BN_parse_asn1_unsigned:
   21|  10.2k|int BN_parse_asn1_unsigned(CBS *cbs, BIGNUM *ret) {
   22|  10.2k|  CBS child;
   23|  10.2k|  int is_negative;
   24|  10.2k|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  10.2k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (24:7): [True: 591, False: 9.69k]
  ------------------
   25|  10.2k|      !CBS_is_valid_asn1_integer(&child, &is_negative)) {
  ------------------
  |  Branch (25:7): [True: 23, False: 9.66k]
  ------------------
   26|    614|    OPENSSL_PUT_ERROR(BN, BN_R_BAD_ENCODING);
  ------------------
  |  |  441|    614|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   27|    614|    return 0;
   28|    614|  }
   29|       |
   30|  9.66k|  if (is_negative) {
  ------------------
  |  Branch (30:7): [True: 19, False: 9.64k]
  ------------------
   31|     19|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|     19|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   32|     19|    return 0;
   33|     19|  }
   34|       |
   35|  9.64k|  return BN_bin2bn(CBS_data(&child), CBS_len(&child), ret) != NULL;
   36|  9.66k|}

CBS_init:
   29|  96.0k|void CBS_init(CBS *cbs, const uint8_t *data, size_t len) {
   30|  96.0k|  cbs->data = data;
   31|  96.0k|  cbs->len = len;
   32|  96.0k|}
CBS_skip:
   45|  56.6k|int CBS_skip(CBS *cbs, size_t len) {
   46|  56.6k|  const uint8_t *dummy;
   47|  56.6k|  return cbs_get(cbs, &dummy, len);
   48|  56.6k|}
CBS_data:
   50|  34.5k|const uint8_t *CBS_data(const CBS *cbs) {
   51|  34.5k|  return cbs->data;
   52|  34.5k|}
CBS_len:
   54|   225k|size_t CBS_len(const CBS *cbs) {
   55|   225k|  return cbs->len;
   56|   225k|}
CBS_mem_equal:
   86|    886|int CBS_mem_equal(const CBS *cbs, const uint8_t *data, size_t len) {
   87|    886|  if (len != cbs->len) {
  ------------------
  |  Branch (87:7): [True: 502, False: 384]
  ------------------
   88|    502|    return 0;
   89|    502|  }
   90|    384|  return CRYPTO_memcmp(cbs->data, data, len) == 0;
   91|    886|}
CBS_get_u8:
  108|   227k|int CBS_get_u8(CBS *cbs, uint8_t *out) {
  109|   227k|  const uint8_t *v;
  110|   227k|  if (!cbs_get(cbs, &v, 1)) {
  ------------------
  |  Branch (110:7): [True: 17.3k, False: 210k]
  ------------------
  111|  17.3k|    return 0;
  112|  17.3k|  }
  113|   210k|  *out = *v;
  114|   210k|  return 1;
  115|   227k|}
CBS_get_bytes:
  181|  78.3k|int CBS_get_bytes(CBS *cbs, CBS *out, size_t len) {
  182|  78.3k|  const uint8_t *v;
  183|  78.3k|  if (!cbs_get(cbs, &v, len)) {
  ------------------
  |  Branch (183:7): [True: 517, False: 77.8k]
  ------------------
  184|    517|    return 0;
  185|    517|  }
  186|  77.8k|  CBS_init(out, v, len);
  187|  77.8k|  return 1;
  188|  78.3k|}
CBS_get_any_asn1_element:
  436|  80.3k|                                    size_t *out_header_len) {
  437|  80.3k|  return cbs_get_any_asn1_element(cbs, out, out_tag, out_header_len, NULL, NULL,
  438|  80.3k|                                  /*ber_ok=*/0);
  439|  80.3k|}
CBS_get_asn1:
  474|  60.3k|int CBS_get_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  475|  60.3k|  return cbs_get_asn1(cbs, out, tag_value, 1 /* skip header */);
  476|  60.3k|}
CBS_peek_asn1_tag:
  482|  5.85k|int CBS_peek_asn1_tag(const CBS *cbs, CBS_ASN1_TAG tag_value) {
  483|  5.85k|  CBS copy = *cbs;
  484|  5.85k|  CBS_ASN1_TAG actual_tag;
  485|  5.85k|  return parse_asn1_tag(&copy, &actual_tag) && tag_value == actual_tag;
  ------------------
  |  Branch (485:10): [True: 4.96k, False: 886]
  |  Branch (485:48): [True: 3.12k, False: 1.84k]
  ------------------
  486|  5.85k|}
CBS_get_asn1_uint64:
  488|  13.1k|int CBS_get_asn1_uint64(CBS *cbs, uint64_t *out) {
  489|  13.1k|  CBS bytes;
  490|  13.1k|  if (!CBS_get_asn1(cbs, &bytes, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  13.1k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (490:7): [True: 400, False: 12.7k]
  ------------------
  491|  13.1k|      !CBS_is_unsigned_asn1_integer(&bytes)) {
  ------------------
  |  Branch (491:7): [True: 153, False: 12.6k]
  ------------------
  492|    553|    return 0;
  493|    553|  }
  494|       |
  495|  12.6k|  *out = 0;
  496|  12.6k|  const uint8_t *data = CBS_data(&bytes);
  497|  12.6k|  size_t len = CBS_len(&bytes);
  498|  33.4k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (498:22): [True: 20.9k, False: 12.5k]
  ------------------
  499|  20.9k|    if ((*out >> 56) != 0) {
  ------------------
  |  Branch (499:9): [True: 102, False: 20.8k]
  ------------------
  500|       |      // Too large to represent as a uint64_t.
  501|    102|      return 0;
  502|    102|    }
  503|  20.8k|    *out <<= 8;
  504|  20.8k|    *out |= data[i];
  505|  20.8k|  }
  506|       |
  507|  12.5k|  return 1;
  508|  12.6k|}
CBS_get_optional_asn1:
  547|    618|int CBS_get_optional_asn1(CBS *cbs, CBS *out, int *out_present, CBS_ASN1_TAG tag) {
  548|    618|  int present = 0;
  549|       |
  550|    618|  if (CBS_peek_asn1_tag(cbs, tag)) {
  ------------------
  |  Branch (550:7): [True: 179, False: 439]
  ------------------
  551|    179|    if (!CBS_get_asn1(cbs, out, tag)) {
  ------------------
  |  Branch (551:9): [True: 6, False: 173]
  ------------------
  552|      6|      return 0;
  553|      6|    }
  554|    173|    present = 1;
  555|    173|  }
  556|       |
  557|    612|  if (out_present != NULL) {
  ------------------
  |  Branch (557:7): [True: 201, False: 411]
  ------------------
  558|    201|    *out_present = present;
  559|    201|  }
  560|       |
  561|    612|  return 1;
  562|    618|}
CBS_is_valid_asn1_integer:
  671|  23.1k|int CBS_is_valid_asn1_integer(const CBS *cbs, int *out_is_negative) {
  672|  23.1k|  CBS copy = *cbs;
  673|  23.1k|  uint8_t first_byte, second_byte;
  674|  23.1k|  if (!CBS_get_u8(&copy, &first_byte)) {
  ------------------
  |  Branch (674:7): [True: 51, False: 23.0k]
  ------------------
  675|     51|    return 0;  // INTEGERs may not be empty.
  676|     51|  }
  677|  23.0k|  if (out_is_negative != NULL) {
  ------------------
  |  Branch (677:7): [True: 23.0k, False: 0]
  ------------------
  678|  23.0k|    *out_is_negative = (first_byte & 0x80) != 0;
  679|  23.0k|  }
  680|  23.0k|  if (!CBS_get_u8(&copy, &second_byte)) {
  ------------------
  |  Branch (680:7): [True: 15.4k, False: 7.65k]
  ------------------
  681|  15.4k|    return 1;  // One byte INTEGERs are always minimal.
  682|  15.4k|  }
  683|  7.65k|  if ((first_byte == 0x00 && (second_byte & 0x80) == 0) ||
  ------------------
  |  Branch (683:8): [True: 3.38k, False: 4.26k]
  |  Branch (683:30): [True: 50, False: 3.33k]
  ------------------
  684|  7.65k|      (first_byte == 0xff && (second_byte & 0x80) != 0)) {
  ------------------
  |  Branch (684:8): [True: 78, False: 7.52k]
  |  Branch (684:30): [True: 48, False: 30]
  ------------------
  685|     98|    return 0;  // The value is minimal iff the first 9 bits are not all equal.
  686|     98|  }
  687|  7.55k|  return 1;
  688|  7.65k|}
CBS_is_unsigned_asn1_integer:
  690|  13.4k|int CBS_is_unsigned_asn1_integer(const CBS *cbs) {
  691|  13.4k|  int is_negative;
  692|  13.4k|  return CBS_is_valid_asn1_integer(cbs, &is_negative) && !is_negative;
  ------------------
  |  Branch (692:10): [True: 13.3k, False: 126]
  |  Branch (692:58): [True: 13.2k, False: 62]
  ------------------
  693|  13.4k|}
cbs.c:cbs_get:
   34|   371k|static int cbs_get(CBS *cbs, const uint8_t **p, size_t n) {
   35|   371k|  if (cbs->len < n) {
  ------------------
  |  Branch (35:7): [True: 17.8k, False: 353k]
  ------------------
   36|  17.8k|    return 0;
   37|  17.8k|  }
   38|       |
   39|   353k|  *p = cbs->data;
   40|   353k|  cbs->data += n;
   41|   353k|  cbs->len -= n;
   42|   353k|  return 1;
   43|   371k|}
cbs.c:cbs_get_u:
   93|  8.29k|static int cbs_get_u(CBS *cbs, uint64_t *out, size_t len) {
   94|  8.29k|  uint64_t result = 0;
   95|  8.29k|  const uint8_t *data;
   96|       |
   97|  8.29k|  if (!cbs_get(cbs, &data, len)) {
  ------------------
  |  Branch (97:7): [True: 22, False: 8.27k]
  ------------------
   98|     22|    return 0;
   99|     22|  }
  100|  21.7k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (100:22): [True: 13.4k, False: 8.27k]
  ------------------
  101|  13.4k|    result <<= 8;
  102|  13.4k|    result |= data[i];
  103|  13.4k|  }
  104|  8.27k|  *out = result;
  105|  8.27k|  return 1;
  106|  8.29k|}
cbs.c:cbs_get_any_asn1_element:
  322|  80.3k|                                    int *out_indefinite, int ber_ok) {
  323|  80.3k|  CBS header = *cbs;
  324|  80.3k|  CBS throwaway;
  325|       |
  326|  80.3k|  if (out == NULL) {
  ------------------
  |  Branch (326:7): [True: 19.9k, False: 60.3k]
  ------------------
  327|  19.9k|    out = &throwaway;
  328|  19.9k|  }
  329|  80.3k|  if (ber_ok) {
  ------------------
  |  Branch (329:7): [True: 0, False: 80.3k]
  ------------------
  330|      0|    *out_ber_found = 0;
  331|      0|    *out_indefinite = 0;
  332|  80.3k|  } else {
  333|  80.3k|    assert(out_ber_found == NULL);
  334|  80.3k|    assert(out_indefinite == NULL);
  335|  80.3k|  }
  336|       |
  337|  80.3k|  CBS_ASN1_TAG tag;
  338|  80.3k|  if (!parse_asn1_tag(&header, &tag)) {
  ------------------
  |  Branch (338:7): [True: 1.37k, False: 79.0k]
  ------------------
  339|  1.37k|    return 0;
  340|  1.37k|  }
  341|  79.0k|  if (out_tag != NULL) {
  ------------------
  |  Branch (341:7): [True: 59.1k, False: 19.8k]
  ------------------
  342|  59.1k|    *out_tag = tag;
  343|  59.1k|  }
  344|       |
  345|  79.0k|  uint8_t length_byte;
  346|  79.0k|  if (!CBS_get_u8(&header, &length_byte)) {
  ------------------
  |  Branch (346:7): [True: 421, False: 78.5k]
  ------------------
  347|    421|    return 0;
  348|    421|  }
  349|       |
  350|  78.5k|  size_t header_len = CBS_len(cbs) - CBS_len(&header);
  351|       |
  352|  78.5k|  size_t len;
  353|       |  // The format for the length encoding is specified in ITU-T X.690 section
  354|       |  // 8.1.3.
  355|  78.5k|  if ((length_byte & 0x80) == 0) {
  ------------------
  |  Branch (355:7): [True: 70.1k, False: 8.42k]
  ------------------
  356|       |    // Short form length.
  357|  70.1k|    len = ((size_t) length_byte) + header_len;
  358|  70.1k|    if (out_header_len != NULL) {
  ------------------
  |  Branch (358:9): [True: 51.8k, False: 18.2k]
  ------------------
  359|  51.8k|      *out_header_len = header_len;
  360|  51.8k|    }
  361|  70.1k|  } else {
  362|       |    // The high bit indicate that this is the long form, while the next 7 bits
  363|       |    // encode the number of subsequent octets used to encode the length (ITU-T
  364|       |    // X.690 clause 8.1.3.5.b).
  365|  8.42k|    const size_t num_bytes = length_byte & 0x7f;
  366|  8.42k|    uint64_t len64;
  367|       |
  368|  8.42k|    if (ber_ok && (tag & CBS_ASN1_CONSTRUCTED) != 0 && num_bytes == 0) {
  ------------------
  |  |  196|      0|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|      0|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (368:9): [True: 0, False: 8.42k]
  |  Branch (368:19): [True: 0, False: 0]
  |  Branch (368:56): [True: 0, False: 0]
  ------------------
  369|       |      // indefinite length
  370|      0|      if (out_header_len != NULL) {
  ------------------
  |  Branch (370:11): [True: 0, False: 0]
  ------------------
  371|      0|        *out_header_len = header_len;
  372|      0|      }
  373|      0|      *out_ber_found = 1;
  374|      0|      *out_indefinite = 1;
  375|      0|      return CBS_get_bytes(cbs, out, header_len);
  376|      0|    }
  377|       |
  378|       |    // ITU-T X.690 clause 8.1.3.5.c specifies that the value 0xff shall not be
  379|       |    // used as the first byte of the length. If this parser encounters that
  380|       |    // value, num_bytes will be parsed as 127, which will fail this check.
  381|  8.42k|    if (num_bytes == 0 || num_bytes > 4) {
  ------------------
  |  Branch (381:9): [True: 10, False: 8.41k]
  |  Branch (381:27): [True: 120, False: 8.29k]
  ------------------
  382|    130|      return 0;
  383|    130|    }
  384|  8.29k|    if (!cbs_get_u(&header, &len64, num_bytes)) {
  ------------------
  |  Branch (384:9): [True: 22, False: 8.27k]
  ------------------
  385|     22|      return 0;
  386|     22|    }
  387|       |    // ITU-T X.690 section 10.1 (DER length forms) requires encoding the
  388|       |    // length with the minimum number of octets. BER could, technically, have
  389|       |    // 125 superfluous zero bytes. We do not attempt to handle that and still
  390|       |    // require that the length fit in a |uint32_t| for BER.
  391|  8.27k|    if (len64 < 128) {
  ------------------
  |  Branch (391:9): [True: 56, False: 8.21k]
  ------------------
  392|       |      // Length should have used short-form encoding.
  393|     56|      if (ber_ok) {
  ------------------
  |  Branch (393:11): [True: 0, False: 56]
  ------------------
  394|      0|        *out_ber_found = 1;
  395|     56|      } else {
  396|     56|        return 0;
  397|     56|      }
  398|     56|    }
  399|  8.21k|    if ((len64 >> ((num_bytes - 1) * 8)) == 0) {
  ------------------
  |  Branch (399:9): [True: 15, False: 8.20k]
  ------------------
  400|       |      // Length should have been at least one byte shorter.
  401|     15|      if (ber_ok) {
  ------------------
  |  Branch (401:11): [True: 0, False: 15]
  ------------------
  402|      0|        *out_ber_found = 1;
  403|     15|      } else {
  404|     15|        return 0;
  405|     15|      }
  406|     15|    }
  407|  8.20k|    len = len64;
  408|  8.20k|    if (len + header_len + num_bytes < len) {
  ------------------
  |  Branch (408:9): [True: 0, False: 8.20k]
  ------------------
  409|       |      // Overflow.
  410|      0|      return 0;
  411|      0|    }
  412|  8.20k|    len += header_len + num_bytes;
  413|  8.20k|    if (out_header_len != NULL) {
  ------------------
  |  Branch (413:9): [True: 6.73k, False: 1.47k]
  ------------------
  414|  6.73k|      *out_header_len = header_len + num_bytes;
  415|  6.73k|    }
  416|  8.20k|  }
  417|       |
  418|  78.3k|  return CBS_get_bytes(cbs, out, len);
  419|  78.5k|}
cbs.c:cbs_get_asn1:
  452|  60.3k|                        int skip_header) {
  453|  60.3k|  size_t header_len;
  454|  60.3k|  CBS_ASN1_TAG tag;
  455|  60.3k|  CBS throwaway;
  456|       |
  457|  60.3k|  if (out == NULL) {
  ------------------
  |  Branch (457:7): [True: 114, False: 60.2k]
  ------------------
  458|    114|    out = &throwaway;
  459|    114|  }
  460|       |
  461|  60.3k|  if (!CBS_get_any_asn1_element(cbs, out, &tag, &header_len) ||
  ------------------
  |  Branch (461:7): [True: 2.27k, False: 58.1k]
  ------------------
  462|  60.3k|      tag != tag_value) {
  ------------------
  |  Branch (462:7): [True: 3.35k, False: 54.7k]
  ------------------
  463|  5.63k|    return 0;
  464|  5.63k|  }
  465|       |
  466|  54.7k|  if (skip_header && !CBS_skip(out, header_len)) {
  ------------------
  |  Branch (466:7): [True: 54.7k, False: 0]
  |  Branch (466:22): [True: 0, False: 54.7k]
  ------------------
  467|      0|    assert(0);
  468|      0|    return 0;
  469|      0|  }
  470|       |
  471|  54.7k|  return 1;
  472|  54.7k|}
cbs.c:parse_asn1_tag:
  281|  86.2k|static int parse_asn1_tag(CBS *cbs, CBS_ASN1_TAG *out) {
  282|  86.2k|  uint8_t tag_byte;
  283|  86.2k|  if (!CBS_get_u8(cbs, &tag_byte)) {
  ------------------
  |  Branch (283:7): [True: 676, False: 85.5k]
  ------------------
  284|    676|    return 0;
  285|    676|  }
  286|       |
  287|       |  // ITU-T X.690 section 8.1.2.3 specifies the format for identifiers with a tag
  288|       |  // number no greater than 30.
  289|       |  //
  290|       |  // If the number portion is 31 (0x1f, the largest value that fits in the
  291|       |  // allotted bits), then the tag is more than one byte long and the
  292|       |  // continuation bytes contain the tag number.
  293|  85.5k|  CBS_ASN1_TAG tag = ((CBS_ASN1_TAG)tag_byte & 0xe0) << CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  85.5k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  294|  85.5k|  CBS_ASN1_TAG tag_number = tag_byte & 0x1f;
  295|  85.5k|  if (tag_number == 0x1f) {
  ------------------
  |  Branch (295:7): [True: 2.78k, False: 82.7k]
  ------------------
  296|  2.78k|    uint64_t v;
  297|  2.78k|    if (!parse_base128_integer(cbs, &v) ||
  ------------------
  |  Branch (297:9): [True: 809, False: 1.97k]
  ------------------
  298|       |        // Check the tag number is within our supported bounds.
  299|  2.78k|        v > CBS_ASN1_TAG_NUMBER_MASK ||
  ------------------
  |  |  210|  4.76k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  1.97k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (299:9): [True: 562, False: 1.41k]
  ------------------
  300|       |        // Small tag numbers should have used low tag number form, even in BER.
  301|  2.78k|        v < 0x1f) {
  ------------------
  |  Branch (301:9): [True: 82, False: 1.33k]
  ------------------
  302|  1.45k|      return 0;
  303|  1.45k|    }
  304|  1.33k|    tag_number = (CBS_ASN1_TAG)v;
  305|  1.33k|  }
  306|       |
  307|  84.0k|  tag |= tag_number;
  308|       |
  309|       |  // Tag [UNIVERSAL 0] is reserved for use by the encoding. Reject it here to
  310|       |  // avoid some ambiguity around ANY values and BER indefinite-length EOCs. See
  311|       |  // https://crbug.com/boringssl/455.
  312|  84.0k|  if ((tag & ~CBS_ASN1_CONSTRUCTED) == 0) {
  ------------------
  |  |  196|  84.0k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  84.0k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (312:7): [True: 130, False: 83.9k]
  ------------------
  313|    130|    return 0;
  314|    130|  }
  315|       |
  316|  83.9k|  *out = tag;
  317|  83.9k|  return 1;
  318|  84.0k|}
cbs.c:parse_base128_integer:
  257|  2.78k|static int parse_base128_integer(CBS *cbs, uint64_t *out) {
  258|  2.78k|  uint64_t v = 0;
  259|  2.78k|  uint8_t b;
  260|  15.5k|  do {
  261|  15.5k|    if (!CBS_get_u8(cbs, &b)) {
  ------------------
  |  Branch (261:9): [True: 754, False: 14.7k]
  ------------------
  262|    754|      return 0;
  263|    754|    }
  264|  14.7k|    if ((v >> (64 - 7)) != 0) {
  ------------------
  |  Branch (264:9): [True: 32, False: 14.7k]
  ------------------
  265|       |      // The value is too large.
  266|     32|      return 0;
  267|     32|    }
  268|  14.7k|    if (v == 0 && b == 0x80) {
  ------------------
  |  Branch (268:9): [True: 2.76k, False: 11.9k]
  |  Branch (268:19): [True: 23, False: 2.73k]
  ------------------
  269|       |      // The value must be minimally encoded.
  270|     23|      return 0;
  271|     23|    }
  272|  14.6k|    v = (v << 7) | (b & 0x7f);
  273|       |
  274|       |    // Values end at an octet with the high bit cleared.
  275|  14.6k|  } while (b & 0x80);
  ------------------
  |  Branch (275:12): [True: 12.7k, False: 1.97k]
  ------------------
  276|       |
  277|  1.97k|  *out = v;
  278|  1.97k|  return 1;
  279|  2.78k|}

OPENSSL_cpuid_setup:
  153|      2|void OPENSSL_cpuid_setup(void) {
  154|       |  // Determine the vendor and maximum input value.
  155|      2|  uint32_t eax, ebx, ecx, edx;
  156|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 0);
  157|       |
  158|      2|  uint32_t num_ids = eax;
  159|       |
  160|      2|  int is_intel = ebx == 0x756e6547 /* Genu */ &&
  ------------------
  |  Branch (160:18): [True: 2, False: 0]
  ------------------
  161|      2|                 edx == 0x49656e69 /* ineI */ &&
  ------------------
  |  Branch (161:18): [True: 2, False: 0]
  ------------------
  162|      2|                 ecx == 0x6c65746e /* ntel */;
  ------------------
  |  Branch (162:18): [True: 2, False: 0]
  ------------------
  163|      2|  int is_amd = ebx == 0x68747541 /* Auth */ &&
  ------------------
  |  Branch (163:16): [True: 0, False: 2]
  ------------------
  164|      2|               edx == 0x69746e65 /* enti */ &&
  ------------------
  |  Branch (164:16): [True: 0, False: 0]
  ------------------
  165|      2|               ecx == 0x444d4163 /* cAMD */;
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|       |
  167|      2|  uint32_t extended_features[2] = {0};
  168|      2|  if (num_ids >= 7) {
  ------------------
  |  Branch (168:7): [True: 2, False: 0]
  ------------------
  169|      2|    OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 7);
  170|      2|    extended_features[0] = ebx;
  171|      2|    extended_features[1] = ecx;
  172|      2|  }
  173|       |
  174|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 1);
  175|       |
  176|      2|  if (is_amd) {
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|       |    // See https://www.amd.com/system/files/TechDocs/25481.pdf, page 10.
  178|      0|    const uint32_t base_family = (eax >> 8) & 15;
  179|      0|    const uint32_t base_model = (eax >> 4) & 15;
  180|       |
  181|      0|    uint32_t family = base_family;
  182|      0|    uint32_t model = base_model;
  183|      0|    if (base_family == 0xf) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      const uint32_t ext_family = (eax >> 20) & 255;
  185|      0|      family += ext_family;
  186|      0|      const uint32_t ext_model = (eax >> 16) & 15;
  187|      0|      model |= ext_model << 4;
  188|      0|    }
  189|       |
  190|      0|    if (family < 0x17 || (family == 0x17 && 0x70 <= model && model <= 0x7f)) {
  ------------------
  |  Branch (190:9): [True: 0, False: 0]
  |  Branch (190:27): [True: 0, False: 0]
  |  Branch (190:45): [True: 0, False: 0]
  |  Branch (190:62): [True: 0, False: 0]
  ------------------
  191|       |      // Disable RDRAND on AMD families before 0x17 (Zen) due to reported
  192|       |      // failures after suspend.
  193|       |      // https://bugzilla.redhat.com/show_bug.cgi?id=1150286
  194|       |      // Also disable for family 0x17, models 0x70–0x7f, due to possible RDRAND
  195|       |      // failures there too.
  196|      0|      ecx &= ~(1u << 30);
  197|      0|    }
  198|      0|  }
  199|       |
  200|       |  // Force the hyper-threading bit so that the more conservative path is always
  201|       |  // chosen.
  202|      2|  edx |= 1u << 28;
  203|       |
  204|       |  // Reserved bit #20 was historically repurposed to control the in-memory
  205|       |  // representation of RC4 state. Always set it to zero.
  206|      2|  edx &= ~(1u << 20);
  207|       |
  208|       |  // Reserved bit #30 is repurposed to signal an Intel CPU.
  209|      2|  if (is_intel) {
  ------------------
  |  Branch (209:7): [True: 2, False: 0]
  ------------------
  210|      2|    edx |= (1u << 30);
  211|       |
  212|       |    // Clear the XSAVE bit on Knights Landing to mimic Silvermont. This enables
  213|       |    // some Silvermont-specific codepaths which perform better. See OpenSSL
  214|       |    // commit 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  215|      2|    if ((eax & 0x0fff0ff0) == 0x00050670 /* Knights Landing */ ||
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      2|        (eax & 0x0fff0ff0) == 0x00080650 /* Knights Mill (per SDE) */) {
  ------------------
  |  Branch (216:9): [True: 0, False: 2]
  ------------------
  217|      0|      ecx &= ~(1u << 26);
  218|      0|    }
  219|      2|  } else {
  220|      0|    edx &= ~(1u << 30);
  221|      0|  }
  222|       |
  223|       |  // The SDBG bit is repurposed to denote AMD XOP support. Don't ever use AMD
  224|       |  // XOP code paths.
  225|      2|  ecx &= ~(1u << 11);
  226|       |
  227|      2|  uint64_t xcr0 = 0;
  228|      2|  if (ecx & (1u << 27)) {
  ------------------
  |  Branch (228:7): [True: 2, False: 0]
  ------------------
  229|       |    // XCR0 may only be queried if the OSXSAVE bit is set.
  230|      2|    xcr0 = OPENSSL_xgetbv(0);
  231|      2|  }
  232|       |  // See Intel manual, volume 1, section 14.3.
  233|      2|  if ((xcr0 & 6) != 6) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2]
  ------------------
  234|       |    // YMM registers cannot be used.
  235|      0|    ecx &= ~(1u << 28);  // AVX
  236|      0|    ecx &= ~(1u << 12);  // FMA
  237|      0|    ecx &= ~(1u << 11);  // AMD XOP
  238|       |    // Clear AVX2 and AVX512* bits.
  239|       |    //
  240|       |    // TODO(davidben): Should bits 17 and 26-28 also be cleared? Upstream
  241|       |    // doesn't clear those.
  242|      0|    extended_features[0] &=
  243|      0|        ~((1u << 5) | (1u << 16) | (1u << 21) | (1u << 30) | (1u << 31));
  244|      0|  }
  245|       |  // See Intel manual, volume 1, section 15.2.
  246|      2|  if ((xcr0 & 0xe6) != 0xe6) {
  ------------------
  |  Branch (246:7): [True: 2, False: 0]
  ------------------
  247|       |    // Clear AVX512F. Note we don't touch other AVX512 extensions because they
  248|       |    // can be used with YMM.
  249|      2|    extended_features[0] &= ~(1u << 16);
  250|      2|  }
  251|       |
  252|       |  // Disable ADX instructions on Knights Landing. See OpenSSL commit
  253|       |  // 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  254|      2|  if ((ecx & (1u << 26)) == 0) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    extended_features[0] &= ~(1u << 19);
  256|      0|  }
  257|       |
  258|      2|  OPENSSL_ia32cap_P[0] = edx;
  259|      2|  OPENSSL_ia32cap_P[1] = ecx;
  260|      2|  OPENSSL_ia32cap_P[2] = extended_features[0];
  261|      2|  OPENSSL_ia32cap_P[3] = extended_features[1];
  262|       |
  263|      2|  const char *env1, *env2;
  264|      2|  env1 = getenv("OPENSSL_ia32cap");
  265|      2|  if (env1 == NULL) {
  ------------------
  |  Branch (265:7): [True: 2, False: 0]
  ------------------
  266|      2|    return;
  267|      2|  }
  268|       |
  269|       |  // OPENSSL_ia32cap can contain zero, one or two values, separated with a ':'.
  270|       |  // Each value is a 64-bit, unsigned value which may start with "0x" to
  271|       |  // indicate a hex value. Prior to the 64-bit value, a '~' or '|' may be given.
  272|       |  //
  273|       |  // If the '~' prefix is present:
  274|       |  //   the value is inverted and ANDed with the probed CPUID result
  275|       |  // If the '|' prefix is present:
  276|       |  //   the value is ORed with the probed CPUID result
  277|       |  // Otherwise:
  278|       |  //   the value is taken as the result of the CPUID
  279|       |  //
  280|       |  // The first value determines OPENSSL_ia32cap_P[0] and [1]. The second [2]
  281|       |  // and [3].
  282|       |
  283|      0|  handle_cpu_env(&OPENSSL_ia32cap_P[0], env1);
  284|      0|  env2 = strchr(env1, ':');
  285|      0|  if (env2 != NULL) {
  ------------------
  |  Branch (285:7): [True: 0, False: 0]
  ------------------
  286|      0|    handle_cpu_env(&OPENSSL_ia32cap_P[2], env2 + 1);
  287|      0|  }
  288|      0|}
cpu_intel.c:OPENSSL_cpuid:
   80|      6|                          uint32_t *out_ecx, uint32_t *out_edx, uint32_t leaf) {
   81|       |#if defined(_MSC_VER)
   82|       |  int tmp[4];
   83|       |  __cpuid(tmp, (int)leaf);
   84|       |  *out_eax = (uint32_t)tmp[0];
   85|       |  *out_ebx = (uint32_t)tmp[1];
   86|       |  *out_ecx = (uint32_t)tmp[2];
   87|       |  *out_edx = (uint32_t)tmp[3];
   88|       |#elif defined(__pic__) && defined(OPENSSL_32_BIT)
   89|       |  // Inline assembly may not clobber the PIC register. For 32-bit, this is EBX.
   90|       |  // See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47602.
   91|       |  __asm__ volatile (
   92|       |    "xor %%ecx, %%ecx\n"
   93|       |    "mov %%ebx, %%edi\n"
   94|       |    "cpuid\n"
   95|       |    "xchg %%edi, %%ebx\n"
   96|       |    : "=a"(*out_eax), "=D"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
   97|       |    : "a"(leaf)
   98|       |  );
   99|       |#else
  100|      6|  __asm__ volatile (
  101|      6|    "xor %%ecx, %%ecx\n"
  102|      6|    "cpuid\n"
  103|      6|    : "=a"(*out_eax), "=b"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
  104|      6|    : "a"(leaf)
  105|      6|  );
  106|      6|#endif
  107|      6|}
cpu_intel.c:OPENSSL_xgetbv:
  111|      2|static uint64_t OPENSSL_xgetbv(uint32_t xcr) {
  112|       |#if defined(_MSC_VER)
  113|       |  return (uint64_t)_xgetbv(xcr);
  114|       |#else
  115|      2|  uint32_t eax, edx;
  116|      2|  __asm__ volatile ("xgetbv" : "=a"(eax), "=d"(edx) : "c"(xcr));
  117|      2|  return (((uint64_t)edx) << 32) | eax;
  118|      2|#endif
  119|      2|}

crypto.c:do_library_init:
  151|      2|static void OPENSSL_CDECL do_library_init(void) {
  152|       | // WARNING: this function may only configure the capability variables. See the
  153|       | // note above about the linker bug.
  154|      2|#if defined(NEED_CPUID)
  155|      2|  OPENSSL_cpuid_setup();
  156|      2|#endif
  157|      2|}

x25519_ge_scalarmult_base:
  799|    153|void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t a[32]) {
  800|    153|#if defined(BORINGSSL_FE25519_ADX)
  801|    153|  if (CRYPTO_is_BMI1_capable() && CRYPTO_is_BMI2_capable() &&
  ------------------
  |  Branch (801:7): [True: 153, False: 0]
  |  Branch (801:35): [True: 153, False: 0]
  ------------------
  802|    153|      CRYPTO_is_ADX_capable()) {
  ------------------
  |  Branch (802:7): [True: 153, False: 0]
  ------------------
  803|    153|    uint8_t t[4][32];
  804|    153|    x25519_ge_scalarmult_base_adx(t, a);
  805|    153|    fiat_25519_from_bytes(h->X.v, t[0]);
  806|    153|    fiat_25519_from_bytes(h->Y.v, t[1]);
  807|    153|    fiat_25519_from_bytes(h->Z.v, t[2]);
  808|    153|    fiat_25519_from_bytes(h->T.v, t[3]);
  809|    153|    return;
  810|    153|  }
  811|      0|#endif
  812|      0|  signed char e[64];
  813|      0|  signed char carry;
  814|      0|  ge_p1p1 r;
  815|      0|  ge_p2 s;
  816|      0|  ge_precomp t;
  817|      0|  int i;
  818|       |
  819|      0|  for (i = 0; i < 32; ++i) {
  ------------------
  |  Branch (819:15): [True: 0, False: 0]
  ------------------
  820|      0|    e[2 * i + 0] = (a[i] >> 0) & 15;
  821|      0|    e[2 * i + 1] = (a[i] >> 4) & 15;
  822|      0|  }
  823|       |  // each e[i] is between 0 and 15
  824|       |  // e[63] is between 0 and 7
  825|       |
  826|      0|  carry = 0;
  827|      0|  for (i = 0; i < 63; ++i) {
  ------------------
  |  Branch (827:15): [True: 0, False: 0]
  ------------------
  828|      0|    e[i] += carry;
  829|      0|    carry = e[i] + 8;
  830|      0|    carry >>= 4;
  831|      0|    e[i] -= carry << 4;
  832|      0|  }
  833|      0|  e[63] += carry;
  834|       |  // each e[i] is between -8 and 8
  835|       |
  836|      0|  ge_p3_0(h);
  837|      0|  for (i = 1; i < 64; i += 2) {
  ------------------
  |  Branch (837:15): [True: 0, False: 0]
  ------------------
  838|      0|    table_select(&t, i / 2, e[i]);
  839|      0|    ge_madd(&r, h, &t);
  840|      0|    x25519_ge_p1p1_to_p3(h, &r);
  841|      0|  }
  842|       |
  843|      0|  ge_p3_dbl(&r, h);
  844|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  845|      0|  ge_p2_dbl(&r, &s);
  846|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  847|      0|  ge_p2_dbl(&r, &s);
  848|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  849|      0|  ge_p2_dbl(&r, &s);
  850|      0|  x25519_ge_p1p1_to_p3(h, &r);
  851|       |
  852|      0|  for (i = 0; i < 64; i += 2) {
  ------------------
  |  Branch (852:15): [True: 0, False: 0]
  ------------------
  853|      0|    table_select(&t, i / 2, e[i]);
  854|      0|    ge_madd(&r, h, &t);
  855|      0|    x25519_ge_p1p1_to_p3(h, &r);
  856|      0|  }
  857|      0|}
ED25519_keypair_from_seed:
 1975|     35|                               const uint8_t seed[32]) {
 1976|     35|  uint8_t az[SHA512_DIGEST_LENGTH];
 1977|     35|  SHA512(seed, 32, az);
 1978|       |
 1979|     35|  az[0] &= 248;
 1980|     35|  az[31] &= 127;
 1981|     35|  az[31] |= 64;
 1982|       |
 1983|     35|  ge_p3 A;
 1984|     35|  x25519_ge_scalarmult_base(&A, az);
 1985|     35|  ge_p3_tobytes(out_public_key, &A);
 1986|       |
 1987|     35|  OPENSSL_memcpy(out_private_key, seed, 32);
 1988|     35|  OPENSSL_memcpy(out_private_key + 32, out_public_key, 32);
 1989|     35|}
X25519_public_from_private:
 2125|    118|                                const uint8_t private_key[32]) {
 2126|       |#if defined(BORINGSSL_X25519_NEON)
 2127|       |  if (CRYPTO_is_NEON_capable()) {
 2128|       |    static const uint8_t kMongomeryBasePoint[32] = {9};
 2129|       |    x25519_NEON(out_public_value, private_key, kMongomeryBasePoint);
 2130|       |    return;
 2131|       |  }
 2132|       |#endif
 2133|       |
 2134|    118|  uint8_t e[32];
 2135|    118|  OPENSSL_memcpy(e, private_key, 32);
 2136|    118|  e[0] &= 248;
 2137|    118|  e[31] &= 127;
 2138|    118|  e[31] |= 64;
 2139|       |
 2140|    118|  ge_p3 A;
 2141|    118|  x25519_ge_scalarmult_base(&A, e);
 2142|       |
 2143|       |  // We only need the u-coordinate of the curve25519 point. The map is
 2144|       |  // u=(y+1)/(1-y). Since y=Y/Z, this gives u=(Z+Y)/(Z-Y).
 2145|    118|  fe_loose zplusy, zminusy;
 2146|    118|  fe zminusy_inv;
 2147|    118|  fe_add(&zplusy, &A.Z, &A.Y);
 2148|    118|  fe_sub(&zminusy, &A.Z, &A.Y);
 2149|    118|  fe_loose_invert(&zminusy_inv, &zminusy);
 2150|    118|  fe_mul_tlt(&zminusy_inv, &zplusy, &zminusy_inv);
 2151|    118|  fe_tobytes(out_public_value, &zminusy_inv);
 2152|    118|  CONSTTIME_DECLASSIFY(out_public_value, 32);
 2153|    118|}
curve25519.c:fe_invert:
  374|     35|static void fe_invert(fe *out, const fe *z) {
  375|     35|  fe_loose l;
  376|     35|  fe_copy_lt(&l, z);
  377|     35|  fe_loose_invert(out, &l);
  378|     35|}
curve25519.c:fe_mul_ttt:
  231|  1.60k|static void fe_mul_ttt(fe *h, const fe *f, const fe *g) {
  232|  1.60k|  fe_mul_impl(h->v, f->v, g->v);
  233|  1.60k|}
curve25519.c:fe_mul_impl:
  216|  1.87k|                        const fe_limb_t in2[FE_NUM_LIMBS]) {
  217|  1.87k|  assert_fe_loose(in1);
  ------------------
  |  |   99|  1.87k|  do {                                                                  \
  |  |  100|  11.2k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 9.35k, False: 1.87k]
  |  |  ------------------
  |  |  101|  9.35k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  9.35k|    }                                                                   \
  |  |  103|  1.87k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  218|  1.87k|  assert_fe_loose(in2);
  ------------------
  |  |   99|  1.87k|  do {                                                                  \
  |  |  100|  11.2k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 9.35k, False: 1.87k]
  |  |  ------------------
  |  |  101|  9.35k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  9.35k|    }                                                                   \
  |  |  103|  1.87k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  219|  1.87k|  fiat_25519_carry_mul(out, in1, in2);
  220|  1.87k|  assert_fe(out);
  ------------------
  |  |   82|  1.87k|  do {                                                                  \
  |  |   83|  11.2k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 9.35k, False: 1.87k]
  |  |  ------------------
  |  |   84|  9.35k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  9.35k|    }                                                                   \
  |  |   86|  1.87k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  221|  1.87k|}
curve25519.c:fe_tobytes:
  165|    188|static void fe_tobytes(uint8_t s[32], const fe *f) {
  166|    188|  assert_fe(f->v);
  ------------------
  |  |   82|    188|  do {                                                                  \
  |  |   83|  1.12k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 940, False: 188]
  |  |  ------------------
  |  |   84|    940|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    940|    }                                                                   \
  |  |   86|    188|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  167|    188|  fiat_25519_to_bytes(s, f->v);
  168|    188|}
curve25519.c:fe_isnegative:
  394|     35|static int fe_isnegative(const fe *f) {
  395|     35|  uint8_t s[32];
  396|     35|  fe_tobytes(s, f);
  397|     35|  return s[0] & 1;
  398|     35|}
curve25519.c:fe_sq_tt:
  253|  38.7k|static void fe_sq_tt(fe *h, const fe *f) {
  254|  38.7k|  assert_fe_loose(f->v);
  ------------------
  |  |   99|  38.7k|  do {                                                                  \
  |  |  100|   232k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 193k, False: 38.7k]
  |  |  ------------------
  |  |  101|   193k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|   193k|    }                                                                   \
  |  |  103|  38.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  255|  38.7k|  fiat_25519_carry_square(h->v, f->v);
  256|  38.7k|  assert_fe(h->v);
  ------------------
  |  |   82|  38.7k|  do {                                                                  \
  |  |   83|   232k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 193k, False: 38.7k]
  |  |  ------------------
  |  |   84|   193k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|   193k|    }                                                                   \
  |  |   86|  38.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  257|  38.7k|}
curve25519.c:fe_sub:
  201|    118|static void fe_sub(fe_loose *h, const fe *f, const fe *g) {
  202|    118|  assert_fe(f->v);
  ------------------
  |  |   82|    118|  do {                                                                  \
  |  |   83|    708|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 590, False: 118]
  |  |  ------------------
  |  |   84|    590|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    590|    }                                                                   \
  |  |   86|    118|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  203|    118|  assert_fe(g->v);
  ------------------
  |  |   82|    118|  do {                                                                  \
  |  |   83|    708|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 590, False: 118]
  |  |  ------------------
  |  |   84|    590|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    590|    }                                                                   \
  |  |   86|    118|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  204|    118|  fiat_25519_sub(h->v, f->v, g->v);
  205|    118|  assert_fe_loose(h->v);
  ------------------
  |  |   99|    118|  do {                                                                  \
  |  |  100|    708|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 590, False: 118]
  |  |  ------------------
  |  |  101|    590|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|    590|    }                                                                   \
  |  |  103|    118|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  206|    118|}
curve25519.c:fe_add:
  192|    118|static void fe_add(fe_loose *h, const fe *f, const fe *g) {
  193|    118|  assert_fe(f->v);
  ------------------
  |  |   82|    118|  do {                                                                  \
  |  |   83|    708|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 590, False: 118]
  |  |  ------------------
  |  |   84|    590|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    590|    }                                                                   \
  |  |   86|    118|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  194|    118|  assert_fe(g->v);
  ------------------
  |  |   82|    118|  do {                                                                  \
  |  |   83|    708|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 590, False: 118]
  |  |  ------------------
  |  |   84|    590|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    590|    }                                                                   \
  |  |   86|    118|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  195|    118|  fiat_25519_add(h->v, f->v, g->v);
  196|    118|  assert_fe_loose(h->v);
  ------------------
  |  |   99|    118|  do {                                                                  \
  |  |  100|    708|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 590, False: 118]
  |  |  ------------------
  |  |  101|    590|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|    590|    }                                                                   \
  |  |  103|    118|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  197|    118|}
curve25519.c:fe_copy_lt:
  311|     35|static void fe_copy_lt(fe_loose *h, const fe *f) {
  312|     35|  static_assert(sizeof(fe_loose) == sizeof(fe), "fe and fe_loose mismatch");
  313|     35|  OPENSSL_memmove(h, f, sizeof(fe));
  314|     35|}
curve25519.c:fe_mul_tlt:
  235|    271|static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) {
  236|    271|  fe_mul_impl(h->v, f->v, g->v);
  237|    271|}
curve25519.c:fe_sq_tl:
  247|    153|static void fe_sq_tl(fe *h, const fe_loose *f) {
  248|    153|  assert_fe_loose(f->v);
  ------------------
  |  |   99|    153|  do {                                                                  \
  |  |  100|    918|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 765, False: 153]
  |  |  ------------------
  |  |  101|    765|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|    765|    }                                                                   \
  |  |  103|    153|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  249|    153|  fiat_25519_carry_square(h->v, f->v);
  250|    153|  assert_fe(h->v);
  ------------------
  |  |   82|    153|  do {                                                                  \
  |  |   83|    918|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 765, False: 153]
  |  |  ------------------
  |  |   84|    765|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|    765|    }                                                                   \
  |  |   86|    153|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  251|    153|}
curve25519.c:ge_p3_tobytes:
  482|     35|static void ge_p3_tobytes(uint8_t s[32], const ge_p3 *h) {
  483|     35|  fe recip;
  484|     35|  fe x;
  485|     35|  fe y;
  486|       |
  487|     35|  fe_invert(&recip, &h->Z);
  488|     35|  fe_mul_ttt(&x, &h->X, &recip);
  489|     35|  fe_mul_ttt(&y, &h->Y, &recip);
  490|     35|  fe_tobytes(s, &y);
  491|     35|  s[31] ^= fe_isnegative(&x) << 7;
  492|     35|}
curve25519.c:fe_loose_invert:
  316|    153|static void fe_loose_invert(fe *out, const fe_loose *z) {
  317|    153|  fe t0;
  318|    153|  fe t1;
  319|    153|  fe t2;
  320|    153|  fe t3;
  321|    153|  int i;
  322|       |
  323|    153|  fe_sq_tl(&t0, z);
  324|    153|  fe_sq_tt(&t1, &t0);
  325|    306|  for (i = 1; i < 2; ++i) {
  ------------------
  |  Branch (325:15): [True: 153, False: 153]
  ------------------
  326|    153|    fe_sq_tt(&t1, &t1);
  327|    153|  }
  328|    153|  fe_mul_tlt(&t1, z, &t1);
  329|    153|  fe_mul_ttt(&t0, &t0, &t1);
  330|    153|  fe_sq_tt(&t2, &t0);
  331|    153|  fe_mul_ttt(&t1, &t1, &t2);
  332|    153|  fe_sq_tt(&t2, &t1);
  333|    765|  for (i = 1; i < 5; ++i) {
  ------------------
  |  Branch (333:15): [True: 612, False: 153]
  ------------------
  334|    612|    fe_sq_tt(&t2, &t2);
  335|    612|  }
  336|    153|  fe_mul_ttt(&t1, &t2, &t1);
  337|    153|  fe_sq_tt(&t2, &t1);
  338|  1.53k|  for (i = 1; i < 10; ++i) {
  ------------------
  |  Branch (338:15): [True: 1.37k, False: 153]
  ------------------
  339|  1.37k|    fe_sq_tt(&t2, &t2);
  340|  1.37k|  }
  341|    153|  fe_mul_ttt(&t2, &t2, &t1);
  342|    153|  fe_sq_tt(&t3, &t2);
  343|  3.06k|  for (i = 1; i < 20; ++i) {
  ------------------
  |  Branch (343:15): [True: 2.90k, False: 153]
  ------------------
  344|  2.90k|    fe_sq_tt(&t3, &t3);
  345|  2.90k|  }
  346|    153|  fe_mul_ttt(&t2, &t3, &t2);
  347|    153|  fe_sq_tt(&t2, &t2);
  348|  1.53k|  for (i = 1; i < 10; ++i) {
  ------------------
  |  Branch (348:15): [True: 1.37k, False: 153]
  ------------------
  349|  1.37k|    fe_sq_tt(&t2, &t2);
  350|  1.37k|  }
  351|    153|  fe_mul_ttt(&t1, &t2, &t1);
  352|    153|  fe_sq_tt(&t2, &t1);
  353|  7.65k|  for (i = 1; i < 50; ++i) {
  ------------------
  |  Branch (353:15): [True: 7.49k, False: 153]
  ------------------
  354|  7.49k|    fe_sq_tt(&t2, &t2);
  355|  7.49k|  }
  356|    153|  fe_mul_ttt(&t2, &t2, &t1);
  357|    153|  fe_sq_tt(&t3, &t2);
  358|  15.3k|  for (i = 1; i < 100; ++i) {
  ------------------
  |  Branch (358:15): [True: 15.1k, False: 153]
  ------------------
  359|  15.1k|    fe_sq_tt(&t3, &t3);
  360|  15.1k|  }
  361|    153|  fe_mul_ttt(&t2, &t3, &t2);
  362|    153|  fe_sq_tt(&t2, &t2);
  363|  7.65k|  for (i = 1; i < 50; ++i) {
  ------------------
  |  Branch (363:15): [True: 7.49k, False: 153]
  ------------------
  364|  7.49k|    fe_sq_tt(&t2, &t2);
  365|  7.49k|  }
  366|    153|  fe_mul_ttt(&t1, &t2, &t1);
  367|    153|  fe_sq_tt(&t1, &t1);
  368|    765|  for (i = 1; i < 5; ++i) {
  ------------------
  |  Branch (368:15): [True: 612, False: 153]
  ------------------
  369|    612|    fe_sq_tt(&t1, &t1);
  370|    612|  }
  371|    153|  fe_mul_ttt(out, &t1, &t0);
  372|    153|}

DSA_new:
   90|    991|DSA *DSA_new(void) {
   91|    991|  DSA *dsa = OPENSSL_malloc(sizeof(DSA));
   92|    991|  if (dsa == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 991]
  ------------------
   93|      0|    return NULL;
   94|      0|  }
   95|       |
   96|    991|  OPENSSL_memset(dsa, 0, sizeof(DSA));
   97|       |
   98|    991|  dsa->references = 1;
   99|       |
  100|    991|  CRYPTO_MUTEX_init(&dsa->method_mont_lock);
  101|    991|  CRYPTO_new_ex_data(&dsa->ex_data);
  102|       |
  103|    991|  return dsa;
  104|    991|}
DSA_free:
  106|  1.62k|void DSA_free(DSA *dsa) {
  107|  1.62k|  if (dsa == NULL) {
  ------------------
  |  Branch (107:7): [True: 635, False: 991]
  ------------------
  108|    635|    return;
  109|    635|  }
  110|       |
  111|    991|  if (!CRYPTO_refcount_dec_and_test_zero(&dsa->references)) {
  ------------------
  |  Branch (111:7): [True: 0, False: 991]
  ------------------
  112|      0|    return;
  113|      0|  }
  114|       |
  115|    991|  CRYPTO_free_ex_data(&g_ex_data_class, dsa, &dsa->ex_data);
  116|       |
  117|    991|  BN_clear_free(dsa->p);
  118|    991|  BN_clear_free(dsa->q);
  119|    991|  BN_clear_free(dsa->g);
  120|    991|  BN_clear_free(dsa->pub_key);
  121|    991|  BN_clear_free(dsa->priv_key);
  122|    991|  BN_MONT_CTX_free(dsa->method_mont_p);
  123|    991|  BN_MONT_CTX_free(dsa->method_mont_q);
  124|    991|  CRYPTO_MUTEX_cleanup(&dsa->method_mont_lock);
  125|    991|  OPENSSL_free(dsa);
  126|    991|}

dsa_check_key:
   73|  1.25k|int dsa_check_key(const DSA *dsa) {
   74|  1.25k|  if (!dsa->p || !dsa->q || !dsa->g) {
  ------------------
  |  Branch (74:7): [True: 0, False: 1.25k]
  |  Branch (74:18): [True: 0, False: 1.25k]
  |  Branch (74:29): [True: 0, False: 1.25k]
  ------------------
   75|      0|    OPENSSL_PUT_ERROR(DSA, DSA_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|       |
   79|       |  // Fully checking for invalid DSA groups is expensive, so security and
   80|       |  // correctness of the signature scheme depend on how |dsa| was computed. I.e.
   81|       |  // we leave "assurance of domain parameter validity" from FIPS 186-4 to the
   82|       |  // caller. However, we check bounds on all values to avoid DoS vectors even
   83|       |  // when domain parameters are invalid. In particular, signing will infinite
   84|       |  // loop if |g| is zero.
   85|  1.25k|  if (BN_is_negative(dsa->p) || BN_is_negative(dsa->q) || BN_is_zero(dsa->p) ||
  ------------------
  |  Branch (85:7): [True: 0, False: 1.25k]
  |  Branch (85:33): [True: 0, False: 1.25k]
  |  Branch (85:59): [True: 3, False: 1.24k]
  ------------------
   86|  1.25k|      BN_is_zero(dsa->q) || !BN_is_odd(dsa->p) || !BN_is_odd(dsa->q) ||
  ------------------
  |  Branch (86:7): [True: 6, False: 1.24k]
  |  Branch (86:29): [True: 46, False: 1.19k]
  |  Branch (86:51): [True: 18, False: 1.17k]
  ------------------
   87|       |      // |q| must be a prime divisor of |p - 1|, which implies |q < p|.
   88|  1.25k|      BN_cmp(dsa->q, dsa->p) >= 0 ||
  ------------------
  |  Branch (88:7): [True: 43, False: 1.13k]
  ------------------
   89|       |      // |g| is in the multiplicative group of |p|.
   90|  1.25k|      BN_is_negative(dsa->g) || BN_is_zero(dsa->g) ||
  ------------------
  |  Branch (90:7): [True: 0, False: 1.13k]
  |  Branch (90:33): [True: 9, False: 1.12k]
  ------------------
   91|  1.25k|      BN_cmp(dsa->g, dsa->p) >= 0) {
  ------------------
  |  Branch (91:7): [True: 18, False: 1.10k]
  ------------------
   92|    143|    OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|    143|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   93|    143|    return 0;
   94|    143|  }
   95|       |
   96|       |  // FIPS 186-4 allows only three different sizes for q.
   97|  1.10k|  unsigned q_bits = BN_num_bits(dsa->q);
   98|  1.10k|  if (q_bits != 160 && q_bits != 224 && q_bits != 256) {
  ------------------
  |  Branch (98:7): [True: 794, False: 313]
  |  Branch (98:24): [True: 213, False: 581]
  |  Branch (98:41): [True: 211, False: 2]
  ------------------
   99|    211|    OPENSSL_PUT_ERROR(DSA, DSA_R_BAD_Q_VALUE);
  ------------------
  |  |  441|    211|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  100|    211|    return 0;
  101|    211|  }
  102|       |
  103|       |  // Bound |dsa->p| to avoid a DoS vector. Note this limit is much larger than
  104|       |  // the one in FIPS 186-4, which only allows L = 1024, 2048, and 3072.
  105|    896|  if (BN_num_bits(dsa->p) > OPENSSL_DSA_MAX_MODULUS_BITS) {
  ------------------
  |  |   68|    896|#define OPENSSL_DSA_MAX_MODULUS_BITS 10000
  ------------------
  |  Branch (105:7): [True: 1, False: 895]
  ------------------
  106|      1|    OPENSSL_PUT_ERROR(DSA, DSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|      1|    return 0;
  108|      1|  }
  109|       |
  110|    895|  if (dsa->pub_key != NULL) {
  ------------------
  |  Branch (110:7): [True: 9, False: 886]
  ------------------
  111|       |    // The public key is also in the multiplicative group of |p|.
  112|      9|    if (BN_is_negative(dsa->pub_key) || BN_is_zero(dsa->pub_key) ||
  ------------------
  |  Branch (112:9): [True: 0, False: 9]
  |  Branch (112:41): [True: 1, False: 8]
  ------------------
  113|      9|        BN_cmp(dsa->pub_key, dsa->p) >= 0) {
  ------------------
  |  Branch (113:9): [True: 2, False: 6]
  ------------------
  114|      3|      OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|      3|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  115|      3|      return 0;
  116|      3|    }
  117|      9|  }
  118|       |
  119|    892|  if (dsa->priv_key != NULL) {
  ------------------
  |  Branch (119:7): [True: 441, False: 451]
  ------------------
  120|       |    // The private key is a non-zero element of the scalar field, determined by
  121|       |    // |q|.
  122|    441|    if (BN_is_negative(dsa->priv_key) || BN_is_zero(dsa->priv_key) ||
  ------------------
  |  Branch (122:9): [True: 0, False: 441]
  |  Branch (122:42): [True: 7, False: 434]
  ------------------
  123|    441|        BN_cmp(dsa->priv_key, dsa->q) >= 0) {
  ------------------
  |  Branch (123:9): [True: 4, False: 430]
  ------------------
  124|     11|      OPENSSL_PUT_ERROR(DSA, DSA_R_INVALID_PARAMETERS);
  ------------------
  |  |  441|     11|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  125|     11|      return 0;
  126|     11|    }
  127|    441|  }
  128|       |
  129|    881|  return 1;
  130|    892|}
DSA_parse_parameters:
  218|    525|DSA *DSA_parse_parameters(CBS *cbs) {
  219|    525|  DSA *ret = DSA_new();
  220|    525|  if (ret == NULL) {
  ------------------
  |  Branch (220:7): [True: 0, False: 525]
  ------------------
  221|      0|    return NULL;
  222|      0|  }
  223|    525|  CBS child;
  224|    525|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    525|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    525|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    525|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (224:7): [True: 4, False: 521]
  ------------------
  225|    525|      !parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (225:7): [True: 18, False: 503]
  ------------------
  226|    525|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (226:7): [True: 4, False: 499]
  ------------------
  227|    525|      !parse_integer(&child, &ret->g) ||
  ------------------
  |  Branch (227:7): [True: 2, False: 497]
  ------------------
  228|    525|      CBS_len(&child) != 0) {
  ------------------
  |  Branch (228:7): [True: 14, False: 483]
  ------------------
  229|     42|    OPENSSL_PUT_ERROR(DSA, DSA_R_DECODE_ERROR);
  ------------------
  |  |  441|     42|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  230|     42|    goto err;
  231|     42|  }
  232|    483|  if (!dsa_check_key(ret)) {
  ------------------
  |  Branch (232:7): [True: 32, False: 451]
  ------------------
  233|     32|    goto err;
  234|     32|  }
  235|    451|  return ret;
  236|       |
  237|     74|err:
  238|     74|  DSA_free(ret);
  239|     74|  return NULL;
  240|    483|}
DSA_parse_private_key:
  255|    466|DSA *DSA_parse_private_key(CBS *cbs) {
  256|    466|  DSA *ret = DSA_new();
  257|    466|  if (ret == NULL) {
  ------------------
  |  Branch (257:7): [True: 0, False: 466]
  ------------------
  258|      0|    return NULL;
  259|      0|  }
  260|       |
  261|    466|  CBS child;
  262|    466|  uint64_t version;
  263|    466|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    466|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    466|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    466|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (263:7): [True: 0, False: 466]
  ------------------
  264|    466|      !CBS_get_asn1_uint64(&child, &version)) {
  ------------------
  |  Branch (264:7): [True: 1, False: 465]
  ------------------
  265|      1|    OPENSSL_PUT_ERROR(DSA, DSA_R_DECODE_ERROR);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      1|    goto err;
  267|      1|  }
  268|       |
  269|    465|  if (version != 0) {
  ------------------
  |  Branch (269:7): [True: 126, False: 339]
  ------------------
  270|    126|    OPENSSL_PUT_ERROR(DSA, DSA_R_BAD_VERSION);
  ------------------
  |  |  441|    126|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  271|    126|    goto err;
  272|    126|  }
  273|       |
  274|    339|  if (!parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (274:7): [True: 3, False: 336]
  ------------------
  275|    339|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (275:7): [True: 1, False: 335]
  ------------------
  276|    339|      !parse_integer(&child, &ret->g) ||
  ------------------
  |  Branch (276:7): [True: 1, False: 334]
  ------------------
  277|    339|      !parse_integer(&child, &ret->pub_key) ||
  ------------------
  |  Branch (277:7): [True: 1, False: 333]
  ------------------
  278|    339|      !parse_integer(&child, &ret->priv_key) ||
  ------------------
  |  Branch (278:7): [True: 1, False: 332]
  ------------------
  279|    339|      CBS_len(&child) != 0) {
  ------------------
  |  Branch (279:7): [True: 0, False: 332]
  ------------------
  280|      7|    OPENSSL_PUT_ERROR(DSA, DSA_R_DECODE_ERROR);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  281|      7|    goto err;
  282|      7|  }
  283|    332|  if (!dsa_check_key(ret)) {
  ------------------
  |  Branch (283:7): [True: 329, False: 3]
  ------------------
  284|    329|    goto err;
  285|    329|  }
  286|       |
  287|      3|  return ret;
  288|       |
  289|    463|err:
  290|    463|  DSA_free(ret);
  291|    463|  return NULL;
  292|    332|}
dsa_asn1.c:parse_integer:
  132|  3.20k|static int parse_integer(CBS *cbs, BIGNUM **out) {
  133|  3.20k|  assert(*out == NULL);
  134|  3.20k|  *out = BN_new();
  135|  3.20k|  if (*out == NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 3.20k]
  ------------------
  136|      0|    return 0;
  137|      0|  }
  138|  3.20k|  return BN_parse_asn1_unsigned(cbs, *out);
  139|  3.20k|}

EC_KEY_parse_private_key:
   75|  2.12k|EC_KEY *EC_KEY_parse_private_key(CBS *cbs, const EC_GROUP *group) {
   76|  2.12k|  CBS ec_private_key, private_key;
   77|  2.12k|  uint64_t version;
   78|  2.12k|  if (!CBS_get_asn1(cbs, &ec_private_key, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  2.12k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  2.12k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  2.12k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (78:7): [True: 6, False: 2.11k]
  ------------------
   79|  2.12k|      !CBS_get_asn1_uint64(&ec_private_key, &version) ||
  ------------------
  |  Branch (79:7): [True: 3, False: 2.11k]
  ------------------
   80|  2.12k|      version != 1 ||
  ------------------
  |  Branch (80:7): [True: 163, False: 1.95k]
  ------------------
   81|  2.12k|      !CBS_get_asn1(&ec_private_key, &private_key, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|  1.95k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (81:7): [True: 3, False: 1.94k]
  ------------------
   82|    175|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|    175|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   83|    175|    return NULL;
   84|    175|  }
   85|       |
   86|       |  // Parse the optional parameters field.
   87|  1.94k|  EC_GROUP *inner_group = NULL;
   88|  1.94k|  EC_KEY *ret = NULL;
   89|  1.94k|  BIGNUM *priv_key = NULL;
   90|  1.94k|  if (CBS_peek_asn1_tag(&ec_private_key, kParametersTag)) {
  ------------------
  |  Branch (90:7): [True: 1.55k, False: 394]
  ------------------
   91|       |    // Per SEC 1, as an alternative to omitting it, one is allowed to specify
   92|       |    // this field and put in a NULL to mean inheriting this value. This was
   93|       |    // omitted in a previous version of this logic without problems, so leave it
   94|       |    // unimplemented.
   95|  1.55k|    CBS child;
   96|  1.55k|    if (!CBS_get_asn1(&ec_private_key, &child, kParametersTag)) {
  ------------------
  |  Branch (96:9): [True: 2, False: 1.55k]
  ------------------
   97|      2|      OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   98|      2|      goto err;
   99|      2|    }
  100|  1.55k|    inner_group = EC_KEY_parse_parameters(&child);
  101|  1.55k|    if (inner_group == NULL) {
  ------------------
  |  Branch (101:9): [True: 604, False: 948]
  ------------------
  102|    604|      goto err;
  103|    604|    }
  104|    948|    if (group == NULL) {
  ------------------
  |  Branch (104:9): [True: 926, False: 22]
  ------------------
  105|    926|      group = inner_group;
  106|    926|    } else if (EC_GROUP_cmp(group, inner_group, NULL) != 0) {
  ------------------
  |  Branch (106:16): [True: 2, False: 20]
  ------------------
  107|       |      // If a group was supplied externally, it must match.
  108|      2|      OPENSSL_PUT_ERROR(EC, EC_R_GROUP_MISMATCH);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  109|      2|      goto err;
  110|      2|    }
  111|    946|    if (CBS_len(&child) != 0) {
  ------------------
  |  Branch (111:9): [True: 9, False: 937]
  ------------------
  112|      9|      OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      9|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  113|      9|      goto err;
  114|      9|    }
  115|    946|  }
  116|       |
  117|  1.33k|  if (group == NULL) {
  ------------------
  |  Branch (117:7): [True: 97, False: 1.23k]
  ------------------
  118|     97|    OPENSSL_PUT_ERROR(EC, EC_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|     97|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  119|     97|    goto err;
  120|     97|  }
  121|       |
  122|  1.23k|  ret = EC_KEY_new();
  123|  1.23k|  if (ret == NULL || !EC_KEY_set_group(ret, group)) {
  ------------------
  |  Branch (123:7): [True: 0, False: 1.23k]
  |  Branch (123:22): [True: 0, False: 1.23k]
  ------------------
  124|      0|    goto err;
  125|      0|  }
  126|       |
  127|       |  // Although RFC 5915 specifies the length of the key, OpenSSL historically
  128|       |  // got this wrong, so accept any length. See upstream's
  129|       |  // 30cd4ff294252c4b6a4b69cbef6a5b4117705d22.
  130|  1.23k|  priv_key = BN_bin2bn(CBS_data(&private_key), CBS_len(&private_key), NULL);
  131|  1.23k|  ret->pub_key = EC_POINT_new(group);
  132|  1.23k|  if (priv_key == NULL || ret->pub_key == NULL ||
  ------------------
  |  Branch (132:7): [True: 0, False: 1.23k]
  |  Branch (132:27): [True: 0, False: 1.23k]
  ------------------
  133|  1.23k|      !EC_KEY_set_private_key(ret, priv_key)) {
  ------------------
  |  Branch (133:7): [True: 136, False: 1.09k]
  ------------------
  134|    136|    goto err;
  135|    136|  }
  136|       |
  137|  1.09k|  if (CBS_peek_asn1_tag(&ec_private_key, kPublicKeyTag)) {
  ------------------
  |  Branch (137:7): [True: 757, False: 341]
  ------------------
  138|    757|    CBS child, public_key;
  139|    757|    uint8_t padding;
  140|    757|    if (!CBS_get_asn1(&ec_private_key, &child, kPublicKeyTag) ||
  ------------------
  |  Branch (140:9): [True: 2, False: 755]
  ------------------
  141|    757|        !CBS_get_asn1(&child, &public_key, CBS_ASN1_BITSTRING) ||
  ------------------
  |  |  216|    755|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (141:9): [True: 4, False: 751]
  ------------------
  142|       |        // As in a SubjectPublicKeyInfo, the byte-encoded public key is then
  143|       |        // encoded as a BIT STRING with bits ordered as in the DER encoding.
  144|    757|        !CBS_get_u8(&public_key, &padding) ||
  ------------------
  |  Branch (144:9): [True: 3, False: 748]
  ------------------
  145|    757|        padding != 0 ||
  ------------------
  |  Branch (145:9): [True: 9, False: 739]
  ------------------
  146|       |        // Explicitly check |public_key| is non-empty to save the conversion
  147|       |        // form later.
  148|    757|        CBS_len(&public_key) == 0 ||
  ------------------
  |  Branch (148:9): [True: 3, False: 736]
  ------------------
  149|    757|        !EC_POINT_oct2point(group, ret->pub_key, CBS_data(&public_key),
  ------------------
  |  Branch (149:9): [True: 255, False: 481]
  ------------------
  150|    736|                            CBS_len(&public_key), NULL) ||
  151|    757|        CBS_len(&child) != 0) {
  ------------------
  |  Branch (151:9): [True: 20, False: 461]
  ------------------
  152|    296|      OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|    296|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  153|    296|      goto err;
  154|    296|    }
  155|       |
  156|       |    // Save the point conversion form.
  157|       |    // TODO(davidben): Consider removing this.
  158|    461|    ret->conv_form =
  159|    461|        (point_conversion_form_t)(CBS_data(&public_key)[0] & ~0x01);
  160|    461|  } else {
  161|       |    // Compute the public key instead.
  162|    341|    if (!ec_point_mul_scalar_base(group, &ret->pub_key->raw,
  ------------------
  |  Branch (162:9): [True: 0, False: 341]
  ------------------
  163|    341|                                  &ret->priv_key->scalar)) {
  164|      0|      goto err;
  165|      0|    }
  166|       |    // Remember the original private-key-only encoding.
  167|       |    // TODO(davidben): Consider removing this.
  168|    341|    ret->enc_flag |= EC_PKEY_NO_PUBKEY;
  ------------------
  |  |  146|    341|#define EC_PKEY_NO_PUBKEY 0x002
  ------------------
  169|    341|  }
  170|       |
  171|    802|  if (CBS_len(&ec_private_key) != 0) {
  ------------------
  |  Branch (171:7): [True: 201, False: 601]
  ------------------
  172|    201|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|    201|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|    201|    goto err;
  174|    201|  }
  175|       |
  176|       |  // Ensure the resulting key is valid.
  177|    601|  if (!EC_KEY_check_key(ret)) {
  ------------------
  |  Branch (177:7): [True: 441, False: 160]
  ------------------
  178|    441|    goto err;
  179|    441|  }
  180|       |
  181|    160|  BN_free(priv_key);
  182|    160|  EC_GROUP_free(inner_group);
  183|    160|  return ret;
  184|       |
  185|  1.78k|err:
  186|  1.78k|  EC_KEY_free(ret);
  187|  1.78k|  BN_free(priv_key);
  188|  1.78k|  EC_GROUP_free(inner_group);
  189|  1.78k|  return NULL;
  190|    601|}
EC_KEY_parse_curve_name:
  324|  1.55k|EC_GROUP *EC_KEY_parse_curve_name(CBS *cbs) {
  325|  1.55k|  CBS named_curve;
  326|  1.55k|  if (!CBS_get_asn1(cbs, &named_curve, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  1.55k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (326:7): [True: 198, False: 1.35k]
  ------------------
  327|    198|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|    198|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|    198|    return NULL;
  329|    198|  }
  330|       |
  331|       |  // Look for a matching curve.
  332|  1.35k|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  333|  4.54k|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|  4.54k|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (333:22): [True: 4.50k, False: 43]
  ------------------
  334|  4.50k|    const struct built_in_curve *curve = &curves->curves[i];
  335|  4.50k|    if (CBS_len(&named_curve) == curve->oid_len &&
  ------------------
  |  Branch (335:9): [True: 3.17k, False: 1.32k]
  ------------------
  336|  4.50k|        OPENSSL_memcmp(CBS_data(&named_curve), curve->oid, curve->oid_len) ==
  ------------------
  |  Branch (336:9): [True: 1.31k, False: 1.85k]
  ------------------
  337|  3.17k|            0) {
  338|  1.31k|      return EC_GROUP_new_by_curve_name(curve->nid);
  339|  1.31k|    }
  340|  4.50k|  }
  341|       |
  342|     43|  OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|     43|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  343|     43|  return NULL;
  344|  1.35k|}
EC_KEY_parse_parameters:
  368|  2.19k|EC_GROUP *EC_KEY_parse_parameters(CBS *cbs) {
  369|  2.19k|  if (!CBS_peek_asn1_tag(cbs, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  2.19k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  2.19k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  2.19k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (369:7): [True: 1.55k, False: 634]
  ------------------
  370|  1.55k|    return EC_KEY_parse_curve_name(cbs);
  371|  1.55k|  }
  372|       |
  373|       |  // OpenSSL sometimes produces ECPrivateKeys with explicitly-encoded versions
  374|       |  // of named curves.
  375|       |  //
  376|       |  // TODO(davidben): Remove support for this.
  377|    634|  CBS prime, a, b, base_x, base_y, order;
  378|    634|  if (!parse_explicit_prime_curve(cbs, &prime, &a, &b, &base_x, &base_y,
  ------------------
  |  Branch (378:7): [True: 496, False: 138]
  ------------------
  379|    634|                                  &order)) {
  380|    496|    return NULL;
  381|    496|  }
  382|       |
  383|       |  // Look for a matching prime curve.
  384|    138|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  385|    668|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|    668|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (385:22): [True: 541, False: 127]
  ------------------
  386|    541|    const struct built_in_curve *curve = &curves->curves[i];
  387|    541|    const unsigned param_len = curve->param_len;
  388|       |    // |curve->params| is ordered p, a, b, x, y, order, each component
  389|       |    // zero-padded up to the field length. Although SEC 1 states that the
  390|       |    // Field-Element-to-Octet-String conversion also pads, OpenSSL mis-encodes
  391|       |    // |a| and |b|, so this comparison must allow omitting leading zeros. (This
  392|       |    // is relevant for P-521 whose |b| has a leading 0.)
  393|    541|    if (integers_equal(&prime, curve->params, param_len) &&
  ------------------
  |  Branch (393:9): [True: 119, False: 422]
  ------------------
  394|    541|        integers_equal(&a, curve->params + param_len, param_len) &&
  ------------------
  |  Branch (394:9): [True: 89, False: 30]
  ------------------
  395|    541|        integers_equal(&b, curve->params + param_len * 2, param_len) &&
  ------------------
  |  Branch (395:9): [True: 67, False: 22]
  ------------------
  396|    541|        integers_equal(&base_x, curve->params + param_len * 3, param_len) &&
  ------------------
  |  Branch (396:9): [True: 43, False: 24]
  ------------------
  397|    541|        integers_equal(&base_y, curve->params + param_len * 4, param_len) &&
  ------------------
  |  Branch (397:9): [True: 27, False: 16]
  ------------------
  398|    541|        integers_equal(&order, curve->params + param_len * 5, param_len)) {
  ------------------
  |  Branch (398:9): [True: 11, False: 16]
  ------------------
  399|     11|      return EC_GROUP_new_by_curve_name(curve->nid);
  400|     11|    }
  401|    541|  }
  402|       |
  403|    127|  OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|    127|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  404|    127|  return NULL;
  405|    138|}
ec_asn1.c:parse_explicit_prime_curve:
  249|    634|                                      CBS *out_base_y, CBS *out_order) {
  250|       |  // See RFC 3279, section 2.3.5. Note that RFC 3279 calls this structure an
  251|       |  // ECParameters while RFC 5480 calls it a SpecifiedECDomain.
  252|    634|  CBS params, field_id, field_type, curve, base, cofactor;
  253|    634|  int has_cofactor;
  254|    634|  uint64_t version;
  255|    634|  if (!CBS_get_asn1(in, &params, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    634|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    634|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    634|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (255:7): [True: 5, False: 629]
  ------------------
  256|    634|      !CBS_get_asn1_uint64(&params, &version) ||
  ------------------
  |  Branch (256:7): [True: 21, False: 608]
  ------------------
  257|    634|      version != 1 ||
  ------------------
  |  Branch (257:7): [True: 117, False: 491]
  ------------------
  258|    634|      !CBS_get_asn1(&params, &field_id, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    491|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    491|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    491|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (258:7): [True: 5, False: 486]
  ------------------
  259|    634|      !CBS_get_asn1(&field_id, &field_type, CBS_ASN1_OBJECT) ||
  ------------------
  |  |  219|    486|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (259:7): [True: 3, False: 483]
  ------------------
  260|    634|      CBS_len(&field_type) != sizeof(kPrimeField) ||
  ------------------
  |  Branch (260:7): [True: 8, False: 475]
  ------------------
  261|    634|      OPENSSL_memcmp(CBS_data(&field_type), kPrimeField, sizeof(kPrimeField)) !=
  ------------------
  |  Branch (261:7): [True: 4, False: 471]
  ------------------
  262|    475|          0 ||
  263|    634|      !CBS_get_asn1(&field_id, out_prime, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|    471|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (263:7): [True: 3, False: 468]
  ------------------
  264|    634|      !CBS_is_unsigned_asn1_integer(out_prime) ||
  ------------------
  |  Branch (264:7): [True: 31, False: 437]
  ------------------
  265|    634|      CBS_len(&field_id) != 0 ||
  ------------------
  |  Branch (265:7): [True: 7, False: 430]
  ------------------
  266|    634|      !CBS_get_asn1(&params, &curve, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|    430|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|    430|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|    430|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (266:7): [True: 10, False: 420]
  ------------------
  267|    634|      !CBS_get_asn1(&curve, out_a, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|    420|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (267:7): [True: 3, False: 417]
  ------------------
  268|    634|      !CBS_get_asn1(&curve, out_b, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|    417|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (268:7): [True: 3, False: 414]
  ------------------
  269|       |      // |curve| has an optional BIT STRING seed which we ignore.
  270|    634|      !CBS_get_optional_asn1(&curve, NULL, NULL, CBS_ASN1_BITSTRING) ||
  ------------------
  |  |  216|    414|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (270:7): [True: 3, False: 411]
  ------------------
  271|    634|      CBS_len(&curve) != 0 ||
  ------------------
  |  Branch (271:7): [True: 196, False: 215]
  ------------------
  272|    634|      !CBS_get_asn1(&params, &base, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|    215|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (272:7): [True: 3, False: 212]
  ------------------
  273|    634|      !CBS_get_asn1(&params, out_order, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|    212|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (273:7): [True: 4, False: 208]
  ------------------
  274|    634|      !CBS_is_unsigned_asn1_integer(out_order) ||
  ------------------
  |  Branch (274:7): [True: 4, False: 204]
  ------------------
  275|    634|      !CBS_get_optional_asn1(&params, &cofactor, &has_cofactor,
  ------------------
  |  Branch (275:7): [True: 3, False: 201]
  ------------------
  276|    204|                             CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|    204|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  277|    634|      CBS_len(&params) != 0) {
  ------------------
  |  Branch (277:7): [True: 23, False: 178]
  ------------------
  278|    456|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|    456|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  279|    456|    return 0;
  280|    456|  }
  281|       |
  282|    178|  if (has_cofactor) {
  ------------------
  |  Branch (282:7): [True: 58, False: 120]
  ------------------
  283|       |    // We only support prime-order curves so the cofactor must be one.
  284|     58|    if (CBS_len(&cofactor) != 1 ||
  ------------------
  |  Branch (284:9): [True: 10, False: 48]
  ------------------
  285|     58|        CBS_data(&cofactor)[0] != 1) {
  ------------------
  |  Branch (285:9): [True: 10, False: 38]
  ------------------
  286|     20|      OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  287|     20|      return 0;
  288|     20|    }
  289|     58|  }
  290|       |
  291|       |  // Require that the base point use uncompressed form.
  292|    158|  uint8_t form;
  293|    158|  if (!CBS_get_u8(&base, &form) || form != POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (293:7): [True: 8, False: 150]
  |  Branch (293:36): [True: 5, False: 145]
  ------------------
  294|     13|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_FORM);
  ------------------
  |  |  441|     13|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  295|     13|    return 0;
  296|     13|  }
  297|       |
  298|    145|  if (CBS_len(&base) % 2 != 0) {
  ------------------
  |  Branch (298:7): [True: 7, False: 138]
  ------------------
  299|      7|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      7|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  300|      7|    return 0;
  301|      7|  }
  302|    138|  size_t field_len = CBS_len(&base) / 2;
  303|    138|  CBS_init(out_base_x, CBS_data(&base), field_len);
  304|    138|  CBS_init(out_base_y, CBS_data(&base) + field_len, field_len);
  305|       |
  306|    138|  return 1;
  307|    145|}
ec_asn1.c:integers_equal:
  311|    886|static int integers_equal(const CBS *a, const uint8_t *b, size_t b_len) {
  312|       |  // Remove leading zeros from |a| and |b|.
  313|    886|  CBS a_copy = *a;
  314|  2.73k|  while (CBS_len(&a_copy) > 0 && CBS_data(&a_copy)[0] == 0) {
  ------------------
  |  Branch (314:10): [True: 2.69k, False: 32]
  |  Branch (314:34): [True: 1.84k, False: 854]
  ------------------
  315|  1.84k|    CBS_skip(&a_copy, 1);
  316|  1.84k|  }
  317|    900|  while (b_len > 0 && b[0] == 0) {
  ------------------
  |  Branch (317:10): [True: 900, False: 0]
  |  Branch (317:23): [True: 14, False: 886]
  ------------------
  318|     14|    b++;
  319|     14|    b_len--;
  320|     14|  }
  321|    886|  return CBS_mem_equal(&a_copy, b, b_len);
  322|    886|}

METHOD_ref:
   86|  2.20k|void METHOD_ref(void *method_in) {
   87|  2.20k|  assert(((struct openssl_method_common_st*) method_in)->is_static);
   88|  2.20k|}
METHOD_unref:
   90|  2.20k|void METHOD_unref(void *method_in) {
   91|  2.20k|  struct openssl_method_common_st *method = method_in;
   92|       |
   93|  2.20k|  if (method == NULL) {
  ------------------
  |  Branch (93:7): [True: 0, False: 2.20k]
  ------------------
   94|      0|    return;
   95|      0|  }
   96|  2.20k|  assert(method->is_static);
   97|  2.20k|}

ERR_peek_last_error:
  328|    192|uint32_t ERR_peek_last_error(void) {
  329|    192|  return get_error_values(0 /* peek */, 1 /* top */, NULL, NULL, NULL, NULL);
  330|    192|}
ERR_clear_error:
  341|  14.5k|void ERR_clear_error(void) {
  342|  14.5k|  ERR_STATE *const state = err_get_state();
  343|  14.5k|  unsigned i;
  344|       |
  345|  14.5k|  if (state == NULL) {
  ------------------
  |  Branch (345:7): [True: 0, False: 14.5k]
  ------------------
  346|      0|    return;
  347|      0|  }
  348|       |
  349|   246k|  for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |  477|   246k|#define ERR_NUM_ERRORS 16
  ------------------
  |  Branch (349:15): [True: 232k, False: 14.5k]
  ------------------
  350|   232k|    err_clear(&state->errors[i]);
  351|   232k|  }
  352|  14.5k|  free(state->to_free);
  353|  14.5k|  state->to_free = NULL;
  354|       |
  355|  14.5k|  state->top = state->bottom = 0;
  356|  14.5k|}
ERR_put_error:
  657|  15.0k|                   unsigned line) {
  658|  15.0k|  ERR_STATE *const state = err_get_state();
  659|  15.0k|  struct err_error_st *error;
  660|       |
  661|  15.0k|  if (state == NULL) {
  ------------------
  |  Branch (661:7): [True: 0, False: 15.0k]
  ------------------
  662|      0|    return;
  663|      0|  }
  664|       |
  665|  15.0k|  if (library == ERR_LIB_SYS && reason == 0) {
  ------------------
  |  Branch (665:7): [True: 0, False: 15.0k]
  |  Branch (665:33): [True: 0, False: 0]
  ------------------
  666|       |#if defined(OPENSSL_WINDOWS)
  667|       |    reason = GetLastError();
  668|       |#else
  669|      0|    reason = errno;
  670|      0|#endif
  671|      0|  }
  672|       |
  673|  15.0k|  state->top = (state->top + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|  15.0k|#define ERR_NUM_ERRORS 16
  ------------------
  674|  15.0k|  if (state->top == state->bottom) {
  ------------------
  |  Branch (674:7): [True: 0, False: 15.0k]
  ------------------
  675|      0|    state->bottom = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|      0|#define ERR_NUM_ERRORS 16
  ------------------
  676|      0|  }
  677|       |
  678|  15.0k|  error = &state->errors[state->top];
  679|  15.0k|  err_clear(error);
  680|  15.0k|  error->file = file;
  681|  15.0k|  error->line = line;
  682|  15.0k|  error->packed = ERR_PACK(library, reason);
  ------------------
  |  |  480|  15.0k|  (((((uint32_t)(lib)) & 0xff) << 24) | ((((uint32_t)(reason)) & 0xfff)))
  ------------------
  683|  15.0k|}
err.c:get_error_values:
  231|    192|                                 const char **data, int *flags) {
  232|    192|  unsigned i = 0;
  233|    192|  ERR_STATE *state;
  234|    192|  struct err_error_st *error;
  235|    192|  uint32_t ret;
  236|       |
  237|    192|  state = err_get_state();
  238|    192|  if (state == NULL || state->bottom == state->top) {
  ------------------
  |  Branch (238:7): [True: 0, False: 192]
  |  Branch (238:24): [True: 0, False: 192]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|    192|  if (top) {
  ------------------
  |  Branch (242:7): [True: 192, False: 0]
  ------------------
  243|    192|    assert(!inc);
  244|       |    // last error
  245|    192|    i = state->top;
  246|    192|  } else {
  247|      0|    i = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|      0|#define ERR_NUM_ERRORS 16
  ------------------
  248|      0|  }
  249|       |
  250|    192|  error = &state->errors[i];
  251|    192|  ret = error->packed;
  252|       |
  253|    192|  if (file != NULL && line != NULL) {
  ------------------
  |  Branch (253:7): [True: 0, False: 192]
  |  Branch (253:23): [True: 0, False: 0]
  ------------------
  254|      0|    if (error->file == NULL) {
  ------------------
  |  Branch (254:9): [True: 0, False: 0]
  ------------------
  255|      0|      *file = "NA";
  256|      0|      *line = 0;
  257|      0|    } else {
  258|      0|      *file = error->file;
  259|      0|      *line = error->line;
  260|      0|    }
  261|      0|  }
  262|       |
  263|    192|  if (data != NULL) {
  ------------------
  |  Branch (263:7): [True: 0, False: 192]
  ------------------
  264|      0|    if (error->data == NULL) {
  ------------------
  |  Branch (264:9): [True: 0, False: 0]
  ------------------
  265|      0|      *data = "";
  266|      0|      if (flags != NULL) {
  ------------------
  |  Branch (266:11): [True: 0, False: 0]
  ------------------
  267|      0|        *flags = 0;
  268|      0|      }
  269|      0|    } else {
  270|      0|      *data = error->data;
  271|      0|      if (flags != NULL) {
  ------------------
  |  Branch (271:11): [True: 0, False: 0]
  ------------------
  272|       |        // Without |ERR_FLAG_MALLOCED|, rust-openssl assumes the string has a
  273|       |        // static lifetime. In both cases, we retain ownership of the string,
  274|       |        // and the caller is not expected to free it.
  275|      0|        *flags = ERR_FLAG_STRING | ERR_FLAG_MALLOCED;
  ------------------
  |  |  188|      0|#define ERR_FLAG_STRING 1
  ------------------
                      *flags = ERR_FLAG_STRING | ERR_FLAG_MALLOCED;
  ------------------
  |  |  197|      0|#define ERR_FLAG_MALLOCED 2
  ------------------
  276|      0|      }
  277|       |      // If this error is being removed, take ownership of data from
  278|       |      // the error. The semantics are such that the caller doesn't
  279|       |      // take ownership either. Instead the error system takes
  280|       |      // ownership and retains it until the next call that affects the
  281|       |      // error queue.
  282|      0|      if (inc) {
  ------------------
  |  Branch (282:11): [True: 0, False: 0]
  ------------------
  283|      0|        if (error->data != NULL) {
  ------------------
  |  Branch (283:13): [True: 0, False: 0]
  ------------------
  284|      0|          free(state->to_free);
  285|      0|          state->to_free = error->data;
  286|      0|        }
  287|      0|        error->data = NULL;
  288|      0|      }
  289|      0|    }
  290|      0|  }
  291|       |
  292|    192|  if (inc) {
  ------------------
  |  Branch (292:7): [True: 0, False: 192]
  ------------------
  293|      0|    assert(!top);
  294|      0|    err_clear(error);
  295|      0|    state->bottom = i;
  296|      0|  }
  297|       |
  298|    192|  return ret;
  299|    192|}
err.c:err_get_state:
  213|  29.7k|static ERR_STATE *err_get_state(void) {
  214|  29.7k|  ERR_STATE *state = CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_ERR);
  215|  29.7k|  if (state == NULL) {
  ------------------
  |  Branch (215:7): [True: 1, False: 29.7k]
  ------------------
  216|      1|    state = malloc(sizeof(ERR_STATE));
  217|      1|    if (state == NULL) {
  ------------------
  |  Branch (217:9): [True: 0, False: 1]
  ------------------
  218|      0|      return NULL;
  219|      0|    }
  220|      1|    OPENSSL_memset(state, 0, sizeof(ERR_STATE));
  221|      1|    if (!CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_ERR, state,
  ------------------
  |  Branch (221:9): [True: 0, False: 1]
  ------------------
  222|      1|                                 err_state_free)) {
  223|      0|      return NULL;
  224|      0|    }
  225|      1|  }
  226|       |
  227|  29.7k|  return state;
  228|  29.7k|}
err.c:err_clear:
  168|   247k|static void err_clear(struct err_error_st *error) {
  169|   247k|  free(error->data);
  170|   247k|  OPENSSL_memset(error, 0, sizeof(struct err_error_st));
  171|   247k|}

EVP_PKEY_new:
   83|  5.82k|EVP_PKEY *EVP_PKEY_new(void) {
   84|  5.82k|  EVP_PKEY *ret;
   85|       |
   86|  5.82k|  ret = OPENSSL_malloc(sizeof(EVP_PKEY));
   87|  5.82k|  if (ret == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 5.82k]
  ------------------
   88|      0|    return NULL;
   89|      0|  }
   90|       |
   91|  5.82k|  OPENSSL_memset(ret, 0, sizeof(EVP_PKEY));
   92|  5.82k|  ret->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  5.82k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  5.82k|#define NID_undef 0
  |  |  ------------------
  ------------------
   93|  5.82k|  ret->references = 1;
   94|       |
   95|  5.82k|  return ret;
   96|  5.82k|}
EVP_PKEY_free:
  106|  10.1k|void EVP_PKEY_free(EVP_PKEY *pkey) {
  107|  10.1k|  if (pkey == NULL) {
  ------------------
  |  Branch (107:7): [True: 4.32k, False: 5.82k]
  ------------------
  108|  4.32k|    return;
  109|  4.32k|  }
  110|       |
  111|  5.82k|  if (!CRYPTO_refcount_dec_and_test_zero(&pkey->references)) {
  ------------------
  |  Branch (111:7): [True: 0, False: 5.82k]
  ------------------
  112|      0|    return;
  113|      0|  }
  114|       |
  115|  5.82k|  free_it(pkey);
  116|  5.82k|  OPENSSL_free(pkey);
  117|  5.82k|}
EVP_PKEY_assign_RSA:
  248|      1|int EVP_PKEY_assign_RSA(EVP_PKEY *pkey, RSA *key) {
  249|      1|  return EVP_PKEY_assign(pkey, EVP_PKEY_RSA, key);
  ------------------
  |  |  175|      1|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|      1|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  250|      1|}
EVP_PKEY_assign_DSA:
  276|    430|int EVP_PKEY_assign_DSA(EVP_PKEY *pkey, DSA *key) {
  277|    430|  return EVP_PKEY_assign(pkey, EVP_PKEY_DSA, key);
  ------------------
  |  |  177|    430|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|    430|#define NID_dsa 116
  |  |  ------------------
  ------------------
  278|    430|}
EVP_PKEY_assign_EC_KEY:
  304|     82|int EVP_PKEY_assign_EC_KEY(EVP_PKEY *pkey, EC_KEY *key) {
  305|     82|  return EVP_PKEY_assign(pkey, EVP_PKEY_EC, key);
  ------------------
  |  |  178|     82|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|     82|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  306|     82|}
EVP_PKEY_assign:
  327|    513|int EVP_PKEY_assign(EVP_PKEY *pkey, int type, void *key) {
  328|    513|  if (!EVP_PKEY_set_type(pkey, type)) {
  ------------------
  |  Branch (328:7): [True: 0, False: 513]
  ------------------
  329|      0|    return 0;
  330|      0|  }
  331|    513|  pkey->pkey = key;
  332|    513|  return key != NULL;
  333|    513|}
EVP_PKEY_set_type:
  335|  2.00k|int EVP_PKEY_set_type(EVP_PKEY *pkey, int type) {
  336|  2.00k|  const EVP_PKEY_ASN1_METHOD *ameth;
  337|       |
  338|  2.00k|  if (pkey && pkey->pkey) {
  ------------------
  |  Branch (338:7): [True: 2.00k, False: 0]
  |  Branch (338:15): [True: 0, False: 2.00k]
  ------------------
  339|      0|    free_it(pkey);
  340|      0|  }
  341|       |
  342|  2.00k|  ameth = evp_pkey_asn1_find(type);
  343|  2.00k|  if (ameth == NULL) {
  ------------------
  |  Branch (343:7): [True: 0, False: 2.00k]
  ------------------
  344|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|    ERR_add_error_dataf("algorithm %d", type);
  346|      0|    return 0;
  347|      0|  }
  348|       |
  349|  2.00k|  if (pkey) {
  ------------------
  |  Branch (349:7): [True: 2.00k, False: 0]
  ------------------
  350|  2.00k|    pkey->ameth = ameth;
  351|  2.00k|    pkey->type = pkey->ameth->pkey_id;
  352|  2.00k|  }
  353|       |
  354|  2.00k|  return 1;
  355|  2.00k|}
evp.c:free_it:
   98|  5.82k|static void free_it(EVP_PKEY *pkey) {
   99|  5.82k|  if (pkey->ameth && pkey->ameth->pkey_free) {
  ------------------
  |  Branch (99:7): [True: 1.49k, False: 4.32k]
  |  Branch (99:22): [True: 1.49k, False: 0]
  ------------------
  100|  1.49k|    pkey->ameth->pkey_free(pkey);
  101|  1.49k|    pkey->pkey = NULL;
  102|  1.49k|    pkey->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  1.49k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  1.49k|#define NID_undef 0
  |  |  ------------------
  ------------------
  103|  1.49k|  }
  104|  5.82k|}
evp.c:evp_pkey_asn1_find:
  215|  2.00k|static const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int nid) {
  216|  2.00k|  switch (nid) {
  217|    115|    case EVP_PKEY_RSA:
  ------------------
  |  |  175|    115|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|    115|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  |  Branch (217:5): [True: 115, False: 1.88k]
  ------------------
  218|    115|      return &rsa_asn1_meth;
  219|    721|    case EVP_PKEY_EC:
  ------------------
  |  |  178|    721|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|    721|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (219:5): [True: 721, False: 1.28k]
  ------------------
  220|    721|      return &ec_asn1_meth;
  221|    955|    case EVP_PKEY_DSA:
  ------------------
  |  |  177|    955|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|    955|#define NID_dsa 116
  |  |  ------------------
  ------------------
  |  Branch (221:5): [True: 955, False: 1.04k]
  ------------------
  222|    955|      return &dsa_asn1_meth;
  223|     67|    case EVP_PKEY_ED25519:
  ------------------
  |  |  179|     67|#define EVP_PKEY_ED25519 NID_ED25519
  |  |  ------------------
  |  |  |  | 4199|     67|#define NID_ED25519 949
  |  |  ------------------
  ------------------
  |  Branch (223:5): [True: 67, False: 1.93k]
  ------------------
  224|     67|      return &ed25519_asn1_meth;
  225|    144|    case EVP_PKEY_X25519:
  ------------------
  |  |  180|    144|#define EVP_PKEY_X25519 NID_X25519
  |  |  ------------------
  |  |  |  | 4195|    144|#define NID_X25519 948
  |  |  ------------------
  ------------------
  |  Branch (225:5): [True: 144, False: 1.85k]
  ------------------
  226|    144|      return &x25519_asn1_meth;
  227|      0|    default:
  ------------------
  |  Branch (227:5): [True: 0, False: 2.00k]
  ------------------
  228|      0|      return NULL;
  229|  2.00k|  }
  230|  2.00k|}

EVP_parse_private_key:
  154|  9.31k|EVP_PKEY *EVP_parse_private_key(CBS *cbs) {
  155|       |  // Parse the PrivateKeyInfo.
  156|  9.31k|  CBS pkcs8, algorithm, key;
  157|  9.31k|  uint64_t version;
  158|  9.31k|  int type;
  159|  9.31k|  if (!CBS_get_asn1(cbs, &pkcs8, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  9.31k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  9.31k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  9.31k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (159:7): [True: 1.04k, False: 8.27k]
  ------------------
  160|  9.31k|      !CBS_get_asn1_uint64(&pkcs8, &version) ||
  ------------------
  |  Branch (160:7): [True: 420, False: 7.85k]
  ------------------
  161|  9.31k|      version != 0 ||
  ------------------
  |  Branch (161:7): [True: 3.97k, False: 3.87k]
  ------------------
  162|  9.31k|      !CBS_get_asn1(&pkcs8, &algorithm, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  3.87k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  3.87k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  3.87k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (162:7): [True: 2.22k, False: 1.65k]
  ------------------
  163|  9.31k|      !CBS_get_asn1(&pkcs8, &key, CBS_ASN1_OCTETSTRING)) {
  ------------------
  |  |  217|  1.65k|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (163:7): [True: 46, False: 1.61k]
  ------------------
  164|  7.70k|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|  7.70k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  165|  7.70k|    return NULL;
  166|  7.70k|  }
  167|  1.61k|  if (!parse_key_type(&algorithm, &type)) {
  ------------------
  |  Branch (167:7): [True: 122, False: 1.48k]
  ------------------
  168|    122|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|    122|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|    122|    return NULL;
  170|    122|  }
  171|       |
  172|       |  // A PrivateKeyInfo ends with a SET of Attributes which we ignore.
  173|       |
  174|       |  // Set up an |EVP_PKEY| of the appropriate type.
  175|  1.48k|  EVP_PKEY *ret = EVP_PKEY_new();
  176|  1.48k|  if (ret == NULL ||
  ------------------
  |  Branch (176:7): [True: 0, False: 1.48k]
  ------------------
  177|  1.48k|      !EVP_PKEY_set_type(ret, type)) {
  ------------------
  |  Branch (177:7): [True: 0, False: 1.48k]
  ------------------
  178|      0|    goto err;
  179|      0|  }
  180|       |
  181|       |  // Call into the type-specific PrivateKeyInfo decoding function.
  182|  1.48k|  if (ret->ameth->priv_decode == NULL) {
  ------------------
  |  Branch (182:7): [True: 0, False: 1.48k]
  ------------------
  183|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  184|      0|    goto err;
  185|      0|  }
  186|  1.48k|  if (!ret->ameth->priv_decode(ret, &algorithm, &key)) {
  ------------------
  |  Branch (186:7): [True: 828, False: 661]
  ------------------
  187|    828|    goto err;
  188|    828|  }
  189|       |
  190|    661|  return ret;
  191|       |
  192|    828|err:
  193|    828|  EVP_PKEY_free(ret);
  194|    828|  return NULL;
  195|  1.48k|}
d2i_PrivateKey:
  248|  4.33k|                         long len) {
  249|  4.33k|  if (len < 0) {
  ------------------
  |  Branch (249:7): [True: 0, False: 4.33k]
  ------------------
  250|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  251|      0|    return NULL;
  252|      0|  }
  253|       |
  254|       |  // Parse with the legacy format.
  255|  4.33k|  CBS cbs;
  256|  4.33k|  CBS_init(&cbs, *inp, (size_t)len);
  257|  4.33k|  EVP_PKEY *ret = old_priv_decode(&cbs, type);
  258|  4.33k|  if (ret == NULL) {
  ------------------
  |  Branch (258:7): [True: 4.32k, False: 5]
  ------------------
  259|       |    // Try again with PKCS#8.
  260|  4.32k|    ERR_clear_error();
  261|  4.32k|    CBS_init(&cbs, *inp, (size_t)len);
  262|  4.32k|    ret = EVP_parse_private_key(&cbs);
  263|  4.32k|    if (ret == NULL) {
  ------------------
  |  Branch (263:9): [True: 4.32k, False: 0]
  ------------------
  264|  4.32k|      return NULL;
  265|  4.32k|    }
  266|      0|    if (ret->type != type) {
  ------------------
  |  Branch (266:9): [True: 0, False: 0]
  ------------------
  267|      0|      OPENSSL_PUT_ERROR(EVP, EVP_R_DIFFERENT_KEY_TYPES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|      EVP_PKEY_free(ret);
  269|      0|      return NULL;
  270|      0|    }
  271|      0|  }
  272|       |
  273|      5|  if (out != NULL) {
  ------------------
  |  Branch (273:7): [True: 0, False: 5]
  ------------------
  274|      0|    EVP_PKEY_free(*out);
  275|      0|    *out = ret;
  276|      0|  }
  277|      5|  *inp = CBS_data(&cbs);
  278|      5|  return ret;
  279|  4.33k|}
d2i_AutoPrivateKey:
  303|  4.99k|EVP_PKEY *d2i_AutoPrivateKey(EVP_PKEY **out, const uint8_t **inp, long len) {
  304|  4.99k|  if (len < 0) {
  ------------------
  |  Branch (304:7): [True: 0, False: 4.99k]
  ------------------
  305|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  306|      0|    return NULL;
  307|      0|  }
  308|       |
  309|       |  // Parse the input as a PKCS#8 PrivateKeyInfo.
  310|  4.99k|  CBS cbs;
  311|  4.99k|  CBS_init(&cbs, *inp, (size_t)len);
  312|  4.99k|  EVP_PKEY *ret = EVP_parse_private_key(&cbs);
  313|  4.99k|  if (ret != NULL) {
  ------------------
  |  Branch (313:7): [True: 661, False: 4.33k]
  ------------------
  314|    661|    if (out != NULL) {
  ------------------
  |  Branch (314:9): [True: 0, False: 661]
  ------------------
  315|      0|      EVP_PKEY_free(*out);
  316|      0|      *out = ret;
  317|      0|    }
  318|    661|    *inp = CBS_data(&cbs);
  319|    661|    return ret;
  320|    661|  }
  321|  4.33k|  ERR_clear_error();
  322|       |
  323|       |  // Count the elements to determine the legacy key format.
  324|  4.33k|  switch (num_elements(*inp, (size_t)len)) {
  325|  1.75k|    case 4:
  ------------------
  |  Branch (325:5): [True: 1.75k, False: 2.57k]
  ------------------
  326|  1.75k|      return d2i_PrivateKey(EVP_PKEY_EC, out, inp, len);
  ------------------
  |  |  178|  1.75k|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|  1.75k|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  327|       |
  328|    466|    case 6:
  ------------------
  |  Branch (328:5): [True: 466, False: 3.86k]
  ------------------
  329|    466|      return d2i_PrivateKey(EVP_PKEY_DSA, out, inp, len);
  ------------------
  |  |  177|    466|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|    466|#define NID_dsa 116
  |  |  ------------------
  ------------------
  330|       |
  331|  2.10k|    default:
  ------------------
  |  Branch (331:5): [True: 2.10k, False: 2.22k]
  ------------------
  332|  2.10k|      return d2i_PrivateKey(EVP_PKEY_RSA, out, inp, len);
  ------------------
  |  |  175|  2.10k|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|  2.10k|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  333|  4.33k|  }
  334|  4.33k|}
evp_asn1.c:parse_key_type:
   80|  1.61k|static int parse_key_type(CBS *cbs, int *out_type) {
   81|  1.61k|  CBS oid;
   82|  1.61k|  if (!CBS_get_asn1(cbs, &oid, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  1.61k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (82:7): [True: 2, False: 1.60k]
  ------------------
   83|      2|    return 0;
   84|      2|  }
   85|       |
   86|  4.67k|  for (unsigned i = 0; i < OPENSSL_ARRAY_SIZE(kASN1Methods); i++) {
  ------------------
  |  |  221|  4.67k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (86:24): [True: 4.55k, False: 120]
  ------------------
   87|  4.55k|    const EVP_PKEY_ASN1_METHOD *method = kASN1Methods[i];
   88|  4.55k|    if (CBS_len(&oid) == method->oid_len &&
  ------------------
  |  Branch (88:9): [True: 2.35k, False: 2.20k]
  ------------------
   89|  4.55k|        OPENSSL_memcmp(CBS_data(&oid), method->oid, method->oid_len) == 0) {
  ------------------
  |  Branch (89:9): [True: 1.48k, False: 863]
  ------------------
   90|  1.48k|      *out_type = method->pkey_id;
   91|  1.48k|      return 1;
   92|  1.48k|    }
   93|  4.55k|  }
   94|       |
   95|    120|  return 0;
   96|  1.60k|}
evp_asn1.c:old_priv_decode:
  206|  4.33k|static EVP_PKEY *old_priv_decode(CBS *cbs, int type) {
  207|  4.33k|  EVP_PKEY *ret = EVP_PKEY_new();
  208|  4.33k|  if (ret == NULL) {
  ------------------
  |  Branch (208:7): [True: 0, False: 4.33k]
  ------------------
  209|      0|    return NULL;
  210|      0|  }
  211|       |
  212|  4.33k|  switch (type) {
  213|  1.75k|    case EVP_PKEY_EC: {
  ------------------
  |  |  178|  1.75k|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|  1.75k|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (213:5): [True: 1.75k, False: 2.57k]
  ------------------
  214|  1.75k|      EC_KEY *ec_key = EC_KEY_parse_private_key(cbs, NULL);
  215|  1.75k|      if (ec_key == NULL || !EVP_PKEY_assign_EC_KEY(ret, ec_key)) {
  ------------------
  |  Branch (215:11): [True: 1.75k, False: 1]
  |  Branch (215:29): [True: 0, False: 1]
  ------------------
  216|  1.75k|        EC_KEY_free(ec_key);
  217|  1.75k|        goto err;
  218|  1.75k|      }
  219|      1|      return ret;
  220|  1.75k|    }
  221|    466|    case EVP_PKEY_DSA: {
  ------------------
  |  |  177|    466|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|    466|#define NID_dsa 116
  |  |  ------------------
  ------------------
  |  Branch (221:5): [True: 466, False: 3.86k]
  ------------------
  222|    466|      DSA *dsa = DSA_parse_private_key(cbs);
  223|    466|      if (dsa == NULL || !EVP_PKEY_assign_DSA(ret, dsa)) {
  ------------------
  |  Branch (223:11): [True: 463, False: 3]
  |  Branch (223:26): [True: 0, False: 3]
  ------------------
  224|    463|        DSA_free(dsa);
  225|    463|        goto err;
  226|    463|      }
  227|      3|      return ret;
  228|    466|    }
  229|  2.10k|    case EVP_PKEY_RSA: {
  ------------------
  |  |  175|  2.10k|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|  2.10k|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  |  Branch (229:5): [True: 2.10k, False: 2.22k]
  ------------------
  230|  2.10k|      RSA *rsa = RSA_parse_private_key(cbs);
  231|  2.10k|      if (rsa == NULL || !EVP_PKEY_assign_RSA(ret, rsa)) {
  ------------------
  |  Branch (231:11): [True: 2.10k, False: 1]
  |  Branch (231:26): [True: 0, False: 1]
  ------------------
  232|  2.10k|        RSA_free(rsa);
  233|  2.10k|        goto err;
  234|  2.10k|      }
  235|      1|      return ret;
  236|  2.10k|    }
  237|      0|    default:
  ------------------
  |  Branch (237:5): [True: 0, False: 4.33k]
  ------------------
  238|      0|      OPENSSL_PUT_ERROR(EVP, EVP_R_UNKNOWN_PUBLIC_KEY_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  239|      0|      goto err;
  240|  4.33k|  }
  241|       |
  242|  4.32k|err:
  243|  4.32k|  EVP_PKEY_free(ret);
  244|  4.32k|  return NULL;
  245|  4.33k|}
evp_asn1.c:num_elements:
  283|  4.33k|static size_t num_elements(const uint8_t *in, size_t in_len) {
  284|  4.33k|  CBS cbs, sequence;
  285|  4.33k|  CBS_init(&cbs, in, (size_t)in_len);
  286|       |
  287|  4.33k|  if (!CBS_get_asn1(&cbs, &sequence, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  4.33k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  4.33k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  4.33k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (287:7): [True: 523, False: 3.80k]
  ------------------
  288|    523|    return 0;
  289|    523|  }
  290|       |
  291|  3.80k|  size_t count = 0;
  292|  23.5k|  while (CBS_len(&sequence) > 0) {
  ------------------
  |  Branch (292:10): [True: 19.9k, False: 3.55k]
  ------------------
  293|  19.9k|    if (!CBS_get_any_asn1_element(&sequence, NULL, NULL, NULL)) {
  ------------------
  |  Branch (293:9): [True: 258, False: 19.7k]
  ------------------
  294|    258|      return 0;
  295|    258|    }
  296|       |
  297|  19.7k|    count++;
  298|  19.7k|  }
  299|       |
  300|  3.55k|  return count;
  301|  3.80k|}

p_dsa_asn1.c:dsa_priv_decode:
  128|    525|static int dsa_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  129|       |  // See PKCS#11, v2.40, section 2.5.
  130|       |
  131|       |  // Decode parameters.
  132|    525|  BN_CTX *ctx = NULL;
  133|    525|  DSA *dsa = DSA_parse_parameters(params);
  134|    525|  if (dsa == NULL || CBS_len(params) != 0) {
  ------------------
  |  Branch (134:7): [True: 74, False: 451]
  |  Branch (134:22): [True: 8, False: 443]
  ------------------
  135|     82|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     82|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  136|     82|    goto err;
  137|     82|  }
  138|       |
  139|    443|  dsa->priv_key = BN_new();
  140|    443|  if (dsa->priv_key == NULL) {
  ------------------
  |  Branch (140:7): [True: 0, False: 443]
  ------------------
  141|      0|    goto err;
  142|      0|  }
  143|    443|  if (!BN_parse_asn1_unsigned(key, dsa->priv_key) ||
  ------------------
  |  Branch (143:7): [True: 6, False: 437]
  ------------------
  144|    443|      CBS_len(key) != 0) {
  ------------------
  |  Branch (144:7): [True: 2, False: 435]
  ------------------
  145|      8|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      8|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  146|      8|    goto err;
  147|      8|  }
  148|       |
  149|       |  // To avoid DoS attacks when importing private keys, check bounds on |dsa|.
  150|       |  // This bounds |dsa->priv_key| against |dsa->q| and bounds |dsa->q|'s bit
  151|       |  // width.
  152|    435|  if (!dsa_check_key(dsa)) {
  ------------------
  |  Branch (152:7): [True: 8, False: 427]
  ------------------
  153|      8|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      8|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  154|      8|    goto err;
  155|      8|  }
  156|       |
  157|       |  // Calculate the public key.
  158|    427|  ctx = BN_CTX_new();
  159|    427|  dsa->pub_key = BN_new();
  160|    427|  if (ctx == NULL || dsa->pub_key == NULL ||
  ------------------
  |  Branch (160:7): [True: 0, False: 427]
  |  Branch (160:22): [True: 0, False: 427]
  ------------------
  161|    427|      !BN_mod_exp_mont_consttime(dsa->pub_key, dsa->g, dsa->priv_key, dsa->p,
  ------------------
  |  Branch (161:7): [True: 0, False: 427]
  ------------------
  162|    427|                                 ctx, NULL)) {
  163|      0|    goto err;
  164|      0|  }
  165|       |
  166|    427|  BN_CTX_free(ctx);
  167|    427|  EVP_PKEY_assign_DSA(out, dsa);
  168|    427|  return 1;
  169|       |
  170|     98|err:
  171|     98|  BN_CTX_free(ctx);
  172|     98|  DSA_free(dsa);
  173|     98|  return 0;
  174|    427|}
p_dsa_asn1.c:int_dsa_free:
  259|    528|static void int_dsa_free(EVP_PKEY *pkey) {
  260|    528|  DSA_free(pkey->pkey);
  261|    528|  pkey->pkey = NULL;
  262|    528|}

p_ec_asn1.c:eckey_priv_decode:
  136|    639|static int eckey_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  137|       |  // See RFC 5915.
  138|    639|  EC_GROUP *group = EC_KEY_parse_parameters(params);
  139|    639|  if (group == NULL || CBS_len(params) != 0) {
  ------------------
  |  Branch (139:7): [True: 260, False: 379]
  |  Branch (139:24): [True: 14, False: 365]
  ------------------
  140|    274|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    274|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|    274|    EC_GROUP_free(group);
  142|    274|    return 0;
  143|    274|  }
  144|       |
  145|    365|  EC_KEY *ec_key = EC_KEY_parse_private_key(key, group);
  146|    365|  EC_GROUP_free(group);
  147|    365|  if (ec_key == NULL || CBS_len(key) != 0) {
  ------------------
  |  Branch (147:7): [True: 206, False: 159]
  |  Branch (147:25): [True: 78, False: 81]
  ------------------
  148|    284|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    284|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  149|    284|    EC_KEY_free(ec_key);
  150|    284|    return 0;
  151|    284|  }
  152|       |
  153|     81|  EVP_PKEY_assign_EC_KEY(out, ec_key);
  154|     81|  return 1;
  155|    365|}
p_ec_asn1.c:int_ec_free:
  264|    640|static void int_ec_free(EVP_PKEY *pkey) {
  265|    640|  EC_KEY_free(pkey->pkey);
  266|    640|  pkey->pkey = NULL;
  267|    640|}

p_ed25519_asn1.c:ed25519_priv_decode:
  154|     67|static int ed25519_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  155|       |  // See RFC 8410, section 7.
  156|       |
  157|       |  // Parameters must be empty. The key is a 32-byte value wrapped in an extra
  158|       |  // OCTET STRING layer.
  159|     67|  CBS inner;
  160|     67|  if (CBS_len(params) != 0 ||
  ------------------
  |  Branch (160:7): [True: 2, False: 65]
  ------------------
  161|     67|      !CBS_get_asn1(key, &inner, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|     65|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (161:7): [True: 6, False: 59]
  ------------------
  162|     67|      CBS_len(key) != 0) {
  ------------------
  |  Branch (162:7): [True: 12, False: 47]
  ------------------
  163|     20|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  164|     20|    return 0;
  165|     20|  }
  166|       |
  167|     47|  return ed25519_set_priv_raw(out, CBS_data(&inner), CBS_len(&inner));
  168|     67|}
p_ed25519_asn1.c:ed25519_set_priv_raw:
   31|     47|static int ed25519_set_priv_raw(EVP_PKEY *pkey, const uint8_t *in, size_t len) {
   32|     47|  if (len != 32) {
  ------------------
  |  Branch (32:7): [True: 12, False: 35]
  ------------------
   33|     12|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     12|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|     12|    return 0;
   35|     12|  }
   36|       |
   37|     35|  ED25519_KEY *key = OPENSSL_malloc(sizeof(ED25519_KEY));
   38|     35|  if (key == NULL) {
  ------------------
  |  Branch (38:7): [True: 0, False: 35]
  ------------------
   39|      0|    return 0;
   40|      0|  }
   41|       |
   42|       |  // The RFC 8032 encoding stores only the 32-byte seed, so we must recover the
   43|       |  // full representation which we use from it.
   44|     35|  uint8_t pubkey_unused[32];
   45|     35|  ED25519_keypair_from_seed(pubkey_unused, key->key, in);
   46|     35|  key->has_private = 1;
   47|       |
   48|     35|  ed25519_free(pkey);
   49|     35|  pkey->pkey = key;
   50|     35|  return 1;
   51|     35|}
p_ed25519_asn1.c:ed25519_free:
   26|    102|static void ed25519_free(EVP_PKEY *pkey) {
   27|    102|  OPENSSL_free(pkey->pkey);
   28|    102|  pkey->pkey = NULL;
   29|    102|}

p_rsa_asn1.c:rsa_priv_decode:
  138|    114|static int rsa_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  139|       |  // Per RFC 3447, A.1, the parameters have type NULL.
  140|    114|  CBS null;
  141|    114|  if (!CBS_get_asn1(params, &null, CBS_ASN1_NULL) ||
  ------------------
  |  |  218|    114|#define CBS_ASN1_NULL 0x5u
  ------------------
  |  Branch (141:7): [True: 4, False: 110]
  ------------------
  142|    114|      CBS_len(&null) != 0 ||
  ------------------
  |  Branch (142:7): [True: 12, False: 98]
  ------------------
  143|    114|      CBS_len(params) != 0) {
  ------------------
  |  Branch (143:7): [True: 4, False: 94]
  ------------------
  144|     20|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     20|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  145|     20|    return 0;
  146|     20|  }
  147|       |
  148|     94|  RSA *rsa = RSA_parse_private_key(key);
  149|     94|  if (rsa == NULL || CBS_len(key) != 0) {
  ------------------
  |  Branch (149:7): [True: 94, False: 0]
  |  Branch (149:22): [True: 0, False: 0]
  ------------------
  150|     94|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     94|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|     94|    RSA_free(rsa);
  152|     94|    return 0;
  153|     94|  }
  154|       |
  155|      0|  EVP_PKEY_assign_RSA(out, rsa);
  156|      0|  return 1;
  157|     94|}
p_rsa_asn1.c:int_rsa_free:
  174|    115|static void int_rsa_free(EVP_PKEY *pkey) {
  175|    115|  RSA_free(pkey->pkey);
  176|    115|  pkey->pkey = NULL;
  177|    115|}

p_x25519_asn1.c:x25519_priv_decode:
  166|    144|static int x25519_priv_decode(EVP_PKEY *out, CBS *params, CBS *key) {
  167|       |  // See RFC 8410, section 7.
  168|       |
  169|       |  // Parameters must be empty. The key is a 32-byte value wrapped in an extra
  170|       |  // OCTET STRING layer.
  171|    144|  CBS inner;
  172|    144|  if (CBS_len(params) != 0 ||
  ------------------
  |  Branch (172:7): [True: 2, False: 142]
  ------------------
  173|    144|      !CBS_get_asn1(key, &inner, CBS_ASN1_OCTETSTRING) ||
  ------------------
  |  |  217|    142|#define CBS_ASN1_OCTETSTRING 0x4u
  ------------------
  |  Branch (173:7): [True: 2, False: 140]
  ------------------
  174|    144|      CBS_len(key) != 0) {
  ------------------
  |  Branch (174:7): [True: 10, False: 130]
  ------------------
  175|     14|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     14|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  176|     14|    return 0;
  177|     14|  }
  178|       |
  179|    130|  return x25519_set_priv_raw(out, CBS_data(&inner), CBS_len(&inner));
  180|    144|}
p_x25519_asn1.c:x25519_set_priv_raw:
   31|    130|static int x25519_set_priv_raw(EVP_PKEY *pkey, const uint8_t *in, size_t len) {
   32|    130|  if (len != 32) {
  ------------------
  |  Branch (32:7): [True: 12, False: 118]
  ------------------
   33|     12|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|     12|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|     12|    return 0;
   35|     12|  }
   36|       |
   37|    118|  X25519_KEY *key = OPENSSL_malloc(sizeof(X25519_KEY));
   38|    118|  if (key == NULL) {
  ------------------
  |  Branch (38:7): [True: 0, False: 118]
  ------------------
   39|      0|    return 0;
   40|      0|  }
   41|       |
   42|    118|  OPENSSL_memcpy(key->priv, in, 32);
   43|    118|  X25519_public_from_private(key->pub, key->priv);
   44|    118|  key->has_private = 1;
   45|       |
   46|    118|  x25519_free(pkey);
   47|    118|  pkey->pkey = key;
   48|    118|  return 1;
   49|    118|}
p_x25519_asn1.c:x25519_free:
   26|    262|static void x25519_free(EVP_PKEY *pkey) {
   27|    262|  OPENSSL_free(pkey->pkey);
   28|    262|  pkey->pkey = NULL;
   29|    262|}

CRYPTO_new_ex_data:
  206|  4.42k|void CRYPTO_new_ex_data(CRYPTO_EX_DATA *ad) {
  207|  4.42k|  ad->sk = NULL;
  208|  4.42k|}
CRYPTO_free_ex_data:
  211|  4.42k|                         CRYPTO_EX_DATA *ad) {
  212|  4.42k|  if (ad->sk == NULL) {
  ------------------
  |  Branch (212:7): [True: 4.42k, False: 0]
  ------------------
  213|       |    // Nothing to do.
  214|  4.42k|    return;
  215|  4.42k|  }
  216|       |
  217|      0|  uint32_t num_funcs = CRYPTO_atomic_load_u32(&ex_data_class->num_funcs);
  218|       |  // |CRYPTO_get_ex_new_index| will not allocate indices beyond |INT_MAX|.
  219|      0|  assert(num_funcs <= (size_t)(INT_MAX - ex_data_class->num_reserved));
  220|       |
  221|       |  // Defer dereferencing |ex_data_class->funcs| and |funcs->next|. It must come
  222|       |  // after the |num_funcs| comparison to be correctly synchronized.
  223|      0|  CRYPTO_EX_DATA_FUNCS *const *funcs = &ex_data_class->funcs;
  224|      0|  for (uint32_t i = 0; i < num_funcs; i++) {
  ------------------
  |  Branch (224:24): [True: 0, False: 0]
  ------------------
  225|      0|    if ((*funcs)->free_func != NULL) {
  ------------------
  |  Branch (225:9): [True: 0, False: 0]
  ------------------
  226|      0|      int index = (int)i + ex_data_class->num_reserved;
  227|      0|      void *ptr = CRYPTO_get_ex_data(ad, index);
  228|      0|      (*funcs)->free_func(obj, ptr, ad, index, (*funcs)->argl, (*funcs)->argp);
  229|      0|    }
  230|      0|    funcs = &(*funcs)->next;
  231|      0|  }
  232|       |
  233|      0|  sk_void_free(ad->sk);
  234|      0|  ad->sk = NULL;
  235|      0|}

BN_add_word:
  138|     91|int BN_add_word(BIGNUM *a, BN_ULONG w) {
  139|     91|  BN_ULONG l;
  140|     91|  int i;
  141|       |
  142|       |  // degenerate case: w is zero
  143|     91|  if (!w) {
  ------------------
  |  Branch (143:7): [True: 0, False: 91]
  ------------------
  144|      0|    return 1;
  145|      0|  }
  146|       |
  147|       |  // degenerate case: a is zero
  148|     91|  if (BN_is_zero(a)) {
  ------------------
  |  Branch (148:7): [True: 0, False: 91]
  ------------------
  149|      0|    return BN_set_word(a, w);
  150|      0|  }
  151|       |
  152|       |  // handle 'a' when negative
  153|     91|  if (a->neg) {
  ------------------
  |  Branch (153:7): [True: 0, False: 91]
  ------------------
  154|      0|    a->neg = 0;
  155|      0|    i = BN_sub_word(a, w);
  156|      0|    if (!BN_is_zero(a)) {
  ------------------
  |  Branch (156:9): [True: 0, False: 0]
  ------------------
  157|      0|      a->neg = !(a->neg);
  158|      0|    }
  159|      0|    return i;
  160|      0|  }
  161|       |
  162|    256|  for (i = 0; w != 0 && i < a->width; i++) {
  ------------------
  |  Branch (162:15): [True: 165, False: 91]
  |  Branch (162:25): [True: 165, False: 0]
  ------------------
  163|    165|    a->d[i] = l = a->d[i] + w;
  164|    165|    w = (w > l) ? 1 : 0;
  ------------------
  |  Branch (164:9): [True: 74, False: 91]
  ------------------
  165|    165|  }
  166|       |
  167|     91|  if (w && i == a->width) {
  ------------------
  |  Branch (167:7): [True: 0, False: 91]
  |  Branch (167:12): [True: 0, False: 0]
  ------------------
  168|      0|    if (!bn_wexpand(a, a->width + 1)) {
  ------------------
  |  Branch (168:9): [True: 0, False: 0]
  ------------------
  169|      0|      return 0;
  170|      0|    }
  171|      0|    a->width++;
  172|      0|    a->d[i] = w;
  173|      0|  }
  174|       |
  175|     91|  return 1;
  176|     91|}
BN_sub:
  178|      4|int BN_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  179|      4|  int add = 0, neg = 0;
  180|      4|  const BIGNUM *tmp;
  181|       |
  182|       |  //  a -  b	a-b
  183|       |  //  a - -b	a+b
  184|       |  // -a -  b	-(a+b)
  185|       |  // -a - -b	b-a
  186|      4|  if (a->neg) {
  ------------------
  |  Branch (186:7): [True: 0, False: 4]
  ------------------
  187|      0|    if (b->neg) {
  ------------------
  |  Branch (187:9): [True: 0, False: 0]
  ------------------
  188|      0|      tmp = a;
  189|      0|      a = b;
  190|      0|      b = tmp;
  191|      0|    } else {
  192|      0|      add = 1;
  193|      0|      neg = 1;
  194|      0|    }
  195|      4|  } else {
  196|      4|    if (b->neg) {
  ------------------
  |  Branch (196:9): [True: 0, False: 4]
  ------------------
  197|      0|      add = 1;
  198|      0|      neg = 0;
  199|      0|    }
  200|      4|  }
  201|       |
  202|      4|  if (add) {
  ------------------
  |  Branch (202:7): [True: 0, False: 4]
  ------------------
  203|      0|    if (!BN_uadd(r, a, b)) {
  ------------------
  |  Branch (203:9): [True: 0, False: 0]
  ------------------
  204|      0|      return 0;
  205|      0|    }
  206|       |
  207|      0|    r->neg = neg;
  208|      0|    return 1;
  209|      0|  }
  210|       |
  211|      4|  if (BN_ucmp(a, b) < 0) {
  ------------------
  |  Branch (211:7): [True: 0, False: 4]
  ------------------
  212|      0|    if (!BN_usub(r, b, a)) {
  ------------------
  |  Branch (212:9): [True: 0, False: 0]
  ------------------
  213|      0|      return 0;
  214|      0|    }
  215|      0|    r->neg = 1;
  216|      4|  } else {
  217|      4|    if (!BN_usub(r, a, b)) {
  ------------------
  |  Branch (217:9): [True: 0, False: 4]
  ------------------
  218|      0|      return 0;
  219|      0|    }
  220|      4|    r->neg = 0;
  221|      4|  }
  222|       |
  223|      4|  return 1;
  224|      4|}
bn_usub_consttime:
  226|    742|int bn_usub_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  227|       |  // |b| may have more words than |a| given non-minimal inputs, but all words
  228|       |  // beyond |a->width| must then be zero.
  229|    742|  int b_width = b->width;
  230|    742|  if (b_width > a->width) {
  ------------------
  |  Branch (230:7): [True: 0, False: 742]
  ------------------
  231|      0|    if (!bn_fits_in_words(b, a->width)) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  233|      0|      return 0;
  234|      0|    }
  235|      0|    b_width = a->width;
  236|      0|  }
  237|       |
  238|    742|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (238:7): [True: 0, False: 742]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|    742|  BN_ULONG borrow = bn_sub_words(r->d, a->d, b->d, b_width);
  243|  6.72k|  for (int i = b_width; i < a->width; i++) {
  ------------------
  |  Branch (243:25): [True: 5.98k, False: 742]
  ------------------
  244|       |    // |r| and |a| may alias, so use a temporary.
  245|  5.98k|    BN_ULONG tmp = a->d[i];
  246|  5.98k|    r->d[i] = a->d[i] - borrow;
  247|  5.98k|    borrow = tmp < r->d[i];
  248|  5.98k|  }
  249|       |
  250|    742|  if (borrow) {
  ------------------
  |  Branch (250:7): [True: 0, False: 742]
  ------------------
  251|      0|    OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  252|      0|    return 0;
  253|      0|  }
  254|       |
  255|    742|  r->width = a->width;
  256|    742|  r->neg = 0;
  257|    742|  return 1;
  258|    742|}
BN_usub:
  260|    296|int BN_usub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  261|    296|  if (!bn_usub_consttime(r, a, b)) {
  ------------------
  |  Branch (261:7): [True: 0, False: 296]
  ------------------
  262|      0|    return 0;
  263|      0|  }
  264|    296|  bn_set_minimal_width(r);
  265|    296|  return 1;
  266|    296|}

bn_mul_add_words:
   98|   153k|                          BN_ULONG w) {
   99|   153k|  BN_ULONG c1 = 0;
  100|       |
  101|   153k|  if (num == 0) {
  ------------------
  |  Branch (101:7): [True: 0, False: 153k]
  ------------------
  102|      0|    return (c1);
  103|      0|  }
  104|       |
  105|   376k|  while (num & ~3) {
  ------------------
  |  Branch (105:10): [True: 222k, False: 153k]
  ------------------
  106|   222k|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|   222k|  do {                                                                     \
  |  |   70|   222k|    register BN_ULONG high, low;                                           \
  |  |   71|   222k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   222k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   222k|            : "a"(low), "g"(0)                                             \
  |  |   75|   222k|            : "cc");                                                       \
  |  |   76|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   222k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   222k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   222k|            : "cc");                                                       \
  |  |   80|   222k|    (carry) = high;                                                        \
  |  |   81|   222k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  107|   222k|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|   222k|  do {                                                                     \
  |  |   70|   222k|    register BN_ULONG high, low;                                           \
  |  |   71|   222k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   222k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   222k|            : "a"(low), "g"(0)                                             \
  |  |   75|   222k|            : "cc");                                                       \
  |  |   76|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   222k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   222k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   222k|            : "cc");                                                       \
  |  |   80|   222k|    (carry) = high;                                                        \
  |  |   81|   222k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  108|   222k|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|   222k|  do {                                                                     \
  |  |   70|   222k|    register BN_ULONG high, low;                                           \
  |  |   71|   222k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   222k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   222k|            : "a"(low), "g"(0)                                             \
  |  |   75|   222k|            : "cc");                                                       \
  |  |   76|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   222k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   222k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   222k|            : "cc");                                                       \
  |  |   80|   222k|    (carry) = high;                                                        \
  |  |   81|   222k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  109|   222k|    mul_add(rp[3], ap[3], w, c1);
  ------------------
  |  |   69|   222k|  do {                                                                     \
  |  |   70|   222k|    register BN_ULONG high, low;                                           \
  |  |   71|   222k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|   222k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|   222k|            : "a"(low), "g"(0)                                             \
  |  |   75|   222k|            : "cc");                                                       \
  |  |   76|   222k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|   222k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|   222k|            : "r"(carry), "g"(0)                                           \
  |  |   79|   222k|            : "cc");                                                       \
  |  |   80|   222k|    (carry) = high;                                                        \
  |  |   81|   222k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  110|   222k|    ap += 4;
  111|   222k|    rp += 4;
  112|   222k|    num -= 4;
  113|   222k|  }
  114|   153k|  if (num) {
  ------------------
  |  Branch (114:7): [True: 6.43k, False: 147k]
  ------------------
  115|  6.43k|    mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   69|  6.43k|  do {                                                                     \
  |  |   70|  6.43k|    register BN_ULONG high, low;                                           \
  |  |   71|  6.43k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  6.43k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  6.43k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  6.43k|            : "a"(low), "g"(0)                                             \
  |  |   75|  6.43k|            : "cc");                                                       \
  |  |   76|  6.43k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  6.43k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  6.43k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  6.43k|            : "cc");                                                       \
  |  |   80|  6.43k|    (carry) = high;                                                        \
  |  |   81|  6.43k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|  6.43k|    if (--num == 0) {
  ------------------
  |  Branch (116:9): [True: 806, False: 5.63k]
  ------------------
  117|    806|      return c1;
  118|    806|    }
  119|  5.63k|    mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   69|  5.63k|  do {                                                                     \
  |  |   70|  5.63k|    register BN_ULONG high, low;                                           \
  |  |   71|  5.63k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  5.63k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  5.63k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  5.63k|            : "a"(low), "g"(0)                                             \
  |  |   75|  5.63k|            : "cc");                                                       \
  |  |   76|  5.63k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  5.63k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  5.63k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  5.63k|            : "cc");                                                       \
  |  |   80|  5.63k|    (carry) = high;                                                        \
  |  |   81|  5.63k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  120|  5.63k|    if (--num == 0) {
  ------------------
  |  Branch (120:9): [True: 423, False: 5.20k]
  ------------------
  121|    423|      return c1;
  122|    423|    }
  123|  5.20k|    mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   69|  5.20k|  do {                                                                     \
  |  |   70|  5.20k|    register BN_ULONG high, low;                                           \
  |  |   71|  5.20k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "m"(a) : "cc"); \
  |  |   72|  5.20k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   73|  5.20k|            : "+r"(carry), "+d"(high)                                      \
  |  |   74|  5.20k|            : "a"(low), "g"(0)                                             \
  |  |   75|  5.20k|            : "cc");                                                       \
  |  |   76|  5.20k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   77|  5.20k|            : "+m"(r), "+d"(high)                                          \
  |  |   78|  5.20k|            : "r"(carry), "g"(0)                                           \
  |  |   79|  5.20k|            : "cc");                                                       \
  |  |   80|  5.20k|    (carry) = high;                                                        \
  |  |   81|  5.20k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  124|  5.20k|    return c1;
  125|  5.63k|  }
  126|       |
  127|   147k|  return c1;
  128|   153k|}
bn_mul_words:
  131|  5.37M|                      BN_ULONG w) {
  132|  5.37M|  BN_ULONG c1 = 0;
  133|       |
  134|  5.37M|  if (num == 0) {
  ------------------
  |  Branch (134:7): [True: 0, False: 5.37M]
  ------------------
  135|      0|    return c1;
  136|      0|  }
  137|       |
  138|  10.7M|  while (num & ~3) {
  ------------------
  |  Branch (138:10): [True: 5.34M, False: 5.37M]
  ------------------
  139|  5.34M|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|  5.34M|  do {                                                                     \
  |  |   85|  5.34M|    register BN_ULONG high, low;                                           \
  |  |   86|  5.34M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  5.34M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  5.34M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  5.34M|            : "a"(low), "g"(0)                                             \
  |  |   90|  5.34M|            : "cc");                                                       \
  |  |   91|  5.34M|    (r) = (carry);                                                         \
  |  |   92|  5.34M|    (carry) = high;                                                        \
  |  |   93|  5.34M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  140|  5.34M|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|  5.34M|  do {                                                                     \
  |  |   85|  5.34M|    register BN_ULONG high, low;                                           \
  |  |   86|  5.34M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  5.34M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  5.34M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  5.34M|            : "a"(low), "g"(0)                                             \
  |  |   90|  5.34M|            : "cc");                                                       \
  |  |   91|  5.34M|    (r) = (carry);                                                         \
  |  |   92|  5.34M|    (carry) = high;                                                        \
  |  |   93|  5.34M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  141|  5.34M|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|  5.34M|  do {                                                                     \
  |  |   85|  5.34M|    register BN_ULONG high, low;                                           \
  |  |   86|  5.34M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  5.34M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  5.34M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  5.34M|            : "a"(low), "g"(0)                                             \
  |  |   90|  5.34M|            : "cc");                                                       \
  |  |   91|  5.34M|    (r) = (carry);                                                         \
  |  |   92|  5.34M|    (carry) = high;                                                        \
  |  |   93|  5.34M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  142|  5.34M|    mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   84|  5.34M|  do {                                                                     \
  |  |   85|  5.34M|    register BN_ULONG high, low;                                           \
  |  |   86|  5.34M|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  5.34M|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  5.34M|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  5.34M|            : "a"(low), "g"(0)                                             \
  |  |   90|  5.34M|            : "cc");                                                       \
  |  |   91|  5.34M|    (r) = (carry);                                                         \
  |  |   92|  5.34M|    (carry) = high;                                                        \
  |  |   93|  5.34M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  143|  5.34M|    ap += 4;
  144|  5.34M|    rp += 4;
  145|  5.34M|    num -= 4;
  146|  5.34M|  }
  147|  5.37M|  if (num) {
  ------------------
  |  Branch (147:7): [True: 39.4k, False: 5.34M]
  ------------------
  148|  39.4k|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|  39.4k|  do {                                                                     \
  |  |   85|  39.4k|    register BN_ULONG high, low;                                           \
  |  |   86|  39.4k|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|  39.4k|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|  39.4k|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|  39.4k|            : "a"(low), "g"(0)                                             \
  |  |   90|  39.4k|            : "cc");                                                       \
  |  |   91|  39.4k|    (r) = (carry);                                                         \
  |  |   92|  39.4k|    (carry) = high;                                                        \
  |  |   93|  39.4k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  149|  39.4k|    if (--num == 0) {
  ------------------
  |  Branch (149:9): [True: 39.0k, False: 378]
  ------------------
  150|  39.0k|      return c1;
  151|  39.0k|    }
  152|    378|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|    378|  do {                                                                     \
  |  |   85|    378|    register BN_ULONG high, low;                                           \
  |  |   86|    378|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|    378|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|    378|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|    378|            : "a"(low), "g"(0)                                             \
  |  |   90|    378|            : "cc");                                                       \
  |  |   91|    378|    (r) = (carry);                                                         \
  |  |   92|    378|    (carry) = high;                                                        \
  |  |   93|    378|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|    378|    if (--num == 0) {
  ------------------
  |  Branch (153:9): [True: 33, False: 345]
  ------------------
  154|     33|      return c1;
  155|     33|    }
  156|    345|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|    345|  do {                                                                     \
  |  |   85|    345|    register BN_ULONG high, low;                                           \
  |  |   86|    345|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|    345|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|    345|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|    345|            : "a"(low), "g"(0)                                             \
  |  |   90|    345|            : "cc");                                                       \
  |  |   91|    345|    (r) = (carry);                                                         \
  |  |   92|    345|    (carry) = high;                                                        \
  |  |   93|    345|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|    345|  }
  158|  5.34M|  return c1;
  159|  5.37M|}
bn_sqr_words:
  161|     39|void bn_sqr_words(BN_ULONG *r, const BN_ULONG *a, size_t n) {
  162|     39|  if (n == 0) {
  ------------------
  |  Branch (162:7): [True: 0, False: 39]
  ------------------
  163|      0|    return;
  164|      0|  }
  165|       |
  166|     67|  while (n & ~3) {
  ------------------
  |  Branch (166:10): [True: 28, False: 39]
  ------------------
  167|     28|    sqr(r[0], r[1], a[0]);
  ------------------
  |  |   95|     28|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  168|     28|    sqr(r[2], r[3], a[1]);
  ------------------
  |  |   95|     28|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  169|     28|    sqr(r[4], r[5], a[2]);
  ------------------
  |  |   95|     28|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  170|     28|    sqr(r[6], r[7], a[3]);
  ------------------
  |  |   95|     28|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  171|     28|    a += 4;
  172|     28|    r += 8;
  173|     28|    n -= 4;
  174|     28|  }
  175|     39|  if (n) {
  ------------------
  |  Branch (175:7): [True: 39, False: 0]
  ------------------
  176|     39|    sqr(r[0], r[1], a[0]);
  ------------------
  |  |   95|     39|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  177|     39|    if (--n == 0) {
  ------------------
  |  Branch (177:9): [True: 0, False: 39]
  ------------------
  178|      0|      return;
  179|      0|    }
  180|     39|    sqr(r[2], r[3], a[1]);
  ------------------
  |  |   95|     39|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  181|     39|    if (--n == 0) {
  ------------------
  |  Branch (181:9): [True: 28, False: 11]
  ------------------
  182|     28|      return;
  183|     28|    }
  184|     11|    sqr(r[4], r[5], a[2]);
  ------------------
  |  |   95|     11|#define sqr(r0, r1, a) __asm__("mulq %2" : "=a"(r0), "=d"(r1) : "a"(a) : "cc");
  ------------------
  185|     11|  }
  186|     39|}
bn_add_words:
  189|  4.11M|                      size_t n) {
  190|  4.11M|  BN_ULONG ret;
  191|  4.11M|  size_t i = 0;
  192|       |
  193|  4.11M|  if (n == 0) {
  ------------------
  |  Branch (193:7): [True: 0, False: 4.11M]
  ------------------
  194|      0|    return 0;
  195|      0|  }
  196|       |
  197|  4.11M|  __asm__ volatile (
  198|  4.11M|      "	subq	%0,%0		\n"  // clear carry
  199|  4.11M|      "	jmp	1f		\n"
  200|  4.11M|      ".p2align 4			\n"
  201|  4.11M|      "1:"
  202|  4.11M|      "	movq	(%4,%2,8),%0	\n"
  203|  4.11M|      "	adcq	(%5,%2,8),%0	\n"
  204|  4.11M|      "	movq	%0,(%3,%2,8)	\n"
  205|  4.11M|      "	lea	1(%2),%2	\n"
  206|  4.11M|      "	dec	%1		\n"
  207|  4.11M|      "	jnz	1b		\n"
  208|  4.11M|      "	sbbq	%0,%0		\n"
  209|  4.11M|      : "=&r"(ret), "+c"(n), "+r"(i)
  210|  4.11M|      : "r"(rp), "r"(ap), "r"(bp)
  211|  4.11M|      : "cc", "memory");
  212|       |
  213|  4.11M|  return ret & 1;
  214|  4.11M|}
bn_sub_words:
  217|  9.43M|                      size_t n) {
  218|  9.43M|  BN_ULONG ret;
  219|  9.43M|  size_t i = 0;
  220|       |
  221|  9.43M|  if (n == 0) {
  ------------------
  |  Branch (221:7): [True: 380, False: 9.43M]
  ------------------
  222|    380|    return 0;
  223|    380|  }
  224|       |
  225|  9.43M|  __asm__ volatile (
  226|  9.43M|      "	subq	%0,%0		\n"  // clear borrow
  227|  9.43M|      "	jmp	1f		\n"
  228|  9.43M|      ".p2align 4			\n"
  229|  9.43M|      "1:"
  230|  9.43M|      "	movq	(%4,%2,8),%0	\n"
  231|  9.43M|      "	sbbq	(%5,%2,8),%0	\n"
  232|  9.43M|      "	movq	%0,(%3,%2,8)	\n"
  233|  9.43M|      "	lea	1(%2),%2	\n"
  234|  9.43M|      "	dec	%1		\n"
  235|  9.43M|      "	jnz	1b		\n"
  236|  9.43M|      "	sbbq	%0,%0		\n"
  237|  9.43M|      : "=&r"(ret), "+c"(n), "+r"(i)
  238|  9.43M|      : "r"(rp), "r"(ap), "r"(bp)
  239|  9.43M|      : "cc", "memory");
  240|       |
  241|  9.43M|  return ret & 1;
  242|  9.43M|}
bn_mul_comba8:
  287|  2.17k|void bn_mul_comba8(BN_ULONG r[16], const BN_ULONG a[8], const BN_ULONG b[8]) {
  288|  2.17k|  BN_ULONG c1, c2, c3;
  289|       |
  290|  2.17k|  c1 = 0;
  291|  2.17k|  c2 = 0;
  292|  2.17k|  c3 = 0;
  293|  2.17k|  mul_add_c(a[0], b[0], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  294|  2.17k|  r[0] = c1;
  295|  2.17k|  c1 = 0;
  296|  2.17k|  mul_add_c(a[0], b[1], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  297|  2.17k|  mul_add_c(a[1], b[0], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  298|  2.17k|  r[1] = c2;
  299|  2.17k|  c2 = 0;
  300|  2.17k|  mul_add_c(a[2], b[0], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  301|  2.17k|  mul_add_c(a[1], b[1], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  302|  2.17k|  mul_add_c(a[0], b[2], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  303|  2.17k|  r[2] = c3;
  304|  2.17k|  c3 = 0;
  305|  2.17k|  mul_add_c(a[0], b[3], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  306|  2.17k|  mul_add_c(a[1], b[2], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  307|  2.17k|  mul_add_c(a[2], b[1], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  308|  2.17k|  mul_add_c(a[3], b[0], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  309|  2.17k|  r[3] = c1;
  310|  2.17k|  c1 = 0;
  311|  2.17k|  mul_add_c(a[4], b[0], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  312|  2.17k|  mul_add_c(a[3], b[1], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  313|  2.17k|  mul_add_c(a[2], b[2], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  314|  2.17k|  mul_add_c(a[1], b[3], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  315|  2.17k|  mul_add_c(a[0], b[4], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  316|  2.17k|  r[4] = c2;
  317|  2.17k|  c2 = 0;
  318|  2.17k|  mul_add_c(a[0], b[5], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  319|  2.17k|  mul_add_c(a[1], b[4], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  320|  2.17k|  mul_add_c(a[2], b[3], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  321|  2.17k|  mul_add_c(a[3], b[2], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  322|  2.17k|  mul_add_c(a[4], b[1], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  323|  2.17k|  mul_add_c(a[5], b[0], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  324|  2.17k|  r[5] = c3;
  325|  2.17k|  c3 = 0;
  326|  2.17k|  mul_add_c(a[6], b[0], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  327|  2.17k|  mul_add_c(a[5], b[1], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  328|  2.17k|  mul_add_c(a[4], b[2], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  329|  2.17k|  mul_add_c(a[3], b[3], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  330|  2.17k|  mul_add_c(a[2], b[4], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  331|  2.17k|  mul_add_c(a[1], b[5], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  332|  2.17k|  mul_add_c(a[0], b[6], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  333|  2.17k|  r[6] = c1;
  334|  2.17k|  c1 = 0;
  335|  2.17k|  mul_add_c(a[0], b[7], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  336|  2.17k|  mul_add_c(a[1], b[6], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  337|  2.17k|  mul_add_c(a[2], b[5], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  338|  2.17k|  mul_add_c(a[3], b[4], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  339|  2.17k|  mul_add_c(a[4], b[3], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  340|  2.17k|  mul_add_c(a[5], b[2], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  341|  2.17k|  mul_add_c(a[6], b[1], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  342|  2.17k|  mul_add_c(a[7], b[0], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  343|  2.17k|  r[7] = c2;
  344|  2.17k|  c2 = 0;
  345|  2.17k|  mul_add_c(a[7], b[1], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  346|  2.17k|  mul_add_c(a[6], b[2], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  347|  2.17k|  mul_add_c(a[5], b[3], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  348|  2.17k|  mul_add_c(a[4], b[4], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  349|  2.17k|  mul_add_c(a[3], b[5], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  350|  2.17k|  mul_add_c(a[2], b[6], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  351|  2.17k|  mul_add_c(a[1], b[7], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  352|  2.17k|  r[8] = c3;
  353|  2.17k|  c3 = 0;
  354|  2.17k|  mul_add_c(a[2], b[7], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  355|  2.17k|  mul_add_c(a[3], b[6], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  356|  2.17k|  mul_add_c(a[4], b[5], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  357|  2.17k|  mul_add_c(a[5], b[4], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  358|  2.17k|  mul_add_c(a[6], b[3], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  359|  2.17k|  mul_add_c(a[7], b[2], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  360|  2.17k|  r[9] = c1;
  361|  2.17k|  c1 = 0;
  362|  2.17k|  mul_add_c(a[7], b[3], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  363|  2.17k|  mul_add_c(a[6], b[4], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  364|  2.17k|  mul_add_c(a[5], b[5], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  365|  2.17k|  mul_add_c(a[4], b[6], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  366|  2.17k|  mul_add_c(a[3], b[7], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  367|  2.17k|  r[10] = c2;
  368|  2.17k|  c2 = 0;
  369|  2.17k|  mul_add_c(a[4], b[7], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  370|  2.17k|  mul_add_c(a[5], b[6], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  371|  2.17k|  mul_add_c(a[6], b[5], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  372|  2.17k|  mul_add_c(a[7], b[4], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  373|  2.17k|  r[11] = c3;
  374|  2.17k|  c3 = 0;
  375|  2.17k|  mul_add_c(a[7], b[5], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  376|  2.17k|  mul_add_c(a[6], b[6], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  377|  2.17k|  mul_add_c(a[5], b[7], c1, c2, c3);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  378|  2.17k|  r[12] = c1;
  379|  2.17k|  c1 = 0;
  380|  2.17k|  mul_add_c(a[6], b[7], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  381|  2.17k|  mul_add_c(a[7], b[6], c2, c3, c1);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  382|  2.17k|  r[13] = c2;
  383|  2.17k|  c2 = 0;
  384|  2.17k|  mul_add_c(a[7], b[7], c3, c1, c2);
  ------------------
  |  |  252|  2.17k|  do {                                                               \
  |  |  253|  2.17k|    BN_ULONG t1, t2;                                                 \
  |  |  254|  2.17k|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|  2.17k|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|  2.17k|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|  2.17k|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|  2.17k|            : "cc");                                                 \
  |  |  259|  2.17k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  385|  2.17k|  r[14] = c3;
  386|  2.17k|  r[15] = c1;
  387|  2.17k|}
bn_sqr_comba4:
  501|  1.01M|void bn_sqr_comba4(BN_ULONG r[8], const BN_ULONG a[4]) {
  502|  1.01M|  BN_ULONG c1, c2, c3;
  503|       |
  504|  1.01M|  c1 = 0;
  505|  1.01M|  c2 = 0;
  506|  1.01M|  c3 = 0;
  507|  1.01M|  sqr_add_c(a, 0, c1, c2, c3);
  ------------------
  |  |  262|  1.01M|  do {                                                            \
  |  |  263|  1.01M|    BN_ULONG t1, t2;                                              \
  |  |  264|  1.01M|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|  1.01M|            : "cc");                                              \
  |  |  269|  1.01M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  508|  1.01M|  r[0] = c1;
  509|  1.01M|  c1 = 0;
  510|  1.01M|  sqr_add_c2(a, 1, 0, c2, c3, c1);
  ------------------
  |  |  285|  1.01M|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|  1.01M|  do {                                                               \
  |  |  |  |  273|  1.01M|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|  1.01M|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|  1.01M|            : "cc");                                                 \
  |  |  |  |  279|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|  1.01M|            : "cc");                                                 \
  |  |  |  |  283|  1.01M|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  511|  1.01M|  r[1] = c2;
  512|  1.01M|  c2 = 0;
  513|  1.01M|  sqr_add_c(a, 1, c3, c1, c2);
  ------------------
  |  |  262|  1.01M|  do {                                                            \
  |  |  263|  1.01M|    BN_ULONG t1, t2;                                              \
  |  |  264|  1.01M|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|  1.01M|            : "cc");                                              \
  |  |  269|  1.01M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  514|  1.01M|  sqr_add_c2(a, 2, 0, c3, c1, c2);
  ------------------
  |  |  285|  1.01M|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|  1.01M|  do {                                                               \
  |  |  |  |  273|  1.01M|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|  1.01M|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|  1.01M|            : "cc");                                                 \
  |  |  |  |  279|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|  1.01M|            : "cc");                                                 \
  |  |  |  |  283|  1.01M|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  515|  1.01M|  r[2] = c3;
  516|  1.01M|  c3 = 0;
  517|  1.01M|  sqr_add_c2(a, 3, 0, c1, c2, c3);
  ------------------
  |  |  285|  1.01M|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|  1.01M|  do {                                                               \
  |  |  |  |  273|  1.01M|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|  1.01M|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|  1.01M|            : "cc");                                                 \
  |  |  |  |  279|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|  1.01M|            : "cc");                                                 \
  |  |  |  |  283|  1.01M|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  518|  1.01M|  sqr_add_c2(a, 2, 1, c1, c2, c3);
  ------------------
  |  |  285|  1.01M|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|  1.01M|  do {                                                               \
  |  |  |  |  273|  1.01M|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|  1.01M|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|  1.01M|            : "cc");                                                 \
  |  |  |  |  279|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|  1.01M|            : "cc");                                                 \
  |  |  |  |  283|  1.01M|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  519|  1.01M|  r[3] = c1;
  520|  1.01M|  c1 = 0;
  521|  1.01M|  sqr_add_c(a, 2, c2, c3, c1);
  ------------------
  |  |  262|  1.01M|  do {                                                            \
  |  |  263|  1.01M|    BN_ULONG t1, t2;                                              \
  |  |  264|  1.01M|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|  1.01M|            : "cc");                                              \
  |  |  269|  1.01M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  522|  1.01M|  sqr_add_c2(a, 3, 1, c2, c3, c1);
  ------------------
  |  |  285|  1.01M|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|  1.01M|  do {                                                               \
  |  |  |  |  273|  1.01M|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|  1.01M|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|  1.01M|            : "cc");                                                 \
  |  |  |  |  279|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|  1.01M|            : "cc");                                                 \
  |  |  |  |  283|  1.01M|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  523|  1.01M|  r[4] = c2;
  524|  1.01M|  c2 = 0;
  525|  1.01M|  sqr_add_c2(a, 3, 2, c3, c1, c2);
  ------------------
  |  |  285|  1.01M|#define sqr_add_c2(a, i, j, c0, c1, c2) mul_add_c2((a)[i], (a)[j], c0, c1, c2)
  |  |  ------------------
  |  |  |  |  272|  1.01M|  do {                                                               \
  |  |  |  |  273|  1.01M|    BN_ULONG t1, t2;                                                 \
  |  |  |  |  274|  1.01M|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  |  |  275|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  276|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  277|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  278|  1.01M|            : "cc");                                                 \
  |  |  |  |  279|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  |  |  280|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  |  |  281|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  |  |  282|  1.01M|            : "cc");                                                 \
  |  |  |  |  283|  1.01M|  } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (283:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  526|  1.01M|  r[5] = c3;
  527|  1.01M|  c3 = 0;
  528|  1.01M|  sqr_add_c(a, 3, c1, c2, c3);
  ------------------
  |  |  262|  1.01M|  do {                                                            \
  |  |  263|  1.01M|    BN_ULONG t1, t2;                                              \
  |  |  264|  1.01M|    __asm__("mulq %2" : "=a"(t1), "=d"(t2) : "a"((a)[i]) : "cc"); \
  |  |  265|  1.01M|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                  \
  |  |  266|  1.01M|            : "+r"(c0), "+r"(c1), "+r"(c2)                        \
  |  |  267|  1.01M|            : "r"(t1), "r"(t2), "g"(0)                            \
  |  |  268|  1.01M|            : "cc");                                              \
  |  |  269|  1.01M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (269:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  529|  1.01M|  r[6] = c1;
  530|  1.01M|  r[7] = c2;
  531|  1.01M|}

BN_new:
   75|  29.4k|BIGNUM *BN_new(void) {
   76|  29.4k|  BIGNUM *bn = OPENSSL_malloc(sizeof(BIGNUM));
   77|       |
   78|  29.4k|  if (bn == NULL) {
  ------------------
  |  Branch (78:7): [True: 0, False: 29.4k]
  ------------------
   79|      0|    return NULL;
   80|      0|  }
   81|       |
   82|  29.4k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   83|  29.4k|  bn->flags = BN_FLG_MALLOCED;
  ------------------
  |  | 1026|  29.4k|#define BN_FLG_MALLOCED 0x01
  ------------------
   84|       |
   85|  29.4k|  return bn;
   86|  29.4k|}
BN_init:
   90|  5.25k|void BN_init(BIGNUM *bn) {
   91|  5.25k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   92|  5.25k|}
BN_free:
   94|  56.0k|void BN_free(BIGNUM *bn) {
   95|  56.0k|  if (bn == NULL) {
  ------------------
  |  Branch (95:7): [True: 21.3k, False: 34.7k]
  ------------------
   96|  21.3k|    return;
   97|  21.3k|  }
   98|       |
   99|  34.7k|  if ((bn->flags & BN_FLG_STATIC_DATA) == 0) {
  ------------------
  |  | 1027|  34.7k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (99:7): [True: 34.7k, False: 0]
  ------------------
  100|  34.7k|    OPENSSL_free(bn->d);
  101|  34.7k|  }
  102|       |
  103|  34.7k|  if (bn->flags & BN_FLG_MALLOCED) {
  ------------------
  |  | 1026|  34.7k|#define BN_FLG_MALLOCED 0x01
  ------------------
  |  Branch (103:7): [True: 29.4k, False: 5.22k]
  ------------------
  104|  29.4k|    OPENSSL_free(bn);
  105|  29.4k|  } else {
  106|  5.22k|    bn->d = NULL;
  107|  5.22k|  }
  108|  34.7k|}
BN_clear_free:
  110|  4.95k|void BN_clear_free(BIGNUM *bn) {
  111|  4.95k|  BN_free(bn);
  112|  4.95k|}
BN_copy:
  134|  59.4k|BIGNUM *BN_copy(BIGNUM *dest, const BIGNUM *src) {
  135|  59.4k|  if (src == dest) {
  ------------------
  |  Branch (135:7): [True: 1.90k, False: 57.5k]
  ------------------
  136|  1.90k|    return dest;
  137|  1.90k|  }
  138|       |
  139|  57.5k|  if (!bn_wexpand(dest, src->width)) {
  ------------------
  |  Branch (139:7): [True: 0, False: 57.5k]
  ------------------
  140|      0|    return NULL;
  141|      0|  }
  142|       |
  143|  57.5k|  OPENSSL_memcpy(dest->d, src->d, sizeof(src->d[0]) * src->width);
  144|       |
  145|  57.5k|  dest->width = src->width;
  146|  57.5k|  dest->neg = src->neg;
  147|  57.5k|  return dest;
  148|  57.5k|}
BN_num_bits_word:
  170|  1.08M|unsigned BN_num_bits_word(BN_ULONG l) {
  171|       |  // |BN_num_bits| is often called on RSA prime factors. These have public bit
  172|       |  // lengths, but all bits beyond the high bit are secret, so count bits in
  173|       |  // constant time.
  174|  1.08M|  BN_ULONG x, mask;
  175|  1.08M|  int bits = (l != 0);
  176|       |
  177|  1.08M|#if BN_BITS2 > 32
  178|       |  // Look at the upper half of |x|. |x| is at most 64 bits long.
  179|  1.08M|  x = l >> 32;
  180|       |  // Set |mask| to all ones if |x| (the top 32 bits of |l|) is non-zero and all
  181|       |  // all zeros otherwise.
  182|  1.08M|  mask = 0u - x;
  183|  1.08M|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  184|       |  // If |x| is non-zero, the lower half is included in the bit count in full,
  185|       |  // and we count the upper half. Otherwise, we count the lower half.
  186|  1.08M|  bits += 32 & mask;
  187|  1.08M|  l ^= (x ^ l) & mask;  // |l| is |x| if |mask| and remains |l| otherwise.
  188|  1.08M|#endif
  189|       |
  190|       |  // The remaining blocks are analogous iterations at lower powers of two.
  191|  1.08M|  x = l >> 16;
  192|  1.08M|  mask = 0u - x;
  193|  1.08M|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  194|  1.08M|  bits += 16 & mask;
  195|  1.08M|  l ^= (x ^ l) & mask;
  196|       |
  197|  1.08M|  x = l >> 8;
  198|  1.08M|  mask = 0u - x;
  199|  1.08M|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  200|  1.08M|  bits += 8 & mask;
  201|  1.08M|  l ^= (x ^ l) & mask;
  202|       |
  203|  1.08M|  x = l >> 4;
  204|  1.08M|  mask = 0u - x;
  205|  1.08M|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  206|  1.08M|  bits += 4 & mask;
  207|  1.08M|  l ^= (x ^ l) & mask;
  208|       |
  209|  1.08M|  x = l >> 2;
  210|  1.08M|  mask = 0u - x;
  211|  1.08M|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  212|  1.08M|  bits += 2 & mask;
  213|  1.08M|  l ^= (x ^ l) & mask;
  214|       |
  215|  1.08M|  x = l >> 1;
  216|  1.08M|  mask = 0u - x;
  217|  1.08M|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  218|  1.08M|  bits += 1 & mask;
  219|       |
  220|  1.08M|  return bits;
  221|  1.08M|}
BN_num_bits:
  223|  1.08M|unsigned BN_num_bits(const BIGNUM *bn) {
  224|  1.08M|  const int width = bn_minimal_width(bn);
  225|  1.08M|  if (width == 0) {
  ------------------
  |  Branch (225:7): [True: 8, False: 1.08M]
  ------------------
  226|      8|    return 0;
  227|      8|  }
  228|       |
  229|  1.08M|  return (width - 1) * BN_BITS2 + BN_num_bits_word(bn->d[width - 1]);
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  230|  1.08M|}
BN_num_bytes:
  232|  4.04k|unsigned BN_num_bytes(const BIGNUM *bn) {
  233|  4.04k|  return (BN_num_bits(bn) + 7) / 8;
  234|  4.04k|}
BN_zero:
  236|  7.24M|void BN_zero(BIGNUM *bn) {
  237|  7.24M|  bn->width = bn->neg = 0;
  238|  7.24M|}
BN_set_word:
  244|  5.84k|int BN_set_word(BIGNUM *bn, BN_ULONG value) {
  245|  5.84k|  if (value == 0) {
  ------------------
  |  Branch (245:7): [True: 0, False: 5.84k]
  ------------------
  246|      0|    BN_zero(bn);
  247|      0|    return 1;
  248|      0|  }
  249|       |
  250|  5.84k|  if (!bn_wexpand(bn, 1)) {
  ------------------
  |  Branch (250:7): [True: 0, False: 5.84k]
  ------------------
  251|      0|    return 0;
  252|      0|  }
  253|       |
  254|  5.84k|  bn->neg = 0;
  255|  5.84k|  bn->d[0] = value;
  256|  5.84k|  bn->width = 1;
  257|  5.84k|  return 1;
  258|  5.84k|}
bn_fits_in_words:
  306|  3.90M|int bn_fits_in_words(const BIGNUM *bn, size_t num) {
  307|       |  // All words beyond |num| must be zero.
  308|  3.90M|  BN_ULONG mask = 0;
  309|  12.4M|  for (size_t i = num; i < (size_t)bn->width; i++) {
  ------------------
  |  Branch (309:24): [True: 8.53M, False: 3.90M]
  ------------------
  310|  8.53M|    mask |= bn->d[i];
  311|  8.53M|  }
  312|  3.90M|  return mask == 0;
  313|  3.90M|}
bn_copy_words:
  315|  5.71k|int bn_copy_words(BN_ULONG *out, size_t num, const BIGNUM *bn) {
  316|  5.71k|  if (bn->neg) {
  ------------------
  |  Branch (316:7): [True: 0, False: 5.71k]
  ------------------
  317|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  318|      0|    return 0;
  319|      0|  }
  320|       |
  321|  5.71k|  size_t width = (size_t)bn->width;
  322|  5.71k|  if (width > num) {
  ------------------
  |  Branch (322:7): [True: 119, False: 5.59k]
  ------------------
  323|    119|    if (!bn_fits_in_words(bn, num)) {
  ------------------
  |  Branch (323:9): [True: 115, False: 4]
  ------------------
  324|    115|      OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|    115|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  325|    115|      return 0;
  326|    115|    }
  327|      4|    width = num;
  328|      4|  }
  329|       |
  330|  5.59k|  OPENSSL_memset(out, 0, sizeof(BN_ULONG) * num);
  331|  5.59k|  OPENSSL_memcpy(out, bn->d, sizeof(BN_ULONG) * width);
  332|  5.59k|  return 1;
  333|  5.71k|}
BN_is_negative:
  335|  20.1k|int BN_is_negative(const BIGNUM *bn) {
  336|  20.1k|  return bn->neg != 0;
  337|  20.1k|}
BN_set_negative:
  339|      4|void BN_set_negative(BIGNUM *bn, int sign) {
  340|      4|  if (sign && !BN_is_zero(bn)) {
  ------------------
  |  Branch (340:7): [True: 0, False: 4]
  |  Branch (340:15): [True: 0, False: 0]
  ------------------
  341|      0|    bn->neg = 1;
  342|      4|  } else {
  343|      4|    bn->neg = 0;
  344|      4|  }
  345|      4|}
bn_wexpand:
  347|  9.59M|int bn_wexpand(BIGNUM *bn, size_t words) {
  348|  9.59M|  BN_ULONG *a;
  349|       |
  350|  9.59M|  if (words <= (size_t)bn->dmax) {
  ------------------
  |  Branch (350:7): [True: 9.54M, False: 45.0k]
  ------------------
  351|  9.54M|    return 1;
  352|  9.54M|  }
  353|       |
  354|  45.0k|  if (words > BN_MAX_WORDS) {
  ------------------
  |  |   73|  45.0k|#define BN_MAX_WORDS (INT_MAX / (4 * BN_BITS2))
  |  |  ------------------
  |  |  |  |  151|  45.0k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (354:7): [True: 0, False: 45.0k]
  ------------------
  355|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  356|      0|    return 0;
  357|      0|  }
  358|       |
  359|  45.0k|  if (bn->flags & BN_FLG_STATIC_DATA) {
  ------------------
  |  | 1027|  45.0k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (359:7): [True: 0, False: 45.0k]
  ------------------
  360|      0|    OPENSSL_PUT_ERROR(BN, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  361|      0|    return 0;
  362|      0|  }
  363|       |
  364|  45.0k|  a = OPENSSL_malloc(sizeof(BN_ULONG) * words);
  365|  45.0k|  if (a == NULL) {
  ------------------
  |  Branch (365:7): [True: 0, False: 45.0k]
  ------------------
  366|      0|    return 0;
  367|      0|  }
  368|       |
  369|  45.0k|  OPENSSL_memcpy(a, bn->d, sizeof(BN_ULONG) * bn->width);
  370|       |
  371|  45.0k|  OPENSSL_free(bn->d);
  372|  45.0k|  bn->d = a;
  373|  45.0k|  bn->dmax = (int)words;
  374|       |
  375|  45.0k|  return 1;
  376|  45.0k|}
bn_resize_words:
  386|  5.46k|int bn_resize_words(BIGNUM *bn, size_t words) {
  387|  5.46k|  if ((size_t)bn->width <= words) {
  ------------------
  |  Branch (387:7): [True: 5.31k, False: 149]
  ------------------
  388|  5.31k|    if (!bn_wexpand(bn, words)) {
  ------------------
  |  Branch (388:9): [True: 0, False: 5.31k]
  ------------------
  389|      0|      return 0;
  390|      0|    }
  391|  5.31k|    OPENSSL_memset(bn->d + bn->width, 0,
  392|  5.31k|                   (words - bn->width) * sizeof(BN_ULONG));
  393|  5.31k|    bn->width = (int)words;
  394|  5.31k|    return 1;
  395|  5.31k|  }
  396|       |
  397|       |  // All words beyond the new width must be zero.
  398|    149|  if (!bn_fits_in_words(bn, words)) {
  ------------------
  |  Branch (398:7): [True: 0, False: 149]
  ------------------
  399|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  400|      0|    return 0;
  401|      0|  }
  402|    149|  bn->width = (int)words;
  403|    149|  return 1;
  404|    149|}
bn_select_words:
  407|  7.11M|                     const BN_ULONG *b, size_t num) {
  408|  70.3M|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (408:22): [True: 63.2M, False: 7.11M]
  ------------------
  409|  63.2M|    static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  410|  63.2M|                  "crypto_word_t is too small");
  411|  63.2M|    r[i] = constant_time_select_w(mask, a[i], b[i]);
  412|  63.2M|  }
  413|  7.11M|}
bn_minimal_width:
  415|  11.7M|int bn_minimal_width(const BIGNUM *bn) {
  416|  11.7M|  int ret = bn->width;
  417|  21.4M|  while (ret > 0 && bn->d[ret - 1] == 0) {
  ------------------
  |  Branch (417:10): [True: 21.4M, False: 12.6k]
  |  Branch (417:21): [True: 9.68M, False: 11.7M]
  ------------------
  418|  9.68M|    ret--;
  419|  9.68M|  }
  420|  11.7M|  return ret;
  421|  11.7M|}
bn_set_minimal_width:
  423|  8.56M|void bn_set_minimal_width(BIGNUM *bn) {
  424|  8.56M|  bn->width = bn_minimal_width(bn);
  425|  8.56M|  if (bn->width == 0) {
  ------------------
  |  Branch (425:7): [True: 12.5k, False: 8.55M]
  ------------------
  426|  12.5k|    bn->neg = 0;
  427|  12.5k|  }
  428|  8.56M|}
bcm.c:BN_value_one_do_init:
  159|      1|DEFINE_METHOD_FUNCTION(BIGNUM, BN_value_one) {
  160|      1|  static const BN_ULONG kOneLimbs[1] = { 1 };
  161|      1|  out->d = (BN_ULONG*) kOneLimbs;
  162|      1|  out->width = 1;
  163|      1|  out->dmax = 1;
  164|      1|  out->neg = 0;
  165|      1|  out->flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|      1|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  166|      1|}

bn_big_endian_to_words:
   65|  13.8k|                            size_t in_len) {
   66|   127k|  for (size_t i = 0; i < out_len; i++) {
  ------------------
  |  Branch (66:22): [True: 125k, False: 1.19k]
  ------------------
   67|   125k|    if (in_len < sizeof(BN_ULONG)) {
  ------------------
  |  Branch (67:9): [True: 12.7k, False: 113k]
  ------------------
   68|       |      // Load the last partial word.
   69|  12.7k|      BN_ULONG word = 0;
   70|  42.3k|      for (size_t j = 0; j < in_len; j++) {
  ------------------
  |  Branch (70:26): [True: 29.6k, False: 12.7k]
  ------------------
   71|  29.6k|        word = (word << 8) | in[j];
   72|  29.6k|      }
   73|  12.7k|      in_len = 0;
   74|  12.7k|      out[i] = word;
   75|       |      // Fill the remainder with zeros.
   76|  12.7k|      OPENSSL_memset(out + i + 1, 0, (out_len - i - 1) * sizeof(BN_ULONG));
   77|  12.7k|      break;
   78|  12.7k|    }
   79|       |
   80|   113k|    in_len -= sizeof(BN_ULONG);
   81|   113k|    out[i] = CRYPTO_load_word_be(in + in_len);
   82|   113k|  }
   83|       |
   84|       |  // The caller should have sized the output to avoid truncation.
   85|  13.8k|  assert(in_len == 0);
   86|  13.8k|}
BN_bin2bn:
   88|  12.9k|BIGNUM *BN_bin2bn(const uint8_t *in, size_t len, BIGNUM *ret) {
   89|  12.9k|  BIGNUM *bn = NULL;
   90|  12.9k|  if (ret == NULL) {
  ------------------
  |  Branch (90:7): [True: 1.25k, False: 11.6k]
  ------------------
   91|  1.25k|    bn = BN_new();
   92|  1.25k|    if (bn == NULL) {
  ------------------
  |  Branch (92:9): [True: 0, False: 1.25k]
  ------------------
   93|      0|      return NULL;
   94|      0|    }
   95|  1.25k|    ret = bn;
   96|  1.25k|  }
   97|       |
   98|  12.9k|  if (len == 0) {
  ------------------
  |  Branch (98:7): [True: 15, False: 12.9k]
  ------------------
   99|     15|    ret->width = 0;
  100|     15|    return ret;
  101|     15|  }
  102|       |
  103|  12.9k|  size_t num_words = ((len - 1) / BN_BYTES) + 1;
  ------------------
  |  |  152|  12.9k|#define BN_BYTES 8
  ------------------
  104|  12.9k|  if (!bn_wexpand(ret, num_words)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 12.9k]
  ------------------
  105|      0|    BN_free(bn);
  106|      0|    return NULL;
  107|      0|  }
  108|       |
  109|       |  // |bn_wexpand| must check bounds on |num_words| to write it into
  110|       |  // |ret->dmax|.
  111|  12.9k|  assert(num_words <= INT_MAX);
  112|  12.9k|  ret->width = (int)num_words;
  113|  12.9k|  ret->neg = 0;
  114|       |
  115|  12.9k|  bn_big_endian_to_words(ret->d, ret->width, in, len);
  116|  12.9k|  return ret;
  117|  12.9k|}
bn_words_to_big_endian:
  178|  2.31k|                            size_t in_len) {
  179|       |  // The caller should have selected an output length without truncation.
  180|  2.31k|  assert(fits_in_bytes(in, in_len, out_len));
  181|       |
  182|       |  // We only support little-endian platforms, so the internal representation is
  183|       |  // also little-endian as bytes. We can simply copy it in reverse.
  184|  2.31k|  const uint8_t *bytes = (const uint8_t *)in;
  185|  2.31k|  size_t num_bytes = in_len * sizeof(BN_ULONG);
  186|  2.31k|  if (out_len < num_bytes) {
  ------------------
  |  Branch (186:7): [True: 2.01k, False: 301]
  ------------------
  187|  2.01k|    num_bytes = out_len;
  188|  2.01k|  }
  189|       |
  190|  68.9k|  for (size_t i = 0; i < num_bytes; i++) {
  ------------------
  |  Branch (190:22): [True: 66.6k, False: 2.31k]
  ------------------
  191|  66.6k|    out[out_len - i - 1] = bytes[i];
  192|  66.6k|  }
  193|       |  // Pad out the rest of the buffer with zeroes.
  194|  2.31k|  OPENSSL_memset(out, 0, out_len - num_bytes);
  195|  2.31k|}
BN_bn2bin_padded:
  222|    970|int BN_bn2bin_padded(uint8_t *out, size_t len, const BIGNUM *in) {
  223|    970|  if (!fits_in_bytes(in->d, in->width, len)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 970]
  ------------------
  224|      0|    return 0;
  225|      0|  }
  226|       |
  227|    970|  bn_words_to_big_endian(out, len, in->d, in->width);
  228|    970|  return 1;
  229|    970|}
bcm.c:fits_in_bytes:
  155|  3.28k|                         size_t num_bytes) {
  156|  3.28k|  const uint8_t *bytes = (const uint8_t *)words;
  157|  3.28k|  size_t tot_bytes = num_words * sizeof(BN_ULONG);
  158|  3.28k|  uint8_t mask = 0;
  159|  14.7k|  for (size_t i = num_bytes; i < tot_bytes; i++) {
  ------------------
  |  Branch (159:30): [True: 11.4k, False: 3.28k]
  ------------------
  160|  11.4k|    mask |= bytes[i];
  161|  11.4k|  }
  162|  3.28k|  return mask == 0;
  163|  3.28k|}

BN_ucmp:
   99|  9.52k|int BN_ucmp(const BIGNUM *a, const BIGNUM *b) {
  100|  9.52k|  return bn_cmp_words_consttime(a->d, a->width, b->d, b->width);
  101|  9.52k|}
BN_cmp:
  103|  6.42k|int BN_cmp(const BIGNUM *a, const BIGNUM *b) {
  104|  6.42k|  if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 6.42k]
  |  Branch (104:22): [True: 0, False: 6.42k]
  ------------------
  105|      0|    if (a != NULL) {
  ------------------
  |  Branch (105:9): [True: 0, False: 0]
  ------------------
  106|      0|      return -1;
  107|      0|    } else if (b != NULL) {
  ------------------
  |  Branch (107:16): [True: 0, False: 0]
  ------------------
  108|      0|      return 1;
  109|      0|    } else {
  110|      0|      return 0;
  111|      0|    }
  112|      0|  }
  113|       |
  114|       |  // We do not attempt to process the sign bit in constant time. Negative
  115|       |  // |BIGNUM|s should never occur in crypto, only calculators.
  116|  6.42k|  if (a->neg != b->neg) {
  ------------------
  |  Branch (116:7): [True: 0, False: 6.42k]
  ------------------
  117|      0|    if (a->neg) {
  ------------------
  |  Branch (117:9): [True: 0, False: 0]
  ------------------
  118|      0|      return -1;
  119|      0|    }
  120|      0|    return 1;
  121|      0|  }
  122|       |
  123|  6.42k|  int ret = BN_ucmp(a, b);
  124|  6.42k|  return a->neg ? -ret : ret;
  ------------------
  |  Branch (124:10): [True: 0, False: 6.42k]
  ------------------
  125|  6.42k|}
bn_less_than_words:
  127|  2.11k|int bn_less_than_words(const BN_ULONG *a, const BN_ULONG *b, size_t len) {
  128|  2.11k|  return bn_cmp_words_consttime(a, len, b, len) < 0;
  129|  2.11k|}
BN_abs_is_word:
  131|  1.00M|int BN_abs_is_word(const BIGNUM *bn, BN_ULONG w) {
  132|  1.00M|  if (bn->width == 0) {
  ------------------
  |  Branch (132:7): [True: 0, False: 1.00M]
  ------------------
  133|      0|    return w == 0;
  134|      0|  }
  135|  1.00M|  BN_ULONG mask = bn->d[0] ^ w;
  136|  3.95M|  for (int i = 1; i < bn->width; i++) {
  ------------------
  |  Branch (136:19): [True: 2.94M, False: 1.00M]
  ------------------
  137|  2.94M|    mask |= bn->d[i];
  138|  2.94M|  }
  139|  1.00M|  return mask == 0;
  140|  1.00M|}
BN_is_zero:
  153|  2.16M|int BN_is_zero(const BIGNUM *bn) {
  154|  2.16M|  return bn_fits_in_words(bn, 0);
  155|  2.16M|}
BN_is_one:
  157|  1.00M|int BN_is_one(const BIGNUM *bn) {
  158|  1.00M|  return bn->neg == 0 && BN_abs_is_word(bn, 1);
  ------------------
  |  Branch (158:10): [True: 1.00M, False: 0]
  |  Branch (158:26): [True: 26.4k, False: 978k]
  ------------------
  159|  1.00M|}
BN_is_odd:
  165|  17.5k|int BN_is_odd(const BIGNUM *bn) {
  166|  17.5k|  return bn->width > 0 && (bn->d[0] & 1) == 1;
  ------------------
  |  Branch (166:10): [True: 17.5k, False: 0]
  |  Branch (166:27): [True: 16.8k, False: 707]
  ------------------
  167|  17.5k|}
bcm.c:bn_cmp_words_consttime:
   68|  11.6k|                                  const BN_ULONG *b, size_t b_len) {
   69|  11.6k|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
   70|  11.6k|                "crypto_word_t is too small");
   71|  11.6k|  int ret = 0;
   72|       |  // Process the common words in little-endian order.
   73|  11.6k|  size_t min = a_len < b_len ? a_len : b_len;
  ------------------
  |  Branch (73:16): [True: 4.15k, False: 7.48k]
  ------------------
   74|  82.6k|  for (size_t i = 0; i < min; i++) {
  ------------------
  |  Branch (74:22): [True: 71.0k, False: 11.6k]
  ------------------
   75|  71.0k|    crypto_word_t eq = constant_time_eq_w(a[i], b[i]);
   76|  71.0k|    crypto_word_t lt = constant_time_lt_w(a[i], b[i]);
   77|  71.0k|    ret =
   78|  71.0k|        constant_time_select_int(eq, ret, constant_time_select_int(lt, -1, 1));
   79|  71.0k|  }
   80|       |
   81|       |  // If |a| or |b| has non-zero words beyond |min|, they take precedence.
   82|  11.6k|  if (a_len < b_len) {
  ------------------
  |  Branch (82:7): [True: 4.15k, False: 7.48k]
  ------------------
   83|  4.15k|    crypto_word_t mask = 0;
   84|  52.5k|    for (size_t i = a_len; i < b_len; i++) {
  ------------------
  |  Branch (84:28): [True: 48.3k, False: 4.15k]
  ------------------
   85|  48.3k|      mask |= b[i];
   86|  48.3k|    }
   87|  4.15k|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, -1);
   88|  7.48k|  } else if (b_len < a_len) {
  ------------------
  |  Branch (88:14): [True: 624, False: 6.86k]
  ------------------
   89|    624|    crypto_word_t mask = 0;
   90|  10.1k|    for (size_t i = b_len; i < a_len; i++) {
  ------------------
  |  Branch (90:28): [True: 9.51k, False: 624]
  ------------------
   91|  9.51k|      mask |= a[i];
   92|  9.51k|    }
   93|    624|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, 1);
   94|    624|  }
   95|       |
   96|  11.6k|  return ret;
   97|  11.6k|}

BN_CTX_new:
  108|  1.42k|BN_CTX *BN_CTX_new(void) {
  109|  1.42k|  BN_CTX *ret = OPENSSL_malloc(sizeof(BN_CTX));
  110|  1.42k|  if (!ret) {
  ------------------
  |  Branch (110:7): [True: 0, False: 1.42k]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|       |  // Initialise the structure
  115|  1.42k|  ret->bignums = NULL;
  116|  1.42k|  BN_STACK_init(&ret->stack);
  117|  1.42k|  ret->used = 0;
  118|  1.42k|  ret->error = 0;
  119|  1.42k|  ret->defer_error = 0;
  120|  1.42k|  return ret;
  121|  1.42k|}
BN_CTX_free:
  123|  2.19k|void BN_CTX_free(BN_CTX *ctx) {
  124|  2.19k|  if (ctx == NULL) {
  ------------------
  |  Branch (124:7): [True: 772, False: 1.42k]
  ------------------
  125|    772|    return;
  126|    772|  }
  127|       |
  128|       |  // All |BN_CTX_start| calls must be matched with |BN_CTX_end|, otherwise the
  129|       |  // function may use more memory than expected, potentially without bound if
  130|       |  // done in a loop. Assert that all |BIGNUM|s have been released.
  131|  1.42k|  assert(ctx->used == 0 || ctx->error);
  132|  1.42k|  sk_BIGNUM_pop_free(ctx->bignums, BN_free);
  133|  1.42k|  BN_STACK_cleanup(&ctx->stack);
  134|  1.42k|  OPENSSL_free(ctx);
  135|  1.42k|}
BN_CTX_start:
  137|  4.02M|void BN_CTX_start(BN_CTX *ctx) {
  138|  4.02M|  if (ctx->error) {
  ------------------
  |  Branch (138:7): [True: 0, False: 4.02M]
  ------------------
  139|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  140|       |    // of |BN_CTX_end| calls to come. Do nothing.
  141|      0|    return;
  142|      0|  }
  143|       |
  144|  4.02M|  if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (144:7): [True: 0, False: 4.02M]
  ------------------
  145|      0|    ctx->error = 1;
  146|       |    // |BN_CTX_start| cannot fail, so defer the error to |BN_CTX_get|.
  147|      0|    ctx->defer_error = 1;
  148|      0|  }
  149|  4.02M|}
BN_CTX_get:
  151|  7.24M|BIGNUM *BN_CTX_get(BN_CTX *ctx) {
  152|       |  // Once any operation has failed, they all do.
  153|  7.24M|  if (ctx->error) {
  ------------------
  |  Branch (153:7): [True: 0, False: 7.24M]
  ------------------
  154|      0|    if (ctx->defer_error) {
  ------------------
  |  Branch (154:9): [True: 0, False: 0]
  ------------------
  155|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      0|      ctx->defer_error = 0;
  157|      0|    }
  158|      0|    return NULL;
  159|      0|  }
  160|       |
  161|  7.24M|  if (ctx->bignums == NULL) {
  ------------------
  |  Branch (161:7): [True: 1.34k, False: 7.24M]
  ------------------
  162|  1.34k|    ctx->bignums = sk_BIGNUM_new_null();
  163|  1.34k|    if (ctx->bignums == NULL) {
  ------------------
  |  Branch (163:9): [True: 0, False: 1.34k]
  ------------------
  164|      0|      ctx->error = 1;
  165|      0|      return NULL;
  166|      0|    }
  167|  1.34k|  }
  168|       |
  169|  7.24M|  if (ctx->used == sk_BIGNUM_num(ctx->bignums)) {
  ------------------
  |  Branch (169:7): [True: 17.5k, False: 7.22M]
  ------------------
  170|  17.5k|    BIGNUM *bn = BN_new();
  171|  17.5k|    if (bn == NULL || !sk_BIGNUM_push(ctx->bignums, bn)) {
  ------------------
  |  Branch (171:9): [True: 0, False: 17.5k]
  |  Branch (171:23): [True: 0, False: 17.5k]
  ------------------
  172|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|      BN_free(bn);
  174|      0|      ctx->error = 1;
  175|      0|      return NULL;
  176|      0|    }
  177|  17.5k|  }
  178|       |
  179|  7.24M|  BIGNUM *ret = sk_BIGNUM_value(ctx->bignums, ctx->used);
  180|  7.24M|  BN_zero(ret);
  181|       |  // This is bounded by |sk_BIGNUM_num|, so it cannot overflow.
  182|  7.24M|  ctx->used++;
  183|  7.24M|  return ret;
  184|  7.24M|}
BN_CTX_end:
  186|  4.02M|void BN_CTX_end(BN_CTX *ctx) {
  187|  4.02M|  if (ctx->error) {
  ------------------
  |  Branch (187:7): [True: 0, False: 4.02M]
  ------------------
  188|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  189|       |    // of |BN_CTX_end| calls to come. Do nothing.
  190|      0|    return;
  191|      0|  }
  192|       |
  193|  4.02M|  ctx->used = BN_STACK_pop(&ctx->stack);
  194|  4.02M|}
bcm.c:BN_STACK_init:
  199|  1.42k|static void BN_STACK_init(BN_STACK *st) {
  200|  1.42k|  st->indexes = NULL;
  201|  1.42k|  st->depth = st->size = 0;
  202|  1.42k|}
bcm.c:BN_STACK_cleanup:
  204|  1.42k|static void BN_STACK_cleanup(BN_STACK *st) {
  205|  1.42k|  OPENSSL_free(st->indexes);
  206|  1.42k|}
bcm.c:BN_STACK_push:
  208|  4.02M|static int BN_STACK_push(BN_STACK *st, size_t idx) {
  209|  4.02M|  if (st->depth == st->size) {
  ------------------
  |  Branch (209:7): [True: 1.41k, False: 4.02M]
  ------------------
  210|       |    // This function intentionally does not push to the error queue on error.
  211|       |    // Error-reporting is deferred to |BN_CTX_get|.
  212|  1.41k|    size_t new_size = st->size != 0 ? st->size * 3 / 2 : BN_CTX_START_FRAMES;
  ------------------
  |  |   67|  1.41k|#define BN_CTX_START_FRAMES 32
  ------------------
  |  Branch (212:23): [True: 0, False: 1.41k]
  ------------------
  213|  1.41k|    if (new_size <= st->size || new_size > ((size_t)-1) / sizeof(size_t)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 1.41k]
  |  Branch (213:33): [True: 0, False: 1.41k]
  ------------------
  214|      0|      return 0;
  215|      0|    }
  216|  1.41k|    size_t *new_indexes =
  217|  1.41k|        OPENSSL_realloc(st->indexes, new_size * sizeof(size_t));
  218|  1.41k|    if (new_indexes == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 1.41k]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|  1.41k|    st->indexes = new_indexes;
  222|  1.41k|    st->size = new_size;
  223|  1.41k|  }
  224|       |
  225|  4.02M|  st->indexes[st->depth] = idx;
  226|  4.02M|  st->depth++;
  227|  4.02M|  return 1;
  228|  4.02M|}
bcm.c:BN_STACK_pop:
  230|  4.02M|static size_t BN_STACK_pop(BN_STACK *st) {
  231|  4.02M|  assert(st->depth > 0);
  232|  4.02M|  st->depth--;
  233|  4.02M|  return st->indexes[st->depth];
  234|  4.02M|}

BN_div:
  195|  1.07M|           const BIGNUM *divisor, BN_CTX *ctx) {
  196|  1.07M|  int norm_shift, loop;
  197|  1.07M|  BIGNUM wnum;
  198|  1.07M|  BN_ULONG *resp, *wnump;
  199|  1.07M|  BN_ULONG d0, d1;
  200|  1.07M|  int num_n, div_n;
  201|       |
  202|       |  // This function relies on the historical minimal-width |BIGNUM| invariant.
  203|       |  // It is already not constant-time (constant-time reductions should use
  204|       |  // Montgomery logic), so we shrink all inputs and intermediate values to
  205|       |  // retain the previous behavior.
  206|       |
  207|       |  // Invalid zero-padding would have particularly bad consequences.
  208|  1.07M|  int numerator_width = bn_minimal_width(numerator);
  209|  1.07M|  int divisor_width = bn_minimal_width(divisor);
  210|  1.07M|  if ((numerator_width > 0 && numerator->d[numerator_width - 1] == 0) ||
  ------------------
  |  Branch (210:8): [True: 1.07M, False: 12]
  |  Branch (210:31): [True: 0, False: 1.07M]
  ------------------
  211|  1.07M|      (divisor_width > 0 && divisor->d[divisor_width - 1] == 0)) {
  ------------------
  |  Branch (211:8): [True: 1.07M, False: 0]
  |  Branch (211:29): [True: 0, False: 1.07M]
  ------------------
  212|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NOT_INITIALIZED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|      0|    return 0;
  214|      0|  }
  215|       |
  216|  1.07M|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (216:7): [True: 0, False: 1.07M]
  ------------------
  217|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  218|      0|    return 0;
  219|      0|  }
  220|       |
  221|  1.07M|  BN_CTX_start(ctx);
  222|  1.07M|  BIGNUM *tmp = BN_CTX_get(ctx);
  223|  1.07M|  BIGNUM *snum = BN_CTX_get(ctx);
  224|  1.07M|  BIGNUM *sdiv = BN_CTX_get(ctx);
  225|  1.07M|  BIGNUM *res = NULL;
  226|  1.07M|  if (quotient == NULL) {
  ------------------
  |  Branch (226:7): [True: 1.07M, False: 0]
  ------------------
  227|  1.07M|    res = BN_CTX_get(ctx);
  228|  1.07M|  } else {
  229|      0|    res = quotient;
  230|      0|  }
  231|  1.07M|  if (sdiv == NULL || res == NULL) {
  ------------------
  |  Branch (231:7): [True: 0, False: 1.07M]
  |  Branch (231:23): [True: 0, False: 1.07M]
  ------------------
  232|      0|    goto err;
  233|      0|  }
  234|       |
  235|       |  // First we normalise the numbers
  236|  1.07M|  norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|  1.07M|#define BN_BITS2 64
  ------------------
                norm_shift = BN_BITS2 - (BN_num_bits(divisor) % BN_BITS2);
  ------------------
  |  |  151|  1.07M|#define BN_BITS2 64
  ------------------
  237|  1.07M|  if (!BN_lshift(sdiv, divisor, norm_shift)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 1.07M]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|  1.07M|  bn_set_minimal_width(sdiv);
  241|  1.07M|  sdiv->neg = 0;
  242|  1.07M|  norm_shift += BN_BITS2;
  ------------------
  |  |  151|  1.07M|#define BN_BITS2 64
  ------------------
  243|  1.07M|  if (!BN_lshift(snum, numerator, norm_shift)) {
  ------------------
  |  Branch (243:7): [True: 0, False: 1.07M]
  ------------------
  244|      0|    goto err;
  245|      0|  }
  246|  1.07M|  bn_set_minimal_width(snum);
  247|  1.07M|  snum->neg = 0;
  248|       |
  249|       |  // Since we don't want to have special-case logic for the case where snum is
  250|       |  // larger than sdiv, we pad snum with enough zeroes without changing its
  251|       |  // value.
  252|  1.07M|  if (snum->width <= sdiv->width + 1) {
  ------------------
  |  Branch (252:7): [True: 845, False: 1.06M]
  ------------------
  253|    845|    if (!bn_wexpand(snum, sdiv->width + 2)) {
  ------------------
  |  Branch (253:9): [True: 0, False: 845]
  ------------------
  254|      0|      goto err;
  255|      0|    }
  256|  1.90k|    for (int i = snum->width; i < sdiv->width + 2; i++) {
  ------------------
  |  Branch (256:31): [True: 1.05k, False: 845]
  ------------------
  257|  1.05k|      snum->d[i] = 0;
  258|  1.05k|    }
  259|    845|    snum->width = sdiv->width + 2;
  260|  1.06M|  } else {
  261|  1.06M|    if (!bn_wexpand(snum, snum->width + 1)) {
  ------------------
  |  Branch (261:9): [True: 0, False: 1.06M]
  ------------------
  262|      0|      goto err;
  263|      0|    }
  264|  1.06M|    snum->d[snum->width] = 0;
  265|  1.06M|    snum->width++;
  266|  1.06M|  }
  267|       |
  268|  1.07M|  div_n = sdiv->width;
  269|  1.07M|  num_n = snum->width;
  270|  1.07M|  loop = num_n - div_n;
  271|       |  // Lets setup a 'window' into snum
  272|       |  // This is the part that corresponds to the current
  273|       |  // 'area' being divided
  274|  1.07M|  wnum.neg = 0;
  275|  1.07M|  wnum.d = &(snum->d[loop]);
  276|  1.07M|  wnum.width = div_n;
  277|       |  // only needed when BN_ucmp messes up the values between width and max
  278|  1.07M|  wnum.dmax = snum->dmax - loop;  // so we don't step out of bounds
  279|       |
  280|       |  // Get the top 2 words of sdiv
  281|       |  // div_n=sdiv->width;
  282|  1.07M|  d0 = sdiv->d[div_n - 1];
  283|  1.07M|  d1 = (div_n == 1) ? 0 : sdiv->d[div_n - 2];
  ------------------
  |  Branch (283:8): [True: 9.92k, False: 1.06M]
  ------------------
  284|       |
  285|       |  // pointer to the 'top' of snum
  286|  1.07M|  wnump = &(snum->d[num_n - 1]);
  287|       |
  288|       |  // Setup |res|. |numerator| and |res| may alias, so we save |numerator->neg|
  289|       |  // for later.
  290|  1.07M|  const int numerator_neg = numerator->neg;
  291|  1.07M|  res->neg = (numerator_neg ^ divisor->neg);
  292|  1.07M|  if (!bn_wexpand(res, loop + 1)) {
  ------------------
  |  Branch (292:7): [True: 0, False: 1.07M]
  ------------------
  293|      0|    goto err;
  294|      0|  }
  295|  1.07M|  res->width = loop - 1;
  296|  1.07M|  resp = &(res->d[loop - 1]);
  297|       |
  298|       |  // space for temp
  299|  1.07M|  if (!bn_wexpand(tmp, div_n + 1)) {
  ------------------
  |  Branch (299:7): [True: 0, False: 1.07M]
  ------------------
  300|      0|    goto err;
  301|      0|  }
  302|       |
  303|       |  // if res->width == 0 then clear the neg value otherwise decrease
  304|       |  // the resp pointer
  305|  1.07M|  if (res->width == 0) {
  ------------------
  |  Branch (305:7): [True: 0, False: 1.07M]
  ------------------
  306|      0|    res->neg = 0;
  307|  1.07M|  } else {
  308|  1.07M|    resp--;
  309|  1.07M|  }
  310|       |
  311|  6.40M|  for (int i = 0; i < loop - 1; i++, wnump--, resp--) {
  ------------------
  |  Branch (311:19): [True: 5.33M, False: 1.07M]
  ------------------
  312|  5.33M|    BN_ULONG q, l0;
  313|       |    // the first part of the loop uses the top two words of snum and sdiv to
  314|       |    // calculate a BN_ULONG q such that | wnum - sdiv * q | < sdiv
  315|  5.33M|    BN_ULONG n0, n1, rm = 0;
  316|       |
  317|  5.33M|    n0 = wnump[0];
  318|  5.33M|    n1 = wnump[-1];
  319|  5.33M|    if (n0 == d0) {
  ------------------
  |  Branch (319:9): [True: 20.2k, False: 5.31M]
  ------------------
  320|  20.2k|      q = BN_MASK2;
  ------------------
  |  |  154|  20.2k|#define BN_MASK2 (0xffffffffffffffffUL)
  ------------------
  321|  5.31M|    } else {
  322|       |      // n0 < d0
  323|  5.31M|      bn_div_rem_words(&q, &rm, n0, n1, d0);
  324|       |
  325|  5.31M|#ifdef BN_ULLONG
  326|  5.31M|      BN_ULLONG t2 = (BN_ULLONG)d1 * q;
  ------------------
  |  |  145|  5.31M|#define BN_ULLONG uint128_t
  ------------------
  327|  5.31M|      for (;;) {
  328|  5.31M|        if (t2 <= ((((BN_ULLONG)rm) << BN_BITS2) | wnump[-2])) {
  ------------------
  |  |  151|  5.31M|#define BN_BITS2 64
  ------------------
  |  Branch (328:13): [True: 3.69M, False: 1.61M]
  ------------------
  329|  3.69M|          break;
  330|  3.69M|        }
  331|  1.61M|        q--;
  332|  1.61M|        rm += d0;
  333|  1.61M|        if (rm < d0) {
  ------------------
  |  Branch (333:13): [True: 1.61M, False: 23]
  ------------------
  334|  1.61M|          break;  // don't let rm overflow
  335|  1.61M|        }
  336|     23|        t2 -= d1;
  337|     23|      }
  338|       |#else  // !BN_ULLONG
  339|       |      BN_ULONG t2l, t2h;
  340|       |      BN_UMULT_LOHI(t2l, t2h, d1, q);
  341|       |      for (;;) {
  342|       |        if (t2h < rm ||
  343|       |            (t2h == rm && t2l <= wnump[-2])) {
  344|       |          break;
  345|       |        }
  346|       |        q--;
  347|       |        rm += d0;
  348|       |        if (rm < d0) {
  349|       |          break;  // don't let rm overflow
  350|       |        }
  351|       |        if (t2l < d1) {
  352|       |          t2h--;
  353|       |        }
  354|       |        t2l -= d1;
  355|       |      }
  356|       |#endif  // !BN_ULLONG
  357|  5.31M|    }
  358|       |
  359|  5.33M|    l0 = bn_mul_words(tmp->d, sdiv->d, div_n, q);
  360|  5.33M|    tmp->d[div_n] = l0;
  361|  5.33M|    wnum.d--;
  362|       |    // ingore top values of the bignums just sub the two
  363|       |    // BN_ULONG arrays with bn_sub_words
  364|  5.33M|    if (bn_sub_words(wnum.d, wnum.d, tmp->d, div_n + 1)) {
  ------------------
  |  Branch (364:9): [True: 20.3k, False: 5.31M]
  ------------------
  365|       |      // Note: As we have considered only the leading
  366|       |      // two BN_ULONGs in the calculation of q, sdiv * q
  367|       |      // might be greater than wnum (but then (q-1) * sdiv
  368|       |      // is less or equal than wnum)
  369|  20.3k|      q--;
  370|  20.3k|      if (bn_add_words(wnum.d, wnum.d, sdiv->d, div_n)) {
  ------------------
  |  Branch (370:11): [True: 20.3k, False: 0]
  ------------------
  371|       |        // we can't have an overflow here (assuming
  372|       |        // that q != 0, but if q == 0 then tmp is
  373|       |        // zero anyway)
  374|  20.3k|        (*wnump)++;
  375|  20.3k|      }
  376|  20.3k|    }
  377|       |    // store part of the result
  378|  5.33M|    *resp = q;
  379|  5.33M|  }
  380|       |
  381|  1.07M|  bn_set_minimal_width(snum);
  382|       |
  383|  1.07M|  if (rem != NULL) {
  ------------------
  |  Branch (383:7): [True: 1.07M, False: 0]
  ------------------
  384|  1.07M|    if (!BN_rshift(rem, snum, norm_shift)) {
  ------------------
  |  Branch (384:9): [True: 0, False: 1.07M]
  ------------------
  385|      0|      goto err;
  386|      0|    }
  387|  1.07M|    if (!BN_is_zero(rem)) {
  ------------------
  |  Branch (387:9): [True: 1.06M, False: 5.85k]
  ------------------
  388|  1.06M|      rem->neg = numerator_neg;
  389|  1.06M|    }
  390|  1.07M|  }
  391|       |
  392|  1.07M|  bn_set_minimal_width(res);
  393|  1.07M|  BN_CTX_end(ctx);
  394|  1.07M|  return 1;
  395|       |
  396|      0|err:
  397|      0|  BN_CTX_end(ctx);
  398|      0|  return 0;
  399|  1.07M|}
BN_nnmod:
  401|  1.02M|int BN_nnmod(BIGNUM *r, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx) {
  402|  1.02M|  if (!(BN_mod(r, m, d, ctx))) {
  ------------------
  |  |  547|  1.02M|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  ------------------
  |  Branch (402:7): [True: 0, False: 1.02M]
  ------------------
  403|      0|    return 0;
  404|      0|  }
  405|  1.02M|  if (!r->neg) {
  ------------------
  |  Branch (405:7): [True: 1.02M, False: 0]
  ------------------
  406|  1.02M|    return 1;
  407|  1.02M|  }
  408|       |
  409|       |  // now -|d| < r < 0, so we have to set r := r + |d|.
  410|      0|  return (d->neg ? BN_sub : BN_add)(r, r, d);
  ------------------
  |  Branch (410:11): [True: 0, False: 0]
  ------------------
  411|  1.02M|}
bn_reduce_once:
  414|  3.02k|                        const BN_ULONG *m, size_t num) {
  415|  3.02k|  assert(r != a);
  416|       |  // |r| = |a| - |m|. |bn_sub_words| performs the bulk of the subtraction, and
  417|       |  // then we apply the borrow to |carry|.
  418|  3.02k|  carry -= bn_sub_words(r, a, m, num);
  419|       |  // We know 0 <= |a| < 2*|m|, so -|m| <= |r| < |m|.
  420|       |  //
  421|       |  // If 0 <= |r| < |m|, |r| fits in |num| words and |carry| is zero. We then
  422|       |  // wish to select |r| as the answer. Otherwise -m <= r < 0 and we wish to
  423|       |  // return |r| + |m|, or |a|. |carry| must then be -1 or all ones. In both
  424|       |  // cases, |carry| is a suitable input to |bn_select_words|.
  425|       |  //
  426|       |  // Although |carry| may be one if it was one on input and |bn_sub_words|
  427|       |  // returns zero, this would give |r| > |m|, violating our input assumptions.
  428|  3.02k|  assert(carry == 0 || carry == (BN_ULONG)-1);
  429|  3.02k|  bn_select_words(r, carry, a /* r < 0 */, r /* r >= 0 */, num);
  430|  3.02k|  return carry;
  431|  3.02k|}
bn_reduce_once_in_place:
  434|  2.99M|                                 BN_ULONG *tmp, size_t num) {
  435|       |  // See |bn_reduce_once| for why this logic works.
  436|  2.99M|  carry -= bn_sub_words(tmp, r, m, num);
  437|  2.99M|  assert(carry == 0 || carry == (BN_ULONG)-1);
  438|  2.99M|  bn_select_words(r, carry, r /* tmp < 0 */, tmp /* tmp >= 0 */, num);
  439|  2.99M|  return carry;
  440|  2.99M|}
bn_mod_sub_words:
  443|  1.09M|                      const BN_ULONG *m, BN_ULONG *tmp, size_t num) {
  444|       |  // r = a - b
  445|  1.09M|  BN_ULONG borrow = bn_sub_words(r, a, b, num);
  446|       |  // tmp = a - b + m
  447|  1.09M|  bn_add_words(tmp, r, m, num);
  448|  1.09M|  bn_select_words(r, 0 - borrow, tmp /* r < 0 */, r /* r >= 0 */, num);
  449|  1.09M|}
bn_mod_add_words:
  452|  2.47M|                      const BN_ULONG *m, BN_ULONG *tmp, size_t num) {
  453|  2.47M|  BN_ULONG carry = bn_add_words(r, a, b, num);
  454|  2.47M|  bn_reduce_once_in_place(r, carry, m, tmp, num);
  455|  2.47M|}
bn_div_consttime:
  459|    680|                     unsigned divisor_min_bits, BN_CTX *ctx) {
  460|    680|  if (BN_is_negative(numerator) || BN_is_negative(divisor)) {
  ------------------
  |  Branch (460:7): [True: 0, False: 680]
  |  Branch (460:36): [True: 0, False: 680]
  ------------------
  461|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  462|      0|    return 0;
  463|      0|  }
  464|    680|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (464:7): [True: 0, False: 680]
  ------------------
  465|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  466|      0|    return 0;
  467|      0|  }
  468|       |
  469|       |  // This function implements long division in binary. It is not very efficient,
  470|       |  // but it is simple, easy to make constant-time, and performant enough for RSA
  471|       |  // key generation.
  472|       |
  473|    680|  int ret = 0;
  474|    680|  BN_CTX_start(ctx);
  475|    680|  BIGNUM *q = quotient, *r = remainder;
  476|    680|  if (quotient == NULL || quotient == numerator || quotient == divisor) {
  ------------------
  |  Branch (476:7): [True: 680, False: 0]
  |  Branch (476:27): [True: 0, False: 0]
  |  Branch (476:52): [True: 0, False: 0]
  ------------------
  477|    680|    q = BN_CTX_get(ctx);
  478|    680|  }
  479|    680|  if (remainder == NULL || remainder == numerator || remainder == divisor) {
  ------------------
  |  Branch (479:7): [True: 0, False: 680]
  |  Branch (479:28): [True: 457, False: 223]
  |  Branch (479:54): [True: 0, False: 223]
  ------------------
  480|    457|    r = BN_CTX_get(ctx);
  481|    457|  }
  482|    680|  BIGNUM *tmp = BN_CTX_get(ctx);
  483|    680|  if (q == NULL || r == NULL || tmp == NULL ||
  ------------------
  |  Branch (483:7): [True: 0, False: 680]
  |  Branch (483:20): [True: 0, False: 680]
  |  Branch (483:33): [True: 0, False: 680]
  ------------------
  484|    680|      !bn_wexpand(q, numerator->width) ||
  ------------------
  |  Branch (484:7): [True: 0, False: 680]
  ------------------
  485|    680|      !bn_wexpand(r, divisor->width) ||
  ------------------
  |  Branch (485:7): [True: 0, False: 680]
  ------------------
  486|    680|      !bn_wexpand(tmp, divisor->width)) {
  ------------------
  |  Branch (486:7): [True: 0, False: 680]
  ------------------
  487|      0|    goto err;
  488|      0|  }
  489|       |
  490|    680|  OPENSSL_memset(q->d, 0, numerator->width * sizeof(BN_ULONG));
  491|    680|  q->width = numerator->width;
  492|    680|  q->neg = 0;
  493|       |
  494|    680|  OPENSSL_memset(r->d, 0, divisor->width * sizeof(BN_ULONG));
  495|    680|  r->width = divisor->width;
  496|    680|  r->neg = 0;
  497|       |
  498|       |  // Incorporate |numerator| into |r|, one bit at a time, reducing after each
  499|       |  // step. We maintain the invariant that |0 <= r < divisor| and
  500|       |  // |q * divisor + r = n| where |n| is the portion of |numerator| incorporated
  501|       |  // so far.
  502|       |  //
  503|       |  // First, we short-circuit the loop: if we know |divisor| has at least
  504|       |  // |divisor_min_bits| bits, the top |divisor_min_bits - 1| can be incorporated
  505|       |  // without reductions. This significantly speeds up |RSA_check_key|. For
  506|       |  // simplicity, we round down to a whole number of words.
  507|    680|  assert(divisor_min_bits <= BN_num_bits(divisor));
  508|    680|  int initial_words = 0;
  509|    680|  if (divisor_min_bits > 0) {
  ------------------
  |  Branch (509:7): [True: 680, False: 0]
  ------------------
  510|    680|    initial_words = (divisor_min_bits - 1) / BN_BITS2;
  ------------------
  |  |  151|    680|#define BN_BITS2 64
  ------------------
  511|    680|    if (initial_words > numerator->width) {
  ------------------
  |  Branch (511:9): [True: 37, False: 643]
  ------------------
  512|     37|      initial_words = numerator->width;
  513|     37|    }
  514|    680|    OPENSSL_memcpy(r->d, numerator->d + numerator->width - initial_words,
  515|    680|                   initial_words * sizeof(BN_ULONG));
  516|    680|  }
  517|       |
  518|  8.91k|  for (int i = numerator->width - initial_words - 1; i >= 0; i--) {
  ------------------
  |  Branch (518:54): [True: 8.23k, False: 680]
  ------------------
  519|   535k|    for (int bit = BN_BITS2 - 1; bit >= 0; bit--) {
  ------------------
  |  |  151|  8.23k|#define BN_BITS2 64
  ------------------
  |  Branch (519:34): [True: 527k, False: 8.23k]
  ------------------
  520|       |      // Incorporate the next bit of the numerator, by computing
  521|       |      // r = 2*r or 2*r + 1. Note the result fits in one more word. We store the
  522|       |      // extra word in |carry|.
  523|   527k|      BN_ULONG carry = bn_add_words(r->d, r->d, r->d, divisor->width);
  524|   527k|      r->d[0] |= (numerator->d[i] >> bit) & 1;
  525|       |      // |r| was previously fully-reduced, so we know:
  526|       |      //      2*0 <= r <= 2*(divisor-1) + 1
  527|       |      //        0 <= r <= 2*divisor - 1 < 2*divisor.
  528|       |      // Thus |r| satisfies the preconditions for |bn_reduce_once_in_place|.
  529|   527k|      BN_ULONG subtracted = bn_reduce_once_in_place(r->d, carry, divisor->d,
  530|   527k|                                                    tmp->d, divisor->width);
  531|       |      // The corresponding bit of the quotient is set iff we needed to subtract.
  532|   527k|      q->d[i] |= (~subtracted & 1) << bit;
  533|   527k|    }
  534|  8.23k|  }
  535|       |
  536|    680|  if ((quotient != NULL && !BN_copy(quotient, q)) ||
  ------------------
  |  Branch (536:8): [True: 0, False: 680]
  |  Branch (536:28): [True: 0, False: 0]
  ------------------
  537|    680|      (remainder != NULL && !BN_copy(remainder, r))) {
  ------------------
  |  Branch (537:8): [True: 680, False: 0]
  |  Branch (537:29): [True: 0, False: 680]
  ------------------
  538|      0|    goto err;
  539|      0|  }
  540|       |
  541|    680|  ret = 1;
  542|       |
  543|    680|err:
  544|    680|  BN_CTX_end(ctx);
  545|    680|  return ret;
  546|    680|}
bn_mod_add_consttime:
  598|   864k|                         const BIGNUM *m, BN_CTX *ctx) {
  599|   864k|  BN_CTX_start(ctx);
  600|   864k|  a = bn_resized_from_ctx(a, m->width, ctx);
  601|   864k|  b = bn_resized_from_ctx(b, m->width, ctx);
  602|   864k|  BIGNUM *tmp = bn_scratch_space_from_ctx(m->width, ctx);
  603|   864k|  int ok = a != NULL && b != NULL && tmp != NULL &&
  ------------------
  |  Branch (603:12): [True: 864k, False: 0]
  |  Branch (603:25): [True: 864k, False: 0]
  |  Branch (603:38): [True: 864k, False: 0]
  ------------------
  604|   864k|           bn_wexpand(r, m->width);
  ------------------
  |  Branch (604:12): [True: 864k, False: 0]
  ------------------
  605|   864k|  if (ok) {
  ------------------
  |  Branch (605:7): [True: 864k, False: 0]
  ------------------
  606|   864k|    bn_mod_add_words(r->d, a->d, b->d, m->d, tmp->d, m->width);
  607|   864k|    r->width = m->width;
  608|   864k|    r->neg = 0;
  609|   864k|  }
  610|   864k|  BN_CTX_end(ctx);
  611|   864k|  return ok;
  612|   864k|}
bn_mod_sub_consttime:
  623|    671|                         const BIGNUM *m, BN_CTX *ctx) {
  624|    671|  BN_CTX_start(ctx);
  625|    671|  a = bn_resized_from_ctx(a, m->width, ctx);
  626|    671|  b = bn_resized_from_ctx(b, m->width, ctx);
  627|    671|  BIGNUM *tmp = bn_scratch_space_from_ctx(m->width, ctx);
  628|    671|  int ok = a != NULL && b != NULL && tmp != NULL &&
  ------------------
  |  Branch (628:12): [True: 671, False: 0]
  |  Branch (628:25): [True: 671, False: 0]
  |  Branch (628:38): [True: 671, False: 0]
  ------------------
  629|    671|           bn_wexpand(r, m->width);
  ------------------
  |  Branch (629:12): [True: 671, False: 0]
  ------------------
  630|    671|  if (ok) {
  ------------------
  |  Branch (630:7): [True: 671, False: 0]
  ------------------
  631|    671|    bn_mod_sub_words(r->d, a->d, b->d, m->d, tmp->d, m->width);
  632|    671|    r->width = m->width;
  633|    671|    r->neg = 0;
  634|    671|  }
  635|    671|  BN_CTX_end(ctx);
  636|    671|  return ok;
  637|    671|}
BN_mod_mul:
  649|  1.01M|               BN_CTX *ctx) {
  650|  1.01M|  BIGNUM *t;
  651|  1.01M|  int ret = 0;
  652|       |
  653|  1.01M|  BN_CTX_start(ctx);
  654|  1.01M|  t = BN_CTX_get(ctx);
  655|  1.01M|  if (t == NULL) {
  ------------------
  |  Branch (655:7): [True: 0, False: 1.01M]
  ------------------
  656|      0|    goto err;
  657|      0|  }
  658|       |
  659|  1.01M|  if (a == b) {
  ------------------
  |  Branch (659:7): [True: 976k, False: 41.8k]
  ------------------
  660|   976k|    if (!BN_sqr(t, a, ctx)) {
  ------------------
  |  Branch (660:9): [True: 0, False: 976k]
  ------------------
  661|      0|      goto err;
  662|      0|    }
  663|   976k|  } else {
  664|  41.8k|    if (!BN_mul(t, a, b, ctx)) {
  ------------------
  |  Branch (664:9): [True: 0, False: 41.8k]
  ------------------
  665|      0|      goto err;
  666|      0|    }
  667|  41.8k|  }
  668|       |
  669|  1.01M|  if (!BN_nnmod(r, t, m, ctx)) {
  ------------------
  |  Branch (669:7): [True: 0, False: 1.01M]
  ------------------
  670|      0|    goto err;
  671|      0|  }
  672|       |
  673|  1.01M|  ret = 1;
  674|       |
  675|  1.01M|err:
  676|  1.01M|  BN_CTX_end(ctx);
  677|  1.01M|  return ret;
  678|  1.01M|}
BN_mod_sqr:
  680|  41.4k|int BN_mod_sqr(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx) {
  681|  41.4k|  if (!BN_sqr(r, a, ctx)) {
  ------------------
  |  Branch (681:7): [True: 0, False: 41.4k]
  ------------------
  682|      0|    return 0;
  683|      0|  }
  684|       |
  685|       |  // r->neg == 0,  thus we don't need BN_nnmod
  686|  41.4k|  return BN_mod(r, r, m, ctx);
  ------------------
  |  |  547|  41.4k|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  ------------------
  687|  41.4k|}
bn_mod_lshift_consttime:
  713|  1.68k|                            BN_CTX *ctx) {
  714|  1.68k|  if (!BN_copy(r, a)) {
  ------------------
  |  Branch (714:7): [True: 0, False: 1.68k]
  ------------------
  715|      0|    return 0;
  716|      0|  }
  717|   864k|  for (int i = 0; i < n; i++) {
  ------------------
  |  Branch (717:19): [True: 862k, False: 1.68k]
  ------------------
  718|   862k|    if (!bn_mod_lshift1_consttime(r, r, m, ctx)) {
  ------------------
  |  Branch (718:9): [True: 0, False: 862k]
  ------------------
  719|      0|      return 0;
  720|      0|    }
  721|   862k|  }
  722|  1.68k|  return 1;
  723|  1.68k|}
bn_mod_lshift1_consttime:
  742|   863k|                             BN_CTX *ctx) {
  743|   863k|  return bn_mod_add_consttime(r, a, a, m, ctx);
  744|   863k|}
bcm.c:bn_div_rem_words:
  140|  5.31M|                                    BN_ULONG n0, BN_ULONG n1, BN_ULONG d0) {
  141|       |  // GCC and Clang generate function calls to |__udivdi3| and |__umoddi3| when
  142|       |  // the |BN_ULLONG|-based C code is used.
  143|       |  //
  144|       |  // GCC bugs:
  145|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=14224
  146|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=43721
  147|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=54183
  148|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=58897
  149|       |  //   * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=65668
  150|       |  //
  151|       |  // Clang bugs:
  152|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=6397
  153|       |  //   * https://llvm.org/bugs/show_bug.cgi?id=12418
  154|       |  //
  155|       |  // These issues aren't specific to x86 and x86_64, so it might be worthwhile
  156|       |  // to add more assembly language implementations.
  157|       |#if defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86)
  158|       |  __asm__ volatile("divl %4"
  159|       |                   : "=a"(*quotient_out), "=d"(*rem_out)
  160|       |                   : "a"(n1), "d"(n0), "rm"(d0)
  161|       |                   : "cc");
  162|       |#elif defined(BN_CAN_USE_INLINE_ASM) && defined(OPENSSL_X86_64)
  163|  5.31M|  __asm__ volatile("divq %4"
  164|  5.31M|                   : "=a"(*quotient_out), "=d"(*rem_out)
  165|  5.31M|                   : "a"(n1), "d"(n0), "rm"(d0)
  166|  5.31M|                   : "cc");
  167|       |#else
  168|       |#if defined(BN_CAN_DIVIDE_ULLONG)
  169|       |  BN_ULLONG n = (((BN_ULLONG)n0) << BN_BITS2) | n1;
  170|       |  *quotient_out = (BN_ULONG)(n / d0);
  171|       |#else
  172|       |  *quotient_out = bn_div_words(n0, n1, d0);
  173|       |#endif
  174|       |  *rem_out = n1 - (*quotient_out * d0);
  175|       |#endif
  176|  5.31M|}
bcm.c:bn_resized_from_ctx:
  565|  1.73M|                                         BN_CTX *ctx) {
  566|  1.73M|  if ((size_t)bn->width >= width) {
  ------------------
  |  Branch (566:7): [True: 1.73M, False: 69]
  ------------------
  567|       |    // Any excess words must be zero.
  568|  1.73M|    assert(bn_fits_in_words(bn, width));
  569|  1.73M|    return bn;
  570|  1.73M|  }
  571|     69|  BIGNUM *ret = bn_scratch_space_from_ctx(width, ctx);
  572|     69|  if (ret == NULL ||
  ------------------
  |  Branch (572:7): [True: 0, False: 69]
  ------------------
  573|     69|      !BN_copy(ret, bn) ||
  ------------------
  |  Branch (573:7): [True: 0, False: 69]
  ------------------
  574|     69|      !bn_resize_words(ret, width)) {
  ------------------
  |  Branch (574:7): [True: 0, False: 69]
  ------------------
  575|      0|    return NULL;
  576|      0|  }
  577|     69|  return ret;
  578|     69|}
bcm.c:bn_scratch_space_from_ctx:
  548|   865k|static BIGNUM *bn_scratch_space_from_ctx(size_t width, BN_CTX *ctx) {
  549|   865k|  BIGNUM *ret = BN_CTX_get(ctx);
  550|   865k|  if (ret == NULL ||
  ------------------
  |  Branch (550:7): [True: 0, False: 865k]
  ------------------
  551|   865k|      !bn_wexpand(ret, width)) {
  ------------------
  |  Branch (551:7): [True: 0, False: 865k]
  ------------------
  552|      0|    return NULL;
  553|      0|  }
  554|   865k|  ret->neg = 0;
  555|   865k|  ret->width = (int)width;
  556|   865k|  return ret;
  557|   865k|}

BN_mod_exp_mont:
  588|  1.25k|                    const BIGNUM *m, BN_CTX *ctx, const BN_MONT_CTX *mont) {
  589|  1.25k|  if (!BN_is_odd(m)) {
  ------------------
  |  Branch (589:7): [True: 0, False: 1.25k]
  ------------------
  590|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  591|      0|    return 0;
  592|      0|  }
  593|  1.25k|  if (m->neg) {
  ------------------
  |  Branch (593:7): [True: 0, False: 1.25k]
  ------------------
  594|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  595|      0|    return 0;
  596|      0|  }
  597|       |  // |a| is secret, but |a < m| is not.
  598|  1.25k|  if (a->neg || constant_time_declassify_int(BN_ucmp(a, m)) >= 0) {
  ------------------
  |  Branch (598:7): [True: 0, False: 1.25k]
  |  Branch (598:17): [True: 0, False: 1.25k]
  ------------------
  599|      0|    OPENSSL_PUT_ERROR(BN, BN_R_INPUT_NOT_REDUCED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  600|      0|    return 0;
  601|      0|  }
  602|       |
  603|  1.25k|  int bits = BN_num_bits(p);
  604|  1.25k|  if (bits == 0) {
  ------------------
  |  Branch (604:7): [True: 0, False: 1.25k]
  ------------------
  605|       |    // x**0 mod 1 is still zero.
  606|      0|    if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (606:9): [True: 0, False: 0]
  ------------------
  607|      0|      BN_zero(rr);
  608|      0|      return 1;
  609|      0|    }
  610|      0|    return BN_one(rr);
  611|      0|  }
  612|       |
  613|  1.25k|  int ret = 0;
  614|  1.25k|  BIGNUM *val[TABLE_SIZE];
  615|  1.25k|  BN_MONT_CTX *new_mont = NULL;
  616|       |
  617|  1.25k|  BN_CTX_start(ctx);
  618|  1.25k|  BIGNUM *r = BN_CTX_get(ctx);
  619|  1.25k|  val[0] = BN_CTX_get(ctx);
  620|  1.25k|  if (r == NULL || val[0] == NULL) {
  ------------------
  |  Branch (620:7): [True: 0, False: 1.25k]
  |  Branch (620:20): [True: 0, False: 1.25k]
  ------------------
  621|      0|    goto err;
  622|      0|  }
  623|       |
  624|       |  // Allocate a montgomery context if it was not supplied by the caller.
  625|  1.25k|  if (mont == NULL) {
  ------------------
  |  Branch (625:7): [True: 1.25k, False: 0]
  ------------------
  626|  1.25k|    new_mont = BN_MONT_CTX_new_consttime(m, ctx);
  627|  1.25k|    if (new_mont == NULL) {
  ------------------
  |  Branch (627:9): [True: 0, False: 1.25k]
  ------------------
  628|      0|      goto err;
  629|      0|    }
  630|  1.25k|    mont = new_mont;
  631|  1.25k|  }
  632|       |
  633|       |  // We exponentiate by looking at sliding windows of the exponent and
  634|       |  // precomputing powers of |a|. Windows may be shifted so they always end on a
  635|       |  // set bit, so only precompute odd powers. We compute val[i] = a^(2*i + 1)
  636|       |  // for i = 0 to 2^(window-1), all in Montgomery form.
  637|  1.25k|  int window = BN_window_bits_for_exponent_size(bits);
  638|  1.25k|  if (!BN_to_montgomery(val[0], a, mont, ctx)) {
  ------------------
  |  Branch (638:7): [True: 0, False: 1.25k]
  ------------------
  639|      0|    goto err;
  640|      0|  }
  641|  1.25k|  if (window > 1) {
  ------------------
  |  Branch (641:7): [True: 1.25k, False: 0]
  ------------------
  642|  1.25k|    BIGNUM *d = BN_CTX_get(ctx);
  643|  1.25k|    if (d == NULL ||
  ------------------
  |  Branch (643:9): [True: 0, False: 1.25k]
  ------------------
  644|  1.25k|        !BN_mod_mul_montgomery(d, val[0], val[0], mont, ctx)) {
  ------------------
  |  Branch (644:9): [True: 0, False: 1.25k]
  ------------------
  645|      0|      goto err;
  646|      0|    }
  647|  10.7k|    for (int i = 1; i < 1 << (window - 1); i++) {
  ------------------
  |  Branch (647:21): [True: 9.48k, False: 1.25k]
  ------------------
  648|  9.48k|      val[i] = BN_CTX_get(ctx);
  649|  9.48k|      if (val[i] == NULL ||
  ------------------
  |  Branch (649:11): [True: 0, False: 9.48k]
  ------------------
  650|  9.48k|          !BN_mod_mul_montgomery(val[i], val[i - 1], d, mont, ctx)) {
  ------------------
  |  Branch (650:11): [True: 0, False: 9.48k]
  ------------------
  651|      0|        goto err;
  652|      0|      }
  653|  9.48k|    }
  654|  1.25k|  }
  655|       |
  656|       |  // |p| is non-zero, so at least one window is non-zero. To save some
  657|       |  // multiplications, defer initializing |r| until then.
  658|  1.25k|  int r_is_one = 1;
  659|  1.25k|  int wstart = bits - 1;  // The top bit of the window.
  660|  56.2k|  for (;;) {
  661|  56.2k|    if (!BN_is_bit_set(p, wstart)) {
  ------------------
  |  Branch (661:9): [True: 17.3k, False: 38.8k]
  ------------------
  662|  17.3k|      if (!r_is_one && !BN_mod_mul_montgomery(r, r, r, mont, ctx)) {
  ------------------
  |  Branch (662:11): [True: 17.3k, False: 0]
  |  Branch (662:24): [True: 0, False: 17.3k]
  ------------------
  663|      0|        goto err;
  664|      0|      }
  665|  17.3k|      if (wstart == 0) {
  ------------------
  |  Branch (665:11): [True: 87, False: 17.2k]
  ------------------
  666|     87|        break;
  667|     87|      }
  668|  17.2k|      wstart--;
  669|  17.2k|      continue;
  670|  17.3k|    }
  671|       |
  672|       |    // We now have wstart on a set bit. Find the largest window we can use.
  673|  38.8k|    int wvalue = 1;
  674|  38.8k|    int wsize = 0;
  675|   156k|    for (int i = 1; i < window && i <= wstart; i++) {
  ------------------
  |  Branch (675:21): [True: 118k, False: 38.2k]
  |  Branch (675:35): [True: 117k, False: 584]
  ------------------
  676|   117k|      if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (676:11): [True: 116k, False: 901]
  ------------------
  677|   116k|        wvalue <<= (i - wsize);
  678|   116k|        wvalue |= 1;
  679|   116k|        wsize = i;
  680|   116k|      }
  681|   117k|    }
  682|       |
  683|       |    // Shift |r| to the end of the window.
  684|  38.8k|    if (!r_is_one) {
  ------------------
  |  Branch (684:9): [True: 37.6k, False: 1.25k]
  ------------------
  685|   187k|      for (int i = 0; i < wsize + 1; i++) {
  ------------------
  |  Branch (685:23): [True: 150k, False: 37.6k]
  ------------------
  686|   150k|        if (!BN_mod_mul_montgomery(r, r, r, mont, ctx)) {
  ------------------
  |  Branch (686:13): [True: 0, False: 150k]
  ------------------
  687|      0|          goto err;
  688|      0|        }
  689|   150k|      }
  690|  37.6k|    }
  691|       |
  692|  38.8k|    assert(wvalue & 1);
  693|  38.8k|    assert(wvalue < (1 << window));
  694|  38.8k|    if (r_is_one) {
  ------------------
  |  Branch (694:9): [True: 1.25k, False: 37.6k]
  ------------------
  695|  1.25k|      if (!BN_copy(r, val[wvalue >> 1])) {
  ------------------
  |  Branch (695:11): [True: 0, False: 1.25k]
  ------------------
  696|      0|        goto err;
  697|      0|      }
  698|  37.6k|    } else if (!BN_mod_mul_montgomery(r, r, val[wvalue >> 1], mont, ctx)) {
  ------------------
  |  Branch (698:16): [True: 0, False: 37.6k]
  ------------------
  699|      0|      goto err;
  700|      0|    }
  701|       |
  702|  38.8k|    r_is_one = 0;
  703|  38.8k|    if (wstart == wsize) {
  ------------------
  |  Branch (703:9): [True: 1.16k, False: 37.6k]
  ------------------
  704|  1.16k|      break;
  705|  1.16k|    }
  706|  37.6k|    wstart -= wsize + 1;
  707|  37.6k|  }
  708|       |
  709|       |  // |p| is non-zero, so |r_is_one| must be cleared at some point.
  710|  1.25k|  assert(!r_is_one);
  711|       |
  712|  1.25k|  if (!BN_from_montgomery(rr, r, mont, ctx)) {
  ------------------
  |  Branch (712:7): [True: 0, False: 1.25k]
  ------------------
  713|      0|    goto err;
  714|      0|  }
  715|  1.25k|  ret = 1;
  716|       |
  717|  1.25k|err:
  718|  1.25k|  BN_MONT_CTX_free(new_mont);
  719|  1.25k|  BN_CTX_end(ctx);
  720|  1.25k|  return ret;
  721|  1.25k|}
BN_mod_exp_mont_consttime:
  885|    427|                              const BN_MONT_CTX *mont) {
  886|    427|  int i, ret = 0, wvalue;
  887|    427|  BN_MONT_CTX *new_mont = NULL;
  888|       |
  889|    427|  unsigned char *powerbuf_free = NULL;
  890|    427|  size_t powerbuf_len = 0;
  891|    427|  BN_ULONG *powerbuf = NULL;
  892|       |
  893|    427|  if (!BN_is_odd(m)) {
  ------------------
  |  Branch (893:7): [True: 0, False: 427]
  ------------------
  894|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  895|      0|    return 0;
  896|      0|  }
  897|    427|  if (m->neg) {
  ------------------
  |  Branch (897:7): [True: 0, False: 427]
  ------------------
  898|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  899|      0|    return 0;
  900|      0|  }
  901|    427|  if (a->neg || BN_ucmp(a, m) >= 0) {
  ------------------
  |  Branch (901:7): [True: 0, False: 427]
  |  Branch (901:17): [True: 0, False: 427]
  ------------------
  902|      0|    OPENSSL_PUT_ERROR(BN, BN_R_INPUT_NOT_REDUCED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  903|      0|    return 0;
  904|      0|  }
  905|       |
  906|       |  // Use all bits stored in |p|, rather than |BN_num_bits|, so we do not leak
  907|       |  // whether the top bits are zero.
  908|    427|  int max_bits = p->width * BN_BITS2;
  ------------------
  |  |  151|    427|#define BN_BITS2 64
  ------------------
  909|    427|  int bits = max_bits;
  910|    427|  if (bits == 0) {
  ------------------
  |  Branch (910:7): [True: 0, False: 427]
  ------------------
  911|       |    // x**0 mod 1 is still zero.
  912|      0|    if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (912:9): [True: 0, False: 0]
  ------------------
  913|      0|      BN_zero(rr);
  914|      0|      return 1;
  915|      0|    }
  916|      0|    return BN_one(rr);
  917|      0|  }
  918|       |
  919|       |  // Allocate a montgomery context if it was not supplied by the caller.
  920|    427|  if (mont == NULL) {
  ------------------
  |  Branch (920:7): [True: 427, False: 0]
  ------------------
  921|    427|    new_mont = BN_MONT_CTX_new_consttime(m, ctx);
  922|    427|    if (new_mont == NULL) {
  ------------------
  |  Branch (922:9): [True: 0, False: 427]
  ------------------
  923|      0|      goto err;
  924|      0|    }
  925|    427|    mont = new_mont;
  926|    427|  }
  927|       |
  928|       |  // Use the width in |mont->N|, rather than the copy in |m|. The assembly
  929|       |  // implementation assumes it can use |top| to size R.
  930|    427|  int top = mont->N.width;
  931|       |
  932|    427|#if defined(OPENSSL_BN_ASM_MONT5) || defined(RSAZ_ENABLED)
  933|       |  // Share one large stack-allocated buffer between the RSAZ and non-RSAZ code
  934|       |  // paths. If we were to use separate static buffers for each then there is
  935|       |  // some chance that both large buffers would be allocated on the stack,
  936|       |  // causing the stack space requirement to be truly huge (~10KB).
  937|    427|  alignas(MOD_EXP_CTIME_ALIGN) BN_ULONG storage[MOD_EXP_CTIME_STORAGE_LEN];
  938|    427|#endif
  939|    427|#if defined(RSAZ_ENABLED)
  940|       |  // If the size of the operands allow it, perform the optimized RSAZ
  941|       |  // exponentiation. For further information see crypto/fipsmodule/bn/rsaz_exp.c
  942|       |  // and accompanying assembly modules.
  943|    427|  if (a->width == 16 && p->width == 16 && BN_num_bits(m) == 1024 &&
  ------------------
  |  Branch (943:7): [True: 2, False: 425]
  |  Branch (943:25): [True: 0, False: 2]
  |  Branch (943:43): [True: 0, False: 0]
  ------------------
  944|    427|      rsaz_avx2_preferred()) {
  ------------------
  |  Branch (944:7): [True: 0, False: 0]
  ------------------
  945|      0|    if (!bn_wexpand(rr, 16)) {
  ------------------
  |  Branch (945:9): [True: 0, False: 0]
  ------------------
  946|      0|      goto err;
  947|      0|    }
  948|      0|    RSAZ_1024_mod_exp_avx2(rr->d, a->d, p->d, m->d, mont->RR.d, mont->n0[0],
  949|      0|                           storage);
  950|      0|    rr->width = 16;
  951|      0|    rr->neg = 0;
  952|      0|    ret = 1;
  953|      0|    goto err;
  954|      0|  }
  955|    427|#endif
  956|       |
  957|       |  // Get the window size to use with size of p.
  958|    427|  int window = BN_window_bits_for_ctime_exponent_size(bits);
  ------------------
  |  |  876|    427|  ((b) > 937 ? 6 : (b) > 306 ? 5 : (b) > 89 ? 4 : (b) > 22 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (876:4): [True: 0, False: 427]
  |  |  |  Branch (876:20): [True: 0, False: 427]
  |  |  |  Branch (876:36): [True: 132, False: 295]
  |  |  |  Branch (876:51): [True: 295, False: 0]
  |  |  ------------------
  ------------------
  959|    427|  assert(window <= BN_MAX_MOD_EXP_CTIME_WINDOW);
  960|       |
  961|       |  // Calculating |powerbuf_len| below cannot overflow because of the bound on
  962|       |  // Montgomery reduction.
  963|    427|  assert((size_t)top <= BN_MONTGOMERY_MAX_WORDS);
  964|    427|  static_assert(
  965|    427|      BN_MONTGOMERY_MAX_WORDS <=
  966|    427|          INT_MAX / sizeof(BN_ULONG) / ((1 << BN_MAX_MOD_EXP_CTIME_WINDOW) + 3),
  967|    427|      "powerbuf_len may overflow");
  968|       |
  969|    427|#if defined(OPENSSL_BN_ASM_MONT5)
  970|    427|  if (window >= 5) {
  ------------------
  |  Branch (970:7): [True: 0, False: 427]
  ------------------
  971|      0|    window = 5;  // ~5% improvement for RSA2048 sign, and even for RSA4096
  972|       |    // Reserve space for the |mont->N| copy.
  973|      0|    powerbuf_len += top * sizeof(mont->N.d[0]);
  974|      0|  }
  975|    427|#endif
  976|       |
  977|       |  // Allocate a buffer large enough to hold all of the pre-computed
  978|       |  // powers of |am|, |am| itself, and |tmp|.
  979|    427|  int num_powers = 1 << window;
  980|    427|  powerbuf_len += sizeof(m->d[0]) * top * (num_powers + 2);
  981|       |
  982|    427|#if defined(OPENSSL_BN_ASM_MONT5)
  983|    427|  if (powerbuf_len <= sizeof(storage)) {
  ------------------
  |  Branch (983:7): [True: 427, False: 0]
  ------------------
  984|    427|    powerbuf = storage;
  985|    427|  }
  986|       |  // |storage| is more than large enough to handle 1024-bit inputs.
  987|    427|  assert(powerbuf != NULL || top * BN_BITS2 > 1024);
  988|    427|#endif
  989|    427|  if (powerbuf == NULL) {
  ------------------
  |  Branch (989:7): [True: 0, False: 427]
  ------------------
  990|      0|    powerbuf_free = OPENSSL_malloc(powerbuf_len + MOD_EXP_CTIME_ALIGN);
  ------------------
  |  |  200|      0|#define MOD_EXP_CTIME_ALIGN 64
  ------------------
  991|      0|    if (powerbuf_free == NULL) {
  ------------------
  |  Branch (991:9): [True: 0, False: 0]
  ------------------
  992|      0|      goto err;
  993|      0|    }
  994|      0|    powerbuf = align_pointer(powerbuf_free, MOD_EXP_CTIME_ALIGN);
  ------------------
  |  |  200|      0|#define MOD_EXP_CTIME_ALIGN 64
  ------------------
  995|      0|  }
  996|    427|  OPENSSL_memset(powerbuf, 0, powerbuf_len);
  997|       |
  998|       |  // Place |tmp| and |am| right after powers table.
  999|    427|  BIGNUM tmp, am;
 1000|    427|  tmp.d = powerbuf + top * num_powers;
 1001|    427|  am.d = tmp.d + top;
 1002|    427|  tmp.width = am.width = 0;
 1003|    427|  tmp.dmax = am.dmax = top;
 1004|    427|  tmp.neg = am.neg = 0;
 1005|    427|  tmp.flags = am.flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|    427|#define BN_FLG_STATIC_DATA 0x02
  ------------------
 1006|       |
 1007|    427|  if (!bn_one_to_montgomery(&tmp, mont, ctx) ||
  ------------------
  |  Branch (1007:7): [True: 0, False: 427]
  ------------------
 1008|    427|      !bn_resize_words(&tmp, top)) {
  ------------------
  |  Branch (1008:7): [True: 0, False: 427]
  ------------------
 1009|      0|    goto err;
 1010|      0|  }
 1011|       |
 1012|       |  // Prepare a^1 in the Montgomery domain.
 1013|    427|  assert(!a->neg);
 1014|    427|  assert(BN_ucmp(a, m) < 0);
 1015|    427|  if (!BN_to_montgomery(&am, a, mont, ctx) ||
  ------------------
  |  Branch (1015:7): [True: 0, False: 427]
  ------------------
 1016|    427|      !bn_resize_words(&am, top)) {
  ------------------
  |  Branch (1016:7): [True: 0, False: 427]
  ------------------
 1017|      0|    goto err;
 1018|      0|  }
 1019|       |
 1020|    427|#if defined(OPENSSL_BN_ASM_MONT5)
 1021|       |  // This optimization uses ideas from https://eprint.iacr.org/2011/239,
 1022|       |  // specifically optimization of cache-timing attack countermeasures,
 1023|       |  // pre-computation optimization, and Almost Montgomery Multiplication.
 1024|       |  //
 1025|       |  // The paper discusses a 4-bit window to optimize 512-bit modular
 1026|       |  // exponentiation, used in RSA-1024 with CRT, but RSA-1024 is no longer
 1027|       |  // important.
 1028|       |  //
 1029|       |  // |bn_mul_mont_gather5| and |bn_power5| implement the "almost" reduction
 1030|       |  // variant, so the values here may not be fully reduced. They are bounded by R
 1031|       |  // (i.e. they fit in |top| words), not |m|. Additionally, we pass these
 1032|       |  // "almost" reduced inputs into |bn_mul_mont|, which implements the normal
 1033|       |  // reduction variant. Given those inputs, |bn_mul_mont| may not give reduced
 1034|       |  // output, but it will still produce "almost" reduced output.
 1035|       |  //
 1036|       |  // TODO(davidben): Using "almost" reduction complicates analysis of this code,
 1037|       |  // and its interaction with other parts of the project. Determine whether this
 1038|       |  // is actually necessary for performance.
 1039|    427|  if (window == 5 && top > 1) {
  ------------------
  |  Branch (1039:7): [True: 0, False: 427]
  |  Branch (1039:22): [True: 0, False: 0]
  ------------------
 1040|       |    // Copy |mont->N| to improve cache locality.
 1041|      0|    BN_ULONG *np = am.d + top;
 1042|      0|    for (i = 0; i < top; i++) {
  ------------------
  |  Branch (1042:17): [True: 0, False: 0]
  ------------------
 1043|      0|      np[i] = mont->N.d[i];
 1044|      0|    }
 1045|       |
 1046|       |    // Fill |powerbuf| with the first 32 powers of |am|.
 1047|      0|    const BN_ULONG *n0 = mont->n0;
 1048|      0|    bn_scatter5(tmp.d, top, powerbuf, 0);
 1049|      0|    bn_scatter5(am.d, am.width, powerbuf, 1);
 1050|      0|    bn_mul_mont(tmp.d, am.d, am.d, np, n0, top);
 1051|      0|    bn_scatter5(tmp.d, top, powerbuf, 2);
 1052|       |
 1053|       |    // Square to compute powers of two.
 1054|      0|    for (i = 4; i < 32; i *= 2) {
  ------------------
  |  Branch (1054:17): [True: 0, False: 0]
  ------------------
 1055|      0|      bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1056|      0|      bn_scatter5(tmp.d, top, powerbuf, i);
 1057|      0|    }
 1058|       |    // Compute odd powers |i| based on |i - 1|, then all powers |i * 2^j|.
 1059|      0|    for (i = 3; i < 32; i += 2) {
  ------------------
  |  Branch (1059:17): [True: 0, False: 0]
  ------------------
 1060|      0|      bn_mul_mont_gather5(tmp.d, am.d, powerbuf, np, n0, top, i - 1);
 1061|      0|      bn_scatter5(tmp.d, top, powerbuf, i);
 1062|      0|      for (int j = 2 * i; j < 32; j *= 2) {
  ------------------
  |  Branch (1062:27): [True: 0, False: 0]
  ------------------
 1063|      0|        bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1064|      0|        bn_scatter5(tmp.d, top, powerbuf, j);
 1065|      0|      }
 1066|      0|    }
 1067|       |
 1068|      0|    bits--;
 1069|      0|    for (wvalue = 0, i = bits % 5; i >= 0; i--, bits--) {
  ------------------
  |  Branch (1069:36): [True: 0, False: 0]
  ------------------
 1070|      0|      wvalue = (wvalue << 1) + BN_is_bit_set(p, bits);
 1071|      0|    }
 1072|      0|    bn_gather5(tmp.d, top, powerbuf, wvalue);
 1073|       |
 1074|       |    // At this point |bits| is 4 mod 5 and at least -1. (|bits| is the first bit
 1075|       |    // that has not been read yet.)
 1076|      0|    assert(bits >= -1 && (bits == -1 || bits % 5 == 4));
 1077|       |
 1078|       |    // Scan the exponent one window at a time starting from the most
 1079|       |    // significant bits.
 1080|      0|    if (top & 7) {
  ------------------
  |  Branch (1080:9): [True: 0, False: 0]
  ------------------
 1081|      0|      while (bits >= 0) {
  ------------------
  |  Branch (1081:14): [True: 0, False: 0]
  ------------------
 1082|      0|        for (wvalue = 0, i = 0; i < 5; i++, bits--) {
  ------------------
  |  Branch (1082:33): [True: 0, False: 0]
  ------------------
 1083|      0|          wvalue = (wvalue << 1) + BN_is_bit_set(p, bits);
 1084|      0|        }
 1085|       |
 1086|      0|        bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1087|      0|        bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1088|      0|        bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1089|      0|        bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1090|      0|        bn_mul_mont(tmp.d, tmp.d, tmp.d, np, n0, top);
 1091|      0|        bn_mul_mont_gather5(tmp.d, tmp.d, powerbuf, np, n0, top, wvalue);
 1092|      0|      }
 1093|      0|    } else {
 1094|      0|      const uint8_t *p_bytes = (const uint8_t *)p->d;
 1095|      0|      assert(bits < max_bits);
 1096|       |      // |p = 0| has been handled as a special case, so |max_bits| is at least
 1097|       |      // one word.
 1098|      0|      assert(max_bits >= 64);
 1099|       |
 1100|       |      // If the first bit to be read lands in the last byte, unroll the first
 1101|       |      // iteration to avoid reading past the bounds of |p->d|. (After the first
 1102|       |      // iteration, we are guaranteed to be past the last byte.) Note |bits|
 1103|       |      // here is the top bit, inclusive.
 1104|      0|      if (bits - 4 >= max_bits - 8) {
  ------------------
  |  Branch (1104:11): [True: 0, False: 0]
  ------------------
 1105|       |        // Read five bits from |bits-4| through |bits|, inclusive.
 1106|      0|        wvalue = p_bytes[p->width * BN_BYTES - 1];
  ------------------
  |  |  152|      0|#define BN_BYTES 8
  ------------------
 1107|      0|        wvalue >>= (bits - 4) & 7;
 1108|      0|        wvalue &= 0x1f;
 1109|      0|        bits -= 5;
 1110|      0|        bn_power5(tmp.d, tmp.d, powerbuf, np, n0, top, wvalue);
 1111|      0|      }
 1112|      0|      while (bits >= 0) {
  ------------------
  |  Branch (1112:14): [True: 0, False: 0]
  ------------------
 1113|       |        // Read five bits from |bits-4| through |bits|, inclusive.
 1114|      0|        int first_bit = bits - 4;
 1115|      0|        uint16_t val;
 1116|      0|        OPENSSL_memcpy(&val, p_bytes + (first_bit >> 3), sizeof(val));
 1117|      0|        val >>= first_bit & 7;
 1118|      0|        val &= 0x1f;
 1119|      0|        bits -= 5;
 1120|      0|        bn_power5(tmp.d, tmp.d, powerbuf, np, n0, top, val);
 1121|      0|      }
 1122|      0|    }
 1123|       |    // The result is now in |tmp| in Montgomery form, but it may not be fully
 1124|       |    // reduced. This is within bounds for |BN_from_montgomery| (tmp < R <= m*R)
 1125|       |    // so it will, when converting from Montgomery form, produce a fully reduced
 1126|       |    // result.
 1127|       |    //
 1128|       |    // This differs from Figure 2 of the paper, which uses AMM(h, 1) to convert
 1129|       |    // from Montgomery form with unreduced output, followed by an extra
 1130|       |    // reduction step. In the paper's terminology, we replace steps 9 and 10
 1131|       |    // with MM(h, 1).
 1132|      0|  } else
 1133|    427|#endif
 1134|    427|  {
 1135|    427|    copy_to_prebuf(&tmp, top, powerbuf, 0, window);
 1136|    427|    copy_to_prebuf(&am, top, powerbuf, 1, window);
 1137|       |
 1138|       |    // If the window size is greater than 1, then calculate
 1139|       |    // val[i=2..2^winsize-1]. Powers are computed as a*a^(i-1)
 1140|       |    // (even powers could instead be computed as (a^(i/2))^2
 1141|       |    // to use the slight performance advantage of sqr over mul).
 1142|    427|    if (window > 1) {
  ------------------
  |  Branch (1142:9): [True: 427, False: 0]
  ------------------
 1143|    427|      if (!BN_mod_mul_montgomery(&tmp, &am, &am, mont, ctx)) {
  ------------------
  |  Branch (1143:11): [True: 0, False: 427]
  ------------------
 1144|      0|        goto err;
 1145|      0|      }
 1146|       |
 1147|    427|      copy_to_prebuf(&tmp, top, powerbuf, 2, window);
 1148|       |
 1149|  3.61k|      for (i = 3; i < num_powers; i++) {
  ------------------
  |  Branch (1149:19): [True: 3.19k, False: 427]
  ------------------
 1150|       |        // Calculate a^i = a^(i-1) * a
 1151|  3.19k|        if (!BN_mod_mul_montgomery(&tmp, &am, &tmp, mont, ctx)) {
  ------------------
  |  Branch (1151:13): [True: 0, False: 3.19k]
  ------------------
 1152|      0|          goto err;
 1153|      0|        }
 1154|       |
 1155|  3.19k|        copy_to_prebuf(&tmp, top, powerbuf, i, window);
 1156|  3.19k|      }
 1157|    427|    }
 1158|       |
 1159|    427|    bits--;
 1160|  1.25k|    for (wvalue = 0, i = bits % window; i >= 0; i--, bits--) {
  ------------------
  |  Branch (1160:41): [True: 823, False: 427]
  ------------------
 1161|    823|      wvalue = (wvalue << 1) + BN_is_bit_set(p, bits);
 1162|    823|    }
 1163|    427|    if (!copy_from_prebuf(&tmp, top, powerbuf, wvalue, window)) {
  ------------------
  |  Branch (1163:9): [True: 0, False: 427]
  ------------------
 1164|      0|      goto err;
 1165|      0|    }
 1166|       |
 1167|       |    // Scan the exponent one window at a time starting from the most
 1168|       |    // significant bits.
 1169|  10.7k|    while (bits >= 0) {
  ------------------
  |  Branch (1169:12): [True: 10.3k, False: 427]
  ------------------
 1170|  10.3k|      wvalue = 0;  // The 'value' of the window
 1171|       |
 1172|       |      // Scan the window, squaring the result as we go
 1173|  45.4k|      for (i = 0; i < window; i++, bits--) {
  ------------------
  |  Branch (1173:19): [True: 35.1k, False: 10.3k]
  ------------------
 1174|  35.1k|        if (!BN_mod_mul_montgomery(&tmp, &tmp, &tmp, mont, ctx)) {
  ------------------
  |  Branch (1174:13): [True: 0, False: 35.1k]
  ------------------
 1175|      0|          goto err;
 1176|      0|        }
 1177|  35.1k|        wvalue = (wvalue << 1) + BN_is_bit_set(p, bits);
 1178|  35.1k|      }
 1179|       |
 1180|       |      // Fetch the appropriate pre-computed value from the pre-buf
 1181|  10.3k|      if (!copy_from_prebuf(&am, top, powerbuf, wvalue, window)) {
  ------------------
  |  Branch (1181:11): [True: 0, False: 10.3k]
  ------------------
 1182|      0|        goto err;
 1183|      0|      }
 1184|       |
 1185|       |      // Multiply the result into the intermediate result
 1186|  10.3k|      if (!BN_mod_mul_montgomery(&tmp, &tmp, &am, mont, ctx)) {
  ------------------
  |  Branch (1186:11): [True: 0, False: 10.3k]
  ------------------
 1187|      0|        goto err;
 1188|      0|      }
 1189|  10.3k|    }
 1190|    427|  }
 1191|       |
 1192|       |  // Convert the final result from Montgomery to standard format. If we used the
 1193|       |  // |OPENSSL_BN_ASM_MONT5| codepath, |tmp| may not be fully reduced. It is only
 1194|       |  // bounded by R rather than |m|. However, that is still within bounds for
 1195|       |  // |BN_from_montgomery|, which implements full Montgomery reduction, not
 1196|       |  // "almost" Montgomery reduction.
 1197|    427|  if (!BN_from_montgomery(rr, &tmp, mont, ctx)) {
  ------------------
  |  Branch (1197:7): [True: 0, False: 427]
  ------------------
 1198|      0|    goto err;
 1199|      0|  }
 1200|    427|  ret = 1;
 1201|       |
 1202|    427|err:
 1203|    427|  BN_MONT_CTX_free(new_mont);
 1204|    427|  if (powerbuf != NULL && powerbuf_free == NULL) {
  ------------------
  |  Branch (1204:7): [True: 427, False: 0]
  |  Branch (1204:27): [True: 427, False: 0]
  ------------------
 1205|    427|    OPENSSL_cleanse(powerbuf, powerbuf_len);
 1206|    427|  }
 1207|    427|  OPENSSL_free(powerbuf_free);
 1208|    427|  return ret;
 1209|    427|}
bcm.c:BN_window_bits_for_exponent_size:
  400|  1.25k|static int BN_window_bits_for_exponent_size(size_t b) {
  401|  1.25k|  if (b > 671) {
  ------------------
  |  Branch (401:7): [True: 0, False: 1.25k]
  ------------------
  402|      0|    return 6;
  403|      0|  }
  404|  1.25k|  if (b > 239) {
  ------------------
  |  Branch (404:7): [True: 87, False: 1.16k]
  ------------------
  405|     87|    return 5;
  406|     87|  }
  407|  1.16k|  if (b > 79) {
  ------------------
  |  Branch (407:7): [True: 1.16k, False: 0]
  ------------------
  408|  1.16k|    return 4;
  409|  1.16k|  }
  410|      0|  if (b > 23) {
  ------------------
  |  Branch (410:7): [True: 0, False: 0]
  ------------------
  411|      0|    return 3;
  412|      0|  }
  413|      0|  return 1;
  414|      0|}
bcm.c:copy_to_prebuf:
  840|  4.47k|                           int window) {
  841|  4.47k|  int ret = bn_copy_words(table + idx * top, top, b);
  842|  4.47k|  assert(ret);  // |b| is guaranteed to fit.
  843|  4.47k|  (void)ret;
  844|  4.47k|}
bcm.c:copy_from_prebuf:
  847|  10.7k|                            int window) {
  848|  10.7k|  if (!bn_wexpand(b, top)) {
  ------------------
  |  Branch (848:7): [True: 0, False: 10.7k]
  ------------------
  849|      0|    return 0;
  850|      0|  }
  851|       |
  852|  10.7k|  OPENSSL_memset(b->d, 0, sizeof(BN_ULONG) * top);
  853|  10.7k|  const int width = 1 << window;
  854|   131k|  for (int i = 0; i < width; i++, table += top) {
  ------------------
  |  Branch (854:19): [True: 120k, False: 10.7k]
  ------------------
  855|       |    // Use a value barrier to prevent Clang from adding a branch when |i != idx|
  856|       |    // and making this copy not constant time. Clang is still allowed to learn
  857|       |    // that |mask| is constant across the inner loop, so this won't inhibit any
  858|       |    // vectorization it might do.
  859|   120k|    BN_ULONG mask = value_barrier_w(constant_time_eq_int(i, idx));
  860|  2.48M|    for (int j = 0; j < top; j++) {
  ------------------
  |  Branch (860:21): [True: 2.36M, False: 120k]
  ------------------
  861|  2.36M|      b->d[j] |= table[j] & mask;
  862|  2.36M|    }
  863|   120k|  }
  864|       |
  865|  10.7k|  b->width = top;
  866|  10.7k|  return 1;
  867|  10.7k|}

bn_jacobi:
   63|  5.84k|int bn_jacobi(const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
   64|       |  // In 'tab', only odd-indexed entries are relevant:
   65|       |  // For any odd BIGNUM n,
   66|       |  //     tab[BN_lsw(n) & 7]
   67|       |  // is $(-1)^{(n^2-1)/8}$ (using TeX notation).
   68|       |  // Note that the sign of n does not matter.
   69|  5.84k|  static const int tab[8] = {0, 1, 0, -1, 0, -1, 0, 1};
   70|       |
   71|       |  // The Jacobi symbol is only defined for odd modulus.
   72|  5.84k|  if (!BN_is_odd(b)) {
  ------------------
  |  Branch (72:7): [True: 0, False: 5.84k]
  ------------------
   73|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   74|      0|    return -2;
   75|      0|  }
   76|       |
   77|       |  // Require b be positive.
   78|  5.84k|  if (BN_is_negative(b)) {
  ------------------
  |  Branch (78:7): [True: 0, False: 5.84k]
  ------------------
   79|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   80|      0|    return -2;
   81|      0|  }
   82|       |
   83|  5.84k|  int ret = -2;
   84|  5.84k|  BN_CTX_start(ctx);
   85|  5.84k|  BIGNUM *A = BN_CTX_get(ctx);
   86|  5.84k|  BIGNUM *B = BN_CTX_get(ctx);
   87|  5.84k|  if (B == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 5.84k]
  ------------------
   88|      0|    goto end;
   89|      0|  }
   90|       |
   91|  5.84k|  if (!BN_copy(A, a) ||
  ------------------
  |  Branch (91:7): [True: 0, False: 5.84k]
  ------------------
   92|  5.84k|      !BN_copy(B, b)) {
  ------------------
  |  Branch (92:7): [True: 0, False: 5.84k]
  ------------------
   93|      0|    goto end;
   94|      0|  }
   95|       |
   96|       |  // Adapted from logic to compute the Kronecker symbol, originally implemented
   97|       |  // according to Henri Cohen, "A Course in Computational Algebraic Number
   98|       |  // Theory" (algorithm 1.4.10).
   99|       |
  100|  5.84k|  ret = 1;
  101|       |
  102|  15.7k|  while (1) {
  ------------------
  |  Branch (102:10): [Folded - Ignored]
  ------------------
  103|       |    // Cohen's step 3:
  104|       |
  105|       |    // B is positive and odd
  106|  15.7k|    if (BN_is_zero(A)) {
  ------------------
  |  Branch (106:9): [True: 5.84k, False: 9.92k]
  ------------------
  107|  5.84k|      ret = BN_is_one(B) ? ret : 0;
  ------------------
  |  Branch (107:13): [True: 5.84k, False: 0]
  ------------------
  108|  5.84k|      goto end;
  109|  5.84k|    }
  110|       |
  111|       |    // now A is non-zero
  112|  9.92k|    int i = 0;
  113|  18.6k|    while (!BN_is_bit_set(A, i)) {
  ------------------
  |  Branch (113:12): [True: 8.76k, False: 9.92k]
  ------------------
  114|  8.76k|      i++;
  115|  8.76k|    }
  116|  9.92k|    if (!BN_rshift(A, A, i)) {
  ------------------
  |  Branch (116:9): [True: 0, False: 9.92k]
  ------------------
  117|      0|      ret = -2;
  118|      0|      goto end;
  119|      0|    }
  120|  9.92k|    if (i & 1) {
  ------------------
  |  Branch (120:9): [True: 2.92k, False: 7.00k]
  ------------------
  121|       |      // i is odd
  122|       |      // multiply 'ret' by  $(-1)^{(B^2-1)/8}$
  123|  2.92k|      ret = ret * tab[BN_lsw(B) & 7];
  ------------------
  |  |   61|  2.92k|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 2.92k]
  |  |  ------------------
  ------------------
  124|  2.92k|    }
  125|       |
  126|       |    // Cohen's step 4:
  127|       |    // multiply 'ret' by  $(-1)^{(A-1)(B-1)/4}$
  128|  9.92k|    if ((A->neg ? ~BN_lsw(A) : BN_lsw(A)) & BN_lsw(B) & 2) {
  ------------------
  |  |   61|      0|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 0]
  |  |  ------------------
  ------------------
                  if ((A->neg ? ~BN_lsw(A) : BN_lsw(A)) & BN_lsw(B) & 2) {
  ------------------
  |  |   61|  9.92k|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 9.92k]
  |  |  ------------------
  ------------------
                  if ((A->neg ? ~BN_lsw(A) : BN_lsw(A)) & BN_lsw(B) & 2) {
  ------------------
  |  |   61|  9.92k|#define BN_lsw(n) (((n)->width == 0) ? (BN_ULONG) 0 : (n)->d[0])
  |  |  ------------------
  |  |  |  Branch (61:20): [True: 0, False: 9.92k]
  |  |  ------------------
  ------------------
  |  Branch (128:9): [True: 0, False: 9.92k]
  |  Branch (128:10): [True: 0, False: 9.92k]
  ------------------
  129|      0|      ret = -ret;
  130|      0|    }
  131|       |
  132|       |    // (A, B) := (B mod |A|, |A|)
  133|  9.92k|    if (!BN_nnmod(B, B, A, ctx)) {
  ------------------
  |  Branch (133:9): [True: 0, False: 9.92k]
  ------------------
  134|      0|      ret = -2;
  135|      0|      goto end;
  136|      0|    }
  137|  9.92k|    BIGNUM *tmp = A;
  138|  9.92k|    A = B;
  139|  9.92k|    B = tmp;
  140|  9.92k|    tmp->neg = 0;
  141|  9.92k|  }
  142|       |
  143|  5.84k|end:
  144|  5.84k|  BN_CTX_end(ctx);
  145|  5.84k|  return ret;
  146|  5.84k|}

BN_MONT_CTX_new:
  124|  1.68k|BN_MONT_CTX *BN_MONT_CTX_new(void) {
  125|  1.68k|  BN_MONT_CTX *ret = OPENSSL_malloc(sizeof(BN_MONT_CTX));
  126|       |
  127|  1.68k|  if (ret == NULL) {
  ------------------
  |  Branch (127:7): [True: 0, False: 1.68k]
  ------------------
  128|      0|    return NULL;
  129|      0|  }
  130|       |
  131|  1.68k|  OPENSSL_memset(ret, 0, sizeof(BN_MONT_CTX));
  132|  1.68k|  BN_init(&ret->RR);
  133|  1.68k|  BN_init(&ret->N);
  134|       |
  135|  1.68k|  return ret;
  136|  1.68k|}
BN_MONT_CTX_free:
  138|  10.2k|void BN_MONT_CTX_free(BN_MONT_CTX *mont) {
  139|  10.2k|  if (mont == NULL) {
  ------------------
  |  Branch (139:7): [True: 8.59k, False: 1.68k]
  ------------------
  140|  8.59k|    return;
  141|  8.59k|  }
  142|       |
  143|  1.68k|  BN_free(&mont->RR);
  144|  1.68k|  BN_free(&mont->N);
  145|  1.68k|  OPENSSL_free(mont);
  146|  1.68k|}
BN_MONT_CTX_set:
  210|      7|int BN_MONT_CTX_set(BN_MONT_CTX *mont, const BIGNUM *mod, BN_CTX *ctx) {
  211|      7|  if (!bn_mont_ctx_set_N_and_n0(mont, mod)) {
  ------------------
  |  Branch (211:7): [True: 0, False: 7]
  ------------------
  212|      0|    return 0;
  213|      0|  }
  214|       |
  215|      7|  BN_CTX *new_ctx = NULL;
  216|      7|  if (ctx == NULL) {
  ------------------
  |  Branch (216:7): [True: 4, False: 3]
  ------------------
  217|      4|    new_ctx = BN_CTX_new();
  218|      4|    if (new_ctx == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 4]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|      4|    ctx = new_ctx;
  222|      4|  }
  223|       |
  224|       |  // Save RR = R**2 (mod N). R is the smallest power of 2**BN_BITS2 such that R
  225|       |  // > mod. Even though the assembly on some 32-bit platforms works with 64-bit
  226|       |  // values, using |BN_BITS2| here, rather than |BN_MONT_CTX_N0_LIMBS *
  227|       |  // BN_BITS2|, is correct because R**2 will still be a multiple of the latter
  228|       |  // as |BN_MONT_CTX_N0_LIMBS| is either one or two.
  229|      7|  unsigned lgBigR = mont->N.width * BN_BITS2;
  ------------------
  |  |  151|      7|#define BN_BITS2 64
  ------------------
  230|      7|  BN_zero(&mont->RR);
  231|      7|  int ok = BN_set_bit(&mont->RR, lgBigR * 2) &&
  ------------------
  |  Branch (231:12): [True: 7, False: 0]
  ------------------
  232|      7|           BN_mod(&mont->RR, &mont->RR, &mont->N, ctx) &&
  ------------------
  |  |  547|     14|  BN_div(NULL, (rem), (numerator), (divisor), (ctx))
  |  |  ------------------
  |  |  |  Branch (547:3): [True: 7, False: 0]
  |  |  ------------------
  ------------------
  233|      7|           bn_resize_words(&mont->RR, mont->N.width);
  ------------------
  |  Branch (233:12): [True: 7, False: 0]
  ------------------
  234|      7|  BN_CTX_free(new_ctx);
  235|      7|  return ok;
  236|      7|}
BN_MONT_CTX_new_for_modulus:
  238|      7|BN_MONT_CTX *BN_MONT_CTX_new_for_modulus(const BIGNUM *mod, BN_CTX *ctx) {
  239|      7|  BN_MONT_CTX *mont = BN_MONT_CTX_new();
  240|      7|  if (mont == NULL ||
  ------------------
  |  Branch (240:7): [True: 0, False: 7]
  ------------------
  241|      7|      !BN_MONT_CTX_set(mont, mod, ctx)) {
  ------------------
  |  Branch (241:7): [True: 0, False: 7]
  ------------------
  242|      0|    BN_MONT_CTX_free(mont);
  243|      0|    return NULL;
  244|      0|  }
  245|      7|  return mont;
  246|      7|}
BN_MONT_CTX_new_consttime:
  248|  1.68k|BN_MONT_CTX *BN_MONT_CTX_new_consttime(const BIGNUM *mod, BN_CTX *ctx) {
  249|  1.68k|  BN_MONT_CTX *mont = BN_MONT_CTX_new();
  250|  1.68k|  if (mont == NULL ||
  ------------------
  |  Branch (250:7): [True: 0, False: 1.68k]
  ------------------
  251|  1.68k|      !bn_mont_ctx_set_N_and_n0(mont, mod)) {
  ------------------
  |  Branch (251:7): [True: 0, False: 1.68k]
  ------------------
  252|      0|    goto err;
  253|      0|  }
  254|  1.68k|  unsigned lgBigR = mont->N.width * BN_BITS2;
  ------------------
  |  |  151|  1.68k|#define BN_BITS2 64
  ------------------
  255|  1.68k|  if (!bn_mod_exp_base_2_consttime(&mont->RR, lgBigR * 2, &mont->N, ctx) ||
  ------------------
  |  Branch (255:7): [True: 0, False: 1.68k]
  ------------------
  256|  1.68k|      !bn_resize_words(&mont->RR, mont->N.width)) {
  ------------------
  |  Branch (256:7): [True: 0, False: 1.68k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|  1.68k|  return mont;
  260|       |
  261|      0|err:
  262|      0|  BN_MONT_CTX_free(mont);
  263|      0|  return NULL;
  264|  1.68k|}
BN_to_montgomery:
  286|  1.68k|                     BN_CTX *ctx) {
  287|  1.68k|  return BN_mod_mul_montgomery(ret, a, &mont->RR, mont, ctx);
  288|  1.68k|}
BN_from_montgomery:
  346|  1.85k|                       BN_CTX *ctx) {
  347|  1.85k|  int ret = 0;
  348|  1.85k|  BIGNUM *t;
  349|       |
  350|  1.85k|  BN_CTX_start(ctx);
  351|  1.85k|  t = BN_CTX_get(ctx);
  352|  1.85k|  if (t == NULL ||
  ------------------
  |  Branch (352:7): [True: 0, False: 1.85k]
  ------------------
  353|  1.85k|      !BN_copy(t, a)) {
  ------------------
  |  Branch (353:7): [True: 0, False: 1.85k]
  ------------------
  354|      0|    goto err;
  355|      0|  }
  356|       |
  357|  1.85k|  ret = BN_from_montgomery_word(r, t, mont);
  358|       |
  359|  1.85k|err:
  360|  1.85k|  BN_CTX_end(ctx);
  361|       |
  362|  1.85k|  return ret;
  363|  1.85k|}
bn_one_to_montgomery:
  365|    427|int bn_one_to_montgomery(BIGNUM *r, const BN_MONT_CTX *mont, BN_CTX *ctx) {
  366|       |  // If the high bit of |n| is set, R = 2^(width*BN_BITS2) < 2 * |n|, so we
  367|       |  // compute R - |n| rather than perform Montgomery reduction.
  368|    427|  const BIGNUM *n = &mont->N;
  369|    427|  if (n->width > 0 && (n->d[n->width - 1] >> (BN_BITS2 - 1)) != 0) {
  ------------------
  |  |  151|    427|#define BN_BITS2 64
  ------------------
  |  Branch (369:7): [True: 427, False: 0]
  |  Branch (369:23): [True: 254, False: 173]
  ------------------
  370|    254|    if (!bn_wexpand(r, n->width)) {
  ------------------
  |  Branch (370:9): [True: 0, False: 254]
  ------------------
  371|      0|      return 0;
  372|      0|    }
  373|    254|    r->d[0] = 0 - n->d[0];
  374|  4.79k|    for (int i = 1; i < n->width; i++) {
  ------------------
  |  Branch (374:21): [True: 4.54k, False: 254]
  ------------------
  375|  4.54k|      r->d[i] = ~n->d[i];
  376|  4.54k|    }
  377|    254|    r->width = n->width;
  378|    254|    r->neg = 0;
  379|    254|    return 1;
  380|    254|  }
  381|       |
  382|    173|  return BN_from_montgomery(r, &mont->RR, mont, ctx);
  383|    427|}
BN_mod_mul_montgomery:
  420|   266k|                          const BN_MONT_CTX *mont, BN_CTX *ctx) {
  421|   266k|  if (a->neg || b->neg) {
  ------------------
  |  Branch (421:7): [True: 0, False: 266k]
  |  Branch (421:17): [True: 0, False: 266k]
  ------------------
  422|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  423|      0|    return 0;
  424|      0|  }
  425|       |
  426|   266k|#if defined(OPENSSL_BN_ASM_MONT)
  427|       |  // |bn_mul_mont| requires at least 128 bits of limbs, at least for x86.
  428|   266k|  int num = mont->N.width;
  429|   266k|  if (num >= (128 / BN_BITS2) &&
  ------------------
  |  |  151|   266k|#define BN_BITS2 64
  ------------------
  |  Branch (429:7): [True: 266k, False: 0]
  ------------------
  430|   266k|      a->width == num &&
  ------------------
  |  Branch (430:7): [True: 265k, False: 1.00k]
  ------------------
  431|   266k|      b->width == num) {
  ------------------
  |  Branch (431:7): [True: 265k, False: 0]
  ------------------
  432|   265k|    if (!bn_wexpand(r, num)) {
  ------------------
  |  Branch (432:9): [True: 0, False: 265k]
  ------------------
  433|      0|      return 0;
  434|      0|    }
  435|       |    // This bound is implied by |bn_mont_ctx_set_N_and_n0|. |bn_mul_mont|
  436|       |    // allocates |num| words on the stack, so |num| cannot be too large.
  437|   265k|    assert((size_t)num <= BN_MONTGOMERY_MAX_WORDS);
  438|   265k|    if (!bn_mul_mont(r->d, a->d, b->d, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (438:9): [True: 0, False: 265k]
  ------------------
  439|       |      // The check above ensures this won't happen.
  440|      0|      assert(0);
  441|      0|      OPENSSL_PUT_ERROR(BN, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  442|      0|      return 0;
  443|      0|    }
  444|   265k|    r->neg = 0;
  445|   265k|    r->width = num;
  446|   265k|    return 1;
  447|   265k|  }
  448|  1.00k|#endif
  449|       |
  450|  1.00k|  return bn_mod_mul_montgomery_fallback(r, a, b, mont, ctx);
  451|   266k|}
bn_to_montgomery_small:
  459|    137|                            const BN_MONT_CTX *mont) {
  460|    137|  bn_mod_mul_montgomery_small(r, a, mont->RR.d, num, mont);
  461|    137|}
bn_from_montgomery_small:
  464|    174|                              size_t num_a, const BN_MONT_CTX *mont) {
  465|    174|  if (num_r != (size_t)mont->N.width || num_r > BN_SMALL_MAX_WORDS ||
  ------------------
  |  |  684|    348|#define BN_SMALL_MAX_WORDS 9
  ------------------
  |  Branch (465:7): [True: 0, False: 174]
  |  Branch (465:41): [True: 0, False: 174]
  ------------------
  466|    174|      num_a > 2 * num_r) {
  ------------------
  |  Branch (466:7): [True: 0, False: 174]
  ------------------
  467|      0|    abort();
  468|      0|  }
  469|    174|  BN_ULONG tmp[BN_SMALL_MAX_WORDS * 2] = {0};
  470|    174|  OPENSSL_memcpy(tmp, a, num_a * sizeof(BN_ULONG));
  471|    174|  if (!bn_from_montgomery_in_place(r, num_r, tmp, 2 * num_r, mont)) {
  ------------------
  |  Branch (471:7): [True: 0, False: 174]
  ------------------
  472|      0|    abort();
  473|      0|  }
  474|    174|  OPENSSL_cleanse(tmp, 2 * num_r * sizeof(BN_ULONG));
  475|    174|}
bn_mod_mul_montgomery_small:
  479|  1.74M|                                 const BN_MONT_CTX *mont) {
  480|  1.74M|  if (num != (size_t)mont->N.width || num > BN_SMALL_MAX_WORDS) {
  ------------------
  |  |  684|  1.74M|#define BN_SMALL_MAX_WORDS 9
  ------------------
  |  Branch (480:7): [True: 0, False: 1.74M]
  |  Branch (480:39): [True: 0, False: 1.74M]
  ------------------
  481|      0|    abort();
  482|      0|  }
  483|       |
  484|  1.74M|#if defined(OPENSSL_BN_ASM_MONT)
  485|       |  // |bn_mul_mont| requires at least 128 bits of limbs, at least for x86.
  486|  1.74M|  if (num >= (128 / BN_BITS2)) {
  ------------------
  |  |  151|  1.74M|#define BN_BITS2 64
  ------------------
  |  Branch (486:7): [True: 1.74M, False: 0]
  ------------------
  487|  1.74M|    if (!bn_mul_mont(r, a, b, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (487:9): [True: 0, False: 1.74M]
  ------------------
  488|      0|      abort();  // The check above ensures this won't happen.
  489|      0|    }
  490|  1.74M|    return;
  491|  1.74M|  }
  492|      0|#endif
  493|       |
  494|       |  // Compute the product.
  495|      0|  BN_ULONG tmp[2 * BN_SMALL_MAX_WORDS];
  496|      0|  if (a == b) {
  ------------------
  |  Branch (496:7): [True: 0, False: 0]
  ------------------
  497|      0|    bn_sqr_small(tmp, 2 * num, a, num);
  498|      0|  } else {
  499|      0|    bn_mul_small(tmp, 2 * num, a, num, b, num);
  500|      0|  }
  501|       |
  502|       |  // Reduce.
  503|      0|  if (!bn_from_montgomery_in_place(r, num, tmp, 2 * num, mont)) {
  ------------------
  |  Branch (503:7): [True: 0, False: 0]
  ------------------
  504|      0|    abort();
  505|      0|  }
  506|      0|  OPENSSL_cleanse(tmp, 2 * num * sizeof(BN_ULONG));
  507|      0|}
bcm.c:bn_mont_ctx_set_N_and_n0:
  162|  1.68k|static int bn_mont_ctx_set_N_and_n0(BN_MONT_CTX *mont, const BIGNUM *mod) {
  163|  1.68k|  if (BN_is_zero(mod)) {
  ------------------
  |  Branch (163:7): [True: 0, False: 1.68k]
  ------------------
  164|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  165|      0|    return 0;
  166|      0|  }
  167|  1.68k|  if (!BN_is_odd(mod)) {
  ------------------
  |  Branch (167:7): [True: 0, False: 1.68k]
  ------------------
  168|      0|    OPENSSL_PUT_ERROR(BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|      0|    return 0;
  170|      0|  }
  171|  1.68k|  if (BN_is_negative(mod)) {
  ------------------
  |  Branch (171:7): [True: 0, False: 1.68k]
  ------------------
  172|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|    return 0;
  174|      0|  }
  175|  1.68k|  if (!bn_fits_in_words(mod, BN_MONTGOMERY_MAX_WORDS)) {
  ------------------
  |  |  363|  1.68k|#define BN_MONTGOMERY_MAX_WORDS (8 * 1024 / sizeof(BN_ULONG))
  ------------------
  |  Branch (175:7): [True: 0, False: 1.68k]
  ------------------
  176|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|    return 0;
  178|      0|  }
  179|       |
  180|       |  // Save the modulus.
  181|  1.68k|  if (!BN_copy(&mont->N, mod)) {
  ------------------
  |  Branch (181:7): [True: 0, False: 1.68k]
  ------------------
  182|      0|    OPENSSL_PUT_ERROR(BN, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  183|      0|    return 0;
  184|      0|  }
  185|       |  // |mont->N| is always stored minimally. Computing RR efficiently leaks the
  186|       |  // size of the modulus. While the modulus may be private in RSA (one of the
  187|       |  // primes), their sizes are public, so this is fine.
  188|  1.68k|  bn_set_minimal_width(&mont->N);
  189|       |
  190|       |  // Find n0 such that n0 * N == -1 (mod r).
  191|       |  //
  192|       |  // Only certain BN_BITS2<=32 platforms actually make use of n0[1]. For the
  193|       |  // others, we could use a shorter R value and use faster |BN_ULONG|-based
  194|       |  // math instead of |uint64_t|-based math, which would be double-precision.
  195|       |  // However, currently only the assembler files know which is which.
  196|  1.68k|  static_assert(BN_MONT_CTX_N0_LIMBS == 1 || BN_MONT_CTX_N0_LIMBS == 2,
  197|  1.68k|                "BN_MONT_CTX_N0_LIMBS value is invalid");
  198|  1.68k|  static_assert(sizeof(BN_ULONG) * BN_MONT_CTX_N0_LIMBS == sizeof(uint64_t),
  199|  1.68k|                "uint64_t is insufficient precision for n0");
  200|  1.68k|  uint64_t n0 = bn_mont_n0(&mont->N);
  201|  1.68k|  mont->n0[0] = (BN_ULONG)n0;
  202|       |#if BN_MONT_CTX_N0_LIMBS == 2
  203|       |  mont->n0[1] = (BN_ULONG)(n0 >> BN_BITS2);
  204|       |#else
  205|  1.68k|  mont->n0[1] = 0;
  206|  1.68k|#endif
  207|  1.68k|  return 1;
  208|  1.68k|}
bcm.c:BN_from_montgomery_word:
  322|  2.85k|                                   const BN_MONT_CTX *mont) {
  323|  2.85k|  if (r->neg) {
  ------------------
  |  Branch (323:7): [True: 0, False: 2.85k]
  ------------------
  324|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  325|      0|    return 0;
  326|      0|  }
  327|       |
  328|  2.85k|  const BIGNUM *n = &mont->N;
  329|  2.85k|  if (n->width == 0) {
  ------------------
  |  Branch (329:7): [True: 0, False: 2.85k]
  ------------------
  330|      0|    ret->width = 0;
  331|      0|    return 1;
  332|      0|  }
  333|       |
  334|  2.85k|  int max = 2 * n->width;  // carry is stored separately
  335|  2.85k|  if (!bn_resize_words(r, max) ||
  ------------------
  |  Branch (335:7): [True: 0, False: 2.85k]
  ------------------
  336|  2.85k|      !bn_wexpand(ret, n->width)) {
  ------------------
  |  Branch (336:7): [True: 0, False: 2.85k]
  ------------------
  337|      0|    return 0;
  338|      0|  }
  339|       |
  340|  2.85k|  ret->width = n->width;
  341|  2.85k|  ret->neg = 0;
  342|  2.85k|  return bn_from_montgomery_in_place(ret->d, ret->width, r->d, r->width, mont);
  343|  2.85k|}
bcm.c:bn_mod_mul_montgomery_fallback:
  388|  1.00k|                                          BN_CTX *ctx) {
  389|  1.00k|  int ret = 0;
  390|       |
  391|  1.00k|  BN_CTX_start(ctx);
  392|  1.00k|  BIGNUM *tmp = BN_CTX_get(ctx);
  393|  1.00k|  if (tmp == NULL) {
  ------------------
  |  Branch (393:7): [True: 0, False: 1.00k]
  ------------------
  394|      0|    goto err;
  395|      0|  }
  396|       |
  397|  1.00k|  if (a == b) {
  ------------------
  |  Branch (397:7): [True: 0, False: 1.00k]
  ------------------
  398|      0|    if (!bn_sqr_consttime(tmp, a, ctx)) {
  ------------------
  |  Branch (398:9): [True: 0, False: 0]
  ------------------
  399|      0|      goto err;
  400|      0|    }
  401|  1.00k|  } else {
  402|  1.00k|    if (!bn_mul_consttime(tmp, a, b, ctx)) {
  ------------------
  |  Branch (402:9): [True: 0, False: 1.00k]
  ------------------
  403|      0|      goto err;
  404|      0|    }
  405|  1.00k|  }
  406|       |
  407|       |  // reduce from aRR to aR
  408|  1.00k|  if (!BN_from_montgomery_word(r, tmp, mont)) {
  ------------------
  |  Branch (408:7): [True: 0, False: 1.00k]
  ------------------
  409|      0|    goto err;
  410|      0|  }
  411|       |
  412|  1.00k|  ret = 1;
  413|       |
  414|  1.00k|err:
  415|  1.00k|  BN_CTX_end(ctx);
  416|  1.00k|  return ret;
  417|  1.00k|}
bcm.c:bn_from_montgomery_in_place:
  291|  3.02k|                                       size_t num_a, const BN_MONT_CTX *mont) {
  292|  3.02k|  const BN_ULONG *n = mont->N.d;
  293|  3.02k|  size_t num_n = mont->N.width;
  294|  3.02k|  if (num_r != num_n || num_a != 2 * num_n) {
  ------------------
  |  Branch (294:7): [True: 0, False: 3.02k]
  |  Branch (294:25): [True: 0, False: 3.02k]
  ------------------
  295|      0|    OPENSSL_PUT_ERROR(BN, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  296|      0|    return 0;
  297|      0|  }
  298|       |
  299|       |  // Add multiples of |n| to |r| until R = 2^(nl * BN_BITS2) divides it. On
  300|       |  // input, we had |r| < |n| * R, so now |r| < 2 * |n| * R. Note that |r|
  301|       |  // includes |carry| which is stored separately.
  302|  3.02k|  BN_ULONG n0 = mont->n0[0];
  303|  3.02k|  BN_ULONG carry = 0;
  304|  29.5k|  for (size_t i = 0; i < num_n; i++) {
  ------------------
  |  Branch (304:22): [True: 26.4k, False: 3.02k]
  ------------------
  305|  26.4k|    BN_ULONG v = bn_mul_add_words(a + i, n, num_n, a[i] * n0);
  306|  26.4k|    v += carry + a[i + num_n];
  307|  26.4k|    carry |= (v != a[i + num_n]);
  308|  26.4k|    carry &= (v <= a[i + num_n]);
  309|  26.4k|    a[i + num_n] = v;
  310|  26.4k|  }
  311|       |
  312|       |  // Shift |num_n| words to divide by R. We have |a| < 2 * |n|. Note that |a|
  313|       |  // includes |carry| which is stored separately.
  314|  3.02k|  a += num_n;
  315|       |
  316|       |  // |a| thus requires at most one additional subtraction |n| to be reduced.
  317|  3.02k|  bn_reduce_once(r, a, carry, n, num_n);
  318|  3.02k|  return 1;
  319|  3.02k|}

bn_mont_n0:
   33|  1.68k|uint64_t bn_mont_n0(const BIGNUM *n) {
   34|       |  // These conditions are checked by the caller, |BN_MONT_CTX_set| or
   35|       |  // |BN_MONT_CTX_new_consttime|.
   36|  1.68k|  assert(!BN_is_zero(n));
   37|  1.68k|  assert(!BN_is_negative(n));
   38|  1.68k|  assert(BN_is_odd(n));
   39|       |
   40|       |  // r == 2**(BN_MONT_CTX_N0_LIMBS * BN_BITS2) and LG_LITTLE_R == lg(r). This
   41|       |  // ensures that we can do integer division by |r| by simply ignoring
   42|       |  // |BN_MONT_CTX_N0_LIMBS| limbs. Similarly, we can calculate values modulo
   43|       |  // |r| by just looking at the lowest |BN_MONT_CTX_N0_LIMBS| limbs. This is
   44|       |  // what makes Montgomery multiplication efficient.
   45|       |  //
   46|       |  // As shown in Algorithm 1 of "Fast Prime Field Elliptic Curve Cryptography
   47|       |  // with 256 Bit Primes" by Shay Gueron and Vlad Krasnov, in the loop of a
   48|       |  // multi-limb Montgomery multiplication of |a * b (mod n)|, given the
   49|       |  // unreduced product |t == a * b|, we repeatedly calculate:
   50|       |  //
   51|       |  //    t1 := t % r         |t1| is |t|'s lowest limb (see previous paragraph).
   52|       |  //    t2 := t1*n0*n
   53|       |  //    t3 := t + t2
   54|       |  //    t := t3 / r         copy all limbs of |t3| except the lowest to |t|.
   55|       |  //
   56|       |  // In the last step, it would only make sense to ignore the lowest limb of
   57|       |  // |t3| if it were zero. The middle steps ensure that this is the case:
   58|       |  //
   59|       |  //                            t3 ==  0 (mod r)
   60|       |  //                        t + t2 ==  0 (mod r)
   61|       |  //                   t + t1*n0*n ==  0 (mod r)
   62|       |  //                       t1*n0*n == -t (mod r)
   63|       |  //                        t*n0*n == -t (mod r)
   64|       |  //                          n0*n == -1 (mod r)
   65|       |  //                            n0 == -1/n (mod r)
   66|       |  //
   67|       |  // Thus, in each iteration of the loop, we multiply by the constant factor
   68|       |  // |n0|, the negative inverse of n (mod r).
   69|       |
   70|       |  // n_mod_r = n % r. As explained above, this is done by taking the lowest
   71|       |  // |BN_MONT_CTX_N0_LIMBS| limbs of |n|.
   72|  1.68k|  uint64_t n_mod_r = n->d[0];
   73|       |#if BN_MONT_CTX_N0_LIMBS == 2
   74|       |  if (n->width > 1) {
   75|       |    n_mod_r |= (uint64_t)n->d[1] << BN_BITS2;
   76|       |  }
   77|       |#endif
   78|       |
   79|  1.68k|  return bn_neg_inv_mod_r_u64(n_mod_r);
   80|  1.68k|}
bn_mod_exp_base_2_consttime:
  163|  1.68k|                                BN_CTX *ctx) {
  164|  1.68k|  assert(!BN_is_zero(n));
  165|  1.68k|  assert(!BN_is_negative(n));
  166|  1.68k|  assert(BN_is_odd(n));
  167|       |
  168|  1.68k|  BN_zero(r);
  169|       |
  170|  1.68k|  unsigned n_bits = BN_num_bits(n);
  171|  1.68k|  assert(n_bits != 0);
  172|  1.68k|  assert(p > n_bits);
  173|  1.68k|  if (n_bits == 1) {
  ------------------
  |  Branch (173:7): [True: 0, False: 1.68k]
  ------------------
  174|      0|    return 1;
  175|      0|  }
  176|       |
  177|       |  // Set |r| to the larger power of two smaller than |n|, then shift with
  178|       |  // reductions the rest of the way.
  179|  1.68k|  if (!BN_set_bit(r, n_bits - 1) ||
  ------------------
  |  Branch (179:7): [True: 0, False: 1.68k]
  ------------------
  180|  1.68k|      !bn_mod_lshift_consttime(r, r, p - (n_bits - 1), n, ctx)) {
  ------------------
  |  Branch (180:7): [True: 0, False: 1.68k]
  ------------------
  181|      0|    return 0;
  182|      0|  }
  183|       |
  184|  1.68k|  return 1;
  185|  1.68k|}
bcm.c:bn_neg_inv_mod_r_u64:
  104|  1.68k|static uint64_t bn_neg_inv_mod_r_u64(uint64_t n) {
  105|  1.68k|  assert(n % 2 == 1);
  106|       |
  107|       |  // alpha == 2**(lg r - 1) == r / 2.
  108|  1.68k|  static const uint64_t alpha = UINT64_C(1) << (LG_LITTLE_R - 1);
  ------------------
  |  |   31|  1.68k|#define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  158|  1.68k|#define BN_MONT_CTX_N0_LIMBS 1
  |  |  ------------------
  |  |               #define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|  1.68k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  109|       |
  110|  1.68k|  const uint64_t beta = n;
  111|       |
  112|  1.68k|  uint64_t u = 1;
  113|  1.68k|  uint64_t v = 0;
  114|       |
  115|       |  // The invariant maintained from here on is:
  116|       |  // 2**(lg r - i) == u*2*alpha - v*beta.
  117|   109k|  for (size_t i = 0; i < LG_LITTLE_R; ++i) {
  ------------------
  |  |   31|   109k|#define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  158|   109k|#define BN_MONT_CTX_N0_LIMBS 1
  |  |  ------------------
  |  |               #define LG_LITTLE_R (BN_MONT_CTX_N0_LIMBS * BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|   109k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (117:22): [True: 108k, False: 1.68k]
  ------------------
  118|   108k|#if BN_BITS2 == 64 && defined(BN_ULLONG)
  119|   108k|    assert((BN_ULLONG)(1) << (LG_LITTLE_R - i) ==
  120|   108k|           ((BN_ULLONG)u * 2 * alpha) - ((BN_ULLONG)v * beta));
  121|   108k|#endif
  122|       |
  123|       |    // Delete a common factor of 2 in u and v if |u| is even. Otherwise, set
  124|       |    // |u = (u + beta) / 2| and |v = (v / 2) + alpha|.
  125|       |
  126|   108k|    uint64_t u_is_odd = UINT64_C(0) - (u & 1);  // Either 0xff..ff or 0.
  127|       |
  128|       |    // The addition can overflow, so use Dietz's method for it.
  129|       |    //
  130|       |    // Dietz calculates (x+y)/2 by (x⊕y)>>1 + x&y. This is valid for all
  131|       |    // (unsigned) x and y, even when x+y overflows. Evidence for 32-bit values
  132|       |    // (embedded in 64 bits to so that overflow can be ignored):
  133|       |    //
  134|       |    // (declare-fun x () (_ BitVec 64))
  135|       |    // (declare-fun y () (_ BitVec 64))
  136|       |    // (assert (let (
  137|       |    //    (one (_ bv1 64))
  138|       |    //    (thirtyTwo (_ bv32 64)))
  139|       |    //    (and
  140|       |    //      (bvult x (bvshl one thirtyTwo))
  141|       |    //      (bvult y (bvshl one thirtyTwo))
  142|       |    //      (not (=
  143|       |    //        (bvadd (bvlshr (bvxor x y) one) (bvand x y))
  144|       |    //        (bvlshr (bvadd x y) one)))
  145|       |    // )))
  146|       |    // (check-sat)
  147|   108k|    uint64_t beta_if_u_is_odd = beta & u_is_odd;  // Either |beta| or 0.
  148|   108k|    u = ((u ^ beta_if_u_is_odd) >> 1) + (u & beta_if_u_is_odd);
  149|       |
  150|   108k|    uint64_t alpha_if_u_is_odd = alpha & u_is_odd;  // Either |alpha| or 0.
  151|   108k|    v = (v >> 1) + alpha_if_u_is_odd;
  152|   108k|  }
  153|       |
  154|       |  // The invariant now shows that u*r - v*n == 1 since r == 2 * alpha.
  155|  1.68k|#if BN_BITS2 == 64 && defined(BN_ULLONG)
  156|  1.68k|  assert(1 == ((BN_ULLONG)u * 2 * alpha) - ((BN_ULLONG)v * beta));
  157|  1.68k|#endif
  158|       |
  159|  1.68k|  return v;
  160|  1.68k|}

BN_mul:
  515|  41.8k|int BN_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  516|  41.8k|  if (!bn_mul_impl(r, a, b, ctx)) {
  ------------------
  |  Branch (516:7): [True: 0, False: 41.8k]
  ------------------
  517|      0|    return 0;
  518|      0|  }
  519|       |
  520|       |  // This additionally fixes any negative zeros created by |bn_mul_impl|.
  521|  41.8k|  bn_set_minimal_width(r);
  522|  41.8k|  return 1;
  523|  41.8k|}
bn_mul_consttime:
  525|  1.75k|int bn_mul_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  526|       |  // Prevent negative zeros.
  527|  1.75k|  if (a->neg || b->neg) {
  ------------------
  |  Branch (527:7): [True: 0, False: 1.75k]
  |  Branch (527:17): [True: 0, False: 1.75k]
  ------------------
  528|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  529|      0|    return 0;
  530|      0|  }
  531|       |
  532|  1.75k|  return bn_mul_impl(r, a, b, ctx);
  533|  1.75k|}
bn_sqr_consttime:
  668|  1.01M|int bn_sqr_consttime(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx) {
  669|  1.01M|  int al = a->width;
  670|  1.01M|  if (al <= 0) {
  ------------------
  |  Branch (670:7): [True: 0, False: 1.01M]
  ------------------
  671|      0|    r->width = 0;
  672|      0|    r->neg = 0;
  673|      0|    return 1;
  674|      0|  }
  675|       |
  676|  1.01M|  int ret = 0;
  677|  1.01M|  BN_CTX_start(ctx);
  678|  1.01M|  BIGNUM *rr = (a != r) ? r : BN_CTX_get(ctx);
  ------------------
  |  Branch (678:16): [True: 998k, False: 19.5k]
  ------------------
  679|  1.01M|  BIGNUM *tmp = BN_CTX_get(ctx);
  680|  1.01M|  if (!rr || !tmp) {
  ------------------
  |  Branch (680:7): [True: 0, False: 1.01M]
  |  Branch (680:14): [True: 0, False: 1.01M]
  ------------------
  681|      0|    goto err;
  682|      0|  }
  683|       |
  684|  1.01M|  int max = 2 * al;  // Non-zero (from above)
  685|  1.01M|  if (!bn_wexpand(rr, max)) {
  ------------------
  |  Branch (685:7): [True: 0, False: 1.01M]
  ------------------
  686|      0|    goto err;
  687|      0|  }
  688|       |
  689|  1.01M|  if (al == 4) {
  ------------------
  |  Branch (689:7): [True: 1.01M, False: 39]
  ------------------
  690|  1.01M|    bn_sqr_comba4(rr->d, a->d);
  691|  1.01M|  } else if (al == 8) {
  ------------------
  |  Branch (691:14): [True: 0, False: 39]
  ------------------
  692|      0|    bn_sqr_comba8(rr->d, a->d);
  693|     39|  } else {
  694|     39|    if (al < BN_SQR_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   71|     39|#define BN_SQR_RECURSIVE_SIZE_NORMAL BN_MUL_RECURSIVE_SIZE_NORMAL
  |  |  ------------------
  |  |  |  |   70|     39|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  |  |  ------------------
  ------------------
  |  Branch (694:9): [True: 39, False: 0]
  ------------------
  695|     39|      BN_ULONG t[BN_SQR_RECURSIVE_SIZE_NORMAL * 2];
  696|     39|      bn_sqr_normal(rr->d, a->d, al, t);
  697|     39|    } else {
  698|       |      // If |al| is a power of two, we can use |bn_sqr_recursive|.
  699|      0|      if (al != 0 && (al & (al - 1)) == 0) {
  ------------------
  |  Branch (699:11): [True: 0, False: 0]
  |  Branch (699:22): [True: 0, False: 0]
  ------------------
  700|      0|        if (!bn_wexpand(tmp, al * 4)) {
  ------------------
  |  Branch (700:13): [True: 0, False: 0]
  ------------------
  701|      0|          goto err;
  702|      0|        }
  703|      0|        bn_sqr_recursive(rr->d, a->d, al, tmp->d);
  704|      0|      } else {
  705|      0|        if (!bn_wexpand(tmp, max)) {
  ------------------
  |  Branch (705:13): [True: 0, False: 0]
  ------------------
  706|      0|          goto err;
  707|      0|        }
  708|      0|        bn_sqr_normal(rr->d, a->d, al, tmp->d);
  709|      0|      }
  710|      0|    }
  711|     39|  }
  712|       |
  713|  1.01M|  rr->neg = 0;
  714|  1.01M|  rr->width = max;
  715|       |
  716|  1.01M|  if (rr != r && !BN_copy(r, rr)) {
  ------------------
  |  Branch (716:7): [True: 19.5k, False: 998k]
  |  Branch (716:18): [True: 0, False: 19.5k]
  ------------------
  717|      0|    goto err;
  718|      0|  }
  719|  1.01M|  ret = 1;
  720|       |
  721|  1.01M|err:
  722|  1.01M|  BN_CTX_end(ctx);
  723|  1.01M|  return ret;
  724|  1.01M|}
BN_sqr:
  726|  1.01M|int BN_sqr(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx) {
  727|  1.01M|  if (!bn_sqr_consttime(r, a, ctx)) {
  ------------------
  |  Branch (727:7): [True: 0, False: 1.01M]
  ------------------
  728|      0|    return 0;
  729|      0|  }
  730|       |
  731|  1.01M|  bn_set_minimal_width(r);
  732|  1.01M|  return 1;
  733|  1.01M|}
bcm.c:bn_abs_sub_part_words:
  172|  2.16k|                                      BN_ULONG *tmp) {
  173|  2.16k|  BN_ULONG borrow = bn_sub_part_words(tmp, a, b, cl, dl);
  174|  2.16k|  bn_sub_part_words(r, b, a, cl, -dl);
  175|  2.16k|  int r_len = cl + (dl < 0 ? -dl : dl);
  ------------------
  |  Branch (175:21): [True: 349, False: 1.81k]
  ------------------
  176|  2.16k|  borrow = 0 - borrow;
  177|  2.16k|  bn_select_words(r, borrow, r /* tmp < 0 */, tmp /* tmp >= 0 */, r_len);
  178|  2.16k|  return borrow;
  179|  2.16k|}
bcm.c:bn_sub_part_words:
  130|  4.33k|                                  const BN_ULONG *b, int cl, int dl) {
  131|  4.33k|  assert(cl >= 0);
  132|  4.33k|  BN_ULONG borrow = bn_sub_words(r, a, b, cl);
  133|  4.33k|  if (dl == 0) {
  ------------------
  |  Branch (133:7): [True: 2.94k, False: 1.39k]
  ------------------
  134|  2.94k|    return borrow;
  135|  2.94k|  }
  136|       |
  137|  1.39k|  r += cl;
  138|  1.39k|  a += cl;
  139|  1.39k|  b += cl;
  140|       |
  141|  1.39k|  if (dl < 0) {
  ------------------
  |  Branch (141:7): [True: 698, False: 698]
  ------------------
  142|       |    // |a| is shorter than |b|. Complete the subtraction as if the excess words
  143|       |    // in |a| were zeros.
  144|    698|    dl = -dl;
  145|  11.5k|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (145:21): [True: 10.8k, False: 698]
  ------------------
  146|  10.8k|      r[i] = 0u - b[i] - borrow;
  147|  10.8k|      borrow |= r[i] != 0;
  148|  10.8k|    }
  149|    698|  } else {
  150|       |    // |b| is shorter than |a|. Complete the subtraction as if the excess words
  151|       |    // in |b| were zeros.
  152|  11.5k|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (152:21): [True: 10.8k, False: 698]
  ------------------
  153|       |      // |r| and |a| may alias, so use a temporary.
  154|  10.8k|      BN_ULONG tmp = a[i];
  155|  10.8k|      r[i] = a[i] - borrow;
  156|  10.8k|      borrow = tmp < r[i];
  157|  10.8k|    }
  158|    698|  }
  159|       |
  160|  1.39k|  return borrow;
  161|  4.33k|}
bcm.c:bn_mul_impl:
  420|  43.6k|                       BN_CTX *ctx) {
  421|  43.6k|  int al = a->width;
  422|  43.6k|  int bl = b->width;
  423|  43.6k|  if (al == 0 || bl == 0) {
  ------------------
  |  Branch (423:7): [True: 6, False: 43.6k]
  |  Branch (423:18): [True: 0, False: 43.6k]
  ------------------
  424|      6|    BN_zero(r);
  425|      6|    return 1;
  426|      6|  }
  427|       |
  428|  43.6k|  int ret = 0;
  429|  43.6k|  BIGNUM *rr;
  430|  43.6k|  BN_CTX_start(ctx);
  431|  43.6k|  if (r == a || r == b) {
  ------------------
  |  Branch (431:7): [True: 0, False: 43.6k]
  |  Branch (431:17): [True: 0, False: 43.6k]
  ------------------
  432|      0|    rr = BN_CTX_get(ctx);
  433|      0|    if (rr == NULL) {
  ------------------
  |  Branch (433:9): [True: 0, False: 0]
  ------------------
  434|      0|      goto err;
  435|      0|    }
  436|  43.6k|  } else {
  437|  43.6k|    rr = r;
  438|  43.6k|  }
  439|  43.6k|  rr->neg = a->neg ^ b->neg;
  440|       |
  441|  43.6k|  int i = al - bl;
  442|  43.6k|  if (i == 0) {
  ------------------
  |  Branch (442:7): [True: 42.0k, False: 1.60k]
  ------------------
  443|  42.0k|    if (al == 8) {
  ------------------
  |  Branch (443:9): [True: 3, False: 42.0k]
  ------------------
  444|      3|      if (!bn_wexpand(rr, 16)) {
  ------------------
  |  Branch (444:11): [True: 0, False: 3]
  ------------------
  445|      0|        goto err;
  446|      0|      }
  447|      3|      rr->width = 16;
  448|      3|      bn_mul_comba8(rr->d, a->d, b->d);
  449|      3|      goto end;
  450|      3|    }
  451|  42.0k|  }
  452|       |
  453|  43.6k|  int top = al + bl;
  454|  43.6k|  static const int kMulNormalSize = 16;
  455|  43.6k|  if (al >= kMulNormalSize && bl >= kMulNormalSize) {
  ------------------
  |  Branch (455:7): [True: 642, False: 42.9k]
  |  Branch (455:31): [True: 362, False: 280]
  ------------------
  456|    362|    if (-1 <= i && i <= 1) {
  ------------------
  |  Branch (456:9): [True: 357, False: 5]
  |  Branch (456:20): [True: 353, False: 4]
  ------------------
  457|       |      // Find the largest power of two less than or equal to the larger length.
  458|    353|      int j;
  459|    353|      if (i >= 0) {
  ------------------
  |  Branch (459:11): [True: 349, False: 4]
  ------------------
  460|    349|        j = BN_num_bits_word((BN_ULONG)al);
  461|    349|      } else {
  462|      4|        j = BN_num_bits_word((BN_ULONG)bl);
  463|      4|      }
  464|    353|      j = 1 << (j - 1);
  465|    353|      assert(j <= al || j <= bl);
  466|    353|      BIGNUM *t = BN_CTX_get(ctx);
  467|    353|      if (t == NULL) {
  ------------------
  |  Branch (467:11): [True: 0, False: 353]
  ------------------
  468|      0|        goto err;
  469|      0|      }
  470|    353|      if (al > j || bl > j) {
  ------------------
  |  Branch (470:11): [True: 345, False: 8]
  |  Branch (470:21): [True: 4, False: 4]
  ------------------
  471|       |        // We know |al| and |bl| are at most one from each other, so if al > j,
  472|       |        // bl >= j, and vice versa. Thus we can use |bn_mul_part_recursive|.
  473|       |        //
  474|       |        // TODO(davidben): This codepath is almost unused in standard
  475|       |        // algorithms. Is this optimization necessary? See notes in
  476|       |        // https://boringssl-review.googlesource.com/q/I0bd604e2cd6a75c266f64476c23a730ca1721ea6
  477|    349|        assert(al >= j && bl >= j);
  478|    349|        if (!bn_wexpand(t, j * 8) ||
  ------------------
  |  Branch (478:13): [True: 0, False: 349]
  ------------------
  479|    349|            !bn_wexpand(rr, j * 4)) {
  ------------------
  |  Branch (479:13): [True: 0, False: 349]
  ------------------
  480|      0|          goto err;
  481|      0|        }
  482|    349|        bn_mul_part_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  483|    349|      } else {
  484|       |        // al <= j && bl <= j. Additionally, we know j <= al or j <= bl, so one
  485|       |        // of al - j or bl - j is zero. The other, by the bound on |i| above, is
  486|       |        // zero or -1. Thus, we can use |bn_mul_recursive|.
  487|      4|        if (!bn_wexpand(t, j * 4) ||
  ------------------
  |  Branch (487:13): [True: 0, False: 4]
  ------------------
  488|      4|            !bn_wexpand(rr, j * 2)) {
  ------------------
  |  Branch (488:13): [True: 0, False: 4]
  ------------------
  489|      0|          goto err;
  490|      0|        }
  491|      4|        bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  492|      4|      }
  493|    353|      rr->width = top;
  494|    353|      goto end;
  495|    353|    }
  496|    362|  }
  497|       |
  498|  43.2k|  if (!bn_wexpand(rr, top)) {
  ------------------
  |  Branch (498:7): [True: 0, False: 43.2k]
  ------------------
  499|      0|    goto err;
  500|      0|  }
  501|  43.2k|  rr->width = top;
  502|  43.2k|  bn_mul_normal(rr->d, a->d, al, b->d, bl);
  503|       |
  504|  43.6k|end:
  505|  43.6k|  if (r != rr && !BN_copy(r, rr)) {
  ------------------
  |  Branch (505:7): [True: 0, False: 43.6k]
  |  Branch (505:18): [True: 0, False: 0]
  ------------------
  506|      0|    goto err;
  507|      0|  }
  508|  43.6k|  ret = 1;
  509|       |
  510|  43.6k|err:
  511|  43.6k|  BN_CTX_end(ctx);
  512|  43.6k|  return ret;
  513|  43.6k|}
bcm.c:bn_mul_part_recursive:
  312|    349|                                  BN_ULONG *t) {
  313|       |  // |n| is a power of two.
  314|    349|  assert(n != 0 && (n & (n - 1)) == 0);
  315|       |  // Check |tna| and |tnb| are in range.
  316|    349|  assert(0 <= tna && tna < n);
  317|    349|  assert(0 <= tnb && tnb < n);
  318|    349|  assert(-1 <= tna - tnb && tna - tnb <= 1);
  319|       |
  320|    349|  int n2 = n * 2;
  321|    349|  if (n < 8) {
  ------------------
  |  Branch (321:7): [True: 0, False: 349]
  ------------------
  322|      0|    bn_mul_normal(r, a, n + tna, b, n + tnb);
  323|      0|    OPENSSL_memset(r + n2 + tna + tnb, 0, n2 - tna - tnb);
  324|      0|    return;
  325|      0|  }
  326|       |
  327|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|. |a1|
  328|       |  // and |b1| have size |tna| and |tnb|, respectively.
  329|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  330|       |  // for recursive calls.
  331|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  332|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  333|       |  //
  334|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  335|       |
  336|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  337|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  338|       |  // themselves store the absolute value.
  339|    349|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  340|    349|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  341|       |
  342|       |  // Compute:
  343|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  344|       |  // r0,r1 = a0 * b0
  345|       |  // r2,r3 = a1 * b1
  346|    349|  if (n == 8) {
  ------------------
  |  Branch (346:7): [True: 0, False: 349]
  ------------------
  347|      0|    bn_mul_comba8(&t[n2], t, &t[n]);
  348|      0|    bn_mul_comba8(r, a, b);
  349|       |
  350|      0|    bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  351|       |    // |bn_mul_normal| only writes |tna| + |tna| words. Zero the rest.
  352|      0|    OPENSSL_memset(&r[n2 + tna + tnb], 0, sizeof(BN_ULONG) * (n2 - tna - tnb));
  353|    349|  } else {
  354|    349|    BN_ULONG *p = &t[n2 * 2];
  355|    349|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  356|    349|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  357|       |
  358|    349|    OPENSSL_memset(&r[n2], 0, sizeof(BN_ULONG) * n2);
  359|    349|    if (tna < BN_MUL_RECURSIVE_SIZE_NORMAL &&
  ------------------
  |  |   70|    698|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (359:9): [True: 349, False: 0]
  ------------------
  360|    349|        tnb < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|    349|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (360:9): [True: 349, False: 0]
  ------------------
  361|    349|      bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  362|    349|    } else {
  363|      0|      int i = n;
  364|      0|      for (;;) {
  365|      0|        i /= 2;
  366|      0|        if (i < tna || i < tnb) {
  ------------------
  |  Branch (366:13): [True: 0, False: 0]
  |  Branch (366:24): [True: 0, False: 0]
  ------------------
  367|       |          // E.g., n == 16, i == 8 and tna == 11. |tna| and |tnb| are within one
  368|       |          // of each other, so if |tna| is larger and tna > i, then we know
  369|       |          // tnb >= i, and this call is valid.
  370|      0|          bn_mul_part_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  371|      0|          break;
  372|      0|        }
  373|      0|        if (i == tna || i == tnb) {
  ------------------
  |  Branch (373:13): [True: 0, False: 0]
  |  Branch (373:25): [True: 0, False: 0]
  ------------------
  374|       |          // If there is only a bottom half to the number, just do it. We know
  375|       |          // the larger of |tna - i| and |tnb - i| is zero. The other is zero or
  376|       |          // -1 by because of |tna| and |tnb| differ by at most one.
  377|      0|          bn_mul_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  378|      0|          break;
  379|      0|        }
  380|       |
  381|       |        // This loop will eventually terminate when |i| falls below
  382|       |        // |BN_MUL_RECURSIVE_SIZE_NORMAL| because we know one of |tna| and |tnb|
  383|       |        // exceeds that.
  384|      0|      }
  385|      0|    }
  386|    349|  }
  387|       |
  388|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  389|    349|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  390|       |
  391|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  392|       |  // The second term is stored as the absolute value, so we do this with a
  393|       |  // constant-time select.
  394|    349|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  395|    349|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  396|    349|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  397|    349|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  398|    349|                "crypto_word_t is too small");
  399|    349|  c = constant_time_select_w(neg, c_neg, c_pos);
  400|       |
  401|       |  // We now have our three components. Add them together.
  402|       |  // r1,r2,c = r1,r2 + t2,t3,c
  403|    349|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  404|       |
  405|       |  // Propagate the carry bit to the end.
  406|  6.01k|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (406:24): [True: 5.66k, False: 349]
  ------------------
  407|  5.66k|    BN_ULONG old = r[i];
  408|  5.66k|    r[i] = old + c;
  409|  5.66k|    c = r[i] < old;
  410|  5.66k|  }
  411|       |
  412|       |  // The product should fit without carries.
  413|    349|  assert(c == 0);
  414|    349|}
bcm.c:bn_mul_recursive:
  211|    735|                             int n2, int dna, int dnb, BN_ULONG *t) {
  212|       |  // |n2| is a power of two.
  213|    735|  assert(n2 != 0 && (n2 & (n2 - 1)) == 0);
  214|       |  // Check |dna| and |dnb| are in range.
  215|    735|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dna && dna <= 0);
  216|    735|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dnb && dnb <= 0);
  217|       |
  218|       |  // Only call bn_mul_comba 8 if n2 == 8 and the
  219|       |  // two arrays are complete [steve]
  220|    735|  if (n2 == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (220:7): [True: 0, False: 735]
  |  Branch (220:18): [True: 0, False: 0]
  |  Branch (220:30): [True: 0, False: 0]
  ------------------
  221|      0|    bn_mul_comba8(r, a, b);
  222|      0|    return;
  223|      0|  }
  224|       |
  225|       |  // Else do normal multiply
  226|    735|  if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|    735|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (226:7): [True: 0, False: 735]
  ------------------
  227|      0|    bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
  228|      0|    if (dna + dnb < 0) {
  ------------------
  |  Branch (228:9): [True: 0, False: 0]
  ------------------
  229|      0|      OPENSSL_memset(&r[2 * n2 + dna + dnb], 0,
  230|      0|                     sizeof(BN_ULONG) * -(dna + dnb));
  231|      0|    }
  232|      0|    return;
  233|      0|  }
  234|       |
  235|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|.
  236|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  237|       |  // for recursive calls.
  238|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  239|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  240|       |  //
  241|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  242|       |  //
  243|       |  // Note that we know |n| >= |BN_MUL_RECURSIVE_SIZE_NORMAL|/2 above, so
  244|       |  // |tna| and |tnb| are non-negative.
  245|    735|  int n = n2 / 2, tna = n + dna, tnb = n + dnb;
  246|       |
  247|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  248|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  249|       |  // themselves store the absolute value.
  250|    735|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  251|    735|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  252|       |
  253|       |  // Compute:
  254|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  255|       |  // r0,r1 = a0 * b0
  256|       |  // r2,r3 = a1 * b1
  257|    735|  if (n == 4 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (257:7): [True: 0, False: 735]
  |  Branch (257:17): [True: 0, False: 0]
  |  Branch (257:29): [True: 0, False: 0]
  ------------------
  258|      0|    bn_mul_comba4(&t[n2], t, &t[n]);
  259|       |
  260|      0|    bn_mul_comba4(r, a, b);
  261|      0|    bn_mul_comba4(&r[n2], &a[n], &b[n]);
  262|    735|  } else if (n == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (262:14): [True: 724, False: 11]
  |  Branch (262:24): [True: 724, False: 0]
  |  Branch (262:36): [True: 724, False: 0]
  ------------------
  263|    724|    bn_mul_comba8(&t[n2], t, &t[n]);
  264|       |
  265|    724|    bn_mul_comba8(r, a, b);
  266|    724|    bn_mul_comba8(&r[n2], &a[n], &b[n]);
  267|    724|  } else {
  268|     11|    BN_ULONG *p = &t[n2 * 2];
  269|     11|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  270|     11|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  271|     11|    bn_mul_recursive(&r[n2], &a[n], &b[n], n, dna, dnb, p);
  272|     11|  }
  273|       |
  274|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  275|    735|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  276|       |
  277|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  278|       |  // The second term is stored as the absolute value, so we do this with a
  279|       |  // constant-time select.
  280|    735|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  281|    735|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  282|    735|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  283|    735|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  284|    735|                "crypto_word_t is too small");
  285|    735|  c = constant_time_select_w(neg, c_neg, c_pos);
  286|       |
  287|       |  // We now have our three components. Add them together.
  288|       |  // r1,r2,c = r1,r2 + t2,t3,c
  289|    735|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  290|       |
  291|       |  // Propagate the carry bit to the end.
  292|  6.70k|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (292:24): [True: 5.96k, False: 735]
  ------------------
  293|  5.96k|    BN_ULONG old = r[i];
  294|  5.96k|    r[i] = old + c;
  295|  5.96k|    c = r[i] < old;
  296|  5.96k|  }
  297|       |
  298|       |  // The product should fit without carries.
  299|    735|  assert(c == 0);
  300|    735|}
bcm.c:bn_mul_normal:
   82|  43.6k|                          const BN_ULONG *b, size_t nb) {
   83|  43.6k|  if (na < nb) {
  ------------------
  |  Branch (83:7): [True: 1.10k, False: 42.4k]
  ------------------
   84|  1.10k|    size_t itmp = na;
   85|  1.10k|    na = nb;
   86|  1.10k|    nb = itmp;
   87|  1.10k|    const BN_ULONG *ltmp = a;
   88|  1.10k|    a = b;
   89|  1.10k|    b = ltmp;
   90|  1.10k|  }
   91|  43.6k|  BN_ULONG *rr = &(r[na]);
   92|  43.6k|  if (nb == 0) {
  ------------------
  |  Branch (92:7): [True: 190, False: 43.4k]
  ------------------
   93|    190|    OPENSSL_memset(r, 0, na * sizeof(BN_ULONG));
   94|    190|    return;
   95|    190|  }
   96|  43.4k|  rr[0] = bn_mul_words(r, a, na, b[0]);
   97|       |
   98|  43.7k|  for (;;) {
   99|  43.7k|    if (--nb == 0) {
  ------------------
  |  Branch (99:9): [True: 1.41k, False: 42.3k]
  ------------------
  100|  1.41k|      return;
  101|  1.41k|    }
  102|  42.3k|    rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  103|  42.3k|    if (--nb == 0) {
  ------------------
  |  Branch (103:9): [True: 59, False: 42.2k]
  ------------------
  104|     59|      return;
  105|     59|    }
  106|  42.2k|    rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  107|  42.2k|    if (--nb == 0) {
  ------------------
  |  Branch (107:9): [True: 95, False: 42.1k]
  ------------------
  108|     95|      return;
  109|     95|    }
  110|  42.1k|    rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  111|  42.1k|    if (--nb == 0) {
  ------------------
  |  Branch (111:9): [True: 41.8k, False: 347]
  ------------------
  112|  41.8k|      return;
  113|  41.8k|    }
  114|    347|    rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  115|    347|    rr += 4;
  116|    347|    r += 4;
  117|    347|    b += 4;
  118|    347|  }
  119|  43.4k|}
bcm.c:bn_sqr_normal:
  551|     39|                          BN_ULONG *tmp) {
  552|     39|  if (n == 0) {
  ------------------
  |  Branch (552:7): [True: 0, False: 39]
  ------------------
  553|      0|    return;
  554|      0|  }
  555|       |
  556|     39|  size_t max = n * 2;
  557|     39|  const BN_ULONG *ap = a;
  558|     39|  BN_ULONG *rp = r;
  559|     39|  rp[0] = rp[max - 1] = 0;
  560|     39|  rp++;
  561|       |
  562|       |  // Compute the contribution of a[i] * a[j] for all i < j.
  563|     39|  if (n > 1) {
  ------------------
  |  Branch (563:7): [True: 39, False: 0]
  ------------------
  564|     39|    ap++;
  565|     39|    rp[n - 1] = bn_mul_words(rp, ap, n - 1, ap[-1]);
  566|     39|    rp += 2;
  567|     39|  }
  568|     39|  if (n > 2) {
  ------------------
  |  Branch (568:7): [True: 39, False: 0]
  ------------------
  569|    162|    for (size_t i = n - 2; i > 0; i--) {
  ------------------
  |  Branch (569:28): [True: 123, False: 39]
  ------------------
  570|    123|      ap++;
  571|    123|      rp[i] = bn_mul_add_words(rp, ap, i, ap[-1]);
  572|    123|      rp += 2;
  573|    123|    }
  574|     39|  }
  575|       |
  576|       |  // The final result fits in |max| words, so none of the following operations
  577|       |  // will overflow.
  578|       |
  579|       |  // Double |r|, giving the contribution of a[i] * a[j] for all i != j.
  580|     39|  bn_add_words(r, r, r, max);
  581|       |
  582|       |  // Add in the contribution of a[i] * a[i] for all i.
  583|     39|  bn_sqr_words(tmp, a, n);
  584|     39|  bn_add_words(r, r, tmp, max);
  585|     39|}

BN_lshift:
   67|  2.14M|int BN_lshift(BIGNUM *r, const BIGNUM *a, int n) {
   68|  2.14M|  int i, nw, lb, rb;
   69|  2.14M|  BN_ULONG *t, *f;
   70|  2.14M|  BN_ULONG l;
   71|       |
   72|  2.14M|  if (n < 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 2.14M]
  ------------------
   73|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   74|      0|    return 0;
   75|      0|  }
   76|       |
   77|  2.14M|  r->neg = a->neg;
   78|  2.14M|  nw = n / BN_BITS2;
  ------------------
  |  |  151|  2.14M|#define BN_BITS2 64
  ------------------
   79|  2.14M|  if (!bn_wexpand(r, a->width + nw + 1)) {
  ------------------
  |  Branch (79:7): [True: 0, False: 2.14M]
  ------------------
   80|      0|    return 0;
   81|      0|  }
   82|  2.14M|  lb = n % BN_BITS2;
  ------------------
  |  |  151|  2.14M|#define BN_BITS2 64
  ------------------
   83|  2.14M|  rb = BN_BITS2 - lb;
  ------------------
  |  |  151|  2.14M|#define BN_BITS2 64
  ------------------
   84|  2.14M|  f = a->d;
   85|  2.14M|  t = r->d;
   86|  2.14M|  t[a->width + nw] = 0;
   87|  2.14M|  if (lb == 0) {
  ------------------
  |  Branch (87:7): [True: 704, False: 2.14M]
  ------------------
   88|  4.66k|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (88:28): [True: 3.95k, False: 704]
  ------------------
   89|  3.95k|      t[nw + i] = f[i];
   90|  3.95k|    }
   91|  2.14M|  } else {
   92|  13.8M|    for (i = a->width - 1; i >= 0; i--) {
  ------------------
  |  Branch (92:28): [True: 11.6M, False: 2.14M]
  ------------------
   93|  11.6M|      l = f[i];
   94|  11.6M|      t[nw + i + 1] |= l >> rb;
   95|  11.6M|      t[nw + i] = l << lb;
   96|  11.6M|    }
   97|  2.14M|  }
   98|  2.14M|  OPENSSL_memset(t, 0, nw * sizeof(t[0]));
   99|  2.14M|  r->width = a->width + nw + 1;
  100|  2.14M|  bn_set_minimal_width(r);
  101|       |
  102|  2.14M|  return 1;
  103|  2.14M|}
bn_rshift_words:
  137|  1.08M|                     size_t num) {
  138|  1.08M|  unsigned shift_bits = shift % BN_BITS2;
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  139|  1.08M|  size_t shift_words = shift / BN_BITS2;
  ------------------
  |  |  151|  1.08M|#define BN_BITS2 64
  ------------------
  140|  1.08M|  if (shift_words >= num) {
  ------------------
  |  Branch (140:7): [True: 5.85k, False: 1.07M]
  ------------------
  141|  5.85k|    OPENSSL_memset(r, 0, num * sizeof(BN_ULONG));
  142|  5.85k|    return;
  143|  5.85k|  }
  144|  1.07M|  if (shift_bits == 0) {
  ------------------
  |  Branch (144:7): [True: 5.60k, False: 1.06M]
  ------------------
  145|  5.60k|    OPENSSL_memmove(r, a + shift_words, (num - shift_words) * sizeof(BN_ULONG));
  146|  1.06M|  } else {
  147|  4.19M|    for (size_t i = shift_words; i < num - 1; i++) {
  ------------------
  |  Branch (147:34): [True: 3.12M, False: 1.06M]
  ------------------
  148|  3.12M|      r[i - shift_words] =
  149|  3.12M|          (a[i] >> shift_bits) | (a[i + 1] << (BN_BITS2 - shift_bits));
  ------------------
  |  |  151|  3.12M|#define BN_BITS2 64
  ------------------
  150|  3.12M|    }
  151|  1.06M|    r[num - 1 - shift_words] = a[num - 1] >> shift_bits;
  152|  1.06M|  }
  153|  1.07M|  OPENSSL_memset(r + num - shift_words, 0, shift_words * sizeof(BN_ULONG));
  154|  1.07M|}
BN_rshift:
  156|  1.08M|int BN_rshift(BIGNUM *r, const BIGNUM *a, int n) {
  157|  1.08M|  if (n < 0) {
  ------------------
  |  Branch (157:7): [True: 0, False: 1.08M]
  ------------------
  158|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  159|      0|    return 0;
  160|      0|  }
  161|       |
  162|  1.08M|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (162:7): [True: 0, False: 1.08M]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|  1.08M|  bn_rshift_words(r->d, a->d, n, a->width);
  166|  1.08M|  r->neg = a->neg;
  167|  1.08M|  r->width = a->width;
  168|  1.08M|  bn_set_minimal_width(r);
  169|  1.08M|  return 1;
  170|  1.08M|}
bn_rshift1_words:
  200|    584|void bn_rshift1_words(BN_ULONG *r, const BN_ULONG *a, size_t num) {
  201|    584|  if (num == 0) {
  ------------------
  |  Branch (201:7): [True: 0, False: 584]
  ------------------
  202|      0|    return;
  203|      0|  }
  204|  1.16k|  for (size_t i = 0; i < num - 1; i++) {
  ------------------
  |  Branch (204:22): [True: 584, False: 584]
  ------------------
  205|    584|    r[i] = (a[i] >> 1) | (a[i + 1] << (BN_BITS2 - 1));
  ------------------
  |  |  151|    584|#define BN_BITS2 64
  ------------------
  206|    584|  }
  207|    584|  r[num - 1] = a[num - 1] >> 1;
  208|    584|}
BN_rshift1:
  210|    584|int BN_rshift1(BIGNUM *r, const BIGNUM *a) {
  211|    584|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (211:7): [True: 0, False: 584]
  ------------------
  212|      0|    return 0;
  213|      0|  }
  214|    584|  bn_rshift1_words(r->d, a->d, a->width);
  215|    584|  r->width = a->width;
  216|    584|  r->neg = a->neg;
  217|    584|  bn_set_minimal_width(r);
  218|    584|  return 1;
  219|    584|}
BN_set_bit:
  221|  1.68k|int BN_set_bit(BIGNUM *a, int n) {
  222|  1.68k|  if (n < 0) {
  ------------------
  |  Branch (222:7): [True: 0, False: 1.68k]
  ------------------
  223|      0|    return 0;
  224|      0|  }
  225|       |
  226|  1.68k|  int i = n / BN_BITS2;
  ------------------
  |  |  151|  1.68k|#define BN_BITS2 64
  ------------------
  227|  1.68k|  int j = n % BN_BITS2;
  ------------------
  |  |  151|  1.68k|#define BN_BITS2 64
  ------------------
  228|  1.68k|  if (a->width <= i) {
  ------------------
  |  Branch (228:7): [True: 1.68k, False: 0]
  ------------------
  229|  1.68k|    if (!bn_wexpand(a, i + 1)) {
  ------------------
  |  Branch (229:9): [True: 0, False: 1.68k]
  ------------------
  230|      0|      return 0;
  231|      0|    }
  232|  14.5k|    for (int k = a->width; k < i + 1; k++) {
  ------------------
  |  Branch (232:28): [True: 12.9k, False: 1.68k]
  ------------------
  233|  12.9k|      a->d[k] = 0;
  234|  12.9k|    }
  235|  1.68k|    a->width = i + 1;
  236|  1.68k|  }
  237|       |
  238|  1.68k|  a->d[i] |= (((BN_ULONG)1) << j);
  239|       |
  240|  1.68k|  return 1;
  241|  1.68k|}
bn_is_bit_set_words:
  261|   431k|int bn_is_bit_set_words(const BN_ULONG *a, size_t num, size_t bit) {
  262|   431k|  size_t i = bit / BN_BITS2;
  ------------------
  |  |  151|   431k|#define BN_BITS2 64
  ------------------
  263|   431k|  size_t j = bit % BN_BITS2;
  ------------------
  |  |  151|   431k|#define BN_BITS2 64
  ------------------
  264|   431k|  if (i >= num) {
  ------------------
  |  Branch (264:7): [True: 164, False: 430k]
  ------------------
  265|    164|    return 0;
  266|    164|  }
  267|   430k|  return (a[i] >> j) & 1;
  268|   431k|}
BN_is_bit_set:
  270|   284k|int BN_is_bit_set(const BIGNUM *a, int n) {
  271|   284k|  if (n < 0) {
  ------------------
  |  Branch (271:7): [True: 0, False: 284k]
  ------------------
  272|      0|    return 0;
  273|      0|  }
  274|   284k|  return bn_is_bit_set_words(a->d, a->width, n);
  275|   284k|}

BN_mod_sqrt:
   62|    671|BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx) {
   63|       |  // Compute a square root of |a| mod |p| using the Tonelli/Shanks algorithm
   64|       |  // (cf. Henri Cohen, "A Course in Algebraic Computational Number Theory",
   65|       |  // algorithm 1.5.1). |p| is assumed to be a prime.
   66|       |
   67|    671|  BIGNUM *ret = in;
   68|    671|  int err = 1;
   69|    671|  int r;
   70|    671|  BIGNUM *A, *b, *q, *t, *x, *y;
   71|    671|  int e, i, j;
   72|       |
   73|    671|  if (!BN_is_odd(p) || BN_abs_is_word(p, 1)) {
  ------------------
  |  Branch (73:7): [True: 0, False: 671]
  |  Branch (73:24): [True: 0, False: 671]
  ------------------
   74|      0|    if (BN_abs_is_word(p, 2)) {
  ------------------
  |  Branch (74:9): [True: 0, False: 0]
  ------------------
   75|      0|      if (ret == NULL) {
  ------------------
  |  Branch (75:11): [True: 0, False: 0]
  ------------------
   76|      0|        ret = BN_new();
   77|      0|      }
   78|      0|      if (ret == NULL ||
  ------------------
  |  Branch (78:11): [True: 0, False: 0]
  ------------------
   79|      0|          !BN_set_word(ret, BN_is_bit_set(a, 0))) {
  ------------------
  |  Branch (79:11): [True: 0, False: 0]
  ------------------
   80|      0|        if (ret != in) {
  ------------------
  |  Branch (80:13): [True: 0, False: 0]
  ------------------
   81|      0|          BN_free(ret);
   82|      0|        }
   83|      0|        return NULL;
   84|      0|      }
   85|      0|      return ret;
   86|      0|    }
   87|       |
   88|      0|    OPENSSL_PUT_ERROR(BN, BN_R_P_IS_NOT_PRIME);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   89|      0|    return NULL;
   90|      0|  }
   91|       |
   92|    671|  if (BN_is_zero(a) || BN_is_one(a)) {
  ------------------
  |  Branch (92:7): [True: 0, False: 671]
  |  Branch (92:24): [True: 0, False: 671]
  ------------------
   93|      0|    if (ret == NULL) {
  ------------------
  |  Branch (93:9): [True: 0, False: 0]
  ------------------
   94|      0|      ret = BN_new();
   95|      0|    }
   96|      0|    if (ret == NULL ||
  ------------------
  |  Branch (96:9): [True: 0, False: 0]
  ------------------
   97|      0|        !BN_set_word(ret, BN_is_one(a))) {
  ------------------
  |  Branch (97:9): [True: 0, False: 0]
  ------------------
   98|      0|      if (ret != in) {
  ------------------
  |  Branch (98:11): [True: 0, False: 0]
  ------------------
   99|      0|        BN_free(ret);
  100|      0|      }
  101|      0|      return NULL;
  102|      0|    }
  103|      0|    return ret;
  104|      0|  }
  105|       |
  106|    671|  BN_CTX_start(ctx);
  107|    671|  A = BN_CTX_get(ctx);
  108|    671|  b = BN_CTX_get(ctx);
  109|    671|  q = BN_CTX_get(ctx);
  110|    671|  t = BN_CTX_get(ctx);
  111|    671|  x = BN_CTX_get(ctx);
  112|    671|  y = BN_CTX_get(ctx);
  113|    671|  if (y == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 671]
  ------------------
  114|      0|    goto end;
  115|      0|  }
  116|       |
  117|    671|  if (ret == NULL) {
  ------------------
  |  Branch (117:7): [True: 0, False: 671]
  ------------------
  118|      0|    ret = BN_new();
  119|      0|  }
  120|    671|  if (ret == NULL) {
  ------------------
  |  Branch (120:7): [True: 0, False: 671]
  ------------------
  121|      0|    goto end;
  122|      0|  }
  123|       |
  124|       |  // A = a mod p
  125|    671|  if (!BN_nnmod(A, a, p, ctx)) {
  ------------------
  |  Branch (125:7): [True: 0, False: 671]
  ------------------
  126|      0|    goto end;
  127|      0|  }
  128|       |
  129|       |  // now write  |p| - 1  as  2^e*q  where  q  is odd
  130|    671|  e = 1;
  131|  56.1k|  while (!BN_is_bit_set(p, e)) {
  ------------------
  |  Branch (131:10): [True: 55.4k, False: 671]
  ------------------
  132|  55.4k|    e++;
  133|  55.4k|  }
  134|       |  // we'll set  q  later (if needed)
  135|       |
  136|    671|  if (e == 1) {
  ------------------
  |  Branch (136:7): [True: 87, False: 584]
  ------------------
  137|       |    // The easy case:  (|p|-1)/2  is odd, so 2 has an inverse
  138|       |    // modulo  (|p|-1)/2,  and square roots can be computed
  139|       |    // directly by modular exponentiation.
  140|       |    // We have
  141|       |    //     2 * (|p|+1)/4 == 1   (mod (|p|-1)/2),
  142|       |    // so we can use exponent  (|p|+1)/4,  i.e.  (|p|-3)/4 + 1.
  143|     87|    if (!BN_rshift(q, p, 2)) {
  ------------------
  |  Branch (143:9): [True: 0, False: 87]
  ------------------
  144|      0|      goto end;
  145|      0|    }
  146|     87|    q->neg = 0;
  147|     87|    if (!BN_add_word(q, 1) ||
  ------------------
  |  Branch (147:9): [True: 0, False: 87]
  ------------------
  148|     87|        !BN_mod_exp_mont(ret, A, q, p, ctx, NULL)) {
  ------------------
  |  Branch (148:9): [True: 0, False: 87]
  ------------------
  149|      0|      goto end;
  150|      0|    }
  151|     87|    err = 0;
  152|     87|    goto vrfy;
  153|     87|  }
  154|       |
  155|    584|  if (e == 2) {
  ------------------
  |  Branch (155:7): [True: 0, False: 584]
  ------------------
  156|       |    // |p| == 5  (mod 8)
  157|       |    //
  158|       |    // In this case  2  is always a non-square since
  159|       |    // Legendre(2,p) = (-1)^((p^2-1)/8)  for any odd prime.
  160|       |    // So if  a  really is a square, then  2*a  is a non-square.
  161|       |    // Thus for
  162|       |    //      b := (2*a)^((|p|-5)/8),
  163|       |    //      i := (2*a)*b^2
  164|       |    // we have
  165|       |    //     i^2 = (2*a)^((1 + (|p|-5)/4)*2)
  166|       |    //         = (2*a)^((p-1)/2)
  167|       |    //         = -1;
  168|       |    // so if we set
  169|       |    //      x := a*b*(i-1),
  170|       |    // then
  171|       |    //     x^2 = a^2 * b^2 * (i^2 - 2*i + 1)
  172|       |    //         = a^2 * b^2 * (-2*i)
  173|       |    //         = a*(-i)*(2*a*b^2)
  174|       |    //         = a*(-i)*i
  175|       |    //         = a.
  176|       |    //
  177|       |    // (This is due to A.O.L. Atkin,
  178|       |    // <URL:
  179|       |    //http://listserv.nodak.edu/scripts/wa.exe?A2=ind9211&L=nmbrthry&O=T&P=562>,
  180|       |    // November 1992.)
  181|       |
  182|       |    // t := 2*a
  183|      0|    if (!bn_mod_lshift1_consttime(t, A, p, ctx)) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      goto end;
  185|      0|    }
  186|       |
  187|       |    // b := (2*a)^((|p|-5)/8)
  188|      0|    if (!BN_rshift(q, p, 3)) {
  ------------------
  |  Branch (188:9): [True: 0, False: 0]
  ------------------
  189|      0|      goto end;
  190|      0|    }
  191|      0|    q->neg = 0;
  192|      0|    if (!BN_mod_exp_mont(b, t, q, p, ctx, NULL)) {
  ------------------
  |  Branch (192:9): [True: 0, False: 0]
  ------------------
  193|      0|      goto end;
  194|      0|    }
  195|       |
  196|       |    // y := b^2
  197|      0|    if (!BN_mod_sqr(y, b, p, ctx)) {
  ------------------
  |  Branch (197:9): [True: 0, False: 0]
  ------------------
  198|      0|      goto end;
  199|      0|    }
  200|       |
  201|       |    // t := (2*a)*b^2 - 1
  202|      0|    if (!BN_mod_mul(t, t, y, p, ctx) ||
  ------------------
  |  Branch (202:9): [True: 0, False: 0]
  ------------------
  203|      0|        !BN_sub_word(t, 1)) {
  ------------------
  |  Branch (203:9): [True: 0, False: 0]
  ------------------
  204|      0|      goto end;
  205|      0|    }
  206|       |
  207|       |    // x = a*b*t
  208|      0|    if (!BN_mod_mul(x, A, b, p, ctx) ||
  ------------------
  |  Branch (208:9): [True: 0, False: 0]
  ------------------
  209|      0|        !BN_mod_mul(x, x, t, p, ctx)) {
  ------------------
  |  Branch (209:9): [True: 0, False: 0]
  ------------------
  210|      0|      goto end;
  211|      0|    }
  212|       |
  213|      0|    if (!BN_copy(ret, x)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 0]
  ------------------
  214|      0|      goto end;
  215|      0|    }
  216|      0|    err = 0;
  217|      0|    goto vrfy;
  218|      0|  }
  219|       |
  220|       |  // e > 2, so we really have to use the Tonelli/Shanks algorithm.
  221|       |  // First, find some  y  that is not a square.
  222|    584|  if (!BN_copy(q, p)) {
  ------------------
  |  Branch (222:7): [True: 0, False: 584]
  ------------------
  223|      0|    goto end;  // use 'q' as temp
  224|      0|  }
  225|    584|  q->neg = 0;
  226|    584|  i = 2;
  227|  5.84k|  do {
  228|       |    // For efficiency, try small numbers first;
  229|       |    // if this fails, try random numbers.
  230|  5.84k|    if (i < 22) {
  ------------------
  |  Branch (230:9): [True: 5.84k, False: 0]
  ------------------
  231|  5.84k|      if (!BN_set_word(y, i)) {
  ------------------
  |  Branch (231:11): [True: 0, False: 5.84k]
  ------------------
  232|      0|        goto end;
  233|      0|      }
  234|  5.84k|    } else {
  235|      0|      if (!BN_pseudo_rand(y, BN_num_bits(p), 0, 0)) {
  ------------------
  |  Branch (235:11): [True: 0, False: 0]
  ------------------
  236|      0|        goto end;
  237|      0|      }
  238|      0|      if (BN_ucmp(y, p) >= 0) {
  ------------------
  |  Branch (238:11): [True: 0, False: 0]
  ------------------
  239|      0|        if (!(p->neg ? BN_add : BN_sub)(y, y, p)) {
  ------------------
  |  Branch (239:13): [True: 0, False: 0]
  |  Branch (239:15): [True: 0, False: 0]
  ------------------
  240|      0|          goto end;
  241|      0|        }
  242|      0|      }
  243|       |      // now 0 <= y < |p|
  244|      0|      if (BN_is_zero(y)) {
  ------------------
  |  Branch (244:11): [True: 0, False: 0]
  ------------------
  245|      0|        if (!BN_set_word(y, i)) {
  ------------------
  |  Branch (245:13): [True: 0, False: 0]
  ------------------
  246|      0|          goto end;
  247|      0|        }
  248|      0|      }
  249|      0|    }
  250|       |
  251|  5.84k|    r = bn_jacobi(y, q, ctx);  // here 'q' is |p|
  252|  5.84k|    if (r < -1) {
  ------------------
  |  Branch (252:9): [True: 0, False: 5.84k]
  ------------------
  253|      0|      goto end;
  254|      0|    }
  255|  5.84k|    if (r == 0) {
  ------------------
  |  Branch (255:9): [True: 0, False: 5.84k]
  ------------------
  256|       |      // m divides p
  257|      0|      OPENSSL_PUT_ERROR(BN, BN_R_P_IS_NOT_PRIME);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  258|      0|      goto end;
  259|      0|    }
  260|  5.84k|  } while (r == 1 && ++i < 82);
  ------------------
  |  Branch (260:12): [True: 5.25k, False: 584]
  |  Branch (260:22): [True: 5.25k, False: 0]
  ------------------
  261|       |
  262|    584|  if (r != -1) {
  ------------------
  |  Branch (262:7): [True: 0, False: 584]
  ------------------
  263|       |    // Many rounds and still no non-square -- this is more likely
  264|       |    // a bug than just bad luck.
  265|       |    // Even if  p  is not prime, we should have found some  y
  266|       |    // such that r == -1.
  267|      0|    OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_ITERATIONS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|    goto end;
  269|      0|  }
  270|       |
  271|       |  // Here's our actual 'q':
  272|    584|  if (!BN_rshift(q, q, e)) {
  ------------------
  |  Branch (272:7): [True: 0, False: 584]
  ------------------
  273|      0|    goto end;
  274|      0|  }
  275|       |
  276|       |  // Now that we have some non-square, we can find an element
  277|       |  // of order  2^e  by computing its q'th power.
  278|    584|  if (!BN_mod_exp_mont(y, y, q, p, ctx, NULL)) {
  ------------------
  |  Branch (278:7): [True: 0, False: 584]
  ------------------
  279|      0|    goto end;
  280|      0|  }
  281|    584|  if (BN_is_one(y)) {
  ------------------
  |  Branch (281:7): [True: 0, False: 584]
  ------------------
  282|      0|    OPENSSL_PUT_ERROR(BN, BN_R_P_IS_NOT_PRIME);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|    goto end;
  284|      0|  }
  285|       |
  286|       |  // Now we know that (if  p  is indeed prime) there is an integer
  287|       |  // k,  0 <= k < 2^e,  such that
  288|       |  //
  289|       |  //      a^q * y^k == 1   (mod p).
  290|       |  //
  291|       |  // As  a^q  is a square and  y  is not,  k  must be even.
  292|       |  // q+1  is even, too, so there is an element
  293|       |  //
  294|       |  //     X := a^((q+1)/2) * y^(k/2),
  295|       |  //
  296|       |  // and it satisfies
  297|       |  //
  298|       |  //     X^2 = a^q * a     * y^k
  299|       |  //         = a,
  300|       |  //
  301|       |  // so it is the square root that we are looking for.
  302|       |
  303|       |  // t := (q-1)/2  (note that  q  is odd)
  304|    584|  if (!BN_rshift1(t, q)) {
  ------------------
  |  Branch (304:7): [True: 0, False: 584]
  ------------------
  305|      0|    goto end;
  306|      0|  }
  307|       |
  308|       |  // x := a^((q-1)/2)
  309|    584|  if (BN_is_zero(t)) {  // special case: p = 2^e + 1
  ------------------
  |  Branch (309:7): [True: 0, False: 584]
  ------------------
  310|      0|    if (!BN_nnmod(t, A, p, ctx)) {
  ------------------
  |  Branch (310:9): [True: 0, False: 0]
  ------------------
  311|      0|      goto end;
  312|      0|    }
  313|      0|    if (BN_is_zero(t)) {
  ------------------
  |  Branch (313:9): [True: 0, False: 0]
  ------------------
  314|       |      // special case: a == 0  (mod p)
  315|      0|      BN_zero(ret);
  316|      0|      err = 0;
  317|      0|      goto end;
  318|      0|    } else if (!BN_one(x)) {
  ------------------
  |  Branch (318:16): [True: 0, False: 0]
  ------------------
  319|      0|      goto end;
  320|      0|    }
  321|    584|  } else {
  322|    584|    if (!BN_mod_exp_mont(x, A, t, p, ctx, NULL)) {
  ------------------
  |  Branch (322:9): [True: 0, False: 584]
  ------------------
  323|      0|      goto end;
  324|      0|    }
  325|    584|    if (BN_is_zero(x)) {
  ------------------
  |  Branch (325:9): [True: 0, False: 584]
  ------------------
  326|       |      // special case: a == 0  (mod p)
  327|      0|      BN_zero(ret);
  328|      0|      err = 0;
  329|      0|      goto end;
  330|      0|    }
  331|    584|  }
  332|       |
  333|       |  // b := a*x^2  (= a^q)
  334|    584|  if (!BN_mod_sqr(b, x, p, ctx) ||
  ------------------
  |  Branch (334:7): [True: 0, False: 584]
  ------------------
  335|    584|      !BN_mod_mul(b, b, A, p, ctx)) {
  ------------------
  |  Branch (335:7): [True: 0, False: 584]
  ------------------
  336|      0|    goto end;
  337|      0|  }
  338|       |
  339|       |  // x := a*x    (= a^((q+1)/2))
  340|    584|  if (!BN_mod_mul(x, x, A, p, ctx)) {
  ------------------
  |  Branch (340:7): [True: 0, False: 584]
  ------------------
  341|      0|    goto end;
  342|      0|  }
  343|       |
  344|  20.5k|  while (1) {
  ------------------
  |  Branch (344:10): [Folded - Ignored]
  ------------------
  345|       |    // Now  b  is  a^q * y^k  for some even  k  (0 <= k < 2^E
  346|       |    // where  E  refers to the original value of  e,  which we
  347|       |    // don't keep in a variable),  and  x  is  a^((q+1)/2) * y^(k/2).
  348|       |    //
  349|       |    // We have  a*b = x^2,
  350|       |    //    y^2^(e-1) = -1,
  351|       |    //    b^2^(e-1) = 1.
  352|  20.5k|    if (BN_is_one(b)) {
  ------------------
  |  Branch (352:9): [True: 421, False: 20.1k]
  ------------------
  353|    421|      if (!BN_copy(ret, x)) {
  ------------------
  |  Branch (353:11): [True: 0, False: 421]
  ------------------
  354|      0|        goto end;
  355|      0|      }
  356|    421|      err = 0;
  357|    421|      goto vrfy;
  358|    421|    }
  359|       |
  360|       |    // Find the smallest i, 0 < i < e, such that b^(2^i) = 1
  361|   976k|    for (i = 1; i < e; i++) {
  ------------------
  |  Branch (361:17): [True: 976k, False: 163]
  ------------------
  362|   976k|      if (i == 1) {
  ------------------
  |  Branch (362:11): [True: 20.1k, False: 956k]
  ------------------
  363|  20.1k|        if (!BN_mod_sqr(t, b, p, ctx)) {
  ------------------
  |  Branch (363:13): [True: 0, False: 20.1k]
  ------------------
  364|      0|          goto end;
  365|      0|        }
  366|   956k|      } else {
  367|   956k|        if (!BN_mod_mul(t, t, t, p, ctx)) {
  ------------------
  |  Branch (367:13): [True: 0, False: 956k]
  ------------------
  368|      0|          goto end;
  369|      0|        }
  370|   956k|      }
  371|   976k|      if (BN_is_one(t)) {
  ------------------
  |  Branch (371:11): [True: 20.0k, False: 956k]
  ------------------
  372|  20.0k|        break;
  373|  20.0k|      }
  374|   976k|    }
  375|       |    // If not found, a is not a square or p is not a prime.
  376|  20.1k|    if (i >= e) {
  ------------------
  |  Branch (376:9): [True: 163, False: 20.0k]
  ------------------
  377|    163|      OPENSSL_PUT_ERROR(BN, BN_R_NOT_A_SQUARE);
  ------------------
  |  |  441|    163|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  378|    163|      goto end;
  379|    163|    }
  380|       |
  381|       |    // t := y^2^(e - i - 1)
  382|  20.0k|    if (!BN_copy(t, y)) {
  ------------------
  |  Branch (382:9): [True: 0, False: 20.0k]
  ------------------
  383|      0|      goto end;
  384|      0|    }
  385|  39.5k|    for (j = e - i - 1; j > 0; j--) {
  ------------------
  |  Branch (385:25): [True: 19.5k, False: 20.0k]
  ------------------
  386|  19.5k|      if (!BN_mod_sqr(t, t, p, ctx)) {
  ------------------
  |  Branch (386:11): [True: 0, False: 19.5k]
  ------------------
  387|      0|        goto end;
  388|      0|      }
  389|  19.5k|    }
  390|  20.0k|    if (!BN_mod_mul(y, t, t, p, ctx) ||
  ------------------
  |  Branch (390:9): [True: 0, False: 20.0k]
  ------------------
  391|  20.0k|        !BN_mod_mul(x, x, t, p, ctx) ||
  ------------------
  |  Branch (391:9): [True: 0, False: 20.0k]
  ------------------
  392|  20.0k|        !BN_mod_mul(b, b, y, p, ctx)) {
  ------------------
  |  Branch (392:9): [True: 0, False: 20.0k]
  ------------------
  393|      0|      goto end;
  394|      0|    }
  395|       |
  396|       |    // e decreases each iteration, so this loop will terminate.
  397|  20.0k|    assert(i < e);
  398|  20.0k|    e = i;
  399|  20.0k|  }
  400|       |
  401|    508|vrfy:
  402|    508|  if (!err) {
  ------------------
  |  Branch (402:7): [True: 508, False: 0]
  ------------------
  403|       |    // Verify the result. The input might have been not a square.
  404|    508|    if (!BN_mod_sqr(x, ret, p, ctx)) {
  ------------------
  |  Branch (404:9): [True: 0, False: 508]
  ------------------
  405|      0|      err = 1;
  406|      0|    }
  407|       |
  408|    508|    if (!err && 0 != BN_cmp(x, A)) {
  ------------------
  |  Branch (408:9): [True: 508, False: 0]
  |  Branch (408:17): [True: 29, False: 479]
  ------------------
  409|     29|      OPENSSL_PUT_ERROR(BN, BN_R_NOT_A_SQUARE);
  ------------------
  |  |  441|     29|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  410|     29|      err = 1;
  411|     29|    }
  412|    508|  }
  413|       |
  414|    671|end:
  415|    671|  if (err) {
  ------------------
  |  Branch (415:7): [True: 192, False: 479]
  ------------------
  416|    192|    if (ret != in) {
  ------------------
  |  Branch (416:9): [True: 0, False: 192]
  ------------------
  417|      0|      BN_clear_free(ret);
  418|      0|    }
  419|    192|    ret = NULL;
  420|    192|  }
  421|    671|  BN_CTX_end(ctx);
  422|    671|  return ret;
  423|    508|}

BN_value_one:
   56|    450|  accessor_decorations type *name(void) {                                     \
   57|    450|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|    450|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|    450|     * cast is needed. */                                                     \
   60|    450|    return (const type *)name##_storage_bss_get();                            \
   61|    450|  }                                                                           \
OPENSSL_built_in_curves:
   56|  2.82k|  accessor_decorations type *name(void) {                                     \
   57|  2.82k|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|  2.82k|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|  2.82k|     * cast is needed. */                                                     \
   60|  2.82k|    return (const type *)name##_storage_bss_get();                            \
   61|  2.82k|  }                                                                           \
EC_GFp_mont_method:
   56|      2|  accessor_decorations type *name(void) {                                     \
   57|      2|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      2|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      2|     * cast is needed. */                                                     \
   60|      2|    return (const type *)name##_storage_bss_get();                            \
   61|      2|  }                                                                           \
EC_GFp_nistp224_method:
   56|      1|  accessor_decorations type *name(void) {                                     \
   57|      1|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      1|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      1|     * cast is needed. */                                                     \
   60|      1|    return (const type *)name##_storage_bss_get();                            \
   61|      1|  }                                                                           \
EC_GFp_nistz256_method:
   56|      1|  accessor_decorations type *name(void) {                                     \
   57|      1|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      1|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      1|     * cast is needed. */                                                     \
   60|      1|    return (const type *)name##_storage_bss_get();                            \
   61|      1|  }                                                                           \
RSA_default_method:
   56|  2.20k|  accessor_decorations type *name(void) {                                     \
   57|  2.20k|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|  2.20k|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|  2.20k|     * cast is needed. */                                                     \
   60|  2.20k|    return (const type *)name##_storage_bss_get();                            \
   61|  2.20k|  }                                                                           \
bcm.c:BN_value_one_once_bss_get:
   42|    450|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:BN_value_one_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:BN_value_one_storage_bss_get:
   39|    451|  static type *name##_bss_get(void) { return &name; }
bcm.c:OPENSSL_built_in_curves_once_bss_get:
   42|  2.82k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:OPENSSL_built_in_curves_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:OPENSSL_built_in_curves_storage_bss_get:
   39|  2.82k|  static type *name##_bss_get(void) { return &name; }
bcm.c:built_in_groups_bss_get:
   39|  1.32k|  static type *name##_bss_get(void) { return &name; }
bcm.c:built_in_groups_lock_bss_get:
   45|  2.66k|  static struct CRYPTO_STATIC_MUTEX *name##_bss_get(void) { return &name; }
bcm.c:g_ec_ex_data_class_bss_get:
   48|  1.23k|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_mont_method_once_bss_get:
   42|      2|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_mont_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_mont_method_storage_bss_get:
   39|      3|  static type *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistp224_method_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistp224_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_nistp224_method_storage_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistz256_method_once_bss_get:
   42|      1|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:EC_GFp_nistz256_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:EC_GFp_nistz256_method_storage_bss_get:
   39|      2|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_rsa_ex_data_class_bss_get:
   48|  2.20k|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_once_bss_get:
   42|  2.20k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_init:
   55|      1|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:RSA_default_method_storage_bss_get:
   39|  2.20k|  static type *name##_bss_get(void) { return &name; }

ec_group_new:
  273|      4|EC_GROUP *ec_group_new(const EC_METHOD *meth) {
  274|      4|  EC_GROUP *ret;
  275|       |
  276|      4|  if (meth == NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 4]
  ------------------
  277|      0|    OPENSSL_PUT_ERROR(EC, EC_R_SLOT_FULL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  278|      0|    return NULL;
  279|      0|  }
  280|       |
  281|      4|  if (meth->group_init == 0) {
  ------------------
  |  Branch (281:7): [True: 0, False: 4]
  ------------------
  282|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|    return NULL;
  284|      0|  }
  285|       |
  286|      4|  ret = OPENSSL_malloc(sizeof(EC_GROUP));
  287|      4|  if (ret == NULL) {
  ------------------
  |  Branch (287:7): [True: 0, False: 4]
  ------------------
  288|      0|    return NULL;
  289|      0|  }
  290|      4|  OPENSSL_memset(ret, 0, sizeof(EC_GROUP));
  291|       |
  292|      4|  ret->references = 1;
  293|      4|  ret->meth = meth;
  294|      4|  BN_init(&ret->order);
  295|       |
  296|      4|  if (!meth->group_init(ret)) {
  ------------------
  |  Branch (296:7): [True: 0, False: 4]
  ------------------
  297|      0|    OPENSSL_free(ret);
  298|      0|    return NULL;
  299|      0|  }
  300|       |
  301|      4|  return ret;
  302|      4|}
EC_GROUP_new_by_curve_name:
  505|  1.32k|EC_GROUP *EC_GROUP_new_by_curve_name(int nid) {
  506|  1.32k|  struct built_in_groups_st *groups = built_in_groups_bss_get();
  507|  1.32k|  EC_GROUP **group_ptr = NULL;
  508|  1.32k|  const struct built_in_curves *const curves = OPENSSL_built_in_curves();
  509|  1.32k|  const struct built_in_curve *curve = NULL;
  510|  4.36k|  for (size_t i = 0; i < OPENSSL_NUM_BUILT_IN_CURVES; i++) {
  ------------------
  |  |  780|  4.36k|#define OPENSSL_NUM_BUILT_IN_CURVES 4
  ------------------
  |  Branch (510:22): [True: 4.36k, False: 0]
  ------------------
  511|  4.36k|    if (curves->curves[i].nid == nid) {
  ------------------
  |  Branch (511:9): [True: 1.32k, False: 3.03k]
  ------------------
  512|  1.32k|      curve = &curves->curves[i];
  513|  1.32k|      group_ptr = &groups->groups[i];
  514|  1.32k|      break;
  515|  1.32k|    }
  516|  4.36k|  }
  517|       |
  518|  1.32k|  if (curve == NULL) {
  ------------------
  |  Branch (518:7): [True: 0, False: 1.32k]
  ------------------
  519|      0|    OPENSSL_PUT_ERROR(EC, EC_R_UNKNOWN_GROUP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  520|      0|    return NULL;
  521|      0|  }
  522|       |
  523|  1.32k|  CRYPTO_STATIC_MUTEX_lock_read(built_in_groups_lock_bss_get());
  524|  1.32k|  EC_GROUP *ret = *group_ptr;
  525|  1.32k|  CRYPTO_STATIC_MUTEX_unlock_read(built_in_groups_lock_bss_get());
  526|  1.32k|  if (ret != NULL) {
  ------------------
  |  Branch (526:7): [True: 1.32k, False: 4]
  ------------------
  527|  1.32k|    return ret;
  528|  1.32k|  }
  529|       |
  530|      4|  ret = ec_group_new_from_data(curve);
  531|      4|  if (ret == NULL) {
  ------------------
  |  Branch (531:7): [True: 0, False: 4]
  ------------------
  532|      0|    return NULL;
  533|      0|  }
  534|       |
  535|      4|  EC_GROUP *to_free = NULL;
  536|      4|  CRYPTO_STATIC_MUTEX_lock_write(built_in_groups_lock_bss_get());
  537|      4|  if (*group_ptr == NULL) {
  ------------------
  |  Branch (537:7): [True: 4, False: 0]
  ------------------
  538|      4|    *group_ptr = ret;
  539|       |    // Filling in |ret->curve_name| makes |EC_GROUP_free| and |EC_GROUP_dup|
  540|       |    // into no-ops. At this point, |ret| is considered static.
  541|      4|    ret->curve_name = nid;
  542|      4|  } else {
  543|      0|    to_free = ret;
  544|      0|    ret = *group_ptr;
  545|      0|  }
  546|      4|  CRYPTO_STATIC_MUTEX_unlock_write(built_in_groups_lock_bss_get());
  547|       |
  548|      4|  EC_GROUP_free(to_free);
  549|      4|  return ret;
  550|      4|}
EC_GROUP_free:
  552|  6.29k|void EC_GROUP_free(EC_GROUP *group) {
  553|  6.29k|  if (group == NULL ||
  ------------------
  |  Branch (553:7): [True: 2.49k, False: 3.79k]
  ------------------
  554|       |      // Built-in curves are static.
  555|  6.29k|      group->curve_name != NID_undef ||
  ------------------
  |  |   85|  10.0k|#define NID_undef 0
  ------------------
  |  Branch (555:7): [True: 3.79k, False: 0]
  ------------------
  556|  6.29k|      !CRYPTO_refcount_dec_and_test_zero(&group->references)) {
  ------------------
  |  Branch (556:7): [True: 0, False: 0]
  ------------------
  557|  6.29k|    return;
  558|  6.29k|  }
  559|       |
  560|      0|  if (group->meth->group_finish != NULL) {
  ------------------
  |  Branch (560:7): [True: 0, False: 0]
  ------------------
  561|      0|    group->meth->group_finish(group);
  562|      0|  }
  563|       |
  564|      0|  ec_point_free(group->generator, 0 /* don't free group */);
  565|      0|  BN_free(&group->order);
  566|      0|  BN_MONT_CTX_free(group->order_mont);
  567|       |
  568|      0|  OPENSSL_free(group);
  569|      0|}
EC_GROUP_dup:
  571|  2.47k|EC_GROUP *EC_GROUP_dup(const EC_GROUP *a) {
  572|  2.47k|  if (a == NULL ||
  ------------------
  |  Branch (572:7): [True: 0, False: 2.47k]
  ------------------
  573|       |      // Built-in curves are static.
  574|  2.47k|      a->curve_name != NID_undef) {
  ------------------
  |  |   85|  2.47k|#define NID_undef 0
  ------------------
  |  Branch (574:7): [True: 2.46k, False: 4]
  ------------------
  575|  2.46k|    return (EC_GROUP *)a;
  576|  2.46k|  }
  577|       |
  578|       |  // Groups are logically immutable (but for |EC_GROUP_set_generator| which must
  579|       |  // be called early on), so we simply take a reference.
  580|      4|  EC_GROUP *group = (EC_GROUP *)a;
  581|      4|  CRYPTO_refcount_inc(&group->references);
  582|      4|  return group;
  583|  2.47k|}
EC_GROUP_cmp:
  585|  3.11k|int EC_GROUP_cmp(const EC_GROUP *a, const EC_GROUP *b, BN_CTX *ignored) {
  586|       |  // Note this function returns 0 if equal and non-zero otherwise.
  587|  3.11k|  if (a == b) {
  ------------------
  |  Branch (587:7): [True: 3.10k, False: 2]
  ------------------
  588|  3.10k|    return 0;
  589|  3.10k|  }
  590|      2|  if (a->curve_name != b->curve_name) {
  ------------------
  |  Branch (590:7): [True: 2, False: 0]
  ------------------
  591|      2|    return 1;
  592|      2|  }
  593|      0|  if (a->curve_name != NID_undef) {
  ------------------
  |  |   85|      0|#define NID_undef 0
  ------------------
  |  Branch (593:7): [True: 0, False: 0]
  ------------------
  594|       |    // Built-in curves may be compared by curve name alone.
  595|      0|    return 0;
  596|      0|  }
  597|       |
  598|       |  // |a| and |b| are both custom curves. We compare the entire curve
  599|       |  // structure. If |a| or |b| is incomplete (due to legacy OpenSSL mistakes,
  600|       |  // custom curve construction is sadly done in two parts) but otherwise not the
  601|       |  // same object, we consider them always unequal.
  602|      0|  return a->meth != b->meth ||
  ------------------
  |  Branch (602:10): [True: 0, False: 0]
  ------------------
  603|      0|         a->generator == NULL ||
  ------------------
  |  Branch (603:10): [True: 0, False: 0]
  ------------------
  604|      0|         b->generator == NULL ||
  ------------------
  |  Branch (604:10): [True: 0, False: 0]
  ------------------
  605|      0|         BN_cmp(&a->order, &b->order) != 0 ||
  ------------------
  |  Branch (605:10): [True: 0, False: 0]
  ------------------
  606|      0|         BN_cmp(&a->field, &b->field) != 0 ||
  ------------------
  |  Branch (606:10): [True: 0, False: 0]
  ------------------
  607|      0|         !ec_felem_equal(a, &a->a, &b->a) ||
  ------------------
  |  Branch (607:10): [True: 0, False: 0]
  ------------------
  608|      0|         !ec_felem_equal(a, &a->b, &b->b) ||
  ------------------
  |  Branch (608:10): [True: 0, False: 0]
  ------------------
  609|      0|         !ec_GFp_simple_points_equal(a, &a->generator->raw, &b->generator->raw);
  ------------------
  |  Branch (609:10): [True: 0, False: 0]
  ------------------
  610|      0|}
EC_GROUP_get_curve_GFp:
  639|    671|                           BIGNUM *out_b, BN_CTX *ctx) {
  640|    671|  return ec_GFp_simple_group_get_curve(group, out_p, out_a, out_b);
  641|    671|}
EC_POINT_new:
  679|  1.23k|EC_POINT *EC_POINT_new(const EC_GROUP *group) {
  680|  1.23k|  if (group == NULL) {
  ------------------
  |  Branch (680:7): [True: 0, False: 1.23k]
  ------------------
  681|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  682|      0|    return NULL;
  683|      0|  }
  684|       |
  685|  1.23k|  EC_POINT *ret = OPENSSL_malloc(sizeof *ret);
  686|  1.23k|  if (ret == NULL) {
  ------------------
  |  Branch (686:7): [True: 0, False: 1.23k]
  ------------------
  687|      0|    return NULL;
  688|      0|  }
  689|       |
  690|  1.23k|  ret->group = EC_GROUP_dup(group);
  691|  1.23k|  ec_GFp_simple_point_init(&ret->raw);
  692|  1.23k|  return ret;
  693|  1.23k|}
EC_POINT_free:
  705|  1.23k|void EC_POINT_free(EC_POINT *point) {
  706|  1.23k|  ec_point_free(point, 1 /* free group */);
  707|  1.23k|}
EC_POINT_is_at_infinity:
  747|    601|int EC_POINT_is_at_infinity(const EC_GROUP *group, const EC_POINT *point) {
  748|    601|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (748:7): [True: 0, False: 601]
  ------------------
  749|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  750|      0|    return 0;
  751|      0|  }
  752|    601|  return ec_GFp_simple_is_at_infinity(group, &point->raw);
  753|    601|}
EC_POINT_is_on_curve:
  756|    601|                         BN_CTX *ctx) {
  757|    601|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (757:7): [True: 0, False: 601]
  ------------------
  758|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  759|      0|    return 0;
  760|      0|  }
  761|    601|  return ec_GFp_simple_is_on_curve(group, &point->raw);
  762|    601|}
ec_affine_to_jacobian:
  805|    485|                           const EC_AFFINE *p) {
  806|    485|  out->X = p->X;
  807|    485|  out->Y = p->Y;
  808|    485|  out->Z = group->one;
  809|    485|}
ec_point_set_affine_coordinates:
  826|    487|                                    const EC_FELEM *x, const EC_FELEM *y) {
  827|    487|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  828|    487|                          const EC_FELEM *b) = group->meth->felem_mul;
  829|    487|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  830|    487|      group->meth->felem_sqr;
  831|       |
  832|       |  // Check if the point is on the curve.
  833|    487|  EC_FELEM lhs, rhs;
  834|    487|  felem_sqr(group, &lhs, y);                   // lhs = y^2
  835|    487|  felem_sqr(group, &rhs, x);                   // rhs = x^2
  836|    487|  ec_felem_add(group, &rhs, &rhs, &group->a);  // rhs = x^2 + a
  837|    487|  felem_mul(group, &rhs, &rhs, x);             // rhs = x^3 + ax
  838|    487|  ec_felem_add(group, &rhs, &rhs, &group->b);  // rhs = x^3 + ax + b
  839|    487|  if (!ec_felem_equal(group, &lhs, &rhs)) {
  ------------------
  |  Branch (839:7): [True: 2, False: 485]
  ------------------
  840|      2|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_IS_NOT_ON_CURVE);
  ------------------
  |  |  441|      2|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  841|       |    // In the event of an error, defend against the caller not checking the
  842|       |    // return value by setting a known safe value. Note this may not be possible
  843|       |    // if the caller is in the process of constructing an arbitrary group and
  844|       |    // the generator is missing.
  845|      2|    if (group->generator != NULL) {
  ------------------
  |  Branch (845:9): [True: 2, False: 0]
  ------------------
  846|      2|      assert(ec_felem_equal(group, &group->one, &group->generator->raw.Z));
  847|      2|      out->X = group->generator->raw.X;
  848|      2|      out->Y = group->generator->raw.Y;
  849|      2|    }
  850|      2|    return 0;
  851|      2|  }
  852|       |
  853|    485|  out->X = *x;
  854|    485|  out->Y = *y;
  855|    485|  return 1;
  856|    487|}
EC_POINT_set_affine_coordinates_GFp:
  860|    479|                                        BN_CTX *ctx) {
  861|    479|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (861:7): [True: 0, False: 479]
  ------------------
  862|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  863|      0|    return 0;
  864|      0|  }
  865|       |
  866|    479|  if (x == NULL || y == NULL) {
  ------------------
  |  Branch (866:7): [True: 0, False: 479]
  |  Branch (866:20): [True: 0, False: 479]
  ------------------
  867|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  868|      0|    return 0;
  869|      0|  }
  870|       |
  871|    479|  EC_FELEM x_felem, y_felem;
  872|    479|  EC_AFFINE affine;
  873|    479|  if (!ec_bignum_to_felem(group, &x_felem, x) ||
  ------------------
  |  Branch (873:7): [True: 0, False: 479]
  ------------------
  874|    479|      !ec_bignum_to_felem(group, &y_felem, y) ||
  ------------------
  |  Branch (874:7): [True: 0, False: 479]
  ------------------
  875|    479|      !ec_point_set_affine_coordinates(group, &affine, &x_felem, &y_felem)) {
  ------------------
  |  Branch (875:7): [True: 0, False: 479]
  ------------------
  876|       |    // In the event of an error, defend against the caller not checking the
  877|       |    // return value by setting a known safe value.
  878|      0|    ec_set_to_safe_point(group, &point->raw);
  879|      0|    return 0;
  880|      0|  }
  881|       |
  882|    479|  ec_affine_to_jacobian(group, &point->raw, &affine);
  883|    479|  return 1;
  884|    479|}
ec_point_mul_scalar_base:
 1068|    942|                             const EC_SCALAR *scalar) {
 1069|    942|  if (scalar == NULL) {
  ------------------
  |  Branch (1069:7): [True: 0, False: 942]
  ------------------
 1070|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1071|      0|    return 0;
 1072|      0|  }
 1073|       |
 1074|    942|  group->meth->mul_base(group, r, scalar);
 1075|       |
 1076|       |  // Check the result is on the curve to defend against fault attacks or bugs.
 1077|       |  // This has negligible cost compared to the multiplication. This can only
 1078|       |  // happen on bug or CPU fault, so it okay to leak this. The alternative would
 1079|       |  // be to proceed with bad data.
 1080|    942|  if (!constant_time_declassify_int(ec_GFp_simple_is_on_curve(group, r))) {
  ------------------
  |  Branch (1080:7): [True: 0, False: 942]
  ------------------
 1081|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1082|      0|    return 0;
 1083|      0|  }
 1084|       |
 1085|    942|  return 1;
 1086|    942|}
ec_point_select:
 1143|   938k|                      const EC_JACOBIAN *a, const EC_JACOBIAN *b) {
 1144|   938k|  ec_felem_select(group, &out->X, mask, &a->X, &b->X);
 1145|   938k|  ec_felem_select(group, &out->Y, mask, &a->Y, &b->Y);
 1146|   938k|  ec_felem_select(group, &out->Z, mask, &a->Z, &b->Z);
 1147|   938k|}
ec_set_to_safe_point:
 1224|     28|void ec_set_to_safe_point(const EC_GROUP *group, EC_JACOBIAN *out) {
 1225|     28|  if (group->generator != NULL) {
  ------------------
  |  Branch (1225:7): [True: 28, False: 0]
  ------------------
 1226|     28|    ec_GFp_simple_point_copy(out, &group->generator->raw);
 1227|     28|  } else {
 1228|       |    // The generator can be missing if the caller is in the process of
 1229|       |    // constructing an arbitrary group. In this case, we give up and use the
 1230|       |    // point at infinity.
 1231|      0|    ec_GFp_simple_point_set_to_infinity(group, out);
 1232|      0|  }
 1233|     28|}
bcm.c:OPENSSL_built_in_curves_do_init:
  218|      1|DEFINE_METHOD_FUNCTION(struct built_in_curves, OPENSSL_built_in_curves) {
  219|       |  // 1.3.132.0.35
  220|      1|  static const uint8_t kOIDP521[] = {0x2b, 0x81, 0x04, 0x00, 0x23};
  221|      1|  out->curves[0].nid = NID_secp521r1;
  ------------------
  |  | 3172|      1|#define NID_secp521r1 716
  ------------------
  222|      1|  out->curves[0].oid = kOIDP521;
  223|      1|  out->curves[0].oid_len = sizeof(kOIDP521);
  224|      1|  out->curves[0].comment = "NIST P-521";
  225|      1|  out->curves[0].param_len = 66;
  226|      1|  out->curves[0].params = kP521Params;
  227|      1|  out->curves[0].method = EC_GFp_mont_method();
  228|       |
  229|       |  // 1.3.132.0.34
  230|      1|  static const uint8_t kOIDP384[] = {0x2b, 0x81, 0x04, 0x00, 0x22};
  231|      1|  out->curves[1].nid = NID_secp384r1;
  ------------------
  |  | 3168|      1|#define NID_secp384r1 715
  ------------------
  232|      1|  out->curves[1].oid = kOIDP384;
  233|      1|  out->curves[1].oid_len = sizeof(kOIDP384);
  234|      1|  out->curves[1].comment = "NIST P-384";
  235|      1|  out->curves[1].param_len = 48;
  236|      1|  out->curves[1].params = kP384Params;
  237|      1|  out->curves[1].method = EC_GFp_mont_method();
  238|       |
  239|       |  // 1.2.840.10045.3.1.7
  240|      1|  static const uint8_t kOIDP256[] = {0x2a, 0x86, 0x48, 0xce,
  241|      1|                                     0x3d, 0x03, 0x01, 0x07};
  242|      1|  out->curves[2].nid = NID_X9_62_prime256v1;
  ------------------
  |  | 1914|      1|#define NID_X9_62_prime256v1 415
  ------------------
  243|      1|  out->curves[2].oid = kOIDP256;
  244|      1|  out->curves[2].oid_len = sizeof(kOIDP256);
  245|      1|  out->curves[2].comment = "NIST P-256";
  246|      1|  out->curves[2].param_len = 32;
  247|      1|  out->curves[2].params = kP256Params;
  248|      1|  out->curves[2].method =
  249|      1|#if !defined(OPENSSL_NO_ASM) && \
  250|      1|    (defined(OPENSSL_X86_64) || defined(OPENSSL_AARCH64)) &&   \
  251|      1|    !defined(OPENSSL_SMALL)
  252|      1|      EC_GFp_nistz256_method();
  253|       |#else
  254|       |      EC_GFp_nistp256_method();
  255|       |#endif
  256|       |
  257|       |  // 1.3.132.0.33
  258|      1|  static const uint8_t kOIDP224[] = {0x2b, 0x81, 0x04, 0x00, 0x21};
  259|      1|  out->curves[3].nid = NID_secp224r1;
  ------------------
  |  | 3160|      1|#define NID_secp224r1 713
  ------------------
  260|      1|  out->curves[3].oid = kOIDP224;
  261|      1|  out->curves[3].oid_len = sizeof(kOIDP224);
  262|      1|  out->curves[3].comment = "NIST P-224";
  263|      1|  out->curves[3].param_len = 28;
  264|      1|  out->curves[3].params = kP224Params;
  265|      1|  out->curves[3].method =
  266|      1|#if defined(BORINGSSL_HAS_UINT128) && !defined(OPENSSL_SMALL)
  267|      1|      EC_GFp_nistp224_method();
  268|       |#else
  269|       |      EC_GFp_mont_method();
  270|       |#endif
  271|      1|}
bcm.c:ec_group_set_generator:
  305|      4|                                  const BIGNUM *order) {
  306|      4|  assert(group->generator == NULL);
  307|       |
  308|      4|  if (!BN_copy(&group->order, order)) {
  ------------------
  |  Branch (308:7): [True: 0, False: 4]
  ------------------
  309|      0|    return 0;
  310|      0|  }
  311|       |  // Store the order in minimal form, so it can be used with |BN_ULONG| arrays.
  312|      4|  bn_set_minimal_width(&group->order);
  313|       |
  314|      4|  BN_MONT_CTX_free(group->order_mont);
  315|      4|  group->order_mont = BN_MONT_CTX_new_for_modulus(&group->order, NULL);
  316|      4|  if (group->order_mont == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 4]
  ------------------
  317|      0|    return 0;
  318|      0|  }
  319|       |
  320|      4|  group->field_greater_than_order = BN_cmp(&group->field, order) > 0;
  321|      4|  if (group->field_greater_than_order) {
  ------------------
  |  Branch (321:7): [True: 4, False: 0]
  ------------------
  322|      4|    BIGNUM tmp;
  323|      4|    BN_init(&tmp);
  324|      4|    int ok =
  325|      4|        BN_sub(&tmp, &group->field, order) &&
  ------------------
  |  Branch (325:9): [True: 4, False: 0]
  ------------------
  326|      4|        bn_copy_words(group->field_minus_order.words, group->field.width, &tmp);
  ------------------
  |  Branch (326:9): [True: 4, False: 0]
  ------------------
  327|      4|    BN_free(&tmp);
  328|      4|    if (!ok) {
  ------------------
  |  Branch (328:9): [True: 0, False: 4]
  ------------------
  329|      0|      return 0;
  330|      0|    }
  331|      4|  }
  332|       |
  333|      4|  group->generator = EC_POINT_new(group);
  334|      4|  if (group->generator == NULL) {
  ------------------
  |  Branch (334:7): [True: 0, False: 4]
  ------------------
  335|      0|    return 0;
  336|      0|  }
  337|      4|  ec_affine_to_jacobian(group, &group->generator->raw, generator);
  338|      4|  assert(ec_felem_equal(group, &group->one, &group->generator->raw.Z));
  339|       |
  340|       |  // Avoid a reference cycle. |group->generator| does not maintain an owning
  341|       |  // pointer to |group|.
  342|      4|  int is_zero = CRYPTO_refcount_dec_and_test_zero(&group->references);
  343|       |
  344|      4|  assert(!is_zero);
  345|      4|  (void)is_zero;
  346|      4|  return 1;
  347|      4|}
bcm.c:ec_group_new_from_data:
  442|      4|static EC_GROUP *ec_group_new_from_data(const struct built_in_curve *curve) {
  443|      4|  EC_GROUP *group = NULL;
  444|      4|  BIGNUM *p = NULL, *a = NULL, *b = NULL, *order = NULL;
  445|      4|  int ok = 0;
  446|       |
  447|      4|  BN_CTX *ctx = BN_CTX_new();
  448|      4|  if (ctx == NULL) {
  ------------------
  |  Branch (448:7): [True: 0, False: 4]
  ------------------
  449|      0|    goto err;
  450|      0|  }
  451|       |
  452|      4|  const unsigned param_len = curve->param_len;
  453|      4|  const uint8_t *params = curve->params;
  454|       |
  455|      4|  if (!(p = BN_bin2bn(params + 0 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (455:7): [True: 0, False: 4]
  ------------------
  456|      4|      !(a = BN_bin2bn(params + 1 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (456:7): [True: 0, False: 4]
  ------------------
  457|      4|      !(b = BN_bin2bn(params + 2 * param_len, param_len, NULL)) ||
  ------------------
  |  Branch (457:7): [True: 0, False: 4]
  ------------------
  458|      4|      !(order = BN_bin2bn(params + 5 * param_len, param_len, NULL))) {
  ------------------
  |  Branch (458:7): [True: 0, False: 4]
  ------------------
  459|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  460|      0|    goto err;
  461|      0|  }
  462|       |
  463|      4|  group = ec_group_new(curve->method);
  464|      4|  if (group == NULL ||
  ------------------
  |  Branch (464:7): [True: 0, False: 4]
  ------------------
  465|      4|      !group->meth->group_set_curve(group, p, a, b, ctx)) {
  ------------------
  |  Branch (465:7): [True: 0, False: 4]
  ------------------
  466|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_EC_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  467|      0|    goto err;
  468|      0|  }
  469|       |
  470|      4|  EC_AFFINE G;
  471|      4|  EC_FELEM x, y;
  472|      4|  if (!ec_felem_from_bytes(group, &x, params + 3 * param_len, param_len) ||
  ------------------
  |  Branch (472:7): [True: 0, False: 4]
  ------------------
  473|      4|      !ec_felem_from_bytes(group, &y, params + 4 * param_len, param_len) ||
  ------------------
  |  Branch (473:7): [True: 0, False: 4]
  ------------------
  474|      4|      !ec_point_set_affine_coordinates(group, &G, &x, &y)) {
  ------------------
  |  Branch (474:7): [True: 0, False: 4]
  ------------------
  475|      0|    goto err;
  476|      0|  }
  477|       |
  478|      4|  if (!ec_group_set_generator(group, &G, order)) {
  ------------------
  |  Branch (478:7): [True: 0, False: 4]
  ------------------
  479|      0|    goto err;
  480|      0|  }
  481|       |
  482|      4|  ok = 1;
  483|       |
  484|      4|err:
  485|      4|  if (!ok) {
  ------------------
  |  Branch (485:7): [True: 0, False: 4]
  ------------------
  486|      0|    EC_GROUP_free(group);
  487|      0|    group = NULL;
  488|      0|  }
  489|      4|  BN_CTX_free(ctx);
  490|      4|  BN_free(p);
  491|      4|  BN_free(a);
  492|      4|  BN_free(b);
  493|      4|  BN_free(order);
  494|      4|  return group;
  495|      4|}
bcm.c:ec_point_free:
  695|  1.23k|static void ec_point_free(EC_POINT *point, int free_group) {
  696|  1.23k|  if (!point) {
  ------------------
  |  Branch (696:7): [True: 0, False: 1.23k]
  ------------------
  697|      0|    return;
  698|      0|  }
  699|  1.23k|  if (free_group) {
  ------------------
  |  Branch (699:7): [True: 1.23k, False: 0]
  ------------------
  700|  1.23k|    EC_GROUP_free(point->group);
  701|  1.23k|  }
  702|  1.23k|  OPENSSL_free(point);
  703|  1.23k|}

EC_KEY_new:
  106|  1.23k|EC_KEY *EC_KEY_new(void) { return EC_KEY_new_method(NULL); }
EC_KEY_new_method:
  108|  1.23k|EC_KEY *EC_KEY_new_method(const ENGINE *engine) {
  109|  1.23k|  EC_KEY *ret = OPENSSL_malloc(sizeof(EC_KEY));
  110|  1.23k|  if (ret == NULL) {
  ------------------
  |  Branch (110:7): [True: 0, False: 1.23k]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|  1.23k|  OPENSSL_memset(ret, 0, sizeof(EC_KEY));
  115|       |
  116|  1.23k|  if (engine) {
  ------------------
  |  Branch (116:7): [True: 0, False: 1.23k]
  ------------------
  117|      0|    ret->ecdsa_meth = ENGINE_get_ECDSA_method(engine);
  118|      0|  }
  119|  1.23k|  if (ret->ecdsa_meth) {
  ------------------
  |  Branch (119:7): [True: 0, False: 1.23k]
  ------------------
  120|      0|    METHOD_ref(ret->ecdsa_meth);
  121|      0|  }
  122|       |
  123|  1.23k|  ret->conv_form = POINT_CONVERSION_UNCOMPRESSED;
  124|  1.23k|  ret->references = 1;
  125|       |
  126|  1.23k|  CRYPTO_new_ex_data(&ret->ex_data);
  127|       |
  128|  1.23k|  if (ret->ecdsa_meth && ret->ecdsa_meth->init && !ret->ecdsa_meth->init(ret)) {
  ------------------
  |  Branch (128:7): [True: 0, False: 1.23k]
  |  Branch (128:26): [True: 0, False: 0]
  |  Branch (128:51): [True: 0, False: 0]
  ------------------
  129|      0|    CRYPTO_free_ex_data(g_ec_ex_data_class_bss_get(), ret, &ret->ex_data);
  130|      0|    if (ret->ecdsa_meth) {
  ------------------
  |  Branch (130:9): [True: 0, False: 0]
  ------------------
  131|      0|      METHOD_unref(ret->ecdsa_meth);
  132|      0|    }
  133|      0|    OPENSSL_free(ret);
  134|      0|    return NULL;
  135|      0|  }
  136|       |
  137|  1.23k|  return ret;
  138|  1.23k|}
EC_KEY_free:
  153|  4.46k|void EC_KEY_free(EC_KEY *r) {
  154|  4.46k|  if (r == NULL) {
  ------------------
  |  Branch (154:7): [True: 3.23k, False: 1.23k]
  ------------------
  155|  3.23k|    return;
  156|  3.23k|  }
  157|       |
  158|  1.23k|  if (!CRYPTO_refcount_dec_and_test_zero(&r->references)) {
  ------------------
  |  Branch (158:7): [True: 0, False: 1.23k]
  ------------------
  159|      0|    return;
  160|      0|  }
  161|       |
  162|  1.23k|  if (r->ecdsa_meth) {
  ------------------
  |  Branch (162:7): [True: 0, False: 1.23k]
  ------------------
  163|      0|    if (r->ecdsa_meth->finish) {
  ------------------
  |  Branch (163:9): [True: 0, False: 0]
  ------------------
  164|      0|      r->ecdsa_meth->finish(r);
  165|      0|    }
  166|      0|    METHOD_unref(r->ecdsa_meth);
  167|      0|  }
  168|       |
  169|  1.23k|  EC_GROUP_free(r->group);
  170|  1.23k|  EC_POINT_free(r->pub_key);
  171|  1.23k|  ec_wrapped_scalar_free(r->priv_key);
  172|       |
  173|  1.23k|  CRYPTO_free_ex_data(g_ec_ex_data_class_bss_get(), r, &r->ex_data);
  174|       |
  175|  1.23k|  OPENSSL_free(r);
  176|  1.23k|}
EC_KEY_set_group:
  215|  1.23k|int EC_KEY_set_group(EC_KEY *key, const EC_GROUP *group) {
  216|       |  // If |key| already has a group, it is an error to switch to another one.
  217|  1.23k|  if (key->group != NULL) {
  ------------------
  |  Branch (217:7): [True: 0, False: 1.23k]
  ------------------
  218|      0|    if (EC_GROUP_cmp(key->group, group, NULL) != 0) {
  ------------------
  |  Branch (218:9): [True: 0, False: 0]
  ------------------
  219|      0|      OPENSSL_PUT_ERROR(EC, EC_R_GROUP_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  220|      0|      return 0;
  221|      0|    }
  222|      0|    return 1;
  223|      0|  }
  224|       |
  225|  1.23k|  assert(key->priv_key == NULL);
  226|  1.23k|  assert(key->pub_key == NULL);
  227|       |
  228|  1.23k|  EC_GROUP_free(key->group);
  229|  1.23k|  key->group = EC_GROUP_dup(group);
  230|  1.23k|  return key->group != NULL;
  231|  1.23k|}
EC_KEY_set_private_key:
  237|  1.23k|int EC_KEY_set_private_key(EC_KEY *key, const BIGNUM *priv_key) {
  238|  1.23k|  if (key->group == NULL) {
  ------------------
  |  Branch (238:7): [True: 0, False: 1.23k]
  ------------------
  239|      0|    OPENSSL_PUT_ERROR(EC, EC_R_MISSING_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  240|      0|    return 0;
  241|      0|  }
  242|       |
  243|  1.23k|  EC_WRAPPED_SCALAR *scalar = ec_wrapped_scalar_new(key->group);
  244|  1.23k|  if (scalar == NULL) {
  ------------------
  |  Branch (244:7): [True: 0, False: 1.23k]
  ------------------
  245|      0|    return 0;
  246|      0|  }
  247|  1.23k|  if (!ec_bignum_to_scalar(key->group, &scalar->scalar, priv_key) ||
  ------------------
  |  Branch (247:7): [True: 119, False: 1.11k]
  ------------------
  248|  1.23k|      ec_scalar_is_zero(key->group, &scalar->scalar)) {
  ------------------
  |  Branch (248:7): [True: 17, False: 1.09k]
  ------------------
  249|    136|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_PRIVATE_KEY);
  ------------------
  |  |  441|    136|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  250|    136|    ec_wrapped_scalar_free(scalar);
  251|    136|    return 0;
  252|    136|  }
  253|  1.09k|  ec_wrapped_scalar_free(key->priv_key);
  254|  1.09k|  key->priv_key = scalar;
  255|  1.09k|  return 1;
  256|  1.23k|}
EC_KEY_check_key:
  292|    601|int EC_KEY_check_key(const EC_KEY *eckey) {
  293|    601|  if (!eckey || !eckey->group || !eckey->pub_key) {
  ------------------
  |  Branch (293:7): [True: 0, False: 601]
  |  Branch (293:17): [True: 0, False: 601]
  |  Branch (293:34): [True: 0, False: 601]
  ------------------
  294|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  295|      0|    return 0;
  296|      0|  }
  297|       |
  298|    601|  if (EC_POINT_is_at_infinity(eckey->group, eckey->pub_key)) {
  ------------------
  |  Branch (298:7): [True: 0, False: 601]
  ------------------
  299|      0|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_AT_INFINITY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  300|      0|    return 0;
  301|      0|  }
  302|       |
  303|       |  // Test whether the public key is on the elliptic curve.
  304|    601|  if (!EC_POINT_is_on_curve(eckey->group, eckey->pub_key, NULL)) {
  ------------------
  |  Branch (304:7): [True: 0, False: 601]
  ------------------
  305|      0|    OPENSSL_PUT_ERROR(EC, EC_R_POINT_IS_NOT_ON_CURVE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  306|      0|    return 0;
  307|      0|  }
  308|       |
  309|       |  // Check the public and private keys match.
  310|       |  //
  311|       |  // NOTE: this is a FIPS pair-wise consistency check for the ECDH case. See SP
  312|       |  // 800-56Ar3, page 36.
  313|    601|  if (eckey->priv_key != NULL) {
  ------------------
  |  Branch (313:7): [True: 601, False: 0]
  ------------------
  314|    601|    EC_JACOBIAN point;
  315|    601|    if (!ec_point_mul_scalar_base(eckey->group, &point,
  ------------------
  |  Branch (315:9): [True: 0, False: 601]
  ------------------
  316|    601|                                  &eckey->priv_key->scalar)) {
  317|      0|      OPENSSL_PUT_ERROR(EC, ERR_R_EC_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  318|      0|      return 0;
  319|      0|    }
  320|    601|    if (!ec_GFp_simple_points_equal(eckey->group, &point,
  ------------------
  |  Branch (320:9): [True: 441, False: 160]
  ------------------
  321|    601|                                    &eckey->pub_key->raw)) {
  322|    441|      OPENSSL_PUT_ERROR(EC, EC_R_INVALID_PRIVATE_KEY);
  ------------------
  |  |  441|    441|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  323|    441|      return 0;
  324|    441|    }
  325|    601|  }
  326|       |
  327|    160|  return 1;
  328|    601|}
bcm.c:ec_wrapped_scalar_free:
  102|  2.46k|static void ec_wrapped_scalar_free(EC_WRAPPED_SCALAR *scalar) {
  103|  2.46k|  OPENSSL_free(scalar);
  104|  2.46k|}
bcm.c:ec_wrapped_scalar_new:
   88|  1.23k|static EC_WRAPPED_SCALAR *ec_wrapped_scalar_new(const EC_GROUP *group) {
   89|  1.23k|  EC_WRAPPED_SCALAR *wrapped = OPENSSL_malloc(sizeof(EC_WRAPPED_SCALAR));
   90|  1.23k|  if (wrapped == NULL) {
  ------------------
  |  Branch (90:7): [True: 0, False: 1.23k]
  ------------------
   91|      0|    return NULL;
   92|      0|  }
   93|       |
   94|  1.23k|  OPENSSL_memset(wrapped, 0, sizeof(EC_WRAPPED_SCALAR));
   95|  1.23k|  wrapped->bignum.d = wrapped->scalar.words;
   96|  1.23k|  wrapped->bignum.width = group->order.width;
   97|  1.23k|  wrapped->bignum.dmax = group->order.width;
   98|  1.23k|  wrapped->bignum.flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|  1.23k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
   99|  1.23k|  return wrapped;
  100|  1.23k|}

ec_GFp_mont_group_init:
   79|      3|int ec_GFp_mont_group_init(EC_GROUP *group) {
   80|      3|  int ok;
   81|       |
   82|      3|  ok = ec_GFp_simple_group_init(group);
   83|      3|  group->mont = NULL;
   84|      3|  return ok;
   85|      3|}
ec_GFp_mont_group_set_curve:
   94|      3|                                const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
   95|      3|  BN_MONT_CTX_free(group->mont);
   96|      3|  group->mont = BN_MONT_CTX_new_for_modulus(p, ctx);
   97|      3|  if (group->mont == NULL) {
  ------------------
  |  Branch (97:7): [True: 0, False: 3]
  ------------------
   98|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   99|      0|    return 0;
  100|      0|  }
  101|       |
  102|      3|  if (!ec_GFp_simple_group_set_curve(group, p, a, b, ctx)) {
  ------------------
  |  Branch (102:7): [True: 0, False: 3]
  ------------------
  103|      0|    BN_MONT_CTX_free(group->mont);
  104|      0|    group->mont = NULL;
  105|      0|    return 0;
  106|      0|  }
  107|       |
  108|      3|  return 1;
  109|      3|}
ec_GFp_mont_felem_mul:
  131|   824k|                           const EC_FELEM *a, const EC_FELEM *b) {
  132|   824k|  bn_mod_mul_montgomery_small(r->words, a->words, b->words, group->field.width,
  133|   824k|                              group->mont);
  134|   824k|}
ec_GFp_mont_felem_sqr:
  137|   921k|                           const EC_FELEM *a) {
  138|   921k|  bn_mod_mul_montgomery_small(r->words, a->words, a->words, group->field.width,
  139|   921k|                              group->mont);
  140|   921k|}
ec_GFp_mont_felem_to_bytes:
  143|    174|                                size_t *out_len, const EC_FELEM *in) {
  144|    174|  EC_FELEM tmp;
  145|    174|  ec_GFp_mont_felem_from_montgomery(group, &tmp, in);
  146|    174|  ec_GFp_simple_felem_to_bytes(group, out, out_len, &tmp);
  147|    174|}
ec_GFp_mont_felem_from_bytes:
  150|    139|                                 const uint8_t *in, size_t len) {
  151|    139|  if (!ec_GFp_simple_felem_from_bytes(group, out, in, len)) {
  ------------------
  |  Branch (151:7): [True: 2, False: 137]
  ------------------
  152|      2|    return 0;
  153|      2|  }
  154|       |
  155|    137|  ec_GFp_mont_felem_to_montgomery(group, out, out);
  156|    137|  return 1;
  157|    139|}
ec_GFp_mont_add:
  251|  33.8k|                     const EC_JACOBIAN *a, const EC_JACOBIAN *b) {
  252|  33.8k|  if (a == b) {
  ------------------
  |  Branch (252:7): [True: 0, False: 33.8k]
  ------------------
  253|      0|    ec_GFp_mont_dbl(group, out, a);
  254|      0|    return;
  255|      0|  }
  256|       |
  257|       |  // The method is taken from:
  258|       |  //   http://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian.html#addition-add-2007-bl
  259|       |  //
  260|       |  // Coq transcription and correctness proof:
  261|       |  // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L467>
  262|       |  // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L544>
  263|  33.8k|  EC_FELEM x_out, y_out, z_out;
  264|  33.8k|  BN_ULONG z1nz = ec_felem_non_zero_mask(group, &a->Z);
  265|  33.8k|  BN_ULONG z2nz = ec_felem_non_zero_mask(group, &b->Z);
  266|       |
  267|       |  // z1z1 = z1z1 = z1**2
  268|  33.8k|  EC_FELEM z1z1;
  269|  33.8k|  ec_GFp_mont_felem_sqr(group, &z1z1, &a->Z);
  270|       |
  271|       |  // z2z2 = z2**2
  272|  33.8k|  EC_FELEM z2z2;
  273|  33.8k|  ec_GFp_mont_felem_sqr(group, &z2z2, &b->Z);
  274|       |
  275|       |  // u1 = x1*z2z2
  276|  33.8k|  EC_FELEM u1;
  277|  33.8k|  ec_GFp_mont_felem_mul(group, &u1, &a->X, &z2z2);
  278|       |
  279|       |  // two_z1z2 = (z1 + z2)**2 - (z1z1 + z2z2) = 2z1z2
  280|  33.8k|  EC_FELEM two_z1z2;
  281|  33.8k|  ec_felem_add(group, &two_z1z2, &a->Z, &b->Z);
  282|  33.8k|  ec_GFp_mont_felem_sqr(group, &two_z1z2, &two_z1z2);
  283|  33.8k|  ec_felem_sub(group, &two_z1z2, &two_z1z2, &z1z1);
  284|  33.8k|  ec_felem_sub(group, &two_z1z2, &two_z1z2, &z2z2);
  285|       |
  286|       |  // s1 = y1 * z2**3
  287|  33.8k|  EC_FELEM s1;
  288|  33.8k|  ec_GFp_mont_felem_mul(group, &s1, &b->Z, &z2z2);
  289|  33.8k|  ec_GFp_mont_felem_mul(group, &s1, &s1, &a->Y);
  290|       |
  291|       |  // u2 = x2*z1z1
  292|  33.8k|  EC_FELEM u2;
  293|  33.8k|  ec_GFp_mont_felem_mul(group, &u2, &b->X, &z1z1);
  294|       |
  295|       |  // h = u2 - u1
  296|  33.8k|  EC_FELEM h;
  297|  33.8k|  ec_felem_sub(group, &h, &u2, &u1);
  298|       |
  299|  33.8k|  BN_ULONG xneq = ec_felem_non_zero_mask(group, &h);
  300|       |
  301|       |  // z_out = two_z1z2 * h
  302|  33.8k|  ec_GFp_mont_felem_mul(group, &z_out, &h, &two_z1z2);
  303|       |
  304|       |  // z1z1z1 = z1 * z1z1
  305|  33.8k|  EC_FELEM z1z1z1;
  306|  33.8k|  ec_GFp_mont_felem_mul(group, &z1z1z1, &a->Z, &z1z1);
  307|       |
  308|       |  // s2 = y2 * z1**3
  309|  33.8k|  EC_FELEM s2;
  310|  33.8k|  ec_GFp_mont_felem_mul(group, &s2, &b->Y, &z1z1z1);
  311|       |
  312|       |  // r = (s2 - s1)*2
  313|  33.8k|  EC_FELEM r;
  314|  33.8k|  ec_felem_sub(group, &r, &s2, &s1);
  315|  33.8k|  ec_felem_add(group, &r, &r, &r);
  316|       |
  317|  33.8k|  BN_ULONG yneq = ec_felem_non_zero_mask(group, &r);
  318|       |
  319|       |  // This case will never occur in the constant-time |ec_GFp_mont_mul|.
  320|  33.8k|  BN_ULONG is_nontrivial_double = ~xneq & ~yneq & z1nz & z2nz;
  321|  33.8k|  if (constant_time_declassify_w(is_nontrivial_double)) {
  ------------------
  |  Branch (321:7): [True: 0, False: 33.8k]
  ------------------
  322|      0|    ec_GFp_mont_dbl(group, out, a);
  323|      0|    return;
  324|      0|  }
  325|       |
  326|       |  // I = (2h)**2
  327|  33.8k|  EC_FELEM i;
  328|  33.8k|  ec_felem_add(group, &i, &h, &h);
  329|  33.8k|  ec_GFp_mont_felem_sqr(group, &i, &i);
  330|       |
  331|       |  // J = h * I
  332|  33.8k|  EC_FELEM j;
  333|  33.8k|  ec_GFp_mont_felem_mul(group, &j, &h, &i);
  334|       |
  335|       |  // V = U1 * I
  336|  33.8k|  EC_FELEM v;
  337|  33.8k|  ec_GFp_mont_felem_mul(group, &v, &u1, &i);
  338|       |
  339|       |  // x_out = r**2 - J - 2V
  340|  33.8k|  ec_GFp_mont_felem_sqr(group, &x_out, &r);
  341|  33.8k|  ec_felem_sub(group, &x_out, &x_out, &j);
  342|  33.8k|  ec_felem_sub(group, &x_out, &x_out, &v);
  343|  33.8k|  ec_felem_sub(group, &x_out, &x_out, &v);
  344|       |
  345|       |  // y_out = r(V-x_out) - 2 * s1 * J
  346|  33.8k|  ec_felem_sub(group, &y_out, &v, &x_out);
  347|  33.8k|  ec_GFp_mont_felem_mul(group, &y_out, &y_out, &r);
  348|  33.8k|  EC_FELEM s1j;
  349|  33.8k|  ec_GFp_mont_felem_mul(group, &s1j, &s1, &j);
  350|  33.8k|  ec_felem_sub(group, &y_out, &y_out, &s1j);
  351|  33.8k|  ec_felem_sub(group, &y_out, &y_out, &s1j);
  352|       |
  353|  33.8k|  ec_felem_select(group, &x_out, z1nz, &x_out, &b->X);
  354|  33.8k|  ec_felem_select(group, &out->X, z2nz, &x_out, &a->X);
  355|  33.8k|  ec_felem_select(group, &y_out, z1nz, &y_out, &b->Y);
  356|  33.8k|  ec_felem_select(group, &out->Y, z2nz, &y_out, &a->Y);
  357|  33.8k|  ec_felem_select(group, &z_out, z1nz, &z_out, &b->Z);
  358|  33.8k|  ec_felem_select(group, &out->Z, z2nz, &z_out, &a->Z);
  359|  33.8k|}
ec_GFp_mont_dbl:
  362|   149k|                     const EC_JACOBIAN *a) {
  363|   149k|  if (group->a_is_minus3) {
  ------------------
  |  Branch (363:7): [True: 149k, False: 0]
  ------------------
  364|       |    // The method is taken from:
  365|       |    //   http://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian-3.html#doubling-dbl-2001-b
  366|       |    //
  367|       |    // Coq transcription and correctness proof:
  368|       |    // <https://github.com/mit-plv/fiat-crypto/blob/79f8b5f39ed609339f0233098dee1a3c4e6b3080/src/Curves/Weierstrass/Jacobian.v#L93>
  369|       |    // <https://github.com/mit-plv/fiat-crypto/blob/79f8b5f39ed609339f0233098dee1a3c4e6b3080/src/Curves/Weierstrass/Jacobian.v#L201>
  370|   149k|    EC_FELEM delta, gamma, beta, ftmp, ftmp2, tmptmp, alpha, fourbeta;
  371|       |    // delta = z^2
  372|   149k|    ec_GFp_mont_felem_sqr(group, &delta, &a->Z);
  373|       |    // gamma = y^2
  374|   149k|    ec_GFp_mont_felem_sqr(group, &gamma, &a->Y);
  375|       |    // beta = x*gamma
  376|   149k|    ec_GFp_mont_felem_mul(group, &beta, &a->X, &gamma);
  377|       |
  378|       |    // alpha = 3*(x-delta)*(x+delta)
  379|   149k|    ec_felem_sub(group, &ftmp, &a->X, &delta);
  380|   149k|    ec_felem_add(group, &ftmp2, &a->X, &delta);
  381|       |
  382|   149k|    ec_felem_add(group, &tmptmp, &ftmp2, &ftmp2);
  383|   149k|    ec_felem_add(group, &ftmp2, &ftmp2, &tmptmp);
  384|   149k|    ec_GFp_mont_felem_mul(group, &alpha, &ftmp, &ftmp2);
  385|       |
  386|       |    // x' = alpha^2 - 8*beta
  387|   149k|    ec_GFp_mont_felem_sqr(group, &r->X, &alpha);
  388|   149k|    ec_felem_add(group, &fourbeta, &beta, &beta);
  389|   149k|    ec_felem_add(group, &fourbeta, &fourbeta, &fourbeta);
  390|   149k|    ec_felem_add(group, &tmptmp, &fourbeta, &fourbeta);
  391|   149k|    ec_felem_sub(group, &r->X, &r->X, &tmptmp);
  392|       |
  393|       |    // z' = (y + z)^2 - gamma - delta
  394|   149k|    ec_felem_add(group, &delta, &gamma, &delta);
  395|   149k|    ec_felem_add(group, &ftmp, &a->Y, &a->Z);
  396|   149k|    ec_GFp_mont_felem_sqr(group, &r->Z, &ftmp);
  397|   149k|    ec_felem_sub(group, &r->Z, &r->Z, &delta);
  398|       |
  399|       |    // y' = alpha*(4*beta - x') - 8*gamma^2
  400|   149k|    ec_felem_sub(group, &r->Y, &fourbeta, &r->X);
  401|   149k|    ec_felem_add(group, &gamma, &gamma, &gamma);
  402|   149k|    ec_GFp_mont_felem_sqr(group, &gamma, &gamma);
  403|   149k|    ec_GFp_mont_felem_mul(group, &r->Y, &alpha, &r->Y);
  404|   149k|    ec_felem_add(group, &gamma, &gamma, &gamma);
  405|   149k|    ec_felem_sub(group, &r->Y, &r->Y, &gamma);
  406|   149k|  } else {
  407|       |    // The method is taken from:
  408|       |    //   http://www.hyperelliptic.org/EFD/g1p/auto-shortw-jacobian.html#doubling-dbl-2007-bl
  409|       |    //
  410|       |    // Coq transcription and correctness proof:
  411|       |    // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L102>
  412|       |    // <https://github.com/davidben/fiat-crypto/blob/c7b95f62b2a54b559522573310e9b487327d219a/src/Curves/Weierstrass/Jacobian.v#L534>
  413|      0|    EC_FELEM xx, yy, yyyy, zz;
  414|      0|    ec_GFp_mont_felem_sqr(group, &xx, &a->X);
  415|      0|    ec_GFp_mont_felem_sqr(group, &yy, &a->Y);
  416|      0|    ec_GFp_mont_felem_sqr(group, &yyyy, &yy);
  417|      0|    ec_GFp_mont_felem_sqr(group, &zz, &a->Z);
  418|       |
  419|       |    // s = 2*((x_in + yy)^2 - xx - yyyy)
  420|      0|    EC_FELEM s;
  421|      0|    ec_felem_add(group, &s, &a->X, &yy);
  422|      0|    ec_GFp_mont_felem_sqr(group, &s, &s);
  423|      0|    ec_felem_sub(group, &s, &s, &xx);
  424|      0|    ec_felem_sub(group, &s, &s, &yyyy);
  425|      0|    ec_felem_add(group, &s, &s, &s);
  426|       |
  427|       |    // m = 3*xx + a*zz^2
  428|      0|    EC_FELEM m;
  429|      0|    ec_GFp_mont_felem_sqr(group, &m, &zz);
  430|      0|    ec_GFp_mont_felem_mul(group, &m, &group->a, &m);
  431|      0|    ec_felem_add(group, &m, &m, &xx);
  432|      0|    ec_felem_add(group, &m, &m, &xx);
  433|      0|    ec_felem_add(group, &m, &m, &xx);
  434|       |
  435|       |    // x_out = m^2 - 2*s
  436|      0|    ec_GFp_mont_felem_sqr(group, &r->X, &m);
  437|      0|    ec_felem_sub(group, &r->X, &r->X, &s);
  438|      0|    ec_felem_sub(group, &r->X, &r->X, &s);
  439|       |
  440|       |    // z_out = (y_in + z_in)^2 - yy - zz
  441|      0|    ec_felem_add(group, &r->Z, &a->Y, &a->Z);
  442|      0|    ec_GFp_mont_felem_sqr(group, &r->Z, &r->Z);
  443|      0|    ec_felem_sub(group, &r->Z, &r->Z, &yy);
  444|      0|    ec_felem_sub(group, &r->Z, &r->Z, &zz);
  445|       |
  446|       |    // y_out = m*(s-x_out) - 8*yyyy
  447|      0|    ec_felem_add(group, &yyyy, &yyyy, &yyyy);
  448|      0|    ec_felem_add(group, &yyyy, &yyyy, &yyyy);
  449|      0|    ec_felem_add(group, &yyyy, &yyyy, &yyyy);
  450|      0|    ec_felem_sub(group, &r->Y, &s, &r->X);
  451|      0|    ec_GFp_mont_felem_mul(group, &r->Y, &r->Y, &m);
  452|      0|    ec_felem_sub(group, &r->Y, &r->Y, &yyyy);
  453|      0|  }
  454|   149k|}
bcm.c:ec_GFp_mont_felem_from_montgomery:
  119|    174|                                              const EC_FELEM *in) {
  120|    174|  bn_from_montgomery_small(out->words, group->field.width, in->words,
  121|    174|                           group->field.width, group->mont);
  122|    174|}
bcm.c:ec_GFp_mont_felem_to_montgomery:
  112|    137|                                            EC_FELEM *out, const EC_FELEM *in) {
  113|    137|  bn_to_montgomery_small(out->words, in->words, group->field.width,
  114|    137|                         group->mont);
  115|    137|}
bcm.c:EC_GFp_mont_method_do_init:
  501|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_mont_method) {
  502|      1|  out->group_init = ec_GFp_mont_group_init;
  503|      1|  out->group_finish = ec_GFp_mont_group_finish;
  504|      1|  out->group_set_curve = ec_GFp_mont_group_set_curve;
  505|      1|  out->point_get_affine_coordinates = ec_GFp_mont_point_get_affine_coordinates;
  506|      1|  out->jacobian_to_affine_batch = ec_GFp_mont_jacobian_to_affine_batch;
  507|      1|  out->add = ec_GFp_mont_add;
  508|      1|  out->dbl = ec_GFp_mont_dbl;
  509|      1|  out->mul = ec_GFp_mont_mul;
  510|      1|  out->mul_base = ec_GFp_mont_mul_base;
  511|      1|  out->mul_batch = ec_GFp_mont_mul_batch;
  512|      1|  out->mul_public_batch = ec_GFp_mont_mul_public_batch;
  513|      1|  out->init_precomp = ec_GFp_mont_init_precomp;
  514|      1|  out->mul_precomp = ec_GFp_mont_mul_precomp;
  515|      1|  out->felem_mul = ec_GFp_mont_felem_mul;
  516|      1|  out->felem_sqr = ec_GFp_mont_felem_sqr;
  517|      1|  out->felem_to_bytes = ec_GFp_mont_felem_to_bytes;
  518|      1|  out->felem_from_bytes = ec_GFp_mont_felem_from_bytes;
  519|      1|  out->felem_reduce = ec_GFp_mont_felem_reduce;
  520|      1|  out->felem_exp = ec_GFp_mont_felem_exp;
  521|      1|  out->scalar_inv0_montgomery = ec_simple_scalar_inv0_montgomery;
  522|      1|  out->scalar_to_montgomery_inv_vartime =
  523|      1|      ec_simple_scalar_to_montgomery_inv_vartime;
  524|      1|  out->cmp_x_coordinate = ec_GFp_mont_cmp_x_coordinate;
  525|      1|}

ec_bignum_to_felem:
   26|    970|int ec_bignum_to_felem(const EC_GROUP *group, EC_FELEM *out, const BIGNUM *in) {
   27|    970|  uint8_t bytes[EC_MAX_BYTES];
   28|    970|  size_t len = BN_num_bytes(&group->field);
   29|    970|  assert(sizeof(bytes) >= len);
   30|    970|  if (BN_is_negative(in) ||
  ------------------
  |  Branch (30:7): [True: 0, False: 970]
  ------------------
   31|    970|      BN_cmp(in, &group->field) >= 0 ||
  ------------------
  |  Branch (31:7): [True: 0, False: 970]
  ------------------
   32|    970|      !BN_bn2bin_padded(bytes, len, in)) {
  ------------------
  |  Branch (32:7): [True: 0, False: 970]
  ------------------
   33|      0|    OPENSSL_PUT_ERROR(EC, EC_R_COORDINATES_OUT_OF_RANGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   34|      0|    return 0;
   35|      0|  }
   36|       |
   37|    970|  return ec_felem_from_bytes(group, out, bytes, len);
   38|    970|}
ec_felem_to_bignum:
   40|  1.34k|int ec_felem_to_bignum(const EC_GROUP *group, BIGNUM *out, const EC_FELEM *in) {
   41|  1.34k|  uint8_t bytes[EC_MAX_BYTES];
   42|  1.34k|  size_t len;
   43|  1.34k|  ec_felem_to_bytes(group, bytes, &len, in);
   44|  1.34k|  return BN_bin2bn(bytes, len, out) != NULL;
   45|  1.34k|}
ec_felem_to_bytes:
   48|  1.34k|                       const EC_FELEM *in) {
   49|  1.34k|  group->meth->felem_to_bytes(group, out, out_len, in);
   50|  1.34k|}
ec_felem_from_bytes:
   53|    998|                        size_t len) {
   54|    998|  return group->meth->felem_from_bytes(group, out, in, len);
   55|    998|}
ec_felem_add:
   70|  1.60M|                  const EC_FELEM *b) {
   71|  1.60M|  EC_FELEM tmp;
   72|  1.60M|  bn_mod_add_words(out->words, a->words, b->words, group->field.d, tmp.words,
   73|  1.60M|                   group->field.width);
   74|  1.60M|}
ec_felem_sub:
   77|  1.09M|                  const EC_FELEM *b) {
   78|  1.09M|  EC_FELEM tmp;
   79|  1.09M|  bn_mod_sub_words(out->words, a->words, b->words, group->field.d, tmp.words,
   80|  1.09M|                   group->field.width);
   81|  1.09M|}
ec_felem_non_zero_mask:
   83|   141k|BN_ULONG ec_felem_non_zero_mask(const EC_GROUP *group, const EC_FELEM *a) {
   84|   141k|  BN_ULONG mask = 0;
   85|  1.20M|  for (int i = 0; i < group->field.width; i++) {
  ------------------
  |  Branch (85:19): [True: 1.06M, False: 141k]
  ------------------
   86|  1.06M|    mask |= a->words[i];
   87|  1.06M|  }
   88|   141k|  return ~constant_time_is_zero_w(mask);
   89|   141k|}
ec_felem_select:
   92|  3.01M|                     const EC_FELEM *a, const EC_FELEM *b) {
   93|  3.01M|  bn_select_words(out->words, mask, a->words, b->words, group->field.width);
   94|  3.01M|}
ec_felem_equal:
   97|    493|                   const EC_FELEM *b) {
   98|    493|  return CRYPTO_memcmp(a->words, b->words,
   99|    493|                       group->field.width * sizeof(BN_ULONG)) == 0;
  100|    493|}

ec_point_from_uncompressed:
  119|     30|                               const uint8_t *in, size_t len) {
  120|     30|  const size_t field_len = BN_num_bytes(&group->field);
  121|     30|  if (len != 1 + 2 * field_len || in[0] != POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (121:7): [True: 18, False: 12]
  |  Branch (121:35): [True: 0, False: 12]
  ------------------
  122|     18|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|     18|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  123|     18|    return 0;
  124|     18|  }
  125|       |
  126|     12|  EC_FELEM x, y;
  127|     12|  if (!ec_felem_from_bytes(group, &x, in + 1, field_len) ||
  ------------------
  |  Branch (127:7): [True: 4, False: 8]
  ------------------
  128|     12|      !ec_felem_from_bytes(group, &y, in + 1 + field_len, field_len) ||
  ------------------
  |  Branch (128:7): [True: 4, False: 4]
  ------------------
  129|     12|      !ec_point_set_affine_coordinates(group, out, &x, &y)) {
  ------------------
  |  Branch (129:7): [True: 2, False: 2]
  ------------------
  130|     10|    return 0;
  131|     10|  }
  132|       |
  133|      2|  return 1;
  134|     12|}
EC_POINT_oct2point:
  203|    736|                       const uint8_t *buf, size_t len, BN_CTX *ctx) {
  204|    736|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (204:7): [True: 0, False: 736]
  ------------------
  205|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  206|      0|    return 0;
  207|      0|  }
  208|    736|  return ec_GFp_simple_oct2point(group, point, buf, len, ctx);
  209|    736|}
EC_POINT_set_compressed_coordinates_GFp:
  257|    671|                                            int y_bit, BN_CTX *ctx) {
  258|    671|  if (EC_GROUP_cmp(group, point->group, NULL) != 0) {
  ------------------
  |  Branch (258:7): [True: 0, False: 671]
  ------------------
  259|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INCOMPATIBLE_OBJECTS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  260|      0|    return 0;
  261|      0|  }
  262|       |
  263|    671|  if (BN_is_negative(x) || BN_cmp(x, &group->field) >= 0) {
  ------------------
  |  Branch (263:7): [True: 0, False: 671]
  |  Branch (263:28): [True: 0, False: 671]
  ------------------
  264|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_COMPRESSED_POINT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  265|      0|    return 0;
  266|      0|  }
  267|       |
  268|    671|  BN_CTX *new_ctx = NULL;
  269|    671|  int ret = 0;
  270|       |
  271|    671|  ERR_clear_error();
  272|       |
  273|    671|  if (ctx == NULL) {
  ------------------
  |  Branch (273:7): [True: 0, False: 671]
  ------------------
  274|      0|    ctx = new_ctx = BN_CTX_new();
  275|      0|    if (ctx == NULL) {
  ------------------
  |  Branch (275:9): [True: 0, False: 0]
  ------------------
  276|      0|      return 0;
  277|      0|    }
  278|      0|  }
  279|       |
  280|    671|  y_bit = (y_bit != 0);
  281|       |
  282|    671|  BN_CTX_start(ctx);
  283|    671|  BIGNUM *tmp1 = BN_CTX_get(ctx);
  284|    671|  BIGNUM *tmp2 = BN_CTX_get(ctx);
  285|    671|  BIGNUM *a = BN_CTX_get(ctx);
  286|    671|  BIGNUM *b = BN_CTX_get(ctx);
  287|    671|  BIGNUM *y = BN_CTX_get(ctx);
  288|    671|  if (y == NULL ||
  ------------------
  |  Branch (288:7): [True: 0, False: 671]
  ------------------
  289|    671|      !EC_GROUP_get_curve_GFp(group, NULL, a, b, ctx)) {
  ------------------
  |  Branch (289:7): [True: 0, False: 671]
  ------------------
  290|      0|    goto err;
  291|      0|  }
  292|       |
  293|       |  // Recover y.  We have a Weierstrass equation
  294|       |  //     y^2 = x^3 + a*x + b,
  295|       |  // so  y  is one of the square roots of  x^3 + a*x + b.
  296|       |
  297|       |  // tmp1 := x^3
  298|    671|  if (!BN_mod_sqr(tmp2, x, &group->field, ctx) ||
  ------------------
  |  Branch (298:7): [True: 0, False: 671]
  ------------------
  299|    671|      !BN_mod_mul(tmp1, tmp2, x, &group->field, ctx)) {
  ------------------
  |  Branch (299:7): [True: 0, False: 671]
  ------------------
  300|      0|    goto err;
  301|      0|  }
  302|       |
  303|       |  // tmp1 := tmp1 + a*x
  304|    671|  if (group->a_is_minus3) {
  ------------------
  |  Branch (304:7): [True: 671, False: 0]
  ------------------
  305|    671|    if (!bn_mod_lshift1_consttime(tmp2, x, &group->field, ctx) ||
  ------------------
  |  Branch (305:9): [True: 0, False: 671]
  ------------------
  306|    671|        !bn_mod_add_consttime(tmp2, tmp2, x, &group->field, ctx) ||
  ------------------
  |  Branch (306:9): [True: 0, False: 671]
  ------------------
  307|    671|        !bn_mod_sub_consttime(tmp1, tmp1, tmp2, &group->field, ctx)) {
  ------------------
  |  Branch (307:9): [True: 0, False: 671]
  ------------------
  308|      0|      goto err;
  309|      0|    }
  310|    671|  } else {
  311|      0|    if (!BN_mod_mul(tmp2, a, x, &group->field, ctx) ||
  ------------------
  |  Branch (311:9): [True: 0, False: 0]
  ------------------
  312|      0|        !bn_mod_add_consttime(tmp1, tmp1, tmp2, &group->field, ctx)) {
  ------------------
  |  Branch (312:9): [True: 0, False: 0]
  ------------------
  313|      0|      goto err;
  314|      0|    }
  315|      0|  }
  316|       |
  317|       |  // tmp1 := tmp1 + b
  318|    671|  if (!bn_mod_add_consttime(tmp1, tmp1, b, &group->field, ctx)) {
  ------------------
  |  Branch (318:7): [True: 0, False: 671]
  ------------------
  319|      0|    goto err;
  320|      0|  }
  321|       |
  322|    671|  if (!BN_mod_sqrt(y, tmp1, &group->field, ctx)) {
  ------------------
  |  Branch (322:7): [True: 192, False: 479]
  ------------------
  323|    192|    uint32_t err = ERR_peek_last_error();
  324|    192|    if (ERR_GET_LIB(err) == ERR_LIB_BN &&
  ------------------
  |  Branch (324:9): [True: 192, False: 0]
  ------------------
  325|    192|        ERR_GET_REASON(err) == BN_R_NOT_A_SQUARE) {
  ------------------
  |  | 1076|    192|#define BN_R_NOT_A_SQUARE 110
  ------------------
  |  Branch (325:9): [True: 192, False: 0]
  ------------------
  326|    192|      ERR_clear_error();
  327|    192|      OPENSSL_PUT_ERROR(EC, EC_R_INVALID_COMPRESSED_POINT);
  ------------------
  |  |  441|    192|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|    192|    } else {
  329|      0|      OPENSSL_PUT_ERROR(EC, ERR_R_BN_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  330|      0|    }
  331|    192|    goto err;
  332|    192|  }
  333|       |
  334|    479|  if (y_bit != BN_is_odd(y)) {
  ------------------
  |  Branch (334:7): [True: 292, False: 187]
  ------------------
  335|    292|    if (BN_is_zero(y)) {
  ------------------
  |  Branch (335:9): [True: 0, False: 292]
  ------------------
  336|      0|      OPENSSL_PUT_ERROR(EC, EC_R_INVALID_COMPRESSION_BIT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  337|      0|      goto err;
  338|      0|    }
  339|    292|    if (!BN_usub(y, &group->field, y)) {
  ------------------
  |  Branch (339:9): [True: 0, False: 292]
  ------------------
  340|      0|      goto err;
  341|      0|    }
  342|    292|  }
  343|    479|  if (y_bit != BN_is_odd(y)) {
  ------------------
  |  Branch (343:7): [True: 0, False: 479]
  ------------------
  344|      0|    OPENSSL_PUT_ERROR(EC, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|    goto err;
  346|      0|  }
  347|       |
  348|    479|  if (!EC_POINT_set_affine_coordinates_GFp(group, point, x, y, ctx)) {
  ------------------
  |  Branch (348:7): [True: 0, False: 479]
  ------------------
  349|      0|    goto err;
  350|      0|  }
  351|       |
  352|    479|  ret = 1;
  353|       |
  354|    671|err:
  355|    671|  BN_CTX_end(ctx);
  356|    671|  BN_CTX_free(new_ctx);
  357|    671|  return ret;
  358|    479|}
bcm.c:ec_GFp_simple_oct2point:
  138|    736|                                   BN_CTX *ctx) {
  139|    736|  if (len == 0) {
  ------------------
  |  Branch (139:7): [True: 0, False: 736]
  ------------------
  140|      0|    OPENSSL_PUT_ERROR(EC, EC_R_BUFFER_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|       |
  144|    736|  point_conversion_form_t form = buf[0];
  145|    736|  if (form == POINT_CONVERSION_UNCOMPRESSED) {
  ------------------
  |  Branch (145:7): [True: 30, False: 706]
  ------------------
  146|     30|    EC_AFFINE affine;
  147|     30|    if (!ec_point_from_uncompressed(group, &affine, buf, len)) {
  ------------------
  |  Branch (147:9): [True: 28, False: 2]
  ------------------
  148|       |      // In the event of an error, defend against the caller not checking the
  149|       |      // return value by setting a known safe value.
  150|     28|      ec_set_to_safe_point(group, &point->raw);
  151|     28|      return 0;
  152|     28|    }
  153|      2|    ec_affine_to_jacobian(group, &point->raw, &affine);
  154|      2|    return 1;
  155|     30|  }
  156|       |
  157|    706|  const int y_bit = form & 1;
  158|    706|  const size_t field_len = BN_num_bytes(&group->field);
  159|    706|  form = form & ~1u;
  160|    706|  if (form != POINT_CONVERSION_COMPRESSED ||
  ------------------
  |  Branch (160:7): [True: 14, False: 692]
  ------------------
  161|    706|      len != 1 /* type byte */ + field_len) {
  ------------------
  |  Branch (161:7): [True: 17, False: 675]
  ------------------
  162|     31|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|     31|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|     31|    return 0;
  164|     31|  }
  165|       |
  166|       |  // TODO(davidben): Integrate compressed coordinates with the lower-level EC
  167|       |  // abstractions. This requires a way to compute square roots, which is tricky
  168|       |  // for primes which are not 3 (mod 4), namely P-224 and custom curves. P-224's
  169|       |  // prime is particularly inconvenient for compressed coordinates. See
  170|       |  // https://cr.yp.to/papers/sqroot.pdf
  171|    675|  BN_CTX *new_ctx = NULL;
  172|    675|  if (ctx == NULL) {
  ------------------
  |  Branch (172:7): [True: 675, False: 0]
  ------------------
  173|    675|    ctx = new_ctx = BN_CTX_new();
  174|    675|    if (ctx == NULL) {
  ------------------
  |  Branch (174:9): [True: 0, False: 675]
  ------------------
  175|      0|      return 0;
  176|      0|    }
  177|    675|  }
  178|       |
  179|    675|  int ret = 0;
  180|    675|  BN_CTX_start(ctx);
  181|    675|  BIGNUM *x = BN_CTX_get(ctx);
  182|    675|  if (x == NULL || !BN_bin2bn(buf + 1, field_len, x)) {
  ------------------
  |  Branch (182:7): [True: 0, False: 675]
  |  Branch (182:20): [True: 0, False: 675]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|    675|  if (BN_ucmp(x, &group->field) >= 0) {
  ------------------
  |  Branch (185:7): [True: 4, False: 671]
  ------------------
  186|      4|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_ENCODING);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  187|      4|    goto err;
  188|      4|  }
  189|       |
  190|    671|  if (!EC_POINT_set_compressed_coordinates_GFp(group, point, x, y_bit, ctx)) {
  ------------------
  |  Branch (190:7): [True: 192, False: 479]
  ------------------
  191|    192|    goto err;
  192|    192|  }
  193|       |
  194|    479|  ret = 1;
  195|       |
  196|    675|err:
  197|    675|  BN_CTX_end(ctx);
  198|    675|  BN_CTX_free(new_ctx);
  199|    675|  return ret;
  200|    479|}

bcm.c:EC_GFp_nistp224_method_do_init:
 1144|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_nistp224_method) {
 1145|      1|  out->group_init = ec_GFp_simple_group_init;
 1146|      1|  out->group_finish = ec_GFp_simple_group_finish;
 1147|      1|  out->group_set_curve = ec_GFp_simple_group_set_curve;
 1148|      1|  out->point_get_affine_coordinates =
 1149|      1|      ec_GFp_nistp224_point_get_affine_coordinates;
 1150|      1|  out->add = ec_GFp_nistp224_add;
 1151|      1|  out->dbl = ec_GFp_nistp224_dbl;
 1152|      1|  out->mul = ec_GFp_nistp224_point_mul;
 1153|      1|  out->mul_base = ec_GFp_nistp224_point_mul_base;
 1154|      1|  out->mul_public = ec_GFp_nistp224_point_mul_public;
 1155|      1|  out->felem_mul = ec_GFp_nistp224_felem_mul;
 1156|      1|  out->felem_sqr = ec_GFp_nistp224_felem_sqr;
 1157|      1|  out->felem_to_bytes = ec_GFp_simple_felem_to_bytes;
 1158|      1|  out->felem_from_bytes = ec_GFp_simple_felem_from_bytes;
 1159|      1|  out->scalar_inv0_montgomery = ec_simple_scalar_inv0_montgomery;
 1160|      1|  out->scalar_to_montgomery_inv_vartime =
 1161|      1|      ec_simple_scalar_to_montgomery_inv_vartime;
 1162|      1|  out->cmp_x_coordinate = ec_GFp_simple_cmp_x_coordinate;
 1163|      1|}
bcm.c:p224_generic_to_felem:
  181|  17.3k|static void p224_generic_to_felem(p224_felem out, const EC_FELEM *in) {
  182|       |  // |p224_felem|'s minimal representation uses four 56-bit words. |EC_FELEM|
  183|       |  // uses four 64-bit words. (The top-most word only has 32 bits.)
  184|  17.3k|  out[0] = in->words[0] & 0x00ffffffffffffff;
  185|  17.3k|  out[1] = ((in->words[0] >> 56) | (in->words[1] << 8)) & 0x00ffffffffffffff;
  186|  17.3k|  out[2] = ((in->words[1] >> 48) | (in->words[2] << 16)) & 0x00ffffffffffffff;
  187|  17.3k|  out[3] = ((in->words[2] >> 40) | (in->words[3] << 24)) & 0x00ffffffffffffff;
  188|  17.3k|}
bcm.c:p224_felem_square:
  364|   156k|static void p224_felem_square(p224_widefelem out, const p224_felem in) {
  365|   156k|  p224_limb tmp0, tmp1, tmp2;
  366|   156k|  tmp0 = 2 * in[0];
  367|   156k|  tmp1 = 2 * in[1];
  368|   156k|  tmp2 = 2 * in[2];
  369|   156k|  out[0] = ((p224_widelimb)in[0]) * in[0];
  370|   156k|  out[1] = ((p224_widelimb)in[0]) * tmp1;
  371|   156k|  out[2] = ((p224_widelimb)in[0]) * tmp2 + ((p224_widelimb)in[1]) * in[1];
  372|   156k|  out[3] = ((p224_widelimb)in[3]) * tmp0 + ((p224_widelimb)in[1]) * tmp2;
  373|   156k|  out[4] = ((p224_widelimb)in[3]) * tmp1 + ((p224_widelimb)in[2]) * in[2];
  374|   156k|  out[5] = ((p224_widelimb)in[3]) * tmp2;
  375|   156k|  out[6] = ((p224_widelimb)in[3]) * in[3];
  376|   156k|}
bcm.c:p224_felem_reduce:
  396|   382k|static void p224_felem_reduce(p224_felem out, const p224_widefelem in) {
  397|   382k|  static const p224_widelimb two127p15 =
  398|   382k|      (((p224_widelimb)1) << 127) + (((p224_widelimb)1) << 15);
  399|   382k|  static const p224_widelimb two127m71 =
  400|   382k|      (((p224_widelimb)1) << 127) - (((p224_widelimb)1) << 71);
  401|   382k|  static const p224_widelimb two127m71m55 = (((p224_widelimb)1) << 127) -
  402|   382k|                                            (((p224_widelimb)1) << 71) -
  403|   382k|                                            (((p224_widelimb)1) << 55);
  404|   382k|  p224_widelimb output[5];
  405|       |
  406|       |  // Add 0 mod 2^224-2^96+1 to ensure all differences are positive
  407|   382k|  output[0] = in[0] + two127p15;
  408|   382k|  output[1] = in[1] + two127m71m55;
  409|   382k|  output[2] = in[2] + two127m71;
  410|   382k|  output[3] = in[3];
  411|   382k|  output[4] = in[4];
  412|       |
  413|       |  // Eliminate in[4], in[5], in[6]
  414|   382k|  output[4] += in[6] >> 16;
  415|   382k|  output[3] += (in[6] & 0xffff) << 40;
  416|   382k|  output[2] -= in[6];
  417|       |
  418|   382k|  output[3] += in[5] >> 16;
  419|   382k|  output[2] += (in[5] & 0xffff) << 40;
  420|   382k|  output[1] -= in[5];
  421|       |
  422|   382k|  output[2] += output[4] >> 16;
  423|   382k|  output[1] += (output[4] & 0xffff) << 40;
  424|   382k|  output[0] -= output[4];
  425|       |
  426|       |  // Carry 2 -> 3 -> 4
  427|   382k|  output[3] += output[2] >> 56;
  428|   382k|  output[2] &= 0x00ffffffffffffff;
  429|       |
  430|   382k|  output[4] = output[3] >> 56;
  431|   382k|  output[3] &= 0x00ffffffffffffff;
  432|       |
  433|       |  // Now output[2] < 2^56, output[3] < 2^56, output[4] < 2^72
  434|       |
  435|       |  // Eliminate output[4]
  436|   382k|  output[2] += output[4] >> 16;
  437|       |  // output[2] < 2^56 + 2^56 = 2^57
  438|   382k|  output[1] += (output[4] & 0xffff) << 40;
  439|   382k|  output[0] -= output[4];
  440|       |
  441|       |  // Carry 0 -> 1 -> 2 -> 3
  442|   382k|  output[1] += output[0] >> 56;
  443|   382k|  out[0] = output[0] & 0x00ffffffffffffff;
  444|       |
  445|   382k|  output[2] += output[1] >> 56;
  446|       |  // output[2] < 2^57 + 2^72
  447|   382k|  out[1] = output[1] & 0x00ffffffffffffff;
  448|   382k|  output[3] += output[2] >> 56;
  449|       |  // output[3] <= 2^56 + 2^16
  450|   382k|  out[2] = output[2] & 0x00ffffffffffffff;
  451|       |
  452|       |  // out[0] < 2^56, out[1] < 2^56, out[2] < 2^56,
  453|       |  // out[3] <= 2^56 + 2^16 (due to final carry),
  454|       |  // so out < 2*p
  455|   382k|  out[3] = output[3];
  456|   382k|}
bcm.c:p224_felem_mul:
  380|   267k|                           const p224_felem in2) {
  381|   267k|  out[0] = ((p224_widelimb)in1[0]) * in2[0];
  382|   267k|  out[1] = ((p224_widelimb)in1[0]) * in2[1] + ((p224_widelimb)in1[1]) * in2[0];
  383|   267k|  out[2] = ((p224_widelimb)in1[0]) * in2[2] + ((p224_widelimb)in1[1]) * in2[1] +
  384|   267k|           ((p224_widelimb)in1[2]) * in2[0];
  385|   267k|  out[3] = ((p224_widelimb)in1[0]) * in2[3] + ((p224_widelimb)in1[1]) * in2[2] +
  386|   267k|           ((p224_widelimb)in1[2]) * in2[1] + ((p224_widelimb)in1[3]) * in2[0];
  387|   267k|  out[4] = ((p224_widelimb)in1[1]) * in2[3] + ((p224_widelimb)in1[2]) * in2[2] +
  388|   267k|           ((p224_widelimb)in1[3]) * in2[1];
  389|   267k|  out[5] = ((p224_widelimb)in1[2]) * in2[3] + ((p224_widelimb)in1[3]) * in2[2];
  390|   267k|  out[6] = ((p224_widelimb)in1[3]) * in2[3];
  391|   267k|}
bcm.c:p224_felem_to_generic:
  191|  12.9k|static void p224_felem_to_generic(EC_FELEM *out, const p224_felem in) {
  192|       |  // Reduce to unique minimal representation.
  193|  12.9k|  static const int64_t two56 = ((p224_limb)1) << 56;
  194|       |  // 0 <= in < 2*p, p = 2^224 - 2^96 + 1
  195|       |  // if in > p , reduce in = in - 2^224 + 2^96 - 1
  196|  12.9k|  int64_t tmp[4], a;
  197|  12.9k|  tmp[0] = in[0];
  198|  12.9k|  tmp[1] = in[1];
  199|  12.9k|  tmp[2] = in[2];
  200|  12.9k|  tmp[3] = in[3];
  201|       |  // Case 1: a = 1 iff in >= 2^224
  202|  12.9k|  a = (in[3] >> 56);
  203|  12.9k|  tmp[0] -= a;
  204|  12.9k|  tmp[1] += a << 40;
  205|  12.9k|  tmp[3] &= 0x00ffffffffffffff;
  206|       |  // Case 2: a = 0 iff p <= in < 2^224, i.e., the high 128 bits are all 1 and
  207|       |  // the lower part is non-zero
  208|  12.9k|  a = ((in[3] & in[2] & (in[1] | 0x000000ffffffffff)) + 1) |
  209|  12.9k|      (((int64_t)(in[0] + (in[1] & 0x000000ffffffffff)) - 1) >> 63);
  210|  12.9k|  a &= 0x00ffffffffffffff;
  211|       |  // turn a into an all-one mask (if a = 0) or an all-zero mask
  212|  12.9k|  a = (a - 1) >> 63;
  213|       |  // subtract 2^224 - 2^96 + 1 if a is all-one
  214|  12.9k|  tmp[3] &= a ^ 0xffffffffffffffff;
  215|  12.9k|  tmp[2] &= a ^ 0xffffffffffffffff;
  216|  12.9k|  tmp[1] &= (a ^ 0xffffffffffffffff) | 0x000000ffffffffff;
  217|  12.9k|  tmp[0] -= 1 & a;
  218|       |
  219|       |  // eliminate negative coefficients: if tmp[0] is negative, tmp[1] must
  220|       |  // be non-zero, so we only need one step
  221|  12.9k|  a = tmp[0] >> 63;
  222|  12.9k|  tmp[0] += two56 & a;
  223|  12.9k|  tmp[1] -= 1 & a;
  224|       |
  225|       |  // carry 1 -> 2 -> 3
  226|  12.9k|  tmp[2] += tmp[1] >> 56;
  227|  12.9k|  tmp[1] &= 0x00ffffffffffffff;
  228|       |
  229|  12.9k|  tmp[3] += tmp[2] >> 56;
  230|  12.9k|  tmp[2] &= 0x00ffffffffffffff;
  231|       |
  232|       |  // Now 0 <= tmp < p
  233|  12.9k|  p224_felem tmp2;
  234|  12.9k|  tmp2[0] = tmp[0];
  235|  12.9k|  tmp2[1] = tmp[1];
  236|  12.9k|  tmp2[2] = tmp[2];
  237|  12.9k|  tmp2[3] = tmp[3];
  238|       |
  239|       |  // |p224_felem|'s minimal representation uses four 56-bit words. |EC_FELEM|
  240|       |  // uses four 64-bit words. (The top-most word only has 32 bits.)
  241|  12.9k|  out->words[0] = tmp2[0] | (tmp2[1] << 56);
  242|  12.9k|  out->words[1] = (tmp2[1] >> 8) | (tmp2[2] << 48);
  243|  12.9k|  out->words[2] = (tmp2[2] >> 16) | (tmp2[3] << 40);
  244|  12.9k|  out->words[3] = tmp2[3] >> 24;
  245|  12.9k|}
bcm.c:p224_point_add:
  680|  27.6k|                           const p224_felem z2) {
  681|  27.6k|  p224_felem ftmp, ftmp2, ftmp3, ftmp4, ftmp5, x_out, y_out, z_out;
  682|  27.6k|  p224_widefelem tmp, tmp2;
  683|  27.6k|  p224_limb z1_is_zero, z2_is_zero, x_equal, y_equal;
  684|       |
  685|  27.6k|  if (!mixed) {
  ------------------
  |  Branch (685:7): [True: 0, False: 27.6k]
  ------------------
  686|       |    // ftmp2 = z2^2
  687|      0|    p224_felem_square(tmp, z2);
  688|      0|    p224_felem_reduce(ftmp2, tmp);
  689|       |
  690|       |    // ftmp4 = z2^3
  691|      0|    p224_felem_mul(tmp, ftmp2, z2);
  692|      0|    p224_felem_reduce(ftmp4, tmp);
  693|       |
  694|       |    // ftmp4 = z2^3*y1
  695|      0|    p224_felem_mul(tmp2, ftmp4, y1);
  696|      0|    p224_felem_reduce(ftmp4, tmp2);
  697|       |
  698|       |    // ftmp2 = z2^2*x1
  699|      0|    p224_felem_mul(tmp2, ftmp2, x1);
  700|      0|    p224_felem_reduce(ftmp2, tmp2);
  701|  27.6k|  } else {
  702|       |    // We'll assume z2 = 1 (special case z2 = 0 is handled later)
  703|       |
  704|       |    // ftmp4 = z2^3*y1
  705|  27.6k|    p224_felem_assign(ftmp4, y1);
  706|       |
  707|       |    // ftmp2 = z2^2*x1
  708|  27.6k|    p224_felem_assign(ftmp2, x1);
  709|  27.6k|  }
  710|       |
  711|       |  // ftmp = z1^2
  712|  27.6k|  p224_felem_square(tmp, z1);
  713|  27.6k|  p224_felem_reduce(ftmp, tmp);
  714|       |
  715|       |  // ftmp3 = z1^3
  716|  27.6k|  p224_felem_mul(tmp, ftmp, z1);
  717|  27.6k|  p224_felem_reduce(ftmp3, tmp);
  718|       |
  719|       |  // tmp = z1^3*y2
  720|  27.6k|  p224_felem_mul(tmp, ftmp3, y2);
  721|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  722|       |
  723|       |  // ftmp3 = z1^3*y2 - z2^3*y1
  724|  27.6k|  p224_felem_diff_128_64(tmp, ftmp4);
  725|       |  // tmp[i] < 2^116 + 2^64 + 8 < 2^117
  726|  27.6k|  p224_felem_reduce(ftmp3, tmp);
  727|       |
  728|       |  // tmp = z1^2*x2
  729|  27.6k|  p224_felem_mul(tmp, ftmp, x2);
  730|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  731|       |
  732|       |  // ftmp = z1^2*x2 - z2^2*x1
  733|  27.6k|  p224_felem_diff_128_64(tmp, ftmp2);
  734|       |  // tmp[i] < 2^116 + 2^64 + 8 < 2^117
  735|  27.6k|  p224_felem_reduce(ftmp, tmp);
  736|       |
  737|       |  // The formulae are incorrect if the points are equal, so we check for this
  738|       |  // and do doubling if this happens.
  739|  27.6k|  x_equal = p224_felem_is_zero(ftmp);
  740|  27.6k|  y_equal = p224_felem_is_zero(ftmp3);
  741|  27.6k|  z1_is_zero = p224_felem_is_zero(z1);
  742|  27.6k|  z2_is_zero = p224_felem_is_zero(z2);
  743|       |  // In affine coordinates, (X_1, Y_1) == (X_2, Y_2)
  744|  27.6k|  p224_limb is_nontrivial_double =
  745|  27.6k|      x_equal & y_equal & (1 - z1_is_zero) & (1 - z2_is_zero);
  746|  27.6k|  if (constant_time_declassify_w(is_nontrivial_double)) {
  ------------------
  |  Branch (746:7): [True: 0, False: 27.6k]
  ------------------
  747|      0|    p224_point_double(x3, y3, z3, x1, y1, z1);
  748|      0|    return;
  749|      0|  }
  750|       |
  751|       |  // ftmp5 = z1*z2
  752|  27.6k|  if (!mixed) {
  ------------------
  |  Branch (752:7): [True: 0, False: 27.6k]
  ------------------
  753|      0|    p224_felem_mul(tmp, z1, z2);
  754|      0|    p224_felem_reduce(ftmp5, tmp);
  755|  27.6k|  } else {
  756|       |    // special case z2 = 0 is handled later
  757|  27.6k|    p224_felem_assign(ftmp5, z1);
  758|  27.6k|  }
  759|       |
  760|       |  // z_out = (z1^2*x2 - z2^2*x1)*(z1*z2)
  761|  27.6k|  p224_felem_mul(tmp, ftmp, ftmp5);
  762|  27.6k|  p224_felem_reduce(z_out, tmp);
  763|       |
  764|       |  // ftmp = (z1^2*x2 - z2^2*x1)^2
  765|  27.6k|  p224_felem_assign(ftmp5, ftmp);
  766|  27.6k|  p224_felem_square(tmp, ftmp);
  767|  27.6k|  p224_felem_reduce(ftmp, tmp);
  768|       |
  769|       |  // ftmp5 = (z1^2*x2 - z2^2*x1)^3
  770|  27.6k|  p224_felem_mul(tmp, ftmp, ftmp5);
  771|  27.6k|  p224_felem_reduce(ftmp5, tmp);
  772|       |
  773|       |  // ftmp2 = z2^2*x1*(z1^2*x2 - z2^2*x1)^2
  774|  27.6k|  p224_felem_mul(tmp, ftmp2, ftmp);
  775|  27.6k|  p224_felem_reduce(ftmp2, tmp);
  776|       |
  777|       |  // tmp = z2^3*y1*(z1^2*x2 - z2^2*x1)^3
  778|  27.6k|  p224_felem_mul(tmp, ftmp4, ftmp5);
  779|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  780|       |
  781|       |  // tmp2 = (z1^3*y2 - z2^3*y1)^2
  782|  27.6k|  p224_felem_square(tmp2, ftmp3);
  783|       |  // tmp2[i] < 4 * 2^57 * 2^57 < 2^116
  784|       |
  785|       |  // tmp2 = (z1^3*y2 - z2^3*y1)^2 - (z1^2*x2 - z2^2*x1)^3
  786|  27.6k|  p224_felem_diff_128_64(tmp2, ftmp5);
  787|       |  // tmp2[i] < 2^116 + 2^64 + 8 < 2^117
  788|       |
  789|       |  // ftmp5 = 2*z2^2*x1*(z1^2*x2 - z2^2*x1)^2
  790|  27.6k|  p224_felem_assign(ftmp5, ftmp2);
  791|  27.6k|  p224_felem_scalar(ftmp5, 2);
  792|       |  // ftmp5[i] < 2 * 2^57 = 2^58
  793|       |
  794|       |  /* x_out = (z1^3*y2 - z2^3*y1)^2 - (z1^2*x2 - z2^2*x1)^3 -
  795|       |     2*z2^2*x1*(z1^2*x2 - z2^2*x1)^2 */
  796|  27.6k|  p224_felem_diff_128_64(tmp2, ftmp5);
  797|       |  // tmp2[i] < 2^117 + 2^64 + 8 < 2^118
  798|  27.6k|  p224_felem_reduce(x_out, tmp2);
  799|       |
  800|       |  // ftmp2 = z2^2*x1*(z1^2*x2 - z2^2*x1)^2 - x_out
  801|  27.6k|  p224_felem_diff(ftmp2, x_out);
  802|       |  // ftmp2[i] < 2^57 + 2^58 + 2 < 2^59
  803|       |
  804|       |  // tmp2 = (z1^3*y2 - z2^3*y1)*(z2^2*x1*(z1^2*x2 - z2^2*x1)^2 - x_out)
  805|  27.6k|  p224_felem_mul(tmp2, ftmp3, ftmp2);
  806|       |  // tmp2[i] < 4 * 2^57 * 2^59 = 2^118
  807|       |
  808|       |  /* y_out = (z1^3*y2 - z2^3*y1)*(z2^2*x1*(z1^2*x2 - z2^2*x1)^2 - x_out) -
  809|       |     z2^3*y1*(z1^2*x2 - z2^2*x1)^3 */
  810|  27.6k|  p224_widefelem_diff(tmp2, tmp);
  811|       |  // tmp2[i] < 2^118 + 2^120 < 2^121
  812|  27.6k|  p224_felem_reduce(y_out, tmp2);
  813|       |
  814|       |  // the result (x_out, y_out, z_out) is incorrect if one of the inputs is
  815|       |  // the point at infinity, so we need to check for this separately
  816|       |
  817|       |  // if point 1 is at infinity, copy point 2 to output, and vice versa
  818|  27.6k|  p224_copy_conditional(x_out, x2, z1_is_zero);
  819|  27.6k|  p224_copy_conditional(x_out, x1, z2_is_zero);
  820|  27.6k|  p224_copy_conditional(y_out, y2, z1_is_zero);
  821|  27.6k|  p224_copy_conditional(y_out, y1, z2_is_zero);
  822|  27.6k|  p224_copy_conditional(z_out, z2, z1_is_zero);
  823|  27.6k|  p224_copy_conditional(z_out, z1, z2_is_zero);
  824|  27.6k|  p224_felem_assign(x3, x_out);
  825|  27.6k|  p224_felem_assign(y3, y_out);
  826|  27.6k|  p224_felem_assign(z3, z_out);
  827|  27.6k|}
bcm.c:p224_felem_assign:
  253|   275k|static void p224_felem_assign(p224_felem out, const p224_felem in) {
  254|   275k|  out[0] = in[0];
  255|   275k|  out[1] = in[1];
  256|   275k|  out[2] = in[2];
  257|   275k|  out[3] = in[3];
  258|   275k|}
bcm.c:p224_felem_diff_128_64:
  320|   137k|static void p224_felem_diff_128_64(p224_widefelem out, const p224_felem in) {
  321|   137k|  static const p224_widelimb two64p8 =
  322|   137k|      (((p224_widelimb)1) << 64) + (((p224_widelimb)1) << 8);
  323|   137k|  static const p224_widelimb two64m8 =
  324|   137k|      (((p224_widelimb)1) << 64) - (((p224_widelimb)1) << 8);
  325|   137k|  static const p224_widelimb two64m48m8 = (((p224_widelimb)1) << 64) -
  326|   137k|                                          (((p224_widelimb)1) << 48) -
  327|   137k|                                          (((p224_widelimb)1) << 8);
  328|       |
  329|       |  // Add 0 mod 2^224-2^96+1 to ensure out > in
  330|   137k|  out[0] += two64p8;
  331|   137k|  out[1] += two64m48m8;
  332|   137k|  out[2] += two64m8;
  333|   137k|  out[3] += two64m8;
  334|       |
  335|   137k|  out[0] -= in[0];
  336|   137k|  out[1] -= in[1];
  337|   137k|  out[2] -= in[2];
  338|   137k|  out[3] -= in[3];
  339|   137k|}
bcm.c:p224_felem_is_zero:
  470|   110k|static p224_limb p224_felem_is_zero(const p224_felem in) {
  471|   110k|  p224_limb zero = in[0] | in[1] | in[2] | in[3];
  472|   110k|  zero = (((int64_t)(zero)-1) >> 63) & 1;
  473|       |
  474|   110k|  p224_limb two224m96p1 = (in[0] ^ 1) | (in[1] ^ 0x00ffff0000000000) |
  475|   110k|                     (in[2] ^ 0x00ffffffffffffff) |
  476|   110k|                     (in[3] ^ 0x00ffffffffffffff);
  477|   110k|  two224m96p1 = (((int64_t)(two224m96p1)-1) >> 63) & 1;
  478|   110k|  p224_limb two225m97p2 = (in[0] ^ 2) | (in[1] ^ 0x00fffe0000000000) |
  479|   110k|                     (in[2] ^ 0x00ffffffffffffff) |
  480|   110k|                     (in[3] ^ 0x01ffffffffffffff);
  481|   110k|  two225m97p2 = (((int64_t)(two225m97p2)-1) >> 63) & 1;
  482|   110k|  return (zero | two224m96p1 | two225m97p2);
  483|   110k|}
bcm.c:p224_point_double:
  593|  13.5k|                              const p224_felem y_in, const p224_felem z_in) {
  594|  13.5k|  p224_widefelem tmp, tmp2;
  595|  13.5k|  p224_felem delta, gamma, beta, alpha, ftmp, ftmp2;
  596|       |
  597|  13.5k|  p224_felem_assign(ftmp, x_in);
  598|  13.5k|  p224_felem_assign(ftmp2, x_in);
  599|       |
  600|       |  // delta = z^2
  601|  13.5k|  p224_felem_square(tmp, z_in);
  602|  13.5k|  p224_felem_reduce(delta, tmp);
  603|       |
  604|       |  // gamma = y^2
  605|  13.5k|  p224_felem_square(tmp, y_in);
  606|  13.5k|  p224_felem_reduce(gamma, tmp);
  607|       |
  608|       |  // beta = x*gamma
  609|  13.5k|  p224_felem_mul(tmp, x_in, gamma);
  610|  13.5k|  p224_felem_reduce(beta, tmp);
  611|       |
  612|       |  // alpha = 3*(x-delta)*(x+delta)
  613|  13.5k|  p224_felem_diff(ftmp, delta);
  614|       |  // ftmp[i] < 2^57 + 2^58 + 2 < 2^59
  615|  13.5k|  p224_felem_sum(ftmp2, delta);
  616|       |  // ftmp2[i] < 2^57 + 2^57 = 2^58
  617|  13.5k|  p224_felem_scalar(ftmp2, 3);
  618|       |  // ftmp2[i] < 3 * 2^58 < 2^60
  619|  13.5k|  p224_felem_mul(tmp, ftmp, ftmp2);
  620|       |  // tmp[i] < 2^60 * 2^59 * 4 = 2^121
  621|  13.5k|  p224_felem_reduce(alpha, tmp);
  622|       |
  623|       |  // x' = alpha^2 - 8*beta
  624|  13.5k|  p224_felem_square(tmp, alpha);
  625|       |  // tmp[i] < 4 * 2^57 * 2^57 = 2^116
  626|  13.5k|  p224_felem_assign(ftmp, beta);
  627|  13.5k|  p224_felem_scalar(ftmp, 8);
  628|       |  // ftmp[i] < 8 * 2^57 = 2^60
  629|  13.5k|  p224_felem_diff_128_64(tmp, ftmp);
  630|       |  // tmp[i] < 2^116 + 2^64 + 8 < 2^117
  631|  13.5k|  p224_felem_reduce(x_out, tmp);
  632|       |
  633|       |  // z' = (y + z)^2 - gamma - delta
  634|  13.5k|  p224_felem_sum(delta, gamma);
  635|       |  // delta[i] < 2^57 + 2^57 = 2^58
  636|  13.5k|  p224_felem_assign(ftmp, y_in);
  637|  13.5k|  p224_felem_sum(ftmp, z_in);
  638|       |  // ftmp[i] < 2^57 + 2^57 = 2^58
  639|  13.5k|  p224_felem_square(tmp, ftmp);
  640|       |  // tmp[i] < 4 * 2^58 * 2^58 = 2^118
  641|  13.5k|  p224_felem_diff_128_64(tmp, delta);
  642|       |  // tmp[i] < 2^118 + 2^64 + 8 < 2^119
  643|  13.5k|  p224_felem_reduce(z_out, tmp);
  644|       |
  645|       |  // y' = alpha*(4*beta - x') - 8*gamma^2
  646|  13.5k|  p224_felem_scalar(beta, 4);
  647|       |  // beta[i] < 4 * 2^57 = 2^59
  648|  13.5k|  p224_felem_diff(beta, x_out);
  649|       |  // beta[i] < 2^59 + 2^58 + 2 < 2^60
  650|  13.5k|  p224_felem_mul(tmp, alpha, beta);
  651|       |  // tmp[i] < 4 * 2^57 * 2^60 = 2^119
  652|  13.5k|  p224_felem_square(tmp2, gamma);
  653|       |  // tmp2[i] < 4 * 2^57 * 2^57 = 2^116
  654|  13.5k|  p224_widefelem_scalar(tmp2, 8);
  655|       |  // tmp2[i] < 8 * 2^116 = 2^119
  656|  13.5k|  p224_widefelem_diff(tmp, tmp2);
  657|       |  // tmp[i] < 2^119 + 2^120 < 2^121
  658|  13.5k|  p224_felem_reduce(y_out, tmp);
  659|  13.5k|}
bcm.c:p224_felem_sum:
  261|  40.6k|static void p224_felem_sum(p224_felem out, const p224_felem in) {
  262|  40.6k|  out[0] += in[0];
  263|  40.6k|  out[1] += in[1];
  264|  40.6k|  out[2] += in[2];
  265|  40.6k|  out[3] += in[3];
  266|  40.6k|}
bcm.c:p224_widefelem_scalar:
  353|  13.5k|                                  const p224_widelimb scalar) {
  354|  13.5k|  out[0] *= scalar;
  355|  13.5k|  out[1] *= scalar;
  356|  13.5k|  out[2] *= scalar;
  357|  13.5k|  out[3] *= scalar;
  358|  13.5k|  out[4] *= scalar;
  359|  13.5k|  out[5] *= scalar;
  360|  13.5k|  out[6] *= scalar;
  361|  13.5k|}
bcm.c:p224_felem_scalar:
  343|  68.2k|static void p224_felem_scalar(p224_felem out, const p224_limb scalar) {
  344|  68.2k|  out[0] *= scalar;
  345|  68.2k|  out[1] *= scalar;
  346|  68.2k|  out[2] *= scalar;
  347|  68.2k|  out[3] *= scalar;
  348|  68.2k|}
bcm.c:p224_felem_diff:
  270|  54.7k|static void p224_felem_diff(p224_felem out, const p224_felem in) {
  271|  54.7k|  static const p224_limb two58p2 =
  272|  54.7k|      (((p224_limb)1) << 58) + (((p224_limb)1) << 2);
  273|  54.7k|  static const p224_limb two58m2 =
  274|  54.7k|      (((p224_limb)1) << 58) - (((p224_limb)1) << 2);
  275|  54.7k|  static const p224_limb two58m42m2 =
  276|  54.7k|      (((p224_limb)1) << 58) - (((p224_limb)1) << 42) - (((p224_limb)1) << 2);
  277|       |
  278|       |  // Add 0 mod 2^224-2^96+1 to ensure out > in
  279|  54.7k|  out[0] += two58p2;
  280|  54.7k|  out[1] += two58m42m2;
  281|  54.7k|  out[2] += two58m2;
  282|  54.7k|  out[3] += two58m2;
  283|       |
  284|  54.7k|  out[0] -= in[0];
  285|  54.7k|  out[1] -= in[1];
  286|  54.7k|  out[2] -= in[2];
  287|  54.7k|  out[3] -= in[3];
  288|  54.7k|}
bcm.c:p224_widefelem_diff:
  292|  41.1k|static void p224_widefelem_diff(p224_widefelem out, const p224_widefelem in) {
  293|  41.1k|  static const p224_widelimb two120 = ((p224_widelimb)1) << 120;
  294|  41.1k|  static const p224_widelimb two120m64 =
  295|  41.1k|      (((p224_widelimb)1) << 120) - (((p224_widelimb)1) << 64);
  296|  41.1k|  static const p224_widelimb two120m104m64 = (((p224_widelimb)1) << 120) -
  297|  41.1k|                                             (((p224_widelimb)1) << 104) -
  298|  41.1k|                                             (((p224_widelimb)1) << 64);
  299|       |
  300|       |  // Add 0 mod 2^224-2^96+1 to ensure out > in
  301|  41.1k|  out[0] += two120;
  302|  41.1k|  out[1] += two120m64;
  303|  41.1k|  out[2] += two120m64;
  304|  41.1k|  out[3] += two120;
  305|  41.1k|  out[4] += two120m104m64;
  306|  41.1k|  out[5] += two120m64;
  307|  41.1k|  out[6] += two120m64;
  308|       |
  309|  41.1k|  out[0] -= in[0];
  310|  41.1k|  out[1] -= in[1];
  311|  41.1k|  out[2] -= in[2];
  312|  41.1k|  out[3] -= in[3];
  313|  41.1k|  out[4] -= in[4];
  314|  41.1k|  out[5] -= in[5];
  315|  41.1k|  out[6] -= in[6];
  316|  41.1k|}
bcm.c:p224_copy_conditional:
  569|   165k|                                  p224_limb icopy) {
  570|       |  // icopy is a (64-bit) 0 or 1, so copy is either all-zero or all-one
  571|   165k|  const p224_limb copy = -icopy;
  572|   828k|  for (size_t i = 0; i < 4; ++i) {
  ------------------
  |  Branch (572:22): [True: 662k, False: 165k]
  ------------------
  573|   662k|    const p224_limb tmp = copy & (in[i] ^ out[i]);
  574|   662k|    out[i] ^= tmp;
  575|   662k|  }
  576|   165k|}
bcm.c:p224_get_bit:
  852|   112k|static crypto_word_t p224_get_bit(const EC_SCALAR *in, size_t i) {
  853|   112k|  if (i >= 224) {
  ------------------
  |  Branch (853:7): [True: 0, False: 112k]
  ------------------
  854|      0|    return 0;
  855|      0|  }
  856|   112k|  static_assert(sizeof(in->words[0]) == 8, "BN_ULONG is not 64-bit");
  857|   112k|  return (in->words[i >> 6] >> (i & 63)) & 1;
  858|   112k|}
bcm.c:p224_select_point:
  833|  28.1k|                              p224_felem out[3]) {
  834|  28.1k|  p224_limb *outlimbs = &out[0][0];
  835|  28.1k|  OPENSSL_memset(outlimbs, 0, 3 * sizeof(p224_felem));
  836|       |
  837|   477k|  for (size_t i = 0; i < size; i++) {
  ------------------
  |  Branch (837:22): [True: 449k, False: 28.1k]
  ------------------
  838|   449k|    const p224_limb *inlimbs = &pre_comp[i][0][0];
  839|   449k|    uint64_t mask = i ^ idx;
  840|   449k|    mask |= mask >> 4;
  841|   449k|    mask |= mask >> 2;
  842|   449k|    mask |= mask >> 1;
  843|   449k|    mask &= 1;
  844|   449k|    mask--;
  845|  5.84M|    for (size_t j = 0; j < 4 * 3; j++) {
  ------------------
  |  Branch (845:24): [True: 5.39M, False: 449k]
  ------------------
  846|  5.39M|      outlimbs[j] |= inlimbs[j] & mask;
  847|  5.39M|    }
  848|   449k|  }
  849|  28.1k|}
bcm.c:ec_GFp_nistp224_point_mul_base:
  997|    502|                                           const EC_SCALAR *scalar) {
  998|       |  // Set nq to the point at infinity.
  999|    502|  p224_felem nq[3], tmp[3];
 1000|    502|  OPENSSL_memset(nq, 0, 3 * sizeof(p224_felem));
 1001|       |
 1002|    502|  int skip = 1;  // Save two point operations in the first round.
 1003|  14.5k|  for (size_t i = 27; i < 28; i--) {
  ------------------
  |  Branch (1003:23): [True: 14.0k, False: 502]
  ------------------
 1004|       |    // double
 1005|  14.0k|    if (!skip) {
  ------------------
  |  Branch (1005:9): [True: 13.5k, False: 502]
  ------------------
 1006|  13.5k|      p224_point_double(nq[0], nq[1], nq[2], nq[0], nq[1], nq[2]);
 1007|  13.5k|    }
 1008|       |
 1009|       |    // First, look 28 bits upwards.
 1010|  14.0k|    crypto_word_t bits = p224_get_bit(scalar, i + 196) << 3;
 1011|  14.0k|    bits |= p224_get_bit(scalar, i + 140) << 2;
 1012|  14.0k|    bits |= p224_get_bit(scalar, i + 84) << 1;
 1013|  14.0k|    bits |= p224_get_bit(scalar, i + 28);
 1014|       |    // Select the point to add, in constant time.
 1015|  14.0k|    p224_select_point(bits, 16, g_p224_pre_comp[1], tmp);
 1016|       |
 1017|  14.0k|    if (!skip) {
  ------------------
  |  Branch (1017:9): [True: 13.5k, False: 502]
  ------------------
 1018|  13.5k|      p224_point_add(nq[0], nq[1], nq[2], nq[0], nq[1], nq[2], 1 /* mixed */,
 1019|  13.5k|                     tmp[0], tmp[1], tmp[2]);
 1020|  13.5k|    } else {
 1021|    502|      OPENSSL_memcpy(nq, tmp, 3 * sizeof(p224_felem));
 1022|    502|      skip = 0;
 1023|    502|    }
 1024|       |
 1025|       |    // Second, look at the current position/
 1026|  14.0k|    bits = p224_get_bit(scalar, i + 168) << 3;
 1027|  14.0k|    bits |= p224_get_bit(scalar, i + 112) << 2;
 1028|  14.0k|    bits |= p224_get_bit(scalar, i + 56) << 1;
 1029|  14.0k|    bits |= p224_get_bit(scalar, i);
 1030|       |    // Select the point to add, in constant time.
 1031|  14.0k|    p224_select_point(bits, 16, g_p224_pre_comp[0], tmp);
 1032|  14.0k|    p224_point_add(nq[0], nq[1], nq[2], nq[0], nq[1], nq[2], 1 /* mixed */,
 1033|  14.0k|                   tmp[0], tmp[1], tmp[2]);
 1034|  14.0k|  }
 1035|       |
 1036|       |  // Reduce the output to its unique minimal representation.
 1037|    502|  p224_felem_to_generic(&r->X, nq[0]);
 1038|    502|  p224_felem_to_generic(&r->Y, nq[1]);
 1039|    502|  p224_felem_to_generic(&r->Z, nq[2]);
 1040|    502|}
bcm.c:ec_GFp_nistp224_felem_mul:
 1124|  5.90k|                                      const EC_FELEM *a, const EC_FELEM *b) {
 1125|  5.90k|  p224_felem felem1, felem2;
 1126|  5.90k|  p224_widefelem wide;
 1127|  5.90k|  p224_generic_to_felem(felem1, a);
 1128|  5.90k|  p224_generic_to_felem(felem2, b);
 1129|  5.90k|  p224_felem_mul(wide, felem1, felem2);
 1130|  5.90k|  p224_felem_reduce(felem1, wide);
 1131|  5.90k|  p224_felem_to_generic(r, felem1);
 1132|  5.90k|}
bcm.c:ec_GFp_nistp224_felem_sqr:
 1135|  5.50k|                                      const EC_FELEM *a) {
 1136|  5.50k|  p224_felem felem;
 1137|  5.50k|  p224_generic_to_felem(felem, a);
 1138|  5.50k|  p224_widefelem wide;
 1139|  5.50k|  p224_felem_square(wide, felem);
 1140|  5.50k|  p224_felem_reduce(felem, wide);
 1141|  5.50k|  p224_felem_to_generic(r, felem);
 1142|  5.50k|}

bcm.c:EC_GFp_nistz256_method_do_init:
  615|      1|DEFINE_METHOD_FUNCTION(EC_METHOD, EC_GFp_nistz256_method) {
  616|      1|  out->group_init = ec_GFp_mont_group_init;
  617|      1|  out->group_finish = ec_GFp_mont_group_finish;
  618|      1|  out->group_set_curve = ec_GFp_mont_group_set_curve;
  619|      1|  out->point_get_affine_coordinates = ecp_nistz256_get_affine;
  620|      1|  out->add = ecp_nistz256_add;
  621|      1|  out->dbl = ecp_nistz256_dbl;
  622|      1|  out->mul = ecp_nistz256_point_mul;
  623|      1|  out->mul_base = ecp_nistz256_point_mul_base;
  624|      1|  out->mul_public = ecp_nistz256_points_mul_public;
  625|      1|  out->felem_mul = ec_GFp_mont_felem_mul;
  626|      1|  out->felem_sqr = ec_GFp_mont_felem_sqr;
  627|      1|  out->felem_to_bytes = ec_GFp_mont_felem_to_bytes;
  628|      1|  out->felem_from_bytes = ec_GFp_mont_felem_from_bytes;
  629|      1|  out->felem_reduce = ec_GFp_mont_felem_reduce;
  630|       |  // TODO(davidben): This should use the specialized field arithmetic
  631|       |  // implementation, rather than the generic one.
  632|      1|  out->felem_exp = ec_GFp_mont_felem_exp;
  633|      1|  out->scalar_inv0_montgomery = ecp_nistz256_inv0_mod_ord;
  634|      1|  out->scalar_to_montgomery_inv_vartime =
  635|      1|      ecp_nistz256_scalar_to_montgomery_inv_vartime;
  636|      1|  out->cmp_x_coordinate = ecp_nistz256_cmp_x_coordinate;
  637|      1|}
bcm.c:copy_conditional:
   80|  4.44k|                             const BN_ULONG src[P256_LIMBS], BN_ULONG move) {
   81|  4.44k|  BN_ULONG mask1 = ((BN_ULONG)0) - move;
   82|  4.44k|  BN_ULONG mask2 = ~mask1;
   83|       |
   84|  4.44k|  dst[0] = (src[0] & mask1) ^ (dst[0] & mask2);
   85|  4.44k|  dst[1] = (src[1] & mask1) ^ (dst[1] & mask2);
   86|  4.44k|  dst[2] = (src[2] & mask1) ^ (dst[2] & mask2);
   87|  4.44k|  dst[3] = (src[3] & mask1) ^ (dst[3] & mask2);
   88|  4.44k|  if (P256_LIMBS == 8) {
  ------------------
  |  |   45|  4.44k|#define P256_LIMBS (256 / BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|  4.44k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (88:7): [Folded - Ignored]
  ------------------
   89|      0|    dst[4] = (src[4] & mask1) ^ (dst[4] & mask2);
   90|      0|    dst[5] = (src[5] & mask1) ^ (dst[5] & mask2);
   91|      0|    dst[6] = (src[6] & mask1) ^ (dst[6] & mask2);
   92|      0|    dst[7] = (src[7] & mask1) ^ (dst[7] & mask2);
   93|      0|  }
   94|  4.44k|}
bcm.c:ecp_nistz256_point_mul_base:
  315|    117|                                        const EC_SCALAR *scalar) {
  316|    117|  uint8_t p_str[33];
  317|    117|  OPENSSL_memcpy(p_str, scalar->words, 32);
  318|    117|  p_str[32] = 0;
  319|       |
  320|       |  // First window
  321|    117|  size_t index = 0;
  322|    117|  crypto_word_t wvalue = calc_first_wvalue(&index, p_str);
  323|       |
  324|    117|  alignas(32) P256_POINT_AFFINE t;
  325|    117|  alignas(32) P256_POINT p;
  326|    117|  ecp_nistz256_select_w7(&t, ecp_nistz256_precomputed[0], wvalue >> 1);
  327|    117|  ecp_nistz256_neg(p.Z, t.Y);
  328|    117|  copy_conditional(t.Y, p.Z, wvalue & 1);
  329|       |
  330|       |  // Convert |t| from affine to Jacobian coordinates. We set Z to zero if |t|
  331|       |  // is infinity and |ONE| otherwise. |t| was computed from the table, so it
  332|       |  // is infinity iff |wvalue >> 1| is zero.
  333|    117|  OPENSSL_memcpy(p.X, t.X, sizeof(p.X));
  334|    117|  OPENSSL_memcpy(p.Y, t.Y, sizeof(p.Y));
  335|    117|  OPENSSL_memset(p.Z, 0, sizeof(p.Z));
  336|    117|  copy_conditional(p.Z, ONE, is_not_zero(wvalue >> 1));
  337|       |
  338|  4.32k|  for (int i = 1; i < 37; i++) {
  ------------------
  |  Branch (338:19): [True: 4.21k, False: 117]
  ------------------
  339|  4.21k|    wvalue = calc_wvalue(&index, p_str);
  340|       |
  341|  4.21k|    ecp_nistz256_select_w7(&t, ecp_nistz256_precomputed[i], wvalue >> 1);
  342|       |
  343|  4.21k|    alignas(32) BN_ULONG neg_Y[P256_LIMBS];
  344|  4.21k|    ecp_nistz256_neg(neg_Y, t.Y);
  345|  4.21k|    copy_conditional(t.Y, neg_Y, wvalue & 1);
  346|       |
  347|       |    // Note |ecp_nistz256_point_add_affine| does not work if |p| and |t| are the
  348|       |    // same non-infinity point.
  349|  4.21k|    ecp_nistz256_point_add_affine(&p, &p, &t);
  350|  4.21k|  }
  351|       |
  352|    117|  assert(group->field.width == P256_LIMBS);
  353|    117|  OPENSSL_memcpy(r->X.words, p.X, P256_LIMBS * sizeof(BN_ULONG));
  ------------------
  |  |   45|    117|#define P256_LIMBS (256 / BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|    117|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  354|    117|  OPENSSL_memcpy(r->Y.words, p.Y, P256_LIMBS * sizeof(BN_ULONG));
  ------------------
  |  |   45|    117|#define P256_LIMBS (256 / BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|    117|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  355|    117|  OPENSSL_memcpy(r->Z.words, p.Z, P256_LIMBS * sizeof(BN_ULONG));
  ------------------
  |  |   45|    117|#define P256_LIMBS (256 / BN_BITS2)
  |  |  ------------------
  |  |  |  |  151|    117|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  356|    117|}
bcm.c:calc_first_wvalue:
  280|    117|static crypto_word_t calc_first_wvalue(size_t *index, const uint8_t p_str[33]) {
  281|    117|  static const size_t kWindowSize = 7;
  282|    117|  static const crypto_word_t kMask = (1 << (7 /* kWindowSize */ + 1)) - 1;
  283|    117|  *index = kWindowSize;
  284|       |
  285|    117|  crypto_word_t wvalue = (p_str[0] << 1) & kMask;
  286|    117|  return booth_recode_w7(wvalue);
  287|    117|}
bcm.c:booth_recode_w7:
   63|  4.32k|static crypto_word_t booth_recode_w7(crypto_word_t in) {
   64|  4.32k|  crypto_word_t s, d;
   65|       |
   66|  4.32k|  s = ~((in >> 7) - 1);
   67|  4.32k|  d = (1 << 8) - in - 1;
   68|  4.32k|  d = (d & s) | (in & ~s);
   69|  4.32k|  d = (d >> 1) + (d & 1);
   70|       |
   71|  4.32k|  return (d << 1) + (s & 1);
   72|  4.32k|}
bcm.c:is_not_zero:
  113|    117|static BN_ULONG is_not_zero(BN_ULONG in) {
  114|    117|  in |= (0 - in);
  115|    117|  in >>= BN_BITS2 - 1;
  ------------------
  |  |  151|    117|#define BN_BITS2 64
  ------------------
  116|    117|  return in;
  117|    117|}
bcm.c:calc_wvalue:
  289|  4.21k|static crypto_word_t calc_wvalue(size_t *index, const uint8_t p_str[33]) {
  290|  4.21k|  static const size_t kWindowSize = 7;
  291|  4.21k|  static const crypto_word_t kMask = (1 << (7 /* kWindowSize */ + 1)) - 1;
  292|       |
  293|  4.21k|  const size_t off = (*index - 1) / 8;
  294|  4.21k|  crypto_word_t wvalue =
  295|  4.21k|      (crypto_word_t)p_str[off] | (crypto_word_t)p_str[off + 1] << 8;
  296|  4.21k|  wvalue = (wvalue >> ((*index - 1) % 8)) & kMask;
  297|  4.21k|  *index += kWindowSize;
  298|       |
  299|  4.21k|  return booth_recode_w7(wvalue);
  300|  4.21k|}

ec_bignum_to_scalar:
   25|  1.23k|                        const BIGNUM *in) {
   26|  1.23k|  if (!bn_copy_words(out->words, group->order.width, in) ||
  ------------------
  |  Branch (26:7): [True: 115, False: 1.11k]
  ------------------
   27|  1.23k|      !bn_less_than_words(out->words, group->order.d, group->order.width)) {
  ------------------
  |  Branch (27:7): [True: 4, False: 1.11k]
  ------------------
   28|    119|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_SCALAR);
  ------------------
  |  |  441|    119|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   29|    119|    return 0;
   30|    119|  }
   31|  1.11k|  return 1;
   32|  1.23k|}
ec_scalar_is_zero:
   40|  1.11k|int ec_scalar_is_zero(const EC_GROUP *group, const EC_SCALAR *a) {
   41|  1.11k|  BN_ULONG mask = 0;
   42|  6.53k|  for (int i = 0; i < group->order.width; i++) {
  ------------------
  |  Branch (42:19): [True: 5.41k, False: 1.11k]
  ------------------
   43|  5.41k|    mask |= a->words[i];
   44|  5.41k|  }
   45|  1.11k|  return mask == 0;
   46|  1.11k|}

ec_GFp_simple_group_init:
   91|      4|int ec_GFp_simple_group_init(EC_GROUP *group) {
   92|      4|  BN_init(&group->field);
   93|      4|  group->a_is_minus3 = 0;
   94|      4|  return 1;
   95|      4|}
ec_GFp_simple_group_set_curve:
  103|      4|                                  BN_CTX *ctx) {
  104|       |  // p must be a prime > 3
  105|      4|  if (BN_num_bits(p) <= 2 || !BN_is_odd(p)) {
  ------------------
  |  Branch (105:7): [True: 0, False: 4]
  |  Branch (105:30): [True: 0, False: 4]
  ------------------
  106|      0|    OPENSSL_PUT_ERROR(EC, EC_R_INVALID_FIELD);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|      4|  int ret = 0;
  111|      4|  BN_CTX_start(ctx);
  112|      4|  BIGNUM *tmp = BN_CTX_get(ctx);
  113|      4|  if (tmp == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 4]
  ------------------
  114|      0|    goto err;
  115|      0|  }
  116|       |
  117|       |  // group->field
  118|      4|  if (!BN_copy(&group->field, p)) {
  ------------------
  |  Branch (118:7): [True: 0, False: 4]
  ------------------
  119|      0|    goto err;
  120|      0|  }
  121|      4|  BN_set_negative(&group->field, 0);
  122|       |  // Store the field in minimal form, so it can be used with |BN_ULONG| arrays.
  123|      4|  bn_set_minimal_width(&group->field);
  124|       |
  125|      4|  if (!ec_bignum_to_felem(group, &group->a, a) ||
  ------------------
  |  Branch (125:7): [True: 0, False: 4]
  ------------------
  126|      4|      !ec_bignum_to_felem(group, &group->b, b) ||
  ------------------
  |  Branch (126:7): [True: 0, False: 4]
  ------------------
  127|      4|      !ec_bignum_to_felem(group, &group->one, BN_value_one())) {
  ------------------
  |  Branch (127:7): [True: 0, False: 4]
  ------------------
  128|      0|    goto err;
  129|      0|  }
  130|       |
  131|       |  // group->a_is_minus3
  132|      4|  if (!BN_copy(tmp, a) ||
  ------------------
  |  Branch (132:7): [True: 0, False: 4]
  ------------------
  133|      4|      !BN_add_word(tmp, 3)) {
  ------------------
  |  Branch (133:7): [True: 0, False: 4]
  ------------------
  134|      0|    goto err;
  135|      0|  }
  136|      4|  group->a_is_minus3 = (0 == BN_cmp(tmp, &group->field));
  137|       |
  138|      4|  ret = 1;
  139|       |
  140|      4|err:
  141|      4|  BN_CTX_end(ctx);
  142|      4|  return ret;
  143|      4|}
ec_GFp_simple_group_get_curve:
  146|    671|                                  BIGNUM *b) {
  147|    671|  if ((p != NULL && !BN_copy(p, &group->field)) ||
  ------------------
  |  Branch (147:8): [True: 0, False: 671]
  |  Branch (147:21): [True: 0, False: 0]
  ------------------
  148|    671|      (a != NULL && !ec_felem_to_bignum(group, a, &group->a)) ||
  ------------------
  |  Branch (148:8): [True: 671, False: 0]
  |  Branch (148:21): [True: 0, False: 671]
  ------------------
  149|    671|      (b != NULL && !ec_felem_to_bignum(group, b, &group->b))) {
  ------------------
  |  Branch (149:8): [True: 671, False: 0]
  |  Branch (149:21): [True: 0, False: 671]
  ------------------
  150|      0|    return 0;
  151|      0|  }
  152|    671|  return 1;
  153|    671|}
ec_GFp_simple_point_init:
  155|  1.56k|void ec_GFp_simple_point_init(EC_JACOBIAN *point) {
  156|  1.56k|  OPENSSL_memset(&point->X, 0, sizeof(EC_FELEM));
  157|  1.56k|  OPENSSL_memset(&point->Y, 0, sizeof(EC_FELEM));
  158|  1.56k|  OPENSSL_memset(&point->Z, 0, sizeof(EC_FELEM));
  159|  1.56k|}
ec_GFp_simple_point_copy:
  161|    674|void ec_GFp_simple_point_copy(EC_JACOBIAN *dest, const EC_JACOBIAN *src) {
  162|    674|  OPENSSL_memcpy(&dest->X, &src->X, sizeof(EC_FELEM));
  163|    674|  OPENSSL_memcpy(&dest->Y, &src->Y, sizeof(EC_FELEM));
  164|    674|  OPENSSL_memcpy(&dest->Z, &src->Z, sizeof(EC_FELEM));
  165|    674|}
ec_GFp_simple_point_set_to_infinity:
  168|    323|                                         EC_JACOBIAN *point) {
  169|       |  // Although it is strictly only necessary to zero Z, we zero the entire point
  170|       |  // in case |point| was stack-allocated and yet to be initialized.
  171|    323|  ec_GFp_simple_point_init(point);
  172|    323|}
ec_GFp_simple_is_at_infinity:
  179|    601|                                 const EC_JACOBIAN *point) {
  180|    601|  return ec_felem_non_zero_mask(group, &point->Z) == 0;
  181|    601|}
ec_GFp_simple_is_on_curve:
  184|  1.54k|                              const EC_JACOBIAN *point) {
  185|       |  // We have a curve defined by a Weierstrass equation
  186|       |  //      y^2 = x^3 + a*x + b.
  187|       |  // The point to consider is given in Jacobian projective coordinates
  188|       |  // where  (X, Y, Z)  represents  (x, y) = (X/Z^2, Y/Z^3).
  189|       |  // Substituting this and multiplying by  Z^6  transforms the above equation
  190|       |  // into
  191|       |  //      Y^2 = X^3 + a*X*Z^4 + b*Z^6.
  192|       |  // To test this, we add up the right-hand side in 'rh'.
  193|       |  //
  194|       |  // This function may be used when double-checking the secret result of a point
  195|       |  // multiplication, so we proceed in constant-time.
  196|       |
  197|  1.54k|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  198|  1.54k|                          const EC_FELEM *b) = group->meth->felem_mul;
  199|  1.54k|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  200|  1.54k|      group->meth->felem_sqr;
  201|       |
  202|       |  // rh := X^2
  203|  1.54k|  EC_FELEM rh;
  204|  1.54k|  felem_sqr(group, &rh, &point->X);
  205|       |
  206|  1.54k|  EC_FELEM tmp, Z4, Z6;
  207|  1.54k|  felem_sqr(group, &tmp, &point->Z);
  208|  1.54k|  felem_sqr(group, &Z4, &tmp);
  209|  1.54k|  felem_mul(group, &Z6, &Z4, &tmp);
  210|       |
  211|       |  // rh := rh + a*Z^4
  212|  1.54k|  if (group->a_is_minus3) {
  ------------------
  |  Branch (212:7): [True: 1.54k, False: 0]
  ------------------
  213|  1.54k|    ec_felem_add(group, &tmp, &Z4, &Z4);
  214|  1.54k|    ec_felem_add(group, &tmp, &tmp, &Z4);
  215|  1.54k|    ec_felem_sub(group, &rh, &rh, &tmp);
  216|  1.54k|  } else {
  217|      0|    felem_mul(group, &tmp, &Z4, &group->a);
  218|      0|    ec_felem_add(group, &rh, &rh, &tmp);
  219|      0|  }
  220|       |
  221|       |  // rh := (rh + a*Z^4)*X
  222|  1.54k|  felem_mul(group, &rh, &rh, &point->X);
  223|       |
  224|       |  // rh := rh + b*Z^6
  225|  1.54k|  felem_mul(group, &tmp, &group->b, &Z6);
  226|  1.54k|  ec_felem_add(group, &rh, &rh, &tmp);
  227|       |
  228|       |  // 'lh' := Y^2
  229|  1.54k|  felem_sqr(group, &tmp, &point->Y);
  230|       |
  231|  1.54k|  ec_felem_sub(group, &tmp, &tmp, &rh);
  232|  1.54k|  BN_ULONG not_equal = ec_felem_non_zero_mask(group, &tmp);
  233|       |
  234|       |  // If Z = 0, the point is infinity, which is always on the curve.
  235|  1.54k|  BN_ULONG not_infinity = ec_felem_non_zero_mask(group, &point->Z);
  236|       |
  237|  1.54k|  return 1 & ~(not_infinity & not_equal);
  238|  1.54k|}
ec_GFp_simple_points_equal:
  241|    601|                               const EC_JACOBIAN *b) {
  242|       |  // This function is implemented in constant-time for two reasons. First,
  243|       |  // although EC points are usually public, their Jacobian Z coordinates may be
  244|       |  // secret, or at least are not obviously public. Second, more complex
  245|       |  // protocols will sometimes manipulate secret points.
  246|       |  //
  247|       |  // This does mean that we pay a 6M+2S Jacobian comparison when comparing two
  248|       |  // publicly affine points costs no field operations at all. If needed, we can
  249|       |  // restore this optimization by keeping better track of affine vs. Jacobian
  250|       |  // forms. See https://crbug.com/boringssl/326.
  251|       |
  252|       |  // If neither |a| or |b| is infinity, we have to decide whether
  253|       |  //     (X_a/Z_a^2, Y_a/Z_a^3) = (X_b/Z_b^2, Y_b/Z_b^3),
  254|       |  // or equivalently, whether
  255|       |  //     (X_a*Z_b^2, Y_a*Z_b^3) = (X_b*Z_a^2, Y_b*Z_a^3).
  256|       |
  257|    601|  void (*const felem_mul)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a,
  258|    601|                          const EC_FELEM *b) = group->meth->felem_mul;
  259|    601|  void (*const felem_sqr)(const EC_GROUP *, EC_FELEM *r, const EC_FELEM *a) =
  260|    601|      group->meth->felem_sqr;
  261|       |
  262|    601|  EC_FELEM tmp1, tmp2, Za23, Zb23;
  263|    601|  felem_sqr(group, &Zb23, &b->Z);         // Zb23 = Z_b^2
  264|    601|  felem_mul(group, &tmp1, &a->X, &Zb23);  // tmp1 = X_a * Z_b^2
  265|    601|  felem_sqr(group, &Za23, &a->Z);         // Za23 = Z_a^2
  266|    601|  felem_mul(group, &tmp2, &b->X, &Za23);  // tmp2 = X_b * Z_a^2
  267|    601|  ec_felem_sub(group, &tmp1, &tmp1, &tmp2);
  268|    601|  const BN_ULONG x_not_equal = ec_felem_non_zero_mask(group, &tmp1);
  269|       |
  270|    601|  felem_mul(group, &Zb23, &Zb23, &b->Z);  // Zb23 = Z_b^3
  271|    601|  felem_mul(group, &tmp1, &a->Y, &Zb23);  // tmp1 = Y_a * Z_b^3
  272|    601|  felem_mul(group, &Za23, &Za23, &a->Z);  // Za23 = Z_a^3
  273|    601|  felem_mul(group, &tmp2, &b->Y, &Za23);  // tmp2 = Y_b * Z_a^3
  274|    601|  ec_felem_sub(group, &tmp1, &tmp1, &tmp2);
  275|    601|  const BN_ULONG y_not_equal = ec_felem_non_zero_mask(group, &tmp1);
  276|    601|  const BN_ULONG x_and_y_equal = ~(x_not_equal | y_not_equal);
  277|       |
  278|    601|  const BN_ULONG a_not_infinity = ec_felem_non_zero_mask(group, &a->Z);
  279|    601|  const BN_ULONG b_not_infinity = ec_felem_non_zero_mask(group, &b->Z);
  280|    601|  const BN_ULONG a_and_b_infinity = ~(a_not_infinity | b_not_infinity);
  281|       |
  282|    601|  const BN_ULONG equal =
  283|    601|      a_and_b_infinity | (a_not_infinity & b_not_infinity & x_and_y_equal);
  284|    601|  return equal & 1;
  285|    601|}
ec_GFp_simple_felem_to_bytes:
  331|  1.34k|                                  size_t *out_len, const EC_FELEM *in) {
  332|  1.34k|  size_t len = BN_num_bytes(&group->field);
  333|  1.34k|  bn_words_to_big_endian(out, len, in->words, group->field.width);
  334|  1.34k|  *out_len = len;
  335|  1.34k|}
ec_GFp_simple_felem_from_bytes:
  338|    998|                                   const uint8_t *in, size_t len) {
  339|    998|  if (len != BN_num_bytes(&group->field)) {
  ------------------
  |  Branch (339:7): [True: 0, False: 998]
  ------------------
  340|      0|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  341|      0|    return 0;
  342|      0|  }
  343|       |
  344|    998|  bn_big_endian_to_words(out->words, group->field.width, in, len);
  345|       |
  346|    998|  if (!bn_less_than_words(out->words, group->field.d, group->field.width)) {
  ------------------
  |  Branch (346:7): [True: 8, False: 990]
  ------------------
  347|      8|    OPENSSL_PUT_ERROR(EC, EC_R_DECODE_ERROR);
  ------------------
  |  |  441|      8|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  348|      8|    return 0;
  349|      8|  }
  350|       |
  351|    990|  return 1;
  352|    998|}

ec_GFp_mont_mul:
   25|    323|                     const EC_JACOBIAN *p, const EC_SCALAR *scalar) {
   26|       |  // This is a generic implementation for uncommon curves that not do not
   27|       |  // warrant a tuned one. It uses unsigned digits so that the doubling case in
   28|       |  // |ec_GFp_mont_add| is always unreachable, erring on safety and simplicity.
   29|       |
   30|       |  // Compute a table of the first 32 multiples of |p| (including infinity).
   31|    323|  EC_JACOBIAN precomp[32];
   32|    323|  ec_GFp_simple_point_set_to_infinity(group, &precomp[0]);
   33|    323|  ec_GFp_simple_point_copy(&precomp[1], p);
   34|  10.0k|  for (size_t j = 2; j < OPENSSL_ARRAY_SIZE(precomp); j++) {
  ------------------
  |  |  221|  10.0k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (34:22): [True: 9.69k, False: 323]
  ------------------
   35|  9.69k|    if (j & 1) {
  ------------------
  |  Branch (35:9): [True: 4.84k, False: 4.84k]
  ------------------
   36|  4.84k|      ec_GFp_mont_add(group, &precomp[j], &precomp[1], &precomp[j - 1]);
   37|  4.84k|    } else {
   38|  4.84k|      ec_GFp_mont_dbl(group, &precomp[j], &precomp[j / 2]);
   39|  4.84k|    }
   40|  9.69k|  }
   41|       |
   42|       |  // Divide bits in |scalar| into windows.
   43|    323|  unsigned bits = BN_num_bits(&group->order);
   44|    323|  int r_is_at_infinity = 1;
   45|   146k|  for (unsigned i = bits - 1; i < bits; i--) {
  ------------------
  |  Branch (45:31): [True: 145k, False: 323]
  ------------------
   46|   145k|    if (!r_is_at_infinity) {
  ------------------
  |  Branch (46:9): [True: 145k, False: 815]
  ------------------
   47|   145k|      ec_GFp_mont_dbl(group, r, r);
   48|   145k|    }
   49|   145k|    if (i % 5 == 0) {
  ------------------
  |  Branch (49:9): [True: 29.3k, False: 116k]
  ------------------
   50|       |      // Compute the next window value.
   51|  29.3k|      const size_t width = group->order.width;
   52|  29.3k|      uint8_t window = bn_is_bit_set_words(scalar->words, width, i + 4) << 4;
   53|  29.3k|      window |= bn_is_bit_set_words(scalar->words, width, i + 3) << 3;
   54|  29.3k|      window |= bn_is_bit_set_words(scalar->words, width, i + 2) << 2;
   55|  29.3k|      window |= bn_is_bit_set_words(scalar->words, width, i + 1) << 1;
   56|  29.3k|      window |= bn_is_bit_set_words(scalar->words, width, i);
   57|       |
   58|       |      // Select the entry in constant-time.
   59|  29.3k|      EC_JACOBIAN tmp;
   60|  29.3k|      OPENSSL_memset(&tmp, 0, sizeof(EC_JACOBIAN));
   61|   967k|      for (size_t j = 0; j < OPENSSL_ARRAY_SIZE(precomp); j++) {
  ------------------
  |  |  221|   967k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (61:26): [True: 938k, False: 29.3k]
  ------------------
   62|   938k|        BN_ULONG mask = constant_time_eq_w(j, window);
   63|   938k|        ec_point_select(group, &tmp, mask, &precomp[j], &tmp);
   64|   938k|      }
   65|       |
   66|  29.3k|      if (r_is_at_infinity) {
  ------------------
  |  Branch (66:11): [True: 323, False: 29.0k]
  ------------------
   67|    323|        ec_GFp_simple_point_copy(r, &tmp);
   68|    323|        r_is_at_infinity = 0;
   69|  29.0k|      } else {
   70|  29.0k|        ec_GFp_mont_add(group, r, r, &tmp);
   71|  29.0k|      }
   72|  29.3k|    }
   73|   145k|  }
   74|    323|  if (r_is_at_infinity) {
  ------------------
  |  Branch (74:7): [True: 0, False: 323]
  ------------------
   75|      0|    ec_GFp_simple_point_set_to_infinity(group, r);
   76|      0|  }
   77|    323|}
ec_GFp_mont_mul_base:
   80|    323|                          const EC_SCALAR *scalar) {
   81|    323|  ec_GFp_mont_mul(group, r, &group->generator->raw, scalar);
   82|    323|}

RSA_new:
  206|  2.20k|RSA *RSA_new(void) { return RSA_new_method(NULL); }
RSA_new_method:
  208|  2.20k|RSA *RSA_new_method(const ENGINE *engine) {
  209|  2.20k|  RSA *rsa = OPENSSL_malloc(sizeof(RSA));
  210|  2.20k|  if (rsa == NULL) {
  ------------------
  |  Branch (210:7): [True: 0, False: 2.20k]
  ------------------
  211|      0|    return NULL;
  212|      0|  }
  213|       |
  214|  2.20k|  OPENSSL_memset(rsa, 0, sizeof(RSA));
  215|       |
  216|  2.20k|  if (engine) {
  ------------------
  |  Branch (216:7): [True: 0, False: 2.20k]
  ------------------
  217|      0|    rsa->meth = ENGINE_get_RSA_method(engine);
  218|      0|  }
  219|       |
  220|  2.20k|  if (rsa->meth == NULL) {
  ------------------
  |  Branch (220:7): [True: 2.20k, False: 0]
  ------------------
  221|  2.20k|    rsa->meth = (RSA_METHOD *) RSA_default_method();
  222|  2.20k|  }
  223|  2.20k|  METHOD_ref(rsa->meth);
  224|       |
  225|  2.20k|  rsa->references = 1;
  226|  2.20k|  rsa->flags = rsa->meth->flags;
  227|  2.20k|  CRYPTO_MUTEX_init(&rsa->lock);
  228|  2.20k|  CRYPTO_new_ex_data(&rsa->ex_data);
  229|       |
  230|  2.20k|  if (rsa->meth->init && !rsa->meth->init(rsa)) {
  ------------------
  |  Branch (230:7): [True: 0, False: 2.20k]
  |  Branch (230:26): [True: 0, False: 0]
  ------------------
  231|      0|    CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  232|      0|    CRYPTO_MUTEX_cleanup(&rsa->lock);
  233|      0|    METHOD_unref(rsa->meth);
  234|      0|    OPENSSL_free(rsa);
  235|      0|    return NULL;
  236|      0|  }
  237|       |
  238|  2.20k|  return rsa;
  239|  2.20k|}
RSA_free:
  252|  4.51k|void RSA_free(RSA *rsa) {
  253|  4.51k|  if (rsa == NULL) {
  ------------------
  |  Branch (253:7): [True: 2.31k, False: 2.20k]
  ------------------
  254|  2.31k|    return;
  255|  2.31k|  }
  256|       |
  257|  2.20k|  if (!CRYPTO_refcount_dec_and_test_zero(&rsa->references)) {
  ------------------
  |  Branch (257:7): [True: 0, False: 2.20k]
  ------------------
  258|      0|    return;
  259|      0|  }
  260|       |
  261|  2.20k|  if (rsa->meth->finish) {
  ------------------
  |  Branch (261:7): [True: 0, False: 2.20k]
  ------------------
  262|      0|    rsa->meth->finish(rsa);
  263|      0|  }
  264|  2.20k|  METHOD_unref(rsa->meth);
  265|       |
  266|  2.20k|  CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  267|       |
  268|  2.20k|  BN_free(rsa->n);
  269|  2.20k|  BN_free(rsa->e);
  270|  2.20k|  BN_free(rsa->d);
  271|  2.20k|  BN_free(rsa->p);
  272|  2.20k|  BN_free(rsa->q);
  273|  2.20k|  BN_free(rsa->dmp1);
  274|  2.20k|  BN_free(rsa->dmq1);
  275|  2.20k|  BN_free(rsa->iqmp);
  276|  2.20k|  rsa_invalidate_key(rsa);
  277|  2.20k|  CRYPTO_MUTEX_cleanup(&rsa->lock);
  278|  2.20k|  OPENSSL_free(rsa);
  279|  2.20k|}
RSA_is_opaque:
  438|    712|int RSA_is_opaque(const RSA *rsa) {
  439|    712|  return rsa->meth && (rsa->meth->flags & RSA_FLAG_OPAQUE);
  ------------------
  |  |  661|    712|#define RSA_FLAG_OPAQUE 1
  ------------------
  |  Branch (439:10): [True: 712, False: 0]
  |  Branch (439:23): [True: 0, False: 712]
  ------------------
  440|    712|}
RSA_check_key:
  787|    712|int RSA_check_key(const RSA *key) {
  788|       |  // TODO(davidben): RSA key initialization is spread across
  789|       |  // |rsa_check_public_key|, |RSA_check_key|, |freeze_private_key|, and
  790|       |  // |BN_MONT_CTX_set_locked| as a result of API issues. See
  791|       |  // https://crbug.com/boringssl/316. As a result, we inconsistently check RSA
  792|       |  // invariants. We should fix this and integrate that logic.
  793|       |
  794|    712|  if (RSA_is_opaque(key)) {
  ------------------
  |  Branch (794:7): [True: 0, False: 712]
  ------------------
  795|       |    // Opaque keys can't be checked.
  796|      0|    return 1;
  797|      0|  }
  798|       |
  799|    712|  if (!rsa_check_public_key(key)) {
  ------------------
  |  Branch (799:7): [True: 398, False: 314]
  ------------------
  800|    398|    return 0;
  801|    398|  }
  802|       |
  803|    314|  if ((key->p != NULL) != (key->q != NULL)) {
  ------------------
  |  Branch (803:7): [True: 0, False: 314]
  ------------------
  804|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_ONLY_ONE_OF_P_Q_GIVEN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  805|      0|    return 0;
  806|      0|  }
  807|       |
  808|       |  // |key->d| must be bounded by |key->n|. This ensures bounds on |RSA_bits|
  809|       |  // translate to bounds on the running time of private key operations.
  810|    314|  if (key->d != NULL &&
  ------------------
  |  Branch (810:7): [True: 314, False: 0]
  ------------------
  811|    314|      (BN_is_negative(key->d) || BN_cmp(key->d, key->n) >= 0)) {
  ------------------
  |  Branch (811:8): [True: 0, False: 314]
  |  Branch (811:34): [True: 4, False: 310]
  ------------------
  812|      4|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_OUT_OF_RANGE);
  ------------------
  |  |  441|      4|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  813|      4|    return 0;
  814|      4|  }
  815|       |
  816|    310|  if (key->d == NULL || key->p == NULL) {
  ------------------
  |  Branch (816:7): [True: 0, False: 310]
  |  Branch (816:25): [True: 0, False: 310]
  ------------------
  817|       |    // For a public key, or without p and q, there's nothing that can be
  818|       |    // checked.
  819|      0|    return 1;
  820|      0|  }
  821|       |
  822|    310|  BN_CTX *ctx = BN_CTX_new();
  823|    310|  if (ctx == NULL) {
  ------------------
  |  Branch (823:7): [True: 0, False: 310]
  ------------------
  824|      0|    return 0;
  825|      0|  }
  826|       |
  827|    310|  BIGNUM tmp, de, pm1, qm1, dmp1, dmq1;
  828|    310|  int ok = 0;
  829|    310|  BN_init(&tmp);
  830|    310|  BN_init(&de);
  831|    310|  BN_init(&pm1);
  832|    310|  BN_init(&qm1);
  833|    310|  BN_init(&dmp1);
  834|    310|  BN_init(&dmq1);
  835|       |
  836|       |  // Check that p * q == n. Before we multiply, we check that p and q are in
  837|       |  // bounds, to avoid a DoS vector in |bn_mul_consttime| below. Note that
  838|       |  // n was bound by |rsa_check_public_key|. This also implicitly checks p and q
  839|       |  // are odd, which is a necessary condition for Montgomery reduction.
  840|    310|  if (BN_is_negative(key->p) || BN_cmp(key->p, key->n) >= 0 ||
  ------------------
  |  Branch (840:7): [True: 0, False: 310]
  |  Branch (840:33): [True: 6, False: 304]
  ------------------
  841|    310|      BN_is_negative(key->q) || BN_cmp(key->q, key->n) >= 0) {
  ------------------
  |  Branch (841:7): [True: 0, False: 304]
  |  Branch (841:33): [True: 3, False: 301]
  ------------------
  842|      9|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|      9|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  843|      9|    goto out;
  844|      9|  }
  845|    301|  if (!bn_mul_consttime(&tmp, key->p, key->q, ctx)) {
  ------------------
  |  Branch (845:7): [True: 0, False: 301]
  ------------------
  846|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  847|      0|    goto out;
  848|      0|  }
  849|    301|  if (BN_cmp(&tmp, key->n) != 0) {
  ------------------
  |  Branch (849:7): [True: 78, False: 223]
  ------------------
  850|     78|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|     78|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  851|     78|    goto out;
  852|     78|  }
  853|       |
  854|       |  // d must be an inverse of e mod the Carmichael totient, lcm(p-1, q-1), but it
  855|       |  // may be unreduced because other implementations use the Euler totient. We
  856|       |  // simply check that d * e is one mod p-1 and mod q-1. Note d and e were bound
  857|       |  // by earlier checks in this function.
  858|    223|  if (!bn_usub_consttime(&pm1, key->p, BN_value_one()) ||
  ------------------
  |  Branch (858:7): [True: 0, False: 223]
  ------------------
  859|    223|      !bn_usub_consttime(&qm1, key->q, BN_value_one())) {
  ------------------
  |  Branch (859:7): [True: 0, False: 223]
  ------------------
  860|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  861|      0|    goto out;
  862|      0|  }
  863|    223|  const unsigned pm1_bits = BN_num_bits(&pm1);
  864|    223|  const unsigned qm1_bits = BN_num_bits(&qm1);
  865|    223|  if (!bn_mul_consttime(&de, key->d, key->e, ctx) ||
  ------------------
  |  Branch (865:7): [True: 0, False: 223]
  ------------------
  866|    223|      !bn_div_consttime(NULL, &tmp, &de, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (866:7): [True: 0, False: 223]
  ------------------
  867|    223|      !bn_div_consttime(NULL, &de, &de, &qm1, qm1_bits, ctx)) {
  ------------------
  |  Branch (867:7): [True: 0, False: 223]
  ------------------
  868|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  869|      0|    goto out;
  870|      0|  }
  871|       |
  872|    223|  if (!BN_is_one(&tmp) || !BN_is_one(&de)) {
  ------------------
  |  Branch (872:7): [True: 125, False: 98]
  |  Branch (872:27): [True: 0, False: 98]
  ------------------
  873|    125|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_E_NOT_CONGRUENT_TO_1);
  ------------------
  |  |  441|    125|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  874|    125|    goto out;
  875|    125|  }
  876|       |
  877|     98|  int has_crt_values = key->dmp1 != NULL;
  878|     98|  if (has_crt_values != (key->dmq1 != NULL) ||
  ------------------
  |  Branch (878:7): [True: 0, False: 98]
  ------------------
  879|     98|      has_crt_values != (key->iqmp != NULL)) {
  ------------------
  |  Branch (879:7): [True: 0, False: 98]
  ------------------
  880|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_INCONSISTENT_SET_OF_CRT_VALUES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  881|      0|    goto out;
  882|      0|  }
  883|       |
  884|     98|  if (has_crt_values) {
  ------------------
  |  Branch (884:7): [True: 98, False: 0]
  ------------------
  885|     98|    int dmp1_ok, dmq1_ok, iqmp_ok;
  886|     98|    if (!check_mod_inverse(&dmp1_ok, key->e, key->dmp1, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (886:9): [True: 0, False: 98]
  ------------------
  887|     98|        !check_mod_inverse(&dmq1_ok, key->e, key->dmq1, &qm1, qm1_bits, ctx) ||
  ------------------
  |  Branch (887:9): [True: 0, False: 98]
  ------------------
  888|       |        // |p| is odd, so |pm1| and |p| have the same bit width. If they didn't,
  889|       |        // we only need a lower bound anyway.
  890|     98|        !check_mod_inverse(&iqmp_ok, key->q, key->iqmp, key->p, pm1_bits,
  ------------------
  |  Branch (890:9): [True: 0, False: 98]
  ------------------
  891|     98|                           ctx)) {
  892|      0|      OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  893|      0|      goto out;
  894|      0|    }
  895|       |
  896|     98|    if (!dmp1_ok || !dmq1_ok || !iqmp_ok) {
  ------------------
  |  Branch (896:9): [True: 95, False: 3]
  |  Branch (896:21): [True: 1, False: 2]
  |  Branch (896:33): [True: 1, False: 1]
  ------------------
  897|     97|      OPENSSL_PUT_ERROR(RSA, RSA_R_CRT_VALUES_INCORRECT);
  ------------------
  |  |  441|     97|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  898|     97|      goto out;
  899|     97|    }
  900|     98|  }
  901|       |
  902|      1|  ok = 1;
  903|       |
  904|    310|out:
  905|    310|  BN_free(&tmp);
  906|    310|  BN_free(&de);
  907|    310|  BN_free(&pm1);
  908|    310|  BN_free(&qm1);
  909|    310|  BN_free(&dmp1);
  910|    310|  BN_free(&dmq1);
  911|    310|  BN_CTX_free(ctx);
  912|       |
  913|    310|  return ok;
  914|      1|}
bcm.c:check_mod_inverse:
  766|    294|                             BN_CTX *ctx) {
  767|    294|  if (BN_is_negative(ainv) || BN_cmp(ainv, m) >= 0) {
  ------------------
  |  Branch (767:7): [True: 0, False: 294]
  |  Branch (767:31): [True: 60, False: 234]
  ------------------
  768|     60|    *out_ok = 0;
  769|     60|    return 1;
  770|     60|  }
  771|       |
  772|       |  // Note |bn_mul_consttime| and |bn_div_consttime| do not scale linearly, but
  773|       |  // checking |ainv| is in range bounds the running time, assuming |m|'s bounds
  774|       |  // were checked by the caller.
  775|    234|  BN_CTX_start(ctx);
  776|    234|  BIGNUM *tmp = BN_CTX_get(ctx);
  777|    234|  int ret = tmp != NULL &&
  ------------------
  |  Branch (777:13): [True: 234, False: 0]
  ------------------
  778|    234|            bn_mul_consttime(tmp, a, ainv, ctx) &&
  ------------------
  |  Branch (778:13): [True: 234, False: 0]
  ------------------
  779|    234|            bn_div_consttime(NULL, tmp, tmp, m, m_min_bits, ctx);
  ------------------
  |  Branch (779:13): [True: 234, False: 0]
  ------------------
  780|    234|  if (ret) {
  ------------------
  |  Branch (780:7): [True: 234, False: 0]
  ------------------
  781|    234|    *out_ok = BN_is_one(tmp);
  782|    234|  }
  783|    234|  BN_CTX_end(ctx);
  784|    234|  return ret;
  785|    294|}

rsa_check_public_key:
   76|    712|int rsa_check_public_key(const RSA *rsa) {
   77|    712|  if (rsa->n == NULL) {
  ------------------
  |  Branch (77:7): [True: 0, False: 712]
  ------------------
   78|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   79|      0|    return 0;
   80|      0|  }
   81|       |
   82|       |  // TODO(davidben): 16384-bit RSA is huge. Can we bring this down to a limit of
   83|       |  // 8192-bit?
   84|    712|  unsigned n_bits = BN_num_bits(rsa->n);
   85|    712|  if (n_bits > 16 * 1024) {
  ------------------
  |  Branch (85:7): [True: 1, False: 711]
  ------------------
   86|      1|    OPENSSL_PUT_ERROR(RSA, RSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|      1|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   87|      1|    return 0;
   88|      1|  }
   89|       |
   90|       |  // TODO(crbug.com/boringssl/607): Raise this limit. 512-bit RSA was factored
   91|       |  // in 1999.
   92|    711|  if (n_bits < 512) {
  ------------------
  |  Branch (92:7): [True: 233, False: 478]
  ------------------
   93|    233|    OPENSSL_PUT_ERROR(RSA, RSA_R_KEY_SIZE_TOO_SMALL);
  ------------------
  |  |  441|    233|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   94|    233|    return 0;
   95|    233|  }
   96|       |
   97|       |  // RSA moduli must be positive and odd. In addition to being necessary for RSA
   98|       |  // in general, we cannot setup Montgomery reduction with even moduli.
   99|    478|  if (!BN_is_odd(rsa->n) || BN_is_negative(rsa->n)) {
  ------------------
  |  Branch (99:7): [True: 9, False: 469]
  |  Branch (99:29): [True: 0, False: 469]
  ------------------
  100|      9|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|      9|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  101|      9|    return 0;
  102|      9|  }
  103|       |
  104|    469|  static const unsigned kMaxExponentBits = 33;
  105|    469|  if (rsa->e != NULL) {
  ------------------
  |  Branch (105:7): [True: 469, False: 0]
  ------------------
  106|       |    // Reject e = 1, negative e, and even e. e must be odd to be relatively
  107|       |    // prime with phi(n).
  108|    469|    unsigned e_bits = BN_num_bits(rsa->e);
  109|    469|    if (e_bits < 2 || BN_is_negative(rsa->e) || !BN_is_odd(rsa->e)) {
  ------------------
  |  Branch (109:9): [True: 7, False: 462]
  |  Branch (109:23): [True: 0, False: 462]
  |  Branch (109:49): [True: 78, False: 384]
  ------------------
  110|     85|      OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|     85|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|     85|      return 0;
  112|     85|    }
  113|    384|    if (rsa->flags & RSA_FLAG_LARGE_PUBLIC_EXPONENT) {
  ------------------
  |  |  683|    384|#define RSA_FLAG_LARGE_PUBLIC_EXPONENT 0x80
  ------------------
  |  Branch (113:9): [True: 0, False: 384]
  ------------------
  114|       |      // The caller has requested disabling DoS protections. Still, e must be
  115|       |      // less than n.
  116|      0|      if (BN_ucmp(rsa->n, rsa->e) <= 0) {
  ------------------
  |  Branch (116:11): [True: 0, False: 0]
  ------------------
  117|      0|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|        return 0;
  119|      0|      }
  120|    384|    } else {
  121|       |      // Mitigate DoS attacks by limiting the exponent size. 33 bits was chosen
  122|       |      // as the limit based on the recommendations in [1] and [2]. Windows
  123|       |      // CryptoAPI doesn't support values larger than 32 bits [3], so it is
  124|       |      // unlikely that exponents larger than 32 bits are being used for anything
  125|       |      // Windows commonly does.
  126|       |      //
  127|       |      // [1] https://www.imperialviolet.org/2012/03/16/rsae.html
  128|       |      // [2] https://www.imperialviolet.org/2012/03/17/rsados.html
  129|       |      // [3] https://msdn.microsoft.com/en-us/library/aa387685(VS.85).aspx
  130|    384|      if (e_bits > kMaxExponentBits) {
  ------------------
  |  Branch (130:11): [True: 70, False: 314]
  ------------------
  131|     70|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|     70|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|     70|        return 0;
  133|     70|      }
  134|       |
  135|       |      // The upper bound on |e_bits| and lower bound on |n_bits| imply e is
  136|       |      // bounded by n.
  137|    314|      assert(BN_ucmp(rsa->n, rsa->e) > 0);
  138|    314|    }
  139|    384|  } else if (!(rsa->flags & RSA_FLAG_NO_PUBLIC_EXPONENT)) {
  ------------------
  |  |  677|      0|#define RSA_FLAG_NO_PUBLIC_EXPONENT 0x40
  ------------------
  |  Branch (139:14): [True: 0, False: 0]
  ------------------
  140|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|       |
  144|    314|  return 1;
  145|    469|}
rsa_invalidate_key:
  289|  2.20k|void rsa_invalidate_key(RSA *rsa) {
  290|  2.20k|  rsa->private_key_frozen = 0;
  291|       |
  292|  2.20k|  BN_MONT_CTX_free(rsa->mont_n);
  293|  2.20k|  rsa->mont_n = NULL;
  294|  2.20k|  BN_MONT_CTX_free(rsa->mont_p);
  295|  2.20k|  rsa->mont_p = NULL;
  296|  2.20k|  BN_MONT_CTX_free(rsa->mont_q);
  297|  2.20k|  rsa->mont_q = NULL;
  298|       |
  299|  2.20k|  BN_free(rsa->d_fixed);
  300|  2.20k|  rsa->d_fixed = NULL;
  301|  2.20k|  BN_free(rsa->dmp1_fixed);
  302|  2.20k|  rsa->dmp1_fixed = NULL;
  303|  2.20k|  BN_free(rsa->dmq1_fixed);
  304|  2.20k|  rsa->dmq1_fixed = NULL;
  305|  2.20k|  BN_free(rsa->inv_small_mod_large_mont);
  306|  2.20k|  rsa->inv_small_mod_large_mont = NULL;
  307|       |
  308|  2.20k|  for (size_t i = 0; i < rsa->num_blindings; i++) {
  ------------------
  |  Branch (308:22): [True: 0, False: 2.20k]
  ------------------
  309|      0|    BN_BLINDING_free(rsa->blindings[i]);
  310|      0|  }
  311|  2.20k|  OPENSSL_free(rsa->blindings);
  312|  2.20k|  rsa->blindings = NULL;
  313|  2.20k|  rsa->num_blindings = 0;
  314|  2.20k|  OPENSSL_free(rsa->blindings_inuse);
  315|  2.20k|  rsa->blindings_inuse = NULL;
  316|  2.20k|  rsa->blinding_fork_generation = 0;
  317|  2.20k|}
bcm.c:RSA_default_method_do_init:
 1349|      1|DEFINE_METHOD_FUNCTION(RSA_METHOD, RSA_default_method) {
 1350|       |  // All of the methods are NULL to make it easier for the compiler/linker to
 1351|       |  // drop unused functions. The wrapper functions will select the appropriate
 1352|       |  // |rsa_default_*| implementation.
 1353|      1|  OPENSSL_memset(out, 0, sizeof(RSA_METHOD));
 1354|      1|  out->common.is_static = 1;
 1355|      1|}

bcm.c:FIPS_service_indicator_update_state:
   56|     35|OPENSSL_INLINE void FIPS_service_indicator_update_state(void) {}

SHA512_Init:
   94|     35|int SHA512_Init(SHA512_CTX *sha) {
   95|     35|  sha->h[0] = UINT64_C(0x6a09e667f3bcc908);
   96|     35|  sha->h[1] = UINT64_C(0xbb67ae8584caa73b);
   97|     35|  sha->h[2] = UINT64_C(0x3c6ef372fe94f82b);
   98|     35|  sha->h[3] = UINT64_C(0xa54ff53a5f1d36f1);
   99|     35|  sha->h[4] = UINT64_C(0x510e527fade682d1);
  100|     35|  sha->h[5] = UINT64_C(0x9b05688c2b3e6c1f);
  101|     35|  sha->h[6] = UINT64_C(0x1f83d9abfb41bd6b);
  102|     35|  sha->h[7] = UINT64_C(0x5be0cd19137e2179);
  103|       |
  104|     35|  sha->Nl = 0;
  105|     35|  sha->Nh = 0;
  106|     35|  sha->num = 0;
  107|     35|  sha->md_len = SHA512_DIGEST_LENGTH;
  ------------------
  |  |  230|     35|#define SHA512_DIGEST_LENGTH 64
  ------------------
  108|     35|  return 1;
  109|     35|}
SHA512:
  139|     35|                uint8_t out[SHA512_DIGEST_LENGTH]) {
  140|     35|  SHA512_CTX ctx;
  141|     35|  SHA512_Init(&ctx);
  142|     35|  SHA512_Update(&ctx, data, len);
  143|     35|  SHA512_Final(out, &ctx);
  144|     35|  OPENSSL_cleanse(&ctx, sizeof(ctx));
  145|     35|  return out;
  146|     35|}
SHA512_Update:
  190|     35|int SHA512_Update(SHA512_CTX *c, const void *in_data, size_t len) {
  191|     35|  uint64_t l;
  192|     35|  uint8_t *p = c->p;
  193|     35|  const uint8_t *data = in_data;
  194|       |
  195|     35|  if (len == 0) {
  ------------------
  |  Branch (195:7): [True: 0, False: 35]
  ------------------
  196|      0|    return 1;
  197|      0|  }
  198|       |
  199|     35|  l = (c->Nl + (((uint64_t)len) << 3)) & UINT64_C(0xffffffffffffffff);
  200|     35|  if (l < c->Nl) {
  ------------------
  |  Branch (200:7): [True: 0, False: 35]
  ------------------
  201|      0|    c->Nh++;
  202|      0|  }
  203|     35|  if (sizeof(len) >= 8) {
  ------------------
  |  Branch (203:7): [Folded - Ignored]
  ------------------
  204|     35|    c->Nh += (((uint64_t)len) >> 61);
  205|     35|  }
  206|     35|  c->Nl = l;
  207|       |
  208|     35|  if (c->num != 0) {
  ------------------
  |  Branch (208:7): [True: 0, False: 35]
  ------------------
  209|      0|    size_t n = sizeof(c->p) - c->num;
  210|       |
  211|      0|    if (len < n) {
  ------------------
  |  Branch (211:9): [True: 0, False: 0]
  ------------------
  212|      0|      OPENSSL_memcpy(p + c->num, data, len);
  213|      0|      c->num += (unsigned int)len;
  214|      0|      return 1;
  215|      0|    } else {
  216|      0|      OPENSSL_memcpy(p + c->num, data, n), c->num = 0;
  217|      0|      len -= n;
  218|      0|      data += n;
  219|      0|      sha512_block_data_order(c->h, p, 1);
  220|      0|    }
  221|      0|  }
  222|       |
  223|     35|  if (len >= sizeof(c->p)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 35]
  ------------------
  224|      0|    sha512_block_data_order(c->h, data, len / sizeof(c->p));
  225|      0|    data += len;
  226|      0|    len %= sizeof(c->p);
  227|      0|    data -= len;
  228|      0|  }
  229|       |
  230|     35|  if (len != 0) {
  ------------------
  |  Branch (230:7): [True: 35, False: 0]
  ------------------
  231|     35|    OPENSSL_memcpy(p, data, len);
  232|     35|    c->num = (int)len;
  233|     35|  }
  234|       |
  235|     35|  return 1;
  236|     35|}
SHA512_Final:
  238|     35|int SHA512_Final(uint8_t out[SHA512_DIGEST_LENGTH], SHA512_CTX *sha) {
  239|       |  // Ideally we would assert |sha->md_len| is |SHA512_DIGEST_LENGTH| to match
  240|       |  // the size hint, but calling code often pairs |SHA384_Init| with
  241|       |  // |SHA512_Final| and expects |sha->md_len| to carry the size over.
  242|       |  //
  243|       |  // TODO(davidben): Add an assert and fix code to match them up.
  244|     35|  return sha512_final_impl(out, sha->md_len, sha);
  245|     35|}
bcm.c:sha512_final_impl:
  247|     35|static int sha512_final_impl(uint8_t *out, size_t md_len, SHA512_CTX *sha) {
  248|     35|  uint8_t *p = sha->p;
  249|     35|  size_t n = sha->num;
  250|       |
  251|     35|  p[n] = 0x80;  // There always is a room for one
  252|     35|  n++;
  253|     35|  if (n > (sizeof(sha->p) - 16)) {
  ------------------
  |  Branch (253:7): [True: 0, False: 35]
  ------------------
  254|      0|    OPENSSL_memset(p + n, 0, sizeof(sha->p) - n);
  255|      0|    n = 0;
  256|      0|    sha512_block_data_order(sha->h, p, 1);
  257|      0|  }
  258|       |
  259|     35|  OPENSSL_memset(p + n, 0, sizeof(sha->p) - 16 - n);
  260|     35|  CRYPTO_store_u64_be(p + sizeof(sha->p) - 16, sha->Nh);
  261|     35|  CRYPTO_store_u64_be(p + sizeof(sha->p) - 8, sha->Nl);
  262|       |
  263|     35|  sha512_block_data_order(sha->h, p, 1);
  264|       |
  265|     35|  if (out == NULL) {
  ------------------
  |  Branch (265:7): [True: 0, False: 35]
  ------------------
  266|       |    // TODO(davidben): This NULL check is absent in other low-level hash 'final'
  267|       |    // functions and is one of the few places one can fail.
  268|      0|    return 0;
  269|      0|  }
  270|       |
  271|     35|  assert(md_len % 8 == 0);
  272|     35|  const size_t out_words = md_len / 8;
  273|    315|  for (size_t i = 0; i < out_words; i++) {
  ------------------
  |  Branch (273:22): [True: 280, False: 35]
  ------------------
  274|    280|    CRYPTO_store_u64_be(out, sha->h[i]);
  275|    280|    out += 8;
  276|    280|  }
  277|       |
  278|     35|  FIPS_service_indicator_update_state();
  279|     35|  return 1;
  280|     35|}

err.c:OPENSSL_memset:
 1055|   247k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   247k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 247k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   247k|  return memset(dst, c, n);
 1061|   247k|}
evp.c:OPENSSL_memset:
 1055|  5.82k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  5.82k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 5.82k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  5.82k|  return memset(dst, c, n);
 1061|  5.82k|}
evp_asn1.c:OPENSSL_memcmp:
 1031|  2.35k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  2.35k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 2.35k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  2.35k|  return memcmp(s1, s2, n);
 1037|  2.35k|}
p_x25519_asn1.c:OPENSSL_memcpy:
 1039|    118|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    118|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 118]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|    118|  return memcpy(dst, src, n);
 1045|    118|}
mem.c:OPENSSL_memset:
 1055|  97.2k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  97.2k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 97.2k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  97.2k|  return memset(dst, c, n);
 1061|  97.2k|}
refcount.c:CRYPTO_atomic_load_u32:
  626|  10.2k|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|  10.2k|  return atomic_load(val);
  628|  10.2k|}
refcount.c:CRYPTO_atomic_compare_exchange_weak_u32:
  631|  10.2k|    CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
  632|  10.2k|  return atomic_compare_exchange_weak(val, expected, desired);
  633|  10.2k|}
thread_pthread.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
bcm.c:OPENSSL_memmove:
 1047|  5.60k|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|  5.60k|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 5.60k]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|  5.60k|  return memmove(dst, src, n);
 1053|  5.60k|}
bcm.c:OPENSSL_memcpy:
 1039|   225k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   225k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 38.7k, False: 187k]
  ------------------
 1041|  38.7k|    return dst;
 1042|  38.7k|  }
 1043|       |
 1044|   187k|  return memcpy(dst, src, n);
 1045|   225k|}
bcm.c:constant_time_eq_int:
  462|   120k|static inline crypto_word_t constant_time_eq_int(int a, int b) {
  463|   120k|  return constant_time_eq_w((crypto_word_t)(a), (crypto_word_t)(b));
  464|   120k|}
bcm.c:constant_time_is_zero_w:
  427|  1.27M|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|  1.27M|  return constant_time_msb_w(~a & (a - 1));
  440|  1.27M|}
bcm.c:constant_time_msb_w:
  368|  1.34M|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|  1.34M|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|  1.34M|}
bcm.c:constant_time_eq_w:
  450|  1.12M|                                               crypto_word_t b) {
  451|  1.12M|  return constant_time_is_zero_w(a ^ b);
  452|  1.12M|}
bcm.c:constant_time_select_w:
  477|  63.4M|                                                   crypto_word_t b) {
  478|       |  // Clang recognizes this pattern as a select. While it usually transforms it
  479|       |  // to a cmov, it sometimes further transforms it into a branch, which we do
  480|       |  // not want.
  481|       |  //
  482|       |  // Hiding the value of the mask from the compiler evades this transformation.
  483|  63.4M|  mask = value_barrier_w(mask);
  484|  63.4M|  return (mask & a) | (~mask & b);
  485|  63.4M|}
bcm.c:value_barrier_w:
  340|  63.5M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  63.5M|#if defined(__GNUC__) || defined(__clang__)
  342|  63.5M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  63.5M|#endif
  344|  63.5M|  return a;
  345|  63.5M|}
bcm.c:OPENSSL_memset:
 1055|  3.36M|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  3.36M|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 1.10M, False: 2.26M]
  ------------------
 1057|  1.10M|    return dst;
 1058|  1.10M|  }
 1059|       |
 1060|  2.26M|  return memset(dst, c, n);
 1061|  3.36M|}
bcm.c:CRYPTO_load_word_be:
 1122|   113k|static inline crypto_word_t CRYPTO_load_word_be(const void *in) {
 1123|   113k|  crypto_word_t v;
 1124|   113k|  OPENSSL_memcpy(&v, in, sizeof(v));
 1125|   113k|#if defined(OPENSSL_64_BIT)
 1126|   113k|  static_assert(sizeof(v) == 8, "crypto_word_t has unexpected size");
 1127|   113k|  return CRYPTO_bswap8(v);
 1128|       |#else
 1129|       |  static_assert(sizeof(v) == 4, "crypto_word_t has unexpected size");
 1130|       |  return CRYPTO_bswap4(v);
 1131|       |#endif
 1132|   113k|}
bcm.c:CRYPTO_bswap8:
  949|   113k|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|   113k|  return __builtin_bswap64(x);
  951|   113k|}
bcm.c:constant_time_select_int:
  503|   146k|static inline int constant_time_select_int(crypto_word_t mask, int a, int b) {
  504|   146k|  return (int)(constant_time_select_w(mask, (crypto_word_t)(a),
  505|   146k|                                      (crypto_word_t)(b)));
  506|   146k|}
bcm.c:constant_time_declassify_int:
  572|  2.19k|static inline int constant_time_declassify_int(int v) {
  573|  2.19k|  static_assert(sizeof(uint32_t) == sizeof(int),
  574|  2.19k|                "int is not the same size as uint32_t");
  575|       |  // See comment above.
  576|  2.19k|  CONSTTIME_DECLASSIFY(&v, sizeof(v));
  577|  2.19k|  return value_barrier_u32(v);
  578|  2.19k|}
bcm.c:value_barrier_u32:
  348|  2.19k|static inline uint32_t value_barrier_u32(uint32_t a) {
  349|  2.19k|#if defined(__GNUC__) || defined(__clang__)
  350|  2.19k|  __asm__("" : "+r"(a) : /* no inputs */);
  351|  2.19k|#endif
  352|  2.19k|  return a;
  353|  2.19k|}
bcm.c:constant_time_lt_w:
  374|  71.0k|                                               crypto_word_t b) {
  375|       |  // Consider the two cases of the problem:
  376|       |  //   msb(a) == msb(b): a < b iff the MSB of a - b is set.
  377|       |  //   msb(a) != msb(b): a < b iff the MSB of b is set.
  378|       |  //
  379|       |  // If msb(a) == msb(b) then the following evaluates as:
  380|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  381|       |  //   msb(a^((a-b) ^ a))       ==   (because msb(a^b) == 0)
  382|       |  //   msb(a^a^(a-b))           ==   (rearranging)
  383|       |  //   msb(a-b)                      (because ∀x. x^x == 0)
  384|       |  //
  385|       |  // Else, if msb(a) != msb(b) then the following evaluates as:
  386|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  387|       |  //   msb(a^(𝟙 | ((a-b)^a)))   ==   (because msb(a^b) == 1 and 𝟙
  388|       |  //                                  represents a value s.t. msb(𝟙) = 1)
  389|       |  //   msb(a^𝟙)                 ==   (because ORing with 1 results in 1)
  390|       |  //   msb(b)
  391|       |  //
  392|       |  //
  393|       |  // Here is an SMT-LIB verification of this formula:
  394|       |  //
  395|       |  // (define-fun lt ((a (_ BitVec 32)) (b (_ BitVec 32))) (_ BitVec 32)
  396|       |  //   (bvxor a (bvor (bvxor a b) (bvxor (bvsub a b) a)))
  397|       |  // )
  398|       |  //
  399|       |  // (declare-fun a () (_ BitVec 32))
  400|       |  // (declare-fun b () (_ BitVec 32))
  401|       |  //
  402|       |  // (assert (not (= (= #x00000001 (bvlshr (lt a b) #x0000001f)) (bvult a b))))
  403|       |  // (check-sat)
  404|       |  // (get-model)
  405|  71.0k|  return constant_time_msb_w(a^((a^b)|((a-b)^a)));
  406|  71.0k|}
bcm.c:constant_time_declassify_w:
  556|  61.4k|static inline crypto_word_t constant_time_declassify_w(crypto_word_t v) {
  557|       |  // Return |v| through a value barrier to be safe. Valgrind-based constant-time
  558|       |  // validation is partly to check the compiler has not undone any constant-time
  559|       |  // work. Any place |BORINGSSL_CONSTANT_TIME_VALIDATION| influences
  560|       |  // optimizations, this validation is inaccurate.
  561|       |  //
  562|       |  // However, by sending pointers through valgrind, we likely inhibit escape
  563|       |  // analysis. On local variables, particularly booleans, we likely
  564|       |  // significantly impact optimizations.
  565|       |  //
  566|       |  // Thus, to be safe, stick a value barrier, in hopes of comparably inhibiting
  567|       |  // compiler analysis.
  568|  61.4k|  CONSTTIME_DECLASSIFY(&v, sizeof(v));
  569|  61.4k|  return value_barrier_w(v);
  570|  61.4k|}
bcm.c:CRYPTO_store_u64_be:
 1107|    350|static inline void CRYPTO_store_u64_be(void *out, uint64_t v) {
 1108|    350|  v = CRYPTO_bswap8(v);
 1109|    350|  OPENSSL_memcpy(out, &v, sizeof(v));
 1110|    350|}
curve25519.c:OPENSSL_memmove:
 1047|     35|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|     35|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 35]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|     35|  return memmove(dst, src, n);
 1053|     35|}
curve25519.c:CRYPTO_is_BMI1_capable:
 1352|    153|OPENSSL_INLINE int CRYPTO_is_BMI1_capable(void) {
 1353|       |#if defined(__BMI1__)
 1354|       |  return 1;
 1355|       |#else
 1356|    153|  return (OPENSSL_ia32cap_get()[2] & (1 << 3)) != 0;
 1357|    153|#endif
 1358|    153|}
curve25519.c:OPENSSL_ia32cap_get:
 1270|    459|OPENSSL_INLINE const uint32_t *OPENSSL_ia32cap_get(void) {
 1271|    459|  return OPENSSL_ia32cap_P;
 1272|    459|}
curve25519.c:CRYPTO_is_BMI2_capable:
 1368|    153|OPENSSL_INLINE int CRYPTO_is_BMI2_capable(void) {
 1369|       |#if defined(__BMI2__)
 1370|       |  return 1;
 1371|       |#else
 1372|    153|  return (OPENSSL_ia32cap_get()[2] & (1 << 8)) != 0;
 1373|    153|#endif
 1374|    153|}
curve25519.c:CRYPTO_is_ADX_capable:
 1376|    153|OPENSSL_INLINE int CRYPTO_is_ADX_capable(void) {
 1377|       |#if defined(__ADX__)
 1378|       |  return 1;
 1379|       |#else
 1380|    153|  return (OPENSSL_ia32cap_get()[2] & (1 << 19)) != 0;
 1381|    153|#endif
 1382|    153|}
curve25519.c:OPENSSL_memcpy:
 1039|    188|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    188|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 188]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|    188|  return memcpy(dst, src, n);
 1045|    188|}
curve25519_64_adx.c:OPENSSL_memcpy:
 1039|  9.94k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  9.94k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 9.94k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  9.94k|  return memcpy(dst, src, n);
 1045|  9.94k|}
curve25519_64_adx.c:constant_time_msb_w:
  368|   107k|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|   107k|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|   107k|}
curve25519_64_adx.c:constant_time_is_zero_w:
  427|  97.9k|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|  97.9k|  return constant_time_msb_w(~a & (a - 1));
  440|  97.9k|}
curve25519_64_adx.c:constant_time_conditional_memxor:
  527|  78.3k|                                                    const crypto_word_t mask) {
  528|  78.3k|  assert(!buffers_alias(dst, n, src, n));
  529|  78.3k|  uint8_t *out = (uint8_t *)dst;
  530|  78.3k|  const uint8_t *in = (const uint8_t *)src;
  531|  7.59M|  for (size_t i = 0; i < n; i++) {
  ------------------
  |  Branch (531:22): [True: 7.52M, False: 78.3k]
  ------------------
  532|  7.52M|    out[i] ^= value_barrier_w(mask) & in[i];
  533|  7.52M|  }
  534|  78.3k|}
curve25519_64_adx.c:buffers_alias:
  269|   107k|                                const void *b, size_t b_bytes) {
  270|       |  // Cast |a| and |b| to integers. In C, pointer comparisons between unrelated
  271|       |  // objects are undefined whereas pointer to integer conversions are merely
  272|       |  // implementation-defined. We assume the implementation defined it in a sane
  273|       |  // way.
  274|   107k|  uintptr_t a_u = (uintptr_t)a;
  275|   107k|  uintptr_t b_u = (uintptr_t)b;
  276|   107k|  return a_u + a_bytes > b_u && b_u + b_bytes > a_u;
  ------------------
  |  Branch (276:10): [True: 78.3k, False: 29.3k]
  |  Branch (276:33): [True: 0, False: 78.3k]
  ------------------
  277|   107k|}
curve25519_64_adx.c:value_barrier_w:
  340|  8.46M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  8.46M|#if defined(__GNUC__) || defined(__clang__)
  342|  8.46M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  8.46M|#endif
  344|  8.46M|  return a;
  345|  8.46M|}
curve25519_64_adx.c:constant_time_eq_w:
  450|  78.3k|                                               crypto_word_t b) {
  451|  78.3k|  return constant_time_is_zero_w(a ^ b);
  452|  78.3k|}
curve25519_64_adx.c:constant_time_conditional_memcpy:
  513|  29.3k|                                                    const crypto_word_t mask) {
  514|  29.3k|  assert(!buffers_alias(dst, n, src, n));
  515|  29.3k|  uint8_t *out = (uint8_t *)dst;
  516|  29.3k|  const uint8_t *in = (const uint8_t *)src;
  517|   969k|  for (size_t i = 0; i < n; i++) {
  ------------------
  |  Branch (517:22): [True: 940k, False: 29.3k]
  ------------------
  518|   940k|    out[i] = constant_time_select_8(mask, in[i], out[i]);
  519|   940k|  }
  520|  29.3k|}
curve25519_64_adx.c:constant_time_select_8:
  490|   940k|                                             uint8_t b) {
  491|       |  // |mask| is a word instead of |uint8_t| to avoid materializing 0x000..0MM
  492|       |  // Making both |mask| and its value barrier |uint8_t| would allow the compiler
  493|       |  // to materialize 0x????..?MM instead, but only clang is that clever.
  494|       |  // However, vectorization of bitwise operations seems to work better on
  495|       |  // |uint8_t| than a mix of |uint64_t| and |uint8_t|, so |m| is cast to
  496|       |  // |uint8_t| after the value barrier but before the bitwise operations.
  497|   940k|  uint8_t m = value_barrier_w(mask);
  498|   940k|  return (m & a) | (~m & b);
  499|   940k|}
dsa.c:OPENSSL_memset:
 1055|    991|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|    991|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 991]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|    991|  return memset(dst, c, n);
 1061|    991|}
ec_asn1.c:OPENSSL_memcmp:
 1031|  3.65k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  3.65k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 3.65k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  3.65k|  return memcmp(s1, s2, n);
 1037|  3.65k|}
stack.c:OPENSSL_memset:
 1055|  2.69k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  2.69k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 2.69k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  2.69k|  return memset(dst, c, n);
 1061|  2.69k|}

OPENSSL_malloc:
  228|  96.6k|void *OPENSSL_malloc(size_t size) {
  229|  96.6k|  if (should_fail_allocation()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 96.6k]
  ------------------
  230|      0|    goto err;
  231|      0|  }
  232|       |
  233|  96.6k|  if (OPENSSL_memory_alloc != NULL) {
  ------------------
  |  Branch (233:7): [True: 0, False: 96.6k]
  ------------------
  234|      0|    assert(OPENSSL_memory_free != NULL);
  235|      0|    assert(OPENSSL_memory_get_size != NULL);
  236|      0|    void *ptr = OPENSSL_memory_alloc(size);
  237|      0|    if (ptr == NULL && size != 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  |  Branch (237:24): [True: 0, False: 0]
  ------------------
  238|      0|      goto err;
  239|      0|    }
  240|      0|    return ptr;
  241|      0|  }
  242|       |
  243|  96.6k|  if (size + OPENSSL_MALLOC_PREFIX < size) {
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  |  Branch (243:7): [True: 0, False: 96.6k]
  ------------------
  244|       |    // |OPENSSL_malloc| is a central function in BoringSSL thus a reference to
  245|       |    // |kBoringSSLBinaryTag| is created here so that the tag isn't discarded by
  246|       |    // the linker. The following is sufficient to stop GCC, Clang, and MSVC
  247|       |    // optimising away the reference at the time of writing. Since this
  248|       |    // probably results in an actual memory reference, it is put in this very
  249|       |    // rare code path.
  250|      0|    uint8_t unused = *(volatile uint8_t *)kBoringSSLBinaryTag;
  251|      0|    (void) unused;
  252|      0|    goto err;
  253|      0|  }
  254|       |
  255|  96.6k|  void *ptr = malloc(size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  256|  96.6k|  if (ptr == NULL) {
  ------------------
  |  Branch (256:7): [True: 0, False: 96.6k]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|  96.6k|  *(size_t *)ptr = size;
  261|       |
  262|  96.6k|  __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  263|  96.6k|  return ((uint8_t *)ptr) + OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  264|       |
  265|      0| err:
  266|       |  // This only works because ERR does not call OPENSSL_malloc.
  267|      0|  OPENSSL_PUT_ERROR(CRYPTO, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|  return NULL;
  269|  96.6k|}
OPENSSL_free:
  271|   137k|void OPENSSL_free(void *orig_ptr) {
  272|   137k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (272:7): [True: 41.0k, False: 96.6k]
  ------------------
  273|  41.0k|    return;
  274|  41.0k|  }
  275|       |
  276|  96.6k|  if (OPENSSL_memory_free != NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 96.6k]
  ------------------
  277|      0|    OPENSSL_memory_free(orig_ptr);
  278|      0|    return;
  279|      0|  }
  280|       |
  281|  96.6k|  void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  282|  96.6k|  __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  283|       |
  284|  96.6k|  size_t size = *(size_t *)ptr;
  285|  96.6k|  OPENSSL_cleanse(ptr, size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  96.6k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  286|       |
  287|       |// ASan knows to intercept malloc and free, but not sdallocx.
  288|       |#if defined(OPENSSL_ASAN)
  289|       |  (void)sdallocx;
  290|       |  free(ptr);
  291|       |#else
  292|  96.6k|  if (sdallocx) {
  ------------------
  |  Branch (292:7): [True: 0, False: 96.6k]
  ------------------
  293|      0|    sdallocx(ptr, size + OPENSSL_MALLOC_PREFIX, 0 /* flags */);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  294|  96.6k|  } else {
  295|  96.6k|    free(ptr);
  296|  96.6k|  }
  297|  96.6k|#endif
  298|  96.6k|}
OPENSSL_realloc:
  300|  3.52k|void *OPENSSL_realloc(void *orig_ptr, size_t new_size) {
  301|  3.52k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (301:7): [True: 1.41k, False: 2.11k]
  ------------------
  302|  1.41k|    return OPENSSL_malloc(new_size);
  303|  1.41k|  }
  304|       |
  305|  2.11k|  size_t old_size;
  306|  2.11k|  if (OPENSSL_memory_get_size != NULL) {
  ------------------
  |  Branch (306:7): [True: 0, False: 2.11k]
  ------------------
  307|      0|    old_size = OPENSSL_memory_get_size(orig_ptr);
  308|  2.11k|  } else {
  309|  2.11k|    void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  2.11k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  310|  2.11k|    __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  2.11k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  311|  2.11k|    old_size = *(size_t *)ptr;
  312|  2.11k|    __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  2.11k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  313|  2.11k|  }
  314|       |
  315|  2.11k|  void *ret = OPENSSL_malloc(new_size);
  316|  2.11k|  if (ret == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 2.11k]
  ------------------
  317|      0|    return NULL;
  318|      0|  }
  319|       |
  320|  2.11k|  size_t to_copy = new_size;
  321|  2.11k|  if (old_size < to_copy) {
  ------------------
  |  Branch (321:7): [True: 2.11k, False: 0]
  ------------------
  322|  2.11k|    to_copy = old_size;
  323|  2.11k|  }
  324|       |
  325|  2.11k|  memcpy(ret, orig_ptr, to_copy);
  326|  2.11k|  OPENSSL_free(orig_ptr);
  327|       |
  328|  2.11k|  return ret;
  329|  2.11k|}
OPENSSL_cleanse:
  331|  97.2k|void OPENSSL_cleanse(void *ptr, size_t len) {
  332|       |#if defined(OPENSSL_WINDOWS)
  333|       |  SecureZeroMemory(ptr, len);
  334|       |#else
  335|  97.2k|  OPENSSL_memset(ptr, 0, len);
  336|       |
  337|  97.2k|#if !defined(OPENSSL_NO_ASM)
  338|       |  /* As best as we can tell, this is sufficient to break any optimisations that
  339|       |     might try to eliminate "superfluous" memsets. If there's an easy way to
  340|       |     detect memset_s, it would be better to use that. */
  341|  97.2k|  __asm__ __volatile__("" : : "r"(ptr) : "memory");
  342|  97.2k|#endif
  343|  97.2k|#endif  // !OPENSSL_NO_ASM
  344|  97.2k|}
CRYPTO_memcmp:
  360|    877|int CRYPTO_memcmp(const void *in_a, const void *in_b, size_t len) {
  361|    877|  const uint8_t *a = in_a;
  362|    877|  const uint8_t *b = in_b;
  363|    877|  uint8_t x = 0;
  364|       |
  365|  29.4k|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (365:22): [True: 28.5k, False: 877]
  ------------------
  366|  28.5k|    x |= a[i] ^ b[i];
  367|  28.5k|  }
  368|       |
  369|    877|  return x;
  370|    877|}
mem.c:should_fail_allocation:
  225|  96.6k|static int should_fail_allocation(void) { return 0; }
mem.c:__asan_poison_memory_region:
   90|  98.8k|static void __asan_poison_memory_region(const void *addr, size_t size) {}
mem.c:__asan_unpoison_memory_region:
   91|  98.7k|static void __asan_unpoison_memory_region(const void *addr, size_t size) {}

CRYPTO_refcount_inc:
   31|      4|void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
   32|      4|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   33|      4|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   34|       |
   35|      4|  while (expected != CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|      4|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (35:10): [True: 4, False: 0]
  ------------------
   36|      4|    uint32_t new_value = expected + 1;
   37|      4|    if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected, new_value)) {
  ------------------
  |  Branch (37:9): [True: 4, False: 0]
  ------------------
   38|      4|      break;
   39|      4|    }
   40|      4|  }
   41|      4|}
CRYPTO_refcount_dec_and_test_zero:
   43|  10.2k|int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
   44|  10.2k|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   45|  10.2k|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   46|       |
   47|  10.2k|  for (;;) {
   48|  10.2k|    if (expected == 0) {
  ------------------
  |  Branch (48:9): [True: 0, False: 10.2k]
  ------------------
   49|      0|      abort();
   50|  10.2k|    } else if (expected == CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|  10.2k|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (50:16): [True: 0, False: 10.2k]
  ------------------
   51|      0|      return 0;
   52|  10.2k|    } else {
   53|  10.2k|      const uint32_t new_value = expected - 1;
   54|  10.2k|      if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected,
  ------------------
  |  Branch (54:11): [True: 10.2k, False: 0]
  ------------------
   55|  10.2k|                                                  new_value)) {
   56|  10.2k|        return new_value == 0;
   57|  10.2k|      }
   58|  10.2k|    }
   59|  10.2k|  }
   60|  10.2k|}

RSA_parse_private_key:
  156|  2.20k|RSA *RSA_parse_private_key(CBS *cbs) {
  157|  2.20k|  RSA *ret = RSA_new();
  158|  2.20k|  if (ret == NULL) {
  ------------------
  |  Branch (158:7): [True: 0, False: 2.20k]
  ------------------
  159|      0|    return NULL;
  160|      0|  }
  161|       |
  162|  2.20k|  CBS child;
  163|  2.20k|  uint64_t version;
  164|  2.20k|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  2.20k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  2.20k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  2.20k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (164:7): [True: 527, False: 1.67k]
  ------------------
  165|  2.20k|      !CBS_get_asn1_uint64(&child, &version)) {
  ------------------
  |  Branch (165:7): [True: 210, False: 1.46k]
  ------------------
  166|    737|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|    737|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  167|    737|    goto err;
  168|    737|  }
  169|       |
  170|  1.46k|  if (version != kVersionTwoPrime) {
  ------------------
  |  Branch (170:7): [True: 141, False: 1.32k]
  ------------------
  171|    141|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_VERSION);
  ------------------
  |  |  441|    141|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  172|    141|    goto err;
  173|    141|  }
  174|       |
  175|  1.32k|  if (!parse_integer(&child, &ret->n) ||
  ------------------
  |  Branch (175:7): [True: 495, False: 828]
  ------------------
  176|  1.32k|      !parse_integer(&child, &ret->e) ||
  ------------------
  |  Branch (176:7): [True: 53, False: 775]
  ------------------
  177|  1.32k|      !parse_integer(&child, &ret->d) ||
  ------------------
  |  Branch (177:7): [True: 18, False: 757]
  ------------------
  178|  1.32k|      !parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (178:7): [True: 9, False: 748]
  ------------------
  179|  1.32k|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (179:7): [True: 7, False: 741]
  ------------------
  180|  1.32k|      !parse_integer(&child, &ret->dmp1) ||
  ------------------
  |  Branch (180:7): [True: 6, False: 735]
  ------------------
  181|  1.32k|      !parse_integer(&child, &ret->dmq1) ||
  ------------------
  |  Branch (181:7): [True: 4, False: 731]
  ------------------
  182|  1.32k|      !parse_integer(&child, &ret->iqmp)) {
  ------------------
  |  Branch (182:7): [True: 4, False: 727]
  ------------------
  183|    596|    goto err;
  184|    596|  }
  185|       |
  186|    727|  if (CBS_len(&child) != 0) {
  ------------------
  |  Branch (186:7): [True: 15, False: 712]
  ------------------
  187|     15|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|     15|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  188|     15|    goto err;
  189|     15|  }
  190|       |
  191|    712|  if (!RSA_check_key(ret)) {
  ------------------
  |  Branch (191:7): [True: 711, False: 1]
  ------------------
  192|    711|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|    711|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  193|    711|    goto err;
  194|    711|  }
  195|       |
  196|      1|  return ret;
  197|       |
  198|  2.20k|err:
  199|  2.20k|  RSA_free(ret);
  200|  2.20k|  return NULL;
  201|    712|}
rsa_asn1.c:parse_integer:
   72|  6.63k|static int parse_integer(CBS *cbs, BIGNUM **out) {
   73|  6.63k|  assert(*out == NULL);
   74|  6.63k|  *out = BN_new();
   75|  6.63k|  if (*out == NULL) {
  ------------------
  |  Branch (75:7): [True: 0, False: 6.63k]
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|  6.63k|  return BN_parse_asn1_unsigned(cbs, *out);
   79|  6.63k|}

sk_new:
   72|  1.34k|_STACK *sk_new(OPENSSL_sk_cmp_func comp) {
   73|  1.34k|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
   74|  1.34k|  if (ret == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 1.34k]
  ------------------
   75|      0|    return NULL;
   76|      0|  }
   77|  1.34k|  OPENSSL_memset(ret, 0, sizeof(_STACK));
   78|       |
   79|  1.34k|  ret->data = OPENSSL_malloc(sizeof(void *) * kMinSize);
   80|  1.34k|  if (ret->data == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 1.34k]
  ------------------
   81|      0|    goto err;
   82|      0|  }
   83|       |
   84|  1.34k|  OPENSSL_memset(ret->data, 0, sizeof(void *) * kMinSize);
   85|       |
   86|  1.34k|  ret->comp = comp;
   87|  1.34k|  ret->num_alloc = kMinSize;
   88|       |
   89|  1.34k|  return ret;
   90|       |
   91|      0|err:
   92|      0|  OPENSSL_free(ret);
   93|      0|  return NULL;
   94|  1.34k|}
sk_new_null:
   96|  1.34k|_STACK *sk_new_null(void) { return sk_new(NULL); }
sk_num:
   98|  7.24M|size_t sk_num(const _STACK *sk) {
   99|  7.24M|  if (sk == NULL) {
  ------------------
  |  Branch (99:7): [True: 0, False: 7.24M]
  ------------------
  100|      0|    return 0;
  101|      0|  }
  102|  7.24M|  return sk->num;
  103|  7.24M|}
sk_value:
  114|  7.24M|void *sk_value(const _STACK *sk, size_t i) {
  115|  7.24M|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (115:7): [True: 0, False: 7.24M]
  |  Branch (115:14): [True: 0, False: 7.24M]
  ------------------
  116|      0|    return NULL;
  117|      0|  }
  118|  7.24M|  return sk->data[i];
  119|  7.24M|}
sk_free:
  128|  1.34k|void sk_free(_STACK *sk) {
  129|  1.34k|  if (sk == NULL) {
  ------------------
  |  Branch (129:7): [True: 0, False: 1.34k]
  ------------------
  130|      0|    return;
  131|      0|  }
  132|  1.34k|  OPENSSL_free(sk->data);
  133|  1.34k|  OPENSSL_free(sk);
  134|  1.34k|}
sk_pop_free_ex:
  137|  1.42k|                    OPENSSL_sk_free_func free_func) {
  138|  1.42k|  if (sk == NULL) {
  ------------------
  |  Branch (138:7): [True: 72, False: 1.34k]
  ------------------
  139|     72|    return;
  140|     72|  }
  141|       |
  142|  18.8k|  for (size_t i = 0; i < sk->num; i++) {
  ------------------
  |  Branch (142:22): [True: 17.5k, False: 1.34k]
  ------------------
  143|  17.5k|    if (sk->data[i] != NULL) {
  ------------------
  |  Branch (143:9): [True: 17.5k, False: 0]
  ------------------
  144|  17.5k|      call_free_func(free_func, sk->data[i]);
  145|  17.5k|    }
  146|  17.5k|  }
  147|  1.34k|  sk_free(sk);
  148|  1.34k|}
sk_insert:
  161|  17.5k|size_t sk_insert(_STACK *sk, void *p, size_t where) {
  162|  17.5k|  if (sk == NULL) {
  ------------------
  |  Branch (162:7): [True: 0, False: 17.5k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|  17.5k|  if (sk->num >= INT_MAX) {
  ------------------
  |  Branch (166:7): [True: 0, False: 17.5k]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|  17.5k|  if (sk->num_alloc <= sk->num + 1) {
  ------------------
  |  Branch (171:7): [True: 2.11k, False: 15.4k]
  ------------------
  172|       |    // Attempt to double the size of the array.
  173|  2.11k|    size_t new_alloc = sk->num_alloc << 1;
  174|  2.11k|    size_t alloc_size = new_alloc * sizeof(void *);
  175|  2.11k|    void **data;
  176|       |
  177|       |    // If the doubling overflowed, try to increment.
  178|  2.11k|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (178:9): [True: 0, False: 2.11k]
  |  Branch (178:38): [True: 0, False: 2.11k]
  ------------------
  179|      0|      new_alloc = sk->num_alloc + 1;
  180|      0|      alloc_size = new_alloc * sizeof(void *);
  181|      0|    }
  182|       |
  183|       |    // If the increment also overflowed, fail.
  184|  2.11k|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 2.11k]
  |  Branch (184:38): [True: 0, False: 2.11k]
  ------------------
  185|      0|      return 0;
  186|      0|    }
  187|       |
  188|  2.11k|    data = OPENSSL_realloc(sk->data, alloc_size);
  189|  2.11k|    if (data == NULL) {
  ------------------
  |  Branch (189:9): [True: 0, False: 2.11k]
  ------------------
  190|      0|      return 0;
  191|      0|    }
  192|       |
  193|  2.11k|    sk->data = data;
  194|  2.11k|    sk->num_alloc = new_alloc;
  195|  2.11k|  }
  196|       |
  197|  17.5k|  if (where >= sk->num) {
  ------------------
  |  Branch (197:7): [True: 17.5k, False: 0]
  ------------------
  198|  17.5k|    sk->data[sk->num] = p;
  199|  17.5k|  } else {
  200|      0|    OPENSSL_memmove(&sk->data[where + 1], &sk->data[where],
  201|      0|                    sizeof(void *) * (sk->num - where));
  202|      0|    sk->data[where] = p;
  203|      0|  }
  204|       |
  205|  17.5k|  sk->num++;
  206|  17.5k|  sk->sorted = 0;
  207|       |
  208|  17.5k|  return sk->num;
  209|  17.5k|}
sk_push:
  340|  17.5k|size_t sk_push(_STACK *sk, void *p) { return (sk_insert(sk, p, sk->num)); }

CRYPTO_MUTEX_init:
   31|  3.19k|void CRYPTO_MUTEX_init(CRYPTO_MUTEX *lock) {
   32|  3.19k|  if (pthread_rwlock_init((pthread_rwlock_t *) lock, NULL) != 0) {
  ------------------
  |  Branch (32:7): [True: 0, False: 3.19k]
  ------------------
   33|      0|    abort();
   34|      0|  }
   35|  3.19k|}
CRYPTO_MUTEX_cleanup:
   61|  3.19k|void CRYPTO_MUTEX_cleanup(CRYPTO_MUTEX *lock) {
   62|  3.19k|  pthread_rwlock_destroy((pthread_rwlock_t *) lock);
   63|  3.19k|}
CRYPTO_STATIC_MUTEX_lock_read:
   65|  1.32k|void CRYPTO_STATIC_MUTEX_lock_read(struct CRYPTO_STATIC_MUTEX *lock) {
   66|  1.32k|  if (pthread_rwlock_rdlock(&lock->lock) != 0) {
  ------------------
  |  Branch (66:7): [True: 0, False: 1.32k]
  ------------------
   67|      0|    abort();
   68|      0|  }
   69|  1.32k|}
CRYPTO_STATIC_MUTEX_lock_write:
   71|      4|void CRYPTO_STATIC_MUTEX_lock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   72|      4|  if (pthread_rwlock_wrlock(&lock->lock) != 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 4]
  ------------------
   73|      0|    abort();
   74|      0|  }
   75|      4|}
CRYPTO_STATIC_MUTEX_unlock_read:
   77|  1.32k|void CRYPTO_STATIC_MUTEX_unlock_read(struct CRYPTO_STATIC_MUTEX *lock) {
   78|  1.32k|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (78:7): [True: 0, False: 1.32k]
  ------------------
   79|      0|    abort();
   80|      0|  }
   81|  1.32k|}
CRYPTO_STATIC_MUTEX_unlock_write:
   83|      4|void CRYPTO_STATIC_MUTEX_unlock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   84|      4|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (84:7): [True: 0, False: 4]
  ------------------
   85|      0|    abort();
   86|      0|  }
   87|      4|}
CRYPTO_once:
   89|  35.2k|void CRYPTO_once(CRYPTO_once_t *once, void (*init)(void)) {
   90|  35.2k|  if (pthread_once(once, init) != 0) {
  ------------------
  |  Branch (90:7): [True: 0, False: 35.2k]
  ------------------
   91|      0|    abort();
   92|      0|  }
   93|  35.2k|}
CRYPTO_get_thread_local:
  132|  29.7k|void *CRYPTO_get_thread_local(thread_local_data_t index) {
  133|  29.7k|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  134|  29.7k|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (134:7): [True: 0, False: 29.7k]
  ------------------
  135|      0|    return NULL;
  136|      0|  }
  137|       |
  138|  29.7k|  void **pointers = pthread_getspecific(g_thread_local_key);
  139|  29.7k|  if (pointers == NULL) {
  ------------------
  |  Branch (139:7): [True: 1, False: 29.7k]
  ------------------
  140|      1|    return NULL;
  141|      1|  }
  142|  29.7k|  return pointers[index];
  143|  29.7k|}
CRYPTO_set_thread_local:
  146|      1|                            thread_local_destructor_t destructor) {
  147|      1|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  148|      1|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (148:7): [True: 0, False: 1]
  ------------------
  149|      0|    destructor(value);
  150|      0|    return 0;
  151|      0|  }
  152|       |
  153|      1|  void **pointers = pthread_getspecific(g_thread_local_key);
  154|      1|  if (pointers == NULL) {
  ------------------
  |  Branch (154:7): [True: 1, False: 0]
  ------------------
  155|      1|    pointers = malloc(sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  156|      1|    if (pointers == NULL) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1]
  ------------------
  157|      0|      destructor(value);
  158|      0|      return 0;
  159|      0|    }
  160|      1|    OPENSSL_memset(pointers, 0, sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  161|      1|    if (pthread_setspecific(g_thread_local_key, pointers) != 0) {
  ------------------
  |  Branch (161:9): [True: 0, False: 1]
  ------------------
  162|      0|      free(pointers);
  163|      0|      destructor(value);
  164|      0|      return 0;
  165|      0|    }
  166|      1|  }
  167|       |
  168|      1|  if (pthread_mutex_lock(&g_destructors_lock) != 0) {
  ------------------
  |  Branch (168:7): [True: 0, False: 1]
  ------------------
  169|      0|    destructor(value);
  170|      0|    return 0;
  171|      0|  }
  172|      1|  g_destructors[index] = destructor;
  173|      1|  pthread_mutex_unlock(&g_destructors_lock);
  174|       |
  175|      1|  pointers[index] = value;
  176|      1|  return 1;
  177|      1|}
thread_pthread.c:thread_local_init:
  127|      1|static void thread_local_init(void) {
  128|      1|  g_thread_local_key_created =
  129|      1|      pthread_key_create(&g_thread_local_key, thread_local_destructor) == 0;
  130|      1|}

LLVMFuzzerTestOneInput:
   18|  4.99k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) {
   19|  4.99k|  EVP_PKEY_free(d2i_AutoPrivateKey(NULL, &buf, len));
   20|  4.99k|  ERR_clear_error();
   21|  4.99k|  return 0;
   22|  4.99k|}

bcm.c:ERR_GET_LIB:
  166|    192|OPENSSL_INLINE int ERR_GET_LIB(uint32_t packed_error) {
  167|    192|  return (int)((packed_error >> 24) & 0xff);
  168|    192|}
bcm.c:ERR_GET_REASON:
  173|    192|OPENSSL_INLINE int ERR_GET_REASON(uint32_t packed_error) {
  174|    192|  return (int)(packed_error & 0xfff);
  175|    192|}

bcm.c:sk_BIGNUM_pop_free:
  447|  1.42k|                                           sk_##name##_free_func free_func) { \
  448|  1.42k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  1.42k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  1.42k|  }                                                                           \
bcm.c:sk_BIGNUM_call_free_func:
  391|  17.5k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  17.5k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  17.5k|  }                                                                           \
bcm.c:sk_BIGNUM_new_null:
  420|  1.34k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  1.34k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  1.34k|  }                                                                           \
bcm.c:sk_BIGNUM_num:
  424|  7.24M|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  7.24M|    return sk_num((const _STACK *)sk);                                        \
  426|  7.24M|  }                                                                           \
bcm.c:sk_BIGNUM_push:
  483|  17.5k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  17.5k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  17.5k|  }                                                                           \
bcm.c:sk_BIGNUM_value:
  433|  7.24M|                                           size_t i) {                        \
  434|  7.24M|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  7.24M|  }                                                                           \

curve25519.c:fiat_25519_carry_mul:
  133|  1.87k|static FIAT_25519_FIAT_INLINE void fiat_25519_carry_mul(fiat_25519_tight_field_element out1, const fiat_25519_loose_field_element arg1, const fiat_25519_loose_field_element arg2) {
  134|  1.87k|  fiat_25519_uint128 x1;
  135|  1.87k|  fiat_25519_uint128 x2;
  136|  1.87k|  fiat_25519_uint128 x3;
  137|  1.87k|  fiat_25519_uint128 x4;
  138|  1.87k|  fiat_25519_uint128 x5;
  139|  1.87k|  fiat_25519_uint128 x6;
  140|  1.87k|  fiat_25519_uint128 x7;
  141|  1.87k|  fiat_25519_uint128 x8;
  142|  1.87k|  fiat_25519_uint128 x9;
  143|  1.87k|  fiat_25519_uint128 x10;
  144|  1.87k|  fiat_25519_uint128 x11;
  145|  1.87k|  fiat_25519_uint128 x12;
  146|  1.87k|  fiat_25519_uint128 x13;
  147|  1.87k|  fiat_25519_uint128 x14;
  148|  1.87k|  fiat_25519_uint128 x15;
  149|  1.87k|  fiat_25519_uint128 x16;
  150|  1.87k|  fiat_25519_uint128 x17;
  151|  1.87k|  fiat_25519_uint128 x18;
  152|  1.87k|  fiat_25519_uint128 x19;
  153|  1.87k|  fiat_25519_uint128 x20;
  154|  1.87k|  fiat_25519_uint128 x21;
  155|  1.87k|  fiat_25519_uint128 x22;
  156|  1.87k|  fiat_25519_uint128 x23;
  157|  1.87k|  fiat_25519_uint128 x24;
  158|  1.87k|  fiat_25519_uint128 x25;
  159|  1.87k|  fiat_25519_uint128 x26;
  160|  1.87k|  uint64_t x27;
  161|  1.87k|  uint64_t x28;
  162|  1.87k|  fiat_25519_uint128 x29;
  163|  1.87k|  fiat_25519_uint128 x30;
  164|  1.87k|  fiat_25519_uint128 x31;
  165|  1.87k|  fiat_25519_uint128 x32;
  166|  1.87k|  fiat_25519_uint128 x33;
  167|  1.87k|  uint64_t x34;
  168|  1.87k|  uint64_t x35;
  169|  1.87k|  fiat_25519_uint128 x36;
  170|  1.87k|  uint64_t x37;
  171|  1.87k|  uint64_t x38;
  172|  1.87k|  fiat_25519_uint128 x39;
  173|  1.87k|  uint64_t x40;
  174|  1.87k|  uint64_t x41;
  175|  1.87k|  fiat_25519_uint128 x42;
  176|  1.87k|  uint64_t x43;
  177|  1.87k|  uint64_t x44;
  178|  1.87k|  uint64_t x45;
  179|  1.87k|  uint64_t x46;
  180|  1.87k|  uint64_t x47;
  181|  1.87k|  uint64_t x48;
  182|  1.87k|  uint64_t x49;
  183|  1.87k|  fiat_25519_uint1 x50;
  184|  1.87k|  uint64_t x51;
  185|  1.87k|  uint64_t x52;
  186|  1.87k|  x1 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[4]) * UINT8_C(0x13)));
  187|  1.87k|  x2 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[3]) * UINT8_C(0x13)));
  188|  1.87k|  x3 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[2]) * UINT8_C(0x13)));
  189|  1.87k|  x4 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[1]) * UINT8_C(0x13)));
  190|  1.87k|  x5 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[4]) * UINT8_C(0x13)));
  191|  1.87k|  x6 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[3]) * UINT8_C(0x13)));
  192|  1.87k|  x7 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[2]) * UINT8_C(0x13)));
  193|  1.87k|  x8 = ((fiat_25519_uint128)(arg1[2]) * ((arg2[4]) * UINT8_C(0x13)));
  194|  1.87k|  x9 = ((fiat_25519_uint128)(arg1[2]) * ((arg2[3]) * UINT8_C(0x13)));
  195|  1.87k|  x10 = ((fiat_25519_uint128)(arg1[1]) * ((arg2[4]) * UINT8_C(0x13)));
  196|  1.87k|  x11 = ((fiat_25519_uint128)(arg1[4]) * (arg2[0]));
  197|  1.87k|  x12 = ((fiat_25519_uint128)(arg1[3]) * (arg2[1]));
  198|  1.87k|  x13 = ((fiat_25519_uint128)(arg1[3]) * (arg2[0]));
  199|  1.87k|  x14 = ((fiat_25519_uint128)(arg1[2]) * (arg2[2]));
  200|  1.87k|  x15 = ((fiat_25519_uint128)(arg1[2]) * (arg2[1]));
  201|  1.87k|  x16 = ((fiat_25519_uint128)(arg1[2]) * (arg2[0]));
  202|  1.87k|  x17 = ((fiat_25519_uint128)(arg1[1]) * (arg2[3]));
  203|  1.87k|  x18 = ((fiat_25519_uint128)(arg1[1]) * (arg2[2]));
  204|  1.87k|  x19 = ((fiat_25519_uint128)(arg1[1]) * (arg2[1]));
  205|  1.87k|  x20 = ((fiat_25519_uint128)(arg1[1]) * (arg2[0]));
  206|  1.87k|  x21 = ((fiat_25519_uint128)(arg1[0]) * (arg2[4]));
  207|  1.87k|  x22 = ((fiat_25519_uint128)(arg1[0]) * (arg2[3]));
  208|  1.87k|  x23 = ((fiat_25519_uint128)(arg1[0]) * (arg2[2]));
  209|  1.87k|  x24 = ((fiat_25519_uint128)(arg1[0]) * (arg2[1]));
  210|  1.87k|  x25 = ((fiat_25519_uint128)(arg1[0]) * (arg2[0]));
  211|  1.87k|  x26 = (x25 + (x10 + (x9 + (x7 + x4))));
  212|  1.87k|  x27 = (uint64_t)(x26 >> 51);
  213|  1.87k|  x28 = (uint64_t)(x26 & UINT64_C(0x7ffffffffffff));
  214|  1.87k|  x29 = (x21 + (x17 + (x14 + (x12 + x11))));
  215|  1.87k|  x30 = (x22 + (x18 + (x15 + (x13 + x1))));
  216|  1.87k|  x31 = (x23 + (x19 + (x16 + (x5 + x2))));
  217|  1.87k|  x32 = (x24 + (x20 + (x8 + (x6 + x3))));
  218|  1.87k|  x33 = (x27 + x32);
  219|  1.87k|  x34 = (uint64_t)(x33 >> 51);
  220|  1.87k|  x35 = (uint64_t)(x33 & UINT64_C(0x7ffffffffffff));
  221|  1.87k|  x36 = (x34 + x31);
  222|  1.87k|  x37 = (uint64_t)(x36 >> 51);
  223|  1.87k|  x38 = (uint64_t)(x36 & UINT64_C(0x7ffffffffffff));
  224|  1.87k|  x39 = (x37 + x30);
  225|  1.87k|  x40 = (uint64_t)(x39 >> 51);
  226|  1.87k|  x41 = (uint64_t)(x39 & UINT64_C(0x7ffffffffffff));
  227|  1.87k|  x42 = (x40 + x29);
  228|  1.87k|  x43 = (uint64_t)(x42 >> 51);
  229|  1.87k|  x44 = (uint64_t)(x42 & UINT64_C(0x7ffffffffffff));
  230|  1.87k|  x45 = (x43 * UINT8_C(0x13));
  231|  1.87k|  x46 = (x28 + x45);
  232|  1.87k|  x47 = (x46 >> 51);
  233|  1.87k|  x48 = (x46 & UINT64_C(0x7ffffffffffff));
  234|  1.87k|  x49 = (x47 + x35);
  235|  1.87k|  x50 = (fiat_25519_uint1)(x49 >> 51);
  236|  1.87k|  x51 = (x49 & UINT64_C(0x7ffffffffffff));
  237|  1.87k|  x52 = (x50 + x38);
  238|  1.87k|  out1[0] = x48;
  239|  1.87k|  out1[1] = x51;
  240|  1.87k|  out1[2] = x52;
  241|  1.87k|  out1[3] = x41;
  242|  1.87k|  out1[4] = x44;
  243|  1.87k|}
curve25519.c:fiat_25519_to_bytes:
  514|    188|static FIAT_25519_FIAT_INLINE void fiat_25519_to_bytes(uint8_t out1[32], const fiat_25519_tight_field_element arg1) {
  515|    188|  uint64_t x1;
  516|    188|  fiat_25519_uint1 x2;
  517|    188|  uint64_t x3;
  518|    188|  fiat_25519_uint1 x4;
  519|    188|  uint64_t x5;
  520|    188|  fiat_25519_uint1 x6;
  521|    188|  uint64_t x7;
  522|    188|  fiat_25519_uint1 x8;
  523|    188|  uint64_t x9;
  524|    188|  fiat_25519_uint1 x10;
  525|    188|  uint64_t x11;
  526|    188|  uint64_t x12;
  527|    188|  fiat_25519_uint1 x13;
  528|    188|  uint64_t x14;
  529|    188|  fiat_25519_uint1 x15;
  530|    188|  uint64_t x16;
  531|    188|  fiat_25519_uint1 x17;
  532|    188|  uint64_t x18;
  533|    188|  fiat_25519_uint1 x19;
  534|    188|  uint64_t x20;
  535|    188|  fiat_25519_uint1 x21;
  536|    188|  uint64_t x22;
  537|    188|  uint64_t x23;
  538|    188|  uint64_t x24;
  539|    188|  uint64_t x25;
  540|    188|  uint8_t x26;
  541|    188|  uint64_t x27;
  542|    188|  uint8_t x28;
  543|    188|  uint64_t x29;
  544|    188|  uint8_t x30;
  545|    188|  uint64_t x31;
  546|    188|  uint8_t x32;
  547|    188|  uint64_t x33;
  548|    188|  uint8_t x34;
  549|    188|  uint64_t x35;
  550|    188|  uint8_t x36;
  551|    188|  uint8_t x37;
  552|    188|  uint64_t x38;
  553|    188|  uint8_t x39;
  554|    188|  uint64_t x40;
  555|    188|  uint8_t x41;
  556|    188|  uint64_t x42;
  557|    188|  uint8_t x43;
  558|    188|  uint64_t x44;
  559|    188|  uint8_t x45;
  560|    188|  uint64_t x46;
  561|    188|  uint8_t x47;
  562|    188|  uint64_t x48;
  563|    188|  uint8_t x49;
  564|    188|  uint8_t x50;
  565|    188|  uint64_t x51;
  566|    188|  uint8_t x52;
  567|    188|  uint64_t x53;
  568|    188|  uint8_t x54;
  569|    188|  uint64_t x55;
  570|    188|  uint8_t x56;
  571|    188|  uint64_t x57;
  572|    188|  uint8_t x58;
  573|    188|  uint64_t x59;
  574|    188|  uint8_t x60;
  575|    188|  uint64_t x61;
  576|    188|  uint8_t x62;
  577|    188|  uint64_t x63;
  578|    188|  uint8_t x64;
  579|    188|  fiat_25519_uint1 x65;
  580|    188|  uint64_t x66;
  581|    188|  uint8_t x67;
  582|    188|  uint64_t x68;
  583|    188|  uint8_t x69;
  584|    188|  uint64_t x70;
  585|    188|  uint8_t x71;
  586|    188|  uint64_t x72;
  587|    188|  uint8_t x73;
  588|    188|  uint64_t x74;
  589|    188|  uint8_t x75;
  590|    188|  uint64_t x76;
  591|    188|  uint8_t x77;
  592|    188|  uint8_t x78;
  593|    188|  uint64_t x79;
  594|    188|  uint8_t x80;
  595|    188|  uint64_t x81;
  596|    188|  uint8_t x82;
  597|    188|  uint64_t x83;
  598|    188|  uint8_t x84;
  599|    188|  uint64_t x85;
  600|    188|  uint8_t x86;
  601|    188|  uint64_t x87;
  602|    188|  uint8_t x88;
  603|    188|  uint64_t x89;
  604|    188|  uint8_t x90;
  605|    188|  uint8_t x91;
  606|    188|  fiat_25519_subborrowx_u51(&x1, &x2, 0x0, (arg1[0]), UINT64_C(0x7ffffffffffed));
  607|    188|  fiat_25519_subborrowx_u51(&x3, &x4, x2, (arg1[1]), UINT64_C(0x7ffffffffffff));
  608|    188|  fiat_25519_subborrowx_u51(&x5, &x6, x4, (arg1[2]), UINT64_C(0x7ffffffffffff));
  609|    188|  fiat_25519_subborrowx_u51(&x7, &x8, x6, (arg1[3]), UINT64_C(0x7ffffffffffff));
  610|    188|  fiat_25519_subborrowx_u51(&x9, &x10, x8, (arg1[4]), UINT64_C(0x7ffffffffffff));
  611|    188|  fiat_25519_cmovznz_u64(&x11, x10, 0x0, UINT64_C(0xffffffffffffffff));
  612|    188|  fiat_25519_addcarryx_u51(&x12, &x13, 0x0, x1, (x11 & UINT64_C(0x7ffffffffffed)));
  613|    188|  fiat_25519_addcarryx_u51(&x14, &x15, x13, x3, (x11 & UINT64_C(0x7ffffffffffff)));
  614|    188|  fiat_25519_addcarryx_u51(&x16, &x17, x15, x5, (x11 & UINT64_C(0x7ffffffffffff)));
  615|    188|  fiat_25519_addcarryx_u51(&x18, &x19, x17, x7, (x11 & UINT64_C(0x7ffffffffffff)));
  616|    188|  fiat_25519_addcarryx_u51(&x20, &x21, x19, x9, (x11 & UINT64_C(0x7ffffffffffff)));
  617|    188|  x22 = (x20 << 4);
  618|    188|  x23 = (x18 * (uint64_t)0x2);
  619|    188|  x24 = (x16 << 6);
  620|    188|  x25 = (x14 << 3);
  621|    188|  x26 = (uint8_t)(x12 & UINT8_C(0xff));
  622|    188|  x27 = (x12 >> 8);
  623|    188|  x28 = (uint8_t)(x27 & UINT8_C(0xff));
  624|    188|  x29 = (x27 >> 8);
  625|    188|  x30 = (uint8_t)(x29 & UINT8_C(0xff));
  626|    188|  x31 = (x29 >> 8);
  627|    188|  x32 = (uint8_t)(x31 & UINT8_C(0xff));
  628|    188|  x33 = (x31 >> 8);
  629|    188|  x34 = (uint8_t)(x33 & UINT8_C(0xff));
  630|    188|  x35 = (x33 >> 8);
  631|    188|  x36 = (uint8_t)(x35 & UINT8_C(0xff));
  632|    188|  x37 = (uint8_t)(x35 >> 8);
  633|    188|  x38 = (x25 + (uint64_t)x37);
  634|    188|  x39 = (uint8_t)(x38 & UINT8_C(0xff));
  635|    188|  x40 = (x38 >> 8);
  636|    188|  x41 = (uint8_t)(x40 & UINT8_C(0xff));
  637|    188|  x42 = (x40 >> 8);
  638|    188|  x43 = (uint8_t)(x42 & UINT8_C(0xff));
  639|    188|  x44 = (x42 >> 8);
  640|    188|  x45 = (uint8_t)(x44 & UINT8_C(0xff));
  641|    188|  x46 = (x44 >> 8);
  642|    188|  x47 = (uint8_t)(x46 & UINT8_C(0xff));
  643|    188|  x48 = (x46 >> 8);
  644|    188|  x49 = (uint8_t)(x48 & UINT8_C(0xff));
  645|    188|  x50 = (uint8_t)(x48 >> 8);
  646|    188|  x51 = (x24 + (uint64_t)x50);
  647|    188|  x52 = (uint8_t)(x51 & UINT8_C(0xff));
  648|    188|  x53 = (x51 >> 8);
  649|    188|  x54 = (uint8_t)(x53 & UINT8_C(0xff));
  650|    188|  x55 = (x53 >> 8);
  651|    188|  x56 = (uint8_t)(x55 & UINT8_C(0xff));
  652|    188|  x57 = (x55 >> 8);
  653|    188|  x58 = (uint8_t)(x57 & UINT8_C(0xff));
  654|    188|  x59 = (x57 >> 8);
  655|    188|  x60 = (uint8_t)(x59 & UINT8_C(0xff));
  656|    188|  x61 = (x59 >> 8);
  657|    188|  x62 = (uint8_t)(x61 & UINT8_C(0xff));
  658|    188|  x63 = (x61 >> 8);
  659|    188|  x64 = (uint8_t)(x63 & UINT8_C(0xff));
  660|    188|  x65 = (fiat_25519_uint1)(x63 >> 8);
  661|    188|  x66 = (x23 + (uint64_t)x65);
  662|    188|  x67 = (uint8_t)(x66 & UINT8_C(0xff));
  663|    188|  x68 = (x66 >> 8);
  664|    188|  x69 = (uint8_t)(x68 & UINT8_C(0xff));
  665|    188|  x70 = (x68 >> 8);
  666|    188|  x71 = (uint8_t)(x70 & UINT8_C(0xff));
  667|    188|  x72 = (x70 >> 8);
  668|    188|  x73 = (uint8_t)(x72 & UINT8_C(0xff));
  669|    188|  x74 = (x72 >> 8);
  670|    188|  x75 = (uint8_t)(x74 & UINT8_C(0xff));
  671|    188|  x76 = (x74 >> 8);
  672|    188|  x77 = (uint8_t)(x76 & UINT8_C(0xff));
  673|    188|  x78 = (uint8_t)(x76 >> 8);
  674|    188|  x79 = (x22 + (uint64_t)x78);
  675|    188|  x80 = (uint8_t)(x79 & UINT8_C(0xff));
  676|    188|  x81 = (x79 >> 8);
  677|    188|  x82 = (uint8_t)(x81 & UINT8_C(0xff));
  678|    188|  x83 = (x81 >> 8);
  679|    188|  x84 = (uint8_t)(x83 & UINT8_C(0xff));
  680|    188|  x85 = (x83 >> 8);
  681|    188|  x86 = (uint8_t)(x85 & UINT8_C(0xff));
  682|    188|  x87 = (x85 >> 8);
  683|    188|  x88 = (uint8_t)(x87 & UINT8_C(0xff));
  684|    188|  x89 = (x87 >> 8);
  685|    188|  x90 = (uint8_t)(x89 & UINT8_C(0xff));
  686|    188|  x91 = (uint8_t)(x89 >> 8);
  687|    188|  out1[0] = x26;
  688|    188|  out1[1] = x28;
  689|    188|  out1[2] = x30;
  690|    188|  out1[3] = x32;
  691|    188|  out1[4] = x34;
  692|    188|  out1[5] = x36;
  693|    188|  out1[6] = x39;
  694|    188|  out1[7] = x41;
  695|    188|  out1[8] = x43;
  696|    188|  out1[9] = x45;
  697|    188|  out1[10] = x47;
  698|    188|  out1[11] = x49;
  699|    188|  out1[12] = x52;
  700|    188|  out1[13] = x54;
  701|    188|  out1[14] = x56;
  702|    188|  out1[15] = x58;
  703|    188|  out1[16] = x60;
  704|    188|  out1[17] = x62;
  705|    188|  out1[18] = x64;
  706|    188|  out1[19] = x67;
  707|    188|  out1[20] = x69;
  708|    188|  out1[21] = x71;
  709|    188|  out1[22] = x73;
  710|    188|  out1[23] = x75;
  711|    188|  out1[24] = x77;
  712|    188|  out1[25] = x80;
  713|    188|  out1[26] = x82;
  714|    188|  out1[27] = x84;
  715|    188|  out1[28] = x86;
  716|    188|  out1[29] = x88;
  717|    188|  out1[30] = x90;
  718|    188|  out1[31] = x91;
  719|    188|}
curve25519.c:fiat_25519_subborrowx_u51:
   92|    940|static FIAT_25519_FIAT_INLINE void fiat_25519_subborrowx_u51(uint64_t* out1, fiat_25519_uint1* out2, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   93|    940|  int64_t x1;
   94|    940|  fiat_25519_int1 x2;
   95|    940|  uint64_t x3;
   96|    940|  x1 = ((int64_t)(arg2 - (int64_t)arg1) - (int64_t)arg3);
   97|    940|  x2 = (fiat_25519_int1)(x1 >> 51);
   98|    940|  x3 = (x1 & UINT64_C(0x7ffffffffffff));
   99|    940|  *out1 = x3;
  100|    940|  *out2 = (fiat_25519_uint1)(0x0 - x2);
  101|    940|}
curve25519.c:fiat_25519_cmovznz_u64:
  116|    188|static FIAT_25519_FIAT_INLINE void fiat_25519_cmovznz_u64(uint64_t* out1, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  117|    188|  fiat_25519_uint1 x1;
  118|    188|  uint64_t x2;
  119|    188|  uint64_t x3;
  120|    188|  x1 = (!(!arg1));
  121|    188|  x2 = ((fiat_25519_int1)(0x0 - x1) & UINT64_C(0xffffffffffffffff));
  122|    188|  x3 = ((fiat_25519_value_barrier_u64(x2) & arg3) | (fiat_25519_value_barrier_u64((~x2)) & arg2));
  123|    188|  *out1 = x3;
  124|    188|}
curve25519.c:fiat_25519_value_barrier_u64:
   42|    376|static __inline__ uint64_t fiat_25519_value_barrier_u64(uint64_t a) {
   43|    376|  __asm__("" : "+r"(a) : /* no inputs */);
   44|    376|  return a;
   45|    376|}
curve25519.c:fiat_25519_addcarryx_u51:
   66|    940|static FIAT_25519_FIAT_INLINE void fiat_25519_addcarryx_u51(uint64_t* out1, fiat_25519_uint1* out2, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   67|    940|  uint64_t x1;
   68|    940|  uint64_t x2;
   69|    940|  fiat_25519_uint1 x3;
   70|    940|  x1 = ((arg1 + arg2) + arg3);
   71|    940|  x2 = (x1 & UINT64_C(0x7ffffffffffff));
   72|    940|  x3 = (fiat_25519_uint1)(x1 >> 51);
   73|    940|  *out1 = x2;
   74|    940|  *out2 = x3;
   75|    940|}
curve25519.c:fiat_25519_carry_square:
  252|  38.8k|static FIAT_25519_FIAT_INLINE void fiat_25519_carry_square(fiat_25519_tight_field_element out1, const fiat_25519_loose_field_element arg1) {
  253|  38.8k|  uint64_t x1;
  254|  38.8k|  uint64_t x2;
  255|  38.8k|  uint64_t x3;
  256|  38.8k|  uint64_t x4;
  257|  38.8k|  uint64_t x5;
  258|  38.8k|  uint64_t x6;
  259|  38.8k|  uint64_t x7;
  260|  38.8k|  uint64_t x8;
  261|  38.8k|  fiat_25519_uint128 x9;
  262|  38.8k|  fiat_25519_uint128 x10;
  263|  38.8k|  fiat_25519_uint128 x11;
  264|  38.8k|  fiat_25519_uint128 x12;
  265|  38.8k|  fiat_25519_uint128 x13;
  266|  38.8k|  fiat_25519_uint128 x14;
  267|  38.8k|  fiat_25519_uint128 x15;
  268|  38.8k|  fiat_25519_uint128 x16;
  269|  38.8k|  fiat_25519_uint128 x17;
  270|  38.8k|  fiat_25519_uint128 x18;
  271|  38.8k|  fiat_25519_uint128 x19;
  272|  38.8k|  fiat_25519_uint128 x20;
  273|  38.8k|  fiat_25519_uint128 x21;
  274|  38.8k|  fiat_25519_uint128 x22;
  275|  38.8k|  fiat_25519_uint128 x23;
  276|  38.8k|  fiat_25519_uint128 x24;
  277|  38.8k|  uint64_t x25;
  278|  38.8k|  uint64_t x26;
  279|  38.8k|  fiat_25519_uint128 x27;
  280|  38.8k|  fiat_25519_uint128 x28;
  281|  38.8k|  fiat_25519_uint128 x29;
  282|  38.8k|  fiat_25519_uint128 x30;
  283|  38.8k|  fiat_25519_uint128 x31;
  284|  38.8k|  uint64_t x32;
  285|  38.8k|  uint64_t x33;
  286|  38.8k|  fiat_25519_uint128 x34;
  287|  38.8k|  uint64_t x35;
  288|  38.8k|  uint64_t x36;
  289|  38.8k|  fiat_25519_uint128 x37;
  290|  38.8k|  uint64_t x38;
  291|  38.8k|  uint64_t x39;
  292|  38.8k|  fiat_25519_uint128 x40;
  293|  38.8k|  uint64_t x41;
  294|  38.8k|  uint64_t x42;
  295|  38.8k|  uint64_t x43;
  296|  38.8k|  uint64_t x44;
  297|  38.8k|  uint64_t x45;
  298|  38.8k|  uint64_t x46;
  299|  38.8k|  uint64_t x47;
  300|  38.8k|  fiat_25519_uint1 x48;
  301|  38.8k|  uint64_t x49;
  302|  38.8k|  uint64_t x50;
  303|  38.8k|  x1 = ((arg1[4]) * UINT8_C(0x13));
  304|  38.8k|  x2 = (x1 * 0x2);
  305|  38.8k|  x3 = ((arg1[4]) * 0x2);
  306|  38.8k|  x4 = ((arg1[3]) * UINT8_C(0x13));
  307|  38.8k|  x5 = (x4 * 0x2);
  308|  38.8k|  x6 = ((arg1[3]) * 0x2);
  309|  38.8k|  x7 = ((arg1[2]) * 0x2);
  310|  38.8k|  x8 = ((arg1[1]) * 0x2);
  311|  38.8k|  x9 = ((fiat_25519_uint128)(arg1[4]) * x1);
  312|  38.8k|  x10 = ((fiat_25519_uint128)(arg1[3]) * x2);
  313|  38.8k|  x11 = ((fiat_25519_uint128)(arg1[3]) * x4);
  314|  38.8k|  x12 = ((fiat_25519_uint128)(arg1[2]) * x2);
  315|  38.8k|  x13 = ((fiat_25519_uint128)(arg1[2]) * x5);
  316|  38.8k|  x14 = ((fiat_25519_uint128)(arg1[2]) * (arg1[2]));
  317|  38.8k|  x15 = ((fiat_25519_uint128)(arg1[1]) * x2);
  318|  38.8k|  x16 = ((fiat_25519_uint128)(arg1[1]) * x6);
  319|  38.8k|  x17 = ((fiat_25519_uint128)(arg1[1]) * x7);
  320|  38.8k|  x18 = ((fiat_25519_uint128)(arg1[1]) * (arg1[1]));
  321|  38.8k|  x19 = ((fiat_25519_uint128)(arg1[0]) * x3);
  322|  38.8k|  x20 = ((fiat_25519_uint128)(arg1[0]) * x6);
  323|  38.8k|  x21 = ((fiat_25519_uint128)(arg1[0]) * x7);
  324|  38.8k|  x22 = ((fiat_25519_uint128)(arg1[0]) * x8);
  325|  38.8k|  x23 = ((fiat_25519_uint128)(arg1[0]) * (arg1[0]));
  326|  38.8k|  x24 = (x23 + (x15 + x13));
  327|  38.8k|  x25 = (uint64_t)(x24 >> 51);
  328|  38.8k|  x26 = (uint64_t)(x24 & UINT64_C(0x7ffffffffffff));
  329|  38.8k|  x27 = (x19 + (x16 + x14));
  330|  38.8k|  x28 = (x20 + (x17 + x9));
  331|  38.8k|  x29 = (x21 + (x18 + x10));
  332|  38.8k|  x30 = (x22 + (x12 + x11));
  333|  38.8k|  x31 = (x25 + x30);
  334|  38.8k|  x32 = (uint64_t)(x31 >> 51);
  335|  38.8k|  x33 = (uint64_t)(x31 & UINT64_C(0x7ffffffffffff));
  336|  38.8k|  x34 = (x32 + x29);
  337|  38.8k|  x35 = (uint64_t)(x34 >> 51);
  338|  38.8k|  x36 = (uint64_t)(x34 & UINT64_C(0x7ffffffffffff));
  339|  38.8k|  x37 = (x35 + x28);
  340|  38.8k|  x38 = (uint64_t)(x37 >> 51);
  341|  38.8k|  x39 = (uint64_t)(x37 & UINT64_C(0x7ffffffffffff));
  342|  38.8k|  x40 = (x38 + x27);
  343|  38.8k|  x41 = (uint64_t)(x40 >> 51);
  344|  38.8k|  x42 = (uint64_t)(x40 & UINT64_C(0x7ffffffffffff));
  345|  38.8k|  x43 = (x41 * UINT8_C(0x13));
  346|  38.8k|  x44 = (x26 + x43);
  347|  38.8k|  x45 = (x44 >> 51);
  348|  38.8k|  x46 = (x44 & UINT64_C(0x7ffffffffffff));
  349|  38.8k|  x47 = (x45 + x33);
  350|  38.8k|  x48 = (fiat_25519_uint1)(x47 >> 51);
  351|  38.8k|  x49 = (x47 & UINT64_C(0x7ffffffffffff));
  352|  38.8k|  x50 = (x48 + x36);
  353|  38.8k|  out1[0] = x46;
  354|  38.8k|  out1[1] = x49;
  355|  38.8k|  out1[2] = x50;
  356|  38.8k|  out1[3] = x39;
  357|  38.8k|  out1[4] = x42;
  358|  38.8k|}
curve25519.c:fiat_25519_sub:
  431|    118|static FIAT_25519_FIAT_INLINE void fiat_25519_sub(fiat_25519_loose_field_element out1, const fiat_25519_tight_field_element arg1, const fiat_25519_tight_field_element arg2) {
  432|    118|  uint64_t x1;
  433|    118|  uint64_t x2;
  434|    118|  uint64_t x3;
  435|    118|  uint64_t x4;
  436|    118|  uint64_t x5;
  437|    118|  x1 = ((UINT64_C(0xfffffffffffda) + (arg1[0])) - (arg2[0]));
  438|    118|  x2 = ((UINT64_C(0xffffffffffffe) + (arg1[1])) - (arg2[1]));
  439|    118|  x3 = ((UINT64_C(0xffffffffffffe) + (arg1[2])) - (arg2[2]));
  440|    118|  x4 = ((UINT64_C(0xffffffffffffe) + (arg1[3])) - (arg2[3]));
  441|    118|  x5 = ((UINT64_C(0xffffffffffffe) + (arg1[4])) - (arg2[4]));
  442|    118|  out1[0] = x1;
  443|    118|  out1[1] = x2;
  444|    118|  out1[2] = x3;
  445|    118|  out1[3] = x4;
  446|    118|  out1[4] = x5;
  447|    118|}
curve25519.c:fiat_25519_add:
  406|    118|static FIAT_25519_FIAT_INLINE void fiat_25519_add(fiat_25519_loose_field_element out1, const fiat_25519_tight_field_element arg1, const fiat_25519_tight_field_element arg2) {
  407|    118|  uint64_t x1;
  408|    118|  uint64_t x2;
  409|    118|  uint64_t x3;
  410|    118|  uint64_t x4;
  411|    118|  uint64_t x5;
  412|    118|  x1 = ((arg1[0]) + (arg2[0]));
  413|    118|  x2 = ((arg1[1]) + (arg2[1]));
  414|    118|  x3 = ((arg1[2]) + (arg2[2]));
  415|    118|  x4 = ((arg1[3]) + (arg2[3]));
  416|    118|  x5 = ((arg1[4]) + (arg2[4]));
  417|    118|  out1[0] = x1;
  418|    118|  out1[1] = x2;
  419|    118|  out1[2] = x3;
  420|    118|  out1[3] = x4;
  421|    118|  out1[4] = x5;
  422|    118|}
curve25519.c:fiat_25519_from_bytes:
  730|    612|static FIAT_25519_FIAT_INLINE void fiat_25519_from_bytes(fiat_25519_tight_field_element out1, const uint8_t arg1[32]) {
  731|    612|  uint64_t x1;
  732|    612|  uint64_t x2;
  733|    612|  uint64_t x3;
  734|    612|  uint64_t x4;
  735|    612|  uint64_t x5;
  736|    612|  uint64_t x6;
  737|    612|  uint64_t x7;
  738|    612|  uint64_t x8;
  739|    612|  uint64_t x9;
  740|    612|  uint64_t x10;
  741|    612|  uint64_t x11;
  742|    612|  uint64_t x12;
  743|    612|  uint64_t x13;
  744|    612|  uint64_t x14;
  745|    612|  uint64_t x15;
  746|    612|  uint64_t x16;
  747|    612|  uint64_t x17;
  748|    612|  uint64_t x18;
  749|    612|  uint64_t x19;
  750|    612|  uint64_t x20;
  751|    612|  uint64_t x21;
  752|    612|  uint64_t x22;
  753|    612|  uint64_t x23;
  754|    612|  uint64_t x24;
  755|    612|  uint64_t x25;
  756|    612|  uint64_t x26;
  757|    612|  uint64_t x27;
  758|    612|  uint64_t x28;
  759|    612|  uint64_t x29;
  760|    612|  uint64_t x30;
  761|    612|  uint64_t x31;
  762|    612|  uint8_t x32;
  763|    612|  uint64_t x33;
  764|    612|  uint64_t x34;
  765|    612|  uint64_t x35;
  766|    612|  uint64_t x36;
  767|    612|  uint64_t x37;
  768|    612|  uint64_t x38;
  769|    612|  uint64_t x39;
  770|    612|  uint8_t x40;
  771|    612|  uint64_t x41;
  772|    612|  uint64_t x42;
  773|    612|  uint64_t x43;
  774|    612|  uint64_t x44;
  775|    612|  uint64_t x45;
  776|    612|  uint64_t x46;
  777|    612|  uint64_t x47;
  778|    612|  uint8_t x48;
  779|    612|  uint64_t x49;
  780|    612|  uint64_t x50;
  781|    612|  uint64_t x51;
  782|    612|  uint64_t x52;
  783|    612|  uint64_t x53;
  784|    612|  uint64_t x54;
  785|    612|  uint64_t x55;
  786|    612|  uint64_t x56;
  787|    612|  uint8_t x57;
  788|    612|  uint64_t x58;
  789|    612|  uint64_t x59;
  790|    612|  uint64_t x60;
  791|    612|  uint64_t x61;
  792|    612|  uint64_t x62;
  793|    612|  uint64_t x63;
  794|    612|  uint64_t x64;
  795|    612|  uint8_t x65;
  796|    612|  uint64_t x66;
  797|    612|  uint64_t x67;
  798|    612|  uint64_t x68;
  799|    612|  uint64_t x69;
  800|    612|  uint64_t x70;
  801|    612|  uint64_t x71;
  802|    612|  x1 = ((uint64_t)(arg1[31]) << 44);
  803|    612|  x2 = ((uint64_t)(arg1[30]) << 36);
  804|    612|  x3 = ((uint64_t)(arg1[29]) << 28);
  805|    612|  x4 = ((uint64_t)(arg1[28]) << 20);
  806|    612|  x5 = ((uint64_t)(arg1[27]) << 12);
  807|    612|  x6 = ((uint64_t)(arg1[26]) << 4);
  808|    612|  x7 = ((uint64_t)(arg1[25]) << 47);
  809|    612|  x8 = ((uint64_t)(arg1[24]) << 39);
  810|    612|  x9 = ((uint64_t)(arg1[23]) << 31);
  811|    612|  x10 = ((uint64_t)(arg1[22]) << 23);
  812|    612|  x11 = ((uint64_t)(arg1[21]) << 15);
  813|    612|  x12 = ((uint64_t)(arg1[20]) << 7);
  814|    612|  x13 = ((uint64_t)(arg1[19]) << 50);
  815|    612|  x14 = ((uint64_t)(arg1[18]) << 42);
  816|    612|  x15 = ((uint64_t)(arg1[17]) << 34);
  817|    612|  x16 = ((uint64_t)(arg1[16]) << 26);
  818|    612|  x17 = ((uint64_t)(arg1[15]) << 18);
  819|    612|  x18 = ((uint64_t)(arg1[14]) << 10);
  820|    612|  x19 = ((uint64_t)(arg1[13]) << 2);
  821|    612|  x20 = ((uint64_t)(arg1[12]) << 45);
  822|    612|  x21 = ((uint64_t)(arg1[11]) << 37);
  823|    612|  x22 = ((uint64_t)(arg1[10]) << 29);
  824|    612|  x23 = ((uint64_t)(arg1[9]) << 21);
  825|    612|  x24 = ((uint64_t)(arg1[8]) << 13);
  826|    612|  x25 = ((uint64_t)(arg1[7]) << 5);
  827|    612|  x26 = ((uint64_t)(arg1[6]) << 48);
  828|    612|  x27 = ((uint64_t)(arg1[5]) << 40);
  829|    612|  x28 = ((uint64_t)(arg1[4]) << 32);
  830|    612|  x29 = ((uint64_t)(arg1[3]) << 24);
  831|    612|  x30 = ((uint64_t)(arg1[2]) << 16);
  832|    612|  x31 = ((uint64_t)(arg1[1]) << 8);
  833|    612|  x32 = (arg1[0]);
  834|    612|  x33 = (x31 + (uint64_t)x32);
  835|    612|  x34 = (x30 + x33);
  836|    612|  x35 = (x29 + x34);
  837|    612|  x36 = (x28 + x35);
  838|    612|  x37 = (x27 + x36);
  839|    612|  x38 = (x26 + x37);
  840|    612|  x39 = (x38 & UINT64_C(0x7ffffffffffff));
  841|    612|  x40 = (uint8_t)(x38 >> 51);
  842|    612|  x41 = (x25 + (uint64_t)x40);
  843|    612|  x42 = (x24 + x41);
  844|    612|  x43 = (x23 + x42);
  845|    612|  x44 = (x22 + x43);
  846|    612|  x45 = (x21 + x44);
  847|    612|  x46 = (x20 + x45);
  848|    612|  x47 = (x46 & UINT64_C(0x7ffffffffffff));
  849|    612|  x48 = (uint8_t)(x46 >> 51);
  850|    612|  x49 = (x19 + (uint64_t)x48);
  851|    612|  x50 = (x18 + x49);
  852|    612|  x51 = (x17 + x50);
  853|    612|  x52 = (x16 + x51);
  854|    612|  x53 = (x15 + x52);
  855|    612|  x54 = (x14 + x53);
  856|    612|  x55 = (x13 + x54);
  857|    612|  x56 = (x55 & UINT64_C(0x7ffffffffffff));
  858|    612|  x57 = (uint8_t)(x55 >> 51);
  859|    612|  x58 = (x12 + (uint64_t)x57);
  860|    612|  x59 = (x11 + x58);
  861|    612|  x60 = (x10 + x59);
  862|    612|  x61 = (x9 + x60);
  863|    612|  x62 = (x8 + x61);
  864|    612|  x63 = (x7 + x62);
  865|    612|  x64 = (x63 & UINT64_C(0x7ffffffffffff));
  866|    612|  x65 = (uint8_t)(x63 >> 51);
  867|    612|  x66 = (x6 + (uint64_t)x65);
  868|    612|  x67 = (x5 + x66);
  869|    612|  x68 = (x4 + x67);
  870|    612|  x69 = (x3 + x68);
  871|    612|  x70 = (x2 + x69);
  872|    612|  x71 = (x1 + x70);
  873|    612|  out1[0] = x39;
  874|    612|  out1[1] = x47;
  875|    612|  out1[2] = x56;
  876|    612|  out1[3] = x64;
  877|    612|  out1[4] = x71;
  878|    612|}

x25519_ge_scalarmult_base_adx:
  626|    153|void x25519_ge_scalarmult_base_adx(uint8_t h[4][32], const uint8_t a[32]) {
  627|    153|  signed char e[64];
  628|    153|  signed char carry;
  629|       |
  630|  5.04k|  for (unsigned i = 0; i < 32; ++i) {
  ------------------
  |  Branch (630:24): [True: 4.89k, False: 153]
  ------------------
  631|  4.89k|    e[2 * i + 0] = (a[i] >> 0) & 15;
  632|  4.89k|    e[2 * i + 1] = (a[i] >> 4) & 15;
  633|  4.89k|  }
  634|       |  // each e[i] is between 0 and 15
  635|       |  // e[63] is between 0 and 7
  636|       |
  637|    153|  carry = 0;
  638|  9.79k|  for (unsigned i = 0; i < 63; ++i) {
  ------------------
  |  Branch (638:24): [True: 9.63k, False: 153]
  ------------------
  639|  9.63k|    e[i] += carry;
  640|  9.63k|    carry = e[i] + 8;
  641|  9.63k|    carry >>= 4;
  642|  9.63k|    e[i] -= carry << 4;
  643|  9.63k|  }
  644|    153|  e[63] += carry;
  645|       |  // each e[i] is between -8 and 8
  646|       |
  647|    153|  ge_p3_4 r = {{0}, {1}, {1}, {0}};
  648|  5.04k|  for (unsigned i = 1; i < 64; i += 2) {
  ------------------
  |  Branch (648:24): [True: 4.89k, False: 153]
  ------------------
  649|  4.89k|    ge_precomp_4 t;
  650|  4.89k|    table_select_4(&t, i / 2, e[i]);
  651|  4.89k|    ge_p3_add_p3_precomp_4(&r, &r, &t);
  652|  4.89k|  }
  653|       |
  654|    153|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  655|    153|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  656|    153|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  657|    153|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/false);
  658|       |
  659|  5.04k|  for (unsigned i = 0; i < 64; i += 2) {
  ------------------
  |  Branch (659:24): [True: 4.89k, False: 153]
  ------------------
  660|  4.89k|    ge_precomp_4 t;
  661|  4.89k|    table_select_4(&t, i / 2, e[i]);
  662|  4.89k|    ge_p3_add_p3_precomp_4(&r, &r, &t);
  663|  4.89k|  }
  664|       |
  665|       |  // fe4 uses saturated 64-bit limbs, so converting to bytes is just a copy.
  666|       |  // Satisfy stated precondition of fiat_25519_from_bytes; tests pass either way
  667|    153|  fe4_canon(r.X, r.X);
  668|    153|  fe4_canon(r.Y, r.Y);
  669|    153|  fe4_canon(r.Z, r.Z);
  670|    153|  fe4_canon(r.T, r.T);
  671|    153|  static_assert(sizeof(ge_p3_4) == sizeof(uint8_t[4][32]), "");
  672|    153|  OPENSSL_memcpy(h, &r, sizeof(ge_p3_4));
  673|    153|}
curve25519_64_adx.c:fiat_cmovznz_u64:
  137|   168k|static inline void fiat_cmovznz_u64(uint64_t* out1, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  138|   168k|  fiat_uint1 x1;
  139|   168k|  uint64_t x2;
  140|   168k|  uint64_t x3;
  141|   168k|  x1 = (!(!arg1));
  142|   168k|  x2 = ((fiat_int1)(0x0 - x1) & UINT64_C(0xffffffffffffffff));
  143|   168k|  x3 = ((fiat_value_barrier_u64(x2) & arg3) | (fiat_value_barrier_u64((~x2)) & arg2));
  144|   168k|  *out1 = x3;
  145|   168k|}
curve25519_64_adx.c:fiat_value_barrier_u64:
   10|   337k|static __inline__ uint64_t fiat_value_barrier_u64(uint64_t a) {
   11|   337k|  __asm__("" : "+r"(a) : /* no inputs */);
   12|   337k|  return a;
   13|   337k|}
curve25519_64_adx.c:fe4_sub:
  199|  41.0k|static void fe4_sub(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
  200|  41.0k|  uint64_t x1;
  201|  41.0k|  uint64_t x2;
  202|  41.0k|  fiat_uint1 x3;
  203|  41.0k|  uint64_t x4;
  204|  41.0k|  uint64_t x5;
  205|  41.0k|  fiat_uint1 x6;
  206|  41.0k|  uint64_t x7;
  207|  41.0k|  uint64_t x8;
  208|  41.0k|  fiat_uint1 x9;
  209|  41.0k|  uint64_t x10;
  210|  41.0k|  uint64_t x11;
  211|  41.0k|  fiat_uint1 x12;
  212|  41.0k|  uint64_t x13;
  213|  41.0k|  uint64_t x14;
  214|  41.0k|  fiat_uint1 x15;
  215|  41.0k|  uint64_t x16;
  216|  41.0k|  fiat_uint1 x17;
  217|  41.0k|  uint64_t x18;
  218|  41.0k|  fiat_uint1 x19;
  219|  41.0k|  uint64_t x20;
  220|  41.0k|  fiat_uint1 x21;
  221|  41.0k|  uint64_t x22;
  222|  41.0k|  uint64_t x23;
  223|  41.0k|  fiat_uint1 x24;
  224|  41.0k|  x1 = (arg2[0]);
  225|  41.0k|  fiat_subborrowx_u64(&x2, &x3, 0x0, (arg1[0]), x1);
  226|  41.0k|  x4 = (arg2[1]);
  227|  41.0k|  fiat_subborrowx_u64(&x5, &x6, x3, (arg1[1]), x4);
  228|  41.0k|  x7 = (arg2[2]);
  229|  41.0k|  fiat_subborrowx_u64(&x8, &x9, x6, (arg1[2]), x7);
  230|  41.0k|  x10 = (arg2[3]);
  231|  41.0k|  fiat_subborrowx_u64(&x11, &x12, x9, (arg1[3]), x10);
  232|  41.0k|  fiat_cmovznz_u64(&x13, x12, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  233|  41.0k|  fiat_subborrowx_u64(&x14, &x15, 0x0, x2, x13);
  234|  41.0k|  fiat_subborrowx_u64(&x16, &x17, x15, x5, 0x0);
  235|  41.0k|  fiat_subborrowx_u64(&x18, &x19, x17, x8, 0x0);
  236|  41.0k|  fiat_subborrowx_u64(&x20, &x21, x19, x11, 0x0);
  237|  41.0k|  fiat_cmovznz_u64(&x22, x21, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  238|  41.0k|  fiat_subborrowx_u64(&x23, &x24, 0x0, x14, x22);
  239|  41.0k|  out1[0] = x23;
  240|  41.0k|  out1[1] = x16;
  241|  41.0k|  out1[2] = x18;
  242|  41.0k|  out1[3] = x20;
  243|  41.0k|}
curve25519_64_adx.c:fiat_subborrowx_u64:
  103|   373k|static inline void fiat_subborrowx_u64(uint64_t* out1, fiat_uint1* out2, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  104|   373k|#if defined(__has_builtin)
  105|   373k|#  if __has_builtin(__builtin_ia32_subborrow_u64)
  106|   373k|#    define subborrow64 __builtin_ia32_subborrow_u64
  107|   373k|#  endif
  108|   373k|#endif
  109|   373k|#if defined(subborrow64)
  110|   373k|  long long unsigned int t;
  111|   373k|  *out2 = subborrow64(arg1, arg2, arg3, &t);
  ------------------
  |  |  106|   373k|#    define subborrow64 __builtin_ia32_subborrow_u64
  ------------------
  112|   373k|  *out1 = t;
  113|       |#elif defined(_M_X64)
  114|       |  long long unsigned int t;
  115|       |  *out2 = _subborrow_u64(arg1, arg2, arg3, &t); // NOTE: edited after generation
  116|       |  *out1 = t;
  117|       |#else
  118|       |  *out1 = arg2 - arg3 - arg1;
  119|       |  *out2 = (arg2 < arg3) | ((arg2 == arg3) & arg1);
  120|       |#endif
  121|   373k|#undef subborrow64
  122|   373k|}
curve25519_64_adx.c:fe4_add:
  154|  41.0k|static void fe4_add(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
  155|  41.0k|  uint64_t x1;
  156|  41.0k|  fiat_uint1 x2;
  157|  41.0k|  uint64_t x3;
  158|  41.0k|  fiat_uint1 x4;
  159|  41.0k|  uint64_t x5;
  160|  41.0k|  fiat_uint1 x6;
  161|  41.0k|  uint64_t x7;
  162|  41.0k|  fiat_uint1 x8;
  163|  41.0k|  uint64_t x9;
  164|  41.0k|  uint64_t x10;
  165|  41.0k|  fiat_uint1 x11;
  166|  41.0k|  uint64_t x12;
  167|  41.0k|  fiat_uint1 x13;
  168|  41.0k|  uint64_t x14;
  169|  41.0k|  fiat_uint1 x15;
  170|  41.0k|  uint64_t x16;
  171|  41.0k|  fiat_uint1 x17;
  172|  41.0k|  uint64_t x18;
  173|  41.0k|  uint64_t x19;
  174|  41.0k|  fiat_uint1 x20;
  175|  41.0k|  fiat_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
  176|  41.0k|  fiat_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
  177|  41.0k|  fiat_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
  178|  41.0k|  fiat_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
  179|  41.0k|  fiat_cmovznz_u64(&x9, x8, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  180|  41.0k|  fiat_addcarryx_u64(&x10, &x11, 0x0, x1, x9);
  181|  41.0k|  fiat_addcarryx_u64(&x12, &x13, x11, x3, 0x0);
  182|  41.0k|  fiat_addcarryx_u64(&x14, &x15, x13, x5, 0x0);
  183|  41.0k|  fiat_addcarryx_u64(&x16, &x17, x15, x7, 0x0);
  184|  41.0k|  fiat_cmovznz_u64(&x18, x17, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  185|  41.0k|  fiat_addcarryx_u64(&x19, &x20, 0x0, x10, x18);
  186|  41.0k|  out1[0] = x19;
  187|  41.0k|  out1[1] = x12;
  188|  41.0k|  out1[2] = x14;
  189|  41.0k|  out1[3] = x16;
  190|  41.0k|}
curve25519_64_adx.c:fiat_addcarryx_u64:
   62|   369k|static inline void fiat_addcarryx_u64(uint64_t* out1, fiat_uint1* out2, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   63|       |// NOTE: edited after generation
   64|   369k|#if defined(__has_builtin)
   65|   369k|#  if __has_builtin(__builtin_ia32_addcarryx_u64)
   66|   369k|#    define addcarry64 __builtin_ia32_addcarryx_u64
   67|   369k|#  endif
   68|   369k|#endif
   69|   369k|#if defined(addcarry64)
   70|   369k|  long long unsigned int t;
   71|   369k|  *out2 = addcarry64(arg1, arg2, arg3, &t);
  ------------------
  |  |   66|   369k|#    define addcarry64 __builtin_ia32_addcarryx_u64
  ------------------
   72|   369k|  *out1 = t;
   73|       |#elif defined(_M_X64)
   74|       |  long long unsigned int t;
   75|       |  *out2 = _addcarry_u64(arg1, arg2, arg3, out1);
   76|       |  *out1 = t;
   77|       |#else
   78|       |  arg2 += arg1;
   79|       |  arg1 = arg2 < arg1;
   80|       |  uint64_t ret = arg2 + arg3;
   81|       |  arg1 += ret < arg2;
   82|       |  *out1 = ret;
   83|       |  *out2 = arg1;
   84|       |#endif
   85|   369k|#undef addcarry64
   86|   369k|}
curve25519_64_adx.c:fe4_mul:
   14|  70.5k|static inline void fe4_mul(fe4 out, const fe4 x, const fe4 y) { fiat_curve25519_adx_mul(out, x, y); }
curve25519_64_adx.c:fe4_sq:
   15|  2.44k|static inline void fe4_sq(fe4 out, const fe4 x) { fiat_curve25519_adx_square(out, x); }
curve25519_64_adx.c:fe4_canon:
  306|    612|static void fe4_canon(uint64_t out1[4], const uint64_t arg1[4]) {
  307|    612|  uint64_t x1;
  308|    612|  fiat_uint1 x2;
  309|    612|  uint64_t x3;
  310|    612|  fiat_uint1 x4;
  311|    612|  uint64_t x5;
  312|    612|  fiat_uint1 x6;
  313|    612|  uint64_t x7;
  314|    612|  fiat_uint1 x8;
  315|    612|  uint64_t x9;
  316|    612|  uint64_t x10;
  317|    612|  uint64_t x11;
  318|    612|  uint64_t x12;
  319|    612|  uint64_t x13;
  320|    612|  fiat_uint1 x14;
  321|    612|  uint64_t x15;
  322|    612|  fiat_uint1 x16;
  323|    612|  uint64_t x17;
  324|    612|  fiat_uint1 x18;
  325|    612|  uint64_t x19;
  326|    612|  fiat_uint1 x20;
  327|    612|  uint64_t x21;
  328|    612|  uint64_t x22;
  329|    612|  uint64_t x23;
  330|    612|  uint64_t x24;
  331|    612|  fiat_subborrowx_u64(&x1, &x2, 0x0, (arg1[0]), UINT64_C(0xffffffffffffffed));
  332|    612|  fiat_subborrowx_u64(&x3, &x4, x2, (arg1[1]), UINT64_C(0xffffffffffffffff));
  333|    612|  fiat_subborrowx_u64(&x5, &x6, x4, (arg1[2]), UINT64_C(0xffffffffffffffff));
  334|    612|  fiat_subborrowx_u64(&x7, &x8, x6, (arg1[3]), UINT64_C(0x7fffffffffffffff));
  335|    612|  fiat_cmovznz_u64(&x9, x8, x1, (arg1[0]));
  336|    612|  fiat_cmovznz_u64(&x10, x8, x3, (arg1[1]));
  337|    612|  fiat_cmovznz_u64(&x11, x8, x5, (arg1[2]));
  338|    612|  fiat_cmovznz_u64(&x12, x8, x7, (arg1[3]));
  339|    612|  fiat_subborrowx_u64(&x13, &x14, 0x0, x9, UINT64_C(0xffffffffffffffed));
  340|    612|  fiat_subborrowx_u64(&x15, &x16, x14, x10, UINT64_C(0xffffffffffffffff));
  341|    612|  fiat_subborrowx_u64(&x17, &x18, x16, x11, UINT64_C(0xffffffffffffffff));
  342|    612|  fiat_subborrowx_u64(&x19, &x20, x18, x12, UINT64_C(0x7fffffffffffffff));
  343|    612|  fiat_cmovznz_u64(&x21, x20, x13, x9);
  344|    612|  fiat_cmovznz_u64(&x22, x20, x15, x10);
  345|    612|  fiat_cmovznz_u64(&x23, x20, x17, x11);
  346|    612|  fiat_cmovznz_u64(&x24, x20, x19, x12);
  347|    612|  out1[0] = x21;
  348|    612|  out1[1] = x22;
  349|    612|  out1[2] = x23;
  350|    612|  out1[3] = x24;
  351|    612|}
curve25519_64_adx.c:table_select_4:
  590|  9.79k|                                  const signed char b) {
  591|  9.79k|  uint8_t bnegative = constant_time_msb_w(b);
  592|  9.79k|  uint8_t babs = b - ((bnegative & b) << 1);
  593|       |
  594|  9.79k|  uint8_t t_bytes[3][32] = {
  595|  9.79k|      {constant_time_is_zero_w(b) & 1}, {constant_time_is_zero_w(b) & 1}, {0}};
  596|  9.79k|#if defined(__clang__)
  597|  9.79k|  __asm__("" : "+m" (t_bytes) : /*no inputs*/);
  598|  9.79k|#endif
  599|  9.79k|  static_assert(sizeof(t_bytes) == sizeof(k25519Precomp[pos][0]), "");
  600|  88.1k|  for (int i = 0; i < 8; i++) {
  ------------------
  |  Branch (600:19): [True: 78.3k, False: 9.79k]
  ------------------
  601|  78.3k|    constant_time_conditional_memxor(t_bytes, k25519Precomp[pos][i],
  602|  78.3k|                                     sizeof(t_bytes),
  603|  78.3k|                                     constant_time_eq_w(babs, 1 + i));
  604|  78.3k|  }
  605|       |
  606|  9.79k|  static_assert(sizeof(t_bytes) == sizeof(ge_precomp_4), "");
  607|       |
  608|       |  // fe4 uses saturated 64-bit limbs, so converting from bytes is just a copy.
  609|  9.79k|  OPENSSL_memcpy(t, t_bytes, sizeof(ge_precomp_4));
  610|       |
  611|  9.79k|  fe4 xy2d_neg = {0};
  612|  9.79k|  fe4_sub(xy2d_neg, xy2d_neg, t->xy2d);
  613|  9.79k|  constant_time_conditional_memcpy(t->yplusx, t_bytes[1], sizeof(fe4),
  614|  9.79k|                                   bnegative);
  615|  9.79k|  constant_time_conditional_memcpy(t->yminusx, t_bytes[0], sizeof(fe4),
  616|  9.79k|                                   bnegative);
  617|  9.79k|  constant_time_conditional_memcpy(t->xy2d, xy2d_neg, sizeof(fe4), bnegative);
  618|  9.79k|}
curve25519_64_adx.c:ge_p3_add_p3_precomp_4:
  568|  9.79k|ge_p3_add_p3_precomp_4(ge_p3_4 *r, const ge_p3_4 *p, const ge_precomp_4 *q) {
  569|  9.79k|  fe4 A, B, C, YplusX, YminusX, D, X3, Y3, Z3, T3;
  570|       |  // Transcribed from a Coq function proven against affine coordinates.
  571|       |  // https://github.com/mit-plv/fiat-crypto/blob/a36568d1d73aff5d7accc79fd28be672882f9c17/src/Curves/Edwards/XYZT/Precomputed.v#L38-L56
  572|  9.79k|  fe4_add(YplusX, p->Y, p->X);
  573|  9.79k|  fe4_sub(YminusX, p->Y, p->X);
  574|  9.79k|  fe4_mul(A, YplusX, q->yplusx);
  575|  9.79k|  fe4_mul(B, YminusX, q->yminusx);
  576|  9.79k|  fe4_mul(C, q->xy2d, p->T);
  577|  9.79k|  fe4_add(D, p->Z, p->Z);
  578|  9.79k|  fe4_sub(X3, A, B);
  579|  9.79k|  fe4_add(Y3, A, B);
  580|  9.79k|  fe4_add(Z3, D, C);
  581|  9.79k|  fe4_sub(T3, D, C);
  582|  9.79k|  fe4_mul(r->X, X3, T3);
  583|  9.79k|  fe4_mul(r->Y, Y3, Z3);
  584|  9.79k|  fe4_mul(r->Z, Z3, T3);
  585|  9.79k|  fe4_mul(r->T, X3, Y3);
  586|  9.79k|}
curve25519_64_adx.c:inline_x25519_ge_dbl_4:
  544|    612|static void inline_x25519_ge_dbl_4(ge_p3_4 *r, const ge_p3_4 *p, bool skip_t) {
  545|       |  // Transcribed from a Coq function proven against affine coordinates.
  546|       |  // https://github.com/mit-plv/fiat-crypto/blob/9943ba9e7d8f3e1c0054b2c94a5edca46ea73ef8/src/Curves/Edwards/XYZT/Basic.v#L136-L165
  547|    612|  fe4 trX, trZ, trT, t0, cX, cY, cZ, cT;
  548|    612|  fe4_sq(trX, p->X);
  549|    612|  fe4_sq(trZ, p->Y);
  550|    612|  fe4_sq(trT, p->Z);
  551|    612|  fe4_add(trT, trT, trT);
  552|    612|  fe4_add(cY, p->X, p->Y);
  553|    612|  fe4_sq(t0, cY);
  554|    612|  fe4_add(cY, trZ, trX);
  555|    612|  fe4_sub(cZ, trZ, trX);
  556|    612|  fe4_sub(cX, t0, cY);
  557|    612|  fe4_sub(cT, trT, cZ);
  558|    612|  fe4_mul(r->X, cX, cT);
  559|    612|  fe4_mul(r->Y, cY, cZ);
  560|    612|  fe4_mul(r->Z, cZ, cT);
  561|    612|  if (!skip_t) {
  ------------------
  |  Branch (561:7): [True: 153, False: 459]
  ------------------
  562|    153|    fe4_mul(r->T, cX, cY);
  563|    153|  }
  564|    612|}

