    "adcq $0, %%r8\n"
  510|  15.7k|    "adcq $0, %%r9\n"
  511|       |    /* (r10,r8,r9) += m6 * c0 */
  512|  15.7k|    "movq %12, %%rax\n"
  513|  15.7k|    "mulq %%r13\n"
  514|  15.7k|    "addq %%rax, %%r10\n"
  515|  15.7k|    "adcq %%rdx, %%r8\n"
  516|  15.7k|    "adcq $0, %%r9\n"
  517|       |    /* (r10,r8,r9) += m5 * c1 */
  518|  15.7k|    "movq %13, %%rax\n"
  519|  15.7k|    "mulq %%r12\n"
  520|  15.7k|    "addq %%rax, %%r10\n"
  521|  15.7k|    "adcq %%rdx, %%r8\n"
  522|  15.7k|    "adcq $0, %%r9\n"
  523|       |    /* (r10,r8,r9) += m4 */
  524|  15.7k|    "addq %%r11, %%r10\n"
  525|  15.7k|    "adcq $0, %%r8\n"
  526|  15.7k|    "adcq $0, %%r9\n"
  527|       |    /* extract p2 */
  528|  15.7k|    "movq %%r10, %q2\n"
  529|       |    /* (r8,r9) += m3 */
  530|  15.7k|    "addq %q8, %%r8\n"
  531|  15.7k|    "adcq $0, %%r9\n"
  532|       |    /* (r8,r9) += m6 * c1 */
  533|  15.7k|    "movq %13, %%rax\n"
  534|  15.7k|    "mulq %%r13\n"
  535|  15.7k|    "addq %%rax, %%r8\n"
  536|  15.7k|    "adcq %%rdx, %%r9\n"
  537|       |    /* (r8,r9) += m5 */
  538|  15.7k|    "addq %%r12, %%r8\n"
  539|  15.7k|    "adcq $0, %%r9\n"
  540|       |    /* extract p3 */
  541|  15.7k|    "movq %%r8, %q3\n"
  542|       |    /* (r9) += m6 */
  543|  15.7k|    "addq %%r13, %%r9\n"
  544|       |    /* extract p4 */
  545|  15.7k|    "movq %%r9, %q4\n"
  546|  15.7k|    : "=&g"(p0), "=&g"(p1), "=&g"(p2), "=g"(p3), "=g"(p4)
  547|  15.7k|    : "g"(m0), "g"(m1), "g"(m2), "g"(m3), "g"(m4), "g"(m5), "g"(m6), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   22|  15.7k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  15.7k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
                  : "g"(m0), "g"(m1), "g"(m2), "g"(m3), "g"(m4), "g"(m5), "g"(m6), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   23|  15.7k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  15.7k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
  548|  15.7k|    : "rax", "rdx", "r8", "r9", "r10", "r11", "r12", "r13", "cc");
  549|       |
  550|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p0, sizeof(p0));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  551|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p1, sizeof(p1));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  552|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p2, sizeof(p2));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  553|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p3, sizeof(p3));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  554|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p4, sizeof(p4));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  555|       |
  556|       |    /* Reduce 258 bits into 256. */
  557|  15.7k|    __asm__ __volatile__(
  558|       |    /* Preload */
  559|  15.7k|    "movq %q5, %%r10\n"
  560|       |    /* (rax,rdx) = p4 * c0 */
  561|  15.7k|    "movq %7, %%rax\n"
  562|  15.7k|    "mulq %%r10\n"
  563|       |    /* (rax,rdx) += p0 */
  564|  15.7k|    "addq %q1, %%rax\n"
  565|  15.7k|    "adcq $0, %%rdx\n"
  566|       |    /* extract r0 */
  567|  15.7k|    "movq %%rax, 0(%q6)\n"
  568|       |    /* Move to (r8,r9) */
  569|  15.7k|    "movq %%rdx, %%r8\n"
  570|  15.7k|    "xorq %%r9, %%r9\n"
  571|       |    /* (r8,r9) += p1 */
  572|  15.7k|    "addq %q2, %%r8\n"
  573|  15.7k|    "adcq $0, %%r9\n"
  574|       |    /* (r8,r9) += p4 * c1 */
  575|  15.7k|    "movq %8, %%rax\n"
  576|  15.7k|    "mulq %%r10\n"
  577|  15.7k|    "addq %%rax, %%r8\n"
  578|  15.7k|    "adcq %%rdx, %%r9\n"
  579|       |    /* Extract r1 */
  580|  15.7k|    "movq %%r8, 8(%q6)\n"
  581|  15.7k|    "xorq %%r8, %%r8\n"
  582|       |    /* (r9,r8) += p4 */
  583|  15.7k|    "addq %%r10, %%r9\n"
  584|  15.7k|    "adcq $0, %%r8\n"
  585|       |    /* (r9,r8) += p2 */
  586|  15.7k|    "addq %q3, %%r9\n"
  587|  15.7k|    "adcq $0, %%r8\n"
  588|       |    /* Extract r2 */
  589|  15.7k|    "movq %%r9, 16(%q6)\n"
  590|  15.7k|    "xorq %%r9, %%r9\n"
  591|       |    /* (r8,r9) += p3 */
  592|  15.7k|    "addq %q4, %%r8\n"
  593|  15.7k|    "adcq $0, %%r9\n"
  594|       |    /* Extract r3 */
  595|  15.7k|    "movq %%r8, 24(%q6)\n"
  596|       |    /* Extract c */
  597|  15.7k|    "movq %%r9, %q0\n"
  598|  15.7k|    : "=g"(c)
  599|  15.7k|    : "g"(p0), "g"(p1), "g"(p2), "g"(p3), "g"(p4), "D"(r), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   22|  15.7k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  15.7k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
                  : "g"(p0), "g"(p1), "g"(p2), "g"(p3), "g"(p4), "D"(r), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   23|  15.7k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  15.7k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
  600|  15.7k|    : "rax", "rdx", "r8", "r9", "r10", "cc", "memory");
  601|       |
  602|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(r, sizeof(*r));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  603|  15.7k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&c, sizeof(c));
  ------------------
  |  |   70|  15.7k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  15.7k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 15.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  604|       |
  605|       |#else
  606|       |    secp256k1_uint128 c128;
  607|       |    uint64_t c, c0, c1, c2;
  608|       |    uint64_t n0 = l[4], n1 = l[5], n2 = l[6], n3 = l[7];
  609|       |    uint64_t m0, m1, m2, m3, m4, m5;
  610|       |    uint32_t m6;
  611|       |    uint64_t p0, p1, p2, p3;
  612|       |    uint32_t p4;
  613|       |
  614|       |    /* Reduce 512 bits into 385. */
  615|       |    /* m[0..6] = l[0..3] + n[0..3] * SECP256K1_N_C. */
  616|       |    c0 = l[0]; c1 = 0; c2 = 0;
  617|       |    muladd_fast(n0, SECP256K1_N_C_0);
  618|       |    extract_fast(m0);
  619|       |    sumadd_fast(l[1]);
  620|       |    muladd(n1, SECP256K1_N_C_0);
  621|       |    muladd(n0, SECP256K1_N_C_1);
  622|       |    extract(m1);
  623|       |    sumadd(l[2]);
  624|       |    muladd(n2, SECP256K1_N_C_0);
  625|       |    muladd(n1, SECP256K1_N_C_1);
  626|       |    sumadd(n0);
  627|       |    extract(m2);
  628|       |    sumadd(l[3]);
  629|       |    muladd(n3, SECP256K1_N_C_0);
  630|       |    muladd(n2, SECP256K1_N_C_1);
  631|       |    sumadd(n1);
  632|       |    extract(m3);
  633|       |    muladd(n3, SECP256K1_N_C_1);
  634|       |    sumadd(n2);
  635|       |    extract(m4);
  636|       |    sumadd_fast(n3);
  637|       |    extract_fast(m5);
  638|       |    VERIFY_CHECK(c0 <= 1);
  639|       |    m6 = c0;
  640|       |
  641|       |    /* Reduce 385 bits into 258. */
  642|       |    /* p[0..4] = m[0..3] + m[4..6] * SECP256K1_N_C. */
  643|       |    c0 = m0; c1 = 0; c2 = 0;
  644|       |    muladd_fast(m4, SECP256K1_N_C_0);
  645|       |    extract_fast(p0);
  646|       |    sumadd_fast(m1);
  647|       |    muladd(m5, SECP256K1_N_C_0);
  648|       |    muladd(m4, SECP256K1_N_C_1);
  649|       |    extract(p1);
  650|       |    sumadd(m2);
  651|       |    muladd(m6, SECP256K1_N_C_0);
  652|       |    muladd(m5, SECP256K1_N_C_1);
  653|       |    sumadd(m4);
  654|       |    extract(p2);
  655|       |    sumadd_fast(m3);
  656|       |    muladd_fast(m6, SECP256K1_N_C_1);
  657|       |    sumadd_fast(m5);
  658|       |    extract_fast(p3);
  659|       |    p4 = c0 + m6;
  660|       |    VERIFY_CHECK(p4 <= 2);
  661|       |
  662|       |    /* Reduce 258 bits into 256. */
  663|       |    /* r[0..3] = p[0..3] + p[4] * SECP256K1_N_C. */
  664|       |    secp256k1_u128_from_u64(&c128, p0);
  665|       |    secp256k1_u128_accum_mul(&c128, SECP256K1_N_C_0, p4);
  666|       |    r->d[0] = secp256k1_u128_to_u64(&c128); secp256k1_u128_rshift(&c128, 64);
  667|       |    secp256k1_u128_accum_u64(&c128, p1);
  668|       |    secp256k1_u128_accum_mul(&c128, SECP256K1_N_C_1, p4);
  669|       |    r->d[1] = secp256k1_u128_to_u64(&c128); secp256k1_u128_rshift(&c128, 64);
  670|       |    secp256k1_u128_accum_u64(&c128, p2);
  671|       |    secp256k1_u128_accum_u64(&c128, p4);
  672|       |    r->d[2] = secp256k1_u128_to_u64(&c128); secp256k1_u128_rshift(&c128, 64);
  673|       |    secp256k1_u128_accum_u64(&c128, p3);
  674|       |    r->d[3] = secp256k1_u128_to_u64(&c128);
  675|       |    c = secp256k1_u128_hi_u64(&c128);
  676|       |#endif
  677|       |
  678|       |    /* Final reduction of r. */
  679|  15.7k|    secp256k1_scalar_reduce(r, c + secp256k1_scalar_check_overflow(r));
  680|  15.7k|}
secp256k1.c:secp256k1_scalar_add:
   96|  31.4k|static int secp256k1_scalar_add(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b) {
   97|  31.4k|    int overflow;
   98|  31.4k|    secp256k1_uint128 t;
   99|  31.4k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  31.4k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  100|  31.4k|    SECP256K1_SCALAR_VERIFY(b);
  ------------------
  |  |  103|  31.4k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  101|       |
  102|  31.4k|    secp256k1_u128_from_u64(&t, a->d[0]);
  103|  31.4k|    secp256k1_u128_accum_u64(&t, b->d[0]);
  104|  31.4k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  105|  31.4k|    secp256k1_u128_accum_u64(&t, a->d[1]);
  106|  31.4k|    secp256k1_u128_accum_u64(&t, b->d[1]);
  107|  31.4k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  108|  31.4k|    secp256k1_u128_accum_u64(&t, a->d[2]);
  109|  31.4k|    secp256k1_u128_accum_u64(&t, b->d[2]);
  110|  31.4k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  111|  31.4k|    secp256k1_u128_accum_u64(&t, a->d[3]);
  112|  31.4k|    secp256k1_u128_accum_u64(&t, b->d[3]);
  113|  31.4k|    r->d[3] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  114|  31.4k|    overflow = secp256k1_u128_to_u64(&t) + secp256k1_scalar_check_overflow(r);
  115|  31.4k|    VERIFY_CHECK(overflow == 0 || overflow == 1);
  116|  31.4k|    secp256k1_scalar_reduce(r, overflow);
  117|       |
  118|  31.4k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  31.4k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  119|  31.4k|    return overflow;
  120|  31.4k|}

secp256k1.c:secp256k1_scalar_verify:
   42|   667k|static void secp256k1_scalar_verify(const secp256k1_scalar *r) {
   43|   667k|    VERIFY_CHECK(secp256k1_scalar_check_overflow(r) == 0);
   44|       |
   45|   667k|    (void)r;
   46|   667k|}
secp256k1.c:secp256k1_scalar_set_b32_seckey:
   34|  9.34k|static int secp256k1_scalar_set_b32_seckey(secp256k1_scalar *r, const unsigned char *bin) {
   35|  9.34k|    int overflow;
   36|  9.34k|    secp256k1_scalar_set_b32(r, bin, &overflow);
   37|       |
   38|  9.34k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  9.34k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   39|  9.34k|    return (!overflow) & (!secp256k1_scalar_is_zero(r));
   40|  9.34k|}
secp256k1.c:secp256k1_scalar_clear:
   30|  19.7k|SECP256K1_INLINE static void secp256k1_scalar_clear(secp256k1_scalar *r) {
   31|  19.7k|    secp256k1_memclear_explicit(r, sizeof(secp256k1_scalar));
   32|  19.7k|}
secp256k1.c:secp256k1_scalar_split_lambda:
  142|  5.26k|static void secp256k1_scalar_split_lambda(secp256k1_scalar * SECP256K1_RESTRICT r1, secp256k1_scalar * SECP256K1_RESTRICT r2, const secp256k1_scalar * SECP256K1_RESTRICT k) {
  143|  5.26k|    secp256k1_scalar c1, c2;
  144|  5.26k|    static const secp256k1_scalar minus_b1 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  5.26k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  145|  5.26k|        0x00000000UL, 0x00000000UL, 0x00000000UL, 0x00000000UL,
  146|  5.26k|        0xE4437ED6UL, 0x010E8828UL, 0x6F547FA9UL, 0x0ABFE4C3UL
  147|  5.26k|    );
  148|  5.26k|    static const secp256k1_scalar minus_b2 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  5.26k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  149|  5.26k|        0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFEUL,
  150|  5.26k|        0x8A280AC5UL, 0x0774346DUL, 0xD765CDA8UL, 0x3DB1562CUL
  151|  5.26k|    );
  152|  5.26k|    static const secp256k1_scalar g1 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  5.26k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  153|  5.26k|        0x3086D221UL, 0xA7D46BCDUL, 0xE86C90E4UL, 0x9284EB15UL,
  154|  5.26k|        0x3DAA8A14UL, 0x71E8CA7FUL, 0xE893209AUL, 0x45DBB031UL
  155|  5.26k|    );
  156|  5.26k|    static const secp256k1_scalar g2 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  5.26k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  157|  5.26k|        0xE4437ED6UL, 0x010E8828UL, 0x6F547FA9UL, 0x0ABFE4C4UL,
  158|  5.26k|        0x221208ACUL, 0x9DF506C6UL, 0x1571B4AEUL, 0x8AC47F71UL
  159|  5.26k|    );
  160|  5.26k|    SECP256K1_SCALAR_VERIFY(k);
  ------------------
  |  |  103|  5.26k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  161|  5.26k|    VERIFY_CHECK(r1 != k);
  162|  5.26k|    VERIFY_CHECK(r2 != k);
  163|  5.26k|    VERIFY_CHECK(r1 != r2);
  164|       |
  165|       |    /* these _var calls are constant time since the shift amount is constant */
  166|  5.26k|    secp256k1_scalar_mul_shift_var(&c1, k, &g1, 384);
  167|  5.26k|    secp256k1_scalar_mul_shift_var(&c2, k, &g2, 384);
  168|  5.26k|    secp256k1_scalar_mul(&c1, &c1, &minus_b1);
  169|  5.26k|    secp256k1_scalar_mul(&c2, &c2, &minus_b2);
  170|  5.26k|    secp256k1_scalar_add(r2, &c1, &c2);
  171|  5.26k|    secp256k1_scalar_mul(r1, r2, &secp256k1_const_lambda);
  172|  5.26k|    secp256k1_scalar_negate(r1, r1);
  173|  5.26k|    secp256k1_scalar_add(r1, r1, k);
  174|       |
  175|  5.26k|    SECP256K1_SCALAR_VERIFY(r1);
  ------------------
  |  |  103|  5.26k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  176|  5.26k|    SECP256K1_SCALAR_VERIFY(r2);
  ------------------
  |  |  103|  5.26k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  177|       |#ifdef VERIFY
  178|       |    secp256k1_scalar_split_lambda_verify(r1, r2, k);
  179|       |#endif
  180|  5.26k|}

secp256k1_context_preallocated_destroy:
  178|      2|void secp256k1_context_preallocated_destroy(secp256k1_context* ctx) {
  179|      2|    ARG_CHECK_VOID(ctx == NULL || secp256k1_context_is_proper(ctx));
  ------------------
  |  |   52|      2|#define ARG_CHECK_VOID(cond) do { \
  |  |   53|      2|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|      4|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   54|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   55|      0|        return; \
  |  |   56|      0|    } \
  |  |   57|      2|} while(0)
  |  |  ------------------
  |  |  |  Branch (57:9): [Folded, False: 2]
  |  |  ------------------
  ------------------
  180|       |
  181|       |    /* Defined as noop */
  182|      2|    if (ctx == NULL) {
  ------------------
  |  Branch (182:9): [True: 0, False: 2]
  ------------------
  183|      0|        return;
  184|      0|    }
  185|       |
  186|      2|    secp256k1_ecmult_gen_context_clear(&ctx->ecmult_gen_ctx);
  187|      2|}
secp256k1_context_destroy:
  189|      2|void secp256k1_context_destroy(secp256k1_context* ctx) {
  190|      2|    ARG_CHECK_VOID(ctx == NULL || secp256k1_context_is_proper(ctx));
  ------------------
  |  |   52|      2|#define ARG_CHECK_VOID(cond) do { \
  |  |   53|      2|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|      4|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   54|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   55|      0|        return; \
  |  |   56|      0|    } \
  |  |   57|      2|} while(0)
  |  |  ------------------
  |  |  |  Branch (57:9): [Folded, False: 2]
  |  |  ------------------
  ------------------
  191|       |
  192|       |    /* Defined as noop */
  193|      2|    if (ctx == NULL) {
  ------------------
  |  Branch (193:9): [True: 0, False: 2]
  ------------------
  194|      0|        return;
  195|      0|    }
  196|       |
  197|      2|    secp256k1_context_preallocated_destroy(ctx);
  198|      2|    free(ctx);
  199|      2|}
secp256k1_ec_seckey_verify:
  615|  4.20k|int secp256k1_ec_seckey_verify(const secp256k1_context* ctx, const unsigned char *seckey) {
  616|  4.20k|    secp256k1_scalar sec;
  617|  4.20k|    int ret;
  618|  4.20k|    VERIFY_CHECK(ctx != NULL);
  619|  4.20k|    ARG_CHECK(seckey != NULL);
  ------------------
  |  |   45|  4.20k|#define ARG_CHECK(cond) do { \
  |  |   46|  4.20k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  4.20k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 4.20k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  4.20k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 4.20k]
  |  |  ------------------
  ------------------
  620|       |
  621|  4.20k|    ret = secp256k1_scalar_set_b32_seckey(&sec, seckey);
  622|  4.20k|    secp256k1_scalar_clear(&sec);
  623|  4.20k|    return ret;
  624|  4.20k|}
secp256k1.c:secp256k1_context_is_proper:
   83|      4|static int secp256k1_context_is_proper(const secp256k1_context* ctx) {
   84|      4|    return secp256k1_ecmult_gen_context_is_built(&ctx->ecmult_gen_ctx);
   85|      4|}
secp256k1.c:secp256k1_ec_pubkey_create_helper:
  626|  5.14k|static int secp256k1_ec_pubkey_create_helper(const secp256k1_ecmult_gen_context *ecmult_gen_ctx, secp256k1_scalar *seckey_scalar, secp256k1_ge *p, const unsigned char *seckey) {
  627|  5.14k|    int ret;
  628|       |
  629|  5.14k|    ret = secp256k1_scalar_set_b32_seckey(seckey_scalar, seckey);
  630|  5.14k|    secp256k1_scalar_cmov(seckey_scalar, &secp256k1_scalar_one, !ret);
  631|       |
  632|  5.14k|    secp256k1_ecmult_gen_ge(ecmult_gen_ctx, p, seckey_scalar);
  633|  5.14k|    return ret;
  634|  5.14k|}
secp256k1.c:secp256k1_get_hash_context:
  237|  49.0k|static SECP256K1_INLINE const secp256k1_hash_ctx* secp256k1_get_hash_context(const secp256k1_context *ctx) {
  238|  49.0k|    return &ctx->hash_ctx;
  239|  49.0k|}
secp256k1.c:secp256k1_declassify:
  254|  10.2k|static SECP256K1_INLINE void secp256k1_declassify(const secp256k1_context* ctx, const void *p, size_t len) {
  255|  10.2k|    if (EXPECT(ctx->declassify, 0)) SECP256K1_CHECKMEM_DEFINE(p, len);
  ------------------
  |  |  146|  10.2k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  ------------------
  |  |  |  Branch (146:21): [True: 0, False: 10.2k]
  |  |  ------------------
  ------------------
                  if (EXPECT(ctx->declassify, 0)) SECP256K1_CHECKMEM_DEFINE(p, len);
  ------------------
  |  |  106|      0|#  define SECP256K1_CHECKMEM_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|      0|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  256|  10.2k|}

secp256k1.c:secp256k1_read_be32:
  428|   787k|SECP256K1_INLINE static uint32_t secp256k1_read_be32(const unsigned char* p) {
  429|   787k|    return (uint32_t)p[0] << 24 |
  430|   787k|           (uint32_t)p[1] << 16 |
  431|   787k|           (uint32_t)p[2] << 8  |
  432|   787k|           (uint32_t)p[3];
  433|   787k|}
secp256k1.c:secp256k1_read_be64:
  444|  58.4k|SECP256K1_INLINE static uint64_t secp256k1_read_be64(const unsigned char* p) {
  445|  58.4k|    return (uint64_t)p[0] << 56 |
  446|  58.4k|           (uint64_t)p[1] << 48 |
  447|  58.4k|           (uint64_t)p[2] << 40 |
  448|  58.4k|           (uint64_t)p[3] << 32 |
  449|  58.4k|           (uint64_t)p[4] << 24 |
  450|  58.4k|           (uint64_t)p[5] << 16 |
  451|  58.4k|           (uint64_t)p[6] << 8  |
  452|  58.4k|           (uint64_t)p[7];
  453|  58.4k|}
secp256k1.c:secp256k1_ctz64_var:
  410|  10.1M|static SECP256K1_INLINE int secp256k1_ctz64_var(uint64_t x) {
  411|  10.1M|    VERIFY_CHECK(x != 0);
  412|  10.1M|#if (__has_builtin(__builtin_ctzl) || defined(__GNUC__))
  413|       |    /* If the unsigned long type is sufficient to represent the largest uint64_t, consider __builtin_ctzl. */
  414|  10.1M|    if (((unsigned long)UINT64_MAX) == UINT64_MAX) {
  ------------------
  |  Branch (414:9): [True: 10.1M, Folded]
  ------------------
  415|  10.1M|        return __builtin_ctzl(x);
  416|  10.1M|    }
  417|      0|#endif
  418|      0|#if (__has_builtin(__builtin_ctzll) || defined(__GNUC__))
  419|       |    /* Otherwise consider __builtin_ctzll (the unsigned long long type is always at least 64 bits). */
  420|      0|    return __builtin_ctzll(x);
  421|       |#else
  422|       |    /* If no suitable CTZ builtin is available, use a (variable time) software emulation. */
  423|       |    return secp256k1_ctz64_var_debruijn(x);
  424|       |#endif
  425|  10.1M|}
secp256k1.c:secp256k1_memczero:
  220|  5.14k|static SECP256K1_INLINE void secp256k1_memczero(void *s, size_t len, int flag) {
  221|  5.14k|    unsigned char *p = (unsigned char *)s;
  222|       |    /* Access flag with a volatile-qualified lvalue.
  223|       |       This prevents clang from figuring out (after inlining) that flag can
  224|       |       take only be 0 or 1, which leads to variable time code. */
  225|  5.14k|    volatile int vflag = flag;
  226|  5.14k|    unsigned char mask = -(unsigned char) vflag;
  227|  5.14k|    VERIFY_CHECK(flag == 0 || flag == 1);
  228|   334k|    while (len) {
  ------------------
  |  Branch (228:12): [True: 329k, False: 5.14k]
  ------------------
  229|   329k|        *p &= ~mask;
  230|   329k|        p++;
  231|   329k|        len--;
  232|   329k|    }
  233|  5.14k|}
secp256k1.c:secp256k1_rotr32:
  468|  1.32M|SECP256K1_INLINE static uint32_t secp256k1_rotr32(const uint32_t x, const unsigned int by) {
  469|       |#if defined(_MSC_VER)
  470|       |    return _rotr(x, by);  /* needs <stdlib.h> */
  471|       |#else
  472|       |    /* Reduce rotation amount to avoid UB when shifting. */
  473|  1.32M|    const unsigned int mask = CHAR_BIT * sizeof(x) - 1;
  474|       |    /* Turned into a rot instruction by GCC and clang. */
  475|  1.32M|    return (x >> (by & mask)) | (x << ((-by) & mask));
  476|  1.32M|#endif
  477|  1.32M|}
secp256k1.c:secp256k1_write_be64:
  456|  41.6k|SECP256K1_INLINE static void secp256k1_write_be64(unsigned char* p, uint64_t x) {
  457|  41.6k|    p[7] = x;
  458|  41.6k|    p[6] = x >>  8;
  459|  41.6k|    p[5] = x >> 16;
  460|  41.6k|    p[4] = x >> 24;
  461|  41.6k|    p[3] = x >> 32;
  462|  41.6k|    p[2] = x >> 40;
  463|  41.6k|    p[1] = x >> 48;
  464|  41.6k|    p[0] = x >> 56;
  465|  41.6k|}
secp256k1.c:secp256k1_memclear_explicit:
  268|  66.4k|static SECP256K1_INLINE void secp256k1_memclear_explicit(void *ptr, size_t len) {
  269|       |    /* The current implementation zeroes, but callers must not rely on this */
  270|  66.4k|    secp256k1_memzero_explicit(ptr, len);
  271|       |#ifdef VERIFY
  272|       |    SECP256K1_CHECKMEM_UNDEFINE(ptr, len);
  273|       |#endif
  274|  66.4k|}
secp256k1.c:secp256k1_memzero_explicit:
  236|  66.4k|static SECP256K1_INLINE void secp256k1_memzero_explicit(void *ptr, size_t len) {
  237|       |#if defined(_MSC_VER)
  238|       |    /* SecureZeroMemory is guaranteed not to be optimized out by MSVC. */
  239|       |    SecureZeroMemory(ptr, len);
  240|       |#elif defined(__GNUC__)
  241|       |    /* We use a memory barrier that scares the compiler away from optimizing out the memset.
  242|       |     *
  243|       |     * Quoting Adam Langley <agl@google.com> in commit ad1907fe73334d6c696c8539646c21b11178f20f
  244|       |     * in BoringSSL (ISC License):
  245|       |     *    As best as we can tell, this is sufficient to break any optimisations that
  246|       |     *    might try to eliminate "superfluous" memsets.
  247|       |     * This method is used in memzero_explicit() the Linux kernel, too. Its advantage is that it
  248|       |     * is pretty efficient, because the compiler can still implement the memset() efficiently,
  249|       |     * just not remove it entirely. See "Dead Store Elimination (Still) Considered Harmful" by
  250|       |     * Yang et al. (USENIX Security 2017) for more background.
  251|       |     */
  252|  66.4k|    memset(ptr, 0, len);
  253|  66.4k|    __asm__ __volatile__("" : : "r"(ptr) : "memory");
  254|       |#else
  255|       |    void *(*volatile const volatile_memset)(void *, int, size_t) = memset;
  256|       |    volatile_memset(ptr, 0, len);
  257|       |#endif
  258|  66.4k|}
secp256k1.c:secp256k1_write_be32:
  436|   335k|SECP256K1_INLINE static void secp256k1_write_be32(unsigned char* p, uint32_t x) {
  437|   335k|    p[3] = x;
  438|   335k|    p[2] = x >>  8;
  439|   335k|    p[1] = x >> 16;
  440|   335k|    p[0] = x >> 24;
  441|   335k|}

_Z9UCharCastPh:
   96|  4.20k|inline unsigned char* UCharCast(unsigned char* c) { return c; }
_Z9UCharCastPSt4byte:
   98|  10.4k|inline unsigned char* UCharCast(std::byte* c) { return reinterpret_cast<unsigned char*>(c); }
_Z9UCharCastPKSt4byte:
  102|  15.6k|inline const unsigned char* UCharCast(const std::byte* c) { return reinterpret_cast<const unsigned char*>(c); }

random.cpp:_ZN16secure_allocatorIN12_GLOBAL__N_18RNGStateEE10deallocateEPS1_m:
   37|      2|    {
   38|      2|        if (p != nullptr) {
  ------------------
  |  Branch (38:13): [True: 2, False: 0]
  ------------------
   39|      2|            memory_cleanse(p, sizeof(T) * n);
   40|      2|        }
   41|      2|        LockedPoolManager::Instance().free(p);
   42|      2|    }
_Z18make_secure_uniqueINSt3__15arrayIhLm32EEEJEENS0_10unique_ptrIT_19SecureUniqueDeleterIS4_EEEDpOT0_:
   67|  3.79k|{
   68|  3.79k|    T* p = secure_allocator<T>().allocate(1);
   69|       |
   70|       |    // initialize in place, and return as secure_unique_ptr
   71|  3.79k|    try {
   72|  3.79k|        return secure_unique_ptr<T>(new (p) T(std::forward<Args>(as)...));
   73|  3.79k|    } catch (...) {
   74|      0|        secure_allocator<T>().deallocate(p, 1);
   75|      0|        throw;
   76|      0|    }
   77|  3.79k|}
_ZN16secure_allocatorINSt3__15arrayIhLm32EEEE8allocateEm:
   28|  3.79k|    {
   29|  3.79k|        T* allocation = static_cast<T*>(LockedPoolManager::Instance().alloc(sizeof(T) * n));
   30|  3.79k|        if (!allocation) {
  ------------------
  |  Branch (30:13): [True: 0, False: 3.79k]
  ------------------
   31|      0|            throw std::bad_alloc();
   32|      0|        }
   33|  3.79k|        return allocation;
   34|  3.79k|    }
_ZN19SecureUniqueDeleterINSt3__15arrayIhLm32EEEEclEPS2_:
   57|  3.79k|    void operator()(T* t) noexcept {
   58|  3.79k|        secure_allocator<T>().deallocate(t, 1);
   59|  3.79k|    }
_ZN16secure_allocatorINSt3__15arrayIhLm32EEEE10deallocateEPS2_m:
   37|  3.79k|    {
   38|  3.79k|        if (p != nullptr) {
  ------------------
  |  Branch (38:13): [True: 3.79k, False: 0]
  ------------------
   39|  3.79k|            memory_cleanse(p, sizeof(T) * n);
   40|  3.79k|        }
   41|  3.79k|        LockedPoolManager::Instance().free(p);
   42|  3.79k|    }

_Z14memory_cleansePvm:
   15|  3.80k|{
   16|       |#if defined(WIN32)
   17|       |    /* SecureZeroMemory is guaranteed not to be optimized out. */
   18|       |    SecureZeroMemory(ptr, len);
   19|       |#else
   20|  3.80k|    std::memset(ptr, 0, len);
   21|       |
   22|       |    /* Memory barrier that scares the compiler away from optimizing out the memset.
   23|       |     *
   24|       |     * Quoting Adam Langley <agl@google.com> in commit ad1907fe73334d6c696c8539646c21b11178f20f
   25|       |     * in BoringSSL (ISC License):
   26|       |     *    As best as we can tell, this is sufficient to break any optimisations that
   27|       |     *    might try to eliminate "superfluous" memsets.
   28|       |     * This method is used in memzero_explicit() the Linux kernel, too. Its advantage is that it
   29|       |     * is pretty efficient because the compiler can still implement the memset() efficiently,
   30|       |     * just not remove it entirely. See "Dead Store Elimination (Still) Considered Harmful" by
   31|       |     * Yang et al. (USENIX Security 2017) for more background.
   32|       |     */
   33|  3.80k|    __asm__ __volatile__("" : : "r"(ptr) : "memory");
   34|  3.80k|#endif
   35|  3.80k|}

_ZN5ArenaD2Ev:
   48|      2|Arena::~Arena() = default;
_ZN5Arena5allocEm:
   51|  3.79k|{
   52|       |    // Round to next multiple of alignment
   53|  3.79k|    size = align_up(size, alignment);
   54|       |
   55|       |    // Don't handle zero-sized chunks
   56|  3.79k|    if (size == 0)
  ------------------
  |  Branch (56:9): [True: 0, False: 3.79k]
  ------------------
   57|      0|        return nullptr;
   58|       |
   59|       |    // Pick a large enough free-chunk. Returns an iterator pointing to the first element that is not less than key.
   60|       |    // This allocation strategy is best-fit. According to "Dynamic Storage Allocation: A Survey and Critical Review",
   61|       |    // Wilson et. al. 1995, https://www.scs.stanford.edu/14wi-cs140/sched/readings/wilson.pdf, best-fit and first-fit
   62|       |    // policies seem to work well in practice.
   63|  3.79k|    auto size_ptr_it = size_to_free_chunk.lower_bound(size);
   64|  3.79k|    if (size_ptr_it == size_to_free_chunk.end())
  ------------------
  |  Branch (64:9): [True: 0, False: 3.79k]
  ------------------
   65|      0|        return nullptr;
   66|       |
   67|       |    // Create the used-chunk, taking its space from the end of the free-chunk
   68|  3.79k|    const size_t size_remaining = size_ptr_it->first - size;
   69|  3.79k|    char* const free_chunk = static_cast<char*>(size_ptr_it->second);
   70|  3.79k|    auto allocated = chunks_used.emplace(free_chunk + size_remaining, size).first;
   71|  3.79k|    chunks_free_end.erase(free_chunk + size_ptr_it->first);
   72|  3.79k|    if (size_ptr_it->first == size) {
  ------------------
  |  Branch (72:9): [True: 0, False: 3.79k]
  ------------------
   73|       |        // whole chunk is used up
   74|      0|        chunks_free.erase(size_ptr_it->second);
   75|  3.79k|    } else {
   76|       |        // still some memory left in the chunk
   77|  3.79k|        auto it_remaining = size_to_free_chunk.emplace(size_remaining, size_ptr_it->second);
   78|  3.79k|        chunks_free[size_ptr_it->second] = it_remaining;
   79|  3.79k|        chunks_free_end.emplace(free_chunk + size_remaining, it_remaining);
   80|  3.79k|    }
   81|  3.79k|    size_to_free_chunk.erase(size_ptr_it);
   82|       |
   83|  3.79k|    return allocated->first;
   84|  3.79k|}
_ZN5Arena4freeEPv:
   87|  3.79k|{
   88|       |    // Freeing the nullptr pointer is OK.
   89|  3.79k|    if (ptr == nullptr) {
  ------------------
  |  Branch (89:9): [True: 0, False: 3.79k]
  ------------------
   90|      0|        return;
   91|      0|    }
   92|       |
   93|       |    // Remove chunk from used map
   94|  3.79k|    auto i = chunks_used.find(ptr);
   95|  3.79k|    if (i == chunks_used.end()) {
  ------------------
  |  Branch (95:9): [True: 0, False: 3.79k]
  ------------------
   96|      0|        throw std::runtime_error("Arena: invalid or double free");
   97|      0|    }
   98|  3.79k|    auto freed = std::make_pair(static_cast<char*>(i->first), i->second);
   99|  3.79k|    chunks_used.erase(i);
  100|       |
  101|       |    // coalesce freed with previous chunk
  102|  3.79k|    auto prev = chunks_free_end.find(freed.first);
  103|  3.79k|    if (prev != chunks_free_end.end()) {
  ------------------
  |  Branch (103:9): [True: 3.79k, False: 0]
  ------------------
  104|  3.79k|        freed.first -= prev->second->first;
  105|  3.79k|        freed.second += prev->second->first;
  106|  3.79k|        size_to_free_chunk.erase(prev->second);
  107|  3.79k|        chunks_free_end.erase(prev);
  108|  3.79k|    }
  109|       |
  110|       |    // coalesce freed with chunk after freed
  111|  3.79k|    auto next = chunks_free.find(freed.first + freed.second);
  112|  3.79k|    if (next != chunks_free.end()) {
  ------------------
  |  Branch (112:9): [True: 0, False: 3.79k]
  ------------------
  113|      0|        freed.second += next->second->first;
  114|      0|        size_to_free_chunk.erase(next->second);
  115|      0|        chunks_free.erase(next);
  116|      0|    }
  117|       |
  118|       |    // Add/set space with coalesced free chunk
  119|  3.79k|    auto it = size_to_free_chunk.emplace(freed.second, freed.first);
  120|  3.79k|    chunks_free[freed.first] = it;
  121|  3.79k|    chunks_free_end[freed.first + freed.second] = it;
  122|  3.79k|}
_ZN24PosixLockedPageAllocator10FreeLockedEPvm:
  254|      2|{
  255|      2|    len = align_up(len, page_size);
  256|      2|    memory_cleanse(addr, len);
  257|      2|    munlock(addr, len);
  258|      2|    munmap(addr, len);
  259|      2|}
_ZN10LockedPoolD2Ev:
  283|      2|LockedPool::~LockedPool() = default;
_ZN10LockedPool5allocEm:
  286|  3.79k|{
  287|  3.79k|    std::lock_guard<std::mutex> lock(mutex);
  288|       |
  289|       |    // Don't handle impossible sizes
  290|  3.79k|    if (size == 0 || size > ARENA_SIZE)
  ------------------
  |  Branch (290:9): [True: 0, False: 3.79k]
  |  Branch (290:22): [True: 0, False: 3.79k]
  ------------------
  291|      0|        return nullptr;
  292|       |
  293|       |    // Try allocating from each current arena
  294|  3.79k|    for (auto &arena: arenas) {
  ------------------
  |  Branch (294:21): [True: 3.79k, False: 0]
  ------------------
  295|  3.79k|        void *addr = arena.alloc(size);
  296|  3.79k|        if (addr) {
  ------------------
  |  Branch (296:13): [True: 3.79k, False: 0]
  ------------------
  297|  3.79k|            return addr;
  298|  3.79k|        }
  299|  3.79k|    }
  300|       |    // If that fails, create a new one
  301|      0|    if (new_arena(ARENA_SIZE, ARENA_ALIGN)) {
  ------------------
  |  Branch (301:9): [True: 0, False: 0]
  ------------------
  302|      0|        return arenas.back().alloc(size);
  303|      0|    }
  304|      0|    return nullptr;
  305|      0|}
_ZN10LockedPool4freeEPv:
  308|  3.79k|{
  309|  3.79k|    std::lock_guard<std::mutex> lock(mutex);
  310|       |    // TODO we can do better than this linear search by keeping a map of arena
  311|       |    // extents to arena, and looking up the address.
  312|  3.79k|    for (auto &arena: arenas) {
  ------------------
  |  Branch (312:21): [True: 3.79k, False: 0]
  ------------------
  313|  3.79k|        if (arena.addressInArena(ptr)) {
  ------------------
  |  Branch (313:13): [True: 3.79k, False: 0]
  ------------------
  314|  3.79k|            arena.free(ptr);
  315|  3.79k|            return;
  316|  3.79k|        }
  317|  3.79k|    }
  318|      0|    throw std::runtime_error("LockedPool: invalid address not pointing to any arena");
  319|  3.79k|}
_ZN10LockedPool15LockedPageArenaD2Ev:
  370|      2|{
  371|      2|    allocator->FreeLocked(base, size);
  372|      2|}
_ZN17LockedPoolManager8InstanceEv:
  405|  7.58k|{
  406|  7.58k|    static std::once_flag init_flag;
  407|  7.58k|    std::call_once(init_flag, LockedPoolManager::CreateInstance);
  408|  7.58k|    return *LockedPoolManager::_instance;
  409|  7.58k|}
lockedpool.cpp:_ZL8align_upmm:
   32|  3.79k|{
   33|  3.79k|    return (x + align - 1) & ~(align - 1);
   34|  3.79k|}

_ZNK5Arena14addressInArenaEPv:
   90|  3.79k|    bool addressInArena(void *ptr) const { return ptr >= base && ptr < end; }
  ------------------
  |  Branch (90:51): [True: 3.79k, False: 0]
  |  Branch (90:66): [True: 3.79k, False: 0]
  ------------------
_ZN19LockedPageAllocatorD2Ev:
   22|      2|    virtual ~LockedPageAllocator() = default;

_ZN14AnnotatedMixinINSt3__115recursive_mutexEED2Ev:
   96|      2|    ~AnnotatedMixin() {
   97|      2|        DeleteLock((void*)this);
   98|      2|    }
_ZN14AnnotatedMixinINSt3__15mutexEED2Ev:
   96|     64|    ~AnnotatedMixin() {
   97|     64|        DeleteLock((void*)this);
   98|     64|    }
_Z10DeleteLockPv:
   74|     66|inline void DeleteLock(void* cs) {}
_Z17MaybeCheckNotHeldR14AnnotatedMixinINSt3__15mutexEE:
  258|     30|inline Mutex& MaybeCheckNotHeld(Mutex& cs) EXCLUSIVE_LOCKS_REQUIRED(!cs) LOCK_RETURNED(cs) { return cs; }
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEEC2ERS3_PKcS7_ib:
  181|     30|    UniqueLock(MutexType& mutexIn, const char* pszName, const char* pszFile, int nLine, bool fTry = false) EXCLUSIVE_LOCK_FUNCTION(mutexIn) : Base(mutexIn, std::defer_lock)
  182|     30|    {
  183|     30|        if (fTry)
  ------------------
  |  Branch (183:13): [True: 0, False: 30]
  ------------------
  184|      0|            TryEnter(pszName, pszFile, nLine);
  185|     30|        else
  186|     30|            Enter(pszName, pszFile, nLine);
  187|     30|    }
_Z13EnterCriticalINSt3__15mutexEEvPKcS3_iPT_b:
   67|     30|inline void EnterCritical(const char* pszName, const char* pszFile, int nLine, MutexType* cs, bool fTry = false) {}
_Z13LeaveCriticalv:
   68|     30|inline void LeaveCritical() {}
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEE5EnterEPKcS6_i:
  159|     30|    {
  160|     30|        EnterCritical(pszName, pszFile, nLine, Base::mutex());
  161|       |#ifdef DEBUG_LOCKCONTENTION
  162|       |        if (!Base::try_lock()) {
  163|       |            ContendedLock(pszName, pszFile, nLine, static_cast<Base&>(*this));
  164|       |        }
  165|       |#else
  166|     30|        Base::lock();
  167|     30|#endif
  168|     30|    }
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEED2Ev:
  201|     30|    {
  202|     30|        if (Base::owns_lock())
  ------------------
  |  Branch (202:13): [True: 30, False: 0]
  ------------------
  203|     30|            LeaveCritical();
  204|     30|    }

_ZN18FuzzedDataProviderC2EPKhm:
   37|  2.12k|      : data_ptr_(data), remaining_bytes_(size) {}
_ZN18FuzzedDataProvider11ConsumeBoolEv:
  289|  1.71k|inline bool FuzzedDataProvider::ConsumeBool() {
  290|  1.71k|  return 1 & ConsumeIntegral<uint8_t>();
  291|  1.71k|}
_ZN18FuzzedDataProvider15ConsumeIntegralIhEET_v:
  195|  1.71k|template <typename T> T FuzzedDataProvider::ConsumeIntegral() {
  196|  1.71k|  return ConsumeIntegralInRange(std::numeric_limits<T>::min(),
  197|  1.71k|                                std::numeric_limits<T>::max());
  198|  1.71k|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeIhEET_S1_S1_:
  205|  1.71k|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|  1.71k|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|  1.71k|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|  1.71k|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 1.71k]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|  1.71k|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|  1.71k|  uint64_t result = 0;
  215|  1.71k|  size_t offset = 0;
  216|       |
  217|  1.78k|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 1.71k, False: 65]
  |  Branch (217:43): [True: 1.71k, False: 0]
  ------------------
  218|  1.71k|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 65, False: 1.65k]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|     65|    --remaining_bytes_;
  226|     65|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|     65|    offset += CHAR_BIT;
  228|     65|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|  1.71k|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 1.71k, False: 0]
  ------------------
  232|  1.71k|    result = result % (range + 1);
  233|       |
  234|  1.71k|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|  1.71k|}
_ZN18FuzzedDataProvider12ConsumeBytesISt4byteEENSt3__16vectorIT_NS2_9allocatorIS4_EEEEm:
  109|  5.14k|std::vector<T> FuzzedDataProvider::ConsumeBytes(size_t num_bytes) {
  110|  5.14k|  num_bytes = std::min(num_bytes, remaining_bytes_);
  111|  5.14k|  return ConsumeBytes<T>(num_bytes, num_bytes);
  112|  5.14k|}
_ZN18FuzzedDataProvider12ConsumeBytesISt4byteEENSt3__16vectorIT_NS2_9allocatorIS4_EEEEmm:
  352|  5.14k|std::vector<T> FuzzedDataProvider::ConsumeBytes(size_t size, size_t num_bytes) {
  353|  5.14k|  static_assert(sizeof(T) == sizeof(uint8_t), "Incompatible data type.");
  354|       |
  355|       |  // The point of using the size-based constructor below is to increase the
  356|       |  // odds of having a vector object with capacity being equal to the length.
  357|       |  // That part is always implementation specific, but at least both libc++ and
  358|       |  // libstdc++ allocate the requested number of bytes in that constructor,
  359|       |  // which seems to be a natural choice for other implementations as well.
  360|       |  // To increase the odds even more, we also call |shrink_to_fit| below.
  361|  5.14k|  std::vector<T> result(size);
  362|  5.14k|  if (size == 0) {
  ------------------
  |  Branch (362:7): [True: 4.75k, False: 391]
  ------------------
  363|  4.75k|    if (num_bytes != 0)
  ------------------
  |  Branch (363:9): [True: 0, False: 4.75k]
  ------------------
  364|      0|      abort();
  365|  4.75k|    return result;
  366|  4.75k|  }
  367|       |
  368|    391|  CopyAndAdvance(result.data(), num_bytes);
  369|       |
  370|       |  // Even though |shrink_to_fit| is also implementation specific, we expect it
  371|       |  // to provide an additional assurance in case vector's constructor allocated
  372|       |  // a buffer which is larger than the actual amount of data we put inside it.
  373|    391|  result.shrink_to_fit();
  374|    391|  return result;
  375|  5.14k|}
_ZN18FuzzedDataProvider14CopyAndAdvanceEPvm:
  338|  4.23k|                                               size_t num_bytes) {
  339|  4.23k|  std::memcpy(destination, data_ptr_, num_bytes);
  340|  4.23k|  Advance(num_bytes);
  341|  4.23k|}
_ZN18FuzzedDataProvider7AdvanceEm:
  343|  4.23k|inline void FuzzedDataProvider::Advance(size_t num_bytes) {
  344|  4.23k|  if (num_bytes > remaining_bytes_)
  ------------------
  |  Branch (344:7): [True: 0, False: 4.23k]
  ------------------
  345|      0|    abort();
  346|       |
  347|  4.23k|  data_ptr_ += num_bytes;
  348|  4.23k|  remaining_bytes_ -= num_bytes;
  349|  4.23k|}
_ZN18FuzzedDataProvider12ConsumeBytesIhEENSt3__16vectorIT_NS1_9allocatorIS3_EEEEm:
  109|  4.20k|std::vector<T> FuzzedDataProvider::ConsumeBytes(size_t num_bytes) {
  110|  4.20k|  num_bytes = std::min(num_bytes, remaining_bytes_);
  111|  4.20k|  return ConsumeBytes<T>(num_bytes, num_bytes);
  112|  4.20k|}
_ZN18FuzzedDataProvider12ConsumeBytesIhEENSt3__16vectorIT_NS1_9allocatorIS3_EEEEmm:
  352|  4.20k|std::vector<T> FuzzedDataProvider::ConsumeBytes(size_t size, size_t num_bytes) {
  353|  4.20k|  static_assert(sizeof(T) == sizeof(uint8_t), "Incompatible data type.");
  354|       |
  355|       |  // The point of using the size-based constructor below is to increase the
  356|       |  // odds of having a vector object with capacity being equal to the length.
  357|       |  // That part is always implementation specific, but at least both libc++ and
  358|       |  // libstdc++ allocate the requested number of bytes in that constructor,
  359|       |  // which seems to be a natural choice for other implementations as well.
  360|       |  // To increase the odds even more, we also call |shrink_to_fit| below.
  361|  4.20k|  std::vector<T> result(size);
  362|  4.20k|  if (size == 0) {
  ------------------
  |  Branch (362:7): [True: 362, False: 3.84k]
  ------------------
  363|    362|    if (num_bytes != 0)
  ------------------
  |  Branch (363:9): [True: 0, False: 362]
  ------------------
  364|      0|      abort();
  365|    362|    return result;
  366|    362|  }
  367|       |
  368|  3.84k|  CopyAndAdvance(result.data(), num_bytes);
  369|       |
  370|       |  // Even though |shrink_to_fit| is also implementation specific, we expect it
  371|       |  // to provide an additional assurance in case vector's constructor allocated
  372|       |  // a buffer which is larger than the actual amount of data we put inside it.
  373|  3.84k|  result.shrink_to_fit();
  374|  3.84k|  return result;
  375|  4.20k|}

LLVMFuzzerTestOneInput:
  213|  2.12k|{
  214|  2.12k|    test_one_input({data, size});
  215|  2.12k|    return 0;
  216|  2.12k|}
fuzz.cpp:_ZL14test_one_inputNSt3__14spanIKhLm18446744073709551615EEE:
   84|  2.12k|{
   85|  2.12k|    CheckGlobals check{};
   86|  2.12k|    (*Assert(g_test_one_input))(buffer);
  ------------------
  |  |  116|  2.12k|#define Assert(val) inline_assertion_check<true>(val, std::source_location::current(), #val)
  ------------------
   87|  2.12k|}

_Z23bip324_ecdh_fuzz_targetNSt3__14spanIKhLm18446744073709551615EEE:
  320|  2.12k|{
  321|  2.12k|    FuzzedDataProvider fdp{buffer.data(), buffer.size()};
  322|       |
  323|       |    // We generate private key, k1.
  324|  2.12k|    CKey k1 = ConsumePrivateKey(fdp, /*compressed=*/true);
  325|  2.12k|    if (!k1.IsValid()) return;
  ------------------
  |  Branch (325:9): [True: 46, False: 2.07k]
  ------------------
  326|       |
  327|       |    // They generate private key, k2.
  328|  2.07k|    CKey k2 = ConsumePrivateKey(fdp, /*compressed=*/true);
  329|  2.07k|    if (!k2.IsValid()) return;
  ------------------
  |  Branch (329:9): [True: 363, False: 1.71k]
  ------------------
  330|       |
  331|       |    // We construct an ellswift encoding for our key, k1_ellswift.
  332|  1.71k|    auto ent32_1 = fdp.ConsumeBytes<std::byte>(32);
  333|  1.71k|    ent32_1.resize(32);
  334|  1.71k|    auto k1_ellswift = k1.EllSwiftCreate(ent32_1);
  335|       |
  336|       |    // They construct an ellswift encoding for their key, k2_ellswift.
  337|  1.71k|    auto ent32_2 = fdp.ConsumeBytes<std::byte>(32);
  338|  1.71k|    ent32_2.resize(32);
  339|  1.71k|    auto k2_ellswift = k2.EllSwiftCreate(ent32_2);
  340|       |
  341|       |    // They construct another (possibly distinct) ellswift encoding for their key, k2_ellswift_bad.
  342|  1.71k|    auto ent32_2_bad = fdp.ConsumeBytes<std::byte>(32);
  343|  1.71k|    ent32_2_bad.resize(32);
  344|  1.71k|    auto k2_ellswift_bad = k2.EllSwiftCreate(ent32_2_bad);
  345|  1.71k|    assert((ent32_2_bad == ent32_2) == (k2_ellswift_bad == k2_ellswift));
  ------------------
  |  Branch (345:5): [True: 1.71k, False: 0]
  ------------------
  346|       |
  347|       |    // Determine who is who.
  348|  1.71k|    bool initiating = fdp.ConsumeBool();
  349|       |
  350|       |    // We compute our shared secret using our key and their public key.
  351|  1.71k|    auto ecdh_secret_1 = k1.ComputeBIP324ECDHSecret(k2_ellswift, k1_ellswift, initiating);
  352|       |    // They compute their shared secret using their key and our public key.
  353|  1.71k|    auto ecdh_secret_2 = k2.ComputeBIP324ECDHSecret(k1_ellswift, k2_ellswift, !initiating);
  354|       |    // Those must match, as everyone is behaving correctly.
  355|  1.71k|    assert(ecdh_secret_1 == ecdh_secret_2);
  ------------------
  |  Branch (355:5): [True: 1.71k, False: 0]
  ------------------
  356|       |
  357|  1.71k|    if (k1_ellswift != k2_ellswift) {
  ------------------
  |  Branch (357:9): [True: 1.71k, False: 5]
  ------------------
  358|       |        // Unless the two keys are exactly identical, acting as the wrong party breaks things.
  359|  1.71k|        auto ecdh_secret_bad = k1.ComputeBIP324ECDHSecret(k2_ellswift, k1_ellswift, !initiating);
  360|  1.71k|        assert(ecdh_secret_bad != ecdh_secret_1);
  ------------------
  |  Branch (360:9): [True: 1.71k, False: 0]
  ------------------
  361|  1.71k|    }
  362|       |
  363|  1.71k|    if (k2_ellswift_bad != k2_ellswift) {
  ------------------
  |  Branch (363:9): [True: 121, False: 1.59k]
  ------------------
  364|       |        // Unless both encodings created by them are identical, using the second one breaks things.
  365|    121|        auto ecdh_secret_bad = k1.ComputeBIP324ECDHSecret(k2_ellswift_bad, k1_ellswift, initiating);
  366|       |        assert(ecdh_secret_bad != ecdh_secret_1);
  ------------------
  |  Branch (366:9): [True: 121, False: 0]
  ------------------
  367|    121|    }
  368|  1.71k|}

_Z17ConsumePrivateKeyR18FuzzedDataProviderNSt3__18optionalIbEE:
  231|  4.20k|{
  232|  4.20k|    auto key_data = fuzzed_data_provider.ConsumeBytes<uint8_t>(32);
  233|  4.20k|    key_data.resize(32);
  234|  4.20k|    CKey key;
  235|  4.20k|    bool compressed_value = compressed ? *compressed : fuzzed_data_provider.ConsumeBool();
  ------------------
  |  Branch (235:29): [True: 4.20k, False: 0]
  ------------------
  236|  4.20k|    key.Set(key_data.begin(), key_data.end(), compressed_value);
  237|  4.20k|    return key;
  238|  4.20k|}

_ZN12CheckGlobalsC2Ev:
   59|  2.12k|CheckGlobals::CheckGlobals() : m_impl(std::make_unique<CheckGlobalsImpl>()) {}
_ZN12CheckGlobalsD2Ev:
   60|  2.12k|CheckGlobals::~CheckGlobals() = default;
_ZN16CheckGlobalsImplC2Ev:
   17|  2.12k|    {
   18|  2.12k|        g_used_g_prng = false;
   19|  2.12k|        g_seeded_g_prng_zero = false;
   20|  2.12k|        g_used_system_time = false;
   21|  2.12k|        SetMockTime(0s);
   22|  2.12k|        MockableSteadyClock::ClearMockTime();
   23|  2.12k|    }
_ZN16CheckGlobalsImplD2Ev:
   25|  2.12k|    {
   26|  2.12k|        if (g_used_g_prng && !g_seeded_g_prng_zero) {
  ------------------
  |  Branch (26:13): [True: 2, False: 2.12k]
  |  Branch (26:30): [True: 0, False: 2]
  ------------------
   27|      0|            std::cerr << "\n\n"
   28|      0|                         "The current fuzz target used the global random state.\n\n"
   29|       |
   30|      0|                         "This is acceptable, but requires the fuzz target to call \n"
   31|      0|                         "SeedRandomStateForTest(SeedRand::ZEROS) in the first line \n"
   32|      0|                         "of the FUZZ_TARGET function.\n\n"
   33|       |
   34|      0|                         "An alternative solution would be to avoid any use of globals.\n\n"
   35|       |
   36|      0|                         "Without a solution, fuzz instability and non-determinism can lead \n"
   37|      0|                         "to non-reproducible bugs or inefficient fuzzing.\n\n"
   38|      0|                      << std::endl;
   39|      0|            std::abort(); // Abort, because AFL may try to recover from a std::exit
   40|      0|        }
   41|       |
   42|  2.12k|        if (g_used_system_time) {
  ------------------
  |  Branch (42:13): [True: 0, False: 2.12k]
  ------------------
   43|      0|            std::cerr << "\n\n"
   44|      0|                         "The current fuzz target accessed system time.\n\n"
   45|       |
   46|      0|                         "This is acceptable, but requires the fuzz target to use \n"
   47|      0|                         "a FakeNodeClock, FakeSteadyClock or call \n"
   48|      0|                         "SetMockTime() at the \n" "beginning of processing the \n"
   49|      0|                         "fuzz input.\n\n"
   50|       |
   51|      0|                         "Without setting mock time, time-dependent behavior can lead \n"
   52|      0|                         "to non-reproducible bugs or inefficient fuzzing.\n\n"
   53|      0|                      << std::endl;
   54|      0|            std::abort();
   55|      0|        }
   56|  2.12k|    }

__gcov_reset:
   13|      2|extern "C" __attribute__((weak)) void __gcov_reset(void) {}

_ZN9base_blobILj256EE4dataEv:
   99|      2|    constexpr unsigned char* data() { return m_data.data(); }
_ZN9base_blobILj256EE4sizeEv:
  107|      2|    static constexpr unsigned int size() { return WIDTH; }

_ZN10btcsignals6signalIFvvENS_10null_valueEED2Ev:
  175|      6|    ~signal() = default;
_ZN10btcsignals6signalIFv20SynchronizationStatellbENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFv20SynchronizationStateRK11CBlockIndexdENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEibENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvbENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFviENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFbRK13bilingual_strRKNSt3__112basic_stringIcNS4_11char_traitsIcEENS4_9allocatorIcEEEEjENS_6any_ofEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRK13bilingual_strjENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;

_Z22inline_assertion_checkILb1ERPKNSt3__18functionIFvNS0_4spanIKhLm18446744073709551615EEEEEEEOT0_SB_RKNS0_15source_locationENS0_17basic_string_viewIcNS0_11char_traitsIcEEEE:
   90|  2.12k|{
   91|  2.12k|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [True: 2.12k, Folded]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|  2.12k|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 2.12k]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|  2.12k|    }
   96|  2.12k|    return std::forward<T>(val);
   97|  2.12k|}
_Z22inline_assertion_checkILb1EbEOT0_S1_RKNSt3__115source_locationENS2_17basic_string_viewIcNS2_11char_traitsIcEEEE:
   90|  2.12k|{
   91|  2.12k|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [True: 2.12k, Folded]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|  2.12k|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 2.12k]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|  2.12k|    }
   96|  2.12k|    return std::forward<T>(val);
   97|  2.12k|}
_Z22inline_assertion_checkILb0EbEOT0_S1_RKNSt3__115source_locationENS2_17basic_string_viewIcNS2_11char_traitsIcEEEE:
   90|     10|{
   91|     10|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [Folded, False: 0]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|     10|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 10]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|     10|    }
   96|     10|    return std::forward<T>(val);
   97|     10|}

_ZN16CThreadInterruptD2Ev:
   32|      4|    virtual ~CThreadInterrupt() = default;

_ZN10ThreadPoolD2Ev:
   93|     10|    {
   94|     10|        Stop(); // In case it hasn't been stopped.
   95|     10|    }
_ZN10ThreadPool4StopEv:
  129|     10|    {
  130|       |        // Notify workers and join them
  131|     10|        std::vector<std::thread> threads_to_join;
  132|     10|        {
  133|     10|            LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  134|       |            // Ensure Stop() is not called from a worker thread while workers are still registered,
  135|       |            // otherwise a self-join deadlock would occur.
  136|     10|            auto id = std::this_thread::get_id();
  137|     10|            for (const auto& worker : m_workers) assert(worker.get_id() != id);
  ------------------
  |  Branch (137:37): [True: 0, False: 10]
  |  Branch (137:50): [True: 0, False: 0]
  ------------------
  138|       |            // Early shutdown to return right away on any concurrent Submit() call
  139|     10|            m_interrupt = true;
  140|     10|            threads_to_join.swap(m_workers);
  141|     10|        }
  142|      0|        m_cv.notify_all();
  143|       |        // Help draining queue
  144|     10|        while (ProcessTask()) {}
  ------------------
  |  Branch (144:16): [True: 0, False: 10]
  ------------------
  145|       |        // Free resources
  146|     10|        for (auto& worker : threads_to_join) worker.join();
  ------------------
  |  Branch (146:27): [True: 0, False: 10]
  ------------------
  147|       |
  148|       |        // Since we currently wait for tasks completion, sanity-check empty queue
  149|     10|        LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  150|     10|        Assume(m_work_queue.empty());
  ------------------
  |  |  128|     10|#define Assume(val) inline_assertion_check<false>(val, std::source_location::current(), #val)
  ------------------
  151|       |        // Re-allow Start() now that all workers have exited
  152|     10|        m_interrupt = false;
  153|     10|    }
_ZN10ThreadPool11ProcessTaskEv:
  244|     10|    {
  245|     10|        std::packaged_task<void()> task;
  246|     10|        {
  247|     10|            LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  248|     10|            if (m_work_queue.empty()) return false;
  ------------------
  |  Branch (248:17): [True: 10, False: 0]
  ------------------
  249|       |
  250|       |            // Pop the task
  251|      0|            task = std::move(m_work_queue.front());
  252|      0|            m_work_queue.pop();
  253|      0|        }
  254|      0|        task();
  255|      0|        return true;
  256|     10|    }

_Z11SetMockTimeNSt3__16chrono8durationIxNS_5ratioILl1ELl1EEEEE:
   54|  2.12k|{
   55|  2.12k|    Assert(mock_time_in >= 0s);
  ------------------
  |  |  116|  2.12k|#define Assert(val) inline_assertion_check<true>(val, std::source_location::current(), #val)
  ------------------
   56|  2.12k|    g_mock_time.store(mock_time_in, std::memory_order_relaxed);
   57|  2.12k|}
_ZN19MockableSteadyClock13ClearMockTimeEv:
   84|  2.12k|{
   85|  2.12k|    g_mock_steady_time.store(0ms, std::memory_order_relaxed);
   86|  2.12k|}

_ZN19WalletInitInterfaceD2Ev:
   25|      2|    virtual ~WalletInitInterface() = default;

