_Z6Paramsv:
  128|  5.69k|const CChainParams &Params() {
  129|  5.69k|    assert(globalChainParams);
  ------------------
  |  Branch (129:5): [True: 5.69k, False: 0]
  ------------------
  130|  5.69k|    return *globalChainParams;
  131|  5.69k|}

_ZN11ArgsManagerD2Ev:
  130|      4|ArgsManager::~ArgsManager() = default;
_ZN11ArgsManager11ForceSetArgERKNSt3__112basic_stringIcNS0_11char_traitsIcEENS0_9allocatorIcEEEES8_:
  628|      2|{
  629|      2|    LOCK(cs_args);
  ------------------
  |  |  268|      2|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|      2|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|      2|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|      2|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  630|      2|    m_settings.forced_settings[SettingName(strArg)] = strValue;
  631|      2|}
_ZN11ArgsManager9ClearArgsEv:
  694|      2|{
  695|      2|    LOCK(cs_args);
  ------------------
  |  |  268|      2|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|      2|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|      2|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|      2|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  696|      2|    m_settings = {};
  697|      2|    m_available_args.clear();
  698|      2|    m_command_args.clear();
  699|      2|    m_network_only_args.clear();
  700|      2|    m_config_sections.clear();
  701|      2|}
args.cpp:_ZL11SettingNameRKNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEE:
   63|      2|{
   64|      2|    return arg.size() > 0 && arg[0] == '-' ? arg.substr(1) : arg;
  ------------------
  |  Branch (64:12): [True: 2, False: 0]
  |  Branch (64:30): [True: 2, False: 0]
  ------------------
   65|      2|}

_Z17internal_bswap_32j:
   54|  10.1M|{
   55|  10.1M|#ifdef bitcoin_builtin_bswap32
   56|  10.1M|    return bitcoin_builtin_bswap32(x);
  ------------------
  |  |   24|  10.1M|#      define bitcoin_builtin_bswap32(x) __builtin_bswap32(x)
  ------------------
   57|       |#else
   58|       |    return (((x & 0xff000000U) >> 24) | ((x & 0x00ff0000U) >>  8) |
   59|       |            ((x & 0x0000ff00U) <<  8) | ((x & 0x000000ffU) << 24));
   60|       |#endif
   61|  10.1M|}
_Z17internal_bswap_64m:
   64|  1.26M|{
   65|  1.26M|#ifdef bitcoin_builtin_bswap64
   66|  1.26M|    return bitcoin_builtin_bswap64(x);
  ------------------
  |  |   27|  1.26M|#      define bitcoin_builtin_bswap64(x) __builtin_bswap64(x)
  ------------------
   67|       |#else
   68|       |     return (((x & 0xff00000000000000ull) >> 56)
   69|       |          | ((x & 0x00ff000000000000ull) >> 40)
   70|       |          | ((x & 0x0000ff0000000000ull) >> 24)
   71|       |          | ((x & 0x000000ff00000000ull) >> 8)
   72|       |          | ((x & 0x00000000ff000000ull) << 8)
   73|       |          | ((x & 0x0000000000ff0000ull) << 24)
   74|       |          | ((x & 0x000000000000ff00ull) << 40)
   75|       |          | ((x & 0x00000000000000ffull) << 56));
   76|       |#endif
   77|  1.26M|}

_Z16htole16_internalt:
   19|  3.30k|{
   20|       |    if constexpr (std::endian::native == std::endian::big) return internal_bswap_16(host_16bits);
   21|  3.30k|        else return host_16bits;
   22|  3.30k|}
_Z16le16toh_internalt:
   29|  3.93k|{
   30|       |    if constexpr (std::endian::native == std::endian::big) return internal_bswap_16(little_endian_16bits);
   31|  3.93k|        else return little_endian_16bits;
   32|  3.93k|}
_Z16be32toh_internalj:
   44|  12.9k|{
   45|  12.9k|    if constexpr (std::endian::native == std::endian::little) return internal_bswap_32(big_endian_32bits);
   46|       |        else return big_endian_32bits;
   47|  12.9k|}
_Z16htobe32_internalj:
   34|  10.1M|{
   35|  10.1M|    if constexpr (std::endian::native == std::endian::little) return internal_bswap_32(host_32bits);
   36|       |        else return host_32bits;
   37|  10.1M|}
_Z16htole64_internalm:
   59|   411k|{
   60|       |    if constexpr (std::endian::native == std::endian::big) return internal_bswap_64(host_64bits);
   61|   411k|        else return host_64bits;
   62|   411k|}
_Z16htobe64_internalm:
   54|  1.26M|{
   55|  1.26M|    if constexpr (std::endian::native == std::endian::little) return internal_bswap_64(host_64bits);
   56|       |        else return host_64bits;
   57|  1.26M|}
_Z16le64toh_internalm:
   69|   687k|{
   70|       |    if constexpr (std::endian::native == std::endian::big) return internal_bswap_64(little_endian_64bits);
   71|   687k|        else return little_endian_64bits;
   72|   687k|}
_Z16htole32_internalj:
   39|  1.41M|{
   40|       |    if constexpr (std::endian::native == std::endian::big) return internal_bswap_32(host_32bits);
   41|  1.41M|        else return host_32bits;
   42|  1.41M|}
_Z16le32toh_internalj:
   49|  1.48M|{
   50|       |    if constexpr (std::endian::native == std::endian::big) return internal_bswap_32(little_endian_32bits);
   51|  1.48M|        else return little_endian_32bits;
   52|  1.48M|}

_Z17ComputeMerkleRootNSt3__16vectorI7uint256NS_9allocatorIS1_EEEEPb:
   52|  8.22k|uint256 ComputeMerkleRoot(std::vector<uint256> hashes, bool* mutated) {
   53|  8.22k|    bool mutation = false;
   54|  8.97k|    while (hashes.size() > 1) {
  ------------------
  |  Branch (54:12): [True: 744, False: 8.22k]
  ------------------
   55|    744|        if (mutated) {
  ------------------
  |  Branch (55:13): [True: 0, False: 744]
  ------------------
   56|       |            // Check every level because equal pairs can appear above the leaves,
   57|       |            // as in the [1,2,3,4,5,6,5,6] construction described above.
   58|       |            // Continuing after finding one is redundant, but mutated blocks should
   59|       |            // not propagate through the network anyway, and the total number of
   60|       |            // comparisons is the same as for an unmutated input of the same length.
   61|      0|            for (size_t pos = 0; pos + 1 < hashes.size(); pos += 2) {
  ------------------
  |  Branch (61:34): [True: 0, False: 0]
  ------------------
   62|      0|                if (hashes[pos] == hashes[pos + 1]) mutation = true;
  ------------------
  |  Branch (62:21): [True: 0, False: 0]
  ------------------
   63|      0|            }
   64|      0|        }
   65|    744|        if (hashes.size() & 1) {
  ------------------
  |  Branch (65:13): [True: 267, False: 477]
  ------------------
   66|    267|            hashes.push_back(hashes.back());
   67|    267|        }
   68|    744|        SHA256D64(hashes[0].begin(), hashes[0].begin(), hashes.size() / 2);
   69|    744|        hashes.resize(hashes.size() / 2);
   70|    744|    }
   71|  8.22k|    if (mutated) *mutated = mutation;
  ------------------
  |  Branch (71:9): [True: 0, False: 8.22k]
  ------------------
   72|  8.22k|    if (hashes.size() == 0) return uint256();
  ------------------
  |  Branch (72:9): [True: 0, False: 8.22k]
  ------------------
   73|  8.22k|    return hashes[0];
   74|  8.22k|}

_Z25GetWitnessCommitmentIndexRK6CBlock:
  156|  9.42k|{
  157|  9.42k|    int commitpos = NO_WITNESS_COMMITMENT;
  158|  9.42k|    if (!block.vtx.empty()) {
  ------------------
  |  Branch (158:9): [True: 9.42k, False: 0]
  ------------------
  159|   291k|        for (size_t o = 0; o < block.vtx[0]->vout.size(); o++) {
  ------------------
  |  Branch (159:28): [True: 281k, False: 9.42k]
  ------------------
  160|   281k|            const CTxOut& vout = block.vtx[0]->vout[o];
  161|   281k|            if (vout.scriptPubKey.size() >= MINIMUM_WITNESS_COMMITMENT &&
  ------------------
  |  Branch (161:17): [True: 14.7k, False: 267k]
  ------------------
  162|  14.7k|                vout.scriptPubKey[0] == OP_RETURN &&
  ------------------
  |  Branch (162:17): [True: 10.2k, False: 4.45k]
  ------------------
  163|  10.2k|                vout.scriptPubKey[1] == 0x24 &&
  ------------------
  |  Branch (163:17): [True: 9.94k, False: 303]
  ------------------
  164|  9.94k|                vout.scriptPubKey[2] == 0xaa &&
  ------------------
  |  Branch (164:17): [True: 9.85k, False: 98]
  ------------------
  165|  9.85k|                vout.scriptPubKey[3] == 0x21 &&
  ------------------
  |  Branch (165:17): [True: 9.64k, False: 206]
  ------------------
  166|  9.64k|                vout.scriptPubKey[4] == 0xa9 &&
  ------------------
  |  Branch (166:17): [True: 9.55k, False: 90]
  ------------------
  167|  9.55k|                vout.scriptPubKey[5] == 0xed) {
  ------------------
  |  Branch (167:17): [True: 9.20k, False: 354]
  ------------------
  168|  9.20k|                commitpos = o;
  169|  9.20k|            }
  170|   281k|        }
  171|  9.42k|    }
  172|  9.42k|    return commitpos;
  173|  9.42k|}

_ZN15ChaCha20AlignedD2Ev:
   42|      6|{
   43|      6|    memory_cleanse(input, sizeof(input));
   44|      6|}
_ZN8ChaCha20D2Ev:
  332|      6|{
  333|      6|    memory_cleanse(m_buffer.data(), m_buffer.size());
  334|      6|}

_Z9WriteLE16ITk8ByteTypehEvPT_t:
   44|  2.35k|{
   45|  2.35k|    uint16_t v = htole16_internal(x);
   46|  2.35k|    memcpy(ptr, &v, 2);
   47|  2.35k|}
_Z8ReadLE16ITk8ByteTypehEtPKT_:
   20|  2.83k|{
   21|  2.83k|    uint16_t x;
   22|  2.83k|    memcpy(&x, ptr, 2);
   23|  2.83k|    return le16toh_internal(x);
   24|  2.83k|}
_Z8ReadLE32ITk8ByteTypehEjPKT_:
   28|  25.3k|{
   29|  25.3k|    uint32_t x;
   30|  25.3k|    memcpy(&x, ptr, 4);
   31|  25.3k|    return le32toh_internal(x);
   32|  25.3k|}
_Z9WriteLE32ITk8ByteTypehEvPT_j:
   51|  7.55k|{
   52|  7.55k|    uint32_t v = htole32_internal(x);
   53|  7.55k|    memcpy(ptr, &v, 4);
   54|  7.55k|}
_Z8ReadBE32ITk8ByteTypehEjPKT_:
   73|  12.9k|{
   74|  12.9k|    uint32_t x;
   75|  12.9k|    memcpy(&x, ptr, 4);
   76|  12.9k|    return be32toh_internal(x);
   77|  12.9k|}
_Z9WriteBE32ITk8ByteTypehEvPT_j:
   96|  10.1M|{
   97|  10.1M|    uint32_t v = htobe32_internal(x);
   98|  10.1M|    memcpy(ptr, &v, 4);
   99|  10.1M|}
_Z9WriteLE64ITk8ByteTypehEvPT_m:
   58|  1.51k|{
   59|  1.51k|    uint64_t v = htole64_internal(x);
   60|  1.51k|    memcpy(ptr, &v, 8);
   61|  1.51k|}
_Z9WriteBE64ITk8ByteTypehEvPT_m:
  103|  1.26M|{
  104|  1.26M|    uint64_t v = htobe64_internal(x);
  105|  1.26M|    memcpy(ptr, &v, 8);
  106|  1.26M|}

_ZN10CRIPEMD160C2Ev:
  243|  1.51k|{
  244|  1.51k|    ripemd160::Initialize(s);
  245|  1.51k|}
_ZN10CRIPEMD1605WriteEPKhm:
  248|  4.53k|{
  249|  4.53k|    const unsigned char* end = data + len;
  250|  4.53k|    size_t bufsize = bytes % 64;
  251|  4.53k|    if (bufsize && bufsize + len >= 64) {
  ------------------
  |  Branch (251:9): [True: 2.98k, False: 1.54k]
  |  Branch (251:20): [True: 1.51k, False: 1.47k]
  ------------------
  252|       |        // Fill the buffer, and process it.
  253|  1.51k|        memcpy(buf + bufsize, data, 64 - bufsize);
  254|  1.51k|        bytes += 64 - bufsize;
  255|  1.51k|        data += 64 - bufsize;
  256|  1.51k|        ripemd160::Transform(s, buf);
  257|  1.51k|        bufsize = 0;
  258|  1.51k|    }
  259|  4.55k|    while (end - data >= 64) {
  ------------------
  |  Branch (259:12): [True: 21, False: 4.53k]
  ------------------
  260|       |        // Process full chunks directly from the source.
  261|     21|        ripemd160::Transform(s, data);
  262|     21|        bytes += 64;
  263|     21|        data += 64;
  264|     21|    }
  265|  4.53k|    if (end > data) {
  ------------------
  |  Branch (265:9): [True: 2.98k, False: 1.54k]
  ------------------
  266|       |        // Fill the buffer with what remains.
  267|  2.98k|        memcpy(buf + bufsize, data, end - data);
  268|  2.98k|        bytes += end - data;
  269|  2.98k|    }
  270|  4.53k|    return *this;
  271|  4.53k|}
_ZN10CRIPEMD1608FinalizeEPh:
  274|  1.51k|{
  275|  1.51k|    static const unsigned char pad[64] = {0x80};
  276|  1.51k|    unsigned char sizedesc[8];
  277|  1.51k|    WriteLE64(sizedesc, bytes << 3);
  278|  1.51k|    Write(pad, 1 + ((119 - (bytes % 64)) % 64));
  279|  1.51k|    Write(sizedesc, 8);
  280|  1.51k|    WriteLE32(hash, s[0]);
  281|  1.51k|    WriteLE32(hash + 4, s[1]);
  282|  1.51k|    WriteLE32(hash + 8, s[2]);
  283|  1.51k|    WriteLE32(hash + 12, s[3]);
  284|  1.51k|    WriteLE32(hash + 16, s[4]);
  285|  1.51k|}
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd16010InitializeEPj:
   25|  1.51k|{
   26|  1.51k|    s[0] = 0x67452301ul;
   27|  1.51k|    s[1] = 0xEFCDAB89ul;
   28|  1.51k|    s[2] = 0x98BADCFEul;
   29|  1.51k|    s[3] = 0x10325476ul;
   30|  1.51k|    s[4] = 0xC3D2E1F0ul;
   31|  1.51k|}
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1609TransformEPjPKh:
   55|  1.53k|{
   56|  1.53k|    uint32_t a1 = s[0], b1 = s[1], c1 = s[2], d1 = s[3], e1 = s[4];
   57|  1.53k|    uint32_t a2 = a1, b2 = b1, c2 = c1, d2 = d1, e2 = e1;
   58|  1.53k|    uint32_t w0 = ReadLE32(chunk + 0), w1 = ReadLE32(chunk + 4), w2 = ReadLE32(chunk + 8), w3 = ReadLE32(chunk + 12);
   59|  1.53k|    uint32_t w4 = ReadLE32(chunk + 16), w5 = ReadLE32(chunk + 20), w6 = ReadLE32(chunk + 24), w7 = ReadLE32(chunk + 28);
   60|  1.53k|    uint32_t w8 = ReadLE32(chunk + 32), w9 = ReadLE32(chunk + 36), w10 = ReadLE32(chunk + 40), w11 = ReadLE32(chunk + 44);
   61|  1.53k|    uint32_t w12 = ReadLE32(chunk + 48), w13 = ReadLE32(chunk + 52), w14 = ReadLE32(chunk + 56), w15 = ReadLE32(chunk + 60);
   62|       |
   63|  1.53k|    R11(a1, b1, c1, d1, e1, w0, 11);
   64|  1.53k|    R12(a2, b2, c2, d2, e2, w5, 8);
   65|  1.53k|    R11(e1, a1, b1, c1, d1, w1, 14);
   66|  1.53k|    R12(e2, a2, b2, c2, d2, w14, 9);
   67|  1.53k|    R11(d1, e1, a1, b1, c1, w2, 15);
   68|  1.53k|    R12(d2, e2, a2, b2, c2, w7, 9);
   69|  1.53k|    R11(c1, d1, e1, a1, b1, w3, 12);
   70|  1.53k|    R12(c2, d2, e2, a2, b2, w0, 11);
   71|  1.53k|    R11(b1, c1, d1, e1, a1, w4, 5);
   72|  1.53k|    R12(b2, c2, d2, e2, a2, w9, 13);
   73|  1.53k|    R11(a1, b1, c1, d1, e1, w5, 8);
   74|  1.53k|    R12(a2, b2, c2, d2, e2, w2, 15);
   75|  1.53k|    R11(e1, a1, b1, c1, d1, w6, 7);
   76|  1.53k|    R12(e2, a2, b2, c2, d2, w11, 15);
   77|  1.53k|    R11(d1, e1, a1, b1, c1, w7, 9);
   78|  1.53k|    R12(d2, e2, a2, b2, c2, w4, 5);
   79|  1.53k|    R11(c1, d1, e1, a1, b1, w8, 11);
   80|  1.53k|    R12(c2, d2, e2, a2, b2, w13, 7);
   81|  1.53k|    R11(b1, c1, d1, e1, a1, w9, 13);
   82|  1.53k|    R12(b2, c2, d2, e2, a2, w6, 7);
   83|  1.53k|    R11(a1, b1, c1, d1, e1, w10, 14);
   84|  1.53k|    R12(a2, b2, c2, d2, e2, w15, 8);
   85|  1.53k|    R11(e1, a1, b1, c1, d1, w11, 15);
   86|  1.53k|    R12(e2, a2, b2, c2, d2, w8, 11);
   87|  1.53k|    R11(d1, e1, a1, b1, c1, w12, 6);
   88|  1.53k|    R12(d2, e2, a2, b2, c2, w1, 14);
   89|  1.53k|    R11(c1, d1, e1, a1, b1, w13, 7);
   90|  1.53k|    R12(c2, d2, e2, a2, b2, w10, 14);
   91|  1.53k|    R11(b1, c1, d1, e1, a1, w14, 9);
   92|  1.53k|    R12(b2, c2, d2, e2, a2, w3, 12);
   93|  1.53k|    R11(a1, b1, c1, d1, e1, w15, 8);
   94|  1.53k|    R12(a2, b2, c2, d2, e2, w12, 6);
   95|       |
   96|  1.53k|    R21(e1, a1, b1, c1, d1, w7, 7);
   97|  1.53k|    R22(e2, a2, b2, c2, d2, w6, 9);
   98|  1.53k|    R21(d1, e1, a1, b1, c1, w4, 6);
   99|  1.53k|    R22(d2, e2, a2, b2, c2, w11, 13);
  100|  1.53k|    R21(c1, d1, e1, a1, b1, w13, 8);
  101|  1.53k|    R22(c2, d2, e2, a2, b2, w3, 15);
  102|  1.53k|    R21(b1, c1, d1, e1, a1, w1, 13);
  103|  1.53k|    R22(b2, c2, d2, e2, a2, w7, 7);
  104|  1.53k|    R21(a1, b1, c1, d1, e1, w10, 11);
  105|  1.53k|    R22(a2, b2, c2, d2, e2, w0, 12);
  106|  1.53k|    R21(e1, a1, b1, c1, d1, w6, 9);
  107|  1.53k|    R22(e2, a2, b2, c2, d2, w13, 8);
  108|  1.53k|    R21(d1, e1, a1, b1, c1, w15, 7);
  109|  1.53k|    R22(d2, e2, a2, b2, c2, w5, 9);
  110|  1.53k|    R21(c1, d1, e1, a1, b1, w3, 15);
  111|  1.53k|    R22(c2, d2, e2, a2, b2, w10, 11);
  112|  1.53k|    R21(b1, c1, d1, e1, a1, w12, 7);
  113|  1.53k|    R22(b2, c2, d2, e2, a2, w14, 7);
  114|  1.53k|    R21(a1, b1, c1, d1, e1, w0, 12);
  115|  1.53k|    R22(a2, b2, c2, d2, e2, w15, 7);
  116|  1.53k|    R21(e1, a1, b1, c1, d1, w9, 15);
  117|  1.53k|    R22(e2, a2, b2, c2, d2, w8, 12);
  118|  1.53k|    R21(d1, e1, a1, b1, c1, w5, 9);
  119|  1.53k|    R22(d2, e2, a2, b2, c2, w12, 7);
  120|  1.53k|    R21(c1, d1, e1, a1, b1, w2, 11);
  121|  1.53k|    R22(c2, d2, e2, a2, b2, w4, 6);
  122|  1.53k|    R21(b1, c1, d1, e1, a1, w14, 7);
  123|  1.53k|    R22(b2, c2, d2, e2, a2, w9, 15);
  124|  1.53k|    R21(a1, b1, c1, d1, e1, w11, 13);
  125|  1.53k|    R22(a2, b2, c2, d2, e2, w1, 13);
  126|  1.53k|    R21(e1, a1, b1, c1, d1, w8, 12);
  127|  1.53k|    R22(e2, a2, b2, c2, d2, w2, 11);
  128|       |
  129|  1.53k|    R31(d1, e1, a1, b1, c1, w3, 11);
  130|  1.53k|    R32(d2, e2, a2, b2, c2, w15, 9);
  131|  1.53k|    R31(c1, d1, e1, a1, b1, w10, 13);
  132|  1.53k|    R32(c2, d2, e2, a2, b2, w5, 7);
  133|  1.53k|    R31(b1, c1, d1, e1, a1, w14, 6);
  134|  1.53k|    R32(b2, c2, d2, e2, a2, w1, 15);
  135|  1.53k|    R31(a1, b1, c1, d1, e1, w4, 7);
  136|  1.53k|    R32(a2, b2, c2, d2, e2, w3, 11);
  137|  1.53k|    R31(e1, a1, b1, c1, d1, w9, 14);
  138|  1.53k|    R32(e2, a2, b2, c2, d2, w7, 8);
  139|  1.53k|    R31(d1, e1, a1, b1, c1, w15, 9);
  140|  1.53k|    R32(d2, e2, a2, b2, c2, w14, 6);
  141|  1.53k|    R31(c1, d1, e1, a1, b1, w8, 13);
  142|  1.53k|    R32(c2, d2, e2, a2, b2, w6, 6);
  143|  1.53k|    R31(b1, c1, d1, e1, a1, w1, 15);
  144|  1.53k|    R32(b2, c2, d2, e2, a2, w9, 14);
  145|  1.53k|    R31(a1, b1, c1, d1, e1, w2, 14);
  146|  1.53k|    R32(a2, b2, c2, d2, e2, w11, 12);
  147|  1.53k|    R31(e1, a1, b1, c1, d1, w7, 8);
  148|  1.53k|    R32(e2, a2, b2, c2, d2, w8, 13);
  149|  1.53k|    R31(d1, e1, a1, b1, c1, w0, 13);
  150|  1.53k|    R32(d2, e2, a2, b2, c2, w12, 5);
  151|  1.53k|    R31(c1, d1, e1, a1, b1, w6, 6);
  152|  1.53k|    R32(c2, d2, e2, a2, b2, w2, 14);
  153|  1.53k|    R31(b1, c1, d1, e1, a1, w13, 5);
  154|  1.53k|    R32(b2, c2, d2, e2, a2, w10, 13);
  155|  1.53k|    R31(a1, b1, c1, d1, e1, w11, 12);
  156|  1.53k|    R32(a2, b2, c2, d2, e2, w0, 13);
  157|  1.53k|    R31(e1, a1, b1, c1, d1, w5, 7);
  158|  1.53k|    R32(e2, a2, b2, c2, d2, w4, 7);
  159|  1.53k|    R31(d1, e1, a1, b1, c1, w12, 5);
  160|  1.53k|    R32(d2, e2, a2, b2, c2, w13, 5);
  161|       |
  162|  1.53k|    R41(c1, d1, e1, a1, b1, w1, 11);
  163|  1.53k|    R42(c2, d2, e2, a2, b2, w8, 15);
  164|  1.53k|    R41(b1, c1, d1, e1, a1, w9, 12);
  165|  1.53k|    R42(b2, c2, d2, e2, a2, w6, 5);
  166|  1.53k|    R41(a1, b1, c1, d1, e1, w11, 14);
  167|  1.53k|    R42(a2, b2, c2, d2, e2, w4, 8);
  168|  1.53k|    R41(e1, a1, b1, c1, d1, w10, 15);
  169|  1.53k|    R42(e2, a2, b2, c2, d2, w1, 11);
  170|  1.53k|    R41(d1, e1, a1, b1, c1, w0, 14);
  171|  1.53k|    R42(d2, e2, a2, b2, c2, w3, 14);
  172|  1.53k|    R41(c1, d1, e1, a1, b1, w8, 15);
  173|  1.53k|    R42(c2, d2, e2, a2, b2, w11, 14);
  174|  1.53k|    R41(b1, c1, d1, e1, a1, w12, 9);
  175|  1.53k|    R42(b2, c2, d2, e2, a2, w15, 6);
  176|  1.53k|    R41(a1, b1, c1, d1, e1, w4, 8);
  177|  1.53k|    R42(a2, b2, c2, d2, e2, w0, 14);
  178|  1.53k|    R41(e1, a1, b1, c1, d1, w13, 9);
  179|  1.53k|    R42(e2, a2, b2, c2, d2, w5, 6);
  180|  1.53k|    R41(d1, e1, a1, b1, c1, w3, 14);
  181|  1.53k|    R42(d2, e2, a2, b2, c2, w12, 9);
  182|  1.53k|    R41(c1, d1, e1, a1, b1, w7, 5);
  183|  1.53k|    R42(c2, d2, e2, a2, b2, w2, 12);
  184|  1.53k|    R41(b1, c1, d1, e1, a1, w15, 6);
  185|  1.53k|    R42(b2, c2, d2, e2, a2, w13, 9);
  186|  1.53k|    R41(a1, b1, c1, d1, e1, w14, 8);
  187|  1.53k|    R42(a2, b2, c2, d2, e2, w9, 12);
  188|  1.53k|    R41(e1, a1, b1, c1, d1, w5, 6);
  189|  1.53k|    R42(e2, a2, b2, c2, d2, w7, 5);
  190|  1.53k|    R41(d1, e1, a1, b1, c1, w6, 5);
  191|  1.53k|    R42(d2, e2, a2, b2, c2, w10, 15);
  192|  1.53k|    R41(c1, d1, e1, a1, b1, w2, 12);
  193|  1.53k|    R42(c2, d2, e2, a2, b2, w14, 8);
  194|       |
  195|  1.53k|    R51(b1, c1, d1, e1, a1, w4, 9);
  196|  1.53k|    R52(b2, c2, d2, e2, a2, w12, 8);
  197|  1.53k|    R51(a1, b1, c1, d1, e1, w0, 15);
  198|  1.53k|    R52(a2, b2, c2, d2, e2, w15, 5);
  199|  1.53k|    R51(e1, a1, b1, c1, d1, w5, 5);
  200|  1.53k|    R52(e2, a2, b2, c2, d2, w10, 12);
  201|  1.53k|    R51(d1, e1, a1, b1, c1, w9, 11);
  202|  1.53k|    R52(d2, e2, a2, b2, c2, w4, 9);
  203|  1.53k|    R51(c1, d1, e1, a1, b1, w7, 6);
  204|  1.53k|    R52(c2, d2, e2, a2, b2, w1, 12);
  205|  1.53k|    R51(b1, c1, d1, e1, a1, w12, 8);
  206|  1.53k|    R52(b2, c2, d2, e2, a2, w5, 5);
  207|  1.53k|    R51(a1, b1, c1, d1, e1, w2, 13);
  208|  1.53k|    R52(a2, b2, c2, d2, e2, w8, 14);
  209|  1.53k|    R51(e1, a1, b1, c1, d1, w10, 12);
  210|  1.53k|    R52(e2, a2, b2, c2, d2, w7, 6);
  211|  1.53k|    R51(d1, e1, a1, b1, c1, w14, 5);
  212|  1.53k|    R52(d2, e2, a2, b2, c2, w6, 8);
  213|  1.53k|    R51(c1, d1, e1, a1, b1, w1, 12);
  214|  1.53k|    R52(c2, d2, e2, a2, b2, w2, 13);
  215|  1.53k|    R51(b1, c1, d1, e1, a1, w3, 13);
  216|  1.53k|    R52(b2, c2, d2, e2, a2, w13, 6);
  217|  1.53k|    R51(a1, b1, c1, d1, e1, w8, 14);
  218|  1.53k|    R52(a2, b2, c2, d2, e2, w14, 5);
  219|  1.53k|    R51(e1, a1, b1, c1, d1, w11, 11);
  220|  1.53k|    R52(e2, a2, b2, c2, d2, w0, 15);
  221|  1.53k|    R51(d1, e1, a1, b1, c1, w6, 8);
  222|  1.53k|    R52(d2, e2, a2, b2, c2, w3, 13);
  223|  1.53k|    R51(c1, d1, e1, a1, b1, w15, 5);
  224|  1.53k|    R52(c2, d2, e2, a2, b2, w9, 11);
  225|  1.53k|    R51(b1, c1, d1, e1, a1, w13, 6);
  226|  1.53k|    R52(b2, c2, d2, e2, a2, w11, 11);
  227|       |
  228|  1.53k|    uint32_t t = s[0];
  229|  1.53k|    s[0] = s[1] + c1 + d2;
  230|  1.53k|    s[1] = s[2] + d1 + e2;
  231|  1.53k|    s[2] = s[3] + e1 + a2;
  232|  1.53k|    s[3] = s[4] + a1 + b2;
  233|  1.53k|    s[4] = t + b1 + c2;
  234|  1.53k|}
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R11ERjjS1_jjji:
   41|  24.5k|void inline R11(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f1(b, c, d), x, 0, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1605RoundERjjS1_jjjjji:
   36|   245k|{
   37|   245k|    a = rol(a + f + x + k, r) + e;
   38|   245k|    c = rol(c, 10);
   39|   245k|}
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603rolEji:
   33|   491k|uint32_t inline rol(uint32_t x, int i) { return (x << i) | (x >> (32 - i)); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1602f1Ejjj:
   17|  49.1k|uint32_t inline f1(uint32_t x, uint32_t y, uint32_t z) { return x ^ y ^ z; }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R12ERjjS1_jjji:
   47|  24.5k|void inline R12(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f5(b, c, d), x, 0x50A28BE6ul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1602f5Ejjj:
   21|  49.1k|uint32_t inline f5(uint32_t x, uint32_t y, uint32_t z) { return x ^ (y | ~z); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R21ERjjS1_jjji:
   42|  24.5k|void inline R21(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f2(b, c, d), x, 0x5A827999ul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1602f2Ejjj:
   18|  49.1k|uint32_t inline f2(uint32_t x, uint32_t y, uint32_t z) { return (x & y) | (~x & z); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R22ERjjS1_jjji:
   48|  24.5k|void inline R22(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f4(b, c, d), x, 0x5C4DD124ul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1602f4Ejjj:
   20|  49.1k|uint32_t inline f4(uint32_t x, uint32_t y, uint32_t z) { return (x & z) | (y & ~z); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R31ERjjS1_jjji:
   43|  24.5k|void inline R31(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f3(b, c, d), x, 0x6ED9EBA1ul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1602f3Ejjj:
   19|  49.1k|uint32_t inline f3(uint32_t x, uint32_t y, uint32_t z) { return (x | ~y) ^ z; }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R32ERjjS1_jjji:
   49|  24.5k|void inline R32(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f3(b, c, d), x, 0x6D703EF3ul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R41ERjjS1_jjji:
   44|  24.5k|void inline R41(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f4(b, c, d), x, 0x8F1BBCDCul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R42ERjjS1_jjji:
   50|  24.5k|void inline R42(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f2(b, c, d), x, 0x7A6D76E9ul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R51ERjjS1_jjji:
   45|  24.5k|void inline R51(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f5(b, c, d), x, 0xA953FD4Eul, r); }
ripemd160.cpp:_ZN12_GLOBAL__N_19ripemd1603R52ERjjS1_jjji:
   51|  24.5k|void inline R52(uint32_t& a, uint32_t b, uint32_t& c, uint32_t d, uint32_t e, uint32_t x, int r) { Round(a, b, c, d, e, f1(b, c, d), x, 0, r); }

_ZN5CSHA1C2Ev:
  150|    758|{
  151|    758|    sha1::Initialize(s);
  152|    758|}
_ZN5CSHA15WriteEPKhm:
  155|  2.27k|{
  156|  2.27k|    const unsigned char* end = data + len;
  157|  2.27k|    size_t bufsize = bytes % 64;
  158|  2.27k|    if (bufsize && bufsize + len >= 64) {
  ------------------
  |  Branch (158:9): [True: 1.47k, False: 800]
  |  Branch (158:20): [True: 759, False: 715]
  ------------------
  159|       |        // Fill the buffer, and process it.
  160|    759|        memcpy(buf + bufsize, data, 64 - bufsize);
  161|    759|        bytes += 64 - bufsize;
  162|    759|        data += 64 - bufsize;
  163|    759|        sha1::Transform(s, buf);
  164|    759|        bufsize = 0;
  165|    759|    }
  166|  2.32k|    while (end - data >= 64) {
  ------------------
  |  Branch (166:12): [True: 48, False: 2.27k]
  ------------------
  167|       |        // Process full chunks directly from the source.
  168|     48|        sha1::Transform(s, data);
  169|     48|        bytes += 64;
  170|     48|        data += 64;
  171|     48|    }
  172|  2.27k|    if (end > data) {
  ------------------
  |  Branch (172:9): [True: 1.47k, False: 800]
  ------------------
  173|       |        // Fill the buffer with what remains.
  174|  1.47k|        memcpy(buf + bufsize, data, end - data);
  175|  1.47k|        bytes += end - data;
  176|  1.47k|    }
  177|  2.27k|    return *this;
  178|  2.27k|}
_ZN5CSHA18FinalizeEPh:
  181|    758|{
  182|    758|    static const unsigned char pad[64] = {0x80};
  183|    758|    unsigned char sizedesc[8];
  184|    758|    WriteBE64(sizedesc, bytes << 3);
  185|    758|    Write(pad, 1 + ((119 - (bytes % 64)) % 64));
  186|    758|    Write(sizedesc, 8);
  187|    758|    WriteBE32(hash, s[0]);
  188|    758|    WriteBE32(hash + 4, s[1]);
  189|    758|    WriteBE32(hash + 8, s[2]);
  190|    758|    WriteBE32(hash + 12, s[3]);
  191|    758|    WriteBE32(hash + 16, s[4]);
  192|    758|}
sha1.cpp:_ZN12_GLOBAL__N_14sha110InitializeEPj:
   32|    758|{
   33|    758|    s[0] = 0x67452301ul;
   34|    758|    s[1] = 0xEFCDAB89ul;
   35|    758|    s[2] = 0x98BADCFEul;
   36|    758|    s[3] = 0x10325476ul;
   37|    758|    s[4] = 0xC3D2E1F0ul;
   38|    758|}
sha1.cpp:_ZN12_GLOBAL__N_14sha19TransformEPjPKh:
   47|    807|{
   48|    807|    uint32_t a = s[0], b = s[1], c = s[2], d = s[3], e = s[4];
   49|    807|    uint32_t w0, w1, w2, w3, w4, w5, w6, w7, w8, w9, w10, w11, w12, w13, w14, w15;
   50|       |
   51|    807|    Round(a, b, c, d, e, f1(b, c, d), k1, w0 = ReadBE32(chunk + 0));
   52|    807|    Round(e, a, b, c, d, f1(a, b, c), k1, w1 = ReadBE32(chunk + 4));
   53|    807|    Round(d, e, a, b, c, f1(e, a, b), k1, w2 = ReadBE32(chunk + 8));
   54|    807|    Round(c, d, e, a, b, f1(d, e, a), k1, w3 = ReadBE32(chunk + 12));
   55|    807|    Round(b, c, d, e, a, f1(c, d, e), k1, w4 = ReadBE32(chunk + 16));
   56|    807|    Round(a, b, c, d, e, f1(b, c, d), k1, w5 = ReadBE32(chunk + 20));
   57|    807|    Round(e, a, b, c, d, f1(a, b, c), k1, w6 = ReadBE32(chunk + 24));
   58|    807|    Round(d, e, a, b, c, f1(e, a, b), k1, w7 = ReadBE32(chunk + 28));
   59|    807|    Round(c, d, e, a, b, f1(d, e, a), k1, w8 = ReadBE32(chunk + 32));
   60|    807|    Round(b, c, d, e, a, f1(c, d, e), k1, w9 = ReadBE32(chunk + 36));
   61|    807|    Round(a, b, c, d, e, f1(b, c, d), k1, w10 = ReadBE32(chunk + 40));
   62|    807|    Round(e, a, b, c, d, f1(a, b, c), k1, w11 = ReadBE32(chunk + 44));
   63|    807|    Round(d, e, a, b, c, f1(e, a, b), k1, w12 = ReadBE32(chunk + 48));
   64|    807|    Round(c, d, e, a, b, f1(d, e, a), k1, w13 = ReadBE32(chunk + 52));
   65|    807|    Round(b, c, d, e, a, f1(c, d, e), k1, w14 = ReadBE32(chunk + 56));
   66|    807|    Round(a, b, c, d, e, f1(b, c, d), k1, w15 = ReadBE32(chunk + 60));
   67|       |
   68|    807|    Round(e, a, b, c, d, f1(a, b, c), k1, w0 = left(w0 ^ w13 ^ w8 ^ w2));
   69|    807|    Round(d, e, a, b, c, f1(e, a, b), k1, w1 = left(w1 ^ w14 ^ w9 ^ w3));
   70|    807|    Round(c, d, e, a, b, f1(d, e, a), k1, w2 = left(w2 ^ w15 ^ w10 ^ w4));
   71|    807|    Round(b, c, d, e, a, f1(c, d, e), k1, w3 = left(w3 ^ w0 ^ w11 ^ w5));
   72|    807|    Round(a, b, c, d, e, f2(b, c, d), k2, w4 = left(w4 ^ w1 ^ w12 ^ w6));
   73|    807|    Round(e, a, b, c, d, f2(a, b, c), k2, w5 = left(w5 ^ w2 ^ w13 ^ w7));
   74|    807|    Round(d, e, a, b, c, f2(e, a, b), k2, w6 = left(w6 ^ w3 ^ w14 ^ w8));
   75|    807|    Round(c, d, e, a, b, f2(d, e, a), k2, w7 = left(w7 ^ w4 ^ w15 ^ w9));
   76|    807|    Round(b, c, d, e, a, f2(c, d, e), k2, w8 = left(w8 ^ w5 ^ w0 ^ w10));
   77|    807|    Round(a, b, c, d, e, f2(b, c, d), k2, w9 = left(w9 ^ w6 ^ w1 ^ w11));
   78|    807|    Round(e, a, b, c, d, f2(a, b, c), k2, w10 = left(w10 ^ w7 ^ w2 ^ w12));
   79|    807|    Round(d, e, a, b, c, f2(e, a, b), k2, w11 = left(w11 ^ w8 ^ w3 ^ w13));
   80|    807|    Round(c, d, e, a, b, f2(d, e, a), k2, w12 = left(w12 ^ w9 ^ w4 ^ w14));
   81|    807|    Round(b, c, d, e, a, f2(c, d, e), k2, w13 = left(w13 ^ w10 ^ w5 ^ w15));
   82|    807|    Round(a, b, c, d, e, f2(b, c, d), k2, w14 = left(w14 ^ w11 ^ w6 ^ w0));
   83|    807|    Round(e, a, b, c, d, f2(a, b, c), k2, w15 = left(w15 ^ w12 ^ w7 ^ w1));
   84|       |
   85|    807|    Round(d, e, a, b, c, f2(e, a, b), k2, w0 = left(w0 ^ w13 ^ w8 ^ w2));
   86|    807|    Round(c, d, e, a, b, f2(d, e, a), k2, w1 = left(w1 ^ w14 ^ w9 ^ w3));
   87|    807|    Round(b, c, d, e, a, f2(c, d, e), k2, w2 = left(w2 ^ w15 ^ w10 ^ w4));
   88|    807|    Round(a, b, c, d, e, f2(b, c, d), k2, w3 = left(w3 ^ w0 ^ w11 ^ w5));
   89|    807|    Round(e, a, b, c, d, f2(a, b, c), k2, w4 = left(w4 ^ w1 ^ w12 ^ w6));
   90|    807|    Round(d, e, a, b, c, f2(e, a, b), k2, w5 = left(w5 ^ w2 ^ w13 ^ w7));
   91|    807|    Round(c, d, e, a, b, f2(d, e, a), k2, w6 = left(w6 ^ w3 ^ w14 ^ w8));
   92|    807|    Round(b, c, d, e, a, f2(c, d, e), k2, w7 = left(w7 ^ w4 ^ w15 ^ w9));
   93|    807|    Round(a, b, c, d, e, f3(b, c, d), k3, w8 = left(w8 ^ w5 ^ w0 ^ w10));
   94|    807|    Round(e, a, b, c, d, f3(a, b, c), k3, w9 = left(w9 ^ w6 ^ w1 ^ w11));
   95|    807|    Round(d, e, a, b, c, f3(e, a, b), k3, w10 = left(w10 ^ w7 ^ w2 ^ w12));
   96|    807|    Round(c, d, e, a, b, f3(d, e, a), k3, w11 = left(w11 ^ w8 ^ w3 ^ w13));
   97|    807|    Round(b, c, d, e, a, f3(c, d, e), k3, w12 = left(w12 ^ w9 ^ w4 ^ w14));
   98|    807|    Round(a, b, c, d, e, f3(b, c, d), k3, w13 = left(w13 ^ w10 ^ w5 ^ w15));
   99|    807|    Round(e, a, b, c, d, f3(a, b, c), k3, w14 = left(w14 ^ w11 ^ w6 ^ w0));
  100|    807|    Round(d, e, a, b, c, f3(e, a, b), k3, w15 = left(w15 ^ w12 ^ w7 ^ w1));
  101|       |
  102|    807|    Round(c, d, e, a, b, f3(d, e, a), k3, w0 = left(w0 ^ w13 ^ w8 ^ w2));
  103|    807|    Round(b, c, d, e, a, f3(c, d, e), k3, w1 = left(w1 ^ w14 ^ w9 ^ w3));
  104|    807|    Round(a, b, c, d, e, f3(b, c, d), k3, w2 = left(w2 ^ w15 ^ w10 ^ w4));
  105|    807|    Round(e, a, b, c, d, f3(a, b, c), k3, w3 = left(w3 ^ w0 ^ w11 ^ w5));
  106|    807|    Round(d, e, a, b, c, f3(e, a, b), k3, w4 = left(w4 ^ w1 ^ w12 ^ w6));
  107|    807|    Round(c, d, e, a, b, f3(d, e, a), k3, w5 = left(w5 ^ w2 ^ w13 ^ w7));
  108|    807|    Round(b, c, d, e, a, f3(c, d, e), k3, w6 = left(w6 ^ w3 ^ w14 ^ w8));
  109|    807|    Round(a, b, c, d, e, f3(b, c, d), k3, w7 = left(w7 ^ w4 ^ w15 ^ w9));
  110|    807|    Round(e, a, b, c, d, f3(a, b, c), k3, w8 = left(w8 ^ w5 ^ w0 ^ w10));
  111|    807|    Round(d, e, a, b, c, f3(e, a, b), k3, w9 = left(w9 ^ w6 ^ w1 ^ w11));
  112|    807|    Round(c, d, e, a, b, f3(d, e, a), k3, w10 = left(w10 ^ w7 ^ w2 ^ w12));
  113|    807|    Round(b, c, d, e, a, f3(c, d, e), k3, w11 = left(w11 ^ w8 ^ w3 ^ w13));
  114|    807|    Round(a, b, c, d, e, f2(b, c, d), k4, w12 = left(w12 ^ w9 ^ w4 ^ w14));
  115|    807|    Round(e, a, b, c, d, f2(a, b, c), k4, w13 = left(w13 ^ w10 ^ w5 ^ w15));
  116|    807|    Round(d, e, a, b, c, f2(e, a, b), k4, w14 = left(w14 ^ w11 ^ w6 ^ w0));
  117|    807|    Round(c, d, e, a, b, f2(d, e, a), k4, w15 = left(w15 ^ w12 ^ w7 ^ w1));
  118|       |
  119|    807|    Round(b, c, d, e, a, f2(c, d, e), k4, w0 = left(w0 ^ w13 ^ w8 ^ w2));
  120|    807|    Round(a, b, c, d, e, f2(b, c, d), k4, w1 = left(w1 ^ w14 ^ w9 ^ w3));
  121|    807|    Round(e, a, b, c, d, f2(a, b, c), k4, w2 = left(w2 ^ w15 ^ w10 ^ w4));
  122|    807|    Round(d, e, a, b, c, f2(e, a, b), k4, w3 = left(w3 ^ w0 ^ w11 ^ w5));
  123|    807|    Round(c, d, e, a, b, f2(d, e, a), k4, w4 = left(w4 ^ w1 ^ w12 ^ w6));
  124|    807|    Round(b, c, d, e, a, f2(c, d, e), k4, w5 = left(w5 ^ w2 ^ w13 ^ w7));
  125|    807|    Round(a, b, c, d, e, f2(b, c, d), k4, w6 = left(w6 ^ w3 ^ w14 ^ w8));
  126|    807|    Round(e, a, b, c, d, f2(a, b, c), k4, w7 = left(w7 ^ w4 ^ w15 ^ w9));
  127|    807|    Round(d, e, a, b, c, f2(e, a, b), k4, w8 = left(w8 ^ w5 ^ w0 ^ w10));
  128|    807|    Round(c, d, e, a, b, f2(d, e, a), k4, w9 = left(w9 ^ w6 ^ w1 ^ w11));
  129|    807|    Round(b, c, d, e, a, f2(c, d, e), k4, w10 = left(w10 ^ w7 ^ w2 ^ w12));
  130|    807|    Round(a, b, c, d, e, f2(b, c, d), k4, w11 = left(w11 ^ w8 ^ w3 ^ w13));
  131|    807|    Round(e, a, b, c, d, f2(a, b, c), k4, w12 = left(w12 ^ w9 ^ w4 ^ w14));
  132|    807|    Round(d, e, a, b, c, f2(e, a, b), k4, left(w13 ^ w10 ^ w5 ^ w15));
  133|    807|    Round(c, d, e, a, b, f2(d, e, a), k4, left(w14 ^ w11 ^ w6 ^ w0));
  134|    807|    Round(b, c, d, e, a, f2(c, d, e), k4, left(w15 ^ w12 ^ w7 ^ w1));
  135|       |
  136|    807|    s[0] += a;
  137|    807|    s[1] += b;
  138|    807|    s[2] += c;
  139|    807|    s[3] += d;
  140|    807|    s[4] += e;
  141|    807|}
sha1.cpp:_ZN12_GLOBAL__N_14sha15RoundEjRjjjS1_jjj:
   19|  64.5k|{
   20|  64.5k|    e += ((a << 5) | (a >> 27)) + f + k + w;
   21|  64.5k|    b = (b << 30) | (b >> 2);
   22|  64.5k|}
sha1.cpp:_ZN12_GLOBAL__N_14sha12f1Ejjj:
   24|  16.1k|uint32_t inline f1(uint32_t b, uint32_t c, uint32_t d) { return d ^ (b & (c ^ d)); }
sha1.cpp:_ZN12_GLOBAL__N_14sha14leftEj:
   28|  51.6k|uint32_t inline left(uint32_t x) { return (x << 1) | (x >> 31); }
sha1.cpp:_ZN12_GLOBAL__N_14sha12f2Ejjj:
   25|  32.2k|uint32_t inline f2(uint32_t b, uint32_t c, uint32_t d) { return b ^ c ^ d; }
sha1.cpp:_ZN12_GLOBAL__N_14sha12f3Ejjj:
   26|  16.1k|uint32_t inline f3(uint32_t b, uint32_t c, uint32_t d) { return (b & c) | (d & (b | c)); }

_ZN7CSHA256C2Ev:
  695|   636k|{
  696|   636k|    sha256::Initialize(s);
  697|   636k|}
_ZN7CSHA2565WriteEPKhm:
  700|  7.07M|{
  701|  7.07M|    const unsigned char* end = data + len;
  702|  7.07M|    size_t bufsize = bytes % 64;
  703|  7.07M|    if (bufsize && bufsize + len >= 64) {
  ------------------
  |  Branch (703:9): [True: 5.79M, False: 1.28M]
  |  Branch (703:20): [True: 1.43M, False: 4.36M]
  ------------------
  704|       |        // Fill the buffer, and process it.
  705|  1.43M|        memcpy(buf + bufsize, data, 64 - bufsize);
  706|  1.43M|        bytes += 64 - bufsize;
  707|  1.43M|        data += 64 - bufsize;
  708|  1.43M|        Transform(s, buf, 1);
  709|  1.43M|        bufsize = 0;
  710|  1.43M|    }
  711|  7.07M|    if (end - data >= 64) {
  ------------------
  |  Branch (711:9): [True: 12.6k, False: 7.06M]
  ------------------
  712|  12.6k|        size_t blocks = (end - data) / 64;
  713|  12.6k|        Transform(s, data, blocks);
  714|  12.6k|        data += 64 * blocks;
  715|  12.6k|        bytes += 64 * blocks;
  716|  12.6k|    }
  717|  7.07M|    if (end > data) {
  ------------------
  |  Branch (717:9): [True: 5.78M, False: 1.29M]
  ------------------
  718|       |        // Fill the buffer with what remains.
  719|  5.78M|        memcpy(buf + bufsize, data, end - data);
  720|  5.78M|        bytes += end - data;
  721|  5.78M|    }
  722|  7.07M|    return *this;
  723|  7.07M|}
_ZN7CSHA2568FinalizeEPh:
  726|  1.26M|{
  727|  1.26M|    static const unsigned char pad[64] = {0x80};
  728|  1.26M|    unsigned char sizedesc[8];
  729|  1.26M|    WriteBE64(sizedesc, bytes << 3);
  730|  1.26M|    Write(pad, 1 + ((119 - (bytes % 64)) % 64));
  731|  1.26M|    Write(sizedesc, 8);
  732|  1.26M|    WriteBE32(hash, s[0]);
  733|  1.26M|    WriteBE32(hash + 4, s[1]);
  734|  1.26M|    WriteBE32(hash + 8, s[2]);
  735|  1.26M|    WriteBE32(hash + 12, s[3]);
  736|  1.26M|    WriteBE32(hash + 16, s[4]);
  737|  1.26M|    WriteBE32(hash + 20, s[5]);
  738|  1.26M|    WriteBE32(hash + 24, s[6]);
  739|  1.26M|    WriteBE32(hash + 28, s[7]);
  740|  1.26M|}
_ZN7CSHA2565ResetEv:
  743|   630k|{
  744|   630k|    bytes = 0;
  745|   630k|    sha256::Initialize(s);
  746|   630k|    return *this;
  747|   630k|}
_Z9SHA256D64PhPKhm:
  750|    744|{
  751|    744|    if (TransformD64_8way) {
  ------------------
  |  Branch (751:9): [True: 0, False: 744]
  ------------------
  752|      0|        while (blocks >= 8) {
  ------------------
  |  Branch (752:16): [True: 0, False: 0]
  ------------------
  753|      0|            TransformD64_8way(out, in);
  754|      0|            out += 256;
  755|      0|            in += 512;
  756|      0|            blocks -= 8;
  757|      0|        }
  758|      0|    }
  759|    744|    if (TransformD64_4way) {
  ------------------
  |  Branch (759:9): [True: 0, False: 744]
  ------------------
  760|      0|        while (blocks >= 4) {
  ------------------
  |  Branch (760:16): [True: 0, False: 0]
  ------------------
  761|      0|            TransformD64_4way(out, in);
  762|      0|            out += 128;
  763|      0|            in += 256;
  764|      0|            blocks -= 4;
  765|      0|        }
  766|      0|    }
  767|    744|    if (TransformD64_2way) {
  ------------------
  |  Branch (767:9): [True: 744, False: 0]
  ------------------
  768|   368k|        while (blocks >= 2) {
  ------------------
  |  Branch (768:16): [True: 367k, False: 744]
  ------------------
  769|   367k|            TransformD64_2way(out, in);
  770|   367k|            out += 64;
  771|   367k|            in += 128;
  772|   367k|            blocks -= 2;
  773|   367k|        }
  774|    744|    }
  775|  1.05k|    while (blocks) {
  ------------------
  |  Branch (775:12): [True: 313, False: 744]
  ------------------
  776|    313|        TransformD64(out, in);
  777|    313|        out += 32;
  778|    313|        in += 64;
  779|    313|        --blocks;
  780|    313|    }
  781|    744|}
sha256.cpp:_ZN12_GLOBAL__N_16sha25610InitializeEPj:
   87|  1.26M|{
   88|  1.26M|    s[0] = 0x6a09e667ul;
   89|  1.26M|    s[1] = 0xbb67ae85ul;
   90|  1.26M|    s[2] = 0x3c6ef372ul;
   91|  1.26M|    s[3] = 0xa54ff53aul;
   92|  1.26M|    s[4] = 0x510e527ful;
   93|  1.26M|    s[5] = 0x9b05688cul;
   94|  1.26M|    s[6] = 0x1f83d9abul;
   95|  1.26M|    s[7] = 0x5be0cd19ul;
   96|  1.26M|}
sha256.cpp:_ZN12_GLOBAL__N_119TransformD64WrapperIXadL_ZN16sha256_x86_shani9TransformEPjPKhmEEEEvPhS4_:
  443|    313|{
  444|    313|    uint32_t s[8];
  445|    313|    static const unsigned char padding1[64] = {
  446|    313|        0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  447|    313|        0,    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  448|    313|        0,    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  449|    313|        0,    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 2, 0
  450|    313|    };
  451|    313|    unsigned char buffer2[64] = {
  452|    313|        0,    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  453|    313|        0,    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  454|    313|        0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  455|    313|        0,    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1, 0
  456|    313|    };
  457|    313|    sha256::Initialize(s);
  458|    313|    tr(s, in, 1);
  459|    313|    tr(s, padding1, 1);
  460|    313|    WriteBE32(buffer2 + 0, s[0]);
  461|    313|    WriteBE32(buffer2 + 4, s[1]);
  462|    313|    WriteBE32(buffer2 + 8, s[2]);
  463|    313|    WriteBE32(buffer2 + 12, s[3]);
  464|    313|    WriteBE32(buffer2 + 16, s[4]);
  465|    313|    WriteBE32(buffer2 + 20, s[5]);
  466|    313|    WriteBE32(buffer2 + 24, s[6]);
  467|    313|    WriteBE32(buffer2 + 28, s[7]);
  468|    313|    sha256::Initialize(s);
  469|    313|    tr(s, buffer2, 1);
  470|    313|    WriteBE32(out + 0, s[0]);
  471|    313|    WriteBE32(out + 4, s[1]);
  472|    313|    WriteBE32(out + 8, s[2]);
  473|    313|    WriteBE32(out + 12, s[3]);
  474|    313|    WriteBE32(out + 16, s[4]);
  475|    313|    WriteBE32(out + 20, s[5]);
  476|    313|    WriteBE32(out + 24, s[6]);
  477|    313|    WriteBE32(out + 28, s[7]);
  478|    313|}

_ZN16sha256_x86_shani9TransformEPjPKhm:
   82|  1.44M|{
   83|  1.44M|    __m128i m0, m1, m2, m3, s0, s1, so0, so1;
   84|       |
   85|       |    /* Load state */
   86|  1.44M|    s0 = _mm_loadu_si128((const __m128i*)s);
   87|  1.44M|    s1 = _mm_loadu_si128((const __m128i*)(s + 4));
   88|  1.44M|    Shuffle(s0, s1);
   89|       |
   90|  33.0M|    while (blocks--) {
  ------------------
  |  Branch (90:12): [True: 31.6M, False: 1.44M]
  ------------------
   91|       |        /* Remember old state */
   92|  31.6M|        so0 = s0;
   93|  31.6M|        so1 = s1;
   94|       |
   95|       |        /* Load data and transform */
   96|  31.6M|        m0 = Load(chunk);
   97|  31.6M|        QuadRound(s0, s1, m0, 0xe9b5dba5b5c0fbcfull, 0x71374491428a2f98ull);
   98|  31.6M|        m1 = Load(chunk + 16);
   99|  31.6M|        QuadRound(s0, s1, m1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  100|  31.6M|        ShiftMessageA(m0, m1);
  101|  31.6M|        m2 = Load(chunk + 32);
  102|  31.6M|        QuadRound(s0, s1, m2, 0x550c7dc3243185beull, 0x12835b01d807aa98ull);
  103|  31.6M|        ShiftMessageA(m1, m2);
  104|  31.6M|        m3 = Load(chunk + 48);
  105|  31.6M|        QuadRound(s0, s1, m3, 0xc19bf1749bdc06a7ull, 0x80deb1fe72be5d74ull);
  106|  31.6M|        ShiftMessageB(m2, m3, m0);
  107|  31.6M|        QuadRound(s0, s1, m0, 0x240ca1cc0fc19dc6ull, 0xefbe4786E49b69c1ull);
  108|  31.6M|        ShiftMessageB(m3, m0, m1);
  109|  31.6M|        QuadRound(s0, s1, m1, 0x76f988da5cb0a9dcull, 0x4a7484aa2de92c6full);
  110|  31.6M|        ShiftMessageB(m0, m1, m2);
  111|  31.6M|        QuadRound(s0, s1, m2, 0xbf597fc7b00327c8ull, 0xa831c66d983e5152ull);
  112|  31.6M|        ShiftMessageB(m1, m2, m3);
  113|  31.6M|        QuadRound(s0, s1, m3, 0x1429296706ca6351ull, 0xd5a79147c6e00bf3ull);
  114|  31.6M|        ShiftMessageB(m2, m3, m0);
  115|  31.6M|        QuadRound(s0, s1, m0, 0x53380d134d2c6dfcull, 0x2e1b213827b70a85ull);
  116|  31.6M|        ShiftMessageB(m3, m0, m1);
  117|  31.6M|        QuadRound(s0, s1, m1, 0x92722c8581c2c92eull, 0x766a0abb650a7354ull);
  118|  31.6M|        ShiftMessageB(m0, m1, m2);
  119|  31.6M|        QuadRound(s0, s1, m2, 0xc76c51A3c24b8b70ull, 0xa81a664ba2bfe8a1ull);
  120|  31.6M|        ShiftMessageB(m1, m2, m3);
  121|  31.6M|        QuadRound(s0, s1, m3, 0x106aa070f40e3585ull, 0xd6990624d192e819ull);
  122|  31.6M|        ShiftMessageB(m2, m3, m0);
  123|  31.6M|        QuadRound(s0, s1, m0, 0x34b0bcb52748774cull, 0x1e376c0819a4c116ull);
  124|  31.6M|        ShiftMessageB(m3, m0, m1);
  125|  31.6M|        QuadRound(s0, s1, m1, 0x682e6ff35b9cca4full, 0x4ed8aa4a391c0cb3ull);
  126|  31.6M|        ShiftMessageC(m0, m1, m2);
  127|  31.6M|        QuadRound(s0, s1, m2, 0x8cc7020884c87814ull, 0x78a5636f748f82eeull);
  128|  31.6M|        ShiftMessageC(m1, m2, m3);
  129|  31.6M|        QuadRound(s0, s1, m3, 0xc67178f2bef9A3f7ull, 0xa4506ceb90befffaull);
  130|       |
  131|       |        /* Combine with old state */
  132|  31.6M|        s0 = _mm_add_epi32(s0, so0);
  133|  31.6M|        s1 = _mm_add_epi32(s1, so1);
  134|       |
  135|       |        /* Advance */
  136|  31.6M|        chunk += 64;
  137|  31.6M|    }
  138|       |
  139|  1.44M|    Unshuffle(s0, s1);
  140|  1.44M|    _mm_storeu_si128((__m128i*)s, s0);
  141|  1.44M|    _mm_storeu_si128((__m128i*)(s + 4), s1);
  142|  1.44M|}
_ZN19sha256d64_x86_shani14Transform_2wayEPhPKh:
  148|   367k|{
  149|   367k|    __m128i am0, am1, am2, am3, as0, as1, aso0, aso1;
  150|   367k|    __m128i bm0, bm1, bm2, bm3, bs0, bs1, bso0, bso1;
  151|       |
  152|       |    /* Transform 1 */
  153|   367k|    bs0 = as0 = _mm_load_si128((const __m128i*)INIT0);
  154|   367k|    bs1 = as1 = _mm_load_si128((const __m128i*)INIT1);
  155|   367k|    am0 = Load(in);
  156|   367k|    bm0 = Load(in + 64);
  157|   367k|    QuadRound(as0, as1, am0, 0xe9b5dba5b5c0fbcfull, 0x71374491428a2f98ull);
  158|   367k|    QuadRound(bs0, bs1, bm0, 0xe9b5dba5b5c0fbcfull, 0x71374491428a2f98ull);
  159|   367k|    am1 = Load(in + 16);
  160|   367k|    bm1 = Load(in + 80);
  161|   367k|    QuadRound(as0, as1, am1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  162|   367k|    QuadRound(bs0, bs1, bm1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  163|   367k|    ShiftMessageA(am0, am1);
  164|   367k|    ShiftMessageA(bm0, bm1);
  165|   367k|    am2 = Load(in + 32);
  166|   367k|    bm2 = Load(in + 96);
  167|   367k|    QuadRound(as0, as1, am2, 0x550c7dc3243185beull, 0x12835b01d807aa98ull);
  168|   367k|    QuadRound(bs0, bs1, bm2, 0x550c7dc3243185beull, 0x12835b01d807aa98ull);
  169|   367k|    ShiftMessageA(am1, am2);
  170|   367k|    ShiftMessageA(bm1, bm2);
  171|   367k|    am3 = Load(in + 48);
  172|   367k|    bm3 = Load(in + 112);
  173|   367k|    QuadRound(as0, as1, am3, 0xc19bf1749bdc06a7ull, 0x80deb1fe72be5d74ull);
  174|   367k|    QuadRound(bs0, bs1, bm3, 0xc19bf1749bdc06a7ull, 0x80deb1fe72be5d74ull);
  175|   367k|    ShiftMessageB(am2, am3, am0);
  176|   367k|    ShiftMessageB(bm2, bm3, bm0);
  177|   367k|    QuadRound(as0, as1, am0, 0x240ca1cc0fc19dc6ull, 0xefbe4786E49b69c1ull);
  178|   367k|    QuadRound(bs0, bs1, bm0, 0x240ca1cc0fc19dc6ull, 0xefbe4786E49b69c1ull);
  179|   367k|    ShiftMessageB(am3, am0, am1);
  180|   367k|    ShiftMessageB(bm3, bm0, bm1);
  181|   367k|    QuadRound(as0, as1, am1, 0x76f988da5cb0a9dcull, 0x4a7484aa2de92c6full);
  182|   367k|    QuadRound(bs0, bs1, bm1, 0x76f988da5cb0a9dcull, 0x4a7484aa2de92c6full);
  183|   367k|    ShiftMessageB(am0, am1, am2);
  184|   367k|    ShiftMessageB(bm0, bm1, bm2);
  185|   367k|    QuadRound(as0, as1, am2, 0xbf597fc7b00327c8ull, 0xa831c66d983e5152ull);
  186|   367k|    QuadRound(bs0, bs1, bm2, 0xbf597fc7b00327c8ull, 0xa831c66d983e5152ull);
  187|   367k|    ShiftMessageB(am1, am2, am3);
  188|   367k|    ShiftMessageB(bm1, bm2, bm3);
  189|   367k|    QuadRound(as0, as1, am3, 0x1429296706ca6351ull, 0xd5a79147c6e00bf3ull);
  190|   367k|    QuadRound(bs0, bs1, bm3, 0x1429296706ca6351ull, 0xd5a79147c6e00bf3ull);
  191|   367k|    ShiftMessageB(am2, am3, am0);
  192|   367k|    ShiftMessageB(bm2, bm3, bm0);
  193|   367k|    QuadRound(as0, as1, am0, 0x53380d134d2c6dfcull, 0x2e1b213827b70a85ull);
  194|   367k|    QuadRound(bs0, bs1, bm0, 0x53380d134d2c6dfcull, 0x2e1b213827b70a85ull);
  195|   367k|    ShiftMessageB(am3, am0, am1);
  196|   367k|    ShiftMessageB(bm3, bm0, bm1);
  197|   367k|    QuadRound(as0, as1, am1, 0x92722c8581c2c92eull, 0x766a0abb650a7354ull);
  198|   367k|    QuadRound(bs0, bs1, bm1, 0x92722c8581c2c92eull, 0x766a0abb650a7354ull);
  199|   367k|    ShiftMessageB(am0, am1, am2);
  200|   367k|    ShiftMessageB(bm0, bm1, bm2);
  201|   367k|    QuadRound(as0, as1, am2, 0xc76c51A3c24b8b70ull, 0xa81a664ba2bfe8a1ull);
  202|   367k|    QuadRound(bs0, bs1, bm2, 0xc76c51A3c24b8b70ull, 0xa81a664ba2bfe8a1ull);
  203|   367k|    ShiftMessageB(am1, am2, am3);
  204|   367k|    ShiftMessageB(bm1, bm2, bm3);
  205|   367k|    QuadRound(as0, as1, am3, 0x106aa070f40e3585ull, 0xd6990624d192e819ull);
  206|   367k|    QuadRound(bs0, bs1, bm3, 0x106aa070f40e3585ull, 0xd6990624d192e819ull);
  207|   367k|    ShiftMessageB(am2, am3, am0);
  208|   367k|    ShiftMessageB(bm2, bm3, bm0);
  209|   367k|    QuadRound(as0, as1, am0, 0x34b0bcb52748774cull, 0x1e376c0819a4c116ull);
  210|   367k|    QuadRound(bs0, bs1, bm0, 0x34b0bcb52748774cull, 0x1e376c0819a4c116ull);
  211|   367k|    ShiftMessageB(am3, am0, am1);
  212|   367k|    ShiftMessageB(bm3, bm0, bm1);
  213|   367k|    QuadRound(as0, as1, am1, 0x682e6ff35b9cca4full, 0x4ed8aa4a391c0cb3ull);
  214|   367k|    QuadRound(bs0, bs1, bm1, 0x682e6ff35b9cca4full, 0x4ed8aa4a391c0cb3ull);
  215|   367k|    ShiftMessageC(am0, am1, am2);
  216|   367k|    ShiftMessageC(bm0, bm1, bm2);
  217|   367k|    QuadRound(as0, as1, am2, 0x8cc7020884c87814ull, 0x78a5636f748f82eeull);
  218|   367k|    QuadRound(bs0, bs1, bm2, 0x8cc7020884c87814ull, 0x78a5636f748f82eeull);
  219|   367k|    ShiftMessageC(am1, am2, am3);
  220|   367k|    ShiftMessageC(bm1, bm2, bm3);
  221|   367k|    QuadRound(as0, as1, am3, 0xc67178f2bef9A3f7ull, 0xa4506ceb90befffaull);
  222|   367k|    QuadRound(bs0, bs1, bm3, 0xc67178f2bef9A3f7ull, 0xa4506ceb90befffaull);
  223|   367k|    as0 = _mm_add_epi32(as0, _mm_load_si128((const __m128i*)INIT0));
  224|   367k|    bs0 = _mm_add_epi32(bs0, _mm_load_si128((const __m128i*)INIT0));
  225|   367k|    as1 = _mm_add_epi32(as1, _mm_load_si128((const __m128i*)INIT1));
  226|   367k|    bs1 = _mm_add_epi32(bs1, _mm_load_si128((const __m128i*)INIT1));
  227|       |
  228|       |    /* Transform 2 */
  229|   367k|    aso0 = as0;
  230|   367k|    bso0 = bs0;
  231|   367k|    aso1 = as1;
  232|   367k|    bso1 = bs1;
  233|   367k|    QuadRound(as0, as1, 0xe9b5dba5b5c0fbcfull, 0x71374491c28a2f98ull);
  234|   367k|    QuadRound(bs0, bs1, 0xe9b5dba5b5c0fbcfull, 0x71374491c28a2f98ull);
  235|   367k|    QuadRound(as0, as1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  236|   367k|    QuadRound(bs0, bs1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  237|   367k|    QuadRound(as0, as1, 0x550c7dc3243185beull, 0x12835b01d807aa98ull);
  238|   367k|    QuadRound(bs0, bs1, 0x550c7dc3243185beull, 0x12835b01d807aa98ull);
  239|   367k|    QuadRound(as0, as1, 0xc19bf3749bdc06a7ull, 0x80deb1fe72be5d74ull);
  240|   367k|    QuadRound(bs0, bs1, 0xc19bf3749bdc06a7ull, 0x80deb1fe72be5d74ull);
  241|   367k|    QuadRound(as0, as1, 0x240cf2540fe1edc6ull, 0xf0fe4786649b69c1ull);
  242|   367k|    QuadRound(bs0, bs1, 0x240cf2540fe1edc6ull, 0xf0fe4786649b69c1ull);
  243|   367k|    QuadRound(as0, as1, 0x16f988fa61b9411eull, 0x6cc984be4fe9346full);
  244|   367k|    QuadRound(bs0, bs1, 0x16f988fa61b9411eull, 0x6cc984be4fe9346full);
  245|   367k|    QuadRound(as0, as1, 0xb9d99ec7b019fc65ull, 0xa88e5a6df2c65152ull);
  246|   367k|    QuadRound(bs0, bs1, 0xb9d99ec7b019fc65ull, 0xa88e5a6df2c65152ull);
  247|   367k|    QuadRound(as0, as1, 0xc7353eb0fdb1232bull, 0xe70eeaa09a1231c3ull);
  248|   367k|    QuadRound(bs0, bs1, 0xc7353eb0fdb1232bull, 0xe70eeaa09a1231c3ull);
  249|   367k|    QuadRound(as0, as1, 0xdc1eeefd5a0f118full, 0xcb976d5f3069bad5ull);
  250|   367k|    QuadRound(bs0, bs1, 0xdc1eeefd5a0f118full, 0xcb976d5f3069bad5ull);
  251|   367k|    QuadRound(as0, as1, 0xe15d5b1658f4ca9dull, 0xde0b7a040a35b689ull);
  252|   367k|    QuadRound(bs0, bs1, 0xe15d5b1658f4ca9dull, 0xde0b7a040a35b689ull);
  253|   367k|    QuadRound(as0, as1, 0x6fab9537a507ea32ull, 0x37088980007f3e86ull);
  254|   367k|    QuadRound(bs0, bs1, 0x6fab9537a507ea32ull, 0x37088980007f3e86ull);
  255|   367k|    QuadRound(as0, as1, 0xc0bbbe37cdaa3b6dull, 0x0d8cd6f117406110ull);
  256|   367k|    QuadRound(bs0, bs1, 0xc0bbbe37cdaa3b6dull, 0x0d8cd6f117406110ull);
  257|   367k|    QuadRound(as0, as1, 0x6fd15ca70b02e931ull, 0xdb48a36383613bdaull);
  258|   367k|    QuadRound(bs0, bs1, 0x6fd15ca70b02e931ull, 0xdb48a36383613bdaull);
  259|   367k|    QuadRound(as0, as1, 0x6d4378906ed41a95ull, 0x31338431521afacaull);
  260|   367k|    QuadRound(bs0, bs1, 0x6d4378906ed41a95ull, 0x31338431521afacaull);
  261|   367k|    QuadRound(as0, as1, 0x532fb63cb5c9a0e6ull, 0x9eccabbdc39c91f2ull);
  262|   367k|    QuadRound(bs0, bs1, 0x532fb63cb5c9a0e6ull, 0x9eccabbdc39c91f2ull);
  263|   367k|    QuadRound(as0, as1, 0x4c191d76a4954b68ull, 0x07237ea3d2c741c6ull);
  264|   367k|    QuadRound(bs0, bs1, 0x4c191d76a4954b68ull, 0x07237ea3d2c741c6ull);
  265|   367k|    as0 = _mm_add_epi32(as0, aso0);
  266|   367k|    bs0 = _mm_add_epi32(bs0, bso0);
  267|   367k|    as1 = _mm_add_epi32(as1, aso1);
  268|   367k|    bs1 = _mm_add_epi32(bs1, bso1);
  269|       |
  270|       |    /* Extract hash */
  271|   367k|    Unshuffle(as0, as1);
  272|   367k|    Unshuffle(bs0, bs1);
  273|   367k|    am0 = as0;
  274|   367k|    bm0 = bs0;
  275|   367k|    am1 = as1;
  276|   367k|    bm1 = bs1;
  277|       |
  278|       |    /* Transform 3 */
  279|   367k|    bs0 = as0 = _mm_load_si128((const __m128i*)INIT0);
  280|   367k|    bs1 = as1 = _mm_load_si128((const __m128i*)INIT1);
  281|   367k|    QuadRound(as0, as1, am0, 0xe9b5dba5B5c0fbcfull, 0x71374491428a2f98ull);
  282|   367k|    QuadRound(bs0, bs1, bm0, 0xe9b5dba5B5c0fbcfull, 0x71374491428a2f98ull);
  283|   367k|    QuadRound(as0, as1, am1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  284|   367k|    QuadRound(bs0, bs1, bm1, 0xab1c5ed5923f82a4ull, 0x59f111f13956c25bull);
  285|   367k|    ShiftMessageA(am0, am1);
  286|   367k|    ShiftMessageA(bm0, bm1);
  287|   367k|    bm2 = am2 = _mm_set_epi64x(0x0ull, 0x80000000ull);
  288|   367k|    QuadRound(as0, as1, 0x550c7dc3243185beull, 0x12835b015807aa98ull);
  289|   367k|    QuadRound(bs0, bs1, 0x550c7dc3243185beull, 0x12835b015807aa98ull);
  290|   367k|    ShiftMessageA(am1, am2);
  291|   367k|    ShiftMessageA(bm1, bm2);
  292|   367k|    bm3 = am3 = _mm_set_epi64x(0x10000000000ull, 0x0ull);
  293|   367k|    QuadRound(as0, as1, 0xc19bf2749bdc06a7ull, 0x80deb1fe72be5d74ull);
  294|   367k|    QuadRound(bs0, bs1, 0xc19bf2749bdc06a7ull, 0x80deb1fe72be5d74ull);
  295|   367k|    ShiftMessageB(am2, am3, am0);
  296|   367k|    ShiftMessageB(bm2, bm3, bm0);
  297|   367k|    QuadRound(as0, as1, am0, 0x240ca1cc0fc19dc6ull, 0xefbe4786e49b69c1ull);
  298|   367k|    QuadRound(bs0, bs1, bm0, 0x240ca1cc0fc19dc6ull, 0xefbe4786e49b69c1ull);
  299|   367k|    ShiftMessageB(am3, am0, am1);
  300|   367k|    ShiftMessageB(bm3, bm0, bm1);
  301|   367k|    QuadRound(as0, as1, am1, 0x76f988da5cb0a9dcull, 0x4a7484aa2de92c6full);
  302|   367k|    QuadRound(bs0, bs1, bm1, 0x76f988da5cb0a9dcull, 0x4a7484aa2de92c6full);
  303|   367k|    ShiftMessageB(am0, am1, am2);
  304|   367k|    ShiftMessageB(bm0, bm1, bm2);
  305|   367k|    QuadRound(as0, as1, am2, 0xbf597fc7b00327c8ull, 0xa831c66d983e5152ull);
  306|   367k|    QuadRound(bs0, bs1, bm2, 0xbf597fc7b00327c8ull, 0xa831c66d983e5152ull);
  307|   367k|    ShiftMessageB(am1, am2, am3);
  308|   367k|    ShiftMessageB(bm1, bm2, bm3);
  309|   367k|    QuadRound(as0, as1, am3, 0x1429296706ca6351ull, 0xd5a79147c6e00bf3ull);
  310|   367k|    QuadRound(bs0, bs1, bm3, 0x1429296706ca6351ull, 0xd5a79147c6e00bf3ull);
  311|   367k|    ShiftMessageB(am2, am3, am0);
  312|   367k|    ShiftMessageB(bm2, bm3, bm0);
  313|   367k|    QuadRound(as0, as1, am0, 0x53380d134d2c6dfcull, 0x2e1b213827b70a85ull);
  314|   367k|    QuadRound(bs0, bs1, bm0, 0x53380d134d2c6dfcull, 0x2e1b213827b70a85ull);
  315|   367k|    ShiftMessageB(am3, am0, am1);
  316|   367k|    ShiftMessageB(bm3, bm0, bm1);
  317|   367k|    QuadRound(as0, as1, am1, 0x92722c8581c2c92eull, 0x766a0abb650a7354ull);
  318|   367k|    QuadRound(bs0, bs1, bm1, 0x92722c8581c2c92eull, 0x766a0abb650a7354ull);
  319|   367k|    ShiftMessageB(am0, am1, am2);
  320|   367k|    ShiftMessageB(bm0, bm1, bm2);
  321|   367k|    QuadRound(as0, as1, am2, 0xc76c51a3c24b8b70ull, 0xa81a664ba2bfe8A1ull);
  322|   367k|    QuadRound(bs0, bs1, bm2, 0xc76c51a3c24b8b70ull, 0xa81a664ba2bfe8A1ull);
  323|   367k|    ShiftMessageB(am1, am2, am3);
  324|   367k|    ShiftMessageB(bm1, bm2, bm3);
  325|   367k|    QuadRound(as0, as1, am3, 0x106aa070f40e3585ull, 0xd6990624d192e819ull);
  326|   367k|    QuadRound(bs0, bs1, bm3, 0x106aa070f40e3585ull, 0xd6990624d192e819ull);
  327|   367k|    ShiftMessageB(am2, am3, am0);
  328|   367k|    ShiftMessageB(bm2, bm3, bm0);
  329|   367k|    QuadRound(as0, as1, am0, 0x34b0bcb52748774cull, 0x1e376c0819a4c116ull);
  330|   367k|    QuadRound(bs0, bs1, bm0, 0x34b0bcb52748774cull, 0x1e376c0819a4c116ull);
  331|   367k|    ShiftMessageB(am3, am0, am1);
  332|   367k|    ShiftMessageB(bm3, bm0, bm1);
  333|   367k|    QuadRound(as0, as1, am1, 0x682e6ff35b9cca4full, 0x4ed8aa4a391c0cb3ull);
  334|   367k|    QuadRound(bs0, bs1, bm1, 0x682e6ff35b9cca4full, 0x4ed8aa4a391c0cb3ull);
  335|   367k|    ShiftMessageC(am0, am1, am2);
  336|   367k|    ShiftMessageC(bm0, bm1, bm2);
  337|   367k|    QuadRound(as0, as1, am2, 0x8cc7020884c87814ull, 0x78a5636f748f82eeull);
  338|   367k|    QuadRound(bs0, bs1, bm2, 0x8cc7020884c87814ull, 0x78a5636f748f82eeull);
  339|   367k|    ShiftMessageC(am1, am2, am3);
  340|   367k|    ShiftMessageC(bm1, bm2, bm3);
  341|   367k|    QuadRound(as0, as1, am3, 0xc67178f2bef9a3f7ull, 0xa4506ceb90befffaull);
  342|   367k|    QuadRound(bs0, bs1, bm3, 0xc67178f2bef9a3f7ull, 0xa4506ceb90befffaull);
  343|   367k|    as0 = _mm_add_epi32(as0, _mm_load_si128((const __m128i*)INIT0));
  344|   367k|    bs0 = _mm_add_epi32(bs0, _mm_load_si128((const __m128i*)INIT0));
  345|   367k|    as1 = _mm_add_epi32(as1, _mm_load_si128((const __m128i*)INIT1));
  346|   367k|    bs1 = _mm_add_epi32(bs1, _mm_load_si128((const __m128i*)INIT1));
  347|       |
  348|       |    /* Extract hash into out */
  349|   367k|    Unshuffle(as0, as1);
  350|   367k|    Unshuffle(bs0, bs1);
  351|   367k|    Save(out, as0);
  352|   367k|    Save(out + 16, as1);
  353|   367k|    Save(out + 32, bs0);
  354|   367k|    Save(out + 48, bs1);
  355|   367k|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_17ShuffleERDv2_xS1_:
   54|  1.44M|{
   55|  1.44M|    const __m128i t1 = _mm_shuffle_epi32(s0, 0xB1);
   56|  1.44M|    const __m128i t2 = _mm_shuffle_epi32(s1, 0x1B);
   57|  1.44M|    s0 = _mm_alignr_epi8(t1, t2, 0x08);
   58|       |    s1 = _mm_blend_epi16(t2, t1, 0xF0);
   59|  1.44M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_14LoadEPKh:
   70|   129M|{
   71|   129M|    return _mm_shuffle_epi8(_mm_loadu_si128((const __m128i*)in), _mm_load_si128((const __m128i*)MASK));
   72|   129M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_19QuadRoundERDv2_xS1_S0_mm:
   31|   528M|{
   32|   528M|    const __m128i msg = _mm_add_epi32(m, _mm_set_epi64x(k1, k0));
   33|   528M|    state1 = _mm_sha256rnds2_epu32(state1, state0, msg);
   34|       |    state0 = _mm_sha256rnds2_epu32(state0, state1, _mm_shuffle_epi32(msg, 0x0e));
   35|   528M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_113ShiftMessageAERDv2_xS0_:
   38|   397M|{
   39|   397M|    m0 = _mm_sha256msg1_epu32(m0, m1);
   40|   397M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_113ShiftMessageBERDv2_xS0_S1_:
   48|   331M|{
   49|   331M|    ShiftMessageC(m0, m1, m2);
   50|   331M|    ShiftMessageA(m0, m1);
   51|   331M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_113ShiftMessageCERDv2_xS0_S1_:
   43|   397M|{
   44|       |    m2 = _mm_sha256msg2_epu32(_mm_add_epi32(m2, _mm_alignr_epi8(m1, m0, 4)), m1);
   45|   397M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_19UnshuffleERDv2_xS1_:
   62|  2.91M|{
   63|  2.91M|    const __m128i t1 = _mm_shuffle_epi32(s0, 0x1B);
   64|  2.91M|    const __m128i t2 = _mm_shuffle_epi32(s1, 0xB1);
   65|  2.91M|    s0 = _mm_blend_epi16(t1, t2, 0xF0);
   66|       |    s1 = _mm_alignr_epi8(t2, t1, 0x08);
   67|  2.91M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_19QuadRoundERDv2_xS1_mm:
   24|  13.2M|{
   25|  13.2M|    const __m128i msg = _mm_set_epi64x(k1, k0);
   26|  13.2M|    state1 = _mm_sha256rnds2_epu32(state1, state0, msg);
   27|       |    state0 = _mm_sha256rnds2_epu32(state0, state1, _mm_shuffle_epi32(msg, 0x0e));
   28|  13.2M|}
sha256_x86_shani.cpp:_ZN12_GLOBAL__N_14SaveEPhDv2_x:
   75|  1.47M|{
   76|  1.47M|    _mm_storeu_si128((__m128i*)out, _mm_shuffle_epi8(s, _mm_load_si128((const __m128i*)MASK)));
   77|  1.47M|}

_Z13SHA256Uint256RK7uint256:
   79|  2.41k|{
   80|  2.41k|    uint256 result;
   81|  2.41k|    CSHA256().Write(input.begin(), 32).Finalize(result.begin());
   82|  2.41k|    return result;
   83|  2.41k|}

_ZN9ChainCodeD2Ev:
   28|      2|    ~ChainCode() { memory_cleanse(data(), size()); }
_ZN10HashWriterlsI12CBlockHeaderEERS_RKT_:
  150|  5.69k|    {
  151|  5.69k|        ::Serialize(*this, obj);
  152|  5.69k|        return *this;
  153|  5.69k|    }
_ZN10HashWriterlsI13ParamsWrapperI20TransactionSerParamsK19CMutableTransactionEEERS_RKT_:
  150|  16.4k|    {
  151|  16.4k|        ::Serialize(*this, obj);
  152|  16.4k|        return *this;
  153|  16.4k|    }
_ZN10HashWriterlsI13ParamsWrapperI20TransactionSerParamsK12CTransactionEEERS_RKT_:
  150|   603k|    {
  151|   603k|        ::Serialize(*this, obj);
  152|   603k|        return *this;
  153|   603k|    }
_ZN8CHash2565WriteENSt3__14spanIKhLm18446744073709551615EEE:
   45|    554|    CHash256& Write(std::span<const unsigned char> input) {
   46|    554|        sha.Write(input.data(), input.size());
   47|    554|        return *this;
   48|    554|    }
_ZN8CHash2568FinalizeENSt3__14spanIhLm18446744073709551615EEE:
   38|    554|    void Finalize(std::span<unsigned char> output) {
   39|    554|        assert(output.size() == OUTPUT_SIZE);
  ------------------
  |  Branch (39:9): [True: 554, False: 0]
  ------------------
   40|    554|        unsigned char buf[CSHA256::OUTPUT_SIZE];
   41|    554|        sha.Finalize(buf);
   42|    554|        sha.Reset().Write(buf, CSHA256::OUTPUT_SIZE).Finalize(output.data());
   43|    554|    }
_ZN10HashWriterlsI9COutPointEERS_RKT_:
  150|    804|    {
  151|    804|        ::Serialize(*this, obj);
  152|    804|        return *this;
  153|    804|    }
_ZN10HashWriterlsINSt3__14spanIKhLm32EEEEERS_RKT_:
  150|  14.6k|    {
  151|  14.6k|        ::Serialize(*this, obj);
  152|  14.6k|        return *this;
  153|  14.6k|    }
_ZN10HashWriterlsIjEERS_RKT_:
  150|    804|    {
  151|    804|        ::Serialize(*this, obj);
  152|    804|        return *this;
  153|    804|    }
_ZN10HashWriterlsI6CTxOutEERS_RKT_:
  150|    804|    {
  151|    804|        ::Serialize(*this, obj);
  152|    804|        return *this;
  153|    804|    }
_ZN10HashWriterlsIiEERS_RKT_:
  150|  5.13k|    {
  151|  5.13k|        ::Serialize(*this, obj);
  152|  5.13k|        return *this;
  153|  5.13k|    }
_ZN10HashWriter7GetHashEv:
  123|   630k|    uint256 GetHash() {
  124|   630k|        uint256 result;
  125|   630k|        ctx.Finalize(result.begin());
  126|   630k|        ctx.Reset().Write(result.begin(), CSHA256::OUTPUT_SIZE).Finalize(result.begin());
  127|   630k|        return result;
  128|   630k|    }
interpreter.cpp:_ZN10HashWriterlsIN12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionEEEERS_RKT_:
  150|  2.48k|    {
  151|  2.48k|        ::Serialize(*this, obj);
  152|  2.48k|        return *this;
  153|  2.48k|    }
_ZN8CHash1605WriteENSt3__14spanIKhLm18446744073709551615EEE:
   70|    798|    CHash160& Write(std::span<const unsigned char> input) {
   71|    798|        sha.Write(input.data(), input.size());
   72|    798|        return *this;
   73|    798|    }
_ZN8CHash1608FinalizeENSt3__14spanIhLm18446744073709551615EEE:
   63|    798|    void Finalize(std::span<unsigned char> output) {
   64|    798|        assert(output.size() == OUTPUT_SIZE);
  ------------------
  |  Branch (64:9): [True: 798, False: 0]
  ------------------
   65|    798|        unsigned char buf[CSHA256::OUTPUT_SIZE];
   66|    798|        sha.Finalize(buf);
   67|    798|        CRIPEMD160().Write(buf, CSHA256::OUTPUT_SIZE).Finalize(output.data());
   68|    798|    }
_ZN10HashWriter5writeENSt3__14spanIKSt4byteLm18446744073709551615EEE:
  115|  3.90M|    {
  116|  3.90M|        ctx.Write(UCharCast(src.data()), src.size());
  117|  3.90M|    }
_ZN10HashWriter9GetSHA256Ev:
  134|  2.41k|    uint256 GetSHA256() {
  135|  2.41k|        uint256 result;
  136|  2.41k|        ctx.Finalize(result.begin());
  137|  2.41k|        return result;
  138|  2.41k|    }

_ZN10interfaces5ChainD2Ev:
  119|      2|    virtual ~Chain() = default;

_ZNK12CChainParams12GetConsensusEv:
   89|  5.69k|    const Consensus::Params& GetConsensus() const { return consensus; }

_ZN11ECC_ContextD2Ev:
  501|      2|{
  502|      2|    ECC_Stop();
  503|      2|}
key.cpp:_ZL8ECC_Stopv:
  486|      2|static void ECC_Stop() {
  487|      2|    secp256k1_context *ctx = secp256k1_context_sign;
  488|      2|    secp256k1_context_sign = nullptr;
  489|       |
  490|      2|    if (ctx) {
  ------------------
  |  Branch (490:9): [True: 2, False: 0]
  ------------------
  491|      2|        secp256k1_context_destroy(ctx);
  492|      2|    }
  493|      2|}

_Z11LogInstancev:
   27|  5.54k|{
   28|       |/**
   29|       | * NOTE: the logger instances is leaked on exit. This is ugly, but will be
   30|       | * cleaned up by the OS/libc. Defining a logger as a global object doesn't work
   31|       | * since the order of destruction of static/global objects is undefined.
   32|       | * Consider if the logger gets destroyed, and then some later destructor calls
   33|       | * LogInfo, maybe indirectly, and you get a core dump at shutdown trying to
   34|       | * access the logger. When the shutdown sequence is fully audited and tested,
   35|       | * explicit destruction of these objects can be implemented by changing this
   36|       | * from a raw pointer to a std::unique_ptr.
   37|       | * Since the ~Logger() destructor is never called, the Logger class and all
   38|       | * its subclasses must have implicitly-defined destructors.
   39|       | *
   40|       | * This method of initialization was originally introduced in
   41|       | * ee3374234c60aba2cc4c5cd5cac1c0aefc2d817c.
   42|       | */
   43|  5.54k|    static BCLog::Logger* g_logger{new BCLog::Logger()};
   44|  5.54k|    return *g_logger;
   45|  5.54k|}
_ZN5BCLog6Logger20DisconnectTestLoggerEv:
  104|      2|{
  105|      2|    STDLOCK(m_cs);
  ------------------
  |  |   41|      2|#define STDLOCK(cs) StdMutex::Guard BITCOIN_UNIQUE_NAME(criticalblock){StdMutex::CheckNotHeld(cs)}
  |  |  ------------------
  |  |  |  |   11|      2|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|      2|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|      2|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  106|      2|    m_buffering = true;
  107|      2|    if (m_fileout != nullptr) fclose(m_fileout);
  ------------------
  |  Branch (107:9): [True: 0, False: 2]
  ------------------
  108|      2|    m_fileout = nullptr;
  109|      2|    m_print_callbacks.clear();
  110|      2|    m_max_buffer_memusage = DEFAULT_MAX_LOG_BUFFER;
  111|      2|    m_cur_buffer_memusage = 0;
  112|      2|    m_buffer_lines_discarded = 0;
  113|      2|    m_msgs_before_open.clear();
  114|      2|}
_ZNK5BCLog6Logger15WillLogCategoryENS_8LogFlagsE:
  157|  5.54k|{
  158|  5.54k|    return (m_categories.load(std::memory_order_relaxed) & category) != 0;
  159|  5.54k|}
_ZNK5BCLog6Logger20WillLogCategoryLevelENS_8LogFlagsEN4util3log5LevelE:
  162|  5.54k|{
  163|       |    // Log messages at Info, Warning and Error level unconditionally, so that
  164|       |    // important troubleshooting information doesn't get lost.
  165|  5.54k|    if (level >= BCLog::Level::Info) return true;
  ------------------
  |  Branch (165:9): [True: 0, False: 5.54k]
  ------------------
  166|       |
  167|  5.54k|    if (!WillLogCategory(category)) return false;
  ------------------
  |  Branch (167:9): [True: 5.54k, False: 0]
  ------------------
  168|       |
  169|      0|    STDLOCK(m_cs);
  ------------------
  |  |   41|      0|#define STDLOCK(cs) StdMutex::Guard BITCOIN_UNIQUE_NAME(criticalblock){StdMutex::CheckNotHeld(cs)}
  |  |  ------------------
  |  |  |  |   11|      0|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|      0|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|      0|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  170|      0|    const auto it{m_category_log_levels.find(category)};
  171|      0|    return level >= (it == m_category_log_levels.end() ? LogLevel() : it->second);
  ------------------
  |  Branch (171:22): [True: 0, False: 0]
  ------------------
  172|  5.54k|}
_ZN4util3log14ShouldDebugLogEm:
  620|  5.54k|{
  621|  5.54k|    return LogInstance().WillLogCategoryLevel(static_cast<BCLog::LogFlags>(category), util::log::Level::Debug);
  622|  5.54k|}

_ZN11CNetCleanupD2Ev:
 3676|      2|    {
 3677|       |#ifdef WIN32
 3678|       |        // Shutdown Windows Sockets
 3679|       |        WSACleanup();
 3680|       |#endif
 3681|      2|    }

_ZN4node11NodeContextD2Ev:
   27|      2|NodeContext::~NodeContext() = default;

_ZN9prevectorILj36EhjiE6insertITkNSt3__114input_iteratorENS2_11__wrap_iterIPhEEEEvNS0_8iteratorET_S7_:
  335|  2.06M|    void insert(iterator pos, InputIterator first, InputIterator last) {
  336|  2.06M|        size_type p = pos - begin();
  337|  2.06M|        difference_type count = last - first;
  338|  2.06M|        size_type new_size = size() + count;
  339|  2.06M|        if (capacity() < new_size) {
  ------------------
  |  Branch (339:13): [True: 887, False: 2.05M]
  ------------------
  340|    887|            change_capacity(new_size + (new_size >> 1));
  341|    887|        }
  342|  2.06M|        T* ptr = item_ptr(p);
  343|  2.06M|        T* dst = ptr + count;
  344|  2.06M|        memmove(dst, ptr, (size() - p) * sizeof(T));
  345|  2.06M|        _size += count;
  346|  2.06M|        fill(ptr, first, last);
  347|  2.06M|    }
_ZNK9prevectorILj16EhjiE9is_directEv:
  126|     16|    bool is_direct() const { return _size <= N; }
_ZN9prevectorILj16EhjiED2Ev:
  422|     16|    ~prevector() {
  423|     16|        if (!is_direct()) {
  ------------------
  |  Branch (423:13): [True: 0, False: 16]
  ------------------
  424|      0|            free(_union.indirect_contents.indirect);
  425|      0|            _union.indirect_contents.indirect = nullptr;
  426|      0|        }
  427|     16|    }
_ZN9prevectorILj36EhjiEC2EOS0_:
  224|   242k|        : _union(std::move(other._union)), _size(other._size)
  225|   242k|    {
  226|   242k|        other._size = 0;
  227|   242k|    }
_ZN9prevectorILj36EhjiE9push_backERKh:
  392|   209k|    void push_back(const T& value) {
  393|   209k|        emplace_back(value);
  394|   209k|    }
_ZN9prevectorILj36EhjiE12emplace_backIJRKhEEEvDpOT_:
  383|   209k|    void emplace_back(Args&&... args) {
  384|   209k|        size_type new_size = size() + 1;
  385|   209k|        if (capacity() < new_size) {
  ------------------
  |  Branch (385:13): [True: 95, False: 209k]
  ------------------
  386|     95|            change_capacity(new_size + (new_size >> 1));
  387|     95|        }
  388|   209k|        new(item_ptr(size())) T(std::forward<Args>(args)...);
  389|   209k|        _size++;
  390|   209k|    }
_ZN9prevectorILj36EhjiE20resize_uninitializedEj:
  349|  65.1k|    inline void resize_uninitialized(size_type new_size) {
  350|       |        // resize_uninitialized changes the size of the prevector but does not initialize it.
  351|       |        // If size < new_size, the added elements must be initialized explicitly.
  352|  65.1k|        if (capacity() < new_size) {
  ------------------
  |  Branch (352:13): [True: 27.0k, False: 38.0k]
  ------------------
  353|  27.0k|            change_capacity(new_size);
  354|  27.0k|            _size += new_size - size();
  355|  27.0k|            return;
  356|  27.0k|        }
  357|  38.0k|        if (new_size < size()) {
  ------------------
  |  Branch (357:13): [True: 0, False: 38.0k]
  ------------------
  358|      0|            erase(item_ptr(new_size), end());
  359|  38.0k|        } else {
  360|  38.0k|            _size += new_size - size();
  361|  38.0k|        }
  362|  38.0k|    }
_ZN9prevectorILj36EhjiEaSEOS0_:
  237|  2.00k|    prevector& operator=(prevector<N, T, Size, Diff>&& other) noexcept {
  238|  2.00k|        if (!is_direct()) {
  ------------------
  |  Branch (238:13): [True: 1.75k, False: 246]
  ------------------
  239|  1.75k|            free(_union.indirect_contents.indirect);
  240|  1.75k|        }
  241|  2.00k|        _union = std::move(other._union);
  242|  2.00k|        _size = other._size;
  243|  2.00k|        other._size = 0;
  244|  2.00k|        return *this;
  245|  2.00k|    }
_ZNK9prevectorILj36EhjiE5emptyEv:
  251|   472k|    bool empty() const {
  252|   472k|        return size() == 0;
  253|   472k|    }
_ZNK9prevectorILj36EhjiE4dataEv:
  468|   123k|    const value_type* data() const {
  469|   123k|        return item_ptr(0);
  470|   123k|    }
_ZN9prevectorILj36EhjiE4fillITkNSt3__114input_iteratorENS0_14const_iteratorEEEvPhT_S5_:
  167|   862k|    void fill(T* dst, InputIterator first, InputIterator last) {
  168|  4.70G|        while (first != last) {
  ------------------
  |  Branch (168:16): [True: 4.70G, False: 862k]
  ------------------
  169|  4.70G|            new(static_cast<void*>(dst)) T(*first);
  170|  4.70G|            ++dst;
  171|  4.70G|            ++first;
  172|  4.70G|        }
  173|   862k|    }
_ZNK9prevectorILj36EhjiE14const_iteratoreqES1_:
  102|  4.70G|        bool operator==(const_iterator x) const { return ptr == x.ptr; }
_ZN9prevectorILj36EhjiE14const_iteratorppEv:
   92|  4.70G|        const_iterator& operator++() { ptr++; return *this; }
_ZNK9prevectorILj36EhjiEixEj:
  272|  63.9k|    const T& operator[](size_type pos) const {
  273|  63.9k|        return *item_ptr(pos);
  274|  63.9k|    }
_ZN9prevectorILj36EhjiE8item_ptrEi:
  159|   100M|    T* item_ptr(difference_type pos) { return is_direct() ? direct_ptr(pos) : indirect_ptr(pos); }
  ------------------
  |  Branch (159:47): [True: 1.21M, False: 99.5M]
  ------------------
_ZNK9prevectorILj36EhjiE9is_directEv:
  126|   247M|    bool is_direct() const { return _size <= N; }
_ZN9prevectorILj36EhjiE10direct_ptrEi:
  122|  1.35M|    T* direct_ptr(difference_type pos) { return reinterpret_cast<T*>(_union.direct) + pos; }
_ZN9prevectorILj36EhjiE12indirect_ptrEi:
  124|  99.5M|    T* indirect_ptr(difference_type pos) { return reinterpret_cast<T*>(_union.indirect_contents.indirect) + pos; }
_ZN9prevectorILj36EhjiE15change_capacityEj:
  128|  1.16M|    void change_capacity(size_type new_capacity) {
  129|  1.16M|        if (new_capacity <= N) {
  ------------------
  |  Branch (129:13): [True: 1.00M, False: 155k]
  ------------------
  130|  1.00M|            if (!is_direct()) {
  ------------------
  |  Branch (130:17): [True: 0, False: 1.00M]
  ------------------
  131|      0|                T* indirect = indirect_ptr(0);
  132|      0|                T* src = indirect;
  133|      0|                T* dst = direct_ptr(0);
  134|      0|                memcpy(dst, src, size() * sizeof(T));
  135|      0|                free(indirect);
  136|      0|                _size -= N + 1;
  137|      0|            }
  138|  1.00M|        } else {
  139|   155k|            if (!is_direct()) {
  ------------------
  |  Branch (139:17): [True: 14.5k, False: 140k]
  ------------------
  140|       |                /* FIXME: Because malloc/realloc here won't call new_handler if allocation fails, assert
  141|       |                    success. These should instead use an allocator or new/delete so that handlers
  142|       |                    are called as necessary, but performance would be slightly degraded by doing so. */
  143|  14.5k|                _union.indirect_contents.indirect = static_cast<char*>(realloc(_union.indirect_contents.indirect, ((size_t)sizeof(T)) * new_capacity));
  144|  14.5k|                assert(_union.indirect_contents.indirect);
  ------------------
  |  Branch (144:17): [True: 14.5k, False: 0]
  ------------------
  145|  14.5k|                _union.indirect_contents.capacity = new_capacity;
  146|   140k|            } else {
  147|   140k|                char* new_indirect = static_cast<char*>(malloc(((size_t)sizeof(T)) * new_capacity));
  148|   140k|                assert(new_indirect);
  ------------------
  |  Branch (148:17): [True: 140k, False: 0]
  ------------------
  149|   140k|                T* src = direct_ptr(0);
  150|   140k|                T* dst = reinterpret_cast<T*>(new_indirect);
  151|   140k|                memcpy(dst, src, size() * sizeof(T));
  152|   140k|                _union.indirect_contents.indirect = new_indirect;
  153|   140k|                _union.indirect_contents.capacity = new_capacity;
  154|   140k|                _size += N + 1;
  155|   140k|            }
  156|   155k|        }
  157|  1.16M|    }
_ZNK9prevectorILj36EhjiE3endEv:
  258|  2.19M|    const_iterator end() const { return const_iterator(item_ptr(size())); }
_ZNK9prevectorILj36EhjiE8item_ptrEi:
  160|  3.14M|    const T* item_ptr(difference_type pos) const { return is_direct() ? direct_ptr(pos) : indirect_ptr(pos); }
  ------------------
  |  Branch (160:59): [True: 1.37M, False: 1.77M]
  ------------------
_ZNK9prevectorILj36EhjiE10direct_ptrEi:
  123|  1.37M|    const T* direct_ptr(difference_type pos) const { return reinterpret_cast<const T*>(_union.direct) + pos; }
_ZNK9prevectorILj36EhjiE12indirect_ptrEi:
  125|  1.77M|    const T* indirect_ptr(difference_type pos) const { return reinterpret_cast<const T*>(_union.indirect_contents.indirect) + pos; }
_ZNK9prevectorILj36EhjiE4sizeEv:
  247|   107M|    size_type size() const {
  248|   107M|        return is_direct() ? _size : _size - N - 1;
  ------------------
  |  Branch (248:16): [True: 5.70M, False: 101M]
  ------------------
  249|   107M|    }
_ZNK9prevectorILj36EhjiE5beginEv:
  256|   762k|    const_iterator begin() const { return const_iterator(item_ptr(0)); }
_ZNK9prevectorILj36EhjiE14const_iteratordeEv:
   89|  4.71G|        const T& operator*() const { return *ptr; }
_ZN9prevectorILj36EhjiEaSERKS0_:
  229|  53.1k|    prevector& operator=(const prevector<N, T, Size, Diff>& other) {
  230|  53.1k|        if (&other == this) {
  ------------------
  |  Branch (230:13): [True: 0, False: 53.1k]
  ------------------
  231|      0|            return *this;
  232|      0|        }
  233|  53.1k|        assign(other.begin(), other.end());
  234|  53.1k|        return *this;
  235|  53.1k|    }
_ZN9prevectorILj36EhjiE6assignITkNSt3__114input_iteratorENS0_14const_iteratorEEEvT_S4_:
  186|  53.1k|    void assign(InputIterator first, InputIterator last) {
  187|  53.1k|        size_type n = last - first;
  188|  53.1k|        clear();
  189|  53.1k|        if (capacity() < n) {
  ------------------
  |  Branch (189:13): [True: 6.23k, False: 46.9k]
  ------------------
  190|  6.23k|            change_capacity(n);
  191|  6.23k|        }
  192|  53.1k|        _size += n;
  193|  53.1k|        fill(item_ptr(0), first, last);
  194|  53.1k|    }
_ZNK9prevectorILj36EhjiEeqERKS0_:
  429|  3.68k|    constexpr bool operator==(const prevector& other) const {
  430|  3.68k|        return std::ranges::equal(*this, other);
  431|  3.68k|    }
_ZNK9prevectorILj36EhjiE14const_iteratorssES1_:
  103|  1.54M|        auto operator<=>(const_iterator x) const { return ptr <=> x.ptr; }
_ZNK9prevectorILj36EhjiE14const_iteratorptEv:
   90|  2.06M|        const T* operator->() const { return ptr; }
_ZN9prevectorILj36EhjiEC2Ev:
  196|   926k|    prevector() = default;
_ZN9prevectorILj36EhjiE6insertENS0_8iteratorERKh:
  307|  20.3M|    iterator insert(iterator pos, const T& value) {
  308|  20.3M|        size_type p = pos - begin();
  309|  20.3M|        size_type new_size = size() + 1;
  310|  20.3M|        if (capacity() < new_size) {
  ------------------
  |  Branch (310:13): [True: 1.73k, False: 20.3M]
  ------------------
  311|  1.73k|            change_capacity(new_size + (new_size >> 1));
  312|  1.73k|        }
  313|  20.3M|        T* ptr = item_ptr(p);
  314|  20.3M|        T* dst = ptr + 1;
  315|  20.3M|        memmove(dst, ptr, (size() - p) * sizeof(T));
  316|  20.3M|        _size++;
  317|  20.3M|        new(static_cast<void*>(ptr)) T(value);
  318|  20.3M|        return iterator(ptr);
  319|  20.3M|    }
_ZmiN9prevectorILj36EhjiE8iteratorES1_:
   68|  33.3M|        difference_type friend operator-(iterator a, iterator b) { return (&(*a) - &(*b)); }
_ZNK9prevectorILj36EhjiE8iteratordeEv:
   61|  66.7M|        T& operator*() const { return *ptr; }
_ZNK9prevectorILj36EhjiE8capacityEv:
  260|  33.6M|    size_t capacity() const {
  261|  33.6M|        if (is_direct()) {
  ------------------
  |  Branch (261:13): [True: 391k, False: 33.2M]
  ------------------
  262|   391k|            return N;
  263|  33.2M|        } else {
  264|  33.2M|            return _union.indirect_contents.capacity;
  265|  33.2M|        }
  266|  33.6M|    }
_ZN9prevectorILj36EhjiE8iteratorC2EPh:
   60|  87.0M|        iterator(T* ptr_) : ptr(ptr_) {}
_ZN9prevectorILj36EhjiE6insertITkNSt3__114input_iteratorEPKhEEvNS0_8iteratorET_S6_:
  335|  2.35k|    void insert(iterator pos, InputIterator first, InputIterator last) {
  336|  2.35k|        size_type p = pos - begin();
  337|  2.35k|        difference_type count = last - first;
  338|  2.35k|        size_type new_size = size() + count;
  339|  2.35k|        if (capacity() < new_size) {
  ------------------
  |  Branch (339:13): [True: 21, False: 2.33k]
  ------------------
  340|     21|            change_capacity(new_size + (new_size >> 1));
  341|     21|        }
  342|  2.35k|        T* ptr = item_ptr(p);
  343|  2.35k|        T* dst = ptr + count;
  344|  2.35k|        memmove(dst, ptr, (size() - p) * sizeof(T));
  345|  2.35k|        _size += count;
  346|  2.35k|        fill(ptr, first, last);
  347|  2.35k|    }
_ZN9prevectorILj36EhjiE4fillITkNSt3__114input_iteratorEPKhEEvPhT_S6_:
  167|  2.35k|    void fill(T* dst, InputIterator first, InputIterator last) {
  168|  7.06k|        while (first != last) {
  ------------------
  |  Branch (168:16): [True: 4.71k, False: 2.35k]
  ------------------
  169|  4.71k|            new(static_cast<void*>(dst)) T(*first);
  170|  4.71k|            ++dst;
  171|  4.71k|            ++first;
  172|  4.71k|        }
  173|  2.35k|    }
_ZN9prevectorILj36EhjiE6insertITkNSt3__114input_iteratorENS2_11__wrap_iterIPKhEEEEvNS0_8iteratorET_S8_:
  335|  10.4M|    void insert(iterator pos, InputIterator first, InputIterator last) {
  336|  10.4M|        size_type p = pos - begin();
  337|  10.4M|        difference_type count = last - first;
  338|  10.4M|        size_type new_size = size() + count;
  339|  10.4M|        if (capacity() < new_size) {
  ------------------
  |  Branch (339:13): [True: 29.1k, False: 10.4M]
  ------------------
  340|  29.1k|            change_capacity(new_size + (new_size >> 1));
  341|  29.1k|        }
  342|  10.4M|        T* ptr = item_ptr(p);
  343|  10.4M|        T* dst = ptr + count;
  344|  10.4M|        memmove(dst, ptr, (size() - p) * sizeof(T));
  345|  10.4M|        _size += count;
  346|  10.4M|        fill(ptr, first, last);
  347|  10.4M|    }
_ZN9prevectorILj36EhjiE4fillITkNSt3__114input_iteratorENS2_11__wrap_iterIPKhEEEEvPhT_S8_:
  167|  10.4M|    void fill(T* dst, InputIterator first, InputIterator last) {
  168|  1.18G|        while (first != last) {
  ------------------
  |  Branch (168:16): [True: 1.17G, False: 10.4M]
  ------------------
  169|  1.17G|            new(static_cast<void*>(dst)) T(*first);
  170|  1.17G|            ++dst;
  171|  1.17G|            ++first;
  172|  1.17G|        }
  173|  10.4M|    }
_ZN9prevectorILj36EhjiEC2ERKS0_:
  216|   385k|    prevector(const prevector<N, T, Size, Diff>& other) {
  217|   385k|        size_type n = other.size();
  218|   385k|        change_capacity(n);
  219|   385k|        _size += n;
  220|   385k|        fill(item_ptr(0), other.begin(),  other.end());
  221|   385k|    }
_ZN9prevectorILj36EhjiE3endEv:
  257|  33.3M|    iterator end() { return iterator(item_ptr(size())); }
_ZN9prevectorILj36EhjiE5beginEv:
  255|  33.3M|    iterator begin() { return iterator(item_ptr(0)); }
_ZN9prevectorILj36EhjiE14const_iteratorC2ENS0_8iteratorE:
   88|  34.2k|        const_iterator(iterator x) : ptr(&(*x)) {}
_ZN9prevectorILj36EhjiE6insertITkNSt3__114input_iteratorENS0_14const_iteratorEEEvNS0_8iteratorET_S5_:
  335|   416k|    void insert(iterator pos, InputIterator first, InputIterator last) {
  336|   416k|        size_type p = pos - begin();
  337|   416k|        difference_type count = last - first;
  338|   416k|        size_type new_size = size() + count;
  339|   416k|        if (capacity() < new_size) {
  ------------------
  |  Branch (339:13): [True: 11.1k, False: 405k]
  ------------------
  340|  11.1k|            change_capacity(new_size + (new_size >> 1));
  341|  11.1k|        }
  342|   416k|        T* ptr = item_ptr(p);
  343|   416k|        T* dst = ptr + count;
  344|   416k|        memmove(dst, ptr, (size() - p) * sizeof(T));
  345|   416k|        _size += count;
  346|   416k|        fill(ptr, first, last);
  347|   416k|    }
_ZN9prevectorILj36EhjiEC2ITkNSt3__114input_iteratorENS0_14const_iteratorEEET_S4_:
  209|  7.84k|    prevector(InputIterator first, InputIterator last) {
  210|  7.84k|        size_type n = last - first;
  211|  7.84k|        change_capacity(n);
  212|  7.84k|        _size += n;
  213|  7.84k|        fill(item_ptr(0), first, last);
  214|  7.84k|    }
_ZN9prevectorILj36EhjiEixEj:
  268|  65.1k|    T& operator[](size_type pos) {
  269|  65.1k|        return *item_ptr(pos);
  270|  65.1k|    }
_ZN9prevectorILj36EhjiE5clearEv:
  303|  1.56M|    void clear() {
  304|  1.56M|        resize(0);
  305|  1.56M|    }
_ZN9prevectorILj36EhjiE6resizeEj:
  276|  1.56M|    void resize(size_type new_size) {
  277|  1.56M|        size_type cur_size = size();
  278|  1.56M|        if (cur_size == new_size) {
  ------------------
  |  Branch (278:13): [True: 1.55M, False: 8.19k]
  ------------------
  279|  1.55M|            return;
  280|  1.55M|        }
  281|  8.19k|        if (cur_size > new_size) {
  ------------------
  |  Branch (281:13): [True: 8.19k, False: 0]
  ------------------
  282|  8.19k|            erase(item_ptr(new_size), end());
  283|  8.19k|            return;
  284|  8.19k|        }
  285|      0|        if (new_size > capacity()) {
  ------------------
  |  Branch (285:13): [True: 0, False: 0]
  ------------------
  286|      0|            change_capacity(new_size);
  287|      0|        }
  288|      0|        ptrdiff_t increase = new_size - cur_size;
  289|      0|        fill(item_ptr(cur_size), increase);
  290|      0|        _size += increase;
  291|      0|    }
_ZN9prevectorILj36EhjiE5eraseENS0_8iteratorES1_:
  368|  8.19k|    iterator erase(iterator first, iterator last) {
  369|       |        // Erase is not allowed to the change the object's capacity. That means
  370|       |        // that when starting with an indirectly allocated prevector with
  371|       |        // size and capacity > N, the result may be a still indirectly allocated
  372|       |        // prevector with size <= N and capacity > N. A shrink_to_fit() call is
  373|       |        // necessary to switch to the (more efficient) directly allocated
  374|       |        // representation (with capacity N and size <= N).
  375|  8.19k|        iterator p = first;
  376|  8.19k|        char* endp = (char*)&(*end());
  377|  8.19k|        _size -= last - p;
  378|  8.19k|        memmove(&(*first), &(*last), endp - ((char*)(&(*last))));
  379|  8.19k|        return first;
  380|  8.19k|    }
_ZN9prevectorILj36EhjiE13shrink_to_fitEv:
  299|   686k|    void shrink_to_fit() {
  300|   686k|        change_capacity(size());
  301|   686k|    }
_ZN9prevectorILj36EhjiEC2ITkNSt3__114input_iteratorENS2_11__wrap_iterIPKhEEEET_S7_:
  209|  5.54k|    prevector(InputIterator first, InputIterator last) {
  210|  5.54k|        size_type n = last - first;
  211|  5.54k|        change_capacity(n);
  212|  5.54k|        _size += n;
  213|  5.54k|        fill(item_ptr(0), first, last);
  214|  5.54k|    }
_ZN9prevectorILj36EhjiED2Ev:
  422|  1.56M|    ~prevector() {
  423|  1.56M|        if (!is_direct()) {
  ------------------
  |  Branch (423:13): [True: 138k, False: 1.42M]
  ------------------
  424|   138k|            free(_union.indirect_contents.indirect);
  425|   138k|            _union.indirect_contents.indirect = nullptr;
  426|   138k|        }
  427|  1.56M|    }
_ZN9prevectorILj36EhjiE14const_iteratorC2EPKh:
   87|  3.64M|        const_iterator(const T* ptr_) : ptr(ptr_) {}
_ZN9prevectorILj36EhjiE4fillITkNSt3__114input_iteratorENS2_11__wrap_iterIPhEEEEvS4_T_S6_:
  167|  2.06M|    void fill(T* dst, InputIterator first, InputIterator last) {
  168|   190M|        while (first != last) {
  ------------------
  |  Branch (168:16): [True: 188M, False: 2.06M]
  ------------------
  169|   188M|            new(static_cast<void*>(dst)) T(*first);
  170|   188M|            ++dst;
  171|   188M|            ++first;
  172|   188M|        }
  173|  2.06M|    }
_ZNK9prevectorILj36EhjiE14const_iteratorplEj:
   97|   689k|        const_iterator operator+(size_type n) const { return const_iterator(ptr + n); }
_ZmiN9prevectorILj36EhjiE14const_iteratorES1_:
   96|  3.44M|        difference_type friend operator-(const_iterator a, const_iterator b) { return (&(*a) - &(*b)); }
_ZN9prevectorILj36EhjiE14const_iteratorppEi:
   94|  1.43M|        const_iterator operator++(int) { const_iterator copy(*this); ++(*this); return copy; }
_ZNK9prevectorILj36EhjiE14const_iteratorixEj:
   91|  17.1k|        const T& operator[](size_type pos) const { return ptr[pos]; }
_ZN9prevectorILj36EhjiE14const_iteratorpLEj:
   99|   433k|        const_iterator& operator+=(size_type n) { ptr += n; return *this; }

_ZNK12CBlockHeader7GetHashEv:
   15|  5.69k|{
   16|  5.69k|    return (HashWriter{} << *this).GetHash();
   17|  5.69k|}

_ZN6CBlock16SerializationOpsI12ParamsStreamIR10SpanReader20TransactionSerParamsES_17ActionUnserializeEEvRT0_RT_T1_:
   96|  6.66k|    {
   97|  6.66k|        READWRITE(AsBase<CBlockHeader>(obj), obj.vtx);
  ------------------
  |  |  148|  6.66k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
   98|  6.66k|    }
_ZN12CBlockHeader16SerializationOpsI12ParamsStreamIR10SpanReader20TransactionSerParamsES_17ActionUnserializeEEvRT0_RT_T1_:
   42|  6.66k|    SERIALIZE_METHODS(CBlockHeader, obj) { READWRITE(obj.nVersion, obj.hashPrevBlock, obj.hashMerkleRoot, obj.nTime, obj.nBits, obj.nNonce); }
  ------------------
  |  |  148|  6.66k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN6CBlockC2Ev:
   85|  6.66k|    {
   86|  6.66k|        SetNull();
   87|  6.66k|    }
_ZN12CBlockHeaderC2Ev:
   38|  6.66k|    {
   39|  6.66k|        SetNull();
   40|  6.66k|    }
_ZN12CBlockHeader7SetNullEv:
   45|  13.3k|    {
   46|  13.3k|        nVersion = 0;
   47|  13.3k|        hashPrevBlock.SetNull();
   48|  13.3k|        hashMerkleRoot.SetNull();
   49|  13.3k|        nTime = 0;
   50|  13.3k|        nBits = 0;
   51|  13.3k|        nNonce = 0;
   52|  13.3k|    }
_ZN6CBlock7SetNullEv:
  101|  6.66k|    {
  102|  6.66k|        CBlockHeader::SetNull();
  103|  6.66k|        vtx.clear();
  104|  6.66k|        fChecked = false;
  105|  6.66k|        m_checked_witness_commitment = false;
  106|  6.66k|        m_checked_merkle_root = false;
  107|  6.66k|    }
_ZN12CBlockHeader16SerializationOpsI10HashWriterKS_15ActionSerializeEEvRT0_RT_T1_:
   42|  5.69k|    SERIALIZE_METHODS(CBlockHeader, obj) { READWRITE(obj.nVersion, obj.hashPrevBlock, obj.hashMerkleRoot, obj.nTime, obj.nBits, obj.nNonce); }
  ------------------
  |  |  148|  5.69k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------

_ZN5CTxInC2E9COutPoint7CScriptj:
   27|  22.4k|{
   28|  22.4k|    prevout = prevoutIn;
   29|  22.4k|    scriptSig = scriptSigIn;
   30|  22.4k|    nSequence = nSequenceIn;
   31|  22.4k|}
_ZN6CTxOutC2ERKl7CScript:
   56|  22.4k|{
   57|  22.4k|    nValue = nValueIn;
   58|  22.4k|    scriptPubKey = scriptPubKeyIn;
   59|  22.4k|}
_ZN19CMutableTransactionC2Ev:
   66|  22.4k|CMutableTransaction::CMutableTransaction() : version{CTransaction::CURRENT_VERSION}, nLockTime{0} {}
_ZN19CMutableTransactionC2ERK12CTransaction:
   67|  9.42k|CMutableTransaction::CMutableTransaction(const CTransaction& tx) : vin(tx.vin), vout(tx.vout), version{tx.version}, nLockTime{tx.nLockTime} {}
_ZNK19CMutableTransaction7GetHashEv:
   70|  16.4k|{
   71|  16.4k|    return Txid::FromUint256((HashWriter{} << TX_NO_WITNESS(*this)).GetHash());
   72|  16.4k|}
_ZNK12CTransaction17ComputeHasWitnessEv:
   75|   600k|{
   76|   600k|    return std::any_of(vin.begin(), vin.end(), [](const auto& input) {
   77|   600k|        return !input.scriptWitness.IsNull();
   78|   600k|    });
   79|   600k|}
_ZNK12CTransaction11ComputeHashEv:
   82|   600k|{
   83|   600k|    return Txid::FromUint256((HashWriter{} << TX_NO_WITNESS(*this)).GetHash());
   84|   600k|}
_ZNK12CTransaction18ComputeWitnessHashEv:
   87|   600k|{
   88|   600k|    if (!HasWitness()) {
  ------------------
  |  Branch (88:9): [True: 598k, False: 2.17k]
  ------------------
   89|   598k|        return Wtxid::FromUint256(hash.ToUint256());
   90|   598k|    }
   91|       |
   92|  2.17k|    return Wtxid::FromUint256((HashWriter{} << TX_WITH_WITNESS(*this)).GetHash());
   93|   600k|}
_ZN12CTransactionC2ERK19CMutableTransaction:
   95|  16.4k|CTransaction::CTransaction(const CMutableTransaction& tx) : vin(tx.vin), vout(tx.vout), version{tx.version}, nLockTime{tx.nLockTime}, m_has_witness{ComputeHasWitness()}, hash{ComputeHash()}, m_witness_hash{ComputeWitnessHash()} {}
_ZN12CTransactionC2EO19CMutableTransaction:
   96|   584k|CTransaction::CTransaction(CMutableTransaction&& tx) : vin(std::move(tx.vin)), vout(std::move(tx.vout)), version{tx.version}, nLockTime{tx.nLockTime}, m_has_witness{ComputeHasWitness()}, hash{ComputeHash()}, m_witness_hash{ComputeWitnessHash()} {}
transaction.cpp:_ZZNK12CTransaction17ComputeHasWitnessEvENK3$_0clI5CTxInEEDaRKT_:
   76|  32.8k|    return std::any_of(vin.begin(), vin.end(), [](const auto& input) {
   77|  32.8k|        return !input.scriptWitness.IsNull();
   78|  32.8k|    });

_ZN12CTransactionC2I12ParamsStreamIR10SpanReader20TransactionSerParamsEEE16deserialize_typeRT_:
  322|   585k|    CTransaction(deserialize_type, Stream& s) : CTransaction(CMutableTransaction(deserialize, s)) {}
_ZN19CMutableTransactionC2I12ParamsStreamIR10SpanReader20TransactionSerParamsEEE16deserialize_typeRT_:
  383|   585k|    CMutableTransaction(deserialize_type, Stream& s) {
  384|   585k|        Unserialize(s);
  385|   585k|    }
_ZN19CMutableTransaction11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  373|   585k|    inline void Unserialize(Stream& s) {
  374|   585k|        UnserializeTransaction(*this, s, s.template GetParams<TransactionSerParams>());
  375|   585k|    }
_Z22UnserializeTransactionI12ParamsStreamIR10SpanReader20TransactionSerParamsE19CMutableTransactionEvRT0_RT_RKS3_:
  202|   585k|{
  203|   585k|    const bool fAllowWitness = params.allow_witness;
  204|       |
  205|   585k|    s >> tx.version;
  206|   585k|    unsigned char flags = 0;
  207|   585k|    tx.vin.clear();
  208|   585k|    tx.vout.clear();
  209|       |    /* Try to read the vin. In case the dummy is there, this will be read as an empty vector. */
  210|   585k|    s >> tx.vin;
  211|   585k|    if (tx.vin.size() == 0 && fAllowWitness) {
  ------------------
  |  Branch (211:9): [True: 578k, False: 6.18k]
  |  Branch (211:31): [True: 578k, False: 0]
  ------------------
  212|       |        /* We read a dummy or an empty vin. */
  213|   578k|        s >> flags;
  214|   578k|        if (flags != 0) {
  ------------------
  |  Branch (214:13): [True: 938, False: 578k]
  ------------------
  215|    938|            s >> tx.vin;
  216|    938|            s >> tx.vout;
  217|    938|        }
  218|   578k|    } else {
  219|       |        /* We read a non-empty vin. Assume a normal vout follows. */
  220|  6.18k|        s >> tx.vout;
  221|  6.18k|    }
  222|   585k|    if ((flags & 1) && fAllowWitness) {
  ------------------
  |  Branch (222:9): [True: 766, False: 584k]
  |  Branch (222:24): [True: 766, False: 0]
  ------------------
  223|       |        /* The witness flag is present, and we support witnesses. */
  224|    766|        flags ^= 1;
  225|  3.52k|        for (size_t i = 0; i < tx.vin.size(); i++) {
  ------------------
  |  Branch (225:28): [True: 2.76k, False: 766]
  ------------------
  226|  2.76k|            s >> tx.vin[i].scriptWitness.stack;
  227|  2.76k|        }
  228|    766|        if (!tx.HasWitness()) {
  ------------------
  |  Branch (228:13): [True: 22, False: 744]
  ------------------
  229|       |            /* It's illegal to encode witnesses when all witness stacks are empty. */
  230|     22|            throw std::ios_base::failure("Superfluous witness record");
  231|     22|        }
  232|    766|    }
  233|   585k|    if (flags) {
  ------------------
  |  Branch (233:9): [True: 11, False: 585k]
  ------------------
  234|       |        /* Unknown flag in the serialization */
  235|     11|        throw std::ios_base::failure("Unknown transaction optional data");
  236|     11|    }
  237|   585k|    s >> tx.nLockTime;
  238|   585k|}
_ZN5CTxIn16SerializationOpsI12ParamsStreamIR10SpanReader20TransactionSerParamsES_17ActionUnserializeEEvRT0_RT_T1_:
  124|   129k|    SERIALIZE_METHODS(CTxIn, obj) { READWRITE(obj.prevout, obj.scriptSig, obj.nSequence); }
  ------------------
  |  |  148|   129k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN9COutPoint16SerializationOpsI12ParamsStreamIR10SpanReader20TransactionSerParamsES_17ActionUnserializeEEvRT0_RT_T1_:
   39|   129k|    SERIALIZE_METHODS(COutPoint, obj) { READWRITE(obj.hash, obj.n); }
  ------------------
  |  |  148|   129k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN6CTxOut16SerializationOpsI12ParamsStreamIR10SpanReader20TransactionSerParamsES_17ActionUnserializeEEvRT0_RT_T1_:
  152|   686k|    SERIALIZE_METHODS(CTxOut, obj) { READWRITE(obj.nValue, obj.scriptPubKey); }
  ------------------
  |  |  148|   686k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN5CTxInC2Ev:
  117|   129k|    {
  118|   129k|        nSequence = SEQUENCE_FINAL;
  119|   129k|    }
_ZN9COutPointC2Ev:
   36|   174k|    COutPoint(): n(NULL_INDEX) { }
_ZN9COutPointC2ERK22transaction_identifierILb0EEj:
   37|  8.22k|    COutPoint(const Txid& hashIn, uint32_t nIn): hash(hashIn), n(nIn) { }
_ZNK12CTransaction10HasWitnessEv:
  353|   603k|    bool HasWitness() const { return m_has_witness; }
_ZNK12CTransaction7GetHashEv:
  328|   735k|    const Txid& GetHash() const LIFETIMEBOUND { return hash; }
_ZNK19CMutableTransaction9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  368|  16.4k|    inline void Serialize(Stream& s) const {
  369|  16.4k|        SerializeTransaction(*this, s, s.template GetParams<TransactionSerParams>());
  370|  16.4k|    }
_Z20SerializeTransactionI12ParamsStreamIR10HashWriter20TransactionSerParamsE19CMutableTransactionEvRKT0_RT_RKS3_:
  242|  16.4k|{
  243|  16.4k|    const bool fAllowWitness = params.allow_witness;
  244|       |
  245|  16.4k|    s << tx.version;
  246|  16.4k|    unsigned char flags = 0;
  247|       |    // Consistency check
  248|  16.4k|    if (fAllowWitness) {
  ------------------
  |  Branch (248:9): [True: 0, False: 16.4k]
  ------------------
  249|       |        /* Check whether witnesses need to be serialized. */
  250|      0|        if (tx.HasWitness()) {
  ------------------
  |  Branch (250:13): [True: 0, False: 0]
  ------------------
  251|      0|            flags |= 1;
  252|      0|        }
  253|      0|    }
  254|  16.4k|    if (flags) {
  ------------------
  |  Branch (254:9): [True: 0, False: 16.4k]
  ------------------
  255|       |        /* Use extended format in case witnesses are to be serialized. */
  256|      0|        std::vector<CTxIn> vinDummy;
  257|      0|        s << vinDummy;
  258|      0|        s << flags;
  259|      0|    }
  260|  16.4k|    s << tx.vin;
  261|  16.4k|    s << tx.vout;
  262|  16.4k|    if (flags & 1) {
  ------------------
  |  Branch (262:9): [True: 0, False: 16.4k]
  ------------------
  263|      0|        for (size_t i = 0; i < tx.vin.size(); i++) {
  ------------------
  |  Branch (263:28): [True: 0, False: 0]
  ------------------
  264|      0|            s << tx.vin[i].scriptWitness.stack;
  265|      0|        }
  266|      0|    }
  267|  16.4k|    s << tx.nLockTime;
  268|  16.4k|}
_ZNK19CMutableTransaction10HasWitnessEv:
  393|    592|    {
  394|  1.16k|        for (size_t i = 0; i < vin.size(); i++) {
  ------------------
  |  Branch (394:28): [True: 1.14k, False: 22]
  ------------------
  395|  1.14k|            if (!vin[i].scriptWitness.IsNull()) {
  ------------------
  |  Branch (395:17): [True: 570, False: 576]
  ------------------
  396|    570|                return true;
  397|    570|            }
  398|  1.14k|        }
  399|     22|        return false;
  400|    592|    }
_ZN5CTxIn16SerializationOpsI12ParamsStreamIR10HashWriter20TransactionSerParamsEKS_15ActionSerializeEEvRT0_RT_T1_:
  124|  54.7k|    SERIALIZE_METHODS(CTxIn, obj) { READWRITE(obj.prevout, obj.scriptSig, obj.nSequence); }
  ------------------
  |  |  148|  54.7k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN9COutPoint16SerializationOpsI12ParamsStreamIR10HashWriter20TransactionSerParamsEKS_15ActionSerializeEEvRT0_RT_T1_:
   39|  54.7k|    SERIALIZE_METHODS(COutPoint, obj) { READWRITE(obj.hash, obj.n); }
  ------------------
  |  |  148|  54.7k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN6CTxOut16SerializationOpsI12ParamsStreamIR10HashWriter20TransactionSerParamsEKS_15ActionSerializeEEvRT0_RT_T1_:
  152|   406k|    SERIALIZE_METHODS(CTxOut, obj) { READWRITE(obj.nValue, obj.scriptPubKey); }
  ------------------
  |  |  148|   406k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZNK12CTransaction9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  313|   603k|    inline void Serialize(Stream& s) const {
  314|   603k|        SerializeTransaction(*this, s, s.template GetParams<TransactionSerParams>());
  315|   603k|    }
_Z20SerializeTransactionI12ParamsStreamIR10HashWriter20TransactionSerParamsE12CTransactionEvRKT0_RT_RKS3_:
  242|   603k|{
  243|   603k|    const bool fAllowWitness = params.allow_witness;
  244|       |
  245|   603k|    s << tx.version;
  246|   603k|    unsigned char flags = 0;
  247|       |    // Consistency check
  248|   603k|    if (fAllowWitness) {
  ------------------
  |  Branch (248:9): [True: 2.17k, False: 600k]
  ------------------
  249|       |        /* Check whether witnesses need to be serialized. */
  250|  2.17k|        if (tx.HasWitness()) {
  ------------------
  |  Branch (250:13): [True: 2.17k, False: 0]
  ------------------
  251|  2.17k|            flags |= 1;
  252|  2.17k|        }
  253|  2.17k|    }
  254|   603k|    if (flags) {
  ------------------
  |  Branch (254:9): [True: 2.17k, False: 600k]
  ------------------
  255|       |        /* Use extended format in case witnesses are to be serialized. */
  256|  2.17k|        std::vector<CTxIn> vinDummy;
  257|  2.17k|        s << vinDummy;
  258|  2.17k|        s << flags;
  259|  2.17k|    }
  260|   603k|    s << tx.vin;
  261|   603k|    s << tx.vout;
  262|   603k|    if (flags & 1) {
  ------------------
  |  Branch (262:9): [True: 2.17k, False: 600k]
  ------------------
  263|  5.67k|        for (size_t i = 0; i < tx.vin.size(); i++) {
  ------------------
  |  Branch (263:28): [True: 3.49k, False: 2.17k]
  ------------------
  264|  3.49k|            s << tx.vin[i].scriptWitness.stack;
  265|  3.49k|        }
  266|  2.17k|    }
  267|   603k|    s << tx.nLockTime;
  268|   603k|}
_ZN6CTxOutC2Ev:
  146|   686k|    {
  147|   686k|        SetNull();
  148|   686k|    }
_ZN6CTxOut7SetNullEv:
  155|   686k|    {
  156|   686k|        nValue = -1;
  157|   686k|        scriptPubKey.clear();
  158|   686k|    }
_ZN9COutPoint16SerializationOpsI10HashWriterKS_15ActionSerializeEEvRT0_RT_T1_:
   39|  3.29k|    SERIALIZE_METHODS(COutPoint, obj) { READWRITE(obj.hash, obj.n); }
  ------------------
  |  |  148|  3.29k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN6CTxOut16SerializationOpsI10HashWriterKS_15ActionSerializeEEvRT0_RT_T1_:
  152|  3.17k|    SERIALIZE_METHODS(CTxOut, obj) { READWRITE(obj.nValue, obj.scriptPubKey); }
  ------------------
  |  |  148|  3.17k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------

_ZN22transaction_identifierILb0EE11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
   56|   129k|    template <typename Stream> void Unserialize(Stream& s) { m_wrapped.Unserialize(s); }
_ZN22transaction_identifierILb0EEC2Ev:
   31|   174k|    transaction_identifier() : m_wrapped{} {}
_ZNK22transaction_identifierILb0EE9ToUint256Ev:
   37|  1.34M|    const uint256& ToUint256() const LIFETIMEBOUND { return m_wrapped; }
_ZN22transaction_identifierILb0EE11FromUint256ERK7uint256:
   38|   617k|    static transaction_identifier FromUint256(const uint256& id) { return {id}; }
_ZN22transaction_identifierILb0EEC2ERK7uint256:
   28|   617k|    transaction_identifier(const uint256& wrapped) : m_wrapped{wrapped} {}
_ZNK22transaction_identifierILb0EE9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
   55|  54.7k|    template <typename Stream> void Serialize(Stream& s) const { m_wrapped.Serialize(s); }
_ZN22transaction_identifierILb1EE11FromUint256ERK7uint256:
   38|   600k|    static transaction_identifier FromUint256(const uint256& id) { return {id}; }
_ZN22transaction_identifierILb1EEC2ERK7uint256:
   28|   600k|    transaction_identifier(const uint256& wrapped) : m_wrapped{wrapped} {}
_ZNK22transaction_identifierILb0EE9SerializeI10HashWriterEEvRT_:
   55|  3.29k|    template <typename Stream> void Serialize(Stream& s) const { m_wrapped.Serialize(s); }

_Z29ecdsa_signature_parse_der_laxP25secp256k1_ecdsa_signaturePKhm:
   45|  3.95k|int ecdsa_signature_parse_der_lax(secp256k1_ecdsa_signature* sig, const unsigned char *input, size_t inputlen) {
   46|  3.95k|    size_t rpos, rlen, spos, slen;
   47|  3.95k|    size_t pos = 0;
   48|  3.95k|    size_t lenbyte;
   49|  3.95k|    unsigned char tmpsig[64] = {0};
   50|  3.95k|    int overflow = 0;
   51|       |
   52|       |    /* Hack to initialize sig with a correctly-parsed but invalid signature. */
   53|  3.95k|    secp256k1_ecdsa_signature_parse_compact(secp256k1_context_static, sig, tmpsig);
   54|       |
   55|       |    /* Sequence tag byte */
   56|  3.95k|    if (pos == inputlen || input[pos] != 0x30) {
  ------------------
  |  Branch (56:9): [True: 0, False: 3.95k]
  |  Branch (56:28): [True: 0, False: 3.95k]
  ------------------
   57|      0|        return 0;
   58|      0|    }
   59|  3.95k|    pos++;
   60|       |
   61|       |    /* Sequence length bytes */
   62|  3.95k|    if (pos == inputlen) {
  ------------------
  |  Branch (62:9): [True: 0, False: 3.95k]
  ------------------
   63|      0|        return 0;
   64|      0|    }
   65|  3.95k|    lenbyte = input[pos++];
   66|  3.95k|    if (lenbyte & 0x80) {
  ------------------
  |  Branch (66:9): [True: 0, False: 3.95k]
  ------------------
   67|      0|        lenbyte -= 0x80;
   68|      0|        if (lenbyte > inputlen - pos) {
  ------------------
  |  Branch (68:13): [True: 0, False: 0]
  ------------------
   69|      0|            return 0;
   70|      0|        }
   71|      0|        pos += lenbyte;
   72|      0|    }
   73|       |
   74|       |    /* Integer tag byte for R */
   75|  3.95k|    if (pos == inputlen || input[pos] != 0x02) {
  ------------------
  |  Branch (75:9): [True: 0, False: 3.95k]
  |  Branch (75:28): [True: 0, False: 3.95k]
  ------------------
   76|      0|        return 0;
   77|      0|    }
   78|  3.95k|    pos++;
   79|       |
   80|       |    /* Integer length for R */
   81|  3.95k|    if (pos == inputlen) {
  ------------------
  |  Branch (81:9): [True: 0, False: 3.95k]
  ------------------
   82|      0|        return 0;
   83|      0|    }
   84|  3.95k|    lenbyte = input[pos++];
   85|  3.95k|    if (lenbyte & 0x80) {
  ------------------
  |  Branch (85:9): [True: 0, False: 3.95k]
  ------------------
   86|      0|        lenbyte -= 0x80;
   87|      0|        if (lenbyte > inputlen - pos) {
  ------------------
  |  Branch (87:13): [True: 0, False: 0]
  ------------------
   88|      0|            return 0;
   89|      0|        }
   90|      0|        while (lenbyte > 0 && input[pos] == 0) {
  ------------------
  |  Branch (90:16): [True: 0, False: 0]
  |  Branch (90:31): [True: 0, False: 0]
  ------------------
   91|      0|            pos++;
   92|      0|            lenbyte--;
   93|      0|        }
   94|      0|        static_assert(sizeof(size_t) >= 4, "size_t too small");
   95|      0|        if (lenbyte >= 4) {
  ------------------
  |  Branch (95:13): [True: 0, False: 0]
  ------------------
   96|      0|            return 0;
   97|      0|        }
   98|      0|        rlen = 0;
   99|      0|        while (lenbyte > 0) {
  ------------------
  |  Branch (99:16): [True: 0, False: 0]
  ------------------
  100|      0|            rlen = (rlen << 8) + input[pos];
  101|      0|            pos++;
  102|      0|            lenbyte--;
  103|      0|        }
  104|  3.95k|    } else {
  105|  3.95k|        rlen = lenbyte;
  106|  3.95k|    }
  107|  3.95k|    if (rlen > inputlen - pos) {
  ------------------
  |  Branch (107:9): [True: 0, False: 3.95k]
  ------------------
  108|      0|        return 0;
  109|      0|    }
  110|  3.95k|    rpos = pos;
  111|  3.95k|    pos += rlen;
  112|       |
  113|       |    /* Integer tag byte for S */
  114|  3.95k|    if (pos == inputlen || input[pos] != 0x02) {
  ------------------
  |  Branch (114:9): [True: 0, False: 3.95k]
  |  Branch (114:28): [True: 0, False: 3.95k]
  ------------------
  115|      0|        return 0;
  116|      0|    }
  117|  3.95k|    pos++;
  118|       |
  119|       |    /* Integer length for S */
  120|  3.95k|    if (pos == inputlen) {
  ------------------
  |  Branch (120:9): [True: 0, False: 3.95k]
  ------------------
  121|      0|        return 0;
  122|      0|    }
  123|  3.95k|    lenbyte = input[pos++];
  124|  3.95k|    if (lenbyte & 0x80) {
  ------------------
  |  Branch (124:9): [True: 0, False: 3.95k]
  ------------------
  125|      0|        lenbyte -= 0x80;
  126|      0|        if (lenbyte > inputlen - pos) {
  ------------------
  |  Branch (126:13): [True: 0, False: 0]
  ------------------
  127|      0|            return 0;
  128|      0|        }
  129|      0|        while (lenbyte > 0 && input[pos] == 0) {
  ------------------
  |  Branch (129:16): [True: 0, False: 0]
  |  Branch (129:31): [True: 0, False: 0]
  ------------------
  130|      0|            pos++;
  131|      0|            lenbyte--;
  132|      0|        }
  133|      0|        static_assert(sizeof(size_t) >= 4, "size_t too small");
  134|      0|        if (lenbyte >= 4) {
  ------------------
  |  Branch (134:13): [True: 0, False: 0]
  ------------------
  135|      0|            return 0;
  136|      0|        }
  137|      0|        slen = 0;
  138|      0|        while (lenbyte > 0) {
  ------------------
  |  Branch (138:16): [True: 0, False: 0]
  ------------------
  139|      0|            slen = (slen << 8) + input[pos];
  140|      0|            pos++;
  141|      0|            lenbyte--;
  142|      0|        }
  143|  3.95k|    } else {
  144|  3.95k|        slen = lenbyte;
  145|  3.95k|    }
  146|  3.95k|    if (slen > inputlen - pos) {
  ------------------
  |  Branch (146:9): [True: 0, False: 3.95k]
  ------------------
  147|      0|        return 0;
  148|      0|    }
  149|  3.95k|    spos = pos;
  150|       |
  151|       |    /* Ignore leading zeroes in R */
  152|  4.44k|    while (rlen > 0 && input[rpos] == 0) {
  ------------------
  |  Branch (152:12): [True: 4.40k, False: 44]
  |  Branch (152:24): [True: 495, False: 3.90k]
  ------------------
  153|    495|        rlen--;
  154|    495|        rpos++;
  155|    495|    }
  156|       |    /* Copy R value */
  157|  3.95k|    if (rlen > 32) {
  ------------------
  |  Branch (157:9): [True: 6, False: 3.94k]
  ------------------
  158|      6|        overflow = 1;
  159|  3.94k|    } else {
  160|  3.94k|        memcpy(tmpsig + 32 - rlen, input + rpos, rlen);
  161|  3.94k|    }
  162|       |
  163|       |    /* Ignore leading zeroes in S */
  164|  6.19k|    while (slen > 0 && input[spos] == 0) {
  ------------------
  |  Branch (164:12): [True: 6.19k, False: 2]
  |  Branch (164:24): [True: 2.24k, False: 3.94k]
  ------------------
  165|  2.24k|        slen--;
  166|  2.24k|        spos++;
  167|  2.24k|    }
  168|       |    /* Copy S value */
  169|  3.95k|    if (slen > 32) {
  ------------------
  |  Branch (169:9): [True: 145, False: 3.80k]
  ------------------
  170|    145|        overflow = 1;
  171|  3.80k|    } else {
  172|  3.80k|        memcpy(tmpsig + 64 - slen, input + spos, slen);
  173|  3.80k|    }
  174|       |
  175|  3.95k|    if (!overflow) {
  ------------------
  |  Branch (175:9): [True: 3.80k, False: 151]
  ------------------
  176|  3.80k|        overflow = !secp256k1_ecdsa_signature_parse_compact(secp256k1_context_static, sig, tmpsig);
  177|  3.80k|    }
  178|  3.95k|    if (overflow) {
  ------------------
  |  Branch (178:9): [True: 221, False: 3.73k]
  ------------------
  179|       |        /* Overwrite the result again with a correctly-parsed but invalid
  180|       |           signature if parsing failed. */
  181|    221|        memset(tmpsig, 0, 64);
  182|    221|        secp256k1_ecdsa_signature_parse_compact(secp256k1_context_static, sig, tmpsig);
  183|    221|    }
  184|  3.95k|    return 1;
  185|  3.95k|}
_ZNK7CPubKey6VerifyERK7uint256RKNSt3__16vectorIhNS3_9allocatorIhEEEE:
  283|  5.13k|bool CPubKey::Verify(const uint256 &hash, const std::vector<unsigned char>& vchSig) const {
  284|  5.13k|    if (!IsValid())
  ------------------
  |  Branch (284:9): [True: 0, False: 5.13k]
  ------------------
  285|      0|        return false;
  286|  5.13k|    secp256k1_pubkey pubkey;
  287|  5.13k|    secp256k1_ecdsa_signature sig;
  288|  5.13k|    if (!secp256k1_ec_pubkey_parse(secp256k1_context_static, &pubkey, vch, size())) {
  ------------------
  |  Branch (288:9): [True: 1.18k, False: 3.95k]
  ------------------
  289|  1.18k|        return false;
  290|  1.18k|    }
  291|  3.95k|    if (!ecdsa_signature_parse_der_lax(&sig, vchSig.data(), vchSig.size())) {
  ------------------
  |  Branch (291:9): [True: 0, False: 3.95k]
  ------------------
  292|      0|        return false;
  293|      0|    }
  294|       |    /* libsecp256k1's ECDSA verification requires lower-S signatures, which have
  295|       |     * not historically been enforced in Bitcoin, so normalize them first. */
  296|  3.95k|    secp256k1_ecdsa_signature_normalize(secp256k1_context_static, &sig, &sig);
  297|  3.95k|    return secp256k1_ecdsa_verify(secp256k1_context_static, &sig, hash.begin(), &pubkey);
  298|  3.95k|}

_ZN7CPubKey6GetLenEh:
   67|  25.8k|    {
   68|  25.8k|        if (chHeader == 2 || chHeader == 3)
  ------------------
  |  Branch (68:13): [True: 10.1k, False: 15.7k]
  |  Branch (68:30): [True: 8.61k, False: 7.10k]
  ------------------
   69|  18.7k|            return COMPRESSED_SIZE;
   70|  7.10k|        if (chHeader == 4 || chHeader == 6 || chHeader == 7)
  ------------------
  |  Branch (70:13): [True: 268, False: 6.83k]
  |  Branch (70:30): [True: 2.36k, False: 4.46k]
  |  Branch (70:47): [True: 1.31k, False: 3.15k]
  ------------------
   71|  3.94k|            return SIZE;
   72|  3.15k|        return 0;
   73|  7.10k|    }
_ZN7CPubKey10InvalidateEv:
   77|  2.56k|    {
   78|  2.56k|        vch[0] = 0xFF;
   79|  2.56k|    }
_ZN7CPubKeyC2ENSt3__14spanIKhLm18446744073709551615EEE:
  113|  8.58k|    {
  114|  8.58k|        Set(_vch.begin(), _vch.end());
  115|  8.58k|    }
_ZNK7CPubKey4sizeEv:
  118|  18.8k|    unsigned int size() const { return GetLen(vch[0]); }
_ZNK7CPubKey7IsValidEv:
  192|  13.7k|    {
  193|  13.7k|        return size() > 0;
  194|  13.7k|    }
_ZN7CPubKey3SetINSt3__111__wrap_iterIPKhEEEEvT_S6_:
   96|  8.58k|    {
   97|  8.58k|        int len = pend == pbegin ? 0 : GetLen(pbegin[0]);
  ------------------
  |  Branch (97:19): [True: 1.60k, False: 6.98k]
  ------------------
   98|  8.58k|        if (len && len == (pend - pbegin))
  ------------------
  |  Branch (98:13): [True: 6.38k, False: 2.19k]
  |  Branch (98:20): [True: 6.02k, False: 368]
  ------------------
   99|  6.02k|            memcpy(vch, (unsigned char*)&pbegin[0], len);
  100|  2.56k|        else
  101|  2.56k|            Invalidate();
  102|  8.58k|    }

random.cpp:_ZN12_GLOBAL__N_18RNGStateD2Ev:
  367|      2|    ~RNGState() = default;

_Z10CastToBoolRKNSt3__16vectorIhNS_9allocatorIhEEEE:
   47|  11.4k|{
   48|  14.1k|    for (unsigned int i = 0; i < vch.size(); i++)
  ------------------
  |  Branch (48:30): [True: 6.61k, False: 7.54k]
  ------------------
   49|  6.61k|    {
   50|  6.61k|        if (vch[i] != 0)
  ------------------
  |  Branch (50:13): [True: 3.87k, False: 2.74k]
  ------------------
   51|  3.87k|        {
   52|       |            // Can be negative zero
   53|  3.87k|            if (i == vch.size()-1 && vch[i] == 0x80)
  ------------------
  |  Branch (53:17): [True: 1.55k, False: 2.31k]
  |  Branch (53:38): [True: 283, False: 1.27k]
  ------------------
   54|    283|                return false;
   55|  3.58k|            return true;
   56|  3.87k|        }
   57|  6.61k|    }
   58|  7.54k|    return false;
   59|  11.4k|}
_Z22CheckSignatureEncodingRKNSt3__16vectorIhNS_9allocatorIhEEEE19script_verify_flagsP13ScriptError_t:
  211|  9.12k|bool CheckSignatureEncoding(const std::vector<unsigned char> &vchSig, script_verify_flags flags, ScriptError* serror) {
  212|       |    // Empty signature. Not strictly DER encoded, but allowed to provide a
  213|       |    // compact way to provide an invalid signature for use with CHECK(MULTI)SIG
  214|  9.12k|    if (vchSig.size() == 0) {
  ------------------
  |  Branch (214:9): [True: 3.10k, False: 6.02k]
  ------------------
  215|  3.10k|        return true;
  216|  3.10k|    }
  217|  6.02k|    if ((flags & (SCRIPT_VERIFY_DERSIG | SCRIPT_VERIFY_LOW_S | SCRIPT_VERIFY_STRICTENC)) != 0 && !IsValidSignatureEncoding(vchSig)) {
  ------------------
  |  Branch (217:9): [True: 6.02k, False: 0]
  |  Branch (217:9): [True: 541, False: 5.48k]
  |  Branch (217:98): [True: 541, False: 5.48k]
  ------------------
  218|    541|        return set_error(serror, SCRIPT_ERR_SIG_DER);
  219|  5.48k|    } else if ((flags & SCRIPT_VERIFY_LOW_S) != 0 && !IsLowDERSignature(vchSig, serror)) {
  ------------------
  |  Branch (219:16): [True: 0, False: 5.48k]
  |  Branch (219:16): [True: 0, False: 5.48k]
  |  Branch (219:54): [True: 0, False: 0]
  ------------------
  220|       |        // serror is set
  221|      0|        return false;
  222|  5.48k|    } else if ((flags & SCRIPT_VERIFY_STRICTENC) != 0 && !IsDefinedHashtypeSignature(vchSig)) {
  ------------------
  |  Branch (222:16): [True: 0, False: 5.48k]
  |  Branch (222:16): [True: 0, False: 5.48k]
  |  Branch (222:58): [True: 0, False: 0]
  ------------------
  223|      0|        return set_error(serror, SCRIPT_ERR_SIG_HASHTYPE);
  224|      0|    }
  225|  5.48k|    return true;
  226|  6.02k|}
_Z13FindAndDeleteR7CScriptRKS_:
  240|  8.47k|{
  241|  8.47k|    int nFound = 0;
  242|  8.47k|    if (b.empty())
  ------------------
  |  Branch (242:9): [True: 0, False: 8.47k]
  ------------------
  243|      0|        return nFound;
  244|  8.47k|    CScript result;
  245|  8.47k|    CScript::const_iterator pc = script.begin(), pc2 = script.begin(), end = script.end();
  246|  8.47k|    opcodetype opcode;
  247|  8.47k|    do
  248|   414k|    {
  249|   414k|        result.insert(result.end(), pc2, pc);
  250|   436k|        while (static_cast<size_t>(end - pc) >= b.size() && std::equal(b.begin(), b.end(), pc))
  ------------------
  |  Branch (250:16): [True: 303k, False: 132k]
  |  Branch (250:61): [True: 21.6k, False: 282k]
  ------------------
  251|  21.6k|        {
  252|  21.6k|            pc = pc + b.size();
  253|  21.6k|            ++nFound;
  254|  21.6k|        }
  255|   414k|        pc2 = pc;
  256|   414k|    }
  257|   414k|    while (script.GetOp(pc, opcode));
  ------------------
  |  Branch (257:12): [True: 405k, False: 8.47k]
  ------------------
  258|       |
  259|  8.47k|    if (nFound > 0) {
  ------------------
  |  Branch (259:9): [True: 2.00k, False: 6.46k]
  ------------------
  260|  2.00k|        result.insert(result.end(), pc2, end);
  261|  2.00k|        script = std::move(result);
  262|  2.00k|    }
  263|       |
  264|  8.47k|    return nFound;
  265|  8.47k|}
_Z10EvalScriptRNSt3__16vectorINS0_IhNS_9allocatorIhEEEENS1_IS3_EEEERK7CScript19script_verify_flagsRK20BaseSignatureChecker10SigVersionR19ScriptExecutionDataP13ScriptError_t:
  418|  6.07k|{
  419|  6.07k|    static const CScriptNum bnZero(0);
  420|  6.07k|    static const CScriptNum bnOne(1);
  421|       |    // static const CScriptNum bnFalse(0);
  422|       |    // static const CScriptNum bnTrue(1);
  423|  6.07k|    static const valtype vchFalse(0);
  424|       |    // static const valtype vchZero(0);
  425|  6.07k|    static const valtype vchTrue(1, 1);
  426|       |
  427|       |    // sigversion cannot be TAPROOT here, as it admits no script execution.
  428|  6.07k|    assert(sigversion == SigVersion::BASE || sigversion == SigVersion::WITNESS_V0 || sigversion == SigVersion::TAPSCRIPT);
  ------------------
  |  Branch (428:5): [True: 6.07k, False: 0]
  |  Branch (428:5): [True: 0, False: 0]
  |  Branch (428:5): [True: 0, False: 0]
  |  Branch (428:5): [True: 6.07k, False: 0]
  ------------------
  429|       |
  430|  6.07k|    CScript::const_iterator pc = script.begin();
  431|  6.07k|    CScript::const_iterator pend = script.end();
  432|  6.07k|    CScript::const_iterator pbegincodehash = script.begin();
  433|  6.07k|    opcodetype opcode;
  434|  6.07k|    valtype vchPushValue;
  435|  6.07k|    ConditionStack vfExec;
  436|  6.07k|    std::vector<valtype> altstack;
  437|  6.07k|    set_error(serror, SCRIPT_ERR_UNKNOWN_ERROR);
  438|  6.07k|    if ((sigversion == SigVersion::BASE || sigversion == SigVersion::WITNESS_V0) && script.size() > MAX_SCRIPT_SIZE) {
  ------------------
  |  Branch (438:10): [True: 6.07k, False: 0]
  |  Branch (438:44): [True: 0, False: 0]
  |  Branch (438:85): [True: 0, False: 6.07k]
  ------------------
  439|      0|        return set_error(serror, SCRIPT_ERR_SCRIPT_SIZE);
  440|      0|    }
  441|  6.07k|    int nOpCount = 0;
  442|  6.07k|    bool fRequireMinimal = (flags & SCRIPT_VERIFY_MINIMALDATA) != 0;
  443|  6.07k|    uint32_t opcode_pos = 0;
  444|  6.07k|    execdata.m_codeseparator_pos = 0xFFFFFFFFUL;
  445|  6.07k|    execdata.m_codeseparator_pos_init = true;
  446|       |
  447|  6.07k|    try
  448|  6.07k|    {
  449|   102k|        for (; pc < pend; ++opcode_pos) {
  ------------------
  |  Branch (449:16): [True: 99.6k, False: 3.20k]
  ------------------
  450|  99.6k|            bool fExec = vfExec.all_true();
  451|       |
  452|       |            //
  453|       |            // Read instruction
  454|       |            //
  455|  99.6k|            if (!script.GetOp(pc, opcode, vchPushValue))
  ------------------
  |  Branch (455:17): [True: 443, False: 99.2k]
  ------------------
  456|    443|                return set_error(serror, SCRIPT_ERR_BAD_OPCODE);
  457|  99.2k|            if (vchPushValue.size() > MAX_SCRIPT_ELEMENT_SIZE)
  ------------------
  |  Branch (457:17): [True: 0, False: 99.2k]
  ------------------
  458|      0|                return set_error(serror, SCRIPT_ERR_PUSH_SIZE);
  459|       |
  460|  99.2k|            if (sigversion == SigVersion::BASE || sigversion == SigVersion::WITNESS_V0) {
  ------------------
  |  Branch (460:17): [True: 99.2k, False: 0]
  |  Branch (460:51): [True: 0, False: 0]
  ------------------
  461|       |                // Note how OP_RESERVED does not count towards the opcode limit.
  462|  99.2k|                if (opcode > OP_16 && ++nOpCount > MAX_OPS_PER_SCRIPT) {
  ------------------
  |  Branch (462:21): [True: 69.1k, False: 30.0k]
  |  Branch (462:39): [True: 1, False: 69.1k]
  ------------------
  463|      1|                    return set_error(serror, SCRIPT_ERR_OP_COUNT);
  464|      1|                }
  465|  99.2k|            }
  466|       |
  467|  99.2k|            if (opcode == OP_CAT ||
  ------------------
  |  Branch (467:17): [True: 6, False: 99.2k]
  ------------------
  468|  99.2k|                opcode == OP_SUBSTR ||
  ------------------
  |  Branch (468:17): [True: 11, False: 99.2k]
  ------------------
  469|  99.2k|                opcode == OP_LEFT ||
  ------------------
  |  Branch (469:17): [True: 16, False: 99.2k]
  ------------------
  470|  99.2k|                opcode == OP_RIGHT ||
  ------------------
  |  Branch (470:17): [True: 3, False: 99.2k]
  ------------------
  471|  99.2k|                opcode == OP_INVERT ||
  ------------------
  |  Branch (471:17): [True: 5, False: 99.2k]
  ------------------
  472|  99.2k|                opcode == OP_AND ||
  ------------------
  |  Branch (472:17): [True: 70, False: 99.1k]
  ------------------
  473|  99.1k|                opcode == OP_OR ||
  ------------------
  |  Branch (473:17): [True: 13, False: 99.1k]
  ------------------
  474|  99.1k|                opcode == OP_XOR ||
  ------------------
  |  Branch (474:17): [True: 4, False: 99.1k]
  ------------------
  475|  99.1k|                opcode == OP_2MUL ||
  ------------------
  |  Branch (475:17): [True: 3, False: 99.1k]
  ------------------
  476|  99.1k|                opcode == OP_2DIV ||
  ------------------
  |  Branch (476:17): [True: 14, False: 99.0k]
  ------------------
  477|  99.0k|                opcode == OP_MUL ||
  ------------------
  |  Branch (477:17): [True: 5, False: 99.0k]
  ------------------
  478|  99.0k|                opcode == OP_DIV ||
  ------------------
  |  Branch (478:17): [True: 10, False: 99.0k]
  ------------------
  479|  99.0k|                opcode == OP_MOD ||
  ------------------
  |  Branch (479:17): [True: 5, False: 99.0k]
  ------------------
  480|  99.0k|                opcode == OP_LSHIFT ||
  ------------------
  |  Branch (480:17): [True: 7, False: 99.0k]
  ------------------
  481|  99.0k|                opcode == OP_RSHIFT)
  ------------------
  |  Branch (481:17): [True: 11, False: 99.0k]
  ------------------
  482|    183|                return set_error(serror, SCRIPT_ERR_DISABLED_OPCODE); // Disabled opcodes (CVE-2010-5137).
  483|       |
  484|       |            // With SCRIPT_VERIFY_CONST_SCRIPTCODE, OP_CODESEPARATOR in non-segwit script is rejected even in an unexecuted branch
  485|  99.0k|            if (opcode == OP_CODESEPARATOR && sigversion == SigVersion::BASE && (flags & SCRIPT_VERIFY_CONST_SCRIPTCODE))
  ------------------
  |  Branch (485:17): [True: 5.60k, False: 93.4k]
  |  Branch (485:17): [True: 0, False: 99.0k]
  |  Branch (485:47): [True: 5.60k, False: 0]
  |  Branch (485:81): [True: 0, False: 5.60k]
  ------------------
  486|      0|                return set_error(serror, SCRIPT_ERR_OP_CODESEPARATOR);
  487|       |
  488|  99.0k|            if (fExec && 0 <= opcode && opcode <= OP_PUSHDATA4) {
  ------------------
  |  Branch (488:17): [True: 96.1k, False: 2.87k]
  |  Branch (488:26): [True: 96.1k, False: 0]
  |  Branch (488:41): [True: 18.5k, False: 77.6k]
  ------------------
  489|  18.5k|                if (fRequireMinimal && !CheckMinimalPush(vchPushValue, opcode)) {
  ------------------
  |  Branch (489:21): [True: 0, False: 18.5k]
  |  Branch (489:40): [True: 0, False: 0]
  ------------------
  490|      0|                    return set_error(serror, SCRIPT_ERR_MINIMALDATA);
  491|      0|                }
  492|  18.5k|                stack.push_back(vchPushValue);
  493|  80.4k|            } else if (fExec || (OP_IF <= opcode && opcode <= OP_ENDIF))
  ------------------
  |  Branch (493:24): [True: 77.6k, False: 2.87k]
  |  Branch (493:34): [True: 2.45k, False: 421]
  |  Branch (493:53): [True: 1.33k, False: 1.11k]
  ------------------
  494|  78.9k|            switch (opcode)
  495|  78.9k|            {
  496|       |                //
  497|       |                // Push value
  498|       |                //
  499|    440|                case OP_1NEGATE:
  ------------------
  |  Branch (499:17): [True: 440, False: 78.5k]
  ------------------
  500|  2.71k|                case OP_1:
  ------------------
  |  Branch (500:17): [True: 2.27k, False: 76.6k]
  ------------------
  501|  5.08k|                case OP_2:
  ------------------
  |  Branch (501:17): [True: 2.37k, False: 76.5k]
  ------------------
  502|  5.43k|                case OP_3:
  ------------------
  |  Branch (502:17): [True: 352, False: 78.6k]
  ------------------
  503|  5.82k|                case OP_4:
  ------------------
  |  Branch (503:17): [True: 382, False: 78.5k]
  ------------------
  504|  6.23k|                case OP_5:
  ------------------
  |  Branch (504:17): [True: 418, False: 78.5k]
  ------------------
  505|  6.65k|                case OP_6:
  ------------------
  |  Branch (505:17): [True: 417, False: 78.5k]
  ------------------
  506|  7.04k|                case OP_7:
  ------------------
  |  Branch (506:17): [True: 386, False: 78.5k]
  ------------------
  507|  7.32k|                case OP_8:
  ------------------
  |  Branch (507:17): [True: 279, False: 78.6k]
  ------------------
  508|  7.76k|                case OP_9:
  ------------------
  |  Branch (508:17): [True: 440, False: 78.5k]
  ------------------
  509|  8.06k|                case OP_10:
  ------------------
  |  Branch (509:17): [True: 305, False: 78.6k]
  ------------------
  510|  8.57k|                case OP_11:
  ------------------
  |  Branch (510:17): [True: 508, False: 78.4k]
  ------------------
  511|  8.77k|                case OP_12:
  ------------------
  |  Branch (511:17): [True: 203, False: 78.7k]
  ------------------
  512|  9.72k|                case OP_13:
  ------------------
  |  Branch (512:17): [True: 949, False: 78.0k]
  ------------------
  513|  10.0k|                case OP_14:
  ------------------
  |  Branch (513:17): [True: 297, False: 78.6k]
  ------------------
  514|  10.4k|                case OP_15:
  ------------------
  |  Branch (514:17): [True: 379, False: 78.5k]
  ------------------
  515|  11.1k|                case OP_16:
  ------------------
  |  Branch (515:17): [True: 703, False: 78.2k]
  ------------------
  516|  11.1k|                {
  517|       |                    // ( -- value)
  518|  11.1k|                    CScriptNum bn((int)opcode - (int)(OP_1 - 1));
  519|  11.1k|                    stack.push_back(bn.getvch());
  520|       |                    // The result of these opcodes should always be the minimal way to push the data
  521|       |                    // they push, so no need for a CheckMinimalPush here.
  522|  11.1k|                }
  523|  11.1k|                break;
  524|       |
  525|       |
  526|       |                //
  527|       |                // Control
  528|       |                //
  529|    279|                case OP_NOP:
  ------------------
  |  Branch (529:17): [True: 279, False: 78.6k]
  ------------------
  530|    279|                    break;
  531|       |
  532|    401|                case OP_CHECKLOCKTIMEVERIFY:
  ------------------
  |  Branch (532:17): [True: 401, False: 78.5k]
  ------------------
  533|    401|                {
  534|    401|                    if (!(flags & SCRIPT_VERIFY_CHECKLOCKTIMEVERIFY)) {
  ------------------
  |  Branch (534:25): [True: 401, False: 0]
  ------------------
  535|       |                        // not enabled; treat as a NOP2
  536|    401|                        break;
  537|    401|                    }
  538|       |
  539|      0|                    if (stack.size() < 1)
  ------------------
  |  Branch (539:25): [True: 0, False: 0]
  ------------------
  540|      0|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  541|       |
  542|       |                    // Note that elsewhere numeric opcodes are limited to
  543|       |                    // operands in the range -2**31+1 to 2**31-1, however it is
  544|       |                    // legal for opcodes to produce results exceeding that
  545|       |                    // range. This limitation is implemented by CScriptNum's
  546|       |                    // default 4-byte limit.
  547|       |                    //
  548|       |                    // If we kept to that limit we'd have a year 2038 problem,
  549|       |                    // even though the nLockTime field in transactions
  550|       |                    // themselves is uint32 which only becomes meaningless
  551|       |                    // after the year 2106.
  552|       |                    //
  553|       |                    // Thus as a special case we tell CScriptNum to accept up
  554|       |                    // to 5-byte bignums, which are good until 2**39-1, well
  555|       |                    // beyond the 2**32-1 limit of the nLockTime field itself.
  556|      0|                    const CScriptNum nLockTime(stacktop(-1), fRequireMinimal, 5);
  ------------------
  |  |   65|      0|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  557|       |
  558|       |                    // In the rare event that the argument may be < 0 due to
  559|       |                    // some arithmetic being done first, you can always use
  560|       |                    // 0 MAX CHECKLOCKTIMEVERIFY.
  561|      0|                    if (nLockTime < 0)
  ------------------
  |  Branch (561:25): [True: 0, False: 0]
  ------------------
  562|      0|                        return set_error(serror, SCRIPT_ERR_NEGATIVE_LOCKTIME);
  563|       |
  564|       |                    // Actually compare the specified lock time with the transaction.
  565|      0|                    if (!checker.CheckLockTime(nLockTime))
  ------------------
  |  Branch (565:25): [True: 0, False: 0]
  ------------------
  566|      0|                        return set_error(serror, SCRIPT_ERR_UNSATISFIED_LOCKTIME);
  567|       |
  568|      0|                    break;
  569|      0|                }
  570|       |
  571|    297|                case OP_CHECKSEQUENCEVERIFY:
  ------------------
  |  Branch (571:17): [True: 297, False: 78.6k]
  ------------------
  572|    297|                {
  573|    297|                    if (!(flags & SCRIPT_VERIFY_CHECKSEQUENCEVERIFY)) {
  ------------------
  |  Branch (573:25): [True: 297, False: 0]
  ------------------
  574|       |                        // not enabled; treat as a NOP3
  575|    297|                        break;
  576|    297|                    }
  577|       |
  578|      0|                    if (stack.size() < 1)
  ------------------
  |  Branch (578:25): [True: 0, False: 0]
  ------------------
  579|      0|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  580|       |
  581|       |                    // nSequence, like nLockTime, is a 32-bit unsigned integer
  582|       |                    // field. See the comment in CHECKLOCKTIMEVERIFY regarding
  583|       |                    // 5-byte numeric operands.
  584|      0|                    const CScriptNum nSequence(stacktop(-1), fRequireMinimal, 5);
  ------------------
  |  |   65|      0|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  585|       |
  586|       |                    // In the rare event that the argument may be < 0 due to
  587|       |                    // some arithmetic being done first, you can always use
  588|       |                    // 0 MAX CHECKSEQUENCEVERIFY.
  589|      0|                    if (nSequence < 0)
  ------------------
  |  Branch (589:25): [True: 0, False: 0]
  ------------------
  590|      0|                        return set_error(serror, SCRIPT_ERR_NEGATIVE_LOCKTIME);
  591|       |
  592|       |                    // To provide for future soft-fork extensibility, if the
  593|       |                    // operand has the disabled lock-time flag set,
  594|       |                    // CHECKSEQUENCEVERIFY behaves as a NOP.
  595|      0|                    if ((nSequence & CTxIn::SEQUENCE_LOCKTIME_DISABLE_FLAG) != 0)
  ------------------
  |  Branch (595:25): [True: 0, False: 0]
  ------------------
  596|      0|                        break;
  597|       |
  598|       |                    // Compare the specified sequence number with the input.
  599|      0|                    if (!checker.CheckSequence(nSequence))
  ------------------
  |  Branch (599:25): [True: 0, False: 0]
  ------------------
  600|      0|                        return set_error(serror, SCRIPT_ERR_UNSATISFIED_LOCKTIME);
  601|       |
  602|      0|                    break;
  603|      0|                }
  604|       |
  605|    976|                case OP_NOP1: case OP_NOP4: case OP_NOP5:
  ------------------
  |  Branch (605:17): [True: 466, False: 78.4k]
  |  Branch (605:31): [True: 242, False: 78.7k]
  |  Branch (605:45): [True: 268, False: 78.6k]
  ------------------
  606|  2.40k|                case OP_NOP6: case OP_NOP7: case OP_NOP8: case OP_NOP9: case OP_NOP10:
  ------------------
  |  Branch (606:17): [True: 262, False: 78.6k]
  |  Branch (606:31): [True: 320, False: 78.6k]
  |  Branch (606:45): [True: 231, False: 78.7k]
  |  Branch (606:59): [True: 376, False: 78.5k]
  |  Branch (606:73): [True: 237, False: 78.7k]
  ------------------
  607|  2.40k|                {
  608|  2.40k|                    if (flags & SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_NOPS)
  ------------------
  |  Branch (608:25): [True: 0, False: 2.40k]
  ------------------
  609|      0|                        return set_error(serror, SCRIPT_ERR_DISCOURAGE_UPGRADABLE_NOPS);
  610|  2.40k|                }
  611|  2.40k|                break;
  612|       |
  613|  2.40k|                case OP_IF:
  ------------------
  |  Branch (613:17): [True: 1.09k, False: 77.8k]
  ------------------
  614|  5.62k|                case OP_NOTIF:
  ------------------
  |  Branch (614:17): [True: 4.53k, False: 74.4k]
  ------------------
  615|  5.62k|                {
  616|       |                    // <expression> if [statements] [else [statements]] endif
  617|  5.62k|                    bool fValue = false;
  618|  5.62k|                    if (fExec)
  ------------------
  |  Branch (618:25): [True: 4.77k, False: 851]
  ------------------
  619|  4.77k|                    {
  620|  4.77k|                        if (stack.size() < 1)
  ------------------
  |  Branch (620:29): [True: 4, False: 4.77k]
  ------------------
  621|      4|                            return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  622|  4.77k|                        valtype& vch = stacktop(-1);
  ------------------
  |  |   65|  4.77k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  623|       |                        // Tapscript requires minimal IF/NOTIF inputs as a consensus rule.
  624|  4.77k|                        if (sigversion == SigVersion::TAPSCRIPT) {
  ------------------
  |  Branch (624:29): [True: 0, False: 4.77k]
  ------------------
  625|       |                            // The input argument to the OP_IF and OP_NOTIF opcodes must be either
  626|       |                            // exactly 0 (the empty vector) or exactly 1 (the one-byte vector with value 1).
  627|      0|                            if (vch.size() > 1 || (vch.size() == 1 && vch[0] != 1)) {
  ------------------
  |  Branch (627:33): [True: 0, False: 0]
  |  Branch (627:52): [True: 0, False: 0]
  |  Branch (627:71): [True: 0, False: 0]
  ------------------
  628|      0|                                return set_error(serror, SCRIPT_ERR_TAPSCRIPT_MINIMALIF);
  629|      0|                            }
  630|      0|                        }
  631|       |                        // Under witness v0 rules it is only a policy rule, enabled through SCRIPT_VERIFY_MINIMALIF.
  632|  4.77k|                        if (sigversion == SigVersion::WITNESS_V0 && (flags & SCRIPT_VERIFY_MINIMALIF)) {
  ------------------
  |  Branch (632:29): [True: 0, False: 4.77k]
  |  Branch (632:29): [True: 0, False: 4.77k]
  |  Branch (632:69): [True: 0, False: 0]
  ------------------
  633|      0|                            if (vch.size() > 1)
  ------------------
  |  Branch (633:33): [True: 0, False: 0]
  ------------------
  634|      0|                                return set_error(serror, SCRIPT_ERR_MINIMALIF);
  635|      0|                            if (vch.size() == 1 && vch[0] != 1)
  ------------------
  |  Branch (635:33): [True: 0, False: 0]
  |  Branch (635:52): [True: 0, False: 0]
  ------------------
  636|      0|                                return set_error(serror, SCRIPT_ERR_MINIMALIF);
  637|      0|                        }
  638|  4.77k|                        fValue = CastToBool(vch);
  639|  4.77k|                        if (opcode == OP_NOTIF)
  ------------------
  |  Branch (639:29): [True: 4.19k, False: 576]
  ------------------
  640|  4.19k|                            fValue = !fValue;
  641|  4.77k|                        popstack(stack);
  642|  4.77k|                    }
  643|  5.62k|                    vfExec.push_back(fValue);
  644|  5.62k|                }
  645|      0|                break;
  646|       |
  647|    449|                case OP_ELSE:
  ------------------
  |  Branch (647:17): [True: 449, False: 78.5k]
  ------------------
  648|    449|                {
  649|    449|                    if (vfExec.empty())
  ------------------
  |  Branch (649:25): [True: 3, False: 446]
  ------------------
  650|      3|                        return set_error(serror, SCRIPT_ERR_UNBALANCED_CONDITIONAL);
  651|    446|                    vfExec.toggle_top();
  652|    446|                }
  653|      0|                break;
  654|       |
  655|    172|                case OP_ENDIF:
  ------------------
  |  Branch (655:17): [True: 172, False: 78.7k]
  ------------------
  656|    172|                {
  657|    172|                    if (vfExec.empty())
  ------------------
  |  Branch (657:25): [True: 2, False: 170]
  ------------------
  658|      2|                        return set_error(serror, SCRIPT_ERR_UNBALANCED_CONDITIONAL);
  659|    170|                    vfExec.pop_back();
  660|    170|                }
  661|      0|                break;
  662|       |
  663|    301|                case OP_VERIFY:
  ------------------
  |  Branch (663:17): [True: 301, False: 78.6k]
  ------------------
  664|    301|                {
  665|       |                    // (true -- ) or
  666|       |                    // (false -- false) and return
  667|    301|                    if (stack.size() < 1)
  ------------------
  |  Branch (667:25): [True: 5, False: 296]
  ------------------
  668|      5|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  669|    296|                    bool fValue = CastToBool(stacktop(-1));
  ------------------
  |  |   65|    296|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  670|    296|                    if (fValue)
  ------------------
  |  Branch (670:25): [True: 295, False: 1]
  ------------------
  671|    295|                        popstack(stack);
  672|      1|                    else
  673|      1|                        return set_error(serror, SCRIPT_ERR_VERIFY);
  674|    296|                }
  675|    295|                break;
  676|       |
  677|    295|                case OP_RETURN:
  ------------------
  |  Branch (677:17): [True: 7, False: 78.9k]
  ------------------
  678|      7|                {
  679|      7|                    return set_error(serror, SCRIPT_ERR_OP_RETURN);
  680|    296|                }
  681|      0|                break;
  682|       |
  683|       |
  684|       |                //
  685|       |                // Stack ops
  686|       |                //
  687|    418|                case OP_TOALTSTACK:
  ------------------
  |  Branch (687:17): [True: 418, False: 78.5k]
  ------------------
  688|    418|                {
  689|    418|                    if (stack.size() < 1)
  ------------------
  |  Branch (689:25): [True: 1, False: 417]
  ------------------
  690|      1|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  691|    417|                    altstack.push_back(stacktop(-1));
  ------------------
  |  |   65|    417|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  692|    417|                    popstack(stack);
  693|    417|                }
  694|      0|                break;
  695|       |
  696|     99|                case OP_FROMALTSTACK:
  ------------------
  |  Branch (696:17): [True: 99, False: 78.8k]
  ------------------
  697|     99|                {
  698|     99|                    if (altstack.size() < 1)
  ------------------
  |  Branch (698:25): [True: 11, False: 88]
  ------------------
  699|     11|                        return set_error(serror, SCRIPT_ERR_INVALID_ALTSTACK_OPERATION);
  700|     88|                    stack.push_back(altstacktop(-1));
  ------------------
  |  |   66|     88|#define altstacktop(i) (altstack.at(size_t(int64_t(altstack.size()) + int64_t{i})))
  ------------------
  701|     88|                    popstack(altstack);
  702|     88|                }
  703|      0|                break;
  704|       |
  705|    128|                case OP_2DROP:
  ------------------
  |  Branch (705:17): [True: 128, False: 78.8k]
  ------------------
  706|    128|                {
  707|       |                    // (x1 x2 -- )
  708|    128|                    if (stack.size() < 2)
  ------------------
  |  Branch (708:25): [True: 4, False: 124]
  ------------------
  709|      4|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  710|    124|                    popstack(stack);
  711|    124|                    popstack(stack);
  712|    124|                }
  713|      0|                break;
  714|       |
  715|  10.1k|                case OP_2DUP:
  ------------------
  |  Branch (715:17): [True: 10.1k, False: 68.8k]
  ------------------
  716|  10.1k|                {
  717|       |                    // (x1 x2 -- x1 x2 x1 x2)
  718|  10.1k|                    if (stack.size() < 2)
  ------------------
  |  Branch (718:25): [True: 12, False: 10.1k]
  ------------------
  719|     12|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  720|  10.1k|                    valtype vch1 = stacktop(-2);
  ------------------
  |  |   65|  10.1k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  721|  10.1k|                    valtype vch2 = stacktop(-1);
  ------------------
  |  |   65|  10.1k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  722|  10.1k|                    stack.push_back(vch1);
  723|  10.1k|                    stack.push_back(vch2);
  724|  10.1k|                }
  725|      0|                break;
  726|       |
  727|  5.57k|                case OP_3DUP:
  ------------------
  |  Branch (727:17): [True: 5.57k, False: 73.3k]
  ------------------
  728|  5.57k|                {
  729|       |                    // (x1 x2 x3 -- x1 x2 x3 x1 x2 x3)
  730|  5.57k|                    if (stack.size() < 3)
  ------------------
  |  Branch (730:25): [True: 2, False: 5.57k]
  ------------------
  731|      2|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  732|  5.57k|                    valtype vch1 = stacktop(-3);
  ------------------
  |  |   65|  5.57k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  733|  5.57k|                    valtype vch2 = stacktop(-2);
  ------------------
  |  |   65|  5.57k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  734|  5.57k|                    valtype vch3 = stacktop(-1);
  ------------------
  |  |   65|  5.57k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  735|  5.57k|                    stack.push_back(vch1);
  736|  5.57k|                    stack.push_back(vch2);
  737|  5.57k|                    stack.push_back(vch3);
  738|  5.57k|                }
  739|      0|                break;
  740|       |
  741|    759|                case OP_2OVER:
  ------------------
  |  Branch (741:17): [True: 759, False: 78.2k]
  ------------------
  742|    759|                {
  743|       |                    // (x1 x2 x3 x4 -- x1 x2 x3 x4 x1 x2)
  744|    759|                    if (stack.size() < 4)
  ------------------
  |  Branch (744:25): [True: 7, False: 752]
  ------------------
  745|      7|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  746|    752|                    valtype vch1 = stacktop(-4);
  ------------------
  |  |   65|    752|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  747|    752|                    valtype vch2 = stacktop(-3);
  ------------------
  |  |   65|    752|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  748|    752|                    stack.push_back(vch1);
  749|    752|                    stack.push_back(vch2);
  750|    752|                }
  751|      0|                break;
  752|       |
  753|    556|                case OP_2ROT:
  ------------------
  |  Branch (753:17): [True: 556, False: 78.4k]
  ------------------
  754|    556|                {
  755|       |                    // (x1 x2 x3 x4 x5 x6 -- x3 x4 x5 x6 x1 x2)
  756|    556|                    if (stack.size() < 6)
  ------------------
  |  Branch (756:25): [True: 5, False: 551]
  ------------------
  757|      5|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  758|    551|                    valtype vch1 = stacktop(-6);
  ------------------
  |  |   65|    551|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  759|    551|                    valtype vch2 = stacktop(-5);
  ------------------
  |  |   65|    551|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  760|    551|                    stack.erase(stack.end()-6, stack.end()-4);
  761|    551|                    stack.push_back(vch1);
  762|    551|                    stack.push_back(vch2);
  763|    551|                }
  764|      0|                break;
  765|       |
  766|    690|                case OP_2SWAP:
  ------------------
  |  Branch (766:17): [True: 690, False: 78.2k]
  ------------------
  767|    690|                {
  768|       |                    // (x1 x2 x3 x4 -- x3 x4 x1 x2)
  769|    690|                    if (stack.size() < 4)
  ------------------
  |  Branch (769:25): [True: 21, False: 669]
  ------------------
  770|     21|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  771|    669|                    swap(stacktop(-4), stacktop(-2));
  ------------------
  |  |   65|    669|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
                                  swap(stacktop(-4), stacktop(-2));
  ------------------
  |  |   65|    669|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  772|    669|                    swap(stacktop(-3), stacktop(-1));
  ------------------
  |  |   65|    669|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
                                  swap(stacktop(-3), stacktop(-1));
  ------------------
  |  |   65|    669|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  773|    669|                }
  774|      0|                break;
  775|       |
  776|  5.15k|                case OP_IFDUP:
  ------------------
  |  Branch (776:17): [True: 5.15k, False: 73.8k]
  ------------------
  777|  5.15k|                {
  778|       |                    // (x - 0 | x x)
  779|  5.15k|                    if (stack.size() < 1)
  ------------------
  |  Branch (779:25): [True: 3, False: 5.15k]
  ------------------
  780|      3|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  781|  5.15k|                    valtype vch = stacktop(-1);
  ------------------
  |  |   65|  5.15k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  782|  5.15k|                    if (CastToBool(vch))
  ------------------
  |  Branch (782:25): [True: 2.67k, False: 2.47k]
  ------------------
  783|  2.67k|                        stack.push_back(vch);
  784|  5.15k|                }
  785|      0|                break;
  786|       |
  787|    688|                case OP_DEPTH:
  ------------------
  |  Branch (787:17): [True: 688, False: 78.2k]
  ------------------
  788|    688|                {
  789|       |                    // -- stacksize
  790|    688|                    CScriptNum bn(stack.size());
  791|    688|                    stack.push_back(bn.getvch());
  792|    688|                }
  793|    688|                break;
  794|       |
  795|    307|                case OP_DROP:
  ------------------
  |  Branch (795:17): [True: 307, False: 78.6k]
  ------------------
  796|    307|                {
  797|       |                    // (x -- )
  798|    307|                    if (stack.size() < 1)
  ------------------
  |  Branch (798:25): [True: 2, False: 305]
  ------------------
  799|      2|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  800|    305|                    popstack(stack);
  801|    305|                }
  802|      0|                break;
  803|       |
  804|    866|                case OP_DUP:
  ------------------
  |  Branch (804:17): [True: 866, False: 78.0k]
  ------------------
  805|    866|                {
  806|       |                    // (x -- x x)
  807|    866|                    if (stack.size() < 1)
  ------------------
  |  Branch (807:25): [True: 1, False: 865]
  ------------------
  808|      1|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  809|    865|                    valtype vch = stacktop(-1);
  ------------------
  |  |   65|    865|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  810|    865|                    stack.push_back(vch);
  811|    865|                }
  812|      0|                break;
  813|       |
  814|    282|                case OP_NIP:
  ------------------
  |  Branch (814:17): [True: 282, False: 78.6k]
  ------------------
  815|    282|                {
  816|       |                    // (x1 x2 -- x2)
  817|    282|                    if (stack.size() < 2)
  ------------------
  |  Branch (817:25): [True: 6, False: 276]
  ------------------
  818|      6|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  819|    276|                    stack.erase(stack.end() - 2);
  820|    276|                }
  821|      0|                break;
  822|       |
  823|    557|                case OP_OVER:
  ------------------
  |  Branch (823:17): [True: 557, False: 78.4k]
  ------------------
  824|    557|                {
  825|       |                    // (x1 x2 -- x1 x2 x1)
  826|    557|                    if (stack.size() < 2)
  ------------------
  |  Branch (826:25): [True: 3, False: 554]
  ------------------
  827|      3|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  828|    554|                    valtype vch = stacktop(-2);
  ------------------
  |  |   65|    554|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  829|    554|                    stack.push_back(vch);
  830|    554|                }
  831|      0|                break;
  832|       |
  833|    252|                case OP_PICK:
  ------------------
  |  Branch (833:17): [True: 252, False: 78.7k]
  ------------------
  834|    699|                case OP_ROLL:
  ------------------
  |  Branch (834:17): [True: 447, False: 78.5k]
  ------------------
  835|    699|                {
  836|       |                    // (xn ... x2 x1 x0 n - xn ... x2 x1 x0 xn)
  837|       |                    // (xn ... x2 x1 x0 n - ... x2 x1 x0 xn)
  838|    699|                    if (stack.size() < 2)
  ------------------
  |  Branch (838:25): [True: 5, False: 694]
  ------------------
  839|      5|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  840|    694|                    int n = CScriptNum(stacktop(-1), fRequireMinimal).getint();
  ------------------
  |  |   65|    694|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  841|    694|                    popstack(stack);
  842|    694|                    if (n < 0 || n >= (int)stack.size())
  ------------------
  |  Branch (842:25): [True: 47, False: 647]
  |  Branch (842:34): [True: 65, False: 582]
  ------------------
  843|    109|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  844|    585|                    valtype vch = stacktop(-n-1);
  ------------------
  |  |   65|    585|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  845|    585|                    if (opcode == OP_ROLL)
  ------------------
  |  Branch (845:25): [True: 354, False: 231]
  ------------------
  846|    354|                        stack.erase(stack.end()-n-1);
  847|    585|                    stack.push_back(vch);
  848|    585|                }
  849|      0|                break;
  850|       |
  851|    268|                case OP_ROT:
  ------------------
  |  Branch (851:17): [True: 268, False: 78.6k]
  ------------------
  852|    268|                {
  853|       |                    // (x1 x2 x3 -- x2 x3 x1)
  854|       |                    //  x2 x1 x3  after first swap
  855|       |                    //  x2 x3 x1  after second swap
  856|    268|                    if (stack.size() < 3)
  ------------------
  |  Branch (856:25): [True: 3, False: 265]
  ------------------
  857|      3|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  858|    265|                    swap(stacktop(-3), stacktop(-2));
  ------------------
  |  |   65|    265|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
                                  swap(stacktop(-3), stacktop(-2));
  ------------------
  |  |   65|    265|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  859|    265|                    swap(stacktop(-2), stacktop(-1));
  ------------------
  |  |   65|    265|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
                                  swap(stacktop(-2), stacktop(-1));
  ------------------
  |  |   65|    265|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  860|    265|                }
  861|      0|                break;
  862|       |
  863|    299|                case OP_SWAP:
  ------------------
  |  Branch (863:17): [True: 299, False: 78.6k]
  ------------------
  864|    299|                {
  865|       |                    // (x1 x2 -- x2 x1)
  866|    299|                    if (stack.size() < 2)
  ------------------
  |  Branch (866:25): [True: 4, False: 295]
  ------------------
  867|      4|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  868|    295|                    swap(stacktop(-2), stacktop(-1));
  ------------------
  |  |   65|    295|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
                                  swap(stacktop(-2), stacktop(-1));
  ------------------
  |  |   65|    295|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  869|    295|                }
  870|      0|                break;
  871|       |
  872|  1.12k|                case OP_TUCK:
  ------------------
  |  Branch (872:17): [True: 1.12k, False: 77.8k]
  ------------------
  873|  1.12k|                {
  874|       |                    // (x1 x2 -- x2 x1 x2)
  875|  1.12k|                    if (stack.size() < 2)
  ------------------
  |  Branch (875:25): [True: 2, False: 1.11k]
  ------------------
  876|      2|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  877|  1.11k|                    valtype vch = stacktop(-1);
  ------------------
  |  |   65|  1.11k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  878|  1.11k|                    stack.insert(stack.end()-2, vch);
  879|  1.11k|                }
  880|      0|                break;
  881|       |
  882|       |
  883|    356|                case OP_SIZE:
  ------------------
  |  Branch (883:17): [True: 356, False: 78.6k]
  ------------------
  884|    356|                {
  885|       |                    // (in -- in size)
  886|    356|                    if (stack.size() < 1)
  ------------------
  |  Branch (886:25): [True: 1, False: 355]
  ------------------
  887|      1|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  888|    355|                    CScriptNum bn(stacktop(-1).size());
  ------------------
  |  |   65|    355|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  889|    355|                    stack.push_back(bn.getvch());
  890|    355|                }
  891|      0|                break;
  892|       |
  893|       |
  894|       |                //
  895|       |                // Bitwise logic
  896|       |                //
  897|    520|                case OP_EQUAL:
  ------------------
  |  Branch (897:17): [True: 520, False: 78.4k]
  ------------------
  898|    614|                case OP_EQUALVERIFY:
  ------------------
  |  Branch (898:17): [True: 94, False: 78.8k]
  ------------------
  899|       |                //case OP_NOTEQUAL: // use OP_NUMNOTEQUAL
  900|    614|                {
  901|       |                    // (x1 x2 - bool)
  902|    614|                    if (stack.size() < 2)
  ------------------
  |  Branch (902:25): [True: 9, False: 605]
  ------------------
  903|      9|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  904|    605|                    valtype& vch1 = stacktop(-2);
  ------------------
  |  |   65|    605|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  905|    605|                    valtype& vch2 = stacktop(-1);
  ------------------
  |  |   65|    605|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  906|    605|                    bool fEqual = (vch1 == vch2);
  907|       |                    // OP_NOTEQUAL is disabled because it would be too easy to say
  908|       |                    // something like n != 1 and have some wiseguy pass in 1 with extra
  909|       |                    // zero bytes after it (numerically, 0x01 == 0x0001 == 0x000001)
  910|       |                    //if (opcode == OP_NOTEQUAL)
  911|       |                    //    fEqual = !fEqual;
  912|    605|                    popstack(stack);
  913|    605|                    popstack(stack);
  914|    605|                    stack.push_back(fEqual ? vchTrue : vchFalse);
  ------------------
  |  Branch (914:37): [True: 264, False: 341]
  ------------------
  915|    605|                    if (opcode == OP_EQUALVERIFY)
  ------------------
  |  Branch (915:25): [True: 93, False: 512]
  ------------------
  916|     93|                    {
  917|     93|                        if (fEqual)
  ------------------
  |  Branch (917:29): [True: 83, False: 10]
  ------------------
  918|     83|                            popstack(stack);
  919|     10|                        else
  920|     10|                            return set_error(serror, SCRIPT_ERR_EQUALVERIFY);
  921|     93|                    }
  922|    605|                }
  923|    595|                break;
  924|       |
  925|       |
  926|       |                //
  927|       |                // Numeric
  928|       |                //
  929|    653|                case OP_1ADD:
  ------------------
  |  Branch (929:17): [True: 653, False: 78.3k]
  ------------------
  930|  1.31k|                case OP_1SUB:
  ------------------
  |  Branch (930:17): [True: 659, False: 78.3k]
  ------------------
  931|  1.88k|                case OP_NEGATE:
  ------------------
  |  Branch (931:17): [True: 577, False: 78.3k]
  ------------------
  932|  2.55k|                case OP_ABS:
  ------------------
  |  Branch (932:17): [True: 662, False: 78.2k]
  ------------------
  933|  2.97k|                case OP_NOT:
  ------------------
  |  Branch (933:17): [True: 423, False: 78.5k]
  ------------------
  934|  5.04k|                case OP_0NOTEQUAL:
  ------------------
  |  Branch (934:17): [True: 2.06k, False: 76.8k]
  ------------------
  935|  5.04k|                {
  936|       |                    // (in -- out)
  937|  5.04k|                    if (stack.size() < 1)
  ------------------
  |  Branch (937:25): [True: 1, False: 5.03k]
  ------------------
  938|      1|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  939|  5.03k|                    CScriptNum bn(stacktop(-1), fRequireMinimal);
  ------------------
  |  |   65|  5.03k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  940|  5.03k|                    switch (opcode)
  941|  5.03k|                    {
  942|    653|                    case OP_1ADD:       bn += bnOne; break;
  ------------------
  |  Branch (942:21): [True: 653, False: 4.38k]
  ------------------
  943|    657|                    case OP_1SUB:       bn -= bnOne; break;
  ------------------
  |  Branch (943:21): [True: 657, False: 4.38k]
  ------------------
  944|    577|                    case OP_NEGATE:     bn = -bn; break;
  ------------------
  |  Branch (944:21): [True: 577, False: 4.46k]
  ------------------
  945|    660|                    case OP_ABS:        if (bn < bnZero) bn = -bn; break;
  ------------------
  |  Branch (945:21): [True: 660, False: 4.37k]
  |  Branch (945:45): [True: 135, False: 525]
  ------------------
  946|    423|                    case OP_NOT:        bn = (bn == bnZero); break;
  ------------------
  |  Branch (946:21): [True: 423, False: 4.61k]
  ------------------
  947|  1.99k|                    case OP_0NOTEQUAL:  bn = (bn != bnZero); break;
  ------------------
  |  Branch (947:21): [True: 1.99k, False: 3.04k]
  ------------------
  948|      0|                    default:            assert(!"invalid opcode"); break;
  ------------------
  |  Branch (948:21): [True: 0, False: 5.03k]
  |  Branch (948:41): [Folded, False: 0]
  ------------------
  949|  5.03k|                    }
  950|  4.96k|                    popstack(stack);
  951|  4.96k|                    stack.push_back(bn.getvch());
  952|  4.96k|                }
  953|      0|                break;
  954|       |
  955|    257|                case OP_ADD:
  ------------------
  |  Branch (955:17): [True: 257, False: 78.7k]
  ------------------
  956|    538|                case OP_SUB:
  ------------------
  |  Branch (956:17): [True: 281, False: 78.6k]
  ------------------
  957|  1.18k|                case OP_BOOLAND:
  ------------------
  |  Branch (957:17): [True: 647, False: 78.3k]
  ------------------
  958|  1.85k|                case OP_BOOLOR:
  ------------------
  |  Branch (958:17): [True: 665, False: 78.2k]
  ------------------
  959|  2.20k|                case OP_NUMEQUAL:
  ------------------
  |  Branch (959:17): [True: 350, False: 78.6k]
  ------------------
  960|  2.33k|                case OP_NUMEQUALVERIFY:
  ------------------
  |  Branch (960:17): [True: 130, False: 78.8k]
  ------------------
  961|  2.66k|                case OP_NUMNOTEQUAL:
  ------------------
  |  Branch (961:17): [True: 337, False: 78.6k]
  ------------------
  962|  3.09k|                case OP_LESSTHAN:
  ------------------
  |  Branch (962:17): [True: 425, False: 78.5k]
  ------------------
  963|  3.44k|                case OP_GREATERTHAN:
  ------------------
  |  Branch (963:17): [True: 356, False: 78.6k]
  ------------------
  964|  3.81k|                case OP_LESSTHANOREQUAL:
  ------------------
  |  Branch (964:17): [True: 364, False: 78.5k]
  ------------------
  965|  4.20k|                case OP_GREATERTHANOREQUAL:
  ------------------
  |  Branch (965:17): [True: 391, False: 78.5k]
  ------------------
  966|  4.72k|                case OP_MIN:
  ------------------
  |  Branch (966:17): [True: 525, False: 78.4k]
  ------------------
  967|  5.27k|                case OP_MAX:
  ------------------
  |  Branch (967:17): [True: 551, False: 78.4k]
  ------------------
  968|  5.27k|                {
  969|       |                    // (x1 x2 -- out)
  970|  5.27k|                    if (stack.size() < 2)
  ------------------
  |  Branch (970:25): [True: 88, False: 5.19k]
  ------------------
  971|     88|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  972|  5.19k|                    CScriptNum bn1(stacktop(-2), fRequireMinimal);
  ------------------
  |  |   65|  5.19k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  973|  5.19k|                    CScriptNum bn2(stacktop(-1), fRequireMinimal);
  ------------------
  |  |   65|  5.19k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  974|  5.19k|                    CScriptNum bn(0);
  975|  5.19k|                    switch (opcode)
  976|  5.19k|                    {
  977|    253|                    case OP_ADD:
  ------------------
  |  Branch (977:21): [True: 253, False: 4.93k]
  ------------------
  978|    253|                        bn = bn1 + bn2;
  979|    253|                        break;
  980|       |
  981|    278|                    case OP_SUB:
  ------------------
  |  Branch (981:21): [True: 278, False: 4.91k]
  ------------------
  982|    278|                        bn = bn1 - bn2;
  983|    278|                        break;
  984|       |
  985|    638|                    case OP_BOOLAND:             bn = (bn1 != bnZero && bn2 != bnZero); break;
  ------------------
  |  Branch (985:21): [True: 638, False: 4.55k]
  |  Branch (985:56): [True: 360, False: 278]
  |  Branch (985:73): [True: 324, False: 36]
  ------------------
  986|    649|                    case OP_BOOLOR:              bn = (bn1 != bnZero || bn2 != bnZero); break;
  ------------------
  |  Branch (986:21): [True: 649, False: 4.54k]
  |  Branch (986:56): [True: 333, False: 316]
  |  Branch (986:73): [True: 101, False: 215]
  ------------------
  987|    343|                    case OP_NUMEQUAL:            bn = (bn1 == bn2); break;
  ------------------
  |  Branch (987:21): [True: 343, False: 4.84k]
  ------------------
  988|    129|                    case OP_NUMEQUALVERIFY:      bn = (bn1 == bn2); break;
  ------------------
  |  Branch (988:21): [True: 129, False: 5.06k]
  ------------------
  989|    333|                    case OP_NUMNOTEQUAL:         bn = (bn1 != bn2); break;
  ------------------
  |  Branch (989:21): [True: 333, False: 4.85k]
  ------------------
  990|    420|                    case OP_LESSTHAN:            bn = (bn1 < bn2); break;
  ------------------
  |  Branch (990:21): [True: 420, False: 4.77k]
  ------------------
  991|    337|                    case OP_GREATERTHAN:         bn = (bn1 > bn2); break;
  ------------------
  |  Branch (991:21): [True: 337, False: 4.85k]
  ------------------
  992|    355|                    case OP_LESSTHANOREQUAL:     bn = (bn1 <= bn2); break;
  ------------------
  |  Branch (992:21): [True: 355, False: 4.83k]
  ------------------
  993|    377|                    case OP_GREATERTHANOREQUAL:  bn = (bn1 >= bn2); break;
  ------------------
  |  Branch (993:21): [True: 377, False: 4.81k]
  ------------------
  994|    501|                    case OP_MIN:                 bn = (bn1 < bn2 ? bn1 : bn2); break;
  ------------------
  |  Branch (994:21): [True: 501, False: 4.69k]
  |  Branch (994:56): [True: 171, False: 330]
  ------------------
  995|    547|                    case OP_MAX:                 bn = (bn1 > bn2 ? bn1 : bn2); break;
  ------------------
  |  Branch (995:21): [True: 547, False: 4.64k]
  |  Branch (995:56): [True: 144, False: 403]
  ------------------
  996|      0|                    default:                     assert(!"invalid opcode"); break;
  ------------------
  |  Branch (996:21): [True: 0, False: 5.19k]
  |  Branch (996:50): [Folded, False: 0]
  ------------------
  997|  5.19k|                    }
  998|  5.16k|                    popstack(stack);
  999|  5.16k|                    popstack(stack);
 1000|  5.16k|                    stack.push_back(bn.getvch());
 1001|       |
 1002|  5.16k|                    if (opcode == OP_NUMEQUALVERIFY)
  ------------------
  |  Branch (1002:25): [True: 129, False: 5.03k]
  ------------------
 1003|    129|                    {
 1004|    129|                        if (CastToBool(stacktop(-1)))
  ------------------
  |  |   65|    129|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  |  Branch (1004:29): [True: 102, False: 27]
  ------------------
 1005|    102|                            popstack(stack);
 1006|     27|                        else
 1007|     27|                            return set_error(serror, SCRIPT_ERR_NUMEQUALVERIFY);
 1008|    129|                    }
 1009|  5.16k|                }
 1010|  5.13k|                break;
 1011|       |
 1012|  5.13k|                case OP_WITHIN:
  ------------------
  |  Branch (1012:17): [True: 581, False: 78.3k]
  ------------------
 1013|    581|                {
 1014|       |                    // (x min max -- out)
 1015|    581|                    if (stack.size() < 3)
  ------------------
  |  Branch (1015:25): [True: 26, False: 555]
  ------------------
 1016|     26|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1017|    555|                    CScriptNum bn1(stacktop(-3), fRequireMinimal);
  ------------------
  |  |   65|    555|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1018|    555|                    CScriptNum bn2(stacktop(-2), fRequireMinimal);
  ------------------
  |  |   65|    555|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1019|    555|                    CScriptNum bn3(stacktop(-1), fRequireMinimal);
  ------------------
  |  |   65|    555|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1020|    555|                    bool fValue = (bn2 <= bn1 && bn1 < bn3);
  ------------------
  |  Branch (1020:36): [True: 390, False: 165]
  |  Branch (1020:50): [True: 172, False: 218]
  ------------------
 1021|    555|                    popstack(stack);
 1022|    555|                    popstack(stack);
 1023|    555|                    popstack(stack);
 1024|    555|                    stack.push_back(fValue ? vchTrue : vchFalse);
  ------------------
  |  Branch (1024:37): [True: 172, False: 383]
  ------------------
 1025|    555|                }
 1026|      0|                break;
 1027|       |
 1028|       |
 1029|       |                //
 1030|       |                // Crypto
 1031|       |                //
 1032|    714|                case OP_RIPEMD160:
  ------------------
  |  Branch (1032:17): [True: 714, False: 78.2k]
  ------------------
 1033|  1.47k|                case OP_SHA1:
  ------------------
  |  Branch (1033:17): [True: 758, False: 78.2k]
  ------------------
 1034|  1.87k|                case OP_SHA256:
  ------------------
  |  Branch (1034:17): [True: 406, False: 78.5k]
  ------------------
 1035|  2.67k|                case OP_HASH160:
  ------------------
  |  Branch (1035:17): [True: 799, False: 78.1k]
  ------------------
 1036|  3.23k|                case OP_HASH256:
  ------------------
  |  Branch (1036:17): [True: 554, False: 78.4k]
  ------------------
 1037|  3.23k|                {
 1038|       |                    // (in -- hash)
 1039|  3.23k|                    if (stack.size() < 1)
  ------------------
  |  Branch (1039:25): [True: 2, False: 3.22k]
  ------------------
 1040|      2|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1041|  3.22k|                    valtype& vch = stacktop(-1);
  ------------------
  |  |   65|  3.22k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1042|  3.22k|                    valtype vchHash((opcode == OP_RIPEMD160 || opcode == OP_SHA1 || opcode == OP_HASH160) ? 20 : 32);
  ------------------
  |  Branch (1042:38): [True: 713, False: 2.51k]
  |  Branch (1042:64): [True: 758, False: 1.75k]
  |  Branch (1042:85): [True: 798, False: 960]
  ------------------
 1043|  3.22k|                    if (opcode == OP_RIPEMD160)
  ------------------
  |  Branch (1043:25): [True: 713, False: 2.51k]
  ------------------
 1044|    713|                        CRIPEMD160().Write(vch.data(), vch.size()).Finalize(vchHash.data());
 1045|  2.51k|                    else if (opcode == OP_SHA1)
  ------------------
  |  Branch (1045:30): [True: 758, False: 1.75k]
  ------------------
 1046|    758|                        CSHA1().Write(vch.data(), vch.size()).Finalize(vchHash.data());
 1047|  1.75k|                    else if (opcode == OP_SHA256)
  ------------------
  |  Branch (1047:30): [True: 406, False: 1.35k]
  ------------------
 1048|    406|                        CSHA256().Write(vch.data(), vch.size()).Finalize(vchHash.data());
 1049|  1.35k|                    else if (opcode == OP_HASH160)
  ------------------
  |  Branch (1049:30): [True: 798, False: 554]
  ------------------
 1050|    798|                        CHash160().Write(vch).Finalize(vchHash);
 1051|    554|                    else if (opcode == OP_HASH256)
  ------------------
  |  Branch (1051:30): [True: 554, False: 0]
  ------------------
 1052|    554|                        CHash256().Write(vch).Finalize(vchHash);
 1053|  3.22k|                    popstack(stack);
 1054|  3.22k|                    stack.push_back(vchHash);
 1055|  3.22k|                }
 1056|      0|                break;
 1057|       |
 1058|  5.36k|                case OP_CODESEPARATOR:
  ------------------
  |  Branch (1058:17): [True: 5.36k, False: 73.5k]
  ------------------
 1059|  5.36k|                {
 1060|       |                    // If SCRIPT_VERIFY_CONST_SCRIPTCODE flag is set, use of OP_CODESEPARATOR is rejected in pre-segwit
 1061|       |                    // script, even in an unexecuted branch (this is checked above the opcode case statement).
 1062|       |
 1063|       |                    // Hash starts after the code separator
 1064|  5.36k|                    pbegincodehash = pc;
 1065|  5.36k|                    execdata.m_codeseparator_pos = opcode_pos;
 1066|  5.36k|                }
 1067|  5.36k|                break;
 1068|       |
 1069|  5.68k|                case OP_CHECKSIG:
  ------------------
  |  Branch (1069:17): [True: 5.68k, False: 73.2k]
  ------------------
 1070|  5.77k|                case OP_CHECKSIGVERIFY:
  ------------------
  |  Branch (1070:17): [True: 83, False: 78.8k]
  ------------------
 1071|  5.77k|                {
 1072|       |                    // (sig pubkey -- bool)
 1073|  5.77k|                    if (stack.size() < 2)
  ------------------
  |  Branch (1073:25): [True: 34, False: 5.73k]
  ------------------
 1074|     34|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1075|       |
 1076|  5.73k|                    valtype& vchSig    = stacktop(-2);
  ------------------
  |  |   65|  5.73k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1077|  5.73k|                    valtype& vchPubKey = stacktop(-1);
  ------------------
  |  |   65|  5.73k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1078|       |
 1079|  5.73k|                    bool fSuccess = true;
 1080|  5.73k|                    if (!EvalChecksig(vchSig, vchPubKey, pbegincodehash, pend, execdata, flags, checker, sigversion, serror, fSuccess)) return false;
  ------------------
  |  Branch (1080:25): [True: 171, False: 5.56k]
  ------------------
 1081|  5.56k|                    popstack(stack);
 1082|  5.56k|                    popstack(stack);
 1083|  5.56k|                    stack.push_back(fSuccess ? vchTrue : vchFalse);
  ------------------
  |  Branch (1083:37): [True: 0, False: 5.56k]
  ------------------
 1084|  5.56k|                    if (opcode == OP_CHECKSIGVERIFY)
  ------------------
  |  Branch (1084:25): [True: 30, False: 5.53k]
  ------------------
 1085|     30|                    {
 1086|     30|                        if (fSuccess)
  ------------------
  |  Branch (1086:29): [True: 0, False: 30]
  ------------------
 1087|      0|                            popstack(stack);
 1088|     30|                        else
 1089|     30|                            return set_error(serror, SCRIPT_ERR_CHECKSIGVERIFY);
 1090|     30|                    }
 1091|  5.56k|                }
 1092|  5.53k|                break;
 1093|       |
 1094|  5.53k|                case OP_CHECKSIGADD:
  ------------------
  |  Branch (1094:17): [True: 13, False: 78.9k]
  ------------------
 1095|     13|                {
 1096|       |                    // OP_CHECKSIGADD is only available in Tapscript
 1097|     13|                    if (sigversion == SigVersion::BASE || sigversion == SigVersion::WITNESS_V0) return set_error(serror, SCRIPT_ERR_BAD_OPCODE);
  ------------------
  |  Branch (1097:25): [True: 13, False: 0]
  |  Branch (1097:59): [True: 0, False: 0]
  ------------------
 1098|       |
 1099|       |                    // (sig num pubkey -- num)
 1100|      0|                    if (stack.size() < 3) return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
  ------------------
  |  Branch (1100:25): [True: 0, False: 0]
  ------------------
 1101|       |
 1102|      0|                    const valtype& sig = stacktop(-3);
  ------------------
  |  |   65|      0|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1103|      0|                    const CScriptNum num(stacktop(-2), fRequireMinimal);
  ------------------
  |  |   65|      0|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1104|      0|                    const valtype& pubkey = stacktop(-1);
  ------------------
  |  |   65|      0|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1105|       |
 1106|      0|                    bool success = true;
 1107|      0|                    if (!EvalChecksig(sig, pubkey, pbegincodehash, pend, execdata, flags, checker, sigversion, serror, success)) return false;
  ------------------
  |  Branch (1107:25): [True: 0, False: 0]
  ------------------
 1108|      0|                    popstack(stack);
 1109|      0|                    popstack(stack);
 1110|      0|                    popstack(stack);
 1111|      0|                    stack.push_back((num + (success ? 1 : 0)).getvch());
  ------------------
  |  Branch (1111:45): [True: 0, False: 0]
  ------------------
 1112|      0|                }
 1113|      0|                break;
 1114|       |
 1115|  2.61k|                case OP_CHECKMULTISIG:
  ------------------
  |  Branch (1115:17): [True: 2.61k, False: 76.3k]
  ------------------
 1116|  2.85k|                case OP_CHECKMULTISIGVERIFY:
  ------------------
  |  Branch (1116:17): [True: 247, False: 78.7k]
  ------------------
 1117|  2.85k|                {
 1118|  2.85k|                    if (sigversion == SigVersion::TAPSCRIPT) return set_error(serror, SCRIPT_ERR_TAPSCRIPT_CHECKMULTISIG);
  ------------------
  |  Branch (1118:25): [True: 0, False: 2.85k]
  ------------------
 1119|       |
 1120|       |                    // ([sig ...] num_of_signatures [pubkey ...] num_of_pubkeys -- bool)
 1121|       |
 1122|  2.85k|                    int i = 1;
 1123|  2.85k|                    if ((int)stack.size() < i)
  ------------------
  |  Branch (1123:25): [True: 2, False: 2.85k]
  ------------------
 1124|      2|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1125|       |
 1126|  2.85k|                    int nKeysCount = CScriptNum(stacktop(-i), fRequireMinimal).getint();
  ------------------
  |  |   65|  2.85k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1127|  2.85k|                    if (nKeysCount < 0 || nKeysCount > MAX_PUBKEYS_PER_MULTISIG)
  ------------------
  |  Branch (1127:25): [True: 66, False: 2.78k]
  |  Branch (1127:43): [True: 57, False: 2.73k]
  ------------------
 1128|    109|                        return set_error(serror, SCRIPT_ERR_PUBKEY_COUNT);
 1129|  2.74k|                    nOpCount += nKeysCount;
 1130|  2.74k|                    if (nOpCount > MAX_OPS_PER_SCRIPT)
  ------------------
  |  Branch (1130:25): [True: 1, False: 2.74k]
  ------------------
 1131|      1|                        return set_error(serror, SCRIPT_ERR_OP_COUNT);
 1132|  2.74k|                    int ikey = ++i;
 1133|       |                    // ikey2 is the position of last non-signature item in the stack. Top stack item = 1.
 1134|       |                    // With SCRIPT_VERIFY_NULLFAIL, this is used for cleanup if operation fails.
 1135|  2.74k|                    int ikey2 = nKeysCount + 2;
 1136|  2.74k|                    i += nKeysCount;
 1137|  2.74k|                    if ((int)stack.size() < i)
  ------------------
  |  Branch (1137:25): [True: 14, False: 2.73k]
  ------------------
 1138|     14|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1139|       |
 1140|  2.73k|                    int nSigsCount = CScriptNum(stacktop(-i), fRequireMinimal).getint();
  ------------------
  |  |   65|  2.73k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1141|  2.73k|                    if (nSigsCount < 0 || nSigsCount > nKeysCount)
  ------------------
  |  Branch (1141:25): [True: 81, False: 2.65k]
  |  Branch (1141:43): [True: 69, False: 2.58k]
  ------------------
 1142|    132|                        return set_error(serror, SCRIPT_ERR_SIG_COUNT);
 1143|  2.59k|                    int isig = ++i;
 1144|  2.59k|                    i += nSigsCount;
 1145|  2.59k|                    if ((int)stack.size() < i)
  ------------------
  |  Branch (1145:25): [True: 470, False: 2.12k]
  ------------------
 1146|    470|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1147|       |
 1148|       |                    // Subset of script starting at the most recent codeseparator
 1149|  2.12k|                    CScript scriptCode(pbegincodehash, pend);
 1150|       |
 1151|       |                    // Drop the signature in pre-segwit scripts but not segwit scripts
 1152|  4.86k|                    for (int k = 0; k < nSigsCount; k++)
  ------------------
  |  Branch (1152:37): [True: 2.73k, False: 2.12k]
  ------------------
 1153|  2.73k|                    {
 1154|  2.73k|                        valtype& vchSig = stacktop(-isig-k);
  ------------------
  |  |   65|  2.73k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1155|  2.73k|                        if (sigversion == SigVersion::BASE) {
  ------------------
  |  Branch (1155:29): [True: 2.73k, False: 0]
  ------------------
 1156|  2.73k|                            int found = FindAndDelete(scriptCode, CScript() << vchSig);
 1157|  2.73k|                            if (found > 0 && (flags & SCRIPT_VERIFY_CONST_SCRIPTCODE))
  ------------------
  |  Branch (1157:33): [True: 203, False: 2.53k]
  |  Branch (1157:33): [True: 0, False: 2.73k]
  |  Branch (1157:46): [True: 0, False: 203]
  ------------------
 1158|      0|                                return set_error(serror, SCRIPT_ERR_SIG_FINDANDDELETE);
 1159|  2.73k|                        }
 1160|  2.73k|                    }
 1161|       |
 1162|  2.12k|                    bool fSuccess = true;
 1163|  5.14k|                    while (fSuccess && nSigsCount > 0)
  ------------------
  |  Branch (1163:28): [True: 3.80k, False: 1.34k]
  |  Branch (1163:40): [True: 3.38k, False: 414]
  ------------------
 1164|  3.38k|                    {
 1165|  3.38k|                        valtype& vchSig    = stacktop(-isig);
  ------------------
  |  |   65|  3.38k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1166|  3.38k|                        valtype& vchPubKey = stacktop(-ikey);
  ------------------
  |  |   65|  3.38k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
 1167|       |
 1168|       |                        // Note how this makes the exact order of pubkey/signature evaluation
 1169|       |                        // distinguishable by CHECKMULTISIG NOT if the STRICTENC flag is set.
 1170|       |                        // See the script_(in)valid tests for details.
 1171|  3.38k|                        if (!CheckSignatureEncoding(vchSig, flags, serror) || !CheckPubKeyEncoding(vchPubKey, flags, sigversion, serror)) {
  ------------------
  |  Branch (1171:29): [True: 370, False: 3.01k]
  |  Branch (1171:79): [True: 0, False: 3.01k]
  ------------------
 1172|       |                            // serror is set
 1173|    370|                            return false;
 1174|    370|                        }
 1175|       |
 1176|       |                        // Check signature
 1177|  3.01k|                        bool fOk = checker.CheckECDSASignature(vchSig, vchPubKey, scriptCode, sigversion);
 1178|       |
 1179|  3.01k|                        if (fOk) {
  ------------------
  |  Branch (1179:29): [True: 0, False: 3.01k]
  ------------------
 1180|      0|                            isig++;
 1181|      0|                            nSigsCount--;
 1182|      0|                        }
 1183|  3.01k|                        ikey++;
 1184|  3.01k|                        nKeysCount--;
 1185|       |
 1186|       |                        // If there are more signatures left than keys left,
 1187|       |                        // then too many signatures have failed. Exit early,
 1188|       |                        // without checking any further signatures.
 1189|  3.01k|                        if (nSigsCount > nKeysCount)
  ------------------
  |  Branch (1189:29): [True: 1.32k, False: 1.69k]
  ------------------
 1190|  1.32k|                            fSuccess = false;
 1191|  3.01k|                    }
 1192|       |
 1193|       |                    // Clean up stack of actual arguments
 1194|  11.1k|                    while (i-- > 1) {
  ------------------
  |  Branch (1194:28): [True: 9.36k, False: 1.75k]
  ------------------
 1195|       |                        // If the operation failed, we require that all signatures must be empty vector
 1196|  9.36k|                        if (!fSuccess && (flags & SCRIPT_VERIFY_NULLFAIL) && !ikey2 && stacktop(-1).size())
  ------------------
  |  |   65|      0|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  |  Branch (1196:29): [True: 8.27k, False: 1.09k]
  |  Branch (1196:29): [True: 0, False: 9.36k]
  |  Branch (1196:42): [True: 0, False: 8.27k]
  |  Branch (1196:78): [True: 0, False: 0]
  |  Branch (1196:88): [True: 0, False: 0]
  ------------------
 1197|      0|                            return set_error(serror, SCRIPT_ERR_SIG_NULLFAIL);
 1198|  9.36k|                        if (ikey2 > 0)
  ------------------
  |  Branch (1198:29): [True: 7.40k, False: 1.96k]
  ------------------
 1199|  7.40k|                            ikey2--;
 1200|  9.36k|                        popstack(stack);
 1201|  9.36k|                    }
 1202|       |
 1203|       |                    // A bug causes CHECKMULTISIG to consume one extra argument
 1204|       |                    // whose contents were not checked in any way.
 1205|       |                    //
 1206|       |                    // Unfortunately this is a potential source of mutability,
 1207|       |                    // so optionally verify it is exactly equal to zero prior
 1208|       |                    // to removing it from the stack.
 1209|  1.75k|                    if (stack.size() < 1)
  ------------------
  |  Branch (1209:25): [True: 0, False: 1.75k]
  ------------------
 1210|      0|                        return set_error(serror, SCRIPT_ERR_INVALID_STACK_OPERATION);
 1211|  1.75k|                    if ((flags & SCRIPT_VERIFY_NULLDUMMY) && stacktop(-1).size())
  ------------------
  |  |   65|  1.74k|#define stacktop(i) (stack.at(size_t(int64_t(stack.size()) + int64_t{i})))
  ------------------
  |  Branch (1211:25): [True: 1.74k, False: 18]
  |  Branch (1211:25): [True: 154, False: 1.60k]
  |  Branch (1211:62): [True: 154, False: 1.58k]
  ------------------
 1212|    154|                        return set_error(serror, SCRIPT_ERR_SIG_NULLDUMMY);
 1213|  1.60k|                    popstack(stack);
 1214|       |
 1215|  1.60k|                    stack.push_back(fSuccess ? vchTrue : vchFalse);
  ------------------
  |  Branch (1215:37): [True: 401, False: 1.20k]
  ------------------
 1216|       |
 1217|  1.60k|                    if (opcode == OP_CHECKMULTISIGVERIFY)
  ------------------
  |  Branch (1217:25): [True: 179, False: 1.42k]
  ------------------
 1218|    179|                    {
 1219|    179|                        if (fSuccess)
  ------------------
  |  Branch (1219:29): [True: 175, False: 4]
  ------------------
 1220|    175|                            popstack(stack);
 1221|      4|                        else
 1222|      4|                            return set_error(serror, SCRIPT_ERR_CHECKMULTISIGVERIFY);
 1223|    179|                    }
 1224|  1.60k|                }
 1225|  1.60k|                break;
 1226|       |
 1227|  1.60k|                default:
  ------------------
  |  Branch (1227:17): [True: 211, False: 78.7k]
  ------------------
 1228|    211|                    return set_error(serror, SCRIPT_ERR_BAD_OPCODE);
 1229|  78.9k|            }
 1230|       |
 1231|       |            // Size limits
 1232|  96.8k|            if (stack.size() + altstack.size() > MAX_STACK_SIZE)
  ------------------
  |  Branch (1232:17): [True: 0, False: 96.8k]
  ------------------
 1233|      0|                return set_error(serror, SCRIPT_ERR_STACK_SIZE);
 1234|  96.8k|        }
 1235|  6.07k|    }
 1236|  6.07k|    catch (const scriptnum_error&)
 1237|  6.07k|    {
 1238|    139|        return set_error(serror, SCRIPT_ERR_SCRIPTNUM);
 1239|    139|    }
 1240|  6.07k|    catch (...)
 1241|  6.07k|    {
 1242|      0|        return set_error(serror, SCRIPT_ERR_UNKNOWN_ERROR);
 1243|      0|    }
 1244|       |
 1245|  3.20k|    if (!vfExec.empty())
  ------------------
  |  Branch (1245:9): [True: 159, False: 3.04k]
  ------------------
 1246|    159|        return set_error(serror, SCRIPT_ERR_UNBALANCED_CONDITIONAL);
 1247|       |
 1248|  3.04k|    return set_success(serror);
 1249|  3.20k|}
_Z10EvalScriptRNSt3__16vectorINS0_IhNS_9allocatorIhEEEENS1_IS3_EEEERK7CScript19script_verify_flagsRK20BaseSignatureChecker10SigVersionP13ScriptError_t:
 1252|  6.07k|{
 1253|  6.07k|    ScriptExecutionData execdata;
 1254|  6.07k|    return EvalScript(stack, script, flags, checker, sigversion, execdata, serror);
 1255|  6.07k|}
_ZN26PrecomputedTransactionData4InitI12CTransactionEEvRKT_ONSt3__16vectorI6CTxOutNS5_9allocatorIS7_EEEEb:
 1414|  4.08k|{
 1415|  4.08k|    assert(!m_spent_outputs_ready);
  ------------------
  |  Branch (1415:5): [True: 4.08k, False: 0]
  ------------------
 1416|       |
 1417|  4.08k|    m_spent_outputs = std::move(spent_outputs);
 1418|  4.08k|    if (!m_spent_outputs.empty()) {
  ------------------
  |  Branch (1418:9): [True: 4.08k, False: 0]
  ------------------
 1419|  4.08k|        assert(m_spent_outputs.size() == txTo.vin.size());
  ------------------
  |  Branch (1419:9): [True: 4.08k, False: 0]
  ------------------
 1420|  4.08k|        m_spent_outputs_ready = true;
 1421|  4.08k|    }
 1422|       |
 1423|       |    // Determine which precomputation-impacting features this transaction uses.
 1424|  4.08k|    bool uses_bip143_segwit = force;
 1425|  4.08k|    bool uses_bip341_taproot = force;
 1426|  8.17k|    for (size_t inpos = 0; inpos < txTo.vin.size() && !(uses_bip143_segwit && uses_bip341_taproot); ++inpos) {
  ------------------
  |  Branch (1426:28): [True: 4.08k, False: 4.08k]
  |  Branch (1426:57): [True: 0, False: 4.08k]
  |  Branch (1426:79): [True: 0, False: 0]
  ------------------
 1427|  4.08k|        if (!txTo.vin[inpos].scriptWitness.IsNull()) {
  ------------------
  |  Branch (1427:13): [True: 804, False: 3.28k]
  ------------------
 1428|    804|            if (m_spent_outputs_ready && m_spent_outputs[inpos].scriptPubKey.size() == 2 + WITNESS_V1_TAPROOT_SIZE &&
  ------------------
  |  Branch (1428:17): [True: 804, False: 0]
  |  Branch (1428:42): [True: 0, False: 804]
  ------------------
 1429|      0|                m_spent_outputs[inpos].scriptPubKey[0] == OP_1) {
  ------------------
  |  Branch (1429:17): [True: 0, False: 0]
  ------------------
 1430|       |                // Treat every witness-bearing spend with 34-byte scriptPubKey that starts with OP_1 as a Taproot
 1431|       |                // spend. This only works if spent_outputs was provided as well, but if it wasn't, actual validation
 1432|       |                // will fail anyway. Note that this branch may trigger for scriptPubKeys that aren't actually segwit
 1433|       |                // but in that case validation will fail as SCRIPT_ERR_WITNESS_UNEXPECTED anyway.
 1434|      0|                uses_bip341_taproot = true;
 1435|    804|            } else {
 1436|       |                // Treat every spend that's not known to native witness v1 as a Witness v0 spend. This branch may
 1437|       |                // also be taken for unknown witness versions, but it is harmless, and being precise would require
 1438|       |                // P2SH evaluation to find the redeemScript.
 1439|    804|                uses_bip143_segwit = true;
 1440|    804|            }
 1441|    804|        }
 1442|  4.08k|        if (uses_bip341_taproot && uses_bip143_segwit) break; // No need to scan further if we already need all.
  ------------------
  |  Branch (1442:13): [True: 0, False: 4.08k]
  |  Branch (1442:36): [True: 0, False: 0]
  ------------------
 1443|  4.08k|    }
 1444|       |
 1445|  4.08k|    if (uses_bip143_segwit || uses_bip341_taproot) {
  ------------------
  |  Branch (1445:9): [True: 804, False: 3.28k]
  |  Branch (1445:31): [True: 0, False: 3.28k]
  ------------------
 1446|       |        // Computations shared between both sighash schemes.
 1447|    804|        m_prevouts_single_hash = GetPrevoutsSHA256(txTo);
 1448|    804|        m_sequences_single_hash = GetSequencesSHA256(txTo);
 1449|    804|        m_outputs_single_hash = GetOutputsSHA256(txTo);
 1450|    804|    }
 1451|  4.08k|    if (uses_bip143_segwit) {
  ------------------
  |  Branch (1451:9): [True: 804, False: 3.28k]
  ------------------
 1452|    804|        hashPrevouts = SHA256Uint256(m_prevouts_single_hash);
 1453|    804|        hashSequence = SHA256Uint256(m_sequences_single_hash);
 1454|    804|        hashOutputs = SHA256Uint256(m_outputs_single_hash);
 1455|    804|        m_bip143_segwit_ready = true;
 1456|    804|    }
 1457|  4.08k|    if (uses_bip341_taproot && m_spent_outputs_ready) {
  ------------------
  |  Branch (1457:9): [True: 0, False: 4.08k]
  |  Branch (1457:32): [True: 0, False: 0]
  ------------------
 1458|      0|        m_spent_amounts_single_hash = GetSpentAmountsSHA256(m_spent_outputs);
 1459|      0|        m_spent_scripts_single_hash = GetSpentScriptsSHA256(m_spent_outputs);
 1460|      0|        m_bip341_taproot_ready = true;
 1461|      0|    }
 1462|  4.08k|}
_ZNK12SigHashCache10CacheIndexEi:
 1583|  7.62k|{
 1584|       |    // Note that we do not distinguish between BASE and WITNESS_V0 to determine the cache index,
 1585|       |    // because no input can simultaneously use both.
 1586|  7.62k|    return 3 * !!(hash_type & SIGHASH_ANYONECANPAY) +
 1587|  7.62k|           2 * ((hash_type & 0x1f) == SIGHASH_SINGLE) +
 1588|  7.62k|           1 * ((hash_type & 0x1f) == SIGHASH_NONE);
 1589|  7.62k|}
_ZNK12SigHashCache4LoadEiRK7CScriptR10HashWriter:
 1592|  5.13k|{
 1593|  5.13k|    auto& entry = m_cache_entries[CacheIndex(hash_type)];
 1594|  5.13k|    if (entry.has_value()) {
  ------------------
  |  Branch (1594:9): [True: 3.68k, False: 1.45k]
  ------------------
 1595|  3.68k|        if (script_code == entry->first) {
  ------------------
  |  Branch (1595:13): [True: 2.65k, False: 1.03k]
  ------------------
 1596|  2.65k|            writer = HashWriter(entry->second);
 1597|  2.65k|            return true;
 1598|  2.65k|        }
 1599|  3.68k|    }
 1600|  2.48k|    return false;
 1601|  5.13k|}
_ZN12SigHashCache5StoreEiRK7CScriptRK10HashWriter:
 1604|  2.48k|{
 1605|  2.48k|    auto& entry = m_cache_entries[CacheIndex(hash_type)];
 1606|  2.48k|    entry.emplace(script_code, writer);
 1607|  2.48k|}
_ZNK34GenericTransactionSignatureCheckerI12CTransactionE20VerifyECDSASignatureERKNSt3__16vectorIhNS2_9allocatorIhEEEERK7CPubKeyRK7uint256:
 1691|  5.13k|{
 1692|  5.13k|    return pubkey.Verify(sighash, vchSig);
 1693|  5.13k|}
_ZNK34GenericTransactionSignatureCheckerI12CTransactionE19CheckECDSASignatureERKNSt3__16vectorIhNS2_9allocatorIhEEEES8_RK7CScript10SigVersion:
 1703|  8.58k|{
 1704|  8.58k|    CPubKey pubkey(vchPubKey);
 1705|  8.58k|    if (!pubkey.IsValid())
  ------------------
  |  Branch (1705:9): [True: 2.56k, False: 6.02k]
  ------------------
 1706|  2.56k|        return false;
 1707|       |
 1708|       |    // Hash type is one byte tacked on to the end of the signature
 1709|  6.02k|    std::vector<unsigned char> vchSig(vchSigIn);
 1710|  6.02k|    if (vchSig.empty())
  ------------------
  |  Branch (1710:9): [True: 882, False: 5.13k]
  ------------------
 1711|    882|        return false;
 1712|  5.13k|    int nHashType = vchSig.back();
 1713|  5.13k|    vchSig.pop_back();
 1714|       |
 1715|       |    // Witness sighashes need the amount.
 1716|  5.13k|    if (sigversion == SigVersion::WITNESS_V0 && amount < 0) return HandleMissingData(m_mdb);
  ------------------
  |  Branch (1716:9): [True: 0, False: 5.13k]
  |  Branch (1716:49): [True: 0, False: 0]
  ------------------
 1717|       |
 1718|  5.13k|    uint256 sighash = SignatureHash(scriptCode, *txTo, nIn, nHashType, amount, sigversion, this->txdata, &m_sighash_cache);
 1719|       |
 1720|  5.13k|    if (!VerifyECDSASignature(vchSig, pubkey, sighash))
  ------------------
  |  Branch (1720:9): [True: 5.13k, False: 0]
  ------------------
 1721|  5.13k|        return false;
 1722|       |
 1723|      0|    return true;
 1724|  5.13k|}
_Z12VerifyScriptRK7CScriptS1_PK14CScriptWitness19script_verify_flagsRK20BaseSignatureCheckerP13ScriptError_t:
 2013|  4.08k|{
 2014|  4.08k|    static const CScriptWitness emptyWitness;
 2015|  4.08k|    if (witness == nullptr) {
  ------------------
  |  Branch (2015:9): [True: 0, False: 4.08k]
  ------------------
 2016|      0|        witness = &emptyWitness;
 2017|      0|    }
 2018|  4.08k|    bool hadWitness = false;
 2019|       |
 2020|  4.08k|    set_error(serror, SCRIPT_ERR_UNKNOWN_ERROR);
 2021|       |
 2022|  4.08k|    if ((flags & SCRIPT_VERIFY_SIGPUSHONLY) != 0 && !scriptSig.IsPushOnly()) {
  ------------------
  |  Branch (2022:9): [True: 0, False: 4.08k]
  |  Branch (2022:9): [True: 0, False: 4.08k]
  |  Branch (2022:53): [True: 0, False: 0]
  ------------------
 2023|      0|        return set_error(serror, SCRIPT_ERR_SIG_PUSHONLY);
 2024|      0|    }
 2025|       |
 2026|       |    // scriptSig and scriptPubKey must be evaluated sequentially on the same stack
 2027|       |    // rather than being simply concatenated (see CVE-2010-5141)
 2028|  4.08k|    std::vector<std::vector<unsigned char> > stack, stackCopy;
 2029|  4.08k|    if (!EvalScript(stack, scriptSig, flags, checker, SigVersion::BASE, serror))
  ------------------
  |  Branch (2029:9): [True: 2.10k, False: 1.98k]
  ------------------
 2030|       |        // serror is set
 2031|  2.10k|        return false;
 2032|  1.98k|    if (flags & SCRIPT_VERIFY_P2SH)
  ------------------
  |  Branch (2032:9): [True: 1.98k, False: 0]
  ------------------
 2033|  1.98k|        stackCopy = stack;
 2034|  1.98k|    if (!EvalScript(stack, scriptPubKey, flags, checker, SigVersion::BASE, serror))
  ------------------
  |  Branch (2034:9): [True: 925, False: 1.05k]
  ------------------
 2035|       |        // serror is set
 2036|    925|        return false;
 2037|  1.05k|    if (stack.empty())
  ------------------
  |  Branch (2037:9): [True: 0, False: 1.05k]
  ------------------
 2038|      0|        return set_error(serror, SCRIPT_ERR_EVAL_FALSE);
 2039|  1.05k|    if (CastToBool(stack.back()) == false)
  ------------------
  |  Branch (2039:9): [True: 1.05k, False: 0]
  ------------------
 2040|  1.05k|        return set_error(serror, SCRIPT_ERR_EVAL_FALSE);
 2041|       |
 2042|       |    // Bare witness programs
 2043|      0|    int witnessversion;
 2044|      0|    std::vector<unsigned char> witnessprogram;
 2045|      0|    if (flags & SCRIPT_VERIFY_WITNESS) {
  ------------------
  |  Branch (2045:9): [True: 0, False: 0]
  ------------------
 2046|      0|        if (scriptPubKey.IsWitnessProgram(witnessversion, witnessprogram)) {
  ------------------
  |  Branch (2046:13): [True: 0, False: 0]
  ------------------
 2047|      0|            hadWitness = true;
 2048|      0|            if (scriptSig.size() != 0) {
  ------------------
  |  Branch (2048:17): [True: 0, False: 0]
  ------------------
 2049|       |                // The scriptSig must be _exactly_ CScript(), otherwise we reintroduce malleability.
 2050|      0|                return set_error(serror, SCRIPT_ERR_WITNESS_MALLEATED);
 2051|      0|            }
 2052|      0|            if (!VerifyWitnessProgram(*witness, witnessversion, witnessprogram, flags, checker, serror, /*is_p2sh=*/false)) {
  ------------------
  |  Branch (2052:17): [True: 0, False: 0]
  ------------------
 2053|      0|                return false;
 2054|      0|            }
 2055|       |            // Bypass the cleanstack check at the end. The actual stack is obviously not clean
 2056|       |            // for witness programs.
 2057|      0|            stack.resize(1);
 2058|      0|        }
 2059|      0|    }
 2060|       |
 2061|       |    // Additional validation for spend-to-script-hash transactions:
 2062|      0|    if ((flags & SCRIPT_VERIFY_P2SH) && scriptPubKey.IsPayToScriptHash())
  ------------------
  |  Branch (2062:9): [True: 0, False: 0]
  |  Branch (2062:9): [True: 0, False: 0]
  |  Branch (2062:41): [True: 0, False: 0]
  ------------------
 2063|      0|    {
 2064|       |        // scriptSig must be literals-only or validation fails
 2065|      0|        if (!scriptSig.IsPushOnly())
  ------------------
  |  Branch (2065:13): [True: 0, False: 0]
  ------------------
 2066|      0|            return set_error(serror, SCRIPT_ERR_SIG_PUSHONLY);
 2067|       |
 2068|       |        // Restore stack.
 2069|      0|        swap(stack, stackCopy);
 2070|       |
 2071|       |        // stack cannot be empty here, because if it was the
 2072|       |        // P2SH  HASH <> EQUAL  scriptPubKey would be evaluated with
 2073|       |        // an empty stack and the EvalScript above would return false.
 2074|      0|        assert(!stack.empty());
  ------------------
  |  Branch (2074:9): [True: 0, False: 0]
  ------------------
 2075|       |
 2076|      0|        const valtype& pubKeySerialized = stack.back();
 2077|      0|        CScript pubKey2(pubKeySerialized.begin(), pubKeySerialized.end());
 2078|      0|        popstack(stack);
 2079|       |
 2080|      0|        if (!EvalScript(stack, pubKey2, flags, checker, SigVersion::BASE, serror))
  ------------------
  |  Branch (2080:13): [True: 0, False: 0]
  ------------------
 2081|       |            // serror is set
 2082|      0|            return false;
 2083|      0|        if (stack.empty())
  ------------------
  |  Branch (2083:13): [True: 0, False: 0]
  ------------------
 2084|      0|            return set_error(serror, SCRIPT_ERR_EVAL_FALSE);
 2085|      0|        if (!CastToBool(stack.back()))
  ------------------
  |  Branch (2085:13): [True: 0, False: 0]
  ------------------
 2086|      0|            return set_error(serror, SCRIPT_ERR_EVAL_FALSE);
 2087|       |
 2088|       |        // P2SH witness program
 2089|      0|        if (flags & SCRIPT_VERIFY_WITNESS) {
  ------------------
  |  Branch (2089:13): [True: 0, False: 0]
  ------------------
 2090|      0|            if (pubKey2.IsWitnessProgram(witnessversion, witnessprogram)) {
  ------------------
  |  Branch (2090:17): [True: 0, False: 0]
  ------------------
 2091|      0|                hadWitness = true;
 2092|      0|                if (scriptSig != CScript() << std::vector<unsigned char>(pubKey2.begin(), pubKey2.end())) {
  ------------------
  |  Branch (2092:21): [True: 0, False: 0]
  ------------------
 2093|       |                    // The scriptSig must be _exactly_ a single push of the redeemScript. Otherwise we
 2094|       |                    // reintroduce malleability.
 2095|      0|                    return set_error(serror, SCRIPT_ERR_WITNESS_MALLEATED_P2SH);
 2096|      0|                }
 2097|      0|                if (!VerifyWitnessProgram(*witness, witnessversion, witnessprogram, flags, checker, serror, /*is_p2sh=*/true)) {
  ------------------
  |  Branch (2097:21): [True: 0, False: 0]
  ------------------
 2098|      0|                    return false;
 2099|      0|                }
 2100|       |                // Bypass the cleanstack check at the end. The actual stack is obviously not clean
 2101|       |                // for witness programs.
 2102|      0|                stack.resize(1);
 2103|      0|            }
 2104|      0|        }
 2105|      0|    }
 2106|       |
 2107|       |    // The CLEANSTACK check is only performed after potential P2SH evaluation,
 2108|       |    // as the non-P2SH evaluation of a P2SH script will obviously not result in
 2109|       |    // a clean stack (the P2SH inputs remain). The same holds for witness evaluation.
 2110|      0|    if ((flags & SCRIPT_VERIFY_CLEANSTACK) != 0) {
  ------------------
  |  Branch (2110:9): [True: 0, False: 0]
  ------------------
 2111|       |        // Disallow CLEANSTACK without P2SH, as otherwise a switch CLEANSTACK->P2SH+CLEANSTACK
 2112|       |        // would be possible, which is not a softfork (and P2SH should be one).
 2113|      0|        assert((flags & SCRIPT_VERIFY_P2SH) != 0);
  ------------------
  |  Branch (2113:9): [True: 0, False: 0]
  ------------------
 2114|      0|        assert((flags & SCRIPT_VERIFY_WITNESS) != 0);
  ------------------
  |  Branch (2114:9): [True: 0, False: 0]
  ------------------
 2115|      0|        if (stack.size() != 1) {
  ------------------
  |  Branch (2115:13): [True: 0, False: 0]
  ------------------
 2116|      0|            return set_error(serror, SCRIPT_ERR_CLEANSTACK);
 2117|      0|        }
 2118|      0|    }
 2119|       |
 2120|      0|    if (flags & SCRIPT_VERIFY_WITNESS) {
  ------------------
  |  Branch (2120:9): [True: 0, False: 0]
  ------------------
 2121|       |        // We can't check for correct unexpected witness data if P2SH was off, so require
 2122|       |        // that WITNESS implies P2SH. Otherwise, going from WITNESS->P2SH+WITNESS would be
 2123|       |        // possible, which is not a softfork.
 2124|      0|        assert((flags & SCRIPT_VERIFY_P2SH) != 0);
  ------------------
  |  Branch (2124:9): [True: 0, False: 0]
  ------------------
 2125|      0|        if (!hadWitness && !witness->IsNull()) {
  ------------------
  |  Branch (2125:13): [True: 0, False: 0]
  |  Branch (2125:28): [True: 0, False: 0]
  ------------------
 2126|      0|            return set_error(serror, SCRIPT_ERR_WITNESS_UNEXPECTED);
 2127|      0|        }
 2128|      0|    }
 2129|       |
 2130|      0|    return set_success(serror);
 2131|      0|}
interpreter.cpp:_ZL24IsValidSignatureEncodingRKNSt3__16vectorIhNS_9allocatorIhEEEE:
  118|  6.02k|bool static IsValidSignatureEncoding(const std::vector<unsigned char> &sig) {
  119|       |    // Format: 0x30 [total-length] 0x02 [R-length] [R] 0x02 [S-length] [S] [sighash]
  120|       |    // * total-length: 1-byte length descriptor of everything that follows,
  121|       |    //   excluding the sighash byte.
  122|       |    // * R-length: 1-byte length descriptor of the R value that follows.
  123|       |    // * R: arbitrary-length big-endian encoded R value. It must use the shortest
  124|       |    //   possible encoding for a positive integer (which means no null bytes at
  125|       |    //   the start, except a single one when the next byte has its highest bit set).
  126|       |    // * S-length: 1-byte length descriptor of the S value that follows.
  127|       |    // * S: arbitrary-length big-endian encoded S value. The same rules apply.
  128|       |    // * sighash: 1-byte value indicating what data is hashed (not part of the DER
  129|       |    //   signature)
  130|       |
  131|       |    // Minimum and maximum size constraints.
  132|  6.02k|    if (sig.size() < 9) return false;
  ------------------
  |  Branch (132:9): [True: 309, False: 5.71k]
  ------------------
  133|  5.71k|    if (sig.size() > 73) return false;
  ------------------
  |  Branch (133:9): [True: 4, False: 5.70k]
  ------------------
  134|       |
  135|       |    // A signature is of type 0x30 (compound).
  136|  5.70k|    if (sig[0] != 0x30) return false;
  ------------------
  |  Branch (136:9): [True: 166, False: 5.54k]
  ------------------
  137|       |
  138|       |    // Make sure the length covers the entire signature.
  139|  5.54k|    if (sig[1] != sig.size() - 3) return false;
  ------------------
  |  Branch (139:9): [True: 13, False: 5.53k]
  ------------------
  140|       |
  141|       |    // Extract the length of the R element.
  142|  5.53k|    unsigned int lenR = sig[3];
  143|       |
  144|       |    // Make sure the length of the S element is still inside the signature.
  145|  5.53k|    if (5 + lenR >= sig.size()) return false;
  ------------------
  |  Branch (145:9): [True: 4, False: 5.52k]
  ------------------
  146|       |
  147|       |    // Extract the length of the S element.
  148|  5.52k|    unsigned int lenS = sig[5 + lenR];
  149|       |
  150|       |    // Verify that the length of the signature matches the sum of the length
  151|       |    // of the elements.
  152|  5.52k|    if ((size_t)(lenR + lenS + 7) != sig.size()) return false;
  ------------------
  |  Branch (152:9): [True: 6, False: 5.52k]
  ------------------
  153|       |
  154|       |    // Check whether the R element is an integer.
  155|  5.52k|    if (sig[2] != 0x02) return false;
  ------------------
  |  Branch (155:9): [True: 14, False: 5.50k]
  ------------------
  156|       |
  157|       |    // Zero-length integers are not allowed for R.
  158|  5.50k|    if (lenR == 0) return false;
  ------------------
  |  Branch (158:9): [True: 1, False: 5.50k]
  ------------------
  159|       |
  160|       |    // Negative numbers are not allowed for R.
  161|  5.50k|    if (sig[4] & 0x80) return false;
  ------------------
  |  Branch (161:9): [True: 6, False: 5.49k]
  ------------------
  162|       |
  163|       |    // Null bytes at the start of R are not allowed, unless R would
  164|       |    // otherwise be interpreted as a negative number.
  165|  5.49k|    if (lenR > 1 && (sig[4] == 0x00) && !(sig[5] & 0x80)) return false;
  ------------------
  |  Branch (165:9): [True: 5.32k, False: 175]
  |  Branch (165:21): [True: 540, False: 4.78k]
  |  Branch (165:41): [True: 2, False: 538]
  ------------------
  166|       |
  167|       |    // Check whether the S element is an integer.
  168|  5.49k|    if (sig[lenR + 4] != 0x02) return false;
  ------------------
  |  Branch (168:9): [True: 5, False: 5.49k]
  ------------------
  169|       |
  170|       |    // Zero-length integers are not allowed for S.
  171|  5.49k|    if (lenS == 0) return false;
  ------------------
  |  Branch (171:9): [True: 1, False: 5.49k]
  ------------------
  172|       |
  173|       |    // Negative numbers are not allowed for S.
  174|  5.49k|    if (sig[lenR + 6] & 0x80) return false;
  ------------------
  |  Branch (174:9): [True: 6, False: 5.48k]
  ------------------
  175|       |
  176|       |    // Null bytes at the start of S are not allowed, unless S would otherwise be
  177|       |    // interpreted as a negative number.
  178|  5.48k|    if (lenS > 1 && (sig[lenR + 6] == 0x00) && !(sig[lenR + 7] & 0x80)) return false;
  ------------------
  |  Branch (178:9): [True: 5.48k, False: 2]
  |  Branch (178:21): [True: 3.67k, False: 1.81k]
  |  Branch (178:48): [True: 4, False: 3.66k]
  ------------------
  179|       |
  180|  5.48k|    return true;
  181|  5.48k|}
interpreter.cpp:_ZN12_GLOBAL__N_19set_errorEP13ScriptError_tS0_:
   38|  14.2k|{
   39|  14.2k|    if (ret)
  ------------------
  |  Branch (39:9): [True: 0, False: 14.2k]
  ------------------
   40|      0|        *ret = serror;
   41|  14.2k|    return false;
   42|  14.2k|}
interpreter.cpp:_ZNK12_GLOBAL__N_114ConditionStack8all_trueEv:
  295|  99.6k|    bool all_true() const { return m_first_false_pos == NO_FALSE; }
interpreter.cpp:_ZL8popstackRNSt3__16vectorINS0_IhNS_9allocatorIhEEEENS1_IS3_EEEE:
   68|  50.6k|{
   69|  50.6k|    if (stack.empty())
  ------------------
  |  Branch (69:9): [True: 0, False: 50.6k]
  ------------------
   70|      0|        throw std::runtime_error("popstack(): stack empty");
   71|  50.6k|    stack.pop_back();
   72|  50.6k|}
interpreter.cpp:_ZN12_GLOBAL__N_114ConditionStack9push_backEb:
  297|  5.62k|    {
  298|  5.62k|        if (m_first_false_pos == NO_FALSE && !f) {
  ------------------
  |  Branch (298:13): [True: 4.77k, False: 851]
  |  Branch (298:46): [True: 166, False: 4.60k]
  ------------------
  299|       |            // The stack consists of all true values, and a false is added.
  300|       |            // The first false value will appear at the current size.
  301|    166|            m_first_false_pos = m_stack_size;
  302|    166|        }
  303|  5.62k|        ++m_stack_size;
  304|  5.62k|    }
interpreter.cpp:_ZNK12_GLOBAL__N_114ConditionStack5emptyEv:
  294|  3.82k|    bool empty() const { return m_stack_size == 0; }
interpreter.cpp:_ZN12_GLOBAL__N_114ConditionStack10toggle_topEv:
  315|    446|    {
  316|    446|        assert(m_stack_size > 0);
  ------------------
  |  Branch (316:9): [True: 446, False: 0]
  ------------------
  317|    446|        if (m_first_false_pos == NO_FALSE) {
  ------------------
  |  Branch (317:13): [True: 86, False: 360]
  ------------------
  318|       |            // The current stack is all true values; the first false will be the top.
  319|     86|            m_first_false_pos = m_stack_size - 1;
  320|    360|        } else if (m_first_false_pos == m_stack_size - 1) {
  ------------------
  |  Branch (320:20): [True: 120, False: 240]
  ------------------
  321|       |            // The top is the first false value; toggling it will make everything true.
  322|    120|            m_first_false_pos = NO_FALSE;
  323|    240|        } else {
  324|       |            // There is a false value, but not on top. No action is needed as toggling
  325|       |            // anything but the first false value is unobservable.
  326|    240|        }
  327|    446|    }
interpreter.cpp:_ZN12_GLOBAL__N_114ConditionStack8pop_backEv:
  306|    170|    {
  307|    170|        assert(m_stack_size > 0);
  ------------------
  |  Branch (307:9): [True: 170, False: 0]
  ------------------
  308|    170|        --m_stack_size;
  309|    170|        if (m_first_false_pos == m_stack_size) {
  ------------------
  |  Branch (309:13): [True: 28, False: 142]
  ------------------
  310|       |            // When popping off the first false value, everything becomes true.
  311|     28|            m_first_false_pos = NO_FALSE;
  312|     28|        }
  313|    170|    }
interpreter.cpp:_ZL12EvalChecksigRKNSt3__16vectorIhNS_9allocatorIhEEEES5_N9prevectorILj36EhjiE14const_iteratorES8_R19ScriptExecutionData19script_verify_flagsRK20BaseSignatureChecker10SigVersionP13ScriptError_tRb:
  403|  5.73k|{
  404|  5.73k|    switch (sigversion) {
  ------------------
  |  Branch (404:13): [True: 5.73k, False: 0]
  ------------------
  405|  5.73k|    case SigVersion::BASE:
  ------------------
  |  Branch (405:5): [True: 5.73k, False: 0]
  ------------------
  406|  5.73k|    case SigVersion::WITNESS_V0:
  ------------------
  |  Branch (406:5): [True: 0, False: 5.73k]
  ------------------
  407|  5.73k|        return EvalChecksigPreTapscript(sig, pubkey, pbegincodehash, pend, flags, checker, sigversion, serror, success);
  408|      0|    case SigVersion::TAPSCRIPT:
  ------------------
  |  Branch (408:5): [True: 0, False: 5.73k]
  ------------------
  409|      0|        return EvalChecksigTapscript(sig, pubkey, execdata, flags, checker, sigversion, serror, success);
  410|      0|    case SigVersion::TAPROOT:
  ------------------
  |  Branch (410:5): [True: 0, False: 5.73k]
  ------------------
  411|       |        // Key path spending in Taproot has no script, so this is unreachable.
  412|      0|        break;
  413|  5.73k|    }
  414|  5.73k|    assert(false);
  ------------------
  |  Branch (414:5): [Folded, False: 0]
  ------------------
  415|      0|}
interpreter.cpp:_ZL24EvalChecksigPreTapscriptRKNSt3__16vectorIhNS_9allocatorIhEEEES5_N9prevectorILj36EhjiE14const_iteratorES8_19script_verify_flagsRK20BaseSignatureChecker10SigVersionP13ScriptError_tRb:
  332|  5.73k|{
  333|  5.73k|    assert(sigversion == SigVersion::BASE || sigversion == SigVersion::WITNESS_V0);
  ------------------
  |  Branch (333:5): [True: 5.73k, False: 0]
  |  Branch (333:5): [True: 0, False: 0]
  |  Branch (333:5): [True: 5.73k, False: 0]
  ------------------
  334|       |
  335|       |    // Subset of script starting at the most recent codeseparator
  336|  5.73k|    CScript scriptCode(pbegincodehash, pend);
  337|       |
  338|       |    // Drop the signature in pre-segwit scripts but not segwit scripts
  339|  5.73k|    if (sigversion == SigVersion::BASE) {
  ------------------
  |  Branch (339:9): [True: 5.73k, False: 0]
  ------------------
  340|  5.73k|        int found = FindAndDelete(scriptCode, CScript() << vchSig);
  341|  5.73k|        if (found > 0 && (flags & SCRIPT_VERIFY_CONST_SCRIPTCODE))
  ------------------
  |  Branch (341:13): [True: 1.80k, False: 3.93k]
  |  Branch (341:13): [True: 0, False: 5.73k]
  |  Branch (341:26): [True: 0, False: 1.80k]
  ------------------
  342|      0|            return set_error(serror, SCRIPT_ERR_SIG_FINDANDDELETE);
  343|  5.73k|    }
  344|       |
  345|  5.73k|    if (!CheckSignatureEncoding(vchSig, flags, serror) || !CheckPubKeyEncoding(vchPubKey, flags, sigversion, serror)) {
  ------------------
  |  Branch (345:9): [True: 171, False: 5.56k]
  |  Branch (345:59): [True: 0, False: 5.56k]
  ------------------
  346|       |        //serror is set
  347|    171|        return false;
  348|    171|    }
  349|  5.56k|    fSuccess = checker.CheckECDSASignature(vchSig, vchPubKey, scriptCode, sigversion);
  350|       |
  351|  5.56k|    if (!fSuccess && (flags & SCRIPT_VERIFY_NULLFAIL) && vchSig.size())
  ------------------
  |  Branch (351:9): [True: 5.56k, False: 0]
  |  Branch (351:9): [True: 0, False: 5.56k]
  |  Branch (351:22): [True: 0, False: 5.56k]
  |  Branch (351:58): [True: 0, False: 0]
  ------------------
  352|      0|        return set_error(serror, SCRIPT_ERR_SIG_NULLFAIL);
  353|       |
  354|  5.56k|    return true;
  355|  5.56k|}
interpreter.cpp:_ZL19CheckPubKeyEncodingRKNSt3__16vectorIhNS_9allocatorIhEEEE19script_verify_flagsRK10SigVersionP13ScriptError_t:
  228|  8.58k|bool static CheckPubKeyEncoding(const valtype &vchPubKey, script_verify_flags flags, const SigVersion &sigversion, ScriptError* serror) {
  229|  8.58k|    if ((flags & SCRIPT_VERIFY_STRICTENC) != 0 && !IsCompressedOrUncompressedPubKey(vchPubKey)) {
  ------------------
  |  Branch (229:9): [True: 0, False: 8.58k]
  |  Branch (229:9): [True: 0, False: 8.58k]
  |  Branch (229:51): [True: 0, False: 0]
  ------------------
  230|      0|        return set_error(serror, SCRIPT_ERR_PUBKEYTYPE);
  231|      0|    }
  232|       |    // Only compressed keys are accepted in segwit
  233|  8.58k|    if ((flags & SCRIPT_VERIFY_WITNESS_PUBKEYTYPE) != 0 && sigversion == SigVersion::WITNESS_V0 && !IsCompressedPubKey(vchPubKey)) {
  ------------------
  |  Branch (233:9): [True: 0, False: 8.58k]
  |  Branch (233:9): [True: 0, False: 8.58k]
  |  Branch (233:60): [True: 0, False: 0]
  |  Branch (233:100): [True: 0, False: 0]
  ------------------
  234|      0|        return set_error(serror, SCRIPT_ERR_WITNESS_PUBKEYTYPE);
  235|      0|    }
  236|  8.58k|    return true;
  237|  8.58k|}
interpreter.cpp:_ZN12_GLOBAL__N_111set_successEP13ScriptError_t:
   31|  3.04k|{
   32|  3.04k|    if (ret)
  ------------------
  |  Branch (32:9): [True: 0, False: 3.04k]
  ------------------
   33|      0|        *ret = SCRIPT_ERR_OK;
   34|  3.04k|    return true;
   35|  3.04k|}
interpreter.cpp:_ZN12_GLOBAL__N_117GetPrevoutsSHA256I12CTransactionEE7uint256RKT_:
 1359|    804|{
 1360|    804|    HashWriter ss{};
 1361|    804|    for (const auto& txin : txTo.vin) {
  ------------------
  |  Branch (1361:27): [True: 804, False: 804]
  ------------------
 1362|    804|        ss << txin.prevout;
 1363|    804|    }
 1364|    804|    return ss.GetSHA256();
 1365|    804|}
interpreter.cpp:_ZN12_GLOBAL__N_118GetSequencesSHA256I12CTransactionEE7uint256RKT_:
 1370|    804|{
 1371|    804|    HashWriter ss{};
 1372|    804|    for (const auto& txin : txTo.vin) {
  ------------------
  |  Branch (1372:27): [True: 804, False: 804]
  ------------------
 1373|    804|        ss << txin.nSequence;
 1374|    804|    }
 1375|    804|    return ss.GetSHA256();
 1376|    804|}
interpreter.cpp:_ZN12_GLOBAL__N_116GetOutputsSHA256I12CTransactionEE7uint256RKT_:
 1381|    804|{
 1382|    804|    HashWriter ss{};
 1383|    804|    for (const auto& txout : txTo.vout) {
  ------------------
  |  Branch (1383:28): [True: 804, False: 804]
  ------------------
 1384|    804|        ss << txout;
 1385|    804|    }
 1386|    804|    return ss.GetSHA256();
 1387|    804|}
_Z13SignatureHashI12CTransactionE7uint256RK7CScriptRKT_jiRKl10SigVersionPK26PrecomputedTransactionDataP12SigHashCache:
 1611|  5.13k|{
 1612|  5.13k|    assert(nIn < txTo.vin.size());
  ------------------
  |  Branch (1612:5): [True: 5.13k, False: 0]
  ------------------
 1613|       |
 1614|  5.13k|    if (sigversion != SigVersion::WITNESS_V0) {
  ------------------
  |  Branch (1614:9): [True: 5.13k, False: 0]
  ------------------
 1615|       |        // Check for invalid use of SIGHASH_SINGLE
 1616|  5.13k|        if ((nHashType & 0x1f) == SIGHASH_SINGLE) {
  ------------------
  |  Branch (1616:13): [True: 173, False: 4.96k]
  ------------------
 1617|    173|            if (nIn >= txTo.vout.size()) {
  ------------------
  |  Branch (1617:17): [True: 0, False: 173]
  ------------------
 1618|       |                //  nOut out of range
 1619|      0|                return uint256::ONE;
 1620|      0|            }
 1621|    173|        }
 1622|  5.13k|    }
 1623|       |
 1624|  5.13k|    HashWriter ss{};
 1625|       |
 1626|       |    // Try to compute using cached SHA256 midstate.
 1627|  5.13k|    if (sighash_cache && sighash_cache->Load(nHashType, scriptCode, ss)) {
  ------------------
  |  Branch (1627:9): [True: 5.13k, False: 0]
  |  Branch (1627:26): [True: 2.65k, False: 2.48k]
  ------------------
 1628|       |        // Add sighash type and hash.
 1629|  2.65k|        ss << nHashType;
 1630|  2.65k|        return ss.GetHash();
 1631|  2.65k|    }
 1632|       |
 1633|  2.48k|    if (sigversion == SigVersion::WITNESS_V0) {
  ------------------
  |  Branch (1633:9): [True: 0, False: 2.48k]
  ------------------
 1634|      0|        uint256 hashPrevouts;
 1635|      0|        uint256 hashSequence;
 1636|      0|        uint256 hashOutputs;
 1637|      0|        const bool cacheready = cache && cache->m_bip143_segwit_ready;
  ------------------
  |  Branch (1637:33): [True: 0, False: 0]
  |  Branch (1637:42): [True: 0, False: 0]
  ------------------
 1638|       |
 1639|      0|        if (!(nHashType & SIGHASH_ANYONECANPAY)) {
  ------------------
  |  Branch (1639:13): [True: 0, False: 0]
  ------------------
 1640|      0|            hashPrevouts = cacheready ? cache->hashPrevouts : SHA256Uint256(GetPrevoutsSHA256(txTo));
  ------------------
  |  Branch (1640:28): [True: 0, False: 0]
  ------------------
 1641|      0|        }
 1642|       |
 1643|      0|        if (!(nHashType & SIGHASH_ANYONECANPAY) && (nHashType & 0x1f) != SIGHASH_SINGLE && (nHashType & 0x1f) != SIGHASH_NONE) {
  ------------------
  |  Branch (1643:13): [True: 0, False: 0]
  |  Branch (1643:52): [True: 0, False: 0]
  |  Branch (1643:92): [True: 0, False: 0]
  ------------------
 1644|      0|            hashSequence = cacheready ? cache->hashSequence : SHA256Uint256(GetSequencesSHA256(txTo));
  ------------------
  |  Branch (1644:28): [True: 0, False: 0]
  ------------------
 1645|      0|        }
 1646|       |
 1647|      0|        if ((nHashType & 0x1f) != SIGHASH_SINGLE && (nHashType & 0x1f) != SIGHASH_NONE) {
  ------------------
  |  Branch (1647:13): [True: 0, False: 0]
  |  Branch (1647:53): [True: 0, False: 0]
  ------------------
 1648|      0|            hashOutputs = cacheready ? cache->hashOutputs : SHA256Uint256(GetOutputsSHA256(txTo));
  ------------------
  |  Branch (1648:27): [True: 0, False: 0]
  ------------------
 1649|      0|        } else if ((nHashType & 0x1f) == SIGHASH_SINGLE && nIn < txTo.vout.size()) {
  ------------------
  |  Branch (1649:20): [True: 0, False: 0]
  |  Branch (1649:60): [True: 0, False: 0]
  ------------------
 1650|      0|            HashWriter inner_ss{};
 1651|      0|            inner_ss << txTo.vout[nIn];
 1652|      0|            hashOutputs = inner_ss.GetHash();
 1653|      0|        }
 1654|       |
 1655|       |        // Version
 1656|      0|        ss << txTo.version;
 1657|       |        // Input prevouts/nSequence (none/all, depending on flags)
 1658|      0|        ss << hashPrevouts;
 1659|      0|        ss << hashSequence;
 1660|       |        // The input being signed (replacing the scriptSig with scriptCode + amount)
 1661|       |        // The prevout may already be contained in hashPrevout, and the nSequence
 1662|       |        // may already be contain in hashSequence.
 1663|      0|        ss << txTo.vin[nIn].prevout;
 1664|      0|        ss << scriptCode;
 1665|      0|        ss << amount;
 1666|      0|        ss << txTo.vin[nIn].nSequence;
 1667|       |        // Outputs (none/one/all, depending on flags)
 1668|      0|        ss << hashOutputs;
 1669|       |        // Locktime
 1670|      0|        ss << txTo.nLockTime;
 1671|  2.48k|    } else {
 1672|       |        // Wrapper to serialize only the necessary parts of the transaction being signed
 1673|  2.48k|        CTransactionSignatureSerializer<T> txTmp(txTo, scriptCode, nIn, nHashType);
 1674|       |
 1675|       |        // Serialize
 1676|  2.48k|        ss << txTmp;
 1677|  2.48k|    }
 1678|       |
 1679|       |    // If a cache object was provided, store the midstate there.
 1680|  2.48k|    if (sighash_cache != nullptr) {
  ------------------
  |  Branch (1680:9): [True: 2.48k, False: 0]
  ------------------
 1681|  2.48k|        sighash_cache->Store(nHashType, scriptCode, ss);
 1682|  2.48k|    }
 1683|       |
 1684|       |    // Add sighash type and hash.
 1685|  2.48k|    ss << nHashType;
 1686|  2.48k|    return ss.GetHash();
 1687|  5.13k|}
interpreter.cpp:_ZN12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionEC2ERKS1_RK7CScriptji:
 1276|  2.48k|        txTo(txToIn), scriptCode(scriptCodeIn), nIn(nInIn),
 1277|  2.48k|        fAnyoneCanPay(!!(nHashTypeIn & SIGHASH_ANYONECANPAY)),
 1278|  2.48k|        fHashSingle((nHashTypeIn & 0x1f) == SIGHASH_SINGLE),
 1279|  2.48k|        fHashNone((nHashTypeIn & 0x1f) == SIGHASH_NONE) {}
interpreter.cpp:_ZNK12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionE9SerializeI10HashWriterEEvRT_:
 1338|  2.48k|    void Serialize(S &s) const {
 1339|       |        // Serialize version
 1340|  2.48k|        ::Serialize(s, txTo.version);
 1341|       |        // Serialize vin
 1342|  2.48k|        unsigned int nInputs = fAnyoneCanPay ? 1 : txTo.vin.size();
  ------------------
  |  Branch (1342:32): [True: 287, False: 2.20k]
  ------------------
 1343|  2.48k|        ::WriteCompactSize(s, nInputs);
 1344|  4.97k|        for (unsigned int nInput = 0; nInput < nInputs; nInput++)
  ------------------
  |  Branch (1344:39): [True: 2.48k, False: 2.48k]
  ------------------
 1345|  2.48k|             SerializeInput(s, nInput);
 1346|       |        // Serialize vout
 1347|  2.48k|        unsigned int nOutputs = fHashNone ? 0 : (fHashSingle ? nIn+1 : txTo.vout.size());
  ------------------
  |  Branch (1347:33): [True: 120, False: 2.36k]
  |  Branch (1347:50): [True: 112, False: 2.25k]
  ------------------
 1348|  2.48k|        ::WriteCompactSize(s, nOutputs);
 1349|  4.85k|        for (unsigned int nOutput = 0; nOutput < nOutputs; nOutput++)
  ------------------
  |  Branch (1349:40): [True: 2.36k, False: 2.48k]
  ------------------
 1350|  2.36k|             SerializeOutput(s, nOutput);
 1351|       |        // Serialize nLockTime
 1352|  2.48k|        ::Serialize(s, txTo.nLockTime);
 1353|  2.48k|    }
interpreter.cpp:_ZNK12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionE14SerializeInputI10HashWriterEEvRT_j:
 1306|  2.48k|    void SerializeInput(S &s, unsigned int nInput) const {
 1307|       |        // In case of SIGHASH_ANYONECANPAY, only the input being signed is serialized
 1308|  2.48k|        if (fAnyoneCanPay)
  ------------------
  |  Branch (1308:13): [True: 287, False: 2.20k]
  ------------------
 1309|    287|            nInput = nIn;
 1310|       |        // Serialize the prevout
 1311|  2.48k|        ::Serialize(s, txTo.vin[nInput].prevout);
 1312|       |        // Serialize the script
 1313|  2.48k|        if (nInput != nIn)
  ------------------
  |  Branch (1313:13): [True: 0, False: 2.48k]
  ------------------
 1314|       |            // Blank out other inputs' signatures
 1315|      0|            ::Serialize(s, CScript());
 1316|  2.48k|        else
 1317|  2.48k|            SerializeScriptCode(s);
 1318|       |        // Serialize the nSequence
 1319|  2.48k|        if (nInput != nIn && (fHashSingle || fHashNone))
  ------------------
  |  Branch (1319:13): [True: 0, False: 2.48k]
  |  Branch (1319:31): [True: 0, False: 0]
  |  Branch (1319:46): [True: 0, False: 0]
  ------------------
 1320|       |            // let the others update at will
 1321|      0|            ::Serialize(s, int32_t{0});
 1322|  2.48k|        else
 1323|  2.48k|            ::Serialize(s, txTo.vin[nInput].nSequence);
 1324|  2.48k|    }
interpreter.cpp:_ZNK12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionE19SerializeScriptCodeI10HashWriterEEvRT_:
 1283|  2.48k|    void SerializeScriptCode(S &s) const {
 1284|  2.48k|        CScript::const_iterator it = scriptCode.begin();
 1285|  2.48k|        CScript::const_iterator itBegin = it;
 1286|  2.48k|        opcodetype opcode;
 1287|  2.48k|        unsigned int nCodeSeparators = 0;
 1288|  68.5k|        while (scriptCode.GetOp(it, opcode)) {
  ------------------
  |  Branch (1288:16): [True: 66.0k, False: 2.48k]
  ------------------
 1289|  66.0k|            if (opcode == OP_CODESEPARATOR)
  ------------------
  |  Branch (1289:17): [True: 11.4k, False: 54.6k]
  ------------------
 1290|  11.4k|                nCodeSeparators++;
 1291|  66.0k|        }
 1292|  2.48k|        ::WriteCompactSize(s, scriptCode.size() - nCodeSeparators);
 1293|  2.48k|        it = itBegin;
 1294|  68.5k|        while (scriptCode.GetOp(it, opcode)) {
  ------------------
  |  Branch (1294:16): [True: 66.0k, False: 2.48k]
  ------------------
 1295|  66.0k|            if (opcode == OP_CODESEPARATOR) {
  ------------------
  |  Branch (1295:17): [True: 11.4k, False: 54.6k]
  ------------------
 1296|  11.4k|                s.write(std::as_bytes(std::span{&itBegin[0], size_t(it - itBegin - 1)}));
 1297|  11.4k|                itBegin = it;
 1298|  11.4k|            }
 1299|  66.0k|        }
 1300|  2.48k|        if (itBegin != scriptCode.end())
  ------------------
  |  Branch (1300:13): [True: 2.09k, False: 396]
  ------------------
 1301|  2.09k|            s.write(std::as_bytes(std::span{&itBegin[0], size_t(it - itBegin)}));
 1302|  2.48k|    }
interpreter.cpp:_ZNK12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionE15SerializeOutputI10HashWriterEEvRT_j:
 1328|  2.36k|    void SerializeOutput(S &s, unsigned int nOutput) const {
 1329|  2.36k|        if (fHashSingle && nOutput != nIn)
  ------------------
  |  Branch (1329:13): [True: 112, False: 2.25k]
  |  Branch (1329:28): [True: 0, False: 112]
  ------------------
 1330|       |            // Do not lock-in the txout payee at other indices as txin
 1331|      0|            ::Serialize(s, CTxOut());
 1332|  2.36k|        else
 1333|  2.36k|            ::Serialize(s, txTo.vout[nOutput]);
 1334|  2.36k|    }

_ZN26PrecomputedTransactionDataC2Ev:
  185|  4.08k|    PrecomputedTransactionData() = default;
_ZN34GenericTransactionSignatureCheckerI12CTransactionEC2EPKS0_jRKlRK26PrecomputedTransactionData19MissingDataBehavior:
  330|  4.08k|    GenericTransactionSignatureChecker(const T* txToIn, unsigned int nInIn, const CAmount& amountIn, const PrecomputedTransactionData& txdataIn, MissingDataBehavior mdb) : txTo(txToIn), m_mdb(mdb), nIn(nInIn), amount(amountIn), txdata(&txdataIn) {}
_ZN20BaseSignatureCheckerD2Ev:
  298|  4.08k|    virtual ~BaseSignatureChecker() = default;

_Z11GetScriptOpRN9prevectorILj36EhjiE14const_iteratorES1_R10opcodetypePNSt3__16vectorIhNS5_9allocatorIhEEEE:
  314|  1.44M|{
  315|  1.44M|    opcodeRet = OP_INVALIDOPCODE;
  316|  1.44M|    if (pvchRet)
  ------------------
  |  Branch (316:9): [True: 888k, False: 551k]
  ------------------
  317|   888k|        pvchRet->clear();
  318|  1.44M|    if (pc >= end)
  ------------------
  |  Branch (318:9): [True: 15.3k, False: 1.42M]
  ------------------
  319|  15.3k|        return false;
  320|       |
  321|       |    // Read instruction
  322|  1.42M|    if (end - pc < 1)
  ------------------
  |  Branch (322:9): [True: 0, False: 1.42M]
  ------------------
  323|      0|        return false;
  324|  1.42M|    unsigned int opcode = *pc++;
  325|       |
  326|       |    // Immediate operand
  327|  1.42M|    if (opcode <= OP_PUSHDATA4)
  ------------------
  |  Branch (327:9): [True: 369k, False: 1.05M]
  ------------------
  328|   369k|    {
  329|   369k|        unsigned int nSize = 0;
  330|   369k|        if (opcode < OP_PUSHDATA1)
  ------------------
  |  Branch (330:13): [True: 360k, False: 9.49k]
  ------------------
  331|   360k|        {
  332|   360k|            nSize = opcode;
  333|   360k|        }
  334|  9.49k|        else if (opcode == OP_PUSHDATA1)
  ------------------
  |  Branch (334:18): [True: 5.22k, False: 4.27k]
  ------------------
  335|  5.22k|        {
  336|  5.22k|            if (end - pc < 1)
  ------------------
  |  Branch (336:17): [True: 232, False: 4.99k]
  ------------------
  337|    232|                return false;
  338|  4.99k|            nSize = *pc++;
  339|  4.99k|        }
  340|  4.27k|        else if (opcode == OP_PUSHDATA2)
  ------------------
  |  Branch (340:18): [True: 3.10k, False: 1.16k]
  ------------------
  341|  3.10k|        {
  342|  3.10k|            if (end - pc < 2)
  ------------------
  |  Branch (342:17): [True: 277, False: 2.83k]
  ------------------
  343|    277|                return false;
  344|  2.83k|            nSize = ReadLE16(&pc[0]);
  345|  2.83k|            pc += 2;
  346|  2.83k|        }
  347|  1.16k|        else if (opcode == OP_PUSHDATA4)
  ------------------
  |  Branch (347:18): [True: 1.16k, False: 0]
  ------------------
  348|  1.16k|        {
  349|  1.16k|            if (end - pc < 4)
  ------------------
  |  Branch (349:17): [True: 375, False: 790]
  ------------------
  350|    375|                return false;
  351|    790|            nSize = ReadLE32(&pc[0]);
  352|    790|            pc += 4;
  353|    790|        }
  354|   368k|        if (end - pc < 0 || (unsigned int)(end - pc) < nSize)
  ------------------
  |  Branch (354:13): [True: 0, False: 368k]
  |  Branch (354:29): [True: 6.52k, False: 362k]
  ------------------
  355|  6.52k|            return false;
  356|   362k|        if (pvchRet)
  ------------------
  |  Branch (356:13): [True: 343k, False: 18.4k]
  ------------------
  357|   343k|            pvchRet->assign(pc, pc + nSize);
  358|   362k|        pc += nSize;
  359|   362k|    }
  360|       |
  361|  1.41M|    opcodeRet = static_cast<opcodetype>(opcode);
  362|  1.41M|    return true;
  363|  1.42M|}

_ZN7CScriptlsERK10CScriptNum:
  479|  26.7k|    {
  480|  26.7k|        *this << b.getvch();
  481|  26.7k|        return *this;
  482|  26.7k|    }
_ZN7CScript16SerializationOpsI12ParamsStreamIR10SpanReader20TransactionSerParamsES_17ActionUnserializeEEvRT0_RT_T1_:
  456|   816k|    SERIALIZE_METHODS(CScript, obj) { READWRITE(AsBase<CScriptBase>(obj)); }
  ------------------
  |  |  148|   816k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN7CScriptC2E10opcodetype:
  459|  22.4k|    explicit CScript(opcodetype b)     { operator<<(b); }
_ZN7CScript16SerializationOpsI10SpanReaderS_17ActionUnserializeEEvRT0_RT_T1_:
  456|  8.19k|    SERIALIZE_METHODS(CScript, obj) { READWRITE(AsBase<CScriptBase>(obj)); }
  ------------------
  |  |  148|  8.19k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN7CScriptlsEl:
  468|   247k|    CScript& operator<<(int64_t b) LIFETIMEBOUND { return push_int64(b); }
_ZN7CScript10push_int64El:
  435|   247k|    {
  436|   247k|        if (n == -1 || (n >= 1 && n <= 16))
  ------------------
  |  Branch (436:13): [True: 2.34k, False: 245k]
  |  Branch (436:25): [True: 202k, False: 42.2k]
  |  Branch (436:35): [True: 176k, False: 26.3k]
  ------------------
  437|   178k|        {
  438|   178k|            push_back(n + (OP_1 - 1));
  439|   178k|        }
  440|  68.5k|        else if (n == 0)
  ------------------
  |  Branch (440:18): [True: 30.8k, False: 37.7k]
  ------------------
  441|  30.8k|        {
  442|  30.8k|            push_back(OP_0);
  443|  30.8k|        }
  444|  37.7k|        else
  445|  37.7k|        {
  446|  37.7k|            *this << CScriptNum::serialize(n);
  447|  37.7k|        }
  448|   247k|        return *this;
  449|   247k|    }
_ZN14CScriptWitnessC2Ev:
  584|   151k|    CScriptWitness() = default;
_ZN7CScript16SerializationOpsI12ParamsStreamIR10HashWriter20TransactionSerParamsEKS_15ActionSerializeEEvRT0_RT_T1_:
  456|   461k|    SERIALIZE_METHODS(CScript, obj) { READWRITE(AsBase<CScriptBase>(obj)); }
  ------------------
  |  |  148|   461k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZNK7CScript5GetOpERN9prevectorILj36EhjiE14const_iteratorER10opcodetypeRNSt3__16vectorIhNS6_9allocatorIhEEEE:
  498|   888k|    {
  499|   888k|        return GetScriptOp(pc, end(), opcodeRet, &vchRet);
  500|   888k|    }
_ZNK7CScript5GetOpERN9prevectorILj36EhjiE14const_iteratorER10opcodetype:
  503|   551k|    {
  504|   551k|        return GetScriptOp(pc, end(), opcodeRet, nullptr);
  505|   551k|    }
_ZN7CScriptC2Ev:
  452|   903k|    CScript() = default;
_ZN10CScriptNumC2ERKl:
  240|  45.2k|    {
  241|  45.2k|        m_value = n;
  242|  45.2k|    }
_ZNK10CScriptNum6getvchEv:
  338|  48.9k|    {
  339|  48.9k|        return serialize(m_value);
  340|  48.9k|    }
_ZN10CScriptNum9serializeERKl:
  343|  86.7k|    {
  344|  86.7k|        if(value == 0)
  ------------------
  |  Branch (344:12): [True: 4.75k, False: 81.9k]
  ------------------
  345|  4.75k|            return std::vector<unsigned char>();
  346|       |
  347|  81.9k|        std::vector<unsigned char> result;
  348|  81.9k|        const bool neg = value < 0;
  349|  81.9k|        uint64_t absvalue = neg ? ~static_cast<uint64_t>(value) + 1 : static_cast<uint64_t>(value);
  ------------------
  |  Branch (349:29): [True: 19.0k, False: 62.9k]
  ------------------
  350|       |
  351|   503k|        while(absvalue)
  ------------------
  |  Branch (351:15): [True: 421k, False: 81.9k]
  ------------------
  352|   421k|        {
  353|   421k|            result.push_back(absvalue & 0xff);
  354|   421k|            absvalue >>= 8;
  355|   421k|        }
  356|       |
  357|       |//    - If the most significant byte is >= 0x80 and the value is positive, push a
  358|       |//    new zero-byte to make the significant byte < 0x80 again.
  359|       |
  360|       |//    - If the most significant byte is >= 0x80 and the value is negative, push a
  361|       |//    new 0x80 byte that will be popped off when converting to an integral.
  362|       |
  363|       |//    - If the most significant byte is < 0x80 and the value is negative, add
  364|       |//    0x80 to it, since it will be subtracted and interpreted as a negative when
  365|       |//    converting to an integral.
  366|       |
  367|  81.9k|        if (result.back() & 0x80)
  ------------------
  |  Branch (367:13): [True: 11.8k, False: 70.1k]
  ------------------
  368|  11.8k|            result.push_back(neg ? 0x80 : 0);
  ------------------
  |  Branch (368:30): [True: 11.4k, False: 382]
  ------------------
  369|  70.1k|        else if (neg)
  ------------------
  |  Branch (369:18): [True: 7.59k, False: 62.5k]
  ------------------
  370|  7.59k|            result.back() |= 0x80;
  371|       |
  372|  81.9k|        return result;
  373|  86.7k|    }
_ZN10CScriptNumC2ERKNSt3__16vectorIhNS0_9allocatorIhEEEEbm:
  248|  23.3k|    {
  249|  23.3k|        if (vch.size() > nMaxNumSize) {
  ------------------
  |  Branch (249:13): [True: 139, False: 23.1k]
  ------------------
  250|    139|            throw scriptnum_error("script number overflow");
  251|    139|        }
  252|  23.1k|        if (fRequireMinimal && vch.size() > 0) {
  ------------------
  |  Branch (252:13): [True: 0, False: 23.1k]
  |  Branch (252:32): [True: 0, False: 0]
  ------------------
  253|       |            // Check that the number is encoded with the minimum possible
  254|       |            // number of bytes.
  255|       |            //
  256|       |            // If the most-significant-byte - excluding the sign bit - is zero
  257|       |            // then we're not minimal. Note how this test also rejects the
  258|       |            // negative-zero encoding, 0x80.
  259|      0|            if ((vch.back() & 0x7f) == 0) {
  ------------------
  |  Branch (259:17): [True: 0, False: 0]
  ------------------
  260|       |                // One exception: if there's more than one byte and the most
  261|       |                // significant bit of the second-most-significant-byte is set
  262|       |                // it would conflict with the sign bit. An example of this case
  263|       |                // is +-255, which encode to 0xff00 and 0xff80 respectively.
  264|       |                // (big-endian).
  265|      0|                if (vch.size() <= 1 || (vch[vch.size() - 2] & 0x80) == 0) {
  ------------------
  |  Branch (265:21): [True: 0, False: 0]
  |  Branch (265:40): [True: 0, False: 0]
  ------------------
  266|      0|                    throw scriptnum_error("non-minimally encoded script number");
  267|      0|                }
  268|      0|            }
  269|      0|        }
  270|  23.1k|        m_value = set_vch(vch);
  271|  23.1k|    }
_ZN15scriptnum_errorC2ERKNSt3__112basic_stringIcNS0_11char_traitsIcEENS0_9allocatorIcEEEE:
  224|    139|    explicit scriptnum_error(const std::string& str) : std::runtime_error(str) {}
_ZN10CScriptNum7set_vchERKNSt3__16vectorIhNS0_9allocatorIhEEEE:
  377|  23.1k|    {
  378|  23.1k|      if (vch.empty())
  ------------------
  |  Branch (378:11): [True: 7.83k, False: 15.3k]
  ------------------
  379|  7.83k|          return 0;
  380|       |
  381|  15.3k|      int64_t result = 0;
  382|  38.7k|      for (size_t i = 0; i != vch.size(); ++i)
  ------------------
  |  Branch (382:26): [True: 23.4k, False: 15.3k]
  ------------------
  383|  23.4k|          result |= static_cast<int64_t>(vch[i]) << 8*i;
  384|       |
  385|       |      // If the input vector's most significant byte is 0x80, remove it from
  386|       |      // the result's msb and return a negative.
  387|  15.3k|      if (vch.back() & 0x80)
  ------------------
  |  Branch (387:11): [True: 2.33k, False: 13.0k]
  ------------------
  388|  2.33k|          return -((int64_t)(result & ~(0x80ULL << (8 * (vch.size() - 1)))));
  389|       |
  390|  13.0k|      return result;
  391|  15.3k|    }
_ZNK10CScriptNumssERKl:
  274|  4.13k|    inline auto operator<=>(const int64_t& rhs) const    { return m_value <=> rhs; }
_ZNK10CScriptNumeqERKl:
  273|  5.18k|    inline bool operator==(const int64_t& rhs) const    { return m_value == rhs; }
_ZNK10CScriptNum6getintEv:
  327|  6.24k|    {
  328|  6.24k|        if (m_value > std::numeric_limits<int>::max())
  ------------------
  |  Branch (328:13): [True: 0, False: 6.24k]
  ------------------
  329|      0|            return std::numeric_limits<int>::max();
  330|  6.24k|        else if (m_value < std::numeric_limits<int>::min())
  ------------------
  |  Branch (330:18): [True: 0, False: 6.24k]
  ------------------
  331|      0|            return std::numeric_limits<int>::min();
  332|  6.24k|        return m_value;
  333|  6.24k|    }
_ZN10CScriptNumpLERKS_:
  284|    653|    inline CScriptNum& operator+=( const CScriptNum& rhs)       { return operator+=(rhs.m_value);  }
_ZN10CScriptNumpLERKl:
  305|    653|    {
  306|    653|        assert(rhs == 0 || (rhs > 0 && m_value <= std::numeric_limits<int64_t>::max() - rhs) ||
  ------------------
  |  Branch (306:9): [True: 653, False: 0]
  |  Branch (306:9): [True: 653, False: 0]
  |  Branch (306:9): [True: 0, False: 653]
  |  Branch (306:9): [True: 0, False: 0]
  |  Branch (306:9): [True: 0, False: 0]
  |  Branch (306:9): [True: 653, False: 0]
  ------------------
  307|    653|                           (rhs < 0 && m_value >= std::numeric_limits<int64_t>::min() - rhs));
  308|    653|        m_value += rhs;
  309|    653|        return *this;
  310|    653|    }
_ZN10CScriptNummIERKS_:
  285|    657|    inline CScriptNum& operator-=( const CScriptNum& rhs)       { return operator-=(rhs.m_value);  }
_ZN10CScriptNummIERKl:
  313|    657|    {
  314|    657|        assert(rhs == 0 || (rhs > 0 && m_value >= std::numeric_limits<int64_t>::min() + rhs) ||
  ------------------
  |  Branch (314:9): [True: 657, False: 0]
  |  Branch (314:9): [True: 657, False: 0]
  |  Branch (314:9): [True: 0, False: 657]
  |  Branch (314:9): [True: 0, False: 0]
  |  Branch (314:9): [True: 0, False: 0]
  |  Branch (314:9): [True: 657, False: 0]
  ------------------
  315|    657|                           (rhs < 0 && m_value <= std::numeric_limits<int64_t>::max() + rhs));
  316|    657|        m_value -= rhs;
  317|    657|        return *this;
  318|    657|    }
_ZNK10CScriptNumngEv:
  293|    712|    {
  294|    712|        assert(m_value != std::numeric_limits<int64_t>::min());
  ------------------
  |  Branch (294:9): [True: 712, False: 0]
  ------------------
  295|    712|        return CScriptNum(-m_value);
  296|    712|    }
_ZNK10CScriptNumssERKS_:
  277|  4.13k|    inline auto operator<=>(const CScriptNum& rhs) const { return operator<=>(rhs.m_value); }
_ZNK10CScriptNumeqERKS_:
  276|  5.18k|    inline bool operator==(const CScriptNum& rhs) const { return operator==(rhs.m_value); }
_ZN10CScriptNumaSERKl:
  299|  5.99k|    {
  300|  5.99k|        m_value = rhs;
  301|  5.99k|        return *this;
  302|  5.99k|    }
_ZNK10CScriptNumplERKS_:
  281|    253|    inline CScriptNum operator+(   const CScriptNum& rhs) const { return operator+(rhs.m_value);   }
_ZNK10CScriptNummiERKS_:
  282|    278|    inline CScriptNum operator-(   const CScriptNum& rhs) const { return operator-(rhs.m_value);   }
_ZNK10CScriptNummiERKl:
  280|    278|    inline CScriptNum operator-(   const int64_t& rhs)    const { return CScriptNum(m_value - rhs);}
_ZNK10CScriptNumplERKl:
  279|    253|    inline CScriptNum operator+(   const int64_t& rhs)    const { return CScriptNum(m_value + rhs);}
_ZN7CScriptlsENSt3__14spanIKhLm18446744073709551615EEE:
  493|  10.4M|    {
  494|  10.4M|        return *this << std::as_bytes(b);
  495|  10.4M|    }
_ZN7CScriptlsENSt3__14spanIKSt4byteLm18446744073709551615EEE:
  485|  10.4M|    {
  486|  10.4M|        AppendDataSize(b.size());
  487|  10.4M|        AppendData({reinterpret_cast<const value_type*>(b.data()), b.size()});
  488|  10.4M|        return *this;
  489|  10.4M|    }
_ZN7CScript14AppendDataSizeEj:
  409|  10.4M|    {
  410|  10.4M|        if (size < OP_PUSHDATA1) {
  ------------------
  |  Branch (410:13): [True: 1.38M, False: 9.09M]
  ------------------
  411|  1.38M|            insert(end(), static_cast<value_type>(size));
  412|  9.09M|        } else if (size <= 0xff) {
  ------------------
  |  Branch (412:20): [True: 9.08M, False: 2.35k]
  ------------------
  413|  9.08M|            insert(end(), OP_PUSHDATA1);
  414|  9.08M|            insert(end(), static_cast<value_type>(size));
  415|  9.08M|        } else if (size <= 0xffff) {
  ------------------
  |  Branch (415:20): [True: 2.35k, False: 0]
  ------------------
  416|  2.35k|            insert(end(), OP_PUSHDATA2);
  417|  2.35k|            value_type data[2];
  418|  2.35k|            WriteLE16(data, size);
  419|  2.35k|            insert(end(), std::cbegin(data), std::cend(data));
  420|  2.35k|        } else {
  421|      0|            insert(end(), OP_PUSHDATA4);
  422|      0|            value_type data[4];
  423|      0|            WriteLE32(data, size);
  424|      0|            insert(end(), std::cbegin(data), std::cend(data));
  425|      0|        }
  426|  10.4M|    }
_ZN7CScript10AppendDataENSt3__14spanIKhLm18446744073709551615EEE:
  429|  10.4M|    {
  430|  10.4M|        insert(end(), data.begin(), data.end());
  431|  10.4M|    }
_ZNK14CScriptWitness6IsNullEv:
  586|  38.0k|    bool IsNull() const { return stack.empty(); }
_ZN7CScript16SerializationOpsI10HashWriterKS_15ActionSerializeEEvRT0_RT_T1_:
  456|  3.17k|    SERIALIZE_METHODS(CScript, obj) { READWRITE(AsBase<CScriptBase>(obj)); }
  ------------------
  |  |  148|  3.17k|#define READWRITE(...) (ser_action.SerReadWriteMany(s, __VA_ARGS__))
  ------------------
_ZN7CScriptlsE10opcodetype:
  471|   792k|    {
  472|   792k|        if (opcode < 0 || opcode > 0xff)
  ------------------
  |  Branch (472:13): [True: 0, False: 792k]
  |  Branch (472:27): [True: 0, False: 792k]
  ------------------
  473|      0|            throw std::runtime_error("CScript::operator<<(): invalid opcode");
  474|   792k|        insert(end(), (unsigned char)opcode);
  475|   792k|        return *this;
  476|   792k|    }
_ZN7CScriptC2ITkNSt3__114input_iteratorEN9prevectorILj36EhjiE14const_iteratorEEET_S5_:
  454|  7.84k|    CScript(InputIterator first, InputIterator last) : CScriptBase{first, last} { }
_ZN7CScript5clearEv:
  570|   686k|    {
  571|       |        // The default prevector::clear() does not release memory
  572|   686k|        CScriptBase::clear();
  573|   686k|        shrink_to_fit();
  574|   686k|    }
_ZN7CScriptC2ITkNSt3__114input_iteratorENS1_11__wrap_iterIPKhEEEET_S6_:
  454|  5.54k|    CScript(InputIterator first, InputIterator last) : CScriptBase{first, last} { }

_ZN20BaseSignatureCreatorD2Ev:
   41|      4|    virtual ~BaseSignatureCreator() = default;

_ZN15SigningProviderD2Ev:
  170|      2|    virtual ~SigningProvider() = default;

_ZN19script_verify_flagsC2E23script_verify_flag_name:
   25|  84.6k|    constexpr explicit(false) script_verify_flags(script_verify_flag_name f) : m_value{value_type{1} << static_cast<uint8_t>(f)} { }
_ZN19script_verify_flags8from_intEm:
   35|  84.6k|    static constexpr script_verify_flags from_int(value_type f) { script_verify_flags r; r.m_value = f; return r; }
_Zor19script_verify_flagsS_:
   40|  12.0k|    friend constexpr script_verify_flags operator|(script_verify_flags a, script_verify_flags b) { return from_int(a.m_value | b.m_value); }
_Zan19script_verify_flagsS_:
   41|  72.5k|    friend constexpr script_verify_flags operator&(script_verify_flags a, script_verify_flags b) { return from_int(a.m_value & b.m_value); }
_ZNK19script_verify_flagscvbEv:
   48|  28.2k|    constexpr explicit operator bool() const { return m_value != 0; }
_ZNK19script_verify_flagseqES_:
   49|  44.3k|    constexpr bool operator==(script_verify_flags other) const { return m_value == other.m_value; }
_Zor23script_verify_flag_nameS_:
   67|  6.02k|{
   68|  6.02k|    return script_verify_flags{f1} | f2;
   69|  6.02k|}

secp256k1.c:secp256k1_ecdsa_sig_verify:
  195|  3.95k|static int secp256k1_ecdsa_sig_verify(const secp256k1_scalar *sigr, const secp256k1_scalar *sigs, const secp256k1_ge *pubkey, const secp256k1_scalar *message) {
  196|  3.95k|    unsigned char c[32];
  197|  3.95k|    secp256k1_scalar sn, u1, u2;
  198|  3.95k|#if !defined(EXHAUSTIVE_TEST_ORDER)
  199|  3.95k|    int range;
  200|  3.95k|    secp256k1_fe xr;
  201|  3.95k|#endif
  202|  3.95k|    secp256k1_gej pubkeyj;
  203|  3.95k|    secp256k1_gej pr;
  204|       |
  205|  3.95k|    if (secp256k1_scalar_is_zero(sigr) || secp256k1_scalar_is_zero(sigs)) {
  ------------------
  |  Branch (205:9): [True: 221, False: 3.73k]
  |  Branch (205:43): [True: 0, False: 3.73k]
  ------------------
  206|    221|        return 0;
  207|    221|    }
  208|       |
  209|  3.73k|    secp256k1_scalar_inverse_var(&sn, sigs);
  210|  3.73k|    secp256k1_scalar_mul(&u1, &sn, message);
  211|  3.73k|    secp256k1_scalar_mul(&u2, &sn, sigr);
  212|  3.73k|    secp256k1_gej_set_ge(&pubkeyj, pubkey);
  213|  3.73k|    secp256k1_ecmult(&pr, &pubkeyj, &u2, &u1);
  214|  3.73k|    if (secp256k1_gej_is_infinity(&pr)) {
  ------------------
  |  Branch (214:9): [True: 0, False: 3.73k]
  ------------------
  215|      0|        return 0;
  216|      0|    }
  217|       |
  218|       |#if defined(EXHAUSTIVE_TEST_ORDER)
  219|       |{
  220|       |    secp256k1_scalar computed_r;
  221|       |    secp256k1_ge pr_ge;
  222|       |    secp256k1_ge_set_gej(&pr_ge, &pr);
  223|       |    secp256k1_fe_normalize(&pr_ge.x);
  224|       |
  225|       |    secp256k1_fe_get_b32(c, &pr_ge.x);
  226|       |    secp256k1_scalar_set_b32(&computed_r, c, NULL);
  227|       |    return secp256k1_scalar_eq(sigr, &computed_r);
  228|       |}
  229|       |#else
  230|       |
  231|       |    /* Interpret sigr as a field element xr  */
  232|  3.73k|    secp256k1_scalar_get_b32(c, sigr);
  233|  3.73k|    range = secp256k1_fe_set_b32_limit(&xr, c);
  ------------------
  |  |   88|  3.73k|#  define secp256k1_fe_set_b32_limit secp256k1_fe_impl_set_b32_limit
  ------------------
  234|       |#ifdef VERIFY
  235|       |    /* We know that c is in range; it comes from a scalar. */
  236|       |    VERIFY_CHECK(range);
  237|       |#else
  238|  3.73k|    (void)range;
  239|  3.73k|#endif
  240|       |
  241|       |    /** We now have the recomputed R point in pr, and its claimed x coordinate (modulo n)
  242|       |     *  in xr. Naively, we would extract the x coordinate from pr (requiring a inversion modulo p),
  243|       |     *  compute the remainder modulo n, and compare it to xr. However:
  244|       |     *
  245|       |     *        xr == X(pr) mod n
  246|       |     *    <=> exists h. (xr + h * n < p && xr + h * n == X(pr))
  247|       |     *    [Since 2 * n > p, h can only be 0 or 1]
  248|       |     *    <=> (xr == X(pr)) || (xr + n < p && xr + n == X(pr))
  249|       |     *    [In Jacobian coordinates, X(pr) is pr.x / pr.z^2 mod p]
  250|       |     *    <=> (xr == pr.x / pr.z^2 mod p) || (xr + n < p && xr + n == pr.x / pr.z^2 mod p)
  251|       |     *    [Multiplying both sides of the equations by pr.z^2 mod p]
  252|       |     *    <=> (xr * pr.z^2 mod p == pr.x) || (xr + n < p && (xr + n) * pr.z^2 mod p == pr.x)
  253|       |     *
  254|       |     *  Thus, we can avoid the inversion, but we have to check both cases separately.
  255|       |     *  secp256k1_gej_eq_x implements the (xr * pr.z^2 mod p == pr.x) test.
  256|       |     */
  257|  3.73k|    if (secp256k1_gej_eq_x_var(&xr, &pr)) {
  ------------------
  |  Branch (257:9): [True: 0, False: 3.73k]
  ------------------
  258|       |        /* xr * pr.z^2 mod p == pr.x, so the signature is valid. */
  259|      0|        return 1;
  260|      0|    }
  261|  3.73k|    if (secp256k1_fe_cmp_var(&xr, &secp256k1_ecdsa_const_p_minus_order) >= 0) {
  ------------------
  |  |   86|  3.73k|#  define secp256k1_fe_cmp_var secp256k1_fe_impl_cmp_var
  ------------------
  |  Branch (261:9): [True: 3.73k, False: 0]
  ------------------
  262|       |        /* xr + n >= p, so we can skip testing the second case. */
  263|  3.73k|        return 0;
  264|  3.73k|    }
  265|      0|    secp256k1_fe_add(&xr, &secp256k1_ecdsa_const_order_as_fe);
  ------------------
  |  |   92|      0|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  266|      0|    if (secp256k1_gej_eq_x_var(&xr, &pr)) {
  ------------------
  |  Branch (266:9): [True: 0, False: 0]
  ------------------
  267|       |        /* (xr + n) * pr.z^2 mod p == pr.x, so the signature is valid. */
  268|      0|        return 1;
  269|      0|    }
  270|      0|    return 0;
  271|      0|#endif
  272|      0|}

secp256k1.c:secp256k1_eckey_pubkey_parse:
   18|  5.13k|static int secp256k1_eckey_pubkey_parse(secp256k1_ge *elem, const unsigned char *pub, size_t size) {
   19|  5.13k|    if (size == 33 && (pub[0] == SECP256K1_TAG_PUBKEY_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_ODD)) {
  ------------------
  |  |  220|  8.50k|#define SECP256K1_TAG_PUBKEY_EVEN 0x02
  ------------------
                  if (size == 33 && (pub[0] == SECP256K1_TAG_PUBKEY_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_ODD)) {
  ------------------
  |  |  221|  1.78k|#define SECP256K1_TAG_PUBKEY_ODD 0x03
  ------------------
  |  Branch (19:9): [True: 4.25k, False: 885]
  |  Branch (19:24): [True: 2.46k, False: 1.78k]
  |  Branch (19:63): [True: 1.78k, False: 0]
  ------------------
   20|  4.25k|        secp256k1_fe x;
   21|  4.25k|        return secp256k1_fe_set_b32_limit(&x, pub+1) && secp256k1_ge_set_xo_var(elem, &x, pub[0] == SECP256K1_TAG_PUBKEY_ODD);
  ------------------
  |  |   88|  4.25k|#  define secp256k1_fe_set_b32_limit secp256k1_fe_impl_set_b32_limit
  ------------------
                      return secp256k1_fe_set_b32_limit(&x, pub+1) && secp256k1_ge_set_xo_var(elem, &x, pub[0] == SECP256K1_TAG_PUBKEY_ODD);
  ------------------
  |  |  221|  4.21k|#define SECP256K1_TAG_PUBKEY_ODD 0x03
  ------------------
  |  Branch (21:16): [True: 4.21k, False: 37]
  |  Branch (21:57): [True: 3.95k, False: 266]
  ------------------
   22|  4.25k|    } else if (size == 65 && (pub[0] == SECP256K1_TAG_PUBKEY_UNCOMPRESSED || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) {
  ------------------
  |  |  222|  1.77k|#define SECP256K1_TAG_PUBKEY_UNCOMPRESSED 0x04
  ------------------
                  } else if (size == 65 && (pub[0] == SECP256K1_TAG_PUBKEY_UNCOMPRESSED || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) {
  ------------------
  |  |  223|  1.73k|#define SECP256K1_TAG_PUBKEY_HYBRID_EVEN 0x06
  ------------------
                  } else if (size == 65 && (pub[0] == SECP256K1_TAG_PUBKEY_UNCOMPRESSED || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) {
  ------------------
  |  |  224|    298|#define SECP256K1_TAG_PUBKEY_HYBRID_ODD 0x07
  ------------------
  |  Branch (22:16): [True: 885, False: 0]
  |  Branch (22:31): [True: 37, False: 848]
  |  Branch (22:78): [True: 550, False: 298]
  |  Branch (22:124): [True: 298, False: 0]
  ------------------
   23|    885|        secp256k1_fe x, y;
   24|    885|        if (!secp256k1_fe_set_b32_limit(&x, pub+1) || !secp256k1_fe_set_b32_limit(&y, pub+33)) {
  ------------------
  |  |   88|    885|#  define secp256k1_fe_set_b32_limit secp256k1_fe_impl_set_b32_limit
  ------------------
                      if (!secp256k1_fe_set_b32_limit(&x, pub+1) || !secp256k1_fe_set_b32_limit(&y, pub+33)) {
  ------------------
  |  |   88|    847|#  define secp256k1_fe_set_b32_limit secp256k1_fe_impl_set_b32_limit
  ------------------
  |  Branch (24:13): [True: 38, False: 847]
  |  Branch (24:55): [True: 72, False: 775]
  ------------------
   25|    110|            return 0;
   26|    110|        }
   27|    775|        secp256k1_ge_set_xy(elem, &x, &y);
   28|    775|        if ((pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD) &&
  ------------------
  |  |  223|  1.55k|#define SECP256K1_TAG_PUBKEY_HYBRID_EVEN 0x06
  ------------------
                      if ((pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD) &&
  ------------------
  |  |  224|    268|#define SECP256K1_TAG_PUBKEY_HYBRID_ODD 0x07
  ------------------
  |  Branch (28:14): [True: 507, False: 268]
  |  Branch (28:60): [True: 231, False: 37]
  ------------------
   29|    738|            secp256k1_fe_is_odd(&y) != (pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) {
  ------------------
  |  |   85|    738|#  define secp256k1_fe_is_odd secp256k1_fe_impl_is_odd
  ------------------
                          secp256k1_fe_is_odd(&y) != (pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) {
  ------------------
  |  |  224|    738|#define SECP256K1_TAG_PUBKEY_HYBRID_ODD 0x07
  ------------------
  |  Branch (29:13): [True: 206, False: 532]
  ------------------
   30|    206|            return 0;
   31|    206|        }
   32|    569|        return secp256k1_ge_is_valid_var(elem);
   33|    775|    } else {
   34|      0|        return 0;
   35|      0|    }
   36|  5.13k|}

secp256k1.c:secp256k1_ecmult_gen_context_clear:
   26|      2|static void secp256k1_ecmult_gen_context_clear(secp256k1_ecmult_gen_context *ctx) {
   27|      2|    ctx->built = 0;
   28|      2|    secp256k1_scalar_clear(&ctx->scalar_offset);
   29|      2|    secp256k1_ge_clear(&ctx->ge_offset);
   30|      2|    secp256k1_fe_clear(&ctx->proj_blind);
   31|      2|}
secp256k1.c:secp256k1_ecmult_gen_context_is_built:
   22|      4|static int secp256k1_ecmult_gen_context_is_built(const secp256k1_ecmult_gen_context* ctx) {
   23|      4|    return ctx->built;
   24|      4|}

secp256k1.c:secp256k1_ecmult:
  365|  3.73k|static void secp256k1_ecmult(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_scalar *na, const secp256k1_scalar *ng) {
  366|  3.73k|    secp256k1_fe aux[ECMULT_TABLE_SIZE(WINDOW_A)];
  367|  3.73k|    secp256k1_ge pre_a[ECMULT_TABLE_SIZE(WINDOW_A)];
  368|  3.73k|    struct secp256k1_strauss_point_state ps[1];
  369|  3.73k|    struct secp256k1_strauss_state state;
  370|       |
  371|  3.73k|    state.aux = aux;
  372|  3.73k|    state.pre_a = pre_a;
  373|  3.73k|    state.ps = ps;
  374|  3.73k|    secp256k1_ecmult_strauss_wnaf(&state, r, 1, a, na, ng);
  375|  3.73k|}
secp256k1.c:secp256k1_ecmult_strauss_wnaf:
  252|  3.73k|static void secp256k1_ecmult_strauss_wnaf(const struct secp256k1_strauss_state *state, secp256k1_gej *r, size_t num, const secp256k1_gej *a, const secp256k1_scalar *na, const secp256k1_scalar *ng) {
  253|  3.73k|    secp256k1_ge tmpa;
  254|  3.73k|    secp256k1_fe Z;
  255|       |    /* Split G factors. */
  256|  3.73k|    secp256k1_scalar ng_1, ng_128;
  257|  3.73k|    int wnaf_ng_1[129];
  258|  3.73k|    int bits_ng_1 = 0;
  259|  3.73k|    int wnaf_ng_128[129];
  260|  3.73k|    int bits_ng_128 = 0;
  261|  3.73k|    int i;
  262|  3.73k|    int bits = 0;
  263|  3.73k|    size_t np;
  264|  3.73k|    size_t no = 0;
  265|       |
  266|  3.73k|    secp256k1_fe_set_int(&Z, 1);
  ------------------
  |  |   83|  3.73k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  267|  7.46k|    for (np = 0; np < num; ++np) {
  ------------------
  |  Branch (267:18): [True: 3.73k, False: 3.73k]
  ------------------
  268|  3.73k|        secp256k1_gej tmp;
  269|  3.73k|        secp256k1_scalar na_1, na_lam;
  270|  3.73k|        if (secp256k1_scalar_is_zero(&na[np]) || secp256k1_gej_is_infinity(&a[np])) {
  ------------------
  |  Branch (270:13): [True: 0, False: 3.73k]
  |  Branch (270:50): [True: 0, False: 3.73k]
  ------------------
  271|      0|            continue;
  272|      0|        }
  273|       |        /* split na into na_1 and na_lam (where na = na_1 + na_lam*lambda, and na_1 and na_lam are ~128 bit) */
  274|  3.73k|        secp256k1_scalar_split_lambda(&na_1, &na_lam, &na[np]);
  275|       |
  276|       |        /* build wnaf representation for na_1 and na_lam. */
  277|  3.73k|        state->ps[no].bits_na_1   = secp256k1_ecmult_wnaf_small(state->ps[no].wnaf_na_1,   129, &na_1,   WINDOW_A);
  ------------------
  |  |   32|  3.73k|#  define WINDOW_A 5
  ------------------
  278|  3.73k|        state->ps[no].bits_na_lam = secp256k1_ecmult_wnaf_small(state->ps[no].wnaf_na_lam, 129, &na_lam, WINDOW_A);
  ------------------
  |  |   32|  3.73k|#  define WINDOW_A 5
  ------------------
  279|  3.73k|        VERIFY_CHECK(state->ps[no].bits_na_1 <= 129);
  280|  3.73k|        VERIFY_CHECK(state->ps[no].bits_na_lam <= 129);
  281|  3.73k|        if (state->ps[no].bits_na_1 > bits) {
  ------------------
  |  Branch (281:13): [True: 3.73k, False: 0]
  ------------------
  282|  3.73k|            bits = state->ps[no].bits_na_1;
  283|  3.73k|        }
  284|  3.73k|        if (state->ps[no].bits_na_lam > bits) {
  ------------------
  |  Branch (284:13): [True: 1.33k, False: 2.39k]
  ------------------
  285|  1.33k|            bits = state->ps[no].bits_na_lam;
  286|  1.33k|        }
  287|       |
  288|       |        /* Calculate odd multiples of a.
  289|       |         * All multiples are brought to the same Z 'denominator', which is stored
  290|       |         * in Z. Due to secp256k1' isomorphism we can do all operations pretending
  291|       |         * that the Z coordinate was 1, use affine addition formulae, and correct
  292|       |         * the Z coordinate of the result once at the end.
  293|       |         * The exception is the precomputed G table points, which are actually
  294|       |         * affine. Compared to the base used for other points, they have a Z ratio
  295|       |         * of 1/Z, so we can use secp256k1_gej_add_zinv_var, which uses the same
  296|       |         * isomorphism to efficiently add with a known Z inverse.
  297|       |         */
  298|  3.73k|        tmp = a[np];
  299|  3.73k|        if (no) {
  ------------------
  |  Branch (299:13): [True: 0, False: 3.73k]
  ------------------
  300|      0|            secp256k1_gej_rescale(&tmp, &Z);
  301|      0|        }
  302|  3.73k|        secp256k1_ecmult_odd_multiples_table(ECMULT_TABLE_SIZE(WINDOW_A), state->pre_a + no * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), &Z, &tmp);
  ------------------
  |  |   41|  3.73k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                      secp256k1_ecmult_odd_multiples_table(ECMULT_TABLE_SIZE(WINDOW_A), state->pre_a + no * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), &Z, &tmp);
  ------------------
  |  |   41|  3.73k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                      secp256k1_ecmult_odd_multiples_table(ECMULT_TABLE_SIZE(WINDOW_A), state->pre_a + no * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), &Z, &tmp);
  ------------------
  |  |   41|  3.73k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
  303|  3.73k|        if (no) secp256k1_fe_mul(state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), &(a[np].z));
  ------------------
  |  |   93|      0|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
                      if (no) secp256k1_fe_mul(state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), &(a[np].z));
  ------------------
  |  |   41|      0|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                      if (no) secp256k1_fe_mul(state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + no * ECMULT_TABLE_SIZE(WINDOW_A), &(a[np].z));
  ------------------
  |  |   41|      0|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
  |  Branch (303:13): [True: 0, False: 3.73k]
  ------------------
  304|       |
  305|  3.73k|        ++no;
  306|  3.73k|    }
  307|       |
  308|       |    /* Bring them to the same Z denominator. */
  309|  3.73k|    if (no) {
  ------------------
  |  Branch (309:9): [True: 3.73k, False: 0]
  ------------------
  310|  3.73k|        secp256k1_ge_table_set_globalz(ECMULT_TABLE_SIZE(WINDOW_A) * no, state->pre_a, state->aux);
  ------------------
  |  |   41|  3.73k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
  311|  3.73k|    }
  312|       |
  313|  7.46k|    for (np = 0; np < no; ++np) {
  ------------------
  |  Branch (313:18): [True: 3.73k, False: 3.73k]
  ------------------
  314|  3.73k|        size_t j;
  315|  33.5k|        for (j = 0; j < ECMULT_TABLE_SIZE(WINDOW_A); j++) {
  ------------------
  |  |   41|  33.5k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
  |  Branch (315:21): [True: 29.8k, False: 3.73k]
  ------------------
  316|  29.8k|            secp256k1_fe_mul(&state->aux[np * ECMULT_TABLE_SIZE(WINDOW_A) + j], &state->pre_a[np * ECMULT_TABLE_SIZE(WINDOW_A) + j].x, &secp256k1_const_beta);
  ------------------
  |  |   93|  29.8k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
                          secp256k1_fe_mul(&state->aux[np * ECMULT_TABLE_SIZE(WINDOW_A) + j], &state->pre_a[np * ECMULT_TABLE_SIZE(WINDOW_A) + j].x, &secp256k1_const_beta);
  ------------------
  |  |   41|  29.8k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                          secp256k1_fe_mul(&state->aux[np * ECMULT_TABLE_SIZE(WINDOW_A) + j], &state->pre_a[np * ECMULT_TABLE_SIZE(WINDOW_A) + j].x, &secp256k1_const_beta);
  ------------------
  |  |   41|  29.8k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
  317|  29.8k|        }
  318|  3.73k|    }
  319|       |
  320|  3.73k|    if (ng) {
  ------------------
  |  Branch (320:9): [True: 3.73k, False: 0]
  ------------------
  321|       |        /* split ng into ng_1 and ng_128 (where gn = gn_1 + gn_128*2^128, and gn_1 and gn_128 are ~128 bit) */
  322|  3.73k|        secp256k1_scalar_split_128(&ng_1, &ng_128, ng);
  323|       |
  324|       |        /* Build wnaf representation for ng_1 and ng_128 */
  325|  3.73k|        bits_ng_1   = secp256k1_ecmult_wnaf(wnaf_ng_1,   129, &ng_1,   WINDOW_G);
  ------------------
  |  |   31|  3.73k|#    define WINDOW_G ECMULT_WINDOW_SIZE
  ------------------
  326|  3.73k|        bits_ng_128 = secp256k1_ecmult_wnaf(wnaf_ng_128, 129, &ng_128, WINDOW_G);
  ------------------
  |  |   31|  3.73k|#    define WINDOW_G ECMULT_WINDOW_SIZE
  ------------------
  327|  3.73k|        if (bits_ng_1 > bits) {
  ------------------
  |  Branch (327:13): [True: 882, False: 2.84k]
  ------------------
  328|    882|            bits = bits_ng_1;
  329|    882|        }
  330|  3.73k|        if (bits_ng_128 > bits) {
  ------------------
  |  Branch (330:13): [True: 689, False: 3.04k]
  ------------------
  331|    689|            bits = bits_ng_128;
  332|    689|        }
  333|  3.73k|    }
  334|       |
  335|  3.73k|    secp256k1_gej_set_infinity(r);
  336|       |
  337|   478k|    for (i = bits - 1; i >= 0; i--) {
  ------------------
  |  Branch (337:24): [True: 474k, False: 3.73k]
  ------------------
  338|   474k|        int n;
  339|   474k|        secp256k1_gej_double_var(r, r, NULL);
  340|   948k|        for (np = 0; np < no; ++np) {
  ------------------
  |  Branch (340:22): [True: 474k, False: 474k]
  ------------------
  341|   474k|            if (i < state->ps[np].bits_na_1 && (n = state->ps[np].wnaf_na_1[i])) {
  ------------------
  |  Branch (341:17): [True: 459k, False: 15.1k]
  |  Branch (341:48): [True: 79.2k, False: 380k]
  ------------------
  342|  79.2k|                secp256k1_ecmult_table_get_ge(&tmpa, state->pre_a + np * ECMULT_TABLE_SIZE(WINDOW_A), n, WINDOW_A);
  ------------------
  |  |   41|  79.2k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                              secp256k1_ecmult_table_get_ge(&tmpa, state->pre_a + np * ECMULT_TABLE_SIZE(WINDOW_A), n, WINDOW_A);
  ------------------
  |  |   32|  79.2k|#  define WINDOW_A 5
  ------------------
  343|  79.2k|                secp256k1_gej_add_ge_var(r, r, &tmpa, NULL);
  344|  79.2k|            }
  345|   474k|            if (i < state->ps[np].bits_na_lam && (n = state->ps[np].wnaf_na_lam[i])) {
  ------------------
  |  Branch (345:17): [True: 457k, False: 16.7k]
  |  Branch (345:50): [True: 78.6k, False: 379k]
  ------------------
  346|  78.6k|                secp256k1_ecmult_table_get_ge_lambda(&tmpa, state->pre_a + np * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + np * ECMULT_TABLE_SIZE(WINDOW_A), n, WINDOW_A);
  ------------------
  |  |   41|  78.6k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                              secp256k1_ecmult_table_get_ge_lambda(&tmpa, state->pre_a + np * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + np * ECMULT_TABLE_SIZE(WINDOW_A), n, WINDOW_A);
  ------------------
  |  |   41|  78.6k|#define ECMULT_TABLE_SIZE(w) ((size_t)1 << ((w)-2))
  ------------------
                              secp256k1_ecmult_table_get_ge_lambda(&tmpa, state->pre_a + np * ECMULT_TABLE_SIZE(WINDOW_A), state->aux + np * ECMULT_TABLE_SIZE(WINDOW_A), n, WINDOW_A);
  ------------------
  |  |   32|  78.6k|#  define WINDOW_A 5
  ------------------
  347|  78.6k|                secp256k1_gej_add_ge_var(r, r, &tmpa, NULL);
  348|  78.6k|            }
  349|   474k|        }
  350|   474k|        if (i < bits_ng_1 && (n = wnaf_ng_1[i])) {
  ------------------
  |  Branch (350:13): [True: 453k, False: 21.1k]
  |  Branch (350:30): [True: 31.5k, False: 421k]
  ------------------
  351|  31.5k|            secp256k1_ecmult_table_get_ge_storage(&tmpa, secp256k1_pre_g, n, WINDOW_G);
  ------------------
  |  |   31|  31.5k|#    define WINDOW_G ECMULT_WINDOW_SIZE
  ------------------
  352|  31.5k|            secp256k1_gej_add_zinv_var(r, r, &tmpa, &Z);
  353|  31.5k|        }
  354|   474k|        if (i < bits_ng_128 && (n = wnaf_ng_128[i])) {
  ------------------
  |  Branch (354:13): [True: 452k, False: 21.5k]
  |  Branch (354:32): [True: 31.5k, False: 421k]
  ------------------
  355|  31.5k|            secp256k1_ecmult_table_get_ge_storage(&tmpa, secp256k1_pre_g_128, n, WINDOW_G);
  ------------------
  |  |   31|  31.5k|#    define WINDOW_G ECMULT_WINDOW_SIZE
  ------------------
  356|  31.5k|            secp256k1_gej_add_zinv_var(r, r, &tmpa, &Z);
  357|  31.5k|        }
  358|   474k|    }
  359|       |
  360|  3.73k|    if (!secp256k1_gej_is_infinity(r)) {
  ------------------
  |  Branch (360:9): [True: 3.73k, False: 0]
  ------------------
  361|  3.73k|        secp256k1_fe_mul(&r->z, &r->z, &Z);
  ------------------
  |  |   93|  3.73k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  362|  3.73k|    }
  363|  3.73k|}
secp256k1.c:secp256k1_ecmult_wnaf_small:
  224|  7.46k|static int secp256k1_ecmult_wnaf_small(int8_t *wnaf, int len, const secp256k1_scalar *a, int w) {
  225|  7.46k|    int wnaf_tmp[256];
  226|  7.46k|    int ret, i;
  227|       |
  228|  7.46k|    VERIFY_CHECK(2 <= w && w <= 8);
  229|  7.46k|    ret = secp256k1_ecmult_wnaf(wnaf_tmp, len, a, w);
  230|       |
  231|   969k|    for (i = 0; i < len; i++) {
  ------------------
  |  Branch (231:17): [True: 962k, False: 7.46k]
  ------------------
  232|   962k|        wnaf[i] = (int8_t)wnaf_tmp[i];
  233|   962k|    }
  234|       |
  235|  7.46k|    return ret;
  236|  7.46k|}
secp256k1.c:secp256k1_ecmult_odd_multiples_table:
   73|  3.73k|static void secp256k1_ecmult_odd_multiples_table(size_t n, secp256k1_ge *pre_a, secp256k1_fe *zr, secp256k1_fe *z, const secp256k1_gej *a) {
   74|  3.73k|    secp256k1_gej d, ai;
   75|  3.73k|    secp256k1_ge d_ge;
   76|  3.73k|    size_t i;
   77|       |
   78|  3.73k|    VERIFY_CHECK(!secp256k1_gej_is_infinity(a));
   79|       |
   80|  3.73k|    secp256k1_gej_double_var(&d, a, NULL);
   81|       |
   82|       |    /*
   83|       |     * Perform the additions using an isomorphic curve Y^2 = X^3 + 7*C^6 where C := d.z.
   84|       |     * The isomorphism, phi, maps a secp256k1 point (x, y) to the point (x*C^2, y*C^3) on the other curve.
   85|       |     * In Jacobian coordinates phi maps (x, y, z) to (x*C^2, y*C^3, z) or, equivalently to (x, y, z/C).
   86|       |     *
   87|       |     *     phi(x, y, z) = (x*C^2, y*C^3, z) = (x, y, z/C)
   88|       |     *   d_ge := phi(d) = (d.x, d.y, 1)
   89|       |     *     ai := phi(a) = (a.x*C^2, a.y*C^3, a.z)
   90|       |     *
   91|       |     * The group addition functions work correctly on these isomorphic curves.
   92|       |     * In particular phi(d) is easy to represent in affine coordinates under this isomorphism.
   93|       |     * This lets us use the faster secp256k1_gej_add_ge_var group addition function that we wouldn't be able to use otherwise.
   94|       |     */
   95|  3.73k|    secp256k1_ge_set_xy(&d_ge, &d.x, &d.y);
   96|  3.73k|    secp256k1_ge_set_gej_zinv(&pre_a[0], a, &d.z);
   97|  3.73k|    secp256k1_gej_set_ge(&ai, &pre_a[0]);
   98|  3.73k|    ai.z = a->z;
   99|       |
  100|       |    /* pre_a[0] is the point (a.x*C^2, a.y*C^3, a.z*C) which is equivalent to a.
  101|       |     * Set zr[0] to C, which is the ratio between the omitted z(pre_a[0]) value and a.z.
  102|       |     */
  103|  3.73k|    zr[0] = d.z;
  104|       |
  105|  29.8k|    for (i = 1; i < n; i++) {
  ------------------
  |  Branch (105:17): [True: 26.1k, False: 3.73k]
  ------------------
  106|  26.1k|        secp256k1_gej_add_ge_var(&ai, &ai, &d_ge, &zr[i]);
  107|  26.1k|        secp256k1_ge_set_xy(&pre_a[i], &ai.x, &ai.y);
  108|  26.1k|    }
  109|       |
  110|       |    /* Multiply the last z-coordinate by C to undo the isomorphism.
  111|       |     * Since the z-coordinates of the pre_a values are implied by the zr array of z-coordinate ratios,
  112|       |     * undoing the isomorphism here undoes the isomorphism for all pre_a values.
  113|       |     */
  114|  3.73k|    secp256k1_fe_mul(z, &ai.z, &d.z);
  ------------------
  |  |   93|  3.73k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  115|  3.73k|}
secp256k1.c:secp256k1_ecmult_wnaf:
  162|  14.9k|static int secp256k1_ecmult_wnaf(int *wnaf, int len, const secp256k1_scalar *a, int w) {
  163|  14.9k|    secp256k1_scalar s;
  164|  14.9k|    int last_set_bit = -1;
  165|  14.9k|    int bit = 0;
  166|  14.9k|    int sign = 1;
  167|  14.9k|    int carry = 0;
  168|       |
  169|  14.9k|    VERIFY_CHECK(wnaf != NULL);
  170|  14.9k|    VERIFY_CHECK(0 <= len && len <= 256);
  171|  14.9k|    VERIFY_CHECK(a != NULL);
  172|  14.9k|    VERIFY_CHECK(2 <= w && w <= 31);
  173|       |
  174|  1.93M|    for (bit = 0; bit < len; bit++) {
  ------------------
  |  Branch (174:19): [True: 1.92M, False: 14.9k]
  ------------------
  175|  1.92M|        wnaf[bit] = 0;
  176|  1.92M|    }
  177|       |
  178|  14.9k|    s = *a;
  179|  14.9k|    if (secp256k1_scalar_get_bits_limb32(&s, 255, 1)) {
  ------------------
  |  Branch (179:9): [True: 3.77k, False: 11.1k]
  ------------------
  180|  3.77k|        secp256k1_scalar_negate(&s, &s);
  181|  3.77k|        sign = -1;
  182|  3.77k|    }
  183|       |
  184|  14.9k|    bit = 0;
  185|   481k|    while (bit < len) {
  ------------------
  |  Branch (185:12): [True: 466k, False: 14.9k]
  ------------------
  186|   466k|        int now;
  187|   466k|        int word;
  188|   466k|        if (secp256k1_scalar_get_bits_limb32(&s, bit, 1) == (unsigned int)carry) {
  ------------------
  |  Branch (188:13): [True: 245k, False: 221k]
  ------------------
  189|   245k|            bit++;
  190|   245k|            continue;
  191|   245k|        }
  192|       |
  193|   221k|        now = w;
  194|   221k|        if (now > len - bit) {
  ------------------
  |  Branch (194:13): [True: 9.23k, False: 211k]
  ------------------
  195|  9.23k|            now = len - bit;
  196|  9.23k|        }
  197|       |
  198|   221k|        word = secp256k1_scalar_get_bits_var(&s, bit, now) + carry;
  199|       |
  200|   221k|        carry = (word >> (w-1)) & 1;
  201|   221k|        word -= carry << w;
  202|       |
  203|   221k|        wnaf[bit] = sign * word;
  204|   221k|        last_set_bit = bit;
  205|       |
  206|   221k|        bit += now;
  207|   221k|    }
  208|       |#ifdef VERIFY
  209|       |    {
  210|       |        int verify_bit = bit;
  211|       |
  212|       |        VERIFY_CHECK(carry == 0);
  213|       |
  214|       |        while (verify_bit < 256) {
  215|       |            VERIFY_CHECK(secp256k1_scalar_get_bits_limb32(&s, verify_bit, 1) == 0);
  216|       |            verify_bit++;
  217|       |        }
  218|       |    }
  219|       |#endif
  220|  14.9k|    return last_set_bit + 1;
  221|  14.9k|}
secp256k1.c:secp256k1_ecmult_table_get_ge:
  125|  79.2k|SECP256K1_INLINE static void secp256k1_ecmult_table_get_ge(secp256k1_ge *r, const secp256k1_ge *pre, int n, int w) {
  126|  79.2k|    secp256k1_ecmult_table_verify(n,w);
  127|  79.2k|    if (n > 0) {
  ------------------
  |  Branch (127:9): [True: 38.8k, False: 40.3k]
  ------------------
  128|  38.8k|        *r = pre[(n-1)/2];
  129|  40.3k|    } else {
  130|  40.3k|        *r = pre[(-n-1)/2];
  131|  40.3k|        secp256k1_fe_negate(&(r->y), &(r->y), 1);
  ------------------
  |  |  211|  40.3k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  40.3k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  40.3k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 40.3k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  40.3k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 40.3k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  40.3k|    } \
  |  |  |  |   94|  40.3k|    stmt; \
  |  |  |  |   95|  40.3k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 40.3k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  132|  40.3k|    }
  133|  79.2k|}
secp256k1.c:secp256k1_ecmult_table_verify:
  117|   221k|SECP256K1_INLINE static void secp256k1_ecmult_table_verify(int n, int w) {
  118|   221k|    (void)n;
  119|   221k|    (void)w;
  120|   221k|    VERIFY_CHECK(((n) & 1) == 1);
  121|   221k|    VERIFY_CHECK((n) >= -((1 << ((w)-1)) - 1));
  122|   221k|    VERIFY_CHECK((n) <=  ((1 << ((w)-1)) - 1));
  123|   221k|}
secp256k1.c:secp256k1_ecmult_table_get_ge_lambda:
  135|  78.6k|SECP256K1_INLINE static void secp256k1_ecmult_table_get_ge_lambda(secp256k1_ge *r, const secp256k1_ge *pre, const secp256k1_fe *x, int n, int w) {
  136|  78.6k|    secp256k1_ecmult_table_verify(n,w);
  137|  78.6k|    if (n > 0) {
  ------------------
  |  Branch (137:9): [True: 40.2k, False: 38.4k]
  ------------------
  138|  40.2k|        secp256k1_ge_set_xy(r, &x[(n-1)/2], &pre[(n-1)/2].y);
  139|  40.2k|    } else {
  140|  38.4k|        secp256k1_ge_set_xy(r, &x[(-n-1)/2], &pre[(-n-1)/2].y);
  141|  38.4k|        secp256k1_fe_negate(&(r->y), &(r->y), 1);
  ------------------
  |  |  211|  38.4k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  38.4k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  38.4k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 38.4k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  38.4k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 38.4k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  38.4k|    } \
  |  |  |  |   94|  38.4k|    stmt; \
  |  |  |  |   95|  38.4k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 38.4k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  142|  38.4k|    }
  143|  78.6k|}
secp256k1.c:secp256k1_ecmult_table_get_ge_storage:
  145|  63.1k|SECP256K1_INLINE static void secp256k1_ecmult_table_get_ge_storage(secp256k1_ge *r, const secp256k1_ge_storage *pre, int n, int w) {
  146|  63.1k|    secp256k1_ecmult_table_verify(n,w);
  147|  63.1k|    if (n > 0) {
  ------------------
  |  Branch (147:9): [True: 34.9k, False: 28.2k]
  ------------------
  148|  34.9k|        secp256k1_ge_from_storage(r, &pre[(n-1)/2]);
  149|  34.9k|    } else {
  150|  28.2k|        secp256k1_ge_from_storage(r, &pre[(-n-1)/2]);
  151|  28.2k|        secp256k1_fe_negate(&(r->y), &(r->y), 1);
  ------------------
  |  |  211|  28.2k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  28.2k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  28.2k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 28.2k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  28.2k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 28.2k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  28.2k|    } \
  |  |  |  |   94|  28.2k|    stmt; \
  |  |  |  |   95|  28.2k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 28.2k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  152|  28.2k|    }
  153|  63.1k|}

secp256k1.c:secp256k1_fe_impl_sqr:
  317|  3.73M|SECP256K1_FORCE_INLINE static void secp256k1_fe_impl_sqr(secp256k1_fe *r, const secp256k1_fe *a) {
  318|  3.73M|    secp256k1_fe_sqr_inner(r->n, a->n);
  319|  3.73M|}
secp256k1.c:secp256k1_fe_impl_mul:
  313|  3.64M|SECP256K1_FORCE_INLINE static void secp256k1_fe_impl_mul(secp256k1_fe *r, const secp256k1_fe *a, const secp256k1_fe * SECP256K1_RESTRICT b) {
  314|  3.64M|    secp256k1_fe_mul_inner(r->n, a->n, b->n);
  315|  3.64M|}
secp256k1.c:secp256k1_fe_impl_add_int:
  301|  4.78k|SECP256K1_INLINE static void secp256k1_fe_impl_add_int(secp256k1_fe *r, int a) {
  302|  4.78k|    r->n[0] += a;
  303|  4.78k|}
secp256k1.c:secp256k1_fe_impl_is_zero:
  206|  3.95k|SECP256K1_INLINE static int secp256k1_fe_impl_is_zero(const secp256k1_fe *a) {
  207|  3.95k|    const uint64_t *t = a->n;
  208|  3.95k|    return (t[0] | t[1] | t[2] | t[3] | t[4]) == 0;
  209|  3.95k|}
secp256k1.c:secp256k1_fe_impl_cmp_var:
  215|  3.73k|static int secp256k1_fe_impl_cmp_var(const secp256k1_fe *a, const secp256k1_fe *b) {
  216|  3.73k|    int i;
  217|  5.85k|    for (i = 4; i >= 0; i--) {
  ------------------
  |  Branch (217:17): [True: 5.85k, False: 0]
  ------------------
  218|  5.85k|        if (a->n[i] > b->n[i]) {
  ------------------
  |  Branch (218:13): [True: 3.73k, False: 2.12k]
  ------------------
  219|  3.73k|            return 1;
  220|  3.73k|        }
  221|  2.12k|        if (a->n[i] < b->n[i]) {
  ------------------
  |  Branch (221:13): [True: 0, False: 2.12k]
  ------------------
  222|      0|            return -1;
  223|      0|        }
  224|  2.12k|    }
  225|      0|    return 0;
  226|  3.73k|}
secp256k1.c:secp256k1_fe_impl_add:
  305|  3.61M|SECP256K1_INLINE static void secp256k1_fe_impl_add(secp256k1_fe *r, const secp256k1_fe *a) {
  306|  3.61M|    r->n[0] += a->n[0];
  307|  3.61M|    r->n[1] += a->n[1];
  308|  3.61M|    r->n[2] += a->n[2];
  309|  3.61M|    r->n[3] += a->n[3];
  310|  3.61M|    r->n[4] += a->n[4];
  311|  3.61M|}
secp256k1.c:secp256k1_fe_impl_normalize_weak:
   80|  3.73k|static void secp256k1_fe_impl_normalize_weak(secp256k1_fe *r) {
   81|  3.73k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
   82|       |
   83|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
   84|  3.73k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
   85|       |
   86|       |    /* The first pass ensures the magnitude is 1, ... */
   87|  3.73k|    t0 += x * 0x1000003D1ULL;
   88|  3.73k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
   89|  3.73k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL;
   90|  3.73k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL;
   91|  3.73k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL;
   92|       |
   93|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
   94|  3.73k|    VERIFY_CHECK(t4 >> 49 == 0);
   95|       |
   96|  3.73k|    r->n[0] = t0; r->n[1] = t1; r->n[2] = t2; r->n[3] = t3; r->n[4] = t4;
   97|  3.73k|}
secp256k1.c:secp256k1_fe_impl_negate_unchecked:
  278|  1.79M|SECP256K1_INLINE static void secp256k1_fe_impl_negate_unchecked(secp256k1_fe *r, const secp256k1_fe *a, int m) {
  279|       |    /* For all legal values of m (0..31), the following properties hold: */
  280|  1.79M|    VERIFY_CHECK(0xFFFFEFFFFFC2FULL * 2 * (m + 1) >= 0xFFFFFFFFFFFFFULL * 2 * m);
  281|  1.79M|    VERIFY_CHECK(0xFFFFFFFFFFFFFULL * 2 * (m + 1) >= 0xFFFFFFFFFFFFFULL * 2 * m);
  282|  1.79M|    VERIFY_CHECK(0x0FFFFFFFFFFFFULL * 2 * (m + 1) >= 0x0FFFFFFFFFFFFULL * 2 * m);
  283|       |
  284|       |    /* Due to the properties above, the left hand in the subtractions below is never less than
  285|       |     * the right hand. */
  286|  1.79M|    r->n[0] = 0xFFFFEFFFFFC2FULL * 2 * (m + 1) - a->n[0];
  287|  1.79M|    r->n[1] = 0xFFFFFFFFFFFFFULL * 2 * (m + 1) - a->n[1];
  288|  1.79M|    r->n[2] = 0xFFFFFFFFFFFFFULL * 2 * (m + 1) - a->n[2];
  289|  1.79M|    r->n[3] = 0xFFFFFFFFFFFFFULL * 2 * (m + 1) - a->n[3];
  290|  1.79M|    r->n[4] = 0x0FFFFFFFFFFFFULL * 2 * (m + 1) - a->n[4];
  291|  1.79M|}
secp256k1.c:secp256k1_fe_impl_normalizes_to_zero:
  137|  8.51k|static int secp256k1_fe_impl_normalizes_to_zero(const secp256k1_fe *r) {
  138|  8.51k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
  139|       |
  140|       |    /* z0 tracks a possible raw value of 0, z1 tracks a possible raw value of P */
  141|  8.51k|    uint64_t z0, z1;
  142|       |
  143|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
  144|  8.51k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
  145|       |
  146|       |    /* The first pass ensures the magnitude is 1, ... */
  147|  8.51k|    t0 += x * 0x1000003D1ULL;
  148|  8.51k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL; z0  = t0; z1  = t0 ^ 0x1000003D0ULL;
  149|  8.51k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; z0 |= t1; z1 &= t1;
  150|  8.51k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; z0 |= t2; z1 &= t2;
  151|  8.51k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; z0 |= t3; z1 &= t3;
  152|  8.51k|                                                z0 |= t4; z1 &= t4 ^ 0xF000000000000ULL;
  153|       |
  154|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
  155|  8.51k|    VERIFY_CHECK(t4 >> 49 == 0);
  156|       |
  157|  8.51k|    return (z0 == 0) | (z1 == 0xFFFFFFFFFFFFFULL);
  158|  8.51k|}
secp256k1.c:secp256k1_fe_impl_set_int:
  201|  37.3k|SECP256K1_INLINE static void secp256k1_fe_impl_set_int(secp256k1_fe *r, int a) {
  202|  37.3k|    r->n[0] = a;
  203|  37.3k|    r->n[1] = r->n[2] = r->n[3] = r->n[4] = 0;
  204|  37.3k|}
secp256k1.c:secp256k1_fe_impl_mul_int_unchecked:
  293|   474k|SECP256K1_INLINE static void secp256k1_fe_impl_mul_int_unchecked(secp256k1_fe *r, int a) {
  294|   474k|    r->n[0] *= a;
  295|   474k|    r->n[1] *= a;
  296|   474k|    r->n[2] *= a;
  297|   474k|    r->n[3] *= a;
  298|   474k|    r->n[4] *= a;
  299|   474k|}
secp256k1.c:secp256k1_fe_impl_half:
  335|   474k|static SECP256K1_INLINE void secp256k1_fe_impl_half(secp256k1_fe *r) {
  336|   474k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
  337|   474k|    uint64_t one = (uint64_t)1;
  338|   474k|    uint64_t mask = -(t0 & one) >> 12;
  339|       |
  340|       |    /* Bounds analysis (over the rationals).
  341|       |     *
  342|       |     * Let m = r->magnitude
  343|       |     *     C = 0xFFFFFFFFFFFFFULL * 2
  344|       |     *     D = 0x0FFFFFFFFFFFFULL * 2
  345|       |     *
  346|       |     * Initial bounds: t0..t3 <= C * m
  347|       |     *                     t4 <= D * m
  348|       |     */
  349|       |
  350|   474k|    t0 += 0xFFFFEFFFFFC2FULL & mask;
  351|   474k|    t1 += mask;
  352|   474k|    t2 += mask;
  353|   474k|    t3 += mask;
  354|   474k|    t4 += mask >> 4;
  355|       |
  356|   474k|    VERIFY_CHECK((t0 & one) == 0);
  357|       |
  358|       |    /* t0..t3: added <= C/2
  359|       |     *     t4: added <= D/2
  360|       |     *
  361|       |     * Current bounds: t0..t3 <= C * (m + 1/2)
  362|       |     *                     t4 <= D * (m + 1/2)
  363|       |     */
  364|       |
  365|   474k|    r->n[0] = (t0 >> 1) + ((t1 & one) << 51);
  366|   474k|    r->n[1] = (t1 >> 1) + ((t2 & one) << 51);
  367|   474k|    r->n[2] = (t2 >> 1) + ((t3 & one) << 51);
  368|   474k|    r->n[3] = (t3 >> 1) + ((t4 & one) << 51);
  369|   474k|    r->n[4] = (t4 >> 1);
  370|       |
  371|       |    /* t0..t3: shifted right and added <= C/4 + 1/2
  372|       |     *     t4: shifted right
  373|       |     *
  374|       |     * Current bounds: t0..t3 <= C * (m/2 + 1/2)
  375|       |     *                     t4 <= D * (m/2 + 1/4)
  376|       |     *
  377|       |     * Therefore the output magnitude (M) has to be set such that:
  378|       |     *     t0..t3: C * M >= C * (m/2 + 1/2)
  379|       |     *         t4: D * M >= D * (m/2 + 1/4)
  380|       |     *
  381|       |     * It suffices for all limbs that, for any input magnitude m:
  382|       |     *     M >= m/2 + 1/2
  383|       |     *
  384|       |     * and since we want the smallest such integer value for M:
  385|       |     *     M == floor(m/2) + 1
  386|       |     */
  387|   474k|}
secp256k1.c:secp256k1_fe_impl_set_b32_limit:
  265|  9.71k|static int secp256k1_fe_impl_set_b32_limit(secp256k1_fe *r, const unsigned char *a) {
  266|  9.71k|    secp256k1_fe_impl_set_b32_mod(r, a);
  267|  9.71k|    return !((r->n[4] == 0x0FFFFFFFFFFFFULL) & ((r->n[3] & r->n[2] & r->n[1]) == 0xFFFFFFFFFFFFFULL) & (r->n[0] >= 0xFFFFEFFFFFC2FULL));
  268|  9.71k|}
secp256k1.c:secp256k1_fe_impl_normalize_var:
   99|  4.21k|static void secp256k1_fe_impl_normalize_var(secp256k1_fe *r) {
  100|  4.21k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
  101|       |
  102|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
  103|  4.21k|    uint64_t m;
  104|  4.21k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
  105|       |
  106|       |    /* The first pass ensures the magnitude is 1, ... */
  107|  4.21k|    t0 += x * 0x1000003D1ULL;
  108|  4.21k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
  109|  4.21k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; m = t1;
  110|  4.21k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; m &= t2;
  111|  4.21k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; m &= t3;
  112|       |
  113|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
  114|  4.21k|    VERIFY_CHECK(t4 >> 49 == 0);
  115|       |
  116|       |    /* At most a single final reduction is needed; check if the value is >= the field characteristic */
  117|  4.21k|    x = (t4 >> 48) | ((t4 == 0x0FFFFFFFFFFFFULL) & (m == 0xFFFFFFFFFFFFFULL)
  118|  4.21k|        & (t0 >= 0xFFFFEFFFFFC2FULL));
  119|       |
  120|  4.21k|    if (x) {
  ------------------
  |  Branch (120:9): [True: 0, False: 4.21k]
  ------------------
  121|      0|        t0 += 0x1000003D1ULL;
  122|      0|        t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
  123|      0|        t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL;
  124|      0|        t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL;
  125|      0|        t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL;
  126|       |
  127|       |        /* If t4 didn't carry to bit 48 already, then it should have after any final reduction */
  128|      0|        VERIFY_CHECK(t4 >> 48 == x);
  129|       |
  130|       |        /* Mask off the possible multiple of 2^256 from the final reduction */
  131|      0|        t4 &= 0x0FFFFFFFFFFFFULL;
  132|      0|    }
  133|       |
  134|  4.21k|    r->n[0] = t0; r->n[1] = t1; r->n[2] = t2; r->n[3] = t3; r->n[4] = t4;
  135|  4.21k|}
secp256k1.c:secp256k1_fe_impl_is_odd:
  211|  4.95k|SECP256K1_INLINE static int secp256k1_fe_impl_is_odd(const secp256k1_fe *a) {
  212|  4.95k|    return a->n[0] & 1;
  213|  4.95k|}
secp256k1.c:secp256k1_fe_impl_from_storage:
  409|   134k|static SECP256K1_INLINE void secp256k1_fe_impl_from_storage(secp256k1_fe *r, const secp256k1_fe_storage *a) {
  410|   134k|    r->n[0] = a->n[0] & 0xFFFFFFFFFFFFFULL;
  411|   134k|    r->n[1] = a->n[0] >> 52 | ((a->n[1] << 12) & 0xFFFFFFFFFFFFFULL);
  412|   134k|    r->n[2] = a->n[1] >> 40 | ((a->n[2] << 24) & 0xFFFFFFFFFFFFFULL);
  413|   134k|    r->n[3] = a->n[2] >> 28 | ((a->n[3] << 36) & 0xFFFFFFFFFFFFFULL);
  414|   134k|    r->n[4] = a->n[3] >> 16;
  415|   134k|}
secp256k1.c:secp256k1_fe_impl_normalizes_to_zero_var:
  160|   243k|static int secp256k1_fe_impl_normalizes_to_zero_var(const secp256k1_fe *r) {
  161|   243k|    uint64_t t0, t1, t2, t3, t4;
  162|   243k|    uint64_t z0, z1;
  163|   243k|    uint64_t x;
  164|       |
  165|   243k|    t0 = r->n[0];
  166|   243k|    t4 = r->n[4];
  167|       |
  168|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
  169|   243k|    x = t4 >> 48;
  170|       |
  171|       |    /* The first pass ensures the magnitude is 1, ... */
  172|   243k|    t0 += x * 0x1000003D1ULL;
  173|       |
  174|       |    /* z0 tracks a possible raw value of 0, z1 tracks a possible raw value of P */
  175|   243k|    z0 = t0 & 0xFFFFFFFFFFFFFULL;
  176|   243k|    z1 = z0 ^ 0x1000003D0ULL;
  177|       |
  178|       |    /* Fast return path should catch the majority of cases */
  179|   243k|    if ((z0 != 0ULL) & (z1 != 0xFFFFFFFFFFFFFULL)) {
  ------------------
  |  Branch (179:9): [True: 243k, False: 42]
  ------------------
  180|   243k|        return 0;
  181|   243k|    }
  182|       |
  183|     42|    t1 = r->n[1];
  184|     42|    t2 = r->n[2];
  185|     42|    t3 = r->n[3];
  186|       |
  187|     42|    t4 &= 0x0FFFFFFFFFFFFULL;
  188|       |
  189|     42|    t1 += (t0 >> 52);
  190|     42|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; z0 |= t1; z1 &= t1;
  191|     42|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; z0 |= t2; z1 &= t2;
  192|     42|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; z0 |= t3; z1 &= t3;
  193|     42|                                                z0 |= t4; z1 &= t4 ^ 0xF000000000000ULL;
  194|       |
  195|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
  196|     42|    VERIFY_CHECK(t4 >> 49 == 0);
  197|       |
  198|     42|    return (z0 == 0) | (z1 == 0xFFFFFFFFFFFFFULL);
  199|   243k|}
secp256k1.c:secp256k1_fe_impl_set_b32_mod:
  228|  9.71k|static void secp256k1_fe_impl_set_b32_mod(secp256k1_fe *r, const unsigned char *a) {
  229|  9.71k|    r->n[0] = (uint64_t)a[31]
  230|  9.71k|            | ((uint64_t)a[30] << 8)
  231|  9.71k|            | ((uint64_t)a[29] << 16)
  232|  9.71k|            | ((uint64_t)a[28] << 24)
  233|  9.71k|            | ((uint64_t)a[27] << 32)
  234|  9.71k|            | ((uint64_t)a[26] << 40)
  235|  9.71k|            | ((uint64_t)(a[25] & 0xF)  << 48);
  236|  9.71k|    r->n[1] = (uint64_t)((a[25] >> 4) & 0xF)
  237|  9.71k|            | ((uint64_t)a[24] << 4)
  238|  9.71k|            | ((uint64_t)a[23] << 12)
  239|  9.71k|            | ((uint64_t)a[22] << 20)
  240|  9.71k|            | ((uint64_t)a[21] << 28)
  241|  9.71k|            | ((uint64_t)a[20] << 36)
  242|  9.71k|            | ((uint64_t)a[19] << 44);
  243|  9.71k|    r->n[2] = (uint64_t)a[18]
  244|  9.71k|            | ((uint64_t)a[17] << 8)
  245|  9.71k|            | ((uint64_t)a[16] << 16)
  246|  9.71k|            | ((uint64_t)a[15] << 24)
  247|  9.71k|            | ((uint64_t)a[14] << 32)
  248|  9.71k|            | ((uint64_t)a[13] << 40)
  249|  9.71k|            | ((uint64_t)(a[12] & 0xF) << 48);
  250|  9.71k|    r->n[3] = (uint64_t)((a[12] >> 4) & 0xF)
  251|  9.71k|            | ((uint64_t)a[11] << 4)
  252|  9.71k|            | ((uint64_t)a[10] << 12)
  253|  9.71k|            | ((uint64_t)a[9]  << 20)
  254|  9.71k|            | ((uint64_t)a[8]  << 28)
  255|  9.71k|            | ((uint64_t)a[7]  << 36)
  256|  9.71k|            | ((uint64_t)a[6]  << 44);
  257|  9.71k|    r->n[4] = (uint64_t)a[5]
  258|  9.71k|            | ((uint64_t)a[4] << 8)
  259|  9.71k|            | ((uint64_t)a[3] << 16)
  260|  9.71k|            | ((uint64_t)a[2] << 24)
  261|  9.71k|            | ((uint64_t)a[1] << 32)
  262|  9.71k|            | ((uint64_t)a[0] << 40);
  263|  9.71k|}
secp256k1.c:secp256k1_fe_impl_normalize:
   43|  7.90k|static void secp256k1_fe_impl_normalize(secp256k1_fe *r) {
   44|  7.90k|    uint64_t t0 = r->n[0], t1 = r->n[1], t2 = r->n[2], t3 = r->n[3], t4 = r->n[4];
   45|       |
   46|       |    /* Reduce t4 at the start so there will be at most a single carry from the first pass */
   47|  7.90k|    uint64_t m;
   48|  7.90k|    uint64_t x = t4 >> 48; t4 &= 0x0FFFFFFFFFFFFULL;
   49|       |
   50|       |    /* The first pass ensures the magnitude is 1, ... */
   51|  7.90k|    t0 += x * 0x1000003D1ULL;
   52|  7.90k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
   53|  7.90k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL; m = t1;
   54|  7.90k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL; m &= t2;
   55|  7.90k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL; m &= t3;
   56|       |
   57|       |    /* ... except for a possible carry at bit 48 of t4 (i.e. bit 256 of the field element) */
   58|  7.90k|    VERIFY_CHECK(t4 >> 49 == 0);
   59|       |
   60|       |    /* At most a single final reduction is needed; check if the value is >= the field characteristic */
   61|  7.90k|    x = (t4 >> 48) | ((t4 == 0x0FFFFFFFFFFFFULL) & (m == 0xFFFFFFFFFFFFFULL)
   62|  7.90k|        & (t0 >= 0xFFFFEFFFFFC2FULL));
   63|       |
   64|       |    /* Apply the final reduction (for constant-time behaviour, we do it always) */
   65|  7.90k|    t0 += x * 0x1000003D1ULL;
   66|  7.90k|    t1 += (t0 >> 52); t0 &= 0xFFFFFFFFFFFFFULL;
   67|  7.90k|    t2 += (t1 >> 52); t1 &= 0xFFFFFFFFFFFFFULL;
   68|  7.90k|    t3 += (t2 >> 52); t2 &= 0xFFFFFFFFFFFFFULL;
   69|  7.90k|    t4 += (t3 >> 52); t3 &= 0xFFFFFFFFFFFFFULL;
   70|       |
   71|       |    /* If t4 didn't carry to bit 48 already, then it should have after any final reduction */
   72|  7.90k|    VERIFY_CHECK(t4 >> 48 == x);
   73|       |
   74|       |    /* Mask off the possible multiple of 2^256 from the final reduction */
   75|  7.90k|    t4 &= 0x0FFFFFFFFFFFFULL;
   76|       |
   77|  7.90k|    r->n[0] = t0; r->n[1] = t1; r->n[2] = t2; r->n[3] = t3; r->n[4] = t4;
   78|  7.90k|}
secp256k1.c:secp256k1_fe_impl_to_storage:
  402|  7.90k|static void secp256k1_fe_impl_to_storage(secp256k1_fe_storage *r, const secp256k1_fe *a) {
  403|  7.90k|    r->n[0] = a->n[0] | a->n[1] << 52;
  404|  7.90k|    r->n[1] = a->n[1] >> 12 | a->n[2] << 40;
  405|  7.90k|    r->n[2] = a->n[2] >> 24 | a->n[3] << 28;
  406|  7.90k|    r->n[3] = a->n[3] >> 36 | a->n[4] << 16;
  407|  7.90k|}

secp256k1.c:secp256k1_fe_sqr_inner:
  154|  3.73M|SECP256K1_FORCE_INLINE static void secp256k1_fe_sqr_inner(uint64_t *r, const uint64_t *a) {
  155|  3.73M|    secp256k1_uint128 c, d;
  156|  3.73M|    uint64_t a0 = a[0], a1 = a[1], a2 = a[2], a3 = a[3], a4 = a[4];
  157|  3.73M|    uint64_t t3, t4, tx, u0;
  158|  3.73M|    const uint64_t M = 0xFFFFFFFFFFFFFULL, R = 0x1000003D10ULL;
  159|       |
  160|  3.73M|    VERIFY_BITS(a[0], 56);
  161|  3.73M|    VERIFY_BITS(a[1], 56);
  162|  3.73M|    VERIFY_BITS(a[2], 56);
  163|  3.73M|    VERIFY_BITS(a[3], 56);
  164|  3.73M|    VERIFY_BITS(a[4], 52);
  165|       |
  166|       |    /**  [... a b c] is a shorthand for ... + a<<104 + b<<52 + c<<0 mod n.
  167|       |     *  px is a shorthand for sum(a[i]*a[x-i], i=0..x).
  168|       |     *  Note that [x 0 0 0 0 0] = [x*R].
  169|       |     */
  170|       |
  171|  3.73M|    secp256k1_u128_mul(&d, a0*2, a3);
  172|  3.73M|    secp256k1_u128_accum_mul(&d, a1*2, a2);
  173|  3.73M|    VERIFY_BITS_128(&d, 114);
  174|       |    /* [d 0 0 0] = [p3 0 0 0] */
  175|  3.73M|    secp256k1_u128_mul(&c, a4, a4);
  176|  3.73M|    VERIFY_BITS_128(&c, 112);
  177|       |    /* [c 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
  178|  3.73M|    secp256k1_u128_accum_mul(&d, R, secp256k1_u128_to_u64(&c)); secp256k1_u128_rshift(&c, 64);
  179|  3.73M|    VERIFY_BITS_128(&d, 115);
  180|  3.73M|    VERIFY_BITS_128(&c, 48);
  181|       |    /* [(c<<12) 0 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
  182|  3.73M|    t3 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
  183|  3.73M|    VERIFY_BITS(t3, 52);
  184|  3.73M|    VERIFY_BITS_128(&d, 63);
  185|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
  186|       |
  187|  3.73M|    a4 *= 2;
  188|  3.73M|    secp256k1_u128_accum_mul(&d, a0, a4);
  189|  3.73M|    secp256k1_u128_accum_mul(&d, a1*2, a3);
  190|  3.73M|    secp256k1_u128_accum_mul(&d, a2, a2);
  191|  3.73M|    VERIFY_BITS_128(&d, 115);
  192|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  193|  3.73M|    secp256k1_u128_accum_mul(&d, R << 12, secp256k1_u128_to_u64(&c));
  194|  3.73M|    VERIFY_BITS_128(&d, 116);
  195|       |    /* [d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  196|  3.73M|    t4 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
  197|  3.73M|    VERIFY_BITS(t4, 52);
  198|  3.73M|    VERIFY_BITS_128(&d, 64);
  199|       |    /* [d t4 t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  200|  3.73M|    tx = (t4 >> 48); t4 &= (M >> 4);
  201|  3.73M|    VERIFY_BITS(tx, 4);
  202|  3.73M|    VERIFY_BITS(t4, 48);
  203|       |    /* [d t4+(tx<<48) t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
  204|       |
  205|  3.73M|    secp256k1_u128_mul(&c, a0, a0);
  206|  3.73M|    VERIFY_BITS_128(&c, 112);
  207|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 0 p4 p3 0 0 p0] */
  208|  3.73M|    secp256k1_u128_accum_mul(&d, a1, a4);
  209|  3.73M|    secp256k1_u128_accum_mul(&d, a2*2, a3);
  210|  3.73M|    VERIFY_BITS_128(&d, 114);
  211|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  212|  3.73M|    u0 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
  213|  3.73M|    VERIFY_BITS(u0, 52);
  214|  3.73M|    VERIFY_BITS_128(&d, 62);
  215|       |    /* [d u0 t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  216|       |    /* [d 0 t4+(tx<<48)+(u0<<52) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  217|  3.73M|    u0 = (u0 << 4) | tx;
  218|  3.73M|    VERIFY_BITS(u0, 56);
  219|       |    /* [d 0 t4+(u0<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  220|  3.73M|    secp256k1_u128_accum_mul(&c, u0, R >> 4);
  221|  3.73M|    VERIFY_BITS_128(&c, 113);
  222|       |    /* [d 0 t4 t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  223|  3.73M|    r[0] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  224|  3.73M|    VERIFY_BITS(r[0], 52);
  225|  3.73M|    VERIFY_BITS_128(&c, 61);
  226|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 0 p0] */
  227|       |
  228|  3.73M|    a0 *= 2;
  229|  3.73M|    secp256k1_u128_accum_mul(&c, a0, a1);
  230|  3.73M|    VERIFY_BITS_128(&c, 114);
  231|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 p1 p0] */
  232|  3.73M|    secp256k1_u128_accum_mul(&d, a2, a4);
  233|  3.73M|    secp256k1_u128_accum_mul(&d, a3, a3);
  234|  3.73M|    VERIFY_BITS_128(&d, 114);
  235|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  236|  3.73M|    secp256k1_u128_accum_mul(&c, secp256k1_u128_to_u64(&d) & M, R); secp256k1_u128_rshift(&d, 52);
  237|  3.73M|    VERIFY_BITS_128(&c, 115);
  238|  3.73M|    VERIFY_BITS_128(&d, 62);
  239|       |    /* [d 0 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  240|  3.73M|    r[1] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  241|  3.73M|    VERIFY_BITS(r[1], 52);
  242|  3.73M|    VERIFY_BITS_128(&c, 63);
  243|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  244|       |
  245|  3.73M|    secp256k1_u128_accum_mul(&c, a0, a2);
  246|  3.73M|    secp256k1_u128_accum_mul(&c, a1, a1);
  247|  3.73M|    VERIFY_BITS_128(&c, 114);
  248|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 p2 p1 p0] */
  249|  3.73M|    secp256k1_u128_accum_mul(&d, a3, a4);
  250|  3.73M|    VERIFY_BITS_128(&d, 114);
  251|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  252|  3.73M|    secp256k1_u128_accum_mul(&c, R, secp256k1_u128_to_u64(&d)); secp256k1_u128_rshift(&d, 64);
  253|  3.73M|    VERIFY_BITS_128(&c, 115);
  254|  3.73M|    VERIFY_BITS_128(&d, 50);
  255|       |    /* [(d<<12) 0 0 0 t4 t3 c r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  256|  3.73M|    r[2] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  257|  3.73M|    VERIFY_BITS(r[2], 52);
  258|  3.73M|    VERIFY_BITS_128(&c, 63);
  259|       |    /* [(d<<12) 0 0 0 t4 t3+c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  260|       |
  261|  3.73M|    secp256k1_u128_accum_mul(&c, R << 12, secp256k1_u128_to_u64(&d));
  262|  3.73M|    secp256k1_u128_accum_u64(&c, t3);
  263|  3.73M|    VERIFY_BITS_128(&c, 100);
  264|       |    /* [t4 c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  265|  3.73M|    r[3] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  266|  3.73M|    VERIFY_BITS(r[3], 52);
  267|  3.73M|    VERIFY_BITS_128(&c, 48);
  268|       |    /* [t4+c r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  269|  3.73M|    r[4] = secp256k1_u128_to_u64(&c) + t4;
  270|  3.73M|    VERIFY_BITS(r[4], 49);
  271|       |    /* [r4 r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  272|  3.73M|}
secp256k1.c:secp256k1_fe_mul_inner:
   18|  3.64M|SECP256K1_FORCE_INLINE static void secp256k1_fe_mul_inner(uint64_t *r, const uint64_t *a, const uint64_t * SECP256K1_RESTRICT b) {
   19|  3.64M|    secp256k1_uint128 c, d;
   20|  3.64M|    uint64_t t3, t4, tx, u0;
   21|  3.64M|    uint64_t a0 = a[0], a1 = a[1], a2 = a[2], a3 = a[3], a4 = a[4];
   22|  3.64M|    const uint64_t M = 0xFFFFFFFFFFFFFULL, R = 0x1000003D10ULL;
   23|       |
   24|  3.64M|    VERIFY_BITS(a[0], 56);
   25|  3.64M|    VERIFY_BITS(a[1], 56);
   26|  3.64M|    VERIFY_BITS(a[2], 56);
   27|  3.64M|    VERIFY_BITS(a[3], 56);
   28|  3.64M|    VERIFY_BITS(a[4], 52);
   29|  3.64M|    VERIFY_BITS(b[0], 56);
   30|  3.64M|    VERIFY_BITS(b[1], 56);
   31|  3.64M|    VERIFY_BITS(b[2], 56);
   32|  3.64M|    VERIFY_BITS(b[3], 56);
   33|  3.64M|    VERIFY_BITS(b[4], 52);
   34|  3.64M|    VERIFY_CHECK(r != b);
   35|  3.64M|    VERIFY_CHECK(a != b);
   36|       |
   37|       |    /*  [... a b c] is a shorthand for ... + a<<104 + b<<52 + c<<0 mod n.
   38|       |     *  for 0 <= x <= 4, px is a shorthand for sum(a[i]*b[x-i], i=0..x).
   39|       |     *  for 4 <= x <= 8, px is a shorthand for sum(a[i]*b[x-i], i=(x-4)..4)
   40|       |     *  Note that [x 0 0 0 0 0] = [x*R].
   41|       |     */
   42|       |
   43|  3.64M|    secp256k1_u128_mul(&d, a0, b[3]);
   44|  3.64M|    secp256k1_u128_accum_mul(&d, a1, b[2]);
   45|  3.64M|    secp256k1_u128_accum_mul(&d, a2, b[1]);
   46|  3.64M|    secp256k1_u128_accum_mul(&d, a3, b[0]);
   47|  3.64M|    VERIFY_BITS_128(&d, 114);
   48|       |    /* [d 0 0 0] = [p3 0 0 0] */
   49|  3.64M|    secp256k1_u128_mul(&c, a4, b[4]);
   50|  3.64M|    VERIFY_BITS_128(&c, 112);
   51|       |    /* [c 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
   52|  3.64M|    secp256k1_u128_accum_mul(&d, R, secp256k1_u128_to_u64(&c)); secp256k1_u128_rshift(&c, 64);
   53|  3.64M|    VERIFY_BITS_128(&d, 115);
   54|  3.64M|    VERIFY_BITS_128(&c, 48);
   55|       |    /* [(c<<12) 0 0 0 0 0 d 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
   56|  3.64M|    t3 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
   57|  3.64M|    VERIFY_BITS(t3, 52);
   58|  3.64M|    VERIFY_BITS_128(&d, 63);
   59|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 0 p3 0 0 0] */
   60|       |
   61|  3.64M|    secp256k1_u128_accum_mul(&d, a0, b[4]);
   62|  3.64M|    secp256k1_u128_accum_mul(&d, a1, b[3]);
   63|  3.64M|    secp256k1_u128_accum_mul(&d, a2, b[2]);
   64|  3.64M|    secp256k1_u128_accum_mul(&d, a3, b[1]);
   65|  3.64M|    secp256k1_u128_accum_mul(&d, a4, b[0]);
   66|  3.64M|    VERIFY_BITS_128(&d, 115);
   67|       |    /* [(c<<12) 0 0 0 0 d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   68|  3.64M|    secp256k1_u128_accum_mul(&d, R << 12, secp256k1_u128_to_u64(&c));
   69|  3.64M|    VERIFY_BITS_128(&d, 116);
   70|       |    /* [d t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   71|  3.64M|    t4 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
   72|  3.64M|    VERIFY_BITS(t4, 52);
   73|  3.64M|    VERIFY_BITS_128(&d, 64);
   74|       |    /* [d t4 t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   75|  3.64M|    tx = (t4 >> 48); t4 &= (M >> 4);
   76|  3.64M|    VERIFY_BITS(tx, 4);
   77|  3.64M|    VERIFY_BITS(t4, 48);
   78|       |    /* [d t4+(tx<<48) t3 0 0 0] = [p8 0 0 0 p4 p3 0 0 0] */
   79|       |
   80|  3.64M|    secp256k1_u128_mul(&c, a0, b[0]);
   81|  3.64M|    VERIFY_BITS_128(&c, 112);
   82|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 0 p4 p3 0 0 p0] */
   83|  3.64M|    secp256k1_u128_accum_mul(&d, a1, b[4]);
   84|  3.64M|    secp256k1_u128_accum_mul(&d, a2, b[3]);
   85|  3.64M|    secp256k1_u128_accum_mul(&d, a3, b[2]);
   86|  3.64M|    secp256k1_u128_accum_mul(&d, a4, b[1]);
   87|  3.64M|    VERIFY_BITS_128(&d, 114);
   88|       |    /* [d t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   89|  3.64M|    u0 = secp256k1_u128_to_u64(&d) & M; secp256k1_u128_rshift(&d, 52);
   90|  3.64M|    VERIFY_BITS(u0, 52);
   91|  3.64M|    VERIFY_BITS_128(&d, 62);
   92|       |    /* [d u0 t4+(tx<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   93|       |    /* [d 0 t4+(tx<<48)+(u0<<52) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   94|  3.64M|    u0 = (u0 << 4) | tx;
   95|  3.64M|    VERIFY_BITS(u0, 56);
   96|       |    /* [d 0 t4+(u0<<48) t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
   97|  3.64M|    secp256k1_u128_accum_mul(&c, u0, R >> 4);
   98|  3.64M|    VERIFY_BITS_128(&c, 113);
   99|       |    /* [d 0 t4 t3 0 0 c] = [p8 0 0 p5 p4 p3 0 0 p0] */
  100|  3.64M|    r[0] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  101|  3.64M|    VERIFY_BITS(r[0], 52);
  102|  3.64M|    VERIFY_BITS_128(&c, 61);
  103|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 0 p0] */
  104|       |
  105|  3.64M|    secp256k1_u128_accum_mul(&c, a0, b[1]);
  106|  3.64M|    secp256k1_u128_accum_mul(&c, a1, b[0]);
  107|  3.64M|    VERIFY_BITS_128(&c, 114);
  108|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 0 p5 p4 p3 0 p1 p0] */
  109|  3.64M|    secp256k1_u128_accum_mul(&d, a2, b[4]);
  110|  3.64M|    secp256k1_u128_accum_mul(&d, a3, b[3]);
  111|  3.64M|    secp256k1_u128_accum_mul(&d, a4, b[2]);
  112|  3.64M|    VERIFY_BITS_128(&d, 114);
  113|       |    /* [d 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  114|  3.64M|    secp256k1_u128_accum_mul(&c, secp256k1_u128_to_u64(&d) & M, R); secp256k1_u128_rshift(&d, 52);
  115|  3.64M|    VERIFY_BITS_128(&c, 115);
  116|  3.64M|    VERIFY_BITS_128(&d, 62);
  117|       |    /* [d 0 0 t4 t3 0 c r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  118|  3.64M|    r[1] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  119|  3.64M|    VERIFY_BITS(r[1], 52);
  120|  3.64M|    VERIFY_BITS_128(&c, 63);
  121|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 0 p1 p0] */
  122|       |
  123|  3.64M|    secp256k1_u128_accum_mul(&c, a0, b[2]);
  124|  3.64M|    secp256k1_u128_accum_mul(&c, a1, b[1]);
  125|  3.64M|    secp256k1_u128_accum_mul(&c, a2, b[0]);
  126|  3.64M|    VERIFY_BITS_128(&c, 114);
  127|       |    /* [d 0 0 t4 t3 c r1 r0] = [p8 0 p6 p5 p4 p3 p2 p1 p0] */
  128|  3.64M|    secp256k1_u128_accum_mul(&d, a3, b[4]);
  129|  3.64M|    secp256k1_u128_accum_mul(&d, a4, b[3]);
  130|  3.64M|    VERIFY_BITS_128(&d, 114);
  131|       |    /* [d 0 0 t4 t3 c t1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  132|  3.64M|    secp256k1_u128_accum_mul(&c, R, secp256k1_u128_to_u64(&d)); secp256k1_u128_rshift(&d, 64);
  133|  3.64M|    VERIFY_BITS_128(&c, 115);
  134|  3.64M|    VERIFY_BITS_128(&d, 50);
  135|       |    /* [(d<<12) 0 0 0 t4 t3 c r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  136|       |
  137|  3.64M|    r[2] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  138|  3.64M|    VERIFY_BITS(r[2], 52);
  139|  3.64M|    VERIFY_BITS_128(&c, 63);
  140|       |    /* [(d<<12) 0 0 0 t4 t3+c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  141|  3.64M|    secp256k1_u128_accum_mul(&c, R << 12, secp256k1_u128_to_u64(&d));
  142|  3.64M|    secp256k1_u128_accum_u64(&c, t3);
  143|  3.64M|    VERIFY_BITS_128(&c, 100);
  144|       |    /* [t4 c r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  145|  3.64M|    r[3] = secp256k1_u128_to_u64(&c) & M; secp256k1_u128_rshift(&c, 52);
  146|  3.64M|    VERIFY_BITS(r[3], 52);
  147|  3.64M|    VERIFY_BITS_128(&c, 48);
  148|       |    /* [t4+c r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  149|  3.64M|    r[4] = secp256k1_u128_to_u64(&c) + t4;
  150|  3.64M|    VERIFY_BITS(r[4], 49);
  151|       |    /* [r4 r3 r2 r1 r0] = [p8 p7 p6 p5 p4 p3 p2 p1 p0] */
  152|  3.64M|}

secp256k1.c:secp256k1_fe_verify:
  149|  8.65M|static void secp256k1_fe_verify(const secp256k1_fe *a) { (void)a; }
secp256k1.c:secp256k1_fe_verify_magnitude:
  150|  8.31M|static void secp256k1_fe_verify_magnitude(const secp256k1_fe *a, int m) { (void)a; (void)m; }
secp256k1.c:secp256k1_fe_sqrt:
   37|  4.21k|static int secp256k1_fe_sqrt(secp256k1_fe * SECP256K1_RESTRICT r, const secp256k1_fe * SECP256K1_RESTRICT a) {
   38|       |    /** Given that p is congruent to 3 mod 4, we can compute the square root of
   39|       |     *  a mod p as the (p+1)/4'th power of a.
   40|       |     *
   41|       |     *  As (p+1)/4 is an even number, it will have the same result for a and for
   42|       |     *  (-a). Only one of these two numbers actually has a square root however,
   43|       |     *  so we test at the end by squaring and comparing to the input.
   44|       |     *  Also because (p+1)/4 is an even number, the computed square root is
   45|       |     *  itself always a square (a ** ((p+1)/4) is the square of a ** ((p+1)/8)).
   46|       |     */
   47|  4.21k|    secp256k1_fe x2, x3, x6, x9, x11, x22, x44, x88, x176, x220, x223, t1;
   48|  4.21k|    int j, ret;
   49|       |
   50|  4.21k|    VERIFY_CHECK(r != a);
   51|  4.21k|    SECP256K1_FE_VERIFY(a);
  ------------------
  |  |  345|  4.21k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   52|  4.21k|    SECP256K1_FE_VERIFY_MAGNITUDE(a, 8);
  ------------------
  |  |  349|  4.21k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   53|       |
   54|       |    /** The binary representation of (p + 1)/4 has 3 blocks of 1s, with lengths in
   55|       |     *  { 2, 22, 223 }. Use an addition chain to calculate 2^n - 1 for each block:
   56|       |     *  1, [2], 3, 6, 9, 11, [22], 44, 88, 176, 220, [223]
   57|       |     */
   58|       |
   59|  4.21k|    secp256k1_fe_sqr(&x2, a);
  ------------------
  |  |   94|  4.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   60|  4.21k|    secp256k1_fe_mul(&x2, &x2, a);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   61|       |
   62|  4.21k|    secp256k1_fe_sqr(&x3, &x2);
  ------------------
  |  |   94|  4.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   63|  4.21k|    secp256k1_fe_mul(&x3, &x3, a);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   64|       |
   65|  4.21k|    x6 = x3;
   66|  16.8k|    for (j=0; j<3; j++) {
  ------------------
  |  Branch (66:15): [True: 12.6k, False: 4.21k]
  ------------------
   67|  12.6k|        secp256k1_fe_sqr(&x6, &x6);
  ------------------
  |  |   94|  12.6k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   68|  12.6k|    }
   69|  4.21k|    secp256k1_fe_mul(&x6, &x6, &x3);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   70|       |
   71|  4.21k|    x9 = x6;
   72|  16.8k|    for (j=0; j<3; j++) {
  ------------------
  |  Branch (72:15): [True: 12.6k, False: 4.21k]
  ------------------
   73|  12.6k|        secp256k1_fe_sqr(&x9, &x9);
  ------------------
  |  |   94|  12.6k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   74|  12.6k|    }
   75|  4.21k|    secp256k1_fe_mul(&x9, &x9, &x3);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   76|       |
   77|  4.21k|    x11 = x9;
   78|  12.6k|    for (j=0; j<2; j++) {
  ------------------
  |  Branch (78:15): [True: 8.43k, False: 4.21k]
  ------------------
   79|  8.43k|        secp256k1_fe_sqr(&x11, &x11);
  ------------------
  |  |   94|  8.43k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   80|  8.43k|    }
   81|  4.21k|    secp256k1_fe_mul(&x11, &x11, &x2);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   82|       |
   83|  4.21k|    x22 = x11;
   84|  50.6k|    for (j=0; j<11; j++) {
  ------------------
  |  Branch (84:15): [True: 46.3k, False: 4.21k]
  ------------------
   85|  46.3k|        secp256k1_fe_sqr(&x22, &x22);
  ------------------
  |  |   94|  46.3k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   86|  46.3k|    }
   87|  4.21k|    secp256k1_fe_mul(&x22, &x22, &x11);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   88|       |
   89|  4.21k|    x44 = x22;
   90|  96.9k|    for (j=0; j<22; j++) {
  ------------------
  |  Branch (90:15): [True: 92.7k, False: 4.21k]
  ------------------
   91|  92.7k|        secp256k1_fe_sqr(&x44, &x44);
  ------------------
  |  |   94|  92.7k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   92|  92.7k|    }
   93|  4.21k|    secp256k1_fe_mul(&x44, &x44, &x22);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
   94|       |
   95|  4.21k|    x88 = x44;
   96|   189k|    for (j=0; j<44; j++) {
  ------------------
  |  Branch (96:15): [True: 185k, False: 4.21k]
  ------------------
   97|   185k|        secp256k1_fe_sqr(&x88, &x88);
  ------------------
  |  |   94|   185k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
   98|   185k|    }
   99|  4.21k|    secp256k1_fe_mul(&x88, &x88, &x44);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  100|       |
  101|  4.21k|    x176 = x88;
  102|   375k|    for (j=0; j<88; j++) {
  ------------------
  |  Branch (102:15): [True: 371k, False: 4.21k]
  ------------------
  103|   371k|        secp256k1_fe_sqr(&x176, &x176);
  ------------------
  |  |   94|   371k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  104|   371k|    }
  105|  4.21k|    secp256k1_fe_mul(&x176, &x176, &x88);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  106|       |
  107|  4.21k|    x220 = x176;
  108|   189k|    for (j=0; j<44; j++) {
  ------------------
  |  Branch (108:15): [True: 185k, False: 4.21k]
  ------------------
  109|   185k|        secp256k1_fe_sqr(&x220, &x220);
  ------------------
  |  |   94|   185k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  110|   185k|    }
  111|  4.21k|    secp256k1_fe_mul(&x220, &x220, &x44);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  112|       |
  113|  4.21k|    x223 = x220;
  114|  16.8k|    for (j=0; j<3; j++) {
  ------------------
  |  Branch (114:15): [True: 12.6k, False: 4.21k]
  ------------------
  115|  12.6k|        secp256k1_fe_sqr(&x223, &x223);
  ------------------
  |  |   94|  12.6k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  116|  12.6k|    }
  117|  4.21k|    secp256k1_fe_mul(&x223, &x223, &x3);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  118|       |
  119|       |    /* The final result is then assembled using a sliding window over the blocks. */
  120|       |
  121|  4.21k|    t1 = x223;
  122|   101k|    for (j=0; j<23; j++) {
  ------------------
  |  Branch (122:15): [True: 96.9k, False: 4.21k]
  ------------------
  123|  96.9k|        secp256k1_fe_sqr(&t1, &t1);
  ------------------
  |  |   94|  96.9k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  124|  96.9k|    }
  125|  4.21k|    secp256k1_fe_mul(&t1, &t1, &x22);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  126|  29.5k|    for (j=0; j<6; j++) {
  ------------------
  |  Branch (126:15): [True: 25.3k, False: 4.21k]
  ------------------
  127|  25.3k|        secp256k1_fe_sqr(&t1, &t1);
  ------------------
  |  |   94|  25.3k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  128|  25.3k|    }
  129|  4.21k|    secp256k1_fe_mul(&t1, &t1, &x2);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  130|  4.21k|    secp256k1_fe_sqr(&t1, &t1);
  ------------------
  |  |   94|  4.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  131|  4.21k|    secp256k1_fe_sqr(r, &t1);
  ------------------
  |  |   94|  4.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  132|       |
  133|       |    /* Check that a square root was actually calculated */
  134|       |
  135|  4.21k|    secp256k1_fe_sqr(&t1, r);
  ------------------
  |  |   94|  4.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  136|  4.21k|    ret = secp256k1_fe_equal(&t1, a);
  137|       |
  138|       |#ifdef VERIFY
  139|       |    if (!ret) {
  140|       |        secp256k1_fe_negate(&t1, &t1, 1);
  141|       |        secp256k1_fe_normalize_var(&t1);
  142|       |        VERIFY_CHECK(secp256k1_fe_equal(&t1, a));
  143|       |    }
  144|       |#endif
  145|  4.21k|    return ret;
  146|  4.21k|}
secp256k1.c:secp256k1_fe_equal:
   25|  8.51k|SECP256K1_INLINE static int secp256k1_fe_equal(const secp256k1_fe *a, const secp256k1_fe *b) {
   26|  8.51k|    secp256k1_fe na;
   27|  8.51k|    SECP256K1_FE_VERIFY(a);
  ------------------
  |  |  345|  8.51k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   28|  8.51k|    SECP256K1_FE_VERIFY(b);
  ------------------
  |  |  345|  8.51k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   29|  8.51k|    SECP256K1_FE_VERIFY_MAGNITUDE(a, 1);
  ------------------
  |  |  349|  8.51k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   30|  8.51k|    SECP256K1_FE_VERIFY_MAGNITUDE(b, 30);
  ------------------
  |  |  349|  8.51k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   31|       |
   32|  8.51k|    secp256k1_fe_negate(&na, a, 1);
  ------------------
  |  |  211|  8.51k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  8.51k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  8.51k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 8.51k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  8.51k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 8.51k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  8.51k|    } \
  |  |  |  |   94|  8.51k|    stmt; \
  |  |  |  |   95|  8.51k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 8.51k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   33|  8.51k|    secp256k1_fe_add(&na, b);
  ------------------
  |  |   92|  8.51k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
   34|  8.51k|    return secp256k1_fe_normalizes_to_zero(&na);
  ------------------
  |  |   81|  8.51k|#  define secp256k1_fe_normalizes_to_zero secp256k1_fe_impl_normalizes_to_zero
  ------------------
   35|  8.51k|}
secp256k1.c:secp256k1_fe_clear:
   21|      2|SECP256K1_INLINE static void secp256k1_fe_clear(secp256k1_fe *a) {
   22|      2|    secp256k1_memclear_explicit(a, sizeof(secp256k1_fe));
   23|      2|}

secp256k1.c:secp256k1_ge_set_xy:
  132|   109k|static void secp256k1_ge_set_xy(secp256k1_ge *r, const secp256k1_fe *x, const secp256k1_fe *y) {
  133|   109k|    SECP256K1_FE_VERIFY(x);
  ------------------
  |  |  345|   109k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  134|   109k|    SECP256K1_FE_VERIFY(y);
  ------------------
  |  |  345|   109k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  135|       |
  136|   109k|    r->infinity = 0;
  137|   109k|    r->x = *x;
  138|   109k|    r->y = *y;
  139|       |
  140|   109k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|   109k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  141|   109k|}
secp256k1.c:secp256k1_ge_verify:
   78|   501k|static void secp256k1_ge_verify(const secp256k1_ge *a) {
   79|   501k|    SECP256K1_FE_VERIFY(&a->x);
  ------------------
  |  |  345|   501k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   80|   501k|    SECP256K1_FE_VERIFY(&a->y);
  ------------------
  |  |  345|   501k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   81|   501k|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->x, SECP256K1_GE_X_MAGNITUDE_MAX);
  ------------------
  |  |  349|   501k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   82|   501k|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->y, SECP256K1_GE_Y_MAGNITUDE_MAX);
  ------------------
  |  |  349|   501k|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   83|   501k|    VERIFY_CHECK(a->infinity == 0 || a->infinity == 1);
   84|   501k|    (void)a;
   85|   501k|}
secp256k1.c:secp256k1_ge_is_valid_var:
  446|    569|static int secp256k1_ge_is_valid_var(const secp256k1_ge *a) {
  447|    569|    secp256k1_fe y2, x3;
  448|    569|    SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|    569|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  449|       |
  450|    569|    if (a->infinity) {
  ------------------
  |  Branch (450:9): [True: 0, False: 569]
  ------------------
  451|      0|        return 0;
  452|      0|    }
  453|       |    /* y^2 = x^3 + 7 */
  454|    569|    secp256k1_fe_sqr(&y2, &a->y);
  ------------------
  |  |   94|    569|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  455|    569|    secp256k1_fe_sqr(&x3, &a->x); secp256k1_fe_mul(&x3, &x3, &a->x);
  ------------------
  |  |   94|    569|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
                  secp256k1_fe_sqr(&x3, &a->x); secp256k1_fe_mul(&x3, &x3, &a->x);
  ------------------
  |  |   93|    569|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  456|    569|    secp256k1_fe_add_int(&x3, SECP256K1_B);
  ------------------
  |  |  102|    569|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                  secp256k1_fe_add_int(&x3, SECP256K1_B);
  ------------------
  |  |   73|    569|#define SECP256K1_B 7
  ------------------
  457|    569|    return secp256k1_fe_equal(&y2, &x3);
  458|    569|}
secp256k1.c:secp256k1_ge_is_in_correct_subgroup:
  926|  3.95k|static int secp256k1_ge_is_in_correct_subgroup(const secp256k1_ge* ge) {
  927|       |#ifdef EXHAUSTIVE_TEST_ORDER
  928|       |    secp256k1_gej out;
  929|       |    int i;
  930|       |    SECP256K1_GE_VERIFY(ge);
  931|       |
  932|       |    /* A very simple EC multiplication ladder that avoids a dependency on ecmult. */
  933|       |    secp256k1_gej_set_infinity(&out);
  934|       |    for (i = 0; i < 32; ++i) {
  935|       |        secp256k1_gej_double_var(&out, &out, NULL);
  936|       |        if ((((uint32_t)EXHAUSTIVE_TEST_ORDER) >> (31 - i)) & 1) {
  937|       |            secp256k1_gej_add_ge_var(&out, &out, ge, NULL);
  938|       |        }
  939|       |    }
  940|       |    return secp256k1_gej_is_infinity(&out);
  941|       |#else
  942|  3.95k|    SECP256K1_GE_VERIFY(ge);
  ------------------
  |  |  212|  3.95k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  943|       |
  944|  3.95k|    (void)ge;
  945|       |    /* The real secp256k1 group has cofactor 1, so the subgroup is the entire curve. */
  946|  3.95k|    return 1;
  947|  3.95k|#endif
  948|  3.95k|}
secp256k1.c:secp256k1_ge_clear:
  343|  3.95k|static void secp256k1_ge_clear(secp256k1_ge *r) {
  344|  3.95k|    secp256k1_memclear_explicit(r, sizeof(secp256k1_ge));
  345|  3.95k|}
secp256k1.c:secp256k1_gej_eq_x_var:
  417|  3.73k|static int secp256k1_gej_eq_x_var(const secp256k1_fe *x, const secp256k1_gej *a) {
  418|  3.73k|    secp256k1_fe r;
  419|  3.73k|    SECP256K1_FE_VERIFY(x);
  ------------------
  |  |  345|  3.73k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  420|  3.73k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  3.73k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  421|  3.73k|    VERIFY_CHECK(!a->infinity);
  422|       |
  423|  3.73k|    secp256k1_fe_sqr(&r, &a->z); secp256k1_fe_mul(&r, &r, x);
  ------------------
  |  |   94|  3.73k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
                  secp256k1_fe_sqr(&r, &a->z); secp256k1_fe_mul(&r, &r, x);
  ------------------
  |  |   93|  3.73k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  424|  3.73k|    return secp256k1_fe_equal(&r, &a->x);
  425|  3.73k|}
secp256k1.c:secp256k1_gej_verify:
   87|  2.42M|static void secp256k1_gej_verify(const secp256k1_gej *a) {
   88|  2.42M|    SECP256K1_FE_VERIFY(&a->x);
  ------------------
  |  |  345|  2.42M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   89|  2.42M|    SECP256K1_FE_VERIFY(&a->y);
  ------------------
  |  |  345|  2.42M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   90|  2.42M|    SECP256K1_FE_VERIFY(&a->z);
  ------------------
  |  |  345|  2.42M|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
   91|  2.42M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->x, SECP256K1_GEJ_X_MAGNITUDE_MAX);
  ------------------
  |  |  349|  2.42M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   92|  2.42M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->y, SECP256K1_GEJ_Y_MAGNITUDE_MAX);
  ------------------
  |  |  349|  2.42M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   93|  2.42M|    SECP256K1_FE_VERIFY_MAGNITUDE(&a->z, SECP256K1_GEJ_Z_MAGNITUDE_MAX);
  ------------------
  |  |  349|  2.42M|#define SECP256K1_FE_VERIFY_MAGNITUDE(a, m) secp256k1_fe_verify_magnitude(a, m)
  ------------------
   94|  2.42M|    VERIFY_CHECK(a->infinity == 0 || a->infinity == 1);
   95|  2.42M|    (void)a;
   96|  2.42M|}
secp256k1.c:secp256k1_gej_set_infinity:
  322|  7.46k|static void secp256k1_gej_set_infinity(secp256k1_gej *r) {
  323|  7.46k|    r->infinity = 1;
  324|  7.46k|    secp256k1_fe_set_int(&r->x, 0);
  ------------------
  |  |   83|  7.46k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  325|  7.46k|    secp256k1_fe_set_int(&r->y, 0);
  ------------------
  |  |   83|  7.46k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  326|  7.46k|    secp256k1_fe_set_int(&r->z, 0);
  ------------------
  |  |   83|  7.46k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  327|       |
  328|  7.46k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  7.46k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  329|  7.46k|}
secp256k1.c:secp256k1_gej_is_infinity:
  440|  11.1k|static int secp256k1_gej_is_infinity(const secp256k1_gej *a) {
  441|  11.1k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  11.1k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  442|       |
  443|  11.1k|    return a->infinity;
  444|  11.1k|}
secp256k1.c:secp256k1_ge_set_xo_var:
  347|  4.21k|static int secp256k1_ge_set_xo_var(secp256k1_ge *r, const secp256k1_fe *x, int odd) {
  348|  4.21k|    secp256k1_fe x2, x3;
  349|  4.21k|    int ret;
  350|  4.21k|    SECP256K1_FE_VERIFY(x);
  ------------------
  |  |  345|  4.21k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  351|       |
  352|  4.21k|    r->x = *x;
  353|  4.21k|    secp256k1_fe_sqr(&x2, x);
  ------------------
  |  |   94|  4.21k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  354|  4.21k|    secp256k1_fe_mul(&x3, x, &x2);
  ------------------
  |  |   93|  4.21k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  355|  4.21k|    r->infinity = 0;
  356|  4.21k|    secp256k1_fe_add_int(&x3, SECP256K1_B);
  ------------------
  |  |  102|  4.21k|#  define secp256k1_fe_add_int secp256k1_fe_impl_add_int
  ------------------
                  secp256k1_fe_add_int(&x3, SECP256K1_B);
  ------------------
  |  |   73|  4.21k|#define SECP256K1_B 7
  ------------------
  357|  4.21k|    ret = secp256k1_fe_sqrt(&r->y, &x3);
  358|  4.21k|    secp256k1_fe_normalize_var(&r->y);
  ------------------
  |  |   80|  4.21k|#  define secp256k1_fe_normalize_var secp256k1_fe_impl_normalize_var
  ------------------
  359|  4.21k|    if (secp256k1_fe_is_odd(&r->y) != odd) {
  ------------------
  |  |   85|  4.21k|#  define secp256k1_fe_is_odd secp256k1_fe_impl_is_odd
  ------------------
  |  Branch (359:9): [True: 1.97k, False: 2.24k]
  ------------------
  360|  1.97k|        secp256k1_fe_negate(&r->y, &r->y, 1);
  ------------------
  |  |  211|  1.97k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  1.97k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  1.97k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 1.97k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  1.97k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 1.97k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  1.97k|    } \
  |  |  |  |   94|  1.97k|    stmt; \
  |  |  |  |   95|  1.97k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 1.97k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  361|  1.97k|    }
  362|       |
  363|  4.21k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  4.21k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  364|  4.21k|    return ret;
  365|  4.21k|}
secp256k1.c:secp256k1_gej_set_ge:
  367|  9.74k|static void secp256k1_gej_set_ge(secp256k1_gej *r, const secp256k1_ge *a) {
  368|  9.74k|   SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  9.74k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  369|       |
  370|  9.74k|   r->infinity = a->infinity;
  371|  9.74k|   r->x = a->x;
  372|  9.74k|   r->y = a->y;
  373|  9.74k|   secp256k1_fe_set_int(&r->z, 1);
  ------------------
  |  |   83|  9.74k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  374|       |
  375|  9.74k|   SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  9.74k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  376|  9.74k|}
secp256k1.c:secp256k1_ge_set_gej_zinv:
   99|  3.73k|static void secp256k1_ge_set_gej_zinv(secp256k1_ge *r, const secp256k1_gej *a, const secp256k1_fe *zi) {
  100|  3.73k|    secp256k1_fe zi2;
  101|  3.73k|    secp256k1_fe zi3;
  102|  3.73k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  3.73k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  103|  3.73k|    SECP256K1_FE_VERIFY(zi);
  ------------------
  |  |  345|  3.73k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  104|  3.73k|    VERIFY_CHECK(!a->infinity);
  105|       |
  106|  3.73k|    secp256k1_fe_sqr(&zi2, zi);
  ------------------
  |  |   94|  3.73k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  107|  3.73k|    secp256k1_fe_mul(&zi3, &zi2, zi);
  ------------------
  |  |   93|  3.73k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  108|  3.73k|    secp256k1_fe_mul(&r->x, &a->x, &zi2);
  ------------------
  |  |   93|  3.73k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  109|  3.73k|    secp256k1_fe_mul(&r->y, &a->y, &zi3);
  ------------------
  |  |   93|  3.73k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  110|  3.73k|    r->infinity = a->infinity;
  111|       |
  112|  3.73k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  3.73k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  113|  3.73k|}
secp256k1.c:secp256k1_ge_table_set_globalz:
  289|  3.73k|static void secp256k1_ge_table_set_globalz(size_t len, secp256k1_ge *a, const secp256k1_fe *zr) {
  290|  3.73k|    size_t i;
  291|  3.73k|    secp256k1_fe zs;
  292|       |#ifdef VERIFY
  293|       |    for (i = 0; i < len; i++) {
  294|       |        SECP256K1_GE_VERIFY(&a[i]);
  295|       |        SECP256K1_FE_VERIFY(&zr[i]);
  296|       |    }
  297|       |#endif
  298|       |
  299|  3.73k|    if (len > 0) {
  ------------------
  |  Branch (299:9): [True: 3.73k, False: 0]
  ------------------
  300|  3.73k|        i = len - 1;
  301|       |        /* Ensure all y values are in weak normal form for fast negation of points */
  302|  3.73k|        secp256k1_fe_normalize_weak(&a[i].y);
  ------------------
  |  |   79|  3.73k|#  define secp256k1_fe_normalize_weak secp256k1_fe_impl_normalize_weak
  ------------------
  303|  3.73k|        zs = zr[i];
  304|       |
  305|       |        /* Work our way backwards, using the z-ratios to scale the x/y values. */
  306|  29.8k|        while (i > 0) {
  ------------------
  |  Branch (306:16): [True: 26.1k, False: 3.73k]
  ------------------
  307|  26.1k|            if (i != len - 1) {
  ------------------
  |  Branch (307:17): [True: 22.3k, False: 3.73k]
  ------------------
  308|  22.3k|                secp256k1_fe_mul(&zs, &zs, &zr[i]);
  ------------------
  |  |   93|  22.3k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  309|  22.3k|            }
  310|  26.1k|            i--;
  311|  26.1k|            secp256k1_ge_set_ge_zinv(&a[i], &a[i], &zs);
  312|  26.1k|        }
  313|  3.73k|    }
  314|       |
  315|       |#ifdef VERIFY
  316|       |    for (i = 0; i < len; i++) {
  317|       |        SECP256K1_GE_VERIFY(&a[i]);
  318|       |    }
  319|       |#endif
  320|  3.73k|}
secp256k1.c:secp256k1_ge_set_ge_zinv:
  116|  26.1k|static void secp256k1_ge_set_ge_zinv(secp256k1_ge *r, const secp256k1_ge *a, const secp256k1_fe *zi) {
  117|  26.1k|    secp256k1_fe zi2;
  118|  26.1k|    secp256k1_fe zi3;
  119|  26.1k|    SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  26.1k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  120|  26.1k|    SECP256K1_FE_VERIFY(zi);
  ------------------
  |  |  345|  26.1k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  121|  26.1k|    VERIFY_CHECK(!a->infinity);
  122|       |
  123|  26.1k|    secp256k1_fe_sqr(&zi2, zi);
  ------------------
  |  |   94|  26.1k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  124|  26.1k|    secp256k1_fe_mul(&zi3, &zi2, zi);
  ------------------
  |  |   93|  26.1k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  125|  26.1k|    secp256k1_fe_mul(&r->x, &a->x, &zi2);
  ------------------
  |  |   93|  26.1k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  126|  26.1k|    secp256k1_fe_mul(&r->y, &a->y, &zi3);
  ------------------
  |  |   93|  26.1k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  127|  26.1k|    r->infinity = a->infinity;
  128|       |
  129|  26.1k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  26.1k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  130|  26.1k|}
secp256k1.c:secp256k1_gej_double_var:
  495|   478k|static void secp256k1_gej_double_var(secp256k1_gej *r, const secp256k1_gej *a, secp256k1_fe *rzr) {
  496|   478k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|   478k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  497|       |
  498|       |    /** For secp256k1, 2Q is infinity if and only if Q is infinity. This is because if 2Q = infinity,
  499|       |     *  Q must equal -Q, or that Q.y == -(Q.y), or Q.y is 0. For a point on y^2 = x^3 + 7 to have
  500|       |     *  y=0, x^3 must be -7 mod p. However, -7 has no cube root mod p.
  501|       |     *
  502|       |     *  Having said this, if this function receives a point on a sextic twist, e.g. by
  503|       |     *  a fault attack, it is possible for y to be 0. This happens for y^2 = x^3 + 6,
  504|       |     *  since -6 does have a cube root mod p. For this point, this function will not set
  505|       |     *  the infinity flag even though the point doubles to infinity, and the result
  506|       |     *  point will be gibberish (z = 0 but infinity = 0).
  507|       |     */
  508|   478k|    if (a->infinity) {
  ------------------
  |  Branch (508:9): [True: 3.73k, False: 474k]
  ------------------
  509|  3.73k|        secp256k1_gej_set_infinity(r);
  510|  3.73k|        if (rzr != NULL) {
  ------------------
  |  Branch (510:13): [True: 0, False: 3.73k]
  ------------------
  511|      0|            secp256k1_fe_set_int(rzr, 1);
  ------------------
  |  |   83|      0|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  512|      0|        }
  513|  3.73k|        return;
  514|  3.73k|    }
  515|       |
  516|   474k|    if (rzr != NULL) {
  ------------------
  |  Branch (516:9): [True: 0, False: 474k]
  ------------------
  517|      0|        *rzr = a->y;
  518|      0|        secp256k1_fe_normalize_weak(rzr);
  ------------------
  |  |   79|      0|#  define secp256k1_fe_normalize_weak secp256k1_fe_impl_normalize_weak
  ------------------
  519|      0|    }
  520|       |
  521|   474k|    secp256k1_gej_double(r, a);
  522|       |
  523|   474k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|   474k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  524|   474k|}
secp256k1.c:secp256k1_gej_double:
  460|   474k|static SECP256K1_INLINE void secp256k1_gej_double(secp256k1_gej *r, const secp256k1_gej *a) {
  461|       |    /* Operations: 3 mul, 4 sqr, 8 add/half/mul_int/negate */
  462|   474k|    secp256k1_fe l, s, t;
  463|   474k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|   474k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  464|       |
  465|   474k|    r->infinity = a->infinity;
  466|       |
  467|       |    /* Formula used:
  468|       |     * L = (3/2) * X1^2
  469|       |     * S = Y1^2
  470|       |     * T = -X1*S
  471|       |     * X3 = L^2 + 2*T
  472|       |     * Y3 = -(L*(X3 + T) + S^2)
  473|       |     * Z3 = Y1*Z1
  474|       |     */
  475|       |
  476|   474k|    secp256k1_fe_mul(&r->z, &a->z, &a->y); /* Z3 = Y1*Z1 (1) */
  ------------------
  |  |   93|   474k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  477|   474k|    secp256k1_fe_sqr(&s, &a->y);           /* S = Y1^2 (1) */
  ------------------
  |  |   94|   474k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  478|   474k|    secp256k1_fe_sqr(&l, &a->x);           /* L = X1^2 (1) */
  ------------------
  |  |   94|   474k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  479|   474k|    secp256k1_fe_mul_int(&l, 3);           /* L = 3*X1^2 (3) */
  ------------------
  |  |  233|   474k|#define secp256k1_fe_mul_int(r, a) ASSERT_INT_CONST_AND_DO(a, secp256k1_fe_mul_int_unchecked(r, a))
  |  |  ------------------
  |  |  |  |   87|   474k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   474k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 474k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   474k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 474k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   474k|    } \
  |  |  |  |   94|   474k|    stmt; \
  |  |  |  |   95|   474k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 474k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  480|   474k|    secp256k1_fe_half(&l);                 /* L = 3/2*X1^2 (2) */
  ------------------
  |  |  101|   474k|#  define secp256k1_fe_half secp256k1_fe_impl_half
  ------------------
  481|   474k|    secp256k1_fe_negate(&t, &s, 1);        /* T = -S (2) */
  ------------------
  |  |  211|   474k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   474k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   474k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 474k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   474k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 474k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   474k|    } \
  |  |  |  |   94|   474k|    stmt; \
  |  |  |  |   95|   474k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 474k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  482|   474k|    secp256k1_fe_mul(&t, &t, &a->x);       /* T = -X1*S (1) */
  ------------------
  |  |   93|   474k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  483|   474k|    secp256k1_fe_sqr(&r->x, &l);           /* X3 = L^2 (1) */
  ------------------
  |  |   94|   474k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  484|   474k|    secp256k1_fe_add(&r->x, &t);           /* X3 = L^2 + T (2) */
  ------------------
  |  |   92|   474k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  485|   474k|    secp256k1_fe_add(&r->x, &t);           /* X3 = L^2 + 2*T (3) */
  ------------------
  |  |   92|   474k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  486|   474k|    secp256k1_fe_sqr(&s, &s);              /* S' = S^2 (1) */
  ------------------
  |  |   94|   474k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  487|   474k|    secp256k1_fe_add(&t, &r->x);           /* T' = X3 + T (4) */
  ------------------
  |  |   92|   474k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  488|   474k|    secp256k1_fe_mul(&r->y, &t, &l);       /* Y3 = L*(X3 + T) (1) */
  ------------------
  |  |   93|   474k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  489|   474k|    secp256k1_fe_add(&r->y, &s);           /* Y3 = L*(X3 + T) + S^2 (2) */
  ------------------
  |  |   92|   474k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  490|   474k|    secp256k1_fe_negate(&r->y, &r->y, 2);  /* Y3 = -(L*(X3 + T) + S^2) (3) */
  ------------------
  |  |  211|   474k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   474k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   474k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 474k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   474k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 474k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   474k|    } \
  |  |  |  |   94|   474k|    stmt; \
  |  |  |  |   95|   474k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 474k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  491|       |
  492|   474k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|   474k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  493|   474k|}
secp256k1.c:secp256k1_ge_from_storage:
  890|  67.1k|static void secp256k1_ge_from_storage(secp256k1_ge *r, const secp256k1_ge_storage *a) {
  891|  67.1k|    secp256k1_fe_from_storage(&r->x, &a->x);
  ------------------
  |  |   97|  67.1k|#  define secp256k1_fe_from_storage secp256k1_fe_impl_from_storage
  ------------------
  892|  67.1k|    secp256k1_fe_from_storage(&r->y, &a->y);
  ------------------
  |  |   97|  67.1k|#  define secp256k1_fe_from_storage secp256k1_fe_impl_from_storage
  ------------------
  893|  67.1k|    r->infinity = 0;
  894|       |
  895|  67.1k|    SECP256K1_GE_VERIFY(r);
  ------------------
  |  |  212|  67.1k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  896|  67.1k|}
secp256k1.c:secp256k1_gej_add_zinv_var:
  653|  63.1k|static void secp256k1_gej_add_zinv_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, const secp256k1_fe *bzinv) {
  654|       |    /* Operations: 9 mul, 3 sqr, 11 add/negate/normalizes_to_zero (ignoring special cases) */
  655|  63.1k|    secp256k1_fe az, z12, u1, u2, s1, s2, h, i, h2, h3, t;
  656|  63.1k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|  63.1k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  657|  63.1k|    SECP256K1_GE_VERIFY(b);
  ------------------
  |  |  212|  63.1k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  658|  63.1k|    SECP256K1_FE_VERIFY(bzinv);
  ------------------
  |  |  345|  63.1k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  659|       |
  660|  63.1k|    if (a->infinity) {
  ------------------
  |  Branch (660:9): [True: 1.44k, False: 61.7k]
  ------------------
  661|  1.44k|        secp256k1_fe bzinv2, bzinv3;
  662|  1.44k|        r->infinity = b->infinity;
  663|  1.44k|        secp256k1_fe_sqr(&bzinv2, bzinv);
  ------------------
  |  |   94|  1.44k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  664|  1.44k|        secp256k1_fe_mul(&bzinv3, &bzinv2, bzinv);
  ------------------
  |  |   93|  1.44k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  665|  1.44k|        secp256k1_fe_mul(&r->x, &b->x, &bzinv2);
  ------------------
  |  |   93|  1.44k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  666|  1.44k|        secp256k1_fe_mul(&r->y, &b->y, &bzinv3);
  ------------------
  |  |   93|  1.44k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  667|  1.44k|        secp256k1_fe_set_int(&r->z, 1);
  ------------------
  |  |   83|  1.44k|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  668|  1.44k|        SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  1.44k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  669|  1.44k|        return;
  670|  1.44k|    }
  671|  61.7k|    if (b->infinity) {
  ------------------
  |  Branch (671:9): [True: 0, False: 61.7k]
  ------------------
  672|      0|        *r = *a;
  673|      0|        return;
  674|      0|    }
  675|       |
  676|       |    /** We need to calculate (rx,ry,rz) = (ax,ay,az) + (bx,by,1/bzinv). Due to
  677|       |     *  secp256k1's isomorphism we can multiply the Z coordinates on both sides
  678|       |     *  by bzinv, and get: (rx,ry,rz*bzinv) = (ax,ay,az*bzinv) + (bx,by,1).
  679|       |     *  This means that (rx,ry,rz) can be calculated as
  680|       |     *  (ax,ay,az*bzinv) + (bx,by,1), when not applying the bzinv factor to rz.
  681|       |     *  The variable az below holds the modified Z coordinate for a, which is used
  682|       |     *  for the computation of rx and ry, but not for rz.
  683|       |     */
  684|  61.7k|    secp256k1_fe_mul(&az, &a->z, bzinv);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  685|       |
  686|  61.7k|    secp256k1_fe_sqr(&z12, &az);
  ------------------
  |  |   94|  61.7k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  687|  61.7k|    u1 = a->x;
  688|  61.7k|    secp256k1_fe_mul(&u2, &b->x, &z12);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  689|  61.7k|    s1 = a->y;
  690|  61.7k|    secp256k1_fe_mul(&s2, &b->y, &z12); secp256k1_fe_mul(&s2, &s2, &az);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
                  secp256k1_fe_mul(&s2, &b->y, &z12); secp256k1_fe_mul(&s2, &s2, &az);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  691|  61.7k|    secp256k1_fe_negate(&h, &u1, SECP256K1_GEJ_X_MAGNITUDE_MAX); secp256k1_fe_add(&h, &u2);
  ------------------
  |  |  211|  61.7k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  61.7k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  61.7k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 61.7k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  61.7k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 61.7k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  61.7k|    } \
  |  |  |  |   94|  61.7k|    stmt; \
  |  |  |  |   95|  61.7k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 61.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  secp256k1_fe_negate(&h, &u1, SECP256K1_GEJ_X_MAGNITUDE_MAX); secp256k1_fe_add(&h, &u2);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  692|  61.7k|    secp256k1_fe_negate(&i, &s2, 1); secp256k1_fe_add(&i, &s1);
  ------------------
  |  |  211|  61.7k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  61.7k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  61.7k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 61.7k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  61.7k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 61.7k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  61.7k|    } \
  |  |  |  |   94|  61.7k|    stmt; \
  |  |  |  |   95|  61.7k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 61.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  secp256k1_fe_negate(&i, &s2, 1); secp256k1_fe_add(&i, &s1);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  693|  61.7k|    if (secp256k1_fe_normalizes_to_zero_var(&h)) {
  ------------------
  |  |   82|  61.7k|#  define secp256k1_fe_normalizes_to_zero_var secp256k1_fe_impl_normalizes_to_zero_var
  ------------------
  |  Branch (693:9): [True: 0, False: 61.7k]
  ------------------
  694|      0|        if (secp256k1_fe_normalizes_to_zero_var(&i)) {
  ------------------
  |  |   82|      0|#  define secp256k1_fe_normalizes_to_zero_var secp256k1_fe_impl_normalizes_to_zero_var
  ------------------
  |  Branch (694:13): [True: 0, False: 0]
  ------------------
  695|      0|            secp256k1_gej_double_var(r, a, NULL);
  696|      0|        } else {
  697|      0|            secp256k1_gej_set_infinity(r);
  698|      0|        }
  699|      0|        return;
  700|      0|    }
  701|       |
  702|  61.7k|    r->infinity = 0;
  703|  61.7k|    secp256k1_fe_mul(&r->z, &a->z, &h);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  704|       |
  705|  61.7k|    secp256k1_fe_sqr(&h2, &h);
  ------------------
  |  |   94|  61.7k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  706|  61.7k|    secp256k1_fe_negate(&h2, &h2, 1);
  ------------------
  |  |  211|  61.7k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|  61.7k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|  61.7k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 61.7k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|  61.7k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 61.7k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|  61.7k|    } \
  |  |  |  |   94|  61.7k|    stmt; \
  |  |  |  |   95|  61.7k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 61.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  707|  61.7k|    secp256k1_fe_mul(&h3, &h2, &h);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  708|  61.7k|    secp256k1_fe_mul(&t, &u1, &h2);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  709|       |
  710|  61.7k|    secp256k1_fe_sqr(&r->x, &i);
  ------------------
  |  |   94|  61.7k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  711|  61.7k|    secp256k1_fe_add(&r->x, &h3);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  712|  61.7k|    secp256k1_fe_add(&r->x, &t);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  713|  61.7k|    secp256k1_fe_add(&r->x, &t);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  714|       |
  715|  61.7k|    secp256k1_fe_add(&t, &r->x);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  716|  61.7k|    secp256k1_fe_mul(&r->y, &t, &i);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  717|  61.7k|    secp256k1_fe_mul(&h3, &h3, &s1);
  ------------------
  |  |   93|  61.7k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  718|  61.7k|    secp256k1_fe_add(&r->y, &h3);
  ------------------
  |  |   92|  61.7k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  719|       |
  720|  61.7k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|  61.7k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  721|  61.7k|}
secp256k1.c:secp256k1_gej_add_ge_var:
  590|   183k|static void secp256k1_gej_add_ge_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, secp256k1_fe *rzr) {
  591|       |    /* Operations: 8 mul, 3 sqr, 11 add/negate/normalizes_to_zero (ignoring special cases) */
  592|   183k|    secp256k1_fe z12, u1, u2, s1, s2, h, i, h2, h3, t;
  593|   183k|    SECP256K1_GEJ_VERIFY(a);
  ------------------
  |  |  216|   183k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  594|   183k|    SECP256K1_GE_VERIFY(b);
  ------------------
  |  |  212|   183k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  595|       |
  596|   183k|    if (a->infinity) {
  ------------------
  |  Branch (596:9): [True: 2.28k, False: 181k]
  ------------------
  597|  2.28k|        VERIFY_CHECK(rzr == NULL);
  598|  2.28k|        secp256k1_gej_set_ge(r, b);
  599|  2.28k|        return;
  600|  2.28k|    }
  601|   181k|    if (b->infinity) {
  ------------------
  |  Branch (601:9): [True: 0, False: 181k]
  ------------------
  602|      0|        if (rzr != NULL) {
  ------------------
  |  Branch (602:13): [True: 0, False: 0]
  ------------------
  603|      0|            secp256k1_fe_set_int(rzr, 1);
  ------------------
  |  |   83|      0|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  604|      0|        }
  605|      0|        *r = *a;
  606|      0|        return;
  607|      0|    }
  608|       |
  609|   181k|    secp256k1_fe_sqr(&z12, &a->z);
  ------------------
  |  |   94|   181k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  610|   181k|    u1 = a->x;
  611|   181k|    secp256k1_fe_mul(&u2, &b->x, &z12);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  612|   181k|    s1 = a->y;
  613|   181k|    secp256k1_fe_mul(&s2, &b->y, &z12); secp256k1_fe_mul(&s2, &s2, &a->z);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
                  secp256k1_fe_mul(&s2, &b->y, &z12); secp256k1_fe_mul(&s2, &s2, &a->z);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  614|   181k|    secp256k1_fe_negate(&h, &u1, SECP256K1_GEJ_X_MAGNITUDE_MAX); secp256k1_fe_add(&h, &u2);
  ------------------
  |  |  211|   181k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   181k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   181k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 181k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   181k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 181k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   181k|    } \
  |  |  |  |   94|   181k|    stmt; \
  |  |  |  |   95|   181k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 181k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  secp256k1_fe_negate(&h, &u1, SECP256K1_GEJ_X_MAGNITUDE_MAX); secp256k1_fe_add(&h, &u2);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  615|   181k|    secp256k1_fe_negate(&i, &s2, 1); secp256k1_fe_add(&i, &s1);
  ------------------
  |  |  211|   181k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   181k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   181k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 181k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   181k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 181k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   181k|    } \
  |  |  |  |   94|   181k|    stmt; \
  |  |  |  |   95|   181k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 181k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  secp256k1_fe_negate(&i, &s2, 1); secp256k1_fe_add(&i, &s1);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  616|   181k|    if (secp256k1_fe_normalizes_to_zero_var(&h)) {
  ------------------
  |  |   82|   181k|#  define secp256k1_fe_normalizes_to_zero_var secp256k1_fe_impl_normalizes_to_zero_var
  ------------------
  |  Branch (616:9): [True: 0, False: 181k]
  ------------------
  617|      0|        if (secp256k1_fe_normalizes_to_zero_var(&i)) {
  ------------------
  |  |   82|      0|#  define secp256k1_fe_normalizes_to_zero_var secp256k1_fe_impl_normalizes_to_zero_var
  ------------------
  |  Branch (617:13): [True: 0, False: 0]
  ------------------
  618|      0|            secp256k1_gej_double_var(r, a, rzr);
  619|      0|        } else {
  620|      0|            if (rzr != NULL) {
  ------------------
  |  Branch (620:17): [True: 0, False: 0]
  ------------------
  621|      0|                secp256k1_fe_set_int(rzr, 0);
  ------------------
  |  |   83|      0|#  define secp256k1_fe_set_int secp256k1_fe_impl_set_int
  ------------------
  622|      0|            }
  623|      0|            secp256k1_gej_set_infinity(r);
  624|      0|        }
  625|      0|        return;
  626|      0|    }
  627|       |
  628|   181k|    r->infinity = 0;
  629|   181k|    if (rzr != NULL) {
  ------------------
  |  Branch (629:9): [True: 26.1k, False: 155k]
  ------------------
  630|  26.1k|        *rzr = h;
  631|  26.1k|    }
  632|   181k|    secp256k1_fe_mul(&r->z, &a->z, &h);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  633|       |
  634|   181k|    secp256k1_fe_sqr(&h2, &h);
  ------------------
  |  |   94|   181k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  635|   181k|    secp256k1_fe_negate(&h2, &h2, 1);
  ------------------
  |  |  211|   181k|#define secp256k1_fe_negate(r, a, m) ASSERT_INT_CONST_AND_DO(m, secp256k1_fe_negate_unchecked(r, a, m))
  |  |  ------------------
  |  |  |  |   87|   181k|#define ASSERT_INT_CONST_AND_DO(expr, stmt) do { \
  |  |  |  |   88|   181k|    switch(42) { \
  |  |  |  |   89|      0|        /* C allows only integer constant expressions as case labels. */ \
  |  |  |  |   90|      0|        case /* ERROR: integer argument is not constant */ (expr): \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (90:9): [True: 0, False: 181k]
  |  |  |  |  ------------------
  |  |  |  |   91|      0|            break; \
  |  |  |  |   92|   181k|        default: ; \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (92:9): [True: 181k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   93|   181k|    } \
  |  |  |  |   94|   181k|    stmt; \
  |  |  |  |   95|   181k|} while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (95:9): [Folded, False: 181k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  636|   181k|    secp256k1_fe_mul(&h3, &h2, &h);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  637|   181k|    secp256k1_fe_mul(&t, &u1, &h2);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  638|       |
  639|   181k|    secp256k1_fe_sqr(&r->x, &i);
  ------------------
  |  |   94|   181k|#  define secp256k1_fe_sqr secp256k1_fe_impl_sqr
  ------------------
  640|   181k|    secp256k1_fe_add(&r->x, &h3);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  641|   181k|    secp256k1_fe_add(&r->x, &t);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  642|   181k|    secp256k1_fe_add(&r->x, &t);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  643|       |
  644|   181k|    secp256k1_fe_add(&t, &r->x);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  645|   181k|    secp256k1_fe_mul(&r->y, &t, &i);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  646|   181k|    secp256k1_fe_mul(&h3, &h3, &s1);
  ------------------
  |  |   93|   181k|#  define secp256k1_fe_mul secp256k1_fe_impl_mul
  ------------------
  647|   181k|    secp256k1_fe_add(&r->y, &h3);
  ------------------
  |  |   92|   181k|#  define secp256k1_fe_add secp256k1_fe_impl_add
  ------------------
  648|       |
  649|   181k|    SECP256K1_GEJ_VERIFY(r);
  ------------------
  |  |  216|   181k|#define SECP256K1_GEJ_VERIFY(a) secp256k1_gej_verify(a)
  ------------------
  650|   181k|    if (rzr != NULL) SECP256K1_FE_VERIFY(rzr);
  ------------------
  |  |  345|  26.1k|#define SECP256K1_FE_VERIFY(a) secp256k1_fe_verify(a)
  ------------------
  |  Branch (650:9): [True: 26.1k, False: 155k]
  ------------------
  651|   181k|}
secp256k1.c:secp256k1_ge_to_bytes:
  977|  3.95k|static void secp256k1_ge_to_bytes(unsigned char *buf, const secp256k1_ge *a) {
  978|  3.95k|    secp256k1_ge_storage s;
  979|       |
  980|       |    /* We require that the secp256k1_ge_storage type is exactly 64 bytes.
  981|       |     * This is formally not guaranteed by the C standard, but should hold on any
  982|       |     * sane compiler in the real world. */
  983|  3.95k|    STATIC_ASSERT(sizeof(secp256k1_ge_storage) == 64);
  ------------------
  |  |   74|  3.95k|#define STATIC_ASSERT(expr) do { \
  |  |   75|  3.95k|    switch(0) { \
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded, False: 0]
  |  |  ------------------
  |  |   76|  3.95k|        case 0: \
  |  |  ------------------
  |  |  |  Branch (76:9): [True: 3.95k, False: 0]
  |  |  ------------------
  |  |   77|  3.95k|        /* If expr evaluates to 0, we have two case labels "0", which is illegal. */ \
  |  |   78|  3.95k|        case /* ERROR: static assertion failed */ (expr): \
  |  |  ------------------
  |  |  |  Branch (78:9): [True: 0, False: 3.95k]
  |  |  ------------------
  |  |   79|  3.95k|        ; \
  |  |   80|  3.95k|    } \
  |  |   81|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (81:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  984|  3.95k|    VERIFY_CHECK(!secp256k1_ge_is_infinity(a));
  985|  3.95k|    secp256k1_ge_to_storage(&s, a);
  986|  3.95k|    memcpy(buf, &s, 64);
  987|  3.95k|}
secp256k1.c:secp256k1_ge_to_storage:
  877|  3.95k|static void secp256k1_ge_to_storage(secp256k1_ge_storage *r, const secp256k1_ge *a) {
  878|  3.95k|    secp256k1_fe x, y;
  879|  3.95k|    SECP256K1_GE_VERIFY(a);
  ------------------
  |  |  212|  3.95k|#define SECP256K1_GE_VERIFY(a) secp256k1_ge_verify(a)
  ------------------
  880|  3.95k|    VERIFY_CHECK(!a->infinity);
  881|       |
  882|  3.95k|    x = a->x;
  883|  3.95k|    secp256k1_fe_normalize(&x);
  ------------------
  |  |   78|  3.95k|#  define secp256k1_fe_normalize secp256k1_fe_impl_normalize
  ------------------
  884|  3.95k|    y = a->y;
  885|  3.95k|    secp256k1_fe_normalize(&y);
  ------------------
  |  |   78|  3.95k|#  define secp256k1_fe_normalize secp256k1_fe_impl_normalize
  ------------------
  886|  3.95k|    secp256k1_fe_to_storage(&r->x, &x);
  ------------------
  |  |   96|  3.95k|#  define secp256k1_fe_to_storage secp256k1_fe_impl_to_storage
  ------------------
  887|  3.95k|    secp256k1_fe_to_storage(&r->y, &y);
  ------------------
  |  |   96|  3.95k|#  define secp256k1_fe_to_storage secp256k1_fe_impl_to_storage
  ------------------
  888|  3.95k|}
secp256k1.c:secp256k1_ge_from_bytes:
  989|  3.95k|static void secp256k1_ge_from_bytes(secp256k1_ge *r, const unsigned char *buf) {
  990|  3.95k|    secp256k1_ge_storage s;
  991|       |
  992|  3.95k|    STATIC_ASSERT(sizeof(secp256k1_ge_storage) == 64);
  ------------------
  |  |   74|  3.95k|#define STATIC_ASSERT(expr) do { \
  |  |   75|  3.95k|    switch(0) { \
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded, False: 0]
  |  |  ------------------
  |  |   76|  3.95k|        case 0: \
  |  |  ------------------
  |  |  |  Branch (76:9): [True: 3.95k, False: 0]
  |  |  ------------------
  |  |   77|  3.95k|        /* If expr evaluates to 0, we have two case labels "0", which is illegal. */ \
  |  |   78|  3.95k|        case /* ERROR: static assertion failed */ (expr): \
  |  |  ------------------
  |  |  |  Branch (78:9): [True: 0, False: 3.95k]
  |  |  ------------------
  |  |   79|  3.95k|        ; \
  |  |   80|  3.95k|    } \
  |  |   81|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (81:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  993|  3.95k|    memcpy(&s, buf, 64);
  994|  3.95k|    secp256k1_ge_from_storage(r, &s);
  995|  3.95k|}

secp256k1.c:secp256k1_u128_mul:
   11|  22.1M|static SECP256K1_INLINE void secp256k1_u128_mul(secp256k1_uint128 *r, uint64_t a, uint64_t b) {
   12|  22.1M|   *r = (uint128_t)a * b;
   13|  22.1M|}
secp256k1.c:secp256k1_u128_accum_mul:
   15|   169M|static SECP256K1_INLINE void secp256k1_u128_accum_mul(secp256k1_uint128 *r, uint64_t a, uint64_t b) {
   16|   169M|   *r += (uint128_t)a * b;
   17|   169M|}
secp256k1.c:secp256k1_u128_to_u64:
   28|  96.3M|static SECP256K1_INLINE uint64_t secp256k1_u128_to_u64(const secp256k1_uint128 *a) {
   29|  96.3M|   return (uint64_t)(*a);
   30|  96.3M|}
secp256k1.c:secp256k1_u128_rshift:
   23|  74.0M|static SECP256K1_INLINE void secp256k1_u128_rshift(secp256k1_uint128 *r, unsigned int n) {
   24|  74.0M|   VERIFY_CHECK(n < 128);
   25|  74.0M|   *r >>= n;
   26|  74.0M|}
secp256k1.c:secp256k1_u128_accum_u64:
   19|  7.82M|static SECP256K1_INLINE void secp256k1_u128_accum_u64(secp256k1_uint128 *r, uint64_t a) {
   20|  7.82M|   *r += a;
   21|  7.82M|}
secp256k1.c:secp256k1_u128_from_u64:
   36|  68.4k|static SECP256K1_INLINE void secp256k1_u128_from_u64(secp256k1_uint128 *r, uint64_t a) {
   37|  68.4k|   *r = a;
   38|  68.4k|}
secp256k1.c:secp256k1_i128_mul:
   49|   134k|static SECP256K1_INLINE void secp256k1_i128_mul(secp256k1_int128 *r, int64_t a, int64_t b) {
   50|   134k|   *r = (int128_t)a * b;
   51|   134k|}
secp256k1.c:secp256k1_i128_accum_mul:
   53|  1.18M|static SECP256K1_INLINE void secp256k1_i128_accum_mul(secp256k1_int128 *r, int64_t a, int64_t b) {
   54|  1.18M|   int128_t ab = (int128_t)a * b;
   55|  1.18M|   VERIFY_CHECK(0 <= ab ? *r <= INT128_MAX - ab : INT128_MIN - ab <= *r);
   56|  1.18M|   *r += ab;
   57|  1.18M|}
secp256k1.c:secp256k1_i128_to_u64:
   71|   460k|static SECP256K1_INLINE uint64_t secp256k1_i128_to_u64(const secp256k1_int128 *a) {
   72|   460k|   return (uint64_t)*a;
   73|   460k|}
secp256k1.c:secp256k1_i128_rshift:
   66|   527k|static SECP256K1_INLINE void secp256k1_i128_rshift(secp256k1_int128 *r, unsigned int n) {
   67|   527k|   VERIFY_CHECK(n < 128);
   68|   527k|   *r >>= n;
   69|   527k|}
secp256k1.c:secp256k1_i128_to_i64:
   75|   134k|static SECP256K1_INLINE int64_t secp256k1_i128_to_i64(const secp256k1_int128 *a) {
   76|   134k|   VERIFY_CHECK(INT64_MIN <= *a && *a <= INT64_MAX);
   77|   134k|   return *a;
   78|   134k|}

secp256k1.c:secp256k1_modinv64_var:
  637|  3.73k|static void secp256k1_modinv64_var(secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo) {
  638|       |    /* Start with d=0, e=1, f=modulus, g=x, eta=-1. */
  639|  3.73k|    secp256k1_modinv64_signed62 d = {{0, 0, 0, 0, 0}};
  640|  3.73k|    secp256k1_modinv64_signed62 e = {{1, 0, 0, 0, 0}};
  641|  3.73k|    secp256k1_modinv64_signed62 f = modinfo->modulus;
  642|  3.73k|    secp256k1_modinv64_signed62 g = *x;
  643|       |#ifdef VERIFY
  644|       |    int i = 0;
  645|       |#endif
  646|  3.73k|    int j, len = 5;
  647|  3.73k|    int64_t eta = -1; /* eta = -delta; delta is initially 1 */
  648|  3.73k|    int64_t cond, fn, gn;
  649|       |
  650|       |    /* Do iterations of 62 divsteps each until g=0. */
  651|  33.6k|    while (1) {
  ------------------
  |  Branch (651:12): [True: 33.6k, Folded]
  ------------------
  652|       |        /* Compute transition matrix and new eta after 62 divsteps. */
  653|  33.6k|        secp256k1_modinv64_trans2x2 t;
  654|  33.6k|        eta = secp256k1_modinv64_divsteps_62_var(eta, f.v[0], g.v[0], &t);
  655|       |        /* Update d,e using that transition matrix. */
  656|  33.6k|        secp256k1_modinv64_update_de_62(&d, &e, &t, modinfo);
  657|       |        /* Update f,g using that transition matrix. */
  658|  33.6k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, -1) > 0); /* f > -modulus */
  659|  33.6k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  660|  33.6k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, -1) > 0); /* g > -modulus */
  661|  33.6k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 1) < 0);  /* g <  modulus */
  662|       |
  663|  33.6k|        secp256k1_modinv64_update_fg_62_var(len, &f, &g, &t);
  664|       |        /* If the bottom limb of g is zero, there is a chance that g=0. */
  665|  33.6k|        if (g.v[0] == 0) {
  ------------------
  |  Branch (665:13): [True: 4.48k, False: 29.1k]
  ------------------
  666|  4.48k|            cond = 0;
  667|       |            /* Check if the other limbs are also 0. */
  668|  7.47k|            for (j = 1; j < len; ++j) {
  ------------------
  |  Branch (668:25): [True: 2.99k, False: 4.48k]
  ------------------
  669|  2.99k|                cond |= g.v[j];
  670|  2.99k|            }
  671|       |            /* If so, we're done. */
  672|  4.48k|            if (cond == 0) break;
  ------------------
  |  Branch (672:17): [True: 3.73k, False: 752]
  ------------------
  673|  4.48k|        }
  674|       |
  675|       |        /* Determine if len>1 and limb (len-1) of both f and g is 0 or -1. */
  676|  29.8k|        fn = f.v[len - 1];
  677|  29.8k|        gn = g.v[len - 1];
  678|  29.8k|        cond = ((int64_t)len - 2) >> 63;
  679|  29.8k|        cond |= fn ^ (fn >> 63);
  680|  29.8k|        cond |= gn ^ (gn >> 63);
  681|       |        /* If so, reduce length, propagating the sign of f and g's top limb into the one below. */
  682|  29.8k|        if (cond == 0) {
  ------------------
  |  Branch (682:13): [True: 14.9k, False: 14.9k]
  ------------------
  683|  14.9k|            f.v[len - 2] |= (uint64_t)fn << 62;
  684|  14.9k|            g.v[len - 2] |= (uint64_t)gn << 62;
  685|  14.9k|            --len;
  686|  14.9k|        }
  687|       |
  688|  29.8k|        VERIFY_CHECK(++i < 12); /* We should never need more than 12*62 = 744 divsteps */
  689|  29.8k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, -1) > 0); /* f > -modulus */
  690|  29.8k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) <= 0); /* f <= modulus */
  691|  29.8k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, -1) > 0); /* g > -modulus */
  692|  29.8k|        VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &modinfo->modulus, 1) < 0);  /* g <  modulus */
  693|  29.8k|    }
  694|       |
  695|       |    /* At this point g is 0 and (if g was not originally 0) f must now equal +/- GCD of
  696|       |     * the initial f, g values i.e. +/- 1, and d now contains +/- the modular inverse. */
  697|       |
  698|       |    /* g == 0 */
  699|  3.73k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&g, len, &SECP256K1_SIGNED62_ONE, 0) == 0);
  700|       |    /* |f| == 1, or (x == 0 and d == 0 and f == modulus) */
  701|  3.73k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(&f, len, &SECP256K1_SIGNED62_ONE, -1) == 0 ||
  702|  3.73k|                 secp256k1_modinv64_mul_cmp_62(&f, len, &SECP256K1_SIGNED62_ONE, 1) == 0 ||
  703|  3.73k|                 (secp256k1_modinv64_mul_cmp_62(x, 5, &SECP256K1_SIGNED62_ONE, 0) == 0 &&
  704|  3.73k|                  secp256k1_modinv64_mul_cmp_62(&d, 5, &SECP256K1_SIGNED62_ONE, 0) == 0 &&
  705|  3.73k|                  secp256k1_modinv64_mul_cmp_62(&f, len, &modinfo->modulus, 1) == 0));
  706|       |
  707|       |    /* Optionally negate d, normalize to [0,modulus), and return it. */
  708|  3.73k|    secp256k1_modinv64_normalize_62(&d, f.v[len - 1], modinfo);
  709|  3.73k|    *x = d;
  710|  3.73k|}
secp256k1.c:secp256k1_modinv64_divsteps_62_var:
  239|  33.6k|static int64_t secp256k1_modinv64_divsteps_62_var(int64_t eta, uint64_t f0, uint64_t g0, secp256k1_modinv64_trans2x2 *t) {
  240|       |    /* Transformation matrix; see comments in secp256k1_modinv64_divsteps_62. */
  241|  33.6k|    uint64_t u = 1, v = 0, q = 0, r = 1;
  242|  33.6k|    uint64_t f = f0, g = g0, m;
  243|  33.6k|    uint32_t w;
  244|  33.6k|    int i = 62, limit, zeros;
  245|       |
  246|   512k|    for (;;) {
  247|       |        /* Use a sentinel bit to count zeros only up to i. */
  248|   512k|        zeros = secp256k1_ctz64_var(g | (UINT64_MAX << i));
  249|       |        /* Perform zeros divsteps at once; they all just divide g by two. */
  250|   512k|        g >>= zeros;
  251|   512k|        u <<= zeros;
  252|   512k|        v <<= zeros;
  253|   512k|        eta -= zeros;
  254|   512k|        i -= zeros;
  255|       |        /* We're done once we've done 62 divsteps. */
  256|   512k|        if (i == 0) break;
  ------------------
  |  Branch (256:13): [True: 33.6k, False: 478k]
  ------------------
  257|   478k|        VERIFY_CHECK((f & 1) == 1);
  258|   478k|        VERIFY_CHECK((g & 1) == 1);
  259|   478k|        VERIFY_CHECK((u * f0 + v * g0) == f << (62 - i));
  260|   478k|        VERIFY_CHECK((q * f0 + r * g0) == g << (62 - i));
  261|       |        /* Bounds on eta that follow from the bounds on iteration count (max 12*62 divsteps). */
  262|   478k|        VERIFY_CHECK(eta >= -745 && eta <= 745);
  263|       |        /* If eta is negative, negate it and replace f,g with g,-f. */
  264|   478k|        if (eta < 0) {
  ------------------
  |  Branch (264:13): [True: 440k, False: 38.5k]
  ------------------
  265|   440k|            uint64_t tmp;
  266|   440k|            eta = -eta;
  267|   440k|            tmp = f; f = g; g = -tmp;
  268|   440k|            tmp = u; u = q; q = -tmp;
  269|   440k|            tmp = v; v = r; r = -tmp;
  270|       |            /* Use a formula to cancel out up to 6 bits of g. Also, no more than i can be cancelled
  271|       |             * out (as we'd be done before that point), and no more than eta+1 can be done as its
  272|       |             * sign will flip again once that happens. */
  273|   440k|            limit = ((int)eta + 1) > i ? i : ((int)eta + 1);
  ------------------
  |  Branch (273:21): [True: 10.0k, False: 430k]
  ------------------
  274|   440k|            VERIFY_CHECK(limit > 0 && limit <= 62);
  275|       |            /* m is a mask for the bottom min(limit, 6) bits. */
  276|   440k|            m = (UINT64_MAX >> (64 - limit)) & 63U;
  277|       |            /* Find what multiple of f must be added to g to cancel its bottom min(limit, 6)
  278|       |             * bits. */
  279|   440k|            w = (f * g * (f * f - 2)) & m;
  280|   440k|        } else {
  281|       |            /* In this branch, use a simpler formula that only lets us cancel up to 4 bits of g, as
  282|       |             * eta tends to be smaller here. */
  283|  38.5k|            limit = ((int)eta + 1) > i ? i : ((int)eta + 1);
  ------------------
  |  Branch (283:21): [True: 17.1k, False: 21.4k]
  ------------------
  284|  38.5k|            VERIFY_CHECK(limit > 0 && limit <= 62);
  285|       |            /* m is a mask for the bottom min(limit, 4) bits. */
  286|  38.5k|            m = (UINT64_MAX >> (64 - limit)) & 15U;
  287|       |            /* Find what multiple of f must be added to g to cancel its bottom min(limit, 4)
  288|       |             * bits. */
  289|  38.5k|            w = f + (((f + 1) & 4) << 1);
  290|  38.5k|            w = (-w * g) & m;
  291|  38.5k|        }
  292|   478k|        g += f * w;
  293|   478k|        q += u * w;
  294|   478k|        r += v * w;
  295|   478k|        VERIFY_CHECK((g & m) == 0);
  296|   478k|    }
  297|       |    /* Return data in t and return value. */
  298|  33.6k|    t->u = (int64_t)u;
  299|  33.6k|    t->v = (int64_t)v;
  300|  33.6k|    t->q = (int64_t)q;
  301|  33.6k|    t->r = (int64_t)r;
  302|       |
  303|       |    /* The determinant of t must be a power of two. This guarantees that multiplication with t
  304|       |     * does not change the gcd of f and g, apart from adding a power-of-2 factor to it (which
  305|       |     * will be divided out again). As each divstep's individual matrix has determinant 2, the
  306|       |     * aggregate of 62 of them will have determinant 2^62. */
  307|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_det_check_pow2(t, 62, 0));
  308|       |
  309|  33.6k|    return eta;
  310|  33.6k|}
secp256k1.c:secp256k1_modinv64_update_de_62:
  411|  33.6k|static void secp256k1_modinv64_update_de_62(secp256k1_modinv64_signed62 *d, secp256k1_modinv64_signed62 *e, const secp256k1_modinv64_trans2x2 *t, const secp256k1_modinv64_modinfo* modinfo) {
  412|  33.6k|    const uint64_t M62 = UINT64_MAX >> 2;
  413|  33.6k|    const int64_t d0 = d->v[0], d1 = d->v[1], d2 = d->v[2], d3 = d->v[3], d4 = d->v[4];
  414|  33.6k|    const int64_t e0 = e->v[0], e1 = e->v[1], e2 = e->v[2], e3 = e->v[3], e4 = e->v[4];
  415|  33.6k|    const int64_t u = t->u, v = t->v, q = t->q, r = t->r;
  416|  33.6k|    int64_t md, me, sd, se;
  417|  33.6k|    secp256k1_int128 cd, ce;
  418|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, -2) > 0); /* d > -2*modulus */
  419|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, 1) < 0);  /* d <    modulus */
  420|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, -2) > 0); /* e > -2*modulus */
  421|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, 1) < 0);  /* e <    modulus */
  422|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_abs(u) <= (((int64_t)1 << 62) - secp256k1_modinv64_abs(v))); /* |u|+|v| <= 2^62 */
  423|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_abs(q) <= (((int64_t)1 << 62) - secp256k1_modinv64_abs(r))); /* |q|+|r| <= 2^62 */
  424|       |
  425|       |    /* [md,me] start as zero; plus [u,q] if d is negative; plus [v,r] if e is negative. */
  426|  33.6k|    sd = d4 >> 63;
  427|  33.6k|    se = e4 >> 63;
  428|  33.6k|    md = (u & sd) + (v & se);
  429|  33.6k|    me = (q & sd) + (r & se);
  430|       |    /* Begin computing t*[d,e]. */
  431|  33.6k|    secp256k1_i128_mul(&cd, u, d0);
  432|  33.6k|    secp256k1_i128_accum_mul(&cd, v, e0);
  433|  33.6k|    secp256k1_i128_mul(&ce, q, d0);
  434|  33.6k|    secp256k1_i128_accum_mul(&ce, r, e0);
  435|       |    /* Correct md,me so that t*[d,e]+modulus*[md,me] has 62 zero bottom bits. */
  436|  33.6k|    md -= (modinfo->modulus_inv62 * secp256k1_i128_to_u64(&cd) + md) & M62;
  437|  33.6k|    me -= (modinfo->modulus_inv62 * secp256k1_i128_to_u64(&ce) + me) & M62;
  438|       |    /* Update the beginning of computation for t*[d,e]+modulus*[md,me] now md,me are known. */
  439|  33.6k|    secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[0], md);
  440|  33.6k|    secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[0], me);
  441|       |    /* Verify that the low 62 bits of the computation are indeed zero, and then throw them away. */
  442|  33.6k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cd) & M62) == 0); secp256k1_i128_rshift(&cd, 62);
  443|  33.6k|    VERIFY_CHECK((secp256k1_i128_to_u64(&ce) & M62) == 0); secp256k1_i128_rshift(&ce, 62);
  444|       |    /* Compute limb 1 of t*[d,e]+modulus*[md,me], and store it as output limb 0 (= down shift). */
  445|  33.6k|    secp256k1_i128_accum_mul(&cd, u, d1);
  446|  33.6k|    secp256k1_i128_accum_mul(&cd, v, e1);
  447|  33.6k|    secp256k1_i128_accum_mul(&ce, q, d1);
  448|  33.6k|    secp256k1_i128_accum_mul(&ce, r, e1);
  449|  33.6k|    if (modinfo->modulus.v[1]) { /* Optimize for the case where limb of modulus is zero. */
  ------------------
  |  Branch (449:9): [True: 33.6k, False: 0]
  ------------------
  450|  33.6k|        secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[1], md);
  451|  33.6k|        secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[1], me);
  452|  33.6k|    }
  453|  33.6k|    d->v[0] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  454|  33.6k|    e->v[0] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  455|       |    /* Compute limb 2 of t*[d,e]+modulus*[md,me], and store it as output limb 1. */
  456|  33.6k|    secp256k1_i128_accum_mul(&cd, u, d2);
  457|  33.6k|    secp256k1_i128_accum_mul(&cd, v, e2);
  458|  33.6k|    secp256k1_i128_accum_mul(&ce, q, d2);
  459|  33.6k|    secp256k1_i128_accum_mul(&ce, r, e2);
  460|  33.6k|    if (modinfo->modulus.v[2]) { /* Optimize for the case where limb of modulus is zero. */
  ------------------
  |  Branch (460:9): [True: 33.6k, False: 0]
  ------------------
  461|  33.6k|        secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[2], md);
  462|  33.6k|        secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[2], me);
  463|  33.6k|    }
  464|  33.6k|    d->v[1] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  465|  33.6k|    e->v[1] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  466|       |    /* Compute limb 3 of t*[d,e]+modulus*[md,me], and store it as output limb 2. */
  467|  33.6k|    secp256k1_i128_accum_mul(&cd, u, d3);
  468|  33.6k|    secp256k1_i128_accum_mul(&cd, v, e3);
  469|  33.6k|    secp256k1_i128_accum_mul(&ce, q, d3);
  470|  33.6k|    secp256k1_i128_accum_mul(&ce, r, e3);
  471|  33.6k|    if (modinfo->modulus.v[3]) { /* Optimize for the case where limb of modulus is zero. */
  ------------------
  |  Branch (471:9): [True: 0, False: 33.6k]
  ------------------
  472|      0|        secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[3], md);
  473|      0|        secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[3], me);
  474|      0|    }
  475|  33.6k|    d->v[2] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  476|  33.6k|    e->v[2] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  477|       |    /* Compute limb 4 of t*[d,e]+modulus*[md,me], and store it as output limb 3. */
  478|  33.6k|    secp256k1_i128_accum_mul(&cd, u, d4);
  479|  33.6k|    secp256k1_i128_accum_mul(&cd, v, e4);
  480|  33.6k|    secp256k1_i128_accum_mul(&ce, q, d4);
  481|  33.6k|    secp256k1_i128_accum_mul(&ce, r, e4);
  482|  33.6k|    secp256k1_i128_accum_mul(&cd, modinfo->modulus.v[4], md);
  483|  33.6k|    secp256k1_i128_accum_mul(&ce, modinfo->modulus.v[4], me);
  484|  33.6k|    d->v[3] = secp256k1_i128_to_u64(&cd) & M62; secp256k1_i128_rshift(&cd, 62);
  485|  33.6k|    e->v[3] = secp256k1_i128_to_u64(&ce) & M62; secp256k1_i128_rshift(&ce, 62);
  486|       |    /* What remains is limb 5 of t*[d,e]+modulus*[md,me]; store it as output limb 4. */
  487|  33.6k|    d->v[4] = secp256k1_i128_to_i64(&cd);
  488|  33.6k|    e->v[4] = secp256k1_i128_to_i64(&ce);
  489|       |
  490|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, -2) > 0); /* d > -2*modulus */
  491|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(d, 5, &modinfo->modulus, 1) < 0);  /* d <    modulus */
  492|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, -2) > 0); /* e > -2*modulus */
  493|  33.6k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(e, 5, &modinfo->modulus, 1) < 0);  /* e <    modulus */
  494|  33.6k|}
secp256k1.c:secp256k1_modinv64_update_fg_62_var:
  553|  33.6k|static void secp256k1_modinv64_update_fg_62_var(int len, secp256k1_modinv64_signed62 *f, secp256k1_modinv64_signed62 *g, const secp256k1_modinv64_trans2x2 *t) {
  554|  33.6k|    const uint64_t M62 = UINT64_MAX >> 2;
  555|  33.6k|    const int64_t u = t->u, v = t->v, q = t->q, r = t->r;
  556|  33.6k|    int64_t fi, gi;
  557|  33.6k|    secp256k1_int128 cf, cg;
  558|  33.6k|    int i;
  559|  33.6k|    VERIFY_CHECK(len > 0);
  560|       |    /* Start computing t*[f,g]. */
  561|  33.6k|    fi = f->v[0];
  562|  33.6k|    gi = g->v[0];
  563|  33.6k|    secp256k1_i128_mul(&cf, u, fi);
  564|  33.6k|    secp256k1_i128_accum_mul(&cf, v, gi);
  565|  33.6k|    secp256k1_i128_mul(&cg, q, fi);
  566|  33.6k|    secp256k1_i128_accum_mul(&cg, r, gi);
  567|       |    /* Verify that the bottom 62 bits of the result are zero, and then throw them away. */
  568|  33.6k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cf) & M62) == 0); secp256k1_i128_rshift(&cf, 62);
  569|  33.6k|    VERIFY_CHECK((secp256k1_i128_to_u64(&cg) & M62) == 0); secp256k1_i128_rshift(&cg, 62);
  570|       |    /* Now iteratively compute limb i=1..len of t*[f,g], and store them in output limb i-1 (shifting
  571|       |     * down by 62 bits). */
  572|  95.8k|    for (i = 1; i < len; ++i) {
  ------------------
  |  Branch (572:17): [True: 62.1k, False: 33.6k]
  ------------------
  573|  62.1k|        fi = f->v[i];
  574|  62.1k|        gi = g->v[i];
  575|  62.1k|        secp256k1_i128_accum_mul(&cf, u, fi);
  576|  62.1k|        secp256k1_i128_accum_mul(&cf, v, gi);
  577|  62.1k|        secp256k1_i128_accum_mul(&cg, q, fi);
  578|  62.1k|        secp256k1_i128_accum_mul(&cg, r, gi);
  579|  62.1k|        f->v[i - 1] = secp256k1_i128_to_u64(&cf) & M62; secp256k1_i128_rshift(&cf, 62);
  580|  62.1k|        g->v[i - 1] = secp256k1_i128_to_u64(&cg) & M62; secp256k1_i128_rshift(&cg, 62);
  581|  62.1k|    }
  582|       |    /* What remains is limb (len) of t*[f,g]; store it as output limb (len-1). */
  583|  33.6k|    f->v[len - 1] = secp256k1_i128_to_i64(&cf);
  584|  33.6k|    g->v[len - 1] = secp256k1_i128_to_i64(&cg);
  585|  33.6k|}
secp256k1.c:secp256k1_modinv64_normalize_62:
   88|  3.73k|static void secp256k1_modinv64_normalize_62(secp256k1_modinv64_signed62 *r, int64_t sign, const secp256k1_modinv64_modinfo *modinfo) {
   89|  3.73k|    const int64_t M62 = (int64_t)(UINT64_MAX >> 2);
   90|  3.73k|    int64_t r0 = r->v[0], r1 = r->v[1], r2 = r->v[2], r3 = r->v[3], r4 = r->v[4];
   91|  3.73k|    volatile int64_t cond_add, cond_negate;
   92|       |
   93|       |#ifdef VERIFY
   94|       |    /* Verify that all limbs are in range (-2^62,2^62). */
   95|       |    int i;
   96|       |    for (i = 0; i < 5; ++i) {
   97|       |        VERIFY_CHECK(r->v[i] >= -M62);
   98|       |        VERIFY_CHECK(r->v[i] <= M62);
   99|       |    }
  100|       |    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, -2) > 0); /* r > -2*modulus */
  101|       |    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, 1) < 0); /* r < modulus */
  102|       |#endif
  103|       |
  104|       |    /* In a first step, add the modulus if the input is negative, and then negate if requested.
  105|       |     * This brings r from range (-2*modulus,modulus) to range (-modulus,modulus). As all input
  106|       |     * limbs are in range (-2^62,2^62), this cannot overflow an int64_t. Note that the right
  107|       |     * shifts below are signed sign-extending shifts (see assumptions.h for tests that that is
  108|       |     * indeed the behavior of the right shift operator). */
  109|  3.73k|    cond_add = r4 >> 63;
  110|  3.73k|    r0 += modinfo->modulus.v[0] & cond_add;
  111|  3.73k|    r1 += modinfo->modulus.v[1] & cond_add;
  112|  3.73k|    r2 += modinfo->modulus.v[2] & cond_add;
  113|  3.73k|    r3 += modinfo->modulus.v[3] & cond_add;
  114|  3.73k|    r4 += modinfo->modulus.v[4] & cond_add;
  115|  3.73k|    cond_negate = sign >> 63;
  116|  3.73k|    r0 = (r0 ^ cond_negate) - cond_negate;
  117|  3.73k|    r1 = (r1 ^ cond_negate) - cond_negate;
  118|  3.73k|    r2 = (r2 ^ cond_negate) - cond_negate;
  119|  3.73k|    r3 = (r3 ^ cond_negate) - cond_negate;
  120|  3.73k|    r4 = (r4 ^ cond_negate) - cond_negate;
  121|       |    /* Propagate the top bits, to bring limbs back to range (-2^62,2^62). */
  122|  3.73k|    r1 += r0 >> 62; r0 &= M62;
  123|  3.73k|    r2 += r1 >> 62; r1 &= M62;
  124|  3.73k|    r3 += r2 >> 62; r2 &= M62;
  125|  3.73k|    r4 += r3 >> 62; r3 &= M62;
  126|       |
  127|       |    /* In a second step add the modulus again if the result is still negative, bringing
  128|       |     * r to range [0,modulus). */
  129|  3.73k|    cond_add = r4 >> 63;
  130|  3.73k|    r0 += modinfo->modulus.v[0] & cond_add;
  131|  3.73k|    r1 += modinfo->modulus.v[1] & cond_add;
  132|  3.73k|    r2 += modinfo->modulus.v[2] & cond_add;
  133|  3.73k|    r3 += modinfo->modulus.v[3] & cond_add;
  134|  3.73k|    r4 += modinfo->modulus.v[4] & cond_add;
  135|       |    /* And propagate again. */
  136|  3.73k|    r1 += r0 >> 62; r0 &= M62;
  137|  3.73k|    r2 += r1 >> 62; r1 &= M62;
  138|  3.73k|    r3 += r2 >> 62; r2 &= M62;
  139|  3.73k|    r4 += r3 >> 62; r3 &= M62;
  140|       |
  141|  3.73k|    r->v[0] = r0;
  142|  3.73k|    r->v[1] = r1;
  143|  3.73k|    r->v[2] = r2;
  144|  3.73k|    r->v[3] = r3;
  145|  3.73k|    r->v[4] = r4;
  146|       |
  147|  3.73k|    VERIFY_CHECK(r0 >> 62 == 0);
  148|  3.73k|    VERIFY_CHECK(r1 >> 62 == 0);
  149|  3.73k|    VERIFY_CHECK(r2 >> 62 == 0);
  150|  3.73k|    VERIFY_CHECK(r3 >> 62 == 0);
  151|  3.73k|    VERIFY_CHECK(r4 >> 62 == 0);
  152|  3.73k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, 0) >= 0); /* r >= 0 */
  153|  3.73k|    VERIFY_CHECK(secp256k1_modinv64_mul_cmp_62(r, 5, &modinfo->modulus, 1) < 0); /* r < modulus */
  154|  3.73k|}

secp256k1.c:secp256k1_scalar_set_b32:
  147|  19.8k|static void secp256k1_scalar_set_b32(secp256k1_scalar *r, const unsigned char *b32, int *overflow) {
  148|  19.8k|    int over;
  149|  19.8k|    r->d[0] = secp256k1_read_be64(&b32[24]);
  150|  19.8k|    r->d[1] = secp256k1_read_be64(&b32[16]);
  151|  19.8k|    r->d[2] = secp256k1_read_be64(&b32[8]);
  152|  19.8k|    r->d[3] = secp256k1_read_be64(&b32[0]);
  153|  19.8k|    over = secp256k1_scalar_reduce(r, secp256k1_scalar_check_overflow(r));
  154|  19.8k|    if (overflow) {
  ------------------
  |  Branch (154:9): [True: 15.9k, False: 3.95k]
  ------------------
  155|  15.9k|        *overflow = over;
  156|  15.9k|    }
  157|       |
  158|  19.8k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  19.8k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  159|  19.8k|}
secp256k1.c:secp256k1_scalar_reduce:
   76|  46.0k|SECP256K1_INLINE static int secp256k1_scalar_reduce(secp256k1_scalar *r, unsigned int overflow) {
   77|  46.0k|    secp256k1_uint128 t;
   78|  46.0k|    VERIFY_CHECK(overflow <= 1);
   79|       |
   80|  46.0k|    secp256k1_u128_from_u64(&t, r->d[0]);
   81|  46.0k|    secp256k1_u128_accum_u64(&t, overflow * SECP256K1_N_C_0);
  ------------------
  |  |   22|  46.0k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  46.0k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
   82|  46.0k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
   83|  46.0k|    secp256k1_u128_accum_u64(&t, r->d[1]);
   84|  46.0k|    secp256k1_u128_accum_u64(&t, overflow * SECP256K1_N_C_1);
  ------------------
  |  |   23|  46.0k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  46.0k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
   85|  46.0k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
   86|  46.0k|    secp256k1_u128_accum_u64(&t, r->d[2]);
   87|  46.0k|    secp256k1_u128_accum_u64(&t, overflow * SECP256K1_N_C_2);
  ------------------
  |  |   24|  46.0k|#define SECP256K1_N_C_2 (1)
  ------------------
   88|  46.0k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
   89|  46.0k|    secp256k1_u128_accum_u64(&t, r->d[3]);
   90|  46.0k|    r->d[3] = secp256k1_u128_to_u64(&t);
   91|       |
   92|  46.0k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  46.0k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   93|  46.0k|    return overflow;
   94|  46.0k|}
secp256k1.c:secp256k1_scalar_check_overflow:
   64|  46.0k|SECP256K1_INLINE static int secp256k1_scalar_check_overflow(const secp256k1_scalar *a) {
   65|  46.0k|    int yes = 0;
   66|  46.0k|    int no = 0;
   67|  46.0k|    no |= (a->d[3] < SECP256K1_N_3); /* No need for a > check. */
  ------------------
  |  |   19|  46.0k|#define SECP256K1_N_3 ((uint64_t)0xFFFFFFFFFFFFFFFFULL)
  ------------------
   68|  46.0k|    no |= (a->d[2] < SECP256K1_N_2);
  ------------------
  |  |   18|  46.0k|#define SECP256K1_N_2 ((uint64_t)0xFFFFFFFFFFFFFFFEULL)
  ------------------
   69|  46.0k|    yes |= (a->d[2] > SECP256K1_N_2) & ~no;
  ------------------
  |  |   18|  46.0k|#define SECP256K1_N_2 ((uint64_t)0xFFFFFFFFFFFFFFFEULL)
  ------------------
   70|  46.0k|    no |= (a->d[1] < SECP256K1_N_1);
  ------------------
  |  |   17|  46.0k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  ------------------
   71|  46.0k|    yes |= (a->d[1] > SECP256K1_N_1) & ~no;
  ------------------
  |  |   17|  46.0k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  ------------------
   72|  46.0k|    yes |= (a->d[0] >= SECP256K1_N_0) & ~no;
  ------------------
  |  |   16|  46.0k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  ------------------
   73|  46.0k|    return yes;
   74|  46.0k|}
secp256k1.c:secp256k1_scalar_get_b32:
  161|  3.73k|static void secp256k1_scalar_get_b32(unsigned char *bin, const secp256k1_scalar* a) {
  162|  3.73k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  163|       |
  164|  3.73k|    secp256k1_write_be64(&bin[0],  a->d[3]);
  165|  3.73k|    secp256k1_write_be64(&bin[8],  a->d[2]);
  166|  3.73k|    secp256k1_write_be64(&bin[16], a->d[1]);
  167|  3.73k|    secp256k1_write_be64(&bin[24], a->d[0]);
  168|  3.73k|}
secp256k1.c:secp256k1_scalar_is_high:
  244|  7.90k|static int secp256k1_scalar_is_high(const secp256k1_scalar *a) {
  245|  7.90k|    int yes = 0;
  246|  7.90k|    int no = 0;
  247|  7.90k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  7.90k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  248|       |
  249|  7.90k|    no |= (a->d[3] < SECP256K1_N_H_3);
  ------------------
  |  |   30|  7.90k|#define SECP256K1_N_H_3 ((uint64_t)0x7FFFFFFFFFFFFFFFULL)
  ------------------
  250|  7.90k|    yes |= (a->d[3] > SECP256K1_N_H_3) & ~no;
  ------------------
  |  |   30|  7.90k|#define SECP256K1_N_H_3 ((uint64_t)0x7FFFFFFFFFFFFFFFULL)
  ------------------
  251|  7.90k|    no |= (a->d[2] < SECP256K1_N_H_2) & ~yes; /* No need for a > check. */
  ------------------
  |  |   29|  7.90k|#define SECP256K1_N_H_2 ((uint64_t)0xFFFFFFFFFFFFFFFFULL)
  ------------------
  252|  7.90k|    no |= (a->d[1] < SECP256K1_N_H_1) & ~yes;
  ------------------
  |  |   28|  7.90k|#define SECP256K1_N_H_1 ((uint64_t)0x5D576E7357A4501DULL)
  ------------------
  253|  7.90k|    yes |= (a->d[1] > SECP256K1_N_H_1) & ~no;
  ------------------
  |  |   28|  7.90k|#define SECP256K1_N_H_1 ((uint64_t)0x5D576E7357A4501DULL)
  ------------------
  254|  7.90k|    yes |= (a->d[0] > SECP256K1_N_H_0) & ~no;
  ------------------
  |  |   27|  7.90k|#define SECP256K1_N_H_0 ((uint64_t)0xDFE92F46681B20A0ULL)
  ------------------
  255|  7.90k|    return yes;
  256|  7.90k|}
secp256k1.c:secp256k1_scalar_negate:
  176|  7.50k|static void secp256k1_scalar_negate(secp256k1_scalar *r, const secp256k1_scalar *a) {
  177|  7.50k|    uint64_t nonzero = 0xFFFFFFFFFFFFFFFFULL * (secp256k1_scalar_is_zero(a) == 0);
  178|  7.50k|    secp256k1_uint128 t;
  179|  7.50k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  7.50k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  180|       |
  181|  7.50k|    secp256k1_u128_from_u64(&t, ~a->d[0]);
  182|  7.50k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_0 + 1);
  ------------------
  |  |   16|  7.50k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  ------------------
  183|  7.50k|    r->d[0] = secp256k1_u128_to_u64(&t) & nonzero; secp256k1_u128_rshift(&t, 64);
  184|  7.50k|    secp256k1_u128_accum_u64(&t, ~a->d[1]);
  185|  7.50k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_1);
  ------------------
  |  |   17|  7.50k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  ------------------
  186|  7.50k|    r->d[1] = secp256k1_u128_to_u64(&t) & nonzero; secp256k1_u128_rshift(&t, 64);
  187|  7.50k|    secp256k1_u128_accum_u64(&t, ~a->d[2]);
  188|  7.50k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_2);
  ------------------
  |  |   18|  7.50k|#define SECP256K1_N_2 ((uint64_t)0xFFFFFFFFFFFFFFFEULL)
  ------------------
  189|  7.50k|    r->d[2] = secp256k1_u128_to_u64(&t) & nonzero; secp256k1_u128_rshift(&t, 64);
  190|  7.50k|    secp256k1_u128_accum_u64(&t, ~a->d[3]);
  191|  7.50k|    secp256k1_u128_accum_u64(&t, SECP256K1_N_3);
  ------------------
  |  |   19|  7.50k|#define SECP256K1_N_3 ((uint64_t)0xFFFFFFFFFFFFFFFFULL)
  ------------------
  192|  7.50k|    r->d[3] = secp256k1_u128_to_u64(&t) & nonzero;
  193|       |
  194|  7.50k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  7.50k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  195|  7.50k|}
secp256k1.c:secp256k1_scalar_inverse_var:
  984|  3.73k|static void secp256k1_scalar_inverse_var(secp256k1_scalar *r, const secp256k1_scalar *x) {
  985|  3.73k|    secp256k1_modinv64_signed62 s;
  986|       |#ifdef VERIFY
  987|       |    int zero_in = secp256k1_scalar_is_zero(x);
  988|       |#endif
  989|  3.73k|    SECP256K1_SCALAR_VERIFY(x);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  990|       |
  991|  3.73k|    secp256k1_scalar_to_signed62(&s, x);
  992|  3.73k|    secp256k1_modinv64_var(&s, &secp256k1_const_modinfo_scalar);
  993|  3.73k|    secp256k1_scalar_from_signed62(r, &s);
  994|       |
  995|  3.73k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  996|  3.73k|    VERIFY_CHECK(secp256k1_scalar_is_zero(r) == zero_in);
  997|  3.73k|}
secp256k1.c:secp256k1_scalar_to_signed62:
  952|  3.73k|static void secp256k1_scalar_to_signed62(secp256k1_modinv64_signed62 *r, const secp256k1_scalar *a) {
  953|  3.73k|    const uint64_t M62 = UINT64_MAX >> 2;
  954|  3.73k|    const uint64_t a0 = a->d[0], a1 = a->d[1], a2 = a->d[2], a3 = a->d[3];
  955|  3.73k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  956|       |
  957|  3.73k|    r->v[0] =  a0                   & M62;
  958|  3.73k|    r->v[1] = (a0 >> 62 | a1 <<  2) & M62;
  959|  3.73k|    r->v[2] = (a1 >> 60 | a2 <<  4) & M62;
  960|  3.73k|    r->v[3] = (a2 >> 58 | a3 <<  6) & M62;
  961|  3.73k|    r->v[4] =  a3 >> 56;
  962|  3.73k|}
secp256k1.c:secp256k1_scalar_from_signed62:
  932|  3.73k|static void secp256k1_scalar_from_signed62(secp256k1_scalar *r, const secp256k1_modinv64_signed62 *a) {
  933|  3.73k|    const uint64_t a0 = a->v[0], a1 = a->v[1], a2 = a->v[2], a3 = a->v[3], a4 = a->v[4];
  934|       |
  935|       |    /* The output from secp256k1_modinv64{_var} should be normalized to range [0,modulus), and
  936|       |     * have limbs in [0,2^62). The modulus is < 2^256, so the top limb must be below 2^(256-62*4).
  937|       |     */
  938|  3.73k|    VERIFY_CHECK(a0 >> 62 == 0);
  939|  3.73k|    VERIFY_CHECK(a1 >> 62 == 0);
  940|  3.73k|    VERIFY_CHECK(a2 >> 62 == 0);
  941|  3.73k|    VERIFY_CHECK(a3 >> 62 == 0);
  942|  3.73k|    VERIFY_CHECK(a4 >> 8 == 0);
  943|       |
  944|  3.73k|    r->d[0] = a0      | a1 << 62;
  945|  3.73k|    r->d[1] = a1 >> 2 | a2 << 60;
  946|  3.73k|    r->d[2] = a2 >> 4 | a3 << 58;
  947|  3.73k|    r->d[3] = a3 >> 6 | a4 << 56;
  948|       |
  949|  3.73k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  950|  3.73k|}
secp256k1.c:secp256k1_scalar_mul_shift_var:
  893|  7.46k|SECP256K1_INLINE static void secp256k1_scalar_mul_shift_var(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b, unsigned int shift) {
  894|  7.46k|    uint64_t l[8];
  895|  7.46k|    unsigned int shiftlimbs;
  896|  7.46k|    unsigned int shiftlow;
  897|  7.46k|    unsigned int shifthigh;
  898|  7.46k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  899|  7.46k|    SECP256K1_SCALAR_VERIFY(b);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  900|  7.46k|    VERIFY_CHECK(shift >= 256);
  901|       |
  902|  7.46k|    secp256k1_scalar_mul_512(l, a, b);
  903|  7.46k|    shiftlimbs = shift >> 6;
  904|  7.46k|    shiftlow = shift & 0x3F;
  905|  7.46k|    shifthigh = 64 - shiftlow;
  906|  7.46k|    r->d[0] = shift < 512 ? (l[0 + shiftlimbs] >> shiftlow | (shift < 448 && shiftlow ? (l[1 + shiftlimbs] << shifthigh) : 0)) : 0;
  ------------------
  |  Branch (906:15): [True: 7.46k, False: 0]
  |  Branch (906:63): [True: 7.46k, False: 0]
  |  Branch (906:78): [True: 0, False: 7.46k]
  ------------------
  907|  7.46k|    r->d[1] = shift < 448 ? (l[1 + shiftlimbs] >> shiftlow | (shift < 384 && shiftlow ? (l[2 + shiftlimbs] << shifthigh) : 0)) : 0;
  ------------------
  |  Branch (907:15): [True: 7.46k, False: 0]
  |  Branch (907:63): [True: 0, False: 7.46k]
  |  Branch (907:78): [True: 0, False: 0]
  ------------------
  908|  7.46k|    r->d[2] = shift < 384 ? (l[2 + shiftlimbs] >> shiftlow | (shift < 320 && shiftlow ? (l[3 + shiftlimbs] << shifthigh) : 0)) : 0;
  ------------------
  |  Branch (908:15): [True: 0, False: 7.46k]
  |  Branch (908:63): [True: 0, False: 0]
  |  Branch (908:78): [True: 0, False: 0]
  ------------------
  909|  7.46k|    r->d[3] = shift < 320 ? (l[3 + shiftlimbs] >> shiftlow) : 0;
  ------------------
  |  Branch (909:15): [True: 0, False: 7.46k]
  ------------------
  910|  7.46k|    secp256k1_scalar_cadd_bit(r, 0, (l[(shift - 1) >> 6] >> ((shift - 1) & 0x3f)) & 1);
  911|       |
  912|  7.46k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  913|  7.46k|}
secp256k1.c:secp256k1_scalar_mul_512:
  682|  26.1k|static void secp256k1_scalar_mul_512(uint64_t *l8, const secp256k1_scalar *a, const secp256k1_scalar *b) {
  683|  26.1k|#ifdef USE_ASM_X86_64
  684|  26.1k|    const uint64_t *pb = b->d;
  685|  26.1k|    __asm__ __volatile__(
  686|       |    /* Preload */
  687|  26.1k|    "movq 0(%%rdi), %%r15\n"
  688|  26.1k|    "movq 8(%%rdi), %%rbx\n"
  689|  26.1k|    "movq 16(%%rdi), %%rcx\n"
  690|  26.1k|    "movq 0(%%rdx), %%r11\n"
  691|  26.1k|    "movq 8(%%rdx), %%r12\n"
  692|  26.1k|    "movq 16(%%rdx), %%r13\n"
  693|  26.1k|    "movq 24(%%rdx), %%r14\n"
  694|       |    /* (rax,rdx) = a0 * b0 */
  695|  26.1k|    "movq %%r15, %%rax\n"
  696|  26.1k|    "mulq %%r11\n"
  697|       |    /* Extract l8[0] */
  698|  26.1k|    "movq %%rax, 0(%%rsi)\n"
  699|       |    /* (r8,r9,r10) = (rdx) */
  700|  26.1k|    "movq %%rdx, %%r8\n"
  701|  26.1k|    "xorq %%r9, %%r9\n"
  702|  26.1k|    "xorq %%r10, %%r10\n"
  703|       |    /* (r8,r9,r10) += a0 * b1 */
  704|  26.1k|    "movq %%r15, %%rax\n"
  705|  26.1k|    "mulq %%r12\n"
  706|  26.1k|    "addq %%rax, %%r8\n"
  707|  26.1k|    "adcq %%rdx, %%r9\n"
  708|  26.1k|    "adcq $0, %%r10\n"
  709|       |    /* (r8,r9,r10) += a1 * b0 */
  710|  26.1k|    "movq %%rbx, %%rax\n"
  711|  26.1k|    "mulq %%r11\n"
  712|  26.1k|    "addq %%rax, %%r8\n"
  713|  26.1k|    "adcq %%rdx, %%r9\n"
  714|  26.1k|    "adcq $0, %%r10\n"
  715|       |    /* Extract l8[1] */
  716|  26.1k|    "movq %%r8, 8(%%rsi)\n"
  717|  26.1k|    "xorq %%r8, %%r8\n"
  718|       |    /* (r9,r10,r8) += a0 * b2 */
  719|  26.1k|    "movq %%r15, %%rax\n"
  720|  26.1k|    "mulq %%r13\n"
  721|  26.1k|    "addq %%rax, %%r9\n"
  722|  26.1k|    "adcq %%rdx, %%r10\n"
  723|  26.1k|    "adcq $0, %%r8\n"
  724|       |    /* (r9,r10,r8) += a1 * b1 */
  725|  26.1k|    "movq %%rbx, %%rax\n"
  726|  26.1k|    "mulq %%r12\n"
  727|  26.1k|    "addq %%rax, %%r9\n"
  728|  26.1k|    "adcq %%rdx, %%r10\n"
  729|  26.1k|    "adcq $0, %%r8\n"
  730|       |    /* (r9,r10,r8) += a2 * b0 */
  731|  26.1k|    "movq %%rcx, %%rax\n"
  732|  26.1k|    "mulq %%r11\n"
  733|  26.1k|    "addq %%rax, %%r9\n"
  734|  26.1k|    "adcq %%rdx, %%r10\n"
  735|  26.1k|    "adcq $0, %%r8\n"
  736|       |    /* Extract l8[2] */
  737|  26.1k|    "movq %%r9, 16(%%rsi)\n"
  738|  26.1k|    "xorq %%r9, %%r9\n"
  739|       |    /* (r10,r8,r9) += a0 * b3 */
  740|  26.1k|    "movq %%r15, %%rax\n"
  741|  26.1k|    "mulq %%r14\n"
  742|  26.1k|    "addq %%rax, %%r10\n"
  743|  26.1k|    "adcq %%rdx, %%r8\n"
  744|  26.1k|    "adcq $0, %%r9\n"
  745|       |    /* Preload a3 */
  746|  26.1k|    "movq 24(%%rdi), %%r15\n"
  747|       |    /* (r10,r8,r9) += a1 * b2 */
  748|  26.1k|    "movq %%rbx, %%rax\n"
  749|  26.1k|    "mulq %%r13\n"
  750|  26.1k|    "addq %%rax, %%r10\n"
  751|  26.1k|    "adcq %%rdx, %%r8\n"
  752|  26.1k|    "adcq $0, %%r9\n"
  753|       |    /* (r10,r8,r9) += a2 * b1 */
  754|  26.1k|    "movq %%rcx, %%rax\n"
  755|  26.1k|    "mulq %%r12\n"
  756|  26.1k|    "addq %%rax, %%r10\n"
  757|  26.1k|    "adcq %%rdx, %%r8\n"
  758|  26.1k|    "adcq $0, %%r9\n"
  759|       |    /* (r10,r8,r9) += a3 * b0 */
  760|  26.1k|    "movq %%r15, %%rax\n"
  761|  26.1k|    "mulq %%r11\n"
  762|  26.1k|    "addq %%rax, %%r10\n"
  763|  26.1k|    "adcq %%rdx, %%r8\n"
  764|  26.1k|    "adcq $0, %%r9\n"
  765|       |    /* Extract l8[3] */
  766|  26.1k|    "movq %%r10, 24(%%rsi)\n"
  767|  26.1k|    "xorq %%r10, %%r10\n"
  768|       |    /* (r8,r9,r10) += a1 * b3 */
  769|  26.1k|    "movq %%rbx, %%rax\n"
  770|  26.1k|    "mulq %%r14\n"
  771|  26.1k|    "addq %%rax, %%r8\n"
  772|  26.1k|    "adcq %%rdx, %%r9\n"
  773|  26.1k|    "adcq $0, %%r10\n"
  774|       |    /* (r8,r9,r10) += a2 * b2 */
  775|  26.1k|    "movq %%rcx, %%rax\n"
  776|  26.1k|    "mulq %%r13\n"
  777|  26.1k|    "addq %%rax, %%r8\n"
  778|  26.1k|    "adcq %%rdx, %%r9\n"
  779|  26.1k|    "adcq $0, %%r10\n"
  780|       |    /* (r8,r9,r10) += a3 * b1 */
  781|  26.1k|    "movq %%r15, %%rax\n"
  782|  26.1k|    "mulq %%r12\n"
  783|  26.1k|    "addq %%rax, %%r8\n"
  784|  26.1k|    "adcq %%rdx, %%r9\n"
  785|  26.1k|    "adcq $0, %%r10\n"
  786|       |    /* Extract l8[4] */
  787|  26.1k|    "movq %%r8, 32(%%rsi)\n"
  788|  26.1k|    "xorq %%r8, %%r8\n"
  789|       |    /* (r9,r10,r8) += a2 * b3 */
  790|  26.1k|    "movq %%rcx, %%rax\n"
  791|  26.1k|    "mulq %%r14\n"
  792|  26.1k|    "addq %%rax, %%r9\n"
  793|  26.1k|    "adcq %%rdx, %%r10\n"
  794|  26.1k|    "adcq $0, %%r8\n"
  795|       |    /* (r9,r10,r8) += a3 * b2 */
  796|  26.1k|    "movq %%r15, %%rax\n"
  797|  26.1k|    "mulq %%r13\n"
  798|  26.1k|    "addq %%rax, %%r9\n"
  799|  26.1k|    "adcq %%rdx, %%r10\n"
  800|  26.1k|    "adcq $0, %%r8\n"
  801|       |    /* Extract l8[5] */
  802|  26.1k|    "movq %%r9, 40(%%rsi)\n"
  803|       |    /* (r10,r8) += a3 * b3 */
  804|  26.1k|    "movq %%r15, %%rax\n"
  805|  26.1k|    "mulq %%r14\n"
  806|  26.1k|    "addq %%rax, %%r10\n"
  807|  26.1k|    "adcq %%rdx, %%r8\n"
  808|       |    /* Extract l8[6] */
  809|  26.1k|    "movq %%r10, 48(%%rsi)\n"
  810|       |    /* Extract l8[7] */
  811|  26.1k|    "movq %%r8, 56(%%rsi)\n"
  812|  26.1k|    : "+d"(pb)
  813|  26.1k|    : "S"(l8), "D"(a->d)
  814|  26.1k|    : "rax", "rbx", "rcx", "r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15", "cc", "memory");
  815|       |
  816|  26.1k|    SECP256K1_CHECKMEM_MSAN_DEFINE(l8, sizeof(*l8) * 8);
  ------------------
  |  |   70|  26.1k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  26.1k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 26.1k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  817|       |
  818|       |#else
  819|       |    /* 160 bit accumulator. */
  820|       |    uint64_t c0 = 0, c1 = 0;
  821|       |    uint32_t c2 = 0;
  822|       |
  823|       |    /* l8[0..7] = a[0..3] * b[0..3]. */
  824|       |    muladd_fast(a->d[0], b->d[0]);
  825|       |    extract_fast(l8[0]);
  826|       |    muladd(a->d[0], b->d[1]);
  827|       |    muladd(a->d[1], b->d[0]);
  828|       |    extract(l8[1]);
  829|       |    muladd(a->d[0], b->d[2]);
  830|       |    muladd(a->d[1], b->d[1]);
  831|       |    muladd(a->d[2], b->d[0]);
  832|       |    extract(l8[2]);
  833|       |    muladd(a->d[0], b->d[3]);
  834|       |    muladd(a->d[1], b->d[2]);
  835|       |    muladd(a->d[2], b->d[1]);
  836|       |    muladd(a->d[3], b->d[0]);
  837|       |    extract(l8[3]);
  838|       |    muladd(a->d[1], b->d[3]);
  839|       |    muladd(a->d[2], b->d[2]);
  840|       |    muladd(a->d[3], b->d[1]);
  841|       |    extract(l8[4]);
  842|       |    muladd(a->d[2], b->d[3]);
  843|       |    muladd(a->d[3], b->d[2]);
  844|       |    extract(l8[5]);
  845|       |    muladd_fast(a->d[3], b->d[3]);
  846|       |    extract_fast(l8[6]);
  847|       |    VERIFY_CHECK(c1 == 0);
  848|       |    l8[7] = c0;
  849|       |#endif
  850|  26.1k|}
secp256k1.c:secp256k1_scalar_cadd_bit:
  122|  7.46k|static void secp256k1_scalar_cadd_bit(secp256k1_scalar *r, unsigned int bit, int flag) {
  123|  7.46k|    secp256k1_uint128 t;
  124|  7.46k|    volatile int vflag = flag;
  125|  7.46k|    VERIFY_CHECK(flag == 0 || flag == 1);
  126|  7.46k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  127|  7.46k|    VERIFY_CHECK(bit < 256);
  128|       |
  129|  7.46k|    bit += ((uint32_t) vflag - 1) & 0x100;  /* forcing (bit >> 6) > 3 makes this a noop */
  130|  7.46k|    secp256k1_u128_from_u64(&t, r->d[0]);
  131|  7.46k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 0)) << (bit & 0x3F));
  132|  7.46k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  133|  7.46k|    secp256k1_u128_accum_u64(&t, r->d[1]);
  134|  7.46k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 1)) << (bit & 0x3F));
  135|  7.46k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  136|  7.46k|    secp256k1_u128_accum_u64(&t, r->d[2]);
  137|  7.46k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 2)) << (bit & 0x3F));
  138|  7.46k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  139|  7.46k|    secp256k1_u128_accum_u64(&t, r->d[3]);
  140|  7.46k|    secp256k1_u128_accum_u64(&t, ((uint64_t)((bit >> 6) == 3)) << (bit & 0x3F));
  141|  7.46k|    r->d[3] = secp256k1_u128_to_u64(&t);
  142|       |
  143|  7.46k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  144|  7.46k|    VERIFY_CHECK(secp256k1_u128_hi_u64(&t) == 0);
  145|  7.46k|}
secp256k1.c:secp256k1_scalar_split_128:
  870|  3.73k|static void secp256k1_scalar_split_128(secp256k1_scalar *r1, secp256k1_scalar *r2, const secp256k1_scalar *k) {
  871|  3.73k|    SECP256K1_SCALAR_VERIFY(k);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  872|       |
  873|  3.73k|    r1->d[0] = k->d[0];
  874|  3.73k|    r1->d[1] = k->d[1];
  875|  3.73k|    r1->d[2] = 0;
  876|  3.73k|    r1->d[3] = 0;
  877|  3.73k|    r2->d[0] = k->d[2];
  878|  3.73k|    r2->d[1] = k->d[3];
  879|  3.73k|    r2->d[2] = 0;
  880|  3.73k|    r2->d[3] = 0;
  881|       |
  882|  3.73k|    SECP256K1_SCALAR_VERIFY(r1);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  883|  3.73k|    SECP256K1_SCALAR_VERIFY(r2);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  884|  3.73k|}
secp256k1.c:secp256k1_scalar_get_bits_limb32:
   41|   481k|SECP256K1_INLINE static uint32_t secp256k1_scalar_get_bits_limb32(const secp256k1_scalar *a, unsigned int offset, unsigned int count) {
   42|   481k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|   481k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   43|   481k|    VERIFY_CHECK(count > 0 && count <= 32);
   44|   481k|    VERIFY_CHECK(offset <= 256 - count);
   45|   481k|    VERIFY_CHECK((offset + count - 1) >> 5 == offset >> 5);
   46|       |
   47|   481k|    return (a->d[offset >> 6] >> (offset & 0x3F)) & (0xFFFFFFFF >> (32 - count));
   48|   481k|}
secp256k1.c:secp256k1_scalar_get_bits_var:
   50|   221k|SECP256K1_INLINE static uint32_t secp256k1_scalar_get_bits_var(const secp256k1_scalar *a, unsigned int offset, unsigned int count) {
   51|   221k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|   221k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
   52|   221k|    VERIFY_CHECK(count > 0 && count <= 32);
   53|   221k|    VERIFY_CHECK(offset <= 256 - count);
   54|       |
   55|   221k|    if ((offset + count - 1) >> 6 == offset >> 6) {
  ------------------
  |  Branch (55:9): [True: 200k, False: 20.2k]
  ------------------
   56|   200k|        return (a->d[offset >> 6] >> (offset & 0x3F)) & (0xFFFFFFFF >> (32 - count));
   57|   200k|    } else {
   58|  20.2k|        VERIFY_CHECK((offset >> 6) + 1 < 4);
   59|  20.2k|        VERIFY_CHECK((offset & 0x3F) > 0);
   60|  20.2k|        return ((a->d[offset >> 6] >> (offset & 0x3F)) | (a->d[(offset >> 6) + 1] << (64 - (offset & 0x3F)))) & (0xFFFFFFFF >> (32 - count));
   61|  20.2k|    }
   62|   221k|}
secp256k1.c:secp256k1_scalar_is_zero:
  170|  18.9k|SECP256K1_INLINE static int secp256k1_scalar_is_zero(const secp256k1_scalar *a) {
  171|  18.9k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  18.9k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  172|       |
  173|  18.9k|    return (a->d[0] | a->d[1] | a->d[2] | a->d[3]) == 0;
  174|  18.9k|}
secp256k1.c:secp256k1_scalar_mul:
  859|  18.6k|static void secp256k1_scalar_mul(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b) {
  860|  18.6k|    uint64_t l[8];
  861|  18.6k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  18.6k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  862|  18.6k|    SECP256K1_SCALAR_VERIFY(b);
  ------------------
  |  |  103|  18.6k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  863|       |
  864|  18.6k|    secp256k1_scalar_mul_512(l, a, b);
  865|  18.6k|    secp256k1_scalar_reduce_512(r, l);
  866|       |
  867|  18.6k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  18.6k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  868|  18.6k|}
secp256k1.c:secp256k1_scalar_reduce_512:
  351|  18.6k|static void secp256k1_scalar_reduce_512(secp256k1_scalar *r, const uint64_t *l) {
  352|  18.6k|#ifdef USE_ASM_X86_64
  353|       |    /* Reduce 512 bits into 385. */
  354|  18.6k|    uint64_t m0, m1, m2, m3, m4, m5, m6;
  355|  18.6k|    uint64_t p0, p1, p2, p3, p4;
  356|  18.6k|    uint64_t c;
  357|       |
  358|  18.6k|    __asm__ __volatile__(
  359|       |    /* Preload. */
  360|  18.6k|    "movq 32(%%rsi), %%r11\n"
  361|  18.6k|    "movq 40(%%rsi), %%r12\n"
  362|  18.6k|    "movq 48(%%rsi), %%r13\n"
  363|  18.6k|    "movq 56(%%rsi), %%r14\n"
  364|       |    /* Initialize r8,r9,r10 */
  365|  18.6k|    "movq 0(%%rsi), %%r8\n"
  366|  18.6k|    "xorq %%r9, %%r9\n"
  367|  18.6k|    "xorq %%r10, %%r10\n"
  368|       |    /* (r8,r9) += n0 * c0 */
  369|  18.6k|    "movq %8, %%rax\n"
  370|  18.6k|    "mulq %%r11\n"
  371|  18.6k|    "addq %%rax, %%r8\n"
  372|  18.6k|    "adcq %%rdx, %%r9\n"
  373|       |    /* extract m0 */
  374|  18.6k|    "movq %%r8, %q0\n"
  375|  18.6k|    "xorq %%r8, %%r8\n"
  376|       |    /* (r9,r10) += l1 */
  377|  18.6k|    "addq 8(%%rsi), %%r9\n"
  378|  18.6k|    "adcq $0, %%r10\n"
  379|       |    /* (r9,r10,r8) += n1 * c0 */
  380|  18.6k|    "movq %8, %%rax\n"
  381|  18.6k|    "mulq %%r12\n"
  382|  18.6k|    "addq %%rax, %%r9\n"
  383|  18.6k|    "adcq %%rdx, %%r10\n"
  384|  18.6k|    "adcq $0, %%r8\n"
  385|       |    /* (r9,r10,r8) += n0 * c1 */
  386|  18.6k|    "movq %9, %%rax\n"
  387|  18.6k|    "mulq %%r11\n"
  388|  18.6k|    "addq %%rax, %%r9\n"
  389|  18.6k|    "adcq %%rdx, %%r10\n"
  390|  18.6k|    "adcq $0, %%r8\n"
  391|       |    /* extract m1 */
  392|  18.6k|    "movq %%r9, %q1\n"
  393|  18.6k|    "xorq %%r9, %%r9\n"
  394|       |    /* (r10,r8,r9) += l2 */
  395|  18.6k|    "addq 16(%%rsi), %%r10\n"
  396|  18.6k|    "adcq $0, %%r8\n"
  397|  18.6k|    "adcq $0, %%r9\n"
  398|       |    /* (r10,r8,r9) += n2 * c0 */
  399|  18.6k|    "movq %8, %%rax\n"
  400|  18.6k|    "mulq %%r13\n"
  401|  18.6k|    "addq %%rax, %%r10\n"
  402|  18.6k|    "adcq %%rdx, %%r8\n"
  403|  18.6k|    "adcq $0, %%r9\n"
  404|       |    /* (r10,r8,r9) += n1 * c1 */
  405|  18.6k|    "movq %9, %%rax\n"
  406|  18.6k|    "mulq %%r12\n"
  407|  18.6k|    "addq %%rax, %%r10\n"
  408|  18.6k|    "adcq %%rdx, %%r8\n"
  409|  18.6k|    "adcq $0, %%r9\n"
  410|       |    /* (r10,r8,r9) += n0 */
  411|  18.6k|    "addq %%r11, %%r10\n"
  412|  18.6k|    "adcq $0, %%r8\n"
  413|  18.6k|    "adcq $0, %%r9\n"
  414|       |    /* extract m2 */
  415|  18.6k|    "movq %%r10, %q2\n"
  416|  18.6k|    "xorq %%r10, %%r10\n"
  417|       |    /* (r8,r9,r10) += l3 */
  418|  18.6k|    "addq 24(%%rsi), %%r8\n"
  419|  18.6k|    "adcq $0, %%r9\n"
  420|  18.6k|    "adcq $0, %%r10\n"
  421|       |    /* (r8,r9,r10) += n3 * c0 */
  422|  18.6k|    "movq %8, %%rax\n"
  423|  18.6k|    "mulq %%r14\n"
  424|  18.6k|    "addq %%rax, %%r8\n"
  425|  18.6k|    "adcq %%rdx, %%r9\n"
  426|  18.6k|    "adcq $0, %%r10\n"
  427|       |    /* (r8,r9,r10) += n2 * c1 */
  428|  18.6k|    "movq %9, %%rax\n"
  429|  18.6k|    "mulq %%r13\n"
  430|  18.6k|    "addq %%rax, %%r8\n"
  431|  18.6k|    "adcq %%rdx, %%r9\n"
  432|  18.6k|    "adcq $0, %%r10\n"
  433|       |    /* (r8,r9,r10) += n1 */
  434|  18.6k|    "addq %%r12, %%r8\n"
  435|  18.6k|    "adcq $0, %%r9\n"
  436|  18.6k|    "adcq $0, %%r10\n"
  437|       |    /* extract m3 */
  438|  18.6k|    "movq %%r8, %q3\n"
  439|  18.6k|    "xorq %%r8, %%r8\n"
  440|       |    /* (r9,r10,r8) += n3 * c1 */
  441|  18.6k|    "movq %9, %%rax\n"
  442|  18.6k|    "mulq %%r14\n"
  443|  18.6k|    "addq %%rax, %%r9\n"
  444|  18.6k|    "adcq %%rdx, %%r10\n"
  445|  18.6k|    "adcq $0, %%r8\n"
  446|       |    /* (r9,r10,r8) += n2 */
  447|  18.6k|    "addq %%r13, %%r9\n"
  448|  18.6k|    "adcq $0, %%r10\n"
  449|  18.6k|    "adcq $0, %%r8\n"
  450|       |    /* extract m4 */
  451|  18.6k|    "movq %%r9, %q4\n"
  452|       |    /* (r10,r8) += n3 */
  453|  18.6k|    "addq %%r14, %%r10\n"
  454|  18.6k|    "adcq $0, %%r8\n"
  455|       |    /* extract m5 */
  456|  18.6k|    "movq %%r10, %q5\n"
  457|       |    /* extract m6 */
  458|  18.6k|    "movq %%r8, %q6\n"
  459|  18.6k|    : "=&g"(m0), "=&g"(m1), "=&g"(m2), "=g"(m3), "=g"(m4), "=g"(m5), "=g"(m6)
  460|  18.6k|    : "S"(l), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   22|  18.6k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  18.6k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
                  : "S"(l), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   23|  18.6k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  18.6k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
  461|  18.6k|    : "rax", "rdx", "r8", "r9", "r10", "r11", "r12", "r13", "r14", "cc");
  462|       |
  463|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m0, sizeof(m0));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  464|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m1, sizeof(m1));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  465|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m2, sizeof(m2));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  466|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m3, sizeof(m3));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  467|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m4, sizeof(m4));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  468|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m5, sizeof(m5));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  469|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&m6, sizeof(m6));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  470|       |
  471|       |    /* Reduce 385 bits into 258. */
  472|  18.6k|    __asm__ __volatile__(
  473|       |    /* Preload */
  474|  18.6k|    "movq %q9, %%r11\n"
  475|  18.6k|    "movq %q10, %%r12\n"
  476|  18.6k|    "movq %q11, %%r13\n"
  477|       |    /* Initialize (r8,r9,r10) */
  478|  18.6k|    "movq %q5, %%r8\n"
  479|  18.6k|    "xorq %%r9, %%r9\n"
  480|  18.6k|    "xorq %%r10, %%r10\n"
  481|       |    /* (r8,r9) += m4 * c0 */
  482|  18.6k|    "movq %12, %%rax\n"
  483|  18.6k|    "mulq %%r11\n"
  484|  18.6k|    "addq %%rax, %%r8\n"
  485|  18.6k|    "adcq %%rdx, %%r9\n"
  486|       |    /* extract p0 */
  487|  18.6k|    "movq %%r8, %q0\n"
  488|  18.6k|    "xorq %%r8, %%r8\n"
  489|       |    /* (r9,r10) += m1 */
  490|  18.6k|    "addq %q6, %%r9\n"
  491|  18.6k|    "adcq $0, %%r10\n"
  492|       |    /* (r9,r10,r8) += m5 * c0 */
  493|  18.6k|    "movq %12, %%rax\n"
  494|  18.6k|    "mulq %%r12\n"
  495|  18.6k|    "addq %%rax, %%r9\n"
  496|  18.6k|    "adcq %%rdx, %%r10\n"
  497|  18.6k|    "adcq $0, %%r8\n"
  498|       |    /* (r9,r10,r8) += m4 * c1 */
  499|  18.6k|    "movq %13, %%rax\n"
  500|  18.6k|    "mulq %%r11\n"
  501|  18.6k|    "addq %%rax, %%r9\n"
  502|  18.6k|    "adcq %%rdx, %%r10\n"
  503|  18.6k|    "adcq $0, %%r8\n"
  504|       |    /* extract p1 */
  505|  18.6k|    "movq %%r9, %q1\n"
  506|  18.6k|    "xorq %%r9, %%r9\n"
  507|       |    /* (r10,r8,r9) += m2 */
  508|  18.6k|    "addq %q7, %%r10\n"
  509|  18.6k|    "adcq $0, %%r8\n"
  510|  18.6k|    "adcq $0, %%r9\n"
  511|       |    /* (r10,r8,r9) += m6 * c0 */
  512|  18.6k|    "movq %12, %%rax\n"
  513|  18.6k|    "mulq %%r13\n"
  514|  18.6k|    "addq %%rax, %%r10\n"
  515|  18.6k|    "adcq %%rdx, %%r8\n"
  516|  18.6k|    "adcq $0, %%r9\n"
  517|       |    /* (r10,r8,r9) += m5 * c1 */
  518|  18.6k|    "movq %13, %%rax\n"
  519|  18.6k|    "mulq %%r12\n"
  520|  18.6k|    "addq %%rax, %%r10\n"
  521|  18.6k|    "adcq %%rdx, %%r8\n"
  522|  18.6k|    "adcq $0, %%r9\n"
  523|       |    /* (r10,r8,r9) += m4 */
  524|  18.6k|    "addq %%r11, %%r10\n"
  525|  18.6k|    "adcq $0, %%r8\n"
  526|  18.6k|    "adcq $0, %%r9\n"
  527|       |    /* extract p2 */
  528|  18.6k|    "movq %%r10, %q2\n"
  529|       |    /* (r8,r9) += m3 */
  530|  18.6k|    "addq %q8, %%r8\n"
  531|  18.6k|    "adcq $0, %%r9\n"
  532|       |    /* (r8,r9) += m6 * c1 */
  533|  18.6k|    "movq %13, %%rax\n"
  534|  18.6k|    "mulq %%r13\n"
  535|  18.6k|    "addq %%rax, %%r8\n"
  536|  18.6k|    "adcq %%rdx, %%r9\n"
  537|       |    /* (r8,r9) += m5 */
  538|  18.6k|    "addq %%r12, %%r8\n"
  539|  18.6k|    "adcq $0, %%r9\n"
  540|       |    /* extract p3 */
  541|  18.6k|    "movq %%r8, %q3\n"
  542|       |    /* (r9) += m6 */
  543|  18.6k|    "addq %%r13, %%r9\n"
  544|       |    /* extract p4 */
  545|  18.6k|    "movq %%r9, %q4\n"
  546|  18.6k|    : "=&g"(p0), "=&g"(p1), "=&g"(p2), "=g"(p3), "=g"(p4)
  547|  18.6k|    : "g"(m0), "g"(m1), "g"(m2), "g"(m3), "g"(m4), "g"(m5), "g"(m6), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   22|  18.6k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  18.6k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
                  : "g"(m0), "g"(m1), "g"(m2), "g"(m3), "g"(m4), "g"(m5), "g"(m6), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   23|  18.6k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  18.6k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
  548|  18.6k|    : "rax", "rdx", "r8", "r9", "r10", "r11", "r12", "r13", "cc");
  549|       |
  550|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p0, sizeof(p0));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  551|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p1, sizeof(p1));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  552|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p2, sizeof(p2));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  553|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p3, sizeof(p3));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  554|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&p4, sizeof(p4));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  555|       |
  556|       |    /* Reduce 258 bits into 256. */
  557|  18.6k|    __asm__ __volatile__(
  558|       |    /* Preload */
  559|  18.6k|    "movq %q5, %%r10\n"
  560|       |    /* (rax,rdx) = p4 * c0 */
  561|  18.6k|    "movq %7, %%rax\n"
  562|  18.6k|    "mulq %%r10\n"
  563|       |    /* (rax,rdx) += p0 */
  564|  18.6k|    "addq %q1, %%rax\n"
  565|  18.6k|    "adcq $0, %%rdx\n"
  566|       |    /* extract r0 */
  567|  18.6k|    "movq %%rax, 0(%q6)\n"
  568|       |    /* Move to (r8,r9) */
  569|  18.6k|    "movq %%rdx, %%r8\n"
  570|  18.6k|    "xorq %%r9, %%r9\n"
  571|       |    /* (r8,r9) += p1 */
  572|  18.6k|    "addq %q2, %%r8\n"
  573|  18.6k|    "adcq $0, %%r9\n"
  574|       |    /* (r8,r9) += p4 * c1 */
  575|  18.6k|    "movq %8, %%rax\n"
  576|  18.6k|    "mulq %%r10\n"
  577|  18.6k|    "addq %%rax, %%r8\n"
  578|  18.6k|    "adcq %%rdx, %%r9\n"
  579|       |    /* Extract r1 */
  580|  18.6k|    "movq %%r8, 8(%q6)\n"
  581|  18.6k|    "xorq %%r8, %%r8\n"
  582|       |    /* (r9,r8) += p4 */
  583|  18.6k|    "addq %%r10, %%r9\n"
  584|  18.6k|    "adcq $0, %%r8\n"
  585|       |    /* (r9,r8) += p2 */
  586|  18.6k|    "addq %q3, %%r9\n"
  587|  18.6k|    "adcq $0, %%r8\n"
  588|       |    /* Extract r2 */
  589|  18.6k|    "movq %%r9, 16(%q6)\n"
  590|  18.6k|    "xorq %%r9, %%r9\n"
  591|       |    /* (r8,r9) += p3 */
  592|  18.6k|    "addq %q4, %%r8\n"
  593|  18.6k|    "adcq $0, %%r9\n"
  594|       |    /* Extract r3 */
  595|  18.6k|    "movq %%r8, 24(%q6)\n"
  596|       |    /* Extract c */
  597|  18.6k|    "movq %%r9, %q0\n"
  598|  18.6k|    : "=g"(c)
  599|  18.6k|    : "g"(p0), "g"(p1), "g"(p2), "g"(p3), "g"(p4), "D"(r), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   22|  18.6k|#define SECP256K1_N_C_0 (~SECP256K1_N_0 + 1)
  |  |  ------------------
  |  |  |  |   16|  18.6k|#define SECP256K1_N_0 ((uint64_t)0xBFD25E8CD0364141ULL)
  |  |  ------------------
  ------------------
                  : "g"(p0), "g"(p1), "g"(p2), "g"(p3), "g"(p4), "D"(r), "i"(SECP256K1_N_C_0), "i"(SECP256K1_N_C_1)
  ------------------
  |  |   23|  18.6k|#define SECP256K1_N_C_1 (~SECP256K1_N_1)
  |  |  ------------------
  |  |  |  |   17|  18.6k|#define SECP256K1_N_1 ((uint64_t)0xBAAEDCE6AF48A03BULL)
  |  |  ------------------
  ------------------
  600|  18.6k|    : "rax", "rdx", "r8", "r9", "r10", "cc", "memory");
  601|       |
  602|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(r, sizeof(*r));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  603|  18.6k|    SECP256K1_CHECKMEM_MSAN_DEFINE(&c, sizeof(c));
  ------------------
  |  |   70|  18.6k|#  define SECP256K1_CHECKMEM_MSAN_DEFINE(p, len) SECP256K1_CHECKMEM_NOOP((p), (len))
  |  |  ------------------
  |  |  |  |   42|  18.6k|#define SECP256K1_CHECKMEM_NOOP(p, len) do { (void)(p); (void)(len); } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (42:78): [Folded, False: 18.6k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  604|       |
  605|       |#else
  606|       |    secp256k1_uint128 c128;
  607|       |    uint64_t c, c0, c1, c2;
  608|       |    uint64_t n0 = l[4], n1 = l[5], n2 = l[6], n3 = l[7];
  609|       |    uint64_t m0, m1, m2, m3, m4, m5;
  610|       |    uint32_t m6;
  611|       |    uint64_t p0, p1, p2, p3;
  612|       |    uint32_t p4;
  613|       |
  614|       |    /* Reduce 512 bits into 385. */
  615|       |    /* m[0..6] = l[0..3] + n[0..3] * SECP256K1_N_C. */
  616|       |    c0 = l[0]; c1 = 0; c2 = 0;
  617|       |    muladd_fast(n0, SECP256K1_N_C_0);
  618|       |    extract_fast(m0);
  619|       |    sumadd_fast(l[1]);
  620|       |    muladd(n1, SECP256K1_N_C_0);
  621|       |    muladd(n0, SECP256K1_N_C_1);
  622|       |    extract(m1);
  623|       |    sumadd(l[2]);
  624|       |    muladd(n2, SECP256K1_N_C_0);
  625|       |    muladd(n1, SECP256K1_N_C_1);
  626|       |    sumadd(n0);
  627|       |    extract(m2);
  628|       |    sumadd(l[3]);
  629|       |    muladd(n3, SECP256K1_N_C_0);
  630|       |    muladd(n2, SECP256K1_N_C_1);
  631|       |    sumadd(n1);
  632|       |    extract(m3);
  633|       |    muladd(n3, SECP256K1_N_C_1);
  634|       |    sumadd(n2);
  635|       |    extract(m4);
  636|       |    sumadd_fast(n3);
  637|       |    extract_fast(m5);
  638|       |    VERIFY_CHECK(c0 <= 1);
  639|       |    m6 = c0;
  640|       |
  641|       |    /* Reduce 385 bits into 258. */
  642|       |    /* p[0..4] = m[0..3] + m[4..6] * SECP256K1_N_C. */
  643|       |    c0 = m0; c1 = 0; c2 = 0;
  644|       |    muladd_fast(m4, SECP256K1_N_C_0);
  645|       |    extract_fast(p0);
  646|       |    sumadd_fast(m1);
  647|       |    muladd(m5, SECP256K1_N_C_0);
  648|       |    muladd(m4, SECP256K1_N_C_1);
  649|       |    extract(p1);
  650|       |    sumadd(m2);
  651|       |    muladd(m6, SECP256K1_N_C_0);
  652|       |    muladd(m5, SECP256K1_N_C_1);
  653|       |    sumadd(m4);
  654|       |    extract(p2);
  655|       |    sumadd_fast(m3);
  656|       |    muladd_fast(m6, SECP256K1_N_C_1);
  657|       |    sumadd_fast(m5);
  658|       |    extract_fast(p3);
  659|       |    p4 = c0 + m6;
  660|       |    VERIFY_CHECK(p4 <= 2);
  661|       |
  662|       |    /* Reduce 258 bits into 256. */
  663|       |    /* r[0..3] = p[0..3] + p[4] * SECP256K1_N_C. */
  664|       |    secp256k1_u128_from_u64(&c128, p0);
  665|       |    secp256k1_u128_accum_mul(&c128, SECP256K1_N_C_0, p4);
  666|       |    r->d[0] = secp256k1_u128_to_u64(&c128); secp256k1_u128_rshift(&c128, 64);
  667|       |    secp256k1_u128_accum_u64(&c128, p1);
  668|       |    secp256k1_u128_accum_mul(&c128, SECP256K1_N_C_1, p4);
  669|       |    r->d[1] = secp256k1_u128_to_u64(&c128); secp256k1_u128_rshift(&c128, 64);
  670|       |    secp256k1_u128_accum_u64(&c128, p2);
  671|       |    secp256k1_u128_accum_u64(&c128, p4);
  672|       |    r->d[2] = secp256k1_u128_to_u64(&c128); secp256k1_u128_rshift(&c128, 64);
  673|       |    secp256k1_u128_accum_u64(&c128, p3);
  674|       |    r->d[3] = secp256k1_u128_to_u64(&c128);
  675|       |    c = secp256k1_u128_hi_u64(&c128);
  676|       |#endif
  677|       |
  678|       |    /* Final reduction of r. */
  679|  18.6k|    secp256k1_scalar_reduce(r, c + secp256k1_scalar_check_overflow(r));
  680|  18.6k|}
secp256k1.c:secp256k1_scalar_add:
   96|  7.46k|static int secp256k1_scalar_add(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b) {
   97|  7.46k|    int overflow;
   98|  7.46k|    secp256k1_uint128 t;
   99|  7.46k|    SECP256K1_SCALAR_VERIFY(a);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  100|  7.46k|    SECP256K1_SCALAR_VERIFY(b);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  101|       |
  102|  7.46k|    secp256k1_u128_from_u64(&t, a->d[0]);
  103|  7.46k|    secp256k1_u128_accum_u64(&t, b->d[0]);
  104|  7.46k|    r->d[0] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  105|  7.46k|    secp256k1_u128_accum_u64(&t, a->d[1]);
  106|  7.46k|    secp256k1_u128_accum_u64(&t, b->d[1]);
  107|  7.46k|    r->d[1] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  108|  7.46k|    secp256k1_u128_accum_u64(&t, a->d[2]);
  109|  7.46k|    secp256k1_u128_accum_u64(&t, b->d[2]);
  110|  7.46k|    r->d[2] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  111|  7.46k|    secp256k1_u128_accum_u64(&t, a->d[3]);
  112|  7.46k|    secp256k1_u128_accum_u64(&t, b->d[3]);
  113|  7.46k|    r->d[3] = secp256k1_u128_to_u64(&t); secp256k1_u128_rshift(&t, 64);
  114|  7.46k|    overflow = secp256k1_u128_to_u64(&t) + secp256k1_scalar_check_overflow(r);
  115|  7.46k|    VERIFY_CHECK(overflow == 0 || overflow == 1);
  116|  7.46k|    secp256k1_scalar_reduce(r, overflow);
  117|       |
  118|  7.46k|    SECP256K1_SCALAR_VERIFY(r);
  ------------------
  |  |  103|  7.46k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  119|  7.46k|    return overflow;
  120|  7.46k|}

secp256k1.c:secp256k1_scalar_verify:
   42|   966k|static void secp256k1_scalar_verify(const secp256k1_scalar *r) {
   43|   966k|    VERIFY_CHECK(secp256k1_scalar_check_overflow(r) == 0);
   44|       |
   45|   966k|    (void)r;
   46|   966k|}
secp256k1.c:secp256k1_scalar_clear:
   30|      2|SECP256K1_INLINE static void secp256k1_scalar_clear(secp256k1_scalar *r) {
   31|      2|    secp256k1_memclear_explicit(r, sizeof(secp256k1_scalar));
   32|      2|}
secp256k1.c:secp256k1_scalar_split_lambda:
  142|  3.73k|static void secp256k1_scalar_split_lambda(secp256k1_scalar * SECP256K1_RESTRICT r1, secp256k1_scalar * SECP256K1_RESTRICT r2, const secp256k1_scalar * SECP256K1_RESTRICT k) {
  143|  3.73k|    secp256k1_scalar c1, c2;
  144|  3.73k|    static const secp256k1_scalar minus_b1 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  3.73k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  145|  3.73k|        0x00000000UL, 0x00000000UL, 0x00000000UL, 0x00000000UL,
  146|  3.73k|        0xE4437ED6UL, 0x010E8828UL, 0x6F547FA9UL, 0x0ABFE4C3UL
  147|  3.73k|    );
  148|  3.73k|    static const secp256k1_scalar minus_b2 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  3.73k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  149|  3.73k|        0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFEUL,
  150|  3.73k|        0x8A280AC5UL, 0x0774346DUL, 0xD765CDA8UL, 0x3DB1562CUL
  151|  3.73k|    );
  152|  3.73k|    static const secp256k1_scalar g1 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  3.73k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  153|  3.73k|        0x3086D221UL, 0xA7D46BCDUL, 0xE86C90E4UL, 0x9284EB15UL,
  154|  3.73k|        0x3DAA8A14UL, 0x71E8CA7FUL, 0xE893209AUL, 0x45DBB031UL
  155|  3.73k|    );
  156|  3.73k|    static const secp256k1_scalar g2 = SECP256K1_SCALAR_CONST(
  ------------------
  |  |   17|  3.73k|#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0) {{((uint64_t)(d1)) << 32 | (d0), ((uint64_t)(d3)) << 32 | (d2), ((uint64_t)(d5)) << 32 | (d4), ((uint64_t)(d7)) << 32 | (d6)}}
  ------------------
  157|  3.73k|        0xE4437ED6UL, 0x010E8828UL, 0x6F547FA9UL, 0x0ABFE4C4UL,
  158|  3.73k|        0x221208ACUL, 0x9DF506C6UL, 0x1571B4AEUL, 0x8AC47F71UL
  159|  3.73k|    );
  160|  3.73k|    SECP256K1_SCALAR_VERIFY(k);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  161|  3.73k|    VERIFY_CHECK(r1 != k);
  162|  3.73k|    VERIFY_CHECK(r2 != k);
  163|  3.73k|    VERIFY_CHECK(r1 != r2);
  164|       |
  165|       |    /* these _var calls are constant time since the shift amount is constant */
  166|  3.73k|    secp256k1_scalar_mul_shift_var(&c1, k, &g1, 384);
  167|  3.73k|    secp256k1_scalar_mul_shift_var(&c2, k, &g2, 384);
  168|  3.73k|    secp256k1_scalar_mul(&c1, &c1, &minus_b1);
  169|  3.73k|    secp256k1_scalar_mul(&c2, &c2, &minus_b2);
  170|  3.73k|    secp256k1_scalar_add(r2, &c1, &c2);
  171|  3.73k|    secp256k1_scalar_mul(r1, r2, &secp256k1_const_lambda);
  172|  3.73k|    secp256k1_scalar_negate(r1, r1);
  173|  3.73k|    secp256k1_scalar_add(r1, r1, k);
  174|       |
  175|  3.73k|    SECP256K1_SCALAR_VERIFY(r1);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  176|  3.73k|    SECP256K1_SCALAR_VERIFY(r2);
  ------------------
  |  |  103|  3.73k|#define SECP256K1_SCALAR_VERIFY(r) secp256k1_scalar_verify(r)
  ------------------
  177|       |#ifdef VERIFY
  178|       |    secp256k1_scalar_split_lambda_verify(r1, r2, k);
  179|       |#endif
  180|  3.73k|}

secp256k1_context_preallocated_destroy:
  178|      2|void secp256k1_context_preallocated_destroy(secp256k1_context* ctx) {
  179|      2|    ARG_CHECK_VOID(ctx == NULL || secp256k1_context_is_proper(ctx));
  ------------------
  |  |   52|      2|#define ARG_CHECK_VOID(cond) do { \
  |  |   53|      2|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|      4|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   54|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   55|      0|        return; \
  |  |   56|      0|    } \
  |  |   57|      2|} while(0)
  |  |  ------------------
  |  |  |  Branch (57:9): [Folded, False: 2]
  |  |  ------------------
  ------------------
  180|       |
  181|       |    /* Defined as noop */
  182|      2|    if (ctx == NULL) {
  ------------------
  |  Branch (182:9): [True: 0, False: 2]
  ------------------
  183|      0|        return;
  184|      0|    }
  185|       |
  186|      2|    secp256k1_ecmult_gen_context_clear(&ctx->ecmult_gen_ctx);
  187|      2|}
secp256k1_context_destroy:
  189|      2|void secp256k1_context_destroy(secp256k1_context* ctx) {
  190|      2|    ARG_CHECK_VOID(ctx == NULL || secp256k1_context_is_proper(ctx));
  ------------------
  |  |   52|      2|#define ARG_CHECK_VOID(cond) do { \
  |  |   53|      2|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|      4|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 0, False: 2]
  |  |  |  |  |  Branch (146:39): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   54|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   55|      0|        return; \
  |  |   56|      0|    } \
  |  |   57|      2|} while(0)
  |  |  ------------------
  |  |  |  Branch (57:9): [Folded, False: 2]
  |  |  ------------------
  ------------------
  191|       |
  192|       |    /* Defined as noop */
  193|      2|    if (ctx == NULL) {
  ------------------
  |  Branch (193:9): [True: 0, False: 2]
  ------------------
  194|      0|        return;
  195|      0|    }
  196|       |
  197|      2|    secp256k1_context_preallocated_destroy(ctx);
  198|      2|    free(ctx);
  199|      2|}
secp256k1_ec_pubkey_parse:
  268|  5.13k|int secp256k1_ec_pubkey_parse(const secp256k1_context* ctx, secp256k1_pubkey* pubkey, const unsigned char *input, size_t inputlen) {
  269|  5.13k|    secp256k1_ge Q;
  270|       |
  271|  5.13k|    VERIFY_CHECK(ctx != NULL);
  272|  5.13k|    ARG_CHECK(pubkey != NULL);
  ------------------
  |  |   45|  5.13k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.13k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.13k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.13k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.13k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.13k]
  |  |  ------------------
  ------------------
  273|  5.13k|    memset(pubkey, 0, sizeof(*pubkey));
  274|  5.13k|    ARG_CHECK(input != NULL);
  ------------------
  |  |   45|  5.13k|#define ARG_CHECK(cond) do { \
  |  |   46|  5.13k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  5.13k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 5.13k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  5.13k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 5.13k]
  |  |  ------------------
  ------------------
  275|  5.13k|    if (!secp256k1_eckey_pubkey_parse(&Q, input, inputlen)) {
  ------------------
  |  Branch (275:9): [True: 1.18k, False: 3.95k]
  ------------------
  276|  1.18k|        return 0;
  277|  1.18k|    }
  278|  3.95k|    if (!secp256k1_ge_is_in_correct_subgroup(&Q)) {
  ------------------
  |  Branch (278:9): [True: 0, False: 3.95k]
  ------------------
  279|      0|        return 0;
  280|      0|    }
  281|  3.95k|    secp256k1_pubkey_save(pubkey, &Q);
  282|  3.95k|    secp256k1_ge_clear(&Q);
  283|  3.95k|    return 1;
  284|  3.95k|}
secp256k1_ecdsa_signature_parse_compact:
  411|  7.97k|int secp256k1_ecdsa_signature_parse_compact(const secp256k1_context* ctx, secp256k1_ecdsa_signature* sig, const unsigned char *input64) {
  412|  7.97k|    secp256k1_scalar r, s;
  413|  7.97k|    int ret = 1;
  414|  7.97k|    int overflow = 0;
  415|       |
  416|  7.97k|    VERIFY_CHECK(ctx != NULL);
  417|  7.97k|    ARG_CHECK(sig != NULL);
  ------------------
  |  |   45|  7.97k|#define ARG_CHECK(cond) do { \
  |  |   46|  7.97k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  7.97k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 7.97k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  7.97k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 7.97k]
  |  |  ------------------
  ------------------
  418|  7.97k|    ARG_CHECK(input64 != NULL);
  ------------------
  |  |   45|  7.97k|#define ARG_CHECK(cond) do { \
  |  |   46|  7.97k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  7.97k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 7.97k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  7.97k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 7.97k]
  |  |  ------------------
  ------------------
  419|       |
  420|  7.97k|    secp256k1_scalar_set_b32(&r, &input64[0], &overflow);
  421|  7.97k|    ret &= !overflow;
  422|  7.97k|    secp256k1_scalar_set_b32(&s, &input64[32], &overflow);
  423|  7.97k|    ret &= !overflow;
  424|  7.97k|    if (ret) {
  ------------------
  |  Branch (424:9): [True: 7.90k, False: 70]
  ------------------
  425|  7.90k|        secp256k1_ecdsa_signature_save(sig, &r, &s);
  426|  7.90k|    } else {
  427|     70|        memset(sig, 0, sizeof(*sig));
  428|     70|    }
  429|  7.97k|    return ret;
  430|  7.97k|}
secp256k1_ecdsa_signature_normalize:
  457|  3.95k|int secp256k1_ecdsa_signature_normalize(const secp256k1_context* ctx, secp256k1_ecdsa_signature *sigout, const secp256k1_ecdsa_signature *sigin) {
  458|  3.95k|    secp256k1_scalar r, s;
  459|  3.95k|    int ret = 0;
  460|       |
  461|  3.95k|    VERIFY_CHECK(ctx != NULL);
  462|  3.95k|    ARG_CHECK(sigin != NULL);
  ------------------
  |  |   45|  3.95k|#define ARG_CHECK(cond) do { \
  |  |   46|  3.95k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  3.95k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 3.95k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  463|       |
  464|  3.95k|    secp256k1_ecdsa_signature_load(ctx, &r, &s, sigin);
  465|  3.95k|    ret = secp256k1_scalar_is_high(&s);
  466|  3.95k|    if (sigout != NULL) {
  ------------------
  |  Branch (466:9): [True: 3.95k, False: 0]
  ------------------
  467|  3.95k|        if (ret) {
  ------------------
  |  Branch (467:13): [True: 8, False: 3.94k]
  ------------------
  468|      8|            secp256k1_scalar_negate(&s, &s);
  469|      8|        }
  470|  3.95k|        secp256k1_ecdsa_signature_save(sigout, &r, &s);
  471|  3.95k|    }
  472|       |
  473|  3.95k|    return ret;
  474|  3.95k|}
secp256k1_ecdsa_verify:
  476|  3.95k|int secp256k1_ecdsa_verify(const secp256k1_context* ctx, const secp256k1_ecdsa_signature *sig, const unsigned char *msghash32, const secp256k1_pubkey *pubkey) {
  477|  3.95k|    secp256k1_ge q;
  478|  3.95k|    secp256k1_scalar r, s;
  479|  3.95k|    secp256k1_scalar m;
  480|  3.95k|    VERIFY_CHECK(ctx != NULL);
  481|  3.95k|    ARG_CHECK(msghash32 != NULL);
  ------------------
  |  |   45|  3.95k|#define ARG_CHECK(cond) do { \
  |  |   46|  3.95k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  3.95k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 3.95k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  482|  3.95k|    ARG_CHECK(sig != NULL);
  ------------------
  |  |   45|  3.95k|#define ARG_CHECK(cond) do { \
  |  |   46|  3.95k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  3.95k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 3.95k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  483|  3.95k|    ARG_CHECK(pubkey != NULL);
  ------------------
  |  |   45|  3.95k|#define ARG_CHECK(cond) do { \
  |  |   46|  3.95k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  3.95k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 3.95k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  484|       |
  485|  3.95k|    secp256k1_scalar_set_b32(&m, msghash32, NULL);
  486|  3.95k|    secp256k1_ecdsa_signature_load(ctx, &r, &s, sig);
  487|  3.95k|    return (!secp256k1_scalar_is_high(&s) &&
  ------------------
  |  Branch (487:13): [True: 3.95k, False: 0]
  ------------------
  488|  3.95k|            secp256k1_pubkey_load(ctx, &q, pubkey) &&
  ------------------
  |  Branch (488:13): [True: 3.95k, False: 0]
  ------------------
  489|  3.95k|            secp256k1_ecdsa_sig_verify(&r, &s, &q, &m));
  ------------------
  |  Branch (489:13): [True: 0, False: 3.95k]
  ------------------
  490|  3.95k|}
secp256k1.c:secp256k1_context_is_proper:
   83|      4|static int secp256k1_context_is_proper(const secp256k1_context* ctx) {
   84|      4|    return secp256k1_ecmult_gen_context_is_built(&ctx->ecmult_gen_ctx);
   85|      4|}
secp256k1.c:secp256k1_pubkey_save:
  264|  3.95k|static void secp256k1_pubkey_save(secp256k1_pubkey* pubkey, secp256k1_ge* ge) {
  265|  3.95k|    secp256k1_ge_to_bytes(pubkey->data, ge);
  266|  3.95k|}
secp256k1.c:secp256k1_pubkey_load:
  258|  3.95k|static int secp256k1_pubkey_load(const secp256k1_context* ctx, secp256k1_ge* ge, const secp256k1_pubkey* pubkey) {
  259|  3.95k|    secp256k1_ge_from_bytes(ge, pubkey->data);
  260|  3.95k|    ARG_CHECK(!secp256k1_fe_is_zero(&ge->x));
  ------------------
  |  |   45|  3.95k|#define ARG_CHECK(cond) do { \
  |  |   46|  3.95k|    if (EXPECT(!(cond), 0)) { \
  |  |  ------------------
  |  |  |  |  146|  3.95k|#define EXPECT(x,c) __builtin_expect((x),(c))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (146:21): [True: 0, False: 3.95k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   47|      0|        secp256k1_callback_call(&ctx->illegal_callback, #cond); \
  |  |   48|      0|        return 0; \
  |  |   49|      0|    } \
  |  |   50|  3.95k|} while(0)
  |  |  ------------------
  |  |  |  Branch (50:9): [Folded, False: 3.95k]
  |  |  ------------------
  ------------------
  261|  3.95k|    return 1;
  262|  3.95k|}
secp256k1.c:secp256k1_ecdsa_signature_save:
  385|  11.8k|static void secp256k1_ecdsa_signature_save(secp256k1_ecdsa_signature* sig, const secp256k1_scalar* r, const secp256k1_scalar* s) {
  386|  11.8k|    if (sizeof(secp256k1_scalar) == 32) {
  ------------------
  |  Branch (386:9): [True: 11.8k, Folded]
  ------------------
  387|  11.8k|        memcpy(&sig->data[0], r, 32);
  388|  11.8k|        memcpy(&sig->data[32], s, 32);
  389|  11.8k|    } else {
  390|      0|        secp256k1_scalar_get_b32(&sig->data[0], r);
  391|      0|        secp256k1_scalar_get_b32(&sig->data[32], s);
  392|      0|    }
  393|  11.8k|}
secp256k1.c:secp256k1_ecdsa_signature_load:
  371|  7.90k|static void secp256k1_ecdsa_signature_load(const secp256k1_context* ctx, secp256k1_scalar* r, secp256k1_scalar* s, const secp256k1_ecdsa_signature* sig) {
  372|  7.90k|    (void)ctx;
  373|  7.90k|    if (sizeof(secp256k1_scalar) == 32) {
  ------------------
  |  Branch (373:9): [True: 7.90k, Folded]
  ------------------
  374|       |        /* When the secp256k1_scalar type is exactly 32 byte, use its
  375|       |         * representation inside secp256k1_ecdsa_signature, as conversion is very fast.
  376|       |         * Note that secp256k1_ecdsa_signature_save must use the same representation. */
  377|  7.90k|        memcpy(r, &sig->data[0], 32);
  378|  7.90k|        memcpy(s, &sig->data[32], 32);
  379|  7.90k|    } else {
  380|      0|        secp256k1_scalar_set_b32(r, &sig->data[0], NULL);
  381|       |        secp256k1_scalar_set_b32(s, &sig->data[32], NULL);
  382|      0|    }
  383|  7.90k|}

secp256k1.c:secp256k1_read_be64:
  444|  79.5k|SECP256K1_INLINE static uint64_t secp256k1_read_be64(const unsigned char* p) {
  445|  79.5k|    return (uint64_t)p[0] << 56 |
  446|  79.5k|           (uint64_t)p[1] << 48 |
  447|  79.5k|           (uint64_t)p[2] << 40 |
  448|  79.5k|           (uint64_t)p[3] << 32 |
  449|  79.5k|           (uint64_t)p[4] << 24 |
  450|  79.5k|           (uint64_t)p[5] << 16 |
  451|  79.5k|           (uint64_t)p[6] << 8  |
  452|  79.5k|           (uint64_t)p[7];
  453|  79.5k|}
secp256k1.c:secp256k1_ctz64_var:
  410|   512k|static SECP256K1_INLINE int secp256k1_ctz64_var(uint64_t x) {
  411|   512k|    VERIFY_CHECK(x != 0);
  412|   512k|#if (__has_builtin(__builtin_ctzl) || defined(__GNUC__))
  413|       |    /* If the unsigned long type is sufficient to represent the largest uint64_t, consider __builtin_ctzl. */
  414|   512k|    if (((unsigned long)UINT64_MAX) == UINT64_MAX) {
  ------------------
  |  Branch (414:9): [True: 512k, Folded]
  ------------------
  415|   512k|        return __builtin_ctzl(x);
  416|   512k|    }
  417|      0|#endif
  418|      0|#if (__has_builtin(__builtin_ctzll) || defined(__GNUC__))
  419|       |    /* Otherwise consider __builtin_ctzll (the unsigned long long type is always at least 64 bits). */
  420|      0|    return __builtin_ctzll(x);
  421|       |#else
  422|       |    /* If no suitable CTZ builtin is available, use a (variable time) software emulation. */
  423|       |    return secp256k1_ctz64_var_debruijn(x);
  424|       |#endif
  425|   512k|}
secp256k1.c:secp256k1_write_be64:
  456|  14.9k|SECP256K1_INLINE static void secp256k1_write_be64(unsigned char* p, uint64_t x) {
  457|  14.9k|    p[7] = x;
  458|  14.9k|    p[6] = x >>  8;
  459|  14.9k|    p[5] = x >> 16;
  460|  14.9k|    p[4] = x >> 24;
  461|  14.9k|    p[3] = x >> 32;
  462|  14.9k|    p[2] = x >> 40;
  463|  14.9k|    p[1] = x >> 48;
  464|  14.9k|    p[0] = x >> 56;
  465|  14.9k|}
secp256k1.c:secp256k1_memclear_explicit:
  268|  3.95k|static SECP256K1_INLINE void secp256k1_memclear_explicit(void *ptr, size_t len) {
  269|       |    /* The current implementation zeroes, but callers must not rely on this */
  270|  3.95k|    secp256k1_memzero_explicit(ptr, len);
  271|       |#ifdef VERIFY
  272|       |    SECP256K1_CHECKMEM_UNDEFINE(ptr, len);
  273|       |#endif
  274|  3.95k|}
secp256k1.c:secp256k1_memzero_explicit:
  236|  3.95k|static SECP256K1_INLINE void secp256k1_memzero_explicit(void *ptr, size_t len) {
  237|       |#if defined(_MSC_VER)
  238|       |    /* SecureZeroMemory is guaranteed not to be optimized out by MSVC. */
  239|       |    SecureZeroMemory(ptr, len);
  240|       |#elif defined(__GNUC__)
  241|       |    /* We use a memory barrier that scares the compiler away from optimizing out the memset.
  242|       |     *
  243|       |     * Quoting Adam Langley <agl@google.com> in commit ad1907fe73334d6c696c8539646c21b11178f20f
  244|       |     * in BoringSSL (ISC License):
  245|       |     *    As best as we can tell, this is sufficient to break any optimisations that
  246|       |     *    might try to eliminate "superfluous" memsets.
  247|       |     * This method is used in memzero_explicit() the Linux kernel, too. Its advantage is that it
  248|       |     * is pretty efficient, because the compiler can still implement the memset() efficiently,
  249|       |     * just not remove it entirely. See "Dead Store Elimination (Still) Considered Harmful" by
  250|       |     * Yang et al. (USENIX Security 2017) for more background.
  251|       |     */
  252|  3.95k|    memset(ptr, 0, len);
  253|  3.95k|    __asm__ __volatile__("" : : "r"(ptr) : "memory");
  254|       |#else
  255|       |    void *(*volatile const volatile_memset)(void *, int, size_t) = memset;
  256|       |    volatile_memset(ptr, 0, len);
  257|       |#endif
  258|  3.95k|}

block.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI5CTxInNS3_9allocatorIS5_EEEEE7WrapperIT_RT0_EOSC_:
  491|   585k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
block.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI6CTxOutNS3_9allocatorIS5_EEEEE7WrapperIT_RT0_EOSC_:
  491|  6.79k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
block.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEE7WrapperIT_RT0_EOSD_:
  491|  2.76k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
block.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS3_10shared_ptrIK12CTransactionEENS3_9allocatorIS8_EEEEE7WrapperIT_RT0_EOSF_:
  491|  6.58k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
transaction.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI5CTxInNS3_9allocatorIS5_EEEEE7WrapperIT_RT0_EOSD_:
  491|   621k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
transaction.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI6CTxOutNS3_9allocatorIS5_EEEEE7WrapperIT_RT0_EOSD_:
  491|   619k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
transaction.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEE7WrapperIT_RT0_EOSE_:
  491|  3.49k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
_Z11UnserializeI10SpanReaderR13ParamsWrapperI20TransactionSerParams6CBlockEQ14UnserializableIT0_T_EEvRS7_OS6_:
  776|  6.66k|{
  777|  6.66k|    a.Unserialize(is);
  778|  6.66k|}
_ZN13ParamsWrapperI20TransactionSerParams6CBlockE11UnserializeI10SpanReaderEEvRT_:
 1259|  6.66k|    {
 1260|  6.66k|        ParamsStream ss{s, m_params};
 1261|  6.66k|        ::Unserialize(ss, m_object);
 1262|  6.66k|    }
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsEC2ES1_RKS2_:
 1181|  6.66k|    ParamsStream(SubStream&& substream, const Params& params LIFETIMEBOUND) : m_params{params}, m_substream{std::forward<SubStream>(substream)} {}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER6CBlockQ14UnserializableIT0_T_EEvRS8_OS7_:
  776|  6.66k|{
  777|  6.66k|    a.Unserialize(is);
  778|  6.66k|}
_ZN6CBlock11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  220|  6.66k|    {                                                                                               \
  221|  6.66k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|  6.66k|        Unser(s, *this);                                                                            \
  223|  6.66k|    }
_ZN6CBlock5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_RS_:
  172|  6.66k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR12CBlockHeaderRNSt3__16vectorINS8_10shared_ptrIK12CTransactionEENS8_9allocatorISD_EEEEEEEvRT_DpOT0_:
 1086|  6.66k|    {
 1087|  6.66k|        ::UnserializeMany(s, args...);
 1088|  6.66k|    }
_Z15UnserializeManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR12CBlockHeaderRNSt3__16vectorINS7_10shared_ptrIK12CTransactionEENS7_9allocatorISC_EEEEEEvRT_DpOT0_:
 1054|  6.66k|{
 1055|  6.66k|    (::Unserialize(s, args), ...);
 1056|  6.66k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER12CBlockHeaderQ14UnserializableIT0_T_EEvRS8_OS7_:
  776|  6.66k|{
  777|  6.66k|    a.Unserialize(is);
  778|  6.66k|}
_ZN12CBlockHeader11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  220|  6.66k|    {                                                                                               \
  221|  6.66k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|  6.66k|        Unser(s, *this);                                                                            \
  223|  6.66k|    }
_ZN12CBlockHeader5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_RS_:
  172|  6.66k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJRiR7uint256S8_RjS9_S9_EEEvRT_DpOT0_:
 1086|  6.66k|    {
 1087|  6.66k|        ::UnserializeMany(s, args...);
 1088|  6.66k|    }
_Z15UnserializeManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJRiR7uint256S7_RjS8_S8_EEvRT_DpOT0_:
 1054|  6.66k|{
 1055|  6.66k|    (::Unserialize(s, args), ...);
 1056|  6.66k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEvRT_Ri:
  269|  6.66k|template <typename Stream> void Unserialize(Stream& s, int32_t& a)   { a = int32_t(ser_readdata32(s)); }
_Z14ser_readdata32I12ParamsStreamIR10SpanReader20TransactionSerParamsEEjRT_:
   94|  1.45M|{
   95|  1.45M|    uint32_t obj;
   96|  1.45M|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
   97|  1.45M|    return le32toh_internal(obj);
   98|  1.45M|}
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsE4readENSt3__14spanISt4byteLm18446744073709551615EEE:
 1190|  11.9M|    void read(std::span<std::byte> dst) { GetStream().read(dst); }
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsE9GetStreamEv:
 1208|  11.9M|    {
 1209|       |        if constexpr (ContainsStream<SubStream>) {
 1210|       |            return m_substream.GetStream();
 1211|  11.9M|        } else {
 1212|  11.9M|            return m_substream;
 1213|  11.9M|        }
 1214|  11.9M|    }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER7uint256Q14UnserializableIT0_T_EEvRS8_OS7_:
  776|  13.2k|{
  777|  13.2k|    a.Unserialize(is);
  778|  13.2k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEvRT_Rj:
  270|  1.44M|template <typename Stream> void Unserialize(Stream& s, uint32_t& a)  { a = ser_readdata32(s); }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__110shared_ptrIK12CTransactionEENS5_9allocatorIS9_EEEvRT_RNS5_6vectorIT0_T1_EE:
  919|  6.58k|{
  920|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|       |        v.clear();
  923|       |        unsigned int nSize = ReadCompactSize(is);
  924|       |        unsigned int i = 0;
  925|       |        while (i < nSize) {
  926|       |            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|       |            v.resize(i + blk);
  928|       |            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|       |            i += blk;
  930|       |        }
  931|  6.58k|    } else {
  932|  6.58k|        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|  6.58k|    }
  934|  6.58k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS9_10shared_ptrIK12CTransactionEENS9_9allocatorISE_EEEEEQ14UnserializableIT0_T_EEvRSL_OSK_:
  776|  6.58k|{
  777|  6.58k|    a.Unserialize(is);
  778|  6.58k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS3_10shared_ptrIK12CTransactionEENS3_9allocatorIS8_EEEEE11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  477|  6.58k|    template<typename Stream> void Unserialize(Stream &s) { Formatter().Unser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__16vectorINS8_10shared_ptrIK12CTransactionEENS8_9allocatorISD_EEEEEEvRT_RT0_:
  680|  6.58k|    {
  681|  6.58k|        Formatter formatter;
  682|  6.58k|        v.clear();
  683|  6.58k|        size_t size = ReadCompactSize(s);
  684|  6.58k|        size_t allocated = 0;
  685|  12.1k|        while (allocated < size) {
  ------------------
  |  Branch (685:16): [True: 5.53k, False: 6.58k]
  ------------------
  686|       |            // For DoS prevention, do not blindly allocate as much as the stream claims to contain.
  687|       |            // Instead, allocate in 5MiB batches, so that an attacker actually needs to provide
  688|       |            // X MiB of data to make us allocate X+5 Mib.
  689|  5.53k|            static_assert(sizeof(typename V::value_type) <= MAX_VECTOR_ALLOCATE, "Vector element size too large");
  690|  5.53k|            allocated = std::min(size, allocated + MAX_VECTOR_ALLOCATE / sizeof(typename V::value_type));
  691|  5.53k|            v.reserve(allocated);
  692|   590k|            while (v.size() < allocated) {
  ------------------
  |  Branch (692:20): [True: 585k, False: 5.53k]
  ------------------
  693|   585k|                v.emplace_back();
  694|   585k|                formatter.Unser(s, v.back());
  695|   585k|            }
  696|  5.53k|        }
  697|  6.58k|    };
_Z15ReadCompactSizeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEmRT_b:
  334|  8.98M|{
  335|  8.98M|    uint8_t chSize = ser_readdata8(is);
  336|  8.98M|    uint64_t nSizeRet = 0;
  337|  8.98M|    if (chSize < 253)
  ------------------
  |  Branch (337:9): [True: 8.98M, False: 1.53k]
  ------------------
  338|  8.98M|    {
  339|  8.98M|        nSizeRet = chSize;
  340|  8.98M|    }
  341|  1.53k|    else if (chSize == 253)
  ------------------
  |  Branch (341:14): [True: 952, False: 586]
  ------------------
  342|    952|    {
  343|    952|        nSizeRet = ser_readdata16(is);
  344|    952|        if (nSizeRet < 253)
  ------------------
  |  Branch (344:13): [True: 8, False: 944]
  ------------------
  345|      8|            throw std::ios_base::failure("non-canonical ReadCompactSize()");
  346|    952|    }
  347|    586|    else if (chSize == 254)
  ------------------
  |  Branch (347:14): [True: 341, False: 245]
  ------------------
  348|    341|    {
  349|    341|        nSizeRet = ser_readdata32(is);
  350|    341|        if (nSizeRet < 0x10000u)
  ------------------
  |  Branch (350:13): [True: 18, False: 323]
  ------------------
  351|     18|            throw std::ios_base::failure("non-canonical ReadCompactSize()");
  352|    341|    }
  353|    245|    else
  354|    245|    {
  355|    245|        nSizeRet = ser_readdata64(is);
  356|    245|        if (nSizeRet < 0x100000000ULL)
  ------------------
  |  Branch (356:13): [True: 38, False: 207]
  ------------------
  357|     38|            throw std::ios_base::failure("non-canonical ReadCompactSize()");
  358|    245|    }
  359|  8.98M|    if (range_check && nSizeRet > MAX_SIZE) {
  ------------------
  |  Branch (359:9): [True: 8.98M, False: 140]
  |  Branch (359:24): [True: 88, False: 8.98M]
  ------------------
  360|     88|        throw std::ios_base::failure("ReadCompactSize(): size too large");
  361|     88|    }
  362|  8.98M|    return nSizeRet;
  363|  8.98M|}
_Z13ser_readdata8I12ParamsStreamIR10SpanReader20TransactionSerParamsEEhRT_:
   82|  9.56M|{
   83|  9.56M|    uint8_t obj;
   84|  9.56M|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
   85|  9.56M|    return obj;
   86|  9.56M|}
_Z14ser_readdata16I12ParamsStreamIR10SpanReader20TransactionSerParamsEEtRT_:
   88|    952|{
   89|    952|    uint16_t obj;
   90|    952|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
   91|    952|    return le16toh_internal(obj);
   92|    952|}
_Z14ser_readdata64I12ParamsStreamIR10SpanReader20TransactionSerParamsEEmRT_:
  106|   686k|{
  107|   686k|    uint64_t obj;
  108|   686k|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
  109|   686k|    return le64toh_internal(obj);
  110|   686k|}
_ZN16DefaultFormatter5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__110shared_ptrIK12CTransactionEEEEvRT_RT0_:
  791|   585k|    static void Unser(Stream& s, T& t) { Unserialize(s, t); }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE12CTransactionEvRT_RNSt3__110shared_ptrIKT0_EE:
 1038|   585k|{
 1039|   585k|    p = std::make_shared<const T>(deserialize, is);
 1040|   585k|}
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsErsIRjEERS3_OT_:
 1188|  1.16M|    template <typename U> ParamsStream& operator>>(U&& obj) { ::Unserialize(*this, obj); return *this; }
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsErsIRNSt3__16vectorI5CTxInNS5_9allocatorIS7_EEEEEERS3_OT_:
 1188|   585k|    template <typename U> ParamsStream& operator>>(U&& obj) { ::Unserialize(*this, obj); return *this; }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE5CTxInNSt3__19allocatorIS5_EEEvRT_RNS6_6vectorIT0_T1_EE:
  919|   585k|{
  920|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|       |        v.clear();
  923|       |        unsigned int nSize = ReadCompactSize(is);
  924|       |        unsigned int i = 0;
  925|       |        while (i < nSize) {
  926|       |            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|       |            v.resize(i + blk);
  928|       |            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|       |            i += blk;
  930|       |        }
  931|   585k|    } else {
  932|   585k|        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|   585k|    }
  934|   585k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI5CTxInNS9_9allocatorISB_EEEEEQ14UnserializableIT0_T_EEvRSI_OSH_:
  776|   585k|{
  777|   585k|    a.Unserialize(is);
  778|   585k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI5CTxInNS3_9allocatorIS5_EEEEE11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  477|   585k|    template<typename Stream> void Unserialize(Stream &s) { Formatter().Unser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__16vectorI5CTxInNS8_9allocatorISA_EEEEEEvRT_RT0_:
  680|   585k|    {
  681|   585k|        Formatter formatter;
  682|   585k|        v.clear();
  683|   585k|        size_t size = ReadCompactSize(s);
  684|   585k|        size_t allocated = 0;
  685|   592k|        while (allocated < size) {
  ------------------
  |  Branch (685:16): [True: 6.81k, False: 585k]
  ------------------
  686|       |            // For DoS prevention, do not blindly allocate as much as the stream claims to contain.
  687|       |            // Instead, allocate in 5MiB batches, so that an attacker actually needs to provide
  688|       |            // X MiB of data to make us allocate X+5 Mib.
  689|  6.81k|            static_assert(sizeof(typename V::value_type) <= MAX_VECTOR_ALLOCATE, "Vector element size too large");
  690|  6.81k|            allocated = std::min(size, allocated + MAX_VECTOR_ALLOCATE / sizeof(typename V::value_type));
  691|  6.81k|            v.reserve(allocated);
  692|   136k|            while (v.size() < allocated) {
  ------------------
  |  Branch (692:20): [True: 129k, False: 6.81k]
  ------------------
  693|   129k|                v.emplace_back();
  694|   129k|                formatter.Unser(s, v.back());
  695|   129k|            }
  696|  6.81k|        }
  697|   585k|    };
_ZN16DefaultFormatter5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsE5CTxInEEvRT_RT0_:
  791|   129k|    static void Unser(Stream& s, T& t) { Unserialize(s, t); }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER5CTxInQ14UnserializableIT0_T_EEvRS8_OS7_:
  776|   129k|{
  777|   129k|    a.Unserialize(is);
  778|   129k|}
_ZN5CTxIn11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  220|   129k|    {                                                                                               \
  221|   129k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|   129k|        Unser(s, *this);                                                                            \
  223|   129k|    }
_ZN5CTxIn5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_RS_:
  172|   129k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR9COutPointR7CScriptRjEEEvRT_DpOT0_:
 1086|   129k|    {
 1087|   129k|        ::UnserializeMany(s, args...);
 1088|   129k|    }
_Z15UnserializeManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR9COutPointR7CScriptRjEEvRT_DpOT0_:
 1054|   129k|{
 1055|   129k|    (::Unserialize(s, args), ...);
 1056|   129k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER9COutPointQ14UnserializableIT0_T_EEvRS8_OS7_:
  776|   129k|{
  777|   129k|    a.Unserialize(is);
  778|   129k|}
_ZN9COutPoint11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  220|   129k|    {                                                                                               \
  221|   129k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|   129k|        Unser(s, *this);                                                                            \
  223|   129k|    }
_ZN9COutPoint5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_RS_:
  172|   129k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR22transaction_identifierILb0EERjEEEvRT_DpOT0_:
 1086|   129k|    {
 1087|   129k|        ::UnserializeMany(s, args...);
 1088|   129k|    }
_Z15UnserializeManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR22transaction_identifierILb0EERjEEvRT_DpOT0_:
 1054|   129k|{
 1055|   129k|    (::Unserialize(s, args), ...);
 1056|   129k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER22transaction_identifierILb0EEQ14UnserializableIT0_T_EEvRS9_OS8_:
  776|   129k|{
  777|   129k|    a.Unserialize(is);
  778|   129k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER7CScriptQ14UnserializableIT0_T_EEvRS8_OS7_:
  776|   816k|{
  777|   816k|    a.Unserialize(is);
  778|   816k|}
_ZN7CScript11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  220|   816k|    {                                                                                               \
  221|   816k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|   816k|        Unser(s, *this);                                                                            \
  223|   816k|    }
_ZN7CScript5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_RS_:
  172|   816k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR9prevectorILj36EhjiEEEEvRT_DpOT0_:
 1086|   816k|    {
 1087|   816k|        ::UnserializeMany(s, args...);
 1088|   816k|    }
_Z15UnserializeManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJR9prevectorILj36EhjiEEEvRT_DpOT0_:
 1054|   816k|{
 1055|   816k|    (::Unserialize(s, args), ...);
 1056|   816k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsELj36EhEvRT_R9prevectorIXT0_ET1_jiE:
  876|   816k|{
  877|   816k|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  878|       |        // Limit size per read so bogus size value won't cause out of memory
  879|   816k|        v.clear();
  880|   816k|        unsigned int nSize = ReadCompactSize(is);
  881|   816k|        unsigned int i = 0;
  882|   873k|        while (i < nSize) {
  ------------------
  |  Branch (882:16): [True: 57.3k, False: 816k]
  ------------------
  883|  57.3k|            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  884|  57.3k|            v.resize_uninitialized(i + blk);
  885|  57.3k|            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  886|  57.3k|            i += blk;
  887|  57.3k|        }
  888|       |    } else {
  889|       |        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  890|       |    }
  891|   816k|}
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsErsIRhEERS3_OT_:
 1188|   578k|    template <typename U> ParamsStream& operator>>(U&& obj) { ::Unserialize(*this, obj); return *this; }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEvRT_Rh:
  266|   578k|template <typename Stream> void Unserialize(Stream& s, uint8_t& a)   { a = ser_readdata8(s); }
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsErsIRNSt3__16vectorI6CTxOutNS5_9allocatorIS7_EEEEEERS3_OT_:
 1188|  6.79k|    template <typename U> ParamsStream& operator>>(U&& obj) { ::Unserialize(*this, obj); return *this; }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE6CTxOutNSt3__19allocatorIS5_EEEvRT_RNS6_6vectorIT0_T1_EE:
  919|  6.79k|{
  920|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|       |        v.clear();
  923|       |        unsigned int nSize = ReadCompactSize(is);
  924|       |        unsigned int i = 0;
  925|       |        while (i < nSize) {
  926|       |            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|       |            v.resize(i + blk);
  928|       |            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|       |            i += blk;
  930|       |        }
  931|  6.79k|    } else {
  932|  6.79k|        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|  6.79k|    }
  934|  6.79k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI6CTxOutNS9_9allocatorISB_EEEEEQ14UnserializableIT0_T_EEvRSI_OSH_:
  776|  6.79k|{
  777|  6.79k|    a.Unserialize(is);
  778|  6.79k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI6CTxOutNS3_9allocatorIS5_EEEEE11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  477|  6.79k|    template<typename Stream> void Unserialize(Stream &s) { Formatter().Unser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__16vectorI6CTxOutNS8_9allocatorISA_EEEEEEvRT_RT0_:
  680|  6.79k|    {
  681|  6.79k|        Formatter formatter;
  682|  6.79k|        v.clear();
  683|  6.79k|        size_t size = ReadCompactSize(s);
  684|  6.79k|        size_t allocated = 0;
  685|  12.4k|        while (allocated < size) {
  ------------------
  |  Branch (685:16): [True: 5.62k, False: 6.79k]
  ------------------
  686|       |            // For DoS prevention, do not blindly allocate as much as the stream claims to contain.
  687|       |            // Instead, allocate in 5MiB batches, so that an attacker actually needs to provide
  688|       |            // X MiB of data to make us allocate X+5 Mib.
  689|  5.62k|            static_assert(sizeof(typename V::value_type) <= MAX_VECTOR_ALLOCATE, "Vector element size too large");
  690|  5.62k|            allocated = std::min(size, allocated + MAX_VECTOR_ALLOCATE / sizeof(typename V::value_type));
  691|  5.62k|            v.reserve(allocated);
  692|   692k|            while (v.size() < allocated) {
  ------------------
  |  Branch (692:20): [True: 686k, False: 5.62k]
  ------------------
  693|   686k|                v.emplace_back();
  694|   686k|                formatter.Unser(s, v.back());
  695|   686k|            }
  696|  5.62k|        }
  697|  6.79k|    };
_ZN16DefaultFormatter5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsE6CTxOutEEvRT_RT0_:
  791|   686k|    static void Unser(Stream& s, T& t) { Unserialize(s, t); }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsER6CTxOutQ14UnserializableIT0_T_EEvRS8_OS7_:
  776|   686k|{
  777|   686k|    a.Unserialize(is);
  778|   686k|}
_ZN6CTxOut11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  220|   686k|    {                                                                                               \
  221|   686k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|   686k|        Unser(s, *this);                                                                            \
  223|   686k|    }
_ZN6CTxOut5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_RS_:
  172|   686k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJRlR7CScriptEEEvRT_DpOT0_:
 1086|   686k|    {
 1087|   686k|        ::UnserializeMany(s, args...);
 1088|   686k|    }
_Z15UnserializeManyI12ParamsStreamIR10SpanReader20TransactionSerParamsEJRlR7CScriptEEvRT_DpOT0_:
 1054|   686k|{
 1055|   686k|    (::Unserialize(s, args), ...);
 1056|   686k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEvRT_Rl:
  271|   686k|template <typename Stream> void Unserialize(Stream& s, int64_t& a)   { a = int64_t(ser_readdata64(s)); }
_ZN12ParamsStreamIR10SpanReader20TransactionSerParamsErsIRNSt3__16vectorINS6_IhNS5_9allocatorIhEEEENS7_IS9_EEEEEERS3_OT_:
 1188|  2.76k|    template <typename U> ParamsStream& operator>>(U&& obj) { ::Unserialize(*this, obj); return *this; }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__16vectorIhNS5_9allocatorIhEEEENS7_IS9_EEEvRT_RNS6_IT0_T1_EE:
  919|  2.76k|{
  920|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|       |        v.clear();
  923|       |        unsigned int nSize = ReadCompactSize(is);
  924|       |        unsigned int i = 0;
  925|       |        while (i < nSize) {
  926|       |            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|       |            v.resize(i + blk);
  928|       |            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|       |            i += blk;
  930|       |        }
  931|  2.76k|    } else {
  932|  2.76k|        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|  2.76k|    }
  934|  2.76k|}
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINSA_IhNS9_9allocatorIhEEEENSB_ISD_EEEEEQ14UnserializableIT0_T_EEvRSJ_OSI_:
  776|  2.76k|{
  777|  2.76k|    a.Unserialize(is);
  778|  2.76k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEE11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  477|  2.76k|    template<typename Stream> void Unserialize(Stream &s) { Formatter().Unser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__16vectorINS9_IhNS8_9allocatorIhEEEENSA_ISC_EEEEEEvRT_RT0_:
  680|  2.76k|    {
  681|  2.76k|        Formatter formatter;
  682|  2.76k|        v.clear();
  683|  2.76k|        size_t size = ReadCompactSize(s);
  684|  2.76k|        size_t allocated = 0;
  685|  3.96k|        while (allocated < size) {
  ------------------
  |  Branch (685:16): [True: 1.20k, False: 2.76k]
  ------------------
  686|       |            // For DoS prevention, do not blindly allocate as much as the stream claims to contain.
  687|       |            // Instead, allocate in 5MiB batches, so that an attacker actually needs to provide
  688|       |            // X MiB of data to make us allocate X+5 Mib.
  689|  1.20k|            static_assert(sizeof(typename V::value_type) <= MAX_VECTOR_ALLOCATE, "Vector element size too large");
  690|  1.20k|            allocated = std::min(size, allocated + MAX_VECTOR_ALLOCATE / sizeof(typename V::value_type));
  691|  1.20k|            v.reserve(allocated);
  692|  7.57M|            while (v.size() < allocated) {
  ------------------
  |  Branch (692:20): [True: 7.56M, False: 1.20k]
  ------------------
  693|  7.56M|                v.emplace_back();
  694|  7.56M|                formatter.Unser(s, v.back());
  695|  7.56M|            }
  696|  1.20k|        }
  697|  2.76k|    };
_ZN16DefaultFormatter5UnserI12ParamsStreamIR10SpanReader20TransactionSerParamsENSt3__16vectorIhNS6_9allocatorIhEEEEEEvRT_RT0_:
  791|  7.56M|    static void Unser(Stream& s, T& t) { Unserialize(s, t); }
_Z11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEhNSt3__19allocatorIhEEEvRT_RNS5_6vectorIT0_T1_EE:
  919|  7.56M|{
  920|  7.56M|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|  7.56M|        v.clear();
  923|  7.56M|        unsigned int nSize = ReadCompactSize(is);
  924|  7.56M|        unsigned int i = 0;
  925|  7.57M|        while (i < nSize) {
  ------------------
  |  Branch (925:16): [True: 4.56k, False: 7.56M]
  ------------------
  926|  4.56k|            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|  4.56k|            v.resize(i + blk);
  928|  4.56k|            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|  4.56k|            i += blk;
  930|  4.56k|        }
  931|       |    } else {
  932|       |        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|       |    }
  934|  7.56M|}
_ZNK12ParamsStreamIR10SpanReader20TransactionSerParamsE9GetParamsIS2_EERKDav:
 1198|   585k|    {
 1199|   585k|        if constexpr (std::is_convertible_v<Params, P>) {
 1200|   585k|            return m_params;
 1201|       |        } else {
 1202|       |            return m_substream.template GetParams<P>();
 1203|       |        }
 1204|   585k|    }
_Z11UnserializeI10SpanReaderR7CScriptQ14UnserializableIT0_T_EEvRS4_OS3_:
  776|  8.19k|{
  777|  8.19k|    a.Unserialize(is);
  778|  8.19k|}
_ZN7CScript11UnserializeI10SpanReaderEEvRT_:
  220|  8.19k|    {                                                                                               \
  221|  8.19k|        static_assert(std::is_same_v<cls&, decltype(*this)>, "Unserialize type mismatch");          \
  222|  8.19k|        Unser(s, *this);                                                                            \
  223|  8.19k|    }
_ZN7CScript5UnserI10SpanReaderEEvRT_RS_:
  172|  8.19k|    static void Unser(Stream& s, cls& obj) { SerializationOps(obj, s, ActionUnserialize{}); } \
_ZN17ActionUnserialize16SerReadWriteManyI10SpanReaderJR9prevectorILj36EhjiEEEEvRT_DpOT0_:
 1086|  8.19k|    {
 1087|  8.19k|        ::UnserializeMany(s, args...);
 1088|  8.19k|    }
_Z15UnserializeManyI10SpanReaderJR9prevectorILj36EhjiEEEvRT_DpOT0_:
 1054|  8.19k|{
 1055|  8.19k|    (::Unserialize(s, args), ...);
 1056|  8.19k|}
_Z11UnserializeI10SpanReaderLj36EhEvRT_R9prevectorIXT0_ET1_jiE:
  876|  8.19k|{
  877|  8.19k|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  878|       |        // Limit size per read so bogus size value won't cause out of memory
  879|  8.19k|        v.clear();
  880|  8.19k|        unsigned int nSize = ReadCompactSize(is);
  881|  8.19k|        unsigned int i = 0;
  882|  15.9k|        while (i < nSize) {
  ------------------
  |  Branch (882:16): [True: 7.80k, False: 8.19k]
  ------------------
  883|  7.80k|            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  884|  7.80k|            v.resize_uninitialized(i + blk);
  885|  7.80k|            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  886|  7.80k|            i += blk;
  887|  7.80k|        }
  888|       |    } else {
  889|       |        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  890|       |    }
  891|  8.19k|}
_Z11UnserializeI10SpanReaderNSt3__16vectorIhNS1_9allocatorIhEEEENS3_IS5_EEEvRT_RNS2_IT0_T1_EE:
  919|  7.89k|{
  920|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|       |        v.clear();
  923|       |        unsigned int nSize = ReadCompactSize(is);
  924|       |        unsigned int i = 0;
  925|       |        while (i < nSize) {
  926|       |            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|       |            v.resize(i + blk);
  928|       |            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|       |            i += blk;
  930|       |        }
  931|  7.89k|    } else {
  932|  7.89k|        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|  7.89k|    }
  934|  7.89k|}
_Z11UnserializeI10SpanReader7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS6_IhNS5_9allocatorIhEEEENS7_IS9_EEEEEQ14UnserializableIT0_T_EEvRSF_OSE_:
  776|  7.89k|{
  777|  7.89k|    a.Unserialize(is);
  778|  7.89k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEE11UnserializeI10SpanReaderEEvRT_:
  477|  7.89k|    template<typename Stream> void Unserialize(Stream &s) { Formatter().Unser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE5UnserI10SpanReaderNSt3__16vectorINS5_IhNS4_9allocatorIhEEEENS6_IS8_EEEEEEvRT_RT0_:
  680|  7.89k|    {
  681|  7.89k|        Formatter formatter;
  682|  7.89k|        v.clear();
  683|  7.89k|        size_t size = ReadCompactSize(s);
  684|  7.89k|        size_t allocated = 0;
  685|  9.73k|        while (allocated < size) {
  ------------------
  |  Branch (685:16): [True: 1.83k, False: 7.89k]
  ------------------
  686|       |            // For DoS prevention, do not blindly allocate as much as the stream claims to contain.
  687|       |            // Instead, allocate in 5MiB batches, so that an attacker actually needs to provide
  688|       |            // X MiB of data to make us allocate X+5 Mib.
  689|  1.83k|            static_assert(sizeof(typename V::value_type) <= MAX_VECTOR_ALLOCATE, "Vector element size too large");
  690|  1.83k|            allocated = std::min(size, allocated + MAX_VECTOR_ALLOCATE / sizeof(typename V::value_type));
  691|  1.83k|            v.reserve(allocated);
  692|  6.02k|            while (v.size() < allocated) {
  ------------------
  |  Branch (692:20): [True: 4.18k, False: 1.83k]
  ------------------
  693|  4.18k|                v.emplace_back();
  694|  4.18k|                formatter.Unser(s, v.back());
  695|  4.18k|            }
  696|  1.83k|        }
  697|  7.89k|    };
_ZN16DefaultFormatter5UnserI10SpanReaderNSt3__16vectorIhNS2_9allocatorIhEEEEEEvRT_RT0_:
  791|  4.18k|    static void Unser(Stream& s, T& t) { Unserialize(s, t); }
_Z11UnserializeI10SpanReaderhNSt3__19allocatorIhEEEvRT_RNS1_6vectorIT0_T1_EE:
  919|  4.18k|{
  920|  4.18k|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  921|       |        // Limit size per read so bogus size value won't cause out of memory
  922|  4.18k|        v.clear();
  923|  4.18k|        unsigned int nSize = ReadCompactSize(is);
  924|  4.18k|        unsigned int i = 0;
  925|  6.75k|        while (i < nSize) {
  ------------------
  |  Branch (925:16): [True: 2.56k, False: 4.18k]
  ------------------
  926|  2.56k|            unsigned int blk = std::min(nSize - i, (unsigned int)(1 + 4999999 / sizeof(T)));
  927|  2.56k|            v.resize(i + blk);
  928|  2.56k|            is.read(std::as_writable_bytes(std::span{&v[i], blk}));
  929|  2.56k|            i += blk;
  930|  2.56k|        }
  931|       |    } else {
  932|       |        Unserialize(is, Using<VectorFormatter<DefaultFormatter>>(v));
  933|       |    }
  934|  4.18k|}
signet.cpp:_ZL5UsingI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEE7WrapperIT_RT0_EOSD_:
  491|  7.89k|static inline Wrapper<Formatter, T&> Using(T&& t) { return Wrapper<Formatter, T&>(t); }
_Z9SerializeI12VectorWriterEvRT_i:
  253|  8.22k|template <typename Stream> void Serialize(Stream& s, int32_t a)   { ser_writedata32(s, uint32_t(a)); }
_Z15ser_writedata32I12VectorWriterEvRT_j:
   67|  16.4k|{
   68|  16.4k|    obj = htole32_internal(obj);
   69|  16.4k|    s.write(std::as_bytes(std::span{&obj, 1}));
   70|  16.4k|}
_Z9SerializeI12VectorWriter7uint256Q12SerializableIT0_T_EEvRS3_RKS2_:
  767|  16.4k|{
  768|  16.4k|    a.Serialize(os);
  769|  16.4k|}
_Z9SerializeI12VectorWriterTk9BasicByteKhLm32EEvRT_NSt3__14spanIT0_XT1_EEE:
  260|  16.4k|template <typename Stream, BasicByte B, size_t N> void Serialize(Stream& s, std::span<B, N> span)      { s.write(std::as_bytes(span)); }
_Z9SerializeI12VectorWriterEvRT_j:
  254|  8.22k|template <typename Stream> void Serialize(Stream& s, uint32_t a)  { ser_writedata32(s, a); }
_Z13ser_readdata8I10SpanReaderEhRT_:
   82|  20.2k|{
   83|  20.2k|    uint8_t obj;
   84|  20.2k|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
   85|  20.2k|    return obj;
   86|  20.2k|}
_Z15ReadCompactSizeI10SpanReaderEmRT_b:
  334|  20.2k|{
  335|  20.2k|    uint8_t chSize = ser_readdata8(is);
  336|  20.2k|    uint64_t nSizeRet = 0;
  337|  20.2k|    if (chSize < 253)
  ------------------
  |  Branch (337:9): [True: 19.5k, False: 689]
  ------------------
  338|  19.5k|    {
  339|  19.5k|        nSizeRet = chSize;
  340|  19.5k|    }
  341|    689|    else if (chSize == 253)
  ------------------
  |  Branch (341:14): [True: 153, False: 536]
  ------------------
  342|    153|    {
  343|    153|        nSizeRet = ser_readdata16(is);
  344|    153|        if (nSizeRet < 253)
  ------------------
  |  Branch (344:13): [True: 12, False: 141]
  ------------------
  345|     12|            throw std::ios_base::failure("non-canonical ReadCompactSize()");
  346|    153|    }
  347|    536|    else if (chSize == 254)
  ------------------
  |  Branch (347:14): [True: 252, False: 284]
  ------------------
  348|    252|    {
  349|    252|        nSizeRet = ser_readdata32(is);
  350|    252|        if (nSizeRet < 0x10000u)
  ------------------
  |  Branch (350:13): [True: 25, False: 227]
  ------------------
  351|     25|            throw std::ios_base::failure("non-canonical ReadCompactSize()");
  352|    252|    }
  353|    284|    else
  354|    284|    {
  355|    284|        nSizeRet = ser_readdata64(is);
  356|    284|        if (nSizeRet < 0x100000000ULL)
  ------------------
  |  Branch (356:13): [True: 55, False: 229]
  ------------------
  357|     55|            throw std::ios_base::failure("non-canonical ReadCompactSize()");
  358|    284|    }
  359|  20.1k|    if (range_check && nSizeRet > MAX_SIZE) {
  ------------------
  |  Branch (359:9): [True: 20.1k, False: 72]
  |  Branch (359:24): [True: 200, False: 19.9k]
  ------------------
  360|    200|        throw std::ios_base::failure("ReadCompactSize(): size too large");
  361|    200|    }
  362|  19.9k|    return nSizeRet;
  363|  20.1k|}
_Z14ser_readdata16I10SpanReaderEtRT_:
   88|    153|{
   89|    153|    uint16_t obj;
   90|    153|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
   91|    153|    return le16toh_internal(obj);
   92|    153|}
_Z14ser_readdata32I10SpanReaderEjRT_:
   94|    252|{
   95|    252|    uint32_t obj;
   96|    252|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
   97|    252|    return le32toh_internal(obj);
   98|    252|}
_Z14ser_readdata64I10SpanReaderEmRT_:
  106|    220|{
  107|    220|    uint64_t obj;
  108|    220|    s.read(std::as_writable_bytes(std::span{&obj, 1}));
  109|    220|    return le64toh_internal(obj);
  110|    220|}
_ZNK20TransactionSerParamsclIR6CBlockEEDaOT_:
 1282|  6.66k|    {                                                                                    \
 1283|  6.66k|        return ParamsWrapper{*this, t};                                                  \
 1284|  6.66k|    }
_ZN13ParamsWrapperI20TransactionSerParams6CBlockEC2ERKS0_RS1_:
 1249|  6.66k|    explicit ParamsWrapper(const Params& params, T& obj) : m_params{params}, m_object{obj} {}
_Z6AsBaseI9prevectorILj36EhjiE7CScriptERT_RT0_:
  137|   824k|{
  138|   824k|    static_assert(std::is_base_of_v<Out, In>);
  139|   824k|    return x;
  140|   824k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI5CTxInNS3_9allocatorIS5_EEEEEC2ES9_:
  475|   585k|    explicit Wrapper(T obj) : m_object(obj) {}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorI6CTxOutNS3_9allocatorIS5_EEEEEC2ES9_:
  475|  6.79k|    explicit Wrapper(T obj) : m_object(obj) {}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEEC2ESA_:
  475|  10.6k|    explicit Wrapper(T obj) : m_object(obj) {}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERNSt3__16vectorINS3_10shared_ptrIK12CTransactionEENS3_9allocatorIS8_EEEEEC2ESC_:
  475|  6.58k|    explicit Wrapper(T obj) : m_object(obj) {}
_Z6AsBaseI12CBlockHeader6CBlockERT_RT0_:
  137|  6.66k|{
  138|  6.66k|    static_assert(std::is_base_of_v<Out, In>);
  139|  6.66k|    return x;
  140|  6.66k|}
_ZNK20TransactionSerParamsclIRK12CTransactionEEDaOT_:
 1282|   603k|    {                                                                                    \
 1283|   603k|        return ParamsWrapper{*this, t};                                                  \
 1284|   603k|    }
_Z6AsBaseI9prevectorILj36EhjiE7CScriptERKT_RKT0_:
  143|   464k|{
  144|   464k|    static_assert(std::is_base_of_v<Out, In>);
  145|   464k|    return x;
  146|   464k|}
_Z9SerializeI10HashWriter12CBlockHeaderQ12SerializableIT0_T_EEvRS3_RKS2_:
  767|  5.69k|{
  768|  5.69k|    a.Serialize(os);
  769|  5.69k|}
_ZNK12CBlockHeader9SerializeI10HashWriterEEvRT_:
  214|  5.69k|    {                                                                                               \
  215|  5.69k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|  5.69k|        Ser(s, *this);                                                                              \
  217|  5.69k|    }                                                                                               \
_ZN12CBlockHeader3SerI10HashWriterEEvRT_RKS_:
  170|  5.69k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI10HashWriterJi7uint256S2_jjjEEEvRT_DpRKT0_:
 1066|  5.69k|    {
 1067|  5.69k|        ::SerializeMany(s, args...);
 1068|  5.69k|    }
_Z13SerializeManyI10HashWriterJi7uint256S1_jjjEEvRT_DpRKT0_:
 1048|  5.69k|{
 1049|  5.69k|    (::Serialize(s, args), ...);
 1050|  5.69k|}
_ZNK20TransactionSerParamsclIRK19CMutableTransactionEEDaOT_:
 1282|  16.4k|    {                                                                                    \
 1283|  16.4k|        return ParamsWrapper{*this, t};                                                  \
 1284|  16.4k|    }
_ZN13ParamsWrapperI20TransactionSerParamsK19CMutableTransactionEC2ERKS0_RS2_:
 1249|  16.4k|    explicit ParamsWrapper(const Params& params, T& obj) : m_params{params}, m_object{obj} {}
_ZN13ParamsWrapperI20TransactionSerParamsK12CTransactionEC2ERKS0_RS2_:
 1249|   603k|    explicit ParamsWrapper(const Params& params, T& obj) : m_params{params}, m_object{obj} {}
_Z9SerializeI10HashWriter13ParamsWrapperI20TransactionSerParamsK19CMutableTransactionEQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|  16.4k|{
  768|  16.4k|    a.Serialize(os);
  769|  16.4k|}
_ZNK13ParamsWrapperI20TransactionSerParamsK19CMutableTransactionE9SerializeI10HashWriterEEvRT_:
 1253|  16.4k|    {
 1254|  16.4k|        ParamsStream ss{s, m_params};
 1255|  16.4k|        ::Serialize(ss, m_object);
 1256|  16.4k|    }
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsEC2ES1_RKS2_:
 1181|   619k|    ParamsStream(SubStream&& substream, const Params& params LIFETIMEBOUND) : m_params{params}, m_substream{std::forward<SubStream>(substream)} {}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE19CMutableTransactionQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|  16.4k|{
  768|  16.4k|    a.Serialize(os);
  769|  16.4k|}
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsElsIjEERS3_RKT_:
 1187|  1.23M|    template <typename U> ParamsStream& operator<<(const U& obj) { ::Serialize(*this, obj); return *this; }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_j:
  254|  1.34M|template <typename Stream> void Serialize(Stream& s, uint32_t a)  { ser_writedata32(s, a); }
_Z15ser_writedata32I12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_j:
   67|  1.34M|{
   68|  1.34M|    obj = htole32_internal(obj);
   69|  1.34M|    s.write(std::as_bytes(std::span{&obj, 1}));
   70|  1.34M|}
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsE5writeENSt3__14spanIKSt4byteLm18446744073709551615EEE:
 1189|  3.82M|    void write(std::span<const std::byte> src) { GetStream().write(src); }
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsE9GetStreamEv:
 1208|  3.82M|    {
 1209|       |        if constexpr (ContainsStream<SubStream>) {
 1210|       |            return m_substream.GetStream();
 1211|  3.82M|        } else {
 1212|  3.82M|            return m_substream;
 1213|  3.82M|        }
 1214|  3.82M|    }
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsElsINSt3__16vectorI5CTxInNS5_9allocatorIS7_EEEEEERS3_RKT_:
 1187|   621k|    template <typename U> ParamsStream& operator<<(const U& obj) { ::Serialize(*this, obj); return *this; }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE5CTxInNSt3__19allocatorIS5_EEEvRT_RKNS6_6vectorIT0_T1_EE:
  899|   621k|{
  900|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  901|       |        WriteCompactSize(os, v.size());
  902|       |        if (!v.empty()) os.write(MakeByteSpan(v));
  903|       |    } else if constexpr (std::is_same_v<T, bool>) {
  904|       |        // A special case for std::vector<bool>, as dereferencing
  905|       |        // std::vector<bool>::const_iterator does not result in a const bool&
  906|       |        // due to std::vector's special casing for bool arguments.
  907|       |        WriteCompactSize(os, v.size());
  908|       |        for (bool elem : v) {
  909|       |            ::Serialize(os, elem);
  910|       |        }
  911|   621k|    } else {
  912|   621k|        Serialize(os, Using<VectorFormatter<DefaultFormatter>>(v));
  913|   621k|    }
  914|   621k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI5CTxInNS9_9allocatorISB_EEEEEQ12SerializableIT0_T_EEvRSJ_RKSI_:
  767|   621k|{
  768|   621k|    a.Serialize(os);
  769|   621k|}
_ZNK7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI5CTxInNS3_9allocatorIS5_EEEEE9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  476|   621k|    template<typename Stream> void Serialize(Stream &s) const { Formatter().Ser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsENSt3__16vectorI5CTxInNS8_9allocatorISA_EEEEEEvRT_RKT0_:
  670|   621k|    {
  671|   621k|        Formatter formatter;
  672|   621k|        WriteCompactSize(s, v.size());
  673|   621k|        for (const typename V::value_type& elem : v) {
  ------------------
  |  Branch (673:49): [True: 54.7k, False: 621k]
  ------------------
  674|  54.7k|            formatter.Ser(s, elem);
  675|  54.7k|        }
  676|   621k|    }
_Z16WriteCompactSizeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_m:
  303|  1.88M|{
  304|  1.88M|    if (nSize < 253)
  ------------------
  |  Branch (304:9): [True: 1.88M, False: 1.26k]
  ------------------
  305|  1.88M|    {
  306|  1.88M|        ser_writedata8(os, nSize);
  307|  1.88M|    }
  308|  1.26k|    else if (nSize <= std::numeric_limits<uint16_t>::max())
  ------------------
  |  Branch (308:14): [True: 945, False: 316]
  ------------------
  309|    945|    {
  310|    945|        ser_writedata8(os, 253);
  311|    945|        ser_writedata16(os, nSize);
  312|    945|    }
  313|    316|    else if (nSize <= std::numeric_limits<unsigned int>::max())
  ------------------
  |  Branch (313:14): [True: 316, False: 0]
  ------------------
  314|    316|    {
  315|    316|        ser_writedata8(os, 254);
  316|    316|        ser_writedata32(os, nSize);
  317|    316|    }
  318|      0|    else
  319|      0|    {
  320|      0|        ser_writedata8(os, 255);
  321|      0|        ser_writedata64(os, nSize);
  322|      0|    }
  323|  1.88M|    return;
  324|  1.88M|}
_Z14ser_writedata8I12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_h:
   58|  1.88M|{
   59|  1.88M|    s.write(std::as_bytes(std::span{&obj, 1}));
   60|  1.88M|}
_Z15ser_writedata16I12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_t:
   62|    945|{
   63|    945|    obj = htole16_internal(obj);
   64|    945|    s.write(std::as_bytes(std::span{&obj, 1}));
   65|    945|}
_Z15ser_writedata64I12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_m:
   77|   406k|{
   78|   406k|    obj = htole64_internal(obj);
   79|   406k|    s.write(std::as_bytes(std::span{&obj, 1}));
   80|   406k|}
_ZN16DefaultFormatter3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsE5CTxInEEvRT_RKT0_:
  788|  54.7k|    static void Ser(Stream& s, const T& t) { Serialize(s, t); }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE5CTxInQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|  54.7k|{
  768|  54.7k|    a.Serialize(os);
  769|  54.7k|}
_ZNK5CTxIn9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  214|  54.7k|    {                                                                                               \
  215|  54.7k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|  54.7k|        Ser(s, *this);                                                                              \
  217|  54.7k|    }                                                                                               \
_ZN5CTxIn3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_RKS_:
  170|  54.7k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJ9COutPoint7CScriptjEEEvRT_DpRKT0_:
 1066|  54.7k|    {
 1067|  54.7k|        ::SerializeMany(s, args...);
 1068|  54.7k|    }
_Z13SerializeManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJ9COutPoint7CScriptjEEvRT_DpRKT0_:
 1048|  54.7k|{
 1049|  54.7k|    (::Serialize(s, args), ...);
 1050|  54.7k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE9COutPointQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|  54.7k|{
  768|  54.7k|    a.Serialize(os);
  769|  54.7k|}
_ZNK9COutPoint9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  214|  54.7k|    {                                                                                               \
  215|  54.7k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|  54.7k|        Ser(s, *this);                                                                              \
  217|  54.7k|    }                                                                                               \
_ZN9COutPoint3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_RKS_:
  170|  54.7k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJ22transaction_identifierILb0EEjEEEvRT_DpRKT0_:
 1066|  54.7k|    {
 1067|  54.7k|        ::SerializeMany(s, args...);
 1068|  54.7k|    }
_Z13SerializeManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJ22transaction_identifierILb0EEjEEvRT_DpRKT0_:
 1048|  54.7k|{
 1049|  54.7k|    (::Serialize(s, args), ...);
 1050|  54.7k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE22transaction_identifierILb0EEQ12SerializableIT0_T_EEvRS8_RKS7_:
  767|  54.7k|{
  768|  54.7k|    a.Serialize(os);
  769|  54.7k|}
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsElsINSt3__14spanIKhLm32EEEEERS3_RKT_:
 1187|  54.7k|    template <typename U> ParamsStream& operator<<(const U& obj) { ::Serialize(*this, obj); return *this; }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsETk9BasicByteKhLm32EEvRT_NSt3__14spanIT0_XT1_EEE:
  260|  54.7k|template <typename Stream, BasicByte B, size_t N> void Serialize(Stream& s, std::span<B, N> span)      { s.write(std::as_bytes(span)); }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE7CScriptQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|   461k|{
  768|   461k|    a.Serialize(os);
  769|   461k|}
_ZNK7CScript9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  214|   461k|    {                                                                                               \
  215|   461k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|   461k|        Ser(s, *this);                                                                              \
  217|   461k|    }                                                                                               \
_ZN7CScript3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_RKS_:
  170|   461k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJ9prevectorILj36EhjiEEEEvRT_DpRKT0_:
 1066|   461k|    {
 1067|   461k|        ::SerializeMany(s, args...);
 1068|   461k|    }
_Z13SerializeManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJ9prevectorILj36EhjiEEEvRT_DpRKT0_:
 1048|   461k|{
 1049|   461k|    (::Serialize(s, args), ...);
 1050|   461k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsELj36EhEvRT_RK9prevectorIXT0_ET1_jiE:
  864|   461k|{
  865|   461k|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  866|   461k|        WriteCompactSize(os, v.size());
  867|   461k|        if (!v.empty()) os.write(MakeByteSpan(v));
  ------------------
  |  Branch (867:13): [True: 120k, False: 340k]
  ------------------
  868|       |    } else {
  869|       |        Serialize(os, Using<VectorFormatter<DefaultFormatter>>(v));
  870|       |    }
  871|   461k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI5CTxInNS3_9allocatorIS5_EEEEEC2ESA_:
  475|   621k|    explicit Wrapper(T obj) : m_object(obj) {}
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsElsIhEERS3_RKT_:
 1187|  2.17k|    template <typename U> ParamsStream& operator<<(const U& obj) { ::Serialize(*this, obj); return *this; }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_h:
  250|  2.17k|template <typename Stream> void Serialize(Stream& s, uint8_t a)   { ser_writedata8(s, a); }
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsElsINSt3__16vectorI6CTxOutNS5_9allocatorIS7_EEEEEERS3_RKT_:
 1187|   619k|    template <typename U> ParamsStream& operator<<(const U& obj) { ::Serialize(*this, obj); return *this; }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE6CTxOutNSt3__19allocatorIS5_EEEvRT_RKNS6_6vectorIT0_T1_EE:
  899|   619k|{
  900|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  901|       |        WriteCompactSize(os, v.size());
  902|       |        if (!v.empty()) os.write(MakeByteSpan(v));
  903|       |    } else if constexpr (std::is_same_v<T, bool>) {
  904|       |        // A special case for std::vector<bool>, as dereferencing
  905|       |        // std::vector<bool>::const_iterator does not result in a const bool&
  906|       |        // due to std::vector's special casing for bool arguments.
  907|       |        WriteCompactSize(os, v.size());
  908|       |        for (bool elem : v) {
  909|       |            ::Serialize(os, elem);
  910|       |        }
  911|   619k|    } else {
  912|   619k|        Serialize(os, Using<VectorFormatter<DefaultFormatter>>(v));
  913|   619k|    }
  914|   619k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI6CTxOutNS9_9allocatorISB_EEEEEQ12SerializableIT0_T_EEvRSJ_RKSI_:
  767|   619k|{
  768|   619k|    a.Serialize(os);
  769|   619k|}
_ZNK7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI6CTxOutNS3_9allocatorIS5_EEEEE9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  476|   619k|    template<typename Stream> void Serialize(Stream &s) const { Formatter().Ser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsENSt3__16vectorI6CTxOutNS8_9allocatorISA_EEEEEEvRT_RKT0_:
  670|   619k|    {
  671|   619k|        Formatter formatter;
  672|   619k|        WriteCompactSize(s, v.size());
  673|   619k|        for (const typename V::value_type& elem : v) {
  ------------------
  |  Branch (673:49): [True: 406k, False: 619k]
  ------------------
  674|   406k|            formatter.Ser(s, elem);
  675|   406k|        }
  676|   619k|    }
_ZN16DefaultFormatter3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsE6CTxOutEEvRT_RKT0_:
  788|   406k|    static void Ser(Stream& s, const T& t) { Serialize(s, t); }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE6CTxOutQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|   406k|{
  768|   406k|    a.Serialize(os);
  769|   406k|}
_ZNK6CTxOut9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  214|   406k|    {                                                                                               \
  215|   406k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|   406k|        Ser(s, *this);                                                                              \
  217|   406k|    }                                                                                               \
_ZN6CTxOut3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_RKS_:
  170|   406k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJl7CScriptEEEvRT_DpRKT0_:
 1066|   406k|    {
 1067|   406k|        ::SerializeMany(s, args...);
 1068|   406k|    }
_Z13SerializeManyI12ParamsStreamIR10HashWriter20TransactionSerParamsEJl7CScriptEEvRT_DpRKT0_:
 1048|   406k|{
 1049|   406k|    (::Serialize(s, args), ...);
 1050|   406k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEvRT_l:
  255|   406k|template <typename Stream> void Serialize(Stream& s, int64_t a)   { ser_writedata64(s, uint64_t(a)); }
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorI6CTxOutNS3_9allocatorIS5_EEEEEC2ESA_:
  475|   619k|    explicit Wrapper(T obj) : m_object(obj) {}
_ZN12ParamsStreamIR10HashWriter20TransactionSerParamsElsINSt3__16vectorINS6_IhNS5_9allocatorIhEEEENS7_IS9_EEEEEERS3_RKT_:
 1187|  3.49k|    template <typename U> ParamsStream& operator<<(const U& obj) { ::Serialize(*this, obj); return *this; }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsENSt3__16vectorIhNS5_9allocatorIhEEEENS7_IS9_EEEvRT_RKNS6_IT0_T1_EE:
  899|  3.49k|{
  900|       |    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  901|       |        WriteCompactSize(os, v.size());
  902|       |        if (!v.empty()) os.write(MakeByteSpan(v));
  903|       |    } else if constexpr (std::is_same_v<T, bool>) {
  904|       |        // A special case for std::vector<bool>, as dereferencing
  905|       |        // std::vector<bool>::const_iterator does not result in a const bool&
  906|       |        // due to std::vector's special casing for bool arguments.
  907|       |        WriteCompactSize(os, v.size());
  908|       |        for (bool elem : v) {
  909|       |            ::Serialize(os, elem);
  910|       |        }
  911|  3.49k|    } else {
  912|  3.49k|        Serialize(os, Using<VectorFormatter<DefaultFormatter>>(v));
  913|  3.49k|    }
  914|  3.49k|}
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorINSA_IhNS9_9allocatorIhEEEENSB_ISD_EEEEEQ12SerializableIT0_T_EEvRSK_RKSJ_:
  767|  3.49k|{
  768|  3.49k|    a.Serialize(os);
  769|  3.49k|}
_ZNK7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEE9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  476|  3.49k|    template<typename Stream> void Serialize(Stream &s) const { Formatter().Ser(s, m_object); }
_ZN15VectorFormatterI16DefaultFormatterE3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsENSt3__16vectorINS9_IhNS8_9allocatorIhEEEENSA_ISC_EEEEEEvRT_RKT0_:
  670|  3.49k|    {
  671|  3.49k|        Formatter formatter;
  672|  3.49k|        WriteCompactSize(s, v.size());
  673|   181k|        for (const typename V::value_type& elem : v) {
  ------------------
  |  Branch (673:49): [True: 181k, False: 3.49k]
  ------------------
  674|   181k|            formatter.Ser(s, elem);
  675|   181k|        }
  676|  3.49k|    }
_ZN16DefaultFormatter3SerI12ParamsStreamIR10HashWriter20TransactionSerParamsENSt3__16vectorIhNS6_9allocatorIhEEEEEEvRT_RKT0_:
  788|   181k|    static void Ser(Stream& s, const T& t) { Serialize(s, t); }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEhNSt3__19allocatorIhEEEvRT_RKNS5_6vectorIT0_T1_EE:
  899|   181k|{
  900|   181k|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  901|   181k|        WriteCompactSize(os, v.size());
  902|   181k|        if (!v.empty()) os.write(MakeByteSpan(v));
  ------------------
  |  Branch (902:13): [True: 3.09k, False: 178k]
  ------------------
  903|       |    } else if constexpr (std::is_same_v<T, bool>) {
  904|       |        // A special case for std::vector<bool>, as dereferencing
  905|       |        // std::vector<bool>::const_iterator does not result in a const bool&
  906|       |        // due to std::vector's special casing for bool arguments.
  907|       |        WriteCompactSize(os, v.size());
  908|       |        for (bool elem : v) {
  909|       |            ::Serialize(os, elem);
  910|       |        }
  911|       |    } else {
  912|       |        Serialize(os, Using<VectorFormatter<DefaultFormatter>>(v));
  913|       |    }
  914|   181k|}
_ZNK12ParamsStreamIR10HashWriter20TransactionSerParamsE9GetParamsIS2_EERKDav:
 1198|   619k|    {
 1199|   619k|        if constexpr (std::is_convertible_v<Params, P>) {
 1200|   619k|            return m_params;
 1201|       |        } else {
 1202|       |            return m_substream.template GetParams<P>();
 1203|       |        }
 1204|   619k|    }
_Z9SerializeI10HashWriter13ParamsWrapperI20TransactionSerParamsK12CTransactionEQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|   603k|{
  768|   603k|    a.Serialize(os);
  769|   603k|}
_ZNK13ParamsWrapperI20TransactionSerParamsK12CTransactionE9SerializeI10HashWriterEEvRT_:
 1253|   603k|    {
 1254|   603k|        ParamsStream ss{s, m_params};
 1255|   603k|        ::Serialize(ss, m_object);
 1256|   603k|    }
_Z9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsE12CTransactionQ12SerializableIT0_T_EEvRS7_RKS6_:
  767|   603k|{
  768|   603k|    a.Serialize(os);
  769|   603k|}
_Z9SerializeI10HashWriterEvRT_l:
  255|  3.17k|template <typename Stream> void Serialize(Stream& s, int64_t a)   { ser_writedata64(s, uint64_t(a)); }
_Z15ser_writedata64I10HashWriterEvRT_m:
   77|  3.17k|{
   78|  3.17k|    obj = htole64_internal(obj);
   79|  3.17k|    s.write(std::as_bytes(std::span{&obj, 1}));
   80|  3.17k|}
_Z9SerializeI10HashWriter7CScriptQ12SerializableIT0_T_EEvRS3_RKS2_:
  767|  3.17k|{
  768|  3.17k|    a.Serialize(os);
  769|  3.17k|}
_ZNK7CScript9SerializeI10HashWriterEEvRT_:
  214|  3.17k|    {                                                                                               \
  215|  3.17k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|  3.17k|        Ser(s, *this);                                                                              \
  217|  3.17k|    }                                                                                               \
_ZN7CScript3SerI10HashWriterEEvRT_RKS_:
  170|  3.17k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI10HashWriterJ9prevectorILj36EhjiEEEEvRT_DpRKT0_:
 1066|  3.17k|    {
 1067|  3.17k|        ::SerializeMany(s, args...);
 1068|  3.17k|    }
_Z13SerializeManyI10HashWriterJ9prevectorILj36EhjiEEEvRT_DpRKT0_:
 1048|  3.17k|{
 1049|  3.17k|    (::Serialize(s, args), ...);
 1050|  3.17k|}
_Z9SerializeI10HashWriterLj36EhEvRT_RK9prevectorIXT0_ET1_jiE:
  864|  3.17k|{
  865|  3.17k|    if constexpr (BasicByte<T>) { // Use optimized version for unformatted basic bytes
  866|  3.17k|        WriteCompactSize(os, v.size());
  867|  3.17k|        if (!v.empty()) os.write(MakeByteSpan(v));
  ------------------
  |  Branch (867:13): [True: 3.17k, False: 0]
  ------------------
  868|       |    } else {
  869|       |        Serialize(os, Using<VectorFormatter<DefaultFormatter>>(v));
  870|       |    }
  871|  3.17k|}
_Z16WriteCompactSizeI10HashWriterEvRT_m:
  303|  10.6k|{
  304|  10.6k|    if (nSize < 253)
  ------------------
  |  Branch (304:9): [True: 10.6k, False: 0]
  ------------------
  305|  10.6k|    {
  306|  10.6k|        ser_writedata8(os, nSize);
  307|  10.6k|    }
  308|      0|    else if (nSize <= std::numeric_limits<uint16_t>::max())
  ------------------
  |  Branch (308:14): [True: 0, False: 0]
  ------------------
  309|      0|    {
  310|      0|        ser_writedata8(os, 253);
  311|      0|        ser_writedata16(os, nSize);
  312|      0|    }
  313|      0|    else if (nSize <= std::numeric_limits<unsigned int>::max())
  ------------------
  |  Branch (313:14): [True: 0, False: 0]
  ------------------
  314|      0|    {
  315|      0|        ser_writedata8(os, 254);
  316|      0|        ser_writedata32(os, nSize);
  317|      0|    }
  318|      0|    else
  319|      0|    {
  320|      0|        ser_writedata8(os, 255);
  321|      0|        ser_writedata64(os, nSize);
  322|      0|    }
  323|  10.6k|    return;
  324|  10.6k|}
_Z14ser_writedata8I10HashWriterEvRT_h:
   58|  10.6k|{
   59|  10.6k|    s.write(std::as_bytes(std::span{&obj, 1}));
   60|  10.6k|}
_Z15ser_writedata32I10HashWriterEvRT_j:
   67|  39.4k|{
   68|  39.4k|    obj = htole32_internal(obj);
   69|  39.4k|    s.write(std::as_bytes(std::span{&obj, 1}));
   70|  39.4k|}
_ZN7WrapperI15VectorFormatterI16DefaultFormatterERKNSt3__16vectorINS4_IhNS3_9allocatorIhEEEENS5_IS7_EEEEEC2ESB_:
  475|  3.49k|    explicit Wrapper(T obj) : m_object(obj) {}
_Z9SerializeI10HashWriter9COutPointQ12SerializableIT0_T_EEvRS3_RKS2_:
  767|  3.29k|{
  768|  3.29k|    a.Serialize(os);
  769|  3.29k|}
_ZNK9COutPoint9SerializeI10HashWriterEEvRT_:
  214|  3.29k|    {                                                                                               \
  215|  3.29k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|  3.29k|        Ser(s, *this);                                                                              \
  217|  3.29k|    }                                                                                               \
_ZN9COutPoint3SerI10HashWriterEEvRT_RKS_:
  170|  3.29k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI10HashWriterJ22transaction_identifierILb0EEjEEEvRT_DpRKT0_:
 1066|  3.29k|    {
 1067|  3.29k|        ::SerializeMany(s, args...);
 1068|  3.29k|    }
_Z13SerializeManyI10HashWriterJ22transaction_identifierILb0EEjEEvRT_DpRKT0_:
 1048|  3.29k|{
 1049|  3.29k|    (::Serialize(s, args), ...);
 1050|  3.29k|}
_Z9SerializeI10HashWriter22transaction_identifierILb0EEQ12SerializableIT0_T_EEvRS4_RKS3_:
  767|  3.29k|{
  768|  3.29k|    a.Serialize(os);
  769|  3.29k|}
_Z9SerializeI10HashWriterTk9BasicByteKhLm32EEvRT_NSt3__14spanIT0_XT1_EEE:
  260|  14.6k|template <typename Stream, BasicByte B, size_t N> void Serialize(Stream& s, std::span<B, N> span)      { s.write(std::as_bytes(span)); }
_Z9SerializeI10HashWriterEvRT_j:
  254|  28.6k|template <typename Stream> void Serialize(Stream& s, uint32_t a)  { ser_writedata32(s, a); }
_Z9SerializeI10HashWriter6CTxOutQ12SerializableIT0_T_EEvRS3_RKS2_:
  767|  3.17k|{
  768|  3.17k|    a.Serialize(os);
  769|  3.17k|}
_ZNK6CTxOut9SerializeI10HashWriterEEvRT_:
  214|  3.17k|    {                                                                                               \
  215|  3.17k|        static_assert(std::is_same_v<const cls&, decltype(*this)>, "Serialize type mismatch");      \
  216|  3.17k|        Ser(s, *this);                                                                              \
  217|  3.17k|    }                                                                                               \
_ZN6CTxOut3SerI10HashWriterEEvRT_RKS_:
  170|  3.17k|    static void Ser(Stream& s, const cls& obj) { SerializationOps(obj, s, ActionSerialize{}); } \
_ZN15ActionSerialize16SerReadWriteManyI10HashWriterJl7CScriptEEEvRT_DpRKT0_:
 1066|  3.17k|    {
 1067|  3.17k|        ::SerializeMany(s, args...);
 1068|  3.17k|    }
_Z13SerializeManyI10HashWriterJl7CScriptEEvRT_DpRKT0_:
 1048|  3.17k|{
 1049|  3.17k|    (::Serialize(s, args), ...);
 1050|  3.17k|}
_Z9SerializeI10HashWriterEvRT_i:
  253|  10.8k|template <typename Stream> void Serialize(Stream& s, int32_t a)   { ser_writedata32(s, uint32_t(a)); }
_Z9SerializeI10HashWriter7uint256Q12SerializableIT0_T_EEvRS3_RKS2_:
  767|  11.3k|{
  768|  11.3k|    a.Serialize(os);
  769|  11.3k|}
interpreter.cpp:_Z9SerializeI10HashWriterN12_GLOBAL__N_131CTransactionSignatureSerializerI12CTransactionEEQ12SerializableIT0_T_EEvRS6_RKS5_:
  767|  2.48k|{
  768|  2.48k|    a.Serialize(os);
  769|  2.48k|}

_ZN9SignetTxs6CreateERK6CBlockRK7CScript:
   71|  11.2k|{
   72|  11.2k|    CMutableTransaction tx_to_spend;
   73|  11.2k|    tx_to_spend.version = 0;
   74|  11.2k|    tx_to_spend.nLockTime = 0;
   75|  11.2k|    tx_to_spend.vin.emplace_back(COutPoint(), CScript(OP_0), 0);
   76|  11.2k|    tx_to_spend.vout.emplace_back(0, challenge);
   77|       |
   78|  11.2k|    CMutableTransaction tx_spending;
   79|  11.2k|    tx_spending.version = 0;
   80|  11.2k|    tx_spending.nLockTime = 0;
   81|  11.2k|    tx_spending.vin.emplace_back(COutPoint(), CScript(), 0);
   82|  11.2k|    tx_spending.vout.emplace_back(0, CScript(OP_RETURN));
   83|       |
   84|       |    // can't fill any other fields before extracting signet
   85|       |    // responses from block coinbase tx
   86|       |
   87|       |    // find and delete signet signature
   88|  11.2k|    if (block.vtx.empty()) return std::nullopt; // no coinbase tx in block; invalid
  ------------------
  |  Branch (88:9): [True: 1.81k, False: 9.42k]
  ------------------
   89|  9.42k|    CMutableTransaction modified_cb(*block.vtx.at(0));
   90|       |
   91|  9.42k|    const int cidx = GetWitnessCommitmentIndex(block);
   92|  9.42k|    if (cidx == NO_WITNESS_COMMITMENT) {
  ------------------
  |  Branch (92:9): [True: 559, False: 8.86k]
  ------------------
   93|    559|        return std::nullopt; // require a witness commitment
   94|    559|    }
   95|       |
   96|  8.86k|    CScript& witness_commitment = modified_cb.vout.at(cidx).scriptPubKey;
   97|       |
   98|  8.86k|    std::vector<uint8_t> signet_solution;
   99|  8.86k|    if (!FetchAndClearCommitmentSection(SIGNET_HEADER, witness_commitment, signet_solution)) {
  ------------------
  |  Branch (99:9): [True: 672, False: 8.19k]
  ------------------
  100|       |        // no signet solution -- allow this to support OP_TRUE as trivial block challenge
  101|  8.19k|    } else {
  102|  8.19k|        try {
  103|  8.19k|            SpanReader v{signet_solution};
  104|  8.19k|            v >> tx_spending.vin[0].scriptSig;
  105|  8.19k|            v >> tx_spending.vin[0].scriptWitness.stack;
  106|  8.19k|            if (!v.empty()) return std::nullopt; // extraneous data encountered
  ------------------
  |  Branch (106:17): [True: 28, False: 8.16k]
  ------------------
  107|  8.19k|        } catch (const std::exception&) {
  108|    607|            return std::nullopt; // parsing error
  109|    607|        }
  110|  8.19k|    }
  111|  8.22k|    uint256 signet_merkle = ComputeModifiedMerkleRoot(modified_cb, block);
  112|       |
  113|  8.22k|    std::vector<uint8_t> block_data;
  114|  8.22k|    VectorWriter writer{block_data, 0};
  115|  8.22k|    writer << block.nVersion;
  116|  8.22k|    writer << block.hashPrevBlock;
  117|  8.22k|    writer << signet_merkle;
  118|  8.22k|    writer << block.nTime;
  119|  8.22k|    tx_to_spend.vin[0].scriptSig << block_data;
  120|  8.22k|    tx_spending.vin[0].prevout = COutPoint(tx_to_spend.GetHash(), 0);
  121|       |
  122|  8.22k|    return SignetTxs{tx_to_spend, tx_spending};
  123|  8.86k|}
_Z24CheckSignetBlockSolutionRK6CBlockRKN9Consensus6ParamsE:
  127|  5.69k|{
  128|  5.69k|    if (block.GetHash() == consensusParams.hashGenesisBlock) {
  ------------------
  |  Branch (128:9): [True: 154, False: 5.54k]
  ------------------
  129|       |        // genesis block solution is always valid
  130|    154|        return true;
  131|    154|    }
  132|       |
  133|  5.54k|    const CScript challenge(consensusParams.signet_challenge.begin(), consensusParams.signet_challenge.end());
  134|  5.54k|    const std::optional<SignetTxs> signet_txs = SignetTxs::Create(block, challenge);
  135|       |
  136|  5.54k|    if (!signet_txs) {
  ------------------
  |  Branch (136:9): [True: 1.45k, False: 4.08k]
  ------------------
  137|  1.45k|        LogDebug(BCLog::VALIDATION, "CheckSignetBlockSolution: Errors in block (block solution parse failure)\n");
  ------------------
  |  |  143|  1.45k|#define LogDebug(category, ...) detail_LogIfCategoryAndLevelEnabled(category, util::log::ShouldDebugLog, util::log::Level::Debug, __VA_ARGS__)
  |  |  ------------------
  |  |  |  |  136|  1.45k|    do {                                                                                      \
  |  |  |  |  137|  1.45k|        if (shouldlog(category)) {                                                            \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (137:13): [True: 0, False: 1.45k]
  |  |  |  |  ------------------
  |  |  |  |  138|      0|            detail_LogWithSrcLoc((category), (level), util::log::NO_RATE_LIMIT, __VA_ARGS__); \
  |  |  |  |  ------------------
  |  |  |  |  |  |  119|      0|#define detail_LogWithSrcLoc(category, level, ...) util::log::LogPrintFormatInternal(SourceLocation{__func__}, category, level, __VA_ARGS__)
  |  |  |  |  ------------------
  |  |  |  |  139|      0|        }                                                                                     \
  |  |  |  |  140|  1.45k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (140:14): [Folded, False: 1.45k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  138|  1.45k|        return false;
  139|  1.45k|    }
  140|       |
  141|  4.08k|    const CScript& scriptSig = signet_txs->m_to_sign.vin[0].scriptSig;
  142|  4.08k|    const CScriptWitness& witness = signet_txs->m_to_sign.vin[0].scriptWitness;
  143|       |
  144|  4.08k|    PrecomputedTransactionData txdata;
  145|  4.08k|    txdata.Init(signet_txs->m_to_sign, {signet_txs->m_to_spend.vout[0]});
  146|  4.08k|    TransactionSignatureChecker sigcheck(&signet_txs->m_to_sign, /* nInIn= */ 0, /* amountIn= */ signet_txs->m_to_spend.vout[0].nValue, txdata, MissingDataBehavior::ASSERT_FAIL);
  147|       |
  148|  4.08k|    if (!VerifyScript(scriptSig, signet_txs->m_to_spend.vout[0].scriptPubKey, &witness, BLOCK_SCRIPT_VERIFY_FLAGS, sigcheck)) {
  ------------------
  |  Branch (148:9): [True: 4.08k, False: 0]
  ------------------
  149|  4.08k|        LogDebug(BCLog::VALIDATION, "CheckSignetBlockSolution: Errors in block (block solution invalid)\n");
  ------------------
  |  |  143|  4.08k|#define LogDebug(category, ...) detail_LogIfCategoryAndLevelEnabled(category, util::log::ShouldDebugLog, util::log::Level::Debug, __VA_ARGS__)
  |  |  ------------------
  |  |  |  |  136|  4.08k|    do {                                                                                      \
  |  |  |  |  137|  4.08k|        if (shouldlog(category)) {                                                            \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (137:13): [True: 0, False: 4.08k]
  |  |  |  |  ------------------
  |  |  |  |  138|      0|            detail_LogWithSrcLoc((category), (level), util::log::NO_RATE_LIMIT, __VA_ARGS__); \
  |  |  |  |  ------------------
  |  |  |  |  |  |  119|      0|#define detail_LogWithSrcLoc(category, level, ...) util::log::LogPrintFormatInternal(SourceLocation{__func__}, category, level, __VA_ARGS__)
  |  |  |  |  ------------------
  |  |  |  |  139|      0|        }                                                                                     \
  |  |  |  |  140|  4.08k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (140:14): [Folded, False: 4.08k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  150|  4.08k|        return false;
  151|  4.08k|    }
  152|      0|    return true;
  153|  4.08k|}
signet.cpp:_ZL30FetchAndClearCommitmentSectionNSt3__14spanIKhLm18446744073709551615EEER7CScriptRNS_6vectorIhNS_9allocatorIhEEEE:
   33|  8.86k|{
   34|  8.86k|    CScript replacement;
   35|  8.86k|    bool found_header = false;
   36|  8.86k|    result.clear();
   37|       |
   38|  8.86k|    opcodetype opcode;
   39|  8.86k|    CScript::const_iterator pc = witness_commitment.begin();
   40|  8.86k|    std::vector<uint8_t> pushdata;
   41|   789k|    while (witness_commitment.GetOp(pc, opcode, pushdata)) {
  ------------------
  |  Branch (41:12): [True: 780k, False: 8.86k]
  ------------------
   42|   780k|        if (pushdata.size() > 0) {
  ------------------
  |  Branch (42:13): [True: 78.1k, False: 702k]
  ------------------
   43|  78.1k|            if (!found_header && pushdata.size() > header.size() && std::ranges::equal(std::span{pushdata}.first(header.size()), header)) {
  ------------------
  |  Branch (43:17): [True: 33.3k, False: 44.7k]
  |  Branch (43:17): [True: 8.19k, False: 69.9k]
  |  Branch (43:34): [True: 24.8k, False: 8.51k]
  |  Branch (43:69): [True: 8.19k, False: 16.6k]
  ------------------
   44|       |                // pushdata only counts if it has the header _and_ some data
   45|  8.19k|                result.insert(result.end(), pushdata.begin() + header.size(), pushdata.end());
   46|  8.19k|                pushdata.erase(pushdata.begin() + header.size(), pushdata.end());
   47|  8.19k|                found_header = true;
   48|  8.19k|            }
   49|  78.1k|            replacement << pushdata;
   50|   702k|        } else {
   51|   702k|            replacement << opcode;
   52|   702k|        }
   53|   780k|    }
   54|       |
   55|  8.86k|    if (found_header) witness_commitment = replacement;
  ------------------
  |  Branch (55:9): [True: 8.19k, False: 672]
  ------------------
   56|  8.86k|    return found_header;
   57|  8.86k|}
signet.cpp:_ZL25ComputeModifiedMerkleRootRK19CMutableTransactionRK6CBlock:
   60|  8.22k|{
   61|  8.22k|    std::vector<uint256> leaves;
   62|  8.22k|    leaves.reserve((block.vtx.size() + 1) & ~1ULL); // capacity rounded up to even
   63|  8.22k|    leaves.push_back(cb.GetHash().ToUint256());
   64|   743k|    for (size_t s = 1; s < block.vtx.size(); ++s) {
  ------------------
  |  Branch (64:24): [True: 735k, False: 8.22k]
  ------------------
   65|   735k|        leaves.push_back(block.vtx[s]->GetHash().ToUint256());
   66|   735k|    }
   67|  8.22k|    return ComputeMerkleRoot(std::move(leaves));
   68|  8.22k|}

_ZN9SignetTxsC2I19CMutableTransactionS1_EERKT_RKT0_:
   32|  8.22k|    SignetTxs(const T1& to_spend, const T2& to_sign) : m_to_spend{to_spend}, m_to_sign{to_sign} { }

_Z20MakeWritableByteSpanIRNSt3__15arrayIhLm32EEEEDaOT_:
   90|   142k|{
   91|   142k|    return std::as_writable_bytes(std::span{std::forward<V>(v)});
   92|   142k|}
_Z12MakeByteSpanI9prevectorILj36EhjiEEDaRKT_:
   85|   123k|{
   86|   123k|    return std::as_bytes(std::span{v});
   87|   123k|}
_Z12MakeByteSpanINSt3__16vectorIhNS0_9allocatorIhEEEEEDaRKT_:
   85|  3.09k|{
   86|  3.09k|    return std::as_bytes(std::span{v});
   87|  3.09k|}
_Z9UCharCastPKSt4byte:
  102|  3.97M|inline const unsigned char* UCharCast(const std::byte* c) { return reinterpret_cast<const unsigned char*>(c); }

_ZN10SpanReaderrsI13ParamsWrapperI20TransactionSerParams6CBlockEEERS_OT_:
   96|  6.66k|    {
   97|  6.66k|        ::Unserialize(*this, obj);
   98|  6.66k|        return (*this);
   99|  6.66k|    }
_ZN10SpanReaderC2ENSt3__14spanIKhLm18446744073709551615EEE:
   91|  14.8k|    explicit SpanReader(std::span<const unsigned char> data) : m_data{std::as_bytes(data)} {}
_ZNK10SpanReader5emptyEv:
  102|  7.58k|    bool empty() const { return m_data.empty(); }
_ZN12VectorWriterC2ERNSt3__16vectorIhNS0_9allocatorIhEEEEm:
   42|  8.22k|    VectorWriter(std::vector<unsigned char>& vchDataIn, size_t nPosIn) : vchData{vchDataIn}, nPos{nPosIn}
   43|  8.22k|    {
   44|  8.22k|        if(nPos > vchData.size())
  ------------------
  |  Branch (44:12): [True: 0, False: 8.22k]
  ------------------
   45|      0|            vchData.resize(nPos);
   46|  8.22k|    }
_ZN10SpanReaderrsIR7CScriptEERS_OT_:
   96|  8.19k|    {
   97|  8.19k|        ::Unserialize(*this, obj);
   98|  8.19k|        return (*this);
   99|  8.19k|    }
_ZN10SpanReaderrsIRNSt3__16vectorINS2_IhNS1_9allocatorIhEEEENS3_IS5_EEEEEERS_OT_:
   96|  7.89k|    {
   97|  7.89k|        ::Unserialize(*this, obj);
   98|  7.89k|        return (*this);
   99|  7.89k|    }
_ZN12VectorWriterlsIiEERS_RKT_:
   70|  8.22k|    {
   71|  8.22k|        ::Serialize(*this, obj);
   72|  8.22k|        return (*this);
   73|  8.22k|    }
_ZN12VectorWriter5writeENSt3__14spanIKSt4byteLm18446744073709551615EEE:
   57|  32.9k|    {
   58|  32.9k|        assert(nPos <= vchData.size());
  ------------------
  |  Branch (58:9): [True: 32.9k, False: 0]
  ------------------
   59|  32.9k|        size_t nOverwrite = std::min(src.size(), vchData.size() - nPos);
   60|  32.9k|        if (nOverwrite) {
  ------------------
  |  Branch (60:13): [True: 0, False: 32.9k]
  ------------------
   61|      0|            memcpy(vchData.data() + nPos, src.data(), nOverwrite);
   62|      0|        }
   63|  32.9k|        if (nOverwrite < src.size()) {
  ------------------
  |  Branch (63:13): [True: 32.9k, False: 0]
  ------------------
   64|  32.9k|            vchData.insert(vchData.end(), UCharCast(src.data()) + nOverwrite, UCharCast(src.data() + src.size()));
   65|  32.9k|        }
   66|  32.9k|        nPos += src.size();
   67|  32.9k|    }
_ZN12VectorWriterlsI7uint256EERS_RKT_:
   70|  16.4k|    {
   71|  16.4k|        ::Serialize(*this, obj);
   72|  16.4k|        return (*this);
   73|  16.4k|    }
_ZN12VectorWriterlsINSt3__14spanIKhLm32EEEEERS_RKT_:
   70|  16.4k|    {
   71|  16.4k|        ::Serialize(*this, obj);
   72|  16.4k|        return (*this);
   73|  16.4k|    }
_ZN12VectorWriterlsIjEERS_RKT_:
   70|  8.22k|    {
   71|  8.22k|        ::Serialize(*this, obj);
   72|  8.22k|        return (*this);
   73|  8.22k|    }
_ZN10SpanReader4readENSt3__14spanISt4byteLm18446744073709551615EEE:
  105|  11.9M|    {
  106|  11.9M|        if (dst.size() == 0) {
  ------------------
  |  Branch (106:13): [True: 0, False: 11.9M]
  ------------------
  107|      0|            return;
  108|      0|        }
  109|       |
  110|       |        // Read from the beginning of the buffer
  111|  11.9M|        if (dst.size() > m_data.size()) {
  ------------------
  |  Branch (111:13): [True: 1.09k, False: 11.9M]
  ------------------
  112|  1.09k|            throw std::ios_base::failure("SpanReader::read(): end of data");
  113|  1.09k|        }
  114|  11.9M|        memcpy(dst.data(), m_data.data(), dst.size());
  115|  11.9M|        m_data = m_data.subspan(dst.size());
  116|  11.9M|    }

random.cpp:_ZN16secure_allocatorIN12_GLOBAL__N_18RNGStateEE10deallocateEPS1_m:
   37|      2|    {
   38|      2|        if (p != nullptr) {
  ------------------
  |  Branch (38:13): [True: 2, False: 0]
  ------------------
   39|      2|            memory_cleanse(p, sizeof(T) * n);
   40|      2|        }
   41|      2|        LockedPoolManager::Instance().free(p);
   42|      2|    }

_Z14memory_cleansePvm:
   15|     18|{
   16|       |#if defined(WIN32)
   17|       |    /* SecureZeroMemory is guaranteed not to be optimized out. */
   18|       |    SecureZeroMemory(ptr, len);
   19|       |#else
   20|     18|    std::memset(ptr, 0, len);
   21|       |
   22|       |    /* Memory barrier that scares the compiler away from optimizing out the memset.
   23|       |     *
   24|       |     * Quoting Adam Langley <agl@google.com> in commit ad1907fe73334d6c696c8539646c21b11178f20f
   25|       |     * in BoringSSL (ISC License):
   26|       |     *    As best as we can tell, this is sufficient to break any optimisations that
   27|       |     *    might try to eliminate "superfluous" memsets.
   28|       |     * This method is used in memzero_explicit() the Linux kernel, too. Its advantage is that it
   29|       |     * is pretty efficient because the compiler can still implement the memset() efficiently,
   30|       |     * just not remove it entirely. See "Dead Store Elimination (Still) Considered Harmful" by
   31|       |     * Yang et al. (USENIX Security 2017) for more background.
   32|       |     */
   33|     18|    __asm__ __volatile__("" : : "r"(ptr) : "memory");
   34|     18|#endif
   35|     18|}

_ZN5ArenaD2Ev:
   48|      2|Arena::~Arena() = default;
_ZN5Arena4freeEPv:
   87|      2|{
   88|       |    // Freeing the nullptr pointer is OK.
   89|      2|    if (ptr == nullptr) {
  ------------------
  |  Branch (89:9): [True: 0, False: 2]
  ------------------
   90|      0|        return;
   91|      0|    }
   92|       |
   93|       |    // Remove chunk from used map
   94|      2|    auto i = chunks_used.find(ptr);
   95|      2|    if (i == chunks_used.end()) {
  ------------------
  |  Branch (95:9): [True: 0, False: 2]
  ------------------
   96|      0|        throw std::runtime_error("Arena: invalid or double free");
   97|      0|    }
   98|      2|    auto freed = std::make_pair(static_cast<char*>(i->first), i->second);
   99|      2|    chunks_used.erase(i);
  100|       |
  101|       |    // coalesce freed with previous chunk
  102|      2|    auto prev = chunks_free_end.find(freed.first);
  103|      2|    if (prev != chunks_free_end.end()) {
  ------------------
  |  Branch (103:9): [True: 2, False: 0]
  ------------------
  104|      2|        freed.first -= prev->second->first;
  105|      2|        freed.second += prev->second->first;
  106|      2|        size_to_free_chunk.erase(prev->second);
  107|      2|        chunks_free_end.erase(prev);
  108|      2|    }
  109|       |
  110|       |    // coalesce freed with chunk after freed
  111|      2|    auto next = chunks_free.find(freed.first + freed.second);
  112|      2|    if (next != chunks_free.end()) {
  ------------------
  |  Branch (112:9): [True: 0, False: 2]
  ------------------
  113|      0|        freed.second += next->second->first;
  114|      0|        size_to_free_chunk.erase(next->second);
  115|      0|        chunks_free.erase(next);
  116|      0|    }
  117|       |
  118|       |    // Add/set space with coalesced free chunk
  119|      2|    auto it = size_to_free_chunk.emplace(freed.second, freed.first);
  120|      2|    chunks_free[freed.first] = it;
  121|      2|    chunks_free_end[freed.first + freed.second] = it;
  122|      2|}
_ZN24PosixLockedPageAllocator10FreeLockedEPvm:
  254|      2|{
  255|      2|    len = align_up(len, page_size);
  256|      2|    memory_cleanse(addr, len);
  257|      2|    munlock(addr, len);
  258|      2|    munmap(addr, len);
  259|      2|}
_ZN10LockedPoolD2Ev:
  283|      2|LockedPool::~LockedPool() = default;
_ZN10LockedPool4freeEPv:
  308|      2|{
  309|      2|    std::lock_guard<std::mutex> lock(mutex);
  310|       |    // TODO we can do better than this linear search by keeping a map of arena
  311|       |    // extents to arena, and looking up the address.
  312|      2|    for (auto &arena: arenas) {
  ------------------
  |  Branch (312:21): [True: 2, False: 0]
  ------------------
  313|      2|        if (arena.addressInArena(ptr)) {
  ------------------
  |  Branch (313:13): [True: 2, False: 0]
  ------------------
  314|      2|            arena.free(ptr);
  315|      2|            return;
  316|      2|        }
  317|      2|    }
  318|      0|    throw std::runtime_error("LockedPool: invalid address not pointing to any arena");
  319|      2|}
_ZN10LockedPool15LockedPageArenaD2Ev:
  370|      2|{
  371|      2|    allocator->FreeLocked(base, size);
  372|      2|}
_ZN17LockedPoolManager8InstanceEv:
  405|      2|{
  406|      2|    static std::once_flag init_flag;
  407|      2|    std::call_once(init_flag, LockedPoolManager::CreateInstance);
  408|      2|    return *LockedPoolManager::_instance;
  409|      2|}
lockedpool.cpp:_ZL8align_upmm:
   32|      2|{
   33|      2|    return (x + align - 1) & ~(align - 1);
   34|      2|}

_ZNK5Arena14addressInArenaEPv:
   90|      2|    bool addressInArena(void *ptr) const { return ptr >= base && ptr < end; }
  ------------------
  |  Branch (90:51): [True: 2, False: 0]
  |  Branch (90:66): [True: 2, False: 0]
  ------------------
_ZN19LockedPageAllocatorD2Ev:
   22|      2|    virtual ~LockedPageAllocator() = default;

_ZN14AnnotatedMixinINSt3__115recursive_mutexEED2Ev:
   96|      2|    ~AnnotatedMixin() {
   97|      2|        DeleteLock((void*)this);
   98|      2|    }
_ZN14AnnotatedMixinINSt3__15mutexEED2Ev:
   96|     68|    ~AnnotatedMixin() {
   97|     68|        DeleteLock((void*)this);
   98|     68|    }
_Z10DeleteLockPv:
   74|     70|inline void DeleteLock(void* cs) {}
_Z17MaybeCheckNotHeldR14AnnotatedMixinINSt3__15mutexEE:
  258|     34|inline Mutex& MaybeCheckNotHeld(Mutex& cs) EXCLUSIVE_LOCKS_REQUIRED(!cs) LOCK_RETURNED(cs) { return cs; }
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEEC2ERS3_PKcS7_ib:
  181|     34|    UniqueLock(MutexType& mutexIn, const char* pszName, const char* pszFile, int nLine, bool fTry = false) EXCLUSIVE_LOCK_FUNCTION(mutexIn) : Base(mutexIn, std::defer_lock)
  182|     34|    {
  183|     34|        if (fTry)
  ------------------
  |  Branch (183:13): [True: 0, False: 34]
  ------------------
  184|      0|            TryEnter(pszName, pszFile, nLine);
  185|     34|        else
  186|     34|            Enter(pszName, pszFile, nLine);
  187|     34|    }
_Z13EnterCriticalINSt3__15mutexEEvPKcS3_iPT_b:
   67|     34|inline void EnterCritical(const char* pszName, const char* pszFile, int nLine, MutexType* cs, bool fTry = false) {}
_Z13LeaveCriticalv:
   68|     34|inline void LeaveCritical() {}
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEE5EnterEPKcS6_i:
  159|     34|    {
  160|     34|        EnterCritical(pszName, pszFile, nLine, Base::mutex());
  161|       |#ifdef DEBUG_LOCKCONTENTION
  162|       |        if (!Base::try_lock()) {
  163|       |            ContendedLock(pszName, pszFile, nLine, static_cast<Base&>(*this));
  164|       |        }
  165|       |#else
  166|     34|        Base::lock();
  167|     34|#endif
  168|     34|    }
_ZN10UniqueLockI14AnnotatedMixinINSt3__15mutexEEED2Ev:
  201|     34|    {
  202|     34|        if (Base::owns_lock())
  ------------------
  |  Branch (202:13): [True: 34, False: 0]
  ------------------
  203|     34|            LeaveCritical();
  204|     34|    }

_ZN18FuzzedDataProviderC2EPKhm:
   37|  6.66k|      : data_ptr_(data), remaining_bytes_(size) {}
_ZN18FuzzedDataProvider11ConsumeBoolEv:
  289|  13.8M|inline bool FuzzedDataProvider::ConsumeBool() {
  290|  13.8M|  return 1 & ConsumeIntegral<uint8_t>();
  291|  13.8M|}
_ZN18FuzzedDataProvider15ConsumeIntegralIhEET_v:
  195|  13.8M|template <typename T> T FuzzedDataProvider::ConsumeIntegral() {
  196|  13.8M|  return ConsumeIntegralInRange(std::numeric_limits<T>::min(),
  197|  13.8M|                                std::numeric_limits<T>::max());
  198|  13.8M|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeIhEET_S1_S1_:
  205|  13.8M|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|  13.8M|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|  13.8M|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|  13.8M|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 13.8M]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|  13.8M|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|  13.8M|  uint64_t result = 0;
  215|  13.8M|  size_t offset = 0;
  216|       |
  217|  27.6M|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 13.8M, False: 13.8M]
  |  Branch (217:43): [True: 13.8M, False: 0]
  ------------------
  218|  13.8M|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 13.8M, False: 10.3k]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|  13.8M|    --remaining_bytes_;
  226|  13.8M|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|  13.8M|    offset += CHAR_BIT;
  228|  13.8M|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|  13.8M|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 13.8M, False: 0]
  ------------------
  232|  13.8M|    result = result % (range + 1);
  233|       |
  234|  13.8M|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|  13.8M|}
_ZN18FuzzedDataProvider25ConsumeRandomLengthStringEm:
  153|  24.6k|FuzzedDataProvider::ConsumeRandomLengthString(size_t max_length) {
  154|       |  // Reads bytes from the start of |data_ptr_|. Maps "\\" to "\", and maps "\"
  155|       |  // followed by anything else to the end of the string. As a result of this
  156|       |  // logic, a fuzzer can insert characters into the string, and the string
  157|       |  // will be lengthened to include those new characters, resulting in a more
  158|       |  // stable fuzzer than picking the length of a string independently from
  159|       |  // picking its contents.
  160|  24.6k|  std::string result;
  161|       |
  162|       |  // Reserve the anticipated capacity to prevent several reallocations.
  163|  24.6k|  result.reserve(std::min(max_length, remaining_bytes_));
  164|  52.2M|  for (size_t i = 0; i < max_length && remaining_bytes_ != 0; ++i) {
  ------------------
  |  Branch (164:22): [True: 52.2M, False: 17.4k]
  |  Branch (164:40): [True: 52.2M, False: 955]
  ------------------
  165|  52.2M|    char next = ConvertUnsignedToSigned<char>(data_ptr_[0]);
  166|  52.2M|    Advance(1);
  167|  52.2M|    if (next == '\\' && remaining_bytes_ != 0) {
  ------------------
  |  Branch (167:9): [True: 18.4k, False: 52.2M]
  |  Branch (167:25): [True: 18.4k, False: 9]
  ------------------
  168|  18.4k|      next = ConvertUnsignedToSigned<char>(data_ptr_[0]);
  169|  18.4k|      Advance(1);
  170|  18.4k|      if (next != '\\')
  ------------------
  |  Branch (170:11): [True: 6.26k, False: 12.1k]
  ------------------
  171|  6.26k|        break;
  172|  18.4k|    }
  173|  52.2M|    result += next;
  174|  52.2M|  }
  175|       |
  176|  24.6k|  result.shrink_to_fit();
  177|  24.6k|  return result;
  178|  24.6k|}
_ZN18FuzzedDataProvider25ConsumeRandomLengthStringEv:
  181|  6.66k|inline std::string FuzzedDataProvider::ConsumeRandomLengthString() {
  182|  6.66k|  return ConsumeRandomLengthString(remaining_bytes_);
  183|  6.66k|}
_ZN18FuzzedDataProvider7AdvanceEm:
  343|  52.2M|inline void FuzzedDataProvider::Advance(size_t num_bytes) {
  344|  52.2M|  if (num_bytes > remaining_bytes_)
  ------------------
  |  Branch (344:7): [True: 0, False: 52.2M]
  ------------------
  345|      0|    abort();
  346|       |
  347|  52.2M|  data_ptr_ += num_bytes;
  348|  52.2M|  remaining_bytes_ -= num_bytes;
  349|  52.2M|}
_ZN18FuzzedDataProvider23ConvertUnsignedToSignedIchEET_T0_:
  378|  52.2M|TS FuzzedDataProvider::ConvertUnsignedToSigned(TU value) {
  379|  52.2M|  static_assert(sizeof(TS) == sizeof(TU), "Incompatible data types.");
  380|  52.2M|  static_assert(!std::numeric_limits<TU>::is_signed,
  381|  52.2M|                "Source type must be unsigned.");
  382|       |
  383|       |  if constexpr (std::numeric_limits<TS>::is_modulo)
  384|       |    return static_cast<TS>(value);
  385|       |
  386|       |  // Avoid using implementation-defined unsigned to signed conversions.
  387|       |  // To learn more, see https://stackoverflow.com/questions/13150449.
  388|  52.2M|  constexpr auto TS_max = static_cast<TU>(std::numeric_limits<TS>::max());
  389|  52.2M|  if (value <= TS_max) {
  ------------------
  |  Branch (389:7): [True: 48.7M, False: 3.45M]
  ------------------
  390|  48.7M|    return static_cast<TS>(value);
  391|  48.7M|  } else {
  392|  3.45M|    constexpr auto TS_min = std::numeric_limits<TS>::min();
  393|  3.45M|    return TS_min + static_cast<TS>(value - TS_min);
  394|  3.45M|  }
  395|  52.2M|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeImEET_S1_S1_:
  205|  12.6M|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|  12.6M|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|  12.6M|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|  12.6M|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 12.6M]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|  12.6M|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|  12.6M|  uint64_t result = 0;
  215|  12.6M|  size_t offset = 0;
  216|       |
  217|  25.2M|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 25.2M, False: 0]
  |  Branch (217:43): [True: 12.6M, False: 12.6M]
  ------------------
  218|  12.6M|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 12.6M, False: 2.49k]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|  12.6M|    --remaining_bytes_;
  226|  12.6M|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|  12.6M|    offset += CHAR_BIT;
  228|  12.6M|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|  12.6M|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 12.6M, False: 0]
  ------------------
  232|  12.6M|    result = result % (range + 1);
  233|       |
  234|  12.6M|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|  12.6M|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeIjEET_S1_S1_:
  205|  11.2M|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|  11.2M|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|  11.2M|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|  11.2M|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 11.2M]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|  11.2M|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|  11.2M|  uint64_t result = 0;
  215|  11.2M|  size_t offset = 0;
  216|       |
  217|  22.5M|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 22.5M, False: 0]
  |  Branch (217:43): [True: 11.2M, False: 11.2M]
  ------------------
  218|  11.2M|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 11.2M, False: 124]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|  11.2M|    --remaining_bytes_;
  226|  11.2M|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|  11.2M|    offset += CHAR_BIT;
  228|  11.2M|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|  11.2M|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 11.2M, False: 0]
  ------------------
  232|  11.2M|    result = result % (range + 1);
  233|       |
  234|  11.2M|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|  11.2M|}
_ZN18FuzzedDataProvider15ConsumeIntegralIlEET_v:
  195|  52.7k|template <typename T> T FuzzedDataProvider::ConsumeIntegral() {
  196|  52.7k|  return ConsumeIntegralInRange(std::numeric_limits<T>::min(),
  197|  52.7k|                                std::numeric_limits<T>::max());
  198|  52.7k|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeIlEET_S1_S1_:
  205|   274k|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|   274k|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|   274k|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|   274k|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 274k]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|   274k|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|   274k|  uint64_t result = 0;
  215|   274k|  size_t offset = 0;
  216|       |
  217|   916k|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 863k, False: 52.6k]
  |  Branch (217:43): [True: 642k, False: 221k]
  ------------------
  218|   642k|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 642k, False: 431]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|   642k|    --remaining_bytes_;
  226|   642k|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|   642k|    offset += CHAR_BIT;
  228|   642k|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|   274k|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 221k, False: 52.7k]
  ------------------
  232|   221k|    result = result % (range + 1);
  233|       |
  234|   274k|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|   274k|}
_ZN18FuzzedDataProvider22ConsumeIntegralInRangeIiEET_S1_S1_:
  205|   110k|T FuzzedDataProvider::ConsumeIntegralInRange(T min, T max) {
  206|   110k|  static_assert(std::is_integral_v<T>, "An integral type is required.");
  207|   110k|  static_assert(sizeof(T) <= sizeof(uint64_t), "Unsupported integral type.");
  208|       |
  209|   110k|  if (min > max)
  ------------------
  |  Branch (209:7): [True: 0, False: 110k]
  ------------------
  210|      0|    abort();
  211|       |
  212|       |  // Use the biggest type possible to hold the range and the result.
  213|   110k|  uint64_t range = static_cast<uint64_t>(max) - static_cast<uint64_t>(min);
  214|   110k|  uint64_t result = 0;
  215|   110k|  size_t offset = 0;
  216|       |
  217|   221k|  while (offset < sizeof(T) * CHAR_BIT && (range >> offset) > 0 &&
  ------------------
  |  Branch (217:10): [True: 221k, False: 0]
  |  Branch (217:43): [True: 110k, False: 110k]
  ------------------
  218|   110k|         remaining_bytes_ != 0) {
  ------------------
  |  Branch (218:10): [True: 110k, False: 71]
  ------------------
  219|       |    // Pull bytes off the end of the seed data. Experimentally, this seems to
  220|       |    // allow the fuzzer to more easily explore the input space. This makes
  221|       |    // sense, since it works by modifying inputs that caused new code to run,
  222|       |    // and this data is often used to encode length of data read by
  223|       |    // |ConsumeBytes|. Separating out read lengths makes it easier modify the
  224|       |    // contents of the data that is actually read.
  225|   110k|    --remaining_bytes_;
  226|   110k|    result = (result << CHAR_BIT) | data_ptr_[remaining_bytes_];
  227|   110k|    offset += CHAR_BIT;
  228|   110k|  }
  229|       |
  230|       |  // Avoid division by 0, in case |range + 1| results in overflow.
  231|   110k|  if (range != std::numeric_limits<decltype(range)>::max())
  ------------------
  |  Branch (231:7): [True: 110k, False: 0]
  ------------------
  232|   110k|    result = result % (range + 1);
  233|       |
  234|   110k|  return static_cast<T>(static_cast<uint64_t>(min) + result);
  235|   110k|}
_ZN18FuzzedDataProvider16PickValueInArrayIiEET_St16initializer_listIKS1_E:
  316|  1.19M|T FuzzedDataProvider::PickValueInArray(std::initializer_list<const T> list) {
  317|  1.19M|  if (!list.size())
  ------------------
  |  Branch (317:7): [True: 0, False: 1.19M]
  ------------------
  318|      0|    abort();
  319|       |
  320|  1.19M|  return *(list.begin() + ConsumeIntegralInRange<size_t>(0, list.size() - 1));
  321|  1.19M|}

LLVMFuzzerTestOneInput:
  213|  6.66k|{
  214|  6.66k|    test_one_input({data, size});
  215|  6.66k|    return 0;
  216|  6.66k|}
fuzz.cpp:_ZL14test_one_inputNSt3__14spanIKhLm18446744073709551615EEE:
   84|  6.66k|{
   85|  6.66k|    CheckGlobals check{};
   86|  6.66k|    (*Assert(g_test_one_input))(buffer);
  ------------------
  |  |  116|  6.66k|#define Assert(val) inline_assertion_check<true>(val, std::source_location::current(), #val)
  ------------------
   87|  6.66k|}

_Z18signet_fuzz_targetNSt3__14spanIKhLm18446744073709551615EEE:
   26|  6.66k|{
   27|  6.66k|    FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
   28|  6.66k|    const std::optional<CBlock> block = ConsumeDeserializable<CBlock>(fuzzed_data_provider, TX_WITH_WITNESS);
   29|  6.66k|    if (!block) {
  ------------------
  |  Branch (29:9): [True: 967, False: 5.69k]
  ------------------
   30|    967|        return;
   31|    967|    }
   32|  5.69k|    (void)CheckSignetBlockSolution(*block, Params().GetConsensus());
   33|  5.69k|    (void)SignetTxs::Create(*block, ConsumeScript(fuzzed_data_provider));
   34|  5.69k|}

_Z20ConstructPubKeyBytesR18FuzzedDataProviderNSt3__14spanIKhLm18446744073709551615EEEb:
   17|  1.19M|{
   18|  1.19M|    uint8_t pk_type;
   19|  1.19M|    if (compressed) {
  ------------------
  |  Branch (19:9): [True: 1.14M, False: 45.5k]
  ------------------
   20|  1.14M|        pk_type = fuzzed_data_provider.PickValueInArray({0x02, 0x03});
   21|  1.14M|    } else {
   22|  45.5k|        pk_type = fuzzed_data_provider.PickValueInArray({0x04, 0x06, 0x07});
   23|  45.5k|    }
   24|  1.19M|    std::vector<uint8_t> pk_data{byte_data.begin(), byte_data.begin() + (compressed ? CPubKey::COMPRESSED_SIZE : CPubKey::SIZE)};
  ------------------
  |  Branch (24:74): [True: 1.14M, False: 45.5k]
  ------------------
   25|  1.19M|    pk_data[0] = pk_type;
   26|  1.19M|    return pk_data;
   27|  1.19M|}
_Z13ConsumeScriptR18FuzzedDataProviderb:
   94|  5.69k|{
   95|  5.69k|    CScript r_script{};
   96|  5.69k|    {
   97|       |        // Keep a buffer of bytes to allow the fuzz engine to produce smaller
   98|       |        // inputs to generate CScripts with repeated data.
   99|  5.69k|        static constexpr unsigned MAX_BUFFER_SZ{128};
  100|  5.69k|        std::vector<uint8_t> buffer(MAX_BUFFER_SZ, uint8_t{'a'});
  101|  11.4M|        while (fuzzed_data_provider.ConsumeBool()) {
  ------------------
  |  Branch (101:16): [True: 11.4M, False: 5.69k]
  ------------------
  102|  11.4M|            CallOneOf(
  103|  11.4M|                fuzzed_data_provider,
  104|  11.4M|                [&] {
  105|       |                    // Insert byte vector directly to allow malformed or unparsable scripts
  106|  11.4M|                    r_script.insert(r_script.end(), buffer.begin(), buffer.begin() + fuzzed_data_provider.ConsumeIntegralInRange(0U, MAX_BUFFER_SZ));
  107|  11.4M|                },
  108|  11.4M|                [&] {
  109|       |                    // Push a byte vector from the buffer
  110|  11.4M|                    r_script << std::vector<uint8_t>{buffer.begin(), buffer.begin() + fuzzed_data_provider.ConsumeIntegralInRange(0U, MAX_BUFFER_SZ)};
  111|  11.4M|                },
  112|  11.4M|                [&] {
  113|       |                    // Push multisig
  114|       |                    // There is a special case for this to aid the fuzz engine
  115|       |                    // navigate the highly structured multisig format.
  116|  11.4M|                    r_script << fuzzed_data_provider.ConsumeIntegralInRange<int64_t>(0, 22);
  117|  11.4M|                    int num_data{fuzzed_data_provider.ConsumeIntegralInRange(1, 22)};
  118|  11.4M|                    while (num_data--) {
  119|  11.4M|                        auto pubkey_bytes{ConstructPubKeyBytes(fuzzed_data_provider, buffer, fuzzed_data_provider.ConsumeBool())};
  120|  11.4M|                        if (fuzzed_data_provider.ConsumeBool()) {
  121|  11.4M|                            pubkey_bytes.back() = num_data; // Make each pubkey different
  122|  11.4M|                        }
  123|  11.4M|                        r_script << pubkey_bytes;
  124|  11.4M|                    }
  125|  11.4M|                    r_script << fuzzed_data_provider.ConsumeIntegralInRange<int64_t>(0, 22);
  126|  11.4M|                },
  127|  11.4M|                [&] {
  128|       |                    // Mutate the buffer
  129|  11.4M|                    const auto vec{ConsumeRandomLengthByteVector(fuzzed_data_provider, /*max_length=*/MAX_BUFFER_SZ)};
  130|  11.4M|                    std::copy(vec.begin(), vec.end(), buffer.begin());
  131|  11.4M|                },
  132|  11.4M|                [&] {
  133|       |                    // Push an integral
  134|  11.4M|                    r_script << fuzzed_data_provider.ConsumeIntegral<int64_t>();
  135|  11.4M|                },
  136|  11.4M|                [&] {
  137|       |                    // Push an opcode
  138|  11.4M|                    r_script << ConsumeOpcodeType(fuzzed_data_provider);
  139|  11.4M|                },
  140|  11.4M|                [&] {
  141|       |                    // Push a scriptnum
  142|  11.4M|                    r_script << ConsumeScriptNum(fuzzed_data_provider);
  143|  11.4M|                });
  144|  11.4M|        }
  145|  5.69k|    }
  146|  5.69k|    if (maybe_p2wsh && fuzzed_data_provider.ConsumeBool()) {
  ------------------
  |  Branch (146:9): [True: 0, False: 5.69k]
  |  Branch (146:24): [True: 0, False: 0]
  ------------------
  147|      0|        uint256 script_hash;
  148|      0|        CSHA256().Write(r_script.data(), r_script.size()).Finalize(script_hash.begin());
  149|      0|        r_script.clear();
  150|      0|        r_script << OP_0 << ToByteVector(script_hash);
  151|      0|    }
  152|  5.69k|    return r_script;
  153|  5.69k|}
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_0clEv:
  104|  2.06M|                [&] {
  105|       |                    // Insert byte vector directly to allow malformed or unparsable scripts
  106|  2.06M|                    r_script.insert(r_script.end(), buffer.begin(), buffer.begin() + fuzzed_data_provider.ConsumeIntegralInRange(0U, MAX_BUFFER_SZ));
  107|  2.06M|                },
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_1clEv:
  108|  9.12M|                [&] {
  109|       |                    // Push a byte vector from the buffer
  110|  9.12M|                    r_script << std::vector<uint8_t>{buffer.begin(), buffer.begin() + fuzzed_data_provider.ConsumeIntegralInRange(0U, MAX_BUFFER_SZ)};
  111|  9.12M|                },
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_2clEv:
  112|   110k|                [&] {
  113|       |                    // Push multisig
  114|       |                    // There is a special case for this to aid the fuzz engine
  115|       |                    // navigate the highly structured multisig format.
  116|   110k|                    r_script << fuzzed_data_provider.ConsumeIntegralInRange<int64_t>(0, 22);
  117|   110k|                    int num_data{fuzzed_data_provider.ConsumeIntegralInRange(1, 22)};
  118|  1.30M|                    while (num_data--) {
  ------------------
  |  Branch (118:28): [True: 1.19M, False: 110k]
  ------------------
  119|  1.19M|                        auto pubkey_bytes{ConstructPubKeyBytes(fuzzed_data_provider, buffer, fuzzed_data_provider.ConsumeBool())};
  120|  1.19M|                        if (fuzzed_data_provider.ConsumeBool()) {
  ------------------
  |  Branch (120:29): [True: 1.15M, False: 39.7k]
  ------------------
  121|  1.15M|                            pubkey_bytes.back() = num_data; // Make each pubkey different
  122|  1.15M|                        }
  123|  1.19M|                        r_script << pubkey_bytes;
  124|  1.19M|                    }
  125|   110k|                    r_script << fuzzed_data_provider.ConsumeIntegralInRange<int64_t>(0, 22);
  126|   110k|                },
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_3clEv:
  127|  18.0k|                [&] {
  128|       |                    // Mutate the buffer
  129|  18.0k|                    const auto vec{ConsumeRandomLengthByteVector(fuzzed_data_provider, /*max_length=*/MAX_BUFFER_SZ)};
  130|  18.0k|                    std::copy(vec.begin(), vec.end(), buffer.begin());
  131|  18.0k|                },
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_4clEv:
  132|  26.0k|                [&] {
  133|       |                    // Push an integral
  134|  26.0k|                    r_script << fuzzed_data_provider.ConsumeIntegral<int64_t>();
  135|  26.0k|                },
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_5clEv:
  136|  68.0k|                [&] {
  137|       |                    // Push an opcode
  138|  68.0k|                    r_script << ConsumeOpcodeType(fuzzed_data_provider);
  139|  68.0k|                },
util.cpp:_ZZ13ConsumeScriptR18FuzzedDataProviderbENK3$_6clEv:
  140|  26.7k|                [&] {
  141|       |                    // Push a scriptnum
  142|  26.7k|                    r_script << ConsumeScriptNum(fuzzed_data_provider);
  143|  26.7k|                });

_Z21ConsumeDeserializableI6CBlock20TransactionSerParamsENSt3__18optionalIT_EER18FuzzedDataProviderRKT0_RKNS3_ImEE:
  107|  6.66k|{
  108|  6.66k|    const std::vector<uint8_t> buffer{ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length)};
  109|  6.66k|    SpanReader ds{buffer};
  110|  6.66k|    T obj;
  111|  6.66k|    try {
  112|  6.66k|        ds >> params(obj);
  113|  6.66k|    } catch (const std::ios_base::failure&) {
  114|    967|        return std::nullopt;
  115|    967|    }
  116|  5.69k|    return obj;
  117|  6.66k|}
_Z17ConsumeOpcodeTypeR18FuzzedDataProvider:
  155|  68.0k|{
  156|  68.0k|    return static_cast<opcodetype>(fuzzed_data_provider.ConsumeIntegralInRange<uint32_t>(0, MAX_OPCODE));
  157|  68.0k|}
_Z16ConsumeScriptNumR18FuzzedDataProvider:
  182|  26.7k|{
  183|  26.7k|    return CScriptNum{fuzzed_data_provider.ConsumeIntegral<int64_t>()};
  184|  26.7k|}
_Z29ConsumeRandomLengthByteVectorIhENSt3__16vectorIT_NS0_9allocatorIS2_EEEER18FuzzedDataProviderRKNS0_8optionalImEE:
   64|  24.6k|{
   65|  24.6k|    static_assert(sizeof(B) == 1);
   66|  24.6k|    const std::string s = max_length ?
  ------------------
  |  Branch (66:27): [True: 18.0k, False: 6.66k]
  ------------------
   67|  18.0k|                              fuzzed_data_provider.ConsumeRandomLengthString(*max_length) :
   68|  24.6k|                              fuzzed_data_provider.ConsumeRandomLengthString();
   69|  24.6k|    std::vector<B> ret(s.size());
   70|  24.6k|    std::copy(s.begin(), s.end(), reinterpret_cast<char*>(ret.data()));
   71|  24.6k|    return ret;
   72|  24.6k|}
util.cpp:_Z9CallOneOfIJZ13ConsumeScriptR18FuzzedDataProviderbE3$_0Z13ConsumeScriptS1_bE3$_1Z13ConsumeScriptS1_bE3$_2Z13ConsumeScriptS1_bE3$_3Z13ConsumeScriptS1_bE3$_4Z13ConsumeScriptS1_bE3$_5Z13ConsumeScriptS1_bE3$_6EEmS1_DpT_:
   38|  11.4M|{
   39|  11.4M|    constexpr size_t call_size{sizeof...(callables)};
   40|  11.4M|    static_assert(call_size >= 1);
   41|  11.4M|    const size_t call_index{fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, call_size - 1)};
   42|       |
   43|  11.4M|    size_t i{0};
   44|  80.0M|    ((i++ == call_index ? callables() : void()), ...);
  ------------------
  |  Branch (44:7): [True: 2.06M, False: 9.37M]
  |  Branch (44:7): [True: 9.12M, False: 2.30M]
  |  Branch (44:7): [True: 110k, False: 11.3M]
  |  Branch (44:7): [True: 18.0k, False: 11.4M]
  |  Branch (44:7): [True: 26.0k, False: 11.4M]
  |  Branch (44:7): [True: 68.0k, False: 11.3M]
  |  Branch (44:7): [True: 26.7k, False: 11.4M]
  ------------------
   45|  11.4M|    return call_size;
   46|  11.4M|}

_ZN12CheckGlobalsC2Ev:
   59|  6.66k|CheckGlobals::CheckGlobals() : m_impl(std::make_unique<CheckGlobalsImpl>()) {}
_ZN12CheckGlobalsD2Ev:
   60|  6.66k|CheckGlobals::~CheckGlobals() = default;
_ZN16CheckGlobalsImplC2Ev:
   17|  6.66k|    {
   18|  6.66k|        g_used_g_prng = false;
   19|  6.66k|        g_seeded_g_prng_zero = false;
   20|  6.66k|        g_used_system_time = false;
   21|  6.66k|        SetMockTime(0s);
   22|  6.66k|        MockableSteadyClock::ClearMockTime();
   23|  6.66k|    }
_ZN16CheckGlobalsImplD2Ev:
   25|  6.66k|    {
   26|  6.66k|        if (g_used_g_prng && !g_seeded_g_prng_zero) {
  ------------------
  |  Branch (26:13): [True: 2, False: 6.66k]
  |  Branch (26:30): [True: 0, False: 2]
  ------------------
   27|      0|            std::cerr << "\n\n"
   28|      0|                         "The current fuzz target used the global random state.\n\n"
   29|       |
   30|      0|                         "This is acceptable, but requires the fuzz target to call \n"
   31|      0|                         "SeedRandomStateForTest(SeedRand::ZEROS) in the first line \n"
   32|      0|                         "of the FUZZ_TARGET function.\n\n"
   33|       |
   34|      0|                         "An alternative solution would be to avoid any use of globals.\n\n"
   35|       |
   36|      0|                         "Without a solution, fuzz instability and non-determinism can lead \n"
   37|      0|                         "to non-reproducible bugs or inefficient fuzzing.\n\n"
   38|      0|                      << std::endl;
   39|      0|            std::abort(); // Abort, because AFL may try to recover from a std::exit
   40|      0|        }
   41|       |
   42|  6.66k|        if (g_used_system_time) {
  ------------------
  |  Branch (42:13): [True: 0, False: 6.66k]
  ------------------
   43|      0|            std::cerr << "\n\n"
   44|      0|                         "The current fuzz target accessed system time.\n\n"
   45|       |
   46|      0|                         "This is acceptable, but requires the fuzz target to use \n"
   47|      0|                         "a FakeNodeClock, FakeSteadyClock or call \n"
   48|      0|                         "SetMockTime() at the \n" "beginning of processing the \n"
   49|      0|                         "fuzz input.\n\n"
   50|       |
   51|      0|                         "Without setting mock time, time-dependent behavior can lead \n"
   52|      0|                         "to non-reproducible bugs or inefficient fuzzing.\n\n"
   53|      0|                      << std::endl;
   54|      0|            std::abort();
   55|      0|        }
   56|  6.66k|    }

__gcov_reset:
   13|      2|extern "C" __attribute__((weak)) void __gcov_reset(void) {}

_ZN17BasicTestingSetupD2Ev:
  252|      2|{
  253|      2|    m_node.ecc_context.reset();
  254|      2|    m_node.kernel.reset();
  255|      2|    if (!EnableFuzzDeterminism()) {
  ------------------
  |  Branch (255:9): [True: 0, False: 2]
  ------------------
  256|      0|        SetMockTime(0s); // Reset mocktime for following tests
  257|      0|    }
  258|      2|    LogInstance().DisconnectTestLogger();
  259|      2|    if (m_has_custom_datadir) {
  ------------------
  |  Branch (259:9): [True: 0, False: 2]
  ------------------
  260|       |        // Only remove the lock file, preserve the data directory.
  261|      0|        UnlockDirectory(m_path_lock, ".lock");
  262|      0|        fs::remove(m_path_lock / ".lock");
  263|      2|    } else {
  264|      2|        fs::remove_all(m_path_root);
  265|      2|    }
  266|       |    // Clear all arguments except for -datadir, which GUI tests currently rely
  267|       |    // on to be set even after the testing setup is destroyed.
  268|      2|    gArgs.ClearArgs();
  269|      2|    gArgs.ForceSetArg("-datadir", fs::PathToString(m_path_root));
  270|      2|}

_ZN9base_blobILj256EE11UnserializeI12ParamsStreamIR10SpanReader20TransactionSerParamsEEEvRT_:
  119|   142k|    {
  120|   142k|        s.read(MakeWritableByteSpan(m_data));
  121|   142k|    }
_ZNK9base_blobILj256EE9SerializeI12VectorWriterEEvRT_:
  113|  16.4k|    {
  114|  16.4k|        s << std::span(m_data);
  115|  16.4k|    }
_ZN9base_blobILj256EE7SetNullEv:
   58|  26.6k|    {
   59|  26.6k|        std::fill(m_data.begin(), m_data.end(), 0);
   60|  26.6k|    }
_ZNK9base_blobILj256EEeqERKS0_:
   62|  5.69k|    constexpr bool operator==(const base_blob&) const = default;
_ZNK9base_blobILj256EE9SerializeI12ParamsStreamIR10HashWriter20TransactionSerParamsEEEvRT_:
  113|  54.7k|    {
  114|  54.7k|        s << std::span(m_data);
  115|  54.7k|    }
_ZNK9base_blobILj256EE5beginEv:
  104|  6.36k|    constexpr const unsigned char* begin() const { return m_data.data(); }
_ZN9base_blobILj256EE4dataEv:
   99|      2|    constexpr unsigned char* data() { return m_data.data(); }
_ZNK9base_blobILj256EE9SerializeI10HashWriterEEvRT_:
  113|  14.6k|    {
  114|  14.6k|        s << std::span(m_data);
  115|  14.6k|    }
_ZN7uint256C2Ev:
  200|   867k|    constexpr uint256() = default;
_ZN9base_blobILj256EEC2Ev:
   37|   867k|    constexpr base_blob() : m_data() {}
_ZN9base_blobILj256EE5beginEv:
  101|  1.89M|    constexpr unsigned char* begin() { return m_data.data(); }
_ZN9base_blobILj256EE4sizeEv:
  107|      2|    static constexpr unsigned int size() { return WIDTH; }

_ZN8UniValueC2Ev:
   31|      2|    UniValue() { typ = VNULL; }
_ZN8UniValueC2IRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEES7_TnNS1_9enable_ifIXoooooooosr3stdE19is_floating_point_vIT0_Esr3stdE9is_same_vIbSB_Esr3stdE11is_signed_vISB_Esr3stdE13is_unsigned_vISB_Esr3stdE18is_constructible_vIS7_SB_EEbE4typeELb1EEEOT_:
   40|      2|    {
   41|       |        if constexpr (std::is_floating_point_v<T>) {
   42|       |            setFloat(val);
   43|       |        } else if constexpr (std::is_same_v<bool, T>) {
   44|       |            setBool(val);
   45|       |        } else if constexpr (std::is_signed_v<T>) {
   46|       |            setInt(int64_t{val});
   47|       |        } else if constexpr (std::is_unsigned_v<T>) {
   48|       |            setInt(uint64_t{val});
   49|      2|        } else {
   50|      2|            setStr(std::string{std::forward<Ref>(val)});
   51|      2|        }
   52|      2|    }

_ZN8UniValue5clearEv:
   18|      2|{
   19|      2|    typ = VNULL;
   20|      2|    val.clear();
   21|      2|    keys.clear();
   22|      2|    values.clear();
   23|      2|}
_ZN8UniValue6setStrENSt3__112basic_stringIcNS0_11char_traitsIcEENS0_9allocatorIcEEEE:
   85|      2|{
   86|      2|    clear();
   87|      2|    typ = VSTR;
   88|      2|    val = std::move(str);
   89|      2|}

_ZN10btcsignals6signalIFvvENS_10null_valueEED2Ev:
  175|      6|    ~signal() = default;
_ZN10btcsignals6signalIFv20SynchronizationStatellbENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFv20SynchronizationStateRK11CBlockIndexdENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEibENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvbENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFviENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFbRK13bilingual_strRKNSt3__112basic_stringIcNS4_11char_traitsIcEENS4_9allocatorIcEEEEjENS_6any_ofEED2Ev:
  175|      2|    ~signal() = default;
_ZN10btcsignals6signalIFvRK13bilingual_strjENS_10null_valueEED2Ev:
  175|      2|    ~signal() = default;

_Z22inline_assertion_checkILb1ERPKNSt3__18functionIFvNS0_4spanIKhLm18446744073709551615EEEEEEEOT0_SB_RKNS0_15source_locationENS0_17basic_string_viewIcNS0_11char_traitsIcEEEE:
   90|  6.66k|{
   91|  6.66k|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [True: 6.66k, Folded]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|  6.66k|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 6.66k]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|  6.66k|    }
   96|  6.66k|    return std::forward<T>(val);
   97|  6.66k|}
_Z21EnableFuzzDeterminismv:
   39|      2|{
   40|      2|    if constexpr (G_FUZZING_BUILD) {
   41|      2|        return true;
   42|       |    } else if constexpr (!G_ABORT_ON_FAILED_ASSUME) {
   43|       |        // Running fuzz tests is always disabled if Assume() doesn't abort
   44|       |        // (ie, non-fuzz non-debug builds), as otherwise tests which
   45|       |        // should fail due to a failing Assume may still pass. As such,
   46|       |        // we also statically disable fuzz determinism in that case.
   47|       |        return false;
   48|       |    } else {
   49|       |        return g_enable_dynamic_fuzz_determinism;
   50|       |    }
   51|      2|}
_Z22inline_assertion_checkILb1EbEOT0_S1_RKNSt3__115source_locationENS2_17basic_string_viewIcNS2_11char_traitsIcEEEE:
   90|  6.66k|{
   91|  6.66k|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [True: 6.66k, Folded]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|  6.66k|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 6.66k]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|  6.66k|    }
   96|  6.66k|    return std::forward<T>(val);
   97|  6.66k|}
_Z22inline_assertion_checkILb0EbEOT0_S1_RKNSt3__115source_locationENS2_17basic_string_viewIcNS2_11char_traitsIcEEEE:
   90|     10|{
   91|     10|    if (IS_ASSERT || std::is_constant_evaluated() || G_ABORT_ON_FAILED_ASSUME) {
  ------------------
  |  Branch (91:9): [Folded, False: 0]
  |  Branch (91:22): [Folded, False: 0]
  |  Branch (91:54): [True: 0, Folded]
  ------------------
   92|     10|        if (!val) {
  ------------------
  |  Branch (92:13): [True: 0, False: 10]
  ------------------
   93|      0|            assertion_fail(loc, assertion);
   94|      0|        }
   95|     10|    }
   96|     10|    return std::forward<T>(val);
   97|     10|}

setup_common.cpp:_ZN2fsL12PathToStringERKNS_4pathE:
  163|      2|{
  164|       |    // Implementation note: On Windows, the std::filesystem::path(string)
  165|       |    // constructor and std::filesystem::path::string() method are not safe to
  166|       |    // use here, because these methods encode the path using C++'s narrow
  167|       |    // multibyte encoding, which on Windows corresponds to the current "code
  168|       |    // page", which is unpredictable and typically not able to represent all
  169|       |    // valid paths. So fs::path::utf8string() and
  170|       |    // fs::u8path() functions are used instead on Windows. On
  171|       |    // POSIX, u8string/utf8string/u8path functions are not safe to use because paths are
  172|       |    // not always valid UTF-8, so plain string methods which do not transform
  173|       |    // the path there are used.
  174|       |#ifdef WIN32
  175|       |    return path.utf8string();
  176|       |#else
  177|      2|    static_assert(std::is_same_v<path::string_type, std::string>, "PathToString not implemented on this platform");
  178|      2|    return path.std::filesystem::path::string();
  179|      2|#endif
  180|      2|}

_ZN8StdMutex12CheckNotHeldERS_:
   37|      2|    static inline StdMutex& CheckNotHeld(StdMutex& cs) EXCLUSIVE_LOCKS_REQUIRED(!cs) LOCK_RETURNED(cs) { return cs; }
_ZN8StdMutex5GuardC2ERS_:
   33|      2|        explicit Guard(StdMutex& cs) EXCLUSIVE_LOCK_FUNCTION(cs) : std::lock_guard<StdMutex>(cs) {}

_ZN16CThreadInterruptD2Ev:
   32|      4|    virtual ~CThreadInterrupt() = default;

_ZN10ThreadPoolD2Ev:
   93|     10|    {
   94|     10|        Stop(); // In case it hasn't been stopped.
   95|     10|    }
_ZN10ThreadPool4StopEv:
  129|     10|    {
  130|       |        // Notify workers and join them
  131|     10|        std::vector<std::thread> threads_to_join;
  132|     10|        {
  133|     10|            LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  134|       |            // Ensure Stop() is not called from a worker thread while workers are still registered,
  135|       |            // otherwise a self-join deadlock would occur.
  136|     10|            auto id = std::this_thread::get_id();
  137|     10|            for (const auto& worker : m_workers) assert(worker.get_id() != id);
  ------------------
  |  Branch (137:37): [True: 0, False: 10]
  |  Branch (137:50): [True: 0, False: 0]
  ------------------
  138|       |            // Early shutdown to return right away on any concurrent Submit() call
  139|     10|            m_interrupt = true;
  140|     10|            threads_to_join.swap(m_workers);
  141|     10|        }
  142|      0|        m_cv.notify_all();
  143|       |        // Help draining queue
  144|     10|        while (ProcessTask()) {}
  ------------------
  |  Branch (144:16): [True: 0, False: 10]
  ------------------
  145|       |        // Free resources
  146|     10|        for (auto& worker : threads_to_join) worker.join();
  ------------------
  |  Branch (146:27): [True: 0, False: 10]
  ------------------
  147|       |
  148|       |        // Since we currently wait for tasks completion, sanity-check empty queue
  149|     10|        LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  150|     10|        Assume(m_work_queue.empty());
  ------------------
  |  |  128|     10|#define Assume(val) inline_assertion_check<false>(val, std::source_location::current(), #val)
  ------------------
  151|       |        // Re-allow Start() now that all workers have exited
  152|     10|        m_interrupt = false;
  153|     10|    }
_ZN10ThreadPool11ProcessTaskEv:
  244|     10|    {
  245|     10|        std::packaged_task<void()> task;
  246|     10|        {
  247|     10|            LOCK(m_mutex);
  ------------------
  |  |  268|     10|#define LOCK(cs) UniqueLock BITCOIN_UNIQUE_NAME(criticalblock)(MaybeCheckNotHeld(cs), #cs, __FILE__, __LINE__)
  |  |  ------------------
  |  |  |  |   11|     10|#define BITCOIN_UNIQUE_NAME(name) PASTE2(name, __COUNTER__)
  |  |  |  |  ------------------
  |  |  |  |  |  |    9|     10|#define PASTE2(x, y) PASTE(x, y)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |    8|     10|#define PASTE(x, y) x ## y
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  248|     10|            if (m_work_queue.empty()) return false;
  ------------------
  |  Branch (248:17): [True: 10, False: 0]
  ------------------
  249|       |
  250|       |            // Pop the task
  251|      0|            task = std::move(m_work_queue.front());
  252|      0|            m_work_queue.pop();
  253|      0|        }
  254|      0|        task();
  255|      0|        return true;
  256|     10|    }

_Z11SetMockTimeNSt3__16chrono8durationIxNS_5ratioILl1ELl1EEEEE:
   54|  6.66k|{
   55|  6.66k|    Assert(mock_time_in >= 0s);
  ------------------
  |  |  116|  6.66k|#define Assert(val) inline_assertion_check<true>(val, std::source_location::current(), #val)
  ------------------
   56|  6.66k|    g_mock_time.store(mock_time_in, std::memory_order_relaxed);
   57|  6.66k|}
_ZN19MockableSteadyClock13ClearMockTimeEv:
   84|  6.66k|{
   85|  6.66k|    g_mock_steady_time.store(0ms, std::memory_order_relaxed);
   86|  6.66k|}

_ZN12TokenPipeEndD2Ev:
   37|      4|{
   38|      4|    Close();
   39|      4|}
_ZN12TokenPipeEnd5CloseEv:
   80|      4|{
   81|      4|    if (m_fd != -1) close(m_fd);
  ------------------
  |  Branch (81:9): [True: 4, False: 0]
  ------------------
   82|      4|    m_fd = -1;
   83|      4|}

_ZN19WalletInitInterfaceD2Ev:
   25|      2|    virtual ~WalletInitInterface() = default;

