_ZN6google8protobuf5Arena21CreateMessageInternalIN8asn1_pdu3PDUEEEPT_PS1_:
  551|  28.7k|  PROTOBUF_NDEBUG_INLINE static T* CreateMessageInternal(Arena* arena) {
  552|  28.7k|    static_assert(
  553|  28.7k|        InternalHelper<T>::is_arena_constructable::value,
  554|  28.7k|        "CreateMessage can only construct types that are ArenaConstructable");
  555|  28.7k|    if (arena == nullptr) {
  ------------------
  |  Branch (555:9): [True: 28.7k, False: 0]
  ------------------
  556|       |      // Generated arena constructor T(Arena*) is protected. Call via
  557|       |      // InternalHelper.
  558|  28.7k|      return InternalHelper<T>::New();
  559|  28.7k|    } else {
  560|      0|      return arena->DoCreateMessage<T>();
  561|      0|    }
  562|  28.7k|  }
_ZN6google8protobuf5Arena14InternalHelperIN8asn1_pdu3PDUEE3NewEv:
  487|  28.7k|    static inline PROTOBUF_ALWAYS_INLINE T* New() {
  488|  28.7k|      return new T(nullptr);
  489|  28.7k|    }
_ZN6google8protobuf5Arena21CreateMessageInternalIN8asn1_pdu10IdentifierEEEPT_PS1_:
  551|  34.2k|  PROTOBUF_NDEBUG_INLINE static T* CreateMessageInternal(Arena* arena) {
  552|  34.2k|    static_assert(
  553|  34.2k|        InternalHelper<T>::is_arena_constructable::value,
  554|  34.2k|        "CreateMessage can only construct types that are ArenaConstructable");
  555|  34.2k|    if (arena == nullptr) {
  ------------------
  |  Branch (555:9): [True: 34.2k, False: 0]
  ------------------
  556|       |      // Generated arena constructor T(Arena*) is protected. Call via
  557|       |      // InternalHelper.
  558|  34.2k|      return InternalHelper<T>::New();
  559|  34.2k|    } else {
  560|      0|      return arena->DoCreateMessage<T>();
  561|      0|    }
  562|  34.2k|  }
_ZN6google8protobuf5Arena14InternalHelperIN8asn1_pdu10IdentifierEE3NewEv:
  487|  34.2k|    static inline PROTOBUF_ALWAYS_INLINE T* New() {
  488|  34.2k|      return new T(nullptr);
  489|  34.2k|    }
_ZN6google8protobuf5Arena21CreateMessageInternalIN8asn1_pdu9TagNumberEEEPT_PS1_:
  551|  33.4k|  PROTOBUF_NDEBUG_INLINE static T* CreateMessageInternal(Arena* arena) {
  552|  33.4k|    static_assert(
  553|  33.4k|        InternalHelper<T>::is_arena_constructable::value,
  554|  33.4k|        "CreateMessage can only construct types that are ArenaConstructable");
  555|  33.4k|    if (arena == nullptr) {
  ------------------
  |  Branch (555:9): [True: 33.4k, False: 0]
  ------------------
  556|       |      // Generated arena constructor T(Arena*) is protected. Call via
  557|       |      // InternalHelper.
  558|  33.4k|      return InternalHelper<T>::New();
  559|  33.4k|    } else {
  560|      0|      return arena->DoCreateMessage<T>();
  561|      0|    }
  562|  33.4k|  }
_ZN6google8protobuf5Arena14InternalHelperIN8asn1_pdu9TagNumberEE3NewEv:
  487|  33.4k|    static inline PROTOBUF_ALWAYS_INLINE T* New() {
  488|  33.4k|      return new T(nullptr);
  489|  33.4k|    }
_ZN6google8protobuf5Arena21CreateMessageInternalIN8asn1_pdu6LengthEEEPT_PS1_:
  551|  34.3k|  PROTOBUF_NDEBUG_INLINE static T* CreateMessageInternal(Arena* arena) {
  552|  34.3k|    static_assert(
  553|  34.3k|        InternalHelper<T>::is_arena_constructable::value,
  554|  34.3k|        "CreateMessage can only construct types that are ArenaConstructable");
  555|  34.3k|    if (arena == nullptr) {
  ------------------
  |  Branch (555:9): [True: 34.3k, False: 0]
  ------------------
  556|       |      // Generated arena constructor T(Arena*) is protected. Call via
  557|       |      // InternalHelper.
  558|  34.3k|      return InternalHelper<T>::New();
  559|  34.3k|    } else {
  560|      0|      return arena->DoCreateMessage<T>();
  561|      0|    }
  562|  34.3k|  }
_ZN6google8protobuf5Arena14InternalHelperIN8asn1_pdu6LengthEE3NewEv:
  487|  34.3k|    static inline PROTOBUF_ALWAYS_INLINE T* New() {
  488|  34.3k|      return new T(nullptr);
  489|  34.3k|    }
_ZN6google8protobuf5Arena21CreateMessageInternalIN8asn1_pdu12ValueElementEEEPT_PS1_:
  551|  69.8k|  PROTOBUF_NDEBUG_INLINE static T* CreateMessageInternal(Arena* arena) {
  552|  69.8k|    static_assert(
  553|  69.8k|        InternalHelper<T>::is_arena_constructable::value,
  554|  69.8k|        "CreateMessage can only construct types that are ArenaConstructable");
  555|  69.8k|    if (arena == nullptr) {
  ------------------
  |  Branch (555:9): [True: 69.8k, False: 0]
  ------------------
  556|       |      // Generated arena constructor T(Arena*) is protected. Call via
  557|       |      // InternalHelper.
  558|  69.8k|      return InternalHelper<T>::New();
  559|  69.8k|    } else {
  560|      0|      return arena->DoCreateMessage<T>();
  561|      0|    }
  562|  69.8k|  }
_ZN6google8protobuf5Arena14InternalHelperIN8asn1_pdu12ValueElementEE3NewEv:
  487|  69.8k|    static inline PROTOBUF_ALWAYS_INLINE T* New() {
  488|  69.8k|      return new T(nullptr);
  489|  69.8k|    }
_ZN6google8protobuf5Arena21CreateMessageInternalIN8asn1_pdu5ValueEEEPT_PS1_:
  551|  34.2k|  PROTOBUF_NDEBUG_INLINE static T* CreateMessageInternal(Arena* arena) {
  552|  34.2k|    static_assert(
  553|  34.2k|        InternalHelper<T>::is_arena_constructable::value,
  554|  34.2k|        "CreateMessage can only construct types that are ArenaConstructable");
  555|  34.2k|    if (arena == nullptr) {
  ------------------
  |  Branch (555:9): [True: 34.2k, False: 0]
  ------------------
  556|       |      // Generated arena constructor T(Arena*) is protected. Call via
  557|       |      // InternalHelper.
  558|  34.2k|      return InternalHelper<T>::New();
  559|  34.2k|    } else {
  560|      0|      return arena->DoCreateMessage<T>();
  561|      0|    }
  562|  34.2k|  }
_ZN6google8protobuf5Arena14InternalHelperIN8asn1_pdu5ValueEE3NewEv:
  487|  34.2k|    static inline PROTOBUF_ALWAYS_INLINE T* New() {
  488|  34.2k|      return new T(nullptr);
  489|  34.2k|    }

_ZN6google8protobuf8internal15TaggedStringPtrC2EPNS1_21ExplicitlyConstructedINSt3__112basic_stringIcNS4_11char_traitsIcEENS4_9allocatorIcEEEELm8EEE:
  133|  69.8k|      : ptr_(ptr) {}
_ZNK6google8protobuf8internal15TaggedStringPtr3GetEv:
  189|  81.9k|  inline std::string* Get() const {
  190|  81.9k|    return reinterpret_cast<std::string*>(as_int() & ~kMask);
  191|  81.9k|  }
_ZNK6google8protobuf8internal15TaggedStringPtr6as_intEv:
  210|  81.9k|  uintptr_t as_int() const { return reinterpret_cast<uintptr_t>(ptr_); }
_ZNK6google8protobuf8internal14ArenaStringPtr3GetEv:
  299|  80.3k|  PROTOBUF_NDEBUG_INLINE const std::string& Get() const {
  300|       |    // Unconditionally mask away the tag.
  301|  80.3k|    return *tagged_ptr_.Get();
  302|  80.3k|  }
_ZN6google8protobuf8internal14ArenaStringPtr11InitDefaultEv:
  395|  69.8k|inline void ArenaStringPtr::InitDefault() {
  396|  69.8k|  tagged_ptr_ = TaggedStringPtr(&fixed_address_empty_string);
  397|  69.8k|}
_ZN6google8protobuf8internal14ArenaStringPtr22ClearNonDefaultToEmptyEv:
  475|  1.58k|inline void ArenaStringPtr::ClearNonDefaultToEmpty() {
  476|       |  // Unconditionally mask away the tag.
  477|  1.58k|  tagged_ptr_.Get()->clear();
  478|  1.58k|}

_ZN6google8protobuf8internal10CachedSizeC2Ev:
  198|   241k|  constexpr CachedSize() noexcept : atom_(Scalar{}) {}

_ZNK6google8protobuf8internal7HasBitsILm1EEixEi:
   61|  97.0k|  PROTOBUF_NDEBUG_INLINE const uint32_t& operator[](int index) const {
   62|  97.0k|    return has_bits_[index];
   63|  97.0k|  }
_ZN6google8protobuf8internal7HasBitsILm1EEixEi:
   57|  28.6k|  PROTOBUF_NDEBUG_INLINE uint32_t& operator[](int index) {
   58|  28.6k|    return has_bits_[index];
   59|  28.6k|  }
_ZN6google8protobuf8internal7HasBitsILm1EEC2Ev:
   51|   172k|  PROTOBUF_NDEBUG_INLINE constexpr HasBits() : has_bits_{} {}
_ZN6google8protobuf8internal7HasBitsILm1EE5ClearEv:
   53|  28.6k|  PROTOBUF_NDEBUG_INLINE void Clear() {
   54|  28.6k|    memset(has_bits_, 0, sizeof(has_bits_));
   55|  28.6k|  }

_ZN6google8protobuf7MessageC2EPNS0_5ArenaE:
  414|   241k|  inline explicit Message(Arena* arena) : MessageLite(arena) {}

_ZN6google8protobuf11MessageLiteC2EPNS0_5ArenaE:
  468|   241k|  inline explicit MessageLite(Arena* arena) : _internal_metadata_(arena) {}
_ZN6google8protobuf11MessageLite18CreateMaybeMessageIN8asn1_pdu3PDUEEEPT_PNS0_5ArenaE:
  464|  28.7k|  static T* CreateMaybeMessage(Arena* arena) {
  465|  28.7k|    return Arena::CreateMaybeMessage<T>(arena);
  466|  28.7k|  }
_ZN6google8protobuf11MessageLite18CreateMaybeMessageIN8asn1_pdu10IdentifierEEEPT_PNS0_5ArenaE:
  464|  34.2k|  static T* CreateMaybeMessage(Arena* arena) {
  465|  34.2k|    return Arena::CreateMaybeMessage<T>(arena);
  466|  34.2k|  }
_ZN6google8protobuf11MessageLite18CreateMaybeMessageIN8asn1_pdu9TagNumberEEEPT_PNS0_5ArenaE:
  464|  33.4k|  static T* CreateMaybeMessage(Arena* arena) {
  465|  33.4k|    return Arena::CreateMaybeMessage<T>(arena);
  466|  33.4k|  }
_ZN6google8protobuf11MessageLite18CreateMaybeMessageIN8asn1_pdu6LengthEEEPT_PNS0_5ArenaE:
  464|  34.3k|  static T* CreateMaybeMessage(Arena* arena) {
  465|  34.3k|    return Arena::CreateMaybeMessage<T>(arena);
  466|  34.3k|  }
_ZN6google8protobuf11MessageLite18CreateMaybeMessageIN8asn1_pdu12ValueElementEEEPT_PNS0_5ArenaE:
  464|  69.8k|  static T* CreateMaybeMessage(Arena* arena) {
  465|  69.8k|    return Arena::CreateMaybeMessage<T>(arena);
  466|  69.8k|  }
_ZN6google8protobuf11MessageLite18CreateMaybeMessageIN8asn1_pdu5ValueEEEPT_PNS0_5ArenaE:
  464|  34.2k|  static T* CreateMaybeMessage(Arena* arena) {
  465|  34.2k|    return Arena::CreateMaybeMessage<T>(arena);
  466|  34.2k|  }
_ZN6google8protobuf11MessageLiteD2Ev:
  175|   241k|  virtual ~MessageLite() = default;

_ZN6google8protobuf8internal16InternalMetadataC2EPNS0_5ArenaE:
   70|   241k|  explicit InternalMetadata(Arena* arena) {
   71|   241k|    ptr_ = reinterpret_cast<intptr_t>(arena);
   72|   241k|  }
_ZNK6google8protobuf8internal16InternalMetadata19have_unknown_fieldsEv:
  106|   279k|  PROTOBUF_NDEBUG_INLINE bool have_unknown_fields() const {
  107|   279k|    return HasUnknownFieldsTag();
  108|   279k|  }
_ZNK6google8protobuf8internal16InternalMetadata19HasUnknownFieldsTagEv:
  173|   279k|  PROTOBUF_ALWAYS_INLINE bool HasUnknownFieldsTag() const {
  174|   279k|    return ptr_ & kUnknownFieldsTagMask;
  175|   279k|  }
_ZNK6google8protobuf8internal16InternalMetadata8PtrValueINS0_5ArenaEEEPT_v:
  178|   241k|  U* PtrValue() const {
  179|   241k|    return reinterpret_cast<U*>(ptr_ & kPtrValueMask);
  180|   241k|  }
_ZN6google8protobuf8internal16InternalMetadata9MergeFromINS0_15UnknownFieldSetEEEvRKS2_:
  151|  2.41k|  PROTOBUF_NDEBUG_INLINE void MergeFrom(const InternalMetadata& other) {
  152|  2.41k|    if (other.have_unknown_fields()) {
  ------------------
  |  Branch (152:9): [True: 0, False: 2.41k]
  ------------------
  153|      0|      DoMergeFrom<T>(other.unknown_fields<T>(nullptr));
  154|      0|    }
  155|  2.41k|  }
_ZN6google8protobuf8internal16InternalMetadata17DeleteReturnArenaINS0_15UnknownFieldSetEEEPNS0_5ArenaEv:
   90|   241k|  Arena* DeleteReturnArena() {
   91|   241k|    if (have_unknown_fields()) {
  ------------------
  |  Branch (91:9): [True: 0, False: 241k]
  ------------------
   92|      0|      return DeleteOutOfLineHelper<T>();
   93|   241k|    } else {
   94|   241k|      return PtrValue<Arena>();
   95|   241k|    }
   96|   241k|  }
_ZN6google8protobuf8internal16InternalMetadata5ClearINS0_15UnknownFieldSetEEEvv:
  158|  35.5k|  PROTOBUF_NDEBUG_INLINE void Clear() {
  159|  35.5k|    if (have_unknown_fields()) {
  ------------------
  |  Branch (159:9): [True: 0, False: 35.5k]
  ------------------
  160|      0|      DoClear<T>();
  161|      0|    }
  162|  35.5k|  }

_ZN6google8protobuf8internal20RepeatedPtrFieldBaseC2EPNS0_5ArenaE:
  169|  34.2k|      : arena_(arena), current_size_(0), total_size_(0), rep_(nullptr) {}
_ZN6google8protobuf8internal20RepeatedPtrFieldBaseD2Ev:
  174|  34.2k|  ~RepeatedPtrFieldBase() {
  175|       |#ifndef NDEBUG
  176|       |    // Try to trigger segfault / asan failure in non-opt builds. If arena_
  177|       |    // lifetime has ended before the destructor.
  178|       |    if (arena_) (void)arena_->SpaceAllocated();
  179|       |#endif
  180|  34.2k|  }
_ZNK6google8protobuf8internal20RepeatedPtrFieldBase4sizeEv:
  183|  31.4k|  int size() const { return current_size_; }
_ZNK6google8protobuf8internal20RepeatedPtrFieldBase12NeedsDestroyEv:
  261|  34.2k|  bool NeedsDestroy() const { return rep_ != nullptr && arena_ == nullptr; }
  ------------------
  |  Branch (261:38): [True: 28.4k, False: 5.87k]
  |  Branch (261:57): [True: 28.4k, False: 0]
  ------------------
_ZNK6google8protobuf8internal20RepeatedPtrFieldBase8raw_dataEv:
  372|  62.8k|  void* const* raw_data() const { return rep_ ? rep_->elements : nullptr; }
  ------------------
  |  Branch (372:42): [True: 54.2k, False: 8.59k]
  ------------------
_ZN6google8protobuf8internal20RepeatedPtrFieldBase19ExchangeCurrentSizeEi:
  668|  1.29k|  inline int ExchangeCurrentSize(int new_size) {
  669|  1.29k|    int prev_size = current_size_;
  670|  1.29k|    current_size_ = new_size;
  671|  1.29k|    return prev_size;
  672|  1.29k|  }
_ZNK6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE4sizeEv:
 1329|  31.4k|inline int RepeatedPtrField<Element>::size() const {
 1330|  31.4k|  return RepeatedPtrFieldBase::size();
 1331|  31.4k|}
_ZN6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE5ClearEv:
 1484|  3.45k|inline void RepeatedPtrField<Element>::Clear() {
 1485|  3.45k|  RepeatedPtrFieldBase::Clear<TypeHandler>();
 1486|  3.45k|}
_ZN6google8protobuf8internal20RepeatedPtrFieldBase5ClearINS0_16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE11TypeHandlerEEEvv:
  283|  3.45k|  void Clear() {
  284|  3.45k|    const int n = current_size_;
  285|  3.45k|    ABSL_DCHECK_GE(n, 0);
  ------------------
  |  |   78|  3.45k|  ABSL_DCHECK_GE_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   94|  3.45k|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|  3.45k|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|  3.45k|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  286|  3.45k|    if (n > 0) {
  ------------------
  |  Branch (286:9): [True: 1.29k, False: 2.16k]
  ------------------
  287|  1.29k|      ClearNonEmpty<TypeHandler>();
  288|  1.29k|    }
  289|  3.45k|  }
_ZN6google8protobuf8internal20RepeatedPtrFieldBase13ClearNonEmptyINS0_16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE11TypeHandlerEEEvv:
  696|  1.29k|  PROTOBUF_NOINLINE void ClearNonEmpty() {
  697|  1.29k|    const int n = current_size_;
  698|  1.29k|    void* const* elements = rep_->elements;
  699|  1.29k|    int i = 0;
  700|  1.29k|    ABSL_DCHECK_GT(
  ------------------
  |  |   80|  1.29k|  ABSL_DCHECK_GT_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   96|  1.29k|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|  1.29k|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|  1.29k|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  701|  1.29k|        n,
  702|  1.29k|        0);  // do/while loop to avoid initial test because we know n > 0
  703|  5.53k|    do {
  704|  5.53k|      TypeHandler::Clear(cast<TypeHandler>(elements[i++]));
  705|  5.53k|    } while (i < n);
  ------------------
  |  Branch (705:14): [True: 4.24k, False: 1.29k]
  ------------------
  706|  1.29k|    ExchangeCurrentSize(0);
  707|  1.29k|  }
_ZN6google8protobuf8internal18GenericTypeHandlerIN8asn1_pdu12ValueElementEE5ClearEPS4_:
  819|  5.53k|  static inline void Clear(GenericType* value) { value->Clear(); }
_ZN6google8protobuf8internal20RepeatedPtrFieldBase4castINS0_16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE11TypeHandlerEEEPNT_4TypeEPv:
  685|  5.53k|  static inline typename TypeHandler::Type* cast(void* element) {
  686|  5.53k|    return reinterpret_cast<typename TypeHandler::Type*>(element);
  687|  5.53k|  }
_ZN6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEEC2EPNS0_5ArenaE:
 1246|  34.2k|    : RepeatedPtrFieldBase(arena) {
 1247|  34.2k|  StaticValidityCheck();
 1248|  34.2k|}
_ZN6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE19StaticValidityCheckEv:
  913|  68.5k|  static constexpr PROTOBUF_ALWAYS_INLINE void StaticValidityCheck() {
  914|  68.5k|    static_assert(
  915|  68.5k|        absl::disjunction<
  916|  68.5k|            internal::is_supported_string_type<Element>,
  917|  68.5k|            internal::is_supported_message_type<Element>>::value,
  918|  68.5k|        "We only support string and Message types in RepeatedPtrField.");
  919|  68.5k|  }
_ZN6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEED2Ev:
 1266|  34.2k|RepeatedPtrField<Element>::~RepeatedPtrField() {
 1267|  34.2k|  StaticValidityCheck();
 1268|       |#ifdef __cpp_if_constexpr
 1269|       |  if constexpr (std::is_base_of<MessageLite, Element>::value) {
 1270|       |#else
 1271|  34.2k|  if (std::is_base_of<MessageLite, Element>::value) {
  ------------------
  |  Branch (1271:7): [Folded - Ignored]
  ------------------
 1272|  34.2k|#endif
 1273|  34.2k|    if (NeedsDestroy()) DestroyProtos();
  ------------------
  |  Branch (1273:9): [True: 28.4k, False: 5.87k]
  ------------------
 1274|  34.2k|  } else {
 1275|      0|    Destroy<TypeHandler>();
 1276|      0|  }
 1277|  34.2k|}
_ZNK6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE5beginEv:
 1845|  31.4k|RepeatedPtrField<Element>::begin() const {
 1846|  31.4k|  return iterator(raw_data());
 1847|  31.4k|}
_ZN6google8protobuf8internal19RepeatedPtrIteratorIN8asn1_pdu12ValueElementEEC2EPKPv:
 1643|  62.8k|  explicit RepeatedPtrIterator(void* const* it) : it_(it) {}
_ZN6google8protobuf8internal19RepeatedPtrIteratorIKN8asn1_pdu12ValueElementEEC2IS4_LPv0EEERKNS2_IT_EE:
 1651|  62.8k|      : it_(other.it_) {}
_ZNK6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE3endEv:
 1860|  31.4k|RepeatedPtrField<Element>::end() const {
 1861|  31.4k|  return iterator(raw_data() + size());
 1862|  31.4k|}
_ZN6google8protobuf8internalneERKNS1_19RepeatedPtrIteratorIKN8asn1_pdu12ValueElementEEES8_:
 1673|  95.7k|  friend bool operator!=(const iterator& x, const iterator& y) {
 1674|  95.7k|    return x.it_ != y.it_;
 1675|  95.7k|  }
_ZN6google8protobuf8internal19RepeatedPtrIteratorIKN8asn1_pdu12ValueElementEEppEv:
 1658|  64.3k|  iterator& operator++() {
 1659|  64.3k|    ++it_;
 1660|  64.3k|    return *this;
 1661|  64.3k|  }
_ZNK6google8protobuf8internal19RepeatedPtrIteratorIKN8asn1_pdu12ValueElementEEdeEv:
 1654|  64.3k|  reference operator*() const { return *reinterpret_cast<Element*>(*it_); }
_ZN6google8protobuf16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE9MergeFromERKS4_:
 1490|    583|    const RepeatedPtrField& other) {
 1491|    583|  RepeatedPtrFieldBase::MergeFrom<TypeHandler>(other);
 1492|    583|}
_ZN6google8protobuf8internal20RepeatedPtrFieldBase9MergeFromINS0_16RepeatedPtrFieldIN8asn1_pdu12ValueElementEE11TypeHandlerEEEvRKS2_:
  292|    583|  void MergeFrom(const RepeatedPtrFieldBase& other) {
  293|       |    // To avoid unnecessary code duplication and reduce binary size, we use a
  294|       |    // layered approach to implementing MergeFrom(). The toplevel method is
  295|       |    // templated, so we get a small thunk per concrete message type in the
  296|       |    // binary. This calls a shared implementation with most of the logic,
  297|       |    // passing a function pointer to another type-specific piece of code that
  298|       |    // calls the object-allocate and merge handlers.
  299|    583|    ABSL_DCHECK_NE(&other, this);
  ------------------
  |  |   72|    583|  ABSL_DCHECK_NE_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   88|    583|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|    583|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|    583|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  300|    583|    if (other.current_size_ == 0) return;
  ------------------
  |  Branch (300:9): [True: 583, False: 0]
  ------------------
  301|      0|    MergeFromInternal(other,
  302|      0|                      &RepeatedPtrFieldBase::MergeFromInnerLoop<TypeHandler>);
  303|      0|  }

_ZN8asn1_pdu12ASN1PDUToDER20EncodeOverrideLengthERKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEm:
   30|  1.72k|                                        size_t len_pos) {
   31|  1.72k|  der_.insert(der_.begin() + len_pos, raw_len.begin(), raw_len.end());
   32|  1.72k|}
_ZN8asn1_pdu12ASN1PDUToDER22EncodeIndefiniteLengthEm:
   34|  1.01k|void ASN1PDUToDER::EncodeIndefiniteLength(size_t len_pos) {
   35|  1.01k|  der_.insert(der_.begin() + len_pos, 0x80);
   36|       |  // The PDU's value is from |len_pos| to the end of |der_|, so just add an
   37|       |  // EOC marker to the end.
   38|  1.01k|  der_.push_back(0x00);
   39|  1.01k|  der_.push_back(0x00);
   40|  1.01k|}
_ZN8asn1_pdu12ASN1PDUToDER20EncodeDefiniteLengthEmm:
   42|  28.6k|void ASN1PDUToDER::EncodeDefiniteLength(size_t actual_len, size_t len_pos) {
   43|  28.6k|  InsertVariableIntBase256(actual_len, len_pos, der_);
   44|       |  // X.690 (2015), 8.1.3.3: The long-form is used when the length is
   45|       |  // larger than 127.
   46|       |  // Note: |len_num_bytes| is not checked here, because it will equal
   47|       |  // 1 for values [128..255], but those require the long-form length.
   48|  28.6k|  if (actual_len > 127) {
  ------------------
  |  Branch (48:7): [True: 10.2k, False: 18.4k]
  ------------------
   49|       |    // See X.690 (2015) 8.1.3.5.
   50|       |    // Long-form length is encoded as a byte with the high-bit set to indicate
   51|       |    // the long-form, while the remaining bits indicate how many bytes are used
   52|       |    // to encode the length.
   53|  10.2k|    size_t len_num_bytes = GetVariableIntLen(actual_len, 256);
   54|  10.2k|    der_.insert(der_.begin() + len_pos, (0x80 | len_num_bytes));
   55|  10.2k|  }
   56|  28.6k|}
_ZN8asn1_pdu12ASN1PDUToDER12EncodeLengthERKNS_6LengthEmm:
   60|  31.4k|                                size_t len_pos) {
   61|  31.4k|  if (len.has_length_override()) {
  ------------------
  |  Branch (61:7): [True: 1.72k, False: 29.6k]
  ------------------
   62|  1.72k|    EncodeOverrideLength(len.length_override(), len_pos);
   63|  29.6k|  } else if (len.has_indefinite_form() && len.indefinite_form()) {
  ------------------
  |  Branch (63:14): [True: 1.21k, False: 28.4k]
  |  Branch (63:43): [True: 1.01k, False: 199]
  ------------------
   64|  1.01k|    EncodeIndefiniteLength(len_pos);
   65|  28.6k|  } else {
   66|  28.6k|    EncodeDefiniteLength(actual_len, len_pos);
   67|  28.6k|  }
   68|  31.4k|}
_ZN8asn1_pdu12ASN1PDUToDER11EncodeValueERKNS_5ValueE:
   70|  31.4k|void ASN1PDUToDER::EncodeValue(const Value& val) {
   71|  64.3k|  for (const auto& val_ele : val.val_array()) {
  ------------------
  |  Branch (71:28): [True: 64.3k, False: 31.4k]
  ------------------
   72|  64.3k|    if (recursion_exceeded_) {
  ------------------
  |  Branch (72:9): [True: 0, False: 64.3k]
  ------------------
   73|       |      // If the message exceeds the recursion limit, abort processing the
   74|       |      // protobuf in order to limit uninteresting work.
   75|      0|      return;
   76|      0|    }
   77|  64.3k|    if (val_ele.has_pdu()) {
  ------------------
  |  Branch (77:9): [True: 25.0k, False: 39.2k]
  ------------------
   78|  25.0k|      EncodePDU(val_ele.pdu());
   79|  39.2k|    } else {
   80|  39.2k|      der_.insert(der_.end(), val_ele.val_bits().begin(),
   81|  39.2k|                  val_ele.val_bits().end());
   82|  39.2k|    }
   83|  64.3k|  }
   84|  31.4k|}
_ZN8asn1_pdu12ASN1PDUToDER23EncodeHighTagNumberFormEhhj:
   88|  1.59k|                                           uint32_t tag_num) {
   89|       |  // High-tag-number form requires the lower 5 bits of the identifier to be set
   90|       |  // to 1 (X.690 (2015), 8.1.2.4.1).
   91|  1.59k|  der_.push_back(id_class | encoding | 0x1F);
   92|       |  // The high-tag-number form base 128 encodes |tag_num| (X.690 (2015), 8.1.2).
   93|  1.59k|  InsertVariableIntBase128(tag_num, der_.size(), der_);
   94|  1.59k|}
_ZN8asn1_pdu12ASN1PDUToDER16EncodeIdentifierERKNS_10IdentifierE:
   96|  31.4k|void ASN1PDUToDER::EncodeIdentifier(const Identifier& id) {
   97|       |  // The class comprises the 7th and 8th bit of the identifier (X.690
   98|       |  // (2015), 8.1.2).
   99|  31.4k|  uint8_t id_class = static_cast<uint8_t>(id.id_class()) << 6;
  100|       |  // The encoding comprises the 6th bit of the identifier (X.690 (2015), 8.1.2).
  101|  31.4k|  uint8_t encoding = static_cast<uint8_t>(id.encoding()) << 5;
  102|       |
  103|  31.4k|  uint32_t tag_num = id.tag_num().has_high_tag_num()
  ------------------
  |  Branch (103:22): [True: 1.73k, False: 29.6k]
  ------------------
  104|  31.4k|                         ? id.tag_num().high_tag_num()
  105|  31.4k|                         : id.tag_num().low_tag_num();
  106|       |  // When the tag number is greater than or equal to 31, encode with a single
  107|       |  // byte; otherwise, use the high-tag-number form (X.690 (2015), 8.1.2).
  108|  31.4k|  if (tag_num >= 31) {
  ------------------
  |  Branch (108:7): [True: 1.59k, False: 29.8k]
  ------------------
  109|  1.59k|    EncodeHighTagNumberForm(id_class, encoding, tag_num);
  110|  29.8k|  } else {
  111|  29.8k|    der_.push_back(static_cast<uint8_t>(id_class | encoding | tag_num));
  112|  29.8k|  }
  113|  31.4k|}
_ZN8asn1_pdu12ASN1PDUToDER9EncodePDUERKNS_3PDUE:
  115|  31.4k|void ASN1PDUToDER::EncodePDU(const PDU& pdu) {
  116|       |  // Artifically limit the stack depth to avoid stack overflow.
  117|  31.4k|  if (depth_ > kRecursionLimit) {
  ------------------
  |  Branch (117:7): [True: 0, False: 31.4k]
  ------------------
  118|      0|    recursion_exceeded_ = true;
  119|      0|    return;
  120|      0|  }
  121|  31.4k|  ++depth_;
  122|  31.4k|  EncodeIdentifier(pdu.id());
  123|  31.4k|  size_t len_pos = der_.size();
  124|  31.4k|  EncodeValue(pdu.val());
  125|  31.4k|  EncodeLength(pdu.len(), der_.size() - len_pos, len_pos);
  126|  31.4k|  --depth_;
  127|  31.4k|}
_ZN8asn1_pdu12ASN1PDUToDER8PDUToDERERKNS_3PDUE:
  129|  6.37k|std::vector<uint8_t> ASN1PDUToDER::PDUToDER(const PDU& pdu) {
  130|       |  // Reset the previous state.
  131|  6.37k|  der_.clear();
  132|  6.37k|  depth_ = 0;
  133|  6.37k|  recursion_exceeded_ = false;
  134|       |
  135|  6.37k|  EncodePDU(pdu);
  136|  6.37k|  if (recursion_exceeded_) {
  ------------------
  |  Branch (136:7): [True: 0, False: 6.37k]
  ------------------
  137|      0|    der_.clear();
  138|      0|  }
  139|  6.37k|  return der_;
  140|  6.37k|}

asn1_bit_string_length:
   75|  20.8k|                           uint8_t *out_padding_bits) {
   76|  20.8k|  int len = str->length;
   77|  20.8k|  if (str->flags & ASN1_STRING_FLAG_BITS_LEFT) {
  ------------------
  |  |  543|  20.8k|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  |  Branch (77:7): [True: 20.8k, False: 0]
  ------------------
   78|       |    // If the string is already empty, it cannot have padding bits.
   79|  20.8k|    *out_padding_bits = len == 0 ? 0 : str->flags & 0x07;
  ------------------
  |  Branch (79:25): [True: 12.9k, False: 7.80k]
  ------------------
   80|  20.8k|    return len;
   81|  20.8k|  }
   82|       |
   83|       |  // TODO(https://crbug.com/boringssl/447): If we move this logic to
   84|       |  // |ASN1_BIT_STRING_set_bit|, can we remove this representation?
   85|      0|  while (len > 0 && str->data[len - 1] == 0) {
  ------------------
  |  Branch (85:10): [True: 0, False: 0]
  |  Branch (85:21): [True: 0, False: 0]
  ------------------
   86|      0|    len--;
   87|      0|  }
   88|      0|  uint8_t padding_bits = 0;
   89|      0|  if (len > 0) {
  ------------------
  |  Branch (89:7): [True: 0, False: 0]
  ------------------
   90|      0|    uint8_t last = str->data[len - 1];
   91|      0|    assert(last != 0);
   92|      0|    for (; padding_bits < 7; padding_bits++) {
  ------------------
  |  Branch (92:12): [True: 0, False: 0]
  ------------------
   93|      0|      if (last & (1 << padding_bits)) {
  ------------------
  |  Branch (93:11): [True: 0, False: 0]
  ------------------
   94|      0|        break;
   95|      0|      }
   96|      0|    }
   97|      0|  }
   98|      0|  *out_padding_bits = padding_bits;
   99|      0|  return len;
  100|      0|}
i2c_ASN1_BIT_STRING:
  112|  20.8k|int i2c_ASN1_BIT_STRING(const ASN1_BIT_STRING *a, unsigned char **pp) {
  113|  20.8k|  if (a == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 20.8k]
  ------------------
  114|      0|    return 0;
  115|      0|  }
  116|       |
  117|  20.8k|  uint8_t bits;
  118|  20.8k|  int len = asn1_bit_string_length(a, &bits);
  119|  20.8k|  if (len > INT_MAX - 1) {
  ------------------
  |  Branch (119:7): [True: 0, False: 20.8k]
  ------------------
  120|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  121|      0|    return 0;
  122|      0|  }
  123|  20.8k|  int ret = 1 + len;
  124|  20.8k|  if (pp == NULL) {
  ------------------
  |  Branch (124:7): [True: 15.3k, False: 5.41k]
  ------------------
  125|  15.3k|    return ret;
  126|  15.3k|  }
  127|       |
  128|  5.41k|  uint8_t *p = *pp;
  129|  5.41k|  *(p++) = bits;
  130|  5.41k|  OPENSSL_memcpy(p, a->data, len);
  131|  5.41k|  if (len > 0) {
  ------------------
  |  Branch (131:7): [True: 1.84k, False: 3.57k]
  ------------------
  132|  1.84k|    p[len - 1] &= (0xff << bits);
  133|  1.84k|  }
  134|  5.41k|  p += len;
  135|  5.41k|  *pp = p;
  136|  5.41k|  return ret;
  137|  20.8k|}
c2i_ASN1_BIT_STRING:
  140|  6.12k|                                     const unsigned char **pp, long len) {
  141|  6.12k|  ASN1_BIT_STRING *ret = NULL;
  142|  6.12k|  const unsigned char *p;
  143|  6.12k|  unsigned char *s;
  144|  6.12k|  int padding;
  145|       |
  146|  6.12k|  if (len < 1) {
  ------------------
  |  Branch (146:7): [True: 23, False: 6.10k]
  ------------------
  147|     23|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_SHORT);
  ------------------
  |  |  441|     23|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  148|     23|    goto err;
  149|     23|  }
  150|       |
  151|  6.10k|  if (len > INT_MAX) {
  ------------------
  |  Branch (151:7): [True: 0, False: 6.10k]
  ------------------
  152|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  153|      0|    goto err;
  154|      0|  }
  155|       |
  156|  6.10k|  if ((a == NULL) || ((*a) == NULL)) {
  ------------------
  |  Branch (156:7): [True: 2.34k, False: 3.75k]
  |  Branch (156:22): [True: 70, False: 3.68k]
  ------------------
  157|  2.41k|    if ((ret = ASN1_BIT_STRING_new()) == NULL) {
  ------------------
  |  Branch (157:9): [True: 0, False: 2.41k]
  ------------------
  158|      0|      return NULL;
  159|      0|    }
  160|  3.68k|  } else {
  161|  3.68k|    ret = (*a);
  162|  3.68k|  }
  163|       |
  164|  6.10k|  p = *pp;
  165|  6.10k|  padding = *(p++);
  166|  6.10k|  len--;
  167|  6.10k|  if (padding > 7) {
  ------------------
  |  Branch (167:7): [True: 46, False: 6.05k]
  ------------------
  168|     46|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BIT_STRING_BITS_LEFT);
  ------------------
  |  |  441|     46|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|     46|    goto err;
  170|     46|  }
  171|       |
  172|       |  // Unused bits in a BIT STRING must be zero.
  173|  6.05k|  uint8_t padding_mask = (1 << padding) - 1;
  174|  6.05k|  if (padding != 0 && (len < 1 || (p[len - 1] & padding_mask) != 0)) {
  ------------------
  |  Branch (174:7): [True: 542, False: 5.51k]
  |  Branch (174:24): [True: 2, False: 540]
  |  Branch (174:35): [True: 7, False: 533]
  ------------------
  175|      9|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BIT_STRING_PADDING);
  ------------------
  |  |  441|      9|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  176|      9|    goto err;
  177|      9|  }
  178|       |
  179|       |  // We do this to preserve the settings.  If we modify the settings, via
  180|       |  // the _set_bit function, we will recalculate on output
  181|  6.04k|  ret->flags &= ~(ASN1_STRING_FLAG_BITS_LEFT | 0x07);    // clear
  ------------------
  |  |  543|  6.04k|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  182|  6.04k|  ret->flags |= (ASN1_STRING_FLAG_BITS_LEFT | padding);  // set
  ------------------
  |  |  543|  6.04k|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  183|       |
  184|  6.04k|  if (len > 0) {
  ------------------
  |  Branch (184:7): [True: 1.86k, False: 4.18k]
  ------------------
  185|  1.86k|    s = OPENSSL_memdup(p, len);
  186|  1.86k|    if (s == NULL) {
  ------------------
  |  Branch (186:9): [True: 0, False: 1.86k]
  ------------------
  187|      0|      goto err;
  188|      0|    }
  189|  1.86k|    p += len;
  190|  4.18k|  } else {
  191|  4.18k|    s = NULL;
  192|  4.18k|  }
  193|       |
  194|  6.04k|  ret->length = (int)len;
  195|  6.04k|  OPENSSL_free(ret->data);
  196|  6.04k|  ret->data = s;
  197|  6.04k|  ret->type = V_ASN1_BIT_STRING;
  ------------------
  |  |  127|  6.04k|#define V_ASN1_BIT_STRING 3
  ------------------
  198|  6.04k|  if (a != NULL) {
  ------------------
  |  Branch (198:7): [True: 3.71k, False: 2.33k]
  ------------------
  199|  3.71k|    (*a) = ret;
  200|  3.71k|  }
  201|  6.04k|  *pp = p;
  202|  6.04k|  return ret;
  203|     78|err:
  204|     78|  if ((ret != NULL) && ((a == NULL) || (*a != ret))) {
  ------------------
  |  Branch (204:7): [True: 55, False: 23]
  |  Branch (204:25): [True: 13, False: 42]
  |  Branch (204:40): [True: 36, False: 6]
  ------------------
  205|     49|    ASN1_BIT_STRING_free(ret);
  206|     49|  }
  207|     78|  return NULL;
  208|  6.04k|}

i2c_ASN1_INTEGER:
  117|  28.4k|int i2c_ASN1_INTEGER(const ASN1_INTEGER *in, unsigned char **outp) {
  118|  28.4k|  if (in == NULL) {
  ------------------
  |  Branch (118:7): [True: 0, False: 28.4k]
  ------------------
  119|      0|    return 0;
  120|      0|  }
  121|       |
  122|       |  // |ASN1_INTEGER|s should be represented minimally, but it is possible to
  123|       |  // construct invalid ones. Skip leading zeros so this does not produce an
  124|       |  // invalid encoding or break invariants.
  125|  28.4k|  CBS cbs;
  126|  28.4k|  CBS_init(&cbs, in->data, in->length);
  127|  28.4k|  while (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0) {
  ------------------
  |  Branch (127:10): [True: 25.0k, False: 3.41k]
  |  Branch (127:31): [True: 0, False: 25.0k]
  ------------------
  128|      0|    CBS_skip(&cbs, 1);
  129|      0|  }
  130|       |
  131|  28.4k|  int is_negative = (in->type & V_ASN1_NEG) != 0;
  ------------------
  |  |  155|  28.4k|#define V_ASN1_NEG 0x100
  ------------------
  132|  28.4k|  size_t pad;
  133|  28.4k|  CBS copy = cbs;
  134|  28.4k|  uint8_t msb;
  135|  28.4k|  if (!CBS_get_u8(&copy, &msb)) {
  ------------------
  |  Branch (135:7): [True: 3.41k, False: 25.0k]
  ------------------
  136|       |    // Zero is represented as a single byte.
  137|  3.41k|    is_negative = 0;
  138|  3.41k|    pad = 1;
  139|  25.0k|  } else if (is_negative) {
  ------------------
  |  Branch (139:14): [True: 16.6k, False: 8.39k]
  ------------------
  140|       |    // 0x80...01 through 0xff...ff have a two's complement of 0x7f...ff
  141|       |    // through 0x00...01 and need an extra byte to be negative.
  142|       |    // 0x01...00 through 0x80...00 have a two's complement of 0xfe...ff
  143|       |    // through 0x80...00 and can be negated as-is.
  144|  16.6k|    pad = msb > 0x80 ||
  ------------------
  |  Branch (144:11): [True: 4.32k, False: 12.3k]
  ------------------
  145|  16.6k|          (msb == 0x80 && !is_all_zeros(CBS_data(&copy), CBS_len(&copy)));
  ------------------
  |  Branch (145:12): [True: 8.93k, False: 3.38k]
  |  Branch (145:27): [True: 3.00k, False: 5.93k]
  ------------------
  146|  16.6k|  } else {
  147|       |    // If the high bit is set, the signed representation needs an extra
  148|       |    // byte to be positive.
  149|  8.39k|    pad = (msb & 0x80) != 0;
  150|  8.39k|  }
  151|       |
  152|  28.4k|  if (CBS_len(&cbs) > INT_MAX - pad) {
  ------------------
  |  Branch (152:7): [True: 0, False: 28.4k]
  ------------------
  153|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  154|      0|    return 0;
  155|      0|  }
  156|  28.4k|  int len = (int)(pad + CBS_len(&cbs));
  157|  28.4k|  assert(len > 0);
  158|  28.4k|  if (outp == NULL) {
  ------------------
  |  Branch (158:7): [True: 22.7k, False: 5.69k]
  ------------------
  159|  22.7k|    return len;
  160|  22.7k|  }
  161|       |
  162|  5.69k|  if (pad) {
  ------------------
  |  Branch (162:7): [True: 2.22k, False: 3.46k]
  ------------------
  163|  2.22k|    (*outp)[0] = 0;
  164|  2.22k|  }
  165|  5.69k|  OPENSSL_memcpy(*outp + pad, CBS_data(&cbs), CBS_len(&cbs));
  166|  5.69k|  if (is_negative) {
  ------------------
  |  Branch (166:7): [True: 3.32k, False: 2.36k]
  ------------------
  167|  3.32k|    negate_twos_complement(*outp, len);
  168|  3.32k|    assert((*outp)[0] >= 0x80);
  169|  3.32k|  } else {
  170|  2.36k|    assert((*outp)[0] < 0x80);
  171|  2.36k|  }
  172|  5.69k|  *outp += len;
  173|  5.69k|  return len;
  174|  5.69k|}
c2i_ASN1_INTEGER:
  177|  11.0k|                               long len) {
  178|       |  // This function can handle lengths up to INT_MAX - 1, but the rest of the
  179|       |  // legacy ASN.1 code mixes integer types, so avoid exposing it to
  180|       |  // ASN1_INTEGERS with larger lengths.
  181|  11.0k|  if (len < 0 || len > INT_MAX / 2) {
  ------------------
  |  Branch (181:7): [True: 0, False: 11.0k]
  |  Branch (181:18): [True: 0, False: 11.0k]
  ------------------
  182|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  183|      0|    return NULL;
  184|      0|  }
  185|       |
  186|  11.0k|  CBS cbs;
  187|  11.0k|  CBS_init(&cbs, *inp, (size_t)len);
  188|  11.0k|  int is_negative;
  189|  11.0k|  if (!CBS_is_valid_asn1_integer(&cbs, &is_negative)) {
  ------------------
  |  Branch (189:7): [True: 16, False: 11.0k]
  ------------------
  190|     16|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|     16|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  191|     16|    return NULL;
  192|     16|  }
  193|       |
  194|  11.0k|  ASN1_INTEGER *ret = NULL;
  195|  11.0k|  if (out == NULL || *out == NULL) {
  ------------------
  |  Branch (195:7): [True: 0, False: 11.0k]
  |  Branch (195:22): [True: 357, False: 10.6k]
  ------------------
  196|    357|    ret = ASN1_INTEGER_new();
  197|    357|    if (ret == NULL) {
  ------------------
  |  Branch (197:9): [True: 0, False: 357]
  ------------------
  198|      0|      return NULL;
  199|      0|    }
  200|  10.6k|  } else {
  201|  10.6k|    ret = *out;
  202|  10.6k|  }
  203|       |
  204|       |  // Convert to |ASN1_INTEGER|'s sign-and-magnitude representation. First,
  205|       |  // determine the size needed for a minimal result.
  206|  11.0k|  if (is_negative) {
  ------------------
  |  Branch (206:7): [True: 3.64k, False: 7.38k]
  ------------------
  207|       |    // 0xff00...01 through 0xff7f..ff have a two's complement of 0x00ff...ff
  208|       |    // through 0x000100...001 and need one leading zero removed. 0x8000...00
  209|       |    // through 0xff00...00 have a two's complement of 0x8000...00 through
  210|       |    // 0x0100...00 and will be minimally-encoded as-is.
  211|  3.64k|    if (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0xff &&
  ------------------
  |  Branch (211:9): [True: 3.64k, False: 0]
  |  Branch (211:30): [True: 1.79k, False: 1.84k]
  ------------------
  212|  3.64k|        !is_all_zeros(CBS_data(&cbs) + 1, CBS_len(&cbs) - 1)) {
  ------------------
  |  Branch (212:9): [True: 1.64k, False: 151]
  ------------------
  213|  1.64k|      CBS_skip(&cbs, 1);
  214|  1.64k|    }
  215|  7.38k|  } else {
  216|       |    // Remove the leading zero byte, if any.
  217|  7.38k|    if (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0x00) {
  ------------------
  |  Branch (217:9): [True: 7.38k, False: 0]
  |  Branch (217:30): [True: 788, False: 6.60k]
  ------------------
  218|    788|      CBS_skip(&cbs, 1);
  219|    788|    }
  220|  7.38k|  }
  221|       |
  222|  11.0k|  if (!ASN1_STRING_set(ret, CBS_data(&cbs), CBS_len(&cbs))) {
  ------------------
  |  Branch (222:7): [True: 0, False: 11.0k]
  ------------------
  223|      0|    goto err;
  224|      0|  }
  225|       |
  226|  11.0k|  if (is_negative) {
  ------------------
  |  Branch (226:7): [True: 3.64k, False: 7.38k]
  ------------------
  227|  3.64k|    ret->type = V_ASN1_NEG_INTEGER;
  ------------------
  |  |  156|  3.64k|#define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  126|  3.64k|#define V_ASN1_INTEGER 2
  |  |  ------------------
  |  |               #define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|  3.64k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  228|  3.64k|    negate_twos_complement(ret->data, ret->length);
  229|  7.38k|  } else {
  230|  7.38k|    ret->type = V_ASN1_INTEGER;
  ------------------
  |  |  126|  7.38k|#define V_ASN1_INTEGER 2
  ------------------
  231|  7.38k|  }
  232|       |
  233|       |  // The value should be minimally-encoded.
  234|  11.0k|  assert(ret->length == 0 || ret->data[0] != 0);
  235|       |  // Zero is not negative.
  236|  11.0k|  assert(!is_negative || ret->length > 0);
  237|       |
  238|  11.0k|  *inp += len;
  239|  11.0k|  if (out != NULL) {
  ------------------
  |  Branch (239:7): [True: 11.0k, False: 0]
  ------------------
  240|  11.0k|    *out = ret;
  241|  11.0k|  }
  242|  11.0k|  return ret;
  243|       |
  244|      0|err:
  245|      0|  if (ret != NULL && (out == NULL || *out != ret)) {
  ------------------
  |  Branch (245:7): [True: 0, False: 0]
  |  Branch (245:23): [True: 0, False: 0]
  |  Branch (245:38): [True: 0, False: 0]
  ------------------
  246|      0|    ASN1_INTEGER_free(ret);
  247|      0|  }
  248|      0|  return NULL;
  249|  11.0k|}
ASN1_INTEGER_get:
  395|    241|long ASN1_INTEGER_get(const ASN1_INTEGER *a) {
  396|    241|  return asn1_string_get_long(a, V_ASN1_INTEGER);
  ------------------
  |  |  126|    241|#define V_ASN1_INTEGER 2
  ------------------
  397|    241|}
a_int.c:is_all_zeros:
  108|  10.7k|static int is_all_zeros(const uint8_t *in, size_t len) {
  109|  17.2k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (109:22): [True: 11.1k, False: 6.08k]
  ------------------
  110|  11.1k|    if (in[i] != 0) {
  ------------------
  |  Branch (110:9): [True: 4.65k, False: 6.47k]
  ------------------
  111|  4.65k|      return 0;
  112|  4.65k|    }
  113|  11.1k|  }
  114|  6.08k|  return 1;
  115|  10.7k|}
a_int.c:negate_twos_complement:
   99|  6.97k|static void negate_twos_complement(uint8_t *buf, size_t len) {
  100|  6.97k|  uint8_t borrow = 0;
  101|  8.38M|  for (size_t i = len - 1; i < len; i--) {
  ------------------
  |  Branch (101:28): [True: 8.37M, False: 6.97k]
  ------------------
  102|  8.37M|    uint8_t t = buf[i];
  103|  8.37M|    buf[i] = 0u - borrow - t;
  104|  8.37M|    borrow |= t != 0;
  105|  8.37M|  }
  106|  6.97k|}
a_int.c:asn1_string_get_abs_uint64:
  313|    241|                                      int type) {
  314|    241|  if ((a->type & ~V_ASN1_NEG) != type) {
  ------------------
  |  |  155|    241|#define V_ASN1_NEG 0x100
  ------------------
  |  Branch (314:7): [True: 0, False: 241]
  ------------------
  315|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_INTEGER_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  316|      0|    return 0;
  317|      0|  }
  318|    241|  uint8_t buf[sizeof(uint64_t)] = {0};
  319|    241|  if (a->length > (int)sizeof(buf)) {
  ------------------
  |  Branch (319:7): [True: 16, False: 225]
  ------------------
  320|     16|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|     16|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  321|     16|    return 0;
  322|     16|  }
  323|    225|  OPENSSL_memcpy(buf + sizeof(buf) - a->length, a->data, a->length);
  324|    225|  *out = CRYPTO_load_u64_be(buf);
  325|    225|  return 1;
  326|    241|}
a_int.c:asn1_string_get_int64:
  348|    241|static int asn1_string_get_int64(int64_t *out, const ASN1_STRING *a, int type) {
  349|    241|  uint64_t v;
  350|    241|  if (!asn1_string_get_abs_uint64(&v, a, type)) {
  ------------------
  |  Branch (350:7): [True: 16, False: 225]
  ------------------
  351|     16|    return 0;
  352|     16|  }
  353|    225|  int64_t i64;
  354|    225|  int fits_in_i64;
  355|       |  // Check |v != 0| to handle manually-constructed negative zeros.
  356|    225|  if ((a->type & V_ASN1_NEG) && v != 0) {
  ------------------
  |  |  155|    225|#define V_ASN1_NEG 0x100
  ------------------
  |  Branch (356:7): [True: 155, False: 70]
  |  Branch (356:33): [True: 155, False: 0]
  ------------------
  357|    155|    i64 = (int64_t)(0u - v);
  358|    155|    fits_in_i64 = i64 < 0;
  359|    155|  } else {
  360|     70|    i64 = (int64_t)v;
  361|     70|    fits_in_i64 = i64 >= 0;
  362|     70|  }
  363|    225|  if (!fits_in_i64) {
  ------------------
  |  Branch (363:7): [True: 62, False: 163]
  ------------------
  364|     62|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|     62|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  365|     62|    return 0;
  366|     62|  }
  367|    163|  *out = i64;
  368|    163|  return 1;
  369|    225|}
a_int.c:asn1_string_get_long:
  379|    241|static long asn1_string_get_long(const ASN1_STRING *a, int type) {
  380|    241|  if (a == NULL) {
  ------------------
  |  Branch (380:7): [True: 0, False: 241]
  ------------------
  381|      0|    return 0;
  382|      0|  }
  383|       |
  384|    241|  int64_t v;
  385|    241|  if (!asn1_string_get_int64(&v, a, type) ||  //
  ------------------
  |  Branch (385:7): [True: 78, False: 163]
  ------------------
  386|    241|      v < LONG_MIN || v > LONG_MAX) {
  ------------------
  |  Branch (386:7): [True: 0, False: 163]
  |  Branch (386:23): [True: 0, False: 163]
  ------------------
  387|       |    // This function's return value does not distinguish overflow from -1.
  388|     78|    ERR_clear_error();
  389|     78|    return -1;
  390|     78|  }
  391|       |
  392|    163|  return (long)v;
  393|    241|}

ASN1_mbstring_copy:
   77|  1.90k|                       ossl_ssize_t len, int inform, unsigned long mask) {
   78|  1.90k|  return ASN1_mbstring_ncopy(out, in, len, inform, mask, /*minsize=*/0,
   79|  1.90k|                             /*maxsize=*/0);
   80|  1.90k|}
ASN1_mbstring_ncopy:
   88|  1.90k|                        ossl_ssize_t minsize, ossl_ssize_t maxsize) {
   89|  1.90k|  if (len == -1) {
  ------------------
  |  Branch (89:7): [True: 0, False: 1.90k]
  ------------------
   90|      0|    len = strlen((const char *)in);
   91|      0|  }
   92|  1.90k|  if (!mask) {
  ------------------
  |  Branch (92:7): [True: 0, False: 1.90k]
  ------------------
   93|      0|    mask = DIRSTRING_TYPE;
  ------------------
  |  |  718|      0|  (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  161|      0|#define B_ASN1_PRINTABLESTRING 0x0002
  |  |  ------------------
  |  |                 (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  162|      0|#define B_ASN1_T61STRING 0x0004
  |  |  ------------------
  |  |                 (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  173|      0|#define B_ASN1_BMPSTRING 0x0800
  |  |  ------------------
  |  |  719|      0|   B_ASN1_UTF8STRING)
  |  |  ------------------
  |  |  |  |  175|      0|#define B_ASN1_UTF8STRING 0x2000
  |  |  ------------------
  ------------------
   94|      0|  }
   95|       |
   96|  1.90k|  int (*decode_func)(CBS *, uint32_t *);
   97|  1.90k|  int error;
   98|  1.90k|  switch (inform) {
   99|    365|    case MBSTRING_BMP:
  ------------------
  |  |  713|    365|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|    365|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (99:5): [True: 365, False: 1.53k]
  ------------------
  100|    365|      decode_func = cbs_get_ucs2_be;
  101|    365|      error = ASN1_R_INVALID_BMPSTRING;
  ------------------
  |  | 2009|    365|#define ASN1_R_INVALID_BMPSTRING 142
  ------------------
  102|    365|      break;
  103|       |
  104|    320|    case MBSTRING_UNIV:
  ------------------
  |  |  714|    320|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|    320|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (104:5): [True: 320, False: 1.58k]
  ------------------
  105|    320|      decode_func = cbs_get_utf32_be;
  106|    320|      error = ASN1_R_INVALID_UNIVERSALSTRING;
  ------------------
  |  | 2016|    320|#define ASN1_R_INVALID_UNIVERSALSTRING 149
  ------------------
  107|    320|      break;
  108|       |
  109|    457|    case MBSTRING_UTF8:
  ------------------
  |  |  711|    457|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|    457|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (109:5): [True: 457, False: 1.44k]
  ------------------
  110|    457|      decode_func = cbs_get_utf8;
  111|    457|      error = ASN1_R_INVALID_UTF8STRING;
  ------------------
  |  | 2017|    457|#define ASN1_R_INVALID_UTF8STRING 150
  ------------------
  112|    457|      break;
  113|       |
  114|    758|    case MBSTRING_ASC:
  ------------------
  |  |  712|    758|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|    758|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (114:5): [True: 758, False: 1.14k]
  ------------------
  115|    758|      decode_func = cbs_get_latin1;
  116|    758|      error = ERR_R_INTERNAL_ERROR;  // Latin-1 inputs are never invalid.
  ------------------
  |  |  387|    758|#define ERR_R_INTERNAL_ERROR (4 | ERR_R_FATAL)
  |  |  ------------------
  |  |  |  |  383|    758|#define ERR_R_FATAL 64
  |  |  ------------------
  ------------------
  117|    758|      break;
  118|       |
  119|      0|    default:
  ------------------
  |  Branch (119:5): [True: 0, False: 1.90k]
  ------------------
  120|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNKNOWN_FORMAT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  121|      0|      return -1;
  122|  1.90k|  }
  123|       |
  124|       |  // Check |minsize| and |maxsize| and work out the minimal type, if any.
  125|  1.90k|  CBS cbs;
  126|  1.90k|  CBS_init(&cbs, in, len);
  127|  1.90k|  size_t utf8_len = 0, nchar = 0;
  128|  7.56M|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (128:10): [True: 7.56M, False: 1.86k]
  ------------------
  129|  7.56M|    uint32_t c;
  130|  7.56M|    if (!decode_func(&cbs, &c)) {
  ------------------
  |  Branch (130:9): [True: 0, False: 7.56M]
  ------------------
  131|      0|      OPENSSL_PUT_ERROR(ASN1, error);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|      0|      return -1;
  133|      0|    }
  134|  7.56M|    if (nchar == 0 && (inform == MBSTRING_BMP || inform == MBSTRING_UNIV) &&
  ------------------
  |  |  713|  3.03k|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|  1.51k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
                  if (nchar == 0 && (inform == MBSTRING_BMP || inform == MBSTRING_UNIV) &&
  ------------------
  |  |  714|  1.15k|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|  1.15k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (134:9): [True: 1.51k, False: 7.56M]
  |  Branch (134:24): [True: 365, False: 1.15k]
  |  Branch (134:50): [True: 126, False: 1.02k]
  ------------------
  135|  7.56M|        c == 0xfeff) {
  ------------------
  |  Branch (135:9): [True: 38, False: 453]
  ------------------
  136|       |      // Reject byte-order mark. We could drop it but that would mean
  137|       |      // adding ambiguity around whether a BOM was included or not when
  138|       |      // matching strings.
  139|       |      //
  140|       |      // For a little-endian UCS-2 string, the BOM will appear as 0xfffe
  141|       |      // and will be rejected as noncharacter, below.
  142|     38|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|     38|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  143|     38|      return -1;
  144|     38|    }
  145|       |
  146|       |    // Update which output formats are still possible.
  147|  7.56M|    if ((mask & B_ASN1_PRINTABLESTRING) && !asn1_is_printable(c)) {
  ------------------
  |  |  161|  7.56M|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  |  Branch (147:9): [True: 0, False: 7.56M]
  |  Branch (147:44): [True: 0, False: 0]
  ------------------
  148|      0|      mask &= ~B_ASN1_PRINTABLESTRING;
  ------------------
  |  |  161|      0|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  149|      0|    }
  150|  7.56M|    if ((mask & B_ASN1_IA5STRING) && (c > 127)) {
  ------------------
  |  |  165|  7.56M|#define B_ASN1_IA5STRING 0x0010
  ------------------
  |  Branch (150:9): [True: 0, False: 7.56M]
  |  Branch (150:38): [True: 0, False: 0]
  ------------------
  151|      0|      mask &= ~B_ASN1_IA5STRING;
  ------------------
  |  |  165|      0|#define B_ASN1_IA5STRING 0x0010
  ------------------
  152|      0|    }
  153|  7.56M|    if ((mask & B_ASN1_T61STRING) && (c > 0xff)) {
  ------------------
  |  |  162|  7.56M|#define B_ASN1_T61STRING 0x0004
  ------------------
  |  Branch (153:9): [True: 0, False: 7.56M]
  |  Branch (153:38): [True: 0, False: 0]
  ------------------
  154|      0|      mask &= ~B_ASN1_T61STRING;
  ------------------
  |  |  162|      0|#define B_ASN1_T61STRING 0x0004
  ------------------
  155|      0|    }
  156|  7.56M|    if ((mask & B_ASN1_BMPSTRING) && (c > 0xffff)) {
  ------------------
  |  |  173|  7.56M|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  |  Branch (156:9): [True: 0, False: 7.56M]
  |  Branch (156:38): [True: 0, False: 0]
  ------------------
  157|      0|      mask &= ~B_ASN1_BMPSTRING;
  ------------------
  |  |  173|      0|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  158|      0|    }
  159|  7.56M|    if (!mask) {
  ------------------
  |  Branch (159:9): [True: 0, False: 7.56M]
  ------------------
  160|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  161|      0|      return -1;
  162|      0|    }
  163|       |
  164|  7.56M|    nchar++;
  165|  7.56M|    utf8_len += cbb_get_utf8_len(c);
  166|  7.56M|    if (maxsize > 0 && nchar > (size_t)maxsize) {
  ------------------
  |  Branch (166:9): [True: 0, False: 7.56M]
  |  Branch (166:24): [True: 0, False: 0]
  ------------------
  167|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|      ERR_add_error_dataf("maxsize=%zu", (size_t)maxsize);
  169|      0|      return -1;
  170|      0|    }
  171|  7.56M|  }
  172|       |
  173|  1.86k|  if (minsize > 0 && nchar < (size_t)minsize) {
  ------------------
  |  Branch (173:7): [True: 0, False: 1.86k]
  |  Branch (173:22): [True: 0, False: 0]
  ------------------
  174|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_SHORT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  175|      0|    ERR_add_error_dataf("minsize=%zu", (size_t)minsize);
  176|      0|    return -1;
  177|      0|  }
  178|       |
  179|       |  // Now work out output format and string type
  180|  1.86k|  int str_type;
  181|  1.86k|  int (*encode_func)(CBB *, uint32_t) = cbb_add_latin1;
  182|  1.86k|  size_t size_estimate = nchar;
  183|  1.86k|  int outform = MBSTRING_ASC;
  ------------------
  |  |  712|  1.86k|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|  1.86k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  184|  1.86k|  if (mask & B_ASN1_PRINTABLESTRING) {
  ------------------
  |  |  161|  1.86k|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  |  Branch (184:7): [True: 0, False: 1.86k]
  ------------------
  185|      0|    str_type = V_ASN1_PRINTABLESTRING;
  ------------------
  |  |  139|      0|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  186|  1.86k|  } else if (mask & B_ASN1_IA5STRING) {
  ------------------
  |  |  165|  1.86k|#define B_ASN1_IA5STRING 0x0010
  ------------------
  |  Branch (186:14): [True: 0, False: 1.86k]
  ------------------
  187|      0|    str_type = V_ASN1_IA5STRING;
  ------------------
  |  |  143|      0|#define V_ASN1_IA5STRING 22
  ------------------
  188|  1.86k|  } else if (mask & B_ASN1_T61STRING) {
  ------------------
  |  |  162|  1.86k|#define B_ASN1_T61STRING 0x0004
  ------------------
  |  Branch (188:14): [True: 0, False: 1.86k]
  ------------------
  189|      0|    str_type = V_ASN1_T61STRING;
  ------------------
  |  |  140|      0|#define V_ASN1_T61STRING 20
  ------------------
  190|  1.86k|  } else if (mask & B_ASN1_BMPSTRING) {
  ------------------
  |  |  173|  1.86k|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  |  Branch (190:14): [True: 0, False: 1.86k]
  ------------------
  191|      0|    str_type = V_ASN1_BMPSTRING;
  ------------------
  |  |  151|      0|#define V_ASN1_BMPSTRING 30
  ------------------
  192|      0|    outform = MBSTRING_BMP;
  ------------------
  |  |  713|      0|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  193|      0|    encode_func = cbb_add_ucs2_be;
  194|      0|    size_estimate = 2 * nchar;
  195|  1.86k|  } else if (mask & B_ASN1_UNIVERSALSTRING) {
  ------------------
  |  |  170|  1.86k|#define B_ASN1_UNIVERSALSTRING 0x0100
  ------------------
  |  Branch (195:14): [True: 0, False: 1.86k]
  ------------------
  196|      0|    str_type = V_ASN1_UNIVERSALSTRING;
  ------------------
  |  |  150|      0|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  197|      0|    encode_func = cbb_add_utf32_be;
  198|      0|    size_estimate = 4 * nchar;
  199|      0|    outform = MBSTRING_UNIV;
  ------------------
  |  |  714|      0|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  200|  1.86k|  } else if (mask & B_ASN1_UTF8STRING) {
  ------------------
  |  |  175|  1.86k|#define B_ASN1_UTF8STRING 0x2000
  ------------------
  |  Branch (200:14): [True: 1.86k, False: 0]
  ------------------
  201|  1.86k|    str_type = V_ASN1_UTF8STRING;
  ------------------
  |  |  135|  1.86k|#define V_ASN1_UTF8STRING 12
  ------------------
  202|  1.86k|    outform = MBSTRING_UTF8;
  ------------------
  |  |  711|  1.86k|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|  1.86k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  203|  1.86k|    encode_func = cbb_add_utf8;
  204|  1.86k|    size_estimate = utf8_len;
  205|  1.86k|  } else {
  206|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  207|      0|    return -1;
  208|      0|  }
  209|       |
  210|  1.86k|  if (!out) {
  ------------------
  |  Branch (210:7): [True: 0, False: 1.86k]
  ------------------
  211|      0|    return str_type;
  212|      0|  }
  213|       |
  214|  1.86k|  int free_dest = 0;
  215|  1.86k|  ASN1_STRING *dest;
  216|  1.86k|  if (*out) {
  ------------------
  |  Branch (216:7): [True: 1.86k, False: 0]
  ------------------
  217|  1.86k|    dest = *out;
  218|  1.86k|  } else {
  219|      0|    free_dest = 1;
  220|      0|    dest = ASN1_STRING_type_new(str_type);
  221|      0|    if (!dest) {
  ------------------
  |  Branch (221:9): [True: 0, False: 0]
  ------------------
  222|      0|      return -1;
  223|      0|    }
  224|      0|  }
  225|       |
  226|  1.86k|  CBB cbb;
  227|  1.86k|  CBB_zero(&cbb);
  228|       |  // If both the same type just copy across
  229|  1.86k|  if (inform == outform) {
  ------------------
  |  Branch (229:7): [True: 457, False: 1.40k]
  ------------------
  230|    457|    if (!ASN1_STRING_set(dest, in, len)) {
  ------------------
  |  Branch (230:9): [True: 0, False: 457]
  ------------------
  231|      0|      goto err;
  232|      0|    }
  233|    457|    dest->type = str_type;
  234|    457|    *out = dest;
  235|    457|    return str_type;
  236|    457|  }
  237|  1.40k|  if (!CBB_init(&cbb, size_estimate + 1)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 1.40k]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|  1.40k|  CBS_init(&cbs, in, len);
  241|  7.43M|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (241:10): [True: 7.43M, False: 1.40k]
  ------------------
  242|  7.43M|    uint32_t c;
  243|  7.43M|    if (!decode_func(&cbs, &c) || !encode_func(&cbb, c)) {
  ------------------
  |  Branch (243:9): [True: 0, False: 7.43M]
  |  Branch (243:35): [True: 0, False: 7.43M]
  ------------------
  244|      0|      OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  245|      0|      goto err;
  246|      0|    }
  247|  7.43M|  }
  248|  1.40k|  uint8_t *data = NULL;
  249|  1.40k|  size_t data_len;
  250|  1.40k|  if (// OpenSSL historically NUL-terminated this value with a single byte,
  251|       |      // even for |MBSTRING_BMP| and |MBSTRING_UNIV|.
  252|  1.40k|      !CBB_add_u8(&cbb, 0) || !CBB_finish(&cbb, &data, &data_len) ||
  ------------------
  |  Branch (252:7): [True: 0, False: 1.40k]
  |  Branch (252:31): [True: 0, False: 1.40k]
  ------------------
  253|  1.40k|      data_len < 1 || data_len > INT_MAX) {
  ------------------
  |  Branch (253:7): [True: 0, False: 1.40k]
  |  Branch (253:23): [True: 0, False: 1.40k]
  ------------------
  254|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  255|      0|    OPENSSL_free(data);
  256|      0|    goto err;
  257|      0|  }
  258|  1.40k|  dest->type = str_type;
  259|  1.40k|  ASN1_STRING_set0(dest, data, (int)data_len - 1);
  260|  1.40k|  *out = dest;
  261|  1.40k|  return str_type;
  262|       |
  263|      0|err:
  264|      0|  if (free_dest) {
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|      0|    ASN1_STRING_free(dest);
  266|      0|  }
  267|      0|  CBB_cleanup(&cbb);
  268|      0|  return -1;
  269|  1.40k|}

c2i_ASN1_OBJECT:
  157|  35.7k|                             long len) {
  158|  35.7k|  if (len < 0) {
  ------------------
  |  Branch (158:7): [True: 0, False: 35.7k]
  ------------------
  159|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_OBJECT_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  160|      0|    return NULL;
  161|      0|  }
  162|       |
  163|  35.7k|  CBS cbs;
  164|  35.7k|  CBS_init(&cbs, *inp, (size_t)len);
  165|  35.7k|  if (!CBS_is_valid_asn1_oid(&cbs)) {
  ------------------
  |  Branch (165:7): [True: 3, False: 35.7k]
  ------------------
  166|      3|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_OBJECT_ENCODING);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  167|      3|    return NULL;
  168|      3|  }
  169|       |
  170|  35.7k|  ASN1_OBJECT *ret = ASN1_OBJECT_create(NID_undef, *inp, (size_t)len,
  ------------------
  |  |   85|  35.7k|#define NID_undef 0
  ------------------
  171|       |                                        /*sn=*/NULL, /*ln=*/NULL);
  172|  35.7k|  if (ret == NULL) {
  ------------------
  |  Branch (172:7): [True: 0, False: 35.7k]
  ------------------
  173|      0|    return NULL;
  174|      0|  }
  175|       |
  176|  35.7k|  if (out != NULL) {
  ------------------
  |  Branch (176:7): [True: 35.7k, False: 0]
  ------------------
  177|  35.7k|    ASN1_OBJECT_free(*out);
  178|  35.7k|    *out = ret;
  179|  35.7k|  }
  180|  35.7k|  *inp += len;  // All bytes were consumed.
  181|  35.7k|  return ret;
  182|  35.7k|}
ASN1_OBJECT_new:
  184|  58.5k|ASN1_OBJECT *ASN1_OBJECT_new(void) {
  185|  58.5k|  ASN1_OBJECT *ret;
  186|       |
  187|  58.5k|  ret = (ASN1_OBJECT *)OPENSSL_malloc(sizeof(ASN1_OBJECT));
  188|  58.5k|  if (ret == NULL) {
  ------------------
  |  Branch (188:7): [True: 0, False: 58.5k]
  ------------------
  189|      0|    return NULL;
  190|      0|  }
  191|  58.5k|  ret->length = 0;
  192|  58.5k|  ret->data = NULL;
  193|  58.5k|  ret->nid = 0;
  194|  58.5k|  ret->sn = NULL;
  195|  58.5k|  ret->ln = NULL;
  196|  58.5k|  ret->flags = ASN1_OBJECT_FLAG_DYNAMIC;
  ------------------
  |  |  105|  58.5k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  197|  58.5k|  return ret;
  198|  58.5k|}
ASN1_OBJECT_free:
  200|  97.3k|void ASN1_OBJECT_free(ASN1_OBJECT *a) {
  201|  97.3k|  if (a == NULL) {
  ------------------
  |  Branch (201:7): [True: 794, False: 96.5k]
  ------------------
  202|    794|    return;
  203|    794|  }
  204|  96.5k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC_STRINGS) {
  ------------------
  |  |  106|  96.5k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  |  Branch (204:7): [True: 58.5k, False: 38.0k]
  ------------------
  205|  58.5k|    OPENSSL_free((void *)a->sn);
  206|  58.5k|    OPENSSL_free((void *)a->ln);
  207|  58.5k|    a->sn = a->ln = NULL;
  208|  58.5k|  }
  209|  96.5k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC_DATA) {
  ------------------
  |  |  107|  96.5k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  |  Branch (209:7): [True: 58.5k, False: 38.0k]
  ------------------
  210|  58.5k|    OPENSSL_free((void *)a->data);
  211|  58.5k|    a->data = NULL;
  212|  58.5k|    a->length = 0;
  213|  58.5k|  }
  214|  96.5k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC) {
  ------------------
  |  |  105|  96.5k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  |  Branch (214:7): [True: 58.5k, False: 38.0k]
  ------------------
  215|  58.5k|    OPENSSL_free(a);
  216|  58.5k|  }
  217|  96.5k|}
ASN1_OBJECT_create:
  220|  35.7k|                                const char *sn, const char *ln) {
  221|  35.7k|  if (len > INT_MAX) {
  ------------------
  |  Branch (221:7): [True: 0, False: 35.7k]
  ------------------
  222|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  223|      0|    return NULL;
  224|      0|  }
  225|       |
  226|  35.7k|  ASN1_OBJECT o;
  227|  35.7k|  o.sn = sn;
  228|  35.7k|  o.ln = ln;
  229|  35.7k|  o.data = data;
  230|  35.7k|  o.nid = nid;
  231|  35.7k|  o.length = (int)len;
  232|  35.7k|  o.flags = ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  105|  35.7k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
                o.flags = ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  106|  35.7k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  233|  35.7k|            ASN1_OBJECT_FLAG_DYNAMIC_DATA;
  ------------------
  |  |  107|  35.7k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  234|  35.7k|  return OBJ_dup(&o);
  235|  35.7k|}

ASN1_STRING_to_UTF8:
  376|  1.90k|int ASN1_STRING_to_UTF8(unsigned char **out, const ASN1_STRING *in) {
  377|  1.90k|  if (!in) {
  ------------------
  |  Branch (377:7): [True: 0, False: 1.90k]
  ------------------
  378|      0|    return -1;
  379|      0|  }
  380|  1.90k|  int mbflag = string_type_to_encoding(in->type);
  381|  1.90k|  if (mbflag == -1) {
  ------------------
  |  Branch (381:7): [True: 0, False: 1.90k]
  ------------------
  382|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNKNOWN_TAG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  383|      0|    return -1;
  384|      0|  }
  385|  1.90k|  ASN1_STRING stmp, *str = &stmp;
  386|  1.90k|  stmp.data = NULL;
  387|  1.90k|  stmp.length = 0;
  388|  1.90k|  stmp.flags = 0;
  389|  1.90k|  int ret =
  390|  1.90k|      ASN1_mbstring_copy(&str, in->data, in->length, mbflag, B_ASN1_UTF8STRING);
  ------------------
  |  |  175|  1.90k|#define B_ASN1_UTF8STRING 0x2000
  ------------------
  391|  1.90k|  if (ret < 0) {
  ------------------
  |  Branch (391:7): [True: 38, False: 1.86k]
  ------------------
  392|     38|    return ret;
  393|     38|  }
  394|  1.86k|  *out = stmp.data;
  395|  1.86k|  return stmp.length;
  396|  1.90k|}
a_strex.c:string_type_to_encoding:
  273|  1.90k|static int string_type_to_encoding(int type) {
  274|       |  // This function is sometimes passed ASN.1 universal types and sometimes
  275|       |  // passed |ASN1_STRING| type values
  276|  1.90k|  switch (type) {
  ------------------
  |  Branch (276:11): [True: 0, False: 1.90k]
  ------------------
  277|    457|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|    457|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (277:5): [True: 457, False: 1.44k]
  ------------------
  278|    457|      return MBSTRING_UTF8;
  ------------------
  |  |  711|    457|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|    457|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  279|      0|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|      0|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (279:5): [True: 0, False: 1.90k]
  ------------------
  280|    165|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|    165|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (280:5): [True: 165, False: 1.73k]
  ------------------
  281|    306|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|    306|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (281:5): [True: 141, False: 1.75k]
  ------------------
  282|    758|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|    758|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (282:5): [True: 452, False: 1.44k]
  ------------------
  283|    758|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|    758|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (283:5): [True: 0, False: 1.90k]
  ------------------
  284|    758|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|    758|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (284:5): [True: 0, False: 1.90k]
  ------------------
  285|    758|    case V_ASN1_ISO64STRING:
  ------------------
  |  |  147|    758|#define V_ASN1_ISO64STRING 26
  ------------------
  |  Branch (285:5): [True: 0, False: 1.90k]
  ------------------
  286|       |      // |MBSTRING_ASC| refers to Latin-1, not ASCII.
  287|    758|      return MBSTRING_ASC;
  ------------------
  |  |  712|    758|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|    758|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  288|    320|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|    320|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (288:5): [True: 320, False: 1.58k]
  ------------------
  289|    320|      return MBSTRING_UNIV;
  ------------------
  |  |  714|    320|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|    320|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  290|    365|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|    365|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (290:5): [True: 365, False: 1.53k]
  ------------------
  291|    365|      return MBSTRING_BMP;
  ------------------
  |  |  713|    365|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|    365|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  292|  1.90k|  }
  293|      0|  return -1;
  294|  1.90k|}

asn1_type_cleanup:
   92|  5.61k|void asn1_type_cleanup(ASN1_TYPE *a) {
   93|  5.61k|  switch (a->type) {
   94|    435|    case V_ASN1_NULL:
  ------------------
  |  |  129|    435|#define V_ASN1_NULL 5
  ------------------
  |  Branch (94:5): [True: 435, False: 5.18k]
  ------------------
   95|    435|      a->value.ptr = NULL;
   96|    435|      break;
   97|     38|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|     38|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (97:5): [True: 38, False: 5.57k]
  ------------------
   98|     38|      a->value.boolean = ASN1_BOOLEAN_NONE;
  ------------------
  |  |  432|     38|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
   99|     38|      break;
  100|    768|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|    768|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (100:5): [True: 768, False: 4.84k]
  ------------------
  101|    768|      ASN1_OBJECT_free(a->value.object);
  102|    768|      a->value.object = NULL;
  103|    768|      break;
  104|  4.37k|    default:
  ------------------
  |  Branch (104:5): [True: 4.37k, False: 1.24k]
  ------------------
  105|  4.37k|      ASN1_STRING_free(a->value.asn1_string);
  106|  4.37k|      a->value.asn1_string = NULL;
  107|  4.37k|      break;
  108|  5.61k|  }
  109|  5.61k|}
ASN1_TYPE_set:
  111|  2.80k|void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value) {
  112|  2.80k|  asn1_type_cleanup(a);
  113|  2.80k|  a->type = type;
  114|  2.80k|  switch (type) {
  115|    435|    case V_ASN1_NULL:
  ------------------
  |  |  129|    435|#define V_ASN1_NULL 5
  ------------------
  |  Branch (115:5): [True: 435, False: 2.37k]
  ------------------
  116|    435|      a->value.ptr = NULL;
  117|    435|      break;
  118|     38|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|     38|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (118:5): [True: 38, False: 2.77k]
  ------------------
  119|     38|      a->value.boolean = value ? ASN1_BOOLEAN_TRUE : ASN1_BOOLEAN_FALSE;
  ------------------
  |  |  427|      0|#define ASN1_BOOLEAN_TRUE 0xff
  ------------------
                    a->value.boolean = value ? ASN1_BOOLEAN_TRUE : ASN1_BOOLEAN_FALSE;
  ------------------
  |  |  423|     76|#define ASN1_BOOLEAN_FALSE 0
  ------------------
  |  Branch (119:26): [True: 0, False: 38]
  ------------------
  120|     38|      break;
  121|    768|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|    768|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (121:5): [True: 768, False: 2.04k]
  ------------------
  122|    768|      a->value.object = value;
  123|    768|      break;
  124|  1.56k|    default:
  ------------------
  |  Branch (124:5): [True: 1.56k, False: 1.24k]
  ------------------
  125|  1.56k|      a->value.asn1_string = value;
  126|  1.56k|      break;
  127|  2.80k|  }
  128|  2.80k|}

ASN1_get_object:
  108|   227k|                    int *out_class, long in_len) {
  109|   227k|  if (in_len < 0) {
  ------------------
  |  Branch (109:7): [True: 0, False: 227k]
  ------------------
  110|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|      0|    return 0x80;
  112|      0|  }
  113|       |
  114|   227k|  CBS_ASN1_TAG tag;
  115|   227k|  CBS cbs, body;
  116|   227k|  CBS_init(&cbs, *inp, (size_t)in_len);
  117|   227k|  if (!CBS_get_any_asn1(&cbs, &body, &tag) ||
  ------------------
  |  Branch (117:7): [True: 313, False: 226k]
  ------------------
  118|       |      // Bound the length to comfortably fit in an int. Lengths in this
  119|       |      // module often switch between int and long without overflow checks.
  120|   227k|      CBS_len(&body) > INT_MAX / 2) {
  ------------------
  |  Branch (120:7): [True: 0, False: 226k]
  ------------------
  121|    313|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|    313|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  122|    313|    return 0x80;
  123|    313|  }
  124|       |
  125|       |  // Convert between tag representations.
  126|   226k|  int tag_class = (tag & CBS_ASN1_CLASS_MASK) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  207|   226k|#define CBS_ASN1_CLASS_MASK (0xc0u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|   226k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                int tag_class = (tag & CBS_ASN1_CLASS_MASK) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|   226k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  127|   226k|  int constructed = (tag & CBS_ASN1_CONSTRUCTED) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  196|   226k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|   226k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                int constructed = (tag & CBS_ASN1_CONSTRUCTED) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|   226k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  128|   226k|  int tag_number = tag & CBS_ASN1_TAG_NUMBER_MASK;
  ------------------
  |  |  210|   226k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|   226k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  129|       |
  130|       |  // To avoid ambiguity with V_ASN1_NEG, impose a limit on universal tags.
  131|   226k|  if (tag_class == V_ASN1_UNIVERSAL && tag_number > V_ASN1_MAX_UNIVERSAL) {
  ------------------
  |  |   92|   453k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
                if (tag_class == V_ASN1_UNIVERSAL && tag_number > V_ASN1_MAX_UNIVERSAL) {
  ------------------
  |  |  112|   225k|#define V_ASN1_MAX_UNIVERSAL 0xff
  ------------------
  |  Branch (131:7): [True: 225k, False: 1.01k]
  |  Branch (131:40): [True: 22, False: 225k]
  ------------------
  132|     22|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|     22|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  133|     22|    return 0x80;
  134|     22|  }
  135|       |
  136|   226k|  *inp = CBS_data(&body);
  137|   226k|  *out_len = CBS_len(&body);
  138|   226k|  *out_tag = tag_number;
  139|   226k|  *out_class = tag_class;
  140|   226k|  return constructed;
  141|   226k|}
ASN1_put_object:
  145|  74.3k|                     int xclass) {
  146|  74.3k|  unsigned char *p = *pp;
  147|  74.3k|  int i, ttag;
  148|       |
  149|  74.3k|  i = (constructed) ? V_ASN1_CONSTRUCTED : 0;
  ------------------
  |  |   99|  34.2k|#define V_ASN1_CONSTRUCTED 0x20
  ------------------
  |  Branch (149:7): [True: 34.2k, False: 40.1k]
  ------------------
  150|  74.3k|  i |= (xclass & V_ASN1_PRIVATE);
  ------------------
  |  |   95|  74.3k|#define V_ASN1_PRIVATE 0xc0
  ------------------
  151|  74.3k|  if (tag < 31) {
  ------------------
  |  Branch (151:7): [True: 74.3k, False: 0]
  ------------------
  152|  74.3k|    *(p++) = i | (tag & V_ASN1_PRIMITIVE_TAG);
  ------------------
  |  |  106|  74.3k|#define V_ASN1_PRIMITIVE_TAG 0x1f
  ------------------
  153|  74.3k|  } else {
  154|      0|    *(p++) = i | V_ASN1_PRIMITIVE_TAG;
  ------------------
  |  |  106|      0|#define V_ASN1_PRIMITIVE_TAG 0x1f
  ------------------
  155|      0|    for (i = 0, ttag = tag; ttag > 0; i++) {
  ------------------
  |  Branch (155:29): [True: 0, False: 0]
  ------------------
  156|      0|      ttag >>= 7;
  157|      0|    }
  158|      0|    ttag = i;
  159|      0|    while (i-- > 0) {
  ------------------
  |  Branch (159:12): [True: 0, False: 0]
  ------------------
  160|      0|      p[i] = tag & 0x7f;
  161|      0|      if (i != (ttag - 1)) {
  ------------------
  |  Branch (161:11): [True: 0, False: 0]
  ------------------
  162|      0|        p[i] |= 0x80;
  163|      0|      }
  164|      0|      tag >>= 7;
  165|      0|    }
  166|      0|    p += ttag;
  167|      0|  }
  168|  74.3k|  if (constructed == 2) {
  ------------------
  |  Branch (168:7): [True: 0, False: 74.3k]
  ------------------
  169|      0|    *(p++) = 0x80;
  170|  74.3k|  } else {
  171|  74.3k|    asn1_put_length(&p, length);
  172|  74.3k|  }
  173|  74.3k|  *pp = p;
  174|  74.3k|}
ASN1_object_size:
  207|   243k|int ASN1_object_size(int constructed, int length, int tag) {
  208|   243k|  int ret = 1;
  209|   243k|  if (length < 0) {
  ------------------
  |  Branch (209:7): [True: 0, False: 243k]
  ------------------
  210|      0|    return -1;
  211|      0|  }
  212|   243k|  if (tag >= 31) {
  ------------------
  |  Branch (212:7): [True: 0, False: 243k]
  ------------------
  213|      0|    while (tag > 0) {
  ------------------
  |  Branch (213:12): [True: 0, False: 0]
  ------------------
  214|      0|      tag >>= 7;
  215|      0|      ret++;
  216|      0|    }
  217|      0|  }
  218|   243k|  if (constructed == 2) {
  ------------------
  |  Branch (218:7): [True: 0, False: 243k]
  ------------------
  219|      0|    ret += 3;
  220|   243k|  } else {
  221|   243k|    ret++;
  222|   243k|    if (length > 127) {
  ------------------
  |  Branch (222:9): [True: 8.30k, False: 235k]
  ------------------
  223|  8.30k|      int tmplen = length;
  224|  24.2k|      while (tmplen > 0) {
  ------------------
  |  Branch (224:14): [True: 15.9k, False: 8.30k]
  ------------------
  225|  15.9k|        tmplen >>= 8;
  226|  15.9k|        ret++;
  227|  15.9k|      }
  228|  8.30k|    }
  229|   243k|  }
  230|   243k|  if (ret >= INT_MAX - length) {
  ------------------
  |  Branch (230:7): [True: 0, False: 243k]
  ------------------
  231|      0|    return -1;
  232|      0|  }
  233|   243k|  return ret + length;
  234|   243k|}
ASN1_STRING_copy:
  236|  20.9k|int ASN1_STRING_copy(ASN1_STRING *dst, const ASN1_STRING *str) {
  237|  20.9k|  if (str == NULL) {
  ------------------
  |  Branch (237:7): [True: 0, False: 20.9k]
  ------------------
  238|      0|    return 0;
  239|      0|  }
  240|  20.9k|  if (!ASN1_STRING_set(dst, str->data, str->length)) {
  ------------------
  |  Branch (240:7): [True: 0, False: 20.9k]
  ------------------
  241|      0|    return 0;
  242|      0|  }
  243|  20.9k|  dst->type = str->type;
  244|  20.9k|  dst->flags = str->flags;
  245|  20.9k|  return 1;
  246|  20.9k|}
ASN1_STRING_set:
  264|  56.8k|int ASN1_STRING_set(ASN1_STRING *str, const void *_data, ossl_ssize_t len_s) {
  265|  56.8k|  const char *data = _data;
  266|  56.8k|  size_t len;
  267|  56.8k|  if (len_s < 0) {
  ------------------
  |  Branch (267:7): [True: 0, False: 56.8k]
  ------------------
  268|      0|    if (data == NULL) {
  ------------------
  |  Branch (268:9): [True: 0, False: 0]
  ------------------
  269|      0|      return 0;
  270|      0|    }
  271|      0|    len = strlen(data);
  272|  56.8k|  } else {
  273|  56.8k|    len = (size_t)len_s;
  274|  56.8k|  }
  275|       |
  276|       |  // |ASN1_STRING| cannot represent strings that exceed |int|, and we must
  277|       |  // reserve space for a trailing NUL below.
  278|  56.8k|  if (len > INT_MAX || len + 1 < len) {
  ------------------
  |  Branch (278:7): [True: 0, False: 56.8k]
  |  Branch (278:24): [True: 0, False: 56.8k]
  ------------------
  279|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  280|      0|    return 0;
  281|      0|  }
  282|       |
  283|  56.8k|  if (str->length <= (int)len || str->data == NULL) {
  ------------------
  |  Branch (283:7): [True: 56.8k, False: 0]
  |  Branch (283:34): [True: 0, False: 0]
  ------------------
  284|  56.8k|    unsigned char *c = str->data;
  285|  56.8k|    if (c == NULL) {
  ------------------
  |  Branch (285:9): [True: 56.8k, False: 0]
  ------------------
  286|  56.8k|      str->data = OPENSSL_malloc(len + 1);
  287|  56.8k|    } else {
  288|      0|      str->data = OPENSSL_realloc(c, len + 1);
  289|      0|    }
  290|       |
  291|  56.8k|    if (str->data == NULL) {
  ------------------
  |  Branch (291:9): [True: 0, False: 56.8k]
  ------------------
  292|      0|      str->data = c;
  293|      0|      return 0;
  294|      0|    }
  295|  56.8k|  }
  296|  56.8k|  str->length = (int)len;
  297|  56.8k|  if (data != NULL) {
  ------------------
  |  Branch (297:7): [True: 56.0k, False: 724]
  ------------------
  298|  56.0k|    OPENSSL_memcpy(str->data, data, len);
  299|       |    // Historically, OpenSSL would NUL-terminate most (but not all)
  300|       |    // |ASN1_STRING|s, in case anyone accidentally passed |str->data| into a
  301|       |    // function expecting a C string. We retain this behavior for compatibility,
  302|       |    // but code must not rely on this. See CVE-2021-3712.
  303|  56.0k|    str->data[len] = '\0';
  304|  56.0k|  }
  305|  56.8k|  return 1;
  306|  56.8k|}
ASN1_STRING_set0:
  308|  1.40k|void ASN1_STRING_set0(ASN1_STRING *str, void *data, int len) {
  309|  1.40k|  OPENSSL_free(str->data);
  310|  1.40k|  str->data = data;
  311|  1.40k|  str->length = len;
  312|  1.40k|}
ASN1_STRING_type_new:
  318|  72.5k|ASN1_STRING *ASN1_STRING_type_new(int type) {
  319|  72.5k|  ASN1_STRING *ret;
  320|       |
  321|  72.5k|  ret = (ASN1_STRING *)OPENSSL_malloc(sizeof(ASN1_STRING));
  322|  72.5k|  if (ret == NULL) {
  ------------------
  |  Branch (322:7): [True: 0, False: 72.5k]
  ------------------
  323|      0|    return NULL;
  324|      0|  }
  325|  72.5k|  ret->length = 0;
  326|  72.5k|  ret->type = type;
  327|  72.5k|  ret->data = NULL;
  328|  72.5k|  ret->flags = 0;
  329|  72.5k|  return ret;
  330|  72.5k|}
ASN1_STRING_free:
  332|   108k|void ASN1_STRING_free(ASN1_STRING *str) {
  333|   108k|  if (str == NULL) {
  ------------------
  |  Branch (333:7): [True: 36.0k, False: 72.5k]
  ------------------
  334|  36.0k|    return;
  335|  36.0k|  }
  336|  72.5k|  OPENSSL_free(str->data);
  337|  72.5k|  OPENSSL_free(str);
  338|  72.5k|}
asn1_lib.c:asn1_put_length:
  186|  74.3k|static void asn1_put_length(unsigned char **pp, int length) {
  187|  74.3k|  unsigned char *p = *pp;
  188|  74.3k|  int i, l;
  189|  74.3k|  if (length <= 127) {
  ------------------
  |  Branch (189:7): [True: 71.3k, False: 2.91k]
  ------------------
  190|  71.3k|    *(p++) = (unsigned char)length;
  191|  71.3k|  } else {
  192|  2.91k|    l = length;
  193|  8.58k|    for (i = 0; l > 0; i++) {
  ------------------
  |  Branch (193:17): [True: 5.66k, False: 2.91k]
  ------------------
  194|  5.66k|      l >>= 8;
  195|  5.66k|    }
  196|  2.91k|    *(p++) = i | 0x80;
  197|  2.91k|    l = i;
  198|  8.58k|    while (i-- > 0) {
  ------------------
  |  Branch (198:12): [True: 5.66k, False: 2.91k]
  ------------------
  199|  5.66k|      p[i] = length & 0xff;
  200|  5.66k|      length >>= 8;
  201|  5.66k|    }
  202|  2.91k|    p += l;
  203|  2.91k|  }
  204|  74.3k|  *pp = p;
  205|  74.3k|}

ASN1_tag2bit:
  132|  53.0k|unsigned long ASN1_tag2bit(int tag) {
  133|  53.0k|  if (tag < 0 || tag > 30) {
  ------------------
  |  Branch (133:7): [True: 0, False: 53.0k]
  |  Branch (133:18): [True: 3.31k, False: 49.7k]
  ------------------
  134|  3.31k|    return 0;
  135|  3.31k|  }
  136|  49.7k|  return tag2bit[tag];
  137|  53.0k|}
ASN1_item_d2i:
  164|  2.42k|                          const ASN1_ITEM *it) {
  165|  2.42k|  ASN1_VALUE *ret = NULL;
  166|  2.42k|  if (asn1_item_ex_d2i(&ret, in, len, it, /*tag=*/-1, /*aclass=*/0, /*opt=*/0,
  ------------------
  |  Branch (166:7): [True: 57, False: 2.36k]
  ------------------
  167|       |                       /*buf=*/NULL, /*depth=*/0) <= 0) {
  168|       |    // Clean up, in case the caller left a partial object.
  169|       |    //
  170|       |    // TODO(davidben): I don't think it can leave one, but the codepaths below
  171|       |    // are a bit inconsistent. Revisit this when rewriting this function.
  172|     57|    ASN1_item_ex_free(&ret, it);
  173|     57|  }
  174|       |
  175|       |  // If the caller supplied an output pointer, free the old one and replace it
  176|       |  // with |ret|. This differs from OpenSSL slightly in that we don't support
  177|       |  // object reuse. We run this on both success and failure. On failure, even
  178|       |  // with object reuse, OpenSSL destroys the previous object.
  179|  2.42k|  if (pval != NULL) {
  ------------------
  |  Branch (179:7): [True: 0, False: 2.42k]
  ------------------
  180|      0|    ASN1_item_ex_free(pval, it);
  181|      0|    *pval = ret;
  182|      0|  }
  183|  2.42k|  return ret;
  184|  2.42k|}
ASN1_item_ex_d2i:
  493|  11.7k|                     CRYPTO_BUFFER *buf) {
  494|  11.7k|  return asn1_item_ex_d2i(pval, in, len, it, tag, aclass, opt, buf,
  495|  11.7k|                          /*depth=*/0);
  496|  11.7k|}
tasn_dec.c:asn1_item_ex_d2i:
  197|   195k|                            char opt, CRYPTO_BUFFER *buf, int depth) {
  198|   195k|  const ASN1_TEMPLATE *tt, *errtt = NULL;
  199|   195k|  const unsigned char *p = NULL, *q;
  200|   195k|  unsigned char oclass;
  201|   195k|  char cst, isopt;
  202|   195k|  int i;
  203|   195k|  int otag;
  204|   195k|  int ret = 0;
  205|   195k|  ASN1_VALUE **pchptr;
  206|   195k|  if (!pval) {
  ------------------
  |  Branch (206:7): [True: 0, False: 195k]
  ------------------
  207|      0|    return 0;
  208|      0|  }
  209|       |
  210|   195k|  if (buf != NULL) {
  ------------------
  |  Branch (210:7): [True: 0, False: 195k]
  ------------------
  211|      0|    assert(CRYPTO_BUFFER_data(buf) <= *in &&
  212|      0|           *in + len <= CRYPTO_BUFFER_data(buf) + CRYPTO_BUFFER_len(buf));
  213|      0|  }
  214|       |
  215|       |  // Bound |len| to comfortably fit in an int. Lengths in this module often
  216|       |  // switch between int and long without overflow checks.
  217|   195k|  if (len > INT_MAX / 2) {
  ------------------
  |  Branch (217:7): [True: 0, False: 195k]
  ------------------
  218|      0|    len = INT_MAX / 2;
  219|      0|  }
  220|       |
  221|   195k|  if (++depth > ASN1_MAX_CONSTRUCTED_NEST) {
  ------------------
  |  |   76|   195k|#define ASN1_MAX_CONSTRUCTED_NEST 30
  ------------------
  |  Branch (221:7): [True: 0, False: 195k]
  ------------------
  222|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_TOO_DEEP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  223|      0|    goto err;
  224|      0|  }
  225|       |
  226|   195k|  switch (it->itype) {
  227|   113k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   113k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (227:5): [True: 113k, False: 82.2k]
  ------------------
  228|   113k|      if (it->templates) {
  ------------------
  |  Branch (228:11): [True: 66.7k, False: 46.3k]
  ------------------
  229|       |        // tagging or OPTIONAL is currently illegal on an item template
  230|       |        // because the flags can't get passed down. In practice this
  231|       |        // isn't a problem: we include the relevant flags from the item
  232|       |        // template in the template itself.
  233|  66.7k|        if ((tag != -1) || opt) {
  ------------------
  |  Branch (233:13): [True: 0, False: 66.7k]
  |  Branch (233:28): [True: 0, False: 66.7k]
  ------------------
  234|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OPTIONS_ON_ITEM_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  235|      0|          goto err;
  236|      0|        }
  237|  66.7k|        return asn1_template_ex_d2i(pval, in, len, it->templates, opt, buf,
  238|  66.7k|                                    depth);
  239|  66.7k|      }
  240|  46.3k|      return asn1_d2i_ex_primitive(pval, in, len, it, tag, aclass, opt);
  241|      0|      break;
  242|       |
  243|  30.2k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  30.2k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (243:5): [True: 30.2k, False: 165k]
  ------------------
  244|       |      // It never makes sense for multi-strings to have implicit tagging, so
  245|       |      // if tag != -1, then this looks like an error in the template.
  246|  30.2k|      if (tag != -1) {
  ------------------
  |  Branch (246:11): [True: 0, False: 30.2k]
  ------------------
  247|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  248|      0|        goto err;
  249|      0|      }
  250|       |
  251|  30.2k|      p = *in;
  252|       |      // Just read in tag and class
  253|  30.2k|      ret = asn1_check_tlen(NULL, &otag, &oclass, NULL, &p, len, -1, 0, 1);
  254|  30.2k|      if (!ret) {
  ------------------
  |  Branch (254:11): [True: 8, False: 30.2k]
  ------------------
  255|      8|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      8|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  256|      8|        goto err;
  257|      8|      }
  258|       |
  259|       |      // Must be UNIVERSAL class
  260|  30.2k|      if (oclass != V_ASN1_UNIVERSAL) {
  ------------------
  |  |   92|  30.2k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (260:11): [True: 1, False: 30.2k]
  ------------------
  261|       |        // If OPTIONAL, assume this is OK
  262|      1|        if (opt) {
  ------------------
  |  Branch (262:13): [True: 0, False: 1]
  ------------------
  263|      0|          return -1;
  264|      0|        }
  265|      1|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_MSTRING_NOT_UNIVERSAL);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      1|        goto err;
  267|      1|      }
  268|       |      // Check tag matches bit map
  269|  30.2k|      if (!(ASN1_tag2bit(otag) & it->utype)) {
  ------------------
  |  Branch (269:11): [True: 9, False: 30.2k]
  ------------------
  270|       |        // If OPTIONAL, assume this is OK
  271|      9|        if (opt) {
  ------------------
  |  Branch (271:13): [True: 0, False: 9]
  ------------------
  272|      0|          return -1;
  273|      0|        }
  274|      9|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_MSTRING_WRONG_TAG);
  ------------------
  |  |  441|      9|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  275|      9|        goto err;
  276|      9|      }
  277|  30.2k|      return asn1_d2i_ex_primitive(pval, in, len, it, otag, 0, 0);
  278|       |
  279|  6.59k|    case ASN1_ITYPE_EXTERN: {
  ------------------
  |  |  493|  6.59k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (279:5): [True: 6.59k, False: 188k]
  ------------------
  280|       |      // We don't support implicit tagging with external types.
  281|  6.59k|      if (tag != -1) {
  ------------------
  |  Branch (281:11): [True: 0, False: 6.59k]
  ------------------
  282|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|        goto err;
  284|      0|      }
  285|  6.59k|      const ASN1_EXTERN_FUNCS *ef = it->funcs;
  286|  6.59k|      return ef->asn1_ex_d2i(pval, in, len, it, opt, NULL);
  287|  6.59k|    }
  288|       |
  289|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (289:5): [True: 0, False: 195k]
  ------------------
  290|       |      // It never makes sense for CHOICE types to have implicit tagging, so if
  291|       |      // tag != -1, then this looks like an error in the template.
  292|      0|      if (tag != -1) {
  ------------------
  |  Branch (292:11): [True: 0, False: 0]
  ------------------
  293|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  294|      0|        goto err;
  295|      0|      }
  296|       |
  297|      0|      const ASN1_AUX *aux = it->funcs;
  298|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (298:30): [True: 0, False: 0]
  ------------------
  299|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_PRE, pval, it, NULL)) {
  ------------------
  |  |  541|      0|#define ASN1_OP_D2I_PRE		4
  ------------------
  |  Branch (299:11): [True: 0, False: 0]
  |  Branch (299:22): [True: 0, False: 0]
  ------------------
  300|      0|        goto auxerr;
  301|      0|      }
  302|       |
  303|      0|      if (*pval) {
  ------------------
  |  Branch (303:11): [True: 0, False: 0]
  ------------------
  304|       |        // Free up and zero CHOICE value if initialised
  305|      0|        i = asn1_get_choice_selector(pval, it);
  306|      0|        if ((i >= 0) && (i < it->tcount)) {
  ------------------
  |  Branch (306:13): [True: 0, False: 0]
  |  Branch (306:25): [True: 0, False: 0]
  ------------------
  307|      0|          tt = it->templates + i;
  308|      0|          pchptr = asn1_get_field_ptr(pval, tt);
  309|      0|          ASN1_template_free(pchptr, tt);
  310|      0|          asn1_set_choice_selector(pval, -1, it);
  311|      0|        }
  312|      0|      } else if (!ASN1_item_ex_new(pval, it)) {
  ------------------
  |  Branch (312:18): [True: 0, False: 0]
  ------------------
  313|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  314|      0|        goto err;
  315|      0|      }
  316|       |      // CHOICE type, try each possibility in turn
  317|      0|      p = *in;
  318|      0|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (318:39): [True: 0, False: 0]
  ------------------
  319|      0|        pchptr = asn1_get_field_ptr(pval, tt);
  320|       |        // We mark field as OPTIONAL so its absence can be recognised.
  321|      0|        ret = asn1_template_ex_d2i(pchptr, &p, len, tt, 1, buf, depth);
  322|       |        // If field not present, try the next one
  323|      0|        if (ret == -1) {
  ------------------
  |  Branch (323:13): [True: 0, False: 0]
  ------------------
  324|      0|          continue;
  325|      0|        }
  326|       |        // If positive return, read OK, break loop
  327|      0|        if (ret > 0) {
  ------------------
  |  Branch (327:13): [True: 0, False: 0]
  ------------------
  328|      0|          break;
  329|      0|        }
  330|       |        // Otherwise must be an ASN1 parsing error
  331|      0|        errtt = tt;
  332|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  333|      0|        goto err;
  334|      0|      }
  335|       |
  336|       |      // Did we fall off the end without reading anything?
  337|      0|      if (i == it->tcount) {
  ------------------
  |  Branch (337:11): [True: 0, False: 0]
  ------------------
  338|       |        // If OPTIONAL, this is OK
  339|      0|        if (opt) {
  ------------------
  |  Branch (339:13): [True: 0, False: 0]
  ------------------
  340|       |          // Free and zero it
  341|      0|          ASN1_item_ex_free(pval, it);
  342|      0|          return -1;
  343|      0|        }
  344|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NO_MATCHING_CHOICE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|        goto err;
  346|      0|      }
  347|       |
  348|      0|      asn1_set_choice_selector(pval, i, it);
  349|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_POST, pval, it, NULL)) {
  ------------------
  |  |  542|      0|#define ASN1_OP_D2I_POST	5
  ------------------
  |  Branch (349:11): [True: 0, False: 0]
  |  Branch (349:22): [True: 0, False: 0]
  ------------------
  350|      0|        goto auxerr;
  351|      0|      }
  352|      0|      *in = p;
  353|      0|      return 1;
  354|      0|    }
  355|       |
  356|  45.4k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  45.4k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (356:5): [True: 45.4k, False: 149k]
  ------------------
  357|  45.4k|      p = *in;
  358|       |
  359|       |      // If no IMPLICIT tagging set to SEQUENCE, UNIVERSAL
  360|  45.4k|      if (tag == -1) {
  ------------------
  |  Branch (360:11): [True: 45.4k, False: 0]
  ------------------
  361|  45.4k|        tag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|  45.4k|#define V_ASN1_SEQUENCE 16
  ------------------
  362|  45.4k|        aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  45.4k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  363|  45.4k|      }
  364|       |      // Get SEQUENCE length and update len, p
  365|  45.4k|      ret = asn1_check_tlen(&len, NULL, NULL, &cst, &p, len, tag, aclass, opt);
  366|  45.4k|      if (!ret) {
  ------------------
  |  Branch (366:11): [True: 146, False: 45.3k]
  ------------------
  367|    146|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    146|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  368|    146|        goto err;
  369|  45.3k|      } else if (ret == -1) {
  ------------------
  |  Branch (369:18): [True: 0, False: 45.3k]
  ------------------
  370|      0|        return -1;
  371|      0|      }
  372|  45.3k|      if (!cst) {
  ------------------
  |  Branch (372:11): [True: 1, False: 45.3k]
  ------------------
  373|      1|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_SEQUENCE_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  374|      1|        goto err;
  375|      1|      }
  376|       |
  377|  45.3k|      if (!*pval && !ASN1_item_ex_new(pval, it)) {
  ------------------
  |  Branch (377:11): [True: 32.9k, False: 12.4k]
  |  Branch (377:21): [True: 0, False: 32.9k]
  ------------------
  378|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  379|      0|        goto err;
  380|      0|      }
  381|       |
  382|  45.3k|      const ASN1_AUX *aux = it->funcs;
  383|  45.3k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (383:30): [True: 7.59k, False: 37.7k]
  ------------------
  384|  45.3k|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_PRE, pval, it, NULL)) {
  ------------------
  |  |  541|  2.47k|#define ASN1_OP_D2I_PRE		4
  ------------------
  |  Branch (384:11): [True: 2.47k, False: 42.8k]
  |  Branch (384:22): [True: 0, False: 2.47k]
  ------------------
  385|      0|        goto auxerr;
  386|      0|      }
  387|       |
  388|       |      // Free up and zero any ADB found
  389|   177k|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (389:39): [True: 131k, False: 45.3k]
  ------------------
  390|   131k|        if (tt->flags & ASN1_TFLG_ADB_MASK) {
  ------------------
  |  |  435|   131k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (390:13): [True: 0, False: 131k]
  ------------------
  391|      0|          const ASN1_TEMPLATE *seqtt;
  392|      0|          ASN1_VALUE **pseqval;
  393|      0|          seqtt = asn1_do_adb(pval, tt, 0);
  394|      0|          if (seqtt == NULL) {
  ------------------
  |  Branch (394:15): [True: 0, False: 0]
  ------------------
  395|      0|            continue;
  396|      0|          }
  397|      0|          pseqval = asn1_get_field_ptr(pval, seqtt);
  398|      0|          ASN1_template_free(pseqval, seqtt);
  399|      0|        }
  400|   131k|      }
  401|       |
  402|       |      // Get each field entry
  403|   143k|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (403:39): [True: 111k, False: 32.6k]
  ------------------
  404|   111k|        const ASN1_TEMPLATE *seqtt;
  405|   111k|        ASN1_VALUE **pseqval;
  406|   111k|        seqtt = asn1_do_adb(pval, tt, 1);
  407|   111k|        if (seqtt == NULL) {
  ------------------
  |  Branch (407:13): [True: 0, False: 111k]
  ------------------
  408|      0|          goto err;
  409|      0|        }
  410|   111k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  411|       |        // Have we ran out of data?
  412|   111k|        if (!len) {
  ------------------
  |  Branch (412:13): [True: 10.5k, False: 100k]
  ------------------
  413|  10.5k|          break;
  414|  10.5k|        }
  415|   100k|        q = p;
  416|       |        // This determines the OPTIONAL flag value. The field cannot be
  417|       |        // omitted if it is the last of a SEQUENCE and there is still
  418|       |        // data to be read. This isn't strictly necessary but it
  419|       |        // increases efficiency in some cases.
  420|   100k|        if (i == (it->tcount - 1)) {
  ------------------
  |  Branch (420:13): [True: 33.1k, False: 67.4k]
  ------------------
  421|  33.1k|          isopt = 0;
  422|  67.4k|        } else {
  423|  67.4k|          isopt = (seqtt->flags & ASN1_TFLG_OPTIONAL) != 0;
  ------------------
  |  |  381|  67.4k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  424|  67.4k|        }
  425|       |        // attempt to read in field, allowing each to be OPTIONAL
  426|       |
  427|   100k|        ret = asn1_template_ex_d2i(pseqval, &p, len, seqtt, isopt, buf, depth);
  428|   100k|        if (!ret) {
  ------------------
  |  Branch (428:13): [True: 2.15k, False: 98.4k]
  ------------------
  429|  2.15k|          errtt = seqtt;
  430|  2.15k|          goto err;
  431|  98.4k|        } else if (ret == -1) {
  ------------------
  |  Branch (431:20): [True: 5.19k, False: 93.2k]
  ------------------
  432|       |          // OPTIONAL component absent. Free and zero the field.
  433|  5.19k|          ASN1_template_free(pseqval, seqtt);
  434|  5.19k|          continue;
  435|  5.19k|        }
  436|       |        // Update length
  437|  93.2k|        len -= p - q;
  438|  93.2k|      }
  439|       |
  440|       |      // Check all data read
  441|  43.1k|      if (len) {
  ------------------
  |  Branch (441:11): [True: 110, False: 43.0k]
  ------------------
  442|    110|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_SEQUENCE_LENGTH_MISMATCH);
  ------------------
  |  |  441|    110|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  443|    110|        goto err;
  444|    110|      }
  445|       |
  446|       |      // If we get here we've got no more data in the SEQUENCE, however we
  447|       |      // may not have read all fields so check all remaining are OPTIONAL
  448|       |      // and clear any that are.
  449|  57.0k|      for (; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (449:14): [True: 15.3k, False: 41.7k]
  ------------------
  450|  15.3k|        const ASN1_TEMPLATE *seqtt;
  451|  15.3k|        seqtt = asn1_do_adb(pval, tt, 1);
  452|  15.3k|        if (seqtt == NULL) {
  ------------------
  |  Branch (452:13): [True: 0, False: 15.3k]
  ------------------
  453|      0|          goto err;
  454|      0|        }
  455|  15.3k|        if (seqtt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|  15.3k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (455:13): [True: 13.9k, False: 1.33k]
  ------------------
  456|  13.9k|          ASN1_VALUE **pseqval;
  457|  13.9k|          pseqval = asn1_get_field_ptr(pval, seqtt);
  458|  13.9k|          ASN1_template_free(pseqval, seqtt);
  459|  13.9k|        } else {
  460|  1.33k|          errtt = seqtt;
  461|  1.33k|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_FIELD_MISSING);
  ------------------
  |  |  441|  1.33k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  462|  1.33k|          goto err;
  463|  1.33k|        }
  464|  15.3k|      }
  465|       |      // Save encoding
  466|  41.7k|      if (!asn1_enc_save(pval, *in, p - *in, it, buf)) {
  ------------------
  |  Branch (466:11): [True: 0, False: 41.7k]
  ------------------
  467|      0|        goto auxerr;
  468|      0|      }
  469|  41.7k|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_POST, pval, it, NULL)) {
  ------------------
  |  |  542|  2.44k|#define ASN1_OP_D2I_POST	5
  ------------------
  |  Branch (469:11): [True: 2.44k, False: 39.2k]
  |  Branch (469:22): [True: 0, False: 2.44k]
  ------------------
  470|      0|        goto auxerr;
  471|      0|      }
  472|  41.7k|      *in = p;
  473|  41.7k|      return 1;
  474|  41.7k|    }
  475|       |
  476|      0|    default:
  ------------------
  |  Branch (476:5): [True: 0, False: 195k]
  ------------------
  477|      0|      return 0;
  478|   195k|  }
  479|      0|auxerr:
  480|      0|  OPENSSL_PUT_ERROR(ASN1, ASN1_R_AUX_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  481|  3.76k|err:
  482|  3.76k|  ASN1_item_ex_free(pval, it);
  483|  3.76k|  if (errtt) {
  ------------------
  |  Branch (483:7): [True: 3.49k, False: 275]
  ------------------
  484|  3.49k|    ERR_add_error_data(4, "Field=", errtt->field_name, ", Type=", it->sname);
  485|  3.49k|  } else {
  486|    275|    ERR_add_error_data(2, "Type=", it->sname);
  487|    275|  }
  488|  3.76k|  return 0;
  489|      0|}
tasn_dec.c:asn1_template_ex_d2i:
  503|   167k|                                CRYPTO_BUFFER *buf, int depth) {
  504|   167k|  int aclass;
  505|   167k|  int ret;
  506|   167k|  long len;
  507|   167k|  const unsigned char *p, *q;
  508|   167k|  if (!val) {
  ------------------
  |  Branch (508:7): [True: 0, False: 167k]
  ------------------
  509|      0|    return 0;
  510|      0|  }
  511|   167k|  uint32_t flags = tt->flags;
  512|   167k|  aclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|   167k|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  513|       |
  514|   167k|  p = *in;
  515|       |
  516|       |  // Check if EXPLICIT tag expected
  517|   167k|  if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|   167k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (517:7): [True: 5.15k, False: 162k]
  ------------------
  518|  5.15k|    char cst;
  519|       |    // Need to work out amount of data available to the inner content and
  520|       |    // where it starts: so read in EXPLICIT header to get the info.
  521|  5.15k|    ret = asn1_check_tlen(&len, NULL, NULL, &cst, &p, inlen, tt->tag, aclass,
  522|  5.15k|                          opt);
  523|  5.15k|    q = p;
  524|  5.15k|    if (!ret) {
  ------------------
  |  Branch (524:9): [True: 26, False: 5.12k]
  ------------------
  525|     26|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     26|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  526|     26|      return 0;
  527|  5.12k|    } else if (ret == -1) {
  ------------------
  |  Branch (527:16): [True: 4.80k, False: 318]
  ------------------
  528|  4.80k|      return -1;
  529|  4.80k|    }
  530|    318|    if (!cst) {
  ------------------
  |  Branch (530:9): [True: 2, False: 316]
  ------------------
  531|      2|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_EXPLICIT_TAG_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  532|      2|      return 0;
  533|      2|    }
  534|       |    // We've found the field so it can't be OPTIONAL now
  535|    316|    ret = asn1_template_noexp_d2i(val, &p, len, tt, /*opt=*/0, buf, depth);
  536|    316|    if (!ret) {
  ------------------
  |  Branch (536:9): [True: 16, False: 300]
  ------------------
  537|     16|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     16|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  538|     16|      return 0;
  539|     16|    }
  540|       |    // We read the field in OK so update length
  541|    300|    len -= p - q;
  542|       |    // Check for trailing data.
  543|    300|    if (len) {
  ------------------
  |  Branch (543:9): [True: 31, False: 269]
  ------------------
  544|     31|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_EXPLICIT_LENGTH_MISMATCH);
  ------------------
  |  |  441|     31|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  545|     31|      goto err;
  546|     31|    }
  547|   162k|  } else {
  548|   162k|    return asn1_template_noexp_d2i(val, in, inlen, tt, opt, buf, depth);
  549|   162k|  }
  550|       |
  551|    269|  *in = p;
  552|    269|  return 1;
  553|       |
  554|     31|err:
  555|     31|  ASN1_template_free(val, tt);
  556|     31|  return 0;
  557|   167k|}
tasn_dec.c:asn1_template_noexp_d2i:
  561|   162k|                                   CRYPTO_BUFFER *buf, int depth) {
  562|   162k|  int aclass;
  563|   162k|  int ret;
  564|   162k|  const unsigned char *p;
  565|   162k|  if (!val) {
  ------------------
  |  Branch (565:7): [True: 0, False: 162k]
  ------------------
  566|      0|    return 0;
  567|      0|  }
  568|   162k|  uint32_t flags = tt->flags;
  569|   162k|  aclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|   162k|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  570|       |
  571|   162k|  p = *in;
  572|       |
  573|   162k|  if (flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   162k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (573:7): [True: 66.7k, False: 95.7k]
  ------------------
  574|       |    // SET OF, SEQUENCE OF
  575|  66.7k|    int sktag, skaclass;
  576|       |    // First work out expected inner tag value
  577|  66.7k|    if (flags & ASN1_TFLG_IMPTAG) {
  ------------------
  |  |  398|  66.7k|#define ASN1_TFLG_IMPTAG	(0x1 << 3)
  ------------------
  |  Branch (577:9): [True: 0, False: 66.7k]
  ------------------
  578|      0|      sktag = tt->tag;
  579|      0|      skaclass = aclass;
  580|  66.7k|    } else {
  581|  66.7k|      skaclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  66.7k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  582|  66.7k|      if (flags & ASN1_TFLG_SET_OF) {
  ------------------
  |  |  384|  66.7k|#define ASN1_TFLG_SET_OF	(0x1 << 1)
  ------------------
  |  Branch (582:11): [True: 60.1k, False: 6.63k]
  ------------------
  583|  60.1k|        sktag = V_ASN1_SET;
  ------------------
  |  |  137|  60.1k|#define V_ASN1_SET 17
  ------------------
  584|  60.1k|      } else {
  585|  6.63k|        sktag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|  6.63k|#define V_ASN1_SEQUENCE 16
  ------------------
  586|  6.63k|      }
  587|  66.7k|    }
  588|       |    // Get the tag
  589|  66.7k|    ret =
  590|  66.7k|        asn1_check_tlen(&len, NULL, NULL, NULL, &p, len, sktag, skaclass, opt);
  591|  66.7k|    if (!ret) {
  ------------------
  |  Branch (591:9): [True: 225, False: 66.5k]
  ------------------
  592|    225|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    225|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  593|    225|      return 0;
  594|  66.5k|    } else if (ret == -1) {
  ------------------
  |  Branch (594:16): [True: 0, False: 66.5k]
  ------------------
  595|      0|      return -1;
  596|      0|    }
  597|  66.5k|    if (!*val) {
  ------------------
  |  Branch (597:9): [True: 66.5k, False: 0]
  ------------------
  598|  66.5k|      *val = (ASN1_VALUE *)sk_ASN1_VALUE_new_null();
  599|  66.5k|    } else {
  600|       |      // We've got a valid STACK: free up any items present
  601|      0|      STACK_OF(ASN1_VALUE) *sktmp = (STACK_OF(ASN1_VALUE) *)*val;
  ------------------
  |  |   81|      0|#define STACK_OF(type) struct stack_st_##type
  ------------------
  602|      0|      ASN1_VALUE *vtmp;
  603|      0|      while (sk_ASN1_VALUE_num(sktmp) > 0) {
  ------------------
  |  Branch (603:14): [True: 0, False: 0]
  ------------------
  604|      0|        vtmp = sk_ASN1_VALUE_pop(sktmp);
  605|      0|        ASN1_item_ex_free(&vtmp, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  606|      0|      }
  607|      0|    }
  608|       |
  609|  66.5k|    if (!*val) {
  ------------------
  |  Branch (609:9): [True: 0, False: 66.5k]
  ------------------
  610|      0|      goto err;
  611|      0|    }
  612|       |
  613|       |    // Read as many items as we can
  614|   151k|    while (len > 0) {
  ------------------
  |  Branch (614:12): [True: 85.5k, False: 66.3k]
  ------------------
  615|  85.5k|      ASN1_VALUE *skfield;
  616|  85.5k|      const unsigned char *q = p;
  617|  85.5k|      skfield = NULL;
  618|  85.5k|      if (!asn1_item_ex_d2i(&skfield, &p, len, ASN1_ITEM_ptr(tt->item),
  ------------------
  |  |  288|  85.5k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (618:11): [True: 166, False: 85.3k]
  ------------------
  619|  85.5k|                            /*tag=*/-1, /*aclass=*/0, /*opt=*/0, buf, depth)) {
  620|    166|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    166|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  621|    166|        goto err;
  622|    166|      }
  623|  85.3k|      len -= p - q;
  624|  85.3k|      if (!sk_ASN1_VALUE_push((STACK_OF(ASN1_VALUE) *)*val, skfield)) {
  ------------------
  |  Branch (624:11): [True: 0, False: 85.3k]
  ------------------
  625|      0|        ASN1_item_ex_free(&skfield, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  626|      0|        goto err;
  627|      0|      }
  628|  85.3k|    }
  629|  95.7k|  } else if (flags & ASN1_TFLG_IMPTAG) {
  ------------------
  |  |  398|  95.7k|#define ASN1_TFLG_IMPTAG	(0x1 << 3)
  ------------------
  |  Branch (629:14): [True: 90, False: 95.6k]
  ------------------
  630|       |    // IMPLICIT tagging
  631|     90|    ret = asn1_item_ex_d2i(val, &p, len, ASN1_ITEM_ptr(tt->item), tt->tag,
  ------------------
  |  |  288|     90|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  632|     90|                           aclass, opt, buf, depth);
  633|     90|    if (!ret) {
  ------------------
  |  Branch (633:9): [True: 1, False: 89]
  ------------------
  634|      1|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  635|      1|      goto err;
  636|     89|    } else if (ret == -1) {
  ------------------
  |  Branch (636:16): [True: 77, False: 12]
  ------------------
  637|     77|      return -1;
  638|     77|    }
  639|  95.6k|  } else {
  640|       |    // Nothing special
  641|  95.6k|    ret = asn1_item_ex_d2i(val, &p, len, ASN1_ITEM_ptr(tt->item), /*tag=*/-1,
  ------------------
  |  |  288|  95.6k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  642|  95.6k|                           /*aclass=*/0, opt, buf, depth);
  643|  95.6k|    if (!ret) {
  ------------------
  |  Branch (643:9): [True: 2.08k, False: 93.5k]
  ------------------
  644|  2.08k|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|  2.08k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  645|  2.08k|      goto err;
  646|  93.5k|    } else if (ret == -1) {
  ------------------
  |  Branch (646:16): [True: 313, False: 93.2k]
  ------------------
  647|    313|      return -1;
  648|    313|    }
  649|  95.6k|  }
  650|       |
  651|   159k|  *in = p;
  652|   159k|  return 1;
  653|       |
  654|  2.24k|err:
  655|  2.24k|  ASN1_template_free(val, tt);
  656|  2.24k|  return 0;
  657|   162k|}
tasn_dec.c:asn1_d2i_ex_primitive:
  661|  76.5k|                                 int aclass, char opt) {
  662|  76.5k|  int ret = 0, utype;
  663|  76.5k|  long plen;
  664|  76.5k|  char cst;
  665|  76.5k|  const unsigned char *p;
  666|  76.5k|  const unsigned char *cont = NULL;
  667|  76.5k|  long len;
  668|  76.5k|  if (!pval) {
  ------------------
  |  Branch (668:7): [True: 0, False: 76.5k]
  ------------------
  669|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_NULL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  670|      0|    return 0;  // Should never happen
  671|      0|  }
  672|       |
  673|  76.5k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|  76.5k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (673:7): [True: 30.2k, False: 46.3k]
  ------------------
  674|  30.2k|    utype = tag;
  675|  30.2k|    tag = -1;
  676|  46.3k|  } else {
  677|  46.3k|    utype = it->utype;
  678|  46.3k|  }
  679|       |
  680|  76.5k|  if (utype == V_ASN1_ANY) {
  ------------------
  |  |  121|  76.5k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (680:7): [True: 2.85k, False: 73.7k]
  ------------------
  681|       |    // If type is ANY need to figure out type from tag
  682|  2.85k|    unsigned char oclass;
  683|  2.85k|    if (tag >= 0) {
  ------------------
  |  Branch (683:9): [True: 0, False: 2.85k]
  ------------------
  684|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_TAGGED_ANY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  685|      0|      return 0;
  686|      0|    }
  687|  2.85k|    if (opt) {
  ------------------
  |  Branch (687:9): [True: 0, False: 2.85k]
  ------------------
  688|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OPTIONAL_ANY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  689|      0|      return 0;
  690|      0|    }
  691|  2.85k|    p = *in;
  692|  2.85k|    ret = asn1_check_tlen(NULL, &utype, &oclass, NULL, &p, inlen, -1, 0, 0);
  693|  2.85k|    if (!ret) {
  ------------------
  |  Branch (693:9): [True: 17, False: 2.84k]
  ------------------
  694|     17|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     17|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  695|     17|      return 0;
  696|     17|    }
  697|  2.84k|    if (!is_supported_universal_type(utype, oclass)) {
  ------------------
  |  Branch (697:9): [True: 243, False: 2.59k]
  ------------------
  698|    243|      utype = V_ASN1_OTHER;
  ------------------
  |  |  118|    243|#define V_ASN1_OTHER (-3)
  ------------------
  699|    243|    }
  700|  2.84k|  }
  701|  76.5k|  if (tag == -1) {
  ------------------
  |  Branch (701:7): [True: 76.4k, False: 90]
  ------------------
  702|  76.4k|    tag = utype;
  703|  76.4k|    aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  76.4k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  704|  76.4k|  }
  705|  76.5k|  p = *in;
  706|       |  // Check header
  707|  76.5k|  ret = asn1_check_tlen(&plen, NULL, NULL, &cst, &p, inlen, tag, aclass, opt);
  708|  76.5k|  if (!ret) {
  ------------------
  |  Branch (708:7): [True: 121, False: 76.4k]
  ------------------
  709|    121|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    121|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  710|    121|    return 0;
  711|  76.4k|  } else if (ret == -1) {
  ------------------
  |  Branch (711:14): [True: 390, False: 76.0k]
  ------------------
  712|    390|    return -1;
  713|    390|  }
  714|  76.0k|  ret = 0;
  715|       |  // SEQUENCE, SET and "OTHER" are left in encoded form
  716|  76.0k|  if ((utype == V_ASN1_SEQUENCE) || (utype == V_ASN1_SET) ||
  ------------------
  |  |  136|  76.0k|#define V_ASN1_SEQUENCE 16
  ------------------
                if ((utype == V_ASN1_SEQUENCE) || (utype == V_ASN1_SET) ||
  ------------------
  |  |  137|  59.8k|#define V_ASN1_SET 17
  ------------------
  |  Branch (716:7): [True: 16.2k, False: 59.8k]
  |  Branch (716:37): [True: 12, False: 59.8k]
  ------------------
  717|  76.0k|      (utype == V_ASN1_OTHER)) {
  ------------------
  |  |  118|  59.8k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (717:7): [True: 243, False: 59.5k]
  ------------------
  718|       |    // SEQUENCE and SET must be constructed
  719|  16.4k|    if (utype != V_ASN1_OTHER && !cst) {
  ------------------
  |  |  118|  32.9k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (719:9): [True: 16.2k, False: 243]
  |  Branch (719:34): [True: 1, False: 16.2k]
  ------------------
  720|      1|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_TYPE_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  721|      1|      return 0;
  722|      1|    }
  723|       |
  724|  16.4k|    cont = *in;
  725|  16.4k|    len = p - cont + plen;
  726|  16.4k|    p += plen;
  727|  59.5k|  } else if (cst) {
  ------------------
  |  Branch (727:14): [True: 40, False: 59.5k]
  ------------------
  728|       |    // This parser historically supported BER constructed strings. We no
  729|       |    // longer do and will gradually tighten this parser into a DER
  730|       |    // parser. BER types should use |CBS_asn1_ber_to_der|.
  731|     40|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_TYPE_NOT_PRIMITIVE);
  ------------------
  |  |  441|     40|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  732|     40|    return 0;
  733|  59.5k|  } else {
  734|  59.5k|    cont = p;
  735|  59.5k|    len = plen;
  736|  59.5k|    p += plen;
  737|  59.5k|  }
  738|       |
  739|       |  // We now have content length and type: translate into a structure
  740|  75.9k|  if (!asn1_ex_c2i(pval, cont, len, utype, it)) {
  ------------------
  |  Branch (740:7): [True: 647, False: 75.3k]
  ------------------
  741|    647|    goto err;
  742|    647|  }
  743|       |
  744|  75.3k|  *in = p;
  745|  75.3k|  ret = 1;
  746|  75.9k|err:
  747|  75.9k|  return ret;
  748|  75.3k|}
tasn_dec.c:is_supported_universal_type:
  139|  2.84k|static int is_supported_universal_type(int tag, int aclass) {
  140|  2.84k|  if (aclass != V_ASN1_UNIVERSAL) {
  ------------------
  |  |   92|  2.84k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (140:7): [True: 192, False: 2.65k]
  ------------------
  141|    192|    return 0;
  142|    192|  }
  143|  2.65k|  return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  130|  5.30k|#define V_ASN1_OBJECT 6
  ------------------
                return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  129|  4.53k|#define V_ASN1_NULL 5
  ------------------
                return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  125|  4.09k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (143:10): [True: 769, False: 1.88k]
  |  Branch (143:34): [True: 435, False: 1.44k]
  |  Branch (143:56): [True: 38, False: 1.40k]
  ------------------
  144|  2.65k|         tag == V_ASN1_BIT_STRING || tag == V_ASN1_INTEGER ||
  ------------------
  |  |  127|  4.05k|#define V_ASN1_BIT_STRING 3
  ------------------
                       tag == V_ASN1_BIT_STRING || tag == V_ASN1_INTEGER ||
  ------------------
  |  |  126|  3.99k|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (144:10): [True: 59, False: 1.34k]
  |  Branch (144:38): [True: 52, False: 1.29k]
  ------------------
  145|  2.65k|         tag == V_ASN1_ENUMERATED || tag == V_ASN1_OCTET_STRING ||
  ------------------
  |  |  134|  3.94k|#define V_ASN1_ENUMERATED 10
  ------------------
                       tag == V_ASN1_ENUMERATED || tag == V_ASN1_OCTET_STRING ||
  ------------------
  |  |  128|  3.92k|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (145:10): [True: 26, False: 1.27k]
  |  Branch (145:38): [True: 7, False: 1.26k]
  ------------------
  146|  2.65k|         tag == V_ASN1_NUMERICSTRING || tag == V_ASN1_PRINTABLESTRING ||
  ------------------
  |  |  138|  3.91k|#define V_ASN1_NUMERICSTRING 18
  ------------------
                       tag == V_ASN1_NUMERICSTRING || tag == V_ASN1_PRINTABLESTRING ||
  ------------------
  |  |  139|  3.90k|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (146:10): [True: 6, False: 1.25k]
  |  Branch (146:41): [True: 7, False: 1.25k]
  ------------------
  147|  2.65k|         tag == V_ASN1_T61STRING || tag == V_ASN1_VIDEOTEXSTRING ||
  ------------------
  |  |  140|  3.90k|#define V_ASN1_T61STRING 20
  ------------------
                       tag == V_ASN1_T61STRING || tag == V_ASN1_VIDEOTEXSTRING ||
  ------------------
  |  |  142|  3.89k|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (147:10): [True: 6, False: 1.24k]
  |  Branch (147:37): [True: 7, False: 1.23k]
  ------------------
  148|  2.65k|         tag == V_ASN1_IA5STRING || tag == V_ASN1_UTCTIME ||
  ------------------
  |  |  143|  3.88k|#define V_ASN1_IA5STRING 22
  ------------------
                       tag == V_ASN1_IA5STRING || tag == V_ASN1_UTCTIME ||
  ------------------
  |  |  144|  3.87k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (148:10): [True: 9, False: 1.22k]
  |  Branch (148:37): [True: 144, False: 1.08k]
  ------------------
  149|  2.65k|         tag == V_ASN1_GENERALIZEDTIME || tag == V_ASN1_GRAPHICSTRING ||
  ------------------
  |  |  145|  3.73k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
                       tag == V_ASN1_GENERALIZEDTIME || tag == V_ASN1_GRAPHICSTRING ||
  ------------------
  |  |  146|  3.70k|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (149:10): [True: 27, False: 1.05k]
  |  Branch (149:43): [True: 7, False: 1.05k]
  ------------------
  150|  2.65k|         tag == V_ASN1_VISIBLESTRING || tag == V_ASN1_GENERALSTRING ||
  ------------------
  |  |  148|  3.70k|#define V_ASN1_VISIBLESTRING 26
  ------------------
                       tag == V_ASN1_VISIBLESTRING || tag == V_ASN1_GENERALSTRING ||
  ------------------
  |  |  149|  3.69k|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (150:10): [True: 7, False: 1.04k]
  |  Branch (150:41): [True: 8, False: 1.03k]
  ------------------
  151|  2.65k|         tag == V_ASN1_UNIVERSALSTRING || tag == V_ASN1_BMPSTRING ||
  ------------------
  |  |  150|  3.68k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
                       tag == V_ASN1_UNIVERSALSTRING || tag == V_ASN1_BMPSTRING ||
  ------------------
  |  |  151|  3.50k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (151:10): [True: 180, False: 856]
  |  Branch (151:43): [True: 98, False: 758]
  ------------------
  152|  2.65k|         tag == V_ASN1_UTF8STRING || tag == V_ASN1_SET ||
  ------------------
  |  |  135|  3.40k|#define V_ASN1_UTF8STRING 12
  ------------------
                       tag == V_ASN1_UTF8STRING || tag == V_ASN1_SET ||
  ------------------
  |  |  137|  3.22k|#define V_ASN1_SET 17
  ------------------
  |  Branch (152:10): [True: 186, False: 572]
  |  Branch (152:38): [True: 12, False: 560]
  ------------------
  153|  2.65k|         tag == V_ASN1_SEQUENCE;
  ------------------
  |  |  136|    560|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (153:10): [True: 509, False: 51]
  ------------------
  154|  2.84k|}
tasn_dec.c:asn1_ex_c2i:
  753|  75.9k|                       int utype, const ASN1_ITEM *it) {
  754|  75.9k|  ASN1_VALUE **opval = NULL;
  755|  75.9k|  ASN1_STRING *stmp;
  756|  75.9k|  ASN1_TYPE *typ = NULL;
  757|  75.9k|  int ret = 0;
  758|  75.9k|  ASN1_INTEGER **tint;
  759|       |
  760|       |  // Historically, |it->funcs| for primitive types contained an
  761|       |  // |ASN1_PRIMITIVE_FUNCS| table of callbacks.
  762|  75.9k|  assert(it->funcs == NULL);
  763|       |
  764|       |  // If ANY type clear type and set pointer to internal value
  765|  75.9k|  if (it->utype == V_ASN1_ANY) {
  ------------------
  |  |  121|  75.9k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (765:7): [True: 2.80k, False: 73.1k]
  ------------------
  766|  2.80k|    if (!*pval) {
  ------------------
  |  Branch (766:9): [True: 2.80k, False: 0]
  ------------------
  767|  2.80k|      typ = ASN1_TYPE_new();
  768|  2.80k|      if (typ == NULL) {
  ------------------
  |  Branch (768:11): [True: 0, False: 2.80k]
  ------------------
  769|      0|        goto err;
  770|      0|      }
  771|  2.80k|      *pval = (ASN1_VALUE *)typ;
  772|  2.80k|    } else {
  773|      0|      typ = (ASN1_TYPE *)*pval;
  774|      0|    }
  775|       |
  776|  2.80k|    if (utype != typ->type) {
  ------------------
  |  Branch (776:9): [True: 2.80k, False: 0]
  ------------------
  777|  2.80k|      ASN1_TYPE_set(typ, utype, NULL);
  778|  2.80k|    }
  779|  2.80k|    opval = pval;
  780|  2.80k|    pval = &typ->value.asn1_value;
  781|  2.80k|  }
  782|  75.9k|  switch (utype) {
  783|  35.7k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  35.7k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (783:5): [True: 35.7k, False: 40.2k]
  ------------------
  784|  35.7k|      if (!c2i_ASN1_OBJECT((ASN1_OBJECT **)pval, &cont, len)) {
  ------------------
  |  Branch (784:11): [True: 3, False: 35.7k]
  ------------------
  785|      3|        goto err;
  786|      3|      }
  787|  35.7k|      break;
  788|       |
  789|  35.7k|    case V_ASN1_NULL:
  ------------------
  |  |  129|    435|#define V_ASN1_NULL 5
  ------------------
  |  Branch (789:5): [True: 435, False: 75.5k]
  ------------------
  790|    435|      if (len) {
  ------------------
  |  Branch (790:11): [True: 19, False: 416]
  ------------------
  791|     19|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NULL_IS_WRONG_LENGTH);
  ------------------
  |  |  441|     19|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  792|     19|        goto err;
  793|     19|      }
  794|    416|      *pval = (ASN1_VALUE *)1;
  795|    416|      break;
  796|       |
  797|     38|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|     38|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (797:5): [True: 38, False: 75.9k]
  ------------------
  798|     38|      if (len != 1) {
  ------------------
  |  Branch (798:11): [True: 20, False: 18]
  ------------------
  799|     20|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BOOLEAN_IS_WRONG_LENGTH);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  800|     20|        goto err;
  801|     20|      } else {
  802|     18|        ASN1_BOOLEAN *tbool;
  803|     18|        tbool = (ASN1_BOOLEAN *)pval;
  804|     18|        *tbool = *cont;
  805|     18|      }
  806|     18|      break;
  807|       |
  808|  3.75k|    case V_ASN1_BIT_STRING:
  ------------------
  |  |  127|  3.75k|#define V_ASN1_BIT_STRING 3
  ------------------
  |  Branch (808:5): [True: 3.75k, False: 72.2k]
  ------------------
  809|  3.75k|      if (!c2i_ASN1_BIT_STRING((ASN1_BIT_STRING **)pval, &cont, len)) {
  ------------------
  |  Branch (809:11): [True: 43, False: 3.71k]
  ------------------
  810|     43|        goto err;
  811|     43|      }
  812|  3.71k|      break;
  813|       |
  814|  5.29k|    case V_ASN1_INTEGER:
  ------------------
  |  |  126|  5.29k|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (814:5): [True: 5.29k, False: 70.6k]
  ------------------
  815|  11.0k|    case V_ASN1_ENUMERATED:
  ------------------
  |  |  134|  11.0k|#define V_ASN1_ENUMERATED 10
  ------------------
  |  Branch (815:5): [True: 5.75k, False: 70.2k]
  ------------------
  816|  11.0k|      tint = (ASN1_INTEGER **)pval;
  817|  11.0k|      if (!c2i_ASN1_INTEGER(tint, &cont, len)) {
  ------------------
  |  Branch (817:11): [True: 16, False: 11.0k]
  ------------------
  818|     16|        goto err;
  819|     16|      }
  820|       |      // Fixup type to match the expected form
  821|  11.0k|      (*tint)->type = utype | ((*tint)->type & V_ASN1_NEG);
  ------------------
  |  |  155|  11.0k|#define V_ASN1_NEG 0x100
  ------------------
  822|  11.0k|      break;
  823|       |
  824|    310|    case V_ASN1_OCTET_STRING:
  ------------------
  |  |  128|    310|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (824:5): [True: 310, False: 75.6k]
  ------------------
  825|    313|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|    313|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (825:5): [True: 3, False: 75.9k]
  ------------------
  826|    483|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|    483|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (826:5): [True: 170, False: 75.8k]
  ------------------
  827|    627|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|    627|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (827:5): [True: 144, False: 75.8k]
  ------------------
  828|    631|    case V_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  142|    631|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (828:5): [True: 4, False: 75.9k]
  ------------------
  829|  1.09k|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|  1.09k|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (829:5): [True: 459, False: 75.5k]
  ------------------
  830|  5.82k|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|  5.82k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (830:5): [True: 4.73k, False: 71.2k]
  ------------------
  831|  6.44k|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|  6.44k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (831:5): [True: 616, False: 75.3k]
  ------------------
  832|  6.44k|    case V_ASN1_GRAPHICSTRING:
  ------------------
  |  |  146|  6.44k|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (832:5): [True: 5, False: 75.9k]
  ------------------
  833|  6.45k|    case V_ASN1_VISIBLESTRING:
  ------------------
  |  |  148|  6.45k|#define V_ASN1_VISIBLESTRING 26
  ------------------
  |  Branch (833:5): [True: 5, False: 75.9k]
  ------------------
  834|  6.45k|    case V_ASN1_GENERALSTRING:
  ------------------
  |  |  149|  6.45k|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (834:5): [True: 6, False: 75.9k]
  ------------------
  835|  6.96k|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|  6.96k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (835:5): [True: 504, False: 75.4k]
  ------------------
  836|  7.42k|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|  7.42k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (836:5): [True: 465, False: 75.5k]
  ------------------
  837|  8.06k|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|  8.06k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (837:5): [True: 641, False: 75.3k]
  ------------------
  838|  8.31k|    case V_ASN1_OTHER:
  ------------------
  |  |  118|  8.31k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (838:5): [True: 243, False: 75.7k]
  ------------------
  839|  8.32k|    case V_ASN1_SET:
  ------------------
  |  |  137|  8.32k|#define V_ASN1_SET 17
  ------------------
  |  Branch (839:5): [True: 12, False: 75.9k]
  ------------------
  840|  24.5k|    case V_ASN1_SEQUENCE:
  ------------------
  |  |  136|  24.5k|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (840:5): [True: 16.2k, False: 59.7k]
  ------------------
  841|       |    // TODO(crbug.com/boringssl/412): This default case should be removed, now
  842|       |    // that we've resolved https://crbug.com/boringssl/561. However, it is still
  843|       |    // needed to support some edge cases in |ASN1_PRINTABLE|. |ASN1_PRINTABLE|
  844|       |    // broadly doesn't tolerate unrecognized universal tags, but except for
  845|       |    // eight values that map to |B_ASN1_UNKNOWN| instead of zero. See the
  846|       |    // X509Test.NameAttributeValues test.
  847|  24.9k|    default: {
  ------------------
  |  Branch (847:5): [True: 436, False: 75.5k]
  ------------------
  848|  24.9k|      CBS cbs;
  849|  24.9k|      CBS_init(&cbs, cont, (size_t)len);
  850|  24.9k|      if (utype == V_ASN1_BMPSTRING) {
  ------------------
  |  |  151|  24.9k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (850:11): [True: 465, False: 24.5k]
  ------------------
  851|  5.53M|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (851:16): [True: 5.53M, False: 425]
  ------------------
  852|  5.53M|          uint32_t c;
  853|  5.53M|          if (!cbs_get_ucs2_be(&cbs, &c)) {
  ------------------
  |  Branch (853:15): [True: 40, False: 5.53M]
  ------------------
  854|     40|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BMPSTRING);
  ------------------
  |  |  441|     40|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  855|     40|            goto err;
  856|     40|          }
  857|  5.53M|        }
  858|    465|      }
  859|  24.9k|      if (utype == V_ASN1_UNIVERSALSTRING) {
  ------------------
  |  |  150|  24.9k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (859:11): [True: 504, False: 24.4k]
  ------------------
  860|  1.62k|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (860:16): [True: 1.23k, False: 387]
  ------------------
  861|  1.23k|          uint32_t c;
  862|  1.23k|          if (!cbs_get_utf32_be(&cbs, &c)) {
  ------------------
  |  Branch (862:15): [True: 117, False: 1.12k]
  ------------------
  863|    117|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_UNIVERSALSTRING);
  ------------------
  |  |  441|    117|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  864|    117|            goto err;
  865|    117|          }
  866|  1.23k|        }
  867|    504|      }
  868|  24.8k|      if (utype == V_ASN1_UTF8STRING) {
  ------------------
  |  |  135|  24.8k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (868:11): [True: 641, False: 24.1k]
  ------------------
  869|   137k|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (869:16): [True: 137k, False: 587]
  ------------------
  870|   137k|          uint32_t c;
  871|   137k|          if (!cbs_get_utf8(&cbs, &c)) {
  ------------------
  |  Branch (871:15): [True: 54, False: 137k]
  ------------------
  872|     54|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_UTF8STRING);
  ------------------
  |  |  441|     54|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  873|     54|            goto err;
  874|     54|          }
  875|   137k|        }
  876|    641|      }
  877|  24.7k|      if (utype == V_ASN1_UTCTIME) {
  ------------------
  |  |  144|  24.7k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (877:11): [True: 4.73k, False: 20.0k]
  ------------------
  878|  4.73k|        if (!CBS_parse_utc_time(&cbs, NULL, /*allow_timezone_offset=*/1)) {
  ------------------
  |  Branch (878:13): [True: 208, False: 4.52k]
  ------------------
  879|    208|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_TIME_FORMAT);
  ------------------
  |  |  441|    208|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  880|    208|          goto err;
  881|    208|        }
  882|  4.73k|      }
  883|  24.5k|      if (utype == V_ASN1_GENERALIZEDTIME) {
  ------------------
  |  |  145|  24.5k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (883:11): [True: 616, False: 23.9k]
  ------------------
  884|    616|        if (!CBS_parse_generalized_time(&cbs, NULL,
  ------------------
  |  Branch (884:13): [True: 127, False: 489]
  ------------------
  885|    616|                                        /*allow_timezone_offset=*/0)) {
  886|    127|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_TIME_FORMAT);
  ------------------
  |  |  441|    127|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  887|    127|          goto err;
  888|    127|        }
  889|    616|      }
  890|       |      // TODO(https://crbug.com/boringssl/427): Check other string types.
  891|       |
  892|       |      // All based on ASN1_STRING and handled the same
  893|  24.4k|      if (!*pval) {
  ------------------
  |  Branch (893:11): [True: 1.09k, False: 23.3k]
  ------------------
  894|  1.09k|        stmp = ASN1_STRING_type_new(utype);
  895|  1.09k|        if (!stmp) {
  ------------------
  |  Branch (895:13): [True: 0, False: 1.09k]
  ------------------
  896|      0|          goto err;
  897|      0|        }
  898|  1.09k|        *pval = (ASN1_VALUE *)stmp;
  899|  23.3k|      } else {
  900|  23.3k|        stmp = (ASN1_STRING *)*pval;
  901|  23.3k|        stmp->type = utype;
  902|  23.3k|      }
  903|  24.4k|      if (!ASN1_STRING_set(stmp, cont, len)) {
  ------------------
  |  Branch (903:11): [True: 0, False: 24.4k]
  ------------------
  904|      0|        ASN1_STRING_free(stmp);
  905|      0|        *pval = NULL;
  906|      0|        goto err;
  907|      0|      }
  908|  24.4k|      break;
  909|  24.4k|    }
  910|  75.9k|  }
  911|       |  // If ASN1_ANY and NULL type fix up value
  912|  75.3k|  if (typ && (utype == V_ASN1_NULL)) {
  ------------------
  |  |  129|  2.39k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (912:7): [True: 2.39k, False: 72.9k]
  |  Branch (912:14): [True: 416, False: 1.97k]
  ------------------
  913|    416|    typ->value.ptr = NULL;
  914|    416|  }
  915|       |
  916|  75.3k|  ret = 1;
  917|  75.9k|err:
  918|  75.9k|  if (!ret) {
  ------------------
  |  Branch (918:7): [True: 647, False: 75.3k]
  ------------------
  919|    647|    ASN1_TYPE_free(typ);
  920|    647|    if (opval) {
  ------------------
  |  Branch (920:9): [True: 417, False: 230]
  ------------------
  921|    417|      *opval = NULL;
  922|    417|    }
  923|    647|  }
  924|  75.9k|  return ret;
  925|  75.3k|}
tasn_dec.c:asn1_check_tlen:
  932|   227k|                           int exptag, int expclass, char opt) {
  933|   227k|  int i;
  934|   227k|  int ptag, pclass;
  935|   227k|  long plen;
  936|   227k|  const unsigned char *p;
  937|   227k|  p = *in;
  938|       |
  939|   227k|  i = ASN1_get_object(&p, &plen, &ptag, &pclass, len);
  940|   227k|  if (i & 0x80) {
  ------------------
  |  Branch (940:7): [True: 335, False: 226k]
  ------------------
  941|    335|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_OBJECT_HEADER);
  ------------------
  |  |  441|    335|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  942|    335|    return 0;
  943|    335|  }
  944|   226k|  if (exptag >= 0) {
  ------------------
  |  Branch (944:7): [True: 193k, False: 33.3k]
  ------------------
  945|   193k|    if ((exptag != ptag) || (expclass != pclass)) {
  ------------------
  |  Branch (945:9): [True: 5.38k, False: 188k]
  |  Branch (945:29): [True: 15, False: 187k]
  ------------------
  946|       |      // If type is OPTIONAL, not an error: indicate missing type.
  947|  5.40k|      if (opt) {
  ------------------
  |  Branch (947:11): [True: 5.19k, False: 208]
  ------------------
  948|  5.19k|        return -1;
  949|  5.19k|      }
  950|    208|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TAG);
  ------------------
  |  |  441|    208|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  951|    208|      return 0;
  952|  5.40k|    }
  953|   193k|  }
  954|       |
  955|   221k|  if (cst) {
  ------------------
  |  Branch (955:7): [True: 121k, False: 99.6k]
  ------------------
  956|   121k|    *cst = i & V_ASN1_CONSTRUCTED;
  ------------------
  |  |   99|   121k|#define V_ASN1_CONSTRUCTED 0x20
  ------------------
  957|   121k|  }
  958|       |
  959|   221k|  if (olen) {
  ------------------
  |  Branch (959:7): [True: 188k, False: 33.0k]
  ------------------
  960|   188k|    *olen = plen;
  961|   188k|  }
  962|       |
  963|   221k|  if (oclass) {
  ------------------
  |  Branch (963:7): [True: 33.0k, False: 188k]
  ------------------
  964|  33.0k|    *oclass = pclass;
  965|  33.0k|  }
  966|       |
  967|   221k|  if (otag) {
  ------------------
  |  Branch (967:7): [True: 33.0k, False: 188k]
  ------------------
  968|  33.0k|    *otag = ptag;
  969|  33.0k|  }
  970|       |
  971|   221k|  *in = p;
  972|   221k|  return 1;
  973|   226k|}

ASN1_item_i2d:
   86|  14.6k|int ASN1_item_i2d(ASN1_VALUE *val, unsigned char **out, const ASN1_ITEM *it) {
   87|  14.6k|  if (out && !*out) {
  ------------------
  |  Branch (87:7): [True: 8.36k, False: 6.27k]
  |  Branch (87:14): [True: 2.09k, False: 6.27k]
  ------------------
   88|  2.09k|    unsigned char *p, *buf;
   89|  2.09k|    int len = ASN1_item_ex_i2d(&val, NULL, it, /*tag=*/-1, /*aclass=*/0);
   90|  2.09k|    if (len <= 0) {
  ------------------
  |  Branch (90:9): [True: 0, False: 2.09k]
  ------------------
   91|      0|      return len;
   92|      0|    }
   93|  2.09k|    buf = OPENSSL_malloc(len);
   94|  2.09k|    if (!buf) {
  ------------------
  |  Branch (94:9): [True: 0, False: 2.09k]
  ------------------
   95|      0|      return -1;
   96|      0|    }
   97|  2.09k|    p = buf;
   98|  2.09k|    int len2 = ASN1_item_ex_i2d(&val, &p, it, /*tag=*/-1, /*aclass=*/0);
   99|  2.09k|    if (len2 <= 0) {
  ------------------
  |  Branch (99:9): [True: 0, False: 2.09k]
  ------------------
  100|      0|      OPENSSL_free(buf);
  101|      0|      return len2;
  102|      0|    }
  103|  2.09k|    assert(len == len2);
  104|  2.09k|    *out = buf;
  105|  2.09k|    return len;
  106|  2.09k|  }
  107|       |
  108|  12.5k|  return ASN1_item_ex_i2d(&val, out, it, /*tag=*/-1, /*aclass=*/0);
  109|  14.6k|}
ASN1_item_ex_i2d:
  115|  93.9k|                     const ASN1_ITEM *it, int tag, int aclass) {
  116|  93.9k|  int ret = asn1_item_ex_i2d_opt(pval, out, it, tag, aclass, /*optional=*/0);
  117|  93.9k|  assert(ret != 0);
  118|  93.9k|  return ret;
  119|  93.9k|}
tasn_enc.c:asn1_item_ex_i2d_opt:
  125|   306k|                         int optional) {
  126|   306k|  const ASN1_TEMPLATE *tt = NULL;
  127|   306k|  int i, seqcontlen, seqlen;
  128|       |
  129|       |  // Historically, |aclass| was repurposed to pass additional flags into the
  130|       |  // encoding process.
  131|   306k|  assert((aclass & ASN1_TFLG_TAG_CLASS) == aclass);
  132|       |  // If not overridding the tag, |aclass| is ignored and should be zero.
  133|   306k|  assert(tag != -1 || aclass == 0);
  134|       |
  135|       |  // All fields are pointers, except for boolean |ASN1_ITYPE_PRIMITIVE|s.
  136|       |  // Optional primitives are handled later.
  137|   306k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) && !*pval) {
  ------------------
  |  |  487|   306k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (137:7): [True: 168k, False: 138k]
  |  Branch (137:46): [True: 0, False: 168k]
  ------------------
  138|      0|    if (optional) {
  ------------------
  |  Branch (138:9): [True: 0, False: 0]
  ------------------
  139|      0|      return 0;
  140|      0|    }
  141|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  142|      0|    return -1;
  143|      0|  }
  144|       |
  145|   306k|  switch (it->itype) {
  146|   138k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   138k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (146:5): [True: 138k, False: 168k]
  ------------------
  147|   138k|      if (it->templates) {
  ------------------
  |  Branch (147:11): [True: 13.1k, False: 125k]
  ------------------
  148|       |        // This is an |ASN1_ITEM_TEMPLATE|.
  149|  13.1k|        if (it->templates->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|  13.1k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (149:13): [True: 0, False: 13.1k]
  ------------------
  150|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|      0|          return -1;
  152|      0|        }
  153|  13.1k|        return asn1_template_ex_i2d(pval, out, it->templates, tag, aclass,
  154|  13.1k|                                    optional);
  155|  13.1k|      }
  156|   125k|      return asn1_i2d_ex_primitive(pval, out, it, tag, aclass, optional);
  157|       |
  158|  85.3k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  85.3k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (158:5): [True: 85.3k, False: 221k]
  ------------------
  159|       |      // It never makes sense for multi-strings to have implicit tagging, so
  160|       |      // if tag != -1, then this looks like an error in the template.
  161|  85.3k|      if (tag != -1) {
  ------------------
  |  Branch (161:11): [True: 0, False: 85.3k]
  ------------------
  162|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|      0|        return -1;
  164|      0|      }
  165|  85.3k|      return asn1_i2d_ex_primitive(pval, out, it, -1, 0, optional);
  166|       |
  167|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (167:5): [True: 0, False: 306k]
  ------------------
  168|       |      // It never makes sense for CHOICE types to have implicit tagging, so if
  169|       |      // tag != -1, then this looks like an error in the template.
  170|      0|      if (tag != -1) {
  ------------------
  |  Branch (170:11): [True: 0, False: 0]
  ------------------
  171|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  172|      0|        return -1;
  173|      0|      }
  174|      0|      i = asn1_get_choice_selector(pval, it);
  175|      0|      if (i < 0 || i >= it->tcount) {
  ------------------
  |  Branch (175:11): [True: 0, False: 0]
  |  Branch (175:20): [True: 0, False: 0]
  ------------------
  176|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NO_MATCHING_CHOICE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|        return -1;
  178|      0|      }
  179|      0|      const ASN1_TEMPLATE *chtt = it->templates + i;
  180|      0|      if (chtt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|      0|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (180:11): [True: 0, False: 0]
  ------------------
  181|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  182|      0|        return -1;
  183|      0|      }
  184|      0|      ASN1_VALUE **pchval = asn1_get_field_ptr(pval, chtt);
  185|      0|      return asn1_template_ex_i2d(pchval, out, chtt, -1, 0, /*optional=*/0);
  186|      0|    }
  187|       |
  188|      0|    case ASN1_ITYPE_EXTERN: {
  ------------------
  |  |  493|      0|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (188:5): [True: 0, False: 306k]
  ------------------
  189|       |      // We don't support implicit tagging with external types.
  190|      0|      if (tag != -1) {
  ------------------
  |  Branch (190:11): [True: 0, False: 0]
  ------------------
  191|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  192|      0|        return -1;
  193|      0|      }
  194|      0|      const ASN1_EXTERN_FUNCS *ef = it->funcs;
  195|      0|      int ret = ef->asn1_ex_i2d(pval, out, it);
  196|      0|      if (ret == 0) {
  ------------------
  |  Branch (196:11): [True: 0, False: 0]
  ------------------
  197|       |        // |asn1_ex_i2d| should never return zero. We have already checked
  198|       |        // for optional values generically, and |ASN1_ITYPE_EXTERN| fields
  199|       |        // must be pointers.
  200|      0|        OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  201|      0|        return -1;
  202|      0|      }
  203|      0|      return ret;
  204|      0|    }
  205|       |
  206|  82.8k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  82.8k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (206:5): [True: 82.8k, False: 223k]
  ------------------
  207|  82.8k|      i = asn1_enc_restore(&seqcontlen, out, pval, it);
  208|       |      // An error occurred
  209|  82.8k|      if (i < 0) {
  ------------------
  |  Branch (209:11): [True: 0, False: 82.8k]
  ------------------
  210|      0|        return -1;
  211|      0|      }
  212|       |      // We have a valid cached encoding...
  213|  82.8k|      if (i > 0) {
  ------------------
  |  Branch (213:11): [True: 4.18k, False: 78.6k]
  ------------------
  214|  4.18k|        return seqcontlen;
  215|  4.18k|      }
  216|       |      // Otherwise carry on
  217|  78.6k|      seqcontlen = 0;
  218|       |      // If no IMPLICIT tagging set to SEQUENCE, UNIVERSAL
  219|  78.6k|      if (tag == -1) {
  ------------------
  |  Branch (219:11): [True: 78.6k, False: 0]
  ------------------
  220|  78.6k|        tag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|  78.6k|#define V_ASN1_SEQUENCE 16
  ------------------
  221|  78.6k|        aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  78.6k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  222|  78.6k|      }
  223|       |      // First work out sequence content length
  224|   235k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (224:39): [True: 157k, False: 78.6k]
  ------------------
  225|   157k|        const ASN1_TEMPLATE *seqtt;
  226|   157k|        ASN1_VALUE **pseqval;
  227|   157k|        int tmplen;
  228|   157k|        seqtt = asn1_do_adb(pval, tt, 1);
  229|   157k|        if (!seqtt) {
  ------------------
  |  Branch (229:13): [True: 0, False: 157k]
  ------------------
  230|      0|          return -1;
  231|      0|        }
  232|   157k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  233|   157k|        tmplen =
  234|   157k|            asn1_template_ex_i2d(pseqval, NULL, seqtt, -1, 0, /*optional=*/0);
  235|   157k|        if (tmplen == -1 || (tmplen > INT_MAX - seqcontlen)) {
  ------------------
  |  Branch (235:13): [True: 0, False: 157k]
  |  Branch (235:29): [True: 0, False: 157k]
  ------------------
  236|      0|          return -1;
  237|      0|        }
  238|   157k|        seqcontlen += tmplen;
  239|   157k|      }
  240|       |
  241|  78.6k|      seqlen = ASN1_object_size(/*constructed=*/1, seqcontlen, tag);
  242|  78.6k|      if (!out || seqlen == -1) {
  ------------------
  |  Branch (242:11): [True: 51.0k, False: 27.6k]
  |  Branch (242:19): [True: 0, False: 27.6k]
  ------------------
  243|  51.0k|        return seqlen;
  244|  51.0k|      }
  245|       |      // Output SEQUENCE header
  246|  27.6k|      ASN1_put_object(out, /*constructed=*/1, seqcontlen, tag, aclass);
  247|  82.8k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (247:39): [True: 55.2k, False: 27.6k]
  ------------------
  248|  55.2k|        const ASN1_TEMPLATE *seqtt;
  249|  55.2k|        ASN1_VALUE **pseqval;
  250|  55.2k|        seqtt = asn1_do_adb(pval, tt, 1);
  251|  55.2k|        if (!seqtt) {
  ------------------
  |  Branch (251:13): [True: 0, False: 55.2k]
  ------------------
  252|      0|          return -1;
  253|      0|        }
  254|  55.2k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  255|  55.2k|        if (asn1_template_ex_i2d(pseqval, out, seqtt, -1, 0, /*optional=*/0) <
  ------------------
  |  Branch (255:13): [True: 0, False: 55.2k]
  ------------------
  256|  55.2k|            0) {
  257|      0|          return -1;
  258|      0|        }
  259|  55.2k|      }
  260|  27.6k|      return seqlen;
  261|  27.6k|    }
  262|       |
  263|      0|    default:
  ------------------
  |  Branch (263:5): [True: 0, False: 306k]
  ------------------
  264|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  265|      0|      return -1;
  266|   306k|  }
  267|   306k|}
tasn_enc.c:asn1_template_ex_i2d:
  274|   225k|                                int optional) {
  275|   225k|  int i, ret, ttag, tclass;
  276|   225k|  size_t j;
  277|   225k|  uint32_t flags = tt->flags;
  278|       |
  279|       |  // Historically, |iclass| was repurposed to pass additional flags into the
  280|       |  // encoding process.
  281|   225k|  assert((iclass & ASN1_TFLG_TAG_CLASS) == iclass);
  282|       |  // If not overridding the tag, |iclass| is ignored and should be zero.
  283|   225k|  assert(tag != -1 || iclass == 0);
  284|       |
  285|       |  // Work out tag and class to use: tagging may come either from the
  286|       |  // template or the arguments, not both because this would create
  287|       |  // ambiguity.
  288|   225k|  if (flags & ASN1_TFLG_TAG_MASK) {
  ------------------
  |  |  404|   225k|#define ASN1_TFLG_TAG_MASK	(0x3 << 3)
  ------------------
  |  Branch (288:7): [True: 0, False: 225k]
  ------------------
  289|       |    // Error if argument and template tagging
  290|      0|    if (tag != -1) {
  ------------------
  |  Branch (290:9): [True: 0, False: 0]
  ------------------
  291|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  292|      0|      return -1;
  293|      0|    }
  294|       |    // Get tagging from template
  295|      0|    ttag = tt->tag;
  296|      0|    tclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|      0|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  297|   225k|  } else if (tag != -1) {
  ------------------
  |  Branch (297:14): [True: 0, False: 225k]
  ------------------
  298|       |    // No template tagging, get from arguments
  299|      0|    ttag = tag;
  300|      0|    tclass = iclass & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|      0|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  301|   225k|  } else {
  302|   225k|    ttag = -1;
  303|   225k|    tclass = 0;
  304|   225k|  }
  305|       |
  306|       |  // The template may itself by marked as optional, or this may be the template
  307|       |  // of an |ASN1_ITEM_TEMPLATE| type which was contained inside an outer
  308|       |  // optional template. (They cannot both be true because the
  309|       |  // |ASN1_ITEM_TEMPLATE| codepath rejects optional templates.)
  310|   225k|  assert(!optional || (flags & ASN1_TFLG_OPTIONAL) == 0);
  311|   225k|  optional = optional || (flags & ASN1_TFLG_OPTIONAL) != 0;
  ------------------
  |  |  381|   225k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (311:14): [True: 0, False: 225k]
  |  Branch (311:26): [True: 14.6k, False: 211k]
  ------------------
  312|       |
  313|       |  // At this point 'ttag' contains the outer tag to use, and 'tclass' is the
  314|       |  // class.
  315|       |
  316|   225k|  if (flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   225k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (316:7): [True: 13.1k, False: 212k]
  ------------------
  317|       |    // SET OF, SEQUENCE OF
  318|  13.1k|    STACK_OF(ASN1_VALUE) *sk = (STACK_OF(ASN1_VALUE) *)*pval;
  ------------------
  |  |   81|  13.1k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  319|  13.1k|    int isset, sktag, skaclass;
  320|  13.1k|    int skcontlen, sklen;
  321|  13.1k|    ASN1_VALUE *skitem;
  322|       |
  323|  13.1k|    if (!*pval) {
  ------------------
  |  Branch (323:9): [True: 0, False: 13.1k]
  ------------------
  324|      0|      if (optional) {
  ------------------
  |  Branch (324:11): [True: 0, False: 0]
  ------------------
  325|      0|        return 0;
  326|      0|      }
  327|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|      0|      return -1;
  329|      0|    }
  330|       |
  331|  13.1k|    if (flags & ASN1_TFLG_SET_OF) {
  ------------------
  |  |  384|  13.1k|#define ASN1_TFLG_SET_OF	(0x1 << 1)
  ------------------
  |  Branch (331:9): [True: 13.1k, False: 0]
  ------------------
  332|  13.1k|      isset = 1;
  333|       |      // Historically, types with both bits set were mutated when
  334|       |      // serialized to apply the sort. We no longer support this.
  335|  13.1k|      assert((flags & ASN1_TFLG_SEQUENCE_OF) == 0);
  336|  13.1k|    } else {
  337|      0|      isset = 0;
  338|      0|    }
  339|       |
  340|       |    // Work out inner tag value: if EXPLICIT or no tagging use underlying
  341|       |    // type.
  342|  13.1k|    if ((ttag != -1) && !(flags & ASN1_TFLG_EXPTAG)) {
  ------------------
  |  |  402|      0|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (342:9): [True: 0, False: 13.1k]
  |  Branch (342:25): [True: 0, False: 0]
  ------------------
  343|      0|      sktag = ttag;
  344|      0|      skaclass = tclass;
  345|  13.1k|    } else {
  346|  13.1k|      skaclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  13.1k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  347|  13.1k|      if (isset) {
  ------------------
  |  Branch (347:11): [True: 13.1k, False: 0]
  ------------------
  348|  13.1k|        sktag = V_ASN1_SET;
  ------------------
  |  |  137|  13.1k|#define V_ASN1_SET 17
  ------------------
  349|  13.1k|      } else {
  350|      0|        sktag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|      0|#define V_ASN1_SEQUENCE 16
  ------------------
  351|      0|      }
  352|  13.1k|    }
  353|       |
  354|       |    // Determine total length of items
  355|  13.1k|    skcontlen = 0;
  356|  55.8k|    for (j = 0; j < sk_ASN1_VALUE_num(sk); j++) {
  ------------------
  |  Branch (356:17): [True: 42.6k, False: 13.1k]
  ------------------
  357|  42.6k|      int tmplen;
  358|  42.6k|      skitem = sk_ASN1_VALUE_value(sk, j);
  359|  42.6k|      tmplen = ASN1_item_ex_i2d(&skitem, NULL, ASN1_ITEM_ptr(tt->item), -1, 0);
  ------------------
  |  |  288|  42.6k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  360|  42.6k|      if (tmplen == -1 || (skcontlen > INT_MAX - tmplen)) {
  ------------------
  |  Branch (360:11): [True: 0, False: 42.6k]
  |  Branch (360:27): [True: 0, False: 42.6k]
  ------------------
  361|      0|        return -1;
  362|      0|      }
  363|  42.6k|      skcontlen += tmplen;
  364|  42.6k|    }
  365|  13.1k|    sklen = ASN1_object_size(/*constructed=*/1, skcontlen, sktag);
  366|  13.1k|    if (sklen == -1) {
  ------------------
  |  Branch (366:9): [True: 0, False: 13.1k]
  ------------------
  367|      0|      return -1;
  368|      0|    }
  369|       |    // If EXPLICIT need length of surrounding tag
  370|  13.1k|    if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  13.1k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (370:9): [True: 0, False: 13.1k]
  ------------------
  371|      0|      ret = ASN1_object_size(/*constructed=*/1, sklen, ttag);
  372|  13.1k|    } else {
  373|  13.1k|      ret = sklen;
  374|  13.1k|    }
  375|       |
  376|  13.1k|    if (!out || ret == -1) {
  ------------------
  |  Branch (376:9): [True: 6.59k, False: 6.59k]
  |  Branch (376:17): [True: 0, False: 6.59k]
  ------------------
  377|  6.59k|      return ret;
  378|  6.59k|    }
  379|       |
  380|       |    // Now encode this lot...
  381|       |    // EXPLICIT tag
  382|  6.59k|    if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  6.59k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (382:9): [True: 0, False: 6.59k]
  ------------------
  383|      0|      ASN1_put_object(out, /*constructed=*/1, sklen, ttag, tclass);
  384|      0|    }
  385|       |    // SET or SEQUENCE and IMPLICIT tag
  386|  6.59k|    ASN1_put_object(out, /*constructed=*/1, skcontlen, sktag, skaclass);
  387|       |    // And the stuff itself
  388|  6.59k|    if (!asn1_set_seq_out(sk, out, skcontlen, ASN1_ITEM_ptr(tt->item), isset)) {
  ------------------
  |  |  288|  6.59k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (388:9): [True: 0, False: 6.59k]
  ------------------
  389|      0|      return -1;
  390|      0|    }
  391|  6.59k|    return ret;
  392|  6.59k|  }
  393|       |
  394|   212k|  if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|   212k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (394:7): [True: 0, False: 212k]
  ------------------
  395|       |    // EXPLICIT tagging
  396|       |    // Find length of tagged item
  397|      0|    i = asn1_item_ex_i2d_opt(pval, NULL, ASN1_ITEM_ptr(tt->item), -1, 0,
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  398|      0|                             optional);
  399|      0|    if (i <= 0) {
  ------------------
  |  Branch (399:9): [True: 0, False: 0]
  ------------------
  400|      0|      return i;
  401|      0|    }
  402|       |    // Find length of EXPLICIT tag
  403|      0|    ret = ASN1_object_size(/*constructed=*/1, i, ttag);
  404|      0|    if (out && ret != -1) {
  ------------------
  |  Branch (404:9): [True: 0, False: 0]
  |  Branch (404:16): [True: 0, False: 0]
  ------------------
  405|       |      // Output tag and item
  406|      0|      ASN1_put_object(out, /*constructed=*/1, i, ttag, tclass);
  407|      0|      if (ASN1_item_ex_i2d(pval, out, ASN1_ITEM_ptr(tt->item), -1, 0) < 0) {
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (407:11): [True: 0, False: 0]
  ------------------
  408|      0|        return -1;
  409|      0|      }
  410|      0|    }
  411|      0|    return ret;
  412|      0|  }
  413|       |
  414|       |  // Either normal or IMPLICIT tagging
  415|   212k|  return asn1_item_ex_i2d_opt(pval, out, ASN1_ITEM_ptr(tt->item), ttag, tclass,
  ------------------
  |  |  288|   212k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  416|   212k|                              optional);
  417|   212k|}
tasn_enc.c:asn1_set_seq_out:
  443|  6.59k|                            int skcontlen, const ASN1_ITEM *item, int do_sort) {
  444|       |  // No need to sort if there are fewer than two items.
  445|  6.59k|  if (!do_sort || sk_ASN1_VALUE_num(sk) < 2) {
  ------------------
  |  Branch (445:7): [True: 0, False: 6.59k]
  |  Branch (445:19): [True: 5.94k, False: 650]
  ------------------
  446|  11.8k|    for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (446:24): [True: 5.94k, False: 5.94k]
  ------------------
  447|  5.94k|      ASN1_VALUE *skitem = sk_ASN1_VALUE_value(sk, i);
  448|  5.94k|      if (ASN1_item_ex_i2d(&skitem, out, item, -1, 0) < 0) {
  ------------------
  |  Branch (448:11): [True: 0, False: 5.94k]
  ------------------
  449|      0|        return 0;
  450|      0|      }
  451|  5.94k|    }
  452|  5.94k|    return 1;
  453|  5.94k|  }
  454|       |
  455|    650|  if (sk_ASN1_VALUE_num(sk) > ((size_t)-1) / sizeof(DER_ENC)) {
  ------------------
  |  Branch (455:7): [True: 0, False: 650]
  ------------------
  456|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  457|      0|    return 0;
  458|      0|  }
  459|       |
  460|    650|  int ret = 0;
  461|    650|  unsigned char *const buf = OPENSSL_malloc(skcontlen);
  462|    650|  DER_ENC *encoded = OPENSSL_malloc(sk_ASN1_VALUE_num(sk) * sizeof(*encoded));
  463|    650|  if (encoded == NULL || buf == NULL) {
  ------------------
  |  Branch (463:7): [True: 0, False: 650]
  |  Branch (463:26): [True: 0, False: 650]
  ------------------
  464|      0|    goto err;
  465|      0|  }
  466|       |
  467|       |  // Encode all the elements into |buf| and populate |encoded|.
  468|    650|  unsigned char *p = buf;
  469|  16.0k|  for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (469:22): [True: 15.3k, False: 650]
  ------------------
  470|  15.3k|    ASN1_VALUE *skitem = sk_ASN1_VALUE_value(sk, i);
  471|  15.3k|    encoded[i].data = p;
  472|  15.3k|    encoded[i].length = ASN1_item_ex_i2d(&skitem, &p, item, -1, 0);
  473|  15.3k|    if (encoded[i].length < 0) {
  ------------------
  |  Branch (473:9): [True: 0, False: 15.3k]
  ------------------
  474|      0|      goto err;
  475|      0|    }
  476|  15.3k|    assert(p - buf <= skcontlen);
  477|  15.3k|  }
  478|       |
  479|    650|  qsort(encoded, sk_ASN1_VALUE_num(sk), sizeof(*encoded), der_cmp);
  480|       |
  481|       |  // Output the elements in sorted order.
  482|    650|  p = *out;
  483|  16.0k|  for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (483:22): [True: 15.3k, False: 650]
  ------------------
  484|  15.3k|    OPENSSL_memcpy(p, encoded[i].data, encoded[i].length);
  485|  15.3k|    p += encoded[i].length;
  486|  15.3k|  }
  487|    650|  *out = p;
  488|       |
  489|    650|  ret = 1;
  490|       |
  491|    650|err:
  492|    650|  OPENSSL_free(encoded);
  493|    650|  OPENSSL_free(buf);
  494|    650|  return ret;
  495|    650|}
tasn_enc.c:der_cmp:
  426|  71.6k|static int der_cmp(const void *a, const void *b) {
  427|  71.6k|  const DER_ENC *d1 = a, *d2 = b;
  428|  71.6k|  int cmplen, i;
  429|  71.6k|  cmplen = (d1->length < d2->length) ? d1->length : d2->length;
  ------------------
  |  Branch (429:12): [True: 556, False: 71.0k]
  ------------------
  430|  71.6k|  i = OPENSSL_memcmp(d1->data, d2->data, cmplen);
  431|  71.6k|  if (i) {
  ------------------
  |  Branch (431:7): [True: 36.3k, False: 35.3k]
  ------------------
  432|  36.3k|    return i;
  433|  36.3k|  }
  434|  35.3k|  return d1->length - d2->length;
  435|  71.6k|}
tasn_enc.c:asn1_i2d_ex_primitive:
  501|   210k|                                 int optional) {
  502|       |  // Get length of content octets and maybe find out the underlying type.
  503|   210k|  int omit;
  504|   210k|  int utype = it->utype;
  505|   210k|  int len = asn1_ex_i2c(pval, NULL, &omit, &utype, it);
  506|   210k|  if (len < 0) {
  ------------------
  |  Branch (506:7): [True: 0, False: 210k]
  ------------------
  507|      0|    return -1;
  508|      0|  }
  509|   210k|  if (omit) {
  ------------------
  |  Branch (509:7): [True: 7.15k, False: 203k]
  ------------------
  510|  7.15k|    if (optional) {
  ------------------
  |  Branch (510:9): [True: 7.15k, False: 0]
  ------------------
  511|  7.15k|      return 0;
  512|  7.15k|    }
  513|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  514|      0|    return -1;
  515|  7.15k|  }
  516|       |
  517|       |  // If SEQUENCE, SET or OTHER then header is included in pseudo content
  518|       |  // octets so don't include tag+length. We need to check here because the
  519|       |  // call to asn1_ex_i2c() could change utype.
  520|   203k|  int usetag =
  521|   203k|      utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  136|   406k|#define V_ASN1_SEQUENCE 16
  ------------------
                    utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  137|   355k|#define V_ASN1_SET 17
  ------------------
                    utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  118|   152k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (521:7): [True: 152k, False: 50.6k]
  |  Branch (521:35): [True: 152k, False: 25]
  |  Branch (521:58): [True: 152k, False: 566]
  ------------------
  522|       |
  523|       |  // If not implicitly tagged get tag from underlying type
  524|   203k|  if (tag == -1) {
  ------------------
  |  Branch (524:7): [True: 203k, False: 0]
  ------------------
  525|   203k|    tag = utype;
  526|   203k|  }
  527|       |
  528|       |  // Output tag+length followed by content octets
  529|   203k|  if (out) {
  ------------------
  |  Branch (529:7): [True: 52.9k, False: 150k]
  ------------------
  530|  52.9k|    if (usetag) {
  ------------------
  |  Branch (530:9): [True: 40.1k, False: 12.8k]
  ------------------
  531|  40.1k|      ASN1_put_object(out, /*constructed=*/0, len, tag, aclass);
  532|  40.1k|    }
  533|  52.9k|    int len2 = asn1_ex_i2c(pval, *out, &omit, &utype, it);
  534|  52.9k|    if (len2 < 0) {
  ------------------
  |  Branch (534:9): [True: 0, False: 52.9k]
  ------------------
  535|      0|      return -1;
  536|      0|    }
  537|  52.9k|    assert(len == len2);
  538|  52.9k|    assert(!omit);
  539|  52.9k|    *out += len;
  540|  52.9k|  }
  541|       |
  542|   203k|  if (usetag) {
  ------------------
  |  Branch (542:7): [True: 152k, False: 51.2k]
  ------------------
  543|   152k|    return ASN1_object_size(/*constructed=*/0, len, tag);
  544|   152k|  }
  545|  51.2k|  return len;
  546|   203k|}
tasn_enc.c:asn1_ex_i2c:
  565|   263k|                       int *putype, const ASN1_ITEM *it) {
  566|   263k|  ASN1_BOOLEAN *tbool = NULL;
  567|   263k|  ASN1_STRING *strtmp;
  568|   263k|  ASN1_OBJECT *otmp;
  569|   263k|  int utype;
  570|   263k|  const unsigned char *cont;
  571|   263k|  unsigned char c;
  572|   263k|  int len;
  573|       |
  574|       |  // Historically, |it->funcs| for primitive types contained an
  575|       |  // |ASN1_PRIMITIVE_FUNCS| table of callbacks.
  576|   263k|  assert(it->funcs == NULL);
  577|       |
  578|   263k|  *out_omit = 0;
  579|       |
  580|       |  // Should type be omitted?
  581|   263k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) || (it->utype != V_ASN1_BOOLEAN)) {
  ------------------
  |  |  487|   263k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
                if ((it->itype != ASN1_ITYPE_PRIMITIVE) || (it->utype != V_ASN1_BOOLEAN)) {
  ------------------
  |  |  125|   156k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (581:7): [True: 106k, False: 156k]
  |  Branch (581:46): [True: 156k, False: 0]
  ------------------
  582|   263k|    if (!*pval) {
  ------------------
  |  Branch (582:9): [True: 7.15k, False: 256k]
  ------------------
  583|  7.15k|      *out_omit = 1;
  584|  7.15k|      return 0;
  585|  7.15k|    }
  586|   263k|  }
  587|       |
  588|   256k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|   256k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (588:7): [True: 106k, False: 149k]
  ------------------
  589|       |    // If MSTRING type set the underlying type
  590|   106k|    strtmp = (ASN1_STRING *)*pval;
  591|   106k|    utype = strtmp->type;
  592|   106k|    if (utype < 0 && utype != V_ASN1_OTHER) {
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (592:9): [True: 0, False: 106k]
  |  Branch (592:22): [True: 0, False: 0]
  ------------------
  593|       |      // MSTRINGs can have type -1 when default-constructed.
  594|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  595|      0|      return -1;
  596|      0|    }
  597|       |    // Negative INTEGER and ENUMERATED values use |ASN1_STRING| type values
  598|       |    // that do not match their corresponding utype values. INTEGERs cannot
  599|       |    // participate in MSTRING types, but ENUMERATEDs can.
  600|       |    //
  601|       |    // TODO(davidben): Is this a bug? Although arguably one of the MSTRING
  602|       |    // types should contain more values, rather than less. See
  603|       |    // https://crbug.com/boringssl/412. But it is not possible to fit all
  604|       |    // possible ANY values into an |ASN1_STRING|, so matching the spec here
  605|       |    // is somewhat hopeless.
  606|   106k|    if (utype == V_ASN1_NEG_INTEGER) {
  ------------------
  |  |  156|   106k|#define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  126|   106k|#define V_ASN1_INTEGER 2
  |  |  ------------------
  |  |               #define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|   106k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  |  Branch (606:9): [True: 0, False: 106k]
  ------------------
  607|      0|      utype = V_ASN1_INTEGER;
  ------------------
  |  |  126|      0|#define V_ASN1_INTEGER 2
  ------------------
  608|   106k|    } else if (utype == V_ASN1_NEG_ENUMERATED) {
  ------------------
  |  |  157|   106k|#define V_ASN1_NEG_ENUMERATED (V_ASN1_ENUMERATED | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  134|   106k|#define V_ASN1_ENUMERATED 10
  |  |  ------------------
  |  |               #define V_ASN1_NEG_ENUMERATED (V_ASN1_ENUMERATED | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|   106k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  |  Branch (608:16): [True: 16.5k, False: 90.1k]
  ------------------
  609|  16.5k|      utype = V_ASN1_ENUMERATED;
  ------------------
  |  |  134|  16.5k|#define V_ASN1_ENUMERATED 10
  ------------------
  610|  16.5k|    }
  611|   106k|    *putype = utype;
  612|   149k|  } else if (it->utype == V_ASN1_ANY) {
  ------------------
  |  |  121|   149k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (612:14): [True: 9.38k, False: 140k]
  ------------------
  613|       |    // If ANY set type and pointer to value
  614|  9.38k|    ASN1_TYPE *typ;
  615|  9.38k|    typ = (ASN1_TYPE *)*pval;
  616|  9.38k|    utype = typ->type;
  617|  9.38k|    if (utype < 0 && utype != V_ASN1_OTHER) {
  ------------------
  |  |  118|    724|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (617:9): [True: 724, False: 8.65k]
  |  Branch (617:22): [True: 0, False: 724]
  ------------------
  618|       |      // |ASN1_TYPE|s can have type -1 when default-constructed.
  619|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  620|      0|      return -1;
  621|      0|    }
  622|  9.38k|    *putype = utype;
  623|  9.38k|    pval = &typ->value.asn1_value;
  624|   140k|  } else {
  625|   140k|    utype = *putype;
  626|   140k|  }
  627|       |
  628|   256k|  switch (utype) {
  629|   129k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|   129k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (629:5): [True: 129k, False: 126k]
  ------------------
  630|   129k|      otmp = (ASN1_OBJECT *)*pval;
  631|   129k|      cont = otmp->data;
  632|   129k|      len = otmp->length;
  633|   129k|      if (len == 0) {
  ------------------
  |  Branch (633:11): [True: 0, False: 129k]
  ------------------
  634|       |        // Some |ASN1_OBJECT|s do not have OIDs and cannot be serialized.
  635|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OBJECT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  636|      0|        return -1;
  637|      0|      }
  638|   129k|      break;
  639|       |
  640|   129k|    case V_ASN1_NULL:
  ------------------
  |  |  129|  2.05k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (640:5): [True: 2.05k, False: 254k]
  ------------------
  641|  2.05k|      cont = NULL;
  642|  2.05k|      len = 0;
  643|  2.05k|      break;
  644|       |
  645|     54|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|     54|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (645:5): [True: 54, False: 256k]
  ------------------
  646|     54|      tbool = (ASN1_BOOLEAN *)pval;
  647|     54|      if (*tbool == ASN1_BOOLEAN_NONE) {
  ------------------
  |  |  432|     54|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
  |  Branch (647:11): [True: 0, False: 54]
  ------------------
  648|      0|        *out_omit = 1;
  649|      0|        return 0;
  650|      0|      }
  651|     54|      if (it->utype != V_ASN1_ANY) {
  ------------------
  |  |  121|     54|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (651:11): [True: 0, False: 54]
  ------------------
  652|       |        // Default handling if value == size field then omit
  653|      0|        if ((*tbool && (it->size > 0)) || (!*tbool && !it->size)) {
  ------------------
  |  Branch (653:14): [True: 0, False: 0]
  |  Branch (653:24): [True: 0, False: 0]
  |  Branch (653:44): [True: 0, False: 0]
  |  Branch (653:55): [True: 0, False: 0]
  ------------------
  654|      0|          *out_omit = 1;
  655|      0|          return 0;
  656|      0|        }
  657|      0|      }
  658|     54|      c = *tbool ? 0xff : 0x00;
  ------------------
  |  Branch (658:11): [True: 49, False: 5]
  ------------------
  659|     54|      cont = &c;
  660|     54|      len = 1;
  661|     54|      break;
  662|       |
  663|  20.8k|    case V_ASN1_BIT_STRING: {
  ------------------
  |  |  127|  20.8k|#define V_ASN1_BIT_STRING 3
  ------------------
  |  Branch (663:5): [True: 20.8k, False: 235k]
  ------------------
  664|  20.8k|      int ret =
  665|  20.8k|          i2c_ASN1_BIT_STRING((ASN1_BIT_STRING *)*pval, cout ? &cout : NULL);
  ------------------
  |  Branch (665:57): [True: 5.41k, False: 15.3k]
  ------------------
  666|       |      // |i2c_ASN1_BIT_STRING| returns zero on error instead of -1.
  667|  20.8k|      return ret <= 0 ? -1 : ret;
  ------------------
  |  Branch (667:14): [True: 0, False: 20.8k]
  ------------------
  668|     54|    }
  669|       |
  670|    212|    case V_ASN1_INTEGER:
  ------------------
  |  |  126|    212|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (670:5): [True: 212, False: 255k]
  ------------------
  671|  28.4k|    case V_ASN1_ENUMERATED: {
  ------------------
  |  |  134|  28.4k|#define V_ASN1_ENUMERATED 10
  ------------------
  |  Branch (671:5): [True: 28.2k, False: 227k]
  ------------------
  672|       |      // |i2c_ASN1_INTEGER| also handles ENUMERATED.
  673|  28.4k|      int ret = i2c_ASN1_INTEGER((ASN1_INTEGER *)*pval, cout ? &cout : NULL);
  ------------------
  |  Branch (673:57): [True: 5.69k, False: 22.7k]
  ------------------
  674|       |      // |i2c_ASN1_INTEGER| returns zero on error instead of -1.
  675|  28.4k|      return ret <= 0 ? -1 : ret;
  ------------------
  |  Branch (675:14): [True: 0, False: 28.4k]
  ------------------
  676|    212|    }
  677|       |
  678|      0|    case V_ASN1_OCTET_STRING:
  ------------------
  |  |  128|      0|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (678:5): [True: 0, False: 256k]
  ------------------
  679|      0|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|      0|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (679:5): [True: 0, False: 256k]
  ------------------
  680|      0|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|      0|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (680:5): [True: 0, False: 256k]
  ------------------
  681|      0|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|      0|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (681:5): [True: 0, False: 256k]
  ------------------
  682|      0|    case V_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  142|      0|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (682:5): [True: 0, False: 256k]
  ------------------
  683|      5|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|      5|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (683:5): [True: 5, False: 256k]
  ------------------
  684|      5|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|      5|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (684:5): [True: 0, False: 256k]
  ------------------
  685|      5|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|      5|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (685:5): [True: 0, False: 256k]
  ------------------
  686|     10|    case V_ASN1_GRAPHICSTRING:
  ------------------
  |  |  146|     10|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (686:5): [True: 5, False: 256k]
  ------------------
  687|     10|    case V_ASN1_VISIBLESTRING:
  ------------------
  |  |  148|     10|#define V_ASN1_VISIBLESTRING 26
  ------------------
  |  Branch (687:5): [True: 0, False: 256k]
  ------------------
  688|     14|    case V_ASN1_GENERALSTRING:
  ------------------
  |  |  149|     14|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (688:5): [True: 4, False: 256k]
  ------------------
  689|     14|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|     14|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (689:5): [True: 0, False: 256k]
  ------------------
  690|     19|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|     19|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (690:5): [True: 5, False: 256k]
  ------------------
  691|  9.33k|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|  9.33k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (691:5): [True: 9.31k, False: 246k]
  ------------------
  692|  72.6k|    case V_ASN1_SEQUENCE:
  ------------------
  |  |  136|  72.6k|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (692:5): [True: 63.2k, False: 192k]
  ------------------
  693|  72.6k|    case V_ASN1_SET:
  ------------------
  |  |  137|  72.6k|#define V_ASN1_SET 17
  ------------------
  |  Branch (693:5): [True: 32, False: 256k]
  ------------------
  694|       |    // This is not a valid |ASN1_ITEM| type, but it appears in |ASN1_TYPE|.
  695|  73.3k|    case V_ASN1_OTHER:
  ------------------
  |  |  118|  73.3k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (695:5): [True: 724, False: 255k]
  ------------------
  696|       |    // TODO(crbug.com/boringssl/412): This default case should be removed, now
  697|       |    // that we've resolved https://crbug.com/boringssl/561. However, it is still
  698|       |    // needed to support some edge cases in |ASN1_PRINTABLE|. |ASN1_PRINTABLE|
  699|       |    // broadly doesn't tolerate unrecognized universal tags, but except for
  700|       |    // eight values that map to |B_ASN1_UNKNOWN| instead of zero. See the
  701|       |    // X509Test.NameAttributeValues test.
  702|  75.5k|    default:
  ------------------
  |  Branch (702:5): [True: 2.17k, False: 254k]
  ------------------
  703|       |      // All based on ASN1_STRING and handled the same
  704|  75.5k|      strtmp = (ASN1_STRING *)*pval;
  705|  75.5k|      cont = strtmp->data;
  706|  75.5k|      len = strtmp->length;
  707|  75.5k|      break;
  708|   256k|  }
  709|   206k|  if (cout && len) {
  ------------------
  |  Branch (709:7): [True: 41.8k, False: 165k]
  |  Branch (709:15): [True: 40.6k, False: 1.20k]
  ------------------
  710|  40.6k|    OPENSSL_memcpy(cout, cont, len);
  711|  40.6k|  }
  712|   206k|  return len;
  713|   256k|}

ASN1_item_free:
   68|  82.3k|void ASN1_item_free(ASN1_VALUE *val, const ASN1_ITEM *it) {
   69|  82.3k|  ASN1_item_ex_free(&val, it);
   70|  82.3k|}
ASN1_item_ex_free:
   72|   306k|void ASN1_item_ex_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
   73|   306k|  const ASN1_TEMPLATE *tt = NULL, *seqtt;
   74|   306k|  const ASN1_EXTERN_FUNCS *ef;
   75|   306k|  int i;
   76|   306k|  if (!pval) {
  ------------------
  |  Branch (76:7): [True: 0, False: 306k]
  ------------------
   77|      0|    return;
   78|      0|  }
   79|   306k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) && !*pval) {
  ------------------
  |  |  487|   306k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (79:7): [True: 167k, False: 139k]
  |  Branch (79:46): [True: 23.3k, False: 144k]
  ------------------
   80|  23.3k|    return;
   81|  23.3k|  }
   82|       |
   83|   283k|  switch (it->itype) {
  ------------------
  |  Branch (83:11): [True: 0, False: 283k]
  ------------------
   84|   139k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   139k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (84:5): [True: 139k, False: 144k]
  ------------------
   85|   139k|      if (it->templates) {
  ------------------
  |  Branch (85:11): [True: 21.1k, False: 117k]
  ------------------
   86|  21.1k|        ASN1_template_free(pval, it->templates);
   87|   117k|      } else {
   88|   117k|        ASN1_primitive_free(pval, it);
   89|   117k|      }
   90|   139k|      break;
   91|       |
   92|  58.0k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  58.0k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (92:5): [True: 58.0k, False: 225k]
  ------------------
   93|  58.0k|      ASN1_primitive_free(pval, it);
   94|  58.0k|      break;
   95|       |
   96|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (96:5): [True: 0, False: 283k]
  ------------------
   97|      0|      const ASN1_AUX *aux = it->funcs;
   98|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (98:30): [True: 0, False: 0]
  ------------------
   99|      0|      if (asn1_cb) {
  ------------------
  |  Branch (99:11): [True: 0, False: 0]
  ------------------
  100|      0|        i = asn1_cb(ASN1_OP_FREE_PRE, pval, it, NULL);
  ------------------
  |  |  539|      0|#define ASN1_OP_FREE_PRE	2
  ------------------
  101|      0|        if (i == 2) {
  ------------------
  |  Branch (101:13): [True: 0, False: 0]
  ------------------
  102|      0|          return;
  103|      0|        }
  104|      0|      }
  105|      0|      i = asn1_get_choice_selector(pval, it);
  106|      0|      if ((i >= 0) && (i < it->tcount)) {
  ------------------
  |  Branch (106:11): [True: 0, False: 0]
  |  Branch (106:23): [True: 0, False: 0]
  ------------------
  107|      0|        ASN1_VALUE **pchval;
  108|      0|        tt = it->templates + i;
  109|      0|        pchval = asn1_get_field_ptr(pval, tt);
  110|      0|        ASN1_template_free(pchval, tt);
  111|      0|      }
  112|      0|      if (asn1_cb) {
  ------------------
  |  Branch (112:11): [True: 0, False: 0]
  ------------------
  113|      0|        asn1_cb(ASN1_OP_FREE_POST, pval, it, NULL);
  ------------------
  |  |  540|      0|#define ASN1_OP_FREE_POST	3
  ------------------
  114|      0|      }
  115|      0|      OPENSSL_free(*pval);
  116|      0|      *pval = NULL;
  117|      0|      break;
  118|      0|    }
  119|       |
  120|  10.2k|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|  10.2k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (120:5): [True: 10.2k, False: 273k]
  ------------------
  121|  10.2k|      ef = it->funcs;
  122|  10.2k|      if (ef && ef->asn1_ex_free) {
  ------------------
  |  Branch (122:11): [True: 10.2k, False: 0]
  |  Branch (122:17): [True: 10.2k, False: 0]
  ------------------
  123|  10.2k|        ef->asn1_ex_free(pval, it);
  124|  10.2k|      }
  125|  10.2k|      break;
  126|       |
  127|  76.2k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  76.2k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (127:5): [True: 76.2k, False: 207k]
  ------------------
  128|  76.2k|      if (!asn1_refcount_dec_and_test_zero(pval, it)) {
  ------------------
  |  Branch (128:11): [True: 0, False: 76.2k]
  ------------------
  129|      0|        return;
  130|      0|      }
  131|  76.2k|      const ASN1_AUX *aux = it->funcs;
  132|  76.2k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (132:30): [True: 10.2k, False: 65.9k]
  ------------------
  133|  76.2k|      if (asn1_cb) {
  ------------------
  |  Branch (133:11): [True: 5.12k, False: 71.0k]
  ------------------
  134|  5.12k|        i = asn1_cb(ASN1_OP_FREE_PRE, pval, it, NULL);
  ------------------
  |  |  539|  5.12k|#define ASN1_OP_FREE_PRE	2
  ------------------
  135|  5.12k|        if (i == 2) {
  ------------------
  |  Branch (135:13): [True: 0, False: 5.12k]
  ------------------
  136|      0|          return;
  137|      0|        }
  138|  5.12k|      }
  139|  76.2k|      asn1_enc_free(pval, it);
  140|       |      // If we free up as normal we will invalidate any ANY DEFINED BY
  141|       |      // field and we wont be able to determine the type of the field it
  142|       |      // defines. So free up in reverse order.
  143|  76.2k|      tt = it->templates + it->tcount - 1;
  144|   269k|      for (i = 0; i < it->tcount; tt--, i++) {
  ------------------
  |  Branch (144:19): [True: 193k, False: 76.2k]
  ------------------
  145|   193k|        ASN1_VALUE **pseqval;
  146|   193k|        seqtt = asn1_do_adb(pval, tt, 0);
  147|   193k|        if (!seqtt) {
  ------------------
  |  Branch (147:13): [True: 0, False: 193k]
  ------------------
  148|      0|          continue;
  149|      0|        }
  150|   193k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  151|   193k|        ASN1_template_free(pseqval, seqtt);
  152|   193k|      }
  153|  76.2k|      if (asn1_cb) {
  ------------------
  |  Branch (153:11): [True: 5.12k, False: 71.0k]
  ------------------
  154|  5.12k|        asn1_cb(ASN1_OP_FREE_POST, pval, it, NULL);
  ------------------
  |  |  540|  5.12k|#define ASN1_OP_FREE_POST	3
  ------------------
  155|  5.12k|      }
  156|  76.2k|      OPENSSL_free(*pval);
  157|  76.2k|      *pval = NULL;
  158|  76.2k|      break;
  159|  76.2k|    }
  160|   283k|  }
  161|   283k|}
ASN1_template_free:
  163|   236k|void ASN1_template_free(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  164|   236k|  if (tt->flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   236k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (164:7): [True: 28.8k, False: 207k]
  ------------------
  165|  28.8k|    STACK_OF(ASN1_VALUE) *sk = (STACK_OF(ASN1_VALUE) *)*pval;
  ------------------
  |  |   81|  28.8k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  166|  42.1k|    for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (166:24): [True: 13.2k, False: 28.8k]
  ------------------
  167|  13.2k|      ASN1_VALUE *vtmp = sk_ASN1_VALUE_value(sk, i);
  168|  13.2k|      ASN1_item_ex_free(&vtmp, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|  13.2k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  169|  13.2k|    }
  170|  28.8k|    sk_ASN1_VALUE_free(sk);
  171|  28.8k|    *pval = NULL;
  172|   207k|  } else {
  173|   207k|    ASN1_item_ex_free(pval, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|   207k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  174|   207k|  }
  175|   236k|}
ASN1_primitive_free:
  177|   175k|void ASN1_primitive_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  178|       |  // Historically, |it->funcs| for primitive types contained an
  179|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  180|   175k|  assert(it->funcs == NULL);
  181|       |
  182|   175k|  int utype = it->itype == ASN1_ITYPE_MSTRING ? -1 : it->utype;
  ------------------
  |  |  495|   175k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (182:15): [True: 58.0k, False: 117k]
  ------------------
  183|   175k|  switch (utype) {
  184|  60.8k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  60.8k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (184:5): [True: 60.8k, False: 115k]
  ------------------
  185|  60.8k|      ASN1_OBJECT_free((ASN1_OBJECT *)*pval);
  186|  60.8k|      break;
  187|       |
  188|    632|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|    632|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (188:5): [True: 632, False: 175k]
  ------------------
  189|    632|      if (it) {
  ------------------
  |  Branch (189:11): [True: 632, False: 0]
  ------------------
  190|    632|        *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  191|    632|      } else {
  192|      0|        *(ASN1_BOOLEAN *)pval = ASN1_BOOLEAN_NONE;
  ------------------
  |  |  432|      0|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
  193|      0|      }
  194|    632|      return;
  195|       |
  196|      0|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (196:5): [True: 0, False: 175k]
  ------------------
  197|      0|      break;
  198|       |
  199|  20.5k|    case V_ASN1_ANY:
  ------------------
  |  |  121|  20.5k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (199:5): [True: 20.5k, False: 155k]
  ------------------
  200|  20.5k|      if (*pval != NULL) {
  ------------------
  |  Branch (200:11): [True: 2.80k, False: 17.7k]
  ------------------
  201|  2.80k|        asn1_type_cleanup((ASN1_TYPE *)*pval);
  202|  2.80k|        OPENSSL_free(*pval);
  203|  2.80k|      }
  204|  20.5k|      break;
  205|       |
  206|  93.8k|    default:
  ------------------
  |  Branch (206:5): [True: 93.8k, False: 82.0k]
  ------------------
  207|  93.8k|      ASN1_STRING_free((ASN1_STRING *)*pval);
  208|  93.8k|      *pval = NULL;
  209|  93.8k|      break;
  210|   175k|  }
  211|   175k|  *pval = NULL;
  212|   175k|}

ASN1_item_new:
   76|  25.6k|ASN1_VALUE *ASN1_item_new(const ASN1_ITEM *it) {
   77|  25.6k|  ASN1_VALUE *ret = NULL;
   78|  25.6k|  if (ASN1_item_ex_new(&ret, it) > 0) {
  ------------------
  |  Branch (78:7): [True: 25.6k, False: 0]
  ------------------
   79|  25.6k|    return ret;
   80|  25.6k|  }
   81|      0|  return NULL;
   82|  25.6k|}
ASN1_item_ex_new:
   86|   218k|int ASN1_item_ex_new(ASN1_VALUE **pval, const ASN1_ITEM *it) {
   87|   218k|  const ASN1_TEMPLATE *tt = NULL;
   88|   218k|  const ASN1_EXTERN_FUNCS *ef;
   89|   218k|  ASN1_VALUE **pseqval;
   90|   218k|  int i;
   91|       |
   92|   218k|  switch (it->itype) {
  ------------------
  |  Branch (92:11): [True: 0, False: 218k]
  ------------------
   93|  10.2k|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|  10.2k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (93:5): [True: 10.2k, False: 208k]
  ------------------
   94|  10.2k|      ef = it->funcs;
   95|  10.2k|      if (ef && ef->asn1_ex_new) {
  ------------------
  |  Branch (95:11): [True: 10.2k, False: 0]
  |  Branch (95:17): [True: 10.2k, False: 0]
  ------------------
   96|  10.2k|        if (!ef->asn1_ex_new(pval, it)) {
  ------------------
  |  Branch (96:13): [True: 0, False: 10.2k]
  ------------------
   97|      0|          goto memerr;
   98|      0|        }
   99|  10.2k|      }
  100|  10.2k|      break;
  101|       |
  102|  74.2k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  74.2k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (102:5): [True: 74.2k, False: 144k]
  ------------------
  103|  74.2k|      if (it->templates) {
  ------------------
  |  Branch (103:11): [True: 0, False: 74.2k]
  ------------------
  104|      0|        if (!ASN1_template_new(pval, it->templates)) {
  ------------------
  |  Branch (104:13): [True: 0, False: 0]
  ------------------
  105|      0|          goto memerr;
  106|      0|        }
  107|  74.2k|      } else if (!ASN1_primitive_new(pval, it)) {
  ------------------
  |  Branch (107:18): [True: 0, False: 74.2k]
  ------------------
  108|      0|        goto memerr;
  109|      0|      }
  110|  74.2k|      break;
  111|       |
  112|  74.2k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  58.0k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (112:5): [True: 58.0k, False: 160k]
  ------------------
  113|  58.0k|      if (!ASN1_primitive_new(pval, it)) {
  ------------------
  |  Branch (113:11): [True: 0, False: 58.0k]
  ------------------
  114|      0|        goto memerr;
  115|      0|      }
  116|  58.0k|      break;
  117|       |
  118|  58.0k|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (118:5): [True: 0, False: 218k]
  ------------------
  119|      0|      const ASN1_AUX *aux = it->funcs;
  120|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (120:30): [True: 0, False: 0]
  ------------------
  121|      0|      if (asn1_cb) {
  ------------------
  |  Branch (121:11): [True: 0, False: 0]
  ------------------
  122|      0|        i = asn1_cb(ASN1_OP_NEW_PRE, pval, it, NULL);
  ------------------
  |  |  537|      0|#define ASN1_OP_NEW_PRE		0
  ------------------
  123|      0|        if (!i) {
  ------------------
  |  Branch (123:13): [True: 0, False: 0]
  ------------------
  124|      0|          goto auxerr;
  125|      0|        }
  126|      0|        if (i == 2) {
  ------------------
  |  Branch (126:13): [True: 0, False: 0]
  ------------------
  127|      0|          return 1;
  128|      0|        }
  129|      0|      }
  130|      0|      *pval = OPENSSL_malloc(it->size);
  131|      0|      if (!*pval) {
  ------------------
  |  Branch (131:11): [True: 0, False: 0]
  ------------------
  132|      0|        goto memerr;
  133|      0|      }
  134|      0|      OPENSSL_memset(*pval, 0, it->size);
  135|      0|      asn1_set_choice_selector(pval, -1, it);
  136|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_NEW_POST, pval, it, NULL)) {
  ------------------
  |  |  538|      0|#define ASN1_OP_NEW_POST	1
  ------------------
  |  Branch (136:11): [True: 0, False: 0]
  |  Branch (136:22): [True: 0, False: 0]
  ------------------
  137|      0|        goto auxerr2;
  138|      0|      }
  139|      0|      break;
  140|      0|    }
  141|       |
  142|  76.2k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  76.2k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (142:5): [True: 76.2k, False: 142k]
  ------------------
  143|  76.2k|      const ASN1_AUX *aux = it->funcs;
  144|  76.2k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (144:30): [True: 10.2k, False: 65.9k]
  ------------------
  145|  76.2k|      if (asn1_cb) {
  ------------------
  |  Branch (145:11): [True: 5.12k, False: 71.0k]
  ------------------
  146|  5.12k|        i = asn1_cb(ASN1_OP_NEW_PRE, pval, it, NULL);
  ------------------
  |  |  537|  5.12k|#define ASN1_OP_NEW_PRE		0
  ------------------
  147|  5.12k|        if (!i) {
  ------------------
  |  Branch (147:13): [True: 0, False: 5.12k]
  ------------------
  148|      0|          goto auxerr;
  149|      0|        }
  150|  5.12k|        if (i == 2) {
  ------------------
  |  Branch (150:13): [True: 0, False: 5.12k]
  ------------------
  151|      0|          return 1;
  152|      0|        }
  153|  5.12k|      }
  154|  76.2k|      *pval = OPENSSL_malloc(it->size);
  155|  76.2k|      if (!*pval) {
  ------------------
  |  Branch (155:11): [True: 0, False: 76.2k]
  ------------------
  156|      0|        goto memerr;
  157|      0|      }
  158|  76.2k|      OPENSSL_memset(*pval, 0, it->size);
  159|  76.2k|      asn1_refcount_set_one(pval, it);
  160|  76.2k|      asn1_enc_init(pval, it);
  161|   269k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (161:39): [True: 193k, False: 76.2k]
  ------------------
  162|   193k|        pseqval = asn1_get_field_ptr(pval, tt);
  163|   193k|        if (!ASN1_template_new(pseqval, tt)) {
  ------------------
  |  Branch (163:13): [True: 0, False: 193k]
  ------------------
  164|      0|          goto memerr2;
  165|      0|        }
  166|   193k|      }
  167|  76.2k|      if (asn1_cb && !asn1_cb(ASN1_OP_NEW_POST, pval, it, NULL)) {
  ------------------
  |  |  538|  5.12k|#define ASN1_OP_NEW_POST	1
  ------------------
  |  Branch (167:11): [True: 5.12k, False: 71.0k]
  |  Branch (167:22): [True: 0, False: 5.12k]
  ------------------
  168|      0|        goto auxerr2;
  169|      0|      }
  170|  76.2k|      break;
  171|  76.2k|    }
  172|   218k|  }
  173|   218k|  return 1;
  174|       |
  175|      0|memerr2:
  176|      0|  ASN1_item_ex_free(pval, it);
  177|      0|memerr:
  178|      0|  return 0;
  179|       |
  180|      0|auxerr2:
  181|      0|  ASN1_item_ex_free(pval, it);
  182|      0|auxerr:
  183|      0|  OPENSSL_PUT_ERROR(ASN1, ASN1_R_AUX_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  184|      0|  return 0;
  185|      0|}
tasn_new.c:ASN1_template_new:
  219|   193k|static int ASN1_template_new(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  220|   193k|  const ASN1_ITEM *it = ASN1_ITEM_ptr(tt->item);
  ------------------
  |  |  288|   193k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  221|   193k|  int ret;
  222|   193k|  if (tt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|   193k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (222:7): [True: 33.4k, False: 160k]
  ------------------
  223|  33.4k|    asn1_template_clear(pval, tt);
  224|  33.4k|    return 1;
  225|  33.4k|  }
  226|       |  // If ANY DEFINED BY nothing to do
  227|       |
  228|   160k|  if (tt->flags & ASN1_TFLG_ADB_MASK) {
  ------------------
  |  |  435|   160k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (228:7): [True: 0, False: 160k]
  ------------------
  229|      0|    *pval = NULL;
  230|      0|    return 1;
  231|      0|  }
  232|       |  // If SET OF or SEQUENCE OF, its a STACK
  233|   160k|  if (tt->flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   160k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (233:7): [True: 0, False: 160k]
  ------------------
  234|      0|    STACK_OF(ASN1_VALUE) *skval;
  ------------------
  |  |   81|      0|#define STACK_OF(type) struct stack_st_##type
  ------------------
  235|      0|    skval = sk_ASN1_VALUE_new_null();
  236|      0|    if (!skval) {
  ------------------
  |  Branch (236:9): [True: 0, False: 0]
  ------------------
  237|      0|      ret = 0;
  238|      0|      goto done;
  239|      0|    }
  240|      0|    *pval = (ASN1_VALUE *)skval;
  241|      0|    ret = 1;
  242|      0|    goto done;
  243|      0|  }
  244|       |  // Otherwise pass it back to the item routine
  245|   160k|  ret = ASN1_item_ex_new(pval, it);
  246|   160k|done:
  247|   160k|  return ret;
  248|   160k|}
tasn_new.c:asn1_template_clear:
  250|  33.4k|static void asn1_template_clear(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  251|       |  // If ADB or STACK just NULL the field
  252|  33.4k|  if (tt->flags & (ASN1_TFLG_ADB_MASK | ASN1_TFLG_SK_MASK)) {
  ------------------
  |  |  435|  33.4k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
                if (tt->flags & (ASN1_TFLG_ADB_MASK | ASN1_TFLG_SK_MASK)) {
  ------------------
  |  |  390|  33.4k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (252:7): [True: 5.12k, False: 28.3k]
  ------------------
  253|  5.12k|    *pval = NULL;
  254|  28.3k|  } else {
  255|  28.3k|    asn1_item_clear(pval, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|  28.3k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  256|  28.3k|  }
  257|  33.4k|}
tasn_new.c:asn1_item_clear:
  187|  28.3k|static void asn1_item_clear(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  188|  28.3k|  const ASN1_EXTERN_FUNCS *ef;
  189|       |
  190|  28.3k|  switch (it->itype) {
  ------------------
  |  Branch (190:11): [True: 0, False: 28.3k]
  ------------------
  191|      0|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|      0|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (191:5): [True: 0, False: 28.3k]
  ------------------
  192|      0|      ef = it->funcs;
  193|      0|      if (ef && ef->asn1_ex_clear) {
  ------------------
  |  Branch (193:11): [True: 0, False: 0]
  |  Branch (193:17): [True: 0, False: 0]
  ------------------
  194|      0|        ef->asn1_ex_clear(pval, it);
  195|      0|      } else {
  196|      0|        *pval = NULL;
  197|      0|      }
  198|      0|      break;
  199|       |
  200|  28.3k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  28.3k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (200:5): [True: 28.3k, False: 0]
  ------------------
  201|  28.3k|      if (it->templates) {
  ------------------
  |  Branch (201:11): [True: 0, False: 28.3k]
  ------------------
  202|      0|        asn1_template_clear(pval, it->templates);
  203|  28.3k|      } else {
  204|  28.3k|        asn1_primitive_clear(pval, it);
  205|  28.3k|      }
  206|  28.3k|      break;
  207|       |
  208|      0|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|      0|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (208:5): [True: 0, False: 28.3k]
  ------------------
  209|      0|      asn1_primitive_clear(pval, it);
  210|      0|      break;
  211|       |
  212|      0|    case ASN1_ITYPE_CHOICE:
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (212:5): [True: 0, False: 28.3k]
  ------------------
  213|      0|    case ASN1_ITYPE_SEQUENCE:
  ------------------
  |  |  489|      0|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (213:5): [True: 0, False: 28.3k]
  ------------------
  214|      0|      *pval = NULL;
  215|      0|      break;
  216|  28.3k|  }
  217|  28.3k|}
tasn_new.c:asn1_primitive_clear:
  311|  28.3k|static void asn1_primitive_clear(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  312|  28.3k|  int utype;
  313|       |  // Historically, |it->funcs| for primitive types contained an
  314|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  315|  28.3k|  assert(it == NULL || it->funcs == NULL);
  316|  28.3k|  if (!it || (it->itype == ASN1_ITYPE_MSTRING)) {
  ------------------
  |  |  495|  28.3k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (316:7): [True: 0, False: 28.3k]
  |  Branch (316:14): [True: 0, False: 28.3k]
  ------------------
  317|      0|    utype = -1;
  318|  28.3k|  } else {
  319|  28.3k|    utype = it->utype;
  320|  28.3k|  }
  321|  28.3k|  if (utype == V_ASN1_BOOLEAN) {
  ------------------
  |  |  125|  28.3k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (321:7): [True: 319, False: 28.0k]
  ------------------
  322|    319|    *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  323|  28.0k|  } else {
  324|  28.0k|    *pval = NULL;
  325|  28.0k|  }
  326|  28.3k|}
tasn_new.c:ASN1_primitive_new:
  262|   132k|static int ASN1_primitive_new(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  263|   132k|  if (!it) {
  ------------------
  |  Branch (263:7): [True: 0, False: 132k]
  ------------------
  264|      0|    return 0;
  265|      0|  }
  266|       |
  267|       |  // Historically, |it->funcs| for primitive types contained an
  268|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  269|   132k|  assert(it->funcs == NULL);
  270|       |
  271|   132k|  int utype;
  272|   132k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|   132k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (272:7): [True: 58.0k, False: 74.2k]
  ------------------
  273|  58.0k|    utype = -1;
  274|  74.2k|  } else {
  275|  74.2k|    utype = it->utype;
  276|  74.2k|  }
  277|   132k|  switch (utype) {
  278|  60.8k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  60.8k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (278:5): [True: 60.8k, False: 71.4k]
  ------------------
  279|  60.8k|      *pval = (ASN1_VALUE *)OBJ_nid2obj(NID_undef);
  ------------------
  |  |   85|  60.8k|#define NID_undef 0
  ------------------
  280|  60.8k|      return 1;
  281|       |
  282|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (282:5): [True: 0, False: 132k]
  ------------------
  283|      0|      *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  284|      0|      return 1;
  285|       |
  286|      0|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (286:5): [True: 0, False: 132k]
  ------------------
  287|      0|      *pval = (ASN1_VALUE *)1;
  288|      0|      return 1;
  289|       |
  290|  2.80k|    case V_ASN1_ANY: {
  ------------------
  |  |  121|  2.80k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (290:5): [True: 2.80k, False: 129k]
  ------------------
  291|  2.80k|      ASN1_TYPE *typ = OPENSSL_malloc(sizeof(ASN1_TYPE));
  292|  2.80k|      if (!typ) {
  ------------------
  |  Branch (292:11): [True: 0, False: 2.80k]
  ------------------
  293|      0|        return 0;
  294|      0|      }
  295|  2.80k|      typ->value.ptr = NULL;
  296|  2.80k|      typ->type = -1;
  297|  2.80k|      *pval = (ASN1_VALUE *)typ;
  298|  2.80k|      break;
  299|  2.80k|    }
  300|       |
  301|  68.6k|    default:
  ------------------
  |  Branch (301:5): [True: 68.6k, False: 63.6k]
  ------------------
  302|  68.6k|      *pval = (ASN1_VALUE *)ASN1_STRING_type_new(utype);
  303|  68.6k|      break;
  304|   132k|  }
  305|  71.4k|  if (*pval) {
  ------------------
  |  Branch (305:7): [True: 71.4k, False: 0]
  ------------------
  306|  71.4k|    return 1;
  307|  71.4k|  }
  308|      0|  return 0;
  309|  71.4k|}

ASN1_OCTET_STRING_free:
   67|  5.12k|  void sname##_free(sname *x) { ASN1_STRING_free(x); }
ASN1_INTEGER_new:
   66|    357|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \
ASN1_BIT_STRING_new:
   66|  2.41k|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \
ASN1_BIT_STRING_free:
   67|  5.17k|  void sname##_free(sname *x) { ASN1_STRING_free(x); }

asn1_refcount_set_one:
  106|  76.2k|void asn1_refcount_set_one(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  107|  76.2k|  CRYPTO_refcount_t *references = asn1_get_references(pval, it);
  108|  76.2k|  if (references != NULL) {
  ------------------
  |  Branch (108:7): [True: 0, False: 76.2k]
  ------------------
  109|      0|    *references = 1;
  110|      0|  }
  111|  76.2k|}
asn1_refcount_dec_and_test_zero:
  113|  76.2k|int asn1_refcount_dec_and_test_zero(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  114|  76.2k|  CRYPTO_refcount_t *references = asn1_get_references(pval, it);
  115|  76.2k|  if (references != NULL) {
  ------------------
  |  Branch (115:7): [True: 0, False: 76.2k]
  ------------------
  116|      0|    return CRYPTO_refcount_dec_and_test_zero(references);
  117|      0|  }
  118|  76.2k|  return 1;
  119|  76.2k|}
asn1_enc_init:
  134|  76.2k|void asn1_enc_init(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  135|  76.2k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  136|  76.2k|  if (enc) {
  ------------------
  |  Branch (136:7): [True: 5.12k, False: 71.0k]
  ------------------
  137|  5.12k|    enc->enc = NULL;
  138|  5.12k|    enc->len = 0;
  139|  5.12k|    enc->buf = NULL;
  140|  5.12k|  }
  141|  76.2k|}
asn1_enc_free:
  143|  76.2k|void asn1_enc_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  144|  76.2k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  145|  76.2k|  if (enc) {
  ------------------
  |  Branch (145:7): [True: 5.12k, False: 71.0k]
  ------------------
  146|  5.12k|    asn1_encoding_clear(enc);
  147|  5.12k|  }
  148|  76.2k|}
asn1_enc_save:
  151|  41.7k|                  const ASN1_ITEM *it, CRYPTO_BUFFER *buf) {
  152|  41.7k|  ASN1_ENCODING *enc;
  153|  41.7k|  enc = asn1_get_enc_ptr(pval, it);
  154|  41.7k|  if (!enc) {
  ------------------
  |  Branch (154:7): [True: 39.2k, False: 2.42k]
  ------------------
  155|  39.2k|    return 1;
  156|  39.2k|  }
  157|       |
  158|  2.42k|  asn1_encoding_clear(enc);
  159|  2.42k|  if (buf != NULL) {
  ------------------
  |  Branch (159:7): [True: 0, False: 2.42k]
  ------------------
  160|      0|    assert(CRYPTO_BUFFER_data(buf) <= in &&
  161|      0|           in + in_len <= CRYPTO_BUFFER_data(buf) + CRYPTO_BUFFER_len(buf));
  162|      0|    CRYPTO_BUFFER_up_ref(buf);
  163|      0|    enc->buf = buf;
  164|      0|    enc->enc = (uint8_t *)in;
  165|  2.42k|  } else {
  166|  2.42k|    enc->enc = OPENSSL_memdup(in, in_len);
  167|  2.42k|    if (!enc->enc) {
  ------------------
  |  Branch (167:9): [True: 0, False: 2.42k]
  ------------------
  168|      0|      return 0;
  169|      0|    }
  170|  2.42k|  }
  171|       |
  172|  2.42k|  enc->len = in_len;
  173|  2.42k|  return 1;
  174|  2.42k|}
asn1_encoding_clear:
  176|  7.55k|void asn1_encoding_clear(ASN1_ENCODING *enc) {
  177|  7.55k|  if (enc->buf != NULL) {
  ------------------
  |  Branch (177:7): [True: 0, False: 7.55k]
  ------------------
  178|      0|    CRYPTO_BUFFER_free(enc->buf);
  179|  7.55k|  } else {
  180|  7.55k|    OPENSSL_free(enc->enc);
  181|  7.55k|  }
  182|  7.55k|  enc->enc = NULL;
  183|  7.55k|  enc->len = 0;
  184|  7.55k|  enc->buf = NULL;
  185|  7.55k|}
asn1_enc_restore:
  188|  82.8k|                     const ASN1_ITEM *it) {
  189|  82.8k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  190|  82.8k|  if (!enc || enc->len == 0) {
  ------------------
  |  Branch (190:7): [True: 78.6k, False: 4.18k]
  |  Branch (190:15): [True: 0, False: 4.18k]
  ------------------
  191|  78.6k|    return 0;
  192|  78.6k|  }
  193|  4.18k|  if (out) {
  ------------------
  |  Branch (193:7): [True: 2.09k, False: 2.09k]
  ------------------
  194|  2.09k|    OPENSSL_memcpy(*out, enc->enc, enc->len);
  195|  2.09k|    *out += enc->len;
  196|  2.09k|  }
  197|  4.18k|  if (len) {
  ------------------
  |  Branch (197:7): [True: 4.18k, False: 0]
  ------------------
  198|  4.18k|    *len = enc->len;
  199|  4.18k|  }
  200|  4.18k|  return 1;
  201|  82.8k|}
asn1_get_field_ptr:
  204|   725k|ASN1_VALUE **asn1_get_field_ptr(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  205|   725k|  ASN1_VALUE **pvaltmp = offset2ptr(*pval, tt->offset);
  ------------------
  |  |   76|   725k|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  206|       |  // NOTE for BOOLEAN types the field is just a plain int so we can't return
  207|       |  // int **, so settle for (int *).
  208|   725k|  return pvaltmp;
  209|   725k|}
asn1_do_adb:
  214|   532k|                                 int nullerr) {
  215|   532k|  const ASN1_ADB *adb;
  216|   532k|  const ASN1_ADB_TABLE *atbl;
  217|   532k|  ASN1_VALUE **sfld;
  218|   532k|  int i;
  219|   532k|  if (!(tt->flags & ASN1_TFLG_ADB_MASK)) {
  ------------------
  |  |  435|   532k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (219:7): [True: 532k, False: 0]
  ------------------
  220|   532k|    return tt;
  221|   532k|  }
  222|       |
  223|       |  // Else ANY DEFINED BY ... get the table
  224|      0|  adb = ASN1_ADB_ptr(tt->item);
  ------------------
  |  |   79|      0|#define ASN1_ADB_ptr(iptr) ((const ASN1_ADB *)(iptr))
  ------------------
  225|       |
  226|       |  // Get the selector field
  227|      0|  sfld = offset2ptr(*pval, adb->offset);
  ------------------
  |  |   76|      0|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  228|       |
  229|       |  // Check if NULL
  230|      0|  if (*sfld == NULL) {
  ------------------
  |  Branch (230:7): [True: 0, False: 0]
  ------------------
  231|      0|    if (!adb->null_tt) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      goto err;
  233|      0|    }
  234|      0|    return adb->null_tt;
  235|      0|  }
  236|       |
  237|       |  // Convert type to a NID:
  238|       |  // NB: don't check for NID_undef here because it
  239|       |  // might be a legitimate value in the table
  240|      0|  assert(tt->flags & ASN1_TFLG_ADB_OID);
  241|      0|  int selector = OBJ_obj2nid((ASN1_OBJECT *)*sfld);
  242|       |
  243|       |  // Try to find matching entry in table Maybe should check application types
  244|       |  // first to allow application override? Might also be useful to have a flag
  245|       |  // which indicates table is sorted and we can do a binary search. For now
  246|       |  // stick to a linear search.
  247|       |
  248|      0|  for (atbl = adb->tbl, i = 0; i < adb->tblcount; i++, atbl++) {
  ------------------
  |  Branch (248:32): [True: 0, False: 0]
  ------------------
  249|      0|    if (atbl->value == selector) {
  ------------------
  |  Branch (249:9): [True: 0, False: 0]
  ------------------
  250|      0|      return &atbl->tt;
  251|      0|    }
  252|      0|  }
  253|       |
  254|       |  // FIXME: need to search application table too
  255|       |
  256|       |  // No match, return default type
  257|      0|  if (!adb->default_tt) {
  ------------------
  |  Branch (257:7): [True: 0, False: 0]
  ------------------
  258|      0|    goto err;
  259|      0|  }
  260|      0|  return adb->default_tt;
  261|       |
  262|      0|err:
  263|       |  // FIXME: should log the value or OID of unsupported type
  264|      0|  if (nullerr) {
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      0|  }
  267|      0|  return NULL;
  268|      0|}
tasn_utl.c:asn1_get_references:
   95|   152k|                                              const ASN1_ITEM *it) {
   96|   152k|  if (it->itype != ASN1_ITYPE_SEQUENCE) {
  ------------------
  |  |  489|   152k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (96:7): [True: 0, False: 152k]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|   152k|  const ASN1_AUX *aux = it->funcs;
  100|   152k|  if (!aux || !(aux->flags & ASN1_AFLG_REFCOUNT)) {
  ------------------
  |  |  531|  20.5k|#define ASN1_AFLG_REFCOUNT	1
  ------------------
  |  Branch (100:7): [True: 131k, False: 20.5k]
  |  Branch (100:15): [True: 20.5k, False: 0]
  ------------------
  101|   152k|    return NULL;
  102|   152k|  }
  103|      0|  return offset2ptr(*pval, aux->ref_offset);
  ------------------
  |  |   76|      0|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  104|   152k|}
tasn_utl.c:asn1_get_enc_ptr:
  121|   276k|static ASN1_ENCODING *asn1_get_enc_ptr(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  122|   276k|  assert(it->itype == ASN1_ITYPE_SEQUENCE);
  123|   276k|  const ASN1_AUX *aux;
  124|   276k|  if (!pval || !*pval) {
  ------------------
  |  Branch (124:7): [True: 0, False: 276k]
  |  Branch (124:16): [True: 0, False: 276k]
  ------------------
  125|      0|    return NULL;
  126|      0|  }
  127|   276k|  aux = it->funcs;
  128|   276k|  if (!aux || !(aux->flags & ASN1_AFLG_ENCODING)) {
  ------------------
  |  |  533|  33.7k|#define ASN1_AFLG_ENCODING	2
  ------------------
  |  Branch (128:7): [True: 243k, False: 33.7k]
  |  Branch (128:15): [True: 16.8k, False: 16.8k]
  ------------------
  129|   260k|    return NULL;
  130|   260k|  }
  131|  16.8k|  return offset2ptr(*pval, aux->enc_offset);
  ------------------
  |  |   76|  16.8k|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  132|   276k|}

BN_parse_asn1_unsigned:
   21|  2.23k|int BN_parse_asn1_unsigned(CBS *cbs, BIGNUM *ret) {
   22|  2.23k|  CBS child;
   23|  2.23k|  int is_negative;
   24|  2.23k|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  2.23k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (24:7): [True: 61, False: 2.17k]
  ------------------
   25|  2.23k|      !CBS_is_valid_asn1_integer(&child, &is_negative)) {
  ------------------
  |  Branch (25:7): [True: 1, False: 2.17k]
  ------------------
   26|     62|    OPENSSL_PUT_ERROR(BN, BN_R_BAD_ENCODING);
  ------------------
  |  |  441|     62|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   27|     62|    return 0;
   28|     62|  }
   29|       |
   30|  2.17k|  if (is_negative) {
  ------------------
  |  Branch (30:7): [True: 1, False: 2.17k]
  ------------------
   31|      1|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   32|      1|    return 0;
   33|      1|  }
   34|       |
   35|  2.17k|  return BN_bin2bn(CBS_data(&child), CBS_len(&child), ret) != NULL;
   36|  2.17k|}

BUF_MEM_new:
   67|  16.5k|BUF_MEM *BUF_MEM_new(void) {
   68|  16.5k|  BUF_MEM *ret;
   69|       |
   70|  16.5k|  ret = OPENSSL_malloc(sizeof(BUF_MEM));
   71|  16.5k|  if (ret == NULL) {
  ------------------
  |  Branch (71:7): [True: 0, False: 16.5k]
  ------------------
   72|      0|    return NULL;
   73|      0|  }
   74|       |
   75|  16.5k|  OPENSSL_memset(ret, 0, sizeof(BUF_MEM));
   76|  16.5k|  return ret;
   77|  16.5k|}
BUF_MEM_free:
   79|  16.5k|void BUF_MEM_free(BUF_MEM *buf) {
   80|  16.5k|  if (buf == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 16.5k]
  ------------------
   81|      0|    return;
   82|      0|  }
   83|       |
   84|  16.5k|  OPENSSL_free(buf->data);
   85|  16.5k|  OPENSSL_free(buf);
   86|  16.5k|}
BUF_MEM_reserve:
   88|  6.32k|int BUF_MEM_reserve(BUF_MEM *buf, size_t cap) {
   89|  6.32k|  if (buf->max >= cap) {
  ------------------
  |  Branch (89:7): [True: 0, False: 6.32k]
  ------------------
   90|      0|    return 1;
   91|      0|  }
   92|       |
   93|  6.32k|  size_t n = cap + 3;
   94|  6.32k|  if (n < cap) {
  ------------------
  |  Branch (94:7): [True: 0, False: 6.32k]
  ------------------
   95|      0|    OPENSSL_PUT_ERROR(BUF, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   96|      0|    return 0;
   97|      0|  }
   98|  6.32k|  n = n / 3;
   99|  6.32k|  size_t alloc_size = n * 4;
  100|  6.32k|  if (alloc_size / 4 != n) {
  ------------------
  |  Branch (100:7): [True: 0, False: 6.32k]
  ------------------
  101|      0|    OPENSSL_PUT_ERROR(BUF, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  102|      0|    return 0;
  103|      0|  }
  104|       |
  105|  6.32k|  char *new_buf = OPENSSL_realloc(buf->data, alloc_size);
  106|  6.32k|  if (new_buf == NULL) {
  ------------------
  |  Branch (106:7): [True: 0, False: 6.32k]
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|  6.32k|  buf->data = new_buf;
  111|  6.32k|  buf->max = alloc_size;
  112|  6.32k|  return 1;
  113|  6.32k|}
BUF_MEM_grow:
  115|  6.32k|size_t BUF_MEM_grow(BUF_MEM *buf, size_t len) {
  116|  6.32k|  if (!BUF_MEM_reserve(buf, len)) {
  ------------------
  |  Branch (116:7): [True: 0, False: 6.32k]
  ------------------
  117|      0|    return 0;
  118|      0|  }
  119|  6.32k|  if (buf->length < len) {
  ------------------
  |  Branch (119:7): [True: 6.32k, False: 0]
  ------------------
  120|  6.32k|    OPENSSL_memset(&buf->data[buf->length], 0, len - buf->length);
  121|  6.32k|  }
  122|  6.32k|  buf->length = len;
  123|  6.32k|  return len;
  124|  6.32k|}

CBB_finish_i2d:
   28|  2.09k|int CBB_finish_i2d(CBB *cbb, uint8_t **outp) {
   29|  2.09k|  assert(!cbb->is_child);
   30|  2.09k|  assert(cbb->u.base.can_resize);
   31|       |
   32|  2.09k|  uint8_t *der;
   33|  2.09k|  size_t der_len;
   34|  2.09k|  if (!CBB_finish(cbb, &der, &der_len)) {
  ------------------
  |  Branch (34:7): [True: 0, False: 2.09k]
  ------------------
   35|      0|    CBB_cleanup(cbb);
   36|      0|    return -1;
   37|      0|  }
   38|  2.09k|  if (der_len > INT_MAX) {
  ------------------
  |  Branch (38:7): [True: 0, False: 2.09k]
  ------------------
   39|      0|    OPENSSL_free(der);
   40|      0|    return -1;
   41|      0|  }
   42|  2.09k|  if (outp != NULL) {
  ------------------
  |  Branch (42:7): [True: 2.09k, False: 0]
  ------------------
   43|  2.09k|    if (*outp == NULL) {
  ------------------
  |  Branch (43:9): [True: 2.09k, False: 0]
  ------------------
   44|  2.09k|      *outp = der;
   45|  2.09k|      der = NULL;
   46|  2.09k|    } else {
   47|      0|      OPENSSL_memcpy(*outp, der, der_len);
   48|      0|      *outp += der_len;
   49|      0|    }
   50|  2.09k|  }
   51|  2.09k|  OPENSSL_free(der);
   52|  2.09k|  return (int)der_len;
   53|  2.09k|}

CBB_zero:
   27|  7.44k|void CBB_zero(CBB *cbb) {
   28|  7.44k|  OPENSSL_memset(cbb, 0, sizeof(CBB));
   29|  7.44k|}
CBB_init:
   41|  3.49k|int CBB_init(CBB *cbb, size_t initial_capacity) {
   42|  3.49k|  CBB_zero(cbb);
   43|       |
   44|  3.49k|  uint8_t *buf = OPENSSL_malloc(initial_capacity);
   45|  3.49k|  if (initial_capacity > 0 && buf == NULL) {
  ------------------
  |  Branch (45:7): [True: 3.49k, False: 0]
  |  Branch (45:31): [True: 0, False: 3.49k]
  ------------------
   46|      0|    return 0;
   47|      0|  }
   48|       |
   49|  3.49k|  cbb_init(cbb, buf, initial_capacity, /*can_resize=*/1);
   50|  3.49k|  return 1;
   51|  3.49k|}
CBB_cleanup:
   59|  3.49k|void CBB_cleanup(CBB *cbb) {
   60|       |  // Child |CBB|s are non-owning. They are implicitly discarded and should not
   61|       |  // be used with |CBB_cleanup| or |ScopedCBB|.
   62|  3.49k|  assert(!cbb->is_child);
   63|  3.49k|  if (cbb->is_child) {
  ------------------
  |  Branch (63:7): [True: 0, False: 3.49k]
  ------------------
   64|      0|    return;
   65|      0|  }
   66|       |
   67|  3.49k|  if (cbb->u.base.can_resize) {
  ------------------
  |  Branch (67:7): [True: 3.49k, False: 0]
  ------------------
   68|  3.49k|    OPENSSL_free(cbb->u.base.buf);
   69|  3.49k|  }
   70|  3.49k|}
CBB_finish:
  125|  3.49k|int CBB_finish(CBB *cbb, uint8_t **out_data, size_t *out_len) {
  126|  3.49k|  if (cbb->is_child) {
  ------------------
  |  Branch (126:7): [True: 0, False: 3.49k]
  ------------------
  127|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  128|      0|    return 0;
  129|      0|  }
  130|       |
  131|  3.49k|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (131:7): [True: 0, False: 3.49k]
  ------------------
  132|      0|    return 0;
  133|      0|  }
  134|       |
  135|  3.49k|  if (cbb->u.base.can_resize && (out_data == NULL || out_len == NULL)) {
  ------------------
  |  Branch (135:7): [True: 3.49k, False: 0]
  |  Branch (135:34): [True: 0, False: 3.49k]
  |  Branch (135:54): [True: 0, False: 3.49k]
  ------------------
  136|       |    // |out_data| and |out_len| can only be NULL if the CBB is fixed.
  137|      0|    return 0;
  138|      0|  }
  139|       |
  140|  3.49k|  if (out_data != NULL) {
  ------------------
  |  Branch (140:7): [True: 3.49k, False: 0]
  ------------------
  141|  3.49k|    *out_data = cbb->u.base.buf;
  142|  3.49k|  }
  143|  3.49k|  if (out_len != NULL) {
  ------------------
  |  Branch (143:7): [True: 3.49k, False: 0]
  ------------------
  144|  3.49k|    *out_len = cbb->u.base.len;
  145|  3.49k|  }
  146|  3.49k|  cbb->u.base.buf = NULL;
  147|  3.49k|  CBB_cleanup(cbb);
  148|  3.49k|  return 1;
  149|  3.49k|}
CBB_flush:
  161|  17.8M|int CBB_flush(CBB *cbb) {
  162|       |  // If |base| has hit an error, the buffer is in an undefined state, so
  163|       |  // fail all following calls. In particular, |cbb->child| may point to invalid
  164|       |  // memory.
  165|  17.8M|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  166|  17.8M|  if (base == NULL || base->error) {
  ------------------
  |  Branch (166:7): [True: 0, False: 17.8M]
  |  Branch (166:23): [True: 0, False: 17.8M]
  ------------------
  167|      0|    return 0;
  168|      0|  }
  169|       |
  170|  17.8M|  if (cbb->child == NULL) {
  ------------------
  |  Branch (170:7): [True: 17.8M, False: 2.09k]
  ------------------
  171|       |    // Nothing to flush.
  172|  17.8M|    return 1;
  173|  17.8M|  }
  174|       |
  175|  2.09k|  assert(cbb->child->is_child);
  176|  2.09k|  struct cbb_child_st *child = &cbb->child->u.child;
  177|  2.09k|  assert(child->base == base);
  178|  2.09k|  size_t child_start = child->offset + child->pending_len_len;
  179|       |
  180|  2.09k|  if (!CBB_flush(cbb->child) ||
  ------------------
  |  Branch (180:7): [True: 0, False: 2.09k]
  ------------------
  181|  2.09k|      child_start < child->offset ||
  ------------------
  |  Branch (181:7): [True: 0, False: 2.09k]
  ------------------
  182|  2.09k|      base->len < child_start) {
  ------------------
  |  Branch (182:7): [True: 0, False: 2.09k]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|  2.09k|  size_t len = base->len - child_start;
  187|       |
  188|  2.09k|  if (child->pending_is_asn1) {
  ------------------
  |  Branch (188:7): [True: 2.09k, False: 0]
  ------------------
  189|       |    // For ASN.1 we assume that we'll only need a single byte for the length.
  190|       |    // If that turned out to be incorrect, we have to move the contents along
  191|       |    // in order to make space.
  192|  2.09k|    uint8_t len_len;
  193|  2.09k|    uint8_t initial_length_byte;
  194|       |
  195|  2.09k|    assert (child->pending_len_len == 1);
  196|       |
  197|  2.09k|    if (len > 0xfffffffe) {
  ------------------
  |  Branch (197:9): [True: 0, False: 2.09k]
  ------------------
  198|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  199|       |      // Too large.
  200|      0|      goto err;
  201|  2.09k|    } else if (len > 0xffffff) {
  ------------------
  |  Branch (201:16): [True: 0, False: 2.09k]
  ------------------
  202|      0|      len_len = 5;
  203|      0|      initial_length_byte = 0x80 | 4;
  204|  2.09k|    } else if (len > 0xffff) {
  ------------------
  |  Branch (204:16): [True: 182, False: 1.90k]
  ------------------
  205|    182|      len_len = 4;
  206|    182|      initial_length_byte = 0x80 | 3;
  207|  1.90k|    } else if (len > 0xff) {
  ------------------
  |  Branch (207:16): [True: 433, False: 1.47k]
  ------------------
  208|    433|      len_len = 3;
  209|    433|      initial_length_byte = 0x80 | 2;
  210|  1.47k|    } else if (len > 0x7f) {
  ------------------
  |  Branch (210:16): [True: 505, False: 971]
  ------------------
  211|    505|      len_len = 2;
  212|    505|      initial_length_byte = 0x80 | 1;
  213|    971|    } else {
  214|    971|      len_len = 1;
  215|    971|      initial_length_byte = (uint8_t)len;
  216|    971|      len = 0;
  217|    971|    }
  218|       |
  219|  2.09k|    if (len_len != 1) {
  ------------------
  |  Branch (219:9): [True: 1.12k, False: 971]
  ------------------
  220|       |      // We need to move the contents along in order to make space.
  221|  1.12k|      size_t extra_bytes = len_len - 1;
  222|  1.12k|      if (!cbb_buffer_add(base, NULL, extra_bytes)) {
  ------------------
  |  Branch (222:11): [True: 0, False: 1.12k]
  ------------------
  223|      0|        goto err;
  224|      0|      }
  225|  1.12k|      OPENSSL_memmove(base->buf + child_start + extra_bytes,
  226|  1.12k|                      base->buf + child_start, len);
  227|  1.12k|    }
  228|  2.09k|    base->buf[child->offset++] = initial_length_byte;
  229|  2.09k|    child->pending_len_len = len_len - 1;
  230|  2.09k|  }
  231|       |
  232|  4.00k|  for (size_t i = child->pending_len_len - 1; i < child->pending_len_len; i--) {
  ------------------
  |  Branch (232:47): [True: 1.91k, False: 2.09k]
  ------------------
  233|  1.91k|    base->buf[child->offset + i] = (uint8_t)len;
  234|  1.91k|    len >>= 8;
  235|  1.91k|  }
  236|  2.09k|  if (len != 0) {
  ------------------
  |  Branch (236:7): [True: 0, False: 2.09k]
  ------------------
  237|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|       |
  241|  2.09k|  child->base = NULL;
  242|  2.09k|  cbb->child = NULL;
  243|       |
  244|  2.09k|  return 1;
  245|       |
  246|      0|err:
  247|      0|  base->error = 1;
  248|      0|  return 0;
  249|  2.09k|}
CBB_add_asn1:
  342|  2.09k|int CBB_add_asn1(CBB *cbb, CBB *out_contents, CBS_ASN1_TAG tag) {
  343|  2.09k|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (343:7): [True: 0, False: 2.09k]
  ------------------
  344|      0|    return 0;
  345|      0|  }
  346|       |
  347|       |  // Split the tag into leading bits and tag number.
  348|  2.09k|  uint8_t tag_bits = (tag >> CBS_ASN1_TAG_SHIFT) & 0xe0;
  ------------------
  |  |  193|  2.09k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  349|  2.09k|  CBS_ASN1_TAG tag_number = tag & CBS_ASN1_TAG_NUMBER_MASK;
  ------------------
  |  |  210|  2.09k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  2.09k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  350|  2.09k|  if (tag_number >= 0x1f) {
  ------------------
  |  Branch (350:7): [True: 0, False: 2.09k]
  ------------------
  351|       |    // Set all the bits in the tag number to signal high tag number form.
  352|      0|    if (!CBB_add_u8(cbb, tag_bits | 0x1f) ||
  ------------------
  |  Branch (352:9): [True: 0, False: 0]
  ------------------
  353|      0|        !add_base128_integer(cbb, tag_number)) {
  ------------------
  |  Branch (353:9): [True: 0, False: 0]
  ------------------
  354|      0|      return 0;
  355|      0|    }
  356|  2.09k|  } else if (!CBB_add_u8(cbb, tag_bits | tag_number)) {
  ------------------
  |  Branch (356:14): [True: 0, False: 2.09k]
  ------------------
  357|      0|    return 0;
  358|      0|  }
  359|       |
  360|       |  // Reserve one byte of length prefix. |CBB_flush| will finish it later.
  361|  2.09k|  return cbb_add_child(cbb, out_contents, /*len_len=*/1, /*is_asn1=*/1);
  362|  2.09k|}
CBB_add_space:
  382|  17.8M|int CBB_add_space(CBB *cbb, uint8_t **out_data, size_t len) {
  383|  17.8M|  if (!CBB_flush(cbb) ||
  ------------------
  |  Branch (383:7): [True: 0, False: 17.8M]
  ------------------
  384|  17.8M|      !cbb_buffer_add(cbb_get_base(cbb), out_data, len)) {
  ------------------
  |  Branch (384:7): [True: 0, False: 17.8M]
  ------------------
  385|      0|    return 0;
  386|      0|  }
  387|  17.8M|  return 1;
  388|  17.8M|}
CBB_add_u8:
  430|  17.8M|int CBB_add_u8(CBB *cbb, uint8_t value) {
  431|  17.8M|  return cbb_add_u(cbb, value, 1);
  432|  17.8M|}
cbb.c:cbb_init:
   31|  3.49k|static void cbb_init(CBB *cbb, uint8_t *buf, size_t cap, int can_resize) {
   32|  3.49k|  cbb->is_child = 0;
   33|  3.49k|  cbb->child = NULL;
   34|  3.49k|  cbb->u.base.buf = buf;
   35|  3.49k|  cbb->u.base.len = 0;
   36|  3.49k|  cbb->u.base.cap = cap;
   37|  3.49k|  cbb->u.base.can_resize = can_resize;
   38|  3.49k|  cbb->u.base.error = 0;
   39|  3.49k|}
cbb.c:cbb_get_base:
  151|  35.6M|static struct cbb_buffer_st *cbb_get_base(CBB *cbb) {
  152|  35.6M|  if (cbb->is_child) {
  ------------------
  |  Branch (152:7): [True: 14.6k, False: 35.6M]
  ------------------
  153|  14.6k|    return cbb->u.child.base;
  154|  14.6k|  }
  155|  35.6M|  return &cbb->u.base;
  156|  35.6M|}
cbb.c:cbb_buffer_add:
  116|  17.8M|                          size_t len) {
  117|  17.8M|  if (!cbb_buffer_reserve(base, out, len)) {
  ------------------
  |  Branch (117:7): [True: 0, False: 17.8M]
  ------------------
  118|      0|    return 0;
  119|      0|  }
  120|       |  // This will not overflow or |cbb_buffer_reserve| would have failed.
  121|  17.8M|  base->len += len;
  122|  17.8M|  return 1;
  123|  17.8M|}
cbb.c:cbb_add_child:
  272|  2.09k|                         int is_asn1) {
  273|  2.09k|  assert(cbb->child == NULL);
  274|  2.09k|  assert(!is_asn1 || len_len == 1);
  275|  2.09k|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  276|  2.09k|  size_t offset = base->len;
  277|       |
  278|       |  // Reserve space for the length prefix.
  279|  2.09k|  uint8_t *prefix_bytes;
  280|  2.09k|  if (!cbb_buffer_add(base, &prefix_bytes, len_len)) {
  ------------------
  |  Branch (280:7): [True: 0, False: 2.09k]
  ------------------
  281|      0|    return 0;
  282|      0|  }
  283|  2.09k|  OPENSSL_memset(prefix_bytes, 0, len_len);
  284|       |
  285|  2.09k|  CBB_zero(out_child);
  286|  2.09k|  out_child->is_child = 1;
  287|  2.09k|  out_child->u.child.base = base;
  288|  2.09k|  out_child->u.child.offset = offset;
  289|  2.09k|  out_child->u.child.pending_len_len = len_len;
  290|  2.09k|  out_child->u.child.pending_is_asn1 = is_asn1;
  291|  2.09k|  cbb->child = out_child;
  292|  2.09k|  return 1;
  293|  2.09k|}
cbb.c:cbb_buffer_reserve:
   73|  17.8M|                              size_t len) {
   74|  17.8M|  if (base == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 17.8M]
  ------------------
   75|      0|    return 0;
   76|      0|  }
   77|       |
   78|  17.8M|  size_t newlen = base->len + len;
   79|  17.8M|  if (newlen < base->len) {
  ------------------
  |  Branch (79:7): [True: 0, False: 17.8M]
  ------------------
   80|       |    // Overflow
   81|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   82|      0|    goto err;
   83|      0|  }
   84|       |
   85|  17.8M|  if (newlen > base->cap) {
  ------------------
  |  Branch (85:7): [True: 3.32k, False: 17.8M]
  ------------------
   86|  3.32k|    if (!base->can_resize) {
  ------------------
  |  Branch (86:9): [True: 0, False: 3.32k]
  ------------------
   87|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   88|      0|      goto err;
   89|      0|    }
   90|       |
   91|  3.32k|    size_t newcap = base->cap * 2;
   92|  3.32k|    if (newcap < base->cap || newcap < newlen) {
  ------------------
  |  Branch (92:9): [True: 0, False: 3.32k]
  |  Branch (92:31): [True: 964, False: 2.35k]
  ------------------
   93|    964|      newcap = newlen;
   94|    964|    }
   95|  3.32k|    uint8_t *newbuf = OPENSSL_realloc(base->buf, newcap);
   96|  3.32k|    if (newbuf == NULL) {
  ------------------
  |  Branch (96:9): [True: 0, False: 3.32k]
  ------------------
   97|      0|      goto err;
   98|      0|    }
   99|       |
  100|  3.32k|    base->buf = newbuf;
  101|  3.32k|    base->cap = newcap;
  102|  3.32k|  }
  103|       |
  104|  17.8M|  if (out) {
  ------------------
  |  Branch (104:7): [True: 17.8M, False: 1.12k]
  ------------------
  105|  17.8M|    *out = base->buf + base->len;
  106|  17.8M|  }
  107|       |
  108|  17.8M|  return 1;
  109|       |
  110|      0|err:
  111|      0|  base->error = 1;
  112|      0|  return 0;
  113|  17.8M|}
cbb.c:cbb_add_u:
  410|  17.8M|static int cbb_add_u(CBB *cbb, uint64_t v, size_t len_len) {
  411|  17.8M|  uint8_t *buf;
  412|  17.8M|  if (!CBB_add_space(cbb, &buf, len_len)) {
  ------------------
  |  Branch (412:7): [True: 0, False: 17.8M]
  ------------------
  413|      0|    return 0;
  414|      0|  }
  415|       |
  416|  35.6M|  for (size_t i = len_len - 1; i < len_len; i--) {
  ------------------
  |  Branch (416:32): [True: 17.8M, False: 17.8M]
  ------------------
  417|  17.8M|    buf[i] = v;
  418|  17.8M|    v >>= 8;
  419|  17.8M|  }
  420|       |
  421|       |  // |v| must fit in |len_len| bytes.
  422|  17.8M|  if (v != 0) {
  ------------------
  |  Branch (422:7): [True: 0, False: 17.8M]
  ------------------
  423|      0|    cbb_get_base(cbb)->error = 1;
  424|      0|    return 0;
  425|      0|  }
  426|       |
  427|  17.8M|  return 1;
  428|  17.8M|}

CBS_init:
   29|   600k|void CBS_init(CBS *cbs, const uint8_t *data, size_t len) {
   30|   600k|  cbs->data = data;
   31|   600k|  cbs->len = len;
   32|   600k|}
CBS_skip:
   45|   252k|int CBS_skip(CBS *cbs, size_t len) {
   46|   252k|  const uint8_t *dummy;
   47|   252k|  return cbs_get(cbs, &dummy, len);
   48|   252k|}
CBS_data:
   50|   316k|const uint8_t *CBS_data(const CBS *cbs) {
   51|   316k|  return cbs->data;
   52|   316k|}
CBS_len:
   54|  21.8M|size_t CBS_len(const CBS *cbs) {
   55|  21.8M|  return cbs->len;
   56|  21.8M|}
CBS_get_u8:
  108|  10.6M|int CBS_get_u8(CBS *cbs, uint8_t *out) {
  109|  10.6M|  const uint8_t *v;
  110|  10.6M|  if (!cbs_get(cbs, &v, 1)) {
  ------------------
  |  Branch (110:7): [True: 46.1k, False: 10.5M]
  ------------------
  111|  46.1k|    return 0;
  112|  46.1k|  }
  113|  10.5M|  *out = *v;
  114|  10.5M|  return 1;
  115|  10.6M|}
CBS_get_u16:
  117|  15.9M|int CBS_get_u16(CBS *cbs, uint16_t *out) {
  118|  15.9M|  uint64_t v;
  119|  15.9M|  if (!cbs_get_u(cbs, &v, 2)) {
  ------------------
  |  Branch (119:7): [True: 23, False: 15.9M]
  ------------------
  120|     23|    return 0;
  121|     23|  }
  122|  15.9M|  *out = v;
  123|  15.9M|  return 1;
  124|  15.9M|}
CBS_get_u32:
  143|  2.12k|int CBS_get_u32(CBS *cbs, uint32_t *out) {
  144|  2.12k|  uint64_t v;
  145|  2.12k|  if (!cbs_get_u(cbs, &v, 4)) {
  ------------------
  |  Branch (145:7): [True: 13, False: 2.11k]
  ------------------
  146|     13|    return 0;
  147|     13|  }
  148|  2.11k|  *out = (uint32_t)v;
  149|  2.11k|  return 1;
  150|  2.12k|}
CBS_get_bytes:
  181|   261k|int CBS_get_bytes(CBS *cbs, CBS *out, size_t len) {
  182|   261k|  const uint8_t *v;
  183|   261k|  if (!cbs_get(cbs, &v, len)) {
  ------------------
  |  Branch (183:7): [True: 342, False: 261k]
  ------------------
  184|    342|    return 0;
  185|    342|  }
  186|   261k|  CBS_init(out, v, len);
  187|   261k|  return 1;
  188|   261k|}
CBS_get_any_asn1:
  421|   227k|int CBS_get_any_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG *out_tag) {
  422|   227k|  size_t header_len;
  423|   227k|  if (!CBS_get_any_asn1_element(cbs, out, out_tag, &header_len)) {
  ------------------
  |  Branch (423:7): [True: 313, False: 226k]
  ------------------
  424|    313|    return 0;
  425|    313|  }
  426|       |
  427|   226k|  if (!CBS_skip(out, header_len)) {
  ------------------
  |  Branch (427:7): [True: 0, False: 226k]
  ------------------
  428|      0|    assert(0);
  429|      0|    return 0;
  430|      0|  }
  431|       |
  432|   226k|  return 1;
  433|   226k|}
CBS_get_any_asn1_element:
  436|   256k|                                    size_t *out_header_len) {
  437|   256k|  return cbs_get_any_asn1_element(cbs, out, out_tag, out_header_len, NULL, NULL,
  438|   256k|                                  /*ber_ok=*/0);
  439|   256k|}
CBS_get_any_ber_asn1_element:
  443|  5.24k|                                 int *out_indefinite) {
  444|  5.24k|  int ber_found_temp;
  445|  5.24k|  return cbs_get_any_asn1_element(
  446|  5.24k|      cbs, out, out_tag, out_header_len,
  447|  5.24k|      out_ber_found ? out_ber_found : &ber_found_temp, out_indefinite,
  ------------------
  |  Branch (447:7): [True: 0, False: 5.24k]
  ------------------
  448|  5.24k|      /*ber_ok=*/1);
  449|  5.24k|}
CBS_get_asn1:
  474|  19.0k|int CBS_get_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  475|  19.0k|  return cbs_get_asn1(cbs, out, tag_value, 1 /* skip header */);
  476|  19.0k|}
CBS_get_asn1_element:
  478|  10.8k|int CBS_get_asn1_element(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  479|  10.8k|  return cbs_get_asn1(cbs, out, tag_value, 0 /* include header */);
  480|  10.8k|}
CBS_is_valid_asn1_integer:
  671|  13.2k|int CBS_is_valid_asn1_integer(const CBS *cbs, int *out_is_negative) {
  672|  13.2k|  CBS copy = *cbs;
  673|  13.2k|  uint8_t first_byte, second_byte;
  674|  13.2k|  if (!CBS_get_u8(&copy, &first_byte)) {
  ------------------
  |  Branch (674:7): [True: 2, False: 13.2k]
  ------------------
  675|      2|    return 0;  // INTEGERs may not be empty.
  676|      2|  }
  677|  13.2k|  if (out_is_negative != NULL) {
  ------------------
  |  Branch (677:7): [True: 13.2k, False: 0]
  ------------------
  678|  13.2k|    *out_is_negative = (first_byte & 0x80) != 0;
  679|  13.2k|  }
  680|  13.2k|  if (!CBS_get_u8(&copy, &second_byte)) {
  ------------------
  |  Branch (680:7): [True: 6.71k, False: 6.50k]
  ------------------
  681|  6.71k|    return 1;  // One byte INTEGERs are always minimal.
  682|  6.71k|  }
  683|  6.50k|  if ((first_byte == 0x00 && (second_byte & 0x80) == 0) ||
  ------------------
  |  Branch (683:8): [True: 532, False: 5.97k]
  |  Branch (683:30): [True: 6, False: 526]
  ------------------
  684|  6.50k|      (first_byte == 0xff && (second_byte & 0x80) != 0)) {
  ------------------
  |  Branch (684:8): [True: 1.72k, False: 4.77k]
  |  Branch (684:30): [True: 9, False: 1.71k]
  ------------------
  685|     15|    return 0;  // The value is minimal iff the first 9 bits are not all equal.
  686|     15|  }
  687|  6.49k|  return 1;
  688|  6.50k|}
CBS_is_valid_asn1_oid:
  701|  35.7k|int CBS_is_valid_asn1_oid(const CBS *cbs) {
  702|  35.7k|  if (CBS_len(cbs) == 0) {
  ------------------
  |  Branch (702:7): [True: 1, False: 35.7k]
  ------------------
  703|      1|    return 0;  // OID encodings cannot be empty.
  704|      1|  }
  705|       |
  706|  35.7k|  CBS copy = *cbs;
  707|  35.7k|  uint8_t v, prev = 0;
  708|  5.22M|  while (CBS_get_u8(&copy, &v)) {
  ------------------
  |  Branch (708:10): [True: 5.19M, False: 35.7k]
  ------------------
  709|       |    // OID encodings are a sequence of minimally-encoded base-128 integers (see
  710|       |    // |parse_base128_integer|). If |prev|'s MSB was clear, it was the last byte
  711|       |    // of an integer (or |v| is the first byte). |v| is then the first byte of
  712|       |    // the next integer. If first byte of an integer is 0x80, it is not
  713|       |    // minimally-encoded.
  714|  5.19M|    if ((prev & 0x80) == 0 && v == 0x80) {
  ------------------
  |  Branch (714:9): [True: 5.18M, False: 4.94k]
  |  Branch (714:31): [True: 1, False: 5.18M]
  ------------------
  715|      1|      return 0;
  716|      1|    }
  717|  5.19M|    prev = v;
  718|  5.19M|  }
  719|       |
  720|       |  // The last byte should must end an integer encoding.
  721|  35.7k|  return (prev & 0x80) == 0;
  722|  35.7k|}
CBS_parse_generalized_time:
  919|    616|                               int allow_timezone_offset) {
  920|    616|  return CBS_parse_rfc5280_time_internal(cbs, 1, allow_timezone_offset, out_tm);
  921|    616|}
CBS_parse_utc_time:
  924|  4.73k|                       int allow_timezone_offset) {
  925|  4.73k|  return CBS_parse_rfc5280_time_internal(cbs, 0, allow_timezone_offset, out_tm);
  926|  4.73k|}
cbs.c:cbs_get:
   34|  27.0M|static int cbs_get(CBS *cbs, const uint8_t **p, size_t n) {
   35|  27.0M|  if (cbs->len < n) {
  ------------------
  |  Branch (35:7): [True: 46.4k, False: 27.0M]
  ------------------
   36|  46.4k|    return 0;
   37|  46.4k|  }
   38|       |
   39|  27.0M|  *p = cbs->data;
   40|  27.0M|  cbs->data += n;
   41|  27.0M|  cbs->len -= n;
   42|  27.0M|  return 1;
   43|  27.0M|}
cbs.c:cbs_get_u:
   93|  15.9M|static int cbs_get_u(CBS *cbs, uint64_t *out, size_t len) {
   94|  15.9M|  uint64_t result = 0;
   95|  15.9M|  const uint8_t *data;
   96|       |
   97|  15.9M|  if (!cbs_get(cbs, &data, len)) {
  ------------------
  |  Branch (97:7): [True: 40, False: 15.9M]
  ------------------
   98|     40|    return 0;
   99|     40|  }
  100|  47.8M|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (100:22): [True: 31.8M, False: 15.9M]
  ------------------
  101|  31.8M|    result <<= 8;
  102|  31.8M|    result |= data[i];
  103|  31.8M|  }
  104|  15.9M|  *out = result;
  105|  15.9M|  return 1;
  106|  15.9M|}
cbs.c:cbs_get_any_asn1_element:
  322|   262k|                                    int *out_indefinite, int ber_ok) {
  323|   262k|  CBS header = *cbs;
  324|   262k|  CBS throwaway;
  325|       |
  326|   262k|  if (out == NULL) {
  ------------------
  |  Branch (326:7): [True: 0, False: 262k]
  ------------------
  327|      0|    out = &throwaway;
  328|      0|  }
  329|   262k|  if (ber_ok) {
  ------------------
  |  Branch (329:7): [True: 5.24k, False: 256k]
  ------------------
  330|  5.24k|    *out_ber_found = 0;
  331|  5.24k|    *out_indefinite = 0;
  332|   256k|  } else {
  333|   256k|    assert(out_ber_found == NULL);
  334|   256k|    assert(out_indefinite == NULL);
  335|   256k|  }
  336|       |
  337|   262k|  CBS_ASN1_TAG tag;
  338|   262k|  if (!parse_asn1_tag(&header, &tag)) {
  ------------------
  |  Branch (338:7): [True: 412, False: 261k]
  ------------------
  339|    412|    return 0;
  340|    412|  }
  341|   261k|  if (out_tag != NULL) {
  ------------------
  |  Branch (341:7): [True: 261k, False: 0]
  ------------------
  342|   261k|    *out_tag = tag;
  343|   261k|  }
  344|       |
  345|   261k|  uint8_t length_byte;
  346|   261k|  if (!CBS_get_u8(&header, &length_byte)) {
  ------------------
  |  Branch (346:7): [True: 46, False: 261k]
  ------------------
  347|     46|    return 0;
  348|     46|  }
  349|       |
  350|   261k|  size_t header_len = CBS_len(cbs) - CBS_len(&header);
  351|       |
  352|   261k|  size_t len;
  353|       |  // The format for the length encoding is specified in ITU-T X.690 section
  354|       |  // 8.1.3.
  355|   261k|  if ((length_byte & 0x80) == 0) {
  ------------------
  |  Branch (355:7): [True: 247k, False: 14.2k]
  ------------------
  356|       |    // Short form length.
  357|   247k|    len = ((size_t) length_byte) + header_len;
  358|   247k|    if (out_header_len != NULL) {
  ------------------
  |  Branch (358:9): [True: 247k, False: 0]
  ------------------
  359|   247k|      *out_header_len = header_len;
  360|   247k|    }
  361|   247k|  } else {
  362|       |    // The high bit indicate that this is the long form, while the next 7 bits
  363|       |    // encode the number of subsequent octets used to encode the length (ITU-T
  364|       |    // X.690 clause 8.1.3.5.b).
  365|  14.2k|    const size_t num_bytes = length_byte & 0x7f;
  366|  14.2k|    uint64_t len64;
  367|       |
  368|  14.2k|    if (ber_ok && (tag & CBS_ASN1_CONSTRUCTED) != 0 && num_bytes == 0) {
  ------------------
  |  |  196|    131|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|    131|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (368:9): [True: 131, False: 14.1k]
  |  Branch (368:19): [True: 48, False: 83]
  |  Branch (368:56): [True: 38, False: 10]
  ------------------
  369|       |      // indefinite length
  370|     38|      if (out_header_len != NULL) {
  ------------------
  |  Branch (370:11): [True: 38, False: 0]
  ------------------
  371|     38|        *out_header_len = header_len;
  372|     38|      }
  373|     38|      *out_ber_found = 1;
  374|     38|      *out_indefinite = 1;
  375|     38|      return CBS_get_bytes(cbs, out, header_len);
  376|     38|    }
  377|       |
  378|       |    // ITU-T X.690 clause 8.1.3.5.c specifies that the value 0xff shall not be
  379|       |    // used as the first byte of the length. If this parser encounters that
  380|       |    // value, num_bytes will be parsed as 127, which will fail this check.
  381|  14.2k|    if (num_bytes == 0 || num_bytes > 4) {
  ------------------
  |  Branch (381:9): [True: 83, False: 14.1k]
  |  Branch (381:27): [True: 21, False: 14.0k]
  ------------------
  382|    104|      return 0;
  383|    104|    }
  384|  14.0k|    if (!cbs_get_u(&header, &len64, num_bytes)) {
  ------------------
  |  Branch (384:9): [True: 4, False: 14.0k]
  ------------------
  385|      4|      return 0;
  386|      4|    }
  387|       |    // ITU-T X.690 section 10.1 (DER length forms) requires encoding the
  388|       |    // length with the minimum number of octets. BER could, technically, have
  389|       |    // 125 superfluous zero bytes. We do not attempt to handle that and still
  390|       |    // require that the length fit in a |uint32_t| for BER.
  391|  14.0k|    if (len64 < 128) {
  ------------------
  |  Branch (391:9): [True: 22, False: 14.0k]
  ------------------
  392|       |      // Length should have used short-form encoding.
  393|     22|      if (ber_ok) {
  ------------------
  |  Branch (393:11): [True: 7, False: 15]
  ------------------
  394|      7|        *out_ber_found = 1;
  395|     15|      } else {
  396|     15|        return 0;
  397|     15|      }
  398|     22|    }
  399|  14.0k|    if ((len64 >> ((num_bytes - 1) * 8)) == 0) {
  ------------------
  |  Branch (399:9): [True: 3, False: 14.0k]
  ------------------
  400|       |      // Length should have been at least one byte shorter.
  401|      3|      if (ber_ok) {
  ------------------
  |  Branch (401:11): [True: 2, False: 1]
  ------------------
  402|      2|        *out_ber_found = 1;
  403|      2|      } else {
  404|      1|        return 0;
  405|      1|      }
  406|      3|    }
  407|  14.0k|    len = len64;
  408|  14.0k|    if (len + header_len + num_bytes < len) {
  ------------------
  |  Branch (408:9): [True: 0, False: 14.0k]
  ------------------
  409|       |      // Overflow.
  410|      0|      return 0;
  411|      0|    }
  412|  14.0k|    len += header_len + num_bytes;
  413|  14.0k|    if (out_header_len != NULL) {
  ------------------
  |  Branch (413:9): [True: 14.0k, False: 0]
  ------------------
  414|  14.0k|      *out_header_len = header_len + num_bytes;
  415|  14.0k|    }
  416|  14.0k|  }
  417|       |
  418|   261k|  return CBS_get_bytes(cbs, out, len);
  419|   261k|}
cbs.c:cbs_get_asn1:
  452|  29.8k|                        int skip_header) {
  453|  29.8k|  size_t header_len;
  454|  29.8k|  CBS_ASN1_TAG tag;
  455|  29.8k|  CBS throwaway;
  456|       |
  457|  29.8k|  if (out == NULL) {
  ------------------
  |  Branch (457:7): [True: 0, False: 29.8k]
  ------------------
  458|      0|    out = &throwaway;
  459|      0|  }
  460|       |
  461|  29.8k|  if (!CBS_get_any_asn1_element(cbs, out, &tag, &header_len) ||
  ------------------
  |  Branch (461:7): [True: 596, False: 29.2k]
  ------------------
  462|  29.8k|      tag != tag_value) {
  ------------------
  |  Branch (462:7): [True: 620, False: 28.6k]
  ------------------
  463|  1.21k|    return 0;
  464|  1.21k|  }
  465|       |
  466|  28.6k|  if (skip_header && !CBS_skip(out, header_len)) {
  ------------------
  |  Branch (466:7): [True: 18.1k, False: 10.5k]
  |  Branch (466:22): [True: 0, False: 18.1k]
  ------------------
  467|      0|    assert(0);
  468|      0|    return 0;
  469|      0|  }
  470|       |
  471|  28.6k|  return 1;
  472|  28.6k|}
cbs.c:parse_asn1_tag:
  281|   262k|static int parse_asn1_tag(CBS *cbs, CBS_ASN1_TAG *out) {
  282|   262k|  uint8_t tag_byte;
  283|   262k|  if (!CBS_get_u8(cbs, &tag_byte)) {
  ------------------
  |  Branch (283:7): [True: 65, False: 262k]
  ------------------
  284|     65|    return 0;
  285|     65|  }
  286|       |
  287|       |  // ITU-T X.690 section 8.1.2.3 specifies the format for identifiers with a tag
  288|       |  // number no greater than 30.
  289|       |  //
  290|       |  // If the number portion is 31 (0x1f, the largest value that fits in the
  291|       |  // allotted bits), then the tag is more than one byte long and the
  292|       |  // continuation bytes contain the tag number.
  293|   262k|  CBS_ASN1_TAG tag = ((CBS_ASN1_TAG)tag_byte & 0xe0) << CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|   262k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  294|   262k|  CBS_ASN1_TAG tag_number = tag_byte & 0x1f;
  295|   262k|  if (tag_number == 0x1f) {
  ------------------
  |  Branch (295:7): [True: 800, False: 261k]
  ------------------
  296|    800|    uint64_t v;
  297|    800|    if (!parse_base128_integer(cbs, &v) ||
  ------------------
  |  Branch (297:9): [True: 78, False: 722]
  ------------------
  298|       |        // Check the tag number is within our supported bounds.
  299|    800|        v > CBS_ASN1_TAG_NUMBER_MASK ||
  ------------------
  |  |  210|  1.52k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|    722|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (299:9): [True: 143, False: 579]
  ------------------
  300|       |        // Small tag numbers should have used low tag number form, even in BER.
  301|    800|        v < 0x1f) {
  ------------------
  |  Branch (301:9): [True: 4, False: 575]
  ------------------
  302|    225|      return 0;
  303|    225|    }
  304|    575|    tag_number = (CBS_ASN1_TAG)v;
  305|    575|  }
  306|       |
  307|   261k|  tag |= tag_number;
  308|       |
  309|       |  // Tag [UNIVERSAL 0] is reserved for use by the encoding. Reject it here to
  310|       |  // avoid some ambiguity around ANY values and BER indefinite-length EOCs. See
  311|       |  // https://crbug.com/boringssl/455.
  312|   261k|  if ((tag & ~CBS_ASN1_CONSTRUCTED) == 0) {
  ------------------
  |  |  196|   261k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|   261k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (312:7): [True: 122, False: 261k]
  ------------------
  313|    122|    return 0;
  314|    122|  }
  315|       |
  316|   261k|  *out = tag;
  317|   261k|  return 1;
  318|   261k|}
cbs.c:parse_base128_integer:
  257|    800|static int parse_base128_integer(CBS *cbs, uint64_t *out) {
  258|    800|  uint64_t v = 0;
  259|    800|  uint8_t b;
  260|  3.46k|  do {
  261|  3.46k|    if (!CBS_get_u8(cbs, &b)) {
  ------------------
  |  Branch (261:9): [True: 74, False: 3.38k]
  ------------------
  262|     74|      return 0;
  263|     74|    }
  264|  3.38k|    if ((v >> (64 - 7)) != 0) {
  ------------------
  |  Branch (264:9): [True: 3, False: 3.38k]
  ------------------
  265|       |      // The value is too large.
  266|      3|      return 0;
  267|      3|    }
  268|  3.38k|    if (v == 0 && b == 0x80) {
  ------------------
  |  Branch (268:9): [True: 798, False: 2.58k]
  |  Branch (268:19): [True: 1, False: 797]
  ------------------
  269|       |      // The value must be minimally encoded.
  270|      1|      return 0;
  271|      1|    }
  272|  3.38k|    v = (v << 7) | (b & 0x7f);
  273|       |
  274|       |    // Values end at an octet with the high bit cleared.
  275|  3.38k|  } while (b & 0x80);
  ------------------
  |  Branch (275:12): [True: 2.66k, False: 722]
  ------------------
  276|       |
  277|    722|  *out = v;
  278|    722|  return 1;
  279|    800|}
cbs.c:CBS_parse_rfc5280_time_internal:
  819|  5.35k|                                           struct tm *out_tm) {
  820|  5.35k|  int year, month, day, hour, min, sec, tmp;
  821|  5.35k|  CBS copy = *cbs;
  822|  5.35k|  uint8_t tz;
  823|       |
  824|  5.35k|  if (is_gentime) {
  ------------------
  |  Branch (824:7): [True: 616, False: 4.73k]
  ------------------
  825|    616|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (825:9): [True: 26, False: 590]
  ------------------
  826|     26|      return 0;
  827|     26|    }
  828|    590|    year = tmp * 100;
  829|    590|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (829:9): [True: 13, False: 577]
  ------------------
  830|     13|      return 0;
  831|     13|    }
  832|    577|      year += tmp;
  833|  4.73k|  } else {
  834|  4.73k|    year = 1900;
  835|  4.73k|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (835:9): [True: 32, False: 4.70k]
  ------------------
  836|     32|      return 0;
  837|     32|    }
  838|  4.70k|    year += tmp;
  839|  4.70k|    if (year < 1950) {
  ------------------
  |  Branch (839:9): [True: 4.64k, False: 63]
  ------------------
  840|  4.64k|      year += 100;
  841|  4.64k|    }
  842|  4.70k|    if (year >= 2050) {
  ------------------
  |  Branch (842:9): [True: 0, False: 4.70k]
  ------------------
  843|      0|      return 0;  // A Generalized time must be used.
  844|      0|    }
  845|  4.70k|  }
  846|  5.28k|  if (!cbs_get_two_digits(&copy, &month) || month < 1 ||
  ------------------
  |  Branch (846:7): [True: 25, False: 5.25k]
  |  Branch (846:45): [True: 2, False: 5.25k]
  ------------------
  847|  5.28k|      month > 12 ||  // Reject invalid months.
  ------------------
  |  Branch (847:7): [True: 13, False: 5.24k]
  ------------------
  848|  5.28k|      !cbs_get_two_digits(&copy, &day) ||
  ------------------
  |  Branch (848:7): [True: 13, False: 5.22k]
  ------------------
  849|  5.28k|      !is_valid_day(year, month, day) ||  // Reject invalid days.
  ------------------
  |  Branch (849:7): [True: 22, False: 5.20k]
  ------------------
  850|  5.28k|      !cbs_get_two_digits(&copy, &hour) ||
  ------------------
  |  Branch (850:7): [True: 48, False: 5.15k]
  ------------------
  851|  5.28k|      hour > 23 ||  // Reject invalid hours.
  ------------------
  |  Branch (851:7): [True: 9, False: 5.14k]
  ------------------
  852|  5.28k|      !cbs_get_two_digits(&copy, &min) ||
  ------------------
  |  Branch (852:7): [True: 19, False: 5.13k]
  ------------------
  853|  5.28k|      min > 59 ||  // Reject invalid minutes.
  ------------------
  |  Branch (853:7): [True: 13, False: 5.11k]
  ------------------
  854|  5.28k|      !cbs_get_two_digits(&copy, &sec) || sec > 59 || !CBS_get_u8(&copy, &tz)) {
  ------------------
  |  Branch (854:7): [True: 30, False: 5.08k]
  |  Branch (854:43): [True: 3, False: 5.08k]
  |  Branch (854:55): [True: 1, False: 5.08k]
  ------------------
  855|    198|    return 0;
  856|    198|  }
  857|       |
  858|  5.08k|  int offset_sign = 0;
  859|  5.08k|  switch (tz) {
  860|  5.05k|    case 'Z':
  ------------------
  |  Branch (860:5): [True: 5.05k, False: 33]
  ------------------
  861|  5.05k|      break;  // We correctly have 'Z' on the end as per spec.
  862|     17|    case '+':
  ------------------
  |  Branch (862:5): [True: 17, False: 5.06k]
  ------------------
  863|     17|      offset_sign = 1;
  864|     17|      break;  // Should not be allowed per RFC 5280.
  865|      3|    case '-':
  ------------------
  |  Branch (865:5): [True: 3, False: 5.08k]
  ------------------
  866|      3|      offset_sign = -1;
  867|      3|      break;  // Should not be allowed per RFC 5280.
  868|     13|    default:
  ------------------
  |  Branch (868:5): [True: 13, False: 5.07k]
  ------------------
  869|     13|      return 0;  // Reject anything else after the time.
  870|  5.08k|  }
  871|       |
  872|       |  // If allow_timezone_offset is non-zero, allow for a four digit timezone
  873|       |  // offset to be specified even though this is not allowed by RFC 5280. We are
  874|       |  // permissive of this for UTCTimes due to the unfortunate existence of
  875|       |  // artisinally rolled long lived certificates that were baked into places that
  876|       |  // are now difficult to change. These certificates were generated with the
  877|       |  // 'openssl' command that permissively allowed the creation of certificates
  878|       |  // with notBefore and notAfter times specified as strings for direct
  879|       |  // certificate inclusion on the command line. For context see cl/237068815.
  880|       |  //
  881|       |  // TODO(bbe): This has been expunged from public web-pki as the ecosystem has
  882|       |  // managed to encourage CA compliance with standards. We should find a way to
  883|       |  // get rid of this or make it off by default.
  884|  5.07k|  int offset_seconds = 0;
  885|  5.07k|  if (offset_sign != 0) {
  ------------------
  |  Branch (885:7): [True: 20, False: 5.05k]
  ------------------
  886|     20|    if (!allow_timezone_offset) {
  ------------------
  |  Branch (886:9): [True: 1, False: 19]
  ------------------
  887|      1|      return 0;
  888|      1|    }
  889|     19|    int offset_hours, offset_minutes;
  890|     19|    if (!cbs_get_two_digits(&copy, &offset_hours) ||
  ------------------
  |  Branch (890:9): [True: 4, False: 15]
  ------------------
  891|     19|        offset_hours > 23 ||  // Reject invalid hours.
  ------------------
  |  Branch (891:9): [True: 2, False: 13]
  ------------------
  892|     19|        !cbs_get_two_digits(&copy, &offset_minutes) ||
  ------------------
  |  Branch (892:9): [True: 1, False: 12]
  ------------------
  893|     19|        offset_minutes > 59) {  // Reject invalid minutes.
  ------------------
  |  Branch (893:9): [True: 1, False: 11]
  ------------------
  894|      8|      return 0;
  895|      8|    }
  896|     11|    offset_seconds = offset_sign * (offset_hours * 3600 + offset_minutes * 60);
  897|     11|  }
  898|       |
  899|  5.06k|  if (CBS_len(&copy) != 0) {
  ------------------
  |  Branch (899:7): [True: 44, False: 5.01k]
  ------------------
  900|     44|    return 0;  // Reject invalid lengths.
  901|     44|  }
  902|       |
  903|  5.01k|  if (out_tm != NULL) {
  ------------------
  |  Branch (903:7): [True: 0, False: 5.01k]
  ------------------
  904|       |    // Fill in the tm fields corresponding to what we validated.
  905|      0|    out_tm->tm_year = year - 1900;
  906|      0|    out_tm->tm_mon = month - 1;
  907|      0|    out_tm->tm_mday = day;
  908|      0|    out_tm->tm_hour = hour;
  909|      0|    out_tm->tm_min = min;
  910|      0|    out_tm->tm_sec = sec;
  911|      0|    if (offset_seconds && !OPENSSL_gmtime_adj(out_tm, 0, offset_seconds)) {
  ------------------
  |  Branch (911:9): [True: 0, False: 0]
  |  Branch (911:27): [True: 0, False: 0]
  ------------------
  912|      0|      return 0;
  913|      0|    }
  914|      0|  }
  915|  5.01k|  return 1;
  916|  5.01k|}
cbs.c:cbs_get_two_digits:
  770|  31.9k|static int cbs_get_two_digits(CBS *cbs, int *out) {
  771|  31.9k|  uint8_t first_digit, second_digit;
  772|  31.9k|  if (!CBS_get_u8(cbs, &first_digit)) {
  ------------------
  |  Branch (772:7): [True: 33, False: 31.9k]
  ------------------
  773|     33|    return 0;
  774|     33|  }
  775|  31.9k|  if (!OPENSSL_isdigit(first_digit)) {
  ------------------
  |  Branch (775:7): [True: 81, False: 31.8k]
  ------------------
  776|     81|    return 0;
  777|     81|  }
  778|  31.8k|  if (!CBS_get_u8(cbs, &second_digit)) {
  ------------------
  |  Branch (778:7): [True: 12, False: 31.8k]
  ------------------
  779|     12|    return 0;
  780|     12|  }
  781|  31.8k|  if (!OPENSSL_isdigit(second_digit)) {
  ------------------
  |  Branch (781:7): [True: 85, False: 31.7k]
  ------------------
  782|     85|    return 0;
  783|     85|  }
  784|  31.7k|  *out = (first_digit - '0') * 10 + (second_digit - '0');
  785|  31.7k|  return 1;
  786|  31.8k|}
cbs.c:is_valid_day:
  788|  5.22k|static int is_valid_day(int year, int month, int day) {
  789|  5.22k|  if (day < 1) {
  ------------------
  |  Branch (789:7): [True: 4, False: 5.22k]
  ------------------
  790|      4|    return 0;
  791|      4|  }
  792|  5.22k|  switch (month) {
  793|     54|    case 1:
  ------------------
  |  Branch (793:5): [True: 54, False: 5.17k]
  ------------------
  794|     63|    case 3:
  ------------------
  |  Branch (794:5): [True: 9, False: 5.21k]
  ------------------
  795|     74|    case 5:
  ------------------
  |  Branch (795:5): [True: 11, False: 5.21k]
  ------------------
  796|     86|    case 7:
  ------------------
  |  Branch (796:5): [True: 12, False: 5.21k]
  ------------------
  797|    106|    case 8:
  ------------------
  |  Branch (797:5): [True: 20, False: 5.20k]
  ------------------
  798|    149|    case 10:
  ------------------
  |  Branch (798:5): [True: 43, False: 5.18k]
  ------------------
  799|    171|    case 12:
  ------------------
  |  Branch (799:5): [True: 22, False: 5.20k]
  ------------------
  800|    171|      return day <= 31;
  801|      6|    case 4:
  ------------------
  |  Branch (801:5): [True: 6, False: 5.21k]
  ------------------
  802|     21|    case 6:
  ------------------
  |  Branch (802:5): [True: 15, False: 5.20k]
  ------------------
  803|     34|    case 9:
  ------------------
  |  Branch (803:5): [True: 13, False: 5.21k]
  ------------------
  804|  4.54k|    case 11:
  ------------------
  |  Branch (804:5): [True: 4.51k, False: 714]
  ------------------
  805|  4.54k|      return day <= 30;
  806|    509|    case 2:
  ------------------
  |  Branch (806:5): [True: 509, False: 4.71k]
  ------------------
  807|    509|      if ((year % 4 == 0 && year % 100 != 0) || year % 400 == 0) {
  ------------------
  |  Branch (807:12): [True: 487, False: 22]
  |  Branch (807:29): [True: 479, False: 8]
  |  Branch (807:49): [True: 8, False: 22]
  ------------------
  808|    487|        return day <= 29;
  809|    487|      } else {
  810|     22|        return day <= 28;
  811|     22|      }
  812|      0|    default:
  ------------------
  |  Branch (812:5): [True: 0, False: 5.22k]
  ------------------
  813|      0|      return 0;
  814|  5.22k|  }
  815|  5.22k|}

cbs_get_utf8:
   41|   273k|int cbs_get_utf8(CBS *cbs, uint32_t *out) {
   42|   273k|  uint8_t c;
   43|   273k|  if (!CBS_get_u8(cbs, &c)) {
  ------------------
  |  Branch (43:7): [True: 0, False: 273k]
  ------------------
   44|      0|    return 0;
   45|      0|  }
   46|   273k|  if (c <= 0x7f) {
  ------------------
  |  Branch (46:7): [True: 272k, False: 1.22k]
  ------------------
   47|   272k|    *out = c;
   48|   272k|    return 1;
   49|   272k|  }
   50|  1.22k|  uint32_t v, lower_bound;
   51|  1.22k|  size_t len;
   52|  1.22k|  if ((c & TOP_BITS(3)) == TOP_BITS(2)) {
  ------------------
  |  |   39|  1.22k|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  1.22k|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                if ((c & TOP_BITS(3)) == TOP_BITS(2)) {
  ------------------
  |  |   39|  1.22k|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  1.22k|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (52:7): [True: 315, False: 906]
  ------------------
   53|    315|    v = c & BOTTOM_BITS(5);
  ------------------
  |  |   36|    315|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   54|    315|    len = 1;
   55|    315|    lower_bound = 0x80;
   56|    906|  } else if ((c & TOP_BITS(4)) == TOP_BITS(3)) {
  ------------------
  |  |   39|    906|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    906|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                } else if ((c & TOP_BITS(4)) == TOP_BITS(3)) {
  ------------------
  |  |   39|    906|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    906|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (56:14): [True: 543, False: 363]
  ------------------
   57|    543|    v = c & BOTTOM_BITS(4);
  ------------------
  |  |   36|    543|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   58|    543|    len = 2;
   59|    543|    lower_bound = 0x800;
   60|    543|  } else if ((c & TOP_BITS(5)) == TOP_BITS(4)) {
  ------------------
  |  |   39|    363|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    363|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                } else if ((c & TOP_BITS(5)) == TOP_BITS(4)) {
  ------------------
  |  |   39|    363|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    363|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (60:14): [True: 358, False: 5]
  ------------------
   61|    358|    v = c & BOTTOM_BITS(3);
  ------------------
  |  |   36|    358|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   62|    358|    len = 3;
   63|    358|    lower_bound = 0x10000;
   64|    358|  } else {
   65|      5|    return 0;
   66|      5|  }
   67|  3.65k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (67:22): [True: 2.46k, False: 1.19k]
  ------------------
   68|  2.46k|    if (!CBS_get_u8(cbs, &c) ||
  ------------------
  |  Branch (68:9): [True: 7, False: 2.45k]
  ------------------
   69|  2.46k|        (c & TOP_BITS(2)) != TOP_BITS(1)) {
  ------------------
  |  |   39|  2.45k|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  2.45k|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                      (c & TOP_BITS(2)) != TOP_BITS(1)) {
  ------------------
  |  |   39|  2.45k|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  2.45k|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (69:9): [True: 18, False: 2.43k]
  ------------------
   70|     25|      return 0;
   71|     25|    }
   72|  2.43k|    v <<= 6;
   73|  2.43k|    v |= c & BOTTOM_BITS(6);
  ------------------
  |  |   36|  2.43k|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   74|  2.43k|  }
   75|  1.19k|  if (!is_valid_code_point(v) ||
  ------------------
  |  Branch (75:7): [True: 21, False: 1.17k]
  ------------------
   76|  1.19k|      v < lower_bound) {
  ------------------
  |  Branch (76:7): [True: 3, False: 1.16k]
  ------------------
   77|     24|    return 0;
   78|     24|  }
   79|  1.16k|  *out = v;
   80|  1.16k|  return 1;
   81|  1.19k|}
cbs_get_latin1:
   83|  4.47M|int cbs_get_latin1(CBS *cbs, uint32_t *out) {
   84|  4.47M|  uint8_t c;
   85|  4.47M|  if (!CBS_get_u8(cbs, &c)) {
  ------------------
  |  Branch (85:7): [True: 0, False: 4.47M]
  ------------------
   86|      0|    return 0;
   87|      0|  }
   88|  4.47M|  *out = c;
   89|  4.47M|  return 1;
   90|  4.47M|}
cbs_get_ucs2_be:
   92|  15.9M|int cbs_get_ucs2_be(CBS *cbs, uint32_t *out) {
   93|       |  // Note UCS-2 (used by BMPString) does not support surrogates.
   94|  15.9M|  uint16_t c;
   95|  15.9M|  if (!CBS_get_u16(cbs, &c) ||
  ------------------
  |  Branch (95:7): [True: 23, False: 15.9M]
  ------------------
   96|  15.9M|      !is_valid_code_point(c)) {
  ------------------
  |  Branch (96:7): [True: 17, False: 15.9M]
  ------------------
   97|     40|    return 0;
   98|     40|  }
   99|  15.9M|  *out = c;
  100|  15.9M|  return 1;
  101|  15.9M|}
cbs_get_utf32_be:
  103|  2.12k|int cbs_get_utf32_be(CBS *cbs, uint32_t *out) {
  104|  2.12k|  return CBS_get_u32(cbs, out) && is_valid_code_point(*out);
  ------------------
  |  Branch (104:10): [True: 2.11k, False: 13]
  |  Branch (104:35): [True: 2.00k, False: 104]
  ------------------
  105|  2.12k|}
cbb_get_utf8_len:
  107|  7.56M|size_t cbb_get_utf8_len(uint32_t u) {
  108|  7.56M|  if (u <= 0x7f) {
  ------------------
  |  Branch (108:7): [True: 2.37M, False: 5.19M]
  ------------------
  109|  2.37M|    return 1;
  110|  2.37M|  }
  111|  5.19M|  if (u <= 0x7ff) {
  ------------------
  |  Branch (111:7): [True: 1.06k, False: 5.19M]
  ------------------
  112|  1.06k|    return 2;
  113|  1.06k|  }
  114|  5.19M|  if (u <= 0xffff) {
  ------------------
  |  Branch (114:7): [True: 5.19M, False: 550]
  ------------------
  115|  5.19M|    return 3;
  116|  5.19M|  }
  117|    550|  return 4;
  118|  5.19M|}
cbb_add_utf8:
  120|  7.43M|int cbb_add_utf8(CBB *cbb, uint32_t u) {
  121|  7.43M|  if (!is_valid_code_point(u)) {
  ------------------
  |  Branch (121:7): [True: 0, False: 7.43M]
  ------------------
  122|      0|    return 0;
  123|      0|  }
  124|  7.43M|  if (u <= 0x7f) {
  ------------------
  |  Branch (124:7): [True: 2.23M, False: 5.19M]
  ------------------
  125|  2.23M|    return CBB_add_u8(cbb, (uint8_t)u);
  126|  2.23M|  }
  127|  5.19M|  if (u <= 0x7ff) {
  ------------------
  |  Branch (127:7): [True: 982, False: 5.19M]
  ------------------
  128|    982|    return CBB_add_u8(cbb, TOP_BITS(2) | (u >> 6)) &&
  ------------------
  |  |   39|    982|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    982|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (128:12): [True: 982, False: 0]
  ------------------
  129|    982|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|    982|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    982|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|    982|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (129:12): [True: 982, False: 0]
  ------------------
  130|    982|  }
  131|  5.19M|  if (u <= 0xffff) {
  ------------------
  |  Branch (131:7): [True: 5.19M, False: 409]
  ------------------
  132|  5.19M|    return CBB_add_u8(cbb, TOP_BITS(3) | (u >> 12)) &&
  ------------------
  |  |   39|  5.19M|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  5.19M|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (132:12): [True: 5.19M, False: 0]
  ------------------
  133|  5.19M|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|  5.19M|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  5.19M|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|  5.19M|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (133:12): [True: 5.19M, False: 0]
  ------------------
  134|  5.19M|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|  5.19M|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|  5.19M|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|  5.19M|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (134:12): [True: 5.19M, False: 0]
  ------------------
  135|  5.19M|  }
  136|    409|  if (u <= 0x10ffff) {
  ------------------
  |  Branch (136:7): [True: 409, False: 0]
  ------------------
  137|    409|    return CBB_add_u8(cbb, TOP_BITS(4) | (u >> 18)) &&
  ------------------
  |  |   39|    409|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (137:12): [True: 409, False: 0]
  ------------------
  138|    409|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 12) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|    409|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 12) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (138:12): [True: 409, False: 0]
  ------------------
  139|    409|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|    409|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (139:12): [True: 409, False: 0]
  ------------------
  140|    409|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|    409|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|    409|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (140:12): [True: 409, False: 0]
  ------------------
  141|    409|  }
  142|      0|  return 0;
  143|    409|}
unicode.c:is_valid_code_point:
   20|  23.3M|static int is_valid_code_point(uint32_t v) {
   21|       |  // References in the following are to Unicode 9.0.0.
   22|  23.3M|  if (// The Unicode space runs from zero to 0x10ffff (3.4 D9).
   23|  23.3M|      v > 0x10ffff ||
  ------------------
  |  Branch (23:7): [True: 85, False: 23.3M]
  ------------------
   24|       |      // Values 0x...fffe, 0x...ffff, and 0xfdd0-0xfdef are permanently reserved
   25|       |      // (3.4 D14)
   26|  23.3M|      (v & 0xfffe) == 0xfffe ||
  ------------------
  |  Branch (26:7): [True: 6, False: 23.3M]
  ------------------
   27|  23.3M|      (v >= 0xfdd0 && v <= 0xfdef) ||
  ------------------
  |  Branch (27:8): [True: 4.12k, False: 23.3M]
  |  Branch (27:23): [True: 18, False: 4.10k]
  ------------------
   28|       |      // Surrogate code points are invalid (3.2 C1).
   29|  23.3M|      (v >= 0xd800 && v <= 0xdfff)) {
  ------------------
  |  Branch (29:8): [True: 5.26k, False: 23.3M]
  |  Branch (29:23): [True: 33, False: 5.23k]
  ------------------
   30|    142|    return 0;
   31|    142|  }
   32|  23.3M|  return 1;
   33|  23.3M|}

OPENSSL_cpuid_setup:
  153|      2|void OPENSSL_cpuid_setup(void) {
  154|       |  // Determine the vendor and maximum input value.
  155|      2|  uint32_t eax, ebx, ecx, edx;
  156|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 0);
  157|       |
  158|      2|  uint32_t num_ids = eax;
  159|       |
  160|      2|  int is_intel = ebx == 0x756e6547 /* Genu */ &&
  ------------------
  |  Branch (160:18): [True: 2, False: 0]
  ------------------
  161|      2|                 edx == 0x49656e69 /* ineI */ &&
  ------------------
  |  Branch (161:18): [True: 2, False: 0]
  ------------------
  162|      2|                 ecx == 0x6c65746e /* ntel */;
  ------------------
  |  Branch (162:18): [True: 2, False: 0]
  ------------------
  163|      2|  int is_amd = ebx == 0x68747541 /* Auth */ &&
  ------------------
  |  Branch (163:16): [True: 0, False: 2]
  ------------------
  164|      2|               edx == 0x69746e65 /* enti */ &&
  ------------------
  |  Branch (164:16): [True: 0, False: 0]
  ------------------
  165|      2|               ecx == 0x444d4163 /* cAMD */;
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|       |
  167|      2|  uint32_t extended_features[2] = {0};
  168|      2|  if (num_ids >= 7) {
  ------------------
  |  Branch (168:7): [True: 2, False: 0]
  ------------------
  169|      2|    OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 7);
  170|      2|    extended_features[0] = ebx;
  171|      2|    extended_features[1] = ecx;
  172|      2|  }
  173|       |
  174|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 1);
  175|       |
  176|      2|  if (is_amd) {
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|       |    // See https://www.amd.com/system/files/TechDocs/25481.pdf, page 10.
  178|      0|    const uint32_t base_family = (eax >> 8) & 15;
  179|      0|    const uint32_t base_model = (eax >> 4) & 15;
  180|       |
  181|      0|    uint32_t family = base_family;
  182|      0|    uint32_t model = base_model;
  183|      0|    if (base_family == 0xf) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      const uint32_t ext_family = (eax >> 20) & 255;
  185|      0|      family += ext_family;
  186|      0|      const uint32_t ext_model = (eax >> 16) & 15;
  187|      0|      model |= ext_model << 4;
  188|      0|    }
  189|       |
  190|      0|    if (family < 0x17 || (family == 0x17 && 0x70 <= model && model <= 0x7f)) {
  ------------------
  |  Branch (190:9): [True: 0, False: 0]
  |  Branch (190:27): [True: 0, False: 0]
  |  Branch (190:45): [True: 0, False: 0]
  |  Branch (190:62): [True: 0, False: 0]
  ------------------
  191|       |      // Disable RDRAND on AMD families before 0x17 (Zen) due to reported
  192|       |      // failures after suspend.
  193|       |      // https://bugzilla.redhat.com/show_bug.cgi?id=1150286
  194|       |      // Also disable for family 0x17, models 0x70–0x7f, due to possible RDRAND
  195|       |      // failures there too.
  196|      0|      ecx &= ~(1u << 30);
  197|      0|    }
  198|      0|  }
  199|       |
  200|       |  // Force the hyper-threading bit so that the more conservative path is always
  201|       |  // chosen.
  202|      2|  edx |= 1u << 28;
  203|       |
  204|       |  // Reserved bit #20 was historically repurposed to control the in-memory
  205|       |  // representation of RC4 state. Always set it to zero.
  206|      2|  edx &= ~(1u << 20);
  207|       |
  208|       |  // Reserved bit #30 is repurposed to signal an Intel CPU.
  209|      2|  if (is_intel) {
  ------------------
  |  Branch (209:7): [True: 2, False: 0]
  ------------------
  210|      2|    edx |= (1u << 30);
  211|       |
  212|       |    // Clear the XSAVE bit on Knights Landing to mimic Silvermont. This enables
  213|       |    // some Silvermont-specific codepaths which perform better. See OpenSSL
  214|       |    // commit 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  215|      2|    if ((eax & 0x0fff0ff0) == 0x00050670 /* Knights Landing */ ||
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      2|        (eax & 0x0fff0ff0) == 0x00080650 /* Knights Mill (per SDE) */) {
  ------------------
  |  Branch (216:9): [True: 0, False: 2]
  ------------------
  217|      0|      ecx &= ~(1u << 26);
  218|      0|    }
  219|      2|  } else {
  220|      0|    edx &= ~(1u << 30);
  221|      0|  }
  222|       |
  223|       |  // The SDBG bit is repurposed to denote AMD XOP support. Don't ever use AMD
  224|       |  // XOP code paths.
  225|      2|  ecx &= ~(1u << 11);
  226|       |
  227|      2|  uint64_t xcr0 = 0;
  228|      2|  if (ecx & (1u << 27)) {
  ------------------
  |  Branch (228:7): [True: 2, False: 0]
  ------------------
  229|       |    // XCR0 may only be queried if the OSXSAVE bit is set.
  230|      2|    xcr0 = OPENSSL_xgetbv(0);
  231|      2|  }
  232|       |  // See Intel manual, volume 1, section 14.3.
  233|      2|  if ((xcr0 & 6) != 6) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2]
  ------------------
  234|       |    // YMM registers cannot be used.
  235|      0|    ecx &= ~(1u << 28);  // AVX
  236|      0|    ecx &= ~(1u << 12);  // FMA
  237|      0|    ecx &= ~(1u << 11);  // AMD XOP
  238|       |    // Clear AVX2 and AVX512* bits.
  239|       |    //
  240|       |    // TODO(davidben): Should bits 17 and 26-28 also be cleared? Upstream
  241|       |    // doesn't clear those.
  242|      0|    extended_features[0] &=
  243|      0|        ~((1u << 5) | (1u << 16) | (1u << 21) | (1u << 30) | (1u << 31));
  244|      0|  }
  245|       |  // See Intel manual, volume 1, section 15.2.
  246|      2|  if ((xcr0 & 0xe6) != 0xe6) {
  ------------------
  |  Branch (246:7): [True: 2, False: 0]
  ------------------
  247|       |    // Clear AVX512F. Note we don't touch other AVX512 extensions because they
  248|       |    // can be used with YMM.
  249|      2|    extended_features[0] &= ~(1u << 16);
  250|      2|  }
  251|       |
  252|       |  // Disable ADX instructions on Knights Landing. See OpenSSL commit
  253|       |  // 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  254|      2|  if ((ecx & (1u << 26)) == 0) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    extended_features[0] &= ~(1u << 19);
  256|      0|  }
  257|       |
  258|      2|  OPENSSL_ia32cap_P[0] = edx;
  259|      2|  OPENSSL_ia32cap_P[1] = ecx;
  260|      2|  OPENSSL_ia32cap_P[2] = extended_features[0];
  261|      2|  OPENSSL_ia32cap_P[3] = extended_features[1];
  262|       |
  263|      2|  const char *env1, *env2;
  264|      2|  env1 = getenv("OPENSSL_ia32cap");
  265|      2|  if (env1 == NULL) {
  ------------------
  |  Branch (265:7): [True: 2, False: 0]
  ------------------
  266|      2|    return;
  267|      2|  }
  268|       |
  269|       |  // OPENSSL_ia32cap can contain zero, one or two values, separated with a ':'.
  270|       |  // Each value is a 64-bit, unsigned value which may start with "0x" to
  271|       |  // indicate a hex value. Prior to the 64-bit value, a '~' or '|' may be given.
  272|       |  //
  273|       |  // If the '~' prefix is present:
  274|       |  //   the value is inverted and ANDed with the probed CPUID result
  275|       |  // If the '|' prefix is present:
  276|       |  //   the value is ORed with the probed CPUID result
  277|       |  // Otherwise:
  278|       |  //   the value is taken as the result of the CPUID
  279|       |  //
  280|       |  // The first value determines OPENSSL_ia32cap_P[0] and [1]. The second [2]
  281|       |  // and [3].
  282|       |
  283|      0|  handle_cpu_env(&OPENSSL_ia32cap_P[0], env1);
  284|      0|  env2 = strchr(env1, ':');
  285|      0|  if (env2 != NULL) {
  ------------------
  |  Branch (285:7): [True: 0, False: 0]
  ------------------
  286|      0|    handle_cpu_env(&OPENSSL_ia32cap_P[2], env2 + 1);
  287|      0|  }
  288|      0|}
cpu_intel.c:OPENSSL_cpuid:
   80|      6|                          uint32_t *out_ecx, uint32_t *out_edx, uint32_t leaf) {
   81|       |#if defined(_MSC_VER)
   82|       |  int tmp[4];
   83|       |  __cpuid(tmp, (int)leaf);
   84|       |  *out_eax = (uint32_t)tmp[0];
   85|       |  *out_ebx = (uint32_t)tmp[1];
   86|       |  *out_ecx = (uint32_t)tmp[2];
   87|       |  *out_edx = (uint32_t)tmp[3];
   88|       |#elif defined(__pic__) && defined(OPENSSL_32_BIT)
   89|       |  // Inline assembly may not clobber the PIC register. For 32-bit, this is EBX.
   90|       |  // See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47602.
   91|       |  __asm__ volatile (
   92|       |    "xor %%ecx, %%ecx\n"
   93|       |    "mov %%ebx, %%edi\n"
   94|       |    "cpuid\n"
   95|       |    "xchg %%edi, %%ebx\n"
   96|       |    : "=a"(*out_eax), "=D"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
   97|       |    : "a"(leaf)
   98|       |  );
   99|       |#else
  100|      6|  __asm__ volatile (
  101|      6|    "xor %%ecx, %%ecx\n"
  102|      6|    "cpuid\n"
  103|      6|    : "=a"(*out_eax), "=b"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
  104|      6|    : "a"(leaf)
  105|      6|  );
  106|      6|#endif
  107|      6|}
cpu_intel.c:OPENSSL_xgetbv:
  111|      2|static uint64_t OPENSSL_xgetbv(uint32_t xcr) {
  112|       |#if defined(_MSC_VER)
  113|       |  return (uint64_t)_xgetbv(xcr);
  114|       |#else
  115|      2|  uint32_t eax, edx;
  116|      2|  __asm__ volatile ("xgetbv" : "=a"(eax), "=d"(edx) : "c"(xcr));
  117|      2|  return (((uint64_t)edx) << 32) | eax;
  118|      2|#endif
  119|      2|}

crypto.c:do_library_init:
  151|      2|static void OPENSSL_CDECL do_library_init(void) {
  152|       | // WARNING: this function may only configure the capability variables. See the
  153|       | // note above about the linker bug.
  154|      2|#if defined(NEED_CPUID)
  155|      2|  OPENSSL_cpuid_setup();
  156|      2|#endif
  157|      2|}

DSA_new:
   90|    505|DSA *DSA_new(void) {
   91|    505|  DSA *dsa = OPENSSL_malloc(sizeof(DSA));
   92|    505|  if (dsa == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 505]
  ------------------
   93|      0|    return NULL;
   94|      0|  }
   95|       |
   96|    505|  OPENSSL_memset(dsa, 0, sizeof(DSA));
   97|       |
   98|    505|  dsa->references = 1;
   99|       |
  100|    505|  CRYPTO_MUTEX_init(&dsa->method_mont_lock);
  101|    505|  CRYPTO_new_ex_data(&dsa->ex_data);
  102|       |
  103|    505|  return dsa;
  104|    505|}
DSA_free:
  106|  1.45k|void DSA_free(DSA *dsa) {
  107|  1.45k|  if (dsa == NULL) {
  ------------------
  |  Branch (107:7): [True: 949, False: 505]
  ------------------
  108|    949|    return;
  109|    949|  }
  110|       |
  111|    505|  if (!CRYPTO_refcount_dec_and_test_zero(&dsa->references)) {
  ------------------
  |  Branch (111:7): [True: 0, False: 505]
  ------------------
  112|      0|    return;
  113|      0|  }
  114|       |
  115|    505|  CRYPTO_free_ex_data(&g_ex_data_class, dsa, &dsa->ex_data);
  116|       |
  117|    505|  BN_clear_free(dsa->p);
  118|    505|  BN_clear_free(dsa->q);
  119|    505|  BN_clear_free(dsa->g);
  120|    505|  BN_clear_free(dsa->pub_key);
  121|    505|  BN_clear_free(dsa->priv_key);
  122|    505|  BN_MONT_CTX_free(dsa->method_mont_p);
  123|    505|  BN_MONT_CTX_free(dsa->method_mont_q);
  124|    505|  CRYPTO_MUTEX_cleanup(&dsa->method_mont_lock);
  125|    505|  OPENSSL_free(dsa);
  126|    505|}

dsa_check_key:
   73|    419|int dsa_check_key(const DSA *dsa) {
   74|    419|  if (!dsa->p || !dsa->q || !dsa->g) {
  ------------------
  |  Branch (74:7): [True: 0, False: 419]
  |  Branch (74:18): [True: 0, False: 419]
  |  Branch (74:29): [True: 0, False: 419]
  ------------------
   75|      0|    OPENSSL_PUT_ERROR(DSA, DSA_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|       |
   79|       |  // Fully checking for invalid DSA groups is expensive, so security and
   80|       |  // correctness of the signature scheme depend on how |dsa| was computed. I.e.
   81|       |  // we leave "assurance of domain parameter validity" from FIPS 186-4 to the
   82|       |  // caller. However, we check bounds on all values to avoid DoS vectors even
   83|       |  // when domain parameters are invalid. In particular, signing will infinite
   84|       |  // loop if |g| is zero.
   85|    419|  if (BN_is_negative(dsa->p) || BN_is_negative(dsa->q) || BN_is_zero(dsa->p) ||
  ------------------
  |  Branch (85:7): [True: 0, False: 419]
  |  Branch (85:33): [True: 0, False: 419]
  |  Branch (85:59): [True: 1, False: 418]
  ------------------
   86|    419|      BN_is_zero(dsa->q) || !BN_is_odd(dsa->p) || !BN_is_odd(dsa->q) ||
  ------------------
  |  Branch (86:7): [True: 1, False: 417]
  |  Branch (86:29): [True: 43, False: 374]
  |  Branch (86:51): [True: 17, False: 357]
  ------------------
   87|       |      // |q| must be a prime divisor of |p - 1|, which implies |q < p|.
   88|    419|      BN_cmp(dsa->q, dsa->p) >= 0 ||
  ------------------
  |  Branch (88:7): [True: 19, False: 338]
  ------------------
   89|       |      // |g| is in the multiplicative group of |p|.
   90|    419|      BN_is_negative(dsa->g) || BN_is_zero(dsa->g) ||
  ------------------
  |  Branch (90:7): [True: 0, False: 338]
  |  Branch (90:33): [True: 2, False: 336]
  ------------------
   91|    419|      BN_cmp(dsa->g, dsa->p) >= 0) {
  ------------------
  |  Branch (91:7): [True: 32, False: 304]
  ------------------
   92|    115|    OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|    115|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   93|    115|    return 0;
   94|    115|  }
   95|       |
   96|       |  // FIPS 186-4 allows only three different sizes for q.
   97|    304|  unsigned q_bits = BN_num_bits(dsa->q);
   98|    304|  if (q_bits != 160 && q_bits != 224 && q_bits != 256) {
  ------------------
  |  Branch (98:7): [True: 266, False: 38]
  |  Branch (98:24): [True: 260, False: 6]
  |  Branch (98:41): [True: 254, False: 6]
  ------------------
   99|    254|    OPENSSL_PUT_ERROR(DSA, DSA_R_BAD_Q_VALUE);
  ------------------
  |  |  441|    254|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  100|    254|    return 0;
  101|    254|  }
  102|       |
  103|       |  // Bound |dsa->p| to avoid a DoS vector. Note this limit is much larger than
  104|       |  // the one in FIPS 186-4, which only allows L = 1024, 2048, and 3072.
  105|     50|  if (BN_num_bits(dsa->p) > OPENSSL_DSA_MAX_MODULUS_BITS) {
  ------------------
  |  |   68|     50|#define OPENSSL_DSA_MAX_MODULUS_BITS 10000
  ------------------
  |  Branch (105:7): [True: 19, False: 31]
  ------------------
  106|     19|    OPENSSL_PUT_ERROR(DSA, DSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|     19|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|     19|    return 0;
  108|     19|  }
  109|       |
  110|     31|  if (dsa->pub_key != NULL) {
  ------------------
  |  Branch (110:7): [True: 0, False: 31]
  ------------------
  111|       |    // The public key is also in the multiplicative group of |p|.
  112|      0|    if (BN_is_negative(dsa->pub_key) || BN_is_zero(dsa->pub_key) ||
  ------------------
  |  Branch (112:9): [True: 0, False: 0]
  |  Branch (112:41): [True: 0, False: 0]
  ------------------
  113|      0|        BN_cmp(dsa->pub_key, dsa->p) >= 0) {
  ------------------
  |  Branch (113:9): [True: 0, False: 0]
  ------------------
  114|      0|      OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  115|      0|      return 0;
  116|      0|    }
  117|      0|  }
  118|       |
  119|     31|  if (dsa->priv_key != NULL) {
  ------------------
  |  Branch (119:7): [True: 0, False: 31]
  ------------------
  120|       |    // The private key is a non-zero element of the scalar field, determined by
  121|       |    // |q|.
  122|      0|    if (BN_is_negative(dsa->priv_key) || BN_is_zero(dsa->priv_key) ||
  ------------------
  |  Branch (122:9): [True: 0, False: 0]
  |  Branch (122:42): [True: 0, False: 0]
  ------------------
  123|      0|        BN_cmp(dsa->priv_key, dsa->q) >= 0) {
  ------------------
  |  Branch (123:9): [True: 0, False: 0]
  ------------------
  124|      0|      OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  125|      0|      return 0;
  126|      0|    }
  127|      0|  }
  128|       |
  129|     31|  return 1;
  130|     31|}
DSA_parse_parameters:
  218|    479|DSA *DSA_parse_parameters(CBS *cbs) {
  219|    479|  DSA *ret = DSA_new();
  220|    479|  if (ret == NULL) {
  ------------------
  |  Branch (220:7): [True: 0, False: 479]
  ------------------
  221|      0|    return NULL;
  222|      0|  }
  223|    479|  CBS child;
  224|    479|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    479|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    479|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    479|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (224:7): [True: 15, False: 464]
  ------------------
  225|    479|      !parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (225:7): [True: 1, False: 463]
  ------------------
  226|    479|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (226:7): [True: 24, False: 439]
  ------------------
  227|    479|      !parse_integer(&child, &ret->g) ||
  ------------------
  |  Branch (227:7): [True: 2, False: 437]
  ------------------
  228|    479|      CBS_len(&child) != 0) {
  ------------------
  |  Branch (228:7): [True: 18, False: 419]
  ------------------
  229|     60|    OPENSSL_PUT_ERROR(DSA, DSA_R_DECODE_ERROR);
  ------------------
  |  |  441|     60|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  230|     60|    goto err;
  231|     60|  }
  232|    419|  if (!dsa_check_key(ret)) {
  ------------------
  |  Branch (232:7): [True: 388, False: 31]
  ------------------
  233|    388|    goto err;
  234|    388|  }
  235|     31|  return ret;
  236|       |
  237|    448|err:
  238|    448|  DSA_free(ret);
  239|    448|  return NULL;
  240|    419|}
dsa_asn1.c:parse_integer:
  132|  1.36k|static int parse_integer(CBS *cbs, BIGNUM **out) {
  133|  1.36k|  assert(*out == NULL);
  134|  1.36k|  *out = BN_new();
  135|  1.36k|  if (*out == NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 1.36k]
  ------------------
  136|      0|    return 0;
  137|      0|  }
  138|  1.36k|  return BN_parse_asn1_unsigned(cbs, *out);
  139|  1.36k|}

EC_KEY_parse_curve_name:
  324|    753|EC_GROUP *EC_KEY_parse_curve_name(CBS *cbs) {
  325|    753|  CBS named_curve;
  326|    753|  if (!CBS_get_asn1(cbs, &named_curve, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|    753|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (326:7): [True: 1, False: 752]
  ------------------
  327|      1|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|      1|    return NULL;
  329|      1|  }
  330|       |
  331|       |  // Look for a matching curve.
  332|    752|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  333|  2.48k|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|  2.48k|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (333:22): [True: 2.46k, False: 14]
  ------------------
  334|  2.46k|    const struct built_in_curve *curve = &curves->curves[i];
  335|  2.46k|    if (CBS_len(&named_curve) == curve->oid_len &&
  ------------------
  |  Branch (335:9): [True: 1.89k, False: 573]
  ------------------
  336|  2.46k|        OPENSSL_memcmp(CBS_data(&named_curve), curve->oid, curve->oid_len) ==
  ------------------
  |  Branch (336:9): [True: 738, False: 1.15k]
  ------------------
  337|  1.89k|            0) {
  338|    738|      return EC_GROUP_new_by_curve_name(curve->nid);
  339|    738|    }
  340|  2.46k|  }
  341|       |
  342|     14|  OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|     14|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  343|     14|  return NULL;
  344|    752|}

METHOD_ref:
   86|    409|void METHOD_ref(void *method_in) {
   87|    409|  assert(((struct openssl_method_common_st*) method_in)->is_static);
   88|    409|}
METHOD_unref:
   90|    409|void METHOD_unref(void *method_in) {
   91|    409|  struct openssl_method_common_st *method = method_in;
   92|       |
   93|    409|  if (method == NULL) {
  ------------------
  |  Branch (93:7): [True: 0, False: 409]
  ------------------
   94|      0|    return;
   95|      0|  }
   96|    409|  assert(method->is_static);
   97|    409|}

ERR_peek_last_error:
  328|    203|uint32_t ERR_peek_last_error(void) {
  329|    203|  return get_error_values(0 /* peek */, 1 /* top */, NULL, NULL, NULL, NULL);
  330|    203|}
ERR_clear_error:
  341|  7.33k|void ERR_clear_error(void) {
  342|  7.33k|  ERR_STATE *const state = err_get_state();
  343|  7.33k|  unsigned i;
  344|       |
  345|  7.33k|  if (state == NULL) {
  ------------------
  |  Branch (345:7): [True: 0, False: 7.33k]
  ------------------
  346|      0|    return;
  347|      0|  }
  348|       |
  349|   124k|  for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |  477|   124k|#define ERR_NUM_ERRORS 16
  ------------------
  |  Branch (349:15): [True: 117k, False: 7.33k]
  ------------------
  350|   117k|    err_clear(&state->errors[i]);
  351|   117k|  }
  352|  7.33k|  free(state->to_free);
  353|  7.33k|  state->to_free = NULL;
  354|       |
  355|  7.33k|  state->top = state->bottom = 0;
  356|  7.33k|}
ERR_put_error:
  657|  12.1k|                   unsigned line) {
  658|  12.1k|  ERR_STATE *const state = err_get_state();
  659|  12.1k|  struct err_error_st *error;
  660|       |
  661|  12.1k|  if (state == NULL) {
  ------------------
  |  Branch (661:7): [True: 0, False: 12.1k]
  ------------------
  662|      0|    return;
  663|      0|  }
  664|       |
  665|  12.1k|  if (library == ERR_LIB_SYS && reason == 0) {
  ------------------
  |  Branch (665:7): [True: 0, False: 12.1k]
  |  Branch (665:33): [True: 0, False: 0]
  ------------------
  666|       |#if defined(OPENSSL_WINDOWS)
  667|       |    reason = GetLastError();
  668|       |#else
  669|      0|    reason = errno;
  670|      0|#endif
  671|      0|  }
  672|       |
  673|  12.1k|  state->top = (state->top + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|  12.1k|#define ERR_NUM_ERRORS 16
  ------------------
  674|  12.1k|  if (state->top == state->bottom) {
  ------------------
  |  Branch (674:7): [True: 0, False: 12.1k]
  ------------------
  675|      0|    state->bottom = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|      0|#define ERR_NUM_ERRORS 16
  ------------------
  676|      0|  }
  677|       |
  678|  12.1k|  error = &state->errors[state->top];
  679|  12.1k|  err_clear(error);
  680|  12.1k|  error->file = file;
  681|  12.1k|  error->line = line;
  682|  12.1k|  error->packed = ERR_PACK(library, reason);
  ------------------
  |  |  480|  12.1k|  (((((uint32_t)(lib)) & 0xff) << 24) | ((((uint32_t)(reason)) & 0xfff)))
  ------------------
  683|  12.1k|}
ERR_add_error_data:
  728|  3.76k|void ERR_add_error_data(unsigned count, ...) {
  729|  3.76k|  va_list args;
  730|  3.76k|  va_start(args, count);
  731|  3.76k|  err_add_error_vdata(count, args);
  732|  3.76k|  va_end(args);
  733|  3.76k|}
err.c:get_error_values:
  231|    203|                                 const char **data, int *flags) {
  232|    203|  unsigned i = 0;
  233|    203|  ERR_STATE *state;
  234|    203|  struct err_error_st *error;
  235|    203|  uint32_t ret;
  236|       |
  237|    203|  state = err_get_state();
  238|    203|  if (state == NULL || state->bottom == state->top) {
  ------------------
  |  Branch (238:7): [True: 0, False: 203]
  |  Branch (238:24): [True: 0, False: 203]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|    203|  if (top) {
  ------------------
  |  Branch (242:7): [True: 203, False: 0]
  ------------------
  243|    203|    assert(!inc);
  244|       |    // last error
  245|    203|    i = state->top;
  246|    203|  } else {
  247|      0|    i = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|      0|#define ERR_NUM_ERRORS 16
  ------------------
  248|      0|  }
  249|       |
  250|    203|  error = &state->errors[i];
  251|    203|  ret = error->packed;
  252|       |
  253|    203|  if (file != NULL && line != NULL) {
  ------------------
  |  Branch (253:7): [True: 0, False: 203]
  |  Branch (253:23): [True: 0, False: 0]
  ------------------
  254|      0|    if (error->file == NULL) {
  ------------------
  |  Branch (254:9): [True: 0, False: 0]
  ------------------
  255|      0|      *file = "NA";
  256|      0|      *line = 0;
  257|      0|    } else {
  258|      0|      *file = error->file;
  259|      0|      *line = error->line;
  260|      0|    }
  261|      0|  }
  262|       |
  263|    203|  if (data != NULL) {
  ------------------
  |  Branch (263:7): [True: 0, False: 203]
  ------------------
  264|      0|    if (error->data == NULL) {
  ------------------
  |  Branch (264:9): [True: 0, False: 0]
  ------------------
  265|      0|      *data = "";
  266|      0|      if (flags != NULL) {
  ------------------
  |  Branch (266:11): [True: 0, False: 0]
  ------------------
  267|      0|        *flags = 0;
  268|      0|      }
  269|      0|    } else {
  270|      0|      *data = error->data;
  271|      0|      if (flags != NULL) {
  ------------------
  |  Branch (271:11): [True: 0, False: 0]
  ------------------
  272|       |        // Without |ERR_FLAG_MALLOCED|, rust-openssl assumes the string has a
  273|       |        // static lifetime. In both cases, we retain ownership of the string,
  274|       |        // and the caller is not expected to free it.
  275|      0|        *flags = ERR_FLAG_STRING | ERR_FLAG_MALLOCED;
  ------------------
  |  |  188|      0|#define ERR_FLAG_STRING 1
  ------------------
                      *flags = ERR_FLAG_STRING | ERR_FLAG_MALLOCED;
  ------------------
  |  |  197|      0|#define ERR_FLAG_MALLOCED 2
  ------------------
  276|      0|      }
  277|       |      // If this error is being removed, take ownership of data from
  278|       |      // the error. The semantics are such that the caller doesn't
  279|       |      // take ownership either. Instead the error system takes
  280|       |      // ownership and retains it until the next call that affects the
  281|       |      // error queue.
  282|      0|      if (inc) {
  ------------------
  |  Branch (282:11): [True: 0, False: 0]
  ------------------
  283|      0|        if (error->data != NULL) {
  ------------------
  |  Branch (283:13): [True: 0, False: 0]
  ------------------
  284|      0|          free(state->to_free);
  285|      0|          state->to_free = error->data;
  286|      0|        }
  287|      0|        error->data = NULL;
  288|      0|      }
  289|      0|    }
  290|      0|  }
  291|       |
  292|    203|  if (inc) {
  ------------------
  |  Branch (292:7): [True: 0, False: 203]
  ------------------
  293|      0|    assert(!top);
  294|      0|    err_clear(error);
  295|      0|    state->bottom = i;
  296|      0|  }
  297|       |
  298|    203|  return ret;
  299|    203|}
err.c:err_get_state:
  213|  23.4k|static ERR_STATE *err_get_state(void) {
  214|  23.4k|  ERR_STATE *state = CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_ERR);
  215|  23.4k|  if (state == NULL) {
  ------------------
  |  Branch (215:7): [True: 1, False: 23.4k]
  ------------------
  216|      1|    state = malloc(sizeof(ERR_STATE));
  217|      1|    if (state == NULL) {
  ------------------
  |  Branch (217:9): [True: 0, False: 1]
  ------------------
  218|      0|      return NULL;
  219|      0|    }
  220|      1|    OPENSSL_memset(state, 0, sizeof(ERR_STATE));
  221|      1|    if (!CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_ERR, state,
  ------------------
  |  Branch (221:9): [True: 0, False: 1]
  ------------------
  222|      1|                                 err_state_free)) {
  223|      0|      return NULL;
  224|      0|    }
  225|      1|  }
  226|       |
  227|  23.4k|  return state;
  228|  23.4k|}
err.c:err_clear:
  168|   129k|static void err_clear(struct err_error_st *error) {
  169|   129k|  free(error->data);
  170|   129k|  OPENSSL_memset(error, 0, sizeof(struct err_error_st));
  171|   129k|}
err.c:err_add_error_vdata:
  688|  3.76k|static void err_add_error_vdata(unsigned num, va_list args) {
  689|  3.76k|  size_t total_size = 0;
  690|  3.76k|  const char *substr;
  691|  3.76k|  char *buf;
  692|       |
  693|  3.76k|  va_list args_copy;
  694|  3.76k|  va_copy(args_copy, args);
  695|  18.2k|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (695:22): [True: 14.5k, False: 3.76k]
  ------------------
  696|  14.5k|    substr = va_arg(args_copy, const char *);
  697|  14.5k|    if (substr == NULL) {
  ------------------
  |  Branch (697:9): [True: 0, False: 14.5k]
  ------------------
  698|      0|      continue;
  699|      0|    }
  700|  14.5k|    size_t substr_len = strlen(substr);
  701|  14.5k|    if (SIZE_MAX - total_size < substr_len) {
  ------------------
  |  Branch (701:9): [True: 0, False: 14.5k]
  ------------------
  702|      0|      return; // Would overflow.
  703|      0|    }
  704|  14.5k|    total_size += substr_len;
  705|  14.5k|  }
  706|  3.76k|  va_end(args_copy);
  707|  3.76k|  if (total_size == SIZE_MAX) {
  ------------------
  |  Branch (707:7): [True: 0, False: 3.76k]
  ------------------
  708|      0|      return; // Would overflow.
  709|      0|  }
  710|  3.76k|  total_size += 1; // NUL terminator.
  711|  3.76k|  if ((buf = malloc(total_size)) == NULL) {
  ------------------
  |  Branch (711:7): [True: 0, False: 3.76k]
  ------------------
  712|      0|    return;
  713|      0|  }
  714|  3.76k|  buf[0] = '\0';
  715|  18.2k|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (715:22): [True: 14.5k, False: 3.76k]
  ------------------
  716|  14.5k|    substr = va_arg(args, const char *);
  717|  14.5k|    if (substr == NULL) {
  ------------------
  |  Branch (717:9): [True: 0, False: 14.5k]
  ------------------
  718|      0|      continue;
  719|      0|    }
  720|  14.5k|    if (OPENSSL_strlcat(buf, substr, total_size) >= total_size) {
  ------------------
  |  Branch (720:9): [True: 0, False: 14.5k]
  ------------------
  721|      0|      assert(0); // should not be possible.
  722|      0|    }
  723|  14.5k|  }
  724|  3.76k|  va_end(args);
  725|  3.76k|  err_set_error_data(buf);
  726|  3.76k|}
err.c:err_set_error_data:
  641|  3.76k|static void err_set_error_data(char *data) {
  642|  3.76k|  ERR_STATE *const state = err_get_state();
  643|  3.76k|  struct err_error_st *error;
  644|       |
  645|  3.76k|  if (state == NULL || state->top == state->bottom) {
  ------------------
  |  Branch (645:7): [True: 0, False: 3.76k]
  |  Branch (645:24): [True: 0, False: 3.76k]
  ------------------
  646|      0|    free(data);
  647|      0|    return;
  648|      0|  }
  649|       |
  650|  3.76k|  error = &state->errors[state->top];
  651|       |
  652|  3.76k|  free(error->data);
  653|  3.76k|  error->data = data;
  654|  3.76k|}

EVP_PKEY_new:
   83|  1.74k|EVP_PKEY *EVP_PKEY_new(void) {
   84|  1.74k|  EVP_PKEY *ret;
   85|       |
   86|  1.74k|  ret = OPENSSL_malloc(sizeof(EVP_PKEY));
   87|  1.74k|  if (ret == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 1.74k]
  ------------------
   88|      0|    return NULL;
   89|      0|  }
   90|       |
   91|  1.74k|  OPENSSL_memset(ret, 0, sizeof(EVP_PKEY));
   92|  1.74k|  ret->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  1.74k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  1.74k|#define NID_undef 0
  |  |  ------------------
  ------------------
   93|  1.74k|  ret->references = 1;
   94|       |
   95|  1.74k|  return ret;
   96|  1.74k|}
EVP_PKEY_free:
  106|  10.0k|void EVP_PKEY_free(EVP_PKEY *pkey) {
  107|  10.0k|  if (pkey == NULL) {
  ------------------
  |  Branch (107:7): [True: 7.77k, False: 2.25k]
  ------------------
  108|  7.77k|    return;
  109|  7.77k|  }
  110|       |
  111|  2.25k|  if (!CRYPTO_refcount_dec_and_test_zero(&pkey->references)) {
  ------------------
  |  Branch (111:7): [True: 512, False: 1.74k]
  ------------------
  112|    512|    return;
  113|    512|  }
  114|       |
  115|  1.74k|  free_it(pkey);
  116|  1.74k|  OPENSSL_free(pkey);
  117|  1.74k|}
EVP_PKEY_up_ref:
  119|    512|int EVP_PKEY_up_ref(EVP_PKEY *pkey) {
  120|    512|  CRYPTO_refcount_inc(&pkey->references);
  121|    512|  return 1;
  122|    512|}
EVP_PKEY_assign_RSA:
  248|     32|int EVP_PKEY_assign_RSA(EVP_PKEY *pkey, RSA *key) {
  249|     32|  return EVP_PKEY_assign(pkey, EVP_PKEY_RSA, key);
  ------------------
  |  |  175|     32|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|     32|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  250|     32|}
EVP_PKEY_assign_DSA:
  276|      4|int EVP_PKEY_assign_DSA(EVP_PKEY *pkey, DSA *key) {
  277|      4|  return EVP_PKEY_assign(pkey, EVP_PKEY_DSA, key);
  ------------------
  |  |  177|      4|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|      4|#define NID_dsa 116
  |  |  ------------------
  ------------------
  278|      4|}
EVP_PKEY_assign_EC_KEY:
  304|    474|int EVP_PKEY_assign_EC_KEY(EVP_PKEY *pkey, EC_KEY *key) {
  305|    474|  return EVP_PKEY_assign(pkey, EVP_PKEY_EC, key);
  ------------------
  |  |  178|    474|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|    474|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  306|    474|}
EVP_PKEY_assign:
  327|    510|int EVP_PKEY_assign(EVP_PKEY *pkey, int type, void *key) {
  328|    510|  if (!EVP_PKEY_set_type(pkey, type)) {
  ------------------
  |  Branch (328:7): [True: 0, False: 510]
  ------------------
  329|      0|    return 0;
  330|      0|  }
  331|    510|  pkey->pkey = key;
  332|    510|  return key != NULL;
  333|    510|}
EVP_PKEY_set_type:
  335|  2.25k|int EVP_PKEY_set_type(EVP_PKEY *pkey, int type) {
  336|  2.25k|  const EVP_PKEY_ASN1_METHOD *ameth;
  337|       |
  338|  2.25k|  if (pkey && pkey->pkey) {
  ------------------
  |  Branch (338:7): [True: 2.25k, False: 0]
  |  Branch (338:15): [True: 0, False: 2.25k]
  ------------------
  339|      0|    free_it(pkey);
  340|      0|  }
  341|       |
  342|  2.25k|  ameth = evp_pkey_asn1_find(type);
  343|  2.25k|  if (ameth == NULL) {
  ------------------
  |  Branch (343:7): [True: 0, False: 2.25k]
  ------------------
  344|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|    ERR_add_error_dataf("algorithm %d", type);
  346|      0|    return 0;
  347|      0|  }
  348|       |
  349|  2.25k|  if (pkey) {
  ------------------
  |  Branch (349:7): [True: 2.25k, False: 0]
  ------------------
  350|  2.25k|    pkey->ameth = ameth;
  351|  2.25k|    pkey->type = pkey->ameth->pkey_id;
  352|  2.25k|  }
  353|       |
  354|  2.25k|  return 1;
  355|  2.25k|}
evp.c:free_it:
   98|  1.74k|static void free_it(EVP_PKEY *pkey) {
   99|  1.74k|  if (pkey->ameth && pkey->ameth->pkey_free) {
  ------------------
  |  Branch (99:7): [True: 1.74k, False: 0]
  |  Branch (99:22): [True: 1.74k, False: 0]
  ------------------
  100|  1.74k|    pkey->ameth->pkey_free(pkey);
  101|  1.74k|    pkey->pkey = NULL;
  102|  1.74k|    pkey->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  1.74k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  1.74k|#define NID_undef 0
  |  |  ------------------
  ------------------
  103|  1.74k|  }
  104|  1.74k|}
evp.c:evp_pkey_asn1_find:
  215|  2.25k|static const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int nid) {
  216|  2.25k|  switch (nid) {
  217|    442|    case EVP_PKEY_RSA:
  ------------------
  |  |  175|    442|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|    442|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  |  Branch (217:5): [True: 442, False: 1.81k]
  ------------------
  218|    442|      return &rsa_asn1_meth;
  219|  1.22k|    case EVP_PKEY_EC:
  ------------------
  |  |  178|  1.22k|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|  1.22k|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (219:5): [True: 1.22k, False: 1.02k]
  ------------------
  220|  1.22k|      return &ec_asn1_meth;
  221|    509|    case EVP_PKEY_DSA:
  ------------------
  |  |  177|    509|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|    509|#define NID_dsa 116
  |  |  ------------------
  ------------------
  |  Branch (221:5): [True: 509, False: 1.74k]
  ------------------
  222|    509|      return &dsa_asn1_meth;
  223|     40|    case EVP_PKEY_ED25519:
  ------------------
  |  |  179|     40|#define EVP_PKEY_ED25519 NID_ED25519
  |  |  ------------------
  |  |  |  | 4199|     40|#define NID_ED25519 949
  |  |  ------------------
  ------------------
  |  Branch (223:5): [True: 40, False: 2.21k]
  ------------------
  224|     40|      return &ed25519_asn1_meth;
  225|     37|    case EVP_PKEY_X25519:
  ------------------
  |  |  180|     37|#define EVP_PKEY_X25519 NID_X25519
  |  |  ------------------
  |  |  |  | 4195|     37|#define NID_X25519 948
  |  |  ------------------
  ------------------
  |  Branch (225:5): [True: 37, False: 2.21k]
  ------------------
  226|     37|      return &x25519_asn1_meth;
  227|      0|    default:
  ------------------
  |  Branch (227:5): [True: 0, False: 2.25k]
  ------------------
  228|      0|      return NULL;
  229|  2.25k|  }
  230|  2.25k|}

EVP_parse_public_key:
   98|  2.09k|EVP_PKEY *EVP_parse_public_key(CBS *cbs) {
   99|       |  // Parse the SubjectPublicKeyInfo.
  100|  2.09k|  CBS spki, algorithm, key;
  101|  2.09k|  int type;
  102|  2.09k|  uint8_t padding;
  103|  2.09k|  if (!CBS_get_asn1(cbs, &spki, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  2.09k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  2.09k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  2.09k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (103:7): [True: 0, False: 2.09k]
  ------------------
  104|  2.09k|      !CBS_get_asn1(&spki, &algorithm, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  2.09k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  2.09k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  2.09k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (104:7): [True: 0, False: 2.09k]
  ------------------
  105|  2.09k|      !CBS_get_asn1(&spki, &key, CBS_ASN1_BITSTRING) ||
  ------------------
  |  |  216|  2.09k|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (105:7): [True: 0, False: 2.09k]
  ------------------
  106|  2.09k|      CBS_len(&spki) != 0) {
  ------------------
  |  Branch (106:7): [True: 0, False: 2.09k]
  ------------------
  107|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  108|      0|    return NULL;
  109|      0|  }
  110|  2.09k|  if (!parse_key_type(&algorithm, &type)) {
  ------------------
  |  Branch (110:7): [True: 344, False: 1.74k]
  ------------------
  111|    344|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|    344|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  112|    344|    return NULL;
  113|    344|  }
  114|  1.74k|  if (// Every key type defined encodes the key as a byte string with the same
  115|       |      // conversion to BIT STRING.
  116|  1.74k|      !CBS_get_u8(&key, &padding) ||
  ------------------
  |  Branch (116:7): [True: 0, False: 1.74k]
  ------------------
  117|  1.74k|      padding != 0) {
  ------------------
  |  Branch (117:7): [True: 2, False: 1.74k]
  ------------------
  118|      2|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  119|      2|    return NULL;
  120|      2|  }
  121|       |
  122|       |  // Set up an |EVP_PKEY| of the appropriate type.
  123|  1.74k|  EVP_PKEY *ret = EVP_PKEY_new();
  124|  1.74k|  if (ret == NULL ||
  ------------------
  |  Branch (124:7): [True: 0, False: 1.74k]
  ------------------
  125|  1.74k|      !EVP_PKEY_set_type(ret, type)) {
  ------------------
  |  Branch (125:7): [True: 0, False: 1.74k]
  ------------------
  126|      0|    goto err;
  127|      0|  }
  128|       |
  129|       |  // Call into the type-specific SPKI decoding function.
  130|  1.74k|  if (ret->ameth->pub_decode == NULL) {
  ------------------
  |  Branch (130:7): [True: 0, False: 1.74k]
  ------------------
  131|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|      0|    goto err;
  133|      0|  }
  134|  1.74k|  if (!ret->ameth->pub_decode(ret, &algorithm, &key)) {
  ------------------
  |  Branch (134:7): [True: 1.23k, False: 512]
  ------------------
  135|  1.23k|    goto err;
  136|  1.23k|  }
  137|       |
  138|    512|  return ret;
  139|       |
  140|  1.23k|err:
  141|  1.23k|  EVP_PKEY_free(ret);
  142|  1.23k|  return NULL;
  143|  1.74k|}
evp_asn1.c:parse_key_type:
   80|  2.09k|static int parse_key_type(CBS *cbs, int *out_type) {
   81|  2.09k|  CBS oid;
   82|  2.09k|  if (!CBS_get_asn1(cbs, &oid, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  2.09k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (82:7): [True: 0, False: 2.09k]
  ------------------
   83|      0|    return 0;
   84|      0|  }
   85|       |
   86|  5.84k|  for (unsigned i = 0; i < OPENSSL_ARRAY_SIZE(kASN1Methods); i++) {
  ------------------
  |  |  221|  5.84k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (86:24): [True: 5.50k, False: 344]
  ------------------
   87|  5.50k|    const EVP_PKEY_ASN1_METHOD *method = kASN1Methods[i];
   88|  5.50k|    if (CBS_len(&oid) == method->oid_len &&
  ------------------
  |  Branch (88:9): [True: 2.42k, False: 3.07k]
  ------------------
   89|  5.50k|        OPENSSL_memcmp(CBS_data(&oid), method->oid, method->oid_len) == 0) {
  ------------------
  |  Branch (89:9): [True: 1.74k, False: 682]
  ------------------
   90|  1.74k|      *out_type = method->pkey_id;
   91|  1.74k|      return 1;
   92|  1.74k|    }
   93|  5.50k|  }
   94|       |
   95|    344|  return 0;
   96|  2.09k|}

p_dsa_asn1.c:dsa_pub_decode:
   68|    505|static int dsa_pub_decode(EVP_PKEY *out, CBS *params, CBS *key) {
   69|       |  // See RFC 3279, section 2.3.2.
   70|       |
   71|       |  // Parameters may or may not be present.
   72|    505|  DSA *dsa;
   73|    505|  if (CBS_len(params) == 0) {
  ------------------
  |  Branch (73:7): [True: 26, False: 479]
  ------------------
   74|     26|    dsa = DSA_new();
   75|     26|    if (dsa == NULL) {
  ------------------
  |  Branch (75:9): [True: 0, False: 26]
  ------------------
   76|      0|      return 0;
   77|      0|    }
   78|    479|  } else {
   79|    479|    dsa = DSA_parse_parameters(params);
   80|    479|    if (dsa == NULL || CBS_len(params) != 0) {
  ------------------
  |  Branch (80:9): [True: 448, False: 31]
  |  Branch (80:24): [True: 0, False: 31]
  ------------------
   81|    448|      OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    448|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   82|    448|      goto err;
   83|    448|    }
   84|    479|  }
   85|       |
   86|     57|  dsa->pub_key = BN_new();
   87|     57|  if (dsa->pub_key == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 57]
  ------------------
   88|      0|    goto err;
   89|      0|  }
   90|       |
   91|     57|  if (!BN_parse_asn1_unsigned(key, dsa->pub_key) ||
  ------------------
  |  Branch (91:7): [True: 33, False: 24]
  ------------------
   92|     57|      CBS_len(key) != 0) {
  ------------------
  |  Branch (92:7): [True: 20, False: 4]
  ------------------
   93|     53|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     53|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   94|     53|    goto err;
   95|     53|  }
   96|       |
   97|      4|  EVP_PKEY_assign_DSA(out, dsa);
   98|      4|  return 1;
   99|       |
  100|    501|err:
  101|    501|  DSA_free(dsa);
  102|    501|  return 0;
  103|     57|}
p_dsa_asn1.c:int_dsa_free:
  259|    505|static void int_dsa_free(EVP_PKEY *pkey) {
  260|    505|  DSA_free(pkey->pkey);
  261|    505|  pkey->pkey = NULL;
  262|    505|}

p_ec_asn1.c:eckey_pub_decode:
   92|    753|static int eckey_pub_decode(EVP_PKEY *out, CBS *params, CBS *key) {
   93|       |  // See RFC 5480, section 2.
   94|       |
   95|       |  // The parameters are a named curve.
   96|    753|  EC_KEY *eckey = NULL;
   97|    753|  EC_GROUP *group = EC_KEY_parse_curve_name(params);
   98|    753|  if (group == NULL || CBS_len(params) != 0) {
  ------------------
  |  Branch (98:7): [True: 15, False: 738]
  |  Branch (98:24): [True: 0, False: 738]
  ------------------
   99|     15|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     15|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  100|     15|    goto err;
  101|     15|  }
  102|       |
  103|    738|  eckey = EC_KEY_new();
  104|    738|  if (eckey == NULL || //
  ------------------
  |  Branch (104:7): [True: 0, False: 738]
  ------------------
  105|    738|      !EC_KEY_set_group(eckey, group) ||
  ------------------
  |  Branch (105:7): [True: 0, False: 738]
  ------------------
  106|    738|      !EC_KEY_oct2key(eckey, CBS_data(key), CBS_len(key), NULL)) {
  ------------------
  |  Branch (106:7): [True: 264, False: 474]
  ------------------
  107|    264|    goto err;
  108|    264|  }
  109|       |
  110|    474|  EC_GROUP_free(group);
  111|    474|  EVP_PKEY_assign_EC_KEY(out, eckey);
  112|    474|  return 1;
  113|       |
  114|    279|err:
  115|    279|  EC_GROUP_free(group);
  116|    279|  EC_KEY_free(eckey);
  117|    279|  return 0;
  118|    738|}
p_ec_asn1.c:int_ec_free:
  264|    753|static void int_ec_free(EVP_PKEY *pkey) {
  265|    753|  EC_KEY_free(pkey->pkey);
  266|    753|  pkey->pkey = NULL;
  267|    753|}

p_ed25519_asn1.c:ed25519_pub_decode:
  114|     40|static int ed25519_pub_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  115|       |  // See RFC 8410, section 4.
  116|       |
  117|       |  // The parameters must be omitted. Public keys have length 32.
  118|     40|  if (CBS_len(params) != 0) {
  ------------------
  |  Branch (118:7): [True: 19, False: 21]
  ------------------
  119|     19|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     19|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  120|     19|    return 0;
  121|     19|  }
  122|       |
  123|     21|  return ed25519_set_pub_raw(out, CBS_data(key), CBS_len(key));
  124|     40|}
p_ed25519_asn1.c:ed25519_set_pub_raw:
   53|     21|static int ed25519_set_pub_raw(EVP_PKEY *pkey, const uint8_t *in, size_t len) {
   54|     21|  if (len != 32) {
  ------------------
  |  Branch (54:7): [True: 20, False: 1]
  ------------------
   55|     20|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   56|     20|    return 0;
   57|     20|  }
   58|       |
   59|      1|  ED25519_KEY *key = OPENSSL_malloc(sizeof(ED25519_KEY));
   60|      1|  if (key == NULL) {
  ------------------
  |  Branch (60:7): [True: 0, False: 1]
  ------------------
   61|      0|    return 0;
   62|      0|  }
   63|       |
   64|      1|  OPENSSL_memcpy(key->key + ED25519_PUBLIC_KEY_OFFSET, in, 32);
  ------------------
  |  |  278|      1|#define ED25519_PUBLIC_KEY_OFFSET 32
  ------------------
   65|      1|  key->has_private = 0;
   66|       |
   67|      1|  ed25519_free(pkey);
   68|      1|  pkey->pkey = key;
   69|      1|  return 1;
   70|      1|}
p_ed25519_asn1.c:ed25519_free:
   26|     41|static void ed25519_free(EVP_PKEY *pkey) {
   27|     41|  OPENSSL_free(pkey->pkey);
   28|     41|  pkey->pkey = NULL;
   29|     41|}

p_rsa_asn1.c:rsa_pub_decode:
   89|    410|static int rsa_pub_decode(EVP_PKEY *out, CBS *params, CBS *key) {
   90|       |  // See RFC 3279, section 2.3.1.
   91|       |
   92|       |  // The parameters must be NULL.
   93|    410|  CBS null;
   94|    410|  if (!CBS_get_asn1(params, &null, CBS_ASN1_NULL) ||
  ------------------
  |  |  218|    410|#define CBS_ASN1_NULL 0x5u
  ------------------
  |  Branch (94:7): [True: 1, False: 409]
  ------------------
   95|    410|      CBS_len(&null) != 0 ||
  ------------------
  |  Branch (95:7): [True: 0, False: 409]
  ------------------
   96|    410|      CBS_len(params) != 0) {
  ------------------
  |  Branch (96:7): [True: 0, False: 409]
  ------------------
   97|      1|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   98|      1|    return 0;
   99|      1|  }
  100|       |
  101|    409|  RSA *rsa = RSA_parse_public_key(key);
  102|    409|  if (rsa == NULL || CBS_len(key) != 0) {
  ------------------
  |  Branch (102:7): [True: 376, False: 33]
  |  Branch (102:22): [True: 1, False: 32]
  ------------------
  103|    377|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    377|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  104|    377|    RSA_free(rsa);
  105|    377|    return 0;
  106|    377|  }
  107|       |
  108|     32|  EVP_PKEY_assign_RSA(out, rsa);
  109|     32|  return 1;
  110|    409|}
p_rsa_asn1.c:int_rsa_free:
  174|    410|static void int_rsa_free(EVP_PKEY *pkey) {
  175|    410|  RSA_free(pkey->pkey);
  176|    410|  pkey->pkey = NULL;
  177|    410|}

p_x25519_asn1.c:x25519_pub_decode:
  128|     37|static int x25519_pub_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  129|       |  // See RFC 8410, section 4.
  130|       |
  131|       |  // The parameters must be omitted. Public keys have length 32.
  132|     37|  if (CBS_len(params) != 0) {
  ------------------
  |  Branch (132:7): [True: 21, False: 16]
  ------------------
  133|     21|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     21|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  134|     21|    return 0;
  135|     21|  }
  136|       |
  137|     16|  return x25519_set_pub_raw(out, CBS_data(key), CBS_len(key));
  138|     37|}
p_x25519_asn1.c:x25519_set_pub_raw:
   51|     16|static int x25519_set_pub_raw(EVP_PKEY *pkey, const uint8_t *in, size_t len) {
   52|     16|  if (len != 32) {
  ------------------
  |  Branch (52:7): [True: 15, False: 1]
  ------------------
   53|     15|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     15|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   54|     15|    return 0;
   55|     15|  }
   56|       |
   57|      1|  X25519_KEY *key = OPENSSL_malloc(sizeof(X25519_KEY));
   58|      1|  if (key == NULL) {
  ------------------
  |  Branch (58:7): [True: 0, False: 1]
  ------------------
   59|      0|    return 0;
   60|      0|  }
   61|       |
   62|      1|  OPENSSL_memcpy(key->pub, in, 32);
   63|      1|  key->has_private = 0;
   64|       |
   65|      1|  x25519_free(pkey);
   66|      1|  pkey->pkey = key;
   67|      1|  return 1;
   68|      1|}
p_x25519_asn1.c:x25519_free:
   26|     38|static void x25519_free(EVP_PKEY *pkey) {
   27|     38|  OPENSSL_free(pkey->pkey);
   28|     38|  pkey->pkey = NULL;
   29|     38|}

CRYPTO_new_ex_data:
  206|  6.77k|void CRYPTO_new_ex_data(CRYPTO_EX_DATA *ad) {
  207|  6.77k|  ad->sk = NULL;
  208|  6.77k|}
CRYPTO_free_ex_data:
  211|  6.77k|                         CRYPTO_EX_DATA *ad) {
  212|  6.77k|  if (ad->sk == NULL) {
  ------------------
  |  Branch (212:7): [True: 6.77k, False: 0]
  ------------------
  213|       |    // Nothing to do.
  214|  6.77k|    return;
  215|  6.77k|  }
  216|       |
  217|      0|  uint32_t num_funcs = CRYPTO_atomic_load_u32(&ex_data_class->num_funcs);
  218|       |  // |CRYPTO_get_ex_new_index| will not allocate indices beyond |INT_MAX|.
  219|      0|  assert(num_funcs <= (size_t)(INT_MAX - ex_data_class->num_reserved));
  220|       |
  221|       |  // Defer dereferencing |ex_data_class->funcs| and |funcs->next|. It must come
  222|       |  // after the |num_funcs| comparison to be correctly synchronized.
  223|      0|  CRYPTO_EX_DATA_FUNCS *const *funcs = &ex_data_class->funcs;
  224|      0|  for (uint32_t i = 0; i < num_funcs; i++) {
  ------------------
  |  Branch (224:24): [True: 0, False: 0]
  ------------------
  225|      0|    if ((*funcs)->free_func != NULL) {
  ------------------
  |  Branch (225:9): [True: 0, False: 0]
  ------------------
  226|      0|      int index = (int)i + ex_data_class->num_reserved;
  227|      0|      void *ptr = CRYPTO_get_ex_data(ad, index);
  228|      0|      (*funcs)->free_func(obj, ptr, ad, index, (*funcs)->argl, (*funcs)->argp);
  229|      0|    }
  230|      0|    funcs = &(*funcs)->next;
  231|      0|  }
  232|       |
  233|      0|  sk_void_free(ad->sk);
  234|      0|  ad->sk = NULL;
  235|      0|}

BN_add_word:
  138|    192|int BN_add_word(BIGNUM *a, BN_ULONG w) {
  139|    192|  BN_ULONG l;
  140|    192|  int i;
  141|       |
  142|       |  // degenerate case: w is zero
  143|    192|  if (!w) {
  ------------------
  |  Branch (143:7): [True: 0, False: 192]
  ------------------
  144|      0|    return 1;
  145|      0|  }
  146|       |
  147|       |  // degenerate case: a is zero
  148|    192|  if (BN_is_zero(a)) {
  ------------------
  |  Branch (148:7): [True: 0, False: 192]
  ------------------
  149|      0|    return BN_set_word(a, w);
  150|      0|  }
  151|       |
  152|       |  // handle 'a' when negative
  153|    192|  if (a->neg) {
  ------------------
  |  Branch (153:7): [True: 0, False: 192]
  ------------------
  154|      0|    a->neg = 0;
  155|      0|    i = BN_sub_word(a, w);
  156|      0|    if (!BN_is_zero(a)) {
  ------------------
  |  Branch (156:9): [True: 0, False: 0]
  ------------------
  157|      0|      a->neg = !(a->neg);
  158|      0|    }
  159|      0|    return i;
  160|      0|  }
  161|       |
  162|  1.20k|  for (i = 0; w != 0 && i < a->width; i++) {
  ------------------
  |  Branch (162:15): [True: 1.01k, False: 192]
  |  Branch (162:25): [True: 1.01k, False: 0]
  ------------------
  163|  1.01k|    a->d[i] = l = a->d[i] + w;
  164|  1.01k|    w = (w > l) ? 1 : 0;
  ------------------
  |  Branch (164:9): [True: 818, False: 192]
  ------------------
  165|  1.01k|  }
  166|       |
  167|    192|  if (w && i == a->width) {
  ------------------
  |  Branch (167:7): [True: 0, False: 192]
  |  Branch (167:12): [True: 0, False: 0]
  ------------------
  168|      0|    if (!bn_wexpand(a, a->width + 1)) {
  ------------------
  |  Branch (168:9): [True: 0, False: 0]
  ------------------
  169|      0|      return 0;
  170|      0|    }
  171|      0|    a->width++;
  172|      0|    a->d[i] = w;
  173|      0|  }
  174|       |
  175|    192|  return 1;
  176|    192|}
BN_sub:
  178|      4|int BN_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  179|      4|  int add = 0, neg = 0;
  180|      4|  const BIGNUM *tmp;
  181|       |
  182|       |  //  a -  b	a-b
  183|       |  //  a - -b	a+b
  184|       |  // -a -  b	-(a+b)
  185|       |  // -a - -b	b-a
  186|      4|  if (a->neg) {
  ------------------
  |  Branch (186:7): [True: 0, False: 4]
  ------------------
  187|      0|    if (b->neg) {
  ------------------
  |  Branch (187:9): [True: 0, False: 0]
  ------------------
  188|      0|      tmp = a;
  189|      0|      a = b;
  190|      0|      b = tmp;
  191|      0|    } else {
  192|      0|      add = 1;
  193|      0|      neg = 1;
  194|      0|    }
  195|      4|  } else {
  196|      4|    if (b->neg) {
  ------------------
  |  Branch (196:9): [True: 0, False: 4]
  ------------------
  197|      0|      add = 1;
  198|      0|      neg = 0;
  199|      0|    }
  200|      4|  }
  201|       |
  202|      4|  if (add) {
  ------------------
  |  Branch (202:7): [True: 0, False: 4]
  ------------------
  203|      0|    if (!BN_uadd(r, a, b)) {
  ------------------
  |  Branch (203:9): [True: 0, False: 0]
  ------------------
  204|      0|      return 0;
  205|      0|    }
  206|       |
  207|      0|    r->neg = neg;
  208|      0|    return 1;
  209|      0|  }
  210|       |
  211|      4|  if (BN_ucmp(a, b) < 0) {
  ------------------
  |  Branch (211:7): [True: 0, False: 4]
  ------------------
  212|      0|    if (!BN_usub(r, b, a)) {
  ------------------
  |  Branch (212:9): [True: 0, False: 0]
  ------------------
  213|      0|      return 0;
  214|      0|    }
  215|      0|    r->neg = 1;
  216|      4|  } else {
  217|      4|    if (!BN_usub(r, a, b)) {
  ------------------
  |  Branch (217:9): [True: 0, False: 4]
  ------------------
  218|      0|      return 0;
  219|      0|    }
  220|      4|    r->neg = 0;
  221|      4|  }
  222|       |
  223|      4|  return 1;
  224|      4|}
bn_usub_consttime:
  226|    289|int bn_usub_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  227|       |  // |b| may have more words than |a| given non-minimal inputs, but all words
  228|       |  // beyond |a->width| must then be zero.
  229|    289|  int b_width = b->width;
  230|    289|  if (b_width > a->width) {
  ------------------
  |  Branch (230:7): [True: 0, False: 289]
  ------------------
  231|      0|    if (!bn_fits_in_words(b, a->width)) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  233|      0|      return 0;
  234|      0|    }
  235|      0|    b_width = a->width;
  236|      0|  }
  237|       |
  238|    289|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (238:7): [True: 0, False: 289]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|    289|  BN_ULONG borrow = bn_sub_words(r->d, a->d, b->d, b_width);
  243|    289|  for (int i = b_width; i < a->width; i++) {
  ------------------
  |  Branch (243:25): [True: 0, False: 289]
  ------------------
  244|       |    // |r| and |a| may alias, so use a temporary.
  245|      0|    BN_ULONG tmp = a->d[i];
  246|      0|    r->d[i] = a->d[i] - borrow;
  247|      0|    borrow = tmp < r->d[i];
  248|      0|  }
  249|       |
  250|    289|  if (borrow) {
  ------------------
  |  Branch (250:7): [True: 0, False: 289]
  ------------------
  251|      0|    OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  252|      0|    return 0;
  253|      0|  }
  254|       |
  255|    289|  r->width = a->width;
  256|    289|  r->neg = 0;
  257|    289|  return 1;
  258|    289|}
BN_usub:
  260|    289|int BN_usub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  261|    289|  if (!bn_usub_consttime(r, a, b)) {
  ------------------
  |  Branch (261:7): [True: 0, False: 289]
  ------------------
  262|      0|    return 0;
  263|      0|  }
  264|    289|  bn_set_minimal_width(r);
  265|    289|  return 1;
  266|    289|}

bn_mul_add_words:
   98|   117k|                          BN_ULONG w) {
   99|   117k|  BN_ULONG c1 = 0;
  100|       |
  101|   117k|  if (num == 0) {
  ------------------
  |  Branch (101:7): [True: 0, False: 117k]
  ------------------
  102|      0|    return (c1);
  103|      0|  }
  104|       |
  105|   237k|  while (num & ~3) {
  ------------------
  |  Branch (105:10): [True: 120k, False: 117k]
  ------------------
  106|   120k|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|   120k|  do {                                                                     \
  |  |   70|   120k|    register BN_ULONG high, low;                                           \
  |  |   71|   120k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   120k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   120k|            : "a"(low), "g"(0)                                             \
  |  |   75|   120k|            : "cc");                                                       \
  |  |   76|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   120k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   120k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   120k|            : "cc");                                                       \
  |  |   80|   120k|    (carry) = high;                                                        \
  |  |   81|   120k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  107|   120k|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|   120k|  do {                                                                     \
  |  |   70|   120k|    register BN_ULONG high, low;                                           \
  |  |   71|   120k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   120k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   120k|            : "a"(low), "g"(0)                                             \
  |  |   75|   120k|            : "cc");                                                       \
  |  |   76|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   120k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   120k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   120k|            : "cc");                                                       \
  |  |   80|   120k|    (carry) = high;                                                        \
  |  |   81|   120k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  108|   120k|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|   120k|  do {                                                                     \
  |  |   70|   120k|    register BN_ULONG high, low;                                           \
  |  |   71|   120k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   120k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   120k|            : "a"(low), "g"(0)                                             \
  |  |   75|   120k|            : "cc");                                                       \
  |  |   76|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   120k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   120k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   120k|            : "cc");                                                       \
  |  |   80|   120k|    (carry) = high;                                                        \
  |  |   81|   120k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  109|   120k|    mul_add(rp[3], ap[3], w, c1);
  ------------------
  |  |   69|   120k|  do {                                                                     \
  |  |   70|   120k|    register BN_ULONG high, low;                                           \
  |  |   71|   120k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   120k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   120k|            : "a"(low), "g"(0)                                             \
  |  |   75|   120k|            : "cc");                                                       \
  |  |   76|   120k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   120k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   120k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   120k|            : "cc");                                                       \
  |  |   80|   120k|    (carry) = high;                                                        \
  |  |   81|   120k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  110|   120k|    ap += 4;
  111|   120k|    rp += 4;
  112|   120k|    num -= 4;
  113|   120k|  }
  114|   117k|  if (num) {
  ------------------
  |  Branch (114:7): [True: 7.25k, False: 110k]
  ------------------
  115|  7.25k|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|  7.25k|  do {                                                                     \
  |  |   70|  7.25k|    register BN_ULONG high, low;                                           \
  |  |   71|  7.25k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  7.25k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  7.25k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  7.25k|            : "a"(low), "g"(0)                                             \
  |  |   75|  7.25k|            : "cc");                                                       \
  |  |   76|  7.25k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  7.25k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  7.25k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  7.25k|            : "cc");                                                       \
  |  |   80|  7.25k|    (carry) = high;                                                        \
  |  |   81|  7.25k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|  7.25k|    if (--num == 0) {
  ------------------
  |  Branch (116:9): [True: 4.14k, False: 3.10k]
  ------------------
  117|  4.14k|      return c1;
  118|  4.14k|    }
  119|  3.10k|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|  3.10k|  do {                                                                     \
  |  |   70|  3.10k|    register BN_ULONG high, low;                                           \
  |  |   71|  3.10k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  3.10k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  3.10k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  3.10k|            : "a"(low), "g"(0)                                             \
  |  |   75|  3.10k|            : "cc");                                                       \
  |  |   76|  3.10k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  3.10k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  3.10k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  3.10k|            : "cc");                                                       \
  |  |   80|  3.10k|    (carry) = high;                                                        \
  |  |   81|  3.10k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  120|  3.10k|    if (--num == 0) {
  ------------------
  |  Branch (120:9): [True: 2.52k, False: 578]
  ------------------
  121|  2.52k|      return c1;
  122|  2.52k|    }
  123|    578|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|    578|  do {                                                                     \
  |  |   70|    578|    register BN_ULONG high, low;                                           \
  |  |   71|    578|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|    578|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|    578|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|    578|            : "a"(low), "g"(0)                                             \
  |  |   75|    578|            : "cc");                                                       \
  |  |   76|    578|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|    578|            : "+m"(r), "+d"(high)                                          \
  |  |   78|    578|            : "r"(carry), "g"(0)                                           \
  |  |   79|    578|            : "cc");                                                       \
  |  |   80|    578|    (carry) = high;                                                        \
  |  |   81|    578|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  124|    578|    return c1;
  125|  3.10k|  }
  126|       |
  127|   110k|  return c1;
  128|   117k|}
bn_mul_words:
  131|  4.47M|                      BN_ULONG w) {
  132|  4.47M|  BN_ULONG c1 = 0;
  133|       |
  134|  4.47M|  if (num == 0) {
  ------------------
  |  Branch (134:7): [True: 0, False: 4.47M]
  ------------------
  135|      0|    return c1;
  136|      0|  }
  137|       |
  138|  8.91M|  while (num & ~3) {
  ------------------
  |  Branch (138:10): [True: 4.44M, False: 4.47M]
  ------------------
  139|  4.44M|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|  4.44M|  do {                                                                     \
  |  |   85|  4.44M|    register BN_ULONG high, low;                                           \
  |  |   86|  4.44M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  4.44M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  4.44M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  4.44M|            : "a"(low), "g"(0)                                             \
  |  |   90|  4.44M|            : "cc");                                                       \
  |  |   91|  4.44M|    (r) = (carry);                                                         \
  |  |   92|  4.44M|    (carry) = high;                                                        \
  |  |   93|  4.44M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  140|  4.44M|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|  4.44M|  do {                                                                     \
  |  |   85|  4.44M|    register BN_ULONG high, low;                                           \
  |  |   86|  4.44M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  4.44M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  4.44M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  4.44M|            : "a"(low), "g"(0)                                             \
  |  |   90|  4.44M|            : "cc");                                                       \
  |  |   91|  4.44M|    (r) = (carry);                                                         \
  |  |   92|  4.44M|    (carry) = high;                                                        \
  |  |   93|  4.44M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  141|  4.44M|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|  4.44M|  do {                                                                     \
  |  |   85|  4.44M|    register BN_ULONG high, low;                                           \
  |  |   86|  4.44M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  4.44M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  4.44M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  4.44M|            : "a"(low), "g"(0)                                             \
  |  |   90|  4.44M|            : "cc");                                                       \
  |  |   91|  4.44M|    (r) = (carry);                                                         \
  |  |   92|  4.44M|    (carry) = high;                                                        \
  |  |   93|  4.44M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  142|  4.44M|    mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   84|  4.44M|  do {                                                                     \
  |  |   85|  4.44M|    register BN_ULONG high, low;                                           \
  |  |   86|  4.44M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  4.44M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  4.44M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  4.44M|            : "a"(low), "g"(0)                                             \
  |  |   90|  4.44M|            : "cc");                                                       \
  |  |   91|  4.44M|    (r) = (carry);                                                         \
  |  |   92|  4.44M|    (carry) = high;                                                        \
  |  |   93|  4.44M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  143|  4.44M|    ap += 4;
  144|  4.44M|    rp += 4;
  145|  4.44M|    num -= 4;
  146|  4.44M|  }
  147|  4.47M|  if (num) {
  ------------------
  |  Branch (147:7): [True: 36.5k, False: 4.43M]
  ------------------
  148|  36.5k|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|  36.5k|  do {                                                                     \
  |  |   85|  36.5k|    register BN_ULONG high, low;                                           \
  |  |   86|  36.5k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  36.5k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  36.5k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  36.5k|            : "a"(low), "g"(0)                                             \
  |  |   90|  36.5k|            : "cc");                                                       \
  |  |   91|  36.5k|    (r) = (carry);                                                         \
  |  |   92|  36.5k|    (carry) = high;                                                        \
  |  |   93|  36.5k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  149|  36.5k|    if (--num == 0) {
  ------------------
  |  Branch (149:9): [True: 34.6k, False: 1.94k]
  ------------------
  150|  34.6k|      return c1;
  151|  34.6k|    }
  152|  1.94k|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|  1.94k|  do {                                                                     \
  |  |   85|  1.94k|    register BN_ULONG high, low;                                           \
  |  |   86|  1.94k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  1.94k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  1.94k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  1.94k|            : "a"(low), "g"(0)                                             \
  |  |   90|  1.94k|            : "cc");                                                       \
  |  |   91|  1.94k|    (r) = (carry);                                                         \
  |  |   92|  1.94k|    (carry) = high;                                                        \
  |  |   93|  1.94k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|  1.94k|    if (--num == 0) {
  ------------------
  |  Branch (153:9): [True: 85, False: 1.86k]
  ------------------
  154|     85|      return c1;
  155|     85|    }
  156|  1.86k|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|  1.86k|  do {                                                                     \
  |  |   85|  1.86k|    register BN_ULONG high, low;                                           \
  |  |   86|  1.86k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  1.86k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  1.86k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  1.86k|            : "a"(low), "g"(0)                                             \
  |  |   90|  1.86k|            : "cc");                                                       \
  |  |   91|  1.86k|    (r) = (carry);                                                         \
  |  |   92|  1.86k|    (carry) = high;                                                        \
  |  |   93|  1.86k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|  1.86k|  }
  158|  4.43M|  return c1;
  159|  4.47M|}
bn_sqr_words:
  161|    375|void bn_sqr_words(BN_ULONG *r, const BN_ULONG *a, size_t n) {
  162|    375|  if (n == 0) {
  ------------------
  |  Branch (162:7): [True: 0, False: 375]
  ------------------
  163|      0|    return;
  164|      0|  }
  165|       |
  166|    953|  while (n & ~3) {
  ------------------
  |  Branch (166:10): [True: 578, False: 375]
  ------------------
  167|    578|    sqr(r[0], r[1], a[0]);
  ------------------
  |  |   95|    578|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  168|    578|    sqr(r[2], r[3], a[1]);
  ------------------
  |  |   95|    578|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  169|    578|    sqr(r[4], r[5], a[2]);
  ------------------
  |  |   95|    578|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  170|    578|    sqr(r[6], r[7], a[3]);
  ------------------
  |  |   95|    578|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  171|    578|    a += 4;
  172|    578|    r += 8;
  173|    578|    n -= 4;
  174|    578|  }
  175|    375|  if (n) {
  ------------------
  |  Branch (175:7): [True: 375, False: 0]
  ------------------
  176|    375|    sqr(r[0], r[1], a[0]);
  ------------------
  |  |   95|    375|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  177|    375|    if (--n == 0) {
  ------------------
  |  Branch (177:9): [True: 204, False: 171]
  ------------------
  178|    204|      return;
  179|    204|    }
  180|    171|    sqr(r[2], r[3], a[1]);
  ------------------
  |  |   95|    171|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  181|    171|    if (--n == 0) {
  ------------------
  |  Branch (181:9): [True: 170, False: 1]
  ------------------
  182|    170|      return;
  183|    170|    }
  184|      1|    sqr(r[4], r[5], a[2]);
  ------------------
  |  |   95|      1|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  185|      1|  }
  186|    375|}
bn_add_words:
  189|   401k|                      size_t n) {
  190|   401k|  BN_ULONG ret;
  191|   401k|  size_t i = 0;
  192|       |
  193|   401k|  if (n == 0) {
  ------------------
  |  Branch (193:7): [True: 0, False: 401k]
  ------------------
  194|      0|    return 0;
  195|      0|  }
  196|       |
  197|   401k|  __asm__ volatile (
  198|   401k|      "	subq	%0,%0		\n"  // clear carry
  199|   401k|      "	jmp	1f		\n"
  200|   401k|      ".p2align 4			\n"
  201|   401k|      "1:"
  202|   401k|      "	movq	(%4,%2,8),%0	\n"
  203|   401k|      "	adcq	(%5,%2,8),%0	\n"
  204|   401k|      "	movq	%0,(%3,%2,8)	\n"
  205|   401k|      "	lea	1(%2),%2	\n"
  206|   401k|      "	dec	%1		\n"
  207|   401k|      "	jnz	1b		\n"
  208|   401k|      "	sbbq	%0,%0		\n"
  209|   401k|      : "=&r"(ret), "+c"(n), "+r"(i)
  210|   401k|      : "r"(rp), "r"(ap), "r"(bp)
  211|   401k|      : "cc", "memory");
  212|       |
  213|   401k|  return ret & 1;
  214|   401k|}
bn_sub_words:
  217|  4.82M|                      size_t n) {
  218|  4.82M|  BN_ULONG ret;
  219|  4.82M|  size_t i = 0;
  220|       |
  221|  4.82M|  if (n == 0) {
  ------------------
  |  Branch (221:7): [True: 0, False: 4.82M]
  ------------------
  222|      0|    return 0;
  223|      0|  }
  224|       |
  225|  4.82M|  __asm__ volatile (
  226|  4.82M|      "	subq	%0,%0		\n"  // clear borrow
  227|  4.82M|      "	jmp	1f		\n"
  228|  4.82M|      ".p2align 4			\n"
  229|  4.82M|      "1:"
  230|  4.82M|      "	movq	(%4,%2,8),%0	\n"
  231|  4.82M|      "	sbbq	(%5,%2,8),%0	\n"
  232|  4.82M|      "	movq	%0,(%3,%2,8)	\n"
  233|  4.82M|      "	lea	1(%2),%2	\n"
  234|  4.82M|      "	dec	%1		\n"
  235|  4.82M|      "	jnz	1b		\n"
  236|  4.82M|      "	sbbq	%0,%0		\n"
  237|  4.82M|      : "=&r"(ret), "+c"(n), "+r"(i)
  238|  4.82M|      : "r"(rp), "r"(ap), "r"(bp)
  239|  4.82M|      : "cc", "memory");
  240|       |
  241|  4.82M|  return ret & 1;
  242|  4.82M|}
bn_sqr_comba4:
  501|   845k|void bn_sqr_comba4(BN_ULONG r[8], const BN_ULONG a[4]) {
  502|   845k|  BN_ULONG c1, c2, c3;
  503|       |
  504|   845k|  c1 = 0;
  505|   845k|  c2 = 0;
  506|   845k|  c3 = 0;
  507|   845k|  sqr_add_c(a, 0, c1, c2, c3);
  ------------------
  |  |  262|   845k|  do {                                                            \
  |  |  263|   845k|    BN_ULONG t1, t2;                                              \
  |  |  264|   845k|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|   845k|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|   845k|            : "cc");                                              \
  |  |  269|   845k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  508|   845k|  r[0] = c1;
  509|   845k|  c1 = 0;
  510|   845k|  sqr_add_c2(a, 1, 0, c2, c3, c1);
  ------------------
  |  |  285|   845k|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|   845k|  do {                                                               \
  |  |  |  |  273|   845k|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|   845k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|   845k|            : "cc");                                                 \
  |  |  |  |  279|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|   845k|            : "cc");                                                 \
  |  |  |  |  283|   845k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  511|   845k|  r[1] = c2;
  512|   845k|  c2 = 0;
  513|   845k|  sqr_add_c(a, 1, c3, c1, c2);
  ------------------
  |  |  262|   845k|  do {                                                            \
  |  |  263|   845k|    BN_ULONG t1, t2;                                              \
  |  |  264|   845k|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|   845k|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|   845k|            : "cc");                                              \
  |  |  269|   845k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  514|   845k|  sqr_add_c2(a, 2, 0, c3, c1, c2);
  ------------------
  |  |  285|   845k|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|   845k|  do {                                                               \
  |  |  |  |  273|   845k|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|   845k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|   845k|            : "cc");                                                 \
  |  |  |  |  279|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|   845k|            : "cc");                                                 \
  |  |  |  |  283|   845k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  515|   845k|  r[2] = c3;
  516|   845k|  c3 = 0;
  517|   845k|  sqr_add_c2(a, 3, 0, c1, c2, c3);
  ------------------
  |  |  285|   845k|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|   845k|  do {                                                               \
  |  |  |  |  273|   845k|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|   845k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|   845k|            : "cc");                                                 \
  |  |  |  |  279|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|   845k|            : "cc");                                                 \
  |  |  |  |  283|   845k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  518|   845k|  sqr_add_c2(a, 2, 1, c1, c2, c3);
  ------------------
  |  |  285|   845k|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|   845k|  do {                                                               \
  |  |  |  |  273|   845k|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|   845k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|   845k|            : "cc");                                                 \
  |  |  |  |  279|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|   845k|            : "cc");                                                 \
  |  |  |  |  283|   845k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  519|   845k|  r[3] = c1;
  520|   845k|  c1 = 0;
  521|   845k|  sqr_add_c(a, 2, c2, c3, c1);
  ------------------
  |  |  262|   845k|  do {                                                            \
  |  |  263|   845k|    BN_ULONG t1, t2;                                              \
  |  |  264|   845k|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|   845k|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|   845k|            : "cc");                                              \
  |  |  269|   845k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  522|   845k|  sqr_add_c2(a, 3, 1, c2, c3, c1);
  ------------------
  |  |  285|   845k|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|   845k|  do {                                                               \
  |  |  |  |  273|   845k|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|   845k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|   845k|            : "cc");                                                 \
  |  |  |  |  279|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|   845k|            : "cc");                                                 \
  |  |  |  |  283|   845k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  523|   845k|  r[4] = c2;
  524|   845k|  c2 = 0;
  525|   845k|  sqr_add_c2(a, 3, 2, c3, c1, c2);
  ------------------
  |  |  285|   845k|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|   845k|  do {                                                               \
  |  |  |  |  273|   845k|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|   845k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|   845k|            : "cc");                                                 \
  |  |  |  |  279|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|   845k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|   845k|            : "cc");                                                 \
  |  |  |  |  283|   845k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  526|   845k|  r[5] = c3;
  527|   845k|  c3 = 0;
  528|   845k|  sqr_add_c(a, 3, c1, c2, c3);
  ------------------
  |  |  262|   845k|  do {                                                            \
  |  |  263|   845k|    BN_ULONG t1, t2;                                              \
  |  |  264|   845k|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|   845k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|   845k|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|   845k|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|   845k|            : "cc");                                              \
  |  |  269|   845k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  529|   845k|  r[6] = c1;
  530|   845k|  r[7] = c2;
  531|   845k|}

BN_new:
   75|  19.3k|BIGNUM *BN_new(void) {
   76|  19.3k|  BIGNUM *bn = OPENSSL_malloc(sizeof(BIGNUM));
   77|       |
   78|  19.3k|  if (bn == NULL) {
  ------------------
  |  Branch (78:7): [True: 0, False: 19.3k]
  ------------------
   79|      0|    return NULL;
   80|      0|  }
   81|       |
   82|  19.3k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   83|  19.3k|  bn->flags = BN_FLG_MALLOCED;
  ------------------
  |  | 1026|  19.3k|#define BN_FLG_MALLOCED 0x01
  ------------------
   84|       |
   85|  19.3k|  return bn;
   86|  19.3k|}
BN_init:
   90|  2.35k|void BN_init(BIGNUM *bn) {
   91|  2.35k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   92|  2.35k|}
BN_free:
   94|  26.8k|void BN_free(BIGNUM *bn) {
   95|  26.8k|  if (bn == NULL) {
  ------------------
  |  Branch (95:7): [True: 5.19k, False: 21.6k]
  ------------------
   96|  5.19k|    return;
   97|  5.19k|  }
   98|       |
   99|  21.6k|  if ((bn->flags & BN_FLG_STATIC_DATA) == 0) {
  ------------------
  |  | 1027|  21.6k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (99:7): [True: 21.6k, False: 0]
  ------------------
  100|  21.6k|    OPENSSL_free(bn->d);
  101|  21.6k|  }
  102|       |
  103|  21.6k|  if (bn->flags & BN_FLG_MALLOCED) {
  ------------------
  |  | 1026|  21.6k|#define BN_FLG_MALLOCED 0x01
  ------------------
  |  Branch (103:7): [True: 19.3k, False: 2.33k]
  ------------------
  104|  19.3k|    OPENSSL_free(bn);
  105|  19.3k|  } else {
  106|  2.33k|    bn->d = NULL;
  107|  2.33k|  }
  108|  21.6k|}
BN_clear_free:
  110|  2.52k|void BN_clear_free(BIGNUM *bn) {
  111|  2.52k|  BN_free(bn);
  112|  2.52k|}
BN_copy:
  134|  48.1k|BIGNUM *BN_copy(BIGNUM *dest, const BIGNUM *src) {
  135|  48.1k|  if (src == dest) {
  ------------------
  |  Branch (135:7): [True: 1.16k, False: 46.9k]
  ------------------
  136|  1.16k|    return dest;
  137|  1.16k|  }
  138|       |
  139|  46.9k|  if (!bn_wexpand(dest, src->width)) {
  ------------------
  |  Branch (139:7): [True: 0, False: 46.9k]
  ------------------
  140|      0|    return NULL;
  141|      0|  }
  142|       |
  143|  46.9k|  OPENSSL_memcpy(dest->d, src->d, sizeof(src->d[0]) * src->width);
  144|       |
  145|  46.9k|  dest->width = src->width;
  146|  46.9k|  dest->neg = src->neg;
  147|  46.9k|  return dest;
  148|  46.9k|}
BN_num_bits_word:
  170|   896k|unsigned BN_num_bits_word(BN_ULONG l) {
  171|       |  // |BN_num_bits| is often called on RSA prime factors. These have public bit
  172|       |  // lengths, but all bits beyond the high bit are secret, so count bits in
  173|       |  // constant time.
  174|   896k|  BN_ULONG x, mask;
  175|   896k|  int bits = (l != 0);
  176|       |
  177|   896k|#if BN_BITS2 > 32
  178|       |  // Look at the upper half of |x|. |x| is at most 64 bits long.
  179|   896k|  x = l >> 32;
  180|       |  // Set |mask| to all ones if |x| (the top 32 bits of |l|) is non-zero and all
  181|       |  // all zeros otherwise.
  182|   896k|  mask = 0u - x;
  183|   896k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  184|       |  // If |x| is non-zero, the lower half is included in the bit count in full,
  185|       |  // and we count the upper half. Otherwise, we count the lower half.
  186|   896k|  bits += 32 & mask;
  187|   896k|  l ^= (x ^ l) & mask;  // |l| is |x| if |mask| and remains |l| otherwise.
  188|   896k|#endif
  189|       |
  190|       |  // The remaining blocks are analogous iterations at lower powers of two.
  191|   896k|  x = l >> 16;
  192|   896k|  mask = 0u - x;
  193|   896k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  194|   896k|  bits += 16 & mask;
  195|   896k|  l ^= (x ^ l) & mask;
  196|       |
  197|   896k|  x = l >> 8;
  198|   896k|  mask = 0u - x;
  199|   896k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  200|   896k|  bits += 8 & mask;
  201|   896k|  l ^= (x ^ l) & mask;
  202|       |
  203|   896k|  x = l >> 4;
  204|   896k|  mask = 0u - x;
  205|   896k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  206|   896k|  bits += 4 & mask;
  207|   896k|  l ^= (x ^ l) & mask;
  208|       |
  209|   896k|  x = l >> 2;
  210|   896k|  mask = 0u - x;
  211|   896k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  212|   896k|  bits += 2 & mask;
  213|   896k|  l ^= (x ^ l) & mask;
  214|       |
  215|   896k|  x = l >> 1;
  216|   896k|  mask = 0u - x;
  217|   896k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  218|   896k|  bits += 1 & mask;
  219|       |
  220|   896k|  return bits;
  221|   896k|}
BN_num_bits:
  223|   896k|unsigned BN_num_bits(const BIGNUM *bn) {
  224|   896k|  const int width = bn_minimal_width(bn);
  225|   896k|  if (width == 0) {
  ------------------
  |  Branch (225:7): [True: 2, False: 896k]
  ------------------
  226|      2|    return 0;
  227|      2|  }
  228|       |
  229|   896k|  return (width - 1) * BN_BITS2 + BN_num_bits_word(bn->d[width - 1]);
  ------------------
  |  |  151|   896k|#define BN_BITS2 64
  ------------------
  230|   896k|}
BN_num_bytes:
  232|  4.02k|unsigned BN_num_bytes(const BIGNUM *bn) {
  233|  4.02k|  return (BN_num_bits(bn) + 7) / 8;
  234|  4.02k|}
BN_zero:
  236|  5.68M|void BN_zero(BIGNUM *bn) {
  237|  5.68M|  bn->width = bn->neg = 0;
  238|  5.68M|}
BN_set_word:
  244|  4.89k|int BN_set_word(BIGNUM *bn, BN_ULONG value) {
  245|  4.89k|  if (value == 0) {
  ------------------
  |  Branch (245:7): [True: 0, False: 4.89k]
  ------------------
  246|      0|    BN_zero(bn);
  247|      0|    return 1;
  248|      0|  }
  249|       |
  250|  4.89k|  if (!bn_wexpand(bn, 1)) {
  ------------------
  |  Branch (250:7): [True: 0, False: 4.89k]
  ------------------
  251|      0|    return 0;
  252|      0|  }
  253|       |
  254|  4.89k|  bn->neg = 0;
  255|  4.89k|  bn->d[0] = value;
  256|  4.89k|  bn->width = 1;
  257|  4.89k|  return 1;
  258|  4.89k|}
bn_fits_in_words:
  306|  2.56M|int bn_fits_in_words(const BIGNUM *bn, size_t num) {
  307|       |  // All words beyond |num| must be zero.
  308|  2.56M|  BN_ULONG mask = 0;
  309|  10.7M|  for (size_t i = num; i < (size_t)bn->width; i++) {
  ------------------
  |  Branch (309:24): [True: 8.15M, False: 2.56M]
  ------------------
  310|  8.15M|    mask |= bn->d[i];
  311|  8.15M|  }
  312|  2.56M|  return mask == 0;
  313|  2.56M|}
bn_copy_words:
  315|      4|int bn_copy_words(BN_ULONG *out, size_t num, const BIGNUM *bn) {
  316|      4|  if (bn->neg) {
  ------------------
  |  Branch (316:7): [True: 0, False: 4]
  ------------------
  317|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  318|      0|    return 0;
  319|      0|  }
  320|       |
  321|      4|  size_t width = (size_t)bn->width;
  322|      4|  if (width > num) {
  ------------------
  |  Branch (322:7): [True: 0, False: 4]
  ------------------
  323|      0|    if (!bn_fits_in_words(bn, num)) {
  ------------------
  |  Branch (323:9): [True: 0, False: 0]
  ------------------
  324|      0|      OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  325|      0|      return 0;
  326|      0|    }
  327|      0|    width = num;
  328|      0|  }
  329|       |
  330|      4|  OPENSSL_memset(out, 0, sizeof(BN_ULONG) * num);
  331|      4|  OPENSSL_memcpy(out, bn->d, sizeof(BN_ULONG) * width);
  332|      4|  return 1;
  333|      4|}
BN_is_negative:
  335|  11.6k|int BN_is_negative(const BIGNUM *bn) {
  336|  11.6k|  return bn->neg != 0;
  337|  11.6k|}
BN_set_negative:
  339|      4|void BN_set_negative(BIGNUM *bn, int sign) {
  340|      4|  if (sign && !BN_is_zero(bn)) {
  ------------------
  |  Branch (340:7): [True: 0, False: 4]
  |  Branch (340:15): [True: 0, False: 0]
  ------------------
  341|      0|    bn->neg = 1;
  342|      4|  } else {
  343|      4|    bn->neg = 0;
  344|      4|  }
  345|      4|}
bn_wexpand:
  347|  7.30M|int bn_wexpand(BIGNUM *bn, size_t words) {
  348|  7.30M|  BN_ULONG *a;
  349|       |
  350|  7.30M|  if (words <= (size_t)bn->dmax) {
  ------------------
  |  Branch (350:7): [True: 7.27M, False: 32.0k]
  ------------------
  351|  7.27M|    return 1;
  352|  7.27M|  }
  353|       |
  354|  32.0k|  if (words > BN_MAX_WORDS) {
  ------------------
  |  |   73|  32.0k|#define BN_MAX_WORDS (INT_MAX / (4 * BN_BITS2))
  |  |  ------------------
  |  |  |  |  151|  32.0k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (354:7): [True: 0, False: 32.0k]
  ------------------
  355|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  356|      0|    return 0;
  357|      0|  }
  358|       |
  359|  32.0k|  if (bn->flags & BN_FLG_STATIC_DATA) {
  ------------------
  |  | 1027|  32.0k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (359:7): [True: 0, False: 32.0k]
  ------------------
  360|      0|    OPENSSL_PUT_ERROR(BN, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  361|      0|    return 0;
  362|      0|  }
  363|       |
  364|  32.0k|  a = OPENSSL_malloc(sizeof(BN_ULONG) * words);
  365|  32.0k|  if (a == NULL) {
  ------------------
  |  Branch (365:7): [True: 0, False: 32.0k]
  ------------------
  366|      0|    return 0;
  367|      0|  }
  368|       |
  369|  32.0k|  OPENSSL_memcpy(a, bn->d, sizeof(BN_ULONG) * bn->width);
  370|       |
  371|  32.0k|  OPENSSL_free(bn->d);
  372|  32.0k|  bn->d = a;
  373|  32.0k|  bn->dmax = (int)words;
  374|       |
  375|  32.0k|  return 1;
  376|  32.0k|}
bn_resize_words:
  386|  2.90k|int bn_resize_words(BIGNUM *bn, size_t words) {
  387|  2.90k|  if ((size_t)bn->width <= words) {
  ------------------
  |  Branch (387:7): [True: 2.90k, False: 0]
  ------------------
  388|  2.90k|    if (!bn_wexpand(bn, words)) {
  ------------------
  |  Branch (388:9): [True: 0, False: 2.90k]
  ------------------
  389|      0|      return 0;
  390|      0|    }
  391|  2.90k|    OPENSSL_memset(bn->d + bn->width, 0,
  392|  2.90k|                   (words - bn->width) * sizeof(BN_ULONG));
  393|  2.90k|    bn->width = (int)words;
  394|  2.90k|    return 1;
  395|  2.90k|  }
  396|       |
  397|       |  // All words beyond the new width must be zero.
  398|      0|  if (!bn_fits_in_words(bn, words)) {
  ------------------
  |  Branch (398:7): [True: 0, False: 0]
  ------------------
  399|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  400|      0|    return 0;
  401|      0|  }
  402|      0|  bn->width = (int)words;
  403|      0|  return 1;
  404|      0|}
bn_select_words:
  407|   385k|                     const BN_ULONG *b, size_t num) {
  408|  2.32M|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (408:22): [True: 1.93M, False: 385k]
  ------------------
  409|  1.93M|    static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  410|  1.93M|                  "crypto_word_t is too small");
  411|  1.93M|    r[i] = constant_time_select_w(mask, a[i], b[i]);
  412|  1.93M|  }
  413|   385k|}
bn_minimal_width:
  415|  9.79M|int bn_minimal_width(const BIGNUM *bn) {
  416|  9.79M|  int ret = bn->width;
  417|  17.8M|  while (ret > 0 && bn->d[ret - 1] == 0) {
  ------------------
  |  Branch (417:10): [True: 17.8M, False: 10.6k]
  |  Branch (417:21): [True: 8.04M, False: 9.78M]
  ------------------
  418|  8.04M|    ret--;
  419|  8.04M|  }
  420|  9.79M|  return ret;
  421|  9.79M|}
bn_set_minimal_width:
  423|  7.11M|void bn_set_minimal_width(BIGNUM *bn) {
  424|  7.11M|  bn->width = bn_minimal_width(bn);
  425|  7.11M|  if (bn->width == 0) {
  ------------------
  |  Branch (425:7): [True: 10.6k, False: 7.10M]
  ------------------
  426|  10.6k|    bn->neg = 0;
  427|  10.6k|  }
  428|  7.11M|}
bcm.c:BN_value_one_do_init:
  159|      1|DEFINE_METHOD_FUNCTION(BIGNUM, BN_value_one) {
  160|      1|  static const BN_ULONG kOneLimbs[1] = { 1 };
  161|      1|  out->d = (BN_ULONG*) kOneLimbs;
  162|      1|  out->width = 1;
  163|      1|  out->dmax = 1;
  164|      1|  out->neg = 0;
  165|      1|  out->flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|      1|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  166|      1|}

bn_big_endian_to_words:
   65|  5.20k|                            size_t in_len) {
   66|  1.89M|  for (size_t i = 0; i < out_len; i++) {
  ------------------
  |  Branch (66:22): [True: 1.89M, False: 844]
  ------------------
   67|  1.89M|    if (in_len < sizeof(BN_ULONG)) {
  ------------------
  |  Branch (67:9): [True: 4.35k, False: 1.89M]
  ------------------
   68|       |      // Load the last partial word.
   69|  4.35k|      BN_ULONG word = 0;
   70|  17.6k|      for (size_t j = 0; j < in_len; j++) {
  ------------------
  |  Branch (70:26): [True: 13.3k, False: 4.35k]
  ------------------
   71|  13.3k|        word = (word << 8) | in[j];
   72|  13.3k|      }
   73|  4.35k|      in_len = 0;
   74|  4.35k|      out[i] = word;
   75|       |      // Fill the remainder with zeros.
   76|  4.35k|      OPENSSL_memset(out + i + 1, 0, (out_len - i - 1) * sizeof(BN_ULONG));
   77|  4.35k|      break;
   78|  4.35k|    }
   79|       |
   80|  1.89M|    in_len -= sizeof(BN_ULONG);
   81|  1.89M|    out[i] = CRYPTO_load_word_be(in + in_len);
   82|  1.89M|  }
   83|       |
   84|       |  // The caller should have sized the output to avoid truncation.
   85|  5.20k|  assert(in_len == 0);
   86|  5.20k|}
BN_bin2bn:
   88|  4.22k|BIGNUM *BN_bin2bn(const uint8_t *in, size_t len, BIGNUM *ret) {
   89|  4.22k|  BIGNUM *bn = NULL;
   90|  4.22k|  if (ret == NULL) {
  ------------------
  |  Branch (90:7): [True: 16, False: 4.20k]
  ------------------
   91|     16|    bn = BN_new();
   92|     16|    if (bn == NULL) {
  ------------------
  |  Branch (92:9): [True: 0, False: 16]
  ------------------
   93|      0|      return NULL;
   94|      0|    }
   95|     16|    ret = bn;
   96|     16|  }
   97|       |
   98|  4.22k|  if (len == 0) {
  ------------------
  |  Branch (98:7): [True: 0, False: 4.22k]
  ------------------
   99|      0|    ret->width = 0;
  100|      0|    return ret;
  101|      0|  }
  102|       |
  103|  4.22k|  size_t num_words = ((len - 1) / BN_BYTES) + 1;
  ------------------
  |  |  152|  4.22k|#define BN_BYTES 8
  ------------------
  104|  4.22k|  if (!bn_wexpand(ret, num_words)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 4.22k]
  ------------------
  105|      0|    BN_free(bn);
  106|      0|    return NULL;
  107|      0|  }
  108|       |
  109|       |  // |bn_wexpand| must check bounds on |num_words| to write it into
  110|       |  // |ret->dmax|.
  111|  4.22k|  assert(num_words <= INT_MAX);
  112|  4.22k|  ret->width = (int)num_words;
  113|  4.22k|  ret->neg = 0;
  114|       |
  115|  4.22k|  bn_big_endian_to_words(ret->d, ret->width, in, len);
  116|  4.22k|  return ret;
  117|  4.22k|}
bn_words_to_big_endian:
  178|  2.31k|                            size_t in_len) {
  179|       |  // The caller should have selected an output length without truncation.
  180|  2.31k|  assert(fits_in_bytes(in, in_len, out_len));
  181|       |
  182|       |  // We only support little-endian platforms, so the internal representation is
  183|       |  // also little-endian as bytes. We can simply copy it in reverse.
  184|  2.31k|  const uint8_t *bytes = (const uint8_t *)in;
  185|  2.31k|  size_t num_bytes = in_len * sizeof(BN_ULONG);
  186|  2.31k|  if (out_len < num_bytes) {
  ------------------
  |  Branch (186:7): [True: 2.02k, False: 293]
  ------------------
  187|  2.02k|    num_bytes = out_len;
  188|  2.02k|  }
  189|       |
  190|  85.8k|  for (size_t i = 0; i < num_bytes; i++) {
  ------------------
  |  Branch (190:22): [True: 83.5k, False: 2.31k]
  ------------------
  191|  83.5k|    out[out_len - i - 1] = bytes[i];
  192|  83.5k|  }
  193|       |  // Pad out the rest of the buffer with zeroes.
  194|  2.31k|  OPENSSL_memset(out, 0, out_len - num_bytes);
  195|  2.31k|}
BN_bn2bin_padded:
  222|    960|int BN_bn2bin_padded(uint8_t *out, size_t len, const BIGNUM *in) {
  223|    960|  if (!fits_in_bytes(in->d, in->width, len)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 960]
  ------------------
  224|      0|    return 0;
  225|      0|  }
  226|       |
  227|    960|  bn_words_to_big_endian(out, len, in->d, in->width);
  228|    960|  return 1;
  229|    960|}
bcm.c:fits_in_bytes:
  155|  3.27k|                         size_t num_bytes) {
  156|  3.27k|  const uint8_t *bytes = (const uint8_t *)words;
  157|  3.27k|  size_t tot_bytes = num_words * sizeof(BN_ULONG);
  158|  3.27k|  uint8_t mask = 0;
  159|  15.6k|  for (size_t i = num_bytes; i < tot_bytes; i++) {
  ------------------
  |  Branch (159:30): [True: 12.4k, False: 3.27k]
  ------------------
  160|  12.4k|    mask |= bytes[i];
  161|  12.4k|  }
  162|  3.27k|  return mask == 0;
  163|  3.27k|}

BN_ucmp:
   99|  4.75k|int BN_ucmp(const BIGNUM *a, const BIGNUM *b) {
  100|  4.75k|  return bn_cmp_words_consttime(a->d, a->width, b->d, b->width);
  101|  4.75k|}
BN_cmp:
  103|  2.87k|int BN_cmp(const BIGNUM *a, const BIGNUM *b) {
  104|  2.87k|  if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 2.87k]
  |  Branch (104:22): [True: 0, False: 2.87k]
  ------------------
  105|      0|    if (a != NULL) {
  ------------------
  |  Branch (105:9): [True: 0, False: 0]
  ------------------
  106|      0|      return -1;
  107|      0|    } else if (b != NULL) {
  ------------------
  |  Branch (107:16): [True: 0, False: 0]
  ------------------
  108|      0|      return 1;
  109|      0|    } else {
  110|      0|      return 0;
  111|      0|    }
  112|      0|  }
  113|       |
  114|       |  // We do not attempt to process the sign bit in constant time. Negative
  115|       |  // |BIGNUM|s should never occur in crypto, only calculators.
  116|  2.87k|  if (a->neg != b->neg) {
  ------------------
  |  Branch (116:7): [True: 0, False: 2.87k]
  ------------------
  117|      0|    if (a->neg) {
  ------------------
  |  Branch (117:9): [True: 0, False: 0]
  ------------------
  118|      0|      return -1;
  119|      0|    }
  120|      0|    return 1;
  121|      0|  }
  122|       |
  123|  2.87k|  int ret = BN_ucmp(a, b);
  124|  2.87k|  return a->neg ? -ret : ret;
  ------------------
  |  Branch (124:10): [True: 0, False: 2.87k]
  ------------------
  125|  2.87k|}
bn_less_than_words:
  127|    976|int bn_less_than_words(const BN_ULONG *a, const BN_ULONG *b, size_t len) {
  128|    976|  return bn_cmp_words_consttime(a, len, b, len) < 0;
  129|    976|}
BN_abs_is_word:
  131|   835k|int BN_abs_is_word(const BIGNUM *bn, BN_ULONG w) {
  132|   835k|  if (bn->width == 0) {
  ------------------
  |  Branch (132:7): [True: 0, False: 835k]
  ------------------
  133|      0|    return w == 0;
  134|      0|  }
  135|   835k|  BN_ULONG mask = bn->d[0] ^ w;
  136|  3.27M|  for (int i = 1; i < bn->width; i++) {
  ------------------
  |  Branch (136:19): [True: 2.44M, False: 835k]
  ------------------
  137|  2.44M|    mask |= bn->d[i];
  138|  2.44M|  }
  139|   835k|  return mask == 0;
  140|   835k|}
BN_is_zero:
  153|  1.79M|int BN_is_zero(const BIGNUM *bn) {
  154|  1.79M|  return bn_fits_in_words(bn, 0);
  155|  1.79M|}
BN_is_one:
  157|   834k|int BN_is_one(const BIGNUM *bn) {
  158|   834k|  return bn->neg == 0 && BN_abs_is_word(bn, 1);
  ------------------
  |  Branch (158:10): [True: 834k, False: 0]
  |  Branch (158:26): [True: 21.8k, False: 812k]
  ------------------
  159|   834k|}
BN_is_odd:
  165|  12.4k|int BN_is_odd(const BIGNUM *bn) {
  166|  12.4k|  return bn->width > 0 && (bn->d[0] & 1) == 1;
  ------------------
  |  Branch (166:10): [True: 12.4k, False: 0]
  |  Branch (166:27): [True: 11.5k, False: 846]
  ------------------
  167|  12.4k|}
bcm.c:bn_cmp_words_consttime:
   68|  5.73k|                                  const BN_ULONG *b, size_t b_len) {
   69|  5.73k|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
   70|  5.73k|                "crypto_word_t is too small");
   71|  5.73k|  int ret = 0;
   72|       |  // Process the common words in little-endian order.
   73|  5.73k|  size_t min = a_len < b_len ? a_len : b_len;
  ------------------
  |  Branch (73:16): [True: 966, False: 4.76k]
  ------------------
   74|   309k|  for (size_t i = 0; i < min; i++) {
  ------------------
  |  Branch (74:22): [True: 303k, False: 5.73k]
  ------------------
   75|   303k|    crypto_word_t eq = constant_time_eq_w(a[i], b[i]);
   76|   303k|    crypto_word_t lt = constant_time_lt_w(a[i], b[i]);
   77|   303k|    ret =
   78|   303k|        constant_time_select_int(eq, ret, constant_time_select_int(lt, -1, 1));
   79|   303k|  }
   80|       |
   81|       |  // If |a| or |b| has non-zero words beyond |min|, they take precedence.
   82|  5.73k|  if (a_len < b_len) {
  ------------------
  |  Branch (82:7): [True: 966, False: 4.76k]
  ------------------
   83|    966|    crypto_word_t mask = 0;
   84|   747k|    for (size_t i = a_len; i < b_len; i++) {
  ------------------
  |  Branch (84:28): [True: 746k, False: 966]
  ------------------
   85|   746k|      mask |= b[i];
   86|   746k|    }
   87|    966|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, -1);
   88|  4.76k|  } else if (b_len < a_len) {
  ------------------
  |  Branch (88:14): [True: 71, False: 4.69k]
  ------------------
   89|     71|    crypto_word_t mask = 0;
   90|   164k|    for (size_t i = b_len; i < a_len; i++) {
  ------------------
  |  Branch (90:28): [True: 164k, False: 71]
  ------------------
   91|   164k|      mask |= a[i];
   92|   164k|    }
   93|     71|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, 1);
   94|     71|  }
   95|       |
   96|  5.73k|  return ret;
   97|  5.73k|}

BN_CTX_new:
  108|    687|BN_CTX *BN_CTX_new(void) {
  109|    687|  BN_CTX *ret = OPENSSL_malloc(sizeof(BN_CTX));
  110|    687|  if (!ret) {
  ------------------
  |  Branch (110:7): [True: 0, False: 687]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|       |  // Initialise the structure
  115|    687|  ret->bignums = NULL;
  116|    687|  BN_STACK_init(&ret->stack);
  117|    687|  ret->used = 0;
  118|    687|  ret->error = 0;
  119|    687|  ret->defer_error = 0;
  120|    687|  return ret;
  121|    687|}
BN_CTX_free:
  123|  1.36k|void BN_CTX_free(BN_CTX *ctx) {
  124|  1.36k|  if (ctx == NULL) {
  ------------------
  |  Branch (124:7): [True: 680, False: 687]
  ------------------
  125|    680|    return;
  126|    680|  }
  127|       |
  128|       |  // All |BN_CTX_start| calls must be matched with |BN_CTX_end|, otherwise the
  129|       |  // function may use more memory than expected, potentially without bound if
  130|       |  // done in a loop. Assert that all |BIGNUM|s have been released.
  131|    687|  assert(ctx->used == 0 || ctx->error);
  132|    687|  sk_BIGNUM_pop_free(ctx->bignums, BN_free);
  133|    687|  BN_STACK_cleanup(&ctx->stack);
  134|    687|  OPENSSL_free(ctx);
  135|    687|}
BN_CTX_start:
  137|  3.00M|void BN_CTX_start(BN_CTX *ctx) {
  138|  3.00M|  if (ctx->error) {
  ------------------
  |  Branch (138:7): [True: 0, False: 3.00M]
  ------------------
  139|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  140|       |    // of |BN_CTX_end| calls to come. Do nothing.
  141|      0|    return;
  142|      0|  }
  143|       |
  144|  3.00M|  if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (144:7): [True: 0, False: 3.00M]
  ------------------
  145|      0|    ctx->error = 1;
  146|       |    // |BN_CTX_start| cannot fail, so defer the error to |BN_CTX_get|.
  147|      0|    ctx->defer_error = 1;
  148|      0|  }
  149|  3.00M|}
BN_CTX_get:
  151|  5.68M|BIGNUM *BN_CTX_get(BN_CTX *ctx) {
  152|       |  // Once any operation has failed, they all do.
  153|  5.68M|  if (ctx->error) {
  ------------------
  |  Branch (153:7): [True: 0, False: 5.68M]
  ------------------
  154|      0|    if (ctx->defer_error) {
  ------------------
  |  Branch (154:9): [True: 0, False: 0]
  ------------------
  155|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      0|      ctx->defer_error = 0;
  157|      0|    }
  158|      0|    return NULL;
  159|      0|  }
  160|       |
  161|  5.68M|  if (ctx->bignums == NULL) {
  ------------------
  |  Branch (161:7): [True: 687, False: 5.68M]
  ------------------
  162|    687|    ctx->bignums = sk_BIGNUM_new_null();
  163|    687|    if (ctx->bignums == NULL) {
  ------------------
  |  Branch (163:9): [True: 0, False: 687]
  ------------------
  164|      0|      ctx->error = 1;
  165|      0|      return NULL;
  166|      0|    }
  167|    687|  }
  168|       |
  169|  5.68M|  if (ctx->used == sk_BIGNUM_num(ctx->bignums)) {
  ------------------
  |  Branch (169:7): [True: 17.1k, False: 5.66M]
  ------------------
  170|  17.1k|    BIGNUM *bn = BN_new();
  171|  17.1k|    if (bn == NULL || !sk_BIGNUM_push(ctx->bignums, bn)) {
  ------------------
  |  Branch (171:9): [True: 0, False: 17.1k]
  |  Branch (171:23): [True: 0, False: 17.1k]
  ------------------
  172|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|      BN_free(bn);
  174|      0|      ctx->error = 1;
  175|      0|      return NULL;
  176|      0|    }
  177|  17.1k|  }
  178|       |
  179|  5.68M|  BIGNUM *ret = sk_BIGNUM_value(ctx->bignums, ctx->used);
  180|  5.68M|  BN_zero(ret);
  181|       |  // This is bounded by |sk_BIGNUM_num|, so it cannot overflow.
  182|  5.68M|  ctx->used++;
  183|  5.68M|  return ret;
  184|  5.68M|}
BN_CTX_end:
  186|  3.00M|void BN_CTX_end(BN_CTX *ctx) {
  187|  3.00M|  if (ctx->error) {
  ------------------
  |  Branch (187:7): [True: 0, False: 3.00M]
  ------------------
  188|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  189|       |    // of |BN_CTX_end| calls to come. Do nothing.
  190|      0|    return;
  191|      0|  }
  192|       |
  193|  3.00M|  ctx->used = BN_STACK_pop(&ctx->stack);
  194|  3.00M|}
bcm.c:BN_STACK_init:
  199|    687|static void BN_STACK_init(BN_STACK *st) {
  200|    687|  st->indexes = NULL;
  201|    687|  st->depth = st->size = 0;
  202|    687|}
bcm.c:BN_STACK_cleanup:
  204|    687|static void BN_STACK_cleanup(BN_STACK *st) {
  205|    687|  OPENSSL_free(st->indexes);
  206|    687|}
bcm.c:BN_STACK_push:
  208|  3.00M|static int BN_STACK_push(BN_STACK *st, size_t idx) {
  209|  3.00M|  if (st->depth == st->size) {
  ------------------
  |  Branch (209:7): [True: 687, False: 3.00M]
  ------------------
  210|       |    // This function intentionally does not push to the error queue on error.
  211|       |    // Error-reporting is deferred to |BN_CTX_get|.
  212|    687|    size_t new_size = st->size != 0 ? st->size * 3 / 2 : BN_CTX_START_FRAMES;
  ------------------
  |  |   67|    687|#define BN_CTX_START_FRAMES 32
  ------------------
  |  Branch (212:23): [True: 0, False: 687]
  ------------------
  213|    687|    if (new_size <= st->size || new_size > ((size_t)-1) / sizeof(size_t)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 687]
  |  Branch (213:33): [True: 0, False: 687]
  ------------------
  214|      0|      return 0;
  215|      0|    }
  216|    687|    size_t *new_indexes =
  217|    687|        OPENSSL_realloc(st->indexes, new_size * sizeof(size_t));
  218|    687|    if (new_indexes == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 687]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|    687|    st->indexes = new_indexes;
  222|    687|    st->size = new_size;
  223|    687|  }
  224|       |
  225|  3.00M|  st->indexes[st->depth] = idx;
  226|  3.00M|  st->depth++;
  227|  3.00M|  return 1;
  228|  3.00M|}
bcm.c:BN_STACK_pop:
  230|  3.00M|static size_t BN_STACK_pop(BN_STACK *st) {
  231|  3.00M|  assert(st->depth > 0);
  232|  3.00M|  st->depth--;
  233|  3.00M|  return st->indexes[st->depth];
  234|  3.00M|}

BN_div:
  195|   889k|           const BIGNUM *divisor, BN_CTX *ctx) {
  196|   889k|  int norm_shift, loop;
  197|   889k|  BIGNUM wnum;
  198|   889k|  BN_ULONG *resp, *wnump;
  199|   889k|  BN_ULONG d0, d1;
  200|   889k|  int num_n, div_n;
  201|       |
  202|       |  // This function relies on the historical minimal-width |BIGNUM| invariant.
  203|       |  // It is already not constant-time (constant-time reductions should use
  204|       |  // Montgomery logic), so we shrink all inputs and intermediate values to
  205|       |  // retain the previous behavior.
  206|       |
  207|       |  // Invalid zero-padding would have particularly bad consequences.
  208|   889k|  int numerator_width = bn_minimal_width(numerator);
  209|   889k|  int divisor_width = bn_minimal_width(divisor);
  210|   889k|  if ((numerator_width > 0 && numerator->d[numerator_width - 1] == 0) ||
  ------------------
  |  Branch (210:8): [True: 889k, False: 6]
  |  Branch (210:31): [True: 0, False: 889k]
  ------------------
  211|   889k|      (divisor_width > 0 && divisor->d[divisor_width - 1] == 0)) {
  ------------------
  |  Branch (211:8): [True: 889k, False: 0]
  |  Branch (211:29): [True: 0, False: 889k]
  ------------------
  212|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NOT_INITIALIZED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|      0|    return 0;
  214|      0|  }
  215|       |
  216|   889k|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (216:7): [True: 0, False: 889k]
  ------------------
  217|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  218|      0|    return 0;
  219|      0|  }
  220|       |
  221|   889k|  BN_CTX_start(ctx);
  222|   889k|  BIGNUM *tmp = BN_CTX_get(ctx);
  223|   889k|  BIGNUM *snum = BN_CTX_get(ctx);
  224|   889k|  BIGNUM *sdiv = BN_CTX_get(ctx);
  225|   889k|  BIGNUM *res = NULL;
  226|   889k|  if (quotient == NULL) {
  ------------------
  |  Branch (226:7): [True: 889k, False: 0]
  ------------------
  227|   889k|    res = BN_CTX_get(ctx);
  228|   889k|  } else {
  229|      0|    res = quotient;
  230|      0|  }
  231|   889k|  if (sdiv == NULL || res == NULL) {
  ------------------
  |  Branch (231:7): [True: 0, False: 889k]
  |  Branch (231:23): [True: 0, False: 889k]
  ------------------
  232|      0|    goto err;
  233|      0|  }
  234|       |
  235|       |  // First we normalise the numbers
  236|   889k|  norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|   889k|#define BN_BITS2 64
  ------------------
                norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|   889k|#define BN_BITS2 64
  ------------------
  237|   889k|  if (!BN_lshift(sdiv, divisor, norm_shift)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 889k]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|   889k|  bn_set_minimal_width(sdiv);
  241|   889k|  sdiv->neg = 0;
  242|   889k|  norm_shift += BN_BITS2;
  ------------------
  |  |  151|   889k|#define BN_BITS2 64
  ------------------
  243|   889k|  if (!BN_lshift(snum, numerator, norm_shift)) {
  ------------------
  |  Branch (243:7): [True: 0, False: 889k]
  ------------------
  244|      0|    goto err;
  245|      0|  }
  246|   889k|  bn_set_minimal_width(snum);
  247|   889k|  snum->neg = 0;
  248|       |
  249|       |  // Since we don't want to have special-case logic for the case where snum is
  250|       |  // larger than sdiv, we pad snum with enough zeroes without changing its
  251|       |  // value.
  252|   889k|  if (snum->width <= sdiv->width + 1) {
  ------------------
  |  Branch (252:7): [True: 849, False: 888k]
  ------------------
  253|    849|    if (!bn_wexpand(snum, sdiv->width + 2)) {
  ------------------
  |  Branch (253:9): [True: 0, False: 849]
  ------------------
  254|      0|      goto err;
  255|      0|    }
  256|  1.89k|    for (int i = snum->width; i < sdiv->width + 2; i++) {
  ------------------
  |  Branch (256:31): [True: 1.04k, False: 849]
  ------------------
  257|  1.04k|      snum->d[i] = 0;
  258|  1.04k|    }
  259|    849|    snum->width = sdiv->width + 2;
  260|   888k|  } else {
  261|   888k|    if (!bn_wexpand(snum, snum->width + 1)) {
  ------------------
  |  Branch (261:9): [True: 0, False: 888k]
  ------------------
  262|      0|      goto err;
  263|      0|    }
  264|   888k|    snum->d[snum->width] = 0;
  265|   888k|    snum->width++;
  266|   888k|  }
  267|       |
  268|   889k|  div_n = sdiv->width;
  269|   889k|  num_n = snum->width;
  270|   889k|  loop = num_n - div_n;
  271|       |  // Lets setup a 'window' into snum
  272|       |  // This is the part that corresponds to the current
  273|       |  // 'area' being divided
  274|   889k|  wnum.neg = 0;
  275|   889k|  wnum.d = &(snum->d[loop]);
  276|   889k|  wnum.width = div_n;
  277|       |  // only needed when BN_ucmp messes up the values between width and max
  278|   889k|  wnum.dmax = snum->dmax - loop;  // so we don't step out of bounds
  279|       |
  280|       |  // Get the top 2 words of sdiv
  281|       |  // div_n=sdiv->width;
  282|   889k|  d0 = sdiv->d[div_n - 1];
  283|   889k|  d1 = (div_n == 1) ? 0 : sdiv->d[div_n - 2];
  ------------------
  |  Branch (283:8): [True: 8.31k, False: 881k]
  ------------------
  284|       |
  285|       |  // pointer to the 'top' of snum
  286|   889k|  wnump = &(snum->d[num_n - 1]);
  287|       |
  288|       |  // Setup |res|. |numerator| and |res| may alias, so we save |numerator->neg|
  289|       |  // for later.
  290|   889k|  const int numerator_neg = numerator->neg;
  291|   889k|  res->neg = (numerator_neg ^ divisor->neg);
  292|   889k|  if (!bn_wexpand(res, loop + 1)) {
  ------------------
  |  Branch (292:7): [True: 0, False: 889k]
  ------------------
  293|      0|    goto err;
  294|      0|  }
  295|   889k|  res->width = loop - 1;
  296|   889k|  resp = &(res->d[loop - 1]);
  297|       |
  298|       |  // space for temp
  299|   889k|  if (!bn_wexpand(tmp, div_n + 1)) {
  ------------------
  |  Branch (299:7): [True: 0, False: 889k]
  ------------------
  300|      0|    goto err;
  301|      0|  }
  302|       |
  303|       |  // if res->width == 0 then clear the neg value otherwise decrease
  304|       |  // the resp pointer
  305|   889k|  if (res->width == 0) {
  ------------------
  |  Branch (305:7): [True: 0, False: 889k]
  ------------------
  306|      0|    res->neg = 0;
  307|   889k|  } else {
  308|   889k|    resp--;
  309|   889k|  }
  310|       |
  311|  5.32M|  for (int i = 0; i < loop - 1; i++, wnump--, resp--) {
  ------------------
  |  Branch (311:19): [True: 4.43M, False: 889k]
  ------------------
  312|  4.43M|    BN_ULONG q, l0;
  313|       |    // the first part of the loop uses the top two words of snum and sdiv to
  314|       |    // calculate a BN_ULONG q such that | wnum - sdiv * q | < sdiv
  315|  4.43M|    BN_ULONG n0, n1, rm = 0;
  316|       |
  317|  4.43M|    n0 = wnump[0];
  318|  4.43M|    n1 = wnump[-1];
  319|  4.43M|    if (n0 == d0) {
  ------------------
  |  Branch (319:9): [True: 16.8k, False: 4.41M]
  ------------------
  320|  16.8k|      q = BN_MASK2;
  ------------------
  |  |  154|  16.8k|#define BN_MASK2 (0xffffffffffffffffUL)
  ------------------
  321|  4.41M|    } else {
  322|       |      // n0 < d0
  323|  4.41M|      bn_div_rem_words(&q, &rm, n0, n1, d0);
  324|       |
  325|  4.41M|#ifdef BN_ULLONG
  326|  4.41M|      BN_ULLONG t2 = (BN_ULLONG)d1 * q;
  ------------------
  |  |  145|  4.41M|#define BN_ULLONG uint128_t
  ------------------
  327|  4.41M|      for (;;) {
  328|  4.41M|        if (t2 <= ((((BN_ULLONG)rm) << BN_BITS2) | wnump[-2])) {
  ------------------
  |  |  151|  4.41M|#define BN_BITS2 64
  ------------------
  |  Branch (328:13): [True: 3.07M, False: 1.34M]
  ------------------
  329|  3.07M|          break;
  330|  3.07M|        }
  331|  1.34M|        q--;
  332|  1.34M|        rm += d0;
  333|  1.34M|        if (rm < d0) {
  ------------------
  |  Branch (333:13): [True: 1.34M, False: 13]
  ------------------
  334|  1.34M|          break;  // don't let rm overflow
  335|  1.34M|        }
  336|     13|        t2 -= d1;
  337|     13|      }
  338|       |#else  // !BN_ULLONG
  339|       |      BN_ULONG t2l, t2h;
  340|       |      BN_UMULT_LOHI(t2l, t2h, d1, q);
  341|       |      for (;;) {
  342|       |        if (t2h < rm ||
  343|       |            (t2h == rm && t2l <= wnump[-2])) {
  344|       |          break;
  345|       |        }
  346|       |        q--;
  347|       |        rm += d0;
  348|       |        if (rm < d0) {
  349|       |          break;  // don't let rm overflow
  350|       |        }
  351|       |        if (t2l < d1) {
  352|       |          t2h--;
  353|       |        }
  354|       |        t2l -= d1;
  355|       |      }
  356|       |#endif  // !BN_ULLONG
  357|  4.41M|    }
  358|       |
  359|  4.43M|    l0 = bn_mul_words(tmp->d, sdiv->d, div_n, q);
  360|  4.43M|    tmp->d[div_n] = l0;
  361|  4.43M|    wnum.d--;
  362|       |    // ingore top values of the bignums just sub the two
  363|       |    // BN_ULONG arrays with bn_sub_words
  364|  4.43M|    if (bn_sub_words(wnum.d, wnum.d, tmp->d, div_n + 1)) {
  ------------------
  |  Branch (364:9): [True: 16.9k, False: 4.41M]
  ------------------
  365|       |      // Note: As we have considered only the leading
  366|       |      // two BN_ULONGs in the calculation of q, sdiv * q
  367|       |      // might be greater than wnum (but then (q-1) * sdiv
  368|       |      // is less or equal than wnum)
  369|  16.9k|      q--;
  370|  16.9k|      if (bn_add_words(wnum.d, wnum.d, sdiv->d, div_n)) {
  ------------------
  |  Branch (370:11): [True: 16.9k, False: 0]
  ------------------
  371|       |        // we can't have an overflow here (assuming
  372|       |        // that q != 0, but if q == 0 then tmp is
  373|       |        // zero anyway)
  374|  16.9k|        (*wnump)++;
  375|  16.9k|      }
  376|  16.9k|    }
  377|       |    // store part of the result
  378|  4.43M|    *resp = q;
  379|  4.43M|  }
  380|       |
  381|   889k|  bn_set_minimal_width(snum);
  382|       |
  383|   889k|  if (rem != NULL) {
  ------------------
  |  Branch (383:7): [True: 889k, False: 0]
  ------------------
  384|   889k|    if (!BN_rshift(rem, snum, norm_shift)) {
  ------------------
  |  Branch (384:9): [True: 0, False: 889k]
  ------------------
  385|      0|      goto err;
  386|      0|    }
  387|   889k|    if (!BN_is_zero(rem)) {
  ------------------
  |  Branch (387:9): [True: 884k, False: 4.89k]
  ------------------
  388|   884k|      rem->neg = numerator_neg;
  389|   884k|    }
  390|   889k|  }
  391|       |
  392|   889k|  bn_set_minimal_width(res);
  393|   889k|  BN_CTX_end(ctx);
  394|   889k|  return 1;
  395|       |
  396|      0|err:
  397|      0|  BN_CTX_end(ctx);
  398|      0|  return 0;
  399|   889k|}
BN_nnmod:
  401|   854k|int BN_nnmod(BIGNUM *r, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx) {
  402|   854k|  if (!(BN_mod(r, m, d, ctx))) {
  ------------------
  |  |  547|   854k|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  ------------------
  |  Branch (402:7): [True: 0, False: 854k]
  ------------------
  403|      0|    return 0;
  404|      0|  }
  405|   854k|  if (!r->neg) {
  ------------------
  |  Branch (405:7): [True: 854k, False: 0]
  ------------------
  406|   854k|    return 1;
  407|   854k|  }
  408|       |
  409|       |  // now -|d| < r < 0, so we have to set r := r + |d|.
  410|      0|  return (d->neg ? BN_sub : BN_add)(r, r, d);
  ------------------
  |  Branch (410:11): [True: 0, False: 0]
  ------------------
  411|   854k|}
bn_reduce_once:
  414|  2.03k|                        const BN_ULONG *m, size_t num) {
  415|  2.03k|  assert(r != a);
  416|       |  // |r| = |a| - |m|. |bn_sub_words| performs the bulk of the subtraction, and
  417|       |  // then we apply the borrow to |carry|.
  418|  2.03k|  carry -= bn_sub_words(r, a, m, num);
  419|       |  // We know 0 <= |a| < 2*|m|, so -|m| <= |r| < |m|.
  420|       |  //
  421|       |  // If 0 <= |r| < |m|, |r| fits in |num| words and |carry| is zero. We then
  422|       |  // wish to select |r| as the answer. Otherwise -m <= r < 0 and we wish to
  423|       |  // return |r| + |m|, or |a|. |carry| must then be -1 or all ones. In both
  424|       |  // cases, |carry| is a suitable input to |bn_select_words|.
  425|       |  //
  426|       |  // Although |carry| may be one if it was one on input and |bn_sub_words|
  427|       |  // returns zero, this would give |r| > |m|, violating our input assumptions.
  428|  2.03k|  assert(carry == 0 || carry == (BN_ULONG)-1);
  429|  2.03k|  bn_select_words(r, carry, a /* r < 0 */, r /* r >= 0 */, num);
  430|  2.03k|  return carry;
  431|  2.03k|}
bn_reduce_once_in_place:
  434|   383k|                                 BN_ULONG *tmp, size_t num) {
  435|       |  // See |bn_reduce_once| for why this logic works.
  436|   383k|  carry -= bn_sub_words(tmp, r, m, num);
  437|   383k|  assert(carry == 0 || carry == (BN_ULONG)-1);
  438|   383k|  bn_select_words(r, carry, r /* tmp < 0 */, tmp /* tmp >= 0 */, num);
  439|   383k|  return carry;
  440|   383k|}
bn_mod_sub_words:
  443|    677|                      const BN_ULONG *m, BN_ULONG *tmp, size_t num) {
  444|       |  // r = a - b
  445|    677|  BN_ULONG borrow = bn_sub_words(r, a, b, num);
  446|       |  // tmp = a - b + m
  447|    677|  bn_add_words(tmp, r, m, num);
  448|    677|  bn_select_words(r, 0 - borrow, tmp /* r < 0 */, r /* r >= 0 */, num);
  449|    677|}
bn_mod_add_words:
  452|   383k|                      const BN_ULONG *m, BN_ULONG *tmp, size_t num) {
  453|   383k|  BN_ULONG carry = bn_add_words(r, a, b, num);
  454|   383k|  bn_reduce_once_in_place(r, carry, m, tmp, num);
  455|   383k|}
bn_mod_add_consttime:
  598|   382k|                         const BIGNUM *m, BN_CTX *ctx) {
  599|   382k|  BN_CTX_start(ctx);
  600|   382k|  a = bn_resized_from_ctx(a, m->width, ctx);
  601|   382k|  b = bn_resized_from_ctx(b, m->width, ctx);
  602|   382k|  BIGNUM *tmp = bn_scratch_space_from_ctx(m->width, ctx);
  603|   382k|  int ok = a != NULL && b != NULL && tmp != NULL &&
  ------------------
  |  Branch (603:12): [True: 382k, False: 0]
  |  Branch (603:25): [True: 382k, False: 0]
  |  Branch (603:38): [True: 382k, False: 0]
  ------------------
  604|   382k|           bn_wexpand(r, m->width);
  ------------------
  |  Branch (604:12): [True: 382k, False: 0]
  ------------------
  605|   382k|  if (ok) {
  ------------------
  |  Branch (605:7): [True: 382k, False: 0]
  ------------------
  606|   382k|    bn_mod_add_words(r->d, a->d, b->d, m->d, tmp->d, m->width);
  607|   382k|    r->width = m->width;
  608|   382k|    r->neg = 0;
  609|   382k|  }
  610|   382k|  BN_CTX_end(ctx);
  611|   382k|  return ok;
  612|   382k|}
bn_mod_sub_consttime:
  623|    677|                         const BIGNUM *m, BN_CTX *ctx) {
  624|    677|  BN_CTX_start(ctx);
  625|    677|  a = bn_resized_from_ctx(a, m->width, ctx);
  626|    677|  b = bn_resized_from_ctx(b, m->width, ctx);
  627|    677|  BIGNUM *tmp = bn_scratch_space_from_ctx(m->width, ctx);
  628|    677|  int ok = a != NULL && b != NULL && tmp != NULL &&
  ------------------
  |  Branch (628:12): [True: 677, False: 0]
  |  Branch (628:25): [True: 677, False: 0]
  |  Branch (628:38): [True: 677, False: 0]
  ------------------
  629|    677|           bn_wexpand(r, m->width);
  ------------------
  |  Branch (629:12): [True: 677, False: 0]
  ------------------
  630|    677|  if (ok) {
  ------------------
  |  Branch (630:7): [True: 677, False: 0]
  ------------------
  631|    677|    bn_mod_sub_words(r->d, a->d, b->d, m->d, tmp->d, m->width);
  632|    677|    r->width = m->width;
  633|    677|    r->neg = 0;
  634|    677|  }
  635|    677|  BN_CTX_end(ctx);
  636|    677|  return ok;
  637|    677|}
BN_mod_mul:
  649|   845k|               BN_CTX *ctx) {
  650|   845k|  BIGNUM *t;
  651|   845k|  int ret = 0;
  652|       |
  653|   845k|  BN_CTX_start(ctx);
  654|   845k|  t = BN_CTX_get(ctx);
  655|   845k|  if (t == NULL) {
  ------------------
  |  Branch (655:7): [True: 0, False: 845k]
  ------------------
  656|      0|    goto err;
  657|      0|  }
  658|       |
  659|   845k|  if (a == b) {
  ------------------
  |  Branch (659:7): [True: 811k, False: 34.9k]
  ------------------
  660|   811k|    if (!BN_sqr(t, a, ctx)) {
  ------------------
  |  Branch (660:9): [True: 0, False: 811k]
  ------------------
  661|      0|      goto err;
  662|      0|    }
  663|   811k|  } else {
  664|  34.9k|    if (!BN_mul(t, a, b, ctx)) {
  ------------------
  |  Branch (664:9): [True: 0, False: 34.9k]
  ------------------
  665|      0|      goto err;
  666|      0|    }
  667|  34.9k|  }
  668|       |
  669|   845k|  if (!BN_nnmod(r, t, m, ctx)) {
  ------------------
  |  Branch (669:7): [True: 0, False: 845k]
  ------------------
  670|      0|    goto err;
  671|      0|  }
  672|       |
  673|   845k|  ret = 1;
  674|       |
  675|   845k|err:
  676|   845k|  BN_CTX_end(ctx);
  677|   845k|  return ret;
  678|   845k|}
BN_mod_sqr:
  680|  34.5k|int BN_mod_sqr(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx) {
  681|  34.5k|  if (!BN_sqr(r, a, ctx)) {
  ------------------
  |  Branch (681:7): [True: 0, False: 34.5k]
  ------------------
  682|      0|    return 0;
  683|      0|  }
  684|       |
  685|       |  // r->neg == 0,  thus we don't need BN_nnmod
  686|  34.5k|  return BN_mod(r, r, m, ctx);
  ------------------
  |  |  547|  34.5k|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  ------------------
  687|  34.5k|}
bn_mod_lshift_consttime:
  713|  1.16k|                            BN_CTX *ctx) {
  714|  1.16k|  if (!BN_copy(r, a)) {
  ------------------
  |  Branch (714:7): [True: 0, False: 1.16k]
  ------------------
  715|      0|    return 0;
  716|      0|  }
  717|   381k|  for (int i = 0; i < n; i++) {
  ------------------
  |  Branch (717:19): [True: 380k, False: 1.16k]
  ------------------
  718|   380k|    if (!bn_mod_lshift1_consttime(r, r, m, ctx)) {
  ------------------
  |  Branch (718:9): [True: 0, False: 380k]
  ------------------
  719|      0|      return 0;
  720|      0|    }
  721|   380k|  }
  722|  1.16k|  return 1;
  723|  1.16k|}
bn_mod_lshift1_consttime:
  742|   380k|                             BN_CTX *ctx) {
  743|   380k|  return bn_mod_add_consttime(r, a, a, m, ctx);
  744|   380k|}
bcm.c:bn_div_rem_words:
  140|  4.41M|                                    BN_ULONG n0, BN_ULONG n1, BN_ULONG d0) {
  141|       |  // GCC and Clang generate function calls to |__udivdi3| and |__umoddi3| when
  142|       |  // the |BN_ULLONG|-based C code is used.
  143|       |  //
  144|       |  // GCC bugs:
  145|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=14224
  146|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=43721
  147|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=54183
  148|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=58897
  149|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=65668
  150|       |  //
  151|       |  // Clang bugs:
  152|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=6397
  153|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=12418
  154|       |  //
  155|       |  // These issues aren't specific to x86 and x86_64, so it might be worthwhile
  156|       |  // to add more assembly language implementations.
  157|       |#if defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86)
  158|       |  __asm__ volatile("divl %4"
  159|       |                   : "=a"(*quotient_out), "=d"(*rem_out)
  160|       |                   : "a"(n1), "d"(n0), "rm"(d0)
  161|       |                   : "cc");
  162|       |#elif defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86_64)
  163|  4.41M|  __asm__ volatile("divq %4"
  164|  4.41M|                   : "=a"(*quotient_out), "=d"(*rem_out)
  165|  4.41M|                   : "a"(n1), "d"(n0), "rm"(d0)
  166|  4.41M|                   : "cc");
  167|       |#else
  168|       |#if defined(BN_CAN_DIVIDE_ULLONG)
  169|       |  BN_ULLONG n = (((BN_ULLONG)n0) << BN_BITS2) | n1;
  170|       |  *quotient_out = (BN_ULONG)(n / d0);
  171|       |#else
  172|       |  *quotient_out = bn_div_words(n0, n1, d0);
  173|       |#endif
  174|       |  *rem_out = n1 - (*quotient_out * d0);
  175|       |#endif
  176|  4.41M|}
bcm.c:bn_resized_from_ctx:
  565|   765k|                                         BN_CTX *ctx) {
  566|   765k|  if ((size_t)bn->width >= width) {
  ------------------
  |  Branch (566:7): [True: 765k, False: 73]
  ------------------
  567|       |    // Any excess words must be zero.
  568|   765k|    assert(bn_fits_in_words(bn, width));
  569|   765k|    return bn;
  570|   765k|  }
  571|     73|  BIGNUM *ret = bn_scratch_space_from_ctx(width, ctx);
  572|     73|  if (ret == NULL ||
  ------------------
  |  Branch (572:7): [True: 0, False: 73]
  ------------------
  573|     73|      !BN_copy(ret, bn) ||
  ------------------
  |  Branch (573:7): [True: 0, False: 73]
  ------------------
  574|     73|      !bn_resize_words(ret, width)) {
  ------------------
  |  Branch (574:7): [True: 0, False: 73]
  ------------------
  575|      0|    return NULL;
  576|      0|  }
  577|     73|  return ret;
  578|     73|}
bcm.c:bn_scratch_space_from_ctx:
  548|   382k|static BIGNUM *bn_scratch_space_from_ctx(size_t width, BN_CTX *ctx) {
  549|   382k|  BIGNUM *ret = BN_CTX_get(ctx);
  550|   382k|  if (ret == NULL ||
  ------------------
  |  Branch (550:7): [True: 0, False: 382k]
  ------------------
  551|   382k|      !bn_wexpand(ret, width)) {
  ------------------
  |  Branch (551:7): [True: 0, False: 382k]
  ------------------
  552|      0|    return NULL;
  553|      0|  }
  554|   382k|  ret->neg = 0;
  555|   382k|  ret->width = (int)width;
  556|   382k|  return ret;
  557|   382k|}

BN_mod_exp_mont:
  588|  1.16k|                    const BIGNUM *m, BN_CTX *ctx, const BN_MONT_CTX *mont) {
  589|  1.16k|  if (!BN_is_odd(m)) {
  ------------------
  |  Branch (589:7): [True: 0, False: 1.16k]
  ------------------
  590|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  591|      0|    return 0;
  592|      0|  }
  593|  1.16k|  if (m->neg) {
  ------------------
  |  Branch (593:7): [True: 0, False: 1.16k]
  ------------------
  594|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  595|      0|    return 0;
  596|      0|  }
  597|       |  // |a| is secret, but |a < m| is not.
  598|  1.16k|  if (a->neg || constant_time_declassify_int(BN_ucmp(a, m)) >= 0) {
  ------------------
  |  Branch (598:7): [True: 0, False: 1.16k]
  |  Branch (598:17): [True: 0, False: 1.16k]
  ------------------
  599|      0|    OPENSSL_PUT_ERROR(BN, BN_R_INPUT_NOT_REDUCED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  600|      0|    return 0;
  601|      0|  }
  602|       |
  603|  1.16k|  int bits = BN_num_bits(p);
  604|  1.16k|  if (bits == 0) {
  ------------------
  |  Branch (604:7): [True: 0, False: 1.16k]
  ------------------
  605|       |    // x**0 mod 1 is still zero.
  606|      0|    if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (606:9): [True: 0, False: 0]
  ------------------
  607|      0|      BN_zero(rr);
  608|      0|      return 1;
  609|      0|    }
  610|      0|    return BN_one(rr);
  611|      0|  }
  612|       |
  613|  1.16k|  int ret = 0;
  614|  1.16k|  BIGNUM *val[TABLE_SIZE];
  615|  1.16k|  BN_MONT_CTX *new_mont = NULL;
  616|       |
  617|  1.16k|  BN_CTX_start(ctx);
  618|  1.16k|  BIGNUM *r = BN_CTX_get(ctx);
  619|  1.16k|  val[0] = BN_CTX_get(ctx);
  620|  1.16k|  if (r == NULL || val[0] == NULL) {
  ------------------
  |  Branch (620:7): [True: 0, False: 1.16k]
  |  Branch (620:20): [True: 0, False: 1.16k]
  ------------------
  621|      0|    goto err;
  622|      0|  }
  623|       |
  624|       |  // Allocate a montgomery context if it was not supplied by the caller.
  625|  1.16k|  if (mont == NULL) {
  ------------------
  |  Branch (625:7): [True: 1.16k, False: 0]
  ------------------
  626|  1.16k|    new_mont = BN_MONT_CTX_new_consttime(m, ctx);
  627|  1.16k|    if (new_mont == NULL) {
  ------------------
  |  Branch (627:9): [True: 0, False: 1.16k]
  ------------------
  628|      0|      goto err;
  629|      0|    }
  630|  1.16k|    mont = new_mont;
  631|  1.16k|  }
  632|       |
  633|       |  // We exponentiate by looking at sliding windows of the exponent and
  634|       |  // precomputing powers of |a|. Windows may be shifted so they always end on a
  635|       |  // set bit, so only precompute odd powers. We compute val[i] = a^(2*i + 1)
  636|       |  // for i = 0 to 2^(window-1), all in Montgomery form.
  637|  1.16k|  int window = BN_window_bits_for_exponent_size(bits);
  638|  1.16k|  if (!BN_to_montgomery(val[0], a, mont, ctx)) {
  ------------------
  |  Branch (638:7): [True: 0, False: 1.16k]
  ------------------
  639|      0|    goto err;
  640|      0|  }
  641|  1.16k|  if (window > 1) {
  ------------------
  |  Branch (641:7): [True: 1.16k, False: 0]
  ------------------
  642|  1.16k|    BIGNUM *d = BN_CTX_get(ctx);
  643|  1.16k|    if (d == NULL ||
  ------------------
  |  Branch (643:9): [True: 0, False: 1.16k]
  ------------------
  644|  1.16k|        !BN_mod_mul_montgomery(d, val[0], val[0], mont, ctx)) {
  ------------------
  |  Branch (644:9): [True: 0, False: 1.16k]
  ------------------
  645|      0|      goto err;
  646|      0|    }
  647|  10.8k|    for (int i = 1; i < 1 << (window - 1); i++) {
  ------------------
  |  Branch (647:21): [True: 9.66k, False: 1.16k]
  ------------------
  648|  9.66k|      val[i] = BN_CTX_get(ctx);
  649|  9.66k|      if (val[i] == NULL ||
  ------------------
  |  Branch (649:11): [True: 0, False: 9.66k]
  ------------------
  650|  9.66k|          !BN_mod_mul_montgomery(val[i], val[i - 1], d, mont, ctx)) {
  ------------------
  |  Branch (650:11): [True: 0, False: 9.66k]
  ------------------
  651|      0|        goto err;
  652|      0|      }
  653|  9.66k|    }
  654|  1.16k|  }
  655|       |
  656|       |  // |p| is non-zero, so at least one window is non-zero. To save some
  657|       |  // multiplications, defer initializing |r| until then.
  658|  1.16k|  int r_is_one = 1;
  659|  1.16k|  int wstart = bits - 1;  // The top bit of the window.
  660|  97.5k|  for (;;) {
  661|  97.5k|    if (!BN_is_bit_set(p, wstart)) {
  ------------------
  |  Branch (661:9): [True: 61.1k, False: 36.4k]
  ------------------
  662|  61.1k|      if (!r_is_one && !BN_mod_mul_montgomery(r, r, r, mont, ctx)) {
  ------------------
  |  Branch (662:11): [True: 61.1k, False: 0]
  |  Branch (662:24): [True: 0, False: 61.1k]
  ------------------
  663|      0|        goto err;
  664|      0|      }
  665|  61.1k|      if (wstart == 0) {
  ------------------
  |  Branch (665:11): [True: 188, False: 60.9k]
  ------------------
  666|    188|        break;
  667|    188|      }
  668|  60.9k|      wstart--;
  669|  60.9k|      continue;
  670|  61.1k|    }
  671|       |
  672|       |    // We now have wstart on a set bit. Find the largest window we can use.
  673|  36.4k|    int wvalue = 1;
  674|  36.4k|    int wsize = 0;
  675|   150k|    for (int i = 1; i < window && i <= wstart; i++) {
  ------------------
  |  Branch (675:21): [True: 114k, False: 35.9k]
  |  Branch (675:35): [True: 113k, False: 489]
  ------------------
  676|   113k|      if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (676:11): [True: 112k, False: 1.01k]
  ------------------
  677|   112k|        wvalue <<= (i - wsize);
  678|   112k|        wvalue |= 1;
  679|   112k|        wsize = i;
  680|   112k|      }
  681|   113k|    }
  682|       |
  683|       |    // Shift |r| to the end of the window.
  684|  36.4k|    if (!r_is_one) {
  ------------------
  |  Branch (684:9): [True: 35.2k, False: 1.16k]
  ------------------
  685|   180k|      for (int i = 0; i < wsize + 1; i++) {
  ------------------
  |  Branch (685:23): [True: 144k, False: 35.2k]
  ------------------
  686|   144k|        if (!BN_mod_mul_montgomery(r, r, r, mont, ctx)) {
  ------------------
  |  Branch (686:13): [True: 0, False: 144k]
  ------------------
  687|      0|          goto err;
  688|      0|        }
  689|   144k|      }
  690|  35.2k|    }
  691|       |
  692|  36.4k|    assert(wvalue & 1);
  693|  36.4k|    assert(wvalue < (1 << window));
  694|  36.4k|    if (r_is_one) {
  ------------------
  |  Branch (694:9): [True: 1.16k, False: 35.2k]
  ------------------
  695|  1.16k|      if (!BN_copy(r, val[wvalue >> 1])) {
  ------------------
  |  Branch (695:11): [True: 0, False: 1.16k]
  ------------------
  696|      0|        goto err;
  697|      0|      }
  698|  35.2k|    } else if (!BN_mod_mul_montgomery(r, r, val[wvalue >> 1], mont, ctx)) {
  ------------------
  |  Branch (698:16): [True: 0, False: 35.2k]
  ------------------
  699|      0|      goto err;
  700|      0|    }
  701|       |
  702|  36.4k|    r_is_one = 0;
  703|  36.4k|    if (wstart == wsize) {
  ------------------
  |  Branch (703:9): [True: 978, False: 35.4k]
  ------------------
  704|    978|      break;
  705|    978|    }
  706|  35.4k|    wstart -= wsize + 1;
  707|  35.4k|  }
  708|       |
  709|       |  // |p| is non-zero, so |r_is_one| must be cleared at some point.
  710|  1.16k|  assert(!r_is_one);
  711|       |
  712|  1.16k|  if (!BN_from_montgomery(rr, r, mont, ctx)) {
  ------------------
  |  Branch (712:7): [True: 0, False: 1.16k]
  ------------------
  713|      0|    goto err;
  714|      0|  }
  715|  1.16k|  ret = 1;
  716|       |
  717|  1.16k|err:
  718|  1.16k|  BN_MONT_CTX_free(new_mont);
  719|  1.16k|  BN_CTX_end(ctx);
  720|  1.16k|  return ret;
  721|  1.16k|}
bcm.c:BN_window_bits_for_exponent_size:
  400|  1.16k|static int BN_window_bits_for_exponent_size(size_t b) {
  401|  1.16k|  if (b > 671) {
  ------------------
  |  Branch (401:7): [True: 0, False: 1.16k]
  ------------------
  402|      0|    return 6;
  403|      0|  }
  404|  1.16k|  if (b > 239) {
  ------------------
  |  Branch (404:7): [True: 188, False: 978]
  ------------------
  405|    188|    return 5;
  406|    188|  }
  407|    978|  if (b > 79) {
  ------------------
  |  Branch (407:7): [True: 978, False: 0]
  ------------------
  408|    978|    return 4;
  409|    978|  }
  410|      0|  if (b > 23) {
  ------------------
  |  Branch (410:7): [True: 0, False: 0]
  ------------------
  411|      0|    return 3;
  412|      0|  }
  413|      0|  return 1;
  414|      0|}

bn_jacobi:
   63|  4.89k|int bn_jacobi(const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
   64|       |  // In 'tab', only odd-indexed entries are relevant:
   65|       |  // For any odd BIGNUM n,
   66|       |  //     tab[BN_lsw(n) & 7]
   67|       |  // is $(-1)^{(n^2-1)/8}$ (using TeX notation).
   68|       |  // Note that the sign of n does not matter.
   69|  4.89k|  static const int tab[8] = {0, 1, 0, -1, 0, -1, 0, 1};
   70|       |
   71|       |  // The Jacobi symbol is only defined for odd modulus.
   72|  4.89k|  if (!BN_is_odd(b)) {
  ------------------
  |  Branch (72:7): [True: 0, False: 4.89k]
  ------------------
   73|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   74|      0|    return -2;
   75|      0|  }
   76|       |
   77|       |  // Require b be positive.
   78|  4.89k|  if (BN_is_negative(b)) {
  ------------------
  |  Branch (78:7): [True: 0, False: 4.89k]
  ------------------
   79|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   80|      0|    return -2;
   81|      0|  }
   82|       |
   83|  4.89k|  int ret = -2;
   84|  4.89k|  BN_CTX_start(ctx);
   85|  4.89k|  BIGNUM *A = BN_CTX_get(ctx);
   86|  4.89k|  BIGNUM *B = BN_CTX_get(ctx);
   87|  4.89k|  if (B == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 4.89k]
  ------------------
   88|      0|    goto end;
   89|      0|  }
   90|       |
   91|  4.89k|  if (!BN_copy(A, a) ||
  ------------------
  |  Branch (91:7): [True: 0, False: 4.89k]
  ------------------
   92|  4.89k|      !BN_copy(B, b)) {
  ------------------
  |  Branch (92:7): [True: 0, False: 4.89k]
  ------------------
   93|      0|    goto end;
   94|      0|  }
   95|       |
   96|       |  // Adapted from logic to compute the Kronecker symbol, originally implemented
   97|       |  // according to Henri Cohen, "A Course in Computational Algebraic Number
   98|       |  // Theory" (algorithm 1.4.10).
   99|       |
  100|  4.89k|  ret = 1;
  101|       |
  102|  13.2k|  while (1) {
  ------------------
  |  Branch (102:10): [Folded - Ignored]
  ------------------
  103|       |    // Cohen's step 3:
  104|       |
  105|       |    // B is positive and odd
  106|  13.2k|    if (BN_is_zero(A)) {
  ------------------
  |  Branch (106:9): [True: 4.89k, False: 8.31k]
  ------------------
  107|  4.89k|      ret = BN_is_one(B) ? ret : 0;
  ------------------
  |  Branch (107:13): [True: 4.89k, False: 0]
  ------------------
  108|  4.89k|      goto end;
  109|  4.89k|    }
  110|       |
  111|       |    // now A is non-zero
  112|  8.31k|    int i = 0;
  113|  15.6k|    while (!BN_is_bit_set(A, i)) {
  ------------------
  |  Branch (113:12): [True: 7.33k, False: 8.31k]
  ------------------
  114|  7.33k|      i++;
  115|  7.33k|    }
  116|  8.31k|    if (!BN_rshift(A, A, i)) {
  ------------------
  |  Branch (116:9): [True: 0, False: 8.31k]
  ------------------
  117|      0|      ret = -2;
  118|      0|      goto end;
  119|      0|    }
  120|  8.31k|    if (i & 1) {
  ------------------
  |  Branch (120:9): [True: 2.44k, False: 5.86k]
  ------------------
  121|       |      // i is odd
  122|       |      // multiply 'ret' by  $(-1)^{(B^2-1)/8}$
  123|  2.44k|      ret = ret * tab[BN_lsw(B) & 7];
  ------------------
  |  |   61|  2.44k|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 2.44k]
  |  |  ------------------
  ------------------
  124|  2.44k|    }
  125|       |
  126|       |    // Cohen's step 4:
  127|       |    // multiply 'ret' by  $(-1)^{(A-1)(B-1)/4}$
  128|  8.31k|    if ((A->neg ? ~BN_lsw(A) : BN_lsw(A)) & BN_lsw(B) & 2) {
  ------------------
  |  |   61|      0|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 0]
  |  |  ------------------
  ------------------
                  if ((A->neg ? ~BN_lsw(A) : BN_lsw(A)) & BN_lsw(B) & 2) {
  ------------------
  |  |   61|  8.31k|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 8.31k]
  |  |  ------------------
  ------------------
                  if ((A->neg ? ~BN_lsw(A) : BN_lsw(A)) & BN_lsw(B) & 2) {
  ------------------
  |  |   61|  8.31k|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 8.31k]
  |  |  ------------------
  ------------------
  |  Branch (128:9): [True: 0, False: 8.31k]
  |  Branch (128:10): [True: 0, False: 8.31k]
  ------------------
  129|      0|      ret = -ret;
  130|      0|    }
  131|       |
  132|       |    // (A, B) := (B mod |A|, |A|)
  133|  8.31k|    if (!BN_nnmod(B, B, A, ctx)) {
  ------------------
  |  Branch (133:9): [True: 0, False: 8.31k]
  ------------------
  134|      0|      ret = -2;
  135|      0|      goto end;
  136|      0|    }
  137|  8.31k|    BIGNUM *tmp = A;
  138|  8.31k|    A = B;
  139|  8.31k|    B = tmp;
  140|  8.31k|    tmp->neg = 0;
  141|  8.31k|  }
  142|       |
  143|  4.89k|end:
  144|  4.89k|  BN_CTX_end(ctx);
  145|  4.89k|  return ret;
  146|  4.89k|}

BN_MONT_CTX_new:
  124|  1.17k|BN_MONT_CTX *BN_MONT_CTX_new(void) {
  125|  1.17k|  BN_MONT_CTX *ret = OPENSSL_malloc(sizeof(BN_MONT_CTX));
  126|       |
  127|  1.17k|  if (ret == NULL) {
  ------------------
  |  Branch (127:7): [True: 0, False: 1.17k]
  ------------------
  128|      0|    return NULL;
  129|      0|  }
  130|       |
  131|  1.17k|  OPENSSL_memset(ret, 0, sizeof(BN_MONT_CTX));
  132|  1.17k|  BN_init(&ret->RR);
  133|  1.17k|  BN_init(&ret->N);
  134|       |
  135|  1.17k|  return ret;
  136|  1.17k|}
BN_MONT_CTX_free:
  138|  3.41k|void BN_MONT_CTX_free(BN_MONT_CTX *mont) {
  139|  3.41k|  if (mont == NULL) {
  ------------------
  |  Branch (139:7): [True: 2.24k, False: 1.16k]
  ------------------
  140|  2.24k|    return;
  141|  2.24k|  }
  142|       |
  143|  1.16k|  BN_free(&mont->RR);
  144|  1.16k|  BN_free(&mont->N);
  145|  1.16k|  OPENSSL_free(mont);
  146|  1.16k|}
BN_MONT_CTX_set:
  210|      7|int BN_MONT_CTX_set(BN_MONT_CTX *mont, const BIGNUM *mod, BN_CTX *ctx) {
  211|      7|  if (!bn_mont_ctx_set_N_and_n0(mont, mod)) {
  ------------------
  |  Branch (211:7): [True: 0, False: 7]
  ------------------
  212|      0|    return 0;
  213|      0|  }
  214|       |
  215|      7|  BN_CTX *new_ctx = NULL;
  216|      7|  if (ctx == NULL) {
  ------------------
  |  Branch (216:7): [True: 4, False: 3]
  ------------------
  217|      4|    new_ctx = BN_CTX_new();
  218|      4|    if (new_ctx == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 4]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|      4|    ctx = new_ctx;
  222|      4|  }
  223|       |
  224|       |  // Save RR = R**2 (mod N). R is the smallest power of 2**BN_BITS2 such that R
  225|       |  // > mod. Even though the assembly on some 32-bit platforms works with 64-bit
  226|       |  // values, using |BN_BITS2| here, rather than |BN_MONT_CTX_N0_LIMBS *
  227|       |  // BN_BITS2|, is correct because R**2 will still be a multiple of the latter
  228|       |  // as |BN_MONT_CTX_N0_LIMBS| is either one or two.
  229|      7|  unsigned lgBigR = mont->N.width * BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  230|      7|  BN_zero(&mont->RR);
  231|      7|  int ok = BN_set_bit(&mont->RR, lgBigR * 2) &&
  ------------------
  |  Branch (231:12): [True: 7, False: 0]
  ------------------
  232|      7|           BN_mod(&mont->RR, &mont->RR, &mont->N, ctx) &&
  ------------------
  |  |  547|     14|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  |  |  ------------------
  |  |  |  Branch (547:3): [True: 7, False: 0]
  |  |  ------------------
  ------------------
  233|      7|           bn_resize_words(&mont->RR, mont->N.width);
  ------------------
  |  Branch (233:12): [True: 7, False: 0]
  ------------------
  234|      7|  BN_CTX_free(new_ctx);
  235|      7|  return ok;
  236|      7|}
BN_MONT_CTX_new_for_modulus:
  238|      7|BN_MONT_CTX *BN_MONT_CTX_new_for_modulus(const BIGNUM *mod, BN_CTX *ctx) {
  239|      7|  BN_MONT_CTX *mont = BN_MONT_CTX_new();
  240|      7|  if (mont == NULL ||
  ------------------
  |  Branch (240:7): [True: 0, False: 7]
  ------------------
  241|      7|      !BN_MONT_CTX_set(mont, mod, ctx)) {
  ------------------
  |  Branch (241:7): [True: 0, False: 7]
  ------------------
  242|      0|    BN_MONT_CTX_free(mont);
  243|      0|    return NULL;
  244|      0|  }
  245|      7|  return mont;
  246|      7|}
BN_MONT_CTX_new_consttime:
  248|  1.16k|BN_MONT_CTX *BN_MONT_CTX_new_consttime(const BIGNUM *mod, BN_CTX *ctx) {
  249|  1.16k|  BN_MONT_CTX *mont = BN_MONT_CTX_new();
  250|  1.16k|  if (mont == NULL ||
  ------------------
  |  Branch (250:7): [True: 0, False: 1.16k]
  ------------------
  251|  1.16k|      !bn_mont_ctx_set_N_and_n0(mont, mod)) {
  ------------------
  |  Branch (251:7): [True: 0, False: 1.16k]
  ------------------
  252|      0|    goto err;
  253|      0|  }
  254|  1.16k|  unsigned lgBigR = mont->N.width * BN_BITS2;
  ------------------
  |  |  151|  1.16k|#define BN_BITS2 64
  ------------------
  255|  1.16k|  if (!bn_mod_exp_base_2_consttime(&mont->RR, lgBigR * 2, &mont->N, ctx) ||
  ------------------
  |  Branch (255:7): [True: 0, False: 1.16k]
  ------------------
  256|  1.16k|      !bn_resize_words(&mont->RR, mont->N.width)) {
  ------------------
  |  Branch (256:7): [True: 0, False: 1.16k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|  1.16k|  return mont;
  260|       |
  261|      0|err:
  262|      0|  BN_MONT_CTX_free(mont);
  263|      0|  return NULL;
  264|  1.16k|}
BN_to_montgomery:
  286|  1.16k|                     BN_CTX *ctx) {
  287|  1.16k|  return BN_mod_mul_montgomery(ret, a, &mont->RR, mont, ctx);
  288|  1.16k|}
BN_from_montgomery:
  346|  1.16k|                       BN_CTX *ctx) {
  347|  1.16k|  int ret = 0;
  348|  1.16k|  BIGNUM *t;
  349|       |
  350|  1.16k|  BN_CTX_start(ctx);
  351|  1.16k|  t = BN_CTX_get(ctx);
  352|  1.16k|  if (t == NULL ||
  ------------------
  |  Branch (352:7): [True: 0, False: 1.16k]
  ------------------
  353|  1.16k|      !BN_copy(t, a)) {
  ------------------
  |  Branch (353:7): [True: 0, False: 1.16k]
  ------------------
  354|      0|    goto err;
  355|      0|  }
  356|       |
  357|  1.16k|  ret = BN_from_montgomery_word(r, t, mont);
  358|       |
  359|  1.16k|err:
  360|  1.16k|  BN_CTX_end(ctx);
  361|       |
  362|  1.16k|  return ret;
  363|  1.16k|}
BN_mod_mul_montgomery:
  420|   253k|                          const BN_MONT_CTX *mont, BN_CTX *ctx) {
  421|   253k|  if (a->neg || b->neg) {
  ------------------
  |  Branch (421:7): [True: 0, False: 253k]
  |  Branch (421:17): [True: 0, False: 253k]
  ------------------
  422|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  423|      0|    return 0;
  424|      0|  }
  425|       |
  426|   253k|#if defined(OPENSSL_BN_ASM_MONT)
  427|       |  // |bn_mul_mont| requires at least 128 bits of limbs, at least for x86.
  428|   253k|  int num = mont->N.width;
  429|   253k|  if (num >= (128 / BN_BITS2) &&
  ------------------
  |  |  151|   253k|#define BN_BITS2 64
  ------------------
  |  Branch (429:7): [True: 253k, False: 0]
  ------------------
  430|   253k|      a->width == num &&
  ------------------
  |  Branch (430:7): [True: 252k, False: 492]
  ------------------
  431|   253k|      b->width == num) {
  ------------------
  |  Branch (431:7): [True: 252k, False: 0]
  ------------------
  432|   252k|    if (!bn_wexpand(r, num)) {
  ------------------
  |  Branch (432:9): [True: 0, False: 252k]
  ------------------
  433|      0|      return 0;
  434|      0|    }
  435|       |    // This bound is implied by |bn_mont_ctx_set_N_and_n0|. |bn_mul_mont|
  436|       |    // allocates |num| words on the stack, so |num| cannot be too large.
  437|   252k|    assert((size_t)num <= BN_MONTGOMERY_MAX_WORDS);
  438|   252k|    if (!bn_mul_mont(r->d, a->d, b->d, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (438:9): [True: 0, False: 252k]
  ------------------
  439|       |      // The check above ensures this won't happen.
  440|      0|      assert(0);
  441|      0|      OPENSSL_PUT_ERROR(BN, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  442|      0|      return 0;
  443|      0|    }
  444|   252k|    r->neg = 0;
  445|   252k|    r->width = num;
  446|   252k|    return 1;
  447|   252k|  }
  448|    492|#endif
  449|       |
  450|    492|  return bn_mod_mul_montgomery_fallback(r, a, b, mont, ctx);
  451|   253k|}
bn_to_montgomery_small:
  459|    268|                            const BN_MONT_CTX *mont) {
  460|    268|  bn_mod_mul_montgomery_small(r, a, mont->RR.d, num, mont);
  461|    268|}
bn_from_montgomery_small:
  464|    376|                              size_t num_a, const BN_MONT_CTX *mont) {
  465|    376|  if (num_r != (size_t)mont->N.width || num_r > BN_SMALL_MAX_WORDS ||
  ------------------
  |  |  684|    752|#define BN_SMALL_MAX_WORDS 9
  ------------------
  |  Branch (465:7): [True: 0, False: 376]
  |  Branch (465:41): [True: 0, False: 376]
  ------------------
  466|    376|      num_a > 2 * num_r) {
  ------------------
  |  Branch (466:7): [True: 0, False: 376]
  ------------------
  467|      0|    abort();
  468|      0|  }
  469|    376|  BN_ULONG tmp[BN_SMALL_MAX_WORDS * 2] = {0};
  470|    376|  OPENSSL_memcpy(tmp, a, num_a * sizeof(BN_ULONG));
  471|    376|  if (!bn_from_montgomery_in_place(r, num_r, tmp, 2 * num_r, mont)) {
  ------------------
  |  Branch (471:7): [True: 0, False: 376]
  ------------------
  472|      0|    abort();
  473|      0|  }
  474|    376|  OPENSSL_cleanse(tmp, 2 * num_r * sizeof(BN_ULONG));
  475|    376|}
bn_mod_mul_montgomery_small:
  479|    655|                                 const BN_MONT_CTX *mont) {
  480|    655|  if (num != (size_t)mont->N.width || num > BN_SMALL_MAX_WORDS) {
  ------------------
  |  |  684|    655|#define BN_SMALL_MAX_WORDS 9
  ------------------
  |  Branch (480:7): [True: 0, False: 655]
  |  Branch (480:39): [True: 0, False: 655]
  ------------------
  481|      0|    abort();
  482|      0|  }
  483|       |
  484|    655|#if defined(OPENSSL_BN_ASM_MONT)
  485|       |  // |bn_mul_mont| requires at least 128 bits of limbs, at least for x86.
  486|    655|  if (num >= (128 / BN_BITS2)) {
  ------------------
  |  |  151|    655|#define BN_BITS2 64
  ------------------
  |  Branch (486:7): [True: 655, False: 0]
  ------------------
  487|    655|    if (!bn_mul_mont(r, a, b, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (487:9): [True: 0, False: 655]
  ------------------
  488|      0|      abort();  // The check above ensures this won't happen.
  489|      0|    }
  490|    655|    return;
  491|    655|  }
  492|      0|#endif
  493|       |
  494|       |  // Compute the product.
  495|      0|  BN_ULONG tmp[2 * BN_SMALL_MAX_WORDS];
  496|      0|  if (a == b) {
  ------------------
  |  Branch (496:7): [True: 0, False: 0]
  ------------------
  497|      0|    bn_sqr_small(tmp, 2 * num, a, num);
  498|      0|  } else {
  499|      0|    bn_mul_small(tmp, 2 * num, a, num, b, num);
  500|      0|  }
  501|       |
  502|       |  // Reduce.
  503|      0|  if (!bn_from_montgomery_in_place(r, num, tmp, 2 * num, mont)) {
  ------------------
  |  Branch (503:7): [True: 0, False: 0]
  ------------------
  504|      0|    abort();
  505|      0|  }
  506|      0|  OPENSSL_cleanse(tmp, 2 * num * sizeof(BN_ULONG));
  507|      0|}
bcm.c:bn_mont_ctx_set_N_and_n0:
  162|  1.17k|static int bn_mont_ctx_set_N_and_n0(BN_MONT_CTX *mont, const BIGNUM *mod) {
  163|  1.17k|  if (BN_is_zero(mod)) {
  ------------------
  |  Branch (163:7): [True: 0, False: 1.17k]
  ------------------
  164|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  165|      0|    return 0;
  166|      0|  }
  167|  1.17k|  if (!BN_is_odd(mod)) {
  ------------------
  |  Branch (167:7): [True: 0, False: 1.17k]
  ------------------
  168|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|      0|    return 0;
  170|      0|  }
  171|  1.17k|  if (BN_is_negative(mod)) {
  ------------------
  |  Branch (171:7): [True: 0, False: 1.17k]
  ------------------
  172|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|    return 0;
  174|      0|  }
  175|  1.17k|  if (!bn_fits_in_words(mod, BN_MONTGOMERY_MAX_WORDS)) {
  ------------------
  |  |  363|  1.17k|#define BN_MONTGOMERY_MAX_WORDS (8 * 1024 / sizeof(BN_ULONG))
  ------------------
  |  Branch (175:7): [True: 0, False: 1.17k]
  ------------------
  176|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|    return 0;
  178|      0|  }
  179|       |
  180|       |  // Save the modulus.
  181|  1.17k|  if (!BN_copy(&mont->N, mod)) {
  ------------------
  |  Branch (181:7): [True: 0, False: 1.17k]
  ------------------
  182|      0|    OPENSSL_PUT_ERROR(BN, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  183|      0|    return 0;
  184|      0|  }
  185|       |  // |mont->N| is always stored minimally. Computing RR efficiently leaks the
  186|       |  // size of the modulus. While the modulus may be private in RSA (one of the
  187|       |  // primes), their sizes are public, so this is fine.
  188|  1.17k|  bn_set_minimal_width(&mont->N);
  189|       |
  190|       |  // Find n0 such that n0 * N == -1 (mod r).
  191|       |  //
  192|       |  // Only certain BN_BITS2<=32 platforms actually make use of n0[1]. For the
  193|       |  // others, we could use a shorter R value and use faster |BN_ULONG|-based
  194|       |  // math instead of |uint64_t|-based math, which would be double-precision.
  195|       |  // However, currently only the assembler files know which is which.
  196|  1.17k|  static_assert(BN_MONT_CTX_N0_LIMBS == 1 || BN_MONT_CTX_N0_LIMBS == 2,
  197|  1.17k|                "BN_MONT_CTX_N0_LIMBS value is invalid");
  198|  1.17k|  static_assert(sizeof(BN_ULONG) * BN_MONT_CTX_N0_LIMBS == sizeof(uint64_t),
  199|  1.17k|                "uint64_t is insufficient precision for n0");
  200|  1.17k|  uint64_t n0 = bn_mont_n0(&mont->N);
  201|  1.17k|  mont->n0[0] = (BN_ULONG)n0;
  202|       |#if BN_MONT_CTX_N0_LIMBS == 2
  203|       |  mont->n0[1] = (BN_ULONG)(n0 >> BN_BITS2);
  204|       |#else
  205|  1.17k|  mont->n0[1] = 0;
  206|  1.17k|#endif
  207|  1.17k|  return 1;
  208|  1.17k|}
bcm.c:BN_from_montgomery_word:
  322|  1.65k|                                   const BN_MONT_CTX *mont) {
  323|  1.65k|  if (r->neg) {
  ------------------
  |  Branch (323:7): [True: 0, False: 1.65k]
  ------------------
  324|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  325|      0|    return 0;
  326|      0|  }
  327|       |
  328|  1.65k|  const BIGNUM *n = &mont->N;
  329|  1.65k|  if (n->width == 0) {
  ------------------
  |  Branch (329:7): [True: 0, False: 1.65k]
  ------------------
  330|      0|    ret->width = 0;
  331|      0|    return 1;
  332|      0|  }
  333|       |
  334|  1.65k|  int max = 2 * n->width;  // carry is stored separately
  335|  1.65k|  if (!bn_resize_words(r, max) ||
  ------------------
  |  Branch (335:7): [True: 0, False: 1.65k]
  ------------------
  336|  1.65k|      !bn_wexpand(ret, n->width)) {
  ------------------
  |  Branch (336:7): [True: 0, False: 1.65k]
  ------------------
  337|      0|    return 0;
  338|      0|  }
  339|       |
  340|  1.65k|  ret->width = n->width;
  341|  1.65k|  ret->neg = 0;
  342|  1.65k|  return bn_from_montgomery_in_place(ret->d, ret->width, r->d, r->width, mont);
  343|  1.65k|}
bcm.c:bn_mod_mul_montgomery_fallback:
  388|    492|                                          BN_CTX *ctx) {
  389|    492|  int ret = 0;
  390|       |
  391|    492|  BN_CTX_start(ctx);
  392|    492|  BIGNUM *tmp = BN_CTX_get(ctx);
  393|    492|  if (tmp == NULL) {
  ------------------
  |  Branch (393:7): [True: 0, False: 492]
  ------------------
  394|      0|    goto err;
  395|      0|  }
  396|       |
  397|    492|  if (a == b) {
  ------------------
  |  Branch (397:7): [True: 0, False: 492]
  ------------------
  398|      0|    if (!bn_sqr_consttime(tmp, a, ctx)) {
  ------------------
  |  Branch (398:9): [True: 0, False: 0]
  ------------------
  399|      0|      goto err;
  400|      0|    }
  401|    492|  } else {
  402|    492|    if (!bn_mul_consttime(tmp, a, b, ctx)) {
  ------------------
  |  Branch (402:9): [True: 0, False: 492]
  ------------------
  403|      0|      goto err;
  404|      0|    }
  405|    492|  }
  406|       |
  407|       |  // reduce from aRR to aR
  408|    492|  if (!BN_from_montgomery_word(r, tmp, mont)) {
  ------------------
  |  Branch (408:7): [True: 0, False: 492]
  ------------------
  409|      0|    goto err;
  410|      0|  }
  411|       |
  412|    492|  ret = 1;
  413|       |
  414|    492|err:
  415|    492|  BN_CTX_end(ctx);
  416|    492|  return ret;
  417|    492|}
bcm.c:bn_from_montgomery_in_place:
  291|  2.03k|                                       size_t num_a, const BN_MONT_CTX *mont) {
  292|  2.03k|  const BN_ULONG *n = mont->N.d;
  293|  2.03k|  size_t num_n = mont->N.width;
  294|  2.03k|  if (num_r != num_n || num_a != 2 * num_n) {
  ------------------
  |  Branch (294:7): [True: 0, False: 2.03k]
  |  Branch (294:25): [True: 0, False: 2.03k]
  ------------------
  295|      0|    OPENSSL_PUT_ERROR(BN, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  296|      0|    return 0;
  297|      0|  }
  298|       |
  299|       |  // Add multiples of |n| to |r| until R = 2^(nl * BN_BITS2) divides it. On
  300|       |  // input, we had |r| < |n| * R, so now |r| < 2 * |n| * R. Note that |r|
  301|       |  // includes |carry| which is stored separately.
  302|  2.03k|  BN_ULONG n0 = mont->n0[0];
  303|  2.03k|  BN_ULONG carry = 0;
  304|  12.2k|  for (size_t i = 0; i < num_n; i++) {
  ------------------
  |  Branch (304:22): [True: 10.1k, False: 2.03k]
  ------------------
  305|  10.1k|    BN_ULONG v = bn_mul_add_words(a + i, n, num_n, a[i] * n0);
  306|  10.1k|    v += carry + a[i + num_n];
  307|  10.1k|    carry |= (v != a[i + num_n]);
  308|  10.1k|    carry &= (v <= a[i + num_n]);
  309|  10.1k|    a[i + num_n] = v;
  310|  10.1k|  }
  311|       |
  312|       |  // Shift |num_n| words to divide by R. We have |a| < 2 * |n|. Note that |a|
  313|       |  // includes |carry| which is stored separately.
  314|  2.03k|  a += num_n;
  315|       |
  316|       |  // |a| thus requires at most one additional subtraction |n| to be reduced.
  317|  2.03k|  bn_reduce_once(r, a, carry, n, num_n);
  318|  2.03k|  return 1;
  319|  2.03k|}

bn_mont_n0:
   33|  1.17k|uint64_t bn_mont_n0(const BIGNUM *n) {
   34|       |  // These conditions are checked by the caller, |BN_MONT_CTX_set| or
   35|       |  // |BN_MONT_CTX_new_consttime|.
   36|  1.17k|  assert(!BN_is_zero(n));
   37|  1.17k|  assert(!BN_is_negative(n));
   38|  1.17k|  assert(BN_is_odd(n));
   39|       |
   40|       |  // r == 2**(BN_MONT_CTX_N0_LIMBS * BN_BITS2) and LG_LITTLE_R == lg(r). This
   41|       |  // ensures that we can do integer division by |r| by simply ignoring
   42|       |  // |BN_MONT_CTX_N0_LIMBS| limbs. Similarly, we can calculate values modulo
   43|       |  // |r| by just looking at the lowest |BN_MONT_CTX_N0_LIMBS| limbs. This is
   44|       |  // what makes Montgomery multiplication efficient.
   45|       |  //
   46|       |  // As shown in Algorithm 1 of "Fast Prime Field Elliptic Curve Cryptography
   47|       |  // with 256 Bit Primes" by Shay Gueron and Vlad Krasnov, in the loop of a
   48|       |  // multi-limb Montgomery multiplication of |a * b (mod n)|, given the
   49|       |  // unreduced product |t == a * b|, we repeatedly calculate:
   50|       |  //
   51|       |  //    t1 := t % r         |t1| is |t|'s lowest limb (see previous paragraph).
   52|       |  //    t2 := t1*n0*n
   53|       |  //    t3 := t + t2
   54|       |  //    t := t3 / r         copy all limbs of |t3| except the lowest to |t|.
   55|       |  //
   56|       |  // In the last step, it would only make sense to ignore the lowest limb of
   57|       |  // |t3| if it were zero. The middle steps ensure that this is the case:
   58|       |  //
   59|       |  //                            t3 ==  0 (mod r)
   60|       |  //                        t + t2 ==  0 (mod r)
   61|       |  //                   t + t1*n0*n ==  0 (mod r)
   62|       |  //                       t1*n0*n == -t (mod r)
   63|       |  //                        t*n0*n == -t (mod r)
   64|       |  //                          n0*n == -1 (mod r)
   65|       |  //                            n0 == -1/n (mod r)
   66|       |  //
   67|       |  // Thus, in each iteration of the loop, we multiply by the constant factor
   68|       |  // |n0|, the negative inverse of n (mod r).
   69|       |
   70|       |  // n_mod_r = n % r. As explained above, this is done by taking the lowest
   71|       |  // |BN_MONT_CTX_N0_LIMBS| limbs of |n|.
   72|  1.17k|  uint64_t n_mod_r = n->d[0];
   73|       |#if BN_MONT_CTX_N0_LIMBS == 2
   74|       |  if (n->width > 1) {
   75|       |    n_mod_r |= (uint64_t)n->d[1] << BN_BITS2;
   76|       |  }
   77|       |#endif
   78|       |
   79|  1.17k|  return bn_neg_inv_mod_r_u64(n_mod_r);
   80|  1.17k|}
bn_mod_exp_base_2_consttime:
  163|  1.16k|                                BN_CTX *ctx) {
  164|  1.16k|  assert(!BN_is_zero(n));
  165|  1.16k|  assert(!BN_is_negative(n));
  166|  1.16k|  assert(BN_is_odd(n));
  167|       |
  168|  1.16k|  BN_zero(r);
  169|       |
  170|  1.16k|  unsigned n_bits = BN_num_bits(n);
  171|  1.16k|  assert(n_bits != 0);
  172|  1.16k|  assert(p > n_bits);
  173|  1.16k|  if (n_bits == 1) {
  ------------------
  |  Branch (173:7): [True: 0, False: 1.16k]
  ------------------
  174|      0|    return 1;
  175|      0|  }
  176|       |
  177|       |  // Set |r| to the larger power of two smaller than |n|, then shift with
  178|       |  // reductions the rest of the way.
  179|  1.16k|  if (!BN_set_bit(r, n_bits - 1) ||
  ------------------
  |  Branch (179:7): [True: 0, False: 1.16k]
  ------------------
  180|  1.16k|      !bn_mod_lshift_consttime(r, r, p - (n_bits - 1), n, ctx)) {
  ------------------
  |  Branch (180:7): [True: 0, False: 1.16k]
  ------------------
  181|      0|    return 0;
  182|      0|  }
  183|       |
  184|  1.16k|  return 1;
  185|  1.16k|}
bcm.c:bn_neg_inv_mod_r_u64:
  104|  1.17k|static uint64_t bn_neg_inv_mod_r_u64(uint64_t n) {
  105|  1.17k|  assert(n % 2 == 1);
  106|       |
  107|       |  // alpha == 2**(lg r - 1) == r / 2.
  108|  1.17k|  static const uint64_t alpha = UINT64_C(1) << (LG_LITTLE_R - 1);
  ------------------
  |  |   31|  1.17k|#define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  158|  1.17k|#define BN_MONT_CTX_N0_LIMBS 1
  |  |  ------------------
  |  |               #define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|  1.17k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  109|       |
  110|  1.17k|  const uint64_t beta = n;
  111|       |
  112|  1.17k|  uint64_t u = 1;
  113|  1.17k|  uint64_t v = 0;
  114|       |
  115|       |  // The invariant maintained from here on is:
  116|       |  // 2**(lg r - i) == u*2*alpha - v*beta.
  117|  76.2k|  for (size_t i = 0; i < LG_LITTLE_R; ++i) {
  ------------------
  |  |   31|  76.2k|#define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  158|  76.2k|#define BN_MONT_CTX_N0_LIMBS 1
  |  |  ------------------
  |  |               #define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|  76.2k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (117:22): [True: 75.0k, False: 1.17k]
  ------------------
  118|  75.0k|#if BN_BITS2 == 64 && defined(BN_ULLONG)
  119|  75.0k|    assert((BN_ULLONG)(1) << (LG_LITTLE_R - i) ==
  120|  75.0k|           ((BN_ULLONG)u * 2 * alpha) - ((BN_ULLONG)v * beta));
  121|  75.0k|#endif
  122|       |
  123|       |    // Delete a common factor of 2 in u and v if |u| is even. Otherwise, set
  124|       |    // |u = (u + beta) / 2| and |v = (v / 2) + alpha|.
  125|       |
  126|  75.0k|    uint64_t u_is_odd = UINT64_C(0) - (u & 1);  // Either 0xff..ff or 0.
  127|       |
  128|       |    // The addition can overflow, so use Dietz's method for it.
  129|       |    //
  130|       |    // Dietz calculates (x+y)/2 by (x⊕y)>>1 + x&y. This is valid for all
  131|       |    // (unsigned) x and y, even when x+y overflows. Evidence for 32-bit values
  132|       |    // (embedded in 64 bits to so that overflow can be ignored):
  133|       |    //
  134|       |    // (declare-fun x () (_ BitVec 64))
  135|       |    // (declare-fun y () (_ BitVec 64))
  136|       |    // (assert (let (
  137|       |    //    (one (_ bv1 64))
  138|       |    //    (thirtyTwo (_ bv32 64)))
  139|       |    //    (and
  140|       |    //      (bvult x (bvshl one thirtyTwo))
  141|       |    //      (bvult y (bvshl one thirtyTwo))
  142|       |    //      (not (=
  143|       |    //        (bvadd (bvlshr (bvxor x y) one) (bvand x y))
  144|       |    //        (bvlshr (bvadd x y) one)))
  145|       |    // )))
  146|       |    // (check-sat)
  147|  75.0k|    uint64_t beta_if_u_is_odd = beta & u_is_odd;  // Either |beta| or 0.
  148|  75.0k|    u = ((u ^ beta_if_u_is_odd) >> 1) + (u & beta_if_u_is_odd);
  149|       |
  150|  75.0k|    uint64_t alpha_if_u_is_odd = alpha & u_is_odd;  // Either |alpha| or 0.
  151|  75.0k|    v = (v >> 1) + alpha_if_u_is_odd;
  152|  75.0k|  }
  153|       |
  154|       |  // The invariant now shows that u*r - v*n == 1 since r == 2 * alpha.
  155|  1.17k|#if BN_BITS2 == 64 && defined(BN_ULLONG)
  156|  1.17k|  assert(1 == ((BN_ULLONG)u * 2 * alpha) - ((BN_ULLONG)v * beta));
  157|  1.17k|#endif
  158|       |
  159|  1.17k|  return v;
  160|  1.17k|}

BN_mul:
  515|  34.9k|int BN_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  516|  34.9k|  if (!bn_mul_impl(r, a, b, ctx)) {
  ------------------
  |  Branch (516:7): [True: 0, False: 34.9k]
  ------------------
  517|      0|    return 0;
  518|      0|  }
  519|       |
  520|       |  // This additionally fixes any negative zeros created by |bn_mul_impl|.
  521|  34.9k|  bn_set_minimal_width(r);
  522|  34.9k|  return 1;
  523|  34.9k|}
bn_mul_consttime:
  525|    492|int bn_mul_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  526|       |  // Prevent negative zeros.
  527|    492|  if (a->neg || b->neg) {
  ------------------
  |  Branch (527:7): [True: 0, False: 492]
  |  Branch (527:17): [True: 0, False: 492]
  ------------------
  528|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  529|      0|    return 0;
  530|      0|  }
  531|       |
  532|    492|  return bn_mul_impl(r, a, b, ctx);
  533|    492|}
bn_sqr_consttime:
  668|   845k|int bn_sqr_consttime(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx) {
  669|   845k|  int al = a->width;
  670|   845k|  if (al <= 0) {
  ------------------
  |  Branch (670:7): [True: 0, False: 845k]
  ------------------
  671|      0|    r->width = 0;
  672|      0|    r->neg = 0;
  673|      0|    return 1;
  674|      0|  }
  675|       |
  676|   845k|  int ret = 0;
  677|   845k|  BN_CTX_start(ctx);
  678|   845k|  BIGNUM *rr = (a != r) ? r : BN_CTX_get(ctx);
  ------------------
  |  Branch (678:16): [True: 829k, False: 16.0k]
  ------------------
  679|   845k|  BIGNUM *tmp = BN_CTX_get(ctx);
  680|   845k|  if (!rr || !tmp) {
  ------------------
  |  Branch (680:7): [True: 0, False: 845k]
  |  Branch (680:14): [True: 0, False: 845k]
  ------------------
  681|      0|    goto err;
  682|      0|  }
  683|       |
  684|   845k|  int max = 2 * al;  // Non-zero (from above)
  685|   845k|  if (!bn_wexpand(rr, max)) {
  ------------------
  |  Branch (685:7): [True: 0, False: 845k]
  ------------------
  686|      0|    goto err;
  687|      0|  }
  688|       |
  689|   845k|  if (al == 4) {
  ------------------
  |  Branch (689:7): [True: 845k, False: 375]
  ------------------
  690|   845k|    bn_sqr_comba4(rr->d, a->d);
  691|   845k|  } else if (al == 8) {
  ------------------
  |  Branch (691:14): [True: 0, False: 375]
  ------------------
  692|      0|    bn_sqr_comba8(rr->d, a->d);
  693|    375|  } else {
  694|    375|    if (al < BN_SQR_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   71|    375|#define BN_SQR_RECURSIVE_SIZE_NORMAL BN_MUL_RECURSIVE_SIZE_NORMAL
  |  |  ------------------
  |  |  |  |   70|    375|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  |  |  ------------------
  ------------------
  |  Branch (694:9): [True: 375, False: 0]
  ------------------
  695|    375|      BN_ULONG t[BN_SQR_RECURSIVE_SIZE_NORMAL * 2];
  696|    375|      bn_sqr_normal(rr->d, a->d, al, t);
  697|    375|    } else {
  698|       |      // If |al| is a power of two, we can use |bn_sqr_recursive|.
  699|      0|      if (al != 0 && (al & (al - 1)) == 0) {
  ------------------
  |  Branch (699:11): [True: 0, False: 0]
  |  Branch (699:22): [True: 0, False: 0]
  ------------------
  700|      0|        if (!bn_wexpand(tmp, al * 4)) {
  ------------------
  |  Branch (700:13): [True: 0, False: 0]
  ------------------
  701|      0|          goto err;
  702|      0|        }
  703|      0|        bn_sqr_recursive(rr->d, a->d, al, tmp->d);
  704|      0|      } else {
  705|      0|        if (!bn_wexpand(tmp, max)) {
  ------------------
  |  Branch (705:13): [True: 0, False: 0]
  ------------------
  706|      0|          goto err;
  707|      0|        }
  708|      0|        bn_sqr_normal(rr->d, a->d, al, tmp->d);
  709|      0|      }
  710|      0|    }
  711|    375|  }
  712|       |
  713|   845k|  rr->neg = 0;
  714|   845k|  rr->width = max;
  715|       |
  716|   845k|  if (rr != r && !BN_copy(r, rr)) {
  ------------------
  |  Branch (716:7): [True: 16.0k, False: 829k]
  |  Branch (716:18): [True: 0, False: 16.0k]
  ------------------
  717|      0|    goto err;
  718|      0|  }
  719|   845k|  ret = 1;
  720|       |
  721|   845k|err:
  722|   845k|  BN_CTX_end(ctx);
  723|   845k|  return ret;
  724|   845k|}
BN_sqr:
  726|   845k|int BN_sqr(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx) {
  727|   845k|  if (!bn_sqr_consttime(r, a, ctx)) {
  ------------------
  |  Branch (727:7): [True: 0, False: 845k]
  ------------------
  728|      0|    return 0;
  729|      0|  }
  730|       |
  731|   845k|  bn_set_minimal_width(r);
  732|   845k|  return 1;
  733|   845k|}
bcm.c:bn_mul_impl:
  420|  35.4k|                       BN_CTX *ctx) {
  421|  35.4k|  int al = a->width;
  422|  35.4k|  int bl = b->width;
  423|  35.4k|  if (al == 0 || bl == 0) {
  ------------------
  |  Branch (423:7): [True: 3, False: 35.4k]
  |  Branch (423:18): [True: 0, False: 35.4k]
  ------------------
  424|      3|    BN_zero(r);
  425|      3|    return 1;
  426|      3|  }
  427|       |
  428|  35.4k|  int ret = 0;
  429|  35.4k|  BIGNUM *rr;
  430|  35.4k|  BN_CTX_start(ctx);
  431|  35.4k|  if (r == a || r == b) {
  ------------------
  |  Branch (431:7): [True: 0, False: 35.4k]
  |  Branch (431:17): [True: 0, False: 35.4k]
  ------------------
  432|      0|    rr = BN_CTX_get(ctx);
  433|      0|    if (rr == NULL) {
  ------------------
  |  Branch (433:9): [True: 0, False: 0]
  ------------------
  434|      0|      goto err;
  435|      0|    }
  436|  35.4k|  } else {
  437|  35.4k|    rr = r;
  438|  35.4k|  }
  439|  35.4k|  rr->neg = a->neg ^ b->neg;
  440|       |
  441|  35.4k|  int i = al - bl;
  442|  35.4k|  if (i == 0) {
  ------------------
  |  Branch (442:7): [True: 34.8k, False: 599]
  ------------------
  443|  34.8k|    if (al == 8) {
  ------------------
  |  Branch (443:9): [True: 0, False: 34.8k]
  ------------------
  444|      0|      if (!bn_wexpand(rr, 16)) {
  ------------------
  |  Branch (444:11): [True: 0, False: 0]
  ------------------
  445|      0|        goto err;
  446|      0|      }
  447|      0|      rr->width = 16;
  448|      0|      bn_mul_comba8(rr->d, a->d, b->d);
  449|      0|      goto end;
  450|      0|    }
  451|  34.8k|  }
  452|       |
  453|  35.4k|  int top = al + bl;
  454|  35.4k|  static const int kMulNormalSize = 16;
  455|  35.4k|  if (al >= kMulNormalSize && bl >= kMulNormalSize) {
  ------------------
  |  Branch (455:7): [True: 0, False: 35.4k]
  |  Branch (455:31): [True: 0, False: 0]
  ------------------
  456|      0|    if (-1 <= i && i <= 1) {
  ------------------
  |  Branch (456:9): [True: 0, False: 0]
  |  Branch (456:20): [True: 0, False: 0]
  ------------------
  457|       |      // Find the largest power of two less than or equal to the larger length.
  458|      0|      int j;
  459|      0|      if (i >= 0) {
  ------------------
  |  Branch (459:11): [True: 0, False: 0]
  ------------------
  460|      0|        j = BN_num_bits_word((BN_ULONG)al);
  461|      0|      } else {
  462|      0|        j = BN_num_bits_word((BN_ULONG)bl);
  463|      0|      }
  464|      0|      j = 1 << (j - 1);
  465|      0|      assert(j <= al || j <= bl);
  466|      0|      BIGNUM *t = BN_CTX_get(ctx);
  467|      0|      if (t == NULL) {
  ------------------
  |  Branch (467:11): [True: 0, False: 0]
  ------------------
  468|      0|        goto err;
  469|      0|      }
  470|      0|      if (al > j || bl > j) {
  ------------------
  |  Branch (470:11): [True: 0, False: 0]
  |  Branch (470:21): [True: 0, False: 0]
  ------------------
  471|       |        // We know |al| and |bl| are at most one from each other, so if al > j,
  472|       |        // bl >= j, and vice versa. Thus we can use |bn_mul_part_recursive|.
  473|       |        //
  474|       |        // TODO(davidben): This codepath is almost unused in standard
  475|       |        // algorithms. Is this optimization necessary? See notes in
  476|       |        // https://boringssl-review.googlesource.com/q/I0bd604e2cd6a75c266f64476c23a730ca1721ea6
  477|      0|        assert(al >= j && bl >= j);
  478|      0|        if (!bn_wexpand(t, j * 8) ||
  ------------------
  |  Branch (478:13): [True: 0, False: 0]
  ------------------
  479|      0|            !bn_wexpand(rr, j * 4)) {
  ------------------
  |  Branch (479:13): [True: 0, False: 0]
  ------------------
  480|      0|          goto err;
  481|      0|        }
  482|      0|        bn_mul_part_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  483|      0|      } else {
  484|       |        // al <= j && bl <= j. Additionally, we know j <= al or j <= bl, so one
  485|       |        // of al - j or bl - j is zero. The other, by the bound on |i| above, is
  486|       |        // zero or -1. Thus, we can use |bn_mul_recursive|.
  487|      0|        if (!bn_wexpand(t, j * 4) ||
  ------------------
  |  Branch (487:13): [True: 0, False: 0]
  ------------------
  488|      0|            !bn_wexpand(rr, j * 2)) {
  ------------------
  |  Branch (488:13): [True: 0, False: 0]
  ------------------
  489|      0|          goto err;
  490|      0|        }
  491|      0|        bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  492|      0|      }
  493|      0|      rr->width = top;
  494|      0|      goto end;
  495|      0|    }
  496|      0|  }
  497|       |
  498|  35.4k|  if (!bn_wexpand(rr, top)) {
  ------------------
  |  Branch (498:7): [True: 0, False: 35.4k]
  ------------------
  499|      0|    goto err;
  500|      0|  }
  501|  35.4k|  rr->width = top;
  502|  35.4k|  bn_mul_normal(rr->d, a->d, al, b->d, bl);
  503|       |
  504|  35.4k|end:
  505|  35.4k|  if (r != rr && !BN_copy(r, rr)) {
  ------------------
  |  Branch (505:7): [True: 0, False: 35.4k]
  |  Branch (505:18): [True: 0, False: 0]
  ------------------
  506|      0|    goto err;
  507|      0|  }
  508|  35.4k|  ret = 1;
  509|       |
  510|  35.4k|err:
  511|  35.4k|  BN_CTX_end(ctx);
  512|  35.4k|  return ret;
  513|  35.4k|}
bcm.c:bn_mul_normal:
   82|  35.4k|                          const BN_ULONG *b, size_t nb) {
   83|  35.4k|  if (na < nb) {
  ------------------
  |  Branch (83:7): [True: 599, False: 34.8k]
  ------------------
   84|    599|    size_t itmp = na;
   85|    599|    na = nb;
   86|    599|    nb = itmp;
   87|    599|    const BN_ULONG *ltmp = a;
   88|    599|    a = b;
   89|    599|    b = ltmp;
   90|    599|  }
   91|  35.4k|  BN_ULONG *rr = &(r[na]);
   92|  35.4k|  if (nb == 0) {
  ------------------
  |  Branch (92:7): [True: 0, False: 35.4k]
  ------------------
   93|      0|    OPENSSL_memset(r, 0, na * sizeof(BN_ULONG));
   94|      0|    return;
   95|      0|  }
   96|  35.4k|  rr[0] = bn_mul_words(r, a, na, b[0]);
   97|       |
   98|  35.7k|  for (;;) {
   99|  35.7k|    if (--nb == 0) {
  ------------------
  |  Branch (99:9): [True: 593, False: 35.1k]
  ------------------
  100|    593|      return;
  101|    593|    }
  102|  35.1k|    rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  103|  35.1k|    if (--nb == 0) {
  ------------------
  |  Branch (103:9): [True: 141, False: 34.9k]
  ------------------
  104|    141|      return;
  105|    141|    }
  106|  34.9k|    rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  107|  34.9k|    if (--nb == 0) {
  ------------------
  |  Branch (107:9): [True: 35, False: 34.9k]
  ------------------
  108|     35|      return;
  109|     35|    }
  110|  34.9k|    rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  111|  34.9k|    if (--nb == 0) {
  ------------------
  |  Branch (111:9): [True: 34.6k, False: 276]
  ------------------
  112|  34.6k|      return;
  113|  34.6k|    }
  114|    276|    rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  115|    276|    rr += 4;
  116|    276|    r += 4;
  117|    276|    b += 4;
  118|    276|  }
  119|  35.4k|}
bcm.c:bn_sqr_normal:
  551|    375|                          BN_ULONG *tmp) {
  552|    375|  if (n == 0) {
  ------------------
  |  Branch (552:7): [True: 0, False: 375]
  ------------------
  553|      0|    return;
  554|      0|  }
  555|       |
  556|    375|  size_t max = n * 2;
  557|    375|  const BN_ULONG *ap = a;
  558|    375|  BN_ULONG *rp = r;
  559|    375|  rp[0] = rp[max - 1] = 0;
  560|    375|  rp++;
  561|       |
  562|       |  // Compute the contribution of a[i] * a[j] for all i < j.
  563|    375|  if (n > 1) {
  ------------------
  |  Branch (563:7): [True: 375, False: 0]
  ------------------
  564|    375|    ap++;
  565|    375|    rp[n - 1] = bn_mul_words(rp, ap, n - 1, ap[-1]);
  566|    375|    rp += 2;
  567|    375|  }
  568|    375|  if (n > 2) {
  ------------------
  |  Branch (568:7): [True: 375, False: 0]
  ------------------
  569|  2.48k|    for (size_t i = n - 2; i > 0; i--) {
  ------------------
  |  Branch (569:28): [True: 2.10k, False: 375]
  ------------------
  570|  2.10k|      ap++;
  571|  2.10k|      rp[i] = bn_mul_add_words(rp, ap, i, ap[-1]);
  572|  2.10k|      rp += 2;
  573|  2.10k|    }
  574|    375|  }
  575|       |
  576|       |  // The final result fits in |max| words, so none of the following operations
  577|       |  // will overflow.
  578|       |
  579|       |  // Double |r|, giving the contribution of a[i] * a[j] for all i != j.
  580|    375|  bn_add_words(r, r, r, max);
  581|       |
  582|       |  // Add in the contribution of a[i] * a[i] for all i.
  583|    375|  bn_sqr_words(tmp, a, n);
  584|    375|  bn_add_words(r, r, tmp, max);
  585|    375|}

BN_lshift:
   67|  1.77M|int BN_lshift(BIGNUM *r, const BIGNUM *a, int n) {
   68|  1.77M|  int i, nw, lb, rb;
   69|  1.77M|  BN_ULONG *t, *f;
   70|  1.77M|  BN_ULONG l;
   71|       |
   72|  1.77M|  if (n < 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 1.77M]
  ------------------
   73|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   74|      0|    return 0;
   75|      0|  }
   76|       |
   77|  1.77M|  r->neg = a->neg;
   78|  1.77M|  nw = n / BN_BITS2;
  ------------------
  |  |  151|  1.77M|#define BN_BITS2 64
  ------------------
   79|  1.77M|  if (!bn_wexpand(r, a->width + nw + 1)) {
  ------------------
  |  Branch (79:7): [True: 0, False: 1.77M]
  ------------------
   80|      0|    return 0;
   81|      0|  }
   82|  1.77M|  lb = n % BN_BITS2;
  ------------------
  |  |  151|  1.77M|#define BN_BITS2 64
  ------------------
   83|  1.77M|  rb = BN_BITS2 - lb;
  ------------------
  |  |  151|  1.77M|#define BN_BITS2 64
  ------------------
   84|  1.77M|  f = a->d;
   85|  1.77M|  t = r->d;
   86|  1.77M|  t[a->width + nw] = 0;
   87|  1.77M|  if (lb == 0) {
  ------------------
  |  Branch (87:7): [True: 696, False: 1.77M]
  ------------------
   88|  6.37k|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (88:28): [True: 5.68k, False: 696]
  ------------------
   89|  5.68k|      t[nw + i] = f[i];
   90|  5.68k|    }
   91|  1.77M|  } else {
   92|  11.5M|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (92:28): [True: 9.72M, False: 1.77M]
  ------------------
   93|  9.72M|      l = f[i];
   94|  9.72M|      t[nw + i + 1] |= l >> rb;
   95|  9.72M|      t[nw + i] = l << lb;
   96|  9.72M|    }
   97|  1.77M|  }
   98|  1.77M|  OPENSSL_memset(t, 0, nw * sizeof(t[0]));
   99|  1.77M|  r->width = a->width + nw + 1;
  100|  1.77M|  bn_set_minimal_width(r);
  101|       |
  102|  1.77M|  return 1;
  103|  1.77M|}
bn_rshift_words:
  137|   898k|                     size_t num) {
  138|   898k|  unsigned shift_bits = shift % BN_BITS2;
  ------------------
  |  |  151|   898k|#define BN_BITS2 64
  ------------------
  139|   898k|  size_t shift_words = shift / BN_BITS2;
  ------------------
  |  |  151|   898k|#define BN_BITS2 64
  ------------------
  140|   898k|  if (shift_words >= num) {
  ------------------
  |  Branch (140:7): [True: 4.89k, False: 893k]
  ------------------
  141|  4.89k|    OPENSSL_memset(r, 0, num * sizeof(BN_ULONG));
  142|  4.89k|    return;
  143|  4.89k|  }
  144|   893k|  if (shift_bits == 0) {
  ------------------
  |  Branch (144:7): [True: 4.74k, False: 888k]
  ------------------
  145|  4.74k|    OPENSSL_memmove(r, a + shift_words, (num - shift_words) * sizeof(BN_ULONG));
  146|   888k|  } else {
  147|  3.48M|    for (size_t i = shift_words; i < num - 1; i++) {
  ------------------
  |  Branch (147:34): [True: 2.59M, False: 888k]
  ------------------
  148|  2.59M|      r[i - shift_words] =
  149|  2.59M|          (a[i] >> shift_bits) | (a[i + 1] << (BN_BITS2 - shift_bits));
  ------------------
  |  |  151|  2.59M|#define BN_BITS2 64
  ------------------
  150|  2.59M|    }
  151|   888k|    r[num - 1 - shift_words] = a[num - 1] >> shift_bits;
  152|   888k|  }
  153|   893k|  OPENSSL_memset(r + num - shift_words, 0, shift_words * sizeof(BN_ULONG));
  154|   893k|}
BN_rshift:
  156|   898k|int BN_rshift(BIGNUM *r, const BIGNUM *a, int n) {
  157|   898k|  if (n < 0) {
  ------------------
  |  Branch (157:7): [True: 0, False: 898k]
  ------------------
  158|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  159|      0|    return 0;
  160|      0|  }
  161|       |
  162|   898k|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (162:7): [True: 0, False: 898k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|   898k|  bn_rshift_words(r->d, a->d, n, a->width);
  166|   898k|  r->neg = a->neg;
  167|   898k|  r->width = a->width;
  168|   898k|  bn_set_minimal_width(r);
  169|   898k|  return 1;
  170|   898k|}
bn_rshift1_words:
  200|    489|void bn_rshift1_words(BN_ULONG *r, const BN_ULONG *a, size_t num) {
  201|    489|  if (num == 0) {
  ------------------
  |  Branch (201:7): [True: 0, False: 489]
  ------------------
  202|      0|    return;
  203|      0|  }
  204|    978|  for (size_t i = 0; i < num - 1; i++) {
  ------------------
  |  Branch (204:22): [True: 489, False: 489]
  ------------------
  205|    489|    r[i] = (a[i] >> 1) | (a[i + 1] << (BN_BITS2 - 1));
  ------------------
  |  |  151|    489|#define BN_BITS2 64
  ------------------
  206|    489|  }
  207|    489|  r[num - 1] = a[num - 1] >> 1;
  208|    489|}
BN_rshift1:
  210|    489|int BN_rshift1(BIGNUM *r, const BIGNUM *a) {
  211|    489|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (211:7): [True: 0, False: 489]
  ------------------
  212|      0|    return 0;
  213|      0|  }
  214|    489|  bn_rshift1_words(r->d, a->d, a->width);
  215|    489|  r->width = a->width;
  216|    489|  r->neg = a->neg;
  217|    489|  bn_set_minimal_width(r);
  218|    489|  return 1;
  219|    489|}
BN_set_bit:
  221|  1.17k|int BN_set_bit(BIGNUM *a, int n) {
  222|  1.17k|  if (n < 0) {
  ------------------
  |  Branch (222:7): [True: 0, False: 1.17k]
  ------------------
  223|      0|    return 0;
  224|      0|  }
  225|       |
  226|  1.17k|  int i = n / BN_BITS2;
  ------------------
  |  |  151|  1.17k|#define BN_BITS2 64
  ------------------
  227|  1.17k|  int j = n % BN_BITS2;
  ------------------
  |  |  151|  1.17k|#define BN_BITS2 64
  ------------------
  228|  1.17k|  if (a->width <= i) {
  ------------------
  |  Branch (228:7): [True: 1.17k, False: 0]
  ------------------
  229|  1.17k|    if (!bn_wexpand(a, i + 1)) {
  ------------------
  |  Branch (229:9): [True: 0, False: 1.17k]
  ------------------
  230|      0|      return 0;
  231|      0|    }
  232|  6.60k|    for (int k = a->width; k < i + 1; k++) {
  ------------------
  |  Branch (232:28): [True: 5.43k, False: 1.17k]
  ------------------
  233|  5.43k|      a->d[k] = 0;
  234|  5.43k|    }
  235|  1.17k|    a->width = i + 1;
  236|  1.17k|  }
  237|       |
  238|  1.17k|  a->d[i] |= (((BN_ULONG)1) << j);
  239|       |
  240|  1.17k|  return 1;
  241|  1.17k|}
bn_is_bit_set_words:
  261|   274k|int bn_is_bit_set_words(const BN_ULONG *a, size_t num, size_t bit) {
  262|   274k|  size_t i = bit / BN_BITS2;
  ------------------
  |  |  151|   274k|#define BN_BITS2 64
  ------------------
  263|   274k|  size_t j = bit % BN_BITS2;
  ------------------
  |  |  151|   274k|#define BN_BITS2 64
  ------------------
  264|   274k|  if (i >= num) {
  ------------------
  |  Branch (264:7): [True: 0, False: 274k]
  ------------------
  265|      0|    return 0;
  266|      0|  }
  267|   274k|  return (a[i] >> j) & 1;
  268|   274k|}
BN_is_bit_set:
  270|   274k|int BN_is_bit_set(const BIGNUM *a, int n) {
  271|   274k|  if (n < 0) {
  ------------------
  |  Branch (271:7): [True: 0, False: 274k]
  ------------------
  272|      0|    return 0;
  273|      0|  }
  274|   274k|  return bn_is_bit_set_words(a->d, a->width, n);
  275|   274k|}

BN_mod_sqrt:
   62|    677|BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx) {
   63|       |  // Compute a square root of |a| mod |p| using the Tonelli/Shanks algorithm
   64|       |  // (cf. Henri Cohen, "A Course in Algebraic Computational Number Theory",
   65|       |  // algorithm 1.5.1). |p| is assumed to be a prime.
   66|       |
   67|    677|  BIGNUM *ret = in;
   68|    677|  int err = 1;
   69|    677|  int r;
   70|    677|  BIGNUM *A, *b, *q, *t, *x, *y;
   71|    677|  int e, i, j;
   72|       |
   73|    677|  if (!BN_is_odd(p) || BN_abs_is_word(p, 1)) {
  ------------------
  |  Branch (73:7): [True: 0, False: 677]
  |  Branch (73:24): [True: 0, False: 677]
  ------------------
   74|      0|    if (BN_abs_is_word(p, 2)) {
  ------------------
  |  Branch (74:9): [True: 0, False: 0]
  ------------------
   75|      0|      if (ret == NULL) {
  ------------------
  |  Branch (75:11): [True: 0, False: 0]
  ------------------
   76|      0|        ret = BN_new();
   77|      0|      }
   78|      0|      if (ret == NULL ||
  ------------------
  |  Branch (78:11): [True: 0, False: 0]
  ------------------
   79|      0|          !BN_set_word(ret, BN_is_bit_set(a, 0))) {
  ------------------
  |  Branch (79:11): [True: 0, False: 0]
  ------------------
   80|      0|        if (ret != in) {
  ------------------
  |  Branch (80:13): [True: 0, False: 0]
  ------------------
   81|      0|          BN_free(ret);
   82|      0|        }
   83|      0|        return NULL;
   84|      0|      }
   85|      0|      return ret;
   86|      0|    }
   87|       |
   88|      0|    OPENSSL_PUT_ERROR(BN, BN_R_P_IS_NOT_PRIME);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   89|      0|    return NULL;
   90|      0|  }
   91|       |
   92|    677|  if (BN_is_zero(a) || BN_is_one(a)) {
  ------------------
  |  Branch (92:7): [True: 0, False: 677]
  |  Branch (92:24): [True: 0, False: 677]
  ------------------
   93|      0|    if (ret == NULL) {
  ------------------
  |  Branch (93:9): [True: 0, False: 0]
  ------------------
   94|      0|      ret = BN_new();
   95|      0|    }
   96|      0|    if (ret == NULL ||
  ------------------
  |  Branch (96:9): [True: 0, False: 0]
  ------------------
   97|      0|        !BN_set_word(ret, BN_is_one(a))) {
  ------------------
  |  Branch (97:9): [True: 0, False: 0]
  ------------------
   98|      0|      if (ret != in) {
  ------------------
  |  Branch (98:11): [True: 0, False: 0]
  ------------------
   99|      0|        BN_free(ret);
  100|      0|      }
  101|      0|      return NULL;
  102|      0|    }
  103|      0|    return ret;
  104|      0|  }
  105|       |
  106|    677|  BN_CTX_start(ctx);
  107|    677|  A = BN_CTX_get(ctx);
  108|    677|  b = BN_CTX_get(ctx);
  109|    677|  q = BN_CTX_get(ctx);
  110|    677|  t = BN_CTX_get(ctx);
  111|    677|  x = BN_CTX_get(ctx);
  112|    677|  y = BN_CTX_get(ctx);
  113|    677|  if (y == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 677]
  ------------------
  114|      0|    goto end;
  115|      0|  }
  116|       |
  117|    677|  if (ret == NULL) {
  ------------------
  |  Branch (117:7): [True: 0, False: 677]
  ------------------
  118|      0|    ret = BN_new();
  119|      0|  }
  120|    677|  if (ret == NULL) {
  ------------------
  |  Branch (120:7): [True: 0, False: 677]
  ------------------
  121|      0|    goto end;
  122|      0|  }
  123|       |
  124|       |  // A = a mod p
  125|    677|  if (!BN_nnmod(A, a, p, ctx)) {
  ------------------
  |  Branch (125:7): [True: 0, False: 677]
  ------------------
  126|      0|    goto end;
  127|      0|  }
  128|       |
  129|       |  // now write  |p| - 1  as  2^e*q  where  q  is odd
  130|    677|  e = 1;
  131|  47.1k|  while (!BN_is_bit_set(p, e)) {
  ------------------
  |  Branch (131:10): [True: 46.4k, False: 677]
  ------------------
  132|  46.4k|    e++;
  133|  46.4k|  }
  134|       |  // we'll set  q  later (if needed)
  135|       |
  136|    677|  if (e == 1) {
  ------------------
  |  Branch (136:7): [True: 188, False: 489]
  ------------------
  137|       |    // The easy case:  (|p|-1)/2  is odd, so 2 has an inverse
  138|       |    // modulo  (|p|-1)/2,  and square roots can be computed
  139|       |    // directly by modular exponentiation.
  140|       |    // We have
  141|       |    //     2 * (|p|+1)/4 == 1   (mod (|p|-1)/2),
  142|       |    // so we can use exponent  (|p|+1)/4,  i.e.  (|p|-3)/4 + 1.
  143|    188|    if (!BN_rshift(q, p, 2)) {
  ------------------
  |  Branch (143:9): [True: 0, False: 188]
  ------------------
  144|      0|      goto end;
  145|      0|    }
  146|    188|    q->neg = 0;
  147|    188|    if (!BN_add_word(q, 1) ||
  ------------------
  |  Branch (147:9): [True: 0, False: 188]
  ------------------
  148|    188|        !BN_mod_exp_mont(ret, A, q, p, ctx, NULL)) {
  ------------------
  |  Branch (148:9): [True: 0, False: 188]
  ------------------
  149|      0|      goto end;
  150|      0|    }
  151|    188|    err = 0;
  152|    188|    goto vrfy;
  153|    188|  }
  154|       |
  155|    489|  if (e == 2) {
  ------------------
  |  Branch (155:7): [True: 0, False: 489]
  ------------------
  156|       |    // |p| == 5  (mod 8)
  157|       |    //
  158|       |    // In this case  2  is always a non-square since
  159|       |    // Legendre(2,p) = (-1)^((p^2-1)/8)  for any odd prime.
  160|       |    // So if  a  really is a square, then  2*a  is a non-square.
  161|       |    // Thus for
  162|       |    //      b := (2*a)^((|p|-5)/8),
  163|       |    //      i := (2*a)*b^2
  164|       |    // we have
  165|       |    //     i^2 = (2*a)^((1 + (|p|-5)/4)*2)
  166|       |    //         = (2*a)^((p-1)/2)
  167|       |    //         = -1;
  168|       |    // so if we set
  169|       |    //      x := a*b*(i-1),
  170|       |    // then
  171|       |    //     x^2 = a^2 * b^2 * (i^2 - 2*i + 1)
  172|       |    //         = a^2 * b^2 * (-2*i)
  173|       |    //         = a*(-i)*(2*a*b^2)
  174|       |    //         = a*(-i)*i
  175|       |    //         = a.
  176|       |    //
  177|       |    // (This is due to A.O.L. Atkin,
  178|       |    // <URL:
  179|       |    //http://listserv.nodak.edu/scripts/wa.exe?A2=ind9211&L=nmbrthry&O=T&P=562>,
  180|       |    // November 1992.)
  181|       |
  182|       |    // t := 2*a
  183|      0|    if (!bn_mod_lshift1_consttime(t, A, p, ctx)) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      goto end;
  185|      0|    }
  186|       |
  187|       |    // b := (2*a)^((|p|-5)/8)
  188|      0|    if (!BN_rshift(q, p, 3)) {
  ------------------
  |  Branch (188:9): [True: 0, False: 0]
  ------------------
  189|      0|      goto end;
  190|      0|    }
  191|      0|    q->neg = 0;
  192|      0|    if (!BN_mod_exp_mont(b, t, q, p, ctx, NULL)) {
  ------------------
  |  Branch (192:9): [True: 0, False: 0]
  ------------------
  193|      0|      goto end;
  194|      0|    }
  195|       |
  196|       |    // y := b^2
  197|      0|    if (!BN_mod_sqr(y, b, p, ctx)) {
  ------------------
  |  Branch (197:9): [True: 0, False: 0]
  ------------------
  198|      0|      goto end;
  199|      0|    }
  200|       |
  201|       |    // t := (2*a)*b^2 - 1
  202|      0|    if (!BN_mod_mul(t, t, y, p, ctx) ||
  ------------------
  |  Branch (202:9): [True: 0, False: 0]
  ------------------
  203|      0|        !BN_sub_word(t, 1)) {
  ------------------
  |  Branch (203:9): [True: 0, False: 0]
  ------------------
  204|      0|      goto end;
  205|      0|    }
  206|       |
  207|       |    // x = a*b*t
  208|      0|    if (!BN_mod_mul(x, A, b, p, ctx) ||
  ------------------
  |  Branch (208:9): [True: 0, False: 0]
  ------------------
  209|      0|        !BN_mod_mul(x, x, t, p, ctx)) {
  ------------------
  |  Branch (209:9): [True: 0, False: 0]
  ------------------
  210|      0|      goto end;
  211|      0|    }
  212|       |
  213|      0|    if (!BN_copy(ret, x)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 0]
  ------------------
  214|      0|      goto end;
  215|      0|    }
  216|      0|    err = 0;
  217|      0|    goto vrfy;
  218|      0|  }
  219|       |
  220|       |  // e > 2, so we really have to use the Tonelli/Shanks algorithm.
  221|       |  // First, find some  y  that is not a square.
  222|    489|  if (!BN_copy(q, p)) {
  ------------------
  |  Branch (222:7): [True: 0, False: 489]
  ------------------
  223|      0|    goto end;  // use 'q' as temp
  224|      0|  }
  225|    489|  q->neg = 0;
  226|    489|  i = 2;
  227|  4.89k|  do {
  228|       |    // For efficiency, try small numbers first;
  229|       |    // if this fails, try random numbers.
  230|  4.89k|    if (i < 22) {
  ------------------
  |  Branch (230:9): [True: 4.89k, False: 0]
  ------------------
  231|  4.89k|      if (!BN_set_word(y, i)) {
  ------------------
  |  Branch (231:11): [True: 0, False: 4.89k]
  ------------------
  232|      0|        goto end;
  233|      0|      }
  234|  4.89k|    } else {
  235|      0|      if (!BN_pseudo_rand(y, BN_num_bits(p), 0, 0)) {
  ------------------
  |  Branch (235:11): [True: 0, False: 0]
  ------------------
  236|      0|        goto end;
  237|      0|      }
  238|      0|      if (BN_ucmp(y, p) >= 0) {
  ------------------
  |  Branch (238:11): [True: 0, False: 0]
  ------------------
  239|      0|        if (!(p->neg ? BN_add : BN_sub)(y, y, p)) {
  ------------------
  |  Branch (239:13): [True: 0, False: 0]
  |  Branch (239:15): [True: 0, False: 0]
  ------------------
  240|      0|          goto end;
  241|      0|        }
  242|      0|      }
  243|       |      // now 0 <= y < |p|
  244|      0|      if (BN_is_zero(y)) {
  ------------------
  |  Branch (244:11): [True: 0, False: 0]
  ------------------
  245|      0|        if (!BN_set_word(y, i)) {
  ------------------
  |  Branch (245:13): [True: 0, False: 0]
  ------------------
  246|      0|          goto end;
  247|      0|        }
  248|      0|      }
  249|      0|    }
  250|       |
  251|  4.89k|    r = bn_jacobi(y, q, ctx);  // here 'q' is |p|
  252|  4.89k|    if (r < -1) {
  ------------------
  |  Branch (252:9): [True: 0, False: 4.89k]
  ------------------
  253|      0|      goto end;
  254|      0|    }
  255|  4.89k|    if (r == 0) {
  ------------------
  |  Branch (255:9): [True: 0, False: 4.89k]
  ------------------
  256|       |      // m divides p
  257|      0|      OPENSSL_PUT_ERROR(BN, BN_R_P_IS_NOT_PRIME);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  258|      0|      goto end;
  259|      0|    }
  260|  4.89k|  } while (r == 1 && ++i < 82);
  ------------------
  |  Branch (260:12): [True: 4.40k, False: 489]
  |  Branch (260:22): [True: 4.40k, False: 0]
  ------------------
  261|       |
  262|    489|  if (r != -1) {
  ------------------
  |  Branch (262:7): [True: 0, False: 489]
  ------------------
  263|       |    // Many rounds and still no non-square -- this is more likely
  264|       |    // a bug than just bad luck.
  265|       |    // Even if  p  is not prime, we should have found some  y
  266|       |    // such that r == -1.
  267|      0|    OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_ITERATIONS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|    goto end;
  269|      0|  }
  270|       |
  271|       |  // Here's our actual 'q':
  272|    489|  if (!BN_rshift(q, q, e)) {
  ------------------
  |  Branch (272:7): [True: 0, False: 489]
  ------------------
  273|      0|    goto end;
  274|      0|  }
  275|       |
  276|       |  // Now that we have some non-square, we can find an element
  277|       |  // of order  2^e  by computing its q'th power.
  278|    489|  if (!BN_mod_exp_mont(y, y, q, p, ctx, NULL)) {
  ------------------
  |  Branch (278:7): [True: 0, False: 489]
  ------------------
  279|      0|    goto end;
  280|      0|  }
  281|    489|  if (BN_is_one(y)) {
  ------------------
  |  Branch (281:7): [True: 0, False: 489]
  ------------------
  282|      0|    OPENSSL_PUT_ERROR(BN, BN_R_P_IS_NOT_PRIME);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|    goto end;
  284|      0|  }
  285|       |
  286|       |  // Now we know that (if  p  is indeed prime) there is an integer
  287|       |  // k,  0 <= k < 2^e,  such that
  288|       |  //
  289|       |  //      a^q * y^k == 1   (mod p).
  290|       |  //
  291|       |  // As  a^q  is a square and  y  is not,  k  must be even.
  292|       |  // q+1  is even, too, so there is an element
  293|       |  //
  294|       |  //     X := a^((q+1)/2) * y^(k/2),
  295|       |  //
  296|       |  // and it satisfies
  297|       |  //
  298|       |  //     X^2 = a^q * a     * y^k
  299|       |  //         = a,
  300|       |  //
  301|       |  // so it is the square root that we are looking for.
  302|       |
  303|       |  // t := (q-1)/2  (note that  q  is odd)
  304|    489|  if (!BN_rshift1(t, q)) {
  ------------------
  |  Branch (304:7): [True: 0, False: 489]
  ------------------
  305|      0|    goto end;
  306|      0|  }
  307|       |
  308|       |  // x := a^((q-1)/2)
  309|    489|  if (BN_is_zero(t)) {  // special case: p = 2^e + 1
  ------------------
  |  Branch (309:7): [True: 0, False: 489]
  ------------------
  310|      0|    if (!BN_nnmod(t, A, p, ctx)) {
  ------------------
  |  Branch (310:9): [True: 0, False: 0]
  ------------------
  311|      0|      goto end;
  312|      0|    }
  313|      0|    if (BN_is_zero(t)) {
  ------------------
  |  Branch (313:9): [True: 0, False: 0]
  ------------------
  314|       |      // special case: a == 0  (mod p)
  315|      0|      BN_zero(ret);
  316|      0|      err = 0;
  317|      0|      goto end;
  318|      0|    } else if (!BN_one(x)) {
  ------------------
  |  Branch (318:16): [True: 0, False: 0]
  ------------------
  319|      0|      goto end;
  320|      0|    }
  321|    489|  } else {
  322|    489|    if (!BN_mod_exp_mont(x, A, t, p, ctx, NULL)) {
  ------------------
  |  Branch (322:9): [True: 0, False: 489]
  ------------------
  323|      0|      goto end;
  324|      0|    }
  325|    489|    if (BN_is_zero(x)) {
  ------------------
  |  Branch (325:9): [True: 0, False: 489]
  ------------------
  326|       |      // special case: a == 0  (mod p)
  327|      0|      BN_zero(ret);
  328|      0|      err = 0;
  329|      0|      goto end;
  330|      0|    }
  331|    489|  }
  332|       |
  333|       |  // b := a*x^2  (= a^q)
  334|    489|  if (!BN_mod_sqr(b, x, p, ctx) ||
  ------------------
  |  Branch (334:7): [True: 0, False: 489]
  ------------------
  335|    489|      !BN_mod_mul(b, b, A, p, ctx)) {
  ------------------
  |  Branch (335:7): [True: 0, False: 489]
  ------------------
  336|      0|    goto end;
  337|      0|  }
  338|       |
  339|       |  // x := a*x    (= a^((q+1)/2))
  340|    489|  if (!BN_mod_mul(x, x, A, p, ctx)) {
  ------------------
  |  Branch (340:7): [True: 0, False: 489]
  ------------------
  341|      0|    goto end;
  342|      0|  }
  343|       |
  344|  17.1k|  while (1) {
  ------------------
  |  Branch (344:10): [Folded - Ignored]
  ------------------
  345|       |    // Now  b  is  a^q * y^k  for some even  k  (0 <= k < 2^E
  346|       |    // where  E  refers to the original value of  e,  which we
  347|       |    // don't keep in a variable),  and  x  is  a^((q+1)/2) * y^(k/2).
  348|       |    //
  349|       |    // We have  a*b = x^2,
  350|       |    //    y^2^(e-1) = -1,
  351|       |    //    b^2^(e-1) = 1.
  352|  17.1k|    if (BN_is_one(b)) {
  ------------------
  |  Branch (352:9): [True: 348, False: 16.7k]
  ------------------
  353|    348|      if (!BN_copy(ret, x)) {
  ------------------
  |  Branch (353:11): [True: 0, False: 348]
  ------------------
  354|      0|        goto end;
  355|      0|      }
  356|    348|      err = 0;
  357|    348|      goto vrfy;
  358|    348|    }
  359|       |
  360|       |    // Find the smallest i, 0 < i < e, such that b^(2^i) = 1
  361|   811k|    for (i = 1; i < e; i++) {
  ------------------
  |  Branch (361:17): [True: 811k, False: 141]
  ------------------
  362|   811k|      if (i == 1) {
  ------------------
  |  Branch (362:11): [True: 16.7k, False: 794k]
  ------------------
  363|  16.7k|        if (!BN_mod_sqr(t, b, p, ctx)) {
  ------------------
  |  Branch (363:13): [True: 0, False: 16.7k]
  ------------------
  364|      0|          goto end;
  365|      0|        }
  366|   794k|      } else {
  367|   794k|        if (!BN_mod_mul(t, t, t, p, ctx)) {
  ------------------
  |  Branch (367:13): [True: 0, False: 794k]
  ------------------
  368|      0|          goto end;
  369|      0|        }
  370|   794k|      }
  371|   811k|      if (BN_is_one(t)) {
  ------------------
  |  Branch (371:11): [True: 16.6k, False: 794k]
  ------------------
  372|  16.6k|        break;
  373|  16.6k|      }
  374|   811k|    }
  375|       |    // If not found, a is not a square or p is not a prime.
  376|  16.7k|    if (i >= e) {
  ------------------
  |  Branch (376:9): [True: 141, False: 16.6k]
  ------------------
  377|    141|      OPENSSL_PUT_ERROR(BN, BN_R_NOT_A_SQUARE);
  ------------------
  |  |  441|    141|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  378|    141|      goto end;
  379|    141|    }
  380|       |
  381|       |    // t := y^2^(e - i - 1)
  382|  16.6k|    if (!BN_copy(t, y)) {
  ------------------
  |  Branch (382:9): [True: 0, False: 16.6k]
  ------------------
  383|      0|      goto end;
  384|      0|    }
  385|  32.7k|    for (j = e - i - 1; j > 0; j--) {
  ------------------
  |  Branch (385:25): [True: 16.0k, False: 16.6k]
  ------------------
  386|  16.0k|      if (!BN_mod_sqr(t, t, p, ctx)) {
  ------------------
  |  Branch (386:11): [True: 0, False: 16.0k]
  ------------------
  387|      0|        goto end;
  388|      0|      }
  389|  16.0k|    }
  390|  16.6k|    if (!BN_mod_mul(y, t, t, p, ctx) ||
  ------------------
  |  Branch (390:9): [True: 0, False: 16.6k]
  ------------------
  391|  16.6k|        !BN_mod_mul(x, x, t, p, ctx) ||
  ------------------
  |  Branch (391:9): [True: 0, False: 16.6k]
  ------------------
  392|  16.6k|        !BN_mod_mul(b, b, y, p, ctx)) {
  ------------------
  |  Branch (392:9): [True: 0, False: 16.6k]
  ------------------
  393|      0|      goto end;
  394|      0|    }
  395|       |
  396|       |    // e decreases each iteration, so this loop will terminate.
  397|  16.6k|    assert(i < e);
  398|  16.6k|    e = i;
  399|  16.6k|  }
  400|       |
  401|    536|vrfy:
  402|    536|  if (!err) {
  ------------------
  |  Branch (402:7): [True: 536, False: 0]
  ------------------
  403|       |    // Verify the result. The input might have been not a square.
  404|    536|    if (!BN_mod_sqr(x, ret, p, ctx)) {
  ------------------
  |  Branch (404:9): [True: 0, False: 536]
  ------------------
  405|      0|      err = 1;
  406|      0|    }
  407|       |
  408|    536|    if (!err && 0 != BN_cmp(x, A)) {
  ------------------
  |  Branch (408:9): [True: 536, False: 0]
  |  Branch (408:17): [True: 62, False: 474]
  ------------------
  409|     62|      OPENSSL_PUT_ERROR(BN, BN_R_NOT_A_SQUARE);
  ------------------
  |  |  441|     62|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  410|     62|      err = 1;
  411|     62|    }
  412|    536|  }
  413|       |
  414|    677|end:
  415|    677|  if (err) {
  ------------------
  |  Branch (415:7): [True: 203, False: 474]
  ------------------
  416|    203|    if (ret != in) {
  ------------------
  |  Branch (416:9): [True: 0, False: 203]
  ------------------
  417|      0|      BN_clear_free(ret);
  418|      0|    }
  419|    203|    ret = NULL;
  420|    203|  }
  421|    677|  BN_CTX_end(ctx);
  422|    677|  return ret;
  423|    536|}

BN_value_one:
   56|      4|  accessor_decorations type *name(void) {                                     \
   57|      4|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      4|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      4|     * cast is needed. */                                                     \
   60|      4|    return (const type *)name##_storage_bss_get();                            \
   61|      4|  }                                                                           \
OPENSSL_built_in_curves:
   56|  1.49k|  accessor_decorations type *name(void) {                                     \
   57|  1.49k|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|  1.49k|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|  1.49k|     * cast is needed. */                                                     \
   60|  1.49k|    return (const type *)name##_storage_bss_get();                            \
   61|  1.49k|  }                                                                           \
EC_GFp_mont_method:
   56|      2|  accessor_decorations type *name(void) {                                     \
   57|      2|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      2|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      2|     * cast is needed. */                                                     \
   60|      2|    return (const type *)name##_storage_bss_get();                            \
   61|      2|  }                                                                           \
EC_GFp_nistp224_method:
   56|      1|  accessor_decorations type *name(void) {                                     \
   57|      1|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      1|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      1|     * cast is needed. */                                                     \
   60|      1|    return (const type *)name##_storage_bss_get();                            \
   61|      1|  }                                                                           \
EC_GFp_nistz256_method:
   56|      1|  accessor_decorations type *name(void) {                                     \
   57|      1|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      1|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      1|     * cast is needed. */                                                     \
   60|      1|    return (const type *)name##_storage_bss_get();                            \
   61|      1|  }                                                                           \
RSA_default_method:
   56|    409|  accessor_decorations type *name(void) {                                     \
   57|    409|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    409|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    409|     * cast is needed. */                                                     \
   60|    409|    return (const type *)name##_storage_bss_get();                            \
   61|    409|  }                                                                           \
bcm.c:BN_value_one_once_bss_get:
   42|      4|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:BN_value_one_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:BN_value_one_storage_bss_get:
   39|      5|  static type *name##_bss_get(void) { return &name; }
bcm.c:OPENSSL_built_in_curves_once_bss_get:
   42|  1.49k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:OPENSSL_built_in_curves_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:OPENSSL_built_in_curves_storage_bss_get:
   39|  1.49k|  static type *name##_bss_get(void) { return &name; }
bcm.c:built_in_groups_bss_get:
   39|    738|  static type *name##_bss_get(void) { return &name; }
bcm.c:built_in_groups_lock_bss_get:
   45|  1.48k|  static struct CRYPTO_STATIC_MUTEX *name##_bss_get(void) { return &name; }
bcm.c:g_ec_ex_data_class_bss_get:
   48|    738|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_mont_method_once_bss_get:
   42|      2|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_mont_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_mont_method_storage_bss_get:
   39|      3|  static type *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistp224_method_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistp224_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_nistp224_method_storage_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistz256_method_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistz256_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_nistz256_method_storage_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_rsa_ex_data_class_bss_get:
   48|    409|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_once_bss_get:
   42|    409|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:RSA_default_method_storage_bss_get:
   39|    410|  static type *name##_bss_get(void) { return &name; }

ec_group_new:
  273|      4|EC_GROUP *ec_group_new(const EC_METHOD *meth) {
  274|      4|  EC_GROUP *ret;
  275|       |
  276|      4|  if (meth == NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 4]
  ------------------
  277|      0|    OPENSSL_PUT_ERROR(EC, EC_R_SLOT_FULL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  278|      0|    return NULL;
  279|      0|  }
  280|       |
  281|      4|  if (meth->group_init == 0) {
  ------------------
  |  Branch (281:7): [True: 0, False: 4]
  ------------------
  282|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|    return NULL;
  284|      0|  }
  285|       |
  286|      4|  ret = OPENSSL_malloc(sizeof(EC_GROUP));
  287|      4|  if (ret == NULL) {
  ------------------
  |  Branch (287:7): [True: 0, False: 4]
  ------------------
  288|      0|    return NULL;
  289|      0|  }
  290|      4|  OPENSSL_memset(ret, 0, sizeof(EC_GROUP));
  291|       |
  292|      4|  ret->references = 1;
  293|      4|  ret->meth = meth;
  294|      4|  BN_init(&ret->order);
  295|       |
  296|      4|  if (!meth->group_init(ret)) {
  ------------------
  |  Branch (296:7): [True: 0, False: 4]
  ------------------
  297|      0|    OPENSSL_free(ret);
  298|      0|    return NULL;
  299|      0|  }
  300|       |
  301|      4|  return ret;
  302|      4|}
EC_GROUP_new_by_curve_name:
  505|    738|EC_GROUP *EC_GROUP_new_by_curve_name(int nid) {
  506|    738|  struct built_in_groups_st *groups = built_in_groups_bss_get();
  507|    738|  EC_GROUP **group_ptr = NULL;
  508|    738|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  509|    738|  const struct built_in_curve *curve = NULL;
  510|  2.41k|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|  2.41k|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (510:22): [True: 2.41k, False: 0]
  ------------------
  511|  2.41k|    if (curves->curves[i].nid == nid) {
  ------------------
  |  Branch (511:9): [True: 738, False: 1.67k]
  ------------------
  512|    738|      curve = &curves->curves[i];
  513|    738|      group_ptr = &groups->groups[i];
  514|    738|      break;
  515|    738|    }
  516|  2.41k|  }
  517|       |
  518|    738|  if (curve == NULL) {
  ------------------
  |  Branch (518:7): [True: 0, False: 738]
  ------------------
  519|      0|    OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  520|      0|    return NULL;
  521|      0|  }
  522|       |
  523|    738|  CRYPTO_STATIC_MUTEX_lock_read(built_in_groups_lock_bss_get());
  524|    738|  EC_GROUP *ret = *group_ptr;
  525|    738|  CRYPTO_STATIC_MUTEX_unlock_read(built_in_groups_lock_bss_get());
  526|    738|  if (ret != NULL) {
  ------------------
  |  Branch (526:7): [True: 734, False: 4]
  ------------------
  527|    734|    return ret;
  528|    734|  }
  529|       |
  530|      4|  ret = ec_group_new_from_data(curve);
  531|      4|  if (ret == NULL) {
  ------------------
  |  Branch (531:7): [True: 0, False: 4]
  ------------------
  532|      0|    return NULL;
  533|      0|  }
  534|       |
  535|      4|  EC_GROUP *to_free = NULL;
  536|      4|  CRYPTO_STATIC_MUTEX_lock_write(built_in_groups_lock_bss_get());
  537|      4|  if (*group_ptr == NULL) {
  ------------------
  |  Branch (537:7): [True: 4, False: 0]
  ------------------
  538|      4|    *group_ptr = ret;
  539|       |    // Filling in |ret->curve_name| makes |EC_GROUP_free| and |EC_GROUP_dup|
  540|       |    // into no-ops. At this point, |ret| is considered static.
  541|      4|    ret->curve_name = nid;
  542|      4|  } else {
  543|      0|    to_free = ret;
  544|      0|    ret = *group_ptr;
  545|      0|  }
  546|      4|  CRYPTO_STATIC_MUTEX_unlock_write(built_in_groups_lock_bss_get());
  547|       |
  548|      4|  EC_GROUP_free(to_free);
  549|      4|  return ret;
  550|      4|}
EC_GROUP_free:
  552|  3.44k|void EC_GROUP_free(EC_GROUP *group) {
  553|  3.44k|  if (group == NULL ||
  ------------------
  |  Branch (553:7): [True: 757, False: 2.68k]
  ------------------
  554|       |      // Built-in curves are static.
  555|  3.44k|      group->curve_name != NID_undef ||
  ------------------
  |  |   85|  6.13k|#define NID_undef 0
  ------------------
  |  Branch (555:7): [True: 2.68k, False: 0]
  ------------------
  556|  3.44k|      !CRYPTO_refcount_dec_and_test_zero(&group->references)) {
  ------------------
  |  Branch (556:7): [True: 0, False: 0]
  ------------------
  557|  3.44k|    return;
  558|  3.44k|  }
  559|       |
  560|      0|  if (group->meth->group_finish != NULL) {
  ------------------
  |  Branch (560:7): [True: 0, False: 0]
  ------------------
  561|      0|    group->meth->group_finish(group);
  562|      0|  }
  563|       |
  564|      0|  ec_point_free(group->generator, 0 /* don't free group */);
  565|      0|  BN_free(&group->order);
  566|      0|  BN_MONT_CTX_free(group->order_mont);
  567|       |
  568|      0|  OPENSSL_free(group);
  569|      0|}
EC_GROUP_dup:
  571|  1.95k|EC_GROUP *EC_GROUP_dup(const EC_GROUP *a) {
  572|  1.95k|  if (a == NULL ||
  ------------------
  |  Branch (572:7): [True: 0, False: 1.95k]
  ------------------
  573|       |      // Built-in curves are static.
  574|  1.95k|      a->curve_name != NID_undef) {
  ------------------
  |  |   85|  1.95k|#define NID_undef 0
  ------------------
  |  Branch (574:7): [True: 1.95k, False: 4]
  ------------------
  575|  1.95k|    return (EC_GROUP *)a;
  576|  1.95k|  }
  577|       |
  578|       |  // Groups are logically immutable (but for |EC_GROUP_set_generator| which must
  579|       |  // be called early on), so we simply take a reference.
  580|      4|  EC_GROUP *group = (EC_GROUP *)a;
  581|      4|  CRYPTO_refcount_inc(&group->references);
  582|      4|  return group;
  583|  1.95k|}
EC_GROUP_cmp:
  585|  2.83k|int EC_GROUP_cmp(const EC_GROUP *a, const EC_GROUP *b, BN_CTX *ignored) {
  586|       |  // Note this function returns 0 if equal and non-zero otherwise.
  587|  2.83k|  if (a == b) {
  ------------------
  |  Branch (587:7): [True: 2.83k, False: 0]
  ------------------
  588|  2.83k|    return 0;
  589|  2.83k|  }
  590|      0|  if (a->curve_name != b->curve_name) {
  ------------------
  |  Branch (590:7): [True: 0, False: 0]
  ------------------
  591|      0|    return 1;
  592|      0|  }
  593|      0|  if (a->curve_name != NID_undef) {
  ------------------
  |  |   85|      0|#define NID_undef 0
  ------------------
  |  Branch (593:7): [True: 0, False: 0]
  ------------------
  594|       |    // Built-in curves may be compared by curve name alone.
  595|      0|    return 0;
  596|      0|  }
  597|       |
  598|       |  // |a| and |b| are both custom curves. We compare the entire curve
  599|       |  // structure. If |a| or |b| is incomplete (due to legacy OpenSSL mistakes,
  600|       |  // custom curve construction is sadly done in two parts) but otherwise not the
  601|       |  // same object, we consider them always unequal.
  602|      0|  return a->meth != b->meth ||
  ------------------
  |  Branch (602:10): [True: 0, False: 0]
  ------------------
  603|      0|         a->generator == NULL ||
  ------------------
  |  Branch (603:10): [True: 0, False: 0]
  ------------------
  604|      0|         b->generator == NULL ||
  ------------------
  |  Branch (604:10): [True: 0, False: 0]
  ------------------
  605|      0|         BN_cmp(&a->order, &b->order) != 0 ||
  ------------------
  |  Branch (605:10): [True: 0, False: 0]
  ------------------
  606|      0|         BN_cmp(&a->field, &b->field) != 0 ||
  ------------------
  |  Branch (606:10): [True: 0, False: 0]
  ------------------
  607|      0|         !ec_felem_equal(a, &a->a, &b->a) ||
  ------------------
  |  Branch (607:10): [True: 0, False: 0]
  ------------------
  608|      0|         !ec_felem_equal(a, &a->b, &b->b) ||
  ------------------
  |  Branch (608:10): [True: 0, False: 0]
  ------------------
  609|      0|         !ec_GFp_simple_points_equal(a, &a->generator->raw, &b->generator->raw);
  ------------------
  |  Branch (609:10): [True: 0, False: 0]
  ------------------
  610|      0|}
EC_GROUP_get_curve_GFp:
  639|    677|                           BIGNUM *out_b, BN_CTX *ctx) {
  640|    677|  return ec_GFp_simple_group_get_curve(group, out_p, out_a, out_b);
  641|    677|}
EC_POINT_new:
  679|  1.21k|EC_POINT *EC_POINT_new(const EC_GROUP *group) {
  680|  1.21k|  if (group == NULL) {
  ------------------
  |  Branch (680:7): [True: 0, False: 1.21k]
  ------------------
  681|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  682|      0|    return NULL;
  683|      0|  }
  684|       |
  685|  1.21k|  EC_POINT *ret = OPENSSL_malloc(sizeof *ret);
  686|  1.21k|  if (ret == NULL) {
  ------------------
  |  Branch (686:7): [True: 0, False: 1.21k]
  ------------------
  687|      0|    return NULL;
  688|      0|  }
  689|       |
  690|  1.21k|  ret->group = EC_GROUP_dup(group);
  691|  1.21k|  ec_GFp_simple_point_init(&ret->raw);
  692|  1.21k|  return ret;
  693|  1.21k|}
EC_POINT_free:
  705|  1.95k|void EC_POINT_free(EC_POINT *point) {
  706|  1.95k|  ec_point_free(point, 1 /* free group */);
  707|  1.95k|}
EC_POINT_copy:
  711|    474|int EC_POINT_copy(EC_POINT *dest, const EC_POINT *src) {
  712|    474|  if (EC_GROUP_cmp(dest->group, src->group, NULL) != 0) {
  ------------------
  |  Branch (712:7): [True: 0, False: 474]
  ------------------
  713|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  714|      0|    return 0;
  715|      0|  }
  716|    474|  if (dest == src) {
  ------------------
  |  Branch (716:7): [True: 0, False: 474]
  ------------------
  717|      0|    return 1;
  718|      0|  }
  719|    474|  ec_GFp_simple_point_copy(&dest->raw, &src->raw);
  720|    474|  return 1;
  721|    474|}
EC_POINT_dup:
  723|    474|EC_POINT *EC_POINT_dup(const EC_POINT *a, const EC_GROUP *group) {
  724|    474|  if (a == NULL) {
  ------------------
  |  Branch (724:7): [True: 0, False: 474]
  ------------------
  725|      0|    return NULL;
  726|      0|  }
  727|       |
  728|    474|  EC_POINT *ret = EC_POINT_new(group);
  729|    474|  if (ret == NULL ||
  ------------------
  |  Branch (729:7): [True: 0, False: 474]
  ------------------
  730|    474|      !EC_POINT_copy(ret, a)) {
  ------------------
  |  Branch (730:7): [True: 0, False: 474]
  ------------------
  731|      0|    EC_POINT_free(ret);
  732|      0|    return NULL;
  733|      0|  }
  734|       |
  735|    474|  return ret;
  736|    474|}
ec_affine_to_jacobian:
  805|    478|                           const EC_AFFINE *p) {
  806|    478|  out->X = p->X;
  807|    478|  out->Y = p->Y;
  808|    478|  out->Z = group->one;
  809|    478|}
ec_point_set_affine_coordinates:
  826|    480|                                    const EC_FELEM *x, const EC_FELEM *y) {
  827|    480|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  828|    480|                          const EC_FELEM *b) = group->meth->felem_mul;
  829|    480|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  830|    480|      group->meth->felem_sqr;
  831|       |
  832|       |  // Check if the point is on the curve.
  833|    480|  EC_FELEM lhs, rhs;
  834|    480|  felem_sqr(group, &lhs, y);                   // lhs = y^2
  835|    480|  felem_sqr(group, &rhs, x);                   // rhs = x^2
  836|    480|  ec_felem_add(group, &rhs, &rhs, &group->a);  // rhs = x^2 + a
  837|    480|  felem_mul(group, &rhs, &rhs, x);             // rhs = x^3 + ax
  838|    480|  ec_felem_add(group, &rhs, &rhs, &group->b);  // rhs = x^3 + ax + b
  839|    480|  if (!ec_felem_equal(group, &lhs, &rhs)) {
  ------------------
  |  Branch (839:7): [True: 2, False: 478]
  ------------------
  840|      2|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_IS_NOT_ON_CURVE);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  841|       |    // In the event of an error, defend against the caller not checking the
  842|       |    // return value by setting a known safe value. Note this may not be possible
  843|       |    // if the caller is in the process of constructing an arbitrary group and
  844|       |    // the generator is missing.
  845|      2|    if (group->generator != NULL) {
  ------------------
  |  Branch (845:9): [True: 2, False: 0]
  ------------------
  846|      2|      assert(ec_felem_equal(group, &group->one, &group->generator->raw.Z));
  847|      2|      out->X = group->generator->raw.X;
  848|      2|      out->Y = group->generator->raw.Y;
  849|      2|    }
  850|      2|    return 0;
  851|      2|  }
  852|       |
  853|    478|  out->X = *x;
  854|    478|  out->Y = *y;
  855|    478|  return 1;
  856|    480|}
EC_POINT_set_affine_coordinates_GFp:
  860|    474|                                        BN_CTX *ctx) {
  861|    474|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (861:7): [True: 0, False: 474]
  ------------------
  862|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  863|      0|    return 0;
  864|      0|  }
  865|       |
  866|    474|  if (x == NULL || y == NULL) {
  ------------------
  |  Branch (866:7): [True: 0, False: 474]
  |  Branch (866:20): [True: 0, False: 474]
  ------------------
  867|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  868|      0|    return 0;
  869|      0|  }
  870|       |
  871|    474|  EC_FELEM x_felem, y_felem;
  872|    474|  EC_AFFINE affine;
  873|    474|  if (!ec_bignum_to_felem(group, &x_felem, x) ||
  ------------------
  |  Branch (873:7): [True: 0, False: 474]
  ------------------
  874|    474|      !ec_bignum_to_felem(group, &y_felem, y) ||
  ------------------
  |  Branch (874:7): [True: 0, False: 474]
  ------------------
  875|    474|      !ec_point_set_affine_coordinates(group, &affine, &x_felem, &y_felem)) {
  ------------------
  |  Branch (875:7): [True: 0, False: 474]
  ------------------
  876|       |    // In the event of an error, defend against the caller not checking the
  877|       |    // return value by setting a known safe value.
  878|      0|    ec_set_to_safe_point(group, &point->raw);
  879|      0|    return 0;
  880|      0|  }
  881|       |
  882|    474|  ec_affine_to_jacobian(group, &point->raw, &affine);
  883|    474|  return 1;
  884|    474|}
ec_set_to_safe_point:
 1224|     22|void ec_set_to_safe_point(const EC_GROUP *group, EC_JACOBIAN *out) {
 1225|     22|  if (group->generator != NULL) {
  ------------------
  |  Branch (1225:7): [True: 22, False: 0]
  ------------------
 1226|     22|    ec_GFp_simple_point_copy(out, &group->generator->raw);
 1227|     22|  } else {
 1228|       |    // The generator can be missing if the caller is in the process of
 1229|       |    // constructing an arbitrary group. In this case, we give up and use the
 1230|       |    // point at infinity.
 1231|      0|    ec_GFp_simple_point_set_to_infinity(group, out);
 1232|      0|  }
 1233|     22|}
bcm.c:OPENSSL_built_in_curves_do_init:
  218|      1|DEFINE_METHOD_FUNCTION(struct built_in_curves, OPENSSL_built_in_curves) {
  219|       |  // 1.3.132.0.35
  220|      1|  static const uint8_t kOIDP521[] = {0x2b, 0x81, 0x04, 0x00, 0x23};
  221|      1|  out->curves[0].nid = NID_secp521r1;
  ------------------
  |  | 3172|      1|#define NID_secp521r1 716
  ------------------
  222|      1|  out->curves[0].oid = kOIDP521;
  223|      1|  out->curves[0].oid_len = sizeof(kOIDP521);
  224|      1|  out->curves[0].comment = "NIST P-521";
  225|      1|  out->curves[0].param_len = 66;
  226|      1|  out->curves[0].params = kP521Params;
  227|      1|  out->curves[0].method = EC_GFp_mont_method();
  228|       |
  229|       |  // 1.3.132.0.34
  230|      1|  static const uint8_t kOIDP384[] = {0x2b, 0x81, 0x04, 0x00, 0x22};
  231|      1|  out->curves[1].nid = NID_secp384r1;
  ------------------
  |  | 3168|      1|#define NID_secp384r1 715
  ------------------
  232|      1|  out->curves[1].oid = kOIDP384;
  233|      1|  out->curves[1].oid_len = sizeof(kOIDP384);
  234|      1|  out->curves[1].comment = "NIST P-384";
  235|      1|  out->curves[1].param_len = 48;
  236|      1|  out->curves[1].params = kP384Params;
  237|      1|  out->curves[1].method = EC_GFp_mont_method();
  238|       |
  239|       |  // 1.2.840.10045.3.1.7
  240|      1|  static const uint8_t kOIDP256[] = {0x2a, 0x86, 0x48, 0xce,
  241|      1|                                     0x3d, 0x03, 0x01, 0x07};
  242|      1|  out->curves[2].nid = NID_X9_62_prime256v1;
  ------------------
  |  | 1914|      1|#define NID_X9_62_prime256v1 415
  ------------------
  243|      1|  out->curves[2].oid = kOIDP256;
  244|      1|  out->curves[2].oid_len = sizeof(kOIDP256);
  245|      1|  out->curves[2].comment = "NIST P-256";
  246|      1|  out->curves[2].param_len = 32;
  247|      1|  out->curves[2].params = kP256Params;
  248|      1|  out->curves[2].method =
  249|      1|#if !defined(OPENSSL_NO_ASM) && \
  250|      1|    (defined(OPENSSL_X86_64) || defined(OPENSSL_AARCH64)) &&   \
  251|      1|    !defined(OPENSSL_SMALL)
  252|      1|      EC_GFp_nistz256_method();
  253|       |#else
  254|       |      EC_GFp_nistp256_method();
  255|       |#endif
  256|       |
  257|       |  // 1.3.132.0.33
  258|      1|  static const uint8_t kOIDP224[] = {0x2b, 0x81, 0x04, 0x00, 0x21};
  259|      1|  out->curves[3].nid = NID_secp224r1;
  ------------------
  |  | 3160|      1|#define NID_secp224r1 713
  ------------------
  260|      1|  out->curves[3].oid = kOIDP224;
  261|      1|  out->curves[3].oid_len = sizeof(kOIDP224);
  262|      1|  out->curves[3].comment = "NIST P-224";
  263|      1|  out->curves[3].param_len = 28;
  264|      1|  out->curves[3].params = kP224Params;
  265|      1|  out->curves[3].method =
  266|      1|#if defined(BORINGSSL_HAS_UINT128) && !defined(OPENSSL_SMALL)
  267|      1|      EC_GFp_nistp224_method();
  268|       |#else
  269|       |      EC_GFp_mont_method();
  270|       |#endif
  271|      1|}
bcm.c:ec_group_set_generator:
  305|      4|                                  const BIGNUM *order) {
  306|      4|  assert(group->generator == NULL);
  307|       |
  308|      4|  if (!BN_copy(&group->order, order)) {
  ------------------
  |  Branch (308:7): [True: 0, False: 4]
  ------------------
  309|      0|    return 0;
  310|      0|  }
  311|       |  // Store the order in minimal form, so it can be used with |BN_ULONG| arrays.
  312|      4|  bn_set_minimal_width(&group->order);
  313|       |
  314|      4|  BN_MONT_CTX_free(group->order_mont);
  315|      4|  group->order_mont = BN_MONT_CTX_new_for_modulus(&group->order, NULL);
  316|      4|  if (group->order_mont == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 4]
  ------------------
  317|      0|    return 0;
  318|      0|  }
  319|       |
  320|      4|  group->field_greater_than_order = BN_cmp(&group->field, order) > 0;
  321|      4|  if (group->field_greater_than_order) {
  ------------------
  |  Branch (321:7): [True: 4, False: 0]
  ------------------
  322|      4|    BIGNUM tmp;
  323|      4|    BN_init(&tmp);
  324|      4|    int ok =
  325|      4|        BN_sub(&tmp, &group->field, order) &&
  ------------------
  |  Branch (325:9): [True: 4, False: 0]
  ------------------
  326|      4|        bn_copy_words(group->field_minus_order.words, group->field.width, &tmp);
  ------------------
  |  Branch (326:9): [True: 4, False: 0]
  ------------------
  327|      4|    BN_free(&tmp);
  328|      4|    if (!ok) {
  ------------------
  |  Branch (328:9): [True: 0, False: 4]
  ------------------
  329|      0|      return 0;
  330|      0|    }
  331|      4|  }
  332|       |
  333|      4|  group->generator = EC_POINT_new(group);
  334|      4|  if (group->generator == NULL) {
  ------------------
  |  Branch (334:7): [True: 0, False: 4]
  ------------------
  335|      0|    return 0;
  336|      0|  }
  337|      4|  ec_affine_to_jacobian(group, &group->generator->raw, generator);
  338|      4|  assert(ec_felem_equal(group, &group->one, &group->generator->raw.Z));
  339|       |
  340|       |  // Avoid a reference cycle. |group->generator| does not maintain an owning
  341|       |  // pointer to |group|.
  342|      4|  int is_zero = CRYPTO_refcount_dec_and_test_zero(&group->references);
  343|       |
  344|      4|  assert(!is_zero);
  345|      4|  (void)is_zero;
  346|      4|  return 1;
  347|      4|}
bcm.c:ec_group_new_from_data:
  442|      4|static EC_GROUP *ec_group_new_from_data(const struct built_in_curve *curve) {
  443|      4|  EC_GROUP *group = NULL;
  444|      4|  BIGNUM *p = NULL, *a = NULL, *b = NULL, *order = NULL;
  445|      4|  int ok = 0;
  446|       |
  447|      4|  BN_CTX *ctx = BN_CTX_new();
  448|      4|  if (ctx == NULL) {
  ------------------
  |  Branch (448:7): [True: 0, False: 4]
  ------------------
  449|      0|    goto err;
  450|      0|  }
  451|       |
  452|      4|  const unsigned param_len = curve->param_len;
  453|      4|  const uint8_t *params = curve->params;
  454|       |
  455|      4|  if (!(p = BN_bin2bn(params + 0 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (455:7): [True: 0, False: 4]
  ------------------
  456|      4|      !(a = BN_bin2bn(params + 1 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (456:7): [True: 0, False: 4]
  ------------------
  457|      4|      !(b = BN_bin2bn(params + 2 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (457:7): [True: 0, False: 4]
  ------------------
  458|      4|      !(order = BN_bin2bn(params + 5 * param_len, param_len, NULL))) {
  ------------------
  |  Branch (458:7): [True: 0, False: 4]
  ------------------
  459|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  460|      0|    goto err;
  461|      0|  }
  462|       |
  463|      4|  group = ec_group_new(curve->method);
  464|      4|  if (group == NULL ||
  ------------------
  |  Branch (464:7): [True: 0, False: 4]
  ------------------
  465|      4|      !group->meth->group_set_curve(group, p, a, b, ctx)) {
  ------------------
  |  Branch (465:7): [True: 0, False: 4]
  ------------------
  466|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_EC_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  467|      0|    goto err;
  468|      0|  }
  469|       |
  470|      4|  EC_AFFINE G;
  471|      4|  EC_FELEM x, y;
  472|      4|  if (!ec_felem_from_bytes(group, &x, params + 3 * param_len, param_len) ||
  ------------------
  |  Branch (472:7): [True: 0, False: 4]
  ------------------
  473|      4|      !ec_felem_from_bytes(group, &y, params + 4 * param_len, param_len) ||
  ------------------
  |  Branch (473:7): [True: 0, False: 4]
  ------------------
  474|      4|      !ec_point_set_affine_coordinates(group, &G, &x, &y)) {
  ------------------
  |  Branch (474:7): [True: 0, False: 4]
  ------------------
  475|      0|    goto err;
  476|      0|  }
  477|       |
  478|      4|  if (!ec_group_set_generator(group, &G, order)) {
  ------------------
  |  Branch (478:7): [True: 0, False: 4]
  ------------------
  479|      0|    goto err;
  480|      0|  }
  481|       |
  482|      4|  ok = 1;
  483|       |
  484|      4|err:
  485|      4|  if (!ok) {
  ------------------
  |  Branch (485:7): [True: 0, False: 4]
  ------------------
  486|      0|    EC_GROUP_free(group);
  487|      0|    group = NULL;
  488|      0|  }
  489|      4|  BN_CTX_free(ctx);
  490|      4|  BN_free(p);
  491|      4|  BN_free(a);
  492|      4|  BN_free(b);
  493|      4|  BN_free(order);
  494|      4|  return group;
  495|      4|}
bcm.c:ec_point_free:
  695|  1.95k|static void ec_point_free(EC_POINT *point, int free_group) {
  696|  1.95k|  if (!point) {
  ------------------
  |  Branch (696:7): [True: 738, False: 1.21k]
  ------------------
  697|    738|    return;
  698|    738|  }
  699|  1.21k|  if (free_group) {
  ------------------
  |  Branch (699:7): [True: 1.21k, False: 0]
  ------------------
  700|  1.21k|    EC_GROUP_free(point->group);
  701|  1.21k|  }
  702|  1.21k|  OPENSSL_free(point);
  703|  1.21k|}

EC_KEY_new:
  106|    738|EC_KEY *EC_KEY_new(void) { return EC_KEY_new_method(NULL); }
EC_KEY_new_method:
  108|    738|EC_KEY *EC_KEY_new_method(const ENGINE *engine) {
  109|    738|  EC_KEY *ret = OPENSSL_malloc(sizeof(EC_KEY));
  110|    738|  if (ret == NULL) {
  ------------------
  |  Branch (110:7): [True: 0, False: 738]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|    738|  OPENSSL_memset(ret, 0, sizeof(EC_KEY));
  115|       |
  116|    738|  if (engine) {
  ------------------
  |  Branch (116:7): [True: 0, False: 738]
  ------------------
  117|      0|    ret->ecdsa_meth = ENGINE_get_ECDSA_method(engine);
  118|      0|  }
  119|    738|  if (ret->ecdsa_meth) {
  ------------------
  |  Branch (119:7): [True: 0, False: 738]
  ------------------
  120|      0|    METHOD_ref(ret->ecdsa_meth);
  121|      0|  }
  122|       |
  123|    738|  ret->conv_form = POINT_CONVERSION_UNCOMPRESSED;
  124|    738|  ret->references = 1;
  125|       |
  126|    738|  CRYPTO_new_ex_data(&ret->ex_data);
  127|       |
  128|    738|  if (ret->ecdsa_meth && ret->ecdsa_meth->init && !ret->ecdsa_meth->init(ret)) {
  ------------------
  |  Branch (128:7): [True: 0, False: 738]
  |  Branch (128:26): [True: 0, False: 0]
  |  Branch (128:51): [True: 0, False: 0]
  ------------------
  129|      0|    CRYPTO_free_ex_data(g_ec_ex_data_class_bss_get(), ret, &ret->ex_data);
  130|      0|    if (ret->ecdsa_meth) {
  ------------------
  |  Branch (130:9): [True: 0, False: 0]
  ------------------
  131|      0|      METHOD_unref(ret->ecdsa_meth);
  132|      0|    }
  133|      0|    OPENSSL_free(ret);
  134|      0|    return NULL;
  135|      0|  }
  136|       |
  137|    738|  return ret;
  138|    738|}
EC_KEY_free:
  153|  1.03k|void EC_KEY_free(EC_KEY *r) {
  154|  1.03k|  if (r == NULL) {
  ------------------
  |  Branch (154:7): [True: 294, False: 738]
  ------------------
  155|    294|    return;
  156|    294|  }
  157|       |
  158|    738|  if (!CRYPTO_refcount_dec_and_test_zero(&r->references)) {
  ------------------
  |  Branch (158:7): [True: 0, False: 738]
  ------------------
  159|      0|    return;
  160|      0|  }
  161|       |
  162|    738|  if (r->ecdsa_meth) {
  ------------------
  |  Branch (162:7): [True: 0, False: 738]
  ------------------
  163|      0|    if (r->ecdsa_meth->finish) {
  ------------------
  |  Branch (163:9): [True: 0, False: 0]
  ------------------
  164|      0|      r->ecdsa_meth->finish(r);
  165|      0|    }
  166|      0|    METHOD_unref(r->ecdsa_meth);
  167|      0|  }
  168|       |
  169|    738|  EC_GROUP_free(r->group);
  170|    738|  EC_POINT_free(r->pub_key);
  171|    738|  ec_wrapped_scalar_free(r->priv_key);
  172|       |
  173|    738|  CRYPTO_free_ex_data(g_ec_ex_data_class_bss_get(), r, &r->ex_data);
  174|       |
  175|    738|  OPENSSL_free(r);
  176|    738|}
EC_KEY_set_group:
  215|    738|int EC_KEY_set_group(EC_KEY *key, const EC_GROUP *group) {
  216|       |  // If |key| already has a group, it is an error to switch to another one.
  217|    738|  if (key->group != NULL) {
  ------------------
  |  Branch (217:7): [True: 0, False: 738]
  ------------------
  218|      0|    if (EC_GROUP_cmp(key->group, group, NULL) != 0) {
  ------------------
  |  Branch (218:9): [True: 0, False: 0]
  ------------------
  219|      0|      OPENSSL_PUT_ERROR(EC, EC_R_GROUP_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  220|      0|      return 0;
  221|      0|    }
  222|      0|    return 1;
  223|      0|  }
  224|       |
  225|    738|  assert(key->priv_key == NULL);
  226|    738|  assert(key->pub_key == NULL);
  227|       |
  228|    738|  EC_GROUP_free(key->group);
  229|    738|  key->group = EC_GROUP_dup(group);
  230|    738|  return key->group != NULL;
  231|    738|}
EC_KEY_set_public_key:
  262|    474|int EC_KEY_set_public_key(EC_KEY *key, const EC_POINT *pub_key) {
  263|    474|  if (key->group == NULL) {
  ------------------
  |  Branch (263:7): [True: 0, False: 474]
  ------------------
  264|      0|    OPENSSL_PUT_ERROR(EC, EC_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  265|      0|    return 0;
  266|      0|  }
  267|       |
  268|    474|  if (pub_key != NULL && EC_GROUP_cmp(key->group, pub_key->group, NULL) != 0) {
  ------------------
  |  Branch (268:7): [True: 474, False: 0]
  |  Branch (268:26): [True: 0, False: 474]
  ------------------
  269|      0|    OPENSSL_PUT_ERROR(EC, EC_R_GROUP_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  270|      0|    return 0;
  271|      0|  }
  272|       |
  273|    474|  EC_POINT_free(key->pub_key);
  274|    474|  key->pub_key = EC_POINT_dup(pub_key, key->group);
  275|    474|  return (key->pub_key == NULL) ? 0 : 1;
  ------------------
  |  Branch (275:10): [True: 0, False: 474]
  ------------------
  276|    474|}
EC_KEY_oct2key:
  395|    738|int EC_KEY_oct2key(EC_KEY *key, const uint8_t *in, size_t len, BN_CTX *ctx) {
  396|    738|  if (key->group == NULL) {
  ------------------
  |  Branch (396:7): [True: 0, False: 738]
  ------------------
  397|      0|    OPENSSL_PUT_ERROR(EC, EC_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  398|      0|    return 0;
  399|      0|  }
  400|       |
  401|    738|  EC_POINT *point = EC_POINT_new(key->group);
  402|    738|  int ok = point != NULL &&
  ------------------
  |  Branch (402:12): [True: 738, False: 0]
  ------------------
  403|    738|           EC_POINT_oct2point(key->group, point, in, len, ctx) &&
  ------------------
  |  Branch (403:12): [True: 474, False: 264]
  ------------------
  404|    738|           EC_KEY_set_public_key(key, point);
  ------------------
  |  Branch (404:12): [True: 474, False: 0]
  ------------------
  405|    738|  EC_POINT_free(point);
  406|    738|  return ok;
  407|    738|}
bcm.c:ec_wrapped_scalar_free:
  102|    738|static void ec_wrapped_scalar_free(EC_WRAPPED_SCALAR *scalar) {
  103|    738|  OPENSSL_free(scalar);
  104|    738|}

ec_GFp_mont_group_init:
   79|      3|int ec_GFp_mont_group_init(EC_GROUP *group) {
   80|      3|  int ok;
   81|       |
   82|      3|  ok = ec_GFp_simple_group_init(group);
   83|      3|  group->mont = NULL;
   84|      3|  return ok;
   85|      3|}
ec_GFp_mont_group_set_curve:
   94|      3|                                const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
   95|      3|  BN_MONT_CTX_free(group->mont);
   96|      3|  group->mont = BN_MONT_CTX_new_for_modulus(p, ctx);
   97|      3|  if (group->mont == NULL) {
  ------------------
  |  Branch (97:7): [True: 0, False: 3]
  ------------------
   98|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   99|      0|    return 0;
  100|      0|  }
  101|       |
  102|      3|  if (!ec_GFp_simple_group_set_curve(group, p, a, b, ctx)) {
  ------------------
  |  Branch (102:7): [True: 0, False: 3]
  ------------------
  103|      0|    BN_MONT_CTX_free(group->mont);
  104|      0|    group->mont = NULL;
  105|      0|    return 0;
  106|      0|  }
  107|       |
  108|      3|  return 1;
  109|      3|}
ec_GFp_mont_felem_mul:
  131|    129|                           const EC_FELEM *a, const EC_FELEM *b) {
  132|    129|  bn_mod_mul_montgomery_small(r->words, a->words, b->words, group->field.width,
  133|    129|                              group->mont);
  134|    129|}
ec_GFp_mont_felem_sqr:
  137|    258|                           const EC_FELEM *a) {
  138|    258|  bn_mod_mul_montgomery_small(r->words, a->words, a->words, group->field.width,
  139|    258|                              group->mont);
  140|    258|}
ec_GFp_mont_felem_to_bytes:
  143|    376|                                size_t *out_len, const EC_FELEM *in) {
  144|    376|  EC_FELEM tmp;
  145|    376|  ec_GFp_mont_felem_from_montgomery(group, &tmp, in);
  146|    376|  ec_GFp_simple_felem_to_bytes(group, out, out_len, &tmp);
  147|    376|}
ec_GFp_mont_felem_from_bytes:
  150|    270|                                 const uint8_t *in, size_t len) {
  151|    270|  if (!ec_GFp_simple_felem_from_bytes(group, out, in, len)) {
  ------------------
  |  Branch (151:7): [True: 2, False: 268]
  ------------------
  152|      2|    return 0;
  153|      2|  }
  154|       |
  155|    268|  ec_GFp_mont_felem_to_montgomery(group, out, out);
  156|    268|  return 1;
  157|    270|}
bcm.c:ec_GFp_mont_felem_from_montgomery:
  119|    376|                                              const EC_FELEM *in) {
  120|    376|  bn_from_montgomery_small(out->words, group->field.width, in->words,
  121|    376|                           group->field.width, group->mont);
  122|    376|}
bcm.c:ec_GFp_mont_felem_to_montgomery:
  112|    268|                                            EC_FELEM *out, const EC_FELEM *in) {
  113|    268|  bn_to_montgomery_small(out->words, in->words, group->field.width,
  114|    268|                         group->mont);
  115|    268|}
bcm.c:EC_GFp_mont_method_do_init:
  501|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_mont_method) {
  502|      1|  out->group_init = ec_GFp_mont_group_init;
  503|      1|  out->group_finish = ec_GFp_mont_group_finish;
  504|      1|  out->group_set_curve = ec_GFp_mont_group_set_curve;
  505|      1|  out->point_get_affine_coordinates = ec_GFp_mont_point_get_affine_coordinates;
  506|      1|  out->jacobian_to_affine_batch = ec_GFp_mont_jacobian_to_affine_batch;
  507|      1|  out->add = ec_GFp_mont_add;
  508|      1|  out->dbl = ec_GFp_mont_dbl;
  509|      1|  out->mul = ec_GFp_mont_mul;
  510|      1|  out->mul_base = ec_GFp_mont_mul_base;
  511|      1|  out->mul_batch = ec_GFp_mont_mul_batch;
  512|      1|  out->mul_public_batch = ec_GFp_mont_mul_public_batch;
  513|      1|  out->init_precomp = ec_GFp_mont_init_precomp;
  514|      1|  out->mul_precomp = ec_GFp_mont_mul_precomp;
  515|      1|  out->felem_mul = ec_GFp_mont_felem_mul;
  516|      1|  out->felem_sqr = ec_GFp_mont_felem_sqr;
  517|      1|  out->felem_to_bytes = ec_GFp_mont_felem_to_bytes;
  518|      1|  out->felem_from_bytes = ec_GFp_mont_felem_from_bytes;
  519|      1|  out->felem_reduce = ec_GFp_mont_felem_reduce;
  520|      1|  out->felem_exp = ec_GFp_mont_felem_exp;
  521|      1|  out->scalar_inv0_montgomery = ec_simple_scalar_inv0_montgomery;
  522|      1|  out->scalar_to_montgomery_inv_vartime =
  523|      1|      ec_simple_scalar_to_montgomery_inv_vartime;
  524|      1|  out->cmp_x_coordinate = ec_GFp_mont_cmp_x_coordinate;
  525|      1|}

ec_bignum_to_felem:
   26|    960|int ec_bignum_to_felem(const EC_GROUP *group, EC_FELEM *out, const BIGNUM *in) {
   27|    960|  uint8_t bytes[EC_MAX_BYTES];
   28|    960|  size_t len = BN_num_bytes(&group->field);
   29|    960|  assert(sizeof(bytes) >= len);
   30|    960|  if (BN_is_negative(in) ||
  ------------------
  |  Branch (30:7): [True: 0, False: 960]
  ------------------
   31|    960|      BN_cmp(in, &group->field) >= 0 ||
  ------------------
  |  Branch (31:7): [True: 0, False: 960]
  ------------------
   32|    960|      !BN_bn2bin_padded(bytes, len, in)) {
  ------------------
  |  Branch (32:7): [True: 0, False: 960]
  ------------------
   33|      0|    OPENSSL_PUT_ERROR(EC, EC_R_COORDINATES_OUT_OF_RANGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|      0|    return 0;
   35|      0|  }
   36|       |
   37|    960|  return ec_felem_from_bytes(group, out, bytes, len);
   38|    960|}
ec_felem_to_bignum:
   40|  1.35k|int ec_felem_to_bignum(const EC_GROUP *group, BIGNUM *out, const EC_FELEM *in) {
   41|  1.35k|  uint8_t bytes[EC_MAX_BYTES];
   42|  1.35k|  size_t len;
   43|  1.35k|  ec_felem_to_bytes(group, bytes, &len, in);
   44|  1.35k|  return BN_bin2bn(bytes, len, out) != NULL;
   45|  1.35k|}
ec_felem_to_bytes:
   48|  1.35k|                       const EC_FELEM *in) {
   49|  1.35k|  group->meth->felem_to_bytes(group, out, out_len, in);
   50|  1.35k|}
ec_felem_from_bytes:
   53|    976|                        size_t len) {
   54|    976|  return group->meth->felem_from_bytes(group, out, in, len);
   55|    976|}
ec_felem_add:
   70|    960|                  const EC_FELEM *b) {
   71|    960|  EC_FELEM tmp;
   72|    960|  bn_mod_add_words(out->words, a->words, b->words, group->field.d, tmp.words,
   73|    960|                   group->field.width);
   74|    960|}
ec_felem_equal:
   97|    486|                   const EC_FELEM *b) {
   98|    486|  return CRYPTO_memcmp(a->words, b->words,
   99|    486|                       group->field.width * sizeof(BN_ULONG)) == 0;
  100|    486|}

ec_point_from_uncompressed:
  119|     22|                               const uint8_t *in, size_t len) {
  120|     22|  const size_t field_len = BN_num_bytes(&group->field);
  121|     22|  if (len != 1 + 2 * field_len || in[0] != POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (121:7): [True: 17, False: 5]
  |  Branch (121:35): [True: 0, False: 5]
  ------------------
  122|     17|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|     17|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  123|     17|    return 0;
  124|     17|  }
  125|       |
  126|      5|  EC_FELEM x, y;
  127|      5|  if (!ec_felem_from_bytes(group, &x, in + 1, field_len) ||
  ------------------
  |  Branch (127:7): [True: 2, False: 3]
  ------------------
  128|      5|      !ec_felem_from_bytes(group, &y, in + 1 + field_len, field_len) ||
  ------------------
  |  Branch (128:7): [True: 1, False: 2]
  ------------------
  129|      5|      !ec_point_set_affine_coordinates(group, out, &x, &y)) {
  ------------------
  |  Branch (129:7): [True: 2, False: 0]
  ------------------
  130|      5|    return 0;
  131|      5|  }
  132|       |
  133|      0|  return 1;
  134|      5|}
EC_POINT_oct2point:
  203|    738|                       const uint8_t *buf, size_t len, BN_CTX *ctx) {
  204|    738|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (204:7): [True: 0, False: 738]
  ------------------
  205|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  206|      0|    return 0;
  207|      0|  }
  208|    738|  return ec_GFp_simple_oct2point(group, point, buf, len, ctx);
  209|    738|}
EC_POINT_set_compressed_coordinates_GFp:
  257|    677|                                            int y_bit, BN_CTX *ctx) {
  258|    677|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (258:7): [True: 0, False: 677]
  ------------------
  259|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  260|      0|    return 0;
  261|      0|  }
  262|       |
  263|    677|  if (BN_is_negative(x) || BN_cmp(x, &group->field) >= 0) {
  ------------------
  |  Branch (263:7): [True: 0, False: 677]
  |  Branch (263:28): [True: 0, False: 677]
  ------------------
  264|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_COMPRESSED_POINT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  265|      0|    return 0;
  266|      0|  }
  267|       |
  268|    677|  BN_CTX *new_ctx = NULL;
  269|    677|  int ret = 0;
  270|       |
  271|    677|  ERR_clear_error();
  272|       |
  273|    677|  if (ctx == NULL) {
  ------------------
  |  Branch (273:7): [True: 0, False: 677]
  ------------------
  274|      0|    ctx = new_ctx = BN_CTX_new();
  275|      0|    if (ctx == NULL) {
  ------------------
  |  Branch (275:9): [True: 0, False: 0]
  ------------------
  276|      0|      return 0;
  277|      0|    }
  278|      0|  }
  279|       |
  280|    677|  y_bit = (y_bit != 0);
  281|       |
  282|    677|  BN_CTX_start(ctx);
  283|    677|  BIGNUM *tmp1 = BN_CTX_get(ctx);
  284|    677|  BIGNUM *tmp2 = BN_CTX_get(ctx);
  285|    677|  BIGNUM *a = BN_CTX_get(ctx);
  286|    677|  BIGNUM *b = BN_CTX_get(ctx);
  287|    677|  BIGNUM *y = BN_CTX_get(ctx);
  288|    677|  if (y == NULL ||
  ------------------
  |  Branch (288:7): [True: 0, False: 677]
  ------------------
  289|    677|      !EC_GROUP_get_curve_GFp(group, NULL, a, b, ctx)) {
  ------------------
  |  Branch (289:7): [True: 0, False: 677]
  ------------------
  290|      0|    goto err;
  291|      0|  }
  292|       |
  293|       |  // Recover y.  We have a Weierstrass equation
  294|       |  //     y^2 = x^3 + a*x + b,
  295|       |  // so  y  is one of the square roots of  x^3 + a*x + b.
  296|       |
  297|       |  // tmp1 := x^3
  298|    677|  if (!BN_mod_sqr(tmp2, x, &group->field, ctx) ||
  ------------------
  |  Branch (298:7): [True: 0, False: 677]
  ------------------
  299|    677|      !BN_mod_mul(tmp1, tmp2, x, &group->field, ctx)) {
  ------------------
  |  Branch (299:7): [True: 0, False: 677]
  ------------------
  300|      0|    goto err;
  301|      0|  }
  302|       |
  303|       |  // tmp1 := tmp1 + a*x
  304|    677|  if (group->a_is_minus3) {
  ------------------
  |  Branch (304:7): [True: 677, False: 0]
  ------------------
  305|    677|    if (!bn_mod_lshift1_consttime(tmp2, x, &group->field, ctx) ||
  ------------------
  |  Branch (305:9): [True: 0, False: 677]
  ------------------
  306|    677|        !bn_mod_add_consttime(tmp2, tmp2, x, &group->field, ctx) ||
  ------------------
  |  Branch (306:9): [True: 0, False: 677]
  ------------------
  307|    677|        !bn_mod_sub_consttime(tmp1, tmp1, tmp2, &group->field, ctx)) {
  ------------------
  |  Branch (307:9): [True: 0, False: 677]
  ------------------
  308|      0|      goto err;
  309|      0|    }
  310|    677|  } else {
  311|      0|    if (!BN_mod_mul(tmp2, a, x, &group->field, ctx) ||
  ------------------
  |  Branch (311:9): [True: 0, False: 0]
  ------------------
  312|      0|        !bn_mod_add_consttime(tmp1, tmp1, tmp2, &group->field, ctx)) {
  ------------------
  |  Branch (312:9): [True: 0, False: 0]
  ------------------
  313|      0|      goto err;
  314|      0|    }
  315|      0|  }
  316|       |
  317|       |  // tmp1 := tmp1 + b
  318|    677|  if (!bn_mod_add_consttime(tmp1, tmp1, b, &group->field, ctx)) {
  ------------------
  |  Branch (318:7): [True: 0, False: 677]
  ------------------
  319|      0|    goto err;
  320|      0|  }
  321|       |
  322|    677|  if (!BN_mod_sqrt(y, tmp1, &group->field, ctx)) {
  ------------------
  |  Branch (322:7): [True: 203, False: 474]
  ------------------
  323|    203|    uint32_t err = ERR_peek_last_error();
  324|    203|    if (ERR_GET_LIB(err) == ERR_LIB_BN &&
  ------------------
  |  Branch (324:9): [True: 203, False: 0]
  ------------------
  325|    203|        ERR_GET_REASON(err) == BN_R_NOT_A_SQUARE) {
  ------------------
  |  | 1076|    203|#define BN_R_NOT_A_SQUARE 110
  ------------------
  |  Branch (325:9): [True: 203, False: 0]
  ------------------
  326|    203|      ERR_clear_error();
  327|    203|      OPENSSL_PUT_ERROR(EC, EC_R_INVALID_COMPRESSED_POINT);
  ------------------
  |  |  441|    203|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|    203|    } else {
  329|      0|      OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  330|      0|    }
  331|    203|    goto err;
  332|    203|  }
  333|       |
  334|    474|  if (y_bit != BN_is_odd(y)) {
  ------------------
  |  Branch (334:7): [True: 285, False: 189]
  ------------------
  335|    285|    if (BN_is_zero(y)) {
  ------------------
  |  Branch (335:9): [True: 0, False: 285]
  ------------------
  336|      0|      OPENSSL_PUT_ERROR(EC, EC_R_INVALID_COMPRESSION_BIT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  337|      0|      goto err;
  338|      0|    }
  339|    285|    if (!BN_usub(y, &group->field, y)) {
  ------------------
  |  Branch (339:9): [True: 0, False: 285]
  ------------------
  340|      0|      goto err;
  341|      0|    }
  342|    285|  }
  343|    474|  if (y_bit != BN_is_odd(y)) {
  ------------------
  |  Branch (343:7): [True: 0, False: 474]
  ------------------
  344|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|    goto err;
  346|      0|  }
  347|       |
  348|    474|  if (!EC_POINT_set_affine_coordinates_GFp(group, point, x, y, ctx)) {
  ------------------
  |  Branch (348:7): [True: 0, False: 474]
  ------------------
  349|      0|    goto err;
  350|      0|  }
  351|       |
  352|    474|  ret = 1;
  353|       |
  354|    677|err:
  355|    677|  BN_CTX_end(ctx);
  356|    677|  BN_CTX_free(new_ctx);
  357|    677|  return ret;
  358|    474|}
bcm.c:ec_GFp_simple_oct2point:
  138|    738|                                   BN_CTX *ctx) {
  139|    738|  if (len == 0) {
  ------------------
  |  Branch (139:7): [True: 2, False: 736]
  ------------------
  140|      2|    OPENSSL_PUT_ERROR(EC, EC_R_BUFFER_TOO_SMALL);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      2|    return 0;
  142|      2|  }
  143|       |
  144|    736|  point_conversion_form_t form = buf[0];
  145|    736|  if (form == POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (145:7): [True: 22, False: 714]
  ------------------
  146|     22|    EC_AFFINE affine;
  147|     22|    if (!ec_point_from_uncompressed(group, &affine, buf, len)) {
  ------------------
  |  Branch (147:9): [True: 22, False: 0]
  ------------------
  148|       |      // In the event of an error, defend against the caller not checking the
  149|       |      // return value by setting a known safe value.
  150|     22|      ec_set_to_safe_point(group, &point->raw);
  151|     22|      return 0;
  152|     22|    }
  153|      0|    ec_affine_to_jacobian(group, &point->raw, &affine);
  154|      0|    return 1;
  155|     22|  }
  156|       |
  157|    714|  const int y_bit = form & 1;
  158|    714|  const size_t field_len = BN_num_bytes(&group->field);
  159|    714|  form = form & ~1u;
  160|    714|  if (form != POINT_CONVERSION_COMPRESSED ||
  ------------------
  |  Branch (160:7): [True: 10, False: 704]
  ------------------
  161|    714|      len != 1 /* type byte */ + field_len) {
  ------------------
  |  Branch (161:7): [True: 25, False: 679]
  ------------------
  162|     35|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|     35|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|     35|    return 0;
  164|     35|  }
  165|       |
  166|       |  // TODO(davidben): Integrate compressed coordinates with the lower-level EC
  167|       |  // abstractions. This requires a way to compute square roots, which is tricky
  168|       |  // for primes which are not 3 (mod 4), namely P-224 and custom curves. P-224's
  169|       |  // prime is particularly inconvenient for compressed coordinates. See
  170|       |  // https://cr.yp.to/papers/sqroot.pdf
  171|    679|  BN_CTX *new_ctx = NULL;
  172|    679|  if (ctx == NULL) {
  ------------------
  |  Branch (172:7): [True: 679, False: 0]
  ------------------
  173|    679|    ctx = new_ctx = BN_CTX_new();
  174|    679|    if (ctx == NULL) {
  ------------------
  |  Branch (174:9): [True: 0, False: 679]
  ------------------
  175|      0|      return 0;
  176|      0|    }
  177|    679|  }
  178|       |
  179|    679|  int ret = 0;
  180|    679|  BN_CTX_start(ctx);
  181|    679|  BIGNUM *x = BN_CTX_get(ctx);
  182|    679|  if (x == NULL || !BN_bin2bn(buf + 1, field_len, x)) {
  ------------------
  |  Branch (182:7): [True: 0, False: 679]
  |  Branch (182:20): [True: 0, False: 679]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|    679|  if (BN_ucmp(x, &group->field) >= 0) {
  ------------------
  |  Branch (185:7): [True: 2, False: 677]
  ------------------
  186|      2|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  187|      2|    goto err;
  188|      2|  }
  189|       |
  190|    677|  if (!EC_POINT_set_compressed_coordinates_GFp(group, point, x, y_bit, ctx)) {
  ------------------
  |  Branch (190:7): [True: 203, False: 474]
  ------------------
  191|    203|    goto err;
  192|    203|  }
  193|       |
  194|    474|  ret = 1;
  195|       |
  196|    679|err:
  197|    679|  BN_CTX_end(ctx);
  198|    679|  BN_CTX_free(new_ctx);
  199|    679|  return ret;
  200|    474|}

bcm.c:EC_GFp_nistp224_method_do_init:
 1144|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_nistp224_method) {
 1145|      1|  out->group_init = ec_GFp_simple_group_init;
 1146|      1|  out->group_finish = ec_GFp_simple_group_finish;
 1147|      1|  out->group_set_curve = ec_GFp_simple_group_set_curve;
 1148|      1|  out->point_get_affine_coordinates =
 1149|      1|      ec_GFp_nistp224_point_get_affine_coordinates;
 1150|      1|  out->add = ec_GFp_nistp224_add;
 1151|      1|  out->dbl = ec_GFp_nistp224_dbl;
 1152|      1|  out->mul = ec_GFp_nistp224_point_mul;
 1153|      1|  out->mul_base = ec_GFp_nistp224_point_mul_base;
 1154|      1|  out->mul_public = ec_GFp_nistp224_point_mul_public;
 1155|      1|  out->felem_mul = ec_GFp_nistp224_felem_mul;
 1156|      1|  out->felem_sqr = ec_GFp_nistp224_felem_sqr;
 1157|      1|  out->felem_to_bytes = ec_GFp_simple_felem_to_bytes;
 1158|      1|  out->felem_from_bytes = ec_GFp_simple_felem_from_bytes;
 1159|      1|  out->scalar_inv0_montgomery = ec_simple_scalar_inv0_montgomery;
 1160|      1|  out->scalar_to_montgomery_inv_vartime =
 1161|      1|      ec_simple_scalar_to_montgomery_inv_vartime;
 1162|      1|  out->cmp_x_coordinate = ec_GFp_simple_cmp_x_coordinate;
 1163|      1|}
bcm.c:p224_generic_to_felem:
  181|  1.40k|static void p224_generic_to_felem(p224_felem out, const EC_FELEM *in) {
  182|       |  // |p224_felem|'s minimal representation uses four 56-bit words. |EC_FELEM|
  183|       |  // uses four 64-bit words. (The top-most word only has 32 bits.)
  184|  1.40k|  out[0] = in->words[0] & 0x00ffffffffffffff;
  185|  1.40k|  out[1] = ((in->words[0] >> 56) | (in->words[1] << 8)) & 0x00ffffffffffffff;
  186|  1.40k|  out[2] = ((in->words[1] >> 48) | (in->words[2] << 16)) & 0x00ffffffffffffff;
  187|  1.40k|  out[3] = ((in->words[2] >> 40) | (in->words[3] << 24)) & 0x00ffffffffffffff;
  188|  1.40k|}
bcm.c:p224_felem_square:
  364|    702|static void p224_felem_square(p224_widefelem out, const p224_felem in) {
  365|    702|  p224_limb tmp0, tmp1, tmp2;
  366|    702|  tmp0 = 2 * in[0];
  367|    702|  tmp1 = 2 * in[1];
  368|    702|  tmp2 = 2 * in[2];
  369|    702|  out[0] = ((p224_widelimb)in[0]) * in[0];
  370|    702|  out[1] = ((p224_widelimb)in[0]) * tmp1;
  371|    702|  out[2] = ((p224_widelimb)in[0]) * tmp2 + ((p224_widelimb)in[1]) * in[1];
  372|    702|  out[3] = ((p224_widelimb)in[3]) * tmp0 + ((p224_widelimb)in[1]) * tmp2;
  373|    702|  out[4] = ((p224_widelimb)in[3]) * tmp1 + ((p224_widelimb)in[2]) * in[2];
  374|    702|  out[5] = ((p224_widelimb)in[3]) * tmp2;
  375|    702|  out[6] = ((p224_widelimb)in[3]) * in[3];
  376|    702|}
bcm.c:p224_felem_reduce:
  396|  1.05k|static void p224_felem_reduce(p224_felem out, const p224_widefelem in) {
  397|  1.05k|  static const p224_widelimb two127p15 =
  398|  1.05k|      (((p224_widelimb)1) << 127) + (((p224_widelimb)1) << 15);
  399|  1.05k|  static const p224_widelimb two127m71 =
  400|  1.05k|      (((p224_widelimb)1) << 127) - (((p224_widelimb)1) << 71);
  401|  1.05k|  static const p224_widelimb two127m71m55 = (((p224_widelimb)1) << 127) -
  402|  1.05k|                                            (((p224_widelimb)1) << 71) -
  403|  1.05k|                                            (((p224_widelimb)1) << 55);
  404|  1.05k|  p224_widelimb output[5];
  405|       |
  406|       |  // Add 0 mod 2^224-2^96+1 to ensure all differences are positive
  407|  1.05k|  output[0] = in[0] + two127p15;
  408|  1.05k|  output[1] = in[1] + two127m71m55;
  409|  1.05k|  output[2] = in[2] + two127m71;
  410|  1.05k|  output[3] = in[3];
  411|  1.05k|  output[4] = in[4];
  412|       |
  413|       |  // Eliminate in[4], in[5], in[6]
  414|  1.05k|  output[4] += in[6] >> 16;
  415|  1.05k|  output[3] += (in[6] & 0xffff) << 40;
  416|  1.05k|  output[2] -= in[6];
  417|       |
  418|  1.05k|  output[3] += in[5] >> 16;
  419|  1.05k|  output[2] += (in[5] & 0xffff) << 40;
  420|  1.05k|  output[1] -= in[5];
  421|       |
  422|  1.05k|  output[2] += output[4] >> 16;
  423|  1.05k|  output[1] += (output[4] & 0xffff) << 40;
  424|  1.05k|  output[0] -= output[4];
  425|       |
  426|       |  // Carry 2 -> 3 -> 4
  427|  1.05k|  output[3] += output[2] >> 56;
  428|  1.05k|  output[2] &= 0x00ffffffffffffff;
  429|       |
  430|  1.05k|  output[4] = output[3] >> 56;
  431|  1.05k|  output[3] &= 0x00ffffffffffffff;
  432|       |
  433|       |  // Now output[2] < 2^56, output[3] < 2^56, output[4] < 2^72
  434|       |
  435|       |  // Eliminate output[4]
  436|  1.05k|  output[2] += output[4] >> 16;
  437|       |  // output[2] < 2^56 + 2^56 = 2^57
  438|  1.05k|  output[1] += (output[4] & 0xffff) << 40;
  439|  1.05k|  output[0] -= output[4];
  440|       |
  441|       |  // Carry 0 -> 1 -> 2 -> 3
  442|  1.05k|  output[1] += output[0] >> 56;
  443|  1.05k|  out[0] = output[0] & 0x00ffffffffffffff;
  444|       |
  445|  1.05k|  output[2] += output[1] >> 56;
  446|       |  // output[2] < 2^57 + 2^72
  447|  1.05k|  out[1] = output[1] & 0x00ffffffffffffff;
  448|  1.05k|  output[3] += output[2] >> 56;
  449|       |  // output[3] <= 2^56 + 2^16
  450|  1.05k|  out[2] = output[2] & 0x00ffffffffffffff;
  451|       |
  452|       |  // out[0] < 2^56, out[1] < 2^56, out[2] < 2^56,
  453|       |  // out[3] <= 2^56 + 2^16 (due to final carry),
  454|       |  // so out < 2*p
  455|  1.05k|  out[3] = output[3];
  456|  1.05k|}
bcm.c:p224_felem_mul:
  380|    351|                           const p224_felem in2) {
  381|    351|  out[0] = ((p224_widelimb)in1[0]) * in2[0];
  382|    351|  out[1] = ((p224_widelimb)in1[0]) * in2[1] + ((p224_widelimb)in1[1]) * in2[0];
  383|    351|  out[2] = ((p224_widelimb)in1[0]) * in2[2] + ((p224_widelimb)in1[1]) * in2[1] +
  384|    351|           ((p224_widelimb)in1[2]) * in2[0];
  385|    351|  out[3] = ((p224_widelimb)in1[0]) * in2[3] + ((p224_widelimb)in1[1]) * in2[2] +
  386|    351|           ((p224_widelimb)in1[2]) * in2[1] + ((p224_widelimb)in1[3]) * in2[0];
  387|    351|  out[4] = ((p224_widelimb)in1[1]) * in2[3] + ((p224_widelimb)in1[2]) * in2[2] +
  388|    351|           ((p224_widelimb)in1[3]) * in2[1];
  389|    351|  out[5] = ((p224_widelimb)in1[2]) * in2[3] + ((p224_widelimb)in1[3]) * in2[2];
  390|    351|  out[6] = ((p224_widelimb)in1[3]) * in2[3];
  391|    351|}
bcm.c:p224_felem_to_generic:
  191|  1.05k|static void p224_felem_to_generic(EC_FELEM *out, const p224_felem in) {
  192|       |  // Reduce to unique minimal representation.
  193|  1.05k|  static const int64_t two56 = ((p224_limb)1) << 56;
  194|       |  // 0 <= in < 2*p, p = 2^224 - 2^96 + 1
  195|       |  // if in > p , reduce in = in - 2^224 + 2^96 - 1
  196|  1.05k|  int64_t tmp[4], a;
  197|  1.05k|  tmp[0] = in[0];
  198|  1.05k|  tmp[1] = in[1];
  199|  1.05k|  tmp[2] = in[2];
  200|  1.05k|  tmp[3] = in[3];
  201|       |  // Case 1: a = 1 iff in >= 2^224
  202|  1.05k|  a = (in[3] >> 56);
  203|  1.05k|  tmp[0] -= a;
  204|  1.05k|  tmp[1] += a << 40;
  205|  1.05k|  tmp[3] &= 0x00ffffffffffffff;
  206|       |  // Case 2: a = 0 iff p <= in < 2^224, i.e., the high 128 bits are all 1 and
  207|       |  // the lower part is non-zero
  208|  1.05k|  a = ((in[3] & in[2] & (in[1] | 0x000000ffffffffff)) + 1) |
  209|  1.05k|      (((int64_t)(in[0] + (in[1] & 0x000000ffffffffff)) - 1) >> 63);
  210|  1.05k|  a &= 0x00ffffffffffffff;
  211|       |  // turn a into an all-one mask (if a = 0) or an all-zero mask
  212|  1.05k|  a = (a - 1) >> 63;
  213|       |  // subtract 2^224 - 2^96 + 1 if a is all-one
  214|  1.05k|  tmp[3] &= a ^ 0xffffffffffffffff;
  215|  1.05k|  tmp[2] &= a ^ 0xffffffffffffffff;
  216|  1.05k|  tmp[1] &= (a ^ 0xffffffffffffffff) | 0x000000ffffffffff;
  217|  1.05k|  tmp[0] -= 1 & a;
  218|       |
  219|       |  // eliminate negative coefficients: if tmp[0] is negative, tmp[1] must
  220|       |  // be non-zero, so we only need one step
  221|  1.05k|  a = tmp[0] >> 63;
  222|  1.05k|  tmp[0] += two56 & a;
  223|  1.05k|  tmp[1] -= 1 & a;
  224|       |
  225|       |  // carry 1 -> 2 -> 3
  226|  1.05k|  tmp[2] += tmp[1] >> 56;
  227|  1.05k|  tmp[1] &= 0x00ffffffffffffff;
  228|       |
  229|  1.05k|  tmp[3] += tmp[2] >> 56;
  230|  1.05k|  tmp[2] &= 0x00ffffffffffffff;
  231|       |
  232|       |  // Now 0 <= tmp < p
  233|  1.05k|  p224_felem tmp2;
  234|  1.05k|  tmp2[0] = tmp[0];
  235|  1.05k|  tmp2[1] = tmp[1];
  236|  1.05k|  tmp2[2] = tmp[2];
  237|  1.05k|  tmp2[3] = tmp[3];
  238|       |
  239|       |  // |p224_felem|'s minimal representation uses four 56-bit words. |EC_FELEM|
  240|       |  // uses four 64-bit words. (The top-most word only has 32 bits.)
  241|  1.05k|  out->words[0] = tmp2[0] | (tmp2[1] << 56);
  242|  1.05k|  out->words[1] = (tmp2[1] >> 8) | (tmp2[2] << 48);
  243|  1.05k|  out->words[2] = (tmp2[2] >> 16) | (tmp2[3] << 40);
  244|  1.05k|  out->words[3] = tmp2[3] >> 24;
  245|  1.05k|}
bcm.c:ec_GFp_nistp224_felem_mul:
 1124|    351|                                      const EC_FELEM *a, const EC_FELEM *b) {
 1125|    351|  p224_felem felem1, felem2;
 1126|    351|  p224_widefelem wide;
 1127|    351|  p224_generic_to_felem(felem1, a);
 1128|    351|  p224_generic_to_felem(felem2, b);
 1129|    351|  p224_felem_mul(wide, felem1, felem2);
 1130|    351|  p224_felem_reduce(felem1, wide);
 1131|    351|  p224_felem_to_generic(r, felem1);
 1132|    351|}
bcm.c:ec_GFp_nistp224_felem_sqr:
 1135|    702|                                      const EC_FELEM *a) {
 1136|    702|  p224_felem felem;
 1137|    702|  p224_generic_to_felem(felem, a);
 1138|    702|  p224_widefelem wide;
 1139|    702|  p224_felem_square(wide, felem);
 1140|    702|  p224_felem_reduce(felem, wide);
 1141|    702|  p224_felem_to_generic(r, felem);
 1142|    702|}

bcm.c:EC_GFp_nistz256_method_do_init:
  615|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_nistz256_method) {
  616|      1|  out->group_init = ec_GFp_mont_group_init;
  617|      1|  out->group_finish = ec_GFp_mont_group_finish;
  618|      1|  out->group_set_curve = ec_GFp_mont_group_set_curve;
  619|      1|  out->point_get_affine_coordinates = ecp_nistz256_get_affine;
  620|      1|  out->add = ecp_nistz256_add;
  621|      1|  out->dbl = ecp_nistz256_dbl;
  622|      1|  out->mul = ecp_nistz256_point_mul;
  623|      1|  out->mul_base = ecp_nistz256_point_mul_base;
  624|      1|  out->mul_public = ecp_nistz256_points_mul_public;
  625|      1|  out->felem_mul = ec_GFp_mont_felem_mul;
  626|      1|  out->felem_sqr = ec_GFp_mont_felem_sqr;
  627|      1|  out->felem_to_bytes = ec_GFp_mont_felem_to_bytes;
  628|      1|  out->felem_from_bytes = ec_GFp_mont_felem_from_bytes;
  629|      1|  out->felem_reduce = ec_GFp_mont_felem_reduce;
  630|       |  // TODO(davidben): This should use the specialized field arithmetic
  631|       |  // implementation, rather than the generic one.
  632|      1|  out->felem_exp = ec_GFp_mont_felem_exp;
  633|      1|  out->scalar_inv0_montgomery = ecp_nistz256_inv0_mod_ord;
  634|      1|  out->scalar_to_montgomery_inv_vartime =
  635|      1|      ecp_nistz256_scalar_to_montgomery_inv_vartime;
  636|      1|  out->cmp_x_coordinate = ecp_nistz256_cmp_x_coordinate;
  637|      1|}

ec_GFp_simple_group_init:
   91|      4|int ec_GFp_simple_group_init(EC_GROUP *group) {
   92|      4|  BN_init(&group->field);
   93|      4|  group->a_is_minus3 = 0;
   94|      4|  return 1;
   95|      4|}
ec_GFp_simple_group_set_curve:
  103|      4|                                  BN_CTX *ctx) {
  104|       |  // p must be a prime > 3
  105|      4|  if (BN_num_bits(p) <= 2 || !BN_is_odd(p)) {
  ------------------
  |  Branch (105:7): [True: 0, False: 4]
  |  Branch (105:30): [True: 0, False: 4]
  ------------------
  106|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_FIELD);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|      4|  int ret = 0;
  111|      4|  BN_CTX_start(ctx);
  112|      4|  BIGNUM *tmp = BN_CTX_get(ctx);
  113|      4|  if (tmp == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 4]
  ------------------
  114|      0|    goto err;
  115|      0|  }
  116|       |
  117|       |  // group->field
  118|      4|  if (!BN_copy(&group->field, p)) {
  ------------------
  |  Branch (118:7): [True: 0, False: 4]
  ------------------
  119|      0|    goto err;
  120|      0|  }
  121|      4|  BN_set_negative(&group->field, 0);
  122|       |  // Store the field in minimal form, so it can be used with |BN_ULONG| arrays.
  123|      4|  bn_set_minimal_width(&group->field);
  124|       |
  125|      4|  if (!ec_bignum_to_felem(group, &group->a, a) ||
  ------------------
  |  Branch (125:7): [True: 0, False: 4]
  ------------------
  126|      4|      !ec_bignum_to_felem(group, &group->b, b) ||
  ------------------
  |  Branch (126:7): [True: 0, False: 4]
  ------------------
  127|      4|      !ec_bignum_to_felem(group, &group->one, BN_value_one())) {
  ------------------
  |  Branch (127:7): [True: 0, False: 4]
  ------------------
  128|      0|    goto err;
  129|      0|  }
  130|       |
  131|       |  // group->a_is_minus3
  132|      4|  if (!BN_copy(tmp, a) ||
  ------------------
  |  Branch (132:7): [True: 0, False: 4]
  ------------------
  133|      4|      !BN_add_word(tmp, 3)) {
  ------------------
  |  Branch (133:7): [True: 0, False: 4]
  ------------------
  134|      0|    goto err;
  135|      0|  }
  136|      4|  group->a_is_minus3 = (0 == BN_cmp(tmp, &group->field));
  137|       |
  138|      4|  ret = 1;
  139|       |
  140|      4|err:
  141|      4|  BN_CTX_end(ctx);
  142|      4|  return ret;
  143|      4|}
ec_GFp_simple_group_get_curve:
  146|    677|                                  BIGNUM *b) {
  147|    677|  if ((p != NULL && !BN_copy(p, &group->field)) ||
  ------------------
  |  Branch (147:8): [True: 0, False: 677]
  |  Branch (147:21): [True: 0, False: 0]
  ------------------
  148|    677|      (a != NULL && !ec_felem_to_bignum(group, a, &group->a)) ||
  ------------------
  |  Branch (148:8): [True: 677, False: 0]
  |  Branch (148:21): [True: 0, False: 677]
  ------------------
  149|    677|      (b != NULL && !ec_felem_to_bignum(group, b, &group->b))) {
  ------------------
  |  Branch (149:8): [True: 677, False: 0]
  |  Branch (149:21): [True: 0, False: 677]
  ------------------
  150|      0|    return 0;
  151|      0|  }
  152|    677|  return 1;
  153|    677|}
ec_GFp_simple_point_init:
  155|  1.21k|void ec_GFp_simple_point_init(EC_JACOBIAN *point) {
  156|  1.21k|  OPENSSL_memset(&point->X, 0, sizeof(EC_FELEM));
  157|  1.21k|  OPENSSL_memset(&point->Y, 0, sizeof(EC_FELEM));
  158|  1.21k|  OPENSSL_memset(&point->Z, 0, sizeof(EC_FELEM));
  159|  1.21k|}
ec_GFp_simple_point_copy:
  161|    496|void ec_GFp_simple_point_copy(EC_JACOBIAN *dest, const EC_JACOBIAN *src) {
  162|    496|  OPENSSL_memcpy(&dest->X, &src->X, sizeof(EC_FELEM));
  163|    496|  OPENSSL_memcpy(&dest->Y, &src->Y, sizeof(EC_FELEM));
  164|    496|  OPENSSL_memcpy(&dest->Z, &src->Z, sizeof(EC_FELEM));
  165|    496|}
ec_GFp_simple_felem_to_bytes:
  331|  1.35k|                                  size_t *out_len, const EC_FELEM *in) {
  332|  1.35k|  size_t len = BN_num_bytes(&group->field);
  333|  1.35k|  bn_words_to_big_endian(out, len, in->words, group->field.width);
  334|  1.35k|  *out_len = len;
  335|  1.35k|}
ec_GFp_simple_felem_from_bytes:
  338|    976|                                   const uint8_t *in, size_t len) {
  339|    976|  if (len != BN_num_bytes(&group->field)) {
  ------------------
  |  Branch (339:7): [True: 0, False: 976]
  ------------------
  340|      0|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  341|      0|    return 0;
  342|      0|  }
  343|       |
  344|    976|  bn_big_endian_to_words(out->words, group->field.width, in, len);
  345|       |
  346|    976|  if (!bn_less_than_words(out->words, group->field.d, group->field.width)) {
  ------------------
  |  Branch (346:7): [True: 3, False: 973]
  ------------------
  347|      3|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  348|      3|    return 0;
  349|      3|  }
  350|       |
  351|    973|  return 1;
  352|    976|}

RSA_new:
  206|    409|RSA *RSA_new(void) { return RSA_new_method(NULL); }
RSA_new_method:
  208|    409|RSA *RSA_new_method(const ENGINE *engine) {
  209|    409|  RSA *rsa = OPENSSL_malloc(sizeof(RSA));
  210|    409|  if (rsa == NULL) {
  ------------------
  |  Branch (210:7): [True: 0, False: 409]
  ------------------
  211|      0|    return NULL;
  212|      0|  }
  213|       |
  214|    409|  OPENSSL_memset(rsa, 0, sizeof(RSA));
  215|       |
  216|    409|  if (engine) {
  ------------------
  |  Branch (216:7): [True: 0, False: 409]
  ------------------
  217|      0|    rsa->meth = ENGINE_get_RSA_method(engine);
  218|      0|  }
  219|       |
  220|    409|  if (rsa->meth == NULL) {
  ------------------
  |  Branch (220:7): [True: 409, False: 0]
  ------------------
  221|    409|    rsa->meth = (RSA_METHOD *) RSA_default_method();
  222|    409|  }
  223|    409|  METHOD_ref(rsa->meth);
  224|       |
  225|    409|  rsa->references = 1;
  226|    409|  rsa->flags = rsa->meth->flags;
  227|    409|  CRYPTO_MUTEX_init(&rsa->lock);
  228|    409|  CRYPTO_new_ex_data(&rsa->ex_data);
  229|       |
  230|    409|  if (rsa->meth->init && !rsa->meth->init(rsa)) {
  ------------------
  |  Branch (230:7): [True: 0, False: 409]
  |  Branch (230:26): [True: 0, False: 0]
  ------------------
  231|      0|    CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  232|      0|    CRYPTO_MUTEX_cleanup(&rsa->lock);
  233|      0|    METHOD_unref(rsa->meth);
  234|      0|    OPENSSL_free(rsa);
  235|      0|    return NULL;
  236|      0|  }
  237|       |
  238|    409|  return rsa;
  239|    409|}
RSA_free:
  252|  1.16k|void RSA_free(RSA *rsa) {
  253|  1.16k|  if (rsa == NULL) {
  ------------------
  |  Branch (253:7): [True: 754, False: 409]
  ------------------
  254|    754|    return;
  255|    754|  }
  256|       |
  257|    409|  if (!CRYPTO_refcount_dec_and_test_zero(&rsa->references)) {
  ------------------
  |  Branch (257:7): [True: 0, False: 409]
  ------------------
  258|      0|    return;
  259|      0|  }
  260|       |
  261|    409|  if (rsa->meth->finish) {
  ------------------
  |  Branch (261:7): [True: 0, False: 409]
  ------------------
  262|      0|    rsa->meth->finish(rsa);
  263|      0|  }
  264|    409|  METHOD_unref(rsa->meth);
  265|       |
  266|    409|  CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  267|       |
  268|    409|  BN_free(rsa->n);
  269|    409|  BN_free(rsa->e);
  270|    409|  BN_free(rsa->d);
  271|    409|  BN_free(rsa->p);
  272|    409|  BN_free(rsa->q);
  273|    409|  BN_free(rsa->dmp1);
  274|    409|  BN_free(rsa->dmq1);
  275|    409|  BN_free(rsa->iqmp);
  276|    409|  rsa_invalidate_key(rsa);
  277|    409|  CRYPTO_MUTEX_cleanup(&rsa->lock);
  278|    409|  OPENSSL_free(rsa);
  279|    409|}
RSA_is_opaque:
  438|    387|int RSA_is_opaque(const RSA *rsa) {
  439|    387|  return rsa->meth && (rsa->meth->flags & RSA_FLAG_OPAQUE);
  ------------------
  |  |  661|    387|#define RSA_FLAG_OPAQUE 1
  ------------------
  |  Branch (439:10): [True: 387, False: 0]
  |  Branch (439:23): [True: 0, False: 387]
  ------------------
  440|    387|}
RSA_check_key:
  787|    387|int RSA_check_key(const RSA *key) {
  788|       |  // TODO(davidben): RSA key initialization is spread across
  789|       |  // |rsa_check_public_key|, |RSA_check_key|, |freeze_private_key|, and
  790|       |  // |BN_MONT_CTX_set_locked| as a result of API issues. See
  791|       |  // https://crbug.com/boringssl/316. As a result, we inconsistently check RSA
  792|       |  // invariants. We should fix this and integrate that logic.
  793|       |
  794|    387|  if (RSA_is_opaque(key)) {
  ------------------
  |  Branch (794:7): [True: 0, False: 387]
  ------------------
  795|       |    // Opaque keys can't be checked.
  796|      0|    return 1;
  797|      0|  }
  798|       |
  799|    387|  if (!rsa_check_public_key(key)) {
  ------------------
  |  Branch (799:7): [True: 354, False: 33]
  ------------------
  800|    354|    return 0;
  801|    354|  }
  802|       |
  803|     33|  if ((key->p != NULL) != (key->q != NULL)) {
  ------------------
  |  Branch (803:7): [True: 0, False: 33]
  ------------------
  804|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_ONLY_ONE_OF_P_Q_GIVEN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  805|      0|    return 0;
  806|      0|  }
  807|       |
  808|       |  // |key->d| must be bounded by |key->n|. This ensures bounds on |RSA_bits|
  809|       |  // translate to bounds on the running time of private key operations.
  810|     33|  if (key->d != NULL &&
  ------------------
  |  Branch (810:7): [True: 0, False: 33]
  ------------------
  811|     33|      (BN_is_negative(key->d) || BN_cmp(key->d, key->n) >= 0)) {
  ------------------
  |  Branch (811:8): [True: 0, False: 0]
  |  Branch (811:34): [True: 0, False: 0]
  ------------------
  812|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_OUT_OF_RANGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  813|      0|    return 0;
  814|      0|  }
  815|       |
  816|     33|  if (key->d == NULL || key->p == NULL) {
  ------------------
  |  Branch (816:7): [True: 33, False: 0]
  |  Branch (816:25): [True: 0, False: 0]
  ------------------
  817|       |    // For a public key, or without p and q, there's nothing that can be
  818|       |    // checked.
  819|     33|    return 1;
  820|     33|  }
  821|       |
  822|      0|  BN_CTX *ctx = BN_CTX_new();
  823|      0|  if (ctx == NULL) {
  ------------------
  |  Branch (823:7): [True: 0, False: 0]
  ------------------
  824|      0|    return 0;
  825|      0|  }
  826|       |
  827|      0|  BIGNUM tmp, de, pm1, qm1, dmp1, dmq1;
  828|      0|  int ok = 0;
  829|      0|  BN_init(&tmp);
  830|      0|  BN_init(&de);
  831|      0|  BN_init(&pm1);
  832|      0|  BN_init(&qm1);
  833|      0|  BN_init(&dmp1);
  834|      0|  BN_init(&dmq1);
  835|       |
  836|       |  // Check that p * q == n. Before we multiply, we check that p and q are in
  837|       |  // bounds, to avoid a DoS vector in |bn_mul_consttime| below. Note that
  838|       |  // n was bound by |rsa_check_public_key|. This also implicitly checks p and q
  839|       |  // are odd, which is a necessary condition for Montgomery reduction.
  840|      0|  if (BN_is_negative(key->p) || BN_cmp(key->p, key->n) >= 0 ||
  ------------------
  |  Branch (840:7): [True: 0, False: 0]
  |  Branch (840:33): [True: 0, False: 0]
  ------------------
  841|      0|      BN_is_negative(key->q) || BN_cmp(key->q, key->n) >= 0) {
  ------------------
  |  Branch (841:7): [True: 0, False: 0]
  |  Branch (841:33): [True: 0, False: 0]
  ------------------
  842|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  843|      0|    goto out;
  844|      0|  }
  845|      0|  if (!bn_mul_consttime(&tmp, key->p, key->q, ctx)) {
  ------------------
  |  Branch (845:7): [True: 0, False: 0]
  ------------------
  846|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  847|      0|    goto out;
  848|      0|  }
  849|      0|  if (BN_cmp(&tmp, key->n) != 0) {
  ------------------
  |  Branch (849:7): [True: 0, False: 0]
  ------------------
  850|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  851|      0|    goto out;
  852|      0|  }
  853|       |
  854|       |  // d must be an inverse of e mod the Carmichael totient, lcm(p-1, q-1), but it
  855|       |  // may be unreduced because other implementations use the Euler totient. We
  856|       |  // simply check that d * e is one mod p-1 and mod q-1. Note d and e were bound
  857|       |  // by earlier checks in this function.
  858|      0|  if (!bn_usub_consttime(&pm1, key->p, BN_value_one()) ||
  ------------------
  |  Branch (858:7): [True: 0, False: 0]
  ------------------
  859|      0|      !bn_usub_consttime(&qm1, key->q, BN_value_one())) {
  ------------------
  |  Branch (859:7): [True: 0, False: 0]
  ------------------
  860|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  861|      0|    goto out;
  862|      0|  }
  863|      0|  const unsigned pm1_bits = BN_num_bits(&pm1);
  864|      0|  const unsigned qm1_bits = BN_num_bits(&qm1);
  865|      0|  if (!bn_mul_consttime(&de, key->d, key->e, ctx) ||
  ------------------
  |  Branch (865:7): [True: 0, False: 0]
  ------------------
  866|      0|      !bn_div_consttime(NULL, &tmp, &de, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (866:7): [True: 0, False: 0]
  ------------------
  867|      0|      !bn_div_consttime(NULL, &de, &de, &qm1, qm1_bits, ctx)) {
  ------------------
  |  Branch (867:7): [True: 0, False: 0]
  ------------------
  868|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  869|      0|    goto out;
  870|      0|  }
  871|       |
  872|      0|  if (!BN_is_one(&tmp) || !BN_is_one(&de)) {
  ------------------
  |  Branch (872:7): [True: 0, False: 0]
  |  Branch (872:27): [True: 0, False: 0]
  ------------------
  873|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_E_NOT_CONGRUENT_TO_1);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  874|      0|    goto out;
  875|      0|  }
  876|       |
  877|      0|  int has_crt_values = key->dmp1 != NULL;
  878|      0|  if (has_crt_values != (key->dmq1 != NULL) ||
  ------------------
  |  Branch (878:7): [True: 0, False: 0]
  ------------------
  879|      0|      has_crt_values != (key->iqmp != NULL)) {
  ------------------
  |  Branch (879:7): [True: 0, False: 0]
  ------------------
  880|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_INCONSISTENT_SET_OF_CRT_VALUES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  881|      0|    goto out;
  882|      0|  }
  883|       |
  884|      0|  if (has_crt_values) {
  ------------------
  |  Branch (884:7): [True: 0, False: 0]
  ------------------
  885|      0|    int dmp1_ok, dmq1_ok, iqmp_ok;
  886|      0|    if (!check_mod_inverse(&dmp1_ok, key->e, key->dmp1, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (886:9): [True: 0, False: 0]
  ------------------
  887|      0|        !check_mod_inverse(&dmq1_ok, key->e, key->dmq1, &qm1, qm1_bits, ctx) ||
  ------------------
  |  Branch (887:9): [True: 0, False: 0]
  ------------------
  888|       |        // |p| is odd, so |pm1| and |p| have the same bit width. If they didn't,
  889|       |        // we only need a lower bound anyway.
  890|      0|        !check_mod_inverse(&iqmp_ok, key->q, key->iqmp, key->p, pm1_bits,
  ------------------
  |  Branch (890:9): [True: 0, False: 0]
  ------------------
  891|      0|                           ctx)) {
  892|      0|      OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  893|      0|      goto out;
  894|      0|    }
  895|       |
  896|      0|    if (!dmp1_ok || !dmq1_ok || !iqmp_ok) {
  ------------------
  |  Branch (896:9): [True: 0, False: 0]
  |  Branch (896:21): [True: 0, False: 0]
  |  Branch (896:33): [True: 0, False: 0]
  ------------------
  897|      0|      OPENSSL_PUT_ERROR(RSA, RSA_R_CRT_VALUES_INCORRECT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  898|      0|      goto out;
  899|      0|    }
  900|      0|  }
  901|       |
  902|      0|  ok = 1;
  903|       |
  904|      0|out:
  905|      0|  BN_free(&tmp);
  906|      0|  BN_free(&de);
  907|      0|  BN_free(&pm1);
  908|      0|  BN_free(&qm1);
  909|      0|  BN_free(&dmp1);
  910|      0|  BN_free(&dmq1);
  911|      0|  BN_CTX_free(ctx);
  912|       |
  913|      0|  return ok;
  914|      0|}

rsa_check_public_key:
   76|    387|int rsa_check_public_key(const RSA *rsa) {
   77|    387|  if (rsa->n == NULL) {
  ------------------
  |  Branch (77:7): [True: 0, False: 387]
  ------------------
   78|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   79|      0|    return 0;
   80|      0|  }
   81|       |
   82|       |  // TODO(davidben): 16384-bit RSA is huge. Can we bring this down to a limit of
   83|       |  // 8192-bit?
   84|    387|  unsigned n_bits = BN_num_bits(rsa->n);
   85|    387|  if (n_bits > 16 * 1024) {
  ------------------
  |  Branch (85:7): [True: 15, False: 372]
  ------------------
   86|     15|    OPENSSL_PUT_ERROR(RSA, RSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|     15|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   87|     15|    return 0;
   88|     15|  }
   89|       |
   90|       |  // TODO(crbug.com/boringssl/607): Raise this limit. 512-bit RSA was factored
   91|       |  // in 1999.
   92|    372|  if (n_bits < 512) {
  ------------------
  |  Branch (92:7): [True: 152, False: 220]
  ------------------
   93|    152|    OPENSSL_PUT_ERROR(RSA, RSA_R_KEY_SIZE_TOO_SMALL);
  ------------------
  |  |  441|    152|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   94|    152|    return 0;
   95|    152|  }
   96|       |
   97|       |  // RSA moduli must be positive and odd. In addition to being necessary for RSA
   98|       |  // in general, we cannot setup Montgomery reduction with even moduli.
   99|    220|  if (!BN_is_odd(rsa->n) || BN_is_negative(rsa->n)) {
  ------------------
  |  Branch (99:7): [True: 11, False: 209]
  |  Branch (99:29): [True: 0, False: 209]
  ------------------
  100|     11|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|     11|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  101|     11|    return 0;
  102|     11|  }
  103|       |
  104|    209|  static const unsigned kMaxExponentBits = 33;
  105|    209|  if (rsa->e != NULL) {
  ------------------
  |  Branch (105:7): [True: 209, False: 0]
  ------------------
  106|       |    // Reject e = 1, negative e, and even e. e must be odd to be relatively
  107|       |    // prime with phi(n).
  108|    209|    unsigned e_bits = BN_num_bits(rsa->e);
  109|    209|    if (e_bits < 2 || BN_is_negative(rsa->e) || !BN_is_odd(rsa->e)) {
  ------------------
  |  Branch (109:9): [True: 2, False: 207]
  |  Branch (109:23): [True: 0, False: 207]
  |  Branch (109:49): [True: 112, False: 95]
  ------------------
  110|    114|      OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|    114|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|    114|      return 0;
  112|    114|    }
  113|     95|    if (rsa->flags & RSA_FLAG_LARGE_PUBLIC_EXPONENT) {
  ------------------
  |  |  683|     95|#define RSA_FLAG_LARGE_PUBLIC_EXPONENT 0x80
  ------------------
  |  Branch (113:9): [True: 0, False: 95]
  ------------------
  114|       |      // The caller has requested disabling DoS protections. Still, e must be
  115|       |      // less than n.
  116|      0|      if (BN_ucmp(rsa->n, rsa->e) <= 0) {
  ------------------
  |  Branch (116:11): [True: 0, False: 0]
  ------------------
  117|      0|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|        return 0;
  119|      0|      }
  120|     95|    } else {
  121|       |      // Mitigate DoS attacks by limiting the exponent size. 33 bits was chosen
  122|       |      // as the limit based on the recommendations in [1] and [2]. Windows
  123|       |      // CryptoAPI doesn't support values larger than 32 bits [3], so it is
  124|       |      // unlikely that exponents larger than 32 bits are being used for anything
  125|       |      // Windows commonly does.
  126|       |      //
  127|       |      // [1] https://www.imperialviolet.org/2012/03/16/rsae.html
  128|       |      // [2] https://www.imperialviolet.org/2012/03/17/rsados.html
  129|       |      // [3] https://msdn.microsoft.com/en-us/library/aa387685(VS.85).aspx
  130|     95|      if (e_bits > kMaxExponentBits) {
  ------------------
  |  Branch (130:11): [True: 62, False: 33]
  ------------------
  131|     62|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|     62|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|     62|        return 0;
  133|     62|      }
  134|       |
  135|       |      // The upper bound on |e_bits| and lower bound on |n_bits| imply e is
  136|       |      // bounded by n.
  137|     33|      assert(BN_ucmp(rsa->n, rsa->e) > 0);
  138|     33|    }
  139|     95|  } else if (!(rsa->flags & RSA_FLAG_NO_PUBLIC_EXPONENT)) {
  ------------------
  |  |  677|      0|#define RSA_FLAG_NO_PUBLIC_EXPONENT 0x40
  ------------------
  |  Branch (139:14): [True: 0, False: 0]
  ------------------
  140|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|       |
  144|     33|  return 1;
  145|    209|}
rsa_invalidate_key:
  289|    409|void rsa_invalidate_key(RSA *rsa) {
  290|    409|  rsa->private_key_frozen = 0;
  291|       |
  292|    409|  BN_MONT_CTX_free(rsa->mont_n);
  293|    409|  rsa->mont_n = NULL;
  294|    409|  BN_MONT_CTX_free(rsa->mont_p);
  295|    409|  rsa->mont_p = NULL;
  296|    409|  BN_MONT_CTX_free(rsa->mont_q);
  297|    409|  rsa->mont_q = NULL;
  298|       |
  299|    409|  BN_free(rsa->d_fixed);
  300|    409|  rsa->d_fixed = NULL;
  301|    409|  BN_free(rsa->dmp1_fixed);
  302|    409|  rsa->dmp1_fixed = NULL;
  303|    409|  BN_free(rsa->dmq1_fixed);
  304|    409|  rsa->dmq1_fixed = NULL;
  305|    409|  BN_free(rsa->inv_small_mod_large_mont);
  306|    409|  rsa->inv_small_mod_large_mont = NULL;
  307|       |
  308|    409|  for (size_t i = 0; i < rsa->num_blindings; i++) {
  ------------------
  |  Branch (308:22): [True: 0, False: 409]
  ------------------
  309|      0|    BN_BLINDING_free(rsa->blindings[i]);
  310|      0|  }
  311|    409|  OPENSSL_free(rsa->blindings);
  312|    409|  rsa->blindings = NULL;
  313|    409|  rsa->num_blindings = 0;
  314|    409|  OPENSSL_free(rsa->blindings_inuse);
  315|    409|  rsa->blindings_inuse = NULL;
  316|    409|  rsa->blinding_fork_generation = 0;
  317|    409|}
bcm.c:RSA_default_method_do_init:
 1349|      1|DEFINE_METHOD_FUNCTION(RSA_METHOD, RSA_default_method) {
 1350|       |  // All of the methods are NULL to make it easier for the compiler/linker to
 1351|       |  // drop unused functions. The wrapper functions will select the appropriate
 1352|       |  // |rsa_default_*| implementation.
 1353|      1|  OPENSSL_memset(out, 0, sizeof(RSA_METHOD));
 1354|      1|  out->common.is_static = 1;
 1355|      1|}

err.c:OPENSSL_memset:
 1055|   129k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   129k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 129k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   129k|  return memset(dst, c, n);
 1061|   129k|}
evp.c:OPENSSL_memset:
 1055|  1.74k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  1.74k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1.74k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  1.74k|  return memset(dst, c, n);
 1061|  1.74k|}
p_ed25519_asn1.c:OPENSSL_memcpy:
 1039|      1|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      1|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 1]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      1|  return memcpy(dst, src, n);
 1045|      1|}
p_x25519_asn1.c:OPENSSL_memcpy:
 1039|      1|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      1|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 1]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      1|  return memcpy(dst, src, n);
 1045|      1|}
mem.c:OPENSSL_memset:
 1055|   636k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   636k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 636k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   636k|  return memset(dst, c, n);
 1061|   636k|}
mem.c:OPENSSL_memcpy:
 1039|  4.28k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  4.28k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 4.28k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  4.28k|  return memcpy(dst, src, n);
 1045|  4.28k|}
refcount.c:CRYPTO_atomic_load_u32:
  626|  9.55k|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|  9.55k|  return atomic_load(val);
  628|  9.55k|}
refcount.c:CRYPTO_atomic_compare_exchange_weak_u32:
  631|  9.55k|    CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
  632|  9.55k|  return atomic_compare_exchange_weak(val, expected, desired);
  633|  9.55k|}
thread_pthread.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
x_name.c:OPENSSL_memcpy:
 1039|  6.32k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  6.32k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 6.32k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  6.32k|  return memcpy(dst, src, n);
 1045|  6.32k|}
x_x509.c:OPENSSL_memset:
 1055|  5.12k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  5.12k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 5.12k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  5.12k|  return memset(dst, c, n);
 1061|  5.12k|}
bcm.c:OPENSSL_memmove:
 1047|  4.74k|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|  4.74k|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 4.74k]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|  4.74k|  return memmove(dst, src, n);
 1053|  4.74k|}
bcm.c:OPENSSL_memcpy:
 1039|  1.97M|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  1.97M|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 26.6k, False: 1.94M]
  ------------------
 1041|  26.6k|    return dst;
 1042|  26.6k|  }
 1043|       |
 1044|  1.94M|  return memcpy(dst, src, n);
 1045|  1.97M|}
bcm.c:constant_time_is_zero_w:
  427|   304k|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|   304k|  return constant_time_msb_w(~a & (a - 1));
  440|   304k|}
bcm.c:constant_time_msb_w:
  368|   608k|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|   608k|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|   608k|}
bcm.c:constant_time_eq_w:
  450|   303k|                                               crypto_word_t b) {
  451|   303k|  return constant_time_is_zero_w(a ^ b);
  452|   303k|}
bcm.c:constant_time_select_w:
  477|  2.54M|                                                   crypto_word_t b) {
  478|       |  // Clang recognizes this pattern as a select. While it usually transforms it
  479|       |  // to a cmov, it sometimes further transforms it into a branch, which we do
  480|       |  // not want.
  481|       |  //
  482|       |  // Hiding the value of the mask from the compiler evades this transformation.
  483|  2.54M|  mask = value_barrier_w(mask);
  484|  2.54M|  return (mask & a) | (~mask & b);
  485|  2.54M|}
bcm.c:value_barrier_w:
  340|  2.54M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  2.54M|#if defined(__GNUC__) || defined(__clang__)
  342|  2.54M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  2.54M|#endif
  344|  2.54M|  return a;
  345|  2.54M|}
bcm.c:OPENSSL_memset:
 1055|  2.71M|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  2.71M|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 910k, False: 1.80M]
  ------------------
 1057|   910k|    return dst;
 1058|   910k|  }
 1059|       |
 1060|  1.80M|  return memset(dst, c, n);
 1061|  2.71M|}
bcm.c:CRYPTO_load_word_be:
 1122|  1.89M|static inline crypto_word_t CRYPTO_load_word_be(const void *in) {
 1123|  1.89M|  crypto_word_t v;
 1124|  1.89M|  OPENSSL_memcpy(&v, in, sizeof(v));
 1125|  1.89M|#if defined(OPENSSL_64_BIT)
 1126|  1.89M|  static_assert(sizeof(v) == 8, "crypto_word_t has unexpected size");
 1127|  1.89M|  return CRYPTO_bswap8(v);
 1128|       |#else
 1129|       |  static_assert(sizeof(v) == 4, "crypto_word_t has unexpected size");
 1130|       |  return CRYPTO_bswap4(v);
 1131|       |#endif
 1132|  1.89M|}
bcm.c:CRYPTO_bswap8:
  949|  1.89M|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|  1.89M|  return __builtin_bswap64(x);
  951|  1.89M|}
bcm.c:constant_time_select_int:
  503|   608k|static inline int constant_time_select_int(crypto_word_t mask, int a, int b) {
  504|   608k|  return (int)(constant_time_select_w(mask, (crypto_word_t)(a),
  505|   608k|                                      (crypto_word_t)(b)));
  506|   608k|}
bcm.c:constant_time_declassify_int:
  572|  1.16k|static inline int constant_time_declassify_int(int v) {
  573|  1.16k|  static_assert(sizeof(uint32_t) == sizeof(int),
  574|  1.16k|                "int is not the same size as uint32_t");
  575|       |  // See comment above.
  576|  1.16k|  CONSTTIME_DECLASSIFY(&v, sizeof(v));
  577|  1.16k|  return value_barrier_u32(v);
  578|  1.16k|}
bcm.c:value_barrier_u32:
  348|  1.16k|static inline uint32_t value_barrier_u32(uint32_t a) {
  349|  1.16k|#if defined(__GNUC__) || defined(__clang__)
  350|  1.16k|  __asm__("" : "+r"(a) : /* no inputs */);
  351|  1.16k|#endif
  352|  1.16k|  return a;
  353|  1.16k|}
bcm.c:constant_time_lt_w:
  374|   303k|                                               crypto_word_t b) {
  375|       |  // Consider the two cases of the problem:
  376|       |  //   msb(a) == msb(b): a < b iff the MSB of a - b is set.
  377|       |  //   msb(a) != msb(b): a < b iff the MSB of b is set.
  378|       |  //
  379|       |  // If msb(a) == msb(b) then the following evaluates as:
  380|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  381|       |  //   msb(a^((a-b) ^ a))       ==   (because msb(a^b) == 0)
  382|       |  //   msb(a^a^(a-b))           ==   (rearranging)
  383|       |  //   msb(a-b)                      (because ∀x. x^x == 0)
  384|       |  //
  385|       |  // Else, if msb(a) != msb(b) then the following evaluates as:
  386|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  387|       |  //   msb(a^(𝟙 | ((a-b)^a)))   ==   (because msb(a^b) == 1 and 𝟙
  388|       |  //                                  represents a value s.t. msb(𝟙) = 1)
  389|       |  //   msb(a^𝟙)                 ==   (because ORing with 1 results in 1)
  390|       |  //   msb(b)
  391|       |  //
  392|       |  //
  393|       |  // Here is an SMT-LIB verification of this formula:
  394|       |  //
  395|       |  // (define-fun lt ((a (_ BitVec 32)) (b (_ BitVec 32))) (_ BitVec 32)
  396|       |  //   (bvxor a (bvor (bvxor a b) (bvxor (bvsub a b) a)))
  397|       |  // )
  398|       |  //
  399|       |  // (declare-fun a () (_ BitVec 32))
  400|       |  // (declare-fun b () (_ BitVec 32))
  401|       |  //
  402|       |  // (assert (not (= (= #x00000001 (bvlshr (lt a b) #x0000001f)) (bvult a b))))
  403|       |  // (check-sat)
  404|       |  // (get-model)
  405|   303k|  return constant_time_msb_w(a^((a^b)|((a-b)^a)));
  406|   303k|}
a_bitstr.c:OPENSSL_memcpy:
 1039|  5.41k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  5.41k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 3.57k, False: 1.84k]
  ------------------
 1041|  3.57k|    return dst;
 1042|  3.57k|  }
 1043|       |
 1044|  1.84k|  return memcpy(dst, src, n);
 1045|  5.41k|}
a_int.c:OPENSSL_memcpy:
 1039|  6.14k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  6.14k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 684, False: 5.45k]
  ------------------
 1041|    684|    return dst;
 1042|    684|  }
 1043|       |
 1044|  5.45k|  return memcpy(dst, src, n);
 1045|  6.14k|}
a_int.c:CRYPTO_bswap8:
  949|    225|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|    225|  return __builtin_bswap64(x);
  951|    225|}
a_int.c:CRYPTO_load_u64_be:
 1101|    225|static inline uint64_t CRYPTO_load_u64_be(const void *ptr) {
 1102|    225|  uint64_t ret;
 1103|    225|  OPENSSL_memcpy(&ret, ptr, sizeof(ret));
 1104|    225|  return CRYPTO_bswap8(ret);
 1105|    225|}
asn1_lib.c:OPENSSL_memcpy:
 1039|  56.0k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  56.0k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 2.37k, False: 53.7k]
  ------------------
 1041|  2.37k|    return dst;
 1042|  2.37k|  }
 1043|       |
 1044|  53.7k|  return memcpy(dst, src, n);
 1045|  56.0k|}
tasn_enc.c:OPENSSL_memcmp:
 1031|  71.6k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  71.6k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 71.6k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  71.6k|  return memcmp(s1, s2, n);
 1037|  71.6k|}
tasn_enc.c:OPENSSL_memcpy:
 1039|  56.0k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  56.0k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 56.0k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  56.0k|  return memcpy(dst, src, n);
 1045|  56.0k|}
tasn_new.c:OPENSSL_memset:
 1055|  76.2k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  76.2k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 76.2k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  76.2k|  return memset(dst, c, n);
 1061|  76.2k|}
tasn_utl.c:OPENSSL_memcpy:
 1039|  2.09k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  2.09k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 2.09k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  2.09k|  return memcpy(dst, src, n);
 1045|  2.09k|}
buf.c:OPENSSL_memset:
 1055|  22.9k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  22.9k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 22.9k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  22.9k|  return memset(dst, c, n);
 1061|  22.9k|}
cbb.c:OPENSSL_memset:
 1055|  9.54k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  9.54k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 9.54k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  9.54k|  return memset(dst, c, n);
 1061|  9.54k|}
cbb.c:OPENSSL_memmove:
 1047|  1.12k|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|  1.12k|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 1.12k]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|  1.12k|  return memmove(dst, src, n);
 1053|  1.12k|}
dsa.c:OPENSSL_memset:
 1055|    505|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|    505|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 505]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|    505|  return memset(dst, c, n);
 1061|    505|}
ec_asn1.c:OPENSSL_memcmp:
 1031|  1.89k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  1.89k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 1.89k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  1.89k|  return memcmp(s1, s2, n);
 1037|  1.89k|}
evp_asn1.c:OPENSSL_memcmp:
 1031|  2.42k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  2.42k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 2.42k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  2.42k|  return memcmp(s1, s2, n);
 1037|  2.42k|}
obj.c:OPENSSL_memcpy:
 1039|  58.5k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  58.5k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 58.5k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  58.5k|  return memcpy(dst, src, n);
 1045|  58.5k|}
stack.c:OPENSSL_memset:
 1055|   184k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   184k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 184k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   184k|  return memset(dst, c, n);
 1061|   184k|}

OPENSSL_malloc:
  228|   636k|void *OPENSSL_malloc(size_t size) {
  229|   636k|  if (should_fail_allocation()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 636k]
  ------------------
  230|      0|    goto err;
  231|      0|  }
  232|       |
  233|   636k|  if (OPENSSL_memory_alloc != NULL) {
  ------------------
  |  Branch (233:7): [True: 0, False: 636k]
  ------------------
  234|      0|    assert(OPENSSL_memory_free != NULL);
  235|      0|    assert(OPENSSL_memory_get_size != NULL);
  236|      0|    void *ptr = OPENSSL_memory_alloc(size);
  237|      0|    if (ptr == NULL && size != 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  |  Branch (237:24): [True: 0, False: 0]
  ------------------
  238|      0|      goto err;
  239|      0|    }
  240|      0|    return ptr;
  241|      0|  }
  242|       |
  243|   636k|  if (size + OPENSSL_MALLOC_PREFIX < size) {
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  |  Branch (243:7): [True: 0, False: 636k]
  ------------------
  244|       |    // |OPENSSL_malloc| is a central function in BoringSSL thus a reference to
  245|       |    // |kBoringSSLBinaryTag| is created here so that the tag isn't discarded by
  246|       |    // the linker. The following is sufficient to stop GCC, Clang, and MSVC
  247|       |    // optimising away the reference at the time of writing. Since this
  248|       |    // probably results in an actual memory reference, it is put in this very
  249|       |    // rare code path.
  250|      0|    uint8_t unused = *(volatile uint8_t *)kBoringSSLBinaryTag;
  251|      0|    (void) unused;
  252|      0|    goto err;
  253|      0|  }
  254|       |
  255|   636k|  void *ptr = malloc(size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  256|   636k|  if (ptr == NULL) {
  ------------------
  |  Branch (256:7): [True: 0, False: 636k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|   636k|  *(size_t *)ptr = size;
  261|       |
  262|   636k|  __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  263|   636k|  return ((uint8_t *)ptr) + OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  264|       |
  265|      0| err:
  266|       |  // This only works because ERR does not call OPENSSL_malloc.
  267|      0|  OPENSSL_PUT_ERROR(CRYPTO, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|  return NULL;
  269|   636k|}
OPENSSL_free:
  271|   817k|void OPENSSL_free(void *orig_ptr) {
  272|   817k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (272:7): [True: 181k, False: 636k]
  ------------------
  273|   181k|    return;
  274|   181k|  }
  275|       |
  276|   636k|  if (OPENSSL_memory_free != NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 636k]
  ------------------
  277|      0|    OPENSSL_memory_free(orig_ptr);
  278|      0|    return;
  279|      0|  }
  280|       |
  281|   636k|  void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  282|   636k|  __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  283|       |
  284|   636k|  size_t size = *(size_t *)ptr;
  285|   636k|  OPENSSL_cleanse(ptr, size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|   636k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  286|       |
  287|       |// ASan knows to intercept malloc and free, but not sdallocx.
  288|       |#if defined(OPENSSL_ASAN)
  289|       |  (void)sdallocx;
  290|       |  free(ptr);
  291|       |#else
  292|   636k|  if (sdallocx) {
  ------------------
  |  Branch (292:7): [True: 0, False: 636k]
  ------------------
  293|      0|    sdallocx(ptr, size + OPENSSL_MALLOC_PREFIX, 0 /* flags */);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  294|   636k|  } else {
  295|   636k|    free(ptr);
  296|   636k|  }
  297|   636k|#endif
  298|   636k|}
OPENSSL_realloc:
  300|  17.8k|void *OPENSSL_realloc(void *orig_ptr, size_t new_size) {
  301|  17.8k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (301:7): [True: 7.01k, False: 10.8k]
  ------------------
  302|  7.01k|    return OPENSSL_malloc(new_size);
  303|  7.01k|  }
  304|       |
  305|  10.8k|  size_t old_size;
  306|  10.8k|  if (OPENSSL_memory_get_size != NULL) {
  ------------------
  |  Branch (306:7): [True: 0, False: 10.8k]
  ------------------
  307|      0|    old_size = OPENSSL_memory_get_size(orig_ptr);
  308|  10.8k|  } else {
  309|  10.8k|    void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  10.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  310|  10.8k|    __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  10.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  311|  10.8k|    old_size = *(size_t *)ptr;
  312|  10.8k|    __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  10.8k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  313|  10.8k|  }
  314|       |
  315|  10.8k|  void *ret = OPENSSL_malloc(new_size);
  316|  10.8k|  if (ret == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 10.8k]
  ------------------
  317|      0|    return NULL;
  318|      0|  }
  319|       |
  320|  10.8k|  size_t to_copy = new_size;
  321|  10.8k|  if (old_size < to_copy) {
  ------------------
  |  Branch (321:7): [True: 10.8k, False: 0]
  ------------------
  322|  10.8k|    to_copy = old_size;
  323|  10.8k|  }
  324|       |
  325|  10.8k|  memcpy(ret, orig_ptr, to_copy);
  326|  10.8k|  OPENSSL_free(orig_ptr);
  327|       |
  328|  10.8k|  return ret;
  329|  10.8k|}
OPENSSL_cleanse:
  331|   636k|void OPENSSL_cleanse(void *ptr, size_t len) {
  332|       |#if defined(OPENSSL_WINDOWS)
  333|       |  SecureZeroMemory(ptr, len);
  334|       |#else
  335|   636k|  OPENSSL_memset(ptr, 0, len);
  336|       |
  337|   636k|#if !defined(OPENSSL_NO_ASM)
  338|       |  /* As best as we can tell, this is sufficient to break any optimisations that
  339|       |     might try to eliminate "superfluous" memsets. If there's an easy way to
  340|       |     detect memset_s, it would be better to use that. */
  341|   636k|  __asm__ __volatile__("" : : "r"(ptr) : "memory");
  342|   636k|#endif
  343|   636k|#endif  // !OPENSSL_NO_ASM
  344|   636k|}
CRYPTO_memcmp:
  360|    486|int CRYPTO_memcmp(const void *in_a, const void *in_b, size_t len) {
  361|    486|  const uint8_t *a = in_a;
  362|    486|  const uint8_t *b = in_b;
  363|    486|  uint8_t x = 0;
  364|       |
  365|  19.8k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (365:22): [True: 19.3k, False: 486]
  ------------------
  366|  19.3k|    x |= a[i] ^ b[i];
  367|  19.3k|  }
  368|       |
  369|    486|  return x;
  370|    486|}
OPENSSL_isdigit:
  417|  63.7k|int OPENSSL_isdigit(int c) { return c >= '0' && c <= '9'; }
  ------------------
  |  Branch (417:37): [True: 63.7k, False: 46]
  |  Branch (417:49): [True: 63.6k, False: 120]
  ------------------
OPENSSL_tolower:
  441|  17.9M|int OPENSSL_tolower(int c) {
  442|  17.9M|  if (c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (442:7): [True: 17.8M, False: 5.87k]
  |  Branch (442:19): [True: 1.97k, False: 17.8M]
  ------------------
  443|  1.97k|    return c + ('a' - 'A');
  444|  1.97k|  }
  445|  17.9M|  return c;
  446|  17.9M|}
OPENSSL_isspace:
  448|  17.9M|int OPENSSL_isspace(int c) {
  449|  17.9M|  return c == '\t' || c == '\n' || c == '\v' || c == '\f' || c == '\r' ||
  ------------------
  |  Branch (449:10): [True: 194, False: 17.9M]
  |  Branch (449:23): [True: 786, False: 17.9M]
  |  Branch (449:36): [True: 206, False: 17.9M]
  |  Branch (449:49): [True: 282, False: 17.9M]
  |  Branch (449:62): [True: 202, False: 17.9M]
  ------------------
  450|  17.9M|         c == ' ';
  ------------------
  |  Branch (450:10): [True: 49.9k, False: 17.9M]
  ------------------
  451|  17.9M|}
OPENSSL_strlcpy:
  572|  14.5k|size_t OPENSSL_strlcpy(char *dst, const char *src, size_t dst_size) {
  573|  14.5k|  size_t l = 0;
  574|       |
  575|   124k|  for (; dst_size > 1 && *src; dst_size--) {
  ------------------
  |  Branch (575:10): [True: 120k, False: 3.76k]
  |  Branch (575:26): [True: 110k, False: 10.7k]
  ------------------
  576|   110k|    *dst++ = *src++;
  577|   110k|    l++;
  578|   110k|  }
  579|       |
  580|  14.5k|  if (dst_size) {
  ------------------
  |  Branch (580:7): [True: 14.5k, False: 0]
  ------------------
  581|  14.5k|    *dst = 0;
  582|  14.5k|  }
  583|       |
  584|  14.5k|  return l + strlen(src);
  585|  14.5k|}
OPENSSL_strlcat:
  587|  14.5k|size_t OPENSSL_strlcat(char *dst, const char *src, size_t dst_size) {
  588|  14.5k|  size_t l = 0;
  589|   160k|  for (; dst_size > 0 && *dst; dst_size--, dst++) {
  ------------------
  |  Branch (589:10): [True: 160k, False: 0]
  |  Branch (589:26): [True: 145k, False: 14.5k]
  ------------------
  590|   145k|    l++;
  591|   145k|  }
  592|  14.5k|  return l + OPENSSL_strlcpy(dst, src, dst_size);
  593|  14.5k|}
OPENSSL_memdup:
  595|  4.28k|void *OPENSSL_memdup(const void *data, size_t size) {
  596|  4.28k|  if (size == 0) {
  ------------------
  |  Branch (596:7): [True: 0, False: 4.28k]
  ------------------
  597|      0|    return NULL;
  598|      0|  }
  599|       |
  600|  4.28k|  void *ret = OPENSSL_malloc(size);
  601|  4.28k|  if (ret == NULL) {
  ------------------
  |  Branch (601:7): [True: 0, False: 4.28k]
  ------------------
  602|      0|    return NULL;
  603|      0|  }
  604|       |
  605|  4.28k|  OPENSSL_memcpy(ret, data, size);
  606|  4.28k|  return ret;
  607|  4.28k|}
mem.c:should_fail_allocation:
  225|   636k|static int should_fail_allocation(void) { return 0; }
mem.c:__asan_poison_memory_region:
   90|   646k|static void __asan_poison_memory_region(const void *addr, size_t size) {}
mem.c:__asan_unpoison_memory_region:
   91|   646k|static void __asan_unpoison_memory_region(const void *addr, size_t size) {}

OBJ_dup:
  101|  58.5k|ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o) {
  102|  58.5k|  ASN1_OBJECT *r;
  103|  58.5k|  unsigned char *data = NULL;
  104|  58.5k|  char *sn = NULL, *ln = NULL;
  105|       |
  106|  58.5k|  if (o == NULL) {
  ------------------
  |  Branch (106:7): [True: 0, False: 58.5k]
  ------------------
  107|      0|    return NULL;
  108|      0|  }
  109|       |
  110|  58.5k|  if (!(o->flags & ASN1_OBJECT_FLAG_DYNAMIC)) {
  ------------------
  |  |  105|  58.5k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  |  Branch (110:7): [True: 0, False: 58.5k]
  ------------------
  111|       |    // TODO(fork): this is a little dangerous.
  112|      0|    return (ASN1_OBJECT *)o;
  113|      0|  }
  114|       |
  115|  58.5k|  r = ASN1_OBJECT_new();
  116|  58.5k|  if (r == NULL) {
  ------------------
  |  Branch (116:7): [True: 0, False: 58.5k]
  ------------------
  117|      0|    OPENSSL_PUT_ERROR(OBJ, ERR_R_ASN1_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|    return NULL;
  119|      0|  }
  120|  58.5k|  r->ln = r->sn = NULL;
  121|       |
  122|  58.5k|  data = OPENSSL_malloc(o->length);
  123|  58.5k|  if (data == NULL) {
  ------------------
  |  Branch (123:7): [True: 0, False: 58.5k]
  ------------------
  124|      0|    goto err;
  125|      0|  }
  126|  58.5k|  if (o->data != NULL) {
  ------------------
  |  Branch (126:7): [True: 58.5k, False: 0]
  ------------------
  127|  58.5k|    OPENSSL_memcpy(data, o->data, o->length);
  128|  58.5k|  }
  129|       |
  130|       |  // once data is attached to an object, it remains const
  131|  58.5k|  r->data = data;
  132|  58.5k|  r->length = o->length;
  133|  58.5k|  r->nid = o->nid;
  134|       |
  135|  58.5k|  if (o->ln != NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 58.5k]
  ------------------
  136|      0|    ln = OPENSSL_strdup(o->ln);
  137|      0|    if (ln == NULL) {
  ------------------
  |  Branch (137:9): [True: 0, False: 0]
  ------------------
  138|      0|      goto err;
  139|      0|    }
  140|      0|  }
  141|       |
  142|  58.5k|  if (o->sn != NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 58.5k]
  ------------------
  143|      0|    sn = OPENSSL_strdup(o->sn);
  144|      0|    if (sn == NULL) {
  ------------------
  |  Branch (144:9): [True: 0, False: 0]
  ------------------
  145|      0|      goto err;
  146|      0|    }
  147|      0|  }
  148|       |
  149|  58.5k|  r->sn = sn;
  150|  58.5k|  r->ln = ln;
  151|       |
  152|  58.5k|  r->flags =
  153|  58.5k|      o->flags | (ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  105|  58.5k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
                    o->flags | (ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  106|  58.5k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  154|  58.5k|                  ASN1_OBJECT_FLAG_DYNAMIC_DATA);
  ------------------
  |  |  107|  58.5k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  155|  58.5k|  return r;
  156|       |
  157|      0|err:
  158|      0|  OPENSSL_free(ln);
  159|      0|  OPENSSL_free(sn);
  160|      0|  OPENSSL_free(data);
  161|      0|  OPENSSL_free(r);
  162|      0|  return NULL;
  163|  58.5k|}
OBJ_nid2obj:
  344|  60.8k|ASN1_OBJECT *OBJ_nid2obj(int nid) {
  345|  60.8k|  if (nid >= 0 && nid < NUM_NID) {
  ------------------
  |  |   60|  60.8k|#define NUM_NID 965
  ------------------
  |  Branch (345:7): [True: 60.8k, False: 0]
  |  Branch (345:19): [True: 60.8k, False: 0]
  ------------------
  346|  60.8k|    if (nid != NID_undef && kObjects[nid].nid == NID_undef) {
  ------------------
  |  |   85|   121k|#define NID_undef 0
  ------------------
                  if (nid != NID_undef && kObjects[nid].nid == NID_undef) {
  ------------------
  |  |   85|      0|#define NID_undef 0
  ------------------
  |  Branch (346:9): [True: 0, False: 60.8k]
  |  Branch (346:29): [True: 0, False: 0]
  ------------------
  347|      0|      goto err;
  348|      0|    }
  349|  60.8k|    return (ASN1_OBJECT *)&kObjects[nid];
  350|  60.8k|  }
  351|       |
  352|      0|  CRYPTO_STATIC_MUTEX_lock_read(&global_added_lock);
  353|      0|  if (global_added_by_nid != NULL) {
  ------------------
  |  Branch (353:7): [True: 0, False: 0]
  ------------------
  354|      0|    ASN1_OBJECT *match, template;
  355|       |
  356|      0|    template.nid = nid;
  357|      0|    match = lh_ASN1_OBJECT_retrieve(global_added_by_nid, &template);
  358|      0|    if (match != NULL) {
  ------------------
  |  Branch (358:9): [True: 0, False: 0]
  ------------------
  359|      0|      CRYPTO_STATIC_MUTEX_unlock_read(&global_added_lock);
  360|      0|      return match;
  361|      0|    }
  362|      0|  }
  363|      0|  CRYPTO_STATIC_MUTEX_unlock_read(&global_added_lock);
  364|       |
  365|      0|err:
  366|      0|  OPENSSL_PUT_ERROR(OBJ, OBJ_R_UNKNOWN_NID);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  367|      0|  return NULL;
  368|      0|}

CRYPTO_refcount_inc:
   31|    516|void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
   32|    516|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   33|    516|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   34|       |
   35|    516|  while (expected != CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|    516|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (35:10): [True: 516, False: 0]
  ------------------
   36|    516|    uint32_t new_value = expected + 1;
   37|    516|    if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected, new_value)) {
  ------------------
  |  Branch (37:9): [True: 516, False: 0]
  ------------------
   38|    516|      break;
   39|    516|    }
   40|    516|  }
   41|    516|}
CRYPTO_refcount_dec_and_test_zero:
   43|  9.03k|int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
   44|  9.03k|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   45|  9.03k|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   46|       |
   47|  9.03k|  for (;;) {
   48|  9.03k|    if (expected == 0) {
  ------------------
  |  Branch (48:9): [True: 0, False: 9.03k]
  ------------------
   49|      0|      abort();
   50|  9.03k|    } else if (expected == CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|  9.03k|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (50:16): [True: 0, False: 9.03k]
  ------------------
   51|      0|      return 0;
   52|  9.03k|    } else {
   53|  9.03k|      const uint32_t new_value = expected - 1;
   54|  9.03k|      if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected,
  ------------------
  |  Branch (54:11): [True: 9.03k, False: 0]
  ------------------
   55|  9.03k|                                                  new_value)) {
   56|  9.03k|        return new_value == 0;
   57|  9.03k|      }
   58|  9.03k|    }
   59|  9.03k|  }
   60|  9.03k|}

RSA_parse_public_key:
   90|    409|RSA *RSA_parse_public_key(CBS *cbs) {
   91|    409|  RSA *ret = RSA_new();
   92|    409|  if (ret == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 409]
  ------------------
   93|      0|    return NULL;
   94|      0|  }
   95|    409|  CBS child;
   96|    409|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    409|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    409|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    409|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (96:7): [True: 1, False: 408]
  ------------------
   97|    409|      !parse_integer(&child, &ret->n) ||
  ------------------
  |  Branch (97:7): [True: 1, False: 407]
  ------------------
   98|    409|      !parse_integer(&child, &ret->e) ||
  ------------------
  |  Branch (98:7): [True: 2, False: 405]
  ------------------
   99|    409|      CBS_len(&child) != 0) {
  ------------------
  |  Branch (99:7): [True: 18, False: 387]
  ------------------
  100|     22|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|     22|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  101|     22|    RSA_free(ret);
  102|     22|    return NULL;
  103|     22|  }
  104|       |
  105|    387|  if (!RSA_check_key(ret)) {
  ------------------
  |  Branch (105:7): [True: 354, False: 33]
  ------------------
  106|    354|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|    354|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|    354|    RSA_free(ret);
  108|    354|    return NULL;
  109|    354|  }
  110|       |
  111|     33|  return ret;
  112|    387|}
rsa_asn1.c:parse_integer:
   72|    815|static int parse_integer(CBS *cbs, BIGNUM **out) {
   73|    815|  assert(*out == NULL);
   74|    815|  *out = BN_new();
   75|    815|  if (*out == NULL) {
  ------------------
  |  Branch (75:7): [True: 0, False: 815]
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|    815|  return BN_parse_asn1_unsigned(cbs, *out);
   79|    815|}

sk_new:
   72|  92.1k|_STACK *sk_new(OPENSSL_sk_cmp_func comp) {
   73|  92.1k|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
   74|  92.1k|  if (ret == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 92.1k]
  ------------------
   75|      0|    return NULL;
   76|      0|  }
   77|  92.1k|  OPENSSL_memset(ret, 0, sizeof(_STACK));
   78|       |
   79|  92.1k|  ret->data = OPENSSL_malloc(sizeof(void *) * kMinSize);
   80|  92.1k|  if (ret->data == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 92.1k]
  ------------------
   81|      0|    goto err;
   82|      0|  }
   83|       |
   84|  92.1k|  OPENSSL_memset(ret->data, 0, sizeof(void *) * kMinSize);
   85|       |
   86|  92.1k|  ret->comp = comp;
   87|  92.1k|  ret->num_alloc = kMinSize;
   88|       |
   89|  92.1k|  return ret;
   90|       |
   91|      0|err:
   92|      0|  OPENSSL_free(ret);
   93|      0|  return NULL;
   94|  92.1k|}
sk_new_null:
   96|  92.1k|_STACK *sk_new_null(void) { return sk_new(NULL); }
sk_num:
   98|  6.00M|size_t sk_num(const _STACK *sk) {
   99|  6.00M|  if (sk == NULL) {
  ------------------
  |  Branch (99:7): [True: 17.7k, False: 5.98M]
  ------------------
  100|  17.7k|    return 0;
  101|  17.7k|  }
  102|  5.98M|  return sk->num;
  103|  6.00M|}
sk_value:
  114|  5.86M|void *sk_value(const _STACK *sk, size_t i) {
  115|  5.86M|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (115:7): [True: 0, False: 5.86M]
  |  Branch (115:14): [True: 0, False: 5.86M]
  ------------------
  116|      0|    return NULL;
  117|      0|  }
  118|  5.86M|  return sk->data[i];
  119|  5.86M|}
sk_set:
  121|  22.9k|void *sk_set(_STACK *sk, size_t i, void *value) {
  122|  22.9k|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (122:7): [True: 0, False: 22.9k]
  |  Branch (122:14): [True: 0, False: 22.9k]
  ------------------
  123|      0|    return NULL;
  124|      0|  }
  125|  22.9k|  return sk->data[i] = value;
  126|  22.9k|}
sk_free:
  128|   109k|void sk_free(_STACK *sk) {
  129|   109k|  if (sk == NULL) {
  ------------------
  |  Branch (129:7): [True: 17.7k, False: 92.1k]
  ------------------
  130|  17.7k|    return;
  131|  17.7k|  }
  132|  92.1k|  OPENSSL_free(sk->data);
  133|  92.1k|  OPENSSL_free(sk);
  134|  92.1k|}
sk_pop_free_ex:
  137|  33.7k|                    OPENSSL_sk_free_func free_func) {
  138|  33.7k|  if (sk == NULL) {
  ------------------
  |  Branch (138:7): [True: 0, False: 33.7k]
  ------------------
  139|      0|    return;
  140|      0|  }
  141|       |
  142|   154k|  for (size_t i = 0; i < sk->num; i++) {
  ------------------
  |  Branch (142:22): [True: 120k, False: 33.7k]
  ------------------
  143|   120k|    if (sk->data[i] != NULL) {
  ------------------
  |  Branch (143:9): [True: 119k, False: 1.65k]
  ------------------
  144|   119k|      call_free_func(free_func, sk->data[i]);
  145|   119k|    }
  146|   120k|  }
  147|  33.7k|  sk_free(sk);
  148|  33.7k|}
sk_insert:
  161|   155k|size_t sk_insert(_STACK *sk, void *p, size_t where) {
  162|   155k|  if (sk == NULL) {
  ------------------
  |  Branch (162:7): [True: 0, False: 155k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|   155k|  if (sk->num >= INT_MAX) {
  ------------------
  |  Branch (166:7): [True: 0, False: 155k]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|   155k|  if (sk->num_alloc <= sk->num + 1) {
  ------------------
  |  Branch (171:7): [True: 7.48k, False: 147k]
  ------------------
  172|       |    // Attempt to double the size of the array.
  173|  7.48k|    size_t new_alloc = sk->num_alloc << 1;
  174|  7.48k|    size_t alloc_size = new_alloc * sizeof(void *);
  175|  7.48k|    void **data;
  176|       |
  177|       |    // If the doubling overflowed, try to increment.
  178|  7.48k|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (178:9): [True: 0, False: 7.48k]
  |  Branch (178:38): [True: 0, False: 7.48k]
  ------------------
  179|      0|      new_alloc = sk->num_alloc + 1;
  180|      0|      alloc_size = new_alloc * sizeof(void *);
  181|      0|    }
  182|       |
  183|       |    // If the increment also overflowed, fail.
  184|  7.48k|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 7.48k]
  |  Branch (184:38): [True: 0, False: 7.48k]
  ------------------
  185|      0|      return 0;
  186|      0|    }
  187|       |
  188|  7.48k|    data = OPENSSL_realloc(sk->data, alloc_size);
  189|  7.48k|    if (data == NULL) {
  ------------------
  |  Branch (189:9): [True: 0, False: 7.48k]
  ------------------
  190|      0|      return 0;
  191|      0|    }
  192|       |
  193|  7.48k|    sk->data = data;
  194|  7.48k|    sk->num_alloc = new_alloc;
  195|  7.48k|  }
  196|       |
  197|   155k|  if (where >= sk->num) {
  ------------------
  |  Branch (197:7): [True: 155k, False: 0]
  ------------------
  198|   155k|    sk->data[sk->num] = p;
  199|   155k|  } else {
  200|      0|    OPENSSL_memmove(&sk->data[where + 1], &sk->data[where],
  201|      0|                    sizeof(void *) * (sk->num - where));
  202|      0|    sk->data[where] = p;
  203|      0|  }
  204|       |
  205|   155k|  sk->num++;
  206|   155k|  sk->sorted = 0;
  207|       |
  208|   155k|  return sk->num;
  209|   155k|}
sk_push:
  340|   155k|size_t sk_push(_STACK *sk, void *p) { return (sk_insert(sk, p, sk->num)); }

CRYPTO_MUTEX_init:
   31|  6.03k|void CRYPTO_MUTEX_init(CRYPTO_MUTEX *lock) {
   32|  6.03k|  if (pthread_rwlock_init((pthread_rwlock_t *) lock, NULL) != 0) {
  ------------------
  |  Branch (32:7): [True: 0, False: 6.03k]
  ------------------
   33|      0|    abort();
   34|      0|  }
   35|  6.03k|}
CRYPTO_MUTEX_cleanup:
   61|  6.03k|void CRYPTO_MUTEX_cleanup(CRYPTO_MUTEX *lock) {
   62|  6.03k|  pthread_rwlock_destroy((pthread_rwlock_t *) lock);
   63|  6.03k|}
CRYPTO_STATIC_MUTEX_lock_read:
   65|  2.82k|void CRYPTO_STATIC_MUTEX_lock_read(struct CRYPTO_STATIC_MUTEX *lock) {
   66|  2.82k|  if (pthread_rwlock_rdlock(&lock->lock) != 0) {
  ------------------
  |  Branch (66:7): [True: 0, False: 2.82k]
  ------------------
   67|      0|    abort();
   68|      0|  }
   69|  2.82k|}
CRYPTO_STATIC_MUTEX_lock_write:
   71|    516|void CRYPTO_STATIC_MUTEX_lock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   72|    516|  if (pthread_rwlock_wrlock(&lock->lock) != 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 516]
  ------------------
   73|      0|    abort();
   74|      0|  }
   75|    516|}
CRYPTO_STATIC_MUTEX_unlock_read:
   77|  2.82k|void CRYPTO_STATIC_MUTEX_unlock_read(struct CRYPTO_STATIC_MUTEX *lock) {
   78|  2.82k|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (78:7): [True: 0, False: 2.82k]
  ------------------
   79|      0|    abort();
   80|      0|  }
   81|  2.82k|}
CRYPTO_STATIC_MUTEX_unlock_write:
   83|    516|void CRYPTO_STATIC_MUTEX_unlock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   84|    516|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (84:7): [True: 0, False: 516]
  ------------------
   85|      0|    abort();
   86|      0|  }
   87|    516|}
CRYPTO_once:
   89|  25.3k|void CRYPTO_once(CRYPTO_once_t *once, void (*init)(void)) {
   90|  25.3k|  if (pthread_once(once, init) != 0) {
  ------------------
  |  Branch (90:7): [True: 0, False: 25.3k]
  ------------------
   91|      0|    abort();
   92|      0|  }
   93|  25.3k|}
CRYPTO_get_thread_local:
  132|  23.4k|void *CRYPTO_get_thread_local(thread_local_data_t index) {
  133|  23.4k|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  134|  23.4k|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (134:7): [True: 0, False: 23.4k]
  ------------------
  135|      0|    return NULL;
  136|      0|  }
  137|       |
  138|  23.4k|  void **pointers = pthread_getspecific(g_thread_local_key);
  139|  23.4k|  if (pointers == NULL) {
  ------------------
  |  Branch (139:7): [True: 1, False: 23.4k]
  ------------------
  140|      1|    return NULL;
  141|      1|  }
  142|  23.4k|  return pointers[index];
  143|  23.4k|}
CRYPTO_set_thread_local:
  146|      1|                            thread_local_destructor_t destructor) {
  147|      1|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  148|      1|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (148:7): [True: 0, False: 1]
  ------------------
  149|      0|    destructor(value);
  150|      0|    return 0;
  151|      0|  }
  152|       |
  153|      1|  void **pointers = pthread_getspecific(g_thread_local_key);
  154|      1|  if (pointers == NULL) {
  ------------------
  |  Branch (154:7): [True: 1, False: 0]
  ------------------
  155|      1|    pointers = malloc(sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  156|      1|    if (pointers == NULL) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1]
  ------------------
  157|      0|      destructor(value);
  158|      0|      return 0;
  159|      0|    }
  160|      1|    OPENSSL_memset(pointers, 0, sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  161|      1|    if (pthread_setspecific(g_thread_local_key, pointers) != 0) {
  ------------------
  |  Branch (161:9): [True: 0, False: 1]
  ------------------
  162|      0|      free(pointers);
  163|      0|      destructor(value);
  164|      0|      return 0;
  165|      0|    }
  166|      1|  }
  167|       |
  168|      1|  if (pthread_mutex_lock(&g_destructors_lock) != 0) {
  ------------------
  |  Branch (168:7): [True: 0, False: 1]
  ------------------
  169|      0|    destructor(value);
  170|      0|    return 0;
  171|      0|  }
  172|      1|  g_destructors[index] = destructor;
  173|      1|  pthread_mutex_unlock(&g_destructors_lock);
  174|       |
  175|      1|  pointers[index] = value;
  176|      1|  return 1;
  177|      1|}
thread_pthread.c:thread_local_init:
  127|      1|static void thread_local_init(void) {
  128|      1|  g_thread_local_key_created =
  129|      1|      pthread_key_create(&g_thread_local_key, thread_local_destructor) == 0;
  130|      1|}

X509_get_pubkey:
  236|  2.09k|EVP_PKEY *X509_get_pubkey(X509 *x) {
  237|  2.09k|  if ((x == NULL) || (x->cert_info == NULL)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 2.09k]
  |  Branch (237:22): [True: 0, False: 2.09k]
  ------------------
  238|      0|    return NULL;
  239|      0|  }
  240|  2.09k|  return (X509_PUBKEY_get(x->cert_info->key));
  241|  2.09k|}

x_name.c:x509_name_ex_new:
  136|  16.5k|static int x509_name_ex_new(ASN1_VALUE **val, const ASN1_ITEM *it) {
  137|  16.5k|  X509_NAME *ret = NULL;
  138|  16.5k|  ret = OPENSSL_malloc(sizeof(X509_NAME));
  139|  16.5k|  if (!ret) {
  ------------------
  |  Branch (139:7): [True: 0, False: 16.5k]
  ------------------
  140|      0|    goto memerr;
  141|      0|  }
  142|  16.5k|  if ((ret->entries = sk_X509_NAME_ENTRY_new_null()) == NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 16.5k]
  ------------------
  143|      0|    goto memerr;
  144|      0|  }
  145|  16.5k|  if ((ret->bytes = BUF_MEM_new()) == NULL) {
  ------------------
  |  Branch (145:7): [True: 0, False: 16.5k]
  ------------------
  146|      0|    goto memerr;
  147|      0|  }
  148|  16.5k|  ret->canon_enc = NULL;
  149|  16.5k|  ret->canon_enclen = 0;
  150|  16.5k|  ret->modified = 1;
  151|  16.5k|  *val = (ASN1_VALUE *)ret;
  152|  16.5k|  return 1;
  153|       |
  154|      0|memerr:
  155|      0|  if (ret) {
  ------------------
  |  Branch (155:7): [True: 0, False: 0]
  ------------------
  156|      0|    if (ret->entries) {
  ------------------
  |  Branch (156:9): [True: 0, False: 0]
  ------------------
  157|      0|      sk_X509_NAME_ENTRY_free(ret->entries);
  158|      0|    }
  159|      0|    OPENSSL_free(ret);
  160|      0|  }
  161|      0|  return 0;
  162|  16.5k|}
x_name.c:x509_name_ex_free:
  164|  16.5k|static void x509_name_ex_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  165|  16.5k|  X509_NAME *a;
  166|  16.5k|  if (!pval || !*pval) {
  ------------------
  |  Branch (166:7): [True: 0, False: 16.5k]
  |  Branch (166:16): [True: 0, False: 16.5k]
  ------------------
  167|      0|    return;
  168|      0|  }
  169|  16.5k|  a = (X509_NAME *)*pval;
  170|       |
  171|  16.5k|  BUF_MEM_free(a->bytes);
  172|  16.5k|  sk_X509_NAME_ENTRY_pop_free(a->entries, X509_NAME_ENTRY_free);
  173|  16.5k|  if (a->canon_enc) {
  ------------------
  |  Branch (173:7): [True: 1.12k, False: 15.4k]
  ------------------
  174|  1.12k|    OPENSSL_free(a->canon_enc);
  175|  1.12k|  }
  176|  16.5k|  OPENSSL_free(a);
  177|  16.5k|  *pval = NULL;
  178|  16.5k|}
x_name.c:x509_name_ex_d2i:
  190|  6.59k|                            ASN1_TLC *ctx) {
  191|  6.59k|  const unsigned char *p = *in, *q;
  192|  6.59k|  STACK_OF(STACK_OF_X509_NAME_ENTRY) *intname = NULL;
  ------------------
  |  |   81|  6.59k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  193|  6.59k|  X509_NAME *nm = NULL;
  194|  6.59k|  size_t i, j;
  195|  6.59k|  int ret;
  196|  6.59k|  STACK_OF(X509_NAME_ENTRY) *entries;
  ------------------
  |  |   81|  6.59k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  197|  6.59k|  X509_NAME_ENTRY *entry;
  198|       |  // Bound the size of an X509_NAME we are willing to parse.
  199|  6.59k|  if (len > X509_NAME_MAX) {
  ------------------
  |  |   80|  6.59k|#define X509_NAME_MAX (1024 * 1024)
  ------------------
  |  Branch (199:7): [True: 0, False: 6.59k]
  ------------------
  200|      0|    len = X509_NAME_MAX;
  ------------------
  |  |   80|      0|#define X509_NAME_MAX (1024 * 1024)
  ------------------
  201|      0|  }
  202|  6.59k|  q = p;
  203|       |
  204|       |  // Get internal representation of Name
  205|  6.59k|  ASN1_VALUE *intname_val = NULL;
  206|  6.59k|  ret = ASN1_item_ex_d2i(&intname_val, &p, len,
  207|  6.59k|                         ASN1_ITEM_rptr(X509_NAME_INTERNAL), /*tag=*/-1,
  ------------------
  |  |  274|  6.59k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  208|  6.59k|                         /*aclass=*/0, opt, /*buf=*/NULL);
  209|  6.59k|  if (ret <= 0) {
  ------------------
  |  Branch (209:7): [True: 270, False: 6.32k]
  ------------------
  210|    270|    return ret;
  211|    270|  }
  212|  6.32k|  intname = (STACK_OF(STACK_OF_X509_NAME_ENTRY) *)intname_val;
  213|       |
  214|  6.32k|  if (*val) {
  ------------------
  |  Branch (214:7): [True: 6.32k, False: 0]
  ------------------
  215|  6.32k|    x509_name_ex_free(val, NULL);
  216|  6.32k|  }
  217|  6.32k|  ASN1_VALUE *nm_val = NULL;
  218|  6.32k|  if (!x509_name_ex_new(&nm_val, NULL)) {
  ------------------
  |  Branch (218:7): [True: 0, False: 6.32k]
  ------------------
  219|      0|    goto err;
  220|      0|  }
  221|  6.32k|  nm = (X509_NAME *)nm_val;
  222|       |  // We've decoded it: now cache encoding
  223|  6.32k|  if (!BUF_MEM_grow(nm->bytes, p - q)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 6.32k]
  ------------------
  224|      0|    goto err;
  225|      0|  }
  226|  6.32k|  OPENSSL_memcpy(nm->bytes->data, q, p - q);
  227|       |
  228|       |  // Convert internal representation to X509_NAME structure
  229|  55.4k|  for (i = 0; i < sk_STACK_OF_X509_NAME_ENTRY_num(intname); i++) {
  ------------------
  |  Branch (229:15): [True: 49.1k, False: 6.32k]
  ------------------
  230|  49.1k|    entries = sk_STACK_OF_X509_NAME_ENTRY_value(intname, i);
  231|  72.1k|    for (j = 0; j < sk_X509_NAME_ENTRY_num(entries); j++) {
  ------------------
  |  Branch (231:17): [True: 22.9k, False: 49.1k]
  ------------------
  232|  22.9k|      entry = sk_X509_NAME_ENTRY_value(entries, j);
  233|  22.9k|      entry->set = (int)i;
  234|  22.9k|      if (!sk_X509_NAME_ENTRY_push(nm->entries, entry)) {
  ------------------
  |  Branch (234:11): [True: 0, False: 22.9k]
  ------------------
  235|      0|        goto err;
  236|      0|      }
  237|  22.9k|      (void)sk_X509_NAME_ENTRY_set(entries, j, NULL);
  238|  22.9k|    }
  239|  49.1k|  }
  240|  6.32k|  ret = x509_name_canon(nm);
  241|  6.32k|  if (!ret) {
  ------------------
  |  Branch (241:7): [True: 38, False: 6.28k]
  ------------------
  242|     38|    goto err;
  243|     38|  }
  244|  6.28k|  sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname, local_sk_X509_NAME_ENTRY_free);
  245|  6.28k|  nm->modified = 0;
  246|  6.28k|  *val = (ASN1_VALUE *)nm;
  247|  6.28k|  *in = p;
  248|  6.28k|  return ret;
  249|     38|err:
  250|     38|  X509_NAME_free(nm);
  251|     38|  sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname,
  252|     38|                                       local_sk_X509_NAME_ENTRY_pop_free);
  253|     38|  OPENSSL_PUT_ERROR(X509, ERR_R_ASN1_LIB);
  ------------------
  |  |  441|     38|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  254|     38|  return 0;
  255|  6.32k|}
x_name.c:x509_name_canon:
  331|  6.32k|static int x509_name_canon(X509_NAME *a) {
  332|  6.32k|  unsigned char *p;
  333|  6.32k|  STACK_OF(STACK_OF_X509_NAME_ENTRY) *intname = NULL;
  ------------------
  |  |   81|  6.32k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  334|  6.32k|  STACK_OF(X509_NAME_ENTRY) *entries = NULL;
  ------------------
  |  |   81|  6.32k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  335|  6.32k|  X509_NAME_ENTRY *entry, *tmpentry = NULL;
  336|  6.32k|  int set = -1, ret = 0, len;
  337|  6.32k|  size_t i;
  338|       |
  339|  6.32k|  if (a->canon_enc) {
  ------------------
  |  Branch (339:7): [True: 0, False: 6.32k]
  ------------------
  340|      0|    OPENSSL_free(a->canon_enc);
  341|      0|    a->canon_enc = NULL;
  342|      0|  }
  343|       |  // Special case: empty X509_NAME => null encoding
  344|  6.32k|  if (sk_X509_NAME_ENTRY_num(a->entries) == 0) {
  ------------------
  |  Branch (344:7): [True: 5.16k, False: 1.16k]
  ------------------
  345|  5.16k|    a->canon_enclen = 0;
  346|  5.16k|    return 1;
  347|  5.16k|  }
  348|  1.16k|  intname = sk_STACK_OF_X509_NAME_ENTRY_new_null();
  349|  1.16k|  if (!intname) {
  ------------------
  |  Branch (349:7): [True: 0, False: 1.16k]
  ------------------
  350|      0|    goto err;
  351|      0|  }
  352|  23.9k|  for (i = 0; i < sk_X509_NAME_ENTRY_num(a->entries); i++) {
  ------------------
  |  Branch (352:15): [True: 22.8k, False: 1.12k]
  ------------------
  353|  22.8k|    entry = sk_X509_NAME_ENTRY_value(a->entries, i);
  354|  22.8k|    if (entry->set != set) {
  ------------------
  |  Branch (354:9): [True: 7.21k, False: 15.5k]
  ------------------
  355|  7.21k|      entries = sk_X509_NAME_ENTRY_new_null();
  356|  7.21k|      if (!entries) {
  ------------------
  |  Branch (356:11): [True: 0, False: 7.21k]
  ------------------
  357|      0|        goto err;
  358|      0|      }
  359|  7.21k|      if (!sk_STACK_OF_X509_NAME_ENTRY_push(intname, entries)) {
  ------------------
  |  Branch (359:11): [True: 0, False: 7.21k]
  ------------------
  360|      0|        sk_X509_NAME_ENTRY_free(entries);
  361|      0|        goto err;
  362|      0|      }
  363|  7.21k|      set = entry->set;
  364|  7.21k|    }
  365|  22.8k|    tmpentry = X509_NAME_ENTRY_new();
  366|  22.8k|    if (tmpentry == NULL) {
  ------------------
  |  Branch (366:9): [True: 0, False: 22.8k]
  ------------------
  367|      0|      goto err;
  368|      0|    }
  369|  22.8k|    tmpentry->object = OBJ_dup(entry->object);
  370|  22.8k|    if (!asn1_string_canon(tmpentry->value, entry->value)) {
  ------------------
  |  Branch (370:9): [True: 38, False: 22.7k]
  ------------------
  371|     38|      goto err;
  372|     38|    }
  373|  22.7k|    if (!sk_X509_NAME_ENTRY_push(entries, tmpentry)) {
  ------------------
  |  Branch (373:9): [True: 0, False: 22.7k]
  ------------------
  374|      0|      goto err;
  375|      0|    }
  376|  22.7k|    tmpentry = NULL;
  377|  22.7k|  }
  378|       |
  379|       |  // Finally generate encoding
  380|       |
  381|  1.12k|  len = i2d_name_canon(intname, NULL);
  382|  1.12k|  if (len < 0) {
  ------------------
  |  Branch (382:7): [True: 0, False: 1.12k]
  ------------------
  383|      0|    goto err;
  384|      0|  }
  385|  1.12k|  a->canon_enclen = len;
  386|       |
  387|  1.12k|  p = OPENSSL_malloc(a->canon_enclen);
  388|       |
  389|  1.12k|  if (!p) {
  ------------------
  |  Branch (389:7): [True: 0, False: 1.12k]
  ------------------
  390|      0|    goto err;
  391|      0|  }
  392|       |
  393|  1.12k|  a->canon_enc = p;
  394|       |
  395|  1.12k|  i2d_name_canon(intname, &p);
  396|       |
  397|  1.12k|  ret = 1;
  398|       |
  399|  1.16k|err:
  400|       |
  401|  1.16k|  if (tmpentry) {
  ------------------
  |  Branch (401:7): [True: 38, False: 1.12k]
  ------------------
  402|     38|    X509_NAME_ENTRY_free(tmpentry);
  403|     38|  }
  404|  1.16k|  if (intname) {
  ------------------
  |  Branch (404:7): [True: 1.16k, False: 0]
  ------------------
  405|  1.16k|    sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname,
  406|  1.16k|                                         local_sk_X509_NAME_ENTRY_pop_free);
  407|  1.16k|  }
  408|  1.16k|  return ret;
  409|  1.12k|}
x_name.c:asn1_string_canon:
  418|  22.8k|static int asn1_string_canon(ASN1_STRING *out, ASN1_STRING *in) {
  419|  22.8k|  unsigned char *to, *from;
  420|  22.8k|  int len, i;
  421|       |
  422|       |  // If type not in bitmask just copy string across
  423|  22.8k|  if (!(ASN1_tag2bit(in->type) & ASN1_MASK_CANON)) {
  ------------------
  |  |  414|  22.8k|  (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  175|  22.8k|#define B_ASN1_UTF8STRING 0x2000
  |  |  ------------------
  |  |                 (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  173|  22.8k|#define B_ASN1_BMPSTRING 0x0800
  |  |  ------------------
  |  |                 (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  170|  22.8k|#define B_ASN1_UNIVERSALSTRING 0x0100
  |  |  ------------------
  |  |  415|  22.8k|   B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  161|  22.8k|#define B_ASN1_PRINTABLESTRING 0x0002
  |  |  ------------------
  |  |                  B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  162|  22.8k|#define B_ASN1_T61STRING 0x0004
  |  |  ------------------
  |  |                  B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  165|  22.8k|#define B_ASN1_IA5STRING 0x0010
  |  |  ------------------
  |  |  416|  22.8k|   B_ASN1_VISIBLESTRING)
  |  |  ------------------
  |  |  |  |  168|  22.8k|#define B_ASN1_VISIBLESTRING 0x0040
  |  |  ------------------
  ------------------
  |  Branch (423:7): [True: 20.9k, False: 1.90k]
  ------------------
  424|  20.9k|    if (!ASN1_STRING_copy(out, in)) {
  ------------------
  |  Branch (424:9): [True: 0, False: 20.9k]
  ------------------
  425|      0|      return 0;
  426|      0|    }
  427|  20.9k|    return 1;
  428|  20.9k|  }
  429|       |
  430|  1.90k|  out->type = V_ASN1_UTF8STRING;
  ------------------
  |  |  135|  1.90k|#define V_ASN1_UTF8STRING 12
  ------------------
  431|  1.90k|  out->length = ASN1_STRING_to_UTF8(&out->data, in);
  432|  1.90k|  if (out->length == -1) {
  ------------------
  |  Branch (432:7): [True: 38, False: 1.86k]
  ------------------
  433|     38|    return 0;
  434|     38|  }
  435|       |
  436|  1.86k|  to = out->data;
  437|  1.86k|  from = to;
  438|       |
  439|  1.86k|  len = out->length;
  440|       |
  441|       |  // Convert string in place to canonical form.
  442|       |
  443|       |  // Ignore leading spaces
  444|  3.57k|  while ((len > 0) && OPENSSL_isspace(*from)) {
  ------------------
  |  Branch (444:10): [True: 2.98k, False: 590]
  |  Branch (444:23): [True: 1.71k, False: 1.27k]
  ------------------
  445|  1.71k|    from++;
  446|  1.71k|    len--;
  447|  1.71k|  }
  448|       |
  449|  1.86k|  to = from + len;
  450|       |
  451|       |  // Ignore trailing spaces
  452|  9.89k|  while ((len > 0) && OPENSSL_isspace(to[-1])) {
  ------------------
  |  Branch (452:10): [True: 9.30k, False: 590]
  |  Branch (452:23): [True: 8.03k, False: 1.27k]
  ------------------
  453|  8.03k|    to--;
  454|  8.03k|    len--;
  455|  8.03k|  }
  456|       |
  457|  1.86k|  to = out->data;
  458|       |
  459|  1.86k|  i = 0;
  460|  17.9M|  while (i < len) {
  ------------------
  |  Branch (460:10): [True: 17.9M, False: 1.86k]
  ------------------
  461|       |    // Collapse multiple spaces
  462|  17.9M|    if (OPENSSL_isspace(*from)) {
  ------------------
  |  Branch (462:9): [True: 2.06k, False: 17.9M]
  ------------------
  463|       |      // Copy one space across
  464|  2.06k|      *to++ = ' ';
  465|       |      // Ignore subsequent spaces. Note: don't need to check len here
  466|       |      // because we know the last character is a non-space so we can't
  467|       |      // overflow.
  468|  41.9k|      do {
  469|  41.9k|        from++;
  470|  41.9k|        i++;
  471|  41.9k|      } while (OPENSSL_isspace(*from));
  ------------------
  |  Branch (471:16): [True: 39.8k, False: 2.06k]
  ------------------
  472|  17.9M|    } else {
  473|  17.9M|      *to++ = OPENSSL_tolower(*from);
  474|  17.9M|      from++;
  475|  17.9M|      i++;
  476|  17.9M|    }
  477|  17.9M|  }
  478|       |
  479|  1.86k|  out->length = to - out->data;
  480|       |
  481|  1.86k|  return 1;
  482|  1.90k|}
x_name.c:i2d_name_canon:
  485|  2.24k|                          unsigned char **in) {
  486|  2.24k|  int len, ltmp;
  487|  2.24k|  size_t i;
  488|  2.24k|  ASN1_VALUE *v;
  489|  2.24k|  STACK_OF(ASN1_VALUE) *intname = (STACK_OF(ASN1_VALUE) *)_intname;
  ------------------
  |  |   81|  2.24k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  490|       |
  491|  2.24k|  len = 0;
  492|  15.4k|  for (i = 0; i < sk_ASN1_VALUE_num(intname); i++) {
  ------------------
  |  Branch (492:15): [True: 13.1k, False: 2.24k]
  ------------------
  493|  13.1k|    v = sk_ASN1_VALUE_value(intname, i);
  494|  13.1k|    ltmp = ASN1_item_ex_i2d(&v, in, ASN1_ITEM_rptr(X509_NAME_ENTRIES),
  ------------------
  |  |  274|  13.1k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  495|  13.1k|                            /*tag=*/-1, /*aclass=*/0);
  496|  13.1k|    if (ltmp < 0) {
  ------------------
  |  Branch (496:9): [True: 0, False: 13.1k]
  ------------------
  497|      0|      return ltmp;
  498|      0|    }
  499|  13.1k|    len += ltmp;
  500|  13.1k|  }
  501|  2.24k|  return len;
  502|  2.24k|}
x_name.c:local_sk_X509_NAME_ENTRY_free:
  180|  47.3k|static void local_sk_X509_NAME_ENTRY_free(STACK_OF(X509_NAME_ENTRY) *ne) {
  181|  47.3k|  sk_X509_NAME_ENTRY_free(ne);
  182|  47.3k|}
x_name.c:local_sk_X509_NAME_ENTRY_pop_free:
  184|  8.95k|static void local_sk_X509_NAME_ENTRY_pop_free(STACK_OF(X509_NAME_ENTRY) *ne) {
  185|  8.95k|  sk_X509_NAME_ENTRY_pop_free(ne, X509_NAME_ENTRY_free);
  186|  8.95k|}

X509_PUBKEY_get:
  133|  2.09k|EVP_PKEY *X509_PUBKEY_get(X509_PUBKEY *key) {
  134|  2.09k|  EVP_PKEY *ret = NULL;
  135|  2.09k|  uint8_t *spki = NULL;
  136|       |
  137|  2.09k|  if (key == NULL) {
  ------------------
  |  Branch (137:7): [True: 0, False: 2.09k]
  ------------------
  138|      0|    goto error;
  139|      0|  }
  140|       |
  141|  2.09k|  CRYPTO_STATIC_MUTEX_lock_read(&g_pubkey_lock);
  142|  2.09k|  if (key->pkey != NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 2.09k]
  ------------------
  143|      0|    CRYPTO_STATIC_MUTEX_unlock_read(&g_pubkey_lock);
  144|      0|    EVP_PKEY_up_ref(key->pkey);
  145|      0|    return key->pkey;
  146|      0|  }
  147|  2.09k|  CRYPTO_STATIC_MUTEX_unlock_read(&g_pubkey_lock);
  148|       |
  149|       |  // Re-encode the |X509_PUBKEY| to DER and parse it.
  150|  2.09k|  int spki_len = i2d_X509_PUBKEY(key, &spki);
  151|  2.09k|  if (spki_len < 0) {
  ------------------
  |  Branch (151:7): [True: 0, False: 2.09k]
  ------------------
  152|      0|    goto error;
  153|      0|  }
  154|  2.09k|  CBS cbs;
  155|  2.09k|  CBS_init(&cbs, spki, (size_t)spki_len);
  156|  2.09k|  ret = EVP_parse_public_key(&cbs);
  157|  2.09k|  if (ret == NULL || CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (157:7): [True: 1.57k, False: 512]
  |  Branch (157:22): [True: 0, False: 512]
  ------------------
  158|  1.57k|    OPENSSL_PUT_ERROR(X509, X509_R_PUBLIC_KEY_DECODE_ERROR);
  ------------------
  |  |  441|  1.57k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  159|  1.57k|    goto error;
  160|  1.57k|  }
  161|       |
  162|       |  // Check to see if another thread set key->pkey first
  163|    512|  CRYPTO_STATIC_MUTEX_lock_write(&g_pubkey_lock);
  164|    512|  if (key->pkey) {
  ------------------
  |  Branch (164:7): [True: 0, False: 512]
  ------------------
  165|      0|    CRYPTO_STATIC_MUTEX_unlock_write(&g_pubkey_lock);
  166|      0|    EVP_PKEY_free(ret);
  167|      0|    ret = key->pkey;
  168|    512|  } else {
  169|    512|    key->pkey = ret;
  170|    512|    CRYPTO_STATIC_MUTEX_unlock_write(&g_pubkey_lock);
  171|    512|  }
  172|       |
  173|    512|  OPENSSL_free(spki);
  174|    512|  EVP_PKEY_up_ref(ret);
  175|    512|  return ret;
  176|       |
  177|  1.57k|error:
  178|  1.57k|  OPENSSL_free(spki);
  179|  1.57k|  EVP_PKEY_free(ret);
  180|  1.57k|  return NULL;
  181|  2.09k|}
x_pubkey.c:pubkey_cb:
   75|  25.4k|                     void *exarg) {
   76|  25.4k|  if (operation == ASN1_OP_FREE_POST) {
  ------------------
  |  |  540|  25.4k|#define ASN1_OP_FREE_POST	3
  ------------------
  |  Branch (76:7): [True: 5.12k, False: 20.2k]
  ------------------
   77|  5.12k|    X509_PUBKEY *pubkey = (X509_PUBKEY *)*pval;
   78|  5.12k|    EVP_PKEY_free(pubkey->pkey);
   79|  5.12k|  }
   80|  25.4k|  return 1;
   81|  25.4k|}

X509_free:
  126|  9.41k|void X509_free(X509 *x509) {
  127|  9.41k|  if (x509 == NULL || !CRYPTO_refcount_dec_and_test_zero(&x509->references)) {
  ------------------
  |  Branch (127:7): [True: 4.28k, False: 5.12k]
  |  Branch (127:23): [True: 0, False: 5.12k]
  ------------------
  128|  4.28k|    return;
  129|  4.28k|  }
  130|       |
  131|  5.12k|  CRYPTO_free_ex_data(&g_ex_data_class, x509, &x509->ex_data);
  132|       |
  133|  5.12k|  X509_CINF_free(x509->cert_info);
  134|  5.12k|  X509_ALGOR_free(x509->sig_alg);
  135|  5.12k|  ASN1_BIT_STRING_free(x509->signature);
  136|  5.12k|  ASN1_OCTET_STRING_free(x509->skid);
  137|  5.12k|  AUTHORITY_KEYID_free(x509->akid);
  138|  5.12k|  CRL_DIST_POINTS_free(x509->crldp);
  139|  5.12k|  GENERAL_NAMES_free(x509->altname);
  140|  5.12k|  NAME_CONSTRAINTS_free(x509->nc);
  141|  5.12k|  X509_CERT_AUX_free(x509->aux);
  142|  5.12k|  CRYPTO_MUTEX_cleanup(&x509->lock);
  143|       |
  144|  5.12k|  OPENSSL_free(x509);
  145|  5.12k|}
d2i_X509:
  237|  6.37k|X509 *d2i_X509(X509 **out, const uint8_t **inp, long len) {
  238|  6.37k|  X509 *ret = NULL;
  239|  6.37k|  if (len < 0) {
  ------------------
  |  Branch (239:7): [True: 0, False: 6.37k]
  ------------------
  240|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_BUFFER_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  241|      0|    goto err;
  242|      0|  }
  243|       |
  244|  6.37k|  CBS cbs;
  245|  6.37k|  CBS_init(&cbs, *inp, (size_t)len);
  246|  6.37k|  ret = x509_parse(&cbs, NULL);
  247|  6.37k|  if (ret == NULL) {
  ------------------
  |  Branch (247:7): [True: 4.28k, False: 2.09k]
  ------------------
  248|  4.28k|    goto err;
  249|  4.28k|  }
  250|       |
  251|  2.09k|  *inp = CBS_data(&cbs);
  252|       |
  253|  6.37k|err:
  254|  6.37k|  if (out != NULL) {
  ------------------
  |  Branch (254:7): [True: 0, False: 6.37k]
  ------------------
  255|      0|    X509_free(*out);
  256|      0|    *out = ret;
  257|      0|  }
  258|  6.37k|  return ret;
  259|  2.09k|}
i2d_X509:
  261|  2.09k|int i2d_X509(X509 *x509, uint8_t **outp) {
  262|  2.09k|  if (x509 == NULL) {
  ------------------
  |  Branch (262:7): [True: 0, False: 2.09k]
  ------------------
  263|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  264|      0|    return -1;
  265|      0|  }
  266|       |
  267|  2.09k|  CBB cbb, cert;
  268|  2.09k|  if (!CBB_init(&cbb, 64) ||  //
  ------------------
  |  Branch (268:7): [True: 0, False: 2.09k]
  ------------------
  269|  2.09k|      !CBB_add_asn1(&cbb, &cert, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  2.09k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  2.09k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  2.09k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (269:7): [True: 0, False: 2.09k]
  ------------------
  270|      0|    goto err;
  271|      0|  }
  272|       |
  273|       |  // TODO(crbug.com/boringssl/443): When the rest of the library is decoupled
  274|       |  // from the tasn_*.c implementation, replace this with |CBS|-based functions.
  275|  2.09k|  uint8_t *out;
  276|  2.09k|  int len = i2d_X509_CINF(x509->cert_info, NULL);
  277|  2.09k|  if (len < 0 ||  //
  ------------------
  |  Branch (277:7): [True: 0, False: 2.09k]
  ------------------
  278|  2.09k|      !CBB_add_space(&cert, &out, (size_t)len) ||
  ------------------
  |  Branch (278:7): [True: 0, False: 2.09k]
  ------------------
  279|  2.09k|      i2d_X509_CINF(x509->cert_info, &out) != len) {
  ------------------
  |  Branch (279:7): [True: 0, False: 2.09k]
  ------------------
  280|      0|    goto err;
  281|      0|  }
  282|       |
  283|  2.09k|  len = i2d_X509_ALGOR(x509->sig_alg, NULL);
  284|  2.09k|  if (len < 0 ||  //
  ------------------
  |  Branch (284:7): [True: 0, False: 2.09k]
  ------------------
  285|  2.09k|      !CBB_add_space(&cert, &out, (size_t)len) ||
  ------------------
  |  Branch (285:7): [True: 0, False: 2.09k]
  ------------------
  286|  2.09k|      i2d_X509_ALGOR(x509->sig_alg, &out) != len) {
  ------------------
  |  Branch (286:7): [True: 0, False: 2.09k]
  ------------------
  287|      0|    goto err;
  288|      0|  }
  289|       |
  290|  2.09k|  len = i2d_ASN1_BIT_STRING(x509->signature, NULL);
  291|  2.09k|  if (len < 0 ||  //
  ------------------
  |  Branch (291:7): [True: 0, False: 2.09k]
  ------------------
  292|  2.09k|      !CBB_add_space(&cert, &out, (size_t)len) ||
  ------------------
  |  Branch (292:7): [True: 0, False: 2.09k]
  ------------------
  293|  2.09k|      i2d_ASN1_BIT_STRING(x509->signature, &out) != len) {
  ------------------
  |  Branch (293:7): [True: 0, False: 2.09k]
  ------------------
  294|      0|    goto err;
  295|      0|  }
  296|       |
  297|  2.09k|  return CBB_finish_i2d(&cbb, outp);
  298|       |
  299|      0|err:
  300|      0|  CBB_cleanup(&cbb);
  301|      0|  return -1;
  302|  2.09k|}
x_x509.c:x509_new_null:
   94|  5.12k|static X509 *x509_new_null(void) {
   95|  5.12k|  X509 *ret = OPENSSL_malloc(sizeof(X509));
   96|  5.12k|  if (ret == NULL) {
  ------------------
  |  Branch (96:7): [True: 0, False: 5.12k]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|  5.12k|  OPENSSL_memset(ret, 0, sizeof(X509));
  100|       |
  101|  5.12k|  ret->references = 1;
  102|  5.12k|  ret->ex_pathlen = -1;
  103|  5.12k|  CRYPTO_new_ex_data(&ret->ex_data);
  104|  5.12k|  CRYPTO_MUTEX_init(&ret->lock);
  105|  5.12k|  return ret;
  106|  5.12k|}
x_x509.c:x509_parse:
  147|  6.37k|static X509 *x509_parse(CBS *cbs, CRYPTO_BUFFER *buf) {
  148|  6.37k|  CBS cert, tbs, sigalg, sig;
  149|  6.37k|  if (!CBS_get_asn1(cbs, &cert, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  6.37k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  6.37k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  6.37k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (149:7): [True: 833, False: 5.54k]
  ------------------
  150|       |      // Bound the length to comfortably fit in an int. Lengths in this
  151|       |      // module often omit overflow checks.
  152|  6.37k|      CBS_len(&cert) > INT_MAX / 2 ||
  ------------------
  |  Branch (152:7): [True: 0, False: 5.54k]
  ------------------
  153|  6.37k|      !CBS_get_asn1_element(&cert, &tbs, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  5.54k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  5.54k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  5.54k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (153:7): [True: 282, False: 5.26k]
  ------------------
  154|  6.37k|      !CBS_get_asn1_element(&cert, &sigalg, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  5.26k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  5.26k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  5.26k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (154:7): [True: 22, False: 5.24k]
  ------------------
  155|  1.13k|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_DECODE_ERROR);
  ------------------
  |  |  441|  1.13k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|  1.13k|    return NULL;
  157|  1.13k|  }
  158|       |
  159|       |  // For just the signature field, we accept non-minimal BER lengths, though not
  160|       |  // indefinite-length encoding. See b/18228011.
  161|       |  //
  162|       |  // TODO(crbug.com/boringssl/354): Switch the affected callers to convert the
  163|       |  // certificate before parsing and then remove this workaround.
  164|  5.24k|  CBS_ASN1_TAG tag;
  165|  5.24k|  size_t header_len;
  166|  5.24k|  int indefinite;
  167|  5.24k|  if (!CBS_get_any_ber_asn1_element(&cert, &sig, &tag, &header_len,
  ------------------
  |  Branch (167:7): [True: 15, False: 5.22k]
  ------------------
  168|       |                                    /*out_ber_found=*/NULL,
  169|  5.24k|                                    &indefinite) ||
  170|  5.24k|      tag != CBS_ASN1_BITSTRING || indefinite ||  //
  ------------------
  |  |  216|  10.4k|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (170:7): [True: 87, False: 5.14k]
  |  Branch (170:36): [True: 0, False: 5.14k]
  ------------------
  171|  5.24k|      !CBS_skip(&sig, header_len) ||              //
  ------------------
  |  Branch (171:7): [True: 0, False: 5.14k]
  ------------------
  172|  5.24k|      CBS_len(&cert) != 0) {
  ------------------
  |  Branch (172:7): [True: 15, False: 5.12k]
  ------------------
  173|    117|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_DECODE_ERROR);
  ------------------
  |  |  441|    117|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  174|    117|    return NULL;
  175|    117|  }
  176|       |
  177|  5.12k|  X509 *ret = x509_new_null();
  178|  5.12k|  if (ret == NULL) {
  ------------------
  |  Branch (178:7): [True: 0, False: 5.12k]
  ------------------
  179|      0|    return NULL;
  180|      0|  }
  181|       |
  182|       |  // TODO(crbug.com/boringssl/443): When the rest of the library is decoupled
  183|       |  // from the tasn_*.c implementation, replace this with |CBS|-based functions.
  184|  5.12k|  const uint8_t *inp = CBS_data(&tbs);
  185|  5.12k|  if (ASN1_item_ex_d2i((ASN1_VALUE **)&ret->cert_info, &inp, CBS_len(&tbs),
  ------------------
  |  Branch (185:7): [True: 2.70k, False: 2.42k]
  ------------------
  186|  5.12k|                       ASN1_ITEM_rptr(X509_CINF), /*tag=*/-1,
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  187|  5.12k|                       /*aclass=*/0, /*opt=*/0, buf) <= 0 ||
  188|  5.12k|      inp != CBS_data(&tbs) + CBS_len(&tbs)) {
  ------------------
  |  Branch (188:7): [True: 0, False: 2.42k]
  ------------------
  189|  2.70k|    goto err;
  190|  2.70k|  }
  191|       |
  192|  2.42k|  inp = CBS_data(&sigalg);
  193|  2.42k|  ret->sig_alg = d2i_X509_ALGOR(NULL, &inp, CBS_len(&sigalg));
  194|  2.42k|  if (ret->sig_alg == NULL || inp != CBS_data(&sigalg) + CBS_len(&sigalg)) {
  ------------------
  |  Branch (194:7): [True: 57, False: 2.36k]
  |  Branch (194:31): [True: 0, False: 2.36k]
  ------------------
  195|     57|    goto err;
  196|     57|  }
  197|       |
  198|  2.36k|  inp = CBS_data(&sig);
  199|  2.36k|  ret->signature = c2i_ASN1_BIT_STRING(NULL, &inp, CBS_len(&sig));
  200|  2.36k|  if (ret->signature == NULL || inp != CBS_data(&sig) + CBS_len(&sig)) {
  ------------------
  |  Branch (200:7): [True: 35, False: 2.33k]
  |  Branch (200:33): [True: 0, False: 2.33k]
  ------------------
  201|     35|    goto err;
  202|     35|  }
  203|       |
  204|       |  // The version must be one of v1(0), v2(1), or v3(2).
  205|  2.33k|  long version = X509_VERSION_1;
  ------------------
  |  |  168|  2.33k|#define X509_VERSION_1 0
  ------------------
  206|  2.33k|  if (ret->cert_info->version != NULL) {
  ------------------
  |  Branch (206:7): [True: 241, False: 2.09k]
  ------------------
  207|    241|    version = ASN1_INTEGER_get(ret->cert_info->version);
  208|       |    // TODO(https://crbug.com/boringssl/364): |X509_VERSION_1| should
  209|       |    // also be rejected here. This means an explicitly-encoded X.509v1
  210|       |    // version. v1 is DEFAULT, so DER requires it be omitted.
  211|    241|    if (version < X509_VERSION_1 || version > X509_VERSION_3) {
  ------------------
  |  |  168|    482|#define X509_VERSION_1 0
  ------------------
                  if (version < X509_VERSION_1 || version > X509_VERSION_3) {
  ------------------
  |  |  170|     70|#define X509_VERSION_3 2
  ------------------
  |  Branch (211:9): [True: 171, False: 70]
  |  Branch (211:37): [True: 67, False: 3]
  ------------------
  212|    238|      OPENSSL_PUT_ERROR(X509, X509_R_INVALID_VERSION);
  ------------------
  |  |  441|    238|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|    238|      goto err;
  214|    238|    }
  215|    241|  }
  216|       |
  217|       |  // Per RFC 5280, section 4.1.2.8, these fields require v2 or v3.
  218|  2.09k|  if (version == X509_VERSION_1 && (ret->cert_info->issuerUID != NULL ||
  ------------------
  |  |  168|  4.19k|#define X509_VERSION_1 0
  ------------------
  |  Branch (218:7): [True: 2.09k, False: 2]
  |  Branch (218:37): [True: 2, False: 2.09k]
  ------------------
  219|  2.09k|                                    ret->cert_info->subjectUID != NULL)) {
  ------------------
  |  Branch (219:37): [True: 1, False: 2.09k]
  ------------------
  220|      3|    OPENSSL_PUT_ERROR(X509, X509_R_INVALID_FIELD_FOR_VERSION);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  221|      3|    goto err;
  222|      3|  }
  223|       |
  224|       |  // Per RFC 5280, section 4.1.2.9, extensions require v3.
  225|  2.09k|  if (version != X509_VERSION_3 && ret->cert_info->extensions != NULL) {
  ------------------
  |  |  170|  4.18k|#define X509_VERSION_3 2
  ------------------
  |  Branch (225:7): [True: 2.09k, False: 1]
  |  Branch (225:36): [True: 1, False: 2.09k]
  ------------------
  226|      1|    OPENSSL_PUT_ERROR(X509, X509_R_INVALID_FIELD_FOR_VERSION);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  227|      1|    goto err;
  228|      1|  }
  229|       |
  230|  2.09k|  return ret;
  231|       |
  232|  3.03k|err:
  233|  3.03k|  X509_free(ret);
  234|  3.03k|  return NULL;
  235|  2.09k|}

X509_NAME_ENTRY_new:
  603|  22.8k|	{ \
  604|  22.8k|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  22.8k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|  22.8k|	} \
X509_NAME_ENTRY_free:
  607|  45.7k|	{ \
  608|  45.7k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  45.7k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  45.7k|	}
X509_NAME_free:
  607|     38|	{ \
  608|     38|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|     38|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|     38|	}
i2d_X509_PUBKEY:
  634|  2.09k|	{ \
  635|  2.09k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  2.09k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  636|  2.09k|	}
i2d_X509_CINF:
  621|  4.18k|	{ \
  622|  4.18k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  4.18k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  623|  4.18k|	} 
X509_CINF_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}
X509_CERT_AUX_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}
AUTHORITY_KEYID_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}
CRL_DIST_POINTS_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}
GENERAL_NAMES_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}
NAME_CONSTRAINTS_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}
i2d_ASN1_BIT_STRING:
  634|  4.18k|	{ \
  635|  4.18k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  4.18k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  636|  4.18k|	}
ASN1_TYPE_new:
  603|  2.80k|	{ \
  604|  2.80k|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  2.80k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|  2.80k|	} \
ASN1_TYPE_free:
  607|    647|	{ \
  608|    647|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    647|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    647|	}
d2i_X509_ALGOR:
  630|  2.42k|	{ \
  631|  2.42k|		return (stname *)ASN1_item_d2i((ASN1_VALUE **)a, in, len, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  2.42k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  632|  2.42k|	} \
i2d_X509_ALGOR:
  634|  4.18k|	{ \
  635|  4.18k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  4.18k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  636|  4.18k|	}
X509_ALGOR_free:
  607|  5.12k|	{ \
  608|  5.12k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  5.12k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  5.12k|	}

bcm.c:ERR_GET_LIB:
  166|    203|OPENSSL_INLINE int ERR_GET_LIB(uint32_t packed_error) {
  167|    203|  return (int)((packed_error >> 24) & 0xff);
  168|    203|}
bcm.c:ERR_GET_REASON:
  173|    203|OPENSSL_INLINE int ERR_GET_REASON(uint32_t packed_error) {
  174|    203|  return (int)(packed_error & 0xfff);
  175|    203|}

x_name.c:sk_X509_NAME_ENTRY_new_null:
  420|  23.7k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  23.7k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  23.7k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_free:
  442|  47.3k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  47.3k|    sk_free((_STACK *)sk);                                                    \
  444|  47.3k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_pop_free:
  447|  25.5k|                                           sk_##name##_free_func free_func) { \
  448|  25.5k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  25.5k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  25.5k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_call_free_func:
  391|  45.7k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  45.7k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  45.7k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_num:
  424|  55.4k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  55.4k|    return sk_num((const _STACK *)sk);                                        \
  426|  55.4k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_value:
  433|  49.1k|                                           size_t i) {                        \
  434|  49.1k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  49.1k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_num:
  424|   102k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|   102k|    return sk_num((const _STACK *)sk);                                        \
  426|   102k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_value:
  433|  45.7k|                                           size_t i) {                        \
  434|  45.7k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  45.7k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_push:
  483|  45.7k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  45.7k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  45.7k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_set:
  438|  22.9k|                                         ptrtype p) {                         \
  439|  22.9k|    return (ptrtype)sk_set((_STACK *)sk, i, (void *)p);                       \
  440|  22.9k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_new_null:
  420|  1.16k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  1.16k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  1.16k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_push:
  483|  7.21k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  7.21k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  7.21k|  }                                                                           \
x_name.c:sk_ASN1_VALUE_num:
  424|  15.4k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  15.4k|    return sk_num((const _STACK *)sk);                                        \
  426|  15.4k|  }                                                                           \
x_name.c:sk_ASN1_VALUE_value:
  433|  13.1k|                                           size_t i) {                        \
  434|  13.1k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  13.1k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_pop_free:
  447|  7.48k|                                           sk_##name##_free_func free_func) { \
  448|  7.48k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  7.48k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  7.48k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_call_free_func:
  391|  56.3k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  56.3k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  56.3k|  }                                                                           \
bcm.c:sk_BIGNUM_pop_free:
  447|    687|                                           sk_##name##_free_func free_func) { \
  448|    687|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|    687|                   (OPENSSL_sk_free_func)free_func);                          \
  450|    687|  }                                                                           \
bcm.c:sk_BIGNUM_call_free_func:
  391|  17.1k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  17.1k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  17.1k|  }                                                                           \
bcm.c:sk_BIGNUM_new_null:
  420|    687|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|    687|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|    687|  }                                                                           \
bcm.c:sk_BIGNUM_num:
  424|  5.68M|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  5.68M|    return sk_num((const _STACK *)sk);                                        \
  426|  5.68M|  }                                                                           \
bcm.c:sk_BIGNUM_push:
  483|  17.1k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  17.1k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  17.1k|  }                                                                           \
bcm.c:sk_BIGNUM_value:
  433|  5.68M|                                           size_t i) {                        \
  434|  5.68M|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  5.68M|  }                                                                           \
tasn_dec.c:sk_ASN1_VALUE_new_null:
  420|  66.5k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  66.5k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  66.5k|  }                                                                           \
tasn_dec.c:sk_ASN1_VALUE_push:
  483|  85.3k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  85.3k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  85.3k|  }                                                                           \
tasn_enc.c:sk_ASN1_VALUE_num:
  424|   108k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|   108k|    return sk_num((const _STACK *)sk);                                        \
  426|   108k|  }                                                                           \
tasn_enc.c:sk_ASN1_VALUE_value:
  433|  64.0k|                                           size_t i) {                        \
  434|  64.0k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  64.0k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_num:
  424|  42.1k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  42.1k|    return sk_num((const _STACK *)sk);                                        \
  426|  42.1k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_value:
  433|  13.2k|                                           size_t i) {                        \
  434|  13.2k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  13.2k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_free:
  442|  28.8k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  28.8k|    sk_free((_STACK *)sk);                                                    \
  444|  28.8k|  }                                                                           \

_Z17GetVariableIntLenmm:
   22|  40.5k|uint8_t GetVariableIntLen(uint64_t value, size_t base) {
   23|  40.5k|  uint8_t base_bits = log2(base);
   24|   302k|  for (uint8_t num_bits = (sizeof(value) - 1) * CHAR_BIT; num_bits >= base_bits;
  ------------------
  |  Branch (24:59): [True: 278k, False: 23.4k]
  ------------------
   25|   278k|       num_bits -= base_bits) {
   26|   278k|    if (value >> num_bits) {
  ------------------
  |  Branch (26:9): [True: 17.0k, False: 261k]
  ------------------
   27|  17.0k|      return ceil(static_cast<double>(num_bits) / base_bits) + 1;
   28|  17.0k|    }
   29|   278k|  }
   30|       |  // Special-case: zero requires one, not zero bytes.
   31|  23.4k|  return 1;
   32|  40.5k|}
_Z24InsertVariableIntBase128mmRNSt3__16vectorIhNS_9allocatorIhEEEE:
   36|  1.59k|                              std::vector<uint8_t>& der) {
   37|  1.59k|  std::vector<uint8_t> variable_int;
   38|  5.35k|  for (uint8_t i = GetVariableIntLen(value, 128) - 1; i != 0; --i) {
  ------------------
  |  Branch (38:55): [True: 3.75k, False: 1.59k]
  ------------------
   39|       |    // If it's not the last byte, the high bit is set to 1.
   40|  3.75k|    variable_int.push_back((0x01 << 7) | ((value >> (i * 7)) & 0x7F));
   41|  3.75k|  }
   42|  1.59k|  variable_int.push_back(value & 0x7F);
   43|  1.59k|  der.insert(der.begin() + pos, variable_int.begin(), variable_int.end());
   44|  1.59k|}
_Z24InsertVariableIntBase256mmRNSt3__16vectorIhNS_9allocatorIhEEEE:
   48|  28.6k|                              std::vector<uint8_t>& der) {
   49|  28.6k|  std::vector<uint8_t> variable_int;
   50|  67.2k|  for (uint8_t shift = GetVariableIntLen(value, 256); shift != 0; --shift) {
  ------------------
  |  Branch (50:55): [True: 38.5k, False: 28.6k]
  ------------------
   51|  38.5k|    variable_int.push_back((value >> ((shift - 1) * CHAR_BIT)) & 0xFF);
   52|  38.5k|  }
   53|  28.6k|  der.insert(der.begin() + pos, variable_int.begin(), variable_int.end());
   54|  28.6k|}

fuzz_certs.cc:_ZL17TestOneProtoInputRKN8asn1_pdu3PDUE:
   28|  6.37k|DEFINE_PROTO_FUZZER(const asn1_pdu::PDU& asn1) {
   29|  6.37k|  asn1_pdu::ASN1PDUToDER converter;
   30|  6.37k|  std::vector<uint8_t> encoded = converter.PDUToDER(asn1);
   31|  6.37k|  const uint8_t* buf = encoded.data();
   32|  6.37k|  size_t len = encoded.size();
   33|       |
   34|  6.37k|  X509* x509 = d2i_X509(NULL, &buf, len);
   35|  6.37k|  if (x509 != NULL) {
  ------------------
  |  Branch (35:7): [True: 2.09k, False: 4.28k]
  ------------------
   36|       |    // Extract the public key.
   37|  2.09k|    EVP_PKEY_free(X509_get_pubkey(x509));
   38|       |
   39|       |    // Reserialize the structure.
   40|  2.09k|    uint8_t* der = NULL;
   41|  2.09k|    i2d_X509(x509, &der);
   42|  2.09k|    OPENSSL_free(der);
   43|  2.09k|  }
   44|  6.37k|  X509_free(x509);
   45|  6.37k|  ERR_clear_error();
   46|  6.37k|}

_Z42descriptor_table_asn1_5fpdu_2eproto_getterv:
  280|      1|PROTOBUF_ATTRIBUTE_WEAK const ::_pbi::DescriptorTable* descriptor_table_asn1_5fpdu_2eproto_getter() {
  281|      1|  return &descriptor_table_asn1_5fpdu_2eproto;
  282|      1|}
_ZN8asn1_pdu3PDUC2EPN6google8protobuf5ArenaE:
  394|  35.3k|  : ::PROTOBUF_NAMESPACE_ID::Message(arena) {
  395|  35.3k|  SharedCtor(arena);
  396|       |  // @@protoc_insertion_point(arena_constructor:asn1_pdu.PDU)
  397|  35.3k|}
_ZN8asn1_pdu3PDUD2Ev:
  432|  35.3k|PDU::~PDU() {
  433|       |  // @@protoc_insertion_point(destructor:asn1_pdu.PDU)
  434|  35.3k|  if (auto *arena = _internal_metadata_.DeleteReturnArena<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>()) {
  ------------------
  |  Branch (434:13): [True: 0, False: 35.3k]
  ------------------
  435|      0|  (void)arena;
  436|      0|    return;
  437|      0|  }
  438|  35.3k|  SharedDtor();
  439|  35.3k|}
_ZN8asn1_pdu3PDU5ClearEv:
  452|  16.9k|void PDU::Clear() {
  453|       |// @@protoc_insertion_point(message_clear_start:asn1_pdu.PDU)
  454|  16.9k|  ::uint32_t cached_has_bits = 0;
  455|       |  // Prevent compiler warnings about cached_has_bits being unused
  456|  16.9k|  (void) cached_has_bits;
  457|       |
  458|  16.9k|  cached_has_bits = _impl_._has_bits_[0];
  459|  16.9k|  if (cached_has_bits & 0x00000007u) {
  ------------------
  |  Branch (459:7): [True: 3.32k, False: 13.6k]
  ------------------
  460|  3.32k|    if (cached_has_bits & 0x00000001u) {
  ------------------
  |  Branch (460:9): [True: 2.33k, False: 990]
  ------------------
  461|  2.33k|      ABSL_DCHECK(_impl_.id_ != nullptr);
  ------------------
  |  |   43|  2.33k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  2.33k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  2.33k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  2.33k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  2.33k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  2.33k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  462|  2.33k|      _impl_.id_->Clear();
  463|  2.33k|    }
  464|  3.32k|    if (cached_has_bits & 0x00000002u) {
  ------------------
  |  Branch (464:9): [True: 2.40k, False: 922]
  ------------------
  465|  2.40k|      ABSL_DCHECK(_impl_.len_ != nullptr);
  ------------------
  |  |   43|  2.40k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  2.40k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  2.40k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  2.40k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  2.40k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  2.40k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  466|  2.40k|      _impl_.len_->Clear();
  467|  2.40k|    }
  468|  3.32k|    if (cached_has_bits & 0x00000004u) {
  ------------------
  |  Branch (468:9): [True: 2.29k, False: 1.03k]
  ------------------
  469|  2.29k|      ABSL_DCHECK(_impl_.val_ != nullptr);
  ------------------
  |  |   43|  2.29k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  2.29k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  2.29k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  2.29k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  2.29k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  2.29k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  470|  2.29k|      _impl_.val_->Clear();
  471|  2.29k|    }
  472|  3.32k|  }
  473|  16.9k|  _impl_._has_bits_.Clear();
  474|  16.9k|  _internal_metadata_.Clear<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>();
  475|  16.9k|}
_ZNK8asn1_pdu3PDU11GetMetadataEv:
  691|   503k|::PROTOBUF_NAMESPACE_ID::Metadata PDU::GetMetadata() const {
  692|   503k|  return ::_pbi::AssignDescriptors(
  693|   503k|      &descriptor_table_asn1_5fpdu_2eproto_getter, &descriptor_table_asn1_5fpdu_2eproto_once,
  694|   503k|      file_level_metadata_asn1_5fpdu_2eproto[0]);
  695|   503k|}
_ZN8asn1_pdu10IdentifierC2EPN6google8protobuf5ArenaE:
  723|  34.2k|  : ::PROTOBUF_NAMESPACE_ID::Message(arena) {
  724|  34.2k|  SharedCtor(arena);
  725|       |  // @@protoc_insertion_point(arena_constructor:asn1_pdu.Identifier)
  726|  34.2k|}
_ZN8asn1_pdu10IdentifierD2Ev:
  762|  34.2k|Identifier::~Identifier() {
  763|       |  // @@protoc_insertion_point(destructor:asn1_pdu.Identifier)
  764|  34.2k|  if (auto *arena = _internal_metadata_.DeleteReturnArena<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>()) {
  ------------------
  |  Branch (764:13): [True: 0, False: 34.2k]
  ------------------
  765|      0|  (void)arena;
  766|      0|    return;
  767|      0|  }
  768|  34.2k|  SharedDtor();
  769|  34.2k|}
_ZN8asn1_pdu10Identifier5ClearEv:
  780|  3.27k|void Identifier::Clear() {
  781|       |// @@protoc_insertion_point(message_clear_start:asn1_pdu.Identifier)
  782|  3.27k|  ::uint32_t cached_has_bits = 0;
  783|       |  // Prevent compiler warnings about cached_has_bits being unused
  784|  3.27k|  (void) cached_has_bits;
  785|       |
  786|  3.27k|  cached_has_bits = _impl_._has_bits_[0];
  787|  3.27k|  if (cached_has_bits & 0x00000001u) {
  ------------------
  |  Branch (787:7): [True: 1.16k, False: 2.10k]
  ------------------
  788|  1.16k|    ABSL_DCHECK(_impl_.tag_num_ != nullptr);
  ------------------
  |  |   43|  1.16k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  1.16k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  1.16k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  1.16k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  1.16k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  1.16k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  789|  1.16k|    _impl_.tag_num_->Clear();
  790|  1.16k|  }
  791|  3.27k|  if (cached_has_bits & 0x00000006u) {
  ------------------
  |  Branch (791:7): [True: 622, False: 2.64k]
  ------------------
  792|    622|    ::memset(&_impl_.encoding_, 0, static_cast<::size_t>(
  793|    622|        reinterpret_cast<char*>(&_impl_.id_class_) -
  794|    622|        reinterpret_cast<char*>(&_impl_.encoding_)) + sizeof(_impl_.id_class_));
  795|    622|  }
  796|  3.27k|  _impl_._has_bits_.Clear();
  797|  3.27k|  _internal_metadata_.Clear<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>();
  798|  3.27k|}
_ZNK8asn1_pdu10Identifier12GetClassDataEv:
  961|  1.40k|const ::PROTOBUF_NAMESPACE_ID::Message::ClassData*Identifier::GetClassData() const { return &_class_data_; }
_ZN8asn1_pdu10Identifier9MergeImplERN6google8protobuf7MessageERKS3_:
  964|    467|void Identifier::MergeImpl(::PROTOBUF_NAMESPACE_ID::Message& to_msg, const ::PROTOBUF_NAMESPACE_ID::Message& from_msg) {
  965|    467|  auto* const _this = static_cast<Identifier*>(&to_msg);
  966|    467|  auto& from = static_cast<const Identifier&>(from_msg);
  967|       |  // @@protoc_insertion_point(class_specific_merge_from_start:asn1_pdu.Identifier)
  968|    467|  ABSL_DCHECK_NE(&from, _this);
  ------------------
  |  |   72|    467|  ABSL_DCHECK_NE_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   88|    467|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|    467|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|    467|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  969|    467|  ::uint32_t cached_has_bits = 0;
  970|    467|  (void) cached_has_bits;
  971|       |
  972|    467|  cached_has_bits = from._impl_._has_bits_[0];
  973|    467|  if (cached_has_bits & 0x00000007u) {
  ------------------
  |  Branch (973:7): [True: 0, False: 467]
  ------------------
  974|      0|    if (cached_has_bits & 0x00000001u) {
  ------------------
  |  Branch (974:9): [True: 0, False: 0]
  ------------------
  975|      0|      _this->_internal_mutable_tag_num()->::asn1_pdu::TagNumber::MergeFrom(
  976|      0|          from._internal_tag_num());
  977|      0|    }
  978|      0|    if (cached_has_bits & 0x00000002u) {
  ------------------
  |  Branch (978:9): [True: 0, False: 0]
  ------------------
  979|      0|      _this->_impl_.encoding_ = from._impl_.encoding_;
  980|      0|    }
  981|      0|    if (cached_has_bits & 0x00000004u) {
  ------------------
  |  Branch (981:9): [True: 0, False: 0]
  ------------------
  982|      0|      _this->_impl_.id_class_ = from._impl_.id_class_;
  983|      0|    }
  984|      0|    _this->_impl_._has_bits_[0] |= cached_has_bits;
  985|      0|  }
  986|    467|  _this->_internal_metadata_.MergeFrom<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>(from._internal_metadata_);
  987|    467|}
_ZNK8asn1_pdu10Identifier11GetMetadataEv:
 1016|   474k|::PROTOBUF_NAMESPACE_ID::Metadata Identifier::GetMetadata() const {
 1017|   474k|  return ::_pbi::AssignDescriptors(
 1018|   474k|      &descriptor_table_asn1_5fpdu_2eproto_getter, &descriptor_table_asn1_5fpdu_2eproto_once,
 1019|   474k|      file_level_metadata_asn1_5fpdu_2eproto[1]);
 1020|   474k|}
_ZN8asn1_pdu9TagNumberC2EPN6google8protobuf5ArenaE:
 1040|  33.4k|  : ::PROTOBUF_NAMESPACE_ID::Message(arena) {
 1041|  33.4k|  SharedCtor(arena);
 1042|       |  // @@protoc_insertion_point(arena_constructor:asn1_pdu.TagNumber)
 1043|  33.4k|}
_ZN8asn1_pdu9TagNumberD2Ev:
 1063|  33.4k|TagNumber::~TagNumber() {
 1064|       |  // @@protoc_insertion_point(destructor:asn1_pdu.TagNumber)
 1065|  33.4k|  if (auto *arena = _internal_metadata_.DeleteReturnArena<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>()) {
  ------------------
  |  Branch (1065:13): [True: 0, False: 33.4k]
  ------------------
 1066|      0|  (void)arena;
 1067|      0|    return;
 1068|      0|  }
 1069|  33.4k|  SharedDtor();
 1070|  33.4k|}
_ZN8asn1_pdu9TagNumber5ClearEv:
 1080|  2.88k|void TagNumber::Clear() {
 1081|       |// @@protoc_insertion_point(message_clear_start:asn1_pdu.TagNumber)
 1082|  2.88k|  ::uint32_t cached_has_bits = 0;
 1083|       |  // Prevent compiler warnings about cached_has_bits being unused
 1084|  2.88k|  (void) cached_has_bits;
 1085|       |
 1086|  2.88k|  cached_has_bits = _impl_._has_bits_[0];
 1087|  2.88k|  if (cached_has_bits & 0x00000003u) {
  ------------------
  |  Branch (1087:7): [True: 772, False: 2.11k]
  ------------------
 1088|    772|    ::memset(&_impl_.high_tag_num_, 0, static_cast<::size_t>(
 1089|    772|        reinterpret_cast<char*>(&_impl_.low_tag_num_) -
 1090|    772|        reinterpret_cast<char*>(&_impl_.high_tag_num_)) + sizeof(_impl_.low_tag_num_));
 1091|    772|  }
 1092|  2.88k|  _impl_._has_bits_.Clear();
 1093|  2.88k|  _internal_metadata_.Clear<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>();
 1094|  2.88k|}
_ZNK8asn1_pdu9TagNumber12GetClassDataEv:
 1207|  2.57k|const ::PROTOBUF_NAMESPACE_ID::Message::ClassData*TagNumber::GetClassData() const { return &_class_data_; }
_ZN8asn1_pdu9TagNumber9MergeImplERN6google8protobuf7MessageERKS3_:
 1210|    858|void TagNumber::MergeImpl(::PROTOBUF_NAMESPACE_ID::Message& to_msg, const ::PROTOBUF_NAMESPACE_ID::Message& from_msg) {
 1211|    858|  auto* const _this = static_cast<TagNumber*>(&to_msg);
 1212|    858|  auto& from = static_cast<const TagNumber&>(from_msg);
 1213|       |  // @@protoc_insertion_point(class_specific_merge_from_start:asn1_pdu.TagNumber)
 1214|    858|  ABSL_DCHECK_NE(&from, _this);
  ------------------
  |  |   72|    858|  ABSL_DCHECK_NE_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   88|    858|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|    858|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|    858|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1215|    858|  ::uint32_t cached_has_bits = 0;
 1216|    858|  (void) cached_has_bits;
 1217|       |
 1218|    858|  cached_has_bits = from._impl_._has_bits_[0];
 1219|    858|  if (cached_has_bits & 0x00000003u) {
  ------------------
  |  Branch (1219:7): [True: 0, False: 858]
  ------------------
 1220|      0|    if (cached_has_bits & 0x00000001u) {
  ------------------
  |  Branch (1220:9): [True: 0, False: 0]
  ------------------
 1221|      0|      _this->_impl_.high_tag_num_ = from._impl_.high_tag_num_;
 1222|      0|    }
 1223|      0|    if (cached_has_bits & 0x00000002u) {
  ------------------
  |  Branch (1223:9): [True: 0, False: 0]
  ------------------
 1224|      0|      _this->_impl_.low_tag_num_ = from._impl_.low_tag_num_;
 1225|      0|    }
 1226|      0|    _this->_impl_._has_bits_[0] |= cached_has_bits;
 1227|      0|  }
 1228|    858|  _this->_internal_metadata_.MergeFrom<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>(from._internal_metadata_);
 1229|    858|}
_ZNK8asn1_pdu9TagNumber11GetMetadataEv:
 1255|   286k|::PROTOBUF_NAMESPACE_ID::Metadata TagNumber::GetMetadata() const {
 1256|   286k|  return ::_pbi::AssignDescriptors(
 1257|   286k|      &descriptor_table_asn1_5fpdu_2eproto_getter, &descriptor_table_asn1_5fpdu_2eproto_once,
 1258|   286k|      file_level_metadata_asn1_5fpdu_2eproto[2]);
 1259|   286k|}
_ZN8asn1_pdu6LengthC2EPN6google8protobuf5ArenaE:
 1269|  34.3k|  : ::PROTOBUF_NAMESPACE_ID::Message(arena) {
 1270|  34.3k|  SharedCtor(arena);
 1271|       |  // @@protoc_insertion_point(arena_constructor:asn1_pdu.Length)
 1272|  34.3k|}
_ZN8asn1_pdu6LengthD2Ev:
 1309|  34.3k|Length::~Length() {
 1310|       |  // @@protoc_insertion_point(destructor:asn1_pdu.Length)
 1311|  34.3k|  if (auto *arena = _internal_metadata_.DeleteReturnArena<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>()) {
  ------------------
  |  Branch (1311:13): [True: 0, False: 34.3k]
  ------------------
 1312|      0|  (void)arena;
 1313|      0|    return;
 1314|      0|  }
 1315|  34.3k|  SharedDtor();
 1316|  34.3k|}
_ZN8asn1_pdu6Length11clear_typesEv:
 1329|  6.35k|void Length::clear_types() {
 1330|       |// @@protoc_insertion_point(one_of_clear_start:asn1_pdu.Length)
 1331|  6.35k|  switch (types_case()) {
  ------------------
  |  Branch (1331:11): [True: 0, False: 6.35k]
  ------------------
 1332|  1.88k|    case kIndefiniteForm: {
  ------------------
  |  Branch (1332:5): [True: 1.88k, False: 4.47k]
  ------------------
 1333|       |      // No need to clear
 1334|  1.88k|      break;
 1335|      0|    }
 1336|  2.02k|    case kLengthOverride: {
  ------------------
  |  Branch (1336:5): [True: 2.02k, False: 4.32k]
  ------------------
 1337|  2.02k|      _impl_.types_.length_override_.Destroy();
 1338|  2.02k|      break;
 1339|      0|    }
 1340|  2.44k|    case TYPES_NOT_SET: {
  ------------------
  |  Branch (1340:5): [True: 2.44k, False: 3.90k]
  ------------------
 1341|  2.44k|      break;
 1342|      0|    }
 1343|  6.35k|  }
 1344|  6.35k|  _impl_._oneof_case_[0] = TYPES_NOT_SET;
 1345|  6.35k|}
_ZN8asn1_pdu6Length5ClearEv:
 1348|  3.42k|void Length::Clear() {
 1349|       |// @@protoc_insertion_point(message_clear_start:asn1_pdu.Length)
 1350|  3.42k|  ::uint32_t cached_has_bits = 0;
 1351|       |  // Prevent compiler warnings about cached_has_bits being unused
 1352|  3.42k|  (void) cached_has_bits;
 1353|       |
 1354|  3.42k|  clear_types();
 1355|  3.42k|  _internal_metadata_.Clear<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>();
 1356|  3.42k|}
_ZNK8asn1_pdu6Length12GetClassDataEv:
 1465|  1.52k|const ::PROTOBUF_NAMESPACE_ID::Message::ClassData*Length::GetClassData() const { return &_class_data_; }
_ZN8asn1_pdu6Length9MergeImplERN6google8protobuf7MessageERKS3_:
 1468|    509|void Length::MergeImpl(::PROTOBUF_NAMESPACE_ID::Message& to_msg, const ::PROTOBUF_NAMESPACE_ID::Message& from_msg) {
 1469|    509|  auto* const _this = static_cast<Length*>(&to_msg);
 1470|    509|  auto& from = static_cast<const Length&>(from_msg);
 1471|       |  // @@protoc_insertion_point(class_specific_merge_from_start:asn1_pdu.Length)
 1472|    509|  ABSL_DCHECK_NE(&from, _this);
  ------------------
  |  |   72|    509|  ABSL_DCHECK_NE_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   88|    509|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|    509|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|    509|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1473|    509|  ::uint32_t cached_has_bits = 0;
 1474|    509|  (void) cached_has_bits;
 1475|       |
 1476|    509|  switch (from.types_case()) {
  ------------------
  |  Branch (1476:11): [True: 0, False: 509]
  ------------------
 1477|      0|    case kIndefiniteForm: {
  ------------------
  |  Branch (1477:5): [True: 0, False: 509]
  ------------------
 1478|      0|      _this->_internal_set_indefinite_form(from._internal_indefinite_form());
 1479|      0|      break;
 1480|      0|    }
 1481|      0|    case kLengthOverride: {
  ------------------
  |  Branch (1481:5): [True: 0, False: 509]
  ------------------
 1482|      0|      _this->_internal_set_length_override(from._internal_length_override());
 1483|      0|      break;
 1484|      0|    }
 1485|    509|    case TYPES_NOT_SET: {
  ------------------
  |  Branch (1485:5): [True: 509, False: 0]
  ------------------
 1486|    509|      break;
 1487|      0|    }
 1488|    509|  }
 1489|    509|  _this->_internal_metadata_.MergeFrom<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>(from._internal_metadata_);
 1490|    509|}
_ZNK8asn1_pdu6Length11GetMetadataEv:
 1510|   200k|::PROTOBUF_NAMESPACE_ID::Metadata Length::GetMetadata() const {
 1511|   200k|  return ::_pbi::AssignDescriptors(
 1512|   200k|      &descriptor_table_asn1_5fpdu_2eproto_getter, &descriptor_table_asn1_5fpdu_2eproto_once,
 1513|   200k|      file_level_metadata_asn1_5fpdu_2eproto[3]);
 1514|   200k|}
_ZN8asn1_pdu12ValueElementC2EPN6google8protobuf5ArenaE:
 1539|  69.8k|  : ::PROTOBUF_NAMESPACE_ID::Message(arena) {
 1540|  69.8k|  SharedCtor(arena);
 1541|       |  // @@protoc_insertion_point(arena_constructor:asn1_pdu.ValueElement)
 1542|  69.8k|}
_ZN8asn1_pdu12ValueElementD2Ev:
 1582|  69.8k|ValueElement::~ValueElement() {
 1583|       |  // @@protoc_insertion_point(destructor:asn1_pdu.ValueElement)
 1584|  69.8k|  if (auto *arena = _internal_metadata_.DeleteReturnArena<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>()) {
  ------------------
  |  Branch (1584:13): [True: 0, False: 69.8k]
  ------------------
 1585|      0|  (void)arena;
 1586|      0|    return;
 1587|      0|  }
 1588|  69.8k|  SharedDtor();
 1589|  69.8k|}
_ZN8asn1_pdu12ValueElement5ClearEv:
 1601|  5.53k|void ValueElement::Clear() {
 1602|       |// @@protoc_insertion_point(message_clear_start:asn1_pdu.ValueElement)
 1603|  5.53k|  ::uint32_t cached_has_bits = 0;
 1604|       |  // Prevent compiler warnings about cached_has_bits being unused
 1605|  5.53k|  (void) cached_has_bits;
 1606|       |
 1607|  5.53k|  cached_has_bits = _impl_._has_bits_[0];
 1608|  5.53k|  if (cached_has_bits & 0x00000003u) {
  ------------------
  |  Branch (1608:7): [True: 4.88k, False: 657]
  ------------------
 1609|  4.88k|    if (cached_has_bits & 0x00000001u) {
  ------------------
  |  Branch (1609:9): [True: 1.58k, False: 3.29k]
  ------------------
 1610|  1.58k|      _impl_.val_bits_.ClearNonDefaultToEmpty();
 1611|  1.58k|    }
 1612|  4.88k|    if (cached_has_bits & 0x00000002u) {
  ------------------
  |  Branch (1612:9): [True: 3.72k, False: 1.15k]
  ------------------
 1613|  3.72k|      ABSL_DCHECK(_impl_.pdu_ != nullptr);
  ------------------
  |  |   43|  3.72k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  3.72k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  3.72k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  3.72k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  3.72k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  3.72k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1614|  3.72k|      _impl_.pdu_->Clear();
 1615|  3.72k|    }
 1616|  4.88k|  }
 1617|  5.53k|  _impl_._has_bits_.Clear();
 1618|  5.53k|  _internal_metadata_.Clear<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>();
 1619|  5.53k|}
_ZNK8asn1_pdu12ValueElement11GetMetadataEv:
 1777|   669k|::PROTOBUF_NAMESPACE_ID::Metadata ValueElement::GetMetadata() const {
 1778|   669k|  return ::_pbi::AssignDescriptors(
 1779|   669k|      &descriptor_table_asn1_5fpdu_2eproto_getter, &descriptor_table_asn1_5fpdu_2eproto_once,
 1780|   669k|      file_level_metadata_asn1_5fpdu_2eproto[4]);
 1781|   669k|}
_ZN8asn1_pdu5ValueC2EPN6google8protobuf5ArenaE:
 1789|  34.2k|  : ::PROTOBUF_NAMESPACE_ID::Message(arena) {
 1790|  34.2k|  SharedCtor(arena);
 1791|       |  // @@protoc_insertion_point(arena_constructor:asn1_pdu.Value)
 1792|  34.2k|}
_ZN8asn1_pdu5ValueD2Ev:
 1812|  34.2k|Value::~Value() {
 1813|       |  // @@protoc_insertion_point(destructor:asn1_pdu.Value)
 1814|  34.2k|  if (auto *arena = _internal_metadata_.DeleteReturnArena<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>()) {
  ------------------
  |  Branch (1814:13): [True: 0, False: 34.2k]
  ------------------
 1815|      0|  (void)arena;
 1816|      0|    return;
 1817|      0|  }
 1818|  34.2k|  SharedDtor();
 1819|  34.2k|}
_ZN8asn1_pdu5Value5ClearEv:
 1830|  3.45k|void Value::Clear() {
 1831|       |// @@protoc_insertion_point(message_clear_start:asn1_pdu.Value)
 1832|  3.45k|  ::uint32_t cached_has_bits = 0;
 1833|       |  // Prevent compiler warnings about cached_has_bits being unused
 1834|  3.45k|  (void) cached_has_bits;
 1835|       |
 1836|  3.45k|  _impl_.val_array_.Clear();
 1837|  3.45k|  _internal_metadata_.Clear<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>();
 1838|  3.45k|}
_ZNK8asn1_pdu5Value12GetClassDataEv:
 1927|  1.74k|const ::PROTOBUF_NAMESPACE_ID::Message::ClassData*Value::GetClassData() const { return &_class_data_; }
_ZN8asn1_pdu5Value9MergeImplERN6google8protobuf7MessageERKS3_:
 1930|    583|void Value::MergeImpl(::PROTOBUF_NAMESPACE_ID::Message& to_msg, const ::PROTOBUF_NAMESPACE_ID::Message& from_msg) {
 1931|    583|  auto* const _this = static_cast<Value*>(&to_msg);
 1932|    583|  auto& from = static_cast<const Value&>(from_msg);
 1933|       |  // @@protoc_insertion_point(class_specific_merge_from_start:asn1_pdu.Value)
 1934|    583|  ABSL_DCHECK_NE(&from, _this);
  ------------------
  |  |   72|    583|  ABSL_DCHECK_NE_IMPL((val1), #val1, (val2), #val2)
  |  |  ------------------
  |  |  |  |   88|    583|  ABSL_LOG_INTERNAL_DCHECK_NOP(val1, val2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   56|    583|  while (false && ((void)(x), (void)(y), 0)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (56:10): [Folded - Ignored]
  |  |  |  |  |  |  |  Branch (56:19): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   57|    583|  ::absl::log_internal::NullStream().InternalStream()
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1935|    583|  ::uint32_t cached_has_bits = 0;
 1936|    583|  (void) cached_has_bits;
 1937|       |
 1938|    583|  _this->_impl_.val_array_.MergeFrom(from._impl_.val_array_);
 1939|    583|  _this->_internal_metadata_.MergeFrom<::PROTOBUF_NAMESPACE_ID::UnknownFieldSet>(from._internal_metadata_);
 1940|    583|}
_ZNK8asn1_pdu5Value11GetMetadataEv:
 1961|   397k|::PROTOBUF_NAMESPACE_ID::Metadata Value::GetMetadata() const {
 1962|   397k|  return ::_pbi::AssignDescriptors(
 1963|   397k|      &descriptor_table_asn1_5fpdu_2eproto_getter, &descriptor_table_asn1_5fpdu_2eproto_once,
 1964|   397k|      file_level_metadata_asn1_5fpdu_2eproto[5]);
 1965|   397k|}
_ZN6google8protobuf5Arena18CreateMaybeMessageIN8asn1_pdu3PDUEJEEEPT_PS1_DpOT0_:
 1970|  28.7k|Arena::CreateMaybeMessage< ::asn1_pdu::PDU >(Arena* arena) {
 1971|  28.7k|  return Arena::CreateMessageInternal< ::asn1_pdu::PDU >(arena);
 1972|  28.7k|}
_ZN6google8protobuf5Arena18CreateMaybeMessageIN8asn1_pdu10IdentifierEJEEEPT_PS1_DpOT0_:
 1974|  34.2k|Arena::CreateMaybeMessage< ::asn1_pdu::Identifier >(Arena* arena) {
 1975|  34.2k|  return Arena::CreateMessageInternal< ::asn1_pdu::Identifier >(arena);
 1976|  34.2k|}
_ZN6google8protobuf5Arena18CreateMaybeMessageIN8asn1_pdu9TagNumberEJEEEPT_PS1_DpOT0_:
 1978|  33.4k|Arena::CreateMaybeMessage< ::asn1_pdu::TagNumber >(Arena* arena) {
 1979|  33.4k|  return Arena::CreateMessageInternal< ::asn1_pdu::TagNumber >(arena);
 1980|  33.4k|}
_ZN6google8protobuf5Arena18CreateMaybeMessageIN8asn1_pdu6LengthEJEEEPT_PS1_DpOT0_:
 1982|  34.3k|Arena::CreateMaybeMessage< ::asn1_pdu::Length >(Arena* arena) {
 1983|  34.3k|  return Arena::CreateMessageInternal< ::asn1_pdu::Length >(arena);
 1984|  34.3k|}
_ZN6google8protobuf5Arena18CreateMaybeMessageIN8asn1_pdu12ValueElementEJEEEPT_PS1_DpOT0_:
 1986|  69.8k|Arena::CreateMaybeMessage< ::asn1_pdu::ValueElement >(Arena* arena) {
 1987|  69.8k|  return Arena::CreateMessageInternal< ::asn1_pdu::ValueElement >(arena);
 1988|  69.8k|}
_ZN6google8protobuf5Arena18CreateMaybeMessageIN8asn1_pdu5ValueEJEEEPT_PS1_DpOT0_:
 1990|  34.2k|Arena::CreateMaybeMessage< ::asn1_pdu::Value >(Arena* arena) {
 1991|  34.2k|  return Arena::CreateMessageInternal< ::asn1_pdu::Value >(arena);
 1992|  34.2k|}
_ZN8asn1_pdu3PDU10SharedCtorEPN6google8protobuf5ArenaE:
  421|  35.3k|inline void PDU::SharedCtor(::_pb::Arena* arena) {
  422|  35.3k|  (void)arena;
  423|  35.3k|  new (&_impl_) Impl_{
  424|  35.3k|      decltype(_impl_._has_bits_){}
  425|  35.3k|    , /*decltype(_impl_._cached_size_)*/{}
  426|  35.3k|    , decltype(_impl_.id_){nullptr}
  427|  35.3k|    , decltype(_impl_.len_){nullptr}
  428|  35.3k|    , decltype(_impl_.val_){nullptr}
  429|  35.3k|  };
  430|  35.3k|}
_ZN8asn1_pdu3PDU10SharedDtorEv:
  441|  35.3k|inline void PDU::SharedDtor() {
  442|  35.3k|  ABSL_DCHECK(GetArenaForAllocation() == nullptr);
  ------------------
  |  |   43|  35.3k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  35.3k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  35.3k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  35.3k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  35.3k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  35.3k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  443|  35.3k|  if (this != internal_default_instance()) delete _impl_.id_;
  ------------------
  |  Branch (443:7): [True: 35.3k, False: 0]
  ------------------
  444|  35.3k|  if (this != internal_default_instance()) delete _impl_.len_;
  ------------------
  |  Branch (444:7): [True: 35.3k, False: 0]
  ------------------
  445|  35.3k|  if (this != internal_default_instance()) delete _impl_.val_;
  ------------------
  |  Branch (445:7): [True: 35.3k, False: 0]
  ------------------
  446|  35.3k|}
_ZN8asn1_pdu10Identifier10SharedCtorEPN6google8protobuf5ArenaE:
  749|  34.2k|inline void Identifier::SharedCtor(::_pb::Arena* arena) {
  750|  34.2k|  (void)arena;
  751|  34.2k|  new (&_impl_) Impl_{
  752|  34.2k|      decltype(_impl_._has_bits_){}
  753|  34.2k|    , /*decltype(_impl_._cached_size_)*/{}
  754|  34.2k|    , decltype(_impl_.tag_num_){nullptr}
  755|  34.2k|    , decltype(_impl_.encoding_) { 0 }
  756|       |
  757|  34.2k|    , decltype(_impl_.id_class_) { 0 }
  758|       |
  759|  34.2k|  };
  760|  34.2k|}
_ZN8asn1_pdu10Identifier10SharedDtorEv:
  771|  34.2k|inline void Identifier::SharedDtor() {
  772|  34.2k|  ABSL_DCHECK(GetArenaForAllocation() == nullptr);
  ------------------
  |  |   43|  34.2k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  34.2k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  34.2k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  34.2k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  34.2k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  34.2k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  773|  34.2k|  if (this != internal_default_instance()) delete _impl_.tag_num_;
  ------------------
  |  Branch (773:7): [True: 34.2k, False: 0]
  ------------------
  774|  34.2k|}
_ZN8asn1_pdu9TagNumber10SharedCtorEPN6google8protobuf5ArenaE:
 1051|  33.4k|inline void TagNumber::SharedCtor(::_pb::Arena* arena) {
 1052|  33.4k|  (void)arena;
 1053|  33.4k|  new (&_impl_) Impl_{
 1054|  33.4k|      decltype(_impl_._has_bits_){}
 1055|  33.4k|    , /*decltype(_impl_._cached_size_)*/{}
 1056|  33.4k|    , decltype(_impl_.high_tag_num_) { 0u }
 1057|       |
 1058|  33.4k|    , decltype(_impl_.low_tag_num_) { 0 }
 1059|       |
 1060|  33.4k|  };
 1061|  33.4k|}
_ZN8asn1_pdu9TagNumber10SharedDtorEv:
 1072|  33.4k|inline void TagNumber::SharedDtor() {
 1073|  33.4k|  ABSL_DCHECK(GetArenaForAllocation() == nullptr);
  ------------------
  |  |   43|  33.4k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  33.4k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  33.4k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  33.4k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  33.4k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  33.4k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1074|  33.4k|}
_ZN8asn1_pdu6Length10SharedCtorEPN6google8protobuf5ArenaE:
 1299|  34.3k|inline void Length::SharedCtor(::_pb::Arena* arena) {
 1300|  34.3k|  (void)arena;
 1301|  34.3k|  new (&_impl_) Impl_{
 1302|  34.3k|      decltype(_impl_.types_){}
 1303|  34.3k|    , /*decltype(_impl_._cached_size_)*/{}
 1304|  34.3k|    , /*decltype(_impl_._oneof_case_)*/{}
 1305|  34.3k|  };
 1306|  34.3k|  clear_has_types();
 1307|  34.3k|}
_ZN8asn1_pdu6Length10SharedDtorEv:
 1318|  34.3k|inline void Length::SharedDtor() {
 1319|  34.3k|  ABSL_DCHECK(GetArenaForAllocation() == nullptr);
  ------------------
  |  |   43|  34.3k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  34.3k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  34.3k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  34.3k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  34.3k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  34.3k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1320|  34.3k|  if (has_types()) {
  ------------------
  |  Branch (1320:7): [True: 2.93k, False: 31.3k]
  ------------------
 1321|  2.93k|    clear_types();
 1322|  2.93k|  }
 1323|  34.3k|}
_ZN8asn1_pdu12ValueElement10SharedCtorEPN6google8protobuf5ArenaE:
 1567|  69.8k|inline void ValueElement::SharedCtor(::_pb::Arena* arena) {
 1568|  69.8k|  (void)arena;
 1569|  69.8k|  new (&_impl_) Impl_{
 1570|  69.8k|      decltype(_impl_._has_bits_){}
 1571|  69.8k|    , /*decltype(_impl_._cached_size_)*/{}
 1572|  69.8k|    , decltype(_impl_.val_bits_) {}
 1573|       |
 1574|  69.8k|    , decltype(_impl_.pdu_){nullptr}
 1575|  69.8k|  };
 1576|  69.8k|  _impl_.val_bits_.InitDefault();
 1577|       |  #ifdef PROTOBUF_FORCE_COPY_DEFAULT_STRING
 1578|       |        _impl_.val_bits_.Set("", GetArenaForAllocation());
 1579|       |  #endif  // PROTOBUF_FORCE_COPY_DEFAULT_STRING
 1580|  69.8k|}
_ZN8asn1_pdu12ValueElement10SharedDtorEv:
 1591|  69.8k|inline void ValueElement::SharedDtor() {
 1592|  69.8k|  ABSL_DCHECK(GetArenaForAllocation() == nullptr);
  ------------------
  |  |   43|  69.8k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  69.8k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  69.8k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  69.8k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  69.8k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  69.8k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1593|  69.8k|  _impl_.val_bits_.Destroy();
 1594|  69.8k|  if (this != internal_default_instance()) delete _impl_.pdu_;
  ------------------
  |  Branch (1594:7): [True: 69.8k, False: 0]
  ------------------
 1595|  69.8k|}
_ZN8asn1_pdu5Value10SharedCtorEPN6google8protobuf5ArenaE:
 1804|  34.2k|inline void Value::SharedCtor(::_pb::Arena* arena) {
 1805|  34.2k|  (void)arena;
 1806|  34.2k|  new (&_impl_) Impl_{
 1807|  34.2k|      decltype(_impl_.val_array_){arena}
 1808|  34.2k|    , /*decltype(_impl_._cached_size_)*/{}
 1809|  34.2k|  };
 1810|  34.2k|}
_ZN8asn1_pdu5Value10SharedDtorEv:
 1821|  34.2k|inline void Value::SharedDtor() {
 1822|  34.2k|  ABSL_DCHECK(GetArenaForAllocation() == nullptr);
  ------------------
  |  |   43|  34.2k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  ------------------
  |  |  |  |   43|  34.2k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  ------------------
  |  |  |  |  |  |   26|  34.2k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  157|  34.2k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  34.2k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |   28|  34.2k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1823|  34.2k|  _impl_.val_array_.~RepeatedPtrField();
 1824|  34.2k|}

_ZN8asn1_pdu3PDUC2Ev:
  214|  6.54k|  inline PDU() : PDU(nullptr) {}
_ZN8asn1_pdu3PDU25internal_default_instanceEv:
  261|   105k|  static inline const PDU* internal_default_instance() {
  262|   105k|    return reinterpret_cast<const PDU*>(
  263|   105k|               &_PDU_default_instance_);
  264|   105k|  }
_ZNK8asn1_pdu3PDU3NewEPN6google8protobuf5ArenaE:
  292|  28.7k|  PDU* New(::PROTOBUF_NAMESPACE_ID::Arena* arena = nullptr) const final {
  293|  28.7k|    return CreateMaybeMessage<PDU>(arena);
  294|  28.7k|  }
_ZN8asn1_pdu10Identifier25internal_default_instanceEv:
  455|  34.2k|  static inline const Identifier* internal_default_instance() {
  456|  34.2k|    return reinterpret_cast<const Identifier*>(
  457|  34.2k|               &_Identifier_default_instance_);
  458|  34.2k|  }
_ZNK8asn1_pdu10Identifier3NewEPN6google8protobuf5ArenaE:
  486|  34.2k|  Identifier* New(::PROTOBUF_NAMESPACE_ID::Arena* arena = nullptr) const final {
  487|  34.2k|    return CreateMaybeMessage<Identifier>(arena);
  488|  34.2k|  }
_ZNK8asn1_pdu9TagNumber3NewEPN6google8protobuf5ArenaE:
  674|  33.4k|  TagNumber* New(::PROTOBUF_NAMESPACE_ID::Arena* arena = nullptr) const final {
  675|  33.4k|    return CreateMaybeMessage<TagNumber>(arena);
  676|  33.4k|  }
_ZNK8asn1_pdu6Length3NewEPN6google8protobuf5ArenaE:
  849|  34.3k|  Length* New(::PROTOBUF_NAMESPACE_ID::Arena* arena = nullptr) const final {
  850|  34.3k|    return CreateMaybeMessage<Length>(arena);
  851|  34.3k|  }
_ZN8asn1_pdu6Length5Impl_10TypesUnionC2Ev:
  946|  34.3k|      constexpr TypesUnion() : _constinit_{} {}
_ZN8asn1_pdu12ValueElement25internal_default_instanceEv:
 1009|  69.8k|  static inline const ValueElement* internal_default_instance() {
 1010|  69.8k|    return reinterpret_cast<const ValueElement*>(
 1011|  69.8k|               &_ValueElement_default_instance_);
 1012|  69.8k|  }
_ZNK8asn1_pdu12ValueElement3NewEPN6google8protobuf5ArenaE:
 1040|  69.8k|  ValueElement* New(::PROTOBUF_NAMESPACE_ID::Arena* arena = nullptr) const final {
 1041|  69.8k|    return CreateMaybeMessage<ValueElement>(arena);
 1042|  69.8k|  }
_ZNK8asn1_pdu5Value3NewEPN6google8protobuf5ArenaE:
 1222|  34.2k|  Value* New(::PROTOBUF_NAMESPACE_ID::Arena* arena = nullptr) const final {
 1223|  34.2k|    return CreateMaybeMessage<Value>(arena);
 1224|  34.2k|  }
_ZNK8asn1_pdu3PDU12_internal_idEv:
 1329|  31.4k|inline const ::asn1_pdu::Identifier& PDU::_internal_id() const {
 1330|  31.4k|  const ::asn1_pdu::Identifier* p = _impl_.id_;
 1331|  31.4k|  return p != nullptr ? *p : reinterpret_cast<const ::asn1_pdu::Identifier&>(
  ------------------
  |  Branch (1331:10): [True: 31.4k, False: 0]
  ------------------
 1332|      0|      ::asn1_pdu::_Identifier_default_instance_);
 1333|  31.4k|}
_ZNK8asn1_pdu3PDU2idEv:
 1334|  31.4k|inline const ::asn1_pdu::Identifier& PDU::id() const {
 1335|       |  // @@protoc_insertion_point(field_get:asn1_pdu.PDU.id)
 1336|  31.4k|  return _internal_id();
 1337|  31.4k|}
_ZNK8asn1_pdu3PDU13_internal_lenEv:
 1416|  31.4k|inline const ::asn1_pdu::Length& PDU::_internal_len() const {
 1417|  31.4k|  const ::asn1_pdu::Length* p = _impl_.len_;
 1418|  31.4k|  return p != nullptr ? *p : reinterpret_cast<const ::asn1_pdu::Length&>(
  ------------------
  |  Branch (1418:10): [True: 31.4k, False: 0]
  ------------------
 1419|      0|      ::asn1_pdu::_Length_default_instance_);
 1420|  31.4k|}
_ZNK8asn1_pdu3PDU3lenEv:
 1421|  31.4k|inline const ::asn1_pdu::Length& PDU::len() const {
 1422|       |  // @@protoc_insertion_point(field_get:asn1_pdu.PDU.len)
 1423|  31.4k|  return _internal_len();
 1424|  31.4k|}
_ZNK8asn1_pdu3PDU13_internal_valEv:
 1503|  31.4k|inline const ::asn1_pdu::Value& PDU::_internal_val() const {
 1504|  31.4k|  const ::asn1_pdu::Value* p = _impl_.val_;
 1505|  31.4k|  return p != nullptr ? *p : reinterpret_cast<const ::asn1_pdu::Value&>(
  ------------------
  |  Branch (1505:10): [True: 31.4k, False: 0]
  ------------------
 1506|      0|      ::asn1_pdu::_Value_default_instance_);
 1507|  31.4k|}
_ZNK8asn1_pdu3PDU3valEv:
 1508|  31.4k|inline const ::asn1_pdu::Value& PDU::val() const {
 1509|       |  // @@protoc_insertion_point(field_get:asn1_pdu.PDU.val)
 1510|  31.4k|  return _internal_val();
 1511|  31.4k|}
_ZNK8asn1_pdu10Identifier8id_classEv:
 1593|  31.4k|inline ::asn1_pdu::Class Identifier::id_class() const {
 1594|       |  // @@protoc_insertion_point(field_get:asn1_pdu.Identifier.id_class)
 1595|  31.4k|  return _internal_id_class();
 1596|  31.4k|}
_ZNK8asn1_pdu10Identifier18_internal_id_classEv:
 1601|  31.4k|inline ::asn1_pdu::Class Identifier::_internal_id_class() const {
 1602|  31.4k|  return static_cast<::asn1_pdu::Class>(_impl_.id_class_);
 1603|  31.4k|}
_ZNK8asn1_pdu10Identifier8encodingEv:
 1619|  31.4k|inline ::asn1_pdu::Encoding Identifier::encoding() const {
 1620|       |  // @@protoc_insertion_point(field_get:asn1_pdu.Identifier.encoding)
 1621|  31.4k|  return _internal_encoding();
 1622|  31.4k|}
_ZNK8asn1_pdu10Identifier18_internal_encodingEv:
 1627|  31.4k|inline ::asn1_pdu::Encoding Identifier::_internal_encoding() const {
 1628|  31.4k|  return static_cast<::asn1_pdu::Encoding>(_impl_.encoding_);
 1629|  31.4k|}
_ZNK8asn1_pdu10Identifier17_internal_tag_numEv:
 1646|  62.8k|inline const ::asn1_pdu::TagNumber& Identifier::_internal_tag_num() const {
 1647|  62.8k|  const ::asn1_pdu::TagNumber* p = _impl_.tag_num_;
 1648|  62.8k|  return p != nullptr ? *p : reinterpret_cast<const ::asn1_pdu::TagNumber&>(
  ------------------
  |  Branch (1648:10): [True: 62.8k, False: 0]
  ------------------
 1649|      0|      ::asn1_pdu::_TagNumber_default_instance_);
 1650|  62.8k|}
_ZNK8asn1_pdu10Identifier7tag_numEv:
 1651|  62.8k|inline const ::asn1_pdu::TagNumber& Identifier::tag_num() const {
 1652|       |  // @@protoc_insertion_point(field_get:asn1_pdu.Identifier.tag_num)
 1653|  62.8k|  return _internal_tag_num();
 1654|  62.8k|}
_ZNK8asn1_pdu9TagNumber16has_high_tag_numEv:
 1728|  31.4k|inline bool TagNumber::has_high_tag_num() const {
 1729|  31.4k|  bool value = (_impl_._has_bits_[0] & 0x00000001u) != 0;
 1730|  31.4k|  return value;
 1731|  31.4k|}
_ZNK8asn1_pdu9TagNumber12high_tag_numEv:
 1736|  1.73k|inline ::uint32_t TagNumber::high_tag_num() const {
 1737|       |  // @@protoc_insertion_point(field_get:asn1_pdu.TagNumber.high_tag_num)
 1738|  1.73k|  return _internal_high_tag_num();
 1739|  1.73k|}
_ZNK8asn1_pdu9TagNumber22_internal_high_tag_numEv:
 1744|  1.73k|inline ::uint32_t TagNumber::_internal_high_tag_num() const {
 1745|  1.73k|  return _impl_.high_tag_num_;
 1746|  1.73k|}
_ZNK8asn1_pdu9TagNumber11low_tag_numEv:
 1761|  29.6k|inline ::asn1_pdu::LowTagNumber TagNumber::low_tag_num() const {
 1762|       |  // @@protoc_insertion_point(field_get:asn1_pdu.TagNumber.low_tag_num)
 1763|  29.6k|  return _internal_low_tag_num();
 1764|  29.6k|}
_ZNK8asn1_pdu9TagNumber21_internal_low_tag_numEv:
 1769|  29.6k|inline ::asn1_pdu::LowTagNumber TagNumber::_internal_low_tag_num() const {
 1770|  29.6k|  return static_cast<::asn1_pdu::LowTagNumber>(_impl_.low_tag_num_);
 1771|  29.6k|}
_ZNK8asn1_pdu6Length19has_indefinite_formEv:
 1783|  29.6k|inline bool Length::has_indefinite_form() const {
 1784|  29.6k|  return types_case() == kIndefiniteForm;
 1785|  29.6k|}
_ZNK8asn1_pdu6Length15indefinite_formEv:
 1795|  1.21k|inline bool Length::indefinite_form() const {
 1796|       |  // @@protoc_insertion_point(field_get:asn1_pdu.Length.indefinite_form)
 1797|  1.21k|  return _internal_indefinite_form();
 1798|  1.21k|}
_ZNK8asn1_pdu6Length25_internal_indefinite_formEv:
 1803|  1.21k|inline bool Length::_internal_indefinite_form() const {
 1804|  1.21k|  if (types_case() == kIndefiniteForm) {
  ------------------
  |  Branch (1804:7): [True: 1.21k, False: 0]
  ------------------
 1805|  1.21k|    return _impl_.types_.indefinite_form_;
 1806|  1.21k|  }
 1807|      0|  return false;
 1808|  1.21k|}
_ZNK8asn1_pdu6Length19has_length_overrideEv:
 1818|  31.4k|inline bool Length::has_length_override() const {
 1819|  31.4k|  return types_case() == kLengthOverride;
 1820|  31.4k|}
_ZNK8asn1_pdu6Length15length_overrideEv:
 1830|  1.72k|inline const std::string& Length::length_override() const {
 1831|       |  // @@protoc_insertion_point(field_get:asn1_pdu.Length.length_override)
 1832|  1.72k|  return _internal_length_override();
 1833|  1.72k|}
_ZNK8asn1_pdu6Length25_internal_length_overrideEv:
 1851|  1.72k|inline const std::string& Length::_internal_length_override() const {
 1852|  1.72k|  if (types_case() != kLengthOverride) {
  ------------------
  |  Branch (1852:7): [True: 0, False: 1.72k]
  ------------------
 1853|      0|    return ::PROTOBUF_NAMESPACE_ID::internal::GetEmptyStringAlreadyInited();
 1854|      0|  }
 1855|  1.72k|  return _impl_.types_.length_override_.Get();
 1856|  1.72k|}
_ZNK8asn1_pdu6Length9has_typesEv:
 1896|  34.3k|inline bool Length::has_types() const {
 1897|  34.3k|  return types_case() != TYPES_NOT_SET;
 1898|  34.3k|}
_ZN8asn1_pdu6Length15clear_has_typesEv:
 1899|  34.3k|inline void Length::clear_has_types() {
 1900|  34.3k|  _impl_._oneof_case_[0] = TYPES_NOT_SET;
 1901|  34.3k|}
_ZNK8asn1_pdu6Length10types_caseEv:
 1902|   105k|inline Length::TypesCase Length::types_case() const {
 1903|   105k|  return Length::TypesCase(_impl_._oneof_case_[0]);
 1904|   105k|}
_ZNK8asn1_pdu12ValueElement7has_pduEv:
 1910|  64.3k|inline bool ValueElement::has_pdu() const {
 1911|  64.3k|  bool value = (_impl_._has_bits_[0] & 0x00000002u) != 0;
 1912|  64.3k|  PROTOBUF_ASSUME(!value || _impl_.pdu_ != nullptr);
  ------------------
  |  |  616|  64.3k|  ABSL_DCHECK(pred);               \
  |  |  ------------------
  |  |  |  |   43|  64.3k|#define ABSL_DCHECK(condition) ABSL_DCHECK_IMPL((condition), #condition)
  |  |  |  |  ------------------
  |  |  |  |  |  |   43|  64.3k|  ABSL_CHECK_IMPL(true || (condition), "true")
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   26|  64.3k|  ABSL_LOG_INTERNAL_CONDITION_FATAL(STATELESS,                        \
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  |  157|  64.3k|  ABSL_LOG_INTERNAL_##type##_CONDITION(condition)
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   27|  64.3k|                                    ABSL_PREDICT_FALSE(!(condition))) \
  |  |  |  |  |  |  |  |   28|  64.3k|  ABSL_LOG_INTERNAL_CHECK(condition_text).InternalStream()
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  |   65|      0|  ::absl::log_internal::LogMessageFatal(__FILE__, __LINE__, failure_message)
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  617|  89.3k|  __builtin_assume(pred)
  |  |  ------------------
  |  |  |  Branch (617:20): [True: 39.2k, False: 25.0k]
  |  |  |  Branch (617:20): [True: 25.0k, False: 0]
  |  |  ------------------
  ------------------
 1913|  64.3k|  return value;
 1914|  64.3k|}
_ZNK8asn1_pdu12ValueElement13_internal_pduEv:
 1919|  25.0k|inline const ::asn1_pdu::PDU& ValueElement::_internal_pdu() const {
 1920|  25.0k|  const ::asn1_pdu::PDU* p = _impl_.pdu_;
 1921|  25.0k|  return p != nullptr ? *p : reinterpret_cast<const ::asn1_pdu::PDU&>(
  ------------------
  |  Branch (1921:10): [True: 25.0k, False: 0]
  ------------------
 1922|      0|      ::asn1_pdu::_PDU_default_instance_);
 1923|  25.0k|}
_ZNK8asn1_pdu12ValueElement3pduEv:
 1924|  25.0k|inline const ::asn1_pdu::PDU& ValueElement::pdu() const {
 1925|       |  // @@protoc_insertion_point(field_get:asn1_pdu.ValueElement.pdu)
 1926|  25.0k|  return _internal_pdu();
 1927|  25.0k|}
_ZNK8asn1_pdu12ValueElement8val_bitsEv:
 2005|  78.5k|inline const std::string& ValueElement::val_bits() const {
 2006|       |  // @@protoc_insertion_point(field_get:asn1_pdu.ValueElement.val_bits)
 2007|  78.5k|  return _internal_val_bits();
 2008|  78.5k|}
_ZNK8asn1_pdu12ValueElement18_internal_val_bitsEv:
 2021|  78.5k|inline const std::string& ValueElement::_internal_val_bits() const {
 2022|  78.5k|  return _impl_.val_bits_.Get();
 2023|  78.5k|}
_ZNK8asn1_pdu5Value9val_arrayEv:
 2100|  31.4k|Value::val_array() const {
 2101|       |  // @@protoc_insertion_point(field_list:asn1_pdu.Value.val_array)
 2102|  31.4k|  return _impl_.val_array_;
 2103|  31.4k|}

