c2i_ASN1_BIT_STRING:
  140|    150|                                     const unsigned char **pp, long len) {
  141|    150|  ASN1_BIT_STRING *ret = NULL;
  142|    150|  const unsigned char *p;
  143|    150|  unsigned char *s;
  144|    150|  int padding;
  145|       |
  146|    150|  if (len < 1) {
  ------------------
  |  Branch (146:7): [True: 1, False: 149]
  ------------------
  147|      1|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_SHORT);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  148|      1|    goto err;
  149|      1|  }
  150|       |
  151|    149|  if (len > INT_MAX) {
  ------------------
  |  Branch (151:7): [True: 0, False: 149]
  ------------------
  152|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  153|      0|    goto err;
  154|      0|  }
  155|       |
  156|    149|  if ((a == NULL) || ((*a) == NULL)) {
  ------------------
  |  Branch (156:7): [True: 30, False: 119]
  |  Branch (156:22): [True: 16, False: 103]
  ------------------
  157|     46|    if ((ret = ASN1_BIT_STRING_new()) == NULL) {
  ------------------
  |  Branch (157:9): [True: 0, False: 46]
  ------------------
  158|      0|      return NULL;
  159|      0|    }
  160|    103|  } else {
  161|    103|    ret = (*a);
  162|    103|  }
  163|       |
  164|    149|  p = *pp;
  165|    149|  padding = *(p++);
  166|    149|  len--;
  167|    149|  if (padding > 7) {
  ------------------
  |  Branch (167:7): [True: 6, False: 143]
  ------------------
  168|      6|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BIT_STRING_BITS_LEFT);
  ------------------
  |  |  441|      6|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|      6|    goto err;
  170|      6|  }
  171|       |
  172|       |  // Unused bits in a BIT STRING must be zero.
  173|    143|  uint8_t padding_mask = (1 << padding) - 1;
  174|    143|  if (padding != 0 && (len < 1 || (p[len - 1] & padding_mask) != 0)) {
  ------------------
  |  Branch (174:7): [True: 15, False: 128]
  |  Branch (174:24): [True: 1, False: 14]
  |  Branch (174:35): [True: 4, False: 10]
  ------------------
  175|      5|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BIT_STRING_PADDING);
  ------------------
  |  |  441|      5|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  176|      5|    goto err;
  177|      5|  }
  178|       |
  179|       |  // We do this to preserve the settings.  If we modify the settings, via
  180|       |  // the _set_bit function, we will recalculate on output
  181|    138|  ret->flags &= ~(ASN1_STRING_FLAG_BITS_LEFT | 0x07);    // clear
  ------------------
  |  |  543|    138|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  182|    138|  ret->flags |= (ASN1_STRING_FLAG_BITS_LEFT | padding);  // set
  ------------------
  |  |  543|    138|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  183|       |
  184|    138|  if (len > 0) {
  ------------------
  |  Branch (184:7): [True: 137, False: 1]
  ------------------
  185|    137|    s = OPENSSL_memdup(p, len);
  186|    137|    if (s == NULL) {
  ------------------
  |  Branch (186:9): [True: 0, False: 137]
  ------------------
  187|      0|      goto err;
  188|      0|    }
  189|    137|    p += len;
  190|    137|  } else {
  191|      1|    s = NULL;
  192|      1|  }
  193|       |
  194|    138|  ret->length = (int)len;
  195|    138|  OPENSSL_free(ret->data);
  196|    138|  ret->data = s;
  197|    138|  ret->type = V_ASN1_BIT_STRING;
  ------------------
  |  |  127|    138|#define V_ASN1_BIT_STRING 3
  ------------------
  198|    138|  if (a != NULL) {
  ------------------
  |  Branch (198:7): [True: 109, False: 29]
  ------------------
  199|    109|    (*a) = ret;
  200|    109|  }
  201|    138|  *pp = p;
  202|    138|  return ret;
  203|     12|err:
  204|     12|  if ((ret != NULL) && ((a == NULL) || (*a != ret))) {
  ------------------
  |  Branch (204:7): [True: 11, False: 1]
  |  Branch (204:25): [True: 1, False: 10]
  |  Branch (204:40): [True: 7, False: 3]
  ------------------
  205|      8|    ASN1_BIT_STRING_free(ret);
  206|      8|  }
  207|     12|  return NULL;
  208|    138|}

i2c_ASN1_INTEGER:
  117|     40|int i2c_ASN1_INTEGER(const ASN1_INTEGER *in, unsigned char **outp) {
  118|     40|  if (in == NULL) {
  ------------------
  |  Branch (118:7): [True: 0, False: 40]
  ------------------
  119|      0|    return 0;
  120|      0|  }
  121|       |
  122|       |  // |ASN1_INTEGER|s should be represented minimally, but it is possible to
  123|       |  // construct invalid ones. Skip leading zeros so this does not produce an
  124|       |  // invalid encoding or break invariants.
  125|     40|  CBS cbs;
  126|     40|  CBS_init(&cbs, in->data, in->length);
  127|     40|  while (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0) {
  ------------------
  |  Branch (127:10): [True: 40, False: 0]
  |  Branch (127:31): [True: 0, False: 40]
  ------------------
  128|      0|    CBS_skip(&cbs, 1);
  129|      0|  }
  130|       |
  131|     40|  int is_negative = (in->type & V_ASN1_NEG) != 0;
  ------------------
  |  |  155|     40|#define V_ASN1_NEG 0x100
  ------------------
  132|     40|  size_t pad;
  133|     40|  CBS copy = cbs;
  134|     40|  uint8_t msb;
  135|     40|  if (!CBS_get_u8(&copy, &msb)) {
  ------------------
  |  Branch (135:7): [True: 0, False: 40]
  ------------------
  136|       |    // Zero is represented as a single byte.
  137|      0|    is_negative = 0;
  138|      0|    pad = 1;
  139|     40|  } else if (is_negative) {
  ------------------
  |  Branch (139:14): [True: 30, False: 10]
  ------------------
  140|       |    // 0x80...01 through 0xff...ff have a two's complement of 0x7f...ff
  141|       |    // through 0x00...01 and need an extra byte to be negative.
  142|       |    // 0x01...00 through 0x80...00 have a two's complement of 0xfe...ff
  143|       |    // through 0x80...00 and can be negated as-is.
  144|     30|    pad = msb > 0x80 ||
  ------------------
  |  Branch (144:11): [True: 0, False: 30]
  ------------------
  145|     30|          (msb == 0x80 && !is_all_zeros(CBS_data(&copy), CBS_len(&copy)));
  ------------------
  |  Branch (145:12): [True: 0, False: 30]
  |  Branch (145:27): [True: 0, False: 0]
  ------------------
  146|     30|  } else {
  147|       |    // If the high bit is set, the signed representation needs an extra
  148|       |    // byte to be positive.
  149|     10|    pad = (msb & 0x80) != 0;
  150|     10|  }
  151|       |
  152|     40|  if (CBS_len(&cbs) > INT_MAX - pad) {
  ------------------
  |  Branch (152:7): [True: 0, False: 40]
  ------------------
  153|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  154|      0|    return 0;
  155|      0|  }
  156|     40|  int len = (int)(pad + CBS_len(&cbs));
  157|     40|  assert(len > 0);
  158|     40|  if (outp == NULL) {
  ------------------
  |  Branch (158:7): [True: 32, False: 8]
  ------------------
  159|     32|    return len;
  160|     32|  }
  161|       |
  162|      8|  if (pad) {
  ------------------
  |  Branch (162:7): [True: 0, False: 8]
  ------------------
  163|      0|    (*outp)[0] = 0;
  164|      0|  }
  165|      8|  OPENSSL_memcpy(*outp + pad, CBS_data(&cbs), CBS_len(&cbs));
  166|      8|  if (is_negative) {
  ------------------
  |  Branch (166:7): [True: 6, False: 2]
  ------------------
  167|      6|    negate_twos_complement(*outp, len);
  168|      6|    assert((*outp)[0] >= 0x80);
  169|      6|  } else {
  170|      2|    assert((*outp)[0] < 0x80);
  171|      2|  }
  172|      8|  *outp += len;
  173|      8|  return len;
  174|      8|}
c2i_ASN1_INTEGER:
  177|  1.24k|                               long len) {
  178|       |  // This function can handle lengths up to INT_MAX - 1, but the rest of the
  179|       |  // legacy ASN.1 code mixes integer types, so avoid exposing it to
  180|       |  // ASN1_INTEGERS with larger lengths.
  181|  1.24k|  if (len < 0 || len > INT_MAX / 2) {
  ------------------
  |  Branch (181:7): [True: 0, False: 1.24k]
  |  Branch (181:18): [True: 0, False: 1.24k]
  ------------------
  182|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  183|      0|    return NULL;
  184|      0|  }
  185|       |
  186|  1.24k|  CBS cbs;
  187|  1.24k|  CBS_init(&cbs, *inp, (size_t)len);
  188|  1.24k|  int is_negative;
  189|  1.24k|  if (!CBS_is_valid_asn1_integer(&cbs, &is_negative)) {
  ------------------
  |  Branch (189:7): [True: 2, False: 1.23k]
  ------------------
  190|      2|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  191|      2|    return NULL;
  192|      2|  }
  193|       |
  194|  1.23k|  ASN1_INTEGER *ret = NULL;
  195|  1.23k|  if (out == NULL || *out == NULL) {
  ------------------
  |  Branch (195:7): [True: 0, False: 1.23k]
  |  Branch (195:22): [True: 626, False: 613]
  ------------------
  196|    626|    ret = ASN1_INTEGER_new();
  197|    626|    if (ret == NULL) {
  ------------------
  |  Branch (197:9): [True: 0, False: 626]
  ------------------
  198|      0|      return NULL;
  199|      0|    }
  200|    626|  } else {
  201|    613|    ret = *out;
  202|    613|  }
  203|       |
  204|       |  // Convert to |ASN1_INTEGER|'s sign-and-magnitude representation. First,
  205|       |  // determine the size needed for a minimal result.
  206|  1.23k|  if (is_negative) {
  ------------------
  |  Branch (206:7): [True: 244, False: 995]
  ------------------
  207|       |    // 0xff00...01 through 0xff7f..ff have a two's complement of 0x00ff...ff
  208|       |    // through 0x000100...001 and need one leading zero removed. 0x8000...00
  209|       |    // through 0xff00...00 have a two's complement of 0x8000...00 through
  210|       |    // 0x0100...00 and will be minimally-encoded as-is.
  211|    244|    if (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0xff &&
  ------------------
  |  Branch (211:9): [True: 244, False: 0]
  |  Branch (211:30): [True: 38, False: 206]
  ------------------
  212|    244|        !is_all_zeros(CBS_data(&cbs) + 1, CBS_len(&cbs) - 1)) {
  ------------------
  |  Branch (212:9): [True: 37, False: 1]
  ------------------
  213|     37|      CBS_skip(&cbs, 1);
  214|     37|    }
  215|    995|  } else {
  216|       |    // Remove the leading zero byte, if any.
  217|    995|    if (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0x00) {
  ------------------
  |  Branch (217:9): [True: 995, False: 0]
  |  Branch (217:30): [True: 109, False: 886]
  ------------------
  218|    109|      CBS_skip(&cbs, 1);
  219|    109|    }
  220|    995|  }
  221|       |
  222|  1.23k|  if (!ASN1_STRING_set(ret, CBS_data(&cbs), CBS_len(&cbs))) {
  ------------------
  |  Branch (222:7): [True: 0, False: 1.23k]
  ------------------
  223|      0|    goto err;
  224|      0|  }
  225|       |
  226|  1.23k|  if (is_negative) {
  ------------------
  |  Branch (226:7): [True: 244, False: 995]
  ------------------
  227|    244|    ret->type = V_ASN1_NEG_INTEGER;
  ------------------
  |  |  156|    244|#define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  126|    244|#define V_ASN1_INTEGER 2
  |  |  ------------------
  |  |               #define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|    244|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  228|    244|    negate_twos_complement(ret->data, ret->length);
  229|    995|  } else {
  230|    995|    ret->type = V_ASN1_INTEGER;
  ------------------
  |  |  126|    995|#define V_ASN1_INTEGER 2
  ------------------
  231|    995|  }
  232|       |
  233|       |  // The value should be minimally-encoded.
  234|  1.23k|  assert(ret->length == 0 || ret->data[0] != 0);
  235|       |  // Zero is not negative.
  236|  1.23k|  assert(!is_negative || ret->length > 0);
  237|       |
  238|  1.23k|  *inp += len;
  239|  1.23k|  if (out != NULL) {
  ------------------
  |  Branch (239:7): [True: 1.23k, False: 0]
  ------------------
  240|  1.23k|    *out = ret;
  241|  1.23k|  }
  242|  1.23k|  return ret;
  243|       |
  244|      0|err:
  245|      0|  if (ret != NULL && (out == NULL || *out != ret)) {
  ------------------
  |  Branch (245:7): [True: 0, False: 0]
  |  Branch (245:23): [True: 0, False: 0]
  |  Branch (245:38): [True: 0, False: 0]
  ------------------
  246|      0|    ASN1_INTEGER_free(ret);
  247|      0|  }
  248|      0|  return NULL;
  249|  1.23k|}
ASN1_INTEGER_get:
  395|     29|long ASN1_INTEGER_get(const ASN1_INTEGER *a) {
  396|     29|  return asn1_string_get_long(a, V_ASN1_INTEGER);
  ------------------
  |  |  126|     29|#define V_ASN1_INTEGER 2
  ------------------
  397|     29|}
a_int.c:is_all_zeros:
  108|     38|static int is_all_zeros(const uint8_t *in, size_t len) {
  109|     39|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (109:22): [True: 38, False: 1]
  ------------------
  110|     38|    if (in[i] != 0) {
  ------------------
  |  Branch (110:9): [True: 37, False: 1]
  ------------------
  111|     37|      return 0;
  112|     37|    }
  113|     38|  }
  114|      1|  return 1;
  115|     38|}
a_int.c:negate_twos_complement:
   99|    250|static void negate_twos_complement(uint8_t *buf, size_t len) {
  100|    250|  uint8_t borrow = 0;
  101|  2.79k|  for (size_t i = len - 1; i < len; i--) {
  ------------------
  |  Branch (101:28): [True: 2.54k, False: 250]
  ------------------
  102|  2.54k|    uint8_t t = buf[i];
  103|  2.54k|    buf[i] = 0u - borrow - t;
  104|  2.54k|    borrow |= t != 0;
  105|  2.54k|  }
  106|    250|}
a_int.c:asn1_string_get_abs_uint64:
  313|     29|                                      int type) {
  314|     29|  if ((a->type & ~V_ASN1_NEG) != type) {
  ------------------
  |  |  155|     29|#define V_ASN1_NEG 0x100
  ------------------
  |  Branch (314:7): [True: 0, False: 29]
  ------------------
  315|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_INTEGER_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  316|      0|    return 0;
  317|      0|  }
  318|     29|  uint8_t buf[sizeof(uint64_t)] = {0};
  319|     29|  if (a->length > (int)sizeof(buf)) {
  ------------------
  |  Branch (319:7): [True: 0, False: 29]
  ------------------
  320|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  321|      0|    return 0;
  322|      0|  }
  323|     29|  OPENSSL_memcpy(buf + sizeof(buf) - a->length, a->data, a->length);
  324|     29|  *out = CRYPTO_load_u64_be(buf);
  325|     29|  return 1;
  326|     29|}
a_int.c:asn1_string_get_int64:
  348|     29|static int asn1_string_get_int64(int64_t *out, const ASN1_STRING *a, int type) {
  349|     29|  uint64_t v;
  350|     29|  if (!asn1_string_get_abs_uint64(&v, a, type)) {
  ------------------
  |  Branch (350:7): [True: 0, False: 29]
  ------------------
  351|      0|    return 0;
  352|      0|  }
  353|     29|  int64_t i64;
  354|     29|  int fits_in_i64;
  355|       |  // Check |v != 0| to handle manually-constructed negative zeros.
  356|     29|  if ((a->type & V_ASN1_NEG) && v != 0) {
  ------------------
  |  |  155|     29|#define V_ASN1_NEG 0x100
  ------------------
  |  Branch (356:7): [True: 0, False: 29]
  |  Branch (356:33): [True: 0, False: 0]
  ------------------
  357|      0|    i64 = (int64_t)(0u - v);
  358|      0|    fits_in_i64 = i64 < 0;
  359|     29|  } else {
  360|     29|    i64 = (int64_t)v;
  361|     29|    fits_in_i64 = i64 >= 0;
  362|     29|  }
  363|     29|  if (!fits_in_i64) {
  ------------------
  |  Branch (363:7): [True: 0, False: 29]
  ------------------
  364|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  365|      0|    return 0;
  366|      0|  }
  367|     29|  *out = i64;
  368|     29|  return 1;
  369|     29|}
a_int.c:asn1_string_get_long:
  379|     29|static long asn1_string_get_long(const ASN1_STRING *a, int type) {
  380|     29|  if (a == NULL) {
  ------------------
  |  Branch (380:7): [True: 0, False: 29]
  ------------------
  381|      0|    return 0;
  382|      0|  }
  383|       |
  384|     29|  int64_t v;
  385|     29|  if (!asn1_string_get_int64(&v, a, type) ||  //
  ------------------
  |  Branch (385:7): [True: 0, False: 29]
  ------------------
  386|     29|      v < LONG_MIN || v > LONG_MAX) {
  ------------------
  |  Branch (386:7): [True: 0, False: 29]
  |  Branch (386:23): [True: 0, False: 29]
  ------------------
  387|       |    // This function's return value does not distinguish overflow from -1.
  388|      0|    ERR_clear_error();
  389|      0|    return -1;
  390|      0|  }
  391|       |
  392|     29|  return (long)v;
  393|     29|}

ASN1_mbstring_copy:
   77|  1.08k|                       ossl_ssize_t len, int inform, unsigned long mask) {
   78|  1.08k|  return ASN1_mbstring_ncopy(out, in, len, inform, mask, /*minsize=*/0,
   79|  1.08k|                             /*maxsize=*/0);
   80|  1.08k|}
ASN1_mbstring_ncopy:
   88|  1.08k|                        ossl_ssize_t minsize, ossl_ssize_t maxsize) {
   89|  1.08k|  if (len == -1) {
  ------------------
  |  Branch (89:7): [True: 0, False: 1.08k]
  ------------------
   90|      0|    len = strlen((const char *)in);
   91|      0|  }
   92|  1.08k|  if (!mask) {
  ------------------
  |  Branch (92:7): [True: 0, False: 1.08k]
  ------------------
   93|      0|    mask = DIRSTRING_TYPE;
  ------------------
  |  |  718|      0|  (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  161|      0|#define B_ASN1_PRINTABLESTRING 0x0002
  |  |  ------------------
  |  |                 (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  162|      0|#define B_ASN1_T61STRING 0x0004
  |  |  ------------------
  |  |                 (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  173|      0|#define B_ASN1_BMPSTRING 0x0800
  |  |  ------------------
  |  |  719|      0|   B_ASN1_UTF8STRING)
  |  |  ------------------
  |  |  |  |  175|      0|#define B_ASN1_UTF8STRING 0x2000
  |  |  ------------------
  ------------------
   94|      0|  }
   95|       |
   96|  1.08k|  int (*decode_func)(CBS *, uint32_t *);
   97|  1.08k|  int error;
   98|  1.08k|  switch (inform) {
   99|     45|    case MBSTRING_BMP:
  ------------------
  |  |  713|     45|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|     45|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (99:5): [True: 45, False: 1.04k]
  ------------------
  100|     45|      decode_func = cbs_get_ucs2_be;
  101|     45|      error = ASN1_R_INVALID_BMPSTRING;
  ------------------
  |  | 2009|     45|#define ASN1_R_INVALID_BMPSTRING 142
  ------------------
  102|     45|      break;
  103|       |
  104|      1|    case MBSTRING_UNIV:
  ------------------
  |  |  714|      1|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      1|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (104:5): [True: 1, False: 1.08k]
  ------------------
  105|      1|      decode_func = cbs_get_utf32_be;
  106|      1|      error = ASN1_R_INVALID_UNIVERSALSTRING;
  ------------------
  |  | 2016|      1|#define ASN1_R_INVALID_UNIVERSALSTRING 149
  ------------------
  107|      1|      break;
  108|       |
  109|    627|    case MBSTRING_UTF8:
  ------------------
  |  |  711|    627|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|    627|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (109:5): [True: 627, False: 458]
  ------------------
  110|    627|      decode_func = cbs_get_utf8;
  111|    627|      error = ASN1_R_INVALID_UTF8STRING;
  ------------------
  |  | 2017|    627|#define ASN1_R_INVALID_UTF8STRING 150
  ------------------
  112|    627|      break;
  113|       |
  114|    412|    case MBSTRING_ASC:
  ------------------
  |  |  712|    412|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|    412|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (114:5): [True: 412, False: 673]
  ------------------
  115|    412|      decode_func = cbs_get_latin1;
  116|    412|      error = ERR_R_INTERNAL_ERROR;  // Latin-1 inputs are never invalid.
  ------------------
  |  |  387|    412|#define ERR_R_INTERNAL_ERROR (4 | ERR_R_FATAL)
  |  |  ------------------
  |  |  |  |  383|    412|#define ERR_R_FATAL 64
  |  |  ------------------
  ------------------
  117|    412|      break;
  118|       |
  119|      0|    default:
  ------------------
  |  Branch (119:5): [True: 0, False: 1.08k]
  ------------------
  120|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNKNOWN_FORMAT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  121|      0|      return -1;
  122|  1.08k|  }
  123|       |
  124|       |  // Check |minsize| and |maxsize| and work out the minimal type, if any.
  125|  1.08k|  CBS cbs;
  126|  1.08k|  CBS_init(&cbs, in, len);
  127|  1.08k|  size_t utf8_len = 0, nchar = 0;
  128|  12.6k|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (128:10): [True: 11.5k, False: 1.08k]
  ------------------
  129|  11.5k|    uint32_t c;
  130|  11.5k|    if (!decode_func(&cbs, &c)) {
  ------------------
  |  Branch (130:9): [True: 0, False: 11.5k]
  ------------------
  131|      0|      OPENSSL_PUT_ERROR(ASN1, error);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|      0|      return -1;
  133|      0|    }
  134|  11.5k|    if (nchar == 0 && (inform == MBSTRING_BMP || inform == MBSTRING_UNIV) &&
  ------------------
  |  |  713|  2.16k|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|  1.08k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
                  if (nchar == 0 && (inform == MBSTRING_BMP || inform == MBSTRING_UNIV) &&
  ------------------
  |  |  714|  1.03k|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|  1.03k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (134:9): [True: 1.08k, False: 10.4k]
  |  Branch (134:24): [True: 45, False: 1.03k]
  |  Branch (134:50): [True: 0, False: 1.03k]
  ------------------
  135|  11.5k|        c == 0xfeff) {
  ------------------
  |  Branch (135:9): [True: 0, False: 45]
  ------------------
  136|       |      // Reject byte-order mark. We could drop it but that would mean
  137|       |      // adding ambiguity around whether a BOM was included or not when
  138|       |      // matching strings.
  139|       |      //
  140|       |      // For a little-endian UCS-2 string, the BOM will appear as 0xfffe
  141|       |      // and will be rejected as noncharacter, below.
  142|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  143|      0|      return -1;
  144|      0|    }
  145|       |
  146|       |    // Update which output formats are still possible.
  147|  11.5k|    if ((mask & B_ASN1_PRINTABLESTRING) && !asn1_is_printable(c)) {
  ------------------
  |  |  161|  11.5k|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  |  Branch (147:9): [True: 0, False: 11.5k]
  |  Branch (147:44): [True: 0, False: 0]
  ------------------
  148|      0|      mask &= ~B_ASN1_PRINTABLESTRING;
  ------------------
  |  |  161|      0|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  149|      0|    }
  150|  11.5k|    if ((mask & B_ASN1_IA5STRING) && (c > 127)) {
  ------------------
  |  |  165|  11.5k|#define B_ASN1_IA5STRING 0x0010
  ------------------
  |  Branch (150:9): [True: 0, False: 11.5k]
  |  Branch (150:38): [True: 0, False: 0]
  ------------------
  151|      0|      mask &= ~B_ASN1_IA5STRING;
  ------------------
  |  |  165|      0|#define B_ASN1_IA5STRING 0x0010
  ------------------
  152|      0|    }
  153|  11.5k|    if ((mask & B_ASN1_T61STRING) && (c > 0xff)) {
  ------------------
  |  |  162|  11.5k|#define B_ASN1_T61STRING 0x0004
  ------------------
  |  Branch (153:9): [True: 0, False: 11.5k]
  |  Branch (153:38): [True: 0, False: 0]
  ------------------
  154|      0|      mask &= ~B_ASN1_T61STRING;
  ------------------
  |  |  162|      0|#define B_ASN1_T61STRING 0x0004
  ------------------
  155|      0|    }
  156|  11.5k|    if ((mask & B_ASN1_BMPSTRING) && (c > 0xffff)) {
  ------------------
  |  |  173|  11.5k|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  |  Branch (156:9): [True: 0, False: 11.5k]
  |  Branch (156:38): [True: 0, False: 0]
  ------------------
  157|      0|      mask &= ~B_ASN1_BMPSTRING;
  ------------------
  |  |  173|      0|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  158|      0|    }
  159|  11.5k|    if (!mask) {
  ------------------
  |  Branch (159:9): [True: 0, False: 11.5k]
  ------------------
  160|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  161|      0|      return -1;
  162|      0|    }
  163|       |
  164|  11.5k|    nchar++;
  165|  11.5k|    utf8_len += cbb_get_utf8_len(c);
  166|  11.5k|    if (maxsize > 0 && nchar > (size_t)maxsize) {
  ------------------
  |  Branch (166:9): [True: 0, False: 11.5k]
  |  Branch (166:24): [True: 0, False: 0]
  ------------------
  167|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|      ERR_add_error_dataf("maxsize=%zu", (size_t)maxsize);
  169|      0|      return -1;
  170|      0|    }
  171|  11.5k|  }
  172|       |
  173|  1.08k|  if (minsize > 0 && nchar < (size_t)minsize) {
  ------------------
  |  Branch (173:7): [True: 0, False: 1.08k]
  |  Branch (173:22): [True: 0, False: 0]
  ------------------
  174|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_SHORT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  175|      0|    ERR_add_error_dataf("minsize=%zu", (size_t)minsize);
  176|      0|    return -1;
  177|      0|  }
  178|       |
  179|       |  // Now work out output format and string type
  180|  1.08k|  int str_type;
  181|  1.08k|  int (*encode_func)(CBB *, uint32_t) = cbb_add_latin1;
  182|  1.08k|  size_t size_estimate = nchar;
  183|  1.08k|  int outform = MBSTRING_ASC;
  ------------------
  |  |  712|  1.08k|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|  1.08k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  184|  1.08k|  if (mask & B_ASN1_PRINTABLESTRING) {
  ------------------
  |  |  161|  1.08k|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  |  Branch (184:7): [True: 0, False: 1.08k]
  ------------------
  185|      0|    str_type = V_ASN1_PRINTABLESTRING;
  ------------------
  |  |  139|      0|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  186|  1.08k|  } else if (mask & B_ASN1_IA5STRING) {
  ------------------
  |  |  165|  1.08k|#define B_ASN1_IA5STRING 0x0010
  ------------------
  |  Branch (186:14): [True: 0, False: 1.08k]
  ------------------
  187|      0|    str_type = V_ASN1_IA5STRING;
  ------------------
  |  |  143|      0|#define V_ASN1_IA5STRING 22
  ------------------
  188|  1.08k|  } else if (mask & B_ASN1_T61STRING) {
  ------------------
  |  |  162|  1.08k|#define B_ASN1_T61STRING 0x0004
  ------------------
  |  Branch (188:14): [True: 0, False: 1.08k]
  ------------------
  189|      0|    str_type = V_ASN1_T61STRING;
  ------------------
  |  |  140|      0|#define V_ASN1_T61STRING 20
  ------------------
  190|  1.08k|  } else if (mask & B_ASN1_BMPSTRING) {
  ------------------
  |  |  173|  1.08k|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  |  Branch (190:14): [True: 0, False: 1.08k]
  ------------------
  191|      0|    str_type = V_ASN1_BMPSTRING;
  ------------------
  |  |  151|      0|#define V_ASN1_BMPSTRING 30
  ------------------
  192|      0|    outform = MBSTRING_BMP;
  ------------------
  |  |  713|      0|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  193|      0|    encode_func = cbb_add_ucs2_be;
  194|      0|    size_estimate = 2 * nchar;
  195|  1.08k|  } else if (mask & B_ASN1_UNIVERSALSTRING) {
  ------------------
  |  |  170|  1.08k|#define B_ASN1_UNIVERSALSTRING 0x0100
  ------------------
  |  Branch (195:14): [True: 0, False: 1.08k]
  ------------------
  196|      0|    str_type = V_ASN1_UNIVERSALSTRING;
  ------------------
  |  |  150|      0|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  197|      0|    encode_func = cbb_add_utf32_be;
  198|      0|    size_estimate = 4 * nchar;
  199|      0|    outform = MBSTRING_UNIV;
  ------------------
  |  |  714|      0|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  200|  1.08k|  } else if (mask & B_ASN1_UTF8STRING) {
  ------------------
  |  |  175|  1.08k|#define B_ASN1_UTF8STRING 0x2000
  ------------------
  |  Branch (200:14): [True: 1.08k, False: 0]
  ------------------
  201|  1.08k|    str_type = V_ASN1_UTF8STRING;
  ------------------
  |  |  135|  1.08k|#define V_ASN1_UTF8STRING 12
  ------------------
  202|  1.08k|    outform = MBSTRING_UTF8;
  ------------------
  |  |  711|  1.08k|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|  1.08k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  203|  1.08k|    encode_func = cbb_add_utf8;
  204|  1.08k|    size_estimate = utf8_len;
  205|  1.08k|  } else {
  206|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  207|      0|    return -1;
  208|      0|  }
  209|       |
  210|  1.08k|  if (!out) {
  ------------------
  |  Branch (210:7): [True: 0, False: 1.08k]
  ------------------
  211|      0|    return str_type;
  212|      0|  }
  213|       |
  214|  1.08k|  int free_dest = 0;
  215|  1.08k|  ASN1_STRING *dest;
  216|  1.08k|  if (*out) {
  ------------------
  |  Branch (216:7): [True: 1.08k, False: 0]
  ------------------
  217|  1.08k|    dest = *out;
  218|  1.08k|  } else {
  219|      0|    free_dest = 1;
  220|      0|    dest = ASN1_STRING_type_new(str_type);
  221|      0|    if (!dest) {
  ------------------
  |  Branch (221:9): [True: 0, False: 0]
  ------------------
  222|      0|      return -1;
  223|      0|    }
  224|      0|  }
  225|       |
  226|  1.08k|  CBB cbb;
  227|  1.08k|  CBB_zero(&cbb);
  228|       |  // If both the same type just copy across
  229|  1.08k|  if (inform == outform) {
  ------------------
  |  Branch (229:7): [True: 627, False: 458]
  ------------------
  230|    627|    if (!ASN1_STRING_set(dest, in, len)) {
  ------------------
  |  Branch (230:9): [True: 0, False: 627]
  ------------------
  231|      0|      goto err;
  232|      0|    }
  233|    627|    dest->type = str_type;
  234|    627|    *out = dest;
  235|    627|    return str_type;
  236|    627|  }
  237|    458|  if (!CBB_init(&cbb, size_estimate + 1)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 458]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|    458|  CBS_init(&cbs, in, len);
  241|  1.63k|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (241:10): [True: 1.18k, False: 458]
  ------------------
  242|  1.18k|    uint32_t c;
  243|  1.18k|    if (!decode_func(&cbs, &c) || !encode_func(&cbb, c)) {
  ------------------
  |  Branch (243:9): [True: 0, False: 1.18k]
  |  Branch (243:35): [True: 0, False: 1.18k]
  ------------------
  244|      0|      OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  245|      0|      goto err;
  246|      0|    }
  247|  1.18k|  }
  248|    458|  uint8_t *data = NULL;
  249|    458|  size_t data_len;
  250|    458|  if (// OpenSSL historically NUL-terminated this value with a single byte,
  251|       |      // even for |MBSTRING_BMP| and |MBSTRING_UNIV|.
  252|    458|      !CBB_add_u8(&cbb, 0) || !CBB_finish(&cbb, &data, &data_len) ||
  ------------------
  |  Branch (252:7): [True: 0, False: 458]
  |  Branch (252:31): [True: 0, False: 458]
  ------------------
  253|    458|      data_len < 1 || data_len > INT_MAX) {
  ------------------
  |  Branch (253:7): [True: 0, False: 458]
  |  Branch (253:23): [True: 0, False: 458]
  ------------------
  254|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  255|      0|    OPENSSL_free(data);
  256|      0|    goto err;
  257|      0|  }
  258|    458|  dest->type = str_type;
  259|    458|  ASN1_STRING_set0(dest, data, (int)data_len - 1);
  260|    458|  *out = dest;
  261|    458|  return str_type;
  262|       |
  263|      0|err:
  264|      0|  if (free_dest) {
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|      0|    ASN1_STRING_free(dest);
  266|      0|  }
  267|      0|  CBB_cleanup(&cbb);
  268|      0|  return -1;
  269|    458|}

c2i_ASN1_OBJECT:
  157|  2.06k|                             long len) {
  158|  2.06k|  if (len < 0) {
  ------------------
  |  Branch (158:7): [True: 0, False: 2.06k]
  ------------------
  159|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_OBJECT_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  160|      0|    return NULL;
  161|      0|  }
  162|       |
  163|  2.06k|  CBS cbs;
  164|  2.06k|  CBS_init(&cbs, *inp, (size_t)len);
  165|  2.06k|  if (!CBS_is_valid_asn1_oid(&cbs)) {
  ------------------
  |  Branch (165:7): [True: 5, False: 2.05k]
  ------------------
  166|      5|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_OBJECT_ENCODING);
  ------------------
  |  |  441|      5|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  167|      5|    return NULL;
  168|      5|  }
  169|       |
  170|  2.05k|  ASN1_OBJECT *ret = ASN1_OBJECT_create(NID_undef, *inp, (size_t)len,
  ------------------
  |  |   85|  2.05k|#define NID_undef 0
  ------------------
  171|       |                                        /*sn=*/NULL, /*ln=*/NULL);
  172|  2.05k|  if (ret == NULL) {
  ------------------
  |  Branch (172:7): [True: 0, False: 2.05k]
  ------------------
  173|      0|    return NULL;
  174|      0|  }
  175|       |
  176|  2.05k|  if (out != NULL) {
  ------------------
  |  Branch (176:7): [True: 2.05k, False: 0]
  ------------------
  177|  2.05k|    ASN1_OBJECT_free(*out);
  178|  2.05k|    *out = ret;
  179|  2.05k|  }
  180|  2.05k|  *inp += len;  // All bytes were consumed.
  181|  2.05k|  return ret;
  182|  2.05k|}
ASN1_OBJECT_new:
  184|  3.16k|ASN1_OBJECT *ASN1_OBJECT_new(void) {
  185|  3.16k|  ASN1_OBJECT *ret;
  186|       |
  187|  3.16k|  ret = (ASN1_OBJECT *)OPENSSL_malloc(sizeof(ASN1_OBJECT));
  188|  3.16k|  if (ret == NULL) {
  ------------------
  |  Branch (188:7): [True: 0, False: 3.16k]
  ------------------
  189|      0|    return NULL;
  190|      0|  }
  191|  3.16k|  ret->length = 0;
  192|  3.16k|  ret->data = NULL;
  193|  3.16k|  ret->nid = 0;
  194|  3.16k|  ret->sn = NULL;
  195|  3.16k|  ret->ln = NULL;
  196|  3.16k|  ret->flags = ASN1_OBJECT_FLAG_DYNAMIC;
  ------------------
  |  |  105|  3.16k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  197|  3.16k|  return ret;
  198|  3.16k|}
ASN1_OBJECT_free:
  200|  5.78k|void ASN1_OBJECT_free(ASN1_OBJECT *a) {
  201|  5.78k|  if (a == NULL) {
  ------------------
  |  Branch (201:7): [True: 19, False: 5.76k]
  ------------------
  202|     19|    return;
  203|     19|  }
  204|  5.76k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC_STRINGS) {
  ------------------
  |  |  106|  5.76k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  |  Branch (204:7): [True: 3.16k, False: 2.60k]
  ------------------
  205|  3.16k|    OPENSSL_free((void *)a->sn);
  206|  3.16k|    OPENSSL_free((void *)a->ln);
  207|  3.16k|    a->sn = a->ln = NULL;
  208|  3.16k|  }
  209|  5.76k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC_DATA) {
  ------------------
  |  |  107|  5.76k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  |  Branch (209:7): [True: 3.16k, False: 2.60k]
  ------------------
  210|  3.16k|    OPENSSL_free((void *)a->data);
  211|  3.16k|    a->data = NULL;
  212|  3.16k|    a->length = 0;
  213|  3.16k|  }
  214|  5.76k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC) {
  ------------------
  |  |  105|  5.76k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  |  Branch (214:7): [True: 3.16k, False: 2.60k]
  ------------------
  215|  3.16k|    OPENSSL_free(a);
  216|  3.16k|  }
  217|  5.76k|}
ASN1_OBJECT_create:
  220|  2.05k|                                const char *sn, const char *ln) {
  221|  2.05k|  if (len > INT_MAX) {
  ------------------
  |  Branch (221:7): [True: 0, False: 2.05k]
  ------------------
  222|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  223|      0|    return NULL;
  224|      0|  }
  225|       |
  226|  2.05k|  ASN1_OBJECT o;
  227|  2.05k|  o.sn = sn;
  228|  2.05k|  o.ln = ln;
  229|  2.05k|  o.data = data;
  230|  2.05k|  o.nid = nid;
  231|  2.05k|  o.length = (int)len;
  232|  2.05k|  o.flags = ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  105|  2.05k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
                o.flags = ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  106|  2.05k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  233|  2.05k|            ASN1_OBJECT_FLAG_DYNAMIC_DATA;
  ------------------
  |  |  107|  2.05k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  234|  2.05k|  return OBJ_dup(&o);
  235|  2.05k|}

ASN1_STRING_to_UTF8:
  376|  1.08k|int ASN1_STRING_to_UTF8(unsigned char **out, const ASN1_STRING *in) {
  377|  1.08k|  if (!in) {
  ------------------
  |  Branch (377:7): [True: 0, False: 1.08k]
  ------------------
  378|      0|    return -1;
  379|      0|  }
  380|  1.08k|  int mbflag = string_type_to_encoding(in->type);
  381|  1.08k|  if (mbflag == -1) {
  ------------------
  |  Branch (381:7): [True: 0, False: 1.08k]
  ------------------
  382|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNKNOWN_TAG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  383|      0|    return -1;
  384|      0|  }
  385|  1.08k|  ASN1_STRING stmp, *str = &stmp;
  386|  1.08k|  stmp.data = NULL;
  387|  1.08k|  stmp.length = 0;
  388|  1.08k|  stmp.flags = 0;
  389|  1.08k|  int ret =
  390|  1.08k|      ASN1_mbstring_copy(&str, in->data, in->length, mbflag, B_ASN1_UTF8STRING);
  ------------------
  |  |  175|  1.08k|#define B_ASN1_UTF8STRING 0x2000
  ------------------
  391|  1.08k|  if (ret < 0) {
  ------------------
  |  Branch (391:7): [True: 0, False: 1.08k]
  ------------------
  392|      0|    return ret;
  393|      0|  }
  394|  1.08k|  *out = stmp.data;
  395|  1.08k|  return stmp.length;
  396|  1.08k|}
a_strex.c:string_type_to_encoding:
  273|  1.08k|static int string_type_to_encoding(int type) {
  274|       |  // This function is sometimes passed ASN.1 universal types and sometimes
  275|       |  // passed |ASN1_STRING| type values
  276|  1.08k|  switch (type) {
  ------------------
  |  Branch (276:11): [True: 0, False: 1.08k]
  ------------------
  277|    627|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|    627|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (277:5): [True: 627, False: 458]
  ------------------
  278|    627|      return MBSTRING_UTF8;
  ------------------
  |  |  711|    627|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|    627|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  279|      0|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|      0|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (279:5): [True: 0, False: 1.08k]
  ------------------
  280|    395|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|    395|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (280:5): [True: 395, False: 690]
  ------------------
  281|    396|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|    396|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (281:5): [True: 1, False: 1.08k]
  ------------------
  282|    412|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|    412|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (282:5): [True: 16, False: 1.06k]
  ------------------
  283|    412|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|    412|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (283:5): [True: 0, False: 1.08k]
  ------------------
  284|    412|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|    412|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (284:5): [True: 0, False: 1.08k]
  ------------------
  285|    412|    case V_ASN1_ISO64STRING:
  ------------------
  |  |  147|    412|#define V_ASN1_ISO64STRING 26
  ------------------
  |  Branch (285:5): [True: 0, False: 1.08k]
  ------------------
  286|       |      // |MBSTRING_ASC| refers to Latin-1, not ASCII.
  287|    412|      return MBSTRING_ASC;
  ------------------
  |  |  712|    412|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|    412|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  288|      1|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|      1|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (288:5): [True: 1, False: 1.08k]
  ------------------
  289|      1|      return MBSTRING_UNIV;
  ------------------
  |  |  714|      1|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      1|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  290|     45|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|     45|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (290:5): [True: 45, False: 1.04k]
  ------------------
  291|     45|      return MBSTRING_BMP;
  ------------------
  |  |  713|     45|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|     45|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  292|  1.08k|  }
  293|      0|  return -1;
  294|  1.08k|}

asn1_type_cleanup:
   92|  1.34k|void asn1_type_cleanup(ASN1_TYPE *a) {
   93|  1.34k|  switch (a->type) {
   94|    257|    case V_ASN1_NULL:
  ------------------
  |  |  129|    257|#define V_ASN1_NULL 5
  ------------------
  |  Branch (94:5): [True: 257, False: 1.08k]
  ------------------
   95|    257|      a->value.ptr = NULL;
   96|    257|      break;
   97|      4|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      4|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (97:5): [True: 4, False: 1.34k]
  ------------------
   98|      4|      a->value.boolean = ASN1_BOOLEAN_NONE;
  ------------------
  |  |  432|      4|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
   99|      4|      break;
  100|      4|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|      4|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (100:5): [True: 4, False: 1.34k]
  ------------------
  101|      4|      ASN1_OBJECT_free(a->value.object);
  102|      4|      a->value.object = NULL;
  103|      4|      break;
  104|  1.08k|    default:
  ------------------
  |  Branch (104:5): [True: 1.08k, False: 265]
  ------------------
  105|  1.08k|      ASN1_STRING_free(a->value.asn1_string);
  106|  1.08k|      a->value.asn1_string = NULL;
  107|  1.08k|      break;
  108|  1.34k|  }
  109|  1.34k|}
ASN1_TYPE_set:
  111|    673|void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value) {
  112|    673|  asn1_type_cleanup(a);
  113|    673|  a->type = type;
  114|    673|  switch (type) {
  115|    257|    case V_ASN1_NULL:
  ------------------
  |  |  129|    257|#define V_ASN1_NULL 5
  ------------------
  |  Branch (115:5): [True: 257, False: 416]
  ------------------
  116|    257|      a->value.ptr = NULL;
  117|    257|      break;
  118|      4|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      4|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (118:5): [True: 4, False: 669]
  ------------------
  119|      4|      a->value.boolean = value ? ASN1_BOOLEAN_TRUE : ASN1_BOOLEAN_FALSE;
  ------------------
  |  |  427|      0|#define ASN1_BOOLEAN_TRUE 0xff
  ------------------
                    a->value.boolean = value ? ASN1_BOOLEAN_TRUE : ASN1_BOOLEAN_FALSE;
  ------------------
  |  |  423|      8|#define ASN1_BOOLEAN_FALSE 0
  ------------------
  |  Branch (119:26): [True: 0, False: 4]
  ------------------
  120|      4|      break;
  121|      4|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|      4|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (121:5): [True: 4, False: 669]
  ------------------
  122|      4|      a->value.object = value;
  123|      4|      break;
  124|    408|    default:
  ------------------
  |  Branch (124:5): [True: 408, False: 265]
  ------------------
  125|    408|      a->value.asn1_string = value;
  126|    408|      break;
  127|    673|  }
  128|    673|}

ASN1_get_object:
  108|  13.9k|                    int *out_class, long in_len) {
  109|  13.9k|  if (in_len < 0) {
  ------------------
  |  Branch (109:7): [True: 0, False: 13.9k]
  ------------------
  110|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|      0|    return 0x80;
  112|      0|  }
  113|       |
  114|  13.9k|  CBS_ASN1_TAG tag;
  115|  13.9k|  CBS cbs, body;
  116|  13.9k|  CBS_init(&cbs, *inp, (size_t)in_len);
  117|  13.9k|  if (!CBS_get_any_asn1(&cbs, &body, &tag) ||
  ------------------
  |  Branch (117:7): [True: 69, False: 13.8k]
  ------------------
  118|       |      // Bound the length to comfortably fit in an int. Lengths in this
  119|       |      // module often switch between int and long without overflow checks.
  120|  13.9k|      CBS_len(&body) > INT_MAX / 2) {
  ------------------
  |  Branch (120:7): [True: 0, False: 13.8k]
  ------------------
  121|     69|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|     69|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  122|     69|    return 0x80;
  123|     69|  }
  124|       |
  125|       |  // Convert between tag representations.
  126|  13.8k|  int tag_class = (tag & CBS_ASN1_CLASS_MASK) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  207|  13.8k|#define CBS_ASN1_CLASS_MASK (0xc0u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  13.8k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                int tag_class = (tag & CBS_ASN1_CLASS_MASK) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  13.8k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  127|  13.8k|  int constructed = (tag & CBS_ASN1_CONSTRUCTED) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  196|  13.8k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  13.8k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                int constructed = (tag & CBS_ASN1_CONSTRUCTED) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  13.8k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  128|  13.8k|  int tag_number = tag & CBS_ASN1_TAG_NUMBER_MASK;
  ------------------
  |  |  210|  13.8k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  13.8k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  129|       |
  130|       |  // To avoid ambiguity with V_ASN1_NEG, impose a limit on universal tags.
  131|  13.8k|  if (tag_class == V_ASN1_UNIVERSAL && tag_number > V_ASN1_MAX_UNIVERSAL) {
  ------------------
  |  |   92|  27.6k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
                if (tag_class == V_ASN1_UNIVERSAL && tag_number > V_ASN1_MAX_UNIVERSAL) {
  ------------------
  |  |  112|  12.6k|#define V_ASN1_MAX_UNIVERSAL 0xff
  ------------------
  |  Branch (131:7): [True: 12.6k, False: 1.14k]
  |  Branch (131:40): [True: 20, False: 12.6k]
  ------------------
  132|     20|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  133|     20|    return 0x80;
  134|     20|  }
  135|       |
  136|  13.8k|  *inp = CBS_data(&body);
  137|  13.8k|  *out_len = CBS_len(&body);
  138|  13.8k|  *out_tag = tag_number;
  139|  13.8k|  *out_class = tag_class;
  140|  13.8k|  return constructed;
  141|  13.8k|}
ASN1_put_object:
  145|  4.41k|                     int xclass) {
  146|  4.41k|  unsigned char *p = *pp;
  147|  4.41k|  int i, ttag;
  148|       |
  149|  4.41k|  i = (constructed) ? V_ASN1_CONSTRUCTED : 0;
  ------------------
  |  |   99|  2.20k|#define V_ASN1_CONSTRUCTED 0x20
  ------------------
  |  Branch (149:7): [True: 2.20k, False: 2.20k]
  ------------------
  150|  4.41k|  i |= (xclass & V_ASN1_PRIVATE);
  ------------------
  |  |   95|  4.41k|#define V_ASN1_PRIVATE 0xc0
  ------------------
  151|  4.41k|  if (tag < 31) {
  ------------------
  |  Branch (151:7): [True: 4.41k, False: 0]
  ------------------
  152|  4.41k|    *(p++) = i | (tag & V_ASN1_PRIMITIVE_TAG);
  ------------------
  |  |  106|  4.41k|#define V_ASN1_PRIMITIVE_TAG 0x1f
  ------------------
  153|  4.41k|  } else {
  154|      0|    *(p++) = i | V_ASN1_PRIMITIVE_TAG;
  ------------------
  |  |  106|      0|#define V_ASN1_PRIMITIVE_TAG 0x1f
  ------------------
  155|      0|    for (i = 0, ttag = tag; ttag > 0; i++) {
  ------------------
  |  Branch (155:29): [True: 0, False: 0]
  ------------------
  156|      0|      ttag >>= 7;
  157|      0|    }
  158|      0|    ttag = i;
  159|      0|    while (i-- > 0) {
  ------------------
  |  Branch (159:12): [True: 0, False: 0]
  ------------------
  160|      0|      p[i] = tag & 0x7f;
  161|      0|      if (i != (ttag - 1)) {
  ------------------
  |  Branch (161:11): [True: 0, False: 0]
  ------------------
  162|      0|        p[i] |= 0x80;
  163|      0|      }
  164|      0|      tag >>= 7;
  165|      0|    }
  166|      0|    p += ttag;
  167|      0|  }
  168|  4.41k|  if (constructed == 2) {
  ------------------
  |  Branch (168:7): [True: 0, False: 4.41k]
  ------------------
  169|      0|    *(p++) = 0x80;
  170|  4.41k|  } else {
  171|  4.41k|    asn1_put_length(&p, length);
  172|  4.41k|  }
  173|  4.41k|  *pp = p;
  174|  4.41k|}
ASN1_object_size:
  207|  14.3k|int ASN1_object_size(int constructed, int length, int tag) {
  208|  14.3k|  int ret = 1;
  209|  14.3k|  if (length < 0) {
  ------------------
  |  Branch (209:7): [True: 0, False: 14.3k]
  ------------------
  210|      0|    return -1;
  211|      0|  }
  212|  14.3k|  if (tag >= 31) {
  ------------------
  |  Branch (212:7): [True: 0, False: 14.3k]
  ------------------
  213|      0|    while (tag > 0) {
  ------------------
  |  Branch (213:12): [True: 0, False: 0]
  ------------------
  214|      0|      tag >>= 7;
  215|      0|      ret++;
  216|      0|    }
  217|      0|  }
  218|  14.3k|  if (constructed == 2) {
  ------------------
  |  Branch (218:7): [True: 0, False: 14.3k]
  ------------------
  219|      0|    ret += 3;
  220|  14.3k|  } else {
  221|  14.3k|    ret++;
  222|  14.3k|    if (length > 127) {
  ------------------
  |  Branch (222:9): [True: 0, False: 14.3k]
  ------------------
  223|      0|      int tmplen = length;
  224|      0|      while (tmplen > 0) {
  ------------------
  |  Branch (224:14): [True: 0, False: 0]
  ------------------
  225|      0|        tmplen >>= 8;
  226|      0|        ret++;
  227|      0|      }
  228|      0|    }
  229|  14.3k|  }
  230|  14.3k|  if (ret >= INT_MAX - length) {
  ------------------
  |  Branch (230:7): [True: 0, False: 14.3k]
  ------------------
  231|      0|    return -1;
  232|      0|  }
  233|  14.3k|  return ret + length;
  234|  14.3k|}
ASN1_STRING_copy:
  236|     19|int ASN1_STRING_copy(ASN1_STRING *dst, const ASN1_STRING *str) {
  237|     19|  if (str == NULL) {
  ------------------
  |  Branch (237:7): [True: 0, False: 19]
  ------------------
  238|      0|    return 0;
  239|      0|  }
  240|     19|  if (!ASN1_STRING_set(dst, str->data, str->length)) {
  ------------------
  |  Branch (240:7): [True: 0, False: 19]
  ------------------
  241|      0|    return 0;
  242|      0|  }
  243|     19|  dst->type = str->type;
  244|     19|  dst->flags = str->flags;
  245|     19|  return 1;
  246|     19|}
ASN1_STRING_set:
  264|  3.71k|int ASN1_STRING_set(ASN1_STRING *str, const void *_data, ossl_ssize_t len_s) {
  265|  3.71k|  const char *data = _data;
  266|  3.71k|  size_t len;
  267|  3.71k|  if (len_s < 0) {
  ------------------
  |  Branch (267:7): [True: 0, False: 3.71k]
  ------------------
  268|      0|    if (data == NULL) {
  ------------------
  |  Branch (268:9): [True: 0, False: 0]
  ------------------
  269|      0|      return 0;
  270|      0|    }
  271|      0|    len = strlen(data);
  272|  3.71k|  } else {
  273|  3.71k|    len = (size_t)len_s;
  274|  3.71k|  }
  275|       |
  276|       |  // |ASN1_STRING| cannot represent strings that exceed |int|, and we must
  277|       |  // reserve space for a trailing NUL below.
  278|  3.71k|  if (len > INT_MAX || len + 1 < len) {
  ------------------
  |  Branch (278:7): [True: 0, False: 3.71k]
  |  Branch (278:24): [True: 0, False: 3.71k]
  ------------------
  279|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  280|      0|    return 0;
  281|      0|  }
  282|       |
  283|  3.71k|  if (str->length <= (int)len || str->data == NULL) {
  ------------------
  |  Branch (283:7): [True: 3.71k, False: 0]
  |  Branch (283:34): [True: 0, False: 0]
  ------------------
  284|  3.71k|    unsigned char *c = str->data;
  285|  3.71k|    if (c == NULL) {
  ------------------
  |  Branch (285:9): [True: 3.71k, False: 0]
  ------------------
  286|  3.71k|      str->data = OPENSSL_malloc(len + 1);
  287|  3.71k|    } else {
  288|      0|      str->data = OPENSSL_realloc(c, len + 1);
  289|      0|    }
  290|       |
  291|  3.71k|    if (str->data == NULL) {
  ------------------
  |  Branch (291:9): [True: 0, False: 3.71k]
  ------------------
  292|      0|      str->data = c;
  293|      0|      return 0;
  294|      0|    }
  295|  3.71k|  }
  296|  3.71k|  str->length = (int)len;
  297|  3.71k|  if (data != NULL) {
  ------------------
  |  Branch (297:7): [True: 3.71k, False: 0]
  ------------------
  298|  3.71k|    OPENSSL_memcpy(str->data, data, len);
  299|       |    // Historically, OpenSSL would NUL-terminate most (but not all)
  300|       |    // |ASN1_STRING|s, in case anyone accidentally passed |str->data| into a
  301|       |    // function expecting a C string. We retain this behavior for compatibility,
  302|       |    // but code must not rely on this. See CVE-2021-3712.
  303|  3.71k|    str->data[len] = '\0';
  304|  3.71k|  }
  305|  3.71k|  return 1;
  306|  3.71k|}
ASN1_STRING_set0:
  308|    458|void ASN1_STRING_set0(ASN1_STRING *str, void *data, int len) {
  309|    458|  OPENSSL_free(str->data);
  310|    458|  str->data = data;
  311|    458|  str->length = len;
  312|    458|}
ASN1_STRING_type_new:
  318|  5.78k|ASN1_STRING *ASN1_STRING_type_new(int type) {
  319|  5.78k|  ASN1_STRING *ret;
  320|       |
  321|  5.78k|  ret = (ASN1_STRING *)OPENSSL_malloc(sizeof(ASN1_STRING));
  322|  5.78k|  if (ret == NULL) {
  ------------------
  |  Branch (322:7): [True: 0, False: 5.78k]
  ------------------
  323|      0|    return NULL;
  324|      0|  }
  325|  5.78k|  ret->length = 0;
  326|  5.78k|  ret->type = type;
  327|  5.78k|  ret->data = NULL;
  328|  5.78k|  ret->flags = 0;
  329|  5.78k|  return ret;
  330|  5.78k|}
ASN1_STRING_free:
  332|  9.23k|void ASN1_STRING_free(ASN1_STRING *str) {
  333|  9.23k|  if (str == NULL) {
  ------------------
  |  Branch (333:7): [True: 3.45k, False: 5.78k]
  ------------------
  334|  3.45k|    return;
  335|  3.45k|  }
  336|  5.78k|  OPENSSL_free(str->data);
  337|  5.78k|  OPENSSL_free(str);
  338|  5.78k|}
asn1_lib.c:asn1_put_length:
  186|  4.41k|static void asn1_put_length(unsigned char **pp, int length) {
  187|  4.41k|  unsigned char *p = *pp;
  188|  4.41k|  int i, l;
  189|  4.41k|  if (length <= 127) {
  ------------------
  |  Branch (189:7): [True: 4.41k, False: 0]
  ------------------
  190|  4.41k|    *(p++) = (unsigned char)length;
  191|  4.41k|  } else {
  192|      0|    l = length;
  193|      0|    for (i = 0; l > 0; i++) {
  ------------------
  |  Branch (193:17): [True: 0, False: 0]
  ------------------
  194|      0|      l >>= 8;
  195|      0|    }
  196|      0|    *(p++) = i | 0x80;
  197|      0|    l = i;
  198|      0|    while (i-- > 0) {
  ------------------
  |  Branch (198:12): [True: 0, False: 0]
  ------------------
  199|      0|      p[i] = length & 0xff;
  200|      0|      length >>= 8;
  201|      0|    }
  202|      0|    p += l;
  203|      0|  }
  204|  4.41k|  *pp = p;
  205|  4.41k|}

ASN1_tag2bit:
  132|  2.69k|unsigned long ASN1_tag2bit(int tag) {
  133|  2.69k|  if (tag < 0 || tag > 30) {
  ------------------
  |  Branch (133:7): [True: 0, False: 2.69k]
  |  Branch (133:18): [True: 8, False: 2.68k]
  ------------------
  134|      8|    return 0;
  135|      8|  }
  136|  2.68k|  return tag2bit[tag];
  137|  2.69k|}
ASN1_item_d2i:
  164|     33|                          const ASN1_ITEM *it) {
  165|     33|  ASN1_VALUE *ret = NULL;
  166|     33|  if (asn1_item_ex_d2i(&ret, in, len, it, /*tag=*/-1, /*aclass=*/0, /*opt=*/0,
  ------------------
  |  Branch (166:7): [True: 3, False: 30]
  ------------------
  167|       |                       /*buf=*/NULL, /*depth=*/0) <= 0) {
  168|       |    // Clean up, in case the caller left a partial object.
  169|       |    //
  170|       |    // TODO(davidben): I don't think it can leave one, but the codepaths below
  171|       |    // are a bit inconsistent. Revisit this when rewriting this function.
  172|      3|    ASN1_item_ex_free(&ret, it);
  173|      3|  }
  174|       |
  175|       |  // If the caller supplied an output pointer, free the old one and replace it
  176|       |  // with |ret|. This differs from OpenSSL slightly in that we don't support
  177|       |  // object reuse. We run this on both success and failure. On failure, even
  178|       |  // with object reuse, OpenSSL destroys the previous object.
  179|     33|  if (pval != NULL) {
  ------------------
  |  Branch (179:7): [True: 0, False: 33]
  ------------------
  180|      0|    ASN1_item_ex_free(pval, it);
  181|      0|    *pval = ret;
  182|      0|  }
  183|     33|  return ret;
  184|     33|}
ASN1_item_ex_d2i:
  493|  1.11k|                     CRYPTO_BUFFER *buf) {
  494|  1.11k|  return asn1_item_ex_d2i(pval, in, len, it, tag, aclass, opt, buf,
  495|  1.11k|                          /*depth=*/0);
  496|  1.11k|}
tasn_dec.c:asn1_item_ex_d2i:
  197|  11.4k|                            char opt, CRYPTO_BUFFER *buf, int depth) {
  198|  11.4k|  const ASN1_TEMPLATE *tt, *errtt = NULL;
  199|  11.4k|  const unsigned char *p = NULL, *q;
  200|  11.4k|  unsigned char oclass;
  201|  11.4k|  char cst, isopt;
  202|  11.4k|  int i;
  203|  11.4k|  int otag;
  204|  11.4k|  int ret = 0;
  205|  11.4k|  ASN1_VALUE **pchptr;
  206|  11.4k|  if (!pval) {
  ------------------
  |  Branch (206:7): [True: 0, False: 11.4k]
  ------------------
  207|      0|    return 0;
  208|      0|  }
  209|       |
  210|  11.4k|  if (buf != NULL) {
  ------------------
  |  Branch (210:7): [True: 0, False: 11.4k]
  ------------------
  211|      0|    assert(CRYPTO_BUFFER_data(buf) <= *in &&
  212|      0|           *in + len <= CRYPTO_BUFFER_data(buf) + CRYPTO_BUFFER_len(buf));
  213|      0|  }
  214|       |
  215|       |  // Bound |len| to comfortably fit in an int. Lengths in this module often
  216|       |  // switch between int and long without overflow checks.
  217|  11.4k|  if (len > INT_MAX / 2) {
  ------------------
  |  Branch (217:7): [True: 0, False: 11.4k]
  ------------------
  218|      0|    len = INT_MAX / 2;
  219|      0|  }
  220|       |
  221|  11.4k|  if (++depth > ASN1_MAX_CONSTRUCTED_NEST) {
  ------------------
  |  |   76|  11.4k|#define ASN1_MAX_CONSTRUCTED_NEST 30
  ------------------
  |  Branch (221:7): [True: 0, False: 11.4k]
  ------------------
  222|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_TOO_DEEP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  223|      0|    goto err;
  224|      0|  }
  225|       |
  226|  11.4k|  switch (it->itype) {
  227|  6.20k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  6.20k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (227:5): [True: 6.20k, False: 5.20k]
  ------------------
  228|  6.20k|      if (it->templates) {
  ------------------
  |  Branch (228:11): [True: 1.77k, False: 4.43k]
  ------------------
  229|       |        // tagging or OPTIONAL is currently illegal on an item template
  230|       |        // because the flags can't get passed down. In practice this
  231|       |        // isn't a problem: we include the relevant flags from the item
  232|       |        // template in the template itself.
  233|  1.77k|        if ((tag != -1) || opt) {
  ------------------
  |  Branch (233:13): [True: 0, False: 1.77k]
  |  Branch (233:28): [True: 0, False: 1.77k]
  ------------------
  234|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OPTIONS_ON_ITEM_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  235|      0|          goto err;
  236|      0|        }
  237|  1.77k|        return asn1_template_ex_d2i(pval, in, len, it->templates, opt, buf,
  238|  1.77k|                                    depth);
  239|  1.77k|      }
  240|  4.43k|      return asn1_d2i_ex_primitive(pval, in, len, it, tag, aclass, opt);
  241|      0|      break;
  242|       |
  243|  1.59k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  1.59k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (243:5): [True: 1.59k, False: 9.82k]
  ------------------
  244|       |      // It never makes sense for multi-strings to have implicit tagging, so
  245|       |      // if tag != -1, then this looks like an error in the template.
  246|  1.59k|      if (tag != -1) {
  ------------------
  |  Branch (246:11): [True: 0, False: 1.59k]
  ------------------
  247|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  248|      0|        goto err;
  249|      0|      }
  250|       |
  251|  1.59k|      p = *in;
  252|       |      // Just read in tag and class
  253|  1.59k|      ret = asn1_check_tlen(NULL, &otag, &oclass, NULL, &p, len, -1, 0, 1);
  254|  1.59k|      if (!ret) {
  ------------------
  |  Branch (254:11): [True: 1, False: 1.59k]
  ------------------
  255|      1|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  256|      1|        goto err;
  257|      1|      }
  258|       |
  259|       |      // Must be UNIVERSAL class
  260|  1.59k|      if (oclass != V_ASN1_UNIVERSAL) {
  ------------------
  |  |   92|  1.59k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (260:11): [True: 2, False: 1.59k]
  ------------------
  261|       |        // If OPTIONAL, assume this is OK
  262|      2|        if (opt) {
  ------------------
  |  Branch (262:13): [True: 0, False: 2]
  ------------------
  263|      0|          return -1;
  264|      0|        }
  265|      2|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_MSTRING_NOT_UNIVERSAL);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      2|        goto err;
  267|      2|      }
  268|       |      // Check tag matches bit map
  269|  1.59k|      if (!(ASN1_tag2bit(otag) & it->utype)) {
  ------------------
  |  Branch (269:11): [True: 3, False: 1.58k]
  ------------------
  270|       |        // If OPTIONAL, assume this is OK
  271|      3|        if (opt) {
  ------------------
  |  Branch (271:13): [True: 0, False: 3]
  ------------------
  272|      0|          return -1;
  273|      0|        }
  274|      3|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_MSTRING_WRONG_TAG);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  275|      3|        goto err;
  276|      3|      }
  277|  1.58k|      return asn1_d2i_ex_primitive(pval, in, len, it, otag, 0, 0);
  278|       |
  279|    504|    case ASN1_ITYPE_EXTERN: {
  ------------------
  |  |  493|    504|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (279:5): [True: 504, False: 10.9k]
  ------------------
  280|       |      // We don't support implicit tagging with external types.
  281|    504|      if (tag != -1) {
  ------------------
  |  Branch (281:11): [True: 0, False: 504]
  ------------------
  282|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|        goto err;
  284|      0|      }
  285|    504|      const ASN1_EXTERN_FUNCS *ef = it->funcs;
  286|    504|      return ef->asn1_ex_d2i(pval, in, len, it, opt, NULL);
  287|    504|    }
  288|       |
  289|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (289:5): [True: 0, False: 11.4k]
  ------------------
  290|       |      // It never makes sense for CHOICE types to have implicit tagging, so if
  291|       |      // tag != -1, then this looks like an error in the template.
  292|      0|      if (tag != -1) {
  ------------------
  |  Branch (292:11): [True: 0, False: 0]
  ------------------
  293|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  294|      0|        goto err;
  295|      0|      }
  296|       |
  297|      0|      const ASN1_AUX *aux = it->funcs;
  298|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (298:30): [True: 0, False: 0]
  ------------------
  299|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_PRE, pval, it, NULL)) {
  ------------------
  |  |  541|      0|#define ASN1_OP_D2I_PRE		4
  ------------------
  |  Branch (299:11): [True: 0, False: 0]
  |  Branch (299:22): [True: 0, False: 0]
  ------------------
  300|      0|        goto auxerr;
  301|      0|      }
  302|       |
  303|      0|      if (*pval) {
  ------------------
  |  Branch (303:11): [True: 0, False: 0]
  ------------------
  304|       |        // Free up and zero CHOICE value if initialised
  305|      0|        i = asn1_get_choice_selector(pval, it);
  306|      0|        if ((i >= 0) && (i < it->tcount)) {
  ------------------
  |  Branch (306:13): [True: 0, False: 0]
  |  Branch (306:25): [True: 0, False: 0]
  ------------------
  307|      0|          tt = it->templates + i;
  308|      0|          pchptr = asn1_get_field_ptr(pval, tt);
  309|      0|          ASN1_template_free(pchptr, tt);
  310|      0|          asn1_set_choice_selector(pval, -1, it);
  311|      0|        }
  312|      0|      } else if (!ASN1_item_ex_new(pval, it)) {
  ------------------
  |  Branch (312:18): [True: 0, False: 0]
  ------------------
  313|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  314|      0|        goto err;
  315|      0|      }
  316|       |      // CHOICE type, try each possibility in turn
  317|      0|      p = *in;
  318|      0|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (318:39): [True: 0, False: 0]
  ------------------
  319|      0|        pchptr = asn1_get_field_ptr(pval, tt);
  320|       |        // We mark field as OPTIONAL so its absence can be recognised.
  321|      0|        ret = asn1_template_ex_d2i(pchptr, &p, len, tt, 1, buf, depth);
  322|       |        // If field not present, try the next one
  323|      0|        if (ret == -1) {
  ------------------
  |  Branch (323:13): [True: 0, False: 0]
  ------------------
  324|      0|          continue;
  325|      0|        }
  326|       |        // If positive return, read OK, break loop
  327|      0|        if (ret > 0) {
  ------------------
  |  Branch (327:13): [True: 0, False: 0]
  ------------------
  328|      0|          break;
  329|      0|        }
  330|       |        // Otherwise must be an ASN1 parsing error
  331|      0|        errtt = tt;
  332|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  333|      0|        goto err;
  334|      0|      }
  335|       |
  336|       |      // Did we fall off the end without reading anything?
  337|      0|      if (i == it->tcount) {
  ------------------
  |  Branch (337:11): [True: 0, False: 0]
  ------------------
  338|       |        // If OPTIONAL, this is OK
  339|      0|        if (opt) {
  ------------------
  |  Branch (339:13): [True: 0, False: 0]
  ------------------
  340|       |          // Free and zero it
  341|      0|          ASN1_item_ex_free(pval, it);
  342|      0|          return -1;
  343|      0|        }
  344|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NO_MATCHING_CHOICE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|        goto err;
  346|      0|      }
  347|       |
  348|      0|      asn1_set_choice_selector(pval, i, it);
  349|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_POST, pval, it, NULL)) {
  ------------------
  |  |  542|      0|#define ASN1_OP_D2I_POST	5
  ------------------
  |  Branch (349:11): [True: 0, False: 0]
  |  Branch (349:22): [True: 0, False: 0]
  ------------------
  350|      0|        goto auxerr;
  351|      0|      }
  352|      0|      *in = p;
  353|      0|      return 1;
  354|      0|    }
  355|       |
  356|  3.11k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  3.11k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (356:5): [True: 3.11k, False: 8.30k]
  ------------------
  357|  3.11k|      p = *in;
  358|       |
  359|       |      // If no IMPLICIT tagging set to SEQUENCE, UNIVERSAL
  360|  3.11k|      if (tag == -1) {
  ------------------
  |  Branch (360:11): [True: 3.11k, False: 0]
  ------------------
  361|  3.11k|        tag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|  3.11k|#define V_ASN1_SEQUENCE 16
  ------------------
  362|  3.11k|        aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  3.11k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  363|  3.11k|      }
  364|       |      // Get SEQUENCE length and update len, p
  365|  3.11k|      ret = asn1_check_tlen(&len, NULL, NULL, &cst, &p, len, tag, aclass, opt);
  366|  3.11k|      if (!ret) {
  ------------------
  |  Branch (366:11): [True: 142, False: 2.96k]
  ------------------
  367|    142|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    142|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  368|    142|        goto err;
  369|  2.96k|      } else if (ret == -1) {
  ------------------
  |  Branch (369:18): [True: 0, False: 2.96k]
  ------------------
  370|      0|        return -1;
  371|      0|      }
  372|  2.96k|      if (!cst) {
  ------------------
  |  Branch (372:11): [True: 2, False: 2.96k]
  ------------------
  373|      2|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_SEQUENCE_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  374|      2|        goto err;
  375|      2|      }
  376|       |
  377|  2.96k|      if (!*pval && !ASN1_item_ex_new(pval, it)) {
  ------------------
  |  Branch (377:11): [True: 1.99k, False: 974]
  |  Branch (377:21): [True: 0, False: 1.99k]
  ------------------
  378|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  379|      0|        goto err;
  380|      0|      }
  381|       |
  382|  2.96k|      const ASN1_AUX *aux = it->funcs;
  383|  2.96k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (383:30): [True: 724, False: 2.24k]
  ------------------
  384|  2.96k|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_PRE, pval, it, NULL)) {
  ------------------
  |  |  541|    114|#define ASN1_OP_D2I_PRE		4
  ------------------
  |  Branch (384:11): [True: 114, False: 2.85k]
  |  Branch (384:22): [True: 0, False: 114]
  ------------------
  385|      0|        goto auxerr;
  386|      0|      }
  387|       |
  388|       |      // Free up and zero any ADB found
  389|  13.8k|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (389:39): [True: 10.9k, False: 2.96k]
  ------------------
  390|  10.9k|        if (tt->flags & ASN1_TFLG_ADB_MASK) {
  ------------------
  |  |  435|  10.9k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (390:13): [True: 0, False: 10.9k]
  ------------------
  391|      0|          const ASN1_TEMPLATE *seqtt;
  392|      0|          ASN1_VALUE **pseqval;
  393|      0|          seqtt = asn1_do_adb(pval, tt, 0);
  394|      0|          if (seqtt == NULL) {
  ------------------
  |  Branch (394:15): [True: 0, False: 0]
  ------------------
  395|      0|            continue;
  396|      0|          }
  397|      0|          pseqval = asn1_get_field_ptr(pval, seqtt);
  398|      0|          ASN1_template_free(pseqval, seqtt);
  399|      0|        }
  400|  10.9k|      }
  401|       |
  402|       |      // Get each field entry
  403|  9.84k|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (403:39): [True: 7.77k, False: 2.07k]
  ------------------
  404|  7.77k|        const ASN1_TEMPLATE *seqtt;
  405|  7.77k|        ASN1_VALUE **pseqval;
  406|  7.77k|        seqtt = asn1_do_adb(pval, tt, 1);
  407|  7.77k|        if (seqtt == NULL) {
  ------------------
  |  Branch (407:13): [True: 0, False: 7.77k]
  ------------------
  408|      0|          goto err;
  409|      0|        }
  410|  7.77k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  411|       |        // Have we ran out of data?
  412|  7.77k|        if (!len) {
  ------------------
  |  Branch (412:13): [True: 38, False: 7.73k]
  ------------------
  413|     38|          break;
  414|     38|        }
  415|  7.73k|        q = p;
  416|       |        // This determines the OPTIONAL flag value. The field cannot be
  417|       |        // omitted if it is the last of a SEQUENCE and there is still
  418|       |        // data to be read. This isn't strictly necessary but it
  419|       |        // increases efficiency in some cases.
  420|  7.73k|        if (i == (it->tcount - 1)) {
  ------------------
  |  Branch (420:13): [True: 2.37k, False: 5.35k]
  ------------------
  421|  2.37k|          isopt = 0;
  422|  5.35k|        } else {
  423|  5.35k|          isopt = (seqtt->flags & ASN1_TFLG_OPTIONAL) != 0;
  ------------------
  |  |  381|  5.35k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  424|  5.35k|        }
  425|       |        // attempt to read in field, allowing each to be OPTIONAL
  426|       |
  427|  7.73k|        ret = asn1_template_ex_d2i(pseqval, &p, len, seqtt, isopt, buf, depth);
  428|  7.73k|        if (!ret) {
  ------------------
  |  Branch (428:13): [True: 852, False: 6.88k]
  ------------------
  429|    852|          errtt = seqtt;
  430|    852|          goto err;
  431|  6.88k|        } else if (ret == -1) {
  ------------------
  |  Branch (431:20): [True: 262, False: 6.62k]
  ------------------
  432|       |          // OPTIONAL component absent. Free and zero the field.
  433|    262|          ASN1_template_free(pseqval, seqtt);
  434|    262|          continue;
  435|    262|        }
  436|       |        // Update length
  437|  6.62k|        len -= p - q;
  438|  6.62k|      }
  439|       |
  440|       |      // Check all data read
  441|  2.11k|      if (len) {
  ------------------
  |  Branch (441:11): [True: 48, False: 2.06k]
  ------------------
  442|     48|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_SEQUENCE_LENGTH_MISMATCH);
  ------------------
  |  |  441|     48|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  443|     48|        goto err;
  444|     48|      }
  445|       |
  446|       |      // If we get here we've got no more data in the SEQUENCE, however we
  447|       |      // may not have read all fields so check all remaining are OPTIONAL
  448|       |      // and clear any that are.
  449|  2.10k|      for (; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (449:14): [True: 40, False: 2.06k]
  ------------------
  450|     40|        const ASN1_TEMPLATE *seqtt;
  451|     40|        seqtt = asn1_do_adb(pval, tt, 1);
  452|     40|        if (seqtt == NULL) {
  ------------------
  |  Branch (452:13): [True: 0, False: 40]
  ------------------
  453|      0|          goto err;
  454|      0|        }
  455|     40|        if (seqtt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|     40|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (455:13): [True: 38, False: 2]
  ------------------
  456|     38|          ASN1_VALUE **pseqval;
  457|     38|          pseqval = asn1_get_field_ptr(pval, seqtt);
  458|     38|          ASN1_template_free(pseqval, seqtt);
  459|     38|        } else {
  460|      2|          errtt = seqtt;
  461|      2|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_FIELD_MISSING);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  462|      2|          goto err;
  463|      2|        }
  464|     40|      }
  465|       |      // Save encoding
  466|  2.06k|      if (!asn1_enc_save(pval, *in, p - *in, it, buf)) {
  ------------------
  |  Branch (466:11): [True: 0, False: 2.06k]
  ------------------
  467|      0|        goto auxerr;
  468|      0|      }
  469|  2.06k|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_POST, pval, it, NULL)) {
  ------------------
  |  |  542|     96|#define ASN1_OP_D2I_POST	5
  ------------------
  |  Branch (469:11): [True: 96, False: 1.96k]
  |  Branch (469:22): [True: 0, False: 96]
  ------------------
  470|      0|        goto auxerr;
  471|      0|      }
  472|  2.06k|      *in = p;
  473|  2.06k|      return 1;
  474|  2.06k|    }
  475|       |
  476|      0|    default:
  ------------------
  |  Branch (476:5): [True: 0, False: 11.4k]
  ------------------
  477|      0|      return 0;
  478|  11.4k|  }
  479|      0|auxerr:
  480|      0|  OPENSSL_PUT_ERROR(ASN1, ASN1_R_AUX_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  481|  1.05k|err:
  482|  1.05k|  ASN1_item_ex_free(pval, it);
  483|  1.05k|  if (errtt) {
  ------------------
  |  Branch (483:7): [True: 854, False: 198]
  ------------------
  484|    854|    ERR_add_error_data(4, "Field=", errtt->field_name, ", Type=", it->sname);
  485|    854|  } else {
  486|    198|    ERR_add_error_data(2, "Type=", it->sname);
  487|    198|  }
  488|  1.05k|  return 0;
  489|      0|}
tasn_dec.c:asn1_template_ex_d2i:
  503|  9.50k|                                CRYPTO_BUFFER *buf, int depth) {
  504|  9.50k|  int aclass;
  505|  9.50k|  int ret;
  506|  9.50k|  long len;
  507|  9.50k|  const unsigned char *p, *q;
  508|  9.50k|  if (!val) {
  ------------------
  |  Branch (508:7): [True: 0, False: 9.50k]
  ------------------
  509|      0|    return 0;
  510|      0|  }
  511|  9.50k|  uint32_t flags = tt->flags;
  512|  9.50k|  aclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|  9.50k|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  513|       |
  514|  9.50k|  p = *in;
  515|       |
  516|       |  // Check if EXPLICIT tag expected
  517|  9.50k|  if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  9.50k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (517:7): [True: 689, False: 8.81k]
  ------------------
  518|    689|    char cst;
  519|       |    // Need to work out amount of data available to the inner content and
  520|       |    // where it starts: so read in EXPLICIT header to get the info.
  521|    689|    ret = asn1_check_tlen(&len, NULL, NULL, &cst, &p, inlen, tt->tag, aclass,
  522|    689|                          opt);
  523|    689|    q = p;
  524|    689|    if (!ret) {
  ------------------
  |  Branch (524:9): [True: 39, False: 650]
  ------------------
  525|     39|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     39|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  526|     39|      return 0;
  527|    650|    } else if (ret == -1) {
  ------------------
  |  Branch (527:16): [True: 4, False: 646]
  ------------------
  528|      4|      return -1;
  529|      4|    }
  530|    646|    if (!cst) {
  ------------------
  |  Branch (530:9): [True: 1, False: 645]
  ------------------
  531|      1|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_EXPLICIT_TAG_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  532|      1|      return 0;
  533|      1|    }
  534|       |    // We've found the field so it can't be OPTIONAL now
  535|    645|    ret = asn1_template_noexp_d2i(val, &p, len, tt, /*opt=*/0, buf, depth);
  536|    645|    if (!ret) {
  ------------------
  |  Branch (536:9): [True: 6, False: 639]
  ------------------
  537|      6|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      6|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  538|      6|      return 0;
  539|      6|    }
  540|       |    // We read the field in OK so update length
  541|    639|    len -= p - q;
  542|       |    // Check for trailing data.
  543|    639|    if (len) {
  ------------------
  |  Branch (543:9): [True: 6, False: 633]
  ------------------
  544|      6|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_EXPLICIT_LENGTH_MISMATCH);
  ------------------
  |  |  441|      6|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  545|      6|      goto err;
  546|      6|    }
  547|  8.81k|  } else {
  548|  8.81k|    return asn1_template_noexp_d2i(val, in, inlen, tt, opt, buf, depth);
  549|  8.81k|  }
  550|       |
  551|    633|  *in = p;
  552|    633|  return 1;
  553|       |
  554|      6|err:
  555|      6|  ASN1_template_free(val, tt);
  556|      6|  return 0;
  557|  9.50k|}
tasn_dec.c:asn1_template_noexp_d2i:
  561|  9.46k|                                   CRYPTO_BUFFER *buf, int depth) {
  562|  9.46k|  int aclass;
  563|  9.46k|  int ret;
  564|  9.46k|  const unsigned char *p;
  565|  9.46k|  if (!val) {
  ------------------
  |  Branch (565:7): [True: 0, False: 9.46k]
  ------------------
  566|      0|    return 0;
  567|      0|  }
  568|  9.46k|  uint32_t flags = tt->flags;
  569|  9.46k|  aclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|  9.46k|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  570|       |
  571|  9.46k|  p = *in;
  572|       |
  573|  9.46k|  if (flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|  9.46k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (573:7): [True: 1.81k, False: 7.64k]
  ------------------
  574|       |    // SET OF, SEQUENCE OF
  575|  1.81k|    int sktag, skaclass;
  576|       |    // First work out expected inner tag value
  577|  1.81k|    if (flags & ASN1_TFLG_IMPTAG) {
  ------------------
  |  |  398|  1.81k|#define ASN1_TFLG_IMPTAG	(0x1 << 3)
  ------------------
  |  Branch (577:9): [True: 0, False: 1.81k]
  ------------------
  578|      0|      sktag = tt->tag;
  579|      0|      skaclass = aclass;
  580|  1.81k|    } else {
  581|  1.81k|      skaclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  1.81k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  582|  1.81k|      if (flags & ASN1_TFLG_SET_OF) {
  ------------------
  |  |  384|  1.81k|#define ASN1_TFLG_SET_OF	(0x1 << 1)
  ------------------
  |  Branch (582:11): [True: 1.26k, False: 545]
  ------------------
  583|  1.26k|        sktag = V_ASN1_SET;
  ------------------
  |  |  137|  1.26k|#define V_ASN1_SET 17
  ------------------
  584|  1.26k|      } else {
  585|    545|        sktag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|    545|#define V_ASN1_SEQUENCE 16
  ------------------
  586|    545|      }
  587|  1.81k|    }
  588|       |    // Get the tag
  589|  1.81k|    ret =
  590|  1.81k|        asn1_check_tlen(&len, NULL, NULL, NULL, &p, len, sktag, skaclass, opt);
  591|  1.81k|    if (!ret) {
  ------------------
  |  Branch (591:9): [True: 55, False: 1.75k]
  ------------------
  592|     55|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     55|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  593|     55|      return 0;
  594|  1.75k|    } else if (ret == -1) {
  ------------------
  |  Branch (594:16): [True: 0, False: 1.75k]
  ------------------
  595|      0|      return -1;
  596|      0|    }
  597|  1.75k|    if (!*val) {
  ------------------
  |  Branch (597:9): [True: 1.75k, False: 0]
  ------------------
  598|  1.75k|      *val = (ASN1_VALUE *)sk_ASN1_VALUE_new_null();
  599|  1.75k|    } else {
  600|       |      // We've got a valid STACK: free up any items present
  601|      0|      STACK_OF(ASN1_VALUE) *sktmp = (STACK_OF(ASN1_VALUE) *)*val;
  ------------------
  |  |   81|      0|#define STACK_OF(type) struct stack_st_##type
  ------------------
  602|      0|      ASN1_VALUE *vtmp;
  603|      0|      while (sk_ASN1_VALUE_num(sktmp) > 0) {
  ------------------
  |  Branch (603:14): [True: 0, False: 0]
  ------------------
  604|      0|        vtmp = sk_ASN1_VALUE_pop(sktmp);
  605|      0|        ASN1_item_ex_free(&vtmp, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  606|      0|      }
  607|      0|    }
  608|       |
  609|  1.75k|    if (!*val) {
  ------------------
  |  Branch (609:9): [True: 0, False: 1.75k]
  ------------------
  610|      0|      goto err;
  611|      0|    }
  612|       |
  613|       |    // Read as many items as we can
  614|  4.25k|    while (len > 0) {
  ------------------
  |  Branch (614:12): [True: 2.61k, False: 1.63k]
  ------------------
  615|  2.61k|      ASN1_VALUE *skfield;
  616|  2.61k|      const unsigned char *q = p;
  617|  2.61k|      skfield = NULL;
  618|  2.61k|      if (!asn1_item_ex_d2i(&skfield, &p, len, ASN1_ITEM_ptr(tt->item),
  ------------------
  |  |  288|  2.61k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (618:11): [True: 120, False: 2.49k]
  ------------------
  619|  2.61k|                            /*tag=*/-1, /*aclass=*/0, /*opt=*/0, buf, depth)) {
  620|    120|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    120|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  621|    120|        goto err;
  622|    120|      }
  623|  2.49k|      len -= p - q;
  624|  2.49k|      if (!sk_ASN1_VALUE_push((STACK_OF(ASN1_VALUE) *)*val, skfield)) {
  ------------------
  |  Branch (624:11): [True: 0, False: 2.49k]
  ------------------
  625|      0|        ASN1_item_ex_free(&skfield, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  626|      0|        goto err;
  627|      0|      }
  628|  2.49k|    }
  629|  7.64k|  } else if (flags & ASN1_TFLG_IMPTAG) {
  ------------------
  |  |  398|  7.64k|#define ASN1_TFLG_IMPTAG	(0x1 << 3)
  ------------------
  |  Branch (629:14): [True: 182, False: 7.46k]
  ------------------
  630|       |    // IMPLICIT tagging
  631|    182|    ret = asn1_item_ex_d2i(val, &p, len, ASN1_ITEM_ptr(tt->item), tt->tag,
  ------------------
  |  |  288|    182|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  632|    182|                           aclass, opt, buf, depth);
  633|    182|    if (!ret) {
  ------------------
  |  Branch (633:9): [True: 11, False: 171]
  ------------------
  634|     11|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     11|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  635|     11|      goto err;
  636|    171|    } else if (ret == -1) {
  ------------------
  |  Branch (636:16): [True: 164, False: 7]
  ------------------
  637|    164|      return -1;
  638|    164|    }
  639|  7.46k|  } else {
  640|       |    // Nothing special
  641|  7.46k|    ret = asn1_item_ex_d2i(val, &p, len, ASN1_ITEM_ptr(tt->item), /*tag=*/-1,
  ------------------
  |  |  288|  7.46k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  642|  7.46k|                           /*aclass=*/0, opt, buf, depth);
  643|  7.46k|    if (!ret) {
  ------------------
  |  Branch (643:9): [True: 789, False: 6.67k]
  ------------------
  644|    789|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|    789|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  645|    789|      goto err;
  646|  6.67k|    } else if (ret == -1) {
  ------------------
  |  Branch (646:16): [True: 94, False: 6.58k]
  ------------------
  647|     94|      return -1;
  648|     94|    }
  649|  7.46k|  }
  650|       |
  651|  8.22k|  *in = p;
  652|  8.22k|  return 1;
  653|       |
  654|    920|err:
  655|    920|  ASN1_template_free(val, tt);
  656|    920|  return 0;
  657|  9.46k|}
tasn_dec.c:asn1_d2i_ex_primitive:
  661|  6.02k|                                 int aclass, char opt) {
  662|  6.02k|  int ret = 0, utype;
  663|  6.02k|  long plen;
  664|  6.02k|  char cst;
  665|  6.02k|  const unsigned char *p;
  666|  6.02k|  const unsigned char *cont = NULL;
  667|  6.02k|  long len;
  668|  6.02k|  if (!pval) {
  ------------------
  |  Branch (668:7): [True: 0, False: 6.02k]
  ------------------
  669|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_NULL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  670|      0|    return 0;  // Should never happen
  671|      0|  }
  672|       |
  673|  6.02k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|  6.02k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (673:7): [True: 1.58k, False: 4.43k]
  ------------------
  674|  1.58k|    utype = tag;
  675|  1.58k|    tag = -1;
  676|  4.43k|  } else {
  677|  4.43k|    utype = it->utype;
  678|  4.43k|  }
  679|       |
  680|  6.02k|  if (utype == V_ASN1_ANY) {
  ------------------
  |  |  121|  6.02k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (680:7): [True: 679, False: 5.34k]
  ------------------
  681|       |    // If type is ANY need to figure out type from tag
  682|    679|    unsigned char oclass;
  683|    679|    if (tag >= 0) {
  ------------------
  |  Branch (683:9): [True: 0, False: 679]
  ------------------
  684|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_TAGGED_ANY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  685|      0|      return 0;
  686|      0|    }
  687|    679|    if (opt) {
  ------------------
  |  Branch (687:9): [True: 0, False: 679]
  ------------------
  688|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OPTIONAL_ANY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  689|      0|      return 0;
  690|      0|    }
  691|    679|    p = *in;
  692|    679|    ret = asn1_check_tlen(NULL, &utype, &oclass, NULL, &p, inlen, -1, 0, 0);
  693|    679|    if (!ret) {
  ------------------
  |  Branch (693:9): [True: 3, False: 676]
  ------------------
  694|      3|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  695|      3|      return 0;
  696|      3|    }
  697|    676|    if (!is_supported_universal_type(utype, oclass)) {
  ------------------
  |  Branch (697:9): [True: 121, False: 555]
  ------------------
  698|    121|      utype = V_ASN1_OTHER;
  ------------------
  |  |  118|    121|#define V_ASN1_OTHER (-3)
  ------------------
  699|    121|    }
  700|    676|  }
  701|  6.02k|  if (tag == -1) {
  ------------------
  |  Branch (701:7): [True: 5.83k, False: 182]
  ------------------
  702|  5.83k|    tag = utype;
  703|  5.83k|    aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  5.83k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  704|  5.83k|  }
  705|  6.02k|  p = *in;
  706|       |  // Check header
  707|  6.02k|  ret = asn1_check_tlen(&plen, NULL, NULL, &cst, &p, inlen, tag, aclass, opt);
  708|  6.02k|  if (!ret) {
  ------------------
  |  Branch (708:7): [True: 27, False: 5.99k]
  ------------------
  709|     27|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|     27|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  710|     27|    return 0;
  711|  5.99k|  } else if (ret == -1) {
  ------------------
  |  Branch (711:14): [True: 258, False: 5.73k]
  ------------------
  712|    258|    return -1;
  713|    258|  }
  714|  5.73k|  ret = 0;
  715|       |  // SEQUENCE, SET and "OTHER" are left in encoded form
  716|  5.73k|  if ((utype == V_ASN1_SEQUENCE) || (utype == V_ASN1_SET) ||
  ------------------
  |  |  136|  5.73k|#define V_ASN1_SEQUENCE 16
  ------------------
                if ((utype == V_ASN1_SEQUENCE) || (utype == V_ASN1_SET) ||
  ------------------
  |  |  137|  5.72k|#define V_ASN1_SET 17
  ------------------
  |  Branch (716:7): [True: 9, False: 5.72k]
  |  Branch (716:37): [True: 1, False: 5.72k]
  ------------------
  717|  5.73k|      (utype == V_ASN1_OTHER)) {
  ------------------
  |  |  118|  5.72k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (717:7): [True: 121, False: 5.60k]
  ------------------
  718|       |    // SEQUENCE and SET must be constructed
  719|    131|    if (utype != V_ASN1_OTHER && !cst) {
  ------------------
  |  |  118|    262|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (719:9): [True: 10, False: 121]
  |  Branch (719:34): [True: 2, False: 8]
  ------------------
  720|      2|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_TYPE_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  721|      2|      return 0;
  722|      2|    }
  723|       |
  724|    129|    cont = *in;
  725|    129|    len = p - cont + plen;
  726|    129|    p += plen;
  727|  5.60k|  } else if (cst) {
  ------------------
  |  Branch (727:14): [True: 2, False: 5.60k]
  ------------------
  728|       |    // This parser historically supported BER constructed strings. We no
  729|       |    // longer do and will gradually tighten this parser into a DER
  730|       |    // parser. BER types should use |CBS_asn1_ber_to_der|.
  731|      2|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_TYPE_NOT_PRIMITIVE);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  732|      2|    return 0;
  733|  5.60k|  } else {
  734|  5.60k|    cont = p;
  735|  5.60k|    len = plen;
  736|  5.60k|    p += plen;
  737|  5.60k|  }
  738|       |
  739|       |  // We now have content length and type: translate into a structure
  740|  5.73k|  if (!asn1_ex_c2i(pval, cont, len, utype, it)) {
  ------------------
  |  Branch (740:7): [True: 245, False: 5.48k]
  ------------------
  741|    245|    goto err;
  742|    245|  }
  743|       |
  744|  5.48k|  *in = p;
  745|  5.48k|  ret = 1;
  746|  5.73k|err:
  747|  5.73k|  return ret;
  748|  5.48k|}
tasn_dec.c:is_supported_universal_type:
  139|    676|static int is_supported_universal_type(int tag, int aclass) {
  140|    676|  if (aclass != V_ASN1_UNIVERSAL) {
  ------------------
  |  |   92|    676|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (140:7): [True: 85, False: 591]
  ------------------
  141|     85|    return 0;
  142|     85|  }
  143|    591|  return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  130|  1.18k|#define V_ASN1_OBJECT 6
  ------------------
                return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  129|  1.17k|#define V_ASN1_NULL 5
  ------------------
                return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  125|    921|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (143:10): [True: 4, False: 587]
  |  Branch (143:34): [True: 257, False: 330]
  |  Branch (143:56): [True: 4, False: 326]
  ------------------
  144|    591|         tag == V_ASN1_BIT_STRING || tag == V_ASN1_INTEGER ||
  ------------------
  |  |  127|    917|#define V_ASN1_BIT_STRING 3
  ------------------
                       tag == V_ASN1_BIT_STRING || tag == V_ASN1_INTEGER ||
  ------------------
  |  |  126|    909|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (144:10): [True: 8, False: 318]
  |  Branch (144:38): [True: 9, False: 309]
  ------------------
  145|    591|         tag == V_ASN1_ENUMERATED || tag == V_ASN1_OCTET_STRING ||
  ------------------
  |  |  134|    900|#define V_ASN1_ENUMERATED 10
  ------------------
                       tag == V_ASN1_ENUMERATED || tag == V_ASN1_OCTET_STRING ||
  ------------------
  |  |  128|    886|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (145:10): [True: 14, False: 295]
  |  Branch (145:38): [True: 10, False: 285]
  ------------------
  146|    591|         tag == V_ASN1_NUMERICSTRING || tag == V_ASN1_PRINTABLESTRING ||
  ------------------
  |  |  138|    876|#define V_ASN1_NUMERICSTRING 18
  ------------------
                       tag == V_ASN1_NUMERICSTRING || tag == V_ASN1_PRINTABLESTRING ||
  ------------------
  |  |  139|    875|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (146:10): [True: 1, False: 284]
  |  Branch (146:41): [True: 6, False: 278]
  ------------------
  147|    591|         tag == V_ASN1_T61STRING || tag == V_ASN1_VIDEOTEXSTRING ||
  ------------------
  |  |  140|    869|#define V_ASN1_T61STRING 20
  ------------------
                       tag == V_ASN1_T61STRING || tag == V_ASN1_VIDEOTEXSTRING ||
  ------------------
  |  |  142|    862|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (147:10): [True: 7, False: 271]
  |  Branch (147:37): [True: 6, False: 265]
  ------------------
  148|    591|         tag == V_ASN1_IA5STRING || tag == V_ASN1_UTCTIME ||
  ------------------
  |  |  143|    856|#define V_ASN1_IA5STRING 22
  ------------------
                       tag == V_ASN1_IA5STRING || tag == V_ASN1_UTCTIME ||
  ------------------
  |  |  144|    854|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (148:10): [True: 2, False: 263]
  |  Branch (148:37): [True: 37, False: 226]
  ------------------
  149|    591|         tag == V_ASN1_GENERALIZEDTIME || tag == V_ASN1_GRAPHICSTRING ||
  ------------------
  |  |  145|    817|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
                       tag == V_ASN1_GENERALIZEDTIME || tag == V_ASN1_GRAPHICSTRING ||
  ------------------
  |  |  146|    797|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (149:10): [True: 20, False: 206]
  |  Branch (149:43): [True: 2, False: 204]
  ------------------
  150|    591|         tag == V_ASN1_VISIBLESTRING || tag == V_ASN1_GENERALSTRING ||
  ------------------
  |  |  148|    795|#define V_ASN1_VISIBLESTRING 26
  ------------------
                       tag == V_ASN1_VISIBLESTRING || tag == V_ASN1_GENERALSTRING ||
  ------------------
  |  |  149|    787|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (150:10): [True: 8, False: 196]
  |  Branch (150:41): [True: 1, False: 195]
  ------------------
  151|    591|         tag == V_ASN1_UNIVERSALSTRING || tag == V_ASN1_BMPSTRING ||
  ------------------
  |  |  150|    786|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
                       tag == V_ASN1_UNIVERSALSTRING || tag == V_ASN1_BMPSTRING ||
  ------------------
  |  |  151|    705|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (151:10): [True: 81, False: 114]
  |  Branch (151:43): [True: 66, False: 48]
  ------------------
  152|    591|         tag == V_ASN1_UTF8STRING || tag == V_ASN1_SET ||
  ------------------
  |  |  135|    639|#define V_ASN1_UTF8STRING 12
  ------------------
                       tag == V_ASN1_UTF8STRING || tag == V_ASN1_SET ||
  ------------------
  |  |  137|    632|#define V_ASN1_SET 17
  ------------------
  |  Branch (152:10): [True: 7, False: 41]
  |  Branch (152:38): [True: 1, False: 40]
  ------------------
  153|    591|         tag == V_ASN1_SEQUENCE;
  ------------------
  |  |  136|     40|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (153:10): [True: 4, False: 36]
  ------------------
  154|    676|}
tasn_dec.c:asn1_ex_c2i:
  753|  5.73k|                       int utype, const ASN1_ITEM *it) {
  754|  5.73k|  ASN1_VALUE **opval = NULL;
  755|  5.73k|  ASN1_STRING *stmp;
  756|  5.73k|  ASN1_TYPE *typ = NULL;
  757|  5.73k|  int ret = 0;
  758|  5.73k|  ASN1_INTEGER **tint;
  759|       |
  760|       |  // Historically, |it->funcs| for primitive types contained an
  761|       |  // |ASN1_PRIMITIVE_FUNCS| table of callbacks.
  762|  5.73k|  assert(it->funcs == NULL);
  763|       |
  764|       |  // If ANY type clear type and set pointer to internal value
  765|  5.73k|  if (it->utype == V_ASN1_ANY) {
  ------------------
  |  |  121|  5.73k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (765:7): [True: 673, False: 5.05k]
  ------------------
  766|    673|    if (!*pval) {
  ------------------
  |  Branch (766:9): [True: 673, False: 0]
  ------------------
  767|    673|      typ = ASN1_TYPE_new();
  768|    673|      if (typ == NULL) {
  ------------------
  |  Branch (768:11): [True: 0, False: 673]
  ------------------
  769|      0|        goto err;
  770|      0|      }
  771|    673|      *pval = (ASN1_VALUE *)typ;
  772|    673|    } else {
  773|      0|      typ = (ASN1_TYPE *)*pval;
  774|      0|    }
  775|       |
  776|    673|    if (utype != typ->type) {
  ------------------
  |  Branch (776:9): [True: 673, False: 0]
  ------------------
  777|    673|      ASN1_TYPE_set(typ, utype, NULL);
  778|    673|    }
  779|    673|    opval = pval;
  780|    673|    pval = &typ->value.asn1_value;
  781|    673|  }
  782|  5.73k|  switch (utype) {
  783|  2.06k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  2.06k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (783:5): [True: 2.06k, False: 3.67k]
  ------------------
  784|  2.06k|      if (!c2i_ASN1_OBJECT((ASN1_OBJECT **)pval, &cont, len)) {
  ------------------
  |  Branch (784:11): [True: 5, False: 2.05k]
  ------------------
  785|      5|        goto err;
  786|      5|      }
  787|  2.05k|      break;
  788|       |
  789|  2.05k|    case V_ASN1_NULL:
  ------------------
  |  |  129|    257|#define V_ASN1_NULL 5
  ------------------
  |  Branch (789:5): [True: 257, False: 5.47k]
  ------------------
  790|    257|      if (len) {
  ------------------
  |  Branch (790:11): [True: 3, False: 254]
  ------------------
  791|      3|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NULL_IS_WRONG_LENGTH);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  792|      3|        goto err;
  793|      3|      }
  794|    254|      *pval = (ASN1_VALUE *)1;
  795|    254|      break;
  796|       |
  797|      4|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      4|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (797:5): [True: 4, False: 5.72k]
  ------------------
  798|      4|      if (len != 1) {
  ------------------
  |  Branch (798:11): [True: 3, False: 1]
  ------------------
  799|      3|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BOOLEAN_IS_WRONG_LENGTH);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  800|      3|        goto err;
  801|      3|      } else {
  802|      1|        ASN1_BOOLEAN *tbool;
  803|      1|        tbool = (ASN1_BOOLEAN *)pval;
  804|      1|        *tbool = *cont;
  805|      1|      }
  806|      1|      break;
  807|       |
  808|    120|    case V_ASN1_BIT_STRING:
  ------------------
  |  |  127|    120|#define V_ASN1_BIT_STRING 3
  ------------------
  |  Branch (808:5): [True: 120, False: 5.61k]
  ------------------
  809|    120|      if (!c2i_ASN1_BIT_STRING((ASN1_BIT_STRING **)pval, &cont, len)) {
  ------------------
  |  Branch (809:11): [True: 11, False: 109]
  ------------------
  810|     11|        goto err;
  811|     11|      }
  812|    109|      break;
  813|       |
  814|  1.21k|    case V_ASN1_INTEGER:
  ------------------
  |  |  126|  1.21k|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (814:5): [True: 1.21k, False: 4.51k]
  ------------------
  815|  1.24k|    case V_ASN1_ENUMERATED:
  ------------------
  |  |  134|  1.24k|#define V_ASN1_ENUMERATED 10
  ------------------
  |  Branch (815:5): [True: 23, False: 5.70k]
  ------------------
  816|  1.24k|      tint = (ASN1_INTEGER **)pval;
  817|  1.24k|      if (!c2i_ASN1_INTEGER(tint, &cont, len)) {
  ------------------
  |  Branch (817:11): [True: 2, False: 1.23k]
  ------------------
  818|      2|        goto err;
  819|      2|      }
  820|       |      // Fixup type to match the expected form
  821|  1.23k|      (*tint)->type = utype | ((*tint)->type & V_ASN1_NEG);
  ------------------
  |  |  155|  1.23k|#define V_ASN1_NEG 0x100
  ------------------
  822|  1.23k|      break;
  823|       |
  824|    103|    case V_ASN1_OCTET_STRING:
  ------------------
  |  |  128|    103|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (824:5): [True: 103, False: 5.62k]
  ------------------
  825|    104|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|    104|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (825:5): [True: 1, False: 5.73k]
  ------------------
  826|    560|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|    560|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (826:5): [True: 456, False: 5.27k]
  ------------------
  827|    567|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|    567|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (827:5): [True: 7, False: 5.72k]
  ------------------
  828|    573|    case V_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  142|    573|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (828:5): [True: 6, False: 5.72k]
  ------------------
  829|    591|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|    591|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (829:5): [True: 18, False: 5.71k]
  ------------------
  830|    967|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|    967|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (830:5): [True: 376, False: 5.35k]
  ------------------
  831|    991|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|    991|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (831:5): [True: 24, False: 5.70k]
  ------------------
  832|    993|    case V_ASN1_GRAPHICSTRING:
  ------------------
  |  |  146|    993|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (832:5): [True: 2, False: 5.73k]
  ------------------
  833|  1.00k|    case V_ASN1_VISIBLESTRING:
  ------------------
  |  |  148|  1.00k|#define V_ASN1_VISIBLESTRING 26
  ------------------
  |  Branch (833:5): [True: 8, False: 5.72k]
  ------------------
  834|  1.00k|    case V_ASN1_GENERALSTRING:
  ------------------
  |  |  149|  1.00k|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (834:5): [True: 1, False: 5.73k]
  ------------------
  835|  1.08k|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|  1.08k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (835:5): [True: 82, False: 5.65k]
  ------------------
  836|  1.19k|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|  1.19k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (836:5): [True: 111, False: 5.62k]
  ------------------
  837|  1.91k|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|  1.91k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (837:5): [True: 718, False: 5.01k]
  ------------------
  838|  2.03k|    case V_ASN1_OTHER:
  ------------------
  |  |  118|  2.03k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (838:5): [True: 121, False: 5.61k]
  ------------------
  839|  2.03k|    case V_ASN1_SET:
  ------------------
  |  |  137|  2.03k|#define V_ASN1_SET 17
  ------------------
  |  Branch (839:5): [True: 0, False: 5.73k]
  ------------------
  840|  2.04k|    case V_ASN1_SEQUENCE:
  ------------------
  |  |  136|  2.04k|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (840:5): [True: 8, False: 5.72k]
  ------------------
  841|       |    // TODO(crbug.com/boringssl/412): This default case should be removed, now
  842|       |    // that we've resolved https://crbug.com/boringssl/561. However, it is still
  843|       |    // needed to support some edge cases in |ASN1_PRINTABLE|. |ASN1_PRINTABLE|
  844|       |    // broadly doesn't tolerate unrecognized universal tags, but except for
  845|       |    // eight values that map to |B_ASN1_UNKNOWN| instead of zero. See the
  846|       |    // X509Test.NameAttributeValues test.
  847|  2.04k|    default: {
  ------------------
  |  Branch (847:5): [True: 7, False: 5.72k]
  ------------------
  848|  2.04k|      CBS cbs;
  849|  2.04k|      CBS_init(&cbs, cont, (size_t)len);
  850|  2.04k|      if (utype == V_ASN1_BMPSTRING) {
  ------------------
  |  |  151|  2.04k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (850:11): [True: 111, False: 1.93k]
  ------------------
  851|  1.19k|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (851:16): [True: 1.11k, False: 82]
  ------------------
  852|  1.11k|          uint32_t c;
  853|  1.11k|          if (!cbs_get_ucs2_be(&cbs, &c)) {
  ------------------
  |  Branch (853:15): [True: 29, False: 1.08k]
  ------------------
  854|     29|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BMPSTRING);
  ------------------
  |  |  441|     29|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  855|     29|            goto err;
  856|     29|          }
  857|  1.11k|        }
  858|    111|      }
  859|  2.02k|      if (utype == V_ASN1_UNIVERSALSTRING) {
  ------------------
  |  |  150|  2.02k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (859:11): [True: 82, False: 1.93k]
  ------------------
  860|    152|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (860:16): [True: 148, False: 4]
  ------------------
  861|    148|          uint32_t c;
  862|    148|          if (!cbs_get_utf32_be(&cbs, &c)) {
  ------------------
  |  Branch (862:15): [True: 78, False: 70]
  ------------------
  863|     78|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_UNIVERSALSTRING);
  ------------------
  |  |  441|     78|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  864|     78|            goto err;
  865|     78|          }
  866|    148|        }
  867|     82|      }
  868|  1.94k|      if (utype == V_ASN1_UTF8STRING) {
  ------------------
  |  |  135|  1.94k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (868:11): [True: 718, False: 1.22k]
  ------------------
  869|  11.9k|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (869:16): [True: 11.2k, False: 672]
  ------------------
  870|  11.2k|          uint32_t c;
  871|  11.2k|          if (!cbs_get_utf8(&cbs, &c)) {
  ------------------
  |  Branch (871:15): [True: 46, False: 11.2k]
  ------------------
  872|     46|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_UTF8STRING);
  ------------------
  |  |  441|     46|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  873|     46|            goto err;
  874|     46|          }
  875|  11.2k|        }
  876|    718|      }
  877|  1.89k|      if (utype == V_ASN1_UTCTIME) {
  ------------------
  |  |  144|  1.89k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (877:11): [True: 376, False: 1.52k]
  ------------------
  878|    376|        if (!CBS_parse_utc_time(&cbs, NULL, /*allow_timezone_offset=*/1)) {
  ------------------
  |  Branch (878:13): [True: 45, False: 331]
  ------------------
  879|     45|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_TIME_FORMAT);
  ------------------
  |  |  441|     45|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  880|     45|          goto err;
  881|     45|        }
  882|    376|      }
  883|  1.85k|      if (utype == V_ASN1_GENERALIZEDTIME) {
  ------------------
  |  |  145|  1.85k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (883:11): [True: 24, False: 1.82k]
  ------------------
  884|     24|        if (!CBS_parse_generalized_time(&cbs, NULL,
  ------------------
  |  Branch (884:13): [True: 23, False: 1]
  ------------------
  885|     24|                                        /*allow_timezone_offset=*/0)) {
  886|     23|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_TIME_FORMAT);
  ------------------
  |  |  441|     23|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  887|     23|          goto err;
  888|     23|        }
  889|     24|      }
  890|       |      // TODO(https://crbug.com/boringssl/427): Check other string types.
  891|       |
  892|       |      // All based on ASN1_STRING and handled the same
  893|  1.82k|      if (!*pval) {
  ------------------
  |  Branch (893:11): [True: 208, False: 1.62k]
  ------------------
  894|    208|        stmp = ASN1_STRING_type_new(utype);
  895|    208|        if (!stmp) {
  ------------------
  |  Branch (895:13): [True: 0, False: 208]
  ------------------
  896|      0|          goto err;
  897|      0|        }
  898|    208|        *pval = (ASN1_VALUE *)stmp;
  899|  1.62k|      } else {
  900|  1.62k|        stmp = (ASN1_STRING *)*pval;
  901|  1.62k|        stmp->type = utype;
  902|  1.62k|      }
  903|  1.82k|      if (!ASN1_STRING_set(stmp, cont, len)) {
  ------------------
  |  Branch (903:11): [True: 0, False: 1.82k]
  ------------------
  904|      0|        ASN1_STRING_free(stmp);
  905|      0|        *pval = NULL;
  906|      0|        goto err;
  907|      0|      }
  908|  1.82k|      break;
  909|  1.82k|    }
  910|  5.73k|  }
  911|       |  // If ASN1_ANY and NULL type fix up value
  912|  5.48k|  if (typ && (utype == V_ASN1_NULL)) {
  ------------------
  |  |  129|    490|#define V_ASN1_NULL 5
  ------------------
  |  Branch (912:7): [True: 490, False: 4.99k]
  |  Branch (912:14): [True: 254, False: 236]
  ------------------
  913|    254|    typ->value.ptr = NULL;
  914|    254|  }
  915|       |
  916|  5.48k|  ret = 1;
  917|  5.73k|err:
  918|  5.73k|  if (!ret) {
  ------------------
  |  Branch (918:7): [True: 245, False: 5.48k]
  ------------------
  919|    245|    ASN1_TYPE_free(typ);
  920|    245|    if (opval) {
  ------------------
  |  Branch (920:9): [True: 183, False: 62]
  ------------------
  921|    183|      *opval = NULL;
  922|    183|    }
  923|    245|  }
  924|  5.73k|  return ret;
  925|  5.48k|}
tasn_dec.c:asn1_check_tlen:
  932|  13.9k|                           int exptag, int expclass, char opt) {
  933|  13.9k|  int i;
  934|  13.9k|  int ptag, pclass;
  935|  13.9k|  long plen;
  936|  13.9k|  const unsigned char *p;
  937|  13.9k|  p = *in;
  938|       |
  939|  13.9k|  i = ASN1_get_object(&p, &plen, &ptag, &pclass, len);
  940|  13.9k|  if (i & 0x80) {
  ------------------
  |  Branch (940:7): [True: 89, False: 13.8k]
  ------------------
  941|     89|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_OBJECT_HEADER);
  ------------------
  |  |  441|     89|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  942|     89|    return 0;
  943|     89|  }
  944|  13.8k|  if (exptag >= 0) {
  ------------------
  |  Branch (944:7): [True: 11.4k, False: 2.39k]
  ------------------
  945|  11.4k|    if ((exptag != ptag) || (expclass != pclass)) {
  ------------------
  |  Branch (945:9): [True: 426, False: 11.0k]
  |  Branch (945:29): [True: 14, False: 10.9k]
  ------------------
  946|       |      // If type is OPTIONAL, not an error: indicate missing type.
  947|    440|      if (opt) {
  ------------------
  |  Branch (947:11): [True: 262, False: 178]
  ------------------
  948|    262|        return -1;
  949|    262|      }
  950|    178|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TAG);
  ------------------
  |  |  441|    178|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  951|    178|      return 0;
  952|    440|    }
  953|  11.4k|  }
  954|       |
  955|  13.3k|  if (cst) {
  ------------------
  |  Branch (955:7): [True: 9.35k, False: 4.02k]
  ------------------
  956|  9.35k|    *cst = i & V_ASN1_CONSTRUCTED;
  ------------------
  |  |   99|  9.35k|#define V_ASN1_CONSTRUCTED 0x20
  ------------------
  957|  9.35k|  }
  958|       |
  959|  13.3k|  if (olen) {
  ------------------
  |  Branch (959:7): [True: 11.1k, False: 2.26k]
  ------------------
  960|  11.1k|    *olen = plen;
  961|  11.1k|  }
  962|       |
  963|  13.3k|  if (oclass) {
  ------------------
  |  Branch (963:7): [True: 2.26k, False: 11.1k]
  ------------------
  964|  2.26k|    *oclass = pclass;
  965|  2.26k|  }
  966|       |
  967|  13.3k|  if (otag) {
  ------------------
  |  Branch (967:7): [True: 2.26k, False: 11.1k]
  ------------------
  968|  2.26k|    *otag = ptag;
  969|  2.26k|  }
  970|       |
  971|  13.3k|  *in = p;
  972|  13.3k|  return 1;
  973|  13.8k|}

ASN1_item_ex_i2d:
  115|  5.52k|                     const ASN1_ITEM *it, int tag, int aclass) {
  116|  5.52k|  int ret = asn1_item_ex_i2d_opt(pval, out, it, tag, aclass, /*optional=*/0);
  117|  5.52k|  assert(ret != 0);
  118|  5.52k|  return ret;
  119|  5.52k|}
tasn_enc.c:asn1_item_ex_i2d_opt:
  125|  14.3k|                         int optional) {
  126|  14.3k|  const ASN1_TEMPLATE *tt = NULL;
  127|  14.3k|  int i, seqcontlen, seqlen;
  128|       |
  129|       |  // Historically, |aclass| was repurposed to pass additional flags into the
  130|       |  // encoding process.
  131|  14.3k|  assert((aclass & ASN1_TFLG_TAG_CLASS) == aclass);
  132|       |  // If not overridding the tag, |aclass| is ignored and should be zero.
  133|  14.3k|  assert(tag != -1 || aclass == 0);
  134|       |
  135|       |  // All fields are pointers, except for boolean |ASN1_ITYPE_PRIMITIVE|s.
  136|       |  // Optional primitives are handled later.
  137|  14.3k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) && !*pval) {
  ------------------
  |  |  487|  14.3k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (137:7): [True: 7.72k, False: 6.62k]
  |  Branch (137:46): [True: 0, False: 7.72k]
  ------------------
  138|      0|    if (optional) {
  ------------------
  |  Branch (138:9): [True: 0, False: 0]
  ------------------
  139|      0|      return 0;
  140|      0|    }
  141|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  142|      0|    return -1;
  143|      0|  }
  144|       |
  145|  14.3k|  switch (it->itype) {
  146|  6.62k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  6.62k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (146:5): [True: 6.62k, False: 7.72k]
  ------------------
  147|  6.62k|      if (it->templates) {
  ------------------
  |  Branch (147:11): [True: 2.20k, False: 4.41k]
  ------------------
  148|       |        // This is an |ASN1_ITEM_TEMPLATE|.
  149|  2.20k|        if (it->templates->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|  2.20k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (149:13): [True: 0, False: 2.20k]
  ------------------
  150|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|      0|          return -1;
  152|      0|        }
  153|  2.20k|        return asn1_template_ex_i2d(pval, out, it->templates, tag, aclass,
  154|  2.20k|                                    optional);
  155|  2.20k|      }
  156|  4.41k|      return asn1_i2d_ex_primitive(pval, out, it, tag, aclass, optional);
  157|       |
  158|  4.41k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  4.41k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (158:5): [True: 4.41k, False: 9.93k]
  ------------------
  159|       |      // It never makes sense for multi-strings to have implicit tagging, so
  160|       |      // if tag != -1, then this looks like an error in the template.
  161|  4.41k|      if (tag != -1) {
  ------------------
  |  Branch (161:11): [True: 0, False: 4.41k]
  ------------------
  162|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|      0|        return -1;
  164|      0|      }
  165|  4.41k|      return asn1_i2d_ex_primitive(pval, out, it, -1, 0, optional);
  166|       |
  167|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (167:5): [True: 0, False: 14.3k]
  ------------------
  168|       |      // It never makes sense for CHOICE types to have implicit tagging, so if
  169|       |      // tag != -1, then this looks like an error in the template.
  170|      0|      if (tag != -1) {
  ------------------
  |  Branch (170:11): [True: 0, False: 0]
  ------------------
  171|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  172|      0|        return -1;
  173|      0|      }
  174|      0|      i = asn1_get_choice_selector(pval, it);
  175|      0|      if (i < 0 || i >= it->tcount) {
  ------------------
  |  Branch (175:11): [True: 0, False: 0]
  |  Branch (175:20): [True: 0, False: 0]
  ------------------
  176|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NO_MATCHING_CHOICE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|        return -1;
  178|      0|      }
  179|      0|      const ASN1_TEMPLATE *chtt = it->templates + i;
  180|      0|      if (chtt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|      0|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (180:11): [True: 0, False: 0]
  ------------------
  181|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  182|      0|        return -1;
  183|      0|      }
  184|      0|      ASN1_VALUE **pchval = asn1_get_field_ptr(pval, chtt);
  185|      0|      return asn1_template_ex_i2d(pchval, out, chtt, -1, 0, /*optional=*/0);
  186|      0|    }
  187|       |
  188|      0|    case ASN1_ITYPE_EXTERN: {
  ------------------
  |  |  493|      0|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (188:5): [True: 0, False: 14.3k]
  ------------------
  189|       |      // We don't support implicit tagging with external types.
  190|      0|      if (tag != -1) {
  ------------------
  |  Branch (190:11): [True: 0, False: 0]
  ------------------
  191|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  192|      0|        return -1;
  193|      0|      }
  194|      0|      const ASN1_EXTERN_FUNCS *ef = it->funcs;
  195|      0|      int ret = ef->asn1_ex_i2d(pval, out, it);
  196|      0|      if (ret == 0) {
  ------------------
  |  Branch (196:11): [True: 0, False: 0]
  ------------------
  197|       |        // |asn1_ex_i2d| should never return zero. We have already checked
  198|       |        // for optional values generically, and |ASN1_ITYPE_EXTERN| fields
  199|       |        // must be pointers.
  200|      0|        OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  201|      0|        return -1;
  202|      0|      }
  203|      0|      return ret;
  204|      0|    }
  205|       |
  206|  3.31k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  3.31k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (206:5): [True: 3.31k, False: 11.0k]
  ------------------
  207|  3.31k|      i = asn1_enc_restore(&seqcontlen, out, pval, it);
  208|       |      // An error occurred
  209|  3.31k|      if (i < 0) {
  ------------------
  |  Branch (209:11): [True: 0, False: 3.31k]
  ------------------
  210|      0|        return -1;
  211|      0|      }
  212|       |      // We have a valid cached encoding...
  213|  3.31k|      if (i > 0) {
  ------------------
  |  Branch (213:11): [True: 0, False: 3.31k]
  ------------------
  214|      0|        return seqcontlen;
  215|      0|      }
  216|       |      // Otherwise carry on
  217|  3.31k|      seqcontlen = 0;
  218|       |      // If no IMPLICIT tagging set to SEQUENCE, UNIVERSAL
  219|  3.31k|      if (tag == -1) {
  ------------------
  |  Branch (219:11): [True: 3.31k, False: 0]
  ------------------
  220|  3.31k|        tag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|  3.31k|#define V_ASN1_SEQUENCE 16
  ------------------
  221|  3.31k|        aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  3.31k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  222|  3.31k|      }
  223|       |      // First work out sequence content length
  224|  9.93k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (224:39): [True: 6.62k, False: 3.31k]
  ------------------
  225|  6.62k|        const ASN1_TEMPLATE *seqtt;
  226|  6.62k|        ASN1_VALUE **pseqval;
  227|  6.62k|        int tmplen;
  228|  6.62k|        seqtt = asn1_do_adb(pval, tt, 1);
  229|  6.62k|        if (!seqtt) {
  ------------------
  |  Branch (229:13): [True: 0, False: 6.62k]
  ------------------
  230|      0|          return -1;
  231|      0|        }
  232|  6.62k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  233|  6.62k|        tmplen =
  234|  6.62k|            asn1_template_ex_i2d(pseqval, NULL, seqtt, -1, 0, /*optional=*/0);
  235|  6.62k|        if (tmplen == -1 || (tmplen > INT_MAX - seqcontlen)) {
  ------------------
  |  Branch (235:13): [True: 0, False: 6.62k]
  |  Branch (235:29): [True: 0, False: 6.62k]
  ------------------
  236|      0|          return -1;
  237|      0|        }
  238|  6.62k|        seqcontlen += tmplen;
  239|  6.62k|      }
  240|       |
  241|  3.31k|      seqlen = ASN1_object_size(/*constructed=*/1, seqcontlen, tag);
  242|  3.31k|      if (!out || seqlen == -1) {
  ------------------
  |  Branch (242:11): [True: 2.20k, False: 1.10k]
  |  Branch (242:19): [True: 0, False: 1.10k]
  ------------------
  243|  2.20k|        return seqlen;
  244|  2.20k|      }
  245|       |      // Output SEQUENCE header
  246|  1.10k|      ASN1_put_object(out, /*constructed=*/1, seqcontlen, tag, aclass);
  247|  3.31k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (247:39): [True: 2.20k, False: 1.10k]
  ------------------
  248|  2.20k|        const ASN1_TEMPLATE *seqtt;
  249|  2.20k|        ASN1_VALUE **pseqval;
  250|  2.20k|        seqtt = asn1_do_adb(pval, tt, 1);
  251|  2.20k|        if (!seqtt) {
  ------------------
  |  Branch (251:13): [True: 0, False: 2.20k]
  ------------------
  252|      0|          return -1;
  253|      0|        }
  254|  2.20k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  255|  2.20k|        if (asn1_template_ex_i2d(pseqval, out, seqtt, -1, 0, /*optional=*/0) <
  ------------------
  |  Branch (255:13): [True: 0, False: 2.20k]
  ------------------
  256|  2.20k|            0) {
  257|      0|          return -1;
  258|      0|        }
  259|  2.20k|      }
  260|  1.10k|      return seqlen;
  261|  1.10k|    }
  262|       |
  263|      0|    default:
  ------------------
  |  Branch (263:5): [True: 0, False: 14.3k]
  ------------------
  264|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  265|      0|      return -1;
  266|  14.3k|  }
  267|  14.3k|}
tasn_enc.c:asn1_template_ex_i2d:
  274|  11.0k|                                int optional) {
  275|  11.0k|  int i, ret, ttag, tclass;
  276|  11.0k|  size_t j;
  277|  11.0k|  uint32_t flags = tt->flags;
  278|       |
  279|       |  // Historically, |iclass| was repurposed to pass additional flags into the
  280|       |  // encoding process.
  281|  11.0k|  assert((iclass & ASN1_TFLG_TAG_CLASS) == iclass);
  282|       |  // If not overridding the tag, |iclass| is ignored and should be zero.
  283|  11.0k|  assert(tag != -1 || iclass == 0);
  284|       |
  285|       |  // Work out tag and class to use: tagging may come either from the
  286|       |  // template or the arguments, not both because this would create
  287|       |  // ambiguity.
  288|  11.0k|  if (flags & ASN1_TFLG_TAG_MASK) {
  ------------------
  |  |  404|  11.0k|#define ASN1_TFLG_TAG_MASK	(0x3 << 3)
  ------------------
  |  Branch (288:7): [True: 0, False: 11.0k]
  ------------------
  289|       |    // Error if argument and template tagging
  290|      0|    if (tag != -1) {
  ------------------
  |  Branch (290:9): [True: 0, False: 0]
  ------------------
  291|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  292|      0|      return -1;
  293|      0|    }
  294|       |    // Get tagging from template
  295|      0|    ttag = tt->tag;
  296|      0|    tclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|      0|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  297|  11.0k|  } else if (tag != -1) {
  ------------------
  |  Branch (297:14): [True: 0, False: 11.0k]
  ------------------
  298|       |    // No template tagging, get from arguments
  299|      0|    ttag = tag;
  300|      0|    tclass = iclass & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|      0|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  301|  11.0k|  } else {
  302|  11.0k|    ttag = -1;
  303|  11.0k|    tclass = 0;
  304|  11.0k|  }
  305|       |
  306|       |  // The template may itself by marked as optional, or this may be the template
  307|       |  // of an |ASN1_ITEM_TEMPLATE| type which was contained inside an outer
  308|       |  // optional template. (They cannot both be true because the
  309|       |  // |ASN1_ITEM_TEMPLATE| codepath rejects optional templates.)
  310|  11.0k|  assert(!optional || (flags & ASN1_TFLG_OPTIONAL) == 0);
  311|  11.0k|  optional = optional || (flags & ASN1_TFLG_OPTIONAL) != 0;
  ------------------
  |  |  381|  11.0k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (311:14): [True: 0, False: 11.0k]
  |  Branch (311:26): [True: 0, False: 11.0k]
  ------------------
  312|       |
  313|       |  // At this point 'ttag' contains the outer tag to use, and 'tclass' is the
  314|       |  // class.
  315|       |
  316|  11.0k|  if (flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|  11.0k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (316:7): [True: 2.20k, False: 8.83k]
  ------------------
  317|       |    // SET OF, SEQUENCE OF
  318|  2.20k|    STACK_OF(ASN1_VALUE) *sk = (STACK_OF(ASN1_VALUE) *)*pval;
  ------------------
  |  |   81|  2.20k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  319|  2.20k|    int isset, sktag, skaclass;
  320|  2.20k|    int skcontlen, sklen;
  321|  2.20k|    ASN1_VALUE *skitem;
  322|       |
  323|  2.20k|    if (!*pval) {
  ------------------
  |  Branch (323:9): [True: 0, False: 2.20k]
  ------------------
  324|      0|      if (optional) {
  ------------------
  |  Branch (324:11): [True: 0, False: 0]
  ------------------
  325|      0|        return 0;
  326|      0|      }
  327|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|      0|      return -1;
  329|      0|    }
  330|       |
  331|  2.20k|    if (flags & ASN1_TFLG_SET_OF) {
  ------------------
  |  |  384|  2.20k|#define ASN1_TFLG_SET_OF	(0x1 << 1)
  ------------------
  |  Branch (331:9): [True: 2.20k, False: 0]
  ------------------
  332|  2.20k|      isset = 1;
  333|       |      // Historically, types with both bits set were mutated when
  334|       |      // serialized to apply the sort. We no longer support this.
  335|  2.20k|      assert((flags & ASN1_TFLG_SEQUENCE_OF) == 0);
  336|  2.20k|    } else {
  337|      0|      isset = 0;
  338|      0|    }
  339|       |
  340|       |    // Work out inner tag value: if EXPLICIT or no tagging use underlying
  341|       |    // type.
  342|  2.20k|    if ((ttag != -1) && !(flags & ASN1_TFLG_EXPTAG)) {
  ------------------
  |  |  402|      0|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (342:9): [True: 0, False: 2.20k]
  |  Branch (342:25): [True: 0, False: 0]
  ------------------
  343|      0|      sktag = ttag;
  344|      0|      skaclass = tclass;
  345|  2.20k|    } else {
  346|  2.20k|      skaclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  2.20k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  347|  2.20k|      if (isset) {
  ------------------
  |  Branch (347:11): [True: 2.20k, False: 0]
  ------------------
  348|  2.20k|        sktag = V_ASN1_SET;
  ------------------
  |  |  137|  2.20k|#define V_ASN1_SET 17
  ------------------
  349|  2.20k|      } else {
  350|      0|        sktag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|      0|#define V_ASN1_SEQUENCE 16
  ------------------
  351|      0|      }
  352|  2.20k|    }
  353|       |
  354|       |    // Determine total length of items
  355|  2.20k|    skcontlen = 0;
  356|  4.41k|    for (j = 0; j < sk_ASN1_VALUE_num(sk); j++) {
  ------------------
  |  Branch (356:17): [True: 2.20k, False: 2.20k]
  ------------------
  357|  2.20k|      int tmplen;
  358|  2.20k|      skitem = sk_ASN1_VALUE_value(sk, j);
  359|  2.20k|      tmplen = ASN1_item_ex_i2d(&skitem, NULL, ASN1_ITEM_ptr(tt->item), -1, 0);
  ------------------
  |  |  288|  2.20k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  360|  2.20k|      if (tmplen == -1 || (skcontlen > INT_MAX - tmplen)) {
  ------------------
  |  Branch (360:11): [True: 0, False: 2.20k]
  |  Branch (360:27): [True: 0, False: 2.20k]
  ------------------
  361|      0|        return -1;
  362|      0|      }
  363|  2.20k|      skcontlen += tmplen;
  364|  2.20k|    }
  365|  2.20k|    sklen = ASN1_object_size(/*constructed=*/1, skcontlen, sktag);
  366|  2.20k|    if (sklen == -1) {
  ------------------
  |  Branch (366:9): [True: 0, False: 2.20k]
  ------------------
  367|      0|      return -1;
  368|      0|    }
  369|       |    // If EXPLICIT need length of surrounding tag
  370|  2.20k|    if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  2.20k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (370:9): [True: 0, False: 2.20k]
  ------------------
  371|      0|      ret = ASN1_object_size(/*constructed=*/1, sklen, ttag);
  372|  2.20k|    } else {
  373|  2.20k|      ret = sklen;
  374|  2.20k|    }
  375|       |
  376|  2.20k|    if (!out || ret == -1) {
  ------------------
  |  Branch (376:9): [True: 1.10k, False: 1.10k]
  |  Branch (376:17): [True: 0, False: 1.10k]
  ------------------
  377|  1.10k|      return ret;
  378|  1.10k|    }
  379|       |
  380|       |    // Now encode this lot...
  381|       |    // EXPLICIT tag
  382|  1.10k|    if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  1.10k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (382:9): [True: 0, False: 1.10k]
  ------------------
  383|      0|      ASN1_put_object(out, /*constructed=*/1, sklen, ttag, tclass);
  384|      0|    }
  385|       |    // SET or SEQUENCE and IMPLICIT tag
  386|  1.10k|    ASN1_put_object(out, /*constructed=*/1, skcontlen, sktag, skaclass);
  387|       |    // And the stuff itself
  388|  1.10k|    if (!asn1_set_seq_out(sk, out, skcontlen, ASN1_ITEM_ptr(tt->item), isset)) {
  ------------------
  |  |  288|  1.10k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (388:9): [True: 0, False: 1.10k]
  ------------------
  389|      0|      return -1;
  390|      0|    }
  391|  1.10k|    return ret;
  392|  1.10k|  }
  393|       |
  394|  8.83k|  if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  8.83k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (394:7): [True: 0, False: 8.83k]
  ------------------
  395|       |    // EXPLICIT tagging
  396|       |    // Find length of tagged item
  397|      0|    i = asn1_item_ex_i2d_opt(pval, NULL, ASN1_ITEM_ptr(tt->item), -1, 0,
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  398|      0|                             optional);
  399|      0|    if (i <= 0) {
  ------------------
  |  Branch (399:9): [True: 0, False: 0]
  ------------------
  400|      0|      return i;
  401|      0|    }
  402|       |    // Find length of EXPLICIT tag
  403|      0|    ret = ASN1_object_size(/*constructed=*/1, i, ttag);
  404|      0|    if (out && ret != -1) {
  ------------------
  |  Branch (404:9): [True: 0, False: 0]
  |  Branch (404:16): [True: 0, False: 0]
  ------------------
  405|       |      // Output tag and item
  406|      0|      ASN1_put_object(out, /*constructed=*/1, i, ttag, tclass);
  407|      0|      if (ASN1_item_ex_i2d(pval, out, ASN1_ITEM_ptr(tt->item), -1, 0) < 0) {
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (407:11): [True: 0, False: 0]
  ------------------
  408|      0|        return -1;
  409|      0|      }
  410|      0|    }
  411|      0|    return ret;
  412|      0|  }
  413|       |
  414|       |  // Either normal or IMPLICIT tagging
  415|  8.83k|  return asn1_item_ex_i2d_opt(pval, out, ASN1_ITEM_ptr(tt->item), ttag, tclass,
  ------------------
  |  |  288|  8.83k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  416|  8.83k|                              optional);
  417|  8.83k|}
tasn_enc.c:asn1_set_seq_out:
  443|  1.10k|                            int skcontlen, const ASN1_ITEM *item, int do_sort) {
  444|       |  // No need to sort if there are fewer than two items.
  445|  1.10k|  if (!do_sort || sk_ASN1_VALUE_num(sk) < 2) {
  ------------------
  |  Branch (445:7): [True: 0, False: 1.10k]
  |  Branch (445:19): [True: 1.10k, False: 0]
  ------------------
  446|  2.20k|    for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (446:24): [True: 1.10k, False: 1.10k]
  ------------------
  447|  1.10k|      ASN1_VALUE *skitem = sk_ASN1_VALUE_value(sk, i);
  448|  1.10k|      if (ASN1_item_ex_i2d(&skitem, out, item, -1, 0) < 0) {
  ------------------
  |  Branch (448:11): [True: 0, False: 1.10k]
  ------------------
  449|      0|        return 0;
  450|      0|      }
  451|  1.10k|    }
  452|  1.10k|    return 1;
  453|  1.10k|  }
  454|       |
  455|      0|  if (sk_ASN1_VALUE_num(sk) > ((size_t)-1) / sizeof(DER_ENC)) {
  ------------------
  |  Branch (455:7): [True: 0, False: 0]
  ------------------
  456|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  457|      0|    return 0;
  458|      0|  }
  459|       |
  460|      0|  int ret = 0;
  461|      0|  unsigned char *const buf = OPENSSL_malloc(skcontlen);
  462|      0|  DER_ENC *encoded = OPENSSL_malloc(sk_ASN1_VALUE_num(sk) * sizeof(*encoded));
  463|      0|  if (encoded == NULL || buf == NULL) {
  ------------------
  |  Branch (463:7): [True: 0, False: 0]
  |  Branch (463:26): [True: 0, False: 0]
  ------------------
  464|      0|    goto err;
  465|      0|  }
  466|       |
  467|       |  // Encode all the elements into |buf| and populate |encoded|.
  468|      0|  unsigned char *p = buf;
  469|      0|  for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (469:22): [True: 0, False: 0]
  ------------------
  470|      0|    ASN1_VALUE *skitem = sk_ASN1_VALUE_value(sk, i);
  471|      0|    encoded[i].data = p;
  472|      0|    encoded[i].length = ASN1_item_ex_i2d(&skitem, &p, item, -1, 0);
  473|      0|    if (encoded[i].length < 0) {
  ------------------
  |  Branch (473:9): [True: 0, False: 0]
  ------------------
  474|      0|      goto err;
  475|      0|    }
  476|      0|    assert(p - buf <= skcontlen);
  477|      0|  }
  478|       |
  479|      0|  qsort(encoded, sk_ASN1_VALUE_num(sk), sizeof(*encoded), der_cmp);
  480|       |
  481|       |  // Output the elements in sorted order.
  482|      0|  p = *out;
  483|      0|  for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (483:22): [True: 0, False: 0]
  ------------------
  484|      0|    OPENSSL_memcpy(p, encoded[i].data, encoded[i].length);
  485|      0|    p += encoded[i].length;
  486|      0|  }
  487|      0|  *out = p;
  488|       |
  489|      0|  ret = 1;
  490|       |
  491|      0|err:
  492|      0|  OPENSSL_free(encoded);
  493|      0|  OPENSSL_free(buf);
  494|      0|  return ret;
  495|      0|}
tasn_enc.c:asn1_i2d_ex_primitive:
  501|  8.83k|                                 int optional) {
  502|       |  // Get length of content octets and maybe find out the underlying type.
  503|  8.83k|  int omit;
  504|  8.83k|  int utype = it->utype;
  505|  8.83k|  int len = asn1_ex_i2c(pval, NULL, &omit, &utype, it);
  506|  8.83k|  if (len < 0) {
  ------------------
  |  Branch (506:7): [True: 0, False: 8.83k]
  ------------------
  507|      0|    return -1;
  508|      0|  }
  509|  8.83k|  if (omit) {
  ------------------
  |  Branch (509:7): [True: 0, False: 8.83k]
  ------------------
  510|      0|    if (optional) {
  ------------------
  |  Branch (510:9): [True: 0, False: 0]
  ------------------
  511|      0|      return 0;
  512|      0|    }
  513|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  514|      0|    return -1;
  515|      0|  }
  516|       |
  517|       |  // If SEQUENCE, SET or OTHER then header is included in pseudo content
  518|       |  // octets so don't include tag+length. We need to check here because the
  519|       |  // call to asn1_ex_i2c() could change utype.
  520|  8.83k|  int usetag =
  521|  8.83k|      utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  136|  17.6k|#define V_ASN1_SEQUENCE 16
  ------------------
                    utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  137|  17.6k|#define V_ASN1_SET 17
  ------------------
                    utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  118|  8.81k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (521:7): [True: 8.81k, False: 20]
  |  Branch (521:35): [True: 8.81k, False: 0]
  |  Branch (521:58): [True: 8.81k, False: 0]
  ------------------
  522|       |
  523|       |  // If not implicitly tagged get tag from underlying type
  524|  8.83k|  if (tag == -1) {
  ------------------
  |  Branch (524:7): [True: 8.83k, False: 0]
  ------------------
  525|  8.83k|    tag = utype;
  526|  8.83k|  }
  527|       |
  528|       |  // Output tag+length followed by content octets
  529|  8.83k|  if (out) {
  ------------------
  |  Branch (529:7): [True: 2.20k, False: 6.62k]
  ------------------
  530|  2.20k|    if (usetag) {
  ------------------
  |  Branch (530:9): [True: 2.20k, False: 5]
  ------------------
  531|  2.20k|      ASN1_put_object(out, /*constructed=*/0, len, tag, aclass);
  532|  2.20k|    }
  533|  2.20k|    int len2 = asn1_ex_i2c(pval, *out, &omit, &utype, it);
  534|  2.20k|    if (len2 < 0) {
  ------------------
  |  Branch (534:9): [True: 0, False: 2.20k]
  ------------------
  535|      0|      return -1;
  536|      0|    }
  537|  2.20k|    assert(len == len2);
  538|  2.20k|    assert(!omit);
  539|  2.20k|    *out += len;
  540|  2.20k|  }
  541|       |
  542|  8.83k|  if (usetag) {
  ------------------
  |  Branch (542:7): [True: 8.81k, False: 20]
  ------------------
  543|  8.81k|    return ASN1_object_size(/*constructed=*/0, len, tag);
  544|  8.81k|  }
  545|     20|  return len;
  546|  8.83k|}
tasn_enc.c:asn1_ex_i2c:
  565|  11.0k|                       int *putype, const ASN1_ITEM *it) {
  566|  11.0k|  ASN1_BOOLEAN *tbool = NULL;
  567|  11.0k|  ASN1_STRING *strtmp;
  568|  11.0k|  ASN1_OBJECT *otmp;
  569|  11.0k|  int utype;
  570|  11.0k|  const unsigned char *cont;
  571|  11.0k|  unsigned char c;
  572|  11.0k|  int len;
  573|       |
  574|       |  // Historically, |it->funcs| for primitive types contained an
  575|       |  // |ASN1_PRIMITIVE_FUNCS| table of callbacks.
  576|  11.0k|  assert(it->funcs == NULL);
  577|       |
  578|  11.0k|  *out_omit = 0;
  579|       |
  580|       |  // Should type be omitted?
  581|  11.0k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) || (it->utype != V_ASN1_BOOLEAN)) {
  ------------------
  |  |  487|  11.0k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
                if ((it->itype != ASN1_ITYPE_PRIMITIVE) || (it->utype != V_ASN1_BOOLEAN)) {
  ------------------
  |  |  125|  5.52k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (581:7): [True: 5.52k, False: 5.52k]
  |  Branch (581:46): [True: 5.52k, False: 0]
  ------------------
  582|  11.0k|    if (!*pval) {
  ------------------
  |  Branch (582:9): [True: 0, False: 11.0k]
  ------------------
  583|      0|      *out_omit = 1;
  584|      0|      return 0;
  585|      0|    }
  586|  11.0k|  }
  587|       |
  588|  11.0k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|  11.0k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (588:7): [True: 5.52k, False: 5.52k]
  ------------------
  589|       |    // If MSTRING type set the underlying type
  590|  5.52k|    strtmp = (ASN1_STRING *)*pval;
  591|  5.52k|    utype = strtmp->type;
  592|  5.52k|    if (utype < 0 && utype != V_ASN1_OTHER) {
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (592:9): [True: 0, False: 5.52k]
  |  Branch (592:22): [True: 0, False: 0]
  ------------------
  593|       |      // MSTRINGs can have type -1 when default-constructed.
  594|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  595|      0|      return -1;
  596|      0|    }
  597|       |    // Negative INTEGER and ENUMERATED values use |ASN1_STRING| type values
  598|       |    // that do not match their corresponding utype values. INTEGERs cannot
  599|       |    // participate in MSTRING types, but ENUMERATEDs can.
  600|       |    //
  601|       |    // TODO(davidben): Is this a bug? Although arguably one of the MSTRING
  602|       |    // types should contain more values, rather than less. See
  603|       |    // https://crbug.com/boringssl/412. But it is not possible to fit all
  604|       |    // possible ANY values into an |ASN1_STRING|, so matching the spec here
  605|       |    // is somewhat hopeless.
  606|  5.52k|    if (utype == V_ASN1_NEG_INTEGER) {
  ------------------
  |  |  156|  5.52k|#define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  126|  5.52k|#define V_ASN1_INTEGER 2
  |  |  ------------------
  |  |               #define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|  5.52k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  |  Branch (606:9): [True: 0, False: 5.52k]
  ------------------
  607|      0|      utype = V_ASN1_INTEGER;
  ------------------
  |  |  126|      0|#define V_ASN1_INTEGER 2
  ------------------
  608|  5.52k|    } else if (utype == V_ASN1_NEG_ENUMERATED) {
  ------------------
  |  |  157|  5.52k|#define V_ASN1_NEG_ENUMERATED (V_ASN1_ENUMERATED | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  134|  5.52k|#define V_ASN1_ENUMERATED 10
  |  |  ------------------
  |  |               #define V_ASN1_NEG_ENUMERATED (V_ASN1_ENUMERATED | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|  5.52k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  |  Branch (608:16): [True: 30, False: 5.49k]
  ------------------
  609|     30|      utype = V_ASN1_ENUMERATED;
  ------------------
  |  |  134|     30|#define V_ASN1_ENUMERATED 10
  ------------------
  610|     30|    }
  611|  5.52k|    *putype = utype;
  612|  5.52k|  } else if (it->utype == V_ASN1_ANY) {
  ------------------
  |  |  121|  5.52k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (612:14): [True: 0, False: 5.52k]
  ------------------
  613|       |    // If ANY set type and pointer to value
  614|      0|    ASN1_TYPE *typ;
  615|      0|    typ = (ASN1_TYPE *)*pval;
  616|      0|    utype = typ->type;
  617|      0|    if (utype < 0 && utype != V_ASN1_OTHER) {
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (617:9): [True: 0, False: 0]
  |  Branch (617:22): [True: 0, False: 0]
  ------------------
  618|       |      // |ASN1_TYPE|s can have type -1 when default-constructed.
  619|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  620|      0|      return -1;
  621|      0|    }
  622|      0|    *putype = utype;
  623|      0|    pval = &typ->value.asn1_value;
  624|  5.52k|  } else {
  625|  5.52k|    utype = *putype;
  626|  5.52k|  }
  627|       |
  628|  11.0k|  switch (utype) {
  629|  5.52k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  5.52k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (629:5): [True: 5.52k, False: 5.52k]
  ------------------
  630|  5.52k|      otmp = (ASN1_OBJECT *)*pval;
  631|  5.52k|      cont = otmp->data;
  632|  5.52k|      len = otmp->length;
  633|  5.52k|      if (len == 0) {
  ------------------
  |  Branch (633:11): [True: 0, False: 5.52k]
  ------------------
  634|       |        // Some |ASN1_OBJECT|s do not have OIDs and cannot be serialized.
  635|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OBJECT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  636|      0|        return -1;
  637|      0|      }
  638|  5.52k|      break;
  639|       |
  640|  5.52k|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (640:5): [True: 0, False: 11.0k]
  ------------------
  641|      0|      cont = NULL;
  642|      0|      len = 0;
  643|      0|      break;
  644|       |
  645|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (645:5): [True: 0, False: 11.0k]
  ------------------
  646|      0|      tbool = (ASN1_BOOLEAN *)pval;
  647|      0|      if (*tbool == ASN1_BOOLEAN_NONE) {
  ------------------
  |  |  432|      0|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
  |  Branch (647:11): [True: 0, False: 0]
  ------------------
  648|      0|        *out_omit = 1;
  649|      0|        return 0;
  650|      0|      }
  651|      0|      if (it->utype != V_ASN1_ANY) {
  ------------------
  |  |  121|      0|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (651:11): [True: 0, False: 0]
  ------------------
  652|       |        // Default handling if value == size field then omit
  653|      0|        if ((*tbool && (it->size > 0)) || (!*tbool && !it->size)) {
  ------------------
  |  Branch (653:14): [True: 0, False: 0]
  |  Branch (653:24): [True: 0, False: 0]
  |  Branch (653:44): [True: 0, False: 0]
  |  Branch (653:55): [True: 0, False: 0]
  ------------------
  654|      0|          *out_omit = 1;
  655|      0|          return 0;
  656|      0|        }
  657|      0|      }
  658|      0|      c = *tbool ? 0xff : 0x00;
  ------------------
  |  Branch (658:11): [True: 0, False: 0]
  ------------------
  659|      0|      cont = &c;
  660|      0|      len = 1;
  661|      0|      break;
  662|       |
  663|      0|    case V_ASN1_BIT_STRING: {
  ------------------
  |  |  127|      0|#define V_ASN1_BIT_STRING 3
  ------------------
  |  Branch (663:5): [True: 0, False: 11.0k]
  ------------------
  664|      0|      int ret =
  665|      0|          i2c_ASN1_BIT_STRING((ASN1_BIT_STRING *)*pval, cout ? &cout : NULL);
  ------------------
  |  Branch (665:57): [True: 0, False: 0]
  ------------------
  666|       |      // |i2c_ASN1_BIT_STRING| returns zero on error instead of -1.
  667|      0|      return ret <= 0 ? -1 : ret;
  ------------------
  |  Branch (667:14): [True: 0, False: 0]
  ------------------
  668|      0|    }
  669|       |
  670|      0|    case V_ASN1_INTEGER:
  ------------------
  |  |  126|      0|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (670:5): [True: 0, False: 11.0k]
  ------------------
  671|     40|    case V_ASN1_ENUMERATED: {
  ------------------
  |  |  134|     40|#define V_ASN1_ENUMERATED 10
  ------------------
  |  Branch (671:5): [True: 40, False: 11.0k]
  ------------------
  672|       |      // |i2c_ASN1_INTEGER| also handles ENUMERATED.
  673|     40|      int ret = i2c_ASN1_INTEGER((ASN1_INTEGER *)*pval, cout ? &cout : NULL);
  ------------------
  |  Branch (673:57): [True: 8, False: 32]
  ------------------
  674|       |      // |i2c_ASN1_INTEGER| returns zero on error instead of -1.
  675|     40|      return ret <= 0 ? -1 : ret;
  ------------------
  |  Branch (675:14): [True: 0, False: 40]
  ------------------
  676|      0|    }
  677|       |
  678|      0|    case V_ASN1_OCTET_STRING:
  ------------------
  |  |  128|      0|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (678:5): [True: 0, False: 11.0k]
  ------------------
  679|      0|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|      0|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (679:5): [True: 0, False: 11.0k]
  ------------------
  680|      0|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|      0|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (680:5): [True: 0, False: 11.0k]
  ------------------
  681|      0|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|      0|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (681:5): [True: 0, False: 11.0k]
  ------------------
  682|      0|    case V_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  142|      0|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (682:5): [True: 0, False: 11.0k]
  ------------------
  683|      0|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|      0|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (683:5): [True: 0, False: 11.0k]
  ------------------
  684|      0|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|      0|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (684:5): [True: 0, False: 11.0k]
  ------------------
  685|      0|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|      0|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (685:5): [True: 0, False: 11.0k]
  ------------------
  686|      0|    case V_ASN1_GRAPHICSTRING:
  ------------------
  |  |  146|      0|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (686:5): [True: 0, False: 11.0k]
  ------------------
  687|      0|    case V_ASN1_VISIBLESTRING:
  ------------------
  |  |  148|      0|#define V_ASN1_VISIBLESTRING 26
  ------------------
  |  Branch (687:5): [True: 0, False: 11.0k]
  ------------------
  688|      0|    case V_ASN1_GENERALSTRING:
  ------------------
  |  |  149|      0|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (688:5): [True: 0, False: 11.0k]
  ------------------
  689|      0|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|      0|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (689:5): [True: 0, False: 11.0k]
  ------------------
  690|      0|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|      0|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (690:5): [True: 0, False: 11.0k]
  ------------------
  691|  5.42k|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|  5.42k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (691:5): [True: 5.42k, False: 5.61k]
  ------------------
  692|  5.45k|    case V_ASN1_SEQUENCE:
  ------------------
  |  |  136|  5.45k|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (692:5): [True: 25, False: 11.0k]
  ------------------
  693|  5.45k|    case V_ASN1_SET:
  ------------------
  |  |  137|  5.45k|#define V_ASN1_SET 17
  ------------------
  |  Branch (693:5): [True: 0, False: 11.0k]
  ------------------
  694|       |    // This is not a valid |ASN1_ITEM| type, but it appears in |ASN1_TYPE|.
  695|  5.45k|    case V_ASN1_OTHER:
  ------------------
  |  |  118|  5.45k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (695:5): [True: 0, False: 11.0k]
  ------------------
  696|       |    // TODO(crbug.com/boringssl/412): This default case should be removed, now
  697|       |    // that we've resolved https://crbug.com/boringssl/561. However, it is still
  698|       |    // needed to support some edge cases in |ASN1_PRINTABLE|. |ASN1_PRINTABLE|
  699|       |    // broadly doesn't tolerate unrecognized universal tags, but except for
  700|       |    // eight values that map to |B_ASN1_UNKNOWN| instead of zero. See the
  701|       |    // X509Test.NameAttributeValues test.
  702|  5.48k|    default:
  ------------------
  |  Branch (702:5): [True: 30, False: 11.0k]
  ------------------
  703|       |      // All based on ASN1_STRING and handled the same
  704|  5.48k|      strtmp = (ASN1_STRING *)*pval;
  705|  5.48k|      cont = strtmp->data;
  706|  5.48k|      len = strtmp->length;
  707|  5.48k|      break;
  708|  11.0k|  }
  709|  11.0k|  if (cout && len) {
  ------------------
  |  Branch (709:7): [True: 2.20k, False: 8.80k]
  |  Branch (709:15): [True: 2.19k, False: 8]
  ------------------
  710|  2.19k|    OPENSSL_memcpy(cout, cont, len);
  711|  2.19k|  }
  712|  11.0k|  return len;
  713|  11.0k|}

ASN1_item_free:
   68|  6.72k|void ASN1_item_free(ASN1_VALUE *val, const ASN1_ITEM *it) {
   69|  6.72k|  ASN1_item_ex_free(&val, it);
   70|  6.72k|}
ASN1_item_ex_free:
   72|  24.6k|void ASN1_item_ex_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
   73|  24.6k|  const ASN1_TEMPLATE *tt = NULL, *seqtt;
   74|  24.6k|  const ASN1_EXTERN_FUNCS *ef;
   75|  24.6k|  int i;
   76|  24.6k|  if (!pval) {
  ------------------
  |  Branch (76:7): [True: 0, False: 24.6k]
  ------------------
   77|      0|    return;
   78|      0|  }
   79|  24.6k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) && !*pval) {
  ------------------
  |  |  487|  24.6k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (79:7): [True: 14.3k, False: 10.3k]
  |  Branch (79:46): [True: 3.97k, False: 10.3k]
  ------------------
   80|  3.97k|    return;
   81|  3.97k|  }
   82|       |
   83|  20.6k|  switch (it->itype) {
  ------------------
  |  Branch (83:11): [True: 0, False: 20.6k]
  ------------------
   84|  10.3k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  10.3k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (84:5): [True: 10.3k, False: 10.3k]
  ------------------
   85|  10.3k|      if (it->templates) {
  ------------------
  |  Branch (85:11): [True: 1.31k, False: 8.98k]
  ------------------
   86|  1.31k|        ASN1_template_free(pval, it->templates);
   87|  8.98k|      } else {
   88|  8.98k|        ASN1_primitive_free(pval, it);
   89|  8.98k|      }
   90|  10.3k|      break;
   91|       |
   92|  3.57k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  3.57k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (92:5): [True: 3.57k, False: 17.0k]
  ------------------
   93|  3.57k|      ASN1_primitive_free(pval, it);
   94|  3.57k|      break;
   95|       |
   96|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (96:5): [True: 0, False: 20.6k]
  ------------------
   97|      0|      const ASN1_AUX *aux = it->funcs;
   98|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (98:30): [True: 0, False: 0]
  ------------------
   99|      0|      if (asn1_cb) {
  ------------------
  |  Branch (99:11): [True: 0, False: 0]
  ------------------
  100|      0|        i = asn1_cb(ASN1_OP_FREE_PRE, pval, it, NULL);
  ------------------
  |  |  539|      0|#define ASN1_OP_FREE_PRE	2
  ------------------
  101|      0|        if (i == 2) {
  ------------------
  |  Branch (101:13): [True: 0, False: 0]
  ------------------
  102|      0|          return;
  103|      0|        }
  104|      0|      }
  105|      0|      i = asn1_get_choice_selector(pval, it);
  106|      0|      if ((i >= 0) && (i < it->tcount)) {
  ------------------
  |  Branch (106:11): [True: 0, False: 0]
  |  Branch (106:23): [True: 0, False: 0]
  ------------------
  107|      0|        ASN1_VALUE **pchval;
  108|      0|        tt = it->templates + i;
  109|      0|        pchval = asn1_get_field_ptr(pval, tt);
  110|      0|        ASN1_template_free(pchval, tt);
  111|      0|      }
  112|      0|      if (asn1_cb) {
  ------------------
  |  Branch (112:11): [True: 0, False: 0]
  ------------------
  113|      0|        asn1_cb(ASN1_OP_FREE_POST, pval, it, NULL);
  ------------------
  |  |  540|      0|#define ASN1_OP_FREE_POST	3
  ------------------
  114|      0|      }
  115|      0|      OPENSSL_free(*pval);
  116|      0|      *pval = NULL;
  117|      0|      break;
  118|      0|    }
  119|       |
  120|  1.22k|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|  1.22k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (120:5): [True: 1.22k, False: 19.4k]
  ------------------
  121|  1.22k|      ef = it->funcs;
  122|  1.22k|      if (ef && ef->asn1_ex_free) {
  ------------------
  |  Branch (122:11): [True: 1.22k, False: 0]
  |  Branch (122:17): [True: 1.22k, False: 0]
  ------------------
  123|  1.22k|        ef->asn1_ex_free(pval, it);
  124|  1.22k|      }
  125|  1.22k|      break;
  126|       |
  127|  5.54k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  5.54k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (127:5): [True: 5.54k, False: 15.0k]
  ------------------
  128|  5.54k|      if (!asn1_refcount_dec_and_test_zero(pval, it)) {
  ------------------
  |  Branch (128:11): [True: 0, False: 5.54k]
  ------------------
  129|      0|        return;
  130|      0|      }
  131|  5.54k|      const ASN1_AUX *aux = it->funcs;
  132|  5.54k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (132:30): [True: 1.22k, False: 4.32k]
  ------------------
  133|  5.54k|      if (asn1_cb) {
  ------------------
  |  Branch (133:11): [True: 610, False: 4.93k]
  ------------------
  134|    610|        i = asn1_cb(ASN1_OP_FREE_PRE, pval, it, NULL);
  ------------------
  |  |  539|    610|#define ASN1_OP_FREE_PRE	2
  ------------------
  135|    610|        if (i == 2) {
  ------------------
  |  Branch (135:13): [True: 0, False: 610]
  ------------------
  136|      0|          return;
  137|      0|        }
  138|    610|      }
  139|  5.54k|      asn1_enc_free(pval, it);
  140|       |      // If we free up as normal we will invalidate any ANY DEFINED BY
  141|       |      // field and we wont be able to determine the type of the field it
  142|       |      // defines. So free up in reverse order.
  143|  5.54k|      tt = it->templates + it->tcount - 1;
  144|  21.6k|      for (i = 0; i < it->tcount; tt--, i++) {
  ------------------
  |  Branch (144:19): [True: 16.0k, False: 5.54k]
  ------------------
  145|  16.0k|        ASN1_VALUE **pseqval;
  146|  16.0k|        seqtt = asn1_do_adb(pval, tt, 0);
  147|  16.0k|        if (!seqtt) {
  ------------------
  |  Branch (147:13): [True: 0, False: 16.0k]
  ------------------
  148|      0|          continue;
  149|      0|        }
  150|  16.0k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  151|  16.0k|        ASN1_template_free(pseqval, seqtt);
  152|  16.0k|      }
  153|  5.54k|      if (asn1_cb) {
  ------------------
  |  Branch (153:11): [True: 610, False: 4.93k]
  ------------------
  154|    610|        asn1_cb(ASN1_OP_FREE_POST, pval, it, NULL);
  ------------------
  |  |  540|    610|#define ASN1_OP_FREE_POST	3
  ------------------
  155|    610|      }
  156|  5.54k|      OPENSSL_free(*pval);
  157|  5.54k|      *pval = NULL;
  158|  5.54k|      break;
  159|  5.54k|    }
  160|  20.6k|  }
  161|  20.6k|}
ASN1_template_free:
  163|  18.6k|void ASN1_template_free(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  164|  18.6k|  if (tt->flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|  18.6k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (164:7): [True: 2.07k, False: 16.5k]
  ------------------
  165|  2.07k|    STACK_OF(ASN1_VALUE) *sk = (STACK_OF(ASN1_VALUE) *)*pval;
  ------------------
  |  |   81|  2.07k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  166|  2.36k|    for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (166:24): [True: 290, False: 2.07k]
  ------------------
  167|    290|      ASN1_VALUE *vtmp = sk_ASN1_VALUE_value(sk, i);
  168|    290|      ASN1_item_ex_free(&vtmp, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|    290|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  169|    290|    }
  170|  2.07k|    sk_ASN1_VALUE_free(sk);
  171|  2.07k|    *pval = NULL;
  172|  16.5k|  } else {
  173|  16.5k|    ASN1_item_ex_free(pval, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|  16.5k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  174|  16.5k|  }
  175|  18.6k|}
ASN1_primitive_free:
  177|  12.5k|void ASN1_primitive_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  178|       |  // Historically, |it->funcs| for primitive types contained an
  179|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  180|  12.5k|  assert(it->funcs == NULL);
  181|       |
  182|  12.5k|  int utype = it->itype == ASN1_ITYPE_MSTRING ? -1 : it->utype;
  ------------------
  |  |  495|  12.5k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (182:15): [True: 3.57k, False: 8.98k]
  ------------------
  183|  12.5k|  switch (utype) {
  184|  3.72k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  3.72k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (184:5): [True: 3.72k, False: 8.83k]
  ------------------
  185|  3.72k|      ASN1_OBJECT_free((ASN1_OBJECT *)*pval);
  186|  3.72k|      break;
  187|       |
  188|    193|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|    193|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (188:5): [True: 193, False: 12.3k]
  ------------------
  189|    193|      if (it) {
  ------------------
  |  Branch (189:11): [True: 193, False: 0]
  ------------------
  190|    193|        *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  191|    193|      } else {
  192|      0|        *(ASN1_BOOLEAN *)pval = ASN1_BOOLEAN_NONE;
  ------------------
  |  |  432|      0|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
  193|      0|      }
  194|    193|      return;
  195|       |
  196|      0|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (196:5): [True: 0, False: 12.5k]
  ------------------
  197|      0|      break;
  198|       |
  199|  1.71k|    case V_ASN1_ANY:
  ------------------
  |  |  121|  1.71k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (199:5): [True: 1.71k, False: 10.8k]
  ------------------
  200|  1.71k|      if (*pval != NULL) {
  ------------------
  |  Branch (200:11): [True: 673, False: 1.04k]
  ------------------
  201|    673|        asn1_type_cleanup((ASN1_TYPE *)*pval);
  202|    673|        OPENSSL_free(*pval);
  203|    673|      }
  204|  1.71k|      break;
  205|       |
  206|  6.92k|    default:
  ------------------
  |  Branch (206:5): [True: 6.92k, False: 5.63k]
  ------------------
  207|  6.92k|      ASN1_STRING_free((ASN1_STRING *)*pval);
  208|  6.92k|      *pval = NULL;
  209|  6.92k|      break;
  210|  12.5k|  }
  211|  12.3k|  *pval = NULL;
  212|  12.3k|}

ASN1_item_new:
   76|  1.78k|ASN1_VALUE *ASN1_item_new(const ASN1_ITEM *it) {
   77|  1.78k|  ASN1_VALUE *ret = NULL;
   78|  1.78k|  if (ASN1_item_ex_new(&ret, it) > 0) {
  ------------------
  |  Branch (78:7): [True: 1.78k, False: 0]
  ------------------
   79|  1.78k|    return ret;
   80|  1.78k|  }
   81|      0|  return NULL;
   82|  1.78k|}
ASN1_item_ex_new:
   86|  16.0k|int ASN1_item_ex_new(ASN1_VALUE **pval, const ASN1_ITEM *it) {
   87|  16.0k|  const ASN1_TEMPLATE *tt = NULL;
   88|  16.0k|  const ASN1_EXTERN_FUNCS *ef;
   89|  16.0k|  ASN1_VALUE **pseqval;
   90|  16.0k|  int i;
   91|       |
   92|  16.0k|  switch (it->itype) {
  ------------------
  |  Branch (92:11): [True: 0, False: 16.0k]
  ------------------
   93|  1.22k|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|  1.22k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (93:5): [True: 1.22k, False: 14.8k]
  ------------------
   94|  1.22k|      ef = it->funcs;
   95|  1.22k|      if (ef && ef->asn1_ex_new) {
  ------------------
  |  Branch (95:11): [True: 1.22k, False: 0]
  |  Branch (95:17): [True: 1.22k, False: 0]
  ------------------
   96|  1.22k|        if (!ef->asn1_ex_new(pval, it)) {
  ------------------
  |  Branch (96:13): [True: 0, False: 1.22k]
  ------------------
   97|      0|          goto memerr;
   98|      0|        }
   99|  1.22k|      }
  100|  1.22k|      break;
  101|       |
  102|  5.69k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  5.69k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (102:5): [True: 5.69k, False: 10.3k]
  ------------------
  103|  5.69k|      if (it->templates) {
  ------------------
  |  Branch (103:11): [True: 0, False: 5.69k]
  ------------------
  104|      0|        if (!ASN1_template_new(pval, it->templates)) {
  ------------------
  |  Branch (104:13): [True: 0, False: 0]
  ------------------
  105|      0|          goto memerr;
  106|      0|        }
  107|  5.69k|      } else if (!ASN1_primitive_new(pval, it)) {
  ------------------
  |  Branch (107:18): [True: 0, False: 5.69k]
  ------------------
  108|      0|        goto memerr;
  109|      0|      }
  110|  5.69k|      break;
  111|       |
  112|  5.69k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  3.57k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (112:5): [True: 3.57k, False: 12.4k]
  ------------------
  113|  3.57k|      if (!ASN1_primitive_new(pval, it)) {
  ------------------
  |  Branch (113:11): [True: 0, False: 3.57k]
  ------------------
  114|      0|        goto memerr;
  115|      0|      }
  116|  3.57k|      break;
  117|       |
  118|  3.57k|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (118:5): [True: 0, False: 16.0k]
  ------------------
  119|      0|      const ASN1_AUX *aux = it->funcs;
  120|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (120:30): [True: 0, False: 0]
  ------------------
  121|      0|      if (asn1_cb) {
  ------------------
  |  Branch (121:11): [True: 0, False: 0]
  ------------------
  122|      0|        i = asn1_cb(ASN1_OP_NEW_PRE, pval, it, NULL);
  ------------------
  |  |  537|      0|#define ASN1_OP_NEW_PRE		0
  ------------------
  123|      0|        if (!i) {
  ------------------
  |  Branch (123:13): [True: 0, False: 0]
  ------------------
  124|      0|          goto auxerr;
  125|      0|        }
  126|      0|        if (i == 2) {
  ------------------
  |  Branch (126:13): [True: 0, False: 0]
  ------------------
  127|      0|          return 1;
  128|      0|        }
  129|      0|      }
  130|      0|      *pval = OPENSSL_malloc(it->size);
  131|      0|      if (!*pval) {
  ------------------
  |  Branch (131:11): [True: 0, False: 0]
  ------------------
  132|      0|        goto memerr;
  133|      0|      }
  134|      0|      OPENSSL_memset(*pval, 0, it->size);
  135|      0|      asn1_set_choice_selector(pval, -1, it);
  136|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_NEW_POST, pval, it, NULL)) {
  ------------------
  |  |  538|      0|#define ASN1_OP_NEW_POST	1
  ------------------
  |  Branch (136:11): [True: 0, False: 0]
  |  Branch (136:22): [True: 0, False: 0]
  ------------------
  137|      0|        goto auxerr2;
  138|      0|      }
  139|      0|      break;
  140|      0|    }
  141|       |
  142|  5.54k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|  5.54k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (142:5): [True: 5.54k, False: 10.4k]
  ------------------
  143|  5.54k|      const ASN1_AUX *aux = it->funcs;
  144|  5.54k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (144:30): [True: 1.22k, False: 4.32k]
  ------------------
  145|  5.54k|      if (asn1_cb) {
  ------------------
  |  Branch (145:11): [True: 610, False: 4.93k]
  ------------------
  146|    610|        i = asn1_cb(ASN1_OP_NEW_PRE, pval, it, NULL);
  ------------------
  |  |  537|    610|#define ASN1_OP_NEW_PRE		0
  ------------------
  147|    610|        if (!i) {
  ------------------
  |  Branch (147:13): [True: 0, False: 610]
  ------------------
  148|      0|          goto auxerr;
  149|      0|        }
  150|    610|        if (i == 2) {
  ------------------
  |  Branch (150:13): [True: 0, False: 610]
  ------------------
  151|      0|          return 1;
  152|      0|        }
  153|    610|      }
  154|  5.54k|      *pval = OPENSSL_malloc(it->size);
  155|  5.54k|      if (!*pval) {
  ------------------
  |  Branch (155:11): [True: 0, False: 5.54k]
  ------------------
  156|      0|        goto memerr;
  157|      0|      }
  158|  5.54k|      OPENSSL_memset(*pval, 0, it->size);
  159|  5.54k|      asn1_refcount_set_one(pval, it);
  160|  5.54k|      asn1_enc_init(pval, it);
  161|  21.6k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (161:39): [True: 16.0k, False: 5.54k]
  ------------------
  162|  16.0k|        pseqval = asn1_get_field_ptr(pval, tt);
  163|  16.0k|        if (!ASN1_template_new(pseqval, tt)) {
  ------------------
  |  Branch (163:13): [True: 0, False: 16.0k]
  ------------------
  164|      0|          goto memerr2;
  165|      0|        }
  166|  16.0k|      }
  167|  5.54k|      if (asn1_cb && !asn1_cb(ASN1_OP_NEW_POST, pval, it, NULL)) {
  ------------------
  |  |  538|    610|#define ASN1_OP_NEW_POST	1
  ------------------
  |  Branch (167:11): [True: 610, False: 4.93k]
  |  Branch (167:22): [True: 0, False: 610]
  ------------------
  168|      0|        goto auxerr2;
  169|      0|      }
  170|  5.54k|      break;
  171|  5.54k|    }
  172|  16.0k|  }
  173|  16.0k|  return 1;
  174|       |
  175|      0|memerr2:
  176|      0|  ASN1_item_ex_free(pval, it);
  177|      0|memerr:
  178|      0|  return 0;
  179|       |
  180|      0|auxerr2:
  181|      0|  ASN1_item_ex_free(pval, it);
  182|      0|auxerr:
  183|      0|  OPENSSL_PUT_ERROR(ASN1, ASN1_R_AUX_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  184|      0|  return 0;
  185|      0|}
tasn_new.c:ASN1_template_new:
  219|  16.0k|static int ASN1_template_new(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  220|  16.0k|  const ASN1_ITEM *it = ASN1_ITEM_ptr(tt->item);
  ------------------
  |  |  288|  16.0k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  221|  16.0k|  int ret;
  222|  16.0k|  if (tt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|  16.0k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (222:7): [True: 3.81k, False: 12.2k]
  ------------------
  223|  3.81k|    asn1_template_clear(pval, tt);
  224|  3.81k|    return 1;
  225|  3.81k|  }
  226|       |  // If ANY DEFINED BY nothing to do
  227|       |
  228|  12.2k|  if (tt->flags & ASN1_TFLG_ADB_MASK) {
  ------------------
  |  |  435|  12.2k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (228:7): [True: 0, False: 12.2k]
  ------------------
  229|      0|    *pval = NULL;
  230|      0|    return 1;
  231|      0|  }
  232|       |  // If SET OF or SEQUENCE OF, its a STACK
  233|  12.2k|  if (tt->flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|  12.2k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (233:7): [True: 0, False: 12.2k]
  ------------------
  234|      0|    STACK_OF(ASN1_VALUE) *skval;
  ------------------
  |  |   81|      0|#define STACK_OF(type) struct stack_st_##type
  ------------------
  235|      0|    skval = sk_ASN1_VALUE_new_null();
  236|      0|    if (!skval) {
  ------------------
  |  Branch (236:9): [True: 0, False: 0]
  ------------------
  237|      0|      ret = 0;
  238|      0|      goto done;
  239|      0|    }
  240|      0|    *pval = (ASN1_VALUE *)skval;
  241|      0|    ret = 1;
  242|      0|    goto done;
  243|      0|  }
  244|       |  // Otherwise pass it back to the item routine
  245|  12.2k|  ret = ASN1_item_ex_new(pval, it);
  246|  12.2k|done:
  247|  12.2k|  return ret;
  248|  12.2k|}
tasn_new.c:asn1_template_clear:
  250|  3.81k|static void asn1_template_clear(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  251|       |  // If ADB or STACK just NULL the field
  252|  3.81k|  if (tt->flags & (ASN1_TFLG_ADB_MASK | ASN1_TFLG_SK_MASK)) {
  ------------------
  |  |  435|  3.81k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
                if (tt->flags & (ASN1_TFLG_ADB_MASK | ASN1_TFLG_SK_MASK)) {
  ------------------
  |  |  390|  3.81k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (252:7): [True: 622, False: 3.19k]
  ------------------
  253|    622|    *pval = NULL;
  254|  3.19k|  } else {
  255|  3.19k|    asn1_item_clear(pval, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|  3.19k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  256|  3.19k|  }
  257|  3.81k|}
tasn_new.c:asn1_item_clear:
  187|  3.19k|static void asn1_item_clear(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  188|  3.19k|  const ASN1_EXTERN_FUNCS *ef;
  189|       |
  190|  3.19k|  switch (it->itype) {
  ------------------
  |  Branch (190:11): [True: 0, False: 3.19k]
  ------------------
  191|      0|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|      0|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (191:5): [True: 0, False: 3.19k]
  ------------------
  192|      0|      ef = it->funcs;
  193|      0|      if (ef && ef->asn1_ex_clear) {
  ------------------
  |  Branch (193:11): [True: 0, False: 0]
  |  Branch (193:17): [True: 0, False: 0]
  ------------------
  194|      0|        ef->asn1_ex_clear(pval, it);
  195|      0|      } else {
  196|      0|        *pval = NULL;
  197|      0|      }
  198|      0|      break;
  199|       |
  200|  3.19k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|  3.19k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (200:5): [True: 3.19k, False: 0]
  ------------------
  201|  3.19k|      if (it->templates) {
  ------------------
  |  Branch (201:11): [True: 0, False: 3.19k]
  ------------------
  202|      0|        asn1_template_clear(pval, it->templates);
  203|  3.19k|      } else {
  204|  3.19k|        asn1_primitive_clear(pval, it);
  205|  3.19k|      }
  206|  3.19k|      break;
  207|       |
  208|      0|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|      0|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (208:5): [True: 0, False: 3.19k]
  ------------------
  209|      0|      asn1_primitive_clear(pval, it);
  210|      0|      break;
  211|       |
  212|      0|    case ASN1_ITYPE_CHOICE:
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (212:5): [True: 0, False: 3.19k]
  ------------------
  213|      0|    case ASN1_ITYPE_SEQUENCE:
  ------------------
  |  |  489|      0|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (213:5): [True: 0, False: 3.19k]
  ------------------
  214|      0|      *pval = NULL;
  215|      0|      break;
  216|  3.19k|  }
  217|  3.19k|}
tasn_new.c:asn1_primitive_clear:
  311|  3.19k|static void asn1_primitive_clear(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  312|  3.19k|  int utype;
  313|       |  // Historically, |it->funcs| for primitive types contained an
  314|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  315|  3.19k|  assert(it == NULL || it->funcs == NULL);
  316|  3.19k|  if (!it || (it->itype == ASN1_ITYPE_MSTRING)) {
  ------------------
  |  |  495|  3.19k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (316:7): [True: 0, False: 3.19k]
  |  Branch (316:14): [True: 0, False: 3.19k]
  ------------------
  317|      0|    utype = -1;
  318|  3.19k|  } else {
  319|  3.19k|    utype = it->utype;
  320|  3.19k|  }
  321|  3.19k|  if (utype == V_ASN1_BOOLEAN) {
  ------------------
  |  |  125|  3.19k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (321:7): [True: 98, False: 3.09k]
  ------------------
  322|     98|    *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  323|  3.09k|  } else {
  324|  3.09k|    *pval = NULL;
  325|  3.09k|  }
  326|  3.19k|}
tasn_new.c:ASN1_primitive_new:
  262|  9.27k|static int ASN1_primitive_new(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  263|  9.27k|  if (!it) {
  ------------------
  |  Branch (263:7): [True: 0, False: 9.27k]
  ------------------
  264|      0|    return 0;
  265|      0|  }
  266|       |
  267|       |  // Historically, |it->funcs| for primitive types contained an
  268|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  269|  9.27k|  assert(it->funcs == NULL);
  270|       |
  271|  9.27k|  int utype;
  272|  9.27k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|  9.27k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (272:7): [True: 3.57k, False: 5.69k]
  ------------------
  273|  3.57k|    utype = -1;
  274|  5.69k|  } else {
  275|  5.69k|    utype = it->utype;
  276|  5.69k|  }
  277|  9.27k|  switch (utype) {
  278|  3.70k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|  3.70k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (278:5): [True: 3.70k, False: 5.56k]
  ------------------
  279|  3.70k|      *pval = (ASN1_VALUE *)OBJ_nid2obj(NID_undef);
  ------------------
  |  |   85|  3.70k|#define NID_undef 0
  ------------------
  280|  3.70k|      return 1;
  281|       |
  282|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (282:5): [True: 0, False: 9.27k]
  ------------------
  283|      0|      *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  284|      0|      return 1;
  285|       |
  286|      0|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (286:5): [True: 0, False: 9.27k]
  ------------------
  287|      0|      *pval = (ASN1_VALUE *)1;
  288|      0|      return 1;
  289|       |
  290|    673|    case V_ASN1_ANY: {
  ------------------
  |  |  121|    673|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (290:5): [True: 673, False: 8.60k]
  ------------------
  291|    673|      ASN1_TYPE *typ = OPENSSL_malloc(sizeof(ASN1_TYPE));
  292|    673|      if (!typ) {
  ------------------
  |  Branch (292:11): [True: 0, False: 673]
  ------------------
  293|      0|        return 0;
  294|      0|      }
  295|    673|      typ->value.ptr = NULL;
  296|    673|      typ->type = -1;
  297|    673|      *pval = (ASN1_VALUE *)typ;
  298|    673|      break;
  299|    673|    }
  300|       |
  301|  4.89k|    default:
  ------------------
  |  Branch (301:5): [True: 4.89k, False: 4.38k]
  ------------------
  302|  4.89k|      *pval = (ASN1_VALUE *)ASN1_STRING_type_new(utype);
  303|  4.89k|      break;
  304|  9.27k|  }
  305|  5.56k|  if (*pval) {
  ------------------
  |  Branch (305:7): [True: 5.56k, False: 0]
  ------------------
  306|  5.56k|    return 1;
  307|  5.56k|  }
  308|      0|  return 0;
  309|  5.56k|}

ASN1_OCTET_STRING_free:
   67|    610|  void sname##_free(sname *x) { ASN1_STRING_free(x); }
ASN1_INTEGER_new:
   66|    626|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \
ASN1_BIT_STRING_new:
   66|     46|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \
ASN1_BIT_STRING_free:
   67|    618|  void sname##_free(sname *x) { ASN1_STRING_free(x); }
ASN1_UTF8STRING_new:
   66|      6|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \

asn1_refcount_set_one:
  106|  5.54k|void asn1_refcount_set_one(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  107|  5.54k|  CRYPTO_refcount_t *references = asn1_get_references(pval, it);
  108|  5.54k|  if (references != NULL) {
  ------------------
  |  Branch (108:7): [True: 0, False: 5.54k]
  ------------------
  109|      0|    *references = 1;
  110|      0|  }
  111|  5.54k|}
asn1_refcount_dec_and_test_zero:
  113|  5.54k|int asn1_refcount_dec_and_test_zero(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  114|  5.54k|  CRYPTO_refcount_t *references = asn1_get_references(pval, it);
  115|  5.54k|  if (references != NULL) {
  ------------------
  |  Branch (115:7): [True: 0, False: 5.54k]
  ------------------
  116|      0|    return CRYPTO_refcount_dec_and_test_zero(references);
  117|      0|  }
  118|  5.54k|  return 1;
  119|  5.54k|}
asn1_enc_init:
  134|  5.54k|void asn1_enc_init(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  135|  5.54k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  136|  5.54k|  if (enc) {
  ------------------
  |  Branch (136:7): [True: 610, False: 4.93k]
  ------------------
  137|    610|    enc->enc = NULL;
  138|    610|    enc->len = 0;
  139|    610|    enc->buf = NULL;
  140|    610|  }
  141|  5.54k|}
asn1_enc_free:
  143|  5.54k|void asn1_enc_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  144|  5.54k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  145|  5.54k|  if (enc) {
  ------------------
  |  Branch (145:7): [True: 610, False: 4.93k]
  ------------------
  146|    610|    asn1_encoding_clear(enc);
  147|    610|  }
  148|  5.54k|}
asn1_enc_save:
  151|  2.06k|                  const ASN1_ITEM *it, CRYPTO_BUFFER *buf) {
  152|  2.06k|  ASN1_ENCODING *enc;
  153|  2.06k|  enc = asn1_get_enc_ptr(pval, it);
  154|  2.06k|  if (!enc) {
  ------------------
  |  Branch (154:7): [True: 2.03k, False: 33]
  ------------------
  155|  2.03k|    return 1;
  156|  2.03k|  }
  157|       |
  158|     33|  asn1_encoding_clear(enc);
  159|     33|  if (buf != NULL) {
  ------------------
  |  Branch (159:7): [True: 0, False: 33]
  ------------------
  160|      0|    assert(CRYPTO_BUFFER_data(buf) <= in &&
  161|      0|           in + in_len <= CRYPTO_BUFFER_data(buf) + CRYPTO_BUFFER_len(buf));
  162|      0|    CRYPTO_BUFFER_up_ref(buf);
  163|      0|    enc->buf = buf;
  164|      0|    enc->enc = (uint8_t *)in;
  165|     33|  } else {
  166|     33|    enc->enc = OPENSSL_memdup(in, in_len);
  167|     33|    if (!enc->enc) {
  ------------------
  |  Branch (167:9): [True: 0, False: 33]
  ------------------
  168|      0|      return 0;
  169|      0|    }
  170|     33|  }
  171|       |
  172|     33|  enc->len = in_len;
  173|     33|  return 1;
  174|     33|}
asn1_encoding_clear:
  176|    643|void asn1_encoding_clear(ASN1_ENCODING *enc) {
  177|    643|  if (enc->buf != NULL) {
  ------------------
  |  Branch (177:7): [True: 0, False: 643]
  ------------------
  178|      0|    CRYPTO_BUFFER_free(enc->buf);
  179|    643|  } else {
  180|    643|    OPENSSL_free(enc->enc);
  181|    643|  }
  182|    643|  enc->enc = NULL;
  183|    643|  enc->len = 0;
  184|    643|  enc->buf = NULL;
  185|    643|}
asn1_enc_restore:
  188|  3.31k|                     const ASN1_ITEM *it) {
  189|  3.31k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  190|  3.31k|  if (!enc || enc->len == 0) {
  ------------------
  |  Branch (190:7): [True: 3.31k, False: 0]
  |  Branch (190:15): [True: 0, False: 0]
  ------------------
  191|  3.31k|    return 0;
  192|  3.31k|  }
  193|      0|  if (out) {
  ------------------
  |  Branch (193:7): [True: 0, False: 0]
  ------------------
  194|      0|    OPENSSL_memcpy(*out, enc->enc, enc->len);
  195|      0|    *out += enc->len;
  196|      0|  }
  197|      0|  if (len) {
  ------------------
  |  Branch (197:7): [True: 0, False: 0]
  ------------------
  198|      0|    *len = enc->len;
  199|      0|  }
  200|      0|  return 1;
  201|  3.31k|}
asn1_get_field_ptr:
  204|  48.7k|ASN1_VALUE **asn1_get_field_ptr(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  205|  48.7k|  ASN1_VALUE **pvaltmp = offset2ptr(*pval, tt->offset);
  ------------------
  |  |   76|  48.7k|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  206|       |  // NOTE for BOOLEAN types the field is just a plain int so we can't return
  207|       |  // int **, so settle for (int *).
  208|  48.7k|  return pvaltmp;
  209|  48.7k|}
asn1_do_adb:
  214|  32.7k|                                 int nullerr) {
  215|  32.7k|  const ASN1_ADB *adb;
  216|  32.7k|  const ASN1_ADB_TABLE *atbl;
  217|  32.7k|  ASN1_VALUE **sfld;
  218|  32.7k|  int i;
  219|  32.7k|  if (!(tt->flags & ASN1_TFLG_ADB_MASK)) {
  ------------------
  |  |  435|  32.7k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (219:7): [True: 32.7k, False: 0]
  ------------------
  220|  32.7k|    return tt;
  221|  32.7k|  }
  222|       |
  223|       |  // Else ANY DEFINED BY ... get the table
  224|      0|  adb = ASN1_ADB_ptr(tt->item);
  ------------------
  |  |   79|      0|#define ASN1_ADB_ptr(iptr) ((const ASN1_ADB *)(iptr))
  ------------------
  225|       |
  226|       |  // Get the selector field
  227|      0|  sfld = offset2ptr(*pval, adb->offset);
  ------------------
  |  |   76|      0|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  228|       |
  229|       |  // Check if NULL
  230|      0|  if (*sfld == NULL) {
  ------------------
  |  Branch (230:7): [True: 0, False: 0]
  ------------------
  231|      0|    if (!adb->null_tt) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      goto err;
  233|      0|    }
  234|      0|    return adb->null_tt;
  235|      0|  }
  236|       |
  237|       |  // Convert type to a NID:
  238|       |  // NB: don't check for NID_undef here because it
  239|       |  // might be a legitimate value in the table
  240|      0|  assert(tt->flags & ASN1_TFLG_ADB_OID);
  241|      0|  int selector = OBJ_obj2nid((ASN1_OBJECT *)*sfld);
  242|       |
  243|       |  // Try to find matching entry in table Maybe should check application types
  244|       |  // first to allow application override? Might also be useful to have a flag
  245|       |  // which indicates table is sorted and we can do a binary search. For now
  246|       |  // stick to a linear search.
  247|       |
  248|      0|  for (atbl = adb->tbl, i = 0; i < adb->tblcount; i++, atbl++) {
  ------------------
  |  Branch (248:32): [True: 0, False: 0]
  ------------------
  249|      0|    if (atbl->value == selector) {
  ------------------
  |  Branch (249:9): [True: 0, False: 0]
  ------------------
  250|      0|      return &atbl->tt;
  251|      0|    }
  252|      0|  }
  253|       |
  254|       |  // FIXME: need to search application table too
  255|       |
  256|       |  // No match, return default type
  257|      0|  if (!adb->default_tt) {
  ------------------
  |  Branch (257:7): [True: 0, False: 0]
  ------------------
  258|      0|    goto err;
  259|      0|  }
  260|      0|  return adb->default_tt;
  261|       |
  262|      0|err:
  263|       |  // FIXME: should log the value or OID of unsupported type
  264|      0|  if (nullerr) {
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      0|  }
  267|      0|  return NULL;
  268|      0|}
tasn_utl.c:asn1_get_references:
   95|  11.0k|                                              const ASN1_ITEM *it) {
   96|  11.0k|  if (it->itype != ASN1_ITYPE_SEQUENCE) {
  ------------------
  |  |  489|  11.0k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (96:7): [True: 0, False: 11.0k]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|  11.0k|  const ASN1_AUX *aux = it->funcs;
  100|  11.0k|  if (!aux || !(aux->flags & ASN1_AFLG_REFCOUNT)) {
  ------------------
  |  |  531|  2.44k|#define ASN1_AFLG_REFCOUNT	1
  ------------------
  |  Branch (100:7): [True: 8.64k, False: 2.44k]
  |  Branch (100:15): [True: 2.44k, False: 0]
  ------------------
  101|  11.0k|    return NULL;
  102|  11.0k|  }
  103|      0|  return offset2ptr(*pval, aux->ref_offset);
  ------------------
  |  |   76|      0|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  104|  11.0k|}
tasn_utl.c:asn1_get_enc_ptr:
  121|  16.4k|static ASN1_ENCODING *asn1_get_enc_ptr(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  122|  16.4k|  assert(it->itype == ASN1_ITYPE_SEQUENCE);
  123|  16.4k|  const ASN1_AUX *aux;
  124|  16.4k|  if (!pval || !*pval) {
  ------------------
  |  Branch (124:7): [True: 0, False: 16.4k]
  |  Branch (124:16): [True: 0, False: 16.4k]
  ------------------
  125|      0|    return NULL;
  126|      0|  }
  127|  16.4k|  aux = it->funcs;
  128|  16.4k|  if (!aux || !(aux->flags & ASN1_AFLG_ENCODING)) {
  ------------------
  |  |  533|  2.56k|#define ASN1_AFLG_ENCODING	2
  ------------------
  |  Branch (128:7): [True: 13.8k, False: 2.56k]
  |  Branch (128:15): [True: 1.31k, False: 1.25k]
  ------------------
  129|  15.2k|    return NULL;
  130|  15.2k|  }
  131|  1.25k|  return offset2ptr(*pval, aux->enc_offset);
  ------------------
  |  |   76|  1.25k|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  132|  16.4k|}

BN_parse_asn1_unsigned:
   21|  4.08k|int BN_parse_asn1_unsigned(CBS *cbs, BIGNUM *ret) {
   22|  4.08k|  CBS child;
   23|  4.08k|  int is_negative;
   24|  4.08k|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  4.08k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (24:7): [True: 16, False: 4.06k]
  ------------------
   25|  4.08k|      !CBS_is_valid_asn1_integer(&child, &is_negative)) {
  ------------------
  |  Branch (25:7): [True: 11, False: 4.05k]
  ------------------
   26|     27|    OPENSSL_PUT_ERROR(BN, BN_R_BAD_ENCODING);
  ------------------
  |  |  441|     27|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   27|     27|    return 0;
   28|     27|  }
   29|       |
   30|  4.05k|  if (is_negative) {
  ------------------
  |  Branch (30:7): [True: 12, False: 4.04k]
  ------------------
   31|     12|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|     12|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   32|     12|    return 0;
   33|     12|  }
   34|       |
   35|  4.04k|  return BN_bin2bn(CBS_data(&child), CBS_len(&child), ret) != NULL;
   36|  4.05k|}

BUF_MEM_new:
   67|  1.61k|BUF_MEM *BUF_MEM_new(void) {
   68|  1.61k|  BUF_MEM *ret;
   69|       |
   70|  1.61k|  ret = OPENSSL_malloc(sizeof(BUF_MEM));
   71|  1.61k|  if (ret == NULL) {
  ------------------
  |  Branch (71:7): [True: 0, False: 1.61k]
  ------------------
   72|      0|    return NULL;
   73|      0|  }
   74|       |
   75|  1.61k|  OPENSSL_memset(ret, 0, sizeof(BUF_MEM));
   76|  1.61k|  return ret;
   77|  1.61k|}
BUF_MEM_free:
   79|  1.61k|void BUF_MEM_free(BUF_MEM *buf) {
   80|  1.61k|  if (buf == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 1.61k]
  ------------------
   81|      0|    return;
   82|      0|  }
   83|       |
   84|  1.61k|  OPENSSL_free(buf->data);
   85|  1.61k|  OPENSSL_free(buf);
   86|  1.61k|}
BUF_MEM_reserve:
   88|    397|int BUF_MEM_reserve(BUF_MEM *buf, size_t cap) {
   89|    397|  if (buf->max >= cap) {
  ------------------
  |  Branch (89:7): [True: 0, False: 397]
  ------------------
   90|      0|    return 1;
   91|      0|  }
   92|       |
   93|    397|  size_t n = cap + 3;
   94|    397|  if (n < cap) {
  ------------------
  |  Branch (94:7): [True: 0, False: 397]
  ------------------
   95|      0|    OPENSSL_PUT_ERROR(BUF, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   96|      0|    return 0;
   97|      0|  }
   98|    397|  n = n / 3;
   99|    397|  size_t alloc_size = n * 4;
  100|    397|  if (alloc_size / 4 != n) {
  ------------------
  |  Branch (100:7): [True: 0, False: 397]
  ------------------
  101|      0|    OPENSSL_PUT_ERROR(BUF, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  102|      0|    return 0;
  103|      0|  }
  104|       |
  105|    397|  char *new_buf = OPENSSL_realloc(buf->data, alloc_size);
  106|    397|  if (new_buf == NULL) {
  ------------------
  |  Branch (106:7): [True: 0, False: 397]
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|    397|  buf->data = new_buf;
  111|    397|  buf->max = alloc_size;
  112|    397|  return 1;
  113|    397|}
BUF_MEM_grow:
  115|    397|size_t BUF_MEM_grow(BUF_MEM *buf, size_t len) {
  116|    397|  if (!BUF_MEM_reserve(buf, len)) {
  ------------------
  |  Branch (116:7): [True: 0, False: 397]
  ------------------
  117|      0|    return 0;
  118|      0|  }
  119|    397|  if (buf->length < len) {
  ------------------
  |  Branch (119:7): [True: 397, False: 0]
  ------------------
  120|    397|    OPENSSL_memset(&buf->data[buf->length], 0, len - buf->length);
  121|    397|  }
  122|    397|  buf->length = len;
  123|    397|  return len;
  124|    397|}

CBS_asn1_ber_to_der:
  193|  10.0k|int CBS_asn1_ber_to_der(CBS *in, CBS *out, uint8_t **out_storage) {
  194|  10.0k|  CBB cbb;
  195|       |
  196|       |  // First, do a quick walk to find any indefinite-length elements. Most of the
  197|       |  // time we hope that there aren't any and thus we can quickly return.
  198|  10.0k|  int conversion_needed;
  199|  10.0k|  if (!cbs_find_ber(in, &conversion_needed, 0)) {
  ------------------
  |  Branch (199:7): [True: 714, False: 9.35k]
  ------------------
  200|    714|    return 0;
  201|    714|  }
  202|       |
  203|  9.35k|  if (!conversion_needed) {
  ------------------
  |  Branch (203:7): [True: 5.37k, False: 3.98k]
  ------------------
  204|  5.37k|    if (!CBS_get_any_asn1_element(in, out, NULL, NULL)) {
  ------------------
  |  Branch (204:9): [True: 131, False: 5.24k]
  ------------------
  205|    131|      return 0;
  206|    131|    }
  207|  5.24k|    *out_storage = NULL;
  208|  5.24k|    return 1;
  209|  5.37k|  }
  210|       |
  211|  3.98k|  size_t len;
  212|  3.98k|  if (!CBB_init(&cbb, CBS_len(in)) ||
  ------------------
  |  Branch (212:7): [True: 0, False: 3.98k]
  ------------------
  213|  3.98k|      !cbs_convert_ber(in, &cbb, 0, 0, 0) ||
  ------------------
  |  Branch (213:7): [True: 536, False: 3.44k]
  ------------------
  214|  3.98k|      !CBB_finish(&cbb, out_storage, &len)) {
  ------------------
  |  Branch (214:7): [True: 0, False: 3.44k]
  ------------------
  215|    536|    CBB_cleanup(&cbb);
  216|    536|    return 0;
  217|    536|  }
  218|       |
  219|  3.44k|  CBS_init(out, *out_storage, len);
  220|  3.44k|  return 1;
  221|  3.98k|}
CBS_get_asn1_implicit_string:
  225|    791|                                 CBS_ASN1_TAG inner_tag) {
  226|    791|  assert(!(outer_tag & CBS_ASN1_CONSTRUCTED));
  227|    791|  assert(!(inner_tag & CBS_ASN1_CONSTRUCTED));
  228|    791|  assert(is_string_type(inner_tag));
  229|       |
  230|    791|  if (CBS_peek_asn1_tag(in, outer_tag)) {
  ------------------
  |  Branch (230:7): [True: 670, False: 121]
  ------------------
  231|       |    // Normal implicitly-tagged string.
  232|    670|    *out_storage = NULL;
  233|    670|    return CBS_get_asn1(in, out, outer_tag);
  234|    670|  }
  235|       |
  236|       |  // Otherwise, try to parse an implicitly-tagged constructed string.
  237|       |  // |CBS_asn1_ber_to_der| is assumed to have run, so only allow one level deep
  238|       |  // of nesting.
  239|    121|  CBB result;
  240|    121|  CBS child;
  241|    121|  if (!CBB_init(&result, CBS_len(in)) ||
  ------------------
  |  Branch (241:7): [True: 0, False: 121]
  ------------------
  242|    121|      !CBS_get_asn1(in, &child, outer_tag | CBS_ASN1_CONSTRUCTED)) {
  ------------------
  |  |  196|    121|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|    121|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (242:7): [True: 75, False: 46]
  ------------------
  243|     75|    goto err;
  244|     75|  }
  245|       |
  246|    410|  while (CBS_len(&child) > 0) {
  ------------------
  |  Branch (246:10): [True: 369, False: 41]
  ------------------
  247|    369|    CBS chunk;
  248|    369|    if (!CBS_get_asn1(&child, &chunk, inner_tag) ||
  ------------------
  |  Branch (248:9): [True: 5, False: 364]
  ------------------
  249|    369|        !CBB_add_bytes(&result, CBS_data(&chunk), CBS_len(&chunk))) {
  ------------------
  |  Branch (249:9): [True: 0, False: 364]
  ------------------
  250|      5|      goto err;
  251|      5|    }
  252|    369|  }
  253|       |
  254|     41|  uint8_t *data;
  255|     41|  size_t len;
  256|     41|  if (!CBB_finish(&result, &data, &len)) {
  ------------------
  |  Branch (256:7): [True: 0, False: 41]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|     41|  CBS_init(out, data, len);
  261|     41|  *out_storage = data;
  262|     41|  return 1;
  263|       |
  264|     80|err:
  265|     80|  CBB_cleanup(&result);
  266|     80|  return 0;
  267|     41|}
ber.c:cbs_find_ber:
   58|  53.6k|static int cbs_find_ber(const CBS *orig_in, int *ber_found, uint32_t depth) {
   59|  53.6k|  CBS in;
   60|       |
   61|  53.6k|  if (depth > kMaxDepth) {
  ------------------
  |  Branch (61:7): [True: 0, False: 53.6k]
  ------------------
   62|      0|    return 0;
   63|      0|  }
   64|       |
   65|  53.6k|  CBS_init(&in, CBS_data(orig_in), CBS_len(orig_in));
   66|  53.6k|  *ber_found = 0;
   67|       |
   68|   136k|  while (CBS_len(&in) > 0) {
  ------------------
  |  Branch (68:10): [True: 93.2k, False: 43.6k]
  ------------------
   69|  93.2k|    CBS contents;
   70|  93.2k|    CBS_ASN1_TAG tag;
   71|  93.2k|    size_t header_len;
   72|  93.2k|    int indefinite;
   73|  93.2k|    if (!CBS_get_any_ber_asn1_element(&in, &contents, &tag, &header_len,
  ------------------
  |  Branch (73:9): [True: 714, False: 92.5k]
  ------------------
   74|  93.2k|                                      ber_found, &indefinite)) {
   75|    714|      return 0;
   76|    714|    }
   77|  92.5k|    if (*ber_found) {
  ------------------
  |  Branch (77:9): [True: 5.56k, False: 86.9k]
  ------------------
   78|  5.56k|      return 1;
   79|  5.56k|    }
   80|  86.9k|    if (tag & CBS_ASN1_CONSTRUCTED) {
  ------------------
  |  |  196|  86.9k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  86.9k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (80:9): [True: 47.0k, False: 39.8k]
  ------------------
   81|  47.0k|      if (is_string_type(tag)) {
  ------------------
  |  Branch (81:11): [True: 3.47k, False: 43.5k]
  ------------------
   82|       |        // Constructed strings are only legal in BER and require conversion.
   83|  3.47k|        *ber_found = 1;
   84|  3.47k|        return 1;
   85|  3.47k|      }
   86|  43.5k|      if (!CBS_skip(&contents, header_len) ||
  ------------------
  |  Branch (86:11): [True: 0, False: 43.5k]
  ------------------
   87|  43.5k|          !cbs_find_ber(&contents, ber_found, depth + 1)) {
  ------------------
  |  Branch (87:11): [True: 215, False: 43.3k]
  ------------------
   88|    215|        return 0;
   89|    215|      }
   90|  43.5k|    }
   91|  86.9k|  }
   92|       |
   93|  43.6k|  return 1;
   94|  53.6k|}
ber.c:cbs_convert_ber:
  114|   200k|                           int looking_for_eoc, uint32_t depth) {
  115|   200k|  assert(!(string_tag & CBS_ASN1_CONSTRUCTED));
  116|       |
  117|   200k|  if (depth > kMaxDepth) {
  ------------------
  |  Branch (117:7): [True: 1, False: 200k]
  ------------------
  118|      1|    return 0;
  119|      1|  }
  120|       |
  121|  3.98M|  while (CBS_len(in) > 0) {
  ------------------
  |  Branch (121:10): [True: 3.93M, False: 48.2k]
  ------------------
  122|  3.93M|    if (looking_for_eoc && cbs_get_eoc(in)) {
  ------------------
  |  Branch (122:9): [True: 3.84M, False: 88.5k]
  |  Branch (122:28): [True: 87.1k, False: 3.76M]
  ------------------
  123|  87.1k|      return 1;
  124|  87.1k|    }
  125|       |
  126|  3.84M|    CBS contents;
  127|  3.84M|    CBS_ASN1_TAG tag, child_string_tag = string_tag;
  128|  3.84M|    size_t header_len;
  129|  3.84M|    int indefinite;
  130|  3.84M|    CBB *out_contents, out_contents_storage;
  131|  3.84M|    if (!CBS_get_any_ber_asn1_element(in, &contents, &tag, &header_len,
  ------------------
  |  Branch (131:9): [True: 231, False: 3.84M]
  ------------------
  132|       |                                      /*out_ber_found=*/NULL, &indefinite)) {
  133|    231|      return 0;
  134|    231|    }
  135|       |
  136|  3.84M|    if (string_tag != 0) {
  ------------------
  |  Branch (136:9): [True: 97.2k, False: 3.75M]
  ------------------
  137|       |      // This is part of a constructed string. All elements must match
  138|       |      // |string_tag| up to the constructed bit and get appended to |out|
  139|       |      // without a child element.
  140|  97.2k|      if ((tag & ~CBS_ASN1_CONSTRUCTED) != string_tag) {
  ------------------
  |  |  196|  97.2k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  97.2k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (140:11): [True: 90, False: 97.1k]
  ------------------
  141|     90|        return 0;
  142|     90|      }
  143|  97.1k|      out_contents = out;
  144|  3.75M|    } else {
  145|  3.75M|      CBS_ASN1_TAG out_tag = tag;
  146|  3.75M|      if ((tag & CBS_ASN1_CONSTRUCTED) && is_string_type(tag)) {
  ------------------
  |  |  196|  3.75M|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  3.75M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (146:11): [True: 170k, False: 3.58M]
  |  Branch (146:43): [True: 2.49k, False: 167k]
  ------------------
  147|       |        // If a constructed string, clear the constructed bit and inform
  148|       |        // children to concatenate bodies.
  149|  2.49k|        out_tag &= ~CBS_ASN1_CONSTRUCTED;
  ------------------
  |  |  196|  2.49k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  2.49k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  150|  2.49k|        child_string_tag = out_tag;
  151|  2.49k|      }
  152|  3.75M|      if (!CBB_add_asn1(out, &out_contents_storage, out_tag)) {
  ------------------
  |  Branch (152:11): [True: 0, False: 3.75M]
  ------------------
  153|      0|        return 0;
  154|      0|      }
  155|  3.75M|      out_contents = &out_contents_storage;
  156|  3.75M|    }
  157|       |
  158|  3.84M|    if (indefinite) {
  ------------------
  |  Branch (158:9): [True: 151k, False: 3.69M]
  ------------------
  159|   151k|      if (!cbs_convert_ber(in, out_contents, child_string_tag,
  ------------------
  |  Branch (159:11): [True: 64.5k, False: 87.1k]
  ------------------
  160|   151k|                           /*looking_for_eoc=*/1, depth + 1) ||
  161|   151k|          !CBB_flush(out)) {
  ------------------
  |  Branch (161:11): [True: 0, False: 87.1k]
  ------------------
  162|  64.5k|        return 0;
  163|  64.5k|      }
  164|  87.1k|      continue;
  165|   151k|    }
  166|       |
  167|  3.69M|    if (!CBS_skip(&contents, header_len)) {
  ------------------
  |  Branch (167:9): [True: 0, False: 3.69M]
  ------------------
  168|      0|      return 0;
  169|      0|    }
  170|       |
  171|  3.69M|    if (tag & CBS_ASN1_CONSTRUCTED) {
  ------------------
  |  |  196|  3.69M|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  3.69M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (171:9): [True: 44.7k, False: 3.65M]
  ------------------
  172|       |      // Recurse into children.
  173|  44.7k|      if (!cbs_convert_ber(&contents, out_contents, child_string_tag,
  ------------------
  |  Branch (173:11): [True: 135, False: 44.6k]
  ------------------
  174|  44.7k|                           /*looking_for_eoc=*/0, depth + 1)) {
  175|    135|        return 0;
  176|    135|      }
  177|  3.65M|    } else {
  178|       |      // Copy primitive contents as-is.
  179|  3.65M|      if (!CBB_add_bytes(out_contents, CBS_data(&contents),
  ------------------
  |  Branch (179:11): [True: 0, False: 3.65M]
  ------------------
  180|  3.65M|                         CBS_len(&contents))) {
  181|      0|        return 0;
  182|      0|      }
  183|  3.65M|    }
  184|       |
  185|  3.69M|    if (!CBB_flush(out)) {
  ------------------
  |  Branch (185:9): [True: 0, False: 3.69M]
  ------------------
  186|      0|      return 0;
  187|      0|    }
  188|  3.69M|  }
  189|       |
  190|  48.2k|  return looking_for_eoc == 0;
  191|   200k|}
ber.c:cbs_get_eoc:
   98|  3.84M|static int cbs_get_eoc(CBS *cbs) {
   99|  3.84M|  if (CBS_len(cbs) >= 2 &&
  ------------------
  |  Branch (99:7): [True: 3.84M, False: 76]
  ------------------
  100|  3.84M|      CBS_data(cbs)[0] == 0 && CBS_data(cbs)[1] == 0) {
  ------------------
  |  Branch (100:7): [True: 87.1k, False: 3.76M]
  |  Branch (100:32): [True: 87.1k, False: 17]
  ------------------
  101|  87.1k|    return CBS_skip(cbs, 2);
  102|  87.1k|  }
  103|  3.76M|  return 0;
  104|  3.84M|}
ber.c:is_string_type:
   31|   218k|static int is_string_type(CBS_ASN1_TAG tag) {
   32|       |  // While BER supports constructed BIT STRINGS, OpenSSL misparses them. To
   33|       |  // avoid acting on an ambiguous input, we do not support constructed BIT
   34|       |  // STRINGS. See https://github.com/openssl/openssl/issues/12810.
   35|   218k|  switch (tag & ~CBS_ASN1_CONSTRUCTED) {
  ------------------
  |  |  196|   218k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|   218k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
   36|  1.61k|    case CBS_ASN1_OCTETSTRING:
  ------------------
  |  |  217|  1.61k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (36:5): [True: 1.61k, False: 216k]
  ------------------
   37|  2.43k|    case CBS_ASN1_UTF8STRING:
  ------------------
  |  |  221|  2.43k|#define CBS_ASN1_UTF8STRING 0xcu
  ------------------
  |  Branch (37:5): [True: 826, False: 217k]
  ------------------
   38|  2.89k|    case CBS_ASN1_NUMERICSTRING:
  ------------------
  |  |  224|  2.89k|#define CBS_ASN1_NUMERICSTRING 0x12u
  ------------------
  |  Branch (38:5): [True: 458, False: 217k]
  ------------------
   39|  3.32k|    case CBS_ASN1_PRINTABLESTRING:
  ------------------
  |  |  225|  3.32k|#define CBS_ASN1_PRINTABLESTRING 0x13u
  ------------------
  |  Branch (39:5): [True: 432, False: 217k]
  ------------------
   40|  3.66k|    case CBS_ASN1_T61STRING:
  ------------------
  |  |  226|  3.66k|#define CBS_ASN1_T61STRING 0x14u
  ------------------
  |  Branch (40:5): [True: 337, False: 217k]
  ------------------
   41|  4.54k|    case CBS_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  227|  4.54k|#define CBS_ASN1_VIDEOTEXSTRING 0x15u
  ------------------
  |  Branch (41:5): [True: 883, False: 217k]
  ------------------
   42|  5.40k|    case CBS_ASN1_IA5STRING:
  ------------------
  |  |  228|  5.40k|#define CBS_ASN1_IA5STRING 0x16u
  ------------------
  |  Branch (42:5): [True: 857, False: 217k]
  ------------------
   43|  5.45k|    case CBS_ASN1_GRAPHICSTRING:
  ------------------
  |  |  231|  5.45k|#define CBS_ASN1_GRAPHICSTRING 0x19u
  ------------------
  |  Branch (43:5): [True: 45, False: 218k]
  ------------------
   44|  5.52k|    case CBS_ASN1_VISIBLESTRING:
  ------------------
  |  |  232|  5.52k|#define CBS_ASN1_VISIBLESTRING 0x1au
  ------------------
  |  Branch (44:5): [True: 78, False: 217k]
  ------------------
   45|  6.18k|    case CBS_ASN1_GENERALSTRING:
  ------------------
  |  |  233|  6.18k|#define CBS_ASN1_GENERALSTRING 0x1bu
  ------------------
  |  Branch (45:5): [True: 652, False: 217k]
  ------------------
   46|  6.43k|    case CBS_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  234|  6.43k|#define CBS_ASN1_UNIVERSALSTRING 0x1cu
  ------------------
  |  Branch (46:5): [True: 257, False: 217k]
  ------------------
   47|  6.76k|    case CBS_ASN1_BMPSTRING:
  ------------------
  |  |  235|  6.76k|#define CBS_ASN1_BMPSTRING 0x1eu
  ------------------
  |  Branch (47:5): [True: 322, False: 217k]
  ------------------
   48|  6.76k|      return 1;
   49|   211k|    default:
  ------------------
  |  Branch (49:5): [True: 211k, False: 6.76k]
  ------------------
   50|   211k|      return 0;
   51|   218k|  }
   52|   218k|}

CBB_zero:
   27|  3.76M|void CBB_zero(CBB *cbb) {
   28|  3.76M|  OPENSSL_memset(cbb, 0, sizeof(CBB));
   29|  3.76M|}
CBB_init:
   41|  9.81k|int CBB_init(CBB *cbb, size_t initial_capacity) {
   42|  9.81k|  CBB_zero(cbb);
   43|       |
   44|  9.81k|  uint8_t *buf = OPENSSL_malloc(initial_capacity);
   45|  9.81k|  if (initial_capacity > 0 && buf == NULL) {
  ------------------
  |  Branch (45:7): [True: 9.81k, False: 1]
  |  Branch (45:31): [True: 0, False: 9.81k]
  ------------------
   46|      0|    return 0;
   47|      0|  }
   48|       |
   49|  9.81k|  cbb_init(cbb, buf, initial_capacity, /*can_resize=*/1);
   50|  9.81k|  return 1;
   51|  9.81k|}
CBB_cleanup:
   59|  9.81k|void CBB_cleanup(CBB *cbb) {
   60|       |  // Child |CBB|s are non-owning. They are implicitly discarded and should not
   61|       |  // be used with |CBB_cleanup| or |ScopedCBB|.
   62|  9.81k|  assert(!cbb->is_child);
   63|  9.81k|  if (cbb->is_child) {
  ------------------
  |  Branch (63:7): [True: 0, False: 9.81k]
  ------------------
   64|      0|    return;
   65|      0|  }
   66|       |
   67|  9.81k|  if (cbb->u.base.can_resize) {
  ------------------
  |  Branch (67:7): [True: 9.81k, False: 0]
  ------------------
   68|  9.81k|    OPENSSL_free(cbb->u.base.buf);
   69|  9.81k|  }
   70|  9.81k|}
CBB_finish:
  125|  9.19k|int CBB_finish(CBB *cbb, uint8_t **out_data, size_t *out_len) {
  126|  9.19k|  if (cbb->is_child) {
  ------------------
  |  Branch (126:7): [True: 0, False: 9.19k]
  ------------------
  127|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  128|      0|    return 0;
  129|      0|  }
  130|       |
  131|  9.19k|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (131:7): [True: 0, False: 9.19k]
  ------------------
  132|      0|    return 0;
  133|      0|  }
  134|       |
  135|  9.19k|  if (cbb->u.base.can_resize && (out_data == NULL || out_len == NULL)) {
  ------------------
  |  Branch (135:7): [True: 9.19k, False: 0]
  |  Branch (135:34): [True: 0, False: 9.19k]
  |  Branch (135:54): [True: 0, False: 9.19k]
  ------------------
  136|       |    // |out_data| and |out_len| can only be NULL if the CBB is fixed.
  137|      0|    return 0;
  138|      0|  }
  139|       |
  140|  9.19k|  if (out_data != NULL) {
  ------------------
  |  Branch (140:7): [True: 9.19k, False: 0]
  ------------------
  141|  9.19k|    *out_data = cbb->u.base.buf;
  142|  9.19k|  }
  143|  9.19k|  if (out_len != NULL) {
  ------------------
  |  Branch (143:7): [True: 9.19k, False: 0]
  ------------------
  144|  9.19k|    *out_len = cbb->u.base.len;
  145|  9.19k|  }
  146|  9.19k|  cbb->u.base.buf = NULL;
  147|  9.19k|  CBB_cleanup(cbb);
  148|  9.19k|  return 1;
  149|  9.19k|}
CBB_flush:
  161|  18.6M|int CBB_flush(CBB *cbb) {
  162|       |  // If |base| has hit an error, the buffer is in an undefined state, so
  163|       |  // fail all following calls. In particular, |cbb->child| may point to invalid
  164|       |  // memory.
  165|  18.6M|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  166|  18.6M|  if (base == NULL || base->error) {
  ------------------
  |  Branch (166:7): [True: 0, False: 18.6M]
  |  Branch (166:23): [True: 0, False: 18.6M]
  ------------------
  167|      0|    return 0;
  168|      0|  }
  169|       |
  170|  18.6M|  if (cbb->child == NULL) {
  ------------------
  |  Branch (170:7): [True: 14.9M, False: 3.71M]
  ------------------
  171|       |    // Nothing to flush.
  172|  14.9M|    return 1;
  173|  14.9M|  }
  174|       |
  175|  3.71M|  assert(cbb->child->is_child);
  176|  3.71M|  struct cbb_child_st *child = &cbb->child->u.child;
  177|  3.71M|  assert(child->base == base);
  178|  3.71M|  size_t child_start = child->offset + child->pending_len_len;
  179|       |
  180|  3.71M|  if (!CBB_flush(cbb->child) ||
  ------------------
  |  Branch (180:7): [True: 0, False: 3.71M]
  ------------------
  181|  3.71M|      child_start < child->offset ||
  ------------------
  |  Branch (181:7): [True: 0, False: 3.71M]
  ------------------
  182|  3.71M|      base->len < child_start) {
  ------------------
  |  Branch (182:7): [True: 0, False: 3.71M]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|  3.71M|  size_t len = base->len - child_start;
  187|       |
  188|  3.71M|  if (child->pending_is_asn1) {
  ------------------
  |  Branch (188:7): [True: 3.71M, False: 0]
  ------------------
  189|       |    // For ASN.1 we assume that we'll only need a single byte for the length.
  190|       |    // If that turned out to be incorrect, we have to move the contents along
  191|       |    // in order to make space.
  192|  3.71M|    uint8_t len_len;
  193|  3.71M|    uint8_t initial_length_byte;
  194|       |
  195|  3.71M|    assert (child->pending_len_len == 1);
  196|       |
  197|  3.71M|    if (len > 0xfffffffe) {
  ------------------
  |  Branch (197:9): [True: 0, False: 3.71M]
  ------------------
  198|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  199|       |      // Too large.
  200|      0|      goto err;
  201|  3.71M|    } else if (len > 0xffffff) {
  ------------------
  |  Branch (201:16): [True: 0, False: 3.71M]
  ------------------
  202|      0|      len_len = 5;
  203|      0|      initial_length_byte = 0x80 | 4;
  204|  3.71M|    } else if (len > 0xffff) {
  ------------------
  |  Branch (204:16): [True: 58.3k, False: 3.65M]
  ------------------
  205|  58.3k|      len_len = 4;
  206|  58.3k|      initial_length_byte = 0x80 | 3;
  207|  3.65M|    } else if (len > 0xff) {
  ------------------
  |  Branch (207:16): [True: 49.1k, False: 3.60M]
  ------------------
  208|  49.1k|      len_len = 3;
  209|  49.1k|      initial_length_byte = 0x80 | 2;
  210|  3.60M|    } else if (len > 0x7f) {
  ------------------
  |  Branch (210:16): [True: 537, False: 3.60M]
  ------------------
  211|    537|      len_len = 2;
  212|    537|      initial_length_byte = 0x80 | 1;
  213|  3.60M|    } else {
  214|  3.60M|      len_len = 1;
  215|  3.60M|      initial_length_byte = (uint8_t)len;
  216|  3.60M|      len = 0;
  217|  3.60M|    }
  218|       |
  219|  3.71M|    if (len_len != 1) {
  ------------------
  |  Branch (219:9): [True: 108k, False: 3.60M]
  ------------------
  220|       |      // We need to move the contents along in order to make space.
  221|   108k|      size_t extra_bytes = len_len - 1;
  222|   108k|      if (!cbb_buffer_add(base, NULL, extra_bytes)) {
  ------------------
  |  Branch (222:11): [True: 0, False: 108k]
  ------------------
  223|      0|        goto err;
  224|      0|      }
  225|   108k|      OPENSSL_memmove(base->buf + child_start + extra_bytes,
  226|   108k|                      base->buf + child_start, len);
  227|   108k|    }
  228|  3.71M|    base->buf[child->offset++] = initial_length_byte;
  229|  3.71M|    child->pending_len_len = len_len - 1;
  230|  3.71M|  }
  231|       |
  232|  3.98M|  for (size_t i = child->pending_len_len - 1; i < child->pending_len_len; i--) {
  ------------------
  |  Branch (232:47): [True: 273k, False: 3.71M]
  ------------------
  233|   273k|    base->buf[child->offset + i] = (uint8_t)len;
  234|   273k|    len >>= 8;
  235|   273k|  }
  236|  3.71M|  if (len != 0) {
  ------------------
  |  Branch (236:7): [True: 0, False: 3.71M]
  ------------------
  237|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|       |
  241|  3.71M|  child->base = NULL;
  242|  3.71M|  cbb->child = NULL;
  243|       |
  244|  3.71M|  return 1;
  245|       |
  246|      0|err:
  247|      0|  base->error = 1;
  248|      0|  return 0;
  249|  3.71M|}
CBB_add_asn1:
  342|  3.75M|int CBB_add_asn1(CBB *cbb, CBB *out_contents, CBS_ASN1_TAG tag) {
  343|  3.75M|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (343:7): [True: 0, False: 3.75M]
  ------------------
  344|      0|    return 0;
  345|      0|  }
  346|       |
  347|       |  // Split the tag into leading bits and tag number.
  348|  3.75M|  uint8_t tag_bits = (tag >> CBS_ASN1_TAG_SHIFT) & 0xe0;
  ------------------
  |  |  193|  3.75M|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  349|  3.75M|  CBS_ASN1_TAG tag_number = tag & CBS_ASN1_TAG_NUMBER_MASK;
  ------------------
  |  |  210|  3.75M|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  3.75M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  350|  3.75M|  if (tag_number >= 0x1f) {
  ------------------
  |  Branch (350:7): [True: 8.09k, False: 3.74M]
  ------------------
  351|       |    // Set all the bits in the tag number to signal high tag number form.
  352|  8.09k|    if (!CBB_add_u8(cbb, tag_bits | 0x1f) ||
  ------------------
  |  Branch (352:9): [True: 0, False: 8.09k]
  ------------------
  353|  8.09k|        !add_base128_integer(cbb, tag_number)) {
  ------------------
  |  Branch (353:9): [True: 0, False: 8.09k]
  ------------------
  354|      0|      return 0;
  355|      0|    }
  356|  3.74M|  } else if (!CBB_add_u8(cbb, tag_bits | tag_number)) {
  ------------------
  |  Branch (356:14): [True: 0, False: 3.74M]
  ------------------
  357|      0|    return 0;
  358|      0|  }
  359|       |
  360|       |  // Reserve one byte of length prefix. |CBB_flush| will finish it later.
  361|  3.75M|  return cbb_add_child(cbb, out_contents, /*len_len=*/1, /*is_asn1=*/1);
  362|  3.75M|}
CBB_add_bytes:
  364|  3.65M|int CBB_add_bytes(CBB *cbb, const uint8_t *data, size_t len) {
  365|  3.65M|  uint8_t *out;
  366|  3.65M|  if (!CBB_add_space(cbb, &out, len)) {
  ------------------
  |  Branch (366:7): [True: 0, False: 3.65M]
  ------------------
  367|      0|    return 0;
  368|      0|  }
  369|  3.65M|  OPENSSL_memcpy(out, data, len);
  370|  3.65M|  return 1;
  371|  3.65M|}
CBB_add_space:
  382|  7.43M|int CBB_add_space(CBB *cbb, uint8_t **out_data, size_t len) {
  383|  7.43M|  if (!CBB_flush(cbb) ||
  ------------------
  |  Branch (383:7): [True: 0, False: 7.43M]
  ------------------
  384|  7.43M|      !cbb_buffer_add(cbb_get_base(cbb), out_data, len)) {
  ------------------
  |  Branch (384:7): [True: 0, False: 7.43M]
  ------------------
  385|      0|    return 0;
  386|      0|  }
  387|  7.43M|  return 1;
  388|  7.43M|}
CBB_add_u8:
  430|  3.76M|int CBB_add_u8(CBB *cbb, uint8_t value) {
  431|  3.76M|  return cbb_add_u(cbb, value, 1);
  432|  3.76M|}
CBB_add_u16:
  434|  20.9k|int CBB_add_u16(CBB *cbb, uint16_t value) {
  435|  20.9k|  return cbb_add_u(cbb, value, 2);
  436|  20.9k|}
cbb.c:cbb_init:
   31|  9.81k|static void cbb_init(CBB *cbb, uint8_t *buf, size_t cap, int can_resize) {
   32|  9.81k|  cbb->is_child = 0;
   33|  9.81k|  cbb->child = NULL;
   34|  9.81k|  cbb->u.base.buf = buf;
   35|  9.81k|  cbb->u.base.len = 0;
   36|  9.81k|  cbb->u.base.cap = cap;
   37|  9.81k|  cbb->u.base.can_resize = can_resize;
   38|  9.81k|  cbb->u.base.error = 0;
   39|  9.81k|}
cbb.c:cbb_get_base:
  151|  29.8M|static struct cbb_buffer_st *cbb_get_base(CBB *cbb) {
  152|  29.8M|  if (cbb->is_child) {
  ------------------
  |  Branch (152:7): [True: 29.7M, False: 127k]
  ------------------
  153|  29.7M|    return cbb->u.child.base;
  154|  29.7M|  }
  155|   127k|  return &cbb->u.base;
  156|  29.8M|}
cbb.c:cbb_buffer_add:
  116|  11.2M|                          size_t len) {
  117|  11.2M|  if (!cbb_buffer_reserve(base, out, len)) {
  ------------------
  |  Branch (117:7): [True: 0, False: 11.2M]
  ------------------
  118|      0|    return 0;
  119|      0|  }
  120|       |  // This will not overflow or |cbb_buffer_reserve| would have failed.
  121|  11.2M|  base->len += len;
  122|  11.2M|  return 1;
  123|  11.2M|}
cbb.c:add_base128_integer:
  319|  8.09k|static int add_base128_integer(CBB *cbb, uint64_t v) {
  320|  8.09k|  unsigned len_len = 0;
  321|  8.09k|  uint64_t copy = v;
  322|  18.9k|  while (copy > 0) {
  ------------------
  |  Branch (322:10): [True: 10.8k, False: 8.09k]
  ------------------
  323|  10.8k|    len_len++;
  324|  10.8k|    copy >>= 7;
  325|  10.8k|  }
  326|  8.09k|  if (len_len == 0) {
  ------------------
  |  Branch (326:7): [True: 0, False: 8.09k]
  ------------------
  327|      0|    len_len = 1;  // Zero is encoded with one byte.
  328|      0|  }
  329|  18.9k|  for (unsigned i = len_len - 1; i < len_len; i--) {
  ------------------
  |  Branch (329:34): [True: 10.8k, False: 8.09k]
  ------------------
  330|  10.8k|    uint8_t byte = (v >> (7 * i)) & 0x7f;
  331|  10.8k|    if (i != 0) {
  ------------------
  |  Branch (331:9): [True: 2.73k, False: 8.09k]
  ------------------
  332|       |      // The high bit denotes whether there is more data.
  333|  2.73k|      byte |= 0x80;
  334|  2.73k|    }
  335|  10.8k|    if (!CBB_add_u8(cbb, byte)) {
  ------------------
  |  Branch (335:9): [True: 0, False: 10.8k]
  ------------------
  336|      0|      return 0;
  337|      0|    }
  338|  10.8k|  }
  339|  8.09k|  return 1;
  340|  8.09k|}
cbb.c:cbb_add_child:
  272|  3.75M|                         int is_asn1) {
  273|  3.75M|  assert(cbb->child == NULL);
  274|  3.75M|  assert(!is_asn1 || len_len == 1);
  275|  3.75M|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  276|  3.75M|  size_t offset = base->len;
  277|       |
  278|       |  // Reserve space for the length prefix.
  279|  3.75M|  uint8_t *prefix_bytes;
  280|  3.75M|  if (!cbb_buffer_add(base, &prefix_bytes, len_len)) {
  ------------------
  |  Branch (280:7): [True: 0, False: 3.75M]
  ------------------
  281|      0|    return 0;
  282|      0|  }
  283|  3.75M|  OPENSSL_memset(prefix_bytes, 0, len_len);
  284|       |
  285|  3.75M|  CBB_zero(out_child);
  286|  3.75M|  out_child->is_child = 1;
  287|  3.75M|  out_child->u.child.base = base;
  288|  3.75M|  out_child->u.child.offset = offset;
  289|  3.75M|  out_child->u.child.pending_len_len = len_len;
  290|  3.75M|  out_child->u.child.pending_is_asn1 = is_asn1;
  291|  3.75M|  cbb->child = out_child;
  292|  3.75M|  return 1;
  293|  3.75M|}
cbb.c:cbb_buffer_reserve:
   73|  11.2M|                              size_t len) {
   74|  11.2M|  if (base == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 11.2M]
  ------------------
   75|      0|    return 0;
   76|      0|  }
   77|       |
   78|  11.2M|  size_t newlen = base->len + len;
   79|  11.2M|  if (newlen < base->len) {
  ------------------
  |  Branch (79:7): [True: 0, False: 11.2M]
  ------------------
   80|       |    // Overflow
   81|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   82|      0|    goto err;
   83|      0|  }
   84|       |
   85|  11.2M|  if (newlen > base->cap) {
  ------------------
  |  Branch (85:7): [True: 5.35k, False: 11.2M]
  ------------------
   86|  5.35k|    if (!base->can_resize) {
  ------------------
  |  Branch (86:9): [True: 0, False: 5.35k]
  ------------------
   87|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   88|      0|      goto err;
   89|      0|    }
   90|       |
   91|  5.35k|    size_t newcap = base->cap * 2;
   92|  5.35k|    if (newcap < base->cap || newcap < newlen) {
  ------------------
  |  Branch (92:9): [True: 0, False: 5.35k]
  |  Branch (92:31): [True: 0, False: 5.35k]
  ------------------
   93|      0|      newcap = newlen;
   94|      0|    }
   95|  5.35k|    uint8_t *newbuf = OPENSSL_realloc(base->buf, newcap);
   96|  5.35k|    if (newbuf == NULL) {
  ------------------
  |  Branch (96:9): [True: 0, False: 5.35k]
  ------------------
   97|      0|      goto err;
   98|      0|    }
   99|       |
  100|  5.35k|    base->buf = newbuf;
  101|  5.35k|    base->cap = newcap;
  102|  5.35k|  }
  103|       |
  104|  11.2M|  if (out) {
  ------------------
  |  Branch (104:7): [True: 11.1M, False: 108k]
  ------------------
  105|  11.1M|    *out = base->buf + base->len;
  106|  11.1M|  }
  107|       |
  108|  11.2M|  return 1;
  109|       |
  110|      0|err:
  111|      0|  base->error = 1;
  112|      0|  return 0;
  113|  11.2M|}
cbb.c:cbb_add_u:
  410|  3.78M|static int cbb_add_u(CBB *cbb, uint64_t v, size_t len_len) {
  411|  3.78M|  uint8_t *buf;
  412|  3.78M|  if (!CBB_add_space(cbb, &buf, len_len)) {
  ------------------
  |  Branch (412:7): [True: 0, False: 3.78M]
  ------------------
  413|      0|    return 0;
  414|      0|  }
  415|       |
  416|  7.59M|  for (size_t i = len_len - 1; i < len_len; i--) {
  ------------------
  |  Branch (416:32): [True: 3.80M, False: 3.78M]
  ------------------
  417|  3.80M|    buf[i] = v;
  418|  3.80M|    v >>= 8;
  419|  3.80M|  }
  420|       |
  421|       |  // |v| must fit in |len_len| bytes.
  422|  3.78M|  if (v != 0) {
  ------------------
  |  Branch (422:7): [True: 0, False: 3.78M]
  ------------------
  423|      0|    cbb_get_base(cbb)->error = 1;
  424|      0|    return 0;
  425|      0|  }
  426|       |
  427|  3.78M|  return 1;
  428|  3.78M|}

CBS_init:
   29|  4.14M|void CBS_init(CBS *cbs, const uint8_t *data, size_t len) {
   30|  4.14M|  cbs->data = data;
   31|  4.14M|  cbs->len = len;
   32|  4.14M|}
CBS_skip:
   45|  3.93M|int CBS_skip(CBS *cbs, size_t len) {
   46|  3.93M|  const uint8_t *dummy;
   47|  3.93M|  return cbs_get(cbs, &dummy, len);
   48|  3.93M|}
CBS_data:
   50|  7.68M|const uint8_t *CBS_data(const CBS *cbs) {
   51|  7.68M|  return cbs->data;
   52|  7.68M|}
CBS_len:
   54|  19.9M|size_t CBS_len(const CBS *cbs) {
   55|  19.9M|  return cbs->len;
   56|  19.9M|}
CBS_mem_equal:
   86|  22.5k|int CBS_mem_equal(const CBS *cbs, const uint8_t *data, size_t len) {
   87|  22.5k|  if (len != cbs->len) {
  ------------------
  |  Branch (87:7): [True: 4.32k, False: 18.2k]
  ------------------
   88|  4.32k|    return 0;
   89|  4.32k|  }
   90|  18.2k|  return CRYPTO_memcmp(cbs->data, data, len) == 0;
   91|  22.5k|}
CBS_get_u8:
  108|  8.23M|int CBS_get_u8(CBS *cbs, uint8_t *out) {
  109|  8.23M|  const uint8_t *v;
  110|  8.23M|  if (!cbs_get(cbs, &v, 1)) {
  ------------------
  |  Branch (110:7): [True: 9.31k, False: 8.22M]
  ------------------
  111|  9.31k|    return 0;
  112|  9.31k|  }
  113|  8.22M|  *out = *v;
  114|  8.22M|  return 1;
  115|  8.23M|}
CBS_get_u16:
  117|  1.89k|int CBS_get_u16(CBS *cbs, uint16_t *out) {
  118|  1.89k|  uint64_t v;
  119|  1.89k|  if (!cbs_get_u(cbs, &v, 2)) {
  ------------------
  |  Branch (119:7): [True: 4, False: 1.89k]
  ------------------
  120|      4|    return 0;
  121|      4|  }
  122|  1.89k|  *out = v;
  123|  1.89k|  return 1;
  124|  1.89k|}
CBS_get_u32:
  143|    148|int CBS_get_u32(CBS *cbs, uint32_t *out) {
  144|    148|  uint64_t v;
  145|    148|  if (!cbs_get_u(cbs, &v, 4)) {
  ------------------
  |  Branch (145:7): [True: 3, False: 145]
  ------------------
  146|      3|    return 0;
  147|      3|  }
  148|    145|  *out = (uint32_t)v;
  149|    145|  return 1;
  150|    148|}
CBS_get_bytes:
  181|  4.05M|int CBS_get_bytes(CBS *cbs, CBS *out, size_t len) {
  182|  4.05M|  const uint8_t *v;
  183|  4.05M|  if (!cbs_get(cbs, &v, len)) {
  ------------------
  |  Branch (183:7): [True: 263, False: 4.05M]
  ------------------
  184|    263|    return 0;
  185|    263|  }
  186|  4.05M|  CBS_init(out, v, len);
  187|  4.05M|  return 1;
  188|  4.05M|}
CBS_get_any_asn1:
  421|  13.9k|int CBS_get_any_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG *out_tag) {
  422|  13.9k|  size_t header_len;
  423|  13.9k|  if (!CBS_get_any_asn1_element(cbs, out, out_tag, &header_len)) {
  ------------------
  |  Branch (423:7): [True: 69, False: 13.8k]
  ------------------
  424|     69|    return 0;
  425|     69|  }
  426|       |
  427|  13.8k|  if (!CBS_skip(out, header_len)) {
  ------------------
  |  Branch (427:7): [True: 0, False: 13.8k]
  ------------------
  428|      0|    assert(0);
  429|      0|    return 0;
  430|      0|  }
  431|       |
  432|  13.8k|  return 1;
  433|  13.8k|}
CBS_get_any_asn1_element:
  436|   117k|                                    size_t *out_header_len) {
  437|   117k|  return cbs_get_any_asn1_element(cbs, out, out_tag, out_header_len, NULL, NULL,
  438|   117k|                                  /*ber_ok=*/0);
  439|   117k|}
CBS_get_any_ber_asn1_element:
  443|  3.94M|                                 int *out_indefinite) {
  444|  3.94M|  int ber_found_temp;
  445|  3.94M|  return cbs_get_any_asn1_element(
  446|  3.94M|      cbs, out, out_tag, out_header_len,
  447|  3.94M|      out_ber_found ? out_ber_found : &ber_found_temp, out_indefinite,
  ------------------
  |  Branch (447:7): [True: 93.2k, False: 3.84M]
  ------------------
  448|  3.94M|      /*ber_ok=*/1);
  449|  3.94M|}
CBS_get_asn1:
  474|  96.6k|int CBS_get_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  475|  96.6k|  return cbs_get_asn1(cbs, out, tag_value, 1 /* skip header */);
  476|  96.6k|}
CBS_get_asn1_element:
  478|  1.29k|int CBS_get_asn1_element(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  479|  1.29k|  return cbs_get_asn1(cbs, out, tag_value, 0 /* include header */);
  480|  1.29k|}
CBS_peek_asn1_tag:
  482|  1.97k|int CBS_peek_asn1_tag(const CBS *cbs, CBS_ASN1_TAG tag_value) {
  483|  1.97k|  CBS copy = *cbs;
  484|  1.97k|  CBS_ASN1_TAG actual_tag;
  485|  1.97k|  return parse_asn1_tag(&copy, &actual_tag) && tag_value == actual_tag;
  ------------------
  |  Branch (485:10): [True: 1.51k, False: 468]
  |  Branch (485:48): [True: 903, False: 607]
  ------------------
  486|  1.97k|}
CBS_get_asn1_uint64:
  488|  7.76k|int CBS_get_asn1_uint64(CBS *cbs, uint64_t *out) {
  489|  7.76k|  CBS bytes;
  490|  7.76k|  if (!CBS_get_asn1(cbs, &bytes, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  7.76k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (490:7): [True: 92, False: 7.67k]
  ------------------
  491|  7.76k|      !CBS_is_unsigned_asn1_integer(&bytes)) {
  ------------------
  |  Branch (491:7): [True: 47, False: 7.62k]
  ------------------
  492|    139|    return 0;
  493|    139|  }
  494|       |
  495|  7.62k|  *out = 0;
  496|  7.62k|  const uint8_t *data = CBS_data(&bytes);
  497|  7.62k|  size_t len = CBS_len(&bytes);
  498|  21.5k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (498:22): [True: 14.0k, False: 7.56k]
  ------------------
  499|  14.0k|    if ((*out >> 56) != 0) {
  ------------------
  |  Branch (499:9): [True: 58, False: 13.9k]
  ------------------
  500|       |      // Too large to represent as a uint64_t.
  501|     58|      return 0;
  502|     58|    }
  503|  13.9k|    *out <<= 8;
  504|  13.9k|    *out |= data[i];
  505|  13.9k|  }
  506|       |
  507|  7.56k|  return 1;
  508|  7.62k|}
CBS_is_valid_asn1_integer:
  671|  12.9k|int CBS_is_valid_asn1_integer(const CBS *cbs, int *out_is_negative) {
  672|  12.9k|  CBS copy = *cbs;
  673|  12.9k|  uint8_t first_byte, second_byte;
  674|  12.9k|  if (!CBS_get_u8(&copy, &first_byte)) {
  ------------------
  |  Branch (674:7): [True: 5, False: 12.9k]
  ------------------
  675|      5|    return 0;  // INTEGERs may not be empty.
  676|      5|  }
  677|  12.9k|  if (out_is_negative != NULL) {
  ------------------
  |  Branch (677:7): [True: 12.9k, False: 0]
  ------------------
  678|  12.9k|    *out_is_negative = (first_byte & 0x80) != 0;
  679|  12.9k|  }
  680|  12.9k|  if (!CBS_get_u8(&copy, &second_byte)) {
  ------------------
  |  Branch (680:7): [True: 6.29k, False: 6.67k]
  ------------------
  681|  6.29k|    return 1;  // One byte INTEGERs are always minimal.
  682|  6.29k|  }
  683|  6.67k|  if ((first_byte == 0x00 && (second_byte & 0x80) == 0) ||
  ------------------
  |  Branch (683:8): [True: 2.46k, False: 4.21k]
  |  Branch (683:30): [True: 14, False: 2.44k]
  ------------------
  684|  6.67k|      (first_byte == 0xff && (second_byte & 0x80) != 0)) {
  ------------------
  |  Branch (684:8): [True: 66, False: 6.59k]
  |  Branch (684:30): [True: 20, False: 46]
  ------------------
  685|     34|    return 0;  // The value is minimal iff the first 9 bits are not all equal.
  686|     34|  }
  687|  6.64k|  return 1;
  688|  6.67k|}
CBS_is_unsigned_asn1_integer:
  690|  7.67k|int CBS_is_unsigned_asn1_integer(const CBS *cbs) {
  691|  7.67k|  int is_negative;
  692|  7.67k|  return CBS_is_valid_asn1_integer(cbs, &is_negative) && !is_negative;
  ------------------
  |  Branch (692:10): [True: 7.64k, False: 26]
  |  Branch (692:58): [True: 7.62k, False: 21]
  ------------------
  693|  7.67k|}
CBS_is_valid_asn1_oid:
  701|  2.06k|int CBS_is_valid_asn1_oid(const CBS *cbs) {
  702|  2.06k|  if (CBS_len(cbs) == 0) {
  ------------------
  |  Branch (702:7): [True: 2, False: 2.05k]
  ------------------
  703|      2|    return 0;  // OID encodings cannot be empty.
  704|      2|  }
  705|       |
  706|  2.05k|  CBS copy = *cbs;
  707|  2.05k|  uint8_t v, prev = 0;
  708|  17.0k|  while (CBS_get_u8(&copy, &v)) {
  ------------------
  |  Branch (708:10): [True: 15.0k, False: 2.05k]
  ------------------
  709|       |    // OID encodings are a sequence of minimally-encoded base-128 integers (see
  710|       |    // |parse_base128_integer|). If |prev|'s MSB was clear, it was the last byte
  711|       |    // of an integer (or |v| is the first byte). |v| is then the first byte of
  712|       |    // the next integer. If first byte of an integer is 0x80, it is not
  713|       |    // minimally-encoded.
  714|  15.0k|    if ((prev & 0x80) == 0 && v == 0x80) {
  ------------------
  |  Branch (714:9): [True: 11.0k, False: 3.97k]
  |  Branch (714:31): [True: 1, False: 11.0k]
  ------------------
  715|      1|      return 0;
  716|      1|    }
  717|  15.0k|    prev = v;
  718|  15.0k|  }
  719|       |
  720|       |  // The last byte should must end an integer encoding.
  721|  2.05k|  return (prev & 0x80) == 0;
  722|  2.05k|}
CBS_parse_generalized_time:
  919|     24|                               int allow_timezone_offset) {
  920|     24|  return CBS_parse_rfc5280_time_internal(cbs, 1, allow_timezone_offset, out_tm);
  921|     24|}
CBS_parse_utc_time:
  924|    376|                       int allow_timezone_offset) {
  925|    376|  return CBS_parse_rfc5280_time_internal(cbs, 0, allow_timezone_offset, out_tm);
  926|    376|}
cbs.c:cbs_get:
   34|  16.3M|static int cbs_get(CBS *cbs, const uint8_t **p, size_t n) {
   35|  16.3M|  if (cbs->len < n) {
  ------------------
  |  Branch (35:7): [True: 9.58k, False: 16.3M]
  ------------------
   36|  9.58k|    return 0;
   37|  9.58k|  }
   38|       |
   39|  16.3M|  *p = cbs->data;
   40|  16.3M|  cbs->data += n;
   41|  16.3M|  cbs->len -= n;
   42|  16.3M|  return 1;
   43|  16.3M|}
cbs.c:cbs_get_u:
   93|  98.6k|static int cbs_get_u(CBS *cbs, uint64_t *out, size_t len) {
   94|  98.6k|  uint64_t result = 0;
   95|  98.6k|  const uint8_t *data;
   96|       |
   97|  98.6k|  if (!cbs_get(cbs, &data, len)) {
  ------------------
  |  Branch (97:7): [True: 11, False: 98.6k]
  ------------------
   98|     11|    return 0;
   99|     11|  }
  100|   293k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (100:22): [True: 194k, False: 98.6k]
  ------------------
  101|   194k|    result <<= 8;
  102|   194k|    result |= data[i];
  103|   194k|  }
  104|  98.6k|  *out = result;
  105|  98.6k|  return 1;
  106|  98.6k|}
cbs.c:cbs_get_any_asn1_element:
  322|  4.06M|                                    int *out_indefinite, int ber_ok) {
  323|  4.06M|  CBS header = *cbs;
  324|  4.06M|  CBS throwaway;
  325|       |
  326|  4.06M|  if (out == NULL) {
  ------------------
  |  Branch (326:7): [True: 0, False: 4.06M]
  ------------------
  327|      0|    out = &throwaway;
  328|      0|  }
  329|  4.06M|  if (ber_ok) {
  ------------------
  |  Branch (329:7): [True: 3.94M, False: 117k]
  ------------------
  330|  3.94M|    *out_ber_found = 0;
  331|  3.94M|    *out_indefinite = 0;
  332|  3.94M|  } else {
  333|   117k|    assert(out_ber_found == NULL);
  334|   117k|    assert(out_indefinite == NULL);
  335|   117k|  }
  336|       |
  337|  4.06M|  CBS_ASN1_TAG tag;
  338|  4.06M|  if (!parse_asn1_tag(&header, &tag)) {
  ------------------
  |  Branch (338:7): [True: 689, False: 4.05M]
  ------------------
  339|    689|    return 0;
  340|    689|  }
  341|  4.05M|  if (out_tag != NULL) {
  ------------------
  |  Branch (341:7): [True: 4.05M, False: 5.24k]
  ------------------
  342|  4.05M|    *out_tag = tag;
  343|  4.05M|  }
  344|       |
  345|  4.05M|  uint8_t length_byte;
  346|  4.05M|  if (!CBS_get_u8(&header, &length_byte)) {
  ------------------
  |  Branch (346:7): [True: 201, False: 4.05M]
  ------------------
  347|    201|    return 0;
  348|    201|  }
  349|       |
  350|  4.05M|  size_t header_len = CBS_len(cbs) - CBS_len(&header);
  351|       |
  352|  4.05M|  size_t len;
  353|       |  // The format for the length encoding is specified in ITU-T X.690 section
  354|       |  // 8.1.3.
  355|  4.05M|  if ((length_byte & 0x80) == 0) {
  ------------------
  |  Branch (355:7): [True: 3.80M, False: 253k]
  ------------------
  356|       |    // Short form length.
  357|  3.80M|    len = ((size_t) length_byte) + header_len;
  358|  3.80M|    if (out_header_len != NULL) {
  ------------------
  |  Branch (358:9): [True: 3.80M, False: 539]
  ------------------
  359|  3.80M|      *out_header_len = header_len;
  360|  3.80M|    }
  361|  3.80M|  } else {
  362|       |    // The high bit indicate that this is the long form, while the next 7 bits
  363|       |    // encode the number of subsequent octets used to encode the length (ITU-T
  364|       |    // X.690 clause 8.1.3.5.b).
  365|   253k|    const size_t num_bytes = length_byte & 0x7f;
  366|   253k|    uint64_t len64;
  367|       |
  368|   253k|    if (ber_ok && (tag & CBS_ASN1_CONSTRUCTED) != 0 && num_bytes == 0) {
  ------------------
  |  |  196|   209k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|   209k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (368:9): [True: 209k, False: 44.1k]
  |  Branch (368:19): [True: 191k, False: 18.4k]
  |  Branch (368:56): [True: 156k, False: 34.2k]
  ------------------
  369|       |      // indefinite length
  370|   156k|      if (out_header_len != NULL) {
  ------------------
  |  Branch (370:11): [True: 156k, False: 0]
  ------------------
  371|   156k|        *out_header_len = header_len;
  372|   156k|      }
  373|   156k|      *out_ber_found = 1;
  374|   156k|      *out_indefinite = 1;
  375|   156k|      return CBS_get_bytes(cbs, out, header_len);
  376|   156k|    }
  377|       |
  378|       |    // ITU-T X.690 clause 8.1.3.5.c specifies that the value 0xff shall not be
  379|       |    // used as the first byte of the length. If this parser encounters that
  380|       |    // value, num_bytes will be parsed as 127, which will fail this check.
  381|  96.8k|    if (num_bytes == 0 || num_bytes > 4) {
  ------------------
  |  Branch (381:9): [True: 9, False: 96.7k]
  |  Branch (381:27): [True: 174, False: 96.6k]
  ------------------
  382|    183|      return 0;
  383|    183|    }
  384|  96.6k|    if (!cbs_get_u(&header, &len64, num_bytes)) {
  ------------------
  |  Branch (384:9): [True: 4, False: 96.6k]
  ------------------
  385|      4|      return 0;
  386|      4|    }
  387|       |    // ITU-T X.690 section 10.1 (DER length forms) requires encoding the
  388|       |    // length with the minimum number of octets. BER could, technically, have
  389|       |    // 125 superfluous zero bytes. We do not attempt to handle that and still
  390|       |    // require that the length fit in a |uint32_t| for BER.
  391|  96.6k|    if (len64 < 128) {
  ------------------
  |  Branch (391:9): [True: 957, False: 95.6k]
  ------------------
  392|       |      // Length should have used short-form encoding.
  393|    957|      if (ber_ok) {
  ------------------
  |  Branch (393:11): [True: 953, False: 4]
  ------------------
  394|    953|        *out_ber_found = 1;
  395|    953|      } else {
  396|      4|        return 0;
  397|      4|      }
  398|    957|    }
  399|  96.6k|    if ((len64 >> ((num_bytes - 1) * 8)) == 0) {
  ------------------
  |  Branch (399:9): [True: 650, False: 95.9k]
  ------------------
  400|       |      // Length should have been at least one byte shorter.
  401|    650|      if (ber_ok) {
  ------------------
  |  Branch (401:11): [True: 649, False: 1]
  ------------------
  402|    649|        *out_ber_found = 1;
  403|    649|      } else {
  404|      1|        return 0;
  405|      1|      }
  406|    650|    }
  407|  96.6k|    len = len64;
  408|  96.6k|    if (len + header_len + num_bytes < len) {
  ------------------
  |  Branch (408:9): [True: 0, False: 96.6k]
  ------------------
  409|       |      // Overflow.
  410|      0|      return 0;
  411|      0|    }
  412|  96.6k|    len += header_len + num_bytes;
  413|  96.6k|    if (out_header_len != NULL) {
  ------------------
  |  Branch (413:9): [True: 91.9k, False: 4.70k]
  ------------------
  414|  91.9k|      *out_header_len = header_len + num_bytes;
  415|  91.9k|    }
  416|  96.6k|  }
  417|       |
  418|  3.90M|  return CBS_get_bytes(cbs, out, len);
  419|  4.05M|}
cbs.c:cbs_get_asn1:
  452|  97.9k|                        int skip_header) {
  453|  97.9k|  size_t header_len;
  454|  97.9k|  CBS_ASN1_TAG tag;
  455|  97.9k|  CBS throwaway;
  456|       |
  457|  97.9k|  if (out == NULL) {
  ------------------
  |  Branch (457:7): [True: 0, False: 97.9k]
  ------------------
  458|      0|    out = &throwaway;
  459|      0|  }
  460|       |
  461|  97.9k|  if (!CBS_get_any_asn1_element(cbs, out, &tag, &header_len) ||
  ------------------
  |  Branch (461:7): [True: 199, False: 97.7k]
  ------------------
  462|  97.9k|      tag != tag_value) {
  ------------------
  |  Branch (462:7): [True: 505, False: 97.2k]
  ------------------
  463|    704|    return 0;
  464|    704|  }
  465|       |
  466|  97.2k|  if (skip_header && !CBS_skip(out, header_len)) {
  ------------------
  |  Branch (466:7): [True: 95.9k, False: 1.29k]
  |  Branch (466:22): [True: 0, False: 95.9k]
  ------------------
  467|      0|    assert(0);
  468|      0|    return 0;
  469|      0|  }
  470|       |
  471|  97.2k|  return 1;
  472|  97.2k|}
cbs.c:parse_asn1_tag:
  281|  4.06M|static int parse_asn1_tag(CBS *cbs, CBS_ASN1_TAG *out) {
  282|  4.06M|  uint8_t tag_byte;
  283|  4.06M|  if (!CBS_get_u8(cbs, &tag_byte)) {
  ------------------
  |  Branch (283:7): [True: 586, False: 4.06M]
  ------------------
  284|    586|    return 0;
  285|    586|  }
  286|       |
  287|       |  // ITU-T X.690 section 8.1.2.3 specifies the format for identifiers with a tag
  288|       |  // number no greater than 30.
  289|       |  //
  290|       |  // If the number portion is 31 (0x1f, the largest value that fits in the
  291|       |  // allotted bits), then the tag is more than one byte long and the
  292|       |  // continuation bytes contain the tag number.
  293|  4.06M|  CBS_ASN1_TAG tag = ((CBS_ASN1_TAG)tag_byte & 0xe0) << CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  4.06M|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  294|  4.06M|  CBS_ASN1_TAG tag_number = tag_byte & 0x1f;
  295|  4.06M|  if (tag_number == 0x1f) {
  ------------------
  |  Branch (295:7): [True: 11.2k, False: 4.05M]
  ------------------
  296|  11.2k|    uint64_t v;
  297|  11.2k|    if (!parse_base128_integer(cbs, &v) ||
  ------------------
  |  Branch (297:9): [True: 194, False: 11.0k]
  ------------------
  298|       |        // Check the tag number is within our supported bounds.
  299|  11.2k|        v > CBS_ASN1_TAG_NUMBER_MASK ||
  ------------------
  |  |  210|  22.3k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  11.0k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (299:9): [True: 204, False: 10.8k]
  ------------------
  300|       |        // Small tag numbers should have used low tag number form, even in BER.
  301|  11.2k|        v < 0x1f) {
  ------------------
  |  Branch (301:9): [True: 22, False: 10.8k]
  ------------------
  302|    420|      return 0;
  303|    420|    }
  304|  10.8k|    tag_number = (CBS_ASN1_TAG)v;
  305|  10.8k|  }
  306|       |
  307|  4.06M|  tag |= tag_number;
  308|       |
  309|       |  // Tag [UNIVERSAL 0] is reserved for use by the encoding. Reject it here to
  310|       |  // avoid some ambiguity around ANY values and BER indefinite-length EOCs. See
  311|       |  // https://crbug.com/boringssl/455.
  312|  4.06M|  if ((tag & ~CBS_ASN1_CONSTRUCTED) == 0) {
  ------------------
  |  |  196|  4.06M|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  4.06M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (312:7): [True: 151, False: 4.06M]
  ------------------
  313|    151|    return 0;
  314|    151|  }
  315|       |
  316|  4.06M|  *out = tag;
  317|  4.06M|  return 1;
  318|  4.06M|}
cbs.c:parse_base128_integer:
  257|  11.2k|static int parse_base128_integer(CBS *cbs, uint64_t *out) {
  258|  11.2k|  uint64_t v = 0;
  259|  11.2k|  uint8_t b;
  260|  21.5k|  do {
  261|  21.5k|    if (!CBS_get_u8(cbs, &b)) {
  ------------------
  |  Branch (261:9): [True: 143, False: 21.3k]
  ------------------
  262|    143|      return 0;
  263|    143|    }
  264|  21.3k|    if ((v >> (64 - 7)) != 0) {
  ------------------
  |  Branch (264:9): [True: 47, False: 21.3k]
  ------------------
  265|       |      // The value is too large.
  266|     47|      return 0;
  267|     47|    }
  268|  21.3k|    if (v == 0 && b == 0x80) {
  ------------------
  |  Branch (268:9): [True: 11.2k, False: 10.0k]
  |  Branch (268:19): [True: 4, False: 11.2k]
  ------------------
  269|       |      // The value must be minimally encoded.
  270|      4|      return 0;
  271|      4|    }
  272|  21.3k|    v = (v << 7) | (b & 0x7f);
  273|       |
  274|       |    // Values end at an octet with the high bit cleared.
  275|  21.3k|  } while (b & 0x80);
  ------------------
  |  Branch (275:12): [True: 10.2k, False: 11.0k]
  ------------------
  276|       |
  277|  11.0k|  *out = v;
  278|  11.0k|  return 1;
  279|  11.2k|}
cbs.c:CBS_parse_rfc5280_time_internal:
  819|    400|                                           struct tm *out_tm) {
  820|    400|  int year, month, day, hour, min, sec, tmp;
  821|    400|  CBS copy = *cbs;
  822|    400|  uint8_t tz;
  823|       |
  824|    400|  if (is_gentime) {
  ------------------
  |  Branch (824:7): [True: 24, False: 376]
  ------------------
  825|     24|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (825:9): [True: 6, False: 18]
  ------------------
  826|      6|      return 0;
  827|      6|    }
  828|     18|    year = tmp * 100;
  829|     18|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (829:9): [True: 12, False: 6]
  ------------------
  830|     12|      return 0;
  831|     12|    }
  832|      6|      year += tmp;
  833|    376|  } else {
  834|    376|    year = 1900;
  835|    376|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (835:9): [True: 6, False: 370]
  ------------------
  836|      6|      return 0;
  837|      6|    }
  838|    370|    year += tmp;
  839|    370|    if (year < 1950) {
  ------------------
  |  Branch (839:9): [True: 357, False: 13]
  ------------------
  840|    357|      year += 100;
  841|    357|    }
  842|    370|    if (year >= 2050) {
  ------------------
  |  Branch (842:9): [True: 0, False: 370]
  ------------------
  843|      0|      return 0;  // A Generalized time must be used.
  844|      0|    }
  845|    370|  }
  846|    376|  if (!cbs_get_two_digits(&copy, &month) || month < 1 ||
  ------------------
  |  Branch (846:7): [True: 6, False: 370]
  |  Branch (846:45): [True: 1, False: 369]
  ------------------
  847|    376|      month > 12 ||  // Reject invalid months.
  ------------------
  |  Branch (847:7): [True: 2, False: 367]
  ------------------
  848|    376|      !cbs_get_two_digits(&copy, &day) ||
  ------------------
  |  Branch (848:7): [True: 5, False: 362]
  ------------------
  849|    376|      !is_valid_day(year, month, day) ||  // Reject invalid days.
  ------------------
  |  Branch (849:7): [True: 7, False: 355]
  ------------------
  850|    376|      !cbs_get_two_digits(&copy, &hour) ||
  ------------------
  |  Branch (850:7): [True: 10, False: 345]
  ------------------
  851|    376|      hour > 23 ||  // Reject invalid hours.
  ------------------
  |  Branch (851:7): [True: 1, False: 344]
  ------------------
  852|    376|      !cbs_get_two_digits(&copy, &min) ||
  ------------------
  |  Branch (852:7): [True: 4, False: 340]
  ------------------
  853|    376|      min > 59 ||  // Reject invalid minutes.
  ------------------
  |  Branch (853:7): [True: 0, False: 340]
  ------------------
  854|    376|      !cbs_get_two_digits(&copy, &sec) || sec > 59 || !CBS_get_u8(&copy, &tz)) {
  ------------------
  |  Branch (854:7): [True: 2, False: 338]
  |  Branch (854:43): [True: 0, False: 338]
  |  Branch (854:55): [True: 1, False: 337]
  ------------------
  855|     39|    return 0;
  856|     39|  }
  857|       |
  858|    337|  int offset_sign = 0;
  859|    337|  switch (tz) {
  860|    334|    case 'Z':
  ------------------
  |  Branch (860:5): [True: 334, False: 3]
  ------------------
  861|    334|      break;  // We correctly have 'Z' on the end as per spec.
  862|      1|    case '+':
  ------------------
  |  Branch (862:5): [True: 1, False: 336]
  ------------------
  863|      1|      offset_sign = 1;
  864|      1|      break;  // Should not be allowed per RFC 5280.
  865|      1|    case '-':
  ------------------
  |  Branch (865:5): [True: 1, False: 336]
  ------------------
  866|      1|      offset_sign = -1;
  867|      1|      break;  // Should not be allowed per RFC 5280.
  868|      1|    default:
  ------------------
  |  Branch (868:5): [True: 1, False: 336]
  ------------------
  869|      1|      return 0;  // Reject anything else after the time.
  870|    337|  }
  871|       |
  872|       |  // If allow_timezone_offset is non-zero, allow for a four digit timezone
  873|       |  // offset to be specified even though this is not allowed by RFC 5280. We are
  874|       |  // permissive of this for UTCTimes due to the unfortunate existence of
  875|       |  // artisinally rolled long lived certificates that were baked into places that
  876|       |  // are now difficult to change. These certificates were generated with the
  877|       |  // 'openssl' command that permissively allowed the creation of certificates
  878|       |  // with notBefore and notAfter times specified as strings for direct
  879|       |  // certificate inclusion on the command line. For context see cl/237068815.
  880|       |  //
  881|       |  // TODO(bbe): This has been expunged from public web-pki as the ecosystem has
  882|       |  // managed to encourage CA compliance with standards. We should find a way to
  883|       |  // get rid of this or make it off by default.
  884|    336|  int offset_seconds = 0;
  885|    336|  if (offset_sign != 0) {
  ------------------
  |  Branch (885:7): [True: 2, False: 334]
  ------------------
  886|      2|    if (!allow_timezone_offset) {
  ------------------
  |  Branch (886:9): [True: 2, False: 0]
  ------------------
  887|      2|      return 0;
  888|      2|    }
  889|      0|    int offset_hours, offset_minutes;
  890|      0|    if (!cbs_get_two_digits(&copy, &offset_hours) ||
  ------------------
  |  Branch (890:9): [True: 0, False: 0]
  ------------------
  891|      0|        offset_hours > 23 ||  // Reject invalid hours.
  ------------------
  |  Branch (891:9): [True: 0, False: 0]
  ------------------
  892|      0|        !cbs_get_two_digits(&copy, &offset_minutes) ||
  ------------------
  |  Branch (892:9): [True: 0, False: 0]
  ------------------
  893|      0|        offset_minutes > 59) {  // Reject invalid minutes.
  ------------------
  |  Branch (893:9): [True: 0, False: 0]
  ------------------
  894|      0|      return 0;
  895|      0|    }
  896|      0|    offset_seconds = offset_sign * (offset_hours * 3600 + offset_minutes * 60);
  897|      0|  }
  898|       |
  899|    334|  if (CBS_len(&copy) != 0) {
  ------------------
  |  Branch (899:7): [True: 2, False: 332]
  ------------------
  900|      2|    return 0;  // Reject invalid lengths.
  901|      2|  }
  902|       |
  903|    332|  if (out_tm != NULL) {
  ------------------
  |  Branch (903:7): [True: 0, False: 332]
  ------------------
  904|       |    // Fill in the tm fields corresponding to what we validated.
  905|      0|    out_tm->tm_year = year - 1900;
  906|      0|    out_tm->tm_mon = month - 1;
  907|      0|    out_tm->tm_mday = day;
  908|      0|    out_tm->tm_hour = hour;
  909|      0|    out_tm->tm_min = min;
  910|      0|    out_tm->tm_sec = sec;
  911|      0|    if (offset_seconds && !OPENSSL_gmtime_adj(out_tm, 0, offset_seconds)) {
  ------------------
  |  Branch (911:9): [True: 0, False: 0]
  |  Branch (911:27): [True: 0, False: 0]
  ------------------
  912|      0|      return 0;
  913|      0|    }
  914|      0|  }
  915|    332|  return 1;
  916|    332|}
cbs.c:cbs_get_two_digits:
  770|  2.20k|static int cbs_get_two_digits(CBS *cbs, int *out) {
  771|  2.20k|  uint8_t first_digit, second_digit;
  772|  2.20k|  if (!CBS_get_u8(cbs, &first_digit)) {
  ------------------
  |  Branch (772:7): [True: 9, False: 2.19k]
  ------------------
  773|      9|    return 0;
  774|      9|  }
  775|  2.19k|  if (!OPENSSL_isdigit(first_digit)) {
  ------------------
  |  Branch (775:7): [True: 18, False: 2.17k]
  ------------------
  776|     18|    return 0;
  777|     18|  }
  778|  2.17k|  if (!CBS_get_u8(cbs, &second_digit)) {
  ------------------
  |  Branch (778:7): [True: 8, False: 2.16k]
  ------------------
  779|      8|    return 0;
  780|      8|  }
  781|  2.16k|  if (!OPENSSL_isdigit(second_digit)) {
  ------------------
  |  Branch (781:7): [True: 16, False: 2.14k]
  ------------------
  782|     16|    return 0;
  783|     16|  }
  784|  2.14k|  *out = (first_digit - '0') * 10 + (second_digit - '0');
  785|  2.14k|  return 1;
  786|  2.16k|}
cbs.c:is_valid_day:
  788|    362|static int is_valid_day(int year, int month, int day) {
  789|    362|  if (day < 1) {
  ------------------
  |  Branch (789:7): [True: 1, False: 361]
  ------------------
  790|      1|    return 0;
  791|      1|  }
  792|    361|  switch (month) {
  793|      1|    case 1:
  ------------------
  |  Branch (793:5): [True: 1, False: 360]
  ------------------
  794|      2|    case 3:
  ------------------
  |  Branch (794:5): [True: 1, False: 360]
  ------------------
  795|      3|    case 5:
  ------------------
  |  Branch (795:5): [True: 1, False: 360]
  ------------------
  796|      8|    case 7:
  ------------------
  |  Branch (796:5): [True: 5, False: 356]
  ------------------
  797|    346|    case 8:
  ------------------
  |  Branch (797:5): [True: 338, False: 23]
  ------------------
  798|    347|    case 10:
  ------------------
  |  Branch (798:5): [True: 1, False: 360]
  ------------------
  799|    348|    case 12:
  ------------------
  |  Branch (799:5): [True: 1, False: 360]
  ------------------
  800|    348|      return day <= 31;
  801|      2|    case 4:
  ------------------
  |  Branch (801:5): [True: 2, False: 359]
  ------------------
  802|      4|    case 6:
  ------------------
  |  Branch (802:5): [True: 2, False: 359]
  ------------------
  803|      6|    case 9:
  ------------------
  |  Branch (803:5): [True: 2, False: 359]
  ------------------
  804|      7|    case 11:
  ------------------
  |  Branch (804:5): [True: 1, False: 360]
  ------------------
  805|      7|      return day <= 30;
  806|      6|    case 2:
  ------------------
  |  Branch (806:5): [True: 6, False: 355]
  ------------------
  807|      6|      if ((year % 4 == 0 && year % 100 != 0) || year % 400 == 0) {
  ------------------
  |  Branch (807:12): [True: 1, False: 5]
  |  Branch (807:29): [True: 1, False: 0]
  |  Branch (807:49): [True: 0, False: 5]
  ------------------
  808|      1|        return day <= 29;
  809|      5|      } else {
  810|      5|        return day <= 28;
  811|      5|      }
  812|      0|    default:
  ------------------
  |  Branch (812:5): [True: 0, False: 361]
  ------------------
  813|      0|      return 0;
  814|    361|  }
  815|    361|}

cbs_get_utf8:
   41|  37.3k|int cbs_get_utf8(CBS *cbs, uint32_t *out) {
   42|  37.3k|  uint8_t c;
   43|  37.3k|  if (!CBS_get_u8(cbs, &c)) {
  ------------------
  |  Branch (43:7): [True: 0, False: 37.3k]
  ------------------
   44|      0|    return 0;
   45|      0|  }
   46|  37.3k|  if (c <= 0x7f) {
  ------------------
  |  Branch (46:7): [True: 36.9k, False: 405]
  ------------------
   47|  36.9k|    *out = c;
   48|  36.9k|    return 1;
   49|  36.9k|  }
   50|    405|  uint32_t v, lower_bound;
   51|    405|  size_t len;
   52|    405|  if ((c & TOP_BITS(3)) == TOP_BITS(2)) {
  ------------------
  |  |   39|    405|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    405|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                if ((c & TOP_BITS(3)) == TOP_BITS(2)) {
  ------------------
  |  |   39|    405|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    405|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (52:7): [True: 277, False: 128]
  ------------------
   53|    277|    v = c & BOTTOM_BITS(5);
  ------------------
  |  |   36|    277|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   54|    277|    len = 1;
   55|    277|    lower_bound = 0x80;
   56|    277|  } else if ((c & TOP_BITS(4)) == TOP_BITS(3)) {
  ------------------
  |  |   39|    128|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    128|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                } else if ((c & TOP_BITS(4)) == TOP_BITS(3)) {
  ------------------
  |  |   39|    128|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    128|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (56:14): [True: 73, False: 55]
  ------------------
   57|     73|    v = c & BOTTOM_BITS(4);
  ------------------
  |  |   36|     73|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   58|     73|    len = 2;
   59|     73|    lower_bound = 0x800;
   60|     73|  } else if ((c & TOP_BITS(5)) == TOP_BITS(4)) {
  ------------------
  |  |   39|     55|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|     55|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                } else if ((c & TOP_BITS(5)) == TOP_BITS(4)) {
  ------------------
  |  |   39|     55|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|     55|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (60:14): [True: 36, False: 19]
  ------------------
   61|     36|    v = c & BOTTOM_BITS(3);
  ------------------
  |  |   36|     36|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   62|     36|    len = 3;
   63|     36|    lower_bound = 0x10000;
   64|     36|  } else {
   65|     19|    return 0;
   66|     19|  }
   67|    890|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (67:22): [True: 520, False: 370]
  ------------------
   68|    520|    if (!CBS_get_u8(cbs, &c) ||
  ------------------
  |  Branch (68:9): [True: 3, False: 517]
  ------------------
   69|    520|        (c & TOP_BITS(2)) != TOP_BITS(1)) {
  ------------------
  |  |   39|    517|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    517|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                      (c & TOP_BITS(2)) != TOP_BITS(1)) {
  ------------------
  |  |   39|    517|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    517|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (69:9): [True: 13, False: 504]
  ------------------
   70|     16|      return 0;
   71|     16|    }
   72|    504|    v <<= 6;
   73|    504|    v |= c & BOTTOM_BITS(6);
  ------------------
  |  |   36|    504|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
   74|    504|  }
   75|    370|  if (!is_valid_code_point(v) ||
  ------------------
  |  Branch (75:7): [True: 10, False: 360]
  ------------------
   76|    370|      v < lower_bound) {
  ------------------
  |  Branch (76:7): [True: 1, False: 359]
  ------------------
   77|     11|    return 0;
   78|     11|  }
   79|    359|  *out = v;
   80|    359|  return 1;
   81|    370|}
cbs_get_latin1:
   83|  1.91k|int cbs_get_latin1(CBS *cbs, uint32_t *out) {
   84|  1.91k|  uint8_t c;
   85|  1.91k|  if (!CBS_get_u8(cbs, &c)) {
  ------------------
  |  Branch (85:7): [True: 0, False: 1.91k]
  ------------------
   86|      0|    return 0;
   87|      0|  }
   88|  1.91k|  *out = c;
   89|  1.91k|  return 1;
   90|  1.91k|}
cbs_get_ucs2_be:
   92|  1.89k|int cbs_get_ucs2_be(CBS *cbs, uint32_t *out) {
   93|       |  // Note UCS-2 (used by BMPString) does not support surrogates.
   94|  1.89k|  uint16_t c;
   95|  1.89k|  if (!CBS_get_u16(cbs, &c) ||
  ------------------
  |  Branch (95:7): [True: 4, False: 1.89k]
  ------------------
   96|  1.89k|      !is_valid_code_point(c)) {
  ------------------
  |  Branch (96:7): [True: 31, False: 1.86k]
  ------------------
   97|     35|    return 0;
   98|     35|  }
   99|  1.86k|  *out = c;
  100|  1.86k|  return 1;
  101|  1.89k|}
cbs_get_utf32_be:
  103|    148|int cbs_get_utf32_be(CBS *cbs, uint32_t *out) {
  104|    148|  return CBS_get_u32(cbs, out) && is_valid_code_point(*out);
  ------------------
  |  Branch (104:10): [True: 145, False: 3]
  |  Branch (104:35): [True: 70, False: 75]
  ------------------
  105|    148|}
cbb_get_utf8_len:
  107|  11.5k|size_t cbb_get_utf8_len(uint32_t u) {
  108|  11.5k|  if (u <= 0x7f) {
  ------------------
  |  Branch (108:7): [True: 11.1k, False: 424]
  ------------------
  109|  11.1k|    return 1;
  110|  11.1k|  }
  111|    424|  if (u <= 0x7ff) {
  ------------------
  |  Branch (111:7): [True: 178, False: 246]
  ------------------
  112|    178|    return 2;
  113|    178|  }
  114|    246|  if (u <= 0xffff) {
  ------------------
  |  Branch (114:7): [True: 239, False: 7]
  ------------------
  115|    239|    return 3;
  116|    239|  }
  117|      7|  return 4;
  118|    246|}
cbb_add_utf8:
  120|  1.50k|int cbb_add_utf8(CBB *cbb, uint32_t u) {
  121|  1.50k|  if (!is_valid_code_point(u)) {
  ------------------
  |  Branch (121:7): [True: 0, False: 1.50k]
  ------------------
  122|      0|    return 0;
  123|      0|  }
  124|  1.50k|  if (u <= 0x7f) {
  ------------------
  |  Branch (124:7): [True: 975, False: 533]
  ------------------
  125|    975|    return CBB_add_u8(cbb, (uint8_t)u);
  126|    975|  }
  127|    533|  if (u <= 0x7ff) {
  ------------------
  |  Branch (127:7): [True: 88, False: 445]
  ------------------
  128|     88|    return CBB_add_u8(cbb, TOP_BITS(2) | (u >> 6)) &&
  ------------------
  |  |   39|     88|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|     88|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (128:12): [True: 88, False: 0]
  ------------------
  129|     88|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|     88|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|     88|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|     88|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (129:12): [True: 88, False: 0]
  ------------------
  130|     88|  }
  131|    445|  if (u <= 0xffff) {
  ------------------
  |  Branch (131:7): [True: 445, False: 0]
  ------------------
  132|    445|    return CBB_add_u8(cbb, TOP_BITS(3) | (u >> 12)) &&
  ------------------
  |  |   39|    445|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    445|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (132:12): [True: 445, False: 0]
  ------------------
  133|    445|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|    445|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    445|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|    445|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (133:12): [True: 445, False: 0]
  ------------------
  134|    445|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|    445|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|    445|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|    445|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (134:12): [True: 445, False: 0]
  ------------------
  135|    445|  }
  136|      0|  if (u <= 0x10ffff) {
  ------------------
  |  Branch (136:7): [True: 0, False: 0]
  ------------------
  137|      0|    return CBB_add_u8(cbb, TOP_BITS(4) | (u >> 18)) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (137:12): [True: 0, False: 0]
  ------------------
  138|      0|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 12) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 12) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (138:12): [True: 0, False: 0]
  ------------------
  139|      0|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (139:12): [True: 0, False: 0]
  ------------------
  140|      0|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (140:12): [True: 0, False: 0]
  ------------------
  141|      0|  }
  142|      0|  return 0;
  143|      0|}
cbb_add_ucs2_be:
  149|  20.9k|int cbb_add_ucs2_be(CBB *cbb, uint32_t u) {
  150|  20.9k|  return u <= 0xffff && is_valid_code_point(u) && CBB_add_u16(cbb, (uint16_t)u);
  ------------------
  |  Branch (150:10): [True: 20.9k, False: 0]
  |  Branch (150:25): [True: 20.9k, False: 0]
  |  Branch (150:51): [True: 20.9k, False: 0]
  ------------------
  151|  20.9k|}
unicode.c:is_valid_code_point:
   20|  24.8k|static int is_valid_code_point(uint32_t v) {
   21|       |  // References in the following are to Unicode 9.0.0.
   22|  24.8k|  if (// The Unicode space runs from zero to 0x10ffff (3.4 D9).
   23|  24.8k|      v > 0x10ffff ||
  ------------------
  |  Branch (23:7): [True: 68, False: 24.7k]
  ------------------
   24|       |      // Values 0x...fffe, 0x...ffff, and 0xfdd0-0xfdef are permanently reserved
   25|       |      // (3.4 D14)
   26|  24.8k|      (v & 0xfffe) == 0xfffe ||
  ------------------
  |  Branch (26:7): [True: 3, False: 24.7k]
  ------------------
   27|  24.8k|      (v >= 0xfdd0 && v <= 0xfdef) ||
  ------------------
  |  Branch (27:8): [True: 202, False: 24.5k]
  |  Branch (27:23): [True: 8, False: 194]
  ------------------
   28|       |      // Surrogate code points are invalid (3.2 C1).
   29|  24.8k|      (v >= 0xd800 && v <= 0xdfff)) {
  ------------------
  |  Branch (29:8): [True: 525, False: 24.2k]
  |  Branch (29:23): [True: 37, False: 488]
  ------------------
   30|    116|    return 0;
   31|    116|  }
   32|  24.7k|  return 1;
   33|  24.8k|}

EVP_des_ede3_cbc:
  181|    559|const EVP_CIPHER *EVP_des_ede3_cbc(void) { return &evp_des_ede3_cbc; }
e_des.c:des_ede3_init_key:
  146|    466|                             const uint8_t *iv, int enc) {
  147|    466|  DES_cblock *deskey = (DES_cblock *)key;
  148|    466|  DES_EDE_KEY *dat = (DES_EDE_KEY *)ctx->cipher_data;
  149|       |
  150|    466|  DES_set_key(&deskey[0], &dat->ks.ks[0]);
  151|    466|  DES_set_key(&deskey[1], &dat->ks.ks[1]);
  152|    466|  DES_set_key(&deskey[2], &dat->ks.ks[2]);
  153|       |
  154|    466|  return 1;
  155|    466|}
e_des.c:des_ede3_cbc_cipher:
  158|    466|                               const uint8_t *in, size_t in_len) {
  159|    466|  DES_EDE_KEY *dat = (DES_EDE_KEY *)ctx->cipher_data;
  160|       |
  161|    466|  DES_ede3_cbc_encrypt(in, out, in_len, &dat->ks.ks[0], &dat->ks.ks[1],
  162|    466|                       &dat->ks.ks[2], (DES_cblock *)ctx->iv, ctx->encrypt);
  163|       |
  164|    466|  return 1;
  165|    466|}

EVP_rc2_40_cbc:
  443|    685|const EVP_CIPHER *EVP_rc2_40_cbc(void) {
  444|    685|  return &rc2_40_cbc;
  445|    685|}
EVP_rc2_cbc:
  461|    113|const EVP_CIPHER *EVP_rc2_cbc(void) {
  462|    113|  return &rc2_cbc;
  463|    113|}
e_rc2.c:rc2_init_key:
  387|    703|                        const uint8_t *iv, int enc) {
  388|    703|  EVP_RC2_KEY *rc2_key = (EVP_RC2_KEY *)ctx->cipher_data;
  389|    703|  RC2_set_key(&rc2_key->ks, EVP_CIPHER_CTX_key_length(ctx), key,
  390|    703|              rc2_key->key_bits);
  391|    703|  return 1;
  392|    703|}
e_rc2.c:RC2_set_key:
  330|    703|static void RC2_set_key(RC2_KEY *key, int len, const uint8_t *data, int bits) {
  331|    703|  int i, j;
  332|    703|  uint8_t *k;
  333|    703|  uint16_t *ki;
  334|    703|  unsigned int c, d;
  335|       |
  336|    703|  k = (uint8_t *)&key->data[0];
  337|    703|  *k = 0;  // for if there is a zero length key
  338|       |
  339|    703|  if (len > 128) {
  ------------------
  |  Branch (339:7): [True: 0, False: 703]
  ------------------
  340|      0|    len = 128;
  341|      0|  }
  342|    703|  if (bits <= 0) {
  ------------------
  |  Branch (342:7): [True: 0, False: 703]
  ------------------
  343|      0|    bits = 1024;
  344|      0|  }
  345|    703|  if (bits > 1024) {
  ------------------
  |  Branch (345:7): [True: 0, False: 703]
  ------------------
  346|      0|    bits = 1024;
  347|      0|  }
  348|       |
  349|  4.41k|  for (i = 0; i < len; i++) {
  ------------------
  |  Branch (349:15): [True: 3.71k, False: 703]
  ------------------
  350|  3.71k|    k[i] = data[i];
  351|  3.71k|  }
  352|       |
  353|       |  // expand table
  354|    703|  d = k[len - 1];
  355|    703|  j = 0;
  356|  86.9k|  for (i = len; i < 128; i++, j++) {
  ------------------
  |  Branch (356:17): [True: 86.2k, False: 703]
  ------------------
  357|  86.2k|    d = key_table[(k[j] + d) & 0xff];
  358|  86.2k|    k[i] = d;
  359|  86.2k|  }
  360|       |
  361|       |  // hmm.... key reduction to 'bits' bits
  362|       |
  363|    703|  j = (bits + 7) >> 3;
  364|    703|  i = 128 - j;
  365|    703|  c = (0xff >> (-bits & 0x07));
  366|       |
  367|    703|  d = key_table[k[i] & c];
  368|    703|  k[i] = d;
  369|  86.9k|  while (i--) {
  ------------------
  |  Branch (369:10): [True: 86.2k, False: 703]
  ------------------
  370|  86.2k|    d = key_table[k[i + j] ^ d];
  371|  86.2k|    k[i] = d;
  372|  86.2k|  }
  373|       |
  374|       |  // copy from bytes into uint16_t's
  375|    703|  ki = &(key->data[63]);
  376|  45.6k|  for (i = 127; i >= 0; i -= 2) {
  ------------------
  |  Branch (376:17): [True: 44.9k, False: 703]
  ------------------
  377|  44.9k|    *(ki--) = ((k[i] << 8) | k[i - 1]) & 0xffff;
  378|  44.9k|  }
  379|    703|}
e_rc2.c:rc2_cbc_cipher:
  395|    701|                          size_t inl) {
  396|    701|  EVP_RC2_KEY *key = (EVP_RC2_KEY *)ctx->cipher_data;
  397|    701|  static const size_t kChunkSize = 0x10000;
  398|       |
  399|    701|  while (inl >= kChunkSize) {
  ------------------
  |  Branch (399:10): [True: 0, False: 701]
  ------------------
  400|      0|    RC2_cbc_encrypt(in, out, kChunkSize, &key->ks, ctx->iv, ctx->encrypt);
  401|      0|    inl -= kChunkSize;
  402|      0|    in += kChunkSize;
  403|      0|    out += kChunkSize;
  404|      0|  }
  405|    701|  if (inl) {
  ------------------
  |  Branch (405:7): [True: 701, False: 0]
  ------------------
  406|    701|    RC2_cbc_encrypt(in, out, inl, &key->ks, ctx->iv, ctx->encrypt);
  407|    701|  }
  408|    701|  return 1;
  409|    701|}
e_rc2.c:RC2_cbc_encrypt:
  233|    701|                            RC2_KEY *ks, uint8_t *iv, int encrypt) {
  234|    701|  uint32_t tin0, tin1;
  235|    701|  uint32_t tout0, tout1, xor0, xor1;
  236|    701|  long l = length;
  237|    701|  uint32_t tin[2];
  238|       |
  239|    701|  if (encrypt) {
  ------------------
  |  Branch (239:7): [True: 0, False: 701]
  ------------------
  240|      0|    c2l(iv, tout0);
  ------------------
  |  |   65|      0|  do {                                    \
  |  |   66|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  241|      0|    c2l(iv, tout1);
  ------------------
  |  |   65|      0|  do {                                    \
  |  |   66|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  242|      0|    iv -= 8;
  243|      0|    for (l -= 8; l >= 0; l -= 8) {
  ------------------
  |  Branch (243:18): [True: 0, False: 0]
  ------------------
  244|      0|      c2l(in, tin0);
  ------------------
  |  |   65|      0|  do {                                    \
  |  |   66|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  245|      0|      c2l(in, tin1);
  ------------------
  |  |   65|      0|  do {                                    \
  |  |   66|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  246|      0|      tin0 ^= tout0;
  247|      0|      tin1 ^= tout1;
  248|      0|      tin[0] = tin0;
  249|      0|      tin[1] = tin1;
  250|      0|      RC2_encrypt(tin, ks);
  251|      0|      tout0 = tin[0];
  252|      0|      l2c(tout0, out);
  ------------------
  |  |  104|      0|  do {                                         \
  |  |  105|      0|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|      0|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|      0|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|      0|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  253|      0|      tout1 = tin[1];
  254|      0|      l2c(tout1, out);
  ------------------
  |  |  104|      0|  do {                                         \
  |  |  105|      0|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|      0|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|      0|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|      0|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  255|      0|    }
  256|      0|    if (l != -8) {
  ------------------
  |  Branch (256:9): [True: 0, False: 0]
  ------------------
  257|      0|      c2ln(in, tin0, tin1, l + 8);
  ------------------
  |  |   73|      0|  do {                                         \
  |  |   74|      0|    (c) += (n);                                \
  |  |   75|      0|    (l1) = (l2) = 0;                           \
  |  |   76|      0|    switch (n) {                               \
  |  |  ------------------
  |  |  |  Branch (76:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   77|      0|      case 8:                                  \
  |  |  ------------------
  |  |  |  Branch (77:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   78|      0|        (l2) = ((uint32_t)(*(--(c)))) << 24L;  \
  |  |   79|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   80|      0|      case 7:                                  \
  |  |  ------------------
  |  |  |  Branch (80:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   81|      0|        (l2) |= ((uint32_t)(*(--(c)))) << 16L; \
  |  |   82|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   83|      0|      case 6:                                  \
  |  |  ------------------
  |  |  |  Branch (83:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   84|      0|        (l2) |= ((uint32_t)(*(--(c)))) << 8L;  \
  |  |   85|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   86|      0|      case 5:                                  \
  |  |  ------------------
  |  |  |  Branch (86:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   87|      0|        (l2) |= ((uint32_t)(*(--(c))));        \
  |  |   88|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   89|      0|      case 4:                                  \
  |  |  ------------------
  |  |  |  Branch (89:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   90|      0|        (l1) = ((uint32_t)(*(--(c)))) << 24L;  \
  |  |   91|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   92|      0|      case 3:                                  \
  |  |  ------------------
  |  |  |  Branch (92:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   93|      0|        (l1) |= ((uint32_t)(*(--(c)))) << 16L; \
  |  |   94|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   95|      0|      case 2:                                  \
  |  |  ------------------
  |  |  |  Branch (95:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   96|      0|        (l1) |= ((uint32_t)(*(--(c)))) << 8L;  \
  |  |   97|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   98|      0|      case 1:                                  \
  |  |  ------------------
  |  |  |  Branch (98:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   99|      0|        (l1) |= ((uint32_t)(*(--(c))));        \
  |  |  100|      0|    }                                          \
  |  |  101|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (101:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  258|      0|      tin0 ^= tout0;
  259|      0|      tin1 ^= tout1;
  260|      0|      tin[0] = tin0;
  261|      0|      tin[1] = tin1;
  262|      0|      RC2_encrypt(tin, ks);
  263|      0|      tout0 = tin[0];
  264|      0|      l2c(tout0, out);
  ------------------
  |  |  104|      0|  do {                                         \
  |  |  105|      0|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|      0|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|      0|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|      0|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  265|      0|      tout1 = tin[1];
  266|      0|      l2c(tout1, out);
  ------------------
  |  |  104|      0|  do {                                         \
  |  |  105|      0|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|      0|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|      0|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|      0|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  267|      0|    }
  268|      0|    l2c(tout0, iv);
  ------------------
  |  |  104|      0|  do {                                         \
  |  |  105|      0|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|      0|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|      0|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|      0|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  269|      0|    l2c(tout1, iv);
  ------------------
  |  |  104|      0|  do {                                         \
  |  |  105|      0|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|      0|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|      0|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|      0|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  270|    701|  } else {
  271|    701|    c2l(iv, xor0);
  ------------------
  |  |   65|    701|  do {                                    \
  |  |   66|    701|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|    701|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|    701|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|    701|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|    701|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  272|    701|    c2l(iv, xor1);
  ------------------
  |  |   65|    701|  do {                                    \
  |  |   66|    701|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|    701|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|    701|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|    701|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|    701|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  273|    701|    iv -= 8;
  274|  84.5k|    for (l -= 8; l >= 0; l -= 8) {
  ------------------
  |  Branch (274:18): [True: 83.8k, False: 701]
  ------------------
  275|  83.8k|      c2l(in, tin0);
  ------------------
  |  |   65|  83.8k|  do {                                    \
  |  |   66|  83.8k|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|  83.8k|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|  83.8k|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|  83.8k|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|  83.8k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  276|  83.8k|      tin[0] = tin0;
  277|  83.8k|      c2l(in, tin1);
  ------------------
  |  |   65|  83.8k|  do {                                    \
  |  |   66|  83.8k|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|  83.8k|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|  83.8k|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|  83.8k|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|  83.8k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  278|  83.8k|      tin[1] = tin1;
  279|  83.8k|      RC2_decrypt(tin, ks);
  280|  83.8k|      tout0 = tin[0] ^ xor0;
  281|  83.8k|      tout1 = tin[1] ^ xor1;
  282|  83.8k|      l2c(tout0, out);
  ------------------
  |  |  104|  83.8k|  do {                                         \
  |  |  105|  83.8k|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|  83.8k|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|  83.8k|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|  83.8k|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|  83.8k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  283|  83.8k|      l2c(tout1, out);
  ------------------
  |  |  104|  83.8k|  do {                                         \
  |  |  105|  83.8k|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|  83.8k|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|  83.8k|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|  83.8k|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|  83.8k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  284|  83.8k|      xor0 = tin0;
  285|  83.8k|      xor1 = tin1;
  286|  83.8k|    }
  287|    701|    if (l != -8) {
  ------------------
  |  Branch (287:9): [True: 0, False: 701]
  ------------------
  288|      0|      c2l(in, tin0);
  ------------------
  |  |   65|      0|  do {                                    \
  |  |   66|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  289|      0|      tin[0] = tin0;
  290|      0|      c2l(in, tin1);
  ------------------
  |  |   65|      0|  do {                                    \
  |  |   66|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   67|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   68|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   69|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   70|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  291|      0|      tin[1] = tin1;
  292|      0|      RC2_decrypt(tin, ks);
  293|      0|      tout0 = tin[0] ^ xor0;
  294|      0|      tout1 = tin[1] ^ xor1;
  295|      0|      l2cn(tout0, tout1, out, l + 8);
  ------------------
  |  |  112|      0|  do {                                              \
  |  |  113|      0|    (c) += (n);                                     \
  |  |  114|      0|    switch (n) {                                    \
  |  |  ------------------
  |  |  |  Branch (114:13): [True: 0, False: 0]
  |  |  ------------------
  |  |  115|      0|      case 8:                                       \
  |  |  ------------------
  |  |  |  Branch (115:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  116|      0|        *(--(c)) = (uint8_t)(((l2) >> 24L) & 0xff); \
  |  |  117|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  118|      0|      case 7:                                       \
  |  |  ------------------
  |  |  |  Branch (118:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  119|      0|        *(--(c)) = (uint8_t)(((l2) >> 16L) & 0xff); \
  |  |  120|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  121|      0|      case 6:                                       \
  |  |  ------------------
  |  |  |  Branch (121:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  122|      0|        *(--(c)) = (uint8_t)(((l2) >> 8L) & 0xff);  \
  |  |  123|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  124|      0|      case 5:                                       \
  |  |  ------------------
  |  |  |  Branch (124:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  125|      0|        *(--(c)) = (uint8_t)(((l2)) & 0xff);        \
  |  |  126|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  127|      0|      case 4:                                       \
  |  |  ------------------
  |  |  |  Branch (127:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  128|      0|        *(--(c)) = (uint8_t)(((l1) >> 24L) & 0xff); \
  |  |  129|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  130|      0|      case 3:                                       \
  |  |  ------------------
  |  |  |  Branch (130:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  131|      0|        *(--(c)) = (uint8_t)(((l1) >> 16L) & 0xff); \
  |  |  132|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  133|      0|      case 2:                                       \
  |  |  ------------------
  |  |  |  Branch (133:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  134|      0|        *(--(c)) = (uint8_t)(((l1) >> 8L) & 0xff);  \
  |  |  135|      0|        OPENSSL_FALLTHROUGH;                        \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  136|      0|      case 1:                                       \
  |  |  ------------------
  |  |  |  Branch (136:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  137|      0|        *(--(c)) = (uint8_t)(((l1)) & 0xff);        \
  |  |  138|      0|    }                                               \
  |  |  139|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (139:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  296|      0|      xor0 = tin0;
  297|      0|      xor1 = tin1;
  298|      0|    }
  299|    701|    l2c(xor0, iv);
  ------------------
  |  |  104|    701|  do {                                         \
  |  |  105|    701|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|    701|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|    701|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|    701|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|    701|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  300|    701|    l2c(xor1, iv);
  ------------------
  |  |  104|    701|  do {                                         \
  |  |  105|    701|    *((c)++) = (uint8_t)(((l)) & 0xff);        \
  |  |  106|    701|    *((c)++) = (uint8_t)(((l) >> 8L) & 0xff);  \
  |  |  107|    701|    *((c)++) = (uint8_t)(((l) >> 16L) & 0xff); \
  |  |  108|    701|    *((c)++) = (uint8_t)(((l) >> 24L) & 0xff); \
  |  |  109|    701|  } while (0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  301|    701|  }
  302|    701|  tin[0] = tin[1] = 0;
  303|    701|}
e_rc2.c:RC2_decrypt:
  187|  83.8k|static void RC2_decrypt(uint32_t *d, RC2_KEY *key) {
  188|  83.8k|  int i, n;
  189|  83.8k|  uint16_t *p0, *p1;
  190|  83.8k|  uint16_t x0, x1, x2, x3, t;
  191|  83.8k|  uint32_t l;
  192|       |
  193|  83.8k|  l = d[0];
  194|  83.8k|  x0 = (uint16_t)l & 0xffff;
  195|  83.8k|  x1 = (uint16_t)(l >> 16L);
  196|  83.8k|  l = d[1];
  197|  83.8k|  x2 = (uint16_t)l & 0xffff;
  198|  83.8k|  x3 = (uint16_t)(l >> 16L);
  199|       |
  200|  83.8k|  n = 3;
  201|  83.8k|  i = 5;
  202|       |
  203|  83.8k|  p0 = &key->data[63];
  204|  83.8k|  p1 = &key->data[0];
  205|  1.34M|  for (;;) {
  206|  1.34M|    t = ((x3 << 11) | (x3 >> 5)) & 0xffff;
  207|  1.34M|    x3 = (t - (x0 & ~x2) - (x1 & x2) - *(p0--)) & 0xffff;
  208|  1.34M|    t = ((x2 << 13) | (x2 >> 3)) & 0xffff;
  209|  1.34M|    x2 = (t - (x3 & ~x1) - (x0 & x1) - *(p0--)) & 0xffff;
  210|  1.34M|    t = ((x1 << 14) | (x1 >> 2)) & 0xffff;
  211|  1.34M|    x1 = (t - (x2 & ~x0) - (x3 & x0) - *(p0--)) & 0xffff;
  212|  1.34M|    t = ((x0 << 15) | (x0 >> 1)) & 0xffff;
  213|  1.34M|    x0 = (t - (x1 & ~x3) - (x2 & x3) - *(p0--)) & 0xffff;
  214|       |
  215|  1.34M|    if (--i == 0) {
  ------------------
  |  Branch (215:9): [True: 251k, False: 1.09M]
  ------------------
  216|   251k|      if (--n == 0) {
  ------------------
  |  Branch (216:11): [True: 83.8k, False: 167k]
  ------------------
  217|  83.8k|        break;
  218|  83.8k|      }
  219|   167k|      i = (n == 2) ? 6 : 5;
  ------------------
  |  Branch (219:11): [True: 83.8k, False: 83.8k]
  ------------------
  220|       |
  221|   167k|      x3 = (x3 - p1[x2 & 0x3f]) & 0xffff;
  222|   167k|      x2 = (x2 - p1[x1 & 0x3f]) & 0xffff;
  223|   167k|      x1 = (x1 - p1[x0 & 0x3f]) & 0xffff;
  224|   167k|      x0 = (x0 - p1[x3 & 0x3f]) & 0xffff;
  225|   167k|    }
  226|  1.34M|  }
  227|       |
  228|  83.8k|  d[0] = (uint32_t)(x0 & 0xffff) | ((uint32_t)(x1 & 0xffff) << 16L);
  229|  83.8k|  d[1] = (uint32_t)(x2 & 0xffff) | ((uint32_t)(x3 & 0xffff) << 16L);
  230|  83.8k|}
e_rc2.c:rc2_ctrl:
  411|    703|static int rc2_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg, void *ptr) {
  412|    703|  EVP_RC2_KEY *key = (EVP_RC2_KEY *)ctx->cipher_data;
  413|       |
  414|    703|  switch (type) {
  415|    703|    case EVP_CTRL_INIT:
  ------------------
  |  |  528|    703|#define EVP_CTRL_INIT 0x0
  ------------------
  |  Branch (415:5): [True: 703, False: 0]
  ------------------
  416|    703|      key->key_bits = EVP_CIPHER_CTX_key_length(ctx) * 8;
  417|    703|      return 1;
  418|      0|    case EVP_CTRL_SET_RC2_KEY_BITS:
  ------------------
  |  |  531|      0|#define EVP_CTRL_SET_RC2_KEY_BITS 0x3
  ------------------
  |  Branch (418:5): [True: 0, False: 703]
  ------------------
  419|       |      // Should be overridden by later call to |EVP_CTRL_INIT|, but
  420|       |      // people call it, so it may as well work.
  421|      0|      key->key_bits = arg;
  422|      0|      return 1;
  423|       |
  424|      0|    default:
  ------------------
  |  Branch (424:5): [True: 0, False: 703]
  ------------------
  425|      0|      return -1;
  426|    703|  }
  427|    703|}

EVP_rc4:
   89|      9|const EVP_CIPHER *EVP_rc4(void) { return &rc4; }
e_rc4.c:rc4_init_key:
   68|      9|                        const uint8_t *iv, int enc) {
   69|      9|  RC4_KEY *rc4key = (RC4_KEY *)ctx->cipher_data;
   70|       |
   71|      9|  RC4_set_key(rc4key, EVP_CIPHER_CTX_key_length(ctx), key);
   72|      9|  return 1;
   73|      9|}
e_rc4.c:rc4_cipher:
   76|      9|                      size_t in_len) {
   77|      9|  RC4_KEY *rc4key = (RC4_KEY *)ctx->cipher_data;
   78|       |
   79|      9|  RC4(rc4key, in_len, in, out);
   80|      9|  return 1;
   81|      9|}

OPENSSL_cpuid_setup:
  153|      2|void OPENSSL_cpuid_setup(void) {
  154|       |  // Determine the vendor and maximum input value.
  155|      2|  uint32_t eax, ebx, ecx, edx;
  156|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 0);
  157|       |
  158|      2|  uint32_t num_ids = eax;
  159|       |
  160|      2|  int is_intel = ebx == 0x756e6547 /* Genu */ &&
  ------------------
  |  Branch (160:18): [True: 2, False: 0]
  ------------------
  161|      2|                 edx == 0x49656e69 /* ineI */ &&
  ------------------
  |  Branch (161:18): [True: 2, False: 0]
  ------------------
  162|      2|                 ecx == 0x6c65746e /* ntel */;
  ------------------
  |  Branch (162:18): [True: 2, False: 0]
  ------------------
  163|      2|  int is_amd = ebx == 0x68747541 /* Auth */ &&
  ------------------
  |  Branch (163:16): [True: 0, False: 2]
  ------------------
  164|      2|               edx == 0x69746e65 /* enti */ &&
  ------------------
  |  Branch (164:16): [True: 0, False: 0]
  ------------------
  165|      2|               ecx == 0x444d4163 /* cAMD */;
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|       |
  167|      2|  uint32_t extended_features[2] = {0};
  168|      2|  if (num_ids >= 7) {
  ------------------
  |  Branch (168:7): [True: 2, False: 0]
  ------------------
  169|      2|    OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 7);
  170|      2|    extended_features[0] = ebx;
  171|      2|    extended_features[1] = ecx;
  172|      2|  }
  173|       |
  174|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 1);
  175|       |
  176|      2|  if (is_amd) {
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|       |    // See https://www.amd.com/system/files/TechDocs/25481.pdf, page 10.
  178|      0|    const uint32_t base_family = (eax >> 8) & 15;
  179|      0|    const uint32_t base_model = (eax >> 4) & 15;
  180|       |
  181|      0|    uint32_t family = base_family;
  182|      0|    uint32_t model = base_model;
  183|      0|    if (base_family == 0xf) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      const uint32_t ext_family = (eax >> 20) & 255;
  185|      0|      family += ext_family;
  186|      0|      const uint32_t ext_model = (eax >> 16) & 15;
  187|      0|      model |= ext_model << 4;
  188|      0|    }
  189|       |
  190|      0|    if (family < 0x17 || (family == 0x17 && 0x70 <= model && model <= 0x7f)) {
  ------------------
  |  Branch (190:9): [True: 0, False: 0]
  |  Branch (190:27): [True: 0, False: 0]
  |  Branch (190:45): [True: 0, False: 0]
  |  Branch (190:62): [True: 0, False: 0]
  ------------------
  191|       |      // Disable RDRAND on AMD families before 0x17 (Zen) due to reported
  192|       |      // failures after suspend.
  193|       |      // https://bugzilla.redhat.com/show_bug.cgi?id=1150286
  194|       |      // Also disable for family 0x17, models 0x70–0x7f, due to possible RDRAND
  195|       |      // failures there too.
  196|      0|      ecx &= ~(1u << 30);
  197|      0|    }
  198|      0|  }
  199|       |
  200|       |  // Force the hyper-threading bit so that the more conservative path is always
  201|       |  // chosen.
  202|      2|  edx |= 1u << 28;
  203|       |
  204|       |  // Reserved bit #20 was historically repurposed to control the in-memory
  205|       |  // representation of RC4 state. Always set it to zero.
  206|      2|  edx &= ~(1u << 20);
  207|       |
  208|       |  // Reserved bit #30 is repurposed to signal an Intel CPU.
  209|      2|  if (is_intel) {
  ------------------
  |  Branch (209:7): [True: 2, False: 0]
  ------------------
  210|      2|    edx |= (1u << 30);
  211|       |
  212|       |    // Clear the XSAVE bit on Knights Landing to mimic Silvermont. This enables
  213|       |    // some Silvermont-specific codepaths which perform better. See OpenSSL
  214|       |    // commit 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  215|      2|    if ((eax & 0x0fff0ff0) == 0x00050670 /* Knights Landing */ ||
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      2|        (eax & 0x0fff0ff0) == 0x00080650 /* Knights Mill (per SDE) */) {
  ------------------
  |  Branch (216:9): [True: 0, False: 2]
  ------------------
  217|      0|      ecx &= ~(1u << 26);
  218|      0|    }
  219|      2|  } else {
  220|      0|    edx &= ~(1u << 30);
  221|      0|  }
  222|       |
  223|       |  // The SDBG bit is repurposed to denote AMD XOP support. Don't ever use AMD
  224|       |  // XOP code paths.
  225|      2|  ecx &= ~(1u << 11);
  226|       |
  227|      2|  uint64_t xcr0 = 0;
  228|      2|  if (ecx & (1u << 27)) {
  ------------------
  |  Branch (228:7): [True: 2, False: 0]
  ------------------
  229|       |    // XCR0 may only be queried if the OSXSAVE bit is set.
  230|      2|    xcr0 = OPENSSL_xgetbv(0);
  231|      2|  }
  232|       |  // See Intel manual, volume 1, section 14.3.
  233|      2|  if ((xcr0 & 6) != 6) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2]
  ------------------
  234|       |    // YMM registers cannot be used.
  235|      0|    ecx &= ~(1u << 28);  // AVX
  236|      0|    ecx &= ~(1u << 12);  // FMA
  237|      0|    ecx &= ~(1u << 11);  // AMD XOP
  238|       |    // Clear AVX2 and AVX512* bits.
  239|       |    //
  240|       |    // TODO(davidben): Should bits 17 and 26-28 also be cleared? Upstream
  241|       |    // doesn't clear those.
  242|      0|    extended_features[0] &=
  243|      0|        ~((1u << 5) | (1u << 16) | (1u << 21) | (1u << 30) | (1u << 31));
  244|      0|  }
  245|       |  // See Intel manual, volume 1, section 15.2.
  246|      2|  if ((xcr0 & 0xe6) != 0xe6) {
  ------------------
  |  Branch (246:7): [True: 2, False: 0]
  ------------------
  247|       |    // Clear AVX512F. Note we don't touch other AVX512 extensions because they
  248|       |    // can be used with YMM.
  249|      2|    extended_features[0] &= ~(1u << 16);
  250|      2|  }
  251|       |
  252|       |  // Disable ADX instructions on Knights Landing. See OpenSSL commit
  253|       |  // 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  254|      2|  if ((ecx & (1u << 26)) == 0) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    extended_features[0] &= ~(1u << 19);
  256|      0|  }
  257|       |
  258|      2|  OPENSSL_ia32cap_P[0] = edx;
  259|      2|  OPENSSL_ia32cap_P[1] = ecx;
  260|      2|  OPENSSL_ia32cap_P[2] = extended_features[0];
  261|      2|  OPENSSL_ia32cap_P[3] = extended_features[1];
  262|       |
  263|      2|  const char *env1, *env2;
  264|      2|  env1 = getenv("OPENSSL_ia32cap");
  265|      2|  if (env1 == NULL) {
  ------------------
  |  Branch (265:7): [True: 2, False: 0]
  ------------------
  266|      2|    return;
  267|      2|  }
  268|       |
  269|       |  // OPENSSL_ia32cap can contain zero, one or two values, separated with a ':'.
  270|       |  // Each value is a 64-bit, unsigned value which may start with "0x" to
  271|       |  // indicate a hex value. Prior to the 64-bit value, a '~' or '|' may be given.
  272|       |  //
  273|       |  // If the '~' prefix is present:
  274|       |  //   the value is inverted and ANDed with the probed CPUID result
  275|       |  // If the '|' prefix is present:
  276|       |  //   the value is ORed with the probed CPUID result
  277|       |  // Otherwise:
  278|       |  //   the value is taken as the result of the CPUID
  279|       |  //
  280|       |  // The first value determines OPENSSL_ia32cap_P[0] and [1]. The second [2]
  281|       |  // and [3].
  282|       |
  283|      0|  handle_cpu_env(&OPENSSL_ia32cap_P[0], env1);
  284|      0|  env2 = strchr(env1, ':');
  285|      0|  if (env2 != NULL) {
  ------------------
  |  Branch (285:7): [True: 0, False: 0]
  ------------------
  286|      0|    handle_cpu_env(&OPENSSL_ia32cap_P[2], env2 + 1);
  287|      0|  }
  288|      0|}
cpu_intel.c:OPENSSL_cpuid:
   80|      6|                          uint32_t *out_ecx, uint32_t *out_edx, uint32_t leaf) {
   81|       |#if defined(_MSC_VER)
   82|       |  int tmp[4];
   83|       |  __cpuid(tmp, (int)leaf);
   84|       |  *out_eax = (uint32_t)tmp[0];
   85|       |  *out_ebx = (uint32_t)tmp[1];
   86|       |  *out_ecx = (uint32_t)tmp[2];
   87|       |  *out_edx = (uint32_t)tmp[3];
   88|       |#elif defined(__pic__) && defined(OPENSSL_32_BIT)
   89|       |  // Inline assembly may not clobber the PIC register. For 32-bit, this is EBX.
   90|       |  // See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47602.
   91|       |  __asm__ volatile (
   92|       |    "xor %%ecx, %%ecx\n"
   93|       |    "mov %%ebx, %%edi\n"
   94|       |    "cpuid\n"
   95|       |    "xchg %%edi, %%ebx\n"
   96|       |    : "=a"(*out_eax), "=D"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
   97|       |    : "a"(leaf)
   98|       |  );
   99|       |#else
  100|      6|  __asm__ volatile (
  101|      6|    "xor %%ecx, %%ecx\n"
  102|      6|    "cpuid\n"
  103|      6|    : "=a"(*out_eax), "=b"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
  104|      6|    : "a"(leaf)
  105|      6|  );
  106|      6|#endif
  107|      6|}
cpu_intel.c:OPENSSL_xgetbv:
  111|      2|static uint64_t OPENSSL_xgetbv(uint32_t xcr) {
  112|       |#if defined(_MSC_VER)
  113|       |  return (uint64_t)_xgetbv(xcr);
  114|       |#else
  115|      2|  uint32_t eax, edx;
  116|      2|  __asm__ volatile ("xgetbv" : "=a"(eax), "=d"(edx) : "c"(xcr));
  117|      2|  return (((uint64_t)edx) << 32) | eax;
  118|      2|#endif
  119|      2|}

crypto.c:do_library_init:
  151|      2|static void OPENSSL_CDECL do_library_init(void) {
  152|       | // WARNING: this function may only configure the capability variables. See the
  153|       | // note above about the linker bug.
  154|      2|#if defined(NEED_CPUID)
  155|      2|  OPENSSL_cpuid_setup();
  156|      2|#endif
  157|      2|}

x25519_ge_scalarmult_base:
  799|    114|void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t a[32]) {
  800|    114|#if defined(BORINGSSL_FE25519_ADX)
  801|    114|  if (CRYPTO_is_BMI1_capable() && CRYPTO_is_BMI2_capable() &&
  ------------------
  |  Branch (801:7): [True: 114, False: 0]
  |  Branch (801:35): [True: 114, False: 0]
  ------------------
  802|    114|      CRYPTO_is_ADX_capable()) {
  ------------------
  |  Branch (802:7): [True: 114, False: 0]
  ------------------
  803|    114|    uint8_t t[4][32];
  804|    114|    x25519_ge_scalarmult_base_adx(t, a);
  805|    114|    fiat_25519_from_bytes(h->X.v, t[0]);
  806|    114|    fiat_25519_from_bytes(h->Y.v, t[1]);
  807|    114|    fiat_25519_from_bytes(h->Z.v, t[2]);
  808|    114|    fiat_25519_from_bytes(h->T.v, t[3]);
  809|    114|    return;
  810|    114|  }
  811|      0|#endif
  812|      0|  signed char e[64];
  813|      0|  signed char carry;
  814|      0|  ge_p1p1 r;
  815|      0|  ge_p2 s;
  816|      0|  ge_precomp t;
  817|      0|  int i;
  818|       |
  819|      0|  for (i = 0; i < 32; ++i) {
  ------------------
  |  Branch (819:15): [True: 0, False: 0]
  ------------------
  820|      0|    e[2 * i + 0] = (a[i] >> 0) & 15;
  821|      0|    e[2 * i + 1] = (a[i] >> 4) & 15;
  822|      0|  }
  823|       |  // each e[i] is between 0 and 15
  824|       |  // e[63] is between 0 and 7
  825|       |
  826|      0|  carry = 0;
  827|      0|  for (i = 0; i < 63; ++i) {
  ------------------
  |  Branch (827:15): [True: 0, False: 0]
  ------------------
  828|      0|    e[i] += carry;
  829|      0|    carry = e[i] + 8;
  830|      0|    carry >>= 4;
  831|      0|    e[i] -= carry << 4;
  832|      0|  }
  833|      0|  e[63] += carry;
  834|       |  // each e[i] is between -8 and 8
  835|       |
  836|      0|  ge_p3_0(h);
  837|      0|  for (i = 1; i < 64; i += 2) {
  ------------------
  |  Branch (837:15): [True: 0, False: 0]
  ------------------
  838|      0|    table_select(&t, i / 2, e[i]);
  839|      0|    ge_madd(&r, h, &t);
  840|      0|    x25519_ge_p1p1_to_p3(h, &r);
  841|      0|  }
  842|       |
  843|      0|  ge_p3_dbl(&r, h);
  844|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  845|      0|  ge_p2_dbl(&r, &s);
  846|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  847|      0|  ge_p2_dbl(&r, &s);
  848|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  849|      0|  ge_p2_dbl(&r, &s);
  850|      0|  x25519_ge_p1p1_to_p3(h, &r);
  851|       |
  852|      0|  for (i = 0; i < 64; i += 2) {
  ------------------
  |  Branch (852:15): [True: 0, False: 0]
  ------------------
  853|      0|    table_select(&t, i / 2, e[i]);
  854|      0|    ge_madd(&r, h, &t);
  855|      0|    x25519_ge_p1p1_to_p3(h, &r);
  856|      0|  }
  857|      0|}
ED25519_keypair_from_seed:
 1975|     83|                               const uint8_t seed[32]) {
 1976|     83|  uint8_t az[SHA512_DIGEST_LENGTH];
 1977|     83|  SHA512(seed, 32, az);
 1978|       |
 1979|     83|  az[0] &= 248;
 1980|     83|  az[31] &= 127;
 1981|     83|  az[31] |= 64;
 1982|       |
 1983|     83|  ge_p3 A;
 1984|     83|  x25519_ge_scalarmult_base(&A, az);
 1985|     83|  ge_p3_tobytes(out_public_key, &A);
 1986|       |
 1987|     83|  OPENSSL_memcpy(out_private_key, seed, 32);
 1988|     83|  OPENSSL_memcpy(out_private_key + 32, out_public_key, 32);
 1989|     83|}
X25519_public_from_private:
 2125|     31|                                const uint8_t private_key[32]) {
 2126|       |#if defined(BORINGSSL_X25519_NEON)
 2127|       |  if (CRYPTO_is_NEON_capable()) {
 2128|       |    static const uint8_t kMongomeryBasePoint[32] = {9};
 2129|       |    x25519_NEON(out_public_value, private_key, kMongomeryBasePoint);
 2130|       |    return;
 2131|       |  }
 2132|       |#endif
 2133|       |
 2134|     31|  uint8_t e[32];
 2135|     31|  OPENSSL_memcpy(e, private_key, 32);
 2136|     31|  e[0] &= 248;
 2137|     31|  e[31] &= 127;
 2138|     31|  e[31] |= 64;
 2139|       |
 2140|     31|  ge_p3 A;
 2141|     31|  x25519_ge_scalarmult_base(&A, e);
 2142|       |
 2143|       |  // We only need the u-coordinate of the curve25519 point. The map is
 2144|       |  // u=(y+1)/(1-y). Since y=Y/Z, this gives u=(Z+Y)/(Z-Y).
 2145|     31|  fe_loose zplusy, zminusy;
 2146|     31|  fe zminusy_inv;
 2147|     31|  fe_add(&zplusy, &A.Z, &A.Y);
 2148|     31|  fe_sub(&zminusy, &A.Z, &A.Y);
 2149|     31|  fe_loose_invert(&zminusy_inv, &zminusy);
 2150|     31|  fe_mul_tlt(&zminusy_inv, &zplusy, &zminusy_inv);
 2151|     31|  fe_tobytes(out_public_value, &zminusy_inv);
 2152|     31|  CONSTTIME_DECLASSIFY(out_public_value, 32);
 2153|     31|}
curve25519.c:fe_invert:
  374|     83|static void fe_invert(fe *out, const fe *z) {
  375|     83|  fe_loose l;
  376|     83|  fe_copy_lt(&l, z);
  377|     83|  fe_loose_invert(out, &l);
  378|     83|}
curve25519.c:fe_mul_ttt:
  231|  1.30k|static void fe_mul_ttt(fe *h, const fe *f, const fe *g) {
  232|  1.30k|  fe_mul_impl(h->v, f->v, g->v);
  233|  1.30k|}
curve25519.c:fe_mul_impl:
  216|  1.45k|                        const fe_limb_t in2[FE_NUM_LIMBS]) {
  217|  1.45k|  assert_fe_loose(in1);
  ------------------
  |  |   99|  1.45k|  do {                                                                  \
  |  |  100|  8.70k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 7.25k, False: 1.45k]
  |  |  ------------------
  |  |  101|  7.25k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  7.25k|    }                                                                   \
  |  |  103|  1.45k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  218|  1.45k|  assert_fe_loose(in2);
  ------------------
  |  |   99|  1.45k|  do {                                                                  \
  |  |  100|  8.70k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 7.25k, False: 1.45k]
  |  |  ------------------
  |  |  101|  7.25k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  7.25k|    }                                                                   \
  |  |  103|  1.45k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  219|  1.45k|  fiat_25519_carry_mul(out, in1, in2);
  220|  1.45k|  assert_fe(out);
  ------------------
  |  |   82|  1.45k|  do {                                                                  \
  |  |   83|  8.70k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 7.25k, False: 1.45k]
  |  |  ------------------
  |  |   84|  7.25k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  7.25k|    }                                                                   \
  |  |   86|  1.45k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  221|  1.45k|}
curve25519.c:fe_tobytes:
  165|    197|static void fe_tobytes(uint8_t s[32], const fe *f) {
  166|    197|  assert_fe(f->v);
  ------------------
  |  |   82|    197|  do {                                                                  \
  |  |   83|  1.18k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 985, False: 197]
  |  |  ------------------
  |  |   84|    985|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    985|    }                                                                   \
  |  |   86|    197|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  167|    197|  fiat_25519_to_bytes(s, f->v);
  168|    197|}
curve25519.c:fe_isnegative:
  394|     83|static int fe_isnegative(const fe *f) {
  395|     83|  uint8_t s[32];
  396|     83|  fe_tobytes(s, f);
  397|     83|  return s[0] & 1;
  398|     83|}
curve25519.c:fe_sq_tt:
  253|  28.8k|static void fe_sq_tt(fe *h, const fe *f) {
  254|  28.8k|  assert_fe_loose(f->v);
  ------------------
  |  |   99|  28.8k|  do {                                                                  \
  |  |  100|   173k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 144k, False: 28.8k]
  |  |  ------------------
  |  |  101|   144k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|   144k|    }                                                                   \
  |  |  103|  28.8k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  255|  28.8k|  fiat_25519_carry_square(h->v, f->v);
  256|  28.8k|  assert_fe(h->v);
  ------------------
  |  |   82|  28.8k|  do {                                                                  \
  |  |   83|   173k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 144k, False: 28.8k]
  |  |  ------------------
  |  |   84|   144k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|   144k|    }                                                                   \
  |  |   86|  28.8k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  257|  28.8k|}
curve25519.c:fe_sub:
  201|     31|static void fe_sub(fe_loose *h, const fe *f, const fe *g) {
  202|     31|  assert_fe(f->v);
  ------------------
  |  |   82|     31|  do {                                                                  \
  |  |   83|    186|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 155, False: 31]
  |  |  ------------------
  |  |   84|    155|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    155|    }                                                                   \
  |  |   86|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  203|     31|  assert_fe(g->v);
  ------------------
  |  |   82|     31|  do {                                                                  \
  |  |   83|    186|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 155, False: 31]
  |  |  ------------------
  |  |   84|    155|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    155|    }                                                                   \
  |  |   86|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  204|     31|  fiat_25519_sub(h->v, f->v, g->v);
  205|     31|  assert_fe_loose(h->v);
  ------------------
  |  |   99|     31|  do {                                                                  \
  |  |  100|    186|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 155, False: 31]
  |  |  ------------------
  |  |  101|    155|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|    155|    }                                                                   \
  |  |  103|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  206|     31|}
curve25519.c:fe_add:
  192|     31|static void fe_add(fe_loose *h, const fe *f, const fe *g) {
  193|     31|  assert_fe(f->v);
  ------------------
  |  |   82|     31|  do {                                                                  \
  |  |   83|    186|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 155, False: 31]
  |  |  ------------------
  |  |   84|    155|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    155|    }                                                                   \
  |  |   86|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  194|     31|  assert_fe(g->v);
  ------------------
  |  |   82|     31|  do {                                                                  \
  |  |   83|    186|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 155, False: 31]
  |  |  ------------------
  |  |   84|    155|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    155|    }                                                                   \
  |  |   86|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  195|     31|  fiat_25519_add(h->v, f->v, g->v);
  196|     31|  assert_fe_loose(h->v);
  ------------------
  |  |   99|     31|  do {                                                                  \
  |  |  100|    186|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 155, False: 31]
  |  |  ------------------
  |  |  101|    155|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|    155|    }                                                                   \
  |  |  103|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  197|     31|}
curve25519.c:fe_copy_lt:
  311|     83|static void fe_copy_lt(fe_loose *h, const fe *f) {
  312|     83|  static_assert(sizeof(fe_loose) == sizeof(fe), "fe and fe_loose mismatch");
  313|     83|  OPENSSL_memmove(h, f, sizeof(fe));
  314|     83|}
curve25519.c:fe_mul_tlt:
  235|    145|static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) {
  236|    145|  fe_mul_impl(h->v, f->v, g->v);
  237|    145|}
curve25519.c:fe_sq_tl:
  247|    114|static void fe_sq_tl(fe *h, const fe_loose *f) {
  248|    114|  assert_fe_loose(f->v);
  ------------------
  |  |   99|    114|  do {                                                                  \
  |  |  100|    684|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 570, False: 114]
  |  |  ------------------
  |  |  101|    570|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|    570|    }                                                                   \
  |  |  103|    114|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  249|    114|  fiat_25519_carry_square(h->v, f->v);
  250|    114|  assert_fe(h->v);
  ------------------
  |  |   82|    114|  do {                                                                  \
  |  |   83|    684|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 570, False: 114]
  |  |  ------------------
  |  |   84|    570|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    570|    }                                                                   \
  |  |   86|    114|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  251|    114|}
curve25519.c:ge_p3_tobytes:
  482|     83|static void ge_p3_tobytes(uint8_t s[32], const ge_p3 *h) {
  483|     83|  fe recip;
  484|     83|  fe x;
  485|     83|  fe y;
  486|       |
  487|     83|  fe_invert(&recip, &h->Z);
  488|     83|  fe_mul_ttt(&x, &h->X, &recip);
  489|     83|  fe_mul_ttt(&y, &h->Y, &recip);
  490|     83|  fe_tobytes(s, &y);
  491|     83|  s[31] ^= fe_isnegative(&x) << 7;
  492|     83|}
curve25519.c:fe_loose_invert:
  316|    114|static void fe_loose_invert(fe *out, const fe_loose *z) {
  317|    114|  fe t0;
  318|    114|  fe t1;
  319|    114|  fe t2;
  320|    114|  fe t3;
  321|    114|  int i;
  322|       |
  323|    114|  fe_sq_tl(&t0, z);
  324|    114|  fe_sq_tt(&t1, &t0);
  325|    228|  for (i = 1; i < 2; ++i) {
  ------------------
  |  Branch (325:15): [True: 114, False: 114]
  ------------------
  326|    114|    fe_sq_tt(&t1, &t1);
  327|    114|  }
  328|    114|  fe_mul_tlt(&t1, z, &t1);
  329|    114|  fe_mul_ttt(&t0, &t0, &t1);
  330|    114|  fe_sq_tt(&t2, &t0);
  331|    114|  fe_mul_ttt(&t1, &t1, &t2);
  332|    114|  fe_sq_tt(&t2, &t1);
  333|    570|  for (i = 1; i < 5; ++i) {
  ------------------
  |  Branch (333:15): [True: 456, False: 114]
  ------------------
  334|    456|    fe_sq_tt(&t2, &t2);
  335|    456|  }
  336|    114|  fe_mul_ttt(&t1, &t2, &t1);
  337|    114|  fe_sq_tt(&t2, &t1);
  338|  1.14k|  for (i = 1; i < 10; ++i) {
  ------------------
  |  Branch (338:15): [True: 1.02k, False: 114]
  ------------------
  339|  1.02k|    fe_sq_tt(&t2, &t2);
  340|  1.02k|  }
  341|    114|  fe_mul_ttt(&t2, &t2, &t1);
  342|    114|  fe_sq_tt(&t3, &t2);
  343|  2.28k|  for (i = 1; i < 20; ++i) {
  ------------------
  |  Branch (343:15): [True: 2.16k, False: 114]
  ------------------
  344|  2.16k|    fe_sq_tt(&t3, &t3);
  345|  2.16k|  }
  346|    114|  fe_mul_ttt(&t2, &t3, &t2);
  347|    114|  fe_sq_tt(&t2, &t2);
  348|  1.14k|  for (i = 1; i < 10; ++i) {
  ------------------
  |  Branch (348:15): [True: 1.02k, False: 114]
  ------------------
  349|  1.02k|    fe_sq_tt(&t2, &t2);
  350|  1.02k|  }
  351|    114|  fe_mul_ttt(&t1, &t2, &t1);
  352|    114|  fe_sq_tt(&t2, &t1);
  353|  5.70k|  for (i = 1; i < 50; ++i) {
  ------------------
  |  Branch (353:15): [True: 5.58k, False: 114]
  ------------------
  354|  5.58k|    fe_sq_tt(&t2, &t2);
  355|  5.58k|  }
  356|    114|  fe_mul_ttt(&t2, &t2, &t1);
  357|    114|  fe_sq_tt(&t3, &t2);
  358|  11.4k|  for (i = 1; i < 100; ++i) {
  ------------------
  |  Branch (358:15): [True: 11.2k, False: 114]
  ------------------
  359|  11.2k|    fe_sq_tt(&t3, &t3);
  360|  11.2k|  }
  361|    114|  fe_mul_ttt(&t2, &t3, &t2);
  362|    114|  fe_sq_tt(&t2, &t2);
  363|  5.70k|  for (i = 1; i < 50; ++i) {
  ------------------
  |  Branch (363:15): [True: 5.58k, False: 114]
  ------------------
  364|  5.58k|    fe_sq_tt(&t2, &t2);
  365|  5.58k|  }
  366|    114|  fe_mul_ttt(&t1, &t2, &t1);
  367|    114|  fe_sq_tt(&t1, &t1);
  368|    570|  for (i = 1; i < 5; ++i) {
  ------------------
  |  Branch (368:15): [True: 456, False: 114]
  ------------------
  369|    456|    fe_sq_tt(&t1, &t1);
  370|    456|  }
  371|    114|  fe_mul_ttt(out, &t1, &t0);
  372|    114|}

DES_set_key:
  296|  1.39k|void DES_set_key(const DES_cblock *key, DES_key_schedule *schedule) {
  297|  1.39k|  static const int shifts2[16] = {0, 0, 1, 1, 1, 1, 1, 1,
  298|  1.39k|                                  0, 1, 1, 1, 1, 1, 1, 0};
  299|  1.39k|  uint32_t c, d, t, s, t2;
  300|  1.39k|  const uint8_t *in;
  301|  1.39k|  int i;
  302|       |
  303|  1.39k|  in = key->bytes;
  304|       |
  305|  1.39k|  c2l(in, c);
  ------------------
  |  |   70|  1.39k|  do {                                    \
  |  |   71|  1.39k|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|  1.39k|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|  1.39k|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|  1.39k|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|  1.39k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  306|  1.39k|  c2l(in, d);
  ------------------
  |  |   70|  1.39k|  do {                                    \
  |  |   71|  1.39k|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|  1.39k|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|  1.39k|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|  1.39k|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|  1.39k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  307|       |
  308|       |  // do PC1 in 47 simple operations :-)
  309|       |  // Thanks to John Fletcher (john_fletcher@lccmail.ocf.llnl.gov)
  310|       |  // for the inspiration. :-)
  311|  1.39k|  PERM_OP(d, c, t, 4, 0x0f0f0f0f);
  ------------------
  |  |  186|  1.39k|  do {                                  \
  |  |  187|  1.39k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  188|  1.39k|    (b) ^= (t);                         \
  |  |  189|  1.39k|    (a) ^= ((t) << (n));                \
  |  |  190|  1.39k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  312|  1.39k|  HPERM_OP(c, t, -2, 0xcccc0000);
  ------------------
  |  |  293|  1.39k|  ((t) = ((((a) << (16 - (n))) ^ (a)) & (m)), \
  |  |  294|  1.39k|   (a) = (a) ^ (t) ^ ((t) >> (16 - (n))))
  ------------------
  313|  1.39k|  HPERM_OP(d, t, -2, 0xcccc0000);
  ------------------
  |  |  293|  1.39k|  ((t) = ((((a) << (16 - (n))) ^ (a)) & (m)), \
  |  |  294|  1.39k|   (a) = (a) ^ (t) ^ ((t) >> (16 - (n))))
  ------------------
  314|  1.39k|  PERM_OP(d, c, t, 1, 0x55555555);
  ------------------
  |  |  186|  1.39k|  do {                                  \
  |  |  187|  1.39k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  188|  1.39k|    (b) ^= (t);                         \
  |  |  189|  1.39k|    (a) ^= ((t) << (n));                \
  |  |  190|  1.39k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  315|  1.39k|  PERM_OP(c, d, t, 8, 0x00ff00ff);
  ------------------
  |  |  186|  1.39k|  do {                                  \
  |  |  187|  1.39k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  188|  1.39k|    (b) ^= (t);                         \
  |  |  189|  1.39k|    (a) ^= ((t) << (n));                \
  |  |  190|  1.39k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  316|  1.39k|  PERM_OP(d, c, t, 1, 0x55555555);
  ------------------
  |  |  186|  1.39k|  do {                                  \
  |  |  187|  1.39k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  188|  1.39k|    (b) ^= (t);                         \
  |  |  189|  1.39k|    (a) ^= ((t) << (n));                \
  |  |  190|  1.39k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  317|  1.39k|  d = (((d & 0x000000ff) << 16) | (d & 0x0000ff00) |
  318|  1.39k|       ((d & 0x00ff0000) >> 16) | ((c & 0xf0000000) >> 4));
  319|  1.39k|  c &= 0x0fffffff;
  320|       |
  321|  23.7k|  for (i = 0; i < ITERATIONS; i++) {
  ------------------
  |  |  230|  23.7k|#define ITERATIONS 16
  ------------------
  |  Branch (321:15): [True: 22.3k, False: 1.39k]
  ------------------
  322|  22.3k|    if (shifts2[i]) {
  ------------------
  |  Branch (322:9): [True: 16.7k, False: 5.59k]
  ------------------
  323|  16.7k|      c = ((c >> 2) | (c << 26));
  324|  16.7k|      d = ((d >> 2) | (d << 26));
  325|  16.7k|    } else {
  326|  5.59k|      c = ((c >> 1) | (c << 27));
  327|  5.59k|      d = ((d >> 1) | (d << 27));
  328|  5.59k|    }
  329|  22.3k|    c &= 0x0fffffff;
  330|  22.3k|    d &= 0x0fffffff;
  331|       |    // could be a few less shifts but I am to lazy at this
  332|       |    // point in time to investigate
  333|  22.3k|    s = des_skb[0][(c) & 0x3f] |
  334|  22.3k|        des_skb[1][((c >> 6) & 0x03) | ((c >> 7) & 0x3c)] |
  335|  22.3k|        des_skb[2][((c >> 13) & 0x0f) | ((c >> 14) & 0x30)] |
  336|  22.3k|        des_skb[3][((c >> 20) & 0x01) | ((c >> 21) & 0x06) |
  337|  22.3k|                   ((c >> 22) & 0x38)];
  338|  22.3k|    t = des_skb[4][(d) & 0x3f] |
  339|  22.3k|        des_skb[5][((d >> 7) & 0x03) | ((d >> 8) & 0x3c)] |
  340|  22.3k|        des_skb[6][(d >> 15) & 0x3f] |
  341|  22.3k|        des_skb[7][((d >> 21) & 0x0f) | ((d >> 22) & 0x30)];
  342|       |
  343|       |    // table contained 0213 4657
  344|  22.3k|    t2 = ((t << 16) | (s & 0x0000ffff)) & 0xffffffff;
  345|  22.3k|    schedule->subkeys[i][0] = CRYPTO_rotr_u32(t2, 30);
  346|       |
  347|  22.3k|    t2 = ((s >> 16) | (t & 0xffff0000));
  348|  22.3k|    schedule->subkeys[i][1] = CRYPTO_rotr_u32(t2, 26);
  349|  22.3k|  }
  350|  1.39k|}
DES_decrypt3:
  522|  70.1k|                  const DES_key_schedule *ks2, const DES_key_schedule *ks3) {
  523|  70.1k|  uint32_t l, r;
  524|       |
  525|  70.1k|  l = data[0];
  526|  70.1k|  r = data[1];
  527|  70.1k|  IP(l, r);
  ------------------
  |  |  193|  70.1k|  do {                                  \
  |  |  194|  70.1k|    uint32_t tt;                        \
  |  |  195|  70.1k|    PERM_OP(r, l, tt, 4, 0x0f0f0f0fL);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  196|  70.1k|    PERM_OP(l, r, tt, 16, 0x0000ffffL); \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  197|  70.1k|    PERM_OP(r, l, tt, 2, 0x33333333L);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  198|  70.1k|    PERM_OP(l, r, tt, 8, 0x00ff00ffL);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  199|  70.1k|    PERM_OP(r, l, tt, 1, 0x55555555L);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  200|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (200:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  528|  70.1k|  data[0] = l;
  529|  70.1k|  data[1] = r;
  530|  70.1k|  DES_encrypt2((uint32_t *)data, ks3, DES_DECRYPT);
  ------------------
  |  |   89|  70.1k|#define DES_DECRYPT 0
  ------------------
  531|  70.1k|  DES_encrypt2((uint32_t *)data, ks2, DES_ENCRYPT);
  ------------------
  |  |   88|  70.1k|#define DES_ENCRYPT 1
  ------------------
  532|  70.1k|  DES_encrypt2((uint32_t *)data, ks1, DES_DECRYPT);
  ------------------
  |  |   89|  70.1k|#define DES_DECRYPT 0
  ------------------
  533|  70.1k|  l = data[0];
  534|  70.1k|  r = data[1];
  535|  70.1k|  FP(r, l);
  ------------------
  |  |  203|  70.1k|  do {                                  \
  |  |  204|  70.1k|    uint32_t tt;                        \
  |  |  205|  70.1k|    PERM_OP(l, r, tt, 1, 0x55555555L);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  206|  70.1k|    PERM_OP(r, l, tt, 8, 0x00ff00ffL);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  207|  70.1k|    PERM_OP(l, r, tt, 2, 0x33333333L);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  208|  70.1k|    PERM_OP(r, l, tt, 16, 0x0000ffffL); \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  209|  70.1k|    PERM_OP(l, r, tt, 4, 0x0f0f0f0fL);  \
  |  |  ------------------
  |  |  |  |  186|  70.1k|  do {                                  \
  |  |  |  |  187|  70.1k|    (t) = ((((a) >> (n)) ^ (b)) & (m)); \
  |  |  |  |  188|  70.1k|    (b) ^= (t);                         \
  |  |  |  |  189|  70.1k|    (a) ^= ((t) << (n));                \
  |  |  |  |  190|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (190:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  210|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (210:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  536|  70.1k|  data[0] = l;
  537|  70.1k|  data[1] = r;
  538|  70.1k|}
DES_ede3_cbc_encrypt:
  662|    466|                          int enc) {
  663|    466|  uint32_t tin0, tin1;
  664|    466|  uint32_t tout0, tout1, xor0, xor1;
  665|    466|  uint32_t tin[2];
  666|    466|  uint8_t *iv;
  667|       |
  668|    466|  iv = ivec->bytes;
  669|       |
  670|    466|  if (enc) {
  ------------------
  |  Branch (670:7): [True: 0, False: 466]
  ------------------
  671|      0|    c2l(iv, tout0);
  ------------------
  |  |   70|      0|  do {                                    \
  |  |   71|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  672|      0|    c2l(iv, tout1);
  ------------------
  |  |   70|      0|  do {                                    \
  |  |   71|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  673|      0|    for (; len >= 8; len -= 8) {
  ------------------
  |  Branch (673:12): [True: 0, False: 0]
  ------------------
  674|      0|      c2l(in, tin0);
  ------------------
  |  |   70|      0|  do {                                    \
  |  |   71|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  675|      0|      c2l(in, tin1);
  ------------------
  |  |   70|      0|  do {                                    \
  |  |   71|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  676|      0|      tin0 ^= tout0;
  677|      0|      tin1 ^= tout1;
  678|       |
  679|      0|      tin[0] = tin0;
  680|      0|      tin[1] = tin1;
  681|      0|      DES_encrypt3((uint32_t *)tin, ks1, ks2, ks3);
  682|      0|      tout0 = tin[0];
  683|      0|      tout1 = tin[1];
  684|       |
  685|      0|      l2c(tout0, out);
  ------------------
  |  |   78|      0|  do {                                               \
  |  |   79|      0|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|      0|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|      0|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|      0|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  686|      0|      l2c(tout1, out);
  ------------------
  |  |   78|      0|  do {                                               \
  |  |   79|      0|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|      0|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|      0|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|      0|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  687|      0|    }
  688|      0|    if (len != 0) {
  ------------------
  |  Branch (688:9): [True: 0, False: 0]
  ------------------
  689|      0|      c2ln(in, tin0, tin1, len);
  ------------------
  |  |   87|      0|  do {                                         \
  |  |   88|      0|    (c) += (n);                                \
  |  |   89|      0|    (l1) = (l2) = 0;                           \
  |  |   90|      0|    switch (n) {                               \
  |  |  ------------------
  |  |  |  Branch (90:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   91|      0|      case 8:                                  \
  |  |  ------------------
  |  |  |  Branch (91:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   92|      0|        (l2) = ((uint32_t)(*(--(c)))) << 24L;  \
  |  |   93|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   94|      0|      case 7:                                  \
  |  |  ------------------
  |  |  |  Branch (94:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   95|      0|        (l2) |= ((uint32_t)(*(--(c)))) << 16L; \
  |  |   96|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |   97|      0|      case 6:                                  \
  |  |  ------------------
  |  |  |  Branch (97:7): [True: 0, False: 0]
  |  |  ------------------
  |  |   98|      0|        (l2) |= ((uint32_t)(*(--(c)))) << 8L;  \
  |  |   99|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  100|      0|      case 5:                                  \
  |  |  ------------------
  |  |  |  Branch (100:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  101|      0|        (l2) |= ((uint32_t)(*(--(c))));        \
  |  |  102|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  103|      0|      case 4:                                  \
  |  |  ------------------
  |  |  |  Branch (103:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  104|      0|        (l1) = ((uint32_t)(*(--(c)))) << 24L;  \
  |  |  105|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  106|      0|      case 3:                                  \
  |  |  ------------------
  |  |  |  Branch (106:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  107|      0|        (l1) |= ((uint32_t)(*(--(c)))) << 16L; \
  |  |  108|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  109|      0|      case 2:                                  \
  |  |  ------------------
  |  |  |  Branch (109:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  110|      0|        (l1) |= ((uint32_t)(*(--(c)))) << 8L;  \
  |  |  111|      0|        OPENSSL_FALLTHROUGH;                   \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  112|      0|      case 1:                                  \
  |  |  ------------------
  |  |  |  Branch (112:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  113|      0|        (l1) |= ((uint32_t)(*(--(c))));        \
  |  |  114|      0|    }                                          \
  |  |  115|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (115:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  690|      0|      tin0 ^= tout0;
  691|      0|      tin1 ^= tout1;
  692|       |
  693|      0|      tin[0] = tin0;
  694|      0|      tin[1] = tin1;
  695|      0|      DES_encrypt3((uint32_t *)tin, ks1, ks2, ks3);
  696|      0|      tout0 = tin[0];
  697|      0|      tout1 = tin[1];
  698|       |
  699|      0|      l2c(tout0, out);
  ------------------
  |  |   78|      0|  do {                                               \
  |  |   79|      0|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|      0|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|      0|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|      0|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  700|      0|      l2c(tout1, out);
  ------------------
  |  |   78|      0|  do {                                               \
  |  |   79|      0|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|      0|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|      0|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|      0|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  701|      0|    }
  702|      0|    iv = ivec->bytes;
  703|      0|    l2c(tout0, iv);
  ------------------
  |  |   78|      0|  do {                                               \
  |  |   79|      0|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|      0|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|      0|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|      0|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  704|      0|    l2c(tout1, iv);
  ------------------
  |  |   78|      0|  do {                                               \
  |  |   79|      0|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|      0|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|      0|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|      0|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  705|    466|  } else {
  706|    466|    uint32_t t0, t1;
  707|       |
  708|    466|    c2l(iv, xor0);
  ------------------
  |  |   70|    466|  do {                                    \
  |  |   71|    466|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|    466|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|    466|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|    466|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|    466|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  709|    466|    c2l(iv, xor1);
  ------------------
  |  |   70|    466|  do {                                    \
  |  |   71|    466|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|    466|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|    466|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|    466|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|    466|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  710|  70.6k|    for (; len >= 8; len -= 8) {
  ------------------
  |  Branch (710:12): [True: 70.1k, False: 466]
  ------------------
  711|  70.1k|      c2l(in, tin0);
  ------------------
  |  |   70|  70.1k|  do {                                    \
  |  |   71|  70.1k|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|  70.1k|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|  70.1k|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|  70.1k|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  712|  70.1k|      c2l(in, tin1);
  ------------------
  |  |   70|  70.1k|  do {                                    \
  |  |   71|  70.1k|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|  70.1k|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|  70.1k|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|  70.1k|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  713|       |
  714|  70.1k|      t0 = tin0;
  715|  70.1k|      t1 = tin1;
  716|       |
  717|  70.1k|      tin[0] = tin0;
  718|  70.1k|      tin[1] = tin1;
  719|  70.1k|      DES_decrypt3((uint32_t *)tin, ks1, ks2, ks3);
  720|  70.1k|      tout0 = tin[0];
  721|  70.1k|      tout1 = tin[1];
  722|       |
  723|  70.1k|      tout0 ^= xor0;
  724|  70.1k|      tout1 ^= xor1;
  725|  70.1k|      l2c(tout0, out);
  ------------------
  |  |   78|  70.1k|  do {                                               \
  |  |   79|  70.1k|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|  70.1k|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|  70.1k|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|  70.1k|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  726|  70.1k|      l2c(tout1, out);
  ------------------
  |  |   78|  70.1k|  do {                                               \
  |  |   79|  70.1k|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|  70.1k|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|  70.1k|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|  70.1k|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  727|  70.1k|      xor0 = t0;
  728|  70.1k|      xor1 = t1;
  729|  70.1k|    }
  730|    466|    if (len != 0) {
  ------------------
  |  Branch (730:9): [True: 0, False: 466]
  ------------------
  731|      0|      c2l(in, tin0);
  ------------------
  |  |   70|      0|  do {                                    \
  |  |   71|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  732|      0|      c2l(in, tin1);
  ------------------
  |  |   70|      0|  do {                                    \
  |  |   71|      0|    (l) = ((uint32_t)(*((c)++)));         \
  |  |   72|      0|    (l) |= ((uint32_t)(*((c)++))) << 8L;  \
  |  |   73|      0|    (l) |= ((uint32_t)(*((c)++))) << 16L; \
  |  |   74|      0|    (l) |= ((uint32_t)(*((c)++))) << 24L; \
  |  |   75|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (75:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  733|       |
  734|      0|      t0 = tin0;
  735|      0|      t1 = tin1;
  736|       |
  737|      0|      tin[0] = tin0;
  738|      0|      tin[1] = tin1;
  739|      0|      DES_decrypt3((uint32_t *)tin, ks1, ks2, ks3);
  740|      0|      tout0 = tin[0];
  741|      0|      tout1 = tin[1];
  742|       |
  743|      0|      tout0 ^= xor0;
  744|      0|      tout1 ^= xor1;
  745|      0|      l2cn(tout0, tout1, out, len);
  ------------------
  |  |  119|      0|  do {                                                    \
  |  |  120|      0|    (c) += (n);                                           \
  |  |  121|      0|    switch (n) {                                          \
  |  |  ------------------
  |  |  |  Branch (121:13): [True: 0, False: 0]
  |  |  ------------------
  |  |  122|      0|      case 8:                                             \
  |  |  ------------------
  |  |  |  Branch (122:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  123|      0|        *(--(c)) = (unsigned char)(((l2) >> 24L) & 0xff); \
  |  |  124|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  125|      0|      case 7:                                             \
  |  |  ------------------
  |  |  |  Branch (125:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  126|      0|        *(--(c)) = (unsigned char)(((l2) >> 16L) & 0xff); \
  |  |  127|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  128|      0|      case 6:                                             \
  |  |  ------------------
  |  |  |  Branch (128:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  129|      0|        *(--(c)) = (unsigned char)(((l2) >> 8L) & 0xff);  \
  |  |  130|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  131|      0|      case 5:                                             \
  |  |  ------------------
  |  |  |  Branch (131:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  132|      0|        *(--(c)) = (unsigned char)(((l2)) & 0xff);        \
  |  |  133|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  134|      0|      case 4:                                             \
  |  |  ------------------
  |  |  |  Branch (134:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  135|      0|        *(--(c)) = (unsigned char)(((l1) >> 24L) & 0xff); \
  |  |  136|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  137|      0|      case 3:                                             \
  |  |  ------------------
  |  |  |  Branch (137:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  138|      0|        *(--(c)) = (unsigned char)(((l1) >> 16L) & 0xff); \
  |  |  139|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  140|      0|      case 2:                                             \
  |  |  ------------------
  |  |  |  Branch (140:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  141|      0|        *(--(c)) = (unsigned char)(((l1) >> 8L) & 0xff);  \
  |  |  142|      0|        OPENSSL_FALLTHROUGH;                              \
  |  |  ------------------
  |  |  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  |  |  ------------------
  |  |  143|      0|      case 1:                                             \
  |  |  ------------------
  |  |  |  Branch (143:7): [True: 0, False: 0]
  |  |  ------------------
  |  |  144|      0|        *(--(c)) = (unsigned char)(((l1)) & 0xff);        \
  |  |  145|      0|    }                                                     \
  |  |  146|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (146:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  746|      0|      xor0 = t0;
  747|      0|      xor1 = t1;
  748|      0|    }
  749|       |
  750|    466|    iv = ivec->bytes;
  751|    466|    l2c(xor0, iv);
  ------------------
  |  |   78|    466|  do {                                               \
  |  |   79|    466|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|    466|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|    466|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|    466|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|    466|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  752|    466|    l2c(xor1, iv);
  ------------------
  |  |   78|    466|  do {                                               \
  |  |   79|    466|    *((c)++) = (unsigned char)(((l)) & 0xff);        \
  |  |   80|    466|    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff);  \
  |  |   81|    466|    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff); \
  |  |   82|    466|    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff); \
  |  |   83|    466|  } while (0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  753|    466|  }
  754|       |
  755|    466|  tin[0] = tin[1] = 0;
  756|    466|}
des.c:DES_encrypt2:
  445|   210k|static void DES_encrypt2(uint32_t *data, const DES_key_schedule *ks, int enc) {
  446|   210k|  uint32_t l, r, t, u;
  447|       |
  448|   210k|  r = data[0];
  449|   210k|  l = data[1];
  450|       |
  451|       |  // Things have been modified so that the initial rotate is done outside the
  452|       |  // loop.  This required the DES_SPtrans values in sp.h to be rotated 1 bit to
  453|       |  // the right. One perl script later and things have a 5% speed up on a
  454|       |  // sparc2. Thanks to Richard Outerbridge <71755.204@CompuServe.COM> for
  455|       |  // pointing this out.
  456|       |  // clear the top bits on machines with 8byte longs
  457|   210k|  r = CRYPTO_rotr_u32(r, 29);
  458|   210k|  l = CRYPTO_rotr_u32(l, 29);
  459|       |
  460|       |  // I don't know if it is worth the effort of loop unrolling the
  461|       |  // inner loop
  462|   210k|  if (enc) {
  ------------------
  |  Branch (462:7): [True: 70.1k, False: 140k]
  ------------------
  463|  70.1k|    D_ENCRYPT(ks, l, r, 0);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  464|  70.1k|    D_ENCRYPT(ks, r, l, 1);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  465|  70.1k|    D_ENCRYPT(ks, l, r, 2);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  466|  70.1k|    D_ENCRYPT(ks, r, l, 3);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  467|  70.1k|    D_ENCRYPT(ks, l, r, 4);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  468|  70.1k|    D_ENCRYPT(ks, r, l, 5);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  469|  70.1k|    D_ENCRYPT(ks, l, r, 6);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  470|  70.1k|    D_ENCRYPT(ks, r, l, 7);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  471|  70.1k|    D_ENCRYPT(ks, l, r, 8);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  472|  70.1k|    D_ENCRYPT(ks, r, l, 9);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  473|  70.1k|    D_ENCRYPT(ks, l, r, 10);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  474|  70.1k|    D_ENCRYPT(ks, r, l, 11);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  475|  70.1k|    D_ENCRYPT(ks, l, r, 12);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  476|  70.1k|    D_ENCRYPT(ks, r, l, 13);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  477|  70.1k|    D_ENCRYPT(ks, l, r, 14);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  478|  70.1k|    D_ENCRYPT(ks, r, l, 15);
  ------------------
  |  |  219|  70.1k|  do {                                                                         \
  |  |  220|  70.1k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|  70.1k|  do {                                    \
  |  |  |  |  214|  70.1k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|  70.1k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|  70.1k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|  70.1k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|  70.1k|    (LL) ^=                                                                    \
  |  |  223|  70.1k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|  70.1k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|  70.1k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|  70.1k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|  70.1k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|  70.1k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  479|   140k|  } else {
  480|   140k|    D_ENCRYPT(ks, l, r, 15);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  481|   140k|    D_ENCRYPT(ks, r, l, 14);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  482|   140k|    D_ENCRYPT(ks, l, r, 13);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  483|   140k|    D_ENCRYPT(ks, r, l, 12);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  484|   140k|    D_ENCRYPT(ks, l, r, 11);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  485|   140k|    D_ENCRYPT(ks, r, l, 10);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  486|   140k|    D_ENCRYPT(ks, l, r, 9);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  487|   140k|    D_ENCRYPT(ks, r, l, 8);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  488|   140k|    D_ENCRYPT(ks, l, r, 7);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  489|   140k|    D_ENCRYPT(ks, r, l, 6);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  490|   140k|    D_ENCRYPT(ks, l, r, 5);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  491|   140k|    D_ENCRYPT(ks, r, l, 4);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  492|   140k|    D_ENCRYPT(ks, l, r, 3);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  493|   140k|    D_ENCRYPT(ks, r, l, 2);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  494|   140k|    D_ENCRYPT(ks, l, r, 1);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  495|   140k|    D_ENCRYPT(ks, r, l, 0);
  ------------------
  |  |  219|   140k|  do {                                                                         \
  |  |  220|   140k|    LOAD_DATA(ks, R, S, u, t, E0, E1);                                         \
  |  |  ------------------
  |  |  |  |  213|   140k|  do {                                    \
  |  |  |  |  214|   140k|    (u) = (R) ^ (ks)->subkeys[S][0];      \
  |  |  |  |  215|   140k|    (t) = (R) ^ (ks)->subkeys[S][1];      \
  |  |  |  |  216|   140k|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (216:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  221|   140k|    t = CRYPTO_rotr_u32(t, 4);                                                 \
  |  |  222|   140k|    (LL) ^=                                                                    \
  |  |  223|   140k|        DES_SPtrans[0][(u >> 2L) & 0x3f] ^ DES_SPtrans[2][(u >> 10L) & 0x3f] ^ \
  |  |  224|   140k|        DES_SPtrans[4][(u >> 18L) & 0x3f] ^                                    \
  |  |  225|   140k|        DES_SPtrans[6][(u >> 26L) & 0x3f] ^ DES_SPtrans[1][(t >> 2L) & 0x3f] ^ \
  |  |  226|   140k|        DES_SPtrans[3][(t >> 10L) & 0x3f] ^                                    \
  |  |  227|   140k|        DES_SPtrans[5][(t >> 18L) & 0x3f] ^ DES_SPtrans[7][(t >> 26L) & 0x3f]; \
  |  |  228|   140k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (228:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  496|   140k|  }
  497|       |  // rotate and clear the top bits on machines with 8byte longs
  498|   210k|  data[0] = CRYPTO_rotr_u32(l, 3);
  499|   210k|  data[1] = CRYPTO_rotr_u32(r, 3);
  500|   210k|}

EVP_get_digestbynid:
  108|  3.13k|const EVP_MD* EVP_get_digestbynid(int nid) {
  109|  3.13k|  if (nid == NID_undef) {
  ------------------
  |  |   85|  3.13k|#define NID_undef 0
  ------------------
  |  Branch (109:7): [True: 0, False: 3.13k]
  ------------------
  110|       |    // Skip the |NID_undef| entries in |nid_to_digest_mapping|.
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|  6.02k|  for (unsigned i = 0; i < OPENSSL_ARRAY_SIZE(nid_to_digest_mapping); i++) {
  ------------------
  |  |  221|  6.02k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (114:24): [True: 6.02k, False: 0]
  ------------------
  115|  6.02k|    if (nid_to_digest_mapping[i].nid == nid) {
  ------------------
  |  Branch (115:9): [True: 3.13k, False: 2.88k]
  ------------------
  116|  3.13k|      return nid_to_digest_mapping[i].md_func();
  117|  3.13k|    }
  118|  6.02k|  }
  119|       |
  120|      0|  return NULL;
  121|  3.13k|}
EVP_parse_digest_algorithm:
  168|  3.22k|const EVP_MD *EVP_parse_digest_algorithm(CBS *cbs) {
  169|  3.22k|  CBS algorithm, oid;
  170|  3.22k|  if (!CBS_get_asn1(cbs, &algorithm, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  3.22k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  3.22k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  3.22k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (170:7): [True: 1, False: 3.22k]
  ------------------
  171|  3.22k|      !CBS_get_asn1(&algorithm, &oid, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  3.22k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (171:7): [True: 1, False: 3.22k]
  ------------------
  172|      2|    OPENSSL_PUT_ERROR(DIGEST, DIGEST_R_DECODE_ERROR);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      2|    return NULL;
  174|      2|  }
  175|       |
  176|  3.22k|  const EVP_MD *ret = cbs_to_md(&oid);
  177|  3.22k|  if (ret == NULL) {
  ------------------
  |  Branch (177:7): [True: 87, False: 3.13k]
  ------------------
  178|     87|    OPENSSL_PUT_ERROR(DIGEST, DIGEST_R_UNKNOWN_HASH);
  ------------------
  |  |  441|     87|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  179|     87|    return NULL;
  180|     87|  }
  181|       |
  182|       |  // The parameters, if present, must be NULL. Historically, whether the NULL
  183|       |  // was included or omitted was not well-specified. When parsing an
  184|       |  // AlgorithmIdentifier, we allow both. (Note this code is not used when
  185|       |  // verifying RSASSA-PKCS1-v1_5 signatures.)
  186|  3.13k|  if (CBS_len(&algorithm) > 0) {
  ------------------
  |  Branch (186:7): [True: 369, False: 2.76k]
  ------------------
  187|    369|    CBS param;
  188|    369|    if (!CBS_get_asn1(&algorithm, &param, CBS_ASN1_NULL) ||
  ------------------
  |  |  218|    369|#define CBS_ASN1_NULL 0x5u
  ------------------
  |  Branch (188:9): [True: 5, False: 364]
  ------------------
  189|    369|        CBS_len(&param) != 0 ||
  ------------------
  |  Branch (189:9): [True: 3, False: 361]
  ------------------
  190|    369|        CBS_len(&algorithm) != 0) {
  ------------------
  |  Branch (190:9): [True: 73, False: 288]
  ------------------
  191|     81|      OPENSSL_PUT_ERROR(DIGEST, DIGEST_R_DECODE_ERROR);
  ------------------
  |  |  441|     81|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  192|     81|      return NULL;
  193|     81|    }
  194|    369|  }
  195|       |
  196|  3.05k|  return ret;
  197|  3.13k|}
digest_extra.c:cbs_to_md:
  144|  3.22k|static const EVP_MD *cbs_to_md(const CBS *cbs) {
  145|  6.59k|  for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(kMDOIDs); i++) {
  ------------------
  |  |  221|  6.59k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (145:22): [True: 6.50k, False: 87]
  ------------------
  146|  6.50k|    if (CBS_len(cbs) == kMDOIDs[i].oid_len &&
  ------------------
  |  Branch (146:9): [True: 4.14k, False: 2.36k]
  ------------------
  147|  6.50k|        OPENSSL_memcmp(CBS_data(cbs), kMDOIDs[i].oid, kMDOIDs[i].oid_len) ==
  ------------------
  |  Branch (147:9): [True: 3.13k, False: 1.00k]
  ------------------
  148|  4.14k|            0) {
  149|  3.13k|      return EVP_get_digestbynid(kMDOIDs[i].nid);
  150|  3.13k|    }
  151|  6.50k|  }
  152|       |
  153|     87|  return NULL;
  154|  3.22k|}

DSA_new:
   90|    164|DSA *DSA_new(void) {
   91|    164|  DSA *dsa = OPENSSL_malloc(sizeof(DSA));
   92|    164|  if (dsa == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 164]
  ------------------
   93|      0|    return NULL;
   94|      0|  }
   95|       |
   96|    164|  OPENSSL_memset(dsa, 0, sizeof(DSA));
   97|       |
   98|    164|  dsa->references = 1;
   99|       |
  100|    164|  CRYPTO_MUTEX_init(&dsa->method_mont_lock);
  101|    164|  CRYPTO_new_ex_data(&dsa->ex_data);
  102|       |
  103|    164|  return dsa;
  104|    164|}
DSA_free:
  106|    492|void DSA_free(DSA *dsa) {
  107|    492|  if (dsa == NULL) {
  ------------------
  |  Branch (107:7): [True: 328, False: 164]
  ------------------
  108|    328|    return;
  109|    328|  }
  110|       |
  111|    164|  if (!CRYPTO_refcount_dec_and_test_zero(&dsa->references)) {
  ------------------
  |  Branch (111:7): [True: 0, False: 164]
  ------------------
  112|      0|    return;
  113|      0|  }
  114|       |
  115|    164|  CRYPTO_free_ex_data(&g_ex_data_class, dsa, &dsa->ex_data);
  116|       |
  117|    164|  BN_clear_free(dsa->p);
  118|    164|  BN_clear_free(dsa->q);
  119|    164|  BN_clear_free(dsa->g);
  120|    164|  BN_clear_free(dsa->pub_key);
  121|    164|  BN_clear_free(dsa->priv_key);
  122|    164|  BN_MONT_CTX_free(dsa->method_mont_p);
  123|    164|  BN_MONT_CTX_free(dsa->method_mont_q);
  124|    164|  CRYPTO_MUTEX_cleanup(&dsa->method_mont_lock);
  125|    164|  OPENSSL_free(dsa);
  126|    164|}

dsa_check_key:
   73|    138|int dsa_check_key(const DSA *dsa) {
   74|    138|  if (!dsa->p || !dsa->q || !dsa->g) {
  ------------------
  |  Branch (74:7): [True: 0, False: 138]
  |  Branch (74:18): [True: 0, False: 138]
  |  Branch (74:29): [True: 0, False: 138]
  ------------------
   75|      0|    OPENSSL_PUT_ERROR(DSA, DSA_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|       |
   79|       |  // Fully checking for invalid DSA groups is expensive, so security and
   80|       |  // correctness of the signature scheme depend on how |dsa| was computed. I.e.
   81|       |  // we leave "assurance of domain parameter validity" from FIPS 186-4 to the
   82|       |  // caller. However, we check bounds on all values to avoid DoS vectors even
   83|       |  // when domain parameters are invalid. In particular, signing will infinite
   84|       |  // loop if |g| is zero.
   85|    138|  if (BN_is_negative(dsa->p) || BN_is_negative(dsa->q) || BN_is_zero(dsa->p) ||
  ------------------
  |  Branch (85:7): [True: 0, False: 138]
  |  Branch (85:33): [True: 0, False: 138]
  |  Branch (85:59): [True: 1, False: 137]
  ------------------
   86|    138|      BN_is_zero(dsa->q) || !BN_is_odd(dsa->p) || !BN_is_odd(dsa->q) ||
  ------------------
  |  Branch (86:7): [True: 3, False: 134]
  |  Branch (86:29): [True: 18, False: 116]
  |  Branch (86:51): [True: 15, False: 101]
  ------------------
   87|       |      // |q| must be a prime divisor of |p - 1|, which implies |q < p|.
   88|    138|      BN_cmp(dsa->q, dsa->p) >= 0 ||
  ------------------
  |  Branch (88:7): [True: 8, False: 93]
  ------------------
   89|       |      // |g| is in the multiplicative group of |p|.
   90|    138|      BN_is_negative(dsa->g) || BN_is_zero(dsa->g) ||
  ------------------
  |  Branch (90:7): [True: 0, False: 93]
  |  Branch (90:33): [True: 1, False: 92]
  ------------------
   91|    138|      BN_cmp(dsa->g, dsa->p) >= 0) {
  ------------------
  |  Branch (91:7): [True: 3, False: 89]
  ------------------
   92|     49|    OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|     49|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   93|     49|    return 0;
   94|     49|  }
   95|       |
   96|       |  // FIPS 186-4 allows only three different sizes for q.
   97|     89|  unsigned q_bits = BN_num_bits(dsa->q);
   98|     89|  if (q_bits != 160 && q_bits != 224 && q_bits != 256) {
  ------------------
  |  Branch (98:7): [True: 89, False: 0]
  |  Branch (98:24): [True: 89, False: 0]
  |  Branch (98:41): [True: 89, False: 0]
  ------------------
   99|     89|    OPENSSL_PUT_ERROR(DSA, DSA_R_BAD_Q_VALUE);
  ------------------
  |  |  441|     89|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  100|     89|    return 0;
  101|     89|  }
  102|       |
  103|       |  // Bound |dsa->p| to avoid a DoS vector. Note this limit is much larger than
  104|       |  // the one in FIPS 186-4, which only allows L = 1024, 2048, and 3072.
  105|      0|  if (BN_num_bits(dsa->p) > OPENSSL_DSA_MAX_MODULUS_BITS) {
  ------------------
  |  |   68|      0|#define OPENSSL_DSA_MAX_MODULUS_BITS 10000
  ------------------
  |  Branch (105:7): [True: 0, False: 0]
  ------------------
  106|      0|    OPENSSL_PUT_ERROR(DSA, DSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|      0|  if (dsa->pub_key != NULL) {
  ------------------
  |  Branch (110:7): [True: 0, False: 0]
  ------------------
  111|       |    // The public key is also in the multiplicative group of |p|.
  112|      0|    if (BN_is_negative(dsa->pub_key) || BN_is_zero(dsa->pub_key) ||
  ------------------
  |  Branch (112:9): [True: 0, False: 0]
  |  Branch (112:41): [True: 0, False: 0]
  ------------------
  113|      0|        BN_cmp(dsa->pub_key, dsa->p) >= 0) {
  ------------------
  |  Branch (113:9): [True: 0, False: 0]
  ------------------
  114|      0|      OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  115|      0|      return 0;
  116|      0|    }
  117|      0|  }
  118|       |
  119|      0|  if (dsa->priv_key != NULL) {
  ------------------
  |  Branch (119:7): [True: 0, False: 0]
  ------------------
  120|       |    // The private key is a non-zero element of the scalar field, determined by
  121|       |    // |q|.
  122|      0|    if (BN_is_negative(dsa->priv_key) || BN_is_zero(dsa->priv_key) ||
  ------------------
  |  Branch (122:9): [True: 0, False: 0]
  |  Branch (122:42): [True: 0, False: 0]
  ------------------
  123|      0|        BN_cmp(dsa->priv_key, dsa->q) >= 0) {
  ------------------
  |  Branch (123:9): [True: 0, False: 0]
  ------------------
  124|      0|      OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  125|      0|      return 0;
  126|      0|    }
  127|      0|  }
  128|       |
  129|      0|  return 1;
  130|      0|}
DSA_parse_parameters:
  218|    164|DSA *DSA_parse_parameters(CBS *cbs) {
  219|    164|  DSA *ret = DSA_new();
  220|    164|  if (ret == NULL) {
  ------------------
  |  Branch (220:7): [True: 0, False: 164]
  ------------------
  221|      0|    return NULL;
  222|      0|  }
  223|    164|  CBS child;
  224|    164|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    164|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    164|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    164|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (224:7): [True: 1, False: 163]
  ------------------
  225|    164|      !parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (225:7): [True: 6, False: 157]
  ------------------
  226|    164|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (226:7): [True: 12, False: 145]
  ------------------
  227|    164|      !parse_integer(&child, &ret->g) ||
  ------------------
  |  Branch (227:7): [True: 5, False: 140]
  ------------------
  228|    164|      CBS_len(&child) != 0) {
  ------------------
  |  Branch (228:7): [True: 2, False: 138]
  ------------------
  229|     26|    OPENSSL_PUT_ERROR(DSA, DSA_R_DECODE_ERROR);
  ------------------
  |  |  441|     26|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  230|     26|    goto err;
  231|     26|  }
  232|    138|  if (!dsa_check_key(ret)) {
  ------------------
  |  Branch (232:7): [True: 138, False: 0]
  ------------------
  233|    138|    goto err;
  234|    138|  }
  235|      0|  return ret;
  236|       |
  237|    164|err:
  238|    164|  DSA_free(ret);
  239|    164|  return NULL;
  240|    138|}
dsa_asn1.c:parse_integer:
  132|    465|static int parse_integer(CBS *cbs, BIGNUM **out) {
  133|    465|  assert(*out == NULL);
  134|    465|  *out = BN_new();
  135|    465|  if (*out == NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 465]
  ------------------
  136|      0|    return 0;
  137|      0|  }
  138|    465|  return BN_parse_asn1_unsigned(cbs, *out);
  139|    465|}

EC_KEY_parse_private_key:
   75|    381|EC_KEY *EC_KEY_parse_private_key(CBS *cbs, const EC_GROUP *group) {
   76|    381|  CBS ec_private_key, private_key;
   77|    381|  uint64_t version;
   78|    381|  if (!CBS_get_asn1(cbs, &ec_private_key, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    381|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    381|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    381|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (78:7): [True: 1, False: 380]
  ------------------
   79|    381|      !CBS_get_asn1_uint64(&ec_private_key, &version) ||
  ------------------
  |  Branch (79:7): [True: 1, False: 379]
  ------------------
   80|    381|      version != 1 ||
  ------------------
  |  Branch (80:7): [True: 91, False: 288]
  ------------------
   81|    381|      !CBS_get_asn1(&ec_private_key, &private_key, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|    288|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (81:7): [True: 1, False: 287]
  ------------------
   82|     94|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|     94|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   83|     94|    return NULL;
   84|     94|  }
   85|       |
   86|       |  // Parse the optional parameters field.
   87|    287|  EC_GROUP *inner_group = NULL;
   88|    287|  EC_KEY *ret = NULL;
   89|    287|  BIGNUM *priv_key = NULL;
   90|    287|  if (CBS_peek_asn1_tag(&ec_private_key, kParametersTag)) {
  ------------------
  |  Branch (90:7): [True: 24, False: 263]
  ------------------
   91|       |    // Per SEC 1, as an alternative to omitting it, one is allowed to specify
   92|       |    // this field and put in a NULL to mean inheriting this value. This was
   93|       |    // omitted in a previous version of this logic without problems, so leave it
   94|       |    // unimplemented.
   95|     24|    CBS child;
   96|     24|    if (!CBS_get_asn1(&ec_private_key, &child, kParametersTag)) {
  ------------------
  |  Branch (96:9): [True: 1, False: 23]
  ------------------
   97|      1|      OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   98|      1|      goto err;
   99|      1|    }
  100|     23|    inner_group = EC_KEY_parse_parameters(&child);
  101|     23|    if (inner_group == NULL) {
  ------------------
  |  Branch (101:9): [True: 15, False: 8]
  ------------------
  102|     15|      goto err;
  103|     15|    }
  104|      8|    if (group == NULL) {
  ------------------
  |  Branch (104:9): [True: 0, False: 8]
  ------------------
  105|      0|      group = inner_group;
  106|      8|    } else if (EC_GROUP_cmp(group, inner_group, NULL) != 0) {
  ------------------
  |  Branch (106:16): [True: 5, False: 3]
  ------------------
  107|       |      // If a group was supplied externally, it must match.
  108|      5|      OPENSSL_PUT_ERROR(EC, EC_R_GROUP_MISMATCH);
  ------------------
  |  |  441|      5|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  109|      5|      goto err;
  110|      5|    }
  111|      3|    if (CBS_len(&child) != 0) {
  ------------------
  |  Branch (111:9): [True: 1, False: 2]
  ------------------
  112|      1|      OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  113|      1|      goto err;
  114|      1|    }
  115|      3|  }
  116|       |
  117|    265|  if (group == NULL) {
  ------------------
  |  Branch (117:7): [True: 0, False: 265]
  ------------------
  118|      0|    OPENSSL_PUT_ERROR(EC, EC_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  119|      0|    goto err;
  120|      0|  }
  121|       |
  122|    265|  ret = EC_KEY_new();
  123|    265|  if (ret == NULL || !EC_KEY_set_group(ret, group)) {
  ------------------
  |  Branch (123:7): [True: 0, False: 265]
  |  Branch (123:22): [True: 0, False: 265]
  ------------------
  124|      0|    goto err;
  125|      0|  }
  126|       |
  127|       |  // Although RFC 5915 specifies the length of the key, OpenSSL historically
  128|       |  // got this wrong, so accept any length. See upstream's
  129|       |  // 30cd4ff294252c4b6a4b69cbef6a5b4117705d22.
  130|    265|  priv_key = BN_bin2bn(CBS_data(&private_key), CBS_len(&private_key), NULL);
  131|    265|  ret->pub_key = EC_POINT_new(group);
  132|    265|  if (priv_key == NULL || ret->pub_key == NULL ||
  ------------------
  |  Branch (132:7): [True: 0, False: 265]
  |  Branch (132:27): [True: 0, False: 265]
  ------------------
  133|    265|      !EC_KEY_set_private_key(ret, priv_key)) {
  ------------------
  |  Branch (133:7): [True: 18, False: 247]
  ------------------
  134|     18|    goto err;
  135|     18|  }
  136|       |
  137|    247|  if (CBS_peek_asn1_tag(&ec_private_key, kPublicKeyTag)) {
  ------------------
  |  Branch (137:7): [True: 26, False: 221]
  ------------------
  138|     26|    CBS child, public_key;
  139|     26|    uint8_t padding;
  140|     26|    if (!CBS_get_asn1(&ec_private_key, &child, kPublicKeyTag) ||
  ------------------
  |  Branch (140:9): [True: 1, False: 25]
  ------------------
  141|     26|        !CBS_get_asn1(&child, &public_key, CBS_ASN1_BITSTRING) ||
  ------------------
  |  |  216|     25|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (141:9): [True: 1, False: 24]
  ------------------
  142|       |        // As in a SubjectPublicKeyInfo, the byte-encoded public key is then
  143|       |        // encoded as a BIT STRING with bits ordered as in the DER encoding.
  144|     26|        !CBS_get_u8(&public_key, &padding) ||
  ------------------
  |  Branch (144:9): [True: 1, False: 23]
  ------------------
  145|     26|        padding != 0 ||
  ------------------
  |  Branch (145:9): [True: 7, False: 16]
  ------------------
  146|       |        // Explicitly check |public_key| is non-empty to save the conversion
  147|       |        // form later.
  148|     26|        CBS_len(&public_key) == 0 ||
  ------------------
  |  Branch (148:9): [True: 1, False: 15]
  ------------------
  149|     26|        !EC_POINT_oct2point(group, ret->pub_key, CBS_data(&public_key),
  ------------------
  |  Branch (149:9): [True: 15, False: 0]
  ------------------
  150|     15|                            CBS_len(&public_key), NULL) ||
  151|     26|        CBS_len(&child) != 0) {
  ------------------
  |  Branch (151:9): [True: 0, False: 0]
  ------------------
  152|     26|      OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|     26|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  153|     26|      goto err;
  154|     26|    }
  155|       |
  156|       |    // Save the point conversion form.
  157|       |    // TODO(davidben): Consider removing this.
  158|      0|    ret->conv_form =
  159|      0|        (point_conversion_form_t)(CBS_data(&public_key)[0] & ~0x01);
  160|    221|  } else {
  161|       |    // Compute the public key instead.
  162|    221|    if (!ec_point_mul_scalar_base(group, &ret->pub_key->raw,
  ------------------
  |  Branch (162:9): [True: 0, False: 221]
  ------------------
  163|    221|                                  &ret->priv_key->scalar)) {
  164|      0|      goto err;
  165|      0|    }
  166|       |    // Remember the original private-key-only encoding.
  167|       |    // TODO(davidben): Consider removing this.
  168|    221|    ret->enc_flag |= EC_PKEY_NO_PUBKEY;
  ------------------
  |  |  146|    221|#define EC_PKEY_NO_PUBKEY 0x002
  ------------------
  169|    221|  }
  170|       |
  171|    221|  if (CBS_len(&ec_private_key) != 0) {
  ------------------
  |  Branch (171:7): [True: 110, False: 111]
  ------------------
  172|    110|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|    110|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|    110|    goto err;
  174|    110|  }
  175|       |
  176|       |  // Ensure the resulting key is valid.
  177|    111|  if (!EC_KEY_check_key(ret)) {
  ------------------
  |  Branch (177:7): [True: 0, False: 111]
  ------------------
  178|      0|    goto err;
  179|      0|  }
  180|       |
  181|    111|  BN_free(priv_key);
  182|    111|  EC_GROUP_free(inner_group);
  183|    111|  return ret;
  184|       |
  185|    176|err:
  186|    176|  EC_KEY_free(ret);
  187|    176|  BN_free(priv_key);
  188|    176|  EC_GROUP_free(inner_group);
  189|    176|  return NULL;
  190|    111|}
EC_KEY_parse_curve_name:
  324|    397|EC_GROUP *EC_KEY_parse_curve_name(CBS *cbs) {
  325|    397|  CBS named_curve;
  326|    397|  if (!CBS_get_asn1(cbs, &named_curve, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|    397|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (326:7): [True: 2, False: 395]
  ------------------
  327|      2|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|      2|    return NULL;
  329|      2|  }
  330|       |
  331|       |  // Look for a matching curve.
  332|    395|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  333|    815|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|    815|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (333:22): [True: 810, False: 5]
  ------------------
  334|    810|    const struct built_in_curve *curve = &curves->curves[i];
  335|    810|    if (CBS_len(&named_curve) == curve->oid_len &&
  ------------------
  |  Branch (335:9): [True: 705, False: 105]
  ------------------
  336|    810|        OPENSSL_memcmp(CBS_data(&named_curve), curve->oid, curve->oid_len) ==
  ------------------
  |  Branch (336:9): [True: 390, False: 315]
  ------------------
  337|    705|            0) {
  338|    390|      return EC_GROUP_new_by_curve_name(curve->nid);
  339|    390|    }
  340|    810|  }
  341|       |
  342|      5|  OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|      5|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  343|      5|  return NULL;
  344|    395|}
EC_KEY_parse_parameters:
  368|    489|EC_GROUP *EC_KEY_parse_parameters(CBS *cbs) {
  369|    489|  if (!CBS_peek_asn1_tag(cbs, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|    489|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    489|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    489|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (369:7): [True: 397, False: 92]
  ------------------
  370|    397|    return EC_KEY_parse_curve_name(cbs);
  371|    397|  }
  372|       |
  373|       |  // OpenSSL sometimes produces ECPrivateKeys with explicitly-encoded versions
  374|       |  // of named curves.
  375|       |  //
  376|       |  // TODO(davidben): Remove support for this.
  377|     92|  CBS prime, a, b, base_x, base_y, order;
  378|     92|  if (!parse_explicit_prime_curve(cbs, &prime, &a, &b, &base_x, &base_y,
  ------------------
  |  Branch (378:7): [True: 92, False: 0]
  ------------------
  379|     92|                                  &order)) {
  380|     92|    return NULL;
  381|     92|  }
  382|       |
  383|       |  // Look for a matching prime curve.
  384|      0|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  385|      0|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|      0|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (385:22): [True: 0, False: 0]
  ------------------
  386|      0|    const struct built_in_curve *curve = &curves->curves[i];
  387|      0|    const unsigned param_len = curve->param_len;
  388|       |    // |curve->params| is ordered p, a, b, x, y, order, each component
  389|       |    // zero-padded up to the field length. Although SEC 1 states that the
  390|       |    // Field-Element-to-Octet-String conversion also pads, OpenSSL mis-encodes
  391|       |    // |a| and |b|, so this comparison must allow omitting leading zeros. (This
  392|       |    // is relevant for P-521 whose |b| has a leading 0.)
  393|      0|    if (integers_equal(&prime, curve->params, param_len) &&
  ------------------
  |  Branch (393:9): [True: 0, False: 0]
  ------------------
  394|      0|        integers_equal(&a, curve->params + param_len, param_len) &&
  ------------------
  |  Branch (394:9): [True: 0, False: 0]
  ------------------
  395|      0|        integers_equal(&b, curve->params + param_len * 2, param_len) &&
  ------------------
  |  Branch (395:9): [True: 0, False: 0]
  ------------------
  396|      0|        integers_equal(&base_x, curve->params + param_len * 3, param_len) &&
  ------------------
  |  Branch (396:9): [True: 0, False: 0]
  ------------------
  397|      0|        integers_equal(&base_y, curve->params + param_len * 4, param_len) &&
  ------------------
  |  Branch (397:9): [True: 0, False: 0]
  ------------------
  398|      0|        integers_equal(&order, curve->params + param_len * 5, param_len)) {
  ------------------
  |  Branch (398:9): [True: 0, False: 0]
  ------------------
  399|      0|      return EC_GROUP_new_by_curve_name(curve->nid);
  400|      0|    }
  401|      0|  }
  402|       |
  403|      0|  OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  404|      0|  return NULL;
  405|      0|}
ec_asn1.c:parse_explicit_prime_curve:
  249|     92|                                      CBS *out_base_y, CBS *out_order) {
  250|       |  // See RFC 3279, section 2.3.5. Note that RFC 3279 calls this structure an
  251|       |  // ECParameters while RFC 5480 calls it a SpecifiedECDomain.
  252|     92|  CBS params, field_id, field_type, curve, base, cofactor;
  253|     92|  int has_cofactor;
  254|     92|  uint64_t version;
  255|     92|  if (!CBS_get_asn1(in, &params, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|     92|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|     92|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|     92|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (255:7): [True: 1, False: 91]
  ------------------
  256|     92|      !CBS_get_asn1_uint64(&params, &version) ||
  ------------------
  |  Branch (256:7): [True: 1, False: 90]
  ------------------
  257|     92|      version != 1 ||
  ------------------
  |  Branch (257:7): [True: 87, False: 3]
  ------------------
  258|     92|      !CBS_get_asn1(&params, &field_id, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|      3|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|      3|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|      3|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (258:7): [True: 1, False: 2]
  ------------------
  259|     92|      !CBS_get_asn1(&field_id, &field_type, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|      2|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (259:7): [True: 1, False: 1]
  ------------------
  260|     92|      CBS_len(&field_type) != sizeof(kPrimeField) ||
  ------------------
  |  Branch (260:7): [True: 1, False: 0]
  ------------------
  261|     92|      OPENSSL_memcmp(CBS_data(&field_type), kPrimeField, sizeof(kPrimeField)) !=
  ------------------
  |  Branch (261:7): [True: 0, False: 0]
  ------------------
  262|      0|          0 ||
  263|     92|      !CBS_get_asn1(&field_id, out_prime, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|      0|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (263:7): [True: 0, False: 0]
  ------------------
  264|     92|      !CBS_is_unsigned_asn1_integer(out_prime) ||
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|     92|      CBS_len(&field_id) != 0 ||
  ------------------
  |  Branch (265:7): [True: 0, False: 0]
  ------------------
  266|     92|      !CBS_get_asn1(&params, &curve, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|      0|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|      0|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|      0|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (266:7): [True: 0, False: 0]
  ------------------
  267|     92|      !CBS_get_asn1(&curve, out_a, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|      0|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (267:7): [True: 0, False: 0]
  ------------------
  268|     92|      !CBS_get_asn1(&curve, out_b, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|      0|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (268:7): [True: 0, False: 0]
  ------------------
  269|       |      // |curve| has an optional BIT STRING seed which we ignore.
  270|     92|      !CBS_get_optional_asn1(&curve, NULL, NULL, CBS_ASN1_BITSTRING) ||
  ------------------
  |  |  216|      0|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (270:7): [True: 0, False: 0]
  ------------------
  271|     92|      CBS_len(&curve) != 0 ||
  ------------------
  |  Branch (271:7): [True: 0, False: 0]
  ------------------
  272|     92|      !CBS_get_asn1(&params, &base, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|      0|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (272:7): [True: 0, False: 0]
  ------------------
  273|     92|      !CBS_get_asn1(&params, out_order, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|      0|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (273:7): [True: 0, False: 0]
  ------------------
  274|     92|      !CBS_is_unsigned_asn1_integer(out_order) ||
  ------------------
  |  Branch (274:7): [True: 0, False: 0]
  ------------------
  275|     92|      !CBS_get_optional_asn1(&params, &cofactor, &has_cofactor,
  ------------------
  |  Branch (275:7): [True: 0, False: 0]
  ------------------
  276|      0|                             CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|      0|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  277|     92|      CBS_len(&params) != 0) {
  ------------------
  |  Branch (277:7): [True: 0, False: 0]
  ------------------
  278|     92|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|     92|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  279|     92|    return 0;
  280|     92|  }
  281|       |
  282|      0|  if (has_cofactor) {
  ------------------
  |  Branch (282:7): [True: 0, False: 0]
  ------------------
  283|       |    // We only support prime-order curves so the cofactor must be one.
  284|      0|    if (CBS_len(&cofactor) != 1 ||
  ------------------
  |  Branch (284:9): [True: 0, False: 0]
  ------------------
  285|      0|        CBS_data(&cofactor)[0] != 1) {
  ------------------
  |  Branch (285:9): [True: 0, False: 0]
  ------------------
  286|      0|      OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  287|      0|      return 0;
  288|      0|    }
  289|      0|  }
  290|       |
  291|       |  // Require that the base point use uncompressed form.
  292|      0|  uint8_t form;
  293|      0|  if (!CBS_get_u8(&base, &form) || form != POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (293:7): [True: 0, False: 0]
  |  Branch (293:36): [True: 0, False: 0]
  ------------------
  294|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_FORM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  295|      0|    return 0;
  296|      0|  }
  297|       |
  298|      0|  if (CBS_len(&base) % 2 != 0) {
  ------------------
  |  Branch (298:7): [True: 0, False: 0]
  ------------------
  299|      0|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  300|      0|    return 0;
  301|      0|  }
  302|      0|  size_t field_len = CBS_len(&base) / 2;
  303|      0|  CBS_init(out_base_x, CBS_data(&base), field_len);
  304|      0|  CBS_init(out_base_y, CBS_data(&base) + field_len, field_len);
  305|       |
  306|      0|  return 1;
  307|      0|}

METHOD_ref:
   86|    469|void METHOD_ref(void *method_in) {
   87|    469|  assert(((struct openssl_method_common_st*) method_in)->is_static);
   88|    469|}
METHOD_unref:
   90|    469|void METHOD_unref(void *method_in) {
   91|    469|  struct openssl_method_common_st *method = method_in;
   92|       |
   93|    469|  if (method == NULL) {
  ------------------
  |  Branch (93:7): [True: 0, False: 469]
  ------------------
   94|      0|    return;
   95|      0|  }
   96|    469|  assert(method->is_static);
   97|    469|}

ERR_put_error:
  657|  8.35k|                   unsigned line) {
  658|  8.35k|  ERR_STATE *const state = err_get_state();
  659|  8.35k|  struct err_error_st *error;
  660|       |
  661|  8.35k|  if (state == NULL) {
  ------------------
  |  Branch (661:7): [True: 0, False: 8.35k]
  ------------------
  662|      0|    return;
  663|      0|  }
  664|       |
  665|  8.35k|  if (library == ERR_LIB_SYS && reason == 0) {
  ------------------
  |  Branch (665:7): [True: 0, False: 8.35k]
  |  Branch (665:33): [True: 0, False: 0]
  ------------------
  666|       |#if defined(OPENSSL_WINDOWS)
  667|       |    reason = GetLastError();
  668|       |#else
  669|      0|    reason = errno;
  670|      0|#endif
  671|      0|  }
  672|       |
  673|  8.35k|  state->top = (state->top + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|  8.35k|#define ERR_NUM_ERRORS 16
  ------------------
  674|  8.35k|  if (state->top == state->bottom) {
  ------------------
  |  Branch (674:7): [True: 8.34k, False: 15]
  ------------------
  675|  8.34k|    state->bottom = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|  8.34k|#define ERR_NUM_ERRORS 16
  ------------------
  676|  8.34k|  }
  677|       |
  678|  8.35k|  error = &state->errors[state->top];
  679|  8.35k|  err_clear(error);
  680|  8.35k|  error->file = file;
  681|  8.35k|  error->line = line;
  682|  8.35k|  error->packed = ERR_PACK(library, reason);
  ------------------
  |  |  480|  8.35k|  (((((uint32_t)(lib)) & 0xff) << 24) | ((((uint32_t)(reason)) & 0xfff)))
  ------------------
  683|  8.35k|}
ERR_add_error_data:
  728|  1.05k|void ERR_add_error_data(unsigned count, ...) {
  729|  1.05k|  va_list args;
  730|  1.05k|  va_start(args, count);
  731|  1.05k|  err_add_error_vdata(count, args);
  732|  1.05k|  va_end(args);
  733|  1.05k|}
err.c:err_get_state:
  213|  9.40k|static ERR_STATE *err_get_state(void) {
  214|  9.40k|  ERR_STATE *state = CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_ERR);
  215|  9.40k|  if (state == NULL) {
  ------------------
  |  Branch (215:7): [True: 1, False: 9.40k]
  ------------------
  216|      1|    state = malloc(sizeof(ERR_STATE));
  217|      1|    if (state == NULL) {
  ------------------
  |  Branch (217:9): [True: 0, False: 1]
  ------------------
  218|      0|      return NULL;
  219|      0|    }
  220|      1|    OPENSSL_memset(state, 0, sizeof(ERR_STATE));
  221|      1|    if (!CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_ERR, state,
  ------------------
  |  Branch (221:9): [True: 0, False: 1]
  ------------------
  222|      1|                                 err_state_free)) {
  223|      0|      return NULL;
  224|      0|    }
  225|      1|  }
  226|       |
  227|  9.40k|  return state;
  228|  9.40k|}
err.c:err_clear:
  168|  8.35k|static void err_clear(struct err_error_st *error) {
  169|  8.35k|  free(error->data);
  170|  8.35k|  OPENSSL_memset(error, 0, sizeof(struct err_error_st));
  171|  8.35k|}
err.c:err_add_error_vdata:
  688|  1.05k|static void err_add_error_vdata(unsigned num, va_list args) {
  689|  1.05k|  size_t total_size = 0;
  690|  1.05k|  const char *substr;
  691|  1.05k|  char *buf;
  692|       |
  693|  1.05k|  va_list args_copy;
  694|  1.05k|  va_copy(args_copy, args);
  695|  4.86k|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (695:22): [True: 3.81k, False: 1.05k]
  ------------------
  696|  3.81k|    substr = va_arg(args_copy, const char *);
  697|  3.81k|    if (substr == NULL) {
  ------------------
  |  Branch (697:9): [True: 0, False: 3.81k]
  ------------------
  698|      0|      continue;
  699|      0|    }
  700|  3.81k|    size_t substr_len = strlen(substr);
  701|  3.81k|    if (SIZE_MAX - total_size < substr_len) {
  ------------------
  |  Branch (701:9): [True: 0, False: 3.81k]
  ------------------
  702|      0|      return; // Would overflow.
  703|      0|    }
  704|  3.81k|    total_size += substr_len;
  705|  3.81k|  }
  706|  1.05k|  va_end(args_copy);
  707|  1.05k|  if (total_size == SIZE_MAX) {
  ------------------
  |  Branch (707:7): [True: 0, False: 1.05k]
  ------------------
  708|      0|      return; // Would overflow.
  709|      0|  }
  710|  1.05k|  total_size += 1; // NUL terminator.
  711|  1.05k|  if ((buf = malloc(total_size)) == NULL) {
  ------------------
  |  Branch (711:7): [True: 0, False: 1.05k]
  ------------------
  712|      0|    return;
  713|      0|  }
  714|  1.05k|  buf[0] = '\0';
  715|  4.86k|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (715:22): [True: 3.81k, False: 1.05k]
  ------------------
  716|  3.81k|    substr = va_arg(args, const char *);
  717|  3.81k|    if (substr == NULL) {
  ------------------
  |  Branch (717:9): [True: 0, False: 3.81k]
  ------------------
  718|      0|      continue;
  719|      0|    }
  720|  3.81k|    if (OPENSSL_strlcat(buf, substr, total_size) >= total_size) {
  ------------------
  |  Branch (720:9): [True: 0, False: 3.81k]
  ------------------
  721|      0|      assert(0); // should not be possible.
  722|      0|    }
  723|  3.81k|  }
  724|  1.05k|  va_end(args);
  725|  1.05k|  err_set_error_data(buf);
  726|  1.05k|}
err.c:err_set_error_data:
  641|  1.05k|static void err_set_error_data(char *data) {
  642|  1.05k|  ERR_STATE *const state = err_get_state();
  643|  1.05k|  struct err_error_st *error;
  644|       |
  645|  1.05k|  if (state == NULL || state->top == state->bottom) {
  ------------------
  |  Branch (645:7): [True: 0, False: 1.05k]
  |  Branch (645:24): [True: 0, False: 1.05k]
  ------------------
  646|      0|    free(data);
  647|      0|    return;
  648|      0|  }
  649|       |
  650|  1.05k|  error = &state->errors[state->top];
  651|       |
  652|  1.05k|  free(error->data);
  653|  1.05k|  error->data = data;
  654|  1.05k|}

EVP_PKEY_new:
   83|  1.23k|EVP_PKEY *EVP_PKEY_new(void) {
   84|  1.23k|  EVP_PKEY *ret;
   85|       |
   86|  1.23k|  ret = OPENSSL_malloc(sizeof(EVP_PKEY));
   87|  1.23k|  if (ret == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 1.23k]
  ------------------
   88|      0|    return NULL;
   89|      0|  }
   90|       |
   91|  1.23k|  OPENSSL_memset(ret, 0, sizeof(EVP_PKEY));
   92|  1.23k|  ret->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  1.23k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  1.23k|#define NID_undef 0
  |  |  ------------------
  ------------------
   93|  1.23k|  ret->references = 1;
   94|       |
   95|  1.23k|  return ret;
   96|  1.23k|}
EVP_PKEY_free:
  106|  10.5k|void EVP_PKEY_free(EVP_PKEY *pkey) {
  107|  10.5k|  if (pkey == NULL) {
  ------------------
  |  Branch (107:7): [True: 9.27k, False: 1.23k]
  ------------------
  108|  9.27k|    return;
  109|  9.27k|  }
  110|       |
  111|  1.23k|  if (!CRYPTO_refcount_dec_and_test_zero(&pkey->references)) {
  ------------------
  |  Branch (111:7): [True: 0, False: 1.23k]
  ------------------
  112|      0|    return;
  113|      0|  }
  114|       |
  115|  1.23k|  free_it(pkey);
  116|  1.23k|  OPENSSL_free(pkey);
  117|  1.23k|}
EVP_PKEY_assign_RSA:
  248|      5|int EVP_PKEY_assign_RSA(EVP_PKEY *pkey, RSA *key) {
  249|      5|  return EVP_PKEY_assign(pkey, EVP_PKEY_RSA, key);
  ------------------
  |  |  175|      5|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|      5|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  250|      5|}
EVP_PKEY_assign_EC_KEY:
  304|     10|int EVP_PKEY_assign_EC_KEY(EVP_PKEY *pkey, EC_KEY *key) {
  305|     10|  return EVP_PKEY_assign(pkey, EVP_PKEY_EC, key);
  ------------------
  |  |  178|     10|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|     10|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  306|     10|}
EVP_PKEY_assign:
  327|     15|int EVP_PKEY_assign(EVP_PKEY *pkey, int type, void *key) {
  328|     15|  if (!EVP_PKEY_set_type(pkey, type)) {
  ------------------
  |  Branch (328:7): [True: 0, False: 15]
  ------------------
  329|      0|    return 0;
  330|      0|  }
  331|     15|  pkey->pkey = key;
  332|     15|  return key != NULL;
  333|     15|}
EVP_PKEY_set_type:
  335|  1.25k|int EVP_PKEY_set_type(EVP_PKEY *pkey, int type) {
  336|  1.25k|  const EVP_PKEY_ASN1_METHOD *ameth;
  337|       |
  338|  1.25k|  if (pkey && pkey->pkey) {
  ------------------
  |  Branch (338:7): [True: 1.25k, False: 0]
  |  Branch (338:15): [True: 0, False: 1.25k]
  ------------------
  339|      0|    free_it(pkey);
  340|      0|  }
  341|       |
  342|  1.25k|  ameth = evp_pkey_asn1_find(type);
  343|  1.25k|  if (ameth == NULL) {
  ------------------
  |  Branch (343:7): [True: 0, False: 1.25k]
  ------------------
  344|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|    ERR_add_error_dataf("algorithm %d", type);
  346|      0|    return 0;
  347|      0|  }
  348|       |
  349|  1.25k|  if (pkey) {
  ------------------
  |  Branch (349:7): [True: 1.25k, False: 0]
  ------------------
  350|  1.25k|    pkey->ameth = ameth;
  351|  1.25k|    pkey->type = pkey->ameth->pkey_id;
  352|  1.25k|  }
  353|       |
  354|  1.25k|  return 1;
  355|  1.25k|}
evp.c:free_it:
   98|  1.23k|static void free_it(EVP_PKEY *pkey) {
   99|  1.23k|  if (pkey->ameth && pkey->ameth->pkey_free) {
  ------------------
  |  Branch (99:7): [True: 1.23k, False: 0]
  |  Branch (99:22): [True: 1.23k, False: 0]
  ------------------
  100|  1.23k|    pkey->ameth->pkey_free(pkey);
  101|  1.23k|    pkey->pkey = NULL;
  102|  1.23k|    pkey->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  1.23k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  1.23k|#define NID_undef 0
  |  |  ------------------
  ------------------
  103|  1.23k|  }
  104|  1.23k|}
evp.c:evp_pkey_asn1_find:
  215|  1.25k|static const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int nid) {
  216|  1.25k|  switch (nid) {
  217|    477|    case EVP_PKEY_RSA:
  ------------------
  |  |  175|    477|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|    477|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  |  Branch (217:5): [True: 477, False: 775]
  ------------------
  218|    477|      return &rsa_asn1_meth;
  219|    476|    case EVP_PKEY_EC:
  ------------------
  |  |  178|    476|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|    476|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (219:5): [True: 476, False: 776]
  ------------------
  220|    476|      return &ec_asn1_meth;
  221|    164|    case EVP_PKEY_DSA:
  ------------------
  |  |  177|    164|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|    164|#define NID_dsa 116
  |  |  ------------------
  ------------------
  |  Branch (221:5): [True: 164, False: 1.08k]
  ------------------
  222|    164|      return &dsa_asn1_meth;
  223|     94|    case EVP_PKEY_ED25519:
  ------------------
  |  |  179|     94|#define EVP_PKEY_ED25519 NID_ED25519
  |  |  ------------------
  |  |  |  | 4199|     94|#define NID_ED25519 949
  |  |  ------------------
  ------------------
  |  Branch (223:5): [True: 94, False: 1.15k]
  ------------------
  224|     94|      return &ed25519_asn1_meth;
  225|     41|    case EVP_PKEY_X25519:
  ------------------
  |  |  180|     41|#define EVP_PKEY_X25519 NID_X25519
  |  |  ------------------
  |  |  |  | 4195|     41|#define NID_X25519 948
  |  |  ------------------
  ------------------
  |  Branch (225:5): [True: 41, False: 1.21k]
  ------------------
  226|     41|      return &x25519_asn1_meth;
  227|      0|    default:
  ------------------
  |  Branch (227:5): [True: 0, False: 1.25k]
  ------------------
  228|      0|      return NULL;
  229|  1.25k|  }
  230|  1.25k|}

EVP_parse_private_key:
  154|  1.36k|EVP_PKEY *EVP_parse_private_key(CBS *cbs) {
  155|       |  // Parse the PrivateKeyInfo.
  156|  1.36k|  CBS pkcs8, algorithm, key;
  157|  1.36k|  uint64_t version;
  158|  1.36k|  int type;
  159|  1.36k|  if (!CBS_get_asn1(cbs, &pkcs8, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  1.36k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  1.36k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  1.36k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (159:7): [True: 9, False: 1.35k]
  ------------------
  160|  1.36k|      !CBS_get_asn1_uint64(&pkcs8, &version) ||
  ------------------
  |  Branch (160:7): [True: 2, False: 1.35k]
  ------------------
  161|  1.36k|      version != 0 ||
  ------------------
  |  Branch (161:7): [True: 84, False: 1.26k]
  ------------------
  162|  1.36k|      !CBS_get_asn1(&pkcs8, &algorithm, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  1.26k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  1.26k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  1.26k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (162:7): [True: 1, False: 1.26k]
  ------------------
  163|  1.36k|      !CBS_get_asn1(&pkcs8, &key, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|  1.26k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (163:7): [True: 1, False: 1.26k]
  ------------------
  164|     97|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     97|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  165|     97|    return NULL;
  166|     97|  }
  167|  1.26k|  if (!parse_key_type(&algorithm, &type)) {
  ------------------
  |  Branch (167:7): [True: 30, False: 1.23k]
  ------------------
  168|     30|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|     30|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|     30|    return NULL;
  170|     30|  }
  171|       |
  172|       |  // A PrivateKeyInfo ends with a SET of Attributes which we ignore.
  173|       |
  174|       |  // Set up an |EVP_PKEY| of the appropriate type.
  175|  1.23k|  EVP_PKEY *ret = EVP_PKEY_new();
  176|  1.23k|  if (ret == NULL ||
  ------------------
  |  Branch (176:7): [True: 0, False: 1.23k]
  ------------------
  177|  1.23k|      !EVP_PKEY_set_type(ret, type)) {
  ------------------
  |  Branch (177:7): [True: 0, False: 1.23k]
  ------------------
  178|      0|    goto err;
  179|      0|  }
  180|       |
  181|       |  // Call into the type-specific PrivateKeyInfo decoding function.
  182|  1.23k|  if (ret->ameth->priv_decode == NULL) {
  ------------------
  |  Branch (182:7): [True: 0, False: 1.23k]
  ------------------
  183|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  184|      0|    goto err;
  185|      0|  }
  186|  1.23k|  if (!ret->ameth->priv_decode(ret, &algorithm, &key)) {
  ------------------
  |  Branch (186:7): [True: 1.10k, False: 129]
  ------------------
  187|  1.10k|    goto err;
  188|  1.10k|  }
  189|       |
  190|    129|  return ret;
  191|       |
  192|  1.10k|err:
  193|  1.10k|  EVP_PKEY_free(ret);
  194|  1.10k|  return NULL;
  195|  1.23k|}
evp_asn1.c:parse_key_type:
   80|  1.26k|static int parse_key_type(CBS *cbs, int *out_type) {
   81|  1.26k|  CBS oid;
   82|  1.26k|  if (!CBS_get_asn1(cbs, &oid, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  1.26k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (82:7): [True: 1, False: 1.26k]
  ------------------
   83|      1|    return 0;
   84|      1|  }
   85|       |
   86|  2.65k|  for (unsigned i = 0; i < OPENSSL_ARRAY_SIZE(kASN1Methods); i++) {
  ------------------
  |  |  221|  2.65k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (86:24): [True: 2.62k, False: 29]
  ------------------
   87|  2.62k|    const EVP_PKEY_ASN1_METHOD *method = kASN1Methods[i];
   88|  2.62k|    if (CBS_len(&oid) == method->oid_len &&
  ------------------
  |  Branch (88:9): [True: 1.48k, False: 1.13k]
  ------------------
   89|  2.62k|        OPENSSL_memcmp(CBS_data(&oid), method->oid, method->oid_len) == 0) {
  ------------------
  |  Branch (89:9): [True: 1.23k, False: 252]
  ------------------
   90|  1.23k|      *out_type = method->pkey_id;
   91|  1.23k|      return 1;
   92|  1.23k|    }
   93|  2.62k|  }
   94|       |
   95|     29|  return 0;
   96|  1.26k|}

p_dsa_asn1.c:dsa_priv_decode:
  128|    164|static int dsa_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  129|       |  // See PKCS#11, v2.40, section 2.5.
  130|       |
  131|       |  // Decode parameters.
  132|    164|  BN_CTX *ctx = NULL;
  133|    164|  DSA *dsa = DSA_parse_parameters(params);
  134|    164|  if (dsa == NULL || CBS_len(params) != 0) {
  ------------------
  |  Branch (134:7): [True: 164, False: 0]
  |  Branch (134:22): [True: 0, False: 0]
  ------------------
  135|    164|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    164|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  136|    164|    goto err;
  137|    164|  }
  138|       |
  139|      0|  dsa->priv_key = BN_new();
  140|      0|  if (dsa->priv_key == NULL) {
  ------------------
  |  Branch (140:7): [True: 0, False: 0]
  ------------------
  141|      0|    goto err;
  142|      0|  }
  143|      0|  if (!BN_parse_asn1_unsigned(key, dsa->priv_key) ||
  ------------------
  |  Branch (143:7): [True: 0, False: 0]
  ------------------
  144|      0|      CBS_len(key) != 0) {
  ------------------
  |  Branch (144:7): [True: 0, False: 0]
  ------------------
  145|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  146|      0|    goto err;
  147|      0|  }
  148|       |
  149|       |  // To avoid DoS attacks when importing private keys, check bounds on |dsa|.
  150|       |  // This bounds |dsa->priv_key| against |dsa->q| and bounds |dsa->q|'s bit
  151|       |  // width.
  152|      0|  if (!dsa_check_key(dsa)) {
  ------------------
  |  Branch (152:7): [True: 0, False: 0]
  ------------------
  153|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  154|      0|    goto err;
  155|      0|  }
  156|       |
  157|       |  // Calculate the public key.
  158|      0|  ctx = BN_CTX_new();
  159|      0|  dsa->pub_key = BN_new();
  160|      0|  if (ctx == NULL || dsa->pub_key == NULL ||
  ------------------
  |  Branch (160:7): [True: 0, False: 0]
  |  Branch (160:22): [True: 0, False: 0]
  ------------------
  161|      0|      !BN_mod_exp_mont_consttime(dsa->pub_key, dsa->g, dsa->priv_key, dsa->p,
  ------------------
  |  Branch (161:7): [True: 0, False: 0]
  ------------------
  162|      0|                                 ctx, NULL)) {
  163|      0|    goto err;
  164|      0|  }
  165|       |
  166|      0|  BN_CTX_free(ctx);
  167|      0|  EVP_PKEY_assign_DSA(out, dsa);
  168|      0|  return 1;
  169|       |
  170|    164|err:
  171|    164|  BN_CTX_free(ctx);
  172|    164|  DSA_free(dsa);
  173|    164|  return 0;
  174|      0|}
p_dsa_asn1.c:int_dsa_free:
  259|    164|static void int_dsa_free(EVP_PKEY *pkey) {
  260|    164|  DSA_free(pkey->pkey);
  261|    164|  pkey->pkey = NULL;
  262|    164|}

p_ec_asn1.c:eckey_priv_decode:
  136|    466|static int eckey_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  137|       |  // See RFC 5915.
  138|    466|  EC_GROUP *group = EC_KEY_parse_parameters(params);
  139|    466|  if (group == NULL || CBS_len(params) != 0) {
  ------------------
  |  Branch (139:7): [True: 84, False: 382]
  |  Branch (139:24): [True: 1, False: 381]
  ------------------
  140|     85|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     85|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|     85|    EC_GROUP_free(group);
  142|     85|    return 0;
  143|     85|  }
  144|       |
  145|    381|  EC_KEY *ec_key = EC_KEY_parse_private_key(key, group);
  146|    381|  EC_GROUP_free(group);
  147|    381|  if (ec_key == NULL || CBS_len(key) != 0) {
  ------------------
  |  Branch (147:7): [True: 270, False: 111]
  |  Branch (147:25): [True: 101, False: 10]
  ------------------
  148|    371|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    371|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  149|    371|    EC_KEY_free(ec_key);
  150|    371|    return 0;
  151|    371|  }
  152|       |
  153|     10|  EVP_PKEY_assign_EC_KEY(out, ec_key);
  154|     10|  return 1;
  155|    381|}
p_ec_asn1.c:int_ec_free:
  264|    466|static void int_ec_free(EVP_PKEY *pkey) {
  265|    466|  EC_KEY_free(pkey->pkey);
  266|    466|  pkey->pkey = NULL;
  267|    466|}

p_ed25519_asn1.c:ed25519_priv_decode:
  154|     94|static int ed25519_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  155|       |  // See RFC 8410, section 7.
  156|       |
  157|       |  // Parameters must be empty. The key is a 32-byte value wrapped in an extra
  158|       |  // OCTET STRING layer.
  159|     94|  CBS inner;
  160|     94|  if (CBS_len(params) != 0 ||
  ------------------
  |  Branch (160:7): [True: 2, False: 92]
  ------------------
  161|     94|      !CBS_get_asn1(key, &inner, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|     92|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (161:7): [True: 1, False: 91]
  ------------------
  162|     94|      CBS_len(key) != 0) {
  ------------------
  |  Branch (162:7): [True: 4, False: 87]
  ------------------
  163|      7|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  164|      7|    return 0;
  165|      7|  }
  166|       |
  167|     87|  return ed25519_set_priv_raw(out, CBS_data(&inner), CBS_len(&inner));
  168|     94|}
p_ed25519_asn1.c:ed25519_set_priv_raw:
   31|     87|static int ed25519_set_priv_raw(EVP_PKEY *pkey, const uint8_t *in, size_t len) {
   32|     87|  if (len != 32) {
  ------------------
  |  Branch (32:7): [True: 4, False: 83]
  ------------------
   33|      4|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|      4|    return 0;
   35|      4|  }
   36|       |
   37|     83|  ED25519_KEY *key = OPENSSL_malloc(sizeof(ED25519_KEY));
   38|     83|  if (key == NULL) {
  ------------------
  |  Branch (38:7): [True: 0, False: 83]
  ------------------
   39|      0|    return 0;
   40|      0|  }
   41|       |
   42|       |  // The RFC 8032 encoding stores only the 32-byte seed, so we must recover the
   43|       |  // full representation which we use from it.
   44|     83|  uint8_t pubkey_unused[32];
   45|     83|  ED25519_keypair_from_seed(pubkey_unused, key->key, in);
   46|     83|  key->has_private = 1;
   47|       |
   48|     83|  ed25519_free(pkey);
   49|     83|  pkey->pkey = key;
   50|     83|  return 1;
   51|     83|}
p_ed25519_asn1.c:ed25519_free:
   26|    177|static void ed25519_free(EVP_PKEY *pkey) {
   27|    177|  OPENSSL_free(pkey->pkey);
   28|    177|  pkey->pkey = NULL;
   29|    177|}

p_rsa_asn1.c:rsa_priv_decode:
  138|    472|static int rsa_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  139|       |  // Per RFC 3447, A.1, the parameters have type NULL.
  140|    472|  CBS null;
  141|    472|  if (!CBS_get_asn1(params, &null, CBS_ASN1_NULL) ||
  ------------------
  |  |  218|    472|#define CBS_ASN1_NULL 0x5u
  ------------------
  |  Branch (141:7): [True: 1, False: 471]
  ------------------
  142|    472|      CBS_len(&null) != 0 ||
  ------------------
  |  Branch (142:7): [True: 1, False: 470]
  ------------------
  143|    472|      CBS_len(params) != 0) {
  ------------------
  |  Branch (143:7): [True: 1, False: 469]
  ------------------
  144|      3|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  145|      3|    return 0;
  146|      3|  }
  147|       |
  148|    469|  RSA *rsa = RSA_parse_private_key(key);
  149|    469|  if (rsa == NULL || CBS_len(key) != 0) {
  ------------------
  |  Branch (149:7): [True: 464, False: 5]
  |  Branch (149:22): [True: 0, False: 5]
  ------------------
  150|    464|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    464|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|    464|    RSA_free(rsa);
  152|    464|    return 0;
  153|    464|  }
  154|       |
  155|      5|  EVP_PKEY_assign_RSA(out, rsa);
  156|      5|  return 1;
  157|    469|}
p_rsa_asn1.c:int_rsa_free:
  174|    472|static void int_rsa_free(EVP_PKEY *pkey) {
  175|    472|  RSA_free(pkey->pkey);
  176|    472|  pkey->pkey = NULL;
  177|    472|}

p_x25519_asn1.c:x25519_priv_decode:
  166|     41|static int x25519_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  167|       |  // See RFC 8410, section 7.
  168|       |
  169|       |  // Parameters must be empty. The key is a 32-byte value wrapped in an extra
  170|       |  // OCTET STRING layer.
  171|     41|  CBS inner;
  172|     41|  if (CBS_len(params) != 0 ||
  ------------------
  |  Branch (172:7): [True: 1, False: 40]
  ------------------
  173|     41|      !CBS_get_asn1(key, &inner, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|     40|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (173:7): [True: 1, False: 39]
  ------------------
  174|     41|      CBS_len(key) != 0) {
  ------------------
  |  Branch (174:7): [True: 5, False: 34]
  ------------------
  175|      7|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  176|      7|    return 0;
  177|      7|  }
  178|       |
  179|     34|  return x25519_set_priv_raw(out, CBS_data(&inner), CBS_len(&inner));
  180|     41|}
p_x25519_asn1.c:x25519_set_priv_raw:
   31|     34|static int x25519_set_priv_raw(EVP_PKEY *pkey, const uint8_t *in, size_t len) {
   32|     34|  if (len != 32) {
  ------------------
  |  Branch (32:7): [True: 3, False: 31]
  ------------------
   33|      3|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|      3|    return 0;
   35|      3|  }
   36|       |
   37|     31|  X25519_KEY *key = OPENSSL_malloc(sizeof(X25519_KEY));
   38|     31|  if (key == NULL) {
  ------------------
  |  Branch (38:7): [True: 0, False: 31]
  ------------------
   39|      0|    return 0;
   40|      0|  }
   41|       |
   42|     31|  OPENSSL_memcpy(key->priv, in, 32);
   43|     31|  X25519_public_from_private(key->pub, key->priv);
   44|     31|  key->has_private = 1;
   45|       |
   46|     31|  x25519_free(pkey);
   47|     31|  pkey->pkey = key;
   48|     31|  return 1;
   49|     31|}
p_x25519_asn1.c:x25519_free:
   26|     72|static void x25519_free(EVP_PKEY *pkey) {
   27|     72|  OPENSSL_free(pkey->pkey);
   28|     72|  pkey->pkey = NULL;
   29|     72|}

PKCS5_PBKDF2_HMAC:
   67|     64|                      const EVP_MD *digest, size_t key_len, uint8_t *out_key) {
   68|       |  // See RFC 8018, section 5.2.
   69|     64|  int ret = 0;
   70|     64|  size_t md_len = EVP_MD_size(digest);
   71|     64|  uint32_t i = 1;
   72|     64|  HMAC_CTX hctx;
   73|     64|  HMAC_CTX_init(&hctx);
   74|       |
   75|     64|  if (!HMAC_Init_ex(&hctx, password, password_len, digest, NULL)) {
  ------------------
  |  Branch (75:7): [True: 0, False: 64]
  ------------------
   76|      0|    goto err;
   77|      0|  }
   78|       |
   79|    140|  while (key_len > 0) {
  ------------------
  |  Branch (79:10): [True: 76, False: 64]
  ------------------
   80|     76|    size_t todo = md_len;
   81|     76|    if (todo > key_len) {
  ------------------
  |  Branch (81:9): [True: 64, False: 12]
  ------------------
   82|     64|      todo = key_len;
   83|     64|    }
   84|       |
   85|     76|    uint8_t i_buf[4];
   86|     76|    i_buf[0] = (uint8_t)((i >> 24) & 0xff);
   87|     76|    i_buf[1] = (uint8_t)((i >> 16) & 0xff);
   88|     76|    i_buf[2] = (uint8_t)((i >> 8) & 0xff);
   89|     76|    i_buf[3] = (uint8_t)(i & 0xff);
   90|       |
   91|       |    // Compute U_1.
   92|     76|    uint8_t digest_tmp[EVP_MAX_MD_SIZE];
   93|     76|    if (!HMAC_Init_ex(&hctx, NULL, 0, NULL, NULL) ||
  ------------------
  |  Branch (93:9): [True: 0, False: 76]
  ------------------
   94|     76|        !HMAC_Update(&hctx, salt, salt_len) ||
  ------------------
  |  Branch (94:9): [True: 0, False: 76]
  ------------------
   95|     76|        !HMAC_Update(&hctx, i_buf, 4) ||
  ------------------
  |  Branch (95:9): [True: 0, False: 76]
  ------------------
   96|     76|        !HMAC_Final(&hctx, digest_tmp, NULL)) {
  ------------------
  |  Branch (96:9): [True: 0, False: 76]
  ------------------
   97|      0|      goto err;
   98|      0|    }
   99|       |
  100|     76|    OPENSSL_memcpy(out_key, digest_tmp, todo);
  101|  96.0k|    for (unsigned j = 1; j < iterations; j++) {
  ------------------
  |  Branch (101:26): [True: 95.9k, False: 76]
  ------------------
  102|       |      // Compute the remaining U_* values and XOR.
  103|  95.9k|      if (!HMAC_Init_ex(&hctx, NULL, 0, NULL, NULL) ||
  ------------------
  |  Branch (103:11): [True: 0, False: 95.9k]
  ------------------
  104|  95.9k|          !HMAC_Update(&hctx, digest_tmp, md_len) ||
  ------------------
  |  Branch (104:11): [True: 0, False: 95.9k]
  ------------------
  105|  95.9k|          !HMAC_Final(&hctx, digest_tmp, NULL)) {
  ------------------
  |  Branch (105:11): [True: 0, False: 95.9k]
  ------------------
  106|      0|        goto err;
  107|      0|      }
  108|  1.57M|      for (size_t k = 0; k < todo; k++) {
  ------------------
  |  Branch (108:26): [True: 1.47M, False: 95.9k]
  ------------------
  109|  1.47M|        out_key[k] ^= digest_tmp[k];
  110|  1.47M|      }
  111|  95.9k|    }
  112|       |
  113|     76|    key_len -= todo;
  114|     76|    out_key += todo;
  115|     76|    i++;
  116|     76|  }
  117|       |
  118|       |  // RFC 8018 describes iterations (c) as being a "positive integer", so a
  119|       |  // value of 0 is an error.
  120|       |  //
  121|       |  // Unfortunately not all consumers of PKCS5_PBKDF2_HMAC() check their return
  122|       |  // value, expecting it to succeed and unconditionally using |out_key|.  As a
  123|       |  // precaution for such callsites in external code, the old behavior of
  124|       |  // iterations < 1 being treated as iterations == 1 is preserved, but
  125|       |  // additionally an error result is returned.
  126|       |  //
  127|       |  // TODO(eroman): Figure out how to remove this compatibility hack, or change
  128|       |  // the default to something more sensible like 2048.
  129|     64|  if (iterations == 0) {
  ------------------
  |  Branch (129:7): [True: 0, False: 64]
  ------------------
  130|      0|    goto err;
  131|      0|  }
  132|       |
  133|     64|  ret = 1;
  134|       |
  135|     64|err:
  136|     64|  HMAC_CTX_cleanup(&hctx);
  137|     64|  return ret;
  138|     64|}

CRYPTO_new_ex_data:
  206|  1.50k|void CRYPTO_new_ex_data(CRYPTO_EX_DATA *ad) {
  207|  1.50k|  ad->sk = NULL;
  208|  1.50k|}
CRYPTO_free_ex_data:
  211|  1.50k|                         CRYPTO_EX_DATA *ad) {
  212|  1.50k|  if (ad->sk == NULL) {
  ------------------
  |  Branch (212:7): [True: 1.50k, False: 0]
  ------------------
  213|       |    // Nothing to do.
  214|  1.50k|    return;
  215|  1.50k|  }
  216|       |
  217|      0|  uint32_t num_funcs = CRYPTO_atomic_load_u32(&ex_data_class->num_funcs);
  218|       |  // |CRYPTO_get_ex_new_index| will not allocate indices beyond |INT_MAX|.
  219|      0|  assert(num_funcs <= (size_t)(INT_MAX - ex_data_class->num_reserved));
  220|       |
  221|       |  // Defer dereferencing |ex_data_class->funcs| and |funcs->next|. It must come
  222|       |  // after the |num_funcs| comparison to be correctly synchronized.
  223|      0|  CRYPTO_EX_DATA_FUNCS *const *funcs = &ex_data_class->funcs;
  224|      0|  for (uint32_t i = 0; i < num_funcs; i++) {
  ------------------
  |  Branch (224:24): [True: 0, False: 0]
  ------------------
  225|      0|    if ((*funcs)->free_func != NULL) {
  ------------------
  |  Branch (225:9): [True: 0, False: 0]
  ------------------
  226|      0|      int index = (int)i + ex_data_class->num_reserved;
  227|      0|      void *ptr = CRYPTO_get_ex_data(ad, index);
  228|      0|      (*funcs)->free_func(obj, ptr, ad, index, (*funcs)->argl, (*funcs)->argp);
  229|      0|    }
  230|      0|    funcs = &(*funcs)->next;
  231|      0|  }
  232|       |
  233|      0|  sk_void_free(ad->sk);
  234|      0|  ad->sk = NULL;
  235|      0|}

bcm.c:hwaes_capable:
   33|     43|OPENSSL_INLINE int hwaes_capable(void) { return CRYPTO_is_AESNI_capable(); }

BN_add_word:
  138|      4|int BN_add_word(BIGNUM *a, BN_ULONG w) {
  139|      4|  BN_ULONG l;
  140|      4|  int i;
  141|       |
  142|       |  // degenerate case: w is zero
  143|      4|  if (!w) {
  ------------------
  |  Branch (143:7): [True: 0, False: 4]
  ------------------
  144|      0|    return 1;
  145|      0|  }
  146|       |
  147|       |  // degenerate case: a is zero
  148|      4|  if (BN_is_zero(a)) {
  ------------------
  |  Branch (148:7): [True: 0, False: 4]
  ------------------
  149|      0|    return BN_set_word(a, w);
  150|      0|  }
  151|       |
  152|       |  // handle 'a' when negative
  153|      4|  if (a->neg) {
  ------------------
  |  Branch (153:7): [True: 0, False: 4]
  ------------------
  154|      0|    a->neg = 0;
  155|      0|    i = BN_sub_word(a, w);
  156|      0|    if (!BN_is_zero(a)) {
  ------------------
  |  Branch (156:9): [True: 0, False: 0]
  ------------------
  157|      0|      a->neg = !(a->neg);
  158|      0|    }
  159|      0|    return i;
  160|      0|  }
  161|       |
  162|      9|  for (i = 0; w != 0 && i < a->width; i++) {
  ------------------
  |  Branch (162:15): [True: 5, False: 4]
  |  Branch (162:25): [True: 5, False: 0]
  ------------------
  163|      5|    a->d[i] = l = a->d[i] + w;
  164|      5|    w = (w > l) ? 1 : 0;
  ------------------
  |  Branch (164:9): [True: 1, False: 4]
  ------------------
  165|      5|  }
  166|       |
  167|      4|  if (w && i == a->width) {
  ------------------
  |  Branch (167:7): [True: 0, False: 4]
  |  Branch (167:12): [True: 0, False: 0]
  ------------------
  168|      0|    if (!bn_wexpand(a, a->width + 1)) {
  ------------------
  |  Branch (168:9): [True: 0, False: 0]
  ------------------
  169|      0|      return 0;
  170|      0|    }
  171|      0|    a->width++;
  172|      0|    a->d[i] = w;
  173|      0|  }
  174|       |
  175|      4|  return 1;
  176|      4|}
BN_sub:
  178|      4|int BN_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  179|      4|  int add = 0, neg = 0;
  180|      4|  const BIGNUM *tmp;
  181|       |
  182|       |  //  a -  b	a-b
  183|       |  //  a - -b	a+b
  184|       |  // -a -  b	-(a+b)
  185|       |  // -a - -b	b-a
  186|      4|  if (a->neg) {
  ------------------
  |  Branch (186:7): [True: 0, False: 4]
  ------------------
  187|      0|    if (b->neg) {
  ------------------
  |  Branch (187:9): [True: 0, False: 0]
  ------------------
  188|      0|      tmp = a;
  189|      0|      a = b;
  190|      0|      b = tmp;
  191|      0|    } else {
  192|      0|      add = 1;
  193|      0|      neg = 1;
  194|      0|    }
  195|      4|  } else {
  196|      4|    if (b->neg) {
  ------------------
  |  Branch (196:9): [True: 0, False: 4]
  ------------------
  197|      0|      add = 1;
  198|      0|      neg = 0;
  199|      0|    }
  200|      4|  }
  201|       |
  202|      4|  if (add) {
  ------------------
  |  Branch (202:7): [True: 0, False: 4]
  ------------------
  203|      0|    if (!BN_uadd(r, a, b)) {
  ------------------
  |  Branch (203:9): [True: 0, False: 0]
  ------------------
  204|      0|      return 0;
  205|      0|    }
  206|       |
  207|      0|    r->neg = neg;
  208|      0|    return 1;
  209|      0|  }
  210|       |
  211|      4|  if (BN_ucmp(a, b) < 0) {
  ------------------
  |  Branch (211:7): [True: 0, False: 4]
  ------------------
  212|      0|    if (!BN_usub(r, b, a)) {
  ------------------
  |  Branch (212:9): [True: 0, False: 0]
  ------------------
  213|      0|      return 0;
  214|      0|    }
  215|      0|    r->neg = 1;
  216|      4|  } else {
  217|      4|    if (!BN_usub(r, a, b)) {
  ------------------
  |  Branch (217:9): [True: 0, False: 4]
  ------------------
  218|      0|      return 0;
  219|      0|    }
  220|      4|    r->neg = 0;
  221|      4|  }
  222|       |
  223|      4|  return 1;
  224|      4|}
bn_usub_consttime:
  226|    328|int bn_usub_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  227|       |  // |b| may have more words than |a| given non-minimal inputs, but all words
  228|       |  // beyond |a->width| must then be zero.
  229|    328|  int b_width = b->width;
  230|    328|  if (b_width > a->width) {
  ------------------
  |  Branch (230:7): [True: 0, False: 328]
  ------------------
  231|      0|    if (!bn_fits_in_words(b, a->width)) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  233|      0|      return 0;
  234|      0|    }
  235|      0|    b_width = a->width;
  236|      0|  }
  237|       |
  238|    328|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (238:7): [True: 0, False: 328]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|    328|  BN_ULONG borrow = bn_sub_words(r->d, a->d, b->d, b_width);
  243|  5.51k|  for (int i = b_width; i < a->width; i++) {
  ------------------
  |  Branch (243:25): [True: 5.18k, False: 328]
  ------------------
  244|       |    // |r| and |a| may alias, so use a temporary.
  245|  5.18k|    BN_ULONG tmp = a->d[i];
  246|  5.18k|    r->d[i] = a->d[i] - borrow;
  247|  5.18k|    borrow = tmp < r->d[i];
  248|  5.18k|  }
  249|       |
  250|    328|  if (borrow) {
  ------------------
  |  Branch (250:7): [True: 0, False: 328]
  ------------------
  251|      0|    OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  252|      0|    return 0;
  253|      0|  }
  254|       |
  255|    328|  r->width = a->width;
  256|    328|  r->neg = 0;
  257|    328|  return 1;
  258|    328|}
BN_usub:
  260|      4|int BN_usub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  261|      4|  if (!bn_usub_consttime(r, a, b)) {
  ------------------
  |  Branch (261:7): [True: 0, False: 4]
  ------------------
  262|      0|    return 0;
  263|      0|  }
  264|      4|  bn_set_minimal_width(r);
  265|      4|  return 1;
  266|      4|}

bn_mul_add_words:
   98|     31|                          BN_ULONG w) {
   99|     31|  BN_ULONG c1 = 0;
  100|       |
  101|     31|  if (num == 0) {
  ------------------
  |  Branch (101:7): [True: 0, False: 31]
  ------------------
  102|      0|    return (c1);
  103|      0|  }
  104|       |
  105|    167|  while (num & ~3) {
  ------------------
  |  Branch (105:10): [True: 136, False: 31]
  ------------------
  106|    136|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|    136|  do {                                                                     \
  |  |   70|    136|    register BN_ULONG high, low;                                           \
  |  |   71|    136|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|    136|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|    136|            : "a"(low), "g"(0)                                             \
  |  |   75|    136|            : "cc");                                                       \
  |  |   76|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|    136|            : "+m"(r), "+d"(high)                                          \
  |  |   78|    136|            : "r"(carry), "g"(0)                                           \
  |  |   79|    136|            : "cc");                                                       \
  |  |   80|    136|    (carry) = high;                                                        \
  |  |   81|    136|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  107|    136|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|    136|  do {                                                                     \
  |  |   70|    136|    register BN_ULONG high, low;                                           \
  |  |   71|    136|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|    136|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|    136|            : "a"(low), "g"(0)                                             \
  |  |   75|    136|            : "cc");                                                       \
  |  |   76|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|    136|            : "+m"(r), "+d"(high)                                          \
  |  |   78|    136|            : "r"(carry), "g"(0)                                           \
  |  |   79|    136|            : "cc");                                                       \
  |  |   80|    136|    (carry) = high;                                                        \
  |  |   81|    136|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  108|    136|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|    136|  do {                                                                     \
  |  |   70|    136|    register BN_ULONG high, low;                                           \
  |  |   71|    136|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|    136|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|    136|            : "a"(low), "g"(0)                                             \
  |  |   75|    136|            : "cc");                                                       \
  |  |   76|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|    136|            : "+m"(r), "+d"(high)                                          \
  |  |   78|    136|            : "r"(carry), "g"(0)                                           \
  |  |   79|    136|            : "cc");                                                       \
  |  |   80|    136|    (carry) = high;                                                        \
  |  |   81|    136|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  109|    136|    mul_add(rp[3], ap[3], w, c1);
  ------------------
  |  |   69|    136|  do {                                                                     \
  |  |   70|    136|    register BN_ULONG high, low;                                           \
  |  |   71|    136|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|    136|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|    136|            : "a"(low), "g"(0)                                             \
  |  |   75|    136|            : "cc");                                                       \
  |  |   76|    136|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|    136|            : "+m"(r), "+d"(high)                                          \
  |  |   78|    136|            : "r"(carry), "g"(0)                                           \
  |  |   79|    136|            : "cc");                                                       \
  |  |   80|    136|    (carry) = high;                                                        \
  |  |   81|    136|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  110|    136|    ap += 4;
  111|    136|    rp += 4;
  112|    136|    num -= 4;
  113|    136|  }
  114|     31|  if (num) {
  ------------------
  |  Branch (114:7): [True: 31, False: 0]
  ------------------
  115|     31|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|     31|  do {                                                                     \
  |  |   70|     31|    register BN_ULONG high, low;                                           \
  |  |   71|     31|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|     31|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|     31|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|     31|            : "a"(low), "g"(0)                                             \
  |  |   75|     31|            : "cc");                                                       \
  |  |   76|     31|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|     31|            : "+m"(r), "+d"(high)                                          \
  |  |   78|     31|            : "r"(carry), "g"(0)                                           \
  |  |   79|     31|            : "cc");                                                       \
  |  |   80|     31|    (carry) = high;                                                        \
  |  |   81|     31|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|     31|    if (--num == 0) {
  ------------------
  |  Branch (116:9): [True: 18, False: 13]
  ------------------
  117|     18|      return c1;
  118|     18|    }
  119|     13|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|     13|  do {                                                                     \
  |  |   70|     13|    register BN_ULONG high, low;                                           \
  |  |   71|     13|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|     13|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|     13|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|     13|            : "a"(low), "g"(0)                                             \
  |  |   75|     13|            : "cc");                                                       \
  |  |   76|     13|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|     13|            : "+m"(r), "+d"(high)                                          \
  |  |   78|     13|            : "r"(carry), "g"(0)                                           \
  |  |   79|     13|            : "cc");                                                       \
  |  |   80|     13|    (carry) = high;                                                        \
  |  |   81|     13|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  120|     13|    if (--num == 0) {
  ------------------
  |  Branch (120:9): [True: 0, False: 13]
  ------------------
  121|      0|      return c1;
  122|      0|    }
  123|     13|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|     13|  do {                                                                     \
  |  |   70|     13|    register BN_ULONG high, low;                                           \
  |  |   71|     13|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|     13|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|     13|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|     13|            : "a"(low), "g"(0)                                             \
  |  |   75|     13|            : "cc");                                                       \
  |  |   76|     13|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|     13|            : "+m"(r), "+d"(high)                                          \
  |  |   78|     13|            : "r"(carry), "g"(0)                                           \
  |  |   79|     13|            : "cc");                                                       \
  |  |   80|     13|    (carry) = high;                                                        \
  |  |   81|     13|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  124|     13|    return c1;
  125|     13|  }
  126|       |
  127|      0|  return c1;
  128|     31|}
bn_mul_words:
  131|    587|                      BN_ULONG w) {
  132|    587|  BN_ULONG c1 = 0;
  133|       |
  134|    587|  if (num == 0) {
  ------------------
  |  Branch (134:7): [True: 0, False: 587]
  ------------------
  135|      0|    return c1;
  136|      0|  }
  137|       |
  138|  2.52k|  while (num & ~3) {
  ------------------
  |  Branch (138:10): [True: 1.94k, False: 587]
  ------------------
  139|  1.94k|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|  1.94k|  do {                                                                     \
  |  |   85|  1.94k|    register BN_ULONG high, low;                                           \
  |  |   86|  1.94k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  1.94k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  1.94k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  1.94k|            : "a"(low), "g"(0)                                             \
  |  |   90|  1.94k|            : "cc");                                                       \
  |  |   91|  1.94k|    (r) = (carry);                                                         \
  |  |   92|  1.94k|    (carry) = high;                                                        \
  |  |   93|  1.94k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  140|  1.94k|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|  1.94k|  do {                                                                     \
  |  |   85|  1.94k|    register BN_ULONG high, low;                                           \
  |  |   86|  1.94k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  1.94k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  1.94k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  1.94k|            : "a"(low), "g"(0)                                             \
  |  |   90|  1.94k|            : "cc");                                                       \
  |  |   91|  1.94k|    (r) = (carry);                                                         \
  |  |   92|  1.94k|    (carry) = high;                                                        \
  |  |   93|  1.94k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  141|  1.94k|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|  1.94k|  do {                                                                     \
  |  |   85|  1.94k|    register BN_ULONG high, low;                                           \
  |  |   86|  1.94k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  1.94k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  1.94k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  1.94k|            : "a"(low), "g"(0)                                             \
  |  |   90|  1.94k|            : "cc");                                                       \
  |  |   91|  1.94k|    (r) = (carry);                                                         \
  |  |   92|  1.94k|    (carry) = high;                                                        \
  |  |   93|  1.94k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  142|  1.94k|    mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   84|  1.94k|  do {                                                                     \
  |  |   85|  1.94k|    register BN_ULONG high, low;                                           \
  |  |   86|  1.94k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  1.94k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  1.94k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  1.94k|            : "a"(low), "g"(0)                                             \
  |  |   90|  1.94k|            : "cc");                                                       \
  |  |   91|  1.94k|    (r) = (carry);                                                         \
  |  |   92|  1.94k|    (carry) = high;                                                        \
  |  |   93|  1.94k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  143|  1.94k|    ap += 4;
  144|  1.94k|    rp += 4;
  145|  1.94k|    num -= 4;
  146|  1.94k|  }
  147|    587|  if (num) {
  ------------------
  |  Branch (147:7): [True: 438, False: 149]
  ------------------
  148|    438|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|    438|  do {                                                                     \
  |  |   85|    438|    register BN_ULONG high, low;                                           \
  |  |   86|    438|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|    438|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|    438|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|    438|            : "a"(low), "g"(0)                                             \
  |  |   90|    438|            : "cc");                                                       \
  |  |   91|    438|    (r) = (carry);                                                         \
  |  |   92|    438|    (carry) = high;                                                        \
  |  |   93|    438|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  149|    438|    if (--num == 0) {
  ------------------
  |  Branch (149:9): [True: 406, False: 32]
  ------------------
  150|    406|      return c1;
  151|    406|    }
  152|     32|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|     32|  do {                                                                     \
  |  |   85|     32|    register BN_ULONG high, low;                                           \
  |  |   86|     32|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|     32|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|     32|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|     32|            : "a"(low), "g"(0)                                             \
  |  |   90|     32|            : "cc");                                                       \
  |  |   91|     32|    (r) = (carry);                                                         \
  |  |   92|     32|    (carry) = high;                                                        \
  |  |   93|     32|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|     32|    if (--num == 0) {
  ------------------
  |  Branch (153:9): [True: 15, False: 17]
  ------------------
  154|     15|      return c1;
  155|     15|    }
  156|     17|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|     17|  do {                                                                     \
  |  |   85|     17|    register BN_ULONG high, low;                                           \
  |  |   86|     17|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|     17|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|     17|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|     17|            : "a"(low), "g"(0)                                             \
  |  |   90|     17|            : "cc");                                                       \
  |  |   91|     17|    (r) = (carry);                                                         \
  |  |   92|     17|    (carry) = high;                                                        \
  |  |   93|     17|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|     17|  }
  158|    166|  return c1;
  159|    587|}
bn_add_words:
  189|  2.38M|                      size_t n) {
  190|  2.38M|  BN_ULONG ret;
  191|  2.38M|  size_t i = 0;
  192|       |
  193|  2.38M|  if (n == 0) {
  ------------------
  |  Branch (193:7): [True: 0, False: 2.38M]
  ------------------
  194|      0|    return 0;
  195|      0|  }
  196|       |
  197|  2.38M|  __asm__ volatile (
  198|  2.38M|      "	subq	%0,%0		\n"  // clear carry
  199|  2.38M|      "	jmp	1f		\n"
  200|  2.38M|      ".p2align 4			\n"
  201|  2.38M|      "1:"
  202|  2.38M|      "	movq	(%4,%2,8),%0	\n"
  203|  2.38M|      "	adcq	(%5,%2,8),%0	\n"
  204|  2.38M|      "	movq	%0,(%3,%2,8)	\n"
  205|  2.38M|      "	lea	1(%2),%2	\n"
  206|  2.38M|      "	dec	%1		\n"
  207|  2.38M|      "	jnz	1b		\n"
  208|  2.38M|      "	sbbq	%0,%0		\n"
  209|  2.38M|      : "=&r"(ret), "+c"(n), "+r"(i)
  210|  2.38M|      : "r"(rp), "r"(ap), "r"(bp)
  211|  2.38M|      : "cc", "memory");
  212|       |
  213|  2.38M|  return ret & 1;
  214|  2.38M|}
bn_sub_words:
  217|  2.38M|                      size_t n) {
  218|  2.38M|  BN_ULONG ret;
  219|  2.38M|  size_t i = 0;
  220|       |
  221|  2.38M|  if (n == 0) {
  ------------------
  |  Branch (221:7): [True: 306, False: 2.38M]
  ------------------
  222|    306|    return 0;
  223|    306|  }
  224|       |
  225|  2.38M|  __asm__ volatile (
  226|  2.38M|      "	subq	%0,%0		\n"  // clear borrow
  227|  2.38M|      "	jmp	1f		\n"
  228|  2.38M|      ".p2align 4			\n"
  229|  2.38M|      "1:"
  230|  2.38M|      "	movq	(%4,%2,8),%0	\n"
  231|  2.38M|      "	sbbq	(%5,%2,8),%0	\n"
  232|  2.38M|      "	movq	%0,(%3,%2,8)	\n"
  233|  2.38M|      "	lea	1(%2),%2	\n"
  234|  2.38M|      "	dec	%1		\n"
  235|  2.38M|      "	jnz	1b		\n"
  236|  2.38M|      "	sbbq	%0,%0		\n"
  237|  2.38M|      : "=&r"(ret), "+c"(n), "+r"(i)
  238|  2.38M|      : "r"(rp), "r"(ap), "r"(bp)
  239|  2.38M|      : "cc", "memory");
  240|       |
  241|  2.38M|  return ret & 1;
  242|  2.38M|}
bn_mul_comba8:
  287|  2.28k|void bn_mul_comba8(BN_ULONG r[16], const BN_ULONG a[8], const BN_ULONG b[8]) {
  288|  2.28k|  BN_ULONG c1, c2, c3;
  289|       |
  290|  2.28k|  c1 = 0;
  291|  2.28k|  c2 = 0;
  292|  2.28k|  c3 = 0;
  293|  2.28k|  mul_add_c(a[0], b[0], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  294|  2.28k|  r[0] = c1;
  295|  2.28k|  c1 = 0;
  296|  2.28k|  mul_add_c(a[0], b[1], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  297|  2.28k|  mul_add_c(a[1], b[0], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  298|  2.28k|  r[1] = c2;
  299|  2.28k|  c2 = 0;
  300|  2.28k|  mul_add_c(a[2], b[0], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  301|  2.28k|  mul_add_c(a[1], b[1], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  302|  2.28k|  mul_add_c(a[0], b[2], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  303|  2.28k|  r[2] = c3;
  304|  2.28k|  c3 = 0;
  305|  2.28k|  mul_add_c(a[0], b[3], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  306|  2.28k|  mul_add_c(a[1], b[2], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  307|  2.28k|  mul_add_c(a[2], b[1], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  308|  2.28k|  mul_add_c(a[3], b[0], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  309|  2.28k|  r[3] = c1;
  310|  2.28k|  c1 = 0;
  311|  2.28k|  mul_add_c(a[4], b[0], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  312|  2.28k|  mul_add_c(a[3], b[1], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  313|  2.28k|  mul_add_c(a[2], b[2], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  314|  2.28k|  mul_add_c(a[1], b[3], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  315|  2.28k|  mul_add_c(a[0], b[4], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  316|  2.28k|  r[4] = c2;
  317|  2.28k|  c2 = 0;
  318|  2.28k|  mul_add_c(a[0], b[5], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  319|  2.28k|  mul_add_c(a[1], b[4], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  320|  2.28k|  mul_add_c(a[2], b[3], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  321|  2.28k|  mul_add_c(a[3], b[2], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  322|  2.28k|  mul_add_c(a[4], b[1], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  323|  2.28k|  mul_add_c(a[5], b[0], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  324|  2.28k|  r[5] = c3;
  325|  2.28k|  c3 = 0;
  326|  2.28k|  mul_add_c(a[6], b[0], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  327|  2.28k|  mul_add_c(a[5], b[1], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  328|  2.28k|  mul_add_c(a[4], b[2], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  329|  2.28k|  mul_add_c(a[3], b[3], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  330|  2.28k|  mul_add_c(a[2], b[4], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  331|  2.28k|  mul_add_c(a[1], b[5], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  332|  2.28k|  mul_add_c(a[0], b[6], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  333|  2.28k|  r[6] = c1;
  334|  2.28k|  c1 = 0;
  335|  2.28k|  mul_add_c(a[0], b[7], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  336|  2.28k|  mul_add_c(a[1], b[6], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  337|  2.28k|  mul_add_c(a[2], b[5], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  338|  2.28k|  mul_add_c(a[3], b[4], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  339|  2.28k|  mul_add_c(a[4], b[3], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  340|  2.28k|  mul_add_c(a[5], b[2], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  341|  2.28k|  mul_add_c(a[6], b[1], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  342|  2.28k|  mul_add_c(a[7], b[0], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  343|  2.28k|  r[7] = c2;
  344|  2.28k|  c2 = 0;
  345|  2.28k|  mul_add_c(a[7], b[1], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  346|  2.28k|  mul_add_c(a[6], b[2], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  347|  2.28k|  mul_add_c(a[5], b[3], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  348|  2.28k|  mul_add_c(a[4], b[4], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  349|  2.28k|  mul_add_c(a[3], b[5], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  350|  2.28k|  mul_add_c(a[2], b[6], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  351|  2.28k|  mul_add_c(a[1], b[7], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  352|  2.28k|  r[8] = c3;
  353|  2.28k|  c3 = 0;
  354|  2.28k|  mul_add_c(a[2], b[7], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  355|  2.28k|  mul_add_c(a[3], b[6], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  356|  2.28k|  mul_add_c(a[4], b[5], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  357|  2.28k|  mul_add_c(a[5], b[4], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  358|  2.28k|  mul_add_c(a[6], b[3], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  359|  2.28k|  mul_add_c(a[7], b[2], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  360|  2.28k|  r[9] = c1;
  361|  2.28k|  c1 = 0;
  362|  2.28k|  mul_add_c(a[7], b[3], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  363|  2.28k|  mul_add_c(a[6], b[4], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  364|  2.28k|  mul_add_c(a[5], b[5], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  365|  2.28k|  mul_add_c(a[4], b[6], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  366|  2.28k|  mul_add_c(a[3], b[7], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  367|  2.28k|  r[10] = c2;
  368|  2.28k|  c2 = 0;
  369|  2.28k|  mul_add_c(a[4], b[7], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  370|  2.28k|  mul_add_c(a[5], b[6], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  371|  2.28k|  mul_add_c(a[6], b[5], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  372|  2.28k|  mul_add_c(a[7], b[4], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  373|  2.28k|  r[11] = c3;
  374|  2.28k|  c3 = 0;
  375|  2.28k|  mul_add_c(a[7], b[5], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  376|  2.28k|  mul_add_c(a[6], b[6], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  377|  2.28k|  mul_add_c(a[5], b[7], c1, c2, c3);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  378|  2.28k|  r[12] = c1;
  379|  2.28k|  c1 = 0;
  380|  2.28k|  mul_add_c(a[6], b[7], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  381|  2.28k|  mul_add_c(a[7], b[6], c2, c3, c1);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  382|  2.28k|  r[13] = c2;
  383|  2.28k|  c2 = 0;
  384|  2.28k|  mul_add_c(a[7], b[7], c3, c1, c2);
  ------------------
  |  |  252|  2.28k|  do {                                                               \
  |  |  253|  2.28k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.28k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.28k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.28k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.28k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.28k|            : "cc");                                                 \
  |  |  259|  2.28k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  385|  2.28k|  r[14] = c3;
  386|  2.28k|  r[15] = c1;
  387|  2.28k|}

BN_new:
   75|  5.14k|BIGNUM *BN_new(void) {
   76|  5.14k|  BIGNUM *bn = OPENSSL_malloc(sizeof(BIGNUM));
   77|       |
   78|  5.14k|  if (bn == NULL) {
  ------------------
  |  Branch (78:7): [True: 0, False: 5.14k]
  ------------------
   79|      0|    return NULL;
   80|      0|  }
   81|       |
   82|  5.14k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   83|  5.14k|  bn->flags = BN_FLG_MALLOCED;
  ------------------
  |  | 1026|  5.14k|#define BN_FLG_MALLOCED 0x01
  ------------------
   84|       |
   85|  5.14k|  return bn;
   86|  5.14k|}
BN_init:
   90|  2.18k|void BN_init(BIGNUM *bn) {
   91|  2.18k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   92|  2.18k|}
BN_free:
   94|  9.68k|void BN_free(BIGNUM *bn) {
   95|  9.68k|  if (bn == NULL) {
  ------------------
  |  Branch (95:7): [True: 2.38k, False: 7.30k]
  ------------------
   96|  2.38k|    return;
   97|  2.38k|  }
   98|       |
   99|  7.30k|  if ((bn->flags & BN_FLG_STATIC_DATA) == 0) {
  ------------------
  |  | 1027|  7.30k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (99:7): [True: 7.30k, False: 0]
  ------------------
  100|  7.30k|    OPENSSL_free(bn->d);
  101|  7.30k|  }
  102|       |
  103|  7.30k|  if (bn->flags & BN_FLG_MALLOCED) {
  ------------------
  |  | 1026|  7.30k|#define BN_FLG_MALLOCED 0x01
  ------------------
  |  Branch (103:7): [True: 5.14k, False: 2.15k]
  ------------------
  104|  5.14k|    OPENSSL_free(bn);
  105|  5.14k|  } else {
  106|  2.15k|    bn->d = NULL;
  107|  2.15k|  }
  108|  7.30k|}
BN_clear_free:
  110|    820|void BN_clear_free(BIGNUM *bn) {
  111|    820|  BN_free(bn);
  112|    820|}
BN_copy:
  134|    507|BIGNUM *BN_copy(BIGNUM *dest, const BIGNUM *src) {
  135|    507|  if (src == dest) {
  ------------------
  |  Branch (135:7): [True: 162, False: 345]
  ------------------
  136|    162|    return dest;
  137|    162|  }
  138|       |
  139|    345|  if (!bn_wexpand(dest, src->width)) {
  ------------------
  |  Branch (139:7): [True: 0, False: 345]
  ------------------
  140|      0|    return NULL;
  141|      0|  }
  142|       |
  143|    345|  OPENSSL_memcpy(dest->d, src->d, sizeof(src->d[0]) * src->width);
  144|       |
  145|    345|  dest->width = src->width;
  146|    345|  dest->neg = src->neg;
  147|    345|  return dest;
  148|    345|}
BN_num_bits_word:
  170|  2.41k|unsigned BN_num_bits_word(BN_ULONG l) {
  171|       |  // |BN_num_bits| is often called on RSA prime factors. These have public bit
  172|       |  // lengths, but all bits beyond the high bit are secret, so count bits in
  173|       |  // constant time.
  174|  2.41k|  BN_ULONG x, mask;
  175|  2.41k|  int bits = (l != 0);
  176|       |
  177|  2.41k|#if BN_BITS2 > 32
  178|       |  // Look at the upper half of |x|. |x| is at most 64 bits long.
  179|  2.41k|  x = l >> 32;
  180|       |  // Set |mask| to all ones if |x| (the top 32 bits of |l|) is non-zero and all
  181|       |  // all zeros otherwise.
  182|  2.41k|  mask = 0u - x;
  183|  2.41k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.41k|#define BN_BITS2 64
  ------------------
  184|       |  // If |x| is non-zero, the lower half is included in the bit count in full,
  185|       |  // and we count the upper half. Otherwise, we count the lower half.
  186|  2.41k|  bits += 32 & mask;
  187|  2.41k|  l ^= (x ^ l) & mask;  // |l| is |x| if |mask| and remains |l| otherwise.
  188|  2.41k|#endif
  189|       |
  190|       |  // The remaining blocks are analogous iterations at lower powers of two.
  191|  2.41k|  x = l >> 16;
  192|  2.41k|  mask = 0u - x;
  193|  2.41k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.41k|#define BN_BITS2 64
  ------------------
  194|  2.41k|  bits += 16 & mask;
  195|  2.41k|  l ^= (x ^ l) & mask;
  196|       |
  197|  2.41k|  x = l >> 8;
  198|  2.41k|  mask = 0u - x;
  199|  2.41k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.41k|#define BN_BITS2 64
  ------------------
  200|  2.41k|  bits += 8 & mask;
  201|  2.41k|  l ^= (x ^ l) & mask;
  202|       |
  203|  2.41k|  x = l >> 4;
  204|  2.41k|  mask = 0u - x;
  205|  2.41k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.41k|#define BN_BITS2 64
  ------------------
  206|  2.41k|  bits += 4 & mask;
  207|  2.41k|  l ^= (x ^ l) & mask;
  208|       |
  209|  2.41k|  x = l >> 2;
  210|  2.41k|  mask = 0u - x;
  211|  2.41k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.41k|#define BN_BITS2 64
  ------------------
  212|  2.41k|  bits += 2 & mask;
  213|  2.41k|  l ^= (x ^ l) & mask;
  214|       |
  215|  2.41k|  x = l >> 1;
  216|  2.41k|  mask = 0u - x;
  217|  2.41k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  2.41k|#define BN_BITS2 64
  ------------------
  218|  2.41k|  bits += 1 & mask;
  219|       |
  220|  2.41k|  return bits;
  221|  2.41k|}
BN_num_bits:
  223|  2.05k|unsigned BN_num_bits(const BIGNUM *bn) {
  224|  2.05k|  const int width = bn_minimal_width(bn);
  225|  2.05k|  if (width == 0) {
  ------------------
  |  Branch (225:7): [True: 18, False: 2.03k]
  ------------------
  226|     18|    return 0;
  227|     18|  }
  228|       |
  229|  2.03k|  return (width - 1) * BN_BITS2 + BN_num_bits_word(bn->d[width - 1]);
  ------------------
  |  |  151|  2.03k|#define BN_BITS2 64
  ------------------
  230|  2.05k|}
BN_num_bytes:
  232|     47|unsigned BN_num_bytes(const BIGNUM *bn) {
  233|     47|  return (BN_num_bits(bn) + 7) / 8;
  234|     47|}
BN_zero:
  236|  1.88k|void BN_zero(BIGNUM *bn) {
  237|  1.88k|  bn->width = bn->neg = 0;
  238|  1.88k|}
bn_fits_in_words:
  306|    895|int bn_fits_in_words(const BIGNUM *bn, size_t num) {
  307|       |  // All words beyond |num| must be zero.
  308|    895|  BN_ULONG mask = 0;
  309|  9.81k|  for (size_t i = num; i < (size_t)bn->width; i++) {
  ------------------
  |  Branch (309:24): [True: 8.91k, False: 895]
  ------------------
  310|  8.91k|    mask |= bn->d[i];
  311|  8.91k|  }
  312|    895|  return mask == 0;
  313|    895|}
bn_copy_words:
  315|    269|int bn_copy_words(BN_ULONG *out, size_t num, const BIGNUM *bn) {
  316|    269|  if (bn->neg) {
  ------------------
  |  Branch (316:7): [True: 0, False: 269]
  ------------------
  317|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  318|      0|    return 0;
  319|      0|  }
  320|       |
  321|    269|  size_t width = (size_t)bn->width;
  322|    269|  if (width > num) {
  ------------------
  |  Branch (322:7): [True: 0, False: 269]
  ------------------
  323|      0|    if (!bn_fits_in_words(bn, num)) {
  ------------------
  |  Branch (323:9): [True: 0, False: 0]
  ------------------
  324|      0|      OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  325|      0|      return 0;
  326|      0|    }
  327|      0|    width = num;
  328|      0|  }
  329|       |
  330|    269|  OPENSSL_memset(out, 0, sizeof(BN_ULONG) * num);
  331|    269|  OPENSSL_memcpy(out, bn->d, sizeof(BN_ULONG) * width);
  332|    269|  return 1;
  333|    269|}
BN_is_negative:
  335|  3.47k|int BN_is_negative(const BIGNUM *bn) {
  336|  3.47k|  return bn->neg != 0;
  337|  3.47k|}
BN_set_negative:
  339|      4|void BN_set_negative(BIGNUM *bn, int sign) {
  340|      4|  if (sign && !BN_is_zero(bn)) {
  ------------------
  |  Branch (340:7): [True: 0, False: 4]
  |  Branch (340:15): [True: 0, False: 0]
  ------------------
  341|      0|    bn->neg = 1;
  342|      4|  } else {
  343|      4|    bn->neg = 0;
  344|      4|  }
  345|      4|}
bn_wexpand:
  347|  7.56k|int bn_wexpand(BIGNUM *bn, size_t words) {
  348|  7.56k|  BN_ULONG *a;
  349|       |
  350|  7.56k|  if (words <= (size_t)bn->dmax) {
  ------------------
  |  Branch (350:7): [True: 1.58k, False: 5.98k]
  ------------------
  351|  1.58k|    return 1;
  352|  1.58k|  }
  353|       |
  354|  5.98k|  if (words > BN_MAX_WORDS) {
  ------------------
  |  |   73|  5.98k|#define BN_MAX_WORDS (INT_MAX / (4 * BN_BITS2))
  |  |  ------------------
  |  |  |  |  151|  5.98k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (354:7): [True: 0, False: 5.98k]
  ------------------
  355|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  356|      0|    return 0;
  357|      0|  }
  358|       |
  359|  5.98k|  if (bn->flags & BN_FLG_STATIC_DATA) {
  ------------------
  |  | 1027|  5.98k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (359:7): [True: 0, False: 5.98k]
  ------------------
  360|      0|    OPENSSL_PUT_ERROR(BN, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  361|      0|    return 0;
  362|      0|  }
  363|       |
  364|  5.98k|  a = OPENSSL_malloc(sizeof(BN_ULONG) * words);
  365|  5.98k|  if (a == NULL) {
  ------------------
  |  Branch (365:7): [True: 0, False: 5.98k]
  ------------------
  366|      0|    return 0;
  367|      0|  }
  368|       |
  369|  5.98k|  OPENSSL_memcpy(a, bn->d, sizeof(BN_ULONG) * bn->width);
  370|       |
  371|  5.98k|  OPENSSL_free(bn->d);
  372|  5.98k|  bn->d = a;
  373|  5.98k|  bn->dmax = (int)words;
  374|       |
  375|  5.98k|  return 1;
  376|  5.98k|}
bn_resize_words:
  386|      7|int bn_resize_words(BIGNUM *bn, size_t words) {
  387|      7|  if ((size_t)bn->width <= words) {
  ------------------
  |  Branch (387:7): [True: 7, False: 0]
  ------------------
  388|      7|    if (!bn_wexpand(bn, words)) {
  ------------------
  |  Branch (388:9): [True: 0, False: 7]
  ------------------
  389|      0|      return 0;
  390|      0|    }
  391|      7|    OPENSSL_memset(bn->d + bn->width, 0,
  392|      7|                   (words - bn->width) * sizeof(BN_ULONG));
  393|      7|    bn->width = (int)words;
  394|      7|    return 1;
  395|      7|  }
  396|       |
  397|       |  // All words beyond the new width must be zero.
  398|      0|  if (!bn_fits_in_words(bn, words)) {
  ------------------
  |  Branch (398:7): [True: 0, False: 0]
  ------------------
  399|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  400|      0|    return 0;
  401|      0|  }
  402|      0|  bn->width = (int)words;
  403|      0|  return 1;
  404|      0|}
bn_select_words:
  407|  4.55M|                     const BN_ULONG *b, size_t num) {
  408|  42.3M|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (408:22): [True: 37.8M, False: 4.55M]
  ------------------
  409|  37.8M|    static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  410|  37.8M|                  "crypto_word_t is too small");
  411|  37.8M|    r[i] = constant_time_select_w(mask, a[i], b[i]);
  412|  37.8M|  }
  413|  4.55M|}
bn_minimal_width:
  415|  2.13k|int bn_minimal_width(const BIGNUM *bn) {
  416|  2.13k|  int ret = bn->width;
  417|  3.53k|  while (ret > 0 && bn->d[ret - 1] == 0) {
  ------------------
  |  Branch (417:10): [True: 3.51k, False: 18]
  |  Branch (417:21): [True: 1.39k, False: 2.11k]
  ------------------
  418|  1.39k|    ret--;
  419|  1.39k|  }
  420|  2.13k|  return ret;
  421|  2.13k|}
bn_set_minimal_width:
  423|     68|void bn_set_minimal_width(BIGNUM *bn) {
  424|     68|  bn->width = bn_minimal_width(bn);
  425|     68|  if (bn->width == 0) {
  ------------------
  |  Branch (425:7): [True: 0, False: 68]
  ------------------
  426|      0|    bn->neg = 0;
  427|      0|  }
  428|     68|}
bcm.c:BN_value_one_do_init:
  159|      1|DEFINE_METHOD_FUNCTION(BIGNUM, BN_value_one) {
  160|      1|  static const BN_ULONG kOneLimbs[1] = { 1 };
  161|      1|  out->d = (BN_ULONG*) kOneLimbs;
  162|      1|  out->width = 1;
  163|      1|  out->dmax = 1;
  164|      1|  out->neg = 0;
  165|      1|  out->flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|      1|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  166|      1|}

bn_big_endian_to_words:
   65|  4.32k|                            size_t in_len) {
   66|  69.8k|  for (size_t i = 0; i < out_len; i++) {
  ------------------
  |  Branch (66:22): [True: 68.8k, False: 1.02k]
  ------------------
   67|  68.8k|    if (in_len < sizeof(BN_ULONG)) {
  ------------------
  |  Branch (67:9): [True: 3.30k, False: 65.5k]
  ------------------
   68|       |      // Load the last partial word.
   69|  3.30k|      BN_ULONG word = 0;
   70|  9.68k|      for (size_t j = 0; j < in_len; j++) {
  ------------------
  |  Branch (70:26): [True: 6.37k, False: 3.30k]
  ------------------
   71|  6.37k|        word = (word << 8) | in[j];
   72|  6.37k|      }
   73|  3.30k|      in_len = 0;
   74|  3.30k|      out[i] = word;
   75|       |      // Fill the remainder with zeros.
   76|  3.30k|      OPENSSL_memset(out + i + 1, 0, (out_len - i - 1) * sizeof(BN_ULONG));
   77|  3.30k|      break;
   78|  3.30k|    }
   79|       |
   80|  65.5k|    in_len -= sizeof(BN_ULONG);
   81|  65.5k|    out[i] = CRYPTO_load_word_be(in + in_len);
   82|  65.5k|  }
   83|       |
   84|       |  // The caller should have sized the output to avoid truncation.
   85|  4.32k|  assert(in_len == 0);
   86|  4.32k|}
BN_bin2bn:
   88|  4.32k|BIGNUM *BN_bin2bn(const uint8_t *in, size_t len, BIGNUM *ret) {
   89|  4.32k|  BIGNUM *bn = NULL;
   90|  4.32k|  if (ret == NULL) {
  ------------------
  |  Branch (90:7): [True: 281, False: 4.04k]
  ------------------
   91|    281|    bn = BN_new();
   92|    281|    if (bn == NULL) {
  ------------------
  |  Branch (92:9): [True: 0, False: 281]
  ------------------
   93|      0|      return NULL;
   94|      0|    }
   95|    281|    ret = bn;
   96|    281|  }
   97|       |
   98|  4.32k|  if (len == 0) {
  ------------------
  |  Branch (98:7): [True: 17, False: 4.30k]
  ------------------
   99|     17|    ret->width = 0;
  100|     17|    return ret;
  101|     17|  }
  102|       |
  103|  4.30k|  size_t num_words = ((len - 1) / BN_BYTES) + 1;
  ------------------
  |  |  152|  4.30k|#define BN_BYTES 8
  ------------------
  104|  4.30k|  if (!bn_wexpand(ret, num_words)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 4.30k]
  ------------------
  105|      0|    BN_free(bn);
  106|      0|    return NULL;
  107|      0|  }
  108|       |
  109|       |  // |bn_wexpand| must check bounds on |num_words| to write it into
  110|       |  // |ret->dmax|.
  111|  4.30k|  assert(num_words <= INT_MAX);
  112|  4.30k|  ret->width = (int)num_words;
  113|  4.30k|  ret->neg = 0;
  114|       |
  115|  4.30k|  bn_big_endian_to_words(ret->d, ret->width, in, len);
  116|  4.30k|  return ret;
  117|  4.30k|}
bn_words_to_big_endian:
  178|     12|                            size_t in_len) {
  179|       |  // The caller should have selected an output length without truncation.
  180|     12|  assert(fits_in_bytes(in, in_len, out_len));
  181|       |
  182|       |  // We only support little-endian platforms, so the internal representation is
  183|       |  // also little-endian as bytes. We can simply copy it in reverse.
  184|     12|  const uint8_t *bytes = (const uint8_t *)in;
  185|     12|  size_t num_bytes = in_len * sizeof(BN_ULONG);
  186|     12|  if (out_len < num_bytes) {
  ------------------
  |  Branch (186:7): [True: 4, False: 8]
  ------------------
  187|      4|    num_bytes = out_len;
  188|      4|  }
  189|       |
  190|    392|  for (size_t i = 0; i < num_bytes; i++) {
  ------------------
  |  Branch (190:22): [True: 380, False: 12]
  ------------------
  191|    380|    out[out_len - i - 1] = bytes[i];
  192|    380|  }
  193|       |  // Pad out the rest of the buffer with zeroes.
  194|     12|  OPENSSL_memset(out, 0, out_len - num_bytes);
  195|     12|}
BN_bn2bin_padded:
  222|     12|int BN_bn2bin_padded(uint8_t *out, size_t len, const BIGNUM *in) {
  223|     12|  if (!fits_in_bytes(in->d, in->width, len)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 12]
  ------------------
  224|      0|    return 0;
  225|      0|  }
  226|       |
  227|     12|  bn_words_to_big_endian(out, len, in->d, in->width);
  228|     12|  return 1;
  229|     12|}
bcm.c:fits_in_bytes:
  155|     24|                         size_t num_bytes) {
  156|     24|  const uint8_t *bytes = (const uint8_t *)words;
  157|     24|  size_t tot_bytes = num_words * sizeof(BN_ULONG);
  158|     24|  uint8_t mask = 0;
  159|     64|  for (size_t i = num_bytes; i < tot_bytes; i++) {
  ------------------
  |  Branch (159:30): [True: 40, False: 24]
  ------------------
  160|     40|    mask |= bytes[i];
  161|     40|  }
  162|     24|  return mask == 0;
  163|     24|}

BN_ucmp:
   99|  2.22k|int BN_ucmp(const BIGNUM *a, const BIGNUM *b) {
  100|  2.22k|  return bn_cmp_words_consttime(a->d, a->width, b->d, b->width);
  101|  2.22k|}
BN_cmp:
  103|  1.85k|int BN_cmp(const BIGNUM *a, const BIGNUM *b) {
  104|  1.85k|  if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 1.85k]
  |  Branch (104:22): [True: 0, False: 1.85k]
  ------------------
  105|      0|    if (a != NULL) {
  ------------------
  |  Branch (105:9): [True: 0, False: 0]
  ------------------
  106|      0|      return -1;
  107|      0|    } else if (b != NULL) {
  ------------------
  |  Branch (107:16): [True: 0, False: 0]
  ------------------
  108|      0|      return 1;
  109|      0|    } else {
  110|      0|      return 0;
  111|      0|    }
  112|      0|  }
  113|       |
  114|       |  // We do not attempt to process the sign bit in constant time. Negative
  115|       |  // |BIGNUM|s should never occur in crypto, only calculators.
  116|  1.85k|  if (a->neg != b->neg) {
  ------------------
  |  Branch (116:7): [True: 0, False: 1.85k]
  ------------------
  117|      0|    if (a->neg) {
  ------------------
  |  Branch (117:9): [True: 0, False: 0]
  ------------------
  118|      0|      return -1;
  119|      0|    }
  120|      0|    return 1;
  121|      0|  }
  122|       |
  123|  1.85k|  int ret = BN_ucmp(a, b);
  124|  1.85k|  return a->neg ? -ret : ret;
  ------------------
  |  Branch (124:10): [True: 0, False: 1.85k]
  ------------------
  125|  1.85k|}
bn_less_than_words:
  127|    285|int bn_less_than_words(const BN_ULONG *a, const BN_ULONG *b, size_t len) {
  128|    285|  return bn_cmp_words_consttime(a, len, b, len) < 0;
  129|    285|}
BN_abs_is_word:
  131|    395|int BN_abs_is_word(const BIGNUM *bn, BN_ULONG w) {
  132|    395|  if (bn->width == 0) {
  ------------------
  |  Branch (132:7): [True: 0, False: 395]
  ------------------
  133|      0|    return w == 0;
  134|      0|  }
  135|    395|  BN_ULONG mask = bn->d[0] ^ w;
  136|  6.71k|  for (int i = 1; i < bn->width; i++) {
  ------------------
  |  Branch (136:19): [True: 6.32k, False: 395]
  ------------------
  137|  6.32k|    mask |= bn->d[i];
  138|  6.32k|  }
  139|    395|  return mask == 0;
  140|    395|}
BN_is_zero:
  153|    888|int BN_is_zero(const BIGNUM *bn) {
  154|    888|  return bn_fits_in_words(bn, 0);
  155|    888|}
BN_is_one:
  157|    395|int BN_is_one(const BIGNUM *bn) {
  158|    395|  return bn->neg == 0 && BN_abs_is_word(bn, 1);
  ------------------
  |  Branch (158:10): [True: 395, False: 0]
  |  Branch (158:26): [True: 156, False: 239]
  ------------------
  159|    395|}
BN_is_odd:
  165|  1.10k|int BN_is_odd(const BIGNUM *bn) {
  166|  1.10k|  return bn->width > 0 && (bn->d[0] & 1) == 1;
  ------------------
  |  Branch (166:10): [True: 1.10k, False: 0]
  |  Branch (166:27): [True: 1.03k, False: 73]
  ------------------
  167|  1.10k|}
bcm.c:bn_cmp_words_consttime:
   68|  2.50k|                                  const BN_ULONG *b, size_t b_len) {
   69|  2.50k|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
   70|  2.50k|                "crypto_word_t is too small");
   71|  2.50k|  int ret = 0;
   72|       |  // Process the common words in little-endian order.
   73|  2.50k|  size_t min = a_len < b_len ? a_len : b_len;
  ------------------
  |  Branch (73:16): [True: 916, False: 1.59k]
  ------------------
   74|  44.2k|  for (size_t i = 0; i < min; i++) {
  ------------------
  |  Branch (74:22): [True: 41.7k, False: 2.50k]
  ------------------
   75|  41.7k|    crypto_word_t eq = constant_time_eq_w(a[i], b[i]);
   76|  41.7k|    crypto_word_t lt = constant_time_lt_w(a[i], b[i]);
   77|  41.7k|    ret =
   78|  41.7k|        constant_time_select_int(eq, ret, constant_time_select_int(lt, -1, 1));
   79|  41.7k|  }
   80|       |
   81|       |  // If |a| or |b| has non-zero words beyond |min|, they take precedence.
   82|  2.50k|  if (a_len < b_len) {
  ------------------
  |  Branch (82:7): [True: 916, False: 1.59k]
  ------------------
   83|    916|    crypto_word_t mask = 0;
   84|  12.7k|    for (size_t i = a_len; i < b_len; i++) {
  ------------------
  |  Branch (84:28): [True: 11.8k, False: 916]
  ------------------
   85|  11.8k|      mask |= b[i];
   86|  11.8k|    }
   87|    916|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, -1);
   88|  1.59k|  } else if (b_len < a_len) {
  ------------------
  |  Branch (88:14): [True: 572, False: 1.02k]
  ------------------
   89|    572|    crypto_word_t mask = 0;
   90|  12.3k|    for (size_t i = b_len; i < a_len; i++) {
  ------------------
  |  Branch (90:28): [True: 11.7k, False: 572]
  ------------------
   91|  11.7k|      mask |= a[i];
   92|  11.7k|    }
   93|    572|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, 1);
   94|    572|  }
   95|       |
   96|  2.50k|  return ret;
   97|  2.50k|}

BN_CTX_new:
  108|    367|BN_CTX *BN_CTX_new(void) {
  109|    367|  BN_CTX *ret = OPENSSL_malloc(sizeof(BN_CTX));
  110|    367|  if (!ret) {
  ------------------
  |  Branch (110:7): [True: 0, False: 367]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|       |  // Initialise the structure
  115|    367|  ret->bignums = NULL;
  116|    367|  BN_STACK_init(&ret->stack);
  117|    367|  ret->used = 0;
  118|    367|  ret->error = 0;
  119|    367|  ret->defer_error = 0;
  120|    367|  return ret;
  121|    367|}
BN_CTX_free:
  123|    534|void BN_CTX_free(BN_CTX *ctx) {
  124|    534|  if (ctx == NULL) {
  ------------------
  |  Branch (124:7): [True: 167, False: 367]
  ------------------
  125|    167|    return;
  126|    167|  }
  127|       |
  128|       |  // All |BN_CTX_start| calls must be matched with |BN_CTX_end|, otherwise the
  129|       |  // function may use more memory than expected, potentially without bound if
  130|       |  // done in a loop. Assert that all |BIGNUM|s have been released.
  131|    367|  assert(ctx->used == 0 || ctx->error);
  132|    367|  sk_BIGNUM_pop_free(ctx->bignums, BN_free);
  133|    367|  BN_STACK_cleanup(&ctx->stack);
  134|    367|  OPENSSL_free(ctx);
  135|    367|}
BN_CTX_start:
  137|  1.34k|void BN_CTX_start(BN_CTX *ctx) {
  138|  1.34k|  if (ctx->error) {
  ------------------
  |  Branch (138:7): [True: 0, False: 1.34k]
  ------------------
  139|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  140|       |    // of |BN_CTX_end| calls to come. Do nothing.
  141|      0|    return;
  142|      0|  }
  143|       |
  144|  1.34k|  if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (144:7): [True: 0, False: 1.34k]
  ------------------
  145|      0|    ctx->error = 1;
  146|       |    // |BN_CTX_start| cannot fail, so defer the error to |BN_CTX_get|.
  147|      0|    ctx->defer_error = 1;
  148|      0|  }
  149|  1.34k|}
BN_CTX_get:
  151|  1.88k|BIGNUM *BN_CTX_get(BN_CTX *ctx) {
  152|       |  // Once any operation has failed, they all do.
  153|  1.88k|  if (ctx->error) {
  ------------------
  |  Branch (153:7): [True: 0, False: 1.88k]
  ------------------
  154|      0|    if (ctx->defer_error) {
  ------------------
  |  Branch (154:9): [True: 0, False: 0]
  ------------------
  155|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      0|      ctx->defer_error = 0;
  157|      0|    }
  158|      0|    return NULL;
  159|      0|  }
  160|       |
  161|  1.88k|  if (ctx->bignums == NULL) {
  ------------------
  |  Branch (161:7): [True: 364, False: 1.51k]
  ------------------
  162|    364|    ctx->bignums = sk_BIGNUM_new_null();
  163|    364|    if (ctx->bignums == NULL) {
  ------------------
  |  Branch (163:9): [True: 0, False: 364]
  ------------------
  164|      0|      ctx->error = 1;
  165|      0|      return NULL;
  166|      0|    }
  167|    364|  }
  168|       |
  169|  1.88k|  if (ctx->used == sk_BIGNUM_num(ctx->bignums)) {
  ------------------
  |  Branch (169:7): [True: 778, False: 1.10k]
  ------------------
  170|    778|    BIGNUM *bn = BN_new();
  171|    778|    if (bn == NULL || !sk_BIGNUM_push(ctx->bignums, bn)) {
  ------------------
  |  Branch (171:9): [True: 0, False: 778]
  |  Branch (171:23): [True: 0, False: 778]
  ------------------
  172|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|      BN_free(bn);
  174|      0|      ctx->error = 1;
  175|      0|      return NULL;
  176|      0|    }
  177|    778|  }
  178|       |
  179|  1.88k|  BIGNUM *ret = sk_BIGNUM_value(ctx->bignums, ctx->used);
  180|  1.88k|  BN_zero(ret);
  181|       |  // This is bounded by |sk_BIGNUM_num|, so it cannot overflow.
  182|  1.88k|  ctx->used++;
  183|  1.88k|  return ret;
  184|  1.88k|}
BN_CTX_end:
  186|  1.34k|void BN_CTX_end(BN_CTX *ctx) {
  187|  1.34k|  if (ctx->error) {
  ------------------
  |  Branch (187:7): [True: 0, False: 1.34k]
  ------------------
  188|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  189|       |    // of |BN_CTX_end| calls to come. Do nothing.
  190|      0|    return;
  191|      0|  }
  192|       |
  193|  1.34k|  ctx->used = BN_STACK_pop(&ctx->stack);
  194|  1.34k|}
bcm.c:BN_STACK_init:
  199|    367|static void BN_STACK_init(BN_STACK *st) {
  200|    367|  st->indexes = NULL;
  201|    367|  st->depth = st->size = 0;
  202|    367|}
bcm.c:BN_STACK_cleanup:
  204|    367|static void BN_STACK_cleanup(BN_STACK *st) {
  205|    367|  OPENSSL_free(st->indexes);
  206|    367|}
bcm.c:BN_STACK_push:
  208|  1.34k|static int BN_STACK_push(BN_STACK *st, size_t idx) {
  209|  1.34k|  if (st->depth == st->size) {
  ------------------
  |  Branch (209:7): [True: 367, False: 981]
  ------------------
  210|       |    // This function intentionally does not push to the error queue on error.
  211|       |    // Error-reporting is deferred to |BN_CTX_get|.
  212|    367|    size_t new_size = st->size != 0 ? st->size * 3 / 2 : BN_CTX_START_FRAMES;
  ------------------
  |  |   67|    367|#define BN_CTX_START_FRAMES 32
  ------------------
  |  Branch (212:23): [True: 0, False: 367]
  ------------------
  213|    367|    if (new_size <= st->size || new_size > ((size_t)-1) / sizeof(size_t)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 367]
  |  Branch (213:33): [True: 0, False: 367]
  ------------------
  214|      0|      return 0;
  215|      0|    }
  216|    367|    size_t *new_indexes =
  217|    367|        OPENSSL_realloc(st->indexes, new_size * sizeof(size_t));
  218|    367|    if (new_indexes == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 367]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|    367|    st->indexes = new_indexes;
  222|    367|    st->size = new_size;
  223|    367|  }
  224|       |
  225|  1.34k|  st->indexes[st->depth] = idx;
  226|  1.34k|  st->depth++;
  227|  1.34k|  return 1;
  228|  1.34k|}
bcm.c:BN_STACK_pop:
  230|  1.34k|static size_t BN_STACK_pop(BN_STACK *st) {
  231|  1.34k|  assert(st->depth > 0);
  232|  1.34k|  st->depth--;
  233|  1.34k|  return st->indexes[st->depth];
  234|  1.34k|}

BN_div:
  195|      7|           const BIGNUM *divisor, BN_CTX *ctx) {
  196|      7|  int norm_shift, loop;
  197|      7|  BIGNUM wnum;
  198|      7|  BN_ULONG *resp, *wnump;
  199|      7|  BN_ULONG d0, d1;
  200|      7|  int num_n, div_n;
  201|       |
  202|       |  // This function relies on the historical minimal-width |BIGNUM| invariant.
  203|       |  // It is already not constant-time (constant-time reductions should use
  204|       |  // Montgomery logic), so we shrink all inputs and intermediate values to
  205|       |  // retain the previous behavior.
  206|       |
  207|       |  // Invalid zero-padding would have particularly bad consequences.
  208|      7|  int numerator_width = bn_minimal_width(numerator);
  209|      7|  int divisor_width = bn_minimal_width(divisor);
  210|      7|  if ((numerator_width > 0 && numerator->d[numerator_width - 1] == 0) ||
  ------------------
  |  Branch (210:8): [True: 7, False: 0]
  |  Branch (210:31): [True: 0, False: 7]
  ------------------
  211|      7|      (divisor_width > 0 && divisor->d[divisor_width - 1] == 0)) {
  ------------------
  |  Branch (211:8): [True: 7, False: 0]
  |  Branch (211:29): [True: 0, False: 7]
  ------------------
  212|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NOT_INITIALIZED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|      0|    return 0;
  214|      0|  }
  215|       |
  216|      7|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (216:7): [True: 0, False: 7]
  ------------------
  217|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  218|      0|    return 0;
  219|      0|  }
  220|       |
  221|      7|  BN_CTX_start(ctx);
  222|      7|  BIGNUM *tmp = BN_CTX_get(ctx);
  223|      7|  BIGNUM *snum = BN_CTX_get(ctx);
  224|      7|  BIGNUM *sdiv = BN_CTX_get(ctx);
  225|      7|  BIGNUM *res = NULL;
  226|      7|  if (quotient == NULL) {
  ------------------
  |  Branch (226:7): [True: 7, False: 0]
  ------------------
  227|      7|    res = BN_CTX_get(ctx);
  228|      7|  } else {
  229|      0|    res = quotient;
  230|      0|  }
  231|      7|  if (sdiv == NULL || res == NULL) {
  ------------------
  |  Branch (231:7): [True: 0, False: 7]
  |  Branch (231:23): [True: 0, False: 7]
  ------------------
  232|      0|    goto err;
  233|      0|  }
  234|       |
  235|       |  // First we normalise the numbers
  236|      7|  norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
                norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  237|      7|  if (!BN_lshift(sdiv, divisor, norm_shift)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 7]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|      7|  bn_set_minimal_width(sdiv);
  241|      7|  sdiv->neg = 0;
  242|      7|  norm_shift += BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  243|      7|  if (!BN_lshift(snum, numerator, norm_shift)) {
  ------------------
  |  Branch (243:7): [True: 0, False: 7]
  ------------------
  244|      0|    goto err;
  245|      0|  }
  246|      7|  bn_set_minimal_width(snum);
  247|      7|  snum->neg = 0;
  248|       |
  249|       |  // Since we don't want to have special-case logic for the case where snum is
  250|       |  // larger than sdiv, we pad snum with enough zeroes without changing its
  251|       |  // value.
  252|      7|  if (snum->width <= sdiv->width + 1) {
  ------------------
  |  Branch (252:7): [True: 0, False: 7]
  ------------------
  253|      0|    if (!bn_wexpand(snum, sdiv->width + 2)) {
  ------------------
  |  Branch (253:9): [True: 0, False: 0]
  ------------------
  254|      0|      goto err;
  255|      0|    }
  256|      0|    for (int i = snum->width; i < sdiv->width + 2; i++) {
  ------------------
  |  Branch (256:31): [True: 0, False: 0]
  ------------------
  257|      0|      snum->d[i] = 0;
  258|      0|    }
  259|      0|    snum->width = sdiv->width + 2;
  260|      7|  } else {
  261|      7|    if (!bn_wexpand(snum, snum->width + 1)) {
  ------------------
  |  Branch (261:9): [True: 0, False: 7]
  ------------------
  262|      0|      goto err;
  263|      0|    }
  264|      7|    snum->d[snum->width] = 0;
  265|      7|    snum->width++;
  266|      7|  }
  267|       |
  268|      7|  div_n = sdiv->width;
  269|      7|  num_n = snum->width;
  270|      7|  loop = num_n - div_n;
  271|       |  // Lets setup a 'window' into snum
  272|       |  // This is the part that corresponds to the current
  273|       |  // 'area' being divided
  274|      7|  wnum.neg = 0;
  275|      7|  wnum.d = &(snum->d[loop]);
  276|      7|  wnum.width = div_n;
  277|       |  // only needed when BN_ucmp messes up the values between width and max
  278|      7|  wnum.dmax = snum->dmax - loop;  // so we don't step out of bounds
  279|       |
  280|       |  // Get the top 2 words of sdiv
  281|       |  // div_n=sdiv->width;
  282|      7|  d0 = sdiv->d[div_n - 1];
  283|      7|  d1 = (div_n == 1) ? 0 : sdiv->d[div_n - 2];
  ------------------
  |  Branch (283:8): [True: 0, False: 7]
  ------------------
  284|       |
  285|       |  // pointer to the 'top' of snum
  286|      7|  wnump = &(snum->d[num_n - 1]);
  287|       |
  288|       |  // Setup |res|. |numerator| and |res| may alias, so we save |numerator->neg|
  289|       |  // for later.
  290|      7|  const int numerator_neg = numerator->neg;
  291|      7|  res->neg = (numerator_neg ^ divisor->neg);
  292|      7|  if (!bn_wexpand(res, loop + 1)) {
  ------------------
  |  Branch (292:7): [True: 0, False: 7]
  ------------------
  293|      0|    goto err;
  294|      0|  }
  295|      7|  res->width = loop - 1;
  296|      7|  resp = &(res->d[loop - 1]);
  297|       |
  298|       |  // space for temp
  299|      7|  if (!bn_wexpand(tmp, div_n + 1)) {
  ------------------
  |  Branch (299:7): [True: 0, False: 7]
  ------------------
  300|      0|    goto err;
  301|      0|  }
  302|       |
  303|       |  // if res->width == 0 then clear the neg value otherwise decrease
  304|       |  // the resp pointer
  305|      7|  if (res->width == 0) {
  ------------------
  |  Branch (305:7): [True: 0, False: 7]
  ------------------
  306|      0|    res->neg = 0;
  307|      7|  } else {
  308|      7|    resp--;
  309|      7|  }
  310|       |
  311|     63|  for (int i = 0; i < loop - 1; i++, wnump--, resp--) {
  ------------------
  |  Branch (311:19): [True: 56, False: 7]
  ------------------
  312|     56|    BN_ULONG q, l0;
  313|       |    // the first part of the loop uses the top two words of snum and sdiv to
  314|       |    // calculate a BN_ULONG q such that | wnum - sdiv * q | < sdiv
  315|     56|    BN_ULONG n0, n1, rm = 0;
  316|       |
  317|     56|    n0 = wnump[0];
  318|     56|    n1 = wnump[-1];
  319|     56|    if (n0 == d0) {
  ------------------
  |  Branch (319:9): [True: 0, False: 56]
  ------------------
  320|      0|      q = BN_MASK2;
  ------------------
  |  |  154|      0|#define BN_MASK2 (0xffffffffffffffffUL)
  ------------------
  321|     56|    } else {
  322|       |      // n0 < d0
  323|     56|      bn_div_rem_words(&q, &rm, n0, n1, d0);
  324|       |
  325|     56|#ifdef BN_ULLONG
  326|     56|      BN_ULLONG t2 = (BN_ULLONG)d1 * q;
  ------------------
  |  |  145|     56|#define BN_ULLONG uint128_t
  ------------------
  327|     57|      for (;;) {
  328|     57|        if (t2 <= ((((BN_ULLONG)rm) << BN_BITS2) | wnump[-2])) {
  ------------------
  |  |  151|     57|#define BN_BITS2 64
  ------------------
  |  Branch (328:13): [True: 49, False: 8]
  ------------------
  329|     49|          break;
  330|     49|        }
  331|      8|        q--;
  332|      8|        rm += d0;
  333|      8|        if (rm < d0) {
  ------------------
  |  Branch (333:13): [True: 7, False: 1]
  ------------------
  334|      7|          break;  // don't let rm overflow
  335|      7|        }
  336|      1|        t2 -= d1;
  337|      1|      }
  338|       |#else  // !BN_ULLONG
  339|       |      BN_ULONG t2l, t2h;
  340|       |      BN_UMULT_LOHI(t2l, t2h, d1, q);
  341|       |      for (;;) {
  342|       |        if (t2h < rm ||
  343|       |            (t2h == rm && t2l <= wnump[-2])) {
  344|       |          break;
  345|       |        }
  346|       |        q--;
  347|       |        rm += d0;
  348|       |        if (rm < d0) {
  349|       |          break;  // don't let rm overflow
  350|       |        }
  351|       |        if (t2l < d1) {
  352|       |          t2h--;
  353|       |        }
  354|       |        t2l -= d1;
  355|       |      }
  356|       |#endif  // !BN_ULLONG
  357|     56|    }
  358|       |
  359|     56|    l0 = bn_mul_words(tmp->d, sdiv->d, div_n, q);
  360|     56|    tmp->d[div_n] = l0;
  361|     56|    wnum.d--;
  362|       |    // ingore top values of the bignums just sub the two
  363|       |    // BN_ULONG arrays with bn_sub_words
  364|     56|    if (bn_sub_words(wnum.d, wnum.d, tmp->d, div_n + 1)) {
  ------------------
  |  Branch (364:9): [True: 0, False: 56]
  ------------------
  365|       |      // Note: As we have considered only the leading
  366|       |      // two BN_ULONGs in the calculation of q, sdiv * q
  367|       |      // might be greater than wnum (but then (q-1) * sdiv
  368|       |      // is less or equal than wnum)
  369|      0|      q--;
  370|      0|      if (bn_add_words(wnum.d, wnum.d, sdiv->d, div_n)) {
  ------------------
  |  Branch (370:11): [True: 0, False: 0]
  ------------------
  371|       |        // we can't have an overflow here (assuming
  372|       |        // that q != 0, but if q == 0 then tmp is
  373|       |        // zero anyway)
  374|      0|        (*wnump)++;
  375|      0|      }
  376|      0|    }
  377|       |    // store part of the result
  378|     56|    *resp = q;
  379|     56|  }
  380|       |
  381|      7|  bn_set_minimal_width(snum);
  382|       |
  383|      7|  if (rem != NULL) {
  ------------------
  |  Branch (383:7): [True: 7, False: 0]
  ------------------
  384|      7|    if (!BN_rshift(rem, snum, norm_shift)) {
  ------------------
  |  Branch (384:9): [True: 0, False: 7]
  ------------------
  385|      0|      goto err;
  386|      0|    }
  387|      7|    if (!BN_is_zero(rem)) {
  ------------------
  |  Branch (387:9): [True: 7, False: 0]
  ------------------
  388|      7|      rem->neg = numerator_neg;
  389|      7|    }
  390|      7|  }
  391|       |
  392|      7|  bn_set_minimal_width(res);
  393|      7|  BN_CTX_end(ctx);
  394|      7|  return 1;
  395|       |
  396|      0|err:
  397|      0|  BN_CTX_end(ctx);
  398|      0|  return 0;
  399|      7|}
bn_reduce_once_in_place:
  434|  1.59M|                                 BN_ULONG *tmp, size_t num) {
  435|       |  // See |bn_reduce_once| for why this logic works.
  436|  1.59M|  carry -= bn_sub_words(tmp, r, m, num);
  437|  1.59M|  assert(carry == 0 || carry == (BN_ULONG)-1);
  438|  1.59M|  bn_select_words(r, carry, r /* tmp < 0 */, tmp /* tmp >= 0 */, num);
  439|  1.59M|  return carry;
  440|  1.59M|}
bn_mod_sub_words:
  443|   785k|                      const BN_ULONG *m, BN_ULONG *tmp, size_t num) {
  444|       |  // r = a - b
  445|   785k|  BN_ULONG borrow = bn_sub_words(r, a, b, num);
  446|       |  // tmp = a - b + m
  447|   785k|  bn_add_words(tmp, r, m, num);
  448|   785k|  bn_select_words(r, 0 - borrow, tmp /* r < 0 */, r /* r >= 0 */, num);
  449|   785k|}
bn_mod_add_words:
  452|  1.15M|                      const BN_ULONG *m, BN_ULONG *tmp, size_t num) {
  453|  1.15M|  BN_ULONG carry = bn_add_words(r, a, b, num);
  454|  1.15M|  bn_reduce_once_in_place(r, carry, m, tmp, num);
  455|  1.15M|}
bn_div_consttime:
  459|    488|                     unsigned divisor_min_bits, BN_CTX *ctx) {
  460|    488|  if (BN_is_negative(numerator) || BN_is_negative(divisor)) {
  ------------------
  |  Branch (460:7): [True: 0, False: 488]
  |  Branch (460:36): [True: 0, False: 488]
  ------------------
  461|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  462|      0|    return 0;
  463|      0|  }
  464|    488|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (464:7): [True: 0, False: 488]
  ------------------
  465|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  466|      0|    return 0;
  467|      0|  }
  468|       |
  469|       |  // This function implements long division in binary. It is not very efficient,
  470|       |  // but it is simple, easy to make constant-time, and performant enough for RSA
  471|       |  // key generation.
  472|       |
  473|    488|  int ret = 0;
  474|    488|  BN_CTX_start(ctx);
  475|    488|  BIGNUM *q = quotient, *r = remainder;
  476|    488|  if (quotient == NULL || quotient == numerator || quotient == divisor) {
  ------------------
  |  Branch (476:7): [True: 488, False: 0]
  |  Branch (476:27): [True: 0, False: 0]
  |  Branch (476:52): [True: 0, False: 0]
  ------------------
  477|    488|    q = BN_CTX_get(ctx);
  478|    488|  }
  479|    488|  if (remainder == NULL || remainder == numerator || remainder == divisor) {
  ------------------
  |  Branch (479:7): [True: 0, False: 488]
  |  Branch (479:28): [True: 326, False: 162]
  |  Branch (479:54): [True: 0, False: 162]
  ------------------
  480|    326|    r = BN_CTX_get(ctx);
  481|    326|  }
  482|    488|  BIGNUM *tmp = BN_CTX_get(ctx);
  483|    488|  if (q == NULL || r == NULL || tmp == NULL ||
  ------------------
  |  Branch (483:7): [True: 0, False: 488]
  |  Branch (483:20): [True: 0, False: 488]
  |  Branch (483:33): [True: 0, False: 488]
  ------------------
  484|    488|      !bn_wexpand(q, numerator->width) ||
  ------------------
  |  Branch (484:7): [True: 0, False: 488]
  ------------------
  485|    488|      !bn_wexpand(r, divisor->width) ||
  ------------------
  |  Branch (485:7): [True: 0, False: 488]
  ------------------
  486|    488|      !bn_wexpand(tmp, divisor->width)) {
  ------------------
  |  Branch (486:7): [True: 0, False: 488]
  ------------------
  487|      0|    goto err;
  488|      0|  }
  489|       |
  490|    488|  OPENSSL_memset(q->d, 0, numerator->width * sizeof(BN_ULONG));
  491|    488|  q->width = numerator->width;
  492|    488|  q->neg = 0;
  493|       |
  494|    488|  OPENSSL_memset(r->d, 0, divisor->width * sizeof(BN_ULONG));
  495|    488|  r->width = divisor->width;
  496|    488|  r->neg = 0;
  497|       |
  498|       |  // Incorporate |numerator| into |r|, one bit at a time, reducing after each
  499|       |  // step. We maintain the invariant that |0 <= r < divisor| and
  500|       |  // |q * divisor + r = n| where |n| is the portion of |numerator| incorporated
  501|       |  // so far.
  502|       |  //
  503|       |  // First, we short-circuit the loop: if we know |divisor| has at least
  504|       |  // |divisor_min_bits| bits, the top |divisor_min_bits - 1| can be incorporated
  505|       |  // without reductions. This significantly speeds up |RSA_check_key|. For
  506|       |  // simplicity, we round down to a whole number of words.
  507|    488|  assert(divisor_min_bits <= BN_num_bits(divisor));
  508|    488|  int initial_words = 0;
  509|    488|  if (divisor_min_bits > 0) {
  ------------------
  |  Branch (509:7): [True: 488, False: 0]
  ------------------
  510|    488|    initial_words = (divisor_min_bits - 1) / BN_BITS2;
  ------------------
  |  |  151|    488|#define BN_BITS2 64
  ------------------
  511|    488|    if (initial_words > numerator->width) {
  ------------------
  |  Branch (511:9): [True: 0, False: 488]
  ------------------
  512|      0|      initial_words = numerator->width;
  513|      0|    }
  514|    488|    OPENSSL_memcpy(r->d, numerator->d + numerator->width - initial_words,
  515|    488|                   initial_words * sizeof(BN_ULONG));
  516|    488|  }
  517|       |
  518|  7.40k|  for (int i = numerator->width - initial_words - 1; i >= 0; i--) {
  ------------------
  |  Branch (518:54): [True: 6.91k, False: 488]
  ------------------
  519|   449k|    for (int bit = BN_BITS2 - 1; bit >= 0; bit--) {
  ------------------
  |  |  151|  6.91k|#define BN_BITS2 64
  ------------------
  |  Branch (519:34): [True: 442k, False: 6.91k]
  ------------------
  520|       |      // Incorporate the next bit of the numerator, by computing
  521|       |      // r = 2*r or 2*r + 1. Note the result fits in one more word. We store the
  522|       |      // extra word in |carry|.
  523|   442k|      BN_ULONG carry = bn_add_words(r->d, r->d, r->d, divisor->width);
  524|   442k|      r->d[0] |= (numerator->d[i] >> bit) & 1;
  525|       |      // |r| was previously fully-reduced, so we know:
  526|       |      //      2*0 <= r <= 2*(divisor-1) + 1
  527|       |      //        0 <= r <= 2*divisor - 1 < 2*divisor.
  528|       |      // Thus |r| satisfies the preconditions for |bn_reduce_once_in_place|.
  529|   442k|      BN_ULONG subtracted = bn_reduce_once_in_place(r->d, carry, divisor->d,
  530|   442k|                                                    tmp->d, divisor->width);
  531|       |      // The corresponding bit of the quotient is set iff we needed to subtract.
  532|   442k|      q->d[i] |= (~subtracted & 1) << bit;
  533|   442k|    }
  534|  6.91k|  }
  535|       |
  536|    488|  if ((quotient != NULL && !BN_copy(quotient, q)) ||
  ------------------
  |  Branch (536:8): [True: 0, False: 488]
  |  Branch (536:28): [True: 0, False: 0]
  ------------------
  537|    488|      (remainder != NULL && !BN_copy(remainder, r))) {
  ------------------
  |  Branch (537:8): [True: 488, False: 0]
  |  Branch (537:29): [True: 0, False: 488]
  ------------------
  538|      0|    goto err;
  539|      0|  }
  540|       |
  541|    488|  ret = 1;
  542|       |
  543|    488|err:
  544|    488|  BN_CTX_end(ctx);
  545|    488|  return ret;
  546|    488|}
bcm.c:bn_div_rem_words:
  140|     56|                                    BN_ULONG n0, BN_ULONG n1, BN_ULONG d0) {
  141|       |  // GCC and Clang generate function calls to |__udivdi3| and |__umoddi3| when
  142|       |  // the |BN_ULLONG|-based C code is used.
  143|       |  //
  144|       |  // GCC bugs:
  145|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=14224
  146|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=43721
  147|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=54183
  148|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=58897
  149|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=65668
  150|       |  //
  151|       |  // Clang bugs:
  152|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=6397
  153|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=12418
  154|       |  //
  155|       |  // These issues aren't specific to x86 and x86_64, so it might be worthwhile
  156|       |  // to add more assembly language implementations.
  157|       |#if defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86)
  158|       |  __asm__ volatile("divl %4"
  159|       |                   : "=a"(*quotient_out), "=d"(*rem_out)
  160|       |                   : "a"(n1), "d"(n0), "rm"(d0)
  161|       |                   : "cc");
  162|       |#elif defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86_64)
  163|     56|  __asm__ volatile("divq %4"
  164|     56|                   : "=a"(*quotient_out), "=d"(*rem_out)
  165|     56|                   : "a"(n1), "d"(n0), "rm"(d0)
  166|     56|                   : "cc");
  167|       |#else
  168|       |#if defined(BN_CAN_DIVIDE_ULLONG)
  169|       |  BN_ULLONG n = (((BN_ULLONG)n0) << BN_BITS2) | n1;
  170|       |  *quotient_out = (BN_ULONG)(n / d0);
  171|       |#else
  172|       |  *quotient_out = bn_div_words(n0, n1, d0);
  173|       |#endif
  174|       |  *rem_out = n1 - (*quotient_out * d0);
  175|       |#endif
  176|     56|}

BN_MONT_CTX_new:
  124|      7|BN_MONT_CTX *BN_MONT_CTX_new(void) {
  125|      7|  BN_MONT_CTX *ret = OPENSSL_malloc(sizeof(BN_MONT_CTX));
  126|       |
  127|      7|  if (ret == NULL) {
  ------------------
  |  Branch (127:7): [True: 0, False: 7]
  ------------------
  128|      0|    return NULL;
  129|      0|  }
  130|       |
  131|      7|  OPENSSL_memset(ret, 0, sizeof(BN_MONT_CTX));
  132|      7|  BN_init(&ret->RR);
  133|      7|  BN_init(&ret->N);
  134|       |
  135|      7|  return ret;
  136|      7|}
BN_MONT_CTX_free:
  138|  1.74k|void BN_MONT_CTX_free(BN_MONT_CTX *mont) {
  139|  1.74k|  if (mont == NULL) {
  ------------------
  |  Branch (139:7): [True: 1.74k, False: 0]
  ------------------
  140|  1.74k|    return;
  141|  1.74k|  }
  142|       |
  143|      0|  BN_free(&mont->RR);
  144|      0|  BN_free(&mont->N);
  145|      0|  OPENSSL_free(mont);
  146|      0|}
BN_MONT_CTX_set:
  210|      7|int BN_MONT_CTX_set(BN_MONT_CTX *mont, const BIGNUM *mod, BN_CTX *ctx) {
  211|      7|  if (!bn_mont_ctx_set_N_and_n0(mont, mod)) {
  ------------------
  |  Branch (211:7): [True: 0, False: 7]
  ------------------
  212|      0|    return 0;
  213|      0|  }
  214|       |
  215|      7|  BN_CTX *new_ctx = NULL;
  216|      7|  if (ctx == NULL) {
  ------------------
  |  Branch (216:7): [True: 4, False: 3]
  ------------------
  217|      4|    new_ctx = BN_CTX_new();
  218|      4|    if (new_ctx == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 4]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|      4|    ctx = new_ctx;
  222|      4|  }
  223|       |
  224|       |  // Save RR = R**2 (mod N). R is the smallest power of 2**BN_BITS2 such that R
  225|       |  // > mod. Even though the assembly on some 32-bit platforms works with 64-bit
  226|       |  // values, using |BN_BITS2| here, rather than |BN_MONT_CTX_N0_LIMBS *
  227|       |  // BN_BITS2|, is correct because R**2 will still be a multiple of the latter
  228|       |  // as |BN_MONT_CTX_N0_LIMBS| is either one or two.
  229|      7|  unsigned lgBigR = mont->N.width * BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  230|      7|  BN_zero(&mont->RR);
  231|      7|  int ok = BN_set_bit(&mont->RR, lgBigR * 2) &&
  ------------------
  |  Branch (231:12): [True: 7, False: 0]
  ------------------
  232|      7|           BN_mod(&mont->RR, &mont->RR, &mont->N, ctx) &&
  ------------------
  |  |  547|     14|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  |  |  ------------------
  |  |  |  Branch (547:3): [True: 7, False: 0]
  |  |  ------------------
  ------------------
  233|      7|           bn_resize_words(&mont->RR, mont->N.width);
  ------------------
  |  Branch (233:12): [True: 7, False: 0]
  ------------------
  234|      7|  BN_CTX_free(new_ctx);
  235|      7|  return ok;
  236|      7|}
BN_MONT_CTX_new_for_modulus:
  238|      7|BN_MONT_CTX *BN_MONT_CTX_new_for_modulus(const BIGNUM *mod, BN_CTX *ctx) {
  239|      7|  BN_MONT_CTX *mont = BN_MONT_CTX_new();
  240|      7|  if (mont == NULL ||
  ------------------
  |  Branch (240:7): [True: 0, False: 7]
  ------------------
  241|      7|      !BN_MONT_CTX_set(mont, mod, ctx)) {
  ------------------
  |  Branch (241:7): [True: 0, False: 7]
  ------------------
  242|      0|    BN_MONT_CTX_free(mont);
  243|      0|    return NULL;
  244|      0|  }
  245|      7|  return mont;
  246|      7|}
bn_to_montgomery_small:
  459|     15|                            const BN_MONT_CTX *mont) {
  460|     15|  bn_mod_mul_montgomery_small(r, a, mont->RR.d, num, mont);
  461|     15|}
bn_mod_mul_montgomery_small:
  479|  1.25M|                                 const BN_MONT_CTX *mont) {
  480|  1.25M|  if (num != (size_t)mont->N.width || num > BN_SMALL_MAX_WORDS) {
  ------------------
  |  |  684|  1.25M|#define BN_SMALL_MAX_WORDS 9
  ------------------
  |  Branch (480:7): [True: 0, False: 1.25M]
  |  Branch (480:39): [True: 0, False: 1.25M]
  ------------------
  481|      0|    abort();
  482|      0|  }
  483|       |
  484|  1.25M|#if defined(OPENSSL_BN_ASM_MONT)
  485|       |  // |bn_mul_mont| requires at least 128 bits of limbs, at least for x86.
  486|  1.25M|  if (num >= (128 / BN_BITS2)) {
  ------------------
  |  |  151|  1.25M|#define BN_BITS2 64
  ------------------
  |  Branch (486:7): [True: 1.25M, False: 0]
  ------------------
  487|  1.25M|    if (!bn_mul_mont(r, a, b, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (487:9): [True: 0, False: 1.25M]
  ------------------
  488|      0|      abort();  // The check above ensures this won't happen.
  489|      0|    }
  490|  1.25M|    return;
  491|  1.25M|  }
  492|      0|#endif
  493|       |
  494|       |  // Compute the product.
  495|      0|  BN_ULONG tmp[2 * BN_SMALL_MAX_WORDS];
  496|      0|  if (a == b) {
  ------------------
  |  Branch (496:7): [True: 0, False: 0]
  ------------------
  497|      0|    bn_sqr_small(tmp, 2 * num, a, num);
  498|      0|  } else {
  499|      0|    bn_mul_small(tmp, 2 * num, a, num, b, num);
  500|      0|  }
  501|       |
  502|       |  // Reduce.
  503|      0|  if (!bn_from_montgomery_in_place(r, num, tmp, 2 * num, mont)) {
  ------------------
  |  Branch (503:7): [True: 0, False: 0]
  ------------------
  504|      0|    abort();
  505|      0|  }
  506|      0|  OPENSSL_cleanse(tmp, 2 * num * sizeof(BN_ULONG));
  507|      0|}
bcm.c:bn_mont_ctx_set_N_and_n0:
  162|      7|static int bn_mont_ctx_set_N_and_n0(BN_MONT_CTX *mont, const BIGNUM *mod) {
  163|      7|  if (BN_is_zero(mod)) {
  ------------------
  |  Branch (163:7): [True: 0, False: 7]
  ------------------
  164|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  165|      0|    return 0;
  166|      0|  }
  167|      7|  if (!BN_is_odd(mod)) {
  ------------------
  |  Branch (167:7): [True: 0, False: 7]
  ------------------
  168|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|      0|    return 0;
  170|      0|  }
  171|      7|  if (BN_is_negative(mod)) {
  ------------------
  |  Branch (171:7): [True: 0, False: 7]
  ------------------
  172|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|    return 0;
  174|      0|  }
  175|      7|  if (!bn_fits_in_words(mod, BN_MONTGOMERY_MAX_WORDS)) {
  ------------------
  |  |  363|      7|#define BN_MONTGOMERY_MAX_WORDS (8 * 1024 / sizeof(BN_ULONG))
  ------------------
  |  Branch (175:7): [True: 0, False: 7]
  ------------------
  176|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|    return 0;
  178|      0|  }
  179|       |
  180|       |  // Save the modulus.
  181|      7|  if (!BN_copy(&mont->N, mod)) {
  ------------------
  |  Branch (181:7): [True: 0, False: 7]
  ------------------
  182|      0|    OPENSSL_PUT_ERROR(BN, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  183|      0|    return 0;
  184|      0|  }
  185|       |  // |mont->N| is always stored minimally. Computing RR efficiently leaks the
  186|       |  // size of the modulus. While the modulus may be private in RSA (one of the
  187|       |  // primes), their sizes are public, so this is fine.
  188|      7|  bn_set_minimal_width(&mont->N);
  189|       |
  190|       |  // Find n0 such that n0 * N == -1 (mod r).
  191|       |  //
  192|       |  // Only certain BN_BITS2<=32 platforms actually make use of n0[1]. For the
  193|       |  // others, we could use a shorter R value and use faster |BN_ULONG|-based
  194|       |  // math instead of |uint64_t|-based math, which would be double-precision.
  195|       |  // However, currently only the assembler files know which is which.
  196|      7|  static_assert(BN_MONT_CTX_N0_LIMBS == 1 || BN_MONT_CTX_N0_LIMBS == 2,
  197|      7|                "BN_MONT_CTX_N0_LIMBS value is invalid");
  198|      7|  static_assert(sizeof(BN_ULONG) * BN_MONT_CTX_N0_LIMBS == sizeof(uint64_t),
  199|      7|                "uint64_t is insufficient precision for n0");
  200|      7|  uint64_t n0 = bn_mont_n0(&mont->N);
  201|      7|  mont->n0[0] = (BN_ULONG)n0;
  202|       |#if BN_MONT_CTX_N0_LIMBS == 2
  203|       |  mont->n0[1] = (BN_ULONG)(n0 >> BN_BITS2);
  204|       |#else
  205|      7|  mont->n0[1] = 0;
  206|      7|#endif
  207|      7|  return 1;
  208|      7|}

bn_mont_n0:
   33|      7|uint64_t bn_mont_n0(const BIGNUM *n) {
   34|       |  // These conditions are checked by the caller, |BN_MONT_CTX_set| or
   35|       |  // |BN_MONT_CTX_new_consttime|.
   36|      7|  assert(!BN_is_zero(n));
   37|      7|  assert(!BN_is_negative(n));
   38|      7|  assert(BN_is_odd(n));
   39|       |
   40|       |  // r == 2**(BN_MONT_CTX_N0_LIMBS * BN_BITS2) and LG_LITTLE_R == lg(r). This
   41|       |  // ensures that we can do integer division by |r| by simply ignoring
   42|       |  // |BN_MONT_CTX_N0_LIMBS| limbs. Similarly, we can calculate values modulo
   43|       |  // |r| by just looking at the lowest |BN_MONT_CTX_N0_LIMBS| limbs. This is
   44|       |  // what makes Montgomery multiplication efficient.
   45|       |  //
   46|       |  // As shown in Algorithm 1 of "Fast Prime Field Elliptic Curve Cryptography
   47|       |  // with 256 Bit Primes" by Shay Gueron and Vlad Krasnov, in the loop of a
   48|       |  // multi-limb Montgomery multiplication of |a * b (mod n)|, given the
   49|       |  // unreduced product |t == a * b|, we repeatedly calculate:
   50|       |  //
   51|       |  //    t1 := t % r         |t1| is |t|'s lowest limb (see previous paragraph).
   52|       |  //    t2 := t1*n0*n
   53|       |  //    t3 := t + t2
   54|       |  //    t := t3 / r         copy all limbs of |t3| except the lowest to |t|.
   55|       |  //
   56|       |  // In the last step, it would only make sense to ignore the lowest limb of
   57|       |  // |t3| if it were zero. The middle steps ensure that this is the case:
   58|       |  //
   59|       |  //                            t3 ==  0 (mod r)
   60|       |  //                        t + t2 ==  0 (mod r)
   61|       |  //                   t + t1*n0*n ==  0 (mod r)
   62|       |  //                       t1*n0*n == -t (mod r)
   63|       |  //                        t*n0*n == -t (mod r)
   64|       |  //                          n0*n == -1 (mod r)
   65|       |  //                            n0 == -1/n (mod r)
   66|       |  //
   67|       |  // Thus, in each iteration of the loop, we multiply by the constant factor
   68|       |  // |n0|, the negative inverse of n (mod r).
   69|       |
   70|       |  // n_mod_r = n % r. As explained above, this is done by taking the lowest
   71|       |  // |BN_MONT_CTX_N0_LIMBS| limbs of |n|.
   72|      7|  uint64_t n_mod_r = n->d[0];
   73|       |#if BN_MONT_CTX_N0_LIMBS == 2
   74|       |  if (n->width > 1) {
   75|       |    n_mod_r |= (uint64_t)n->d[1] << BN_BITS2;
   76|       |  }
   77|       |#endif
   78|       |
   79|      7|  return bn_neg_inv_mod_r_u64(n_mod_r);
   80|      7|}
bcm.c:bn_neg_inv_mod_r_u64:
  104|      7|static uint64_t bn_neg_inv_mod_r_u64(uint64_t n) {
  105|      7|  assert(n % 2 == 1);
  106|       |
  107|       |  // alpha == 2**(lg r - 1) == r / 2.
  108|      7|  static const uint64_t alpha = UINT64_C(1) << (LG_LITTLE_R - 1);
  ------------------
  |  |   31|      7|#define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  158|      7|#define BN_MONT_CTX_N0_LIMBS 1
  |  |  ------------------
  |  |               #define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|      7|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  109|       |
  110|      7|  const uint64_t beta = n;
  111|       |
  112|      7|  uint64_t u = 1;
  113|      7|  uint64_t v = 0;
  114|       |
  115|       |  // The invariant maintained from here on is:
  116|       |  // 2**(lg r - i) == u*2*alpha - v*beta.
  117|    455|  for (size_t i = 0; i < LG_LITTLE_R; ++i) {
  ------------------
  |  |   31|    455|#define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  158|    455|#define BN_MONT_CTX_N0_LIMBS 1
  |  |  ------------------
  |  |               #define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|    455|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (117:22): [True: 448, False: 7]
  ------------------
  118|    448|#if BN_BITS2 == 64 && defined(BN_ULLONG)
  119|    448|    assert((BN_ULLONG)(1) << (LG_LITTLE_R - i) ==
  120|    448|           ((BN_ULLONG)u * 2 * alpha) - ((BN_ULLONG)v * beta));
  121|    448|#endif
  122|       |
  123|       |    // Delete a common factor of 2 in u and v if |u| is even. Otherwise, set
  124|       |    // |u = (u + beta) / 2| and |v = (v / 2) + alpha|.
  125|       |
  126|    448|    uint64_t u_is_odd = UINT64_C(0) - (u & 1);  // Either 0xff..ff or 0.
  127|       |
  128|       |    // The addition can overflow, so use Dietz's method for it.
  129|       |    //
  130|       |    // Dietz calculates (x+y)/2 by (x⊕y)>>1 + x&y. This is valid for all
  131|       |    // (unsigned) x and y, even when x+y overflows. Evidence for 32-bit values
  132|       |    // (embedded in 64 bits to so that overflow can be ignored):
  133|       |    //
  134|       |    // (declare-fun x () (_ BitVec 64))
  135|       |    // (declare-fun y () (_ BitVec 64))
  136|       |    // (assert (let (
  137|       |    //    (one (_ bv1 64))
  138|       |    //    (thirtyTwo (_ bv32 64)))
  139|       |    //    (and
  140|       |    //      (bvult x (bvshl one thirtyTwo))
  141|       |    //      (bvult y (bvshl one thirtyTwo))
  142|       |    //      (not (=
  143|       |    //        (bvadd (bvlshr (bvxor x y) one) (bvand x y))
  144|       |    //        (bvlshr (bvadd x y) one)))
  145|       |    // )))
  146|       |    // (check-sat)
  147|    448|    uint64_t beta_if_u_is_odd = beta & u_is_odd;  // Either |beta| or 0.
  148|    448|    u = ((u ^ beta_if_u_is_odd) >> 1) + (u & beta_if_u_is_odd);
  149|       |
  150|    448|    uint64_t alpha_if_u_is_odd = alpha & u_is_odd;  // Either |alpha| or 0.
  151|    448|    v = (v >> 1) + alpha_if_u_is_odd;
  152|    448|  }
  153|       |
  154|       |  // The invariant now shows that u*r - v*n == 1 since r == 2 * alpha.
  155|      7|#if BN_BITS2 == 64 && defined(BN_ULLONG)
  156|      7|  assert(1 == ((BN_ULLONG)u * 2 * alpha) - ((BN_ULLONG)v * beta));
  157|      7|#endif
  158|       |
  159|      7|  return v;
  160|      7|}

bn_mul_consttime:
  525|    685|int bn_mul_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  526|       |  // Prevent negative zeros.
  527|    685|  if (a->neg || b->neg) {
  ------------------
  |  Branch (527:7): [True: 0, False: 685]
  |  Branch (527:17): [True: 0, False: 685]
  ------------------
  528|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  529|      0|    return 0;
  530|      0|  }
  531|       |
  532|    685|  return bn_mul_impl(r, a, b, ctx);
  533|    685|}
bcm.c:bn_abs_sub_part_words:
  172|  2.28k|                                      BN_ULONG *tmp) {
  173|  2.28k|  BN_ULONG borrow = bn_sub_part_words(tmp, a, b, cl, dl);
  174|  2.28k|  bn_sub_part_words(r, b, a, cl, -dl);
  175|  2.28k|  int r_len = cl + (dl < 0 ? -dl : dl);
  ------------------
  |  Branch (175:21): [True: 381, False: 1.90k]
  ------------------
  176|  2.28k|  borrow = 0 - borrow;
  177|  2.28k|  bn_select_words(r, borrow, r /* tmp < 0 */, tmp /* tmp >= 0 */, r_len);
  178|  2.28k|  return borrow;
  179|  2.28k|}
bcm.c:bn_sub_part_words:
  130|  4.57k|                                  const BN_ULONG *b, int cl, int dl) {
  131|  4.57k|  assert(cl >= 0);
  132|  4.57k|  BN_ULONG borrow = bn_sub_words(r, a, b, cl);
  133|  4.57k|  if (dl == 0) {
  ------------------
  |  Branch (133:7): [True: 3.05k, False: 1.52k]
  ------------------
  134|  3.05k|    return borrow;
  135|  3.05k|  }
  136|       |
  137|  1.52k|  r += cl;
  138|  1.52k|  a += cl;
  139|  1.52k|  b += cl;
  140|       |
  141|  1.52k|  if (dl < 0) {
  ------------------
  |  Branch (141:7): [True: 762, False: 762]
  ------------------
  142|       |    // |a| is shorter than |b|. Complete the subtraction as if the excess words
  143|       |    // in |a| were zeros.
  144|    762|    dl = -dl;
  145|  12.3k|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (145:21): [True: 11.5k, False: 762]
  ------------------
  146|  11.5k|      r[i] = 0u - b[i] - borrow;
  147|  11.5k|      borrow |= r[i] != 0;
  148|  11.5k|    }
  149|    762|  } else {
  150|       |    // |b| is shorter than |a|. Complete the subtraction as if the excess words
  151|       |    // in |b| were zeros.
  152|  12.3k|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (152:21): [True: 11.5k, False: 762]
  ------------------
  153|       |      // |r| and |a| may alias, so use a temporary.
  154|  11.5k|      BN_ULONG tmp = a[i];
  155|  11.5k|      r[i] = a[i] - borrow;
  156|  11.5k|      borrow = tmp < r[i];
  157|  11.5k|    }
  158|    762|  }
  159|       |
  160|  1.52k|  return borrow;
  161|  4.57k|}
bcm.c:bn_mul_impl:
  420|    685|                       BN_CTX *ctx) {
  421|    685|  int al = a->width;
  422|    685|  int bl = b->width;
  423|    685|  if (al == 0 || bl == 0) {
  ------------------
  |  Branch (423:7): [True: 0, False: 685]
  |  Branch (423:18): [True: 0, False: 685]
  ------------------
  424|      0|    BN_zero(r);
  425|      0|    return 1;
  426|      0|  }
  427|       |
  428|    685|  int ret = 0;
  429|    685|  BIGNUM *rr;
  430|    685|  BN_CTX_start(ctx);
  431|    685|  if (r == a || r == b) {
  ------------------
  |  Branch (431:7): [True: 0, False: 685]
  |  Branch (431:17): [True: 0, False: 685]
  ------------------
  432|      0|    rr = BN_CTX_get(ctx);
  433|      0|    if (rr == NULL) {
  ------------------
  |  Branch (433:9): [True: 0, False: 0]
  ------------------
  434|      0|      goto err;
  435|      0|    }
  436|    685|  } else {
  437|    685|    rr = r;
  438|    685|  }
  439|    685|  rr->neg = a->neg ^ b->neg;
  440|       |
  441|    685|  int i = al - bl;
  442|    685|  if (i == 0) {
  ------------------
  |  Branch (442:7): [True: 214, False: 471]
  ------------------
  443|    214|    if (al == 8) {
  ------------------
  |  Branch (443:9): [True: 0, False: 214]
  ------------------
  444|      0|      if (!bn_wexpand(rr, 16)) {
  ------------------
  |  Branch (444:11): [True: 0, False: 0]
  ------------------
  445|      0|        goto err;
  446|      0|      }
  447|      0|      rr->width = 16;
  448|      0|      bn_mul_comba8(rr->d, a->d, b->d);
  449|      0|      goto end;
  450|      0|    }
  451|    214|  }
  452|       |
  453|    685|  int top = al + bl;
  454|    685|  static const int kMulNormalSize = 16;
  455|    685|  if (al >= kMulNormalSize && bl >= kMulNormalSize) {
  ------------------
  |  Branch (455:7): [True: 547, False: 138]
  |  Branch (455:31): [True: 382, False: 165]
  ------------------
  456|    382|    if (-1 <= i && i <= 1) {
  ------------------
  |  Branch (456:9): [True: 382, False: 0]
  |  Branch (456:20): [True: 382, False: 0]
  ------------------
  457|       |      // Find the largest power of two less than or equal to the larger length.
  458|    382|      int j;
  459|    382|      if (i >= 0) {
  ------------------
  |  Branch (459:11): [True: 367, False: 15]
  ------------------
  460|    367|        j = BN_num_bits_word((BN_ULONG)al);
  461|    367|      } else {
  462|     15|        j = BN_num_bits_word((BN_ULONG)bl);
  463|     15|      }
  464|    382|      j = 1 << (j - 1);
  465|    382|      assert(j <= al || j <= bl);
  466|    382|      BIGNUM *t = BN_CTX_get(ctx);
  467|    382|      if (t == NULL) {
  ------------------
  |  Branch (467:11): [True: 0, False: 382]
  ------------------
  468|      0|        goto err;
  469|      0|      }
  470|    382|      if (al > j || bl > j) {
  ------------------
  |  Branch (470:11): [True: 381, False: 1]
  |  Branch (470:21): [True: 0, False: 1]
  ------------------
  471|       |        // We know |al| and |bl| are at most one from each other, so if al > j,
  472|       |        // bl >= j, and vice versa. Thus we can use |bn_mul_part_recursive|.
  473|       |        //
  474|       |        // TODO(davidben): This codepath is almost unused in standard
  475|       |        // algorithms. Is this optimization necessary? See notes in
  476|       |        // https://boringssl-review.googlesource.com/q/I0bd604e2cd6a75c266f64476c23a730ca1721ea6
  477|    381|        assert(al >= j && bl >= j);
  478|    381|        if (!bn_wexpand(t, j * 8) ||
  ------------------
  |  Branch (478:13): [True: 0, False: 381]
  ------------------
  479|    381|            !bn_wexpand(rr, j * 4)) {
  ------------------
  |  Branch (479:13): [True: 0, False: 381]
  ------------------
  480|      0|          goto err;
  481|      0|        }
  482|    381|        bn_mul_part_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  483|    381|      } else {
  484|       |        // al <= j && bl <= j. Additionally, we know j <= al or j <= bl, so one
  485|       |        // of al - j or bl - j is zero. The other, by the bound on |i| above, is
  486|       |        // zero or -1. Thus, we can use |bn_mul_recursive|.
  487|      1|        if (!bn_wexpand(t, j * 4) ||
  ------------------
  |  Branch (487:13): [True: 0, False: 1]
  ------------------
  488|      1|            !bn_wexpand(rr, j * 2)) {
  ------------------
  |  Branch (488:13): [True: 0, False: 1]
  ------------------
  489|      0|          goto err;
  490|      0|        }
  491|      1|        bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  492|      1|      }
  493|    382|      rr->width = top;
  494|    382|      goto end;
  495|    382|    }
  496|    382|  }
  497|       |
  498|    303|  if (!bn_wexpand(rr, top)) {
  ------------------
  |  Branch (498:7): [True: 0, False: 303]
  ------------------
  499|      0|    goto err;
  500|      0|  }
  501|    303|  rr->width = top;
  502|    303|  bn_mul_normal(rr->d, a->d, al, b->d, bl);
  503|       |
  504|    685|end:
  505|    685|  if (r != rr && !BN_copy(r, rr)) {
  ------------------
  |  Branch (505:7): [True: 0, False: 685]
  |  Branch (505:18): [True: 0, False: 0]
  ------------------
  506|      0|    goto err;
  507|      0|  }
  508|    685|  ret = 1;
  509|       |
  510|    685|err:
  511|    685|  BN_CTX_end(ctx);
  512|    685|  return ret;
  513|    685|}
bcm.c:bn_mul_part_recursive:
  312|    381|                                  BN_ULONG *t) {
  313|       |  // |n| is a power of two.
  314|    381|  assert(n != 0 && (n & (n - 1)) == 0);
  315|       |  // Check |tna| and |tnb| are in range.
  316|    381|  assert(0 <= tna && tna < n);
  317|    381|  assert(0 <= tnb && tnb < n);
  318|    381|  assert(-1 <= tna - tnb && tna - tnb <= 1);
  319|       |
  320|    381|  int n2 = n * 2;
  321|    381|  if (n < 8) {
  ------------------
  |  Branch (321:7): [True: 0, False: 381]
  ------------------
  322|      0|    bn_mul_normal(r, a, n + tna, b, n + tnb);
  323|      0|    OPENSSL_memset(r + n2 + tna + tnb, 0, n2 - tna - tnb);
  324|      0|    return;
  325|      0|  }
  326|       |
  327|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|. |a1|
  328|       |  // and |b1| have size |tna| and |tnb|, respectively.
  329|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  330|       |  // for recursive calls.
  331|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  332|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  333|       |  //
  334|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  335|       |
  336|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  337|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  338|       |  // themselves store the absolute value.
  339|    381|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  340|    381|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  341|       |
  342|       |  // Compute:
  343|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  344|       |  // r0,r1 = a0 * b0
  345|       |  // r2,r3 = a1 * b1
  346|    381|  if (n == 8) {
  ------------------
  |  Branch (346:7): [True: 0, False: 381]
  ------------------
  347|      0|    bn_mul_comba8(&t[n2], t, &t[n]);
  348|      0|    bn_mul_comba8(r, a, b);
  349|       |
  350|      0|    bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  351|       |    // |bn_mul_normal| only writes |tna| + |tna| words. Zero the rest.
  352|      0|    OPENSSL_memset(&r[n2 + tna + tnb], 0, sizeof(BN_ULONG) * (n2 - tna - tnb));
  353|    381|  } else {
  354|    381|    BN_ULONG *p = &t[n2 * 2];
  355|    381|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  356|    381|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  357|       |
  358|    381|    OPENSSL_memset(&r[n2], 0, sizeof(BN_ULONG) * n2);
  359|    381|    if (tna < BN_MUL_RECURSIVE_SIZE_NORMAL &&
  ------------------
  |  |   70|    762|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (359:9): [True: 381, False: 0]
  ------------------
  360|    381|        tnb < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|    381|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (360:9): [True: 381, False: 0]
  ------------------
  361|    381|      bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  362|    381|    } else {
  363|      0|      int i = n;
  364|      0|      for (;;) {
  365|      0|        i /= 2;
  366|      0|        if (i < tna || i < tnb) {
  ------------------
  |  Branch (366:13): [True: 0, False: 0]
  |  Branch (366:24): [True: 0, False: 0]
  ------------------
  367|       |          // E.g., n == 16, i == 8 and tna == 11. |tna| and |tnb| are within one
  368|       |          // of each other, so if |tna| is larger and tna > i, then we know
  369|       |          // tnb >= i, and this call is valid.
  370|      0|          bn_mul_part_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  371|      0|          break;
  372|      0|        }
  373|      0|        if (i == tna || i == tnb) {
  ------------------
  |  Branch (373:13): [True: 0, False: 0]
  |  Branch (373:25): [True: 0, False: 0]
  ------------------
  374|       |          // If there is only a bottom half to the number, just do it. We know
  375|       |          // the larger of |tna - i| and |tnb - i| is zero. The other is zero or
  376|       |          // -1 by because of |tna| and |tnb| differ by at most one.
  377|      0|          bn_mul_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  378|      0|          break;
  379|      0|        }
  380|       |
  381|       |        // This loop will eventually terminate when |i| falls below
  382|       |        // |BN_MUL_RECURSIVE_SIZE_NORMAL| because we know one of |tna| and |tnb|
  383|       |        // exceeds that.
  384|      0|      }
  385|      0|    }
  386|    381|  }
  387|       |
  388|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  389|    381|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  390|       |
  391|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  392|       |  // The second term is stored as the absolute value, so we do this with a
  393|       |  // constant-time select.
  394|    381|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  395|    381|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  396|    381|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  397|    381|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  398|    381|                "crypto_word_t is too small");
  399|    381|  c = constant_time_select_w(neg, c_neg, c_pos);
  400|       |
  401|       |  // We now have our three components. Add them together.
  402|       |  // r1,r2,c = r1,r2 + t2,t3,c
  403|    381|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  404|       |
  405|       |  // Propagate the carry bit to the end.
  406|  6.47k|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (406:24): [True: 6.09k, False: 381]
  ------------------
  407|  6.09k|    BN_ULONG old = r[i];
  408|  6.09k|    r[i] = old + c;
  409|  6.09k|    c = r[i] < old;
  410|  6.09k|  }
  411|       |
  412|       |  // The product should fit without carries.
  413|    381|  assert(c == 0);
  414|    381|}
bcm.c:bn_mul_recursive:
  211|    763|                             int n2, int dna, int dnb, BN_ULONG *t) {
  212|       |  // |n2| is a power of two.
  213|    763|  assert(n2 != 0 && (n2 & (n2 - 1)) == 0);
  214|       |  // Check |dna| and |dnb| are in range.
  215|    763|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dna && dna <= 0);
  216|    763|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dnb && dnb <= 0);
  217|       |
  218|       |  // Only call bn_mul_comba 8 if n2 == 8 and the
  219|       |  // two arrays are complete [steve]
  220|    763|  if (n2 == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (220:7): [True: 0, False: 763]
  |  Branch (220:18): [True: 0, False: 0]
  |  Branch (220:30): [True: 0, False: 0]
  ------------------
  221|      0|    bn_mul_comba8(r, a, b);
  222|      0|    return;
  223|      0|  }
  224|       |
  225|       |  // Else do normal multiply
  226|    763|  if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|    763|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (226:7): [True: 0, False: 763]
  ------------------
  227|      0|    bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
  228|      0|    if (dna + dnb < 0) {
  ------------------
  |  Branch (228:9): [True: 0, False: 0]
  ------------------
  229|      0|      OPENSSL_memset(&r[2 * n2 + dna + dnb], 0,
  230|      0|                     sizeof(BN_ULONG) * -(dna + dnb));
  231|      0|    }
  232|      0|    return;
  233|      0|  }
  234|       |
  235|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|.
  236|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  237|       |  // for recursive calls.
  238|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  239|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  240|       |  //
  241|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  242|       |  //
  243|       |  // Note that we know |n| >= |BN_MUL_RECURSIVE_SIZE_NORMAL|/2 above, so
  244|       |  // |tna| and |tnb| are non-negative.
  245|    763|  int n = n2 / 2, tna = n + dna, tnb = n + dnb;
  246|       |
  247|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  248|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  249|       |  // themselves store the absolute value.
  250|    763|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  251|    763|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  252|       |
  253|       |  // Compute:
  254|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  255|       |  // r0,r1 = a0 * b0
  256|       |  // r2,r3 = a1 * b1
  257|    763|  if (n == 4 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (257:7): [True: 0, False: 763]
  |  Branch (257:17): [True: 0, False: 0]
  |  Branch (257:29): [True: 0, False: 0]
  ------------------
  258|      0|    bn_mul_comba4(&t[n2], t, &t[n]);
  259|       |
  260|      0|    bn_mul_comba4(r, a, b);
  261|      0|    bn_mul_comba4(&r[n2], &a[n], &b[n]);
  262|    763|  } else if (n == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (262:14): [True: 763, False: 0]
  |  Branch (262:24): [True: 763, False: 0]
  |  Branch (262:36): [True: 763, False: 0]
  ------------------
  263|    763|    bn_mul_comba8(&t[n2], t, &t[n]);
  264|       |
  265|    763|    bn_mul_comba8(r, a, b);
  266|    763|    bn_mul_comba8(&r[n2], &a[n], &b[n]);
  267|    763|  } else {
  268|      0|    BN_ULONG *p = &t[n2 * 2];
  269|      0|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  270|      0|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  271|      0|    bn_mul_recursive(&r[n2], &a[n], &b[n], n, dna, dnb, p);
  272|      0|  }
  273|       |
  274|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  275|    763|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  276|       |
  277|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  278|       |  // The second term is stored as the absolute value, so we do this with a
  279|       |  // constant-time select.
  280|    763|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  281|    763|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  282|    763|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  283|    763|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  284|    763|                "crypto_word_t is too small");
  285|    763|  c = constant_time_select_w(neg, c_neg, c_pos);
  286|       |
  287|       |  // We now have our three components. Add them together.
  288|       |  // r1,r2,c = r1,r2 + t2,t3,c
  289|    763|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  290|       |
  291|       |  // Propagate the carry bit to the end.
  292|  6.86k|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (292:24): [True: 6.10k, False: 763]
  ------------------
  293|  6.10k|    BN_ULONG old = r[i];
  294|  6.10k|    r[i] = old + c;
  295|  6.10k|    c = r[i] < old;
  296|  6.10k|  }
  297|       |
  298|       |  // The product should fit without carries.
  299|    763|  assert(c == 0);
  300|    763|}
bcm.c:bn_mul_normal:
   82|    684|                          const BN_ULONG *b, size_t nb) {
   83|    684|  if (na < nb) {
  ------------------
  |  Branch (83:7): [True: 153, False: 531]
  ------------------
   84|    153|    size_t itmp = na;
   85|    153|    na = nb;
   86|    153|    nb = itmp;
   87|    153|    const BN_ULONG *ltmp = a;
   88|    153|    a = b;
   89|    153|    b = ltmp;
   90|    153|  }
   91|    684|  BN_ULONG *rr = &(r[na]);
   92|    684|  if (nb == 0) {
  ------------------
  |  Branch (92:7): [True: 153, False: 531]
  ------------------
   93|    153|    OPENSSL_memset(r, 0, na * sizeof(BN_ULONG));
   94|    153|    return;
   95|    153|  }
   96|    531|  rr[0] = bn_mul_words(r, a, na, b[0]);
   97|       |
   98|    538|  for (;;) {
   99|    538|    if (--nb == 0) {
  ------------------
  |  Branch (99:9): [True: 529, False: 9]
  ------------------
  100|    529|      return;
  101|    529|    }
  102|      9|    rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  103|      9|    if (--nb == 0) {
  ------------------
  |  Branch (103:9): [True: 1, False: 8]
  ------------------
  104|      1|      return;
  105|      1|    }
  106|      8|    rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  107|      8|    if (--nb == 0) {
  ------------------
  |  Branch (107:9): [True: 1, False: 7]
  ------------------
  108|      1|      return;
  109|      1|    }
  110|      7|    rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  111|      7|    if (--nb == 0) {
  ------------------
  |  Branch (111:9): [True: 0, False: 7]
  ------------------
  112|      0|      return;
  113|      0|    }
  114|      7|    rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  115|      7|    rr += 4;
  116|      7|    r += 4;
  117|      7|    b += 4;
  118|      7|  }
  119|    531|}

BN_lshift:
   67|     14|int BN_lshift(BIGNUM *r, const BIGNUM *a, int n) {
   68|     14|  int i, nw, lb, rb;
   69|     14|  BN_ULONG *t, *f;
   70|     14|  BN_ULONG l;
   71|       |
   72|     14|  if (n < 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 14]
  ------------------
   73|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   74|      0|    return 0;
   75|      0|  }
   76|       |
   77|     14|  r->neg = a->neg;
   78|     14|  nw = n / BN_BITS2;
  ------------------
  |  |  151|     14|#define BN_BITS2 64
  ------------------
   79|     14|  if (!bn_wexpand(r, a->width + nw + 1)) {
  ------------------
  |  Branch (79:7): [True: 0, False: 14]
  ------------------
   80|      0|    return 0;
   81|      0|  }
   82|     14|  lb = n % BN_BITS2;
  ------------------
  |  |  151|     14|#define BN_BITS2 64
  ------------------
   83|     14|  rb = BN_BITS2 - lb;
  ------------------
  |  |  151|     14|#define BN_BITS2 64
  ------------------
   84|     14|  f = a->d;
   85|     14|  t = r->d;
   86|     14|  t[a->width + nw] = 0;
   87|     14|  if (lb == 0) {
  ------------------
  |  Branch (87:7): [True: 8, False: 6]
  ------------------
   88|     72|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (88:28): [True: 64, False: 8]
  ------------------
   89|     64|      t[nw + i] = f[i];
   90|     64|    }
   91|      8|  } else {
   92|     75|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (92:28): [True: 69, False: 6]
  ------------------
   93|     69|      l = f[i];
   94|     69|      t[nw + i + 1] |= l >> rb;
   95|     69|      t[nw + i] = l << lb;
   96|     69|    }
   97|      6|  }
   98|     14|  OPENSSL_memset(t, 0, nw * sizeof(t[0]));
   99|     14|  r->width = a->width + nw + 1;
  100|     14|  bn_set_minimal_width(r);
  101|       |
  102|     14|  return 1;
  103|     14|}
bn_rshift_words:
  137|      7|                     size_t num) {
  138|      7|  unsigned shift_bits = shift % BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  139|      7|  size_t shift_words = shift / BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  140|      7|  if (shift_words >= num) {
  ------------------
  |  Branch (140:7): [True: 0, False: 7]
  ------------------
  141|      0|    OPENSSL_memset(r, 0, num * sizeof(BN_ULONG));
  142|      0|    return;
  143|      0|  }
  144|      7|  if (shift_bits == 0) {
  ------------------
  |  Branch (144:7): [True: 4, False: 3]
  ------------------
  145|      4|    OPENSSL_memmove(r, a + shift_words, (num - shift_words) * sizeof(BN_ULONG));
  146|      4|  } else {
  147|     16|    for (size_t i = shift_words; i < num - 1; i++) {
  ------------------
  |  Branch (147:34): [True: 13, False: 3]
  ------------------
  148|     13|      r[i - shift_words] =
  149|     13|          (a[i] >> shift_bits) | (a[i + 1] << (BN_BITS2 - shift_bits));
  ------------------
  |  |  151|     13|#define BN_BITS2 64
  ------------------
  150|     13|    }
  151|      3|    r[num - 1 - shift_words] = a[num - 1] >> shift_bits;
  152|      3|  }
  153|      7|  OPENSSL_memset(r + num - shift_words, 0, shift_words * sizeof(BN_ULONG));
  154|      7|}
BN_rshift:
  156|      7|int BN_rshift(BIGNUM *r, const BIGNUM *a, int n) {
  157|      7|  if (n < 0) {
  ------------------
  |  Branch (157:7): [True: 0, False: 7]
  ------------------
  158|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  159|      0|    return 0;
  160|      0|  }
  161|       |
  162|      7|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (162:7): [True: 0, False: 7]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|      7|  bn_rshift_words(r->d, a->d, n, a->width);
  166|      7|  r->neg = a->neg;
  167|      7|  r->width = a->width;
  168|      7|  bn_set_minimal_width(r);
  169|      7|  return 1;
  170|      7|}
BN_set_bit:
  221|      7|int BN_set_bit(BIGNUM *a, int n) {
  222|      7|  if (n < 0) {
  ------------------
  |  Branch (222:7): [True: 0, False: 7]
  ------------------
  223|      0|    return 0;
  224|      0|  }
  225|       |
  226|      7|  int i = n / BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  227|      7|  int j = n % BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  228|      7|  if (a->width <= i) {
  ------------------
  |  Branch (228:7): [True: 7, False: 0]
  ------------------
  229|      7|    if (!bn_wexpand(a, i + 1)) {
  ------------------
  |  Branch (229:9): [True: 0, False: 7]
  ------------------
  230|      0|      return 0;
  231|      0|    }
  232|     98|    for (int k = a->width; k < i + 1; k++) {
  ------------------
  |  Branch (232:28): [True: 91, False: 7]
  ------------------
  233|     91|      a->d[k] = 0;
  234|     91|    }
  235|      7|    a->width = i + 1;
  236|      7|  }
  237|       |
  238|      7|  a->d[i] |= (((BN_ULONG)1) << j);
  239|       |
  240|      7|  return 1;
  241|      7|}
bn_is_bit_set_words:
  261|   105k|int bn_is_bit_set_words(const BN_ULONG *a, size_t num, size_t bit) {
  262|   105k|  size_t i = bit / BN_BITS2;
  ------------------
  |  |  151|   105k|#define BN_BITS2 64
  ------------------
  263|   105k|  size_t j = bit % BN_BITS2;
  ------------------
  |  |  151|   105k|#define BN_BITS2 64
  ------------------
  264|   105k|  if (i >= num) {
  ------------------
  |  Branch (264:7): [True: 150, False: 105k]
  ------------------
  265|    150|    return 0;
  266|    150|  }
  267|   105k|  return (a[i] >> j) & 1;
  268|   105k|}

EVP_CIPHER_CTX_init:
   72|  1.43k|void EVP_CIPHER_CTX_init(EVP_CIPHER_CTX *ctx) {
   73|  1.43k|  OPENSSL_memset(ctx, 0, sizeof(EVP_CIPHER_CTX));
   74|  1.43k|}
EVP_CIPHER_CTX_cleanup:
   84|  1.43k|int EVP_CIPHER_CTX_cleanup(EVP_CIPHER_CTX *c) {
   85|  1.43k|  if (c->cipher != NULL && c->cipher->cleanup) {
  ------------------
  |  Branch (85:7): [True: 1.22k, False: 211]
  |  Branch (85:28): [True: 0, False: 1.22k]
  ------------------
   86|      0|    c->cipher->cleanup(c);
   87|      0|  }
   88|  1.43k|  OPENSSL_free(c->cipher_data);
   89|       |
   90|  1.43k|  OPENSSL_memset(c, 0, sizeof(EVP_CIPHER_CTX));
   91|  1.43k|  return 1;
   92|  1.43k|}
EVP_CipherInit_ex:
  142|  1.22k|                      int enc) {
  143|  1.22k|  if (enc == -1) {
  ------------------
  |  Branch (143:7): [True: 0, False: 1.22k]
  ------------------
  144|      0|    enc = ctx->encrypt;
  145|  1.22k|  } else {
  146|  1.22k|    if (enc) {
  ------------------
  |  Branch (146:9): [True: 0, False: 1.22k]
  ------------------
  147|      0|      enc = 1;
  148|      0|    }
  149|  1.22k|    ctx->encrypt = enc;
  150|  1.22k|  }
  151|       |
  152|  1.22k|  if (cipher) {
  ------------------
  |  Branch (152:7): [True: 1.22k, False: 0]
  ------------------
  153|       |    // Ensure a context left from last time is cleared (the previous check
  154|       |    // attempted to avoid this if the same ENGINE and EVP_CIPHER could be
  155|       |    // used).
  156|  1.22k|    if (ctx->cipher) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1.22k]
  ------------------
  157|      0|      EVP_CIPHER_CTX_cleanup(ctx);
  158|       |      // Restore encrypt and flags
  159|      0|      ctx->encrypt = enc;
  160|      0|    }
  161|       |
  162|  1.22k|    ctx->cipher = cipher;
  163|  1.22k|    if (ctx->cipher->ctx_size) {
  ------------------
  |  Branch (163:9): [True: 1.22k, False: 0]
  ------------------
  164|  1.22k|      ctx->cipher_data = OPENSSL_malloc(ctx->cipher->ctx_size);
  165|  1.22k|      if (!ctx->cipher_data) {
  ------------------
  |  Branch (165:11): [True: 0, False: 1.22k]
  ------------------
  166|      0|        ctx->cipher = NULL;
  167|      0|        return 0;
  168|      0|      }
  169|  1.22k|    } else {
  170|      0|      ctx->cipher_data = NULL;
  171|      0|    }
  172|       |
  173|  1.22k|    ctx->key_len = cipher->key_len;
  174|  1.22k|    ctx->flags = 0;
  175|       |
  176|  1.22k|    if (ctx->cipher->flags & EVP_CIPH_CTRL_INIT) {
  ------------------
  |  |  368|  1.22k|#define EVP_CIPH_CTRL_INIT 0x200
  ------------------
  |  Branch (176:9): [True: 703, False: 518]
  ------------------
  177|    703|      if (!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_INIT, 0, NULL)) {
  ------------------
  |  |  528|    703|#define EVP_CTRL_INIT 0x0
  ------------------
  |  Branch (177:11): [True: 0, False: 703]
  ------------------
  178|      0|        ctx->cipher = NULL;
  179|      0|        OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_INITIALIZATION_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  180|      0|        return 0;
  181|      0|      }
  182|    703|    }
  183|  1.22k|  } else if (!ctx->cipher) {
  ------------------
  |  Branch (183:14): [True: 0, False: 0]
  ------------------
  184|      0|    OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_NO_CIPHER_SET);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  185|      0|    return 0;
  186|      0|  }
  187|       |
  188|       |  // we assume block size is a power of 2 in *cryptUpdate
  189|  1.22k|  assert(ctx->cipher->block_size == 1 || ctx->cipher->block_size == 8 ||
  190|  1.22k|         ctx->cipher->block_size == 16);
  191|       |
  192|  1.22k|  if (!(EVP_CIPHER_CTX_flags(ctx) & EVP_CIPH_CUSTOM_IV)) {
  ------------------
  |  |  364|  1.22k|#define EVP_CIPH_CUSTOM_IV 0x100
  ------------------
  |  Branch (192:7): [True: 1.22k, False: 0]
  ------------------
  193|  1.22k|    switch (EVP_CIPHER_CTX_mode(ctx)) {
  194|      9|      case EVP_CIPH_STREAM_CIPHER:
  ------------------
  |  |  335|      9|#define EVP_CIPH_STREAM_CIPHER 0x0
  ------------------
  |  Branch (194:7): [True: 9, False: 1.21k]
  ------------------
  195|      9|      case EVP_CIPH_ECB_MODE:
  ------------------
  |  |  336|      9|#define EVP_CIPH_ECB_MODE 0x1
  ------------------
  |  Branch (195:7): [True: 0, False: 1.22k]
  ------------------
  196|      9|        break;
  197|       |
  198|      0|      case EVP_CIPH_CFB_MODE:
  ------------------
  |  |  338|      0|#define EVP_CIPH_CFB_MODE 0x3
  ------------------
  |  Branch (198:7): [True: 0, False: 1.22k]
  ------------------
  199|      0|        ctx->num = 0;
  200|      0|        OPENSSL_FALLTHROUGH;
  ------------------
  |  |  238|      0|#define OPENSSL_FALLTHROUGH __attribute__ ((fallthrough))
  ------------------
  201|       |
  202|  1.21k|      case EVP_CIPH_CBC_MODE:
  ------------------
  |  |  337|  1.21k|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (202:7): [True: 1.21k, False: 9]
  ------------------
  203|  1.21k|        assert(EVP_CIPHER_CTX_iv_length(ctx) <= sizeof(ctx->iv));
  204|  1.21k|        if (iv) {
  ------------------
  |  Branch (204:13): [True: 1.21k, False: 0]
  ------------------
  205|  1.21k|          OPENSSL_memcpy(ctx->oiv, iv, EVP_CIPHER_CTX_iv_length(ctx));
  206|  1.21k|        }
  207|  1.21k|        OPENSSL_memcpy(ctx->iv, ctx->oiv, EVP_CIPHER_CTX_iv_length(ctx));
  208|  1.21k|        break;
  209|       |
  210|      0|      case EVP_CIPH_CTR_MODE:
  ------------------
  |  |  340|      0|#define EVP_CIPH_CTR_MODE 0x5
  ------------------
  |  Branch (210:7): [True: 0, False: 1.22k]
  ------------------
  211|      0|      case EVP_CIPH_OFB_MODE:
  ------------------
  |  |  339|      0|#define EVP_CIPH_OFB_MODE 0x4
  ------------------
  |  Branch (211:7): [True: 0, False: 1.22k]
  ------------------
  212|      0|        ctx->num = 0;
  213|       |        // Don't reuse IV for CTR mode
  214|      0|        if (iv) {
  ------------------
  |  Branch (214:13): [True: 0, False: 0]
  ------------------
  215|      0|          OPENSSL_memcpy(ctx->iv, iv, EVP_CIPHER_CTX_iv_length(ctx));
  216|      0|        }
  217|      0|        break;
  218|       |
  219|      0|      default:
  ------------------
  |  Branch (219:7): [True: 0, False: 1.22k]
  ------------------
  220|      0|        return 0;
  221|  1.22k|    }
  222|  1.22k|  }
  223|       |
  224|  1.22k|  if (key || (ctx->cipher->flags & EVP_CIPH_ALWAYS_CALL_INIT)) {
  ------------------
  |  |  360|      0|#define EVP_CIPH_ALWAYS_CALL_INIT 0x80
  ------------------
  |  Branch (224:7): [True: 1.22k, False: 0]
  |  Branch (224:14): [True: 0, False: 0]
  ------------------
  225|  1.22k|    if (!ctx->cipher->init(ctx, key, iv, enc)) {
  ------------------
  |  Branch (225:9): [True: 0, False: 1.22k]
  ------------------
  226|      0|      return 0;
  227|      0|    }
  228|  1.22k|  }
  229|       |
  230|  1.22k|  ctx->buf_len = 0;
  231|  1.22k|  ctx->final_used = 0;
  232|       |  // Clear the poisoned flag to permit re-use of a CTX that previously had a
  233|       |  // failed operation.
  234|  1.22k|  ctx->poisoned = 0;
  235|  1.22k|  return 1;
  236|  1.22k|}
EVP_EncryptUpdate:
  258|  1.22k|                      const uint8_t *in, int in_len) {
  259|  1.22k|  if (ctx->poisoned) {
  ------------------
  |  Branch (259:7): [True: 0, False: 1.22k]
  ------------------
  260|      0|    OPENSSL_PUT_ERROR(CIPHER, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  261|      0|    return 0;
  262|      0|  }
  263|       |  // If the first call to |cipher| succeeds and the second fails, |ctx| may be
  264|       |  // left in an indeterminate state. We set a poison flag on failure to ensure
  265|       |  // callers do not continue to use the object in that case.
  266|  1.22k|  ctx->poisoned = 1;
  267|       |
  268|       |  // Ciphers that use blocks may write up to |bl| extra bytes. Ensure the output
  269|       |  // does not overflow |*out_len|.
  270|  1.22k|  int bl = ctx->cipher->block_size;
  271|  1.22k|  if (bl > 1 && in_len > INT_MAX - bl) {
  ------------------
  |  Branch (271:7): [True: 1.21k, False: 9]
  |  Branch (271:17): [True: 0, False: 1.21k]
  ------------------
  272|      0|    OPENSSL_PUT_ERROR(CIPHER, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  273|      0|    return 0;
  274|      0|  }
  275|       |
  276|  1.22k|  if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
  ------------------
  |  |  372|  1.22k|#define EVP_CIPH_FLAG_CUSTOM_CIPHER 0x400
  ------------------
  |  Branch (276:7): [True: 0, False: 1.22k]
  ------------------
  277|      0|    int ret = ctx->cipher->cipher(ctx, out, in, in_len);
  278|      0|    if (ret < 0) {
  ------------------
  |  Branch (278:9): [True: 0, False: 0]
  ------------------
  279|      0|      return 0;
  280|      0|    } else {
  281|      0|      *out_len = ret;
  282|      0|    }
  283|      0|    ctx->poisoned = 0;
  284|      0|    return 1;
  285|      0|  }
  286|       |
  287|  1.22k|  if (in_len <= 0) {
  ------------------
  |  Branch (287:7): [True: 0, False: 1.22k]
  ------------------
  288|      0|    *out_len = 0;
  289|      0|    if (in_len == 0) {
  ------------------
  |  Branch (289:9): [True: 0, False: 0]
  ------------------
  290|      0|      ctx->poisoned = 0;
  291|      0|      return 1;
  292|      0|    }
  293|      0|    return 0;
  294|      0|  }
  295|       |
  296|  1.22k|  if (ctx->buf_len == 0 && block_remainder(ctx, in_len) == 0) {
  ------------------
  |  Branch (296:7): [True: 1.22k, False: 0]
  |  Branch (296:28): [True: 1.19k, False: 23]
  ------------------
  297|  1.19k|    if (ctx->cipher->cipher(ctx, out, in, in_len)) {
  ------------------
  |  Branch (297:9): [True: 1.19k, False: 0]
  ------------------
  298|  1.19k|      *out_len = in_len;
  299|  1.19k|      ctx->poisoned = 0;
  300|  1.19k|      return 1;
  301|  1.19k|    } else {
  302|      0|      *out_len = 0;
  303|      0|      return 0;
  304|      0|    }
  305|  1.19k|  }
  306|       |
  307|     23|  int i = ctx->buf_len;
  308|     23|  assert(bl <= (int)sizeof(ctx->buf));
  309|     23|  if (i != 0) {
  ------------------
  |  Branch (309:7): [True: 0, False: 23]
  ------------------
  310|      0|    if (bl - i > in_len) {
  ------------------
  |  Branch (310:9): [True: 0, False: 0]
  ------------------
  311|      0|      OPENSSL_memcpy(&ctx->buf[i], in, in_len);
  312|      0|      ctx->buf_len += in_len;
  313|      0|      *out_len = 0;
  314|      0|      ctx->poisoned = 0;
  315|      0|      return 1;
  316|      0|    } else {
  317|      0|      int j = bl - i;
  318|      0|      OPENSSL_memcpy(&ctx->buf[i], in, j);
  319|      0|      if (!ctx->cipher->cipher(ctx, out, ctx->buf, bl)) {
  ------------------
  |  Branch (319:11): [True: 0, False: 0]
  ------------------
  320|      0|        return 0;
  321|      0|      }
  322|      0|      in_len -= j;
  323|      0|      in += j;
  324|      0|      out += bl;
  325|      0|      *out_len = bl;
  326|      0|    }
  327|     23|  } else {
  328|     23|    *out_len = 0;
  329|     23|  }
  330|       |
  331|     23|  i = block_remainder(ctx, in_len);
  332|     23|  in_len -= i;
  333|     23|  if (in_len > 0) {
  ------------------
  |  Branch (333:7): [True: 22, False: 1]
  ------------------
  334|     22|    if (!ctx->cipher->cipher(ctx, out, in, in_len)) {
  ------------------
  |  Branch (334:9): [True: 0, False: 22]
  ------------------
  335|      0|      return 0;
  336|      0|    }
  337|     22|    *out_len += in_len;
  338|     22|  }
  339|       |
  340|     23|  if (i != 0) {
  ------------------
  |  Branch (340:7): [True: 23, False: 0]
  ------------------
  341|     23|    OPENSSL_memcpy(ctx->buf, &in[in_len], i);
  342|     23|  }
  343|     23|  ctx->buf_len = i;
  344|     23|  ctx->poisoned = 0;
  345|     23|  return 1;
  346|     23|}
EVP_DecryptUpdate:
  401|  1.22k|                      const uint8_t *in, int in_len) {
  402|  1.22k|  if (ctx->poisoned) {
  ------------------
  |  Branch (402:7): [True: 0, False: 1.22k]
  ------------------
  403|      0|    OPENSSL_PUT_ERROR(CIPHER, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  404|      0|    return 0;
  405|      0|  }
  406|       |
  407|       |  // Ciphers that use blocks may write up to |bl| extra bytes. Ensure the output
  408|       |  // does not overflow |*out_len|.
  409|  1.22k|  unsigned int b = ctx->cipher->block_size;
  410|  1.22k|  if (b > 1 && in_len > INT_MAX - (int)b) {
  ------------------
  |  Branch (410:7): [True: 1.21k, False: 9]
  |  Branch (410:16): [True: 0, False: 1.21k]
  ------------------
  411|      0|    OPENSSL_PUT_ERROR(CIPHER, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  412|      0|    return 0;
  413|      0|  }
  414|       |
  415|  1.22k|  if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
  ------------------
  |  |  372|  1.22k|#define EVP_CIPH_FLAG_CUSTOM_CIPHER 0x400
  ------------------
  |  Branch (415:7): [True: 0, False: 1.22k]
  ------------------
  416|      0|    int r = ctx->cipher->cipher(ctx, out, in, in_len);
  417|      0|    if (r < 0) {
  ------------------
  |  Branch (417:9): [True: 0, False: 0]
  ------------------
  418|      0|      *out_len = 0;
  419|      0|      return 0;
  420|      0|    } else {
  421|      0|      *out_len = r;
  422|      0|    }
  423|      0|    return 1;
  424|      0|  }
  425|       |
  426|  1.22k|  if (in_len <= 0) {
  ------------------
  |  Branch (426:7): [True: 1, False: 1.22k]
  ------------------
  427|      1|    *out_len = 0;
  428|      1|    return in_len == 0;
  429|      1|  }
  430|       |
  431|  1.22k|  if (ctx->flags & EVP_CIPH_NO_PADDING) {
  ------------------
  |  |  525|  1.22k|#define EVP_CIPH_NO_PADDING 0x800
  ------------------
  |  Branch (431:7): [True: 0, False: 1.22k]
  ------------------
  432|      0|    return EVP_EncryptUpdate(ctx, out, out_len, in, in_len);
  433|      0|  }
  434|       |
  435|  1.22k|  assert(b <= sizeof(ctx->final));
  436|  1.22k|  int fix_len = 0;
  437|  1.22k|  if (ctx->final_used) {
  ------------------
  |  Branch (437:7): [True: 0, False: 1.22k]
  ------------------
  438|      0|    OPENSSL_memcpy(out, ctx->final, b);
  439|      0|    out += b;
  440|      0|    fix_len = 1;
  441|      0|  }
  442|       |
  443|  1.22k|  if (!EVP_EncryptUpdate(ctx, out, out_len, in, in_len)) {
  ------------------
  |  Branch (443:7): [True: 0, False: 1.22k]
  ------------------
  444|      0|    return 0;
  445|      0|  }
  446|       |
  447|       |  // if we have 'decrypted' a multiple of block size, make sure
  448|       |  // we have a copy of this last block
  449|  1.22k|  if (b > 1 && !ctx->buf_len) {
  ------------------
  |  Branch (449:7): [True: 1.21k, False: 9]
  |  Branch (449:16): [True: 1.18k, False: 23]
  ------------------
  450|  1.18k|    *out_len -= b;
  451|  1.18k|    ctx->final_used = 1;
  452|  1.18k|    OPENSSL_memcpy(ctx->final, &out[*out_len], b);
  453|  1.18k|  } else {
  454|     32|    ctx->final_used = 0;
  455|     32|  }
  456|       |
  457|  1.22k|  if (fix_len) {
  ------------------
  |  Branch (457:7): [True: 0, False: 1.22k]
  ------------------
  458|      0|    *out_len += b;
  459|      0|  }
  460|       |
  461|  1.22k|  return 1;
  462|  1.22k|}
EVP_DecryptFinal_ex:
  464|  1.22k|int EVP_DecryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *out_len) {
  465|  1.22k|  int i, n;
  466|  1.22k|  unsigned int b;
  467|  1.22k|  *out_len = 0;
  468|       |
  469|  1.22k|  if (ctx->poisoned) {
  ------------------
  |  Branch (469:7): [True: 0, False: 1.22k]
  ------------------
  470|      0|    OPENSSL_PUT_ERROR(CIPHER, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  471|      0|    return 0;
  472|      0|  }
  473|       |
  474|  1.22k|  if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
  ------------------
  |  |  372|  1.22k|#define EVP_CIPH_FLAG_CUSTOM_CIPHER 0x400
  ------------------
  |  Branch (474:7): [True: 0, False: 1.22k]
  ------------------
  475|      0|    i = ctx->cipher->cipher(ctx, out, NULL, 0);
  476|      0|    if (i < 0) {
  ------------------
  |  Branch (476:9): [True: 0, False: 0]
  ------------------
  477|      0|      return 0;
  478|      0|    } else {
  479|      0|      *out_len = i;
  480|      0|    }
  481|      0|    goto out;
  482|      0|  }
  483|       |
  484|  1.22k|  b = ctx->cipher->block_size;
  485|  1.22k|  if (ctx->flags & EVP_CIPH_NO_PADDING) {
  ------------------
  |  |  525|  1.22k|#define EVP_CIPH_NO_PADDING 0x800
  ------------------
  |  Branch (485:7): [True: 0, False: 1.22k]
  ------------------
  486|      0|    if (ctx->buf_len) {
  ------------------
  |  Branch (486:9): [True: 0, False: 0]
  ------------------
  487|      0|      OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  488|      0|      return 0;
  489|      0|    }
  490|      0|    *out_len = 0;
  491|      0|    goto out;
  492|      0|  }
  493|       |
  494|  1.22k|  if (b > 1) {
  ------------------
  |  Branch (494:7): [True: 1.21k, False: 9]
  ------------------
  495|  1.21k|    if (ctx->buf_len || !ctx->final_used) {
  ------------------
  |  Branch (495:9): [True: 23, False: 1.18k]
  |  Branch (495:25): [True: 1, False: 1.18k]
  ------------------
  496|     24|      OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_WRONG_FINAL_BLOCK_LENGTH);
  ------------------
  |  |  441|     24|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  497|     24|      return 0;
  498|     24|    }
  499|  1.18k|    assert(b <= sizeof(ctx->final));
  500|       |
  501|       |    // The following assumes that the ciphertext has been authenticated.
  502|       |    // Otherwise it provides a padding oracle.
  503|  1.18k|    n = ctx->final[b - 1];
  504|  1.18k|    if (n == 0 || n > (int)b) {
  ------------------
  |  Branch (504:9): [True: 1, False: 1.18k]
  |  Branch (504:19): [True: 40, False: 1.14k]
  ------------------
  505|     41|      OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_BAD_DECRYPT);
  ------------------
  |  |  441|     41|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  506|     41|      return 0;
  507|     41|    }
  508|       |
  509|  8.16k|    for (i = 0; i < n; i++) {
  ------------------
  |  Branch (509:17): [True: 7.02k, False: 1.14k]
  ------------------
  510|  7.02k|      if (ctx->final[--b] != n) {
  ------------------
  |  Branch (510:11): [True: 7, False: 7.01k]
  ------------------
  511|      7|        OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_BAD_DECRYPT);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  512|      7|        return 0;
  513|      7|      }
  514|  7.02k|    }
  515|       |
  516|  1.14k|    n = ctx->cipher->block_size - n;
  517|  3.50k|    for (i = 0; i < n; i++) {
  ------------------
  |  Branch (517:17): [True: 2.36k, False: 1.14k]
  ------------------
  518|  2.36k|      out[i] = ctx->final[i];
  519|  2.36k|    }
  520|  1.14k|    *out_len = n;
  521|  1.14k|  } else {
  522|      9|    *out_len = 0;
  523|      9|  }
  524|       |
  525|  1.14k|out:
  526|  1.14k|  EVP_Cipher_verify_service_indicator(ctx);
  527|  1.14k|  return 1;
  528|  1.22k|}
EVP_CIPHER_CTX_key_length:
  584|  1.41k|unsigned EVP_CIPHER_CTX_key_length(const EVP_CIPHER_CTX *ctx) {
  585|  1.41k|  return ctx->key_len;
  586|  1.41k|}
EVP_CIPHER_CTX_iv_length:
  588|  3.63k|unsigned EVP_CIPHER_CTX_iv_length(const EVP_CIPHER_CTX *ctx) {
  589|  3.63k|  return ctx->cipher->iv_len;
  590|  3.63k|}
EVP_CIPHER_CTX_flags:
  600|  1.22k|uint32_t EVP_CIPHER_CTX_flags(const EVP_CIPHER_CTX *ctx) {
  601|  1.22k|  return ctx->cipher->flags & ~EVP_CIPH_MODE_MASK;
  ------------------
  |  |   74|  1.22k|#define EVP_CIPH_MODE_MASK 0x3f
  ------------------
  602|  1.22k|}
EVP_CIPHER_CTX_mode:
  604|  1.22k|uint32_t EVP_CIPHER_CTX_mode(const EVP_CIPHER_CTX *ctx) {
  605|  1.22k|  return ctx->cipher->flags & EVP_CIPH_MODE_MASK;
  ------------------
  |  |   74|  1.22k|#define EVP_CIPH_MODE_MASK 0x3f
  ------------------
  606|  1.22k|}
EVP_CIPHER_CTX_ctrl:
  608|    703|int EVP_CIPHER_CTX_ctrl(EVP_CIPHER_CTX *ctx, int command, int arg, void *ptr) {
  609|    703|  int ret;
  610|    703|  if (!ctx->cipher) {
  ------------------
  |  Branch (610:7): [True: 0, False: 703]
  ------------------
  611|      0|    OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_NO_CIPHER_SET);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  612|      0|    return 0;
  613|      0|  }
  614|       |
  615|    703|  if (!ctx->cipher->ctrl) {
  ------------------
  |  Branch (615:7): [True: 0, False: 703]
  ------------------
  616|      0|    OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_CTRL_NOT_IMPLEMENTED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  617|      0|    return 0;
  618|      0|  }
  619|       |
  620|    703|  ret = ctx->cipher->ctrl(ctx, command, arg, ptr);
  621|    703|  if (ret == -1) {
  ------------------
  |  Branch (621:7): [True: 0, False: 703]
  ------------------
  622|      0|    OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_CTRL_OPERATION_NOT_IMPLEMENTED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  623|      0|    return 0;
  624|      0|  }
  625|       |
  626|    703|  return ret;
  627|    703|}
EVP_CIPHER_key_length:
  658|  1.30k|unsigned EVP_CIPHER_key_length(const EVP_CIPHER *cipher) {
  659|  1.30k|  return cipher->key_len;
  660|  1.30k|}
EVP_CIPHER_iv_length:
  662|  1.22k|unsigned EVP_CIPHER_iv_length(const EVP_CIPHER *cipher) {
  663|  1.22k|  return cipher->iv_len;
  664|  1.22k|}
bcm.c:block_remainder:
  250|  1.24k|static int block_remainder(const EVP_CIPHER_CTX *ctx, int len) {
  251|       |  // |block_size| must be a power of two.
  252|  1.24k|  assert(ctx->cipher->block_size != 0);
  253|  1.24k|  assert((ctx->cipher->block_size & (ctx->cipher->block_size - 1)) == 0);
  254|  1.24k|  return len & (ctx->cipher->block_size - 1);
  255|  1.24k|}

bcm.c:EVP_aes_128_cbc_do_init:
  611|      1|DEFINE_METHOD_FUNCTION(EVP_CIPHER, EVP_aes_128_cbc) {
  612|      1|  memset(out, 0, sizeof(EVP_CIPHER));
  613|       |
  614|      1|  out->nid = NID_aes_128_cbc;
  ------------------
  |  | 1933|      1|#define NID_aes_128_cbc 419
  ------------------
  615|      1|  out->block_size = 16;
  616|      1|  out->key_len = 16;
  617|      1|  out->iv_len = 16;
  618|      1|  out->ctx_size = sizeof(EVP_AES_KEY);
  619|      1|  out->flags = EVP_CIPH_CBC_MODE;
  ------------------
  |  |  337|      1|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  620|      1|  out->init = aes_init_key;
  621|      1|  out->cipher = aes_cbc_cipher;
  622|      1|}
bcm.c:aes_init_key:
  141|     43|                        const uint8_t *iv, int enc) {
  142|     43|  int ret;
  143|     43|  EVP_AES_KEY *dat = (EVP_AES_KEY *)ctx->cipher_data;
  144|     43|  const int mode = ctx->cipher->flags & EVP_CIPH_MODE_MASK;
  ------------------
  |  |   74|     43|#define EVP_CIPH_MODE_MASK 0x3f
  ------------------
  145|       |
  146|     43|  if (mode == EVP_CIPH_CTR_MODE) {
  ------------------
  |  |  340|     43|#define EVP_CIPH_CTR_MODE 0x5
  ------------------
  |  Branch (146:7): [True: 0, False: 43]
  ------------------
  147|      0|    switch (ctx->key_len) {
  ------------------
  |  Branch (147:13): [True: 0, False: 0]
  ------------------
  148|      0|      case 16:
  ------------------
  |  Branch (148:7): [True: 0, False: 0]
  ------------------
  149|      0|        boringssl_fips_inc_counter(fips_counter_evp_aes_128_ctr);
  150|      0|        break;
  151|       |
  152|      0|      case 32:
  ------------------
  |  Branch (152:7): [True: 0, False: 0]
  ------------------
  153|      0|        boringssl_fips_inc_counter(fips_counter_evp_aes_256_ctr);
  154|      0|        break;
  155|      0|    }
  156|      0|  }
  157|       |
  158|     43|  if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE) && !enc) {
  ------------------
  |  |  336|     86|#define EVP_CIPH_ECB_MODE 0x1
  ------------------
                if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE) && !enc) {
  ------------------
  |  |  337|     43|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (158:8): [True: 0, False: 43]
  |  Branch (158:37): [True: 43, False: 0]
  |  Branch (158:67): [True: 43, False: 0]
  ------------------
  159|     43|    if (hwaes_capable()) {
  ------------------
  |  Branch (159:9): [True: 43, False: 0]
  ------------------
  160|     43|      ret = aes_hw_set_decrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  161|     43|      dat->block = aes_hw_decrypt;
  162|     43|      dat->stream.cbc = NULL;
  163|     43|      if (mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|     43|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (163:11): [True: 43, False: 0]
  ------------------
  164|     43|        dat->stream.cbc = aes_hw_cbc_encrypt;
  165|     43|      }
  166|     43|    } else if (bsaes_capable() && mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|      0|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (166:16): [True: 0, False: 0]
  |  Branch (166:35): [True: 0, False: 0]
  ------------------
  167|      0|      assert(vpaes_capable());
  168|      0|      ret = vpaes_set_decrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  169|      0|      if (ret == 0) {
  ------------------
  |  Branch (169:11): [True: 0, False: 0]
  ------------------
  170|      0|        vpaes_decrypt_key_to_bsaes(&dat->ks.ks, &dat->ks.ks);
  171|      0|      }
  172|       |      // If |dat->stream.cbc| is provided, |dat->block| is never used.
  173|      0|      dat->block = NULL;
  174|      0|      dat->stream.cbc = bsaes_cbc_encrypt;
  175|      0|    } else if (vpaes_capable()) {
  ------------------
  |  Branch (175:16): [True: 0, False: 0]
  ------------------
  176|      0|      ret = vpaes_set_decrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  177|      0|      dat->block = vpaes_decrypt;
  178|      0|      dat->stream.cbc = NULL;
  179|      0|#if defined(VPAES_CBC)
  180|      0|      if (mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|      0|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (180:11): [True: 0, False: 0]
  ------------------
  181|      0|        dat->stream.cbc = vpaes_cbc_encrypt;
  182|      0|      }
  183|      0|#endif
  184|      0|    } else {
  185|      0|      ret = aes_nohw_set_decrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  186|      0|      dat->block = aes_nohw_decrypt;
  187|      0|      dat->stream.cbc = NULL;
  188|      0|      if (mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|      0|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (188:11): [True: 0, False: 0]
  ------------------
  189|      0|        dat->stream.cbc = aes_nohw_cbc_encrypt;
  190|      0|      }
  191|      0|    }
  192|     43|  } else if (hwaes_capable()) {
  ------------------
  |  Branch (192:14): [True: 0, False: 0]
  ------------------
  193|      0|    ret = aes_hw_set_encrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  194|      0|    dat->block = aes_hw_encrypt;
  195|      0|    dat->stream.cbc = NULL;
  196|      0|    if (mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|      0|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (196:9): [True: 0, False: 0]
  ------------------
  197|      0|      dat->stream.cbc = aes_hw_cbc_encrypt;
  198|      0|    } else if (mode == EVP_CIPH_CTR_MODE) {
  ------------------
  |  |  340|      0|#define EVP_CIPH_CTR_MODE 0x5
  ------------------
  |  Branch (198:16): [True: 0, False: 0]
  ------------------
  199|      0|      dat->stream.ctr = aes_hw_ctr32_encrypt_blocks;
  200|      0|    }
  201|      0|  } else if (vpaes_capable()) {
  ------------------
  |  Branch (201:14): [True: 0, False: 0]
  ------------------
  202|      0|    ret = vpaes_set_encrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  203|      0|    dat->block = vpaes_encrypt;
  204|      0|    dat->stream.cbc = NULL;
  205|      0|#if defined(VPAES_CBC)
  206|      0|    if (mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|      0|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (206:9): [True: 0, False: 0]
  ------------------
  207|      0|      dat->stream.cbc = vpaes_cbc_encrypt;
  208|      0|    }
  209|      0|#endif
  210|      0|    if (mode == EVP_CIPH_CTR_MODE) {
  ------------------
  |  |  340|      0|#define EVP_CIPH_CTR_MODE 0x5
  ------------------
  |  Branch (210:9): [True: 0, False: 0]
  ------------------
  211|       |#if defined(BSAES)
  212|       |      assert(bsaes_capable());
  213|       |      dat->stream.ctr = vpaes_ctr32_encrypt_blocks_with_bsaes;
  214|       |#elif defined(VPAES_CTR32)
  215|      0|      dat->stream.ctr = vpaes_ctr32_encrypt_blocks;
  216|      0|#endif
  217|      0|    }
  218|      0|  } else {
  219|      0|    ret = aes_nohw_set_encrypt_key(key, ctx->key_len * 8, &dat->ks.ks);
  220|      0|    dat->block = aes_nohw_encrypt;
  221|      0|    dat->stream.cbc = NULL;
  222|      0|    if (mode == EVP_CIPH_CBC_MODE) {
  ------------------
  |  |  337|      0|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  |  Branch (222:9): [True: 0, False: 0]
  ------------------
  223|      0|      dat->stream.cbc = aes_nohw_cbc_encrypt;
  224|      0|    }
  225|      0|  }
  226|       |
  227|     43|  if (ret < 0) {
  ------------------
  |  Branch (227:7): [True: 0, False: 43]
  ------------------
  228|      0|    OPENSSL_PUT_ERROR(CIPHER, CIPHER_R_AES_KEY_SETUP_FAILED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  229|      0|    return 0;
  230|      0|  }
  231|       |
  232|     43|  return 1;
  233|     43|}
bcm.c:aes_cbc_cipher:
  236|     43|                          size_t len) {
  237|     43|  EVP_AES_KEY *dat = (EVP_AES_KEY *)ctx->cipher_data;
  238|       |
  239|     43|  if (dat->stream.cbc) {
  ------------------
  |  Branch (239:7): [True: 43, False: 0]
  ------------------
  240|     43|    (*dat->stream.cbc)(in, out, len, &dat->ks.ks, ctx->iv, ctx->encrypt);
  241|     43|  } else if (ctx->encrypt) {
  ------------------
  |  Branch (241:14): [True: 0, False: 0]
  ------------------
  242|      0|    CRYPTO_cbc128_encrypt(in, out, len, &dat->ks.ks, ctx->iv, dat->block);
  243|      0|  } else {
  244|      0|    CRYPTO_cbc128_decrypt(in, out, len, &dat->ks.ks, ctx->iv, dat->block);
  245|      0|  }
  246|       |
  247|     43|  return 1;
  248|     43|}
bcm.c:EVP_aes_192_cbc_do_init:
  679|      1|DEFINE_METHOD_FUNCTION(EVP_CIPHER, EVP_aes_192_cbc) {
  680|      1|  memset(out, 0, sizeof(EVP_CIPHER));
  681|       |
  682|      1|  out->nid = NID_aes_192_cbc;
  ------------------
  |  | 1953|      1|#define NID_aes_192_cbc 423
  ------------------
  683|      1|  out->block_size = 16;
  684|      1|  out->key_len = 24;
  685|      1|  out->iv_len = 16;
  686|      1|  out->ctx_size = sizeof(EVP_AES_KEY);
  687|      1|  out->flags = EVP_CIPH_CBC_MODE;
  ------------------
  |  |  337|      1|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  688|      1|  out->init = aes_init_key;
  689|      1|  out->cipher = aes_cbc_cipher;
  690|      1|}
bcm.c:EVP_aes_256_cbc_do_init:
  747|      1|DEFINE_METHOD_FUNCTION(EVP_CIPHER, EVP_aes_256_cbc) {
  748|      1|  memset(out, 0, sizeof(EVP_CIPHER));
  749|       |
  750|      1|  out->nid = NID_aes_256_cbc;
  ------------------
  |  | 1973|      1|#define NID_aes_256_cbc 427
  ------------------
  751|      1|  out->block_size = 16;
  752|      1|  out->key_len = 32;
  753|      1|  out->iv_len = 16;
  754|      1|  out->ctx_size = sizeof(EVP_AES_KEY);
  755|      1|  out->flags = EVP_CIPH_CBC_MODE;
  ------------------
  |  |  337|      1|#define EVP_CIPH_CBC_MODE 0x2
  ------------------
  756|      1|  out->init = aes_init_key;
  757|      1|  out->cipher = aes_cbc_cipher;
  758|      1|}

BN_value_one:
   56|    328|  accessor_decorations type *name(void) {                                     \
   57|    328|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    328|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    328|     * cast is needed. */                                                     \
   60|    328|    return (const type *)name##_storage_bss_get();                            \
   61|    328|  }                                                                           \
EVP_aes_128_cbc:
   56|     34|  accessor_decorations type *name(void) {                                     \
   57|     34|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|     34|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|     34|     * cast is needed. */                                                     \
   60|     34|    return (const type *)name##_storage_bss_get();                            \
   61|     34|  }                                                                           \
EVP_aes_192_cbc:
   56|      6|  accessor_decorations type *name(void) {                                     \
   57|      6|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      6|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      6|     * cast is needed. */                                                     \
   60|      6|    return (const type *)name##_storage_bss_get();                            \
   61|      6|  }                                                                           \
EVP_aes_256_cbc:
   56|      4|  accessor_decorations type *name(void) {                                     \
   57|      4|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      4|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      4|     * cast is needed. */                                                     \
   60|      4|    return (const type *)name##_storage_bss_get();                            \
   61|      4|  }                                                                           \
EVP_md4:
   56|  1.97k|  accessor_decorations type *name(void) {                                     \
   57|  1.97k|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|  1.97k|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|  1.97k|     * cast is needed. */                                                     \
   60|  1.97k|    return (const type *)name##_storage_bss_get();                            \
   61|  1.97k|  }                                                                           \
EVP_md5:
   56|    420|  accessor_decorations type *name(void) {                                     \
   57|    420|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    420|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    420|     * cast is needed. */                                                     \
   60|    420|    return (const type *)name##_storage_bss_get();                            \
   61|    420|  }                                                                           \
EVP_sha1:
   56|  1.59k|  accessor_decorations type *name(void) {                                     \
   57|  1.59k|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|  1.59k|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|  1.59k|     * cast is needed. */                                                     \
   60|  1.59k|    return (const type *)name##_storage_bss_get();                            \
   61|  1.59k|  }                                                                           \
EVP_sha224:
   56|     64|  accessor_decorations type *name(void) {                                     \
   57|     64|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|     64|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|     64|     * cast is needed. */                                                     \
   60|     64|    return (const type *)name##_storage_bss_get();                            \
   61|     64|  }                                                                           \
EVP_sha256:
   56|    117|  accessor_decorations type *name(void) {                                     \
   57|    117|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    117|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    117|     * cast is needed. */                                                     \
   60|    117|    return (const type *)name##_storage_bss_get();                            \
   61|    117|  }                                                                           \
EVP_sha384:
   56|    120|  accessor_decorations type *name(void) {                                     \
   57|    120|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    120|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    120|     * cast is needed. */                                                     \
   60|    120|    return (const type *)name##_storage_bss_get();                            \
   61|    120|  }                                                                           \
EVP_sha512:
   56|     81|  accessor_decorations type *name(void) {                                     \
   57|     81|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|     81|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|     81|     * cast is needed. */                                                     \
   60|     81|    return (const type *)name##_storage_bss_get();                            \
   61|     81|  }                                                                           \
OPENSSL_built_in_curves:
   56|    785|  accessor_decorations type *name(void) {                                     \
   57|    785|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    785|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    785|     * cast is needed. */                                                     \
   60|    785|    return (const type *)name##_storage_bss_get();                            \
   61|    785|  }                                                                           \
EC_GFp_mont_method:
   56|      2|  accessor_decorations type *name(void) {                                     \
   57|      2|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      2|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      2|     * cast is needed. */                                                     \
   60|      2|    return (const type *)name##_storage_bss_get();                            \
   61|      2|  }                                                                           \
EC_GFp_nistp224_method:
   56|      1|  accessor_decorations type *name(void) {                                     \
   57|      1|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      1|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      1|     * cast is needed. */                                                     \
   60|      1|    return (const type *)name##_storage_bss_get();                            \
   61|      1|  }                                                                           \
EC_GFp_nistz256_method:
   56|      1|  accessor_decorations type *name(void) {                                     \
   57|      1|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      1|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      1|     * cast is needed. */                                                     \
   60|      1|    return (const type *)name##_storage_bss_get();                            \
   61|      1|  }                                                                           \
RSA_default_method:
   56|    469|  accessor_decorations type *name(void) {                                     \
   57|    469|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    469|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    469|     * cast is needed. */                                                     \
   60|    469|    return (const type *)name##_storage_bss_get();                            \
   61|    469|  }                                                                           \
bcm.c:BN_value_one_once_bss_get:
   42|    328|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:BN_value_one_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:BN_value_one_storage_bss_get:
   39|    329|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_aes_128_cbc_once_bss_get:
   42|     34|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_aes_128_cbc_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_aes_128_cbc_storage_bss_get:
   39|     35|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_aes_192_cbc_once_bss_get:
   42|      6|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_aes_192_cbc_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_aes_192_cbc_storage_bss_get:
   39|      7|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_aes_256_cbc_once_bss_get:
   42|      4|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_aes_256_cbc_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_aes_256_cbc_storage_bss_get:
   39|      5|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_md4_once_bss_get:
   42|  1.97k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_md4_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_md4_storage_bss_get:
   39|  1.97k|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_md5_once_bss_get:
   42|    420|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_md5_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_md5_storage_bss_get:
   39|    421|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha1_once_bss_get:
   42|  1.59k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha1_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_sha1_storage_bss_get:
   39|  1.59k|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha224_once_bss_get:
   42|     64|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha224_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_sha224_storage_bss_get:
   39|     65|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha256_once_bss_get:
   42|    117|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha256_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_sha256_storage_bss_get:
   39|    118|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha384_once_bss_get:
   42|    120|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha384_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_sha384_storage_bss_get:
   39|    121|  static type *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha512_once_bss_get:
   42|     81|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EVP_sha512_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EVP_sha512_storage_bss_get:
   39|     82|  static type *name##_bss_get(void) { return &name; }
bcm.c:OPENSSL_built_in_curves_once_bss_get:
   42|    785|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:OPENSSL_built_in_curves_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:OPENSSL_built_in_curves_storage_bss_get:
   39|    786|  static type *name##_bss_get(void) { return &name; }
bcm.c:built_in_groups_bss_get:
   39|    390|  static type *name##_bss_get(void) { return &name; }
bcm.c:built_in_groups_lock_bss_get:
   45|    788|  static struct CRYPTO_STATIC_MUTEX *name##_bss_get(void) { return &name; }
bcm.c:g_ec_ex_data_class_bss_get:
   48|    265|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_mont_method_once_bss_get:
   42|      2|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_mont_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_mont_method_storage_bss_get:
   39|      3|  static type *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistp224_method_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistp224_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_nistp224_method_storage_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistz256_method_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistz256_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_nistz256_method_storage_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_rsa_ex_data_class_bss_get:
   48|    469|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_once_bss_get:
   42|    469|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:RSA_default_method_storage_bss_get:
   39|    470|  static type *name##_bss_get(void) { return &name; }

EVP_MD_size:
   75|  8.88k|size_t EVP_MD_size(const EVP_MD *md) { return md->md_size; }
EVP_MD_block_size:
   77|  8.21k|size_t EVP_MD_block_size(const EVP_MD *md) { return md->block_size; }
EVP_MD_CTX_init:
   80|   226k|void EVP_MD_CTX_init(EVP_MD_CTX *ctx) {
   81|   226k|  OPENSSL_memset(ctx, 0, sizeof(EVP_MD_CTX));
   82|   226k|}
EVP_MD_CTX_cleanup:
   96|   212k|int EVP_MD_CTX_cleanup(EVP_MD_CTX *ctx) {
   97|   212k|  OPENSSL_free(ctx->md_data);
   98|       |
   99|   212k|  assert(ctx->pctx == NULL || ctx->pctx_ops != NULL);
  100|   212k|  if (ctx->pctx_ops) {
  ------------------
  |  Branch (100:7): [True: 0, False: 212k]
  ------------------
  101|      0|    ctx->pctx_ops->free(ctx->pctx);
  102|      0|  }
  103|       |
  104|   212k|  EVP_MD_CTX_init(ctx);
  105|       |
  106|   212k|  return 1;
  107|   212k|}
EVP_MD_CTX_copy_ex:
  134|   197k|int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in) {
  135|       |  // |in->digest| may be NULL if this is a signing |EVP_MD_CTX| for, e.g.,
  136|       |  // Ed25519 which does not hash with |EVP_MD_CTX|.
  137|   197k|  if (in == NULL || (in->pctx == NULL && in->digest == NULL)) {
  ------------------
  |  Branch (137:7): [True: 0, False: 197k]
  |  Branch (137:22): [True: 197k, False: 0]
  |  Branch (137:42): [True: 0, False: 197k]
  ------------------
  138|      0|    OPENSSL_PUT_ERROR(DIGEST, DIGEST_R_INPUT_NOT_INITIALIZED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  139|      0|    return 0;
  140|      0|  }
  141|       |
  142|   197k|  EVP_PKEY_CTX *pctx = NULL;
  143|   197k|  assert(in->pctx == NULL || in->pctx_ops != NULL);
  144|   197k|  if (in->pctx) {
  ------------------
  |  Branch (144:7): [True: 0, False: 197k]
  ------------------
  145|      0|    pctx = in->pctx_ops->dup(in->pctx);
  146|      0|    if (!pctx) {
  ------------------
  |  Branch (146:9): [True: 0, False: 0]
  ------------------
  147|      0|      return 0;
  148|      0|    }
  149|      0|  }
  150|       |
  151|   197k|  uint8_t *tmp_buf = NULL;
  152|   197k|  if (in->digest != NULL) {
  ------------------
  |  Branch (152:7): [True: 197k, False: 0]
  ------------------
  153|   197k|    if (out->digest != in->digest) {
  ------------------
  |  Branch (153:9): [True: 2.98k, False: 194k]
  ------------------
  154|  2.98k|      assert(in->digest->ctx_size != 0);
  155|  2.98k|      tmp_buf = OPENSSL_malloc(in->digest->ctx_size);
  156|  2.98k|      if (tmp_buf == NULL) {
  ------------------
  |  Branch (156:11): [True: 0, False: 2.98k]
  ------------------
  157|      0|        if (pctx) {
  ------------------
  |  Branch (157:13): [True: 0, False: 0]
  ------------------
  158|      0|          in->pctx_ops->free(pctx);
  159|      0|        }
  160|      0|        return 0;
  161|      0|      }
  162|   194k|    } else {
  163|       |      // |md_data| will be the correct size in this case. It's removed from
  164|       |      // |out| so that |EVP_MD_CTX_cleanup| doesn't free it, and then it's
  165|       |      // reused.
  166|   194k|      tmp_buf = out->md_data;
  167|   194k|      out->md_data = NULL;
  168|   194k|    }
  169|   197k|  }
  170|       |
  171|   197k|  EVP_MD_CTX_cleanup(out);
  172|       |
  173|   197k|  out->digest = in->digest;
  174|   197k|  out->md_data = tmp_buf;
  175|   197k|  if (in->digest != NULL) {
  ------------------
  |  Branch (175:7): [True: 197k, False: 0]
  ------------------
  176|   197k|    OPENSSL_memcpy(out->md_data, in->md_data, in->digest->ctx_size);
  177|   197k|  }
  178|   197k|  out->pctx = pctx;
  179|   197k|  out->pctx_ops = in->pctx_ops;
  180|   197k|  assert(out->pctx == NULL || out->pctx_ops != NULL);
  181|       |
  182|   197k|  return 1;
  183|   197k|}
EVP_DigestInit_ex:
  203|  5.86M|int EVP_DigestInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *engine) {
  204|  5.86M|  if (ctx->digest != type) {
  ------------------
  |  Branch (204:7): [True: 11.1k, False: 5.85M]
  ------------------
  205|  11.1k|    assert(type->ctx_size != 0);
  206|  11.1k|    uint8_t *md_data = OPENSSL_malloc(type->ctx_size);
  207|  11.1k|    if (md_data == NULL) {
  ------------------
  |  Branch (207:9): [True: 0, False: 11.1k]
  ------------------
  208|      0|      return 0;
  209|      0|    }
  210|       |
  211|  11.1k|    OPENSSL_free(ctx->md_data);
  212|  11.1k|    ctx->md_data = md_data;
  213|  11.1k|    ctx->digest = type;
  214|  11.1k|  }
  215|       |
  216|  5.86M|  assert(ctx->pctx == NULL || ctx->pctx_ops != NULL);
  217|       |
  218|  5.86M|  ctx->digest->init(ctx);
  219|  5.86M|  return 1;
  220|  5.86M|}
EVP_DigestUpdate:
  227|  6.06M|int EVP_DigestUpdate(EVP_MD_CTX *ctx, const void *data, size_t len) {
  228|  6.06M|  ctx->digest->update(ctx, data, len);
  229|  6.06M|  return 1;
  230|  6.06M|}
EVP_DigestFinal_ex:
  232|  6.05M|int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, uint8_t *md_out, unsigned int *size) {
  233|  6.05M|  assert(ctx->digest->md_size <= EVP_MAX_MD_SIZE);
  234|  6.05M|  ctx->digest->final(ctx, md_out);
  235|  6.05M|  if (size != NULL) {
  ------------------
  |  Branch (235:7): [True: 5.95M, False: 96.0k]
  ------------------
  236|  5.95M|    *size = ctx->digest->md_size;
  237|  5.95M|  }
  238|  6.05M|  OPENSSL_cleanse(ctx->md_data, ctx->digest->ctx_size);
  239|  6.05M|  return 1;
  240|  6.05M|}

bcm.c:EVP_md4_do_init:
   90|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_md4) {
   91|      1|  out->type = NID_md4;
  ------------------
  |  | 1254|      1|#define NID_md4 257
  ------------------
   92|      1|  out->md_size = MD4_DIGEST_LENGTH;
  ------------------
  |  |   73|      1|#define MD4_DIGEST_LENGTH 16
  ------------------
   93|      1|  out->flags = 0;
   94|      1|  out->init = md4_init;
   95|      1|  out->update = md4_update;
   96|      1|  out->final = md4_final;
   97|      1|  out->block_size = 64;
   98|      1|  out->ctx_size = sizeof(MD4_CTX);
   99|      1|}
bcm.c:md4_init:
   78|  20.9k|static void md4_init(EVP_MD_CTX *ctx) {
   79|  20.9k|  CHECK(MD4_Init(ctx->md_data));
  ------------------
  |  |   74|  20.9k|#define CHECK(x) assert(x)
  ------------------
   80|  20.9k|}
bcm.c:md4_update:
   82|  26.7k|static void md4_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
   83|  26.7k|  CHECK(MD4_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  26.7k|#define CHECK(x) assert(x)
  ------------------
   84|  26.7k|}
bcm.c:md4_final:
   86|  20.9k|static void md4_final(EVP_MD_CTX *ctx, uint8_t *out) {
   87|  20.9k|  CHECK(MD4_Final(out, ctx->md_data));
  ------------------
  |  |   74|  20.9k|#define CHECK(x) assert(x)
  ------------------
   88|  20.9k|}
bcm.c:EVP_md5_do_init:
  114|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_md5) {
  115|      1|  out->type = NID_md5;
  ------------------
  |  |  105|      1|#define NID_md5 4
  ------------------
  116|      1|  out->md_size = MD5_DIGEST_LENGTH;
  ------------------
  |  |   74|      1|#define MD5_DIGEST_LENGTH 16
  ------------------
  117|      1|  out->flags = 0;
  118|      1|  out->init = md5_init;
  119|      1|  out->update = md5_update;
  120|      1|  out->final = md5_final;
  121|      1|  out->block_size = 64;
  122|      1|  out->ctx_size = sizeof(MD5_CTX);
  123|      1|}
bcm.c:md5_init:
  102|  9.19k|static void md5_init(EVP_MD_CTX *ctx) {
  103|  9.19k|  CHECK(MD5_Init(ctx->md_data));
  ------------------
  |  |   74|  9.19k|#define CHECK(x) assert(x)
  ------------------
  104|  9.19k|}
bcm.c:md5_update:
  106|  10.4k|static void md5_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
  107|  10.4k|  CHECK(MD5_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  10.4k|#define CHECK(x) assert(x)
  ------------------
  108|  10.4k|}
bcm.c:md5_final:
  110|  9.19k|static void md5_final(EVP_MD_CTX *ctx, uint8_t *out) {
  111|  9.19k|  CHECK(MD5_Final(out, ctx->md_data));
  ------------------
  |  |   74|  9.19k|#define CHECK(x) assert(x)
  ------------------
  112|  9.19k|}
bcm.c:EVP_sha1_do_init:
  138|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_sha1) {
  139|      1|  out->type = NID_sha1;
  ------------------
  |  |  372|      1|#define NID_sha1 64
  ------------------
  140|      1|  out->md_size = SHA_DIGEST_LENGTH;
  ------------------
  |  |   74|      1|#define SHA_DIGEST_LENGTH 20
  ------------------
  141|      1|  out->flags = 0;
  142|      1|  out->init = sha1_init;
  143|      1|  out->update = sha1_update;
  144|      1|  out->final = sha1_final;
  145|      1|  out->block_size = 64;
  146|      1|  out->ctx_size = sizeof(SHA_CTX);
  147|      1|}
bcm.c:sha1_init:
  126|  5.80M|static void sha1_init(EVP_MD_CTX *ctx) {
  127|  5.80M|  CHECK(SHA1_Init(ctx->md_data));
  ------------------
  |  |   74|  5.80M|#define CHECK(x) assert(x)
  ------------------
  128|  5.80M|}
bcm.c:sha1_update:
  130|  5.99M|static void sha1_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
  131|  5.99M|  CHECK(SHA1_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  5.99M|#define CHECK(x) assert(x)
  ------------------
  132|  5.99M|}
bcm.c:sha1_final:
  134|  5.99M|static void sha1_final(EVP_MD_CTX *ctx, uint8_t *md) {
  135|  5.99M|  CHECK(SHA1_Final(md, ctx->md_data));
  ------------------
  |  |   74|  5.99M|#define CHECK(x) assert(x)
  ------------------
  136|  5.99M|}
bcm.c:EVP_sha224_do_init:
  162|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_sha224) {
  163|      1|  out->type = NID_sha224;
  ------------------
  |  | 3008|      1|#define NID_sha224 675
  ------------------
  164|      1|  out->md_size = SHA224_DIGEST_LENGTH;
  ------------------
  |  |  128|      1|#define SHA224_DIGEST_LENGTH 28
  ------------------
  165|      1|  out->flags = 0;
  166|      1|  out->init = sha224_init;
  167|      1|  out->update = sha224_update;
  168|      1|  out->final = sha224_final;
  169|      1|  out->block_size = 64;
  170|      1|  out->ctx_size = sizeof(SHA256_CTX);
  171|      1|}
bcm.c:sha224_init:
  150|  6.95k|static void sha224_init(EVP_MD_CTX *ctx) {
  151|  6.95k|  CHECK(SHA224_Init(ctx->md_data));
  ------------------
  |  |   74|  6.95k|#define CHECK(x) assert(x)
  ------------------
  152|  6.95k|}
bcm.c:sha224_update:
  154|  7.13k|static void sha224_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
  155|  7.13k|  CHECK(SHA224_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  7.13k|#define CHECK(x) assert(x)
  ------------------
  156|  7.13k|}
bcm.c:sha224_final:
  158|  6.95k|static void sha224_final(EVP_MD_CTX *ctx, uint8_t *md) {
  159|  6.95k|  CHECK(SHA224_Final(md, ctx->md_data));
  ------------------
  |  |   74|  6.95k|#define CHECK(x) assert(x)
  ------------------
  160|  6.95k|}
bcm.c:EVP_sha256_do_init:
  186|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_sha256) {
  187|      1|  out->type = NID_sha256;
  ------------------
  |  | 2993|      1|#define NID_sha256 672
  ------------------
  188|      1|  out->md_size = SHA256_DIGEST_LENGTH;
  ------------------
  |  |  155|      1|#define SHA256_DIGEST_LENGTH 32
  ------------------
  189|      1|  out->flags = 0;
  190|      1|  out->init = sha256_init;
  191|      1|  out->update = sha256_update;
  192|      1|  out->final = sha256_final;
  193|      1|  out->block_size = 64;
  194|      1|  out->ctx_size = sizeof(SHA256_CTX);
  195|      1|}
bcm.c:sha256_init:
  174|  6.89k|static void sha256_init(EVP_MD_CTX *ctx) {
  175|  6.89k|  CHECK(SHA256_Init(ctx->md_data));
  ------------------
  |  |   74|  6.89k|#define CHECK(x) assert(x)
  ------------------
  176|  6.89k|}
bcm.c:sha256_update:
  178|  7.24k|static void sha256_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
  179|  7.24k|  CHECK(SHA256_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  7.24k|#define CHECK(x) assert(x)
  ------------------
  180|  7.24k|}
bcm.c:sha256_final:
  182|  6.89k|static void sha256_final(EVP_MD_CTX *ctx, uint8_t *md) {
  183|  6.89k|  CHECK(SHA256_Final(md, ctx->md_data));
  ------------------
  |  |   74|  6.89k|#define CHECK(x) assert(x)
  ------------------
  184|  6.89k|}
bcm.c:EVP_sha384_do_init:
  210|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_sha384) {
  211|      1|  out->type = NID_sha384;
  ------------------
  |  | 2998|      1|#define NID_sha384 673
  ------------------
  212|      1|  out->md_size = SHA384_DIGEST_LENGTH;
  ------------------
  |  |  203|      1|#define SHA384_DIGEST_LENGTH 48
  ------------------
  213|      1|  out->flags = 0;
  214|      1|  out->init = sha384_init;
  215|      1|  out->update = sha384_update;
  216|      1|  out->final = sha384_final;
  217|      1|  out->block_size = 128;
  218|      1|  out->ctx_size = sizeof(SHA512_CTX);
  219|      1|}
bcm.c:sha384_init:
  198|  9.96k|static void sha384_init(EVP_MD_CTX *ctx) {
  199|  9.96k|  CHECK(SHA384_Init(ctx->md_data));
  ------------------
  |  |   74|  9.96k|#define CHECK(x) assert(x)
  ------------------
  200|  9.96k|}
bcm.c:sha384_update:
  202|  10.3k|static void sha384_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
  203|  10.3k|  CHECK(SHA384_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  10.3k|#define CHECK(x) assert(x)
  ------------------
  204|  10.3k|}
bcm.c:sha384_final:
  206|  9.96k|static void sha384_final(EVP_MD_CTX *ctx, uint8_t *md) {
  207|  9.96k|  CHECK(SHA384_Final(md, ctx->md_data));
  ------------------
  |  |   74|  9.96k|#define CHECK(x) assert(x)
  ------------------
  208|  9.96k|}
bcm.c:EVP_sha512_do_init:
  234|      1|DEFINE_METHOD_FUNCTION(EVP_MD, EVP_sha512) {
  235|      1|  out->type = NID_sha512;
  ------------------
  |  | 3003|      1|#define NID_sha512 674
  ------------------
  236|      1|  out->md_size = SHA512_DIGEST_LENGTH;
  ------------------
  |  |  230|      1|#define SHA512_DIGEST_LENGTH 64
  ------------------
  237|      1|  out->flags = 0;
  238|      1|  out->init = sha512_init;
  239|      1|  out->update = sha512_update;
  240|      1|  out->final = sha512_final;
  241|      1|  out->block_size = 128;
  242|      1|  out->ctx_size = sizeof(SHA512_CTX);
  243|      1|}
bcm.c:sha512_init:
  222|  7.20k|static void sha512_init(EVP_MD_CTX *ctx) {
  223|  7.20k|  CHECK(SHA512_Init(ctx->md_data));
  ------------------
  |  |   74|  7.20k|#define CHECK(x) assert(x)
  ------------------
  224|  7.20k|}
bcm.c:sha512_update:
  226|  7.44k|static void sha512_update(EVP_MD_CTX *ctx, const void *data, size_t count) {
  227|  7.44k|  CHECK(SHA512_Update(ctx->md_data, data, count));
  ------------------
  |  |   74|  7.44k|#define CHECK(x) assert(x)
  ------------------
  228|  7.44k|}
bcm.c:sha512_final:
  230|  7.20k|static void sha512_final(EVP_MD_CTX *ctx, uint8_t *md) {
  231|  7.20k|  CHECK(SHA512_Final(md, ctx->md_data));
  ------------------
  |  |   74|  7.20k|#define CHECK(x) assert(x)
  ------------------
  232|  7.20k|}

bcm.c:crypto_md32_update:
  102|  6.04M|                                      const uint8_t *in, size_t len) {
  103|  6.04M|  if (len == 0) {
  ------------------
  |  Branch (103:7): [True: 97, False: 6.04M]
  ------------------
  104|     97|    return;
  105|     97|  }
  106|       |
  107|  6.04M|  uint32_t l = *Nl + (((uint32_t)len) << 3);
  108|  6.04M|  if (l < *Nl) {
  ------------------
  |  Branch (108:7): [True: 0, False: 6.04M]
  ------------------
  109|       |    // Handle carries.
  110|      0|    (*Nh)++;
  111|      0|  }
  112|  6.04M|  *Nh += (uint32_t)(len >> 29);
  113|  6.04M|  *Nl = l;
  114|       |
  115|  6.04M|  size_t n = *num;
  116|  6.04M|  if (n != 0) {
  ------------------
  |  Branch (116:7): [True: 76, False: 6.04M]
  ------------------
  117|     76|    if (len >= block_size || len + n >= block_size) {
  ------------------
  |  Branch (117:9): [True: 0, False: 76]
  |  Branch (117:30): [True: 0, False: 76]
  ------------------
  118|      0|      OPENSSL_memcpy(data + n, in, block_size - n);
  119|      0|      block_func(h, data, 1);
  120|      0|      n = block_size - n;
  121|      0|      in += n;
  122|      0|      len -= n;
  123|      0|      *num = 0;
  124|       |      // Keep |data| zeroed when unused.
  125|      0|      OPENSSL_memset(data, 0, block_size);
  126|     76|    } else {
  127|     76|      OPENSSL_memcpy(data + n, in, len);
  128|     76|      *num += (unsigned)len;
  129|     76|      return;
  130|     76|    }
  131|     76|  }
  132|       |
  133|  6.04M|  n = len / block_size;
  134|  6.04M|  if (n > 0) {
  ------------------
  |  Branch (134:7): [True: 19.0k, False: 6.03M]
  ------------------
  135|  19.0k|    block_func(h, in, n);
  136|  19.0k|    n *= block_size;
  137|  19.0k|    in += n;
  138|  19.0k|    len -= n;
  139|  19.0k|  }
  140|       |
  141|  6.04M|  if (len != 0) {
  ------------------
  |  Branch (141:7): [True: 6.03M, False: 16.5k]
  ------------------
  142|  6.03M|    *num = (unsigned)len;
  143|  6.03M|    OPENSSL_memcpy(data, in, len);
  144|  6.03M|  }
  145|  6.04M|}
bcm.c:crypto_md32_final:
  161|  6.03M|                                     int is_big_endian) {
  162|       |  // |data| always has room for at least one byte. A full block would have
  163|       |  // been consumed.
  164|  6.03M|  size_t n = *num;
  165|  6.03M|  assert(n < block_size);
  166|  6.03M|  data[n] = 0x80;
  167|  6.03M|  n++;
  168|       |
  169|       |  // Fill the block with zeros if there isn't room for a 64-bit length.
  170|  6.03M|  if (n > block_size - 8) {
  ------------------
  |  Branch (170:7): [True: 123, False: 6.03M]
  ------------------
  171|    123|    OPENSSL_memset(data + n, 0, block_size - n);
  172|    123|    n = 0;
  173|    123|    block_func(h, data, 1);
  174|    123|  }
  175|  6.03M|  OPENSSL_memset(data + n, 0, block_size - 8 - n);
  176|       |
  177|       |  // Append a 64-bit length to the block and process it.
  178|  6.03M|  if (is_big_endian) {
  ------------------
  |  Branch (178:7): [True: 6.00M, False: 30.1k]
  ------------------
  179|  6.00M|    CRYPTO_store_u32_be(data + block_size - 8, Nh);
  180|  6.00M|    CRYPTO_store_u32_be(data + block_size - 4, Nl);
  181|  6.00M|  } else {
  182|  30.1k|    CRYPTO_store_u32_le(data + block_size - 8, Nl);
  183|  30.1k|    CRYPTO_store_u32_le(data + block_size - 4, Nh);
  184|  30.1k|  }
  185|  6.03M|  block_func(h, data, 1);
  186|  6.03M|  *num = 0;
  187|  6.03M|  OPENSSL_memset(data, 0, block_size);
  188|  6.03M|}

ec_group_new:
  273|      4|EC_GROUP *ec_group_new(const EC_METHOD *meth) {
  274|      4|  EC_GROUP *ret;
  275|       |
  276|      4|  if (meth == NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 4]
  ------------------
  277|      0|    OPENSSL_PUT_ERROR(EC, EC_R_SLOT_FULL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  278|      0|    return NULL;
  279|      0|  }
  280|       |
  281|      4|  if (meth->group_init == 0) {
  ------------------
  |  Branch (281:7): [True: 0, False: 4]
  ------------------
  282|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|    return NULL;
  284|      0|  }
  285|       |
  286|      4|  ret = OPENSSL_malloc(sizeof(EC_GROUP));
  287|      4|  if (ret == NULL) {
  ------------------
  |  Branch (287:7): [True: 0, False: 4]
  ------------------
  288|      0|    return NULL;
  289|      0|  }
  290|      4|  OPENSSL_memset(ret, 0, sizeof(EC_GROUP));
  291|       |
  292|      4|  ret->references = 1;
  293|      4|  ret->meth = meth;
  294|      4|  BN_init(&ret->order);
  295|       |
  296|      4|  if (!meth->group_init(ret)) {
  ------------------
  |  Branch (296:7): [True: 0, False: 4]
  ------------------
  297|      0|    OPENSSL_free(ret);
  298|      0|    return NULL;
  299|      0|  }
  300|       |
  301|      4|  return ret;
  302|      4|}
EC_GROUP_new_by_curve_name:
  505|    390|EC_GROUP *EC_GROUP_new_by_curve_name(int nid) {
  506|    390|  struct built_in_groups_st *groups = built_in_groups_bss_get();
  507|    390|  EC_GROUP **group_ptr = NULL;
  508|    390|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  509|    390|  const struct built_in_curve *curve = NULL;
  510|    790|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|    790|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (510:22): [True: 790, False: 0]
  ------------------
  511|    790|    if (curves->curves[i].nid == nid) {
  ------------------
  |  Branch (511:9): [True: 390, False: 400]
  ------------------
  512|    390|      curve = &curves->curves[i];
  513|    390|      group_ptr = &groups->groups[i];
  514|    390|      break;
  515|    390|    }
  516|    790|  }
  517|       |
  518|    390|  if (curve == NULL) {
  ------------------
  |  Branch (518:7): [True: 0, False: 390]
  ------------------
  519|      0|    OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  520|      0|    return NULL;
  521|      0|  }
  522|       |
  523|    390|  CRYPTO_STATIC_MUTEX_lock_read(built_in_groups_lock_bss_get());
  524|    390|  EC_GROUP *ret = *group_ptr;
  525|    390|  CRYPTO_STATIC_MUTEX_unlock_read(built_in_groups_lock_bss_get());
  526|    390|  if (ret != NULL) {
  ------------------
  |  Branch (526:7): [True: 386, False: 4]
  ------------------
  527|    386|    return ret;
  528|    386|  }
  529|       |
  530|      4|  ret = ec_group_new_from_data(curve);
  531|      4|  if (ret == NULL) {
  ------------------
  |  Branch (531:7): [True: 0, False: 4]
  ------------------
  532|      0|    return NULL;
  533|      0|  }
  534|       |
  535|      4|  EC_GROUP *to_free = NULL;
  536|      4|  CRYPTO_STATIC_MUTEX_lock_write(built_in_groups_lock_bss_get());
  537|      4|  if (*group_ptr == NULL) {
  ------------------
  |  Branch (537:7): [True: 4, False: 0]
  ------------------
  538|      4|    *group_ptr = ret;
  539|       |    // Filling in |ret->curve_name| makes |EC_GROUP_free| and |EC_GROUP_dup|
  540|       |    // into no-ops. At this point, |ret| is considered static.
  541|      4|    ret->curve_name = nid;
  542|      4|  } else {
  543|      0|    to_free = ret;
  544|      0|    ret = *group_ptr;
  545|      0|  }
  546|      4|  CRYPTO_STATIC_MUTEX_unlock_write(built_in_groups_lock_bss_get());
  547|       |
  548|      4|  EC_GROUP_free(to_free);
  549|      4|  return ret;
  550|      4|}
EC_GROUP_free:
  552|  1.55k|void EC_GROUP_free(EC_GROUP *group) {
  553|  1.55k|  if (group == NULL ||
  ------------------
  |  Branch (553:7): [True: 632, False: 920]
  ------------------
  554|       |      // Built-in curves are static.
  555|  1.55k|      group->curve_name != NID_undef ||
  ------------------
  |  |   85|  2.47k|#define NID_undef 0
  ------------------
  |  Branch (555:7): [True: 920, False: 0]
  ------------------
  556|  1.55k|      !CRYPTO_refcount_dec_and_test_zero(&group->references)) {
  ------------------
  |  Branch (556:7): [True: 0, False: 0]
  ------------------
  557|  1.55k|    return;
  558|  1.55k|  }
  559|       |
  560|      0|  if (group->meth->group_finish != NULL) {
  ------------------
  |  Branch (560:7): [True: 0, False: 0]
  ------------------
  561|      0|    group->meth->group_finish(group);
  562|      0|  }
  563|       |
  564|      0|  ec_point_free(group->generator, 0 /* don't free group */);
  565|      0|  BN_free(&group->order);
  566|      0|  BN_MONT_CTX_free(group->order_mont);
  567|       |
  568|      0|  OPENSSL_free(group);
  569|      0|}
EC_GROUP_dup:
  571|    534|EC_GROUP *EC_GROUP_dup(const EC_GROUP *a) {
  572|    534|  if (a == NULL ||
  ------------------
  |  Branch (572:7): [True: 0, False: 534]
  ------------------
  573|       |      // Built-in curves are static.
  574|    534|      a->curve_name != NID_undef) {
  ------------------
  |  |   85|    534|#define NID_undef 0
  ------------------
  |  Branch (574:7): [True: 530, False: 4]
  ------------------
  575|    530|    return (EC_GROUP *)a;
  576|    530|  }
  577|       |
  578|       |  // Groups are logically immutable (but for |EC_GROUP_set_generator| which must
  579|       |  // be called early on), so we simply take a reference.
  580|      4|  EC_GROUP *group = (EC_GROUP *)a;
  581|      4|  CRYPTO_refcount_inc(&group->references);
  582|      4|  return group;
  583|    534|}
EC_GROUP_cmp:
  585|    245|int EC_GROUP_cmp(const EC_GROUP *a, const EC_GROUP *b, BN_CTX *ignored) {
  586|       |  // Note this function returns 0 if equal and non-zero otherwise.
  587|    245|  if (a == b) {
  ------------------
  |  Branch (587:7): [True: 240, False: 5]
  ------------------
  588|    240|    return 0;
  589|    240|  }
  590|      5|  if (a->curve_name != b->curve_name) {
  ------------------
  |  Branch (590:7): [True: 5, False: 0]
  ------------------
  591|      5|    return 1;
  592|      5|  }
  593|      0|  if (a->curve_name != NID_undef) {
  ------------------
  |  |   85|      0|#define NID_undef 0
  ------------------
  |  Branch (593:7): [True: 0, False: 0]
  ------------------
  594|       |    // Built-in curves may be compared by curve name alone.
  595|      0|    return 0;
  596|      0|  }
  597|       |
  598|       |  // |a| and |b| are both custom curves. We compare the entire curve
  599|       |  // structure. If |a| or |b| is incomplete (due to legacy OpenSSL mistakes,
  600|       |  // custom curve construction is sadly done in two parts) but otherwise not the
  601|       |  // same object, we consider them always unequal.
  602|      0|  return a->meth != b->meth ||
  ------------------
  |  Branch (602:10): [True: 0, False: 0]
  ------------------
  603|      0|         a->generator == NULL ||
  ------------------
  |  Branch (603:10): [True: 0, False: 0]
  ------------------
  604|      0|         b->generator == NULL ||
  ------------------
  |  Branch (604:10): [True: 0, False: 0]
  ------------------
  605|      0|         BN_cmp(&a->order, &b->order) != 0 ||
  ------------------
  |  Branch (605:10): [True: 0, False: 0]
  ------------------
  606|      0|         BN_cmp(&a->field, &b->field) != 0 ||
  ------------------
  |  Branch (606:10): [True: 0, False: 0]
  ------------------
  607|      0|         !ec_felem_equal(a, &a->a, &b->a) ||
  ------------------
  |  Branch (607:10): [True: 0, False: 0]
  ------------------
  608|      0|         !ec_felem_equal(a, &a->b, &b->b) ||
  ------------------
  |  Branch (608:10): [True: 0, False: 0]
  ------------------
  609|      0|         !ec_GFp_simple_points_equal(a, &a->generator->raw, &b->generator->raw);
  ------------------
  |  Branch (609:10): [True: 0, False: 0]
  ------------------
  610|      0|}
EC_POINT_new:
  679|    269|EC_POINT *EC_POINT_new(const EC_GROUP *group) {
  680|    269|  if (group == NULL) {
  ------------------
  |  Branch (680:7): [True: 0, False: 269]
  ------------------
  681|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  682|      0|    return NULL;
  683|      0|  }
  684|       |
  685|    269|  EC_POINT *ret = OPENSSL_malloc(sizeof *ret);
  686|    269|  if (ret == NULL) {
  ------------------
  |  Branch (686:7): [True: 0, False: 269]
  ------------------
  687|      0|    return NULL;
  688|      0|  }
  689|       |
  690|    269|  ret->group = EC_GROUP_dup(group);
  691|    269|  ec_GFp_simple_point_init(&ret->raw);
  692|    269|  return ret;
  693|    269|}
EC_POINT_free:
  705|    265|void EC_POINT_free(EC_POINT *point) {
  706|    265|  ec_point_free(point, 1 /* free group */);
  707|    265|}
EC_POINT_is_at_infinity:
  747|    111|int EC_POINT_is_at_infinity(const EC_GROUP *group, const EC_POINT *point) {
  748|    111|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (748:7): [True: 0, False: 111]
  ------------------
  749|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  750|      0|    return 0;
  751|      0|  }
  752|    111|  return ec_GFp_simple_is_at_infinity(group, &point->raw);
  753|    111|}
EC_POINT_is_on_curve:
  756|    111|                         BN_CTX *ctx) {
  757|    111|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (757:7): [True: 0, False: 111]
  ------------------
  758|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  759|      0|    return 0;
  760|      0|  }
  761|    111|  return ec_GFp_simple_is_on_curve(group, &point->raw);
  762|    111|}
ec_affine_to_jacobian:
  805|      4|                           const EC_AFFINE *p) {
  806|      4|  out->X = p->X;
  807|      4|  out->Y = p->Y;
  808|      4|  out->Z = group->one;
  809|      4|}
ec_point_set_affine_coordinates:
  826|      4|                                    const EC_FELEM *x, const EC_FELEM *y) {
  827|      4|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  828|      4|                          const EC_FELEM *b) = group->meth->felem_mul;
  829|      4|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  830|      4|      group->meth->felem_sqr;
  831|       |
  832|       |  // Check if the point is on the curve.
  833|      4|  EC_FELEM lhs, rhs;
  834|      4|  felem_sqr(group, &lhs, y);                   // lhs = y^2
  835|      4|  felem_sqr(group, &rhs, x);                   // rhs = x^2
  836|      4|  ec_felem_add(group, &rhs, &rhs, &group->a);  // rhs = x^2 + a
  837|      4|  felem_mul(group, &rhs, &rhs, x);             // rhs = x^3 + ax
  838|      4|  ec_felem_add(group, &rhs, &rhs, &group->b);  // rhs = x^3 + ax + b
  839|      4|  if (!ec_felem_equal(group, &lhs, &rhs)) {
  ------------------
  |  Branch (839:7): [True: 0, False: 4]
  ------------------
  840|      0|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_IS_NOT_ON_CURVE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  841|       |    // In the event of an error, defend against the caller not checking the
  842|       |    // return value by setting a known safe value. Note this may not be possible
  843|       |    // if the caller is in the process of constructing an arbitrary group and
  844|       |    // the generator is missing.
  845|      0|    if (group->generator != NULL) {
  ------------------
  |  Branch (845:9): [True: 0, False: 0]
  ------------------
  846|      0|      assert(ec_felem_equal(group, &group->one, &group->generator->raw.Z));
  847|      0|      out->X = group->generator->raw.X;
  848|      0|      out->Y = group->generator->raw.Y;
  849|      0|    }
  850|      0|    return 0;
  851|      0|  }
  852|       |
  853|      4|  out->X = *x;
  854|      4|  out->Y = *y;
  855|      4|  return 1;
  856|      4|}
ec_point_mul_scalar_base:
 1068|    332|                             const EC_SCALAR *scalar) {
 1069|    332|  if (scalar == NULL) {
  ------------------
  |  Branch (1069:7): [True: 0, False: 332]
  ------------------
 1070|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1071|      0|    return 0;
 1072|      0|  }
 1073|       |
 1074|    332|  group->meth->mul_base(group, r, scalar);
 1075|       |
 1076|       |  // Check the result is on the curve to defend against fault attacks or bugs.
 1077|       |  // This has negligible cost compared to the multiplication. This can only
 1078|       |  // happen on bug or CPU fault, so it okay to leak this. The alternative would
 1079|       |  // be to proceed with bad data.
 1080|    332|  if (!constant_time_declassify_int(ec_GFp_simple_is_on_curve(group, r))) {
  ------------------
  |  Branch (1080:7): [True: 0, False: 332]
  ------------------
 1081|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1082|      0|    return 0;
 1083|      0|  }
 1084|       |
 1085|    332|  return 1;
 1086|    332|}
ec_point_select:
 1143|   675k|                      const EC_JACOBIAN *a, const EC_JACOBIAN *b) {
 1144|   675k|  ec_felem_select(group, &out->X, mask, &a->X, &b->X);
 1145|   675k|  ec_felem_select(group, &out->Y, mask, &a->Y, &b->Y);
 1146|   675k|  ec_felem_select(group, &out->Z, mask, &a->Z, &b->Z);
 1147|   675k|}
ec_set_to_safe_point:
 1224|      4|void ec_set_to_safe_point(const EC_GROUP *group, EC_JACOBIAN *out) {
 1225|      4|  if (group->generator != NULL) {
  ------------------
  |  Branch (1225:7): [True: 4, False: 0]
  ------------------
 1226|      4|    ec_GFp_simple_point_copy(out, &group->generator->raw);
 1227|      4|  } else {
 1228|       |    // The generator can be missing if the caller is in the process of
 1229|       |    // constructing an arbitrary group. In this case, we give up and use the
 1230|       |    // point at infinity.
 1231|      0|    ec_GFp_simple_point_set_to_infinity(group, out);
 1232|      0|  }
 1233|      4|}
bcm.c:OPENSSL_built_in_curves_do_init:
  218|      1|DEFINE_METHOD_FUNCTION(struct built_in_curves, OPENSSL_built_in_curves) {
  219|       |  // 1.3.132.0.35
  220|      1|  static const uint8_t kOIDP521[] = {0x2b, 0x81, 0x04, 0x00, 0x23};
  221|      1|  out->curves[0].nid = NID_secp521r1;
  ------------------
  |  | 3172|      1|#define NID_secp521r1 716
  ------------------
  222|      1|  out->curves[0].oid = kOIDP521;
  223|      1|  out->curves[0].oid_len = sizeof(kOIDP521);
  224|      1|  out->curves[0].comment = "NIST P-521";
  225|      1|  out->curves[0].param_len = 66;
  226|      1|  out->curves[0].params = kP521Params;
  227|      1|  out->curves[0].method = EC_GFp_mont_method();
  228|       |
  229|       |  // 1.3.132.0.34
  230|      1|  static const uint8_t kOIDP384[] = {0x2b, 0x81, 0x04, 0x00, 0x22};
  231|      1|  out->curves[1].nid = NID_secp384r1;
  ------------------
  |  | 3168|      1|#define NID_secp384r1 715
  ------------------
  232|      1|  out->curves[1].oid = kOIDP384;
  233|      1|  out->curves[1].oid_len = sizeof(kOIDP384);
  234|      1|  out->curves[1].comment = "NIST P-384";
  235|      1|  out->curves[1].param_len = 48;
  236|      1|  out->curves[1].params = kP384Params;
  237|      1|  out->curves[1].method = EC_GFp_mont_method();
  238|       |
  239|       |  // 1.2.840.10045.3.1.7
  240|      1|  static const uint8_t kOIDP256[] = {0x2a, 0x86, 0x48, 0xce,
  241|      1|                                     0x3d, 0x03, 0x01, 0x07};
  242|      1|  out->curves[2].nid = NID_X9_62_prime256v1;
  ------------------
  |  | 1914|      1|#define NID_X9_62_prime256v1 415
  ------------------
  243|      1|  out->curves[2].oid = kOIDP256;
  244|      1|  out->curves[2].oid_len = sizeof(kOIDP256);
  245|      1|  out->curves[2].comment = "NIST P-256";
  246|      1|  out->curves[2].param_len = 32;
  247|      1|  out->curves[2].params = kP256Params;
  248|      1|  out->curves[2].method =
  249|      1|#if !defined(OPENSSL_NO_ASM) && \
  250|      1|    (defined(OPENSSL_X86_64) || defined(OPENSSL_AARCH64)) &&   \
  251|      1|    !defined(OPENSSL_SMALL)
  252|      1|      EC_GFp_nistz256_method();
  253|       |#else
  254|       |      EC_GFp_nistp256_method();
  255|       |#endif
  256|       |
  257|       |  // 1.3.132.0.33
  258|      1|  static const uint8_t kOIDP224[] = {0x2b, 0x81, 0x04, 0x00, 0x21};
  259|      1|  out->curves[3].nid = NID_secp224r1;
  ------------------
  |  | 3160|      1|#define NID_secp224r1 713
  ------------------
  260|      1|  out->curves[3].oid = kOIDP224;
  261|      1|  out->curves[3].oid_len = sizeof(kOIDP224);
  262|      1|  out->curves[3].comment = "NIST P-224";
  263|      1|  out->curves[3].param_len = 28;
  264|      1|  out->curves[3].params = kP224Params;
  265|      1|  out->curves[3].method =
  266|      1|#if defined(BORINGSSL_HAS_UINT128) && !defined(OPENSSL_SMALL)
  267|      1|      EC_GFp_nistp224_method();
  268|       |#else
  269|       |      EC_GFp_mont_method();
  270|       |#endif
  271|      1|}
bcm.c:ec_group_set_generator:
  305|      4|                                  const BIGNUM *order) {
  306|      4|  assert(group->generator == NULL);
  307|       |
  308|      4|  if (!BN_copy(&group->order, order)) {
  ------------------
  |  Branch (308:7): [True: 0, False: 4]
  ------------------
  309|      0|    return 0;
  310|      0|  }
  311|       |  // Store the order in minimal form, so it can be used with |BN_ULONG| arrays.
  312|      4|  bn_set_minimal_width(&group->order);
  313|       |
  314|      4|  BN_MONT_CTX_free(group->order_mont);
  315|      4|  group->order_mont = BN_MONT_CTX_new_for_modulus(&group->order, NULL);
  316|      4|  if (group->order_mont == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 4]
  ------------------
  317|      0|    return 0;
  318|      0|  }
  319|       |
  320|      4|  group->field_greater_than_order = BN_cmp(&group->field, order) > 0;
  321|      4|  if (group->field_greater_than_order) {
  ------------------
  |  Branch (321:7): [True: 4, False: 0]
  ------------------
  322|      4|    BIGNUM tmp;
  323|      4|    BN_init(&tmp);
  324|      4|    int ok =
  325|      4|        BN_sub(&tmp, &group->field, order) &&
  ------------------
  |  Branch (325:9): [True: 4, False: 0]
  ------------------
  326|      4|        bn_copy_words(group->field_minus_order.words, group->field.width, &tmp);
  ------------------
  |  Branch (326:9): [True: 4, False: 0]
  ------------------
  327|      4|    BN_free(&tmp);
  328|      4|    if (!ok) {
  ------------------
  |  Branch (328:9): [True: 0, False: 4]
  ------------------
  329|      0|      return 0;
  330|      0|    }
  331|      4|  }
  332|       |
  333|      4|  group->generator = EC_POINT_new(group);
  334|      4|  if (group->generator == NULL) {
  ------------------
  |  Branch (334:7): [True: 0, False: 4]
  ------------------
  335|      0|    return 0;
  336|      0|  }
  337|      4|  ec_affine_to_jacobian(group, &group->generator->raw, generator);
  338|      4|  assert(ec_felem_equal(group, &group->one, &group->generator->raw.Z));
  339|       |
  340|       |  // Avoid a reference cycle. |group->generator| does not maintain an owning
  341|       |  // pointer to |group|.
  342|      4|  int is_zero = CRYPTO_refcount_dec_and_test_zero(&group->references);
  343|       |
  344|      4|  assert(!is_zero);
  345|      4|  (void)is_zero;
  346|      4|  return 1;
  347|      4|}
bcm.c:ec_group_new_from_data:
  442|      4|static EC_GROUP *ec_group_new_from_data(const struct built_in_curve *curve) {
  443|      4|  EC_GROUP *group = NULL;
  444|      4|  BIGNUM *p = NULL, *a = NULL, *b = NULL, *order = NULL;
  445|      4|  int ok = 0;
  446|       |
  447|      4|  BN_CTX *ctx = BN_CTX_new();
  448|      4|  if (ctx == NULL) {
  ------------------
  |  Branch (448:7): [True: 0, False: 4]
  ------------------
  449|      0|    goto err;
  450|      0|  }
  451|       |
  452|      4|  const unsigned param_len = curve->param_len;
  453|      4|  const uint8_t *params = curve->params;
  454|       |
  455|      4|  if (!(p = BN_bin2bn(params + 0 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (455:7): [True: 0, False: 4]
  ------------------
  456|      4|      !(a = BN_bin2bn(params + 1 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (456:7): [True: 0, False: 4]
  ------------------
  457|      4|      !(b = BN_bin2bn(params + 2 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (457:7): [True: 0, False: 4]
  ------------------
  458|      4|      !(order = BN_bin2bn(params + 5 * param_len, param_len, NULL))) {
  ------------------
  |  Branch (458:7): [True: 0, False: 4]
  ------------------
  459|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  460|      0|    goto err;
  461|      0|  }
  462|       |
  463|      4|  group = ec_group_new(curve->method);
  464|      4|  if (group == NULL ||
  ------------------
  |  Branch (464:7): [True: 0, False: 4]
  ------------------
  465|      4|      !group->meth->group_set_curve(group, p, a, b, ctx)) {
  ------------------
  |  Branch (465:7): [True: 0, False: 4]
  ------------------
  466|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_EC_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  467|      0|    goto err;
  468|      0|  }
  469|       |
  470|      4|  EC_AFFINE G;
  471|      4|  EC_FELEM x, y;
  472|      4|  if (!ec_felem_from_bytes(group, &x, params + 3 * param_len, param_len) ||
  ------------------
  |  Branch (472:7): [True: 0, False: 4]
  ------------------
  473|      4|      !ec_felem_from_bytes(group, &y, params + 4 * param_len, param_len) ||
  ------------------
  |  Branch (473:7): [True: 0, False: 4]
  ------------------
  474|      4|      !ec_point_set_affine_coordinates(group, &G, &x, &y)) {
  ------------------
  |  Branch (474:7): [True: 0, False: 4]
  ------------------
  475|      0|    goto err;
  476|      0|  }
  477|       |
  478|      4|  if (!ec_group_set_generator(group, &G, order)) {
  ------------------
  |  Branch (478:7): [True: 0, False: 4]
  ------------------
  479|      0|    goto err;
  480|      0|  }
  481|       |
  482|      4|  ok = 1;
  483|       |
  484|      4|err:
  485|      4|  if (!ok) {
  ------------------
  |  Branch (485:7): [True: 0, False: 4]
  ------------------
  486|      0|    EC_GROUP_free(group);
  487|      0|    group = NULL;
  488|      0|  }
  489|      4|  BN_CTX_free(ctx);
  490|      4|  BN_free(p);
  491|      4|  BN_free(a);
  492|      4|  BN_free(b);
  493|      4|  BN_free(order);
  494|      4|  return group;
  495|      4|}
bcm.c:ec_point_free:
  695|    265|static void ec_point_free(EC_POINT *point, int free_group) {
  696|    265|  if (!point) {
  ------------------
  |  Branch (696:7): [True: 0, False: 265]
  ------------------
  697|      0|    return;
  698|      0|  }
  699|    265|  if (free_group) {
  ------------------
  |  Branch (699:7): [True: 265, False: 0]
  ------------------
  700|    265|    EC_GROUP_free(point->group);
  701|    265|  }
  702|    265|  OPENSSL_free(point);
  703|    265|}

EC_KEY_new:
  106|    265|EC_KEY *EC_KEY_new(void) { return EC_KEY_new_method(NULL); }
EC_KEY_new_method:
  108|    265|EC_KEY *EC_KEY_new_method(const ENGINE *engine) {
  109|    265|  EC_KEY *ret = OPENSSL_malloc(sizeof(EC_KEY));
  110|    265|  if (ret == NULL) {
  ------------------
  |  Branch (110:7): [True: 0, False: 265]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|    265|  OPENSSL_memset(ret, 0, sizeof(EC_KEY));
  115|       |
  116|    265|  if (engine) {
  ------------------
  |  Branch (116:7): [True: 0, False: 265]
  ------------------
  117|      0|    ret->ecdsa_meth = ENGINE_get_ECDSA_method(engine);
  118|      0|  }
  119|    265|  if (ret->ecdsa_meth) {
  ------------------
  |  Branch (119:7): [True: 0, False: 265]
  ------------------
  120|      0|    METHOD_ref(ret->ecdsa_meth);
  121|      0|  }
  122|       |
  123|    265|  ret->conv_form = POINT_CONVERSION_UNCOMPRESSED;
  124|    265|  ret->references = 1;
  125|       |
  126|    265|  CRYPTO_new_ex_data(&ret->ex_data);
  127|       |
  128|    265|  if (ret->ecdsa_meth && ret->ecdsa_meth->init && !ret->ecdsa_meth->init(ret)) {
  ------------------
  |  Branch (128:7): [True: 0, False: 265]
  |  Branch (128:26): [True: 0, False: 0]
  |  Branch (128:51): [True: 0, False: 0]
  ------------------
  129|      0|    CRYPTO_free_ex_data(g_ec_ex_data_class_bss_get(), ret, &ret->ex_data);
  130|      0|    if (ret->ecdsa_meth) {
  ------------------
  |  Branch (130:9): [True: 0, False: 0]
  ------------------
  131|      0|      METHOD_unref(ret->ecdsa_meth);
  132|      0|    }
  133|      0|    OPENSSL_free(ret);
  134|      0|    return NULL;
  135|      0|  }
  136|       |
  137|    265|  return ret;
  138|    265|}
EC_KEY_free:
  153|  1.01k|void EC_KEY_free(EC_KEY *r) {
  154|  1.01k|  if (r == NULL) {
  ------------------
  |  Branch (154:7): [True: 748, False: 265]
  ------------------
  155|    748|    return;
  156|    748|  }
  157|       |
  158|    265|  if (!CRYPTO_refcount_dec_and_test_zero(&r->references)) {
  ------------------
  |  Branch (158:7): [True: 0, False: 265]
  ------------------
  159|      0|    return;
  160|      0|  }
  161|       |
  162|    265|  if (r->ecdsa_meth) {
  ------------------
  |  Branch (162:7): [True: 0, False: 265]
  ------------------
  163|      0|    if (r->ecdsa_meth->finish) {
  ------------------
  |  Branch (163:9): [True: 0, False: 0]
  ------------------
  164|      0|      r->ecdsa_meth->finish(r);
  165|      0|    }
  166|      0|    METHOD_unref(r->ecdsa_meth);
  167|      0|  }
  168|       |
  169|    265|  EC_GROUP_free(r->group);
  170|    265|  EC_POINT_free(r->pub_key);
  171|    265|  ec_wrapped_scalar_free(r->priv_key);
  172|       |
  173|    265|  CRYPTO_free_ex_data(g_ec_ex_data_class_bss_get(), r, &r->ex_data);
  174|       |
  175|    265|  OPENSSL_free(r);
  176|    265|}
EC_KEY_set_group:
  215|    265|int EC_KEY_set_group(EC_KEY *key, const EC_GROUP *group) {
  216|       |  // If |key| already has a group, it is an error to switch to another one.
  217|    265|  if (key->group != NULL) {
  ------------------
  |  Branch (217:7): [True: 0, False: 265]
  ------------------
  218|      0|    if (EC_GROUP_cmp(key->group, group, NULL) != 0) {
  ------------------
  |  Branch (218:9): [True: 0, False: 0]
  ------------------
  219|      0|      OPENSSL_PUT_ERROR(EC, EC_R_GROUP_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  220|      0|      return 0;
  221|      0|    }
  222|      0|    return 1;
  223|      0|  }
  224|       |
  225|    265|  assert(key->priv_key == NULL);
  226|    265|  assert(key->pub_key == NULL);
  227|       |
  228|    265|  EC_GROUP_free(key->group);
  229|    265|  key->group = EC_GROUP_dup(group);
  230|    265|  return key->group != NULL;
  231|    265|}
EC_KEY_set_private_key:
  237|    265|int EC_KEY_set_private_key(EC_KEY *key, const BIGNUM *priv_key) {
  238|    265|  if (key->group == NULL) {
  ------------------
  |  Branch (238:7): [True: 0, False: 265]
  ------------------
  239|      0|    OPENSSL_PUT_ERROR(EC, EC_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  240|      0|    return 0;
  241|      0|  }
  242|       |
  243|    265|  EC_WRAPPED_SCALAR *scalar = ec_wrapped_scalar_new(key->group);
  244|    265|  if (scalar == NULL) {
  ------------------
  |  Branch (244:7): [True: 0, False: 265]
  ------------------
  245|      0|    return 0;
  246|      0|  }
  247|    265|  if (!ec_bignum_to_scalar(key->group, &scalar->scalar, priv_key) ||
  ------------------
  |  Branch (247:7): [True: 0, False: 265]
  ------------------
  248|    265|      ec_scalar_is_zero(key->group, &scalar->scalar)) {
  ------------------
  |  Branch (248:7): [True: 18, False: 247]
  ------------------
  249|     18|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_PRIVATE_KEY);
  ------------------
  |  |  441|     18|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  250|     18|    ec_wrapped_scalar_free(scalar);
  251|     18|    return 0;
  252|     18|  }
  253|    247|  ec_wrapped_scalar_free(key->priv_key);
  254|    247|  key->priv_key = scalar;
  255|    247|  return 1;
  256|    265|}
EC_KEY_check_key:
  292|    111|int EC_KEY_check_key(const EC_KEY *eckey) {
  293|    111|  if (!eckey || !eckey->group || !eckey->pub_key) {
  ------------------
  |  Branch (293:7): [True: 0, False: 111]
  |  Branch (293:17): [True: 0, False: 111]
  |  Branch (293:34): [True: 0, False: 111]
  ------------------
  294|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  295|      0|    return 0;
  296|      0|  }
  297|       |
  298|    111|  if (EC_POINT_is_at_infinity(eckey->group, eckey->pub_key)) {
  ------------------
  |  Branch (298:7): [True: 0, False: 111]
  ------------------
  299|      0|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_AT_INFINITY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  300|      0|    return 0;
  301|      0|  }
  302|       |
  303|       |  // Test whether the public key is on the elliptic curve.
  304|    111|  if (!EC_POINT_is_on_curve(eckey->group, eckey->pub_key, NULL)) {
  ------------------
  |  Branch (304:7): [True: 0, False: 111]
  ------------------
  305|      0|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_IS_NOT_ON_CURVE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  306|      0|    return 0;
  307|      0|  }
  308|       |
  309|       |  // Check the public and private keys match.
  310|       |  //
  311|       |  // NOTE: this is a FIPS pair-wise consistency check for the ECDH case. See SP
  312|       |  // 800-56Ar3, page 36.
  313|    111|  if (eckey->priv_key != NULL) {
  ------------------
  |  Branch (313:7): [True: 111, False: 0]
  ------------------
  314|    111|    EC_JACOBIAN point;
  315|    111|    if (!ec_point_mul_scalar_base(eckey->group, &point,
  ------------------
  |  Branch (315:9): [True: 0, False: 111]
  ------------------
  316|    111|                                  &eckey->priv_key->scalar)) {
  317|      0|      OPENSSL_PUT_ERROR(EC, ERR_R_EC_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  318|      0|      return 0;
  319|      0|    }
  320|    111|    if (!ec_GFp_simple_points_equal(eckey->group, &point,
  ------------------
  |  Branch (320:9): [True: 0, False: 111]
  ------------------
  321|    111|                                    &eckey->pub_key->raw)) {
  322|      0|      OPENSSL_PUT_ERROR(EC, EC_R_INVALID_PRIVATE_KEY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  323|      0|      return 0;
  324|      0|    }
  325|    111|  }
  326|       |
  327|    111|  return 1;
  328|    111|}
bcm.c:ec_wrapped_scalar_free:
  102|    530|static void ec_wrapped_scalar_free(EC_WRAPPED_SCALAR *scalar) {
  103|    530|  OPENSSL_free(scalar);
  104|    530|}
bcm.c:ec_wrapped_scalar_new:
   88|    265|static EC_WRAPPED_SCALAR *ec_wrapped_scalar_new(const EC_GROUP *group) {
   89|    265|  EC_WRAPPED_SCALAR *wrapped = OPENSSL_malloc(sizeof(EC_WRAPPED_SCALAR));
   90|    265|  if (wrapped == NULL) {
  ------------------
  |  Branch (90:7): [True: 0, False: 265]
  ------------------
   91|      0|    return NULL;
   92|      0|  }
   93|       |
   94|    265|  OPENSSL_memset(wrapped, 0, sizeof(EC_WRAPPED_SCALAR));
   95|    265|  wrapped->bignum.d = wrapped->scalar.words;
   96|    265|  wrapped->bignum.width = group->order.width;
   97|    265|  wrapped->bignum.dmax = group->order.width;
   98|    265|  wrapped->bignum.flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|    265|#define BN_FLG_STATIC_DATA 0x02
  ------------------
   99|    265|  return wrapped;
  100|    265|}

ec_GFp_mont_group_init:
   79|      3|int ec_GFp_mont_group_init(EC_GROUP *group) {
   80|      3|  int ok;
   81|       |
   82|      3|  ok = ec_GFp_simple_group_init(group);
   83|      3|  group->mont = NULL;
   84|      3|  return ok;
   85|      3|}
ec_GFp_mont_group_set_curve:
   94|      3|                                const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
   95|      3|  BN_MONT_CTX_free(group->mont);
   96|      3|  group->mont = BN_MONT_CTX_new_for_modulus(p, ctx);
   97|      3|  if (group->mont == NULL) {
  ------------------
  |  Branch (97:7): [True: 0, False: 3]
  ------------------
   98|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   99|      0|    return 0;
  100|      0|  }
  101|       |
  102|      3|  if (!ec_GFp_simple_group_set_curve(group, p, a, b, ctx)) {
  ------------------
  |  Branch (102:7): [True: 0, False: 3]
  ------------------
  103|      0|    BN_MONT_CTX_free(group->mont);
  104|      0|    group->mont = NULL;
  105|      0|    return 0;
  106|      0|  }
  107|       |
  108|      3|  return 1;
  109|      3|}
ec_GFp_mont_felem_mul:
  131|   594k|                           const EC_FELEM *a, const EC_FELEM *b) {
  132|   594k|  bn_mod_mul_montgomery_small(r->words, a->words, b->words, group->field.width,
  133|   594k|                              group->mont);
  134|   594k|}
ec_GFp_mont_felem_sqr:
  137|   663k|                           const EC_FELEM *a) {
  138|   663k|  bn_mod_mul_montgomery_small(r->words, a->words, a->words, group->field.width,
  139|   663k|                              group->mont);
  140|   663k|}
ec_GFp_mont_felem_from_bytes:
  150|     15|                                 const uint8_t *in, size_t len) {
  151|     15|  if (!ec_GFp_simple_felem_from_bytes(group, out, in, len)) {
  ------------------
  |  Branch (151:7): [True: 0, False: 15]
  ------------------
  152|      0|    return 0;
  153|      0|  }
  154|       |
  155|     15|  ec_GFp_mont_felem_to_montgomery(group, out, out);
  156|     15|  return 1;
  157|     15|}
ec_GFp_mont_add:
  251|  24.4k|                     const EC_JACOBIAN *a, const EC_JACOBIAN *b) {
  252|  24.4k|  if (a == b) {
  ------------------
  |  Branch (252:7): [True: 0, False: 24.4k]
  ------------------
  253|      0|    ec_GFp_mont_dbl(group, out, a);
  254|      0|    return;
  255|      0|  }
  256|       |
  257|       |  // The method is taken from:
  258|       |  //   http://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian.html#addition-add-2007-bl
  259|       |  //
  260|       |  // Coq transcription and correctness proof:
  261|       |  // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L467>
  262|       |  // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L544>
  263|  24.4k|  EC_FELEM x_out, y_out, z_out;
  264|  24.4k|  BN_ULONG z1nz = ec_felem_non_zero_mask(group, &a->Z);
  265|  24.4k|  BN_ULONG z2nz = ec_felem_non_zero_mask(group, &b->Z);
  266|       |
  267|       |  // z1z1 = z1z1 = z1**2
  268|  24.4k|  EC_FELEM z1z1;
  269|  24.4k|  ec_GFp_mont_felem_sqr(group, &z1z1, &a->Z);
  270|       |
  271|       |  // z2z2 = z2**2
  272|  24.4k|  EC_FELEM z2z2;
  273|  24.4k|  ec_GFp_mont_felem_sqr(group, &z2z2, &b->Z);
  274|       |
  275|       |  // u1 = x1*z2z2
  276|  24.4k|  EC_FELEM u1;
  277|  24.4k|  ec_GFp_mont_felem_mul(group, &u1, &a->X, &z2z2);
  278|       |
  279|       |  // two_z1z2 = (z1 + z2)**2 - (z1z1 + z2z2) = 2z1z2
  280|  24.4k|  EC_FELEM two_z1z2;
  281|  24.4k|  ec_felem_add(group, &two_z1z2, &a->Z, &b->Z);
  282|  24.4k|  ec_GFp_mont_felem_sqr(group, &two_z1z2, &two_z1z2);
  283|  24.4k|  ec_felem_sub(group, &two_z1z2, &two_z1z2, &z1z1);
  284|  24.4k|  ec_felem_sub(group, &two_z1z2, &two_z1z2, &z2z2);
  285|       |
  286|       |  // s1 = y1 * z2**3
  287|  24.4k|  EC_FELEM s1;
  288|  24.4k|  ec_GFp_mont_felem_mul(group, &s1, &b->Z, &z2z2);
  289|  24.4k|  ec_GFp_mont_felem_mul(group, &s1, &s1, &a->Y);
  290|       |
  291|       |  // u2 = x2*z1z1
  292|  24.4k|  EC_FELEM u2;
  293|  24.4k|  ec_GFp_mont_felem_mul(group, &u2, &b->X, &z1z1);
  294|       |
  295|       |  // h = u2 - u1
  296|  24.4k|  EC_FELEM h;
  297|  24.4k|  ec_felem_sub(group, &h, &u2, &u1);
  298|       |
  299|  24.4k|  BN_ULONG xneq = ec_felem_non_zero_mask(group, &h);
  300|       |
  301|       |  // z_out = two_z1z2 * h
  302|  24.4k|  ec_GFp_mont_felem_mul(group, &z_out, &h, &two_z1z2);
  303|       |
  304|       |  // z1z1z1 = z1 * z1z1
  305|  24.4k|  EC_FELEM z1z1z1;
  306|  24.4k|  ec_GFp_mont_felem_mul(group, &z1z1z1, &a->Z, &z1z1);
  307|       |
  308|       |  // s2 = y2 * z1**3
  309|  24.4k|  EC_FELEM s2;
  310|  24.4k|  ec_GFp_mont_felem_mul(group, &s2, &b->Y, &z1z1z1);
  311|       |
  312|       |  // r = (s2 - s1)*2
  313|  24.4k|  EC_FELEM r;
  314|  24.4k|  ec_felem_sub(group, &r, &s2, &s1);
  315|  24.4k|  ec_felem_add(group, &r, &r, &r);
  316|       |
  317|  24.4k|  BN_ULONG yneq = ec_felem_non_zero_mask(group, &r);
  318|       |
  319|       |  // This case will never occur in the constant-time |ec_GFp_mont_mul|.
  320|  24.4k|  BN_ULONG is_nontrivial_double = ~xneq & ~yneq & z1nz & z2nz;
  321|  24.4k|  if (constant_time_declassify_w(is_nontrivial_double)) {
  ------------------
  |  Branch (321:7): [True: 0, False: 24.4k]
  ------------------
  322|      0|    ec_GFp_mont_dbl(group, out, a);
  323|      0|    return;
  324|      0|  }
  325|       |
  326|       |  // I = (2h)**2
  327|  24.4k|  EC_FELEM i;
  328|  24.4k|  ec_felem_add(group, &i, &h, &h);
  329|  24.4k|  ec_GFp_mont_felem_sqr(group, &i, &i);
  330|       |
  331|       |  // J = h * I
  332|  24.4k|  EC_FELEM j;
  333|  24.4k|  ec_GFp_mont_felem_mul(group, &j, &h, &i);
  334|       |
  335|       |  // V = U1 * I
  336|  24.4k|  EC_FELEM v;
  337|  24.4k|  ec_GFp_mont_felem_mul(group, &v, &u1, &i);
  338|       |
  339|       |  // x_out = r**2 - J - 2V
  340|  24.4k|  ec_GFp_mont_felem_sqr(group, &x_out, &r);
  341|  24.4k|  ec_felem_sub(group, &x_out, &x_out, &j);
  342|  24.4k|  ec_felem_sub(group, &x_out, &x_out, &v);
  343|  24.4k|  ec_felem_sub(group, &x_out, &x_out, &v);
  344|       |
  345|       |  // y_out = r(V-x_out) - 2 * s1 * J
  346|  24.4k|  ec_felem_sub(group, &y_out, &v, &x_out);
  347|  24.4k|  ec_GFp_mont_felem_mul(group, &y_out, &y_out, &r);
  348|  24.4k|  EC_FELEM s1j;
  349|  24.4k|  ec_GFp_mont_felem_mul(group, &s1j, &s1, &j);
  350|  24.4k|  ec_felem_sub(group, &y_out, &y_out, &s1j);
  351|  24.4k|  ec_felem_sub(group, &y_out, &y_out, &s1j);
  352|       |
  353|  24.4k|  ec_felem_select(group, &x_out, z1nz, &x_out, &b->X);
  354|  24.4k|  ec_felem_select(group, &out->X, z2nz, &x_out, &a->X);
  355|  24.4k|  ec_felem_select(group, &y_out, z1nz, &y_out, &b->Y);
  356|  24.4k|  ec_felem_select(group, &out->Y, z2nz, &y_out, &a->Y);
  357|  24.4k|  ec_felem_select(group, &z_out, z1nz, &z_out, &b->Z);
  358|  24.4k|  ec_felem_select(group, &out->Z, z2nz, &z_out, &a->Z);
  359|  24.4k|}
ec_GFp_mont_dbl:
  362|   107k|                     const EC_JACOBIAN *a) {
  363|   107k|  if (group->a_is_minus3) {
  ------------------
  |  Branch (363:7): [True: 107k, False: 0]
  ------------------
  364|       |    // The method is taken from:
  365|       |    //   http://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian-3.html#doubling-dbl-2001-b
  366|       |    //
  367|       |    // Coq transcription and correctness proof:
  368|       |    // <https://github.com/mit-plv/fiat-crypto/blob/79f8b5f39ed609339f0233098dee1a3c4e6b3080/src/Curves/Weierstrass/Jacobian.v#L93>
  369|       |    // <https://github.com/mit-plv/fiat-crypto/blob/79f8b5f39ed609339f0233098dee1a3c4e6b3080/src/Curves/Weierstrass/Jacobian.v#L201>
  370|   107k|    EC_FELEM delta, gamma, beta, ftmp, ftmp2, tmptmp, alpha, fourbeta;
  371|       |    // delta = z^2
  372|   107k|    ec_GFp_mont_felem_sqr(group, &delta, &a->Z);
  373|       |    // gamma = y^2
  374|   107k|    ec_GFp_mont_felem_sqr(group, &gamma, &a->Y);
  375|       |    // beta = x*gamma
  376|   107k|    ec_GFp_mont_felem_mul(group, &beta, &a->X, &gamma);
  377|       |
  378|       |    // alpha = 3*(x-delta)*(x+delta)
  379|   107k|    ec_felem_sub(group, &ftmp, &a->X, &delta);
  380|   107k|    ec_felem_add(group, &ftmp2, &a->X, &delta);
  381|       |
  382|   107k|    ec_felem_add(group, &tmptmp, &ftmp2, &ftmp2);
  383|   107k|    ec_felem_add(group, &ftmp2, &ftmp2, &tmptmp);
  384|   107k|    ec_GFp_mont_felem_mul(group, &alpha, &ftmp, &ftmp2);
  385|       |
  386|       |    // x' = alpha^2 - 8*beta
  387|   107k|    ec_GFp_mont_felem_sqr(group, &r->X, &alpha);
  388|   107k|    ec_felem_add(group, &fourbeta, &beta, &beta);
  389|   107k|    ec_felem_add(group, &fourbeta, &fourbeta, &fourbeta);
  390|   107k|    ec_felem_add(group, &tmptmp, &fourbeta, &fourbeta);
  391|   107k|    ec_felem_sub(group, &r->X, &r->X, &tmptmp);
  392|       |
  393|       |    // z' = (y + z)^2 - gamma - delta
  394|   107k|    ec_felem_add(group, &delta, &gamma, &delta);
  395|   107k|    ec_felem_add(group, &ftmp, &a->Y, &a->Z);
  396|   107k|    ec_GFp_mont_felem_sqr(group, &r->Z, &ftmp);
  397|   107k|    ec_felem_sub(group, &r->Z, &r->Z, &delta);
  398|       |
  399|       |    // y' = alpha*(4*beta - x') - 8*gamma^2
  400|   107k|    ec_felem_sub(group, &r->Y, &fourbeta, &r->X);
  401|   107k|    ec_felem_add(group, &gamma, &gamma, &gamma);
  402|   107k|    ec_GFp_mont_felem_sqr(group, &gamma, &gamma);
  403|   107k|    ec_GFp_mont_felem_mul(group, &r->Y, &alpha, &r->Y);
  404|   107k|    ec_felem_add(group, &gamma, &gamma, &gamma);
  405|   107k|    ec_felem_sub(group, &r->Y, &r->Y, &gamma);
  406|   107k|  } else {
  407|       |    // The method is taken from:
  408|       |    //   http://www.hyperelliptic.org/EFD/g1p/auto-shortw-jacobian.html#doubling-dbl-2007-bl
  409|       |    //
  410|       |    // Coq transcription and correctness proof:
  411|       |    // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L102>
  412|       |    // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L534>
  413|      0|    EC_FELEM xx, yy, yyyy, zz;
  414|      0|    ec_GFp_mont_felem_sqr(group, &xx, &a->X);
  415|      0|    ec_GFp_mont_felem_sqr(group, &yy, &a->Y);
  416|      0|    ec_GFp_mont_felem_sqr(group, &yyyy, &yy);
  417|      0|    ec_GFp_mont_felem_sqr(group, &zz, &a->Z);
  418|       |
  419|       |    // s = 2*((x_in + yy)^2 - xx - yyyy)
  420|      0|    EC_FELEM s;
  421|      0|    ec_felem_add(group, &s, &a->X, &yy);
  422|      0|    ec_GFp_mont_felem_sqr(group, &s, &s);
  423|      0|    ec_felem_sub(group, &s, &s, &xx);
  424|      0|    ec_felem_sub(group, &s, &s, &yyyy);
  425|      0|    ec_felem_add(group, &s, &s, &s);
  426|       |
  427|       |    // m = 3*xx + a*zz^2
  428|      0|    EC_FELEM m;
  429|      0|    ec_GFp_mont_felem_sqr(group, &m, &zz);
  430|      0|    ec_GFp_mont_felem_mul(group, &m, &group->a, &m);
  431|      0|    ec_felem_add(group, &m, &m, &xx);
  432|      0|    ec_felem_add(group, &m, &m, &xx);
  433|      0|    ec_felem_add(group, &m, &m, &xx);
  434|       |
  435|       |    // x_out = m^2 - 2*s
  436|      0|    ec_GFp_mont_felem_sqr(group, &r->X, &m);
  437|      0|    ec_felem_sub(group, &r->X, &r->X, &s);
  438|      0|    ec_felem_sub(group, &r->X, &r->X, &s);
  439|       |
  440|       |    // z_out = (y_in + z_in)^2 - yy - zz
  441|      0|    ec_felem_add(group, &r->Z, &a->Y, &a->Z);
  442|      0|    ec_GFp_mont_felem_sqr(group, &r->Z, &r->Z);
  443|      0|    ec_felem_sub(group, &r->Z, &r->Z, &yy);
  444|      0|    ec_felem_sub(group, &r->Z, &r->Z, &zz);
  445|       |
  446|       |    // y_out = m*(s-x_out) - 8*yyyy
  447|      0|    ec_felem_add(group, &yyyy, &yyyy, &yyyy);
  448|      0|    ec_felem_add(group, &yyyy, &yyyy, &yyyy);
  449|      0|    ec_felem_add(group, &yyyy, &yyyy, &yyyy);
  450|      0|    ec_felem_sub(group, &r->Y, &s, &r->X);
  451|      0|    ec_GFp_mont_felem_mul(group, &r->Y, &r->Y, &m);
  452|      0|    ec_felem_sub(group, &r->Y, &r->Y, &yyyy);
  453|      0|  }
  454|   107k|}
bcm.c:ec_GFp_mont_felem_to_montgomery:
  112|     15|                                            EC_FELEM *out, const EC_FELEM *in) {
  113|     15|  bn_to_montgomery_small(out->words, in->words, group->field.width,
  114|     15|                         group->mont);
  115|     15|}
bcm.c:EC_GFp_mont_method_do_init:
  501|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_mont_method) {
  502|      1|  out->group_init = ec_GFp_mont_group_init;
  503|      1|  out->group_finish = ec_GFp_mont_group_finish;
  504|      1|  out->group_set_curve = ec_GFp_mont_group_set_curve;
  505|      1|  out->point_get_affine_coordinates = ec_GFp_mont_point_get_affine_coordinates;
  506|      1|  out->jacobian_to_affine_batch = ec_GFp_mont_jacobian_to_affine_batch;
  507|      1|  out->add = ec_GFp_mont_add;
  508|      1|  out->dbl = ec_GFp_mont_dbl;
  509|      1|  out->mul = ec_GFp_mont_mul;
  510|      1|  out->mul_base = ec_GFp_mont_mul_base;
  511|      1|  out->mul_batch = ec_GFp_mont_mul_batch;
  512|      1|  out->mul_public_batch = ec_GFp_mont_mul_public_batch;
  513|      1|  out->init_precomp = ec_GFp_mont_init_precomp;
  514|      1|  out->mul_precomp = ec_GFp_mont_mul_precomp;
  515|      1|  out->felem_mul = ec_GFp_mont_felem_mul;
  516|      1|  out->felem_sqr = ec_GFp_mont_felem_sqr;
  517|      1|  out->felem_to_bytes = ec_GFp_mont_felem_to_bytes;
  518|      1|  out->felem_from_bytes = ec_GFp_mont_felem_from_bytes;
  519|      1|  out->felem_reduce = ec_GFp_mont_felem_reduce;
  520|      1|  out->felem_exp = ec_GFp_mont_felem_exp;
  521|      1|  out->scalar_inv0_montgomery = ec_simple_scalar_inv0_montgomery;
  522|      1|  out->scalar_to_montgomery_inv_vartime =
  523|      1|      ec_simple_scalar_to_montgomery_inv_vartime;
  524|      1|  out->cmp_x_coordinate = ec_GFp_mont_cmp_x_coordinate;
  525|      1|}

ec_bignum_to_felem:
   26|     12|int ec_bignum_to_felem(const EC_GROUP *group, EC_FELEM *out, const BIGNUM *in) {
   27|     12|  uint8_t bytes[EC_MAX_BYTES];
   28|     12|  size_t len = BN_num_bytes(&group->field);
   29|     12|  assert(sizeof(bytes) >= len);
   30|     12|  if (BN_is_negative(in) ||
  ------------------
  |  Branch (30:7): [True: 0, False: 12]
  ------------------
   31|     12|      BN_cmp(in, &group->field) >= 0 ||
  ------------------
  |  Branch (31:7): [True: 0, False: 12]
  ------------------
   32|     12|      !BN_bn2bin_padded(bytes, len, in)) {
  ------------------
  |  Branch (32:7): [True: 0, False: 12]
  ------------------
   33|      0|    OPENSSL_PUT_ERROR(EC, EC_R_COORDINATES_OUT_OF_RANGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|      0|    return 0;
   35|      0|  }
   36|       |
   37|     12|  return ec_felem_from_bytes(group, out, bytes, len);
   38|     12|}
ec_felem_from_bytes:
   53|     20|                        size_t len) {
   54|     20|  return group->meth->felem_from_bytes(group, out, in, len);
   55|     20|}
ec_felem_add:
   70|  1.15M|                  const EC_FELEM *b) {
   71|  1.15M|  EC_FELEM tmp;
   72|  1.15M|  bn_mod_add_words(out->words, a->words, b->words, group->field.d, tmp.words,
   73|  1.15M|                   group->field.width);
   74|  1.15M|}
ec_felem_sub:
   77|   785k|                  const EC_FELEM *b) {
   78|   785k|  EC_FELEM tmp;
   79|   785k|  bn_mod_sub_words(out->words, a->words, b->words, group->field.d, tmp.words,
   80|   785k|                   group->field.width);
   81|   785k|}
ec_felem_non_zero_mask:
   83|  99.3k|BN_ULONG ec_felem_non_zero_mask(const EC_GROUP *group, const EC_FELEM *a) {
   84|  99.3k|  BN_ULONG mask = 0;
   85|   825k|  for (int i = 0; i < group->field.width; i++) {
  ------------------
  |  Branch (85:19): [True: 726k, False: 99.3k]
  ------------------
   86|   726k|    mask |= a->words[i];
   87|   726k|  }
   88|  99.3k|  return ~constant_time_is_zero_w(mask);
   89|  99.3k|}
ec_felem_select:
   92|  2.17M|                     const EC_FELEM *a, const EC_FELEM *b) {
   93|  2.17M|  bn_select_words(out->words, mask, a->words, b->words, group->field.width);
   94|  2.17M|}
ec_felem_equal:
   97|      8|                   const EC_FELEM *b) {
   98|      8|  return CRYPTO_memcmp(a->words, b->words,
   99|      8|                       group->field.width * sizeof(BN_ULONG)) == 0;
  100|      8|}

ec_point_from_uncompressed:
  119|      4|                               const uint8_t *in, size_t len) {
  120|      4|  const size_t field_len = BN_num_bytes(&group->field);
  121|      4|  if (len != 1 + 2 * field_len || in[0] != POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (121:7): [True: 4, False: 0]
  |  Branch (121:35): [True: 0, False: 0]
  ------------------
  122|      4|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  123|      4|    return 0;
  124|      4|  }
  125|       |
  126|      0|  EC_FELEM x, y;
  127|      0|  if (!ec_felem_from_bytes(group, &x, in + 1, field_len) ||
  ------------------
  |  Branch (127:7): [True: 0, False: 0]
  ------------------
  128|      0|      !ec_felem_from_bytes(group, &y, in + 1 + field_len, field_len) ||
  ------------------
  |  Branch (128:7): [True: 0, False: 0]
  ------------------
  129|      0|      !ec_point_set_affine_coordinates(group, out, &x, &y)) {
  ------------------
  |  Branch (129:7): [True: 0, False: 0]
  ------------------
  130|      0|    return 0;
  131|      0|  }
  132|       |
  133|      0|  return 1;
  134|      0|}
EC_POINT_oct2point:
  203|     15|                       const uint8_t *buf, size_t len, BN_CTX *ctx) {
  204|     15|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (204:7): [True: 0, False: 15]
  ------------------
  205|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  206|      0|    return 0;
  207|      0|  }
  208|     15|  return ec_GFp_simple_oct2point(group, point, buf, len, ctx);
  209|     15|}
bcm.c:ec_GFp_simple_oct2point:
  138|     15|                                   BN_CTX *ctx) {
  139|     15|  if (len == 0) {
  ------------------
  |  Branch (139:7): [True: 0, False: 15]
  ------------------
  140|      0|    OPENSSL_PUT_ERROR(EC, EC_R_BUFFER_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|       |
  144|     15|  point_conversion_form_t form = buf[0];
  145|     15|  if (form == POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (145:7): [True: 4, False: 11]
  ------------------
  146|      4|    EC_AFFINE affine;
  147|      4|    if (!ec_point_from_uncompressed(group, &affine, buf, len)) {
  ------------------
  |  Branch (147:9): [True: 4, False: 0]
  ------------------
  148|       |      // In the event of an error, defend against the caller not checking the
  149|       |      // return value by setting a known safe value.
  150|      4|      ec_set_to_safe_point(group, &point->raw);
  151|      4|      return 0;
  152|      4|    }
  153|      0|    ec_affine_to_jacobian(group, &point->raw, &affine);
  154|      0|    return 1;
  155|      4|  }
  156|       |
  157|     11|  const int y_bit = form & 1;
  158|     11|  const size_t field_len = BN_num_bytes(&group->field);
  159|     11|  form = form & ~1u;
  160|     11|  if (form != POINT_CONVERSION_COMPRESSED ||
  ------------------
  |  Branch (160:7): [True: 8, False: 3]
  ------------------
  161|     11|      len != 1 /* type byte */ + field_len) {
  ------------------
  |  Branch (161:7): [True: 3, False: 0]
  ------------------
  162|     11|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|     11|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|     11|    return 0;
  164|     11|  }
  165|       |
  166|       |  // TODO(davidben): Integrate compressed coordinates with the lower-level EC
  167|       |  // abstractions. This requires a way to compute square roots, which is tricky
  168|       |  // for primes which are not 3 (mod 4), namely P-224 and custom curves. P-224's
  169|       |  // prime is particularly inconvenient for compressed coordinates. See
  170|       |  // https://cr.yp.to/papers/sqroot.pdf
  171|      0|  BN_CTX *new_ctx = NULL;
  172|      0|  if (ctx == NULL) {
  ------------------
  |  Branch (172:7): [True: 0, False: 0]
  ------------------
  173|      0|    ctx = new_ctx = BN_CTX_new();
  174|      0|    if (ctx == NULL) {
  ------------------
  |  Branch (174:9): [True: 0, False: 0]
  ------------------
  175|      0|      return 0;
  176|      0|    }
  177|      0|  }
  178|       |
  179|      0|  int ret = 0;
  180|      0|  BN_CTX_start(ctx);
  181|      0|  BIGNUM *x = BN_CTX_get(ctx);
  182|      0|  if (x == NULL || !BN_bin2bn(buf + 1, field_len, x)) {
  ------------------
  |  Branch (182:7): [True: 0, False: 0]
  |  Branch (182:20): [True: 0, False: 0]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|      0|  if (BN_ucmp(x, &group->field) >= 0) {
  ------------------
  |  Branch (185:7): [True: 0, False: 0]
  ------------------
  186|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  187|      0|    goto err;
  188|      0|  }
  189|       |
  190|      0|  if (!EC_POINT_set_compressed_coordinates_GFp(group, point, x, y_bit, ctx)) {
  ------------------
  |  Branch (190:7): [True: 0, False: 0]
  ------------------
  191|      0|    goto err;
  192|      0|  }
  193|       |
  194|      0|  ret = 1;
  195|       |
  196|      0|err:
  197|      0|  BN_CTX_end(ctx);
  198|      0|  BN_CTX_free(new_ctx);
  199|      0|  return ret;
  200|      0|}

bcm.c:EC_GFp_nistp224_method_do_init:
 1144|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_nistp224_method) {
 1145|      1|  out->group_init = ec_GFp_simple_group_init;
 1146|      1|  out->group_finish = ec_GFp_simple_group_finish;
 1147|      1|  out->group_set_curve = ec_GFp_simple_group_set_curve;
 1148|      1|  out->point_get_affine_coordinates =
 1149|      1|      ec_GFp_nistp224_point_get_affine_coordinates;
 1150|      1|  out->add = ec_GFp_nistp224_add;
 1151|      1|  out->dbl = ec_GFp_nistp224_dbl;
 1152|      1|  out->mul = ec_GFp_nistp224_point_mul;
 1153|      1|  out->mul_base = ec_GFp_nistp224_point_mul_base;
 1154|      1|  out->mul_public = ec_GFp_nistp224_point_mul_public;
 1155|      1|  out->felem_mul = ec_GFp_nistp224_felem_mul;
 1156|      1|  out->felem_sqr = ec_GFp_nistp224_felem_sqr;
 1157|      1|  out->felem_to_bytes = ec_GFp_simple_felem_to_bytes;
 1158|      1|  out->felem_from_bytes = ec_GFp_simple_felem_from_bytes;
 1159|      1|  out->scalar_inv0_montgomery = ec_simple_scalar_inv0_montgomery;
 1160|      1|  out->scalar_to_montgomery_inv_vartime =
 1161|      1|      ec_simple_scalar_to_montgomery_inv_vartime;
 1162|      1|  out->cmp_x_coordinate = ec_GFp_simple_cmp_x_coordinate;
 1163|      1|}
bcm.c:p224_generic_to_felem:
  181|  1.75k|static void p224_generic_to_felem(p224_felem out, const EC_FELEM *in) {
  182|       |  // |p224_felem|'s minimal representation uses four 56-bit words. |EC_FELEM|
  183|       |  // uses four 64-bit words. (The top-most word only has 32 bits.)
  184|  1.75k|  out[0] = in->words[0] & 0x00ffffffffffffff;
  185|  1.75k|  out[1] = ((in->words[0] >> 56) | (in->words[1] << 8)) & 0x00ffffffffffffff;
  186|  1.75k|  out[2] = ((in->words[1] >> 48) | (in->words[2] << 16)) & 0x00ffffffffffffff;
  187|  1.75k|  out[3] = ((in->words[2] >> 40) | (in->words[3] << 24)) & 0x00ffffffffffffff;
  188|  1.75k|}
bcm.c:p224_felem_square:
  364|  27.8k|static void p224_felem_square(p224_widefelem out, const p224_felem in) {
  365|  27.8k|  p224_limb tmp0, tmp1, tmp2;
  366|  27.8k|  tmp0 = 2 * in[0];
  367|  27.8k|  tmp1 = 2 * in[1];
  368|  27.8k|  tmp2 = 2 * in[2];
  369|  27.8k|  out[0] = ((p224_widelimb)in[0]) * in[0];
  370|  27.8k|  out[1] = ((p224_widelimb)in[0]) * tmp1;
  371|  27.8k|  out[2] = ((p224_widelimb)in[0]) * tmp2 + ((p224_widelimb)in[1]) * in[1];
  372|  27.8k|  out[3] = ((p224_widelimb)in[3]) * tmp0 + ((p224_widelimb)in[1]) * tmp2;
  373|  27.8k|  out[4] = ((p224_widelimb)in[3]) * tmp1 + ((p224_widelimb)in[2]) * in[2];
  374|  27.8k|  out[5] = ((p224_widelimb)in[3]) * tmp2;
  375|  27.8k|  out[6] = ((p224_widelimb)in[3]) * in[3];
  376|  27.8k|}
bcm.c:p224_felem_reduce:
  396|  68.4k|static void p224_felem_reduce(p224_felem out, const p224_widefelem in) {
  397|  68.4k|  static const p224_widelimb two127p15 =
  398|  68.4k|      (((p224_widelimb)1) << 127) + (((p224_widelimb)1) << 15);
  399|  68.4k|  static const p224_widelimb two127m71 =
  400|  68.4k|      (((p224_widelimb)1) << 127) - (((p224_widelimb)1) << 71);
  401|  68.4k|  static const p224_widelimb two127m71m55 = (((p224_widelimb)1) << 127) -
  402|  68.4k|                                            (((p224_widelimb)1) << 71) -
  403|  68.4k|                                            (((p224_widelimb)1) << 55);
  404|  68.4k|  p224_widelimb output[5];
  405|       |
  406|       |  // Add 0 mod 2^224-2^96+1 to ensure all differences are positive
  407|  68.4k|  output[0] = in[0] + two127p15;
  408|  68.4k|  output[1] = in[1] + two127m71m55;
  409|  68.4k|  output[2] = in[2] + two127m71;
  410|  68.4k|  output[3] = in[3];
  411|  68.4k|  output[4] = in[4];
  412|       |
  413|       |  // Eliminate in[4], in[5], in[6]
  414|  68.4k|  output[4] += in[6] >> 16;
  415|  68.4k|  output[3] += (in[6] & 0xffff) << 40;
  416|  68.4k|  output[2] -= in[6];
  417|       |
  418|  68.4k|  output[3] += in[5] >> 16;
  419|  68.4k|  output[2] += (in[5] & 0xffff) << 40;
  420|  68.4k|  output[1] -= in[5];
  421|       |
  422|  68.4k|  output[2] += output[4] >> 16;
  423|  68.4k|  output[1] += (output[4] & 0xffff) << 40;
  424|  68.4k|  output[0] -= output[4];
  425|       |
  426|       |  // Carry 2 -> 3 -> 4
  427|  68.4k|  output[3] += output[2] >> 56;
  428|  68.4k|  output[2] &= 0x00ffffffffffffff;
  429|       |
  430|  68.4k|  output[4] = output[3] >> 56;
  431|  68.4k|  output[3] &= 0x00ffffffffffffff;
  432|       |
  433|       |  // Now output[2] < 2^56, output[3] < 2^56, output[4] < 2^72
  434|       |
  435|       |  // Eliminate output[4]
  436|  68.4k|  output[2] += output[4] >> 16;
  437|       |  // output[2] < 2^56 + 2^56 = 2^57
  438|  68.4k|  output[1] += (output[4] & 0xffff) << 40;
  439|  68.4k|  output[0] -= output[4];
  440|       |
  441|       |  // Carry 0 -> 1 -> 2 -> 3
  442|  68.4k|  output[1] += output[0] >> 56;
  443|  68.4k|  out[0] = output[0] & 0x00ffffffffffffff;
  444|       |
  445|  68.4k|  output[2] += output[1] >> 56;
  446|       |  // output[2] < 2^57 + 2^72
  447|  68.4k|  out[1] = output[1] & 0x00ffffffffffffff;
  448|  68.4k|  output[3] += output[2] >> 56;
  449|       |  // output[3] <= 2^56 + 2^16
  450|  68.4k|  out[2] = output[2] & 0x00ffffffffffffff;
  451|       |
  452|       |  // out[0] < 2^56, out[1] < 2^56, out[2] < 2^56,
  453|       |  // out[3] <= 2^56 + 2^16 (due to final carry),
  454|       |  // so out < 2*p
  455|  68.4k|  out[3] = output[3];
  456|  68.4k|}
bcm.c:p224_felem_mul:
  380|  48.0k|                           const p224_felem in2) {
  381|  48.0k|  out[0] = ((p224_widelimb)in1[0]) * in2[0];
  382|  48.0k|  out[1] = ((p224_widelimb)in1[0]) * in2[1] + ((p224_widelimb)in1[1]) * in2[0];
  383|  48.0k|  out[2] = ((p224_widelimb)in1[0]) * in2[2] + ((p224_widelimb)in1[1]) * in2[1] +
  384|  48.0k|           ((p224_widelimb)in1[2]) * in2[0];
  385|  48.0k|  out[3] = ((p224_widelimb)in1[0]) * in2[3] + ((p224_widelimb)in1[1]) * in2[2] +
  386|  48.0k|           ((p224_widelimb)in1[2]) * in2[1] + ((p224_widelimb)in1[3]) * in2[0];
  387|  48.0k|  out[4] = ((p224_widelimb)in1[1]) * in2[3] + ((p224_widelimb)in1[2]) * in2[2] +
  388|  48.0k|           ((p224_widelimb)in1[3]) * in2[1];
  389|  48.0k|  out[5] = ((p224_widelimb)in1[2]) * in2[3] + ((p224_widelimb)in1[3]) * in2[2];
  390|  48.0k|  out[6] = ((p224_widelimb)in1[3]) * in2[3];
  391|  48.0k|}
bcm.c:p224_felem_to_generic:
  191|  1.43k|static void p224_felem_to_generic(EC_FELEM *out, const p224_felem in) {
  192|       |  // Reduce to unique minimal representation.
  193|  1.43k|  static const int64_t two56 = ((p224_limb)1) << 56;
  194|       |  // 0 <= in < 2*p, p = 2^224 - 2^96 + 1
  195|       |  // if in > p , reduce in = in - 2^224 + 2^96 - 1
  196|  1.43k|  int64_t tmp[4], a;
  197|  1.43k|  tmp[0] = in[0];
  198|  1.43k|  tmp[1] = in[1];
  199|  1.43k|  tmp[2] = in[2];
  200|  1.43k|  tmp[3] = in[3];
  201|       |  // Case 1: a = 1 iff in >= 2^224
  202|  1.43k|  a = (in[3] >> 56);
  203|  1.43k|  tmp[0] -= a;
  204|  1.43k|  tmp[1] += a << 40;
  205|  1.43k|  tmp[3] &= 0x00ffffffffffffff;
  206|       |  // Case 2: a = 0 iff p <= in < 2^224, i.e., the high 128 bits are all 1 and
  207|       |  // the lower part is non-zero
  208|  1.43k|  a = ((in[3] & in[2] & (in[1] | 0x000000ffffffffff)) + 1) |
  209|  1.43k|      (((int64_t)(in[0] + (in[1] & 0x000000ffffffffff)) - 1) >> 63);
  210|  1.43k|  a &= 0x00ffffffffffffff;
  211|       |  // turn a into an all-one mask (if a = 0) or an all-zero mask
  212|  1.43k|  a = (a - 1) >> 63;
  213|       |  // subtract 2^224 - 2^96 + 1 if a is all-one
  214|  1.43k|  tmp[3] &= a ^ 0xffffffffffffffff;
  215|  1.43k|  tmp[2] &= a ^ 0xffffffffffffffff;
  216|  1.43k|  tmp[1] &= (a ^ 0xffffffffffffffff) | 0x000000ffffffffff;
  217|  1.43k|  tmp[0] -= 1 & a;
  218|       |
  219|       |  // eliminate negative coefficients: if tmp[0] is negative, tmp[1] must
  220|       |  // be non-zero, so we only need one step
  221|  1.43k|  a = tmp[0] >> 63;
  222|  1.43k|  tmp[0] += two56 & a;
  223|  1.43k|  tmp[1] -= 1 & a;
  224|       |
  225|       |  // carry 1 -> 2 -> 3
  226|  1.43k|  tmp[2] += tmp[1] >> 56;
  227|  1.43k|  tmp[1] &= 0x00ffffffffffffff;
  228|       |
  229|  1.43k|  tmp[3] += tmp[2] >> 56;
  230|  1.43k|  tmp[2] &= 0x00ffffffffffffff;
  231|       |
  232|       |  // Now 0 <= tmp < p
  233|  1.43k|  p224_felem tmp2;
  234|  1.43k|  tmp2[0] = tmp[0];
  235|  1.43k|  tmp2[1] = tmp[1];
  236|  1.43k|  tmp2[2] = tmp[2];
  237|  1.43k|  tmp2[3] = tmp[3];
  238|       |
  239|       |  // |p224_felem|'s minimal representation uses four 56-bit words. |EC_FELEM|
  240|       |  // uses four 64-bit words. (The top-most word only has 32 bits.)
  241|  1.43k|  out->words[0] = tmp2[0] | (tmp2[1] << 56);
  242|  1.43k|  out->words[1] = (tmp2[1] >> 8) | (tmp2[2] << 48);
  243|  1.43k|  out->words[2] = (tmp2[2] >> 16) | (tmp2[3] << 40);
  244|  1.43k|  out->words[3] = tmp2[3] >> 24;
  245|  1.43k|}
bcm.c:p224_point_add:
  680|  5.00k|                           const p224_felem z2) {
  681|  5.00k|  p224_felem ftmp, ftmp2, ftmp3, ftmp4, ftmp5, x_out, y_out, z_out;
  682|  5.00k|  p224_widefelem tmp, tmp2;
  683|  5.00k|  p224_limb z1_is_zero, z2_is_zero, x_equal, y_equal;
  684|       |
  685|  5.00k|  if (!mixed) {
  ------------------
  |  Branch (685:7): [True: 0, False: 5.00k]
  ------------------
  686|       |    // ftmp2 = z2^2
  687|      0|    p224_felem_square(tmp, z2);
  688|      0|    p224_felem_reduce(ftmp2, tmp);
  689|       |
  690|       |    // ftmp4 = z2^3
  691|      0|    p224_felem_mul(tmp, ftmp2, z2);
  692|      0|    p224_felem_reduce(ftmp4, tmp);
  693|       |
  694|       |    // ftmp4 = z2^3*y1
  695|      0|    p224_felem_mul(tmp2, ftmp4, y1);
  696|      0|    p224_felem_reduce(ftmp4, tmp2);
  697|       |
  698|       |    // ftmp2 = z2^2*x1
  699|      0|    p224_felem_mul(tmp2, ftmp2, x1);
  700|      0|    p224_felem_reduce(ftmp2, tmp2);
  701|  5.00k|  } else {
  702|       |    // We'll assume z2 = 1 (special case z2 = 0 is handled later)
  703|       |
  704|       |    // ftmp4 = z2^3*y1
  705|  5.00k|    p224_felem_assign(ftmp4, y1);
  706|       |
  707|       |    // ftmp2 = z2^2*x1
  708|  5.00k|    p224_felem_assign(ftmp2, x1);
  709|  5.00k|  }
  710|       |
  711|       |  // ftmp = z1^2
  712|  5.00k|  p224_felem_square(tmp, z1);
  713|  5.00k|  p224_felem_reduce(ftmp, tmp);
  714|       |
  715|       |  // ftmp3 = z1^3
  716|  5.00k|  p224_felem_mul(tmp, ftmp, z1);
  717|  5.00k|  p224_felem_reduce(ftmp3, tmp);
  718|       |
  719|       |  // tmp = z1^3*y2
  720|  5.00k|  p224_felem_mul(tmp, ftmp3, y2);
  721|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  722|       |
  723|       |  // ftmp3 = z1^3*y2 - z2^3*y1
  724|  5.00k|  p224_felem_diff_128_64(tmp, ftmp4);
  725|       |  // tmp[i] < 2^116 + 2^64 + 8 < 2^117
  726|  5.00k|  p224_felem_reduce(ftmp3, tmp);
  727|       |
  728|       |  // tmp = z1^2*x2
  729|  5.00k|  p224_felem_mul(tmp, ftmp, x2);
  730|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  731|       |
  732|       |  // ftmp = z1^2*x2 - z2^2*x1
  733|  5.00k|  p224_felem_diff_128_64(tmp, ftmp2);
  734|       |  // tmp[i] < 2^116 + 2^64 + 8 < 2^117
  735|  5.00k|  p224_felem_reduce(ftmp, tmp);
  736|       |
  737|       |  // The formulae are incorrect if the points are equal, so we check for this
  738|       |  // and do doubling if this happens.
  739|  5.00k|  x_equal = p224_felem_is_zero(ftmp);
  740|  5.00k|  y_equal = p224_felem_is_zero(ftmp3);
  741|  5.00k|  z1_is_zero = p224_felem_is_zero(z1);
  742|  5.00k|  z2_is_zero = p224_felem_is_zero(z2);
  743|       |  // In affine coordinates, (X_1, Y_1) == (X_2, Y_2)
  744|  5.00k|  p224_limb is_nontrivial_double =
  745|  5.00k|      x_equal & y_equal & (1 - z1_is_zero) & (1 - z2_is_zero);
  746|  5.00k|  if (constant_time_declassify_w(is_nontrivial_double)) {
  ------------------
  |  Branch (746:7): [True: 0, False: 5.00k]
  ------------------
  747|      0|    p224_point_double(x3, y3, z3, x1, y1, z1);
  748|      0|    return;
  749|      0|  }
  750|       |
  751|       |  // ftmp5 = z1*z2
  752|  5.00k|  if (!mixed) {
  ------------------
  |  Branch (752:7): [True: 0, False: 5.00k]
  ------------------
  753|      0|    p224_felem_mul(tmp, z1, z2);
  754|      0|    p224_felem_reduce(ftmp5, tmp);
  755|  5.00k|  } else {
  756|       |    // special case z2 = 0 is handled later
  757|  5.00k|    p224_felem_assign(ftmp5, z1);
  758|  5.00k|  }
  759|       |
  760|       |  // z_out = (z1^2*x2 - z2^2*x1)*(z1*z2)
  761|  5.00k|  p224_felem_mul(tmp, ftmp, ftmp5);
  762|  5.00k|  p224_felem_reduce(z_out, tmp);
  763|       |
  764|       |  // ftmp = (z1^2*x2 - z2^2*x1)^2
  765|  5.00k|  p224_felem_assign(ftmp5, ftmp);
  766|  5.00k|  p224_felem_square(tmp, ftmp);
  767|  5.00k|  p224_felem_reduce(ftmp, tmp);
  768|       |
  769|       |  // ftmp5 = (z1^2*x2 - z2^2*x1)^3
  770|  5.00k|  p224_felem_mul(tmp, ftmp, ftmp5);
  771|  5.00k|  p224_felem_reduce(ftmp5, tmp);
  772|       |
  773|       |  // ftmp2 = z2^2*x1*(z1^2*x2 - z2^2*x1)^2
  774|  5.00k|  p224_felem_mul(tmp, ftmp2, ftmp);
  775|  5.00k|  p224_felem_reduce(ftmp2, tmp);
  776|       |
  777|       |  // tmp = z2^3*y1*(z1^2*x2 - z2^2*x1)^3
  778|  5.00k|  p224_felem_mul(tmp, ftmp4, ftmp5);
  779|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  780|       |
  781|       |  // tmp2 = (z1^3*y2 - z2^3*y1)^2
  782|  5.00k|  p224_felem_square(tmp2, ftmp3);
  783|       |  // tmp2[i] < 4 * 2^57 * 2^57 < 2^116
  784|       |
  785|       |  // tmp2 = (z1^3*y2 - z2^3*y1)^2 - (z1^2*x2 - z2^2*x1)^3
  786|  5.00k|  p224_felem_diff_128_64(tmp2, ftmp5);
  787|       |  // tmp2[i] < 2^116 + 2^64 + 8 < 2^117
  788|       |
  789|       |  // ftmp5 = 2*z2^2*x1*(z1^2*x2 - z2^2*x1)^2
  790|  5.00k|  p224_felem_assign(ftmp5, ftmp2);
  791|  5.00k|  p224_felem_scalar(ftmp5, 2);
  792|       |  // ftmp5[i] < 2 * 2^57 = 2^58
  793|       |
  794|       |  /* x_out = (z1^3*y2 - z2^3*y1)^2 - (z1^2*x2 - z2^2*x1)^3 -
  795|       |     2*z2^2*x1*(z1^2*x2 - z2^2*x1)^2 */
  796|  5.00k|  p224_felem_diff_128_64(tmp2, ftmp5);
  797|       |  // tmp2[i] < 2^117 + 2^64 + 8 < 2^118
  798|  5.00k|  p224_felem_reduce(x_out, tmp2);
  799|       |
  800|       |  // ftmp2 = z2^2*x1*(z1^2*x2 - z2^2*x1)^2 - x_out
  801|  5.00k|  p224_felem_diff(ftmp2, x_out);
  802|       |  // ftmp2[i] < 2^57 + 2^58 + 2 < 2^59
  803|       |
  804|       |  // tmp2 = (z1^3*y2 - z2^3*y1)*(z2^2*x1*(z1^2*x2 - z2^2*x1)^2 - x_out)
  805|  5.00k|  p224_felem_mul(tmp2, ftmp3, ftmp2);
  806|       |  // tmp2[i] < 4 * 2^57 * 2^59 = 2^118
  807|       |
  808|       |  /* y_out = (z1^3*y2 - z2^3*y1)*(z2^2*x1*(z1^2*x2 - z2^2*x1)^2 - x_out) -
  809|       |     z2^3*y1*(z1^2*x2 - z2^2*x1)^3 */
  810|  5.00k|  p224_widefelem_diff(tmp2, tmp);
  811|       |  // tmp2[i] < 2^118 + 2^120 < 2^121
  812|  5.00k|  p224_felem_reduce(y_out, tmp2);
  813|       |
  814|       |  // the result (x_out, y_out, z_out) is incorrect if one of the inputs is
  815|       |  // the point at infinity, so we need to check for this separately
  816|       |
  817|       |  // if point 1 is at infinity, copy point 2 to output, and vice versa
  818|  5.00k|  p224_copy_conditional(x_out, x2, z1_is_zero);
  819|  5.00k|  p224_copy_conditional(x_out, x1, z2_is_zero);
  820|  5.00k|  p224_copy_conditional(y_out, y2, z1_is_zero);
  821|  5.00k|  p224_copy_conditional(y_out, y1, z2_is_zero);
  822|  5.00k|  p224_copy_conditional(z_out, z2, z1_is_zero);
  823|  5.00k|  p224_copy_conditional(z_out, z1, z2_is_zero);
  824|  5.00k|  p224_felem_assign(x3, x_out);
  825|  5.00k|  p224_felem_assign(y3, y_out);
  826|  5.00k|  p224_felem_assign(z3, z_out);
  827|  5.00k|}
bcm.c:p224_felem_assign:
  253|  49.8k|static void p224_felem_assign(p224_felem out, const p224_felem in) {
  254|  49.8k|  out[0] = in[0];
  255|  49.8k|  out[1] = in[1];
  256|  49.8k|  out[2] = in[2];
  257|  49.8k|  out[3] = in[3];
  258|  49.8k|}
bcm.c:p224_felem_diff_128_64:
  320|  24.9k|static void p224_felem_diff_128_64(p224_widefelem out, const p224_felem in) {
  321|  24.9k|  static const p224_widelimb two64p8 =
  322|  24.9k|      (((p224_widelimb)1) << 64) + (((p224_widelimb)1) << 8);
  323|  24.9k|  static const p224_widelimb two64m8 =
  324|  24.9k|      (((p224_widelimb)1) << 64) - (((p224_widelimb)1) << 8);
  325|  24.9k|  static const p224_widelimb two64m48m8 = (((p224_widelimb)1) << 64) -
  326|  24.9k|                                          (((p224_widelimb)1) << 48) -
  327|  24.9k|                                          (((p224_widelimb)1) << 8);
  328|       |
  329|       |  // Add 0 mod 2^224-2^96+1 to ensure out > in
  330|  24.9k|  out[0] += two64p8;
  331|  24.9k|  out[1] += two64m48m8;
  332|  24.9k|  out[2] += two64m8;
  333|  24.9k|  out[3] += two64m8;
  334|       |
  335|  24.9k|  out[0] -= in[0];
  336|  24.9k|  out[1] -= in[1];
  337|  24.9k|  out[2] -= in[2];
  338|  24.9k|  out[3] -= in[3];
  339|  24.9k|}
bcm.c:p224_felem_is_zero:
  470|  20.0k|static p224_limb p224_felem_is_zero(const p224_felem in) {
  471|  20.0k|  p224_limb zero = in[0] | in[1] | in[2] | in[3];
  472|  20.0k|  zero = (((int64_t)(zero)-1) >> 63) & 1;
  473|       |
  474|  20.0k|  p224_limb two224m96p1 = (in[0] ^ 1) | (in[1] ^ 0x00ffff0000000000) |
  475|  20.0k|                     (in[2] ^ 0x00ffffffffffffff) |
  476|  20.0k|                     (in[3] ^ 0x00ffffffffffffff);
  477|  20.0k|  two224m96p1 = (((int64_t)(two224m96p1)-1) >> 63) & 1;
  478|  20.0k|  p224_limb two225m97p2 = (in[0] ^ 2) | (in[1] ^ 0x00fffe0000000000) |
  479|  20.0k|                     (in[2] ^ 0x00ffffffffffffff) |
  480|  20.0k|                     (in[3] ^ 0x01ffffffffffffff);
  481|  20.0k|  two225m97p2 = (((int64_t)(two225m97p2)-1) >> 63) & 1;
  482|  20.0k|  return (zero | two224m96p1 | two225m97p2);
  483|  20.0k|}
bcm.c:p224_point_double:
  593|  2.45k|                              const p224_felem y_in, const p224_felem z_in) {
  594|  2.45k|  p224_widefelem tmp, tmp2;
  595|  2.45k|  p224_felem delta, gamma, beta, alpha, ftmp, ftmp2;
  596|       |
  597|  2.45k|  p224_felem_assign(ftmp, x_in);
  598|  2.45k|  p224_felem_assign(ftmp2, x_in);
  599|       |
  600|       |  // delta = z^2
  601|  2.45k|  p224_felem_square(tmp, z_in);
  602|  2.45k|  p224_felem_reduce(delta, tmp);
  603|       |
  604|       |  // gamma = y^2
  605|  2.45k|  p224_felem_square(tmp, y_in);
  606|  2.45k|  p224_felem_reduce(gamma, tmp);
  607|       |
  608|       |  // beta = x*gamma
  609|  2.45k|  p224_felem_mul(tmp, x_in, gamma);
  610|  2.45k|  p224_felem_reduce(beta, tmp);
  611|       |
  612|       |  // alpha = 3*(x-delta)*(x+delta)
  613|  2.45k|  p224_felem_diff(ftmp, delta);
  614|       |  // ftmp[i] < 2^57 + 2^58 + 2 < 2^59
  615|  2.45k|  p224_felem_sum(ftmp2, delta);
  616|       |  // ftmp2[i] < 2^57 + 2^57 = 2^58
  617|  2.45k|  p224_felem_scalar(ftmp2, 3);
  618|       |  // ftmp2[i] < 3 * 2^58 < 2^60
  619|  2.45k|  p224_felem_mul(tmp, ftmp, ftmp2);
  620|       |  // tmp[i] < 2^60 * 2^59 * 4 = 2^121
  621|  2.45k|  p224_felem_reduce(alpha, tmp);
  622|       |
  623|       |  // x' = alpha^2 - 8*beta
  624|  2.45k|  p224_felem_square(tmp, alpha);
  625|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  626|  2.45k|  p224_felem_assign(ftmp, beta);
  627|  2.45k|  p224_felem_scalar(ftmp, 8);
  628|       |  // ftmp[i] < 8 * 2^57 = 2^60
  629|  2.45k|  p224_felem_diff_128_64(tmp, ftmp);
  630|       |  // tmp[i] < 2^116 + 2^64 + 8 < 2^117
  631|  2.45k|  p224_felem_reduce(x_out, tmp);
  632|       |
  633|       |  // z' = (y + z)^2 - gamma - delta
  634|  2.45k|  p224_felem_sum(delta, gamma);
  635|       |  // delta[i] < 2^57 + 2^57 = 2^58
  636|  2.45k|  p224_felem_assign(ftmp, y_in);
  637|  2.45k|  p224_felem_sum(ftmp, z_in);
  638|       |  // ftmp[i] < 2^57 + 2^57 = 2^58
  639|  2.45k|  p224_felem_square(tmp, ftmp);
  640|       |  // tmp[i] < 4 * 2^58 * 2^58 = 2^118
  641|  2.45k|  p224_felem_diff_128_64(tmp, delta);
  642|       |  // tmp[i] < 2^118 + 2^64 + 8 < 2^119
  643|  2.45k|  p224_felem_reduce(z_out, tmp);
  644|       |
  645|       |  // y' = alpha*(4*beta - x') - 8*gamma^2
  646|  2.45k|  p224_felem_scalar(beta, 4);
  647|       |  // beta[i] < 4 * 2^57 = 2^59
  648|  2.45k|  p224_felem_diff(beta, x_out);
  649|       |  // beta[i] < 2^59 + 2^58 + 2 < 2^60
  650|  2.45k|  p224_felem_mul(tmp, alpha, beta);
  651|       |  // tmp[i] < 4 * 2^57 * 2^60 = 2^119
  652|  2.45k|  p224_felem_square(tmp2, gamma);
  653|       |  // tmp2[i] < 4 * 2^57 * 2^57 = 2^116
  654|  2.45k|  p224_widefelem_scalar(tmp2, 8);
  655|       |  // tmp2[i] < 8 * 2^116 = 2^119
  656|  2.45k|  p224_widefelem_diff(tmp, tmp2);
  657|       |  // tmp[i] < 2^119 + 2^120 < 2^121
  658|  2.45k|  p224_felem_reduce(y_out, tmp);
  659|  2.45k|}
bcm.c:p224_felem_sum:
  261|  7.37k|static void p224_felem_sum(p224_felem out, const p224_felem in) {
  262|  7.37k|  out[0] += in[0];
  263|  7.37k|  out[1] += in[1];
  264|  7.37k|  out[2] += in[2];
  265|  7.37k|  out[3] += in[3];
  266|  7.37k|}
bcm.c:p224_widefelem_scalar:
  353|  2.45k|                                  const p224_widelimb scalar) {
  354|  2.45k|  out[0] *= scalar;
  355|  2.45k|  out[1] *= scalar;
  356|  2.45k|  out[2] *= scalar;
  357|  2.45k|  out[3] *= scalar;
  358|  2.45k|  out[4] *= scalar;
  359|  2.45k|  out[5] *= scalar;
  360|  2.45k|  out[6] *= scalar;
  361|  2.45k|}
bcm.c:p224_felem_scalar:
  343|  12.3k|static void p224_felem_scalar(p224_felem out, const p224_limb scalar) {
  344|  12.3k|  out[0] *= scalar;
  345|  12.3k|  out[1] *= scalar;
  346|  12.3k|  out[2] *= scalar;
  347|  12.3k|  out[3] *= scalar;
  348|  12.3k|}
bcm.c:p224_felem_diff:
  270|  9.91k|static void p224_felem_diff(p224_felem out, const p224_felem in) {
  271|  9.91k|  static const p224_limb two58p2 =
  272|  9.91k|      (((p224_limb)1) << 58) + (((p224_limb)1) << 2);
  273|  9.91k|  static const p224_limb two58m2 =
  274|  9.91k|      (((p224_limb)1) << 58) - (((p224_limb)1) << 2);
  275|  9.91k|  static const p224_limb two58m42m2 =
  276|  9.91k|      (((p224_limb)1) << 58) - (((p224_limb)1) << 42) - (((p224_limb)1) << 2);
  277|       |
  278|       |  // Add 0 mod 2^224-2^96+1 to ensure out > in
  279|  9.91k|  out[0] += two58p2;
  280|  9.91k|  out[1] += two58m42m2;
  281|  9.91k|  out[2] += two58m2;
  282|  9.91k|  out[3] += two58m2;
  283|       |
  284|  9.91k|  out[0] -= in[0];
  285|  9.91k|  out[1] -= in[1];
  286|  9.91k|  out[2] -= in[2];
  287|  9.91k|  out[3] -= in[3];
  288|  9.91k|}
bcm.c:p224_widefelem_diff:
  292|  7.46k|static void p224_widefelem_diff(p224_widefelem out, const p224_widefelem in) {
  293|  7.46k|  static const p224_widelimb two120 = ((p224_widelimb)1) << 120;
  294|  7.46k|  static const p224_widelimb two120m64 =
  295|  7.46k|      (((p224_widelimb)1) << 120) - (((p224_widelimb)1) << 64);
  296|  7.46k|  static const p224_widelimb two120m104m64 = (((p224_widelimb)1) << 120) -
  297|  7.46k|                                             (((p224_widelimb)1) << 104) -
  298|  7.46k|                                             (((p224_widelimb)1) << 64);
  299|       |
  300|       |  // Add 0 mod 2^224-2^96+1 to ensure out > in
  301|  7.46k|  out[0] += two120;
  302|  7.46k|  out[1] += two120m64;
  303|  7.46k|  out[2] += two120m64;
  304|  7.46k|  out[3] += two120;
  305|  7.46k|  out[4] += two120m104m64;
  306|  7.46k|  out[5] += two120m64;
  307|  7.46k|  out[6] += two120m64;
  308|       |
  309|  7.46k|  out[0] -= in[0];
  310|  7.46k|  out[1] -= in[1];
  311|  7.46k|  out[2] -= in[2];
  312|  7.46k|  out[3] -= in[3];
  313|  7.46k|  out[4] -= in[4];
  314|  7.46k|  out[5] -= in[5];
  315|  7.46k|  out[6] -= in[6];
  316|  7.46k|}
bcm.c:p224_copy_conditional:
  569|  30.0k|                                  p224_limb icopy) {
  570|       |  // icopy is a (64-bit) 0 or 1, so copy is either all-zero or all-one
  571|  30.0k|  const p224_limb copy = -icopy;
  572|   150k|  for (size_t i = 0; i < 4; ++i) {
  ------------------
  |  Branch (572:22): [True: 120k, False: 30.0k]
  ------------------
  573|   120k|    const p224_limb tmp = copy & (in[i] ^ out[i]);
  574|   120k|    out[i] ^= tmp;
  575|   120k|  }
  576|  30.0k|}
bcm.c:p224_get_bit:
  852|  20.3k|static crypto_word_t p224_get_bit(const EC_SCALAR *in, size_t i) {
  853|  20.3k|  if (i >= 224) {
  ------------------
  |  Branch (853:7): [True: 0, False: 20.3k]
  ------------------
  854|      0|    return 0;
  855|      0|  }
  856|  20.3k|  static_assert(sizeof(in->words[0]) == 8, "BN_ULONG is not 64-bit");
  857|  20.3k|  return (in->words[i >> 6] >> (i & 63)) & 1;
  858|  20.3k|}
bcm.c:p224_select_point:
  833|  5.09k|                              p224_felem out[3]) {
  834|  5.09k|  p224_limb *outlimbs = &out[0][0];
  835|  5.09k|  OPENSSL_memset(outlimbs, 0, 3 * sizeof(p224_felem));
  836|       |
  837|  86.6k|  for (size_t i = 0; i < size; i++) {
  ------------------
  |  Branch (837:22): [True: 81.5k, False: 5.09k]
  ------------------
  838|  81.5k|    const p224_limb *inlimbs = &pre_comp[i][0][0];
  839|  81.5k|    uint64_t mask = i ^ idx;
  840|  81.5k|    mask |= mask >> 4;
  841|  81.5k|    mask |= mask >> 2;
  842|  81.5k|    mask |= mask >> 1;
  843|  81.5k|    mask &= 1;
  844|  81.5k|    mask--;
  845|  1.05M|    for (size_t j = 0; j < 4 * 3; j++) {
  ------------------
  |  Branch (845:24): [True: 978k, False: 81.5k]
  ------------------
  846|   978k|      outlimbs[j] |= inlimbs[j] & mask;
  847|   978k|    }
  848|  81.5k|  }
  849|  5.09k|}
bcm.c:ec_GFp_nistp224_point_mul_base:
  997|     91|                                           const EC_SCALAR *scalar) {
  998|       |  // Set nq to the point at infinity.
  999|     91|  p224_felem nq[3], tmp[3];
 1000|     91|  OPENSSL_memset(nq, 0, 3 * sizeof(p224_felem));
 1001|       |
 1002|     91|  int skip = 1;  // Save two point operations in the first round.
 1003|  2.63k|  for (size_t i = 27; i < 28; i--) {
  ------------------
  |  Branch (1003:23): [True: 2.54k, False: 91]
  ------------------
 1004|       |    // double
 1005|  2.54k|    if (!skip) {
  ------------------
  |  Branch (1005:9): [True: 2.45k, False: 91]
  ------------------
 1006|  2.45k|      p224_point_double(nq[0], nq[1], nq[2], nq[0], nq[1], nq[2]);
 1007|  2.45k|    }
 1008|       |
 1009|       |    // First, look 28 bits upwards.
 1010|  2.54k|    crypto_word_t bits = p224_get_bit(scalar, i + 196) << 3;
 1011|  2.54k|    bits |= p224_get_bit(scalar, i + 140) << 2;
 1012|  2.54k|    bits |= p224_get_bit(scalar, i + 84) << 1;
 1013|  2.54k|    bits |= p224_get_bit(scalar, i + 28);
 1014|       |    // Select the point to add, in constant time.
 1015|  2.54k|    p224_select_point(bits, 16, g_p224_pre_comp[1], tmp);
 1016|       |
 1017|  2.54k|    if (!skip) {
  ------------------
  |  Branch (1017:9): [True: 2.45k, False: 91]
  ------------------
 1018|  2.45k|      p224_point_add(nq[0], nq[1], nq[2], nq[0], nq[1], nq[2], 1 /* mixed */,
 1019|  2.45k|                     tmp[0], tmp[1], tmp[2]);
 1020|  2.45k|    } else {
 1021|     91|      OPENSSL_memcpy(nq, tmp, 3 * sizeof(p224_felem));
 1022|     91|      skip = 0;
 1023|     91|    }
 1024|       |
 1025|       |    // Second, look at the current position/
 1026|  2.54k|    bits = p224_get_bit(scalar, i + 168) << 3;
 1027|  2.54k|    bits |= p224_get_bit(scalar, i + 112) << 2;
 1028|  2.54k|    bits |= p224_get_bit(scalar, i + 56) << 1;
 1029|  2.54k|    bits |= p224_get_bit(scalar, i);
 1030|       |    // Select the point to add, in constant time.
 1031|  2.54k|    p224_select_point(bits, 16, g_p224_pre_comp[0], tmp);
 1032|  2.54k|    p224_point_add(nq[0], nq[1], nq[2], nq[0], nq[1], nq[2], 1 /* mixed */,
 1033|  2.54k|                   tmp[0], tmp[1], tmp[2]);
 1034|  2.54k|  }
 1035|       |
 1036|       |  // Reduce the output to its unique minimal representation.
 1037|     91|  p224_felem_to_generic(&r->X, nq[0]);
 1038|     91|  p224_felem_to_generic(&r->Y, nq[1]);
 1039|     91|  p224_felem_to_generic(&r->Z, nq[2]);
 1040|     91|}
bcm.c:ec_GFp_nistp224_felem_mul:
 1124|    589|                                      const EC_FELEM *a, const EC_FELEM *b) {
 1125|    589|  p224_felem felem1, felem2;
 1126|    589|  p224_widefelem wide;
 1127|    589|  p224_generic_to_felem(felem1, a);
 1128|    589|  p224_generic_to_felem(felem2, b);
 1129|    589|  p224_felem_mul(wide, felem1, felem2);
 1130|    589|  p224_felem_reduce(felem1, wide);
 1131|    589|  p224_felem_to_generic(r, felem1);
 1132|    589|}
bcm.c:ec_GFp_nistp224_felem_sqr:
 1135|    576|                                      const EC_FELEM *a) {
 1136|    576|  p224_felem felem;
 1137|    576|  p224_generic_to_felem(felem, a);
 1138|    576|  p224_widefelem wide;
 1139|    576|  p224_felem_square(wide, felem);
 1140|    576|  p224_felem_reduce(felem, wide);
 1141|    576|  p224_felem_to_generic(r, felem);
 1142|    576|}

bcm.c:EC_GFp_nistz256_method_do_init:
  615|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_nistz256_method) {
  616|      1|  out->group_init = ec_GFp_mont_group_init;
  617|      1|  out->group_finish = ec_GFp_mont_group_finish;
  618|      1|  out->group_set_curve = ec_GFp_mont_group_set_curve;
  619|      1|  out->point_get_affine_coordinates = ecp_nistz256_get_affine;
  620|      1|  out->add = ecp_nistz256_add;
  621|      1|  out->dbl = ecp_nistz256_dbl;
  622|      1|  out->mul = ecp_nistz256_point_mul;
  623|      1|  out->mul_base = ecp_nistz256_point_mul_base;
  624|      1|  out->mul_public = ecp_nistz256_points_mul_public;
  625|      1|  out->felem_mul = ec_GFp_mont_felem_mul;
  626|      1|  out->felem_sqr = ec_GFp_mont_felem_sqr;
  627|      1|  out->felem_to_bytes = ec_GFp_mont_felem_to_bytes;
  628|      1|  out->felem_from_bytes = ec_GFp_mont_felem_from_bytes;
  629|      1|  out->felem_reduce = ec_GFp_mont_felem_reduce;
  630|       |  // TODO(davidben): This should use the specialized field arithmetic
  631|       |  // implementation, rather than the generic one.
  632|      1|  out->felem_exp = ec_GFp_mont_felem_exp;
  633|      1|  out->scalar_inv0_montgomery = ecp_nistz256_inv0_mod_ord;
  634|      1|  out->scalar_to_montgomery_inv_vartime =
  635|      1|      ecp_nistz256_scalar_to_montgomery_inv_vartime;
  636|      1|  out->cmp_x_coordinate = ecp_nistz256_cmp_x_coordinate;
  637|      1|}

ec_bignum_to_scalar:
   25|    265|                        const BIGNUM *in) {
   26|    265|  if (!bn_copy_words(out->words, group->order.width, in) ||
  ------------------
  |  Branch (26:7): [True: 0, False: 265]
  ------------------
   27|    265|      !bn_less_than_words(out->words, group->order.d, group->order.width)) {
  ------------------
  |  Branch (27:7): [True: 0, False: 265]
  ------------------
   28|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_SCALAR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   29|      0|    return 0;
   30|      0|  }
   31|    265|  return 1;
   32|    265|}
ec_scalar_is_zero:
   40|    265|int ec_scalar_is_zero(const EC_GROUP *group, const EC_SCALAR *a) {
   41|    265|  BN_ULONG mask = 0;
   42|  1.98k|  for (int i = 0; i < group->order.width; i++) {
  ------------------
  |  Branch (42:19): [True: 1.72k, False: 265]
  ------------------
   43|  1.72k|    mask |= a->words[i];
   44|  1.72k|  }
   45|    265|  return mask == 0;
   46|    265|}

ec_GFp_simple_group_init:
   91|      4|int ec_GFp_simple_group_init(EC_GROUP *group) {
   92|      4|  BN_init(&group->field);
   93|      4|  group->a_is_minus3 = 0;
   94|      4|  return 1;
   95|      4|}
ec_GFp_simple_group_set_curve:
  103|      4|                                  BN_CTX *ctx) {
  104|       |  // p must be a prime > 3
  105|      4|  if (BN_num_bits(p) <= 2 || !BN_is_odd(p)) {
  ------------------
  |  Branch (105:7): [True: 0, False: 4]
  |  Branch (105:30): [True: 0, False: 4]
  ------------------
  106|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_FIELD);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|      4|  int ret = 0;
  111|      4|  BN_CTX_start(ctx);
  112|      4|  BIGNUM *tmp = BN_CTX_get(ctx);
  113|      4|  if (tmp == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 4]
  ------------------
  114|      0|    goto err;
  115|      0|  }
  116|       |
  117|       |  // group->field
  118|      4|  if (!BN_copy(&group->field, p)) {
  ------------------
  |  Branch (118:7): [True: 0, False: 4]
  ------------------
  119|      0|    goto err;
  120|      0|  }
  121|      4|  BN_set_negative(&group->field, 0);
  122|       |  // Store the field in minimal form, so it can be used with |BN_ULONG| arrays.
  123|      4|  bn_set_minimal_width(&group->field);
  124|       |
  125|      4|  if (!ec_bignum_to_felem(group, &group->a, a) ||
  ------------------
  |  Branch (125:7): [True: 0, False: 4]
  ------------------
  126|      4|      !ec_bignum_to_felem(group, &group->b, b) ||
  ------------------
  |  Branch (126:7): [True: 0, False: 4]
  ------------------
  127|      4|      !ec_bignum_to_felem(group, &group->one, BN_value_one())) {
  ------------------
  |  Branch (127:7): [True: 0, False: 4]
  ------------------
  128|      0|    goto err;
  129|      0|  }
  130|       |
  131|       |  // group->a_is_minus3
  132|      4|  if (!BN_copy(tmp, a) ||
  ------------------
  |  Branch (132:7): [True: 0, False: 4]
  ------------------
  133|      4|      !BN_add_word(tmp, 3)) {
  ------------------
  |  Branch (133:7): [True: 0, False: 4]
  ------------------
  134|      0|    goto err;
  135|      0|  }
  136|      4|  group->a_is_minus3 = (0 == BN_cmp(tmp, &group->field));
  137|       |
  138|      4|  ret = 1;
  139|       |
  140|      4|err:
  141|      4|  BN_CTX_end(ctx);
  142|      4|  return ret;
  143|      4|}
ec_GFp_simple_point_init:
  155|    510|void ec_GFp_simple_point_init(EC_JACOBIAN *point) {
  156|    510|  OPENSSL_memset(&point->X, 0, sizeof(EC_FELEM));
  157|    510|  OPENSSL_memset(&point->Y, 0, sizeof(EC_FELEM));
  158|    510|  OPENSSL_memset(&point->Z, 0, sizeof(EC_FELEM));
  159|    510|}
ec_GFp_simple_point_copy:
  161|    486|void ec_GFp_simple_point_copy(EC_JACOBIAN *dest, const EC_JACOBIAN *src) {
  162|    486|  OPENSSL_memcpy(&dest->X, &src->X, sizeof(EC_FELEM));
  163|    486|  OPENSSL_memcpy(&dest->Y, &src->Y, sizeof(EC_FELEM));
  164|    486|  OPENSSL_memcpy(&dest->Z, &src->Z, sizeof(EC_FELEM));
  165|    486|}
ec_GFp_simple_point_set_to_infinity:
  168|    241|                                         EC_JACOBIAN *point) {
  169|       |  // Although it is strictly only necessary to zero Z, we zero the entire point
  170|       |  // in case |point| was stack-allocated and yet to be initialized.
  171|    241|  ec_GFp_simple_point_init(point);
  172|    241|}
ec_GFp_simple_is_at_infinity:
  179|    111|                                 const EC_JACOBIAN *point) {
  180|    111|  return ec_felem_non_zero_mask(group, &point->Z) == 0;
  181|    111|}
ec_GFp_simple_is_on_curve:
  184|    443|                              const EC_JACOBIAN *point) {
  185|       |  // We have a curve defined by a Weierstrass equation
  186|       |  //      y^2 = x^3 + a*x + b.
  187|       |  // The point to consider is given in Jacobian projective coordinates
  188|       |  // where  (X, Y, Z)  represents  (x, y) = (X/Z^2, Y/Z^3).
  189|       |  // Substituting this and multiplying by  Z^6  transforms the above equation
  190|       |  // into
  191|       |  //      Y^2 = X^3 + a*X*Z^4 + b*Z^6.
  192|       |  // To test this, we add up the right-hand side in 'rh'.
  193|       |  //
  194|       |  // This function may be used when double-checking the secret result of a point
  195|       |  // multiplication, so we proceed in constant-time.
  196|       |
  197|    443|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  198|    443|                          const EC_FELEM *b) = group->meth->felem_mul;
  199|    443|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  200|    443|      group->meth->felem_sqr;
  201|       |
  202|       |  // rh := X^2
  203|    443|  EC_FELEM rh;
  204|    443|  felem_sqr(group, &rh, &point->X);
  205|       |
  206|    443|  EC_FELEM tmp, Z4, Z6;
  207|    443|  felem_sqr(group, &tmp, &point->Z);
  208|    443|  felem_sqr(group, &Z4, &tmp);
  209|    443|  felem_mul(group, &Z6, &Z4, &tmp);
  210|       |
  211|       |  // rh := rh + a*Z^4
  212|    443|  if (group->a_is_minus3) {
  ------------------
  |  Branch (212:7): [True: 443, False: 0]
  ------------------
  213|    443|    ec_felem_add(group, &tmp, &Z4, &Z4);
  214|    443|    ec_felem_add(group, &tmp, &tmp, &Z4);
  215|    443|    ec_felem_sub(group, &rh, &rh, &tmp);
  216|    443|  } else {
  217|      0|    felem_mul(group, &tmp, &Z4, &group->a);
  218|      0|    ec_felem_add(group, &rh, &rh, &tmp);
  219|      0|  }
  220|       |
  221|       |  // rh := (rh + a*Z^4)*X
  222|    443|  felem_mul(group, &rh, &rh, &point->X);
  223|       |
  224|       |  // rh := rh + b*Z^6
  225|    443|  felem_mul(group, &tmp, &group->b, &Z6);
  226|    443|  ec_felem_add(group, &rh, &rh, &tmp);
  227|       |
  228|       |  // 'lh' := Y^2
  229|    443|  felem_sqr(group, &tmp, &point->Y);
  230|       |
  231|    443|  ec_felem_sub(group, &tmp, &tmp, &rh);
  232|    443|  BN_ULONG not_equal = ec_felem_non_zero_mask(group, &tmp);
  233|       |
  234|       |  // If Z = 0, the point is infinity, which is always on the curve.
  235|    443|  BN_ULONG not_infinity = ec_felem_non_zero_mask(group, &point->Z);
  236|       |
  237|    443|  return 1 & ~(not_infinity & not_equal);
  238|    443|}
ec_GFp_simple_points_equal:
  241|    111|                               const EC_JACOBIAN *b) {
  242|       |  // This function is implemented in constant-time for two reasons. First,
  243|       |  // although EC points are usually public, their Jacobian Z coordinates may be
  244|       |  // secret, or at least are not obviously public. Second, more complex
  245|       |  // protocols will sometimes manipulate secret points.
  246|       |  //
  247|       |  // This does mean that we pay a 6M+2S Jacobian comparison when comparing two
  248|       |  // publicly affine points costs no field operations at all. If needed, we can
  249|       |  // restore this optimization by keeping better track of affine vs. Jacobian
  250|       |  // forms. See https://crbug.com/boringssl/326.
  251|       |
  252|       |  // If neither |a| or |b| is infinity, we have to decide whether
  253|       |  //     (X_a/Z_a^2, Y_a/Z_a^3) = (X_b/Z_b^2, Y_b/Z_b^3),
  254|       |  // or equivalently, whether
  255|       |  //     (X_a*Z_b^2, Y_a*Z_b^3) = (X_b*Z_a^2, Y_b*Z_a^3).
  256|       |
  257|    111|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  258|    111|                          const EC_FELEM *b) = group->meth->felem_mul;
  259|    111|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  260|    111|      group->meth->felem_sqr;
  261|       |
  262|    111|  EC_FELEM tmp1, tmp2, Za23, Zb23;
  263|    111|  felem_sqr(group, &Zb23, &b->Z);         // Zb23 = Z_b^2
  264|    111|  felem_mul(group, &tmp1, &a->X, &Zb23);  // tmp1 = X_a * Z_b^2
  265|    111|  felem_sqr(group, &Za23, &a->Z);         // Za23 = Z_a^2
  266|    111|  felem_mul(group, &tmp2, &b->X, &Za23);  // tmp2 = X_b * Z_a^2
  267|    111|  ec_felem_sub(group, &tmp1, &tmp1, &tmp2);
  268|    111|  const BN_ULONG x_not_equal = ec_felem_non_zero_mask(group, &tmp1);
  269|       |
  270|    111|  felem_mul(group, &Zb23, &Zb23, &b->Z);  // Zb23 = Z_b^3
  271|    111|  felem_mul(group, &tmp1, &a->Y, &Zb23);  // tmp1 = Y_a * Z_b^3
  272|    111|  felem_mul(group, &Za23, &Za23, &a->Z);  // Za23 = Z_a^3
  273|    111|  felem_mul(group, &tmp2, &b->Y, &Za23);  // tmp2 = Y_b * Z_a^3
  274|    111|  ec_felem_sub(group, &tmp1, &tmp1, &tmp2);
  275|    111|  const BN_ULONG y_not_equal = ec_felem_non_zero_mask(group, &tmp1);
  276|    111|  const BN_ULONG x_and_y_equal = ~(x_not_equal | y_not_equal);
  277|       |
  278|    111|  const BN_ULONG a_not_infinity = ec_felem_non_zero_mask(group, &a->Z);
  279|    111|  const BN_ULONG b_not_infinity = ec_felem_non_zero_mask(group, &b->Z);
  280|    111|  const BN_ULONG a_and_b_infinity = ~(a_not_infinity | b_not_infinity);
  281|       |
  282|    111|  const BN_ULONG equal =
  283|    111|      a_and_b_infinity | (a_not_infinity & b_not_infinity & x_and_y_equal);
  284|    111|  return equal & 1;
  285|    111|}
ec_GFp_simple_felem_from_bytes:
  338|     20|                                   const uint8_t *in, size_t len) {
  339|     20|  if (len != BN_num_bytes(&group->field)) {
  ------------------
  |  Branch (339:7): [True: 0, False: 20]
  ------------------
  340|      0|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  341|      0|    return 0;
  342|      0|  }
  343|       |
  344|     20|  bn_big_endian_to_words(out->words, group->field.width, in, len);
  345|       |
  346|     20|  if (!bn_less_than_words(out->words, group->field.d, group->field.width)) {
  ------------------
  |  Branch (346:7): [True: 0, False: 20]
  ------------------
  347|      0|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  348|      0|    return 0;
  349|      0|  }
  350|       |
  351|     20|  return 1;
  352|     20|}

ec_GFp_mont_mul:
   25|    241|                     const EC_JACOBIAN *p, const EC_SCALAR *scalar) {
   26|       |  // This is a generic implementation for uncommon curves that not do not
   27|       |  // warrant a tuned one. It uses unsigned digits so that the doubling case in
   28|       |  // |ec_GFp_mont_add| is always unreachable, erring on safety and simplicity.
   29|       |
   30|       |  // Compute a table of the first 32 multiples of |p| (including infinity).
   31|    241|  EC_JACOBIAN precomp[32];
   32|    241|  ec_GFp_simple_point_set_to_infinity(group, &precomp[0]);
   33|    241|  ec_GFp_simple_point_copy(&precomp[1], p);
   34|  7.47k|  for (size_t j = 2; j < OPENSSL_ARRAY_SIZE(precomp); j++) {
  ------------------
  |  |  221|  7.47k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (34:22): [True: 7.23k, False: 241]
  ------------------
   35|  7.23k|    if (j & 1) {
  ------------------
  |  Branch (35:9): [True: 3.61k, False: 3.61k]
  ------------------
   36|  3.61k|      ec_GFp_mont_add(group, &precomp[j], &precomp[1], &precomp[j - 1]);
   37|  3.61k|    } else {
   38|  3.61k|      ec_GFp_mont_dbl(group, &precomp[j], &precomp[j / 2]);
   39|  3.61k|    }
   40|  7.23k|  }
   41|       |
   42|       |  // Divide bits in |scalar| into windows.
   43|    241|  unsigned bits = BN_num_bits(&group->order);
   44|    241|  int r_is_at_infinity = 1;
   45|   105k|  for (unsigned i = bits - 1; i < bits; i--) {
  ------------------
  |  Branch (45:31): [True: 105k, False: 241]
  ------------------
   46|   105k|    if (!r_is_at_infinity) {
  ------------------
  |  Branch (46:9): [True: 104k, False: 691]
  ------------------
   47|   104k|      ec_GFp_mont_dbl(group, r, r);
   48|   104k|    }
   49|   105k|    if (i % 5 == 0) {
  ------------------
  |  Branch (49:9): [True: 21.1k, False: 83.9k]
  ------------------
   50|       |      // Compute the next window value.
   51|  21.1k|      const size_t width = group->order.width;
   52|  21.1k|      uint8_t window = bn_is_bit_set_words(scalar->words, width, i + 4) << 4;
   53|  21.1k|      window |= bn_is_bit_set_words(scalar->words, width, i + 3) << 3;
   54|  21.1k|      window |= bn_is_bit_set_words(scalar->words, width, i + 2) << 2;
   55|  21.1k|      window |= bn_is_bit_set_words(scalar->words, width, i + 1) << 1;
   56|  21.1k|      window |= bn_is_bit_set_words(scalar->words, width, i);
   57|       |
   58|       |      // Select the entry in constant-time.
   59|  21.1k|      EC_JACOBIAN tmp;
   60|  21.1k|      OPENSSL_memset(&tmp, 0, sizeof(EC_JACOBIAN));
   61|   696k|      for (size_t j = 0; j < OPENSSL_ARRAY_SIZE(precomp); j++) {
  ------------------
  |  |  221|   696k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (61:26): [True: 675k, False: 21.1k]
  ------------------
   62|   675k|        BN_ULONG mask = constant_time_eq_w(j, window);
   63|   675k|        ec_point_select(group, &tmp, mask, &precomp[j], &tmp);
   64|   675k|      }
   65|       |
   66|  21.1k|      if (r_is_at_infinity) {
  ------------------
  |  Branch (66:11): [True: 241, False: 20.8k]
  ------------------
   67|    241|        ec_GFp_simple_point_copy(r, &tmp);
   68|    241|        r_is_at_infinity = 0;
   69|  20.8k|      } else {
   70|  20.8k|        ec_GFp_mont_add(group, r, r, &tmp);
   71|  20.8k|      }
   72|  21.1k|    }
   73|   105k|  }
   74|    241|  if (r_is_at_infinity) {
  ------------------
  |  Branch (74:7): [True: 0, False: 241]
  ------------------
   75|      0|    ec_GFp_simple_point_set_to_infinity(group, r);
   76|      0|  }
   77|    241|}
ec_GFp_mont_mul_base:
   80|    241|                          const EC_SCALAR *scalar) {
   81|    241|  ec_GFp_mont_mul(group, r, &group->generator->raw, scalar);
   82|    241|}

HMAC:
   71|  2.92k|              unsigned int *out_len) {
   72|  2.92k|  HMAC_CTX ctx;
   73|  2.92k|  HMAC_CTX_init(&ctx);
   74|       |
   75|       |  // The underlying hash functions should not set the FIPS service indicator
   76|       |  // until all operations have completed.
   77|  2.92k|  FIPS_service_indicator_lock_state();
   78|  2.92k|  const int ok = HMAC_Init_ex(&ctx, key, key_len, evp_md, NULL) &&
  ------------------
  |  Branch (78:18): [True: 2.92k, False: 0]
  ------------------
   79|  2.92k|                 HMAC_Update(&ctx, data, data_len) &&
  ------------------
  |  Branch (79:18): [True: 2.92k, False: 0]
  ------------------
   80|  2.92k|                 HMAC_Final(&ctx, out, out_len);
  ------------------
  |  Branch (80:18): [True: 2.92k, False: 0]
  ------------------
   81|  2.92k|  FIPS_service_indicator_unlock_state();
   82|       |
   83|  2.92k|  HMAC_CTX_cleanup(&ctx);
   84|       |
   85|  2.92k|  if (!ok) {
  ------------------
  |  Branch (85:7): [True: 0, False: 2.92k]
  ------------------
   86|      0|    return NULL;
   87|      0|  }
   88|       |
   89|  2.92k|  HMAC_verify_service_indicator(evp_md);
   90|  2.92k|  return out;
   91|  2.92k|}
HMAC_CTX_init:
   93|  2.98k|void HMAC_CTX_init(HMAC_CTX *ctx) {
   94|  2.98k|  ctx->md = NULL;
   95|  2.98k|  EVP_MD_CTX_init(&ctx->i_ctx);
   96|  2.98k|  EVP_MD_CTX_init(&ctx->o_ctx);
   97|  2.98k|  EVP_MD_CTX_init(&ctx->md_ctx);
   98|  2.98k|}
HMAC_CTX_cleanup:
  108|  2.98k|void HMAC_CTX_cleanup(HMAC_CTX *ctx) {
  109|  2.98k|  EVP_MD_CTX_cleanup(&ctx->i_ctx);
  110|  2.98k|  EVP_MD_CTX_cleanup(&ctx->o_ctx);
  111|  2.98k|  EVP_MD_CTX_cleanup(&ctx->md_ctx);
  112|  2.98k|  OPENSSL_cleanse(ctx, sizeof(HMAC_CTX));
  113|  2.98k|}
HMAC_Init_ex:
  132|  98.9k|                 const EVP_MD *md, ENGINE *impl) {
  133|  98.9k|  int ret = 0;
  134|  98.9k|  FIPS_service_indicator_lock_state();
  135|       |
  136|  98.9k|  if (md == NULL) {
  ------------------
  |  Branch (136:7): [True: 96.0k, False: 2.98k]
  ------------------
  137|  96.0k|    md = ctx->md;
  138|  96.0k|  }
  139|       |
  140|       |  // If either |key| is non-NULL or |md| has changed, initialize with a new key
  141|       |  // rather than rewinding the previous one.
  142|       |  //
  143|       |  // TODO(davidben,eroman): Passing the previous |md| with a NULL |key| is
  144|       |  // ambiguous between using the empty key and reusing the previous key. There
  145|       |  // exist callers which intend the latter, but the former is an awkward edge
  146|       |  // case. Fix to API to avoid this.
  147|  98.9k|  if (md != ctx->md || key != NULL) {
  ------------------
  |  Branch (147:7): [True: 2.98k, False: 96.0k]
  |  Branch (147:24): [True: 0, False: 96.0k]
  ------------------
  148|  2.98k|    uint8_t pad[EVP_MAX_MD_BLOCK_SIZE];
  149|  2.98k|    uint8_t key_block[EVP_MAX_MD_BLOCK_SIZE];
  150|  2.98k|    unsigned key_block_len;
  151|       |
  152|  2.98k|    size_t block_size = EVP_MD_block_size(md);
  153|  2.98k|    assert(block_size <= sizeof(key_block));
  154|  2.98k|    assert(EVP_MD_size(md) <= block_size);
  155|  2.98k|    if (block_size < key_len) {
  ------------------
  |  Branch (155:9): [True: 0, False: 2.98k]
  ------------------
  156|       |      // Long keys are hashed.
  157|      0|      if (!EVP_DigestInit_ex(&ctx->md_ctx, md, impl) ||
  ------------------
  |  Branch (157:11): [True: 0, False: 0]
  ------------------
  158|      0|          !EVP_DigestUpdate(&ctx->md_ctx, key, key_len) ||
  ------------------
  |  Branch (158:11): [True: 0, False: 0]
  ------------------
  159|      0|          !EVP_DigestFinal_ex(&ctx->md_ctx, key_block, &key_block_len)) {
  ------------------
  |  Branch (159:11): [True: 0, False: 0]
  ------------------
  160|      0|        goto out;
  161|      0|      }
  162|  2.98k|    } else {
  163|  2.98k|      assert(key_len <= sizeof(key_block));
  164|  2.98k|      OPENSSL_memcpy(key_block, key, key_len);
  165|  2.98k|      key_block_len = (unsigned)key_len;
  166|  2.98k|    }
  167|       |    // Keys are then padded with zeros.
  168|  2.98k|    OPENSSL_memset(key_block + key_block_len, 0, block_size - key_block_len);
  169|       |
  170|   206k|    for (size_t i = 0; i < block_size; i++) {
  ------------------
  |  Branch (170:24): [True: 203k, False: 2.98k]
  ------------------
  171|   203k|      pad[i] = 0x36 ^ key_block[i];
  172|   203k|    }
  173|  2.98k|    if (!EVP_DigestInit_ex(&ctx->i_ctx, md, impl) ||
  ------------------
  |  Branch (173:9): [True: 0, False: 2.98k]
  ------------------
  174|  2.98k|        !EVP_DigestUpdate(&ctx->i_ctx, pad, block_size)) {
  ------------------
  |  Branch (174:9): [True: 0, False: 2.98k]
  ------------------
  175|      0|      goto out;
  176|      0|    }
  177|       |
  178|   206k|    for (size_t i = 0; i < block_size; i++) {
  ------------------
  |  Branch (178:24): [True: 203k, False: 2.98k]
  ------------------
  179|   203k|      pad[i] = 0x5c ^ key_block[i];
  180|   203k|    }
  181|  2.98k|    if (!EVP_DigestInit_ex(&ctx->o_ctx, md, impl) ||
  ------------------
  |  Branch (181:9): [True: 0, False: 2.98k]
  ------------------
  182|  2.98k|        !EVP_DigestUpdate(&ctx->o_ctx, pad, block_size)) {
  ------------------
  |  Branch (182:9): [True: 0, False: 2.98k]
  ------------------
  183|      0|      goto out;
  184|      0|    }
  185|       |
  186|  2.98k|    ctx->md = md;
  187|  2.98k|  }
  188|       |
  189|  98.9k|  ret = EVP_MD_CTX_copy_ex(&ctx->md_ctx, &ctx->i_ctx);
  190|       |
  191|  98.9k|out:
  192|  98.9k|  FIPS_service_indicator_unlock_state();
  193|  98.9k|  return ret;
  194|  98.9k|}
HMAC_Update:
  196|  99.0k|int HMAC_Update(HMAC_CTX *ctx, const uint8_t *data, size_t data_len) {
  197|  99.0k|  return EVP_DigestUpdate(&ctx->md_ctx, data, data_len);
  198|  99.0k|}
HMAC_Final:
  200|  98.9k|int HMAC_Final(HMAC_CTX *ctx, uint8_t *out, unsigned int *out_len) {
  201|  98.9k|  int ret = 0;
  202|  98.9k|  unsigned int i;
  203|  98.9k|  uint8_t buf[EVP_MAX_MD_SIZE];
  204|       |
  205|  98.9k|  FIPS_service_indicator_lock_state();
  206|       |  // TODO(davidben): The only thing that can officially fail here is
  207|       |  // |EVP_MD_CTX_copy_ex|, but even that should be impossible in this case.
  208|  98.9k|  if (!EVP_DigestFinal_ex(&ctx->md_ctx, buf, &i) ||
  ------------------
  |  Branch (208:7): [True: 0, False: 98.9k]
  ------------------
  209|  98.9k|      !EVP_MD_CTX_copy_ex(&ctx->md_ctx, &ctx->o_ctx) ||
  ------------------
  |  Branch (209:7): [True: 0, False: 98.9k]
  ------------------
  210|  98.9k|      !EVP_DigestUpdate(&ctx->md_ctx, buf, i) ||
  ------------------
  |  Branch (210:7): [True: 0, False: 98.9k]
  ------------------
  211|  98.9k|      !EVP_DigestFinal_ex(&ctx->md_ctx, out, out_len)) {
  ------------------
  |  Branch (211:7): [True: 0, False: 98.9k]
  ------------------
  212|      0|    *out_len = 0;
  213|      0|    goto out;
  214|      0|  }
  215|       |
  216|  98.9k|  ret = 1;
  217|       |
  218|  98.9k| out:
  219|  98.9k|  FIPS_service_indicator_unlock_state();
  220|  98.9k|  if (ret) {
  ------------------
  |  Branch (220:7): [True: 98.9k, False: 0]
  ------------------
  221|  98.9k|    HMAC_verify_service_indicator(ctx->md);
  222|  98.9k|  }
  223|  98.9k|  return ret;
  224|  98.9k|}

MD4_Init:
   77|  20.9k|int MD4_Init(MD4_CTX *md4) {
   78|  20.9k|  OPENSSL_memset(md4, 0, sizeof(MD4_CTX));
   79|  20.9k|  md4->h[0] = 0x67452301UL;
   80|  20.9k|  md4->h[1] = 0xefcdab89UL;
   81|  20.9k|  md4->h[2] = 0x98badcfeUL;
   82|  20.9k|  md4->h[3] = 0x10325476UL;
   83|  20.9k|  return 1;
   84|  20.9k|}
MD4_Update:
   92|  26.7k|int MD4_Update(MD4_CTX *c, const void *data, size_t len) {
   93|  26.7k|  crypto_md32_update(&md4_block_data_order, c->h, c->data, MD4_CBLOCK, &c->num,
  ------------------
  |  |   70|  26.7k|#define MD4_CBLOCK 64
  ------------------
   94|  26.7k|                     &c->Nh, &c->Nl, data, len);
   95|  26.7k|  return 1;
   96|  26.7k|}
MD4_Final:
   98|  20.9k|int MD4_Final(uint8_t out[MD4_DIGEST_LENGTH], MD4_CTX *c) {
   99|  20.9k|  crypto_md32_final(&md4_block_data_order, c->h, c->data, MD4_CBLOCK, &c->num,
  ------------------
  |  |   70|  20.9k|#define MD4_CBLOCK 64
  ------------------
  100|  20.9k|                    c->Nh, c->Nl, /*is_big_endian=*/0);
  101|       |
  102|  20.9k|  CRYPTO_store_u32_le(out, c->h[0]);
  103|  20.9k|  CRYPTO_store_u32_le(out + 4, c->h[1]);
  104|  20.9k|  CRYPTO_store_u32_le(out + 8, c->h[2]);
  105|  20.9k|  CRYPTO_store_u32_le(out + 12, c->h[3]);
  106|  20.9k|  return 1;
  107|  20.9k|}
md4_block_data_order:
  134|  30.5k|void md4_block_data_order(uint32_t *state, const uint8_t *data, size_t num) {
  135|  30.5k|  uint32_t A, B, C, D;
  136|  30.5k|  uint32_t X0, X1, X2, X3, X4, X5, X6, X7, X8, X9, X10, X11, X12, X13, X14, X15;
  137|       |
  138|  30.5k|  A = state[0];
  139|  30.5k|  B = state[1];
  140|  30.5k|  C = state[2];
  141|  30.5k|  D = state[3];
  142|       |
  143|   197k|  for (; num--;) {
  ------------------
  |  Branch (143:10): [True: 166k, False: 30.5k]
  ------------------
  144|   166k|    X0 = CRYPTO_load_u32_le(data);
  145|   166k|    data += 4;
  146|   166k|    X1 = CRYPTO_load_u32_le(data);
  147|   166k|    data += 4;
  148|       |    // Round 0
  149|   166k|    R0(A, B, C, D, X0, 3, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  150|   166k|    X2 = CRYPTO_load_u32_le(data);
  151|   166k|    data += 4;
  152|   166k|    R0(D, A, B, C, X1, 7, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|   166k|    X3 = CRYPTO_load_u32_le(data);
  154|   166k|    data += 4;
  155|   166k|    R0(C, D, A, B, X2, 11, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  156|   166k|    X4 = CRYPTO_load_u32_le(data);
  157|   166k|    data += 4;
  158|   166k|    R0(B, C, D, A, X3, 19, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  159|   166k|    X5 = CRYPTO_load_u32_le(data);
  160|   166k|    data += 4;
  161|   166k|    R0(A, B, C, D, X4, 3, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  162|   166k|    X6 = CRYPTO_load_u32_le(data);
  163|   166k|    data += 4;
  164|   166k|    R0(D, A, B, C, X5, 7, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  165|   166k|    X7 = CRYPTO_load_u32_le(data);
  166|   166k|    data += 4;
  167|   166k|    R0(C, D, A, B, X6, 11, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  168|   166k|    X8 = CRYPTO_load_u32_le(data);
  169|   166k|    data += 4;
  170|   166k|    R0(B, C, D, A, X7, 19, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  171|   166k|    X9 = CRYPTO_load_u32_le(data);
  172|   166k|    data += 4;
  173|   166k|    R0(A, B, C, D, X8, 3, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  174|   166k|    X10 = CRYPTO_load_u32_le(data);
  175|   166k|    data += 4;
  176|   166k|    R0(D, A, B, C, X9, 7, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  177|   166k|    X11 = CRYPTO_load_u32_le(data);
  178|   166k|    data += 4;
  179|   166k|    R0(C, D, A, B, X10, 11, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  180|   166k|    X12 = CRYPTO_load_u32_le(data);
  181|   166k|    data += 4;
  182|   166k|    R0(B, C, D, A, X11, 19, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  183|   166k|    X13 = CRYPTO_load_u32_le(data);
  184|   166k|    data += 4;
  185|   166k|    R0(A, B, C, D, X12, 3, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  186|   166k|    X14 = CRYPTO_load_u32_le(data);
  187|   166k|    data += 4;
  188|   166k|    R0(D, A, B, C, X13, 7, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  189|   166k|    X15 = CRYPTO_load_u32_le(data);
  190|   166k|    data += 4;
  191|   166k|    R0(C, D, A, B, X14, 11, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  192|   166k|    R0(B, C, D, A, X15, 19, 0);
  ------------------
  |  |  117|   166k|  do {                                     \
  |  |  118|   166k|    (a) += ((k) + (t) + F((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  112|   166k|#define F(b, c, d) ((((c) ^ (d)) & (b)) ^ (d))
  |  |  ------------------
  |  |  119|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  120|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (120:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  193|       |    // Round 1
  194|   166k|    R1(A, B, C, D, X0, 3, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  195|   166k|    R1(D, A, B, C, X4, 5, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  196|   166k|    R1(C, D, A, B, X8, 9, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  197|   166k|    R1(B, C, D, A, X12, 13, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  198|   166k|    R1(A, B, C, D, X1, 3, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  199|   166k|    R1(D, A, B, C, X5, 5, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  200|   166k|    R1(C, D, A, B, X9, 9, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  201|   166k|    R1(B, C, D, A, X13, 13, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  202|   166k|    R1(A, B, C, D, X2, 3, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  203|   166k|    R1(D, A, B, C, X6, 5, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  204|   166k|    R1(C, D, A, B, X10, 9, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  205|   166k|    R1(B, C, D, A, X14, 13, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  206|   166k|    R1(A, B, C, D, X3, 3, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  207|   166k|    R1(D, A, B, C, X7, 5, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  208|   166k|    R1(C, D, A, B, X11, 9, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  209|   166k|    R1(B, C, D, A, X15, 13, 0x5A827999L);
  ------------------
  |  |  123|   166k|  do {                                     \
  |  |  124|   166k|    (a) += ((k) + (t) + G((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  113|   166k|#define G(b, c, d) (((b) & (c)) | ((b) & (d)) | ((c) & (d)))
  |  |  ------------------
  |  |  125|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  126|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (126:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  210|       |    // Round 2
  211|   166k|    R2(A, B, C, D, X0, 3, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  212|   166k|    R2(D, A, B, C, X8, 9, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  213|   166k|    R2(C, D, A, B, X4, 11, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  214|   166k|    R2(B, C, D, A, X12, 15, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  215|   166k|    R2(A, B, C, D, X2, 3, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  216|   166k|    R2(D, A, B, C, X10, 9, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  217|   166k|    R2(C, D, A, B, X6, 11, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  218|   166k|    R2(B, C, D, A, X14, 15, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  219|   166k|    R2(A, B, C, D, X1, 3, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  220|   166k|    R2(D, A, B, C, X9, 9, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  221|   166k|    R2(C, D, A, B, X5, 11, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  222|   166k|    R2(B, C, D, A, X13, 15, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  223|   166k|    R2(A, B, C, D, X3, 3, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  224|   166k|    R2(D, A, B, C, X11, 9, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  225|   166k|    R2(C, D, A, B, X7, 11, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  226|   166k|    R2(B, C, D, A, X15, 15, 0x6ED9EBA1L);
  ------------------
  |  |  129|   166k|  do {                                     \
  |  |  130|   166k|    (a) += ((k) + (t) + H((b), (c), (d))); \
  |  |  ------------------
  |  |  |  |  114|   166k|#define H(b, c, d) ((b) ^ (c) ^ (d))
  |  |  ------------------
  |  |  131|   166k|    (a) = CRYPTO_rotl_u32(a, s);           \
  |  |  132|   166k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (132:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  227|       |
  228|   166k|    A = state[0] += A;
  229|   166k|    B = state[1] += B;
  230|   166k|    C = state[2] += C;
  231|   166k|    D = state[3] += D;
  232|   166k|  }
  233|  30.5k|}

MD5_Init:
   77|  9.19k|int MD5_Init(MD5_CTX *md5) {
   78|  9.19k|  OPENSSL_memset(md5, 0, sizeof(MD5_CTX));
   79|  9.19k|  md5->h[0] = 0x67452301UL;
   80|  9.19k|  md5->h[1] = 0xefcdab89UL;
   81|  9.19k|  md5->h[2] = 0x98badcfeUL;
   82|  9.19k|  md5->h[3] = 0x10325476UL;
   83|  9.19k|  return 1;
   84|  9.19k|}
MD5_Update:
   97|  10.4k|int MD5_Update(MD5_CTX *c, const void *data, size_t len) {
   98|  10.4k|  crypto_md32_update(&md5_block_data_order, c->h, c->data, MD5_CBLOCK, &c->num,
  ------------------
  |  |   87|  10.4k|#define md5_block_data_order md5_block_asm_data_order
  ------------------
                crypto_md32_update(&md5_block_data_order, c->h, c->data, MD5_CBLOCK, &c->num,
  ------------------
  |  |   71|  10.4k|#define MD5_CBLOCK 64
  ------------------
   99|  10.4k|                     &c->Nh, &c->Nl, data, len);
  100|  10.4k|  return 1;
  101|  10.4k|}
MD5_Final:
  103|  9.19k|int MD5_Final(uint8_t out[MD5_DIGEST_LENGTH], MD5_CTX *c) {
  104|  9.19k|  crypto_md32_final(&md5_block_data_order, c->h, c->data, MD5_CBLOCK, &c->num,
  ------------------
  |  |   87|  9.19k|#define md5_block_data_order md5_block_asm_data_order
  ------------------
                crypto_md32_final(&md5_block_data_order, c->h, c->data, MD5_CBLOCK, &c->num,
  ------------------
  |  |   71|  9.19k|#define MD5_CBLOCK 64
  ------------------
  105|  9.19k|                    c->Nh, c->Nl, /*is_big_endian=*/0);
  106|       |
  107|  9.19k|  CRYPTO_store_u32_le(out, c->h[0]);
  108|  9.19k|  CRYPTO_store_u32_le(out + 4, c->h[1]);
  109|  9.19k|  CRYPTO_store_u32_le(out + 8, c->h[2]);
  110|  9.19k|  CRYPTO_store_u32_le(out + 12, c->h[3]);
  111|  9.19k|  return 1;
  112|  9.19k|}

RSA_new:
  206|    469|RSA *RSA_new(void) { return RSA_new_method(NULL); }
RSA_new_method:
  208|    469|RSA *RSA_new_method(const ENGINE *engine) {
  209|    469|  RSA *rsa = OPENSSL_malloc(sizeof(RSA));
  210|    469|  if (rsa == NULL) {
  ------------------
  |  Branch (210:7): [True: 0, False: 469]
  ------------------
  211|      0|    return NULL;
  212|      0|  }
  213|       |
  214|    469|  OPENSSL_memset(rsa, 0, sizeof(RSA));
  215|       |
  216|    469|  if (engine) {
  ------------------
  |  Branch (216:7): [True: 0, False: 469]
  ------------------
  217|      0|    rsa->meth = ENGINE_get_RSA_method(engine);
  218|      0|  }
  219|       |
  220|    469|  if (rsa->meth == NULL) {
  ------------------
  |  Branch (220:7): [True: 469, False: 0]
  ------------------
  221|    469|    rsa->meth = (RSA_METHOD *) RSA_default_method();
  222|    469|  }
  223|    469|  METHOD_ref(rsa->meth);
  224|       |
  225|    469|  rsa->references = 1;
  226|    469|  rsa->flags = rsa->meth->flags;
  227|    469|  CRYPTO_MUTEX_init(&rsa->lock);
  228|    469|  CRYPTO_new_ex_data(&rsa->ex_data);
  229|       |
  230|    469|  if (rsa->meth->init && !rsa->meth->init(rsa)) {
  ------------------
  |  Branch (230:7): [True: 0, False: 469]
  |  Branch (230:26): [True: 0, False: 0]
  ------------------
  231|      0|    CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  232|      0|    CRYPTO_MUTEX_cleanup(&rsa->lock);
  233|      0|    METHOD_unref(rsa->meth);
  234|      0|    OPENSSL_free(rsa);
  235|      0|    return NULL;
  236|      0|  }
  237|       |
  238|    469|  return rsa;
  239|    469|}
RSA_free:
  252|  1.40k|void RSA_free(RSA *rsa) {
  253|  1.40k|  if (rsa == NULL) {
  ------------------
  |  Branch (253:7): [True: 931, False: 469]
  ------------------
  254|    931|    return;
  255|    931|  }
  256|       |
  257|    469|  if (!CRYPTO_refcount_dec_and_test_zero(&rsa->references)) {
  ------------------
  |  Branch (257:7): [True: 0, False: 469]
  ------------------
  258|      0|    return;
  259|      0|  }
  260|       |
  261|    469|  if (rsa->meth->finish) {
  ------------------
  |  Branch (261:7): [True: 0, False: 469]
  ------------------
  262|      0|    rsa->meth->finish(rsa);
  263|      0|  }
  264|    469|  METHOD_unref(rsa->meth);
  265|       |
  266|    469|  CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  267|       |
  268|    469|  BN_free(rsa->n);
  269|    469|  BN_free(rsa->e);
  270|    469|  BN_free(rsa->d);
  271|    469|  BN_free(rsa->p);
  272|    469|  BN_free(rsa->q);
  273|    469|  BN_free(rsa->dmp1);
  274|    469|  BN_free(rsa->dmq1);
  275|    469|  BN_free(rsa->iqmp);
  276|    469|  rsa_invalidate_key(rsa);
  277|    469|  CRYPTO_MUTEX_cleanup(&rsa->lock);
  278|    469|  OPENSSL_free(rsa);
  279|    469|}
RSA_is_opaque:
  438|    437|int RSA_is_opaque(const RSA *rsa) {
  439|    437|  return rsa->meth && (rsa->meth->flags & RSA_FLAG_OPAQUE);
  ------------------
  |  |  661|    437|#define RSA_FLAG_OPAQUE 1
  ------------------
  |  Branch (439:10): [True: 437, False: 0]
  |  Branch (439:23): [True: 0, False: 437]
  ------------------
  440|    437|}
RSA_check_key:
  787|    437|int RSA_check_key(const RSA *key) {
  788|       |  // TODO(davidben): RSA key initialization is spread across
  789|       |  // |rsa_check_public_key|, |RSA_check_key|, |freeze_private_key|, and
  790|       |  // |BN_MONT_CTX_set_locked| as a result of API issues. See
  791|       |  // https://crbug.com/boringssl/316. As a result, we inconsistently check RSA
  792|       |  // invariants. We should fix this and integrate that logic.
  793|       |
  794|    437|  if (RSA_is_opaque(key)) {
  ------------------
  |  Branch (794:7): [True: 0, False: 437]
  ------------------
  795|       |    // Opaque keys can't be checked.
  796|      0|    return 1;
  797|      0|  }
  798|       |
  799|    437|  if (!rsa_check_public_key(key)) {
  ------------------
  |  Branch (799:7): [True: 76, False: 361]
  ------------------
  800|     76|    return 0;
  801|     76|  }
  802|       |
  803|    361|  if ((key->p != NULL) != (key->q != NULL)) {
  ------------------
  |  Branch (803:7): [True: 0, False: 361]
  ------------------
  804|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_ONLY_ONE_OF_P_Q_GIVEN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  805|      0|    return 0;
  806|      0|  }
  807|       |
  808|       |  // |key->d| must be bounded by |key->n|. This ensures bounds on |RSA_bits|
  809|       |  // translate to bounds on the running time of private key operations.
  810|    361|  if (key->d != NULL &&
  ------------------
  |  Branch (810:7): [True: 361, False: 0]
  ------------------
  811|    361|      (BN_is_negative(key->d) || BN_cmp(key->d, key->n) >= 0)) {
  ------------------
  |  Branch (811:8): [True: 0, False: 361]
  |  Branch (811:34): [True: 2, False: 359]
  ------------------
  812|      2|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_OUT_OF_RANGE);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  813|      2|    return 0;
  814|      2|  }
  815|       |
  816|    359|  if (key->d == NULL || key->p == NULL) {
  ------------------
  |  Branch (816:7): [True: 0, False: 359]
  |  Branch (816:25): [True: 0, False: 359]
  ------------------
  817|       |    // For a public key, or without p and q, there's nothing that can be
  818|       |    // checked.
  819|      0|    return 1;
  820|      0|  }
  821|       |
  822|    359|  BN_CTX *ctx = BN_CTX_new();
  823|    359|  if (ctx == NULL) {
  ------------------
  |  Branch (823:7): [True: 0, False: 359]
  ------------------
  824|      0|    return 0;
  825|      0|  }
  826|       |
  827|    359|  BIGNUM tmp, de, pm1, qm1, dmp1, dmq1;
  828|    359|  int ok = 0;
  829|    359|  BN_init(&tmp);
  830|    359|  BN_init(&de);
  831|    359|  BN_init(&pm1);
  832|    359|  BN_init(&qm1);
  833|    359|  BN_init(&dmp1);
  834|    359|  BN_init(&dmq1);
  835|       |
  836|       |  // Check that p * q == n. Before we multiply, we check that p and q are in
  837|       |  // bounds, to avoid a DoS vector in |bn_mul_consttime| below. Note that
  838|       |  // n was bound by |rsa_check_public_key|. This also implicitly checks p and q
  839|       |  // are odd, which is a necessary condition for Montgomery reduction.
  840|    359|  if (BN_is_negative(key->p) || BN_cmp(key->p, key->n) >= 0 ||
  ------------------
  |  Branch (840:7): [True: 0, False: 359]
  |  Branch (840:33): [True: 0, False: 359]
  ------------------
  841|    359|      BN_is_negative(key->q) || BN_cmp(key->q, key->n) >= 0) {
  ------------------
  |  Branch (841:7): [True: 0, False: 359]
  |  Branch (841:33): [True: 0, False: 359]
  ------------------
  842|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  843|      0|    goto out;
  844|      0|  }
  845|    359|  if (!bn_mul_consttime(&tmp, key->p, key->q, ctx)) {
  ------------------
  |  Branch (845:7): [True: 0, False: 359]
  ------------------
  846|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  847|      0|    goto out;
  848|      0|  }
  849|    359|  if (BN_cmp(&tmp, key->n) != 0) {
  ------------------
  |  Branch (849:7): [True: 197, False: 162]
  ------------------
  850|    197|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|    197|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  851|    197|    goto out;
  852|    197|  }
  853|       |
  854|       |  // d must be an inverse of e mod the Carmichael totient, lcm(p-1, q-1), but it
  855|       |  // may be unreduced because other implementations use the Euler totient. We
  856|       |  // simply check that d * e is one mod p-1 and mod q-1. Note d and e were bound
  857|       |  // by earlier checks in this function.
  858|    162|  if (!bn_usub_consttime(&pm1, key->p, BN_value_one()) ||
  ------------------
  |  Branch (858:7): [True: 0, False: 162]
  ------------------
  859|    162|      !bn_usub_consttime(&qm1, key->q, BN_value_one())) {
  ------------------
  |  Branch (859:7): [True: 0, False: 162]
  ------------------
  860|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  861|      0|    goto out;
  862|      0|  }
  863|    162|  const unsigned pm1_bits = BN_num_bits(&pm1);
  864|    162|  const unsigned qm1_bits = BN_num_bits(&qm1);
  865|    162|  if (!bn_mul_consttime(&de, key->d, key->e, ctx) ||
  ------------------
  |  Branch (865:7): [True: 0, False: 162]
  ------------------
  866|    162|      !bn_div_consttime(NULL, &tmp, &de, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (866:7): [True: 0, False: 162]
  ------------------
  867|    162|      !bn_div_consttime(NULL, &de, &de, &qm1, qm1_bits, ctx)) {
  ------------------
  |  Branch (867:7): [True: 0, False: 162]
  ------------------
  868|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  869|      0|    goto out;
  870|      0|  }
  871|       |
  872|    162|  if (!BN_is_one(&tmp) || !BN_is_one(&de)) {
  ------------------
  |  Branch (872:7): [True: 93, False: 69]
  |  Branch (872:27): [True: 0, False: 69]
  ------------------
  873|     93|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_E_NOT_CONGRUENT_TO_1);
  ------------------
  |  |  441|     93|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  874|     93|    goto out;
  875|     93|  }
  876|       |
  877|     69|  int has_crt_values = key->dmp1 != NULL;
  878|     69|  if (has_crt_values != (key->dmq1 != NULL) ||
  ------------------
  |  Branch (878:7): [True: 0, False: 69]
  ------------------
  879|     69|      has_crt_values != (key->iqmp != NULL)) {
  ------------------
  |  Branch (879:7): [True: 0, False: 69]
  ------------------
  880|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_INCONSISTENT_SET_OF_CRT_VALUES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  881|      0|    goto out;
  882|      0|  }
  883|       |
  884|     69|  if (has_crt_values) {
  ------------------
  |  Branch (884:7): [True: 69, False: 0]
  ------------------
  885|     69|    int dmp1_ok, dmq1_ok, iqmp_ok;
  886|     69|    if (!check_mod_inverse(&dmp1_ok, key->e, key->dmp1, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (886:9): [True: 0, False: 69]
  ------------------
  887|     69|        !check_mod_inverse(&dmq1_ok, key->e, key->dmq1, &qm1, qm1_bits, ctx) ||
  ------------------
  |  Branch (887:9): [True: 0, False: 69]
  ------------------
  888|       |        // |p| is odd, so |pm1| and |p| have the same bit width. If they didn't,
  889|       |        // we only need a lower bound anyway.
  890|     69|        !check_mod_inverse(&iqmp_ok, key->q, key->iqmp, key->p, pm1_bits,
  ------------------
  |  Branch (890:9): [True: 0, False: 69]
  ------------------
  891|     69|                           ctx)) {
  892|      0|      OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  893|      0|      goto out;
  894|      0|    }
  895|       |
  896|     69|    if (!dmp1_ok || !dmq1_ok || !iqmp_ok) {
  ------------------
  |  Branch (896:9): [True: 62, False: 7]
  |  Branch (896:21): [True: 1, False: 6]
  |  Branch (896:33): [True: 1, False: 5]
  ------------------
  897|     64|      OPENSSL_PUT_ERROR(RSA, RSA_R_CRT_VALUES_INCORRECT);
  ------------------
  |  |  441|     64|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  898|     64|      goto out;
  899|     64|    }
  900|     69|  }
  901|       |
  902|      5|  ok = 1;
  903|       |
  904|    359|out:
  905|    359|  BN_free(&tmp);
  906|    359|  BN_free(&de);
  907|    359|  BN_free(&pm1);
  908|    359|  BN_free(&qm1);
  909|    359|  BN_free(&dmp1);
  910|    359|  BN_free(&dmq1);
  911|    359|  BN_CTX_free(ctx);
  912|       |
  913|    359|  return ok;
  914|      5|}
bcm.c:check_mod_inverse:
  766|    207|                             BN_CTX *ctx) {
  767|    207|  if (BN_is_negative(ainv) || BN_cmp(ainv, m) >= 0) {
  ------------------
  |  Branch (767:7): [True: 0, False: 207]
  |  Branch (767:31): [True: 43, False: 164]
  ------------------
  768|     43|    *out_ok = 0;
  769|     43|    return 1;
  770|     43|  }
  771|       |
  772|       |  // Note |bn_mul_consttime| and |bn_div_consttime| do not scale linearly, but
  773|       |  // checking |ainv| is in range bounds the running time, assuming |m|'s bounds
  774|       |  // were checked by the caller.
  775|    164|  BN_CTX_start(ctx);
  776|    164|  BIGNUM *tmp = BN_CTX_get(ctx);
  777|    164|  int ret = tmp != NULL &&
  ------------------
  |  Branch (777:13): [True: 164, False: 0]
  ------------------
  778|    164|            bn_mul_consttime(tmp, a, ainv, ctx) &&
  ------------------
  |  Branch (778:13): [True: 164, False: 0]
  ------------------
  779|    164|            bn_div_consttime(NULL, tmp, tmp, m, m_min_bits, ctx);
  ------------------
  |  Branch (779:13): [True: 164, False: 0]
  ------------------
  780|    164|  if (ret) {
  ------------------
  |  Branch (780:7): [True: 164, False: 0]
  ------------------
  781|    164|    *out_ok = BN_is_one(tmp);
  782|    164|  }
  783|    164|  BN_CTX_end(ctx);
  784|    164|  return ret;
  785|    207|}

rsa_check_public_key:
   76|    437|int rsa_check_public_key(const RSA *rsa) {
   77|    437|  if (rsa->n == NULL) {
  ------------------
  |  Branch (77:7): [True: 0, False: 437]
  ------------------
   78|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   79|      0|    return 0;
   80|      0|  }
   81|       |
   82|       |  // TODO(davidben): 16384-bit RSA is huge. Can we bring this down to a limit of
   83|       |  // 8192-bit?
   84|    437|  unsigned n_bits = BN_num_bits(rsa->n);
   85|    437|  if (n_bits > 16 * 1024) {
  ------------------
  |  Branch (85:7): [True: 0, False: 437]
  ------------------
   86|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   87|      0|    return 0;
   88|      0|  }
   89|       |
   90|       |  // TODO(crbug.com/boringssl/607): Raise this limit. 512-bit RSA was factored
   91|       |  // in 1999.
   92|    437|  if (n_bits < 512) {
  ------------------
  |  Branch (92:7): [True: 0, False: 437]
  ------------------
   93|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_KEY_SIZE_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   94|      0|    return 0;
   95|      0|  }
   96|       |
   97|       |  // RSA moduli must be positive and odd. In addition to being necessary for RSA
   98|       |  // in general, we cannot setup Montgomery reduction with even moduli.
   99|    437|  if (!BN_is_odd(rsa->n) || BN_is_negative(rsa->n)) {
  ------------------
  |  Branch (99:7): [True: 20, False: 417]
  |  Branch (99:29): [True: 0, False: 417]
  ------------------
  100|     20|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  101|     20|    return 0;
  102|     20|  }
  103|       |
  104|    417|  static const unsigned kMaxExponentBits = 33;
  105|    417|  if (rsa->e != NULL) {
  ------------------
  |  Branch (105:7): [True: 417, False: 0]
  ------------------
  106|       |    // Reject e = 1, negative e, and even e. e must be odd to be relatively
  107|       |    // prime with phi(n).
  108|    417|    unsigned e_bits = BN_num_bits(rsa->e);
  109|    417|    if (e_bits < 2 || BN_is_negative(rsa->e) || !BN_is_odd(rsa->e)) {
  ------------------
  |  Branch (109:9): [True: 18, False: 399]
  |  Branch (109:23): [True: 0, False: 399]
  |  Branch (109:49): [True: 20, False: 379]
  ------------------
  110|     38|      OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|     38|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|     38|      return 0;
  112|     38|    }
  113|    379|    if (rsa->flags & RSA_FLAG_LARGE_PUBLIC_EXPONENT) {
  ------------------
  |  |  683|    379|#define RSA_FLAG_LARGE_PUBLIC_EXPONENT 0x80
  ------------------
  |  Branch (113:9): [True: 0, False: 379]
  ------------------
  114|       |      // The caller has requested disabling DoS protections. Still, e must be
  115|       |      // less than n.
  116|      0|      if (BN_ucmp(rsa->n, rsa->e) <= 0) {
  ------------------
  |  Branch (116:11): [True: 0, False: 0]
  ------------------
  117|      0|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|        return 0;
  119|      0|      }
  120|    379|    } else {
  121|       |      // Mitigate DoS attacks by limiting the exponent size. 33 bits was chosen
  122|       |      // as the limit based on the recommendations in [1] and [2]. Windows
  123|       |      // CryptoAPI doesn't support values larger than 32 bits [3], so it is
  124|       |      // unlikely that exponents larger than 32 bits are being used for anything
  125|       |      // Windows commonly does.
  126|       |      //
  127|       |      // [1] https://www.imperialviolet.org/2012/03/16/rsae.html
  128|       |      // [2] https://www.imperialviolet.org/2012/03/17/rsados.html
  129|       |      // [3] https://msdn.microsoft.com/en-us/library/aa387685(VS.85).aspx
  130|    379|      if (e_bits > kMaxExponentBits) {
  ------------------
  |  Branch (130:11): [True: 18, False: 361]
  ------------------
  131|     18|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|     18|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|     18|        return 0;
  133|     18|      }
  134|       |
  135|       |      // The upper bound on |e_bits| and lower bound on |n_bits| imply e is
  136|       |      // bounded by n.
  137|    361|      assert(BN_ucmp(rsa->n, rsa->e) > 0);
  138|    361|    }
  139|    379|  } else if (!(rsa->flags & RSA_FLAG_NO_PUBLIC_EXPONENT)) {
  ------------------
  |  |  677|      0|#define RSA_FLAG_NO_PUBLIC_EXPONENT 0x40
  ------------------
  |  Branch (139:14): [True: 0, False: 0]
  ------------------
  140|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|       |
  144|    361|  return 1;
  145|    417|}
rsa_invalidate_key:
  289|    469|void rsa_invalidate_key(RSA *rsa) {
  290|    469|  rsa->private_key_frozen = 0;
  291|       |
  292|    469|  BN_MONT_CTX_free(rsa->mont_n);
  293|    469|  rsa->mont_n = NULL;
  294|    469|  BN_MONT_CTX_free(rsa->mont_p);
  295|    469|  rsa->mont_p = NULL;
  296|    469|  BN_MONT_CTX_free(rsa->mont_q);
  297|    469|  rsa->mont_q = NULL;
  298|       |
  299|    469|  BN_free(rsa->d_fixed);
  300|    469|  rsa->d_fixed = NULL;
  301|    469|  BN_free(rsa->dmp1_fixed);
  302|    469|  rsa->dmp1_fixed = NULL;
  303|    469|  BN_free(rsa->dmq1_fixed);
  304|    469|  rsa->dmq1_fixed = NULL;
  305|    469|  BN_free(rsa->inv_small_mod_large_mont);
  306|    469|  rsa->inv_small_mod_large_mont = NULL;
  307|       |
  308|    469|  for (size_t i = 0; i < rsa->num_blindings; i++) {
  ------------------
  |  Branch (308:22): [True: 0, False: 469]
  ------------------
  309|      0|    BN_BLINDING_free(rsa->blindings[i]);
  310|      0|  }
  311|    469|  OPENSSL_free(rsa->blindings);
  312|    469|  rsa->blindings = NULL;
  313|    469|  rsa->num_blindings = 0;
  314|    469|  OPENSSL_free(rsa->blindings_inuse);
  315|    469|  rsa->blindings_inuse = NULL;
  316|    469|  rsa->blinding_fork_generation = 0;
  317|    469|}
bcm.c:RSA_default_method_do_init:
 1349|      1|DEFINE_METHOD_FUNCTION(RSA_METHOD, RSA_default_method) {
 1350|       |  // All of the methods are NULL to make it easier for the compiler/linker to
 1351|       |  // drop unused functions. The wrapper functions will select the appropriate
 1352|       |  // |rsa_default_*| implementation.
 1353|      1|  OPENSSL_memset(out, 0, sizeof(RSA_METHOD));
 1354|      1|  out->common.is_static = 1;
 1355|      1|}

bcm.c:FIPS_service_indicator_update_state:
   56|  6.02M|OPENSSL_INLINE void FIPS_service_indicator_update_state(void) {}
bcm.c:FIPS_service_indicator_lock_state:
   57|   200k|OPENSSL_INLINE void FIPS_service_indicator_lock_state(void) {}
bcm.c:FIPS_service_indicator_unlock_state:
   58|   200k|OPENSSL_INLINE void FIPS_service_indicator_unlock_state(void) {}
bcm.c:EVP_Cipher_verify_service_indicator:
   73|  1.14k|    OPENSSL_UNUSED const EVP_CIPHER_CTX *ctx) {}
bcm.c:HMAC_verify_service_indicator:
   82|   101k|    OPENSSL_UNUSED const EVP_MD *evp_md) {}

SHA1_Init:
   69|  5.80M|int SHA1_Init(SHA_CTX *sha) {
   70|  5.80M|  OPENSSL_memset(sha, 0, sizeof(SHA_CTX));
   71|  5.80M|  sha->h[0] = 0x67452301UL;
   72|  5.80M|  sha->h[1] = 0xefcdab89UL;
   73|  5.80M|  sha->h[2] = 0x98badcfeUL;
   74|  5.80M|  sha->h[3] = 0x10325476UL;
   75|  5.80M|  sha->h[4] = 0xc3d2e1f0UL;
   76|  5.80M|  return 1;
   77|  5.80M|}
SHA1_Update:
   97|  5.99M|int SHA1_Update(SHA_CTX *c, const void *data, size_t len) {
   98|  5.99M|  crypto_md32_update(&sha1_block_data_order, c->h, c->data, SHA_CBLOCK, &c->num,
  ------------------
  |  |   71|  5.99M|#define SHA_CBLOCK 64
  ------------------
   99|  5.99M|                     &c->Nh, &c->Nl, data, len);
  100|  5.99M|  return 1;
  101|  5.99M|}
SHA1_Final:
  103|  5.99M|int SHA1_Final(uint8_t out[SHA_DIGEST_LENGTH], SHA_CTX *c) {
  104|  5.99M|  crypto_md32_final(&sha1_block_data_order, c->h, c->data, SHA_CBLOCK, &c->num,
  ------------------
  |  |   71|  5.99M|#define SHA_CBLOCK 64
  ------------------
  105|  5.99M|                    c->Nh, c->Nl, /*is_big_endian=*/1);
  106|       |
  107|  5.99M|  CRYPTO_store_u32_be(out, c->h[0]);
  108|  5.99M|  CRYPTO_store_u32_be(out + 4, c->h[1]);
  109|  5.99M|  CRYPTO_store_u32_be(out + 8, c->h[2]);
  110|  5.99M|  CRYPTO_store_u32_be(out + 12, c->h[3]);
  111|  5.99M|  CRYPTO_store_u32_be(out + 16, c->h[4]);
  112|  5.99M|  FIPS_service_indicator_update_state();
  113|  5.99M|  return 1;
  114|  5.99M|}

SHA224_Init:
   69|  6.95k|int SHA224_Init(SHA256_CTX *sha) {
   70|  6.95k|  OPENSSL_memset(sha, 0, sizeof(SHA256_CTX));
   71|  6.95k|  sha->h[0] = 0xc1059ed8UL;
   72|  6.95k|  sha->h[1] = 0x367cd507UL;
   73|  6.95k|  sha->h[2] = 0x3070dd17UL;
   74|  6.95k|  sha->h[3] = 0xf70e5939UL;
   75|  6.95k|  sha->h[4] = 0xffc00b31UL;
   76|  6.95k|  sha->h[5] = 0x68581511UL;
   77|  6.95k|  sha->h[6] = 0x64f98fa7UL;
   78|  6.95k|  sha->h[7] = 0xbefa4fa4UL;
   79|  6.95k|  sha->md_len = SHA224_DIGEST_LENGTH;
  ------------------
  |  |  128|  6.95k|#define SHA224_DIGEST_LENGTH 28
  ------------------
   80|  6.95k|  return 1;
   81|  6.95k|}
SHA256_Init:
   83|  6.89k|int SHA256_Init(SHA256_CTX *sha) {
   84|  6.89k|  OPENSSL_memset(sha, 0, sizeof(SHA256_CTX));
   85|  6.89k|  sha->h[0] = 0x6a09e667UL;
   86|  6.89k|  sha->h[1] = 0xbb67ae85UL;
   87|  6.89k|  sha->h[2] = 0x3c6ef372UL;
   88|  6.89k|  sha->h[3] = 0xa54ff53aUL;
   89|  6.89k|  sha->h[4] = 0x510e527fUL;
   90|  6.89k|  sha->h[5] = 0x9b05688cUL;
   91|  6.89k|  sha->h[6] = 0x1f83d9abUL;
   92|  6.89k|  sha->h[7] = 0x5be0cd19UL;
   93|  6.89k|  sha->md_len = SHA256_DIGEST_LENGTH;
  ------------------
  |  |  155|  6.89k|#define SHA256_DIGEST_LENGTH 32
  ------------------
   94|  6.89k|  return 1;
   95|  6.89k|}
SHA256_Update:
  126|  14.3k|int SHA256_Update(SHA256_CTX *c, const void *data, size_t len) {
  127|  14.3k|  crypto_md32_update(&sha256_block_data_order, c->h, c->data, SHA256_CBLOCK,
  ------------------
  |  |  152|  14.3k|#define SHA256_CBLOCK 64
  ------------------
  128|  14.3k|                     &c->num, &c->Nh, &c->Nl, data, len);
  129|  14.3k|  return 1;
  130|  14.3k|}
SHA224_Update:
  132|  7.13k|int SHA224_Update(SHA256_CTX *ctx, const void *data, size_t len) {
  133|  7.13k|  return SHA256_Update(ctx, data, len);
  134|  7.13k|}
SHA256_Final:
  159|  6.89k|int SHA256_Final(uint8_t out[SHA256_DIGEST_LENGTH], SHA256_CTX *c) {
  160|       |  // Ideally we would assert |sha->md_len| is |SHA256_DIGEST_LENGTH| to match
  161|       |  // the size hint, but calling code often pairs |SHA224_Init| with
  162|       |  // |SHA256_Final| and expects |sha->md_len| to carry the size over.
  163|       |  //
  164|       |  // TODO(davidben): Add an assert and fix code to match them up.
  165|  6.89k|  return sha256_final_impl(out, c->md_len, c);
  166|  6.89k|}
SHA224_Final:
  168|  6.95k|int SHA224_Final(uint8_t out[SHA224_DIGEST_LENGTH], SHA256_CTX *ctx) {
  169|       |  // This function must be paired with |SHA224_Init|, which sets |ctx->md_len|
  170|       |  // to |SHA224_DIGEST_LENGTH|.
  171|  6.95k|  assert(ctx->md_len == SHA224_DIGEST_LENGTH);
  172|  6.95k|  return sha256_final_impl(out, SHA224_DIGEST_LENGTH, ctx);
  ------------------
  |  |  128|  6.95k|#define SHA224_DIGEST_LENGTH 28
  ------------------
  173|  6.95k|}
bcm.c:sha256_final_impl:
  136|  13.8k|static int sha256_final_impl(uint8_t *out, size_t md_len, SHA256_CTX *c) {
  137|  13.8k|  crypto_md32_final(&sha256_block_data_order, c->h, c->data, SHA256_CBLOCK,
  ------------------
  |  |  152|  13.8k|#define SHA256_CBLOCK 64
  ------------------
  138|  13.8k|                    &c->num, c->Nh, c->Nl, /*is_big_endian=*/1);
  139|       |
  140|       |  // TODO(davidben): This overflow check one of the few places a low-level hash
  141|       |  // 'final' function can fail. SHA-512 does not have a corresponding check.
  142|       |  // These functions already misbehave if the caller arbitrarily mutates |c|, so
  143|       |  // can we assume one of |SHA256_Init| or |SHA224_Init| was used?
  144|  13.8k|  if (md_len > SHA256_DIGEST_LENGTH) {
  ------------------
  |  |  155|  13.8k|#define SHA256_DIGEST_LENGTH 32
  ------------------
  |  Branch (144:7): [True: 0, False: 13.8k]
  ------------------
  145|      0|    return 0;
  146|      0|  }
  147|       |
  148|  13.8k|  assert(md_len % 4 == 0);
  149|  13.8k|  const size_t out_words = md_len / 4;
  150|   117k|  for (size_t i = 0; i < out_words; i++) {
  ------------------
  |  Branch (150:22): [True: 103k, False: 13.8k]
  ------------------
  151|   103k|    CRYPTO_store_u32_be(out, c->h[i]);
  152|   103k|    out += 4;
  153|   103k|  }
  154|       |
  155|  13.8k|  FIPS_service_indicator_update_state();
  156|  13.8k|  return 1;
  157|  13.8k|}

SHA384_Init:
   76|  9.96k|int SHA384_Init(SHA512_CTX *sha) {
   77|  9.96k|  sha->h[0] = UINT64_C(0xcbbb9d5dc1059ed8);
   78|  9.96k|  sha->h[1] = UINT64_C(0x629a292a367cd507);
   79|  9.96k|  sha->h[2] = UINT64_C(0x9159015a3070dd17);
   80|  9.96k|  sha->h[3] = UINT64_C(0x152fecd8f70e5939);
   81|  9.96k|  sha->h[4] = UINT64_C(0x67332667ffc00b31);
   82|  9.96k|  sha->h[5] = UINT64_C(0x8eb44a8768581511);
   83|  9.96k|  sha->h[6] = UINT64_C(0xdb0c2e0d64f98fa7);
   84|  9.96k|  sha->h[7] = UINT64_C(0x47b5481dbefa4fa4);
   85|       |
   86|  9.96k|  sha->Nl = 0;
   87|  9.96k|  sha->Nh = 0;
   88|  9.96k|  sha->num = 0;
   89|  9.96k|  sha->md_len = SHA384_DIGEST_LENGTH;
  ------------------
  |  |  203|  9.96k|#define SHA384_DIGEST_LENGTH 48
  ------------------
   90|  9.96k|  return 1;
   91|  9.96k|}
SHA512_Init:
   94|  7.28k|int SHA512_Init(SHA512_CTX *sha) {
   95|  7.28k|  sha->h[0] = UINT64_C(0x6a09e667f3bcc908);
   96|  7.28k|  sha->h[1] = UINT64_C(0xbb67ae8584caa73b);
   97|  7.28k|  sha->h[2] = UINT64_C(0x3c6ef372fe94f82b);
   98|  7.28k|  sha->h[3] = UINT64_C(0xa54ff53a5f1d36f1);
   99|  7.28k|  sha->h[4] = UINT64_C(0x510e527fade682d1);
  100|  7.28k|  sha->h[5] = UINT64_C(0x9b05688c2b3e6c1f);
  101|  7.28k|  sha->h[6] = UINT64_C(0x1f83d9abfb41bd6b);
  102|  7.28k|  sha->h[7] = UINT64_C(0x5be0cd19137e2179);
  103|       |
  104|  7.28k|  sha->Nl = 0;
  105|  7.28k|  sha->Nh = 0;
  106|  7.28k|  sha->num = 0;
  107|  7.28k|  sha->md_len = SHA512_DIGEST_LENGTH;
  ------------------
  |  |  230|  7.28k|#define SHA512_DIGEST_LENGTH 64
  ------------------
  108|  7.28k|  return 1;
  109|  7.28k|}
SHA512:
  139|     83|                uint8_t out[SHA512_DIGEST_LENGTH]) {
  140|     83|  SHA512_CTX ctx;
  141|     83|  SHA512_Init(&ctx);
  142|     83|  SHA512_Update(&ctx, data, len);
  143|     83|  SHA512_Final(out, &ctx);
  144|     83|  OPENSSL_cleanse(&ctx, sizeof(ctx));
  145|     83|  return out;
  146|     83|}
SHA384_Final:
  164|  9.96k|int SHA384_Final(uint8_t out[SHA384_DIGEST_LENGTH], SHA512_CTX *sha) {
  165|       |  // This function must be paired with |SHA384_Init|, which sets |sha->md_len|
  166|       |  // to |SHA384_DIGEST_LENGTH|.
  167|  9.96k|  assert(sha->md_len == SHA384_DIGEST_LENGTH);
  168|  9.96k|  return sha512_final_impl(out, SHA384_DIGEST_LENGTH, sha);
  ------------------
  |  |  203|  9.96k|#define SHA384_DIGEST_LENGTH 48
  ------------------
  169|  9.96k|}
SHA384_Update:
  171|  10.3k|int SHA384_Update(SHA512_CTX *sha, const void *data, size_t len) {
  172|  10.3k|  return SHA512_Update(sha, data, len);
  173|  10.3k|}
SHA512_Update:
  190|  17.8k|int SHA512_Update(SHA512_CTX *c, const void *in_data, size_t len) {
  191|  17.8k|  uint64_t l;
  192|  17.8k|  uint8_t *p = c->p;
  193|  17.8k|  const uint8_t *data = in_data;
  194|       |
  195|  17.8k|  if (len == 0) {
  ------------------
  |  Branch (195:7): [True: 32, False: 17.8k]
  ------------------
  196|     32|    return 1;
  197|     32|  }
  198|       |
  199|  17.8k|  l = (c->Nl + (((uint64_t)len) << 3)) & UINT64_C(0xffffffffffffffff);
  200|  17.8k|  if (l < c->Nl) {
  ------------------
  |  Branch (200:7): [True: 0, False: 17.8k]
  ------------------
  201|      0|    c->Nh++;
  202|      0|  }
  203|  17.8k|  if (sizeof(len) >= 8) {
  ------------------
  |  Branch (203:7): [Folded - Ignored]
  ------------------
  204|  17.8k|    c->Nh += (((uint64_t)len) >> 61);
  205|  17.8k|  }
  206|  17.8k|  c->Nl = l;
  207|       |
  208|  17.8k|  if (c->num != 0) {
  ------------------
  |  Branch (208:7): [True: 0, False: 17.8k]
  ------------------
  209|      0|    size_t n = sizeof(c->p) - c->num;
  210|       |
  211|      0|    if (len < n) {
  ------------------
  |  Branch (211:9): [True: 0, False: 0]
  ------------------
  212|      0|      OPENSSL_memcpy(p + c->num, data, len);
  213|      0|      c->num += (unsigned int)len;
  214|      0|      return 1;
  215|      0|    } else {
  216|      0|      OPENSSL_memcpy(p + c->num, data, n), c->num = 0;
  217|      0|      len -= n;
  218|      0|      data += n;
  219|      0|      sha512_block_data_order(c->h, p, 1);
  220|      0|    }
  221|      0|  }
  222|       |
  223|  17.8k|  if (len >= sizeof(c->p)) {
  ------------------
  |  Branch (223:7): [True: 867, False: 16.9k]
  ------------------
  224|    867|    sha512_block_data_order(c->h, data, len / sizeof(c->p));
  225|    867|    data += len;
  226|    867|    len %= sizeof(c->p);
  227|    867|    data -= len;
  228|    867|  }
  229|       |
  230|  17.8k|  if (len != 0) {
  ------------------
  |  Branch (230:7): [True: 17.0k, False: 799]
  ------------------
  231|  17.0k|    OPENSSL_memcpy(p, data, len);
  232|  17.0k|    c->num = (int)len;
  233|  17.0k|  }
  234|       |
  235|  17.8k|  return 1;
  236|  17.8k|}
SHA512_Final:
  238|  7.28k|int SHA512_Final(uint8_t out[SHA512_DIGEST_LENGTH], SHA512_CTX *sha) {
  239|       |  // Ideally we would assert |sha->md_len| is |SHA512_DIGEST_LENGTH| to match
  240|       |  // the size hint, but calling code often pairs |SHA384_Init| with
  241|       |  // |SHA512_Final| and expects |sha->md_len| to carry the size over.
  242|       |  //
  243|       |  // TODO(davidben): Add an assert and fix code to match them up.
  244|  7.28k|  return sha512_final_impl(out, sha->md_len, sha);
  245|  7.28k|}
bcm.c:sha512_final_impl:
  247|  17.2k|static int sha512_final_impl(uint8_t *out, size_t md_len, SHA512_CTX *sha) {
  248|  17.2k|  uint8_t *p = sha->p;
  249|  17.2k|  size_t n = sha->num;
  250|       |
  251|  17.2k|  p[n] = 0x80;  // There always is a room for one
  252|  17.2k|  n++;
  253|  17.2k|  if (n > (sizeof(sha->p) - 16)) {
  ------------------
  |  Branch (253:7): [True: 26, False: 17.2k]
  ------------------
  254|     26|    OPENSSL_memset(p + n, 0, sizeof(sha->p) - n);
  255|     26|    n = 0;
  256|     26|    sha512_block_data_order(sha->h, p, 1);
  257|     26|  }
  258|       |
  259|  17.2k|  OPENSSL_memset(p + n, 0, sizeof(sha->p) - 16 - n);
  260|  17.2k|  CRYPTO_store_u64_be(p + sizeof(sha->p) - 16, sha->Nh);
  261|  17.2k|  CRYPTO_store_u64_be(p + sizeof(sha->p) - 8, sha->Nl);
  262|       |
  263|  17.2k|  sha512_block_data_order(sha->h, p, 1);
  264|       |
  265|  17.2k|  if (out == NULL) {
  ------------------
  |  Branch (265:7): [True: 0, False: 17.2k]
  ------------------
  266|       |    // TODO(davidben): This NULL check is absent in other low-level hash 'final'
  267|       |    // functions and is one of the few places one can fail.
  268|      0|    return 0;
  269|      0|  }
  270|       |
  271|  17.2k|  assert(md_len % 8 == 0);
  272|  17.2k|  const size_t out_words = md_len / 8;
  273|   135k|  for (size_t i = 0; i < out_words; i++) {
  ------------------
  |  Branch (273:22): [True: 118k, False: 17.2k]
  ------------------
  274|   118k|    CRYPTO_store_u64_be(out, sha->h[i]);
  275|   118k|    out += 8;
  276|   118k|  }
  277|       |
  278|  17.2k|  FIPS_service_indicator_update_state();
  279|  17.2k|  return 1;
  280|  17.2k|}

evp.c:OPENSSL_memset:
 1055|  1.23k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  1.23k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1.23k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  1.23k|  return memset(dst, c, n);
 1061|  1.23k|}
p_x25519_asn1.c:OPENSSL_memcpy:
 1039|     31|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|     31|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 31]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|     31|  return memcpy(dst, src, n);
 1045|     31|}
mem.c:OPENSSL_memset:
 1055|  6.16M|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  6.16M|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 6.16M]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  6.16M|  return memset(dst, c, n);
 1061|  6.16M|}
mem.c:OPENSSL_memcpy:
 1039|    170|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    170|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 170]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|    170|  return memcpy(dst, src, n);
 1045|    170|}
pkcs8_x509.c:OPENSSL_memset:
 1055|  3.87k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  3.87k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 3.87k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  3.87k|  return memset(dst, c, n);
 1061|  3.87k|}
refcount.c:CRYPTO_atomic_load_u32:
  626|  2.75k|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|  2.75k|  return atomic_load(val);
  628|  2.75k|}
refcount.c:CRYPTO_atomic_compare_exchange_weak_u32:
  631|  2.75k|    CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
  632|  2.75k|  return atomic_compare_exchange_weak(val, expected, desired);
  633|  2.75k|}
stack.c:OPENSSL_memset:
 1055|  20.0k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  20.0k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 20.0k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  20.0k|  return memset(dst, c, n);
 1061|  20.0k|}
x_name.c:OPENSSL_memcpy:
 1039|    397|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    397|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 397]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|    397|  return memcpy(dst, src, n);
 1045|    397|}
x_x509.c:OPENSSL_memset:
 1055|    610|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|    610|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 610]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|    610|  return memset(dst, c, n);
 1061|    610|}
bcm.c:CRYPTO_is_AESNI_capable:
 1324|     43|OPENSSL_INLINE int CRYPTO_is_AESNI_capable(void) {
 1325|       |#if defined(__AES__)
 1326|       |  return 1;
 1327|       |#else
 1328|     43|  return (OPENSSL_ia32cap_get()[1] & (1 << 25)) != 0;
 1329|     43|#endif
 1330|     43|}
bcm.c:OPENSSL_ia32cap_get:
 1270|     43|OPENSSL_INLINE const uint32_t *OPENSSL_ia32cap_get(void) {
 1271|     43|  return OPENSSL_ia32cap_P;
 1272|     43|}
bcm.c:CRYPTO_bswap4:
  945|  42.0M|static inline uint32_t CRYPTO_bswap4(uint32_t x) {
  946|  42.0M|  return __builtin_bswap32(x);
  947|  42.0M|}
bcm.c:CRYPTO_store_u32_be:
 1086|  42.0M|static inline void CRYPTO_store_u32_be(void *out, uint32_t v) {
 1087|  42.0M|  v = CRYPTO_bswap4(v);
 1088|  42.0M|  OPENSSL_memcpy(out, &v, sizeof(v));
 1089|  42.0M|}
bcm.c:OPENSSL_memmove:
 1047|      4|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|      4|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 4]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|      4|  return memmove(dst, src, n);
 1053|      4|}
bcm.c:OPENSSL_memcpy:
 1039|  51.4M|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  51.4M|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 6.00k, False: 51.4M]
  ------------------
 1041|  6.00k|    return dst;
 1042|  6.00k|  }
 1043|       |
 1044|  51.4M|  return memcpy(dst, src, n);
 1045|  51.4M|}
bcm.c:constant_time_is_zero_w:
  427|   817k|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|   817k|  return constant_time_msb_w(~a & (a - 1));
  440|   817k|}
bcm.c:constant_time_msb_w:
  368|   859k|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|   859k|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|   859k|}
bcm.c:constant_time_eq_w:
  450|   717k|                                               crypto_word_t b) {
  451|   717k|  return constant_time_is_zero_w(a ^ b);
  452|   717k|}
bcm.c:constant_time_select_w:
  477|  37.8M|                                                   crypto_word_t b) {
  478|       |  // Clang recognizes this pattern as a select. While it usually transforms it
  479|       |  // to a cmov, it sometimes further transforms it into a branch, which we do
  480|       |  // not want.
  481|       |  //
  482|       |  // Hiding the value of the mask from the compiler evades this transformation.
  483|  37.8M|  mask = value_barrier_w(mask);
  484|  37.8M|  return (mask & a) | (~mask & b);
  485|  37.8M|}
bcm.c:value_barrier_w:
  340|  37.9M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  37.9M|#if defined(__GNUC__) || defined(__clang__)
  342|  37.9M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  37.9M|#endif
  344|  37.9M|  return a;
  345|  37.9M|}
bcm.c:OPENSSL_memset:
 1055|  18.2M|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  18.2M|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 3.44k, False: 18.2M]
  ------------------
 1057|  3.44k|    return dst;
 1058|  3.44k|  }
 1059|       |
 1060|  18.2M|  return memset(dst, c, n);
 1061|  18.2M|}
bcm.c:CRYPTO_load_word_be:
 1122|  65.5k|static inline crypto_word_t CRYPTO_load_word_be(const void *in) {
 1123|  65.5k|  crypto_word_t v;
 1124|  65.5k|  OPENSSL_memcpy(&v, in, sizeof(v));
 1125|  65.5k|#if defined(OPENSSL_64_BIT)
 1126|  65.5k|  static_assert(sizeof(v) == 8, "crypto_word_t has unexpected size");
 1127|  65.5k|  return CRYPTO_bswap8(v);
 1128|       |#else
 1129|       |  static_assert(sizeof(v) == 4, "crypto_word_t has unexpected size");
 1130|       |  return CRYPTO_bswap4(v);
 1131|       |#endif
 1132|  65.5k|}
bcm.c:CRYPTO_bswap8:
  949|   218k|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|   218k|  return __builtin_bswap64(x);
  951|   218k|}
bcm.c:constant_time_select_int:
  503|  84.9k|static inline int constant_time_select_int(crypto_word_t mask, int a, int b) {
  504|  84.9k|  return (int)(constant_time_select_w(mask, (crypto_word_t)(a),
  505|  84.9k|                                      (crypto_word_t)(b)));
  506|  84.9k|}
bcm.c:constant_time_declassify_int:
  572|    332|static inline int constant_time_declassify_int(int v) {
  573|    332|  static_assert(sizeof(uint32_t) == sizeof(int),
  574|    332|                "int is not the same size as uint32_t");
  575|       |  // See comment above.
  576|    332|  CONSTTIME_DECLASSIFY(&v, sizeof(v));
  577|    332|  return value_barrier_u32(v);
  578|    332|}
bcm.c:value_barrier_u32:
  348|    332|static inline uint32_t value_barrier_u32(uint32_t a) {
  349|    332|#if defined(__GNUC__) || defined(__clang__)
  350|    332|  __asm__("" : "+r"(a) : /* no inputs */);
  351|    332|#endif
  352|    332|  return a;
  353|    332|}
bcm.c:constant_time_lt_w:
  374|  41.7k|                                               crypto_word_t b) {
  375|       |  // Consider the two cases of the problem:
  376|       |  //   msb(a) == msb(b): a < b iff the MSB of a - b is set.
  377|       |  //   msb(a) != msb(b): a < b iff the MSB of b is set.
  378|       |  //
  379|       |  // If msb(a) == msb(b) then the following evaluates as:
  380|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  381|       |  //   msb(a^((a-b) ^ a))       ==   (because msb(a^b) == 0)
  382|       |  //   msb(a^a^(a-b))           ==   (rearranging)
  383|       |  //   msb(a-b)                      (because ∀x. x^x == 0)
  384|       |  //
  385|       |  // Else, if msb(a) != msb(b) then the following evaluates as:
  386|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  387|       |  //   msb(a^(𝟙 | ((a-b)^a)))   ==   (because msb(a^b) == 1 and 𝟙
  388|       |  //                                  represents a value s.t. msb(𝟙) = 1)
  389|       |  //   msb(a^𝟙)                 ==   (because ORing with 1 results in 1)
  390|       |  //   msb(b)
  391|       |  //
  392|       |  //
  393|       |  // Here is an SMT-LIB verification of this formula:
  394|       |  //
  395|       |  // (define-fun lt ((a (_ BitVec 32)) (b (_ BitVec 32))) (_ BitVec 32)
  396|       |  //   (bvxor a (bvor (bvxor a b) (bvxor (bvsub a b) a)))
  397|       |  // )
  398|       |  //
  399|       |  // (declare-fun a () (_ BitVec 32))
  400|       |  // (declare-fun b () (_ BitVec 32))
  401|       |  //
  402|       |  // (assert (not (= (= #x00000001 (bvlshr (lt a b) #x0000001f)) (bvult a b))))
  403|       |  // (check-sat)
  404|       |  // (get-model)
  405|  41.7k|  return constant_time_msb_w(a^((a^b)|((a-b)^a)));
  406|  41.7k|}
bcm.c:constant_time_declassify_w:
  556|  29.4k|static inline crypto_word_t constant_time_declassify_w(crypto_word_t v) {
  557|       |  // Return |v| through a value barrier to be safe. Valgrind-based constant-time
  558|       |  // validation is partly to check the compiler has not undone any constant-time
  559|       |  // work. Any place |BORINGSSL_CONSTANT_TIME_VALIDATION| influences
  560|       |  // optimizations, this validation is inaccurate.
  561|       |  //
  562|       |  // However, by sending pointers through valgrind, we likely inhibit escape
  563|       |  // analysis. On local variables, particularly booleans, we likely
  564|       |  // significantly impact optimizations.
  565|       |  //
  566|       |  // Thus, to be safe, stick a value barrier, in hopes of comparably inhibiting
  567|       |  // compiler analysis.
  568|  29.4k|  CONSTTIME_DECLASSIFY(&v, sizeof(v));
  569|  29.4k|  return value_barrier_w(v);
  570|  29.4k|}
bcm.c:CRYPTO_store_u32_le:
 1076|   180k|static inline void CRYPTO_store_u32_le(void *out, uint32_t v) {
 1077|   180k|  OPENSSL_memcpy(out, &v, sizeof(v));
 1078|   180k|}
bcm.c:CRYPTO_load_u32_le:
 1070|  2.66M|static inline uint32_t CRYPTO_load_u32_le(const void *in) {
 1071|  2.66M|  uint32_t v;
 1072|  2.66M|  OPENSSL_memcpy(&v, in, sizeof(v));
 1073|  2.66M|  return v;
 1074|  2.66M|}
bcm.c:CRYPTO_rotl_u32:
 1141|  8.00M|static inline uint32_t CRYPTO_rotl_u32(uint32_t value, int shift) {
 1142|       |#if defined(_MSC_VER)
 1143|       |  return _rotl(value, shift);
 1144|       |#else
 1145|  8.00M|  return (value << shift) | (value >> ((-shift) & 31));
 1146|  8.00M|#endif
 1147|  8.00M|}
bcm.c:CRYPTO_store_u64_be:
 1107|   152k|static inline void CRYPTO_store_u64_be(void *out, uint64_t v) {
 1108|   152k|  v = CRYPTO_bswap8(v);
 1109|   152k|  OPENSSL_memcpy(out, &v, sizeof(v));
 1110|   152k|}
a_int.c:OPENSSL_memcpy:
 1039|     66|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|     66|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 66]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|     66|  return memcpy(dst, src, n);
 1045|     66|}
a_int.c:CRYPTO_bswap8:
  949|     29|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|     29|  return __builtin_bswap64(x);
  951|     29|}
a_int.c:CRYPTO_load_u64_be:
 1101|     29|static inline uint64_t CRYPTO_load_u64_be(const void *ptr) {
 1102|     29|  uint64_t ret;
 1103|     29|  OPENSSL_memcpy(&ret, ptr, sizeof(ret));
 1104|     29|  return CRYPTO_bswap8(ret);
 1105|     29|}
asn1_lib.c:OPENSSL_memcpy:
 1039|  3.71k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  3.71k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 39, False: 3.68k]
  ------------------
 1041|     39|    return dst;
 1042|     39|  }
 1043|       |
 1044|  3.68k|  return memcpy(dst, src, n);
 1045|  3.71k|}
tasn_enc.c:OPENSSL_memcpy:
 1039|  2.19k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  2.19k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 2.19k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  2.19k|  return memcpy(dst, src, n);
 1045|  2.19k|}
tasn_new.c:OPENSSL_memset:
 1055|  5.54k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  5.54k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 5.54k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  5.54k|  return memset(dst, c, n);
 1061|  5.54k|}
buf.c:OPENSSL_memset:
 1055|  2.01k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  2.01k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 2.01k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  2.01k|  return memset(dst, c, n);
 1061|  2.01k|}
cbb.c:OPENSSL_memset:
 1055|  7.51M|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  7.51M|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 7.51M]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  7.51M|  return memset(dst, c, n);
 1061|  7.51M|}
cbb.c:OPENSSL_memmove:
 1047|   108k|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|   108k|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 108k]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|   108k|  return memmove(dst, src, n);
 1053|   108k|}
cbb.c:OPENSSL_memcpy:
 1039|  3.65M|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  3.65M|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 86.4k, False: 3.56M]
  ------------------
 1041|  86.4k|    return dst;
 1042|  86.4k|  }
 1043|       |
 1044|  3.56M|  return memcpy(dst, src, n);
 1045|  3.65M|}
curve25519.c:OPENSSL_memmove:
 1047|     83|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|     83|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 83]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|     83|  return memmove(dst, src, n);
 1053|     83|}
curve25519.c:CRYPTO_is_BMI1_capable:
 1352|    114|OPENSSL_INLINE int CRYPTO_is_BMI1_capable(void) {
 1353|       |#if defined(__BMI1__)
 1354|       |  return 1;
 1355|       |#else
 1356|    114|  return (OPENSSL_ia32cap_get()[2] & (1 << 3)) != 0;
 1357|    114|#endif
 1358|    114|}
curve25519.c:OPENSSL_ia32cap_get:
 1270|    342|OPENSSL_INLINE const uint32_t *OPENSSL_ia32cap_get(void) {
 1271|    342|  return OPENSSL_ia32cap_P;
 1272|    342|}
curve25519.c:CRYPTO_is_BMI2_capable:
 1368|    114|OPENSSL_INLINE int CRYPTO_is_BMI2_capable(void) {
 1369|       |#if defined(__BMI2__)
 1370|       |  return 1;
 1371|       |#else
 1372|    114|  return (OPENSSL_ia32cap_get()[2] & (1 << 8)) != 0;
 1373|    114|#endif
 1374|    114|}
curve25519.c:CRYPTO_is_ADX_capable:
 1376|    114|OPENSSL_INLINE int CRYPTO_is_ADX_capable(void) {
 1377|       |#if defined(__ADX__)
 1378|       |  return 1;
 1379|       |#else
 1380|    114|  return (OPENSSL_ia32cap_get()[2] & (1 << 19)) != 0;
 1381|    114|#endif
 1382|    114|}
curve25519.c:OPENSSL_memcpy:
 1039|    197|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    197|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 197]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|    197|  return memcpy(dst, src, n);
 1045|    197|}
curve25519_64_adx.c:OPENSSL_memcpy:
 1039|  7.41k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  7.41k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 7.41k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  7.41k|  return memcpy(dst, src, n);
 1045|  7.41k|}
curve25519_64_adx.c:constant_time_msb_w:
  368|  80.2k|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|  80.2k|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|  80.2k|}
curve25519_64_adx.c:constant_time_is_zero_w:
  427|  72.9k|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|  72.9k|  return constant_time_msb_w(~a & (a - 1));
  440|  72.9k|}
curve25519_64_adx.c:constant_time_conditional_memxor:
  527|  58.3k|                                                    const crypto_word_t mask) {
  528|  58.3k|  assert(!buffers_alias(dst, n, src, n));
  529|  58.3k|  uint8_t *out = (uint8_t *)dst;
  530|  58.3k|  const uint8_t *in = (const uint8_t *)src;
  531|  5.66M|  for (size_t i = 0; i < n; i++) {
  ------------------
  |  Branch (531:22): [True: 5.60M, False: 58.3k]
  ------------------
  532|  5.60M|    out[i] ^= value_barrier_w(mask) & in[i];
  533|  5.60M|  }
  534|  58.3k|}
curve25519_64_adx.c:buffers_alias:
  269|  80.2k|                                const void *b, size_t b_bytes) {
  270|       |  // Cast |a| and |b| to integers. In C, pointer comparisons between unrelated
  271|       |  // objects are undefined whereas pointer to integer conversions are merely
  272|       |  // implementation-defined. We assume the implementation defined it in a sane
  273|       |  // way.
  274|  80.2k|  uintptr_t a_u = (uintptr_t)a;
  275|  80.2k|  uintptr_t b_u = (uintptr_t)b;
  276|  80.2k|  return a_u + a_bytes > b_u && b_u + b_bytes > a_u;
  ------------------
  |  Branch (276:10): [True: 58.3k, False: 21.8k]
  |  Branch (276:33): [True: 0, False: 58.3k]
  ------------------
  277|  80.2k|}
curve25519_64_adx.c:value_barrier_w:
  340|  6.30M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  6.30M|#if defined(__GNUC__) || defined(__clang__)
  342|  6.30M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  6.30M|#endif
  344|  6.30M|  return a;
  345|  6.30M|}
curve25519_64_adx.c:constant_time_eq_w:
  450|  58.3k|                                               crypto_word_t b) {
  451|  58.3k|  return constant_time_is_zero_w(a ^ b);
  452|  58.3k|}
curve25519_64_adx.c:constant_time_conditional_memcpy:
  513|  21.8k|                                                    const crypto_word_t mask) {
  514|  21.8k|  assert(!buffers_alias(dst, n, src, n));
  515|  21.8k|  uint8_t *out = (uint8_t *)dst;
  516|  21.8k|  const uint8_t *in = (const uint8_t *)src;
  517|   722k|  for (size_t i = 0; i < n; i++) {
  ------------------
  |  Branch (517:22): [True: 700k, False: 21.8k]
  ------------------
  518|   700k|    out[i] = constant_time_select_8(mask, in[i], out[i]);
  519|   700k|  }
  520|  21.8k|}
curve25519_64_adx.c:constant_time_select_8:
  490|   700k|                                             uint8_t b) {
  491|       |  // |mask| is a word instead of |uint8_t| to avoid materializing 0x000..0MM
  492|       |  // Making both |mask| and its value barrier |uint8_t| would allow the compiler
  493|       |  // to materialize 0x????..?MM instead, but only clang is that clever.
  494|       |  // However, vectorization of bitwise operations seems to work better on
  495|       |  // |uint8_t| than a mix of |uint64_t| and |uint8_t|, so |m| is cast to
  496|       |  // |uint8_t| after the value barrier but before the bitwise operations.
  497|   700k|  uint8_t m = value_barrier_w(mask);
  498|   700k|  return (m & a) | (~m & b);
  499|   700k|}
digest_extra.c:OPENSSL_memcmp:
 1031|  4.14k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  4.14k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 4.14k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  4.14k|  return memcmp(s1, s2, n);
 1037|  4.14k|}
dsa.c:OPENSSL_memset:
 1055|    164|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|    164|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 164]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|    164|  return memset(dst, c, n);
 1061|    164|}
ec_asn1.c:OPENSSL_memcmp:
 1031|    705|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|    705|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 705]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|    705|  return memcmp(s1, s2, n);
 1037|    705|}
err.c:OPENSSL_memset:
 1055|  8.35k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  8.35k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 8.35k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  8.35k|  return memset(dst, c, n);
 1061|  8.35k|}
evp_asn1.c:OPENSSL_memcmp:
 1031|  1.48k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  1.48k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 1.48k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  1.48k|  return memcmp(s1, s2, n);
 1037|  1.48k|}
obj.c:OPENSSL_memcpy:
 1039|  3.16k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  3.16k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 3.16k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  3.16k|  return memcpy(dst, src, n);
 1045|  3.16k|}
pkcs8.c:OPENSSL_memset:
 1055|  5.23k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  5.23k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 5.23k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  5.23k|  return memset(dst, c, n);
 1061|  5.23k|}
pkcs8.c:OPENSSL_memcpy:
 1039|  5.68k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  5.68k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 5.68k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  5.68k|  return memcpy(dst, src, n);
 1045|  5.68k|}
thread_pthread.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
des.c:CRYPTO_rotr_u32:
 1149|  4.25M|static inline uint32_t CRYPTO_rotr_u32(uint32_t value, int shift) {
 1150|       |#if defined(_MSC_VER)
 1151|       |  return _rotr(value, shift);
 1152|       |#else
 1153|  4.25M|  return (value >> shift) | (value << ((-shift) & 31));
 1154|  4.25M|#endif
 1155|  4.25M|}
pbkdf.c:OPENSSL_memcpy:
 1039|     76|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|     76|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 76]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|     76|  return memcpy(dst, src, n);
 1045|     76|}

OPENSSL_malloc:
  228|  98.6k|void *OPENSSL_malloc(size_t size) {
  229|  98.6k|  if (should_fail_allocation()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 98.6k]
  ------------------
  230|      0|    goto err;
  231|      0|  }
  232|       |
  233|  98.6k|  if (OPENSSL_memory_alloc != NULL) {
  ------------------
  |  Branch (233:7): [True: 0, False: 98.6k]
  ------------------
  234|      0|    assert(OPENSSL_memory_free != NULL);
  235|      0|    assert(OPENSSL_memory_get_size != NULL);
  236|      0|    void *ptr = OPENSSL_memory_alloc(size);
  237|      0|    if (ptr == NULL && size != 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  |  Branch (237:24): [True: 0, False: 0]
  ------------------
  238|      0|      goto err;
  239|      0|    }
  240|      0|    return ptr;
  241|      0|  }
  242|       |
  243|  98.6k|  if (size + OPENSSL_MALLOC_PREFIX < size) {
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  |  Branch (243:7): [True: 0, False: 98.6k]
  ------------------
  244|       |    // |OPENSSL_malloc| is a central function in BoringSSL thus a reference to
  245|       |    // |kBoringSSLBinaryTag| is created here so that the tag isn't discarded by
  246|       |    // the linker. The following is sufficient to stop GCC, Clang, and MSVC
  247|       |    // optimising away the reference at the time of writing. Since this
  248|       |    // probably results in an actual memory reference, it is put in this very
  249|       |    // rare code path.
  250|      0|    uint8_t unused = *(volatile uint8_t *)kBoringSSLBinaryTag;
  251|      0|    (void) unused;
  252|      0|    goto err;
  253|      0|  }
  254|       |
  255|  98.6k|  void *ptr = malloc(size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  256|  98.6k|  if (ptr == NULL) {
  ------------------
  |  Branch (256:7): [True: 0, False: 98.6k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|  98.6k|  *(size_t *)ptr = size;
  261|       |
  262|  98.6k|  __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  263|  98.6k|  return ((uint8_t *)ptr) + OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  264|       |
  265|      0| err:
  266|       |  // This only works because ERR does not call OPENSSL_malloc.
  267|      0|  OPENSSL_PUT_ERROR(CRYPTO, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|  return NULL;
  269|  98.6k|}
OPENSSL_free:
  271|   345k|void OPENSSL_free(void *orig_ptr) {
  272|   345k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (272:7): [True: 247k, False: 98.6k]
  ------------------
  273|   247k|    return;
  274|   247k|  }
  275|       |
  276|  98.6k|  if (OPENSSL_memory_free != NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 98.6k]
  ------------------
  277|      0|    OPENSSL_memory_free(orig_ptr);
  278|      0|    return;
  279|      0|  }
  280|       |
  281|  98.6k|  void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  282|  98.6k|  __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  283|       |
  284|  98.6k|  size_t size = *(size_t *)ptr;
  285|  98.6k|  OPENSSL_cleanse(ptr, size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  98.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  286|       |
  287|       |// ASan knows to intercept malloc and free, but not sdallocx.
  288|       |#if defined(OPENSSL_ASAN)
  289|       |  (void)sdallocx;
  290|       |  free(ptr);
  291|       |#else
  292|  98.6k|  if (sdallocx) {
  ------------------
  |  Branch (292:7): [True: 0, False: 98.6k]
  ------------------
  293|      0|    sdallocx(ptr, size + OPENSSL_MALLOC_PREFIX, 0 /* flags */);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  294|  98.6k|  } else {
  295|  98.6k|    free(ptr);
  296|  98.6k|  }
  297|  98.6k|#endif
  298|  98.6k|}
OPENSSL_realloc:
  300|  6.19k|void *OPENSSL_realloc(void *orig_ptr, size_t new_size) {
  301|  6.19k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (301:7): [True: 764, False: 5.43k]
  ------------------
  302|    764|    return OPENSSL_malloc(new_size);
  303|    764|  }
  304|       |
  305|  5.43k|  size_t old_size;
  306|  5.43k|  if (OPENSSL_memory_get_size != NULL) {
  ------------------
  |  Branch (306:7): [True: 0, False: 5.43k]
  ------------------
  307|      0|    old_size = OPENSSL_memory_get_size(orig_ptr);
  308|  5.43k|  } else {
  309|  5.43k|    void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  5.43k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  310|  5.43k|    __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  5.43k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  311|  5.43k|    old_size = *(size_t *)ptr;
  312|  5.43k|    __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  5.43k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  313|  5.43k|  }
  314|       |
  315|  5.43k|  void *ret = OPENSSL_malloc(new_size);
  316|  5.43k|  if (ret == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 5.43k]
  ------------------
  317|      0|    return NULL;
  318|      0|  }
  319|       |
  320|  5.43k|  size_t to_copy = new_size;
  321|  5.43k|  if (old_size < to_copy) {
  ------------------
  |  Branch (321:7): [True: 5.43k, False: 0]
  ------------------
  322|  5.43k|    to_copy = old_size;
  323|  5.43k|  }
  324|       |
  325|  5.43k|  memcpy(ret, orig_ptr, to_copy);
  326|  5.43k|  OPENSSL_free(orig_ptr);
  327|       |
  328|  5.43k|  return ret;
  329|  5.43k|}
OPENSSL_cleanse:
  331|  6.16M|void OPENSSL_cleanse(void *ptr, size_t len) {
  332|       |#if defined(OPENSSL_WINDOWS)
  333|       |  SecureZeroMemory(ptr, len);
  334|       |#else
  335|  6.16M|  OPENSSL_memset(ptr, 0, len);
  336|       |
  337|  6.16M|#if !defined(OPENSSL_NO_ASM)
  338|       |  /* As best as we can tell, this is sufficient to break any optimisations that
  339|       |     might try to eliminate "superfluous" memsets. If there's an easy way to
  340|       |     detect memset_s, it would be better to use that. */
  341|  6.16M|  __asm__ __volatile__("" : : "r"(ptr) : "memory");
  342|  6.16M|#endif
  343|  6.16M|#endif  // !OPENSSL_NO_ASM
  344|  6.16M|}
CRYPTO_memcmp:
  360|  18.2k|int CRYPTO_memcmp(const void *in_a, const void *in_b, size_t len) {
  361|  18.2k|  const uint8_t *a = in_a;
  362|  18.2k|  const uint8_t *b = in_b;
  363|  18.2k|  uint8_t x = 0;
  364|       |
  365|   197k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (365:22): [True: 179k, False: 18.2k]
  ------------------
  366|   179k|    x |= a[i] ^ b[i];
  367|   179k|  }
  368|       |
  369|  18.2k|  return x;
  370|  18.2k|}
OPENSSL_isdigit:
  417|  4.35k|int OPENSSL_isdigit(int c) { return c >= '0' && c <= '9'; }
  ------------------
  |  Branch (417:37): [True: 4.34k, False: 12]
  |  Branch (417:49): [True: 4.32k, False: 22]
  ------------------
OPENSSL_tolower:
  441|  11.3k|int OPENSSL_tolower(int c) {
  442|  11.3k|  if (c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (442:7): [True: 10.5k, False: 792]
  |  Branch (442:19): [True: 2.65k, False: 7.92k]
  ------------------
  443|  2.65k|    return c + ('a' - 'A');
  444|  2.65k|  }
  445|  8.71k|  return c;
  446|  11.3k|}
OPENSSL_isspace:
  448|  15.2k|int OPENSSL_isspace(int c) {
  449|  15.2k|  return c == '\t' || c == '\n' || c == '\v' || c == '\f' || c == '\r' ||
  ------------------
  |  Branch (449:10): [True: 14, False: 15.2k]
  |  Branch (449:23): [True: 19, False: 15.1k]
  |  Branch (449:36): [True: 20, False: 15.1k]
  |  Branch (449:49): [True: 16, False: 15.1k]
  |  Branch (449:62): [True: 16, False: 15.1k]
  ------------------
  450|  15.2k|         c == ' ';
  ------------------
  |  Branch (450:10): [True: 768, False: 14.3k]
  ------------------
  451|  15.2k|}
OPENSSL_strlcpy:
  572|  3.81k|size_t OPENSSL_strlcpy(char *dst, const char *src, size_t dst_size) {
  573|  3.81k|  size_t l = 0;
  574|       |
  575|  32.8k|  for (; dst_size > 1 && *src; dst_size--) {
  ------------------
  |  Branch (575:10): [True: 31.7k, False: 1.05k]
  |  Branch (575:26): [True: 29.0k, False: 2.76k]
  ------------------
  576|  29.0k|    *dst++ = *src++;
  577|  29.0k|    l++;
  578|  29.0k|  }
  579|       |
  580|  3.81k|  if (dst_size) {
  ------------------
  |  Branch (580:7): [True: 3.81k, False: 0]
  ------------------
  581|  3.81k|    *dst = 0;
  582|  3.81k|  }
  583|       |
  584|  3.81k|  return l + strlen(src);
  585|  3.81k|}
OPENSSL_strlcat:
  587|  3.81k|size_t OPENSSL_strlcat(char *dst, const char *src, size_t dst_size) {
  588|  3.81k|  size_t l = 0;
  589|  39.8k|  for (; dst_size > 0 && *dst; dst_size--, dst++) {
  ------------------
  |  Branch (589:10): [True: 39.8k, False: 0]
  |  Branch (589:26): [True: 36.0k, False: 3.81k]
  ------------------
  590|  36.0k|    l++;
  591|  36.0k|  }
  592|  3.81k|  return l + OPENSSL_strlcpy(dst, src, dst_size);
  593|  3.81k|}
OPENSSL_memdup:
  595|    170|void *OPENSSL_memdup(const void *data, size_t size) {
  596|    170|  if (size == 0) {
  ------------------
  |  Branch (596:7): [True: 0, False: 170]
  ------------------
  597|      0|    return NULL;
  598|      0|  }
  599|       |
  600|    170|  void *ret = OPENSSL_malloc(size);
  601|    170|  if (ret == NULL) {
  ------------------
  |  Branch (601:7): [True: 0, False: 170]
  ------------------
  602|      0|    return NULL;
  603|      0|  }
  604|       |
  605|    170|  OPENSSL_memcpy(ret, data, size);
  606|    170|  return ret;
  607|    170|}
mem.c:should_fail_allocation:
  225|  98.6k|static int should_fail_allocation(void) { return 0; }
mem.c:__asan_poison_memory_region:
   90|   104k|static void __asan_poison_memory_region(const void *addr, size_t size) {}
mem.c:__asan_unpoison_memory_region:
   91|   104k|static void __asan_unpoison_memory_region(const void *addr, size_t size) {}

OBJ_dup:
  101|  3.16k|ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o) {
  102|  3.16k|  ASN1_OBJECT *r;
  103|  3.16k|  unsigned char *data = NULL;
  104|  3.16k|  char *sn = NULL, *ln = NULL;
  105|       |
  106|  3.16k|  if (o == NULL) {
  ------------------
  |  Branch (106:7): [True: 0, False: 3.16k]
  ------------------
  107|      0|    return NULL;
  108|      0|  }
  109|       |
  110|  3.16k|  if (!(o->flags & ASN1_OBJECT_FLAG_DYNAMIC)) {
  ------------------
  |  |  105|  3.16k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  |  Branch (110:7): [True: 0, False: 3.16k]
  ------------------
  111|       |    // TODO(fork): this is a little dangerous.
  112|      0|    return (ASN1_OBJECT *)o;
  113|      0|  }
  114|       |
  115|  3.16k|  r = ASN1_OBJECT_new();
  116|  3.16k|  if (r == NULL) {
  ------------------
  |  Branch (116:7): [True: 0, False: 3.16k]
  ------------------
  117|      0|    OPENSSL_PUT_ERROR(OBJ, ERR_R_ASN1_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|    return NULL;
  119|      0|  }
  120|  3.16k|  r->ln = r->sn = NULL;
  121|       |
  122|  3.16k|  data = OPENSSL_malloc(o->length);
  123|  3.16k|  if (data == NULL) {
  ------------------
  |  Branch (123:7): [True: 0, False: 3.16k]
  ------------------
  124|      0|    goto err;
  125|      0|  }
  126|  3.16k|  if (o->data != NULL) {
  ------------------
  |  Branch (126:7): [True: 3.16k, False: 0]
  ------------------
  127|  3.16k|    OPENSSL_memcpy(data, o->data, o->length);
  128|  3.16k|  }
  129|       |
  130|       |  // once data is attached to an object, it remains const
  131|  3.16k|  r->data = data;
  132|  3.16k|  r->length = o->length;
  133|  3.16k|  r->nid = o->nid;
  134|       |
  135|  3.16k|  if (o->ln != NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 3.16k]
  ------------------
  136|      0|    ln = OPENSSL_strdup(o->ln);
  137|      0|    if (ln == NULL) {
  ------------------
  |  Branch (137:9): [True: 0, False: 0]
  ------------------
  138|      0|      goto err;
  139|      0|    }
  140|      0|  }
  141|       |
  142|  3.16k|  if (o->sn != NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 3.16k]
  ------------------
  143|      0|    sn = OPENSSL_strdup(o->sn);
  144|      0|    if (sn == NULL) {
  ------------------
  |  Branch (144:9): [True: 0, False: 0]
  ------------------
  145|      0|      goto err;
  146|      0|    }
  147|      0|  }
  148|       |
  149|  3.16k|  r->sn = sn;
  150|  3.16k|  r->ln = ln;
  151|       |
  152|  3.16k|  r->flags =
  153|  3.16k|      o->flags | (ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  105|  3.16k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
                    o->flags | (ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  106|  3.16k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  154|  3.16k|                  ASN1_OBJECT_FLAG_DYNAMIC_DATA);
  ------------------
  |  |  107|  3.16k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  155|  3.16k|  return r;
  156|       |
  157|      0|err:
  158|      0|  OPENSSL_free(ln);
  159|      0|  OPENSSL_free(sn);
  160|      0|  OPENSSL_free(data);
  161|      0|  OPENSSL_free(r);
  162|      0|  return NULL;
  163|  3.16k|}
OBJ_nid2obj:
  344|  3.70k|ASN1_OBJECT *OBJ_nid2obj(int nid) {
  345|  3.70k|  if (nid >= 0 && nid < NUM_NID) {
  ------------------
  |  |   60|  3.70k|#define NUM_NID 965
  ------------------
  |  Branch (345:7): [True: 3.70k, False: 0]
  |  Branch (345:19): [True: 3.70k, False: 0]
  ------------------
  346|  3.70k|    if (nid != NID_undef && kObjects[nid].nid == NID_undef) {
  ------------------
  |  |   85|  7.41k|#define NID_undef 0
  ------------------
                  if (nid != NID_undef && kObjects[nid].nid == NID_undef) {
  ------------------
  |  |   85|      0|#define NID_undef 0
  ------------------
  |  Branch (346:9): [True: 0, False: 3.70k]
  |  Branch (346:29): [True: 0, False: 0]
  ------------------
  347|      0|      goto err;
  348|      0|    }
  349|  3.70k|    return (ASN1_OBJECT *)&kObjects[nid];
  350|  3.70k|  }
  351|       |
  352|      0|  CRYPTO_STATIC_MUTEX_lock_read(&global_added_lock);
  353|      0|  if (global_added_by_nid != NULL) {
  ------------------
  |  Branch (353:7): [True: 0, False: 0]
  ------------------
  354|      0|    ASN1_OBJECT *match, template;
  355|       |
  356|      0|    template.nid = nid;
  357|      0|    match = lh_ASN1_OBJECT_retrieve(global_added_by_nid, &template);
  358|      0|    if (match != NULL) {
  ------------------
  |  Branch (358:9): [True: 0, False: 0]
  ------------------
  359|      0|      CRYPTO_STATIC_MUTEX_unlock_read(&global_added_lock);
  360|      0|      return match;
  361|      0|    }
  362|      0|  }
  363|      0|  CRYPTO_STATIC_MUTEX_unlock_read(&global_added_lock);
  364|       |
  365|      0|err:
  366|      0|  OPENSSL_PUT_ERROR(OBJ, OBJ_R_UNKNOWN_NID);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  367|      0|  return NULL;
  368|      0|}

PKCS5_pbe2_decrypt_init:
  214|    265|                            const char *pass, size_t pass_len, CBS *param) {
  215|    265|  CBS pbe_param, kdf, kdf_obj, enc_scheme, enc_obj;
  216|    265|  if (!CBS_get_asn1(param, &pbe_param, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    265|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    265|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    265|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (216:7): [True: 1, False: 264]
  ------------------
  217|    265|      CBS_len(param) != 0 ||
  ------------------
  |  Branch (217:7): [True: 4, False: 260]
  ------------------
  218|    265|      !CBS_get_asn1(&pbe_param, &kdf, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    260|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    260|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    260|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (218:7): [True: 1, False: 259]
  ------------------
  219|    265|      !CBS_get_asn1(&pbe_param, &enc_scheme, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    259|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    259|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    259|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (219:7): [True: 1, False: 258]
  ------------------
  220|    265|      CBS_len(&pbe_param) != 0 ||
  ------------------
  |  Branch (220:7): [True: 1, False: 257]
  ------------------
  221|    265|      !CBS_get_asn1(&kdf, &kdf_obj, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|    257|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (221:7): [True: 1, False: 256]
  ------------------
  222|    265|      !CBS_get_asn1(&enc_scheme, &enc_obj, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|    256|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (222:7): [True: 1, False: 255]
  ------------------
  223|     10|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|     10|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  224|     10|    return 0;
  225|     10|  }
  226|       |
  227|       |  // Only PBKDF2 is supported.
  228|    255|  if (!CBS_mem_equal(&kdf_obj, kPBKDF2, sizeof(kPBKDF2))) {
  ------------------
  |  Branch (228:7): [True: 1, False: 254]
  ------------------
  229|      1|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_UNSUPPORTED_KEY_DERIVATION_FUNCTION);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  230|      1|    return 0;
  231|      1|  }
  232|       |
  233|       |  // See if we recognise the encryption algorithm.
  234|    254|  const EVP_CIPHER *cipher = cbs_to_cipher(&enc_obj);
  235|    254|  if (cipher == NULL) {
  ------------------
  |  Branch (235:7): [True: 1, False: 253]
  ------------------
  236|      1|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_UNSUPPORTED_CIPHER);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  237|      1|    return 0;
  238|      1|  }
  239|       |
  240|       |  // Parse the KDF parameters. See RFC 8018, appendix A.2.
  241|    253|  CBS pbkdf2_params, salt;
  242|    253|  uint64_t iterations;
  243|    253|  if (!CBS_get_asn1(&kdf, &pbkdf2_params, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    253|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    253|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    253|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (243:7): [True: 1, False: 252]
  ------------------
  244|    253|      CBS_len(&kdf) != 0 ||
  ------------------
  |  Branch (244:7): [True: 1, False: 251]
  ------------------
  245|    253|      !CBS_get_asn1(&pbkdf2_params, &salt, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|    251|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (245:7): [True: 1, False: 250]
  ------------------
  246|    253|      !CBS_get_asn1_uint64(&pbkdf2_params, &iterations)) {
  ------------------
  |  Branch (246:7): [True: 1, False: 249]
  ------------------
  247|      4|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  248|      4|    return 0;
  249|      4|  }
  250|       |
  251|    249|  if (!pkcs12_iterations_acceptable(iterations)) {
  ------------------
  |  Branch (251:7): [True: 85, False: 164]
  ------------------
  252|     85|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_ITERATION_COUNT);
  ------------------
  |  |  441|     85|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  253|     85|    return 0;
  254|     85|  }
  255|       |
  256|       |  // The optional keyLength parameter, if present, must match the key length of
  257|       |  // the cipher.
  258|    164|  if (CBS_peek_asn1_tag(&pbkdf2_params, CBS_ASN1_INTEGER)) {
  ------------------
  |  |  215|    164|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (258:7): [True: 91, False: 73]
  ------------------
  259|     91|    uint64_t key_len;
  260|     91|    if (!CBS_get_asn1_uint64(&pbkdf2_params, &key_len)) {
  ------------------
  |  Branch (260:9): [True: 3, False: 88]
  ------------------
  261|      3|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  262|      3|      return 0;
  263|      3|    }
  264|       |
  265|     88|    if (key_len != EVP_CIPHER_key_length(cipher)) {
  ------------------
  |  Branch (265:9): [True: 87, False: 1]
  ------------------
  266|     87|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_UNSUPPORTED_KEYLENGTH);
  ------------------
  |  |  441|     87|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  267|     87|      return 0;
  268|     87|    }
  269|     88|  }
  270|       |
  271|     74|  const EVP_MD *md = EVP_sha1();
  272|     74|  if (CBS_len(&pbkdf2_params) != 0) {
  ------------------
  |  Branch (272:7): [True: 7, False: 67]
  ------------------
  273|      7|    CBS alg_id, prf;
  274|      7|    if (!CBS_get_asn1(&pbkdf2_params, &alg_id, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|      7|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|      7|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|      7|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (274:9): [True: 1, False: 6]
  ------------------
  275|      7|        !CBS_get_asn1(&alg_id, &prf, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|      6|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (275:9): [True: 1, False: 5]
  ------------------
  276|      7|        CBS_len(&pbkdf2_params) != 0) {
  ------------------
  |  Branch (276:9): [True: 1, False: 4]
  ------------------
  277|      3|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  278|      3|      return 0;
  279|      3|    }
  280|       |
  281|      4|    if (CBS_mem_equal(&prf, kHMACWithSHA1, sizeof(kHMACWithSHA1))) {
  ------------------
  |  Branch (281:9): [True: 1, False: 3]
  ------------------
  282|       |      // hmacWithSHA1 is the DEFAULT, so DER requires it be omitted, but we
  283|       |      // match OpenSSL in tolerating it being present.
  284|      1|      md = EVP_sha1();
  285|      3|    } else if (CBS_mem_equal(&prf, kHMACWithSHA256, sizeof(kHMACWithSHA256))) {
  ------------------
  |  Branch (285:16): [True: 2, False: 1]
  ------------------
  286|      2|      md = EVP_sha256();
  287|      2|    } else {
  288|      1|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_UNSUPPORTED_PRF);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  289|      1|      return 0;
  290|      1|    }
  291|       |
  292|       |    // All supported PRFs use a NULL parameter.
  293|      3|    CBS null;
  294|      3|    if (!CBS_get_asn1(&alg_id, &null, CBS_ASN1_NULL) ||
  ------------------
  |  |  218|      3|#define CBS_ASN1_NULL 0x5u
  ------------------
  |  Branch (294:9): [True: 3, False: 0]
  ------------------
  295|      3|        CBS_len(&null) != 0 ||
  ------------------
  |  Branch (295:9): [True: 0, False: 0]
  ------------------
  296|      3|        CBS_len(&alg_id) != 0) {
  ------------------
  |  Branch (296:9): [True: 0, False: 0]
  ------------------
  297|      3|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  298|      3|      return 0;
  299|      3|    }
  300|      3|  }
  301|       |
  302|       |  // Parse the encryption scheme parameters. Note OpenSSL does not match the
  303|       |  // specification. Per RFC 2898, this should depend on the encryption scheme.
  304|       |  // In particular, RC2-CBC uses a SEQUENCE with version and IV. We align with
  305|       |  // OpenSSL.
  306|     67|  CBS iv;
  307|     67|  if (!CBS_get_asn1(&enc_scheme, &iv, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|     67|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (307:7): [True: 1, False: 66]
  ------------------
  308|     67|      CBS_len(&enc_scheme) != 0) {
  ------------------
  |  Branch (308:7): [True: 1, False: 65]
  ------------------
  309|      2|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_UNSUPPORTED_PRF);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  310|      2|    return 0;
  311|      2|  }
  312|       |
  313|     65|  return pkcs5_pbe2_cipher_init(ctx, cipher, md, (unsigned)iterations, pass,
  314|     65|                                pass_len, CBS_data(&salt), CBS_len(&salt),
  315|     65|                                CBS_data(&iv), CBS_len(&iv), 0 /* decrypt */);
  316|     67|}
p5_pbev2.c:pkcs5_pbe2_cipher_init:
  150|     65|                                  const uint8_t *iv, size_t iv_len, int enc) {
  151|     65|  if (iv_len != EVP_CIPHER_iv_length(cipher)) {
  ------------------
  |  Branch (151:7): [True: 1, False: 64]
  ------------------
  152|      1|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_ERROR_SETTING_CIPHER_PARAMS);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  153|      1|    return 0;
  154|      1|  }
  155|       |
  156|     64|  uint8_t key[EVP_MAX_KEY_LENGTH];
  157|     64|  int ret = PKCS5_PBKDF2_HMAC(pass, pass_len, salt, salt_len, iterations,
  ------------------
  |  Branch (157:13): [True: 64, False: 0]
  ------------------
  158|     64|                              pbkdf2_md, EVP_CIPHER_key_length(cipher), key) &&
  159|     64|            EVP_CipherInit_ex(ctx, cipher, NULL /* engine */, key, iv, enc);
  ------------------
  |  Branch (159:13): [True: 64, False: 0]
  ------------------
  160|     64|  OPENSSL_cleanse(key, EVP_MAX_KEY_LENGTH);
  ------------------
  |  |  557|     64|#define EVP_MAX_KEY_LENGTH 64
  ------------------
  161|     64|  return ret;
  162|     65|}
p5_pbev2.c:cbs_to_cipher:
  121|    254|static const EVP_CIPHER *cbs_to_cipher(const CBS *cbs) {
  122|    457|  for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(kCipherOIDs); i++) {
  ------------------
  |  |  221|    457|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (122:22): [True: 456, False: 1]
  ------------------
  123|    456|    if (CBS_mem_equal(cbs, kCipherOIDs[i].oid, kCipherOIDs[i].oid_len)) {
  ------------------
  |  Branch (123:9): [True: 253, False: 203]
  ------------------
  124|    253|      return kCipherOIDs[i].cipher_func();
  125|    253|    }
  126|    456|  }
  127|       |
  128|      1|  return NULL;
  129|    254|}

pkcs12_key_gen:
  110|  5.23k|                   size_t out_len, uint8_t *out, const EVP_MD *md) {
  111|       |  // See https://tools.ietf.org/html/rfc7292#appendix-B. Quoted parts of the
  112|       |  // specification have errata applied and other typos fixed.
  113|       |
  114|  5.23k|  if (iterations < 1) {
  ------------------
  |  Branch (114:7): [True: 0, False: 5.23k]
  ------------------
  115|      0|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_ITERATION_COUNT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  116|      0|    return 0;
  117|      0|  }
  118|       |
  119|  5.23k|  int ret = 0;
  120|  5.23k|  EVP_MD_CTX ctx;
  121|  5.23k|  EVP_MD_CTX_init(&ctx);
  122|  5.23k|  uint8_t *pass_raw = NULL, *I = NULL;
  123|  5.23k|  size_t pass_raw_len = 0, I_len = 0;
  124|       |  // If |pass| is NULL, we use the empty string rather than {0, 0} as the raw
  125|       |  // password.
  126|  5.23k|  if (pass != NULL &&
  ------------------
  |  Branch (126:7): [True: 5.23k, False: 0]
  ------------------
  127|  5.23k|      !pkcs12_encode_password(pass, pass_len, &pass_raw, &pass_raw_len)) {
  ------------------
  |  Branch (127:7): [True: 0, False: 5.23k]
  ------------------
  128|      0|    goto err;
  129|      0|  }
  130|       |
  131|       |  // In the spec, |block_size| is called "v", but measured in bits.
  132|  5.23k|  size_t block_size = EVP_MD_block_size(md);
  133|       |
  134|       |  // 1. Construct a string, D (the "diversifier"), by concatenating v/8 copies
  135|       |  // of ID.
  136|  5.23k|  uint8_t D[EVP_MAX_MD_BLOCK_SIZE];
  137|  5.23k|  OPENSSL_memset(D, id, block_size);
  138|       |
  139|       |  // 2. Concatenate copies of the salt together to create a string S of length
  140|       |  // v(ceiling(s/v)) bits (the final copy of the salt may be truncated to
  141|       |  // create S). Note that if the salt is the empty string, then so is S.
  142|       |  //
  143|       |  // 3. Concatenate copies of the password together to create a string P of
  144|       |  // length v(ceiling(p/v)) bits (the final copy of the password may be
  145|       |  // truncated to create P).  Note that if the password is the empty string,
  146|       |  // then so is P.
  147|       |  //
  148|       |  // 4. Set I=S||P to be the concatenation of S and P.
  149|  5.23k|  if (salt_len + block_size - 1 < salt_len ||
  ------------------
  |  Branch (149:7): [True: 0, False: 5.23k]
  ------------------
  150|  5.23k|      pass_raw_len + block_size - 1 < pass_raw_len) {
  ------------------
  |  Branch (150:7): [True: 0, False: 5.23k]
  ------------------
  151|      0|    OPENSSL_PUT_ERROR(PKCS8, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  152|      0|    goto err;
  153|      0|  }
  154|  5.23k|  size_t S_len = block_size * ((salt_len + block_size - 1) / block_size);
  155|  5.23k|  size_t P_len = block_size * ((pass_raw_len + block_size - 1) / block_size);
  156|  5.23k|  I_len = S_len + P_len;
  157|  5.23k|  if (I_len < S_len) {
  ------------------
  |  Branch (157:7): [True: 0, False: 5.23k]
  ------------------
  158|      0|    OPENSSL_PUT_ERROR(PKCS8, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  159|      0|    goto err;
  160|      0|  }
  161|       |
  162|  5.23k|  I = OPENSSL_malloc(I_len);
  163|  5.23k|  if (I_len != 0 && I == NULL) {
  ------------------
  |  Branch (163:7): [True: 5.23k, False: 0]
  |  Branch (163:21): [True: 0, False: 5.23k]
  ------------------
  164|      0|    goto err;
  165|      0|  }
  166|       |
  167|  2.57M|  for (size_t i = 0; i < S_len; i++) {
  ------------------
  |  Branch (167:22): [True: 2.57M, False: 5.23k]
  ------------------
  168|  2.57M|    I[i] = salt[i % salt_len];
  169|  2.57M|  }
  170|   352k|  for (size_t i = 0; i < P_len; i++) {
  ------------------
  |  Branch (170:22): [True: 347k, False: 5.23k]
  ------------------
  171|   347k|    I[i + S_len] = pass_raw[i % pass_raw_len];
  172|   347k|  }
  173|       |
  174|  5.69k|  while (out_len != 0) {
  ------------------
  |  Branch (174:10): [True: 5.68k, False: 9]
  ------------------
  175|       |    // A. Set A_i=H^r(D||I). (i.e., the r-th hash of D||I,
  176|       |    // H(H(H(... H(D||I))))
  177|  5.68k|    uint8_t A[EVP_MAX_MD_SIZE];
  178|  5.68k|    unsigned A_len;
  179|  5.68k|    if (!EVP_DigestInit_ex(&ctx, md, NULL) ||
  ------------------
  |  Branch (179:9): [True: 0, False: 5.68k]
  ------------------
  180|  5.68k|        !EVP_DigestUpdate(&ctx, D, block_size) ||
  ------------------
  |  Branch (180:9): [True: 0, False: 5.68k]
  ------------------
  181|  5.68k|        !EVP_DigestUpdate(&ctx, I, I_len) ||
  ------------------
  |  Branch (181:9): [True: 0, False: 5.68k]
  ------------------
  182|  5.68k|        !EVP_DigestFinal_ex(&ctx, A, &A_len)) {
  ------------------
  |  Branch (182:9): [True: 0, False: 5.68k]
  ------------------
  183|      0|      goto err;
  184|      0|    }
  185|  5.85M|    for (unsigned iter = 1; iter < iterations; iter++) {
  ------------------
  |  Branch (185:29): [True: 5.85M, False: 5.68k]
  ------------------
  186|  5.85M|      if (!EVP_DigestInit_ex(&ctx, md, NULL) ||
  ------------------
  |  Branch (186:11): [True: 0, False: 5.85M]
  ------------------
  187|  5.85M|          !EVP_DigestUpdate(&ctx, A, A_len) ||
  ------------------
  |  Branch (187:11): [True: 0, False: 5.85M]
  ------------------
  188|  5.85M|          !EVP_DigestFinal_ex(&ctx, A, &A_len)) {
  ------------------
  |  Branch (188:11): [True: 0, False: 5.85M]
  ------------------
  189|      0|        goto err;
  190|      0|      }
  191|  5.85M|    }
  192|       |
  193|  5.68k|    size_t todo = out_len < A_len ? out_len : A_len;
  ------------------
  |  Branch (193:19): [True: 2.30k, False: 3.38k]
  ------------------
  194|  5.68k|    OPENSSL_memcpy(out, A, todo);
  195|  5.68k|    out += todo;
  196|  5.68k|    out_len -= todo;
  197|  5.68k|    if (out_len == 0) {
  ------------------
  |  Branch (197:9): [True: 5.22k, False: 463]
  ------------------
  198|  5.22k|      break;
  199|  5.22k|    }
  200|       |
  201|       |    // B. Concatenate copies of A_i to create a string B of length v bits (the
  202|       |    // final copy of A_i may be truncated to create B).
  203|    463|    uint8_t B[EVP_MAX_MD_BLOCK_SIZE];
  204|  30.0k|    for (size_t i = 0; i < block_size; i++) {
  ------------------
  |  Branch (204:24): [True: 29.6k, False: 463]
  ------------------
  205|  29.6k|      B[i] = A[i % A_len];
  206|  29.6k|    }
  207|       |
  208|       |    // C. Treating I as a concatenation I_0, I_1, ..., I_(k-1) of v-bit blocks,
  209|       |    // where k=ceiling(s/v)+ceiling(p/v), modify I by setting I_j=(I_j+B+1) mod
  210|       |    // 2^v for each j.
  211|    463|    assert(I_len % block_size == 0);
  212|  1.38k|    for (size_t i = 0; i < I_len; i += block_size) {
  ------------------
  |  Branch (212:24): [True: 926, False: 463]
  ------------------
  213|    926|      unsigned carry = 1;
  214|  60.1k|      for (size_t j = block_size - 1; j < block_size; j--) {
  ------------------
  |  Branch (214:39): [True: 59.2k, False: 926]
  ------------------
  215|  59.2k|        carry += I[i + j] + B[j];
  216|  59.2k|        I[i + j] = (uint8_t)carry;
  217|  59.2k|        carry >>= 8;
  218|  59.2k|      }
  219|    926|    }
  220|    463|  }
  221|       |
  222|  5.23k|  ret = 1;
  223|       |
  224|  5.23k|err:
  225|  5.23k|  OPENSSL_free(I);
  226|  5.23k|  OPENSSL_free(pass_raw);
  227|  5.23k|  EVP_MD_CTX_cleanup(&ctx);
  228|  5.23k|  return ret;
  229|  5.23k|}
pkcs8_pbe_decrypt:
  360|  1.43k|                      size_t in_len) {
  361|  1.43k|  int ret = 0;
  362|  1.43k|  uint8_t *buf = NULL;;
  363|  1.43k|  EVP_CIPHER_CTX ctx;
  364|  1.43k|  EVP_CIPHER_CTX_init(&ctx);
  365|       |
  366|  1.43k|  CBS obj;
  367|  1.43k|  if (!CBS_get_asn1(algorithm, &obj, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  1.43k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (367:7): [True: 1, False: 1.43k]
  ------------------
  368|      1|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  369|      1|    goto err;
  370|      1|  }
  371|       |
  372|  1.43k|  const struct pbe_suite *suite = NULL;
  373|  3.17k|  for (unsigned i = 0; i < OPENSSL_ARRAY_SIZE(kBuiltinPBE); i++) {
  ------------------
  |  |  221|  3.17k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (373:24): [True: 3.17k, False: 1]
  ------------------
  374|  3.17k|    if (CBS_mem_equal(&obj, kBuiltinPBE[i].oid, kBuiltinPBE[i].oid_len)) {
  ------------------
  |  Branch (374:9): [True: 1.43k, False: 1.74k]
  ------------------
  375|  1.43k|      suite = &kBuiltinPBE[i];
  376|  1.43k|      break;
  377|  1.43k|    }
  378|  3.17k|  }
  379|  1.43k|  if (suite == NULL) {
  ------------------
  |  Branch (379:7): [True: 1, False: 1.43k]
  ------------------
  380|      1|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_UNKNOWN_ALGORITHM);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  381|      1|    goto err;
  382|      1|  }
  383|       |
  384|  1.43k|  if (!suite->decrypt_init(suite, &ctx, pass, pass_len, algorithm)) {
  ------------------
  |  Branch (384:7): [True: 209, False: 1.22k]
  ------------------
  385|    209|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_KEYGEN_FAILURE);
  ------------------
  |  |  441|    209|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  386|    209|    goto err;
  387|    209|  }
  388|       |
  389|  1.22k|  buf = OPENSSL_malloc(in_len);
  390|  1.22k|  if (buf == NULL) {
  ------------------
  |  Branch (390:7): [True: 0, False: 1.22k]
  ------------------
  391|      0|    goto err;
  392|      0|  }
  393|       |
  394|  1.22k|  if (in_len > INT_MAX) {
  ------------------
  |  Branch (394:7): [True: 0, False: 1.22k]
  ------------------
  395|      0|    OPENSSL_PUT_ERROR(PKCS8, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  396|      0|    goto err;
  397|      0|  }
  398|       |
  399|  1.22k|  int n1, n2;
  400|  1.22k|  if (!EVP_DecryptUpdate(&ctx, buf, &n1, in, (int)in_len) ||
  ------------------
  |  Branch (400:7): [True: 0, False: 1.22k]
  ------------------
  401|  1.22k|      !EVP_DecryptFinal_ex(&ctx, buf + n1, &n2)) {
  ------------------
  |  Branch (401:7): [True: 72, False: 1.14k]
  ------------------
  402|     72|    goto err;
  403|     72|  }
  404|       |
  405|  1.14k|  *out = buf;
  406|  1.14k|  *out_len = n1 + n2;
  407|  1.14k|  ret = 1;
  408|  1.14k|  buf = NULL;
  409|       |
  410|  1.43k|err:
  411|  1.43k|  OPENSSL_free(buf);
  412|  1.43k|  EVP_CIPHER_CTX_cleanup(&ctx);
  413|  1.43k|  return ret;
  414|  1.14k|}
PKCS8_parse_encrypted_private_key:
  417|    730|                                            size_t pass_len) {
  418|       |  // See RFC 5208, section 6.
  419|    730|  CBS epki, algorithm, ciphertext;
  420|    730|  if (!CBS_get_asn1(cbs, &epki, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    730|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    730|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    730|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (420:7): [True: 1, False: 729]
  ------------------
  421|    730|      !CBS_get_asn1(&epki, &algorithm, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    729|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    729|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    729|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (421:7): [True: 1, False: 728]
  ------------------
  422|    730|      !CBS_get_asn1(&epki, &ciphertext, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|    728|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (422:7): [True: 1, False: 727]
  ------------------
  423|    730|      CBS_len(&epki) != 0) {
  ------------------
  |  Branch (423:7): [True: 2, False: 725]
  ------------------
  424|      5|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      5|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  425|      5|    return 0;
  426|      5|  }
  427|       |
  428|    725|  uint8_t *out;
  429|    725|  size_t out_len;
  430|    725|  if (!pkcs8_pbe_decrypt(&out, &out_len, &algorithm, pass, pass_len,
  ------------------
  |  Branch (430:7): [True: 244, False: 481]
  ------------------
  431|    725|                         CBS_data(&ciphertext), CBS_len(&ciphertext))) {
  432|    244|    return 0;
  433|    244|  }
  434|       |
  435|    481|  CBS pki;
  436|    481|  CBS_init(&pki, out, out_len);
  437|    481|  EVP_PKEY *ret = EVP_parse_private_key(&pki);
  438|    481|  OPENSSL_free(out);
  439|    481|  return ret;
  440|    725|}
pkcs8.c:pkcs12_encode_password:
   76|  5.23k|                                  size_t *out_len) {
   77|  5.23k|  CBB cbb;
   78|  5.23k|  if (!CBB_init(&cbb, in_len * 2)) {
  ------------------
  |  Branch (78:7): [True: 0, False: 5.23k]
  ------------------
   79|      0|    return 0;
   80|      0|  }
   81|       |
   82|       |  // Convert the password to BMPString, or UCS-2. See
   83|       |  // https://tools.ietf.org/html/rfc7292#appendix-B.1.
   84|  5.23k|  CBS cbs;
   85|  5.23k|  CBS_init(&cbs, (const uint8_t *)in, in_len);
   86|  20.9k|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (86:10): [True: 15.7k, False: 5.23k]
  ------------------
   87|  15.7k|    uint32_t c;
   88|  15.7k|    if (!cbs_get_utf8(&cbs, &c) ||
  ------------------
  |  Branch (88:9): [True: 0, False: 15.7k]
  ------------------
   89|  15.7k|        !cbb_add_ucs2_be(&cbb, c)) {
  ------------------
  |  Branch (89:9): [True: 0, False: 15.7k]
  ------------------
   90|      0|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_INVALID_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   91|      0|      goto err;
   92|      0|    }
   93|  15.7k|  }
   94|       |
   95|       |  // Terminate the result with a UCS-2 NUL.
   96|  5.23k|  if (!cbb_add_ucs2_be(&cbb, 0) ||
  ------------------
  |  Branch (96:7): [True: 0, False: 5.23k]
  ------------------
   97|  5.23k|      !CBB_finish(&cbb, out, out_len)) {
  ------------------
  |  Branch (97:7): [True: 0, False: 5.23k]
  ------------------
   98|      0|    goto err;
   99|      0|  }
  100|       |
  101|  5.23k|  return 1;
  102|       |
  103|      0|err:
  104|      0|  CBB_cleanup(&cbb);
  105|      0|  return 0;
  106|  5.23k|}
pkcs8.c:pkcs12_pbe_cipher_init:
  235|  1.15k|                                  int is_encrypt) {
  236|  1.15k|  const EVP_CIPHER *cipher = suite->cipher_func();
  237|  1.15k|  const EVP_MD *md = suite->md_func();
  238|       |
  239|  1.15k|  uint8_t key[EVP_MAX_KEY_LENGTH];
  240|  1.15k|  uint8_t iv[EVP_MAX_IV_LENGTH];
  241|  1.15k|  if (!pkcs12_key_gen(pass, pass_len, salt, salt_len, PKCS12_KEY_ID, iterations,
  ------------------
  |  |   81|  1.15k|#define PKCS12_KEY_ID 1
  ------------------
  |  Branch (241:7): [True: 0, False: 1.15k]
  ------------------
  242|  1.15k|                      EVP_CIPHER_key_length(cipher), key, md) ||
  243|  1.15k|      !pkcs12_key_gen(pass, pass_len, salt, salt_len, PKCS12_IV_ID, iterations,
  ------------------
  |  |   82|  1.15k|#define PKCS12_IV_ID 2
  ------------------
  |  Branch (243:7): [True: 0, False: 1.15k]
  ------------------
  244|  1.15k|                      EVP_CIPHER_iv_length(cipher), iv, md)) {
  245|      0|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_KEY_GEN_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  246|      0|    return 0;
  247|      0|  }
  248|       |
  249|  1.15k|  int ret = EVP_CipherInit_ex(ctx, cipher, NULL, key, iv, is_encrypt);
  250|  1.15k|  OPENSSL_cleanse(key, EVP_MAX_KEY_LENGTH);
  ------------------
  |  |  557|  1.15k|#define EVP_MAX_KEY_LENGTH 64
  ------------------
  251|  1.15k|  OPENSSL_cleanse(iv, EVP_MAX_IV_LENGTH);
  ------------------
  |  |  558|  1.15k|#define EVP_MAX_IV_LENGTH 16
  ------------------
  252|  1.15k|  return ret;
  253|  1.15k|}
pkcs8.c:pkcs12_pbe_decrypt_init:
  257|  1.16k|                                   size_t pass_len, CBS *param) {
  258|  1.16k|  CBS pbe_param, salt;
  259|  1.16k|  uint64_t iterations;
  260|  1.16k|  if (!CBS_get_asn1(param, &pbe_param, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  1.16k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  1.16k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  1.16k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (260:7): [True: 1, False: 1.16k]
  ------------------
  261|  1.16k|      !CBS_get_asn1(&pbe_param, &salt, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|  1.16k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (261:7): [True: 1, False: 1.16k]
  ------------------
  262|  1.16k|      !CBS_get_asn1_uint64(&pbe_param, &iterations) ||
  ------------------
  |  Branch (262:7): [True: 1, False: 1.16k]
  ------------------
  263|  1.16k|      CBS_len(&pbe_param) != 0 ||
  ------------------
  |  Branch (263:7): [True: 1, False: 1.16k]
  ------------------
  264|  1.16k|      CBS_len(param) != 0) {
  ------------------
  |  Branch (264:7): [True: 3, False: 1.15k]
  ------------------
  265|      7|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_DECODE_ERROR);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      7|    return 0;
  267|      7|  }
  268|       |
  269|  1.15k|  if (!pkcs12_iterations_acceptable(iterations)) {
  ------------------
  |  Branch (269:7): [True: 1, False: 1.15k]
  ------------------
  270|      1|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_ITERATION_COUNT);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  271|      1|    return 0;
  272|      1|  }
  273|       |
  274|  1.15k|  return pkcs12_pbe_cipher_init(suite, ctx, (unsigned)iterations, pass,
  275|  1.15k|                                pass_len, CBS_data(&salt), CBS_len(&salt),
  276|  1.15k|                                0 /* decrypt */);
  277|  1.15k|}

pkcs12_iterations_acceptable:
   78|  1.76k|int pkcs12_iterations_acceptable(uint64_t iterations) {
   79|  1.76k|#if defined(BORINGSSL_UNSAFE_FUZZER_MODE)
   80|  1.76k|  static const uint64_t kIterationsLimit = 2048;
   81|       |#else
   82|       |  // Windows imposes a limit of 600K. Mozilla say: “so them increasing
   83|       |  // maximum to something like 100M or 1G (to have few decades of breathing
   84|       |  // room) would be very welcome”[1]. So here we set the limit to 100M.
   85|       |  //
   86|       |  // [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1436873#c14
   87|       |  static const uint64_t kIterationsLimit = 100 * 1000000;
   88|       |#endif
   89|       |
   90|  1.76k|  return 0 < iterations && iterations <= kIterationsLimit;
  ------------------
  |  Branch (90:10): [True: 1.76k, False: 2]
  |  Branch (90:28): [True: 1.56k, False: 199]
  ------------------
   91|  1.76k|}
PKCS12_get_key_and_certs:
  587|  4.80k|                             CBS *ber_in, const char *password) {
  588|  4.80k|  uint8_t *storage = NULL;
  589|  4.80k|  CBS in, pfx, mac_data, authsafe, content_type, wrapped_authsafes, authsafes;
  590|  4.80k|  uint64_t version;
  591|  4.80k|  int ret = 0;
  592|  4.80k|  struct pkcs12_context ctx;
  593|  4.80k|  const size_t original_out_certs_len = sk_X509_num(out_certs);
  594|       |
  595|       |  // The input may be in BER format.
  596|  4.80k|  if (!CBS_asn1_ber_to_der(ber_in, &in, &storage)) {
  ------------------
  |  Branch (596:7): [True: 928, False: 3.87k]
  ------------------
  597|    928|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    928|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  598|    928|    return 0;
  599|    928|  }
  600|       |
  601|  3.87k|  *out_key = NULL;
  602|  3.87k|  OPENSSL_memset(&ctx, 0, sizeof(ctx));
  603|       |
  604|       |  // See ftp://ftp.rsasecurity.com/pub/pkcs/pkcs-12/pkcs-12v1.pdf, section
  605|       |  // four.
  606|  3.87k|  if (!CBS_get_asn1(&in, &pfx, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  3.87k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  3.87k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  3.87k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (606:7): [True: 222, False: 3.65k]
  ------------------
  607|  3.87k|      CBS_len(&in) != 0 ||
  ------------------
  |  Branch (607:7): [True: 61, False: 3.59k]
  ------------------
  608|  3.87k|      !CBS_get_asn1_uint64(&pfx, &version)) {
  ------------------
  |  Branch (608:7): [True: 176, False: 3.41k]
  ------------------
  609|    459|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    459|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  610|    459|    goto err;
  611|    459|  }
  612|       |
  613|  3.41k|  if (version < 3) {
  ------------------
  |  Branch (613:7): [True: 2, False: 3.41k]
  ------------------
  614|      2|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_VERSION);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  615|      2|    goto err;
  616|      2|  }
  617|       |
  618|  3.41k|  if (!CBS_get_asn1(&pfx, &authsafe, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  3.41k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  3.41k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  3.41k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (618:7): [True: 139, False: 3.27k]
  ------------------
  619|    139|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    139|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  620|    139|    goto err;
  621|    139|  }
  622|       |
  623|  3.27k|  if (CBS_len(&pfx) == 0) {
  ------------------
  |  Branch (623:7): [True: 4, False: 3.27k]
  ------------------
  624|      4|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_MISSING_MAC);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  625|      4|    goto err;
  626|      4|  }
  627|       |
  628|  3.27k|  if (!CBS_get_asn1(&pfx, &mac_data, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  3.27k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  3.27k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  3.27k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (628:7): [True: 17, False: 3.25k]
  ------------------
  629|     17|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     17|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  630|     17|    goto err;
  631|     17|  }
  632|       |
  633|       |  // authsafe is a PKCS#7 ContentInfo. See
  634|       |  // https://tools.ietf.org/html/rfc2315#section-7.
  635|  3.25k|  if (!CBS_get_asn1(&authsafe, &content_type, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|  3.25k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (635:7): [True: 4, False: 3.25k]
  ------------------
  636|  3.25k|      !CBS_get_asn1(&authsafe, &wrapped_authsafes,
  ------------------
  |  Branch (636:7): [True: 2, False: 3.25k]
  ------------------
  637|  3.25k|                        CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0)) {
  ------------------
  |  |  202|  3.25k|#define CBS_ASN1_CONTEXT_SPECIFIC (0x80u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  3.25k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                                      CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0)) {
  ------------------
  |  |  196|  3.25k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  3.25k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  638|      6|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      6|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  639|      6|    goto err;
  640|      6|  }
  641|       |
  642|       |  // The content type can either be data or signedData. The latter indicates
  643|       |  // that it's signed by a public key, which isn't supported.
  644|  3.25k|  if (!CBS_mem_equal(&content_type, kPKCS7Data, sizeof(kPKCS7Data))) {
  ------------------
  |  Branch (644:7): [True: 23, False: 3.22k]
  ------------------
  645|     23|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_PKCS12_PUBLIC_KEY_INTEGRITY_NOT_SUPPORTED);
  ------------------
  |  |  441|     23|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  646|     23|    goto err;
  647|     23|  }
  648|       |
  649|  3.22k|  if (!CBS_get_asn1(&wrapped_authsafes, &authsafes, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|  3.22k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (649:7): [True: 2, False: 3.22k]
  ------------------
  650|      2|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  651|      2|    goto err;
  652|      2|  }
  653|       |
  654|  3.22k|  ctx.out_key = out_key;
  655|  3.22k|  ctx.out_certs = out_certs;
  656|  3.22k|  ctx.password = password;
  657|  3.22k|  ctx.password_len = password != NULL ? strlen(password) : 0;
  ------------------
  |  Branch (657:22): [True: 3.22k, False: 0]
  ------------------
  658|       |
  659|       |  // Verify the MAC.
  660|  3.22k|  {
  661|  3.22k|    CBS mac, salt, expected_mac;
  662|  3.22k|    if (!CBS_get_asn1(&mac_data, &mac, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  3.22k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  3.22k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  3.22k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (662:9): [True: 1, False: 3.22k]
  ------------------
  663|      1|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  664|      1|      goto err;
  665|      1|    }
  666|       |
  667|  3.22k|    const EVP_MD *md = EVP_parse_digest_algorithm(&mac);
  668|  3.22k|    if (md == NULL) {
  ------------------
  |  Branch (668:9): [True: 170, False: 3.05k]
  ------------------
  669|    170|      goto err;
  670|    170|    }
  671|       |
  672|  3.05k|    if (!CBS_get_asn1(&mac, &expected_mac, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|  3.05k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (672:9): [True: 8, False: 3.04k]
  ------------------
  673|  3.05k|        !CBS_get_asn1(&mac_data, &salt, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|  3.04k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (673:9): [True: 1, False: 3.04k]
  ------------------
  674|      9|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      9|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  675|      9|      goto err;
  676|      9|    }
  677|       |
  678|       |    // The iteration count is optional and the default is one.
  679|  3.04k|    uint64_t iterations = 1;
  680|  3.04k|    if (CBS_len(&mac_data) > 0) {
  ------------------
  |  Branch (680:9): [True: 369, False: 2.67k]
  ------------------
  681|    369|      if (!CBS_get_asn1_uint64(&mac_data, &iterations) ||
  ------------------
  |  Branch (681:11): [True: 11, False: 358]
  ------------------
  682|    369|          !pkcs12_iterations_acceptable(iterations)) {
  ------------------
  |  Branch (682:11): [True: 115, False: 243]
  ------------------
  683|    126|        OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    126|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  684|    126|        goto err;
  685|    126|      }
  686|    369|    }
  687|       |
  688|  2.92k|    int mac_ok;
  689|  2.92k|    if (!pkcs12_check_mac(&mac_ok, ctx.password, ctx.password_len, &salt,
  ------------------
  |  Branch (689:9): [True: 0, False: 2.92k]
  ------------------
  690|  2.92k|                          iterations, md, &authsafes, &expected_mac)) {
  691|      0|      goto err;
  692|      0|    }
  693|  2.92k|    if (!mac_ok && ctx.password_len == 0) {
  ------------------
  |  Branch (693:9): [True: 0, False: 2.92k]
  |  Branch (693:20): [True: 0, False: 0]
  ------------------
  694|       |      // PKCS#12 encodes passwords as NUL-terminated UCS-2, so the empty
  695|       |      // password is encoded as {0, 0}. Some implementations use the empty byte
  696|       |      // array for "no password". OpenSSL considers a non-NULL password as {0,
  697|       |      // 0} and a NULL password as {}. It then, in high-level PKCS#12 parsing
  698|       |      // code, tries both options. We match this behavior.
  699|      0|      ctx.password = ctx.password != NULL ? NULL : "";
  ------------------
  |  Branch (699:22): [True: 0, False: 0]
  ------------------
  700|      0|      if (!pkcs12_check_mac(&mac_ok, ctx.password, ctx.password_len, &salt,
  ------------------
  |  Branch (700:11): [True: 0, False: 0]
  ------------------
  701|      0|                            iterations, md, &authsafes, &expected_mac)) {
  702|      0|        goto err;
  703|      0|      }
  704|      0|    }
  705|  2.92k|    if (!mac_ok) {
  ------------------
  |  Branch (705:9): [True: 0, False: 2.92k]
  ------------------
  706|      0|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_INCORRECT_PASSWORD);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  707|      0|      goto err;
  708|      0|    }
  709|  2.92k|  }
  710|       |
  711|       |  // authsafes contains a series of PKCS#7 ContentInfos.
  712|  2.92k|  if (!PKCS12_handle_sequence(&authsafes, &ctx, PKCS12_handle_content_info)) {
  ------------------
  |  Branch (712:7): [True: 2.90k, False: 17]
  ------------------
  713|  2.90k|    goto err;
  714|  2.90k|  }
  715|       |
  716|     17|  ret = 1;
  717|       |
  718|  3.87k|err:
  719|  3.87k|  OPENSSL_free(storage);
  720|  3.87k|  if (!ret) {
  ------------------
  |  Branch (720:7): [True: 3.86k, False: 17]
  ------------------
  721|  3.86k|    EVP_PKEY_free(*out_key);
  722|  3.86k|    *out_key = NULL;
  723|  3.86k|    while (sk_X509_num(out_certs) > original_out_certs_len) {
  ------------------
  |  Branch (723:12): [True: 3, False: 3.86k]
  ------------------
  724|      3|      X509 *x509 = sk_X509_pop(out_certs);
  725|      3|      X509_free(x509);
  726|      3|    }
  727|  3.86k|  }
  728|       |
  729|  3.87k|  return ret;
  730|     17|}
pkcs8_x509.c:pkcs12_check_mac:
  558|  2.92k|                            const CBS *authsafes, const CBS *expected_mac) {
  559|  2.92k|  int ret = 0;
  560|  2.92k|  uint8_t hmac_key[EVP_MAX_MD_SIZE];
  561|  2.92k|  if (!pkcs12_key_gen(password, password_len, CBS_data(salt), CBS_len(salt),
  ------------------
  |  Branch (561:7): [True: 0, False: 2.92k]
  ------------------
  562|  2.92k|                      PKCS12_MAC_ID, iterations, EVP_MD_size(md), hmac_key,
  ------------------
  |  |   83|  2.92k|#define PKCS12_MAC_ID 3
  ------------------
  563|  2.92k|                      md)) {
  564|      0|    goto err;
  565|      0|  }
  566|       |
  567|  2.92k|  uint8_t hmac[EVP_MAX_MD_SIZE];
  568|  2.92k|  unsigned hmac_len;
  569|  2.92k|  if (NULL == HMAC(md, hmac_key, EVP_MD_size(md), CBS_data(authsafes),
  ------------------
  |  Branch (569:7): [True: 0, False: 2.92k]
  ------------------
  570|  2.92k|                   CBS_len(authsafes), hmac, &hmac_len)) {
  571|      0|    goto err;
  572|      0|  }
  573|       |
  574|  2.92k|  *out_mac_ok = CBS_mem_equal(expected_mac, hmac, hmac_len);
  575|  2.92k|#if defined(BORINGSSL_UNSAFE_FUZZER_MODE)
  576|  2.92k|  *out_mac_ok = 1;
  577|  2.92k|#endif
  578|  2.92k|  ret = 1;
  579|       |
  580|  2.92k|err:
  581|  2.92k|  OPENSSL_cleanse(hmac_key, sizeof(hmac_key));
  582|  2.92k|  return ret;
  583|  2.92k|}
pkcs8_x509.c:PKCS12_handle_sequence:
  241|  5.26k|    int (*handle_element)(CBS *cbs, struct pkcs12_context *ctx)) {
  242|  5.26k|  uint8_t *storage = NULL;
  243|  5.26k|  CBS in;
  244|  5.26k|  int ret = 0;
  245|       |
  246|       |  // Although a BER->DER conversion is done at the beginning of |PKCS12_parse|,
  247|       |  // the ASN.1 data gets wrapped in OCTETSTRINGs and/or encrypted and the
  248|       |  // conversion cannot see through those wrappings. So each time we step
  249|       |  // through one we need to convert to DER again.
  250|  5.26k|  if (!CBS_asn1_ber_to_der(sequence, &in, &storage)) {
  ------------------
  |  Branch (250:7): [True: 453, False: 4.81k]
  ------------------
  251|    453|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    453|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  252|    453|    return 0;
  253|    453|  }
  254|       |
  255|  4.81k|  CBS child;
  256|  4.81k|  if (!CBS_get_asn1(&in, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  4.81k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  4.81k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  4.81k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (256:7): [True: 7, False: 4.80k]
  ------------------
  257|  4.81k|      CBS_len(&in) != 0) {
  ------------------
  |  Branch (257:7): [True: 12, False: 4.79k]
  ------------------
  258|     19|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     19|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  259|     19|    goto err;
  260|     19|  }
  261|       |
  262|  5.63k|  while (CBS_len(&child) > 0) {
  ------------------
  |  Branch (262:10): [True: 5.56k, False: 71]
  ------------------
  263|  5.56k|    CBS element;
  264|  5.56k|    if (!CBS_get_asn1(&child, &element, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  5.56k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  5.56k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  5.56k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (264:9): [True: 16, False: 5.54k]
  ------------------
  265|     16|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     16|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|     16|      goto err;
  267|     16|    }
  268|       |
  269|  5.54k|    if (!handle_element(&element, ctx)) {
  ------------------
  |  Branch (269:9): [True: 4.70k, False: 840]
  ------------------
  270|  4.70k|      goto err;
  271|  4.70k|    }
  272|  5.54k|  }
  273|       |
  274|     71|  ret = 1;
  275|       |
  276|  4.81k|err:
  277|  4.81k|  OPENSSL_free(storage);
  278|  4.81k|  return ret;
  279|     71|}
pkcs8_x509.c:PKCS12_handle_content_info:
  479|  3.01k|                                      struct pkcs12_context *ctx) {
  480|  3.01k|  CBS content_type, wrapped_contents, contents;
  481|  3.01k|  int ret = 0;
  482|  3.01k|  uint8_t *storage = NULL;
  483|       |
  484|  3.01k|  if (!CBS_get_asn1(content_info, &content_type, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|  3.01k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (484:7): [True: 3, False: 3.01k]
  ------------------
  485|  3.01k|      !CBS_get_asn1(content_info, &wrapped_contents,
  ------------------
  |  Branch (485:7): [True: 1, False: 3.01k]
  ------------------
  486|  3.01k|                        CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0) ||
  ------------------
  |  |  202|  3.01k|#define CBS_ASN1_CONTEXT_SPECIFIC (0x80u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  3.01k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                                      CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0) ||
  ------------------
  |  |  196|  3.01k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  3.01k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  487|  3.01k|      CBS_len(content_info) != 0) {
  ------------------
  |  Branch (487:7): [True: 8, False: 3.00k]
  ------------------
  488|     12|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     12|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  489|     12|    goto err;
  490|     12|  }
  491|       |
  492|  3.00k|  if (CBS_mem_equal(&content_type, kPKCS7EncryptedData,
  ------------------
  |  Branch (492:7): [True: 796, False: 2.20k]
  ------------------
  493|  3.00k|                    sizeof(kPKCS7EncryptedData))) {
  494|       |    // See https://tools.ietf.org/html/rfc2315#section-13.
  495|       |    //
  496|       |    // PKCS#7 encrypted data inside a PKCS#12 structure is generally an
  497|       |    // encrypted certificate bag and it's generally encrypted with 40-bit
  498|       |    // RC2-CBC.
  499|    796|    CBS version_bytes, eci, contents_type, ai, encrypted_contents;
  500|    796|    uint8_t *out;
  501|    796|    size_t out_len;
  502|       |
  503|    796|    if (!CBS_get_asn1(&wrapped_contents, &contents, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    796|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    796|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    796|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (503:9): [True: 1, False: 795]
  ------------------
  504|    796|        !CBS_get_asn1(&contents, &version_bytes, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|    795|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (504:9): [True: 1, False: 794]
  ------------------
  505|       |        // EncryptedContentInfo, see
  506|       |        // https://tools.ietf.org/html/rfc2315#section-10.1
  507|    796|        !CBS_get_asn1(&contents, &eci, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    794|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    794|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    794|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (507:9): [True: 1, False: 793]
  ------------------
  508|    796|        !CBS_get_asn1(&eci, &contents_type, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|    793|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (508:9): [True: 1, False: 792]
  ------------------
  509|       |        // AlgorithmIdentifier, see
  510|       |        // https://tools.ietf.org/html/rfc5280#section-4.1.1.2
  511|    796|        !CBS_get_asn1(&eci, &ai, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    792|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    792|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    792|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (511:9): [True: 1, False: 791]
  ------------------
  512|    796|        !CBS_get_asn1_implicit_string(
  ------------------
  |  Branch (512:9): [True: 80, False: 711]
  ------------------
  513|    791|            &eci, &encrypted_contents, &storage,
  514|    791|            CBS_ASN1_CONTEXT_SPECIFIC | 0, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  202|    791|#define CBS_ASN1_CONTEXT_SPECIFIC (0x80u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|    791|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                          CBS_ASN1_CONTEXT_SPECIFIC | 0, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|    791|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  515|     85|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     85|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  516|     85|      goto err;
  517|     85|    }
  518|       |
  519|    711|    if (!CBS_mem_equal(&contents_type, kPKCS7Data, sizeof(kPKCS7Data))) {
  ------------------
  |  Branch (519:9): [True: 4, False: 707]
  ------------------
  520|      4|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  521|      4|      goto err;
  522|      4|    }
  523|       |
  524|    707|    if (!pkcs8_pbe_decrypt(&out, &out_len, &ai, ctx->password,
  ------------------
  |  Branch (524:9): [True: 39, False: 668]
  ------------------
  525|    707|                           ctx->password_len, CBS_data(&encrypted_contents),
  526|    707|                           CBS_len(&encrypted_contents))) {
  527|     39|      goto err;
  528|     39|    }
  529|       |
  530|    668|    CBS safe_contents;
  531|    668|    CBS_init(&safe_contents, out, out_len);
  532|    668|    ret = PKCS12_handle_sequence(&safe_contents, ctx, PKCS12_handle_safe_bag);
  533|    668|    OPENSSL_free(out);
  534|  2.20k|  } else if (CBS_mem_equal(&content_type, kPKCS7Data, sizeof(kPKCS7Data))) {
  ------------------
  |  Branch (534:14): [True: 1.67k, False: 529]
  ------------------
  535|  1.67k|    CBS octet_string_contents;
  536|       |
  537|  1.67k|    if (!CBS_get_asn1(&wrapped_contents, &octet_string_contents,
  ------------------
  |  Branch (537:9): [True: 1, False: 1.67k]
  ------------------
  538|  1.67k|                      CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|  1.67k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  539|      1|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  540|      1|      goto err;
  541|      1|    }
  542|       |
  543|  1.67k|    ret = PKCS12_handle_sequence(&octet_string_contents, ctx,
  544|  1.67k|                                 PKCS12_handle_safe_bag);
  545|  1.67k|  } else {
  546|       |    // Unknown element type - ignore it.
  547|    529|    ret = 1;
  548|    529|  }
  549|       |
  550|  3.01k|err:
  551|  3.01k|  OPENSSL_free(storage);
  552|  3.01k|  return ret;
  553|  3.00k|}
pkcs8_x509.c:PKCS12_handle_safe_bag:
  366|  2.53k|static int PKCS12_handle_safe_bag(CBS *safe_bag, struct pkcs12_context *ctx) {
  367|  2.53k|  CBS bag_id, wrapped_value, bag_attrs;
  368|  2.53k|  if (!CBS_get_asn1(safe_bag, &bag_id, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|  2.53k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (368:7): [True: 3, False: 2.52k]
  ------------------
  369|  2.53k|      !CBS_get_asn1(safe_bag, &wrapped_value,
  ------------------
  |  Branch (369:7): [True: 2, False: 2.52k]
  ------------------
  370|  2.52k|                    CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0)) {
  ------------------
  |  |  202|  2.52k|#define CBS_ASN1_CONTEXT_SPECIFIC (0x80u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  2.52k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                                  CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0)) {
  ------------------
  |  |  196|  2.52k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  2.52k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  371|      5|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      5|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  372|      5|    return 0;
  373|      5|  }
  374|  2.52k|  if (CBS_len(safe_bag) == 0) {
  ------------------
  |  Branch (374:7): [True: 1.39k, False: 1.13k]
  ------------------
  375|  1.39k|    CBS_init(&bag_attrs, NULL, 0);
  376|  1.39k|  } else if (!CBS_get_asn1(safe_bag, &bag_attrs, CBS_ASN1_SET) ||
  ------------------
  |  |  223|  1.13k|#define CBS_ASN1_SET (0x11u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  1.13k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  1.13k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (376:14): [True: 8, False: 1.12k]
  ------------------
  377|  1.13k|             CBS_len(safe_bag) != 0) {
  ------------------
  |  Branch (377:14): [True: 9, False: 1.11k]
  ------------------
  378|     17|    OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     17|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  379|     17|    return 0;
  380|     17|  }
  381|       |
  382|  2.50k|  const int is_key_bag = CBS_mem_equal(&bag_id, kKeyBag, sizeof(kKeyBag));
  383|  2.50k|  const int is_shrouded_key_bag = CBS_mem_equal(&bag_id, kPKCS8ShroudedKeyBag,
  384|  2.50k|                                                sizeof(kPKCS8ShroudedKeyBag));
  385|  2.50k|  if (is_key_bag || is_shrouded_key_bag) {
  ------------------
  |  Branch (385:7): [True: 883, False: 1.62k]
  |  Branch (385:21): [True: 730, False: 896]
  ------------------
  386|       |    // See RFC 7292, section 4.2.1 and 4.2.2.
  387|  1.61k|    if (*ctx->out_key) {
  ------------------
  |  Branch (387:9): [True: 0, False: 1.61k]
  ------------------
  388|      0|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_MULTIPLE_PRIVATE_KEYS_IN_PKCS12);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  389|      0|      return 0;
  390|      0|    }
  391|       |
  392|  1.61k|    EVP_PKEY *pkey =
  393|  1.61k|        is_key_bag ? EVP_parse_private_key(&wrapped_value)
  ------------------
  |  Branch (393:9): [True: 883, False: 730]
  ------------------
  394|  1.61k|                   : PKCS8_parse_encrypted_private_key(
  395|    730|                         &wrapped_value, ctx->password, ctx->password_len);
  396|  1.61k|    if (pkey == NULL) {
  ------------------
  |  Branch (396:9): [True: 1.48k, False: 129]
  ------------------
  397|  1.48k|      return 0;
  398|  1.48k|    }
  399|       |
  400|    129|    if (CBS_len(&wrapped_value) != 0) {
  ------------------
  |  Branch (400:9): [True: 124, False: 5]
  ------------------
  401|    124|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    124|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  402|    124|      EVP_PKEY_free(pkey);
  403|    124|      return 0;
  404|    124|    }
  405|       |
  406|      5|    *ctx->out_key = pkey;
  407|      5|    return 1;
  408|    129|  }
  409|       |
  410|    896|  if (CBS_mem_equal(&bag_id, kCertBag, sizeof(kCertBag))) {
  ------------------
  |  Branch (410:7): [True: 666, False: 230]
  ------------------
  411|       |    // See RFC 7292, section 4.2.3.
  412|    666|    CBS cert_bag, cert_type, wrapped_cert, cert;
  413|    666|    if (!CBS_get_asn1(&wrapped_value, &cert_bag, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    666|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    666|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    666|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (413:9): [True: 1, False: 665]
  ------------------
  414|    666|        !CBS_get_asn1(&cert_bag, &cert_type, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|    665|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (414:9): [True: 1, False: 664]
  ------------------
  415|    666|        !CBS_get_asn1(&cert_bag, &wrapped_cert,
  ------------------
  |  Branch (415:9): [True: 1, False: 663]
  ------------------
  416|    664|                      CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0) ||
  ------------------
  |  |  202|    664|#define CBS_ASN1_CONTEXT_SPECIFIC (0x80u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|    664|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                                    CBS_ASN1_CONTEXT_SPECIFIC | CBS_ASN1_CONSTRUCTED | 0) ||
  ------------------
  |  |  196|    664|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|    664|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  417|    666|        !CBS_get_asn1(&wrapped_cert, &cert, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|    663|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (417:9): [True: 1, False: 662]
  ------------------
  418|      4|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  419|      4|      return 0;
  420|      4|    }
  421|       |
  422|       |    // Skip unknown certificate types.
  423|    662|    if (!CBS_mem_equal(&cert_type, kX509Certificate,
  ------------------
  |  Branch (423:9): [True: 9, False: 653]
  ------------------
  424|    662|                       sizeof(kX509Certificate))) {
  425|      9|      return 1;
  426|      9|    }
  427|       |
  428|    653|    if (CBS_len(&cert) > LONG_MAX) {
  ------------------
  |  Branch (428:9): [True: 0, False: 653]
  ------------------
  429|      0|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  430|      0|      return 0;
  431|      0|    }
  432|       |
  433|    653|    const uint8_t *inp = CBS_data(&cert);
  434|    653|    X509 *x509 = d2i_X509(NULL, &inp, (long)CBS_len(&cert));
  435|    653|    if (!x509) {
  ------------------
  |  Branch (435:9): [True: 624, False: 29]
  ------------------
  436|    624|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|    624|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  437|    624|      return 0;
  438|    624|    }
  439|       |
  440|     29|    if (inp != CBS_data(&cert) + CBS_len(&cert)) {
  ------------------
  |  Branch (440:9): [True: 0, False: 29]
  ------------------
  441|      0|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  442|      0|      X509_free(x509);
  443|      0|      return 0;
  444|      0|    }
  445|       |
  446|     29|    uint8_t *friendly_name;
  447|     29|    size_t friendly_name_len;
  448|     29|    if (!parse_bag_attributes(&bag_attrs, &friendly_name, &friendly_name_len)) {
  ------------------
  |  Branch (448:9): [True: 16, False: 13]
  ------------------
  449|     16|      X509_free(x509);
  450|     16|      return 0;
  451|     16|    }
  452|     13|    int ok = friendly_name_len == 0 ||
  ------------------
  |  Branch (452:14): [True: 7, False: 6]
  ------------------
  453|     13|             X509_alias_set1(x509, friendly_name, friendly_name_len);
  ------------------
  |  Branch (453:14): [True: 6, False: 0]
  ------------------
  454|     13|    OPENSSL_free(friendly_name);
  455|     13|    if (!ok ||
  ------------------
  |  Branch (455:9): [True: 0, False: 13]
  ------------------
  456|     13|        0 == sk_X509_push(ctx->out_certs, x509)) {
  ------------------
  |  Branch (456:9): [True: 0, False: 13]
  ------------------
  457|      0|      X509_free(x509);
  458|      0|      return 0;
  459|      0|    }
  460|       |
  461|     13|    return 1;
  462|     13|  }
  463|       |
  464|       |  // Unknown element type - ignore it.
  465|    230|  return 1;
  466|    896|}
pkcs8_x509.c:parse_bag_attributes:
  310|     29|                                size_t *out_friendly_name_len) {
  311|     29|  *out_friendly_name = NULL;
  312|     29|  *out_friendly_name_len = 0;
  313|       |
  314|       |  // See https://tools.ietf.org/html/rfc7292#section-4.2.
  315|     55|  while (CBS_len(attrs) != 0) {
  ------------------
  |  Branch (315:10): [True: 42, False: 13]
  ------------------
  316|     42|    CBS attr, oid, values;
  317|     42|    if (!CBS_get_asn1(attrs, &attr, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|     42|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|     42|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|     42|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (317:9): [True: 6, False: 36]
  ------------------
  318|     42|        !CBS_get_asn1(&attr, &oid, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|     36|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (318:9): [True: 1, False: 35]
  ------------------
  319|     42|        !CBS_get_asn1(&attr, &values, CBS_ASN1_SET) ||
  ------------------
  |  |  223|     35|#define CBS_ASN1_SET (0x11u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|     35|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|     35|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (319:9): [True: 2, False: 33]
  ------------------
  320|     42|        CBS_len(&attr) != 0) {
  ------------------
  |  Branch (320:9): [True: 1, False: 32]
  ------------------
  321|     10|      OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|     10|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  322|     10|      goto err;
  323|     10|    }
  324|     32|    if (CBS_mem_equal(&oid, kFriendlyName, sizeof(kFriendlyName))) {
  ------------------
  |  Branch (324:9): [True: 18, False: 14]
  ------------------
  325|       |      // See https://tools.ietf.org/html/rfc2985, section 5.5.1.
  326|     18|      CBS value;
  327|     18|      if (*out_friendly_name != NULL ||
  ------------------
  |  Branch (327:11): [True: 0, False: 18]
  ------------------
  328|     18|          !CBS_get_asn1(&values, &value, CBS_ASN1_BMPSTRING) ||
  ------------------
  |  |  235|     18|#define CBS_ASN1_BMPSTRING 0x1eu
  ------------------
  |  Branch (328:11): [True: 0, False: 18]
  ------------------
  329|     18|          CBS_len(&values) != 0 ||
  ------------------
  |  Branch (329:11): [True: 0, False: 18]
  ------------------
  330|     18|          CBS_len(&value) == 0) {
  ------------------
  |  Branch (330:11): [True: 0, False: 18]
  ------------------
  331|      0|        OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_BAD_PKCS12_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  332|      0|        goto err;
  333|      0|      }
  334|       |      // Convert the friendly name to UTF-8.
  335|     18|      CBB cbb;
  336|     18|      if (!CBB_init(&cbb, CBS_len(&value))) {
  ------------------
  |  Branch (336:11): [True: 0, False: 18]
  ------------------
  337|      0|        goto err;
  338|      0|      }
  339|    346|      while (CBS_len(&value) != 0) {
  ------------------
  |  Branch (339:14): [True: 334, False: 12]
  ------------------
  340|    334|        uint32_t c;
  341|    334|        if (!cbs_get_ucs2_be(&value, &c) ||
  ------------------
  |  Branch (341:13): [True: 6, False: 328]
  ------------------
  342|    334|            !cbb_add_utf8(&cbb, c)) {
  ------------------
  |  Branch (342:13): [True: 0, False: 328]
  ------------------
  343|      6|          OPENSSL_PUT_ERROR(PKCS8, PKCS8_R_INVALID_CHARACTERS);
  ------------------
  |  |  441|      6|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  344|      6|          CBB_cleanup(&cbb);
  345|      6|          goto err;
  346|      6|        }
  347|    334|      }
  348|     12|      if (!CBB_finish(&cbb, out_friendly_name, out_friendly_name_len)) {
  ------------------
  |  Branch (348:11): [True: 0, False: 12]
  ------------------
  349|      0|        CBB_cleanup(&cbb);
  350|      0|        goto err;
  351|      0|      }
  352|     12|    }
  353|     32|  }
  354|       |
  355|     13|  return 1;
  356|       |
  357|     16|err:
  358|     16|  OPENSSL_free(*out_friendly_name);
  359|     16|  *out_friendly_name = NULL;
  360|     16|  *out_friendly_name_len = 0;
  361|     16|  return 0;
  362|     29|}

RC4:
   60|      9|void RC4(RC4_KEY *key, size_t len, const uint8_t *in, uint8_t *out) {
   61|      9|  uint32_t x = key->x;
   62|      9|  uint32_t y = key->y;
   63|      9|  uint32_t *d = key->data;
   64|       |
   65|  3.60k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (65:22): [True: 3.59k, False: 9]
  ------------------
   66|  3.59k|    x = (x + 1) & 0xff;
   67|  3.59k|    uint32_t tx = d[x];
   68|  3.59k|    y = (tx + y) & 0xff;
   69|  3.59k|    uint32_t ty = d[y];
   70|  3.59k|    d[x] = ty;
   71|  3.59k|    d[y] = tx;
   72|  3.59k|    out[i] = d[(tx + ty) & 0xff] ^ in[i];
   73|  3.59k|  }
   74|       |
   75|      9|  key->x = x;
   76|      9|  key->y = y;
   77|      9|}
RC4_set_key:
   79|      9|void RC4_set_key(RC4_KEY *rc4key, unsigned len, const uint8_t *key) {
   80|      9|  uint32_t *d = &rc4key->data[0];
   81|      9|  rc4key->x = 0;
   82|      9|  rc4key->y = 0;
   83|       |
   84|  2.31k|  for (unsigned i = 0; i < 256; i++) {
  ------------------
  |  Branch (84:24): [True: 2.30k, False: 9]
  ------------------
   85|  2.30k|    d[i] = i;
   86|  2.30k|  }
   87|       |
   88|      9|  unsigned id1 = 0, id2 = 0;
   89|  2.31k|  for (unsigned i = 0; i < 256; i++) {
  ------------------
  |  Branch (89:24): [True: 2.30k, False: 9]
  ------------------
   90|  2.30k|    uint32_t tmp = d[i];
   91|  2.30k|    id2 = (key[id1] + tmp + id2) & 0xff;
   92|  2.30k|    if (++id1 == len) {
  ------------------
  |  Branch (92:9): [True: 144, False: 2.16k]
  ------------------
   93|    144|      id1 = 0;
   94|    144|    }
   95|  2.30k|    d[i] = d[id2];
   96|  2.30k|    d[id2] = tmp;
   97|  2.30k|  }
   98|      9|}

CRYPTO_refcount_inc:
   31|      4|void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
   32|      4|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   33|      4|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   34|       |
   35|      4|  while (expected != CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|      4|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (35:10): [True: 4, False: 0]
  ------------------
   36|      4|    uint32_t new_value = expected + 1;
   37|      4|    if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected, new_value)) {
  ------------------
  |  Branch (37:9): [True: 4, False: 0]
  ------------------
   38|      4|      break;
   39|      4|    }
   40|      4|  }
   41|      4|}
CRYPTO_refcount_dec_and_test_zero:
   43|  2.74k|int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
   44|  2.74k|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   45|  2.74k|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   46|       |
   47|  2.74k|  for (;;) {
   48|  2.74k|    if (expected == 0) {
  ------------------
  |  Branch (48:9): [True: 0, False: 2.74k]
  ------------------
   49|      0|      abort();
   50|  2.74k|    } else if (expected == CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|  2.74k|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (50:16): [True: 0, False: 2.74k]
  ------------------
   51|      0|      return 0;
   52|  2.74k|    } else {
   53|  2.74k|      const uint32_t new_value = expected - 1;
   54|  2.74k|      if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected,
  ------------------
  |  Branch (54:11): [True: 2.74k, False: 0]
  ------------------
   55|  2.74k|                                                  new_value)) {
   56|  2.74k|        return new_value == 0;
   57|  2.74k|      }
   58|  2.74k|    }
   59|  2.74k|  }
   60|  2.74k|}

RSA_parse_private_key:
  156|    469|RSA *RSA_parse_private_key(CBS *cbs) {
  157|    469|  RSA *ret = RSA_new();
  158|    469|  if (ret == NULL) {
  ------------------
  |  Branch (158:7): [True: 0, False: 469]
  ------------------
  159|      0|    return NULL;
  160|      0|  }
  161|       |
  162|    469|  CBS child;
  163|    469|  uint64_t version;
  164|    469|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    469|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    469|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    469|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (164:7): [True: 1, False: 468]
  ------------------
  165|    469|      !CBS_get_asn1_uint64(&child, &version)) {
  ------------------
  |  Branch (165:7): [True: 1, False: 467]
  ------------------
  166|      2|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  167|      2|    goto err;
  168|      2|  }
  169|       |
  170|    467|  if (version != kVersionTwoPrime) {
  ------------------
  |  Branch (170:7): [True: 7, False: 460]
  ------------------
  171|      7|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_VERSION);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  172|      7|    goto err;
  173|      7|  }
  174|       |
  175|    460|  if (!parse_integer(&child, &ret->n) ||
  ------------------
  |  Branch (175:7): [True: 1, False: 459]
  ------------------
  176|    460|      !parse_integer(&child, &ret->e) ||
  ------------------
  |  Branch (176:7): [True: 3, False: 456]
  ------------------
  177|    460|      !parse_integer(&child, &ret->d) ||
  ------------------
  |  Branch (177:7): [True: 1, False: 455]
  ------------------
  178|    460|      !parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (178:7): [True: 6, False: 449]
  ------------------
  179|    460|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (179:7): [True: 1, False: 448]
  ------------------
  180|    460|      !parse_integer(&child, &ret->dmp1) ||
  ------------------
  |  Branch (180:7): [True: 1, False: 447]
  ------------------
  181|    460|      !parse_integer(&child, &ret->dmq1) ||
  ------------------
  |  Branch (181:7): [True: 2, False: 445]
  ------------------
  182|    460|      !parse_integer(&child, &ret->iqmp)) {
  ------------------
  |  Branch (182:7): [True: 1, False: 444]
  ------------------
  183|     16|    goto err;
  184|     16|  }
  185|       |
  186|    444|  if (CBS_len(&child) != 0) {
  ------------------
  |  Branch (186:7): [True: 7, False: 437]
  ------------------
  187|      7|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  188|      7|    goto err;
  189|      7|  }
  190|       |
  191|    437|  if (!RSA_check_key(ret)) {
  ------------------
  |  Branch (191:7): [True: 432, False: 5]
  ------------------
  192|    432|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|    432|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  193|    432|    goto err;
  194|    432|  }
  195|       |
  196|      5|  return ret;
  197|       |
  198|    464|err:
  199|    464|  RSA_free(ret);
  200|    464|  return NULL;
  201|    437|}
rsa_asn1.c:parse_integer:
   72|  3.61k|static int parse_integer(CBS *cbs, BIGNUM **out) {
   73|  3.61k|  assert(*out == NULL);
   74|  3.61k|  *out = BN_new();
   75|  3.61k|  if (*out == NULL) {
  ------------------
  |  Branch (75:7): [True: 0, False: 3.61k]
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|  3.61k|  return BN_parse_asn1_unsigned(cbs, *out);
   79|  3.61k|}

sk_new:
   72|  10.0k|_STACK *sk_new(OPENSSL_sk_cmp_func comp) {
   73|  10.0k|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
   74|  10.0k|  if (ret == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 10.0k]
  ------------------
   75|      0|    return NULL;
   76|      0|  }
   77|  10.0k|  OPENSSL_memset(ret, 0, sizeof(_STACK));
   78|       |
   79|  10.0k|  ret->data = OPENSSL_malloc(sizeof(void *) * kMinSize);
   80|  10.0k|  if (ret->data == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 10.0k]
  ------------------
   81|      0|    goto err;
   82|      0|  }
   83|       |
   84|  10.0k|  OPENSSL_memset(ret->data, 0, sizeof(void *) * kMinSize);
   85|       |
   86|  10.0k|  ret->comp = comp;
   87|  10.0k|  ret->num_alloc = kMinSize;
   88|       |
   89|  10.0k|  return ret;
   90|       |
   91|      0|err:
   92|      0|  OPENSSL_free(ret);
   93|      0|  return NULL;
   94|  10.0k|}
sk_new_null:
   96|  10.0k|_STACK *sk_new_null(void) { return sk_new(NULL); }
sk_num:
   98|  29.2k|size_t sk_num(const _STACK *sk) {
   99|  29.2k|  if (sk == NULL) {
  ------------------
  |  Branch (99:7): [True: 1.81k, False: 27.4k]
  ------------------
  100|  1.81k|    return 0;
  101|  1.81k|  }
  102|  27.4k|  return sk->num;
  103|  29.2k|}
sk_value:
  114|  11.0k|void *sk_value(const _STACK *sk, size_t i) {
  115|  11.0k|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (115:7): [True: 0, False: 11.0k]
  |  Branch (115:14): [True: 0, False: 11.0k]
  ------------------
  116|      0|    return NULL;
  117|      0|  }
  118|  11.0k|  return sk->data[i];
  119|  11.0k|}
sk_set:
  121|  1.10k|void *sk_set(_STACK *sk, size_t i, void *value) {
  122|  1.10k|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (122:7): [True: 0, False: 1.10k]
  |  Branch (122:14): [True: 0, False: 1.10k]
  ------------------
  123|      0|    return NULL;
  124|      0|  }
  125|  1.10k|  return sk->data[i] = value;
  126|  1.10k|}
sk_free:
  128|  11.8k|void sk_free(_STACK *sk) {
  129|  11.8k|  if (sk == NULL) {
  ------------------
  |  Branch (129:7): [True: 1.81k, False: 10.0k]
  ------------------
  130|  1.81k|    return;
  131|  1.81k|  }
  132|  10.0k|  OPENSSL_free(sk->data);
  133|  10.0k|  OPENSSL_free(sk);
  134|  10.0k|}
sk_pop_free_ex:
  137|  8.68k|                    OPENSSL_sk_free_func free_func) {
  138|  8.68k|  if (sk == NULL) {
  ------------------
  |  Branch (138:7): [True: 3, False: 8.68k]
  ------------------
  139|      3|    return;
  140|      3|  }
  141|       |
  142|  13.8k|  for (size_t i = 0; i < sk->num; i++) {
  ------------------
  |  Branch (142:22): [True: 5.20k, False: 8.68k]
  ------------------
  143|  5.20k|    if (sk->data[i] != NULL) {
  ------------------
  |  Branch (143:9): [True: 5.20k, False: 0]
  ------------------
  144|  5.20k|      call_free_func(free_func, sk->data[i]);
  145|  5.20k|    }
  146|  5.20k|  }
  147|  8.68k|  sk_free(sk);
  148|  8.68k|}
sk_insert:
  161|  6.60k|size_t sk_insert(_STACK *sk, void *p, size_t where) {
  162|  6.60k|  if (sk == NULL) {
  ------------------
  |  Branch (162:7): [True: 0, False: 6.60k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|  6.60k|  if (sk->num >= INT_MAX) {
  ------------------
  |  Branch (166:7): [True: 0, False: 6.60k]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|  6.60k|  if (sk->num_alloc <= sk->num + 1) {
  ------------------
  |  Branch (171:7): [True: 76, False: 6.52k]
  ------------------
  172|       |    // Attempt to double the size of the array.
  173|     76|    size_t new_alloc = sk->num_alloc << 1;
  174|     76|    size_t alloc_size = new_alloc * sizeof(void *);
  175|     76|    void **data;
  176|       |
  177|       |    // If the doubling overflowed, try to increment.
  178|     76|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (178:9): [True: 0, False: 76]
  |  Branch (178:38): [True: 0, False: 76]
  ------------------
  179|      0|      new_alloc = sk->num_alloc + 1;
  180|      0|      alloc_size = new_alloc * sizeof(void *);
  181|      0|    }
  182|       |
  183|       |    // If the increment also overflowed, fail.
  184|     76|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 76]
  |  Branch (184:38): [True: 0, False: 76]
  ------------------
  185|      0|      return 0;
  186|      0|    }
  187|       |
  188|     76|    data = OPENSSL_realloc(sk->data, alloc_size);
  189|     76|    if (data == NULL) {
  ------------------
  |  Branch (189:9): [True: 0, False: 76]
  ------------------
  190|      0|      return 0;
  191|      0|    }
  192|       |
  193|     76|    sk->data = data;
  194|     76|    sk->num_alloc = new_alloc;
  195|     76|  }
  196|       |
  197|  6.60k|  if (where >= sk->num) {
  ------------------
  |  Branch (197:7): [True: 6.60k, False: 0]
  ------------------
  198|  6.60k|    sk->data[sk->num] = p;
  199|  6.60k|  } else {
  200|      0|    OPENSSL_memmove(&sk->data[where + 1], &sk->data[where],
  201|      0|                    sizeof(void *) * (sk->num - where));
  202|      0|    sk->data[where] = p;
  203|      0|  }
  204|       |
  205|  6.60k|  sk->num++;
  206|  6.60k|  sk->sorted = 0;
  207|       |
  208|  6.60k|  return sk->num;
  209|  6.60k|}
sk_delete:
  211|      3|void *sk_delete(_STACK *sk, size_t where) {
  212|      3|  void *ret;
  213|       |
  214|      3|  if (!sk || where >= sk->num) {
  ------------------
  |  Branch (214:7): [True: 0, False: 3]
  |  Branch (214:14): [True: 0, False: 3]
  ------------------
  215|      0|    return NULL;
  216|      0|  }
  217|       |
  218|      3|  ret = sk->data[where];
  219|       |
  220|      3|  if (where != sk->num - 1) {
  ------------------
  |  Branch (220:7): [True: 0, False: 3]
  ------------------
  221|      0|    OPENSSL_memmove(&sk->data[where], &sk->data[where + 1],
  222|      0|                    sizeof(void *) * (sk->num - where - 1));
  223|      0|  }
  224|       |
  225|      3|  sk->num--;
  226|      3|  return ret;
  227|      3|}
sk_push:
  340|  6.60k|size_t sk_push(_STACK *sk, void *p) { return (sk_insert(sk, p, sk->num)); }
sk_pop:
  342|      3|void *sk_pop(_STACK *sk) {
  343|      3|  if (sk == NULL) {
  ------------------
  |  Branch (343:7): [True: 0, False: 3]
  ------------------
  344|      0|    return NULL;
  345|      0|  }
  346|      3|  if (sk->num == 0) {
  ------------------
  |  Branch (346:7): [True: 0, False: 3]
  ------------------
  347|      0|    return NULL;
  348|      0|  }
  349|      3|  return sk_delete(sk, sk->num - 1);
  350|      3|}

CRYPTO_MUTEX_init:
   31|  1.24k|void CRYPTO_MUTEX_init(CRYPTO_MUTEX *lock) {
   32|  1.24k|  if (pthread_rwlock_init((pthread_rwlock_t *) lock, NULL) != 0) {
  ------------------
  |  Branch (32:7): [True: 0, False: 1.24k]
  ------------------
   33|      0|    abort();
   34|      0|  }
   35|  1.24k|}
CRYPTO_MUTEX_cleanup:
   61|  1.24k|void CRYPTO_MUTEX_cleanup(CRYPTO_MUTEX *lock) {
   62|  1.24k|  pthread_rwlock_destroy((pthread_rwlock_t *) lock);
   63|  1.24k|}
CRYPTO_STATIC_MUTEX_lock_read:
   65|    390|void CRYPTO_STATIC_MUTEX_lock_read(struct CRYPTO_STATIC_MUTEX *lock) {
   66|    390|  if (pthread_rwlock_rdlock(&lock->lock) != 0) {
  ------------------
  |  Branch (66:7): [True: 0, False: 390]
  ------------------
   67|      0|    abort();
   68|      0|  }
   69|    390|}
CRYPTO_STATIC_MUTEX_lock_write:
   71|      4|void CRYPTO_STATIC_MUTEX_lock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   72|      4|  if (pthread_rwlock_wrlock(&lock->lock) != 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 4]
  ------------------
   73|      0|    abort();
   74|      0|  }
   75|      4|}
CRYPTO_STATIC_MUTEX_unlock_read:
   77|    390|void CRYPTO_STATIC_MUTEX_unlock_read(struct CRYPTO_STATIC_MUTEX *lock) {
   78|    390|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (78:7): [True: 0, False: 390]
  ------------------
   79|      0|    abort();
   80|      0|  }
   81|    390|}
CRYPTO_STATIC_MUTEX_unlock_write:
   83|      4|void CRYPTO_STATIC_MUTEX_unlock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   84|      4|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (84:7): [True: 0, False: 4]
  ------------------
   85|      0|    abort();
   86|      0|  }
   87|      4|}
CRYPTO_once:
   89|  15.4k|void CRYPTO_once(CRYPTO_once_t *once, void (*init)(void)) {
   90|  15.4k|  if (pthread_once(once, init) != 0) {
  ------------------
  |  Branch (90:7): [True: 0, False: 15.4k]
  ------------------
   91|      0|    abort();
   92|      0|  }
   93|  15.4k|}
CRYPTO_get_thread_local:
  132|  9.40k|void *CRYPTO_get_thread_local(thread_local_data_t index) {
  133|  9.40k|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  134|  9.40k|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (134:7): [True: 0, False: 9.40k]
  ------------------
  135|      0|    return NULL;
  136|      0|  }
  137|       |
  138|  9.40k|  void **pointers = pthread_getspecific(g_thread_local_key);
  139|  9.40k|  if (pointers == NULL) {
  ------------------
  |  Branch (139:7): [True: 1, False: 9.40k]
  ------------------
  140|      1|    return NULL;
  141|      1|  }
  142|  9.40k|  return pointers[index];
  143|  9.40k|}
CRYPTO_set_thread_local:
  146|      1|                            thread_local_destructor_t destructor) {
  147|      1|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  148|      1|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (148:7): [True: 0, False: 1]
  ------------------
  149|      0|    destructor(value);
  150|      0|    return 0;
  151|      0|  }
  152|       |
  153|      1|  void **pointers = pthread_getspecific(g_thread_local_key);
  154|      1|  if (pointers == NULL) {
  ------------------
  |  Branch (154:7): [True: 1, False: 0]
  ------------------
  155|      1|    pointers = malloc(sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  156|      1|    if (pointers == NULL) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1]
  ------------------
  157|      0|      destructor(value);
  158|      0|      return 0;
  159|      0|    }
  160|      1|    OPENSSL_memset(pointers, 0, sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  161|      1|    if (pthread_setspecific(g_thread_local_key, pointers) != 0) {
  ------------------
  |  Branch (161:9): [True: 0, False: 1]
  ------------------
  162|      0|      free(pointers);
  163|      0|      destructor(value);
  164|      0|      return 0;
  165|      0|    }
  166|      1|  }
  167|       |
  168|      1|  if (pthread_mutex_lock(&g_destructors_lock) != 0) {
  ------------------
  |  Branch (168:7): [True: 0, False: 1]
  ------------------
  169|      0|    destructor(value);
  170|      0|    return 0;
  171|      0|  }
  172|      1|  g_destructors[index] = destructor;
  173|      1|  pthread_mutex_unlock(&g_destructors_lock);
  174|       |
  175|      1|  pointers[index] = value;
  176|      1|  return 1;
  177|      1|}
thread_pthread.c:thread_local_init:
  127|      1|static void thread_local_init(void) {
  128|      1|  g_thread_local_key_created =
  129|      1|      pthread_key_create(&g_thread_local_key, thread_local_destructor) == 0;
  130|      1|}

x_name.c:x509_name_ex_new:
  136|  1.61k|static int x509_name_ex_new(ASN1_VALUE **val, const ASN1_ITEM *it) {
  137|  1.61k|  X509_NAME *ret = NULL;
  138|  1.61k|  ret = OPENSSL_malloc(sizeof(X509_NAME));
  139|  1.61k|  if (!ret) {
  ------------------
  |  Branch (139:7): [True: 0, False: 1.61k]
  ------------------
  140|      0|    goto memerr;
  141|      0|  }
  142|  1.61k|  if ((ret->entries = sk_X509_NAME_ENTRY_new_null()) == NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 1.61k]
  ------------------
  143|      0|    goto memerr;
  144|      0|  }
  145|  1.61k|  if ((ret->bytes = BUF_MEM_new()) == NULL) {
  ------------------
  |  Branch (145:7): [True: 0, False: 1.61k]
  ------------------
  146|      0|    goto memerr;
  147|      0|  }
  148|  1.61k|  ret->canon_enc = NULL;
  149|  1.61k|  ret->canon_enclen = 0;
  150|  1.61k|  ret->modified = 1;
  151|  1.61k|  *val = (ASN1_VALUE *)ret;
  152|  1.61k|  return 1;
  153|       |
  154|      0|memerr:
  155|      0|  if (ret) {
  ------------------
  |  Branch (155:7): [True: 0, False: 0]
  ------------------
  156|      0|    if (ret->entries) {
  ------------------
  |  Branch (156:9): [True: 0, False: 0]
  ------------------
  157|      0|      sk_X509_NAME_ENTRY_free(ret->entries);
  158|      0|    }
  159|      0|    OPENSSL_free(ret);
  160|      0|  }
  161|      0|  return 0;
  162|  1.61k|}
x_name.c:x509_name_ex_free:
  164|  1.61k|static void x509_name_ex_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  165|  1.61k|  X509_NAME *a;
  166|  1.61k|  if (!pval || !*pval) {
  ------------------
  |  Branch (166:7): [True: 0, False: 1.61k]
  |  Branch (166:16): [True: 0, False: 1.61k]
  ------------------
  167|      0|    return;
  168|      0|  }
  169|  1.61k|  a = (X509_NAME *)*pval;
  170|       |
  171|  1.61k|  BUF_MEM_free(a->bytes);
  172|  1.61k|  sk_X509_NAME_ENTRY_pop_free(a->entries, X509_NAME_ENTRY_free);
  173|  1.61k|  if (a->canon_enc) {
  ------------------
  |  Branch (173:7): [True: 395, False: 1.22k]
  ------------------
  174|    395|    OPENSSL_free(a->canon_enc);
  175|    395|  }
  176|  1.61k|  OPENSSL_free(a);
  177|  1.61k|  *pval = NULL;
  178|  1.61k|}
x_name.c:x509_name_ex_d2i:
  190|    504|                            ASN1_TLC *ctx) {
  191|    504|  const unsigned char *p = *in, *q;
  192|    504|  STACK_OF(STACK_OF_X509_NAME_ENTRY) *intname = NULL;
  ------------------
  |  |   81|    504|#define STACK_OF(type) struct stack_st_##type
  ------------------
  193|    504|  X509_NAME *nm = NULL;
  194|    504|  size_t i, j;
  195|    504|  int ret;
  196|    504|  STACK_OF(X509_NAME_ENTRY) *entries;
  ------------------
  |  |   81|    504|#define STACK_OF(type) struct stack_st_##type
  ------------------
  197|    504|  X509_NAME_ENTRY *entry;
  198|       |  // Bound the size of an X509_NAME we are willing to parse.
  199|    504|  if (len > X509_NAME_MAX) {
  ------------------
  |  |   80|    504|#define X509_NAME_MAX (1024 * 1024)
  ------------------
  |  Branch (199:7): [True: 0, False: 504]
  ------------------
  200|      0|    len = X509_NAME_MAX;
  ------------------
  |  |   80|      0|#define X509_NAME_MAX (1024 * 1024)
  ------------------
  201|      0|  }
  202|    504|  q = p;
  203|       |
  204|       |  // Get internal representation of Name
  205|    504|  ASN1_VALUE *intname_val = NULL;
  206|    504|  ret = ASN1_item_ex_d2i(&intname_val, &p, len,
  207|    504|                         ASN1_ITEM_rptr(X509_NAME_INTERNAL), /*tag=*/-1,
  ------------------
  |  |  274|    504|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  208|    504|                         /*aclass=*/0, opt, /*buf=*/NULL);
  209|    504|  if (ret <= 0) {
  ------------------
  |  Branch (209:7): [True: 107, False: 397]
  ------------------
  210|    107|    return ret;
  211|    107|  }
  212|    397|  intname = (STACK_OF(STACK_OF_X509_NAME_ENTRY) *)intname_val;
  213|       |
  214|    397|  if (*val) {
  ------------------
  |  Branch (214:7): [True: 397, False: 0]
  ------------------
  215|    397|    x509_name_ex_free(val, NULL);
  216|    397|  }
  217|    397|  ASN1_VALUE *nm_val = NULL;
  218|    397|  if (!x509_name_ex_new(&nm_val, NULL)) {
  ------------------
  |  Branch (218:7): [True: 0, False: 397]
  ------------------
  219|      0|    goto err;
  220|      0|  }
  221|    397|  nm = (X509_NAME *)nm_val;
  222|       |  // We've decoded it: now cache encoding
  223|    397|  if (!BUF_MEM_grow(nm->bytes, p - q)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 397]
  ------------------
  224|      0|    goto err;
  225|      0|  }
  226|    397|  OPENSSL_memcpy(nm->bytes->data, q, p - q);
  227|       |
  228|       |  // Convert internal representation to X509_NAME structure
  229|  1.50k|  for (i = 0; i < sk_STACK_OF_X509_NAME_ENTRY_num(intname); i++) {
  ------------------
  |  Branch (229:15): [True: 1.10k, False: 397]
  ------------------
  230|  1.10k|    entries = sk_STACK_OF_X509_NAME_ENTRY_value(intname, i);
  231|  2.20k|    for (j = 0; j < sk_X509_NAME_ENTRY_num(entries); j++) {
  ------------------
  |  Branch (231:17): [True: 1.10k, False: 1.10k]
  ------------------
  232|  1.10k|      entry = sk_X509_NAME_ENTRY_value(entries, j);
  233|  1.10k|      entry->set = (int)i;
  234|  1.10k|      if (!sk_X509_NAME_ENTRY_push(nm->entries, entry)) {
  ------------------
  |  Branch (234:11): [True: 0, False: 1.10k]
  ------------------
  235|      0|        goto err;
  236|      0|      }
  237|  1.10k|      (void)sk_X509_NAME_ENTRY_set(entries, j, NULL);
  238|  1.10k|    }
  239|  1.10k|  }
  240|    397|  ret = x509_name_canon(nm);
  241|    397|  if (!ret) {
  ------------------
  |  Branch (241:7): [True: 0, False: 397]
  ------------------
  242|      0|    goto err;
  243|      0|  }
  244|    397|  sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname, local_sk_X509_NAME_ENTRY_free);
  245|    397|  nm->modified = 0;
  246|    397|  *val = (ASN1_VALUE *)nm;
  247|    397|  *in = p;
  248|    397|  return ret;
  249|      0|err:
  250|      0|  X509_NAME_free(nm);
  251|      0|  sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname,
  252|      0|                                       local_sk_X509_NAME_ENTRY_pop_free);
  253|      0|  OPENSSL_PUT_ERROR(X509, ERR_R_ASN1_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  254|      0|  return 0;
  255|    397|}
x_name.c:x509_name_canon:
  331|    397|static int x509_name_canon(X509_NAME *a) {
  332|    397|  unsigned char *p;
  333|    397|  STACK_OF(STACK_OF_X509_NAME_ENTRY) *intname = NULL;
  ------------------
  |  |   81|    397|#define STACK_OF(type) struct stack_st_##type
  ------------------
  334|    397|  STACK_OF(X509_NAME_ENTRY) *entries = NULL;
  ------------------
  |  |   81|    397|#define STACK_OF(type) struct stack_st_##type
  ------------------
  335|    397|  X509_NAME_ENTRY *entry, *tmpentry = NULL;
  336|    397|  int set = -1, ret = 0, len;
  337|    397|  size_t i;
  338|       |
  339|    397|  if (a->canon_enc) {
  ------------------
  |  Branch (339:7): [True: 0, False: 397]
  ------------------
  340|      0|    OPENSSL_free(a->canon_enc);
  341|      0|    a->canon_enc = NULL;
  342|      0|  }
  343|       |  // Special case: empty X509_NAME => null encoding
  344|    397|  if (sk_X509_NAME_ENTRY_num(a->entries) == 0) {
  ------------------
  |  Branch (344:7): [True: 2, False: 395]
  ------------------
  345|      2|    a->canon_enclen = 0;
  346|      2|    return 1;
  347|      2|  }
  348|    395|  intname = sk_STACK_OF_X509_NAME_ENTRY_new_null();
  349|    395|  if (!intname) {
  ------------------
  |  Branch (349:7): [True: 0, False: 395]
  ------------------
  350|      0|    goto err;
  351|      0|  }
  352|  1.49k|  for (i = 0; i < sk_X509_NAME_ENTRY_num(a->entries); i++) {
  ------------------
  |  Branch (352:15): [True: 1.10k, False: 395]
  ------------------
  353|  1.10k|    entry = sk_X509_NAME_ENTRY_value(a->entries, i);
  354|  1.10k|    if (entry->set != set) {
  ------------------
  |  Branch (354:9): [True: 1.10k, False: 0]
  ------------------
  355|  1.10k|      entries = sk_X509_NAME_ENTRY_new_null();
  356|  1.10k|      if (!entries) {
  ------------------
  |  Branch (356:11): [True: 0, False: 1.10k]
  ------------------
  357|      0|        goto err;
  358|      0|      }
  359|  1.10k|      if (!sk_STACK_OF_X509_NAME_ENTRY_push(intname, entries)) {
  ------------------
  |  Branch (359:11): [True: 0, False: 1.10k]
  ------------------
  360|      0|        sk_X509_NAME_ENTRY_free(entries);
  361|      0|        goto err;
  362|      0|      }
  363|  1.10k|      set = entry->set;
  364|  1.10k|    }
  365|  1.10k|    tmpentry = X509_NAME_ENTRY_new();
  366|  1.10k|    if (tmpentry == NULL) {
  ------------------
  |  Branch (366:9): [True: 0, False: 1.10k]
  ------------------
  367|      0|      goto err;
  368|      0|    }
  369|  1.10k|    tmpentry->object = OBJ_dup(entry->object);
  370|  1.10k|    if (!asn1_string_canon(tmpentry->value, entry->value)) {
  ------------------
  |  Branch (370:9): [True: 0, False: 1.10k]
  ------------------
  371|      0|      goto err;
  372|      0|    }
  373|  1.10k|    if (!sk_X509_NAME_ENTRY_push(entries, tmpentry)) {
  ------------------
  |  Branch (373:9): [True: 0, False: 1.10k]
  ------------------
  374|      0|      goto err;
  375|      0|    }
  376|  1.10k|    tmpentry = NULL;
  377|  1.10k|  }
  378|       |
  379|       |  // Finally generate encoding
  380|       |
  381|    395|  len = i2d_name_canon(intname, NULL);
  382|    395|  if (len < 0) {
  ------------------
  |  Branch (382:7): [True: 0, False: 395]
  ------------------
  383|      0|    goto err;
  384|      0|  }
  385|    395|  a->canon_enclen = len;
  386|       |
  387|    395|  p = OPENSSL_malloc(a->canon_enclen);
  388|       |
  389|    395|  if (!p) {
  ------------------
  |  Branch (389:7): [True: 0, False: 395]
  ------------------
  390|      0|    goto err;
  391|      0|  }
  392|       |
  393|    395|  a->canon_enc = p;
  394|       |
  395|    395|  i2d_name_canon(intname, &p);
  396|       |
  397|    395|  ret = 1;
  398|       |
  399|    395|err:
  400|       |
  401|    395|  if (tmpentry) {
  ------------------
  |  Branch (401:7): [True: 0, False: 395]
  ------------------
  402|      0|    X509_NAME_ENTRY_free(tmpentry);
  403|      0|  }
  404|    395|  if (intname) {
  ------------------
  |  Branch (404:7): [True: 395, False: 0]
  ------------------
  405|    395|    sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname,
  406|    395|                                         local_sk_X509_NAME_ENTRY_pop_free);
  407|    395|  }
  408|    395|  return ret;
  409|    395|}
x_name.c:asn1_string_canon:
  418|  1.10k|static int asn1_string_canon(ASN1_STRING *out, ASN1_STRING *in) {
  419|  1.10k|  unsigned char *to, *from;
  420|  1.10k|  int len, i;
  421|       |
  422|       |  // If type not in bitmask just copy string across
  423|  1.10k|  if (!(ASN1_tag2bit(in->type) & ASN1_MASK_CANON)) {
  ------------------
  |  |  414|  1.10k|  (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  175|  1.10k|#define B_ASN1_UTF8STRING 0x2000
  |  |  ------------------
  |  |                 (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  173|  1.10k|#define B_ASN1_BMPSTRING 0x0800
  |  |  ------------------
  |  |                 (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  170|  1.10k|#define B_ASN1_UNIVERSALSTRING 0x0100
  |  |  ------------------
  |  |  415|  1.10k|   B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  161|  1.10k|#define B_ASN1_PRINTABLESTRING 0x0002
  |  |  ------------------
  |  |                  B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  162|  1.10k|#define B_ASN1_T61STRING 0x0004
  |  |  ------------------
  |  |                  B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  165|  1.10k|#define B_ASN1_IA5STRING 0x0010
  |  |  ------------------
  |  |  416|  1.10k|   B_ASN1_VISIBLESTRING)
  |  |  ------------------
  |  |  |  |  168|  1.10k|#define B_ASN1_VISIBLESTRING 0x0040
  |  |  ------------------
  ------------------
  |  Branch (423:7): [True: 19, False: 1.08k]
  ------------------
  424|     19|    if (!ASN1_STRING_copy(out, in)) {
  ------------------
  |  Branch (424:9): [True: 0, False: 19]
  ------------------
  425|      0|      return 0;
  426|      0|    }
  427|     19|    return 1;
  428|     19|  }
  429|       |
  430|  1.08k|  out->type = V_ASN1_UTF8STRING;
  ------------------
  |  |  135|  1.08k|#define V_ASN1_UTF8STRING 12
  ------------------
  431|  1.08k|  out->length = ASN1_STRING_to_UTF8(&out->data, in);
  432|  1.08k|  if (out->length == -1) {
  ------------------
  |  Branch (432:7): [True: 0, False: 1.08k]
  ------------------
  433|      0|    return 0;
  434|      0|  }
  435|       |
  436|  1.08k|  to = out->data;
  437|  1.08k|  from = to;
  438|       |
  439|  1.08k|  len = out->length;
  440|       |
  441|       |  // Convert string in place to canonical form.
  442|       |
  443|       |  // Ignore leading spaces
  444|  1.08k|  while ((len > 0) && OPENSSL_isspace(*from)) {
  ------------------
  |  Branch (444:10): [True: 1.08k, False: 3]
  |  Branch (444:23): [True: 0, False: 1.08k]
  ------------------
  445|      0|    from++;
  446|      0|    len--;
  447|      0|  }
  448|       |
  449|  1.08k|  to = from + len;
  450|       |
  451|       |  // Ignore trailing spaces
  452|  1.10k|  while ((len > 0) && OPENSSL_isspace(to[-1])) {
  ------------------
  |  Branch (452:10): [True: 1.10k, False: 3]
  |  Branch (452:23): [True: 18, False: 1.08k]
  ------------------
  453|     18|    to--;
  454|     18|    len--;
  455|     18|  }
  456|       |
  457|  1.08k|  to = out->data;
  458|       |
  459|  1.08k|  i = 0;
  460|  13.2k|  while (i < len) {
  ------------------
  |  Branch (460:10): [True: 12.1k, False: 1.08k]
  ------------------
  461|       |    // Collapse multiple spaces
  462|  12.1k|    if (OPENSSL_isspace(*from)) {
  ------------------
  |  Branch (462:9): [True: 824, False: 11.3k]
  ------------------
  463|       |      // Copy one space across
  464|    824|      *to++ = ' ';
  465|       |      // Ignore subsequent spaces. Note: don't need to check len here
  466|       |      // because we know the last character is a non-space so we can't
  467|       |      // overflow.
  468|    835|      do {
  469|    835|        from++;
  470|    835|        i++;
  471|    835|      } while (OPENSSL_isspace(*from));
  ------------------
  |  Branch (471:16): [True: 11, False: 824]
  ------------------
  472|  11.3k|    } else {
  473|  11.3k|      *to++ = OPENSSL_tolower(*from);
  474|  11.3k|      from++;
  475|  11.3k|      i++;
  476|  11.3k|    }
  477|  12.1k|  }
  478|       |
  479|  1.08k|  out->length = to - out->data;
  480|       |
  481|  1.08k|  return 1;
  482|  1.08k|}
x_name.c:i2d_name_canon:
  485|    790|                          unsigned char **in) {
  486|    790|  int len, ltmp;
  487|    790|  size_t i;
  488|    790|  ASN1_VALUE *v;
  489|    790|  STACK_OF(ASN1_VALUE) *intname = (STACK_OF(ASN1_VALUE) *)_intname;
  ------------------
  |  |   81|    790|#define STACK_OF(type) struct stack_st_##type
  ------------------
  490|       |
  491|    790|  len = 0;
  492|  2.99k|  for (i = 0; i < sk_ASN1_VALUE_num(intname); i++) {
  ------------------
  |  Branch (492:15): [True: 2.20k, False: 790]
  ------------------
  493|  2.20k|    v = sk_ASN1_VALUE_value(intname, i);
  494|  2.20k|    ltmp = ASN1_item_ex_i2d(&v, in, ASN1_ITEM_rptr(X509_NAME_ENTRIES),
  ------------------
  |  |  274|  2.20k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  495|  2.20k|                            /*tag=*/-1, /*aclass=*/0);
  496|  2.20k|    if (ltmp < 0) {
  ------------------
  |  Branch (496:9): [True: 0, False: 2.20k]
  ------------------
  497|      0|      return ltmp;
  498|      0|    }
  499|  2.20k|    len += ltmp;
  500|  2.20k|  }
  501|    790|  return len;
  502|    790|}
x_name.c:local_sk_X509_NAME_ENTRY_free:
  180|  1.10k|static void local_sk_X509_NAME_ENTRY_free(STACK_OF(X509_NAME_ENTRY) *ne) {
  181|  1.10k|  sk_X509_NAME_ENTRY_free(ne);
  182|  1.10k|}
x_name.c:local_sk_X509_NAME_ENTRY_pop_free:
  184|  1.10k|static void local_sk_X509_NAME_ENTRY_pop_free(STACK_OF(X509_NAME_ENTRY) *ne) {
  185|  1.10k|  sk_X509_NAME_ENTRY_pop_free(ne, X509_NAME_ENTRY_free);
  186|  1.10k|}

x_pubkey.c:pubkey_cb:
   75|  2.65k|                     void *exarg) {
   76|  2.65k|  if (operation == ASN1_OP_FREE_POST) {
  ------------------
  |  |  540|  2.65k|#define ASN1_OP_FREE_POST	3
  ------------------
  |  Branch (76:7): [True: 610, False: 2.04k]
  ------------------
   77|    610|    X509_PUBKEY *pubkey = (X509_PUBKEY *)*pval;
   78|    610|    EVP_PKEY_free(pubkey->pkey);
   79|    610|  }
   80|  2.65k|  return 1;
   81|  2.65k|}

X509_free:
  126|    610|void X509_free(X509 *x509) {
  127|    610|  if (x509 == NULL || !CRYPTO_refcount_dec_and_test_zero(&x509->references)) {
  ------------------
  |  Branch (127:7): [True: 0, False: 610]
  |  Branch (127:23): [True: 0, False: 610]
  ------------------
  128|      0|    return;
  129|      0|  }
  130|       |
  131|    610|  CRYPTO_free_ex_data(&g_ex_data_class, x509, &x509->ex_data);
  132|       |
  133|    610|  X509_CINF_free(x509->cert_info);
  134|    610|  X509_ALGOR_free(x509->sig_alg);
  135|    610|  ASN1_BIT_STRING_free(x509->signature);
  136|    610|  ASN1_OCTET_STRING_free(x509->skid);
  137|    610|  AUTHORITY_KEYID_free(x509->akid);
  138|    610|  CRL_DIST_POINTS_free(x509->crldp);
  139|    610|  GENERAL_NAMES_free(x509->altname);
  140|    610|  NAME_CONSTRAINTS_free(x509->nc);
  141|    610|  X509_CERT_AUX_free(x509->aux);
  142|    610|  CRYPTO_MUTEX_cleanup(&x509->lock);
  143|       |
  144|    610|  OPENSSL_free(x509);
  145|    610|}
d2i_X509:
  237|    653|X509 *d2i_X509(X509 **out, const uint8_t **inp, long len) {
  238|    653|  X509 *ret = NULL;
  239|    653|  if (len < 0) {
  ------------------
  |  Branch (239:7): [True: 0, False: 653]
  ------------------
  240|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_BUFFER_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  241|      0|    goto err;
  242|      0|  }
  243|       |
  244|    653|  CBS cbs;
  245|    653|  CBS_init(&cbs, *inp, (size_t)len);
  246|    653|  ret = x509_parse(&cbs, NULL);
  247|    653|  if (ret == NULL) {
  ------------------
  |  Branch (247:7): [True: 624, False: 29]
  ------------------
  248|    624|    goto err;
  249|    624|  }
  250|       |
  251|     29|  *inp = CBS_data(&cbs);
  252|       |
  253|    653|err:
  254|    653|  if (out != NULL) {
  ------------------
  |  Branch (254:7): [True: 0, False: 653]
  ------------------
  255|      0|    X509_free(*out);
  256|      0|    *out = ret;
  257|      0|  }
  258|    653|  return ret;
  259|     29|}
x_x509.c:x509_new_null:
   94|    610|static X509 *x509_new_null(void) {
   95|    610|  X509 *ret = OPENSSL_malloc(sizeof(X509));
   96|    610|  if (ret == NULL) {
  ------------------
  |  Branch (96:7): [True: 0, False: 610]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|    610|  OPENSSL_memset(ret, 0, sizeof(X509));
  100|       |
  101|    610|  ret->references = 1;
  102|    610|  ret->ex_pathlen = -1;
  103|    610|  CRYPTO_new_ex_data(&ret->ex_data);
  104|    610|  CRYPTO_MUTEX_init(&ret->lock);
  105|    610|  return ret;
  106|    610|}
x_x509.c:x509_parse:
  147|    653|static X509 *x509_parse(CBS *cbs, CRYPTO_BUFFER *buf) {
  148|    653|  CBS cert, tbs, sigalg, sig;
  149|    653|  if (!CBS_get_asn1(cbs, &cert, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    653|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    653|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    653|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (149:7): [True: 5, False: 648]
  ------------------
  150|       |      // Bound the length to comfortably fit in an int. Lengths in this
  151|       |      // module often omit overflow checks.
  152|    653|      CBS_len(&cert) > INT_MAX / 2 ||
  ------------------
  |  Branch (152:7): [True: 0, False: 648]
  ------------------
  153|    653|      !CBS_get_asn1_element(&cert, &tbs, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    648|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    648|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    648|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (153:7): [True: 1, False: 647]
  ------------------
  154|    653|      !CBS_get_asn1_element(&cert, &sigalg, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|    647|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    647|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    647|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (154:7): [True: 2, False: 645]
  ------------------
  155|      8|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_DECODE_ERROR);
  ------------------
  |  |  441|      8|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      8|    return NULL;
  157|      8|  }
  158|       |
  159|       |  // For just the signature field, we accept non-minimal BER lengths, though not
  160|       |  // indefinite-length encoding. See b/18228011.
  161|       |  //
  162|       |  // TODO(crbug.com/boringssl/354): Switch the affected callers to convert the
  163|       |  // certificate before parsing and then remove this workaround.
  164|    645|  CBS_ASN1_TAG tag;
  165|    645|  size_t header_len;
  166|    645|  int indefinite;
  167|    645|  if (!CBS_get_any_ber_asn1_element(&cert, &sig, &tag, &header_len,
  ------------------
  |  Branch (167:7): [True: 1, False: 644]
  ------------------
  168|       |                                    /*out_ber_found=*/NULL,
  169|    645|                                    &indefinite) ||
  170|    645|      tag != CBS_ASN1_BITSTRING || indefinite ||  //
  ------------------
  |  |  216|  1.28k|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (170:7): [True: 32, False: 612]
  |  Branch (170:36): [True: 0, False: 612]
  ------------------
  171|    645|      !CBS_skip(&sig, header_len) ||              //
  ------------------
  |  Branch (171:7): [True: 0, False: 612]
  ------------------
  172|    645|      CBS_len(&cert) != 0) {
  ------------------
  |  Branch (172:7): [True: 2, False: 610]
  ------------------
  173|     35|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_DECODE_ERROR);
  ------------------
  |  |  441|     35|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  174|     35|    return NULL;
  175|     35|  }
  176|       |
  177|    610|  X509 *ret = x509_new_null();
  178|    610|  if (ret == NULL) {
  ------------------
  |  Branch (178:7): [True: 0, False: 610]
  ------------------
  179|      0|    return NULL;
  180|      0|  }
  181|       |
  182|       |  // TODO(crbug.com/boringssl/443): When the rest of the library is decoupled
  183|       |  // from the tasn_*.c implementation, replace this with |CBS|-based functions.
  184|    610|  const uint8_t *inp = CBS_data(&tbs);
  185|    610|  if (ASN1_item_ex_d2i((ASN1_VALUE **)&ret->cert_info, &inp, CBS_len(&tbs),
  ------------------
  |  Branch (185:7): [True: 577, False: 33]
  ------------------
  186|    610|                       ASN1_ITEM_rptr(X509_CINF), /*tag=*/-1,
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  187|    610|                       /*aclass=*/0, /*opt=*/0, buf) <= 0 ||
  188|    610|      inp != CBS_data(&tbs) + CBS_len(&tbs)) {
  ------------------
  |  Branch (188:7): [True: 0, False: 33]
  ------------------
  189|    577|    goto err;
  190|    577|  }
  191|       |
  192|     33|  inp = CBS_data(&sigalg);
  193|     33|  ret->sig_alg = d2i_X509_ALGOR(NULL, &inp, CBS_len(&sigalg));
  194|     33|  if (ret->sig_alg == NULL || inp != CBS_data(&sigalg) + CBS_len(&sigalg)) {
  ------------------
  |  Branch (194:7): [True: 3, False: 30]
  |  Branch (194:31): [True: 0, False: 30]
  ------------------
  195|      3|    goto err;
  196|      3|  }
  197|       |
  198|     30|  inp = CBS_data(&sig);
  199|     30|  ret->signature = c2i_ASN1_BIT_STRING(NULL, &inp, CBS_len(&sig));
  200|     30|  if (ret->signature == NULL || inp != CBS_data(&sig) + CBS_len(&sig)) {
  ------------------
  |  Branch (200:7): [True: 1, False: 29]
  |  Branch (200:33): [True: 0, False: 29]
  ------------------
  201|      1|    goto err;
  202|      1|  }
  203|       |
  204|       |  // The version must be one of v1(0), v2(1), or v3(2).
  205|     29|  long version = X509_VERSION_1;
  ------------------
  |  |  168|     29|#define X509_VERSION_1 0
  ------------------
  206|     29|  if (ret->cert_info->version != NULL) {
  ------------------
  |  Branch (206:7): [True: 29, False: 0]
  ------------------
  207|     29|    version = ASN1_INTEGER_get(ret->cert_info->version);
  208|       |    // TODO(https://crbug.com/boringssl/364): |X509_VERSION_1| should
  209|       |    // also be rejected here. This means an explicitly-encoded X.509v1
  210|       |    // version. v1 is DEFAULT, so DER requires it be omitted.
  211|     29|    if (version < X509_VERSION_1 || version > X509_VERSION_3) {
  ------------------
  |  |  168|     58|#define X509_VERSION_1 0
  ------------------
                  if (version < X509_VERSION_1 || version > X509_VERSION_3) {
  ------------------
  |  |  170|     29|#define X509_VERSION_3 2
  ------------------
  |  Branch (211:9): [True: 0, False: 29]
  |  Branch (211:37): [True: 0, False: 29]
  ------------------
  212|      0|      OPENSSL_PUT_ERROR(X509, X509_R_INVALID_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|      0|      goto err;
  214|      0|    }
  215|     29|  }
  216|       |
  217|       |  // Per RFC 5280, section 4.1.2.8, these fields require v2 or v3.
  218|     29|  if (version == X509_VERSION_1 && (ret->cert_info->issuerUID != NULL ||
  ------------------
  |  |  168|     58|#define X509_VERSION_1 0
  ------------------
  |  Branch (218:7): [True: 0, False: 29]
  |  Branch (218:37): [True: 0, False: 0]
  ------------------
  219|      0|                                    ret->cert_info->subjectUID != NULL)) {
  ------------------
  |  Branch (219:37): [True: 0, False: 0]
  ------------------
  220|      0|    OPENSSL_PUT_ERROR(X509, X509_R_INVALID_FIELD_FOR_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  221|      0|    goto err;
  222|      0|  }
  223|       |
  224|       |  // Per RFC 5280, section 4.1.2.9, extensions require v3.
  225|     29|  if (version != X509_VERSION_3 && ret->cert_info->extensions != NULL) {
  ------------------
  |  |  170|     58|#define X509_VERSION_3 2
  ------------------
  |  Branch (225:7): [True: 0, False: 29]
  |  Branch (225:36): [True: 0, False: 0]
  ------------------
  226|      0|    OPENSSL_PUT_ERROR(X509, X509_R_INVALID_FIELD_FOR_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  227|      0|    goto err;
  228|      0|  }
  229|       |
  230|     29|  return ret;
  231|       |
  232|    581|err:
  233|    581|  X509_free(ret);
  234|    581|  return NULL;
  235|     29|}

X509_alias_set1:
   93|      6|int X509_alias_set1(X509 *x, const unsigned char *name, ossl_ssize_t len) {
   94|      6|  X509_CERT_AUX *aux;
   95|       |  // TODO(davidben): Empty aliases are not meaningful in PKCS#12, and the
   96|       |  // getters cannot quite represent them. Also erase the object if |len| is
   97|       |  // zero.
   98|      6|  if (!name) {
  ------------------
  |  Branch (98:7): [True: 0, False: 6]
  ------------------
   99|      0|    if (!x || !x->aux || !x->aux->alias) {
  ------------------
  |  Branch (99:9): [True: 0, False: 0]
  |  Branch (99:15): [True: 0, False: 0]
  |  Branch (99:26): [True: 0, False: 0]
  ------------------
  100|      0|      return 1;
  101|      0|    }
  102|      0|    ASN1_UTF8STRING_free(x->aux->alias);
  103|      0|    x->aux->alias = NULL;
  104|      0|    return 1;
  105|      0|  }
  106|      6|  if (!(aux = aux_get(x))) {
  ------------------
  |  Branch (106:7): [True: 0, False: 6]
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|      6|  if (!aux->alias && !(aux->alias = ASN1_UTF8STRING_new())) {
  ------------------
  |  Branch (109:7): [True: 6, False: 0]
  |  Branch (109:22): [True: 0, False: 6]
  ------------------
  110|      0|    return 0;
  111|      0|  }
  112|      6|  return ASN1_STRING_set(aux->alias, name, len);
  113|      6|}
x_x509a.c:aux_get:
   83|      6|static X509_CERT_AUX *aux_get(X509 *x) {
   84|      6|  if (!x) {
  ------------------
  |  Branch (84:7): [True: 0, False: 6]
  ------------------
   85|      0|    return NULL;
   86|      0|  }
   87|      6|  if (!x->aux && !(x->aux = X509_CERT_AUX_new())) {
  ------------------
  |  Branch (87:7): [True: 6, False: 0]
  |  Branch (87:18): [True: 0, False: 6]
  ------------------
   88|      0|    return NULL;
   89|      0|  }
   90|      6|  return x->aux;
   91|      6|}

LLVMFuzzerTestOneInput:
   21|  4.80k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) {
   22|  4.80k|  bssl::UniquePtr<STACK_OF(X509)> certs(sk_X509_new_null());
   23|  4.80k|  EVP_PKEY *key = nullptr;
   24|  4.80k|  CBS cbs;
   25|  4.80k|  CBS_init(&cbs, buf, len);
   26|  4.80k|  PKCS12_get_key_and_certs(&key, certs.get(), &cbs, "foo");
   27|  4.80k|  EVP_PKEY_free(key);
   28|  4.80k|  return 0;
   29|  4.80k|}

d2i_X509_ALGOR:
  630|     33|	{ \
  631|     33|		return (stname *)ASN1_item_d2i((ASN1_VALUE **)a, in, len, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|     33|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  632|     33|	} \
X509_ALGOR_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
X509_NAME_ENTRY_new:
  603|  1.10k|	{ \
  604|  1.10k|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  1.10k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|  1.10k|	} \
X509_NAME_ENTRY_free:
  607|  2.20k|	{ \
  608|  2.20k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  2.20k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  2.20k|	}
X509_CINF_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
X509_CERT_AUX_new:
  603|      6|	{ \
  604|      6|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|      6|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|      6|	} \
X509_CERT_AUX_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
AUTHORITY_KEYID_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
CRL_DIST_POINTS_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
GENERAL_NAMES_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
NAME_CONSTRAINTS_free:
  607|    610|	{ \
  608|    610|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    610|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    610|	}
ASN1_TYPE_new:
  603|    673|	{ \
  604|    673|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    673|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|    673|	} \
ASN1_TYPE_free:
  607|    245|	{ \
  608|    245|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|    245|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|    245|	}

_ZN4bssl8internal7DeleterclI13stack_st_X509EEvPT_:
  560|  4.80k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  4.80k|    DeleterImpl<T>::Free(ptr);
  570|  4.80k|  }
_ZN4bssl8internal11DeleterImplI7x509_stvE4FreeEPS2_:
  635|     10|    static void Free(type *ptr) { deleter(ptr); } \

sk_X509_new_null:
  420|  4.80k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  4.80k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  4.80k|  }                                                                           \
_ZN4bssl8internal11DeleterImplI13stack_st_X509vE4FreeEPS2_:
  552|  4.80k|  static void Free(Stack *sk) {
  553|       |    // sk_FOO_pop_free is defined by macros and bound by name, so we cannot
  554|       |    // access it from C++ here.
  555|  4.80k|    using Type = typename StackTraits<Stack>::Type;
  556|  4.80k|    sk_pop_free_ex(reinterpret_cast<_STACK *>(sk),
  557|  4.80k|                   [](OPENSSL_sk_free_func /* unused */, void *ptr) {
  558|  4.80k|                     DeleterImpl<Type>::Free(reinterpret_cast<Type *>(ptr));
  559|  4.80k|                   },
  560|  4.80k|                   nullptr);
  561|  4.80k|  }
_ZZN4bssl8internal11DeleterImplI13stack_st_X509vE4FreeEPS2_ENKUlPFvPvES5_E_clES7_S5_:
  557|     10|                   [](OPENSSL_sk_free_func /* unused */, void *ptr) {
  558|     10|                     DeleterImpl<Type>::Free(reinterpret_cast<Type *>(ptr));
  559|     10|                   },
pkcs8_x509.c:sk_X509_num:
  424|  8.67k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  8.67k|    return sk_num((const _STACK *)sk);                                        \
  426|  8.67k|  }                                                                           \
pkcs8_x509.c:sk_X509_push:
  483|     13|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|     13|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|     13|  }                                                                           \
pkcs8_x509.c:sk_X509_pop:
  487|      3|  OPENSSL_INLINE ptrtype sk_##name##_pop(STACK_OF(name) *sk) {                \
  488|      3|    return (ptrtype)sk_pop((_STACK *)sk);                                     \
  489|      3|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_new_null:
  420|  2.72k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  2.72k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  2.72k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_free:
  442|  1.10k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  1.10k|    sk_free((_STACK *)sk);                                                    \
  444|  1.10k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_pop_free:
  447|  2.72k|                                           sk_##name##_free_func free_func) { \
  448|  2.72k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  2.72k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  2.72k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_call_free_func:
  391|  2.20k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  2.20k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  2.20k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_num:
  424|  1.50k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  1.50k|    return sk_num((const _STACK *)sk);                                        \
  426|  1.50k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_value:
  433|  1.10k|                                           size_t i) {                        \
  434|  1.10k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  1.10k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_num:
  424|  4.10k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  4.10k|    return sk_num((const _STACK *)sk);                                        \
  426|  4.10k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_value:
  433|  2.20k|                                           size_t i) {                        \
  434|  2.20k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  2.20k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_push:
  483|  2.20k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  2.20k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  2.20k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_set:
  438|  1.10k|                                         ptrtype p) {                         \
  439|  1.10k|    return (ptrtype)sk_set((_STACK *)sk, i, (void *)p);                       \
  440|  1.10k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_new_null:
  420|    395|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|    395|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|    395|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_push:
  483|  1.10k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  1.10k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  1.10k|  }                                                                           \
x_name.c:sk_ASN1_VALUE_num:
  424|  2.99k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  2.99k|    return sk_num((const _STACK *)sk);                                        \
  426|  2.99k|  }                                                                           \
x_name.c:sk_ASN1_VALUE_value:
  433|  2.20k|                                           size_t i) {                        \
  434|  2.20k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  2.20k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_pop_free:
  447|    792|                                           sk_##name##_free_func free_func) { \
  448|    792|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|    792|                   (OPENSSL_sk_free_func)free_func);                          \
  450|    792|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_call_free_func:
  391|  2.20k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  2.20k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  2.20k|  }                                                                           \
bcm.c:sk_BIGNUM_pop_free:
  447|    367|                                           sk_##name##_free_func free_func) { \
  448|    367|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|    367|                   (OPENSSL_sk_free_func)free_func);                          \
  450|    367|  }                                                                           \
bcm.c:sk_BIGNUM_call_free_func:
  391|    778|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|    778|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|    778|  }                                                                           \
bcm.c:sk_BIGNUM_new_null:
  420|    364|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|    364|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|    364|  }                                                                           \
bcm.c:sk_BIGNUM_num:
  424|  1.88k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  1.88k|    return sk_num((const _STACK *)sk);                                        \
  426|  1.88k|  }                                                                           \
bcm.c:sk_BIGNUM_push:
  483|    778|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|    778|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|    778|  }                                                                           \
bcm.c:sk_BIGNUM_value:
  433|  1.88k|                                           size_t i) {                        \
  434|  1.88k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  1.88k|  }                                                                           \
tasn_dec.c:sk_ASN1_VALUE_new_null:
  420|  1.75k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  1.75k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  1.75k|  }                                                                           \
tasn_dec.c:sk_ASN1_VALUE_push:
  483|  2.49k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  2.49k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  2.49k|  }                                                                           \
tasn_enc.c:sk_ASN1_VALUE_num:
  424|  7.72k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  7.72k|    return sk_num((const _STACK *)sk);                                        \
  426|  7.72k|  }                                                                           \
tasn_enc.c:sk_ASN1_VALUE_value:
  433|  3.31k|                                           size_t i) {                        \
  434|  3.31k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  3.31k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_num:
  424|  2.36k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  2.36k|    return sk_num((const _STACK *)sk);                                        \
  426|  2.36k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_value:
  433|    290|                                           size_t i) {                        \
  434|    290|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|    290|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_free:
  442|  2.07k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  2.07k|    sk_free((_STACK *)sk);                                                    \
  444|  2.07k|  }                                                                           \

curve25519.c:fiat_25519_carry_mul:
  133|  1.45k|static FIAT_25519_FIAT_INLINE void fiat_25519_carry_mul(fiat_25519_tight_field_element out1, const fiat_25519_loose_field_element arg1, const fiat_25519_loose_field_element arg2) {
  134|  1.45k|  fiat_25519_uint128 x1;
  135|  1.45k|  fiat_25519_uint128 x2;
  136|  1.45k|  fiat_25519_uint128 x3;
  137|  1.45k|  fiat_25519_uint128 x4;
  138|  1.45k|  fiat_25519_uint128 x5;
  139|  1.45k|  fiat_25519_uint128 x6;
  140|  1.45k|  fiat_25519_uint128 x7;
  141|  1.45k|  fiat_25519_uint128 x8;
  142|  1.45k|  fiat_25519_uint128 x9;
  143|  1.45k|  fiat_25519_uint128 x10;
  144|  1.45k|  fiat_25519_uint128 x11;
  145|  1.45k|  fiat_25519_uint128 x12;
  146|  1.45k|  fiat_25519_uint128 x13;
  147|  1.45k|  fiat_25519_uint128 x14;
  148|  1.45k|  fiat_25519_uint128 x15;
  149|  1.45k|  fiat_25519_uint128 x16;
  150|  1.45k|  fiat_25519_uint128 x17;
  151|  1.45k|  fiat_25519_uint128 x18;
  152|  1.45k|  fiat_25519_uint128 x19;
  153|  1.45k|  fiat_25519_uint128 x20;
  154|  1.45k|  fiat_25519_uint128 x21;
  155|  1.45k|  fiat_25519_uint128 x22;
  156|  1.45k|  fiat_25519_uint128 x23;
  157|  1.45k|  fiat_25519_uint128 x24;
  158|  1.45k|  fiat_25519_uint128 x25;
  159|  1.45k|  fiat_25519_uint128 x26;
  160|  1.45k|  uint64_t x27;
  161|  1.45k|  uint64_t x28;
  162|  1.45k|  fiat_25519_uint128 x29;
  163|  1.45k|  fiat_25519_uint128 x30;
  164|  1.45k|  fiat_25519_uint128 x31;
  165|  1.45k|  fiat_25519_uint128 x32;
  166|  1.45k|  fiat_25519_uint128 x33;
  167|  1.45k|  uint64_t x34;
  168|  1.45k|  uint64_t x35;
  169|  1.45k|  fiat_25519_uint128 x36;
  170|  1.45k|  uint64_t x37;
  171|  1.45k|  uint64_t x38;
  172|  1.45k|  fiat_25519_uint128 x39;
  173|  1.45k|  uint64_t x40;
  174|  1.45k|  uint64_t x41;
  175|  1.45k|  fiat_25519_uint128 x42;
  176|  1.45k|  uint64_t x43;
  177|  1.45k|  uint64_t x44;
  178|  1.45k|  uint64_t x45;
  179|  1.45k|  uint64_t x46;
  180|  1.45k|  uint64_t x47;
  181|  1.45k|  uint64_t x48;
  182|  1.45k|  uint64_t x49;
  183|  1.45k|  fiat_25519_uint1 x50;
  184|  1.45k|  uint64_t x51;
  185|  1.45k|  uint64_t x52;
  186|  1.45k|  x1 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[4]) * UINT8_C(0x13)));
  187|  1.45k|  x2 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[3]) * UINT8_C(0x13)));
  188|  1.45k|  x3 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[2]) * UINT8_C(0x13)));
  189|  1.45k|  x4 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[1]) * UINT8_C(0x13)));
  190|  1.45k|  x5 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[4]) * UINT8_C(0x13)));
  191|  1.45k|  x6 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[3]) * UINT8_C(0x13)));
  192|  1.45k|  x7 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[2]) * UINT8_C(0x13)));
  193|  1.45k|  x8 = ((fiat_25519_uint128)(arg1[2]) * ((arg2[4]) * UINT8_C(0x13)));
  194|  1.45k|  x9 = ((fiat_25519_uint128)(arg1[2]) * ((arg2[3]) * UINT8_C(0x13)));
  195|  1.45k|  x10 = ((fiat_25519_uint128)(arg1[1]) * ((arg2[4]) * UINT8_C(0x13)));
  196|  1.45k|  x11 = ((fiat_25519_uint128)(arg1[4]) * (arg2[0]));
  197|  1.45k|  x12 = ((fiat_25519_uint128)(arg1[3]) * (arg2[1]));
  198|  1.45k|  x13 = ((fiat_25519_uint128)(arg1[3]) * (arg2[0]));
  199|  1.45k|  x14 = ((fiat_25519_uint128)(arg1[2]) * (arg2[2]));
  200|  1.45k|  x15 = ((fiat_25519_uint128)(arg1[2]) * (arg2[1]));
  201|  1.45k|  x16 = ((fiat_25519_uint128)(arg1[2]) * (arg2[0]));
  202|  1.45k|  x17 = ((fiat_25519_uint128)(arg1[1]) * (arg2[3]));
  203|  1.45k|  x18 = ((fiat_25519_uint128)(arg1[1]) * (arg2[2]));
  204|  1.45k|  x19 = ((fiat_25519_uint128)(arg1[1]) * (arg2[1]));
  205|  1.45k|  x20 = ((fiat_25519_uint128)(arg1[1]) * (arg2[0]));
  206|  1.45k|  x21 = ((fiat_25519_uint128)(arg1[0]) * (arg2[4]));
  207|  1.45k|  x22 = ((fiat_25519_uint128)(arg1[0]) * (arg2[3]));
  208|  1.45k|  x23 = ((fiat_25519_uint128)(arg1[0]) * (arg2[2]));
  209|  1.45k|  x24 = ((fiat_25519_uint128)(arg1[0]) * (arg2[1]));
  210|  1.45k|  x25 = ((fiat_25519_uint128)(arg1[0]) * (arg2[0]));
  211|  1.45k|  x26 = (x25 + (x10 + (x9 + (x7 + x4))));
  212|  1.45k|  x27 = (uint64_t)(x26 >> 51);
  213|  1.45k|  x28 = (uint64_t)(x26 & UINT64_C(0x7ffffffffffff));
  214|  1.45k|  x29 = (x21 + (x17 + (x14 + (x12 + x11))));
  215|  1.45k|  x30 = (x22 + (x18 + (x15 + (x13 + x1))));
  216|  1.45k|  x31 = (x23 + (x19 + (x16 + (x5 + x2))));
  217|  1.45k|  x32 = (x24 + (x20 + (x8 + (x6 + x3))));
  218|  1.45k|  x33 = (x27 + x32);
  219|  1.45k|  x34 = (uint64_t)(x33 >> 51);
  220|  1.45k|  x35 = (uint64_t)(x33 & UINT64_C(0x7ffffffffffff));
  221|  1.45k|  x36 = (x34 + x31);
  222|  1.45k|  x37 = (uint64_t)(x36 >> 51);
  223|  1.45k|  x38 = (uint64_t)(x36 & UINT64_C(0x7ffffffffffff));
  224|  1.45k|  x39 = (x37 + x30);
  225|  1.45k|  x40 = (uint64_t)(x39 >> 51);
  226|  1.45k|  x41 = (uint64_t)(x39 & UINT64_C(0x7ffffffffffff));
  227|  1.45k|  x42 = (x40 + x29);
  228|  1.45k|  x43 = (uint64_t)(x42 >> 51);
  229|  1.45k|  x44 = (uint64_t)(x42 & UINT64_C(0x7ffffffffffff));
  230|  1.45k|  x45 = (x43 * UINT8_C(0x13));
  231|  1.45k|  x46 = (x28 + x45);
  232|  1.45k|  x47 = (x46 >> 51);
  233|  1.45k|  x48 = (x46 & UINT64_C(0x7ffffffffffff));
  234|  1.45k|  x49 = (x47 + x35);
  235|  1.45k|  x50 = (fiat_25519_uint1)(x49 >> 51);
  236|  1.45k|  x51 = (x49 & UINT64_C(0x7ffffffffffff));
  237|  1.45k|  x52 = (x50 + x38);
  238|  1.45k|  out1[0] = x48;
  239|  1.45k|  out1[1] = x51;
  240|  1.45k|  out1[2] = x52;
  241|  1.45k|  out1[3] = x41;
  242|  1.45k|  out1[4] = x44;
  243|  1.45k|}
curve25519.c:fiat_25519_to_bytes:
  514|    197|static FIAT_25519_FIAT_INLINE void fiat_25519_to_bytes(uint8_t out1[32], const fiat_25519_tight_field_element arg1) {
  515|    197|  uint64_t x1;
  516|    197|  fiat_25519_uint1 x2;
  517|    197|  uint64_t x3;
  518|    197|  fiat_25519_uint1 x4;
  519|    197|  uint64_t x5;
  520|    197|  fiat_25519_uint1 x6;
  521|    197|  uint64_t x7;
  522|    197|  fiat_25519_uint1 x8;
  523|    197|  uint64_t x9;
  524|    197|  fiat_25519_uint1 x10;
  525|    197|  uint64_t x11;
  526|    197|  uint64_t x12;
  527|    197|  fiat_25519_uint1 x13;
  528|    197|  uint64_t x14;
  529|    197|  fiat_25519_uint1 x15;
  530|    197|  uint64_t x16;
  531|    197|  fiat_25519_uint1 x17;
  532|    197|  uint64_t x18;
  533|    197|  fiat_25519_uint1 x19;
  534|    197|  uint64_t x20;
  535|    197|  fiat_25519_uint1 x21;
  536|    197|  uint64_t x22;
  537|    197|  uint64_t x23;
  538|    197|  uint64_t x24;
  539|    197|  uint64_t x25;
  540|    197|  uint8_t x26;
  541|    197|  uint64_t x27;
  542|    197|  uint8_t x28;
  543|    197|  uint64_t x29;
  544|    197|  uint8_t x30;
  545|    197|  uint64_t x31;
  546|    197|  uint8_t x32;
  547|    197|  uint64_t x33;
  548|    197|  uint8_t x34;
  549|    197|  uint64_t x35;
  550|    197|  uint8_t x36;
  551|    197|  uint8_t x37;
  552|    197|  uint64_t x38;
  553|    197|  uint8_t x39;
  554|    197|  uint64_t x40;
  555|    197|  uint8_t x41;
  556|    197|  uint64_t x42;
  557|    197|  uint8_t x43;
  558|    197|  uint64_t x44;
  559|    197|  uint8_t x45;
  560|    197|  uint64_t x46;
  561|    197|  uint8_t x47;
  562|    197|  uint64_t x48;
  563|    197|  uint8_t x49;
  564|    197|  uint8_t x50;
  565|    197|  uint64_t x51;
  566|    197|  uint8_t x52;
  567|    197|  uint64_t x53;
  568|    197|  uint8_t x54;
  569|    197|  uint64_t x55;
  570|    197|  uint8_t x56;
  571|    197|  uint64_t x57;
  572|    197|  uint8_t x58;
  573|    197|  uint64_t x59;
  574|    197|  uint8_t x60;
  575|    197|  uint64_t x61;
  576|    197|  uint8_t x62;
  577|    197|  uint64_t x63;
  578|    197|  uint8_t x64;
  579|    197|  fiat_25519_uint1 x65;
  580|    197|  uint64_t x66;
  581|    197|  uint8_t x67;
  582|    197|  uint64_t x68;
  583|    197|  uint8_t x69;
  584|    197|  uint64_t x70;
  585|    197|  uint8_t x71;
  586|    197|  uint64_t x72;
  587|    197|  uint8_t x73;
  588|    197|  uint64_t x74;
  589|    197|  uint8_t x75;
  590|    197|  uint64_t x76;
  591|    197|  uint8_t x77;
  592|    197|  uint8_t x78;
  593|    197|  uint64_t x79;
  594|    197|  uint8_t x80;
  595|    197|  uint64_t x81;
  596|    197|  uint8_t x82;
  597|    197|  uint64_t x83;
  598|    197|  uint8_t x84;
  599|    197|  uint64_t x85;
  600|    197|  uint8_t x86;
  601|    197|  uint64_t x87;
  602|    197|  uint8_t x88;
  603|    197|  uint64_t x89;
  604|    197|  uint8_t x90;
  605|    197|  uint8_t x91;
  606|    197|  fiat_25519_subborrowx_u51(&x1, &x2, 0x0, (arg1[0]), UINT64_C(0x7ffffffffffed));
  607|    197|  fiat_25519_subborrowx_u51(&x3, &x4, x2, (arg1[1]), UINT64_C(0x7ffffffffffff));
  608|    197|  fiat_25519_subborrowx_u51(&x5, &x6, x4, (arg1[2]), UINT64_C(0x7ffffffffffff));
  609|    197|  fiat_25519_subborrowx_u51(&x7, &x8, x6, (arg1[3]), UINT64_C(0x7ffffffffffff));
  610|    197|  fiat_25519_subborrowx_u51(&x9, &x10, x8, (arg1[4]), UINT64_C(0x7ffffffffffff));
  611|    197|  fiat_25519_cmovznz_u64(&x11, x10, 0x0, UINT64_C(0xffffffffffffffff));
  612|    197|  fiat_25519_addcarryx_u51(&x12, &x13, 0x0, x1, (x11 & UINT64_C(0x7ffffffffffed)));
  613|    197|  fiat_25519_addcarryx_u51(&x14, &x15, x13, x3, (x11 & UINT64_C(0x7ffffffffffff)));
  614|    197|  fiat_25519_addcarryx_u51(&x16, &x17, x15, x5, (x11 & UINT64_C(0x7ffffffffffff)));
  615|    197|  fiat_25519_addcarryx_u51(&x18, &x19, x17, x7, (x11 & UINT64_C(0x7ffffffffffff)));
  616|    197|  fiat_25519_addcarryx_u51(&x20, &x21, x19, x9, (x11 & UINT64_C(0x7ffffffffffff)));
  617|    197|  x22 = (x20 << 4);
  618|    197|  x23 = (x18 * (uint64_t)0x2);
  619|    197|  x24 = (x16 << 6);
  620|    197|  x25 = (x14 << 3);
  621|    197|  x26 = (uint8_t)(x12 & UINT8_C(0xff));
  622|    197|  x27 = (x12 >> 8);
  623|    197|  x28 = (uint8_t)(x27 & UINT8_C(0xff));
  624|    197|  x29 = (x27 >> 8);
  625|    197|  x30 = (uint8_t)(x29 & UINT8_C(0xff));
  626|    197|  x31 = (x29 >> 8);
  627|    197|  x32 = (uint8_t)(x31 & UINT8_C(0xff));
  628|    197|  x33 = (x31 >> 8);
  629|    197|  x34 = (uint8_t)(x33 & UINT8_C(0xff));
  630|    197|  x35 = (x33 >> 8);
  631|    197|  x36 = (uint8_t)(x35 & UINT8_C(0xff));
  632|    197|  x37 = (uint8_t)(x35 >> 8);
  633|    197|  x38 = (x25 + (uint64_t)x37);
  634|    197|  x39 = (uint8_t)(x38 & UINT8_C(0xff));
  635|    197|  x40 = (x38 >> 8);
  636|    197|  x41 = (uint8_t)(x40 & UINT8_C(0xff));
  637|    197|  x42 = (x40 >> 8);
  638|    197|  x43 = (uint8_t)(x42 & UINT8_C(0xff));
  639|    197|  x44 = (x42 >> 8);
  640|    197|  x45 = (uint8_t)(x44 & UINT8_C(0xff));
  641|    197|  x46 = (x44 >> 8);
  642|    197|  x47 = (uint8_t)(x46 & UINT8_C(0xff));
  643|    197|  x48 = (x46 >> 8);
  644|    197|  x49 = (uint8_t)(x48 & UINT8_C(0xff));
  645|    197|  x50 = (uint8_t)(x48 >> 8);
  646|    197|  x51 = (x24 + (uint64_t)x50);
  647|    197|  x52 = (uint8_t)(x51 & UINT8_C(0xff));
  648|    197|  x53 = (x51 >> 8);
  649|    197|  x54 = (uint8_t)(x53 & UINT8_C(0xff));
  650|    197|  x55 = (x53 >> 8);
  651|    197|  x56 = (uint8_t)(x55 & UINT8_C(0xff));
  652|    197|  x57 = (x55 >> 8);
  653|    197|  x58 = (uint8_t)(x57 & UINT8_C(0xff));
  654|    197|  x59 = (x57 >> 8);
  655|    197|  x60 = (uint8_t)(x59 & UINT8_C(0xff));
  656|    197|  x61 = (x59 >> 8);
  657|    197|  x62 = (uint8_t)(x61 & UINT8_C(0xff));
  658|    197|  x63 = (x61 >> 8);
  659|    197|  x64 = (uint8_t)(x63 & UINT8_C(0xff));
  660|    197|  x65 = (fiat_25519_uint1)(x63 >> 8);
  661|    197|  x66 = (x23 + (uint64_t)x65);
  662|    197|  x67 = (uint8_t)(x66 & UINT8_C(0xff));
  663|    197|  x68 = (x66 >> 8);
  664|    197|  x69 = (uint8_t)(x68 & UINT8_C(0xff));
  665|    197|  x70 = (x68 >> 8);
  666|    197|  x71 = (uint8_t)(x70 & UINT8_C(0xff));
  667|    197|  x72 = (x70 >> 8);
  668|    197|  x73 = (uint8_t)(x72 & UINT8_C(0xff));
  669|    197|  x74 = (x72 >> 8);
  670|    197|  x75 = (uint8_t)(x74 & UINT8_C(0xff));
  671|    197|  x76 = (x74 >> 8);
  672|    197|  x77 = (uint8_t)(x76 & UINT8_C(0xff));
  673|    197|  x78 = (uint8_t)(x76 >> 8);
  674|    197|  x79 = (x22 + (uint64_t)x78);
  675|    197|  x80 = (uint8_t)(x79 & UINT8_C(0xff));
  676|    197|  x81 = (x79 >> 8);
  677|    197|  x82 = (uint8_t)(x81 & UINT8_C(0xff));
  678|    197|  x83 = (x81 >> 8);
  679|    197|  x84 = (uint8_t)(x83 & UINT8_C(0xff));
  680|    197|  x85 = (x83 >> 8);
  681|    197|  x86 = (uint8_t)(x85 & UINT8_C(0xff));
  682|    197|  x87 = (x85 >> 8);
  683|    197|  x88 = (uint8_t)(x87 & UINT8_C(0xff));
  684|    197|  x89 = (x87 >> 8);
  685|    197|  x90 = (uint8_t)(x89 & UINT8_C(0xff));
  686|    197|  x91 = (uint8_t)(x89 >> 8);
  687|    197|  out1[0] = x26;
  688|    197|  out1[1] = x28;
  689|    197|  out1[2] = x30;
  690|    197|  out1[3] = x32;
  691|    197|  out1[4] = x34;
  692|    197|  out1[5] = x36;
  693|    197|  out1[6] = x39;
  694|    197|  out1[7] = x41;
  695|    197|  out1[8] = x43;
  696|    197|  out1[9] = x45;
  697|    197|  out1[10] = x47;
  698|    197|  out1[11] = x49;
  699|    197|  out1[12] = x52;
  700|    197|  out1[13] = x54;
  701|    197|  out1[14] = x56;
  702|    197|  out1[15] = x58;
  703|    197|  out1[16] = x60;
  704|    197|  out1[17] = x62;
  705|    197|  out1[18] = x64;
  706|    197|  out1[19] = x67;
  707|    197|  out1[20] = x69;
  708|    197|  out1[21] = x71;
  709|    197|  out1[22] = x73;
  710|    197|  out1[23] = x75;
  711|    197|  out1[24] = x77;
  712|    197|  out1[25] = x80;
  713|    197|  out1[26] = x82;
  714|    197|  out1[27] = x84;
  715|    197|  out1[28] = x86;
  716|    197|  out1[29] = x88;
  717|    197|  out1[30] = x90;
  718|    197|  out1[31] = x91;
  719|    197|}
curve25519.c:fiat_25519_subborrowx_u51:
   92|    985|static FIAT_25519_FIAT_INLINE void fiat_25519_subborrowx_u51(uint64_t* out1, fiat_25519_uint1* out2, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   93|    985|  int64_t x1;
   94|    985|  fiat_25519_int1 x2;
   95|    985|  uint64_t x3;
   96|    985|  x1 = ((int64_t)(arg2 - (int64_t)arg1) - (int64_t)arg3);
   97|    985|  x2 = (fiat_25519_int1)(x1 >> 51);
   98|    985|  x3 = (x1 & UINT64_C(0x7ffffffffffff));
   99|    985|  *out1 = x3;
  100|    985|  *out2 = (fiat_25519_uint1)(0x0 - x2);
  101|    985|}
curve25519.c:fiat_25519_cmovznz_u64:
  116|    197|static FIAT_25519_FIAT_INLINE void fiat_25519_cmovznz_u64(uint64_t* out1, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  117|    197|  fiat_25519_uint1 x1;
  118|    197|  uint64_t x2;
  119|    197|  uint64_t x3;
  120|    197|  x1 = (!(!arg1));
  121|    197|  x2 = ((fiat_25519_int1)(0x0 - x1) & UINT64_C(0xffffffffffffffff));
  122|    197|  x3 = ((fiat_25519_value_barrier_u64(x2) & arg3) | (fiat_25519_value_barrier_u64((~x2)) & arg2));
  123|    197|  *out1 = x3;
  124|    197|}
curve25519.c:fiat_25519_value_barrier_u64:
   42|    394|static __inline__ uint64_t fiat_25519_value_barrier_u64(uint64_t a) {
   43|    394|  __asm__("" : "+r"(a) : /* no inputs */);
   44|    394|  return a;
   45|    394|}
curve25519.c:fiat_25519_addcarryx_u51:
   66|    985|static FIAT_25519_FIAT_INLINE void fiat_25519_addcarryx_u51(uint64_t* out1, fiat_25519_uint1* out2, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   67|    985|  uint64_t x1;
   68|    985|  uint64_t x2;
   69|    985|  fiat_25519_uint1 x3;
   70|    985|  x1 = ((arg1 + arg2) + arg3);
   71|    985|  x2 = (x1 & UINT64_C(0x7ffffffffffff));
   72|    985|  x3 = (fiat_25519_uint1)(x1 >> 51);
   73|    985|  *out1 = x2;
   74|    985|  *out2 = x3;
   75|    985|}
curve25519.c:fiat_25519_carry_square:
  252|  28.9k|static FIAT_25519_FIAT_INLINE void fiat_25519_carry_square(fiat_25519_tight_field_element out1, const fiat_25519_loose_field_element arg1) {
  253|  28.9k|  uint64_t x1;
  254|  28.9k|  uint64_t x2;
  255|  28.9k|  uint64_t x3;
  256|  28.9k|  uint64_t x4;
  257|  28.9k|  uint64_t x5;
  258|  28.9k|  uint64_t x6;
  259|  28.9k|  uint64_t x7;
  260|  28.9k|  uint64_t x8;
  261|  28.9k|  fiat_25519_uint128 x9;
  262|  28.9k|  fiat_25519_uint128 x10;
  263|  28.9k|  fiat_25519_uint128 x11;
  264|  28.9k|  fiat_25519_uint128 x12;
  265|  28.9k|  fiat_25519_uint128 x13;
  266|  28.9k|  fiat_25519_uint128 x14;
  267|  28.9k|  fiat_25519_uint128 x15;
  268|  28.9k|  fiat_25519_uint128 x16;
  269|  28.9k|  fiat_25519_uint128 x17;
  270|  28.9k|  fiat_25519_uint128 x18;
  271|  28.9k|  fiat_25519_uint128 x19;
  272|  28.9k|  fiat_25519_uint128 x20;
  273|  28.9k|  fiat_25519_uint128 x21;
  274|  28.9k|  fiat_25519_uint128 x22;
  275|  28.9k|  fiat_25519_uint128 x23;
  276|  28.9k|  fiat_25519_uint128 x24;
  277|  28.9k|  uint64_t x25;
  278|  28.9k|  uint64_t x26;
  279|  28.9k|  fiat_25519_uint128 x27;
  280|  28.9k|  fiat_25519_uint128 x28;
  281|  28.9k|  fiat_25519_uint128 x29;
  282|  28.9k|  fiat_25519_uint128 x30;
  283|  28.9k|  fiat_25519_uint128 x31;
  284|  28.9k|  uint64_t x32;
  285|  28.9k|  uint64_t x33;
  286|  28.9k|  fiat_25519_uint128 x34;
  287|  28.9k|  uint64_t x35;
  288|  28.9k|  uint64_t x36;
  289|  28.9k|  fiat_25519_uint128 x37;
  290|  28.9k|  uint64_t x38;
  291|  28.9k|  uint64_t x39;
  292|  28.9k|  fiat_25519_uint128 x40;
  293|  28.9k|  uint64_t x41;
  294|  28.9k|  uint64_t x42;
  295|  28.9k|  uint64_t x43;
  296|  28.9k|  uint64_t x44;
  297|  28.9k|  uint64_t x45;
  298|  28.9k|  uint64_t x46;
  299|  28.9k|  uint64_t x47;
  300|  28.9k|  fiat_25519_uint1 x48;
  301|  28.9k|  uint64_t x49;
  302|  28.9k|  uint64_t x50;
  303|  28.9k|  x1 = ((arg1[4]) * UINT8_C(0x13));
  304|  28.9k|  x2 = (x1 * 0x2);
  305|  28.9k|  x3 = ((arg1[4]) * 0x2);
  306|  28.9k|  x4 = ((arg1[3]) * UINT8_C(0x13));
  307|  28.9k|  x5 = (x4 * 0x2);
  308|  28.9k|  x6 = ((arg1[3]) * 0x2);
  309|  28.9k|  x7 = ((arg1[2]) * 0x2);
  310|  28.9k|  x8 = ((arg1[1]) * 0x2);
  311|  28.9k|  x9 = ((fiat_25519_uint128)(arg1[4]) * x1);
  312|  28.9k|  x10 = ((fiat_25519_uint128)(arg1[3]) * x2);
  313|  28.9k|  x11 = ((fiat_25519_uint128)(arg1[3]) * x4);
  314|  28.9k|  x12 = ((fiat_25519_uint128)(arg1[2]) * x2);
  315|  28.9k|  x13 = ((fiat_25519_uint128)(arg1[2]) * x5);
  316|  28.9k|  x14 = ((fiat_25519_uint128)(arg1[2]) * (arg1[2]));
  317|  28.9k|  x15 = ((fiat_25519_uint128)(arg1[1]) * x2);
  318|  28.9k|  x16 = ((fiat_25519_uint128)(arg1[1]) * x6);
  319|  28.9k|  x17 = ((fiat_25519_uint128)(arg1[1]) * x7);
  320|  28.9k|  x18 = ((fiat_25519_uint128)(arg1[1]) * (arg1[1]));
  321|  28.9k|  x19 = ((fiat_25519_uint128)(arg1[0]) * x3);
  322|  28.9k|  x20 = ((fiat_25519_uint128)(arg1[0]) * x6);
  323|  28.9k|  x21 = ((fiat_25519_uint128)(arg1[0]) * x7);
  324|  28.9k|  x22 = ((fiat_25519_uint128)(arg1[0]) * x8);
  325|  28.9k|  x23 = ((fiat_25519_uint128)(arg1[0]) * (arg1[0]));
  326|  28.9k|  x24 = (x23 + (x15 + x13));
  327|  28.9k|  x25 = (uint64_t)(x24 >> 51);
  328|  28.9k|  x26 = (uint64_t)(x24 & UINT64_C(0x7ffffffffffff));
  329|  28.9k|  x27 = (x19 + (x16 + x14));
  330|  28.9k|  x28 = (x20 + (x17 + x9));
  331|  28.9k|  x29 = (x21 + (x18 + x10));
  332|  28.9k|  x30 = (x22 + (x12 + x11));
  333|  28.9k|  x31 = (x25 + x30);
  334|  28.9k|  x32 = (uint64_t)(x31 >> 51);
  335|  28.9k|  x33 = (uint64_t)(x31 & UINT64_C(0x7ffffffffffff));
  336|  28.9k|  x34 = (x32 + x29);
  337|  28.9k|  x35 = (uint64_t)(x34 >> 51);
  338|  28.9k|  x36 = (uint64_t)(x34 & UINT64_C(0x7ffffffffffff));
  339|  28.9k|  x37 = (x35 + x28);
  340|  28.9k|  x38 = (uint64_t)(x37 >> 51);
  341|  28.9k|  x39 = (uint64_t)(x37 & UINT64_C(0x7ffffffffffff));
  342|  28.9k|  x40 = (x38 + x27);
  343|  28.9k|  x41 = (uint64_t)(x40 >> 51);
  344|  28.9k|  x42 = (uint64_t)(x40 & UINT64_C(0x7ffffffffffff));
  345|  28.9k|  x43 = (x41 * UINT8_C(0x13));
  346|  28.9k|  x44 = (x26 + x43);
  347|  28.9k|  x45 = (x44 >> 51);
  348|  28.9k|  x46 = (x44 & UINT64_C(0x7ffffffffffff));
  349|  28.9k|  x47 = (x45 + x33);
  350|  28.9k|  x48 = (fiat_25519_uint1)(x47 >> 51);
  351|  28.9k|  x49 = (x47 & UINT64_C(0x7ffffffffffff));
  352|  28.9k|  x50 = (x48 + x36);
  353|  28.9k|  out1[0] = x46;
  354|  28.9k|  out1[1] = x49;
  355|  28.9k|  out1[2] = x50;
  356|  28.9k|  out1[3] = x39;
  357|  28.9k|  out1[4] = x42;
  358|  28.9k|}
curve25519.c:fiat_25519_sub:
  431|     31|static FIAT_25519_FIAT_INLINE void fiat_25519_sub(fiat_25519_loose_field_element out1, const fiat_25519_tight_field_element arg1, const fiat_25519_tight_field_element arg2) {
  432|     31|  uint64_t x1;
  433|     31|  uint64_t x2;
  434|     31|  uint64_t x3;
  435|     31|  uint64_t x4;
  436|     31|  uint64_t x5;
  437|     31|  x1 = ((UINT64_C(0xfffffffffffda) + (arg1[0])) - (arg2[0]));
  438|     31|  x2 = ((UINT64_C(0xffffffffffffe) + (arg1[1])) - (arg2[1]));
  439|     31|  x3 = ((UINT64_C(0xffffffffffffe) + (arg1[2])) - (arg2[2]));
  440|     31|  x4 = ((UINT64_C(0xffffffffffffe) + (arg1[3])) - (arg2[3]));
  441|     31|  x5 = ((UINT64_C(0xffffffffffffe) + (arg1[4])) - (arg2[4]));
  442|     31|  out1[0] = x1;
  443|     31|  out1[1] = x2;
  444|     31|  out1[2] = x3;
  445|     31|  out1[3] = x4;
  446|     31|  out1[4] = x5;
  447|     31|}
curve25519.c:fiat_25519_add:
  406|     31|static FIAT_25519_FIAT_INLINE void fiat_25519_add(fiat_25519_loose_field_element out1, const fiat_25519_tight_field_element arg1, const fiat_25519_tight_field_element arg2) {
  407|     31|  uint64_t x1;
  408|     31|  uint64_t x2;
  409|     31|  uint64_t x3;
  410|     31|  uint64_t x4;
  411|     31|  uint64_t x5;
  412|     31|  x1 = ((arg1[0]) + (arg2[0]));
  413|     31|  x2 = ((arg1[1]) + (arg2[1]));
  414|     31|  x3 = ((arg1[2]) + (arg2[2]));
  415|     31|  x4 = ((arg1[3]) + (arg2[3]));
  416|     31|  x5 = ((arg1[4]) + (arg2[4]));
  417|     31|  out1[0] = x1;
  418|     31|  out1[1] = x2;
  419|     31|  out1[2] = x3;
  420|     31|  out1[3] = x4;
  421|     31|  out1[4] = x5;
  422|     31|}
curve25519.c:fiat_25519_from_bytes:
  730|    456|static FIAT_25519_FIAT_INLINE void fiat_25519_from_bytes(fiat_25519_tight_field_element out1, const uint8_t arg1[32]) {
  731|    456|  uint64_t x1;
  732|    456|  uint64_t x2;
  733|    456|  uint64_t x3;
  734|    456|  uint64_t x4;
  735|    456|  uint64_t x5;
  736|    456|  uint64_t x6;
  737|    456|  uint64_t x7;
  738|    456|  uint64_t x8;
  739|    456|  uint64_t x9;
  740|    456|  uint64_t x10;
  741|    456|  uint64_t x11;
  742|    456|  uint64_t x12;
  743|    456|  uint64_t x13;
  744|    456|  uint64_t x14;
  745|    456|  uint64_t x15;
  746|    456|  uint64_t x16;
  747|    456|  uint64_t x17;
  748|    456|  uint64_t x18;
  749|    456|  uint64_t x19;
  750|    456|  uint64_t x20;
  751|    456|  uint64_t x21;
  752|    456|  uint64_t x22;
  753|    456|  uint64_t x23;
  754|    456|  uint64_t x24;
  755|    456|  uint64_t x25;
  756|    456|  uint64_t x26;
  757|    456|  uint64_t x27;
  758|    456|  uint64_t x28;
  759|    456|  uint64_t x29;
  760|    456|  uint64_t x30;
  761|    456|  uint64_t x31;
  762|    456|  uint8_t x32;
  763|    456|  uint64_t x33;
  764|    456|  uint64_t x34;
  765|    456|  uint64_t x35;
  766|    456|  uint64_t x36;
  767|    456|  uint64_t x37;
  768|    456|  uint64_t x38;
  769|    456|  uint64_t x39;
  770|    456|  uint8_t x40;
  771|    456|  uint64_t x41;
  772|    456|  uint64_t x42;
  773|    456|  uint64_t x43;
  774|    456|  uint64_t x44;
  775|    456|  uint64_t x45;
  776|    456|  uint64_t x46;
  777|    456|  uint64_t x47;
  778|    456|  uint8_t x48;
  779|    456|  uint64_t x49;
  780|    456|  uint64_t x50;
  781|    456|  uint64_t x51;
  782|    456|  uint64_t x52;
  783|    456|  uint64_t x53;
  784|    456|  uint64_t x54;
  785|    456|  uint64_t x55;
  786|    456|  uint64_t x56;
  787|    456|  uint8_t x57;
  788|    456|  uint64_t x58;
  789|    456|  uint64_t x59;
  790|    456|  uint64_t x60;
  791|    456|  uint64_t x61;
  792|    456|  uint64_t x62;
  793|    456|  uint64_t x63;
  794|    456|  uint64_t x64;
  795|    456|  uint8_t x65;
  796|    456|  uint64_t x66;
  797|    456|  uint64_t x67;
  798|    456|  uint64_t x68;
  799|    456|  uint64_t x69;
  800|    456|  uint64_t x70;
  801|    456|  uint64_t x71;
  802|    456|  x1 = ((uint64_t)(arg1[31]) << 44);
  803|    456|  x2 = ((uint64_t)(arg1[30]) << 36);
  804|    456|  x3 = ((uint64_t)(arg1[29]) << 28);
  805|    456|  x4 = ((uint64_t)(arg1[28]) << 20);
  806|    456|  x5 = ((uint64_t)(arg1[27]) << 12);
  807|    456|  x6 = ((uint64_t)(arg1[26]) << 4);
  808|    456|  x7 = ((uint64_t)(arg1[25]) << 47);
  809|    456|  x8 = ((uint64_t)(arg1[24]) << 39);
  810|    456|  x9 = ((uint64_t)(arg1[23]) << 31);
  811|    456|  x10 = ((uint64_t)(arg1[22]) << 23);
  812|    456|  x11 = ((uint64_t)(arg1[21]) << 15);
  813|    456|  x12 = ((uint64_t)(arg1[20]) << 7);
  814|    456|  x13 = ((uint64_t)(arg1[19]) << 50);
  815|    456|  x14 = ((uint64_t)(arg1[18]) << 42);
  816|    456|  x15 = ((uint64_t)(arg1[17]) << 34);
  817|    456|  x16 = ((uint64_t)(arg1[16]) << 26);
  818|    456|  x17 = ((uint64_t)(arg1[15]) << 18);
  819|    456|  x18 = ((uint64_t)(arg1[14]) << 10);
  820|    456|  x19 = ((uint64_t)(arg1[13]) << 2);
  821|    456|  x20 = ((uint64_t)(arg1[12]) << 45);
  822|    456|  x21 = ((uint64_t)(arg1[11]) << 37);
  823|    456|  x22 = ((uint64_t)(arg1[10]) << 29);
  824|    456|  x23 = ((uint64_t)(arg1[9]) << 21);
  825|    456|  x24 = ((uint64_t)(arg1[8]) << 13);
  826|    456|  x25 = ((uint64_t)(arg1[7]) << 5);
  827|    456|  x26 = ((uint64_t)(arg1[6]) << 48);
  828|    456|  x27 = ((uint64_t)(arg1[5]) << 40);
  829|    456|  x28 = ((uint64_t)(arg1[4]) << 32);
  830|    456|  x29 = ((uint64_t)(arg1[3]) << 24);
  831|    456|  x30 = ((uint64_t)(arg1[2]) << 16);
  832|    456|  x31 = ((uint64_t)(arg1[1]) << 8);
  833|    456|  x32 = (arg1[0]);
  834|    456|  x33 = (x31 + (uint64_t)x32);
  835|    456|  x34 = (x30 + x33);
  836|    456|  x35 = (x29 + x34);
  837|    456|  x36 = (x28 + x35);
  838|    456|  x37 = (x27 + x36);
  839|    456|  x38 = (x26 + x37);
  840|    456|  x39 = (x38 & UINT64_C(0x7ffffffffffff));
  841|    456|  x40 = (uint8_t)(x38 >> 51);
  842|    456|  x41 = (x25 + (uint64_t)x40);
  843|    456|  x42 = (x24 + x41);
  844|    456|  x43 = (x23 + x42);
  845|    456|  x44 = (x22 + x43);
  846|    456|  x45 = (x21 + x44);
  847|    456|  x46 = (x20 + x45);
  848|    456|  x47 = (x46 & UINT64_C(0x7ffffffffffff));
  849|    456|  x48 = (uint8_t)(x46 >> 51);
  850|    456|  x49 = (x19 + (uint64_t)x48);
  851|    456|  x50 = (x18 + x49);
  852|    456|  x51 = (x17 + x50);
  853|    456|  x52 = (x16 + x51);
  854|    456|  x53 = (x15 + x52);
  855|    456|  x54 = (x14 + x53);
  856|    456|  x55 = (x13 + x54);
  857|    456|  x56 = (x55 & UINT64_C(0x7ffffffffffff));
  858|    456|  x57 = (uint8_t)(x55 >> 51);
  859|    456|  x58 = (x12 + (uint64_t)x57);
  860|    456|  x59 = (x11 + x58);
  861|    456|  x60 = (x10 + x59);
  862|    456|  x61 = (x9 + x60);
  863|    456|  x62 = (x8 + x61);
  864|    456|  x63 = (x7 + x62);
  865|    456|  x64 = (x63 & UINT64_C(0x7ffffffffffff));
  866|    456|  x65 = (uint8_t)(x63 >> 51);
  867|    456|  x66 = (x6 + (uint64_t)x65);
  868|    456|  x67 = (x5 + x66);
  869|    456|  x68 = (x4 + x67);
  870|    456|  x69 = (x3 + x68);
  871|    456|  x70 = (x2 + x69);
  872|    456|  x71 = (x1 + x70);
  873|    456|  out1[0] = x39;
  874|    456|  out1[1] = x47;
  875|    456|  out1[2] = x56;
  876|    456|  out1[3] = x64;
  877|    456|  out1[4] = x71;
  878|    456|}

x25519_ge_scalarmult_base_adx:
  626|    114|void x25519_ge_scalarmult_base_adx(uint8_t h[4][32], const uint8_t a[32]) {
  627|    114|  signed char e[64];
  628|    114|  signed char carry;
  629|       |
  630|  3.76k|  for (unsigned i = 0; i < 32; ++i) {
  ------------------
  |  Branch (630:24): [True: 3.64k, False: 114]
  ------------------
  631|  3.64k|    e[2 * i + 0] = (a[i] >> 0) & 15;
  632|  3.64k|    e[2 * i + 1] = (a[i] >> 4) & 15;
  633|  3.64k|  }
  634|       |  // each e[i] is between 0 and 15
  635|       |  // e[63] is between 0 and 7
  636|       |
  637|    114|  carry = 0;
  638|  7.29k|  for (unsigned i = 0; i < 63; ++i) {
  ------------------
  |  Branch (638:24): [True: 7.18k, False: 114]
  ------------------
  639|  7.18k|    e[i] += carry;
  640|  7.18k|    carry = e[i] + 8;
  641|  7.18k|    carry >>= 4;
  642|  7.18k|    e[i] -= carry << 4;
  643|  7.18k|  }
  644|    114|  e[63] += carry;
  645|       |  // each e[i] is between -8 and 8
  646|       |
  647|    114|  ge_p3_4 r = {{0}, {1}, {1}, {0}};
  648|  3.76k|  for (unsigned i = 1; i < 64; i += 2) {
  ------------------
  |  Branch (648:24): [True: 3.64k, False: 114]
  ------------------
  649|  3.64k|    ge_precomp_4 t;
  650|  3.64k|    table_select_4(&t, i / 2, e[i]);
  651|  3.64k|    ge_p3_add_p3_precomp_4(&r, &r, &t);
  652|  3.64k|  }
  653|       |
  654|    114|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  655|    114|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  656|    114|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  657|    114|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/false);
  658|       |
  659|  3.76k|  for (unsigned i = 0; i < 64; i += 2) {
  ------------------
  |  Branch (659:24): [True: 3.64k, False: 114]
  ------------------
  660|  3.64k|    ge_precomp_4 t;
  661|  3.64k|    table_select_4(&t, i / 2, e[i]);
  662|  3.64k|    ge_p3_add_p3_precomp_4(&r, &r, &t);
  663|  3.64k|  }
  664|       |
  665|       |  // fe4 uses saturated 64-bit limbs, so converting to bytes is just a copy.
  666|       |  // Satisfy stated precondition of fiat_25519_from_bytes; tests pass either way
  667|    114|  fe4_canon(r.X, r.X);
  668|    114|  fe4_canon(r.Y, r.Y);
  669|    114|  fe4_canon(r.Z, r.Z);
  670|    114|  fe4_canon(r.T, r.T);
  671|    114|  static_assert(sizeof(ge_p3_4) == sizeof(uint8_t[4][32]), "");
  672|    114|  OPENSSL_memcpy(h, &r, sizeof(ge_p3_4));
  673|    114|}
curve25519_64_adx.c:fiat_cmovznz_u64:
  137|   125k|static inline void fiat_cmovznz_u64(uint64_t* out1, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  138|   125k|  fiat_uint1 x1;
  139|   125k|  uint64_t x2;
  140|   125k|  uint64_t x3;
  141|   125k|  x1 = (!(!arg1));
  142|   125k|  x2 = ((fiat_int1)(0x0 - x1) & UINT64_C(0xffffffffffffffff));
  143|   125k|  x3 = ((fiat_value_barrier_u64(x2) & arg3) | (fiat_value_barrier_u64((~x2)) & arg2));
  144|   125k|  *out1 = x3;
  145|   125k|}
curve25519_64_adx.c:fiat_value_barrier_u64:
   10|   251k|static __inline__ uint64_t fiat_value_barrier_u64(uint64_t a) {
   11|   251k|  __asm__("" : "+r"(a) : /* no inputs */);
   12|   251k|  return a;
   13|   251k|}
curve25519_64_adx.c:fe4_sub:
  199|  30.5k|static void fe4_sub(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
  200|  30.5k|  uint64_t x1;
  201|  30.5k|  uint64_t x2;
  202|  30.5k|  fiat_uint1 x3;
  203|  30.5k|  uint64_t x4;
  204|  30.5k|  uint64_t x5;
  205|  30.5k|  fiat_uint1 x6;
  206|  30.5k|  uint64_t x7;
  207|  30.5k|  uint64_t x8;
  208|  30.5k|  fiat_uint1 x9;
  209|  30.5k|  uint64_t x10;
  210|  30.5k|  uint64_t x11;
  211|  30.5k|  fiat_uint1 x12;
  212|  30.5k|  uint64_t x13;
  213|  30.5k|  uint64_t x14;
  214|  30.5k|  fiat_uint1 x15;
  215|  30.5k|  uint64_t x16;
  216|  30.5k|  fiat_uint1 x17;
  217|  30.5k|  uint64_t x18;
  218|  30.5k|  fiat_uint1 x19;
  219|  30.5k|  uint64_t x20;
  220|  30.5k|  fiat_uint1 x21;
  221|  30.5k|  uint64_t x22;
  222|  30.5k|  uint64_t x23;
  223|  30.5k|  fiat_uint1 x24;
  224|  30.5k|  x1 = (arg2[0]);
  225|  30.5k|  fiat_subborrowx_u64(&x2, &x3, 0x0, (arg1[0]), x1);
  226|  30.5k|  x4 = (arg2[1]);
  227|  30.5k|  fiat_subborrowx_u64(&x5, &x6, x3, (arg1[1]), x4);
  228|  30.5k|  x7 = (arg2[2]);
  229|  30.5k|  fiat_subborrowx_u64(&x8, &x9, x6, (arg1[2]), x7);
  230|  30.5k|  x10 = (arg2[3]);
  231|  30.5k|  fiat_subborrowx_u64(&x11, &x12, x9, (arg1[3]), x10);
  232|  30.5k|  fiat_cmovznz_u64(&x13, x12, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  233|  30.5k|  fiat_subborrowx_u64(&x14, &x15, 0x0, x2, x13);
  234|  30.5k|  fiat_subborrowx_u64(&x16, &x17, x15, x5, 0x0);
  235|  30.5k|  fiat_subborrowx_u64(&x18, &x19, x17, x8, 0x0);
  236|  30.5k|  fiat_subborrowx_u64(&x20, &x21, x19, x11, 0x0);
  237|  30.5k|  fiat_cmovznz_u64(&x22, x21, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  238|  30.5k|  fiat_subborrowx_u64(&x23, &x24, 0x0, x14, x22);
  239|  30.5k|  out1[0] = x23;
  240|  30.5k|  out1[1] = x16;
  241|  30.5k|  out1[2] = x18;
  242|  30.5k|  out1[3] = x20;
  243|  30.5k|}
curve25519_64_adx.c:fiat_subborrowx_u64:
  103|   278k|static inline void fiat_subborrowx_u64(uint64_t* out1, fiat_uint1* out2, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  104|   278k|#if defined(__has_builtin)
  105|   278k|#  if __has_builtin(__builtin_ia32_subborrow_u64)
  106|   278k|#    define subborrow64 __builtin_ia32_subborrow_u64
  107|   278k|#  endif
  108|   278k|#endif
  109|   278k|#if defined(subborrow64)
  110|   278k|  long long unsigned int t;
  111|   278k|  *out2 = subborrow64(arg1, arg2, arg3, &t);
  ------------------
  |  |  106|   278k|#    define subborrow64 __builtin_ia32_subborrow_u64
  ------------------
  112|   278k|  *out1 = t;
  113|       |#elif defined(_M_X64)
  114|       |  long long unsigned int t;
  115|       |  *out2 = _subborrow_u64(arg1, arg2, arg3, &t); // NOTE: edited after generation
  116|       |  *out1 = t;
  117|       |#else
  118|       |  *out1 = arg2 - arg3 - arg1;
  119|       |  *out2 = (arg2 < arg3) | ((arg2 == arg3) & arg1);
  120|       |#endif
  121|   278k|#undef subborrow64
  122|   278k|}
curve25519_64_adx.c:fe4_add:
  154|  30.5k|static void fe4_add(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
  155|  30.5k|  uint64_t x1;
  156|  30.5k|  fiat_uint1 x2;
  157|  30.5k|  uint64_t x3;
  158|  30.5k|  fiat_uint1 x4;
  159|  30.5k|  uint64_t x5;
  160|  30.5k|  fiat_uint1 x6;
  161|  30.5k|  uint64_t x7;
  162|  30.5k|  fiat_uint1 x8;
  163|  30.5k|  uint64_t x9;
  164|  30.5k|  uint64_t x10;
  165|  30.5k|  fiat_uint1 x11;
  166|  30.5k|  uint64_t x12;
  167|  30.5k|  fiat_uint1 x13;
  168|  30.5k|  uint64_t x14;
  169|  30.5k|  fiat_uint1 x15;
  170|  30.5k|  uint64_t x16;
  171|  30.5k|  fiat_uint1 x17;
  172|  30.5k|  uint64_t x18;
  173|  30.5k|  uint64_t x19;
  174|  30.5k|  fiat_uint1 x20;
  175|  30.5k|  fiat_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
  176|  30.5k|  fiat_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
  177|  30.5k|  fiat_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
  178|  30.5k|  fiat_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
  179|  30.5k|  fiat_cmovznz_u64(&x9, x8, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  180|  30.5k|  fiat_addcarryx_u64(&x10, &x11, 0x0, x1, x9);
  181|  30.5k|  fiat_addcarryx_u64(&x12, &x13, x11, x3, 0x0);
  182|  30.5k|  fiat_addcarryx_u64(&x14, &x15, x13, x5, 0x0);
  183|  30.5k|  fiat_addcarryx_u64(&x16, &x17, x15, x7, 0x0);
  184|  30.5k|  fiat_cmovznz_u64(&x18, x17, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  185|  30.5k|  fiat_addcarryx_u64(&x19, &x20, 0x0, x10, x18);
  186|  30.5k|  out1[0] = x19;
  187|  30.5k|  out1[1] = x12;
  188|  30.5k|  out1[2] = x14;
  189|  30.5k|  out1[3] = x16;
  190|  30.5k|}
curve25519_64_adx.c:fiat_addcarryx_u64:
   62|   274k|static inline void fiat_addcarryx_u64(uint64_t* out1, fiat_uint1* out2, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   63|       |// NOTE: edited after generation
   64|   274k|#if defined(__has_builtin)
   65|   274k|#  if __has_builtin(__builtin_ia32_addcarryx_u64)
   66|   274k|#    define addcarry64 __builtin_ia32_addcarryx_u64
   67|   274k|#  endif
   68|   274k|#endif
   69|   274k|#if defined(addcarry64)
   70|   274k|  long long unsigned int t;
   71|   274k|  *out2 = addcarry64(arg1, arg2, arg3, &t);
  ------------------
  |  |   66|   274k|#    define addcarry64 __builtin_ia32_addcarryx_u64
  ------------------
   72|   274k|  *out1 = t;
   73|       |#elif defined(_M_X64)
   74|       |  long long unsigned int t;
   75|       |  *out2 = _addcarry_u64(arg1, arg2, arg3, out1);
   76|       |  *out1 = t;
   77|       |#else
   78|       |  arg2 += arg1;
   79|       |  arg1 = arg2 < arg1;
   80|       |  uint64_t ret = arg2 + arg3;
   81|       |  arg1 += ret < arg2;
   82|       |  *out1 = ret;
   83|       |  *out2 = arg1;
   84|       |#endif
   85|   274k|#undef addcarry64
   86|   274k|}
curve25519_64_adx.c:fe4_mul:
   14|  52.5k|static inline void fe4_mul(fe4 out, const fe4 x, const fe4 y) { fiat_curve25519_adx_mul(out, x, y); }
curve25519_64_adx.c:fe4_sq:
   15|  1.82k|static inline void fe4_sq(fe4 out, const fe4 x) { fiat_curve25519_adx_square(out, x); }
curve25519_64_adx.c:fe4_canon:
  306|    456|static void fe4_canon(uint64_t out1[4], const uint64_t arg1[4]) {
  307|    456|  uint64_t x1;
  308|    456|  fiat_uint1 x2;
  309|    456|  uint64_t x3;
  310|    456|  fiat_uint1 x4;
  311|    456|  uint64_t x5;
  312|    456|  fiat_uint1 x6;
  313|    456|  uint64_t x7;
  314|    456|  fiat_uint1 x8;
  315|    456|  uint64_t x9;
  316|    456|  uint64_t x10;
  317|    456|  uint64_t x11;
  318|    456|  uint64_t x12;
  319|    456|  uint64_t x13;
  320|    456|  fiat_uint1 x14;
  321|    456|  uint64_t x15;
  322|    456|  fiat_uint1 x16;
  323|    456|  uint64_t x17;
  324|    456|  fiat_uint1 x18;
  325|    456|  uint64_t x19;
  326|    456|  fiat_uint1 x20;
  327|    456|  uint64_t x21;
  328|    456|  uint64_t x22;
  329|    456|  uint64_t x23;
  330|    456|  uint64_t x24;
  331|    456|  fiat_subborrowx_u64(&x1, &x2, 0x0, (arg1[0]), UINT64_C(0xffffffffffffffed));
  332|    456|  fiat_subborrowx_u64(&x3, &x4, x2, (arg1[1]), UINT64_C(0xffffffffffffffff));
  333|    456|  fiat_subborrowx_u64(&x5, &x6, x4, (arg1[2]), UINT64_C(0xffffffffffffffff));
  334|    456|  fiat_subborrowx_u64(&x7, &x8, x6, (arg1[3]), UINT64_C(0x7fffffffffffffff));
  335|    456|  fiat_cmovznz_u64(&x9, x8, x1, (arg1[0]));
  336|    456|  fiat_cmovznz_u64(&x10, x8, x3, (arg1[1]));
  337|    456|  fiat_cmovznz_u64(&x11, x8, x5, (arg1[2]));
  338|    456|  fiat_cmovznz_u64(&x12, x8, x7, (arg1[3]));
  339|    456|  fiat_subborrowx_u64(&x13, &x14, 0x0, x9, UINT64_C(0xffffffffffffffed));
  340|    456|  fiat_subborrowx_u64(&x15, &x16, x14, x10, UINT64_C(0xffffffffffffffff));
  341|    456|  fiat_subborrowx_u64(&x17, &x18, x16, x11, UINT64_C(0xffffffffffffffff));
  342|    456|  fiat_subborrowx_u64(&x19, &x20, x18, x12, UINT64_C(0x7fffffffffffffff));
  343|    456|  fiat_cmovznz_u64(&x21, x20, x13, x9);
  344|    456|  fiat_cmovznz_u64(&x22, x20, x15, x10);
  345|    456|  fiat_cmovznz_u64(&x23, x20, x17, x11);
  346|    456|  fiat_cmovznz_u64(&x24, x20, x19, x12);
  347|    456|  out1[0] = x21;
  348|    456|  out1[1] = x22;
  349|    456|  out1[2] = x23;
  350|    456|  out1[3] = x24;
  351|    456|}
curve25519_64_adx.c:table_select_4:
  590|  7.29k|                                  const signed char b) {
  591|  7.29k|  uint8_t bnegative = constant_time_msb_w(b);
  592|  7.29k|  uint8_t babs = b - ((bnegative & b) << 1);
  593|       |
  594|  7.29k|  uint8_t t_bytes[3][32] = {
  595|  7.29k|      {constant_time_is_zero_w(b) & 1}, {constant_time_is_zero_w(b) & 1}, {0}};
  596|  7.29k|#if defined(__clang__)
  597|  7.29k|  __asm__("" : "+m" (t_bytes) : /*no inputs*/);
  598|  7.29k|#endif
  599|  7.29k|  static_assert(sizeof(t_bytes) == sizeof(k25519Precomp[pos][0]), "");
  600|  65.6k|  for (int i = 0; i < 8; i++) {
  ------------------
  |  Branch (600:19): [True: 58.3k, False: 7.29k]
  ------------------
  601|  58.3k|    constant_time_conditional_memxor(t_bytes, k25519Precomp[pos][i],
  602|  58.3k|                                     sizeof(t_bytes),
  603|  58.3k|                                     constant_time_eq_w(babs, 1 + i));
  604|  58.3k|  }
  605|       |
  606|  7.29k|  static_assert(sizeof(t_bytes) == sizeof(ge_precomp_4), "");
  607|       |
  608|       |  // fe4 uses saturated 64-bit limbs, so converting from bytes is just a copy.
  609|  7.29k|  OPENSSL_memcpy(t, t_bytes, sizeof(ge_precomp_4));
  610|       |
  611|  7.29k|  fe4 xy2d_neg = {0};
  612|  7.29k|  fe4_sub(xy2d_neg, xy2d_neg, t->xy2d);
  613|  7.29k|  constant_time_conditional_memcpy(t->yplusx, t_bytes[1], sizeof(fe4),
  614|  7.29k|                                   bnegative);
  615|  7.29k|  constant_time_conditional_memcpy(t->yminusx, t_bytes[0], sizeof(fe4),
  616|  7.29k|                                   bnegative);
  617|  7.29k|  constant_time_conditional_memcpy(t->xy2d, xy2d_neg, sizeof(fe4), bnegative);
  618|  7.29k|}
curve25519_64_adx.c:ge_p3_add_p3_precomp_4:
  568|  7.29k|ge_p3_add_p3_precomp_4(ge_p3_4 *r, const ge_p3_4 *p, const ge_precomp_4 *q) {
  569|  7.29k|  fe4 A, B, C, YplusX, YminusX, D, X3, Y3, Z3, T3;
  570|       |  // Transcribed from a Coq function proven against affine coordinates.
  571|       |  // https://github.com/mit-plv/fiat-crypto/blob/a36568d1d73aff5d7accc79fd28be672882f9c17/src/Curves/Edwards/XYZT/Precomputed.v#L38-L56
  572|  7.29k|  fe4_add(YplusX, p->Y, p->X);
  573|  7.29k|  fe4_sub(YminusX, p->Y, p->X);
  574|  7.29k|  fe4_mul(A, YplusX, q->yplusx);
  575|  7.29k|  fe4_mul(B, YminusX, q->yminusx);
  576|  7.29k|  fe4_mul(C, q->xy2d, p->T);
  577|  7.29k|  fe4_add(D, p->Z, p->Z);
  578|  7.29k|  fe4_sub(X3, A, B);
  579|  7.29k|  fe4_add(Y3, A, B);
  580|  7.29k|  fe4_add(Z3, D, C);
  581|  7.29k|  fe4_sub(T3, D, C);
  582|  7.29k|  fe4_mul(r->X, X3, T3);
  583|  7.29k|  fe4_mul(r->Y, Y3, Z3);
  584|  7.29k|  fe4_mul(r->Z, Z3, T3);
  585|  7.29k|  fe4_mul(r->T, X3, Y3);
  586|  7.29k|}
curve25519_64_adx.c:inline_x25519_ge_dbl_4:
  544|    456|static void inline_x25519_ge_dbl_4(ge_p3_4 *r, const ge_p3_4 *p, bool skip_t) {
  545|       |  // Transcribed from a Coq function proven against affine coordinates.
  546|       |  // https://github.com/mit-plv/fiat-crypto/blob/9943ba9e7d8f3e1c0054b2c94a5edca46ea73ef8/src/Curves/Edwards/XYZT/Basic.v#L136-L165
  547|    456|  fe4 trX, trZ, trT, t0, cX, cY, cZ, cT;
  548|    456|  fe4_sq(trX, p->X);
  549|    456|  fe4_sq(trZ, p->Y);
  550|    456|  fe4_sq(trT, p->Z);
  551|    456|  fe4_add(trT, trT, trT);
  552|    456|  fe4_add(cY, p->X, p->Y);
  553|    456|  fe4_sq(t0, cY);
  554|    456|  fe4_add(cY, trZ, trX);
  555|    456|  fe4_sub(cZ, trZ, trX);
  556|    456|  fe4_sub(cX, t0, cY);
  557|    456|  fe4_sub(cT, trT, cZ);
  558|    456|  fe4_mul(r->X, cX, cT);
  559|    456|  fe4_mul(r->Y, cY, cZ);
  560|    456|  fe4_mul(r->Z, cZ, cT);
  561|    456|  if (!skip_t) {
  ------------------
  |  Branch (561:7): [True: 114, False: 342]
  ------------------
  562|    114|    fe4_mul(r->T, cX, cY);
  563|    114|  }
  564|    456|}

