BUF_MEM_new:
   67|      1|BUF_MEM *BUF_MEM_new(void) {
   68|      1|  BUF_MEM *ret;
   69|       |
   70|      1|  ret = OPENSSL_malloc(sizeof(BUF_MEM));
   71|      1|  if (ret == NULL) {
  ------------------
  |  Branch (71:7): [True: 0, False: 1]
  ------------------
   72|      0|    return NULL;
   73|      0|  }
   74|       |
   75|      1|  OPENSSL_memset(ret, 0, sizeof(BUF_MEM));
   76|      1|  return ret;
   77|      1|}
BUF_MEM_free:
   79|      1|void BUF_MEM_free(BUF_MEM *buf) {
   80|      1|  if (buf == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 1]
  ------------------
   81|      0|    return;
   82|      0|  }
   83|       |
   84|      1|  OPENSSL_free(buf->data);
   85|      1|  OPENSSL_free(buf);
   86|      1|}

CBB_zero:
   27|  2.19k|void CBB_zero(CBB *cbb) {
   28|  2.19k|  OPENSSL_memset(cbb, 0, sizeof(CBB));
   29|  2.19k|}
CBB_init:
   41|    314|int CBB_init(CBB *cbb, size_t initial_capacity) {
   42|    314|  CBB_zero(cbb);
   43|       |
   44|    314|  uint8_t *buf = OPENSSL_malloc(initial_capacity);
   45|    314|  if (initial_capacity > 0 && buf == NULL) {
  ------------------
  |  Branch (45:7): [True: 314, False: 0]
  |  Branch (45:31): [True: 0, False: 314]
  ------------------
   46|      0|    return 0;
   47|      0|  }
   48|       |
   49|    314|  cbb_init(cbb, buf, initial_capacity, /*can_resize=*/1);
   50|    314|  return 1;
   51|    314|}
CBB_cleanup:
   59|    368|void CBB_cleanup(CBB *cbb) {
   60|       |  // Child |CBB|s are non-owning. They are implicitly discarded and should not
   61|       |  // be used with |CBB_cleanup| or |ScopedCBB|.
   62|    368|  assert(!cbb->is_child);
   63|    368|  if (cbb->is_child) {
  ------------------
  |  Branch (63:7): [True: 0, False: 368]
  ------------------
   64|      0|    return;
   65|      0|  }
   66|       |
   67|    368|  if (cbb->u.base.can_resize) {
  ------------------
  |  Branch (67:7): [True: 368, False: 0]
  ------------------
   68|    368|    OPENSSL_free(cbb->u.base.buf);
   69|    368|  }
   70|    368|}
CBB_finish:
  125|     54|int CBB_finish(CBB *cbb, uint8_t **out_data, size_t *out_len) {
  126|     54|  if (cbb->is_child) {
  ------------------
  |  Branch (126:7): [True: 0, False: 54]
  ------------------
  127|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  128|      0|    return 0;
  129|      0|  }
  130|       |
  131|     54|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (131:7): [True: 0, False: 54]
  ------------------
  132|      0|    return 0;
  133|      0|  }
  134|       |
  135|     54|  if (cbb->u.base.can_resize && (out_data == NULL || out_len == NULL)) {
  ------------------
  |  Branch (135:7): [True: 54, False: 0]
  |  Branch (135:34): [True: 0, False: 54]
  |  Branch (135:54): [True: 0, False: 54]
  ------------------
  136|       |    // |out_data| and |out_len| can only be NULL if the CBB is fixed.
  137|      0|    return 0;
  138|      0|  }
  139|       |
  140|     54|  if (out_data != NULL) {
  ------------------
  |  Branch (140:7): [True: 54, False: 0]
  ------------------
  141|     54|    *out_data = cbb->u.base.buf;
  142|     54|  }
  143|     54|  if (out_len != NULL) {
  ------------------
  |  Branch (143:7): [True: 54, False: 0]
  ------------------
  144|     54|    *out_len = cbb->u.base.len;
  145|     54|  }
  146|     54|  cbb->u.base.buf = NULL;
  147|     54|  CBB_cleanup(cbb);
  148|     54|  return 1;
  149|     54|}
CBB_flush:
  161|  5.77k|int CBB_flush(CBB *cbb) {
  162|       |  // If |base| has hit an error, the buffer is in an undefined state, so
  163|       |  // fail all following calls. In particular, |cbb->child| may point to invalid
  164|       |  // memory.
  165|  5.77k|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  166|  5.77k|  if (base == NULL || base->error) {
  ------------------
  |  Branch (166:7): [True: 0, False: 5.77k]
  |  Branch (166:23): [True: 0, False: 5.77k]
  ------------------
  167|      0|    return 0;
  168|      0|  }
  169|       |
  170|  5.77k|  if (cbb->child == NULL) {
  ------------------
  |  Branch (170:7): [True: 4.56k, False: 1.21k]
  ------------------
  171|       |    // Nothing to flush.
  172|  4.56k|    return 1;
  173|  4.56k|  }
  174|       |
  175|  1.21k|  assert(cbb->child->is_child);
  176|  1.21k|  struct cbb_child_st *child = &cbb->child->u.child;
  177|  1.21k|  assert(child->base == base);
  178|  1.21k|  size_t child_start = child->offset + child->pending_len_len;
  179|       |
  180|  1.21k|  if (!CBB_flush(cbb->child) ||
  ------------------
  |  Branch (180:7): [True: 0, False: 1.21k]
  ------------------
  181|  1.21k|      child_start < child->offset ||
  ------------------
  |  Branch (181:7): [True: 0, False: 1.21k]
  ------------------
  182|  1.21k|      base->len < child_start) {
  ------------------
  |  Branch (182:7): [True: 0, False: 1.21k]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|  1.21k|  size_t len = base->len - child_start;
  187|       |
  188|  1.21k|  if (child->pending_is_asn1) {
  ------------------
  |  Branch (188:7): [True: 0, False: 1.21k]
  ------------------
  189|       |    // For ASN.1 we assume that we'll only need a single byte for the length.
  190|       |    // If that turned out to be incorrect, we have to move the contents along
  191|       |    // in order to make space.
  192|      0|    uint8_t len_len;
  193|      0|    uint8_t initial_length_byte;
  194|       |
  195|      0|    assert (child->pending_len_len == 1);
  196|       |
  197|      0|    if (len > 0xfffffffe) {
  ------------------
  |  Branch (197:9): [True: 0, False: 0]
  ------------------
  198|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  199|       |      // Too large.
  200|      0|      goto err;
  201|      0|    } else if (len > 0xffffff) {
  ------------------
  |  Branch (201:16): [True: 0, False: 0]
  ------------------
  202|      0|      len_len = 5;
  203|      0|      initial_length_byte = 0x80 | 4;
  204|      0|    } else if (len > 0xffff) {
  ------------------
  |  Branch (204:16): [True: 0, False: 0]
  ------------------
  205|      0|      len_len = 4;
  206|      0|      initial_length_byte = 0x80 | 3;
  207|      0|    } else if (len > 0xff) {
  ------------------
  |  Branch (207:16): [True: 0, False: 0]
  ------------------
  208|      0|      len_len = 3;
  209|      0|      initial_length_byte = 0x80 | 2;
  210|      0|    } else if (len > 0x7f) {
  ------------------
  |  Branch (210:16): [True: 0, False: 0]
  ------------------
  211|      0|      len_len = 2;
  212|      0|      initial_length_byte = 0x80 | 1;
  213|      0|    } else {
  214|      0|      len_len = 1;
  215|      0|      initial_length_byte = (uint8_t)len;
  216|      0|      len = 0;
  217|      0|    }
  218|       |
  219|      0|    if (len_len != 1) {
  ------------------
  |  Branch (219:9): [True: 0, False: 0]
  ------------------
  220|       |      // We need to move the contents along in order to make space.
  221|      0|      size_t extra_bytes = len_len - 1;
  222|      0|      if (!cbb_buffer_add(base, NULL, extra_bytes)) {
  ------------------
  |  Branch (222:11): [True: 0, False: 0]
  ------------------
  223|      0|        goto err;
  224|      0|      }
  225|      0|      OPENSSL_memmove(base->buf + child_start + extra_bytes,
  226|      0|                      base->buf + child_start, len);
  227|      0|    }
  228|      0|    base->buf[child->offset++] = initial_length_byte;
  229|      0|    child->pending_len_len = len_len - 1;
  230|      0|  }
  231|       |
  232|  3.05k|  for (size_t i = child->pending_len_len - 1; i < child->pending_len_len; i--) {
  ------------------
  |  Branch (232:47): [True: 1.84k, False: 1.21k]
  ------------------
  233|  1.84k|    base->buf[child->offset + i] = (uint8_t)len;
  234|  1.84k|    len >>= 8;
  235|  1.84k|  }
  236|  1.21k|  if (len != 0) {
  ------------------
  |  Branch (236:7): [True: 0, False: 1.21k]
  ------------------
  237|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|       |
  241|  1.21k|  child->base = NULL;
  242|  1.21k|  cbb->child = NULL;
  243|       |
  244|  1.21k|  return 1;
  245|       |
  246|      0|err:
  247|      0|  base->error = 1;
  248|      0|  return 0;
  249|  1.21k|}
CBB_data:
  251|    215|const uint8_t *CBB_data(const CBB *cbb) {
  252|    215|  assert(cbb->child == NULL);
  253|    215|  if (cbb->is_child) {
  ------------------
  |  Branch (253:7): [True: 215, False: 0]
  ------------------
  254|    215|    return cbb->u.child.base->buf + cbb->u.child.offset +
  255|    215|           cbb->u.child.pending_len_len;
  256|    215|  }
  257|      0|  return cbb->u.base.buf;
  258|    215|}
CBB_len:
  260|    215|size_t CBB_len(const CBB *cbb) {
  261|    215|  assert(cbb->child == NULL);
  262|    215|  if (cbb->is_child) {
  ------------------
  |  Branch (262:7): [True: 215, False: 0]
  ------------------
  263|    215|    assert(cbb->u.child.offset + cbb->u.child.pending_len_len <=
  264|    215|           cbb->u.child.base->len);
  265|    215|    return cbb->u.child.base->len - cbb->u.child.offset -
  266|    215|           cbb->u.child.pending_len_len;
  267|    215|  }
  268|      0|  return cbb->u.base.len;
  269|    215|}
CBB_add_u8_length_prefixed:
  304|    628|int CBB_add_u8_length_prefixed(CBB *cbb, CBB *out_contents) {
  305|    628|  return cbb_add_length_prefixed(cbb, out_contents, 1);
  306|    628|}
CBB_add_u16_length_prefixed:
  308|    628|int CBB_add_u16_length_prefixed(CBB *cbb, CBB *out_contents) {
  309|    628|  return cbb_add_length_prefixed(cbb, out_contents, 2);
  310|    628|}
CBB_add_u24_length_prefixed:
  312|    314|int CBB_add_u24_length_prefixed(CBB *cbb, CBB *out_contents) {
  313|    314|  return cbb_add_length_prefixed(cbb, out_contents, 3);
  314|    314|}
CBB_add_bytes:
  364|  1.65k|int CBB_add_bytes(CBB *cbb, const uint8_t *data, size_t len) {
  365|  1.65k|  uint8_t *out;
  366|  1.65k|  if (!CBB_add_space(cbb, &out, len)) {
  ------------------
  |  Branch (366:7): [True: 0, False: 1.65k]
  ------------------
  367|      0|    return 0;
  368|      0|  }
  369|  1.65k|  OPENSSL_memcpy(out, data, len);
  370|  1.65k|  return 1;
  371|  1.65k|}
CBB_add_space:
  382|  2.41k|int CBB_add_space(CBB *cbb, uint8_t **out_data, size_t len) {
  383|  2.41k|  if (!CBB_flush(cbb) ||
  ------------------
  |  Branch (383:7): [True: 0, False: 2.41k]
  ------------------
  384|  2.41k|      !cbb_buffer_add(cbb_get_base(cbb), out_data, len)) {
  ------------------
  |  Branch (384:7): [True: 0, False: 2.41k]
  ------------------
  385|      0|    return 0;
  386|      0|  }
  387|  2.41k|  return 1;
  388|  2.41k|}
CBB_add_u8:
  430|    314|int CBB_add_u8(CBB *cbb, uint8_t value) {
  431|    314|  return cbb_add_u(cbb, value, 1);
  432|    314|}
CBB_add_u16:
  434|    442|int CBB_add_u16(CBB *cbb, uint16_t value) {
  435|    442|  return cbb_add_u(cbb, value, 2);
  436|    442|}
cbb.c:cbb_init:
   31|    314|static void cbb_init(CBB *cbb, uint8_t *buf, size_t cap, int can_resize) {
   32|    314|  cbb->is_child = 0;
   33|    314|  cbb->child = NULL;
   34|    314|  cbb->u.base.buf = buf;
   35|    314|  cbb->u.base.len = 0;
   36|    314|  cbb->u.base.cap = cap;
   37|    314|  cbb->u.base.can_resize = can_resize;
   38|    314|  cbb->u.base.error = 0;
   39|    314|}
cbb.c:cbb_get_base:
  151|  9.76k|static struct cbb_buffer_st *cbb_get_base(CBB *cbb) {
  152|  9.76k|  if (cbb->is_child) {
  ------------------
  |  Branch (152:7): [True: 8.45k, False: 1.31k]
  ------------------
  153|  8.45k|    return cbb->u.child.base;
  154|  8.45k|  }
  155|  1.31k|  return &cbb->u.base;
  156|  9.76k|}
cbb.c:cbb_buffer_add:
  116|  3.98k|                          size_t len) {
  117|  3.98k|  if (!cbb_buffer_reserve(base, out, len)) {
  ------------------
  |  Branch (117:7): [True: 0, False: 3.98k]
  ------------------
  118|      0|    return 0;
  119|      0|  }
  120|       |  // This will not overflow or |cbb_buffer_reserve| would have failed.
  121|  3.98k|  base->len += len;
  122|  3.98k|  return 1;
  123|  3.98k|}
cbb.c:cbb_add_length_prefixed:
  296|  1.57k|                                   uint8_t len_len) {
  297|  1.57k|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (297:7): [True: 0, False: 1.57k]
  ------------------
  298|      0|    return 0;
  299|      0|  }
  300|       |
  301|  1.57k|  return cbb_add_child(cbb, out_contents, len_len, /*is_asn1=*/0);
  302|  1.57k|}
cbb.c:cbb_add_child:
  272|  1.57k|                         int is_asn1) {
  273|  1.57k|  assert(cbb->child == NULL);
  274|  1.57k|  assert(!is_asn1 || len_len == 1);
  275|  1.57k|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  276|  1.57k|  size_t offset = base->len;
  277|       |
  278|       |  // Reserve space for the length prefix.
  279|  1.57k|  uint8_t *prefix_bytes;
  280|  1.57k|  if (!cbb_buffer_add(base, &prefix_bytes, len_len)) {
  ------------------
  |  Branch (280:7): [True: 0, False: 1.57k]
  ------------------
  281|      0|    return 0;
  282|      0|  }
  283|  1.57k|  OPENSSL_memset(prefix_bytes, 0, len_len);
  284|       |
  285|  1.57k|  CBB_zero(out_child);
  286|  1.57k|  out_child->is_child = 1;
  287|  1.57k|  out_child->u.child.base = base;
  288|  1.57k|  out_child->u.child.offset = offset;
  289|  1.57k|  out_child->u.child.pending_len_len = len_len;
  290|  1.57k|  out_child->u.child.pending_is_asn1 = is_asn1;
  291|  1.57k|  cbb->child = out_child;
  292|  1.57k|  return 1;
  293|  1.57k|}
cbb.c:cbb_buffer_reserve:
   73|  3.98k|                              size_t len) {
   74|  3.98k|  if (base == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 3.98k]
  ------------------
   75|      0|    return 0;
   76|      0|  }
   77|       |
   78|  3.98k|  size_t newlen = base->len + len;
   79|  3.98k|  if (newlen < base->len) {
  ------------------
  |  Branch (79:7): [True: 0, False: 3.98k]
  ------------------
   80|       |    // Overflow
   81|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   82|      0|    goto err;
   83|      0|  }
   84|       |
   85|  3.98k|  if (newlen > base->cap) {
  ------------------
  |  Branch (85:7): [True: 210, False: 3.77k]
  ------------------
   86|    210|    if (!base->can_resize) {
  ------------------
  |  Branch (86:9): [True: 0, False: 210]
  ------------------
   87|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   88|      0|      goto err;
   89|      0|    }
   90|       |
   91|    210|    size_t newcap = base->cap * 2;
   92|    210|    if (newcap < base->cap || newcap < newlen) {
  ------------------
  |  Branch (92:9): [True: 0, False: 210]
  |  Branch (92:31): [True: 74, False: 136]
  ------------------
   93|     74|      newcap = newlen;
   94|     74|    }
   95|    210|    uint8_t *newbuf = OPENSSL_realloc(base->buf, newcap);
   96|    210|    if (newbuf == NULL) {
  ------------------
  |  Branch (96:9): [True: 0, False: 210]
  ------------------
   97|      0|      goto err;
   98|      0|    }
   99|       |
  100|    210|    base->buf = newbuf;
  101|    210|    base->cap = newcap;
  102|    210|  }
  103|       |
  104|  3.98k|  if (out) {
  ------------------
  |  Branch (104:7): [True: 3.98k, False: 0]
  ------------------
  105|  3.98k|    *out = base->buf + base->len;
  106|  3.98k|  }
  107|       |
  108|  3.98k|  return 1;
  109|       |
  110|      0|err:
  111|      0|  base->error = 1;
  112|      0|  return 0;
  113|  3.98k|}
cbb.c:cbb_add_u:
  410|    756|static int cbb_add_u(CBB *cbb, uint64_t v, size_t len_len) {
  411|    756|  uint8_t *buf;
  412|    756|  if (!CBB_add_space(cbb, &buf, len_len)) {
  ------------------
  |  Branch (412:7): [True: 0, False: 756]
  ------------------
  413|      0|    return 0;
  414|      0|  }
  415|       |
  416|  1.95k|  for (size_t i = len_len - 1; i < len_len; i--) {
  ------------------
  |  Branch (416:32): [True: 1.19k, False: 756]
  ------------------
  417|  1.19k|    buf[i] = v;
  418|  1.19k|    v >>= 8;
  419|  1.19k|  }
  420|       |
  421|       |  // |v| must fit in |len_len| bytes.
  422|    756|  if (v != 0) {
  ------------------
  |  Branch (422:7): [True: 0, False: 756]
  ------------------
  423|      0|    cbb_get_base(cbb)->error = 1;
  424|      0|    return 0;
  425|      0|  }
  426|       |
  427|    756|  return 1;
  428|    756|}

CBS_init:
   29|   222k|void CBS_init(CBS *cbs, const uint8_t *data, size_t len) {
   30|   222k|  cbs->data = data;
   31|   222k|  cbs->len = len;
   32|   222k|}
CBS_data:
   50|  6.71k|const uint8_t *CBS_data(const CBS *cbs) {
   51|  6.71k|  return cbs->data;
   52|  6.71k|}
CBS_len:
   54|   127k|size_t CBS_len(const CBS *cbs) {
   55|   127k|  return cbs->len;
   56|   127k|}
CBS_get_u8:
  108|  4.14k|int CBS_get_u8(CBS *cbs, uint8_t *out) {
  109|  4.14k|  const uint8_t *v;
  110|  4.14k|  if (!cbs_get(cbs, &v, 1)) {
  ------------------
  |  Branch (110:7): [True: 333, False: 3.81k]
  ------------------
  111|    333|    return 0;
  112|    333|  }
  113|  3.81k|  *out = *v;
  114|  3.81k|  return 1;
  115|  4.14k|}
CBS_get_u16:
  117|   216k|int CBS_get_u16(CBS *cbs, uint16_t *out) {
  118|   216k|  uint64_t v;
  119|   216k|  if (!cbs_get_u(cbs, &v, 2)) {
  ------------------
  |  Branch (119:7): [True: 108, False: 216k]
  ------------------
  120|    108|    return 0;
  121|    108|  }
  122|   216k|  *out = v;
  123|   216k|  return 1;
  124|   216k|}
CBS_get_bytes:
  181|   221k|int CBS_get_bytes(CBS *cbs, CBS *out, size_t len) {
  182|   221k|  const uint8_t *v;
  183|   221k|  if (!cbs_get(cbs, &v, len)) {
  ------------------
  |  Branch (183:7): [True: 125, False: 221k]
  ------------------
  184|    125|    return 0;
  185|    125|  }
  186|   221k|  CBS_init(out, v, len);
  187|   221k|  return 1;
  188|   221k|}
CBS_get_u8_length_prefixed:
  210|  2.61k|int CBS_get_u8_length_prefixed(CBS *cbs, CBS *out) {
  211|  2.61k|  return cbs_get_length_prefixed(cbs, out, 1);
  212|  2.61k|}
CBS_get_u16_length_prefixed:
  214|   217k|int CBS_get_u16_length_prefixed(CBS *cbs, CBS *out) {
  215|   217k|  return cbs_get_length_prefixed(cbs, out, 2);
  216|   217k|}
CBS_get_u24_length_prefixed:
  218|    796|int CBS_get_u24_length_prefixed(CBS *cbs, CBS *out) {
  219|    796|  return cbs_get_length_prefixed(cbs, out, 3);
  220|    796|}
cbs.c:cbs_get:
   34|   663k|static int cbs_get(CBS *cbs, const uint8_t **p, size_t n) {
   35|   663k|  if (cbs->len < n) {
  ------------------
  |  Branch (35:7): [True: 611, False: 662k]
  ------------------
   36|    611|    return 0;
   37|    611|  }
   38|       |
   39|   662k|  *p = cbs->data;
   40|   662k|  cbs->data += n;
   41|   662k|  cbs->len -= n;
   42|   662k|  return 1;
   43|   663k|}
cbs.c:cbs_get_u:
   93|   437k|static int cbs_get_u(CBS *cbs, uint64_t *out, size_t len) {
   94|   437k|  uint64_t result = 0;
   95|   437k|  const uint8_t *data;
   96|       |
   97|   437k|  if (!cbs_get(cbs, &data, len)) {
  ------------------
  |  Branch (97:7): [True: 153, False: 437k]
  ------------------
   98|    153|    return 0;
   99|    153|  }
  100|  1.30M|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (100:22): [True: 872k, False: 437k]
  ------------------
  101|   872k|    result <<= 8;
  102|   872k|    result |= data[i];
  103|   872k|  }
  104|   437k|  *out = result;
  105|   437k|  return 1;
  106|   437k|}
cbs.c:cbs_get_length_prefixed:
  199|   220k|static int cbs_get_length_prefixed(CBS *cbs, CBS *out, size_t len_len) {
  200|   220k|  uint64_t len;
  201|   220k|  if (!cbs_get_u(cbs, &len, len_len)) {
  ------------------
  |  Branch (201:7): [True: 45, False: 220k]
  ------------------
  202|     45|    return 0;
  203|     45|  }
  204|       |  // If |len_len| <= 3 then we know that |len| will fit into a |size_t|, even on
  205|       |  // 32-bit systems.
  206|   220k|  assert(len_len <= 3);
  207|   220k|  return CBS_get_bytes(cbs, out, len);
  208|   220k|}

CRYPTO_chacha_20:
   67|      1|                      uint32_t counter) {
   68|      1|  assert(!buffers_alias(out, in_len, in, in_len) || in == out);
   69|       |
   70|      1|  uint32_t counter_nonce[4];
   71|      1|  counter_nonce[0] = counter;
   72|      1|  counter_nonce[1] = CRYPTO_load_u32_le(nonce + 0);
   73|      1|  counter_nonce[2] = CRYPTO_load_u32_le(nonce + 4);
   74|      1|  counter_nonce[3] = CRYPTO_load_u32_le(nonce + 8);
   75|       |
   76|      1|  const uint32_t *key_ptr = (const uint32_t *)key;
   77|       |#if !defined(OPENSSL_X86) && !defined(OPENSSL_X86_64)
   78|       |  // The assembly expects the key to be four-byte aligned.
   79|       |  uint32_t key_u32[8];
   80|       |  if ((((uintptr_t)key) & 3) != 0) {
   81|       |    key_u32[0] = CRYPTO_load_u32_le(key + 0);
   82|       |    key_u32[1] = CRYPTO_load_u32_le(key + 4);
   83|       |    key_u32[2] = CRYPTO_load_u32_le(key + 8);
   84|       |    key_u32[3] = CRYPTO_load_u32_le(key + 12);
   85|       |    key_u32[4] = CRYPTO_load_u32_le(key + 16);
   86|       |    key_u32[5] = CRYPTO_load_u32_le(key + 20);
   87|       |    key_u32[6] = CRYPTO_load_u32_le(key + 24);
   88|       |    key_u32[7] = CRYPTO_load_u32_le(key + 28);
   89|       |
   90|       |    key_ptr = key_u32;
   91|       |  }
   92|       |#endif
   93|       |
   94|      2|  while (in_len > 0) {
  ------------------
  |  Branch (94:10): [True: 1, False: 1]
  ------------------
   95|       |    // The assembly functions do not have defined overflow behavior. While
   96|       |    // overflow is almost always a bug in the caller, we prefer our functions to
   97|       |    // behave the same across platforms, so divide into multiple calls to avoid
   98|       |    // this case.
   99|      1|    uint64_t todo = 64 * ((UINT64_C(1) << 32) - counter_nonce[0]);
  100|      1|    if (todo > in_len) {
  ------------------
  |  Branch (100:9): [True: 1, False: 0]
  ------------------
  101|      1|      todo = in_len;
  102|      1|    }
  103|       |
  104|      1|    ChaCha20_ctr32(out, in, (size_t)todo, key_ptr, counter_nonce);
  105|      1|    in += todo;
  106|      1|    out += todo;
  107|      1|    in_len -= todo;
  108|       |
  109|       |    // We're either done and will next break out of the loop, or we stopped at
  110|       |    // the wraparound point and the counter should continue at zero.
  111|      1|    counter_nonce[0] = 0;
  112|      1|  }
  113|      1|}

OPENSSL_cpuid_setup:
  153|      2|void OPENSSL_cpuid_setup(void) {
  154|       |  // Determine the vendor and maximum input value.
  155|      2|  uint32_t eax, ebx, ecx, edx;
  156|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 0);
  157|       |
  158|      2|  uint32_t num_ids = eax;
  159|       |
  160|      2|  int is_intel = ebx == 0x756e6547 /* Genu */ &&
  ------------------
  |  Branch (160:18): [True: 2, False: 0]
  ------------------
  161|      2|                 edx == 0x49656e69 /* ineI */ &&
  ------------------
  |  Branch (161:18): [True: 2, False: 0]
  ------------------
  162|      2|                 ecx == 0x6c65746e /* ntel */;
  ------------------
  |  Branch (162:18): [True: 2, False: 0]
  ------------------
  163|      2|  int is_amd = ebx == 0x68747541 /* Auth */ &&
  ------------------
  |  Branch (163:16): [True: 0, False: 2]
  ------------------
  164|      2|               edx == 0x69746e65 /* enti */ &&
  ------------------
  |  Branch (164:16): [True: 0, False: 0]
  ------------------
  165|      2|               ecx == 0x444d4163 /* cAMD */;
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|       |
  167|      2|  uint32_t extended_features[2] = {0};
  168|      2|  if (num_ids >= 7) {
  ------------------
  |  Branch (168:7): [True: 2, False: 0]
  ------------------
  169|      2|    OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 7);
  170|      2|    extended_features[0] = ebx;
  171|      2|    extended_features[1] = ecx;
  172|      2|  }
  173|       |
  174|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 1);
  175|       |
  176|      2|  if (is_amd) {
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|       |    // See https://www.amd.com/system/files/TechDocs/25481.pdf, page 10.
  178|      0|    const uint32_t base_family = (eax >> 8) & 15;
  179|      0|    const uint32_t base_model = (eax >> 4) & 15;
  180|       |
  181|      0|    uint32_t family = base_family;
  182|      0|    uint32_t model = base_model;
  183|      0|    if (base_family == 0xf) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      const uint32_t ext_family = (eax >> 20) & 255;
  185|      0|      family += ext_family;
  186|      0|      const uint32_t ext_model = (eax >> 16) & 15;
  187|      0|      model |= ext_model << 4;
  188|      0|    }
  189|       |
  190|      0|    if (family < 0x17 || (family == 0x17 && 0x70 <= model && model <= 0x7f)) {
  ------------------
  |  Branch (190:9): [True: 0, False: 0]
  |  Branch (190:27): [True: 0, False: 0]
  |  Branch (190:45): [True: 0, False: 0]
  |  Branch (190:62): [True: 0, False: 0]
  ------------------
  191|       |      // Disable RDRAND on AMD families before 0x17 (Zen) due to reported
  192|       |      // failures after suspend.
  193|       |      // https://bugzilla.redhat.com/show_bug.cgi?id=1150286
  194|       |      // Also disable for family 0x17, models 0x70–0x7f, due to possible RDRAND
  195|       |      // failures there too.
  196|      0|      ecx &= ~(1u << 30);
  197|      0|    }
  198|      0|  }
  199|       |
  200|       |  // Force the hyper-threading bit so that the more conservative path is always
  201|       |  // chosen.
  202|      2|  edx |= 1u << 28;
  203|       |
  204|       |  // Reserved bit #20 was historically repurposed to control the in-memory
  205|       |  // representation of RC4 state. Always set it to zero.
  206|      2|  edx &= ~(1u << 20);
  207|       |
  208|       |  // Reserved bit #30 is repurposed to signal an Intel CPU.
  209|      2|  if (is_intel) {
  ------------------
  |  Branch (209:7): [True: 2, False: 0]
  ------------------
  210|      2|    edx |= (1u << 30);
  211|       |
  212|       |    // Clear the XSAVE bit on Knights Landing to mimic Silvermont. This enables
  213|       |    // some Silvermont-specific codepaths which perform better. See OpenSSL
  214|       |    // commit 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  215|      2|    if ((eax & 0x0fff0ff0) == 0x00050670 /* Knights Landing */ ||
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      2|        (eax & 0x0fff0ff0) == 0x00080650 /* Knights Mill (per SDE) */) {
  ------------------
  |  Branch (216:9): [True: 0, False: 2]
  ------------------
  217|      0|      ecx &= ~(1u << 26);
  218|      0|    }
  219|      2|  } else {
  220|      0|    edx &= ~(1u << 30);
  221|      0|  }
  222|       |
  223|       |  // The SDBG bit is repurposed to denote AMD XOP support. Don't ever use AMD
  224|       |  // XOP code paths.
  225|      2|  ecx &= ~(1u << 11);
  226|       |
  227|      2|  uint64_t xcr0 = 0;
  228|      2|  if (ecx & (1u << 27)) {
  ------------------
  |  Branch (228:7): [True: 2, False: 0]
  ------------------
  229|       |    // XCR0 may only be queried if the OSXSAVE bit is set.
  230|      2|    xcr0 = OPENSSL_xgetbv(0);
  231|      2|  }
  232|       |  // See Intel manual, volume 1, section 14.3.
  233|      2|  if ((xcr0 & 6) != 6) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2]
  ------------------
  234|       |    // YMM registers cannot be used.
  235|      0|    ecx &= ~(1u << 28);  // AVX
  236|      0|    ecx &= ~(1u << 12);  // FMA
  237|      0|    ecx &= ~(1u << 11);  // AMD XOP
  238|       |    // Clear AVX2 and AVX512* bits.
  239|       |    //
  240|       |    // TODO(davidben): Should bits 17 and 26-28 also be cleared? Upstream
  241|       |    // doesn't clear those.
  242|      0|    extended_features[0] &=
  243|      0|        ~((1u << 5) | (1u << 16) | (1u << 21) | (1u << 30) | (1u << 31));
  244|      0|  }
  245|       |  // See Intel manual, volume 1, section 15.2.
  246|      2|  if ((xcr0 & 0xe6) != 0xe6) {
  ------------------
  |  Branch (246:7): [True: 2, False: 0]
  ------------------
  247|       |    // Clear AVX512F. Note we don't touch other AVX512 extensions because they
  248|       |    // can be used with YMM.
  249|      2|    extended_features[0] &= ~(1u << 16);
  250|      2|  }
  251|       |
  252|       |  // Disable ADX instructions on Knights Landing. See OpenSSL commit
  253|       |  // 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  254|      2|  if ((ecx & (1u << 26)) == 0) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    extended_features[0] &= ~(1u << 19);
  256|      0|  }
  257|       |
  258|      2|  OPENSSL_ia32cap_P[0] = edx;
  259|      2|  OPENSSL_ia32cap_P[1] = ecx;
  260|      2|  OPENSSL_ia32cap_P[2] = extended_features[0];
  261|      2|  OPENSSL_ia32cap_P[3] = extended_features[1];
  262|       |
  263|      2|  const char *env1, *env2;
  264|      2|  env1 = getenv("OPENSSL_ia32cap");
  265|      2|  if (env1 == NULL) {
  ------------------
  |  Branch (265:7): [True: 2, False: 0]
  ------------------
  266|      2|    return;
  267|      2|  }
  268|       |
  269|       |  // OPENSSL_ia32cap can contain zero, one or two values, separated with a ':'.
  270|       |  // Each value is a 64-bit, unsigned value which may start with "0x" to
  271|       |  // indicate a hex value. Prior to the 64-bit value, a '~' or '|' may be given.
  272|       |  //
  273|       |  // If the '~' prefix is present:
  274|       |  //   the value is inverted and ANDed with the probed CPUID result
  275|       |  // If the '|' prefix is present:
  276|       |  //   the value is ORed with the probed CPUID result
  277|       |  // Otherwise:
  278|       |  //   the value is taken as the result of the CPUID
  279|       |  //
  280|       |  // The first value determines OPENSSL_ia32cap_P[0] and [1]. The second [2]
  281|       |  // and [3].
  282|       |
  283|      0|  handle_cpu_env(&OPENSSL_ia32cap_P[0], env1);
  284|      0|  env2 = strchr(env1, ':');
  285|      0|  if (env2 != NULL) {
  ------------------
  |  Branch (285:7): [True: 0, False: 0]
  ------------------
  286|      0|    handle_cpu_env(&OPENSSL_ia32cap_P[2], env2 + 1);
  287|      0|  }
  288|      0|}
cpu_intel.c:OPENSSL_cpuid:
   80|      6|                          uint32_t *out_ecx, uint32_t *out_edx, uint32_t leaf) {
   81|       |#if defined(_MSC_VER)
   82|       |  int tmp[4];
   83|       |  __cpuid(tmp, (int)leaf);
   84|       |  *out_eax = (uint32_t)tmp[0];
   85|       |  *out_ebx = (uint32_t)tmp[1];
   86|       |  *out_ecx = (uint32_t)tmp[2];
   87|       |  *out_edx = (uint32_t)tmp[3];
   88|       |#elif defined(__pic__) && defined(OPENSSL_32_BIT)
   89|       |  // Inline assembly may not clobber the PIC register. For 32-bit, this is EBX.
   90|       |  // See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47602.
   91|       |  __asm__ volatile (
   92|       |    "xor %%ecx, %%ecx\n"
   93|       |    "mov %%ebx, %%edi\n"
   94|       |    "cpuid\n"
   95|       |    "xchg %%edi, %%ebx\n"
   96|       |    : "=a"(*out_eax), "=D"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
   97|       |    : "a"(leaf)
   98|       |  );
   99|       |#else
  100|      6|  __asm__ volatile (
  101|      6|    "xor %%ecx, %%ecx\n"
  102|      6|    "cpuid\n"
  103|      6|    : "=a"(*out_eax), "=b"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
  104|      6|    : "a"(leaf)
  105|      6|  );
  106|      6|#endif
  107|      6|}
cpu_intel.c:OPENSSL_xgetbv:
  111|      2|static uint64_t OPENSSL_xgetbv(uint32_t xcr) {
  112|       |#if defined(_MSC_VER)
  113|       |  return (uint64_t)_xgetbv(xcr);
  114|       |#else
  115|      2|  uint32_t eax, edx;
  116|      2|  __asm__ volatile ("xgetbv" : "=a"(eax), "=d"(edx) : "c"(xcr));
  117|      2|  return (((uint64_t)edx) << 32) | eax;
  118|      2|#endif
  119|      2|}

crypto.c:do_library_init:
  151|      2|static void OPENSSL_CDECL do_library_init(void) {
  152|       | // WARNING: this function may only configure the capability variables. See the
  153|       | // note above about the linker bug.
  154|      2|#if defined(NEED_CPUID)
  155|      2|  OPENSSL_cpuid_setup();
  156|      2|#endif
  157|      2|}

ERR_put_error:
  657|    361|                   unsigned line) {
  658|    361|  ERR_STATE *const state = err_get_state();
  659|    361|  struct err_error_st *error;
  660|       |
  661|    361|  if (state == NULL) {
  ------------------
  |  Branch (661:7): [True: 0, False: 361]
  ------------------
  662|      0|    return;
  663|      0|  }
  664|       |
  665|    361|  if (library == ERR_LIB_SYS && reason == 0) {
  ------------------
  |  Branch (665:7): [True: 0, False: 361]
  |  Branch (665:33): [True: 0, False: 0]
  ------------------
  666|       |#if defined(OPENSSL_WINDOWS)
  667|       |    reason = GetLastError();
  668|       |#else
  669|      0|    reason = errno;
  670|      0|#endif
  671|      0|  }
  672|       |
  673|    361|  state->top = (state->top + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|    361|#define ERR_NUM_ERRORS 16
  ------------------
  674|    361|  if (state->top == state->bottom) {
  ------------------
  |  Branch (674:7): [True: 346, False: 15]
  ------------------
  675|    346|    state->bottom = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|    346|#define ERR_NUM_ERRORS 16
  ------------------
  676|    346|  }
  677|       |
  678|    361|  error = &state->errors[state->top];
  679|    361|  err_clear(error);
  680|    361|  error->file = file;
  681|    361|  error->line = line;
  682|    361|  error->packed = ERR_PACK(library, reason);
  ------------------
  |  |  480|    361|  (((((uint32_t)(lib)) & 0xff) << 24) | ((((uint32_t)(reason)) & 0xfff)))
  ------------------
  683|    361|}
err.c:err_get_state:
  213|    361|static ERR_STATE *err_get_state(void) {
  214|    361|  ERR_STATE *state = CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_ERR);
  215|    361|  if (state == NULL) {
  ------------------
  |  Branch (215:7): [True: 1, False: 360]
  ------------------
  216|      1|    state = malloc(sizeof(ERR_STATE));
  217|      1|    if (state == NULL) {
  ------------------
  |  Branch (217:9): [True: 0, False: 1]
  ------------------
  218|      0|      return NULL;
  219|      0|    }
  220|      1|    OPENSSL_memset(state, 0, sizeof(ERR_STATE));
  221|      1|    if (!CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_ERR, state,
  ------------------
  |  Branch (221:9): [True: 0, False: 1]
  ------------------
  222|      1|                                 err_state_free)) {
  223|      0|      return NULL;
  224|      0|    }
  225|      1|  }
  226|       |
  227|    361|  return state;
  228|    361|}
err.c:err_clear:
  168|    361|static void err_clear(struct err_error_st *error) {
  169|    361|  free(error->data);
  170|    361|  OPENSSL_memset(error, 0, sizeof(struct err_error_st));
  171|    361|}

CRYPTO_new_ex_data:
  206|      2|void CRYPTO_new_ex_data(CRYPTO_EX_DATA *ad) {
  207|      2|  ad->sk = NULL;
  208|      2|}
CRYPTO_free_ex_data:
  211|      2|                         CRYPTO_EX_DATA *ad) {
  212|      2|  if (ad->sk == NULL) {
  ------------------
  |  Branch (212:7): [True: 2, False: 0]
  ------------------
  213|       |    // Nothing to do.
  214|      2|    return;
  215|      2|  }
  216|       |
  217|      0|  uint32_t num_funcs = CRYPTO_atomic_load_u32(&ex_data_class->num_funcs);
  218|       |  // |CRYPTO_get_ex_new_index| will not allocate indices beyond |INT_MAX|.
  219|      0|  assert(num_funcs <= (size_t)(INT_MAX - ex_data_class->num_reserved));
  220|       |
  221|       |  // Defer dereferencing |ex_data_class->funcs| and |funcs->next|. It must come
  222|       |  // after the |num_funcs| comparison to be correctly synchronized.
  223|      0|  CRYPTO_EX_DATA_FUNCS *const *funcs = &ex_data_class->funcs;
  224|      0|  for (uint32_t i = 0; i < num_funcs; i++) {
  ------------------
  |  Branch (224:24): [True: 0, False: 0]
  ------------------
  225|      0|    if ((*funcs)->free_func != NULL) {
  ------------------
  |  Branch (225:9): [True: 0, False: 0]
  ------------------
  226|      0|      int index = (int)i + ex_data_class->num_reserved;
  227|      0|      void *ptr = CRYPTO_get_ex_data(ad, index);
  228|      0|      (*funcs)->free_func(obj, ptr, ad, index, (*funcs)->argl, (*funcs)->argp);
  229|      0|    }
  230|      0|    funcs = &(*funcs)->next;
  231|      0|  }
  232|       |
  233|      0|  sk_void_free(ad->sk);
  234|      0|  ad->sk = NULL;
  235|      0|}

bcm.c:hwaes_capable:
   33|      4|OPENSSL_INLINE int hwaes_capable(void) { return CRYPTO_is_AESNI_capable(); }

EVP_AEAD_CTX_zero:
   36|      3|void EVP_AEAD_CTX_zero(EVP_AEAD_CTX *ctx) {
   37|      3|  OPENSSL_memset(ctx, 0, sizeof(EVP_AEAD_CTX));
   38|      3|}
EVP_AEAD_CTX_cleanup:
   99|      3|void EVP_AEAD_CTX_cleanup(EVP_AEAD_CTX *ctx) {
  100|      3|  if (ctx->aead == NULL) {
  ------------------
  |  Branch (100:7): [True: 3, False: 0]
  ------------------
  101|      3|    return;
  102|      3|  }
  103|      0|  ctx->aead->cleanup(ctx);
  104|      0|  ctx->aead = NULL;
  105|      0|}

aes_ctr_set_key:
  292|      3|                         size_t key_bytes) {
  293|       |  // This function assumes the key length was previously validated.
  294|      3|  assert(key_bytes == 128 / 8 || key_bytes == 192 / 8 || key_bytes == 256 / 8);
  295|      3|  if (hwaes_capable()) {
  ------------------
  |  Branch (295:7): [True: 3, False: 0]
  ------------------
  296|      3|    aes_hw_set_encrypt_key(key, (int)key_bytes * 8, aes_key);
  297|      3|    if (gcm_key != NULL) {
  ------------------
  |  Branch (297:9): [True: 0, False: 3]
  ------------------
  298|      0|      CRYPTO_gcm128_init_key(gcm_key, aes_key, aes_hw_encrypt, 1);
  299|      0|    }
  300|      3|    if (out_block) {
  ------------------
  |  Branch (300:9): [True: 3, False: 0]
  ------------------
  301|      3|      *out_block = aes_hw_encrypt;
  302|      3|    }
  303|      3|    return aes_hw_ctr32_encrypt_blocks;
  304|      3|  }
  305|       |
  306|      0|  if (vpaes_capable()) {
  ------------------
  |  Branch (306:7): [True: 0, False: 0]
  ------------------
  307|      0|    vpaes_set_encrypt_key(key, (int)key_bytes * 8, aes_key);
  308|      0|    if (out_block) {
  ------------------
  |  Branch (308:9): [True: 0, False: 0]
  ------------------
  309|      0|      *out_block = vpaes_encrypt;
  310|      0|    }
  311|      0|    if (gcm_key != NULL) {
  ------------------
  |  Branch (311:9): [True: 0, False: 0]
  ------------------
  312|      0|      CRYPTO_gcm128_init_key(gcm_key, aes_key, vpaes_encrypt, 0);
  313|      0|    }
  314|       |#if defined(BSAES)
  315|       |    assert(bsaes_capable());
  316|       |    return vpaes_ctr32_encrypt_blocks_with_bsaes;
  317|       |#elif defined(VPAES_CTR32)
  318|      0|    return vpaes_ctr32_encrypt_blocks;
  319|       |#else
  320|       |    return NULL;
  321|       |#endif
  322|      0|  }
  323|       |
  324|      0|  aes_nohw_set_encrypt_key(key, (int)key_bytes * 8, aes_key);
  325|      0|  if (gcm_key != NULL) {
  ------------------
  |  Branch (325:7): [True: 0, False: 0]
  ------------------
  326|      0|    CRYPTO_gcm128_init_key(gcm_key, aes_key, aes_nohw_encrypt, 0);
  327|      0|  }
  328|      0|  if (out_block) {
  ------------------
  |  Branch (328:7): [True: 0, False: 0]
  ------------------
  329|      0|    *out_block = aes_nohw_encrypt;
  330|      0|  }
  331|      0|  return aes_nohw_ctr32_encrypt_blocks;
  332|      0|}
EVP_has_aes_hardware:
 1466|      1|int EVP_has_aes_hardware(void) {
 1467|      1|#if defined(OPENSSL_X86) || defined(OPENSSL_X86_64)
 1468|      1|  return hwaes_capable() && crypto_gcm_clmul_enabled();
  ------------------
  |  Branch (1468:10): [True: 1, False: 0]
  |  Branch (1468:29): [True: 1, False: 0]
  ------------------
 1469|       |#elif defined(OPENSSL_ARM) || defined(OPENSSL_AARCH64)
 1470|       |  return hwaes_capable() && CRYPTO_is_ARMv8_PMULL_capable();
 1471|       |#else
 1472|       |  return 0;
 1473|       |#endif
 1474|      1|}

bcm.c:g_fork_detect_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:g_fork_detect_addr_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_force_madv_wipeonfork_bss_get:
   39|      1|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_fork_generation_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }

EVP_MD_CTX_init:
   80|      6|void EVP_MD_CTX_init(EVP_MD_CTX *ctx) {
   81|      6|  OPENSSL_memset(ctx, 0, sizeof(EVP_MD_CTX));
   82|      6|}
EVP_MD_CTX_cleanup:
   96|      3|int EVP_MD_CTX_cleanup(EVP_MD_CTX *ctx) {
   97|      3|  OPENSSL_free(ctx->md_data);
   98|       |
   99|      3|  assert(ctx->pctx == NULL || ctx->pctx_ops != NULL);
  100|      3|  if (ctx->pctx_ops) {
  ------------------
  |  Branch (100:7): [True: 0, False: 3]
  ------------------
  101|      0|    ctx->pctx_ops->free(ctx->pctx);
  102|      0|  }
  103|       |
  104|      3|  EVP_MD_CTX_init(ctx);
  105|       |
  106|      3|  return 1;
  107|      3|}

crypto_gcm_clmul_enabled:
  736|      1|int crypto_gcm_clmul_enabled(void) {
  737|      1|#if defined(GHASH_ASM_X86) || defined(GHASH_ASM_X86_64)
  738|      1|  return CRYPTO_is_FXSR_capable() && CRYPTO_is_PCLMUL_capable();
  ------------------
  |  Branch (738:10): [True: 1, False: 0]
  |  Branch (738:38): [True: 1, False: 0]
  ------------------
  739|       |#else
  740|       |  return 0;
  741|       |#endif
  742|      1|}

CTR_DRBG_init:
   49|      1|                  const uint8_t *personalization, size_t personalization_len) {
   50|       |  // Section 10.2.1.3.1
   51|      1|  if (personalization_len > CTR_DRBG_ENTROPY_LEN) {
  ------------------
  |  |   36|      1|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  |  Branch (51:7): [True: 0, False: 1]
  ------------------
   52|      0|    return 0;
   53|      0|  }
   54|       |
   55|      1|  uint8_t seed_material[CTR_DRBG_ENTROPY_LEN];
   56|      1|  OPENSSL_memcpy(seed_material, entropy, CTR_DRBG_ENTROPY_LEN);
  ------------------
  |  |   36|      1|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
   57|       |
   58|      1|  for (size_t i = 0; i < personalization_len; i++) {
  ------------------
  |  Branch (58:22): [True: 0, False: 1]
  ------------------
   59|      0|    seed_material[i] ^= personalization[i];
   60|      0|  }
   61|       |
   62|       |  // Section 10.2.1.2
   63|       |
   64|       |  // kInitMask is the result of encrypting blocks with big-endian value 1, 2
   65|       |  // and 3 with the all-zero AES-256 key.
   66|      1|  static const uint8_t kInitMask[CTR_DRBG_ENTROPY_LEN] = {
   67|      1|      0x53, 0x0f, 0x8a, 0xfb, 0xc7, 0x45, 0x36, 0xb9, 0xa9, 0x63, 0xb4, 0xf1,
   68|      1|      0xc4, 0xcb, 0x73, 0x8b, 0xce, 0xa7, 0x40, 0x3d, 0x4d, 0x60, 0x6b, 0x6e,
   69|      1|      0x07, 0x4e, 0xc5, 0xd3, 0xba, 0xf3, 0x9d, 0x18, 0x72, 0x60, 0x03, 0xca,
   70|      1|      0x37, 0xa6, 0x2a, 0x74, 0xd1, 0xa2, 0xf5, 0x8e, 0x75, 0x06, 0x35, 0x8e,
   71|      1|  };
   72|       |
   73|     49|  for (size_t i = 0; i < sizeof(kInitMask); i++) {
  ------------------
  |  Branch (73:22): [True: 48, False: 1]
  ------------------
   74|     48|    seed_material[i] ^= kInitMask[i];
   75|     48|  }
   76|       |
   77|      1|  drbg->ctr = aes_ctr_set_key(&drbg->ks, NULL, &drbg->block, seed_material, 32);
   78|      1|  OPENSSL_memcpy(drbg->counter, seed_material + 32, 16);
   79|      1|  drbg->reseed_counter = 1;
   80|       |
   81|      1|  return 1;
   82|      1|}
CTR_DRBG_generate:
  150|      1|                      size_t additional_data_len) {
  151|       |  // See 9.3.1
  152|      1|  if (out_len > CTR_DRBG_MAX_GENERATE_LENGTH) {
  ------------------
  |  |   40|      1|#define CTR_DRBG_MAX_GENERATE_LENGTH 65536
  ------------------
  |  Branch (152:7): [True: 0, False: 1]
  ------------------
  153|      0|    return 0;
  154|      0|  }
  155|       |
  156|       |  // See 10.2.1.5.1
  157|      1|  if (drbg->reseed_counter > kMaxReseedCount) {
  ------------------
  |  Branch (157:7): [True: 0, False: 1]
  ------------------
  158|      0|    return 0;
  159|      0|  }
  160|       |
  161|      1|  if (additional_data_len != 0 &&
  ------------------
  |  Branch (161:7): [True: 1, False: 0]
  ------------------
  162|      1|      !ctr_drbg_update(drbg, additional_data, additional_data_len)) {
  ------------------
  |  Branch (162:7): [True: 0, False: 1]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|       |  // kChunkSize is used to interact better with the cache. Since the AES-CTR
  167|       |  // code assumes that it's encrypting rather than just writing keystream, the
  168|       |  // buffer has to be zeroed first. Without chunking, large reads would zero
  169|       |  // the whole buffer, flushing the L1 cache, and then do another pass (missing
  170|       |  // the cache every time) to “encrypt” it. The code can avoid this by
  171|       |  // chunking.
  172|      1|  static const size_t kChunkSize = 8 * 1024;
  173|       |
  174|      1|  while (out_len >= AES_BLOCK_SIZE) {
  ------------------
  |  |   68|      1|#define AES_BLOCK_SIZE 16
  ------------------
  |  Branch (174:10): [True: 0, False: 1]
  ------------------
  175|      0|    size_t todo = kChunkSize;
  176|      0|    if (todo > out_len) {
  ------------------
  |  Branch (176:9): [True: 0, False: 0]
  ------------------
  177|      0|      todo = out_len;
  178|      0|    }
  179|       |
  180|      0|    todo &= ~(AES_BLOCK_SIZE-1);
  ------------------
  |  |   68|      0|#define AES_BLOCK_SIZE 16
  ------------------
  181|      0|    const size_t num_blocks = todo / AES_BLOCK_SIZE;
  ------------------
  |  |   68|      0|#define AES_BLOCK_SIZE 16
  ------------------
  182|       |
  183|      0|    if (drbg->ctr) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      OPENSSL_memset(out, 0, todo);
  185|      0|      ctr32_add(drbg, 1);
  186|      0|      drbg->ctr(out, out, num_blocks, &drbg->ks, drbg->counter);
  187|      0|      ctr32_add(drbg, (uint32_t)(num_blocks - 1));
  188|      0|    } else {
  189|      0|      for (size_t i = 0; i < todo; i += AES_BLOCK_SIZE) {
  ------------------
  |  |   68|      0|#define AES_BLOCK_SIZE 16
  ------------------
  |  Branch (189:26): [True: 0, False: 0]
  ------------------
  190|      0|        ctr32_add(drbg, 1);
  191|      0|        drbg->block(drbg->counter, out + i, &drbg->ks);
  192|      0|      }
  193|      0|    }
  194|       |
  195|      0|    out += todo;
  196|      0|    out_len -= todo;
  197|      0|  }
  198|       |
  199|      1|  if (out_len > 0) {
  ------------------
  |  Branch (199:7): [True: 1, False: 0]
  ------------------
  200|      1|    uint8_t block[AES_BLOCK_SIZE];
  201|      1|    ctr32_add(drbg, 1);
  202|      1|    drbg->block(drbg->counter, block, &drbg->ks);
  203|       |
  204|      1|    OPENSSL_memcpy(out, block, out_len);
  205|      1|  }
  206|       |
  207|       |  // Right-padding |additional_data| in step 2.2 is handled implicitly by
  208|       |  // |ctr_drbg_update|, to save a copy.
  209|      1|  if (!ctr_drbg_update(drbg, additional_data, additional_data_len)) {
  ------------------
  |  Branch (209:7): [True: 0, False: 1]
  ------------------
  210|      0|    return 0;
  211|      0|  }
  212|       |
  213|      1|  drbg->reseed_counter++;
  214|      1|  FIPS_service_indicator_update_state();
  215|      1|  return 1;
  216|      1|}
bcm.c:ctr_drbg_update:
   95|      2|                           size_t data_len) {
   96|       |  // Per section 10.2.1.2, |data_len| must be |CTR_DRBG_ENTROPY_LEN|. Here, we
   97|       |  // allow shorter inputs and right-pad them with zeros. This is equivalent to
   98|       |  // the specified algorithm but saves a copy in |CTR_DRBG_generate|.
   99|      2|  if (data_len > CTR_DRBG_ENTROPY_LEN) {
  ------------------
  |  |   36|      2|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  |  Branch (99:7): [True: 0, False: 2]
  ------------------
  100|      0|    return 0;
  101|      0|  }
  102|       |
  103|      2|  uint8_t temp[CTR_DRBG_ENTROPY_LEN];
  104|      8|  for (size_t i = 0; i < CTR_DRBG_ENTROPY_LEN; i += AES_BLOCK_SIZE) {
  ------------------
  |  |   36|      8|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
                for (size_t i = 0; i < CTR_DRBG_ENTROPY_LEN; i += AES_BLOCK_SIZE) {
  ------------------
  |  |   68|      6|#define AES_BLOCK_SIZE 16
  ------------------
  |  Branch (104:22): [True: 6, False: 2]
  ------------------
  105|      6|    ctr32_add(drbg, 1);
  106|      6|    drbg->block(drbg->counter, temp + i, &drbg->ks);
  107|      6|  }
  108|       |
  109|     66|  for (size_t i = 0; i < data_len; i++) {
  ------------------
  |  Branch (109:22): [True: 64, False: 2]
  ------------------
  110|     64|    temp[i] ^= data[i];
  111|     64|  }
  112|       |
  113|      2|  drbg->ctr = aes_ctr_set_key(&drbg->ks, NULL, &drbg->block, temp, 32);
  114|      2|  OPENSSL_memcpy(drbg->counter, temp + 32, 16);
  115|       |
  116|      2|  return 1;
  117|      2|}
bcm.c:ctr32_add:
   89|      7|static void ctr32_add(CTR_DRBG_STATE *drbg, uint32_t n) {
   90|      7|  uint32_t ctr = CRYPTO_load_u32_be(drbg->counter + 12);
   91|      7|  CRYPTO_store_u32_be(drbg->counter + 12, ctr + n);
   92|      7|}

CRYPTO_get_fork_generation:
   78|      1|uint64_t CRYPTO_get_fork_generation(void) {
   79|       |  // In a single-threaded process, there are obviously no races because there's
   80|       |  // only a single mutator in the address space.
   81|       |  //
   82|       |  // In a multi-threaded environment, |CRYPTO_once| ensures that the flag byte
   83|       |  // is initialised atomically, even if multiple threads enter this function
   84|       |  // concurrently.
   85|       |  //
   86|       |  // Additionally, while the kernel will only clear WIPEONFORK at a point when a
   87|       |  // child process is single-threaded, the child may become multi-threaded
   88|       |  // before it observes this. Therefore, we must synchronize the logic below.
   89|       |
   90|      1|  CRYPTO_once(g_fork_detect_once_bss_get(), init_fork_detect);
   91|      1|  CRYPTO_atomic_u32 *const flag_ptr = *g_fork_detect_addr_bss_get();
   92|      1|  if (flag_ptr == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 1]
  ------------------
   93|       |    // Our kernel is too old to support |MADV_WIPEONFORK| or
   94|       |    // |g_force_madv_wipeonfork| is set.
   95|      0|    if (*g_force_madv_wipeonfork_bss_get() &&
  ------------------
  |  Branch (95:9): [True: 0, False: 0]
  ------------------
   96|      0|        *g_force_madv_wipeonfork_enabled_bss_get()) {
  ------------------
  |  Branch (96:9): [True: 0, False: 0]
  ------------------
   97|       |      // A constant generation number to simulate support, even if the kernel
   98|       |      // doesn't support it.
   99|      0|      return 42;
  100|      0|    }
  101|      0|    return 0;
  102|      0|  }
  103|       |
  104|       |  // In the common case, try to observe the flag without taking a lock. This
  105|       |  // avoids cacheline contention in the PRNG.
  106|      1|  uint64_t *const generation_ptr = g_fork_generation_bss_get();
  107|      1|  if (CRYPTO_atomic_load_u32(flag_ptr) != 0) {
  ------------------
  |  Branch (107:7): [True: 1, False: 0]
  ------------------
  108|       |    // If we observe a non-zero flag, it is safe to read |generation_ptr|
  109|       |    // without a lock. The flag and generation number are fixed for this copy of
  110|       |    // the address space.
  111|      1|    return *generation_ptr;
  112|      1|  }
  113|       |
  114|       |  // The flag was zero. The generation number must be incremented, but other
  115|       |  // threads may have concurrently observed the zero, so take a lock before
  116|       |  // incrementing.
  117|      0|  struct CRYPTO_STATIC_MUTEX *const lock = g_fork_detect_lock_bss_get();
  118|      0|  CRYPTO_STATIC_MUTEX_lock_write(lock);
  119|      0|  uint64_t current_generation = *generation_ptr;
  120|      0|  if (CRYPTO_atomic_load_u32(flag_ptr) == 0) {
  ------------------
  |  Branch (120:7): [True: 0, False: 0]
  ------------------
  121|       |    // A fork has occurred.
  122|      0|    current_generation++;
  123|      0|    if (current_generation == 0) {
  ------------------
  |  Branch (123:9): [True: 0, False: 0]
  ------------------
  124|       |      // Zero means fork detection isn't supported, so skip that value.
  125|      0|      current_generation = 1;
  126|      0|    }
  127|       |
  128|       |    // We must update |generation_ptr| before |flag_ptr|. Other threads may
  129|       |    // observe |flag_ptr| without taking a lock.
  130|      0|    *generation_ptr = current_generation;
  131|      0|    CRYPTO_atomic_store_u32(flag_ptr, 1);
  132|      0|  }
  133|      0|  CRYPTO_STATIC_MUTEX_unlock_write(lock);
  134|       |
  135|      0|  return current_generation;
  136|      1|}
bcm.c:init_fork_detect:
   46|      1|static void init_fork_detect(void) {
   47|      1|  if (*g_force_madv_wipeonfork_bss_get()) {
  ------------------
  |  Branch (47:7): [True: 0, False: 1]
  ------------------
   48|      0|    return;
   49|      0|  }
   50|       |
   51|      1|  long page_size = sysconf(_SC_PAGESIZE);
   52|      1|  if (page_size <= 0) {
  ------------------
  |  Branch (52:7): [True: 0, False: 1]
  ------------------
   53|      0|    return;
   54|      0|  }
   55|       |
   56|      1|  void *addr = mmap(NULL, (size_t)page_size, PROT_READ | PROT_WRITE,
   57|      1|                    MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
   58|      1|  if (addr == MAP_FAILED) {
  ------------------
  |  Branch (58:7): [True: 0, False: 1]
  ------------------
   59|      0|    return;
   60|      0|  }
   61|       |
   62|       |  // Some versions of qemu (up to at least 5.0.0-rc4, see linux-user/syscall.c)
   63|       |  // ignore |madvise| calls and just return zero (i.e. success). But we need to
   64|       |  // know whether MADV_WIPEONFORK actually took effect. Therefore try an invalid
   65|       |  // call to check that the implementation of |madvise| is actually rejecting
   66|       |  // unknown |advice| values.
   67|      1|  if (madvise(addr, (size_t)page_size, -1) == 0 ||
  ------------------
  |  Branch (67:7): [True: 0, False: 1]
  ------------------
   68|      1|      madvise(addr, (size_t)page_size, MADV_WIPEONFORK) != 0) {
  ------------------
  |  Branch (68:7): [True: 0, False: 1]
  ------------------
   69|      0|    munmap(addr, (size_t)page_size);
   70|      0|    return;
   71|      0|  }
   72|       |
   73|      1|  CRYPTO_atomic_store_u32(addr, 1);
   74|      1|  *g_fork_detect_addr_bss_get() = addr;
   75|      1|  *g_fork_generation_bss_get() = 1;
   76|      1|}

bcm.c:have_fast_rdrand:
  125|      1|OPENSSL_INLINE int have_fast_rdrand(void) {
  126|      1|  return CRYPTO_is_RDRAND_capable() && CRYPTO_is_intel_cpu();
  ------------------
  |  Branch (126:10): [True: 1, False: 0]
  |  Branch (126:40): [True: 1, False: 0]
  ------------------
  127|      1|}

RAND_bytes_with_additional_data:
  331|      1|                                     const uint8_t user_additional_data[32]) {
  332|      1|  if (out_len == 0) {
  ------------------
  |  Branch (332:7): [True: 0, False: 1]
  ------------------
  333|      0|    return;
  334|      0|  }
  335|       |
  336|      1|  const uint64_t fork_generation = CRYPTO_get_fork_generation();
  337|      1|  const int fork_unsafe_buffering = rand_fork_unsafe_buffering_enabled();
  338|       |
  339|       |  // Additional data is mixed into every CTR-DRBG call to protect, as best we
  340|       |  // can, against forks & VM clones. We do not over-read this information and
  341|       |  // don't reseed with it so, from the point of view of FIPS, this doesn't
  342|       |  // provide “prediction resistance”. But, in practice, it does.
  343|      1|  uint8_t additional_data[32];
  344|       |  // Intel chips have fast RDRAND instructions while, in other cases, RDRAND can
  345|       |  // be _slower_ than a system call.
  346|      1|  if (!have_fast_rdrand() ||
  ------------------
  |  Branch (346:7): [True: 0, False: 1]
  ------------------
  347|      1|      !rdrand(additional_data, sizeof(additional_data))) {
  ------------------
  |  Branch (347:7): [True: 1, False: 0]
  ------------------
  348|       |    // Without a hardware RNG to save us from address-space duplication, the OS
  349|       |    // entropy is used. This can be expensive (one read per |RAND_bytes| call)
  350|       |    // and so is disabled when we have fork detection, or if the application has
  351|       |    // promised not to fork.
  352|      1|    if (fork_generation != 0 || fork_unsafe_buffering) {
  ------------------
  |  Branch (352:9): [True: 1, False: 0]
  |  Branch (352:33): [True: 0, False: 0]
  ------------------
  353|      1|      OPENSSL_memset(additional_data, 0, sizeof(additional_data));
  354|      1|    } else if (!have_rdrand()) {
  ------------------
  |  Branch (354:16): [True: 0, False: 0]
  ------------------
  355|       |      // No alternative so block for OS entropy.
  356|      0|      CRYPTO_sysrand(additional_data, sizeof(additional_data));
  357|      0|    } else if (!CRYPTO_sysrand_if_available(additional_data,
  ------------------
  |  Branch (357:16): [True: 0, False: 0]
  ------------------
  358|      0|                                            sizeof(additional_data)) &&
  359|      0|               !rdrand(additional_data, sizeof(additional_data))) {
  ------------------
  |  Branch (359:16): [True: 0, False: 0]
  ------------------
  360|       |      // RDRAND failed: block for OS entropy.
  361|      0|      CRYPTO_sysrand(additional_data, sizeof(additional_data));
  362|      0|    }
  363|      1|  }
  364|       |
  365|     33|  for (size_t i = 0; i < sizeof(additional_data); i++) {
  ------------------
  |  Branch (365:22): [True: 32, False: 1]
  ------------------
  366|     32|    additional_data[i] ^= user_additional_data[i];
  367|     32|  }
  368|       |
  369|      1|  struct rand_thread_state stack_state;
  370|      1|  struct rand_thread_state *state =
  371|      1|      CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_RAND);
  372|       |
  373|      1|  if (state == NULL) {
  ------------------
  |  Branch (373:7): [True: 1, False: 0]
  ------------------
  374|      1|    state = OPENSSL_malloc(sizeof(struct rand_thread_state));
  375|      1|    if (state == NULL ||
  ------------------
  |  Branch (375:9): [True: 0, False: 1]
  ------------------
  376|      1|        !CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_RAND, state,
  ------------------
  |  Branch (376:9): [True: 0, False: 1]
  ------------------
  377|      1|                                 rand_thread_state_free)) {
  378|       |      // If the system is out of memory, use an ephemeral state on the
  379|       |      // stack.
  380|      0|      state = &stack_state;
  381|      0|    }
  382|       |
  383|      1|    state->last_block_valid = 0;
  384|      1|    uint8_t seed[CTR_DRBG_ENTROPY_LEN];
  385|      1|    uint8_t personalization[CTR_DRBG_ENTROPY_LEN] = {0};
  386|      1|    size_t personalization_len = 0;
  387|      1|    rand_get_seed(state, seed, personalization, &personalization_len);
  388|       |
  389|      1|    if (!CTR_DRBG_init(&state->drbg, seed, personalization,
  ------------------
  |  Branch (389:9): [True: 0, False: 1]
  ------------------
  390|      1|                       personalization_len)) {
  391|      0|      abort();
  392|      0|    }
  393|      1|    state->calls = 0;
  394|      1|    state->fork_generation = fork_generation;
  395|      1|    state->fork_unsafe_buffering = fork_unsafe_buffering;
  396|       |
  397|       |#if defined(BORINGSSL_FIPS)
  398|       |    CRYPTO_MUTEX_init(&state->clear_drbg_lock);
  399|       |    if (state != &stack_state) {
  400|       |      CRYPTO_STATIC_MUTEX_lock_write(thread_states_list_lock_bss_get());
  401|       |      struct rand_thread_state **states_list = thread_states_list_bss_get();
  402|       |      state->next = *states_list;
  403|       |      if (state->next != NULL) {
  404|       |        state->next->prev = state;
  405|       |      }
  406|       |      state->prev = NULL;
  407|       |      *states_list = state;
  408|       |      CRYPTO_STATIC_MUTEX_unlock_write(thread_states_list_lock_bss_get());
  409|       |    }
  410|       |#endif
  411|      1|  }
  412|       |
  413|      1|  if (state->calls >= kReseedInterval ||
  ------------------
  |  Branch (413:7): [True: 0, False: 1]
  ------------------
  414|       |      // If we've forked since |state| was last seeded, reseed.
  415|      1|      state->fork_generation != fork_generation ||
  ------------------
  |  Branch (415:7): [True: 0, False: 1]
  ------------------
  416|       |      // If |state| was seeded from a state with different fork-safety
  417|       |      // preferences, reseed. Suppose |state| was fork-safe, then forked into
  418|       |      // two children, but each of the children never fork and disable fork
  419|       |      // safety. The children must reseed to avoid working from the same PRNG
  420|       |      // state.
  421|      1|      state->fork_unsafe_buffering != fork_unsafe_buffering) {
  ------------------
  |  Branch (421:7): [True: 0, False: 1]
  ------------------
  422|      0|    uint8_t seed[CTR_DRBG_ENTROPY_LEN];
  423|      0|    uint8_t reseed_additional_data[CTR_DRBG_ENTROPY_LEN] = {0};
  424|      0|    size_t reseed_additional_data_len = 0;
  425|      0|    rand_get_seed(state, seed, reseed_additional_data,
  426|      0|                  &reseed_additional_data_len);
  427|       |#if defined(BORINGSSL_FIPS)
  428|       |    // Take a read lock around accesses to |state->drbg|. This is needed to
  429|       |    // avoid returning bad entropy if we race with
  430|       |    // |rand_thread_state_clear_all|.
  431|       |    CRYPTO_MUTEX_lock_read(&state->clear_drbg_lock);
  432|       |#endif
  433|      0|    if (!CTR_DRBG_reseed(&state->drbg, seed, reseed_additional_data,
  ------------------
  |  Branch (433:9): [True: 0, False: 0]
  ------------------
  434|      0|                         reseed_additional_data_len)) {
  435|      0|      abort();
  436|      0|    }
  437|      0|    state->calls = 0;
  438|      0|    state->fork_generation = fork_generation;
  439|      0|    state->fork_unsafe_buffering = fork_unsafe_buffering;
  440|      1|  } else {
  441|       |#if defined(BORINGSSL_FIPS)
  442|       |    CRYPTO_MUTEX_lock_read(&state->clear_drbg_lock);
  443|       |#endif
  444|      1|  }
  445|       |
  446|      1|  int first_call = 1;
  447|      2|  while (out_len > 0) {
  ------------------
  |  Branch (447:10): [True: 1, False: 1]
  ------------------
  448|      1|    size_t todo = out_len;
  449|      1|    if (todo > CTR_DRBG_MAX_GENERATE_LENGTH) {
  ------------------
  |  |   40|      1|#define CTR_DRBG_MAX_GENERATE_LENGTH 65536
  ------------------
  |  Branch (449:9): [True: 0, False: 1]
  ------------------
  450|      0|      todo = CTR_DRBG_MAX_GENERATE_LENGTH;
  ------------------
  |  |   40|      0|#define CTR_DRBG_MAX_GENERATE_LENGTH 65536
  ------------------
  451|      0|    }
  452|       |
  453|      1|    if (!CTR_DRBG_generate(&state->drbg, out, todo, additional_data,
  ------------------
  |  Branch (453:9): [True: 0, False: 1]
  ------------------
  454|      1|                           first_call ? sizeof(additional_data) : 0)) {
  ------------------
  |  Branch (454:28): [True: 1, False: 0]
  ------------------
  455|      0|      abort();
  456|      0|    }
  457|       |
  458|      1|    out += todo;
  459|      1|    out_len -= todo;
  460|       |    // Though we only check before entering the loop, this cannot add enough to
  461|       |    // overflow a |size_t|.
  462|      1|    state->calls++;
  463|      1|    first_call = 0;
  464|      1|  }
  465|       |
  466|      1|  if (state == &stack_state) {
  ------------------
  |  Branch (466:7): [True: 0, False: 1]
  ------------------
  467|      0|    CTR_DRBG_clear(&state->drbg);
  468|      0|  }
  469|       |
  470|       |#if defined(BORINGSSL_FIPS)
  471|       |  CRYPTO_MUTEX_unlock_read(&state->clear_drbg_lock);
  472|       |#endif
  473|      1|}
RAND_bytes:
  475|      1|int RAND_bytes(uint8_t *out, size_t out_len) {
  476|      1|  static const uint8_t kZeroAdditionalData[32] = {0};
  477|      1|  RAND_bytes_with_additional_data(out, out_len, kZeroAdditionalData);
  478|      1|  return 1;
  479|      1|}
bcm.c:rdrand:
  164|      1|static int rdrand(uint8_t *buf, size_t len) {
  165|      1|  return 0;
  166|      1|}
bcm.c:rand_get_seed:
  321|      1|                          size_t *out_additional_input_len) {
  322|       |  // If not in FIPS mode, we don't overread from the system entropy source and
  323|       |  // we don't depend only on the hardware RDRAND.
  324|      1|  CRYPTO_sysrand_for_seed(seed, CTR_DRBG_ENTROPY_LEN);
  ------------------
  |  |   36|      1|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  325|      1|  *out_additional_input_len = 0;
  326|      1|}

bcm.c:FIPS_service_indicator_update_state:
   56|      1|OPENSSL_INLINE void FIPS_service_indicator_update_state(void) {}

EVP_HPKE_CTX_zero:
  540|      1|void EVP_HPKE_CTX_zero(EVP_HPKE_CTX *ctx) {
  541|      1|  OPENSSL_memset(ctx, 0, sizeof(EVP_HPKE_CTX));
  542|      1|  EVP_AEAD_CTX_zero(&ctx->aead_ctx);
  543|      1|}
EVP_HPKE_CTX_cleanup:
  545|      1|void EVP_HPKE_CTX_cleanup(EVP_HPKE_CTX *ctx) {
  546|      1|  EVP_AEAD_CTX_cleanup(&ctx->aead_ctx);
  547|      1|}

decode_client_hello_inner.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|    760|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    760|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 360, False: 400]
  ------------------
 1041|    360|    return dst;
 1042|    360|  }
 1043|       |
 1044|    400|  return memcpy(dst, src, n);
 1045|    760|}
_ZN4bssl8internal13MutexLockBaseIXadL_Z23CRYPTO_MUTEX_lock_writeEEXadL_Z25CRYPTO_MUTEX_unlock_writeEEEC2EP15crypto_mutex_st:
  821|      1|  explicit MutexLockBase(CRYPTO_MUTEX *mu) : mu_(mu) {
  822|      1|    assert(mu_ != nullptr);
  823|      0|    LockFunc(mu_);
  824|      1|  }
_ZN4bssl8internal13MutexLockBaseIXadL_Z23CRYPTO_MUTEX_lock_writeEEXadL_Z25CRYPTO_MUTEX_unlock_writeEEED2Ev:
  825|      1|  ~MutexLockBase() { ReleaseFunc(mu_); }
extensions.cc:_ZL14OPENSSL_memsetPvim:
 1055|  1.39k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  1.39k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1.39k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  1.39k|  return memset(dst, c, n);
 1061|  1.39k|}
ssl_aead_ctx.cc:_ZL14OPENSSL_memsetPvim:
 1055|      2|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      2|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 2]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      2|  return memset(dst, c, n);
 1061|      2|}
ssl_cert.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|      2|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      2|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 1, False: 1]
  ------------------
 1041|      1|    return dst;
 1042|      1|  }
 1043|       |
 1044|      1|  return memcpy(dst, src, n);
 1045|      2|}
ssl_cipher.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|      1|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      1|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 1]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      1|  return memcpy(dst, src, n);
 1045|      1|}
ssl_lib.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|      3|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      3|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 3, False: 0]
  ------------------
 1041|      3|    return dst;
 1042|      3|  }
 1043|       |
 1044|      0|  return memcpy(dst, src, n);
 1045|      3|}
bcm.c:CRYPTO_is_AESNI_capable:
 1324|      4|OPENSSL_INLINE int CRYPTO_is_AESNI_capable(void) {
 1325|       |#if defined(__AES__)
 1326|       |  return 1;
 1327|       |#else
 1328|      4|  return (OPENSSL_ia32cap_get()[1] & (1 << 25)) != 0;
 1329|      4|#endif
 1330|      4|}
bcm.c:OPENSSL_ia32cap_get:
 1270|      7|OPENSSL_INLINE const uint32_t *OPENSSL_ia32cap_get(void) {
 1271|      7|  return OPENSSL_ia32cap_P;
 1272|      7|}
bcm.c:CRYPTO_load_u32_be:
 1080|      7|static inline uint32_t CRYPTO_load_u32_be(const void *in) {
 1081|      7|  uint32_t v;
 1082|      7|  OPENSSL_memcpy(&v, in, sizeof(v));
 1083|      7|  return CRYPTO_bswap4(v);
 1084|      7|}
bcm.c:CRYPTO_bswap4:
  945|     14|static inline uint32_t CRYPTO_bswap4(uint32_t x) {
  946|     14|  return __builtin_bswap32(x);
  947|     14|}
bcm.c:CRYPTO_store_u32_be:
 1086|      7|static inline void CRYPTO_store_u32_be(void *out, uint32_t v) {
 1087|      7|  v = CRYPTO_bswap4(v);
 1088|      7|  OPENSSL_memcpy(out, &v, sizeof(v));
 1089|      7|}
bcm.c:OPENSSL_memcpy:
 1039|     19|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|     19|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 19]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|     19|  return memcpy(dst, src, n);
 1045|     19|}
bcm.c:OPENSSL_memset:
 1055|     10|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|     10|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 10]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|     10|  return memset(dst, c, n);
 1061|     10|}
bcm.c:CRYPTO_is_FXSR_capable:
 1277|      1|OPENSSL_INLINE int CRYPTO_is_FXSR_capable(void) {
 1278|      1|#if defined(__FXSR__)
 1279|      1|  return 1;
 1280|       |#else
 1281|       |  return (OPENSSL_ia32cap_get()[0] & (1 << 24)) != 0;
 1282|       |#endif
 1283|      1|}
bcm.c:CRYPTO_is_PCLMUL_capable:
 1292|      1|OPENSSL_INLINE int CRYPTO_is_PCLMUL_capable(void) {
 1293|       |#if defined(__PCLMUL__)
 1294|       |  return 1;
 1295|       |#else
 1296|      1|  return (OPENSSL_ia32cap_get()[1] & (1 << 1)) != 0;
 1297|      1|#endif
 1298|      1|}
bcm.c:CRYPTO_atomic_load_u32:
  626|      1|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|      1|  return atomic_load(val);
  628|      1|}
bcm.c:CRYPTO_atomic_store_u32:
  636|      1|                                            uint32_t desired) {
  637|      1|  atomic_store(val, desired);
  638|      1|}
bcm.c:CRYPTO_is_RDRAND_capable:
 1340|      1|OPENSSL_INLINE int CRYPTO_is_RDRAND_capable(void) {
 1341|       |  // The GCC/Clang feature name and preprocessor symbol for RDRAND are "rdrnd"
 1342|       |  // and |__RDRND__|, respectively.
 1343|       |#if defined(__RDRND__)
 1344|       |  return 1;
 1345|       |#else
 1346|      1|  return (OPENSSL_ia32cap_get()[1] & (1u << 30)) != 0;
 1347|      1|#endif
 1348|      1|}
bcm.c:CRYPTO_is_intel_cpu:
 1285|      1|OPENSSL_INLINE int CRYPTO_is_intel_cpu(void) {
 1286|       |  // The reserved bit 30 is used to indicate an Intel CPU.
 1287|      1|  return (OPENSSL_ia32cap_get()[0] & (1 << 30)) != 0;
 1288|      1|}
buf.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
cbb.c:OPENSSL_memset:
 1055|  3.76k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  3.76k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 3.76k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  3.76k|  return memset(dst, c, n);
 1061|  3.76k|}
cbb.c:OPENSSL_memcpy:
 1039|  1.65k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  1.65k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 400, False: 1.25k]
  ------------------
 1041|    400|    return dst;
 1042|    400|  }
 1043|       |
 1044|  1.25k|  return memcpy(dst, src, n);
 1045|  1.65k|}
err.c:OPENSSL_memset:
 1055|    362|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|    362|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 362]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|    362|  return memset(dst, c, n);
 1061|    362|}
hpke.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
lhash.c:OPENSSL_memset:
 1055|      2|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      2|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 2]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      2|  return memset(dst, c, n);
 1061|      2|}
mem.c:OPENSSL_memset:
 1055|  1.64k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  1.64k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1.64k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  1.64k|  return memset(dst, c, n);
 1061|  1.64k|}
deterministic.c:OPENSSL_memset:
 1055|      2|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      2|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 2]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      2|  return memset(dst, c, n);
 1061|      2|}
deterministic.c:OPENSSL_memcpy:
 1039|      1|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      1|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 1]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      1|  return memcpy(dst, src, n);
 1045|      1|}
forkunsafe.c:CRYPTO_atomic_load_u32:
  626|      1|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|      1|  return atomic_load(val);
  628|      1|}
refcount.c:CRYPTO_atomic_load_u32:
  626|      6|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|      6|  return atomic_load(val);
  628|      6|}
refcount.c:CRYPTO_atomic_compare_exchange_weak_u32:
  631|      6|    CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
  632|      6|  return atomic_compare_exchange_weak(val, expected, desired);
  633|      6|}
stack.c:OPENSSL_memset:
 1055|      8|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      8|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 8]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      8|  return memset(dst, c, n);
 1061|      8|}
thread_pthread.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
x509_lu.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
x509_vpm.c:OPENSSL_memset:
 1055|      3|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      3|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 3]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      3|  return memset(dst, c, n);
 1061|      3|}
chacha.c:OPENSSL_memcpy:
 1039|      3|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      3|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 3]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      3|  return memcpy(dst, src, n);
 1045|      3|}
chacha.c:buffers_alias:
  269|      1|                                const void *b, size_t b_bytes) {
  270|       |  // Cast |a| and |b| to integers. In C, pointer comparisons between unrelated
  271|       |  // objects are undefined whereas pointer to integer conversions are merely
  272|       |  // implementation-defined. We assume the implementation defined it in a sane
  273|       |  // way.
  274|      1|  uintptr_t a_u = (uintptr_t)a;
  275|      1|  uintptr_t b_u = (uintptr_t)b;
  276|      1|  return a_u + a_bytes > b_u && b_u + b_bytes > a_u;
  ------------------
  |  Branch (276:10): [True: 1, False: 0]
  |  Branch (276:33): [True: 1, False: 0]
  ------------------
  277|      1|}
chacha.c:CRYPTO_load_u32_le:
 1070|      3|static inline uint32_t CRYPTO_load_u32_le(const void *in) {
 1071|      3|  uint32_t v;
 1072|      3|  OPENSSL_memcpy(&v, in, sizeof(v));
 1073|      3|  return v;
 1074|      3|}

_Z18lh_SSL_SESSION_newPFjPK14ssl_session_stEPFiS1_S1_E:
  186|      1|      lhash_##type##_hash_func hash, lhash_##type##_cmp_func comp) {           \
  187|      1|    return (LHASH_OF(type) *)OPENSSL_lh_new((lhash_hash_func)hash,             \
  188|      1|                                            (lhash_cmp_func)comp);             \
  189|      1|  }                                                                            \
_Z19lh_SSL_SESSION_freeP20lhash_st_SSL_SESSION:
  191|      1|  OPENSSL_INLINE void lh_##type##_free(LHASH_OF(type) *lh) {                   \
  192|      1|    OPENSSL_lh_free((_LHASH *)lh);                                             \
  193|      1|  }                                                                            \
_Z24lh_SSL_SESSION_doall_argP20lhash_st_SSL_SESSIONPFvP14ssl_session_stPvES3_:
  253|      1|      LHASH_OF(type) *lh, void (*func)(type *, void *), void *arg) {           \
  254|      1|    LHASH_DOALL_##type cb = {func, arg};                                       \
  255|      1|    OPENSSL_lh_doall_arg((_LHASH *)lh, lh_##type##_call_doall_arg, &cb);       \
  256|      1|  }                                                                            \

OPENSSL_lh_new:
  106|      1|_LHASH *OPENSSL_lh_new(lhash_hash_func hash, lhash_cmp_func comp) {
  107|      1|  _LHASH *ret = OPENSSL_malloc(sizeof(_LHASH));
  108|      1|  if (ret == NULL) {
  ------------------
  |  Branch (108:7): [True: 0, False: 1]
  ------------------
  109|      0|    return NULL;
  110|      0|  }
  111|      1|  OPENSSL_memset(ret, 0, sizeof(_LHASH));
  112|       |
  113|      1|  ret->num_buckets = kMinNumBuckets;
  114|      1|  ret->buckets = OPENSSL_malloc(sizeof(LHASH_ITEM *) * ret->num_buckets);
  115|      1|  if (ret->buckets == NULL) {
  ------------------
  |  Branch (115:7): [True: 0, False: 1]
  ------------------
  116|      0|    OPENSSL_free(ret);
  117|      0|    return NULL;
  118|      0|  }
  119|      1|  OPENSSL_memset(ret->buckets, 0, sizeof(LHASH_ITEM *) * ret->num_buckets);
  120|       |
  121|      1|  ret->comp = comp;
  122|      1|  ret->hash = hash;
  123|      1|  return ret;
  124|      1|}
OPENSSL_lh_free:
  126|      1|void OPENSSL_lh_free(_LHASH *lh) {
  127|      1|  if (lh == NULL) {
  ------------------
  |  Branch (127:7): [True: 0, False: 1]
  ------------------
  128|      0|    return;
  129|      0|  }
  130|       |
  131|     17|  for (size_t i = 0; i < lh->num_buckets; i++) {
  ------------------
  |  Branch (131:22): [True: 16, False: 1]
  ------------------
  132|     16|    LHASH_ITEM *next;
  133|     16|    for (LHASH_ITEM *n = lh->buckets[i]; n != NULL; n = next) {
  ------------------
  |  Branch (133:42): [True: 0, False: 16]
  ------------------
  134|      0|      next = n->next;
  135|      0|      OPENSSL_free(n);
  136|      0|    }
  137|     16|  }
  138|       |
  139|      1|  OPENSSL_free(lh->buckets);
  140|      1|  OPENSSL_free(lh);
  141|      1|}
OPENSSL_lh_doall_arg:
  327|      1|void OPENSSL_lh_doall_arg(_LHASH *lh, void (*func)(void *, void *), void *arg) {
  328|      1|  if (lh == NULL) {
  ------------------
  |  Branch (328:7): [True: 0, False: 1]
  ------------------
  329|      0|    return;
  330|      0|  }
  331|       |
  332|      1|  if (lh->callback_depth < UINT_MAX) {
  ------------------
  |  Branch (332:7): [True: 1, False: 0]
  ------------------
  333|       |    // |callback_depth| is a saturating counter.
  334|      1|    lh->callback_depth++;
  335|      1|  }
  336|       |
  337|     17|  for (size_t i = 0; i < lh->num_buckets; i++) {
  ------------------
  |  Branch (337:22): [True: 16, False: 1]
  ------------------
  338|     16|    LHASH_ITEM *next;
  339|     16|    for (LHASH_ITEM *cur = lh->buckets[i]; cur != NULL; cur = next) {
  ------------------
  |  Branch (339:44): [True: 0, False: 16]
  ------------------
  340|      0|      next = cur->next;
  341|      0|      func(cur->data, arg);
  342|      0|    }
  343|     16|  }
  344|       |
  345|      1|  if (lh->callback_depth < UINT_MAX) {
  ------------------
  |  Branch (345:7): [True: 1, False: 0]
  ------------------
  346|      1|    lh->callback_depth--;
  347|      1|  }
  348|       |
  349|       |  // The callback may have added or removed elements and the non-zero value of
  350|       |  // |callback_depth| will have suppressed any resizing. Thus any needed
  351|       |  // resizing is done here.
  352|      1|  lh_maybe_resize(lh);
  353|      1|}
lhash.c:lh_maybe_resize:
  239|      1|static void lh_maybe_resize(_LHASH *lh) {
  240|      1|  size_t avg_chain_length;
  241|       |
  242|      1|  if (lh->callback_depth > 0) {
  ------------------
  |  Branch (242:7): [True: 0, False: 1]
  ------------------
  243|       |    // Don't resize the hash if we are currently iterating over it.
  244|      0|    return;
  245|      0|  }
  246|       |
  247|      1|  assert(lh->num_buckets >= kMinNumBuckets);
  248|      1|  avg_chain_length = lh->num_items / lh->num_buckets;
  249|       |
  250|      1|  if (avg_chain_length > kMaxAverageChainLength) {
  ------------------
  |  Branch (250:7): [True: 0, False: 1]
  ------------------
  251|      0|    const size_t new_num_buckets = lh->num_buckets * 2;
  252|       |
  253|      0|    if (new_num_buckets > lh->num_buckets) {
  ------------------
  |  Branch (253:9): [True: 0, False: 0]
  ------------------
  254|      0|      lh_rebucket(lh, new_num_buckets);
  255|      0|    }
  256|      1|  } else if (avg_chain_length < kMinAverageChainLength &&
  ------------------
  |  Branch (256:14): [True: 1, False: 0]
  ------------------
  257|      1|             lh->num_buckets > kMinNumBuckets) {
  ------------------
  |  Branch (257:14): [True: 0, False: 1]
  ------------------
  258|      0|    size_t new_num_buckets = lh->num_buckets / 2;
  259|       |
  260|      0|    if (new_num_buckets < kMinNumBuckets) {
  ------------------
  |  Branch (260:9): [True: 0, False: 0]
  ------------------
  261|      0|      new_num_buckets = kMinNumBuckets;
  262|      0|    }
  263|       |
  264|      0|    lh_rebucket(lh, new_num_buckets);
  265|      0|  }
  266|      1|}

OPENSSL_malloc:
  228|  1.64k|void *OPENSSL_malloc(size_t size) {
  229|  1.64k|  if (should_fail_allocation()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 1.64k]
  ------------------
  230|      0|    goto err;
  231|      0|  }
  232|       |
  233|  1.64k|  if (OPENSSL_memory_alloc != NULL) {
  ------------------
  |  Branch (233:7): [True: 0, False: 1.64k]
  ------------------
  234|      0|    assert(OPENSSL_memory_free != NULL);
  235|      0|    assert(OPENSSL_memory_get_size != NULL);
  236|      0|    void *ptr = OPENSSL_memory_alloc(size);
  237|      0|    if (ptr == NULL && size != 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  |  Branch (237:24): [True: 0, False: 0]
  ------------------
  238|      0|      goto err;
  239|      0|    }
  240|      0|    return ptr;
  241|      0|  }
  242|       |
  243|  1.64k|  if (size + OPENSSL_MALLOC_PREFIX < size) {
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  |  Branch (243:7): [True: 0, False: 1.64k]
  ------------------
  244|       |    // |OPENSSL_malloc| is a central function in BoringSSL thus a reference to
  245|       |    // |kBoringSSLBinaryTag| is created here so that the tag isn't discarded by
  246|       |    // the linker. The following is sufficient to stop GCC, Clang, and MSVC
  247|       |    // optimising away the reference at the time of writing. Since this
  248|       |    // probably results in an actual memory reference, it is put in this very
  249|       |    // rare code path.
  250|      0|    uint8_t unused = *(volatile uint8_t *)kBoringSSLBinaryTag;
  251|      0|    (void) unused;
  252|      0|    goto err;
  253|      0|  }
  254|       |
  255|  1.64k|  void *ptr = malloc(size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  256|  1.64k|  if (ptr == NULL) {
  ------------------
  |  Branch (256:7): [True: 0, False: 1.64k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|  1.64k|  *(size_t *)ptr = size;
  261|       |
  262|  1.64k|  __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  263|  1.64k|  return ((uint8_t *)ptr) + OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  264|       |
  265|      0| err:
  266|       |  // This only works because ERR does not call OPENSSL_malloc.
  267|      0|  OPENSSL_PUT_ERROR(CRYPTO, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|  return NULL;
  269|  1.64k|}
OPENSSL_free:
  271|  4.01k|void OPENSSL_free(void *orig_ptr) {
  272|  4.01k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (272:7): [True: 2.37k, False: 1.64k]
  ------------------
  273|  2.37k|    return;
  274|  2.37k|  }
  275|       |
  276|  1.64k|  if (OPENSSL_memory_free != NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 1.64k]
  ------------------
  277|      0|    OPENSSL_memory_free(orig_ptr);
  278|      0|    return;
  279|      0|  }
  280|       |
  281|  1.64k|  void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  282|  1.64k|  __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  283|       |
  284|  1.64k|  size_t size = *(size_t *)ptr;
  285|  1.64k|  OPENSSL_cleanse(ptr, size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  1.64k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  286|       |
  287|       |// ASan knows to intercept malloc and free, but not sdallocx.
  288|       |#if defined(OPENSSL_ASAN)
  289|       |  (void)sdallocx;
  290|       |  free(ptr);
  291|       |#else
  292|  1.64k|  if (sdallocx) {
  ------------------
  |  Branch (292:7): [True: 0, False: 1.64k]
  ------------------
  293|      0|    sdallocx(ptr, size + OPENSSL_MALLOC_PREFIX, 0 /* flags */);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  294|  1.64k|  } else {
  295|  1.64k|    free(ptr);
  296|  1.64k|  }
  297|  1.64k|#endif
  298|  1.64k|}
OPENSSL_realloc:
  300|    213|void *OPENSSL_realloc(void *orig_ptr, size_t new_size) {
  301|    213|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (301:7): [True: 0, False: 213]
  ------------------
  302|      0|    return OPENSSL_malloc(new_size);
  303|      0|  }
  304|       |
  305|    213|  size_t old_size;
  306|    213|  if (OPENSSL_memory_get_size != NULL) {
  ------------------
  |  Branch (306:7): [True: 0, False: 213]
  ------------------
  307|      0|    old_size = OPENSSL_memory_get_size(orig_ptr);
  308|    213|  } else {
  309|    213|    void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|    213|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  310|    213|    __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|    213|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  311|    213|    old_size = *(size_t *)ptr;
  312|    213|    __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|    213|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  313|    213|  }
  314|       |
  315|    213|  void *ret = OPENSSL_malloc(new_size);
  316|    213|  if (ret == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 213]
  ------------------
  317|      0|    return NULL;
  318|      0|  }
  319|       |
  320|    213|  size_t to_copy = new_size;
  321|    213|  if (old_size < to_copy) {
  ------------------
  |  Branch (321:7): [True: 213, False: 0]
  ------------------
  322|    213|    to_copy = old_size;
  323|    213|  }
  324|       |
  325|    213|  memcpy(ret, orig_ptr, to_copy);
  326|    213|  OPENSSL_free(orig_ptr);
  327|       |
  328|    213|  return ret;
  329|    213|}
OPENSSL_cleanse:
  331|  1.64k|void OPENSSL_cleanse(void *ptr, size_t len) {
  332|       |#if defined(OPENSSL_WINDOWS)
  333|       |  SecureZeroMemory(ptr, len);
  334|       |#else
  335|  1.64k|  OPENSSL_memset(ptr, 0, len);
  336|       |
  337|  1.64k|#if !defined(OPENSSL_NO_ASM)
  338|       |  /* As best as we can tell, this is sufficient to break any optimisations that
  339|       |     might try to eliminate "superfluous" memsets. If there's an easy way to
  340|       |     detect memset_s, it would be better to use that. */
  341|  1.64k|  __asm__ __volatile__("" : : "r"(ptr) : "memory");
  342|  1.64k|#endif
  343|  1.64k|#endif  // !OPENSSL_NO_ASM
  344|  1.64k|}
OPENSSL_isalpha:
  413|      4|int OPENSSL_isalpha(int c) {
  414|      4|  return (c >= 'a' && c <= 'z') || (c >= 'A' && c <= 'Z');
  ------------------
  |  Branch (414:11): [True: 0, False: 4]
  |  Branch (414:23): [True: 0, False: 0]
  |  Branch (414:37): [True: 3, False: 1]
  |  Branch (414:49): [True: 3, False: 0]
  ------------------
  415|      4|}
OPENSSL_isdigit:
  417|      1|int OPENSSL_isdigit(int c) { return c >= '0' && c <= '9'; }
  ------------------
  |  Branch (417:37): [True: 0, False: 1]
  |  Branch (417:49): [True: 0, False: 0]
  ------------------
OPENSSL_isalnum:
  439|      4|int OPENSSL_isalnum(int c) { return OPENSSL_isalpha(c) || OPENSSL_isdigit(c); }
  ------------------
  |  Branch (439:37): [True: 3, False: 1]
  |  Branch (439:59): [True: 0, False: 1]
  ------------------
mem.c:should_fail_allocation:
  225|  1.64k|static int should_fail_allocation(void) { return 0; }
mem.c:__asan_poison_memory_region:
   90|  1.85k|static void __asan_poison_memory_region(const void *addr, size_t size) {}
mem.c:__asan_unpoison_memory_region:
   91|  1.85k|static void __asan_unpoison_memory_region(const void *addr, size_t size) {}

CRYPTO_sysrand:
   37|      1|void CRYPTO_sysrand(uint8_t *out, size_t requested) {
   38|      1|  static const uint8_t kZeroKey[32];
   39|       |
   40|      1|  CRYPTO_STATIC_MUTEX_lock_write(&g_num_calls_lock);
   41|      1|  uint64_t num_calls = g_num_calls++;
   42|      1|  CRYPTO_STATIC_MUTEX_unlock_write(&g_num_calls_lock);
   43|       |
   44|      1|  uint8_t nonce[12];
   45|      1|  OPENSSL_memset(nonce, 0, sizeof(nonce));
   46|      1|  OPENSSL_memcpy(nonce, &num_calls, sizeof(num_calls));
   47|       |
   48|      1|  OPENSSL_memset(out, 0, requested);
   49|      1|  CRYPTO_chacha_20(out, out, requested, kZeroKey, nonce, 0);
   50|      1|}
CRYPTO_sysrand_for_seed:
   52|      1|void CRYPTO_sysrand_for_seed(uint8_t *out, size_t requested) {
   53|      1|  CRYPTO_sysrand(out, requested);
   54|      1|}

rand_fork_unsafe_buffering_enabled:
   38|      1|int rand_fork_unsafe_buffering_enabled(void) {
   39|      1|  return CRYPTO_atomic_load_u32(&g_buffering_enabled) != 0;
   40|      1|}

CRYPTO_refcount_inc:
   31|      2|void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
   32|      2|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   33|      2|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   34|       |
   35|      2|  while (expected != CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|      2|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (35:10): [True: 2, False: 0]
  ------------------
   36|      2|    uint32_t new_value = expected + 1;
   37|      2|    if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected, new_value)) {
  ------------------
  |  Branch (37:9): [True: 2, False: 0]
  ------------------
   38|      2|      break;
   39|      2|    }
   40|      2|  }
   41|      2|}
CRYPTO_refcount_dec_and_test_zero:
   43|      4|int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
   44|      4|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   45|      4|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   46|       |
   47|      4|  for (;;) {
   48|      4|    if (expected == 0) {
  ------------------
  |  Branch (48:9): [True: 0, False: 4]
  ------------------
   49|      0|      abort();
   50|      4|    } else if (expected == CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|      4|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (50:16): [True: 0, False: 4]
  ------------------
   51|      0|      return 0;
   52|      4|    } else {
   53|      4|      const uint32_t new_value = expected - 1;
   54|      4|      if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected,
  ------------------
  |  Branch (54:11): [True: 4, False: 0]
  ------------------
   55|      4|                                                  new_value)) {
   56|      4|        return new_value == 0;
   57|      4|      }
   58|      4|    }
   59|      4|  }
   60|      4|}

sk_new:
   72|      4|_STACK *sk_new(OPENSSL_sk_cmp_func comp) {
   73|      4|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
   74|      4|  if (ret == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 4]
  ------------------
   75|      0|    return NULL;
   76|      0|  }
   77|      4|  OPENSSL_memset(ret, 0, sizeof(_STACK));
   78|       |
   79|      4|  ret->data = OPENSSL_malloc(sizeof(void *) * kMinSize);
   80|      4|  if (ret->data == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 4]
  ------------------
   81|      0|    goto err;
   82|      0|  }
   83|       |
   84|      4|  OPENSSL_memset(ret->data, 0, sizeof(void *) * kMinSize);
   85|       |
   86|      4|  ret->comp = comp;
   87|      4|  ret->num_alloc = kMinSize;
   88|       |
   89|      4|  return ret;
   90|       |
   91|      0|err:
   92|      0|  OPENSSL_free(ret);
   93|      0|  return NULL;
   94|      4|}
sk_new_null:
   96|      3|_STACK *sk_new_null(void) { return sk_new(NULL); }
sk_num:
   98|      3|size_t sk_num(const _STACK *sk) {
   99|      3|  if (sk == NULL) {
  ------------------
  |  Branch (99:7): [True: 0, False: 3]
  ------------------
  100|      0|    return 0;
  101|      0|  }
  102|      3|  return sk->num;
  103|      3|}
sk_free:
  128|      4|void sk_free(_STACK *sk) {
  129|      4|  if (sk == NULL) {
  ------------------
  |  Branch (129:7): [True: 0, False: 4]
  ------------------
  130|      0|    return;
  131|      0|  }
  132|      4|  OPENSSL_free(sk->data);
  133|      4|  OPENSSL_free(sk);
  134|      4|}
sk_pop_free_ex:
  137|      9|                    OPENSSL_sk_free_func free_func) {
  138|      9|  if (sk == NULL) {
  ------------------
  |  Branch (138:7): [True: 7, False: 2]
  ------------------
  139|      7|    return;
  140|      7|  }
  141|       |
  142|      2|  for (size_t i = 0; i < sk->num; i++) {
  ------------------
  |  Branch (142:22): [True: 0, False: 2]
  ------------------
  143|      0|    if (sk->data[i] != NULL) {
  ------------------
  |  Branch (143:9): [True: 0, False: 0]
  ------------------
  144|      0|      call_free_func(free_func, sk->data[i]);
  145|      0|    }
  146|      0|  }
  147|      2|  sk_free(sk);
  148|      2|}
sk_insert:
  161|     19|size_t sk_insert(_STACK *sk, void *p, size_t where) {
  162|     19|  if (sk == NULL) {
  ------------------
  |  Branch (162:7): [True: 0, False: 19]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|     19|  if (sk->num >= INT_MAX) {
  ------------------
  |  Branch (166:7): [True: 0, False: 19]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|     19|  if (sk->num_alloc <= sk->num + 1) {
  ------------------
  |  Branch (171:7): [True: 3, False: 16]
  ------------------
  172|       |    // Attempt to double the size of the array.
  173|      3|    size_t new_alloc = sk->num_alloc << 1;
  174|      3|    size_t alloc_size = new_alloc * sizeof(void *);
  175|      3|    void **data;
  176|       |
  177|       |    // If the doubling overflowed, try to increment.
  178|      3|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (178:9): [True: 0, False: 3]
  |  Branch (178:38): [True: 0, False: 3]
  ------------------
  179|      0|      new_alloc = sk->num_alloc + 1;
  180|      0|      alloc_size = new_alloc * sizeof(void *);
  181|      0|    }
  182|       |
  183|       |    // If the increment also overflowed, fail.
  184|      3|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 3]
  |  Branch (184:38): [True: 0, False: 3]
  ------------------
  185|      0|      return 0;
  186|      0|    }
  187|       |
  188|      3|    data = OPENSSL_realloc(sk->data, alloc_size);
  189|      3|    if (data == NULL) {
  ------------------
  |  Branch (189:9): [True: 0, False: 3]
  ------------------
  190|      0|      return 0;
  191|      0|    }
  192|       |
  193|      3|    sk->data = data;
  194|      3|    sk->num_alloc = new_alloc;
  195|      3|  }
  196|       |
  197|     19|  if (where >= sk->num) {
  ------------------
  |  Branch (197:7): [True: 19, False: 0]
  ------------------
  198|     19|    sk->data[sk->num] = p;
  199|     19|  } else {
  200|      0|    OPENSSL_memmove(&sk->data[where + 1], &sk->data[where],
  201|      0|                    sizeof(void *) * (sk->num - where));
  202|      0|    sk->data[where] = p;
  203|      0|  }
  204|       |
  205|     19|  sk->num++;
  206|     19|  sk->sorted = 0;
  207|       |
  208|     19|  return sk->num;
  209|     19|}
sk_push:
  340|     19|size_t sk_push(_STACK *sk, void *p) { return (sk_insert(sk, p, sk->num)); }

CRYPTO_MUTEX_init:
   31|      2|void CRYPTO_MUTEX_init(CRYPTO_MUTEX *lock) {
   32|      2|  if (pthread_rwlock_init((pthread_rwlock_t *) lock, NULL) != 0) {
  ------------------
  |  Branch (32:7): [True: 0, False: 2]
  ------------------
   33|      0|    abort();
   34|      0|  }
   35|      2|}
CRYPTO_MUTEX_lock_write:
   43|      1|void CRYPTO_MUTEX_lock_write(CRYPTO_MUTEX *lock) {
   44|      1|  if (pthread_rwlock_wrlock((pthread_rwlock_t *) lock) != 0) {
  ------------------
  |  Branch (44:7): [True: 0, False: 1]
  ------------------
   45|      0|    abort();
   46|      0|  }
   47|      1|}
CRYPTO_MUTEX_unlock_write:
   55|      1|void CRYPTO_MUTEX_unlock_write(CRYPTO_MUTEX *lock) {
   56|      1|  if (pthread_rwlock_unlock((pthread_rwlock_t *) lock) != 0) {
  ------------------
  |  Branch (56:7): [True: 0, False: 1]
  ------------------
   57|      0|    abort();
   58|      0|  }
   59|      1|}
CRYPTO_MUTEX_cleanup:
   61|      2|void CRYPTO_MUTEX_cleanup(CRYPTO_MUTEX *lock) {
   62|      2|  pthread_rwlock_destroy((pthread_rwlock_t *) lock);
   63|      2|}
CRYPTO_STATIC_MUTEX_lock_write:
   71|      1|void CRYPTO_STATIC_MUTEX_lock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   72|      1|  if (pthread_rwlock_wrlock(&lock->lock) != 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 1]
  ------------------
   73|      0|    abort();
   74|      0|  }
   75|      1|}
CRYPTO_STATIC_MUTEX_unlock_write:
   83|      1|void CRYPTO_STATIC_MUTEX_unlock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   84|      1|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (84:7): [True: 0, False: 1]
  ------------------
   85|      0|    abort();
   86|      0|  }
   87|      1|}
CRYPTO_once:
   89|    365|void CRYPTO_once(CRYPTO_once_t *once, void (*init)(void)) {
   90|    365|  if (pthread_once(once, init) != 0) {
  ------------------
  |  Branch (90:7): [True: 0, False: 365]
  ------------------
   91|      0|    abort();
   92|      0|  }
   93|    365|}
CRYPTO_get_thread_local:
  132|    362|void *CRYPTO_get_thread_local(thread_local_data_t index) {
  133|    362|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  134|    362|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (134:7): [True: 0, False: 362]
  ------------------
  135|      0|    return NULL;
  136|      0|  }
  137|       |
  138|    362|  void **pointers = pthread_getspecific(g_thread_local_key);
  139|    362|  if (pointers == NULL) {
  ------------------
  |  Branch (139:7): [True: 1, False: 361]
  ------------------
  140|      1|    return NULL;
  141|      1|  }
  142|    361|  return pointers[index];
  143|    362|}
CRYPTO_set_thread_local:
  146|      2|                            thread_local_destructor_t destructor) {
  147|      2|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  148|      2|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (148:7): [True: 0, False: 2]
  ------------------
  149|      0|    destructor(value);
  150|      0|    return 0;
  151|      0|  }
  152|       |
  153|      2|  void **pointers = pthread_getspecific(g_thread_local_key);
  154|      2|  if (pointers == NULL) {
  ------------------
  |  Branch (154:7): [True: 1, False: 1]
  ------------------
  155|      1|    pointers = malloc(sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  156|      1|    if (pointers == NULL) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1]
  ------------------
  157|      0|      destructor(value);
  158|      0|      return 0;
  159|      0|    }
  160|      1|    OPENSSL_memset(pointers, 0, sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  161|      1|    if (pthread_setspecific(g_thread_local_key, pointers) != 0) {
  ------------------
  |  Branch (161:9): [True: 0, False: 1]
  ------------------
  162|      0|      free(pointers);
  163|      0|      destructor(value);
  164|      0|      return 0;
  165|      0|    }
  166|      1|  }
  167|       |
  168|      2|  if (pthread_mutex_lock(&g_destructors_lock) != 0) {
  ------------------
  |  Branch (168:7): [True: 0, False: 2]
  ------------------
  169|      0|    destructor(value);
  170|      0|    return 0;
  171|      0|  }
  172|      2|  g_destructors[index] = destructor;
  173|      2|  pthread_mutex_unlock(&g_destructors_lock);
  174|       |
  175|      2|  pointers[index] = value;
  176|      2|  return 1;
  177|      2|}
thread_pthread.c:thread_local_init:
  127|      1|static void thread_local_init(void) {
  128|      1|  g_thread_local_key_created =
  129|      1|      pthread_key_create(&g_thread_local_key, thread_local_destructor) == 0;
  130|      1|}

X509_STORE_new:
  164|      1|X509_STORE *X509_STORE_new(void) {
  165|      1|  X509_STORE *ret;
  166|       |
  167|      1|  if ((ret = (X509_STORE *)OPENSSL_malloc(sizeof(X509_STORE))) == NULL) {
  ------------------
  |  Branch (167:7): [True: 0, False: 1]
  ------------------
  168|      0|    return NULL;
  169|      0|  }
  170|      1|  OPENSSL_memset(ret, 0, sizeof(*ret));
  171|      1|  CRYPTO_MUTEX_init(&ret->objs_lock);
  172|      1|  ret->objs = sk_X509_OBJECT_new(x509_object_cmp_sk);
  173|      1|  if (ret->objs == NULL) {
  ------------------
  |  Branch (173:7): [True: 0, False: 1]
  ------------------
  174|      0|    goto err;
  175|      0|  }
  176|      1|  ret->cache = 1;
  177|      1|  ret->get_cert_methods = sk_X509_LOOKUP_new_null();
  178|      1|  if (ret->get_cert_methods == NULL) {
  ------------------
  |  Branch (178:7): [True: 0, False: 1]
  ------------------
  179|      0|    goto err;
  180|      0|  }
  181|      1|  ret->param = X509_VERIFY_PARAM_new();
  182|      1|  if (ret->param == NULL) {
  ------------------
  |  Branch (182:7): [True: 0, False: 1]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|      1|  ret->references = 1;
  187|      1|  return ret;
  188|      0|err:
  189|      0|  if (ret) {
  ------------------
  |  Branch (189:7): [True: 0, False: 0]
  ------------------
  190|      0|    CRYPTO_MUTEX_cleanup(&ret->objs_lock);
  191|      0|    if (ret->param) {
  ------------------
  |  Branch (191:9): [True: 0, False: 0]
  ------------------
  192|      0|      X509_VERIFY_PARAM_free(ret->param);
  193|      0|    }
  194|      0|    if (ret->get_cert_methods) {
  ------------------
  |  Branch (194:9): [True: 0, False: 0]
  ------------------
  195|      0|      sk_X509_LOOKUP_free(ret->get_cert_methods);
  196|      0|    }
  197|      0|    if (ret->objs) {
  ------------------
  |  Branch (197:9): [True: 0, False: 0]
  ------------------
  198|      0|      sk_X509_OBJECT_free(ret->objs);
  199|      0|    }
  200|      0|    OPENSSL_free(ret);
  201|      0|  }
  202|      0|  return NULL;
  203|      1|}
X509_STORE_free:
  225|      3|void X509_STORE_free(X509_STORE *vfy) {
  226|      3|  size_t j;
  227|      3|  STACK_OF(X509_LOOKUP) *sk;
  ------------------
  |  |   81|      3|#define STACK_OF(type) struct stack_st_##type
  ------------------
  228|      3|  X509_LOOKUP *lu;
  229|       |
  230|      3|  if (vfy == NULL) {
  ------------------
  |  Branch (230:7): [True: 2, False: 1]
  ------------------
  231|      2|    return;
  232|      2|  }
  233|       |
  234|      1|  if (!CRYPTO_refcount_dec_and_test_zero(&vfy->references)) {
  ------------------
  |  Branch (234:7): [True: 0, False: 1]
  ------------------
  235|      0|    return;
  236|      0|  }
  237|       |
  238|      1|  CRYPTO_MUTEX_cleanup(&vfy->objs_lock);
  239|       |
  240|      1|  sk = vfy->get_cert_methods;
  241|      1|  for (j = 0; j < sk_X509_LOOKUP_num(sk); j++) {
  ------------------
  |  Branch (241:15): [True: 0, False: 1]
  ------------------
  242|      0|    lu = sk_X509_LOOKUP_value(sk, j);
  243|      0|    X509_LOOKUP_shutdown(lu);
  244|      0|    X509_LOOKUP_free(lu);
  245|      0|  }
  246|      1|  sk_X509_LOOKUP_free(sk);
  247|      1|  sk_X509_OBJECT_pop_free(vfy->objs, cleanup);
  248|       |
  249|      1|  if (vfy->param) {
  ------------------
  |  Branch (249:7): [True: 1, False: 0]
  ------------------
  250|      1|    X509_VERIFY_PARAM_free(vfy->param);
  251|      1|  }
  252|      1|  OPENSSL_free(vfy);
  253|      1|}

X509_VERIFY_PARAM_new:
  158|      3|X509_VERIFY_PARAM *X509_VERIFY_PARAM_new(void) {
  159|      3|  X509_VERIFY_PARAM *param;
  160|      3|  param = OPENSSL_malloc(sizeof(X509_VERIFY_PARAM));
  161|      3|  if (!param) {
  ------------------
  |  Branch (161:7): [True: 0, False: 3]
  ------------------
  162|      0|    return NULL;
  163|      0|  }
  164|      3|  OPENSSL_memset(param, 0, sizeof(X509_VERIFY_PARAM));
  165|      3|  x509_verify_param_zero(param);
  166|      3|  return param;
  167|      3|}
X509_VERIFY_PARAM_free:
  169|      3|void X509_VERIFY_PARAM_free(X509_VERIFY_PARAM *param) {
  170|      3|  if (param == NULL) {
  ------------------
  |  Branch (170:7): [True: 0, False: 3]
  ------------------
  171|      0|    return;
  172|      0|  }
  173|      3|  x509_verify_param_zero(param);
  174|      3|  OPENSSL_free(param);
  175|      3|}
X509_VERIFY_PARAM_inherit:
  221|      1|                              const X509_VERIFY_PARAM *src) {
  222|      1|  unsigned long inh_flags;
  223|      1|  int to_default, to_overwrite;
  224|      1|  if (!src) {
  ------------------
  |  Branch (224:7): [True: 0, False: 1]
  ------------------
  225|      0|    return 1;
  226|      0|  }
  227|      1|  inh_flags = dest->inh_flags | src->inh_flags;
  228|       |
  229|      1|  if (inh_flags & X509_VP_FLAG_ONCE) {
  ------------------
  |  | 2738|      1|#define X509_VP_FLAG_ONCE 0x10
  ------------------
  |  Branch (229:7): [True: 0, False: 1]
  ------------------
  230|      0|    dest->inh_flags = 0;
  231|      0|  }
  232|       |
  233|      1|  if (inh_flags & X509_VP_FLAG_LOCKED) {
  ------------------
  |  | 2737|      1|#define X509_VP_FLAG_LOCKED 0x8
  ------------------
  |  Branch (233:7): [True: 0, False: 1]
  ------------------
  234|      0|    return 1;
  235|      0|  }
  236|       |
  237|      1|  if (inh_flags & X509_VP_FLAG_DEFAULT) {
  ------------------
  |  | 2734|      1|#define X509_VP_FLAG_DEFAULT 0x1
  ------------------
  |  Branch (237:7): [True: 0, False: 1]
  ------------------
  238|      0|    to_default = 1;
  239|      1|  } else {
  240|      1|    to_default = 0;
  241|      1|  }
  242|       |
  243|      1|  if (inh_flags & X509_VP_FLAG_OVERWRITE) {
  ------------------
  |  | 2735|      1|#define X509_VP_FLAG_OVERWRITE 0x2
  ------------------
  |  Branch (243:7): [True: 0, False: 1]
  ------------------
  244|      0|    to_overwrite = 1;
  245|      1|  } else {
  246|      1|    to_overwrite = 0;
  247|      1|  }
  248|       |
  249|      1|  x509_verify_param_copy(purpose, 0);
  ------------------
  |  |  217|      1|  if (test_x509_verify_param_copy(field, def)) \
  |  |  ------------------
  |  |  |  |  211|      1|  (to_overwrite ||                              \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  |  |  ------------------
  |  |  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  218|      1|  dest->field = src->field
  ------------------
  250|      1|  x509_verify_param_copy(trust, 0);
  ------------------
  |  |  217|      1|  if (test_x509_verify_param_copy(field, def)) \
  |  |  ------------------
  |  |  |  |  211|      1|  (to_overwrite ||                              \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  |  |  ------------------
  |  |  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  218|      1|  dest->field = src->field
  ------------------
  251|      1|  x509_verify_param_copy(depth, -1);
  ------------------
  |  |  217|      1|  if (test_x509_verify_param_copy(field, def)) \
  |  |  ------------------
  |  |  |  |  211|      1|  (to_overwrite ||                              \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  |  |  ------------------
  |  |  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  218|      1|  dest->field = src->field
  ------------------
  252|       |
  253|       |  // If overwrite or check time not set, copy across
  254|       |
  255|      1|  if (to_overwrite || !(dest->flags & X509_V_FLAG_USE_CHECK_TIME)) {
  ------------------
  |  | 2692|      1|#define X509_V_FLAG_USE_CHECK_TIME 0x2
  ------------------
  |  Branch (255:7): [True: 0, False: 1]
  |  Branch (255:23): [True: 1, False: 0]
  ------------------
  256|      1|    dest->check_time = src->check_time;
  257|      1|    dest->flags &= ~X509_V_FLAG_USE_CHECK_TIME;
  ------------------
  |  | 2692|      1|#define X509_V_FLAG_USE_CHECK_TIME 0x2
  ------------------
  258|       |    // Don't need to copy flag: that is done below
  259|      1|  }
  260|       |
  261|      1|  if (inh_flags & X509_VP_FLAG_RESET_FLAGS) {
  ------------------
  |  | 2736|      1|#define X509_VP_FLAG_RESET_FLAGS 0x4
  ------------------
  |  Branch (261:7): [True: 0, False: 1]
  ------------------
  262|      0|    dest->flags = 0;
  263|      0|  }
  264|       |
  265|      1|  dest->flags |= src->flags;
  266|       |
  267|      1|  if (test_x509_verify_param_copy(policies, NULL)) {
  ------------------
  |  |  211|      1|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  ------------------
  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  268|      0|    if (!X509_VERIFY_PARAM_set1_policies(dest, src->policies)) {
  ------------------
  |  Branch (268:9): [True: 0, False: 0]
  ------------------
  269|      0|      return 0;
  270|      0|    }
  271|      0|  }
  272|       |
  273|       |  // Copy the host flags if and only if we're copying the host list
  274|      1|  if (test_x509_verify_param_copy(hosts, NULL)) {
  ------------------
  |  |  211|      1|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  ------------------
  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  275|      0|    if (dest->hosts) {
  ------------------
  |  Branch (275:9): [True: 0, False: 0]
  ------------------
  276|      0|      string_stack_free(dest->hosts);
  ------------------
  |  |   77|      0|#define string_stack_free(sk) sk_OPENSSL_STRING_pop_free(sk, str_free)
  ------------------
  277|      0|      dest->hosts = NULL;
  278|      0|    }
  279|      0|    if (src->hosts) {
  ------------------
  |  Branch (279:9): [True: 0, False: 0]
  ------------------
  280|      0|      dest->hosts =
  281|      0|          sk_OPENSSL_STRING_deep_copy(src->hosts, OPENSSL_strdup, str_free);
  282|      0|      if (dest->hosts == NULL) {
  ------------------
  |  Branch (282:11): [True: 0, False: 0]
  ------------------
  283|      0|        return 0;
  284|      0|      }
  285|      0|      dest->hostflags = src->hostflags;
  286|      0|    }
  287|      0|  }
  288|       |
  289|      1|  if (test_x509_verify_param_copy(email, NULL)) {
  ------------------
  |  |  211|      1|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  ------------------
  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  290|      0|    if (!X509_VERIFY_PARAM_set1_email(dest, src->email, src->emaillen)) {
  ------------------
  |  Branch (290:9): [True: 0, False: 0]
  ------------------
  291|      0|      return 0;
  292|      0|    }
  293|      0|  }
  294|       |
  295|      1|  if (test_x509_verify_param_copy(ip, NULL)) {
  ------------------
  |  |  211|      1|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 1]
  |  |  ------------------
  |  |  212|      1|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 1]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  296|      0|    if (!X509_VERIFY_PARAM_set1_ip(dest, src->ip, src->iplen)) {
  ------------------
  |  Branch (296:9): [True: 0, False: 0]
  ------------------
  297|      0|      return 0;
  298|      0|    }
  299|      0|  }
  300|       |
  301|      1|  dest->poison = src->poison;
  302|       |
  303|      1|  return 1;
  304|      1|}
x509_vpm.c:x509_verify_param_zero:
  122|      6|static void x509_verify_param_zero(X509_VERIFY_PARAM *param) {
  123|      6|  if (!param) {
  ------------------
  |  Branch (123:7): [True: 0, False: 6]
  ------------------
  124|      0|    return;
  125|      0|  }
  126|      6|  param->name = NULL;
  127|      6|  param->purpose = 0;
  128|      6|  param->trust = 0;
  129|       |  // param->inh_flags = X509_VP_FLAG_DEFAULT;
  130|      6|  param->inh_flags = 0;
  131|      6|  param->flags = 0;
  132|      6|  param->depth = -1;
  133|      6|  if (param->policies) {
  ------------------
  |  Branch (133:7): [True: 0, False: 6]
  ------------------
  134|      0|    sk_ASN1_OBJECT_pop_free(param->policies, ASN1_OBJECT_free);
  135|      0|    param->policies = NULL;
  136|      0|  }
  137|      6|  if (param->hosts) {
  ------------------
  |  Branch (137:7): [True: 0, False: 6]
  ------------------
  138|      0|    string_stack_free(param->hosts);
  ------------------
  |  |   77|      0|#define string_stack_free(sk) sk_OPENSSL_STRING_pop_free(sk, str_free)
  ------------------
  139|      0|    param->hosts = NULL;
  140|      0|  }
  141|      6|  if (param->peername) {
  ------------------
  |  Branch (141:7): [True: 0, False: 6]
  ------------------
  142|      0|    OPENSSL_free(param->peername);
  143|      0|    param->peername = NULL;
  144|      0|  }
  145|      6|  if (param->email) {
  ------------------
  |  Branch (145:7): [True: 0, False: 6]
  ------------------
  146|      0|    OPENSSL_free(param->email);
  147|      0|    param->email = NULL;
  148|      0|    param->emaillen = 0;
  149|      0|  }
  150|      6|  if (param->ip) {
  ------------------
  |  Branch (150:7): [True: 0, False: 6]
  ------------------
  151|      0|    OPENSSL_free(param->ip);
  152|      0|    param->ip = NULL;
  153|      0|    param->iplen = 0;
  154|      0|  }
  155|      6|  param->poison = 0;
  156|      6|}

X509_free:
  126|      8|void X509_free(X509 *x509) {
  127|      8|  if (x509 == NULL || !CRYPTO_refcount_dec_and_test_zero(&x509->references)) {
  ------------------
  |  Branch (127:7): [True: 8, False: 0]
  |  Branch (127:23): [True: 0, False: 0]
  ------------------
  128|      8|    return;
  129|      8|  }
  130|       |
  131|      0|  CRYPTO_free_ex_data(&g_ex_data_class, x509, &x509->ex_data);
  132|       |
  133|      0|  X509_CINF_free(x509->cert_info);
  134|      0|  X509_ALGOR_free(x509->sig_alg);
  135|      0|  ASN1_BIT_STRING_free(x509->signature);
  136|      0|  ASN1_OCTET_STRING_free(x509->skid);
  137|      0|  AUTHORITY_KEYID_free(x509->akid);
  138|      0|  CRL_DIST_POINTS_free(x509->crldp);
  139|      0|  GENERAL_NAMES_free(x509->altname);
  140|      0|  NAME_CONSTRAINTS_free(x509->nc);
  141|      0|  X509_CERT_AUX_free(x509->aux);
  142|      0|  CRYPTO_MUTEX_cleanup(&x509->lock);
  143|       |
  144|      0|  OPENSSL_free(x509);
  145|      0|}

LLVMFuzzerTestOneInput:
   22|    796|extern "C" int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) {
   23|    796|  static bssl::UniquePtr<SSL_CTX> ctx(SSL_CTX_new(TLS_method()));
   24|    796|  static bssl::UniquePtr<SSL> ssl(SSL_new(ctx.get()));
   25|       |
   26|    796|  CBS reader(bssl::MakeConstSpan(buf, len));
   27|    796|  CBS encoded_client_hello_inner_cbs;
   28|       |
   29|    796|  if (!CBS_get_u24_length_prefixed(&reader, &encoded_client_hello_inner_cbs)) {
  ------------------
  |  Branch (29:7): [True: 36, False: 760]
  ------------------
   30|     36|    return 0;
   31|     36|  }
   32|       |
   33|    760|  bssl::Array<uint8_t> encoded_client_hello_inner;
   34|    760|  if (!encoded_client_hello_inner.CopyFrom(encoded_client_hello_inner_cbs)) {
  ------------------
  |  Branch (34:7): [True: 0, False: 760]
  ------------------
   35|      0|    return 0;
   36|      0|  }
   37|       |
   38|       |  // Use the remaining bytes in |reader| as the ClientHelloOuter.
   39|    760|  SSL_CLIENT_HELLO client_hello_outer;
   40|    760|  if (!bssl::ssl_client_hello_init(ssl.get(), &client_hello_outer, reader)) {
  ------------------
  |  Branch (40:7): [True: 345, False: 415]
  ------------------
   41|    345|    return 0;
   42|    345|  }
   43|       |
   44|       |  // Recover the ClientHelloInner from the EncodedClientHelloInner and
   45|       |  // ClientHelloOuter.
   46|    415|  uint8_t alert_unused;
   47|    415|  bssl::Array<uint8_t> client_hello_inner;
   48|    415|  bssl::ssl_decode_client_hello_inner(
   49|    415|      ssl.get(), &alert_unused, &client_hello_inner, encoded_client_hello_inner,
   50|    415|      &client_hello_outer);
   51|    415|  return 0;
   52|    760|}

_ZN4bssl8internal7DeleterclI10ssl_ctx_stEEvPT_:
  560|      3|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      3|    DeleterImpl<T>::Free(ptr);
  570|      3|  }
_ZN4bssl8internal11DeleterImplI10ssl_ctx_stvE4FreeEPS2_:
  635|      3|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl8internal7DeleterclI6ssl_stEEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal11DeleterImplI6ssl_stvE4FreeEPS2_:
  635|      1|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl8internal11DeleterImplI10buf_mem_stvE4FreeEPS2_:
  635|      1|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl5UpRefEP11evp_pkey_st:
  646|      3|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|      3|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 0, False: 3]
  ------------------
  648|      0|      up_ref_func(v);                                        \
  649|      0|    }                                                        \
  650|      3|    return UniquePtr<type>(v);                               \
  651|      3|  }                                                          \
_ZN4bssl5UpRefERKNSt3__110unique_ptrI11evp_pkey_stNS_8internal7DeleterEEE:
  653|      3|  inline UniquePtr<type> UpRef(const UniquePtr<type> &ptr) { \
  654|      3|    return UpRef(ptr.get());                                 \
  655|      3|  }
_ZN4bssl5UpRefEP16crypto_buffer_st:
  646|      2|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|      2|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 0, False: 2]
  ------------------
  648|      0|      up_ref_func(v);                                        \
  649|      0|    }                                                        \
  650|      2|    return UniquePtr<type>(v);                               \
  651|      2|  }                                                          \
_ZN4bssl5UpRefERKNSt3__110unique_ptrI16crypto_buffer_stNS_8internal7DeleterEEE:
  653|      2|  inline UniquePtr<type> UpRef(const UniquePtr<type> &ptr) { \
  654|      2|    return UpRef(ptr.get());                                 \
  655|      2|  }
_ZN4bssl5UpRefEP10ssl_ctx_st:
  646|      2|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|      2|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 2, False: 0]
  ------------------
  648|      2|      up_ref_func(v);                                        \
  649|      2|    }                                                        \
  650|      2|    return UniquePtr<type>(v);                               \
  651|      2|  }                                                          \
_ZN4bssl8internal14StackAllocatedI6cbb_stvXadL_Z8CBB_zeroEEXadL_Z11CBB_cleanupEEEC2Ev:
  577|    314|  StackAllocated() { init(&ctx_); }
_ZN4bssl8internal14StackAllocatedI6cbb_stvXadL_Z8CBB_zeroEEXadL_Z11CBB_cleanupEEED2Ev:
  578|    314|  ~StackAllocated() { cleanup(&ctx_); }
_ZN4bssl8internal14StackAllocatedI6cbb_stvXadL_Z8CBB_zeroEEXadL_Z11CBB_cleanupEEE3getEv:
  583|    368|  T *get() { return &ctx_; }
_ZN4bssl8internal14StackAllocatedI15evp_hpke_ctx_stvXadL_Z17EVP_HPKE_CTX_zeroEEXadL_Z20EVP_HPKE_CTX_cleanupEEEC2Ev:
  577|      1|  StackAllocated() { init(&ctx_); }
_ZN4bssl8internal14StackAllocatedI15evp_hpke_ctx_stvXadL_Z17EVP_HPKE_CTX_zeroEEXadL_Z20EVP_HPKE_CTX_cleanupEEED2Ev:
  578|      1|  ~StackAllocated() { cleanup(&ctx_); }
_ZN4bssl8internal7DeleterclI22stack_st_CRYPTO_BUFFEREEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal7DeleterclINS_13SSL_HANDSHAKEEEEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal7DeleterclI19stack_st_SSL_CIPHEREEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal7DeleterclI10buf_mem_stEEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal14StackAllocatedI15evp_aead_ctx_stvXadL_Z17EVP_AEAD_CTX_zeroEEXadL_Z20EVP_AEAD_CTX_cleanupEEEC2Ev:
  577|      2|  StackAllocated() { init(&ctx_); }
_ZN4bssl8internal14StackAllocatedI15evp_aead_ctx_stvXadL_Z17EVP_AEAD_CTX_zeroEEXadL_Z20EVP_AEAD_CTX_cleanupEEED2Ev:
  578|      2|  ~StackAllocated() { cleanup(&ctx_); }
_ZN4bssl8internal7DeleterclINS_14SSLAEADContextEEEvPT_:
  560|      2|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      2|    DeleterImpl<T>::Free(ptr);
  570|      2|  }
_ZN4bssl8internal7DeleterclINS_4CERTEEEvPT_:
  560|      2|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      2|    DeleterImpl<T>::Free(ptr);
  570|      2|  }
_ZN4bssl8internal7DeleterclINS_23SSLCipherPreferenceListEEEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal7DeleterclINS_10SSL_CONFIGEEEvPT_:
  560|      1|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|      1|    DeleterImpl<T>::Free(ptr);
  570|      1|  }
_ZN4bssl8internal21StackAllocatedMovableI13env_md_ctx_stiXadL_Z15EVP_MD_CTX_initEEXadL_Z18EVP_MD_CTX_cleanupEEXadL_Z15EVP_MD_CTX_moveEEEC2Ev:
  602|      2|  StackAllocatedMovable() { init(&ctx_); }
_ZN4bssl8internal21StackAllocatedMovableI13env_md_ctx_stiXadL_Z15EVP_MD_CTX_initEEXadL_Z18EVP_MD_CTX_cleanupEEXadL_Z15EVP_MD_CTX_moveEEED2Ev:
  603|      2|  ~StackAllocatedMovable() { cleanup(&ctx_); }
_ZN4bssl8internal21StackAllocatedMovableI13env_md_ctx_stiXadL_Z15EVP_MD_CTX_initEEXadL_Z18EVP_MD_CTX_cleanupEEXadL_Z15EVP_MD_CTX_moveEEE5ResetEv:
  620|      1|  void Reset() {
  621|      1|    cleanup(&ctx_);
  622|      1|    init(&ctx_);
  623|      1|  }

_ZN6cbs_stC2EN4bssl4SpanIKhEE:
   47|  2.18k|      : data(span.data()), len(span.size()) {}
_ZNK6cbs_stcvN4bssl4SpanIKhEEEv:
   48|  1.52k|  operator bssl::Span<const uint8_t>() const {
   49|  1.52k|    return bssl::MakeConstSpan(data, len);
   50|  1.52k|  }

_ZNK4bssl4SpanIKhE4dataEv:
  124|  3.40k|  T *data() const { return data_; }
_ZNK4bssl4SpanIKhE4sizeEv:
  125|  4.04k|  size_t size() const { return size_; }
_ZN4bssl13MakeConstSpanIKhEENS_4SpanIKT_EEPS3_m:
  199|  2.84k|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|  2.84k|  return Span<const T>(ptr, size);
  201|  2.84k|}
_ZN4bssl4SpanIKhEC2EPS1_m:
  110|  3.09k|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZN4bssl4SpanIKhEC2INS_5ArrayIhEEvS5_EERKT_:
  117|    416|  Span(const C &container) : data_(container.data()), size_(container.size()) {}
_ZN4bssl4SpanIKhEC2Ev:
  109|      1|  constexpr Span() : Span(nullptr, 0) {}
_ZN4bssl4SpanIhEC2EPhm:
  110|      1|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZNK4bssl4SpanIKhE7subspanEmm:
  154|    244|  Span subspan(size_t pos = 0, size_t len = npos) const {
  155|    244|    if (pos > size_) {
  ------------------
  |  Branch (155:9): [True: 0, False: 244]
  ------------------
  156|       |      // absl::Span throws an exception here. Note std::span and Chromium
  157|       |      // base::span additionally forbid pos + len being out of range, with a
  158|       |      // special case at npos/dynamic_extent, while absl::Span::subspan clips
  159|       |      // the span. For now, we align with absl::Span in case we switch to it in
  160|       |      // the future.
  161|      0|      abort();
  162|      0|    }
  163|    244|    return Span(data_ + pos, std::min(size_ - pos, len));
  164|    244|  }
_ZN4bssl4SpanIKtEC2INS_5ArrayItEEvS5_EERKT_:
  117|      3|  Span(const C &container) : data_(container.data()), size_(container.size()) {}
_ZNK4bssl4SpanIKtE4sizeEv:
  125|      6|  size_t size() const { return size_; }
_ZN4bssl4SpanIhEC2Ev:
  109|      1|  constexpr Span() : Span(nullptr, 0) {}
_ZNK4bssl4SpanIKtE4dataEv:
  124|      3|  T *data() const { return data_; }
_ZN4bssl4SpanIKbEC2EPS1_m:
  110|      2|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZNK4bssl4SpanIKbE4sizeEv:
  125|      3|  size_t size() const { return size_; }
_ZNK4bssl4SpanIKbE4dataEv:
  124|      1|  T *data() const { return data_; }
_ZN4bssl13MakeConstSpanINS_5ArrayIbEEEEDTcl13MakeConstSpancldtfp_4dataEcldtfp_4sizeEEERKT_:
  204|      1|auto MakeConstSpan(const C &c) -> decltype(MakeConstSpan(c.data(), c.size())) {
  205|      1|  return MakeConstSpan(c.data(), c.size());
  206|      1|}
_ZN4bssl13MakeConstSpanIKbEENS_4SpanIKT_EEPS3_m:
  199|      1|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|      1|  return Span<const T>(ptr, size);
  201|      1|}
_ZNK4bssl4SpanIKbE7subspanEmm:
  154|      1|  Span subspan(size_t pos = 0, size_t len = npos) const {
  155|      1|    if (pos > size_) {
  ------------------
  |  Branch (155:9): [True: 0, False: 1]
  ------------------
  156|       |      // absl::Span throws an exception here. Note std::span and Chromium
  157|       |      // base::span additionally forbid pos + len being out of range, with a
  158|       |      // special case at npos/dynamic_extent, while absl::Span::subspan clips
  159|       |      // the span. For now, we align with absl::Span in case we switch to it in
  160|       |      // the future.
  161|      0|      abort();
  162|      0|    }
  163|      1|    return Span(data_ + pos, std::min(size_ - pos, len));
  164|      1|  }

sk_CRYPTO_BUFFER_new_null:
  420|      1|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|      1|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|      1|  }                                                                           \
sk_X509_pop_free:
  447|      4|                                           sk_##name##_free_func free_func) { \
  448|      4|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|      4|                   (OPENSSL_sk_free_func)free_func);                          \
  450|      4|  }                                                                           \
sk_X509_NAME_pop_free:
  447|      3|                                           sk_##name##_free_func free_func) { \
  448|      3|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|      3|                   (OPENSSL_sk_free_func)free_func);                          \
  450|      3|  }                                                                           \
sk_SSL_CIPHER_new_null:
  420|      1|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|      1|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|      1|  }                                                                           \
sk_SSL_CIPHER_num:
  424|      2|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|      2|    return sk_num((const _STACK *)sk);                                        \
  426|      2|  }                                                                           \
sk_SSL_CIPHER_push:
  483|     19|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|     19|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|     19|  }                                                                           \
_ZN4bssl8internal11DeleterImplI22stack_st_CRYPTO_BUFFERvE4FreeEPS2_:
  552|      1|  static void Free(Stack *sk) {
  553|       |    // sk_FOO_pop_free is defined by macros and bound by name, so we cannot
  554|       |    // access it from C++ here.
  555|      1|    using Type = typename StackTraits<Stack>::Type;
  556|      1|    sk_pop_free_ex(reinterpret_cast<_STACK *>(sk),
  557|      1|                   [](OPENSSL_sk_free_func /* unused */, void *ptr) {
  558|      1|                     DeleterImpl<Type>::Free(reinterpret_cast<Type *>(ptr));
  559|      1|                   },
  560|      1|                   nullptr);
  561|      1|  }
_ZN4bssl8internal11DeleterImplI19stack_st_SSL_CIPHERvE4FreeEPS2_:
  545|      1|  static void Free(Stack *sk) { sk_free(reinterpret_cast<_STACK *>(sk)); }
x509_lu.c:sk_X509_OBJECT_new:
  416|      1|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new(sk_##name##_cmp_func comp) { \
  417|      1|    return (STACK_OF(name) *)sk_new((OPENSSL_sk_cmp_func)comp);               \
  418|      1|  }                                                                           \
x509_lu.c:sk_X509_LOOKUP_new_null:
  420|      1|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|      1|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|      1|  }                                                                           \
x509_lu.c:sk_X509_LOOKUP_free:
  442|      1|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|      1|    sk_free((_STACK *)sk);                                                    \
  444|      1|  }                                                                           \
x509_lu.c:sk_X509_LOOKUP_num:
  424|      1|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|      1|    return sk_num((const _STACK *)sk);                                        \
  426|      1|  }                                                                           \
x509_lu.c:sk_X509_OBJECT_pop_free:
  447|      1|                                           sk_##name##_free_func free_func) { \
  448|      1|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|      1|                   (OPENSSL_sk_free_func)free_func);                          \
  450|      1|  }                                                                           \

_ZN4bssl29ssl_decode_client_hello_innerEP6ssl_stPhPNS_5ArrayIhEENS_4SpanIKhEEPK22ssl_early_callback_ctx:
  128|    415|    const SSL_CLIENT_HELLO *client_hello_outer) {
  129|    415|  SSL_CLIENT_HELLO client_hello_inner;
  130|    415|  CBS cbs = encoded_client_hello_inner;
  131|    415|  if (!ssl_parse_client_hello_with_trailing_data(ssl, &cbs,
  ------------------
  |  Branch (131:7): [True: 67, False: 348]
  ------------------
  132|    415|                                                 &client_hello_inner)) {
  133|     67|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|     67|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  134|     67|    return false;
  135|     67|  }
  136|       |  // The remaining data is padding.
  137|    348|  uint8_t padding;
  138|  4.14k|  while (CBS_get_u8(&cbs, &padding)) {
  ------------------
  |  Branch (138:10): [True: 3.81k, False: 333]
  ------------------
  139|  3.81k|    if (padding != 0) {
  ------------------
  |  Branch (139:9): [True: 15, False: 3.80k]
  ------------------
  140|     15|      OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|     15|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|     15|      *out_alert = SSL_AD_ILLEGAL_PARAMETER;
  ------------------
  |  | 3940|     15|#define SSL_AD_ILLEGAL_PARAMETER SSL3_AD_ILLEGAL_PARAMETER
  |  |  ------------------
  |  |  |  |  288|     15|#define SSL3_AD_ILLEGAL_PARAMETER 47       // fatal
  |  |  ------------------
  ------------------
  142|     15|      return false;
  143|     15|    }
  144|  3.81k|  }
  145|       |
  146|       |  // TLS 1.3 ClientHellos must have extensions, and EncodedClientHelloInners use
  147|       |  // ClientHelloOuter's session_id.
  148|    333|  if (client_hello_inner.extensions_len == 0 ||
  ------------------
  |  Branch (148:7): [True: 15, False: 318]
  ------------------
  149|    333|      client_hello_inner.session_id_len != 0) {
  ------------------
  |  Branch (149:7): [True: 4, False: 314]
  ------------------
  150|     19|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|     19|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|     19|    return false;
  152|     19|  }
  153|    314|  client_hello_inner.session_id = client_hello_outer->session_id;
  154|    314|  client_hello_inner.session_id_len = client_hello_outer->session_id_len;
  155|       |
  156|       |  // Begin serializing a message containing the ClientHelloInner in |cbb|.
  157|    314|  ScopedCBB cbb;
  158|    314|  CBB body, extensions_cbb;
  159|    314|  if (!ssl->method->init_message(ssl, cbb.get(), &body, SSL3_MT_CLIENT_HELLO) ||
  ------------------
  |  |  294|    314|#define SSL3_MT_CLIENT_HELLO 1
  ------------------
  |  Branch (159:7): [True: 0, False: 314]
  ------------------
  160|    314|      !ssl_client_hello_write_without_extensions(&client_hello_inner, &body) ||
  ------------------
  |  Branch (160:7): [True: 0, False: 314]
  ------------------
  161|    314|      !CBB_add_u16_length_prefixed(&body, &extensions_cbb)) {
  ------------------
  |  Branch (161:7): [True: 0, False: 314]
  ------------------
  162|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|      0|    return false;
  164|      0|  }
  165|       |
  166|    314|  auto inner_extensions = MakeConstSpan(client_hello_inner.extensions,
  167|    314|                                        client_hello_inner.extensions_len);
  168|    314|  CBS ext_list_wrapper;
  169|    314|  if (!ssl_client_hello_get_extension(&client_hello_inner, &ext_list_wrapper,
  ------------------
  |  Branch (169:7): [True: 192, False: 122]
  ------------------
  170|    314|                                      TLSEXT_TYPE_ech_outer_extensions)) {
  ------------------
  |  |  252|    314|#define TLSEXT_TYPE_ech_outer_extensions 0xfd00
  ------------------
  171|       |    // No ech_outer_extensions. Copy everything.
  172|    192|    if (!CBB_add_bytes(&extensions_cbb, inner_extensions.data(),
  ------------------
  |  Branch (172:9): [True: 0, False: 192]
  ------------------
  173|    192|                       inner_extensions.size())) {
  174|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  175|      0|      return false;
  176|      0|    }
  177|    192|  } else {
  178|    122|    const size_t offset = CBS_data(&ext_list_wrapper) - inner_extensions.data();
  179|    122|    auto inner_extensions_before =
  180|    122|        inner_extensions.subspan(0, offset - 4 /* extension header */);
  181|    122|    auto inner_extensions_after =
  182|    122|        inner_extensions.subspan(offset + CBS_len(&ext_list_wrapper));
  183|    122|    if (!CBB_add_bytes(&extensions_cbb, inner_extensions_before.data(),
  ------------------
  |  Branch (183:9): [True: 0, False: 122]
  ------------------
  184|    122|                       inner_extensions_before.size())) {
  185|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  186|      0|      return false;
  187|      0|    }
  188|       |
  189|       |    // Expand ech_outer_extensions. See draft-ietf-tls-esni-13, Appendix B.
  190|    122|    CBS ext_list;
  191|    122|    if (!CBS_get_u8_length_prefixed(&ext_list_wrapper, &ext_list) ||
  ------------------
  |  Branch (191:9): [True: 18, False: 104]
  ------------------
  192|    122|        CBS_len(&ext_list) == 0 || CBS_len(&ext_list_wrapper) != 0) {
  ------------------
  |  Branch (192:9): [True: 5, False: 99]
  |  Branch (192:36): [True: 25, False: 74]
  ------------------
  193|     48|      OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|     48|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  194|     48|      return false;
  195|     48|    }
  196|     74|    CBS outer_extensions;
  197|     74|    CBS_init(&outer_extensions, client_hello_outer->extensions,
  198|     74|             client_hello_outer->extensions_len);
  199|    138|    while (CBS_len(&ext_list) != 0) {
  ------------------
  |  Branch (199:12): [True: 115, False: 23]
  ------------------
  200|       |      // Find the next extension to copy.
  201|    115|      uint16_t want;
  202|    115|      if (!CBS_get_u16(&ext_list, &want)) {
  ------------------
  |  Branch (202:11): [True: 1, False: 114]
  ------------------
  203|      1|        OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  204|      1|        return false;
  205|      1|      }
  206|       |      // The ECH extension itself is not in the AAD and may not be referenced.
  207|    114|      if (want == TLSEXT_TYPE_encrypted_client_hello) {
  ------------------
  |  |  251|    114|#define TLSEXT_TYPE_encrypted_client_hello 0xfe0d
  ------------------
  |  Branch (207:11): [True: 1, False: 113]
  ------------------
  208|      1|        *out_alert = SSL_AD_ILLEGAL_PARAMETER;
  ------------------
  |  | 3940|      1|#define SSL_AD_ILLEGAL_PARAMETER SSL3_AD_ILLEGAL_PARAMETER
  |  |  ------------------
  |  |  |  |  288|      1|#define SSL3_AD_ILLEGAL_PARAMETER 47       // fatal
  |  |  ------------------
  ------------------
  209|      1|        OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_OUTER_EXTENSION);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  210|      1|        return false;
  211|      1|      }
  212|       |      // Seek to |want| in |outer_extensions|. |ext_list| is required to match
  213|       |      // ClientHelloOuter in order.
  214|    113|      uint16_t found;
  215|    113|      CBS ext_body;
  216|    225|      do {
  217|    225|        if (CBS_len(&outer_extensions) == 0) {
  ------------------
  |  Branch (217:13): [True: 49, False: 176]
  ------------------
  218|     49|          *out_alert = SSL_AD_ILLEGAL_PARAMETER;
  ------------------
  |  | 3940|     49|#define SSL_AD_ILLEGAL_PARAMETER SSL3_AD_ILLEGAL_PARAMETER
  |  |  ------------------
  |  |  |  |  288|     49|#define SSL3_AD_ILLEGAL_PARAMETER 47       // fatal
  |  |  ------------------
  ------------------
  219|     49|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_OUTER_EXTENSION);
  ------------------
  |  |  441|     49|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  220|     49|          return false;
  221|     49|        }
  222|    176|        if (!CBS_get_u16(&outer_extensions, &found) ||
  ------------------
  |  Branch (222:13): [True: 0, False: 176]
  ------------------
  223|    176|            !CBS_get_u16_length_prefixed(&outer_extensions, &ext_body)) {
  ------------------
  |  Branch (223:13): [True: 0, False: 176]
  ------------------
  224|      0|          OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  225|      0|          return false;
  226|      0|        }
  227|    176|      } while (found != want);
  ------------------
  |  Branch (227:16): [True: 112, False: 64]
  ------------------
  228|       |      // Copy the extension.
  229|     64|      if (!CBB_add_u16(&extensions_cbb, found) ||
  ------------------
  |  Branch (229:11): [True: 0, False: 64]
  ------------------
  230|     64|          !CBB_add_u16(&extensions_cbb, CBS_len(&ext_body)) ||
  ------------------
  |  Branch (230:11): [True: 0, False: 64]
  ------------------
  231|     64|          !CBB_add_bytes(&extensions_cbb, CBS_data(&ext_body),
  ------------------
  |  Branch (231:11): [True: 0, False: 64]
  ------------------
  232|     64|                         CBS_len(&ext_body))) {
  233|      0|        OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  234|      0|        return false;
  235|      0|      }
  236|     64|    }
  237|       |
  238|     23|    if (!CBB_add_bytes(&extensions_cbb, inner_extensions_after.data(),
  ------------------
  |  Branch (238:9): [True: 0, False: 23]
  ------------------
  239|     23|                       inner_extensions_after.size())) {
  240|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  241|      0|      return false;
  242|      0|    }
  243|     23|  }
  244|    215|  if (!CBB_flush(&body)) {
  ------------------
  |  Branch (244:7): [True: 0, False: 215]
  ------------------
  245|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  246|      0|    return false;
  247|      0|  }
  248|       |
  249|    215|  if (!is_valid_client_hello_inner(
  ------------------
  |  Branch (249:7): [True: 161, False: 54]
  ------------------
  250|    215|          ssl, out_alert, MakeConstSpan(CBB_data(&body), CBB_len(&body)))) {
  251|    161|    return false;
  252|    161|  }
  253|       |
  254|     54|  if (!ssl->method->finish_message(ssl, cbb.get(), out_client_hello_inner)) {
  ------------------
  |  Branch (254:7): [True: 0, False: 54]
  ------------------
  255|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  256|      0|    return false;
  257|      0|  }
  258|     54|  return true;
  259|     54|}
encrypted_client_hello.cc:_ZN4bsslL41ssl_client_hello_write_without_extensionsEPK22ssl_early_callback_ctxP6cbb_st:
   62|    314|    const SSL_CLIENT_HELLO *client_hello, CBB *out) {
   63|    314|  CBB cbb;
   64|    314|  if (!CBB_add_u16(out, client_hello->version) ||
  ------------------
  |  Branch (64:7): [True: 0, False: 314]
  ------------------
   65|    314|      !CBB_add_bytes(out, client_hello->random, client_hello->random_len) ||
  ------------------
  |  Branch (65:7): [True: 0, False: 314]
  ------------------
   66|    314|      !CBB_add_u8_length_prefixed(out, &cbb) ||
  ------------------
  |  Branch (66:7): [True: 0, False: 314]
  ------------------
   67|    314|      !CBB_add_bytes(&cbb, client_hello->session_id,
  ------------------
  |  Branch (67:7): [True: 0, False: 314]
  ------------------
   68|    314|                     client_hello->session_id_len) ||
   69|    314|      !CBB_add_u16_length_prefixed(out, &cbb) ||
  ------------------
  |  Branch (69:7): [True: 0, False: 314]
  ------------------
   70|    314|      !CBB_add_bytes(&cbb, client_hello->cipher_suites,
  ------------------
  |  Branch (70:7): [True: 0, False: 314]
  ------------------
   71|    314|                     client_hello->cipher_suites_len) ||
   72|    314|      !CBB_add_u8_length_prefixed(out, &cbb) ||
  ------------------
  |  Branch (72:7): [True: 0, False: 314]
  ------------------
   73|    314|      !CBB_add_bytes(&cbb, client_hello->compression_methods,
  ------------------
  |  Branch (73:7): [True: 0, False: 314]
  ------------------
   74|    314|                     client_hello->compression_methods_len) ||
   75|    314|      !CBB_flush(out)) {
  ------------------
  |  Branch (75:7): [True: 0, False: 314]
  ------------------
   76|      0|    return false;
   77|      0|  }
   78|    314|  return true;
   79|    314|}
encrypted_client_hello.cc:_ZN4bsslL27is_valid_client_hello_innerEP6ssl_stPhNS_4SpanIKhEE:
   82|    215|                                        Span<const uint8_t> body) {
   83|       |  // See draft-ietf-tls-esni-13, section 7.1.
   84|    215|  SSL_CLIENT_HELLO client_hello;
   85|    215|  CBS extension;
   86|    215|  if (!ssl_client_hello_init(ssl, &client_hello, body) ||
  ------------------
  |  Branch (86:7): [True: 3, False: 212]
  ------------------
   87|    215|      !ssl_client_hello_get_extension(&client_hello, &extension,
  ------------------
  |  Branch (87:7): [True: 91, False: 121]
  ------------------
   88|    212|                                      TLSEXT_TYPE_encrypted_client_hello) ||
  ------------------
  |  |  251|    212|#define TLSEXT_TYPE_encrypted_client_hello 0xfe0d
  ------------------
   89|    215|      CBS_len(&extension) != 1 ||  //
  ------------------
  |  Branch (89:7): [True: 13, False: 108]
  ------------------
   90|    215|      CBS_data(&extension)[0] != ECH_CLIENT_INNER ||
  ------------------
  |  | 1510|    323|#define ECH_CLIENT_INNER 1
  ------------------
  |  Branch (90:7): [True: 9, False: 99]
  ------------------
   91|    215|      !ssl_client_hello_get_extension(&client_hello, &extension,
  ------------------
  |  Branch (91:7): [True: 13, False: 86]
  ------------------
   92|    129|                                      TLSEXT_TYPE_supported_versions)) {
  ------------------
  |  |  232|     99|#define TLSEXT_TYPE_supported_versions 43
  ------------------
   93|    129|    *out_alert = SSL_AD_ILLEGAL_PARAMETER;
  ------------------
  |  | 3940|    129|#define SSL_AD_ILLEGAL_PARAMETER SSL3_AD_ILLEGAL_PARAMETER
  |  |  ------------------
  |  |  |  |  288|    129|#define SSL3_AD_ILLEGAL_PARAMETER 47       // fatal
  |  |  ------------------
  ------------------
   94|    129|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_CLIENT_HELLO_INNER);
  ------------------
  |  |  441|    129|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   95|    129|    return false;
   96|    129|  }
   97|       |  // Parse supported_versions and reject TLS versions prior to TLS 1.3. Older
   98|       |  // versions are incompatible with ECH.
   99|     86|  CBS versions;
  100|     86|  if (!CBS_get_u8_length_prefixed(&extension, &versions) ||
  ------------------
  |  Branch (100:7): [True: 2, False: 84]
  ------------------
  101|     86|      CBS_len(&extension) != 0 ||  //
  ------------------
  |  Branch (101:7): [True: 8, False: 76]
  ------------------
  102|     86|      CBS_len(&versions) == 0) {
  ------------------
  |  Branch (102:7): [True: 3, False: 73]
  ------------------
  103|     13|    *out_alert = SSL_AD_DECODE_ERROR;
  ------------------
  |  | 3943|     13|#define SSL_AD_DECODE_ERROR TLS1_AD_DECODE_ERROR
  |  |  ------------------
  |  |  |  |  165|     13|#define TLS1_AD_DECODE_ERROR 50
  |  |  ------------------
  ------------------
  104|     13|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|     13|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  105|     13|    return false;
  106|     13|  }
  107|    399|  while (CBS_len(&versions) != 0) {
  ------------------
  |  Branch (107:10): [True: 345, False: 54]
  ------------------
  108|    345|    uint16_t version;
  109|    345|    if (!CBS_get_u16(&versions, &version)) {
  ------------------
  |  Branch (109:9): [True: 8, False: 337]
  ------------------
  110|      8|      *out_alert = SSL_AD_DECODE_ERROR;
  ------------------
  |  | 3943|      8|#define SSL_AD_DECODE_ERROR TLS1_AD_DECODE_ERROR
  |  |  ------------------
  |  |  |  |  165|      8|#define TLS1_AD_DECODE_ERROR 50
  |  |  ------------------
  ------------------
  111|      8|      OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|      8|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  112|      8|      return false;
  113|      8|    }
  114|    337|    if (version == SSL3_VERSION || version == TLS1_VERSION ||
  ------------------
  |  |  644|    674|#define SSL3_VERSION 0x0300
  ------------------
                  if (version == SSL3_VERSION || version == TLS1_VERSION ||
  ------------------
  |  |  645|    671|#define TLS1_VERSION 0x0301
  ------------------
  |  Branch (114:9): [True: 3, False: 334]
  |  Branch (114:36): [True: 3, False: 331]
  ------------------
  115|    337|        version == TLS1_1_VERSION || version == TLS1_2_VERSION ||
  ------------------
  |  |  646|    668|#define TLS1_1_VERSION 0x0302
  ------------------
                      version == TLS1_1_VERSION || version == TLS1_2_VERSION ||
  ------------------
  |  |  647|    667|#define TLS1_2_VERSION 0x0303
  ------------------
  |  Branch (115:9): [True: 1, False: 330]
  |  Branch (115:38): [True: 1, False: 329]
  ------------------
  116|    337|        version == DTLS1_VERSION || version == DTLS1_2_VERSION) {
  ------------------
  |  |  650|    666|#define DTLS1_VERSION 0xfeff
  ------------------
                      version == DTLS1_VERSION || version == DTLS1_2_VERSION) {
  ------------------
  |  |  651|    327|#define DTLS1_2_VERSION 0xfefd
  ------------------
  |  Branch (116:9): [True: 2, False: 327]
  |  Branch (116:37): [True: 1, False: 326]
  ------------------
  117|     11|      *out_alert = SSL_AD_ILLEGAL_PARAMETER;
  ------------------
  |  | 3940|     11|#define SSL_AD_ILLEGAL_PARAMETER SSL3_AD_ILLEGAL_PARAMETER
  |  |  ------------------
  |  |  |  |  288|     11|#define SSL3_AD_ILLEGAL_PARAMETER 47       // fatal
  |  |  ------------------
  ------------------
  118|     11|      OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_CLIENT_HELLO_INNER);
  ------------------
  |  |  441|     11|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  119|     11|      return false;
  120|     11|    }
  121|    337|  }
  122|     54|  return true;
  123|     73|}

_ZN4bssl21ssl_client_hello_initEPK6ssl_stP22ssl_early_callback_ctxNS_4SpanIKhEE:
  217|    975|                           Span<const uint8_t> body) {
  218|    975|  CBS cbs = body;
  219|    975|  if (!ssl_parse_client_hello_with_trailing_data(ssl, &cbs, out) ||
  ------------------
  |  Branch (219:7): [True: 308, False: 667]
  ------------------
  220|    975|      CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (220:7): [True: 40, False: 627]
  ------------------
  221|    348|    return false;
  222|    348|  }
  223|    627|  return true;
  224|    975|}
_ZN4bssl41ssl_parse_client_hello_with_trailing_dataEPK6ssl_stP6cbs_stP22ssl_early_callback_ctx:
  227|  1.39k|                                               SSL_CLIENT_HELLO *out) {
  228|  1.39k|  OPENSSL_memset(out, 0, sizeof(*out));
  229|  1.39k|  out->ssl = const_cast<SSL *>(ssl);
  230|       |
  231|  1.39k|  CBS copy = *cbs;
  232|  1.39k|  CBS random, session_id;
  233|  1.39k|  if (!CBS_get_u16(cbs, &out->version) ||
  ------------------
  |  Branch (233:7): [True: 97, False: 1.29k]
  ------------------
  234|  1.39k|      !CBS_get_bytes(cbs, &random, SSL3_RANDOM_SIZE) ||
  ------------------
  |  |  202|  1.29k|#define SSL3_RANDOM_SIZE 32
  ------------------
  |  Branch (234:7): [True: 18, False: 1.27k]
  ------------------
  235|  1.39k|      !CBS_get_u8_length_prefixed(cbs, &session_id) ||
  ------------------
  |  Branch (235:7): [True: 12, False: 1.26k]
  ------------------
  236|  1.39k|      CBS_len(&session_id) > SSL_MAX_SSL_SESSION_ID_LENGTH) {
  ------------------
  |  | 1766|  1.26k|#define SSL_MAX_SSL_SESSION_ID_LENGTH 32
  ------------------
  |  Branch (236:7): [True: 25, False: 1.23k]
  ------------------
  237|    152|    return false;
  238|    152|  }
  239|       |
  240|  1.23k|  out->random = CBS_data(&random);
  241|  1.23k|  out->random_len = CBS_len(&random);
  242|  1.23k|  out->session_id = CBS_data(&session_id);
  243|  1.23k|  out->session_id_len = CBS_len(&session_id);
  244|       |
  245|       |  // Skip past DTLS cookie
  246|  1.23k|  if (SSL_is_dtls(out->ssl)) {
  ------------------
  |  Branch (246:7): [True: 0, False: 1.23k]
  ------------------
  247|      0|    CBS cookie;
  248|      0|    if (!CBS_get_u8_length_prefixed(cbs, &cookie)) {
  ------------------
  |  Branch (248:9): [True: 0, False: 0]
  ------------------
  249|      0|      return false;
  250|      0|    }
  251|      0|  }
  252|       |
  253|  1.23k|  CBS cipher_suites, compression_methods;
  254|  1.23k|  if (!CBS_get_u16_length_prefixed(cbs, &cipher_suites) ||
  ------------------
  |  Branch (254:7): [True: 40, False: 1.19k]
  ------------------
  255|  1.23k|      CBS_len(&cipher_suites) < 2 || (CBS_len(&cipher_suites) & 1) != 0 ||
  ------------------
  |  Branch (255:7): [True: 44, False: 1.15k]
  |  Branch (255:38): [True: 24, False: 1.13k]
  ------------------
  256|  1.23k|      !CBS_get_u8_length_prefixed(cbs, &compression_methods) ||
  ------------------
  |  Branch (256:7): [True: 5, False: 1.12k]
  ------------------
  257|  1.23k|      CBS_len(&compression_methods) < 1) {
  ------------------
  |  Branch (257:7): [True: 5, False: 1.12k]
  ------------------
  258|    118|    return false;
  259|    118|  }
  260|       |
  261|  1.12k|  out->cipher_suites = CBS_data(&cipher_suites);
  262|  1.12k|  out->cipher_suites_len = CBS_len(&cipher_suites);
  263|  1.12k|  out->compression_methods = CBS_data(&compression_methods);
  264|  1.12k|  out->compression_methods_len = CBS_len(&compression_methods);
  265|       |
  266|       |  // If the ClientHello ends here then it's valid, but doesn't have any
  267|       |  // extensions.
  268|  1.12k|  if (CBS_len(cbs) == 0) {
  ------------------
  |  Branch (268:7): [True: 322, False: 798]
  ------------------
  269|    322|    out->extensions = nullptr;
  270|    322|    out->extensions_len = 0;
  271|    798|  } else {
  272|       |    // Extract extensions and check it is valid.
  273|    798|    CBS extensions;
  274|    798|    if (!CBS_get_u16_length_prefixed(cbs, &extensions) ||
  ------------------
  |  Branch (274:9): [True: 10, False: 788]
  ------------------
  275|    798|        !tls1_check_duplicate_extensions(&extensions)) {
  ------------------
  |  Branch (275:9): [True: 95, False: 693]
  ------------------
  276|    105|      return false;
  277|    105|    }
  278|    693|    out->extensions = CBS_data(&extensions);
  279|    693|    out->extensions_len = CBS_len(&extensions);
  280|    693|  }
  281|       |
  282|  1.01k|  out->client_hello = CBS_data(&copy);
  283|  1.01k|  out->client_hello_len = CBS_len(&copy) - CBS_len(cbs);
  284|  1.01k|  return true;
  285|  1.12k|}
_ZN4bssl30ssl_client_hello_get_extensionEPK22ssl_early_callback_ctxP6cbs_stt:
  288|    625|                                    CBS *out, uint16_t extension_type) {
  289|    625|  CBS extensions;
  290|    625|  CBS_init(&extensions, client_hello->extensions, client_hello->extensions_len);
  291|  1.97k|  while (CBS_len(&extensions) != 0) {
  ------------------
  |  Branch (291:10): [True: 1.67k, False: 296]
  ------------------
  292|       |    // Decode the next extension.
  293|  1.67k|    uint16_t type;
  294|  1.67k|    CBS extension;
  295|  1.67k|    if (!CBS_get_u16(&extensions, &type) ||
  ------------------
  |  Branch (295:9): [True: 0, False: 1.67k]
  ------------------
  296|  1.67k|        !CBS_get_u16_length_prefixed(&extensions, &extension)) {
  ------------------
  |  Branch (296:9): [True: 0, False: 1.67k]
  ------------------
  297|      0|      return false;
  298|      0|    }
  299|       |
  300|  1.67k|    if (type == extension_type) {
  ------------------
  |  Branch (300:9): [True: 329, False: 1.34k]
  ------------------
  301|    329|      *out = extension;
  302|    329|      return true;
  303|    329|    }
  304|  1.67k|  }
  305|       |
  306|    296|  return false;
  307|    625|}
extensions.cc:_ZN4bsslL31tls1_check_duplicate_extensionsEPK6cbs_st:
  157|    788|static bool tls1_check_duplicate_extensions(const CBS *cbs) {
  158|       |  // First pass: count the extensions.
  159|    788|  size_t num_extensions = 0;
  160|    788|  CBS extensions = *cbs;
  161|   109k|  while (CBS_len(&extensions) > 0) {
  ------------------
  |  Branch (161:10): [True: 108k, False: 757]
  ------------------
  162|   108k|    uint16_t type;
  163|   108k|    CBS extension;
  164|       |
  165|   108k|    if (!CBS_get_u16(&extensions, &type) ||
  ------------------
  |  Branch (165:9): [True: 2, False: 108k]
  ------------------
  166|   108k|        !CBS_get_u16_length_prefixed(&extensions, &extension)) {
  ------------------
  |  Branch (166:9): [True: 29, False: 108k]
  ------------------
  167|     31|      return false;
  168|     31|    }
  169|       |
  170|   108k|    num_extensions++;
  171|   108k|  }
  172|       |
  173|    757|  if (num_extensions == 0) {
  ------------------
  |  Branch (173:7): [True: 67, False: 690]
  ------------------
  174|     67|    return true;
  175|     67|  }
  176|       |
  177|    690|  Array<uint16_t> extension_types;
  178|    690|  if (!extension_types.Init(num_extensions)) {
  ------------------
  |  Branch (178:7): [True: 0, False: 690]
  ------------------
  179|      0|    return false;
  180|      0|  }
  181|       |
  182|       |  // Second pass: gather the extension types.
  183|    690|  extensions = *cbs;
  184|   105k|  for (size_t i = 0; i < extension_types.size(); i++) {
  ------------------
  |  Branch (184:22): [True: 104k, False: 690]
  ------------------
  185|   104k|    CBS extension;
  186|       |
  187|   104k|    if (!CBS_get_u16(&extensions, &extension_types[i]) ||
  ------------------
  |  Branch (187:9): [True: 0, False: 104k]
  ------------------
  188|   104k|        !CBS_get_u16_length_prefixed(&extensions, &extension)) {
  ------------------
  |  Branch (188:9): [True: 0, False: 104k]
  ------------------
  189|       |      // This should not happen.
  190|      0|      return false;
  191|      0|    }
  192|   104k|  }
  193|    690|  assert(CBS_len(&extensions) == 0);
  194|       |
  195|       |  // Sort the extensions and make sure there are no duplicates.
  196|      0|  qsort(extension_types.data(), extension_types.size(), sizeof(uint16_t),
  197|    690|        compare_uint16_t);
  198|  2.29k|  for (size_t i = 1; i < num_extensions; i++) {
  ------------------
  |  Branch (198:22): [True: 1.66k, False: 626]
  ------------------
  199|  1.66k|    if (extension_types[i - 1] == extension_types[i]) {
  ------------------
  |  Branch (199:9): [True: 64, False: 1.60k]
  ------------------
  200|     64|      return false;
  201|     64|    }
  202|  1.66k|  }
  203|       |
  204|    626|  return true;
  205|    690|}
extensions.cc:_ZN4bsslL16compare_uint16_tEPKvS1_:
  141|   923k|static int compare_uint16_t(const void *p1, const void *p2) {
  142|   923k|  uint16_t u1 = *((const uint16_t *)p1);
  143|   923k|  uint16_t u2 = *((const uint16_t *)p2);
  144|   923k|  if (u1 < u2) {
  ------------------
  |  Branch (144:7): [True: 15.4k, False: 907k]
  ------------------
  145|  15.4k|    return -1;
  146|   907k|  } else if (u1 > u2) {
  ------------------
  |  Branch (146:14): [True: 283k, False: 624k]
  ------------------
  147|   283k|    return 1;
  148|   624k|  } else {
  149|   624k|    return 0;
  150|   624k|  }
  151|   923k|}

_ZN4bssl13SSL_HANDSHAKEC2EP6ssl_st:
  153|      1|      channel_id_negotiated(false) {
  154|      1|  assert(ssl);
  155|       |
  156|       |  // Draw entropy for all GREASE values at once. This avoids calling
  157|       |  // |RAND_bytes| repeatedly and makes the values consistent within a
  158|       |  // connection. The latter is so the second ClientHello matches after
  159|       |  // HelloRetryRequest and so supported_groups and key_shares are consistent.
  160|      0|  RAND_bytes(grease_seed, sizeof(grease_seed));
  161|      1|}
_ZN4bssl13SSL_HANDSHAKED2Ev:
  163|      1|SSL_HANDSHAKE::~SSL_HANDSHAKE() {
  164|      1|  ssl->ctx->x509_method->hs_flush_cached_ca_names(this);
  165|      1|}
_ZN4bssl17ssl_handshake_newEP6ssl_st:
  196|      1|UniquePtr<SSL_HANDSHAKE> ssl_handshake_new(SSL *ssl) {
  197|      1|  UniquePtr<SSL_HANDSHAKE> hs = MakeUnique<SSL_HANDSHAKE>(ssl);
  198|      1|  if (!hs || !hs->transcript.Init()) {
  ------------------
  |  Branch (198:7): [True: 0, False: 1]
  |  Branch (198:14): [True: 0, False: 1]
  ------------------
  199|      0|    return nullptr;
  200|      0|  }
  201|      1|  hs->config = ssl->config.get();
  202|      1|  if (!hs->config) {
  ------------------
  |  Branch (202:7): [True: 0, False: 1]
  ------------------
  203|      0|    assert(hs->config);
  204|      0|    return nullptr;
  205|      0|  }
  206|      1|  return hs;
  207|      1|}

_ZN4bssl5ArrayIhEC2Ev:
  252|  1.19k|  Array() {}
_ZN4bssl5ArrayIhED2Ev:
  256|  1.19k|  ~Array() { Reset(); }
_ZN4bssl5ArrayIhE5ResetEv:
  278|  1.95k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayIhE5ResetEPhm:
  282|  2.01k|  void Reset(T *new_data, size_t new_size) {
  283|  5.44M|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 5.44M, False: 2.01k]
  ------------------
  284|  5.44M|      data_[i].~T();
  285|  5.44M|    }
  286|  2.01k|    OPENSSL_free(data_);
  287|  2.01k|    data_ = new_data;
  288|  2.01k|    size_ = new_size;
  289|  2.01k|  }
_ZN4bssl5ArrayIhE8CopyFromENS_4SpanIKhEE:
  328|    761|  bool CopyFrom(Span<const T> in) {
  329|    761|    if (!Init(in.size())) {
  ------------------
  |  Branch (329:9): [True: 0, False: 761]
  ------------------
  330|      0|      return false;
  331|      0|    }
  332|    761|    OPENSSL_memcpy(data_, in.data(), sizeof(T) * in.size());
  333|    761|    return true;
  334|    761|  }
_ZN4bssl5ArrayIhE4InitEm:
  305|    761|  bool Init(size_t new_size) {
  306|    761|    Reset();
  307|    761|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 361, False: 400]
  ------------------
  308|    361|      return true;
  309|    361|    }
  310|       |
  311|    400|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 400]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|    400|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|    400|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 400]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|    400|    size_ = new_size;
  320|  5.44M|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 5.44M, False: 400]
  ------------------
  321|  5.44M|      new (&data_[i]) T;
  322|  5.44M|    }
  323|    400|    return true;
  324|    400|  }
_ZNK4bssl5ArrayIhE4dataEv:
  265|    416|  const T *data() const { return data_; }
_ZNK4bssl5ArrayIhE4sizeEv:
  267|    416|  size_t size() const { return size_; }
_ZN4bssl9SSLBufferC2Ev:
 1231|      2|  SSLBuffer() {}
_ZN4bssl9SSLBufferD2Ev:
 1232|      2|  ~SSLBuffer() { Clear(); }
_ZN4bssl5ArrayItEC2Ev:
  252|    699|  Array() {}
_ZN4bssl5ArrayItE4InitEm:
  305|    693|  bool Init(size_t new_size) {
  306|    693|    Reset();
  307|    693|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 3, False: 690]
  ------------------
  308|      3|      return true;
  309|      3|    }
  310|       |
  311|    690|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 690]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|    690|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|    690|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 690]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|    690|    size_ = new_size;
  320|   105k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 104k, False: 690]
  ------------------
  321|   104k|      new (&data_[i]) T;
  322|   104k|    }
  323|    690|    return true;
  324|    690|  }
_ZN4bssl5ArrayItE5ResetEv:
  278|  1.39k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayItE5ResetEPtm:
  282|  1.39k|  void Reset(T *new_data, size_t new_size) {
  283|   106k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 104k, False: 1.39k]
  ------------------
  284|   104k|      data_[i].~T();
  285|   104k|    }
  286|  1.39k|    OPENSSL_free(data_);
  287|  1.39k|    data_ = new_data;
  288|  1.39k|    size_ = new_size;
  289|  1.39k|  }
_ZNK4bssl5ArrayItE4sizeEv:
  267|   106k|  size_t size() const { return size_; }
_ZN4bssl5ArrayItEixEm:
  271|   108k|  T &operator[](size_t i) { return data_[i]; }
_ZN4bssl5ArrayItE4dataEv:
  266|    690|  T *data() { return data_; }
_ZN4bssl5ArrayItED2Ev:
  256|    699|  ~Array() { Reset(); }
_ZNK4bssl5ArrayItE4dataEv:
  265|      3|  const T *data() const { return data_; }
_ZN4bssl10MakeUniqueINS_13SSL_HANDSHAKEEJRP6ssl_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewINS_13SSL_HANDSHAKEEJRP6ssl_stEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl8internal11DeleterImplINS_13SSL_HANDSHAKEEvE4FreeEPS2_:
  219|      1|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_13SSL_HANDSHAKEEEEvPT_:
  207|      1|void Delete(T *t) {
  208|      1|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 1, False: 0]
  ------------------
  209|      1|    t->~T();
  210|      1|    OPENSSL_free(t);
  211|      1|  }
  212|      1|}
_ZN4bssl10MakeUniqueINS_14SSLAEADContextEJiRbDnEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      2|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      2|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      2|}
_ZN4bssl3NewINS_14SSLAEADContextEJiRbDnEEEPT_DpOT0_:
  195|      2|T *New(Args &&... args) {
  196|      2|  void *t = OPENSSL_malloc(sizeof(T));
  197|      2|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 2]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      2|  return new (t) T(std::forward<Args>(args)...);
  201|      2|}
_ZN4bssl8internal11DeleterImplINS_14SSLAEADContextEvE4FreeEPS2_:
  219|      2|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_14SSLAEADContextEEEvPT_:
  207|      2|void Delete(T *t) {
  208|      2|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 2, False: 0]
  ------------------
  209|      2|    t->~T();
  210|      2|    OPENSSL_free(t);
  211|      2|  }
  212|      2|}
_ZN4bssl10MakeUniqueINS_4CERTEJRPKNS_15SSL_X509_METHODEEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewINS_4CERTEJRPKNS_15SSL_X509_METHODEEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl8internal11DeleterImplINS_4CERTEvE4FreeEPS2_:
  219|      2|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_4CERTEEEvPT_:
  207|      2|void Delete(T *t) {
  208|      2|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 2, False: 0]
  ------------------
  209|      2|    t->~T();
  210|      2|    OPENSSL_free(t);
  211|      2|  }
  212|      2|}
_ZN4bssl5ArrayItE8CopyFromENS_4SpanIKtEE:
  328|      3|  bool CopyFrom(Span<const T> in) {
  329|      3|    if (!Init(in.size())) {
  ------------------
  |  Branch (329:9): [True: 0, False: 3]
  ------------------
  330|      0|      return false;
  331|      0|    }
  332|      3|    OPENSSL_memcpy(data_, in.data(), sizeof(T) * in.size());
  333|      3|    return true;
  334|      3|  }
_ZN4bssl5ArrayIbEC2Ev:
  252|      2|  Array() {}
_ZN4bssl5ArrayIbED2Ev:
  256|      2|  ~Array() { Reset(); }
_ZN4bssl5ArrayIbE5ResetEv:
  278|      4|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayIbE5ResetEPbm:
  282|      4|  void Reset(T *new_data, size_t new_size) {
  283|     28|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 24, False: 4]
  ------------------
  284|     24|      data_[i].~T();
  285|     24|    }
  286|      4|    OPENSSL_free(data_);
  287|      4|    data_ = new_data;
  288|      4|    size_ = new_size;
  289|      4|  }
_ZN4bssl5ArrayIbE8CopyFromENS_4SpanIKbEE:
  328|      1|  bool CopyFrom(Span<const T> in) {
  329|      1|    if (!Init(in.size())) {
  ------------------
  |  Branch (329:9): [True: 0, False: 1]
  ------------------
  330|      0|      return false;
  331|      0|    }
  332|      1|    OPENSSL_memcpy(data_, in.data(), sizeof(T) * in.size());
  333|      1|    return true;
  334|      1|  }
_ZN4bssl5ArrayIbE7ReleaseEPPbPm:
  293|      1|  void Release(T **out, size_t *out_size) {
  294|      1|    *out = data_;
  295|      1|    *out_size = size_;
  296|      1|    data_ = nullptr;
  297|      1|    size_ = 0;
  298|      1|  }
_ZN4bssl5ArrayIbE4InitEm:
  305|      2|  bool Init(size_t new_size) {
  306|      2|    Reset();
  307|      2|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 0, False: 2]
  ------------------
  308|      0|      return true;
  309|      0|    }
  310|       |
  311|      2|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 2]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|      2|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|      2|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 2]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|      2|    size_ = new_size;
  320|     45|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 43, False: 2]
  ------------------
  321|     43|      new (&data_[i]) T;
  322|     43|    }
  323|      2|    return true;
  324|      2|  }
_ZN4bssl5ArrayIbEixEm:
  271|     19|  T &operator[](size_t i) { return data_[i]; }
_ZN4bssl10MakeUniqueINS_23SSLCipherPreferenceListEJEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewINS_23SSLCipherPreferenceListEJEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl23SSLCipherPreferenceListC2Ev:
  622|      1|  SSLCipherPreferenceList() = default;
_ZN4bssl8internal11DeleterImplINS_23SSLCipherPreferenceListEvE4FreeEPS2_:
  219|      1|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_23SSLCipherPreferenceListEEEvPT_:
  207|      1|void Delete(T *t) {
  208|      1|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 1, False: 0]
  ------------------
  209|      1|    t->~T();
  210|      1|    OPENSSL_free(t);
  211|      1|  }
  212|      1|}
_ZNK4bssl5ArrayIbE4dataEv:
  265|      1|  const T *data() const { return data_; }
_ZNK4bssl5ArrayIbE4sizeEv:
  267|      1|  size_t size() const { return size_; }
_ZN4bssl13GrowableArrayINS_18CertCompressionAlgEEC2Ev:
  362|      1|  GrowableArray() = default;
_ZN4bssl5ArrayINS_18CertCompressionAlgEEC2Ev:
  252|      1|  Array() {}
_ZN4bssl13GrowableArrayINS_10ALPSConfigEEC2Ev:
  362|      1|  GrowableArray() = default;
_ZN4bssl5ArrayINS_10ALPSConfigEEC2Ev:
  252|      1|  Array() {}
_ZN4bssl8internal11DeleterImplINS_10SSL_CONFIGEvE4FreeEPS2_:
  219|      1|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_10SSL_CONFIGEEEvPT_:
  207|      1|void Delete(T *t) {
  208|      1|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 1, False: 0]
  ------------------
  209|      1|    t->~T();
  210|      1|    OPENSSL_free(t);
  211|      1|  }
  212|      1|}
_ZN4bssl13GrowableArrayINS_18CertCompressionAlgEED2Ev:
  365|      1|  ~GrowableArray() {}
_ZN4bssl5ArrayINS_18CertCompressionAlgEED2Ev:
  256|      1|  ~Array() { Reset(); }
_ZN4bssl5ArrayINS_18CertCompressionAlgEE5ResetEv:
  278|      1|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayINS_18CertCompressionAlgEE5ResetEPS1_m:
  282|      1|  void Reset(T *new_data, size_t new_size) {
  283|      1|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 0, False: 1]
  ------------------
  284|      0|      data_[i].~T();
  285|      0|    }
  286|      1|    OPENSSL_free(data_);
  287|      1|    data_ = new_data;
  288|      1|    size_ = new_size;
  289|      1|  }
_ZN4bssl10MakeUniqueI10ssl_ctx_stJRPK13ssl_method_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewI10ssl_ctx_stJRPK13ssl_method_stEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl10MakeUniqueINS_4CERTEJRKPKNS_15SSL_X509_METHODEEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewINS_4CERTEJRKPKNS_15SSL_X509_METHODEEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl10MakeUniqueI6ssl_stJRP10ssl_ctx_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewI6ssl_stJRP10ssl_ctx_stEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl10MakeUniqueINS_10SSL_CONFIGEJP6ssl_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewINS_10SSL_CONFIGEJP6ssl_stEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl13GrowableArrayINS_10ALPSConfigEED2Ev:
  365|      1|  ~GrowableArray() {}
_ZN4bssl5ArrayINS_10ALPSConfigEED2Ev:
  256|      1|  ~Array() { Reset(); }
_ZN4bssl5ArrayINS_10ALPSConfigEE5ResetEv:
  278|      1|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayINS_10ALPSConfigEE5ResetEPS1_m:
  282|      1|  void Reset(T *new_data, size_t new_size) {
  283|      1|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 0, False: 1]
  ------------------
  284|      0|      data_[i].~T();
  285|      0|    }
  286|      1|    OPENSSL_free(data_);
  287|      1|    data_ = new_data;
  288|      1|    size_ = new_size;
  289|      1|  }
_ZN4bssl6DeleteI6ssl_stEEvPT_:
  207|      1|void Delete(T *t) {
  208|      1|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 1, False: 0]
  ------------------
  209|      1|    t->~T();
  210|      1|    OPENSSL_free(t);
  211|      1|  }
  212|      1|}
_ZN4bssl10MakeUniqueINS_10SSL3_STATEEJEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|      1|UniquePtr<T> MakeUnique(Args &&... args) {
  227|      1|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|      1|}
_ZN4bssl3NewINS_10SSL3_STATEEJEEEPT_DpOT0_:
  195|      1|T *New(Args &&... args) {
  196|      1|  void *t = OPENSSL_malloc(sizeof(T));
  197|      1|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 1]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|      1|  return new (t) T(std::forward<Args>(args)...);
  201|      1|}
_ZN4bssl6DeleteINS_10SSL3_STATEEEEvPT_:
  207|      1|void Delete(T *t) {
  208|      1|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 1, False: 0]
  ------------------
  209|      1|    t->~T();
  210|      1|    OPENSSL_free(t);
  211|      1|  }
  212|      1|}

_ZN4bssl16tls_init_messageEPK6ssl_stP6cbb_stS4_h:
  171|    314|bool tls_init_message(const SSL *ssl, CBB *cbb, CBB *body, uint8_t type) {
  172|       |  // Pick a modest size hint to save most of the |realloc| calls.
  173|    314|  if (!CBB_init(cbb, 64) ||
  ------------------
  |  Branch (173:7): [True: 0, False: 314]
  ------------------
  174|    314|      !CBB_add_u8(cbb, type) ||
  ------------------
  |  Branch (174:7): [True: 0, False: 314]
  ------------------
  175|    314|      !CBB_add_u24_length_prefixed(cbb, body)) {
  ------------------
  |  Branch (175:7): [True: 0, False: 314]
  ------------------
  176|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|    CBB_cleanup(cbb);
  178|      0|    return false;
  179|      0|  }
  180|       |
  181|    314|  return true;
  182|    314|}
_ZN4bssl18tls_finish_messageEPK6ssl_stP6cbb_stPNS_5ArrayIhEE:
  184|     54|bool tls_finish_message(const SSL *ssl, CBB *cbb, Array<uint8_t> *out_msg) {
  185|     54|  return CBBFinishArray(cbb, out_msg);
  186|     54|}

_ZN4bssl10SSL3_STATEC2Ev:
  182|      1|      was_key_usage_invalid(false) {}
_ZN4bssl10SSL3_STATED2Ev:
  184|      1|SSL3_STATE::~SSL3_STATE() {}
_ZN4bssl7tls_newEP6ssl_st:
  186|      1|bool tls_new(SSL *ssl) {
  187|      1|  UniquePtr<SSL3_STATE> s3 = MakeUnique<SSL3_STATE>();
  188|      1|  if (!s3) {
  ------------------
  |  Branch (188:7): [True: 0, False: 1]
  ------------------
  189|      0|    return false;
  190|      0|  }
  191|       |
  192|      1|  s3->aead_read_ctx = SSLAEADContext::CreateNullCipher(SSL_is_dtls(ssl));
  193|      1|  s3->aead_write_ctx = SSLAEADContext::CreateNullCipher(SSL_is_dtls(ssl));
  194|      1|  s3->hs = ssl_handshake_new(ssl);
  195|      1|  if (!s3->aead_read_ctx || !s3->aead_write_ctx || !s3->hs) {
  ------------------
  |  Branch (195:7): [True: 0, False: 1]
  |  Branch (195:29): [True: 0, False: 1]
  |  Branch (195:52): [True: 0, False: 1]
  ------------------
  196|      0|    return false;
  197|      0|  }
  198|       |
  199|      1|  ssl->s3 = s3.release();
  200|       |
  201|       |  // Set the version to the highest supported version.
  202|       |  //
  203|       |  // TODO(davidben): Move this field into |s3|, have it store the normalized
  204|       |  // protocol version, and implement this pre-negotiation quirk in |SSL_version|
  205|       |  // at the API boundary rather than in internal state.
  206|      1|  ssl->version = TLS1_2_VERSION;
  ------------------
  |  |  647|      1|#define TLS1_2_VERSION 0x0303
  ------------------
  207|      1|  return true;
  208|      1|}
_ZN4bssl8tls_freeEP6ssl_st:
  210|      1|void tls_free(SSL *ssl) {
  211|      1|  if (ssl == NULL || ssl->s3 == NULL) {
  ------------------
  |  Branch (211:7): [True: 0, False: 1]
  |  Branch (211:22): [True: 0, False: 1]
  ------------------
  212|      0|    return;
  213|      0|  }
  214|       |
  215|      1|  Delete(ssl->s3);
  216|      1|  ssl->s3 = NULL;
  217|      1|}

_ZN4bssl14SSLAEADContextC2EtbPK13ssl_cipher_st:
   45|      2|      ad_is_header_(false) {
   46|      2|  OPENSSL_memset(fixed_nonce_, 0, sizeof(fixed_nonce_));
   47|      2|}
_ZN4bssl14SSLAEADContextD2Ev:
   49|      2|SSLAEADContext::~SSLAEADContext() {}
_ZN4bssl14SSLAEADContext16CreateNullCipherEb:
   51|      2|UniquePtr<SSLAEADContext> SSLAEADContext::CreateNullCipher(bool is_dtls) {
   52|      2|  return MakeUnique<SSLAEADContext>(0 /* version */, is_dtls,
   53|      2|                                    nullptr /* cipher */);
   54|      2|}

_ZN4bssl9SSLBuffer5ClearEv:
   39|      2|void SSLBuffer::Clear() {
   40|      2|  if (buf_allocated_) {
  ------------------
  |  Branch (40:7): [True: 0, False: 2]
  ------------------
   41|      0|    free(buf_);  // Allocated with malloc().
   42|      0|  }
   43|      2|  buf_ = nullptr;
   44|      2|  buf_allocated_ = false;
   45|      2|  offset_ = 0;
   46|      2|  size_ = 0;
   47|      2|  cap_ = 0;
   48|      2|}

_ZN4bssl4CERTC2EPKNS_15SSL_X509_METHODE:
  138|      2|    : x509_method(x509_method_arg) {}
_ZN4bssl4CERTD2Ev:
  140|      2|CERT::~CERT() {
  141|      2|  ssl_cert_clear_certs(this);
  142|      2|  x509_method->cert_free(this);
  143|      2|}
_ZN4bssl12ssl_cert_dupEPNS_4CERTE:
  150|      1|UniquePtr<CERT> ssl_cert_dup(CERT *cert) {
  151|      1|  UniquePtr<CERT> ret = MakeUnique<CERT>(cert->x509_method);
  152|      1|  if (!ret) {
  ------------------
  |  Branch (152:7): [True: 0, False: 1]
  ------------------
  153|      0|    return nullptr;
  154|      0|  }
  155|       |
  156|      1|  if (cert->chain) {
  ------------------
  |  Branch (156:7): [True: 0, False: 1]
  ------------------
  157|      0|    ret->chain.reset(sk_CRYPTO_BUFFER_deep_copy(
  158|      0|        cert->chain.get(), buffer_up_ref, CRYPTO_BUFFER_free));
  159|      0|    if (!ret->chain) {
  ------------------
  |  Branch (159:9): [True: 0, False: 0]
  ------------------
  160|      0|      return nullptr;
  161|      0|    }
  162|      0|  }
  163|       |
  164|      1|  ret->privatekey = UpRef(cert->privatekey);
  165|      1|  ret->key_method = cert->key_method;
  166|       |
  167|      1|  if (!ret->sigalgs.CopyFrom(cert->sigalgs)) {
  ------------------
  |  Branch (167:7): [True: 0, False: 1]
  ------------------
  168|      0|    return nullptr;
  169|      0|  }
  170|       |
  171|      1|  ret->cert_cb = cert->cert_cb;
  172|      1|  ret->cert_cb_arg = cert->cert_cb_arg;
  173|       |
  174|      1|  ret->x509_method->cert_dup(ret.get(), cert);
  175|       |
  176|      1|  ret->signed_cert_timestamp_list = UpRef(cert->signed_cert_timestamp_list);
  177|      1|  ret->ocsp_response = UpRef(cert->ocsp_response);
  178|       |
  179|      1|  ret->sid_ctx_length = cert->sid_ctx_length;
  180|      1|  OPENSSL_memcpy(ret->sid_ctx, cert->sid_ctx, sizeof(ret->sid_ctx));
  181|       |
  182|      1|  if (cert->dc) {
  ------------------
  |  Branch (182:7): [True: 0, False: 1]
  ------------------
  183|      0|    ret->dc = cert->dc->Dup();
  184|      0|    if (!ret->dc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 0]
  ------------------
  185|      0|       return nullptr;
  186|      0|    }
  187|      0|  }
  188|       |
  189|      1|  ret->dc_privatekey = UpRef(cert->dc_privatekey);
  190|      1|  ret->dc_key_method = cert->dc_key_method;
  191|       |
  192|      1|  return ret;
  193|      1|}
_ZN4bssl20ssl_cert_clear_certsEPNS_4CERTE:
  196|      2|void ssl_cert_clear_certs(CERT *cert) {
  197|      2|  if (cert == NULL) {
  ------------------
  |  Branch (197:7): [True: 0, False: 2]
  ------------------
  198|      0|    return;
  199|      0|  }
  200|       |
  201|      2|  cert->x509_method->cert_clear(cert);
  202|       |
  203|      2|  cert->chain.reset();
  204|      2|  cert->privatekey.reset();
  205|      2|  cert->key_method = nullptr;
  206|       |
  207|      2|  cert->dc.reset();
  208|      2|  cert->dc_privatekey.reset();
  209|      2|  cert->dc_key_method = nullptr;
  210|      2|}

_ZN4bssl23SSLCipherPreferenceListD2Ev:
  729|      1|SSLCipherPreferenceList::~SSLCipherPreferenceList() {
  730|      1|  OPENSSL_free(in_group_flags);
  731|      1|}
_ZN4bssl23SSLCipherPreferenceList4InitENSt3__110unique_ptrI19stack_st_SSL_CIPHERNS_8internal7DeleterEEENS_4SpanIKbEE:
  734|      1|                                   Span<const bool> in_group_flags_arg) {
  735|      1|  if (sk_SSL_CIPHER_num(ciphers_arg.get()) != in_group_flags_arg.size()) {
  ------------------
  |  Branch (735:7): [True: 0, False: 1]
  ------------------
  736|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  737|      0|    return false;
  738|      0|  }
  739|       |
  740|      1|  Array<bool> copy;
  741|      1|  if (!copy.CopyFrom(in_group_flags_arg)) {
  ------------------
  |  Branch (741:7): [True: 0, False: 1]
  ------------------
  742|      0|    return false;
  743|      0|  }
  744|      1|  ciphers = std::move(ciphers_arg);
  745|      1|  size_t unused_len;
  746|      1|  copy.Release(&in_group_flags, &unused_len);
  747|      1|  return true;
  748|      1|}
_ZN4bssl24ssl_cipher_is_deprecatedEPK13ssl_cipher_st:
  775|     21|bool ssl_cipher_is_deprecated(const SSL_CIPHER *cipher) {
  776|     21|  return cipher->id == TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ||
  ------------------
  |  |  411|     42|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0x0300C027
  ------------------
  |  Branch (776:10): [True: 1, False: 20]
  ------------------
  777|     21|         cipher->algorithm_enc == SSL_3DES;
  ------------------
  |  |  566|     20|#define SSL_3DES 0x00000001u
  ------------------
  |  Branch (777:10): [True: 1, False: 19]
  ------------------
  778|     21|}
_ZN4bssl22ssl_create_cipher_listEPNSt3__110unique_ptrINS_23SSLCipherPreferenceListENS_8internal7DeleterEEEbPKcb:
 1136|      1|                            bool strict) {
 1137|       |  // Return with error if nothing to do.
 1138|      1|  if (rule_str == NULL || out_cipher_list == NULL) {
  ------------------
  |  Branch (1138:7): [True: 0, False: 1]
  |  Branch (1138:27): [True: 0, False: 1]
  ------------------
 1139|      0|    return false;
 1140|      0|  }
 1141|       |
 1142|       |  // We prefer ECDHE ciphers over non-PFS ciphers. Then we prefer AEAD over
 1143|       |  // non-AEAD. The constants are masked by 0xffff to remove the vestigial 0x03
 1144|       |  // byte from SSL 2.0.
 1145|      1|  static const uint16_t kAESCiphers[] = {
 1146|      1|      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 & 0xffff,
  ------------------
  |  |  442|      1|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0x0300C02B
  ------------------
 1147|      1|      TLS1_CK_ECDHE_RSA_WITH_AES_128_GCM_SHA256 & 0xffff,
  ------------------
  |  |  446|      1|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0x0300C02F
  ------------------
 1148|      1|      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 & 0xffff,
  ------------------
  |  |  443|      1|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0x0300C02C
  ------------------
 1149|      1|      TLS1_CK_ECDHE_RSA_WITH_AES_256_GCM_SHA384 & 0xffff,
  ------------------
  |  |  447|      1|#define TLS1_CK_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0x0300C030
  ------------------
 1150|      1|  };
 1151|      1|  static const uint16_t kChaChaCiphers[] = {
 1152|      1|      TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 & 0xffff,
  ------------------
  |  |  453|      1|#define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 0x0300CCA9
  ------------------
 1153|      1|      TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 & 0xffff,
  ------------------
  |  |  452|      1|#define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 0x0300CCA8
  ------------------
 1154|      1|      TLS1_CK_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 & 0xffff,
  ------------------
  |  |  454|      1|#define TLS1_CK_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 0x0300CCAC
  ------------------
 1155|      1|  };
 1156|      1|  static const uint16_t kLegacyCiphers[] = {
 1157|      1|      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  396|      1|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_128_CBC_SHA 0x0300C009
  ------------------
 1158|      1|      TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  408|      1|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA 0x0300C013
  ------------------
 1159|      1|      TLS1_CK_ECDHE_PSK_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  299|      1|#define TLS1_CK_ECDHE_PSK_WITH_AES_128_CBC_SHA          0x0300C035
  ------------------
 1160|      1|      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  397|      1|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_256_CBC_SHA 0x0300C00A
  ------------------
 1161|      1|      TLS1_CK_ECDHE_RSA_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  409|      1|#define TLS1_CK_ECDHE_RSA_WITH_AES_256_CBC_SHA 0x0300C014
  ------------------
 1162|      1|      TLS1_CK_ECDHE_PSK_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  300|      1|#define TLS1_CK_ECDHE_PSK_WITH_AES_256_CBC_SHA          0x0300C036
  ------------------
 1163|      1|      TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 & 0xffff,
  ------------------
  |  |  411|      1|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0x0300C027
  ------------------
 1164|      1|      TLS1_CK_RSA_WITH_AES_128_GCM_SHA256 & 0xffff,
  ------------------
  |  |  373|      1|#define TLS1_CK_RSA_WITH_AES_128_GCM_SHA256 0x0300009C
  ------------------
 1165|      1|      TLS1_CK_RSA_WITH_AES_256_GCM_SHA384 & 0xffff,
  ------------------
  |  |  374|      1|#define TLS1_CK_RSA_WITH_AES_256_GCM_SHA384 0x0300009D
  ------------------
 1166|      1|      TLS1_CK_RSA_WITH_AES_128_SHA & 0xffff,
  ------------------
  |  |  317|      1|#define TLS1_CK_RSA_WITH_AES_128_SHA 0x0300002F
  ------------------
 1167|      1|      TLS1_CK_PSK_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  295|      1|#define TLS1_CK_PSK_WITH_AES_128_CBC_SHA                0x0300008C
  ------------------
 1168|      1|      TLS1_CK_RSA_WITH_AES_256_SHA & 0xffff,
  ------------------
  |  |  324|      1|#define TLS1_CK_RSA_WITH_AES_256_SHA 0x03000035
  ------------------
 1169|      1|      TLS1_CK_PSK_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  296|      1|#define TLS1_CK_PSK_WITH_AES_256_CBC_SHA                0x0300008D
  ------------------
 1170|      1|      SSL3_CK_RSA_DES_192_CBC3_SHA & 0xffff,
  ------------------
  |  |  145|      1|#define SSL3_CK_RSA_DES_192_CBC3_SHA 0x0300000A
  ------------------
 1171|      1|  };
 1172|       |
 1173|       |  // Set up a linked list of ciphers.
 1174|      1|  CIPHER_ORDER co_list[OPENSSL_ARRAY_SIZE(kAESCiphers) +
 1175|      1|                       OPENSSL_ARRAY_SIZE(kChaChaCiphers) +
 1176|      1|                       OPENSSL_ARRAY_SIZE(kLegacyCiphers)];
 1177|     22|  for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(co_list); i++) {
  ------------------
  |  |  221|     22|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1177:22): [True: 21, False: 1]
  ------------------
 1178|     21|    co_list[i].next =
 1179|     21|        i + 1 < OPENSSL_ARRAY_SIZE(co_list) ? &co_list[i + 1] : nullptr;
  ------------------
  |  |  221|     21|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1179:9): [True: 20, False: 1]
  ------------------
 1180|     21|    co_list[i].prev = i == 0 ? nullptr : &co_list[i - 1];
  ------------------
  |  Branch (1180:23): [True: 1, False: 20]
  ------------------
 1181|     21|    co_list[i].active = false;
 1182|     21|    co_list[i].in_group = false;
 1183|     21|  }
 1184|      1|  CIPHER_ORDER *head = &co_list[0];
 1185|      1|  CIPHER_ORDER *tail = &co_list[OPENSSL_ARRAY_SIZE(co_list) - 1];
  ------------------
  |  |  221|      1|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
 1186|       |
 1187|       |  // Order AES ciphers vs ChaCha ciphers based on whether we have AES hardware.
 1188|       |  //
 1189|       |  // TODO(crbug.com/boringssl/29): We should also set up equipreference groups
 1190|       |  // as a server.
 1191|      1|  size_t num = 0;
 1192|      1|  if (has_aes_hw) {
  ------------------
  |  Branch (1192:7): [True: 1, False: 0]
  ------------------
 1193|      4|    for (uint16_t id : kAESCiphers) {
  ------------------
  |  Branch (1193:22): [True: 4, False: 1]
  ------------------
 1194|      4|      co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1195|      4|      assert(co_list[num - 1].cipher != nullptr);
 1196|      4|    }
 1197|      1|  }
 1198|      3|  for (uint16_t id : kChaChaCiphers) {
  ------------------
  |  Branch (1198:20): [True: 3, False: 1]
  ------------------
 1199|      3|    co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1200|      3|    assert(co_list[num - 1].cipher != nullptr);
 1201|      3|  }
 1202|      1|  if (!has_aes_hw) {
  ------------------
  |  Branch (1202:7): [True: 0, False: 1]
  ------------------
 1203|      0|    for (uint16_t id : kAESCiphers) {
  ------------------
  |  Branch (1203:22): [True: 0, False: 0]
  ------------------
 1204|      0|      co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1205|      0|      assert(co_list[num - 1].cipher != nullptr);
 1206|      0|    }
 1207|      0|  }
 1208|     14|  for (uint16_t id : kLegacyCiphers) {
  ------------------
  |  Branch (1208:20): [True: 14, False: 1]
  ------------------
 1209|     14|    co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1210|     14|    assert(co_list[num - 1].cipher != nullptr);
 1211|     14|  }
 1212|      1|  assert(num == OPENSSL_ARRAY_SIZE(co_list));
 1213|      0|  static_assert(OPENSSL_ARRAY_SIZE(co_list) + NumTLS13Ciphers() ==
 1214|      1|                    OPENSSL_ARRAY_SIZE(kCiphers),
 1215|      1|                "Not all ciphers are included in the cipher order");
 1216|       |
 1217|       |  // If the rule_string begins with DEFAULT, apply the default rule before
 1218|       |  // using the (possibly available) additional rules.
 1219|      1|  const char *rule_p = rule_str;
 1220|      1|  if (strncmp(rule_str, "DEFAULT", 7) == 0) {
  ------------------
  |  Branch (1220:7): [True: 0, False: 1]
  ------------------
 1221|      0|    if (!ssl_cipher_process_rulestr(SSL_DEFAULT_CIPHER_LIST, &head, &tail,
  ------------------
  |  | 1541|      0|#define SSL_DEFAULT_CIPHER_LIST "ALL"
  ------------------
  |  Branch (1221:9): [True: 0, False: 0]
  ------------------
 1222|      0|                                    strict)) {
 1223|      0|      return false;
 1224|      0|    }
 1225|      0|    rule_p += 7;
 1226|      0|    if (*rule_p == ':') {
  ------------------
  |  Branch (1226:9): [True: 0, False: 0]
  ------------------
 1227|      0|      rule_p++;
 1228|      0|    }
 1229|      0|  }
 1230|       |
 1231|      1|  if (*rule_p != '\0' &&
  ------------------
  |  Branch (1231:7): [True: 1, False: 0]
  ------------------
 1232|      1|      !ssl_cipher_process_rulestr(rule_p, &head, &tail, strict)) {
  ------------------
  |  Branch (1232:7): [True: 0, False: 1]
  ------------------
 1233|      0|    return false;
 1234|      0|  }
 1235|       |
 1236|       |  // Allocate new "cipherstack" for the result, return with error
 1237|       |  // if we cannot get one.
 1238|      1|  UniquePtr<STACK_OF(SSL_CIPHER)> cipherstack(sk_SSL_CIPHER_new_null());
 1239|      1|  Array<bool> in_group_flags;
 1240|      1|  if (cipherstack == nullptr ||
  ------------------
  |  Branch (1240:7): [True: 0, False: 1]
  ------------------
 1241|      1|      !in_group_flags.Init(OPENSSL_ARRAY_SIZE(kCiphers))) {
  ------------------
  |  |  221|      1|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1241:7): [True: 0, False: 1]
  ------------------
 1242|      0|    return false;
 1243|      0|  }
 1244|       |
 1245|       |  // The cipher selection for the list is done. The ciphers are added
 1246|       |  // to the resulting precedence to the STACK_OF(SSL_CIPHER).
 1247|      1|  size_t num_in_group_flags = 0;
 1248|     22|  for (CIPHER_ORDER *curr = head; curr != NULL; curr = curr->next) {
  ------------------
  |  Branch (1248:35): [True: 21, False: 1]
  ------------------
 1249|     21|    if (curr->active) {
  ------------------
  |  Branch (1249:9): [True: 19, False: 2]
  ------------------
 1250|     19|      if (!sk_SSL_CIPHER_push(cipherstack.get(), curr->cipher)) {
  ------------------
  |  Branch (1250:11): [True: 0, False: 19]
  ------------------
 1251|      0|        return false;
 1252|      0|      }
 1253|     19|      in_group_flags[num_in_group_flags++] = curr->in_group;
 1254|     19|    }
 1255|     21|  }
 1256|       |
 1257|      1|  UniquePtr<SSLCipherPreferenceList> pref_list =
 1258|      1|      MakeUnique<SSLCipherPreferenceList>();
 1259|      1|  if (!pref_list ||
  ------------------
  |  Branch (1259:7): [True: 0, False: 1]
  |  Branch (1259:7): [True: 0, False: 1]
  ------------------
 1260|      1|      !pref_list->Init(
  ------------------
  |  Branch (1260:7): [True: 0, False: 1]
  ------------------
 1261|      1|          std::move(cipherstack),
 1262|      1|          MakeConstSpan(in_group_flags).subspan(0, num_in_group_flags))) {
 1263|      0|    return false;
 1264|      0|  }
 1265|       |
 1266|      1|  *out_cipher_list = std::move(pref_list);
 1267|       |
 1268|       |  // Configuring an empty cipher list is an error but still updates the
 1269|       |  // output.
 1270|      1|  if (sk_SSL_CIPHER_num((*out_cipher_list)->ciphers.get()) == 0) {
  ------------------
  |  Branch (1270:7): [True: 0, False: 1]
  ------------------
 1271|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_NO_CIPHER_MATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1272|      0|    return false;
 1273|      0|  }
 1274|       |
 1275|      1|  return true;
 1276|      1|}
SSL_get_cipher_by_value:
 1355|     21|const SSL_CIPHER *SSL_get_cipher_by_value(uint16_t value) {
 1356|     21|  SSL_CIPHER c;
 1357|       |
 1358|     21|  c.id = 0x03000000L | value;
 1359|     21|  return reinterpret_cast<const SSL_CIPHER *>(bsearch(
 1360|     21|      &c, kCiphers, OPENSSL_ARRAY_SIZE(kCiphers), sizeof(SSL_CIPHER),
  ------------------
  |  |  221|     21|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
 1361|     21|      ssl_cipher_id_cmp_void));
 1362|     21|}
ssl_cipher.cc:_ZN4bsslL26ssl_cipher_process_rulestrEPKcPPNS_15cipher_order_stES4_b:
  953|      1|                                       CIPHER_ORDER **tail_p, bool strict) {
  954|      1|  const char *l, *buf;
  955|      1|  bool in_group = false, has_group = false;
  956|      1|  size_t j, buf_len;
  957|      1|  char ch;
  958|       |
  959|      1|  l = rule_str;
  960|      2|  for (;;) {
  961|      2|    ch = *l;
  962|       |
  963|      2|    if (ch == '\0') {
  ------------------
  |  Branch (963:9): [True: 1, False: 1]
  ------------------
  964|      1|      break;  // done
  965|      1|    }
  966|       |
  967|      1|    int rule;
  968|      1|    if (in_group) {
  ------------------
  |  Branch (968:9): [True: 0, False: 1]
  ------------------
  969|      0|      if (ch == ']') {
  ------------------
  |  Branch (969:11): [True: 0, False: 0]
  ------------------
  970|      0|        if (*tail_p) {
  ------------------
  |  Branch (970:13): [True: 0, False: 0]
  ------------------
  971|      0|          (*tail_p)->in_group = false;
  972|      0|        }
  973|      0|        in_group = false;
  974|      0|        l++;
  975|      0|        continue;
  976|      0|      }
  977|       |
  978|      0|      if (ch == '|') {
  ------------------
  |  Branch (978:11): [True: 0, False: 0]
  ------------------
  979|      0|        rule = CIPHER_ADD;
  ------------------
  |  |  480|      0|#define CIPHER_ADD 1
  ------------------
  980|      0|        l++;
  981|      0|        continue;
  982|      0|      } else if (!OPENSSL_isalnum(ch)) {
  ------------------
  |  Branch (982:18): [True: 0, False: 0]
  ------------------
  983|      0|        OPENSSL_PUT_ERROR(SSL, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  984|      0|        return false;
  985|      0|      } else {
  986|      0|        rule = CIPHER_ADD;
  ------------------
  |  |  480|      0|#define CIPHER_ADD 1
  ------------------
  987|      0|      }
  988|      1|    } else if (ch == '-') {
  ------------------
  |  Branch (988:16): [True: 0, False: 1]
  ------------------
  989|      0|      rule = CIPHER_DEL;
  ------------------
  |  |  482|      0|#define CIPHER_DEL 3
  ------------------
  990|      0|      l++;
  991|      1|    } else if (ch == '+') {
  ------------------
  |  Branch (991:16): [True: 0, False: 1]
  ------------------
  992|      0|      rule = CIPHER_ORD;
  ------------------
  |  |  483|      0|#define CIPHER_ORD 4
  ------------------
  993|      0|      l++;
  994|      1|    } else if (ch == '!') {
  ------------------
  |  Branch (994:16): [True: 0, False: 1]
  ------------------
  995|      0|      rule = CIPHER_KILL;
  ------------------
  |  |  481|      0|#define CIPHER_KILL 2
  ------------------
  996|      0|      l++;
  997|      1|    } else if (ch == '@') {
  ------------------
  |  Branch (997:16): [True: 0, False: 1]
  ------------------
  998|      0|      rule = CIPHER_SPECIAL;
  ------------------
  |  |  484|      0|#define CIPHER_SPECIAL 5
  ------------------
  999|      0|      l++;
 1000|      1|    } else if (ch == '[') {
  ------------------
  |  Branch (1000:16): [True: 0, False: 1]
  ------------------
 1001|      0|      assert(!in_group);
 1002|      0|      in_group = true;
 1003|      0|      has_group = true;
 1004|      0|      l++;
 1005|      0|      continue;
 1006|      1|    } else {
 1007|      1|      rule = CIPHER_ADD;
  ------------------
  |  |  480|      1|#define CIPHER_ADD 1
  ------------------
 1008|      1|    }
 1009|       |
 1010|       |    // If preference groups are enabled, the only legal operator is +.
 1011|       |    // Otherwise the in_group bits will get mixed up.
 1012|      1|    if (has_group && rule != CIPHER_ADD) {
  ------------------
  |  |  480|      0|#define CIPHER_ADD 1
  ------------------
  |  Branch (1012:9): [True: 0, False: 1]
  |  Branch (1012:22): [True: 0, False: 0]
  ------------------
 1013|      0|      OPENSSL_PUT_ERROR(SSL, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1014|      0|      return false;
 1015|      0|    }
 1016|       |
 1017|      1|    if (is_cipher_list_separator(ch, strict)) {
  ------------------
  |  Branch (1017:9): [True: 0, False: 1]
  ------------------
 1018|      0|      l++;
 1019|      0|      continue;
 1020|      0|    }
 1021|       |
 1022|      1|    bool multi = false;
 1023|      1|    uint32_t cipher_id = 0;
 1024|      1|    CIPHER_ALIAS alias;
 1025|      1|    bool skip_rule = false;
 1026|       |
 1027|       |    // When adding, exclude deprecated ciphers by default.
 1028|      1|    alias.include_deprecated = rule != CIPHER_ADD;
  ------------------
  |  |  480|      1|#define CIPHER_ADD 1
  ------------------
 1029|       |
 1030|      1|    for (;;) {
 1031|      1|      ch = *l;
 1032|      1|      buf = l;
 1033|      1|      buf_len = 0;
 1034|      4|      while (OPENSSL_isalnum(ch) || ch == '-' || ch == '.' || ch == '_') {
  ------------------
  |  Branch (1034:14): [True: 3, False: 1]
  |  Branch (1034:37): [True: 0, False: 1]
  |  Branch (1034:50): [True: 0, False: 1]
  |  Branch (1034:63): [True: 0, False: 1]
  ------------------
 1035|      3|        ch = *(++l);
 1036|      3|        buf_len++;
 1037|      3|      }
 1038|       |
 1039|      1|      if (buf_len == 0) {
  ------------------
  |  Branch (1039:11): [True: 0, False: 1]
  ------------------
 1040|       |        // We hit something we cannot deal with, it is no command or separator
 1041|       |        // nor alphanumeric, so we call this an error.
 1042|      0|        OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1043|      0|        return false;
 1044|      0|      }
 1045|       |
 1046|      1|      if (rule == CIPHER_SPECIAL) {
  ------------------
  |  |  484|      1|#define CIPHER_SPECIAL 5
  ------------------
  |  Branch (1046:11): [True: 0, False: 1]
  ------------------
 1047|      0|        break;
 1048|      0|      }
 1049|       |
 1050|       |      // Look for a matching exact cipher. These aren't allowed in multipart
 1051|       |      // rules.
 1052|      1|      if (!multi && ch != '+') {
  ------------------
  |  Branch (1052:11): [True: 1, False: 0]
  |  Branch (1052:21): [True: 1, False: 0]
  ------------------
 1053|     25|        for (j = 0; j < OPENSSL_ARRAY_SIZE(kCiphers); j++) {
  ------------------
  |  |  221|     25|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1053:21): [True: 24, False: 1]
  ------------------
 1054|     24|          const SSL_CIPHER *cipher = &kCiphers[j];
 1055|     24|          if (rule_equals(cipher->name, buf, buf_len) ||
  ------------------
  |  Branch (1055:15): [True: 0, False: 24]
  ------------------
 1056|     24|              rule_equals(cipher->standard_name, buf, buf_len)) {
  ------------------
  |  Branch (1056:15): [True: 0, False: 24]
  ------------------
 1057|      0|            cipher_id = cipher->id;
 1058|      0|            break;
 1059|      0|          }
 1060|     24|        }
 1061|      1|      }
 1062|      1|      if (cipher_id == 0) {
  ------------------
  |  Branch (1062:11): [True: 1, False: 0]
  ------------------
 1063|       |        // If not an exact cipher, look for a matching cipher alias.
 1064|      1|        for (j = 0; j < kCipherAliasesLen; j++) {
  ------------------
  |  Branch (1064:21): [True: 1, False: 0]
  ------------------
 1065|      1|          if (rule_equals(kCipherAliases[j].name, buf, buf_len)) {
  ------------------
  |  Branch (1065:15): [True: 1, False: 0]
  ------------------
 1066|      1|            alias.algorithm_mkey &= kCipherAliases[j].algorithm_mkey;
 1067|      1|            alias.algorithm_auth &= kCipherAliases[j].algorithm_auth;
 1068|      1|            alias.algorithm_enc &= kCipherAliases[j].algorithm_enc;
 1069|      1|            alias.algorithm_mac &= kCipherAliases[j].algorithm_mac;
 1070|       |
 1071|       |            // When specifying a combination of aliases, if any aliases
 1072|       |            // enables deprecated ciphers, deprecated ciphers are included. This
 1073|       |            // is slightly different from the bitmasks in that adding aliases
 1074|       |            // can increase the set of matched ciphers. This is so that an alias
 1075|       |            // like "RSA" will only specifiy AES-based RSA ciphers, but
 1076|       |            // "RSA+3DES" will still specify 3DES.
 1077|      1|            alias.include_deprecated |= kCipherAliases[j].include_deprecated;
 1078|       |
 1079|      1|            if (alias.min_version != 0 &&
  ------------------
  |  Branch (1079:17): [True: 0, False: 1]
  ------------------
 1080|      1|                alias.min_version != kCipherAliases[j].min_version) {
  ------------------
  |  Branch (1080:17): [True: 0, False: 0]
  ------------------
 1081|      0|              skip_rule = true;
 1082|      1|            } else {
 1083|      1|              alias.min_version = kCipherAliases[j].min_version;
 1084|      1|            }
 1085|      1|            break;
 1086|      1|          }
 1087|      1|        }
 1088|      1|        if (j == kCipherAliasesLen) {
  ------------------
  |  Branch (1088:13): [True: 0, False: 1]
  ------------------
 1089|      0|          skip_rule = true;
 1090|      0|          if (strict) {
  ------------------
  |  Branch (1090:15): [True: 0, False: 0]
  ------------------
 1091|      0|            OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1092|      0|            return false;
 1093|      0|          }
 1094|      0|        }
 1095|      1|      }
 1096|       |
 1097|       |      // Check for a multipart rule.
 1098|      1|      if (ch != '+') {
  ------------------
  |  Branch (1098:11): [True: 1, False: 0]
  ------------------
 1099|      1|        break;
 1100|      1|      }
 1101|      0|      l++;
 1102|      0|      multi = true;
 1103|      0|    }
 1104|       |
 1105|       |    // Ok, we have the rule, now apply it.
 1106|      1|    if (rule == CIPHER_SPECIAL) {
  ------------------
  |  |  484|      1|#define CIPHER_SPECIAL 5
  ------------------
  |  Branch (1106:9): [True: 0, False: 1]
  ------------------
 1107|      0|      if (buf_len != 8 || strncmp(buf, "STRENGTH", 8) != 0) {
  ------------------
  |  Branch (1107:11): [True: 0, False: 0]
  |  Branch (1107:27): [True: 0, False: 0]
  ------------------
 1108|      0|        OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1109|      0|        return false;
 1110|      0|      }
 1111|      0|      if (!ssl_cipher_strength_sort(head_p, tail_p)) {
  ------------------
  |  Branch (1111:11): [True: 0, False: 0]
  ------------------
 1112|      0|        return false;
 1113|      0|      }
 1114|       |
 1115|       |      // We do not support any "multi" options together with "@", so throw away
 1116|       |      // the rest of the command, if any left, until end or ':' is found.
 1117|      0|      while (*l != '\0' && !is_cipher_list_separator(*l, strict)) {
  ------------------
  |  Branch (1117:14): [True: 0, False: 0]
  |  Branch (1117:28): [True: 0, False: 0]
  ------------------
 1118|      0|        l++;
 1119|      0|      }
 1120|      1|    } else if (!skip_rule) {
  ------------------
  |  Branch (1120:16): [True: 1, False: 0]
  ------------------
 1121|      1|      ssl_cipher_apply_rule(cipher_id, &alias, rule, -1, in_group, head_p,
 1122|      1|                            tail_p);
 1123|      1|    }
 1124|      1|  }
 1125|       |
 1126|      1|  if (in_group) {
  ------------------
  |  Branch (1126:7): [True: 0, False: 1]
  ------------------
 1127|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1128|      0|    return false;
 1129|      0|  }
 1130|       |
 1131|      1|  return true;
 1132|      1|}
ssl_cipher.cc:_ZN4bsslL24is_cipher_list_separatorEcb:
  675|      1|static bool is_cipher_list_separator(char c, bool is_strict) {
  676|      1|  if (c == ':') {
  ------------------
  |  Branch (676:7): [True: 0, False: 1]
  ------------------
  677|      0|    return true;
  678|      0|  }
  679|      1|  return !is_strict && (c == ' ' || c == ';' || c == ',');
  ------------------
  |  Branch (679:10): [True: 0, False: 1]
  |  Branch (679:25): [True: 0, False: 0]
  |  Branch (679:37): [True: 0, False: 0]
  |  Branch (679:49): [True: 0, False: 0]
  ------------------
  680|      1|}
ssl_cipher.cc:_ZN4bsslL11rule_equalsEPKcS1_m:
  684|     49|static bool rule_equals(const char *rule, const char *buf, size_t buf_len) {
  685|       |  // |strncmp| alone only checks that |buf| is a prefix of |rule|.
  686|     49|  return strncmp(rule, buf, buf_len) == 0 && rule[buf_len] == '\0';
  ------------------
  |  Branch (686:10): [True: 1, False: 48]
  |  Branch (686:46): [True: 1, False: 0]
  ------------------
  687|     49|}
ssl_cipher.cc:_ZN4bsslL21ssl_cipher_apply_ruleEjPKNS_15cipher_alias_stEiibPPNS_15cipher_order_stES5_:
  792|      1|                                  CIPHER_ORDER **tail_p) {
  793|      1|  CIPHER_ORDER *head, *tail, *curr, *next, *last;
  794|      1|  const SSL_CIPHER *cp;
  795|      1|  bool reverse = false;
  796|       |
  797|      1|  if (cipher_id == 0 && strength_bits == -1 && alias->min_version == 0 &&
  ------------------
  |  Branch (797:7): [True: 1, False: 0]
  |  Branch (797:25): [True: 1, False: 0]
  |  Branch (797:48): [True: 1, False: 0]
  ------------------
  798|      1|      (alias->algorithm_mkey == 0 || alias->algorithm_auth == 0 ||
  ------------------
  |  Branch (798:8): [True: 0, False: 1]
  |  Branch (798:38): [True: 0, False: 1]
  ------------------
  799|      1|       alias->algorithm_enc == 0 || alias->algorithm_mac == 0)) {
  ------------------
  |  Branch (799:8): [True: 0, False: 1]
  |  Branch (799:37): [True: 0, False: 1]
  ------------------
  800|       |    // The rule matches nothing, so bail early.
  801|      0|    return;
  802|      0|  }
  803|       |
  804|      1|  if (rule == CIPHER_DEL) {
  ------------------
  |  |  482|      1|#define CIPHER_DEL 3
  ------------------
  |  Branch (804:7): [True: 0, False: 1]
  ------------------
  805|       |    // needed to maintain sorting between currently deleted ciphers
  806|      0|    reverse = true;
  807|      0|  }
  808|       |
  809|      1|  head = *head_p;
  810|      1|  tail = *tail_p;
  811|       |
  812|      1|  if (reverse) {
  ------------------
  |  Branch (812:7): [True: 0, False: 1]
  ------------------
  813|      0|    next = tail;
  814|      0|    last = head;
  815|      1|  } else {
  816|      1|    next = head;
  817|      1|    last = tail;
  818|      1|  }
  819|       |
  820|      1|  curr = NULL;
  821|     22|  for (;;) {
  822|     22|    if (curr == last) {
  ------------------
  |  Branch (822:9): [True: 1, False: 21]
  ------------------
  823|      1|      break;
  824|      1|    }
  825|       |
  826|     21|    curr = next;
  827|     21|    if (curr == NULL) {
  ------------------
  |  Branch (827:9): [True: 0, False: 21]
  ------------------
  828|      0|      break;
  829|      0|    }
  830|       |
  831|     21|    next = reverse ? curr->prev : curr->next;
  ------------------
  |  Branch (831:12): [True: 0, False: 21]
  ------------------
  832|     21|    cp = curr->cipher;
  833|       |
  834|       |    // Selection criteria is either a specific cipher, the value of
  835|       |    // |strength_bits|, or the algorithms used.
  836|     21|    if (cipher_id != 0) {
  ------------------
  |  Branch (836:9): [True: 0, False: 21]
  ------------------
  837|      0|      if (cipher_id != cp->id) {
  ------------------
  |  Branch (837:11): [True: 0, False: 0]
  ------------------
  838|      0|        continue;
  839|      0|      }
  840|     21|    } else if (strength_bits >= 0) {
  ------------------
  |  Branch (840:16): [True: 0, False: 21]
  ------------------
  841|      0|      if (strength_bits != SSL_CIPHER_get_bits(cp, NULL)) {
  ------------------
  |  Branch (841:11): [True: 0, False: 0]
  ------------------
  842|      0|        continue;
  843|      0|      }
  844|     21|    } else {
  845|     21|      if (!(alias->algorithm_mkey & cp->algorithm_mkey) ||
  ------------------
  |  Branch (845:11): [True: 0, False: 21]
  ------------------
  846|     21|          !(alias->algorithm_auth & cp->algorithm_auth) ||
  ------------------
  |  Branch (846:11): [True: 0, False: 21]
  ------------------
  847|     21|          !(alias->algorithm_enc & cp->algorithm_enc) ||
  ------------------
  |  Branch (847:11): [True: 0, False: 21]
  ------------------
  848|     21|          !(alias->algorithm_mac & cp->algorithm_mac) ||
  ------------------
  |  Branch (848:11): [True: 0, False: 21]
  ------------------
  849|     21|          (alias->min_version != 0 &&
  ------------------
  |  Branch (849:12): [True: 0, False: 21]
  ------------------
  850|     21|           SSL_CIPHER_get_min_version(cp) != alias->min_version) ||
  ------------------
  |  Branch (850:12): [True: 0, False: 0]
  ------------------
  851|     21|          (!alias->include_deprecated && ssl_cipher_is_deprecated(cp))) {
  ------------------
  |  Branch (851:12): [True: 21, False: 0]
  |  Branch (851:42): [True: 2, False: 19]
  ------------------
  852|      2|        continue;
  853|      2|      }
  854|     21|    }
  855|       |
  856|       |    // add the cipher if it has not been added yet.
  857|     19|    if (rule == CIPHER_ADD) {
  ------------------
  |  |  480|     19|#define CIPHER_ADD 1
  ------------------
  |  Branch (857:9): [True: 19, False: 0]
  ------------------
  858|       |      // reverse == false
  859|     19|      if (!curr->active) {
  ------------------
  |  Branch (859:11): [True: 19, False: 0]
  ------------------
  860|     19|        ll_append_tail(&head, curr, &tail);
  861|     19|        curr->active = true;
  862|     19|        curr->in_group = in_group;
  863|     19|      }
  864|     19|    }
  865|       |
  866|       |    // Move the added cipher to this location
  867|      0|    else if (rule == CIPHER_ORD) {
  ------------------
  |  |  483|      0|#define CIPHER_ORD 4
  ------------------
  |  Branch (867:14): [True: 0, False: 0]
  ------------------
  868|       |      // reverse == false
  869|      0|      if (curr->active) {
  ------------------
  |  Branch (869:11): [True: 0, False: 0]
  ------------------
  870|      0|        ll_append_tail(&head, curr, &tail);
  871|      0|        curr->in_group = false;
  872|      0|      }
  873|      0|    } else if (rule == CIPHER_DEL) {
  ------------------
  |  |  482|      0|#define CIPHER_DEL 3
  ------------------
  |  Branch (873:16): [True: 0, False: 0]
  ------------------
  874|       |      // reverse == true
  875|      0|      if (curr->active) {
  ------------------
  |  Branch (875:11): [True: 0, False: 0]
  ------------------
  876|       |        // most recently deleted ciphersuites get best positions
  877|       |        // for any future CIPHER_ADD (note that the CIPHER_DEL loop
  878|       |        // works in reverse to maintain the order)
  879|      0|        ll_append_head(&head, curr, &tail);
  880|      0|        curr->active = false;
  881|      0|        curr->in_group = false;
  882|      0|      }
  883|      0|    } else if (rule == CIPHER_KILL) {
  ------------------
  |  |  481|      0|#define CIPHER_KILL 2
  ------------------
  |  Branch (883:16): [True: 0, False: 0]
  ------------------
  884|       |      // reverse == false
  885|      0|      if (head == curr) {
  ------------------
  |  Branch (885:11): [True: 0, False: 0]
  ------------------
  886|      0|        head = curr->next;
  887|      0|      } else {
  888|      0|        curr->prev->next = curr->next;
  889|      0|      }
  890|       |
  891|      0|      if (tail == curr) {
  ------------------
  |  Branch (891:11): [True: 0, False: 0]
  ------------------
  892|      0|        tail = curr->prev;
  893|      0|      }
  894|      0|      curr->active = false;
  895|      0|      if (curr->next != NULL) {
  ------------------
  |  Branch (895:11): [True: 0, False: 0]
  ------------------
  896|      0|        curr->next->prev = curr->prev;
  897|      0|      }
  898|      0|      if (curr->prev != NULL) {
  ------------------
  |  Branch (898:11): [True: 0, False: 0]
  ------------------
  899|      0|        curr->prev->next = curr->next;
  900|      0|      }
  901|      0|      curr->next = NULL;
  902|      0|      curr->prev = NULL;
  903|      0|    }
  904|     19|  }
  905|       |
  906|      1|  *head_p = head;
  907|      1|  *tail_p = tail;
  908|      1|}
ssl_cipher.cc:_ZN4bsslL14ll_append_tailEPPNS_15cipher_order_stES1_S2_:
  690|     19|                           CIPHER_ORDER **tail) {
  691|     19|  if (curr == *tail) {
  ------------------
  |  Branch (691:7): [True: 0, False: 19]
  ------------------
  692|      0|    return;
  693|      0|  }
  694|     19|  if (curr == *head) {
  ------------------
  |  Branch (694:7): [True: 13, False: 6]
  ------------------
  695|     13|    *head = curr->next;
  696|     13|  }
  697|     19|  if (curr->prev != NULL) {
  ------------------
  |  Branch (697:7): [True: 6, False: 13]
  ------------------
  698|      6|    curr->prev->next = curr->next;
  699|      6|  }
  700|     19|  if (curr->next != NULL) {
  ------------------
  |  Branch (700:7): [True: 19, False: 0]
  ------------------
  701|     19|    curr->next->prev = curr->prev;
  702|     19|  }
  703|     19|  (*tail)->next = curr;
  704|     19|  curr->prev = *tail;
  705|     19|  curr->next = NULL;
  706|     19|  *tail = curr;
  707|     19|}
ssl_cipher.cc:_ZL22ssl_cipher_id_cmp_voidPKvS0_:
 1337|     82|static int ssl_cipher_id_cmp_void(const void *in_a, const void *in_b) {
 1338|     82|  return ssl_cipher_id_cmp(reinterpret_cast<const SSL_CIPHER *>(in_a),
 1339|     82|                           reinterpret_cast<const SSL_CIPHER *>(in_b));
 1340|     82|}
ssl_cipher.cc:_ZL17ssl_cipher_id_cmpPK13ssl_cipher_stS1_:
 1327|     82|                                       const SSL_CIPHER *b) {
 1328|     82|  if (a->id > b->id) {
  ------------------
  |  Branch (1328:7): [True: 27, False: 55]
  ------------------
 1329|     27|    return 1;
 1330|     27|  }
 1331|     55|  if (a->id < b->id) {
  ------------------
  |  Branch (1331:7): [True: 34, False: 21]
  ------------------
 1332|     34|    return -1;
 1333|     34|  }
 1334|     21|  return 0;
 1335|     55|}

_ZN4bssl14CBBFinishArrayEP6cbb_stPNS_5ArrayIhEE:
  197|     54|bool CBBFinishArray(CBB *cbb, Array<uint8_t> *out) {
  198|     54|  uint8_t *ptr;
  199|     54|  size_t len;
  200|     54|  if (!CBB_finish(cbb, &ptr, &len)) {
  ------------------
  |  Branch (200:7): [True: 0, False: 54]
  ------------------
  201|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  202|      0|    return false;
  203|      0|  }
  204|     54|  out->Reset(ptr, len);
  205|     54|  return true;
  206|     54|}
_ZN10ssl_ctx_stC2EPK13ssl_method_st:
  540|      1|      aes_hw_override_value(false) {
  541|      1|  CRYPTO_MUTEX_init(&lock);
  542|      1|  CRYPTO_new_ex_data(&ex_data);
  543|      1|}
_ZN10ssl_ctx_stD2Ev:
  545|      1|ssl_ctx_st::~ssl_ctx_st() {
  546|       |  // Free the internal session cache. Note that this calls the caller-supplied
  547|       |  // remove callback, so we must do it before clearing ex_data. (See ticket
  548|       |  // [openssl.org #212].)
  549|      1|  SSL_CTX_flush_sessions(this, 0);
  550|       |
  551|      1|  CRYPTO_free_ex_data(&g_ex_data_class_ssl_ctx, this, &ex_data);
  552|       |
  553|      1|  CRYPTO_MUTEX_cleanup(&lock);
  554|      1|  lh_SSL_SESSION_free(sessions);
  555|      1|  x509_method->ssl_ctx_free(this);
  556|      1|}
SSL_CTX_new:
  558|      1|SSL_CTX *SSL_CTX_new(const SSL_METHOD *method) {
  559|      1|  if (method == NULL) {
  ------------------
  |  Branch (559:7): [True: 0, False: 1]
  ------------------
  560|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_NULL_SSL_METHOD_PASSED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  561|      0|    return nullptr;
  562|      0|  }
  563|       |
  564|      1|  UniquePtr<SSL_CTX> ret = MakeUnique<SSL_CTX>(method);
  565|      1|  if (!ret) {
  ------------------
  |  Branch (565:7): [True: 0, False: 1]
  ------------------
  566|      0|    return nullptr;
  567|      0|  }
  568|       |
  569|      1|  ret->cert = MakeUnique<CERT>(method->x509_method);
  570|      1|  ret->sessions = lh_SSL_SESSION_new(ssl_session_hash, ssl_session_cmp);
  571|      1|  ret->client_CA.reset(sk_CRYPTO_BUFFER_new_null());
  572|      1|  if (ret->cert == nullptr ||
  ------------------
  |  Branch (572:7): [True: 0, False: 1]
  ------------------
  573|      1|      ret->sessions == nullptr ||
  ------------------
  |  Branch (573:7): [True: 0, False: 1]
  ------------------
  574|      1|      ret->client_CA == nullptr ||
  ------------------
  |  Branch (574:7): [True: 0, False: 1]
  ------------------
  575|      1|      !ret->x509_method->ssl_ctx_new(ret.get())) {
  ------------------
  |  Branch (575:7): [True: 0, False: 1]
  ------------------
  576|      0|    return nullptr;
  577|      0|  }
  578|       |
  579|      1|  if (!SSL_CTX_set_strict_cipher_list(ret.get(), SSL_DEFAULT_CIPHER_LIST) ||
  ------------------
  |  | 1541|      1|#define SSL_DEFAULT_CIPHER_LIST "ALL"
  ------------------
  |  Branch (579:7): [True: 0, False: 1]
  ------------------
  580|       |      // Lock the SSL_CTX to the specified version, for compatibility with
  581|       |      // legacy uses of SSL_METHOD.
  582|      1|      !SSL_CTX_set_max_proto_version(ret.get(), method->version) ||
  ------------------
  |  Branch (582:7): [True: 0, False: 1]
  ------------------
  583|      1|      !SSL_CTX_set_min_proto_version(ret.get(), method->version)) {
  ------------------
  |  Branch (583:7): [True: 0, False: 1]
  ------------------
  584|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  585|      0|    return nullptr;
  586|      0|  }
  587|       |
  588|      1|  return ret.release();
  589|      1|}
SSL_CTX_up_ref:
  591|      2|int SSL_CTX_up_ref(SSL_CTX *ctx) {
  592|      2|  CRYPTO_refcount_inc(&ctx->references);
  593|      2|  return 1;
  594|      2|}
SSL_CTX_free:
  596|      3|void SSL_CTX_free(SSL_CTX *ctx) {
  597|      3|  if (ctx == NULL ||
  ------------------
  |  Branch (597:7): [True: 0, False: 3]
  ------------------
  598|      3|      !CRYPTO_refcount_dec_and_test_zero(&ctx->references)) {
  ------------------
  |  Branch (598:7): [True: 2, False: 1]
  ------------------
  599|      2|    return;
  600|      2|  }
  601|       |
  602|      1|  ctx->~ssl_ctx_st();
  603|      1|  OPENSSL_free(ctx);
  604|      1|}
_ZN6ssl_stC2EP10ssl_ctx_st:
  618|      1|      enable_early_data(ctx->enable_early_data) {
  619|      1|  CRYPTO_new_ex_data(&ex_data);
  620|      1|}
_ZN6ssl_stD2Ev:
  622|      1|ssl_st::~ssl_st() {
  623|      1|  CRYPTO_free_ex_data(&g_ex_data_class_ssl, this, &ex_data);
  624|       |  // |config| refers to |this|, so we must release it earlier.
  625|      1|  config.reset();
  626|      1|  if (method != NULL) {
  ------------------
  |  Branch (626:7): [True: 1, False: 0]
  ------------------
  627|      1|    method->ssl_free(this);
  628|      1|  }
  629|      1|}
SSL_new:
  631|      1|SSL *SSL_new(SSL_CTX *ctx) {
  632|      1|  if (ctx == nullptr) {
  ------------------
  |  Branch (632:7): [True: 0, False: 1]
  ------------------
  633|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_NULL_SSL_CTX);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  634|      0|    return nullptr;
  635|      0|  }
  636|       |
  637|      1|  UniquePtr<SSL> ssl = MakeUnique<SSL>(ctx);
  638|      1|  if (ssl == nullptr) {
  ------------------
  |  Branch (638:7): [True: 0, False: 1]
  ------------------
  639|      0|    return nullptr;
  640|      0|  }
  641|       |
  642|      1|  ssl->config = MakeUnique<SSL_CONFIG>(ssl.get());
  643|      1|  if (ssl->config == nullptr) {
  ------------------
  |  Branch (643:7): [True: 0, False: 1]
  ------------------
  644|      0|    return nullptr;
  645|      0|  }
  646|      1|  ssl->config->conf_min_version = ctx->conf_min_version;
  647|      1|  ssl->config->conf_max_version = ctx->conf_max_version;
  648|       |
  649|      1|  ssl->config->cert = ssl_cert_dup(ctx->cert.get());
  650|      1|  if (ssl->config->cert == nullptr) {
  ------------------
  |  Branch (650:7): [True: 0, False: 1]
  ------------------
  651|      0|    return nullptr;
  652|      0|  }
  653|       |
  654|      1|  ssl->config->verify_mode = ctx->verify_mode;
  655|      1|  ssl->config->verify_callback = ctx->default_verify_callback;
  656|      1|  ssl->config->custom_verify_callback = ctx->custom_verify_callback;
  657|      1|  ssl->config->retain_only_sha256_of_client_certs =
  658|      1|      ctx->retain_only_sha256_of_client_certs;
  659|      1|  ssl->config->permute_extensions = ctx->permute_extensions;
  660|      1|  ssl->config->aes_hw_override = ctx->aes_hw_override;
  661|      1|  ssl->config->aes_hw_override_value = ctx->aes_hw_override_value;
  662|      1|  ssl->config->tls13_cipher_policy = ctx->tls13_cipher_policy;
  663|       |
  664|      1|  if (!ssl->config->supported_group_list.CopyFrom(ctx->supported_group_list) ||
  ------------------
  |  Branch (664:7): [True: 0, False: 1]
  |  Branch (664:7): [True: 0, False: 1]
  ------------------
  665|      1|      !ssl->config->alpn_client_proto_list.CopyFrom(
  ------------------
  |  Branch (665:7): [True: 0, False: 1]
  ------------------
  666|      1|          ctx->alpn_client_proto_list) ||
  667|      1|      !ssl->config->verify_sigalgs.CopyFrom(ctx->verify_sigalgs)) {
  ------------------
  |  Branch (667:7): [True: 0, False: 1]
  ------------------
  668|      0|    return nullptr;
  669|      0|  }
  670|       |
  671|      1|  if (ctx->psk_identity_hint) {
  ------------------
  |  Branch (671:7): [True: 0, False: 1]
  ------------------
  672|      0|    ssl->config->psk_identity_hint.reset(
  673|      0|        OPENSSL_strdup(ctx->psk_identity_hint.get()));
  674|      0|    if (ssl->config->psk_identity_hint == nullptr) {
  ------------------
  |  Branch (674:9): [True: 0, False: 0]
  ------------------
  675|      0|      return nullptr;
  676|      0|    }
  677|      0|  }
  678|      1|  ssl->config->psk_client_callback = ctx->psk_client_callback;
  679|      1|  ssl->config->psk_server_callback = ctx->psk_server_callback;
  680|       |
  681|      1|  ssl->config->channel_id_enabled = ctx->channel_id_enabled;
  682|      1|  ssl->config->channel_id_private = UpRef(ctx->channel_id_private);
  683|       |
  684|      1|  ssl->config->signed_cert_timestamps_enabled =
  685|      1|      ctx->signed_cert_timestamps_enabled;
  686|      1|  ssl->config->ocsp_stapling_enabled = ctx->ocsp_stapling_enabled;
  687|      1|  ssl->config->handoff = ctx->handoff;
  688|      1|  ssl->quic_method = ctx->quic_method;
  689|       |
  690|      1|  if (!ssl->method->ssl_new(ssl.get()) ||
  ------------------
  |  Branch (690:7): [True: 0, False: 1]
  ------------------
  691|      1|      !ssl->ctx->x509_method->ssl_new(ssl->s3->hs.get())) {
  ------------------
  |  Branch (691:7): [True: 0, False: 1]
  ------------------
  692|      0|    return nullptr;
  693|      0|  }
  694|       |
  695|      1|  return ssl.release();
  696|      1|}
_ZN4bssl10SSL_CONFIGC2EP6ssl_st:
  710|      1|      permute_extensions(false) {
  711|      1|  assert(ssl);
  712|      1|}
_ZN4bssl10SSL_CONFIGD2Ev:
  714|      1|SSL_CONFIG::~SSL_CONFIG() {
  715|      1|  if (ssl->ctx != nullptr) {
  ------------------
  |  Branch (715:7): [True: 1, False: 0]
  ------------------
  716|      1|    ssl->ctx->x509_method->ssl_config_free(this);
  717|      1|  }
  718|      1|}
SSL_free:
  720|      1|void SSL_free(SSL *ssl) {
  721|      1|  Delete(ssl);
  722|      1|}
SSL_CTX_set_strict_cipher_list:
 2121|      1|int SSL_CTX_set_strict_cipher_list(SSL_CTX *ctx, const char *str) {
 2122|      1|  const bool has_aes_hw = ctx->aes_hw_override ? ctx->aes_hw_override_value
  ------------------
  |  Branch (2122:27): [True: 0, False: 1]
  ------------------
 2123|      1|                                               : EVP_has_aes_hardware();
 2124|      1|  return ssl_create_cipher_list(&ctx->cipher_list, has_aes_hw, str,
 2125|      1|                                true /* strict */);
 2126|      1|}
SSL_is_dtls:
 2883|  1.24k|int SSL_is_dtls(const SSL *ssl) { return ssl->method->is_dtls; }

SSL_CTX_flush_sessions:
 1298|      1|void SSL_CTX_flush_sessions(SSL_CTX *ctx, uint64_t time) {
 1299|      1|  TIMEOUT_PARAM tp;
 1300|       |
 1301|      1|  tp.ctx = ctx;
 1302|      1|  tp.cache = ctx->sessions;
 1303|      1|  if (tp.cache == NULL) {
  ------------------
  |  Branch (1303:7): [True: 0, False: 1]
  ------------------
 1304|      0|    return;
 1305|      0|  }
 1306|      1|  tp.time = time;
 1307|      1|  MutexWriteLock lock(&ctx->lock);
 1308|      1|  lh_SSL_SESSION_doall_arg(tp.cache, timeout_doall_arg, &tp);
 1309|      1|}

_ZN4bssl13SSLTranscriptC2Ev:
  147|      2|SSLTranscript::SSLTranscript() {}
_ZN4bssl13SSLTranscriptD2Ev:
  149|      2|SSLTranscript::~SSLTranscript() {}
_ZN4bssl13SSLTranscript4InitEv:
  151|      1|bool SSLTranscript::Init() {
  152|      1|  buffer_.reset(BUF_MEM_new());
  153|      1|  if (!buffer_) {
  ------------------
  |  Branch (153:7): [True: 0, False: 1]
  ------------------
  154|      0|    return false;
  155|      0|  }
  156|       |
  157|      1|  hash_.Reset();
  158|      1|  return true;
  159|      1|}

SSL_CTX_set_min_proto_version:
  337|      1|int SSL_CTX_set_min_proto_version(SSL_CTX *ctx, uint16_t version) {
  338|      1|  return set_min_version(ctx->method, &ctx->conf_min_version, version);
  339|      1|}
SSL_CTX_set_max_proto_version:
  341|      1|int SSL_CTX_set_max_proto_version(SSL_CTX *ctx, uint16_t version) {
  342|      1|  return set_max_version(ctx->method, &ctx->conf_max_version, version);
  343|      1|}
ssl_versions.cc:_ZN4bsslL15set_min_versionEPKNS_19SSL_PROTOCOL_METHODEPtt:
  142|      1|                            uint16_t version) {
  143|       |  // Zero is interpreted as the default minimum version.
  144|      1|  if (version == 0) {
  ------------------
  |  Branch (144:7): [True: 1, False: 0]
  ------------------
  145|      1|    *out = method->is_dtls ? DTLS1_VERSION : TLS1_VERSION;
  ------------------
  |  |  650|      0|#define DTLS1_VERSION 0xfeff
  ------------------
                  *out = method->is_dtls ? DTLS1_VERSION : TLS1_VERSION;
  ------------------
  |  |  645|      2|#define TLS1_VERSION 0x0301
  ------------------
  |  Branch (145:12): [True: 0, False: 1]
  ------------------
  146|      1|    return true;
  147|      1|  }
  148|       |
  149|      0|  return set_version_bound(method, out, version);
  150|      1|}
ssl_versions.cc:_ZN4bsslL15set_max_versionEPKNS_19SSL_PROTOCOL_METHODEPtt:
  153|      1|                            uint16_t version) {
  154|       |  // Zero is interpreted as the default maximum version.
  155|      1|  if (version == 0) {
  ------------------
  |  Branch (155:7): [True: 1, False: 0]
  ------------------
  156|      1|    *out = method->is_dtls ? DTLS1_2_VERSION : TLS1_3_VERSION;
  ------------------
  |  |  651|      0|#define DTLS1_2_VERSION 0xfefd
  ------------------
                  *out = method->is_dtls ? DTLS1_2_VERSION : TLS1_3_VERSION;
  ------------------
  |  |  648|      2|#define TLS1_3_VERSION 0x0304
  ------------------
  |  Branch (156:12): [True: 0, False: 1]
  ------------------
  157|      1|    return true;
  158|      1|  }
  159|       |
  160|      0|  return set_version_bound(method, out, version);
  161|      1|}

ssl_x509.cc:_ZN4bsslL26ssl_crypto_x509_cert_clearEPNS_4CERTE:
  262|      4|static void ssl_crypto_x509_cert_clear(CERT *cert) {
  263|      4|  ssl_crypto_x509_cert_flush_cached_leaf(cert);
  264|      4|  ssl_crypto_x509_cert_flush_cached_chain(cert);
  265|       |
  266|      4|  X509_free(cert->x509_stash);
  267|      4|  cert->x509_stash = nullptr;
  268|      4|}
ssl_x509.cc:_ZN4bsslL25ssl_crypto_x509_cert_freeEPNS_4CERTE:
  270|      2|static void ssl_crypto_x509_cert_free(CERT *cert) {
  271|      2|  ssl_crypto_x509_cert_clear(cert);
  272|      2|  X509_STORE_free(cert->verify_store);
  273|      2|}
ssl_x509.cc:_ZN4bsslL24ssl_crypto_x509_cert_dupEPNS_4CERTEPKS0_:
  275|      1|static void ssl_crypto_x509_cert_dup(CERT *new_cert, const CERT *cert) {
  276|      1|  if (cert->verify_store != nullptr) {
  ------------------
  |  Branch (276:7): [True: 0, False: 1]
  ------------------
  277|      0|    X509_STORE_up_ref(cert->verify_store);
  278|      0|    new_cert->verify_store = cert->verify_store;
  279|      0|  }
  280|      1|}
ssl_x509.cc:_ZN4bsslL39ssl_crypto_x509_cert_flush_cached_chainEPNS_4CERTE:
  242|      4|static void ssl_crypto_x509_cert_flush_cached_chain(CERT *cert) {
  243|      4|  sk_X509_pop_free(cert->x509_chain, X509_free);
  244|      4|  cert->x509_chain = nullptr;
  245|      4|}
ssl_x509.cc:_ZN4bsslL38ssl_crypto_x509_cert_flush_cached_leafEPNS_4CERTE:
  237|      4|static void ssl_crypto_x509_cert_flush_cached_leaf(CERT *cert) {
  238|      4|  X509_free(cert->x509_leaf);
  239|      4|  cert->x509_leaf = nullptr;
  240|      4|}
ssl_x509.cc:_ZN4bsslL40ssl_crypto_x509_hs_flush_cached_ca_namesEPNS_13SSL_HANDSHAKEE:
  422|      1|static void ssl_crypto_x509_hs_flush_cached_ca_names(SSL_HANDSHAKE *hs) {
  423|      1|  sk_X509_NAME_pop_free(hs->cached_x509_ca_names, X509_NAME_free);
  424|      1|  hs->cached_x509_ca_names = nullptr;
  425|      1|}
ssl_x509.cc:_ZN4bsslL23ssl_crypto_x509_ssl_newEPNS_13SSL_HANDSHAKEE:
  427|      1|static bool ssl_crypto_x509_ssl_new(SSL_HANDSHAKE *hs) {
  428|      1|  hs->config->param = X509_VERIFY_PARAM_new();
  429|      1|  if (hs->config->param == nullptr) {
  ------------------
  |  Branch (429:7): [True: 0, False: 1]
  ------------------
  430|      0|    return false;
  431|      0|  }
  432|      1|  X509_VERIFY_PARAM_inherit(hs->config->param, hs->ssl->ctx->param);
  433|      1|  return true;
  434|      1|}
ssl_x509.cc:_ZN4bsslL31ssl_crypto_x509_ssl_config_freeEPNS_10SSL_CONFIGE:
  441|      1|static void ssl_crypto_x509_ssl_config_free(SSL_CONFIG *cfg) {
  442|      1|  sk_X509_NAME_pop_free(cfg->cached_x509_client_CA, X509_NAME_free);
  443|      1|  cfg->cached_x509_client_CA = nullptr;
  444|      1|  X509_VERIFY_PARAM_free(cfg->param);
  445|      1|}
ssl_x509.cc:_ZN4bsslL27ssl_crypto_x509_ssl_ctx_newEP10ssl_ctx_st:
  495|      1|static bool ssl_crypto_x509_ssl_ctx_new(SSL_CTX *ctx) {
  496|      1|  ctx->cert_store = X509_STORE_new();
  497|      1|  ctx->param = X509_VERIFY_PARAM_new();
  498|      1|  return (ctx->cert_store != nullptr && ctx->param != nullptr);
  ------------------
  |  Branch (498:11): [True: 1, False: 0]
  |  Branch (498:41): [True: 1, False: 0]
  ------------------
  499|      1|}
ssl_x509.cc:_ZN4bsslL28ssl_crypto_x509_ssl_ctx_freeEP10ssl_ctx_st:
  501|      1|static void ssl_crypto_x509_ssl_ctx_free(SSL_CTX *ctx) {
  502|      1|  ssl_crypto_x509_ssl_ctx_flush_cached_client_CA(ctx);
  503|      1|  X509_VERIFY_PARAM_free(ctx->param);
  504|      1|  X509_STORE_free(ctx->cert_store);
  505|      1|}
ssl_x509.cc:_ZN4bsslL46ssl_crypto_x509_ssl_ctx_flush_cached_client_CAEP10ssl_ctx_st:
  490|      1|static void ssl_crypto_x509_ssl_ctx_flush_cached_client_CA(SSL_CTX *ctx) {
  491|      1|  sk_X509_NAME_pop_free(ctx->cached_x509_client_CA, X509_NAME_free);
  492|      1|  ctx->cached_x509_client_CA = nullptr;
  493|      1|}

TLS_method:
  228|      1|const SSL_METHOD *TLS_method(void) {
  229|      1|  static const SSL_METHOD kMethod = {
  230|      1|      0,
  231|      1|      &kTLSProtocolMethod,
  232|      1|      &ssl_crypto_x509_method,
  233|      1|  };
  234|      1|  return &kMethod;
  235|      1|}

