_ZN11ArgsManagerD2Ev:
  130|      2|ArgsManager::~ArgsManager() = default;

_ZN13AES256EncryptC2EPKh:
   15|    496|{
   16|    496|    ctx = allocator.allocate(1);
   17|    496|    AES256_init(ctx, key);
   18|    496|}
_ZN13AES256EncryptD2Ev:
   21|    496|{
   22|    496|    allocator.deallocate(ctx, 1);
   23|    496|}
_ZNK13AES256Encrypt7EncryptEPhPKh:
   26|  1.37M|{
   27|  1.37M|    AES256_encrypt(ctx, 1, ciphertext, plaintext);
   28|  1.37M|}
_ZN13AES256DecryptC2EPKh:
   31|    496|{
   32|    496|    ctx = allocator.allocate(1);
   33|    496|    AES256_init(ctx, key);
   34|    496|}
_ZN13AES256DecryptD2Ev:
   37|    496|{
   38|    496|    allocator.deallocate(ctx, 1);
   39|    496|}
_ZNK13AES256Decrypt7DecryptEPhPKh:
   42|  1.37M|{
   43|  1.37M|    AES256_decrypt(ctx, 1, plaintext, ciphertext);
   44|  1.37M|}
_ZN16AES256CBCEncryptC2EPKhS1_b:
  125|    496|    : enc(key), pad(padIn)
  126|    496|{
  127|    496|    iv = allocator.allocate(AES_BLOCKSIZE);
  128|    496|    memcpy(iv, ivIn, AES_BLOCKSIZE);
  129|    496|}
_ZNK16AES256CBCEncrypt7EncryptEPKhiPh:
  132|  39.2k|{
  133|  39.2k|    return CBCEncrypt(enc, iv, data, size, pad, out);
  134|  39.2k|}
_ZN16AES256CBCEncryptD2Ev:
  137|    496|{
  138|    496|    allocator.deallocate(iv, AES_BLOCKSIZE);
  139|    496|}
_ZN16AES256CBCDecryptC2EPKhS1_b:
  142|    496|    : dec(key), pad(padIn)
  143|    496|{
  144|    496|    iv = allocator.allocate(AES_BLOCKSIZE);
  145|    496|    memcpy(iv, ivIn, AES_BLOCKSIZE);
  146|    496|}
_ZNK16AES256CBCDecrypt7DecryptEPKhiPh:
  150|  39.2k|{
  151|  39.2k|    return CBCDecrypt(dec, iv, data, size, pad, out);
  152|  39.2k|}
_ZN16AES256CBCDecryptD2Ev:
  155|    496|{
  156|    496|    allocator.deallocate(iv, AES_BLOCKSIZE);
  157|    496|}
aes.cpp:_ZL10CBCEncryptI13AES256EncryptEiRKT_PKhS5_ibPh:
   49|  39.2k|{
   50|  39.2k|    int written = 0;
   51|  39.2k|    int padsize = size % AES_BLOCKSIZE;
   52|  39.2k|    unsigned char mixed[AES_BLOCKSIZE];
   53|       |
   54|  39.2k|    if (!data || !size || !out)
  ------------------
  |  Branch (54:9): [True: 20.6k, False: 18.6k]
  |  Branch (54:18): [True: 0, False: 18.6k]
  |  Branch (54:27): [True: 0, False: 18.6k]
  ------------------
   55|  20.6k|        return 0;
   56|       |
   57|  18.6k|    if (!pad && padsize != 0)
  ------------------
  |  Branch (57:9): [True: 1.19k, False: 17.4k]
  |  Branch (57:17): [True: 808, False: 391]
  ------------------
   58|    808|        return 0;
   59|       |
   60|  17.8k|    memcpy(mixed, iv, AES_BLOCKSIZE);
   61|       |
   62|       |    // Write all but the last block
   63|  1.37M|    while (written + AES_BLOCKSIZE <= size) {
  ------------------
  |  Branch (63:12): [True: 1.35M, False: 17.8k]
  ------------------
   64|  23.0M|        for (int i = 0; i != AES_BLOCKSIZE; i++)
  ------------------
  |  Branch (64:25): [True: 21.7M, False: 1.35M]
  ------------------
   65|  21.7M|            mixed[i] ^= *data++;
   66|  1.35M|        enc.Encrypt(out + written, mixed);
   67|  1.35M|        memcpy(mixed, out + written, AES_BLOCKSIZE);
   68|  1.35M|        written += AES_BLOCKSIZE;
   69|  1.35M|    }
   70|  17.8k|    if (pad) {
  ------------------
  |  Branch (70:9): [True: 17.4k, False: 391]
  ------------------
   71|       |        // For all that remains, pad each byte with the value of the remaining
   72|       |        // space. If there is none, pad by a full block.
   73|  66.0k|        for (int i = 0; i != padsize; i++)
  ------------------
  |  Branch (73:25): [True: 48.6k, False: 17.4k]
  ------------------
   74|  48.6k|            mixed[i] ^= *data++;
   75|   247k|        for (int i = padsize; i != AES_BLOCKSIZE; i++)
  ------------------
  |  Branch (75:31): [True: 230k, False: 17.4k]
  ------------------
   76|   230k|            mixed[i] ^= AES_BLOCKSIZE - padsize;
   77|  17.4k|        enc.Encrypt(out + written, mixed);
   78|  17.4k|        written += AES_BLOCKSIZE;
   79|  17.4k|    }
   80|  17.8k|    return written;
   81|  18.6k|}
aes.cpp:_ZL10CBCDecryptI13AES256DecryptEiRKT_PKhS5_ibPh:
   85|  39.2k|{
   86|  39.2k|    int written = 0;
   87|  39.2k|    bool fail = false;
   88|  39.2k|    const unsigned char* prev = iv;
   89|       |
   90|  39.2k|    if (!data || !size || !out)
  ------------------
  |  Branch (90:9): [True: 0, False: 39.2k]
  |  Branch (90:18): [True: 21.4k, False: 17.8k]
  |  Branch (90:27): [True: 0, False: 17.8k]
  ------------------
   91|  21.4k|        return 0;
   92|       |
   93|  17.8k|    if (size % AES_BLOCKSIZE != 0)
  ------------------
  |  Branch (93:9): [True: 0, False: 17.8k]
  ------------------
   94|      0|        return 0;
   95|       |
   96|       |    // Decrypt all data. Padding will be checked in the output.
   97|  1.39M|    while (written != size) {
  ------------------
  |  Branch (97:12): [True: 1.37M, False: 17.8k]
  ------------------
   98|  1.37M|        dec.Decrypt(out, data + written);
   99|  23.3M|        for (int i = 0; i != AES_BLOCKSIZE; i++)
  ------------------
  |  Branch (99:25): [True: 22.0M, False: 1.37M]
  ------------------
  100|  22.0M|            *out++ ^= prev[i];
  101|  1.37M|        prev = data + written;
  102|  1.37M|        written += AES_BLOCKSIZE;
  103|  1.37M|    }
  104|       |
  105|       |    // When decrypting padding, attempt to run in constant-time
  106|  17.8k|    if (pad) {
  ------------------
  |  Branch (106:9): [True: 17.4k, False: 391]
  ------------------
  107|       |        // If used, padding size is the value of the last decrypted byte. For
  108|       |        // it to be valid, It must be between 1 and AES_BLOCKSIZE.
  109|  17.4k|        unsigned char padsize = *--out;
  110|  17.4k|        fail = !padsize | (padsize > AES_BLOCKSIZE);
  111|       |
  112|       |        // If not well-formed, treat it as though there's no padding.
  113|  17.4k|        padsize *= !fail;
  114|       |
  115|       |        // All padding must equal the last byte otherwise it's not well-formed
  116|   296k|        for (int i = AES_BLOCKSIZE; i != 0; i--)
  ------------------
  |  Branch (116:37): [True: 278k, False: 17.4k]
  ------------------
  117|   278k|            fail |= ((i > AES_BLOCKSIZE - padsize) & (*out-- != padsize));
  118|       |
  119|  17.4k|        written -= padsize;
  120|  17.4k|    }
  121|  17.8k|    return written * !fail;
  122|  17.8k|}

_ZN15ChaCha20AlignedD2Ev:
   42|      4|{
   43|      4|    memory_cleanse(input, sizeof(input));
   44|      4|}
_ZN8ChaCha20D2Ev:
  332|      4|{
  333|      4|    memory_cleanse(m_buffer.data(), m_buffer.size());
  334|      4|}

AES256_init:
  538|    992|void AES256_init(AES256_ctx* ctx, const unsigned char* key32) {
  539|    992|    AES_setup(ctx->rk, key32, 8, 14);
  540|    992|}
AES256_encrypt:
  542|  1.37M|void AES256_encrypt(const AES256_ctx* ctx, size_t blocks, unsigned char* cipher16, const unsigned char* plain16) {
  543|  2.75M|    while (blocks--) {
  ------------------
  |  Branch (543:12): [True: 1.37M, False: 1.37M]
  ------------------
  544|  1.37M|        AES_encrypt(ctx->rk, 14, cipher16, plain16);
  545|  1.37M|        cipher16 += 16;
  546|  1.37M|        plain16 += 16;
  547|  1.37M|    }
  548|  1.37M|}
AES256_decrypt:
  550|  1.37M|void AES256_decrypt(const AES256_ctx* ctx, size_t blocks, unsigned char* plain16, const unsigned char* cipher16) {
  551|  2.75M|    while (blocks--) {
  ------------------
  |  Branch (551:12): [True: 1.37M, False: 1.37M]
  ------------------
  552|  1.37M|        AES_decrypt(ctx->rk, 14, plain16, cipher16);
  553|  1.37M|        cipher16 += 16;
  554|  1.37M|        plain16 += 16;
  555|  1.37M|    }
  556|  1.37M|}
aes.cpp:_ZL9AES_setupP9AES_statePKhii:
  408|    992|{
  409|    992|    int i;
  410|       |
  411|       |    /* The one-byte round constant */
  412|    992|    AES_state rcon = {{1,0,0,0,0,0,0,0}};
  413|       |    /* The number of the word being generated, modulo nkeywords */
  414|    992|    int pos = 0;
  415|       |    /* The column representing the word currently being processed */
  416|    992|    AES_state column;
  417|       |
  418|  15.8k|    for (i = 0; i < nrounds + 1; i++) {
  ------------------
  |  Branch (418:17): [True: 14.8k, False: 992]
  ------------------
  419|  14.8k|        int b;
  420|   133k|        for (b = 0; b < 8; b++) {
  ------------------
  |  Branch (420:21): [True: 119k, False: 14.8k]
  ------------------
  421|   119k|            rounds[i].slice[b] = 0;
  422|   119k|        }
  423|  14.8k|    }
  424|       |
  425|       |    /* The first nkeywords round columns are just taken from the key directly. */
  426|  8.92k|    for (i = 0; i < nkeywords; i++) {
  ------------------
  |  Branch (426:17): [True: 7.93k, False: 992]
  ------------------
  427|  7.93k|        int r;
  428|  39.6k|        for (r = 0; r < 4; r++) {
  ------------------
  |  Branch (428:21): [True: 31.7k, False: 7.93k]
  ------------------
  429|  31.7k|            LoadByte(&rounds[i >> 2], *(key++), r, i & 3);
  430|  31.7k|        }
  431|  7.93k|    }
  432|       |
  433|    992|    GetOneColumn(&column, &rounds[(nkeywords - 1) >> 2], (nkeywords - 1) & 3);
  434|       |
  435|  52.5k|    for (i = nkeywords; i < 4 * (nrounds + 1); i++) {
  ------------------
  |  Branch (435:25): [True: 51.5k, False: 992]
  ------------------
  436|       |        /* Transform column */
  437|  51.5k|        if (pos == 0) {
  ------------------
  |  Branch (437:13): [True: 6.94k, False: 44.6k]
  ------------------
  438|  6.94k|            SubBytes(&column, 0);
  439|  6.94k|            KeySetupTransform(&column, &rcon);
  440|  6.94k|            MultX(&rcon);
  441|  44.6k|        } else if (nkeywords > 6 && pos == 4) {
  ------------------
  |  Branch (441:20): [True: 44.6k, False: 0]
  |  Branch (441:37): [True: 5.95k, False: 38.6k]
  ------------------
  442|  5.95k|            SubBytes(&column, 0);
  443|  5.95k|        }
  444|  51.5k|        if (++pos == nkeywords) pos = 0;
  ------------------
  |  Branch (444:13): [True: 5.95k, False: 45.6k]
  ------------------
  445|  51.5k|        KeySetupColumnMix(&column, &rounds[i >> 2], &rounds[(i - nkeywords) >> 2], i & 3, (i - nkeywords) & 3);
  446|  51.5k|    }
  447|    992|}
aes.cpp:_ZL8LoadByteP9AES_statehii:
   25|  44.0M|static void LoadByte(AES_state* s, unsigned char byte, int r, int c) {
   26|  44.0M|    int i;
   27|   396M|    for (i = 0; i < 8; i++) {
  ------------------
  |  Branch (27:17): [True: 352M, False: 44.0M]
  ------------------
   28|   352M|        s->slice[i] |= (byte & 1) << (r * 4 + c);
   29|   352M|        byte >>= 1;
   30|   352M|    }
   31|  44.0M|}
aes.cpp:_ZL12GetOneColumnP9AES_statePKS_i:
  362|    992|static void GetOneColumn(AES_state* s, const AES_state* a, int c) {
  363|    992|    int b;
  364|  8.92k|    for (b = 0; b < 8; b++) {
  ------------------
  |  Branch (364:17): [True: 7.93k, False: 992]
  ------------------
  365|  7.93k|        s->slice[b] = (a->slice[b] >> c) & 0x1111;
  366|  7.93k|    }
  367|    992|}
aes.cpp:_ZL8SubBytesP9AES_statei:
   64|  38.5M|static void SubBytes(AES_state *s, int inv) {
   65|       |    /* Load the bit slices */
   66|  38.5M|    uint16_t U0 = s->slice[7], U1 = s->slice[6], U2 = s->slice[5], U3 = s->slice[4];
   67|  38.5M|    uint16_t U4 = s->slice[3], U5 = s->slice[2], U6 = s->slice[1], U7 = s->slice[0];
   68|       |
   69|  38.5M|    uint16_t T1, T2, T3, T4, T5, T6, T7, T8, T9, T10, T11, T12, T13, T14, T15, T16;
   70|  38.5M|    uint16_t T17, T18, T19, T20, T21, T22, T23, T24, T25, T26, T27, D;
   71|  38.5M|    uint16_t M1, M6, M11, M13, M15, M20, M21, M22, M23, M25, M37, M38, M39, M40;
   72|  38.5M|    uint16_t M41, M42, M43, M44, M45, M46, M47, M48, M49, M50, M51, M52, M53, M54;
   73|  38.5M|    uint16_t M55, M56, M57, M58, M59, M60, M61, M62, M63;
   74|       |
   75|  38.5M|    if (inv) {
  ------------------
  |  Branch (75:9): [True: 19.2M, False: 19.2M]
  ------------------
   76|  19.2M|        uint16_t R5, R13, R17, R18, R19;
   77|       |        /* Undo linear postprocessing */
   78|  19.2M|        T23 = U0 ^ U3;
   79|  19.2M|        T22 = ~(U1 ^ U3);
   80|  19.2M|        T2 = ~(U0 ^ U1);
   81|  19.2M|        T1 = U3 ^ U4;
   82|  19.2M|        T24 = ~(U4 ^ U7);
   83|  19.2M|        R5 = U6 ^ U7;
   84|  19.2M|        T8 = ~(U1 ^ T23);
   85|  19.2M|        T19 = T22 ^ R5;
   86|  19.2M|        T9 = ~(U7 ^ T1);
   87|  19.2M|        T10 = T2 ^ T24;
   88|  19.2M|        T13 = T2 ^ R5;
   89|  19.2M|        T3 = T1 ^ R5;
   90|  19.2M|        T25 = ~(U2 ^ T1);
   91|  19.2M|        R13 = U1 ^ U6;
   92|  19.2M|        T17 = ~(U2 ^ T19);
   93|  19.2M|        T20 = T24 ^ R13;
   94|  19.2M|        T4 = U4 ^ T8;
   95|  19.2M|        R17 = ~(U2 ^ U5);
   96|  19.2M|        R18 = ~(U5 ^ U6);
   97|  19.2M|        R19 = ~(U2 ^ U4);
   98|  19.2M|        D = U0 ^ R17;
   99|  19.2M|        T6 = T22 ^ R17;
  100|  19.2M|        T16 = R13 ^ R19;
  101|  19.2M|        T27 = T1 ^ R18;
  102|  19.2M|        T15 = T10 ^ T27;
  103|  19.2M|        T14 = T10 ^ R18;
  104|  19.2M|        T26 = T3 ^ T16;
  105|  19.2M|    } else {
  106|       |        /* Linear preprocessing. */
  107|  19.2M|        T1 = U0 ^ U3;
  108|  19.2M|        T2 = U0 ^ U5;
  109|  19.2M|        T3 = U0 ^ U6;
  110|  19.2M|        T4 = U3 ^ U5;
  111|  19.2M|        T5 = U4 ^ U6;
  112|  19.2M|        T6 = T1 ^ T5;
  113|  19.2M|        T7 = U1 ^ U2;
  114|  19.2M|        T8 = U7 ^ T6;
  115|  19.2M|        T9 = U7 ^ T7;
  116|  19.2M|        T10 = T6 ^ T7;
  117|  19.2M|        T11 = U1 ^ U5;
  118|  19.2M|        T12 = U2 ^ U5;
  119|  19.2M|        T13 = T3 ^ T4;
  120|  19.2M|        T14 = T6 ^ T11;
  121|  19.2M|        T15 = T5 ^ T11;
  122|  19.2M|        T16 = T5 ^ T12;
  123|  19.2M|        T17 = T9 ^ T16;
  124|  19.2M|        T18 = U3 ^ U7;
  125|  19.2M|        T19 = T7 ^ T18;
  126|  19.2M|        T20 = T1 ^ T19;
  127|  19.2M|        T21 = U6 ^ U7;
  128|  19.2M|        T22 = T7 ^ T21;
  129|  19.2M|        T23 = T2 ^ T22;
  130|  19.2M|        T24 = T2 ^ T10;
  131|  19.2M|        T25 = T20 ^ T17;
  132|  19.2M|        T26 = T3 ^ T16;
  133|  19.2M|        T27 = T1 ^ T12;
  134|  19.2M|        D = U7;
  135|  19.2M|    }
  136|       |
  137|       |    /* Non-linear transformation (shared between the forward and backward case) */
  138|  38.5M|    M1 = T13 & T6;
  139|  38.5M|    M6 = T3 & T16;
  140|  38.5M|    M11 = T1 & T15;
  141|  38.5M|    M13 = (T4 & T27) ^ M11;
  142|  38.5M|    M15 = (T2 & T10) ^ M11;
  143|  38.5M|    M20 = T14 ^ M1 ^ (T23 & T8) ^ M13;
  144|  38.5M|    M21 = (T19 & D) ^ M1 ^ T24 ^ M15;
  145|  38.5M|    M22 = T26 ^ M6 ^ (T22 & T9) ^ M13;
  146|  38.5M|    M23 = (T20 & T17) ^ M6 ^ M15 ^ T25;
  147|  38.5M|    M25 = M22 & M20;
  148|  38.5M|    M37 = M21 ^ ((M20 ^ M21) & (M23 ^ M25));
  149|  38.5M|    M38 = M20 ^ M25 ^ (M21 | (M20 & M23));
  150|  38.5M|    M39 = M23 ^ ((M22 ^ M23) & (M21 ^ M25));
  151|  38.5M|    M40 = M22 ^ M25 ^ (M23 | (M21 & M22));
  152|  38.5M|    M41 = M38 ^ M40;
  153|  38.5M|    M42 = M37 ^ M39;
  154|  38.5M|    M43 = M37 ^ M38;
  155|  38.5M|    M44 = M39 ^ M40;
  156|  38.5M|    M45 = M42 ^ M41;
  157|  38.5M|    M46 = M44 & T6;
  158|  38.5M|    M47 = M40 & T8;
  159|  38.5M|    M48 = M39 & D;
  160|  38.5M|    M49 = M43 & T16;
  161|  38.5M|    M50 = M38 & T9;
  162|  38.5M|    M51 = M37 & T17;
  163|  38.5M|    M52 = M42 & T15;
  164|  38.5M|    M53 = M45 & T27;
  165|  38.5M|    M54 = M41 & T10;
  166|  38.5M|    M55 = M44 & T13;
  167|  38.5M|    M56 = M40 & T23;
  168|  38.5M|    M57 = M39 & T19;
  169|  38.5M|    M58 = M43 & T3;
  170|  38.5M|    M59 = M38 & T22;
  171|  38.5M|    M60 = M37 & T20;
  172|  38.5M|    M61 = M42 & T1;
  173|  38.5M|    M62 = M45 & T4;
  174|  38.5M|    M63 = M41 & T2;
  175|       |
  176|  38.5M|    if (inv){
  ------------------
  |  Branch (176:9): [True: 19.2M, False: 19.2M]
  ------------------
  177|       |        /* Undo linear preprocessing */
  178|  19.2M|        uint16_t P0 = M52 ^ M61;
  179|  19.2M|        uint16_t P1 = M58 ^ M59;
  180|  19.2M|        uint16_t P2 = M54 ^ M62;
  181|  19.2M|        uint16_t P3 = M47 ^ M50;
  182|  19.2M|        uint16_t P4 = M48 ^ M56;
  183|  19.2M|        uint16_t P5 = M46 ^ M51;
  184|  19.2M|        uint16_t P6 = M49 ^ M60;
  185|  19.2M|        uint16_t P7 = P0 ^ P1;
  186|  19.2M|        uint16_t P8 = M50 ^ M53;
  187|  19.2M|        uint16_t P9 = M55 ^ M63;
  188|  19.2M|        uint16_t P10 = M57 ^ P4;
  189|  19.2M|        uint16_t P11 = P0 ^ P3;
  190|  19.2M|        uint16_t P12 = M46 ^ M48;
  191|  19.2M|        uint16_t P13 = M49 ^ M51;
  192|  19.2M|        uint16_t P14 = M49 ^ M62;
  193|  19.2M|        uint16_t P15 = M54 ^ M59;
  194|  19.2M|        uint16_t P16 = M57 ^ M61;
  195|  19.2M|        uint16_t P17 = M58 ^ P2;
  196|  19.2M|        uint16_t P18 = M63 ^ P5;
  197|  19.2M|        uint16_t P19 = P2 ^ P3;
  198|  19.2M|        uint16_t P20 = P4 ^ P6;
  199|  19.2M|        uint16_t P22 = P2 ^ P7;
  200|  19.2M|        uint16_t P23 = P7 ^ P8;
  201|  19.2M|        uint16_t P24 = P5 ^ P7;
  202|  19.2M|        uint16_t P25 = P6 ^ P10;
  203|  19.2M|        uint16_t P26 = P9 ^ P11;
  204|  19.2M|        uint16_t P27 = P10 ^ P18;
  205|  19.2M|        uint16_t P28 = P11 ^ P25;
  206|  19.2M|        uint16_t P29 = P15 ^ P20;
  207|  19.2M|        s->slice[7] = P13 ^ P22;
  208|  19.2M|        s->slice[6] = P26 ^ P29;
  209|  19.2M|        s->slice[5] = P17 ^ P28;
  210|  19.2M|        s->slice[4] = P12 ^ P22;
  211|  19.2M|        s->slice[3] = P23 ^ P27;
  212|  19.2M|        s->slice[2] = P19 ^ P24;
  213|  19.2M|        s->slice[1] = P14 ^ P23;
  214|  19.2M|        s->slice[0] = P9 ^ P16;
  215|  19.2M|    } else {
  216|       |        /* Linear postprocessing */
  217|  19.2M|        uint16_t L0 = M61 ^ M62;
  218|  19.2M|        uint16_t L1 = M50 ^ M56;
  219|  19.2M|        uint16_t L2 = M46 ^ M48;
  220|  19.2M|        uint16_t L3 = M47 ^ M55;
  221|  19.2M|        uint16_t L4 = M54 ^ M58;
  222|  19.2M|        uint16_t L5 = M49 ^ M61;
  223|  19.2M|        uint16_t L6 = M62 ^ L5;
  224|  19.2M|        uint16_t L7 = M46 ^ L3;
  225|  19.2M|        uint16_t L8 = M51 ^ M59;
  226|  19.2M|        uint16_t L9 = M52 ^ M53;
  227|  19.2M|        uint16_t L10 = M53 ^ L4;
  228|  19.2M|        uint16_t L11 = M60 ^ L2;
  229|  19.2M|        uint16_t L12 = M48 ^ M51;
  230|  19.2M|        uint16_t L13 = M50 ^ L0;
  231|  19.2M|        uint16_t L14 = M52 ^ M61;
  232|  19.2M|        uint16_t L15 = M55 ^ L1;
  233|  19.2M|        uint16_t L16 = M56 ^ L0;
  234|  19.2M|        uint16_t L17 = M57 ^ L1;
  235|  19.2M|        uint16_t L18 = M58 ^ L8;
  236|  19.2M|        uint16_t L19 = M63 ^ L4;
  237|  19.2M|        uint16_t L20 = L0 ^ L1;
  238|  19.2M|        uint16_t L21 = L1 ^ L7;
  239|  19.2M|        uint16_t L22 = L3 ^ L12;
  240|  19.2M|        uint16_t L23 = L18 ^ L2;
  241|  19.2M|        uint16_t L24 = L15 ^ L9;
  242|  19.2M|        uint16_t L25 = L6 ^ L10;
  243|  19.2M|        uint16_t L26 = L7 ^ L9;
  244|  19.2M|        uint16_t L27 = L8 ^ L10;
  245|  19.2M|        uint16_t L28 = L11 ^ L14;
  246|  19.2M|        uint16_t L29 = L11 ^ L17;
  247|  19.2M|        s->slice[7] = L6 ^ L24;
  248|  19.2M|        s->slice[6] = ~(L16 ^ L26);
  249|  19.2M|        s->slice[5] = ~(L19 ^ L28);
  250|  19.2M|        s->slice[4] = L6 ^ L21;
  251|  19.2M|        s->slice[3] = L20 ^ L22;
  252|  19.2M|        s->slice[2] = L25 ^ L29;
  253|  19.2M|        s->slice[1] = ~(L13 ^ L27);
  254|  19.2M|        s->slice[0] = ~(L6 ^ L23);
  255|  19.2M|    }
  256|  38.5M|}
aes.cpp:_ZL17KeySetupTransformP9AES_statePKS_:
  378|  6.94k|static void KeySetupTransform(AES_state* s, const AES_state* r) {
  379|  6.94k|    int b;
  380|  62.4k|    for (b = 0; b < 8; b++) {
  ------------------
  |  Branch (380:17): [True: 55.5k, False: 6.94k]
  ------------------
  381|  55.5k|        s->slice[b] = ((s->slice[b] >> 4) | (s->slice[b] << 12)) ^ r->slice[b];
  382|  55.5k|    }
  383|  6.94k|}
aes.cpp:_ZL5MultXP9AES_state:
  386|  6.94k|static void MultX(AES_state* s) {
  387|  6.94k|    uint16_t top = s->slice[7];
  388|  6.94k|    s->slice[7] = s->slice[6];
  389|  6.94k|    s->slice[6] = s->slice[5];
  390|  6.94k|    s->slice[5] = s->slice[4];
  391|  6.94k|    s->slice[4] = s->slice[3] ^ top;
  392|  6.94k|    s->slice[3] = s->slice[2] ^ top;
  393|  6.94k|    s->slice[2] = s->slice[1];
  394|  6.94k|    s->slice[1] = s->slice[0] ^ top;
  395|  6.94k|    s->slice[0] = top;
  396|  6.94k|}
aes.cpp:_ZL17KeySetupColumnMixP9AES_stateS0_PKS_ii:
  370|  51.5k|static void KeySetupColumnMix(AES_state* s, AES_state* r, const AES_state* a, int c1, int c2) {
  371|  51.5k|    int b;
  372|   464k|    for (b = 0; b < 8; b++) {
  ------------------
  |  Branch (372:17): [True: 412k, False: 51.5k]
  ------------------
  373|   412k|        r->slice[b] |= ((s->slice[b] ^= ((a->slice[b] >> c2) & 0x1111)) & 0x1111) << c1;
  374|   412k|    }
  375|  51.5k|}
aes.cpp:_ZL11AES_encryptPK9AES_stateiPhPKh:
  449|  1.37M|static void AES_encrypt(const AES_state* rounds, int nrounds, unsigned char* cipher16, const unsigned char* plain16) {
  450|  1.37M|    AES_state s = {{0}};
  451|  1.37M|    int round;
  452|       |
  453|  1.37M|    LoadBytes(&s, plain16);
  454|  1.37M|    AddRoundKey(&s, rounds++);
  455|       |
  456|  19.2M|    for (round = 1; round < nrounds; round++) {
  ------------------
  |  Branch (456:21): [True: 17.8M, False: 1.37M]
  ------------------
  457|  17.8M|        SubBytes(&s, 0);
  458|  17.8M|        ShiftRows(&s);
  459|  17.8M|        MixColumns(&s, 0);
  460|  17.8M|        AddRoundKey(&s, rounds++);
  461|  17.8M|    }
  462|       |
  463|  1.37M|    SubBytes(&s, 0);
  464|  1.37M|    ShiftRows(&s);
  465|  1.37M|    AddRoundKey(&s, rounds);
  466|       |
  467|  1.37M|    SaveBytes(cipher16, &s);
  468|  1.37M|}
aes.cpp:_ZL9LoadBytesP9AES_statePKh:
   34|  2.75M|static void LoadBytes(AES_state *s, const unsigned char* data16) {
   35|  2.75M|    int c;
   36|  13.7M|    for (c = 0; c < 4; c++) {
  ------------------
  |  Branch (36:17): [True: 11.0M, False: 2.75M]
  ------------------
   37|  11.0M|        int r;
   38|  55.0M|        for (r = 0; r < 4; r++) {
  ------------------
  |  Branch (38:21): [True: 44.0M, False: 11.0M]
  ------------------
   39|  44.0M|            LoadByte(s, *(data16++), r, c);
   40|  44.0M|        }
   41|  11.0M|    }
   42|  2.75M|}
aes.cpp:_ZL11AddRoundKeyP9AES_statePKS_:
  354|  41.2M|static void AddRoundKey(AES_state* s, const AES_state* round) {
  355|  41.2M|    int b;
  356|   371M|    for (b = 0; b < 8; b++) {
  ------------------
  |  Branch (356:17): [True: 330M, False: 41.2M]
  ------------------
  357|   330M|        s->slice[b] ^= round->slice[b];
  358|   330M|    }
  359|  41.2M|}
aes.cpp:_ZL9ShiftRowsP9AES_state:
  263|  19.2M|static void ShiftRows(AES_state* s) {
  264|  19.2M|    int i;
  265|   173M|    for (i = 0; i < 8; i++) {
  ------------------
  |  Branch (265:17): [True: 154M, False: 19.2M]
  ------------------
  266|   154M|        uint16_t v = s->slice[i];
  267|   154M|        s->slice[i] =
  268|   154M|            (v & BIT_RANGE(0, 4)) |
  ------------------
  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  ------------------
  269|   154M|            BIT_RANGE_LEFT(v, 4, 5, 3) | BIT_RANGE_RIGHT(v, 5, 8, 1) |
  ------------------
  |  |  260|   154M|#define BIT_RANGE_LEFT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) << (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
                          BIT_RANGE_LEFT(v, 4, 5, 3) | BIT_RANGE_RIGHT(v, 5, 8, 1) |
  ------------------
  |  |  261|   154M|#define BIT_RANGE_RIGHT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) >> (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
  270|   154M|            BIT_RANGE_LEFT(v, 8, 10, 2) | BIT_RANGE_RIGHT(v, 10, 12, 2) |
  ------------------
  |  |  260|   154M|#define BIT_RANGE_LEFT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) << (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
                          BIT_RANGE_LEFT(v, 8, 10, 2) | BIT_RANGE_RIGHT(v, 10, 12, 2) |
  ------------------
  |  |  261|   154M|#define BIT_RANGE_RIGHT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) >> (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
  271|   154M|            BIT_RANGE_LEFT(v, 12, 15, 1) | BIT_RANGE_RIGHT(v, 15, 16, 3);
  ------------------
  |  |  260|   154M|#define BIT_RANGE_LEFT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) << (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
                          BIT_RANGE_LEFT(v, 12, 15, 1) | BIT_RANGE_RIGHT(v, 15, 16, 3);
  ------------------
  |  |  261|   154M|#define BIT_RANGE_RIGHT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) >> (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
  272|   154M|    }
  273|  19.2M|}
aes.cpp:_ZL10MixColumnsP9AES_statei:
  289|  35.7M|static void MixColumns(AES_state* s, int inv) {
  290|       |    /* The MixColumns transform treats the bytes of the columns of the state as
  291|       |     * coefficients of a 3rd degree polynomial over GF(2^8) and multiplies them
  292|       |     * by the fixed polynomial a(x) = {03}x^3 + {01}x^2 + {01}x + {02}, modulo
  293|       |     * x^4 + {01}.
  294|       |     *
  295|       |     * In the inverse transform, we multiply by the inverse of a(x),
  296|       |     * a^-1(x) = {0b}x^3 + {0d}x^2 + {09}x + {0e}. This is equal to
  297|       |     * a(x) * ({04}x^2 + {05}), so we can reuse the forward transform's code
  298|       |     * (found in OpenSSL's bsaes-x86_64.pl, attributed to Jussi Kivilinna)
  299|       |     *
  300|       |     * In the bitsliced representation, a multiplication of every column by x
  301|       |     * mod x^4 + 1 is simply a right rotation.
  302|       |     */
  303|       |
  304|       |    /* Shared for both directions is a multiplication by a(x), which can be
  305|       |     * rewritten as (x^3 + x^2 + x) + {02}*(x^3 + {01}).
  306|       |     *
  307|       |     * First compute s into the s? variables, (x^3 + {01}) * s into the s?_01
  308|       |     * variables and (x^3 + x^2 + x)*s into the s?_123 variables.
  309|       |     */
  310|  35.7M|    uint16_t s0 = s->slice[0], s1 = s->slice[1], s2 = s->slice[2], s3 = s->slice[3];
  311|  35.7M|    uint16_t s4 = s->slice[4], s5 = s->slice[5], s6 = s->slice[6], s7 = s->slice[7];
  312|  35.7M|    uint16_t s0_01 = s0 ^ ROT(s0, 1), s0_123 = ROT(s0_01, 1) ^ ROT(s0, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s0_01 = s0 ^ ROT(s0, 1), s0_123 = ROT(s0_01, 1) ^ ROT(s0, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s0_01 = s0 ^ ROT(s0, 1), s0_123 = ROT(s0_01, 1) ^ ROT(s0, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  313|  35.7M|    uint16_t s1_01 = s1 ^ ROT(s1, 1), s1_123 = ROT(s1_01, 1) ^ ROT(s1, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s1_01 = s1 ^ ROT(s1, 1), s1_123 = ROT(s1_01, 1) ^ ROT(s1, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s1_01 = s1 ^ ROT(s1, 1), s1_123 = ROT(s1_01, 1) ^ ROT(s1, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  314|  35.7M|    uint16_t s2_01 = s2 ^ ROT(s2, 1), s2_123 = ROT(s2_01, 1) ^ ROT(s2, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s2_01 = s2 ^ ROT(s2, 1), s2_123 = ROT(s2_01, 1) ^ ROT(s2, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s2_01 = s2 ^ ROT(s2, 1), s2_123 = ROT(s2_01, 1) ^ ROT(s2, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  315|  35.7M|    uint16_t s3_01 = s3 ^ ROT(s3, 1), s3_123 = ROT(s3_01, 1) ^ ROT(s3, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s3_01 = s3 ^ ROT(s3, 1), s3_123 = ROT(s3_01, 1) ^ ROT(s3, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s3_01 = s3 ^ ROT(s3, 1), s3_123 = ROT(s3_01, 1) ^ ROT(s3, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  316|  35.7M|    uint16_t s4_01 = s4 ^ ROT(s4, 1), s4_123 = ROT(s4_01, 1) ^ ROT(s4, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s4_01 = s4 ^ ROT(s4, 1), s4_123 = ROT(s4_01, 1) ^ ROT(s4, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s4_01 = s4 ^ ROT(s4, 1), s4_123 = ROT(s4_01, 1) ^ ROT(s4, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  317|  35.7M|    uint16_t s5_01 = s5 ^ ROT(s5, 1), s5_123 = ROT(s5_01, 1) ^ ROT(s5, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s5_01 = s5 ^ ROT(s5, 1), s5_123 = ROT(s5_01, 1) ^ ROT(s5, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s5_01 = s5 ^ ROT(s5, 1), s5_123 = ROT(s5_01, 1) ^ ROT(s5, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  318|  35.7M|    uint16_t s6_01 = s6 ^ ROT(s6, 1), s6_123 = ROT(s6_01, 1) ^ ROT(s6, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s6_01 = s6 ^ ROT(s6, 1), s6_123 = ROT(s6_01, 1) ^ ROT(s6, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s6_01 = s6 ^ ROT(s6, 1), s6_123 = ROT(s6_01, 1) ^ ROT(s6, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  319|  35.7M|    uint16_t s7_01 = s7 ^ ROT(s7, 1), s7_123 = ROT(s7_01, 1) ^ ROT(s7, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s7_01 = s7 ^ ROT(s7, 1), s7_123 = ROT(s7_01, 1) ^ ROT(s7, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
                  uint16_t s7_01 = s7 ^ ROT(s7, 1), s7_123 = ROT(s7_01, 1) ^ ROT(s7, 3);
  ------------------
  |  |  287|  35.7M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  320|       |    /* Now compute s = s?_123 + {02} * s?_01. */
  321|  35.7M|    s->slice[0] = s7_01 ^ s0_123;
  322|  35.7M|    s->slice[1] = s7_01 ^ s0_01 ^ s1_123;
  323|  35.7M|    s->slice[2] = s1_01 ^ s2_123;
  324|  35.7M|    s->slice[3] = s7_01 ^ s2_01 ^ s3_123;
  325|  35.7M|    s->slice[4] = s7_01 ^ s3_01 ^ s4_123;
  326|  35.7M|    s->slice[5] = s4_01 ^ s5_123;
  327|  35.7M|    s->slice[6] = s5_01 ^ s6_123;
  328|  35.7M|    s->slice[7] = s6_01 ^ s7_123;
  329|  35.7M|    if (inv) {
  ------------------
  |  Branch (329:9): [True: 17.8M, False: 17.8M]
  ------------------
  330|       |        /* In the reverse direction, we further need to multiply by
  331|       |         * {04}x^2 + {05}, which can be written as {04} * (x^2 + {01}) + {01}.
  332|       |         *
  333|       |         * First compute (x^2 + {01}) * s into the t?_02 variables: */
  334|  17.8M|        uint16_t t0_02 = s->slice[0] ^ ROT(s->slice[0], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  335|  17.8M|        uint16_t t1_02 = s->slice[1] ^ ROT(s->slice[1], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  336|  17.8M|        uint16_t t2_02 = s->slice[2] ^ ROT(s->slice[2], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  337|  17.8M|        uint16_t t3_02 = s->slice[3] ^ ROT(s->slice[3], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  338|  17.8M|        uint16_t t4_02 = s->slice[4] ^ ROT(s->slice[4], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  339|  17.8M|        uint16_t t5_02 = s->slice[5] ^ ROT(s->slice[5], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  340|  17.8M|        uint16_t t6_02 = s->slice[6] ^ ROT(s->slice[6], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  341|  17.8M|        uint16_t t7_02 = s->slice[7] ^ ROT(s->slice[7], 2);
  ------------------
  |  |  287|  17.8M|#define ROT(x,b) (((x) >> ((b) * 4)) | ((x) << ((4-(b)) * 4)))
  ------------------
  342|       |        /* And then update s += {04} * t?_02 */
  343|  17.8M|        s->slice[0] ^= t6_02;
  344|  17.8M|        s->slice[1] ^= t6_02 ^ t7_02;
  345|  17.8M|        s->slice[2] ^= t0_02 ^ t7_02;
  346|  17.8M|        s->slice[3] ^= t1_02 ^ t6_02;
  347|  17.8M|        s->slice[4] ^= t2_02 ^ t6_02 ^ t7_02;
  348|  17.8M|        s->slice[5] ^= t3_02 ^ t7_02;
  349|  17.8M|        s->slice[6] ^= t4_02;
  350|  17.8M|        s->slice[7] ^= t5_02;
  351|  17.8M|    }
  352|  35.7M|}
aes.cpp:_ZL9SaveBytesPhPK9AES_state:
   45|  2.75M|static void SaveBytes(unsigned char* data16, const AES_state *s) {
   46|  2.75M|    int c;
   47|  13.7M|    for (c = 0; c < 4; c++) {
  ------------------
  |  Branch (47:17): [True: 11.0M, False: 2.75M]
  ------------------
   48|  11.0M|        int r;
   49|  55.0M|        for (r = 0; r < 4; r++) {
  ------------------
  |  Branch (49:21): [True: 44.0M, False: 11.0M]
  ------------------
   50|  44.0M|            int b;
   51|  44.0M|            uint8_t v = 0;
   52|   396M|            for (b = 0; b < 8; b++) {
  ------------------
  |  Branch (52:25): [True: 352M, False: 44.0M]
  ------------------
   53|   352M|                v |= ((s->slice[b] >> (r * 4 + c)) & 1) << b;
   54|   352M|            }
   55|  44.0M|            *(data16++) = v;
   56|  44.0M|        }
   57|  11.0M|    }
   58|  2.75M|}
aes.cpp:_ZL11AES_decryptPK9AES_stateiPhPKh:
  470|  1.37M|static void AES_decrypt(const AES_state* rounds, int nrounds, unsigned char* plain16, const unsigned char* cipher16) {
  471|       |    /* Most AES decryption implementations use the alternate scheme
  472|       |     * (the Equivalent Inverse Cipher), which allows for more code reuse between
  473|       |     * the encryption and decryption code, but requires separate setup for both.
  474|       |     */
  475|  1.37M|    AES_state s = {{0}};
  476|  1.37M|    int round;
  477|       |
  478|  1.37M|    rounds += nrounds;
  479|       |
  480|  1.37M|    LoadBytes(&s, cipher16);
  481|  1.37M|    AddRoundKey(&s, rounds--);
  482|       |
  483|  19.2M|    for (round = 1; round < nrounds; round++) {
  ------------------
  |  Branch (483:21): [True: 17.8M, False: 1.37M]
  ------------------
  484|  17.8M|        InvShiftRows(&s);
  485|  17.8M|        SubBytes(&s, 1);
  486|  17.8M|        AddRoundKey(&s, rounds--);
  487|  17.8M|        MixColumns(&s, 1);
  488|  17.8M|    }
  489|       |
  490|  1.37M|    InvShiftRows(&s);
  491|  1.37M|    SubBytes(&s, 1);
  492|  1.37M|    AddRoundKey(&s, rounds);
  493|       |
  494|  1.37M|    SaveBytes(plain16, &s);
  495|  1.37M|}
aes.cpp:_ZL12InvShiftRowsP9AES_state:
  275|  19.2M|static void InvShiftRows(AES_state* s) {
  276|  19.2M|    int i;
  277|   173M|    for (i = 0; i < 8; i++) {
  ------------------
  |  Branch (277:17): [True: 154M, False: 19.2M]
  ------------------
  278|   154M|        uint16_t v = s->slice[i];
  279|   154M|        s->slice[i] =
  280|   154M|            (v & BIT_RANGE(0, 4)) |
  ------------------
  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  ------------------
  281|   154M|            BIT_RANGE_LEFT(v, 4, 7, 1) | BIT_RANGE_RIGHT(v, 7, 8, 3) |
  ------------------
  |  |  260|   154M|#define BIT_RANGE_LEFT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) << (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
                          BIT_RANGE_LEFT(v, 4, 7, 1) | BIT_RANGE_RIGHT(v, 7, 8, 3) |
  ------------------
  |  |  261|   154M|#define BIT_RANGE_RIGHT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) >> (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
  282|   154M|            BIT_RANGE_LEFT(v, 8, 10, 2) | BIT_RANGE_RIGHT(v, 10, 12, 2) |
  ------------------
  |  |  260|   154M|#define BIT_RANGE_LEFT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) << (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
                          BIT_RANGE_LEFT(v, 8, 10, 2) | BIT_RANGE_RIGHT(v, 10, 12, 2) |
  ------------------
  |  |  261|   154M|#define BIT_RANGE_RIGHT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) >> (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
  283|   154M|            BIT_RANGE_LEFT(v, 12, 13, 3) | BIT_RANGE_RIGHT(v, 13, 16, 1);
  ------------------
  |  |  260|   154M|#define BIT_RANGE_LEFT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) << (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
                          BIT_RANGE_LEFT(v, 12, 13, 3) | BIT_RANGE_RIGHT(v, 13, 16, 1);
  ------------------
  |  |  261|   154M|#define BIT_RANGE_RIGHT(x,from,to,shift) (((x) & BIT_RANGE((from), (to))) >> (shift))
  |  |  ------------------
  |  |  |  |  258|   154M|#define BIT_RANGE(from,to) (((1 << ((to) - (from))) - 1) << (from))
  |  |  ------------------
  ------------------
  284|   154M|    }
  285|  19.2M|}

_ZN9ChainCodeD2Ev:
   28|      2|    ~ChainCode() { memory_cleanse(data(), size()); }

_ZN11CNetCleanupD2Ev:
 3676|      2|    {
 3677|       |#ifdef WIN32
 3678|       |        // Shutdown Windows Sockets
 3679|       |        WSACleanup();
 3680|       |#endif
 3681|      2|    }

_ZNK9prevectorILj16EhjiE9is_directEv:
  126|     16|    bool is_direct() const { return _size <= N; }
_ZN9prevectorILj16EhjiED2Ev:
  422|     16|    ~prevector() {
  423|     16|        if (!is_direct()) {
  ------------------
  |  Branch (423:13): [True: 0, False: 16]
  ------------------
  424|      0|            free(_union.indirect_contents.indirect);
  425|      0|            _union.indirect_contents.indirect = nullptr;
  426|      0|        }
  427|     16|    }
_ZNK9prevectorILj36EhjiE9is_directEv:
  126|     14|    bool is_direct() const { return _size <= N; }
_ZN9prevectorILj36EhjiED2Ev:
  422|     14|    ~prevector() {
  423|     14|        if (!is_direct()) {
  ------------------
  |  Branch (423:13): [True: 0, False: 14]
  ------------------
  424|      0|            free(_union.indirect_contents.indirect);
  425|      0|            _union.indirect_contents.indirect = nullptr;
  426|      0|        }
  427|     14|    }

random.cpp:_ZN12_GLOBAL__N_18RNGStateD2Ev:
  367|      2|    ~RNGState() = default;

_ZN20BaseSignatureCheckerD2Ev:
  298|      2|    virtual ~BaseSignatureChecker() = default;

_ZN20BaseSignatureCreatorD2Ev:
   41|      4|    virtual ~BaseSignatureCreator() = default;

_ZN15SigningProviderD2Ev:
  170|      2|    virtual ~SigningProvider() = default;

random.cpp:_ZN16secure_allocatorIN12_GLOBAL__N_18RNGStateEE10deallocateEPS1_m:
   37|      2|    {
   38|      2|        if (p != nullptr) {
  ------------------
  |  Branch (38:13): [True: 2, False: 0]
  ------------------
   39|      2|            memory_cleanse(p, sizeof(T) * n);
   40|      2|        }
   41|      2|        LockedPoolManager::Instance().free(p);
   42|      2|    }
_ZN16secure_allocatorIhE10deallocateEPhm:
   37|    992|    {
   38|    992|        if (p != nullptr) {
  ------------------
  |  Branch (38:13): [True: 992, False: 0]
  ------------------
   39|    992|            memory_cleanse(p, sizeof(T) * n);
   40|    992|        }
   41|    992|        LockedPoolManager::Instance().free(p);
   42|    992|    }
_ZN16secure_allocatorIhE8allocateEm:
   28|    992|    {
   29|    992|        T* allocation = static_cast<T*>(LockedPoolManager::Instance().alloc(sizeof(T) * n));
   30|    992|        if (!allocation) {
  ------------------
  |  Branch (30:13): [True: 0, False: 992]
  ------------------
   31|      0|            throw std::bad_alloc();
   32|      0|        }
   33|    992|        return allocation;
   34|    992|    }
_ZN16secure_allocatorI10AES256_ctxE8allocateEm:
   28|    992|    {
   29|    992|        T* allocation = static_cast<T*>(LockedPoolManager::Instance().alloc(sizeof(T) * n));
   30|    992|        if (!allocation) {
  ------------------
  |  Branch (30:13): [True: 0, False: 992]
  ------------------
   31|      0|            throw std::bad_alloc();
   32|      0|        }
   33|    992|        return allocation;
   34|    992|    }
_ZN16secure_allocatorI10AES256_ctxE10deallocateEPS0_m:
   37|    992|    {
   38|    992|        if (p != nullptr) {
  ------------------
  |  Branch (38:13): [True: 992, False: 0]
  ------------------
   39|    992|            memory_cleanse(p, sizeof(T) * n);
   40|    992|        }
   41|    992|        LockedPoolManager::Instance().free(p);
   42|    992|    }

_Z14memory_cleansePvm:
   15|  1.99k|{
   16|       |#if defined(WIN32)
   17|       |    /* SecureZeroMemory is guaranteed not to be optimized out. */
   18|       |    SecureZeroMemory(ptr, len);
   19|       |#else
   20|  1.99k|    std::memset(ptr, 0, len);
   21|       |
   22|       |    /* Memory barrier that scares the compiler away from optimizing out the memset.
   23|       |     *
   24|       |     * Quoting Adam Langley <agl@google.com> in commit ad1907fe73334d6c696c8539646c21b11178f20f
   25|       |     * in BoringSSL (ISC License):
   26|       |     *    As best as we can tell, this is sufficient to break any optimisations that
   27|       |     *    might try to eliminate "superfluous" memsets.
   28|       |     * This method is used in memzero_explicit() the Linux kernel, too. Its advantage is that it
   29|       |     * is pretty efficient because the compiler can still implement the memset() efficiently,
   30|       |     * just not remove it entirely. See "Dead Store Elimination (Still) Considered Harmful" by
   31|       |     * Yang et al. (USENIX Security 2017) for more background.
   32|       |     */
   33|  1.99k|    __asm__ __volatile__("" : : "r"(ptr) : "memory");
   34|  1.99k|#endif
   35|  1.99k|}

_ZN5ArenaD2Ev:
   48|      2|Arena::~Arena() = default;
_ZN5Arena5allocEm:
   51|  1.98k|{
   52|       |    // Round to next multiple of alignment
   53|  1.98k|    size = align_up(size, alignment);
   54|       |
   55|       |    // Don't handle zero-sized chunks
   56|  1.98k|    if (size == 0)
  ------------------
  |  Branch (56:9): [True: 0, False: 1.98k]
  ------------------
   57|      0|        return nullptr;
   58|       |
   59|       |    // Pick a large enough free-chunk. Returns an iterator pointing to the first element that is not less than key.
   60|       |    // This allocation strategy is best-fit. According to "Dynamic Storage Allocation: A Survey and Critical Review",
   61|       |    // Wilson et. al. 1995, https://www.scs.stanford.edu/14wi-cs140/sched/readings/wilson.pdf, best-fit and first-fit
   62|       |    // policies seem to work well in practice.
   63|  1.98k|    auto size_ptr_it = size_to_free_chunk.lower_bound(size);
   64|  1.98k|    if (size_ptr_it == size_to_free_chunk.end())
  ------------------
  |  Branch (64:9): [True: 0, False: 1.98k]
  ------------------
   65|      0|        return nullptr;
   66|       |
   67|       |    // Create the used-chunk, taking its space from the end of the free-chunk
   68|  1.98k|    const size_t size_remaining = size_ptr_it->first - size;
   69|  1.98k|    char* const free_chunk = static_cast<char*>(size_ptr_it->second);
   70|  1.98k|    auto allocated = chunks_used.emplace(free_chunk + size_remaining, size).first;
   71|  1.98k|    chunks_free_end.erase(free_chunk + size_ptr_it->first);
   72|  1.98k|    if (size_ptr_it->first == size) {
  ------------------
  |  Branch (72:9): [True: 0, False: 1.98k]
  ------------------
   73|       |        // whole chunk is used up
   74|      0|        chunks_free.erase(size_ptr_it->second);
   75|  1.98k|    } else {
   76|       |        // still some memory left in the chunk
   77|  1.98k|        auto it_remaining = size_to_free_chunk.emplace(size_remaining, size_ptr_it->second);
   78|  1.98k|        chunks_free[size_ptr_it->second] = it_remaining;
   79|  1.98k|        chunks_free_end.emplace(free_chunk + size_remaining, it_remaining);
   80|  1.98k|    }
   81|  1.98k|    size_to_free_chunk.erase(size_ptr_it);
   82|       |
   83|  1.98k|    return allocated->first;
   84|  1.98k|}
_ZN5Arena4freeEPv:
   87|  1.98k|{
   88|       |    // Freeing the nullptr pointer is OK.
   89|  1.98k|    if (ptr == nullptr) {
  ------------------
  |  Branch (89:9): [True: 0, False: 1.98k]
  ------------------
   90|      0|        return;
   91|      0|    }
   92|       |
   93|       |    // Remove chunk from used map
   94|  1.98k|    auto i = chunks_used.find(ptr);
   95|  1.98k|    if (i == chunks_used.end()) {
  ------------------
  |  Branch (95:9): [True: 0, False: 1.98k]
  ------------------
   96|      0|        throw std::runtime_error("Arena: invalid or double free");
   97|      0|    }
   98|  1.98k|    auto freed = std::make_pair(static_cast<char*>(i->first), i->second);
   99|  1.98k|    chunks_used.erase(i);
  100|       |
  101|       |    // coalesce freed with previous chunk
  102|  1.98k|    auto prev = chunks_free_end.find(freed.first);
  103|  1.98k|    if (prev != chunks_free_end.end()) {
  ------------------
  |  Branch (103:9): [True: 1.98k, False: 0]
  ------------------
  104|  1.98k|        freed.first -= prev->second->first;
  105|  1.98k|        freed.second += prev->second->first;
  106|  1.98k|        size_to_free_chunk.erase(prev->second);
  107|  1.98k|        chunks_free_end.erase(prev);
  108|  1.98k|    }
  109|       |
  110|       |    // coalesce freed with chunk after freed
  111|  1.98k|    auto next = chunks_free.find(freed.first + freed.second);
  112|  1.98k|    if (next != chunks_free.end()) {
  ------------------
  |  Branch (112:9): [True: 0, False: 1.98k]
  ------------------
  113|      0|        freed.second += next->second->first;
  114|      0|        size_to_free_chunk.erase(next->second);
  115|      0|        chunks_free.erase(next);
  116|      0|    }
  117|       |
  118|       |    // Add/set space with coalesced free chunk
  119|  1.98k|    auto it = size_to_free_chunk.emplace(freed.second, freed.first);
  120|  1.98k|    chunks_free[freed.first] = it;
  121|  1.98k|    chunks_free_end[freed.first + freed.second] = it;
  122|  1.98k|}
_ZN24PosixLockedPageAllocator10FreeLockedEPvm:
  254|      2|{
  255|      2|    len = align_up(len, page_size);
  256|      2|    memory_cleanse(addr, len);
  257|      2|    munlock(addr, len);
  258|      2|    munmap(addr, len);
  259|      2|}
_ZN10LockedPoolD2Ev:
  283|      2|LockedPool::~LockedPool() = default;
_ZN10LockedPool5allocEm:
  286|  1.98k|{
  287|  1.98k|    std::lock_guard<std::mutex> lock(mutex);
  288|       |
  289|       |    // Don't handle impossible sizes
  290|  1.98k|    if (size == 0 || size > ARENA_SIZE)
  ------------------
  |  Branch (290:9): [True: 0, False: 1.98k]
  |  Branch (290:22): [True: 0, False: 1.98k]
  ------------------
  291|      0|        return nullptr;
  292|       |
  293|       |    // Try allocating from each current arena
  294|  1.98k|    for (auto &arena: arenas) {
  ------------------
  |  Branch (294:21): [True: 1.98k, False: 0]
  ------------------
  295|  1.98k|        void *addr = arena.alloc(size);
  296|  1.98k|        if (addr) {
  ------------------
  |  Branch (296:13): [True: 1.98k, False: 0]
  ------------------
  297|  1.98k|            return addr;
  298|  1.98k|        }
  299|  1.98k|    }
  300|       |    // If that fails, create a new one
  301|      0|    if (new_arena(ARENA_SIZE, ARENA_ALIGN)) {
  ------------------
  |  Branch (301:9): [True: 0, False: 0]
  ------------------
  302|      0|        return arenas.back().alloc(size);
  303|      0|    }
  304|      0|    return nullptr;
  305|      0|}
_ZN10LockedPool4freeEPv:
  308|  1.98k|{
  309|  1.98k|    std::lock_guard<std::mutex> lock(mutex);
  310|       |    // TODO we can do better than this linear search by keeping a map of arena
  311|       |    // extents to arena, and looking up the address.
  312|  1.98k|    for (auto &arena: arenas) {
  ------------------
  |  Branch (312:21): [True: 1.98k, False: 0]
  ------------------
  313|  1.98k|        if (arena.addressInArena(ptr)) {
  ------------------
  |  Branch (313:13): [True: 1.98k, False: 0]
  ------------------
  314|  1.98k|            arena.free(ptr);
  315|  1.98k|            return;
  316|  1.98k|        }
  317|  1.98k|    }
  318|      0|    throw std::runtime_error("LockedPool: invalid address not pointing to any arena");
  319|  1.98k|}
_ZN10LockedPool15LockedPageArenaD2Ev:
  370|      2|{
  371|      2|    allocator->FreeLocked(base, size);
  372|      2|}
_ZN17LockedPoolManager8InstanceEv:
  405|  3.97k|{
  406|  3.97k|    static std::once_flag init_flag;
  407|  3.97k|    std::call_once(init_flag, LockedPoolManager::CreateInstance);
  408|  3.97k|    return *LockedPoolManager::_instance;
  409|  3.97k|}
lockedpool.cpp:_ZL8align_upmm:
   32|  1.98k|{
   33|  1.98k|    return (x + align - 1) & ~(align - 1);
   34|  1.98k|}

_ZNK5Arena14addressInArenaEPv:
   90|  1.98k|    bool addressInArena(void *ptr) const { return ptr >= base && ptr < end; }
  ------------------
  |  Branch (90:51): [True: 1.98k, False: 0]
  |  Branch (90:66): [True: 1.98k, False: 0]
  ------------------
_ZN19LockedPageAllocatorD2Ev:
   22|      2|    virtual ~LockedPageAllocator() = default;

_ZN14AnnotatedMixinINSt3__115recursive_mutexEED2Ev:
   96|      2|    ~AnnotatedMixin() {
   97|      2|        DeleteLock((void*)this);
   98|      2|    }
_ZN14AnnotatedMixinINSt3__15mutexEED2Ev:
   96|     64|    ~AnnotatedMixin() {
   97|     64|        DeleteLock((void*)this);
   98|     64|    }
_Z10DeleteLockPv:
   74|     66|inline void DeleteLock(void* cs) {}
_Z17MaybeCheckNotHeldR14AnnotatedMixinINSt3__15mutexEE:
  258|     30|inline Mutex& MaybeCheckNotHeld(Mutex& cs) EXCLUSIVE_LOCKS_REQUIRED(!cs) LOCK_RETURNED(cs) { return cs; }
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEEC2ERS3_PKcS7_ib:
  181|     30|    UniqueLock(MutexType& mutexIn, const char* pszName, const char* pszFile, int nLine, bool fTry = false) EXCLUSIVE_LOCK_FUNCTION(mutexIn) : Base(mutexIn, std::defer_lock)
  182|     30|    {
  183|     30|        if (fTry)
  ------------------
  |  Branch (183:13): [True: 0, False: 30]
  ------------------
  184|      0|            TryEnter(pszName, pszFile, nLine);
  185|     30|        else
  186|     30|            Enter(pszName, pszFile, nLine);
  187|     30|    }
_Z13EnterCriticalINSt3__15mutexEEvPKcS3_iPT_b:
   67|     30|inline void EnterCritical(const char* pszName, const char* pszFile, int nLine, MutexType* cs, bool fTry = false) {}
_Z13LeaveCriticalv:
   68|     30|inline void LeaveCritical() {}
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEE5EnterEPKcS6_i:
  159|     30|    {
  160|     30|        EnterCritical(pszName, pszFile, nLine, Base::mutex());
  161|       |#ifdef DEBUG_LOCKCONTENTION
  162|       |        if (!Base::try_lock()) {
  163|       |            ContendedLock(pszName, pszFile, nLine, static_cast<Base&>(*this));
  164|       |        }
  165|       |#else
  166|     30|        Base::lock();
  167|     30|#endif
  168|     30|    }
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEED2Ev:
  201|     30|    {
  202|     30|        if (Base::owns_lock())
  ------------------
  |  Branch (202:13): [True: 30, False: 0]
  ------------------
  203|     30|            LeaveCritical();
  204|     30|    }

_ZN18FuzzedDataProviderC2EPKhm:
   37|    496|      : data_ptr_(data), remaining_bytes_(size) {}
_ZN18FuzzedDataProvider11ConsumeBoolEv:
  289|  40.2k|inline bool FuzzedDataProvider::ConsumeBool() {
  290|  40.2k|  return 1 & ConsumeIntegral<uint8_t>();
  291|  40.2k|}
_ZN18FuzzedDataProvider15ConsumeIntegralIhEET_v:
  195|  40.2k|template <typename T> T FuzzedDataProvider::ConsumeIntegral() {
  196|  40.2k|  return ConsumeIntegralInRange(std::numeric_limits<T>::min(),
  197|  40.2k|                                std::numeric_limits<T>::max());
  198|  40.2k|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeIhEET_S1_S1_:
  205|  40.2k|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|  40.2k|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|  40.2k|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|  40.2k|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 40.2k]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|  40.2k|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|  40.2k|  uint64_t result = 0;
  215|  40.2k|  size_t offset = 0;
  216|       |
  217|  79.9k|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 40.2k, False: 39.7k]
  |  Branch (217:43): [True: 40.2k, False: 0]
  ------------------
  218|  40.2k|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 39.7k, False: 468]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|  39.7k|    --remaining_bytes_;
  226|  39.7k|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|  39.7k|    offset += CHAR_BIT;
  228|  39.7k|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|  40.2k|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 40.2k, False: 0]
  ------------------
  232|  40.2k|    result = result % (range + 1);
  233|       |
  234|  40.2k|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|  40.2k|}
_ZN18FuzzedDataProvider25ConsumeRandomLengthStringEm:
  153|  39.2k|FuzzedDataProvider::ConsumeRandomLengthString(size_t max_length) {
  154|       |  // Reads bytes from the start of |data_ptr_|. Maps "\\" to "\", and maps "\"
  155|       |  // followed by anything else to the end of the string. As a result of this
  156|       |  // logic, a fuzzer can insert characters into the string, and the string
  157|       |  // will be lengthened to include those new characters, resulting in a more
  158|       |  // stable fuzzer than picking the length of a string independently from
  159|       |  // picking its contents.
  160|  39.2k|  std::string result;
  161|       |
  162|       |  // Reserve the anticipated capacity to prevent several reallocations.
  163|  39.2k|  result.reserve(std::min(max_length, remaining_bytes_));
  164|  29.4M|  for (size_t i = 0; i < max_length && remaining_bytes_ != 0; ++i) {
  ------------------
  |  Branch (164:22): [True: 29.4M, False: 325]
  |  Branch (164:40): [True: 29.4M, False: 54]
  ------------------
  165|  29.4M|    char next = ConvertUnsignedToSigned<char>(data_ptr_[0]);
  166|  29.4M|    Advance(1);
  167|  29.4M|    if (next == '\\' && remaining_bytes_ != 0) {
  ------------------
  |  Branch (167:9): [True: 39.7k, False: 29.3M]
  |  Branch (167:25): [True: 39.7k, False: 13]
  ------------------
  168|  39.7k|      next = ConvertUnsignedToSigned<char>(data_ptr_[0]);
  169|  39.7k|      Advance(1);
  170|  39.7k|      if (next != '\\')
  ------------------
  |  Branch (170:11): [True: 38.8k, False: 863]
  ------------------
  171|  38.8k|        break;
  172|  39.7k|    }
  173|  29.3M|    result += next;
  174|  29.3M|  }
  175|       |
  176|  39.2k|  result.shrink_to_fit();
  177|  39.2k|  return result;
  178|  39.2k|}
_ZN18FuzzedDataProvider25ConsumeRandomLengthStringEv:
  181|  39.2k|inline std::string FuzzedDataProvider::ConsumeRandomLengthString() {
  182|  39.2k|  return ConsumeRandomLengthString(remaining_bytes_);
  183|  39.2k|}
_ZN18FuzzedDataProvider14CopyAndAdvanceEPvm:
  338|    973|                                               size_t num_bytes) {
  339|    973|  std::memcpy(destination, data_ptr_, num_bytes);
  340|    973|  Advance(num_bytes);
  341|    973|}
_ZN18FuzzedDataProvider7AdvanceEm:
  343|  29.4M|inline void FuzzedDataProvider::Advance(size_t num_bytes) {
  344|  29.4M|  if (num_bytes > remaining_bytes_)
  ------------------
  |  Branch (344:7): [True: 0, False: 29.4M]
  ------------------
  345|      0|    abort();
  346|       |
  347|  29.4M|  data_ptr_ += num_bytes;
  348|  29.4M|  remaining_bytes_ -= num_bytes;
  349|  29.4M|}
_ZN18FuzzedDataProvider23ConvertUnsignedToSignedIchEET_T0_:
  378|  29.4M|TS FuzzedDataProvider::ConvertUnsignedToSigned(TU value) {
  379|  29.4M|  static_assert(sizeof(TS) == sizeof(TU), "Incompatible data types.");
  380|  29.4M|  static_assert(!std::numeric_limits<TU>::is_signed,
  381|  29.4M|                "Source type must be unsigned.");
  382|       |
  383|       |  if constexpr (std::numeric_limits<TS>::is_modulo)
  384|       |    return static_cast<TS>(value);
  385|       |
  386|       |  // Avoid using implementation-defined unsigned to signed conversions.
  387|       |  // To learn more, see https://stackoverflow.com/questions/13150449.
  388|  29.4M|  constexpr auto TS_max = static_cast<TU>(std::numeric_limits<TS>::max());
  389|  29.4M|  if (value <= TS_max) {
  ------------------
  |  Branch (389:7): [True: 24.2M, False: 5.24M]
  ------------------
  390|  24.2M|    return static_cast<TS>(value);
  391|  24.2M|  } else {
  392|  5.24M|    constexpr auto TS_min = std::numeric_limits<TS>::min();
  393|  5.24M|    return TS_min + static_cast<TS>(value - TS_min);
  394|  5.24M|  }
  395|  29.4M|}
_ZN18FuzzedDataProvider12ConsumeBytesIhEENSt3__16vectorIT_NS1_9allocatorIS3_EEEEm:
  109|    992|std::vector<T> FuzzedDataProvider::ConsumeBytes(size_t num_bytes) {
  110|    992|  num_bytes = std::min(num_bytes, remaining_bytes_);
  111|    992|  return ConsumeBytes<T>(num_bytes, num_bytes);
  112|    992|}
_ZN18FuzzedDataProvider12ConsumeBytesIhEENSt3__16vectorIT_NS1_9allocatorIS3_EEEEmm:
  352|    992|std::vector<T> FuzzedDataProvider::ConsumeBytes(size_t size, size_t num_bytes) {
  353|    992|  static_assert(sizeof(T) == sizeof(uint8_t), "Incompatible data type.");
  354|       |
  355|       |  // The point of using the size-based constructor below is to increase the
  356|       |  // odds of having a vector object with capacity being equal to the length.
  357|       |  // That part is always implementation specific, but at least both libc++ and
  358|       |  // libstdc++ allocate the requested number of bytes in that constructor,
  359|       |  // which seems to be a natural choice for other implementations as well.
  360|       |  // To increase the odds even more, we also call |shrink_to_fit| below.
  361|    992|  std::vector<T> result(size);
  362|    992|  if (size == 0) {
  ------------------
  |  Branch (362:7): [True: 19, False: 973]
  ------------------
  363|     19|    if (num_bytes != 0)
  ------------------
  |  Branch (363:9): [True: 0, False: 19]
  ------------------
  364|      0|      abort();
  365|     19|    return result;
  366|     19|  }
  367|       |
  368|    973|  CopyAndAdvance(result.data(), num_bytes);
  369|       |
  370|       |  // Even though |shrink_to_fit| is also implementation specific, we expect it
  371|       |  // to provide an additional assurance in case vector's constructor allocated
  372|       |  // a buffer which is larger than the actual amount of data we put inside it.
  373|    973|  result.shrink_to_fit();
  374|    973|  return result;
  375|    992|}

_Z28crypto_aes256cbc_fuzz_targetNSt3__14spanIKhLm18446744073709551615EEE:
   15|    496|{
   16|    496|    FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
   17|    496|    const std::vector<uint8_t> key = ConsumeFixedLengthByteVector(fuzzed_data_provider, AES256_KEYSIZE);
   18|    496|    const std::vector<uint8_t> iv = ConsumeFixedLengthByteVector(fuzzed_data_provider, AES_BLOCKSIZE);
   19|    496|    const bool pad = fuzzed_data_provider.ConsumeBool();
   20|       |
   21|    496|    AES256CBCEncrypt encrypt{key.data(), iv.data(), pad};
   22|    496|    AES256CBCDecrypt decrypt{key.data(), iv.data(), pad};
   23|       |
   24|  39.2k|    LIMITED_WHILE (fuzzed_data_provider.ConsumeBool(), 10000) {
  ------------------
  |  |   23|  39.7k|    for (unsigned _count{limit}; (condition) && _count; --_count)
  |  |  ------------------
  |  |  |  Branch (23:34): [True: 39.2k, False: 495]
  |  |  |  Branch (23:49): [True: 39.2k, False: 1]
  |  |  ------------------
  ------------------
   25|  39.2k|        const std::vector<uint8_t> plaintext = ConsumeRandomLengthByteVector(fuzzed_data_provider);
   26|  39.2k|        std::vector<uint8_t> ciphertext(plaintext.size() + AES_BLOCKSIZE);
   27|  39.2k|        const int encrypt_ret = encrypt.Encrypt(plaintext.data(), plaintext.size(), ciphertext.data());
   28|  39.2k|        ciphertext.resize(encrypt_ret);
   29|  39.2k|        std::vector<uint8_t> decrypted_plaintext(ciphertext.size());
   30|  39.2k|        const int decrypt_ret = decrypt.Decrypt(ciphertext.data(), ciphertext.size(), decrypted_plaintext.data());
   31|  39.2k|        decrypted_plaintext.resize(decrypt_ret);
   32|       |        assert(decrypted_plaintext == plaintext || (!pad && plaintext.size() % AES_BLOCKSIZE != 0 && encrypt_ret == 0 && decrypt_ret == 0));
  ------------------
  |  Branch (32:9): [True: 808, False: 0]
  |  Branch (32:9): [True: 808, False: 0]
  |  Branch (32:9): [True: 808, False: 0]
  |  Branch (32:9): [True: 808, False: 0]
  |  Branch (32:9): [True: 38.4k, False: 808]
  |  Branch (32:9): [True: 39.2k, False: 0]
  ------------------
   33|  39.2k|    }
   34|    496|}

LLVMFuzzerTestOneInput:
  213|    496|{
  214|    496|    test_one_input({data, size});
  215|    496|    return 0;
  216|    496|}
fuzz.cpp:_ZL14test_one_inputNSt3__14spanIKhLm18446744073709551615EEE:
   84|    496|{
   85|    496|    CheckGlobals check{};
   86|    496|    (*Assert(g_test_one_input))(buffer);
  ------------------
  |  |  116|    496|#define Assert(val) inline_assertion_check<true>(val, std::source_location::current(), #val)
  ------------------
   87|    496|}

_Z29ConsumeRandomLengthByteVectorIhENSt3__16vectorIT_NS0_9allocatorIS2_EEEER18FuzzedDataProviderRKNS0_8optionalImEE:
   64|  39.2k|{
   65|  39.2k|    static_assert(sizeof(B) == 1);
   66|  39.2k|    const std::string s = max_length ?
  ------------------
  |  Branch (66:27): [True: 0, False: 39.2k]
  ------------------
   67|      0|                              fuzzed_data_provider.ConsumeRandomLengthString(*max_length) :
   68|  39.2k|                              fuzzed_data_provider.ConsumeRandomLengthString();
   69|  39.2k|    std::vector<B> ret(s.size());
   70|  39.2k|    std::copy(s.begin(), s.end(), reinterpret_cast<char*>(ret.data()));
   71|  39.2k|    return ret;
   72|  39.2k|}
_Z28ConsumeFixedLengthByteVectorIhENSt3__16vectorIT_NS0_9allocatorIS2_EEEER18FuzzedDataProviderm:
  281|    992|{
  282|    992|    static_assert(sizeof(B) == 1);
  283|    992|    auto random_bytes = fuzzed_data_provider.ConsumeBytes<B>(length);
  284|    992|    random_bytes.resize(length);
  285|    992|    return random_bytes;
  286|    992|}

_ZN12CheckGlobalsC2Ev:
   59|    496|CheckGlobals::CheckGlobals() : m_impl(std::make_unique<CheckGlobalsImpl>()) {}
_ZN12CheckGlobalsD2Ev:
   60|    498|CheckGlobals::~CheckGlobals() = default;
_ZN16CheckGlobalsImplC2Ev:
   17|    496|    {
   18|    496|        g_used_g_prng = false;
   19|    496|        g_seeded_g_prng_zero = false;
   20|    496|        g_used_system_time = false;
   21|    496|        SetMockTime(0s);
   22|    496|        MockableSteadyClock::ClearMockTime();
   23|    496|    }
_ZN16CheckGlobalsImplD2Ev:
   25|    498|    {
   26|    498|        if (g_used_g_prng && !g_seeded_g_prng_zero) {
  ------------------
  |  Branch (26:13): [True: 0, False: 498]
  |  Branch (26:30): [True: 0, False: 0]
  ------------------
   27|      0|            std::cerr << "\n\n"
   28|      0|                         "The current fuzz target used the global random state.\n\n"
   29|       |
   30|      0|                         "This is acceptable, but requires the fuzz target to call \n"
   31|      0|                         "SeedRandomStateForTest(SeedRand::ZEROS) in the first line \n"
   32|      0|                         "of the FUZZ_TARGET function.\n\n"
   33|       |
   34|      0|                         "An alternative solution would be to avoid any use of globals.\n\n"
   35|       |
   36|      0|                         "Without a solution, fuzz instability and non-determinism can lead \n"
   37|      0|                         "to non-reproducible bugs or inefficient fuzzing.\n\n"
   38|      0|                      << std::endl;
   39|      0|            std::abort(); // Abort, because AFL may try to recover from a std::exit
   40|      0|        }
   41|       |
   42|    498|        if (g_used_system_time) {
  ------------------
  |  Branch (42:13): [True: 0, False: 498]
  ------------------
   43|      0|            std::cerr << "\n\n"
   44|      0|                         "The current fuzz target accessed system time.\n\n"
   45|       |
   46|      0|                         "This is acceptable, but requires the fuzz target to use \n"
   47|      0|                         "a FakeNodeClock, FakeSteadyClock or call \n"
   48|      0|                         "SetMockTime() at the \n" "beginning of processing the \n"
   49|      0|                         "fuzz input.\n\n"
   50|       |
   51|      0|                         "Without setting mock time, time-dependent behavior can lead \n"
   52|      0|                         "to non-reproducible bugs or inefficient fuzzing.\n\n"
   53|      0|                      << std::endl;
   54|      0|            std::abort();
   55|      0|        }
   56|    498|    }

__gcov_reset:
   13|      2|extern "C" __attribute__((weak)) void __gcov_reset(void) {}

_ZN9base_blobILj256EE4dataEv:
   99|      2|    constexpr unsigned char* data() { return m_data.data(); }
_ZN9base_blobILj256EE4sizeEv:
  107|      2|    static constexpr unsigned int size() { return WIDTH; }

_ZN10btcsignals6signalIFvvENS_10null_valueEED2Ev:
  175|      6|    ~signal() = default;
_ZN10btcsignals6signalIFv20SynchronizationStatellbENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFv20SynchronizationStateRK11CBlockIndexdENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEibENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvbENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFviENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFbRK13bilingual_strRKNSt3__112basic_stringIcNS4_11char_traitsIcEENS4_9allocatorIcEEEEjENS_6any_ofEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRK13bilingual_strjENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;

_Z22inline_assertion_checkILb1ERPKNSt3__18functionIFvNS0_4spanIKhLm18446744073709551615EEEEEEEOT0_SB_RKNS0_15source_locationENS0_17basic_string_viewIcNS0_11char_traitsIcEEEE:
   90|    496|{
   91|    496|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [True: 496, Folded]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|    496|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 496]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|    496|    }
   96|    496|    return std::forward<T>(val);
   97|    496|}
_Z22inline_assertion_checkILb1EbEOT0_S1_RKNSt3__115source_locationENS2_17basic_string_viewIcNS2_11char_traitsIcEEEE:
   90|    496|{
   91|    496|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [True: 496, Folded]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|    496|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 496]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|    496|    }
   96|    496|    return std::forward<T>(val);
   97|    496|}
_Z22inline_assertion_checkILb0EbEOT0_S1_RKNSt3__115source_locationENS2_17basic_string_viewIcNS2_11char_traitsIcEEEE:
   90|     10|{
   91|     10|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [Folded, False: 0]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|     10|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 10]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|     10|    }
   96|     10|    return std::forward<T>(val);
   97|     10|}

_ZN16CThreadInterruptD2Ev:
   32|      4|    virtual ~CThreadInterrupt() = default;

_ZN10ThreadPoolD2Ev:
   93|     10|    {
   94|     10|        Stop(); // In case it hasn't been stopped.
   95|     10|    }
_ZN10ThreadPool4StopEv:
  129|     10|    {
  130|       |        // Notify workers and join them
  131|     10|        std::vector<std::thread> threads_to_join;
  132|     10|        {
  133|     10|            LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  134|       |            // Ensure Stop() is not called from a worker thread while workers are still registered,
  135|       |            // otherwise a self-join deadlock would occur.
  136|     10|            auto id = std::this_thread::get_id();
  137|     10|            for (const auto& worker : m_workers) assert(worker.get_id() != id);
  ------------------
  |  Branch (137:37): [True: 0, False: 10]
  |  Branch (137:50): [True: 0, False: 0]
  ------------------
  138|       |            // Early shutdown to return right away on any concurrent Submit() call
  139|     10|            m_interrupt = true;
  140|     10|            threads_to_join.swap(m_workers);
  141|     10|        }
  142|      0|        m_cv.notify_all();
  143|       |        // Help draining queue
  144|     10|        while (ProcessTask()) {}
  ------------------
  |  Branch (144:16): [True: 0, False: 10]
  ------------------
  145|       |        // Free resources
  146|     10|        for (auto& worker : threads_to_join) worker.join();
  ------------------
  |  Branch (146:27): [True: 0, False: 10]
  ------------------
  147|       |
  148|       |        // Since we currently wait for tasks completion, sanity-check empty queue
  149|     10|        LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  150|     10|        Assume(m_work_queue.empty());
  ------------------
  |  |  128|     10|#define Assume(val) inline_assertion_check<false>(val, std::source_location::current(), #val)
  ------------------
  151|       |        // Re-allow Start() now that all workers have exited
  152|     10|        m_interrupt = false;
  153|     10|    }
_ZN10ThreadPool11ProcessTaskEv:
  244|     10|    {
  245|     10|        std::packaged_task<void()> task;
  246|     10|        {
  247|     10|            LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  248|     10|            if (m_work_queue.empty()) return false;
  ------------------
  |  Branch (248:17): [True: 10, False: 0]
  ------------------
  249|       |
  250|       |            // Pop the task
  251|      0|            task = std::move(m_work_queue.front());
  252|      0|            m_work_queue.pop();
  253|      0|        }
  254|      0|        task();
  255|      0|        return true;
  256|     10|    }

_Z11SetMockTimeNSt3__16chrono8durationIxNS_5ratioILl1ELl1EEEEE:
   54|    496|{
   55|    496|    Assert(mock_time_in >= 0s);
  ------------------
  |  |  116|    496|#define Assert(val) inline_assertion_check<true>(val, std::source_location::current(), #val)
  ------------------
   56|    496|    g_mock_time.store(mock_time_in, std::memory_order_relaxed);
   57|    496|}
_ZN19MockableSteadyClock13ClearMockTimeEv:
   84|    496|{
   85|    496|    g_mock_steady_time.store(0ms, std::memory_order_relaxed);
   86|    496|}

_ZN19WalletInitInterfaceD2Ev:
   25|      2|    virtual ~WalletInitInterface() = default;

