CBS_init:
   29|  5.38k|void CBS_init(CBS *cbs, const uint8_t *data, size_t len) {
   30|  5.38k|  cbs->data = data;
   31|  5.38k|  cbs->len = len;
   32|  5.38k|}
CBS_data:
   50|  3.50k|const uint8_t *CBS_data(const CBS *cbs) {
   51|  3.50k|  return cbs->data;
   52|  3.50k|}
CBS_len:
   54|  7.04k|size_t CBS_len(const CBS *cbs) {
   55|  7.04k|  return cbs->len;
   56|  7.04k|}
CBS_get_u8:
  108|  3.56k|int CBS_get_u8(CBS *cbs, uint8_t *out) {
  109|  3.56k|  const uint8_t *v;
  110|  3.56k|  if (!cbs_get(cbs, &v, 1)) {
  ------------------
  |  Branch (110:7): [True: 27, False: 3.53k]
  ------------------
  111|     27|    return 0;
  112|     27|  }
  113|  3.53k|  *out = *v;
  114|  3.53k|  return 1;
  115|  3.56k|}
CBS_get_bytes:
  181|  3.57k|int CBS_get_bytes(CBS *cbs, CBS *out, size_t len) {
  182|  3.57k|  const uint8_t *v;
  183|  3.57k|  if (!cbs_get(cbs, &v, len)) {
  ------------------
  |  Branch (183:7): [True: 18, False: 3.56k]
  ------------------
  184|     18|    return 0;
  185|     18|  }
  186|  3.56k|  CBS_init(out, v, len);
  187|  3.56k|  return 1;
  188|  3.57k|}
CBS_get_u16_length_prefixed:
  214|  3.59k|int CBS_get_u16_length_prefixed(CBS *cbs, CBS *out) {
  215|  3.59k|  return cbs_get_length_prefixed(cbs, out, 2);
  216|  3.59k|}
cbs.c:cbs_get:
   34|  10.7k|static int cbs_get(CBS *cbs, const uint8_t **p, size_t n) {
   35|  10.7k|  if (cbs->len < n) {
  ------------------
  |  Branch (35:7): [True: 63, False: 10.6k]
  ------------------
   36|     63|    return 0;
   37|     63|  }
   38|       |
   39|  10.6k|  *p = cbs->data;
   40|  10.6k|  cbs->data += n;
   41|  10.6k|  cbs->len -= n;
   42|  10.6k|  return 1;
   43|  10.7k|}
cbs.c:cbs_get_u:
   93|  3.59k|static int cbs_get_u(CBS *cbs, uint64_t *out, size_t len) {
   94|  3.59k|  uint64_t result = 0;
   95|  3.59k|  const uint8_t *data;
   96|       |
   97|  3.59k|  if (!cbs_get(cbs, &data, len)) {
  ------------------
  |  Branch (97:7): [True: 18, False: 3.57k]
  ------------------
   98|     18|    return 0;
   99|     18|  }
  100|  10.7k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (100:22): [True: 7.15k, False: 3.57k]
  ------------------
  101|  7.15k|    result <<= 8;
  102|  7.15k|    result |= data[i];
  103|  7.15k|  }
  104|  3.57k|  *out = result;
  105|  3.57k|  return 1;
  106|  3.59k|}
cbs.c:cbs_get_length_prefixed:
  199|  3.59k|static int cbs_get_length_prefixed(CBS *cbs, CBS *out, size_t len_len) {
  200|  3.59k|  uint64_t len;
  201|  3.59k|  if (!cbs_get_u(cbs, &len, len_len)) {
  ------------------
  |  Branch (201:7): [True: 18, False: 3.57k]
  ------------------
  202|     18|    return 0;
  203|     18|  }
  204|       |  // If |len_len| <= 3 then we know that |len| will fit into a |size_t|, even on
  205|       |  // 32-bit systems.
  206|  3.57k|  assert(len_len <= 3);
  207|  3.57k|  return CBS_get_bytes(cbs, out, len);
  208|  3.57k|}

OPENSSL_cpuid_setup:
  153|      2|void OPENSSL_cpuid_setup(void) {
  154|       |  // Determine the vendor and maximum input value.
  155|      2|  uint32_t eax, ebx, ecx, edx;
  156|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 0);
  157|       |
  158|      2|  uint32_t num_ids = eax;
  159|       |
  160|      2|  int is_intel = ebx == 0x756e6547 /* Genu */ &&
  ------------------
  |  Branch (160:18): [True: 2, False: 0]
  ------------------
  161|      2|                 edx == 0x49656e69 /* ineI */ &&
  ------------------
  |  Branch (161:18): [True: 2, False: 0]
  ------------------
  162|      2|                 ecx == 0x6c65746e /* ntel */;
  ------------------
  |  Branch (162:18): [True: 2, False: 0]
  ------------------
  163|      2|  int is_amd = ebx == 0x68747541 /* Auth */ &&
  ------------------
  |  Branch (163:16): [True: 0, False: 2]
  ------------------
  164|      2|               edx == 0x69746e65 /* enti */ &&
  ------------------
  |  Branch (164:16): [True: 0, False: 0]
  ------------------
  165|      2|               ecx == 0x444d4163 /* cAMD */;
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|       |
  167|      2|  uint32_t extended_features[2] = {0};
  168|      2|  if (num_ids >= 7) {
  ------------------
  |  Branch (168:7): [True: 2, False: 0]
  ------------------
  169|      2|    OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 7);
  170|      2|    extended_features[0] = ebx;
  171|      2|    extended_features[1] = ecx;
  172|      2|  }
  173|       |
  174|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 1);
  175|       |
  176|      2|  if (is_amd) {
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|       |    // See https://www.amd.com/system/files/TechDocs/25481.pdf, page 10.
  178|      0|    const uint32_t base_family = (eax >> 8) & 15;
  179|      0|    const uint32_t base_model = (eax >> 4) & 15;
  180|       |
  181|      0|    uint32_t family = base_family;
  182|      0|    uint32_t model = base_model;
  183|      0|    if (base_family == 0xf) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      const uint32_t ext_family = (eax >> 20) & 255;
  185|      0|      family += ext_family;
  186|      0|      const uint32_t ext_model = (eax >> 16) & 15;
  187|      0|      model |= ext_model << 4;
  188|      0|    }
  189|       |
  190|      0|    if (family < 0x17 || (family == 0x17 && 0x70 <= model && model <= 0x7f)) {
  ------------------
  |  Branch (190:9): [True: 0, False: 0]
  |  Branch (190:27): [True: 0, False: 0]
  |  Branch (190:45): [True: 0, False: 0]
  |  Branch (190:62): [True: 0, False: 0]
  ------------------
  191|       |      // Disable RDRAND on AMD families before 0x17 (Zen) due to reported
  192|       |      // failures after suspend.
  193|       |      // https://bugzilla.redhat.com/show_bug.cgi?id=1150286
  194|       |      // Also disable for family 0x17, models 0x70–0x7f, due to possible RDRAND
  195|       |      // failures there too.
  196|      0|      ecx &= ~(1u << 30);
  197|      0|    }
  198|      0|  }
  199|       |
  200|       |  // Force the hyper-threading bit so that the more conservative path is always
  201|       |  // chosen.
  202|      2|  edx |= 1u << 28;
  203|       |
  204|       |  // Reserved bit #20 was historically repurposed to control the in-memory
  205|       |  // representation of RC4 state. Always set it to zero.
  206|      2|  edx &= ~(1u << 20);
  207|       |
  208|       |  // Reserved bit #30 is repurposed to signal an Intel CPU.
  209|      2|  if (is_intel) {
  ------------------
  |  Branch (209:7): [True: 2, False: 0]
  ------------------
  210|      2|    edx |= (1u << 30);
  211|       |
  212|       |    // Clear the XSAVE bit on Knights Landing to mimic Silvermont. This enables
  213|       |    // some Silvermont-specific codepaths which perform better. See OpenSSL
  214|       |    // commit 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  215|      2|    if ((eax & 0x0fff0ff0) == 0x00050670 /* Knights Landing */ ||
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      2|        (eax & 0x0fff0ff0) == 0x00080650 /* Knights Mill (per SDE) */) {
  ------------------
  |  Branch (216:9): [True: 0, False: 2]
  ------------------
  217|      0|      ecx &= ~(1u << 26);
  218|      0|    }
  219|      2|  } else {
  220|      0|    edx &= ~(1u << 30);
  221|      0|  }
  222|       |
  223|       |  // The SDBG bit is repurposed to denote AMD XOP support. Don't ever use AMD
  224|       |  // XOP code paths.
  225|      2|  ecx &= ~(1u << 11);
  226|       |
  227|      2|  uint64_t xcr0 = 0;
  228|      2|  if (ecx & (1u << 27)) {
  ------------------
  |  Branch (228:7): [True: 2, False: 0]
  ------------------
  229|       |    // XCR0 may only be queried if the OSXSAVE bit is set.
  230|      2|    xcr0 = OPENSSL_xgetbv(0);
  231|      2|  }
  232|       |  // See Intel manual, volume 1, section 14.3.
  233|      2|  if ((xcr0 & 6) != 6) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2]
  ------------------
  234|       |    // YMM registers cannot be used.
  235|      0|    ecx &= ~(1u << 28);  // AVX
  236|      0|    ecx &= ~(1u << 12);  // FMA
  237|      0|    ecx &= ~(1u << 11);  // AMD XOP
  238|       |    // Clear AVX2 and AVX512* bits.
  239|       |    //
  240|       |    // TODO(davidben): Should bits 17 and 26-28 also be cleared? Upstream
  241|       |    // doesn't clear those.
  242|      0|    extended_features[0] &=
  243|      0|        ~((1u << 5) | (1u << 16) | (1u << 21) | (1u << 30) | (1u << 31));
  244|      0|  }
  245|       |  // See Intel manual, volume 1, section 15.2.
  246|      2|  if ((xcr0 & 0xe6) != 0xe6) {
  ------------------
  |  Branch (246:7): [True: 2, False: 0]
  ------------------
  247|       |    // Clear AVX512F. Note we don't touch other AVX512 extensions because they
  248|       |    // can be used with YMM.
  249|      2|    extended_features[0] &= ~(1u << 16);
  250|      2|  }
  251|       |
  252|       |  // Disable ADX instructions on Knights Landing. See OpenSSL commit
  253|       |  // 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  254|      2|  if ((ecx & (1u << 26)) == 0) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    extended_features[0] &= ~(1u << 19);
  256|      0|  }
  257|       |
  258|      2|  OPENSSL_ia32cap_P[0] = edx;
  259|      2|  OPENSSL_ia32cap_P[1] = ecx;
  260|      2|  OPENSSL_ia32cap_P[2] = extended_features[0];
  261|      2|  OPENSSL_ia32cap_P[3] = extended_features[1];
  262|       |
  263|      2|  const char *env1, *env2;
  264|      2|  env1 = getenv("OPENSSL_ia32cap");
  265|      2|  if (env1 == NULL) {
  ------------------
  |  Branch (265:7): [True: 2, False: 0]
  ------------------
  266|      2|    return;
  267|      2|  }
  268|       |
  269|       |  // OPENSSL_ia32cap can contain zero, one or two values, separated with a ':'.
  270|       |  // Each value is a 64-bit, unsigned value which may start with "0x" to
  271|       |  // indicate a hex value. Prior to the 64-bit value, a '~' or '|' may be given.
  272|       |  //
  273|       |  // If the '~' prefix is present:
  274|       |  //   the value is inverted and ANDed with the probed CPUID result
  275|       |  // If the '|' prefix is present:
  276|       |  //   the value is ORed with the probed CPUID result
  277|       |  // Otherwise:
  278|       |  //   the value is taken as the result of the CPUID
  279|       |  //
  280|       |  // The first value determines OPENSSL_ia32cap_P[0] and [1]. The second [2]
  281|       |  // and [3].
  282|       |
  283|      0|  handle_cpu_env(&OPENSSL_ia32cap_P[0], env1);
  284|      0|  env2 = strchr(env1, ':');
  285|      0|  if (env2 != NULL) {
  ------------------
  |  Branch (285:7): [True: 0, False: 0]
  ------------------
  286|      0|    handle_cpu_env(&OPENSSL_ia32cap_P[2], env2 + 1);
  287|      0|  }
  288|      0|}
cpu_intel.c:OPENSSL_cpuid:
   80|      6|                          uint32_t *out_ecx, uint32_t *out_edx, uint32_t leaf) {
   81|       |#if defined(_MSC_VER)
   82|       |  int tmp[4];
   83|       |  __cpuid(tmp, (int)leaf);
   84|       |  *out_eax = (uint32_t)tmp[0];
   85|       |  *out_ebx = (uint32_t)tmp[1];
   86|       |  *out_ecx = (uint32_t)tmp[2];
   87|       |  *out_edx = (uint32_t)tmp[3];
   88|       |#elif defined(__pic__) && defined(OPENSSL_32_BIT)
   89|       |  // Inline assembly may not clobber the PIC register. For 32-bit, this is EBX.
   90|       |  // See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47602.
   91|       |  __asm__ volatile (
   92|       |    "xor %%ecx, %%ecx\n"
   93|       |    "mov %%ebx, %%edi\n"
   94|       |    "cpuid\n"
   95|       |    "xchg %%edi, %%ebx\n"
   96|       |    : "=a"(*out_eax), "=D"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
   97|       |    : "a"(leaf)
   98|       |  );
   99|       |#else
  100|      6|  __asm__ volatile (
  101|      6|    "xor %%ecx, %%ecx\n"
  102|      6|    "cpuid\n"
  103|      6|    : "=a"(*out_eax), "=b"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
  104|      6|    : "a"(leaf)
  105|      6|  );
  106|      6|#endif
  107|      6|}
cpu_intel.c:OPENSSL_xgetbv:
  111|      2|static uint64_t OPENSSL_xgetbv(uint32_t xcr) {
  112|       |#if defined(_MSC_VER)
  113|       |  return (uint64_t)_xgetbv(xcr);
  114|       |#else
  115|      2|  uint32_t eax, edx;
  116|      2|  __asm__ volatile ("xgetbv" : "=a"(eax), "=d"(edx) : "c"(xcr));
  117|      2|  return (((uint64_t)edx) << 32) | eax;
  118|      2|#endif
  119|      2|}

crypto.c:do_library_init:
  151|      2|static void OPENSSL_CDECL do_library_init(void) {
  152|       | // WARNING: this function may only configure the capability variables. See the
  153|       | // note above about the linker bug.
  154|      2|#if defined(NEED_CPUID)
  155|      2|  OPENSSL_cpuid_setup();
  156|      2|#endif
  157|      2|}

BN_add:
   67|  1.75k|int BN_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
   68|  1.75k|  const BIGNUM *tmp;
   69|  1.75k|  int a_neg = a->neg, ret;
   70|       |
   71|       |  //  a +  b	a+b
   72|       |  //  a + -b	a-b
   73|       |  // -a +  b	b-a
   74|       |  // -a + -b	-(a+b)
   75|  1.75k|  if (a_neg ^ b->neg) {
  ------------------
  |  Branch (75:7): [True: 581, False: 1.17k]
  ------------------
   76|       |    // only one is negative
   77|    581|    if (a_neg) {
  ------------------
  |  Branch (77:9): [True: 288, False: 293]
  ------------------
   78|    288|      tmp = a;
   79|    288|      a = b;
   80|    288|      b = tmp;
   81|    288|    }
   82|       |
   83|       |    // we are now a - b
   84|    581|    if (BN_ucmp(a, b) < 0) {
  ------------------
  |  Branch (84:9): [True: 581, False: 0]
  ------------------
   85|    581|      if (!BN_usub(r, b, a)) {
  ------------------
  |  Branch (85:11): [True: 0, False: 581]
  ------------------
   86|      0|        return 0;
   87|      0|      }
   88|    581|      r->neg = 1;
   89|    581|    } else {
   90|      0|      if (!BN_usub(r, a, b)) {
  ------------------
  |  Branch (90:11): [True: 0, False: 0]
  ------------------
   91|      0|        return 0;
   92|      0|      }
   93|      0|      r->neg = 0;
   94|      0|    }
   95|    581|    return 1;
   96|    581|  }
   97|       |
   98|  1.17k|  ret = BN_uadd(r, a, b);
   99|  1.17k|  r->neg = a_neg;
  100|  1.17k|  return ret;
  101|  1.75k|}
bn_uadd_consttime:
  103|  1.17k|int bn_uadd_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  104|       |  // Widths are public, so we normalize to make |a| the larger one.
  105|  1.17k|  if (a->width < b->width) {
  ------------------
  |  Branch (105:7): [True: 143, False: 1.02k]
  ------------------
  106|    143|    const BIGNUM *tmp = a;
  107|    143|    a = b;
  108|    143|    b = tmp;
  109|    143|  }
  110|       |
  111|  1.17k|  int max = a->width;
  112|  1.17k|  int min = b->width;
  113|  1.17k|  if (!bn_wexpand(r, max + 1)) {
  ------------------
  |  Branch (113:7): [True: 0, False: 1.17k]
  ------------------
  114|      0|    return 0;
  115|      0|  }
  116|  1.17k|  r->width = max + 1;
  117|       |
  118|  1.17k|  BN_ULONG carry = bn_add_words(r->d, a->d, b->d, min);
  119|   278k|  for (int i = min; i < max; i++) {
  ------------------
  |  Branch (119:21): [True: 277k, False: 1.17k]
  ------------------
  120|       |    // |r| and |a| may alias, so use a temporary.
  121|   277k|    BN_ULONG tmp = carry + a->d[i];
  122|   277k|    carry = tmp < a->d[i];
  123|   277k|    r->d[i] = tmp;
  124|   277k|  }
  125|       |
  126|  1.17k|  r->d[max] = carry;
  127|  1.17k|  return 1;
  128|  1.17k|}
BN_uadd:
  130|  1.17k|int BN_uadd(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  131|  1.17k|  if (!bn_uadd_consttime(r, a, b)) {
  ------------------
  |  Branch (131:7): [True: 0, False: 1.17k]
  ------------------
  132|      0|    return 0;
  133|      0|  }
  134|  1.17k|  bn_set_minimal_width(r);
  135|  1.17k|  return 1;
  136|  1.17k|}
bn_usub_consttime:
  226|    581|int bn_usub_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  227|       |  // |b| may have more words than |a| given non-minimal inputs, but all words
  228|       |  // beyond |a->width| must then be zero.
  229|    581|  int b_width = b->width;
  230|    581|  if (b_width > a->width) {
  ------------------
  |  Branch (230:7): [True: 0, False: 581]
  ------------------
  231|      0|    if (!bn_fits_in_words(b, a->width)) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  233|      0|      return 0;
  234|      0|    }
  235|      0|    b_width = a->width;
  236|      0|  }
  237|       |
  238|    581|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (238:7): [True: 0, False: 581]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|    581|  BN_ULONG borrow = bn_sub_words(r->d, a->d, b->d, b_width);
  243|   103k|  for (int i = b_width; i < a->width; i++) {
  ------------------
  |  Branch (243:25): [True: 102k, False: 581]
  ------------------
  244|       |    // |r| and |a| may alias, so use a temporary.
  245|   102k|    BN_ULONG tmp = a->d[i];
  246|   102k|    r->d[i] = a->d[i] - borrow;
  247|   102k|    borrow = tmp < r->d[i];
  248|   102k|  }
  249|       |
  250|    581|  if (borrow) {
  ------------------
  |  Branch (250:7): [True: 0, False: 581]
  ------------------
  251|      0|    OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  252|      0|    return 0;
  253|      0|  }
  254|       |
  255|    581|  r->width = a->width;
  256|    581|  r->neg = 0;
  257|    581|  return 1;
  258|    581|}
BN_usub:
  260|    581|int BN_usub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  261|    581|  if (!bn_usub_consttime(r, a, b)) {
  ------------------
  |  Branch (261:7): [True: 0, False: 581]
  ------------------
  262|      0|    return 0;
  263|      0|  }
  264|    581|  bn_set_minimal_width(r);
  265|    581|  return 1;
  266|    581|}

bn_mul_add_words:
   98|  29.0k|                          BN_ULONG w) {
   99|  29.0k|  BN_ULONG c1 = 0;
  100|       |
  101|  29.0k|  if (num == 0) {
  ------------------
  |  Branch (101:7): [True: 0, False: 29.0k]
  ------------------
  102|      0|    return (c1);
  103|      0|  }
  104|       |
  105|  17.8M|  while (num & ~3) {
  ------------------
  |  Branch (105:10): [True: 17.8M, False: 29.0k]
  ------------------
  106|  17.8M|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|  17.8M|  do {                                                                     \
  |  |   70|  17.8M|    register BN_ULONG high, low;                                           \
  |  |   71|  17.8M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  17.8M|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  17.8M|            : "a"(low), "g"(0)                                             \
  |  |   75|  17.8M|            : "cc");                                                       \
  |  |   76|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  17.8M|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  17.8M|            : "r"(carry), "g"(0)                                           \
  |  |   79|  17.8M|            : "cc");                                                       \
  |  |   80|  17.8M|    (carry) = high;                                                        \
  |  |   81|  17.8M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  107|  17.8M|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|  17.8M|  do {                                                                     \
  |  |   70|  17.8M|    register BN_ULONG high, low;                                           \
  |  |   71|  17.8M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  17.8M|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  17.8M|            : "a"(low), "g"(0)                                             \
  |  |   75|  17.8M|            : "cc");                                                       \
  |  |   76|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  17.8M|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  17.8M|            : "r"(carry), "g"(0)                                           \
  |  |   79|  17.8M|            : "cc");                                                       \
  |  |   80|  17.8M|    (carry) = high;                                                        \
  |  |   81|  17.8M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  108|  17.8M|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|  17.8M|  do {                                                                     \
  |  |   70|  17.8M|    register BN_ULONG high, low;                                           \
  |  |   71|  17.8M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  17.8M|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  17.8M|            : "a"(low), "g"(0)                                             \
  |  |   75|  17.8M|            : "cc");                                                       \
  |  |   76|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  17.8M|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  17.8M|            : "r"(carry), "g"(0)                                           \
  |  |   79|  17.8M|            : "cc");                                                       \
  |  |   80|  17.8M|    (carry) = high;                                                        \
  |  |   81|  17.8M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  109|  17.8M|    mul_add(rp[3], ap[3], w, c1);
  ------------------
  |  |   69|  17.8M|  do {                                                                     \
  |  |   70|  17.8M|    register BN_ULONG high, low;                                           \
  |  |   71|  17.8M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  17.8M|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  17.8M|            : "a"(low), "g"(0)                                             \
  |  |   75|  17.8M|            : "cc");                                                       \
  |  |   76|  17.8M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  17.8M|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  17.8M|            : "r"(carry), "g"(0)                                           \
  |  |   79|  17.8M|            : "cc");                                                       \
  |  |   80|  17.8M|    (carry) = high;                                                        \
  |  |   81|  17.8M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  110|  17.8M|    ap += 4;
  111|  17.8M|    rp += 4;
  112|  17.8M|    num -= 4;
  113|  17.8M|  }
  114|  29.0k|  if (num) {
  ------------------
  |  Branch (114:7): [True: 13.6k, False: 15.4k]
  ------------------
  115|  13.6k|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|  13.6k|  do {                                                                     \
  |  |   70|  13.6k|    register BN_ULONG high, low;                                           \
  |  |   71|  13.6k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  13.6k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  13.6k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  13.6k|            : "a"(low), "g"(0)                                             \
  |  |   75|  13.6k|            : "cc");                                                       \
  |  |   76|  13.6k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  13.6k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  13.6k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  13.6k|            : "cc");                                                       \
  |  |   80|  13.6k|    (carry) = high;                                                        \
  |  |   81|  13.6k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|  13.6k|    if (--num == 0) {
  ------------------
  |  Branch (116:9): [True: 7.42k, False: 6.17k]
  ------------------
  117|  7.42k|      return c1;
  118|  7.42k|    }
  119|  6.17k|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|  6.17k|  do {                                                                     \
  |  |   70|  6.17k|    register BN_ULONG high, low;                                           \
  |  |   71|  6.17k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  6.17k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  6.17k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  6.17k|            : "a"(low), "g"(0)                                             \
  |  |   75|  6.17k|            : "cc");                                                       \
  |  |   76|  6.17k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  6.17k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  6.17k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  6.17k|            : "cc");                                                       \
  |  |   80|  6.17k|    (carry) = high;                                                        \
  |  |   81|  6.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  120|  6.17k|    if (--num == 0) {
  ------------------
  |  Branch (120:9): [True: 2.02k, False: 4.15k]
  ------------------
  121|  2.02k|      return c1;
  122|  2.02k|    }
  123|  4.15k|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|  4.15k|  do {                                                                     \
  |  |   70|  4.15k|    register BN_ULONG high, low;                                           \
  |  |   71|  4.15k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  4.15k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  4.15k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  4.15k|            : "a"(low), "g"(0)                                             \
  |  |   75|  4.15k|            : "cc");                                                       \
  |  |   76|  4.15k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  4.15k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  4.15k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  4.15k|            : "cc");                                                       \
  |  |   80|  4.15k|    (carry) = high;                                                        \
  |  |   81|  4.15k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  124|  4.15k|    return c1;
  125|  6.17k|  }
  126|       |
  127|  15.4k|  return c1;
  128|  29.0k|}
bn_mul_words:
  131|   330k|                      BN_ULONG w) {
  132|   330k|  BN_ULONG c1 = 0;
  133|       |
  134|   330k|  if (num == 0) {
  ------------------
  |  Branch (134:7): [True: 0, False: 330k]
  ------------------
  135|      0|    return c1;
  136|      0|  }
  137|       |
  138|  68.7M|  while (num & ~3) {
  ------------------
  |  Branch (138:10): [True: 68.4M, False: 330k]
  ------------------
  139|  68.4M|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|  68.4M|  do {                                                                     \
  |  |   85|  68.4M|    register BN_ULONG high, low;                                           \
  |  |   86|  68.4M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  68.4M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  68.4M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  68.4M|            : "a"(low), "g"(0)                                             \
  |  |   90|  68.4M|            : "cc");                                                       \
  |  |   91|  68.4M|    (r) = (carry);                                                         \
  |  |   92|  68.4M|    (carry) = high;                                                        \
  |  |   93|  68.4M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  140|  68.4M|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|  68.4M|  do {                                                                     \
  |  |   85|  68.4M|    register BN_ULONG high, low;                                           \
  |  |   86|  68.4M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  68.4M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  68.4M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  68.4M|            : "a"(low), "g"(0)                                             \
  |  |   90|  68.4M|            : "cc");                                                       \
  |  |   91|  68.4M|    (r) = (carry);                                                         \
  |  |   92|  68.4M|    (carry) = high;                                                        \
  |  |   93|  68.4M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  141|  68.4M|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|  68.4M|  do {                                                                     \
  |  |   85|  68.4M|    register BN_ULONG high, low;                                           \
  |  |   86|  68.4M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  68.4M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  68.4M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  68.4M|            : "a"(low), "g"(0)                                             \
  |  |   90|  68.4M|            : "cc");                                                       \
  |  |   91|  68.4M|    (r) = (carry);                                                         \
  |  |   92|  68.4M|    (carry) = high;                                                        \
  |  |   93|  68.4M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  142|  68.4M|    mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   84|  68.4M|  do {                                                                     \
  |  |   85|  68.4M|    register BN_ULONG high, low;                                           \
  |  |   86|  68.4M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  68.4M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  68.4M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  68.4M|            : "a"(low), "g"(0)                                             \
  |  |   90|  68.4M|            : "cc");                                                       \
  |  |   91|  68.4M|    (r) = (carry);                                                         \
  |  |   92|  68.4M|    (carry) = high;                                                        \
  |  |   93|  68.4M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  143|  68.4M|    ap += 4;
  144|  68.4M|    rp += 4;
  145|  68.4M|    num -= 4;
  146|  68.4M|  }
  147|   330k|  if (num) {
  ------------------
  |  Branch (147:7): [True: 282k, False: 48.1k]
  ------------------
  148|   282k|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|   282k|  do {                                                                     \
  |  |   85|   282k|    register BN_ULONG high, low;                                           \
  |  |   86|   282k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|   282k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|   282k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|   282k|            : "a"(low), "g"(0)                                             \
  |  |   90|   282k|            : "cc");                                                       \
  |  |   91|   282k|    (r) = (carry);                                                         \
  |  |   92|   282k|    (carry) = high;                                                        \
  |  |   93|   282k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  149|   282k|    if (--num == 0) {
  ------------------
  |  Branch (149:9): [True: 194k, False: 87.2k]
  ------------------
  150|   194k|      return c1;
  151|   194k|    }
  152|  87.2k|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|  87.2k|  do {                                                                     \
  |  |   85|  87.2k|    register BN_ULONG high, low;                                           \
  |  |   86|  87.2k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  87.2k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  87.2k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  87.2k|            : "a"(low), "g"(0)                                             \
  |  |   90|  87.2k|            : "cc");                                                       \
  |  |   91|  87.2k|    (r) = (carry);                                                         \
  |  |   92|  87.2k|    (carry) = high;                                                        \
  |  |   93|  87.2k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|  87.2k|    if (--num == 0) {
  ------------------
  |  Branch (153:9): [True: 53.7k, False: 33.4k]
  ------------------
  154|  53.7k|      return c1;
  155|  53.7k|    }
  156|  33.4k|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|  33.4k|  do {                                                                     \
  |  |   85|  33.4k|    register BN_ULONG high, low;                                           \
  |  |   86|  33.4k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  33.4k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  33.4k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  33.4k|            : "a"(low), "g"(0)                                             \
  |  |   90|  33.4k|            : "cc");                                                       \
  |  |   91|  33.4k|    (r) = (carry);                                                         \
  |  |   92|  33.4k|    (carry) = high;                                                        \
  |  |   93|  33.4k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|  33.4k|  }
  158|  81.6k|  return c1;
  159|   330k|}
bn_add_words:
  189|   724k|                      size_t n) {
  190|   724k|  BN_ULONG ret;
  191|   724k|  size_t i = 0;
  192|       |
  193|   724k|  if (n == 0) {
  ------------------
  |  Branch (193:7): [True: 321, False: 724k]
  ------------------
  194|    321|    return 0;
  195|    321|  }
  196|       |
  197|   724k|  __asm__ volatile (
  198|   724k|      "	subq	%0,%0		\n"  // clear carry
  199|   724k|      "	jmp	1f		\n"
  200|   724k|      ".p2align 4			\n"
  201|   724k|      "1:"
  202|   724k|      "	movq	(%4,%2,8),%0	\n"
  203|   724k|      "	adcq	(%5,%2,8),%0	\n"
  204|   724k|      "	movq	%0,(%3,%2,8)	\n"
  205|   724k|      "	lea	1(%2),%2	\n"
  206|   724k|      "	dec	%1		\n"
  207|   724k|      "	jnz	1b		\n"
  208|   724k|      "	sbbq	%0,%0		\n"
  209|   724k|      : "=&r"(ret), "+c"(n), "+r"(i)
  210|   724k|      : "r"(rp), "r"(ap), "r"(bp)
  211|   724k|      : "cc", "memory");
  212|       |
  213|   724k|  return ret & 1;
  214|   724k|}
bn_sub_words:
  217|  1.53M|                      size_t n) {
  218|  1.53M|  BN_ULONG ret;
  219|  1.53M|  size_t i = 0;
  220|       |
  221|  1.53M|  if (n == 0) {
  ------------------
  |  Branch (221:7): [True: 1.03k, False: 1.53M]
  ------------------
  222|  1.03k|    return 0;
  223|  1.03k|  }
  224|       |
  225|  1.53M|  __asm__ volatile (
  226|  1.53M|      "	subq	%0,%0		\n"  // clear borrow
  227|  1.53M|      "	jmp	1f		\n"
  228|  1.53M|      ".p2align 4			\n"
  229|  1.53M|      "1:"
  230|  1.53M|      "	movq	(%4,%2,8),%0	\n"
  231|  1.53M|      "	sbbq	(%5,%2,8),%0	\n"
  232|  1.53M|      "	movq	%0,(%3,%2,8)	\n"
  233|  1.53M|      "	lea	1(%2),%2	\n"
  234|  1.53M|      "	dec	%1		\n"
  235|  1.53M|      "	jnz	1b		\n"
  236|  1.53M|      "	sbbq	%0,%0		\n"
  237|  1.53M|      : "=&r"(ret), "+c"(n), "+r"(i)
  238|  1.53M|      : "r"(rp), "r"(ap), "r"(bp)
  239|  1.53M|      : "cc", "memory");
  240|       |
  241|  1.53M|  return ret & 1;
  242|  1.53M|}
bn_mul_comba8:
  287|   482k|void bn_mul_comba8(BN_ULONG r[16], const BN_ULONG a[8], const BN_ULONG b[8]) {
  288|   482k|  BN_ULONG c1, c2, c3;
  289|       |
  290|   482k|  c1 = 0;
  291|   482k|  c2 = 0;
  292|   482k|  c3 = 0;
  293|   482k|  mul_add_c(a[0], b[0], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  294|   482k|  r[0] = c1;
  295|   482k|  c1 = 0;
  296|   482k|  mul_add_c(a[0], b[1], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  297|   482k|  mul_add_c(a[1], b[0], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  298|   482k|  r[1] = c2;
  299|   482k|  c2 = 0;
  300|   482k|  mul_add_c(a[2], b[0], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  301|   482k|  mul_add_c(a[1], b[1], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  302|   482k|  mul_add_c(a[0], b[2], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  303|   482k|  r[2] = c3;
  304|   482k|  c3 = 0;
  305|   482k|  mul_add_c(a[0], b[3], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  306|   482k|  mul_add_c(a[1], b[2], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  307|   482k|  mul_add_c(a[2], b[1], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  308|   482k|  mul_add_c(a[3], b[0], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  309|   482k|  r[3] = c1;
  310|   482k|  c1 = 0;
  311|   482k|  mul_add_c(a[4], b[0], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  312|   482k|  mul_add_c(a[3], b[1], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  313|   482k|  mul_add_c(a[2], b[2], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  314|   482k|  mul_add_c(a[1], b[3], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  315|   482k|  mul_add_c(a[0], b[4], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  316|   482k|  r[4] = c2;
  317|   482k|  c2 = 0;
  318|   482k|  mul_add_c(a[0], b[5], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  319|   482k|  mul_add_c(a[1], b[4], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  320|   482k|  mul_add_c(a[2], b[3], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  321|   482k|  mul_add_c(a[3], b[2], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  322|   482k|  mul_add_c(a[4], b[1], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  323|   482k|  mul_add_c(a[5], b[0], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  324|   482k|  r[5] = c3;
  325|   482k|  c3 = 0;
  326|   482k|  mul_add_c(a[6], b[0], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  327|   482k|  mul_add_c(a[5], b[1], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  328|   482k|  mul_add_c(a[4], b[2], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  329|   482k|  mul_add_c(a[3], b[3], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  330|   482k|  mul_add_c(a[2], b[4], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  331|   482k|  mul_add_c(a[1], b[5], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  332|   482k|  mul_add_c(a[0], b[6], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  333|   482k|  r[6] = c1;
  334|   482k|  c1 = 0;
  335|   482k|  mul_add_c(a[0], b[7], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  336|   482k|  mul_add_c(a[1], b[6], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  337|   482k|  mul_add_c(a[2], b[5], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  338|   482k|  mul_add_c(a[3], b[4], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  339|   482k|  mul_add_c(a[4], b[3], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  340|   482k|  mul_add_c(a[5], b[2], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  341|   482k|  mul_add_c(a[6], b[1], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  342|   482k|  mul_add_c(a[7], b[0], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  343|   482k|  r[7] = c2;
  344|   482k|  c2 = 0;
  345|   482k|  mul_add_c(a[7], b[1], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  346|   482k|  mul_add_c(a[6], b[2], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  347|   482k|  mul_add_c(a[5], b[3], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  348|   482k|  mul_add_c(a[4], b[4], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  349|   482k|  mul_add_c(a[3], b[5], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  350|   482k|  mul_add_c(a[2], b[6], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  351|   482k|  mul_add_c(a[1], b[7], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  352|   482k|  r[8] = c3;
  353|   482k|  c3 = 0;
  354|   482k|  mul_add_c(a[2], b[7], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  355|   482k|  mul_add_c(a[3], b[6], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  356|   482k|  mul_add_c(a[4], b[5], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  357|   482k|  mul_add_c(a[5], b[4], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  358|   482k|  mul_add_c(a[6], b[3], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  359|   482k|  mul_add_c(a[7], b[2], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  360|   482k|  r[9] = c1;
  361|   482k|  c1 = 0;
  362|   482k|  mul_add_c(a[7], b[3], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  363|   482k|  mul_add_c(a[6], b[4], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  364|   482k|  mul_add_c(a[5], b[5], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  365|   482k|  mul_add_c(a[4], b[6], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  366|   482k|  mul_add_c(a[3], b[7], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  367|   482k|  r[10] = c2;
  368|   482k|  c2 = 0;
  369|   482k|  mul_add_c(a[4], b[7], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  370|   482k|  mul_add_c(a[5], b[6], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  371|   482k|  mul_add_c(a[6], b[5], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  372|   482k|  mul_add_c(a[7], b[4], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  373|   482k|  r[11] = c3;
  374|   482k|  c3 = 0;
  375|   482k|  mul_add_c(a[7], b[5], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  376|   482k|  mul_add_c(a[6], b[6], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  377|   482k|  mul_add_c(a[5], b[7], c1, c2, c3);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  378|   482k|  r[12] = c1;
  379|   482k|  c1 = 0;
  380|   482k|  mul_add_c(a[6], b[7], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  381|   482k|  mul_add_c(a[7], b[6], c2, c3, c1);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  382|   482k|  r[13] = c2;
  383|   482k|  c2 = 0;
  384|   482k|  mul_add_c(a[7], b[7], c3, c1, c2);
  ------------------
  |  |  252|   482k|  do {                                                               \
  |  |  253|   482k|    BN_ULONG t1, t2;                                                 \
  |  |  254|   482k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|   482k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|   482k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|   482k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|   482k|            : "cc");                                                 \
  |  |  259|   482k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  385|   482k|  r[14] = c3;
  386|   482k|  r[15] = c1;
  387|   482k|}

BN_new:
   75|  12.2k|BIGNUM *BN_new(void) {
   76|  12.2k|  BIGNUM *bn = OPENSSL_malloc(sizeof(BIGNUM));
   77|       |
   78|  12.2k|  if (bn == NULL) {
  ------------------
  |  Branch (78:7): [True: 0, False: 12.2k]
  ------------------
   79|      0|    return NULL;
   80|      0|  }
   81|       |
   82|  12.2k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   83|  12.2k|  bn->flags = BN_FLG_MALLOCED;
  ------------------
  |  | 1026|  12.2k|#define BN_FLG_MALLOCED 0x01
  ------------------
   84|       |
   85|  12.2k|  return bn;
   86|  12.2k|}
BN_free:
   94|  12.2k|void BN_free(BIGNUM *bn) {
   95|  12.2k|  if (bn == NULL) {
  ------------------
  |  Branch (95:7): [True: 0, False: 12.2k]
  ------------------
   96|      0|    return;
   97|      0|  }
   98|       |
   99|  12.2k|  if ((bn->flags & BN_FLG_STATIC_DATA) == 0) {
  ------------------
  |  | 1027|  12.2k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (99:7): [True: 12.2k, False: 0]
  ------------------
  100|  12.2k|    OPENSSL_free(bn->d);
  101|  12.2k|  }
  102|       |
  103|  12.2k|  if (bn->flags & BN_FLG_MALLOCED) {
  ------------------
  |  | 1026|  12.2k|#define BN_FLG_MALLOCED 0x01
  ------------------
  |  Branch (103:7): [True: 12.2k, False: 0]
  ------------------
  104|  12.2k|    OPENSSL_free(bn);
  105|  12.2k|  } else {
  106|      0|    bn->d = NULL;
  107|      0|  }
  108|  12.2k|}
BN_copy:
  134|  1.21k|BIGNUM *BN_copy(BIGNUM *dest, const BIGNUM *src) {
  135|  1.21k|  if (src == dest) {
  ------------------
  |  Branch (135:7): [True: 0, False: 1.21k]
  ------------------
  136|      0|    return dest;
  137|      0|  }
  138|       |
  139|  1.21k|  if (!bn_wexpand(dest, src->width)) {
  ------------------
  |  Branch (139:7): [True: 0, False: 1.21k]
  ------------------
  140|      0|    return NULL;
  141|      0|  }
  142|       |
  143|  1.21k|  OPENSSL_memcpy(dest->d, src->d, sizeof(src->d[0]) * src->width);
  144|       |
  145|  1.21k|  dest->width = src->width;
  146|  1.21k|  dest->neg = src->neg;
  147|  1.21k|  return dest;
  148|  1.21k|}
BN_num_bits_word:
  170|  2.12k|unsigned BN_num_bits_word(BN_ULONG l) {
  171|       |  // |BN_num_bits| is often called on RSA prime factors. These have public bit
  172|       |  // lengths, but all bits beyond the high bit are secret, so count bits in
  173|       |  // constant time.
  174|  2.12k|  BN_ULONG x, mask;
  175|  2.12k|  int bits = (l != 0);
  176|       |
  177|  2.12k|#if BN_BITS2 > 32
  178|       |  // Look at the upper half of |x|. |x| is at most 64 bits long.
  179|  2.12k|  x = l >> 32;
  180|       |  // Set |mask| to all ones if |x| (the top 32 bits of |l|) is non-zero and all
  181|       |  // all zeros otherwise.
  182|  2.12k|  mask = 0u - x;
  183|  2.12k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.12k|#define BN_BITS2 64
  ------------------
  184|       |  // If |x| is non-zero, the lower half is included in the bit count in full,
  185|       |  // and we count the upper half. Otherwise, we count the lower half.
  186|  2.12k|  bits += 32 & mask;
  187|  2.12k|  l ^= (x ^ l) & mask;  // |l| is |x| if |mask| and remains |l| otherwise.
  188|  2.12k|#endif
  189|       |
  190|       |  // The remaining blocks are analogous iterations at lower powers of two.
  191|  2.12k|  x = l >> 16;
  192|  2.12k|  mask = 0u - x;
  193|  2.12k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.12k|#define BN_BITS2 64
  ------------------
  194|  2.12k|  bits += 16 & mask;
  195|  2.12k|  l ^= (x ^ l) & mask;
  196|       |
  197|  2.12k|  x = l >> 8;
  198|  2.12k|  mask = 0u - x;
  199|  2.12k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.12k|#define BN_BITS2 64
  ------------------
  200|  2.12k|  bits += 8 & mask;
  201|  2.12k|  l ^= (x ^ l) & mask;
  202|       |
  203|  2.12k|  x = l >> 4;
  204|  2.12k|  mask = 0u - x;
  205|  2.12k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.12k|#define BN_BITS2 64
  ------------------
  206|  2.12k|  bits += 4 & mask;
  207|  2.12k|  l ^= (x ^ l) & mask;
  208|       |
  209|  2.12k|  x = l >> 2;
  210|  2.12k|  mask = 0u - x;
  211|  2.12k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.12k|#define BN_BITS2 64
  ------------------
  212|  2.12k|  bits += 2 & mask;
  213|  2.12k|  l ^= (x ^ l) & mask;
  214|       |
  215|  2.12k|  x = l >> 1;
  216|  2.12k|  mask = 0u - x;
  217|  2.12k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.12k|#define BN_BITS2 64
  ------------------
  218|  2.12k|  bits += 1 & mask;
  219|       |
  220|  2.12k|  return bits;
  221|  2.12k|}
BN_num_bits:
  223|  1.75k|unsigned BN_num_bits(const BIGNUM *bn) {
  224|  1.75k|  const int width = bn_minimal_width(bn);
  225|  1.75k|  if (width == 0) {
  ------------------
  |  Branch (225:7): [True: 0, False: 1.75k]
  ------------------
  226|      0|    return 0;
  227|      0|  }
  228|       |
  229|  1.75k|  return (width - 1) * BN_BITS2 + BN_num_bits_word(bn->d[width - 1]);
  ------------------
  |  |  151|  1.75k|#define BN_BITS2 64
  ------------------
  230|  1.75k|}
BN_zero:
  236|  7.38k|void BN_zero(BIGNUM *bn) {
  237|  7.38k|  bn->width = bn->neg = 0;
  238|  7.38k|}
bn_fits_in_words:
  306|  7.22k|int bn_fits_in_words(const BIGNUM *bn, size_t num) {
  307|       |  // All words beyond |num| must be zero.
  308|  7.22k|  BN_ULONG mask = 0;
  309|  1.66M|  for (size_t i = num; i < (size_t)bn->width; i++) {
  ------------------
  |  Branch (309:24): [True: 1.65M, False: 7.22k]
  ------------------
  310|  1.65M|    mask |= bn->d[i];
  311|  1.65M|  }
  312|  7.22k|  return mask == 0;
  313|  7.22k|}
BN_set_negative:
  339|  3.50k|void BN_set_negative(BIGNUM *bn, int sign) {
  340|  3.50k|  if (sign && !BN_is_zero(bn)) {
  ------------------
  |  Branch (340:7): [True: 1.97k, False: 1.53k]
  |  Branch (340:15): [True: 1.91k, False: 59]
  ------------------
  341|  1.91k|    bn->neg = 1;
  342|  1.91k|  } else {
  343|  1.59k|    bn->neg = 0;
  344|  1.59k|  }
  345|  3.50k|}
bn_wexpand:
  347|  18.5k|int bn_wexpand(BIGNUM *bn, size_t words) {
  348|  18.5k|  BN_ULONG *a;
  349|       |
  350|  18.5k|  if (words <= (size_t)bn->dmax) {
  ------------------
  |  Branch (350:7): [True: 3.99k, False: 14.5k]
  ------------------
  351|  3.99k|    return 1;
  352|  3.99k|  }
  353|       |
  354|  14.5k|  if (words > BN_MAX_WORDS) {
  ------------------
  |  |   73|  14.5k|#define BN_MAX_WORDS (INT_MAX / (4 * BN_BITS2))
  |  |  ------------------
  |  |  |  |  151|  14.5k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (354:7): [True: 0, False: 14.5k]
  ------------------
  355|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  356|      0|    return 0;
  357|      0|  }
  358|       |
  359|  14.5k|  if (bn->flags & BN_FLG_STATIC_DATA) {
  ------------------
  |  | 1027|  14.5k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (359:7): [True: 0, False: 14.5k]
  ------------------
  360|      0|    OPENSSL_PUT_ERROR(BN, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  361|      0|    return 0;
  362|      0|  }
  363|       |
  364|  14.5k|  a = OPENSSL_malloc(sizeof(BN_ULONG) * words);
  365|  14.5k|  if (a == NULL) {
  ------------------
  |  Branch (365:7): [True: 0, False: 14.5k]
  ------------------
  366|      0|    return 0;
  367|      0|  }
  368|       |
  369|  14.5k|  OPENSSL_memcpy(a, bn->d, sizeof(BN_ULONG) * bn->width);
  370|       |
  371|  14.5k|  OPENSSL_free(bn->d);
  372|  14.5k|  bn->d = a;
  373|  14.5k|  bn->dmax = (int)words;
  374|       |
  375|  14.5k|  return 1;
  376|  14.5k|}
bn_select_words:
  407|   723k|                     const BN_ULONG *b, size_t num) {
  408|  15.7M|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (408:22): [True: 15.0M, False: 723k]
  ------------------
  409|  15.0M|    static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  410|  15.0M|                  "crypto_word_t is too small");
  411|  15.0M|    r[i] = constant_time_select_w(mask, a[i], b[i]);
  412|  15.0M|  }
  413|   723k|}
bn_minimal_width:
  415|  21.0k|int bn_minimal_width(const BIGNUM *bn) {
  416|  21.0k|  int ret = bn->width;
  417|   717k|  while (ret > 0 && bn->d[ret - 1] == 0) {
  ------------------
  |  Branch (417:10): [True: 715k, False: 2.38k]
  |  Branch (417:21): [True: 696k, False: 18.6k]
  ------------------
  418|   696k|    ret--;
  419|   696k|  }
  420|  21.0k|  return ret;
  421|  21.0k|}
bn_set_minimal_width:
  423|  15.7k|void bn_set_minimal_width(BIGNUM *bn) {
  424|  15.7k|  bn->width = bn_minimal_width(bn);
  425|  15.7k|  if (bn->width == 0) {
  ------------------
  |  Branch (425:7): [True: 2.28k, False: 13.4k]
  ------------------
  426|  2.28k|    bn->neg = 0;
  427|  2.28k|  }
  428|  15.7k|}

bn_big_endian_to_words:
   65|  3.50k|                            size_t in_len) {
   66|   965k|  for (size_t i = 0; i < out_len; i++) {
  ------------------
  |  Branch (66:22): [True: 964k, False: 470]
  ------------------
   67|   964k|    if (in_len < sizeof(BN_ULONG)) {
  ------------------
  |  Branch (67:9): [True: 3.03k, False: 961k]
  ------------------
   68|       |      // Load the last partial word.
   69|  3.03k|      BN_ULONG word = 0;
   70|  9.60k|      for (size_t j = 0; j < in_len; j++) {
  ------------------
  |  Branch (70:26): [True: 6.56k, False: 3.03k]
  ------------------
   71|  6.56k|        word = (word << 8) | in[j];
   72|  6.56k|      }
   73|  3.03k|      in_len = 0;
   74|  3.03k|      out[i] = word;
   75|       |      // Fill the remainder with zeros.
   76|  3.03k|      OPENSSL_memset(out + i + 1, 0, (out_len - i - 1) * sizeof(BN_ULONG));
   77|  3.03k|      break;
   78|  3.03k|    }
   79|       |
   80|   961k|    in_len -= sizeof(BN_ULONG);
   81|   961k|    out[i] = CRYPTO_load_word_be(in + in_len);
   82|   961k|  }
   83|       |
   84|       |  // The caller should have sized the output to avoid truncation.
   85|  3.50k|  assert(in_len == 0);
   86|  3.50k|}
BN_bin2bn:
   88|  3.50k|BIGNUM *BN_bin2bn(const uint8_t *in, size_t len, BIGNUM *ret) {
   89|  3.50k|  BIGNUM *bn = NULL;
   90|  3.50k|  if (ret == NULL) {
  ------------------
  |  Branch (90:7): [True: 3.50k, False: 0]
  ------------------
   91|  3.50k|    bn = BN_new();
   92|  3.50k|    if (bn == NULL) {
  ------------------
  |  Branch (92:9): [True: 0, False: 3.50k]
  ------------------
   93|      0|      return NULL;
   94|      0|    }
   95|  3.50k|    ret = bn;
   96|  3.50k|  }
   97|       |
   98|  3.50k|  if (len == 0) {
  ------------------
  |  Branch (98:7): [True: 0, False: 3.50k]
  ------------------
   99|      0|    ret->width = 0;
  100|      0|    return ret;
  101|      0|  }
  102|       |
  103|  3.50k|  size_t num_words = ((len - 1) / BN_BYTES) + 1;
  ------------------
  |  |  152|  3.50k|#define BN_BYTES 8
  ------------------
  104|  3.50k|  if (!bn_wexpand(ret, num_words)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 3.50k]
  ------------------
  105|      0|    BN_free(bn);
  106|      0|    return NULL;
  107|      0|  }
  108|       |
  109|       |  // |bn_wexpand| must check bounds on |num_words| to write it into
  110|       |  // |ret->dmax|.
  111|  3.50k|  assert(num_words <= INT_MAX);
  112|  3.50k|  ret->width = (int)num_words;
  113|  3.50k|  ret->neg = 0;
  114|       |
  115|  3.50k|  bn_big_endian_to_words(ret->d, ret->width, in, len);
  116|  3.50k|  return ret;
  117|  3.50k|}

BN_ucmp:
   99|  4.08k|int BN_ucmp(const BIGNUM *a, const BIGNUM *b) {
  100|  4.08k|  return bn_cmp_words_consttime(a->d, a->width, b->d, b->width);
  101|  4.08k|}
BN_cmp:
  103|  1.75k|int BN_cmp(const BIGNUM *a, const BIGNUM *b) {
  104|  1.75k|  if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 1.75k]
  |  Branch (104:22): [True: 0, False: 1.75k]
  ------------------
  105|      0|    if (a != NULL) {
  ------------------
  |  Branch (105:9): [True: 0, False: 0]
  ------------------
  106|      0|      return -1;
  107|      0|    } else if (b != NULL) {
  ------------------
  |  Branch (107:16): [True: 0, False: 0]
  ------------------
  108|      0|      return 1;
  109|      0|    } else {
  110|      0|      return 0;
  111|      0|    }
  112|      0|  }
  113|       |
  114|       |  // We do not attempt to process the sign bit in constant time. Negative
  115|       |  // |BIGNUM|s should never occur in crypto, only calculators.
  116|  1.75k|  if (a->neg != b->neg) {
  ------------------
  |  Branch (116:7): [True: 0, False: 1.75k]
  ------------------
  117|      0|    if (a->neg) {
  ------------------
  |  Branch (117:9): [True: 0, False: 0]
  ------------------
  118|      0|      return -1;
  119|      0|    }
  120|      0|    return 1;
  121|      0|  }
  122|       |
  123|  1.75k|  int ret = BN_ucmp(a, b);
  124|  1.75k|  return a->neg ? -ret : ret;
  ------------------
  |  Branch (124:10): [True: 1.10k, False: 652]
  ------------------
  125|  1.75k|}
BN_is_zero:
  153|  7.22k|int BN_is_zero(const BIGNUM *bn) {
  154|  7.22k|  return bn_fits_in_words(bn, 0);
  155|  7.22k|}
bcm.c:bn_cmp_words_consttime:
   68|  4.08k|                                  const BN_ULONG *b, size_t b_len) {
   69|  4.08k|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
   70|  4.08k|                "crypto_word_t is too small");
   71|  4.08k|  int ret = 0;
   72|       |  // Process the common words in little-endian order.
   73|  4.08k|  size_t min = a_len < b_len ? a_len : b_len;
  ------------------
  |  Branch (73:16): [True: 1.83k, False: 2.24k]
  ------------------
   74|   778k|  for (size_t i = 0; i < min; i++) {
  ------------------
  |  Branch (74:22): [True: 774k, False: 4.08k]
  ------------------
   75|   774k|    crypto_word_t eq = constant_time_eq_w(a[i], b[i]);
   76|   774k|    crypto_word_t lt = constant_time_lt_w(a[i], b[i]);
   77|   774k|    ret =
   78|   774k|        constant_time_select_int(eq, ret, constant_time_select_int(lt, -1, 1));
   79|   774k|  }
   80|       |
   81|       |  // If |a| or |b| has non-zero words beyond |min|, they take precedence.
   82|  4.08k|  if (a_len < b_len) {
  ------------------
  |  Branch (82:7): [True: 1.83k, False: 2.24k]
  ------------------
   83|  1.83k|    crypto_word_t mask = 0;
   84|   295k|    for (size_t i = a_len; i < b_len; i++) {
  ------------------
  |  Branch (84:28): [True: 293k, False: 1.83k]
  ------------------
   85|   293k|      mask |= b[i];
   86|   293k|    }
   87|  1.83k|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, -1);
   88|  2.24k|  } else if (b_len < a_len) {
  ------------------
  |  Branch (88:14): [True: 0, False: 2.24k]
  ------------------
   89|      0|    crypto_word_t mask = 0;
   90|      0|    for (size_t i = b_len; i < a_len; i++) {
  ------------------
  |  Branch (90:28): [True: 0, False: 0]
  ------------------
   91|      0|      mask |= a[i];
   92|      0|    }
   93|      0|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, 1);
   94|      0|  }
   95|       |
   96|  4.08k|  return ret;
   97|  4.08k|}

BN_CTX_new:
  108|  1.75k|BN_CTX *BN_CTX_new(void) {
  109|  1.75k|  BN_CTX *ret = OPENSSL_malloc(sizeof(BN_CTX));
  110|  1.75k|  if (!ret) {
  ------------------
  |  Branch (110:7): [True: 0, False: 1.75k]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|       |  // Initialise the structure
  115|  1.75k|  ret->bignums = NULL;
  116|  1.75k|  BN_STACK_init(&ret->stack);
  117|  1.75k|  ret->used = 0;
  118|  1.75k|  ret->error = 0;
  119|  1.75k|  ret->defer_error = 0;
  120|  1.75k|  return ret;
  121|  1.75k|}
BN_CTX_free:
  123|  1.75k|void BN_CTX_free(BN_CTX *ctx) {
  124|  1.75k|  if (ctx == NULL) {
  ------------------
  |  Branch (124:7): [True: 0, False: 1.75k]
  ------------------
  125|      0|    return;
  126|      0|  }
  127|       |
  128|       |  // All |BN_CTX_start| calls must be matched with |BN_CTX_end|, otherwise the
  129|       |  // function may use more memory than expected, potentially without bound if
  130|       |  // done in a loop. Assert that all |BIGNUM|s have been released.
  131|  1.75k|  assert(ctx->used == 0 || ctx->error);
  132|  1.75k|  sk_BIGNUM_pop_free(ctx->bignums, BN_free);
  133|  1.75k|  BN_STACK_cleanup(&ctx->stack);
  134|  1.75k|  OPENSSL_free(ctx);
  135|  1.75k|}
BN_CTX_start:
  137|  2.97k|void BN_CTX_start(BN_CTX *ctx) {
  138|  2.97k|  if (ctx->error) {
  ------------------
  |  Branch (138:7): [True: 0, False: 2.97k]
  ------------------
  139|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  140|       |    // of |BN_CTX_end| calls to come. Do nothing.
  141|      0|    return;
  142|      0|  }
  143|       |
  144|  2.97k|  if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (144:7): [True: 0, False: 2.97k]
  ------------------
  145|      0|    ctx->error = 1;
  146|       |    // |BN_CTX_start| cannot fail, so defer the error to |BN_CTX_get|.
  147|      0|    ctx->defer_error = 1;
  148|      0|  }
  149|  2.97k|}
BN_CTX_get:
  151|  6.84k|BIGNUM *BN_CTX_get(BN_CTX *ctx) {
  152|       |  // Once any operation has failed, they all do.
  153|  6.84k|  if (ctx->error) {
  ------------------
  |  Branch (153:7): [True: 0, False: 6.84k]
  ------------------
  154|      0|    if (ctx->defer_error) {
  ------------------
  |  Branch (154:9): [True: 0, False: 0]
  ------------------
  155|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      0|      ctx->defer_error = 0;
  157|      0|    }
  158|      0|    return NULL;
  159|      0|  }
  160|       |
  161|  6.84k|  if (ctx->bignums == NULL) {
  ------------------
  |  Branch (161:7): [True: 1.75k, False: 5.09k]
  ------------------
  162|  1.75k|    ctx->bignums = sk_BIGNUM_new_null();
  163|  1.75k|    if (ctx->bignums == NULL) {
  ------------------
  |  Branch (163:9): [True: 0, False: 1.75k]
  ------------------
  164|      0|      ctx->error = 1;
  165|      0|      return NULL;
  166|      0|    }
  167|  1.75k|  }
  168|       |
  169|  6.84k|  if (ctx->used == sk_BIGNUM_num(ctx->bignums)) {
  ------------------
  |  Branch (169:7): [True: 5.25k, False: 1.59k]
  ------------------
  170|  5.25k|    BIGNUM *bn = BN_new();
  171|  5.25k|    if (bn == NULL || !sk_BIGNUM_push(ctx->bignums, bn)) {
  ------------------
  |  Branch (171:9): [True: 0, False: 5.25k]
  |  Branch (171:23): [True: 0, False: 5.25k]
  ------------------
  172|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|      BN_free(bn);
  174|      0|      ctx->error = 1;
  175|      0|      return NULL;
  176|      0|    }
  177|  5.25k|  }
  178|       |
  179|  6.84k|  BIGNUM *ret = sk_BIGNUM_value(ctx->bignums, ctx->used);
  180|  6.84k|  BN_zero(ret);
  181|       |  // This is bounded by |sk_BIGNUM_num|, so it cannot overflow.
  182|  6.84k|  ctx->used++;
  183|  6.84k|  return ret;
  184|  6.84k|}
BN_CTX_end:
  186|  2.97k|void BN_CTX_end(BN_CTX *ctx) {
  187|  2.97k|  if (ctx->error) {
  ------------------
  |  Branch (187:7): [True: 0, False: 2.97k]
  ------------------
  188|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  189|       |    // of |BN_CTX_end| calls to come. Do nothing.
  190|      0|    return;
  191|      0|  }
  192|       |
  193|  2.97k|  ctx->used = BN_STACK_pop(&ctx->stack);
  194|  2.97k|}
bcm.c:BN_STACK_init:
  199|  1.75k|static void BN_STACK_init(BN_STACK *st) {
  200|  1.75k|  st->indexes = NULL;
  201|  1.75k|  st->depth = st->size = 0;
  202|  1.75k|}
bcm.c:BN_STACK_cleanup:
  204|  1.75k|static void BN_STACK_cleanup(BN_STACK *st) {
  205|  1.75k|  OPENSSL_free(st->indexes);
  206|  1.75k|}
bcm.c:BN_STACK_push:
  208|  2.97k|static int BN_STACK_push(BN_STACK *st, size_t idx) {
  209|  2.97k|  if (st->depth == st->size) {
  ------------------
  |  Branch (209:7): [True: 1.75k, False: 1.21k]
  ------------------
  210|       |    // This function intentionally does not push to the error queue on error.
  211|       |    // Error-reporting is deferred to |BN_CTX_get|.
  212|  1.75k|    size_t new_size = st->size != 0 ? st->size * 3 / 2 : BN_CTX_START_FRAMES;
  ------------------
  |  |   67|  1.75k|#define BN_CTX_START_FRAMES 32
  ------------------
  |  Branch (212:23): [True: 0, False: 1.75k]
  ------------------
  213|  1.75k|    if (new_size <= st->size || new_size > ((size_t)-1) / sizeof(size_t)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 1.75k]
  |  Branch (213:33): [True: 0, False: 1.75k]
  ------------------
  214|      0|      return 0;
  215|      0|    }
  216|  1.75k|    size_t *new_indexes =
  217|  1.75k|        OPENSSL_realloc(st->indexes, new_size * sizeof(size_t));
  218|  1.75k|    if (new_indexes == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 1.75k]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|  1.75k|    st->indexes = new_indexes;
  222|  1.75k|    st->size = new_size;
  223|  1.75k|  }
  224|       |
  225|  2.97k|  st->indexes[st->depth] = idx;
  226|  2.97k|  st->depth++;
  227|  2.97k|  return 1;
  228|  2.97k|}
bcm.c:BN_STACK_pop:
  230|  2.97k|static size_t BN_STACK_pop(BN_STACK *st) {
  231|  2.97k|  assert(st->depth > 0);
  232|  2.97k|  st->depth--;
  233|  2.97k|  return st->indexes[st->depth];
  234|  2.97k|}

BN_div:
  195|  1.75k|           const BIGNUM *divisor, BN_CTX *ctx) {
  196|  1.75k|  int norm_shift, loop;
  197|  1.75k|  BIGNUM wnum;
  198|  1.75k|  BN_ULONG *resp, *wnump;
  199|  1.75k|  BN_ULONG d0, d1;
  200|  1.75k|  int num_n, div_n;
  201|       |
  202|       |  // This function relies on the historical minimal-width |BIGNUM| invariant.
  203|       |  // It is already not constant-time (constant-time reductions should use
  204|       |  // Montgomery logic), so we shrink all inputs and intermediate values to
  205|       |  // retain the previous behavior.
  206|       |
  207|       |  // Invalid zero-padding would have particularly bad consequences.
  208|  1.75k|  int numerator_width = bn_minimal_width(numerator);
  209|  1.75k|  int divisor_width = bn_minimal_width(divisor);
  210|  1.75k|  if ((numerator_width > 0 && numerator->d[numerator_width - 1] == 0) ||
  ------------------
  |  Branch (210:8): [True: 1.65k, False: 97]
  |  Branch (210:31): [True: 0, False: 1.65k]
  ------------------
  211|  1.75k|      (divisor_width > 0 && divisor->d[divisor_width - 1] == 0)) {
  ------------------
  |  Branch (211:8): [True: 1.75k, False: 0]
  |  Branch (211:29): [True: 0, False: 1.75k]
  ------------------
  212|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NOT_INITIALIZED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|      0|    return 0;
  214|      0|  }
  215|       |
  216|  1.75k|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (216:7): [True: 0, False: 1.75k]
  ------------------
  217|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  218|      0|    return 0;
  219|      0|  }
  220|       |
  221|  1.75k|  BN_CTX_start(ctx);
  222|  1.75k|  BIGNUM *tmp = BN_CTX_get(ctx);
  223|  1.75k|  BIGNUM *snum = BN_CTX_get(ctx);
  224|  1.75k|  BIGNUM *sdiv = BN_CTX_get(ctx);
  225|  1.75k|  BIGNUM *res = NULL;
  226|  1.75k|  if (quotient == NULL) {
  ------------------
  |  Branch (226:7): [True: 0, False: 1.75k]
  ------------------
  227|      0|    res = BN_CTX_get(ctx);
  228|  1.75k|  } else {
  229|  1.75k|    res = quotient;
  230|  1.75k|  }
  231|  1.75k|  if (sdiv == NULL || res == NULL) {
  ------------------
  |  Branch (231:7): [True: 0, False: 1.75k]
  |  Branch (231:23): [True: 0, False: 1.75k]
  ------------------
  232|      0|    goto err;
  233|      0|  }
  234|       |
  235|       |  // First we normalise the numbers
  236|  1.75k|  norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|  1.75k|#define BN_BITS2 64
  ------------------
                norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|  1.75k|#define BN_BITS2 64
  ------------------
  237|  1.75k|  if (!BN_lshift(sdiv, divisor, norm_shift)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 1.75k]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|  1.75k|  bn_set_minimal_width(sdiv);
  241|  1.75k|  sdiv->neg = 0;
  242|  1.75k|  norm_shift += BN_BITS2;
  ------------------
  |  |  151|  1.75k|#define BN_BITS2 64
  ------------------
  243|  1.75k|  if (!BN_lshift(snum, numerator, norm_shift)) {
  ------------------
  |  Branch (243:7): [True: 0, False: 1.75k]
  ------------------
  244|      0|    goto err;
  245|      0|  }
  246|  1.75k|  bn_set_minimal_width(snum);
  247|  1.75k|  snum->neg = 0;
  248|       |
  249|       |  // Since we don't want to have special-case logic for the case where snum is
  250|       |  // larger than sdiv, we pad snum with enough zeroes without changing its
  251|       |  // value.
  252|  1.75k|  if (snum->width <= sdiv->width + 1) {
  ------------------
  |  Branch (252:7): [True: 565, False: 1.18k]
  ------------------
  253|    565|    if (!bn_wexpand(snum, sdiv->width + 2)) {
  ------------------
  |  Branch (253:9): [True: 0, False: 565]
  ------------------
  254|      0|      goto err;
  255|      0|    }
  256|   134k|    for (int i = snum->width; i < sdiv->width + 2; i++) {
  ------------------
  |  Branch (256:31): [True: 133k, False: 565]
  ------------------
  257|   133k|      snum->d[i] = 0;
  258|   133k|    }
  259|    565|    snum->width = sdiv->width + 2;
  260|  1.18k|  } else {
  261|  1.18k|    if (!bn_wexpand(snum, snum->width + 1)) {
  ------------------
  |  Branch (261:9): [True: 0, False: 1.18k]
  ------------------
  262|      0|      goto err;
  263|      0|    }
  264|  1.18k|    snum->d[snum->width] = 0;
  265|  1.18k|    snum->width++;
  266|  1.18k|  }
  267|       |
  268|  1.75k|  div_n = sdiv->width;
  269|  1.75k|  num_n = snum->width;
  270|  1.75k|  loop = num_n - div_n;
  271|       |  // Lets setup a 'window' into snum
  272|       |  // This is the part that corresponds to the current
  273|       |  // 'area' being divided
  274|  1.75k|  wnum.neg = 0;
  275|  1.75k|  wnum.d = &(snum->d[loop]);
  276|  1.75k|  wnum.width = div_n;
  277|       |  // only needed when BN_ucmp messes up the values between width and max
  278|  1.75k|  wnum.dmax = snum->dmax - loop;  // so we don't step out of bounds
  279|       |
  280|       |  // Get the top 2 words of sdiv
  281|       |  // div_n=sdiv->width;
  282|  1.75k|  d0 = sdiv->d[div_n - 1];
  283|  1.75k|  d1 = (div_n == 1) ? 0 : sdiv->d[div_n - 2];
  ------------------
  |  Branch (283:8): [True: 963, False: 789]
  ------------------
  284|       |
  285|       |  // pointer to the 'top' of snum
  286|  1.75k|  wnump = &(snum->d[num_n - 1]);
  287|       |
  288|       |  // Setup |res|. |numerator| and |res| may alias, so we save |numerator->neg|
  289|       |  // for later.
  290|  1.75k|  const int numerator_neg = numerator->neg;
  291|  1.75k|  res->neg = (numerator_neg ^ divisor->neg);
  292|  1.75k|  if (!bn_wexpand(res, loop + 1)) {
  ------------------
  |  Branch (292:7): [True: 0, False: 1.75k]
  ------------------
  293|      0|    goto err;
  294|      0|  }
  295|  1.75k|  res->width = loop - 1;
  296|  1.75k|  resp = &(res->d[loop - 1]);
  297|       |
  298|       |  // space for temp
  299|  1.75k|  if (!bn_wexpand(tmp, div_n + 1)) {
  ------------------
  |  Branch (299:7): [True: 0, False: 1.75k]
  ------------------
  300|      0|    goto err;
  301|      0|  }
  302|       |
  303|       |  // if res->width == 0 then clear the neg value otherwise decrease
  304|       |  // the resp pointer
  305|  1.75k|  if (res->width == 0) {
  ------------------
  |  Branch (305:7): [True: 0, False: 1.75k]
  ------------------
  306|      0|    res->neg = 0;
  307|  1.75k|  } else {
  308|  1.75k|    resp--;
  309|  1.75k|  }
  310|       |
  311|   331k|  for (int i = 0; i < loop - 1; i++, wnump--, resp--) {
  ------------------
  |  Branch (311:19): [True: 329k, False: 1.75k]
  ------------------
  312|   329k|    BN_ULONG q, l0;
  313|       |    // the first part of the loop uses the top two words of snum and sdiv to
  314|       |    // calculate a BN_ULONG q such that | wnum - sdiv * q | < sdiv
  315|   329k|    BN_ULONG n0, n1, rm = 0;
  316|       |
  317|   329k|    n0 = wnump[0];
  318|   329k|    n1 = wnump[-1];
  319|   329k|    if (n0 == d0) {
  ------------------
  |  Branch (319:9): [True: 401, False: 329k]
  ------------------
  320|    401|      q = BN_MASK2;
  ------------------
  |  |  154|    401|#define BN_MASK2 (0xffffffffffffffffUL)
  ------------------
  321|   329k|    } else {
  322|       |      // n0 < d0
  323|   329k|      bn_div_rem_words(&q, &rm, n0, n1, d0);
  324|       |
  325|   329k|#ifdef BN_ULLONG
  326|   329k|      BN_ULLONG t2 = (BN_ULLONG)d1 * q;
  ------------------
  |  |  145|   329k|#define BN_ULLONG uint128_t
  ------------------
  327|   345k|      for (;;) {
  328|   345k|        if (t2 <= ((((BN_ULLONG)rm) << BN_BITS2) | wnump[-2])) {
  ------------------
  |  |  151|   345k|#define BN_BITS2 64
  ------------------
  |  Branch (328:13): [True: 311k, False: 33.9k]
  ------------------
  329|   311k|          break;
  330|   311k|        }
  331|  33.9k|        q--;
  332|  33.9k|        rm += d0;
  333|  33.9k|        if (rm < d0) {
  ------------------
  |  Branch (333:13): [True: 17.5k, False: 16.3k]
  ------------------
  334|  17.5k|          break;  // don't let rm overflow
  335|  17.5k|        }
  336|  16.3k|        t2 -= d1;
  337|  16.3k|      }
  338|       |#else  // !BN_ULLONG
  339|       |      BN_ULONG t2l, t2h;
  340|       |      BN_UMULT_LOHI(t2l, t2h, d1, q);
  341|       |      for (;;) {
  342|       |        if (t2h < rm ||
  343|       |            (t2h == rm && t2l <= wnump[-2])) {
  344|       |          break;
  345|       |        }
  346|       |        q--;
  347|       |        rm += d0;
  348|       |        if (rm < d0) {
  349|       |          break;  // don't let rm overflow
  350|       |        }
  351|       |        if (t2l < d1) {
  352|       |          t2h--;
  353|       |        }
  354|       |        t2l -= d1;
  355|       |      }
  356|       |#endif  // !BN_ULLONG
  357|   329k|    }
  358|       |
  359|   329k|    l0 = bn_mul_words(tmp->d, sdiv->d, div_n, q);
  360|   329k|    tmp->d[div_n] = l0;
  361|   329k|    wnum.d--;
  362|       |    // ingore top values of the bignums just sub the two
  363|       |    // BN_ULONG arrays with bn_sub_words
  364|   329k|    if (bn_sub_words(wnum.d, wnum.d, tmp->d, div_n + 1)) {
  ------------------
  |  Branch (364:9): [True: 260, False: 329k]
  ------------------
  365|       |      // Note: As we have considered only the leading
  366|       |      // two BN_ULONGs in the calculation of q, sdiv * q
  367|       |      // might be greater than wnum (but then (q-1) * sdiv
  368|       |      // is less or equal than wnum)
  369|    260|      q--;
  370|    260|      if (bn_add_words(wnum.d, wnum.d, sdiv->d, div_n)) {
  ------------------
  |  Branch (370:11): [True: 260, False: 0]
  ------------------
  371|       |        // we can't have an overflow here (assuming
  372|       |        // that q != 0, but if q == 0 then tmp is
  373|       |        // zero anyway)
  374|    260|        (*wnump)++;
  375|    260|      }
  376|    260|    }
  377|       |    // store part of the result
  378|   329k|    *resp = q;
  379|   329k|  }
  380|       |
  381|  1.75k|  bn_set_minimal_width(snum);
  382|       |
  383|  1.75k|  if (rem != NULL) {
  ------------------
  |  Branch (383:7): [True: 1.75k, False: 0]
  ------------------
  384|  1.75k|    if (!BN_rshift(rem, snum, norm_shift)) {
  ------------------
  |  Branch (384:9): [True: 0, False: 1.75k]
  ------------------
  385|      0|      goto err;
  386|      0|    }
  387|  1.75k|    if (!BN_is_zero(rem)) {
  ------------------
  |  Branch (387:9): [True: 1.28k, False: 466]
  ------------------
  388|  1.28k|      rem->neg = numerator_neg;
  389|  1.28k|    }
  390|  1.75k|  }
  391|       |
  392|  1.75k|  bn_set_minimal_width(res);
  393|  1.75k|  BN_CTX_end(ctx);
  394|  1.75k|  return 1;
  395|       |
  396|      0|err:
  397|      0|  BN_CTX_end(ctx);
  398|      0|  return 0;
  399|  1.75k|}
bcm.c:bn_div_rem_words:
  140|   329k|                                    BN_ULONG n0, BN_ULONG n1, BN_ULONG d0) {
  141|       |  // GCC and Clang generate function calls to |__udivdi3| and |__umoddi3| when
  142|       |  // the |BN_ULLONG|-based C code is used.
  143|       |  //
  144|       |  // GCC bugs:
  145|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=14224
  146|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=43721
  147|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=54183
  148|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=58897
  149|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=65668
  150|       |  //
  151|       |  // Clang bugs:
  152|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=6397
  153|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=12418
  154|       |  //
  155|       |  // These issues aren't specific to x86 and x86_64, so it might be worthwhile
  156|       |  // to add more assembly language implementations.
  157|       |#if defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86)
  158|       |  __asm__ volatile("divl %4"
  159|       |                   : "=a"(*quotient_out), "=d"(*rem_out)
  160|       |                   : "a"(n1), "d"(n0), "rm"(d0)
  161|       |                   : "cc");
  162|       |#elif defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86_64)
  163|   329k|  __asm__ volatile("divq %4"
  164|   329k|                   : "=a"(*quotient_out), "=d"(*rem_out)
  165|   329k|                   : "a"(n1), "d"(n0), "rm"(d0)
  166|   329k|                   : "cc");
  167|       |#else
  168|       |#if defined(BN_CAN_DIVIDE_ULLONG)
  169|       |  BN_ULLONG n = (((BN_ULLONG)n0) << BN_BITS2) | n1;
  170|       |  *quotient_out = (BN_ULONG)(n / d0);
  171|       |#else
  172|       |  *quotient_out = bn_div_words(n0, n1, d0);
  173|       |#endif
  174|       |  *rem_out = n1 - (*quotient_out * d0);
  175|       |#endif
  176|   329k|}

BN_mul:
  515|  1.75k|int BN_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  516|  1.75k|  if (!bn_mul_impl(r, a, b, ctx)) {
  ------------------
  |  Branch (516:7): [True: 0, False: 1.75k]
  ------------------
  517|      0|    return 0;
  518|      0|  }
  519|       |
  520|       |  // This additionally fixes any negative zeros created by |bn_mul_impl|.
  521|  1.75k|  bn_set_minimal_width(r);
  522|  1.75k|  return 1;
  523|  1.75k|}
bcm.c:bn_abs_sub_part_words:
  172|   482k|                                      BN_ULONG *tmp) {
  173|   482k|  BN_ULONG borrow = bn_sub_part_words(tmp, a, b, cl, dl);
  174|   482k|  bn_sub_part_words(r, b, a, cl, -dl);
  175|   482k|  int r_len = cl + (dl < 0 ? -dl : dl);
  ------------------
  |  Branch (175:21): [True: 537, False: 481k]
  ------------------
  176|   482k|  borrow = 0 - borrow;
  177|   482k|  bn_select_words(r, borrow, r /* tmp < 0 */, tmp /* tmp >= 0 */, r_len);
  178|   482k|  return borrow;
  179|   482k|}
bcm.c:bn_sub_part_words:
  130|   964k|                                  const BN_ULONG *b, int cl, int dl) {
  131|   964k|  assert(cl >= 0);
  132|   964k|  BN_ULONG borrow = bn_sub_words(r, a, b, cl);
  133|   964k|  if (dl == 0) {
  ------------------
  |  Branch (133:7): [True: 962k, False: 2.07k]
  ------------------
  134|   962k|    return borrow;
  135|   962k|  }
  136|       |
  137|  2.07k|  r += cl;
  138|  2.07k|  a += cl;
  139|  2.07k|  b += cl;
  140|       |
  141|  2.07k|  if (dl < 0) {
  ------------------
  |  Branch (141:7): [True: 1.03k, False: 1.03k]
  ------------------
  142|       |    // |a| is shorter than |b|. Complete the subtraction as if the excess words
  143|       |    // in |a| were zeros.
  144|  1.03k|    dl = -dl;
  145|  91.8k|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (145:21): [True: 90.7k, False: 1.03k]
  ------------------
  146|  90.7k|      r[i] = 0u - b[i] - borrow;
  147|  90.7k|      borrow |= r[i] != 0;
  148|  90.7k|    }
  149|  1.03k|  } else {
  150|       |    // |b| is shorter than |a|. Complete the subtraction as if the excess words
  151|       |    // in |b| were zeros.
  152|  91.8k|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (152:21): [True: 90.7k, False: 1.03k]
  ------------------
  153|       |      // |r| and |a| may alias, so use a temporary.
  154|  90.7k|      BN_ULONG tmp = a[i];
  155|  90.7k|      r[i] = a[i] - borrow;
  156|  90.7k|      borrow = tmp < r[i];
  157|  90.7k|    }
  158|  1.03k|  }
  159|       |
  160|  2.07k|  return borrow;
  161|   964k|}
bcm.c:bn_mul_impl:
  420|  1.75k|                       BN_CTX *ctx) {
  421|  1.75k|  int al = a->width;
  422|  1.75k|  int bl = b->width;
  423|  1.75k|  if (al == 0 || bl == 0) {
  ------------------
  |  Branch (423:7): [True: 533, False: 1.21k]
  |  Branch (423:18): [True: 0, False: 1.21k]
  ------------------
  424|    533|    BN_zero(r);
  425|    533|    return 1;
  426|    533|  }
  427|       |
  428|  1.21k|  int ret = 0;
  429|  1.21k|  BIGNUM *rr;
  430|  1.21k|  BN_CTX_start(ctx);
  431|  1.21k|  if (r == a || r == b) {
  ------------------
  |  Branch (431:7): [True: 1.21k, False: 0]
  |  Branch (431:17): [True: 0, False: 0]
  ------------------
  432|  1.21k|    rr = BN_CTX_get(ctx);
  433|  1.21k|    if (rr == NULL) {
  ------------------
  |  Branch (433:9): [True: 0, False: 1.21k]
  ------------------
  434|      0|      goto err;
  435|      0|    }
  436|  1.21k|  } else {
  437|      0|    rr = r;
  438|      0|  }
  439|  1.21k|  rr->neg = a->neg ^ b->neg;
  440|       |
  441|  1.21k|  int i = al - bl;
  442|  1.21k|  if (i == 0) {
  ------------------
  |  Branch (442:7): [True: 394, False: 825]
  ------------------
  443|    394|    if (al == 8) {
  ------------------
  |  Branch (443:9): [True: 2, False: 392]
  ------------------
  444|      2|      if (!bn_wexpand(rr, 16)) {
  ------------------
  |  Branch (444:11): [True: 0, False: 2]
  ------------------
  445|      0|        goto err;
  446|      0|      }
  447|      2|      rr->width = 16;
  448|      2|      bn_mul_comba8(rr->d, a->d, b->d);
  449|      2|      goto end;
  450|      2|    }
  451|    394|  }
  452|       |
  453|  1.21k|  int top = al + bl;
  454|  1.21k|  static const int kMulNormalSize = 16;
  455|  1.21k|  if (al >= kMulNormalSize && bl >= kMulNormalSize) {
  ------------------
  |  Branch (455:7): [True: 608, False: 609]
  |  Branch (455:31): [True: 471, False: 137]
  ------------------
  456|    471|    if (-1 <= i && i <= 1) {
  ------------------
  |  Branch (456:9): [True: 422, False: 49]
  |  Branch (456:20): [True: 374, False: 48]
  ------------------
  457|       |      // Find the largest power of two less than or equal to the larger length.
  458|    374|      int j;
  459|    374|      if (i >= 0) {
  ------------------
  |  Branch (459:11): [True: 327, False: 47]
  ------------------
  460|    327|        j = BN_num_bits_word((BN_ULONG)al);
  461|    327|      } else {
  462|     47|        j = BN_num_bits_word((BN_ULONG)bl);
  463|     47|      }
  464|    374|      j = 1 << (j - 1);
  465|    374|      assert(j <= al || j <= bl);
  466|    374|      BIGNUM *t = BN_CTX_get(ctx);
  467|    374|      if (t == NULL) {
  ------------------
  |  Branch (467:11): [True: 0, False: 374]
  ------------------
  468|      0|        goto err;
  469|      0|      }
  470|    374|      if (al > j || bl > j) {
  ------------------
  |  Branch (470:11): [True: 303, False: 71]
  |  Branch (470:21): [True: 9, False: 62]
  ------------------
  471|       |        // We know |al| and |bl| are at most one from each other, so if al > j,
  472|       |        // bl >= j, and vice versa. Thus we can use |bn_mul_part_recursive|.
  473|       |        //
  474|       |        // TODO(davidben): This codepath is almost unused in standard
  475|       |        // algorithms. Is this optimization necessary? See notes in
  476|       |        // https://boringssl-review.googlesource.com/q/I0bd604e2cd6a75c266f64476c23a730ca1721ea6
  477|    312|        assert(al >= j && bl >= j);
  478|    312|        if (!bn_wexpand(t, j * 8) ||
  ------------------
  |  Branch (478:13): [True: 0, False: 312]
  ------------------
  479|    312|            !bn_wexpand(rr, j * 4)) {
  ------------------
  |  Branch (479:13): [True: 0, False: 312]
  ------------------
  480|      0|          goto err;
  481|      0|        }
  482|    312|        bn_mul_part_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  483|    312|      } else {
  484|       |        // al <= j && bl <= j. Additionally, we know j <= al or j <= bl, so one
  485|       |        // of al - j or bl - j is zero. The other, by the bound on |i| above, is
  486|       |        // zero or -1. Thus, we can use |bn_mul_recursive|.
  487|     62|        if (!bn_wexpand(t, j * 4) ||
  ------------------
  |  Branch (487:13): [True: 0, False: 62]
  ------------------
  488|     62|            !bn_wexpand(rr, j * 2)) {
  ------------------
  |  Branch (488:13): [True: 0, False: 62]
  ------------------
  489|      0|          goto err;
  490|      0|        }
  491|     62|        bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  492|     62|      }
  493|    374|      rr->width = top;
  494|    374|      goto end;
  495|    374|    }
  496|    471|  }
  497|       |
  498|    843|  if (!bn_wexpand(rr, top)) {
  ------------------
  |  Branch (498:7): [True: 0, False: 843]
  ------------------
  499|      0|    goto err;
  500|      0|  }
  501|    843|  rr->width = top;
  502|    843|  bn_mul_normal(rr->d, a->d, al, b->d, bl);
  503|       |
  504|  1.21k|end:
  505|  1.21k|  if (r != rr && !BN_copy(r, rr)) {
  ------------------
  |  Branch (505:7): [True: 1.21k, False: 0]
  |  Branch (505:18): [True: 0, False: 1.21k]
  ------------------
  506|      0|    goto err;
  507|      0|  }
  508|  1.21k|  ret = 1;
  509|       |
  510|  1.21k|err:
  511|  1.21k|  BN_CTX_end(ctx);
  512|  1.21k|  return ret;
  513|  1.21k|}
bcm.c:bn_mul_part_recursive:
  312|    436|                                  BN_ULONG *t) {
  313|       |  // |n| is a power of two.
  314|    436|  assert(n != 0 && (n & (n - 1)) == 0);
  315|       |  // Check |tna| and |tnb| are in range.
  316|    436|  assert(0 <= tna && tna < n);
  317|    436|  assert(0 <= tnb && tnb < n);
  318|    436|  assert(-1 <= tna - tnb && tna - tnb <= 1);
  319|       |
  320|    436|  int n2 = n * 2;
  321|    436|  if (n < 8) {
  ------------------
  |  Branch (321:7): [True: 0, False: 436]
  ------------------
  322|      0|    bn_mul_normal(r, a, n + tna, b, n + tnb);
  323|      0|    OPENSSL_memset(r + n2 + tna + tnb, 0, n2 - tna - tnb);
  324|      0|    return;
  325|      0|  }
  326|       |
  327|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|. |a1|
  328|       |  // and |b1| have size |tna| and |tnb|, respectively.
  329|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  330|       |  // for recursive calls.
  331|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  332|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  333|       |  //
  334|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  335|       |
  336|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  337|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  338|       |  // themselves store the absolute value.
  339|    436|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  340|    436|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  341|       |
  342|       |  // Compute:
  343|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  344|       |  // r0,r1 = a0 * b0
  345|       |  // r2,r3 = a1 * b1
  346|    436|  if (n == 8) {
  ------------------
  |  Branch (346:7): [True: 0, False: 436]
  ------------------
  347|      0|    bn_mul_comba8(&t[n2], t, &t[n]);
  348|      0|    bn_mul_comba8(r, a, b);
  349|       |
  350|      0|    bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  351|       |    // |bn_mul_normal| only writes |tna| + |tna| words. Zero the rest.
  352|      0|    OPENSSL_memset(&r[n2 + tna + tnb], 0, sizeof(BN_ULONG) * (n2 - tna - tnb));
  353|    436|  } else {
  354|    436|    BN_ULONG *p = &t[n2 * 2];
  355|    436|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  356|    436|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  357|       |
  358|    436|    OPENSSL_memset(&r[n2], 0, sizeof(BN_ULONG) * n2);
  359|    436|    if (tna < BN_MUL_RECURSIVE_SIZE_NORMAL &&
  ------------------
  |  |   70|    872|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (359:9): [True: 283, False: 153]
  ------------------
  360|    436|        tnb < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|    283|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (360:9): [True: 279, False: 4]
  ------------------
  361|    279|      bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  362|    279|    } else {
  363|    157|      int i = n;
  364|    214|      for (;;) {
  365|    214|        i /= 2;
  366|    214|        if (i < tna || i < tnb) {
  ------------------
  |  Branch (366:13): [True: 120, False: 94]
  |  Branch (366:24): [True: 4, False: 90]
  ------------------
  367|       |          // E.g., n == 16, i == 8 and tna == 11. |tna| and |tnb| are within one
  368|       |          // of each other, so if |tna| is larger and tna > i, then we know
  369|       |          // tnb >= i, and this call is valid.
  370|    124|          bn_mul_part_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  371|    124|          break;
  372|    124|        }
  373|     90|        if (i == tna || i == tnb) {
  ------------------
  |  Branch (373:13): [True: 24, False: 66]
  |  Branch (373:25): [True: 9, False: 57]
  ------------------
  374|       |          // If there is only a bottom half to the number, just do it. We know
  375|       |          // the larger of |tna - i| and |tnb - i| is zero. The other is zero or
  376|       |          // -1 by because of |tna| and |tnb| differ by at most one.
  377|     33|          bn_mul_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  378|     33|          break;
  379|     33|        }
  380|       |
  381|       |        // This loop will eventually terminate when |i| falls below
  382|       |        // |BN_MUL_RECURSIVE_SIZE_NORMAL| because we know one of |tna| and |tnb|
  383|       |        // exceeds that.
  384|     90|      }
  385|    157|    }
  386|    436|  }
  387|       |
  388|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  389|    436|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  390|       |
  391|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  392|       |  // The second term is stored as the absolute value, so we do this with a
  393|       |  // constant-time select.
  394|    436|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  395|    436|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  396|    436|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  397|    436|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  398|    436|                "crypto_word_t is too small");
  399|    436|  c = constant_time_select_w(neg, c_neg, c_pos);
  400|       |
  401|       |  // We now have our three components. Add them together.
  402|       |  // r1,r2,c = r1,r2 + t2,t3,c
  403|    436|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  404|       |
  405|       |  // Propagate the carry bit to the end.
  406|  82.0k|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (406:24): [True: 81.5k, False: 436]
  ------------------
  407|  81.5k|    BN_ULONG old = r[i];
  408|  81.5k|    r[i] = old + c;
  409|  81.5k|    c = r[i] < old;
  410|  81.5k|  }
  411|       |
  412|       |  // The product should fit without carries.
  413|    436|  assert(c == 0);
  414|    436|}
bcm.c:bn_mul_recursive:
  211|   240k|                             int n2, int dna, int dnb, BN_ULONG *t) {
  212|       |  // |n2| is a power of two.
  213|   240k|  assert(n2 != 0 && (n2 & (n2 - 1)) == 0);
  214|       |  // Check |dna| and |dnb| are in range.
  215|   240k|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dna && dna <= 0);
  216|   240k|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dnb && dnb <= 0);
  217|       |
  218|       |  // Only call bn_mul_comba 8 if n2 == 8 and the
  219|       |  // two arrays are complete [steve]
  220|   240k|  if (n2 == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (220:7): [True: 135, False: 240k]
  |  Branch (220:18): [True: 118, False: 17]
  |  Branch (220:30): [True: 90, False: 28]
  ------------------
  221|     90|    bn_mul_comba8(r, a, b);
  222|     90|    return;
  223|     90|  }
  224|       |
  225|       |  // Else do normal multiply
  226|   240k|  if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|   240k|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (226:7): [True: 45, False: 240k]
  ------------------
  227|     45|    bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
  228|     45|    if (dna + dnb < 0) {
  ------------------
  |  Branch (228:9): [True: 45, False: 0]
  ------------------
  229|     45|      OPENSSL_memset(&r[2 * n2 + dna + dnb], 0,
  230|     45|                     sizeof(BN_ULONG) * -(dna + dnb));
  231|     45|    }
  232|     45|    return;
  233|     45|  }
  234|       |
  235|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|.
  236|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  237|       |  // for recursive calls.
  238|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  239|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  240|       |  //
  241|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  242|       |  //
  243|       |  // Note that we know |n| >= |BN_MUL_RECURSIVE_SIZE_NORMAL|/2 above, so
  244|       |  // |tna| and |tnb| are non-negative.
  245|   240k|  int n = n2 / 2, tna = n + dna, tnb = n + dnb;
  246|       |
  247|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  248|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  249|       |  // themselves store the absolute value.
  250|   240k|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  251|   240k|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  252|       |
  253|       |  // Compute:
  254|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  255|       |  // r0,r1 = a0 * b0
  256|       |  // r2,r3 = a1 * b1
  257|   240k|  if (n == 4 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (257:7): [True: 0, False: 240k]
  |  Branch (257:17): [True: 0, False: 0]
  |  Branch (257:29): [True: 0, False: 0]
  ------------------
  258|      0|    bn_mul_comba4(&t[n2], t, &t[n]);
  259|       |
  260|      0|    bn_mul_comba4(r, a, b);
  261|      0|    bn_mul_comba4(&r[n2], &a[n], &b[n]);
  262|   240k|  } else if (n == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (262:14): [True: 160k, False: 79.9k]
  |  Branch (262:24): [True: 160k, False: 17]
  |  Branch (262:36): [True: 160k, False: 28]
  ------------------
  263|   160k|    bn_mul_comba8(&t[n2], t, &t[n]);
  264|       |
  265|   160k|    bn_mul_comba8(r, a, b);
  266|   160k|    bn_mul_comba8(&r[n2], &a[n], &b[n]);
  267|   160k|  } else {
  268|  79.9k|    BN_ULONG *p = &t[n2 * 2];
  269|  79.9k|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  270|  79.9k|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  271|  79.9k|    bn_mul_recursive(&r[n2], &a[n], &b[n], n, dna, dnb, p);
  272|  79.9k|  }
  273|       |
  274|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  275|   240k|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  276|       |
  277|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  278|       |  // The second term is stored as the absolute value, so we do this with a
  279|       |  // constant-time select.
  280|   240k|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  281|   240k|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  282|   240k|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  283|   240k|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  284|   240k|                "crypto_word_t is too small");
  285|   240k|  c = constant_time_select_w(neg, c_neg, c_pos);
  286|       |
  287|       |  // We now have our three components. Add them together.
  288|       |  // r1,r2,c = r1,r2 + t2,t3,c
  289|   240k|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  290|       |
  291|       |  // Propagate the carry bit to the end.
  292|  3.91M|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (292:24): [True: 3.67M, False: 240k]
  ------------------
  293|  3.67M|    BN_ULONG old = r[i];
  294|  3.67M|    r[i] = old + c;
  295|  3.67M|    c = r[i] < old;
  296|  3.67M|  }
  297|       |
  298|       |  // The product should fit without carries.
  299|   240k|  assert(c == 0);
  300|   240k|}
bcm.c:bn_mul_normal:
   82|  1.16k|                          const BN_ULONG *b, size_t nb) {
   83|  1.16k|  if (na < nb) {
  ------------------
  |  Branch (83:7): [True: 278, False: 889]
  ------------------
   84|    278|    size_t itmp = na;
   85|    278|    na = nb;
   86|    278|    nb = itmp;
   87|    278|    const BN_ULONG *ltmp = a;
   88|    278|    a = b;
   89|    278|    b = ltmp;
   90|    278|  }
   91|  1.16k|  BN_ULONG *rr = &(r[na]);
   92|  1.16k|  if (nb == 0) {
  ------------------
  |  Branch (92:7): [True: 229, False: 938]
  ------------------
   93|    229|    OPENSSL_memset(r, 0, na * sizeof(BN_ULONG));
   94|    229|    return;
   95|    229|  }
   96|    938|  rr[0] = bn_mul_words(r, a, na, b[0]);
   97|       |
   98|  8.08k|  for (;;) {
   99|  8.08k|    if (--nb == 0) {
  ------------------
  |  Branch (99:9): [True: 678, False: 7.40k]
  ------------------
  100|    678|      return;
  101|    678|    }
  102|  7.40k|    rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  103|  7.40k|    if (--nb == 0) {
  ------------------
  |  Branch (103:9): [True: 101, False: 7.30k]
  ------------------
  104|    101|      return;
  105|    101|    }
  106|  7.30k|    rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  107|  7.30k|    if (--nb == 0) {
  ------------------
  |  Branch (107:9): [True: 100, False: 7.20k]
  ------------------
  108|    100|      return;
  109|    100|    }
  110|  7.20k|    rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  111|  7.20k|    if (--nb == 0) {
  ------------------
  |  Branch (111:9): [True: 59, False: 7.14k]
  ------------------
  112|     59|      return;
  113|     59|    }
  114|  7.14k|    rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  115|  7.14k|    rr += 4;
  116|  7.14k|    r += 4;
  117|  7.14k|    b += 4;
  118|  7.14k|  }
  119|    938|}

BN_lshift:
   67|  3.50k|int BN_lshift(BIGNUM *r, const BIGNUM *a, int n) {
   68|  3.50k|  int i, nw, lb, rb;
   69|  3.50k|  BN_ULONG *t, *f;
   70|  3.50k|  BN_ULONG l;
   71|       |
   72|  3.50k|  if (n < 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 3.50k]
  ------------------
   73|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   74|      0|    return 0;
   75|      0|  }
   76|       |
   77|  3.50k|  r->neg = a->neg;
   78|  3.50k|  nw = n / BN_BITS2;
  ------------------
  |  |  151|  3.50k|#define BN_BITS2 64
  ------------------
   79|  3.50k|  if (!bn_wexpand(r, a->width + nw + 1)) {
  ------------------
  |  Branch (79:7): [True: 0, False: 3.50k]
  ------------------
   80|      0|    return 0;
   81|      0|  }
   82|  3.50k|  lb = n % BN_BITS2;
  ------------------
  |  |  151|  3.50k|#define BN_BITS2 64
  ------------------
   83|  3.50k|  rb = BN_BITS2 - lb;
  ------------------
  |  |  151|  3.50k|#define BN_BITS2 64
  ------------------
   84|  3.50k|  f = a->d;
   85|  3.50k|  t = r->d;
   86|  3.50k|  t[a->width + nw] = 0;
   87|  3.50k|  if (lb == 0) {
  ------------------
  |  Branch (87:7): [True: 630, False: 2.87k]
  ------------------
   88|   120k|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (88:28): [True: 120k, False: 630]
  ------------------
   89|   120k|      t[nw + i] = f[i];
   90|   120k|    }
   91|  2.87k|  } else {
   92|   847k|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (92:28): [True: 844k, False: 2.87k]
  ------------------
   93|   844k|      l = f[i];
   94|   844k|      t[nw + i + 1] |= l >> rb;
   95|   844k|      t[nw + i] = l << lb;
   96|   844k|    }
   97|  2.87k|  }
   98|  3.50k|  OPENSSL_memset(t, 0, nw * sizeof(t[0]));
   99|  3.50k|  r->width = a->width + nw + 1;
  100|  3.50k|  bn_set_minimal_width(r);
  101|       |
  102|  3.50k|  return 1;
  103|  3.50k|}
bn_rshift_words:
  137|  1.75k|                     size_t num) {
  138|  1.75k|  unsigned shift_bits = shift % BN_BITS2;
  ------------------
  |  |  151|  1.75k|#define BN_BITS2 64
  ------------------
  139|  1.75k|  size_t shift_words = shift / BN_BITS2;
  ------------------
  |  |  151|  1.75k|#define BN_BITS2 64
  ------------------
  140|  1.75k|  if (shift_words >= num) {
  ------------------
  |  Branch (140:7): [True: 466, False: 1.28k]
  ------------------
  141|    466|    OPENSSL_memset(r, 0, num * sizeof(BN_ULONG));
  142|    466|    return;
  143|    466|  }
  144|  1.28k|  if (shift_bits == 0) {
  ------------------
  |  Branch (144:7): [True: 264, False: 1.02k]
  ------------------
  145|    264|    OPENSSL_memmove(r, a + shift_words, (num - shift_words) * sizeof(BN_ULONG));
  146|  1.02k|  } else {
  147|   201k|    for (size_t i = shift_words; i < num - 1; i++) {
  ------------------
  |  Branch (147:34): [True: 200k, False: 1.02k]
  ------------------
  148|   200k|      r[i - shift_words] =
  149|   200k|          (a[i] >> shift_bits) | (a[i + 1] << (BN_BITS2 - shift_bits));
  ------------------
  |  |  151|   200k|#define BN_BITS2 64
  ------------------
  150|   200k|    }
  151|  1.02k|    r[num - 1 - shift_words] = a[num - 1] >> shift_bits;
  152|  1.02k|  }
  153|  1.28k|  OPENSSL_memset(r + num - shift_words, 0, shift_words * sizeof(BN_ULONG));
  154|  1.28k|}
BN_rshift:
  156|  1.75k|int BN_rshift(BIGNUM *r, const BIGNUM *a, int n) {
  157|  1.75k|  if (n < 0) {
  ------------------
  |  Branch (157:7): [True: 0, False: 1.75k]
  ------------------
  158|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  159|      0|    return 0;
  160|      0|  }
  161|       |
  162|  1.75k|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (162:7): [True: 0, False: 1.75k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|  1.75k|  bn_rshift_words(r->d, a->d, n, a->width);
  166|  1.75k|  r->neg = a->neg;
  167|  1.75k|  r->width = a->width;
  168|  1.75k|  bn_set_minimal_width(r);
  169|  1.75k|  return 1;
  170|  1.75k|}

bcm.c:OPENSSL_memmove:
 1047|    264|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|    264|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 264]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|    264|  return memmove(dst, src, n);
 1053|    264|}
bcm.c:OPENSSL_memcpy:
 1039|   977k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   977k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 13.0k, False: 964k]
  ------------------
 1041|  13.0k|    return dst;
 1042|  13.0k|  }
 1043|       |
 1044|   964k|  return memcpy(dst, src, n);
 1045|   977k|}
bcm.c:constant_time_is_zero_w:
  427|   776k|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|   776k|  return constant_time_msb_w(~a & (a - 1));
  440|   776k|}
bcm.c:constant_time_msb_w:
  368|  1.55M|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|  1.55M|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|  1.55M|}
bcm.c:constant_time_eq_w:
  450|   774k|                                               crypto_word_t b) {
  451|   774k|  return constant_time_is_zero_w(a ^ b);
  452|   774k|}
bcm.c:constant_time_select_w:
  477|  16.8M|                                                   crypto_word_t b) {
  478|       |  // Clang recognizes this pattern as a select. While it usually transforms it
  479|       |  // to a cmov, it sometimes further transforms it into a branch, which we do
  480|       |  // not want.
  481|       |  //
  482|       |  // Hiding the value of the mask from the compiler evades this transformation.
  483|  16.8M|  mask = value_barrier_w(mask);
  484|  16.8M|  return (mask & a) | (~mask & b);
  485|  16.8M|}
bcm.c:value_barrier_w:
  340|  16.8M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  16.8M|#if defined(__GNUC__) || defined(__clang__)
  342|  16.8M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  16.8M|#endif
  344|  16.8M|  return a;
  345|  16.8M|}
bcm.c:OPENSSL_memset:
 1055|  21.2k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  21.2k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 4.93k, False: 16.3k]
  ------------------
 1057|  4.93k|    return dst;
 1058|  4.93k|  }
 1059|       |
 1060|  16.3k|  return memset(dst, c, n);
 1061|  21.2k|}
bcm.c:CRYPTO_load_word_be:
 1122|   961k|static inline crypto_word_t CRYPTO_load_word_be(const void *in) {
 1123|   961k|  crypto_word_t v;
 1124|   961k|  OPENSSL_memcpy(&v, in, sizeof(v));
 1125|   961k|#if defined(OPENSSL_64_BIT)
 1126|   961k|  static_assert(sizeof(v) == 8, "crypto_word_t has unexpected size");
 1127|   961k|  return CRYPTO_bswap8(v);
 1128|       |#else
 1129|       |  static_assert(sizeof(v) == 4, "crypto_word_t has unexpected size");
 1130|       |  return CRYPTO_bswap4(v);
 1131|       |#endif
 1132|   961k|}
bcm.c:CRYPTO_bswap8:
  949|   961k|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|   961k|  return __builtin_bswap64(x);
  951|   961k|}
bcm.c:constant_time_select_int:
  503|  1.55M|static inline int constant_time_select_int(crypto_word_t mask, int a, int b) {
  504|  1.55M|  return (int)(constant_time_select_w(mask, (crypto_word_t)(a),
  505|  1.55M|                                      (crypto_word_t)(b)));
  506|  1.55M|}
bcm.c:constant_time_lt_w:
  374|   774k|                                               crypto_word_t b) {
  375|       |  // Consider the two cases of the problem:
  376|       |  //   msb(a) == msb(b): a < b iff the MSB of a - b is set.
  377|       |  //   msb(a) != msb(b): a < b iff the MSB of b is set.
  378|       |  //
  379|       |  // If msb(a) == msb(b) then the following evaluates as:
  380|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  381|       |  //   msb(a^((a-b) ^ a))       ==   (because msb(a^b) == 0)
  382|       |  //   msb(a^a^(a-b))           ==   (rearranging)
  383|       |  //   msb(a-b)                      (because ∀x. x^x == 0)
  384|       |  //
  385|       |  // Else, if msb(a) != msb(b) then the following evaluates as:
  386|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  387|       |  //   msb(a^(𝟙 | ((a-b)^a)))   ==   (because msb(a^b) == 1 and 𝟙
  388|       |  //                                  represents a value s.t. msb(𝟙) = 1)
  389|       |  //   msb(a^𝟙)                 ==   (because ORing with 1 results in 1)
  390|       |  //   msb(b)
  391|       |  //
  392|       |  //
  393|       |  // Here is an SMT-LIB verification of this formula:
  394|       |  //
  395|       |  // (define-fun lt ((a (_ BitVec 32)) (b (_ BitVec 32))) (_ BitVec 32)
  396|       |  //   (bvxor a (bvor (bvxor a b) (bvxor (bvsub a b) a)))
  397|       |  // )
  398|       |  //
  399|       |  // (declare-fun a () (_ BitVec 32))
  400|       |  // (declare-fun b () (_ BitVec 32))
  401|       |  //
  402|       |  // (assert (not (= (= #x00000001 (bvlshr (lt a b) #x0000001f)) (bvult a b))))
  403|       |  // (check-sat)
  404|       |  // (get-model)
  405|   774k|  return constant_time_msb_w(a^((a^b)|((a-b)^a)));
  406|   774k|}
mem.c:OPENSSL_memset:
 1055|  33.8k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  33.8k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 33.8k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  33.8k|  return memset(dst, c, n);
 1061|  33.8k|}
stack.c:OPENSSL_memset:
 1055|  3.50k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  3.50k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 3.50k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  3.50k|  return memset(dst, c, n);
 1061|  3.50k|}

OPENSSL_malloc:
  228|  33.8k|void *OPENSSL_malloc(size_t size) {
  229|  33.8k|  if (should_fail_allocation()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 33.8k]
  ------------------
  230|      0|    goto err;
  231|      0|  }
  232|       |
  233|  33.8k|  if (OPENSSL_memory_alloc != NULL) {
  ------------------
  |  Branch (233:7): [True: 0, False: 33.8k]
  ------------------
  234|      0|    assert(OPENSSL_memory_free != NULL);
  235|      0|    assert(OPENSSL_memory_get_size != NULL);
  236|      0|    void *ptr = OPENSSL_memory_alloc(size);
  237|      0|    if (ptr == NULL && size != 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  |  Branch (237:24): [True: 0, False: 0]
  ------------------
  238|      0|      goto err;
  239|      0|    }
  240|      0|    return ptr;
  241|      0|  }
  242|       |
  243|  33.8k|  if (size + OPENSSL_MALLOC_PREFIX < size) {
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  |  Branch (243:7): [True: 0, False: 33.8k]
  ------------------
  244|       |    // |OPENSSL_malloc| is a central function in BoringSSL thus a reference to
  245|       |    // |kBoringSSLBinaryTag| is created here so that the tag isn't discarded by
  246|       |    // the linker. The following is sufficient to stop GCC, Clang, and MSVC
  247|       |    // optimising away the reference at the time of writing. Since this
  248|       |    // probably results in an actual memory reference, it is put in this very
  249|       |    // rare code path.
  250|      0|    uint8_t unused = *(volatile uint8_t *)kBoringSSLBinaryTag;
  251|      0|    (void) unused;
  252|      0|    goto err;
  253|      0|  }
  254|       |
  255|  33.8k|  void *ptr = malloc(size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  256|  33.8k|  if (ptr == NULL) {
  ------------------
  |  Branch (256:7): [True: 0, False: 33.8k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|  33.8k|  *(size_t *)ptr = size;
  261|       |
  262|  33.8k|  __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  263|  33.8k|  return ((uint8_t *)ptr) + OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  264|       |
  265|      0| err:
  266|       |  // This only works because ERR does not call OPENSSL_malloc.
  267|      0|  OPENSSL_PUT_ERROR(CRYPTO, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|  return NULL;
  269|  33.8k|}
OPENSSL_free:
  271|  46.1k|void OPENSSL_free(void *orig_ptr) {
  272|  46.1k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (272:7): [True: 12.2k, False: 33.8k]
  ------------------
  273|  12.2k|    return;
  274|  12.2k|  }
  275|       |
  276|  33.8k|  if (OPENSSL_memory_free != NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 33.8k]
  ------------------
  277|      0|    OPENSSL_memory_free(orig_ptr);
  278|      0|    return;
  279|      0|  }
  280|       |
  281|  33.8k|  void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  282|  33.8k|  __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  283|       |
  284|  33.8k|  size_t size = *(size_t *)ptr;
  285|  33.8k|  OPENSSL_cleanse(ptr, size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  33.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  286|       |
  287|       |// ASan knows to intercept malloc and free, but not sdallocx.
  288|       |#if defined(OPENSSL_ASAN)
  289|       |  (void)sdallocx;
  290|       |  free(ptr);
  291|       |#else
  292|  33.8k|  if (sdallocx) {
  ------------------
  |  Branch (292:7): [True: 0, False: 33.8k]
  ------------------
  293|      0|    sdallocx(ptr, size + OPENSSL_MALLOC_PREFIX, 0 /* flags */);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  294|  33.8k|  } else {
  295|  33.8k|    free(ptr);
  296|  33.8k|  }
  297|  33.8k|#endif
  298|  33.8k|}
OPENSSL_realloc:
  300|  1.75k|void *OPENSSL_realloc(void *orig_ptr, size_t new_size) {
  301|  1.75k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (301:7): [True: 1.75k, False: 0]
  ------------------
  302|  1.75k|    return OPENSSL_malloc(new_size);
  303|  1.75k|  }
  304|       |
  305|      0|  size_t old_size;
  306|      0|  if (OPENSSL_memory_get_size != NULL) {
  ------------------
  |  Branch (306:7): [True: 0, False: 0]
  ------------------
  307|      0|    old_size = OPENSSL_memory_get_size(orig_ptr);
  308|      0|  } else {
  309|      0|    void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  310|      0|    __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  311|      0|    old_size = *(size_t *)ptr;
  312|      0|    __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  313|      0|  }
  314|       |
  315|      0|  void *ret = OPENSSL_malloc(new_size);
  316|      0|  if (ret == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 0]
  ------------------
  317|      0|    return NULL;
  318|      0|  }
  319|       |
  320|      0|  size_t to_copy = new_size;
  321|      0|  if (old_size < to_copy) {
  ------------------
  |  Branch (321:7): [True: 0, False: 0]
  ------------------
  322|      0|    to_copy = old_size;
  323|      0|  }
  324|       |
  325|      0|  memcpy(ret, orig_ptr, to_copy);
  326|      0|  OPENSSL_free(orig_ptr);
  327|       |
  328|      0|  return ret;
  329|      0|}
OPENSSL_cleanse:
  331|  33.8k|void OPENSSL_cleanse(void *ptr, size_t len) {
  332|       |#if defined(OPENSSL_WINDOWS)
  333|       |  SecureZeroMemory(ptr, len);
  334|       |#else
  335|  33.8k|  OPENSSL_memset(ptr, 0, len);
  336|       |
  337|  33.8k|#if !defined(OPENSSL_NO_ASM)
  338|       |  /* As best as we can tell, this is sufficient to break any optimisations that
  339|       |     might try to eliminate "superfluous" memsets. If there's an easy way to
  340|       |     detect memset_s, it would be better to use that. */
  341|  33.8k|  __asm__ __volatile__("" : : "r"(ptr) : "memory");
  342|  33.8k|#endif
  343|  33.8k|#endif  // !OPENSSL_NO_ASM
  344|  33.8k|}
mem.c:should_fail_allocation:
  225|  33.8k|static int should_fail_allocation(void) { return 0; }
mem.c:__asan_poison_memory_region:
   90|  33.8k|static void __asan_poison_memory_region(const void *addr, size_t size) {}
mem.c:__asan_unpoison_memory_region:
   91|  33.8k|static void __asan_unpoison_memory_region(const void *addr, size_t size) {}

sk_new:
   72|  1.75k|_STACK *sk_new(OPENSSL_sk_cmp_func comp) {
   73|  1.75k|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
   74|  1.75k|  if (ret == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 1.75k]
  ------------------
   75|      0|    return NULL;
   76|      0|  }
   77|  1.75k|  OPENSSL_memset(ret, 0, sizeof(_STACK));
   78|       |
   79|  1.75k|  ret->data = OPENSSL_malloc(sizeof(void *) * kMinSize);
   80|  1.75k|  if (ret->data == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 1.75k]
  ------------------
   81|      0|    goto err;
   82|      0|  }
   83|       |
   84|  1.75k|  OPENSSL_memset(ret->data, 0, sizeof(void *) * kMinSize);
   85|       |
   86|  1.75k|  ret->comp = comp;
   87|  1.75k|  ret->num_alloc = kMinSize;
   88|       |
   89|  1.75k|  return ret;
   90|       |
   91|      0|err:
   92|      0|  OPENSSL_free(ret);
   93|      0|  return NULL;
   94|  1.75k|}
sk_new_null:
   96|  1.75k|_STACK *sk_new_null(void) { return sk_new(NULL); }
sk_num:
   98|  6.84k|size_t sk_num(const _STACK *sk) {
   99|  6.84k|  if (sk == NULL) {
  ------------------
  |  Branch (99:7): [True: 0, False: 6.84k]
  ------------------
  100|      0|    return 0;
  101|      0|  }
  102|  6.84k|  return sk->num;
  103|  6.84k|}
sk_value:
  114|  6.84k|void *sk_value(const _STACK *sk, size_t i) {
  115|  6.84k|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (115:7): [True: 0, False: 6.84k]
  |  Branch (115:14): [True: 0, False: 6.84k]
  ------------------
  116|      0|    return NULL;
  117|      0|  }
  118|  6.84k|  return sk->data[i];
  119|  6.84k|}
sk_free:
  128|  1.75k|void sk_free(_STACK *sk) {
  129|  1.75k|  if (sk == NULL) {
  ------------------
  |  Branch (129:7): [True: 0, False: 1.75k]
  ------------------
  130|      0|    return;
  131|      0|  }
  132|  1.75k|  OPENSSL_free(sk->data);
  133|  1.75k|  OPENSSL_free(sk);
  134|  1.75k|}
sk_pop_free_ex:
  137|  1.75k|                    OPENSSL_sk_free_func free_func) {
  138|  1.75k|  if (sk == NULL) {
  ------------------
  |  Branch (138:7): [True: 0, False: 1.75k]
  ------------------
  139|      0|    return;
  140|      0|  }
  141|       |
  142|  7.00k|  for (size_t i = 0; i < sk->num; i++) {
  ------------------
  |  Branch (142:22): [True: 5.25k, False: 1.75k]
  ------------------
  143|  5.25k|    if (sk->data[i] != NULL) {
  ------------------
  |  Branch (143:9): [True: 5.25k, False: 0]
  ------------------
  144|  5.25k|      call_free_func(free_func, sk->data[i]);
  145|  5.25k|    }
  146|  5.25k|  }
  147|  1.75k|  sk_free(sk);
  148|  1.75k|}
sk_insert:
  161|  5.25k|size_t sk_insert(_STACK *sk, void *p, size_t where) {
  162|  5.25k|  if (sk == NULL) {
  ------------------
  |  Branch (162:7): [True: 0, False: 5.25k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|  5.25k|  if (sk->num >= INT_MAX) {
  ------------------
  |  Branch (166:7): [True: 0, False: 5.25k]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|  5.25k|  if (sk->num_alloc <= sk->num + 1) {
  ------------------
  |  Branch (171:7): [True: 0, False: 5.25k]
  ------------------
  172|       |    // Attempt to double the size of the array.
  173|      0|    size_t new_alloc = sk->num_alloc << 1;
  174|      0|    size_t alloc_size = new_alloc * sizeof(void *);
  175|      0|    void **data;
  176|       |
  177|       |    // If the doubling overflowed, try to increment.
  178|      0|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (178:9): [True: 0, False: 0]
  |  Branch (178:38): [True: 0, False: 0]
  ------------------
  179|      0|      new_alloc = sk->num_alloc + 1;
  180|      0|      alloc_size = new_alloc * sizeof(void *);
  181|      0|    }
  182|       |
  183|       |    // If the increment also overflowed, fail.
  184|      0|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 0]
  |  Branch (184:38): [True: 0, False: 0]
  ------------------
  185|      0|      return 0;
  186|      0|    }
  187|       |
  188|      0|    data = OPENSSL_realloc(sk->data, alloc_size);
  189|      0|    if (data == NULL) {
  ------------------
  |  Branch (189:9): [True: 0, False: 0]
  ------------------
  190|      0|      return 0;
  191|      0|    }
  192|       |
  193|      0|    sk->data = data;
  194|      0|    sk->num_alloc = new_alloc;
  195|      0|  }
  196|       |
  197|  5.25k|  if (where >= sk->num) {
  ------------------
  |  Branch (197:7): [True: 5.25k, False: 0]
  ------------------
  198|  5.25k|    sk->data[sk->num] = p;
  199|  5.25k|  } else {
  200|      0|    OPENSSL_memmove(&sk->data[where + 1], &sk->data[where],
  201|      0|                    sizeof(void *) * (sk->num - where));
  202|      0|    sk->data[where] = p;
  203|      0|  }
  204|       |
  205|  5.25k|  sk->num++;
  206|  5.25k|  sk->sorted = 0;
  207|       |
  208|  5.25k|  return sk->num;
  209|  5.25k|}
sk_push:
  340|  5.25k|size_t sk_push(_STACK *sk, void *p) { return (sk_insert(sk, p, sk->num)); }

LLVMFuzzerTestOneInput:
   27|  1.82k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) {
   28|  1.82k|  CBS cbs, child0, child1;
   29|  1.82k|  uint8_t sign0, sign1;
   30|  1.82k|  CBS_init(&cbs, buf, len);
   31|  1.82k|  if (!CBS_get_u16_length_prefixed(&cbs, &child0) ||
  ------------------
  |  Branch (31:7): [True: 17, False: 1.80k]
  ------------------
   32|  1.82k|      !CBS_get_u8(&child0, &sign0) ||
  ------------------
  |  Branch (32:7): [True: 23, False: 1.78k]
  ------------------
   33|  1.82k|      CBS_len(&child0) == 0 ||
  ------------------
  |  Branch (33:7): [True: 3, False: 1.77k]
  ------------------
   34|  1.82k|      !CBS_get_u16_length_prefixed(&cbs, &child1) ||
  ------------------
  |  Branch (34:7): [True: 19, False: 1.75k]
  ------------------
   35|  1.82k|      !CBS_get_u8(&child1, &sign1) ||
  ------------------
  |  Branch (35:7): [True: 4, False: 1.75k]
  ------------------
   36|  1.82k|      CBS_len(&child1) == 0) {
  ------------------
  |  Branch (36:7): [True: 1, False: 1.75k]
  ------------------
   37|     67|    return 0;
   38|     67|  }
   39|       |
   40|  1.75k|  bssl::UniquePtr<BIGNUM> numerator(
   41|  1.75k|      BN_bin2bn(CBS_data(&child0), CBS_len(&child0), nullptr));
   42|  1.75k|  BN_set_negative(numerator.get(), sign0 % 2);
   43|  1.75k|  bssl::UniquePtr<BIGNUM> divisor(
   44|  1.75k|      BN_bin2bn(CBS_data(&child1), CBS_len(&child1), nullptr));
   45|  1.75k|  BN_set_negative(divisor.get(), sign1 % 2);
   46|       |
   47|  1.75k|  if (BN_is_zero(divisor.get())) {
  ------------------
  |  Branch (47:7): [True: 1, False: 1.75k]
  ------------------
   48|      1|    return 0;
   49|      1|  }
   50|       |
   51|  1.75k|  bssl::UniquePtr<BN_CTX> ctx(BN_CTX_new());
   52|  1.75k|  bssl::UniquePtr<BIGNUM> result(BN_new());
   53|  1.75k|  bssl::UniquePtr<BIGNUM> remainder(BN_new());
   54|  1.75k|  CHECK(ctx);
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   55|  1.75k|  CHECK(result);
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   56|  1.75k|  CHECK(remainder);
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   57|       |
   58|       |
   59|  1.75k|  CHECK(BN_div(result.get(), remainder.get(), numerator.get(), divisor.get(),
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   60|  1.75k|               ctx.get()));
   61|  1.75k|  CHECK(BN_ucmp(remainder.get(), divisor.get()) < 0);
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   62|       |
   63|       |  // Check that result*divisor+remainder = numerator.
   64|  1.75k|  CHECK(BN_mul(result.get(), result.get(), divisor.get(), ctx.get()));
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   65|  1.75k|  CHECK(BN_add(result.get(), result.get(), remainder.get()));
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   66|  1.75k|  CHECK(BN_cmp(result.get(), numerator.get()) == 0);
  ------------------
  |  |   20|  1.75k|  do {                              \
  |  |   21|  1.75k|    if (!(expr)) {                  \
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 1.75k]
  |  |  ------------------
  |  |   22|      0|      printf("%s failed\n", #expr); \
  |  |   23|      0|      abort();                      \
  |  |   24|      0|    }                               \
  |  |   25|  1.75k|  } while (false)
  |  |  ------------------
  |  |  |  Branch (25:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   67|       |
   68|  1.75k|  return 0;
   69|  1.75k|}

_ZN4bssl8internal7DeleterclI9bignum_stEEvPT_:
  560|  7.01k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  7.01k|    DeleterImpl<T>::Free(ptr);
  570|  7.01k|  }
_ZN4bssl8internal11DeleterImplI9bignum_stvE4FreeEPS2_:
  635|  7.01k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl8internal7DeleterclI10bignum_ctxEEvPT_:
  560|  1.75k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  1.75k|    DeleterImpl<T>::Free(ptr);
  570|  1.75k|  }
_ZN4bssl8internal11DeleterImplI10bignum_ctxvE4FreeEPS2_:
  635|  1.75k|    static void Free(type *ptr) { deleter(ptr); } \

bcm.c:sk_BIGNUM_pop_free:
  447|  1.75k|                                           sk_##name##_free_func free_func) { \
  448|  1.75k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  1.75k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  1.75k|  }                                                                           \
bcm.c:sk_BIGNUM_call_free_func:
  391|  5.25k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  5.25k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  5.25k|  }                                                                           \
bcm.c:sk_BIGNUM_new_null:
  420|  1.75k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  1.75k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  1.75k|  }                                                                           \
bcm.c:sk_BIGNUM_num:
  424|  6.84k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  6.84k|    return sk_num((const _STACK *)sk);                                        \
  426|  6.84k|  }                                                                           \
bcm.c:sk_BIGNUM_push:
  483|  5.25k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  5.25k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  5.25k|  }                                                                           \
bcm.c:sk_BIGNUM_value:
  433|  6.84k|                                           size_t i) {                        \
  434|  6.84k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  6.84k|  }                                                                           \

