asn1_bit_string_length:
   75|   101k|                           uint8_t *out_padding_bits) {
   76|   101k|  int len = str->length;
   77|   101k|  if (str->flags & ASN1_STRING_FLAG_BITS_LEFT) {
  ------------------
  |  |  543|   101k|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  |  Branch (77:7): [True: 101k, False: 0]
  ------------------
   78|       |    // If the string is already empty, it cannot have padding bits.
   79|   101k|    *out_padding_bits = len == 0 ? 0 : str->flags & 0x07;
  ------------------
  |  Branch (79:25): [True: 0, False: 101k]
  ------------------
   80|   101k|    return len;
   81|   101k|  }
   82|       |
   83|       |  // TODO(https://crbug.com/boringssl/447): If we move this logic to
   84|       |  // |ASN1_BIT_STRING_set_bit|, can we remove this representation?
   85|      0|  while (len > 0 && str->data[len - 1] == 0) {
  ------------------
  |  Branch (85:10): [True: 0, False: 0]
  |  Branch (85:21): [True: 0, False: 0]
  ------------------
   86|      0|    len--;
   87|      0|  }
   88|      0|  uint8_t padding_bits = 0;
   89|      0|  if (len > 0) {
  ------------------
  |  Branch (89:7): [True: 0, False: 0]
  ------------------
   90|      0|    uint8_t last = str->data[len - 1];
   91|      0|    assert(last != 0);
   92|      0|    for (; padding_bits < 7; padding_bits++) {
  ------------------
  |  Branch (92:12): [True: 0, False: 0]
  ------------------
   93|      0|      if (last & (1 << padding_bits)) {
  ------------------
  |  Branch (93:11): [True: 0, False: 0]
  ------------------
   94|      0|        break;
   95|      0|      }
   96|      0|    }
   97|      0|  }
   98|      0|  *out_padding_bits = padding_bits;
   99|      0|  return len;
  100|      0|}
i2c_ASN1_BIT_STRING:
  112|   101k|int i2c_ASN1_BIT_STRING(const ASN1_BIT_STRING *a, unsigned char **pp) {
  113|   101k|  if (a == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 101k]
  ------------------
  114|      0|    return 0;
  115|      0|  }
  116|       |
  117|   101k|  uint8_t bits;
  118|   101k|  int len = asn1_bit_string_length(a, &bits);
  119|   101k|  if (len > INT_MAX - 1) {
  ------------------
  |  Branch (119:7): [True: 0, False: 101k]
  ------------------
  120|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  121|      0|    return 0;
  122|      0|  }
  123|   101k|  int ret = 1 + len;
  124|   101k|  if (pp == NULL) {
  ------------------
  |  Branch (124:7): [True: 67.4k, False: 33.7k]
  ------------------
  125|  67.4k|    return ret;
  126|  67.4k|  }
  127|       |
  128|  33.7k|  uint8_t *p = *pp;
  129|  33.7k|  *(p++) = bits;
  130|  33.7k|  OPENSSL_memcpy(p, a->data, len);
  131|  33.7k|  if (len > 0) {
  ------------------
  |  Branch (131:7): [True: 33.7k, False: 0]
  ------------------
  132|  33.7k|    p[len - 1] &= (0xff << bits);
  133|  33.7k|  }
  134|  33.7k|  p += len;
  135|  33.7k|  *pp = p;
  136|  33.7k|  return ret;
  137|   101k|}
c2i_ASN1_BIT_STRING:
  140|  40.1k|                                     const unsigned char **pp, long len) {
  141|  40.1k|  ASN1_BIT_STRING *ret = NULL;
  142|  40.1k|  const unsigned char *p;
  143|  40.1k|  unsigned char *s;
  144|  40.1k|  int padding;
  145|       |
  146|  40.1k|  if (len < 1) {
  ------------------
  |  Branch (146:7): [True: 0, False: 40.1k]
  ------------------
  147|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_SHORT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  148|      0|    goto err;
  149|      0|  }
  150|       |
  151|  40.1k|  if (len > INT_MAX) {
  ------------------
  |  Branch (151:7): [True: 0, False: 40.1k]
  ------------------
  152|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  153|      0|    goto err;
  154|      0|  }
  155|       |
  156|  40.1k|  if ((a == NULL) || ((*a) == NULL)) {
  ------------------
  |  Branch (156:7): [True: 20.0k, False: 20.0k]
  |  Branch (156:22): [True: 0, False: 20.0k]
  ------------------
  157|  20.0k|    if ((ret = ASN1_BIT_STRING_new()) == NULL) {
  ------------------
  |  Branch (157:9): [True: 0, False: 20.0k]
  ------------------
  158|      0|      return NULL;
  159|      0|    }
  160|  20.0k|  } else {
  161|  20.0k|    ret = (*a);
  162|  20.0k|  }
  163|       |
  164|  40.1k|  p = *pp;
  165|  40.1k|  padding = *(p++);
  166|  40.1k|  len--;
  167|  40.1k|  if (padding > 7) {
  ------------------
  |  Branch (167:7): [True: 0, False: 40.1k]
  ------------------
  168|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BIT_STRING_BITS_LEFT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  169|      0|    goto err;
  170|      0|  }
  171|       |
  172|       |  // Unused bits in a BIT STRING must be zero.
  173|  40.1k|  uint8_t padding_mask = (1 << padding) - 1;
  174|  40.1k|  if (padding != 0 && (len < 1 || (p[len - 1] & padding_mask) != 0)) {
  ------------------
  |  Branch (174:7): [True: 0, False: 40.1k]
  |  Branch (174:24): [True: 0, False: 0]
  |  Branch (174:35): [True: 0, False: 0]
  ------------------
  175|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BIT_STRING_PADDING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  176|      0|    goto err;
  177|      0|  }
  178|       |
  179|       |  // We do this to preserve the settings.  If we modify the settings, via
  180|       |  // the _set_bit function, we will recalculate on output
  181|  40.1k|  ret->flags &= ~(ASN1_STRING_FLAG_BITS_LEFT | 0x07);    // clear
  ------------------
  |  |  543|  40.1k|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  182|  40.1k|  ret->flags |= (ASN1_STRING_FLAG_BITS_LEFT | padding);  // set
  ------------------
  |  |  543|  40.1k|#define ASN1_STRING_FLAG_BITS_LEFT 0x08
  ------------------
  183|       |
  184|  40.1k|  if (len > 0) {
  ------------------
  |  Branch (184:7): [True: 40.1k, False: 0]
  ------------------
  185|  40.1k|    s = OPENSSL_memdup(p, len);
  186|  40.1k|    if (s == NULL) {
  ------------------
  |  Branch (186:9): [True: 0, False: 40.1k]
  ------------------
  187|      0|      goto err;
  188|      0|    }
  189|  40.1k|    p += len;
  190|  40.1k|  } else {
  191|      0|    s = NULL;
  192|      0|  }
  193|       |
  194|  40.1k|  ret->length = (int)len;
  195|  40.1k|  OPENSSL_free(ret->data);
  196|  40.1k|  ret->data = s;
  197|  40.1k|  ret->type = V_ASN1_BIT_STRING;
  ------------------
  |  |  127|  40.1k|#define V_ASN1_BIT_STRING 3
  ------------------
  198|  40.1k|  if (a != NULL) {
  ------------------
  |  Branch (198:7): [True: 20.0k, False: 20.0k]
  ------------------
  199|  20.0k|    (*a) = ret;
  200|  20.0k|  }
  201|  40.1k|  *pp = p;
  202|  40.1k|  return ret;
  203|      0|err:
  204|      0|  if ((ret != NULL) && ((a == NULL) || (*a != ret))) {
  ------------------
  |  Branch (204:7): [True: 0, False: 0]
  |  Branch (204:25): [True: 0, False: 0]
  |  Branch (204:40): [True: 0, False: 0]
  ------------------
  205|      0|    ASN1_BIT_STRING_free(ret);
  206|      0|  }
  207|      0|  return NULL;
  208|  40.1k|}

c2i_ASN1_INTEGER:
  177|  40.1k|                               long len) {
  178|       |  // This function can handle lengths up to INT_MAX - 1, but the rest of the
  179|       |  // legacy ASN.1 code mixes integer types, so avoid exposing it to
  180|       |  // ASN1_INTEGERS with larger lengths.
  181|  40.1k|  if (len < 0 || len > INT_MAX / 2) {
  ------------------
  |  Branch (181:7): [True: 0, False: 40.1k]
  |  Branch (181:18): [True: 0, False: 40.1k]
  ------------------
  182|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  183|      0|    return NULL;
  184|      0|  }
  185|       |
  186|  40.1k|  CBS cbs;
  187|  40.1k|  CBS_init(&cbs, *inp, (size_t)len);
  188|  40.1k|  int is_negative;
  189|  40.1k|  if (!CBS_is_valid_asn1_integer(&cbs, &is_negative)) {
  ------------------
  |  Branch (189:7): [True: 0, False: 40.1k]
  ------------------
  190|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  191|      0|    return NULL;
  192|      0|  }
  193|       |
  194|  40.1k|  ASN1_INTEGER *ret = NULL;
  195|  40.1k|  if (out == NULL || *out == NULL) {
  ------------------
  |  Branch (195:7): [True: 0, False: 40.1k]
  |  Branch (195:22): [True: 20.0k, False: 20.0k]
  ------------------
  196|  20.0k|    ret = ASN1_INTEGER_new();
  197|  20.0k|    if (ret == NULL) {
  ------------------
  |  Branch (197:9): [True: 0, False: 20.0k]
  ------------------
  198|      0|      return NULL;
  199|      0|    }
  200|  20.0k|  } else {
  201|  20.0k|    ret = *out;
  202|  20.0k|  }
  203|       |
  204|       |  // Convert to |ASN1_INTEGER|'s sign-and-magnitude representation. First,
  205|       |  // determine the size needed for a minimal result.
  206|  40.1k|  if (is_negative) {
  ------------------
  |  Branch (206:7): [True: 0, False: 40.1k]
  ------------------
  207|       |    // 0xff00...01 through 0xff7f..ff have a two's complement of 0x00ff...ff
  208|       |    // through 0x000100...001 and need one leading zero removed. 0x8000...00
  209|       |    // through 0xff00...00 have a two's complement of 0x8000...00 through
  210|       |    // 0x0100...00 and will be minimally-encoded as-is.
  211|      0|    if (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0xff &&
  ------------------
  |  Branch (211:9): [True: 0, False: 0]
  |  Branch (211:30): [True: 0, False: 0]
  ------------------
  212|      0|        !is_all_zeros(CBS_data(&cbs) + 1, CBS_len(&cbs) - 1)) {
  ------------------
  |  Branch (212:9): [True: 0, False: 0]
  ------------------
  213|      0|      CBS_skip(&cbs, 1);
  214|      0|    }
  215|  40.1k|  } else {
  216|       |    // Remove the leading zero byte, if any.
  217|  40.1k|    if (CBS_len(&cbs) > 0 && CBS_data(&cbs)[0] == 0x00) {
  ------------------
  |  Branch (217:9): [True: 40.1k, False: 0]
  |  Branch (217:30): [True: 20.0k, False: 20.0k]
  ------------------
  218|  20.0k|      CBS_skip(&cbs, 1);
  219|  20.0k|    }
  220|  40.1k|  }
  221|       |
  222|  40.1k|  if (!ASN1_STRING_set(ret, CBS_data(&cbs), CBS_len(&cbs))) {
  ------------------
  |  Branch (222:7): [True: 0, False: 40.1k]
  ------------------
  223|      0|    goto err;
  224|      0|  }
  225|       |
  226|  40.1k|  if (is_negative) {
  ------------------
  |  Branch (226:7): [True: 0, False: 40.1k]
  ------------------
  227|      0|    ret->type = V_ASN1_NEG_INTEGER;
  ------------------
  |  |  156|      0|#define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  126|      0|#define V_ASN1_INTEGER 2
  |  |  ------------------
  |  |               #define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|      0|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  228|      0|    negate_twos_complement(ret->data, ret->length);
  229|  40.1k|  } else {
  230|  40.1k|    ret->type = V_ASN1_INTEGER;
  ------------------
  |  |  126|  40.1k|#define V_ASN1_INTEGER 2
  ------------------
  231|  40.1k|  }
  232|       |
  233|       |  // The value should be minimally-encoded.
  234|  40.1k|  assert(ret->length == 0 || ret->data[0] != 0);
  235|       |  // Zero is not negative.
  236|  40.1k|  assert(!is_negative || ret->length > 0);
  237|       |
  238|  40.1k|  *inp += len;
  239|  40.1k|  if (out != NULL) {
  ------------------
  |  Branch (239:7): [True: 40.1k, False: 0]
  ------------------
  240|  40.1k|    *out = ret;
  241|  40.1k|  }
  242|  40.1k|  return ret;
  243|       |
  244|      0|err:
  245|      0|  if (ret != NULL && (out == NULL || *out != ret)) {
  ------------------
  |  Branch (245:7): [True: 0, False: 0]
  |  Branch (245:23): [True: 0, False: 0]
  |  Branch (245:38): [True: 0, False: 0]
  ------------------
  246|      0|    ASN1_INTEGER_free(ret);
  247|      0|  }
  248|      0|  return NULL;
  249|  40.1k|}
ASN1_INTEGER_get:
  395|  20.0k|long ASN1_INTEGER_get(const ASN1_INTEGER *a) {
  396|  20.0k|  return asn1_string_get_long(a, V_ASN1_INTEGER);
  ------------------
  |  |  126|  20.0k|#define V_ASN1_INTEGER 2
  ------------------
  397|  20.0k|}
a_int.c:asn1_string_get_abs_uint64:
  313|  20.0k|                                      int type) {
  314|  20.0k|  if ((a->type & ~V_ASN1_NEG) != type) {
  ------------------
  |  |  155|  20.0k|#define V_ASN1_NEG 0x100
  ------------------
  |  Branch (314:7): [True: 0, False: 20.0k]
  ------------------
  315|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_INTEGER_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  316|      0|    return 0;
  317|      0|  }
  318|  20.0k|  uint8_t buf[sizeof(uint64_t)] = {0};
  319|  20.0k|  if (a->length > (int)sizeof(buf)) {
  ------------------
  |  Branch (319:7): [True: 0, False: 20.0k]
  ------------------
  320|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  321|      0|    return 0;
  322|      0|  }
  323|  20.0k|  OPENSSL_memcpy(buf + sizeof(buf) - a->length, a->data, a->length);
  324|  20.0k|  *out = CRYPTO_load_u64_be(buf);
  325|  20.0k|  return 1;
  326|  20.0k|}
a_int.c:asn1_string_get_int64:
  348|  20.0k|static int asn1_string_get_int64(int64_t *out, const ASN1_STRING *a, int type) {
  349|  20.0k|  uint64_t v;
  350|  20.0k|  if (!asn1_string_get_abs_uint64(&v, a, type)) {
  ------------------
  |  Branch (350:7): [True: 0, False: 20.0k]
  ------------------
  351|      0|    return 0;
  352|      0|  }
  353|  20.0k|  int64_t i64;
  354|  20.0k|  int fits_in_i64;
  355|       |  // Check |v != 0| to handle manually-constructed negative zeros.
  356|  20.0k|  if ((a->type & V_ASN1_NEG) && v != 0) {
  ------------------
  |  |  155|  20.0k|#define V_ASN1_NEG 0x100
  ------------------
  |  Branch (356:7): [True: 0, False: 20.0k]
  |  Branch (356:33): [True: 0, False: 0]
  ------------------
  357|      0|    i64 = (int64_t)(0u - v);
  358|      0|    fits_in_i64 = i64 < 0;
  359|  20.0k|  } else {
  360|  20.0k|    i64 = (int64_t)v;
  361|  20.0k|    fits_in_i64 = i64 >= 0;
  362|  20.0k|  }
  363|  20.0k|  if (!fits_in_i64) {
  ------------------
  |  Branch (363:7): [True: 0, False: 20.0k]
  ------------------
  364|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_INTEGER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  365|      0|    return 0;
  366|      0|  }
  367|  20.0k|  *out = i64;
  368|  20.0k|  return 1;
  369|  20.0k|}
a_int.c:asn1_string_get_long:
  379|  20.0k|static long asn1_string_get_long(const ASN1_STRING *a, int type) {
  380|  20.0k|  if (a == NULL) {
  ------------------
  |  Branch (380:7): [True: 0, False: 20.0k]
  ------------------
  381|      0|    return 0;
  382|      0|  }
  383|       |
  384|  20.0k|  int64_t v;
  385|  20.0k|  if (!asn1_string_get_int64(&v, a, type) ||  //
  ------------------
  |  Branch (385:7): [True: 0, False: 20.0k]
  ------------------
  386|  20.0k|      v < LONG_MIN || v > LONG_MAX) {
  ------------------
  |  Branch (386:7): [True: 0, False: 20.0k]
  |  Branch (386:23): [True: 0, False: 20.0k]
  ------------------
  387|       |    // This function's return value does not distinguish overflow from -1.
  388|      0|    ERR_clear_error();
  389|      0|    return -1;
  390|      0|  }
  391|       |
  392|  20.0k|  return (long)v;
  393|  20.0k|}

ASN1_mbstring_copy:
   77|  40.1k|                       ossl_ssize_t len, int inform, unsigned long mask) {
   78|  40.1k|  return ASN1_mbstring_ncopy(out, in, len, inform, mask, /*minsize=*/0,
   79|  40.1k|                             /*maxsize=*/0);
   80|  40.1k|}
ASN1_mbstring_ncopy:
   88|  40.1k|                        ossl_ssize_t minsize, ossl_ssize_t maxsize) {
   89|  40.1k|  if (len == -1) {
  ------------------
  |  Branch (89:7): [True: 0, False: 40.1k]
  ------------------
   90|      0|    len = strlen((const char *)in);
   91|      0|  }
   92|  40.1k|  if (!mask) {
  ------------------
  |  Branch (92:7): [True: 0, False: 40.1k]
  ------------------
   93|      0|    mask = DIRSTRING_TYPE;
  ------------------
  |  |  718|      0|  (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  161|      0|#define B_ASN1_PRINTABLESTRING 0x0002
  |  |  ------------------
  |  |                 (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  162|      0|#define B_ASN1_T61STRING 0x0004
  |  |  ------------------
  |  |                 (B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING | \
  |  |  ------------------
  |  |  |  |  173|      0|#define B_ASN1_BMPSTRING 0x0800
  |  |  ------------------
  |  |  719|      0|   B_ASN1_UTF8STRING)
  |  |  ------------------
  |  |  |  |  175|      0|#define B_ASN1_UTF8STRING 0x2000
  |  |  ------------------
  ------------------
   94|      0|  }
   95|       |
   96|  40.1k|  int (*decode_func)(CBS *, uint32_t *);
   97|  40.1k|  int error;
   98|  40.1k|  switch (inform) {
   99|      0|    case MBSTRING_BMP:
  ------------------
  |  |  713|      0|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (99:5): [True: 0, False: 40.1k]
  ------------------
  100|      0|      decode_func = cbs_get_ucs2_be;
  101|      0|      error = ASN1_R_INVALID_BMPSTRING;
  ------------------
  |  | 2009|      0|#define ASN1_R_INVALID_BMPSTRING 142
  ------------------
  102|      0|      break;
  103|       |
  104|      0|    case MBSTRING_UNIV:
  ------------------
  |  |  714|      0|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (104:5): [True: 0, False: 40.1k]
  ------------------
  105|      0|      decode_func = cbs_get_utf32_be;
  106|      0|      error = ASN1_R_INVALID_UNIVERSALSTRING;
  ------------------
  |  | 2016|      0|#define ASN1_R_INVALID_UNIVERSALSTRING 149
  ------------------
  107|      0|      break;
  108|       |
  109|      0|    case MBSTRING_UTF8:
  ------------------
  |  |  711|      0|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (109:5): [True: 0, False: 40.1k]
  ------------------
  110|      0|      decode_func = cbs_get_utf8;
  111|      0|      error = ASN1_R_INVALID_UTF8STRING;
  ------------------
  |  | 2017|      0|#define ASN1_R_INVALID_UTF8STRING 150
  ------------------
  112|      0|      break;
  113|       |
  114|  40.1k|    case MBSTRING_ASC:
  ------------------
  |  |  712|  40.1k|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|  40.1k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (114:5): [True: 40.1k, False: 0]
  ------------------
  115|  40.1k|      decode_func = cbs_get_latin1;
  116|  40.1k|      error = ERR_R_INTERNAL_ERROR;  // Latin-1 inputs are never invalid.
  ------------------
  |  |  387|  40.1k|#define ERR_R_INTERNAL_ERROR (4 | ERR_R_FATAL)
  |  |  ------------------
  |  |  |  |  383|  40.1k|#define ERR_R_FATAL 64
  |  |  ------------------
  ------------------
  117|  40.1k|      break;
  118|       |
  119|      0|    default:
  ------------------
  |  Branch (119:5): [True: 0, False: 40.1k]
  ------------------
  120|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNKNOWN_FORMAT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  121|      0|      return -1;
  122|  40.1k|  }
  123|       |
  124|       |  // Check |minsize| and |maxsize| and work out the minimal type, if any.
  125|  40.1k|  CBS cbs;
  126|  40.1k|  CBS_init(&cbs, in, len);
  127|  40.1k|  size_t utf8_len = 0, nchar = 0;
  128|   321k|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (128:10): [True: 281k, False: 40.1k]
  ------------------
  129|   281k|    uint32_t c;
  130|   281k|    if (!decode_func(&cbs, &c)) {
  ------------------
  |  Branch (130:9): [True: 0, False: 281k]
  ------------------
  131|      0|      OPENSSL_PUT_ERROR(ASN1, error);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|      0|      return -1;
  133|      0|    }
  134|   281k|    if (nchar == 0 && (inform == MBSTRING_BMP || inform == MBSTRING_UNIV) &&
  ------------------
  |  |  713|  80.3k|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|  40.1k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
                  if (nchar == 0 && (inform == MBSTRING_BMP || inform == MBSTRING_UNIV) &&
  ------------------
  |  |  714|  40.1k|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|  40.1k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  |  Branch (134:9): [True: 40.1k, False: 241k]
  |  Branch (134:24): [True: 0, False: 40.1k]
  |  Branch (134:50): [True: 0, False: 40.1k]
  ------------------
  135|   281k|        c == 0xfeff) {
  ------------------
  |  Branch (135:9): [True: 0, False: 0]
  ------------------
  136|       |      // Reject byte-order mark. We could drop it but that would mean
  137|       |      // adding ambiguity around whether a BOM was included or not when
  138|       |      // matching strings.
  139|       |      //
  140|       |      // For a little-endian UCS-2 string, the BOM will appear as 0xfffe
  141|       |      // and will be rejected as noncharacter, below.
  142|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  143|      0|      return -1;
  144|      0|    }
  145|       |
  146|       |    // Update which output formats are still possible.
  147|   281k|    if ((mask & B_ASN1_PRINTABLESTRING) && !asn1_is_printable(c)) {
  ------------------
  |  |  161|   281k|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  |  Branch (147:9): [True: 0, False: 281k]
  |  Branch (147:44): [True: 0, False: 0]
  ------------------
  148|      0|      mask &= ~B_ASN1_PRINTABLESTRING;
  ------------------
  |  |  161|      0|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  149|      0|    }
  150|   281k|    if ((mask & B_ASN1_IA5STRING) && (c > 127)) {
  ------------------
  |  |  165|   281k|#define B_ASN1_IA5STRING 0x0010
  ------------------
  |  Branch (150:9): [True: 0, False: 281k]
  |  Branch (150:38): [True: 0, False: 0]
  ------------------
  151|      0|      mask &= ~B_ASN1_IA5STRING;
  ------------------
  |  |  165|      0|#define B_ASN1_IA5STRING 0x0010
  ------------------
  152|      0|    }
  153|   281k|    if ((mask & B_ASN1_T61STRING) && (c > 0xff)) {
  ------------------
  |  |  162|   281k|#define B_ASN1_T61STRING 0x0004
  ------------------
  |  Branch (153:9): [True: 0, False: 281k]
  |  Branch (153:38): [True: 0, False: 0]
  ------------------
  154|      0|      mask &= ~B_ASN1_T61STRING;
  ------------------
  |  |  162|      0|#define B_ASN1_T61STRING 0x0004
  ------------------
  155|      0|    }
  156|   281k|    if ((mask & B_ASN1_BMPSTRING) && (c > 0xffff)) {
  ------------------
  |  |  173|   281k|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  |  Branch (156:9): [True: 0, False: 281k]
  |  Branch (156:38): [True: 0, False: 0]
  ------------------
  157|      0|      mask &= ~B_ASN1_BMPSTRING;
  ------------------
  |  |  173|      0|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  158|      0|    }
  159|   281k|    if (!mask) {
  ------------------
  |  Branch (159:9): [True: 0, False: 281k]
  ------------------
  160|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  161|      0|      return -1;
  162|      0|    }
  163|       |
  164|   281k|    nchar++;
  165|   281k|    utf8_len += cbb_get_utf8_len(c);
  166|   281k|    if (maxsize > 0 && nchar > (size_t)maxsize) {
  ------------------
  |  Branch (166:9): [True: 0, False: 281k]
  |  Branch (166:24): [True: 0, False: 0]
  ------------------
  167|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|      ERR_add_error_dataf("maxsize=%zu", (size_t)maxsize);
  169|      0|      return -1;
  170|      0|    }
  171|   281k|  }
  172|       |
  173|  40.1k|  if (minsize > 0 && nchar < (size_t)minsize) {
  ------------------
  |  Branch (173:7): [True: 0, False: 40.1k]
  |  Branch (173:22): [True: 0, False: 0]
  ------------------
  174|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_SHORT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  175|      0|    ERR_add_error_dataf("minsize=%zu", (size_t)minsize);
  176|      0|    return -1;
  177|      0|  }
  178|       |
  179|       |  // Now work out output format and string type
  180|  40.1k|  int str_type;
  181|  40.1k|  int (*encode_func)(CBB *, uint32_t) = cbb_add_latin1;
  182|  40.1k|  size_t size_estimate = nchar;
  183|  40.1k|  int outform = MBSTRING_ASC;
  ------------------
  |  |  712|  40.1k|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|  40.1k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  184|  40.1k|  if (mask & B_ASN1_PRINTABLESTRING) {
  ------------------
  |  |  161|  40.1k|#define B_ASN1_PRINTABLESTRING 0x0002
  ------------------
  |  Branch (184:7): [True: 0, False: 40.1k]
  ------------------
  185|      0|    str_type = V_ASN1_PRINTABLESTRING;
  ------------------
  |  |  139|      0|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  186|  40.1k|  } else if (mask & B_ASN1_IA5STRING) {
  ------------------
  |  |  165|  40.1k|#define B_ASN1_IA5STRING 0x0010
  ------------------
  |  Branch (186:14): [True: 0, False: 40.1k]
  ------------------
  187|      0|    str_type = V_ASN1_IA5STRING;
  ------------------
  |  |  143|      0|#define V_ASN1_IA5STRING 22
  ------------------
  188|  40.1k|  } else if (mask & B_ASN1_T61STRING) {
  ------------------
  |  |  162|  40.1k|#define B_ASN1_T61STRING 0x0004
  ------------------
  |  Branch (188:14): [True: 0, False: 40.1k]
  ------------------
  189|      0|    str_type = V_ASN1_T61STRING;
  ------------------
  |  |  140|      0|#define V_ASN1_T61STRING 20
  ------------------
  190|  40.1k|  } else if (mask & B_ASN1_BMPSTRING) {
  ------------------
  |  |  173|  40.1k|#define B_ASN1_BMPSTRING 0x0800
  ------------------
  |  Branch (190:14): [True: 0, False: 40.1k]
  ------------------
  191|      0|    str_type = V_ASN1_BMPSTRING;
  ------------------
  |  |  151|      0|#define V_ASN1_BMPSTRING 30
  ------------------
  192|      0|    outform = MBSTRING_BMP;
  ------------------
  |  |  713|      0|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  193|      0|    encode_func = cbb_add_ucs2_be;
  194|      0|    size_estimate = 2 * nchar;
  195|  40.1k|  } else if (mask & B_ASN1_UNIVERSALSTRING) {
  ------------------
  |  |  170|  40.1k|#define B_ASN1_UNIVERSALSTRING 0x0100
  ------------------
  |  Branch (195:14): [True: 0, False: 40.1k]
  ------------------
  196|      0|    str_type = V_ASN1_UNIVERSALSTRING;
  ------------------
  |  |  150|      0|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  197|      0|    encode_func = cbb_add_utf32_be;
  198|      0|    size_estimate = 4 * nchar;
  199|      0|    outform = MBSTRING_UNIV;
  ------------------
  |  |  714|      0|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  200|  40.1k|  } else if (mask & B_ASN1_UTF8STRING) {
  ------------------
  |  |  175|  40.1k|#define B_ASN1_UTF8STRING 0x2000
  ------------------
  |  Branch (200:14): [True: 40.1k, False: 0]
  ------------------
  201|  40.1k|    str_type = V_ASN1_UTF8STRING;
  ------------------
  |  |  135|  40.1k|#define V_ASN1_UTF8STRING 12
  ------------------
  202|  40.1k|    outform = MBSTRING_UTF8;
  ------------------
  |  |  711|  40.1k|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|  40.1k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  203|  40.1k|    encode_func = cbb_add_utf8;
  204|  40.1k|    size_estimate = utf8_len;
  205|  40.1k|  } else {
  206|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_CHARACTERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  207|      0|    return -1;
  208|      0|  }
  209|       |
  210|  40.1k|  if (!out) {
  ------------------
  |  Branch (210:7): [True: 0, False: 40.1k]
  ------------------
  211|      0|    return str_type;
  212|      0|  }
  213|       |
  214|  40.1k|  int free_dest = 0;
  215|  40.1k|  ASN1_STRING *dest;
  216|  40.1k|  if (*out) {
  ------------------
  |  Branch (216:7): [True: 40.1k, False: 0]
  ------------------
  217|  40.1k|    dest = *out;
  218|  40.1k|  } else {
  219|      0|    free_dest = 1;
  220|      0|    dest = ASN1_STRING_type_new(str_type);
  221|      0|    if (!dest) {
  ------------------
  |  Branch (221:9): [True: 0, False: 0]
  ------------------
  222|      0|      return -1;
  223|      0|    }
  224|      0|  }
  225|       |
  226|  40.1k|  CBB cbb;
  227|  40.1k|  CBB_zero(&cbb);
  228|       |  // If both the same type just copy across
  229|  40.1k|  if (inform == outform) {
  ------------------
  |  Branch (229:7): [True: 0, False: 40.1k]
  ------------------
  230|      0|    if (!ASN1_STRING_set(dest, in, len)) {
  ------------------
  |  Branch (230:9): [True: 0, False: 0]
  ------------------
  231|      0|      goto err;
  232|      0|    }
  233|      0|    dest->type = str_type;
  234|      0|    *out = dest;
  235|      0|    return str_type;
  236|      0|  }
  237|  40.1k|  if (!CBB_init(&cbb, size_estimate + 1)) {
  ------------------
  |  Branch (237:7): [True: 0, False: 40.1k]
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|  40.1k|  CBS_init(&cbs, in, len);
  241|   321k|  while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (241:10): [True: 281k, False: 40.1k]
  ------------------
  242|   281k|    uint32_t c;
  243|   281k|    if (!decode_func(&cbs, &c) || !encode_func(&cbb, c)) {
  ------------------
  |  Branch (243:9): [True: 0, False: 281k]
  |  Branch (243:35): [True: 0, False: 281k]
  ------------------
  244|      0|      OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  245|      0|      goto err;
  246|      0|    }
  247|   281k|  }
  248|  40.1k|  uint8_t *data = NULL;
  249|  40.1k|  size_t data_len;
  250|  40.1k|  if (// OpenSSL historically NUL-terminated this value with a single byte,
  251|       |      // even for |MBSTRING_BMP| and |MBSTRING_UNIV|.
  252|  40.1k|      !CBB_add_u8(&cbb, 0) || !CBB_finish(&cbb, &data, &data_len) ||
  ------------------
  |  Branch (252:7): [True: 0, False: 40.1k]
  |  Branch (252:31): [True: 0, False: 40.1k]
  ------------------
  253|  40.1k|      data_len < 1 || data_len > INT_MAX) {
  ------------------
  |  Branch (253:7): [True: 0, False: 40.1k]
  |  Branch (253:23): [True: 0, False: 40.1k]
  ------------------
  254|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  255|      0|    OPENSSL_free(data);
  256|      0|    goto err;
  257|      0|  }
  258|  40.1k|  dest->type = str_type;
  259|  40.1k|  ASN1_STRING_set0(dest, data, (int)data_len - 1);
  260|  40.1k|  *out = dest;
  261|  40.1k|  return str_type;
  262|       |
  263|      0|err:
  264|      0|  if (free_dest) {
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|      0|    ASN1_STRING_free(dest);
  266|      0|  }
  267|      0|  CBB_cleanup(&cbb);
  268|      0|  return -1;
  269|  40.1k|}

c2i_ASN1_OBJECT:
  157|   180k|                             long len) {
  158|   180k|  if (len < 0) {
  ------------------
  |  Branch (158:7): [True: 0, False: 180k]
  ------------------
  159|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_OBJECT_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  160|      0|    return NULL;
  161|      0|  }
  162|       |
  163|   180k|  CBS cbs;
  164|   180k|  CBS_init(&cbs, *inp, (size_t)len);
  165|   180k|  if (!CBS_is_valid_asn1_oid(&cbs)) {
  ------------------
  |  Branch (165:7): [True: 0, False: 180k]
  ------------------
  166|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_OBJECT_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  167|      0|    return NULL;
  168|      0|  }
  169|       |
  170|   180k|  ASN1_OBJECT *ret = ASN1_OBJECT_create(NID_undef, *inp, (size_t)len,
  ------------------
  |  |   85|   180k|#define NID_undef 0
  ------------------
  171|       |                                        /*sn=*/NULL, /*ln=*/NULL);
  172|   180k|  if (ret == NULL) {
  ------------------
  |  Branch (172:7): [True: 0, False: 180k]
  ------------------
  173|      0|    return NULL;
  174|      0|  }
  175|       |
  176|   180k|  if (out != NULL) {
  ------------------
  |  Branch (176:7): [True: 180k, False: 0]
  ------------------
  177|   180k|    ASN1_OBJECT_free(*out);
  178|   180k|    *out = ret;
  179|   180k|  }
  180|   180k|  *inp += len;  // All bytes were consumed.
  181|   180k|  return ret;
  182|   180k|}
ASN1_OBJECT_new:
  184|   221k|ASN1_OBJECT *ASN1_OBJECT_new(void) {
  185|   221k|  ASN1_OBJECT *ret;
  186|       |
  187|   221k|  ret = (ASN1_OBJECT *)OPENSSL_malloc(sizeof(ASN1_OBJECT));
  188|   221k|  if (ret == NULL) {
  ------------------
  |  Branch (188:7): [True: 0, False: 221k]
  ------------------
  189|      0|    return NULL;
  190|      0|  }
  191|   221k|  ret->length = 0;
  192|   221k|  ret->data = NULL;
  193|   221k|  ret->nid = 0;
  194|   221k|  ret->sn = NULL;
  195|   221k|  ret->ln = NULL;
  196|   221k|  ret->flags = ASN1_OBJECT_FLAG_DYNAMIC;
  ------------------
  |  |  105|   221k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  197|   221k|  return ret;
  198|   221k|}
ASN1_OBJECT_free:
  200|   401k|void ASN1_OBJECT_free(ASN1_OBJECT *a) {
  201|   401k|  if (a == NULL) {
  ------------------
  |  Branch (201:7): [True: 0, False: 401k]
  ------------------
  202|      0|    return;
  203|      0|  }
  204|   401k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC_STRINGS) {
  ------------------
  |  |  106|   401k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  |  Branch (204:7): [True: 220k, False: 180k]
  ------------------
  205|   220k|    OPENSSL_free((void *)a->sn);
  206|   220k|    OPENSSL_free((void *)a->ln);
  207|   220k|    a->sn = a->ln = NULL;
  208|   220k|  }
  209|   401k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC_DATA) {
  ------------------
  |  |  107|   401k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  |  Branch (209:7): [True: 220k, False: 180k]
  ------------------
  210|   220k|    OPENSSL_free((void *)a->data);
  211|   220k|    a->data = NULL;
  212|   220k|    a->length = 0;
  213|   220k|  }
  214|   401k|  if (a->flags & ASN1_OBJECT_FLAG_DYNAMIC) {
  ------------------
  |  |  105|   401k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  |  Branch (214:7): [True: 220k, False: 180k]
  ------------------
  215|   220k|    OPENSSL_free(a);
  216|   220k|  }
  217|   401k|}
ASN1_OBJECT_create:
  220|   180k|                                const char *sn, const char *ln) {
  221|   180k|  if (len > INT_MAX) {
  ------------------
  |  Branch (221:7): [True: 0, False: 180k]
  ------------------
  222|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_STRING_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  223|      0|    return NULL;
  224|      0|  }
  225|       |
  226|   180k|  ASN1_OBJECT o;
  227|   180k|  o.sn = sn;
  228|   180k|  o.ln = ln;
  229|   180k|  o.data = data;
  230|   180k|  o.nid = nid;
  231|   180k|  o.length = (int)len;
  232|   180k|  o.flags = ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  105|   180k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
                o.flags = ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  106|   180k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  233|   180k|            ASN1_OBJECT_FLAG_DYNAMIC_DATA;
  ------------------
  |  |  107|   180k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  234|   180k|  return OBJ_dup(&o);
  235|   180k|}

ASN1_STRING_to_UTF8:
  376|  40.1k|int ASN1_STRING_to_UTF8(unsigned char **out, const ASN1_STRING *in) {
  377|  40.1k|  if (!in) {
  ------------------
  |  Branch (377:7): [True: 0, False: 40.1k]
  ------------------
  378|      0|    return -1;
  379|      0|  }
  380|  40.1k|  int mbflag = string_type_to_encoding(in->type);
  381|  40.1k|  if (mbflag == -1) {
  ------------------
  |  Branch (381:7): [True: 0, False: 40.1k]
  ------------------
  382|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNKNOWN_TAG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  383|      0|    return -1;
  384|      0|  }
  385|  40.1k|  ASN1_STRING stmp, *str = &stmp;
  386|  40.1k|  stmp.data = NULL;
  387|  40.1k|  stmp.length = 0;
  388|  40.1k|  stmp.flags = 0;
  389|  40.1k|  int ret =
  390|  40.1k|      ASN1_mbstring_copy(&str, in->data, in->length, mbflag, B_ASN1_UTF8STRING);
  ------------------
  |  |  175|  40.1k|#define B_ASN1_UTF8STRING 0x2000
  ------------------
  391|  40.1k|  if (ret < 0) {
  ------------------
  |  Branch (391:7): [True: 0, False: 40.1k]
  ------------------
  392|      0|    return ret;
  393|      0|  }
  394|  40.1k|  *out = stmp.data;
  395|  40.1k|  return stmp.length;
  396|  40.1k|}
a_strex.c:string_type_to_encoding:
  273|  40.1k|static int string_type_to_encoding(int type) {
  274|       |  // This function is sometimes passed ASN.1 universal types and sometimes
  275|       |  // passed |ASN1_STRING| type values
  276|  40.1k|  switch (type) {
  ------------------
  |  Branch (276:11): [True: 0, False: 40.1k]
  ------------------
  277|      0|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|      0|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (277:5): [True: 0, False: 40.1k]
  ------------------
  278|      0|      return MBSTRING_UTF8;
  ------------------
  |  |  711|      0|#define MBSTRING_UTF8 (MBSTRING_FLAG)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  279|      0|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|      0|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (279:5): [True: 0, False: 40.1k]
  ------------------
  280|  40.1k|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|  40.1k|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (280:5): [True: 40.1k, False: 0]
  ------------------
  281|  40.1k|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|  40.1k|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (281:5): [True: 0, False: 40.1k]
  ------------------
  282|  40.1k|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|  40.1k|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (282:5): [True: 0, False: 40.1k]
  ------------------
  283|  40.1k|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|  40.1k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (283:5): [True: 0, False: 40.1k]
  ------------------
  284|  40.1k|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|  40.1k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (284:5): [True: 0, False: 40.1k]
  ------------------
  285|  40.1k|    case V_ASN1_ISO64STRING:
  ------------------
  |  |  147|  40.1k|#define V_ASN1_ISO64STRING 26
  ------------------
  |  Branch (285:5): [True: 0, False: 40.1k]
  ------------------
  286|       |      // |MBSTRING_ASC| refers to Latin-1, not ASCII.
  287|  40.1k|      return MBSTRING_ASC;
  ------------------
  |  |  712|  40.1k|#define MBSTRING_ASC (MBSTRING_FLAG | 1)
  |  |  ------------------
  |  |  |  |  710|  40.1k|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  288|      0|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|      0|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (288:5): [True: 0, False: 40.1k]
  ------------------
  289|      0|      return MBSTRING_UNIV;
  ------------------
  |  |  714|      0|#define MBSTRING_UNIV (MBSTRING_FLAG | 4)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  290|      0|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|      0|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (290:5): [True: 0, False: 40.1k]
  ------------------
  291|      0|      return MBSTRING_BMP;
  ------------------
  |  |  713|      0|#define MBSTRING_BMP (MBSTRING_FLAG | 2)
  |  |  ------------------
  |  |  |  |  710|      0|#define MBSTRING_FLAG 0x1000
  |  |  ------------------
  ------------------
  292|  40.1k|  }
  293|      0|  return -1;
  294|  40.1k|}

asn1_type_cleanup:
   92|   120k|void asn1_type_cleanup(ASN1_TYPE *a) {
   93|   120k|  switch (a->type) {
   94|  60.2k|    case V_ASN1_NULL:
  ------------------
  |  |  129|  60.2k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (94:5): [True: 60.2k, False: 60.2k]
  ------------------
   95|  60.2k|      a->value.ptr = NULL;
   96|  60.2k|      break;
   97|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (97:5): [True: 0, False: 120k]
  ------------------
   98|      0|      a->value.boolean = ASN1_BOOLEAN_NONE;
  ------------------
  |  |  432|      0|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
   99|      0|      break;
  100|      0|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|      0|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (100:5): [True: 0, False: 120k]
  ------------------
  101|      0|      ASN1_OBJECT_free(a->value.object);
  102|      0|      a->value.object = NULL;
  103|      0|      break;
  104|  60.2k|    default:
  ------------------
  |  Branch (104:5): [True: 60.2k, False: 60.2k]
  ------------------
  105|  60.2k|      ASN1_STRING_free(a->value.asn1_string);
  106|  60.2k|      a->value.asn1_string = NULL;
  107|  60.2k|      break;
  108|   120k|  }
  109|   120k|}
ASN1_TYPE_set:
  111|  60.2k|void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value) {
  112|  60.2k|  asn1_type_cleanup(a);
  113|  60.2k|  a->type = type;
  114|  60.2k|  switch (type) {
  115|  60.2k|    case V_ASN1_NULL:
  ------------------
  |  |  129|  60.2k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (115:5): [True: 60.2k, False: 0]
  ------------------
  116|  60.2k|      a->value.ptr = NULL;
  117|  60.2k|      break;
  118|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (118:5): [True: 0, False: 60.2k]
  ------------------
  119|      0|      a->value.boolean = value ? ASN1_BOOLEAN_TRUE : ASN1_BOOLEAN_FALSE;
  ------------------
  |  |  427|      0|#define ASN1_BOOLEAN_TRUE 0xff
  ------------------
                    a->value.boolean = value ? ASN1_BOOLEAN_TRUE : ASN1_BOOLEAN_FALSE;
  ------------------
  |  |  423|      0|#define ASN1_BOOLEAN_FALSE 0
  ------------------
  |  Branch (119:26): [True: 0, False: 0]
  ------------------
  120|      0|      break;
  121|      0|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|      0|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (121:5): [True: 0, False: 60.2k]
  ------------------
  122|      0|      a->value.object = value;
  123|      0|      break;
  124|      0|    default:
  ------------------
  |  Branch (124:5): [True: 0, False: 60.2k]
  ------------------
  125|      0|      a->value.asn1_string = value;
  126|      0|      break;
  127|  60.2k|  }
  128|  60.2k|}

ASN1_get_object:
  108|  1.10M|                    int *out_class, long in_len) {
  109|  1.10M|  if (in_len < 0) {
  ------------------
  |  Branch (109:7): [True: 0, False: 1.10M]
  ------------------
  110|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|      0|    return 0x80;
  112|      0|  }
  113|       |
  114|  1.10M|  CBS_ASN1_TAG tag;
  115|  1.10M|  CBS cbs, body;
  116|  1.10M|  CBS_init(&cbs, *inp, (size_t)in_len);
  117|  1.10M|  if (!CBS_get_any_asn1(&cbs, &body, &tag) ||
  ------------------
  |  Branch (117:7): [True: 0, False: 1.10M]
  ------------------
  118|       |      // Bound the length to comfortably fit in an int. Lengths in this
  119|       |      // module often switch between int and long without overflow checks.
  120|  1.10M|      CBS_len(&body) > INT_MAX / 2) {
  ------------------
  |  Branch (120:7): [True: 0, False: 1.10M]
  ------------------
  121|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  122|      0|    return 0x80;
  123|      0|  }
  124|       |
  125|       |  // Convert between tag representations.
  126|  1.10M|  int tag_class = (tag & CBS_ASN1_CLASS_MASK) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  207|  1.10M|#define CBS_ASN1_CLASS_MASK (0xc0u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  1.10M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                int tag_class = (tag & CBS_ASN1_CLASS_MASK) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  1.10M|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  127|  1.10M|  int constructed = (tag & CBS_ASN1_CONSTRUCTED) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  196|  1.10M|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  1.10M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                int constructed = (tag & CBS_ASN1_CONSTRUCTED) >> CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  1.10M|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  128|  1.10M|  int tag_number = tag & CBS_ASN1_TAG_NUMBER_MASK;
  ------------------
  |  |  210|  1.10M|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  1.10M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  129|       |
  130|       |  // To avoid ambiguity with V_ASN1_NEG, impose a limit on universal tags.
  131|  1.10M|  if (tag_class == V_ASN1_UNIVERSAL && tag_number > V_ASN1_MAX_UNIVERSAL) {
  ------------------
  |  |   92|  2.21M|#define V_ASN1_UNIVERSAL 0x00
  ------------------
                if (tag_class == V_ASN1_UNIVERSAL && tag_number > V_ASN1_MAX_UNIVERSAL) {
  ------------------
  |  |  112|  1.02M|#define V_ASN1_MAX_UNIVERSAL 0xff
  ------------------
  |  Branch (131:7): [True: 1.02M, False: 80.3k]
  |  Branch (131:40): [True: 0, False: 1.02M]
  ------------------
  132|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_HEADER_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  133|      0|    return 0x80;
  134|      0|  }
  135|       |
  136|  1.10M|  *inp = CBS_data(&body);
  137|  1.10M|  *out_len = CBS_len(&body);
  138|  1.10M|  *out_tag = tag_number;
  139|  1.10M|  *out_class = tag_class;
  140|  1.10M|  return constructed;
  141|  1.10M|}
ASN1_put_object:
  145|   295k|                     int xclass) {
  146|   295k|  unsigned char *p = *pp;
  147|   295k|  int i, ttag;
  148|       |
  149|   295k|  i = (constructed) ? V_ASN1_CONSTRUCTED : 0;
  ------------------
  |  |   99|   114k|#define V_ASN1_CONSTRUCTED 0x20
  ------------------
  |  Branch (149:7): [True: 114k, False: 181k]
  ------------------
  150|   295k|  i |= (xclass & V_ASN1_PRIVATE);
  ------------------
  |  |   95|   295k|#define V_ASN1_PRIVATE 0xc0
  ------------------
  151|   295k|  if (tag < 31) {
  ------------------
  |  Branch (151:7): [True: 295k, False: 0]
  ------------------
  152|   295k|    *(p++) = i | (tag & V_ASN1_PRIMITIVE_TAG);
  ------------------
  |  |  106|   295k|#define V_ASN1_PRIMITIVE_TAG 0x1f
  ------------------
  153|   295k|  } else {
  154|      0|    *(p++) = i | V_ASN1_PRIMITIVE_TAG;
  ------------------
  |  |  106|      0|#define V_ASN1_PRIMITIVE_TAG 0x1f
  ------------------
  155|      0|    for (i = 0, ttag = tag; ttag > 0; i++) {
  ------------------
  |  Branch (155:29): [True: 0, False: 0]
  ------------------
  156|      0|      ttag >>= 7;
  157|      0|    }
  158|      0|    ttag = i;
  159|      0|    while (i-- > 0) {
  ------------------
  |  Branch (159:12): [True: 0, False: 0]
  ------------------
  160|      0|      p[i] = tag & 0x7f;
  161|      0|      if (i != (ttag - 1)) {
  ------------------
  |  Branch (161:11): [True: 0, False: 0]
  ------------------
  162|      0|        p[i] |= 0x80;
  163|      0|      }
  164|      0|      tag >>= 7;
  165|      0|    }
  166|      0|    p += ttag;
  167|      0|  }
  168|   295k|  if (constructed == 2) {
  ------------------
  |  Branch (168:7): [True: 0, False: 295k]
  ------------------
  169|      0|    *(p++) = 0x80;
  170|   295k|  } else {
  171|   295k|    asn1_put_length(&p, length);
  172|   295k|  }
  173|   295k|  *pp = p;
  174|   295k|}
ASN1_object_size:
  207|   859k|int ASN1_object_size(int constructed, int length, int tag) {
  208|   859k|  int ret = 1;
  209|   859k|  if (length < 0) {
  ------------------
  |  Branch (209:7): [True: 0, False: 859k]
  ------------------
  210|      0|    return -1;
  211|      0|  }
  212|   859k|  if (tag >= 31) {
  ------------------
  |  Branch (212:7): [True: 0, False: 859k]
  ------------------
  213|      0|    while (tag > 0) {
  ------------------
  |  Branch (213:12): [True: 0, False: 0]
  ------------------
  214|      0|      tag >>= 7;
  215|      0|      ret++;
  216|      0|    }
  217|      0|  }
  218|   859k|  if (constructed == 2) {
  ------------------
  |  Branch (218:7): [True: 0, False: 859k]
  ------------------
  219|      0|    ret += 3;
  220|   859k|  } else {
  221|   859k|    ret++;
  222|   859k|    if (length > 127) {
  ------------------
  |  Branch (222:9): [True: 67.4k, False: 792k]
  ------------------
  223|  67.4k|      int tmplen = length;
  224|   202k|      while (tmplen > 0) {
  ------------------
  |  Branch (224:14): [True: 134k, False: 67.4k]
  ------------------
  225|   134k|        tmplen >>= 8;
  226|   134k|        ret++;
  227|   134k|      }
  228|  67.4k|    }
  229|   859k|  }
  230|   859k|  if (ret >= INT_MAX - length) {
  ------------------
  |  Branch (230:7): [True: 0, False: 859k]
  ------------------
  231|      0|    return -1;
  232|      0|  }
  233|   859k|  return ret + length;
  234|   859k|}
ASN1_STRING_set:
  264|   200k|int ASN1_STRING_set(ASN1_STRING *str, const void *_data, ossl_ssize_t len_s) {
  265|   200k|  const char *data = _data;
  266|   200k|  size_t len;
  267|   200k|  if (len_s < 0) {
  ------------------
  |  Branch (267:7): [True: 0, False: 200k]
  ------------------
  268|      0|    if (data == NULL) {
  ------------------
  |  Branch (268:9): [True: 0, False: 0]
  ------------------
  269|      0|      return 0;
  270|      0|    }
  271|      0|    len = strlen(data);
  272|   200k|  } else {
  273|   200k|    len = (size_t)len_s;
  274|   200k|  }
  275|       |
  276|       |  // |ASN1_STRING| cannot represent strings that exceed |int|, and we must
  277|       |  // reserve space for a trailing NUL below.
  278|   200k|  if (len > INT_MAX || len + 1 < len) {
  ------------------
  |  Branch (278:7): [True: 0, False: 200k]
  |  Branch (278:24): [True: 0, False: 200k]
  ------------------
  279|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  280|      0|    return 0;
  281|      0|  }
  282|       |
  283|   200k|  if (str->length <= (int)len || str->data == NULL) {
  ------------------
  |  Branch (283:7): [True: 200k, False: 0]
  |  Branch (283:34): [True: 0, False: 0]
  ------------------
  284|   200k|    unsigned char *c = str->data;
  285|   200k|    if (c == NULL) {
  ------------------
  |  Branch (285:9): [True: 200k, False: 0]
  ------------------
  286|   200k|      str->data = OPENSSL_malloc(len + 1);
  287|   200k|    } else {
  288|      0|      str->data = OPENSSL_realloc(c, len + 1);
  289|      0|    }
  290|       |
  291|   200k|    if (str->data == NULL) {
  ------------------
  |  Branch (291:9): [True: 0, False: 200k]
  ------------------
  292|      0|      str->data = c;
  293|      0|      return 0;
  294|      0|    }
  295|   200k|  }
  296|   200k|  str->length = (int)len;
  297|   200k|  if (data != NULL) {
  ------------------
  |  Branch (297:7): [True: 200k, False: 0]
  ------------------
  298|   200k|    OPENSSL_memcpy(str->data, data, len);
  299|       |    // Historically, OpenSSL would NUL-terminate most (but not all)
  300|       |    // |ASN1_STRING|s, in case anyone accidentally passed |str->data| into a
  301|       |    // function expecting a C string. We retain this behavior for compatibility,
  302|       |    // but code must not rely on this. See CVE-2021-3712.
  303|   200k|    str->data[len] = '\0';
  304|   200k|  }
  305|   200k|  return 1;
  306|   200k|}
ASN1_STRING_set0:
  308|  40.1k|void ASN1_STRING_set0(ASN1_STRING *str, void *data, int len) {
  309|  40.1k|  OPENSSL_free(str->data);
  310|  40.1k|  str->data = data;
  311|  40.1k|  str->length = len;
  312|  40.1k|}
ASN1_STRING_type_new:
  318|   281k|ASN1_STRING *ASN1_STRING_type_new(int type) {
  319|   281k|  ASN1_STRING *ret;
  320|       |
  321|   281k|  ret = (ASN1_STRING *)OPENSSL_malloc(sizeof(ASN1_STRING));
  322|   281k|  if (ret == NULL) {
  ------------------
  |  Branch (322:7): [True: 0, False: 281k]
  ------------------
  323|      0|    return NULL;
  324|      0|  }
  325|   281k|  ret->length = 0;
  326|   281k|  ret->type = type;
  327|   281k|  ret->data = NULL;
  328|   281k|  ret->flags = 0;
  329|   281k|  return ret;
  330|   281k|}
ASN1_STRING_free:
  332|   441k|void ASN1_STRING_free(ASN1_STRING *str) {
  333|   441k|  if (str == NULL) {
  ------------------
  |  Branch (333:7): [True: 160k, False: 281k]
  ------------------
  334|   160k|    return;
  335|   160k|  }
  336|   281k|  OPENSSL_free(str->data);
  337|   281k|  OPENSSL_free(str);
  338|   281k|}
asn1_lib.c:asn1_put_length:
  186|   295k|static void asn1_put_length(unsigned char **pp, int length) {
  187|   295k|  unsigned char *p = *pp;
  188|   295k|  int i, l;
  189|   295k|  if (length <= 127) {
  ------------------
  |  Branch (189:7): [True: 261k, False: 33.7k]
  ------------------
  190|   261k|    *(p++) = (unsigned char)length;
  191|   261k|  } else {
  192|  33.7k|    l = length;
  193|   101k|    for (i = 0; l > 0; i++) {
  ------------------
  |  Branch (193:17): [True: 67.4k, False: 33.7k]
  ------------------
  194|  67.4k|      l >>= 8;
  195|  67.4k|    }
  196|  33.7k|    *(p++) = i | 0x80;
  197|  33.7k|    l = i;
  198|   101k|    while (i-- > 0) {
  ------------------
  |  Branch (198:12): [True: 67.4k, False: 33.7k]
  ------------------
  199|  67.4k|      p[i] = length & 0xff;
  200|  67.4k|      length >>= 8;
  201|  67.4k|    }
  202|  33.7k|    p += l;
  203|  33.7k|  }
  204|   295k|  *pp = p;
  205|   295k|}

ASN1_tag2bit:
  132|   120k|unsigned long ASN1_tag2bit(int tag) {
  133|   120k|  if (tag < 0 || tag > 30) {
  ------------------
  |  Branch (133:7): [True: 0, False: 120k]
  |  Branch (133:18): [True: 0, False: 120k]
  ------------------
  134|      0|    return 0;
  135|      0|  }
  136|   120k|  return tag2bit[tag];
  137|   120k|}
ASN1_item_d2i:
  164|  20.0k|                          const ASN1_ITEM *it) {
  165|  20.0k|  ASN1_VALUE *ret = NULL;
  166|  20.0k|  if (asn1_item_ex_d2i(&ret, in, len, it, /*tag=*/-1, /*aclass=*/0, /*opt=*/0,
  ------------------
  |  Branch (166:7): [True: 0, False: 20.0k]
  ------------------
  167|       |                       /*buf=*/NULL, /*depth=*/0) <= 0) {
  168|       |    // Clean up, in case the caller left a partial object.
  169|       |    //
  170|       |    // TODO(davidben): I don't think it can leave one, but the codepaths below
  171|       |    // are a bit inconsistent. Revisit this when rewriting this function.
  172|      0|    ASN1_item_ex_free(&ret, it);
  173|      0|  }
  174|       |
  175|       |  // If the caller supplied an output pointer, free the old one and replace it
  176|       |  // with |ret|. This differs from OpenSSL slightly in that we don't support
  177|       |  // object reuse. We run this on both success and failure. On failure, even
  178|       |  // with object reuse, OpenSSL destroys the previous object.
  179|  20.0k|  if (pval != NULL) {
  ------------------
  |  Branch (179:7): [True: 0, False: 20.0k]
  ------------------
  180|      0|    ASN1_item_ex_free(pval, it);
  181|      0|    *pval = ret;
  182|      0|  }
  183|  20.0k|  return ret;
  184|  20.0k|}
ASN1_item_ex_d2i:
  493|  60.2k|                     CRYPTO_BUFFER *buf) {
  494|  60.2k|  return asn1_item_ex_d2i(pval, in, len, it, tag, aclass, opt, buf,
  495|  60.2k|                          /*depth=*/0);
  496|  60.2k|}
tasn_dec.c:asn1_item_ex_d2i:
  197|   944k|                            char opt, CRYPTO_BUFFER *buf, int depth) {
  198|   944k|  const ASN1_TEMPLATE *tt, *errtt = NULL;
  199|   944k|  const unsigned char *p = NULL, *q;
  200|   944k|  unsigned char oclass;
  201|   944k|  char cst, isopt;
  202|   944k|  int i;
  203|   944k|  int otag;
  204|   944k|  int ret = 0;
  205|   944k|  ASN1_VALUE **pchptr;
  206|   944k|  if (!pval) {
  ------------------
  |  Branch (206:7): [True: 0, False: 944k]
  ------------------
  207|      0|    return 0;
  208|      0|  }
  209|       |
  210|   944k|  if (buf != NULL) {
  ------------------
  |  Branch (210:7): [True: 683k, False: 261k]
  ------------------
  211|   683k|    assert(CRYPTO_BUFFER_data(buf) <= *in &&
  212|   683k|           *in + len <= CRYPTO_BUFFER_data(buf) + CRYPTO_BUFFER_len(buf));
  213|   683k|  }
  214|       |
  215|       |  // Bound |len| to comfortably fit in an int. Lengths in this module often
  216|       |  // switch between int and long without overflow checks.
  217|   944k|  if (len > INT_MAX / 2) {
  ------------------
  |  Branch (217:7): [True: 0, False: 944k]
  ------------------
  218|      0|    len = INT_MAX / 2;
  219|      0|  }
  220|       |
  221|   944k|  if (++depth > ASN1_MAX_CONSTRUCTED_NEST) {
  ------------------
  |  |   76|   944k|#define ASN1_MAX_CONSTRUCTED_NEST 30
  ------------------
  |  Branch (221:7): [True: 0, False: 944k]
  ------------------
  222|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_TOO_DEEP);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  223|      0|    goto err;
  224|      0|  }
  225|       |
  226|   944k|  switch (it->itype) {
  227|   582k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   582k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (227:5): [True: 582k, False: 361k]
  ------------------
  228|   582k|      if (it->templates) {
  ------------------
  |  Branch (228:11): [True: 80.3k, False: 502k]
  ------------------
  229|       |        // tagging or OPTIONAL is currently illegal on an item template
  230|       |        // because the flags can't get passed down. In practice this
  231|       |        // isn't a problem: we include the relevant flags from the item
  232|       |        // template in the template itself.
  233|  80.3k|        if ((tag != -1) || opt) {
  ------------------
  |  Branch (233:13): [True: 0, False: 80.3k]
  |  Branch (233:28): [True: 0, False: 80.3k]
  ------------------
  234|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OPTIONS_ON_ITEM_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  235|      0|          goto err;
  236|      0|        }
  237|  80.3k|        return asn1_template_ex_d2i(pval, in, len, it->templates, opt, buf,
  238|  80.3k|                                    depth);
  239|  80.3k|      }
  240|   502k|      return asn1_d2i_ex_primitive(pval, in, len, it, tag, aclass, opt);
  241|      0|      break;
  242|       |
  243|  80.3k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|  80.3k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (243:5): [True: 80.3k, False: 863k]
  ------------------
  244|       |      // It never makes sense for multi-strings to have implicit tagging, so
  245|       |      // if tag != -1, then this looks like an error in the template.
  246|  80.3k|      if (tag != -1) {
  ------------------
  |  Branch (246:11): [True: 0, False: 80.3k]
  ------------------
  247|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  248|      0|        goto err;
  249|      0|      }
  250|       |
  251|  80.3k|      p = *in;
  252|       |      // Just read in tag and class
  253|  80.3k|      ret = asn1_check_tlen(NULL, &otag, &oclass, NULL, &p, len, -1, 0, 1);
  254|  80.3k|      if (!ret) {
  ------------------
  |  Branch (254:11): [True: 0, False: 80.3k]
  ------------------
  255|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  256|      0|        goto err;
  257|      0|      }
  258|       |
  259|       |      // Must be UNIVERSAL class
  260|  80.3k|      if (oclass != V_ASN1_UNIVERSAL) {
  ------------------
  |  |   92|  80.3k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (260:11): [True: 0, False: 80.3k]
  ------------------
  261|       |        // If OPTIONAL, assume this is OK
  262|      0|        if (opt) {
  ------------------
  |  Branch (262:13): [True: 0, False: 0]
  ------------------
  263|      0|          return -1;
  264|      0|        }
  265|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_MSTRING_NOT_UNIVERSAL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      0|        goto err;
  267|      0|      }
  268|       |      // Check tag matches bit map
  269|  80.3k|      if (!(ASN1_tag2bit(otag) & it->utype)) {
  ------------------
  |  Branch (269:11): [True: 0, False: 80.3k]
  ------------------
  270|       |        // If OPTIONAL, assume this is OK
  271|      0|        if (opt) {
  ------------------
  |  Branch (271:13): [True: 0, False: 0]
  ------------------
  272|      0|          return -1;
  273|      0|        }
  274|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_MSTRING_WRONG_TAG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  275|      0|        goto err;
  276|      0|      }
  277|  80.3k|      return asn1_d2i_ex_primitive(pval, in, len, it, otag, 0, 0);
  278|       |
  279|  40.1k|    case ASN1_ITYPE_EXTERN: {
  ------------------
  |  |  493|  40.1k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (279:5): [True: 40.1k, False: 904k]
  ------------------
  280|       |      // We don't support implicit tagging with external types.
  281|  40.1k|      if (tag != -1) {
  ------------------
  |  Branch (281:11): [True: 0, False: 40.1k]
  ------------------
  282|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  283|      0|        goto err;
  284|      0|      }
  285|  40.1k|      const ASN1_EXTERN_FUNCS *ef = it->funcs;
  286|  40.1k|      return ef->asn1_ex_d2i(pval, in, len, it, opt, NULL);
  287|  40.1k|    }
  288|       |
  289|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (289:5): [True: 0, False: 944k]
  ------------------
  290|       |      // It never makes sense for CHOICE types to have implicit tagging, so if
  291|       |      // tag != -1, then this looks like an error in the template.
  292|      0|      if (tag != -1) {
  ------------------
  |  Branch (292:11): [True: 0, False: 0]
  ------------------
  293|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  294|      0|        goto err;
  295|      0|      }
  296|       |
  297|      0|      const ASN1_AUX *aux = it->funcs;
  298|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (298:30): [True: 0, False: 0]
  ------------------
  299|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_PRE, pval, it, NULL)) {
  ------------------
  |  |  541|      0|#define ASN1_OP_D2I_PRE		4
  ------------------
  |  Branch (299:11): [True: 0, False: 0]
  |  Branch (299:22): [True: 0, False: 0]
  ------------------
  300|      0|        goto auxerr;
  301|      0|      }
  302|       |
  303|      0|      if (*pval) {
  ------------------
  |  Branch (303:11): [True: 0, False: 0]
  ------------------
  304|       |        // Free up and zero CHOICE value if initialised
  305|      0|        i = asn1_get_choice_selector(pval, it);
  306|      0|        if ((i >= 0) && (i < it->tcount)) {
  ------------------
  |  Branch (306:13): [True: 0, False: 0]
  |  Branch (306:25): [True: 0, False: 0]
  ------------------
  307|      0|          tt = it->templates + i;
  308|      0|          pchptr = asn1_get_field_ptr(pval, tt);
  309|      0|          ASN1_template_free(pchptr, tt);
  310|      0|          asn1_set_choice_selector(pval, -1, it);
  311|      0|        }
  312|      0|      } else if (!ASN1_item_ex_new(pval, it)) {
  ------------------
  |  Branch (312:18): [True: 0, False: 0]
  ------------------
  313|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  314|      0|        goto err;
  315|      0|      }
  316|       |      // CHOICE type, try each possibility in turn
  317|      0|      p = *in;
  318|      0|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (318:39): [True: 0, False: 0]
  ------------------
  319|      0|        pchptr = asn1_get_field_ptr(pval, tt);
  320|       |        // We mark field as OPTIONAL so its absence can be recognised.
  321|      0|        ret = asn1_template_ex_d2i(pchptr, &p, len, tt, 1, buf, depth);
  322|       |        // If field not present, try the next one
  323|      0|        if (ret == -1) {
  ------------------
  |  Branch (323:13): [True: 0, False: 0]
  ------------------
  324|      0|          continue;
  325|      0|        }
  326|       |        // If positive return, read OK, break loop
  327|      0|        if (ret > 0) {
  ------------------
  |  Branch (327:13): [True: 0, False: 0]
  ------------------
  328|      0|          break;
  329|      0|        }
  330|       |        // Otherwise must be an ASN1 parsing error
  331|      0|        errtt = tt;
  332|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  333|      0|        goto err;
  334|      0|      }
  335|       |
  336|       |      // Did we fall off the end without reading anything?
  337|      0|      if (i == it->tcount) {
  ------------------
  |  Branch (337:11): [True: 0, False: 0]
  ------------------
  338|       |        // If OPTIONAL, this is OK
  339|      0|        if (opt) {
  ------------------
  |  Branch (339:13): [True: 0, False: 0]
  ------------------
  340|       |          // Free and zero it
  341|      0|          ASN1_item_ex_free(pval, it);
  342|      0|          return -1;
  343|      0|        }
  344|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NO_MATCHING_CHOICE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|        goto err;
  346|      0|      }
  347|       |
  348|      0|      asn1_set_choice_selector(pval, i, it);
  349|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_POST, pval, it, NULL)) {
  ------------------
  |  |  542|      0|#define ASN1_OP_D2I_POST	5
  ------------------
  |  Branch (349:11): [True: 0, False: 0]
  |  Branch (349:22): [True: 0, False: 0]
  ------------------
  350|      0|        goto auxerr;
  351|      0|      }
  352|      0|      *in = p;
  353|      0|      return 1;
  354|      0|    }
  355|       |
  356|   241k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|   241k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (356:5): [True: 241k, False: 703k]
  ------------------
  357|   241k|      p = *in;
  358|       |
  359|       |      // If no IMPLICIT tagging set to SEQUENCE, UNIVERSAL
  360|   241k|      if (tag == -1) {
  ------------------
  |  Branch (360:11): [True: 241k, False: 0]
  ------------------
  361|   241k|        tag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|   241k|#define V_ASN1_SEQUENCE 16
  ------------------
  362|   241k|        aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|   241k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  363|   241k|      }
  364|       |      // Get SEQUENCE length and update len, p
  365|   241k|      ret = asn1_check_tlen(&len, NULL, NULL, &cst, &p, len, tag, aclass, opt);
  366|   241k|      if (!ret) {
  ------------------
  |  Branch (366:11): [True: 0, False: 241k]
  ------------------
  367|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  368|      0|        goto err;
  369|   241k|      } else if (ret == -1) {
  ------------------
  |  Branch (369:18): [True: 0, False: 241k]
  ------------------
  370|      0|        return -1;
  371|      0|      }
  372|   241k|      if (!cst) {
  ------------------
  |  Branch (372:11): [True: 0, False: 241k]
  ------------------
  373|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_SEQUENCE_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  374|      0|        goto err;
  375|      0|      }
  376|       |
  377|   241k|      if (!*pval && !ASN1_item_ex_new(pval, it)) {
  ------------------
  |  Branch (377:11): [True: 160k, False: 80.3k]
  |  Branch (377:21): [True: 0, False: 160k]
  ------------------
  378|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  379|      0|        goto err;
  380|      0|      }
  381|       |
  382|   241k|      const ASN1_AUX *aux = it->funcs;
  383|   241k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (383:30): [True: 40.1k, False: 200k]
  ------------------
  384|   241k|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_PRE, pval, it, NULL)) {
  ------------------
  |  |  541|  20.0k|#define ASN1_OP_D2I_PRE		4
  ------------------
  |  Branch (384:11): [True: 20.0k, False: 221k]
  |  Branch (384:22): [True: 0, False: 20.0k]
  ------------------
  385|      0|        goto auxerr;
  386|      0|      }
  387|       |
  388|       |      // Free up and zero any ADB found
  389|   964k|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (389:39): [True: 723k, False: 241k]
  ------------------
  390|   723k|        if (tt->flags & ASN1_TFLG_ADB_MASK) {
  ------------------
  |  |  435|   723k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (390:13): [True: 0, False: 723k]
  ------------------
  391|      0|          const ASN1_TEMPLATE *seqtt;
  392|      0|          ASN1_VALUE **pseqval;
  393|      0|          seqtt = asn1_do_adb(pval, tt, 0);
  394|      0|          if (seqtt == NULL) {
  ------------------
  |  Branch (394:15): [True: 0, False: 0]
  ------------------
  395|      0|            continue;
  396|      0|          }
  397|      0|          pseqval = asn1_get_field_ptr(pval, seqtt);
  398|      0|          ASN1_template_free(pseqval, seqtt);
  399|      0|        }
  400|   723k|      }
  401|       |
  402|       |      // Get each field entry
  403|   964k|      for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
  ------------------
  |  Branch (403:39): [True: 723k, False: 241k]
  ------------------
  404|   723k|        const ASN1_TEMPLATE *seqtt;
  405|   723k|        ASN1_VALUE **pseqval;
  406|   723k|        seqtt = asn1_do_adb(pval, tt, 1);
  407|   723k|        if (seqtt == NULL) {
  ------------------
  |  Branch (407:13): [True: 0, False: 723k]
  ------------------
  408|      0|          goto err;
  409|      0|        }
  410|   723k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  411|       |        // Have we ran out of data?
  412|   723k|        if (!len) {
  ------------------
  |  Branch (412:13): [True: 0, False: 723k]
  ------------------
  413|      0|          break;
  414|      0|        }
  415|   723k|        q = p;
  416|       |        // This determines the OPTIONAL flag value. The field cannot be
  417|       |        // omitted if it is the last of a SEQUENCE and there is still
  418|       |        // data to be read. This isn't strictly necessary but it
  419|       |        // increases efficiency in some cases.
  420|   723k|        if (i == (it->tcount - 1)) {
  ------------------
  |  Branch (420:13): [True: 241k, False: 482k]
  ------------------
  421|   241k|          isopt = 0;
  422|   482k|        } else {
  423|   482k|          isopt = (seqtt->flags & ASN1_TFLG_OPTIONAL) != 0;
  ------------------
  |  |  381|   482k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  424|   482k|        }
  425|       |        // attempt to read in field, allowing each to be OPTIONAL
  426|       |
  427|   723k|        ret = asn1_template_ex_d2i(pseqval, &p, len, seqtt, isopt, buf, depth);
  428|   723k|        if (!ret) {
  ------------------
  |  Branch (428:13): [True: 0, False: 723k]
  ------------------
  429|      0|          errtt = seqtt;
  430|      0|          goto err;
  431|   723k|        } else if (ret == -1) {
  ------------------
  |  Branch (431:20): [True: 80.3k, False: 642k]
  ------------------
  432|       |          // OPTIONAL component absent. Free and zero the field.
  433|  80.3k|          ASN1_template_free(pseqval, seqtt);
  434|  80.3k|          continue;
  435|  80.3k|        }
  436|       |        // Update length
  437|   642k|        len -= p - q;
  438|   642k|      }
  439|       |
  440|       |      // Check all data read
  441|   241k|      if (len) {
  ------------------
  |  Branch (441:11): [True: 0, False: 241k]
  ------------------
  442|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_SEQUENCE_LENGTH_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  443|      0|        goto err;
  444|      0|      }
  445|       |
  446|       |      // If we get here we've got no more data in the SEQUENCE, however we
  447|       |      // may not have read all fields so check all remaining are OPTIONAL
  448|       |      // and clear any that are.
  449|   241k|      for (; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (449:14): [True: 0, False: 241k]
  ------------------
  450|      0|        const ASN1_TEMPLATE *seqtt;
  451|      0|        seqtt = asn1_do_adb(pval, tt, 1);
  452|      0|        if (seqtt == NULL) {
  ------------------
  |  Branch (452:13): [True: 0, False: 0]
  ------------------
  453|      0|          goto err;
  454|      0|        }
  455|      0|        if (seqtt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|      0|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (455:13): [True: 0, False: 0]
  ------------------
  456|      0|          ASN1_VALUE **pseqval;
  457|      0|          pseqval = asn1_get_field_ptr(pval, seqtt);
  458|      0|          ASN1_template_free(pseqval, seqtt);
  459|      0|        } else {
  460|      0|          errtt = seqtt;
  461|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_FIELD_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  462|      0|          goto err;
  463|      0|        }
  464|      0|      }
  465|       |      // Save encoding
  466|   241k|      if (!asn1_enc_save(pval, *in, p - *in, it, buf)) {
  ------------------
  |  Branch (466:11): [True: 0, False: 241k]
  ------------------
  467|      0|        goto auxerr;
  468|      0|      }
  469|   241k|      if (asn1_cb && !asn1_cb(ASN1_OP_D2I_POST, pval, it, NULL)) {
  ------------------
  |  |  542|  20.0k|#define ASN1_OP_D2I_POST	5
  ------------------
  |  Branch (469:11): [True: 20.0k, False: 221k]
  |  Branch (469:22): [True: 0, False: 20.0k]
  ------------------
  470|      0|        goto auxerr;
  471|      0|      }
  472|   241k|      *in = p;
  473|   241k|      return 1;
  474|   241k|    }
  475|       |
  476|      0|    default:
  ------------------
  |  Branch (476:5): [True: 0, False: 944k]
  ------------------
  477|      0|      return 0;
  478|   944k|  }
  479|      0|auxerr:
  480|      0|  OPENSSL_PUT_ERROR(ASN1, ASN1_R_AUX_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  481|      0|err:
  482|      0|  ASN1_item_ex_free(pval, it);
  483|      0|  if (errtt) {
  ------------------
  |  Branch (483:7): [True: 0, False: 0]
  ------------------
  484|      0|    ERR_add_error_data(4, "Field=", errtt->field_name, ", Type=", it->sname);
  485|      0|  } else {
  486|      0|    ERR_add_error_data(2, "Type=", it->sname);
  487|      0|  }
  488|      0|  return 0;
  489|      0|}
tasn_dec.c:asn1_template_ex_d2i:
  503|   803k|                                CRYPTO_BUFFER *buf, int depth) {
  504|   803k|  int aclass;
  505|   803k|  int ret;
  506|   803k|  long len;
  507|   803k|  const unsigned char *p, *q;
  508|   803k|  if (!val) {
  ------------------
  |  Branch (508:7): [True: 0, False: 803k]
  ------------------
  509|      0|    return 0;
  510|      0|  }
  511|   803k|  uint32_t flags = tt->flags;
  512|   803k|  aclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|   803k|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  513|       |
  514|   803k|  p = *in;
  515|       |
  516|       |  // Check if EXPLICIT tag expected
  517|   803k|  if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|   803k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (517:7): [True: 40.1k, False: 763k]
  ------------------
  518|  40.1k|    char cst;
  519|       |    // Need to work out amount of data available to the inner content and
  520|       |    // where it starts: so read in EXPLICIT header to get the info.
  521|  40.1k|    ret = asn1_check_tlen(&len, NULL, NULL, &cst, &p, inlen, tt->tag, aclass,
  522|  40.1k|                          opt);
  523|  40.1k|    q = p;
  524|  40.1k|    if (!ret) {
  ------------------
  |  Branch (524:9): [True: 0, False: 40.1k]
  ------------------
  525|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  526|      0|      return 0;
  527|  40.1k|    } else if (ret == -1) {
  ------------------
  |  Branch (527:16): [True: 0, False: 40.1k]
  ------------------
  528|      0|      return -1;
  529|      0|    }
  530|  40.1k|    if (!cst) {
  ------------------
  |  Branch (530:9): [True: 0, False: 40.1k]
  ------------------
  531|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_EXPLICIT_TAG_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  532|      0|      return 0;
  533|      0|    }
  534|       |    // We've found the field so it can't be OPTIONAL now
  535|  40.1k|    ret = asn1_template_noexp_d2i(val, &p, len, tt, /*opt=*/0, buf, depth);
  536|  40.1k|    if (!ret) {
  ------------------
  |  Branch (536:9): [True: 0, False: 40.1k]
  ------------------
  537|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  538|      0|      return 0;
  539|      0|    }
  540|       |    // We read the field in OK so update length
  541|  40.1k|    len -= p - q;
  542|       |    // Check for trailing data.
  543|  40.1k|    if (len) {
  ------------------
  |  Branch (543:9): [True: 0, False: 40.1k]
  ------------------
  544|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_EXPLICIT_LENGTH_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  545|      0|      goto err;
  546|      0|    }
  547|   763k|  } else {
  548|   763k|    return asn1_template_noexp_d2i(val, in, inlen, tt, opt, buf, depth);
  549|   763k|  }
  550|       |
  551|  40.1k|  *in = p;
  552|  40.1k|  return 1;
  553|       |
  554|      0|err:
  555|      0|  ASN1_template_free(val, tt);
  556|      0|  return 0;
  557|   803k|}
tasn_dec.c:asn1_template_noexp_d2i:
  561|   803k|                                   CRYPTO_BUFFER *buf, int depth) {
  562|   803k|  int aclass;
  563|   803k|  int ret;
  564|   803k|  const unsigned char *p;
  565|   803k|  if (!val) {
  ------------------
  |  Branch (565:7): [True: 0, False: 803k]
  ------------------
  566|      0|    return 0;
  567|      0|  }
  568|   803k|  uint32_t flags = tt->flags;
  569|   803k|  aclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|   803k|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  570|       |
  571|   803k|  p = *in;
  572|       |
  573|   803k|  if (flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   803k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (573:7): [True: 100k, False: 703k]
  ------------------
  574|       |    // SET OF, SEQUENCE OF
  575|   100k|    int sktag, skaclass;
  576|       |    // First work out expected inner tag value
  577|   100k|    if (flags & ASN1_TFLG_IMPTAG) {
  ------------------
  |  |  398|   100k|#define ASN1_TFLG_IMPTAG	(0x1 << 3)
  ------------------
  |  Branch (577:9): [True: 0, False: 100k]
  ------------------
  578|      0|      sktag = tt->tag;
  579|      0|      skaclass = aclass;
  580|   100k|    } else {
  581|   100k|      skaclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|   100k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  582|   100k|      if (flags & ASN1_TFLG_SET_OF) {
  ------------------
  |  |  384|   100k|#define ASN1_TFLG_SET_OF	(0x1 << 1)
  ------------------
  |  Branch (582:11): [True: 40.1k, False: 60.2k]
  ------------------
  583|  40.1k|        sktag = V_ASN1_SET;
  ------------------
  |  |  137|  40.1k|#define V_ASN1_SET 17
  ------------------
  584|  60.2k|      } else {
  585|  60.2k|        sktag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|  60.2k|#define V_ASN1_SEQUENCE 16
  ------------------
  586|  60.2k|      }
  587|   100k|    }
  588|       |    // Get the tag
  589|   100k|    ret =
  590|   100k|        asn1_check_tlen(&len, NULL, NULL, NULL, &p, len, sktag, skaclass, opt);
  591|   100k|    if (!ret) {
  ------------------
  |  Branch (591:9): [True: 0, False: 100k]
  ------------------
  592|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  593|      0|      return 0;
  594|   100k|    } else if (ret == -1) {
  ------------------
  |  Branch (594:16): [True: 0, False: 100k]
  ------------------
  595|      0|      return -1;
  596|      0|    }
  597|   100k|    if (!*val) {
  ------------------
  |  Branch (597:9): [True: 100k, False: 0]
  ------------------
  598|   100k|      *val = (ASN1_VALUE *)sk_ASN1_VALUE_new_null();
  599|   100k|    } else {
  600|       |      // We've got a valid STACK: free up any items present
  601|      0|      STACK_OF(ASN1_VALUE) *sktmp = (STACK_OF(ASN1_VALUE) *)*val;
  ------------------
  |  |   81|      0|#define STACK_OF(type) struct stack_st_##type
  ------------------
  602|      0|      ASN1_VALUE *vtmp;
  603|      0|      while (sk_ASN1_VALUE_num(sktmp) > 0) {
  ------------------
  |  Branch (603:14): [True: 0, False: 0]
  ------------------
  604|      0|        vtmp = sk_ASN1_VALUE_pop(sktmp);
  605|      0|        ASN1_item_ex_free(&vtmp, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  606|      0|      }
  607|      0|    }
  608|       |
  609|   100k|    if (!*val) {
  ------------------
  |  Branch (609:9): [True: 0, False: 100k]
  ------------------
  610|      0|      goto err;
  611|      0|    }
  612|       |
  613|       |    // Read as many items as we can
  614|   261k|    while (len > 0) {
  ------------------
  |  Branch (614:12): [True: 160k, False: 100k]
  ------------------
  615|   160k|      ASN1_VALUE *skfield;
  616|   160k|      const unsigned char *q = p;
  617|   160k|      skfield = NULL;
  618|   160k|      if (!asn1_item_ex_d2i(&skfield, &p, len, ASN1_ITEM_ptr(tt->item),
  ------------------
  |  |  288|   160k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (618:11): [True: 0, False: 160k]
  ------------------
  619|   160k|                            /*tag=*/-1, /*aclass=*/0, /*opt=*/0, buf, depth)) {
  620|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  621|      0|        goto err;
  622|      0|      }
  623|   160k|      len -= p - q;
  624|   160k|      if (!sk_ASN1_VALUE_push((STACK_OF(ASN1_VALUE) *)*val, skfield)) {
  ------------------
  |  Branch (624:11): [True: 0, False: 160k]
  ------------------
  625|      0|        ASN1_item_ex_free(&skfield, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  626|      0|        goto err;
  627|      0|      }
  628|   160k|    }
  629|   703k|  } else if (flags & ASN1_TFLG_IMPTAG) {
  ------------------
  |  |  398|   703k|#define ASN1_TFLG_IMPTAG	(0x1 << 3)
  ------------------
  |  Branch (629:14): [True: 40.1k, False: 663k]
  ------------------
  630|       |    // IMPLICIT tagging
  631|  40.1k|    ret = asn1_item_ex_d2i(val, &p, len, ASN1_ITEM_ptr(tt->item), tt->tag,
  ------------------
  |  |  288|  40.1k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  632|  40.1k|                           aclass, opt, buf, depth);
  633|  40.1k|    if (!ret) {
  ------------------
  |  Branch (633:9): [True: 0, False: 40.1k]
  ------------------
  634|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  635|      0|      goto err;
  636|  40.1k|    } else if (ret == -1) {
  ------------------
  |  Branch (636:16): [True: 40.1k, False: 0]
  ------------------
  637|  40.1k|      return -1;
  638|  40.1k|    }
  639|   663k|  } else {
  640|       |    // Nothing special
  641|   663k|    ret = asn1_item_ex_d2i(val, &p, len, ASN1_ITEM_ptr(tt->item), /*tag=*/-1,
  ------------------
  |  |  288|   663k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  642|   663k|                           /*aclass=*/0, opt, buf, depth);
  643|   663k|    if (!ret) {
  ------------------
  |  Branch (643:9): [True: 0, False: 663k]
  ------------------
  644|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  645|      0|      goto err;
  646|   663k|    } else if (ret == -1) {
  ------------------
  |  Branch (646:16): [True: 40.1k, False: 622k]
  ------------------
  647|  40.1k|      return -1;
  648|  40.1k|    }
  649|   663k|  }
  650|       |
  651|   723k|  *in = p;
  652|   723k|  return 1;
  653|       |
  654|      0|err:
  655|      0|  ASN1_template_free(val, tt);
  656|      0|  return 0;
  657|   803k|}
tasn_dec.c:asn1_d2i_ex_primitive:
  661|   582k|                                 int aclass, char opt) {
  662|   582k|  int ret = 0, utype;
  663|   582k|  long plen;
  664|   582k|  char cst;
  665|   582k|  const unsigned char *p;
  666|   582k|  const unsigned char *cont = NULL;
  667|   582k|  long len;
  668|   582k|  if (!pval) {
  ------------------
  |  Branch (668:7): [True: 0, False: 582k]
  ------------------
  669|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_NULL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  670|      0|    return 0;  // Should never happen
  671|      0|  }
  672|       |
  673|   582k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|   582k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (673:7): [True: 80.3k, False: 502k]
  ------------------
  674|  80.3k|    utype = tag;
  675|  80.3k|    tag = -1;
  676|   502k|  } else {
  677|   502k|    utype = it->utype;
  678|   502k|  }
  679|       |
  680|   582k|  if (utype == V_ASN1_ANY) {
  ------------------
  |  |  121|   582k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (680:7): [True: 60.2k, False: 522k]
  ------------------
  681|       |    // If type is ANY need to figure out type from tag
  682|  60.2k|    unsigned char oclass;
  683|  60.2k|    if (tag >= 0) {
  ------------------
  |  Branch (683:9): [True: 0, False: 60.2k]
  ------------------
  684|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_TAGGED_ANY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  685|      0|      return 0;
  686|      0|    }
  687|  60.2k|    if (opt) {
  ------------------
  |  Branch (687:9): [True: 0, False: 60.2k]
  ------------------
  688|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OPTIONAL_ANY);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  689|      0|      return 0;
  690|      0|    }
  691|  60.2k|    p = *in;
  692|  60.2k|    ret = asn1_check_tlen(NULL, &utype, &oclass, NULL, &p, inlen, -1, 0, 0);
  693|  60.2k|    if (!ret) {
  ------------------
  |  Branch (693:9): [True: 0, False: 60.2k]
  ------------------
  694|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  695|      0|      return 0;
  696|      0|    }
  697|  60.2k|    if (!is_supported_universal_type(utype, oclass)) {
  ------------------
  |  Branch (697:9): [True: 0, False: 60.2k]
  ------------------
  698|      0|      utype = V_ASN1_OTHER;
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  699|      0|    }
  700|  60.2k|  }
  701|   582k|  if (tag == -1) {
  ------------------
  |  Branch (701:7): [True: 542k, False: 40.1k]
  ------------------
  702|   542k|    tag = utype;
  703|   542k|    aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|   542k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  704|   542k|  }
  705|   582k|  p = *in;
  706|       |  // Check header
  707|   582k|  ret = asn1_check_tlen(&plen, NULL, NULL, &cst, &p, inlen, tag, aclass, opt);
  708|   582k|  if (!ret) {
  ------------------
  |  Branch (708:7): [True: 0, False: 582k]
  ------------------
  709|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_NESTED_ASN1_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  710|      0|    return 0;
  711|   582k|  } else if (ret == -1) {
  ------------------
  |  Branch (711:14): [True: 80.3k, False: 502k]
  ------------------
  712|  80.3k|    return -1;
  713|  80.3k|  }
  714|   502k|  ret = 0;
  715|       |  // SEQUENCE, SET and "OTHER" are left in encoded form
  716|   502k|  if ((utype == V_ASN1_SEQUENCE) || (utype == V_ASN1_SET) ||
  ------------------
  |  |  136|   502k|#define V_ASN1_SEQUENCE 16
  ------------------
                if ((utype == V_ASN1_SEQUENCE) || (utype == V_ASN1_SET) ||
  ------------------
  |  |  137|   502k|#define V_ASN1_SET 17
  ------------------
  |  Branch (716:7): [True: 0, False: 502k]
  |  Branch (716:37): [True: 0, False: 502k]
  ------------------
  717|   502k|      (utype == V_ASN1_OTHER)) {
  ------------------
  |  |  118|   502k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (717:7): [True: 0, False: 502k]
  ------------------
  718|       |    // SEQUENCE and SET must be constructed
  719|      0|    if (utype != V_ASN1_OTHER && !cst) {
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (719:9): [True: 0, False: 0]
  |  Branch (719:34): [True: 0, False: 0]
  ------------------
  720|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_TYPE_NOT_CONSTRUCTED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  721|      0|      return 0;
  722|      0|    }
  723|       |
  724|      0|    cont = *in;
  725|      0|    len = p - cont + plen;
  726|      0|    p += plen;
  727|   502k|  } else if (cst) {
  ------------------
  |  Branch (727:14): [True: 0, False: 502k]
  ------------------
  728|       |    // This parser historically supported BER constructed strings. We no
  729|       |    // longer do and will gradually tighten this parser into a DER
  730|       |    // parser. BER types should use |CBS_asn1_ber_to_der|.
  731|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_TYPE_NOT_PRIMITIVE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  732|      0|    return 0;
  733|   502k|  } else {
  734|   502k|    cont = p;
  735|   502k|    len = plen;
  736|   502k|    p += plen;
  737|   502k|  }
  738|       |
  739|       |  // We now have content length and type: translate into a structure
  740|   502k|  if (!asn1_ex_c2i(pval, cont, len, utype, it)) {
  ------------------
  |  Branch (740:7): [True: 0, False: 502k]
  ------------------
  741|      0|    goto err;
  742|      0|  }
  743|       |
  744|   502k|  *in = p;
  745|   502k|  ret = 1;
  746|   502k|err:
  747|   502k|  return ret;
  748|   502k|}
tasn_dec.c:is_supported_universal_type:
  139|  60.2k|static int is_supported_universal_type(int tag, int aclass) {
  140|  60.2k|  if (aclass != V_ASN1_UNIVERSAL) {
  ------------------
  |  |   92|  60.2k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (140:7): [True: 0, False: 60.2k]
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|  60.2k|  return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  130|   120k|#define V_ASN1_OBJECT 6
  ------------------
                return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  129|   120k|#define V_ASN1_NULL 5
  ------------------
                return tag == V_ASN1_OBJECT || tag == V_ASN1_NULL || tag == V_ASN1_BOOLEAN ||
  ------------------
  |  |  125|  60.2k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (143:10): [True: 0, False: 60.2k]
  |  Branch (143:34): [True: 60.2k, False: 0]
  |  Branch (143:56): [True: 0, False: 0]
  ------------------
  144|  60.2k|         tag == V_ASN1_BIT_STRING || tag == V_ASN1_INTEGER ||
  ------------------
  |  |  127|  60.2k|#define V_ASN1_BIT_STRING 3
  ------------------
                       tag == V_ASN1_BIT_STRING || tag == V_ASN1_INTEGER ||
  ------------------
  |  |  126|  60.2k|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (144:10): [True: 0, False: 0]
  |  Branch (144:38): [True: 0, False: 0]
  ------------------
  145|  60.2k|         tag == V_ASN1_ENUMERATED || tag == V_ASN1_OCTET_STRING ||
  ------------------
  |  |  134|  60.2k|#define V_ASN1_ENUMERATED 10
  ------------------
                       tag == V_ASN1_ENUMERATED || tag == V_ASN1_OCTET_STRING ||
  ------------------
  |  |  128|  60.2k|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (145:10): [True: 0, False: 0]
  |  Branch (145:38): [True: 0, False: 0]
  ------------------
  146|  60.2k|         tag == V_ASN1_NUMERICSTRING || tag == V_ASN1_PRINTABLESTRING ||
  ------------------
  |  |  138|  60.2k|#define V_ASN1_NUMERICSTRING 18
  ------------------
                       tag == V_ASN1_NUMERICSTRING || tag == V_ASN1_PRINTABLESTRING ||
  ------------------
  |  |  139|  60.2k|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (146:10): [True: 0, False: 0]
  |  Branch (146:41): [True: 0, False: 0]
  ------------------
  147|  60.2k|         tag == V_ASN1_T61STRING || tag == V_ASN1_VIDEOTEXSTRING ||
  ------------------
  |  |  140|  60.2k|#define V_ASN1_T61STRING 20
  ------------------
                       tag == V_ASN1_T61STRING || tag == V_ASN1_VIDEOTEXSTRING ||
  ------------------
  |  |  142|  60.2k|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (147:10): [True: 0, False: 0]
  |  Branch (147:37): [True: 0, False: 0]
  ------------------
  148|  60.2k|         tag == V_ASN1_IA5STRING || tag == V_ASN1_UTCTIME ||
  ------------------
  |  |  143|  60.2k|#define V_ASN1_IA5STRING 22
  ------------------
                       tag == V_ASN1_IA5STRING || tag == V_ASN1_UTCTIME ||
  ------------------
  |  |  144|  60.2k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (148:10): [True: 0, False: 0]
  |  Branch (148:37): [True: 0, False: 0]
  ------------------
  149|  60.2k|         tag == V_ASN1_GENERALIZEDTIME || tag == V_ASN1_GRAPHICSTRING ||
  ------------------
  |  |  145|  60.2k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
                       tag == V_ASN1_GENERALIZEDTIME || tag == V_ASN1_GRAPHICSTRING ||
  ------------------
  |  |  146|  60.2k|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (149:10): [True: 0, False: 0]
  |  Branch (149:43): [True: 0, False: 0]
  ------------------
  150|  60.2k|         tag == V_ASN1_VISIBLESTRING || tag == V_ASN1_GENERALSTRING ||
  ------------------
  |  |  148|  60.2k|#define V_ASN1_VISIBLESTRING 26
  ------------------
                       tag == V_ASN1_VISIBLESTRING || tag == V_ASN1_GENERALSTRING ||
  ------------------
  |  |  149|  60.2k|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (150:10): [True: 0, False: 0]
  |  Branch (150:41): [True: 0, False: 0]
  ------------------
  151|  60.2k|         tag == V_ASN1_UNIVERSALSTRING || tag == V_ASN1_BMPSTRING ||
  ------------------
  |  |  150|  60.2k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
                       tag == V_ASN1_UNIVERSALSTRING || tag == V_ASN1_BMPSTRING ||
  ------------------
  |  |  151|  60.2k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (151:10): [True: 0, False: 0]
  |  Branch (151:43): [True: 0, False: 0]
  ------------------
  152|  60.2k|         tag == V_ASN1_UTF8STRING || tag == V_ASN1_SET ||
  ------------------
  |  |  135|  60.2k|#define V_ASN1_UTF8STRING 12
  ------------------
                       tag == V_ASN1_UTF8STRING || tag == V_ASN1_SET ||
  ------------------
  |  |  137|  60.2k|#define V_ASN1_SET 17
  ------------------
  |  Branch (152:10): [True: 0, False: 0]
  |  Branch (152:38): [True: 0, False: 0]
  ------------------
  153|  60.2k|         tag == V_ASN1_SEQUENCE;
  ------------------
  |  |  136|      0|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (153:10): [True: 0, False: 0]
  ------------------
  154|  60.2k|}
tasn_dec.c:asn1_ex_c2i:
  753|   502k|                       int utype, const ASN1_ITEM *it) {
  754|   502k|  ASN1_VALUE **opval = NULL;
  755|   502k|  ASN1_STRING *stmp;
  756|   502k|  ASN1_TYPE *typ = NULL;
  757|   502k|  int ret = 0;
  758|   502k|  ASN1_INTEGER **tint;
  759|       |
  760|       |  // Historically, |it->funcs| for primitive types contained an
  761|       |  // |ASN1_PRIMITIVE_FUNCS| table of callbacks.
  762|   502k|  assert(it->funcs == NULL);
  763|       |
  764|       |  // If ANY type clear type and set pointer to internal value
  765|   502k|  if (it->utype == V_ASN1_ANY) {
  ------------------
  |  |  121|   502k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (765:7): [True: 60.2k, False: 442k]
  ------------------
  766|  60.2k|    if (!*pval) {
  ------------------
  |  Branch (766:9): [True: 60.2k, False: 0]
  ------------------
  767|  60.2k|      typ = ASN1_TYPE_new();
  768|  60.2k|      if (typ == NULL) {
  ------------------
  |  Branch (768:11): [True: 0, False: 60.2k]
  ------------------
  769|      0|        goto err;
  770|      0|      }
  771|  60.2k|      *pval = (ASN1_VALUE *)typ;
  772|  60.2k|    } else {
  773|      0|      typ = (ASN1_TYPE *)*pval;
  774|      0|    }
  775|       |
  776|  60.2k|    if (utype != typ->type) {
  ------------------
  |  Branch (776:9): [True: 60.2k, False: 0]
  ------------------
  777|  60.2k|      ASN1_TYPE_set(typ, utype, NULL);
  778|  60.2k|    }
  779|  60.2k|    opval = pval;
  780|  60.2k|    pval = &typ->value.asn1_value;
  781|  60.2k|  }
  782|   502k|  switch (utype) {
  783|   180k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|   180k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (783:5): [True: 180k, False: 321k]
  ------------------
  784|   180k|      if (!c2i_ASN1_OBJECT((ASN1_OBJECT **)pval, &cont, len)) {
  ------------------
  |  Branch (784:11): [True: 0, False: 180k]
  ------------------
  785|      0|        goto err;
  786|      0|      }
  787|   180k|      break;
  788|       |
  789|   180k|    case V_ASN1_NULL:
  ------------------
  |  |  129|  60.2k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (789:5): [True: 60.2k, False: 442k]
  ------------------
  790|  60.2k|      if (len) {
  ------------------
  |  Branch (790:11): [True: 0, False: 60.2k]
  ------------------
  791|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NULL_IS_WRONG_LENGTH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  792|      0|        goto err;
  793|      0|      }
  794|  60.2k|      *pval = (ASN1_VALUE *)1;
  795|  60.2k|      break;
  796|       |
  797|  40.1k|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|  40.1k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (797:5): [True: 40.1k, False: 462k]
  ------------------
  798|  40.1k|      if (len != 1) {
  ------------------
  |  Branch (798:11): [True: 0, False: 40.1k]
  ------------------
  799|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BOOLEAN_IS_WRONG_LENGTH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  800|      0|        goto err;
  801|  40.1k|      } else {
  802|  40.1k|        ASN1_BOOLEAN *tbool;
  803|  40.1k|        tbool = (ASN1_BOOLEAN *)pval;
  804|  40.1k|        *tbool = *cont;
  805|  40.1k|      }
  806|  40.1k|      break;
  807|       |
  808|  40.1k|    case V_ASN1_BIT_STRING:
  ------------------
  |  |  127|  20.0k|#define V_ASN1_BIT_STRING 3
  ------------------
  |  Branch (808:5): [True: 20.0k, False: 482k]
  ------------------
  809|  20.0k|      if (!c2i_ASN1_BIT_STRING((ASN1_BIT_STRING **)pval, &cont, len)) {
  ------------------
  |  Branch (809:11): [True: 0, False: 20.0k]
  ------------------
  810|      0|        goto err;
  811|      0|      }
  812|  20.0k|      break;
  813|       |
  814|  40.1k|    case V_ASN1_INTEGER:
  ------------------
  |  |  126|  40.1k|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (814:5): [True: 40.1k, False: 462k]
  ------------------
  815|  40.1k|    case V_ASN1_ENUMERATED:
  ------------------
  |  |  134|  40.1k|#define V_ASN1_ENUMERATED 10
  ------------------
  |  Branch (815:5): [True: 0, False: 502k]
  ------------------
  816|  40.1k|      tint = (ASN1_INTEGER **)pval;
  817|  40.1k|      if (!c2i_ASN1_INTEGER(tint, &cont, len)) {
  ------------------
  |  Branch (817:11): [True: 0, False: 40.1k]
  ------------------
  818|      0|        goto err;
  819|      0|      }
  820|       |      // Fixup type to match the expected form
  821|  40.1k|      (*tint)->type = utype | ((*tint)->type & V_ASN1_NEG);
  ------------------
  |  |  155|  40.1k|#define V_ASN1_NEG 0x100
  ------------------
  822|  40.1k|      break;
  823|       |
  824|  80.3k|    case V_ASN1_OCTET_STRING:
  ------------------
  |  |  128|  80.3k|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (824:5): [True: 80.3k, False: 421k]
  ------------------
  825|  80.3k|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|  80.3k|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (825:5): [True: 0, False: 502k]
  ------------------
  826|   120k|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|   120k|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (826:5): [True: 40.1k, False: 462k]
  ------------------
  827|   120k|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|   120k|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (827:5): [True: 0, False: 502k]
  ------------------
  828|   120k|    case V_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  142|   120k|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (828:5): [True: 0, False: 502k]
  ------------------
  829|   120k|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|   120k|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (829:5): [True: 0, False: 502k]
  ------------------
  830|   160k|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|   160k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (830:5): [True: 40.1k, False: 462k]
  ------------------
  831|   160k|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|   160k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (831:5): [True: 0, False: 502k]
  ------------------
  832|   160k|    case V_ASN1_GRAPHICSTRING:
  ------------------
  |  |  146|   160k|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (832:5): [True: 0, False: 502k]
  ------------------
  833|   160k|    case V_ASN1_VISIBLESTRING:
  ------------------
  |  |  148|   160k|#define V_ASN1_VISIBLESTRING 26
  ------------------
  |  Branch (833:5): [True: 0, False: 502k]
  ------------------
  834|   160k|    case V_ASN1_GENERALSTRING:
  ------------------
  |  |  149|   160k|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (834:5): [True: 0, False: 502k]
  ------------------
  835|   160k|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|   160k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (835:5): [True: 0, False: 502k]
  ------------------
  836|   160k|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|   160k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (836:5): [True: 0, False: 502k]
  ------------------
  837|   160k|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|   160k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (837:5): [True: 0, False: 502k]
  ------------------
  838|   160k|    case V_ASN1_OTHER:
  ------------------
  |  |  118|   160k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (838:5): [True: 0, False: 502k]
  ------------------
  839|   160k|    case V_ASN1_SET:
  ------------------
  |  |  137|   160k|#define V_ASN1_SET 17
  ------------------
  |  Branch (839:5): [True: 0, False: 502k]
  ------------------
  840|   160k|    case V_ASN1_SEQUENCE:
  ------------------
  |  |  136|   160k|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (840:5): [True: 0, False: 502k]
  ------------------
  841|       |    // TODO(crbug.com/boringssl/412): This default case should be removed, now
  842|       |    // that we've resolved https://crbug.com/boringssl/561. However, it is still
  843|       |    // needed to support some edge cases in |ASN1_PRINTABLE|. |ASN1_PRINTABLE|
  844|       |    // broadly doesn't tolerate unrecognized universal tags, but except for
  845|       |    // eight values that map to |B_ASN1_UNKNOWN| instead of zero. See the
  846|       |    // X509Test.NameAttributeValues test.
  847|   160k|    default: {
  ------------------
  |  Branch (847:5): [True: 0, False: 502k]
  ------------------
  848|   160k|      CBS cbs;
  849|   160k|      CBS_init(&cbs, cont, (size_t)len);
  850|   160k|      if (utype == V_ASN1_BMPSTRING) {
  ------------------
  |  |  151|   160k|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (850:11): [True: 0, False: 160k]
  ------------------
  851|      0|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (851:16): [True: 0, False: 0]
  ------------------
  852|      0|          uint32_t c;
  853|      0|          if (!cbs_get_ucs2_be(&cbs, &c)) {
  ------------------
  |  Branch (853:15): [True: 0, False: 0]
  ------------------
  854|      0|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_BMPSTRING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  855|      0|            goto err;
  856|      0|          }
  857|      0|        }
  858|      0|      }
  859|   160k|      if (utype == V_ASN1_UNIVERSALSTRING) {
  ------------------
  |  |  150|   160k|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (859:11): [True: 0, False: 160k]
  ------------------
  860|      0|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (860:16): [True: 0, False: 0]
  ------------------
  861|      0|          uint32_t c;
  862|      0|          if (!cbs_get_utf32_be(&cbs, &c)) {
  ------------------
  |  Branch (862:15): [True: 0, False: 0]
  ------------------
  863|      0|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_UNIVERSALSTRING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  864|      0|            goto err;
  865|      0|          }
  866|      0|        }
  867|      0|      }
  868|   160k|      if (utype == V_ASN1_UTF8STRING) {
  ------------------
  |  |  135|   160k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (868:11): [True: 0, False: 160k]
  ------------------
  869|      0|        while (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (869:16): [True: 0, False: 0]
  ------------------
  870|      0|          uint32_t c;
  871|      0|          if (!cbs_get_utf8(&cbs, &c)) {
  ------------------
  |  Branch (871:15): [True: 0, False: 0]
  ------------------
  872|      0|            OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_UTF8STRING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  873|      0|            goto err;
  874|      0|          }
  875|      0|        }
  876|      0|      }
  877|   160k|      if (utype == V_ASN1_UTCTIME) {
  ------------------
  |  |  144|   160k|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (877:11): [True: 40.1k, False: 120k]
  ------------------
  878|  40.1k|        if (!CBS_parse_utc_time(&cbs, NULL, /*allow_timezone_offset=*/1)) {
  ------------------
  |  Branch (878:13): [True: 0, False: 40.1k]
  ------------------
  879|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_TIME_FORMAT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  880|      0|          goto err;
  881|      0|        }
  882|  40.1k|      }
  883|   160k|      if (utype == V_ASN1_GENERALIZEDTIME) {
  ------------------
  |  |  145|   160k|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (883:11): [True: 0, False: 160k]
  ------------------
  884|      0|        if (!CBS_parse_generalized_time(&cbs, NULL,
  ------------------
  |  Branch (884:13): [True: 0, False: 0]
  ------------------
  885|      0|                                        /*allow_timezone_offset=*/0)) {
  886|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_INVALID_TIME_FORMAT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  887|      0|          goto err;
  888|      0|        }
  889|      0|      }
  890|       |      // TODO(https://crbug.com/boringssl/427): Check other string types.
  891|       |
  892|       |      // All based on ASN1_STRING and handled the same
  893|   160k|      if (!*pval) {
  ------------------
  |  Branch (893:11): [True: 0, False: 160k]
  ------------------
  894|      0|        stmp = ASN1_STRING_type_new(utype);
  895|      0|        if (!stmp) {
  ------------------
  |  Branch (895:13): [True: 0, False: 0]
  ------------------
  896|      0|          goto err;
  897|      0|        }
  898|      0|        *pval = (ASN1_VALUE *)stmp;
  899|   160k|      } else {
  900|   160k|        stmp = (ASN1_STRING *)*pval;
  901|   160k|        stmp->type = utype;
  902|   160k|      }
  903|   160k|      if (!ASN1_STRING_set(stmp, cont, len)) {
  ------------------
  |  Branch (903:11): [True: 0, False: 160k]
  ------------------
  904|      0|        ASN1_STRING_free(stmp);
  905|      0|        *pval = NULL;
  906|      0|        goto err;
  907|      0|      }
  908|   160k|      break;
  909|   160k|    }
  910|   502k|  }
  911|       |  // If ASN1_ANY and NULL type fix up value
  912|   502k|  if (typ && (utype == V_ASN1_NULL)) {
  ------------------
  |  |  129|  60.2k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (912:7): [True: 60.2k, False: 442k]
  |  Branch (912:14): [True: 60.2k, False: 0]
  ------------------
  913|  60.2k|    typ->value.ptr = NULL;
  914|  60.2k|  }
  915|       |
  916|   502k|  ret = 1;
  917|   502k|err:
  918|   502k|  if (!ret) {
  ------------------
  |  Branch (918:7): [True: 0, False: 502k]
  ------------------
  919|      0|    ASN1_TYPE_free(typ);
  920|      0|    if (opval) {
  ------------------
  |  Branch (920:9): [True: 0, False: 0]
  ------------------
  921|      0|      *opval = NULL;
  922|      0|    }
  923|      0|  }
  924|   502k|  return ret;
  925|   502k|}
tasn_dec.c:asn1_check_tlen:
  932|  1.10M|                           int exptag, int expclass, char opt) {
  933|  1.10M|  int i;
  934|  1.10M|  int ptag, pclass;
  935|  1.10M|  long plen;
  936|  1.10M|  const unsigned char *p;
  937|  1.10M|  p = *in;
  938|       |
  939|  1.10M|  i = ASN1_get_object(&p, &plen, &ptag, &pclass, len);
  940|  1.10M|  if (i & 0x80) {
  ------------------
  |  Branch (940:7): [True: 0, False: 1.10M]
  ------------------
  941|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_OBJECT_HEADER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  942|      0|    return 0;
  943|      0|  }
  944|  1.10M|  if (exptag >= 0) {
  ------------------
  |  Branch (944:7): [True: 964k, False: 140k]
  ------------------
  945|   964k|    if ((exptag != ptag) || (expclass != pclass)) {
  ------------------
  |  Branch (945:9): [True: 80.3k, False: 884k]
  |  Branch (945:29): [True: 0, False: 884k]
  ------------------
  946|       |      // If type is OPTIONAL, not an error: indicate missing type.
  947|  80.3k|      if (opt) {
  ------------------
  |  Branch (947:11): [True: 80.3k, False: 0]
  ------------------
  948|  80.3k|        return -1;
  949|  80.3k|      }
  950|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TAG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  951|      0|      return 0;
  952|  80.3k|    }
  953|   964k|  }
  954|       |
  955|  1.02M|  if (cst) {
  ------------------
  |  Branch (955:7): [True: 783k, False: 241k]
  ------------------
  956|   783k|    *cst = i & V_ASN1_CONSTRUCTED;
  ------------------
  |  |   99|   783k|#define V_ASN1_CONSTRUCTED 0x20
  ------------------
  957|   783k|  }
  958|       |
  959|  1.02M|  if (olen) {
  ------------------
  |  Branch (959:7): [True: 884k, False: 140k]
  ------------------
  960|   884k|    *olen = plen;
  961|   884k|  }
  962|       |
  963|  1.02M|  if (oclass) {
  ------------------
  |  Branch (963:7): [True: 140k, False: 884k]
  ------------------
  964|   140k|    *oclass = pclass;
  965|   140k|  }
  966|       |
  967|  1.02M|  if (otag) {
  ------------------
  |  Branch (967:7): [True: 140k, False: 884k]
  ------------------
  968|   140k|    *otag = ptag;
  969|   140k|  }
  970|       |
  971|  1.02M|  *in = p;
  972|  1.02M|  return 1;
  973|  1.10M|}

ASN1_item_i2d:
   86|   206k|int ASN1_item_i2d(ASN1_VALUE *val, unsigned char **out, const ASN1_ITEM *it) {
   87|   206k|  if (out && !*out) {
  ------------------
  |  Branch (87:7): [True: 104k, False: 101k]
  |  Branch (87:14): [True: 3.63k, False: 101k]
  ------------------
   88|  3.63k|    unsigned char *p, *buf;
   89|  3.63k|    int len = ASN1_item_ex_i2d(&val, NULL, it, /*tag=*/-1, /*aclass=*/0);
   90|  3.63k|    if (len <= 0) {
  ------------------
  |  Branch (90:9): [True: 0, False: 3.63k]
  ------------------
   91|      0|      return len;
   92|      0|    }
   93|  3.63k|    buf = OPENSSL_malloc(len);
   94|  3.63k|    if (!buf) {
  ------------------
  |  Branch (94:9): [True: 0, False: 3.63k]
  ------------------
   95|      0|      return -1;
   96|      0|    }
   97|  3.63k|    p = buf;
   98|  3.63k|    int len2 = ASN1_item_ex_i2d(&val, &p, it, /*tag=*/-1, /*aclass=*/0);
   99|  3.63k|    if (len2 <= 0) {
  ------------------
  |  Branch (99:9): [True: 0, False: 3.63k]
  ------------------
  100|      0|      OPENSSL_free(buf);
  101|      0|      return len2;
  102|      0|    }
  103|  3.63k|    assert(len == len2);
  104|  3.63k|    *out = buf;
  105|  3.63k|    return len;
  106|  3.63k|  }
  107|       |
  108|   202k|  return ASN1_item_ex_i2d(&val, out, it, /*tag=*/-1, /*aclass=*/0);
  109|   206k|}
ASN1_item_ex_i2d:
  115|   410k|                     const ASN1_ITEM *it, int tag, int aclass) {
  116|   410k|  int ret = asn1_item_ex_i2d_opt(pval, out, it, tag, aclass, /*optional=*/0);
  117|   410k|  assert(ret != 0);
  118|   410k|  return ret;
  119|   410k|}
tasn_enc.c:asn1_item_ex_i2d_opt:
  125|   934k|                         int optional) {
  126|   934k|  const ASN1_TEMPLATE *tt = NULL;
  127|   934k|  int i, seqcontlen, seqlen;
  128|       |
  129|       |  // Historically, |aclass| was repurposed to pass additional flags into the
  130|       |  // encoding process.
  131|   934k|  assert((aclass & ASN1_TFLG_TAG_CLASS) == aclass);
  132|       |  // If not overridding the tag, |aclass| is ignored and should be zero.
  133|   934k|  assert(tag != -1 || aclass == 0);
  134|       |
  135|       |  // All fields are pointers, except for boolean |ASN1_ITYPE_PRIMITIVE|s.
  136|       |  // Optional primitives are handled later.
  137|   934k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) && !*pval) {
  ------------------
  |  |  487|   934k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (137:7): [True: 423k, False: 511k]
  |  Branch (137:46): [True: 0, False: 423k]
  ------------------
  138|      0|    if (optional) {
  ------------------
  |  Branch (138:9): [True: 0, False: 0]
  ------------------
  139|      0|      return 0;
  140|      0|    }
  141|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  142|      0|    return -1;
  143|      0|  }
  144|       |
  145|   934k|  switch (it->itype) {
  146|   511k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   511k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (146:5): [True: 511k, False: 423k]
  ------------------
  147|   511k|      if (it->templates) {
  ------------------
  |  Branch (147:11): [True: 80.3k, False: 430k]
  ------------------
  148|       |        // This is an |ASN1_ITEM_TEMPLATE|.
  149|  80.3k|        if (it->templates->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|  80.3k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (149:13): [True: 0, False: 80.3k]
  ------------------
  150|      0|          OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|      0|          return -1;
  152|      0|        }
  153|  80.3k|        return asn1_template_ex_i2d(pval, out, it->templates, tag, aclass,
  154|  80.3k|                                    optional);
  155|  80.3k|      }
  156|   430k|      return asn1_i2d_ex_primitive(pval, out, it, tag, aclass, optional);
  157|       |
  158|   160k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|   160k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (158:5): [True: 160k, False: 773k]
  ------------------
  159|       |      // It never makes sense for multi-strings to have implicit tagging, so
  160|       |      // if tag != -1, then this looks like an error in the template.
  161|   160k|      if (tag != -1) {
  ------------------
  |  Branch (161:11): [True: 0, False: 160k]
  ------------------
  162|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  163|      0|        return -1;
  164|      0|      }
  165|   160k|      return asn1_i2d_ex_primitive(pval, out, it, -1, 0, optional);
  166|       |
  167|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (167:5): [True: 0, False: 934k]
  ------------------
  168|       |      // It never makes sense for CHOICE types to have implicit tagging, so if
  169|       |      // tag != -1, then this looks like an error in the template.
  170|      0|      if (tag != -1) {
  ------------------
  |  Branch (170:11): [True: 0, False: 0]
  ------------------
  171|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  172|      0|        return -1;
  173|      0|      }
  174|      0|      i = asn1_get_choice_selector(pval, it);
  175|      0|      if (i < 0 || i >= it->tcount) {
  ------------------
  |  Branch (175:11): [True: 0, False: 0]
  |  Branch (175:20): [True: 0, False: 0]
  ------------------
  176|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_NO_MATCHING_CHOICE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  177|      0|        return -1;
  178|      0|      }
  179|      0|      const ASN1_TEMPLATE *chtt = it->templates + i;
  180|      0|      if (chtt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|      0|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (180:11): [True: 0, False: 0]
  ------------------
  181|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  182|      0|        return -1;
  183|      0|      }
  184|      0|      ASN1_VALUE **pchval = asn1_get_field_ptr(pval, chtt);
  185|      0|      return asn1_template_ex_i2d(pchval, out, chtt, -1, 0, /*optional=*/0);
  186|      0|    }
  187|       |
  188|  7.26k|    case ASN1_ITYPE_EXTERN: {
  ------------------
  |  |  493|  7.26k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (188:5): [True: 7.26k, False: 927k]
  ------------------
  189|       |      // We don't support implicit tagging with external types.
  190|  7.26k|      if (tag != -1) {
  ------------------
  |  Branch (190:11): [True: 0, False: 7.26k]
  ------------------
  191|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  192|      0|        return -1;
  193|      0|      }
  194|  7.26k|      const ASN1_EXTERN_FUNCS *ef = it->funcs;
  195|  7.26k|      int ret = ef->asn1_ex_i2d(pval, out, it);
  196|  7.26k|      if (ret == 0) {
  ------------------
  |  Branch (196:11): [True: 0, False: 7.26k]
  ------------------
  197|       |        // |asn1_ex_i2d| should never return zero. We have already checked
  198|       |        // for optional values generically, and |ASN1_ITYPE_EXTERN| fields
  199|       |        // must be pointers.
  200|      0|        OPENSSL_PUT_ERROR(ASN1, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  201|      0|        return -1;
  202|      0|      }
  203|  7.26k|      return ret;
  204|  7.26k|    }
  205|       |
  206|   255k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|   255k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (206:5): [True: 255k, False: 679k]
  ------------------
  207|   255k|      i = asn1_enc_restore(&seqcontlen, out, pval, it);
  208|       |      // An error occurred
  209|   255k|      if (i < 0) {
  ------------------
  |  Branch (209:11): [True: 0, False: 255k]
  ------------------
  210|      0|        return -1;
  211|      0|      }
  212|       |      // We have a valid cached encoding...
  213|   255k|      if (i > 0) {
  ------------------
  |  Branch (213:11): [True: 67.4k, False: 188k]
  ------------------
  214|  67.4k|        return seqcontlen;
  215|  67.4k|      }
  216|       |      // Otherwise carry on
  217|   188k|      seqcontlen = 0;
  218|       |      // If no IMPLICIT tagging set to SEQUENCE, UNIVERSAL
  219|   188k|      if (tag == -1) {
  ------------------
  |  Branch (219:11): [True: 188k, False: 0]
  ------------------
  220|   188k|        tag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|   188k|#define V_ASN1_SEQUENCE 16
  ------------------
  221|   188k|        aclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|   188k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  222|   188k|      }
  223|       |      // First work out sequence content length
  224|   564k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (224:39): [True: 376k, False: 188k]
  ------------------
  225|   376k|        const ASN1_TEMPLATE *seqtt;
  226|   376k|        ASN1_VALUE **pseqval;
  227|   376k|        int tmplen;
  228|   376k|        seqtt = asn1_do_adb(pval, tt, 1);
  229|   376k|        if (!seqtt) {
  ------------------
  |  Branch (229:13): [True: 0, False: 376k]
  ------------------
  230|      0|          return -1;
  231|      0|        }
  232|   376k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  233|   376k|        tmplen =
  234|   376k|            asn1_template_ex_i2d(pseqval, NULL, seqtt, -1, 0, /*optional=*/0);
  235|   376k|        if (tmplen == -1 || (tmplen > INT_MAX - seqcontlen)) {
  ------------------
  |  Branch (235:13): [True: 0, False: 376k]
  |  Branch (235:29): [True: 0, False: 376k]
  ------------------
  236|      0|          return -1;
  237|      0|        }
  238|   376k|        seqcontlen += tmplen;
  239|   376k|      }
  240|       |
  241|   188k|      seqlen = ASN1_object_size(/*constructed=*/1, seqcontlen, tag);
  242|   188k|      if (!out || seqlen == -1) {
  ------------------
  |  Branch (242:11): [True: 114k, False: 73.9k]
  |  Branch (242:19): [True: 0, False: 73.9k]
  ------------------
  243|   114k|        return seqlen;
  244|   114k|      }
  245|       |      // Output SEQUENCE header
  246|  73.9k|      ASN1_put_object(out, /*constructed=*/1, seqcontlen, tag, aclass);
  247|   221k|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (247:39): [True: 147k, False: 73.9k]
  ------------------
  248|   147k|        const ASN1_TEMPLATE *seqtt;
  249|   147k|        ASN1_VALUE **pseqval;
  250|   147k|        seqtt = asn1_do_adb(pval, tt, 1);
  251|   147k|        if (!seqtt) {
  ------------------
  |  Branch (251:13): [True: 0, False: 147k]
  ------------------
  252|      0|          return -1;
  253|      0|        }
  254|   147k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  255|   147k|        if (asn1_template_ex_i2d(pseqval, out, seqtt, -1, 0, /*optional=*/0) <
  ------------------
  |  Branch (255:13): [True: 0, False: 147k]
  ------------------
  256|   147k|            0) {
  257|      0|          return -1;
  258|      0|        }
  259|   147k|      }
  260|  73.9k|      return seqlen;
  261|  73.9k|    }
  262|       |
  263|      0|    default:
  ------------------
  |  Branch (263:5): [True: 0, False: 934k]
  ------------------
  264|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  265|      0|      return -1;
  266|   934k|  }
  267|   934k|}
tasn_enc.c:asn1_template_ex_i2d:
  274|   604k|                                int optional) {
  275|   604k|  int i, ret, ttag, tclass;
  276|   604k|  size_t j;
  277|   604k|  uint32_t flags = tt->flags;
  278|       |
  279|       |  // Historically, |iclass| was repurposed to pass additional flags into the
  280|       |  // encoding process.
  281|   604k|  assert((iclass & ASN1_TFLG_TAG_CLASS) == iclass);
  282|       |  // If not overridding the tag, |iclass| is ignored and should be zero.
  283|   604k|  assert(tag != -1 || iclass == 0);
  284|       |
  285|       |  // Work out tag and class to use: tagging may come either from the
  286|       |  // template or the arguments, not both because this would create
  287|       |  // ambiguity.
  288|   604k|  if (flags & ASN1_TFLG_TAG_MASK) {
  ------------------
  |  |  404|   604k|#define ASN1_TFLG_TAG_MASK	(0x3 << 3)
  ------------------
  |  Branch (288:7): [True: 0, False: 604k]
  ------------------
  289|       |    // Error if argument and template tagging
  290|      0|    if (tag != -1) {
  ------------------
  |  Branch (290:9): [True: 0, False: 0]
  ------------------
  291|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_BAD_TEMPLATE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  292|      0|      return -1;
  293|      0|    }
  294|       |    // Get tagging from template
  295|      0|    ttag = tt->tag;
  296|      0|    tclass = flags & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|      0|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  297|   604k|  } else if (tag != -1) {
  ------------------
  |  Branch (297:14): [True: 0, False: 604k]
  ------------------
  298|       |    // No template tagging, get from arguments
  299|      0|    ttag = tag;
  300|      0|    tclass = iclass & ASN1_TFLG_TAG_CLASS;
  ------------------
  |  |  427|      0|#define ASN1_TFLG_TAG_CLASS	(0x3<<6)
  ------------------
  301|   604k|  } else {
  302|   604k|    ttag = -1;
  303|   604k|    tclass = 0;
  304|   604k|  }
  305|       |
  306|       |  // The template may itself by marked as optional, or this may be the template
  307|       |  // of an |ASN1_ITEM_TEMPLATE| type which was contained inside an outer
  308|       |  // optional template. (They cannot both be true because the
  309|       |  // |ASN1_ITEM_TEMPLATE| codepath rejects optional templates.)
  310|   604k|  assert(!optional || (flags & ASN1_TFLG_OPTIONAL) == 0);
  311|   604k|  optional = optional || (flags & ASN1_TFLG_OPTIONAL) != 0;
  ------------------
  |  |  381|   604k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (311:14): [True: 0, False: 604k]
  |  Branch (311:26): [True: 101k, False: 503k]
  ------------------
  312|       |
  313|       |  // At this point 'ttag' contains the outer tag to use, and 'tclass' is the
  314|       |  // class.
  315|       |
  316|   604k|  if (flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   604k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (316:7): [True: 80.3k, False: 523k]
  ------------------
  317|       |    // SET OF, SEQUENCE OF
  318|  80.3k|    STACK_OF(ASN1_VALUE) *sk = (STACK_OF(ASN1_VALUE) *)*pval;
  ------------------
  |  |   81|  80.3k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  319|  80.3k|    int isset, sktag, skaclass;
  320|  80.3k|    int skcontlen, sklen;
  321|  80.3k|    ASN1_VALUE *skitem;
  322|       |
  323|  80.3k|    if (!*pval) {
  ------------------
  |  Branch (323:9): [True: 0, False: 80.3k]
  ------------------
  324|      0|      if (optional) {
  ------------------
  |  Branch (324:11): [True: 0, False: 0]
  ------------------
  325|      0|        return 0;
  326|      0|      }
  327|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  328|      0|      return -1;
  329|      0|    }
  330|       |
  331|  80.3k|    if (flags & ASN1_TFLG_SET_OF) {
  ------------------
  |  |  384|  80.3k|#define ASN1_TFLG_SET_OF	(0x1 << 1)
  ------------------
  |  Branch (331:9): [True: 80.3k, False: 0]
  ------------------
  332|  80.3k|      isset = 1;
  333|       |      // Historically, types with both bits set were mutated when
  334|       |      // serialized to apply the sort. We no longer support this.
  335|  80.3k|      assert((flags & ASN1_TFLG_SEQUENCE_OF) == 0);
  336|  80.3k|    } else {
  337|      0|      isset = 0;
  338|      0|    }
  339|       |
  340|       |    // Work out inner tag value: if EXPLICIT or no tagging use underlying
  341|       |    // type.
  342|  80.3k|    if ((ttag != -1) && !(flags & ASN1_TFLG_EXPTAG)) {
  ------------------
  |  |  402|      0|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (342:9): [True: 0, False: 80.3k]
  |  Branch (342:25): [True: 0, False: 0]
  ------------------
  343|      0|      sktag = ttag;
  344|      0|      skaclass = tclass;
  345|  80.3k|    } else {
  346|  80.3k|      skaclass = V_ASN1_UNIVERSAL;
  ------------------
  |  |   92|  80.3k|#define V_ASN1_UNIVERSAL 0x00
  ------------------
  347|  80.3k|      if (isset) {
  ------------------
  |  Branch (347:11): [True: 80.3k, False: 0]
  ------------------
  348|  80.3k|        sktag = V_ASN1_SET;
  ------------------
  |  |  137|  80.3k|#define V_ASN1_SET 17
  ------------------
  349|  80.3k|      } else {
  350|      0|        sktag = V_ASN1_SEQUENCE;
  ------------------
  |  |  136|      0|#define V_ASN1_SEQUENCE 16
  ------------------
  351|      0|      }
  352|  80.3k|    }
  353|       |
  354|       |    // Determine total length of items
  355|  80.3k|    skcontlen = 0;
  356|   160k|    for (j = 0; j < sk_ASN1_VALUE_num(sk); j++) {
  ------------------
  |  Branch (356:17): [True: 80.3k, False: 80.3k]
  ------------------
  357|  80.3k|      int tmplen;
  358|  80.3k|      skitem = sk_ASN1_VALUE_value(sk, j);
  359|  80.3k|      tmplen = ASN1_item_ex_i2d(&skitem, NULL, ASN1_ITEM_ptr(tt->item), -1, 0);
  ------------------
  |  |  288|  80.3k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  360|  80.3k|      if (tmplen == -1 || (skcontlen > INT_MAX - tmplen)) {
  ------------------
  |  Branch (360:11): [True: 0, False: 80.3k]
  |  Branch (360:27): [True: 0, False: 80.3k]
  ------------------
  361|      0|        return -1;
  362|      0|      }
  363|  80.3k|      skcontlen += tmplen;
  364|  80.3k|    }
  365|  80.3k|    sklen = ASN1_object_size(/*constructed=*/1, skcontlen, sktag);
  366|  80.3k|    if (sklen == -1) {
  ------------------
  |  Branch (366:9): [True: 0, False: 80.3k]
  ------------------
  367|      0|      return -1;
  368|      0|    }
  369|       |    // If EXPLICIT need length of surrounding tag
  370|  80.3k|    if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  80.3k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (370:9): [True: 0, False: 80.3k]
  ------------------
  371|      0|      ret = ASN1_object_size(/*constructed=*/1, sklen, ttag);
  372|  80.3k|    } else {
  373|  80.3k|      ret = sklen;
  374|  80.3k|    }
  375|       |
  376|  80.3k|    if (!out || ret == -1) {
  ------------------
  |  Branch (376:9): [True: 40.1k, False: 40.1k]
  |  Branch (376:17): [True: 0, False: 40.1k]
  ------------------
  377|  40.1k|      return ret;
  378|  40.1k|    }
  379|       |
  380|       |    // Now encode this lot...
  381|       |    // EXPLICIT tag
  382|  40.1k|    if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|  40.1k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (382:9): [True: 0, False: 40.1k]
  ------------------
  383|      0|      ASN1_put_object(out, /*constructed=*/1, sklen, ttag, tclass);
  384|      0|    }
  385|       |    // SET or SEQUENCE and IMPLICIT tag
  386|  40.1k|    ASN1_put_object(out, /*constructed=*/1, skcontlen, sktag, skaclass);
  387|       |    // And the stuff itself
  388|  40.1k|    if (!asn1_set_seq_out(sk, out, skcontlen, ASN1_ITEM_ptr(tt->item), isset)) {
  ------------------
  |  |  288|  40.1k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (388:9): [True: 0, False: 40.1k]
  ------------------
  389|      0|      return -1;
  390|      0|    }
  391|  40.1k|    return ret;
  392|  40.1k|  }
  393|       |
  394|   523k|  if (flags & ASN1_TFLG_EXPTAG) {
  ------------------
  |  |  402|   523k|#define ASN1_TFLG_EXPTAG	(0x2 << 3)
  ------------------
  |  Branch (394:7): [True: 0, False: 523k]
  ------------------
  395|       |    // EXPLICIT tagging
  396|       |    // Find length of tagged item
  397|      0|    i = asn1_item_ex_i2d_opt(pval, NULL, ASN1_ITEM_ptr(tt->item), -1, 0,
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  398|      0|                             optional);
  399|      0|    if (i <= 0) {
  ------------------
  |  Branch (399:9): [True: 0, False: 0]
  ------------------
  400|      0|      return i;
  401|      0|    }
  402|       |    // Find length of EXPLICIT tag
  403|      0|    ret = ASN1_object_size(/*constructed=*/1, i, ttag);
  404|      0|    if (out && ret != -1) {
  ------------------
  |  Branch (404:9): [True: 0, False: 0]
  |  Branch (404:16): [True: 0, False: 0]
  ------------------
  405|       |      // Output tag and item
  406|      0|      ASN1_put_object(out, /*constructed=*/1, i, ttag, tclass);
  407|      0|      if (ASN1_item_ex_i2d(pval, out, ASN1_ITEM_ptr(tt->item), -1, 0) < 0) {
  ------------------
  |  |  288|      0|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  |  Branch (407:11): [True: 0, False: 0]
  ------------------
  408|      0|        return -1;
  409|      0|      }
  410|      0|    }
  411|      0|    return ret;
  412|      0|  }
  413|       |
  414|       |  // Either normal or IMPLICIT tagging
  415|   523k|  return asn1_item_ex_i2d_opt(pval, out, ASN1_ITEM_ptr(tt->item), ttag, tclass,
  ------------------
  |  |  288|   523k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  416|   523k|                              optional);
  417|   523k|}
tasn_enc.c:asn1_set_seq_out:
  443|  40.1k|                            int skcontlen, const ASN1_ITEM *item, int do_sort) {
  444|       |  // No need to sort if there are fewer than two items.
  445|  40.1k|  if (!do_sort || sk_ASN1_VALUE_num(sk) < 2) {
  ------------------
  |  Branch (445:7): [True: 0, False: 40.1k]
  |  Branch (445:19): [True: 40.1k, False: 0]
  ------------------
  446|  80.3k|    for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (446:24): [True: 40.1k, False: 40.1k]
  ------------------
  447|  40.1k|      ASN1_VALUE *skitem = sk_ASN1_VALUE_value(sk, i);
  448|  40.1k|      if (ASN1_item_ex_i2d(&skitem, out, item, -1, 0) < 0) {
  ------------------
  |  Branch (448:11): [True: 0, False: 40.1k]
  ------------------
  449|      0|        return 0;
  450|      0|      }
  451|  40.1k|    }
  452|  40.1k|    return 1;
  453|  40.1k|  }
  454|       |
  455|      0|  if (sk_ASN1_VALUE_num(sk) > ((size_t)-1) / sizeof(DER_ENC)) {
  ------------------
  |  Branch (455:7): [True: 0, False: 0]
  ------------------
  456|      0|    OPENSSL_PUT_ERROR(ASN1, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  457|      0|    return 0;
  458|      0|  }
  459|       |
  460|      0|  int ret = 0;
  461|      0|  unsigned char *const buf = OPENSSL_malloc(skcontlen);
  462|      0|  DER_ENC *encoded = OPENSSL_malloc(sk_ASN1_VALUE_num(sk) * sizeof(*encoded));
  463|      0|  if (encoded == NULL || buf == NULL) {
  ------------------
  |  Branch (463:7): [True: 0, False: 0]
  |  Branch (463:26): [True: 0, False: 0]
  ------------------
  464|      0|    goto err;
  465|      0|  }
  466|       |
  467|       |  // Encode all the elements into |buf| and populate |encoded|.
  468|      0|  unsigned char *p = buf;
  469|      0|  for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (469:22): [True: 0, False: 0]
  ------------------
  470|      0|    ASN1_VALUE *skitem = sk_ASN1_VALUE_value(sk, i);
  471|      0|    encoded[i].data = p;
  472|      0|    encoded[i].length = ASN1_item_ex_i2d(&skitem, &p, item, -1, 0);
  473|      0|    if (encoded[i].length < 0) {
  ------------------
  |  Branch (473:9): [True: 0, False: 0]
  ------------------
  474|      0|      goto err;
  475|      0|    }
  476|      0|    assert(p - buf <= skcontlen);
  477|      0|  }
  478|       |
  479|      0|  qsort(encoded, sk_ASN1_VALUE_num(sk), sizeof(*encoded), der_cmp);
  480|       |
  481|       |  // Output the elements in sorted order.
  482|      0|  p = *out;
  483|      0|  for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (483:22): [True: 0, False: 0]
  ------------------
  484|      0|    OPENSSL_memcpy(p, encoded[i].data, encoded[i].length);
  485|      0|    p += encoded[i].length;
  486|      0|  }
  487|      0|  *out = p;
  488|       |
  489|      0|  ret = 1;
  490|       |
  491|      0|err:
  492|      0|  OPENSSL_free(encoded);
  493|      0|  OPENSSL_free(buf);
  494|      0|  return ret;
  495|      0|}
tasn_enc.c:asn1_i2d_ex_primitive:
  501|   591k|                                 int optional) {
  502|       |  // Get length of content octets and maybe find out the underlying type.
  503|   591k|  int omit;
  504|   591k|  int utype = it->utype;
  505|   591k|  int len = asn1_ex_i2c(pval, NULL, &omit, &utype, it);
  506|   591k|  if (len < 0) {
  ------------------
  |  Branch (506:7): [True: 0, False: 591k]
  ------------------
  507|      0|    return -1;
  508|      0|  }
  509|   591k|  if (omit) {
  ------------------
  |  Branch (509:7): [True: 0, False: 591k]
  ------------------
  510|      0|    if (optional) {
  ------------------
  |  Branch (510:9): [True: 0, False: 0]
  ------------------
  511|      0|      return 0;
  512|      0|    }
  513|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  514|      0|    return -1;
  515|      0|  }
  516|       |
  517|       |  // If SEQUENCE, SET or OTHER then header is included in pseudo content
  518|       |  // octets so don't include tag+length. We need to check here because the
  519|       |  // call to asn1_ex_i2c() could change utype.
  520|   591k|  int usetag =
  521|   591k|      utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  136|  1.18M|#define V_ASN1_SEQUENCE 16
  ------------------
                    utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  137|  1.18M|#define V_ASN1_SET 17
  ------------------
                    utype != V_ASN1_SEQUENCE && utype != V_ASN1_SET && utype != V_ASN1_OTHER;
  ------------------
  |  |  118|   591k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (521:7): [True: 591k, False: 0]
  |  Branch (521:35): [True: 591k, False: 0]
  |  Branch (521:58): [True: 591k, False: 0]
  ------------------
  522|       |
  523|       |  // If not implicitly tagged get tag from underlying type
  524|   591k|  if (tag == -1) {
  ------------------
  |  Branch (524:7): [True: 591k, False: 0]
  ------------------
  525|   591k|    tag = utype;
  526|   591k|  }
  527|       |
  528|       |  // Output tag+length followed by content octets
  529|   591k|  if (out) {
  ------------------
  |  Branch (529:7): [True: 181k, False: 409k]
  ------------------
  530|   181k|    if (usetag) {
  ------------------
  |  Branch (530:9): [True: 181k, False: 0]
  ------------------
  531|   181k|      ASN1_put_object(out, /*constructed=*/0, len, tag, aclass);
  532|   181k|    }
  533|   181k|    int len2 = asn1_ex_i2c(pval, *out, &omit, &utype, it);
  534|   181k|    if (len2 < 0) {
  ------------------
  |  Branch (534:9): [True: 0, False: 181k]
  ------------------
  535|      0|      return -1;
  536|      0|    }
  537|   181k|    assert(len == len2);
  538|   181k|    assert(!omit);
  539|   181k|    *out += len;
  540|   181k|  }
  541|       |
  542|   591k|  if (usetag) {
  ------------------
  |  Branch (542:7): [True: 591k, False: 0]
  ------------------
  543|   591k|    return ASN1_object_size(/*constructed=*/0, len, tag);
  544|   591k|  }
  545|      0|  return len;
  546|   591k|}
tasn_enc.c:asn1_ex_i2c:
  565|   772k|                       int *putype, const ASN1_ITEM *it) {
  566|   772k|  ASN1_BOOLEAN *tbool = NULL;
  567|   772k|  ASN1_STRING *strtmp;
  568|   772k|  ASN1_OBJECT *otmp;
  569|   772k|  int utype;
  570|   772k|  const unsigned char *cont;
  571|   772k|  unsigned char c;
  572|   772k|  int len;
  573|       |
  574|       |  // Historically, |it->funcs| for primitive types contained an
  575|       |  // |ASN1_PRIMITIVE_FUNCS| table of callbacks.
  576|   772k|  assert(it->funcs == NULL);
  577|       |
  578|   772k|  *out_omit = 0;
  579|       |
  580|       |  // Should type be omitted?
  581|   772k|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) || (it->utype != V_ASN1_BOOLEAN)) {
  ------------------
  |  |  487|   772k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
                if ((it->itype != ASN1_ITYPE_PRIMITIVE) || (it->utype != V_ASN1_BOOLEAN)) {
  ------------------
  |  |  125|   572k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (581:7): [True: 200k, False: 572k]
  |  Branch (581:46): [True: 572k, False: 0]
  ------------------
  582|   772k|    if (!*pval) {
  ------------------
  |  Branch (582:9): [True: 0, False: 772k]
  ------------------
  583|      0|      *out_omit = 1;
  584|      0|      return 0;
  585|      0|    }
  586|   772k|  }
  587|       |
  588|   772k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|   772k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (588:7): [True: 200k, False: 572k]
  ------------------
  589|       |    // If MSTRING type set the underlying type
  590|   200k|    strtmp = (ASN1_STRING *)*pval;
  591|   200k|    utype = strtmp->type;
  592|   200k|    if (utype < 0 && utype != V_ASN1_OTHER) {
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (592:9): [True: 0, False: 200k]
  |  Branch (592:22): [True: 0, False: 0]
  ------------------
  593|       |      // MSTRINGs can have type -1 when default-constructed.
  594|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  595|      0|      return -1;
  596|      0|    }
  597|       |    // Negative INTEGER and ENUMERATED values use |ASN1_STRING| type values
  598|       |    // that do not match their corresponding utype values. INTEGERs cannot
  599|       |    // participate in MSTRING types, but ENUMERATEDs can.
  600|       |    //
  601|       |    // TODO(davidben): Is this a bug? Although arguably one of the MSTRING
  602|       |    // types should contain more values, rather than less. See
  603|       |    // https://crbug.com/boringssl/412. But it is not possible to fit all
  604|       |    // possible ANY values into an |ASN1_STRING|, so matching the spec here
  605|       |    // is somewhat hopeless.
  606|   200k|    if (utype == V_ASN1_NEG_INTEGER) {
  ------------------
  |  |  156|   200k|#define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  126|   200k|#define V_ASN1_INTEGER 2
  |  |  ------------------
  |  |               #define V_ASN1_NEG_INTEGER (V_ASN1_INTEGER | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|   200k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  |  Branch (606:9): [True: 0, False: 200k]
  ------------------
  607|      0|      utype = V_ASN1_INTEGER;
  ------------------
  |  |  126|      0|#define V_ASN1_INTEGER 2
  ------------------
  608|   200k|    } else if (utype == V_ASN1_NEG_ENUMERATED) {
  ------------------
  |  |  157|   200k|#define V_ASN1_NEG_ENUMERATED (V_ASN1_ENUMERATED | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  134|   200k|#define V_ASN1_ENUMERATED 10
  |  |  ------------------
  |  |               #define V_ASN1_NEG_ENUMERATED (V_ASN1_ENUMERATED | V_ASN1_NEG)
  |  |  ------------------
  |  |  |  |  155|   200k|#define V_ASN1_NEG 0x100
  |  |  ------------------
  ------------------
  |  Branch (608:16): [True: 0, False: 200k]
  ------------------
  609|      0|      utype = V_ASN1_ENUMERATED;
  ------------------
  |  |  134|      0|#define V_ASN1_ENUMERATED 10
  ------------------
  610|      0|    }
  611|   200k|    *putype = utype;
  612|   572k|  } else if (it->utype == V_ASN1_ANY) {
  ------------------
  |  |  121|   572k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (612:14): [True: 134k, False: 437k]
  ------------------
  613|       |    // If ANY set type and pointer to value
  614|   134k|    ASN1_TYPE *typ;
  615|   134k|    typ = (ASN1_TYPE *)*pval;
  616|   134k|    utype = typ->type;
  617|   134k|    if (utype < 0 && utype != V_ASN1_OTHER) {
  ------------------
  |  |  118|      0|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (617:9): [True: 0, False: 134k]
  |  Branch (617:22): [True: 0, False: 0]
  ------------------
  618|       |      // |ASN1_TYPE|s can have type -1 when default-constructed.
  619|      0|      OPENSSL_PUT_ERROR(ASN1, ASN1_R_WRONG_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  620|      0|      return -1;
  621|      0|    }
  622|   134k|    *putype = utype;
  623|   134k|    pval = &typ->value.asn1_value;
  624|   437k|  } else {
  625|   437k|    utype = *putype;
  626|   437k|  }
  627|       |
  628|   772k|  switch (utype) {
  629|   335k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|   335k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (629:5): [True: 335k, False: 437k]
  ------------------
  630|   335k|      otmp = (ASN1_OBJECT *)*pval;
  631|   335k|      cont = otmp->data;
  632|   335k|      len = otmp->length;
  633|   335k|      if (len == 0) {
  ------------------
  |  Branch (633:11): [True: 0, False: 335k]
  ------------------
  634|       |        // Some |ASN1_OBJECT|s do not have OIDs and cannot be serialized.
  635|      0|        OPENSSL_PUT_ERROR(ASN1, ASN1_R_ILLEGAL_OBJECT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  636|      0|        return -1;
  637|      0|      }
  638|   335k|      break;
  639|       |
  640|   335k|    case V_ASN1_NULL:
  ------------------
  |  |  129|   134k|#define V_ASN1_NULL 5
  ------------------
  |  Branch (640:5): [True: 134k, False: 638k]
  ------------------
  641|   134k|      cont = NULL;
  642|   134k|      len = 0;
  643|   134k|      break;
  644|       |
  645|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (645:5): [True: 0, False: 772k]
  ------------------
  646|      0|      tbool = (ASN1_BOOLEAN *)pval;
  647|      0|      if (*tbool == ASN1_BOOLEAN_NONE) {
  ------------------
  |  |  432|      0|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
  |  Branch (647:11): [True: 0, False: 0]
  ------------------
  648|      0|        *out_omit = 1;
  649|      0|        return 0;
  650|      0|      }
  651|      0|      if (it->utype != V_ASN1_ANY) {
  ------------------
  |  |  121|      0|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (651:11): [True: 0, False: 0]
  ------------------
  652|       |        // Default handling if value == size field then omit
  653|      0|        if ((*tbool && (it->size > 0)) || (!*tbool && !it->size)) {
  ------------------
  |  Branch (653:14): [True: 0, False: 0]
  |  Branch (653:24): [True: 0, False: 0]
  |  Branch (653:44): [True: 0, False: 0]
  |  Branch (653:55): [True: 0, False: 0]
  ------------------
  654|      0|          *out_omit = 1;
  655|      0|          return 0;
  656|      0|        }
  657|      0|      }
  658|      0|      c = *tbool ? 0xff : 0x00;
  ------------------
  |  Branch (658:11): [True: 0, False: 0]
  ------------------
  659|      0|      cont = &c;
  660|      0|      len = 1;
  661|      0|      break;
  662|       |
  663|   101k|    case V_ASN1_BIT_STRING: {
  ------------------
  |  |  127|   101k|#define V_ASN1_BIT_STRING 3
  ------------------
  |  Branch (663:5): [True: 101k, False: 671k]
  ------------------
  664|   101k|      int ret =
  665|   101k|          i2c_ASN1_BIT_STRING((ASN1_BIT_STRING *)*pval, cout ? &cout : NULL);
  ------------------
  |  Branch (665:57): [True: 33.7k, False: 67.4k]
  ------------------
  666|       |      // |i2c_ASN1_BIT_STRING| returns zero on error instead of -1.
  667|   101k|      return ret <= 0 ? -1 : ret;
  ------------------
  |  Branch (667:14): [True: 0, False: 101k]
  ------------------
  668|      0|    }
  669|       |
  670|      0|    case V_ASN1_INTEGER:
  ------------------
  |  |  126|      0|#define V_ASN1_INTEGER 2
  ------------------
  |  Branch (670:5): [True: 0, False: 772k]
  ------------------
  671|      0|    case V_ASN1_ENUMERATED: {
  ------------------
  |  |  134|      0|#define V_ASN1_ENUMERATED 10
  ------------------
  |  Branch (671:5): [True: 0, False: 772k]
  ------------------
  672|       |      // |i2c_ASN1_INTEGER| also handles ENUMERATED.
  673|      0|      int ret = i2c_ASN1_INTEGER((ASN1_INTEGER *)*pval, cout ? &cout : NULL);
  ------------------
  |  Branch (673:57): [True: 0, False: 0]
  ------------------
  674|       |      // |i2c_ASN1_INTEGER| returns zero on error instead of -1.
  675|      0|      return ret <= 0 ? -1 : ret;
  ------------------
  |  Branch (675:14): [True: 0, False: 0]
  ------------------
  676|      0|    }
  677|       |
  678|      0|    case V_ASN1_OCTET_STRING:
  ------------------
  |  |  128|      0|#define V_ASN1_OCTET_STRING 4
  ------------------
  |  Branch (678:5): [True: 0, False: 772k]
  ------------------
  679|      0|    case V_ASN1_NUMERICSTRING:
  ------------------
  |  |  138|      0|#define V_ASN1_NUMERICSTRING 18
  ------------------
  |  Branch (679:5): [True: 0, False: 772k]
  ------------------
  680|      0|    case V_ASN1_PRINTABLESTRING:
  ------------------
  |  |  139|      0|#define V_ASN1_PRINTABLESTRING 19
  ------------------
  |  Branch (680:5): [True: 0, False: 772k]
  ------------------
  681|      0|    case V_ASN1_T61STRING:
  ------------------
  |  |  140|      0|#define V_ASN1_T61STRING 20
  ------------------
  |  Branch (681:5): [True: 0, False: 772k]
  ------------------
  682|      0|    case V_ASN1_VIDEOTEXSTRING:
  ------------------
  |  |  142|      0|#define V_ASN1_VIDEOTEXSTRING 21
  ------------------
  |  Branch (682:5): [True: 0, False: 772k]
  ------------------
  683|      0|    case V_ASN1_IA5STRING:
  ------------------
  |  |  143|      0|#define V_ASN1_IA5STRING 22
  ------------------
  |  Branch (683:5): [True: 0, False: 772k]
  ------------------
  684|      0|    case V_ASN1_UTCTIME:
  ------------------
  |  |  144|      0|#define V_ASN1_UTCTIME 23
  ------------------
  |  Branch (684:5): [True: 0, False: 772k]
  ------------------
  685|      0|    case V_ASN1_GENERALIZEDTIME:
  ------------------
  |  |  145|      0|#define V_ASN1_GENERALIZEDTIME 24
  ------------------
  |  Branch (685:5): [True: 0, False: 772k]
  ------------------
  686|      0|    case V_ASN1_GRAPHICSTRING:
  ------------------
  |  |  146|      0|#define V_ASN1_GRAPHICSTRING 25
  ------------------
  |  Branch (686:5): [True: 0, False: 772k]
  ------------------
  687|      0|    case V_ASN1_VISIBLESTRING:
  ------------------
  |  |  148|      0|#define V_ASN1_VISIBLESTRING 26
  ------------------
  |  Branch (687:5): [True: 0, False: 772k]
  ------------------
  688|      0|    case V_ASN1_GENERALSTRING:
  ------------------
  |  |  149|      0|#define V_ASN1_GENERALSTRING 27
  ------------------
  |  Branch (688:5): [True: 0, False: 772k]
  ------------------
  689|      0|    case V_ASN1_UNIVERSALSTRING:
  ------------------
  |  |  150|      0|#define V_ASN1_UNIVERSALSTRING 28
  ------------------
  |  Branch (689:5): [True: 0, False: 772k]
  ------------------
  690|      0|    case V_ASN1_BMPSTRING:
  ------------------
  |  |  151|      0|#define V_ASN1_BMPSTRING 30
  ------------------
  |  Branch (690:5): [True: 0, False: 772k]
  ------------------
  691|   200k|    case V_ASN1_UTF8STRING:
  ------------------
  |  |  135|   200k|#define V_ASN1_UTF8STRING 12
  ------------------
  |  Branch (691:5): [True: 200k, False: 572k]
  ------------------
  692|   200k|    case V_ASN1_SEQUENCE:
  ------------------
  |  |  136|   200k|#define V_ASN1_SEQUENCE 16
  ------------------
  |  Branch (692:5): [True: 0, False: 772k]
  ------------------
  693|   200k|    case V_ASN1_SET:
  ------------------
  |  |  137|   200k|#define V_ASN1_SET 17
  ------------------
  |  Branch (693:5): [True: 0, False: 772k]
  ------------------
  694|       |    // This is not a valid |ASN1_ITEM| type, but it appears in |ASN1_TYPE|.
  695|   200k|    case V_ASN1_OTHER:
  ------------------
  |  |  118|   200k|#define V_ASN1_OTHER (-3)
  ------------------
  |  Branch (695:5): [True: 0, False: 772k]
  ------------------
  696|       |    // TODO(crbug.com/boringssl/412): This default case should be removed, now
  697|       |    // that we've resolved https://crbug.com/boringssl/561. However, it is still
  698|       |    // needed to support some edge cases in |ASN1_PRINTABLE|. |ASN1_PRINTABLE|
  699|       |    // broadly doesn't tolerate unrecognized universal tags, but except for
  700|       |    // eight values that map to |B_ASN1_UNKNOWN| instead of zero. See the
  701|       |    // X509Test.NameAttributeValues test.
  702|   200k|    default:
  ------------------
  |  Branch (702:5): [True: 0, False: 772k]
  ------------------
  703|       |      // All based on ASN1_STRING and handled the same
  704|   200k|      strtmp = (ASN1_STRING *)*pval;
  705|   200k|      cont = strtmp->data;
  706|   200k|      len = strtmp->length;
  707|   200k|      break;
  708|   772k|  }
  709|   671k|  if (cout && len) {
  ------------------
  |  Branch (709:7): [True: 147k, False: 523k]
  |  Branch (709:15): [True: 114k, False: 33.7k]
  ------------------
  710|   114k|    OPENSSL_memcpy(cout, cont, len);
  711|   114k|  }
  712|   671k|  return len;
  713|   772k|}

ASN1_item_free:
   68|   220k|void ASN1_item_free(ASN1_VALUE *val, const ASN1_ITEM *it) {
   69|   220k|  ASN1_item_ex_free(&val, it);
   70|   220k|}
ASN1_item_ex_free:
   72|  1.16M|void ASN1_item_ex_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
   73|  1.16M|  const ASN1_TEMPLATE *tt = NULL, *seqtt;
   74|  1.16M|  const ASN1_EXTERN_FUNCS *ef;
   75|  1.16M|  int i;
   76|  1.16M|  if (!pval) {
  ------------------
  |  Branch (76:7): [True: 0, False: 1.16M]
  ------------------
   77|      0|    return;
   78|      0|  }
   79|  1.16M|  if ((it->itype != ASN1_ITYPE_PRIMITIVE) && !*pval) {
  ------------------
  |  |  487|  1.16M|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (79:7): [True: 502k, False: 662k]
  |  Branch (79:46): [True: 60.2k, False: 441k]
  ------------------
   80|  60.2k|    return;
   81|  60.2k|  }
   82|       |
   83|  1.10M|  switch (it->itype) {
  ------------------
  |  Branch (83:11): [True: 0, False: 1.10M]
  ------------------
   84|   662k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   662k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (84:5): [True: 662k, False: 441k]
  ------------------
   85|   662k|      if (it->templates) {
  ------------------
  |  Branch (85:11): [True: 40.1k, False: 622k]
  ------------------
   86|  40.1k|        ASN1_template_free(pval, it->templates);
   87|   622k|      } else {
   88|   622k|        ASN1_primitive_free(pval, it);
   89|   622k|      }
   90|   662k|      break;
   91|       |
   92|   120k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|   120k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (92:5): [True: 120k, False: 984k]
  ------------------
   93|   120k|      ASN1_primitive_free(pval, it);
   94|   120k|      break;
   95|       |
   96|      0|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (96:5): [True: 0, False: 1.10M]
  ------------------
   97|      0|      const ASN1_AUX *aux = it->funcs;
   98|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (98:30): [True: 0, False: 0]
  ------------------
   99|      0|      if (asn1_cb) {
  ------------------
  |  Branch (99:11): [True: 0, False: 0]
  ------------------
  100|      0|        i = asn1_cb(ASN1_OP_FREE_PRE, pval, it, NULL);
  ------------------
  |  |  539|      0|#define ASN1_OP_FREE_PRE	2
  ------------------
  101|      0|        if (i == 2) {
  ------------------
  |  Branch (101:13): [True: 0, False: 0]
  ------------------
  102|      0|          return;
  103|      0|        }
  104|      0|      }
  105|      0|      i = asn1_get_choice_selector(pval, it);
  106|      0|      if ((i >= 0) && (i < it->tcount)) {
  ------------------
  |  Branch (106:11): [True: 0, False: 0]
  |  Branch (106:23): [True: 0, False: 0]
  ------------------
  107|      0|        ASN1_VALUE **pchval;
  108|      0|        tt = it->templates + i;
  109|      0|        pchval = asn1_get_field_ptr(pval, tt);
  110|      0|        ASN1_template_free(pchval, tt);
  111|      0|      }
  112|      0|      if (asn1_cb) {
  ------------------
  |  Branch (112:11): [True: 0, False: 0]
  ------------------
  113|      0|        asn1_cb(ASN1_OP_FREE_POST, pval, it, NULL);
  ------------------
  |  |  540|      0|#define ASN1_OP_FREE_POST	3
  ------------------
  114|      0|      }
  115|      0|      OPENSSL_free(*pval);
  116|      0|      *pval = NULL;
  117|      0|      break;
  118|      0|    }
  119|       |
  120|  40.1k|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|  40.1k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (120:5): [True: 40.1k, False: 1.06M]
  ------------------
  121|  40.1k|      ef = it->funcs;
  122|  40.1k|      if (ef && ef->asn1_ex_free) {
  ------------------
  |  Branch (122:11): [True: 40.1k, False: 0]
  |  Branch (122:17): [True: 40.1k, False: 0]
  ------------------
  123|  40.1k|        ef->asn1_ex_free(pval, it);
  124|  40.1k|      }
  125|  40.1k|      break;
  126|       |
  127|   281k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|   281k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (127:5): [True: 281k, False: 823k]
  ------------------
  128|   281k|      if (!asn1_refcount_dec_and_test_zero(pval, it)) {
  ------------------
  |  Branch (128:11): [True: 0, False: 281k]
  ------------------
  129|      0|        return;
  130|      0|      }
  131|   281k|      const ASN1_AUX *aux = it->funcs;
  132|   281k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (132:30): [True: 40.1k, False: 241k]
  ------------------
  133|   281k|      if (asn1_cb) {
  ------------------
  |  Branch (133:11): [True: 20.0k, False: 261k]
  ------------------
  134|  20.0k|        i = asn1_cb(ASN1_OP_FREE_PRE, pval, it, NULL);
  ------------------
  |  |  539|  20.0k|#define ASN1_OP_FREE_PRE	2
  ------------------
  135|  20.0k|        if (i == 2) {
  ------------------
  |  Branch (135:13): [True: 0, False: 20.0k]
  ------------------
  136|      0|          return;
  137|      0|        }
  138|  20.0k|      }
  139|   281k|      asn1_enc_free(pval, it);
  140|       |      // If we free up as normal we will invalidate any ANY DEFINED BY
  141|       |      // field and we wont be able to determine the type of the field it
  142|       |      // defines. So free up in reverse order.
  143|   281k|      tt = it->templates + it->tcount - 1;
  144|  1.08M|      for (i = 0; i < it->tcount; tt--, i++) {
  ------------------
  |  Branch (144:19): [True: 803k, False: 281k]
  ------------------
  145|   803k|        ASN1_VALUE **pseqval;
  146|   803k|        seqtt = asn1_do_adb(pval, tt, 0);
  147|   803k|        if (!seqtt) {
  ------------------
  |  Branch (147:13): [True: 0, False: 803k]
  ------------------
  148|      0|          continue;
  149|      0|        }
  150|   803k|        pseqval = asn1_get_field_ptr(pval, seqtt);
  151|   803k|        ASN1_template_free(pseqval, seqtt);
  152|   803k|      }
  153|   281k|      if (asn1_cb) {
  ------------------
  |  Branch (153:11): [True: 20.0k, False: 261k]
  ------------------
  154|  20.0k|        asn1_cb(ASN1_OP_FREE_POST, pval, it, NULL);
  ------------------
  |  |  540|  20.0k|#define ASN1_OP_FREE_POST	3
  ------------------
  155|  20.0k|      }
  156|   281k|      OPENSSL_free(*pval);
  157|   281k|      *pval = NULL;
  158|   281k|      break;
  159|   281k|    }
  160|  1.10M|  }
  161|  1.10M|}
ASN1_template_free:
  163|   924k|void ASN1_template_free(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  164|   924k|  if (tt->flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   924k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (164:7): [True: 60.2k, False: 863k]
  ------------------
  165|  60.2k|    STACK_OF(ASN1_VALUE) *sk = (STACK_OF(ASN1_VALUE) *)*pval;
  ------------------
  |  |   81|  60.2k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  166|   140k|    for (size_t i = 0; i < sk_ASN1_VALUE_num(sk); i++) {
  ------------------
  |  Branch (166:24): [True: 80.3k, False: 60.2k]
  ------------------
  167|  80.3k|      ASN1_VALUE *vtmp = sk_ASN1_VALUE_value(sk, i);
  168|  80.3k|      ASN1_item_ex_free(&vtmp, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|  80.3k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  169|  80.3k|    }
  170|  60.2k|    sk_ASN1_VALUE_free(sk);
  171|  60.2k|    *pval = NULL;
  172|   863k|  } else {
  173|   863k|    ASN1_item_ex_free(pval, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|   863k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  174|   863k|  }
  175|   924k|}
ASN1_primitive_free:
  177|   743k|void ASN1_primitive_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  178|       |  // Historically, |it->funcs| for primitive types contained an
  179|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  180|   743k|  assert(it->funcs == NULL);
  181|       |
  182|   743k|  int utype = it->itype == ASN1_ITYPE_MSTRING ? -1 : it->utype;
  ------------------
  |  |  495|   743k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (182:15): [True: 120k, False: 622k]
  ------------------
  183|   743k|  switch (utype) {
  184|   220k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|   220k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (184:5): [True: 220k, False: 522k]
  ------------------
  185|   220k|      ASN1_OBJECT_free((ASN1_OBJECT *)*pval);
  186|   220k|      break;
  187|       |
  188|   120k|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|   120k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (188:5): [True: 120k, False: 622k]
  ------------------
  189|   120k|      if (it) {
  ------------------
  |  Branch (189:11): [True: 120k, False: 0]
  ------------------
  190|   120k|        *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  191|   120k|      } else {
  192|      0|        *(ASN1_BOOLEAN *)pval = ASN1_BOOLEAN_NONE;
  ------------------
  |  |  432|      0|#define ASN1_BOOLEAN_NONE (-1)
  ------------------
  193|      0|      }
  194|   120k|      return;
  195|       |
  196|      0|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (196:5): [True: 0, False: 743k]
  ------------------
  197|      0|      break;
  198|       |
  199|  60.2k|    case V_ASN1_ANY:
  ------------------
  |  |  121|  60.2k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (199:5): [True: 60.2k, False: 683k]
  ------------------
  200|  60.2k|      if (*pval != NULL) {
  ------------------
  |  Branch (200:11): [True: 60.2k, False: 0]
  ------------------
  201|  60.2k|        asn1_type_cleanup((ASN1_TYPE *)*pval);
  202|  60.2k|        OPENSSL_free(*pval);
  203|  60.2k|      }
  204|  60.2k|      break;
  205|       |
  206|   341k|    default:
  ------------------
  |  Branch (206:5): [True: 341k, False: 401k]
  ------------------
  207|   341k|      ASN1_STRING_free((ASN1_STRING *)*pval);
  208|   341k|      *pval = NULL;
  209|   341k|      break;
  210|   743k|  }
  211|   622k|  *pval = NULL;
  212|   622k|}

ASN1_item_new:
   76|   100k|ASN1_VALUE *ASN1_item_new(const ASN1_ITEM *it) {
   77|   100k|  ASN1_VALUE *ret = NULL;
   78|   100k|  if (ASN1_item_ex_new(&ret, it) > 0) {
  ------------------
  |  Branch (78:7): [True: 100k, False: 0]
  ------------------
   79|   100k|    return ret;
   80|   100k|  }
   81|      0|  return NULL;
   82|   100k|}
ASN1_item_ex_new:
   86|   843k|int ASN1_item_ex_new(ASN1_VALUE **pval, const ASN1_ITEM *it) {
   87|   843k|  const ASN1_TEMPLATE *tt = NULL;
   88|   843k|  const ASN1_EXTERN_FUNCS *ef;
   89|   843k|  ASN1_VALUE **pseqval;
   90|   843k|  int i;
   91|       |
   92|   843k|  switch (it->itype) {
  ------------------
  |  Branch (92:11): [True: 0, False: 843k]
  ------------------
   93|  40.1k|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|  40.1k|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (93:5): [True: 40.1k, False: 803k]
  ------------------
   94|  40.1k|      ef = it->funcs;
   95|  40.1k|      if (ef && ef->asn1_ex_new) {
  ------------------
  |  Branch (95:11): [True: 40.1k, False: 0]
  |  Branch (95:17): [True: 40.1k, False: 0]
  ------------------
   96|  40.1k|        if (!ef->asn1_ex_new(pval, it)) {
  ------------------
  |  Branch (96:13): [True: 0, False: 40.1k]
  ------------------
   97|      0|          goto memerr;
   98|      0|        }
   99|  40.1k|      }
  100|  40.1k|      break;
  101|       |
  102|   401k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   401k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (102:5): [True: 401k, False: 442k]
  ------------------
  103|   401k|      if (it->templates) {
  ------------------
  |  Branch (103:11): [True: 0, False: 401k]
  ------------------
  104|      0|        if (!ASN1_template_new(pval, it->templates)) {
  ------------------
  |  Branch (104:13): [True: 0, False: 0]
  ------------------
  105|      0|          goto memerr;
  106|      0|        }
  107|   401k|      } else if (!ASN1_primitive_new(pval, it)) {
  ------------------
  |  Branch (107:18): [True: 0, False: 401k]
  ------------------
  108|      0|        goto memerr;
  109|      0|      }
  110|   401k|      break;
  111|       |
  112|   401k|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|   120k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (112:5): [True: 120k, False: 723k]
  ------------------
  113|   120k|      if (!ASN1_primitive_new(pval, it)) {
  ------------------
  |  Branch (113:11): [True: 0, False: 120k]
  ------------------
  114|      0|        goto memerr;
  115|      0|      }
  116|   120k|      break;
  117|       |
  118|   120k|    case ASN1_ITYPE_CHOICE: {
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (118:5): [True: 0, False: 843k]
  ------------------
  119|      0|      const ASN1_AUX *aux = it->funcs;
  120|      0|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (120:30): [True: 0, False: 0]
  ------------------
  121|      0|      if (asn1_cb) {
  ------------------
  |  Branch (121:11): [True: 0, False: 0]
  ------------------
  122|      0|        i = asn1_cb(ASN1_OP_NEW_PRE, pval, it, NULL);
  ------------------
  |  |  537|      0|#define ASN1_OP_NEW_PRE		0
  ------------------
  123|      0|        if (!i) {
  ------------------
  |  Branch (123:13): [True: 0, False: 0]
  ------------------
  124|      0|          goto auxerr;
  125|      0|        }
  126|      0|        if (i == 2) {
  ------------------
  |  Branch (126:13): [True: 0, False: 0]
  ------------------
  127|      0|          return 1;
  128|      0|        }
  129|      0|      }
  130|      0|      *pval = OPENSSL_malloc(it->size);
  131|      0|      if (!*pval) {
  ------------------
  |  Branch (131:11): [True: 0, False: 0]
  ------------------
  132|      0|        goto memerr;
  133|      0|      }
  134|      0|      OPENSSL_memset(*pval, 0, it->size);
  135|      0|      asn1_set_choice_selector(pval, -1, it);
  136|      0|      if (asn1_cb && !asn1_cb(ASN1_OP_NEW_POST, pval, it, NULL)) {
  ------------------
  |  |  538|      0|#define ASN1_OP_NEW_POST	1
  ------------------
  |  Branch (136:11): [True: 0, False: 0]
  |  Branch (136:22): [True: 0, False: 0]
  ------------------
  137|      0|        goto auxerr2;
  138|      0|      }
  139|      0|      break;
  140|      0|    }
  141|       |
  142|   281k|    case ASN1_ITYPE_SEQUENCE: {
  ------------------
  |  |  489|   281k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (142:5): [True: 281k, False: 562k]
  ------------------
  143|   281k|      const ASN1_AUX *aux = it->funcs;
  144|   281k|      ASN1_aux_cb *asn1_cb = aux != NULL ? aux->asn1_cb : NULL;
  ------------------
  |  Branch (144:30): [True: 40.1k, False: 241k]
  ------------------
  145|   281k|      if (asn1_cb) {
  ------------------
  |  Branch (145:11): [True: 20.0k, False: 261k]
  ------------------
  146|  20.0k|        i = asn1_cb(ASN1_OP_NEW_PRE, pval, it, NULL);
  ------------------
  |  |  537|  20.0k|#define ASN1_OP_NEW_PRE		0
  ------------------
  147|  20.0k|        if (!i) {
  ------------------
  |  Branch (147:13): [True: 0, False: 20.0k]
  ------------------
  148|      0|          goto auxerr;
  149|      0|        }
  150|  20.0k|        if (i == 2) {
  ------------------
  |  Branch (150:13): [True: 0, False: 20.0k]
  ------------------
  151|      0|          return 1;
  152|      0|        }
  153|  20.0k|      }
  154|   281k|      *pval = OPENSSL_malloc(it->size);
  155|   281k|      if (!*pval) {
  ------------------
  |  Branch (155:11): [True: 0, False: 281k]
  ------------------
  156|      0|        goto memerr;
  157|      0|      }
  158|   281k|      OPENSSL_memset(*pval, 0, it->size);
  159|   281k|      asn1_refcount_set_one(pval, it);
  160|   281k|      asn1_enc_init(pval, it);
  161|  1.08M|      for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
  ------------------
  |  Branch (161:39): [True: 803k, False: 281k]
  ------------------
  162|   803k|        pseqval = asn1_get_field_ptr(pval, tt);
  163|   803k|        if (!ASN1_template_new(pseqval, tt)) {
  ------------------
  |  Branch (163:13): [True: 0, False: 803k]
  ------------------
  164|      0|          goto memerr2;
  165|      0|        }
  166|   803k|      }
  167|   281k|      if (asn1_cb && !asn1_cb(ASN1_OP_NEW_POST, pval, it, NULL)) {
  ------------------
  |  |  538|  20.0k|#define ASN1_OP_NEW_POST	1
  ------------------
  |  Branch (167:11): [True: 20.0k, False: 261k]
  |  Branch (167:22): [True: 0, False: 20.0k]
  ------------------
  168|      0|        goto auxerr2;
  169|      0|      }
  170|   281k|      break;
  171|   281k|    }
  172|   843k|  }
  173|   843k|  return 1;
  174|       |
  175|      0|memerr2:
  176|      0|  ASN1_item_ex_free(pval, it);
  177|      0|memerr:
  178|      0|  return 0;
  179|       |
  180|      0|auxerr2:
  181|      0|  ASN1_item_ex_free(pval, it);
  182|      0|auxerr:
  183|      0|  OPENSSL_PUT_ERROR(ASN1, ASN1_R_AUX_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  184|      0|  return 0;
  185|      0|}
tasn_new.c:ASN1_template_new:
  219|   803k|static int ASN1_template_new(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  220|   803k|  const ASN1_ITEM *it = ASN1_ITEM_ptr(tt->item);
  ------------------
  |  |  288|   803k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  221|   803k|  int ret;
  222|   803k|  if (tt->flags & ASN1_TFLG_OPTIONAL) {
  ------------------
  |  |  381|   803k|#define ASN1_TFLG_OPTIONAL	(0x1)
  ------------------
  |  Branch (222:7): [True: 221k, False: 582k]
  ------------------
  223|   221k|    asn1_template_clear(pval, tt);
  224|   221k|    return 1;
  225|   221k|  }
  226|       |  // If ANY DEFINED BY nothing to do
  227|       |
  228|   582k|  if (tt->flags & ASN1_TFLG_ADB_MASK) {
  ------------------
  |  |  435|   582k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (228:7): [True: 0, False: 582k]
  ------------------
  229|      0|    *pval = NULL;
  230|      0|    return 1;
  231|      0|  }
  232|       |  // If SET OF or SEQUENCE OF, its a STACK
  233|   582k|  if (tt->flags & ASN1_TFLG_SK_MASK) {
  ------------------
  |  |  390|   582k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (233:7): [True: 0, False: 582k]
  ------------------
  234|      0|    STACK_OF(ASN1_VALUE) *skval;
  ------------------
  |  |   81|      0|#define STACK_OF(type) struct stack_st_##type
  ------------------
  235|      0|    skval = sk_ASN1_VALUE_new_null();
  236|      0|    if (!skval) {
  ------------------
  |  Branch (236:9): [True: 0, False: 0]
  ------------------
  237|      0|      ret = 0;
  238|      0|      goto done;
  239|      0|    }
  240|      0|    *pval = (ASN1_VALUE *)skval;
  241|      0|    ret = 1;
  242|      0|    goto done;
  243|      0|  }
  244|       |  // Otherwise pass it back to the item routine
  245|   582k|  ret = ASN1_item_ex_new(pval, it);
  246|   582k|done:
  247|   582k|  return ret;
  248|   582k|}
tasn_new.c:asn1_template_clear:
  250|   221k|static void asn1_template_clear(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  251|       |  // If ADB or STACK just NULL the field
  252|   221k|  if (tt->flags & (ASN1_TFLG_ADB_MASK | ASN1_TFLG_SK_MASK)) {
  ------------------
  |  |  435|   221k|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
                if (tt->flags & (ASN1_TFLG_ADB_MASK | ASN1_TFLG_SK_MASK)) {
  ------------------
  |  |  390|   221k|#define ASN1_TFLG_SK_MASK	(0x3 << 1)
  ------------------
  |  Branch (252:7): [True: 20.0k, False: 200k]
  ------------------
  253|  20.0k|    *pval = NULL;
  254|   200k|  } else {
  255|   200k|    asn1_item_clear(pval, ASN1_ITEM_ptr(tt->item));
  ------------------
  |  |  288|   200k|#define ASN1_ITEM_ptr(iptr) (iptr)
  ------------------
  256|   200k|  }
  257|   221k|}
tasn_new.c:asn1_item_clear:
  187|   200k|static void asn1_item_clear(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  188|   200k|  const ASN1_EXTERN_FUNCS *ef;
  189|       |
  190|   200k|  switch (it->itype) {
  ------------------
  |  Branch (190:11): [True: 0, False: 200k]
  ------------------
  191|      0|    case ASN1_ITYPE_EXTERN:
  ------------------
  |  |  493|      0|#define ASN1_ITYPE_EXTERN		0x4
  ------------------
  |  Branch (191:5): [True: 0, False: 200k]
  ------------------
  192|      0|      ef = it->funcs;
  193|      0|      if (ef && ef->asn1_ex_clear) {
  ------------------
  |  Branch (193:11): [True: 0, False: 0]
  |  Branch (193:17): [True: 0, False: 0]
  ------------------
  194|      0|        ef->asn1_ex_clear(pval, it);
  195|      0|      } else {
  196|      0|        *pval = NULL;
  197|      0|      }
  198|      0|      break;
  199|       |
  200|   200k|    case ASN1_ITYPE_PRIMITIVE:
  ------------------
  |  |  487|   200k|#define ASN1_ITYPE_PRIMITIVE		0x0
  ------------------
  |  Branch (200:5): [True: 200k, False: 0]
  ------------------
  201|   200k|      if (it->templates) {
  ------------------
  |  Branch (201:11): [True: 0, False: 200k]
  ------------------
  202|      0|        asn1_template_clear(pval, it->templates);
  203|   200k|      } else {
  204|   200k|        asn1_primitive_clear(pval, it);
  205|   200k|      }
  206|   200k|      break;
  207|       |
  208|      0|    case ASN1_ITYPE_MSTRING:
  ------------------
  |  |  495|      0|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (208:5): [True: 0, False: 200k]
  ------------------
  209|      0|      asn1_primitive_clear(pval, it);
  210|      0|      break;
  211|       |
  212|      0|    case ASN1_ITYPE_CHOICE:
  ------------------
  |  |  491|      0|#define ASN1_ITYPE_CHOICE		0x2
  ------------------
  |  Branch (212:5): [True: 0, False: 200k]
  ------------------
  213|      0|    case ASN1_ITYPE_SEQUENCE:
  ------------------
  |  |  489|      0|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (213:5): [True: 0, False: 200k]
  ------------------
  214|      0|      *pval = NULL;
  215|      0|      break;
  216|   200k|  }
  217|   200k|}
tasn_new.c:asn1_primitive_clear:
  311|   200k|static void asn1_primitive_clear(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  312|   200k|  int utype;
  313|       |  // Historically, |it->funcs| for primitive types contained an
  314|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  315|   200k|  assert(it == NULL || it->funcs == NULL);
  316|   200k|  if (!it || (it->itype == ASN1_ITYPE_MSTRING)) {
  ------------------
  |  |  495|   200k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (316:7): [True: 0, False: 200k]
  |  Branch (316:14): [True: 0, False: 200k]
  ------------------
  317|      0|    utype = -1;
  318|   200k|  } else {
  319|   200k|    utype = it->utype;
  320|   200k|  }
  321|   200k|  if (utype == V_ASN1_BOOLEAN) {
  ------------------
  |  |  125|   200k|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (321:7): [True: 80.3k, False: 120k]
  ------------------
  322|  80.3k|    *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  323|   120k|  } else {
  324|   120k|    *pval = NULL;
  325|   120k|  }
  326|   200k|}
tasn_new.c:ASN1_primitive_new:
  262|   522k|static int ASN1_primitive_new(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  263|   522k|  if (!it) {
  ------------------
  |  Branch (263:7): [True: 0, False: 522k]
  ------------------
  264|      0|    return 0;
  265|      0|  }
  266|       |
  267|       |  // Historically, |it->funcs| for primitive types contained an
  268|       |  // |ASN1_PRIMITIVE_FUNCS| table of calbacks.
  269|   522k|  assert(it->funcs == NULL);
  270|       |
  271|   522k|  int utype;
  272|   522k|  if (it->itype == ASN1_ITYPE_MSTRING) {
  ------------------
  |  |  495|   522k|#define ASN1_ITYPE_MSTRING		0x5
  ------------------
  |  Branch (272:7): [True: 120k, False: 401k]
  ------------------
  273|   120k|    utype = -1;
  274|   401k|  } else {
  275|   401k|    utype = it->utype;
  276|   401k|  }
  277|   522k|  switch (utype) {
  278|   221k|    case V_ASN1_OBJECT:
  ------------------
  |  |  130|   221k|#define V_ASN1_OBJECT 6
  ------------------
  |  Branch (278:5): [True: 221k, False: 301k]
  ------------------
  279|   221k|      *pval = (ASN1_VALUE *)OBJ_nid2obj(NID_undef);
  ------------------
  |  |   85|   221k|#define NID_undef 0
  ------------------
  280|   221k|      return 1;
  281|       |
  282|      0|    case V_ASN1_BOOLEAN:
  ------------------
  |  |  125|      0|#define V_ASN1_BOOLEAN 1
  ------------------
  |  Branch (282:5): [True: 0, False: 522k]
  ------------------
  283|      0|      *(ASN1_BOOLEAN *)pval = (ASN1_BOOLEAN)it->size;
  284|      0|      return 1;
  285|       |
  286|      0|    case V_ASN1_NULL:
  ------------------
  |  |  129|      0|#define V_ASN1_NULL 5
  ------------------
  |  Branch (286:5): [True: 0, False: 522k]
  ------------------
  287|      0|      *pval = (ASN1_VALUE *)1;
  288|      0|      return 1;
  289|       |
  290|  60.2k|    case V_ASN1_ANY: {
  ------------------
  |  |  121|  60.2k|#define V_ASN1_ANY (-4)
  ------------------
  |  Branch (290:5): [True: 60.2k, False: 462k]
  ------------------
  291|  60.2k|      ASN1_TYPE *typ = OPENSSL_malloc(sizeof(ASN1_TYPE));
  292|  60.2k|      if (!typ) {
  ------------------
  |  Branch (292:11): [True: 0, False: 60.2k]
  ------------------
  293|      0|        return 0;
  294|      0|      }
  295|  60.2k|      typ->value.ptr = NULL;
  296|  60.2k|      typ->type = -1;
  297|  60.2k|      *pval = (ASN1_VALUE *)typ;
  298|  60.2k|      break;
  299|  60.2k|    }
  300|       |
  301|   241k|    default:
  ------------------
  |  Branch (301:5): [True: 241k, False: 281k]
  ------------------
  302|   241k|      *pval = (ASN1_VALUE *)ASN1_STRING_type_new(utype);
  303|   241k|      break;
  304|   522k|  }
  305|   301k|  if (*pval) {
  ------------------
  |  Branch (305:7): [True: 301k, False: 0]
  ------------------
  306|   301k|    return 1;
  307|   301k|  }
  308|      0|  return 0;
  309|   301k|}

ASN1_OCTET_STRING_free:
   67|  20.0k|  void sname##_free(sname *x) { ASN1_STRING_free(x); }
ASN1_INTEGER_new:
   66|  20.0k|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \
ASN1_BIT_STRING_new:
   66|  20.0k|  sname *sname##_new(void) { return ASN1_STRING_type_new(V_##sname); } \
ASN1_BIT_STRING_free:
   67|  20.0k|  void sname##_free(sname *x) { ASN1_STRING_free(x); }

asn1_refcount_set_one:
  106|   281k|void asn1_refcount_set_one(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  107|   281k|  CRYPTO_refcount_t *references = asn1_get_references(pval, it);
  108|   281k|  if (references != NULL) {
  ------------------
  |  Branch (108:7): [True: 0, False: 281k]
  ------------------
  109|      0|    *references = 1;
  110|      0|  }
  111|   281k|}
asn1_refcount_dec_and_test_zero:
  113|   281k|int asn1_refcount_dec_and_test_zero(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  114|   281k|  CRYPTO_refcount_t *references = asn1_get_references(pval, it);
  115|   281k|  if (references != NULL) {
  ------------------
  |  Branch (115:7): [True: 0, False: 281k]
  ------------------
  116|      0|    return CRYPTO_refcount_dec_and_test_zero(references);
  117|      0|  }
  118|   281k|  return 1;
  119|   281k|}
asn1_enc_init:
  134|   281k|void asn1_enc_init(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  135|   281k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  136|   281k|  if (enc) {
  ------------------
  |  Branch (136:7): [True: 20.0k, False: 261k]
  ------------------
  137|  20.0k|    enc->enc = NULL;
  138|  20.0k|    enc->len = 0;
  139|  20.0k|    enc->buf = NULL;
  140|  20.0k|  }
  141|   281k|}
asn1_enc_free:
  143|   281k|void asn1_enc_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  144|   281k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  145|   281k|  if (enc) {
  ------------------
  |  Branch (145:7): [True: 20.0k, False: 261k]
  ------------------
  146|  20.0k|    asn1_encoding_clear(enc);
  147|  20.0k|  }
  148|   281k|}
asn1_enc_save:
  151|   241k|                  const ASN1_ITEM *it, CRYPTO_BUFFER *buf) {
  152|   241k|  ASN1_ENCODING *enc;
  153|   241k|  enc = asn1_get_enc_ptr(pval, it);
  154|   241k|  if (!enc) {
  ------------------
  |  Branch (154:7): [True: 221k, False: 20.0k]
  ------------------
  155|   221k|    return 1;
  156|   221k|  }
  157|       |
  158|  20.0k|  asn1_encoding_clear(enc);
  159|  20.0k|  if (buf != NULL) {
  ------------------
  |  Branch (159:7): [True: 20.0k, False: 2]
  ------------------
  160|  20.0k|    assert(CRYPTO_BUFFER_data(buf) <= in &&
  161|  20.0k|           in + in_len <= CRYPTO_BUFFER_data(buf) + CRYPTO_BUFFER_len(buf));
  162|  20.0k|    CRYPTO_BUFFER_up_ref(buf);
  163|  20.0k|    enc->buf = buf;
  164|  20.0k|    enc->enc = (uint8_t *)in;
  165|  20.0k|  } else {
  166|      2|    enc->enc = OPENSSL_memdup(in, in_len);
  167|      2|    if (!enc->enc) {
  ------------------
  |  Branch (167:9): [True: 0, False: 2]
  ------------------
  168|      0|      return 0;
  169|      0|    }
  170|      2|  }
  171|       |
  172|  20.0k|  enc->len = in_len;
  173|  20.0k|  return 1;
  174|  20.0k|}
asn1_encoding_clear:
  176|  40.1k|void asn1_encoding_clear(ASN1_ENCODING *enc) {
  177|  40.1k|  if (enc->buf != NULL) {
  ------------------
  |  Branch (177:7): [True: 20.0k, False: 20.0k]
  ------------------
  178|  20.0k|    CRYPTO_BUFFER_free(enc->buf);
  179|  20.0k|  } else {
  180|  20.0k|    OPENSSL_free(enc->enc);
  181|  20.0k|  }
  182|  40.1k|  enc->enc = NULL;
  183|  40.1k|  enc->len = 0;
  184|  40.1k|  enc->buf = NULL;
  185|  40.1k|}
asn1_enc_restore:
  188|   255k|                     const ASN1_ITEM *it) {
  189|   255k|  ASN1_ENCODING *enc = asn1_get_enc_ptr(pval, it);
  190|   255k|  if (!enc || enc->len == 0) {
  ------------------
  |  Branch (190:7): [True: 188k, False: 67.4k]
  |  Branch (190:15): [True: 0, False: 67.4k]
  ------------------
  191|   188k|    return 0;
  192|   188k|  }
  193|  67.4k|  if (out) {
  ------------------
  |  Branch (193:7): [True: 33.7k, False: 33.7k]
  ------------------
  194|  33.7k|    OPENSSL_memcpy(*out, enc->enc, enc->len);
  195|  33.7k|    *out += enc->len;
  196|  33.7k|  }
  197|  67.4k|  if (len) {
  ------------------
  |  Branch (197:7): [True: 67.4k, False: 0]
  ------------------
  198|  67.4k|    *len = enc->len;
  199|  67.4k|  }
  200|  67.4k|  return 1;
  201|   255k|}
asn1_get_field_ptr:
  204|  2.85M|ASN1_VALUE **asn1_get_field_ptr(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt) {
  205|  2.85M|  ASN1_VALUE **pvaltmp = offset2ptr(*pval, tt->offset);
  ------------------
  |  |   76|  2.85M|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  206|       |  // NOTE for BOOLEAN types the field is just a plain int so we can't return
  207|       |  // int **, so settle for (int *).
  208|  2.85M|  return pvaltmp;
  209|  2.85M|}
asn1_do_adb:
  214|  2.05M|                                 int nullerr) {
  215|  2.05M|  const ASN1_ADB *adb;
  216|  2.05M|  const ASN1_ADB_TABLE *atbl;
  217|  2.05M|  ASN1_VALUE **sfld;
  218|  2.05M|  int i;
  219|  2.05M|  if (!(tt->flags & ASN1_TFLG_ADB_MASK)) {
  ------------------
  |  |  435|  2.05M|#define ASN1_TFLG_ADB_MASK	(0x3<<8)
  ------------------
  |  Branch (219:7): [True: 2.05M, False: 0]
  ------------------
  220|  2.05M|    return tt;
  221|  2.05M|  }
  222|       |
  223|       |  // Else ANY DEFINED BY ... get the table
  224|      0|  adb = ASN1_ADB_ptr(tt->item);
  ------------------
  |  |   79|      0|#define ASN1_ADB_ptr(iptr) ((const ASN1_ADB *)(iptr))
  ------------------
  225|       |
  226|       |  // Get the selector field
  227|      0|  sfld = offset2ptr(*pval, adb->offset);
  ------------------
  |  |   76|      0|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  228|       |
  229|       |  // Check if NULL
  230|      0|  if (*sfld == NULL) {
  ------------------
  |  Branch (230:7): [True: 0, False: 0]
  ------------------
  231|      0|    if (!adb->null_tt) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      goto err;
  233|      0|    }
  234|      0|    return adb->null_tt;
  235|      0|  }
  236|       |
  237|       |  // Convert type to a NID:
  238|       |  // NB: don't check for NID_undef here because it
  239|       |  // might be a legitimate value in the table
  240|      0|  assert(tt->flags & ASN1_TFLG_ADB_OID);
  241|      0|  int selector = OBJ_obj2nid((ASN1_OBJECT *)*sfld);
  242|       |
  243|       |  // Try to find matching entry in table Maybe should check application types
  244|       |  // first to allow application override? Might also be useful to have a flag
  245|       |  // which indicates table is sorted and we can do a binary search. For now
  246|       |  // stick to a linear search.
  247|       |
  248|      0|  for (atbl = adb->tbl, i = 0; i < adb->tblcount; i++, atbl++) {
  ------------------
  |  Branch (248:32): [True: 0, False: 0]
  ------------------
  249|      0|    if (atbl->value == selector) {
  ------------------
  |  Branch (249:9): [True: 0, False: 0]
  ------------------
  250|      0|      return &atbl->tt;
  251|      0|    }
  252|      0|  }
  253|       |
  254|       |  // FIXME: need to search application table too
  255|       |
  256|       |  // No match, return default type
  257|      0|  if (!adb->default_tt) {
  ------------------
  |  Branch (257:7): [True: 0, False: 0]
  ------------------
  258|      0|    goto err;
  259|      0|  }
  260|      0|  return adb->default_tt;
  261|       |
  262|      0|err:
  263|       |  // FIXME: should log the value or OID of unsupported type
  264|      0|  if (nullerr) {
  ------------------
  |  Branch (264:7): [True: 0, False: 0]
  ------------------
  265|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  266|      0|  }
  267|      0|  return NULL;
  268|      0|}
tasn_utl.c:asn1_get_references:
   95|   562k|                                              const ASN1_ITEM *it) {
   96|   562k|  if (it->itype != ASN1_ITYPE_SEQUENCE) {
  ------------------
  |  |  489|   562k|#define ASN1_ITYPE_SEQUENCE		0x1
  ------------------
  |  Branch (96:7): [True: 0, False: 562k]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|   562k|  const ASN1_AUX *aux = it->funcs;
  100|   562k|  if (!aux || !(aux->flags & ASN1_AFLG_REFCOUNT)) {
  ------------------
  |  |  531|  80.3k|#define ASN1_AFLG_REFCOUNT	1
  ------------------
  |  Branch (100:7): [True: 482k, False: 80.3k]
  |  Branch (100:15): [True: 80.3k, False: 0]
  ------------------
  101|   562k|    return NULL;
  102|   562k|  }
  103|      0|  return offset2ptr(*pval, aux->ref_offset);
  ------------------
  |  |   76|      0|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  104|   562k|}
tasn_utl.c:asn1_get_enc_ptr:
  121|  1.05M|static ASN1_ENCODING *asn1_get_enc_ptr(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  122|  1.05M|  assert(it->itype == ASN1_ITYPE_SEQUENCE);
  123|  1.05M|  const ASN1_AUX *aux;
  124|  1.05M|  if (!pval || !*pval) {
  ------------------
  |  Branch (124:7): [True: 0, False: 1.05M]
  |  Branch (124:16): [True: 0, False: 1.05M]
  ------------------
  125|      0|    return NULL;
  126|      0|  }
  127|  1.05M|  aux = it->funcs;
  128|  1.05M|  if (!aux || !(aux->flags & ASN1_AFLG_ENCODING)) {
  ------------------
  |  |  533|   188k|#define ASN1_AFLG_ENCODING	2
  ------------------
  |  Branch (128:7): [True: 871k, False: 188k]
  |  Branch (128:15): [True: 60.2k, False: 127k]
  ------------------
  129|   931k|    return NULL;
  130|   931k|  }
  131|   127k|  return offset2ptr(*pval, aux->enc_offset);
  ------------------
  |  |   76|   127k|#define offset2ptr(addr, offset) (void *)(((char *)(addr)) + (offset))
  ------------------
  132|  1.05M|}

BN_parse_asn1_unsigned:
   21|  45.4k|int BN_parse_asn1_unsigned(CBS *cbs, BIGNUM *ret) {
   22|  45.4k|  CBS child;
   23|  45.4k|  int is_negative;
   24|  45.4k|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  45.4k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (24:7): [True: 0, False: 45.4k]
  ------------------
   25|  45.4k|      !CBS_is_valid_asn1_integer(&child, &is_negative)) {
  ------------------
  |  Branch (25:7): [True: 0, False: 45.4k]
  ------------------
   26|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BAD_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   27|      0|    return 0;
   28|      0|  }
   29|       |
   30|  45.4k|  if (is_negative) {
  ------------------
  |  Branch (30:7): [True: 0, False: 45.4k]
  ------------------
   31|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   32|      0|    return 0;
   33|      0|  }
   34|       |
   35|  45.4k|  return BN_bin2bn(CBS_data(&child), CBS_len(&child), ret) != NULL;
   36|  45.4k|}

BUF_MEM_new:
   67|  85.1k|BUF_MEM *BUF_MEM_new(void) {
   68|  85.1k|  BUF_MEM *ret;
   69|       |
   70|  85.1k|  ret = OPENSSL_malloc(sizeof(BUF_MEM));
   71|  85.1k|  if (ret == NULL) {
  ------------------
  |  Branch (71:7): [True: 0, False: 85.1k]
  ------------------
   72|      0|    return NULL;
   73|      0|  }
   74|       |
   75|  85.1k|  OPENSSL_memset(ret, 0, sizeof(BUF_MEM));
   76|  85.1k|  return ret;
   77|  85.1k|}
BUF_MEM_free:
   79|  85.1k|void BUF_MEM_free(BUF_MEM *buf) {
   80|  85.1k|  if (buf == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 85.1k]
  ------------------
   81|      0|    return;
   82|      0|  }
   83|       |
   84|  85.1k|  OPENSSL_free(buf->data);
   85|  85.1k|  OPENSSL_free(buf);
   86|  85.1k|}
BUF_MEM_reserve:
   88|  40.1k|int BUF_MEM_reserve(BUF_MEM *buf, size_t cap) {
   89|  40.1k|  if (buf->max >= cap) {
  ------------------
  |  Branch (89:7): [True: 0, False: 40.1k]
  ------------------
   90|      0|    return 1;
   91|      0|  }
   92|       |
   93|  40.1k|  size_t n = cap + 3;
   94|  40.1k|  if (n < cap) {
  ------------------
  |  Branch (94:7): [True: 0, False: 40.1k]
  ------------------
   95|      0|    OPENSSL_PUT_ERROR(BUF, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   96|      0|    return 0;
   97|      0|  }
   98|  40.1k|  n = n / 3;
   99|  40.1k|  size_t alloc_size = n * 4;
  100|  40.1k|  if (alloc_size / 4 != n) {
  ------------------
  |  Branch (100:7): [True: 0, False: 40.1k]
  ------------------
  101|      0|    OPENSSL_PUT_ERROR(BUF, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  102|      0|    return 0;
  103|      0|  }
  104|       |
  105|  40.1k|  char *new_buf = OPENSSL_realloc(buf->data, alloc_size);
  106|  40.1k|  if (new_buf == NULL) {
  ------------------
  |  Branch (106:7): [True: 0, False: 40.1k]
  ------------------
  107|      0|    return 0;
  108|      0|  }
  109|       |
  110|  40.1k|  buf->data = new_buf;
  111|  40.1k|  buf->max = alloc_size;
  112|  40.1k|  return 1;
  113|  40.1k|}
BUF_MEM_grow:
  115|  40.1k|size_t BUF_MEM_grow(BUF_MEM *buf, size_t len) {
  116|  40.1k|  if (!BUF_MEM_reserve(buf, len)) {
  ------------------
  |  Branch (116:7): [True: 0, False: 40.1k]
  ------------------
  117|      0|    return 0;
  118|      0|  }
  119|  40.1k|  if (buf->length < len) {
  ------------------
  |  Branch (119:7): [True: 40.1k, False: 0]
  ------------------
  120|  40.1k|    OPENSSL_memset(&buf->data[buf->length], 0, len - buf->length);
  121|  40.1k|  }
  122|  40.1k|  buf->length = len;
  123|  40.1k|  return len;
  124|  40.1k|}

CBB_finish_i2d:
   28|  33.7k|int CBB_finish_i2d(CBB *cbb, uint8_t **outp) {
   29|  33.7k|  assert(!cbb->is_child);
   30|  33.7k|  assert(cbb->u.base.can_resize);
   31|       |
   32|  33.7k|  uint8_t *der;
   33|  33.7k|  size_t der_len;
   34|  33.7k|  if (!CBB_finish(cbb, &der, &der_len)) {
  ------------------
  |  Branch (34:7): [True: 0, False: 33.7k]
  ------------------
   35|      0|    CBB_cleanup(cbb);
   36|      0|    return -1;
   37|      0|  }
   38|  33.7k|  if (der_len > INT_MAX) {
  ------------------
  |  Branch (38:7): [True: 0, False: 33.7k]
  ------------------
   39|      0|    OPENSSL_free(der);
   40|      0|    return -1;
   41|      0|  }
   42|  33.7k|  if (outp != NULL) {
  ------------------
  |  Branch (42:7): [True: 33.7k, False: 0]
  ------------------
   43|  33.7k|    if (*outp == NULL) {
  ------------------
  |  Branch (43:9): [True: 33.7k, False: 0]
  ------------------
   44|  33.7k|      *outp = der;
   45|  33.7k|      der = NULL;
   46|  33.7k|    } else {
   47|      0|      OPENSSL_memcpy(*outp, der, der_len);
   48|      0|      *outp += der_len;
   49|      0|    }
   50|  33.7k|  }
   51|  33.7k|  OPENSSL_free(der);
   52|  33.7k|  return (int)der_len;
   53|  33.7k|}

CBB_zero:
   27|   147k|void CBB_zero(CBB *cbb) {
   28|   147k|  OPENSSL_memset(cbb, 0, sizeof(CBB));
   29|   147k|}
CBB_init:
   41|  73.9k|int CBB_init(CBB *cbb, size_t initial_capacity) {
   42|  73.9k|  CBB_zero(cbb);
   43|       |
   44|  73.9k|  uint8_t *buf = OPENSSL_malloc(initial_capacity);
   45|  73.9k|  if (initial_capacity > 0 && buf == NULL) {
  ------------------
  |  Branch (45:7): [True: 73.9k, False: 0]
  |  Branch (45:31): [True: 0, False: 73.9k]
  ------------------
   46|      0|    return 0;
   47|      0|  }
   48|       |
   49|  73.9k|  cbb_init(cbb, buf, initial_capacity, /*can_resize=*/1);
   50|  73.9k|  return 1;
   51|  73.9k|}
CBB_cleanup:
   59|  73.9k|void CBB_cleanup(CBB *cbb) {
   60|       |  // Child |CBB|s are non-owning. They are implicitly discarded and should not
   61|       |  // be used with |CBB_cleanup| or |ScopedCBB|.
   62|  73.9k|  assert(!cbb->is_child);
   63|  73.9k|  if (cbb->is_child) {
  ------------------
  |  Branch (63:7): [True: 0, False: 73.9k]
  ------------------
   64|      0|    return;
   65|      0|  }
   66|       |
   67|  73.9k|  if (cbb->u.base.can_resize) {
  ------------------
  |  Branch (67:7): [True: 73.9k, False: 0]
  ------------------
   68|  73.9k|    OPENSSL_free(cbb->u.base.buf);
   69|  73.9k|  }
   70|  73.9k|}
CBB_finish:
  125|  73.9k|int CBB_finish(CBB *cbb, uint8_t **out_data, size_t *out_len) {
  126|  73.9k|  if (cbb->is_child) {
  ------------------
  |  Branch (126:7): [True: 0, False: 73.9k]
  ------------------
  127|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  128|      0|    return 0;
  129|      0|  }
  130|       |
  131|  73.9k|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (131:7): [True: 0, False: 73.9k]
  ------------------
  132|      0|    return 0;
  133|      0|  }
  134|       |
  135|  73.9k|  if (cbb->u.base.can_resize && (out_data == NULL || out_len == NULL)) {
  ------------------
  |  Branch (135:7): [True: 73.9k, False: 0]
  |  Branch (135:34): [True: 0, False: 73.9k]
  |  Branch (135:54): [True: 0, False: 73.9k]
  ------------------
  136|       |    // |out_data| and |out_len| can only be NULL if the CBB is fixed.
  137|      0|    return 0;
  138|      0|  }
  139|       |
  140|  73.9k|  if (out_data != NULL) {
  ------------------
  |  Branch (140:7): [True: 73.9k, False: 0]
  ------------------
  141|  73.9k|    *out_data = cbb->u.base.buf;
  142|  73.9k|  }
  143|  73.9k|  if (out_len != NULL) {
  ------------------
  |  Branch (143:7): [True: 73.9k, False: 0]
  ------------------
  144|  73.9k|    *out_len = cbb->u.base.len;
  145|  73.9k|  }
  146|  73.9k|  cbb->u.base.buf = NULL;
  147|  73.9k|  CBB_cleanup(cbb);
  148|  73.9k|  return 1;
  149|  73.9k|}
CBB_flush:
  161|   597k|int CBB_flush(CBB *cbb) {
  162|       |  // If |base| has hit an error, the buffer is in an undefined state, so
  163|       |  // fail all following calls. In particular, |cbb->child| may point to invalid
  164|       |  // memory.
  165|   597k|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  166|   597k|  if (base == NULL || base->error) {
  ------------------
  |  Branch (166:7): [True: 0, False: 597k]
  |  Branch (166:23): [True: 0, False: 597k]
  ------------------
  167|      0|    return 0;
  168|      0|  }
  169|       |
  170|   597k|  if (cbb->child == NULL) {
  ------------------
  |  Branch (170:7): [True: 564k, False: 33.7k]
  ------------------
  171|       |    // Nothing to flush.
  172|   564k|    return 1;
  173|   564k|  }
  174|       |
  175|  33.7k|  assert(cbb->child->is_child);
  176|  33.7k|  struct cbb_child_st *child = &cbb->child->u.child;
  177|  33.7k|  assert(child->base == base);
  178|  33.7k|  size_t child_start = child->offset + child->pending_len_len;
  179|       |
  180|  33.7k|  if (!CBB_flush(cbb->child) ||
  ------------------
  |  Branch (180:7): [True: 0, False: 33.7k]
  ------------------
  181|  33.7k|      child_start < child->offset ||
  ------------------
  |  Branch (181:7): [True: 0, False: 33.7k]
  ------------------
  182|  33.7k|      base->len < child_start) {
  ------------------
  |  Branch (182:7): [True: 0, False: 33.7k]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|  33.7k|  size_t len = base->len - child_start;
  187|       |
  188|  33.7k|  if (child->pending_is_asn1) {
  ------------------
  |  Branch (188:7): [True: 33.7k, False: 0]
  ------------------
  189|       |    // For ASN.1 we assume that we'll only need a single byte for the length.
  190|       |    // If that turned out to be incorrect, we have to move the contents along
  191|       |    // in order to make space.
  192|  33.7k|    uint8_t len_len;
  193|  33.7k|    uint8_t initial_length_byte;
  194|       |
  195|  33.7k|    assert (child->pending_len_len == 1);
  196|       |
  197|  33.7k|    if (len > 0xfffffffe) {
  ------------------
  |  Branch (197:9): [True: 0, False: 33.7k]
  ------------------
  198|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  199|       |      // Too large.
  200|      0|      goto err;
  201|  33.7k|    } else if (len > 0xffffff) {
  ------------------
  |  Branch (201:16): [True: 0, False: 33.7k]
  ------------------
  202|      0|      len_len = 5;
  203|      0|      initial_length_byte = 0x80 | 4;
  204|  33.7k|    } else if (len > 0xffff) {
  ------------------
  |  Branch (204:16): [True: 0, False: 33.7k]
  ------------------
  205|      0|      len_len = 4;
  206|      0|      initial_length_byte = 0x80 | 3;
  207|  33.7k|    } else if (len > 0xff) {
  ------------------
  |  Branch (207:16): [True: 33.7k, False: 0]
  ------------------
  208|  33.7k|      len_len = 3;
  209|  33.7k|      initial_length_byte = 0x80 | 2;
  210|  33.7k|    } else if (len > 0x7f) {
  ------------------
  |  Branch (210:16): [True: 0, False: 0]
  ------------------
  211|      0|      len_len = 2;
  212|      0|      initial_length_byte = 0x80 | 1;
  213|      0|    } else {
  214|      0|      len_len = 1;
  215|      0|      initial_length_byte = (uint8_t)len;
  216|      0|      len = 0;
  217|      0|    }
  218|       |
  219|  33.7k|    if (len_len != 1) {
  ------------------
  |  Branch (219:9): [True: 33.7k, False: 0]
  ------------------
  220|       |      // We need to move the contents along in order to make space.
  221|  33.7k|      size_t extra_bytes = len_len - 1;
  222|  33.7k|      if (!cbb_buffer_add(base, NULL, extra_bytes)) {
  ------------------
  |  Branch (222:11): [True: 0, False: 33.7k]
  ------------------
  223|      0|        goto err;
  224|      0|      }
  225|  33.7k|      OPENSSL_memmove(base->buf + child_start + extra_bytes,
  226|  33.7k|                      base->buf + child_start, len);
  227|  33.7k|    }
  228|  33.7k|    base->buf[child->offset++] = initial_length_byte;
  229|  33.7k|    child->pending_len_len = len_len - 1;
  230|  33.7k|  }
  231|       |
  232|   101k|  for (size_t i = child->pending_len_len - 1; i < child->pending_len_len; i--) {
  ------------------
  |  Branch (232:47): [True: 67.4k, False: 33.7k]
  ------------------
  233|  67.4k|    base->buf[child->offset + i] = (uint8_t)len;
  234|  67.4k|    len >>= 8;
  235|  67.4k|  }
  236|  33.7k|  if (len != 0) {
  ------------------
  |  Branch (236:7): [True: 0, False: 33.7k]
  ------------------
  237|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  238|      0|    goto err;
  239|      0|  }
  240|       |
  241|  33.7k|  child->base = NULL;
  242|  33.7k|  cbb->child = NULL;
  243|       |
  244|  33.7k|  return 1;
  245|       |
  246|      0|err:
  247|      0|  base->error = 1;
  248|      0|  return 0;
  249|  33.7k|}
CBB_add_asn1:
  342|  33.7k|int CBB_add_asn1(CBB *cbb, CBB *out_contents, CBS_ASN1_TAG tag) {
  343|  33.7k|  if (!CBB_flush(cbb)) {
  ------------------
  |  Branch (343:7): [True: 0, False: 33.7k]
  ------------------
  344|      0|    return 0;
  345|      0|  }
  346|       |
  347|       |  // Split the tag into leading bits and tag number.
  348|  33.7k|  uint8_t tag_bits = (tag >> CBS_ASN1_TAG_SHIFT) & 0xe0;
  ------------------
  |  |  193|  33.7k|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  349|  33.7k|  CBS_ASN1_TAG tag_number = tag & CBS_ASN1_TAG_NUMBER_MASK;
  ------------------
  |  |  210|  33.7k|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|  33.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  350|  33.7k|  if (tag_number >= 0x1f) {
  ------------------
  |  Branch (350:7): [True: 0, False: 33.7k]
  ------------------
  351|       |    // Set all the bits in the tag number to signal high tag number form.
  352|      0|    if (!CBB_add_u8(cbb, tag_bits | 0x1f) ||
  ------------------
  |  Branch (352:9): [True: 0, False: 0]
  ------------------
  353|      0|        !add_base128_integer(cbb, tag_number)) {
  ------------------
  |  Branch (353:9): [True: 0, False: 0]
  ------------------
  354|      0|      return 0;
  355|      0|    }
  356|  33.7k|  } else if (!CBB_add_u8(cbb, tag_bits | tag_number)) {
  ------------------
  |  Branch (356:14): [True: 0, False: 33.7k]
  ------------------
  357|      0|    return 0;
  358|      0|  }
  359|       |
  360|       |  // Reserve one byte of length prefix. |CBB_flush| will finish it later.
  361|  33.7k|  return cbb_add_child(cbb, out_contents, /*len_len=*/1, /*is_asn1=*/1);
  362|  33.7k|}
CBB_add_space:
  382|   456k|int CBB_add_space(CBB *cbb, uint8_t **out_data, size_t len) {
  383|   456k|  if (!CBB_flush(cbb) ||
  ------------------
  |  Branch (383:7): [True: 0, False: 456k]
  ------------------
  384|   456k|      !cbb_buffer_add(cbb_get_base(cbb), out_data, len)) {
  ------------------
  |  Branch (384:7): [True: 0, False: 456k]
  ------------------
  385|      0|    return 0;
  386|      0|  }
  387|   456k|  return 1;
  388|   456k|}
CBB_add_u8:
  430|   355k|int CBB_add_u8(CBB *cbb, uint8_t value) {
  431|   355k|  return cbb_add_u(cbb, value, 1);
  432|   355k|}
cbb.c:cbb_init:
   31|  73.9k|static void cbb_init(CBB *cbb, uint8_t *buf, size_t cap, int can_resize) {
   32|  73.9k|  cbb->is_child = 0;
   33|  73.9k|  cbb->child = NULL;
   34|  73.9k|  cbb->u.base.buf = buf;
   35|  73.9k|  cbb->u.base.len = 0;
   36|  73.9k|  cbb->u.base.cap = cap;
   37|  73.9k|  cbb->u.base.can_resize = can_resize;
   38|  73.9k|  cbb->u.base.error = 0;
   39|  73.9k|}
cbb.c:cbb_get_base:
  151|  1.08M|static struct cbb_buffer_st *cbb_get_base(CBB *cbb) {
  152|  1.08M|  if (cbb->is_child) {
  ------------------
  |  Branch (152:7): [True: 236k, False: 851k]
  ------------------
  153|   236k|    return cbb->u.child.base;
  154|   236k|  }
  155|   851k|  return &cbb->u.base;
  156|  1.08M|}
cbb.c:cbb_buffer_add:
  116|   523k|                          size_t len) {
  117|   523k|  if (!cbb_buffer_reserve(base, out, len)) {
  ------------------
  |  Branch (117:7): [True: 0, False: 523k]
  ------------------
  118|      0|    return 0;
  119|      0|  }
  120|       |  // This will not overflow or |cbb_buffer_reserve| would have failed.
  121|   523k|  base->len += len;
  122|   523k|  return 1;
  123|   523k|}
cbb.c:cbb_add_child:
  272|  33.7k|                         int is_asn1) {
  273|  33.7k|  assert(cbb->child == NULL);
  274|  33.7k|  assert(!is_asn1 || len_len == 1);
  275|  33.7k|  struct cbb_buffer_st *base = cbb_get_base(cbb);
  276|  33.7k|  size_t offset = base->len;
  277|       |
  278|       |  // Reserve space for the length prefix.
  279|  33.7k|  uint8_t *prefix_bytes;
  280|  33.7k|  if (!cbb_buffer_add(base, &prefix_bytes, len_len)) {
  ------------------
  |  Branch (280:7): [True: 0, False: 33.7k]
  ------------------
  281|      0|    return 0;
  282|      0|  }
  283|  33.7k|  OPENSSL_memset(prefix_bytes, 0, len_len);
  284|       |
  285|  33.7k|  CBB_zero(out_child);
  286|  33.7k|  out_child->is_child = 1;
  287|  33.7k|  out_child->u.child.base = base;
  288|  33.7k|  out_child->u.child.offset = offset;
  289|  33.7k|  out_child->u.child.pending_len_len = len_len;
  290|  33.7k|  out_child->u.child.pending_is_asn1 = is_asn1;
  291|  33.7k|  cbb->child = out_child;
  292|  33.7k|  return 1;
  293|  33.7k|}
cbb.c:cbb_buffer_reserve:
   73|   523k|                              size_t len) {
   74|   523k|  if (base == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 523k]
  ------------------
   75|      0|    return 0;
   76|      0|  }
   77|       |
   78|   523k|  size_t newlen = base->len + len;
   79|   523k|  if (newlen < base->len) {
  ------------------
  |  Branch (79:7): [True: 0, False: 523k]
  ------------------
   80|       |    // Overflow
   81|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   82|      0|    goto err;
   83|      0|  }
   84|       |
   85|   523k|  if (newlen > base->cap) {
  ------------------
  |  Branch (85:7): [True: 67.4k, False: 456k]
  ------------------
   86|  67.4k|    if (!base->can_resize) {
  ------------------
  |  Branch (86:9): [True: 0, False: 67.4k]
  ------------------
   87|      0|      OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   88|      0|      goto err;
   89|      0|    }
   90|       |
   91|  67.4k|    size_t newcap = base->cap * 2;
   92|  67.4k|    if (newcap < base->cap || newcap < newlen) {
  ------------------
  |  Branch (92:9): [True: 0, False: 67.4k]
  |  Branch (92:31): [True: 33.7k, False: 33.7k]
  ------------------
   93|  33.7k|      newcap = newlen;
   94|  33.7k|    }
   95|  67.4k|    uint8_t *newbuf = OPENSSL_realloc(base->buf, newcap);
   96|  67.4k|    if (newbuf == NULL) {
  ------------------
  |  Branch (96:9): [True: 0, False: 67.4k]
  ------------------
   97|      0|      goto err;
   98|      0|    }
   99|       |
  100|  67.4k|    base->buf = newbuf;
  101|  67.4k|    base->cap = newcap;
  102|  67.4k|  }
  103|       |
  104|   523k|  if (out) {
  ------------------
  |  Branch (104:7): [True: 490k, False: 33.7k]
  ------------------
  105|   490k|    *out = base->buf + base->len;
  106|   490k|  }
  107|       |
  108|   523k|  return 1;
  109|       |
  110|      0|err:
  111|      0|  base->error = 1;
  112|      0|  return 0;
  113|   523k|}
cbb.c:cbb_add_u:
  410|   355k|static int cbb_add_u(CBB *cbb, uint64_t v, size_t len_len) {
  411|   355k|  uint8_t *buf;
  412|   355k|  if (!CBB_add_space(cbb, &buf, len_len)) {
  ------------------
  |  Branch (412:7): [True: 0, False: 355k]
  ------------------
  413|      0|    return 0;
  414|      0|  }
  415|       |
  416|   710k|  for (size_t i = len_len - 1; i < len_len; i--) {
  ------------------
  |  Branch (416:32): [True: 355k, False: 355k]
  ------------------
  417|   355k|    buf[i] = v;
  418|   355k|    v >>= 8;
  419|   355k|  }
  420|       |
  421|       |  // |v| must fit in |len_len| bytes.
  422|   355k|  if (v != 0) {
  ------------------
  |  Branch (422:7): [True: 0, False: 355k]
  ------------------
  423|      0|    cbb_get_base(cbb)->error = 1;
  424|      0|    return 0;
  425|      0|  }
  426|       |
  427|   355k|  return 1;
  428|   355k|}

CBS_init:
   29|  3.33M|void CBS_init(CBS *cbs, const uint8_t *data, size_t len) {
   30|  3.33M|  cbs->data = data;
   31|  3.33M|  cbs->len = len;
   32|  3.33M|}
CBS_skip:
   45|  1.53M|int CBS_skip(CBS *cbs, size_t len) {
   46|  1.53M|  const uint8_t *dummy;
   47|  1.53M|  return cbs_get(cbs, &dummy, len);
   48|  1.53M|}
CBS_data:
   50|  1.50M|const uint8_t *CBS_data(const CBS *cbs) {
   51|  1.50M|  return cbs->data;
   52|  1.50M|}
CBS_len:
   54|  6.83M|size_t CBS_len(const CBS *cbs) {
   55|  6.83M|  return cbs->len;
   56|  6.83M|}
CBS_get_u8:
  108|  6.19M|int CBS_get_u8(CBS *cbs, uint8_t *out) {
  109|  6.19M|  const uint8_t *v;
  110|  6.19M|  if (!cbs_get(cbs, &v, 1)) {
  ------------------
  |  Branch (110:7): [True: 206k, False: 5.98M]
  ------------------
  111|   206k|    return 0;
  112|   206k|  }
  113|  5.98M|  *out = *v;
  114|  5.98M|  return 1;
  115|  6.19M|}
CBS_get_u16:
  117|  59.5k|int CBS_get_u16(CBS *cbs, uint16_t *out) {
  118|  59.5k|  uint64_t v;
  119|  59.5k|  if (!cbs_get_u(cbs, &v, 2)) {
  ------------------
  |  Branch (119:7): [True: 4.47k, False: 55.0k]
  ------------------
  120|  4.47k|    return 0;
  121|  4.47k|  }
  122|  55.0k|  *out = v;
  123|  55.0k|  return 1;
  124|  59.5k|}
CBS_get_u32:
  143|  30.1k|int CBS_get_u32(CBS *cbs, uint32_t *out) {
  144|  30.1k|  uint64_t v;
  145|  30.1k|  if (!cbs_get_u(cbs, &v, 4)) {
  ------------------
  |  Branch (145:7): [True: 298, False: 29.8k]
  ------------------
  146|    298|    return 0;
  147|    298|  }
  148|  29.8k|  *out = (uint32_t)v;
  149|  29.8k|  return 1;
  150|  30.1k|}
CBS_get_bytes:
  181|  1.72M|int CBS_get_bytes(CBS *cbs, CBS *out, size_t len) {
  182|  1.72M|  const uint8_t *v;
  183|  1.72M|  if (!cbs_get(cbs, &v, len)) {
  ------------------
  |  Branch (183:7): [True: 8.47k, False: 1.72M]
  ------------------
  184|  8.47k|    return 0;
  185|  8.47k|  }
  186|  1.72M|  CBS_init(out, v, len);
  187|  1.72M|  return 1;
  188|  1.72M|}
CBS_get_u8_length_prefixed:
  210|   113k|int CBS_get_u8_length_prefixed(CBS *cbs, CBS *out) {
  211|   113k|  return cbs_get_length_prefixed(cbs, out, 1);
  212|   113k|}
CBS_get_u16_length_prefixed:
  214|  68.7k|int CBS_get_u16_length_prefixed(CBS *cbs, CBS *out) {
  215|  68.7k|  return cbs_get_length_prefixed(cbs, out, 2);
  216|  68.7k|}
CBS_get_any_asn1:
  421|  1.10M|int CBS_get_any_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG *out_tag) {
  422|  1.10M|  size_t header_len;
  423|  1.10M|  if (!CBS_get_any_asn1_element(cbs, out, out_tag, &header_len)) {
  ------------------
  |  Branch (423:7): [True: 0, False: 1.10M]
  ------------------
  424|      0|    return 0;
  425|      0|  }
  426|       |
  427|  1.10M|  if (!CBS_skip(out, header_len)) {
  ------------------
  |  Branch (427:7): [True: 0, False: 1.10M]
  ------------------
  428|      0|    assert(0);
  429|      0|    return 0;
  430|      0|  }
  431|       |
  432|  1.10M|  return 1;
  433|  1.10M|}
CBS_get_any_asn1_element:
  436|  1.52M|                                    size_t *out_header_len) {
  437|  1.52M|  return cbs_get_any_asn1_element(cbs, out, out_tag, out_header_len, NULL, NULL,
  438|  1.52M|                                  /*ber_ok=*/0);
  439|  1.52M|}
CBS_get_any_ber_asn1_element:
  443|  20.0k|                                 int *out_indefinite) {
  444|  20.0k|  int ber_found_temp;
  445|  20.0k|  return cbs_get_any_asn1_element(
  446|  20.0k|      cbs, out, out_tag, out_header_len,
  447|  20.0k|      out_ber_found ? out_ber_found : &ber_found_temp, out_indefinite,
  ------------------
  |  Branch (447:7): [True: 0, False: 20.0k]
  ------------------
  448|  20.0k|      /*ber_ok=*/1);
  449|  20.0k|}
CBS_get_asn1:
  474|   383k|int CBS_get_asn1(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  475|   383k|  return cbs_get_asn1(cbs, out, tag_value, 1 /* skip header */);
  476|   383k|}
CBS_get_asn1_element:
  478|  40.1k|int CBS_get_asn1_element(CBS *cbs, CBS *out, CBS_ASN1_TAG tag_value) {
  479|  40.1k|  return cbs_get_asn1(cbs, out, tag_value, 0 /* include header */);
  480|  40.1k|}
CBS_peek_asn1_tag:
  482|  22.7k|int CBS_peek_asn1_tag(const CBS *cbs, CBS_ASN1_TAG tag_value) {
  483|  22.7k|  CBS copy = *cbs;
  484|  22.7k|  CBS_ASN1_TAG actual_tag;
  485|  22.7k|  return parse_asn1_tag(&copy, &actual_tag) && tag_value == actual_tag;
  ------------------
  |  Branch (485:10): [True: 22.7k, False: 0]
  |  Branch (485:48): [True: 22.7k, False: 0]
  ------------------
  486|  22.7k|}
CBS_get_asn1_uint64:
  488|      2|int CBS_get_asn1_uint64(CBS *cbs, uint64_t *out) {
  489|      2|  CBS bytes;
  490|      2|  if (!CBS_get_asn1(cbs, &bytes, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|      2|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (490:7): [True: 0, False: 2]
  ------------------
  491|      2|      !CBS_is_unsigned_asn1_integer(&bytes)) {
  ------------------
  |  Branch (491:7): [True: 0, False: 2]
  ------------------
  492|      0|    return 0;
  493|      0|  }
  494|       |
  495|      2|  *out = 0;
  496|      2|  const uint8_t *data = CBS_data(&bytes);
  497|      2|  size_t len = CBS_len(&bytes);
  498|      4|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (498:22): [True: 2, False: 2]
  ------------------
  499|      2|    if ((*out >> 56) != 0) {
  ------------------
  |  Branch (499:9): [True: 0, False: 2]
  ------------------
  500|       |      // Too large to represent as a uint64_t.
  501|      0|      return 0;
  502|      0|    }
  503|      2|    *out <<= 8;
  504|      2|    *out |= data[i];
  505|      2|  }
  506|       |
  507|      2|  return 1;
  508|      2|}
CBS_get_optional_asn1:
  547|  22.7k|int CBS_get_optional_asn1(CBS *cbs, CBS *out, int *out_present, CBS_ASN1_TAG tag) {
  548|  22.7k|  int present = 0;
  549|       |
  550|  22.7k|  if (CBS_peek_asn1_tag(cbs, tag)) {
  ------------------
  |  Branch (550:7): [True: 22.7k, False: 0]
  ------------------
  551|  22.7k|    if (!CBS_get_asn1(cbs, out, tag)) {
  ------------------
  |  Branch (551:9): [True: 0, False: 22.7k]
  ------------------
  552|      0|      return 0;
  553|      0|    }
  554|  22.7k|    present = 1;
  555|  22.7k|  }
  556|       |
  557|  22.7k|  if (out_present != NULL) {
  ------------------
  |  Branch (557:7): [True: 0, False: 22.7k]
  ------------------
  558|      0|    *out_present = present;
  559|      0|  }
  560|       |
  561|  22.7k|  return 1;
  562|  22.7k|}
CBS_is_valid_asn1_integer:
  671|  85.6k|int CBS_is_valid_asn1_integer(const CBS *cbs, int *out_is_negative) {
  672|  85.6k|  CBS copy = *cbs;
  673|  85.6k|  uint8_t first_byte, second_byte;
  674|  85.6k|  if (!CBS_get_u8(&copy, &first_byte)) {
  ------------------
  |  Branch (674:7): [True: 0, False: 85.6k]
  ------------------
  675|      0|    return 0;  // INTEGERs may not be empty.
  676|      0|  }
  677|  85.6k|  if (out_is_negative != NULL) {
  ------------------
  |  Branch (677:7): [True: 85.6k, False: 0]
  ------------------
  678|  85.6k|    *out_is_negative = (first_byte & 0x80) != 0;
  679|  85.6k|  }
  680|  85.6k|  if (!CBS_get_u8(&copy, &second_byte)) {
  ------------------
  |  Branch (680:7): [True: 20.0k, False: 65.5k]
  ------------------
  681|  20.0k|    return 1;  // One byte INTEGERs are always minimal.
  682|  20.0k|  }
  683|  65.5k|  if ((first_byte == 0x00 && (second_byte & 0x80) == 0) ||
  ------------------
  |  Branch (683:8): [True: 42.8k, False: 22.7k]
  |  Branch (683:30): [True: 0, False: 42.8k]
  ------------------
  684|  65.5k|      (first_byte == 0xff && (second_byte & 0x80) != 0)) {
  ------------------
  |  Branch (684:8): [True: 0, False: 65.5k]
  |  Branch (684:30): [True: 0, False: 0]
  ------------------
  685|      0|    return 0;  // The value is minimal iff the first 9 bits are not all equal.
  686|      0|  }
  687|  65.5k|  return 1;
  688|  65.5k|}
CBS_is_unsigned_asn1_integer:
  690|      2|int CBS_is_unsigned_asn1_integer(const CBS *cbs) {
  691|      2|  int is_negative;
  692|      2|  return CBS_is_valid_asn1_integer(cbs, &is_negative) && !is_negative;
  ------------------
  |  Branch (692:10): [True: 2, False: 0]
  |  Branch (692:58): [True: 2, False: 0]
  ------------------
  693|      2|}
CBS_is_valid_asn1_oid:
  701|   180k|int CBS_is_valid_asn1_oid(const CBS *cbs) {
  702|   180k|  if (CBS_len(cbs) == 0) {
  ------------------
  |  Branch (702:7): [True: 0, False: 180k]
  ------------------
  703|      0|    return 0;  // OID encodings cannot be empty.
  704|      0|  }
  705|       |
  706|   180k|  CBS copy = *cbs;
  707|   180k|  uint8_t v, prev = 0;
  708|  1.08M|  while (CBS_get_u8(&copy, &v)) {
  ------------------
  |  Branch (708:10): [True: 904k, False: 180k]
  ------------------
  709|       |    // OID encodings are a sequence of minimally-encoded base-128 integers (see
  710|       |    // |parse_base128_integer|). If |prev|'s MSB was clear, it was the last byte
  711|       |    // of an integer (or |v| is the first byte). |v| is then the first byte of
  712|       |    // the next integer. If first byte of an integer is 0x80, it is not
  713|       |    // minimally-encoded.
  714|   904k|    if ((prev & 0x80) == 0 && v == 0x80) {
  ------------------
  |  Branch (714:9): [True: 723k, False: 180k]
  |  Branch (714:31): [True: 0, False: 723k]
  ------------------
  715|      0|      return 0;
  716|      0|    }
  717|   904k|    prev = v;
  718|   904k|  }
  719|       |
  720|       |  // The last byte should must end an integer encoding.
  721|   180k|  return (prev & 0x80) == 0;
  722|   180k|}
CBS_parse_utc_time:
  924|  40.1k|                       int allow_timezone_offset) {
  925|  40.1k|  return CBS_parse_rfc5280_time_internal(cbs, 0, allow_timezone_offset, out_tm);
  926|  40.1k|}
cbs.c:cbs_get:
   34|  9.98M|static int cbs_get(CBS *cbs, const uint8_t **p, size_t n) {
   35|  9.98M|  if (cbs->len < n) {
  ------------------
  |  Branch (35:7): [True: 220k, False: 9.76M]
  ------------------
   36|   220k|    return 0;
   37|   220k|  }
   38|       |
   39|  9.76M|  *p = cbs->data;
   40|  9.76M|  cbs->data += n;
   41|  9.76M|  cbs->len -= n;
   42|  9.76M|  return 1;
   43|  9.98M|}
cbs.c:cbs_get_u:
   93|   528k|static int cbs_get_u(CBS *cbs, uint64_t *out, size_t len) {
   94|   528k|  uint64_t result = 0;
   95|   528k|  const uint8_t *data;
   96|       |
   97|   528k|  if (!cbs_get(cbs, &data, len)) {
  ------------------
  |  Branch (97:7): [True: 5.96k, False: 522k]
  ------------------
   98|  5.96k|    return 0;
   99|  5.96k|  }
  100|  1.51M|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (100:22): [True: 992k, False: 522k]
  ------------------
  101|   992k|    result <<= 8;
  102|   992k|    result |= data[i];
  103|   992k|  }
  104|   522k|  *out = result;
  105|   522k|  return 1;
  106|   528k|}
cbs.c:cbs_get_length_prefixed:
  199|   181k|static int cbs_get_length_prefixed(CBS *cbs, CBS *out, size_t len_len) {
  200|   181k|  uint64_t len;
  201|   181k|  if (!cbs_get_u(cbs, &len, len_len)) {
  ------------------
  |  Branch (201:7): [True: 1.19k, False: 180k]
  ------------------
  202|  1.19k|    return 0;
  203|  1.19k|  }
  204|       |  // If |len_len| <= 3 then we know that |len| will fit into a |size_t|, even on
  205|       |  // 32-bit systems.
  206|   180k|  assert(len_len <= 3);
  207|   180k|  return CBS_get_bytes(cbs, out, len);
  208|   180k|}
cbs.c:cbs_get_any_asn1_element:
  322|  1.54M|                                    int *out_indefinite, int ber_ok) {
  323|  1.54M|  CBS header = *cbs;
  324|  1.54M|  CBS throwaway;
  325|       |
  326|  1.54M|  if (out == NULL) {
  ------------------
  |  Branch (326:7): [True: 0, False: 1.54M]
  ------------------
  327|      0|    out = &throwaway;
  328|      0|  }
  329|  1.54M|  if (ber_ok) {
  ------------------
  |  Branch (329:7): [True: 20.0k, False: 1.52M]
  ------------------
  330|  20.0k|    *out_ber_found = 0;
  331|  20.0k|    *out_indefinite = 0;
  332|  1.52M|  } else {
  333|  1.52M|    assert(out_ber_found == NULL);
  334|  1.52M|    assert(out_indefinite == NULL);
  335|  1.52M|  }
  336|       |
  337|  1.54M|  CBS_ASN1_TAG tag;
  338|  1.54M|  if (!parse_asn1_tag(&header, &tag)) {
  ------------------
  |  Branch (338:7): [True: 0, False: 1.54M]
  ------------------
  339|      0|    return 0;
  340|      0|  }
  341|  1.54M|  if (out_tag != NULL) {
  ------------------
  |  Branch (341:7): [True: 1.54M, False: 0]
  ------------------
  342|  1.54M|    *out_tag = tag;
  343|  1.54M|  }
  344|       |
  345|  1.54M|  uint8_t length_byte;
  346|  1.54M|  if (!CBS_get_u8(&header, &length_byte)) {
  ------------------
  |  Branch (346:7): [True: 0, False: 1.54M]
  ------------------
  347|      0|    return 0;
  348|      0|  }
  349|       |
  350|  1.54M|  size_t header_len = CBS_len(cbs) - CBS_len(&header);
  351|       |
  352|  1.54M|  size_t len;
  353|       |  // The format for the length encoding is specified in ITU-T X.690 section
  354|       |  // 8.1.3.
  355|  1.54M|  if ((length_byte & 0x80) == 0) {
  ------------------
  |  Branch (355:7): [True: 1.29M, False: 256k]
  ------------------
  356|       |    // Short form length.
  357|  1.29M|    len = ((size_t) length_byte) + header_len;
  358|  1.29M|    if (out_header_len != NULL) {
  ------------------
  |  Branch (358:9): [True: 1.29M, False: 0]
  ------------------
  359|  1.29M|      *out_header_len = header_len;
  360|  1.29M|    }
  361|  1.29M|  } else {
  362|       |    // The high bit indicate that this is the long form, while the next 7 bits
  363|       |    // encode the number of subsequent octets used to encode the length (ITU-T
  364|       |    // X.690 clause 8.1.3.5.b).
  365|   256k|    const size_t num_bytes = length_byte & 0x7f;
  366|   256k|    uint64_t len64;
  367|       |
  368|   256k|    if (ber_ok && (tag & CBS_ASN1_CONSTRUCTED) != 0 && num_bytes == 0) {
  ------------------
  |  |  196|  20.0k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  20.0k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (368:9): [True: 20.0k, False: 236k]
  |  Branch (368:19): [True: 0, False: 20.0k]
  |  Branch (368:56): [True: 0, False: 0]
  ------------------
  369|       |      // indefinite length
  370|      0|      if (out_header_len != NULL) {
  ------------------
  |  Branch (370:11): [True: 0, False: 0]
  ------------------
  371|      0|        *out_header_len = header_len;
  372|      0|      }
  373|      0|      *out_ber_found = 1;
  374|      0|      *out_indefinite = 1;
  375|      0|      return CBS_get_bytes(cbs, out, header_len);
  376|      0|    }
  377|       |
  378|       |    // ITU-T X.690 clause 8.1.3.5.c specifies that the value 0xff shall not be
  379|       |    // used as the first byte of the length. If this parser encounters that
  380|       |    // value, num_bytes will be parsed as 127, which will fail this check.
  381|   256k|    if (num_bytes == 0 || num_bytes > 4) {
  ------------------
  |  Branch (381:9): [True: 0, False: 256k]
  |  Branch (381:27): [True: 0, False: 256k]
  ------------------
  382|      0|      return 0;
  383|      0|    }
  384|   256k|    if (!cbs_get_u(&header, &len64, num_bytes)) {
  ------------------
  |  Branch (384:9): [True: 0, False: 256k]
  ------------------
  385|      0|      return 0;
  386|      0|    }
  387|       |    // ITU-T X.690 section 10.1 (DER length forms) requires encoding the
  388|       |    // length with the minimum number of octets. BER could, technically, have
  389|       |    // 125 superfluous zero bytes. We do not attempt to handle that and still
  390|       |    // require that the length fit in a |uint32_t| for BER.
  391|   256k|    if (len64 < 128) {
  ------------------
  |  Branch (391:9): [True: 0, False: 256k]
  ------------------
  392|       |      // Length should have used short-form encoding.
  393|      0|      if (ber_ok) {
  ------------------
  |  Branch (393:11): [True: 0, False: 0]
  ------------------
  394|      0|        *out_ber_found = 1;
  395|      0|      } else {
  396|      0|        return 0;
  397|      0|      }
  398|      0|    }
  399|   256k|    if ((len64 >> ((num_bytes - 1) * 8)) == 0) {
  ------------------
  |  Branch (399:9): [True: 0, False: 256k]
  ------------------
  400|       |      // Length should have been at least one byte shorter.
  401|      0|      if (ber_ok) {
  ------------------
  |  Branch (401:11): [True: 0, False: 0]
  ------------------
  402|      0|        *out_ber_found = 1;
  403|      0|      } else {
  404|      0|        return 0;
  405|      0|      }
  406|      0|    }
  407|   256k|    len = len64;
  408|   256k|    if (len + header_len + num_bytes < len) {
  ------------------
  |  Branch (408:9): [True: 0, False: 256k]
  ------------------
  409|       |      // Overflow.
  410|      0|      return 0;
  411|      0|    }
  412|   256k|    len += header_len + num_bytes;
  413|   256k|    if (out_header_len != NULL) {
  ------------------
  |  Branch (413:9): [True: 256k, False: 0]
  ------------------
  414|   256k|      *out_header_len = header_len + num_bytes;
  415|   256k|    }
  416|   256k|  }
  417|       |
  418|  1.54M|  return CBS_get_bytes(cbs, out, len);
  419|  1.54M|}
cbs.c:cbs_get_asn1:
  452|   424k|                        int skip_header) {
  453|   424k|  size_t header_len;
  454|   424k|  CBS_ASN1_TAG tag;
  455|   424k|  CBS throwaway;
  456|       |
  457|   424k|  if (out == NULL) {
  ------------------
  |  Branch (457:7): [True: 136k, False: 287k]
  ------------------
  458|   136k|    out = &throwaway;
  459|   136k|  }
  460|       |
  461|   424k|  if (!CBS_get_any_asn1_element(cbs, out, &tag, &header_len) ||
  ------------------
  |  Branch (461:7): [True: 0, False: 424k]
  ------------------
  462|   424k|      tag != tag_value) {
  ------------------
  |  Branch (462:7): [True: 0, False: 424k]
  ------------------
  463|      0|    return 0;
  464|      0|  }
  465|       |
  466|   424k|  if (skip_header && !CBS_skip(out, header_len)) {
  ------------------
  |  Branch (466:7): [True: 383k, False: 40.1k]
  |  Branch (466:22): [True: 0, False: 383k]
  ------------------
  467|      0|    assert(0);
  468|      0|    return 0;
  469|      0|  }
  470|       |
  471|   424k|  return 1;
  472|   424k|}
cbs.c:parse_asn1_tag:
  281|  1.57M|static int parse_asn1_tag(CBS *cbs, CBS_ASN1_TAG *out) {
  282|  1.57M|  uint8_t tag_byte;
  283|  1.57M|  if (!CBS_get_u8(cbs, &tag_byte)) {
  ------------------
  |  Branch (283:7): [True: 0, False: 1.57M]
  ------------------
  284|      0|    return 0;
  285|      0|  }
  286|       |
  287|       |  // ITU-T X.690 section 8.1.2.3 specifies the format for identifiers with a tag
  288|       |  // number no greater than 30.
  289|       |  //
  290|       |  // If the number portion is 31 (0x1f, the largest value that fits in the
  291|       |  // allotted bits), then the tag is more than one byte long and the
  292|       |  // continuation bytes contain the tag number.
  293|  1.57M|  CBS_ASN1_TAG tag = ((CBS_ASN1_TAG)tag_byte & 0xe0) << CBS_ASN1_TAG_SHIFT;
  ------------------
  |  |  193|  1.57M|#define CBS_ASN1_TAG_SHIFT 24
  ------------------
  294|  1.57M|  CBS_ASN1_TAG tag_number = tag_byte & 0x1f;
  295|  1.57M|  if (tag_number == 0x1f) {
  ------------------
  |  Branch (295:7): [True: 0, False: 1.57M]
  ------------------
  296|      0|    uint64_t v;
  297|      0|    if (!parse_base128_integer(cbs, &v) ||
  ------------------
  |  Branch (297:9): [True: 0, False: 0]
  ------------------
  298|       |        // Check the tag number is within our supported bounds.
  299|      0|        v > CBS_ASN1_TAG_NUMBER_MASK ||
  ------------------
  |  |  210|      0|#define CBS_ASN1_TAG_NUMBER_MASK ((1u << (5 + CBS_ASN1_TAG_SHIFT)) - 1)
  |  |  ------------------
  |  |  |  |  193|      0|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (299:9): [True: 0, False: 0]
  ------------------
  300|       |        // Small tag numbers should have used low tag number form, even in BER.
  301|      0|        v < 0x1f) {
  ------------------
  |  Branch (301:9): [True: 0, False: 0]
  ------------------
  302|      0|      return 0;
  303|      0|    }
  304|      0|    tag_number = (CBS_ASN1_TAG)v;
  305|      0|  }
  306|       |
  307|  1.57M|  tag |= tag_number;
  308|       |
  309|       |  // Tag [UNIVERSAL 0] is reserved for use by the encoding. Reject it here to
  310|       |  // avoid some ambiguity around ANY values and BER indefinite-length EOCs. See
  311|       |  // https://crbug.com/boringssl/455.
  312|  1.57M|  if ((tag & ~CBS_ASN1_CONSTRUCTED) == 0) {
  ------------------
  |  |  196|  1.57M|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  1.57M|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  |  Branch (312:7): [True: 0, False: 1.57M]
  ------------------
  313|      0|    return 0;
  314|      0|  }
  315|       |
  316|  1.57M|  *out = tag;
  317|  1.57M|  return 1;
  318|  1.57M|}
cbs.c:CBS_parse_rfc5280_time_internal:
  819|  40.1k|                                           struct tm *out_tm) {
  820|  40.1k|  int year, month, day, hour, min, sec, tmp;
  821|  40.1k|  CBS copy = *cbs;
  822|  40.1k|  uint8_t tz;
  823|       |
  824|  40.1k|  if (is_gentime) {
  ------------------
  |  Branch (824:7): [True: 0, False: 40.1k]
  ------------------
  825|      0|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (825:9): [True: 0, False: 0]
  ------------------
  826|      0|      return 0;
  827|      0|    }
  828|      0|    year = tmp * 100;
  829|      0|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (829:9): [True: 0, False: 0]
  ------------------
  830|      0|      return 0;
  831|      0|    }
  832|      0|      year += tmp;
  833|  40.1k|  } else {
  834|  40.1k|    year = 1900;
  835|  40.1k|    if (!cbs_get_two_digits(&copy, &tmp)) {
  ------------------
  |  Branch (835:9): [True: 0, False: 40.1k]
  ------------------
  836|      0|      return 0;
  837|      0|    }
  838|  40.1k|    year += tmp;
  839|  40.1k|    if (year < 1950) {
  ------------------
  |  Branch (839:9): [True: 40.1k, False: 0]
  ------------------
  840|  40.1k|      year += 100;
  841|  40.1k|    }
  842|  40.1k|    if (year >= 2050) {
  ------------------
  |  Branch (842:9): [True: 0, False: 40.1k]
  ------------------
  843|      0|      return 0;  // A Generalized time must be used.
  844|      0|    }
  845|  40.1k|  }
  846|  40.1k|  if (!cbs_get_two_digits(&copy, &month) || month < 1 ||
  ------------------
  |  Branch (846:7): [True: 0, False: 40.1k]
  |  Branch (846:45): [True: 0, False: 40.1k]
  ------------------
  847|  40.1k|      month > 12 ||  // Reject invalid months.
  ------------------
  |  Branch (847:7): [True: 0, False: 40.1k]
  ------------------
  848|  40.1k|      !cbs_get_two_digits(&copy, &day) ||
  ------------------
  |  Branch (848:7): [True: 0, False: 40.1k]
  ------------------
  849|  40.1k|      !is_valid_day(year, month, day) ||  // Reject invalid days.
  ------------------
  |  Branch (849:7): [True: 0, False: 40.1k]
  ------------------
  850|  40.1k|      !cbs_get_two_digits(&copy, &hour) ||
  ------------------
  |  Branch (850:7): [True: 0, False: 40.1k]
  ------------------
  851|  40.1k|      hour > 23 ||  // Reject invalid hours.
  ------------------
  |  Branch (851:7): [True: 0, False: 40.1k]
  ------------------
  852|  40.1k|      !cbs_get_two_digits(&copy, &min) ||
  ------------------
  |  Branch (852:7): [True: 0, False: 40.1k]
  ------------------
  853|  40.1k|      min > 59 ||  // Reject invalid minutes.
  ------------------
  |  Branch (853:7): [True: 0, False: 40.1k]
  ------------------
  854|  40.1k|      !cbs_get_two_digits(&copy, &sec) || sec > 59 || !CBS_get_u8(&copy, &tz)) {
  ------------------
  |  Branch (854:7): [True: 0, False: 40.1k]
  |  Branch (854:43): [True: 0, False: 40.1k]
  |  Branch (854:55): [True: 0, False: 40.1k]
  ------------------
  855|      0|    return 0;
  856|      0|  }
  857|       |
  858|  40.1k|  int offset_sign = 0;
  859|  40.1k|  switch (tz) {
  860|  40.1k|    case 'Z':
  ------------------
  |  Branch (860:5): [True: 40.1k, False: 0]
  ------------------
  861|  40.1k|      break;  // We correctly have 'Z' on the end as per spec.
  862|      0|    case '+':
  ------------------
  |  Branch (862:5): [True: 0, False: 40.1k]
  ------------------
  863|      0|      offset_sign = 1;
  864|      0|      break;  // Should not be allowed per RFC 5280.
  865|      0|    case '-':
  ------------------
  |  Branch (865:5): [True: 0, False: 40.1k]
  ------------------
  866|      0|      offset_sign = -1;
  867|      0|      break;  // Should not be allowed per RFC 5280.
  868|      0|    default:
  ------------------
  |  Branch (868:5): [True: 0, False: 40.1k]
  ------------------
  869|      0|      return 0;  // Reject anything else after the time.
  870|  40.1k|  }
  871|       |
  872|       |  // If allow_timezone_offset is non-zero, allow for a four digit timezone
  873|       |  // offset to be specified even though this is not allowed by RFC 5280. We are
  874|       |  // permissive of this for UTCTimes due to the unfortunate existence of
  875|       |  // artisinally rolled long lived certificates that were baked into places that
  876|       |  // are now difficult to change. These certificates were generated with the
  877|       |  // 'openssl' command that permissively allowed the creation of certificates
  878|       |  // with notBefore and notAfter times specified as strings for direct
  879|       |  // certificate inclusion on the command line. For context see cl/237068815.
  880|       |  //
  881|       |  // TODO(bbe): This has been expunged from public web-pki as the ecosystem has
  882|       |  // managed to encourage CA compliance with standards. We should find a way to
  883|       |  // get rid of this or make it off by default.
  884|  40.1k|  int offset_seconds = 0;
  885|  40.1k|  if (offset_sign != 0) {
  ------------------
  |  Branch (885:7): [True: 0, False: 40.1k]
  ------------------
  886|      0|    if (!allow_timezone_offset) {
  ------------------
  |  Branch (886:9): [True: 0, False: 0]
  ------------------
  887|      0|      return 0;
  888|      0|    }
  889|      0|    int offset_hours, offset_minutes;
  890|      0|    if (!cbs_get_two_digits(&copy, &offset_hours) ||
  ------------------
  |  Branch (890:9): [True: 0, False: 0]
  ------------------
  891|      0|        offset_hours > 23 ||  // Reject invalid hours.
  ------------------
  |  Branch (891:9): [True: 0, False: 0]
  ------------------
  892|      0|        !cbs_get_two_digits(&copy, &offset_minutes) ||
  ------------------
  |  Branch (892:9): [True: 0, False: 0]
  ------------------
  893|      0|        offset_minutes > 59) {  // Reject invalid minutes.
  ------------------
  |  Branch (893:9): [True: 0, False: 0]
  ------------------
  894|      0|      return 0;
  895|      0|    }
  896|      0|    offset_seconds = offset_sign * (offset_hours * 3600 + offset_minutes * 60);
  897|      0|  }
  898|       |
  899|  40.1k|  if (CBS_len(&copy) != 0) {
  ------------------
  |  Branch (899:7): [True: 0, False: 40.1k]
  ------------------
  900|      0|    return 0;  // Reject invalid lengths.
  901|      0|  }
  902|       |
  903|  40.1k|  if (out_tm != NULL) {
  ------------------
  |  Branch (903:7): [True: 0, False: 40.1k]
  ------------------
  904|       |    // Fill in the tm fields corresponding to what we validated.
  905|      0|    out_tm->tm_year = year - 1900;
  906|      0|    out_tm->tm_mon = month - 1;
  907|      0|    out_tm->tm_mday = day;
  908|      0|    out_tm->tm_hour = hour;
  909|      0|    out_tm->tm_min = min;
  910|      0|    out_tm->tm_sec = sec;
  911|      0|    if (offset_seconds && !OPENSSL_gmtime_adj(out_tm, 0, offset_seconds)) {
  ------------------
  |  Branch (911:9): [True: 0, False: 0]
  |  Branch (911:27): [True: 0, False: 0]
  ------------------
  912|      0|      return 0;
  913|      0|    }
  914|      0|  }
  915|  40.1k|  return 1;
  916|  40.1k|}
cbs.c:cbs_get_two_digits:
  770|   241k|static int cbs_get_two_digits(CBS *cbs, int *out) {
  771|   241k|  uint8_t first_digit, second_digit;
  772|   241k|  if (!CBS_get_u8(cbs, &first_digit)) {
  ------------------
  |  Branch (772:7): [True: 0, False: 241k]
  ------------------
  773|      0|    return 0;
  774|      0|  }
  775|   241k|  if (!OPENSSL_isdigit(first_digit)) {
  ------------------
  |  Branch (775:7): [True: 0, False: 241k]
  ------------------
  776|      0|    return 0;
  777|      0|  }
  778|   241k|  if (!CBS_get_u8(cbs, &second_digit)) {
  ------------------
  |  Branch (778:7): [True: 0, False: 241k]
  ------------------
  779|      0|    return 0;
  780|      0|  }
  781|   241k|  if (!OPENSSL_isdigit(second_digit)) {
  ------------------
  |  Branch (781:7): [True: 0, False: 241k]
  ------------------
  782|      0|    return 0;
  783|      0|  }
  784|   241k|  *out = (first_digit - '0') * 10 + (second_digit - '0');
  785|   241k|  return 1;
  786|   241k|}
cbs.c:is_valid_day:
  788|  40.1k|static int is_valid_day(int year, int month, int day) {
  789|  40.1k|  if (day < 1) {
  ------------------
  |  Branch (789:7): [True: 0, False: 40.1k]
  ------------------
  790|      0|    return 0;
  791|      0|  }
  792|  40.1k|  switch (month) {
  793|      0|    case 1:
  ------------------
  |  Branch (793:5): [True: 0, False: 40.1k]
  ------------------
  794|      0|    case 3:
  ------------------
  |  Branch (794:5): [True: 0, False: 40.1k]
  ------------------
  795|      0|    case 5:
  ------------------
  |  Branch (795:5): [True: 0, False: 40.1k]
  ------------------
  796|      0|    case 7:
  ------------------
  |  Branch (796:5): [True: 0, False: 40.1k]
  ------------------
  797|      0|    case 8:
  ------------------
  |  Branch (797:5): [True: 0, False: 40.1k]
  ------------------
  798|      0|    case 10:
  ------------------
  |  Branch (798:5): [True: 0, False: 40.1k]
  ------------------
  799|      0|    case 12:
  ------------------
  |  Branch (799:5): [True: 0, False: 40.1k]
  ------------------
  800|      0|      return day <= 31;
  801|      0|    case 4:
  ------------------
  |  Branch (801:5): [True: 0, False: 40.1k]
  ------------------
  802|      0|    case 6:
  ------------------
  |  Branch (802:5): [True: 0, False: 40.1k]
  ------------------
  803|      0|    case 9:
  ------------------
  |  Branch (803:5): [True: 0, False: 40.1k]
  ------------------
  804|  40.1k|    case 11:
  ------------------
  |  Branch (804:5): [True: 40.1k, False: 0]
  ------------------
  805|  40.1k|      return day <= 30;
  806|      0|    case 2:
  ------------------
  |  Branch (806:5): [True: 0, False: 40.1k]
  ------------------
  807|      0|      if ((year % 4 == 0 && year % 100 != 0) || year % 400 == 0) {
  ------------------
  |  Branch (807:12): [True: 0, False: 0]
  |  Branch (807:29): [True: 0, False: 0]
  |  Branch (807:49): [True: 0, False: 0]
  ------------------
  808|      0|        return day <= 29;
  809|      0|      } else {
  810|      0|        return day <= 28;
  811|      0|      }
  812|      0|    default:
  ------------------
  |  Branch (812:5): [True: 0, False: 40.1k]
  ------------------
  813|      0|      return 0;
  814|  40.1k|  }
  815|  40.1k|}

cbs_get_latin1:
   83|   562k|int cbs_get_latin1(CBS *cbs, uint32_t *out) {
   84|   562k|  uint8_t c;
   85|   562k|  if (!CBS_get_u8(cbs, &c)) {
  ------------------
  |  Branch (85:7): [True: 0, False: 562k]
  ------------------
   86|      0|    return 0;
   87|      0|  }
   88|   562k|  *out = c;
   89|   562k|  return 1;
   90|   562k|}
cbb_get_utf8_len:
  107|   281k|size_t cbb_get_utf8_len(uint32_t u) {
  108|   281k|  if (u <= 0x7f) {
  ------------------
  |  Branch (108:7): [True: 281k, False: 0]
  ------------------
  109|   281k|    return 1;
  110|   281k|  }
  111|      0|  if (u <= 0x7ff) {
  ------------------
  |  Branch (111:7): [True: 0, False: 0]
  ------------------
  112|      0|    return 2;
  113|      0|  }
  114|      0|  if (u <= 0xffff) {
  ------------------
  |  Branch (114:7): [True: 0, False: 0]
  ------------------
  115|      0|    return 3;
  116|      0|  }
  117|      0|  return 4;
  118|      0|}
cbb_add_utf8:
  120|   281k|int cbb_add_utf8(CBB *cbb, uint32_t u) {
  121|   281k|  if (!is_valid_code_point(u)) {
  ------------------
  |  Branch (121:7): [True: 0, False: 281k]
  ------------------
  122|      0|    return 0;
  123|      0|  }
  124|   281k|  if (u <= 0x7f) {
  ------------------
  |  Branch (124:7): [True: 281k, False: 0]
  ------------------
  125|   281k|    return CBB_add_u8(cbb, (uint8_t)u);
  126|   281k|  }
  127|      0|  if (u <= 0x7ff) {
  ------------------
  |  Branch (127:7): [True: 0, False: 0]
  ------------------
  128|      0|    return CBB_add_u8(cbb, TOP_BITS(2) | (u >> 6)) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (128:12): [True: 0, False: 0]
  ------------------
  129|      0|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (129:12): [True: 0, False: 0]
  ------------------
  130|      0|  }
  131|      0|  if (u <= 0xffff) {
  ------------------
  |  Branch (131:7): [True: 0, False: 0]
  ------------------
  132|      0|    return CBB_add_u8(cbb, TOP_BITS(3) | (u >> 12)) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (132:12): [True: 0, False: 0]
  ------------------
  133|      0|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (133:12): [True: 0, False: 0]
  ------------------
  134|      0|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (134:12): [True: 0, False: 0]
  ------------------
  135|      0|  }
  136|      0|  if (u <= 0x10ffff) {
  ------------------
  |  Branch (136:7): [True: 0, False: 0]
  ------------------
  137|      0|    return CBB_add_u8(cbb, TOP_BITS(4) | (u >> 18)) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
  |  Branch (137:12): [True: 0, False: 0]
  ------------------
  138|      0|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 12) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 12) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (138:12): [True: 0, False: 0]
  ------------------
  139|      0|           CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | ((u >> 6) & BOTTOM_BITS(6))) &&
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (139:12): [True: 0, False: 0]
  ------------------
  140|      0|           CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   39|      0|#define TOP_BITS(n) ((uint8_t)~BOTTOM_BITS(8 - (n)))
  |  |  ------------------
  |  |  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  |  |  ------------------
  ------------------
                         CBB_add_u8(cbb, TOP_BITS(1) | (u & BOTTOM_BITS(6)));
  ------------------
  |  |   36|      0|#define BOTTOM_BITS(n) (uint8_t)((1u << (n)) - 1)
  ------------------
  |  Branch (140:12): [True: 0, False: 0]
  ------------------
  141|      0|  }
  142|      0|  return 0;
  143|      0|}
unicode.c:is_valid_code_point:
   20|   281k|static int is_valid_code_point(uint32_t v) {
   21|       |  // References in the following are to Unicode 9.0.0.
   22|   281k|  if (// The Unicode space runs from zero to 0x10ffff (3.4 D9).
   23|   281k|      v > 0x10ffff ||
  ------------------
  |  Branch (23:7): [True: 0, False: 281k]
  ------------------
   24|       |      // Values 0x...fffe, 0x...ffff, and 0xfdd0-0xfdef are permanently reserved
   25|       |      // (3.4 D14)
   26|   281k|      (v & 0xfffe) == 0xfffe ||
  ------------------
  |  Branch (26:7): [True: 0, False: 281k]
  ------------------
   27|   281k|      (v >= 0xfdd0 && v <= 0xfdef) ||
  ------------------
  |  Branch (27:8): [True: 0, False: 281k]
  |  Branch (27:23): [True: 0, False: 0]
  ------------------
   28|       |      // Surrogate code points are invalid (3.2 C1).
   29|   281k|      (v >= 0xd800 && v <= 0xdfff)) {
  ------------------
  |  Branch (29:8): [True: 0, False: 281k]
  |  Branch (29:23): [True: 0, False: 0]
  ------------------
   30|      0|    return 0;
   31|      0|  }
   32|   281k|  return 1;
   33|   281k|}

CRYPTO_chacha_20:
   67|      2|                      uint32_t counter) {
   68|      2|  assert(!buffers_alias(out, in_len, in, in_len) || in == out);
   69|       |
   70|      2|  uint32_t counter_nonce[4];
   71|      2|  counter_nonce[0] = counter;
   72|      2|  counter_nonce[1] = CRYPTO_load_u32_le(nonce + 0);
   73|      2|  counter_nonce[2] = CRYPTO_load_u32_le(nonce + 4);
   74|      2|  counter_nonce[3] = CRYPTO_load_u32_le(nonce + 8);
   75|       |
   76|      2|  const uint32_t *key_ptr = (const uint32_t *)key;
   77|       |#if !defined(OPENSSL_X86) && !defined(OPENSSL_X86_64)
   78|       |  // The assembly expects the key to be four-byte aligned.
   79|       |  uint32_t key_u32[8];
   80|       |  if ((((uintptr_t)key) & 3) != 0) {
   81|       |    key_u32[0] = CRYPTO_load_u32_le(key + 0);
   82|       |    key_u32[1] = CRYPTO_load_u32_le(key + 4);
   83|       |    key_u32[2] = CRYPTO_load_u32_le(key + 8);
   84|       |    key_u32[3] = CRYPTO_load_u32_le(key + 12);
   85|       |    key_u32[4] = CRYPTO_load_u32_le(key + 16);
   86|       |    key_u32[5] = CRYPTO_load_u32_le(key + 20);
   87|       |    key_u32[6] = CRYPTO_load_u32_le(key + 24);
   88|       |    key_u32[7] = CRYPTO_load_u32_le(key + 28);
   89|       |
   90|       |    key_ptr = key_u32;
   91|       |  }
   92|       |#endif
   93|       |
   94|      4|  while (in_len > 0) {
  ------------------
  |  Branch (94:10): [True: 2, False: 2]
  ------------------
   95|       |    // The assembly functions do not have defined overflow behavior. While
   96|       |    // overflow is almost always a bug in the caller, we prefer our functions to
   97|       |    // behave the same across platforms, so divide into multiple calls to avoid
   98|       |    // this case.
   99|      2|    uint64_t todo = 64 * ((UINT64_C(1) << 32) - counter_nonce[0]);
  100|      2|    if (todo > in_len) {
  ------------------
  |  Branch (100:9): [True: 2, False: 0]
  ------------------
  101|      2|      todo = in_len;
  102|      2|    }
  103|       |
  104|      2|    ChaCha20_ctr32(out, in, (size_t)todo, key_ptr, counter_nonce);
  105|      2|    in += todo;
  106|      2|    out += todo;
  107|      2|    in_len -= todo;
  108|       |
  109|       |    // We're either done and will next break out of the loop, or we stopped at
  110|       |    // the wraparound point and the counter should continue at zero.
  111|      2|    counter_nonce[0] = 0;
  112|      2|  }
  113|      2|}

OPENSSL_cpuid_setup:
  153|      2|void OPENSSL_cpuid_setup(void) {
  154|       |  // Determine the vendor and maximum input value.
  155|      2|  uint32_t eax, ebx, ecx, edx;
  156|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 0);
  157|       |
  158|      2|  uint32_t num_ids = eax;
  159|       |
  160|      2|  int is_intel = ebx == 0x756e6547 /* Genu */ &&
  ------------------
  |  Branch (160:18): [True: 2, False: 0]
  ------------------
  161|      2|                 edx == 0x49656e69 /* ineI */ &&
  ------------------
  |  Branch (161:18): [True: 2, False: 0]
  ------------------
  162|      2|                 ecx == 0x6c65746e /* ntel */;
  ------------------
  |  Branch (162:18): [True: 2, False: 0]
  ------------------
  163|      2|  int is_amd = ebx == 0x68747541 /* Auth */ &&
  ------------------
  |  Branch (163:16): [True: 0, False: 2]
  ------------------
  164|      2|               edx == 0x69746e65 /* enti */ &&
  ------------------
  |  Branch (164:16): [True: 0, False: 0]
  ------------------
  165|      2|               ecx == 0x444d4163 /* cAMD */;
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|       |
  167|      2|  uint32_t extended_features[2] = {0};
  168|      2|  if (num_ids >= 7) {
  ------------------
  |  Branch (168:7): [True: 2, False: 0]
  ------------------
  169|      2|    OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 7);
  170|      2|    extended_features[0] = ebx;
  171|      2|    extended_features[1] = ecx;
  172|      2|  }
  173|       |
  174|      2|  OPENSSL_cpuid(&eax, &ebx, &ecx, &edx, 1);
  175|       |
  176|      2|  if (is_amd) {
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|       |    // See https://www.amd.com/system/files/TechDocs/25481.pdf, page 10.
  178|      0|    const uint32_t base_family = (eax >> 8) & 15;
  179|      0|    const uint32_t base_model = (eax >> 4) & 15;
  180|       |
  181|      0|    uint32_t family = base_family;
  182|      0|    uint32_t model = base_model;
  183|      0|    if (base_family == 0xf) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      const uint32_t ext_family = (eax >> 20) & 255;
  185|      0|      family += ext_family;
  186|      0|      const uint32_t ext_model = (eax >> 16) & 15;
  187|      0|      model |= ext_model << 4;
  188|      0|    }
  189|       |
  190|      0|    if (family < 0x17 || (family == 0x17 && 0x70 <= model && model <= 0x7f)) {
  ------------------
  |  Branch (190:9): [True: 0, False: 0]
  |  Branch (190:27): [True: 0, False: 0]
  |  Branch (190:45): [True: 0, False: 0]
  |  Branch (190:62): [True: 0, False: 0]
  ------------------
  191|       |      // Disable RDRAND on AMD families before 0x17 (Zen) due to reported
  192|       |      // failures after suspend.
  193|       |      // https://bugzilla.redhat.com/show_bug.cgi?id=1150286
  194|       |      // Also disable for family 0x17, models 0x70–0x7f, due to possible RDRAND
  195|       |      // failures there too.
  196|      0|      ecx &= ~(1u << 30);
  197|      0|    }
  198|      0|  }
  199|       |
  200|       |  // Force the hyper-threading bit so that the more conservative path is always
  201|       |  // chosen.
  202|      2|  edx |= 1u << 28;
  203|       |
  204|       |  // Reserved bit #20 was historically repurposed to control the in-memory
  205|       |  // representation of RC4 state. Always set it to zero.
  206|      2|  edx &= ~(1u << 20);
  207|       |
  208|       |  // Reserved bit #30 is repurposed to signal an Intel CPU.
  209|      2|  if (is_intel) {
  ------------------
  |  Branch (209:7): [True: 2, False: 0]
  ------------------
  210|      2|    edx |= (1u << 30);
  211|       |
  212|       |    // Clear the XSAVE bit on Knights Landing to mimic Silvermont. This enables
  213|       |    // some Silvermont-specific codepaths which perform better. See OpenSSL
  214|       |    // commit 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  215|      2|    if ((eax & 0x0fff0ff0) == 0x00050670 /* Knights Landing */ ||
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      2|        (eax & 0x0fff0ff0) == 0x00080650 /* Knights Mill (per SDE) */) {
  ------------------
  |  Branch (216:9): [True: 0, False: 2]
  ------------------
  217|      0|      ecx &= ~(1u << 26);
  218|      0|    }
  219|      2|  } else {
  220|      0|    edx &= ~(1u << 30);
  221|      0|  }
  222|       |
  223|       |  // The SDBG bit is repurposed to denote AMD XOP support. Don't ever use AMD
  224|       |  // XOP code paths.
  225|      2|  ecx &= ~(1u << 11);
  226|       |
  227|      2|  uint64_t xcr0 = 0;
  228|      2|  if (ecx & (1u << 27)) {
  ------------------
  |  Branch (228:7): [True: 2, False: 0]
  ------------------
  229|       |    // XCR0 may only be queried if the OSXSAVE bit is set.
  230|      2|    xcr0 = OPENSSL_xgetbv(0);
  231|      2|  }
  232|       |  // See Intel manual, volume 1, section 14.3.
  233|      2|  if ((xcr0 & 6) != 6) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2]
  ------------------
  234|       |    // YMM registers cannot be used.
  235|      0|    ecx &= ~(1u << 28);  // AVX
  236|      0|    ecx &= ~(1u << 12);  // FMA
  237|      0|    ecx &= ~(1u << 11);  // AMD XOP
  238|       |    // Clear AVX2 and AVX512* bits.
  239|       |    //
  240|       |    // TODO(davidben): Should bits 17 and 26-28 also be cleared? Upstream
  241|       |    // doesn't clear those.
  242|      0|    extended_features[0] &=
  243|      0|        ~((1u << 5) | (1u << 16) | (1u << 21) | (1u << 30) | (1u << 31));
  244|      0|  }
  245|       |  // See Intel manual, volume 1, section 15.2.
  246|      2|  if ((xcr0 & 0xe6) != 0xe6) {
  ------------------
  |  Branch (246:7): [True: 2, False: 0]
  ------------------
  247|       |    // Clear AVX512F. Note we don't touch other AVX512 extensions because they
  248|       |    // can be used with YMM.
  249|      2|    extended_features[0] &= ~(1u << 16);
  250|      2|  }
  251|       |
  252|       |  // Disable ADX instructions on Knights Landing. See OpenSSL commit
  253|       |  // 64d92d74985ebb3d0be58a9718f9e080a14a8e7f.
  254|      2|  if ((ecx & (1u << 26)) == 0) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    extended_features[0] &= ~(1u << 19);
  256|      0|  }
  257|       |
  258|      2|  OPENSSL_ia32cap_P[0] = edx;
  259|      2|  OPENSSL_ia32cap_P[1] = ecx;
  260|      2|  OPENSSL_ia32cap_P[2] = extended_features[0];
  261|      2|  OPENSSL_ia32cap_P[3] = extended_features[1];
  262|       |
  263|      2|  const char *env1, *env2;
  264|      2|  env1 = getenv("OPENSSL_ia32cap");
  265|      2|  if (env1 == NULL) {
  ------------------
  |  Branch (265:7): [True: 2, False: 0]
  ------------------
  266|      2|    return;
  267|      2|  }
  268|       |
  269|       |  // OPENSSL_ia32cap can contain zero, one or two values, separated with a ':'.
  270|       |  // Each value is a 64-bit, unsigned value which may start with "0x" to
  271|       |  // indicate a hex value. Prior to the 64-bit value, a '~' or '|' may be given.
  272|       |  //
  273|       |  // If the '~' prefix is present:
  274|       |  //   the value is inverted and ANDed with the probed CPUID result
  275|       |  // If the '|' prefix is present:
  276|       |  //   the value is ORed with the probed CPUID result
  277|       |  // Otherwise:
  278|       |  //   the value is taken as the result of the CPUID
  279|       |  //
  280|       |  // The first value determines OPENSSL_ia32cap_P[0] and [1]. The second [2]
  281|       |  // and [3].
  282|       |
  283|      0|  handle_cpu_env(&OPENSSL_ia32cap_P[0], env1);
  284|      0|  env2 = strchr(env1, ':');
  285|      0|  if (env2 != NULL) {
  ------------------
  |  Branch (285:7): [True: 0, False: 0]
  ------------------
  286|      0|    handle_cpu_env(&OPENSSL_ia32cap_P[2], env2 + 1);
  287|      0|  }
  288|      0|}
cpu_intel.c:OPENSSL_cpuid:
   80|      6|                          uint32_t *out_ecx, uint32_t *out_edx, uint32_t leaf) {
   81|       |#if defined(_MSC_VER)
   82|       |  int tmp[4];
   83|       |  __cpuid(tmp, (int)leaf);
   84|       |  *out_eax = (uint32_t)tmp[0];
   85|       |  *out_ebx = (uint32_t)tmp[1];
   86|       |  *out_ecx = (uint32_t)tmp[2];
   87|       |  *out_edx = (uint32_t)tmp[3];
   88|       |#elif defined(__pic__) && defined(OPENSSL_32_BIT)
   89|       |  // Inline assembly may not clobber the PIC register. For 32-bit, this is EBX.
   90|       |  // See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=47602.
   91|       |  __asm__ volatile (
   92|       |    "xor %%ecx, %%ecx\n"
   93|       |    "mov %%ebx, %%edi\n"
   94|       |    "cpuid\n"
   95|       |    "xchg %%edi, %%ebx\n"
   96|       |    : "=a"(*out_eax), "=D"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
   97|       |    : "a"(leaf)
   98|       |  );
   99|       |#else
  100|      6|  __asm__ volatile (
  101|      6|    "xor %%ecx, %%ecx\n"
  102|      6|    "cpuid\n"
  103|      6|    : "=a"(*out_eax), "=b"(*out_ebx), "=c"(*out_ecx), "=d"(*out_edx)
  104|      6|    : "a"(leaf)
  105|      6|  );
  106|      6|#endif
  107|      6|}
cpu_intel.c:OPENSSL_xgetbv:
  111|      2|static uint64_t OPENSSL_xgetbv(uint32_t xcr) {
  112|       |#if defined(_MSC_VER)
  113|       |  return (uint64_t)_xgetbv(xcr);
  114|       |#else
  115|      2|  uint32_t eax, edx;
  116|      2|  __asm__ volatile ("xgetbv" : "=a"(eax), "=d"(edx) : "c"(xcr));
  117|      2|  return (((uint64_t)edx) << 32) | eax;
  118|      2|#endif
  119|      2|}

crypto.c:do_library_init:
  151|      2|static void OPENSSL_CDECL do_library_init(void) {
  152|       | // WARNING: this function may only configure the capability variables. See the
  153|       | // note above about the linker bug.
  154|      2|#if defined(NEED_CPUID)
  155|      2|  OPENSSL_cpuid_setup();
  156|      2|#endif
  157|      2|}

x25519_ge_scalarmult_base:
  799|  11.7k|void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t a[32]) {
  800|  11.7k|#if defined(BORINGSSL_FE25519_ADX)
  801|  11.7k|  if (CRYPTO_is_BMI1_capable() && CRYPTO_is_BMI2_capable() &&
  ------------------
  |  Branch (801:7): [True: 11.7k, False: 0]
  |  Branch (801:35): [True: 11.7k, False: 0]
  ------------------
  802|  11.7k|      CRYPTO_is_ADX_capable()) {
  ------------------
  |  Branch (802:7): [True: 11.7k, False: 0]
  ------------------
  803|  11.7k|    uint8_t t[4][32];
  804|  11.7k|    x25519_ge_scalarmult_base_adx(t, a);
  805|  11.7k|    fiat_25519_from_bytes(h->X.v, t[0]);
  806|  11.7k|    fiat_25519_from_bytes(h->Y.v, t[1]);
  807|  11.7k|    fiat_25519_from_bytes(h->Z.v, t[2]);
  808|  11.7k|    fiat_25519_from_bytes(h->T.v, t[3]);
  809|  11.7k|    return;
  810|  11.7k|  }
  811|      0|#endif
  812|      0|  signed char e[64];
  813|      0|  signed char carry;
  814|      0|  ge_p1p1 r;
  815|      0|  ge_p2 s;
  816|      0|  ge_precomp t;
  817|      0|  int i;
  818|       |
  819|      0|  for (i = 0; i < 32; ++i) {
  ------------------
  |  Branch (819:15): [True: 0, False: 0]
  ------------------
  820|      0|    e[2 * i + 0] = (a[i] >> 0) & 15;
  821|      0|    e[2 * i + 1] = (a[i] >> 4) & 15;
  822|      0|  }
  823|       |  // each e[i] is between 0 and 15
  824|       |  // e[63] is between 0 and 7
  825|       |
  826|      0|  carry = 0;
  827|      0|  for (i = 0; i < 63; ++i) {
  ------------------
  |  Branch (827:15): [True: 0, False: 0]
  ------------------
  828|      0|    e[i] += carry;
  829|      0|    carry = e[i] + 8;
  830|      0|    carry >>= 4;
  831|      0|    e[i] -= carry << 4;
  832|      0|  }
  833|      0|  e[63] += carry;
  834|       |  // each e[i] is between -8 and 8
  835|       |
  836|      0|  ge_p3_0(h);
  837|      0|  for (i = 1; i < 64; i += 2) {
  ------------------
  |  Branch (837:15): [True: 0, False: 0]
  ------------------
  838|      0|    table_select(&t, i / 2, e[i]);
  839|      0|    ge_madd(&r, h, &t);
  840|      0|    x25519_ge_p1p1_to_p3(h, &r);
  841|      0|  }
  842|       |
  843|      0|  ge_p3_dbl(&r, h);
  844|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  845|      0|  ge_p2_dbl(&r, &s);
  846|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  847|      0|  ge_p2_dbl(&r, &s);
  848|      0|  x25519_ge_p1p1_to_p2(&s, &r);
  849|      0|  ge_p2_dbl(&r, &s);
  850|      0|  x25519_ge_p1p1_to_p3(h, &r);
  851|       |
  852|      0|  for (i = 0; i < 64; i += 2) {
  ------------------
  |  Branch (852:15): [True: 0, False: 0]
  ------------------
  853|      0|    table_select(&t, i / 2, e[i]);
  854|      0|    ge_madd(&r, h, &t);
  855|      0|    x25519_ge_p1p1_to_p3(h, &r);
  856|      0|  }
  857|      0|}
X25519_public_from_private:
 2125|  11.7k|                                const uint8_t private_key[32]) {
 2126|       |#if defined(BORINGSSL_X25519_NEON)
 2127|       |  if (CRYPTO_is_NEON_capable()) {
 2128|       |    static const uint8_t kMongomeryBasePoint[32] = {9};
 2129|       |    x25519_NEON(out_public_value, private_key, kMongomeryBasePoint);
 2130|       |    return;
 2131|       |  }
 2132|       |#endif
 2133|       |
 2134|  11.7k|  uint8_t e[32];
 2135|  11.7k|  OPENSSL_memcpy(e, private_key, 32);
 2136|  11.7k|  e[0] &= 248;
 2137|  11.7k|  e[31] &= 127;
 2138|  11.7k|  e[31] |= 64;
 2139|       |
 2140|  11.7k|  ge_p3 A;
 2141|  11.7k|  x25519_ge_scalarmult_base(&A, e);
 2142|       |
 2143|       |  // We only need the u-coordinate of the curve25519 point. The map is
 2144|       |  // u=(y+1)/(1-y). Since y=Y/Z, this gives u=(Z+Y)/(Z-Y).
 2145|  11.7k|  fe_loose zplusy, zminusy;
 2146|  11.7k|  fe zminusy_inv;
 2147|  11.7k|  fe_add(&zplusy, &A.Z, &A.Y);
 2148|  11.7k|  fe_sub(&zminusy, &A.Z, &A.Y);
 2149|  11.7k|  fe_loose_invert(&zminusy_inv, &zminusy);
 2150|  11.7k|  fe_mul_tlt(&zminusy_inv, &zplusy, &zminusy_inv);
 2151|  11.7k|  fe_tobytes(out_public_value, &zminusy_inv);
 2152|  11.7k|  CONSTTIME_DECLASSIFY(out_public_value, 32);
 2153|  11.7k|}
curve25519.c:fe_mul_ttt:
  231|   117k|static void fe_mul_ttt(fe *h, const fe *f, const fe *g) {
  232|   117k|  fe_mul_impl(h->v, f->v, g->v);
  233|   117k|}
curve25519.c:fe_mul_impl:
  216|   141k|                        const fe_limb_t in2[FE_NUM_LIMBS]) {
  217|   141k|  assert_fe_loose(in1);
  ------------------
  |  |   99|   141k|  do {                                                                  \
  |  |  100|   846k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 705k, False: 141k]
  |  |  ------------------
  |  |  101|   705k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|   705k|    }                                                                   \
  |  |  103|   141k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  218|   141k|  assert_fe_loose(in2);
  ------------------
  |  |   99|   141k|  do {                                                                  \
  |  |  100|   846k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 705k, False: 141k]
  |  |  ------------------
  |  |  101|   705k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|   705k|    }                                                                   \
  |  |  103|   141k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  219|   141k|  fiat_25519_carry_mul(out, in1, in2);
  220|   141k|  assert_fe(out);
  ------------------
  |  |   82|   141k|  do {                                                                  \
  |  |   83|   846k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 705k, False: 141k]
  |  |  ------------------
  |  |   84|   705k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|   705k|    }                                                                   \
  |  |   86|   141k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  221|   141k|}
curve25519.c:fe_tobytes:
  165|  11.7k|static void fe_tobytes(uint8_t s[32], const fe *f) {
  166|  11.7k|  assert_fe(f->v);
  ------------------
  |  |   82|  11.7k|  do {                                                                  \
  |  |   83|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |   84|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  58.7k|    }                                                                   \
  |  |   86|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  167|  11.7k|  fiat_25519_to_bytes(s, f->v);
  168|  11.7k|}
curve25519.c:fe_sq_tt:
  253|  2.97M|static void fe_sq_tt(fe *h, const fe *f) {
  254|  2.97M|  assert_fe_loose(f->v);
  ------------------
  |  |   99|  2.97M|  do {                                                                  \
  |  |  100|  17.8M|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 14.8M, False: 2.97M]
  |  |  ------------------
  |  |  101|  14.8M|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  14.8M|    }                                                                   \
  |  |  103|  2.97M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  255|  2.97M|  fiat_25519_carry_square(h->v, f->v);
  256|  2.97M|  assert_fe(h->v);
  ------------------
  |  |   82|  2.97M|  do {                                                                  \
  |  |   83|  17.8M|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 14.8M, False: 2.97M]
  |  |  ------------------
  |  |   84|  14.8M|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  14.8M|    }                                                                   \
  |  |   86|  2.97M|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  257|  2.97M|}
curve25519.c:fe_sub:
  201|  11.7k|static void fe_sub(fe_loose *h, const fe *f, const fe *g) {
  202|  11.7k|  assert_fe(f->v);
  ------------------
  |  |   82|  11.7k|  do {                                                                  \
  |  |   83|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |   84|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  58.7k|    }                                                                   \
  |  |   86|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  203|  11.7k|  assert_fe(g->v);
  ------------------
  |  |   82|  11.7k|  do {                                                                  \
  |  |   83|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |   84|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  58.7k|    }                                                                   \
  |  |   86|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  204|  11.7k|  fiat_25519_sub(h->v, f->v, g->v);
  205|  11.7k|  assert_fe_loose(h->v);
  ------------------
  |  |   99|  11.7k|  do {                                                                  \
  |  |  100|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |  101|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  58.7k|    }                                                                   \
  |  |  103|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  206|  11.7k|}
curve25519.c:fe_add:
  192|  11.7k|static void fe_add(fe_loose *h, const fe *f, const fe *g) {
  193|  11.7k|  assert_fe(f->v);
  ------------------
  |  |   82|  11.7k|  do {                                                                  \
  |  |   83|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |   84|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  58.7k|    }                                                                   \
  |  |   86|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  194|  11.7k|  assert_fe(g->v);
  ------------------
  |  |   82|  11.7k|  do {                                                                  \
  |  |   83|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |   84|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  58.7k|    }                                                                   \
  |  |   86|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  195|  11.7k|  fiat_25519_add(h->v, f->v, g->v);
  196|  11.7k|  assert_fe_loose(h->v);
  ------------------
  |  |   99|  11.7k|  do {                                                                  \
  |  |  100|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |  101|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  58.7k|    }                                                                   \
  |  |  103|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  197|  11.7k|}
curve25519.c:fe_mul_tlt:
  235|  23.5k|static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) {
  236|  23.5k|  fe_mul_impl(h->v, f->v, g->v);
  237|  23.5k|}
curve25519.c:fe_sq_tl:
  247|  11.7k|static void fe_sq_tl(fe *h, const fe_loose *f) {
  248|  11.7k|  assert_fe_loose(f->v);
  ------------------
  |  |   99|  11.7k|  do {                                                                  \
  |  |  100|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (100:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |  101|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x1a666666666664));            \
  |  |  102|  58.7k|    }                                                                   \
  |  |  103|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  249|  11.7k|  fiat_25519_carry_square(h->v, f->v);
  250|  11.7k|  assert_fe(h->v);
  ------------------
  |  |   82|  11.7k|  do {                                                                  \
  |  |   83|  70.5k|    for (unsigned _assert_fe_i = 0; _assert_fe_i < 5; _assert_fe_i++) { \
  |  |  ------------------
  |  |  |  Branch (83:37): [True: 58.7k, False: 11.7k]
  |  |  ------------------
  |  |   84|  58.7k|      assert(f[_assert_fe_i] <= UINT64_C(0x8cccccccccccc));             \
  |  |   85|  58.7k|    }                                                                   \
  |  |   86|  11.7k|  } while (0)
  |  |  ------------------
  |  |  |  Branch (86:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  251|  11.7k|}
curve25519.c:fe_loose_invert:
  316|  11.7k|static void fe_loose_invert(fe *out, const fe_loose *z) {
  317|  11.7k|  fe t0;
  318|  11.7k|  fe t1;
  319|  11.7k|  fe t2;
  320|  11.7k|  fe t3;
  321|  11.7k|  int i;
  322|       |
  323|  11.7k|  fe_sq_tl(&t0, z);
  324|  11.7k|  fe_sq_tt(&t1, &t0);
  325|  23.5k|  for (i = 1; i < 2; ++i) {
  ------------------
  |  Branch (325:15): [True: 11.7k, False: 11.7k]
  ------------------
  326|  11.7k|    fe_sq_tt(&t1, &t1);
  327|  11.7k|  }
  328|  11.7k|  fe_mul_tlt(&t1, z, &t1);
  329|  11.7k|  fe_mul_ttt(&t0, &t0, &t1);
  330|  11.7k|  fe_sq_tt(&t2, &t0);
  331|  11.7k|  fe_mul_ttt(&t1, &t1, &t2);
  332|  11.7k|  fe_sq_tt(&t2, &t1);
  333|  58.7k|  for (i = 1; i < 5; ++i) {
  ------------------
  |  Branch (333:15): [True: 47.0k, False: 11.7k]
  ------------------
  334|  47.0k|    fe_sq_tt(&t2, &t2);
  335|  47.0k|  }
  336|  11.7k|  fe_mul_ttt(&t1, &t2, &t1);
  337|  11.7k|  fe_sq_tt(&t2, &t1);
  338|   117k|  for (i = 1; i < 10; ++i) {
  ------------------
  |  Branch (338:15): [True: 105k, False: 11.7k]
  ------------------
  339|   105k|    fe_sq_tt(&t2, &t2);
  340|   105k|  }
  341|  11.7k|  fe_mul_ttt(&t2, &t2, &t1);
  342|  11.7k|  fe_sq_tt(&t3, &t2);
  343|   235k|  for (i = 1; i < 20; ++i) {
  ------------------
  |  Branch (343:15): [True: 223k, False: 11.7k]
  ------------------
  344|   223k|    fe_sq_tt(&t3, &t3);
  345|   223k|  }
  346|  11.7k|  fe_mul_ttt(&t2, &t3, &t2);
  347|  11.7k|  fe_sq_tt(&t2, &t2);
  348|   117k|  for (i = 1; i < 10; ++i) {
  ------------------
  |  Branch (348:15): [True: 105k, False: 11.7k]
  ------------------
  349|   105k|    fe_sq_tt(&t2, &t2);
  350|   105k|  }
  351|  11.7k|  fe_mul_ttt(&t1, &t2, &t1);
  352|  11.7k|  fe_sq_tt(&t2, &t1);
  353|   587k|  for (i = 1; i < 50; ++i) {
  ------------------
  |  Branch (353:15): [True: 575k, False: 11.7k]
  ------------------
  354|   575k|    fe_sq_tt(&t2, &t2);
  355|   575k|  }
  356|  11.7k|  fe_mul_ttt(&t2, &t2, &t1);
  357|  11.7k|  fe_sq_tt(&t3, &t2);
  358|  1.17M|  for (i = 1; i < 100; ++i) {
  ------------------
  |  Branch (358:15): [True: 1.16M, False: 11.7k]
  ------------------
  359|  1.16M|    fe_sq_tt(&t3, &t3);
  360|  1.16M|  }
  361|  11.7k|  fe_mul_ttt(&t2, &t3, &t2);
  362|  11.7k|  fe_sq_tt(&t2, &t2);
  363|   587k|  for (i = 1; i < 50; ++i) {
  ------------------
  |  Branch (363:15): [True: 575k, False: 11.7k]
  ------------------
  364|   575k|    fe_sq_tt(&t2, &t2);
  365|   575k|  }
  366|  11.7k|  fe_mul_ttt(&t1, &t2, &t1);
  367|  11.7k|  fe_sq_tt(&t1, &t1);
  368|  58.7k|  for (i = 1; i < 5; ++i) {
  ------------------
  |  Branch (368:15): [True: 47.0k, False: 11.7k]
  ------------------
  369|  47.0k|    fe_sq_tt(&t1, &t1);
  370|  47.0k|  }
  371|  11.7k|  fe_mul_ttt(out, &t1, &t0);
  372|  11.7k|}

METHOD_ref:
   86|  22.7k|void METHOD_ref(void *method_in) {
   87|  22.7k|  assert(((struct openssl_method_common_st*) method_in)->is_static);
   88|  22.7k|}
METHOD_unref:
   90|  22.7k|void METHOD_unref(void *method_in) {
   91|  22.7k|  struct openssl_method_common_st *method = method_in;
   92|       |
   93|  22.7k|  if (method == NULL) {
  ------------------
  |  Branch (93:7): [True: 0, False: 22.7k]
  ------------------
   94|      0|    return;
   95|      0|  }
   96|  22.7k|  assert(method->is_static);
   97|  22.7k|}

ERR_clear_error:
  341|  4.83k|void ERR_clear_error(void) {
  342|  4.83k|  ERR_STATE *const state = err_get_state();
  343|  4.83k|  unsigned i;
  344|       |
  345|  4.83k|  if (state == NULL) {
  ------------------
  |  Branch (345:7): [True: 0, False: 4.83k]
  ------------------
  346|      0|    return;
  347|      0|  }
  348|       |
  349|  82.1k|  for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |  477|  82.1k|#define ERR_NUM_ERRORS 16
  ------------------
  |  Branch (349:15): [True: 77.2k, False: 4.83k]
  ------------------
  350|  77.2k|    err_clear(&state->errors[i]);
  351|  77.2k|  }
  352|  4.83k|  free(state->to_free);
  353|  4.83k|  state->to_free = NULL;
  354|       |
  355|  4.83k|  state->top = state->bottom = 0;
  356|  4.83k|}
ERR_put_error:
  657|   120k|                   unsigned line) {
  658|   120k|  ERR_STATE *const state = err_get_state();
  659|   120k|  struct err_error_st *error;
  660|       |
  661|   120k|  if (state == NULL) {
  ------------------
  |  Branch (661:7): [True: 0, False: 120k]
  ------------------
  662|      0|    return;
  663|      0|  }
  664|       |
  665|   120k|  if (library == ERR_LIB_SYS && reason == 0) {
  ------------------
  |  Branch (665:7): [True: 0, False: 120k]
  |  Branch (665:33): [True: 0, False: 0]
  ------------------
  666|       |#if defined(OPENSSL_WINDOWS)
  667|       |    reason = GetLastError();
  668|       |#else
  669|      0|    reason = errno;
  670|      0|#endif
  671|      0|  }
  672|       |
  673|   120k|  state->top = (state->top + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|   120k|#define ERR_NUM_ERRORS 16
  ------------------
  674|   120k|  if (state->top == state->bottom) {
  ------------------
  |  Branch (674:7): [True: 105k, False: 15.0k]
  ------------------
  675|   105k|    state->bottom = (state->bottom + 1) % ERR_NUM_ERRORS;
  ------------------
  |  |  477|   105k|#define ERR_NUM_ERRORS 16
  ------------------
  676|   105k|  }
  677|       |
  678|   120k|  error = &state->errors[state->top];
  679|   120k|  err_clear(error);
  680|   120k|  error->file = file;
  681|   120k|  error->line = line;
  682|   120k|  error->packed = ERR_PACK(library, reason);
  ------------------
  |  |  480|   120k|  (((((uint32_t)(lib)) & 0xff) << 24) | ((((uint32_t)(reason)) & 0xfff)))
  ------------------
  683|   120k|}
ERR_add_error_dataf:
  735|  13.2k|void ERR_add_error_dataf(const char *format, ...) {
  736|  13.2k|  char *buf = NULL;
  737|  13.2k|  va_list ap;
  738|       |
  739|  13.2k|  va_start(ap, format);
  740|  13.2k|  if (OPENSSL_vasprintf_internal(&buf, format, ap, /*system_malloc=*/1) == -1) {
  ------------------
  |  Branch (740:7): [True: 0, False: 13.2k]
  ------------------
  741|      0|    return;
  742|      0|  }
  743|  13.2k|  va_end(ap);
  744|       |
  745|  13.2k|  err_set_error_data(buf);
  746|  13.2k|}
err.c:err_get_state:
  213|   138k|static ERR_STATE *err_get_state(void) {
  214|   138k|  ERR_STATE *state = CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_ERR);
  215|   138k|  if (state == NULL) {
  ------------------
  |  Branch (215:7): [True: 1, False: 138k]
  ------------------
  216|      1|    state = malloc(sizeof(ERR_STATE));
  217|      1|    if (state == NULL) {
  ------------------
  |  Branch (217:9): [True: 0, False: 1]
  ------------------
  218|      0|      return NULL;
  219|      0|    }
  220|      1|    OPENSSL_memset(state, 0, sizeof(ERR_STATE));
  221|      1|    if (!CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_ERR, state,
  ------------------
  |  Branch (221:9): [True: 0, False: 1]
  ------------------
  222|      1|                                 err_state_free)) {
  223|      0|      return NULL;
  224|      0|    }
  225|      1|  }
  226|       |
  227|   138k|  return state;
  228|   138k|}
err.c:err_clear:
  168|   198k|static void err_clear(struct err_error_st *error) {
  169|   198k|  free(error->data);
  170|   198k|  OPENSSL_memset(error, 0, sizeof(struct err_error_st));
  171|   198k|}
err.c:err_set_error_data:
  641|  13.2k|static void err_set_error_data(char *data) {
  642|  13.2k|  ERR_STATE *const state = err_get_state();
  643|  13.2k|  struct err_error_st *error;
  644|       |
  645|  13.2k|  if (state == NULL || state->top == state->bottom) {
  ------------------
  |  Branch (645:7): [True: 0, False: 13.2k]
  |  Branch (645:24): [True: 0, False: 13.2k]
  ------------------
  646|      0|    free(data);
  647|      0|    return;
  648|      0|  }
  649|       |
  650|  13.2k|  error = &state->errors[state->top];
  651|       |
  652|  13.2k|  free(error->data);
  653|  13.2k|  error->data = data;
  654|  13.2k|}

EVP_PKEY_new:
   83|  22.7k|EVP_PKEY *EVP_PKEY_new(void) {
   84|  22.7k|  EVP_PKEY *ret;
   85|       |
   86|  22.7k|  ret = OPENSSL_malloc(sizeof(EVP_PKEY));
   87|  22.7k|  if (ret == NULL) {
  ------------------
  |  Branch (87:7): [True: 0, False: 22.7k]
  ------------------
   88|      0|    return NULL;
   89|      0|  }
   90|       |
   91|  22.7k|  OPENSSL_memset(ret, 0, sizeof(EVP_PKEY));
   92|  22.7k|  ret->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  22.7k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  22.7k|#define NID_undef 0
  |  |  ------------------
  ------------------
   93|  22.7k|  ret->references = 1;
   94|       |
   95|  22.7k|  return ret;
   96|  22.7k|}
EVP_PKEY_free:
  106|  49.7k|void EVP_PKEY_free(EVP_PKEY *pkey) {
  107|  49.7k|  if (pkey == NULL) {
  ------------------
  |  Branch (107:7): [True: 20.0k, False: 29.6k]
  ------------------
  108|  20.0k|    return;
  109|  20.0k|  }
  110|       |
  111|  29.6k|  if (!CRYPTO_refcount_dec_and_test_zero(&pkey->references)) {
  ------------------
  |  Branch (111:7): [True: 6.91k, False: 22.7k]
  ------------------
  112|  6.91k|    return;
  113|  6.91k|  }
  114|       |
  115|  22.7k|  free_it(pkey);
  116|  22.7k|  OPENSSL_free(pkey);
  117|  22.7k|}
EVP_PKEY_up_ref:
  119|  6.91k|int EVP_PKEY_up_ref(EVP_PKEY *pkey) {
  120|  6.91k|  CRYPTO_refcount_inc(&pkey->references);
  121|  6.91k|  return 1;
  122|  6.91k|}
EVP_PKEY_is_opaque:
  124|  14.7k|int EVP_PKEY_is_opaque(const EVP_PKEY *pkey) {
  125|  14.7k|  if (pkey->ameth && pkey->ameth->pkey_opaque) {
  ------------------
  |  Branch (125:7): [True: 14.7k, False: 0]
  |  Branch (125:22): [True: 14.7k, False: 0]
  ------------------
  126|  14.7k|    return pkey->ameth->pkey_opaque(pkey);
  127|  14.7k|  }
  128|      0|  return 0;
  129|  14.7k|}
EVP_PKEY_cmp:
  131|  14.7k|int EVP_PKEY_cmp(const EVP_PKEY *a, const EVP_PKEY *b) {
  132|  14.7k|  if (a->type != b->type) {
  ------------------
  |  Branch (132:7): [True: 0, False: 14.7k]
  ------------------
  133|      0|    return -1;
  134|      0|  }
  135|       |
  136|  14.7k|  if (a->ameth) {
  ------------------
  |  Branch (136:7): [True: 14.7k, False: 0]
  ------------------
  137|  14.7k|    int ret;
  138|       |    // Compare parameters if the algorithm has them
  139|  14.7k|    if (a->ameth->param_cmp) {
  ------------------
  |  Branch (139:9): [True: 0, False: 14.7k]
  ------------------
  140|      0|      ret = a->ameth->param_cmp(a, b);
  141|      0|      if (ret <= 0) {
  ------------------
  |  Branch (141:11): [True: 0, False: 0]
  ------------------
  142|      0|        return ret;
  143|      0|      }
  144|      0|    }
  145|       |
  146|  14.7k|    if (a->ameth->pub_cmp) {
  ------------------
  |  Branch (146:9): [True: 14.7k, False: 0]
  ------------------
  147|  14.7k|      return a->ameth->pub_cmp(a, b);
  148|  14.7k|    }
  149|  14.7k|  }
  150|       |
  151|      0|  return -2;
  152|  14.7k|}
EVP_PKEY_id:
  208|  32.5k|int EVP_PKEY_id(const EVP_PKEY *pkey) {
  209|  32.5k|  return pkey->type;
  210|  32.5k|}
EVP_PKEY_assign_RSA:
  248|  22.7k|int EVP_PKEY_assign_RSA(EVP_PKEY *pkey, RSA *key) {
  249|  22.7k|  return EVP_PKEY_assign(pkey, EVP_PKEY_RSA, key);
  ------------------
  |  |  175|  22.7k|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|  22.7k|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  250|  22.7k|}
EVP_PKEY_assign:
  327|  22.7k|int EVP_PKEY_assign(EVP_PKEY *pkey, int type, void *key) {
  328|  22.7k|  if (!EVP_PKEY_set_type(pkey, type)) {
  ------------------
  |  Branch (328:7): [True: 0, False: 22.7k]
  ------------------
  329|      0|    return 0;
  330|      0|  }
  331|  22.7k|  pkey->pkey = key;
  332|  22.7k|  return key != NULL;
  333|  22.7k|}
EVP_PKEY_set_type:
  335|  45.4k|int EVP_PKEY_set_type(EVP_PKEY *pkey, int type) {
  336|  45.4k|  const EVP_PKEY_ASN1_METHOD *ameth;
  337|       |
  338|  45.4k|  if (pkey && pkey->pkey) {
  ------------------
  |  Branch (338:7): [True: 45.4k, False: 0]
  |  Branch (338:15): [True: 0, False: 45.4k]
  ------------------
  339|      0|    free_it(pkey);
  340|      0|  }
  341|       |
  342|  45.4k|  ameth = evp_pkey_asn1_find(type);
  343|  45.4k|  if (ameth == NULL) {
  ------------------
  |  Branch (343:7): [True: 0, False: 45.4k]
  ------------------
  344|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  345|      0|    ERR_add_error_dataf("algorithm %d", type);
  346|      0|    return 0;
  347|      0|  }
  348|       |
  349|  45.4k|  if (pkey) {
  ------------------
  |  Branch (349:7): [True: 45.4k, False: 0]
  ------------------
  350|  45.4k|    pkey->ameth = ameth;
  351|  45.4k|    pkey->type = pkey->ameth->pkey_id;
  352|  45.4k|  }
  353|       |
  354|  45.4k|  return 1;
  355|  45.4k|}
evp.c:free_it:
   98|  22.7k|static void free_it(EVP_PKEY *pkey) {
   99|  22.7k|  if (pkey->ameth && pkey->ameth->pkey_free) {
  ------------------
  |  Branch (99:7): [True: 22.7k, False: 0]
  |  Branch (99:22): [True: 22.7k, False: 0]
  ------------------
  100|  22.7k|    pkey->ameth->pkey_free(pkey);
  101|  22.7k|    pkey->pkey = NULL;
  102|  22.7k|    pkey->type = EVP_PKEY_NONE;
  ------------------
  |  |  174|  22.7k|#define EVP_PKEY_NONE NID_undef
  |  |  ------------------
  |  |  |  |   85|  22.7k|#define NID_undef 0
  |  |  ------------------
  ------------------
  103|  22.7k|  }
  104|  22.7k|}
evp.c:evp_pkey_asn1_find:
  215|  45.4k|static const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int nid) {
  216|  45.4k|  switch (nid) {
  217|  45.4k|    case EVP_PKEY_RSA:
  ------------------
  |  |  175|  45.4k|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|  45.4k|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  |  Branch (217:5): [True: 45.4k, False: 0]
  ------------------
  218|  45.4k|      return &rsa_asn1_meth;
  219|      0|    case EVP_PKEY_EC:
  ------------------
  |  |  178|      0|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|      0|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (219:5): [True: 0, False: 45.4k]
  ------------------
  220|      0|      return &ec_asn1_meth;
  221|      0|    case EVP_PKEY_DSA:
  ------------------
  |  |  177|      0|#define EVP_PKEY_DSA NID_dsa
  |  |  ------------------
  |  |  |  |  612|      0|#define NID_dsa 116
  |  |  ------------------
  ------------------
  |  Branch (221:5): [True: 0, False: 45.4k]
  ------------------
  222|      0|      return &dsa_asn1_meth;
  223|      0|    case EVP_PKEY_ED25519:
  ------------------
  |  |  179|      0|#define EVP_PKEY_ED25519 NID_ED25519
  |  |  ------------------
  |  |  |  | 4199|      0|#define NID_ED25519 949
  |  |  ------------------
  ------------------
  |  Branch (223:5): [True: 0, False: 45.4k]
  ------------------
  224|      0|      return &ed25519_asn1_meth;
  225|      0|    case EVP_PKEY_X25519:
  ------------------
  |  |  180|      0|#define EVP_PKEY_X25519 NID_X25519
  |  |  ------------------
  |  |  |  | 4195|      0|#define NID_X25519 948
  |  |  ------------------
  ------------------
  |  Branch (225:5): [True: 0, False: 45.4k]
  ------------------
  226|      0|      return &x25519_asn1_meth;
  227|      0|    default:
  ------------------
  |  Branch (227:5): [True: 0, False: 45.4k]
  ------------------
  228|      0|      return NULL;
  229|  45.4k|  }
  230|  45.4k|}

EVP_parse_public_key:
   98|  22.7k|EVP_PKEY *EVP_parse_public_key(CBS *cbs) {
   99|       |  // Parse the SubjectPublicKeyInfo.
  100|  22.7k|  CBS spki, algorithm, key;
  101|  22.7k|  int type;
  102|  22.7k|  uint8_t padding;
  103|  22.7k|  if (!CBS_get_asn1(cbs, &spki, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (103:7): [True: 0, False: 22.7k]
  ------------------
  104|  22.7k|      !CBS_get_asn1(&spki, &algorithm, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (104:7): [True: 0, False: 22.7k]
  ------------------
  105|  22.7k|      !CBS_get_asn1(&spki, &key, CBS_ASN1_BITSTRING) ||
  ------------------
  |  |  216|  22.7k|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (105:7): [True: 0, False: 22.7k]
  ------------------
  106|  22.7k|      CBS_len(&spki) != 0) {
  ------------------
  |  Branch (106:7): [True: 0, False: 22.7k]
  ------------------
  107|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  108|      0|    return NULL;
  109|      0|  }
  110|  22.7k|  if (!parse_key_type(&algorithm, &type)) {
  ------------------
  |  Branch (110:7): [True: 0, False: 22.7k]
  ------------------
  111|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  112|      0|    return NULL;
  113|      0|  }
  114|  22.7k|  if (// Every key type defined encodes the key as a byte string with the same
  115|       |      // conversion to BIT STRING.
  116|  22.7k|      !CBS_get_u8(&key, &padding) ||
  ------------------
  |  Branch (116:7): [True: 0, False: 22.7k]
  ------------------
  117|  22.7k|      padding != 0) {
  ------------------
  |  Branch (117:7): [True: 0, False: 22.7k]
  ------------------
  118|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  119|      0|    return NULL;
  120|      0|  }
  121|       |
  122|       |  // Set up an |EVP_PKEY| of the appropriate type.
  123|  22.7k|  EVP_PKEY *ret = EVP_PKEY_new();
  124|  22.7k|  if (ret == NULL ||
  ------------------
  |  Branch (124:7): [True: 0, False: 22.7k]
  ------------------
  125|  22.7k|      !EVP_PKEY_set_type(ret, type)) {
  ------------------
  |  Branch (125:7): [True: 0, False: 22.7k]
  ------------------
  126|      0|    goto err;
  127|      0|  }
  128|       |
  129|       |  // Call into the type-specific SPKI decoding function.
  130|  22.7k|  if (ret->ameth->pub_decode == NULL) {
  ------------------
  |  Branch (130:7): [True: 0, False: 22.7k]
  ------------------
  131|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_UNSUPPORTED_ALGORITHM);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|      0|    goto err;
  133|      0|  }
  134|  22.7k|  if (!ret->ameth->pub_decode(ret, &algorithm, &key)) {
  ------------------
  |  Branch (134:7): [True: 0, False: 22.7k]
  ------------------
  135|      0|    goto err;
  136|      0|  }
  137|       |
  138|  22.7k|  return ret;
  139|       |
  140|      0|err:
  141|      0|  EVP_PKEY_free(ret);
  142|      0|  return NULL;
  143|  22.7k|}
evp_asn1.c:parse_key_type:
   80|  22.7k|static int parse_key_type(CBS *cbs, int *out_type) {
   81|  22.7k|  CBS oid;
   82|  22.7k|  if (!CBS_get_asn1(cbs, &oid, CBS_ASN1_OBJECT)) {
  ------------------
  |  |  219|  22.7k|#define CBS_ASN1_OBJECT 0x6u
  ------------------
  |  Branch (82:7): [True: 0, False: 22.7k]
  ------------------
   83|      0|    return 0;
   84|      0|  }
   85|       |
   86|  22.7k|  for (unsigned i = 0; i < OPENSSL_ARRAY_SIZE(kASN1Methods); i++) {
  ------------------
  |  |  221|  22.7k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (86:24): [True: 22.7k, False: 0]
  ------------------
   87|  22.7k|    const EVP_PKEY_ASN1_METHOD *method = kASN1Methods[i];
   88|  22.7k|    if (CBS_len(&oid) == method->oid_len &&
  ------------------
  |  Branch (88:9): [True: 22.7k, False: 0]
  ------------------
   89|  22.7k|        OPENSSL_memcmp(CBS_data(&oid), method->oid, method->oid_len) == 0) {
  ------------------
  |  Branch (89:9): [True: 22.7k, False: 0]
  ------------------
   90|  22.7k|      *out_type = method->pkey_id;
   91|  22.7k|      return 1;
   92|  22.7k|    }
   93|  22.7k|  }
   94|       |
   95|      0|  return 0;
   96|  22.7k|}

p_rsa_asn1.c:rsa_pub_decode:
   89|  22.7k|static int rsa_pub_decode(EVP_PKEY *out, CBS *params, CBS *key) {
   90|       |  // See RFC 3279, section 2.3.1.
   91|       |
   92|       |  // The parameters must be NULL.
   93|  22.7k|  CBS null;
   94|  22.7k|  if (!CBS_get_asn1(params, &null, CBS_ASN1_NULL) ||
  ------------------
  |  |  218|  22.7k|#define CBS_ASN1_NULL 0x5u
  ------------------
  |  Branch (94:7): [True: 0, False: 22.7k]
  ------------------
   95|  22.7k|      CBS_len(&null) != 0 ||
  ------------------
  |  Branch (95:7): [True: 0, False: 22.7k]
  ------------------
   96|  22.7k|      CBS_len(params) != 0) {
  ------------------
  |  Branch (96:7): [True: 0, False: 22.7k]
  ------------------
   97|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   98|      0|    return 0;
   99|      0|  }
  100|       |
  101|  22.7k|  RSA *rsa = RSA_parse_public_key(key);
  102|  22.7k|  if (rsa == NULL || CBS_len(key) != 0) {
  ------------------
  |  Branch (102:7): [True: 0, False: 22.7k]
  |  Branch (102:22): [True: 0, False: 22.7k]
  ------------------
  103|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  104|      0|    RSA_free(rsa);
  105|      0|    return 0;
  106|      0|  }
  107|       |
  108|  22.7k|  EVP_PKEY_assign_RSA(out, rsa);
  109|  22.7k|  return 1;
  110|  22.7k|}
p_rsa_asn1.c:rsa_pub_cmp:
  112|  14.7k|static int rsa_pub_cmp(const EVP_PKEY *a, const EVP_PKEY *b) {
  113|  14.7k|  const RSA *a_rsa = a->pkey;
  114|  14.7k|  const RSA *b_rsa = b->pkey;
  115|  14.7k|  return BN_cmp(RSA_get0_n(b_rsa), RSA_get0_n(a_rsa)) == 0 &&
  ------------------
  |  Branch (115:10): [True: 14.7k, False: 0]
  ------------------
  116|  14.7k|         BN_cmp(RSA_get0_e(b_rsa), RSA_get0_e(a_rsa)) == 0;
  ------------------
  |  Branch (116:10): [True: 14.7k, False: 0]
  ------------------
  117|  14.7k|}
p_rsa_asn1.c:rsa_opaque:
  159|  14.7k|static int rsa_opaque(const EVP_PKEY *pkey) {
  160|  14.7k|  const RSA *rsa = pkey->pkey;
  161|  14.7k|  return RSA_is_opaque(rsa);
  162|  14.7k|}
p_rsa_asn1.c:int_rsa_free:
  174|  22.7k|static void int_rsa_free(EVP_PKEY *pkey) {
  175|  22.7k|  RSA_free(pkey->pkey);
  176|  22.7k|  pkey->pkey = NULL;
  177|  22.7k|}

CRYPTO_new_ex_data:
  206|  52.4k|void CRYPTO_new_ex_data(CRYPTO_EX_DATA *ad) {
  207|  52.4k|  ad->sk = NULL;
  208|  52.4k|}
CRYPTO_free_ex_data:
  211|  52.4k|                         CRYPTO_EX_DATA *ad) {
  212|  52.4k|  if (ad->sk == NULL) {
  ------------------
  |  Branch (212:7): [True: 52.4k, False: 0]
  ------------------
  213|       |    // Nothing to do.
  214|  52.4k|    return;
  215|  52.4k|  }
  216|       |
  217|      0|  uint32_t num_funcs = CRYPTO_atomic_load_u32(&ex_data_class->num_funcs);
  218|       |  // |CRYPTO_get_ex_new_index| will not allocate indices beyond |INT_MAX|.
  219|      0|  assert(num_funcs <= (size_t)(INT_MAX - ex_data_class->num_reserved));
  220|       |
  221|       |  // Defer dereferencing |ex_data_class->funcs| and |funcs->next|. It must come
  222|       |  // after the |num_funcs| comparison to be correctly synchronized.
  223|      0|  CRYPTO_EX_DATA_FUNCS *const *funcs = &ex_data_class->funcs;
  224|      0|  for (uint32_t i = 0; i < num_funcs; i++) {
  ------------------
  |  Branch (224:24): [True: 0, False: 0]
  ------------------
  225|      0|    if ((*funcs)->free_func != NULL) {
  ------------------
  |  Branch (225:9): [True: 0, False: 0]
  ------------------
  226|      0|      int index = (int)i + ex_data_class->num_reserved;
  227|      0|      void *ptr = CRYPTO_get_ex_data(ad, index);
  228|      0|      (*funcs)->free_func(obj, ptr, ad, index, (*funcs)->argl, (*funcs)->argp);
  229|      0|    }
  230|      0|    funcs = &(*funcs)->next;
  231|      0|  }
  232|       |
  233|      0|  sk_void_free(ad->sk);
  234|      0|  ad->sk = NULL;
  235|      0|}

bcm.c:hwaes_capable:
   33|  41.9k|OPENSSL_INLINE int hwaes_capable(void) { return CRYPTO_is_AESNI_capable(); }

bn_usub_consttime:
  226|      4|int bn_usub_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b) {
  227|       |  // |b| may have more words than |a| given non-minimal inputs, but all words
  228|       |  // beyond |a->width| must then be zero.
  229|      4|  int b_width = b->width;
  230|      4|  if (b_width > a->width) {
  ------------------
  |  Branch (230:7): [True: 0, False: 4]
  ------------------
  231|      0|    if (!bn_fits_in_words(b, a->width)) {
  ------------------
  |  Branch (231:9): [True: 0, False: 0]
  ------------------
  232|      0|      OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  233|      0|      return 0;
  234|      0|    }
  235|      0|    b_width = a->width;
  236|      0|  }
  237|       |
  238|      4|  if (!bn_wexpand(r, a->width)) {
  ------------------
  |  Branch (238:7): [True: 0, False: 4]
  ------------------
  239|      0|    return 0;
  240|      0|  }
  241|       |
  242|      4|  BN_ULONG borrow = bn_sub_words(r->d, a->d, b->d, b_width);
  243|     68|  for (int i = b_width; i < a->width; i++) {
  ------------------
  |  Branch (243:25): [True: 64, False: 4]
  ------------------
  244|       |    // |r| and |a| may alias, so use a temporary.
  245|     64|    BN_ULONG tmp = a->d[i];
  246|     64|    r->d[i] = a->d[i] - borrow;
  247|     64|    borrow = tmp < r->d[i];
  248|     64|  }
  249|       |
  250|      4|  if (borrow) {
  ------------------
  |  Branch (250:7): [True: 0, False: 4]
  ------------------
  251|      0|    OPENSSL_PUT_ERROR(BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  252|      0|    return 0;
  253|      0|  }
  254|       |
  255|      4|  r->width = a->width;
  256|      4|  r->neg = 0;
  257|      4|  return 1;
  258|      4|}

bn_mul_words:
  131|      8|                      BN_ULONG w) {
  132|      8|  BN_ULONG c1 = 0;
  133|       |
  134|      8|  if (num == 0) {
  ------------------
  |  Branch (134:7): [True: 0, False: 8]
  ------------------
  135|      0|    return c1;
  136|      0|  }
  137|       |
  138|     40|  while (num & ~3) {
  ------------------
  |  Branch (138:10): [True: 32, False: 8]
  ------------------
  139|     32|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|     32|  do {                                                                     \
  |  |   85|     32|    register BN_ULONG high, low;                                           \
  |  |   86|     32|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|     32|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|     32|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|     32|            : "a"(low), "g"(0)                                             \
  |  |   90|     32|            : "cc");                                                       \
  |  |   91|     32|    (r) = (carry);                                                         \
  |  |   92|     32|    (carry) = high;                                                        \
  |  |   93|     32|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  140|     32|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|     32|  do {                                                                     \
  |  |   85|     32|    register BN_ULONG high, low;                                           \
  |  |   86|     32|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|     32|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|     32|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|     32|            : "a"(low), "g"(0)                                             \
  |  |   90|     32|            : "cc");                                                       \
  |  |   91|     32|    (r) = (carry);                                                         \
  |  |   92|     32|    (carry) = high;                                                        \
  |  |   93|     32|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  141|     32|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|     32|  do {                                                                     \
  |  |   85|     32|    register BN_ULONG high, low;                                           \
  |  |   86|     32|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|     32|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|     32|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|     32|            : "a"(low), "g"(0)                                             \
  |  |   90|     32|            : "cc");                                                       \
  |  |   91|     32|    (r) = (carry);                                                         \
  |  |   92|     32|    (carry) = high;                                                        \
  |  |   93|     32|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  142|     32|    mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   84|     32|  do {                                                                     \
  |  |   85|     32|    register BN_ULONG high, low;                                           \
  |  |   86|     32|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|     32|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|     32|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|     32|            : "a"(low), "g"(0)                                             \
  |  |   90|     32|            : "cc");                                                       \
  |  |   91|     32|    (r) = (carry);                                                         \
  |  |   92|     32|    (carry) = high;                                                        \
  |  |   93|     32|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  143|     32|    ap += 4;
  144|     32|    rp += 4;
  145|     32|    num -= 4;
  146|     32|  }
  147|      8|  if (num) {
  ------------------
  |  Branch (147:7): [True: 8, False: 0]
  ------------------
  148|      8|    mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   84|      8|  do {                                                                     \
  |  |   85|      8|    register BN_ULONG high, low;                                           \
  |  |   86|      8|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|      8|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|      8|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|      8|            : "a"(low), "g"(0)                                             \
  |  |   90|      8|            : "cc");                                                       \
  |  |   91|      8|    (r) = (carry);                                                         \
  |  |   92|      8|    (carry) = high;                                                        \
  |  |   93|      8|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  149|      8|    if (--num == 0) {
  ------------------
  |  Branch (149:9): [True: 8, False: 0]
  ------------------
  150|      8|      return c1;
  151|      8|    }
  152|      0|    mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   84|      0|  do {                                                                     \
  |  |   85|      0|    register BN_ULONG high, low;                                           \
  |  |   86|      0|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|      0|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|      0|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|      0|            : "a"(low), "g"(0)                                             \
  |  |   90|      0|            : "cc");                                                       \
  |  |   91|      0|    (r) = (carry);                                                         \
  |  |   92|      0|    (carry) = high;                                                        \
  |  |   93|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|      0|    if (--num == 0) {
  ------------------
  |  Branch (153:9): [True: 0, False: 0]
  ------------------
  154|      0|      return c1;
  155|      0|    }
  156|      0|    mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   84|      0|  do {                                                                     \
  |  |   85|      0|    register BN_ULONG high, low;                                           \
  |  |   86|      0|    __asm__("mulq %3" : "=a"(low), "=d"(high) : "a"(word), "g"(a) : "cc"); \
  |  |   87|      0|    __asm__("addq %2,%0; adcq %3,%1"                                       \
  |  |   88|      0|            : "+r"(carry), "+d"(high)                                      \
  |  |   89|      0|            : "a"(low), "g"(0)                                             \
  |  |   90|      0|            : "cc");                                                       \
  |  |   91|      0|    (r) = (carry);                                                         \
  |  |   92|      0|    (carry) = high;                                                        \
  |  |   93|      0|  } while (0)
  |  |  ------------------
  |  |  |  Branch (93:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|      0|  }
  158|      0|  return c1;
  159|      8|}
bn_add_words:
  189|  7.97k|                      size_t n) {
  190|  7.97k|  BN_ULONG ret;
  191|  7.97k|  size_t i = 0;
  192|       |
  193|  7.97k|  if (n == 0) {
  ------------------
  |  Branch (193:7): [True: 0, False: 7.97k]
  ------------------
  194|      0|    return 0;
  195|      0|  }
  196|       |
  197|  7.97k|  __asm__ volatile (
  198|  7.97k|      "	subq	%0,%0		\n"  // clear carry
  199|  7.97k|      "	jmp	1f		\n"
  200|  7.97k|      ".p2align 4			\n"
  201|  7.97k|      "1:"
  202|  7.97k|      "	movq	(%4,%2,8),%0	\n"
  203|  7.97k|      "	adcq	(%5,%2,8),%0	\n"
  204|  7.97k|      "	movq	%0,(%3,%2,8)	\n"
  205|  7.97k|      "	lea	1(%2),%2	\n"
  206|  7.97k|      "	dec	%1		\n"
  207|  7.97k|      "	jnz	1b		\n"
  208|  7.97k|      "	sbbq	%0,%0		\n"
  209|  7.97k|      : "=&r"(ret), "+c"(n), "+r"(i)
  210|  7.97k|      : "r"(rp), "r"(ap), "r"(bp)
  211|  7.97k|      : "cc", "memory");
  212|       |
  213|  7.97k|  return ret & 1;
  214|  7.97k|}
bn_sub_words:
  217|  8.00k|                      size_t n) {
  218|  8.00k|  BN_ULONG ret;
  219|  8.00k|  size_t i = 0;
  220|       |
  221|  8.00k|  if (n == 0) {
  ------------------
  |  Branch (221:7): [True: 4, False: 7.99k]
  ------------------
  222|      4|    return 0;
  223|      4|  }
  224|       |
  225|  7.99k|  __asm__ volatile (
  226|  7.99k|      "	subq	%0,%0		\n"  // clear borrow
  227|  7.99k|      "	jmp	1f		\n"
  228|  7.99k|      ".p2align 4			\n"
  229|  7.99k|      "1:"
  230|  7.99k|      "	movq	(%4,%2,8),%0	\n"
  231|  7.99k|      "	sbbq	(%5,%2,8),%0	\n"
  232|  7.99k|      "	movq	%0,(%3,%2,8)	\n"
  233|  7.99k|      "	lea	1(%2),%2	\n"
  234|  7.99k|      "	dec	%1		\n"
  235|  7.99k|      "	jnz	1b		\n"
  236|  7.99k|      "	sbbq	%0,%0		\n"
  237|  7.99k|      : "=&r"(ret), "+c"(n), "+r"(i)
  238|  7.99k|      : "r"(rp), "r"(ap), "r"(bp)
  239|  7.99k|      : "cc", "memory");
  240|       |
  241|  7.99k|  return ret & 1;
  242|  8.00k|}
bn_mul_comba8:
  287|     24|void bn_mul_comba8(BN_ULONG r[16], const BN_ULONG a[8], const BN_ULONG b[8]) {
  288|     24|  BN_ULONG c1, c2, c3;
  289|       |
  290|     24|  c1 = 0;
  291|     24|  c2 = 0;
  292|     24|  c3 = 0;
  293|     24|  mul_add_c(a[0], b[0], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  294|     24|  r[0] = c1;
  295|     24|  c1 = 0;
  296|     24|  mul_add_c(a[0], b[1], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  297|     24|  mul_add_c(a[1], b[0], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  298|     24|  r[1] = c2;
  299|     24|  c2 = 0;
  300|     24|  mul_add_c(a[2], b[0], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  301|     24|  mul_add_c(a[1], b[1], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  302|     24|  mul_add_c(a[0], b[2], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  303|     24|  r[2] = c3;
  304|     24|  c3 = 0;
  305|     24|  mul_add_c(a[0], b[3], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  306|     24|  mul_add_c(a[1], b[2], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  307|     24|  mul_add_c(a[2], b[1], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  308|     24|  mul_add_c(a[3], b[0], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  309|     24|  r[3] = c1;
  310|     24|  c1 = 0;
  311|     24|  mul_add_c(a[4], b[0], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  312|     24|  mul_add_c(a[3], b[1], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  313|     24|  mul_add_c(a[2], b[2], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  314|     24|  mul_add_c(a[1], b[3], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  315|     24|  mul_add_c(a[0], b[4], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  316|     24|  r[4] = c2;
  317|     24|  c2 = 0;
  318|     24|  mul_add_c(a[0], b[5], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  319|     24|  mul_add_c(a[1], b[4], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  320|     24|  mul_add_c(a[2], b[3], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  321|     24|  mul_add_c(a[3], b[2], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  322|     24|  mul_add_c(a[4], b[1], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  323|     24|  mul_add_c(a[5], b[0], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  324|     24|  r[5] = c3;
  325|     24|  c3 = 0;
  326|     24|  mul_add_c(a[6], b[0], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  327|     24|  mul_add_c(a[5], b[1], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  328|     24|  mul_add_c(a[4], b[2], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  329|     24|  mul_add_c(a[3], b[3], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  330|     24|  mul_add_c(a[2], b[4], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  331|     24|  mul_add_c(a[1], b[5], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  332|     24|  mul_add_c(a[0], b[6], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  333|     24|  r[6] = c1;
  334|     24|  c1 = 0;
  335|     24|  mul_add_c(a[0], b[7], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  336|     24|  mul_add_c(a[1], b[6], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  337|     24|  mul_add_c(a[2], b[5], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  338|     24|  mul_add_c(a[3], b[4], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  339|     24|  mul_add_c(a[4], b[3], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  340|     24|  mul_add_c(a[5], b[2], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  341|     24|  mul_add_c(a[6], b[1], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  342|     24|  mul_add_c(a[7], b[0], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  343|     24|  r[7] = c2;
  344|     24|  c2 = 0;
  345|     24|  mul_add_c(a[7], b[1], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  346|     24|  mul_add_c(a[6], b[2], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  347|     24|  mul_add_c(a[5], b[3], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  348|     24|  mul_add_c(a[4], b[4], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  349|     24|  mul_add_c(a[3], b[5], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  350|     24|  mul_add_c(a[2], b[6], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  351|     24|  mul_add_c(a[1], b[7], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  352|     24|  r[8] = c3;
  353|     24|  c3 = 0;
  354|     24|  mul_add_c(a[2], b[7], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  355|     24|  mul_add_c(a[3], b[6], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  356|     24|  mul_add_c(a[4], b[5], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  357|     24|  mul_add_c(a[5], b[4], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  358|     24|  mul_add_c(a[6], b[3], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  359|     24|  mul_add_c(a[7], b[2], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  360|     24|  r[9] = c1;
  361|     24|  c1 = 0;
  362|     24|  mul_add_c(a[7], b[3], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  363|     24|  mul_add_c(a[6], b[4], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  364|     24|  mul_add_c(a[5], b[5], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  365|     24|  mul_add_c(a[4], b[6], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  366|     24|  mul_add_c(a[3], b[7], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  367|     24|  r[10] = c2;
  368|     24|  c2 = 0;
  369|     24|  mul_add_c(a[4], b[7], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  370|     24|  mul_add_c(a[5], b[6], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  371|     24|  mul_add_c(a[6], b[5], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  372|     24|  mul_add_c(a[7], b[4], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  373|     24|  r[11] = c3;
  374|     24|  c3 = 0;
  375|     24|  mul_add_c(a[7], b[5], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  376|     24|  mul_add_c(a[6], b[6], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  377|     24|  mul_add_c(a[5], b[7], c1, c2, c3);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  378|     24|  r[12] = c1;
  379|     24|  c1 = 0;
  380|     24|  mul_add_c(a[6], b[7], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  381|     24|  mul_add_c(a[7], b[6], c2, c3, c1);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  382|     24|  r[13] = c2;
  383|     24|  c2 = 0;
  384|     24|  mul_add_c(a[7], b[7], c3, c1, c2);
  ------------------
  |  |  252|     24|  do {                                                               \
  |  |  253|     24|    BN_ULONG t1, t2;                                                 \
  |  |  254|     24|    __asm__("mulq %3" : "=a"(t1), "=d"(t2) : "a"(a), "m"(b) : "cc"); \
  |  |  255|     24|    __asm__("addq %3,%0; adcq %4,%1; adcq %5,%2"                     \
  |  |  256|     24|            : "+r"(c0), "+r"(c1), "+r"(c2)                           \
  |  |  257|     24|            : "r"(t1), "r"(t2), "g"(0)                               \
  |  |  258|     24|            : "cc");                                                 \
  |  |  259|     24|  } while (0)
  |  |  ------------------
  |  |  |  Branch (259:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  385|     24|  r[14] = c3;
  386|     24|  r[15] = c1;
  387|     24|}

BN_new:
   75|  45.4k|BIGNUM *BN_new(void) {
   76|  45.4k|  BIGNUM *bn = OPENSSL_malloc(sizeof(BIGNUM));
   77|       |
   78|  45.4k|  if (bn == NULL) {
  ------------------
  |  Branch (78:7): [True: 0, False: 45.4k]
  ------------------
   79|      0|    return NULL;
   80|      0|  }
   81|       |
   82|  45.4k|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   83|  45.4k|  bn->flags = BN_FLG_MALLOCED;
  ------------------
  |  | 1026|  45.4k|#define BN_FLG_MALLOCED 0x01
  ------------------
   84|       |
   85|  45.4k|  return bn;
   86|  45.4k|}
BN_init:
   90|     12|void BN_init(BIGNUM *bn) {
   91|     12|  OPENSSL_memset(bn, 0, sizeof(BIGNUM));
   92|     12|}
BN_free:
   94|   272k|void BN_free(BIGNUM *bn) {
   95|   272k|  if (bn == NULL) {
  ------------------
  |  Branch (95:7): [True: 227k, False: 45.4k]
  ------------------
   96|   227k|    return;
   97|   227k|  }
   98|       |
   99|  45.4k|  if ((bn->flags & BN_FLG_STATIC_DATA) == 0) {
  ------------------
  |  | 1027|  45.4k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (99:7): [True: 45.4k, False: 0]
  ------------------
  100|  45.4k|    OPENSSL_free(bn->d);
  101|  45.4k|  }
  102|       |
  103|  45.4k|  if (bn->flags & BN_FLG_MALLOCED) {
  ------------------
  |  | 1026|  45.4k|#define BN_FLG_MALLOCED 0x01
  ------------------
  |  Branch (103:7): [True: 45.4k, False: 12]
  ------------------
  104|  45.4k|    OPENSSL_free(bn);
  105|  45.4k|  } else {
  106|     12|    bn->d = NULL;
  107|     12|  }
  108|  45.4k|}
BN_copy:
  134|     10|BIGNUM *BN_copy(BIGNUM *dest, const BIGNUM *src) {
  135|     10|  if (src == dest) {
  ------------------
  |  Branch (135:7): [True: 2, False: 8]
  ------------------
  136|      2|    return dest;
  137|      2|  }
  138|       |
  139|      8|  if (!bn_wexpand(dest, src->width)) {
  ------------------
  |  Branch (139:7): [True: 0, False: 8]
  ------------------
  140|      0|    return NULL;
  141|      0|  }
  142|       |
  143|      8|  OPENSSL_memcpy(dest->d, src->d, sizeof(src->d[0]) * src->width);
  144|       |
  145|      8|  dest->width = src->width;
  146|      8|  dest->neg = src->neg;
  147|      8|  return dest;
  148|      8|}
BN_num_bits_word:
  170|  45.4k|unsigned BN_num_bits_word(BN_ULONG l) {
  171|       |  // |BN_num_bits| is often called on RSA prime factors. These have public bit
  172|       |  // lengths, but all bits beyond the high bit are secret, so count bits in
  173|       |  // constant time.
  174|  45.4k|  BN_ULONG x, mask;
  175|  45.4k|  int bits = (l != 0);
  176|       |
  177|  45.4k|#if BN_BITS2 > 32
  178|       |  // Look at the upper half of |x|. |x| is at most 64 bits long.
  179|  45.4k|  x = l >> 32;
  180|       |  // Set |mask| to all ones if |x| (the top 32 bits of |l|) is non-zero and all
  181|       |  // all zeros otherwise.
  182|  45.4k|  mask = 0u - x;
  183|  45.4k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  184|       |  // If |x| is non-zero, the lower half is included in the bit count in full,
  185|       |  // and we count the upper half. Otherwise, we count the lower half.
  186|  45.4k|  bits += 32 & mask;
  187|  45.4k|  l ^= (x ^ l) & mask;  // |l| is |x| if |mask| and remains |l| otherwise.
  188|  45.4k|#endif
  189|       |
  190|       |  // The remaining blocks are analogous iterations at lower powers of two.
  191|  45.4k|  x = l >> 16;
  192|  45.4k|  mask = 0u - x;
  193|  45.4k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  194|  45.4k|  bits += 16 & mask;
  195|  45.4k|  l ^= (x ^ l) & mask;
  196|       |
  197|  45.4k|  x = l >> 8;
  198|  45.4k|  mask = 0u - x;
  199|  45.4k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  200|  45.4k|  bits += 8 & mask;
  201|  45.4k|  l ^= (x ^ l) & mask;
  202|       |
  203|  45.4k|  x = l >> 4;
  204|  45.4k|  mask = 0u - x;
  205|  45.4k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  206|  45.4k|  bits += 4 & mask;
  207|  45.4k|  l ^= (x ^ l) & mask;
  208|       |
  209|  45.4k|  x = l >> 2;
  210|  45.4k|  mask = 0u - x;
  211|  45.4k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  212|  45.4k|  bits += 2 & mask;
  213|  45.4k|  l ^= (x ^ l) & mask;
  214|       |
  215|  45.4k|  x = l >> 1;
  216|  45.4k|  mask = 0u - x;
  217|  45.4k|  mask = (0u - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  218|  45.4k|  bits += 1 & mask;
  219|       |
  220|  45.4k|  return bits;
  221|  45.4k|}
BN_num_bits:
  223|  45.4k|unsigned BN_num_bits(const BIGNUM *bn) {
  224|  45.4k|  const int width = bn_minimal_width(bn);
  225|  45.4k|  if (width == 0) {
  ------------------
  |  Branch (225:7): [True: 0, False: 45.4k]
  ------------------
  226|      0|    return 0;
  227|      0|  }
  228|       |
  229|  45.4k|  return (width - 1) * BN_BITS2 + BN_num_bits_word(bn->d[width - 1]);
  ------------------
  |  |  151|  45.4k|#define BN_BITS2 64
  ------------------
  230|  45.4k|}
BN_zero:
  236|     38|void BN_zero(BIGNUM *bn) {
  237|     38|  bn->width = bn->neg = 0;
  238|     38|}
bn_fits_in_words:
  306|     10|int bn_fits_in_words(const BIGNUM *bn, size_t num) {
  307|       |  // All words beyond |num| must be zero.
  308|     10|  BN_ULONG mask = 0;
  309|    180|  for (size_t i = num; i < (size_t)bn->width; i++) {
  ------------------
  |  Branch (309:24): [True: 170, False: 10]
  ------------------
  310|    170|    mask |= bn->d[i];
  311|    170|  }
  312|     10|  return mask == 0;
  313|     10|}
BN_is_negative:
  335|  45.5k|int BN_is_negative(const BIGNUM *bn) {
  336|  45.5k|  return bn->neg != 0;
  337|  45.5k|}
bn_wexpand:
  347|  45.5k|int bn_wexpand(BIGNUM *bn, size_t words) {
  348|  45.5k|  BN_ULONG *a;
  349|       |
  350|  45.5k|  if (words <= (size_t)bn->dmax) {
  ------------------
  |  Branch (350:7): [True: 36, False: 45.5k]
  ------------------
  351|     36|    return 1;
  352|     36|  }
  353|       |
  354|  45.5k|  if (words > BN_MAX_WORDS) {
  ------------------
  |  |   73|  45.5k|#define BN_MAX_WORDS (INT_MAX / (4 * BN_BITS2))
  |  |  ------------------
  |  |  |  |  151|  45.5k|#define BN_BITS2 64
  |  |  ------------------
  ------------------
  |  Branch (354:7): [True: 0, False: 45.5k]
  ------------------
  355|      0|    OPENSSL_PUT_ERROR(BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  356|      0|    return 0;
  357|      0|  }
  358|       |
  359|  45.5k|  if (bn->flags & BN_FLG_STATIC_DATA) {
  ------------------
  |  | 1027|  45.5k|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  |  Branch (359:7): [True: 0, False: 45.5k]
  ------------------
  360|      0|    OPENSSL_PUT_ERROR(BN, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  361|      0|    return 0;
  362|      0|  }
  363|       |
  364|  45.5k|  a = OPENSSL_malloc(sizeof(BN_ULONG) * words);
  365|  45.5k|  if (a == NULL) {
  ------------------
  |  Branch (365:7): [True: 0, False: 45.5k]
  ------------------
  366|      0|    return 0;
  367|      0|  }
  368|       |
  369|  45.5k|  OPENSSL_memcpy(a, bn->d, sizeof(BN_ULONG) * bn->width);
  370|       |
  371|  45.5k|  OPENSSL_free(bn->d);
  372|  45.5k|  bn->d = a;
  373|  45.5k|  bn->dmax = (int)words;
  374|       |
  375|  45.5k|  return 1;
  376|  45.5k|}
bn_select_words:
  407|  7.97k|                     const BN_ULONG *b, size_t num) {
  408|   143k|  for (size_t i = 0; i < num; i++) {
  ------------------
  |  Branch (408:22): [True: 135k, False: 7.97k]
  ------------------
  409|   135k|    static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  410|   135k|                  "crypto_word_t is too small");
  411|   135k|    r[i] = constant_time_select_w(mask, a[i], b[i]);
  412|   135k|  }
  413|  7.97k|}
bn_minimal_width:
  415|  45.4k|int bn_minimal_width(const BIGNUM *bn) {
  416|  45.4k|  int ret = bn->width;
  417|  68.2k|  while (ret > 0 && bn->d[ret - 1] == 0) {
  ------------------
  |  Branch (417:10): [True: 68.2k, False: 0]
  |  Branch (417:21): [True: 22.7k, False: 45.4k]
  ------------------
  418|  22.7k|    ret--;
  419|  22.7k|  }
  420|  45.4k|  return ret;
  421|  45.4k|}
bcm.c:BN_value_one_do_init:
  159|      2|DEFINE_METHOD_FUNCTION(BIGNUM, BN_value_one) {
  160|      2|  static const BN_ULONG kOneLimbs[1] = { 1 };
  161|      2|  out->d = (BN_ULONG*) kOneLimbs;
  162|      2|  out->width = 1;
  163|      2|  out->dmax = 1;
  164|      2|  out->neg = 0;
  165|      2|  out->flags = BN_FLG_STATIC_DATA;
  ------------------
  |  | 1027|      2|#define BN_FLG_STATIC_DATA 0x02
  ------------------
  166|      2|}

bn_big_endian_to_words:
   65|  45.4k|                            size_t in_len) {
   66|   773k|  for (size_t i = 0; i < out_len; i++) {
  ------------------
  |  Branch (66:22): [True: 773k, False: 2]
  ------------------
   67|   773k|    if (in_len < sizeof(BN_ULONG)) {
  ------------------
  |  Branch (67:9): [True: 45.4k, False: 727k]
  ------------------
   68|       |      // Load the last partial word.
   69|  45.4k|      BN_ULONG word = 0;
   70|   136k|      for (size_t j = 0; j < in_len; j++) {
  ------------------
  |  Branch (70:26): [True: 90.9k, False: 45.4k]
  ------------------
   71|  90.9k|        word = (word << 8) | in[j];
   72|  90.9k|      }
   73|  45.4k|      in_len = 0;
   74|  45.4k|      out[i] = word;
   75|       |      // Fill the remainder with zeros.
   76|  45.4k|      OPENSSL_memset(out + i + 1, 0, (out_len - i - 1) * sizeof(BN_ULONG));
   77|  45.4k|      break;
   78|  45.4k|    }
   79|       |
   80|   727k|    in_len -= sizeof(BN_ULONG);
   81|   727k|    out[i] = CRYPTO_load_word_be(in + in_len);
   82|   727k|  }
   83|       |
   84|       |  // The caller should have sized the output to avoid truncation.
   85|  45.4k|  assert(in_len == 0);
   86|  45.4k|}
BN_bin2bn:
   88|  45.4k|BIGNUM *BN_bin2bn(const uint8_t *in, size_t len, BIGNUM *ret) {
   89|  45.4k|  BIGNUM *bn = NULL;
   90|  45.4k|  if (ret == NULL) {
  ------------------
  |  Branch (90:7): [True: 0, False: 45.4k]
  ------------------
   91|      0|    bn = BN_new();
   92|      0|    if (bn == NULL) {
  ------------------
  |  Branch (92:9): [True: 0, False: 0]
  ------------------
   93|      0|      return NULL;
   94|      0|    }
   95|      0|    ret = bn;
   96|      0|  }
   97|       |
   98|  45.4k|  if (len == 0) {
  ------------------
  |  Branch (98:7): [True: 0, False: 45.4k]
  ------------------
   99|      0|    ret->width = 0;
  100|      0|    return ret;
  101|      0|  }
  102|       |
  103|  45.4k|  size_t num_words = ((len - 1) / BN_BYTES) + 1;
  ------------------
  |  |  152|  45.4k|#define BN_BYTES 8
  ------------------
  104|  45.4k|  if (!bn_wexpand(ret, num_words)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 45.4k]
  ------------------
  105|      0|    BN_free(bn);
  106|      0|    return NULL;
  107|      0|  }
  108|       |
  109|       |  // |bn_wexpand| must check bounds on |num_words| to write it into
  110|       |  // |ret->dmax|.
  111|  45.4k|  assert(num_words <= INT_MAX);
  112|  45.4k|  ret->width = (int)num_words;
  113|  45.4k|  ret->neg = 0;
  114|       |
  115|  45.4k|  bn_big_endian_to_words(ret->d, ret->width, in, len);
  116|  45.4k|  return ret;
  117|  45.4k|}

BN_ucmp:
   99|  52.3k|int BN_ucmp(const BIGNUM *a, const BIGNUM *b) {
  100|  52.3k|  return bn_cmp_words_consttime(a->d, a->width, b->d, b->width);
  101|  52.3k|}
BN_cmp:
  103|  29.5k|int BN_cmp(const BIGNUM *a, const BIGNUM *b) {
  104|  29.5k|  if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (104:7): [True: 0, False: 29.5k]
  |  Branch (104:22): [True: 0, False: 29.5k]
  ------------------
  105|      0|    if (a != NULL) {
  ------------------
  |  Branch (105:9): [True: 0, False: 0]
  ------------------
  106|      0|      return -1;
  107|      0|    } else if (b != NULL) {
  ------------------
  |  Branch (107:16): [True: 0, False: 0]
  ------------------
  108|      0|      return 1;
  109|      0|    } else {
  110|      0|      return 0;
  111|      0|    }
  112|      0|  }
  113|       |
  114|       |  // We do not attempt to process the sign bit in constant time. Negative
  115|       |  // |BIGNUM|s should never occur in crypto, only calculators.
  116|  29.5k|  if (a->neg != b->neg) {
  ------------------
  |  Branch (116:7): [True: 0, False: 29.5k]
  ------------------
  117|      0|    if (a->neg) {
  ------------------
  |  Branch (117:9): [True: 0, False: 0]
  ------------------
  118|      0|      return -1;
  119|      0|    }
  120|      0|    return 1;
  121|      0|  }
  122|       |
  123|  29.5k|  int ret = BN_ucmp(a, b);
  124|  29.5k|  return a->neg ? -ret : ret;
  ------------------
  |  Branch (124:10): [True: 0, False: 29.5k]
  ------------------
  125|  29.5k|}
BN_abs_is_word:
  131|     10|int BN_abs_is_word(const BIGNUM *bn, BN_ULONG w) {
  132|     10|  if (bn->width == 0) {
  ------------------
  |  Branch (132:7): [True: 0, False: 10]
  ------------------
  133|      0|    return w == 0;
  134|      0|  }
  135|     10|  BN_ULONG mask = bn->d[0] ^ w;
  136|    170|  for (int i = 1; i < bn->width; i++) {
  ------------------
  |  Branch (136:19): [True: 160, False: 10]
  ------------------
  137|    160|    mask |= bn->d[i];
  138|    160|  }
  139|     10|  return mask == 0;
  140|     10|}
BN_is_zero:
  153|     10|int BN_is_zero(const BIGNUM *bn) {
  154|     10|  return bn_fits_in_words(bn, 0);
  155|     10|}
BN_is_one:
  157|     10|int BN_is_one(const BIGNUM *bn) {
  158|     10|  return bn->neg == 0 && BN_abs_is_word(bn, 1);
  ------------------
  |  Branch (158:10): [True: 10, False: 0]
  |  Branch (158:26): [True: 10, False: 0]
  ------------------
  159|     10|}
BN_is_odd:
  165|  45.4k|int BN_is_odd(const BIGNUM *bn) {
  166|  45.4k|  return bn->width > 0 && (bn->d[0] & 1) == 1;
  ------------------
  |  Branch (166:10): [True: 45.4k, False: 0]
  |  Branch (166:27): [True: 45.4k, False: 0]
  ------------------
  167|  45.4k|}
bcm.c:bn_cmp_words_consttime:
   68|  52.3k|                                  const BN_ULONG *b, size_t b_len) {
   69|  52.3k|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
   70|  52.3k|                "crypto_word_t is too small");
   71|  52.3k|  int ret = 0;
   72|       |  // Process the common words in little-endian order.
   73|  52.3k|  size_t min = a_len < b_len ? a_len : b_len;
  ------------------
  |  Branch (73:16): [True: 6, False: 52.3k]
  ------------------
   74|   577k|  for (size_t i = 0; i < min; i++) {
  ------------------
  |  Branch (74:22): [True: 525k, False: 52.3k]
  ------------------
   75|   525k|    crypto_word_t eq = constant_time_eq_w(a[i], b[i]);
   76|   525k|    crypto_word_t lt = constant_time_lt_w(a[i], b[i]);
   77|   525k|    ret =
   78|   525k|        constant_time_select_int(eq, ret, constant_time_select_int(lt, -1, 1));
   79|   525k|  }
   80|       |
   81|       |  // If |a| or |b| has non-zero words beyond |min|, they take precedence.
   82|  52.3k|  if (a_len < b_len) {
  ------------------
  |  Branch (82:7): [True: 6, False: 52.3k]
  ------------------
   83|      6|    crypto_word_t mask = 0;
   84|     72|    for (size_t i = a_len; i < b_len; i++) {
  ------------------
  |  Branch (84:28): [True: 66, False: 6]
  ------------------
   85|     66|      mask |= b[i];
   86|     66|    }
   87|      6|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, -1);
   88|  52.3k|  } else if (b_len < a_len) {
  ------------------
  |  Branch (88:14): [True: 22.7k, False: 29.5k]
  ------------------
   89|  22.7k|    crypto_word_t mask = 0;
   90|   750k|    for (size_t i = b_len; i < a_len; i++) {
  ------------------
  |  Branch (90:28): [True: 727k, False: 22.7k]
  ------------------
   91|   727k|      mask |= a[i];
   92|   727k|    }
   93|  22.7k|    ret = constant_time_select_int(constant_time_is_zero_w(mask), ret, 1);
   94|  22.7k|  }
   95|       |
   96|  52.3k|  return ret;
   97|  52.3k|}

BN_CTX_new:
  108|      2|BN_CTX *BN_CTX_new(void) {
  109|      2|  BN_CTX *ret = OPENSSL_malloc(sizeof(BN_CTX));
  110|      2|  if (!ret) {
  ------------------
  |  Branch (110:7): [True: 0, False: 2]
  ------------------
  111|      0|    return NULL;
  112|      0|  }
  113|       |
  114|       |  // Initialise the structure
  115|      2|  ret->bignums = NULL;
  116|      2|  BN_STACK_init(&ret->stack);
  117|      2|  ret->used = 0;
  118|      2|  ret->error = 0;
  119|      2|  ret->defer_error = 0;
  120|      2|  return ret;
  121|      2|}
BN_CTX_free:
  123|      2|void BN_CTX_free(BN_CTX *ctx) {
  124|      2|  if (ctx == NULL) {
  ------------------
  |  Branch (124:7): [True: 0, False: 2]
  ------------------
  125|      0|    return;
  126|      0|  }
  127|       |
  128|       |  // All |BN_CTX_start| calls must be matched with |BN_CTX_end|, otherwise the
  129|       |  // function may use more memory than expected, potentially without bound if
  130|       |  // done in a loop. Assert that all |BIGNUM|s have been released.
  131|      2|  assert(ctx->used == 0 || ctx->error);
  132|      2|  sk_BIGNUM_pop_free(ctx->bignums, BN_free);
  133|      2|  BN_STACK_cleanup(&ctx->stack);
  134|      2|  OPENSSL_free(ctx);
  135|      2|}
BN_CTX_start:
  137|     26|void BN_CTX_start(BN_CTX *ctx) {
  138|     26|  if (ctx->error) {
  ------------------
  |  Branch (138:7): [True: 0, False: 26]
  ------------------
  139|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  140|       |    // of |BN_CTX_end| calls to come. Do nothing.
  141|      0|    return;
  142|      0|  }
  143|       |
  144|     26|  if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (144:7): [True: 0, False: 26]
  ------------------
  145|      0|    ctx->error = 1;
  146|       |    // |BN_CTX_start| cannot fail, so defer the error to |BN_CTX_get|.
  147|      0|    ctx->defer_error = 1;
  148|      0|  }
  149|     26|}
BN_CTX_get:
  151|     38|BIGNUM *BN_CTX_get(BN_CTX *ctx) {
  152|       |  // Once any operation has failed, they all do.
  153|     38|  if (ctx->error) {
  ------------------
  |  Branch (153:7): [True: 0, False: 38]
  ------------------
  154|      0|    if (ctx->defer_error) {
  ------------------
  |  Branch (154:9): [True: 0, False: 0]
  ------------------
  155|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      0|      ctx->defer_error = 0;
  157|      0|    }
  158|      0|    return NULL;
  159|      0|  }
  160|       |
  161|     38|  if (ctx->bignums == NULL) {
  ------------------
  |  Branch (161:7): [True: 2, False: 36]
  ------------------
  162|      2|    ctx->bignums = sk_BIGNUM_new_null();
  163|      2|    if (ctx->bignums == NULL) {
  ------------------
  |  Branch (163:9): [True: 0, False: 2]
  ------------------
  164|      0|      ctx->error = 1;
  165|      0|      return NULL;
  166|      0|    }
  167|      2|  }
  168|       |
  169|     38|  if (ctx->used == sk_BIGNUM_num(ctx->bignums)) {
  ------------------
  |  Branch (169:7): [True: 8, False: 30]
  ------------------
  170|      8|    BIGNUM *bn = BN_new();
  171|      8|    if (bn == NULL || !sk_BIGNUM_push(ctx->bignums, bn)) {
  ------------------
  |  Branch (171:9): [True: 0, False: 8]
  |  Branch (171:23): [True: 0, False: 8]
  ------------------
  172|      0|      OPENSSL_PUT_ERROR(BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  173|      0|      BN_free(bn);
  174|      0|      ctx->error = 1;
  175|      0|      return NULL;
  176|      0|    }
  177|      8|  }
  178|       |
  179|     38|  BIGNUM *ret = sk_BIGNUM_value(ctx->bignums, ctx->used);
  180|     38|  BN_zero(ret);
  181|       |  // This is bounded by |sk_BIGNUM_num|, so it cannot overflow.
  182|     38|  ctx->used++;
  183|     38|  return ret;
  184|     38|}
BN_CTX_end:
  186|     26|void BN_CTX_end(BN_CTX *ctx) {
  187|     26|  if (ctx->error) {
  ------------------
  |  Branch (187:7): [True: 0, False: 26]
  ------------------
  188|       |    // Once an operation has failed, |ctx->stack| no longer matches the number
  189|       |    // of |BN_CTX_end| calls to come. Do nothing.
  190|      0|    return;
  191|      0|  }
  192|       |
  193|     26|  ctx->used = BN_STACK_pop(&ctx->stack);
  194|     26|}
bcm.c:BN_STACK_init:
  199|      2|static void BN_STACK_init(BN_STACK *st) {
  200|      2|  st->indexes = NULL;
  201|      2|  st->depth = st->size = 0;
  202|      2|}
bcm.c:BN_STACK_cleanup:
  204|      2|static void BN_STACK_cleanup(BN_STACK *st) {
  205|      2|  OPENSSL_free(st->indexes);
  206|      2|}
bcm.c:BN_STACK_push:
  208|     26|static int BN_STACK_push(BN_STACK *st, size_t idx) {
  209|     26|  if (st->depth == st->size) {
  ------------------
  |  Branch (209:7): [True: 2, False: 24]
  ------------------
  210|       |    // This function intentionally does not push to the error queue on error.
  211|       |    // Error-reporting is deferred to |BN_CTX_get|.
  212|      2|    size_t new_size = st->size != 0 ? st->size * 3 / 2 : BN_CTX_START_FRAMES;
  ------------------
  |  |   67|      2|#define BN_CTX_START_FRAMES 32
  ------------------
  |  Branch (212:23): [True: 0, False: 2]
  ------------------
  213|      2|    if (new_size <= st->size || new_size > ((size_t)-1) / sizeof(size_t)) {
  ------------------
  |  Branch (213:9): [True: 0, False: 2]
  |  Branch (213:33): [True: 0, False: 2]
  ------------------
  214|      0|      return 0;
  215|      0|    }
  216|      2|    size_t *new_indexes =
  217|      2|        OPENSSL_realloc(st->indexes, new_size * sizeof(size_t));
  218|      2|    if (new_indexes == NULL) {
  ------------------
  |  Branch (218:9): [True: 0, False: 2]
  ------------------
  219|      0|      return 0;
  220|      0|    }
  221|      2|    st->indexes = new_indexes;
  222|      2|    st->size = new_size;
  223|      2|  }
  224|       |
  225|     26|  st->indexes[st->depth] = idx;
  226|     26|  st->depth++;
  227|     26|  return 1;
  228|     26|}
bcm.c:BN_STACK_pop:
  230|     26|static size_t BN_STACK_pop(BN_STACK *st) {
  231|     26|  assert(st->depth > 0);
  232|     26|  st->depth--;
  233|     26|  return st->indexes[st->depth];
  234|     26|}

bn_reduce_once_in_place:
  434|  7.93k|                                 BN_ULONG *tmp, size_t num) {
  435|       |  // See |bn_reduce_once| for why this logic works.
  436|  7.93k|  carry -= bn_sub_words(tmp, r, m, num);
  437|  7.93k|  assert(carry == 0 || carry == (BN_ULONG)-1);
  438|  7.93k|  bn_select_words(r, carry, r /* tmp < 0 */, tmp /* tmp >= 0 */, num);
  439|  7.93k|  return carry;
  440|  7.93k|}
bn_div_consttime:
  459|     10|                     unsigned divisor_min_bits, BN_CTX *ctx) {
  460|     10|  if (BN_is_negative(numerator) || BN_is_negative(divisor)) {
  ------------------
  |  Branch (460:7): [True: 0, False: 10]
  |  Branch (460:36): [True: 0, False: 10]
  ------------------
  461|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  462|      0|    return 0;
  463|      0|  }
  464|     10|  if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (464:7): [True: 0, False: 10]
  ------------------
  465|      0|    OPENSSL_PUT_ERROR(BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  466|      0|    return 0;
  467|      0|  }
  468|       |
  469|       |  // This function implements long division in binary. It is not very efficient,
  470|       |  // but it is simple, easy to make constant-time, and performant enough for RSA
  471|       |  // key generation.
  472|       |
  473|     10|  int ret = 0;
  474|     10|  BN_CTX_start(ctx);
  475|     10|  BIGNUM *q = quotient, *r = remainder;
  476|     10|  if (quotient == NULL || quotient == numerator || quotient == divisor) {
  ------------------
  |  Branch (476:7): [True: 10, False: 0]
  |  Branch (476:27): [True: 0, False: 0]
  |  Branch (476:52): [True: 0, False: 0]
  ------------------
  477|     10|    q = BN_CTX_get(ctx);
  478|     10|  }
  479|     10|  if (remainder == NULL || remainder == numerator || remainder == divisor) {
  ------------------
  |  Branch (479:7): [True: 0, False: 10]
  |  Branch (479:28): [True: 8, False: 2]
  |  Branch (479:54): [True: 0, False: 2]
  ------------------
  480|      8|    r = BN_CTX_get(ctx);
  481|      8|  }
  482|     10|  BIGNUM *tmp = BN_CTX_get(ctx);
  483|     10|  if (q == NULL || r == NULL || tmp == NULL ||
  ------------------
  |  Branch (483:7): [True: 0, False: 10]
  |  Branch (483:20): [True: 0, False: 10]
  |  Branch (483:33): [True: 0, False: 10]
  ------------------
  484|     10|      !bn_wexpand(q, numerator->width) ||
  ------------------
  |  Branch (484:7): [True: 0, False: 10]
  ------------------
  485|     10|      !bn_wexpand(r, divisor->width) ||
  ------------------
  |  Branch (485:7): [True: 0, False: 10]
  ------------------
  486|     10|      !bn_wexpand(tmp, divisor->width)) {
  ------------------
  |  Branch (486:7): [True: 0, False: 10]
  ------------------
  487|      0|    goto err;
  488|      0|  }
  489|       |
  490|     10|  OPENSSL_memset(q->d, 0, numerator->width * sizeof(BN_ULONG));
  491|     10|  q->width = numerator->width;
  492|     10|  q->neg = 0;
  493|       |
  494|     10|  OPENSSL_memset(r->d, 0, divisor->width * sizeof(BN_ULONG));
  495|     10|  r->width = divisor->width;
  496|     10|  r->neg = 0;
  497|       |
  498|       |  // Incorporate |numerator| into |r|, one bit at a time, reducing after each
  499|       |  // step. We maintain the invariant that |0 <= r < divisor| and
  500|       |  // |q * divisor + r = n| where |n| is the portion of |numerator| incorporated
  501|       |  // so far.
  502|       |  //
  503|       |  // First, we short-circuit the loop: if we know |divisor| has at least
  504|       |  // |divisor_min_bits| bits, the top |divisor_min_bits - 1| can be incorporated
  505|       |  // without reductions. This significantly speeds up |RSA_check_key|. For
  506|       |  // simplicity, we round down to a whole number of words.
  507|     10|  assert(divisor_min_bits <= BN_num_bits(divisor));
  508|     10|  int initial_words = 0;
  509|     10|  if (divisor_min_bits > 0) {
  ------------------
  |  Branch (509:7): [True: 10, False: 0]
  ------------------
  510|     10|    initial_words = (divisor_min_bits - 1) / BN_BITS2;
  ------------------
  |  |  151|     10|#define BN_BITS2 64
  ------------------
  511|     10|    if (initial_words > numerator->width) {
  ------------------
  |  Branch (511:9): [True: 0, False: 10]
  ------------------
  512|      0|      initial_words = numerator->width;
  513|      0|    }
  514|     10|    OPENSSL_memcpy(r->d, numerator->d + numerator->width - initial_words,
  515|     10|                   initial_words * sizeof(BN_ULONG));
  516|     10|  }
  517|       |
  518|    134|  for (int i = numerator->width - initial_words - 1; i >= 0; i--) {
  ------------------
  |  Branch (518:54): [True: 124, False: 10]
  ------------------
  519|  8.06k|    for (int bit = BN_BITS2 - 1; bit >= 0; bit--) {
  ------------------
  |  |  151|    124|#define BN_BITS2 64
  ------------------
  |  Branch (519:34): [True: 7.93k, False: 124]
  ------------------
  520|       |      // Incorporate the next bit of the numerator, by computing
  521|       |      // r = 2*r or 2*r + 1. Note the result fits in one more word. We store the
  522|       |      // extra word in |carry|.
  523|  7.93k|      BN_ULONG carry = bn_add_words(r->d, r->d, r->d, divisor->width);
  524|  7.93k|      r->d[0] |= (numerator->d[i] >> bit) & 1;
  525|       |      // |r| was previously fully-reduced, so we know:
  526|       |      //      2*0 <= r <= 2*(divisor-1) + 1
  527|       |      //        0 <= r <= 2*divisor - 1 < 2*divisor.
  528|       |      // Thus |r| satisfies the preconditions for |bn_reduce_once_in_place|.
  529|  7.93k|      BN_ULONG subtracted = bn_reduce_once_in_place(r->d, carry, divisor->d,
  530|  7.93k|                                                    tmp->d, divisor->width);
  531|       |      // The corresponding bit of the quotient is set iff we needed to subtract.
  532|  7.93k|      q->d[i] |= (~subtracted & 1) << bit;
  533|  7.93k|    }
  534|    124|  }
  535|       |
  536|     10|  if ((quotient != NULL && !BN_copy(quotient, q)) ||
  ------------------
  |  Branch (536:8): [True: 0, False: 10]
  |  Branch (536:28): [True: 0, False: 0]
  ------------------
  537|     10|      (remainder != NULL && !BN_copy(remainder, r))) {
  ------------------
  |  Branch (537:8): [True: 10, False: 0]
  |  Branch (537:29): [True: 0, False: 10]
  ------------------
  538|      0|    goto err;
  539|      0|  }
  540|       |
  541|     10|  ret = 1;
  542|       |
  543|     10|err:
  544|     10|  BN_CTX_end(ctx);
  545|     10|  return ret;
  546|     10|}

BN_MONT_CTX_free:
  138|  68.2k|void BN_MONT_CTX_free(BN_MONT_CTX *mont) {
  139|  68.2k|  if (mont == NULL) {
  ------------------
  |  Branch (139:7): [True: 68.2k, False: 0]
  ------------------
  140|  68.2k|    return;
  141|  68.2k|  }
  142|       |
  143|      0|  BN_free(&mont->RR);
  144|      0|  BN_free(&mont->N);
  145|      0|  OPENSSL_free(mont);
  146|      0|}

bn_mul_consttime:
  525|     10|int bn_mul_consttime(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx) {
  526|       |  // Prevent negative zeros.
  527|     10|  if (a->neg || b->neg) {
  ------------------
  |  Branch (527:7): [True: 0, False: 10]
  |  Branch (527:17): [True: 0, False: 10]
  ------------------
  528|      0|    OPENSSL_PUT_ERROR(BN, BN_R_NEGATIVE_NUMBER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  529|      0|    return 0;
  530|      0|  }
  531|       |
  532|     10|  return bn_mul_impl(r, a, b, ctx);
  533|     10|}
bcm.c:bn_abs_sub_part_words:
  172|     24|                                      BN_ULONG *tmp) {
  173|     24|  BN_ULONG borrow = bn_sub_part_words(tmp, a, b, cl, dl);
  174|     24|  bn_sub_part_words(r, b, a, cl, -dl);
  175|     24|  int r_len = cl + (dl < 0 ? -dl : dl);
  ------------------
  |  Branch (175:21): [True: 4, False: 20]
  ------------------
  176|     24|  borrow = 0 - borrow;
  177|     24|  bn_select_words(r, borrow, r /* tmp < 0 */, tmp /* tmp >= 0 */, r_len);
  178|     24|  return borrow;
  179|     24|}
bcm.c:bn_sub_part_words:
  130|     48|                                  const BN_ULONG *b, int cl, int dl) {
  131|     48|  assert(cl >= 0);
  132|     48|  BN_ULONG borrow = bn_sub_words(r, a, b, cl);
  133|     48|  if (dl == 0) {
  ------------------
  |  Branch (133:7): [True: 32, False: 16]
  ------------------
  134|     32|    return borrow;
  135|     32|  }
  136|       |
  137|     16|  r += cl;
  138|     16|  a += cl;
  139|     16|  b += cl;
  140|       |
  141|     16|  if (dl < 0) {
  ------------------
  |  Branch (141:7): [True: 8, False: 8]
  ------------------
  142|       |    // |a| is shorter than |b|. Complete the subtraction as if the excess words
  143|       |    // in |a| were zeros.
  144|      8|    dl = -dl;
  145|    130|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (145:21): [True: 122, False: 8]
  ------------------
  146|    122|      r[i] = 0u - b[i] - borrow;
  147|    122|      borrow |= r[i] != 0;
  148|    122|    }
  149|      8|  } else {
  150|       |    // |b| is shorter than |a|. Complete the subtraction as if the excess words
  151|       |    // in |b| were zeros.
  152|    130|    for (int i = 0; i < dl; i++) {
  ------------------
  |  Branch (152:21): [True: 122, False: 8]
  ------------------
  153|       |      // |r| and |a| may alias, so use a temporary.
  154|    122|      BN_ULONG tmp = a[i];
  155|    122|      r[i] = a[i] - borrow;
  156|    122|      borrow = tmp < r[i];
  157|    122|    }
  158|      8|  }
  159|       |
  160|     16|  return borrow;
  161|     48|}
bcm.c:bn_mul_impl:
  420|     10|                       BN_CTX *ctx) {
  421|     10|  int al = a->width;
  422|     10|  int bl = b->width;
  423|     10|  if (al == 0 || bl == 0) {
  ------------------
  |  Branch (423:7): [True: 0, False: 10]
  |  Branch (423:18): [True: 0, False: 10]
  ------------------
  424|      0|    BN_zero(r);
  425|      0|    return 1;
  426|      0|  }
  427|       |
  428|     10|  int ret = 0;
  429|     10|  BIGNUM *rr;
  430|     10|  BN_CTX_start(ctx);
  431|     10|  if (r == a || r == b) {
  ------------------
  |  Branch (431:7): [True: 0, False: 10]
  |  Branch (431:17): [True: 0, False: 10]
  ------------------
  432|      0|    rr = BN_CTX_get(ctx);
  433|      0|    if (rr == NULL) {
  ------------------
  |  Branch (433:9): [True: 0, False: 0]
  ------------------
  434|      0|      goto err;
  435|      0|    }
  436|     10|  } else {
  437|     10|    rr = r;
  438|     10|  }
  439|     10|  rr->neg = a->neg ^ b->neg;
  440|       |
  441|     10|  int i = al - bl;
  442|     10|  if (i == 0) {
  ------------------
  |  Branch (442:7): [True: 2, False: 8]
  ------------------
  443|      2|    if (al == 8) {
  ------------------
  |  Branch (443:9): [True: 0, False: 2]
  ------------------
  444|      0|      if (!bn_wexpand(rr, 16)) {
  ------------------
  |  Branch (444:11): [True: 0, False: 0]
  ------------------
  445|      0|        goto err;
  446|      0|      }
  447|      0|      rr->width = 16;
  448|      0|      bn_mul_comba8(rr->d, a->d, b->d);
  449|      0|      goto end;
  450|      0|    }
  451|      2|  }
  452|       |
  453|     10|  int top = al + bl;
  454|     10|  static const int kMulNormalSize = 16;
  455|     10|  if (al >= kMulNormalSize && bl >= kMulNormalSize) {
  ------------------
  |  Branch (455:7): [True: 6, False: 4]
  |  Branch (455:31): [True: 4, False: 2]
  ------------------
  456|      4|    if (-1 <= i && i <= 1) {
  ------------------
  |  Branch (456:9): [True: 4, False: 0]
  |  Branch (456:20): [True: 4, False: 0]
  ------------------
  457|       |      // Find the largest power of two less than or equal to the larger length.
  458|      4|      int j;
  459|      4|      if (i >= 0) {
  ------------------
  |  Branch (459:11): [True: 4, False: 0]
  ------------------
  460|      4|        j = BN_num_bits_word((BN_ULONG)al);
  461|      4|      } else {
  462|      0|        j = BN_num_bits_word((BN_ULONG)bl);
  463|      0|      }
  464|      4|      j = 1 << (j - 1);
  465|      4|      assert(j <= al || j <= bl);
  466|      4|      BIGNUM *t = BN_CTX_get(ctx);
  467|      4|      if (t == NULL) {
  ------------------
  |  Branch (467:11): [True: 0, False: 4]
  ------------------
  468|      0|        goto err;
  469|      0|      }
  470|      4|      if (al > j || bl > j) {
  ------------------
  |  Branch (470:11): [True: 4, False: 0]
  |  Branch (470:21): [True: 0, False: 0]
  ------------------
  471|       |        // We know |al| and |bl| are at most one from each other, so if al > j,
  472|       |        // bl >= j, and vice versa. Thus we can use |bn_mul_part_recursive|.
  473|       |        //
  474|       |        // TODO(davidben): This codepath is almost unused in standard
  475|       |        // algorithms. Is this optimization necessary? See notes in
  476|       |        // https://boringssl-review.googlesource.com/q/I0bd604e2cd6a75c266f64476c23a730ca1721ea6
  477|      4|        assert(al >= j && bl >= j);
  478|      4|        if (!bn_wexpand(t, j * 8) ||
  ------------------
  |  Branch (478:13): [True: 0, False: 4]
  ------------------
  479|      4|            !bn_wexpand(rr, j * 4)) {
  ------------------
  |  Branch (479:13): [True: 0, False: 4]
  ------------------
  480|      0|          goto err;
  481|      0|        }
  482|      4|        bn_mul_part_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  483|      4|      } else {
  484|       |        // al <= j && bl <= j. Additionally, we know j <= al or j <= bl, so one
  485|       |        // of al - j or bl - j is zero. The other, by the bound on |i| above, is
  486|       |        // zero or -1. Thus, we can use |bn_mul_recursive|.
  487|      0|        if (!bn_wexpand(t, j * 4) ||
  ------------------
  |  Branch (487:13): [True: 0, False: 0]
  ------------------
  488|      0|            !bn_wexpand(rr, j * 2)) {
  ------------------
  |  Branch (488:13): [True: 0, False: 0]
  ------------------
  489|      0|          goto err;
  490|      0|        }
  491|      0|        bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  492|      0|      }
  493|      4|      rr->width = top;
  494|      4|      goto end;
  495|      4|    }
  496|      4|  }
  497|       |
  498|      6|  if (!bn_wexpand(rr, top)) {
  ------------------
  |  Branch (498:7): [True: 0, False: 6]
  ------------------
  499|      0|    goto err;
  500|      0|  }
  501|      6|  rr->width = top;
  502|      6|  bn_mul_normal(rr->d, a->d, al, b->d, bl);
  503|       |
  504|     10|end:
  505|     10|  if (r != rr && !BN_copy(r, rr)) {
  ------------------
  |  Branch (505:7): [True: 0, False: 10]
  |  Branch (505:18): [True: 0, False: 0]
  ------------------
  506|      0|    goto err;
  507|      0|  }
  508|     10|  ret = 1;
  509|       |
  510|     10|err:
  511|     10|  BN_CTX_end(ctx);
  512|     10|  return ret;
  513|     10|}
bcm.c:bn_mul_part_recursive:
  312|      4|                                  BN_ULONG *t) {
  313|       |  // |n| is a power of two.
  314|      4|  assert(n != 0 && (n & (n - 1)) == 0);
  315|       |  // Check |tna| and |tnb| are in range.
  316|      4|  assert(0 <= tna && tna < n);
  317|      4|  assert(0 <= tnb && tnb < n);
  318|      4|  assert(-1 <= tna - tnb && tna - tnb <= 1);
  319|       |
  320|      4|  int n2 = n * 2;
  321|      4|  if (n < 8) {
  ------------------
  |  Branch (321:7): [True: 0, False: 4]
  ------------------
  322|      0|    bn_mul_normal(r, a, n + tna, b, n + tnb);
  323|      0|    OPENSSL_memset(r + n2 + tna + tnb, 0, n2 - tna - tnb);
  324|      0|    return;
  325|      0|  }
  326|       |
  327|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|. |a1|
  328|       |  // and |b1| have size |tna| and |tnb|, respectively.
  329|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  330|       |  // for recursive calls.
  331|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  332|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  333|       |  //
  334|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  335|       |
  336|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  337|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  338|       |  // themselves store the absolute value.
  339|      4|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  340|      4|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  341|       |
  342|       |  // Compute:
  343|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  344|       |  // r0,r1 = a0 * b0
  345|       |  // r2,r3 = a1 * b1
  346|      4|  if (n == 8) {
  ------------------
  |  Branch (346:7): [True: 0, False: 4]
  ------------------
  347|      0|    bn_mul_comba8(&t[n2], t, &t[n]);
  348|      0|    bn_mul_comba8(r, a, b);
  349|       |
  350|      0|    bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  351|       |    // |bn_mul_normal| only writes |tna| + |tna| words. Zero the rest.
  352|      0|    OPENSSL_memset(&r[n2 + tna + tnb], 0, sizeof(BN_ULONG) * (n2 - tna - tnb));
  353|      4|  } else {
  354|      4|    BN_ULONG *p = &t[n2 * 2];
  355|      4|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  356|      4|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  357|       |
  358|      4|    OPENSSL_memset(&r[n2], 0, sizeof(BN_ULONG) * n2);
  359|      4|    if (tna < BN_MUL_RECURSIVE_SIZE_NORMAL &&
  ------------------
  |  |   70|      8|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (359:9): [True: 4, False: 0]
  ------------------
  360|      4|        tnb < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|      4|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (360:9): [True: 4, False: 0]
  ------------------
  361|      4|      bn_mul_normal(&r[n2], &a[n], tna, &b[n], tnb);
  362|      4|    } else {
  363|      0|      int i = n;
  364|      0|      for (;;) {
  365|      0|        i /= 2;
  366|      0|        if (i < tna || i < tnb) {
  ------------------
  |  Branch (366:13): [True: 0, False: 0]
  |  Branch (366:24): [True: 0, False: 0]
  ------------------
  367|       |          // E.g., n == 16, i == 8 and tna == 11. |tna| and |tnb| are within one
  368|       |          // of each other, so if |tna| is larger and tna > i, then we know
  369|       |          // tnb >= i, and this call is valid.
  370|      0|          bn_mul_part_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  371|      0|          break;
  372|      0|        }
  373|      0|        if (i == tna || i == tnb) {
  ------------------
  |  Branch (373:13): [True: 0, False: 0]
  |  Branch (373:25): [True: 0, False: 0]
  ------------------
  374|       |          // If there is only a bottom half to the number, just do it. We know
  375|       |          // the larger of |tna - i| and |tnb - i| is zero. The other is zero or
  376|       |          // -1 by because of |tna| and |tnb| differ by at most one.
  377|      0|          bn_mul_recursive(&r[n2], &a[n], &b[n], i, tna - i, tnb - i, p);
  378|      0|          break;
  379|      0|        }
  380|       |
  381|       |        // This loop will eventually terminate when |i| falls below
  382|       |        // |BN_MUL_RECURSIVE_SIZE_NORMAL| because we know one of |tna| and |tnb|
  383|       |        // exceeds that.
  384|      0|      }
  385|      0|    }
  386|      4|  }
  387|       |
  388|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  389|      4|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  390|       |
  391|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  392|       |  // The second term is stored as the absolute value, so we do this with a
  393|       |  // constant-time select.
  394|      4|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  395|      4|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  396|      4|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  397|      4|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  398|      4|                "crypto_word_t is too small");
  399|      4|  c = constant_time_select_w(neg, c_neg, c_pos);
  400|       |
  401|       |  // We now have our three components. Add them together.
  402|       |  // r1,r2,c = r1,r2 + t2,t3,c
  403|      4|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  404|       |
  405|       |  // Propagate the carry bit to the end.
  406|     68|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (406:24): [True: 64, False: 4]
  ------------------
  407|     64|    BN_ULONG old = r[i];
  408|     64|    r[i] = old + c;
  409|     64|    c = r[i] < old;
  410|     64|  }
  411|       |
  412|       |  // The product should fit without carries.
  413|      4|  assert(c == 0);
  414|      4|}
bcm.c:bn_mul_recursive:
  211|      8|                             int n2, int dna, int dnb, BN_ULONG *t) {
  212|       |  // |n2| is a power of two.
  213|      8|  assert(n2 != 0 && (n2 & (n2 - 1)) == 0);
  214|       |  // Check |dna| and |dnb| are in range.
  215|      8|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dna && dna <= 0);
  216|      8|  assert(-BN_MUL_RECURSIVE_SIZE_NORMAL/2 <= dnb && dnb <= 0);
  217|       |
  218|       |  // Only call bn_mul_comba 8 if n2 == 8 and the
  219|       |  // two arrays are complete [steve]
  220|      8|  if (n2 == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (220:7): [True: 0, False: 8]
  |  Branch (220:18): [True: 0, False: 0]
  |  Branch (220:30): [True: 0, False: 0]
  ------------------
  221|      0|    bn_mul_comba8(r, a, b);
  222|      0|    return;
  223|      0|  }
  224|       |
  225|       |  // Else do normal multiply
  226|      8|  if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |   70|      8|#define BN_MUL_RECURSIVE_SIZE_NORMAL 16
  ------------------
  |  Branch (226:7): [True: 0, False: 8]
  ------------------
  227|      0|    bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
  228|      0|    if (dna + dnb < 0) {
  ------------------
  |  Branch (228:9): [True: 0, False: 0]
  ------------------
  229|      0|      OPENSSL_memset(&r[2 * n2 + dna + dnb], 0,
  230|      0|                     sizeof(BN_ULONG) * -(dna + dnb));
  231|      0|    }
  232|      0|    return;
  233|      0|  }
  234|       |
  235|       |  // Split |a| and |b| into a0,a1 and b0,b1, where a0 and b0 have size |n|.
  236|       |  // Split |t| into t0,t1,t2,t3, each of size |n|, with the remaining 4*|n| used
  237|       |  // for recursive calls.
  238|       |  // Split |r| into r0,r1,r2,r3. We must contribute a0*b0 to r0,r1, a0*a1+b0*b1
  239|       |  // to r1,r2, and a1*b1 to r2,r3. The middle term we will compute as:
  240|       |  //
  241|       |  //   a0*a1 + b0*b1 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0
  242|       |  //
  243|       |  // Note that we know |n| >= |BN_MUL_RECURSIVE_SIZE_NORMAL|/2 above, so
  244|       |  // |tna| and |tnb| are non-negative.
  245|      8|  int n = n2 / 2, tna = n + dna, tnb = n + dnb;
  246|       |
  247|       |  // t0 = a0 - a1 and t1 = b1 - b0. The result will be multiplied, so we XOR
  248|       |  // their sign masks, giving the sign of (a0 - a1)*(b1 - b0). t0 and t1
  249|       |  // themselves store the absolute value.
  250|      8|  BN_ULONG neg = bn_abs_sub_part_words(t, a, &a[n], tna, n - tna, &t[n2]);
  251|      8|  neg ^= bn_abs_sub_part_words(&t[n], &b[n], b, tnb, tnb - n, &t[n2]);
  252|       |
  253|       |  // Compute:
  254|       |  // t2,t3 = t0 * t1 = |(a0 - a1)*(b1 - b0)|
  255|       |  // r0,r1 = a0 * b0
  256|       |  // r2,r3 = a1 * b1
  257|      8|  if (n == 4 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (257:7): [True: 0, False: 8]
  |  Branch (257:17): [True: 0, False: 0]
  |  Branch (257:29): [True: 0, False: 0]
  ------------------
  258|      0|    bn_mul_comba4(&t[n2], t, &t[n]);
  259|       |
  260|      0|    bn_mul_comba4(r, a, b);
  261|      0|    bn_mul_comba4(&r[n2], &a[n], &b[n]);
  262|      8|  } else if (n == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (262:14): [True: 8, False: 0]
  |  Branch (262:24): [True: 8, False: 0]
  |  Branch (262:36): [True: 8, False: 0]
  ------------------
  263|      8|    bn_mul_comba8(&t[n2], t, &t[n]);
  264|       |
  265|      8|    bn_mul_comba8(r, a, b);
  266|      8|    bn_mul_comba8(&r[n2], &a[n], &b[n]);
  267|      8|  } else {
  268|      0|    BN_ULONG *p = &t[n2 * 2];
  269|      0|    bn_mul_recursive(&t[n2], t, &t[n], n, 0, 0, p);
  270|      0|    bn_mul_recursive(r, a, b, n, 0, 0, p);
  271|      0|    bn_mul_recursive(&r[n2], &a[n], &b[n], n, dna, dnb, p);
  272|      0|  }
  273|       |
  274|       |  // t0,t1,c = r0,r1 + r2,r3 = a0*b0 + a1*b1
  275|      8|  BN_ULONG c = bn_add_words(t, r, &r[n2], n2);
  276|       |
  277|       |  // t2,t3,c = t0,t1,c + neg*t2,t3 = (a0 - a1)*(b1 - b0) + a1*b1 + a0*b0.
  278|       |  // The second term is stored as the absolute value, so we do this with a
  279|       |  // constant-time select.
  280|      8|  BN_ULONG c_neg = c - bn_sub_words(&t[n2 * 2], t, &t[n2], n2);
  281|      8|  BN_ULONG c_pos = c + bn_add_words(&t[n2], t, &t[n2], n2);
  282|      8|  bn_select_words(&t[n2], neg, &t[n2 * 2], &t[n2], n2);
  283|      8|  static_assert(sizeof(BN_ULONG) <= sizeof(crypto_word_t),
  284|      8|                "crypto_word_t is too small");
  285|      8|  c = constant_time_select_w(neg, c_neg, c_pos);
  286|       |
  287|       |  // We now have our three components. Add them together.
  288|       |  // r1,r2,c = r1,r2 + t2,t3,c
  289|      8|  c += bn_add_words(&r[n], &r[n], &t[n2], n2);
  290|       |
  291|       |  // Propagate the carry bit to the end.
  292|     72|  for (int i = n + n2; i < n2 + n2; i++) {
  ------------------
  |  Branch (292:24): [True: 64, False: 8]
  ------------------
  293|     64|    BN_ULONG old = r[i];
  294|     64|    r[i] = old + c;
  295|     64|    c = r[i] < old;
  296|     64|  }
  297|       |
  298|       |  // The product should fit without carries.
  299|      8|  assert(c == 0);
  300|      8|}
bcm.c:bn_mul_normal:
   82|     10|                          const BN_ULONG *b, size_t nb) {
   83|     10|  if (na < nb) {
  ------------------
  |  Branch (83:7): [True: 4, False: 6]
  ------------------
   84|      4|    size_t itmp = na;
   85|      4|    na = nb;
   86|      4|    nb = itmp;
   87|      4|    const BN_ULONG *ltmp = a;
   88|      4|    a = b;
   89|      4|    b = ltmp;
   90|      4|  }
   91|     10|  BN_ULONG *rr = &(r[na]);
   92|     10|  if (nb == 0) {
  ------------------
  |  Branch (92:7): [True: 2, False: 8]
  ------------------
   93|      2|    OPENSSL_memset(r, 0, na * sizeof(BN_ULONG));
   94|      2|    return;
   95|      2|  }
   96|      8|  rr[0] = bn_mul_words(r, a, na, b[0]);
   97|       |
   98|      8|  for (;;) {
   99|      8|    if (--nb == 0) {
  ------------------
  |  Branch (99:9): [True: 8, False: 0]
  ------------------
  100|      8|      return;
  101|      8|    }
  102|      0|    rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  103|      0|    if (--nb == 0) {
  ------------------
  |  Branch (103:9): [True: 0, False: 0]
  ------------------
  104|      0|      return;
  105|      0|    }
  106|      0|    rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  107|      0|    if (--nb == 0) {
  ------------------
  |  Branch (107:9): [True: 0, False: 0]
  ------------------
  108|      0|      return;
  109|      0|    }
  110|      0|    rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  111|      0|    if (--nb == 0) {
  ------------------
  |  Branch (111:9): [True: 0, False: 0]
  ------------------
  112|      0|      return;
  113|      0|    }
  114|      0|    rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  115|      0|    rr += 4;
  116|      0|    r += 4;
  117|      0|    b += 4;
  118|      0|  }
  119|      8|}

EVP_AEAD_CTX_zero:
   36|  14.4k|void EVP_AEAD_CTX_zero(EVP_AEAD_CTX *ctx) {
   37|  14.4k|  OPENSSL_memset(ctx, 0, sizeof(EVP_AEAD_CTX));
   38|  14.4k|}
EVP_AEAD_CTX_cleanup:
   99|  14.4k|void EVP_AEAD_CTX_cleanup(EVP_AEAD_CTX *ctx) {
  100|  14.4k|  if (ctx->aead == NULL) {
  ------------------
  |  Branch (100:7): [True: 14.4k, False: 0]
  ------------------
  101|  14.4k|    return;
  102|  14.4k|  }
  103|      0|  ctx->aead->cleanup(ctx);
  104|      0|  ctx->aead = NULL;
  105|      0|}

aes_ctr_set_key:
  292|  9.66k|                         size_t key_bytes) {
  293|       |  // This function assumes the key length was previously validated.
  294|  9.66k|  assert(key_bytes == 128 / 8 || key_bytes == 192 / 8 || key_bytes == 256 / 8);
  295|  9.66k|  if (hwaes_capable()) {
  ------------------
  |  Branch (295:7): [True: 9.66k, False: 0]
  ------------------
  296|  9.66k|    aes_hw_set_encrypt_key(key, (int)key_bytes * 8, aes_key);
  297|  9.66k|    if (gcm_key != NULL) {
  ------------------
  |  Branch (297:9): [True: 0, False: 9.66k]
  ------------------
  298|      0|      CRYPTO_gcm128_init_key(gcm_key, aes_key, aes_hw_encrypt, 1);
  299|      0|    }
  300|  9.66k|    if (out_block) {
  ------------------
  |  Branch (300:9): [True: 9.66k, False: 0]
  ------------------
  301|  9.66k|      *out_block = aes_hw_encrypt;
  302|  9.66k|    }
  303|  9.66k|    return aes_hw_ctr32_encrypt_blocks;
  304|  9.66k|  }
  305|       |
  306|      0|  if (vpaes_capable()) {
  ------------------
  |  Branch (306:7): [True: 0, False: 0]
  ------------------
  307|      0|    vpaes_set_encrypt_key(key, (int)key_bytes * 8, aes_key);
  308|      0|    if (out_block) {
  ------------------
  |  Branch (308:9): [True: 0, False: 0]
  ------------------
  309|      0|      *out_block = vpaes_encrypt;
  310|      0|    }
  311|      0|    if (gcm_key != NULL) {
  ------------------
  |  Branch (311:9): [True: 0, False: 0]
  ------------------
  312|      0|      CRYPTO_gcm128_init_key(gcm_key, aes_key, vpaes_encrypt, 0);
  313|      0|    }
  314|       |#if defined(BSAES)
  315|       |    assert(bsaes_capable());
  316|       |    return vpaes_ctr32_encrypt_blocks_with_bsaes;
  317|       |#elif defined(VPAES_CTR32)
  318|      0|    return vpaes_ctr32_encrypt_blocks;
  319|       |#else
  320|       |    return NULL;
  321|       |#endif
  322|      0|  }
  323|       |
  324|      0|  aes_nohw_set_encrypt_key(key, (int)key_bytes * 8, aes_key);
  325|      0|  if (gcm_key != NULL) {
  ------------------
  |  Branch (325:7): [True: 0, False: 0]
  ------------------
  326|      0|    CRYPTO_gcm128_init_key(gcm_key, aes_key, aes_nohw_encrypt, 0);
  327|      0|  }
  328|      0|  if (out_block) {
  ------------------
  |  Branch (328:7): [True: 0, False: 0]
  ------------------
  329|      0|    *out_block = aes_nohw_encrypt;
  330|      0|  }
  331|      0|  return aes_nohw_ctr32_encrypt_blocks;
  332|      0|}
EVP_has_aes_hardware:
 1466|  32.2k|int EVP_has_aes_hardware(void) {
 1467|  32.2k|#if defined(OPENSSL_X86) || defined(OPENSSL_X86_64)
 1468|  32.2k|  return hwaes_capable() && crypto_gcm_clmul_enabled();
  ------------------
  |  Branch (1468:10): [True: 32.2k, False: 0]
  |  Branch (1468:29): [True: 32.2k, False: 0]
  ------------------
 1469|       |#elif defined(OPENSSL_ARM) || defined(OPENSSL_AARCH64)
 1470|       |  return hwaes_capable() && CRYPTO_is_ARMv8_PMULL_capable();
 1471|       |#else
 1472|       |  return 0;
 1473|       |#endif
 1474|  32.2k|}

BN_value_one:
   56|      4|  accessor_decorations type *name(void) {                                     \
   57|      4|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|      4|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|      4|     * cast is needed. */                                                     \
   60|      4|    return (const type *)name##_storage_bss_get();                            \
   61|      4|  }                                                                           \
RSA_default_method:
   56|  22.7k|  accessor_decorations type *name(void) {                                     \
   57|  22.7k|    CRYPTO_once(name##_once_bss_get(), name##_init);                          \
   58|  22.7k|    /* See http://c-faq.com/ansi/constmismatch.html for why the following     \
   59|  22.7k|     * cast is needed. */                                                     \
   60|  22.7k|    return (const type *)name##_storage_bss_get();                            \
   61|  22.7k|  }                                                                           \
bcm.c:BN_value_one_once_bss_get:
   42|      4|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:BN_value_one_init:
   55|      2|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:BN_value_one_storage_bss_get:
   39|      6|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_fork_detect_once_bss_get:
   42|  4.83k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:g_fork_detect_addr_bss_get:
   39|  4.83k|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_force_madv_wipeonfork_bss_get:
   39|      1|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_fork_generation_bss_get:
   39|  4.83k|  static type *name##_bss_get(void) { return &name; }
bcm.c:g_rsa_ex_data_class_bss_get:
   48|  22.7k|  static CRYPTO_EX_DATA_CLASS *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_once_bss_get:
   42|  22.7k|  static CRYPTO_once_t *name##_bss_get(void) { return &name; }
bcm.c:RSA_default_method_init:
   55|      2|  static void name##_init(void) { name##_do_init(name##_storage_bss_get()); } \
bcm.c:RSA_default_method_storage_bss_get:
   39|  22.7k|  static type *name##_bss_get(void) { return &name; }

EVP_MD_CTX_init:
   80|  28.9k|void EVP_MD_CTX_init(EVP_MD_CTX *ctx) {
   81|  28.9k|  OPENSSL_memset(ctx, 0, sizeof(EVP_MD_CTX));
   82|  28.9k|}
EVP_MD_CTX_cleanup:
   96|  14.4k|int EVP_MD_CTX_cleanup(EVP_MD_CTX *ctx) {
   97|  14.4k|  OPENSSL_free(ctx->md_data);
   98|       |
   99|  14.4k|  assert(ctx->pctx == NULL || ctx->pctx_ops != NULL);
  100|  14.4k|  if (ctx->pctx_ops) {
  ------------------
  |  Branch (100:7): [True: 0, False: 14.4k]
  ------------------
  101|      0|    ctx->pctx_ops->free(ctx->pctx);
  102|      0|  }
  103|       |
  104|  14.4k|  EVP_MD_CTX_init(ctx);
  105|       |
  106|  14.4k|  return 1;
  107|  14.4k|}

crypto_gcm_clmul_enabled:
  736|  32.2k|int crypto_gcm_clmul_enabled(void) {
  737|  32.2k|#if defined(GHASH_ASM_X86) || defined(GHASH_ASM_X86_64)
  738|  32.2k|  return CRYPTO_is_FXSR_capable() && CRYPTO_is_PCLMUL_capable();
  ------------------
  |  Branch (738:10): [True: 32.2k, False: 0]
  |  Branch (738:38): [True: 32.2k, False: 0]
  ------------------
  739|       |#else
  740|       |  return 0;
  741|       |#endif
  742|  32.2k|}

CTR_DRBG_init:
   49|      1|                  const uint8_t *personalization, size_t personalization_len) {
   50|       |  // Section 10.2.1.3.1
   51|      1|  if (personalization_len > CTR_DRBG_ENTROPY_LEN) {
  ------------------
  |  |   36|      1|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  |  Branch (51:7): [True: 0, False: 1]
  ------------------
   52|      0|    return 0;
   53|      0|  }
   54|       |
   55|      1|  uint8_t seed_material[CTR_DRBG_ENTROPY_LEN];
   56|      1|  OPENSSL_memcpy(seed_material, entropy, CTR_DRBG_ENTROPY_LEN);
  ------------------
  |  |   36|      1|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
   57|       |
   58|      1|  for (size_t i = 0; i < personalization_len; i++) {
  ------------------
  |  Branch (58:22): [True: 0, False: 1]
  ------------------
   59|      0|    seed_material[i] ^= personalization[i];
   60|      0|  }
   61|       |
   62|       |  // Section 10.2.1.2
   63|       |
   64|       |  // kInitMask is the result of encrypting blocks with big-endian value 1, 2
   65|       |  // and 3 with the all-zero AES-256 key.
   66|      1|  static const uint8_t kInitMask[CTR_DRBG_ENTROPY_LEN] = {
   67|      1|      0x53, 0x0f, 0x8a, 0xfb, 0xc7, 0x45, 0x36, 0xb9, 0xa9, 0x63, 0xb4, 0xf1,
   68|      1|      0xc4, 0xcb, 0x73, 0x8b, 0xce, 0xa7, 0x40, 0x3d, 0x4d, 0x60, 0x6b, 0x6e,
   69|      1|      0x07, 0x4e, 0xc5, 0xd3, 0xba, 0xf3, 0x9d, 0x18, 0x72, 0x60, 0x03, 0xca,
   70|      1|      0x37, 0xa6, 0x2a, 0x74, 0xd1, 0xa2, 0xf5, 0x8e, 0x75, 0x06, 0x35, 0x8e,
   71|      1|  };
   72|       |
   73|     49|  for (size_t i = 0; i < sizeof(kInitMask); i++) {
  ------------------
  |  Branch (73:22): [True: 48, False: 1]
  ------------------
   74|     48|    seed_material[i] ^= kInitMask[i];
   75|     48|  }
   76|       |
   77|      1|  drbg->ctr = aes_ctr_set_key(&drbg->ks, NULL, &drbg->block, seed_material, 32);
   78|      1|  OPENSSL_memcpy(drbg->counter, seed_material + 32, 16);
   79|      1|  drbg->reseed_counter = 1;
   80|       |
   81|      1|  return 1;
   82|      1|}
CTR_DRBG_reseed:
  122|      1|                    size_t additional_data_len) {
  123|       |  // Section 10.2.1.4
  124|      1|  uint8_t entropy_copy[CTR_DRBG_ENTROPY_LEN];
  125|       |
  126|      1|  if (additional_data_len > 0) {
  ------------------
  |  Branch (126:7): [True: 0, False: 1]
  ------------------
  127|      0|    if (additional_data_len > CTR_DRBG_ENTROPY_LEN) {
  ------------------
  |  |   36|      0|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  |  Branch (127:9): [True: 0, False: 0]
  ------------------
  128|      0|      return 0;
  129|      0|    }
  130|       |
  131|      0|    OPENSSL_memcpy(entropy_copy, entropy, CTR_DRBG_ENTROPY_LEN);
  ------------------
  |  |   36|      0|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  132|      0|    for (size_t i = 0; i < additional_data_len; i++) {
  ------------------
  |  Branch (132:24): [True: 0, False: 0]
  ------------------
  133|      0|      entropy_copy[i] ^= additional_data[i];
  134|      0|    }
  135|       |
  136|      0|    entropy = entropy_copy;
  137|      0|  }
  138|       |
  139|      1|  if (!ctr_drbg_update(drbg, entropy, CTR_DRBG_ENTROPY_LEN)) {
  ------------------
  |  |   36|      1|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  |  Branch (139:7): [True: 0, False: 1]
  ------------------
  140|      0|    return 0;
  141|      0|  }
  142|       |
  143|      1|  drbg->reseed_counter = 1;
  144|       |
  145|      1|  return 1;
  146|      1|}
CTR_DRBG_generate:
  150|  4.83k|                      size_t additional_data_len) {
  151|       |  // See 9.3.1
  152|  4.83k|  if (out_len > CTR_DRBG_MAX_GENERATE_LENGTH) {
  ------------------
  |  |   40|  4.83k|#define CTR_DRBG_MAX_GENERATE_LENGTH 65536
  ------------------
  |  Branch (152:7): [True: 0, False: 4.83k]
  ------------------
  153|      0|    return 0;
  154|      0|  }
  155|       |
  156|       |  // See 10.2.1.5.1
  157|  4.83k|  if (drbg->reseed_counter > kMaxReseedCount) {
  ------------------
  |  Branch (157:7): [True: 0, False: 4.83k]
  ------------------
  158|      0|    return 0;
  159|      0|  }
  160|       |
  161|  4.83k|  if (additional_data_len != 0 &&
  ------------------
  |  Branch (161:7): [True: 4.83k, False: 0]
  ------------------
  162|  4.83k|      !ctr_drbg_update(drbg, additional_data, additional_data_len)) {
  ------------------
  |  Branch (162:7): [True: 0, False: 4.83k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|       |  // kChunkSize is used to interact better with the cache. Since the AES-CTR
  167|       |  // code assumes that it's encrypting rather than just writing keystream, the
  168|       |  // buffer has to be zeroed first. Without chunking, large reads would zero
  169|       |  // the whole buffer, flushing the L1 cache, and then do another pass (missing
  170|       |  // the cache every time) to “encrypt” it. The code can avoid this by
  171|       |  // chunking.
  172|  4.83k|  static const size_t kChunkSize = 8 * 1024;
  173|       |
  174|  4.83k|  while (out_len >= AES_BLOCK_SIZE) {
  ------------------
  |  |   68|  4.83k|#define AES_BLOCK_SIZE 16
  ------------------
  |  Branch (174:10): [True: 0, False: 4.83k]
  ------------------
  175|      0|    size_t todo = kChunkSize;
  176|      0|    if (todo > out_len) {
  ------------------
  |  Branch (176:9): [True: 0, False: 0]
  ------------------
  177|      0|      todo = out_len;
  178|      0|    }
  179|       |
  180|      0|    todo &= ~(AES_BLOCK_SIZE-1);
  ------------------
  |  |   68|      0|#define AES_BLOCK_SIZE 16
  ------------------
  181|      0|    const size_t num_blocks = todo / AES_BLOCK_SIZE;
  ------------------
  |  |   68|      0|#define AES_BLOCK_SIZE 16
  ------------------
  182|       |
  183|      0|    if (drbg->ctr) {
  ------------------
  |  Branch (183:9): [True: 0, False: 0]
  ------------------
  184|      0|      OPENSSL_memset(out, 0, todo);
  185|      0|      ctr32_add(drbg, 1);
  186|      0|      drbg->ctr(out, out, num_blocks, &drbg->ks, drbg->counter);
  187|      0|      ctr32_add(drbg, (uint32_t)(num_blocks - 1));
  188|      0|    } else {
  189|      0|      for (size_t i = 0; i < todo; i += AES_BLOCK_SIZE) {
  ------------------
  |  |   68|      0|#define AES_BLOCK_SIZE 16
  ------------------
  |  Branch (189:26): [True: 0, False: 0]
  ------------------
  190|      0|        ctr32_add(drbg, 1);
  191|      0|        drbg->block(drbg->counter, out + i, &drbg->ks);
  192|      0|      }
  193|      0|    }
  194|       |
  195|      0|    out += todo;
  196|      0|    out_len -= todo;
  197|      0|  }
  198|       |
  199|  4.83k|  if (out_len > 0) {
  ------------------
  |  Branch (199:7): [True: 4.83k, False: 0]
  ------------------
  200|  4.83k|    uint8_t block[AES_BLOCK_SIZE];
  201|  4.83k|    ctr32_add(drbg, 1);
  202|  4.83k|    drbg->block(drbg->counter, block, &drbg->ks);
  203|       |
  204|  4.83k|    OPENSSL_memcpy(out, block, out_len);
  205|  4.83k|  }
  206|       |
  207|       |  // Right-padding |additional_data| in step 2.2 is handled implicitly by
  208|       |  // |ctr_drbg_update|, to save a copy.
  209|  4.83k|  if (!ctr_drbg_update(drbg, additional_data, additional_data_len)) {
  ------------------
  |  Branch (209:7): [True: 0, False: 4.83k]
  ------------------
  210|      0|    return 0;
  211|      0|  }
  212|       |
  213|  4.83k|  drbg->reseed_counter++;
  214|  4.83k|  FIPS_service_indicator_update_state();
  215|  4.83k|  return 1;
  216|  4.83k|}
bcm.c:ctr_drbg_update:
   95|  9.66k|                           size_t data_len) {
   96|       |  // Per section 10.2.1.2, |data_len| must be |CTR_DRBG_ENTROPY_LEN|. Here, we
   97|       |  // allow shorter inputs and right-pad them with zeros. This is equivalent to
   98|       |  // the specified algorithm but saves a copy in |CTR_DRBG_generate|.
   99|  9.66k|  if (data_len > CTR_DRBG_ENTROPY_LEN) {
  ------------------
  |  |   36|  9.66k|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  |  Branch (99:7): [True: 0, False: 9.66k]
  ------------------
  100|      0|    return 0;
  101|      0|  }
  102|       |
  103|  9.66k|  uint8_t temp[CTR_DRBG_ENTROPY_LEN];
  104|  38.6k|  for (size_t i = 0; i < CTR_DRBG_ENTROPY_LEN; i += AES_BLOCK_SIZE) {
  ------------------
  |  |   36|  38.6k|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
                for (size_t i = 0; i < CTR_DRBG_ENTROPY_LEN; i += AES_BLOCK_SIZE) {
  ------------------
  |  |   68|  28.9k|#define AES_BLOCK_SIZE 16
  ------------------
  |  Branch (104:22): [True: 28.9k, False: 9.66k]
  ------------------
  105|  28.9k|    ctr32_add(drbg, 1);
  106|  28.9k|    drbg->block(drbg->counter, temp + i, &drbg->ks);
  107|  28.9k|  }
  108|       |
  109|   318k|  for (size_t i = 0; i < data_len; i++) {
  ------------------
  |  Branch (109:22): [True: 309k, False: 9.66k]
  ------------------
  110|   309k|    temp[i] ^= data[i];
  111|   309k|  }
  112|       |
  113|  9.66k|  drbg->ctr = aes_ctr_set_key(&drbg->ks, NULL, &drbg->block, temp, 32);
  114|  9.66k|  OPENSSL_memcpy(drbg->counter, temp + 32, 16);
  115|       |
  116|  9.66k|  return 1;
  117|  9.66k|}
bcm.c:ctr32_add:
   89|  33.8k|static void ctr32_add(CTR_DRBG_STATE *drbg, uint32_t n) {
   90|  33.8k|  uint32_t ctr = CRYPTO_load_u32_be(drbg->counter + 12);
   91|  33.8k|  CRYPTO_store_u32_be(drbg->counter + 12, ctr + n);
   92|  33.8k|}

CRYPTO_get_fork_generation:
   78|  4.83k|uint64_t CRYPTO_get_fork_generation(void) {
   79|       |  // In a single-threaded process, there are obviously no races because there's
   80|       |  // only a single mutator in the address space.
   81|       |  //
   82|       |  // In a multi-threaded environment, |CRYPTO_once| ensures that the flag byte
   83|       |  // is initialised atomically, even if multiple threads enter this function
   84|       |  // concurrently.
   85|       |  //
   86|       |  // Additionally, while the kernel will only clear WIPEONFORK at a point when a
   87|       |  // child process is single-threaded, the child may become multi-threaded
   88|       |  // before it observes this. Therefore, we must synchronize the logic below.
   89|       |
   90|  4.83k|  CRYPTO_once(g_fork_detect_once_bss_get(), init_fork_detect);
   91|  4.83k|  CRYPTO_atomic_u32 *const flag_ptr = *g_fork_detect_addr_bss_get();
   92|  4.83k|  if (flag_ptr == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 4.83k]
  ------------------
   93|       |    // Our kernel is too old to support |MADV_WIPEONFORK| or
   94|       |    // |g_force_madv_wipeonfork| is set.
   95|      0|    if (*g_force_madv_wipeonfork_bss_get() &&
  ------------------
  |  Branch (95:9): [True: 0, False: 0]
  ------------------
   96|      0|        *g_force_madv_wipeonfork_enabled_bss_get()) {
  ------------------
  |  Branch (96:9): [True: 0, False: 0]
  ------------------
   97|       |      // A constant generation number to simulate support, even if the kernel
   98|       |      // doesn't support it.
   99|      0|      return 42;
  100|      0|    }
  101|      0|    return 0;
  102|      0|  }
  103|       |
  104|       |  // In the common case, try to observe the flag without taking a lock. This
  105|       |  // avoids cacheline contention in the PRNG.
  106|  4.83k|  uint64_t *const generation_ptr = g_fork_generation_bss_get();
  107|  4.83k|  if (CRYPTO_atomic_load_u32(flag_ptr) != 0) {
  ------------------
  |  Branch (107:7): [True: 4.83k, False: 0]
  ------------------
  108|       |    // If we observe a non-zero flag, it is safe to read |generation_ptr|
  109|       |    // without a lock. The flag and generation number are fixed for this copy of
  110|       |    // the address space.
  111|  4.83k|    return *generation_ptr;
  112|  4.83k|  }
  113|       |
  114|       |  // The flag was zero. The generation number must be incremented, but other
  115|       |  // threads may have concurrently observed the zero, so take a lock before
  116|       |  // incrementing.
  117|      0|  struct CRYPTO_STATIC_MUTEX *const lock = g_fork_detect_lock_bss_get();
  118|      0|  CRYPTO_STATIC_MUTEX_lock_write(lock);
  119|      0|  uint64_t current_generation = *generation_ptr;
  120|      0|  if (CRYPTO_atomic_load_u32(flag_ptr) == 0) {
  ------------------
  |  Branch (120:7): [True: 0, False: 0]
  ------------------
  121|       |    // A fork has occurred.
  122|      0|    current_generation++;
  123|      0|    if (current_generation == 0) {
  ------------------
  |  Branch (123:9): [True: 0, False: 0]
  ------------------
  124|       |      // Zero means fork detection isn't supported, so skip that value.
  125|      0|      current_generation = 1;
  126|      0|    }
  127|       |
  128|       |    // We must update |generation_ptr| before |flag_ptr|. Other threads may
  129|       |    // observe |flag_ptr| without taking a lock.
  130|      0|    *generation_ptr = current_generation;
  131|      0|    CRYPTO_atomic_store_u32(flag_ptr, 1);
  132|      0|  }
  133|      0|  CRYPTO_STATIC_MUTEX_unlock_write(lock);
  134|       |
  135|      0|  return current_generation;
  136|  4.83k|}
bcm.c:init_fork_detect:
   46|      1|static void init_fork_detect(void) {
   47|      1|  if (*g_force_madv_wipeonfork_bss_get()) {
  ------------------
  |  Branch (47:7): [True: 0, False: 1]
  ------------------
   48|      0|    return;
   49|      0|  }
   50|       |
   51|      1|  long page_size = sysconf(_SC_PAGESIZE);
   52|      1|  if (page_size <= 0) {
  ------------------
  |  Branch (52:7): [True: 0, False: 1]
  ------------------
   53|      0|    return;
   54|      0|  }
   55|       |
   56|      1|  void *addr = mmap(NULL, (size_t)page_size, PROT_READ | PROT_WRITE,
   57|      1|                    MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);
   58|      1|  if (addr == MAP_FAILED) {
  ------------------
  |  Branch (58:7): [True: 0, False: 1]
  ------------------
   59|      0|    return;
   60|      0|  }
   61|       |
   62|       |  // Some versions of qemu (up to at least 5.0.0-rc4, see linux-user/syscall.c)
   63|       |  // ignore |madvise| calls and just return zero (i.e. success). But we need to
   64|       |  // know whether MADV_WIPEONFORK actually took effect. Therefore try an invalid
   65|       |  // call to check that the implementation of |madvise| is actually rejecting
   66|       |  // unknown |advice| values.
   67|      1|  if (madvise(addr, (size_t)page_size, -1) == 0 ||
  ------------------
  |  Branch (67:7): [True: 0, False: 1]
  ------------------
   68|      1|      madvise(addr, (size_t)page_size, MADV_WIPEONFORK) != 0) {
  ------------------
  |  Branch (68:7): [True: 0, False: 1]
  ------------------
   69|      0|    munmap(addr, (size_t)page_size);
   70|      0|    return;
   71|      0|  }
   72|       |
   73|      1|  CRYPTO_atomic_store_u32(addr, 1);
   74|      1|  *g_fork_detect_addr_bss_get() = addr;
   75|      1|  *g_fork_generation_bss_get() = 1;
   76|      1|}

bcm.c:have_fast_rdrand:
  125|  4.83k|OPENSSL_INLINE int have_fast_rdrand(void) {
  126|  4.83k|  return CRYPTO_is_RDRAND_capable() && CRYPTO_is_intel_cpu();
  ------------------
  |  Branch (126:10): [True: 4.83k, False: 0]
  |  Branch (126:40): [True: 4.83k, False: 0]
  ------------------
  127|  4.83k|}

RAND_bytes_with_additional_data:
  331|  4.83k|                                     const uint8_t user_additional_data[32]) {
  332|  4.83k|  if (out_len == 0) {
  ------------------
  |  Branch (332:7): [True: 0, False: 4.83k]
  ------------------
  333|      0|    return;
  334|      0|  }
  335|       |
  336|  4.83k|  const uint64_t fork_generation = CRYPTO_get_fork_generation();
  337|  4.83k|  const int fork_unsafe_buffering = rand_fork_unsafe_buffering_enabled();
  338|       |
  339|       |  // Additional data is mixed into every CTR-DRBG call to protect, as best we
  340|       |  // can, against forks & VM clones. We do not over-read this information and
  341|       |  // don't reseed with it so, from the point of view of FIPS, this doesn't
  342|       |  // provide “prediction resistance”. But, in practice, it does.
  343|  4.83k|  uint8_t additional_data[32];
  344|       |  // Intel chips have fast RDRAND instructions while, in other cases, RDRAND can
  345|       |  // be _slower_ than a system call.
  346|  4.83k|  if (!have_fast_rdrand() ||
  ------------------
  |  Branch (346:7): [True: 0, False: 4.83k]
  ------------------
  347|  4.83k|      !rdrand(additional_data, sizeof(additional_data))) {
  ------------------
  |  Branch (347:7): [True: 4.83k, False: 0]
  ------------------
  348|       |    // Without a hardware RNG to save us from address-space duplication, the OS
  349|       |    // entropy is used. This can be expensive (one read per |RAND_bytes| call)
  350|       |    // and so is disabled when we have fork detection, or if the application has
  351|       |    // promised not to fork.
  352|  4.83k|    if (fork_generation != 0 || fork_unsafe_buffering) {
  ------------------
  |  Branch (352:9): [True: 4.83k, False: 0]
  |  Branch (352:33): [True: 0, False: 0]
  ------------------
  353|  4.83k|      OPENSSL_memset(additional_data, 0, sizeof(additional_data));
  354|  4.83k|    } else if (!have_rdrand()) {
  ------------------
  |  Branch (354:16): [True: 0, False: 0]
  ------------------
  355|       |      // No alternative so block for OS entropy.
  356|      0|      CRYPTO_sysrand(additional_data, sizeof(additional_data));
  357|      0|    } else if (!CRYPTO_sysrand_if_available(additional_data,
  ------------------
  |  Branch (357:16): [True: 0, False: 0]
  ------------------
  358|      0|                                            sizeof(additional_data)) &&
  359|      0|               !rdrand(additional_data, sizeof(additional_data))) {
  ------------------
  |  Branch (359:16): [True: 0, False: 0]
  ------------------
  360|       |      // RDRAND failed: block for OS entropy.
  361|      0|      CRYPTO_sysrand(additional_data, sizeof(additional_data));
  362|      0|    }
  363|  4.83k|  }
  364|       |
  365|   159k|  for (size_t i = 0; i < sizeof(additional_data); i++) {
  ------------------
  |  Branch (365:22): [True: 154k, False: 4.83k]
  ------------------
  366|   154k|    additional_data[i] ^= user_additional_data[i];
  367|   154k|  }
  368|       |
  369|  4.83k|  struct rand_thread_state stack_state;
  370|  4.83k|  struct rand_thread_state *state =
  371|  4.83k|      CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_RAND);
  372|       |
  373|  4.83k|  if (state == NULL) {
  ------------------
  |  Branch (373:7): [True: 1, False: 4.82k]
  ------------------
  374|      1|    state = OPENSSL_malloc(sizeof(struct rand_thread_state));
  375|      1|    if (state == NULL ||
  ------------------
  |  Branch (375:9): [True: 0, False: 1]
  ------------------
  376|      1|        !CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_RAND, state,
  ------------------
  |  Branch (376:9): [True: 0, False: 1]
  ------------------
  377|      1|                                 rand_thread_state_free)) {
  378|       |      // If the system is out of memory, use an ephemeral state on the
  379|       |      // stack.
  380|      0|      state = &stack_state;
  381|      0|    }
  382|       |
  383|      1|    state->last_block_valid = 0;
  384|      1|    uint8_t seed[CTR_DRBG_ENTROPY_LEN];
  385|      1|    uint8_t personalization[CTR_DRBG_ENTROPY_LEN] = {0};
  386|      1|    size_t personalization_len = 0;
  387|      1|    rand_get_seed(state, seed, personalization, &personalization_len);
  388|       |
  389|      1|    if (!CTR_DRBG_init(&state->drbg, seed, personalization,
  ------------------
  |  Branch (389:9): [True: 0, False: 1]
  ------------------
  390|      1|                       personalization_len)) {
  391|      0|      abort();
  392|      0|    }
  393|      1|    state->calls = 0;
  394|      1|    state->fork_generation = fork_generation;
  395|      1|    state->fork_unsafe_buffering = fork_unsafe_buffering;
  396|       |
  397|       |#if defined(BORINGSSL_FIPS)
  398|       |    CRYPTO_MUTEX_init(&state->clear_drbg_lock);
  399|       |    if (state != &stack_state) {
  400|       |      CRYPTO_STATIC_MUTEX_lock_write(thread_states_list_lock_bss_get());
  401|       |      struct rand_thread_state **states_list = thread_states_list_bss_get();
  402|       |      state->next = *states_list;
  403|       |      if (state->next != NULL) {
  404|       |        state->next->prev = state;
  405|       |      }
  406|       |      state->prev = NULL;
  407|       |      *states_list = state;
  408|       |      CRYPTO_STATIC_MUTEX_unlock_write(thread_states_list_lock_bss_get());
  409|       |    }
  410|       |#endif
  411|      1|  }
  412|       |
  413|  4.83k|  if (state->calls >= kReseedInterval ||
  ------------------
  |  Branch (413:7): [True: 1, False: 4.82k]
  ------------------
  414|       |      // If we've forked since |state| was last seeded, reseed.
  415|  4.83k|      state->fork_generation != fork_generation ||
  ------------------
  |  Branch (415:7): [True: 0, False: 4.82k]
  ------------------
  416|       |      // If |state| was seeded from a state with different fork-safety
  417|       |      // preferences, reseed. Suppose |state| was fork-safe, then forked into
  418|       |      // two children, but each of the children never fork and disable fork
  419|       |      // safety. The children must reseed to avoid working from the same PRNG
  420|       |      // state.
  421|  4.83k|      state->fork_unsafe_buffering != fork_unsafe_buffering) {
  ------------------
  |  Branch (421:7): [True: 0, False: 4.82k]
  ------------------
  422|      1|    uint8_t seed[CTR_DRBG_ENTROPY_LEN];
  423|      1|    uint8_t reseed_additional_data[CTR_DRBG_ENTROPY_LEN] = {0};
  424|      1|    size_t reseed_additional_data_len = 0;
  425|      1|    rand_get_seed(state, seed, reseed_additional_data,
  426|      1|                  &reseed_additional_data_len);
  427|       |#if defined(BORINGSSL_FIPS)
  428|       |    // Take a read lock around accesses to |state->drbg|. This is needed to
  429|       |    // avoid returning bad entropy if we race with
  430|       |    // |rand_thread_state_clear_all|.
  431|       |    CRYPTO_MUTEX_lock_read(&state->clear_drbg_lock);
  432|       |#endif
  433|      1|    if (!CTR_DRBG_reseed(&state->drbg, seed, reseed_additional_data,
  ------------------
  |  Branch (433:9): [True: 0, False: 1]
  ------------------
  434|      1|                         reseed_additional_data_len)) {
  435|      0|      abort();
  436|      0|    }
  437|      1|    state->calls = 0;
  438|      1|    state->fork_generation = fork_generation;
  439|      1|    state->fork_unsafe_buffering = fork_unsafe_buffering;
  440|  4.82k|  } else {
  441|       |#if defined(BORINGSSL_FIPS)
  442|       |    CRYPTO_MUTEX_lock_read(&state->clear_drbg_lock);
  443|       |#endif
  444|  4.82k|  }
  445|       |
  446|  4.83k|  int first_call = 1;
  447|  9.66k|  while (out_len > 0) {
  ------------------
  |  Branch (447:10): [True: 4.83k, False: 4.83k]
  ------------------
  448|  4.83k|    size_t todo = out_len;
  449|  4.83k|    if (todo > CTR_DRBG_MAX_GENERATE_LENGTH) {
  ------------------
  |  |   40|  4.83k|#define CTR_DRBG_MAX_GENERATE_LENGTH 65536
  ------------------
  |  Branch (449:9): [True: 0, False: 4.83k]
  ------------------
  450|      0|      todo = CTR_DRBG_MAX_GENERATE_LENGTH;
  ------------------
  |  |   40|      0|#define CTR_DRBG_MAX_GENERATE_LENGTH 65536
  ------------------
  451|      0|    }
  452|       |
  453|  4.83k|    if (!CTR_DRBG_generate(&state->drbg, out, todo, additional_data,
  ------------------
  |  Branch (453:9): [True: 0, False: 4.83k]
  ------------------
  454|  4.83k|                           first_call ? sizeof(additional_data) : 0)) {
  ------------------
  |  Branch (454:28): [True: 4.83k, False: 0]
  ------------------
  455|      0|      abort();
  456|      0|    }
  457|       |
  458|  4.83k|    out += todo;
  459|  4.83k|    out_len -= todo;
  460|       |    // Though we only check before entering the loop, this cannot add enough to
  461|       |    // overflow a |size_t|.
  462|  4.83k|    state->calls++;
  463|  4.83k|    first_call = 0;
  464|  4.83k|  }
  465|       |
  466|  4.83k|  if (state == &stack_state) {
  ------------------
  |  Branch (466:7): [True: 0, False: 4.83k]
  ------------------
  467|      0|    CTR_DRBG_clear(&state->drbg);
  468|      0|  }
  469|       |
  470|       |#if defined(BORINGSSL_FIPS)
  471|       |  CRYPTO_MUTEX_unlock_read(&state->clear_drbg_lock);
  472|       |#endif
  473|  4.83k|}
RAND_bytes:
  475|  4.83k|int RAND_bytes(uint8_t *out, size_t out_len) {
  476|  4.83k|  static const uint8_t kZeroAdditionalData[32] = {0};
  477|  4.83k|  RAND_bytes_with_additional_data(out, out_len, kZeroAdditionalData);
  478|  4.83k|  return 1;
  479|  4.83k|}
bcm.c:rdrand:
  164|  4.83k|static int rdrand(uint8_t *buf, size_t len) {
  165|  4.83k|  return 0;
  166|  4.83k|}
bcm.c:rand_get_seed:
  321|      2|                          size_t *out_additional_input_len) {
  322|       |  // If not in FIPS mode, we don't overread from the system entropy source and
  323|       |  // we don't depend only on the hardware RDRAND.
  324|      2|  CRYPTO_sysrand_for_seed(seed, CTR_DRBG_ENTROPY_LEN);
  ------------------
  |  |   36|      2|#define CTR_DRBG_ENTROPY_LEN 48
  ------------------
  325|      2|  *out_additional_input_len = 0;
  326|      2|}

RSA_new:
  206|  22.7k|RSA *RSA_new(void) { return RSA_new_method(NULL); }
RSA_new_method:
  208|  22.7k|RSA *RSA_new_method(const ENGINE *engine) {
  209|  22.7k|  RSA *rsa = OPENSSL_malloc(sizeof(RSA));
  210|  22.7k|  if (rsa == NULL) {
  ------------------
  |  Branch (210:7): [True: 0, False: 22.7k]
  ------------------
  211|      0|    return NULL;
  212|      0|  }
  213|       |
  214|  22.7k|  OPENSSL_memset(rsa, 0, sizeof(RSA));
  215|       |
  216|  22.7k|  if (engine) {
  ------------------
  |  Branch (216:7): [True: 0, False: 22.7k]
  ------------------
  217|      0|    rsa->meth = ENGINE_get_RSA_method(engine);
  218|      0|  }
  219|       |
  220|  22.7k|  if (rsa->meth == NULL) {
  ------------------
  |  Branch (220:7): [True: 22.7k, False: 0]
  ------------------
  221|  22.7k|    rsa->meth = (RSA_METHOD *) RSA_default_method();
  222|  22.7k|  }
  223|  22.7k|  METHOD_ref(rsa->meth);
  224|       |
  225|  22.7k|  rsa->references = 1;
  226|  22.7k|  rsa->flags = rsa->meth->flags;
  227|  22.7k|  CRYPTO_MUTEX_init(&rsa->lock);
  228|  22.7k|  CRYPTO_new_ex_data(&rsa->ex_data);
  229|       |
  230|  22.7k|  if (rsa->meth->init && !rsa->meth->init(rsa)) {
  ------------------
  |  Branch (230:7): [True: 0, False: 22.7k]
  |  Branch (230:26): [True: 0, False: 0]
  ------------------
  231|      0|    CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  232|      0|    CRYPTO_MUTEX_cleanup(&rsa->lock);
  233|      0|    METHOD_unref(rsa->meth);
  234|      0|    OPENSSL_free(rsa);
  235|      0|    return NULL;
  236|      0|  }
  237|       |
  238|  22.7k|  return rsa;
  239|  22.7k|}
RSA_free:
  252|  22.7k|void RSA_free(RSA *rsa) {
  253|  22.7k|  if (rsa == NULL) {
  ------------------
  |  Branch (253:7): [True: 0, False: 22.7k]
  ------------------
  254|      0|    return;
  255|      0|  }
  256|       |
  257|  22.7k|  if (!CRYPTO_refcount_dec_and_test_zero(&rsa->references)) {
  ------------------
  |  Branch (257:7): [True: 0, False: 22.7k]
  ------------------
  258|      0|    return;
  259|      0|  }
  260|       |
  261|  22.7k|  if (rsa->meth->finish) {
  ------------------
  |  Branch (261:7): [True: 0, False: 22.7k]
  ------------------
  262|      0|    rsa->meth->finish(rsa);
  263|      0|  }
  264|  22.7k|  METHOD_unref(rsa->meth);
  265|       |
  266|  22.7k|  CRYPTO_free_ex_data(g_rsa_ex_data_class_bss_get(), rsa, &rsa->ex_data);
  267|       |
  268|  22.7k|  BN_free(rsa->n);
  269|  22.7k|  BN_free(rsa->e);
  270|  22.7k|  BN_free(rsa->d);
  271|  22.7k|  BN_free(rsa->p);
  272|  22.7k|  BN_free(rsa->q);
  273|  22.7k|  BN_free(rsa->dmp1);
  274|  22.7k|  BN_free(rsa->dmq1);
  275|  22.7k|  BN_free(rsa->iqmp);
  276|  22.7k|  rsa_invalidate_key(rsa);
  277|  22.7k|  CRYPTO_MUTEX_cleanup(&rsa->lock);
  278|  22.7k|  OPENSSL_free(rsa);
  279|  22.7k|}
RSA_get0_n:
  288|  29.5k|const BIGNUM *RSA_get0_n(const RSA *rsa) { return rsa->n; }
RSA_get0_e:
  290|  29.5k|const BIGNUM *RSA_get0_e(const RSA *rsa) { return rsa->e; }
RSA_is_opaque:
  438|  37.5k|int RSA_is_opaque(const RSA *rsa) {
  439|  37.5k|  return rsa->meth && (rsa->meth->flags & RSA_FLAG_OPAQUE);
  ------------------
  |  |  661|  37.5k|#define RSA_FLAG_OPAQUE 1
  ------------------
  |  Branch (439:10): [True: 37.5k, False: 0]
  |  Branch (439:23): [True: 0, False: 37.5k]
  ------------------
  440|  37.5k|}
RSA_check_key:
  787|  22.7k|int RSA_check_key(const RSA *key) {
  788|       |  // TODO(davidben): RSA key initialization is spread across
  789|       |  // |rsa_check_public_key|, |RSA_check_key|, |freeze_private_key|, and
  790|       |  // |BN_MONT_CTX_set_locked| as a result of API issues. See
  791|       |  // https://crbug.com/boringssl/316. As a result, we inconsistently check RSA
  792|       |  // invariants. We should fix this and integrate that logic.
  793|       |
  794|  22.7k|  if (RSA_is_opaque(key)) {
  ------------------
  |  Branch (794:7): [True: 0, False: 22.7k]
  ------------------
  795|       |    // Opaque keys can't be checked.
  796|      0|    return 1;
  797|      0|  }
  798|       |
  799|  22.7k|  if (!rsa_check_public_key(key)) {
  ------------------
  |  Branch (799:7): [True: 0, False: 22.7k]
  ------------------
  800|      0|    return 0;
  801|      0|  }
  802|       |
  803|  22.7k|  if ((key->p != NULL) != (key->q != NULL)) {
  ------------------
  |  Branch (803:7): [True: 0, False: 22.7k]
  ------------------
  804|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_ONLY_ONE_OF_P_Q_GIVEN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  805|      0|    return 0;
  806|      0|  }
  807|       |
  808|       |  // |key->d| must be bounded by |key->n|. This ensures bounds on |RSA_bits|
  809|       |  // translate to bounds on the running time of private key operations.
  810|  22.7k|  if (key->d != NULL &&
  ------------------
  |  Branch (810:7): [True: 2, False: 22.7k]
  ------------------
  811|  22.7k|      (BN_is_negative(key->d) || BN_cmp(key->d, key->n) >= 0)) {
  ------------------
  |  Branch (811:8): [True: 0, False: 2]
  |  Branch (811:34): [True: 0, False: 2]
  ------------------
  812|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_OUT_OF_RANGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  813|      0|    return 0;
  814|      0|  }
  815|       |
  816|  22.7k|  if (key->d == NULL || key->p == NULL) {
  ------------------
  |  Branch (816:7): [True: 22.7k, False: 2]
  |  Branch (816:25): [True: 0, False: 2]
  ------------------
  817|       |    // For a public key, or without p and q, there's nothing that can be
  818|       |    // checked.
  819|  22.7k|    return 1;
  820|  22.7k|  }
  821|       |
  822|      2|  BN_CTX *ctx = BN_CTX_new();
  823|      2|  if (ctx == NULL) {
  ------------------
  |  Branch (823:7): [True: 0, False: 2]
  ------------------
  824|      0|    return 0;
  825|      0|  }
  826|       |
  827|      2|  BIGNUM tmp, de, pm1, qm1, dmp1, dmq1;
  828|      2|  int ok = 0;
  829|      2|  BN_init(&tmp);
  830|      2|  BN_init(&de);
  831|      2|  BN_init(&pm1);
  832|      2|  BN_init(&qm1);
  833|      2|  BN_init(&dmp1);
  834|      2|  BN_init(&dmq1);
  835|       |
  836|       |  // Check that p * q == n. Before we multiply, we check that p and q are in
  837|       |  // bounds, to avoid a DoS vector in |bn_mul_consttime| below. Note that
  838|       |  // n was bound by |rsa_check_public_key|. This also implicitly checks p and q
  839|       |  // are odd, which is a necessary condition for Montgomery reduction.
  840|      2|  if (BN_is_negative(key->p) || BN_cmp(key->p, key->n) >= 0 ||
  ------------------
  |  Branch (840:7): [True: 0, False: 2]
  |  Branch (840:33): [True: 0, False: 2]
  ------------------
  841|      2|      BN_is_negative(key->q) || BN_cmp(key->q, key->n) >= 0) {
  ------------------
  |  Branch (841:7): [True: 0, False: 2]
  |  Branch (841:33): [True: 0, False: 2]
  ------------------
  842|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  843|      0|    goto out;
  844|      0|  }
  845|      2|  if (!bn_mul_consttime(&tmp, key->p, key->q, ctx)) {
  ------------------
  |  Branch (845:7): [True: 0, False: 2]
  ------------------
  846|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  847|      0|    goto out;
  848|      0|  }
  849|      2|  if (BN_cmp(&tmp, key->n) != 0) {
  ------------------
  |  Branch (849:7): [True: 0, False: 2]
  ------------------
  850|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  851|      0|    goto out;
  852|      0|  }
  853|       |
  854|       |  // d must be an inverse of e mod the Carmichael totient, lcm(p-1, q-1), but it
  855|       |  // may be unreduced because other implementations use the Euler totient. We
  856|       |  // simply check that d * e is one mod p-1 and mod q-1. Note d and e were bound
  857|       |  // by earlier checks in this function.
  858|      2|  if (!bn_usub_consttime(&pm1, key->p, BN_value_one()) ||
  ------------------
  |  Branch (858:7): [True: 0, False: 2]
  ------------------
  859|      2|      !bn_usub_consttime(&qm1, key->q, BN_value_one())) {
  ------------------
  |  Branch (859:7): [True: 0, False: 2]
  ------------------
  860|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  861|      0|    goto out;
  862|      0|  }
  863|      2|  const unsigned pm1_bits = BN_num_bits(&pm1);
  864|      2|  const unsigned qm1_bits = BN_num_bits(&qm1);
  865|      2|  if (!bn_mul_consttime(&de, key->d, key->e, ctx) ||
  ------------------
  |  Branch (865:7): [True: 0, False: 2]
  ------------------
  866|      2|      !bn_div_consttime(NULL, &tmp, &de, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (866:7): [True: 0, False: 2]
  ------------------
  867|      2|      !bn_div_consttime(NULL, &de, &de, &qm1, qm1_bits, ctx)) {
  ------------------
  |  Branch (867:7): [True: 0, False: 2]
  ------------------
  868|      0|    OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  869|      0|    goto out;
  870|      0|  }
  871|       |
  872|      2|  if (!BN_is_one(&tmp) || !BN_is_one(&de)) {
  ------------------
  |  Branch (872:7): [True: 0, False: 2]
  |  Branch (872:27): [True: 0, False: 2]
  ------------------
  873|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_D_E_NOT_CONGRUENT_TO_1);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  874|      0|    goto out;
  875|      0|  }
  876|       |
  877|      2|  int has_crt_values = key->dmp1 != NULL;
  878|      2|  if (has_crt_values != (key->dmq1 != NULL) ||
  ------------------
  |  Branch (878:7): [True: 0, False: 2]
  ------------------
  879|      2|      has_crt_values != (key->iqmp != NULL)) {
  ------------------
  |  Branch (879:7): [True: 0, False: 2]
  ------------------
  880|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_INCONSISTENT_SET_OF_CRT_VALUES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  881|      0|    goto out;
  882|      0|  }
  883|       |
  884|      2|  if (has_crt_values) {
  ------------------
  |  Branch (884:7): [True: 2, False: 0]
  ------------------
  885|      2|    int dmp1_ok, dmq1_ok, iqmp_ok;
  886|      2|    if (!check_mod_inverse(&dmp1_ok, key->e, key->dmp1, &pm1, pm1_bits, ctx) ||
  ------------------
  |  Branch (886:9): [True: 0, False: 2]
  ------------------
  887|      2|        !check_mod_inverse(&dmq1_ok, key->e, key->dmq1, &qm1, qm1_bits, ctx) ||
  ------------------
  |  Branch (887:9): [True: 0, False: 2]
  ------------------
  888|       |        // |p| is odd, so |pm1| and |p| have the same bit width. If they didn't,
  889|       |        // we only need a lower bound anyway.
  890|      2|        !check_mod_inverse(&iqmp_ok, key->q, key->iqmp, key->p, pm1_bits,
  ------------------
  |  Branch (890:9): [True: 0, False: 2]
  ------------------
  891|      2|                           ctx)) {
  892|      0|      OPENSSL_PUT_ERROR(RSA, ERR_LIB_BN);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  893|      0|      goto out;
  894|      0|    }
  895|       |
  896|      2|    if (!dmp1_ok || !dmq1_ok || !iqmp_ok) {
  ------------------
  |  Branch (896:9): [True: 0, False: 2]
  |  Branch (896:21): [True: 0, False: 2]
  |  Branch (896:33): [True: 0, False: 2]
  ------------------
  897|      0|      OPENSSL_PUT_ERROR(RSA, RSA_R_CRT_VALUES_INCORRECT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  898|      0|      goto out;
  899|      0|    }
  900|      2|  }
  901|       |
  902|      2|  ok = 1;
  903|       |
  904|      2|out:
  905|      2|  BN_free(&tmp);
  906|      2|  BN_free(&de);
  907|      2|  BN_free(&pm1);
  908|      2|  BN_free(&qm1);
  909|      2|  BN_free(&dmp1);
  910|      2|  BN_free(&dmq1);
  911|      2|  BN_CTX_free(ctx);
  912|       |
  913|      2|  return ok;
  914|      2|}
bcm.c:check_mod_inverse:
  766|      6|                             BN_CTX *ctx) {
  767|      6|  if (BN_is_negative(ainv) || BN_cmp(ainv, m) >= 0) {
  ------------------
  |  Branch (767:7): [True: 0, False: 6]
  |  Branch (767:31): [True: 0, False: 6]
  ------------------
  768|      0|    *out_ok = 0;
  769|      0|    return 1;
  770|      0|  }
  771|       |
  772|       |  // Note |bn_mul_consttime| and |bn_div_consttime| do not scale linearly, but
  773|       |  // checking |ainv| is in range bounds the running time, assuming |m|'s bounds
  774|       |  // were checked by the caller.
  775|      6|  BN_CTX_start(ctx);
  776|      6|  BIGNUM *tmp = BN_CTX_get(ctx);
  777|      6|  int ret = tmp != NULL &&
  ------------------
  |  Branch (777:13): [True: 6, False: 0]
  ------------------
  778|      6|            bn_mul_consttime(tmp, a, ainv, ctx) &&
  ------------------
  |  Branch (778:13): [True: 6, False: 0]
  ------------------
  779|      6|            bn_div_consttime(NULL, tmp, tmp, m, m_min_bits, ctx);
  ------------------
  |  Branch (779:13): [True: 6, False: 0]
  ------------------
  780|      6|  if (ret) {
  ------------------
  |  Branch (780:7): [True: 6, False: 0]
  ------------------
  781|      6|    *out_ok = BN_is_one(tmp);
  782|      6|  }
  783|      6|  BN_CTX_end(ctx);
  784|      6|  return ret;
  785|      6|}

rsa_check_public_key:
   76|  22.7k|int rsa_check_public_key(const RSA *rsa) {
   77|  22.7k|  if (rsa->n == NULL) {
  ------------------
  |  Branch (77:7): [True: 0, False: 22.7k]
  ------------------
   78|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   79|      0|    return 0;
   80|      0|  }
   81|       |
   82|       |  // TODO(davidben): 16384-bit RSA is huge. Can we bring this down to a limit of
   83|       |  // 8192-bit?
   84|  22.7k|  unsigned n_bits = BN_num_bits(rsa->n);
   85|  22.7k|  if (n_bits > 16 * 1024) {
  ------------------
  |  Branch (85:7): [True: 0, False: 22.7k]
  ------------------
   86|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_MODULUS_TOO_LARGE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   87|      0|    return 0;
   88|      0|  }
   89|       |
   90|       |  // TODO(crbug.com/boringssl/607): Raise this limit. 512-bit RSA was factored
   91|       |  // in 1999.
   92|  22.7k|  if (n_bits < 512) {
  ------------------
  |  Branch (92:7): [True: 0, False: 22.7k]
  ------------------
   93|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_KEY_SIZE_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   94|      0|    return 0;
   95|      0|  }
   96|       |
   97|       |  // RSA moduli must be positive and odd. In addition to being necessary for RSA
   98|       |  // in general, we cannot setup Montgomery reduction with even moduli.
   99|  22.7k|  if (!BN_is_odd(rsa->n) || BN_is_negative(rsa->n)) {
  ------------------
  |  Branch (99:7): [True: 0, False: 22.7k]
  |  Branch (99:29): [True: 0, False: 22.7k]
  ------------------
  100|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  101|      0|    return 0;
  102|      0|  }
  103|       |
  104|  22.7k|  static const unsigned kMaxExponentBits = 33;
  105|  22.7k|  if (rsa->e != NULL) {
  ------------------
  |  Branch (105:7): [True: 22.7k, False: 0]
  ------------------
  106|       |    // Reject e = 1, negative e, and even e. e must be odd to be relatively
  107|       |    // prime with phi(n).
  108|  22.7k|    unsigned e_bits = BN_num_bits(rsa->e);
  109|  22.7k|    if (e_bits < 2 || BN_is_negative(rsa->e) || !BN_is_odd(rsa->e)) {
  ------------------
  |  Branch (109:9): [True: 0, False: 22.7k]
  |  Branch (109:23): [True: 0, False: 22.7k]
  |  Branch (109:49): [True: 0, False: 22.7k]
  ------------------
  110|      0|      OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  111|      0|      return 0;
  112|      0|    }
  113|  22.7k|    if (rsa->flags & RSA_FLAG_LARGE_PUBLIC_EXPONENT) {
  ------------------
  |  |  683|  22.7k|#define RSA_FLAG_LARGE_PUBLIC_EXPONENT 0x80
  ------------------
  |  Branch (113:9): [True: 0, False: 22.7k]
  ------------------
  114|       |      // The caller has requested disabling DoS protections. Still, e must be
  115|       |      // less than n.
  116|      0|      if (BN_ucmp(rsa->n, rsa->e) <= 0) {
  ------------------
  |  Branch (116:11): [True: 0, False: 0]
  ------------------
  117|      0|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|        return 0;
  119|      0|      }
  120|  22.7k|    } else {
  121|       |      // Mitigate DoS attacks by limiting the exponent size. 33 bits was chosen
  122|       |      // as the limit based on the recommendations in [1] and [2]. Windows
  123|       |      // CryptoAPI doesn't support values larger than 32 bits [3], so it is
  124|       |      // unlikely that exponents larger than 32 bits are being used for anything
  125|       |      // Windows commonly does.
  126|       |      //
  127|       |      // [1] https://www.imperialviolet.org/2012/03/16/rsae.html
  128|       |      // [2] https://www.imperialviolet.org/2012/03/17/rsados.html
  129|       |      // [3] https://msdn.microsoft.com/en-us/library/aa387685(VS.85).aspx
  130|  22.7k|      if (e_bits > kMaxExponentBits) {
  ------------------
  |  Branch (130:11): [True: 0, False: 22.7k]
  ------------------
  131|      0|        OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_E_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  132|      0|        return 0;
  133|      0|      }
  134|       |
  135|       |      // The upper bound on |e_bits| and lower bound on |n_bits| imply e is
  136|       |      // bounded by n.
  137|  22.7k|      assert(BN_ucmp(rsa->n, rsa->e) > 0);
  138|  22.7k|    }
  139|  22.7k|  } else if (!(rsa->flags & RSA_FLAG_NO_PUBLIC_EXPONENT)) {
  ------------------
  |  |  677|      0|#define RSA_FLAG_NO_PUBLIC_EXPONENT 0x40
  ------------------
  |  Branch (139:14): [True: 0, False: 0]
  ------------------
  140|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_VALUE_MISSING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  141|      0|    return 0;
  142|      0|  }
  143|       |
  144|  22.7k|  return 1;
  145|  22.7k|}
rsa_invalidate_key:
  289|  22.7k|void rsa_invalidate_key(RSA *rsa) {
  290|  22.7k|  rsa->private_key_frozen = 0;
  291|       |
  292|  22.7k|  BN_MONT_CTX_free(rsa->mont_n);
  293|  22.7k|  rsa->mont_n = NULL;
  294|  22.7k|  BN_MONT_CTX_free(rsa->mont_p);
  295|  22.7k|  rsa->mont_p = NULL;
  296|  22.7k|  BN_MONT_CTX_free(rsa->mont_q);
  297|  22.7k|  rsa->mont_q = NULL;
  298|       |
  299|  22.7k|  BN_free(rsa->d_fixed);
  300|  22.7k|  rsa->d_fixed = NULL;
  301|  22.7k|  BN_free(rsa->dmp1_fixed);
  302|  22.7k|  rsa->dmp1_fixed = NULL;
  303|  22.7k|  BN_free(rsa->dmq1_fixed);
  304|  22.7k|  rsa->dmq1_fixed = NULL;
  305|  22.7k|  BN_free(rsa->inv_small_mod_large_mont);
  306|  22.7k|  rsa->inv_small_mod_large_mont = NULL;
  307|       |
  308|  22.7k|  for (size_t i = 0; i < rsa->num_blindings; i++) {
  ------------------
  |  Branch (308:22): [True: 0, False: 22.7k]
  ------------------
  309|      0|    BN_BLINDING_free(rsa->blindings[i]);
  310|      0|  }
  311|  22.7k|  OPENSSL_free(rsa->blindings);
  312|  22.7k|  rsa->blindings = NULL;
  313|  22.7k|  rsa->num_blindings = 0;
  314|  22.7k|  OPENSSL_free(rsa->blindings_inuse);
  315|  22.7k|  rsa->blindings_inuse = NULL;
  316|  22.7k|  rsa->blinding_fork_generation = 0;
  317|  22.7k|}
bcm.c:RSA_default_method_do_init:
 1349|      2|DEFINE_METHOD_FUNCTION(RSA_METHOD, RSA_default_method) {
 1350|       |  // All of the methods are NULL to make it easier for the compiler/linker to
 1351|       |  // drop unused functions. The wrapper functions will select the appropriate
 1352|       |  // |rsa_default_*| implementation.
 1353|      2|  OPENSSL_memset(out, 0, sizeof(RSA_METHOD));
 1354|      2|  out->common.is_static = 1;
 1355|      2|}

bcm.c:FIPS_service_indicator_update_state:
   56|  4.83k|OPENSSL_INLINE void FIPS_service_indicator_update_state(void) {}

EVP_hpke_x25519_hkdf_sha256:
  295|  12.4k|const EVP_HPKE_KEM *EVP_hpke_x25519_hkdf_sha256(void) {
  296|  12.4k|  static const EVP_HPKE_KEM kKEM = {
  297|       |      /*id=*/EVP_HPKE_DHKEM_X25519_HKDF_SHA256,
  ------------------
  |  |   43|  12.4k|#define EVP_HPKE_DHKEM_X25519_HKDF_SHA256 0x0020
  ------------------
  298|       |      /*public_key_len=*/X25519_PUBLIC_VALUE_LEN,
  ------------------
  |  |   37|  12.4k|#define X25519_PUBLIC_VALUE_LEN 32
  ------------------
  299|       |      /*private_key_len=*/X25519_PRIVATE_KEY_LEN,
  ------------------
  |  |   36|  12.4k|#define X25519_PRIVATE_KEY_LEN 32
  ------------------
  300|       |      /*seed_len=*/X25519_PRIVATE_KEY_LEN,
  ------------------
  |  |   36|  12.4k|#define X25519_PRIVATE_KEY_LEN 32
  ------------------
  301|       |      /*enc_len=*/X25519_PUBLIC_VALUE_LEN,
  ------------------
  |  |   37|  12.4k|#define X25519_PUBLIC_VALUE_LEN 32
  ------------------
  302|  12.4k|      x25519_init_key,
  303|  12.4k|      x25519_generate_key,
  304|  12.4k|      x25519_encap_with_seed,
  305|  12.4k|      x25519_decap,
  306|  12.4k|      x25519_auth_encap_with_seed,
  307|  12.4k|      x25519_auth_decap,
  308|  12.4k|  };
  309|  12.4k|  return &kKEM;
  310|  12.4k|}
EVP_HPKE_KEM_id:
  312|    551|uint16_t EVP_HPKE_KEM_id(const EVP_HPKE_KEM *kem) { return kem->id; }
EVP_HPKE_KEY_zero:
  324|  36.7k|void EVP_HPKE_KEY_zero(EVP_HPKE_KEY *key) {
  325|  36.7k|  OPENSSL_memset(key, 0, sizeof(EVP_HPKE_KEY));
  326|  36.7k|}
EVP_HPKE_KEY_cleanup:
  328|  24.2k|void EVP_HPKE_KEY_cleanup(EVP_HPKE_KEY *key) {
  329|       |  // Nothing to clean up for now, but we may introduce a cleanup process in the
  330|       |  // future.
  331|  24.2k|}
EVP_HPKE_KEY_init:
  356|  12.4k|                      const uint8_t *priv_key, size_t priv_key_len) {
  357|  12.4k|  EVP_HPKE_KEY_zero(key);
  358|  12.4k|  key->kem = kem;
  359|  12.4k|  if (!kem->init_key(key, priv_key, priv_key_len)) {
  ------------------
  |  Branch (359:7): [True: 728, False: 11.7k]
  ------------------
  360|    728|    key->kem = NULL;
  361|    728|    return 0;
  362|    728|  }
  363|  11.7k|  return 1;
  364|  12.4k|}
EVP_HPKE_KEY_kem:
  376|    551|const EVP_HPKE_KEM *EVP_HPKE_KEY_kem(const EVP_HPKE_KEY *key) {
  377|    551|  return key->kem;
  378|    551|}
EVP_HPKE_KEY_public_key:
  381|    551|                            size_t *out_len, size_t max_out) {
  382|    551|  if (max_out < key->kem->public_key_len) {
  ------------------
  |  Branch (382:7): [True: 0, False: 551]
  ------------------
  383|      0|    OPENSSL_PUT_ERROR(EVP, EVP_R_INVALID_BUFFER_SIZE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  384|      0|    return 0;
  385|      0|  }
  386|    551|  OPENSSL_memcpy(out, key->public_key, key->kem->public_key_len);
  387|    551|  *out_len = key->kem->public_key_len;
  388|    551|  return 1;
  389|    551|}
EVP_hpke_aes_128_gcm:
  416|    910|const EVP_HPKE_AEAD *EVP_hpke_aes_128_gcm(void) {
  417|    910|  static const EVP_HPKE_AEAD kAEAD = {EVP_HPKE_AES_128_GCM,
  ------------------
  |  |   93|    910|#define EVP_HPKE_AES_128_GCM 0x0001
  ------------------
  418|    910|                                      &EVP_aead_aes_128_gcm};
  419|    910|  return &kAEAD;
  420|    910|}
EVP_hpke_aes_256_gcm:
  422|    614|const EVP_HPKE_AEAD *EVP_hpke_aes_256_gcm(void) {
  423|    614|  static const EVP_HPKE_AEAD kAEAD = {EVP_HPKE_AES_256_GCM,
  ------------------
  |  |   94|    614|#define EVP_HPKE_AES_256_GCM 0x0002
  ------------------
  424|    614|                                      &EVP_aead_aes_256_gcm};
  425|    614|  return &kAEAD;
  426|    614|}
EVP_hpke_chacha20_poly1305:
  428|    609|const EVP_HPKE_AEAD *EVP_hpke_chacha20_poly1305(void) {
  429|    609|  static const EVP_HPKE_AEAD kAEAD = {EVP_HPKE_CHACHA20_POLY1305,
  ------------------
  |  |   95|    609|#define EVP_HPKE_CHACHA20_POLY1305 0x0003
  ------------------
  430|    609|                                      &EVP_aead_chacha20_poly1305};
  431|    609|  return &kAEAD;
  432|    609|}
EVP_HPKE_AEAD_id:
  434|  2.13k|uint16_t EVP_HPKE_AEAD_id(const EVP_HPKE_AEAD *aead) { return aead->id; }
EVP_HPKE_CTX_zero:
  540|  4.83k|void EVP_HPKE_CTX_zero(EVP_HPKE_CTX *ctx) {
  541|  4.83k|  OPENSSL_memset(ctx, 0, sizeof(EVP_HPKE_CTX));
  542|  4.83k|  EVP_AEAD_CTX_zero(&ctx->aead_ctx);
  543|  4.83k|}
EVP_HPKE_CTX_cleanup:
  545|  4.83k|void EVP_HPKE_CTX_cleanup(EVP_HPKE_CTX *ctx) {
  546|  4.83k|  EVP_AEAD_CTX_cleanup(&ctx->aead_ctx);
  547|  4.83k|}
hpke.c:x25519_init_key:
  148|  12.4k|                           size_t priv_key_len) {
  149|  12.4k|  if (priv_key_len != X25519_PRIVATE_KEY_LEN) {
  ------------------
  |  |   36|  12.4k|#define X25519_PRIVATE_KEY_LEN 32
  ------------------
  |  Branch (149:7): [True: 728, False: 11.7k]
  ------------------
  150|    728|    OPENSSL_PUT_ERROR(EVP, EVP_R_DECODE_ERROR);
  ------------------
  |  |  441|    728|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  151|    728|    return 0;
  152|    728|  }
  153|       |
  154|  11.7k|  OPENSSL_memcpy(key->private_key, priv_key, priv_key_len);
  155|  11.7k|  X25519_public_from_private(key->public_key, priv_key);
  156|  11.7k|  return 1;
  157|  12.4k|}

ssl_ctx_api.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|  55.7k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  55.7k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 9.12k, False: 46.6k]
  ------------------
 1041|  9.12k|    return dst;
 1042|  9.12k|  }
 1043|       |
 1044|  46.6k|  return memcpy(dst, src, n);
 1045|  55.7k|}
encrypted_client_hello.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|  7.49k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  7.49k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 7.49k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  7.49k|  return memcpy(dst, src, n);
 1045|  7.49k|}
_ZN4bssl8internal13MutexLockBaseIXadL_Z23CRYPTO_MUTEX_lock_writeEEXadL_Z25CRYPTO_MUTEX_unlock_writeEEEC2EP15crypto_mutex_st:
  821|  21.9k|  explicit MutexLockBase(CRYPTO_MUTEX *mu) : mu_(mu) {
  822|  21.9k|    assert(mu_ != nullptr);
  823|      0|    LockFunc(mu_);
  824|  21.9k|  }
_ZN4bssl8internal13MutexLockBaseIXadL_Z23CRYPTO_MUTEX_lock_writeEEXadL_Z25CRYPTO_MUTEX_unlock_writeEEED2Ev:
  825|  21.9k|  ~MutexLockBase() { ReleaseFunc(mu_); }
_ZN4bssl8internal13MutexLockBaseIXadL_Z22CRYPTO_MUTEX_lock_readEEXadL_Z24CRYPTO_MUTEX_unlock_readEEEC2EP15crypto_mutex_st:
  821|  4.94k|  explicit MutexLockBase(CRYPTO_MUTEX *mu) : mu_(mu) {
  822|  4.94k|    assert(mu_ != nullptr);
  823|      0|    LockFunc(mu_);
  824|  4.94k|  }
_ZN4bssl8internal13MutexLockBaseIXadL_Z22CRYPTO_MUTEX_lock_readEEXadL_Z24CRYPTO_MUTEX_unlock_readEEED2Ev:
  825|  4.94k|  ~MutexLockBase() { ReleaseFunc(mu_); }
ssl_aead_ctx.cc:_ZL14OPENSSL_memsetPvim:
 1055|  9.66k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  9.66k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 9.66k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  9.66k|  return memset(dst, c, n);
 1061|  9.66k|}
ssl_cert.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|  9.66k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  9.66k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 4.77k, False: 4.88k]
  ------------------
 1041|  4.77k|    return dst;
 1042|  4.77k|  }
 1043|       |
 1044|  4.88k|  return memcpy(dst, src, n);
 1045|  9.66k|}
ssl_cipher.cc:_ZL14OPENSSL_memsetPvim:
 1055|  5.47k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  5.47k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 5.47k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  5.47k|  return memset(dst, c, n);
 1061|  5.47k|}
ssl_cipher.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|  22.7k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  22.7k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 10.4k, False: 12.3k]
  ------------------
 1041|  10.4k|    return dst;
 1042|  10.4k|  }
 1043|       |
 1044|  12.3k|  return memcpy(dst, src, n);
 1045|  22.7k|}
ssl_lib.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|  18.8k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  18.8k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 17.0k, False: 1.82k]
  ------------------
 1041|  17.0k|    return dst;
 1042|  17.0k|  }
 1043|       |
 1044|  1.82k|  return memcpy(dst, src, n);
 1045|  18.8k|}
ssl_privkey.cc:_ZL14OPENSSL_memcpyPvPKvm:
 1039|  3.77k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  3.77k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 3.77k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  3.77k|  return memcpy(dst, src, n);
 1045|  3.77k|}
bcm.c:CRYPTO_is_AESNI_capable:
 1324|  41.9k|OPENSSL_INLINE int CRYPTO_is_AESNI_capable(void) {
 1325|       |#if defined(__AES__)
 1326|       |  return 1;
 1327|       |#else
 1328|  41.9k|  return (OPENSSL_ia32cap_get()[1] & (1 << 25)) != 0;
 1329|  41.9k|#endif
 1330|  41.9k|}
bcm.c:OPENSSL_ia32cap_get:
 1270|  83.8k|OPENSSL_INLINE const uint32_t *OPENSSL_ia32cap_get(void) {
 1271|  83.8k|  return OPENSSL_ia32cap_P;
 1272|  83.8k|}
bcm.c:CRYPTO_load_u32_be:
 1080|  33.8k|static inline uint32_t CRYPTO_load_u32_be(const void *in) {
 1081|  33.8k|  uint32_t v;
 1082|  33.8k|  OPENSSL_memcpy(&v, in, sizeof(v));
 1083|  33.8k|  return CRYPTO_bswap4(v);
 1084|  33.8k|}
bcm.c:CRYPTO_bswap4:
  945|  67.6k|static inline uint32_t CRYPTO_bswap4(uint32_t x) {
  946|  67.6k|  return __builtin_bswap32(x);
  947|  67.6k|}
bcm.c:CRYPTO_store_u32_be:
 1086|  33.8k|static inline void CRYPTO_store_u32_be(void *out, uint32_t v) {
 1087|  33.8k|  v = CRYPTO_bswap4(v);
 1088|  33.8k|  OPENSSL_memcpy(out, &v, sizeof(v));
 1089|  33.8k|}
bcm.c:OPENSSL_memcpy:
 1039|   855k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   855k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 45.5k, False: 809k]
  ------------------
 1041|  45.5k|    return dst;
 1042|  45.5k|  }
 1043|       |
 1044|   809k|  return memcpy(dst, src, n);
 1045|   855k|}
bcm.c:constant_time_is_zero_w:
  427|   548k|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|   548k|  return constant_time_msb_w(~a & (a - 1));
  440|   548k|}
bcm.c:constant_time_msb_w:
  368|  1.07M|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|  1.07M|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|  1.07M|}
bcm.c:constant_time_eq_w:
  450|   525k|                                               crypto_word_t b) {
  451|   525k|  return constant_time_is_zero_w(a ^ b);
  452|   525k|}
bcm.c:constant_time_select_w:
  477|  1.20M|                                                   crypto_word_t b) {
  478|       |  // Clang recognizes this pattern as a select. While it usually transforms it
  479|       |  // to a cmov, it sometimes further transforms it into a branch, which we do
  480|       |  // not want.
  481|       |  //
  482|       |  // Hiding the value of the mask from the compiler evades this transformation.
  483|  1.20M|  mask = value_barrier_w(mask);
  484|  1.20M|  return (mask & a) | (~mask & b);
  485|  1.20M|}
bcm.c:value_barrier_w:
  340|  1.20M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|  1.20M|#if defined(__GNUC__) || defined(__clang__)
  342|  1.20M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|  1.20M|#endif
  344|  1.20M|  return a;
  345|  1.20M|}
bcm.c:OPENSSL_memset:
 1055|   162k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   162k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 45.4k, False: 116k]
  ------------------
 1057|  45.4k|    return dst;
 1058|  45.4k|  }
 1059|       |
 1060|   116k|  return memset(dst, c, n);
 1061|   162k|}
bcm.c:CRYPTO_load_word_be:
 1122|   727k|static inline crypto_word_t CRYPTO_load_word_be(const void *in) {
 1123|   727k|  crypto_word_t v;
 1124|   727k|  OPENSSL_memcpy(&v, in, sizeof(v));
 1125|   727k|#if defined(OPENSSL_64_BIT)
 1126|   727k|  static_assert(sizeof(v) == 8, "crypto_word_t has unexpected size");
 1127|   727k|  return CRYPTO_bswap8(v);
 1128|       |#else
 1129|       |  static_assert(sizeof(v) == 4, "crypto_word_t has unexpected size");
 1130|       |  return CRYPTO_bswap4(v);
 1131|       |#endif
 1132|   727k|}
bcm.c:CRYPTO_bswap8:
  949|   727k|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|   727k|  return __builtin_bswap64(x);
  951|   727k|}
bcm.c:constant_time_select_int:
  503|  1.07M|static inline int constant_time_select_int(crypto_word_t mask, int a, int b) {
  504|  1.07M|  return (int)(constant_time_select_w(mask, (crypto_word_t)(a),
  505|  1.07M|                                      (crypto_word_t)(b)));
  506|  1.07M|}
bcm.c:constant_time_lt_w:
  374|   525k|                                               crypto_word_t b) {
  375|       |  // Consider the two cases of the problem:
  376|       |  //   msb(a) == msb(b): a < b iff the MSB of a - b is set.
  377|       |  //   msb(a) != msb(b): a < b iff the MSB of b is set.
  378|       |  //
  379|       |  // If msb(a) == msb(b) then the following evaluates as:
  380|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  381|       |  //   msb(a^((a-b) ^ a))       ==   (because msb(a^b) == 0)
  382|       |  //   msb(a^a^(a-b))           ==   (rearranging)
  383|       |  //   msb(a-b)                      (because ∀x. x^x == 0)
  384|       |  //
  385|       |  // Else, if msb(a) != msb(b) then the following evaluates as:
  386|       |  //   msb(a^((a^b)|((a-b)^a))) ==
  387|       |  //   msb(a^(𝟙 | ((a-b)^a)))   ==   (because msb(a^b) == 1 and 𝟙
  388|       |  //                                  represents a value s.t. msb(𝟙) = 1)
  389|       |  //   msb(a^𝟙)                 ==   (because ORing with 1 results in 1)
  390|       |  //   msb(b)
  391|       |  //
  392|       |  //
  393|       |  // Here is an SMT-LIB verification of this formula:
  394|       |  //
  395|       |  // (define-fun lt ((a (_ BitVec 32)) (b (_ BitVec 32))) (_ BitVec 32)
  396|       |  //   (bvxor a (bvor (bvxor a b) (bvxor (bvsub a b) a)))
  397|       |  // )
  398|       |  //
  399|       |  // (declare-fun a () (_ BitVec 32))
  400|       |  // (declare-fun b () (_ BitVec 32))
  401|       |  //
  402|       |  // (assert (not (= (= #x00000001 (bvlshr (lt a b) #x0000001f)) (bvult a b))))
  403|       |  // (check-sat)
  404|       |  // (get-model)
  405|   525k|  return constant_time_msb_w(a^((a^b)|((a-b)^a)));
  406|   525k|}
bcm.c:CRYPTO_is_FXSR_capable:
 1277|  32.2k|OPENSSL_INLINE int CRYPTO_is_FXSR_capable(void) {
 1278|  32.2k|#if defined(__FXSR__)
 1279|  32.2k|  return 1;
 1280|       |#else
 1281|       |  return (OPENSSL_ia32cap_get()[0] & (1 << 24)) != 0;
 1282|       |#endif
 1283|  32.2k|}
bcm.c:CRYPTO_is_PCLMUL_capable:
 1292|  32.2k|OPENSSL_INLINE int CRYPTO_is_PCLMUL_capable(void) {
 1293|       |#if defined(__PCLMUL__)
 1294|       |  return 1;
 1295|       |#else
 1296|  32.2k|  return (OPENSSL_ia32cap_get()[1] & (1 << 1)) != 0;
 1297|  32.2k|#endif
 1298|  32.2k|}
bcm.c:CRYPTO_atomic_load_u32:
  626|  4.83k|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|  4.83k|  return atomic_load(val);
  628|  4.83k|}
bcm.c:CRYPTO_atomic_store_u32:
  636|      1|                                            uint32_t desired) {
  637|      1|  atomic_store(val, desired);
  638|      1|}
bcm.c:CRYPTO_is_RDRAND_capable:
 1340|  4.83k|OPENSSL_INLINE int CRYPTO_is_RDRAND_capable(void) {
 1341|       |  // The GCC/Clang feature name and preprocessor symbol for RDRAND are "rdrnd"
 1342|       |  // and |__RDRND__|, respectively.
 1343|       |#if defined(__RDRND__)
 1344|       |  return 1;
 1345|       |#else
 1346|  4.83k|  return (OPENSSL_ia32cap_get()[1] & (1u << 30)) != 0;
 1347|  4.83k|#endif
 1348|  4.83k|}
bcm.c:CRYPTO_is_intel_cpu:
 1285|  4.83k|OPENSSL_INLINE int CRYPTO_is_intel_cpu(void) {
 1286|       |  // The reserved bit 30 is used to indicate an Intel CPU.
 1287|  4.83k|  return (OPENSSL_ia32cap_get()[0] & (1 << 30)) != 0;
 1288|  4.83k|}
buf.c:OPENSSL_memset:
 1055|   125k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   125k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 125k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   125k|  return memset(dst, c, n);
 1061|   125k|}
cbb.c:OPENSSL_memset:
 1055|   181k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   181k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 181k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   181k|  return memset(dst, c, n);
 1061|   181k|}
cbb.c:OPENSSL_memmove:
 1047|  33.7k|static inline void *OPENSSL_memmove(void *dst, const void *src, size_t n) {
 1048|  33.7k|  if (n == 0) {
  ------------------
  |  Branch (1048:7): [True: 0, False: 33.7k]
  ------------------
 1049|      0|    return dst;
 1050|      0|  }
 1051|       |
 1052|  33.7k|  return memmove(dst, src, n);
 1053|  33.7k|}
curve25519.c:CRYPTO_is_BMI1_capable:
 1352|  11.7k|OPENSSL_INLINE int CRYPTO_is_BMI1_capable(void) {
 1353|       |#if defined(__BMI1__)
 1354|       |  return 1;
 1355|       |#else
 1356|  11.7k|  return (OPENSSL_ia32cap_get()[2] & (1 << 3)) != 0;
 1357|  11.7k|#endif
 1358|  11.7k|}
curve25519.c:OPENSSL_ia32cap_get:
 1270|  35.2k|OPENSSL_INLINE const uint32_t *OPENSSL_ia32cap_get(void) {
 1271|  35.2k|  return OPENSSL_ia32cap_P;
 1272|  35.2k|}
curve25519.c:CRYPTO_is_BMI2_capable:
 1368|  11.7k|OPENSSL_INLINE int CRYPTO_is_BMI2_capable(void) {
 1369|       |#if defined(__BMI2__)
 1370|       |  return 1;
 1371|       |#else
 1372|  11.7k|  return (OPENSSL_ia32cap_get()[2] & (1 << 8)) != 0;
 1373|  11.7k|#endif
 1374|  11.7k|}
curve25519.c:CRYPTO_is_ADX_capable:
 1376|  11.7k|OPENSSL_INLINE int CRYPTO_is_ADX_capable(void) {
 1377|       |#if defined(__ADX__)
 1378|       |  return 1;
 1379|       |#else
 1380|  11.7k|  return (OPENSSL_ia32cap_get()[2] & (1 << 19)) != 0;
 1381|  11.7k|#endif
 1382|  11.7k|}
curve25519.c:OPENSSL_memcpy:
 1039|  11.7k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  11.7k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 11.7k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  11.7k|  return memcpy(dst, src, n);
 1045|  11.7k|}
curve25519_64_adx.c:OPENSSL_memcpy:
 1039|   763k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   763k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 763k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|   763k|  return memcpy(dst, src, n);
 1045|   763k|}
curve25519_64_adx.c:constant_time_msb_w:
  368|  8.27M|static inline crypto_word_t constant_time_msb_w(crypto_word_t a) {
  369|  8.27M|  return 0u - (a >> (sizeof(a) * 8 - 1));
  370|  8.27M|}
curve25519_64_adx.c:constant_time_is_zero_w:
  427|  7.52M|static inline crypto_word_t constant_time_is_zero_w(crypto_word_t a) {
  428|       |  // Here is an SMT-LIB verification of this formula:
  429|       |  //
  430|       |  // (define-fun is_zero ((a (_ BitVec 32))) (_ BitVec 32)
  431|       |  //   (bvand (bvnot a) (bvsub a #x00000001))
  432|       |  // )
  433|       |  //
  434|       |  // (declare-fun a () (_ BitVec 32))
  435|       |  //
  436|       |  // (assert (not (= (= #x00000001 (bvlshr (is_zero a) #x0000001f)) (= a #x00000000))))
  437|       |  // (check-sat)
  438|       |  // (get-model)
  439|  7.52M|  return constant_time_msb_w(~a & (a - 1));
  440|  7.52M|}
curve25519_64_adx.c:constant_time_conditional_memxor:
  527|  6.01M|                                                    const crypto_word_t mask) {
  528|  6.01M|  assert(!buffers_alias(dst, n, src, n));
  529|  6.01M|  uint8_t *out = (uint8_t *)dst;
  530|  6.01M|  const uint8_t *in = (const uint8_t *)src;
  531|   583M|  for (size_t i = 0; i < n; i++) {
  ------------------
  |  Branch (531:22): [True: 577M, False: 6.01M]
  ------------------
  532|   577M|    out[i] ^= value_barrier_w(mask) & in[i];
  533|   577M|  }
  534|  6.01M|}
curve25519_64_adx.c:buffers_alias:
  269|  8.27M|                                const void *b, size_t b_bytes) {
  270|       |  // Cast |a| and |b| to integers. In C, pointer comparisons between unrelated
  271|       |  // objects are undefined whereas pointer to integer conversions are merely
  272|       |  // implementation-defined. We assume the implementation defined it in a sane
  273|       |  // way.
  274|  8.27M|  uintptr_t a_u = (uintptr_t)a;
  275|  8.27M|  uintptr_t b_u = (uintptr_t)b;
  276|  8.27M|  return a_u + a_bytes > b_u && b_u + b_bytes > a_u;
  ------------------
  |  Branch (276:10): [True: 6.01M, False: 2.25M]
  |  Branch (276:33): [True: 0, False: 6.01M]
  ------------------
  277|  8.27M|}
curve25519_64_adx.c:value_barrier_w:
  340|   649M|static inline crypto_word_t value_barrier_w(crypto_word_t a) {
  341|   649M|#if defined(__GNUC__) || defined(__clang__)
  342|   649M|  __asm__("" : "+r"(a) : /* no inputs */);
  343|   649M|#endif
  344|   649M|  return a;
  345|   649M|}
curve25519_64_adx.c:constant_time_eq_w:
  450|  6.01M|                                               crypto_word_t b) {
  451|  6.01M|  return constant_time_is_zero_w(a ^ b);
  452|  6.01M|}
curve25519_64_adx.c:constant_time_conditional_memcpy:
  513|  2.25M|                                                    const crypto_word_t mask) {
  514|  2.25M|  assert(!buffers_alias(dst, n, src, n));
  515|  2.25M|  uint8_t *out = (uint8_t *)dst;
  516|  2.25M|  const uint8_t *in = (const uint8_t *)src;
  517|  74.4M|  for (size_t i = 0; i < n; i++) {
  ------------------
  |  Branch (517:22): [True: 72.1M, False: 2.25M]
  ------------------
  518|  72.1M|    out[i] = constant_time_select_8(mask, in[i], out[i]);
  519|  72.1M|  }
  520|  2.25M|}
curve25519_64_adx.c:constant_time_select_8:
  490|  72.1M|                                             uint8_t b) {
  491|       |  // |mask| is a word instead of |uint8_t| to avoid materializing 0x000..0MM
  492|       |  // Making both |mask| and its value barrier |uint8_t| would allow the compiler
  493|       |  // to materialize 0x????..?MM instead, but only clang is that clever.
  494|       |  // However, vectorization of bitwise operations seems to work better on
  495|       |  // |uint8_t| than a mix of |uint64_t| and |uint8_t|, so |m| is cast to
  496|       |  // |uint8_t| after the value barrier but before the bitwise operations.
  497|  72.1M|  uint8_t m = value_barrier_w(mask);
  498|  72.1M|  return (m & a) | (~m & b);
  499|  72.1M|}
err.c:OPENSSL_memset:
 1055|   198k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   198k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 198k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   198k|  return memset(dst, c, n);
 1061|   198k|}
evp.c:OPENSSL_memset:
 1055|  22.7k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  22.7k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 22.7k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  22.7k|  return memset(dst, c, n);
 1061|  22.7k|}
evp_asn1.c:OPENSSL_memcmp:
 1031|  22.7k|static inline int OPENSSL_memcmp(const void *s1, const void *s2, size_t n) {
 1032|  22.7k|  if (n == 0) {
  ------------------
  |  Branch (1032:7): [True: 0, False: 22.7k]
  ------------------
 1033|      0|    return 0;
 1034|      0|  }
 1035|       |
 1036|  22.7k|  return memcmp(s1, s2, n);
 1037|  22.7k|}
hpke.c:OPENSSL_memset:
 1055|  41.5k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  41.5k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 41.5k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  41.5k|  return memset(dst, c, n);
 1061|  41.5k|}
hpke.c:OPENSSL_memcpy:
 1039|  12.3k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  12.3k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 12.3k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  12.3k|  return memcpy(dst, src, n);
 1045|  12.3k|}
lhash.c:OPENSSL_memset:
 1055|  9.66k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  9.66k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 9.66k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  9.66k|  return memset(dst, c, n);
 1061|  9.66k|}
mem.c:OPENSSL_memset:
 1055|  2.92M|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  2.92M|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 2.92M]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  2.92M|  return memset(dst, c, n);
 1061|  2.92M|}
mem.c:OPENSSL_memcpy:
 1039|  96.0k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  96.0k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 96.0k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  96.0k|  return memcpy(dst, src, n);
 1045|  96.0k|}
pool.c:OPENSSL_memset:
 1055|  56.4k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  56.4k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 56.4k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  56.4k|  return memset(dst, c, n);
 1061|  56.4k|}
deterministic.c:OPENSSL_memset:
 1055|      4|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      4|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 4]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      4|  return memset(dst, c, n);
 1061|      4|}
deterministic.c:OPENSSL_memcpy:
 1039|      2|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      2|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 2]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      2|  return memcpy(dst, src, n);
 1045|      2|}
forkunsafe.c:CRYPTO_atomic_load_u32:
  626|  4.83k|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|  4.83k|  return atomic_load(val);
  628|  4.83k|}
refcount.c:CRYPTO_atomic_load_u32:
  626|   270k|OPENSSL_INLINE uint32_t CRYPTO_atomic_load_u32(CRYPTO_atomic_u32 *val) {
  627|   270k|  return atomic_load(val);
  628|   270k|}
refcount.c:CRYPTO_atomic_compare_exchange_weak_u32:
  631|   270k|    CRYPTO_atomic_u32 *val, uint32_t *expected, uint32_t desired) {
  632|   270k|  return atomic_compare_exchange_weak(val, expected, desired);
  633|   270k|}
stack.c:OPENSSL_memset:
 1055|   694k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   694k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 694k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   694k|  return memset(dst, c, n);
 1061|   694k|}
stack.c:OPENSSL_memcpy:
 1039|    828|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|    828|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 828]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|    828|  return memcpy(dst, src, n);
 1045|    828|}
thread_pthread.c:OPENSSL_memset:
 1055|      1|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|      1|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 1]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|      1|  return memset(dst, c, n);
 1061|      1|}
x509_lu.c:OPENSSL_memset:
 1055|  4.83k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  4.83k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 4.83k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  4.83k|  return memset(dst, c, n);
 1061|  4.83k|}
x509_vpm.c:OPENSSL_memset:
 1055|  14.4k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  14.4k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 14.4k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  14.4k|  return memset(dst, c, n);
 1061|  14.4k|}
x_name.c:OPENSSL_memcpy:
 1039|  43.8k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  43.8k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 43.8k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  43.8k|  return memcpy(dst, src, n);
 1045|  43.8k|}
x_x509.c:OPENSSL_memset:
 1055|  20.0k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|  20.0k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 20.0k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|  20.0k|  return memset(dst, c, n);
 1061|  20.0k|}
a_bitstr.c:OPENSSL_memcpy:
 1039|  33.7k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  33.7k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 33.7k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  33.7k|  return memcpy(dst, src, n);
 1045|  33.7k|}
a_int.c:OPENSSL_memcpy:
 1039|  40.1k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  40.1k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 40.1k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  40.1k|  return memcpy(dst, src, n);
 1045|  40.1k|}
a_int.c:CRYPTO_bswap8:
  949|  20.0k|static inline uint64_t CRYPTO_bswap8(uint64_t x) {
  950|  20.0k|  return __builtin_bswap64(x);
  951|  20.0k|}
a_int.c:CRYPTO_load_u64_be:
 1101|  20.0k|static inline uint64_t CRYPTO_load_u64_be(const void *ptr) {
 1102|  20.0k|  uint64_t ret;
 1103|  20.0k|  OPENSSL_memcpy(&ret, ptr, sizeof(ret));
 1104|  20.0k|  return CRYPTO_bswap8(ret);
 1105|  20.0k|}
asn1_lib.c:OPENSSL_memcpy:
 1039|   200k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   200k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 200k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|   200k|  return memcpy(dst, src, n);
 1045|   200k|}
tasn_enc.c:OPENSSL_memcpy:
 1039|   114k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   114k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 114k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|   114k|  return memcpy(dst, src, n);
 1045|   114k|}
tasn_new.c:OPENSSL_memset:
 1055|   281k|static inline void *OPENSSL_memset(void *dst, int c, size_t n) {
 1056|   281k|  if (n == 0) {
  ------------------
  |  Branch (1056:7): [True: 0, False: 281k]
  ------------------
 1057|      0|    return dst;
 1058|      0|  }
 1059|       |
 1060|   281k|  return memset(dst, c, n);
 1061|   281k|}
tasn_utl.c:OPENSSL_memcpy:
 1039|  33.7k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|  33.7k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 33.7k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|  33.7k|  return memcpy(dst, src, n);
 1045|  33.7k|}
chacha.c:OPENSSL_memcpy:
 1039|      6|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|      6|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 6]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|      6|  return memcpy(dst, src, n);
 1045|      6|}
chacha.c:buffers_alias:
  269|      2|                                const void *b, size_t b_bytes) {
  270|       |  // Cast |a| and |b| to integers. In C, pointer comparisons between unrelated
  271|       |  // objects are undefined whereas pointer to integer conversions are merely
  272|       |  // implementation-defined. We assume the implementation defined it in a sane
  273|       |  // way.
  274|      2|  uintptr_t a_u = (uintptr_t)a;
  275|      2|  uintptr_t b_u = (uintptr_t)b;
  276|      2|  return a_u + a_bytes > b_u && b_u + b_bytes > a_u;
  ------------------
  |  Branch (276:10): [True: 2, False: 0]
  |  Branch (276:33): [True: 2, False: 0]
  ------------------
  277|      2|}
chacha.c:CRYPTO_load_u32_le:
 1070|      6|static inline uint32_t CRYPTO_load_u32_le(const void *in) {
 1071|      6|  uint32_t v;
 1072|      6|  OPENSSL_memcpy(&v, in, sizeof(v));
 1073|      6|  return v;
 1074|      6|}
obj.c:OPENSSL_memcpy:
 1039|   221k|static inline void *OPENSSL_memcpy(void *dst, const void *src, size_t n) {
 1040|   221k|  if (n == 0) {
  ------------------
  |  Branch (1040:7): [True: 0, False: 221k]
  ------------------
 1041|      0|    return dst;
 1042|      0|  }
 1043|       |
 1044|   221k|  return memcpy(dst, src, n);
 1045|   221k|}

_Z18lh_SSL_SESSION_newPFjPK14ssl_session_stEPFiS1_S1_E:
  186|  4.83k|      lhash_##type##_hash_func hash, lhash_##type##_cmp_func comp) {           \
  187|  4.83k|    return (LHASH_OF(type) *)OPENSSL_lh_new((lhash_hash_func)hash,             \
  188|  4.83k|                                            (lhash_cmp_func)comp);             \
  189|  4.83k|  }                                                                            \
_Z19lh_SSL_SESSION_freeP20lhash_st_SSL_SESSION:
  191|  4.83k|  OPENSSL_INLINE void lh_##type##_free(LHASH_OF(type) *lh) {                   \
  192|  4.83k|    OPENSSL_lh_free((_LHASH *)lh);                                             \
  193|  4.83k|  }                                                                            \
_Z24lh_SSL_SESSION_num_itemsPK20lhash_st_SSL_SESSION:
  195|  4.94k|  OPENSSL_INLINE size_t lh_##type##_num_items(const LHASH_OF(type) *lh) {      \
  196|  4.94k|    return OPENSSL_lh_num_items((const _LHASH *)lh);                           \
  197|  4.94k|  }                                                                            \
_Z24lh_SSL_SESSION_doall_argP20lhash_st_SSL_SESSIONPFvP14ssl_session_stPvES3_:
  253|  9.18k|      LHASH_OF(type) *lh, void (*func)(type *, void *), void *arg) {           \
  254|  9.18k|    LHASH_DOALL_##type cb = {func, arg};                                       \
  255|  9.18k|    OPENSSL_lh_doall_arg((_LHASH *)lh, lh_##type##_call_doall_arg, &cb);       \
  256|  9.18k|  }                                                                            \

OPENSSL_lh_new:
  106|  4.83k|_LHASH *OPENSSL_lh_new(lhash_hash_func hash, lhash_cmp_func comp) {
  107|  4.83k|  _LHASH *ret = OPENSSL_malloc(sizeof(_LHASH));
  108|  4.83k|  if (ret == NULL) {
  ------------------
  |  Branch (108:7): [True: 0, False: 4.83k]
  ------------------
  109|      0|    return NULL;
  110|      0|  }
  111|  4.83k|  OPENSSL_memset(ret, 0, sizeof(_LHASH));
  112|       |
  113|  4.83k|  ret->num_buckets = kMinNumBuckets;
  114|  4.83k|  ret->buckets = OPENSSL_malloc(sizeof(LHASH_ITEM *) * ret->num_buckets);
  115|  4.83k|  if (ret->buckets == NULL) {
  ------------------
  |  Branch (115:7): [True: 0, False: 4.83k]
  ------------------
  116|      0|    OPENSSL_free(ret);
  117|      0|    return NULL;
  118|      0|  }
  119|  4.83k|  OPENSSL_memset(ret->buckets, 0, sizeof(LHASH_ITEM *) * ret->num_buckets);
  120|       |
  121|  4.83k|  ret->comp = comp;
  122|  4.83k|  ret->hash = hash;
  123|  4.83k|  return ret;
  124|  4.83k|}
OPENSSL_lh_free:
  126|  4.83k|void OPENSSL_lh_free(_LHASH *lh) {
  127|  4.83k|  if (lh == NULL) {
  ------------------
  |  Branch (127:7): [True: 0, False: 4.83k]
  ------------------
  128|      0|    return;
  129|      0|  }
  130|       |
  131|  82.1k|  for (size_t i = 0; i < lh->num_buckets; i++) {
  ------------------
  |  Branch (131:22): [True: 77.2k, False: 4.83k]
  ------------------
  132|  77.2k|    LHASH_ITEM *next;
  133|  77.2k|    for (LHASH_ITEM *n = lh->buckets[i]; n != NULL; n = next) {
  ------------------
  |  Branch (133:42): [True: 0, False: 77.2k]
  ------------------
  134|      0|      next = n->next;
  135|      0|      OPENSSL_free(n);
  136|      0|    }
  137|  77.2k|  }
  138|       |
  139|  4.83k|  OPENSSL_free(lh->buckets);
  140|  4.83k|  OPENSSL_free(lh);
  141|  4.83k|}
OPENSSL_lh_num_items:
  143|  4.94k|size_t OPENSSL_lh_num_items(const _LHASH *lh) { return lh->num_items; }
OPENSSL_lh_doall_arg:
  327|  9.18k|void OPENSSL_lh_doall_arg(_LHASH *lh, void (*func)(void *, void *), void *arg) {
  328|  9.18k|  if (lh == NULL) {
  ------------------
  |  Branch (328:7): [True: 0, False: 9.18k]
  ------------------
  329|      0|    return;
  330|      0|  }
  331|       |
  332|  9.18k|  if (lh->callback_depth < UINT_MAX) {
  ------------------
  |  Branch (332:7): [True: 9.18k, False: 0]
  ------------------
  333|       |    // |callback_depth| is a saturating counter.
  334|  9.18k|    lh->callback_depth++;
  335|  9.18k|  }
  336|       |
  337|   156k|  for (size_t i = 0; i < lh->num_buckets; i++) {
  ------------------
  |  Branch (337:22): [True: 146k, False: 9.18k]
  ------------------
  338|   146k|    LHASH_ITEM *next;
  339|   146k|    for (LHASH_ITEM *cur = lh->buckets[i]; cur != NULL; cur = next) {
  ------------------
  |  Branch (339:44): [True: 0, False: 146k]
  ------------------
  340|      0|      next = cur->next;
  341|      0|      func(cur->data, arg);
  342|      0|    }
  343|   146k|  }
  344|       |
  345|  9.18k|  if (lh->callback_depth < UINT_MAX) {
  ------------------
  |  Branch (345:7): [True: 9.18k, False: 0]
  ------------------
  346|  9.18k|    lh->callback_depth--;
  347|  9.18k|  }
  348|       |
  349|       |  // The callback may have added or removed elements and the non-zero value of
  350|       |  // |callback_depth| will have suppressed any resizing. Thus any needed
  351|       |  // resizing is done here.
  352|  9.18k|  lh_maybe_resize(lh);
  353|  9.18k|}
lhash.c:lh_maybe_resize:
  239|  9.18k|static void lh_maybe_resize(_LHASH *lh) {
  240|  9.18k|  size_t avg_chain_length;
  241|       |
  242|  9.18k|  if (lh->callback_depth > 0) {
  ------------------
  |  Branch (242:7): [True: 0, False: 9.18k]
  ------------------
  243|       |    // Don't resize the hash if we are currently iterating over it.
  244|      0|    return;
  245|      0|  }
  246|       |
  247|  9.18k|  assert(lh->num_buckets >= kMinNumBuckets);
  248|  9.18k|  avg_chain_length = lh->num_items / lh->num_buckets;
  249|       |
  250|  9.18k|  if (avg_chain_length > kMaxAverageChainLength) {
  ------------------
  |  Branch (250:7): [True: 0, False: 9.18k]
  ------------------
  251|      0|    const size_t new_num_buckets = lh->num_buckets * 2;
  252|       |
  253|      0|    if (new_num_buckets > lh->num_buckets) {
  ------------------
  |  Branch (253:9): [True: 0, False: 0]
  ------------------
  254|      0|      lh_rebucket(lh, new_num_buckets);
  255|      0|    }
  256|  9.18k|  } else if (avg_chain_length < kMinAverageChainLength &&
  ------------------
  |  Branch (256:14): [True: 9.18k, False: 0]
  ------------------
  257|  9.18k|             lh->num_buckets > kMinNumBuckets) {
  ------------------
  |  Branch (257:14): [True: 0, False: 9.18k]
  ------------------
  258|      0|    size_t new_num_buckets = lh->num_buckets / 2;
  259|       |
  260|      0|    if (new_num_buckets < kMinNumBuckets) {
  ------------------
  |  Branch (260:9): [True: 0, False: 0]
  ------------------
  261|      0|      new_num_buckets = kMinNumBuckets;
  262|      0|    }
  263|       |
  264|      0|    lh_rebucket(lh, new_num_buckets);
  265|      0|  }
  266|  9.18k|}

OPENSSL_malloc:
  228|  2.92M|void *OPENSSL_malloc(size_t size) {
  229|  2.92M|  if (should_fail_allocation()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 2.92M]
  ------------------
  230|      0|    goto err;
  231|      0|  }
  232|       |
  233|  2.92M|  if (OPENSSL_memory_alloc != NULL) {
  ------------------
  |  Branch (233:7): [True: 0, False: 2.92M]
  ------------------
  234|      0|    assert(OPENSSL_memory_free != NULL);
  235|      0|    assert(OPENSSL_memory_get_size != NULL);
  236|      0|    void *ptr = OPENSSL_memory_alloc(size);
  237|      0|    if (ptr == NULL && size != 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  |  Branch (237:24): [True: 0, False: 0]
  ------------------
  238|      0|      goto err;
  239|      0|    }
  240|      0|    return ptr;
  241|      0|  }
  242|       |
  243|  2.92M|  if (size + OPENSSL_MALLOC_PREFIX < size) {
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  |  Branch (243:7): [True: 0, False: 2.92M]
  ------------------
  244|       |    // |OPENSSL_malloc| is a central function in BoringSSL thus a reference to
  245|       |    // |kBoringSSLBinaryTag| is created here so that the tag isn't discarded by
  246|       |    // the linker. The following is sufficient to stop GCC, Clang, and MSVC
  247|       |    // optimising away the reference at the time of writing. Since this
  248|       |    // probably results in an actual memory reference, it is put in this very
  249|       |    // rare code path.
  250|      0|    uint8_t unused = *(volatile uint8_t *)kBoringSSLBinaryTag;
  251|      0|    (void) unused;
  252|      0|    goto err;
  253|      0|  }
  254|       |
  255|  2.92M|  void *ptr = malloc(size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  256|  2.92M|  if (ptr == NULL) {
  ------------------
  |  Branch (256:7): [True: 0, False: 2.92M]
  ------------------
  257|      0|    goto err;
  258|      0|  }
  259|       |
  260|  2.92M|  *(size_t *)ptr = size;
  261|       |
  262|  2.92M|  __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  263|  2.92M|  return ((uint8_t *)ptr) + OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  264|       |
  265|      0| err:
  266|       |  // This only works because ERR does not call OPENSSL_malloc.
  267|      0|  OPENSSL_PUT_ERROR(CRYPTO, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  268|      0|  return NULL;
  269|  2.92M|}
OPENSSL_free:
  271|  4.05M|void OPENSSL_free(void *orig_ptr) {
  272|  4.05M|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (272:7): [True: 1.13M, False: 2.92M]
  ------------------
  273|  1.13M|    return;
  274|  1.13M|  }
  275|       |
  276|  2.92M|  if (OPENSSL_memory_free != NULL) {
  ------------------
  |  Branch (276:7): [True: 0, False: 2.92M]
  ------------------
  277|      0|    OPENSSL_memory_free(orig_ptr);
  278|      0|    return;
  279|      0|  }
  280|       |
  281|  2.92M|  void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  282|  2.92M|  __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  283|       |
  284|  2.92M|  size_t size = *(size_t *)ptr;
  285|  2.92M|  OPENSSL_cleanse(ptr, size + OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|  2.92M|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  286|       |
  287|       |// ASan knows to intercept malloc and free, but not sdallocx.
  288|       |#if defined(OPENSSL_ASAN)
  289|       |  (void)sdallocx;
  290|       |  free(ptr);
  291|       |#else
  292|  2.92M|  if (sdallocx) {
  ------------------
  |  Branch (292:7): [True: 0, False: 2.92M]
  ------------------
  293|      0|    sdallocx(ptr, size + OPENSSL_MALLOC_PREFIX, 0 /* flags */);
  ------------------
  |  |   83|      0|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  294|  2.92M|  } else {
  295|  2.92M|    free(ptr);
  296|  2.92M|  }
  297|  2.92M|#endif
  298|  2.92M|}
OPENSSL_realloc:
  300|   163k|void *OPENSSL_realloc(void *orig_ptr, size_t new_size) {
  301|   163k|  if (orig_ptr == NULL) {
  ------------------
  |  Branch (301:7): [True: 40.1k, False: 123k]
  ------------------
  302|  40.1k|    return OPENSSL_malloc(new_size);
  303|  40.1k|  }
  304|       |
  305|   123k|  size_t old_size;
  306|   123k|  if (OPENSSL_memory_get_size != NULL) {
  ------------------
  |  Branch (306:7): [True: 0, False: 123k]
  ------------------
  307|      0|    old_size = OPENSSL_memory_get_size(orig_ptr);
  308|   123k|  } else {
  309|   123k|    void *ptr = ((uint8_t *)orig_ptr) - OPENSSL_MALLOC_PREFIX;
  ------------------
  |  |   83|   123k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  310|   123k|    __asan_unpoison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|   123k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  311|   123k|    old_size = *(size_t *)ptr;
  312|   123k|    __asan_poison_memory_region(ptr, OPENSSL_MALLOC_PREFIX);
  ------------------
  |  |   83|   123k|#define OPENSSL_MALLOC_PREFIX 8
  ------------------
  313|   123k|  }
  314|       |
  315|   123k|  void *ret = OPENSSL_malloc(new_size);
  316|   123k|  if (ret == NULL) {
  ------------------
  |  Branch (316:7): [True: 0, False: 123k]
  ------------------
  317|      0|    return NULL;
  318|      0|  }
  319|       |
  320|   123k|  size_t to_copy = new_size;
  321|   123k|  if (old_size < to_copy) {
  ------------------
  |  Branch (321:7): [True: 123k, False: 0]
  ------------------
  322|   123k|    to_copy = old_size;
  323|   123k|  }
  324|       |
  325|   123k|  memcpy(ret, orig_ptr, to_copy);
  326|   123k|  OPENSSL_free(orig_ptr);
  327|       |
  328|   123k|  return ret;
  329|   123k|}
OPENSSL_cleanse:
  331|  2.92M|void OPENSSL_cleanse(void *ptr, size_t len) {
  332|       |#if defined(OPENSSL_WINDOWS)
  333|       |  SecureZeroMemory(ptr, len);
  334|       |#else
  335|  2.92M|  OPENSSL_memset(ptr, 0, len);
  336|       |
  337|  2.92M|#if !defined(OPENSSL_NO_ASM)
  338|       |  /* As best as we can tell, this is sufficient to break any optimisations that
  339|       |     might try to eliminate "superfluous" memsets. If there's an easy way to
  340|       |     detect memset_s, it would be better to use that. */
  341|  2.92M|  __asm__ __volatile__("" : : "r"(ptr) : "memory");
  342|  2.92M|#endif
  343|  2.92M|#endif  // !OPENSSL_NO_ASM
  344|  2.92M|}
OPENSSL_isalpha:
  413|   268k|int OPENSSL_isalpha(int c) {
  414|   268k|  return (c >= 'a' && c <= 'z') || (c >= 'A' && c <= 'Z');
  ------------------
  |  Branch (414:11): [True: 15.1k, False: 253k]
  |  Branch (414:23): [True: 12.8k, False: 2.31k]
  |  Branch (414:37): [True: 183k, False: 72.1k]
  |  Branch (414:49): [True: 177k, False: 6.33k]
  ------------------
  415|   268k|}
OPENSSL_isdigit:
  417|   564k|int OPENSSL_isdigit(int c) { return c >= '0' && c <= '9'; }
  ------------------
  |  Branch (417:37): [True: 529k, False: 34.8k]
  |  Branch (417:49): [True: 509k, False: 20.1k]
  ------------------
OPENSSL_isxdigit:
  419|  3.51k|int OPENSSL_isxdigit(int c) {
  420|  3.51k|  return OPENSSL_isdigit(c) || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F');
  ------------------
  |  Branch (420:10): [True: 678, False: 2.83k]
  |  Branch (420:33): [True: 1.64k, False: 1.18k]
  |  Branch (420:45): [True: 1.30k, False: 338]
  |  Branch (420:59): [True: 1.26k, False: 254]
  |  Branch (420:71): [True: 884, False: 385]
  ------------------
  421|  3.51k|}
OPENSSL_isalnum:
  439|   268k|int OPENSSL_isalnum(int c) { return OPENSSL_isalpha(c) || OPENSSL_isdigit(c); }
  ------------------
  |  Branch (439:37): [True: 190k, False: 78.4k]
  |  Branch (439:59): [True: 26.2k, False: 52.2k]
  ------------------
OPENSSL_tolower:
  441|   241k|int OPENSSL_tolower(int c) {
  442|   241k|  if (c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (442:7): [True: 241k, False: 0]
  |  Branch (442:19): [True: 80.3k, False: 160k]
  ------------------
  443|  80.3k|    return c + ('a' - 'A');
  444|  80.3k|  }
  445|   160k|  return c;
  446|   241k|}
OPENSSL_isspace:
  448|   401k|int OPENSSL_isspace(int c) {
  449|   401k|  return c == '\t' || c == '\n' || c == '\v' || c == '\f' || c == '\r' ||
  ------------------
  |  Branch (449:10): [True: 0, False: 401k]
  |  Branch (449:23): [True: 0, False: 401k]
  |  Branch (449:36): [True: 0, False: 401k]
  |  Branch (449:49): [True: 0, False: 401k]
  |  Branch (449:62): [True: 0, False: 401k]
  ------------------
  450|   401k|         c == ' ';
  ------------------
  |  Branch (450:10): [True: 40.1k, False: 361k]
  ------------------
  451|   401k|}
OPENSSL_vasprintf_internal:
  498|  13.2k|                               int system_malloc) {
  499|  13.2k|  void *(*allocate)(size_t) = system_malloc ? malloc : OPENSSL_malloc;
  ------------------
  |  Branch (499:31): [True: 13.2k, False: 0]
  ------------------
  500|  13.2k|  void (*deallocate)(void *) = system_malloc ? free : OPENSSL_free;
  ------------------
  |  Branch (500:32): [True: 13.2k, False: 0]
  ------------------
  501|  13.2k|  void *(*reallocate)(void *, size_t) =
  502|  13.2k|      system_malloc ? realloc : OPENSSL_realloc;
  ------------------
  |  Branch (502:7): [True: 13.2k, False: 0]
  ------------------
  503|  13.2k|  char *candidate = NULL;
  504|  13.2k|  size_t candidate_len = 64;  // TODO(bbe) what's the best initial size?
  505|       |
  506|  13.2k|  if ((candidate = allocate(candidate_len)) == NULL) {
  ------------------
  |  Branch (506:7): [True: 0, False: 13.2k]
  ------------------
  507|      0|    goto err;
  508|      0|  }
  509|  13.2k|  va_list args_copy;
  510|  13.2k|  va_copy(args_copy, args);
  511|  13.2k|  int ret = vsnprintf(candidate, candidate_len, format, args_copy);
  512|  13.2k|  va_end(args_copy);
  513|  13.2k|  if (ret < 0) {
  ------------------
  |  Branch (513:7): [True: 0, False: 13.2k]
  ------------------
  514|      0|    goto err;
  515|      0|  }
  516|  13.2k|  if ((size_t)ret >= candidate_len) {
  ------------------
  |  Branch (516:7): [True: 0, False: 13.2k]
  ------------------
  517|       |    // Too big to fit in allocation.
  518|      0|    char *tmp;
  519|       |
  520|      0|    candidate_len = (size_t)ret + 1;
  521|      0|    if ((tmp = reallocate(candidate, candidate_len)) == NULL) {
  ------------------
  |  Branch (521:9): [True: 0, False: 0]
  ------------------
  522|      0|      goto err;
  523|      0|    }
  524|      0|    candidate = tmp;
  525|      0|    ret = vsnprintf(candidate, candidate_len, format, args);
  526|      0|  }
  527|       |  // At this point this should not happen unless vsnprintf is insane.
  528|  13.2k|  if (ret < 0 || (size_t)ret >= candidate_len) {
  ------------------
  |  Branch (528:7): [True: 0, False: 13.2k]
  |  Branch (528:18): [True: 0, False: 13.2k]
  ------------------
  529|      0|    goto err;
  530|      0|  }
  531|  13.2k|  *str = candidate;
  532|  13.2k|  return ret;
  533|       |
  534|      0| err:
  535|      0|  deallocate(candidate);
  536|      0|  *str = NULL;
  537|      0|  errno = ENOMEM;
  538|      0|  return -1;
  539|  13.2k|}
OPENSSL_memdup:
  595|  96.6k|void *OPENSSL_memdup(const void *data, size_t size) {
  596|  96.6k|  if (size == 0) {
  ------------------
  |  Branch (596:7): [True: 637, False: 96.0k]
  ------------------
  597|    637|    return NULL;
  598|    637|  }
  599|       |
  600|  96.0k|  void *ret = OPENSSL_malloc(size);
  601|  96.0k|  if (ret == NULL) {
  ------------------
  |  Branch (601:7): [True: 0, False: 96.0k]
  ------------------
  602|      0|    return NULL;
  603|      0|  }
  604|       |
  605|  96.0k|  OPENSSL_memcpy(ret, data, size);
  606|  96.0k|  return ret;
  607|  96.0k|}
mem.c:should_fail_allocation:
  225|  2.92M|static int should_fail_allocation(void) { return 0; }
mem.c:__asan_poison_memory_region:
   90|  3.04M|static void __asan_poison_memory_region(const void *addr, size_t size) {}
mem.c:__asan_unpoison_memory_region:
   91|  3.04M|static void __asan_unpoison_memory_region(const void *addr, size_t size) {}

OBJ_dup:
  101|   221k|ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o) {
  102|   221k|  ASN1_OBJECT *r;
  103|   221k|  unsigned char *data = NULL;
  104|   221k|  char *sn = NULL, *ln = NULL;
  105|       |
  106|   221k|  if (o == NULL) {
  ------------------
  |  Branch (106:7): [True: 0, False: 221k]
  ------------------
  107|      0|    return NULL;
  108|      0|  }
  109|       |
  110|   221k|  if (!(o->flags & ASN1_OBJECT_FLAG_DYNAMIC)) {
  ------------------
  |  |  105|   221k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
  |  Branch (110:7): [True: 0, False: 221k]
  ------------------
  111|       |    // TODO(fork): this is a little dangerous.
  112|      0|    return (ASN1_OBJECT *)o;
  113|      0|  }
  114|       |
  115|   221k|  r = ASN1_OBJECT_new();
  116|   221k|  if (r == NULL) {
  ------------------
  |  Branch (116:7): [True: 0, False: 221k]
  ------------------
  117|      0|    OPENSSL_PUT_ERROR(OBJ, ERR_R_ASN1_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  118|      0|    return NULL;
  119|      0|  }
  120|   221k|  r->ln = r->sn = NULL;
  121|       |
  122|   221k|  data = OPENSSL_malloc(o->length);
  123|   221k|  if (data == NULL) {
  ------------------
  |  Branch (123:7): [True: 0, False: 221k]
  ------------------
  124|      0|    goto err;
  125|      0|  }
  126|   221k|  if (o->data != NULL) {
  ------------------
  |  Branch (126:7): [True: 221k, False: 0]
  ------------------
  127|   221k|    OPENSSL_memcpy(data, o->data, o->length);
  128|   221k|  }
  129|       |
  130|       |  // once data is attached to an object, it remains const
  131|   221k|  r->data = data;
  132|   221k|  r->length = o->length;
  133|   221k|  r->nid = o->nid;
  134|       |
  135|   221k|  if (o->ln != NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 221k]
  ------------------
  136|      0|    ln = OPENSSL_strdup(o->ln);
  137|      0|    if (ln == NULL) {
  ------------------
  |  Branch (137:9): [True: 0, False: 0]
  ------------------
  138|      0|      goto err;
  139|      0|    }
  140|      0|  }
  141|       |
  142|   221k|  if (o->sn != NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 221k]
  ------------------
  143|      0|    sn = OPENSSL_strdup(o->sn);
  144|      0|    if (sn == NULL) {
  ------------------
  |  Branch (144:9): [True: 0, False: 0]
  ------------------
  145|      0|      goto err;
  146|      0|    }
  147|      0|  }
  148|       |
  149|   221k|  r->sn = sn;
  150|   221k|  r->ln = ln;
  151|       |
  152|   221k|  r->flags =
  153|   221k|      o->flags | (ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  105|   221k|#define ASN1_OBJECT_FLAG_DYNAMIC 0x01          // internal use
  ------------------
                    o->flags | (ASN1_OBJECT_FLAG_DYNAMIC | ASN1_OBJECT_FLAG_DYNAMIC_STRINGS |
  ------------------
  |  |  106|   221k|#define ASN1_OBJECT_FLAG_DYNAMIC_STRINGS 0x04  // internal use
  ------------------
  154|   221k|                  ASN1_OBJECT_FLAG_DYNAMIC_DATA);
  ------------------
  |  |  107|   221k|#define ASN1_OBJECT_FLAG_DYNAMIC_DATA 0x08     // internal use
  ------------------
  155|   221k|  return r;
  156|       |
  157|      0|err:
  158|      0|  OPENSSL_free(ln);
  159|      0|  OPENSSL_free(sn);
  160|      0|  OPENSSL_free(data);
  161|      0|  OPENSSL_free(r);
  162|      0|  return NULL;
  163|   221k|}
OBJ_nid2obj:
  344|   221k|ASN1_OBJECT *OBJ_nid2obj(int nid) {
  345|   221k|  if (nid >= 0 && nid < NUM_NID) {
  ------------------
  |  |   60|   221k|#define NUM_NID 965
  ------------------
  |  Branch (345:7): [True: 221k, False: 0]
  |  Branch (345:19): [True: 221k, False: 0]
  ------------------
  346|   221k|    if (nid != NID_undef && kObjects[nid].nid == NID_undef) {
  ------------------
  |  |   85|   442k|#define NID_undef 0
  ------------------
                  if (nid != NID_undef && kObjects[nid].nid == NID_undef) {
  ------------------
  |  |   85|      0|#define NID_undef 0
  ------------------
  |  Branch (346:9): [True: 0, False: 221k]
  |  Branch (346:29): [True: 0, False: 0]
  ------------------
  347|      0|      goto err;
  348|      0|    }
  349|   221k|    return (ASN1_OBJECT *)&kObjects[nid];
  350|   221k|  }
  351|       |
  352|      0|  CRYPTO_STATIC_MUTEX_lock_read(&global_added_lock);
  353|      0|  if (global_added_by_nid != NULL) {
  ------------------
  |  Branch (353:7): [True: 0, False: 0]
  ------------------
  354|      0|    ASN1_OBJECT *match, template;
  355|       |
  356|      0|    template.nid = nid;
  357|      0|    match = lh_ASN1_OBJECT_retrieve(global_added_by_nid, &template);
  358|      0|    if (match != NULL) {
  ------------------
  |  Branch (358:9): [True: 0, False: 0]
  ------------------
  359|      0|      CRYPTO_STATIC_MUTEX_unlock_read(&global_added_lock);
  360|      0|      return match;
  361|      0|    }
  362|      0|  }
  363|      0|  CRYPTO_STATIC_MUTEX_unlock_read(&global_added_lock);
  364|       |
  365|      0|err:
  366|      0|  OPENSSL_PUT_ERROR(OBJ, OBJ_R_UNKNOWN_NID);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  367|      0|  return NULL;
  368|      0|}

CRYPTO_BUFFER_new:
  168|  56.4k|                                 CRYPTO_BUFFER_POOL *pool) {
  169|  56.4k|  return crypto_buffer_new(data, len, /*data_is_static=*/0, pool);
  170|  56.4k|}
CRYPTO_BUFFER_free:
  201|   101k|void CRYPTO_BUFFER_free(CRYPTO_BUFFER *buf) {
  202|   101k|  if (buf == NULL) {
  ------------------
  |  Branch (202:7): [True: 108, False: 101k]
  ------------------
  203|    108|    return;
  204|    108|  }
  205|       |
  206|   101k|  CRYPTO_BUFFER_POOL *const pool = buf->pool;
  207|   101k|  if (pool == NULL) {
  ------------------
  |  Branch (207:7): [True: 101k, False: 0]
  ------------------
  208|   101k|    if (CRYPTO_refcount_dec_and_test_zero(&buf->references)) {
  ------------------
  |  Branch (208:9): [True: 56.4k, False: 45.1k]
  ------------------
  209|       |      // If a reference count of zero is observed, there cannot be a reference
  210|       |      // from any pool to this buffer and thus we are able to free this
  211|       |      // buffer.
  212|  56.4k|      crypto_buffer_free_object(buf);
  213|  56.4k|    }
  214|       |
  215|   101k|    return;
  216|   101k|  }
  217|       |
  218|      0|  CRYPTO_MUTEX_lock_write(&pool->lock);
  219|      0|  if (!CRYPTO_refcount_dec_and_test_zero(&buf->references)) {
  ------------------
  |  Branch (219:7): [True: 0, False: 0]
  ------------------
  220|      0|    CRYPTO_MUTEX_unlock_write(&buf->pool->lock);
  221|      0|    return;
  222|      0|  }
  223|       |
  224|       |  // We have an exclusive lock on the pool, therefore no concurrent lookups can
  225|       |  // find this buffer and increment the reference count. Thus, if the count is
  226|       |  // zero there are and can never be any more references and thus we can free
  227|       |  // this buffer.
  228|       |  //
  229|       |  // Note it is possible |buf| is no longer in the pool, if it was replaced by a
  230|       |  // static version. If that static version was since removed, it is even
  231|       |  // possible for |found| to be NULL.
  232|      0|  CRYPTO_BUFFER *found = lh_CRYPTO_BUFFER_retrieve(pool->bufs, buf);
  233|      0|  if (found == buf) {
  ------------------
  |  Branch (233:7): [True: 0, False: 0]
  ------------------
  234|      0|    found = lh_CRYPTO_BUFFER_delete(pool->bufs, buf);
  235|      0|    assert(found == buf);
  236|      0|    (void)found;
  237|      0|  }
  238|       |
  239|      0|  CRYPTO_MUTEX_unlock_write(&buf->pool->lock);
  240|      0|  crypto_buffer_free_object(buf);
  241|      0|}
CRYPTO_BUFFER_up_ref:
  243|  45.1k|int CRYPTO_BUFFER_up_ref(CRYPTO_BUFFER *buf) {
  244|       |  // This is safe in the case that |buf->pool| is NULL because it's just
  245|       |  // standard reference counting in that case.
  246|       |  //
  247|       |  // This is also safe if |buf->pool| is non-NULL because, if it were racing
  248|       |  // with |CRYPTO_BUFFER_free| then the two callers must have independent
  249|       |  // references already and so the reference count will never hit zero.
  250|  45.1k|  CRYPTO_refcount_inc(&buf->references);
  251|  45.1k|  return 1;
  252|  45.1k|}
CRYPTO_BUFFER_data:
  254|  1.42M|const uint8_t *CRYPTO_BUFFER_data(const CRYPTO_BUFFER *buf) {
  255|  1.42M|  return buf->data;
  256|  1.42M|}
CRYPTO_BUFFER_len:
  258|   723k|size_t CRYPTO_BUFFER_len(const CRYPTO_BUFFER *buf) {
  259|   723k|  return buf->len;
  260|   723k|}
CRYPTO_BUFFER_init_CBS:
  262|  22.7k|void CRYPTO_BUFFER_init_CBS(const CRYPTO_BUFFER *buf, CBS *out) {
  263|  22.7k|  CBS_init(out, buf->data, buf->len);
  264|  22.7k|}
pool.c:crypto_buffer_new:
   88|  56.4k|                                        CRYPTO_BUFFER_POOL *pool) {
   89|  56.4k|  if (pool != NULL) {
  ------------------
  |  Branch (89:7): [True: 0, False: 56.4k]
  ------------------
   90|      0|    CRYPTO_BUFFER tmp;
   91|      0|    tmp.data = (uint8_t *) data;
   92|      0|    tmp.len = len;
   93|      0|    tmp.pool = pool;
   94|       |
   95|      0|    CRYPTO_MUTEX_lock_read(&pool->lock);
   96|      0|    CRYPTO_BUFFER *duplicate = lh_CRYPTO_BUFFER_retrieve(pool->bufs, &tmp);
   97|      0|    if (data_is_static && duplicate != NULL && !duplicate->data_is_static) {
  ------------------
  |  Branch (97:9): [True: 0, False: 0]
  |  Branch (97:27): [True: 0, False: 0]
  |  Branch (97:48): [True: 0, False: 0]
  ------------------
   98|       |      // If the new |CRYPTO_BUFFER| would have static data, but the duplicate
   99|       |      // does not, we replace the old one with the new static version.
  100|      0|      duplicate = NULL;
  101|      0|    }
  102|      0|    if (duplicate != NULL) {
  ------------------
  |  Branch (102:9): [True: 0, False: 0]
  ------------------
  103|      0|      CRYPTO_refcount_inc(&duplicate->references);
  104|      0|    }
  105|      0|    CRYPTO_MUTEX_unlock_read(&pool->lock);
  106|       |
  107|      0|    if (duplicate != NULL) {
  ------------------
  |  Branch (107:9): [True: 0, False: 0]
  ------------------
  108|      0|      return duplicate;
  109|      0|    }
  110|      0|  }
  111|       |
  112|  56.4k|  CRYPTO_BUFFER *const buf = OPENSSL_malloc(sizeof(CRYPTO_BUFFER));
  113|  56.4k|  if (buf == NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 56.4k]
  ------------------
  114|      0|    return NULL;
  115|      0|  }
  116|  56.4k|  OPENSSL_memset(buf, 0, sizeof(CRYPTO_BUFFER));
  117|       |
  118|  56.4k|  if (data_is_static) {
  ------------------
  |  Branch (118:7): [True: 0, False: 56.4k]
  ------------------
  119|      0|    buf->data = (uint8_t *)data;
  120|      0|    buf->data_is_static = 1;
  121|  56.4k|  } else {
  122|  56.4k|    buf->data = OPENSSL_memdup(data, len);
  123|  56.4k|    if (len != 0 && buf->data == NULL) {
  ------------------
  |  Branch (123:9): [True: 55.8k, False: 637]
  |  Branch (123:21): [True: 0, False: 55.8k]
  ------------------
  124|      0|      OPENSSL_free(buf);
  125|      0|      return NULL;
  126|      0|    }
  127|  56.4k|  }
  128|       |
  129|  56.4k|  buf->len = len;
  130|  56.4k|  buf->references = 1;
  131|       |
  132|  56.4k|  if (pool == NULL) {
  ------------------
  |  Branch (132:7): [True: 56.4k, False: 0]
  ------------------
  133|  56.4k|    return buf;
  134|  56.4k|  }
  135|       |
  136|      0|  buf->pool = pool;
  137|       |
  138|      0|  CRYPTO_MUTEX_lock_write(&pool->lock);
  139|      0|  CRYPTO_BUFFER *duplicate = lh_CRYPTO_BUFFER_retrieve(pool->bufs, buf);
  140|      0|  if (data_is_static && duplicate != NULL && !duplicate->data_is_static) {
  ------------------
  |  Branch (140:7): [True: 0, False: 0]
  |  Branch (140:25): [True: 0, False: 0]
  |  Branch (140:46): [True: 0, False: 0]
  ------------------
  141|       |    // If the new |CRYPTO_BUFFER| would have static data, but the duplicate does
  142|       |    // not, we replace the old one with the new static version.
  143|      0|    duplicate = NULL;
  144|      0|  }
  145|      0|  int inserted = 0;
  146|      0|  if (duplicate == NULL) {
  ------------------
  |  Branch (146:7): [True: 0, False: 0]
  ------------------
  147|      0|    CRYPTO_BUFFER *old = NULL;
  148|      0|    inserted = lh_CRYPTO_BUFFER_insert(pool->bufs, &old, buf);
  149|       |    // |old| may be non-NULL if a match was found but ignored. |pool->bufs| does
  150|       |    // not increment refcounts, so there is no need to clean up after the
  151|       |    // replacement.
  152|      0|  } else {
  153|      0|    CRYPTO_refcount_inc(&duplicate->references);
  154|      0|  }
  155|      0|  CRYPTO_MUTEX_unlock_write(&pool->lock);
  156|       |
  157|      0|  if (!inserted) {
  ------------------
  |  Branch (157:7): [True: 0, False: 0]
  ------------------
  158|       |    // We raced to insert |buf| into the pool and lost, or else there was an
  159|       |    // error inserting.
  160|      0|    crypto_buffer_free_object(buf);
  161|      0|    return duplicate;
  162|      0|  }
  163|       |
  164|      0|  return buf;
  165|      0|}
pool.c:crypto_buffer_free_object:
   79|  56.4k|static void crypto_buffer_free_object(CRYPTO_BUFFER *buf) {
   80|  56.4k|  if (!buf->data_is_static) {
  ------------------
  |  Branch (80:7): [True: 56.4k, False: 0]
  ------------------
   81|  56.4k|    OPENSSL_free(buf->data);
   82|  56.4k|  }
   83|  56.4k|  OPENSSL_free(buf);
   84|  56.4k|}

CRYPTO_sysrand:
   37|      2|void CRYPTO_sysrand(uint8_t *out, size_t requested) {
   38|      2|  static const uint8_t kZeroKey[32];
   39|       |
   40|      2|  CRYPTO_STATIC_MUTEX_lock_write(&g_num_calls_lock);
   41|      2|  uint64_t num_calls = g_num_calls++;
   42|      2|  CRYPTO_STATIC_MUTEX_unlock_write(&g_num_calls_lock);
   43|       |
   44|      2|  uint8_t nonce[12];
   45|      2|  OPENSSL_memset(nonce, 0, sizeof(nonce));
   46|      2|  OPENSSL_memcpy(nonce, &num_calls, sizeof(num_calls));
   47|       |
   48|      2|  OPENSSL_memset(out, 0, requested);
   49|      2|  CRYPTO_chacha_20(out, out, requested, kZeroKey, nonce, 0);
   50|      2|}
CRYPTO_sysrand_for_seed:
   52|      2|void CRYPTO_sysrand_for_seed(uint8_t *out, size_t requested) {
   53|      2|  CRYPTO_sysrand(out, requested);
   54|      2|}

rand_fork_unsafe_buffering_enabled:
   38|  4.83k|int rand_fork_unsafe_buffering_enabled(void) {
   39|  4.83k|  return CRYPTO_atomic_load_u32(&g_buffering_enabled) != 0;
   40|  4.83k|}

CRYPTO_refcount_inc:
   31|  61.7k|void CRYPTO_refcount_inc(CRYPTO_refcount_t *in_count) {
   32|  61.7k|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   33|  61.7k|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   34|       |
   35|  61.7k|  while (expected != CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|  61.7k|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (35:10): [True: 61.7k, False: 0]
  ------------------
   36|  61.7k|    uint32_t new_value = expected + 1;
   37|  61.7k|    if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected, new_value)) {
  ------------------
  |  Branch (37:9): [True: 61.7k, False: 0]
  ------------------
   38|  61.7k|      break;
   39|  61.7k|    }
   40|  61.7k|  }
   41|  61.7k|}
CRYPTO_refcount_dec_and_test_zero:
   43|   208k|int CRYPTO_refcount_dec_and_test_zero(CRYPTO_refcount_t *in_count) {
   44|   208k|  CRYPTO_atomic_u32 *count = (CRYPTO_atomic_u32 *)in_count;
   45|   208k|  uint32_t expected = CRYPTO_atomic_load_u32(count);
   46|       |
   47|   208k|  for (;;) {
   48|   208k|    if (expected == 0) {
  ------------------
  |  Branch (48:9): [True: 0, False: 208k]
  ------------------
   49|      0|      abort();
   50|   208k|    } else if (expected == CRYPTO_REFCOUNT_MAX) {
  ------------------
  |  |  718|   208k|#define CRYPTO_REFCOUNT_MAX 0xffffffff
  ------------------
  |  Branch (50:16): [True: 0, False: 208k]
  ------------------
   51|      0|      return 0;
   52|   208k|    } else {
   53|   208k|      const uint32_t new_value = expected - 1;
   54|   208k|      if (CRYPTO_atomic_compare_exchange_weak_u32(count, &expected,
  ------------------
  |  Branch (54:11): [True: 208k, False: 0]
  ------------------
   55|   208k|                                                  new_value)) {
   56|   208k|        return new_value == 0;
   57|   208k|      }
   58|   208k|    }
   59|   208k|  }
   60|   208k|}

RSA_parse_public_key:
   90|  22.7k|RSA *RSA_parse_public_key(CBS *cbs) {
   91|  22.7k|  RSA *ret = RSA_new();
   92|  22.7k|  if (ret == NULL) {
  ------------------
  |  Branch (92:7): [True: 0, False: 22.7k]
  ------------------
   93|      0|    return NULL;
   94|      0|  }
   95|  22.7k|  CBS child;
   96|  22.7k|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (96:7): [True: 0, False: 22.7k]
  ------------------
   97|  22.7k|      !parse_integer(&child, &ret->n) ||
  ------------------
  |  Branch (97:7): [True: 0, False: 22.7k]
  ------------------
   98|  22.7k|      !parse_integer(&child, &ret->e) ||
  ------------------
  |  Branch (98:7): [True: 0, False: 22.7k]
  ------------------
   99|  22.7k|      CBS_len(&child) != 0) {
  ------------------
  |  Branch (99:7): [True: 0, False: 22.7k]
  ------------------
  100|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  101|      0|    RSA_free(ret);
  102|      0|    return NULL;
  103|      0|  }
  104|       |
  105|  22.7k|  if (!RSA_check_key(ret)) {
  ------------------
  |  Branch (105:7): [True: 0, False: 22.7k]
  ------------------
  106|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  107|      0|    RSA_free(ret);
  108|      0|    return NULL;
  109|      0|  }
  110|       |
  111|  22.7k|  return ret;
  112|  22.7k|}
RSA_parse_private_key:
  156|      2|RSA *RSA_parse_private_key(CBS *cbs) {
  157|      2|  RSA *ret = RSA_new();
  158|      2|  if (ret == NULL) {
  ------------------
  |  Branch (158:7): [True: 0, False: 2]
  ------------------
  159|      0|    return NULL;
  160|      0|  }
  161|       |
  162|      2|  CBS child;
  163|      2|  uint64_t version;
  164|      2|  if (!CBS_get_asn1(cbs, &child, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|      2|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|      2|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|      2|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (164:7): [True: 0, False: 2]
  ------------------
  165|      2|      !CBS_get_asn1_uint64(&child, &version)) {
  ------------------
  |  Branch (165:7): [True: 0, False: 2]
  ------------------
  166|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  167|      0|    goto err;
  168|      0|  }
  169|       |
  170|      2|  if (version != kVersionTwoPrime) {
  ------------------
  |  Branch (170:7): [True: 0, False: 2]
  ------------------
  171|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  172|      0|    goto err;
  173|      0|  }
  174|       |
  175|      2|  if (!parse_integer(&child, &ret->n) ||
  ------------------
  |  Branch (175:7): [True: 0, False: 2]
  ------------------
  176|      2|      !parse_integer(&child, &ret->e) ||
  ------------------
  |  Branch (176:7): [True: 0, False: 2]
  ------------------
  177|      2|      !parse_integer(&child, &ret->d) ||
  ------------------
  |  Branch (177:7): [True: 0, False: 2]
  ------------------
  178|      2|      !parse_integer(&child, &ret->p) ||
  ------------------
  |  Branch (178:7): [True: 0, False: 2]
  ------------------
  179|      2|      !parse_integer(&child, &ret->q) ||
  ------------------
  |  Branch (179:7): [True: 0, False: 2]
  ------------------
  180|      2|      !parse_integer(&child, &ret->dmp1) ||
  ------------------
  |  Branch (180:7): [True: 0, False: 2]
  ------------------
  181|      2|      !parse_integer(&child, &ret->dmq1) ||
  ------------------
  |  Branch (181:7): [True: 0, False: 2]
  ------------------
  182|      2|      !parse_integer(&child, &ret->iqmp)) {
  ------------------
  |  Branch (182:7): [True: 0, False: 2]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|      2|  if (CBS_len(&child) != 0) {
  ------------------
  |  Branch (186:7): [True: 0, False: 2]
  ------------------
  187|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_ENCODING);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  188|      0|    goto err;
  189|      0|  }
  190|       |
  191|      2|  if (!RSA_check_key(ret)) {
  ------------------
  |  Branch (191:7): [True: 0, False: 2]
  ------------------
  192|      0|    OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  193|      0|    goto err;
  194|      0|  }
  195|       |
  196|      2|  return ret;
  197|       |
  198|      0|err:
  199|      0|  RSA_free(ret);
  200|      0|  return NULL;
  201|      2|}
d2i_RSAPrivateKey:
  276|      2|RSA *d2i_RSAPrivateKey(RSA **out, const uint8_t **inp, long len) {
  277|      2|  if (len < 0) {
  ------------------
  |  Branch (277:7): [True: 0, False: 2]
  ------------------
  278|      0|    return NULL;
  279|      0|  }
  280|      2|  CBS cbs;
  281|      2|  CBS_init(&cbs, *inp, (size_t)len);
  282|      2|  RSA *ret = RSA_parse_private_key(&cbs);
  283|      2|  if (ret == NULL) {
  ------------------
  |  Branch (283:7): [True: 0, False: 2]
  ------------------
  284|      0|    return NULL;
  285|      0|  }
  286|      2|  if (out != NULL) {
  ------------------
  |  Branch (286:7): [True: 0, False: 2]
  ------------------
  287|      0|    RSA_free(*out);
  288|      0|    *out = ret;
  289|      0|  }
  290|      2|  *inp = CBS_data(&cbs);
  291|      2|  return ret;
  292|      2|}
rsa_asn1.c:parse_integer:
   72|  45.4k|static int parse_integer(CBS *cbs, BIGNUM **out) {
   73|  45.4k|  assert(*out == NULL);
   74|  45.4k|  *out = BN_new();
   75|  45.4k|  if (*out == NULL) {
  ------------------
  |  Branch (75:7): [True: 0, False: 45.4k]
  ------------------
   76|      0|    return 0;
   77|      0|  }
   78|  45.4k|  return BN_parse_asn1_unsigned(cbs, *out);
   79|  45.4k|}

sk_new:
   72|   346k|_STACK *sk_new(OPENSSL_sk_cmp_func comp) {
   73|   346k|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
   74|   346k|  if (ret == NULL) {
  ------------------
  |  Branch (74:7): [True: 0, False: 346k]
  ------------------
   75|      0|    return NULL;
   76|      0|  }
   77|   346k|  OPENSSL_memset(ret, 0, sizeof(_STACK));
   78|       |
   79|   346k|  ret->data = OPENSSL_malloc(sizeof(void *) * kMinSize);
   80|   346k|  if (ret->data == NULL) {
  ------------------
  |  Branch (80:7): [True: 0, False: 346k]
  ------------------
   81|      0|    goto err;
   82|      0|  }
   83|       |
   84|   346k|  OPENSSL_memset(ret->data, 0, sizeof(void *) * kMinSize);
   85|       |
   86|   346k|  ret->comp = comp;
   87|   346k|  ret->num_alloc = kMinSize;
   88|       |
   89|   346k|  return ret;
   90|       |
   91|      0|err:
   92|      0|  OPENSSL_free(ret);
   93|      0|  return NULL;
   94|   346k|}
sk_new_null:
   96|   341k|_STACK *sk_new_null(void) { return sk_new(NULL); }
sk_num:
   98|   984k|size_t sk_num(const _STACK *sk) {
   99|   984k|  if (sk == NULL) {
  ------------------
  |  Branch (99:7): [True: 74.7k, False: 909k]
  ------------------
  100|  74.7k|    return 0;
  101|  74.7k|  }
  102|   909k|  return sk->num;
  103|   984k|}
sk_value:
  114|   512k|void *sk_value(const _STACK *sk, size_t i) {
  115|   512k|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (115:7): [True: 0, False: 512k]
  |  Branch (115:14): [True: 0, False: 512k]
  ------------------
  116|      0|    return NULL;
  117|      0|  }
  118|   512k|  return sk->data[i];
  119|   512k|}
sk_set:
  121|  52.8k|void *sk_set(_STACK *sk, size_t i, void *value) {
  122|  52.8k|  if (!sk || i >= sk->num) {
  ------------------
  |  Branch (122:7): [True: 0, False: 52.8k]
  |  Branch (122:14): [True: 0, False: 52.8k]
  ------------------
  123|      0|    return NULL;
  124|      0|  }
  125|  52.8k|  return sk->data[i] = value;
  126|  52.8k|}
sk_free:
  128|   387k|void sk_free(_STACK *sk) {
  129|   387k|  if (sk == NULL) {
  ------------------
  |  Branch (129:7): [True: 40.1k, False: 347k]
  ------------------
  130|  40.1k|    return;
  131|  40.1k|  }
  132|   347k|  OPENSSL_free(sk->data);
  133|   347k|  OPENSSL_free(sk);
  134|   347k|}
sk_pop_free_ex:
  137|   378k|                    OPENSSL_sk_free_func free_func) {
  138|   378k|  if (sk == NULL) {
  ------------------
  |  Branch (138:7): [True: 124k, False: 254k]
  ------------------
  139|   124k|    return;
  140|   124k|  }
  141|       |
  142|   503k|  for (size_t i = 0; i < sk->num; i++) {
  ------------------
  |  Branch (142:22): [True: 249k, False: 254k]
  ------------------
  143|   249k|    if (sk->data[i] != NULL) {
  ------------------
  |  Branch (143:9): [True: 228k, False: 20.2k]
  ------------------
  144|   228k|      call_free_func(free_func, sk->data[i]);
  145|   228k|    }
  146|   249k|  }
  147|   254k|  sk_free(sk);
  148|   254k|}
sk_insert:
  161|   565k|size_t sk_insert(_STACK *sk, void *p, size_t where) {
  162|   565k|  if (sk == NULL) {
  ------------------
  |  Branch (162:7): [True: 0, False: 565k]
  ------------------
  163|      0|    return 0;
  164|      0|  }
  165|       |
  166|   565k|  if (sk->num >= INT_MAX) {
  ------------------
  |  Branch (166:7): [True: 0, False: 565k]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(CRYPTO, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|   565k|  if (sk->num_alloc <= sk->num + 1) {
  ------------------
  |  Branch (171:7): [True: 55.9k, False: 510k]
  ------------------
  172|       |    // Attempt to double the size of the array.
  173|  55.9k|    size_t new_alloc = sk->num_alloc << 1;
  174|  55.9k|    size_t alloc_size = new_alloc * sizeof(void *);
  175|  55.9k|    void **data;
  176|       |
  177|       |    // If the doubling overflowed, try to increment.
  178|  55.9k|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (178:9): [True: 0, False: 55.9k]
  |  Branch (178:38): [True: 0, False: 55.9k]
  ------------------
  179|      0|      new_alloc = sk->num_alloc + 1;
  180|      0|      alloc_size = new_alloc * sizeof(void *);
  181|      0|    }
  182|       |
  183|       |    // If the increment also overflowed, fail.
  184|  55.9k|    if (new_alloc < sk->num_alloc || alloc_size / sizeof(void *) != new_alloc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 55.9k]
  |  Branch (184:38): [True: 0, False: 55.9k]
  ------------------
  185|      0|      return 0;
  186|      0|    }
  187|       |
  188|  55.9k|    data = OPENSSL_realloc(sk->data, alloc_size);
  189|  55.9k|    if (data == NULL) {
  ------------------
  |  Branch (189:9): [True: 0, False: 55.9k]
  ------------------
  190|      0|      return 0;
  191|      0|    }
  192|       |
  193|  55.9k|    sk->data = data;
  194|  55.9k|    sk->num_alloc = new_alloc;
  195|  55.9k|  }
  196|       |
  197|   565k|  if (where >= sk->num) {
  ------------------
  |  Branch (197:7): [True: 565k, False: 0]
  ------------------
  198|   565k|    sk->data[sk->num] = p;
  199|   565k|  } else {
  200|      0|    OPENSSL_memmove(&sk->data[where + 1], &sk->data[where],
  201|      0|                    sizeof(void *) * (sk->num - where));
  202|      0|    sk->data[where] = p;
  203|      0|  }
  204|       |
  205|   565k|  sk->num++;
  206|   565k|  sk->sorted = 0;
  207|       |
  208|   565k|  return sk->num;
  209|   565k|}
sk_push:
  340|   565k|size_t sk_push(_STACK *sk, void *p) { return (sk_insert(sk, p, sk->num)); }
sk_dup:
  352|    828|_STACK *sk_dup(const _STACK *sk) {
  353|    828|  if (sk == NULL) {
  ------------------
  |  Branch (353:7): [True: 0, False: 828]
  ------------------
  354|      0|    return NULL;
  355|      0|  }
  356|       |
  357|    828|  _STACK *ret = OPENSSL_malloc(sizeof(_STACK));
  358|    828|  if (ret == NULL) {
  ------------------
  |  Branch (358:7): [True: 0, False: 828]
  ------------------
  359|      0|    return NULL;
  360|      0|  }
  361|    828|  OPENSSL_memset(ret, 0, sizeof(_STACK));
  362|       |
  363|    828|  ret->data = OPENSSL_malloc(sizeof(void *) * sk->num_alloc);
  364|    828|  if (ret->data == NULL) {
  ------------------
  |  Branch (364:7): [True: 0, False: 828]
  ------------------
  365|      0|    goto err;
  366|      0|  }
  367|       |
  368|    828|  ret->num = sk->num;
  369|    828|  OPENSSL_memcpy(ret->data, sk->data, sizeof(void *) * sk->num);
  370|    828|  ret->sorted = sk->sorted;
  371|    828|  ret->num_alloc = sk->num_alloc;
  372|    828|  ret->comp = sk->comp;
  373|    828|  return ret;
  374|       |
  375|      0|err:
  376|      0|  sk_free(ret);
  377|      0|  return NULL;
  378|    828|}
sk_deep_copy:
  443|    828|                     OPENSSL_sk_free_func free_func) {
  444|    828|  _STACK *ret = sk_dup(sk);
  445|    828|  if (ret == NULL) {
  ------------------
  |  Branch (445:7): [True: 0, False: 828]
  ------------------
  446|      0|    return NULL;
  447|      0|  }
  448|       |
  449|  6.16k|  for (size_t i = 0; i < ret->num; i++) {
  ------------------
  |  Branch (449:22): [True: 5.33k, False: 828]
  ------------------
  450|  5.33k|    if (ret->data[i] == NULL) {
  ------------------
  |  Branch (450:9): [True: 506, False: 4.82k]
  ------------------
  451|    506|      continue;
  452|    506|    }
  453|  4.82k|    ret->data[i] = call_copy_func(copy_func, ret->data[i]);
  454|  4.82k|    if (ret->data[i] == NULL) {
  ------------------
  |  Branch (454:9): [True: 0, False: 4.82k]
  ------------------
  455|      0|      for (size_t j = 0; j < i; j++) {
  ------------------
  |  Branch (455:26): [True: 0, False: 0]
  ------------------
  456|      0|        if (ret->data[j] != NULL) {
  ------------------
  |  Branch (456:13): [True: 0, False: 0]
  ------------------
  457|      0|          call_free_func(free_func, ret->data[j]);
  458|      0|        }
  459|      0|      }
  460|      0|      sk_free(ret);
  461|      0|      return NULL;
  462|      0|    }
  463|  4.82k|  }
  464|       |
  465|    828|  return ret;
  466|    828|}

CRYPTO_MUTEX_init:
   31|  52.4k|void CRYPTO_MUTEX_init(CRYPTO_MUTEX *lock) {
   32|  52.4k|  if (pthread_rwlock_init((pthread_rwlock_t *) lock, NULL) != 0) {
  ------------------
  |  Branch (32:7): [True: 0, False: 52.4k]
  ------------------
   33|      0|    abort();
   34|      0|  }
   35|  52.4k|}
CRYPTO_MUTEX_lock_read:
   37|  4.94k|void CRYPTO_MUTEX_lock_read(CRYPTO_MUTEX *lock) {
   38|  4.94k|  if (pthread_rwlock_rdlock((pthread_rwlock_t *) lock) != 0) {
  ------------------
  |  Branch (38:7): [True: 0, False: 4.94k]
  ------------------
   39|      0|    abort();
   40|      0|  }
   41|  4.94k|}
CRYPTO_MUTEX_lock_write:
   43|  21.9k|void CRYPTO_MUTEX_lock_write(CRYPTO_MUTEX *lock) {
   44|  21.9k|  if (pthread_rwlock_wrlock((pthread_rwlock_t *) lock) != 0) {
  ------------------
  |  Branch (44:7): [True: 0, False: 21.9k]
  ------------------
   45|      0|    abort();
   46|      0|  }
   47|  21.9k|}
CRYPTO_MUTEX_unlock_read:
   49|  4.94k|void CRYPTO_MUTEX_unlock_read(CRYPTO_MUTEX *lock) {
   50|  4.94k|  if (pthread_rwlock_unlock((pthread_rwlock_t *) lock) != 0) {
  ------------------
  |  Branch (50:7): [True: 0, False: 4.94k]
  ------------------
   51|      0|    abort();
   52|      0|  }
   53|  4.94k|}
CRYPTO_MUTEX_unlock_write:
   55|  21.9k|void CRYPTO_MUTEX_unlock_write(CRYPTO_MUTEX *lock) {
   56|  21.9k|  if (pthread_rwlock_unlock((pthread_rwlock_t *) lock) != 0) {
  ------------------
  |  Branch (56:7): [True: 0, False: 21.9k]
  ------------------
   57|      0|    abort();
   58|      0|  }
   59|  21.9k|}
CRYPTO_MUTEX_cleanup:
   61|  52.4k|void CRYPTO_MUTEX_cleanup(CRYPTO_MUTEX *lock) {
   62|  52.4k|  pthread_rwlock_destroy((pthread_rwlock_t *) lock);
   63|  52.4k|}
CRYPTO_STATIC_MUTEX_lock_write:
   71|      2|void CRYPTO_STATIC_MUTEX_lock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   72|      2|  if (pthread_rwlock_wrlock(&lock->lock) != 0) {
  ------------------
  |  Branch (72:7): [True: 0, False: 2]
  ------------------
   73|      0|    abort();
   74|      0|  }
   75|      2|}
CRYPTO_STATIC_MUTEX_unlock_write:
   83|      2|void CRYPTO_STATIC_MUTEX_unlock_write(struct CRYPTO_STATIC_MUTEX *lock) {
   84|      2|  if (pthread_rwlock_unlock(&lock->lock) != 0) {
  ------------------
  |  Branch (84:7): [True: 0, False: 2]
  ------------------
   85|      0|    abort();
   86|      0|  }
   87|      2|}
CRYPTO_once:
   89|   171k|void CRYPTO_once(CRYPTO_once_t *once, void (*init)(void)) {
   90|   171k|  if (pthread_once(once, init) != 0) {
  ------------------
  |  Branch (90:7): [True: 0, False: 171k]
  ------------------
   91|      0|    abort();
   92|      0|  }
   93|   171k|}
CRYPTO_get_thread_local:
  132|   143k|void *CRYPTO_get_thread_local(thread_local_data_t index) {
  133|   143k|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  134|   143k|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (134:7): [True: 0, False: 143k]
  ------------------
  135|      0|    return NULL;
  136|      0|  }
  137|       |
  138|   143k|  void **pointers = pthread_getspecific(g_thread_local_key);
  139|   143k|  if (pointers == NULL) {
  ------------------
  |  Branch (139:7): [True: 1, False: 143k]
  ------------------
  140|      1|    return NULL;
  141|      1|  }
  142|   143k|  return pointers[index];
  143|   143k|}
CRYPTO_set_thread_local:
  146|      2|                            thread_local_destructor_t destructor) {
  147|      2|  CRYPTO_once(&g_thread_local_init_once, thread_local_init);
  148|      2|  if (!g_thread_local_key_created) {
  ------------------
  |  Branch (148:7): [True: 0, False: 2]
  ------------------
  149|      0|    destructor(value);
  150|      0|    return 0;
  151|      0|  }
  152|       |
  153|      2|  void **pointers = pthread_getspecific(g_thread_local_key);
  154|      2|  if (pointers == NULL) {
  ------------------
  |  Branch (154:7): [True: 1, False: 1]
  ------------------
  155|      1|    pointers = malloc(sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  156|      1|    if (pointers == NULL) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1]
  ------------------
  157|      0|      destructor(value);
  158|      0|      return 0;
  159|      0|    }
  160|      1|    OPENSSL_memset(pointers, 0, sizeof(void *) * NUM_OPENSSL_THREAD_LOCALS);
  161|      1|    if (pthread_setspecific(g_thread_local_key, pointers) != 0) {
  ------------------
  |  Branch (161:9): [True: 0, False: 1]
  ------------------
  162|      0|      free(pointers);
  163|      0|      destructor(value);
  164|      0|      return 0;
  165|      0|    }
  166|      1|  }
  167|       |
  168|      2|  if (pthread_mutex_lock(&g_destructors_lock) != 0) {
  ------------------
  |  Branch (168:7): [True: 0, False: 2]
  ------------------
  169|      0|    destructor(value);
  170|      0|    return 0;
  171|      0|  }
  172|      2|  g_destructors[index] = destructor;
  173|      2|  pthread_mutex_unlock(&g_destructors_lock);
  174|       |
  175|      2|  pointers[index] = value;
  176|      2|  return 1;
  177|      2|}
thread_pthread.c:thread_local_init:
  127|      1|static void thread_local_init(void) {
  128|      1|  g_thread_local_key_created =
  129|      1|      pthread_key_create(&g_thread_local_key, thread_local_destructor) == 0;
  130|      1|}

X509_get_subject_name:
  101|  3.63k|X509_NAME *X509_get_subject_name(const X509 *a) {
  102|  3.63k|  return a->cert_info->subject;
  103|  3.63k|}

X509_STORE_new:
  164|  4.83k|X509_STORE *X509_STORE_new(void) {
  165|  4.83k|  X509_STORE *ret;
  166|       |
  167|  4.83k|  if ((ret = (X509_STORE *)OPENSSL_malloc(sizeof(X509_STORE))) == NULL) {
  ------------------
  |  Branch (167:7): [True: 0, False: 4.83k]
  ------------------
  168|      0|    return NULL;
  169|      0|  }
  170|  4.83k|  OPENSSL_memset(ret, 0, sizeof(*ret));
  171|  4.83k|  CRYPTO_MUTEX_init(&ret->objs_lock);
  172|  4.83k|  ret->objs = sk_X509_OBJECT_new(x509_object_cmp_sk);
  173|  4.83k|  if (ret->objs == NULL) {
  ------------------
  |  Branch (173:7): [True: 0, False: 4.83k]
  ------------------
  174|      0|    goto err;
  175|      0|  }
  176|  4.83k|  ret->cache = 1;
  177|  4.83k|  ret->get_cert_methods = sk_X509_LOOKUP_new_null();
  178|  4.83k|  if (ret->get_cert_methods == NULL) {
  ------------------
  |  Branch (178:7): [True: 0, False: 4.83k]
  ------------------
  179|      0|    goto err;
  180|      0|  }
  181|  4.83k|  ret->param = X509_VERIFY_PARAM_new();
  182|  4.83k|  if (ret->param == NULL) {
  ------------------
  |  Branch (182:7): [True: 0, False: 4.83k]
  ------------------
  183|      0|    goto err;
  184|      0|  }
  185|       |
  186|  4.83k|  ret->references = 1;
  187|  4.83k|  return ret;
  188|      0|err:
  189|      0|  if (ret) {
  ------------------
  |  Branch (189:7): [True: 0, False: 0]
  ------------------
  190|      0|    CRYPTO_MUTEX_cleanup(&ret->objs_lock);
  191|      0|    if (ret->param) {
  ------------------
  |  Branch (191:9): [True: 0, False: 0]
  ------------------
  192|      0|      X509_VERIFY_PARAM_free(ret->param);
  193|      0|    }
  194|      0|    if (ret->get_cert_methods) {
  ------------------
  |  Branch (194:9): [True: 0, False: 0]
  ------------------
  195|      0|      sk_X509_LOOKUP_free(ret->get_cert_methods);
  196|      0|    }
  197|      0|    if (ret->objs) {
  ------------------
  |  Branch (197:9): [True: 0, False: 0]
  ------------------
  198|      0|      sk_X509_OBJECT_free(ret->objs);
  199|      0|    }
  200|      0|    OPENSSL_free(ret);
  201|      0|  }
  202|      0|  return NULL;
  203|  4.83k|}
X509_STORE_free:
  225|  14.4k|void X509_STORE_free(X509_STORE *vfy) {
  226|  14.4k|  size_t j;
  227|  14.4k|  STACK_OF(X509_LOOKUP) *sk;
  ------------------
  |  |   81|  14.4k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  228|  14.4k|  X509_LOOKUP *lu;
  229|       |
  230|  14.4k|  if (vfy == NULL) {
  ------------------
  |  Branch (230:7): [True: 9.66k, False: 4.83k]
  ------------------
  231|  9.66k|    return;
  232|  9.66k|  }
  233|       |
  234|  4.83k|  if (!CRYPTO_refcount_dec_and_test_zero(&vfy->references)) {
  ------------------
  |  Branch (234:7): [True: 0, False: 4.83k]
  ------------------
  235|      0|    return;
  236|      0|  }
  237|       |
  238|  4.83k|  CRYPTO_MUTEX_cleanup(&vfy->objs_lock);
  239|       |
  240|  4.83k|  sk = vfy->get_cert_methods;
  241|  4.83k|  for (j = 0; j < sk_X509_LOOKUP_num(sk); j++) {
  ------------------
  |  Branch (241:15): [True: 0, False: 4.83k]
  ------------------
  242|      0|    lu = sk_X509_LOOKUP_value(sk, j);
  243|      0|    X509_LOOKUP_shutdown(lu);
  244|      0|    X509_LOOKUP_free(lu);
  245|      0|  }
  246|  4.83k|  sk_X509_LOOKUP_free(sk);
  247|  4.83k|  sk_X509_OBJECT_pop_free(vfy->objs, cleanup);
  248|       |
  249|  4.83k|  if (vfy->param) {
  ------------------
  |  Branch (249:7): [True: 4.83k, False: 0]
  ------------------
  250|  4.83k|    X509_VERIFY_PARAM_free(vfy->param);
  251|  4.83k|  }
  252|  4.83k|  OPENSSL_free(vfy);
  253|  4.83k|}

X509_VERIFY_PARAM_new:
  158|  14.4k|X509_VERIFY_PARAM *X509_VERIFY_PARAM_new(void) {
  159|  14.4k|  X509_VERIFY_PARAM *param;
  160|  14.4k|  param = OPENSSL_malloc(sizeof(X509_VERIFY_PARAM));
  161|  14.4k|  if (!param) {
  ------------------
  |  Branch (161:7): [True: 0, False: 14.4k]
  ------------------
  162|      0|    return NULL;
  163|      0|  }
  164|  14.4k|  OPENSSL_memset(param, 0, sizeof(X509_VERIFY_PARAM));
  165|  14.4k|  x509_verify_param_zero(param);
  166|  14.4k|  return param;
  167|  14.4k|}
X509_VERIFY_PARAM_free:
  169|  14.4k|void X509_VERIFY_PARAM_free(X509_VERIFY_PARAM *param) {
  170|  14.4k|  if (param == NULL) {
  ------------------
  |  Branch (170:7): [True: 0, False: 14.4k]
  ------------------
  171|      0|    return;
  172|      0|  }
  173|  14.4k|  x509_verify_param_zero(param);
  174|  14.4k|  OPENSSL_free(param);
  175|  14.4k|}
X509_VERIFY_PARAM_inherit:
  221|  4.83k|                              const X509_VERIFY_PARAM *src) {
  222|  4.83k|  unsigned long inh_flags;
  223|  4.83k|  int to_default, to_overwrite;
  224|  4.83k|  if (!src) {
  ------------------
  |  Branch (224:7): [True: 0, False: 4.83k]
  ------------------
  225|      0|    return 1;
  226|      0|  }
  227|  4.83k|  inh_flags = dest->inh_flags | src->inh_flags;
  228|       |
  229|  4.83k|  if (inh_flags & X509_VP_FLAG_ONCE) {
  ------------------
  |  | 2738|  4.83k|#define X509_VP_FLAG_ONCE 0x10
  ------------------
  |  Branch (229:7): [True: 0, False: 4.83k]
  ------------------
  230|      0|    dest->inh_flags = 0;
  231|      0|  }
  232|       |
  233|  4.83k|  if (inh_flags & X509_VP_FLAG_LOCKED) {
  ------------------
  |  | 2737|  4.83k|#define X509_VP_FLAG_LOCKED 0x8
  ------------------
  |  Branch (233:7): [True: 0, False: 4.83k]
  ------------------
  234|      0|    return 1;
  235|      0|  }
  236|       |
  237|  4.83k|  if (inh_flags & X509_VP_FLAG_DEFAULT) {
  ------------------
  |  | 2734|  4.83k|#define X509_VP_FLAG_DEFAULT 0x1
  ------------------
  |  Branch (237:7): [True: 0, False: 4.83k]
  ------------------
  238|      0|    to_default = 1;
  239|  4.83k|  } else {
  240|  4.83k|    to_default = 0;
  241|  4.83k|  }
  242|       |
  243|  4.83k|  if (inh_flags & X509_VP_FLAG_OVERWRITE) {
  ------------------
  |  | 2735|  4.83k|#define X509_VP_FLAG_OVERWRITE 0x2
  ------------------
  |  Branch (243:7): [True: 0, False: 4.83k]
  ------------------
  244|      0|    to_overwrite = 1;
  245|  4.83k|  } else {
  246|  4.83k|    to_overwrite = 0;
  247|  4.83k|  }
  248|       |
  249|  4.83k|  x509_verify_param_copy(purpose, 0);
  ------------------
  |  |  217|  4.83k|  if (test_x509_verify_param_copy(field, def)) \
  |  |  ------------------
  |  |  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  |  |  ------------------
  |  |  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  218|  4.83k|  dest->field = src->field
  ------------------
  250|  4.83k|  x509_verify_param_copy(trust, 0);
  ------------------
  |  |  217|  4.83k|  if (test_x509_verify_param_copy(field, def)) \
  |  |  ------------------
  |  |  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  |  |  ------------------
  |  |  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  218|  4.83k|  dest->field = src->field
  ------------------
  251|  4.83k|  x509_verify_param_copy(depth, -1);
  ------------------
  |  |  217|  4.83k|  if (test_x509_verify_param_copy(field, def)) \
  |  |  ------------------
  |  |  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  |  |  ------------------
  |  |  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  218|  4.83k|  dest->field = src->field
  ------------------
  252|       |
  253|       |  // If overwrite or check time not set, copy across
  254|       |
  255|  4.83k|  if (to_overwrite || !(dest->flags & X509_V_FLAG_USE_CHECK_TIME)) {
  ------------------
  |  | 2692|  4.83k|#define X509_V_FLAG_USE_CHECK_TIME 0x2
  ------------------
  |  Branch (255:7): [True: 0, False: 4.83k]
  |  Branch (255:23): [True: 4.83k, False: 0]
  ------------------
  256|  4.83k|    dest->check_time = src->check_time;
  257|  4.83k|    dest->flags &= ~X509_V_FLAG_USE_CHECK_TIME;
  ------------------
  |  | 2692|  4.83k|#define X509_V_FLAG_USE_CHECK_TIME 0x2
  ------------------
  258|       |    // Don't need to copy flag: that is done below
  259|  4.83k|  }
  260|       |
  261|  4.83k|  if (inh_flags & X509_VP_FLAG_RESET_FLAGS) {
  ------------------
  |  | 2736|  4.83k|#define X509_VP_FLAG_RESET_FLAGS 0x4
  ------------------
  |  Branch (261:7): [True: 0, False: 4.83k]
  ------------------
  262|      0|    dest->flags = 0;
  263|      0|  }
  264|       |
  265|  4.83k|  dest->flags |= src->flags;
  266|       |
  267|  4.83k|  if (test_x509_verify_param_copy(policies, NULL)) {
  ------------------
  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  ------------------
  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  268|      0|    if (!X509_VERIFY_PARAM_set1_policies(dest, src->policies)) {
  ------------------
  |  Branch (268:9): [True: 0, False: 0]
  ------------------
  269|      0|      return 0;
  270|      0|    }
  271|      0|  }
  272|       |
  273|       |  // Copy the host flags if and only if we're copying the host list
  274|  4.83k|  if (test_x509_verify_param_copy(hosts, NULL)) {
  ------------------
  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  ------------------
  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  275|      0|    if (dest->hosts) {
  ------------------
  |  Branch (275:9): [True: 0, False: 0]
  ------------------
  276|      0|      string_stack_free(dest->hosts);
  ------------------
  |  |   77|      0|#define string_stack_free(sk) sk_OPENSSL_STRING_pop_free(sk, str_free)
  ------------------
  277|      0|      dest->hosts = NULL;
  278|      0|    }
  279|      0|    if (src->hosts) {
  ------------------
  |  Branch (279:9): [True: 0, False: 0]
  ------------------
  280|      0|      dest->hosts =
  281|      0|          sk_OPENSSL_STRING_deep_copy(src->hosts, OPENSSL_strdup, str_free);
  282|      0|      if (dest->hosts == NULL) {
  ------------------
  |  Branch (282:11): [True: 0, False: 0]
  ------------------
  283|      0|        return 0;
  284|      0|      }
  285|      0|      dest->hostflags = src->hostflags;
  286|      0|    }
  287|      0|  }
  288|       |
  289|  4.83k|  if (test_x509_verify_param_copy(email, NULL)) {
  ------------------
  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  ------------------
  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  290|      0|    if (!X509_VERIFY_PARAM_set1_email(dest, src->email, src->emaillen)) {
  ------------------
  |  Branch (290:9): [True: 0, False: 0]
  ------------------
  291|      0|      return 0;
  292|      0|    }
  293|      0|  }
  294|       |
  295|  4.83k|  if (test_x509_verify_param_copy(ip, NULL)) {
  ------------------
  |  |  211|  4.83k|  (to_overwrite ||                              \
  |  |  ------------------
  |  |  |  Branch (211:4): [True: 0, False: 4.83k]
  |  |  ------------------
  |  |  212|  4.83k|   ((src->field != (def)) && (to_default || (dest->field == (def)))))
  |  |  ------------------
  |  |  |  Branch (212:5): [True: 0, False: 4.83k]
  |  |  |  Branch (212:31): [True: 0, False: 0]
  |  |  |  Branch (212:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  296|      0|    if (!X509_VERIFY_PARAM_set1_ip(dest, src->ip, src->iplen)) {
  ------------------
  |  Branch (296:9): [True: 0, False: 0]
  ------------------
  297|      0|      return 0;
  298|      0|    }
  299|      0|  }
  300|       |
  301|  4.83k|  dest->poison = src->poison;
  302|       |
  303|  4.83k|  return 1;
  304|  4.83k|}
x509_vpm.c:x509_verify_param_zero:
  122|  28.9k|static void x509_verify_param_zero(X509_VERIFY_PARAM *param) {
  123|  28.9k|  if (!param) {
  ------------------
  |  Branch (123:7): [True: 0, False: 28.9k]
  ------------------
  124|      0|    return;
  125|      0|  }
  126|  28.9k|  param->name = NULL;
  127|  28.9k|  param->purpose = 0;
  128|  28.9k|  param->trust = 0;
  129|       |  // param->inh_flags = X509_VP_FLAG_DEFAULT;
  130|  28.9k|  param->inh_flags = 0;
  131|  28.9k|  param->flags = 0;
  132|  28.9k|  param->depth = -1;
  133|  28.9k|  if (param->policies) {
  ------------------
  |  Branch (133:7): [True: 0, False: 28.9k]
  ------------------
  134|      0|    sk_ASN1_OBJECT_pop_free(param->policies, ASN1_OBJECT_free);
  135|      0|    param->policies = NULL;
  136|      0|  }
  137|  28.9k|  if (param->hosts) {
  ------------------
  |  Branch (137:7): [True: 0, False: 28.9k]
  ------------------
  138|      0|    string_stack_free(param->hosts);
  ------------------
  |  |   77|      0|#define string_stack_free(sk) sk_OPENSSL_STRING_pop_free(sk, str_free)
  ------------------
  139|      0|    param->hosts = NULL;
  140|      0|  }
  141|  28.9k|  if (param->peername) {
  ------------------
  |  Branch (141:7): [True: 0, False: 28.9k]
  ------------------
  142|      0|    OPENSSL_free(param->peername);
  143|      0|    param->peername = NULL;
  144|      0|  }
  145|  28.9k|  if (param->email) {
  ------------------
  |  Branch (145:7): [True: 0, False: 28.9k]
  ------------------
  146|      0|    OPENSSL_free(param->email);
  147|      0|    param->email = NULL;
  148|      0|    param->emaillen = 0;
  149|      0|  }
  150|  28.9k|  if (param->ip) {
  ------------------
  |  Branch (150:7): [True: 0, False: 28.9k]
  ------------------
  151|      0|    OPENSSL_free(param->ip);
  152|      0|    param->ip = NULL;
  153|      0|    param->iplen = 0;
  154|      0|  }
  155|  28.9k|  param->poison = 0;
  156|  28.9k|}

x_name.c:x509_name_ex_new:
  136|  80.3k|static int x509_name_ex_new(ASN1_VALUE **val, const ASN1_ITEM *it) {
  137|  80.3k|  X509_NAME *ret = NULL;
  138|  80.3k|  ret = OPENSSL_malloc(sizeof(X509_NAME));
  139|  80.3k|  if (!ret) {
  ------------------
  |  Branch (139:7): [True: 0, False: 80.3k]
  ------------------
  140|      0|    goto memerr;
  141|      0|  }
  142|  80.3k|  if ((ret->entries = sk_X509_NAME_ENTRY_new_null()) == NULL) {
  ------------------
  |  Branch (142:7): [True: 0, False: 80.3k]
  ------------------
  143|      0|    goto memerr;
  144|      0|  }
  145|  80.3k|  if ((ret->bytes = BUF_MEM_new()) == NULL) {
  ------------------
  |  Branch (145:7): [True: 0, False: 80.3k]
  ------------------
  146|      0|    goto memerr;
  147|      0|  }
  148|  80.3k|  ret->canon_enc = NULL;
  149|  80.3k|  ret->canon_enclen = 0;
  150|  80.3k|  ret->modified = 1;
  151|  80.3k|  *val = (ASN1_VALUE *)ret;
  152|  80.3k|  return 1;
  153|       |
  154|      0|memerr:
  155|      0|  if (ret) {
  ------------------
  |  Branch (155:7): [True: 0, False: 0]
  ------------------
  156|      0|    if (ret->entries) {
  ------------------
  |  Branch (156:9): [True: 0, False: 0]
  ------------------
  157|      0|      sk_X509_NAME_ENTRY_free(ret->entries);
  158|      0|    }
  159|      0|    OPENSSL_free(ret);
  160|      0|  }
  161|      0|  return 0;
  162|  80.3k|}
x_name.c:x509_name_ex_free:
  164|  80.3k|static void x509_name_ex_free(ASN1_VALUE **pval, const ASN1_ITEM *it) {
  165|  80.3k|  X509_NAME *a;
  166|  80.3k|  if (!pval || !*pval) {
  ------------------
  |  Branch (166:7): [True: 0, False: 80.3k]
  |  Branch (166:16): [True: 0, False: 80.3k]
  ------------------
  167|      0|    return;
  168|      0|  }
  169|  80.3k|  a = (X509_NAME *)*pval;
  170|       |
  171|  80.3k|  BUF_MEM_free(a->bytes);
  172|  80.3k|  sk_X509_NAME_ENTRY_pop_free(a->entries, X509_NAME_ENTRY_free);
  173|  80.3k|  if (a->canon_enc) {
  ------------------
  |  Branch (173:7): [True: 40.1k, False: 40.1k]
  ------------------
  174|  40.1k|    OPENSSL_free(a->canon_enc);
  175|  40.1k|  }
  176|  80.3k|  OPENSSL_free(a);
  177|  80.3k|  *pval = NULL;
  178|  80.3k|}
x_name.c:x509_name_ex_d2i:
  190|  40.1k|                            ASN1_TLC *ctx) {
  191|  40.1k|  const unsigned char *p = *in, *q;
  192|  40.1k|  STACK_OF(STACK_OF_X509_NAME_ENTRY) *intname = NULL;
  ------------------
  |  |   81|  40.1k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  193|  40.1k|  X509_NAME *nm = NULL;
  194|  40.1k|  size_t i, j;
  195|  40.1k|  int ret;
  196|  40.1k|  STACK_OF(X509_NAME_ENTRY) *entries;
  ------------------
  |  |   81|  40.1k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  197|  40.1k|  X509_NAME_ENTRY *entry;
  198|       |  // Bound the size of an X509_NAME we are willing to parse.
  199|  40.1k|  if (len > X509_NAME_MAX) {
  ------------------
  |  |   80|  40.1k|#define X509_NAME_MAX (1024 * 1024)
  ------------------
  |  Branch (199:7): [True: 0, False: 40.1k]
  ------------------
  200|      0|    len = X509_NAME_MAX;
  ------------------
  |  |   80|      0|#define X509_NAME_MAX (1024 * 1024)
  ------------------
  201|      0|  }
  202|  40.1k|  q = p;
  203|       |
  204|       |  // Get internal representation of Name
  205|  40.1k|  ASN1_VALUE *intname_val = NULL;
  206|  40.1k|  ret = ASN1_item_ex_d2i(&intname_val, &p, len,
  207|  40.1k|                         ASN1_ITEM_rptr(X509_NAME_INTERNAL), /*tag=*/-1,
  ------------------
  |  |  274|  40.1k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  208|  40.1k|                         /*aclass=*/0, opt, /*buf=*/NULL);
  209|  40.1k|  if (ret <= 0) {
  ------------------
  |  Branch (209:7): [True: 0, False: 40.1k]
  ------------------
  210|      0|    return ret;
  211|      0|  }
  212|  40.1k|  intname = (STACK_OF(STACK_OF_X509_NAME_ENTRY) *)intname_val;
  213|       |
  214|  40.1k|  if (*val) {
  ------------------
  |  Branch (214:7): [True: 40.1k, False: 0]
  ------------------
  215|  40.1k|    x509_name_ex_free(val, NULL);
  216|  40.1k|  }
  217|  40.1k|  ASN1_VALUE *nm_val = NULL;
  218|  40.1k|  if (!x509_name_ex_new(&nm_val, NULL)) {
  ------------------
  |  Branch (218:7): [True: 0, False: 40.1k]
  ------------------
  219|      0|    goto err;
  220|      0|  }
  221|  40.1k|  nm = (X509_NAME *)nm_val;
  222|       |  // We've decoded it: now cache encoding
  223|  40.1k|  if (!BUF_MEM_grow(nm->bytes, p - q)) {
  ------------------
  |  Branch (223:7): [True: 0, False: 40.1k]
  ------------------
  224|      0|    goto err;
  225|      0|  }
  226|  40.1k|  OPENSSL_memcpy(nm->bytes->data, q, p - q);
  227|       |
  228|       |  // Convert internal representation to X509_NAME structure
  229|  80.3k|  for (i = 0; i < sk_STACK_OF_X509_NAME_ENTRY_num(intname); i++) {
  ------------------
  |  Branch (229:15): [True: 40.1k, False: 40.1k]
  ------------------
  230|  40.1k|    entries = sk_STACK_OF_X509_NAME_ENTRY_value(intname, i);
  231|  80.3k|    for (j = 0; j < sk_X509_NAME_ENTRY_num(entries); j++) {
  ------------------
  |  Branch (231:17): [True: 40.1k, False: 40.1k]
  ------------------
  232|  40.1k|      entry = sk_X509_NAME_ENTRY_value(entries, j);
  233|  40.1k|      entry->set = (int)i;
  234|  40.1k|      if (!sk_X509_NAME_ENTRY_push(nm->entries, entry)) {
  ------------------
  |  Branch (234:11): [True: 0, False: 40.1k]
  ------------------
  235|      0|        goto err;
  236|      0|      }
  237|  40.1k|      (void)sk_X509_NAME_ENTRY_set(entries, j, NULL);
  238|  40.1k|    }
  239|  40.1k|  }
  240|  40.1k|  ret = x509_name_canon(nm);
  241|  40.1k|  if (!ret) {
  ------------------
  |  Branch (241:7): [True: 0, False: 40.1k]
  ------------------
  242|      0|    goto err;
  243|      0|  }
  244|  40.1k|  sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname, local_sk_X509_NAME_ENTRY_free);
  245|  40.1k|  nm->modified = 0;
  246|  40.1k|  *val = (ASN1_VALUE *)nm;
  247|  40.1k|  *in = p;
  248|  40.1k|  return ret;
  249|      0|err:
  250|      0|  X509_NAME_free(nm);
  251|      0|  sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname,
  252|      0|                                       local_sk_X509_NAME_ENTRY_pop_free);
  253|      0|  OPENSSL_PUT_ERROR(X509, ERR_R_ASN1_LIB);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  254|      0|  return 0;
  255|  40.1k|}
x_name.c:x509_name_canon:
  331|  40.1k|static int x509_name_canon(X509_NAME *a) {
  332|  40.1k|  unsigned char *p;
  333|  40.1k|  STACK_OF(STACK_OF_X509_NAME_ENTRY) *intname = NULL;
  ------------------
  |  |   81|  40.1k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  334|  40.1k|  STACK_OF(X509_NAME_ENTRY) *entries = NULL;
  ------------------
  |  |   81|  40.1k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  335|  40.1k|  X509_NAME_ENTRY *entry, *tmpentry = NULL;
  336|  40.1k|  int set = -1, ret = 0, len;
  337|  40.1k|  size_t i;
  338|       |
  339|  40.1k|  if (a->canon_enc) {
  ------------------
  |  Branch (339:7): [True: 0, False: 40.1k]
  ------------------
  340|      0|    OPENSSL_free(a->canon_enc);
  341|      0|    a->canon_enc = NULL;
  342|      0|  }
  343|       |  // Special case: empty X509_NAME => null encoding
  344|  40.1k|  if (sk_X509_NAME_ENTRY_num(a->entries) == 0) {
  ------------------
  |  Branch (344:7): [True: 0, False: 40.1k]
  ------------------
  345|      0|    a->canon_enclen = 0;
  346|      0|    return 1;
  347|      0|  }
  348|  40.1k|  intname = sk_STACK_OF_X509_NAME_ENTRY_new_null();
  349|  40.1k|  if (!intname) {
  ------------------
  |  Branch (349:7): [True: 0, False: 40.1k]
  ------------------
  350|      0|    goto err;
  351|      0|  }
  352|  80.3k|  for (i = 0; i < sk_X509_NAME_ENTRY_num(a->entries); i++) {
  ------------------
  |  Branch (352:15): [True: 40.1k, False: 40.1k]
  ------------------
  353|  40.1k|    entry = sk_X509_NAME_ENTRY_value(a->entries, i);
  354|  40.1k|    if (entry->set != set) {
  ------------------
  |  Branch (354:9): [True: 40.1k, False: 0]
  ------------------
  355|  40.1k|      entries = sk_X509_NAME_ENTRY_new_null();
  356|  40.1k|      if (!entries) {
  ------------------
  |  Branch (356:11): [True: 0, False: 40.1k]
  ------------------
  357|      0|        goto err;
  358|      0|      }
  359|  40.1k|      if (!sk_STACK_OF_X509_NAME_ENTRY_push(intname, entries)) {
  ------------------
  |  Branch (359:11): [True: 0, False: 40.1k]
  ------------------
  360|      0|        sk_X509_NAME_ENTRY_free(entries);
  361|      0|        goto err;
  362|      0|      }
  363|  40.1k|      set = entry->set;
  364|  40.1k|    }
  365|  40.1k|    tmpentry = X509_NAME_ENTRY_new();
  366|  40.1k|    if (tmpentry == NULL) {
  ------------------
  |  Branch (366:9): [True: 0, False: 40.1k]
  ------------------
  367|      0|      goto err;
  368|      0|    }
  369|  40.1k|    tmpentry->object = OBJ_dup(entry->object);
  370|  40.1k|    if (!asn1_string_canon(tmpentry->value, entry->value)) {
  ------------------
  |  Branch (370:9): [True: 0, False: 40.1k]
  ------------------
  371|      0|      goto err;
  372|      0|    }
  373|  40.1k|    if (!sk_X509_NAME_ENTRY_push(entries, tmpentry)) {
  ------------------
  |  Branch (373:9): [True: 0, False: 40.1k]
  ------------------
  374|      0|      goto err;
  375|      0|    }
  376|  40.1k|    tmpentry = NULL;
  377|  40.1k|  }
  378|       |
  379|       |  // Finally generate encoding
  380|       |
  381|  40.1k|  len = i2d_name_canon(intname, NULL);
  382|  40.1k|  if (len < 0) {
  ------------------
  |  Branch (382:7): [True: 0, False: 40.1k]
  ------------------
  383|      0|    goto err;
  384|      0|  }
  385|  40.1k|  a->canon_enclen = len;
  386|       |
  387|  40.1k|  p = OPENSSL_malloc(a->canon_enclen);
  388|       |
  389|  40.1k|  if (!p) {
  ------------------
  |  Branch (389:7): [True: 0, False: 40.1k]
  ------------------
  390|      0|    goto err;
  391|      0|  }
  392|       |
  393|  40.1k|  a->canon_enc = p;
  394|       |
  395|  40.1k|  i2d_name_canon(intname, &p);
  396|       |
  397|  40.1k|  ret = 1;
  398|       |
  399|  40.1k|err:
  400|       |
  401|  40.1k|  if (tmpentry) {
  ------------------
  |  Branch (401:7): [True: 0, False: 40.1k]
  ------------------
  402|      0|    X509_NAME_ENTRY_free(tmpentry);
  403|      0|  }
  404|  40.1k|  if (intname) {
  ------------------
  |  Branch (404:7): [True: 40.1k, False: 0]
  ------------------
  405|  40.1k|    sk_STACK_OF_X509_NAME_ENTRY_pop_free(intname,
  406|  40.1k|                                         local_sk_X509_NAME_ENTRY_pop_free);
  407|  40.1k|  }
  408|  40.1k|  return ret;
  409|  40.1k|}
x_name.c:asn1_string_canon:
  418|  40.1k|static int asn1_string_canon(ASN1_STRING *out, ASN1_STRING *in) {
  419|  40.1k|  unsigned char *to, *from;
  420|  40.1k|  int len, i;
  421|       |
  422|       |  // If type not in bitmask just copy string across
  423|  40.1k|  if (!(ASN1_tag2bit(in->type) & ASN1_MASK_CANON)) {
  ------------------
  |  |  414|  40.1k|  (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  175|  40.1k|#define B_ASN1_UTF8STRING 0x2000
  |  |  ------------------
  |  |                 (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  173|  40.1k|#define B_ASN1_BMPSTRING 0x0800
  |  |  ------------------
  |  |                 (B_ASN1_UTF8STRING | B_ASN1_BMPSTRING | B_ASN1_UNIVERSALSTRING | \
  |  |  ------------------
  |  |  |  |  170|  40.1k|#define B_ASN1_UNIVERSALSTRING 0x0100
  |  |  ------------------
  |  |  415|  40.1k|   B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  161|  40.1k|#define B_ASN1_PRINTABLESTRING 0x0002
  |  |  ------------------
  |  |                  B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  162|  40.1k|#define B_ASN1_T61STRING 0x0004
  |  |  ------------------
  |  |                  B_ASN1_PRINTABLESTRING | B_ASN1_T61STRING | B_ASN1_IA5STRING |  \
  |  |  ------------------
  |  |  |  |  165|  40.1k|#define B_ASN1_IA5STRING 0x0010
  |  |  ------------------
  |  |  416|  40.1k|   B_ASN1_VISIBLESTRING)
  |  |  ------------------
  |  |  |  |  168|  40.1k|#define B_ASN1_VISIBLESTRING 0x0040
  |  |  ------------------
  ------------------
  |  Branch (423:7): [True: 0, False: 40.1k]
  ------------------
  424|      0|    if (!ASN1_STRING_copy(out, in)) {
  ------------------
  |  Branch (424:9): [True: 0, False: 0]
  ------------------
  425|      0|      return 0;
  426|      0|    }
  427|      0|    return 1;
  428|      0|  }
  429|       |
  430|  40.1k|  out->type = V_ASN1_UTF8STRING;
  ------------------
  |  |  135|  40.1k|#define V_ASN1_UTF8STRING 12
  ------------------
  431|  40.1k|  out->length = ASN1_STRING_to_UTF8(&out->data, in);
  432|  40.1k|  if (out->length == -1) {
  ------------------
  |  Branch (432:7): [True: 0, False: 40.1k]
  ------------------
  433|      0|    return 0;
  434|      0|  }
  435|       |
  436|  40.1k|  to = out->data;
  437|  40.1k|  from = to;
  438|       |
  439|  40.1k|  len = out->length;
  440|       |
  441|       |  // Convert string in place to canonical form.
  442|       |
  443|       |  // Ignore leading spaces
  444|  40.1k|  while ((len > 0) && OPENSSL_isspace(*from)) {
  ------------------
  |  Branch (444:10): [True: 40.1k, False: 0]
  |  Branch (444:23): [True: 0, False: 40.1k]
  ------------------
  445|      0|    from++;
  446|      0|    len--;
  447|      0|  }
  448|       |
  449|  40.1k|  to = from + len;
  450|       |
  451|       |  // Ignore trailing spaces
  452|  40.1k|  while ((len > 0) && OPENSSL_isspace(to[-1])) {
  ------------------
  |  Branch (452:10): [True: 40.1k, False: 0]
  |  Branch (452:23): [True: 0, False: 40.1k]
  ------------------
  453|      0|    to--;
  454|      0|    len--;
  455|      0|  }
  456|       |
  457|  40.1k|  to = out->data;
  458|       |
  459|  40.1k|  i = 0;
  460|   321k|  while (i < len) {
  ------------------
  |  Branch (460:10): [True: 281k, False: 40.1k]
  ------------------
  461|       |    // Collapse multiple spaces
  462|   281k|    if (OPENSSL_isspace(*from)) {
  ------------------
  |  Branch (462:9): [True: 40.1k, False: 241k]
  ------------------
  463|       |      // Copy one space across
  464|  40.1k|      *to++ = ' ';
  465|       |      // Ignore subsequent spaces. Note: don't need to check len here
  466|       |      // because we know the last character is a non-space so we can't
  467|       |      // overflow.
  468|  40.1k|      do {
  469|  40.1k|        from++;
  470|  40.1k|        i++;
  471|  40.1k|      } while (OPENSSL_isspace(*from));
  ------------------
  |  Branch (471:16): [True: 0, False: 40.1k]
  ------------------
  472|   241k|    } else {
  473|   241k|      *to++ = OPENSSL_tolower(*from);
  474|   241k|      from++;
  475|   241k|      i++;
  476|   241k|    }
  477|   281k|  }
  478|       |
  479|  40.1k|  out->length = to - out->data;
  480|       |
  481|  40.1k|  return 1;
  482|  40.1k|}
x_name.c:i2d_name_canon:
  485|  80.3k|                          unsigned char **in) {
  486|  80.3k|  int len, ltmp;
  487|  80.3k|  size_t i;
  488|  80.3k|  ASN1_VALUE *v;
  489|  80.3k|  STACK_OF(ASN1_VALUE) *intname = (STACK_OF(ASN1_VALUE) *)_intname;
  ------------------
  |  |   81|  80.3k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  490|       |
  491|  80.3k|  len = 0;
  492|   160k|  for (i = 0; i < sk_ASN1_VALUE_num(intname); i++) {
  ------------------
  |  Branch (492:15): [True: 80.3k, False: 80.3k]
  ------------------
  493|  80.3k|    v = sk_ASN1_VALUE_value(intname, i);
  494|  80.3k|    ltmp = ASN1_item_ex_i2d(&v, in, ASN1_ITEM_rptr(X509_NAME_ENTRIES),
  ------------------
  |  |  274|  80.3k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  495|  80.3k|                            /*tag=*/-1, /*aclass=*/0);
  496|  80.3k|    if (ltmp < 0) {
  ------------------
  |  Branch (496:9): [True: 0, False: 80.3k]
  ------------------
  497|      0|      return ltmp;
  498|      0|    }
  499|  80.3k|    len += ltmp;
  500|  80.3k|  }
  501|  80.3k|  return len;
  502|  80.3k|}
x_name.c:local_sk_X509_NAME_ENTRY_free:
  180|  40.1k|static void local_sk_X509_NAME_ENTRY_free(STACK_OF(X509_NAME_ENTRY) *ne) {
  181|  40.1k|  sk_X509_NAME_ENTRY_free(ne);
  182|  40.1k|}
x_name.c:local_sk_X509_NAME_ENTRY_pop_free:
  184|  40.1k|static void local_sk_X509_NAME_ENTRY_pop_free(STACK_OF(X509_NAME_ENTRY) *ne) {
  185|  40.1k|  sk_X509_NAME_ENTRY_pop_free(ne, X509_NAME_ENTRY_free);
  186|  40.1k|}
x_name.c:x509_name_ex_i2d:
  258|  7.26k|                            const ASN1_ITEM *it) {
  259|  7.26k|  X509_NAME *a = (X509_NAME *)*val;
  260|  7.26k|  if (a->modified && (!x509_name_encode(a) || !x509_name_canon(a))) {
  ------------------
  |  Branch (260:7): [True: 0, False: 7.26k]
  |  Branch (260:23): [True: 0, False: 0]
  |  Branch (260:47): [True: 0, False: 0]
  ------------------
  261|      0|    return -1;
  262|      0|  }
  263|  7.26k|  int ret = a->bytes->length;
  264|  7.26k|  if (out != NULL) {
  ------------------
  |  Branch (264:7): [True: 3.63k, False: 3.63k]
  ------------------
  265|  3.63k|    OPENSSL_memcpy(*out, a->bytes->data, ret);
  266|  3.63k|    *out += ret;
  267|  3.63k|  }
  268|  7.26k|  return ret;
  269|  7.26k|}

x_pubkey.c:pubkey_cb:
   75|   120k|                     void *exarg) {
   76|   120k|  if (operation == ASN1_OP_FREE_POST) {
  ------------------
  |  |  540|   120k|#define ASN1_OP_FREE_POST	3
  ------------------
  |  Branch (76:7): [True: 20.0k, False: 100k]
  ------------------
   77|  20.0k|    X509_PUBKEY *pubkey = (X509_PUBKEY *)*pval;
   78|  20.0k|    EVP_PKEY_free(pubkey->pkey);
   79|  20.0k|  }
   80|   120k|  return 1;
   81|   120k|}

X509_free:
  126|  70.0k|void X509_free(X509 *x509) {
  127|  70.0k|  if (x509 == NULL || !CRYPTO_refcount_dec_and_test_zero(&x509->references)) {
  ------------------
  |  Branch (127:7): [True: 49.9k, False: 20.0k]
  |  Branch (127:23): [True: 0, False: 20.0k]
  ------------------
  128|  49.9k|    return;
  129|  49.9k|  }
  130|       |
  131|  20.0k|  CRYPTO_free_ex_data(&g_ex_data_class, x509, &x509->ex_data);
  132|       |
  133|  20.0k|  X509_CINF_free(x509->cert_info);
  134|  20.0k|  X509_ALGOR_free(x509->sig_alg);
  135|  20.0k|  ASN1_BIT_STRING_free(x509->signature);
  136|  20.0k|  ASN1_OCTET_STRING_free(x509->skid);
  137|  20.0k|  AUTHORITY_KEYID_free(x509->akid);
  138|  20.0k|  CRL_DIST_POINTS_free(x509->crldp);
  139|  20.0k|  GENERAL_NAMES_free(x509->altname);
  140|  20.0k|  NAME_CONSTRAINTS_free(x509->nc);
  141|  20.0k|  X509_CERT_AUX_free(x509->aux);
  142|  20.0k|  CRYPTO_MUTEX_cleanup(&x509->lock);
  143|       |
  144|  20.0k|  OPENSSL_free(x509);
  145|  20.0k|}
d2i_X509:
  237|      2|X509 *d2i_X509(X509 **out, const uint8_t **inp, long len) {
  238|      2|  X509 *ret = NULL;
  239|      2|  if (len < 0) {
  ------------------
  |  Branch (239:7): [True: 0, False: 2]
  ------------------
  240|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_BUFFER_TOO_SMALL);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  241|      0|    goto err;
  242|      0|  }
  243|       |
  244|      2|  CBS cbs;
  245|      2|  CBS_init(&cbs, *inp, (size_t)len);
  246|      2|  ret = x509_parse(&cbs, NULL);
  247|      2|  if (ret == NULL) {
  ------------------
  |  Branch (247:7): [True: 0, False: 2]
  ------------------
  248|      0|    goto err;
  249|      0|  }
  250|       |
  251|      2|  *inp = CBS_data(&cbs);
  252|       |
  253|      2|err:
  254|      2|  if (out != NULL) {
  ------------------
  |  Branch (254:7): [True: 0, False: 2]
  ------------------
  255|      0|    X509_free(*out);
  256|      0|    *out = ret;
  257|      0|  }
  258|      2|  return ret;
  259|      2|}
i2d_X509:
  261|  33.7k|int i2d_X509(X509 *x509, uint8_t **outp) {
  262|  33.7k|  if (x509 == NULL) {
  ------------------
  |  Branch (262:7): [True: 0, False: 33.7k]
  ------------------
  263|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_MISSING_VALUE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  264|      0|    return -1;
  265|      0|  }
  266|       |
  267|  33.7k|  CBB cbb, cert;
  268|  33.7k|  if (!CBB_init(&cbb, 64) ||  //
  ------------------
  |  Branch (268:7): [True: 0, False: 33.7k]
  ------------------
  269|  33.7k|      !CBB_add_asn1(&cbb, &cert, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  33.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  33.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  33.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (269:7): [True: 0, False: 33.7k]
  ------------------
  270|      0|    goto err;
  271|      0|  }
  272|       |
  273|       |  // TODO(crbug.com/boringssl/443): When the rest of the library is decoupled
  274|       |  // from the tasn_*.c implementation, replace this with |CBS|-based functions.
  275|  33.7k|  uint8_t *out;
  276|  33.7k|  int len = i2d_X509_CINF(x509->cert_info, NULL);
  277|  33.7k|  if (len < 0 ||  //
  ------------------
  |  Branch (277:7): [True: 0, False: 33.7k]
  ------------------
  278|  33.7k|      !CBB_add_space(&cert, &out, (size_t)len) ||
  ------------------
  |  Branch (278:7): [True: 0, False: 33.7k]
  ------------------
  279|  33.7k|      i2d_X509_CINF(x509->cert_info, &out) != len) {
  ------------------
  |  Branch (279:7): [True: 0, False: 33.7k]
  ------------------
  280|      0|    goto err;
  281|      0|  }
  282|       |
  283|  33.7k|  len = i2d_X509_ALGOR(x509->sig_alg, NULL);
  284|  33.7k|  if (len < 0 ||  //
  ------------------
  |  Branch (284:7): [True: 0, False: 33.7k]
  ------------------
  285|  33.7k|      !CBB_add_space(&cert, &out, (size_t)len) ||
  ------------------
  |  Branch (285:7): [True: 0, False: 33.7k]
  ------------------
  286|  33.7k|      i2d_X509_ALGOR(x509->sig_alg, &out) != len) {
  ------------------
  |  Branch (286:7): [True: 0, False: 33.7k]
  ------------------
  287|      0|    goto err;
  288|      0|  }
  289|       |
  290|  33.7k|  len = i2d_ASN1_BIT_STRING(x509->signature, NULL);
  291|  33.7k|  if (len < 0 ||  //
  ------------------
  |  Branch (291:7): [True: 0, False: 33.7k]
  ------------------
  292|  33.7k|      !CBB_add_space(&cert, &out, (size_t)len) ||
  ------------------
  |  Branch (292:7): [True: 0, False: 33.7k]
  ------------------
  293|  33.7k|      i2d_ASN1_BIT_STRING(x509->signature, &out) != len) {
  ------------------
  |  Branch (293:7): [True: 0, False: 33.7k]
  ------------------
  294|      0|    goto err;
  295|      0|  }
  296|       |
  297|  33.7k|  return CBB_finish_i2d(&cbb, outp);
  298|       |
  299|      0|err:
  300|      0|  CBB_cleanup(&cbb);
  301|      0|  return -1;
  302|  33.7k|}
X509_parse_from_buffer:
  366|  20.0k|X509 *X509_parse_from_buffer(CRYPTO_BUFFER *buf) {
  367|  20.0k|  CBS cbs;
  368|  20.0k|  CBS_init(&cbs, CRYPTO_BUFFER_data(buf), CRYPTO_BUFFER_len(buf));
  369|  20.0k|  X509 *ret = x509_parse(&cbs, buf);
  370|  20.0k|  if (ret == NULL || CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (370:7): [True: 0, False: 20.0k]
  |  Branch (370:22): [True: 0, False: 20.0k]
  ------------------
  371|      0|    X509_free(ret);
  372|      0|    return NULL;
  373|      0|  }
  374|       |
  375|  20.0k|  return ret;
  376|  20.0k|}
X509_up_ref:
  378|      2|int X509_up_ref(X509 *x) {
  379|      2|  CRYPTO_refcount_inc(&x->references);
  380|      2|  return 1;
  381|      2|}
x_x509.c:x509_new_null:
   94|  20.0k|static X509 *x509_new_null(void) {
   95|  20.0k|  X509 *ret = OPENSSL_malloc(sizeof(X509));
   96|  20.0k|  if (ret == NULL) {
  ------------------
  |  Branch (96:7): [True: 0, False: 20.0k]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|  20.0k|  OPENSSL_memset(ret, 0, sizeof(X509));
  100|       |
  101|  20.0k|  ret->references = 1;
  102|  20.0k|  ret->ex_pathlen = -1;
  103|  20.0k|  CRYPTO_new_ex_data(&ret->ex_data);
  104|  20.0k|  CRYPTO_MUTEX_init(&ret->lock);
  105|  20.0k|  return ret;
  106|  20.0k|}
x_x509.c:x509_parse:
  147|  20.0k|static X509 *x509_parse(CBS *cbs, CRYPTO_BUFFER *buf) {
  148|  20.0k|  CBS cert, tbs, sigalg, sig;
  149|  20.0k|  if (!CBS_get_asn1(cbs, &cert, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  20.0k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  20.0k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  20.0k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (149:7): [True: 0, False: 20.0k]
  ------------------
  150|       |      // Bound the length to comfortably fit in an int. Lengths in this
  151|       |      // module often omit overflow checks.
  152|  20.0k|      CBS_len(&cert) > INT_MAX / 2 ||
  ------------------
  |  Branch (152:7): [True: 0, False: 20.0k]
  ------------------
  153|  20.0k|      !CBS_get_asn1_element(&cert, &tbs, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  20.0k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  20.0k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  20.0k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (153:7): [True: 0, False: 20.0k]
  ------------------
  154|  20.0k|      !CBS_get_asn1_element(&cert, &sigalg, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  20.0k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  20.0k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  20.0k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (154:7): [True: 0, False: 20.0k]
  ------------------
  155|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  156|      0|    return NULL;
  157|      0|  }
  158|       |
  159|       |  // For just the signature field, we accept non-minimal BER lengths, though not
  160|       |  // indefinite-length encoding. See b/18228011.
  161|       |  //
  162|       |  // TODO(crbug.com/boringssl/354): Switch the affected callers to convert the
  163|       |  // certificate before parsing and then remove this workaround.
  164|  20.0k|  CBS_ASN1_TAG tag;
  165|  20.0k|  size_t header_len;
  166|  20.0k|  int indefinite;
  167|  20.0k|  if (!CBS_get_any_ber_asn1_element(&cert, &sig, &tag, &header_len,
  ------------------
  |  Branch (167:7): [True: 0, False: 20.0k]
  ------------------
  168|       |                                    /*out_ber_found=*/NULL,
  169|  20.0k|                                    &indefinite) ||
  170|  20.0k|      tag != CBS_ASN1_BITSTRING || indefinite ||  //
  ------------------
  |  |  216|  40.1k|#define CBS_ASN1_BITSTRING 0x3u
  ------------------
  |  Branch (170:7): [True: 0, False: 20.0k]
  |  Branch (170:36): [True: 0, False: 20.0k]
  ------------------
  171|  20.0k|      !CBS_skip(&sig, header_len) ||              //
  ------------------
  |  Branch (171:7): [True: 0, False: 20.0k]
  ------------------
  172|  20.0k|      CBS_len(&cert) != 0) {
  ------------------
  |  Branch (172:7): [True: 0, False: 20.0k]
  ------------------
  173|      0|    OPENSSL_PUT_ERROR(ASN1, ASN1_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  174|      0|    return NULL;
  175|      0|  }
  176|       |
  177|  20.0k|  X509 *ret = x509_new_null();
  178|  20.0k|  if (ret == NULL) {
  ------------------
  |  Branch (178:7): [True: 0, False: 20.0k]
  ------------------
  179|      0|    return NULL;
  180|      0|  }
  181|       |
  182|       |  // TODO(crbug.com/boringssl/443): When the rest of the library is decoupled
  183|       |  // from the tasn_*.c implementation, replace this with |CBS|-based functions.
  184|  20.0k|  const uint8_t *inp = CBS_data(&tbs);
  185|  20.0k|  if (ASN1_item_ex_d2i((ASN1_VALUE **)&ret->cert_info, &inp, CBS_len(&tbs),
  ------------------
  |  Branch (185:7): [True: 0, False: 20.0k]
  ------------------
  186|  20.0k|                       ASN1_ITEM_rptr(X509_CINF), /*tag=*/-1,
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  187|  20.0k|                       /*aclass=*/0, /*opt=*/0, buf) <= 0 ||
  188|  20.0k|      inp != CBS_data(&tbs) + CBS_len(&tbs)) {
  ------------------
  |  Branch (188:7): [True: 0, False: 20.0k]
  ------------------
  189|      0|    goto err;
  190|      0|  }
  191|       |
  192|  20.0k|  inp = CBS_data(&sigalg);
  193|  20.0k|  ret->sig_alg = d2i_X509_ALGOR(NULL, &inp, CBS_len(&sigalg));
  194|  20.0k|  if (ret->sig_alg == NULL || inp != CBS_data(&sigalg) + CBS_len(&sigalg)) {
  ------------------
  |  Branch (194:7): [True: 0, False: 20.0k]
  |  Branch (194:31): [True: 0, False: 20.0k]
  ------------------
  195|      0|    goto err;
  196|      0|  }
  197|       |
  198|  20.0k|  inp = CBS_data(&sig);
  199|  20.0k|  ret->signature = c2i_ASN1_BIT_STRING(NULL, &inp, CBS_len(&sig));
  200|  20.0k|  if (ret->signature == NULL || inp != CBS_data(&sig) + CBS_len(&sig)) {
  ------------------
  |  Branch (200:7): [True: 0, False: 20.0k]
  |  Branch (200:33): [True: 0, False: 20.0k]
  ------------------
  201|      0|    goto err;
  202|      0|  }
  203|       |
  204|       |  // The version must be one of v1(0), v2(1), or v3(2).
  205|  20.0k|  long version = X509_VERSION_1;
  ------------------
  |  |  168|  20.0k|#define X509_VERSION_1 0
  ------------------
  206|  20.0k|  if (ret->cert_info->version != NULL) {
  ------------------
  |  Branch (206:7): [True: 20.0k, False: 0]
  ------------------
  207|  20.0k|    version = ASN1_INTEGER_get(ret->cert_info->version);
  208|       |    // TODO(https://crbug.com/boringssl/364): |X509_VERSION_1| should
  209|       |    // also be rejected here. This means an explicitly-encoded X.509v1
  210|       |    // version. v1 is DEFAULT, so DER requires it be omitted.
  211|  20.0k|    if (version < X509_VERSION_1 || version > X509_VERSION_3) {
  ------------------
  |  |  168|  40.1k|#define X509_VERSION_1 0
  ------------------
                  if (version < X509_VERSION_1 || version > X509_VERSION_3) {
  ------------------
  |  |  170|  20.0k|#define X509_VERSION_3 2
  ------------------
  |  Branch (211:9): [True: 0, False: 20.0k]
  |  Branch (211:37): [True: 0, False: 20.0k]
  ------------------
  212|      0|      OPENSSL_PUT_ERROR(X509, X509_R_INVALID_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  213|      0|      goto err;
  214|      0|    }
  215|  20.0k|  }
  216|       |
  217|       |  // Per RFC 5280, section 4.1.2.8, these fields require v2 or v3.
  218|  20.0k|  if (version == X509_VERSION_1 && (ret->cert_info->issuerUID != NULL ||
  ------------------
  |  |  168|  40.1k|#define X509_VERSION_1 0
  ------------------
  |  Branch (218:7): [True: 0, False: 20.0k]
  |  Branch (218:37): [True: 0, False: 0]
  ------------------
  219|      0|                                    ret->cert_info->subjectUID != NULL)) {
  ------------------
  |  Branch (219:37): [True: 0, False: 0]
  ------------------
  220|      0|    OPENSSL_PUT_ERROR(X509, X509_R_INVALID_FIELD_FOR_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  221|      0|    goto err;
  222|      0|  }
  223|       |
  224|       |  // Per RFC 5280, section 4.1.2.9, extensions require v3.
  225|  20.0k|  if (version != X509_VERSION_3 && ret->cert_info->extensions != NULL) {
  ------------------
  |  |  170|  40.1k|#define X509_VERSION_3 2
  ------------------
  |  Branch (225:7): [True: 0, False: 20.0k]
  |  Branch (225:36): [True: 0, False: 0]
  ------------------
  226|      0|    OPENSSL_PUT_ERROR(X509, X509_R_INVALID_FIELD_FOR_VERSION);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  227|      0|    goto err;
  228|      0|  }
  229|       |
  230|  20.0k|  return ret;
  231|       |
  232|      0|err:
  233|      0|  X509_free(ret);
  234|      0|  return NULL;
  235|  20.0k|}

LLVMFuzzerTestOneInput:
  255|  4.83k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) {
  256|  4.83k|  constexpr size_t kMaxExpensiveAPIs = 100;
  257|  4.83k|  constexpr size_t kMaxAPIs = 10000;
  258|  4.83k|  unsigned expensive_api_count = 0;
  259|       |
  260|  4.83k|  const std::function<void(SSL_CTX *, CBS *)> kAPIs[] = {
  261|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  262|  4.83k|        uint8_t b;
  263|  4.83k|        if (!CBS_get_u8(cbs, &b)) {
  264|  4.83k|          return;
  265|  4.83k|        }
  266|  4.83k|        SSL_CTX_set_quiet_shutdown(ctx, b);
  267|  4.83k|      },
  268|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_quiet_shutdown(ctx); },
  269|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  270|  4.83k|        uint16_t version;
  271|  4.83k|        if (!CBS_get_u16(cbs, &version)) {
  272|  4.83k|          return;
  273|  4.83k|        }
  274|  4.83k|        SSL_CTX_set_min_proto_version(ctx, version);
  275|  4.83k|      },
  276|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  277|  4.83k|        uint16_t version;
  278|  4.83k|        if (!CBS_get_u16(cbs, &version)) {
  279|  4.83k|          return;
  280|  4.83k|        }
  281|  4.83k|        SSL_CTX_set_max_proto_version(ctx, version);
  282|  4.83k|      },
  283|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  284|  4.83k|        uint32_t options;
  285|  4.83k|        if (!CBS_get_u32(cbs, &options)) {
  286|  4.83k|          return;
  287|  4.83k|        }
  288|  4.83k|        SSL_CTX_set_options(ctx, options);
  289|  4.83k|      },
  290|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  291|  4.83k|        uint32_t options;
  292|  4.83k|        if (!CBS_get_u32(cbs, &options)) {
  293|  4.83k|          return;
  294|  4.83k|        }
  295|  4.83k|        SSL_CTX_clear_options(ctx, options);
  296|  4.83k|      },
  297|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_options(ctx); },
  298|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  299|  4.83k|        uint32_t mode;
  300|  4.83k|        if (!CBS_get_u32(cbs, &mode)) {
  301|  4.83k|          return;
  302|  4.83k|        }
  303|  4.83k|        SSL_CTX_set_mode(ctx, mode);
  304|  4.83k|      },
  305|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  306|  4.83k|        uint32_t mode;
  307|  4.83k|        if (!CBS_get_u32(cbs, &mode)) {
  308|  4.83k|          return;
  309|  4.83k|        }
  310|  4.83k|        SSL_CTX_clear_mode(ctx, mode);
  311|  4.83k|      },
  312|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_mode(ctx); },
  313|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  314|  4.83k|        SSL_CTX_use_certificate(ctx, g_state.cert_.get());
  315|  4.83k|      },
  316|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  317|  4.83k|        SSL_CTX_use_PrivateKey(ctx, g_state.pkey_.get());
  318|  4.83k|      },
  319|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  320|  4.83k|        SSL_CTX_set1_chain(ctx, g_state.certs_.get());
  321|  4.83k|      },
  322|  4.83k|      [&](SSL_CTX *ctx, CBS *cbs) {
  323|       |        // Avoid an unbounded certificate chain.
  324|  4.83k|        if (++expensive_api_count >= kMaxExpensiveAPIs) {
  325|  4.83k|          return;
  326|  4.83k|        }
  327|       |
  328|  4.83k|        SSL_CTX_add1_chain_cert(ctx, g_state.cert_.get());
  329|  4.83k|      },
  330|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_clear_chain_certs(ctx); },
  331|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_clear_extra_chain_certs(ctx); },
  332|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_check_private_key(ctx); },
  333|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get0_certificate(ctx); },
  334|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get0_privatekey(ctx); },
  335|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  336|  4.83k|        STACK_OF(X509) * chains;
  337|  4.83k|        SSL_CTX_get0_chain_certs(ctx, &chains);
  338|  4.83k|      },
  339|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  340|  4.83k|        std::vector<uint8_t> sct_data;
  341|  4.83k|        if (!GetVector(&sct_data, cbs)) {
  342|  4.83k|          return;
  343|  4.83k|        }
  344|  4.83k|        SSL_CTX_set_signed_cert_timestamp_list(ctx, sct_data.data(),
  345|  4.83k|                                               sct_data.size());
  346|  4.83k|      },
  347|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  348|  4.83k|        std::vector<uint8_t> ocsp_data;
  349|  4.83k|        if (!GetVector(&ocsp_data, cbs)) {
  350|  4.83k|          return;
  351|  4.83k|        }
  352|  4.83k|        SSL_CTX_set_ocsp_response(ctx, ocsp_data.data(), ocsp_data.size());
  353|  4.83k|      },
  354|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  355|  4.83k|        std::vector<uint16_t> algs;
  356|  4.83k|        if (!GetVector(&algs, cbs)) {
  357|  4.83k|          return;
  358|  4.83k|        }
  359|  4.83k|        SSL_CTX_set_signing_algorithm_prefs(ctx, algs.data(), algs.size());
  360|  4.83k|      },
  361|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  362|  4.83k|        std::string ciphers;
  363|  4.83k|        if (!GetString(&ciphers, cbs)) {
  364|  4.83k|          return;
  365|  4.83k|        }
  366|  4.83k|        SSL_CTX_set_strict_cipher_list(ctx, ciphers.c_str());
  367|  4.83k|      },
  368|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  369|  4.83k|        std::string ciphers;
  370|  4.83k|        if (!GetString(&ciphers, cbs)) {
  371|  4.83k|          return;
  372|  4.83k|        }
  373|  4.83k|        SSL_CTX_set_cipher_list(ctx, ciphers.c_str());
  374|  4.83k|      },
  375|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  376|  4.83k|        std::vector<uint16_t> algs;
  377|  4.83k|        if (!GetVector(&algs, cbs)) {
  378|  4.83k|          return;
  379|  4.83k|        }
  380|  4.83k|        SSL_CTX_set_verify_algorithm_prefs(ctx, algs.data(), algs.size());
  381|  4.83k|      },
  382|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  383|  4.83k|        std::vector<uint8_t> id_ctx;
  384|  4.83k|        if (!GetVector(&id_ctx, cbs)) {
  385|  4.83k|          return;
  386|  4.83k|        }
  387|  4.83k|        SSL_CTX_set_session_id_context(ctx, id_ctx.data(), id_ctx.size());
  388|  4.83k|      },
  389|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  390|  4.83k|        uint32_t size;
  391|  4.83k|        if (!CBS_get_u32(cbs, &size)) {
  392|  4.83k|          return;
  393|  4.83k|        }
  394|  4.83k|        SSL_CTX_sess_set_cache_size(ctx, size);
  395|  4.83k|      },
  396|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_sess_get_cache_size(ctx); },
  397|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_sess_number(ctx); },
  398|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  399|  4.83k|        uint32_t time;
  400|  4.83k|        if (!CBS_get_u32(cbs, &time)) {
  401|  4.83k|          return;
  402|  4.83k|        }
  403|  4.83k|        SSL_CTX_flush_sessions(ctx, time);
  404|  4.83k|      },
  405|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  406|  4.83k|        std::vector<uint8_t> keys;
  407|  4.83k|        if (!GetVector(&keys, cbs)) {
  408|  4.83k|          return;
  409|  4.83k|        }
  410|  4.83k|        SSL_CTX_set_tlsext_ticket_keys(ctx, keys.data(), keys.size());
  411|  4.83k|      },
  412|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  413|  4.83k|        std::vector<int> groups;
  414|  4.83k|        if (!GetVector(&groups, cbs)) {
  415|  4.83k|          return;
  416|  4.83k|        }
  417|  4.83k|        SSL_CTX_set1_groups(ctx, groups.data(), groups.size());
  418|  4.83k|      },
  419|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  420|  4.83k|        std::vector<uint16_t> groups;
  421|  4.83k|        if (!GetVector(&groups, cbs)) {
  422|  4.83k|          return;
  423|  4.83k|        }
  424|  4.83k|        SSL_CTX_set1_group_ids(ctx, groups.data(), groups.size());
  425|  4.83k|      },
  426|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  427|  4.83k|        std::string groups;
  428|  4.83k|        if (!GetString(&groups, cbs)) {
  429|  4.83k|          return;
  430|  4.83k|        }
  431|  4.83k|        SSL_CTX_set1_groups_list(ctx, groups.c_str());
  432|  4.83k|      },
  433|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  434|  4.83k|        SSL_CTX_enable_signed_cert_timestamps(ctx);
  435|  4.83k|      },
  436|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_enable_ocsp_stapling(ctx); },
  437|  4.83k|      [&](SSL_CTX *ctx, CBS *cbs) {
  438|       |        // Avoid an unbounded client CA list.
  439|  4.83k|        if (++expensive_api_count >= kMaxExpensiveAPIs) {
  440|  4.83k|          return;
  441|  4.83k|        }
  442|       |
  443|  4.83k|        SSL_CTX_add_client_CA(ctx, g_state.cert_.get());
  444|  4.83k|      },
  445|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  446|  4.83k|        std::vector<uint8_t> protos;
  447|  4.83k|        if (!GetVector(&protos, cbs)) {
  448|  4.83k|          return;
  449|  4.83k|        }
  450|  4.83k|        SSL_CTX_set_alpn_protos(ctx, protos.data(), protos.size());
  451|  4.83k|      },
  452|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  453|  4.83k|        std::string profiles;
  454|  4.83k|        if (!GetString(&profiles, cbs)) {
  455|  4.83k|          return;
  456|  4.83k|        }
  457|  4.83k|        SSL_CTX_set_srtp_profiles(ctx, profiles.c_str());
  458|  4.83k|      },
  459|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_max_cert_list(ctx); },
  460|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  461|  4.83k|        uint32_t size;
  462|  4.83k|        if (!CBS_get_u32(cbs, &size)) {
  463|  4.83k|          return;
  464|  4.83k|        }
  465|  4.83k|        SSL_CTX_set_max_cert_list(ctx, size);
  466|  4.83k|      },
  467|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  468|  4.83k|        uint32_t size;
  469|  4.83k|        if (!CBS_get_u32(cbs, &size)) {
  470|  4.83k|          return;
  471|  4.83k|        }
  472|  4.83k|        SSL_CTX_set_max_send_fragment(ctx, size);
  473|  4.83k|      },
  474|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  475|  4.83k|        uint8_t b;
  476|  4.83k|        if (!CBS_get_u8(cbs, &b)) {
  477|  4.83k|          return;
  478|  4.83k|        }
  479|  4.83k|        SSL_CTX_set_retain_only_sha256_of_client_certs(ctx, b);
  480|  4.83k|      },
  481|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  482|  4.83k|        uint8_t b;
  483|  4.83k|        if (!CBS_get_u8(cbs, &b)) {
  484|  4.83k|          return;
  485|  4.83k|        }
  486|  4.83k|        SSL_CTX_set_grease_enabled(ctx, b);
  487|  4.83k|      },
  488|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  489|  4.83k|        std::vector<int> sigalgs;
  490|  4.83k|        if (!GetVector(&sigalgs, cbs)) {
  491|  4.83k|          return;
  492|  4.83k|        }
  493|  4.83k|        SSL_CTX_set1_sigalgs(ctx, sigalgs.data(), sigalgs.size());
  494|  4.83k|      },
  495|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  496|  4.83k|        std::string sigalgs;
  497|  4.83k|        if (!GetString(&sigalgs, cbs)) {
  498|  4.83k|          return;
  499|  4.83k|        }
  500|  4.83k|        SSL_CTX_set1_sigalgs_list(ctx, sigalgs.c_str());
  501|  4.83k|      },
  502|  4.83k|      [](SSL_CTX *ctx, CBS *cbs) {
  503|  4.83k|        bssl::UniquePtr<SSL_ECH_KEYS> keys(SSL_ECH_KEYS_new());
  504|  4.83k|        if (keys == nullptr) {
  505|  4.83k|          return;
  506|  4.83k|        }
  507|  4.83k|        uint8_t is_retry_config;
  508|  4.83k|        CBS ech_config, private_key;
  509|  4.83k|        if (!CBS_get_u8(cbs, &is_retry_config) ||
  510|  4.83k|            !CBS_get_u16_length_prefixed(cbs, &ech_config) ||
  511|  4.83k|            !CBS_get_u16_length_prefixed(cbs, &private_key)) {
  512|  4.83k|          return;
  513|  4.83k|        }
  514|  4.83k|        bssl::ScopedEVP_HPKE_KEY key;
  515|  4.83k|        if (!EVP_HPKE_KEY_init(key.get(), EVP_hpke_x25519_hkdf_sha256(),
  516|  4.83k|                               CBS_data(&private_key), CBS_len(&private_key)) ||
  517|  4.83k|            !SSL_ECH_KEYS_add(keys.get(), is_retry_config,
  518|  4.83k|                              CBS_data(&ech_config), CBS_len(&ech_config),
  519|  4.83k|                              key.get()) ||
  520|  4.83k|            !SSL_CTX_set1_ech_keys(ctx, keys.get())) {
  521|  4.83k|          return;
  522|  4.83k|        }
  523|  4.83k|      },
  524|  4.83k|  };
  525|       |
  526|  4.83k|  bssl::UniquePtr<SSL_CTX> ctx(SSL_CTX_new(TLS_method()));
  527|       |
  528|       |  // If the number of functions exceeds this limit then the code needs to do
  529|       |  // more than sample a single uint8_t to pick the function.
  530|  4.83k|  static_assert(OPENSSL_ARRAY_SIZE(kAPIs) < 256, "kAPIs too large");
  531|       |
  532|  4.83k|  CBS cbs;
  533|  4.83k|  CBS_init(&cbs, buf, len);
  534|       |
  535|   538k|  for (unsigned i = 0; i < kMaxAPIs; i++) {
  ------------------
  |  Branch (535:24): [True: 538k, False: 15]
  ------------------
  536|   538k|    uint8_t index;
  537|   538k|    if (!CBS_get_u8(&cbs, &index)) {
  ------------------
  |  Branch (537:9): [True: 4.81k, False: 533k]
  ------------------
  538|  4.81k|      break;
  539|  4.81k|    }
  540|       |
  541|   533k|    kAPIs[index % OPENSSL_ARRAY_SIZE(kAPIs)](ctx.get(), &cbs);
  ------------------
  |  |  221|   533k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  542|   533k|  }
  543|       |
  544|  4.83k|  bssl::UniquePtr<SSL> ssl(SSL_new(ctx.get()));
  545|  4.83k|  ERR_clear_error();
  546|       |
  547|  4.83k|  return 0;
  548|  4.83k|}
_ZN11GlobalStateC2Ev:
  205|      2|  GlobalState() {
  206|      2|    const uint8_t *bufp = kRSAPrivateKeyDER;
  207|      2|    RSA *privkey = d2i_RSAPrivateKey(NULL, &bufp, sizeof(kRSAPrivateKeyDER));
  208|      2|    assert(privkey != nullptr);
  209|       |
  210|      0|    pkey_.reset(EVP_PKEY_new());
  211|      2|    EVP_PKEY_assign_RSA(pkey_.get(), privkey);
  212|       |
  213|      2|    bufp = kCertificateDER;
  214|      2|    cert_.reset(d2i_X509(NULL, &bufp, sizeof(kCertificateDER)));
  215|      2|    assert(cert_.get() != nullptr);
  216|       |
  217|      0|    certs_.reset(sk_X509_new_null());
  218|      2|    bssl::PushToStack(certs_.get(), bssl::UpRef(cert_));
  219|      2|  }
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_0clEP10ssl_ctx_stP6cbs_st:
  261|   136k|      [](SSL_CTX *ctx, CBS *cbs) {
  262|   136k|        uint8_t b;
  263|   136k|        if (!CBS_get_u8(cbs, &b)) {
  ------------------
  |  Branch (263:13): [True: 76, False: 136k]
  ------------------
  264|     76|          return;
  265|     76|        }
  266|   136k|        SSL_CTX_set_quiet_shutdown(ctx, b);
  267|   136k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_1clEP10ssl_ctx_stP6cbs_st:
  268|  27.3k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_quiet_shutdown(ctx); },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_2clEP10ssl_ctx_stP6cbs_st:
  269|  9.18k|      [](SSL_CTX *ctx, CBS *cbs) {
  270|  9.18k|        uint16_t version;
  271|  9.18k|        if (!CBS_get_u16(cbs, &version)) {
  ------------------
  |  Branch (271:13): [True: 36, False: 9.14k]
  ------------------
  272|     36|          return;
  273|     36|        }
  274|  9.14k|        SSL_CTX_set_min_proto_version(ctx, version);
  275|  9.14k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_3clEP10ssl_ctx_stP6cbs_st:
  276|  25.6k|      [](SSL_CTX *ctx, CBS *cbs) {
  277|  25.6k|        uint16_t version;
  278|  25.6k|        if (!CBS_get_u16(cbs, &version)) {
  ------------------
  |  Branch (278:13): [True: 45, False: 25.6k]
  ------------------
  279|     45|          return;
  280|     45|        }
  281|  25.6k|        SSL_CTX_set_max_proto_version(ctx, version);
  282|  25.6k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_4clEP10ssl_ctx_stP6cbs_st:
  283|  5.16k|      [](SSL_CTX *ctx, CBS *cbs) {
  284|  5.16k|        uint32_t options;
  285|  5.16k|        if (!CBS_get_u32(cbs, &options)) {
  ------------------
  |  Branch (285:13): [True: 48, False: 5.11k]
  ------------------
  286|     48|          return;
  287|     48|        }
  288|  5.11k|        SSL_CTX_set_options(ctx, options);
  ------------------
  |  | 5447|  5.11k|#define SSL_CTX_set_options SSL_CTX_set_options
  ------------------
  289|  5.11k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_5clEP10ssl_ctx_stP6cbs_st:
  290|  2.96k|      [](SSL_CTX *ctx, CBS *cbs) {
  291|  2.96k|        uint32_t options;
  292|  2.96k|        if (!CBS_get_u32(cbs, &options)) {
  ------------------
  |  Branch (292:13): [True: 38, False: 2.92k]
  ------------------
  293|     38|          return;
  294|     38|        }
  295|  2.92k|        SSL_CTX_clear_options(ctx, options);
  ------------------
  |  | 5427|  2.92k|#define SSL_CTX_clear_options SSL_CTX_clear_options
  ------------------
  296|  2.92k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_6clEP10ssl_ctx_stP6cbs_st:
  297|  3.94k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_options(ctx); },
  ------------------
  |  | 5432|  3.94k|#define SSL_CTX_get_options SSL_CTX_get_options
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_7clEP10ssl_ctx_stP6cbs_st:
  298|  3.33k|      [](SSL_CTX *ctx, CBS *cbs) {
  299|  3.33k|        uint32_t mode;
  300|  3.33k|        if (!CBS_get_u32(cbs, &mode)) {
  ------------------
  |  Branch (300:13): [True: 32, False: 3.29k]
  ------------------
  301|     32|          return;
  302|     32|        }
  303|  3.29k|        SSL_CTX_set_mode(ctx, mode);
  ------------------
  |  | 5445|  3.29k|#define SSL_CTX_set_mode SSL_CTX_set_mode
  ------------------
  304|  3.29k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_8clEP10ssl_ctx_stP6cbs_st:
  305|  5.88k|      [](SSL_CTX *ctx, CBS *cbs) {
  306|  5.88k|        uint32_t mode;
  307|  5.88k|        if (!CBS_get_u32(cbs, &mode)) {
  ------------------
  |  Branch (307:13): [True: 44, False: 5.84k]
  ------------------
  308|     44|          return;
  309|     44|        }
  310|  5.84k|        SSL_CTX_clear_mode(ctx, mode);
  ------------------
  |  | 5426|  5.84k|#define SSL_CTX_clear_mode SSL_CTX_clear_mode
  ------------------
  311|  5.84k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK3$_9clEP10ssl_ctx_stP6cbs_st:
  312|  3.30k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_mode(ctx); },
  ------------------
  |  | 5431|  3.30k|#define SSL_CTX_get_mode SSL_CTX_get_mode
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_10clEP10ssl_ctx_stP6cbs_st:
  313|  12.9k|      [](SSL_CTX *ctx, CBS *cbs) {
  314|  12.9k|        SSL_CTX_use_certificate(ctx, g_state.cert_.get());
  315|  12.9k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_11clEP10ssl_ctx_stP6cbs_st:
  316|  6.72k|      [](SSL_CTX *ctx, CBS *cbs) {
  317|  6.72k|        SSL_CTX_use_PrivateKey(ctx, g_state.pkey_.get());
  318|  6.72k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_12clEP10ssl_ctx_stP6cbs_st:
  319|  10.2k|      [](SSL_CTX *ctx, CBS *cbs) {
  320|  10.2k|        SSL_CTX_set1_chain(ctx, g_state.certs_.get());
  ------------------
  |  | 5441|  10.2k|#define SSL_CTX_set1_chain SSL_CTX_set1_chain
  ------------------
  321|  10.2k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_13clEP10ssl_ctx_stP6cbs_st:
  322|  27.9k|      [&](SSL_CTX *ctx, CBS *cbs) {
  323|       |        // Avoid an unbounded certificate chain.
  324|  27.9k|        if (++expensive_api_count >= kMaxExpensiveAPIs) {
  ------------------
  |  Branch (324:13): [True: 17.3k, False: 10.6k]
  ------------------
  325|  17.3k|          return;
  326|  17.3k|        }
  327|       |
  328|  10.6k|        SSL_CTX_add1_chain_cert(ctx, g_state.cert_.get());
  ------------------
  |  | 5422|  10.6k|#define SSL_CTX_add1_chain_cert SSL_CTX_add1_chain_cert
  ------------------
  329|  10.6k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_14clEP10ssl_ctx_stP6cbs_st:
  330|  6.19k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_clear_chain_certs(ctx); },
  ------------------
  |  | 5425|  6.19k|#define SSL_CTX_clear_chain_certs SSL_CTX_clear_chain_certs
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_15clEP10ssl_ctx_stP6cbs_st:
  331|  28.3k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_clear_extra_chain_certs(ctx); },
  ------------------
  |  | 5424|  28.3k|#define SSL_CTX_clear_extra_chain_certs SSL_CTX_clear_extra_chain_certs
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_16clEP10ssl_ctx_stP6cbs_st:
  332|  8.41k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_check_private_key(ctx); },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_17clEP10ssl_ctx_stP6cbs_st:
  333|  6.36k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get0_certificate(ctx); },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_18clEP10ssl_ctx_stP6cbs_st:
  334|  1.99k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get0_privatekey(ctx); },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_19clEP10ssl_ctx_stP6cbs_st:
  335|  6.43k|      [](SSL_CTX *ctx, CBS *cbs) {
  336|  6.43k|        STACK_OF(X509) * chains;
  ------------------
  |  |   81|  6.43k|#define STACK_OF(type) struct stack_st_##type
  ------------------
  337|  6.43k|        SSL_CTX_get0_chain_certs(ctx, &chains);
  ------------------
  |  | 5428|  6.43k|#define SSL_CTX_get0_chain_certs SSL_CTX_get0_chain_certs
  ------------------
  338|  6.43k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_20clEP10ssl_ctx_stP6cbs_st:
  339|  3.06k|      [](SSL_CTX *ctx, CBS *cbs) {
  340|  3.06k|        std::vector<uint8_t> sct_data;
  341|  3.06k|        if (!GetVector(&sct_data, cbs)) {
  ------------------
  |  Branch (341:13): [True: 106, False: 2.95k]
  ------------------
  342|    106|          return;
  343|    106|        }
  344|  2.95k|        SSL_CTX_set_signed_cert_timestamp_list(ctx, sct_data.data(),
  345|  2.95k|                                               sct_data.size());
  346|  2.95k|      },
ssl_ctx_api.cc:_ZL9GetVectorIhEbPNSt3__16vectorIT_NS0_9allocatorIS2_EEEEP6cbs_st:
  239|  29.5k|static bool GetVector(std::vector<T> *out, CBS *cbs) {
  240|  29.5k|  static_assert(std::is_pod<T>::value,
  241|  29.5k|                "GetVector may only be called on POD types");
  242|       |
  243|  29.5k|  CBS child;
  244|  29.5k|  if (!CBS_get_u8_length_prefixed(cbs, &child)) {
  ------------------
  |  Branch (244:7): [True: 565, False: 29.0k]
  ------------------
  245|    565|    return false;
  246|    565|  }
  247|       |
  248|  29.0k|  size_t num = CBS_len(&child) / sizeof(T);
  249|  29.0k|  out->resize(num);
  250|  29.0k|  out->shrink_to_fit();  // Ensure ASan notices out-of-bounds reads.
  251|  29.0k|  OPENSSL_memcpy(out->data(), CBS_data(&child), num * sizeof(T));
  252|  29.0k|  return true;
  253|  29.5k|}
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_21clEP10ssl_ctx_stP6cbs_st:
  347|  18.7k|      [](SSL_CTX *ctx, CBS *cbs) {
  348|  18.7k|        std::vector<uint8_t> ocsp_data;
  349|  18.7k|        if (!GetVector(&ocsp_data, cbs)) {
  ------------------
  |  Branch (349:13): [True: 158, False: 18.5k]
  ------------------
  350|    158|          return;
  351|    158|        }
  352|  18.5k|        SSL_CTX_set_ocsp_response(ctx, ocsp_data.data(), ocsp_data.size());
  353|  18.5k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_22clEP10ssl_ctx_stP6cbs_st:
  354|  4.06k|      [](SSL_CTX *ctx, CBS *cbs) {
  355|  4.06k|        std::vector<uint16_t> algs;
  356|  4.06k|        if (!GetVector(&algs, cbs)) {
  ------------------
  |  Branch (356:13): [True: 130, False: 3.93k]
  ------------------
  357|    130|          return;
  358|    130|        }
  359|  3.93k|        SSL_CTX_set_signing_algorithm_prefs(ctx, algs.data(), algs.size());
  360|  3.93k|      },
ssl_ctx_api.cc:_ZL9GetVectorItEbPNSt3__16vectorIT_NS0_9allocatorIS2_EEEEP6cbs_st:
  239|  10.5k|static bool GetVector(std::vector<T> *out, CBS *cbs) {
  240|  10.5k|  static_assert(std::is_pod<T>::value,
  241|  10.5k|                "GetVector may only be called on POD types");
  242|       |
  243|  10.5k|  CBS child;
  244|  10.5k|  if (!CBS_get_u8_length_prefixed(cbs, &child)) {
  ------------------
  |  Branch (244:7): [True: 358, False: 10.1k]
  ------------------
  245|    358|    return false;
  246|    358|  }
  247|       |
  248|  10.1k|  size_t num = CBS_len(&child) / sizeof(T);
  249|  10.1k|  out->resize(num);
  250|  10.1k|  out->shrink_to_fit();  // Ensure ASan notices out-of-bounds reads.
  251|  10.1k|  OPENSSL_memcpy(out->data(), CBS_data(&child), num * sizeof(T));
  252|  10.1k|  return true;
  253|  10.5k|}
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_23clEP10ssl_ctx_stP6cbs_st:
  361|  7.30k|      [](SSL_CTX *ctx, CBS *cbs) {
  362|  7.30k|        std::string ciphers;
  363|  7.30k|        if (!GetString(&ciphers, cbs)) {
  ------------------
  |  Branch (363:13): [True: 160, False: 7.14k]
  ------------------
  364|    160|          return;
  365|    160|        }
  366|  7.14k|        SSL_CTX_set_strict_cipher_list(ctx, ciphers.c_str());
  367|  7.14k|      },
ssl_ctx_api.cc:_ZL9GetStringPNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEEP6cbs_st:
  228|  47.5k|static bool GetString(std::string *out, CBS *cbs) {
  229|  47.5k|  CBS str;
  230|  47.5k|  if (!CBS_get_u8_length_prefixed(cbs, &str)) {
  ------------------
  |  Branch (230:7): [True: 735, False: 46.8k]
  ------------------
  231|    735|    return false;
  232|    735|  }
  233|       |
  234|  46.8k|  out->assign(reinterpret_cast<const char *>(CBS_data(&str)), CBS_len(&str));
  235|  46.8k|  return true;
  236|  47.5k|}
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_24clEP10ssl_ctx_stP6cbs_st:
  368|  20.4k|      [](SSL_CTX *ctx, CBS *cbs) {
  369|  20.4k|        std::string ciphers;
  370|  20.4k|        if (!GetString(&ciphers, cbs)) {
  ------------------
  |  Branch (370:13): [True: 178, False: 20.2k]
  ------------------
  371|    178|          return;
  372|    178|        }
  373|  20.2k|        SSL_CTX_set_cipher_list(ctx, ciphers.c_str());
  374|  20.2k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_25clEP10ssl_ctx_stP6cbs_st:
  375|  1.38k|      [](SSL_CTX *ctx, CBS *cbs) {
  376|  1.38k|        std::vector<uint16_t> algs;
  377|  1.38k|        if (!GetVector(&algs, cbs)) {
  ------------------
  |  Branch (377:13): [True: 84, False: 1.29k]
  ------------------
  378|     84|          return;
  379|     84|        }
  380|  1.29k|        SSL_CTX_set_verify_algorithm_prefs(ctx, algs.data(), algs.size());
  381|  1.29k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_26clEP10ssl_ctx_stP6cbs_st:
  382|  2.70k|      [](SSL_CTX *ctx, CBS *cbs) {
  383|  2.70k|        std::vector<uint8_t> id_ctx;
  384|  2.70k|        if (!GetVector(&id_ctx, cbs)) {
  ------------------
  |  Branch (384:13): [True: 104, False: 2.59k]
  ------------------
  385|    104|          return;
  386|    104|        }
  387|  2.59k|        SSL_CTX_set_session_id_context(ctx, id_ctx.data(), id_ctx.size());
  388|  2.59k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_27clEP10ssl_ctx_stP6cbs_st:
  389|  2.32k|      [](SSL_CTX *ctx, CBS *cbs) {
  390|  2.32k|        uint32_t size;
  391|  2.32k|        if (!CBS_get_u32(cbs, &size)) {
  ------------------
  |  Branch (391:13): [True: 31, False: 2.29k]
  ------------------
  392|     31|          return;
  393|     31|        }
  394|  2.29k|        SSL_CTX_sess_set_cache_size(ctx, size);
  ------------------
  |  | 5439|  2.29k|#define SSL_CTX_sess_set_cache_size SSL_CTX_sess_set_cache_size
  ------------------
  395|  2.29k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_28clEP10ssl_ctx_stP6cbs_st:
  396|  7.18k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_sess_get_cache_size(ctx); },
  ------------------
  |  | 5437|  7.18k|#define SSL_CTX_sess_get_cache_size SSL_CTX_sess_get_cache_size
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_29clEP10ssl_ctx_stP6cbs_st:
  397|  4.94k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_sess_number(ctx); },
  ------------------
  |  | 5438|  4.94k|#define SSL_CTX_sess_number SSL_CTX_sess_number
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_30clEP10ssl_ctx_stP6cbs_st:
  398|  4.40k|      [](SSL_CTX *ctx, CBS *cbs) {
  399|  4.40k|        uint32_t time;
  400|  4.40k|        if (!CBS_get_u32(cbs, &time)) {
  ------------------
  |  Branch (400:13): [True: 48, False: 4.35k]
  ------------------
  401|     48|          return;
  402|     48|        }
  403|  4.35k|        SSL_CTX_flush_sessions(ctx, time);
  404|  4.35k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_31clEP10ssl_ctx_stP6cbs_st:
  405|  1.99k|      [](SSL_CTX *ctx, CBS *cbs) {
  406|  1.99k|        std::vector<uint8_t> keys;
  407|  1.99k|        if (!GetVector(&keys, cbs)) {
  ------------------
  |  Branch (407:13): [True: 96, False: 1.90k]
  ------------------
  408|     96|          return;
  409|     96|        }
  410|  1.90k|        SSL_CTX_set_tlsext_ticket_keys(ctx, keys.data(), keys.size());
  ------------------
  |  | 5454|  1.90k|#define SSL_CTX_set_tlsext_ticket_keys SSL_CTX_set_tlsext_ticket_keys
  ------------------
  411|  1.90k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_32clEP10ssl_ctx_stP6cbs_st:
  412|  8.84k|      [](SSL_CTX *ctx, CBS *cbs) {
  413|  8.84k|        std::vector<int> groups;
  414|  8.84k|        if (!GetVector(&groups, cbs)) {
  ------------------
  |  Branch (414:13): [True: 167, False: 8.67k]
  ------------------
  415|    167|          return;
  416|    167|        }
  417|  8.67k|        SSL_CTX_set1_groups(ctx, groups.data(), groups.size());
  ------------------
  |  | 5442|  8.67k|#define SSL_CTX_set1_groups SSL_CTX_set1_groups
  ------------------
  418|  8.67k|      },
ssl_ctx_api.cc:_ZL9GetVectorIiEbPNSt3__16vectorIT_NS0_9allocatorIS2_EEEEP6cbs_st:
  239|  16.8k|static bool GetVector(std::vector<T> *out, CBS *cbs) {
  240|  16.8k|  static_assert(std::is_pod<T>::value,
  241|  16.8k|                "GetVector may only be called on POD types");
  242|       |
  243|  16.8k|  CBS child;
  244|  16.8k|  if (!CBS_get_u8_length_prefixed(cbs, &child)) {
  ------------------
  |  Branch (244:7): [True: 301, False: 16.5k]
  ------------------
  245|    301|    return false;
  246|    301|  }
  247|       |
  248|  16.5k|  size_t num = CBS_len(&child) / sizeof(T);
  249|  16.5k|  out->resize(num);
  250|  16.5k|  out->shrink_to_fit();  // Ensure ASan notices out-of-bounds reads.
  251|  16.5k|  OPENSSL_memcpy(out->data(), CBS_data(&child), num * sizeof(T));
  252|  16.5k|  return true;
  253|  16.8k|}
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_33clEP10ssl_ctx_stP6cbs_st:
  419|  5.07k|      [](SSL_CTX *ctx, CBS *cbs) {
  420|  5.07k|        std::vector<uint16_t> groups;
  421|  5.07k|        if (!GetVector(&groups, cbs)) {
  ------------------
  |  Branch (421:13): [True: 144, False: 4.92k]
  ------------------
  422|    144|          return;
  423|    144|        }
  424|  4.92k|        SSL_CTX_set1_group_ids(ctx, groups.data(), groups.size());
  425|  4.92k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_34clEP10ssl_ctx_stP6cbs_st:
  426|  6.16k|      [](SSL_CTX *ctx, CBS *cbs) {
  427|  6.16k|        std::string groups;
  428|  6.16k|        if (!GetString(&groups, cbs)) {
  ------------------
  |  Branch (428:13): [True: 171, False: 5.99k]
  ------------------
  429|    171|          return;
  430|    171|        }
  431|  5.99k|        SSL_CTX_set1_groups_list(ctx, groups.c_str());
  432|  5.99k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_35clEP10ssl_ctx_stP6cbs_st:
  433|  12.7k|      [](SSL_CTX *ctx, CBS *cbs) {
  434|  12.7k|        SSL_CTX_enable_signed_cert_timestamps(ctx);
  435|  12.7k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_36clEP10ssl_ctx_stP6cbs_st:
  436|  10.2k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_enable_ocsp_stapling(ctx); },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_37clEP10ssl_ctx_stP6cbs_st:
  437|  19.6k|      [&](SSL_CTX *ctx, CBS *cbs) {
  438|       |        // Avoid an unbounded client CA list.
  439|  19.6k|        if (++expensive_api_count >= kMaxExpensiveAPIs) {
  ------------------
  |  Branch (439:13): [True: 16.0k, False: 3.63k]
  ------------------
  440|  16.0k|          return;
  441|  16.0k|        }
  442|       |
  443|  3.63k|        SSL_CTX_add_client_CA(ctx, g_state.cert_.get());
  444|  3.63k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_38clEP10ssl_ctx_stP6cbs_st:
  445|  3.05k|      [](SSL_CTX *ctx, CBS *cbs) {
  446|  3.05k|        std::vector<uint8_t> protos;
  447|  3.05k|        if (!GetVector(&protos, cbs)) {
  ------------------
  |  Branch (447:13): [True: 101, False: 2.95k]
  ------------------
  448|    101|          return;
  449|    101|        }
  450|  2.95k|        SSL_CTX_set_alpn_protos(ctx, protos.data(), protos.size());
  451|  2.95k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_39clEP10ssl_ctx_stP6cbs_st:
  452|  5.59k|      [](SSL_CTX *ctx, CBS *cbs) {
  453|  5.59k|        std::string profiles;
  454|  5.59k|        if (!GetString(&profiles, cbs)) {
  ------------------
  |  Branch (454:13): [True: 105, False: 5.48k]
  ------------------
  455|    105|          return;
  456|    105|        }
  457|  5.48k|        SSL_CTX_set_srtp_profiles(ctx, profiles.c_str());
  458|  5.48k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_40clEP10ssl_ctx_stP6cbs_st:
  459|  1.55k|      [](SSL_CTX *ctx, CBS *cbs) { SSL_CTX_get_max_cert_list(ctx); },
  ------------------
  |  | 5430|  1.55k|#define SSL_CTX_get_max_cert_list SSL_CTX_get_max_cert_list
  ------------------
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_41clEP10ssl_ctx_stP6cbs_st:
  460|  1.18k|      [](SSL_CTX *ctx, CBS *cbs) {
  461|  1.18k|        uint32_t size;
  462|  1.18k|        if (!CBS_get_u32(cbs, &size)) {
  ------------------
  |  Branch (462:13): [True: 35, False: 1.14k]
  ------------------
  463|     35|          return;
  464|     35|        }
  465|  1.14k|        SSL_CTX_set_max_cert_list(ctx, size);
  ------------------
  |  | 5443|  1.14k|#define SSL_CTX_set_max_cert_list SSL_CTX_set_max_cert_list
  ------------------
  466|  1.14k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_42clEP10ssl_ctx_stP6cbs_st:
  467|  4.91k|      [](SSL_CTX *ctx, CBS *cbs) {
  468|  4.91k|        uint32_t size;
  469|  4.91k|        if (!CBS_get_u32(cbs, &size)) {
  ------------------
  |  Branch (469:13): [True: 22, False: 4.88k]
  ------------------
  470|     22|          return;
  471|     22|        }
  472|  4.88k|        SSL_CTX_set_max_send_fragment(ctx, size);
  ------------------
  |  | 5444|  4.88k|#define SSL_CTX_set_max_send_fragment SSL_CTX_set_max_send_fragment
  ------------------
  473|  4.88k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_43clEP10ssl_ctx_stP6cbs_st:
  474|  4.28k|      [](SSL_CTX *ctx, CBS *cbs) {
  475|  4.28k|        uint8_t b;
  476|  4.28k|        if (!CBS_get_u8(cbs, &b)) {
  ------------------
  |  Branch (476:13): [True: 38, False: 4.24k]
  ------------------
  477|     38|          return;
  478|     38|        }
  479|  4.24k|        SSL_CTX_set_retain_only_sha256_of_client_certs(ctx, b);
  480|  4.24k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_44clEP10ssl_ctx_stP6cbs_st:
  481|  1.46k|      [](SSL_CTX *ctx, CBS *cbs) {
  482|  1.46k|        uint8_t b;
  483|  1.46k|        if (!CBS_get_u8(cbs, &b)) {
  ------------------
  |  Branch (483:13): [True: 6, False: 1.46k]
  ------------------
  484|      6|          return;
  485|      6|        }
  486|  1.46k|        SSL_CTX_set_grease_enabled(ctx, b);
  487|  1.46k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_45clEP10ssl_ctx_stP6cbs_st:
  488|  8.04k|      [](SSL_CTX *ctx, CBS *cbs) {
  489|  8.04k|        std::vector<int> sigalgs;
  490|  8.04k|        if (!GetVector(&sigalgs, cbs)) {
  ------------------
  |  Branch (490:13): [True: 134, False: 7.90k]
  ------------------
  491|    134|          return;
  492|    134|        }
  493|  7.90k|        SSL_CTX_set1_sigalgs(ctx, sigalgs.data(), sigalgs.size());
  494|  7.90k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_46clEP10ssl_ctx_stP6cbs_st:
  495|  8.01k|      [](SSL_CTX *ctx, CBS *cbs) {
  496|  8.01k|        std::string sigalgs;
  497|  8.01k|        if (!GetString(&sigalgs, cbs)) {
  ------------------
  |  Branch (497:13): [True: 121, False: 7.89k]
  ------------------
  498|    121|          return;
  499|    121|        }
  500|  7.89k|        SSL_CTX_set1_sigalgs_list(ctx, sigalgs.c_str());
  501|  7.89k|      },
ssl_ctx_api.cc:_ZZ22LLVMFuzzerTestOneInputENK4$_47clEP10ssl_ctx_stP6cbs_st:
  502|  14.9k|      [](SSL_CTX *ctx, CBS *cbs) {
  503|  14.9k|        bssl::UniquePtr<SSL_ECH_KEYS> keys(SSL_ECH_KEYS_new());
  504|  14.9k|        if (keys == nullptr) {
  ------------------
  |  Branch (504:13): [True: 0, False: 14.9k]
  ------------------
  505|      0|          return;
  506|      0|        }
  507|  14.9k|        uint8_t is_retry_config;
  508|  14.9k|        CBS ech_config, private_key;
  509|  14.9k|        if (!CBS_get_u8(cbs, &is_retry_config) ||
  ------------------
  |  Branch (509:13): [True: 10, False: 14.9k]
  ------------------
  510|  14.9k|            !CBS_get_u16_length_prefixed(cbs, &ech_config) ||
  ------------------
  |  Branch (510:13): [True: 1.73k, False: 13.1k]
  ------------------
  511|  14.9k|            !CBS_get_u16_length_prefixed(cbs, &private_key)) {
  ------------------
  |  Branch (511:13): [True: 685, False: 12.4k]
  ------------------
  512|  2.43k|          return;
  513|  2.43k|        }
  514|  12.4k|        bssl::ScopedEVP_HPKE_KEY key;
  515|  12.4k|        if (!EVP_HPKE_KEY_init(key.get(), EVP_hpke_x25519_hkdf_sha256(),
  ------------------
  |  Branch (515:13): [True: 728, False: 11.7k]
  ------------------
  516|  12.4k|                               CBS_data(&private_key), CBS_len(&private_key)) ||
  517|  12.4k|            !SSL_ECH_KEYS_add(keys.get(), is_retry_config,
  ------------------
  |  Branch (517:13): [True: 11.7k, False: 0]
  ------------------
  518|  11.7k|                              CBS_data(&ech_config), CBS_len(&ech_config),
  519|  11.7k|                              key.get()) ||
  520|  12.4k|            !SSL_CTX_set1_ech_keys(ctx, keys.get())) {
  ------------------
  |  Branch (520:13): [True: 0, False: 0]
  ------------------
  521|  12.4k|          return;
  522|  12.4k|        }
  523|  12.4k|      },

d2i_X509_ALGOR:
  630|  20.0k|	{ \
  631|  20.0k|		return (stname *)ASN1_item_d2i((ASN1_VALUE **)a, in, len, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  632|  20.0k|	} \
i2d_X509_ALGOR:
  634|  67.4k|	{ \
  635|  67.4k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  67.4k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  636|  67.4k|	}
X509_ALGOR_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
X509_NAME_ENTRY_new:
  603|  40.1k|	{ \
  604|  40.1k|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  40.1k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|  40.1k|	} \
X509_NAME_ENTRY_free:
  607|  80.3k|	{ \
  608|  80.3k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  80.3k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  80.3k|	}
i2d_X509_NAME:
  621|  3.63k|	{ \
  622|  3.63k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  3.63k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  623|  3.63k|	} 
i2d_X509_CINF:
  621|  67.4k|	{ \
  622|  67.4k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  67.4k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  623|  67.4k|	} 
X509_CINF_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
X509_CERT_AUX_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
AUTHORITY_KEYID_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
CRL_DIST_POINTS_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
GENERAL_NAMES_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
NAME_CONSTRAINTS_free:
  607|  20.0k|	{ \
  608|  20.0k|		ASN1_item_free((ASN1_VALUE *)a, ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  20.0k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  609|  20.0k|	}
i2d_ASN1_BIT_STRING:
  634|  67.4k|	{ \
  635|  67.4k|		return ASN1_item_i2d((ASN1_VALUE *)a, out, ASN1_ITEM_rptr(itname));\
  ------------------
  |  |  274|  67.4k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  636|  67.4k|	}
ASN1_TYPE_new:
  603|  60.2k|	{ \
  604|  60.2k|		return (stname *)ASN1_item_new(ASN1_ITEM_rptr(itname)); \
  ------------------
  |  |  274|  60.2k|#define ASN1_ITEM_rptr(name) (&(name##_it))
  ------------------
  605|  60.2k|	} \

_ZN4bssl8internal7DeleterclI11evp_pkey_stEEvPT_:
  560|  29.6k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  29.6k|    DeleterImpl<T>::Free(ptr);
  570|  29.6k|  }
_ZN4bssl8internal11DeleterImplI11evp_pkey_stvE4FreeEPS2_:
  635|  29.6k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl5UpRefERKNSt3__110unique_ptrI7x509_stNS_8internal7DeleterEEE:
  653|      2|  inline UniquePtr<type> UpRef(const UniquePtr<type> &ptr) { \
  654|      2|    return UpRef(ptr.get());                                 \
  655|      2|  }
_ZN4bssl5UpRefEP7x509_st:
  646|      2|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|      2|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 2, False: 0]
  ------------------
  648|      2|      up_ref_func(v);                                        \
  649|      2|    }                                                        \
  650|      2|    return UniquePtr<type>(v);                               \
  651|      2|  }                                                          \
_ZN4bssl8internal7DeleterclI10ssl_ctx_stEEvPT_:
  560|  14.4k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  14.4k|    DeleterImpl<T>::Free(ptr);
  570|  14.4k|  }
_ZN4bssl8internal11DeleterImplI10ssl_ctx_stvE4FreeEPS2_:
  635|  14.4k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl8internal14StackAllocatedI15evp_hpke_key_stvXadL_Z17EVP_HPKE_KEY_zeroEEXadL_Z20EVP_HPKE_KEY_cleanupEEEC2Ev:
  577|  24.2k|  StackAllocated() { init(&ctx_); }
_ZN4bssl8internal14StackAllocatedI15evp_hpke_key_stvXadL_Z17EVP_HPKE_KEY_zeroEEXadL_Z20EVP_HPKE_KEY_cleanupEEE3getEv:
  583|  24.2k|  T *get() { return &ctx_; }
_ZN4bssl8internal14StackAllocatedI15evp_hpke_key_stvXadL_Z17EVP_HPKE_KEY_zeroEEXadL_Z20EVP_HPKE_KEY_cleanupEEED2Ev:
  578|  24.2k|  ~StackAllocated() { cleanup(&ctx_); }
_ZN4bssl8internal7DeleterclI15ssl_ech_keys_stEEvPT_:
  560|  14.9k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  14.9k|    DeleterImpl<T>::Free(ptr);
  570|  14.9k|  }
_ZN4bssl8internal11DeleterImplI15ssl_ech_keys_stvE4FreeEPS2_:
  635|  14.9k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl8internal7DeleterclI6ssl_stEEvPT_:
  560|  4.83k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  4.83k|    DeleterImpl<T>::Free(ptr);
  570|  4.83k|  }
_ZN4bssl8internal11DeleterImplI6ssl_stvE4FreeEPS2_:
  635|  4.83k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl5UpRefEP11evp_pkey_st:
  646|  21.2k|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|  21.2k|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 6.91k, False: 14.3k]
  ------------------
  648|  6.91k|      up_ref_func(v);                                        \
  649|  6.91k|    }                                                        \
  650|  21.2k|    return UniquePtr<type>(v);                               \
  651|  21.2k|  }                                                          \
_ZN4bssl5UpRefERKNSt3__110unique_ptrI11evp_pkey_stNS_8internal7DeleterEEE:
  653|  14.4k|  inline UniquePtr<type> UpRef(const UniquePtr<type> &ptr) { \
  654|  14.4k|    return UpRef(ptr.get());                                 \
  655|  14.4k|  }
_ZN4bssl8internal11DeleterImplI10buf_mem_stvE4FreeEPS2_:
  635|  4.83k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl8internal11DeleterImplI16crypto_buffer_stvE4FreeEPS2_:
  635|  68.9k|    static void Free(type *ptr) { deleter(ptr); } \
_ZN4bssl5UpRefEP16crypto_buffer_st:
  646|  48.9k|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|  48.9k|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 20.2k, False: 28.6k]
  ------------------
  648|  20.2k|      up_ref_func(v);                                        \
  649|  20.2k|    }                                                        \
  650|  48.9k|    return UniquePtr<type>(v);                               \
  651|  48.9k|  }                                                          \
_ZN4bssl5UpRefERKNSt3__110unique_ptrI16crypto_buffer_stNS_8internal7DeleterEEE:
  653|  9.66k|  inline UniquePtr<type> UpRef(const UniquePtr<type> &ptr) { \
  654|  9.66k|    return UpRef(ptr.get());                                 \
  655|  9.66k|  }
_ZN4bssl5UpRefEP10ssl_ctx_st:
  646|  9.66k|  inline UniquePtr<type> UpRef(type *v) {                    \
  647|  9.66k|    if (v != nullptr) {                                      \
  ------------------
  |  Branch (647:9): [True: 9.66k, False: 0]
  ------------------
  648|  9.66k|      up_ref_func(v);                                        \
  649|  9.66k|    }                                                        \
  650|  9.66k|    return UniquePtr<type>(v);                               \
  651|  9.66k|  }                                                          \
_ZN4bssl8internal7DeleterclI16crypto_buffer_stEEvPT_:
  560|  19.3k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  19.3k|    DeleterImpl<T>::Free(ptr);
  570|  19.3k|  }
_ZN4bssl8internal7DeleterclI32stack_st_SRTP_PROTECTION_PROFILEEEvPT_:
  560|  5.48k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  5.48k|    DeleterImpl<T>::Free(ptr);
  570|  5.48k|  }
_ZN4bssl8internal7DeleterclINS_15ECHServerConfigEEEvPT_:
  560|  11.7k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  11.7k|    DeleterImpl<T>::Free(ptr);
  570|  11.7k|  }
_ZN4bssl8internal14StackAllocatedI15evp_hpke_ctx_stvXadL_Z17EVP_HPKE_CTX_zeroEEXadL_Z20EVP_HPKE_CTX_cleanupEEEC2Ev:
  577|  4.83k|  StackAllocated() { init(&ctx_); }
_ZN4bssl8internal14StackAllocatedI15evp_hpke_ctx_stvXadL_Z17EVP_HPKE_CTX_zeroEEXadL_Z20EVP_HPKE_CTX_cleanupEEED2Ev:
  578|  4.83k|  ~StackAllocated() { cleanup(&ctx_); }
_ZN4bssl8internal7DeleterclI22stack_st_CRYPTO_BUFFEREEvPT_:
  560|  45.7k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  45.7k|    DeleterImpl<T>::Free(ptr);
  570|  45.7k|  }
_ZN4bssl8internal7DeleterclINS_13SSL_HANDSHAKEEEEvPT_:
  560|  4.83k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  4.83k|    DeleterImpl<T>::Free(ptr);
  570|  4.83k|  }
_ZN4bssl8internal7DeleterclI19stack_st_SSL_CIPHEREEvPT_:
  560|  22.7k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  22.7k|    DeleterImpl<T>::Free(ptr);
  570|  22.7k|  }
_ZN4bssl8internal7DeleterclI10buf_mem_stEEvPT_:
  560|  4.83k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  4.83k|    DeleterImpl<T>::Free(ptr);
  570|  4.83k|  }
_ZN4bssl8internal14StackAllocatedI15evp_aead_ctx_stvXadL_Z17EVP_AEAD_CTX_zeroEEXadL_Z20EVP_AEAD_CTX_cleanupEEEC2Ev:
  577|  9.66k|  StackAllocated() { init(&ctx_); }
_ZN4bssl8internal14StackAllocatedI15evp_aead_ctx_stvXadL_Z17EVP_AEAD_CTX_zeroEEXadL_Z20EVP_AEAD_CTX_cleanupEEED2Ev:
  578|  9.66k|  ~StackAllocated() { cleanup(&ctx_); }
_ZN4bssl8internal7DeleterclINS_14SSLAEADContextEEEvPT_:
  560|  9.66k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  9.66k|    DeleterImpl<T>::Free(ptr);
  570|  9.66k|  }
_ZN4bssl8internal7DeleterclINS_4CERTEEEvPT_:
  560|  9.66k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  9.66k|    DeleterImpl<T>::Free(ptr);
  570|  9.66k|  }
_ZN4bssl8internal7DeleterclINS_23SSLCipherPreferenceListEEEvPT_:
  560|  22.7k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  22.7k|    DeleterImpl<T>::Free(ptr);
  570|  22.7k|  }
_ZN4bssl8internal7DeleterclINS_10SSL_CONFIGEEEvPT_:
  560|  4.83k|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|  4.83k|    DeleterImpl<T>::Free(ptr);
  570|  4.83k|  }
_ZN4bssl8internal7DeleterclINS_9TicketKeyEEEvPT_:
  560|    259|  void operator()(T *ptr) {
  561|       |    // Rather than specialize Deleter for each type, we specialize
  562|       |    // DeleterImpl. This allows bssl::UniquePtr<T> to be used while only
  563|       |    // including base.h as long as the destructor is not emitted. This matches
  564|       |    // std::unique_ptr's behavior on forward-declared types.
  565|       |    //
  566|       |    // DeleterImpl itself is specialized in the corresponding module's header
  567|       |    // and must be included to release an object. If not included, the compiler
  568|       |    // will error that DeleterImpl<T> does not have a method Free.
  569|    259|    DeleterImpl<T>::Free(ptr);
  570|    259|  }
_ZN4bssl8internal21StackAllocatedMovableI13env_md_ctx_stiXadL_Z15EVP_MD_CTX_initEEXadL_Z18EVP_MD_CTX_cleanupEEXadL_Z15EVP_MD_CTX_moveEEEC2Ev:
  602|  9.66k|  StackAllocatedMovable() { init(&ctx_); }
_ZN4bssl8internal21StackAllocatedMovableI13env_md_ctx_stiXadL_Z15EVP_MD_CTX_initEEXadL_Z18EVP_MD_CTX_cleanupEEXadL_Z15EVP_MD_CTX_moveEEED2Ev:
  603|  9.66k|  ~StackAllocatedMovable() { cleanup(&ctx_); }
_ZN4bssl8internal21StackAllocatedMovableI13env_md_ctx_stiXadL_Z15EVP_MD_CTX_initEEXadL_Z18EVP_MD_CTX_cleanupEEXadL_Z15EVP_MD_CTX_moveEEE5ResetEv:
  620|  4.83k|  void Reset() {
  621|  4.83k|    cleanup(&ctx_);
  622|  4.83k|    init(&ctx_);
  623|  4.83k|  }

_ZN6cbs_stC2EN4bssl4SpanIKhEE:
   47|  23.2k|      : data(span.data()), len(span.size()) {}
_ZNK6cbs_stcvN4bssl4SpanIKhEEEv:
   48|  13.1k|  operator bssl::Span<const uint8_t>() const {
   49|  13.1k|    return bssl::MakeConstSpan(data, len);
   50|  13.1k|  }

_ZNK4bssl4SpanIKhE4dataEv:
  124|  36.3k|  T *data() const { return data_; }
_ZNK4bssl4SpanIKhE4sizeEv:
  125|  58.1k|  size_t size() const { return size_; }
_ZN4bssl13MakeConstSpanIKhEENS_4SpanIKT_EEPS3_m:
  199|  35.3k|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|  35.3k|  return Span<const T>(ptr, size);
  201|  35.3k|}
_ZN4bssl4SpanIKhEC2EPS1_m:
  110|  92.5k|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZN4bssl4SpanIKhEC2Ev:
  109|  54.1k|  constexpr Span() : Span(nullptr, 0) {}
_ZNK4bssl4SpanIKhEixEm:
  146|  5.58k|  T &operator[](size_t i) const {
  147|  5.58k|    if (i >= size_) {
  ------------------
  |  Branch (147:9): [True: 0, False: 5.58k]
  ------------------
  148|      0|      abort();
  149|      0|    }
  150|  5.58k|    return data_[i];
  151|  5.58k|  }
_ZN4bssl4SpanIhEC2EPhm:
  110|  4.83k|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZNK4bssl4SpanIKhE7subspanEmm:
  154|  2.81k|  Span subspan(size_t pos = 0, size_t len = npos) const {
  155|  2.81k|    if (pos > size_) {
  ------------------
  |  Branch (155:9): [True: 0, False: 2.81k]
  ------------------
  156|       |      // absl::Span throws an exception here. Note std::span and Chromium
  157|       |      // base::span additionally forbid pos + len being out of range, with a
  158|       |      // special case at npos/dynamic_extent, while absl::Span::subspan clips
  159|       |      // the span. For now, we align with absl::Span in case we switch to it in
  160|       |      // the future.
  161|      0|      abort();
  162|      0|    }
  163|  2.81k|    return Span(data_ + pos, std::min(size_ - pos, len));
  164|  2.81k|  }
_ZN4bssl8internaleqENS_4SpanIKhEES3_:
   42|    267|  friend bool operator==(Span<T> lhs, Span<T> rhs) {
   43|       |    // MSVC issues warning C4996 because std::equal is unsafe. The pragma to
   44|       |    // suppress the warning mysteriously has no effect, hence this
   45|       |    // implementation. See
   46|       |    // https://msdn.microsoft.com/en-us/library/aa985974.aspx.
   47|    267|    if (lhs.size() != rhs.size()) {
  ------------------
  |  Branch (47:9): [True: 267, False: 0]
  ------------------
   48|    267|      return false;
   49|    267|    }
   50|      0|    for (T *l = lhs.begin(), *r = rhs.begin(); l != lhs.end() && r != rhs.end();
  ------------------
  |  Branch (50:48): [True: 0, False: 0]
  |  Branch (50:66): [True: 0, False: 0]
  ------------------
   51|      0|         ++l, ++r) {
   52|      0|      if (*l != *r) {
  ------------------
  |  Branch (52:11): [True: 0, False: 0]
  ------------------
   53|      0|        return false;
   54|      0|      }
   55|      0|    }
   56|      0|    return true;
   57|      0|  }
_ZN4bssl4SpanIKhEC2INS_5ArrayIhEEvS5_EERKT_:
  117|  12.3k|  Span(const C &container) : data_(container.data()), size_(container.size()) {}
_ZNK4bssl4SpanIKhE5beginEv:
  128|  15.1k|  T *begin() const { return data_; }
_ZNK4bssl4SpanIKhE3endEv:
  130|  18.4k|  T *end() const { return data_ + size_; }
_ZNK4bssl4SpanIKhE5emptyEv:
  126|  25.1k|  bool empty() const { return size_ == 0; }
_ZNK4bssl4SpanIKhE5frontEv:
  133|  4.52k|  T &front() const {
  134|  4.52k|    if (size_ == 0) {
  ------------------
  |  Branch (134:9): [True: 0, False: 4.52k]
  ------------------
  135|      0|      abort();
  136|      0|    }
  137|  4.52k|    return data_[0];
  138|  4.52k|  }
_ZNK4bssl4SpanIKhE4backEv:
  139|  4.31k|  T &back() const {
  140|  4.31k|    if (size_ == 0) {
  ------------------
  |  Branch (140:9): [True: 0, False: 4.31k]
  ------------------
  141|      0|      abort();
  142|      0|    }
  143|  4.31k|    return data_[size_ - 1];
  144|  4.31k|  }
_ZN4bssl13MakeConstSpanIhEENS_4SpanIKT_EEPS2_m:
  199|    267|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|    267|  return Span<const T>(ptr, size);
  201|    267|}
_ZN4bssl8internalneENS_4SpanIKhEES3_:
   59|    267|  friend bool operator!=(Span<T> lhs, Span<T> rhs) { return !(lhs == rhs); }
_ZN4bssl4SpanIKtEC2EPS1_m:
  110|  16.8k|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZN4bssl4SpanIKtEC2INS_5ArrayItEEvS5_EERKT_:
  117|  14.4k|  Span(const C &container) : data_(container.data()), size_(container.size()) {}
_ZNK4bssl4SpanIKtE5beginEv:
  128|  14.2k|  T *begin() const { return data_; }
_ZNK4bssl4SpanIKtE3endEv:
  130|  14.2k|  T *end() const { return data_ + size_; }
_ZNK4bssl4SpanIKtE5emptyEv:
  126|  4.16k|  bool empty() const { return size_ == 0; }
_ZNK4bssl4SpanIKtE4sizeEv:
  125|  54.8k|  size_t size() const { return size_; }
_ZN4bssl4SpanIhEC2Ev:
  109|  4.83k|  constexpr Span() : Span(nullptr, 0) {}
_ZNK4bssl4SpanIKtE4dataEv:
  124|  20.2k|  T *data() const { return data_; }
_ZN4bssl4SpanIKbEC2EPS1_m:
  110|  45.4k|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZNK4bssl4SpanIKbE4sizeEv:
  125|  68.1k|  size_t size() const { return size_; }
_ZNK4bssl4SpanIKbE4dataEv:
  124|  22.7k|  T *data() const { return data_; }
_ZN4bssl13MakeConstSpanINS_5ArrayIbEEEEDTcl13MakeConstSpancldtfp_4dataEcldtfp_4sizeEEERKT_:
  204|  22.7k|auto MakeConstSpan(const C &c) -> decltype(MakeConstSpan(c.data(), c.size())) {
  205|  22.7k|  return MakeConstSpan(c.data(), c.size());
  206|  22.7k|}
_ZN4bssl13MakeConstSpanIKbEENS_4SpanIKT_EEPS3_m:
  199|  22.7k|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|  22.7k|  return Span<const T>(ptr, size);
  201|  22.7k|}
_ZNK4bssl4SpanIKbE7subspanEmm:
  154|  22.7k|  Span subspan(size_t pos = 0, size_t len = npos) const {
  155|  22.7k|    if (pos > size_) {
  ------------------
  |  Branch (155:9): [True: 0, False: 22.7k]
  ------------------
  156|       |      // absl::Span throws an exception here. Note std::span and Chromium
  157|       |      // base::span additionally forbid pos + len being out of range, with a
  158|       |      // special case at npos/dynamic_extent, while absl::Span::subspan clips
  159|       |      // the span. For now, we align with absl::Span in case we switch to it in
  160|       |      // the future.
  161|      0|      abort();
  162|      0|    }
  163|  22.7k|    return Span(data_ + pos, std::min(size_ - pos, len));
  164|  22.7k|  }
_ZNK4bssl4SpanIKiE4sizeEv:
  125|  18.0k|  size_t size() const { return size_; }
_ZNK4bssl4SpanIKiEixEm:
  146|  5.94k|  T &operator[](size_t i) const {
  147|  5.94k|    if (i >= size_) {
  ------------------
  |  Branch (147:9): [True: 0, False: 5.94k]
  ------------------
  148|      0|      abort();
  149|      0|    }
  150|  5.94k|    return data_[i];
  151|  5.94k|  }
_ZN4bssl13MakeConstSpanIKtEENS_4SpanIKT_EEPS3_m:
  199|  13.3k|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|  13.3k|  return Span<const T>(ptr, size);
  201|  13.3k|}
_ZN4bssl13MakeConstSpanIKiEENS_4SpanIKT_EEPS3_m:
  199|  8.67k|Span<const T> MakeConstSpan(T *ptr, size_t size) {
  200|  8.67k|  return Span<const T>(ptr, size);
  201|  8.67k|}
_ZN4bssl4SpanIKiEC2EPS1_m:
  110|  8.67k|  constexpr Span(T *ptr, size_t len) : data_(ptr), size_(len) {}
_ZN4bssl4SpanIKtEC2ILm4EEERAT__S1_:
  113|  3.48k|  constexpr Span(T (&array)[N]) : Span(array, N) {}

sk_X509_new_null:
  420|  2.80k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  2.80k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  2.80k|  }                                                                           \
_ZN4bssl11PushToStackI13stack_st_X509EENSt3__19enable_ifIXntsr8internal11StackTraitsIT_EE8kIsConstEbE4typeEPS4_NS2_10unique_ptrINS_8internal11StackTraitsIS4_E4TypeENS9_7DeleterEEE:
  611|  18.5k|            UniquePtr<typename internal::StackTraits<Stack>::Type> elem) {
  612|  18.5k|  if (!sk_push(reinterpret_cast<_STACK *>(sk), elem.get())) {
  ------------------
  |  Branch (612:7): [True: 0, False: 18.5k]
  ------------------
  613|      0|    return false;
  614|      0|  }
  615|       |  // sk_push takes ownership on success.
  616|  18.5k|  elem.release();
  617|  18.5k|  return true;
  618|  18.5k|}
sk_CRYPTO_BUFFER_call_copy_func:
  396|  4.82k|      OPENSSL_sk_copy_func copy_func, const void *ptr) {                      \
  397|  4.82k|    return (void *)((sk_##name##_copy_func)copy_func)((constptrtype)ptr);     \
  398|  4.82k|  }                                                                           \
sk_CRYPTO_BUFFER_new_null:
  420|  44.9k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  44.9k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  44.9k|  }                                                                           \
sk_CRYPTO_BUFFER_num:
  424|  25.7k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  25.7k|    return sk_num((const _STACK *)sk);                                        \
  426|  25.7k|  }                                                                           \
sk_CRYPTO_BUFFER_value:
  433|  99.9k|                                           size_t i) {                        \
  434|  99.9k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  99.9k|  }                                                                           \
sk_CRYPTO_BUFFER_set:
  438|  12.6k|                                         ptrtype p) {                         \
  439|  12.6k|    return (ptrtype)sk_set((_STACK *)sk, i, (void *)p);                       \
  440|  12.6k|  }                                                                           \
sk_CRYPTO_BUFFER_push:
  483|    614|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|    614|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|    614|  }                                                                           \
sk_CRYPTO_BUFFER_deep_copy:
  511|    828|      sk_##name##_free_func free_func) {                                      \
  512|    828|    return (STACK_OF(name) *)sk_deep_copy(                                    \
  513|    828|        (const _STACK *)sk, sk_##name##_call_copy_func,                       \
  514|    828|        (OPENSSL_sk_copy_func)copy_func, sk_##name##_call_free_func,          \
  515|    828|        (OPENSSL_sk_free_func)free_func);                                     \
  516|    828|  }                                                                           \
sk_X509_call_free_func:
  391|  18.5k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  18.5k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  18.5k|  }                                                                           \
sk_X509_pop_free:
  447|   109k|                                           sk_##name##_free_func free_func) { \
  448|   109k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|   109k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|   109k|  }                                                                           \
sk_X509_NAME_pop_free:
  447|  18.1k|                                           sk_##name##_free_func free_func) { \
  448|  18.1k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  18.1k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  18.1k|  }                                                                           \
sk_SSL_CIPHER_new_null:
  420|  22.7k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  22.7k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  22.7k|  }                                                                           \
sk_SSL_CIPHER_num:
  424|  45.4k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  45.4k|    return sk_num((const _STACK *)sk);                                        \
  426|  45.4k|  }                                                                           \
sk_SSL_CIPHER_push:
  483|   200k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|   200k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|   200k|  }                                                                           \
sk_SRTP_PROTECTION_PROFILE_new_null:
  420|  5.48k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  5.48k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  5.48k|  }                                                                           \
sk_SRTP_PROTECTION_PROFILE_push:
  483|    847|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|    847|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|    847|  }                                                                           \
_ZN4bssl8internal11DeleterImplI32stack_st_SRTP_PROTECTION_PROFILEvE4FreeEPS2_:
  545|  5.48k|  static void Free(Stack *sk) { sk_free(reinterpret_cast<_STACK *>(sk)); }
_ZN4bssl8internal11DeleterImplI22stack_st_CRYPTO_BUFFERvE4FreeEPS2_:
  552|  45.7k|  static void Free(Stack *sk) {
  553|       |    // sk_FOO_pop_free is defined by macros and bound by name, so we cannot
  554|       |    // access it from C++ here.
  555|  45.7k|    using Type = typename StackTraits<Stack>::Type;
  556|  45.7k|    sk_pop_free_ex(reinterpret_cast<_STACK *>(sk),
  557|  45.7k|                   [](OPENSSL_sk_free_func /* unused */, void *ptr) {
  558|  45.7k|                     DeleterImpl<Type>::Free(reinterpret_cast<Type *>(ptr));
  559|  45.7k|                   },
  560|  45.7k|                   nullptr);
  561|  45.7k|  }
_ZZN4bssl8internal11DeleterImplI22stack_st_CRYPTO_BUFFERvE4FreeEPS2_ENKUlPFvPvES5_E_clES7_S5_:
  557|  49.6k|                   [](OPENSSL_sk_free_func /* unused */, void *ptr) {
  558|  49.6k|                     DeleterImpl<Type>::Free(reinterpret_cast<Type *>(ptr));
  559|  49.6k|                   },
_ZN4bssl8internal11DeleterImplI19stack_st_SSL_CIPHERvE4FreeEPS2_:
  545|  22.7k|  static void Free(Stack *sk) { sk_free(reinterpret_cast<_STACK *>(sk)); }
_ZN4bssl11PushToStackI22stack_st_CRYPTO_BUFFEREENSt3__19enable_ifIXntsr8internal11StackTraitsIT_EE8kIsConstEbE4typeEPS4_NS2_10unique_ptrINS_8internal11StackTraitsIS4_E4TypeENS9_7DeleterEEE:
  611|  63.9k|            UniquePtr<typename internal::StackTraits<Stack>::Type> elem) {
  612|  63.9k|  if (!sk_push(reinterpret_cast<_STACK *>(sk), elem.get())) {
  ------------------
  |  Branch (612:7): [True: 0, False: 63.9k]
  ------------------
  613|      0|    return false;
  614|      0|  }
  615|       |  // sk_push takes ownership on success.
  616|  63.9k|  elem.release();
  617|  63.9k|  return true;
  618|  63.9k|}
_Z5beginI13stack_st_X509ENSt3__19enable_ifIXsr11StackTraitsIT_EE8kIsStackEN4bssl8internal17StackIteratorImplIS3_EEE4typeEPKS3_:
  624|  44.7k|inline bssl::internal::StackIterator<Stack> begin(const Stack *sk) {
  625|  44.7k|  return bssl::internal::StackIterator<Stack>(sk, 0);
  626|  44.7k|}
_ZN4bssl8internal17StackIteratorImplI13stack_st_X509EC2EPKS2_m:
  570|  89.5k|  StackIteratorImpl(const Stack *sk, size_t idx) : sk_(sk), idx_(idx) {}
_Z3endI13stack_st_X509ENSt3__19enable_ifIXsr11StackTraitsIT_EE8kIsStackEN4bssl8internal17StackIteratorImplIS3_EEE4typeEPKS3_:
  629|  44.7k|inline bssl::internal::StackIterator<Stack> end(const Stack *sk) {
  630|  44.7k|  return bssl::internal::StackIterator<Stack>(
  631|  44.7k|      sk, sk_num(reinterpret_cast<const _STACK *>(sk)));
  632|  44.7k|}
_ZNK4bssl8internal17StackIteratorImplI13stack_st_X509EneES3_:
  575|  54.9k|  bool operator!=(StackIteratorImpl other) const {
  576|  54.9k|    return !(*this == other);
  577|  54.9k|  }
_ZNK4bssl8internal17StackIteratorImplI13stack_st_X509EeqES3_:
  572|  54.9k|  bool operator==(StackIteratorImpl other) const {
  573|  54.9k|    return sk_ == other.sk_ && idx_ == other.idx_;
  ------------------
  |  Branch (573:12): [True: 54.9k, False: 0]
  |  Branch (573:32): [True: 44.7k, False: 10.2k]
  ------------------
  574|  54.9k|  }
_ZNK4bssl8internal17StackIteratorImplI13stack_st_X509EdeEv:
  579|  10.2k|  Type *operator*() const {
  580|  10.2k|    return reinterpret_cast<Type *>(
  581|  10.2k|        sk_value(reinterpret_cast<const _STACK *>(sk_), idx_));
  582|  10.2k|  }
_ZN4bssl8internal17StackIteratorImplI13stack_st_X509EppEv:
  584|  10.2k|  StackIteratorImpl &operator++(/* prefix */) {
  585|  10.2k|    idx_++;
  586|  10.2k|    return *this;
  587|  10.2k|  }
bcm.c:sk_BIGNUM_pop_free:
  447|      2|                                           sk_##name##_free_func free_func) { \
  448|      2|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|      2|                   (OPENSSL_sk_free_func)free_func);                          \
  450|      2|  }                                                                           \
bcm.c:sk_BIGNUM_call_free_func:
  391|      8|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|      8|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|      8|  }                                                                           \
bcm.c:sk_BIGNUM_new_null:
  420|      2|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|      2|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|      2|  }                                                                           \
bcm.c:sk_BIGNUM_num:
  424|     38|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|     38|    return sk_num((const _STACK *)sk);                                        \
  426|     38|  }                                                                           \
bcm.c:sk_BIGNUM_push:
  483|      8|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|      8|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|      8|  }                                                                           \
bcm.c:sk_BIGNUM_value:
  433|     38|                                           size_t i) {                        \
  434|     38|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|     38|  }                                                                           \
x509_lu.c:sk_X509_OBJECT_new:
  416|  4.83k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new(sk_##name##_cmp_func comp) { \
  417|  4.83k|    return (STACK_OF(name) *)sk_new((OPENSSL_sk_cmp_func)comp);               \
  418|  4.83k|  }                                                                           \
x509_lu.c:sk_X509_LOOKUP_new_null:
  420|  4.83k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  4.83k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  4.83k|  }                                                                           \
x509_lu.c:sk_X509_LOOKUP_free:
  442|  4.83k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  4.83k|    sk_free((_STACK *)sk);                                                    \
  444|  4.83k|  }                                                                           \
x509_lu.c:sk_X509_LOOKUP_num:
  424|  4.83k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  4.83k|    return sk_num((const _STACK *)sk);                                        \
  426|  4.83k|  }                                                                           \
x509_lu.c:sk_X509_OBJECT_pop_free:
  447|  4.83k|                                           sk_##name##_free_func free_func) { \
  448|  4.83k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  4.83k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  4.83k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_new_null:
  420|   120k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|   120k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|   120k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_free:
  442|  40.1k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  40.1k|    sk_free((_STACK *)sk);                                                    \
  444|  40.1k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_pop_free:
  447|   120k|                                           sk_##name##_free_func free_func) { \
  448|   120k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|   120k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|   120k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_call_free_func:
  391|  80.3k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  80.3k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  80.3k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_num:
  424|  80.3k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|  80.3k|    return sk_num((const _STACK *)sk);                                        \
  426|  80.3k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_value:
  433|  40.1k|                                           size_t i) {                        \
  434|  40.1k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  40.1k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_num:
  424|   200k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|   200k|    return sk_num((const _STACK *)sk);                                        \
  426|   200k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_value:
  433|  80.3k|                                           size_t i) {                        \
  434|  80.3k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  80.3k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_push:
  483|  80.3k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  80.3k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  80.3k|  }                                                                           \
x_name.c:sk_X509_NAME_ENTRY_set:
  438|  40.1k|                                         ptrtype p) {                         \
  439|  40.1k|    return (ptrtype)sk_set((_STACK *)sk, i, (void *)p);                       \
  440|  40.1k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_new_null:
  420|  40.1k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|  40.1k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|  40.1k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_push:
  483|  40.1k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|  40.1k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|  40.1k|  }                                                                           \
x_name.c:sk_ASN1_VALUE_num:
  424|   160k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|   160k|    return sk_num((const _STACK *)sk);                                        \
  426|   160k|  }                                                                           \
x_name.c:sk_ASN1_VALUE_value:
  433|  80.3k|                                           size_t i) {                        \
  434|  80.3k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  80.3k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_pop_free:
  447|  80.3k|                                           sk_##name##_free_func free_func) { \
  448|  80.3k|    sk_pop_free_ex((_STACK *)sk, sk_##name##_call_free_func,                  \
  449|  80.3k|                   (OPENSSL_sk_free_func)free_func);                          \
  450|  80.3k|  }                                                                           \
x_name.c:sk_STACK_OF_X509_NAME_ENTRY_call_free_func:
  391|  80.3k|      OPENSSL_sk_free_func free_func, void *ptr) {                            \
  392|  80.3k|    ((sk_##name##_free_func)free_func)((ptrtype)ptr);                         \
  393|  80.3k|  }                                                                           \
tasn_dec.c:sk_ASN1_VALUE_new_null:
  420|   100k|  OPENSSL_INLINE STACK_OF(name) *sk_##name##_new_null(void) {                 \
  421|   100k|    return (STACK_OF(name) *)sk_new_null();                                   \
  422|   100k|  }                                                                           \
tasn_dec.c:sk_ASN1_VALUE_push:
  483|   160k|  OPENSSL_INLINE size_t sk_##name##_push(STACK_OF(name) *sk, ptrtype p) {     \
  484|   160k|    return sk_push((_STACK *)sk, (void *)p);                                  \
  485|   160k|  }                                                                           \
tasn_enc.c:sk_ASN1_VALUE_num:
  424|   281k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|   281k|    return sk_num((const _STACK *)sk);                                        \
  426|   281k|  }                                                                           \
tasn_enc.c:sk_ASN1_VALUE_value:
  433|   120k|                                           size_t i) {                        \
  434|   120k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|   120k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_num:
  424|   140k|  OPENSSL_INLINE size_t sk_##name##_num(const STACK_OF(name) *sk) {           \
  425|   140k|    return sk_num((const _STACK *)sk);                                        \
  426|   140k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_value:
  433|  80.3k|                                           size_t i) {                        \
  434|  80.3k|    return (ptrtype)sk_value((const _STACK *)sk, i);                          \
  435|  80.3k|  }                                                                           \
tasn_fre.c:sk_ASN1_VALUE_free:
  442|  60.2k|  OPENSSL_INLINE void sk_##name##_free(STACK_OF(name) *sk) {                  \
  443|  60.2k|    sk_free((_STACK *)sk);                                                    \
  444|  60.2k|  }                                                                           \

SSL_CTX_set_srtp_profiles:
  196|  5.48k|int SSL_CTX_set_srtp_profiles(SSL_CTX *ctx, const char *profiles) {
  197|  5.48k|  return ssl_ctx_make_profiles(profiles, &ctx->srtp_profiles);
  198|  5.48k|}
d1_srtp.cc:_ZL21ssl_ctx_make_profilesPKcPNSt3__110unique_ptrI32stack_st_SRTP_PROTECTION_PROFILEN4bssl8internal7DeleterEEE:
  163|  5.48k|    UniquePtr<STACK_OF(SRTP_PROTECTION_PROFILE)> *out) {
  164|  5.48k|  UniquePtr<STACK_OF(SRTP_PROTECTION_PROFILE)> profiles(
  165|  5.48k|      sk_SRTP_PROTECTION_PROFILE_new_null());
  166|  5.48k|  if (profiles == nullptr) {
  ------------------
  |  Branch (166:7): [True: 0, False: 5.48k]
  ------------------
  167|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_SRTP_COULD_NOT_ALLOCATE_PROFILES);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  168|      0|    return 0;
  169|      0|  }
  170|       |
  171|  5.48k|  const char *col;
  172|  5.48k|  const char *ptr = profiles_string;
  173|  5.92k|  do {
  174|  5.92k|    col = strchr(ptr, ':');
  175|       |
  176|  5.92k|    const SRTP_PROTECTION_PROFILE *profile;
  177|  5.92k|    if (!find_profile_by_name(ptr, &profile,
  ------------------
  |  Branch (177:9): [True: 5.07k, False: 847]
  ------------------
  178|  5.92k|                              col ? (size_t)(col - ptr) : strlen(ptr))) {
  ------------------
  |  Branch (178:31): [True: 1.08k, False: 4.83k]
  ------------------
  179|  5.07k|      OPENSSL_PUT_ERROR(SSL, SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE);
  ------------------
  |  |  441|  5.07k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  180|  5.07k|      return 0;
  181|  5.07k|    }
  182|       |
  183|    847|    if (!sk_SRTP_PROTECTION_PROFILE_push(profiles.get(), profile)) {
  ------------------
  |  Branch (183:9): [True: 0, False: 847]
  ------------------
  184|      0|      return 0;
  185|      0|    }
  186|       |
  187|    847|    if (col) {
  ------------------
  |  Branch (187:9): [True: 433, False: 414]
  ------------------
  188|    433|      ptr = col + 1;
  189|    433|    }
  190|    847|  } while (col);
  ------------------
  |  Branch (190:12): [True: 433, False: 414]
  ------------------
  191|       |
  192|    414|  *out = std::move(profiles);
  193|    414|  return 1;
  194|  5.48k|}
d1_srtp.cc:_ZL20find_profile_by_namePKcPPK26srtp_protection_profile_stm:
  147|  5.92k|                                size_t len) {
  148|  5.92k|  const SRTP_PROTECTION_PROFILE *p = kSRTPProfiles;
  149|  28.1k|  while (p->name) {
  ------------------
  |  Branch (149:10): [True: 23.1k, False: 5.07k]
  ------------------
  150|  23.1k|    if (len == strlen(p->name) && !strncmp(p->name, profile_name, len)) {
  ------------------
  |  Branch (150:9): [True: 1.95k, False: 21.1k]
  |  Branch (150:35): [True: 847, False: 1.10k]
  ------------------
  151|    847|      *pptr = p;
  152|    847|      return 1;
  153|    847|    }
  154|       |
  155|  22.2k|    p++;
  156|  22.2k|  }
  157|       |
  158|  5.07k|  return 0;
  159|  5.92k|}

_ZN4bssl28ssl_is_valid_ech_public_nameENS_4SpanIKhEE:
  356|  4.79k|bool ssl_is_valid_ech_public_name(Span<const uint8_t> public_name) {
  357|       |  // See draft-ietf-tls-esni-13, Section 4 and RFC 5890, Section 2.3.1. The
  358|       |  // public name must be a dot-separated sequence of LDH labels and not begin or
  359|       |  // end with a dot.
  360|  4.79k|  auto remaining = public_name;
  361|  4.79k|  if (remaining.empty()) {
  ------------------
  |  Branch (361:7): [True: 0, False: 4.79k]
  ------------------
  362|      0|    return false;
  363|      0|  }
  364|  4.79k|  Span<const uint8_t> last;
  365|  8.65k|  while (!remaining.empty()) {
  ------------------
  |  Branch (365:10): [True: 5.08k, False: 3.57k]
  ------------------
  366|       |    // Find the next dot-separated component.
  367|  5.08k|    auto dot = std::find(remaining.begin(), remaining.end(), '.');
  368|  5.08k|    Span<const uint8_t> component;
  369|  5.08k|    if (dot == remaining.end()) {
  ------------------
  |  Branch (369:9): [True: 4.22k, False: 859]
  ------------------
  370|  4.22k|      component = remaining;
  371|  4.22k|      last = component;
  372|  4.22k|      remaining = Span<const uint8_t>();
  373|  4.22k|    } else {
  374|    859|      component = remaining.subspan(0, dot - remaining.begin());
  375|       |      // Skip the dot.
  376|    859|      remaining = remaining.subspan(dot - remaining.begin() + 1);
  377|    859|      if (remaining.empty()) {
  ------------------
  |  Branch (377:11): [True: 272, False: 587]
  ------------------
  378|       |        // Trailing dots are not allowed.
  379|    272|        return false;
  380|    272|      }
  381|    859|    }
  382|       |    // |component| must be a valid LDH label. Checking for empty components also
  383|       |    // rejects leading dots.
  384|  4.81k|    if (component.empty() || component.size() > 63 ||
  ------------------
  |  Branch (384:9): [True: 197, False: 4.61k]
  |  Branch (384:30): [True: 91, False: 4.52k]
  ------------------
  385|  4.81k|        component.front() == '-' || component.back() == '-') {
  ------------------
  |  Branch (385:9): [True: 207, False: 4.31k]
  |  Branch (385:37): [True: 208, False: 4.11k]
  ------------------
  386|    703|      return false;
  387|    703|    }
  388|  12.7k|    for (uint8_t c : component) {
  ------------------
  |  Branch (388:20): [True: 12.7k, False: 3.85k]
  ------------------
  389|  12.7k|      if (!OPENSSL_isalnum(c) && c != '-') {
  ------------------
  |  Branch (389:11): [True: 845, False: 11.8k]
  |  Branch (389:34): [True: 252, False: 593]
  ------------------
  390|    252|        return false;
  391|    252|      }
  392|  12.7k|    }
  393|  4.11k|  }
  394|       |
  395|       |  // The WHATWG URL parser additionally does not allow any DNS names that end in
  396|       |  // a numeric component. See:
  397|       |  // https://url.spec.whatwg.org/#concept-host-parser
  398|       |  // https://url.spec.whatwg.org/#ends-in-a-number-checker
  399|       |  //
  400|       |  // The WHATWG parser is formulated in terms of parsing decimal, octal, and
  401|       |  // hex, along with a separate ASCII digits check. The ASCII digits check
  402|       |  // subsumes the decimal and octal check, so we only need to check two cases.
  403|  3.57k|  return !is_hex_component(last) && !is_decimal_component(last);
  ------------------
  |  Branch (403:10): [True: 3.11k, False: 456]
  |  Branch (403:37): [True: 2.77k, False: 343]
  ------------------
  404|  4.79k|}
_ZN4bssl15ECHServerConfig4InitENS_4SpanIKhEEPK15evp_hpke_key_stb:
  485|  11.7k|                           const EVP_HPKE_KEY *key, bool is_retry_config) {
  486|  11.7k|  is_retry_config_ = is_retry_config;
  487|       |
  488|       |  // Parse the ECHConfig, rejecting all unsupported parameters and extensions.
  489|       |  // Unlike most server options, ECH's server configuration is serialized and
  490|       |  // configured in both the server and DNS. If the caller configures an
  491|       |  // unsupported parameter, this is a deployment error. To catch these errors,
  492|       |  // we fail early.
  493|  11.7k|  CBS cbs = ech_config;
  494|  11.7k|  bool supported;
  495|  11.7k|  if (!parse_ech_config(&cbs, &ech_config_, &supported,
  ------------------
  |  Branch (495:7): [True: 7.56k, False: 4.18k]
  ------------------
  496|  11.7k|                        /*all_extensions_mandatory=*/true)) {
  497|  7.56k|    return false;
  498|  7.56k|  }
  499|  4.18k|  if (CBS_len(&cbs) != 0) {
  ------------------
  |  Branch (499:7): [True: 461, False: 3.72k]
  ------------------
  500|    461|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|    461|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  501|    461|    return false;
  502|    461|  }
  503|  3.72k|  if (!supported) {
  ------------------
  |  Branch (503:7): [True: 2.18k, False: 1.54k]
  ------------------
  504|  2.18k|    OPENSSL_PUT_ERROR(SSL, SSL_R_UNSUPPORTED_ECH_SERVER_CONFIG);
  ------------------
  |  |  441|  2.18k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  505|  2.18k|    return false;
  506|  2.18k|  }
  507|       |
  508|  1.54k|  CBS cipher_suites = ech_config_.cipher_suites;
  509|  2.09k|  while (CBS_len(&cipher_suites) > 0) {
  ------------------
  |  Branch (509:10): [True: 1.54k, False: 551]
  ------------------
  510|  1.54k|    uint16_t kdf_id, aead_id;
  511|  1.54k|    if (!CBS_get_u16(&cipher_suites, &kdf_id) ||
  ------------------
  |  Branch (511:9): [True: 0, False: 1.54k]
  ------------------
  512|  1.54k|        !CBS_get_u16(&cipher_suites, &aead_id)) {
  ------------------
  |  Branch (512:9): [True: 0, False: 1.54k]
  ------------------
  513|      0|      OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  514|      0|      return false;
  515|      0|    }
  516|       |    // The server promises to support every option in the ECHConfig, so reject
  517|       |    // any unsupported cipher suites.
  518|  1.54k|    if (kdf_id != EVP_HPKE_HKDF_SHA256 || get_ech_aead(aead_id) == nullptr) {
  ------------------
  |  |   79|  3.08k|#define EVP_HPKE_HKDF_SHA256 0x0001
  ------------------
  |  Branch (518:9): [True: 634, False: 910]
  |  Branch (518:43): [True: 359, False: 551]
  ------------------
  519|    993|      OPENSSL_PUT_ERROR(SSL, SSL_R_UNSUPPORTED_ECH_SERVER_CONFIG);
  ------------------
  |  |  441|    993|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  520|    993|      return false;
  521|    993|    }
  522|  1.54k|  }
  523|       |
  524|       |  // Check the public key in the ECHConfig matches |key|.
  525|    551|  uint8_t expected_public_key[EVP_HPKE_MAX_PUBLIC_KEY_LENGTH];
  526|    551|  size_t expected_public_key_len;
  527|    551|  if (!EVP_HPKE_KEY_public_key(key, expected_public_key,
  ------------------
  |  Branch (527:7): [True: 0, False: 551]
  ------------------
  528|    551|                               &expected_public_key_len,
  529|    551|                               sizeof(expected_public_key))) {
  530|      0|    return false;
  531|      0|  }
  532|    551|  if (ech_config_.kem_id != EVP_HPKE_KEM_id(EVP_HPKE_KEY_kem(key)) ||
  ------------------
  |  Branch (532:7): [True: 284, False: 267]
  |  Branch (532:7): [True: 551, False: 0]
  ------------------
  533|    551|      MakeConstSpan(expected_public_key, expected_public_key_len) !=
  ------------------
  |  Branch (533:7): [True: 267, False: 0]
  ------------------
  534|    551|          ech_config_.public_key) {
  535|    551|    OPENSSL_PUT_ERROR(SSL, SSL_R_ECH_SERVER_CONFIG_AND_PRIVATE_KEY_MISMATCH);
  ------------------
  |  |  441|    551|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  536|    551|    return false;
  537|    551|  }
  538|       |
  539|      0|  if (!EVP_HPKE_KEY_copy(key_.get(), key)) {
  ------------------
  |  Branch (539:7): [True: 0, False: 0]
  ------------------
  540|      0|    return false;
  541|      0|  }
  542|       |
  543|      0|  return true;
  544|      0|}
SSL_ECH_KEYS_new:
 1013|  14.9k|SSL_ECH_KEYS *SSL_ECH_KEYS_new() { return New<SSL_ECH_KEYS>(); }
SSL_ECH_KEYS_free:
 1019|  14.9k|void SSL_ECH_KEYS_free(SSL_ECH_KEYS *keys) {
 1020|  14.9k|  if (keys == nullptr ||
  ------------------
  |  Branch (1020:7): [True: 0, False: 14.9k]
  ------------------
 1021|  14.9k|      !CRYPTO_refcount_dec_and_test_zero(&keys->references)) {
  ------------------
  |  Branch (1021:7): [True: 0, False: 14.9k]
  ------------------
 1022|      0|    return;
 1023|      0|  }
 1024|       |
 1025|  14.9k|  keys->~ssl_ech_keys_st();
 1026|  14.9k|  OPENSSL_free(keys);
 1027|  14.9k|}
SSL_ECH_KEYS_add:
 1031|  11.7k|                     const EVP_HPKE_KEY *key) {
 1032|  11.7k|  UniquePtr<ECHServerConfig> parsed_config = MakeUnique<ECHServerConfig>();
 1033|  11.7k|  if (!parsed_config) {
  ------------------
  |  Branch (1033:7): [True: 0, False: 11.7k]
  ------------------
 1034|      0|    return 0;
 1035|      0|  }
 1036|  11.7k|  if (!parsed_config->Init(MakeConstSpan(ech_config, ech_config_len), key,
  ------------------
  |  Branch (1036:7): [True: 11.7k, False: 0]
  ------------------
 1037|  11.7k|                           !!is_retry_config)) {
 1038|  11.7k|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|  11.7k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1039|  11.7k|    return 0;
 1040|  11.7k|  }
 1041|      0|  if (!configs->configs.Push(std::move(parsed_config))) {
  ------------------
  |  Branch (1041:7): [True: 0, False: 0]
  ------------------
 1042|      0|    return 0;
 1043|      0|  }
 1044|      0|  return 1;
 1045|      0|}
encrypted_client_hello.cc:_ZN4bsslL16is_hex_componentENS_4SpanIKhEE:
  332|  3.57k|static bool is_hex_component(Span<const uint8_t> in) {
  333|  3.57k|  if (in.size() < 2 || in[0] != '0' || (in[1] != 'x' && in[1] != 'X')) {
  ------------------
  |  Branch (333:7): [True: 1.08k, False: 2.48k]
  |  Branch (333:24): [True: 493, False: 1.99k]
  |  Branch (333:41): [True: 1.11k, False: 876]
  |  Branch (333:57): [True: 895, False: 219]
  ------------------
  334|  2.47k|    return false;
  335|  2.47k|  }
  336|  3.51k|  for (uint8_t b : in.subspan(2)) {
  ------------------
  |  Branch (336:18): [True: 3.51k, False: 456]
  ------------------
  337|  3.51k|    if (!OPENSSL_isxdigit(b)) {
  ------------------
  |  Branch (337:9): [True: 639, False: 2.87k]
  ------------------
  338|    639|      return false;
  339|    639|    }
  340|  3.51k|  }
  341|    456|  return true;
  342|  1.09k|}
encrypted_client_hello.cc:_ZN4bsslL20is_decimal_componentENS_4SpanIKhEE:
  344|  3.11k|static bool is_decimal_component(Span<const uint8_t> in) {
  345|  3.11k|  if (in.empty()) {
  ------------------
  |  Branch (345:7): [True: 0, False: 3.11k]
  ------------------
  346|      0|    return false;
  347|      0|  }
  348|  5.07k|  for (uint8_t b : in) {
  ------------------
  |  Branch (348:18): [True: 5.07k, False: 343]
  ------------------
  349|  5.07k|    if (!('0' <= b && b <= '9')) {
  ------------------
  |  Branch (349:11): [True: 4.88k, False: 198]
  |  Branch (349:23): [True: 2.30k, False: 2.57k]
  ------------------
  350|  2.77k|      return false;
  351|  2.77k|    }
  352|  5.07k|  }
  353|    343|  return true;
  354|  3.11k|}
encrypted_client_hello.cc:_ZN4bsslL16parse_ech_configEP6cbs_stPNS_9ECHConfigEPbb:
  407|  11.7k|                             bool all_extensions_mandatory) {
  408|  11.7k|  uint16_t version;
  409|  11.7k|  CBS orig = *cbs;
  410|  11.7k|  CBS contents;
  411|  11.7k|  if (!CBS_get_u16(cbs, &version) ||
  ------------------
  |  Branch (411:7): [True: 3.71k, False: 8.03k]
  ------------------
  412|  11.7k|      !CBS_get_u16_length_prefixed(cbs, &contents)) {
  ------------------
  |  Branch (412:7): [True: 245, False: 7.78k]
  ------------------
  413|  3.96k|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|  3.96k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  414|  3.96k|    return false;
  415|  3.96k|  }
  416|       |
  417|  7.78k|  if (version != kECHConfigVersion) {
  ------------------
  |  Branch (417:7): [True: 296, False: 7.49k]
  ------------------
  418|    296|    *out_supported = false;
  419|    296|    return true;
  420|    296|  }
  421|       |
  422|       |  // Make a copy of the ECHConfig and parse from it, so the results alias into
  423|       |  // the saved copy.
  424|  7.49k|  if (!out->raw.CopyFrom(
  ------------------
  |  Branch (424:7): [True: 0, False: 7.49k]
  ------------------
  425|  7.49k|          MakeConstSpan(CBS_data(&orig), CBS_len(&orig) - CBS_len(cbs)))) {
  426|      0|    return false;
  427|      0|  }
  428|       |
  429|  7.49k|  CBS ech_config(out->raw);
  430|  7.49k|  CBS public_name, public_key, cipher_suites, extensions;
  431|  7.49k|  if (!CBS_skip(&ech_config, 2) || // version
  ------------------
  |  Branch (431:7): [True: 0, False: 7.49k]
  ------------------
  432|  7.49k|      !CBS_get_u16_length_prefixed(&ech_config, &contents) ||
  ------------------
  |  Branch (432:7): [True: 0, False: 7.49k]
  ------------------
  433|  7.49k|      !CBS_get_u8(&contents, &out->config_id) ||
  ------------------
  |  Branch (433:7): [True: 221, False: 7.27k]
  ------------------
  434|  7.49k|      !CBS_get_u16(&contents, &out->kem_id) ||
  ------------------
  |  Branch (434:7): [True: 196, False: 7.07k]
  ------------------
  435|  7.49k|      !CBS_get_u16_length_prefixed(&contents, &public_key) ||
  ------------------
  |  Branch (435:7): [True: 223, False: 6.85k]
  ------------------
  436|  7.49k|      CBS_len(&public_key) == 0 ||
  ------------------
  |  Branch (436:7): [True: 196, False: 6.65k]
  ------------------
  437|  7.49k|      !CBS_get_u16_length_prefixed(&contents, &cipher_suites) ||
  ------------------
  |  Branch (437:7): [True: 254, False: 6.40k]
  ------------------
  438|  7.49k|      CBS_len(&cipher_suites) == 0 || CBS_len(&cipher_suites) % 4 != 0 ||
  ------------------
  |  Branch (438:7): [True: 205, False: 6.19k]
  |  Branch (438:39): [True: 325, False: 5.87k]
  ------------------
  439|  7.49k|      !CBS_get_u8(&contents, &out->maximum_name_length) ||
  ------------------
  |  Branch (439:7): [True: 196, False: 5.67k]
  ------------------
  440|  7.49k|      !CBS_get_u8_length_prefixed(&contents, &public_name) ||
  ------------------
  |  Branch (440:7): [True: 226, False: 5.45k]
  ------------------
  441|  7.49k|      CBS_len(&public_name) == 0 ||
  ------------------
  |  Branch (441:7): [True: 194, False: 5.25k]
  ------------------
  442|  7.49k|      !CBS_get_u16_length_prefixed(&contents, &extensions) ||
  ------------------
  |  Branch (442:7): [True: 256, False: 5.00k]
  ------------------
  443|  7.49k|      CBS_len(&contents) != 0) {
  ------------------
  |  Branch (443:7): [True: 204, False: 4.79k]
  ------------------
  444|  2.69k|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|  2.69k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  445|  2.69k|    return false;
  446|  2.69k|  }
  447|       |
  448|  4.79k|  if (!ssl_is_valid_ech_public_name(public_name)) {
  ------------------
  |  Branch (448:7): [True: 2.02k, False: 2.77k]
  ------------------
  449|       |    // TODO(https://crbug.com/boringssl/275): The draft says ECHConfigs with
  450|       |    // invalid public names should be ignored, but LDH syntax failures are
  451|       |    // unambiguously invalid.
  452|  2.02k|    *out_supported = false;
  453|  2.02k|    return true;
  454|  2.02k|  }
  455|       |
  456|  2.77k|  out->public_key = public_key;
  457|  2.77k|  out->public_name = public_name;
  458|       |  // This function does not ensure |out->kem_id| and |out->cipher_suites| use
  459|       |  // supported algorithms. The caller must do this.
  460|  2.77k|  out->cipher_suites = cipher_suites;
  461|       |
  462|  2.77k|  bool has_unknown_mandatory_extension = false;
  463|  4.43k|  while (CBS_len(&extensions) != 0) {
  ------------------
  |  Branch (463:10): [True: 2.56k, False: 1.86k]
  ------------------
  464|  2.56k|    uint16_t type;
  465|  2.56k|    CBS body;
  466|  2.56k|    if (!CBS_get_u16(&extensions, &type) ||
  ------------------
  |  Branch (466:9): [True: 481, False: 2.08k]
  ------------------
  467|  2.56k|        !CBS_get_u16_length_prefixed(&extensions, &body)) {
  ------------------
  |  Branch (467:9): [True: 424, False: 1.66k]
  ------------------
  468|    905|      OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|    905|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  469|    905|      return false;
  470|    905|    }
  471|       |    // We currently do not support any extensions.
  472|  1.66k|    if (type & 0x8000 || all_extensions_mandatory) {
  ------------------
  |  Branch (472:9): [True: 963, False: 699]
  |  Branch (472:26): [True: 699, False: 0]
  ------------------
  473|       |      // Extension numbers with the high bit set are mandatory. Continue parsing
  474|       |      // to enforce syntax, but we will ultimately ignore this ECHConfig as a
  475|       |      // client and reject it as a server.
  476|  1.66k|      has_unknown_mandatory_extension = true;
  477|  1.66k|    }
  478|  1.66k|  }
  479|       |
  480|  1.86k|  *out_supported = !has_unknown_mandatory_extension;
  481|  1.86k|  return true;
  482|  2.77k|}
encrypted_client_hello.cc:_ZN4bsslL12get_ech_aeadEt:
   46|    910|static const EVP_HPKE_AEAD *get_ech_aead(uint16_t aead_id) {
   47|  2.13k|  for (const auto aead_func : kSupportedAEADs) {
  ------------------
  |  Branch (47:29): [True: 2.13k, False: 359]
  ------------------
   48|  2.13k|    const EVP_HPKE_AEAD *aead = aead_func();
   49|  2.13k|    if (aead_id == EVP_HPKE_AEAD_id(aead)) {
  ------------------
  |  Branch (49:9): [True: 551, False: 1.58k]
  ------------------
   50|    551|      return aead;
   51|    551|    }
   52|  2.13k|  }
   53|    359|  return nullptr;
   54|    910|}

_ZN4bssl22ssl_is_valid_alpn_listENS_4SpanIKhEE:
 1449|  2.48k|bool ssl_is_valid_alpn_list(Span<const uint8_t> in) {
 1450|  2.48k|  CBS protocol_name_list = in;
 1451|  2.48k|  if (CBS_len(&protocol_name_list) == 0) {
  ------------------
  |  Branch (1451:7): [True: 0, False: 2.48k]
  ------------------
 1452|      0|    return false;
 1453|      0|  }
 1454|  3.17k|  while (CBS_len(&protocol_name_list) > 0) {
  ------------------
  |  Branch (1454:10): [True: 2.87k, False: 298]
  ------------------
 1455|  2.87k|    CBS protocol_name;
 1456|  2.87k|    if (!CBS_get_u8_length_prefixed(&protocol_name_list, &protocol_name) ||
  ------------------
  |  Branch (1456:9): [True: 1.85k, False: 1.01k]
  ------------------
 1457|       |        // Empty protocol names are forbidden.
 1458|  2.87k|        CBS_len(&protocol_name) == 0) {
  ------------------
  |  Branch (1458:9): [True: 326, False: 689]
  ------------------
 1459|  2.18k|      return false;
 1460|  2.18k|    }
 1461|  2.87k|  }
 1462|    298|  return true;
 1463|  2.48k|}
_ZN4bssl21ssl_is_sct_list_validEPK6cbs_st:
 4264|  2.95k|bool ssl_is_sct_list_valid(const CBS *contents) {
 4265|       |  // Shallow parse the SCT list for sanity. By the RFC
 4266|       |  // (https://tools.ietf.org/html/rfc6962#section-3.3) neither the list nor any
 4267|       |  // of the SCTs may be empty.
 4268|  2.95k|  CBS copy = *contents;
 4269|  2.95k|  CBS sct_list;
 4270|  2.95k|  if (!CBS_get_u16_length_prefixed(&copy, &sct_list) ||
  ------------------
  |  Branch (4270:7): [True: 1.59k, False: 1.36k]
  ------------------
 4271|  2.95k|      CBS_len(&copy) != 0 ||
  ------------------
  |  Branch (4271:7): [True: 229, False: 1.13k]
  ------------------
 4272|  2.95k|      CBS_len(&sct_list) == 0) {
  ------------------
  |  Branch (4272:7): [True: 194, False: 938]
  ------------------
 4273|  2.01k|    return false;
 4274|  2.01k|  }
 4275|       |
 4276|  1.63k|  while (CBS_len(&sct_list) > 0) {
  ------------------
  |  Branch (4276:10): [True: 1.09k, False: 533]
  ------------------
 4277|  1.09k|    CBS sct;
 4278|  1.09k|    if (!CBS_get_u16_length_prefixed(&sct_list, &sct) ||
  ------------------
  |  Branch (4278:9): [True: 208, False: 889]
  ------------------
 4279|  1.09k|        CBS_len(&sct) == 0) {
  ------------------
  |  Branch (4279:9): [True: 197, False: 692]
  ------------------
 4280|    405|      return false;
 4281|    405|    }
 4282|  1.09k|  }
 4283|       |
 4284|    533|  return true;
 4285|    938|}

_ZN4bssl13SSL_HANDSHAKEC2EP6ssl_st:
  153|  4.83k|      channel_id_negotiated(false) {
  154|  4.83k|  assert(ssl);
  155|       |
  156|       |  // Draw entropy for all GREASE values at once. This avoids calling
  157|       |  // |RAND_bytes| repeatedly and makes the values consistent within a
  158|       |  // connection. The latter is so the second ClientHello matches after
  159|       |  // HelloRetryRequest and so supported_groups and key_shares are consistent.
  160|      0|  RAND_bytes(grease_seed, sizeof(grease_seed));
  161|  4.83k|}
_ZN4bssl13SSL_HANDSHAKED2Ev:
  163|  4.83k|SSL_HANDSHAKE::~SSL_HANDSHAKE() {
  164|  4.83k|  ssl->ctx->x509_method->hs_flush_cached_ca_names(this);
  165|  4.83k|}
_ZN4bssl17ssl_handshake_newEP6ssl_st:
  196|  4.83k|UniquePtr<SSL_HANDSHAKE> ssl_handshake_new(SSL *ssl) {
  197|  4.83k|  UniquePtr<SSL_HANDSHAKE> hs = MakeUnique<SSL_HANDSHAKE>(ssl);
  198|  4.83k|  if (!hs || !hs->transcript.Init()) {
  ------------------
  |  Branch (198:7): [True: 0, False: 4.83k]
  |  Branch (198:14): [True: 0, False: 4.83k]
  ------------------
  199|      0|    return nullptr;
  200|      0|  }
  201|  4.83k|  hs->config = ssl->config.get();
  202|  4.83k|  if (!hs->config) {
  ------------------
  |  Branch (202:7): [True: 0, False: 4.83k]
  ------------------
  203|      0|    assert(hs->config);
  204|      0|    return nullptr;
  205|      0|  }
  206|  4.83k|  return hs;
  207|  4.83k|}

_ZN4bssl9SSLBufferC2Ev:
 1231|  9.66k|  SSLBuffer() {}
_ZN4bssl9SSLBufferD2Ev:
 1232|  9.66k|  ~SSLBuffer() { Clear(); }
_ZN4bssl5ArrayIhE5ResetEv:
  278|   121k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayIhE5ResetEPhm:
  282|   121k|  void Reset(T *new_data, size_t new_size) {
  283|   304k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 183k, False: 121k]
  ------------------
  284|   183k|      data_[i].~T();
  285|   183k|    }
  286|   121k|    OPENSSL_free(data_);
  287|   121k|    data_ = new_data;
  288|   121k|    size_ = new_size;
  289|   121k|  }
_ZN15ssl_ech_keys_stD2Ev:
 4021|  14.9k|  ~ssl_ech_keys_st() = default;
_ZN4bssl13GrowableArrayINSt3__110unique_ptrINS_15ECHServerConfigENS_8internal7DeleterEEEED2Ev:
  365|  14.9k|  ~GrowableArray() {}
_ZN4bssl5ArrayINSt3__110unique_ptrINS_15ECHServerConfigENS_8internal7DeleterEEEED2Ev:
  256|  14.9k|  ~Array() { Reset(); }
_ZN4bssl5ArrayINSt3__110unique_ptrINS_15ECHServerConfigENS_8internal7DeleterEEEE5ResetEv:
  278|  14.9k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayINSt3__110unique_ptrINS_15ECHServerConfigENS_8internal7DeleterEEEE5ResetEPS6_m:
  282|  14.9k|  void Reset(T *new_data, size_t new_size) {
  283|  14.9k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 0, False: 14.9k]
  ------------------
  284|      0|      data_[i].~T();
  285|      0|    }
  286|  14.9k|    OPENSSL_free(data_);
  287|  14.9k|    data_ = new_data;
  288|  14.9k|    size_ = new_size;
  289|  14.9k|  }
_ZN4bssl5ArrayIhEC2Ev:
  252|   108k|  Array() {}
_ZN4bssl5ArrayIhED2Ev:
  256|   108k|  ~Array() { Reset(); }
_ZN4bssl5ArrayIhE8CopyFromENS_4SpanIKhEE:
  328|  13.0k|  bool CopyFrom(Span<const T> in) {
  329|  13.0k|    if (!Init(in.size())) {
  ------------------
  |  Branch (329:9): [True: 0, False: 13.0k]
  ------------------
  330|      0|      return false;
  331|      0|    }
  332|  13.0k|    OPENSSL_memcpy(data_, in.data(), sizeof(T) * in.size());
  333|  13.0k|    return true;
  334|  13.0k|  }
_ZN4bssl5ArrayIhE4InitEm:
  305|  13.0k|  bool Init(size_t new_size) {
  306|  13.0k|    Reset();
  307|  13.0k|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 5.27k, False: 7.81k]
  ------------------
  308|  5.27k|      return true;
  309|  5.27k|    }
  310|       |
  311|  7.81k|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 7.81k]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|  7.81k|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|  7.81k|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 7.81k]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|  7.81k|    size_ = new_size;
  320|   191k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 183k, False: 7.81k]
  ------------------
  321|   183k|      new (&data_[i]) T;
  322|   183k|    }
  323|  7.81k|    return true;
  324|  7.81k|  }
_ZNK4bssl5ArrayIhE4sizeEv:
  267|  12.3k|  size_t size() const { return size_; }
_ZNK4bssl5ArrayIhE4dataEv:
  265|  12.3k|  const T *data() const { return data_; }
_ZN4bssl3NewI15ssl_ech_keys_stJEEEPT_DpOT0_:
  195|  14.9k|T *New(Args &&... args) {
  196|  14.9k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  14.9k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 14.9k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  14.9k|  return new (t) T(std::forward<Args>(args)...);
  201|  14.9k|}
_ZN15ssl_ech_keys_stC2Ev:
 4013|  14.9k|  ssl_ech_keys_st() = default;
_ZN4bssl13GrowableArrayINSt3__110unique_ptrINS_15ECHServerConfigENS_8internal7DeleterEEEEC2Ev:
  362|  14.9k|  GrowableArray() = default;
_ZN4bssl5ArrayINSt3__110unique_ptrINS_15ECHServerConfigENS_8internal7DeleterEEEEC2Ev:
  252|  14.9k|  Array() {}
_ZN4bssl10MakeUniqueINS_15ECHServerConfigEJEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  11.7k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  11.7k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  11.7k|}
_ZN4bssl3NewINS_15ECHServerConfigEJEEEPT_DpOT0_:
  195|  11.7k|T *New(Args &&... args) {
  196|  11.7k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  11.7k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 11.7k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  11.7k|  return new (t) T(std::forward<Args>(args)...);
  201|  11.7k|}
_ZN4bssl15ECHServerConfigC2Ev:
 1478|  11.7k|  ECHServerConfig() = default;
_ZN4bssl8internal11DeleterImplINS_15ECHServerConfigEvE4FreeEPS2_:
  219|  11.7k|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_15ECHServerConfigEEEvPT_:
  207|  11.7k|void Delete(T *t) {
  208|  11.7k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 11.7k, False: 0]
  ------------------
  209|  11.7k|    t->~T();
  210|  11.7k|    OPENSSL_free(t);
  211|  11.7k|  }
  212|  11.7k|}
_ZN4bssl5ArrayItEC2Ev:
  252|  83.5k|  Array() {}
_ZN4bssl5ArrayItE4InitEm:
  305|  55.9k|  bool Init(size_t new_size) {
  306|  55.9k|    Reset();
  307|  55.9k|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 23.0k, False: 32.9k]
  ------------------
  308|  23.0k|      return true;
  309|  23.0k|    }
  310|       |
  311|  32.9k|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 32.9k]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|  32.9k|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|  32.9k|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 32.9k]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|  32.9k|    size_ = new_size;
  320|   320k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 288k, False: 32.9k]
  ------------------
  321|   288k|      new (&data_[i]) T;
  322|   288k|    }
  323|  32.9k|    return true;
  324|  32.9k|  }
_ZN4bssl5ArrayItE5ResetEv:
  278|   147k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayItE5ResetEPtm:
  282|   147k|  void Reset(T *new_data, size_t new_size) {
  283|   434k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 287k, False: 147k]
  ------------------
  284|   287k|      data_[i].~T();
  285|   287k|    }
  286|   147k|    OPENSSL_free(data_);
  287|   147k|    data_ = new_data;
  288|   147k|    size_ = new_size;
  289|   147k|  }
_ZNK4bssl5ArrayItE4sizeEv:
  267|  56.3k|  size_t size() const { return size_; }
_ZN4bssl5ArrayItEixEm:
  271|  82.7k|  T &operator[](size_t i) { return data_[i]; }
_ZN4bssl5ArrayItE4dataEv:
  266|  6.97k|  T *data() { return data_; }
_ZN4bssl5ArrayItED2Ev:
  256|  83.5k|  ~Array() { Reset(); }
_ZN4bssl5ArrayItEaSEOS1_:
  259|  7.50k|  Array &operator=(Array &&other) {
  260|  7.50k|    Reset();
  261|  7.50k|    other.Release(&data_, &size_);
  262|  7.50k|    return *this;
  263|  7.50k|  }
_ZN4bssl5ArrayItE7ReleaseEPPtPm:
  293|  7.50k|  void Release(T **out, size_t *out_size) {
  294|  7.50k|    *out = data_;
  295|  7.50k|    *out_size = size_;
  296|  7.50k|    data_ = nullptr;
  297|  7.50k|    size_ = 0;
  298|  7.50k|  }
_ZNK4bssl5ArrayItE5emptyEv:
  268|  1.27k|  bool empty() const { return size_ == 0; }
_ZNK4bssl5ArrayItE4dataEv:
  265|  14.4k|  const T *data() const { return data_; }
_ZN4bssl10MakeUniqueINS_13SSL_HANDSHAKEEJRP6ssl_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewINS_13SSL_HANDSHAKEEJRP6ssl_stEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl8internal11DeleterImplINS_13SSL_HANDSHAKEEvE4FreeEPS2_:
  219|  4.83k|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_13SSL_HANDSHAKEEEEvPT_:
  207|  4.83k|void Delete(T *t) {
  208|  4.83k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 4.83k, False: 0]
  ------------------
  209|  4.83k|    t->~T();
  210|  4.83k|    OPENSSL_free(t);
  211|  4.83k|  }
  212|  4.83k|}
_ZN4bssl10MakeUniqueINS_14SSLAEADContextEJiRbDnEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  9.66k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  9.66k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  9.66k|}
_ZN4bssl3NewINS_14SSLAEADContextEJiRbDnEEEPT_DpOT0_:
  195|  9.66k|T *New(Args &&... args) {
  196|  9.66k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  9.66k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 9.66k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  9.66k|  return new (t) T(std::forward<Args>(args)...);
  201|  9.66k|}
_ZN4bssl8internal11DeleterImplINS_14SSLAEADContextEvE4FreeEPS2_:
  219|  9.66k|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_14SSLAEADContextEEEvPT_:
  207|  9.66k|void Delete(T *t) {
  208|  9.66k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 9.66k, False: 0]
  ------------------
  209|  9.66k|    t->~T();
  210|  9.66k|    OPENSSL_free(t);
  211|  9.66k|  }
  212|  9.66k|}
_ZN4bssl10MakeUniqueINS_4CERTEJRPKNS_15SSL_X509_METHODEEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewINS_4CERTEJRPKNS_15SSL_X509_METHODEEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl8internal11DeleterImplINS_4CERTEvE4FreeEPS2_:
  219|  9.66k|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_4CERTEEEvPT_:
  207|  9.66k|void Delete(T *t) {
  208|  9.66k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 9.66k, False: 0]
  ------------------
  209|  9.66k|    t->~T();
  210|  9.66k|    OPENSSL_free(t);
  211|  9.66k|  }
  212|  9.66k|}
_ZN4bssl5ArrayItE8CopyFromENS_4SpanIKtEE:
  328|  20.2k|  bool CopyFrom(Span<const T> in) {
  329|  20.2k|    if (!Init(in.size())) {
  ------------------
  |  Branch (329:9): [True: 0, False: 20.2k]
  ------------------
  330|      0|      return false;
  331|      0|    }
  332|  20.2k|    OPENSSL_memcpy(data_, in.data(), sizeof(T) * in.size());
  333|  20.2k|    return true;
  334|  20.2k|  }
_ZN4bssl5ArrayIiEC2Ev:
  252|  5.47k|  Array() {}
_ZN4bssl5ArrayIiE4InitEm:
  305|  5.47k|  bool Init(size_t new_size) {
  306|  5.47k|    Reset();
  307|  5.47k|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 0, False: 5.47k]
  ------------------
  308|      0|      return true;
  309|      0|    }
  310|       |
  311|  5.47k|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 5.47k]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|  5.47k|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|  5.47k|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 5.47k]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|  5.47k|    size_ = new_size;
  320|   937k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 932k, False: 5.47k]
  ------------------
  321|   932k|      new (&data_[i]) T;
  322|   932k|    }
  323|  5.47k|    return true;
  324|  5.47k|  }
_ZN4bssl5ArrayIiE5ResetEv:
  278|  10.9k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayIiE5ResetEPim:
  282|  10.9k|  void Reset(T *new_data, size_t new_size) {
  283|   943k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 932k, False: 10.9k]
  ------------------
  284|   932k|      data_[i].~T();
  285|   932k|    }
  286|  10.9k|    OPENSSL_free(data_);
  287|  10.9k|    data_ = new_data;
  288|  10.9k|    size_ = new_size;
  289|  10.9k|  }
_ZN4bssl5ArrayIiE4dataEv:
  266|  5.47k|  T *data() { return data_; }
_ZN4bssl5ArrayIiEixEm:
  271|   987k|  T &operator[](size_t i) { return data_[i]; }
_ZN4bssl5ArrayIiED2Ev:
  256|  5.47k|  ~Array() { Reset(); }
_ZN4bssl5ArrayIbEC2Ev:
  252|  45.4k|  Array() {}
_ZN4bssl5ArrayIbED2Ev:
  256|  45.4k|  ~Array() { Reset(); }
_ZN4bssl5ArrayIbE5ResetEv:
  278|  90.9k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayIbE5ResetEPbm:
  282|  90.9k|  void Reset(T *new_data, size_t new_size) {
  283|   636k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 545k, False: 90.9k]
  ------------------
  284|   545k|      data_[i].~T();
  285|   545k|    }
  286|  90.9k|    OPENSSL_free(data_);
  287|  90.9k|    data_ = new_data;
  288|  90.9k|    size_ = new_size;
  289|  90.9k|  }
_ZN4bssl5ArrayIbE8CopyFromENS_4SpanIKbEE:
  328|  22.7k|  bool CopyFrom(Span<const T> in) {
  329|  22.7k|    if (!Init(in.size())) {
  ------------------
  |  Branch (329:9): [True: 0, False: 22.7k]
  ------------------
  330|      0|      return false;
  331|      0|    }
  332|  22.7k|    OPENSSL_memcpy(data_, in.data(), sizeof(T) * in.size());
  333|  22.7k|    return true;
  334|  22.7k|  }
_ZN4bssl5ArrayIbE7ReleaseEPPbPm:
  293|  22.7k|  void Release(T **out, size_t *out_size) {
  294|  22.7k|    *out = data_;
  295|  22.7k|    *out_size = size_;
  296|  22.7k|    data_ = nullptr;
  297|  22.7k|    size_ = 0;
  298|  22.7k|  }
_ZN4bssl5ArrayIbE4InitEm:
  305|  45.4k|  bool Init(size_t new_size) {
  306|  45.4k|    Reset();
  307|  45.4k|    if (new_size == 0) {
  ------------------
  |  Branch (307:9): [True: 10.4k, False: 35.0k]
  ------------------
  308|  10.4k|      return true;
  309|  10.4k|    }
  310|       |
  311|  35.0k|    if (new_size > std::numeric_limits<size_t>::max() / sizeof(T)) {
  ------------------
  |  Branch (311:9): [True: 0, False: 35.0k]
  ------------------
  312|      0|      OPENSSL_PUT_ERROR(SSL, ERR_R_OVERFLOW);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  313|      0|      return false;
  314|      0|    }
  315|  35.0k|    data_ = reinterpret_cast<T *>(OPENSSL_malloc(new_size * sizeof(T)));
  316|  35.0k|    if (data_ == nullptr) {
  ------------------
  |  Branch (316:9): [True: 0, False: 35.0k]
  ------------------
  317|      0|      return false;
  318|      0|    }
  319|  35.0k|    size_ = new_size;
  320|   781k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (320:24): [True: 746k, False: 35.0k]
  ------------------
  321|   746k|      new (&data_[i]) T;
  322|   746k|    }
  323|  35.0k|    return true;
  324|  35.0k|  }
_ZN4bssl5ArrayIbEixEm:
  271|   200k|  T &operator[](size_t i) { return data_[i]; }
_ZN4bssl10MakeUniqueINS_23SSLCipherPreferenceListEJEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  22.7k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  22.7k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  22.7k|}
_ZN4bssl3NewINS_23SSLCipherPreferenceListEJEEEPT_DpOT0_:
  195|  22.7k|T *New(Args &&... args) {
  196|  22.7k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  22.7k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 22.7k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  22.7k|  return new (t) T(std::forward<Args>(args)...);
  201|  22.7k|}
_ZN4bssl23SSLCipherPreferenceListC2Ev:
  622|  22.7k|  SSLCipherPreferenceList() = default;
_ZN4bssl8internal11DeleterImplINS_23SSLCipherPreferenceListEvE4FreeEPS2_:
  219|  22.7k|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_23SSLCipherPreferenceListEEEvPT_:
  207|  22.7k|void Delete(T *t) {
  208|  22.7k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 22.7k, False: 0]
  ------------------
  209|  22.7k|    t->~T();
  210|  22.7k|    OPENSSL_free(t);
  211|  22.7k|  }
  212|  22.7k|}
_ZNK4bssl5ArrayIbE4dataEv:
  265|  22.7k|  const T *data() const { return data_; }
_ZNK4bssl5ArrayIbE4sizeEv:
  267|  22.7k|  size_t size() const { return size_; }
_ZN4bssl13GrowableArrayINS_18CertCompressionAlgEEC2Ev:
  362|  4.83k|  GrowableArray() = default;
_ZN4bssl5ArrayINS_18CertCompressionAlgEEC2Ev:
  252|  4.83k|  Array() {}
_ZN4bssl13GrowableArrayINS_10ALPSConfigEEC2Ev:
  362|  4.83k|  GrowableArray() = default;
_ZN4bssl5ArrayINS_10ALPSConfigEEC2Ev:
  252|  4.83k|  Array() {}
_ZN4bssl8internal11DeleterImplINS_10SSL_CONFIGEvE4FreeEPS2_:
  219|  4.83k|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_10SSL_CONFIGEEEvPT_:
  207|  4.83k|void Delete(T *t) {
  208|  4.83k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 4.83k, False: 0]
  ------------------
  209|  4.83k|    t->~T();
  210|  4.83k|    OPENSSL_free(t);
  211|  4.83k|  }
  212|  4.83k|}
_ZN4bssl13GrowableArrayINS_18CertCompressionAlgEED2Ev:
  365|  4.83k|  ~GrowableArray() {}
_ZN4bssl5ArrayINS_18CertCompressionAlgEED2Ev:
  256|  4.83k|  ~Array() { Reset(); }
_ZN4bssl5ArrayINS_18CertCompressionAlgEE5ResetEv:
  278|  4.83k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayINS_18CertCompressionAlgEE5ResetEPS1_m:
  282|  4.83k|  void Reset(T *new_data, size_t new_size) {
  283|  4.83k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 0, False: 4.83k]
  ------------------
  284|      0|      data_[i].~T();
  285|      0|    }
  286|  4.83k|    OPENSSL_free(data_);
  287|  4.83k|    data_ = new_data;
  288|  4.83k|    size_ = new_size;
  289|  4.83k|  }
_ZN4bssl10MakeUniqueI10ssl_ctx_stJRPK13ssl_method_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewI10ssl_ctx_stJRPK13ssl_method_stEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl10MakeUniqueINS_4CERTEJRKPKNS_15SSL_X509_METHODEEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewINS_4CERTEJRKPKNS_15SSL_X509_METHODEEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl10MakeUniqueI6ssl_stJRP10ssl_ctx_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewI6ssl_stJRP10ssl_ctx_stEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl10MakeUniqueINS_10SSL_CONFIGEJP6ssl_stEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewINS_10SSL_CONFIGEJP6ssl_stEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl13GrowableArrayINS_10ALPSConfigEED2Ev:
  365|  4.83k|  ~GrowableArray() {}
_ZN4bssl5ArrayINS_10ALPSConfigEED2Ev:
  256|  4.83k|  ~Array() { Reset(); }
_ZN4bssl5ArrayINS_10ALPSConfigEE5ResetEv:
  278|  4.83k|  void Reset() { Reset(nullptr, 0); }
_ZN4bssl5ArrayINS_10ALPSConfigEE5ResetEPS1_m:
  282|  4.83k|  void Reset(T *new_data, size_t new_size) {
  283|  4.83k|    for (size_t i = 0; i < size_; i++) {
  ------------------
  |  Branch (283:24): [True: 0, False: 4.83k]
  ------------------
  284|      0|      data_[i].~T();
  285|      0|    }
  286|  4.83k|    OPENSSL_free(data_);
  287|  4.83k|    data_ = new_data;
  288|  4.83k|    size_ = new_size;
  289|  4.83k|  }
_ZN4bssl6DeleteI6ssl_stEEvPT_:
  207|  4.83k|void Delete(T *t) {
  208|  4.83k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 4.83k, False: 0]
  ------------------
  209|  4.83k|    t->~T();
  210|  4.83k|    OPENSSL_free(t);
  211|  4.83k|  }
  212|  4.83k|}
_ZN4bssl10MakeUniqueINS_9TicketKeyEJEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|    259|UniquePtr<T> MakeUnique(Args &&... args) {
  227|    259|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|    259|}
_ZN4bssl3NewINS_9TicketKeyEJEEEPT_DpOT0_:
  195|    259|T *New(Args &&... args) {
  196|    259|  void *t = OPENSSL_malloc(sizeof(T));
  197|    259|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 259]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|    259|  return new (t) T(std::forward<Args>(args)...);
  201|    259|}
_ZN4bssl8internal11DeleterImplINS_9TicketKeyEvE4FreeEPS2_:
  219|    259|  static void Free(T *t) { Delete(t); }
_ZN4bssl6DeleteINS_9TicketKeyEEEvPT_:
  207|    259|void Delete(T *t) {
  208|    259|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 259, False: 0]
  ------------------
  209|    259|    t->~T();
  210|    259|    OPENSSL_free(t);
  211|    259|  }
  212|    259|}
_ZN4bssl5ArrayItE6ShrinkEm:
  338|  4.16k|  void Shrink(size_t new_size) {
  339|  4.16k|    if (new_size > size_) {
  ------------------
  |  Branch (339:9): [True: 0, False: 4.16k]
  ------------------
  340|      0|      abort();
  341|      0|    }
  342|  4.43k|    for (size_t i = new_size; i < size_; i++) {
  ------------------
  |  Branch (342:31): [True: 271, False: 4.16k]
  ------------------
  343|    271|      data_[i].~T();
  344|    271|    }
  345|  4.16k|    size_ = new_size;
  346|  4.16k|  }
_ZN4bssl10MakeUniqueINS_10SSL3_STATEEJEEENSt3__110unique_ptrIT_NS_8internal7DeleterEEEDpOT0_:
  226|  4.83k|UniquePtr<T> MakeUnique(Args &&... args) {
  227|  4.83k|  return UniquePtr<T>(New<T>(std::forward<Args>(args)...));
  228|  4.83k|}
_ZN4bssl3NewINS_10SSL3_STATEEJEEEPT_DpOT0_:
  195|  4.83k|T *New(Args &&... args) {
  196|  4.83k|  void *t = OPENSSL_malloc(sizeof(T));
  197|  4.83k|  if (t == nullptr) {
  ------------------
  |  Branch (197:7): [True: 0, False: 4.83k]
  ------------------
  198|      0|    return nullptr;
  199|      0|  }
  200|  4.83k|  return new (t) T(std::forward<Args>(args)...);
  201|  4.83k|}
_ZN4bssl6DeleteINS_10SSL3_STATEEEEvPT_:
  207|  4.83k|void Delete(T *t) {
  208|  4.83k|  if (t != nullptr) {
  ------------------
  |  Branch (208:7): [True: 4.83k, False: 0]
  ------------------
  209|  4.83k|    t->~T();
  210|  4.83k|    OPENSSL_free(t);
  211|  4.83k|  }
  212|  4.83k|}

_ZN4bssl10SSL3_STATEC2Ev:
  182|  4.83k|      was_key_usage_invalid(false) {}
_ZN4bssl10SSL3_STATED2Ev:
  184|  4.83k|SSL3_STATE::~SSL3_STATE() {}
_ZN4bssl7tls_newEP6ssl_st:
  186|  4.83k|bool tls_new(SSL *ssl) {
  187|  4.83k|  UniquePtr<SSL3_STATE> s3 = MakeUnique<SSL3_STATE>();
  188|  4.83k|  if (!s3) {
  ------------------
  |  Branch (188:7): [True: 0, False: 4.83k]
  ------------------
  189|      0|    return false;
  190|      0|  }
  191|       |
  192|  4.83k|  s3->aead_read_ctx = SSLAEADContext::CreateNullCipher(SSL_is_dtls(ssl));
  193|  4.83k|  s3->aead_write_ctx = SSLAEADContext::CreateNullCipher(SSL_is_dtls(ssl));
  194|  4.83k|  s3->hs = ssl_handshake_new(ssl);
  195|  4.83k|  if (!s3->aead_read_ctx || !s3->aead_write_ctx || !s3->hs) {
  ------------------
  |  Branch (195:7): [True: 0, False: 4.83k]
  |  Branch (195:29): [True: 0, False: 4.83k]
  |  Branch (195:52): [True: 0, False: 4.83k]
  ------------------
  196|      0|    return false;
  197|      0|  }
  198|       |
  199|  4.83k|  ssl->s3 = s3.release();
  200|       |
  201|       |  // Set the version to the highest supported version.
  202|       |  //
  203|       |  // TODO(davidben): Move this field into |s3|, have it store the normalized
  204|       |  // protocol version, and implement this pre-negotiation quirk in |SSL_version|
  205|       |  // at the API boundary rather than in internal state.
  206|  4.83k|  ssl->version = TLS1_2_VERSION;
  ------------------
  |  |  647|  4.83k|#define TLS1_2_VERSION 0x0303
  ------------------
  207|  4.83k|  return true;
  208|  4.83k|}
_ZN4bssl8tls_freeEP6ssl_st:
  210|  4.83k|void tls_free(SSL *ssl) {
  211|  4.83k|  if (ssl == NULL || ssl->s3 == NULL) {
  ------------------
  |  Branch (211:7): [True: 0, False: 4.83k]
  |  Branch (211:22): [True: 0, False: 4.83k]
  ------------------
  212|      0|    return;
  213|      0|  }
  214|       |
  215|  4.83k|  Delete(ssl->s3);
  216|  4.83k|  ssl->s3 = NULL;
  217|  4.83k|}

_ZN4bssl14SSLAEADContextC2EtbPK13ssl_cipher_st:
   45|  9.66k|      ad_is_header_(false) {
   46|  9.66k|  OPENSSL_memset(fixed_nonce_, 0, sizeof(fixed_nonce_));
   47|  9.66k|}
_ZN4bssl14SSLAEADContextD2Ev:
   49|  9.66k|SSLAEADContext::~SSLAEADContext() {}
_ZN4bssl14SSLAEADContext16CreateNullCipherEb:
   51|  9.66k|UniquePtr<SSLAEADContext> SSLAEADContext::CreateNullCipher(bool is_dtls) {
   52|  9.66k|  return MakeUnique<SSLAEADContext>(0 /* version */, is_dtls,
   53|  9.66k|                                    nullptr /* cipher */);
   54|  9.66k|}

_ZN4bssl9SSLBuffer5ClearEv:
   39|  9.66k|void SSLBuffer::Clear() {
   40|  9.66k|  if (buf_allocated_) {
  ------------------
  |  Branch (40:7): [True: 0, False: 9.66k]
  ------------------
   41|      0|    free(buf_);  // Allocated with malloc().
   42|      0|  }
   43|  9.66k|  buf_ = nullptr;
   44|  9.66k|  buf_allocated_ = false;
   45|  9.66k|  offset_ = 0;
   46|  9.66k|  size_ = 0;
   47|  9.66k|  cap_ = 0;
   48|  9.66k|}

_ZN4bssl4CERTC2EPKNS_15SSL_X509_METHODE:
  138|  9.66k|    : x509_method(x509_method_arg) {}
_ZN4bssl4CERTD2Ev:
  140|  9.66k|CERT::~CERT() {
  141|  9.66k|  ssl_cert_clear_certs(this);
  142|  9.66k|  x509_method->cert_free(this);
  143|  9.66k|}
_ZN4bssl12ssl_cert_dupEPNS_4CERTE:
  150|  4.83k|UniquePtr<CERT> ssl_cert_dup(CERT *cert) {
  151|  4.83k|  UniquePtr<CERT> ret = MakeUnique<CERT>(cert->x509_method);
  152|  4.83k|  if (!ret) {
  ------------------
  |  Branch (152:7): [True: 0, False: 4.83k]
  ------------------
  153|      0|    return nullptr;
  154|      0|  }
  155|       |
  156|  4.83k|  if (cert->chain) {
  ------------------
  |  Branch (156:7): [True: 828, False: 4.00k]
  ------------------
  157|    828|    ret->chain.reset(sk_CRYPTO_BUFFER_deep_copy(
  158|    828|        cert->chain.get(), buffer_up_ref, CRYPTO_BUFFER_free));
  159|    828|    if (!ret->chain) {
  ------------------
  |  Branch (159:9): [True: 0, False: 828]
  ------------------
  160|      0|      return nullptr;
  161|      0|    }
  162|    828|  }
  163|       |
  164|  4.83k|  ret->privatekey = UpRef(cert->privatekey);
  165|  4.83k|  ret->key_method = cert->key_method;
  166|       |
  167|  4.83k|  if (!ret->sigalgs.CopyFrom(cert->sigalgs)) {
  ------------------
  |  Branch (167:7): [True: 0, False: 4.83k]
  ------------------
  168|      0|    return nullptr;
  169|      0|  }
  170|       |
  171|  4.83k|  ret->cert_cb = cert->cert_cb;
  172|  4.83k|  ret->cert_cb_arg = cert->cert_cb_arg;
  173|       |
  174|  4.83k|  ret->x509_method->cert_dup(ret.get(), cert);
  175|       |
  176|  4.83k|  ret->signed_cert_timestamp_list = UpRef(cert->signed_cert_timestamp_list);
  177|  4.83k|  ret->ocsp_response = UpRef(cert->ocsp_response);
  178|       |
  179|  4.83k|  ret->sid_ctx_length = cert->sid_ctx_length;
  180|  4.83k|  OPENSSL_memcpy(ret->sid_ctx, cert->sid_ctx, sizeof(ret->sid_ctx));
  181|       |
  182|  4.83k|  if (cert->dc) {
  ------------------
  |  Branch (182:7): [True: 0, False: 4.83k]
  ------------------
  183|      0|    ret->dc = cert->dc->Dup();
  184|      0|    if (!ret->dc) {
  ------------------
  |  Branch (184:9): [True: 0, False: 0]
  ------------------
  185|      0|       return nullptr;
  186|      0|    }
  187|      0|  }
  188|       |
  189|  4.83k|  ret->dc_privatekey = UpRef(cert->dc_privatekey);
  190|  4.83k|  ret->dc_key_method = cert->dc_key_method;
  191|       |
  192|  4.83k|  return ret;
  193|  4.83k|}
_ZN4bssl20ssl_cert_clear_certsEPNS_4CERTE:
  196|  9.66k|void ssl_cert_clear_certs(CERT *cert) {
  197|  9.66k|  if (cert == NULL) {
  ------------------
  |  Branch (197:7): [True: 0, False: 9.66k]
  ------------------
  198|      0|    return;
  199|      0|  }
  200|       |
  201|  9.66k|  cert->x509_method->cert_clear(cert);
  202|       |
  203|  9.66k|  cert->chain.reset();
  204|  9.66k|  cert->privatekey.reset();
  205|  9.66k|  cert->key_method = nullptr;
  206|       |
  207|  9.66k|  cert->dc.reset();
  208|  9.66k|  cert->dc_privatekey.reset();
  209|  9.66k|  cert->dc_key_method = nullptr;
  210|  9.66k|}
_ZN4bssl12ssl_set_certEPNS_4CERTENSt3__110unique_ptrI16crypto_buffer_stNS_8internal7DeleterEEE:
  305|  12.9k|bool ssl_set_cert(CERT *cert, UniquePtr<CRYPTO_BUFFER> buffer) {
  306|  12.9k|  switch (check_leaf_cert_and_privkey(buffer.get(), cert->privatekey.get())) {
  ------------------
  |  Branch (306:11): [True: 0, False: 12.9k]
  ------------------
  307|      0|    case leaf_cert_and_privkey_error:
  ------------------
  |  Branch (307:5): [True: 0, False: 12.9k]
  ------------------
  308|      0|      return false;
  309|      0|    case leaf_cert_and_privkey_mismatch:
  ------------------
  |  Branch (309:5): [True: 0, False: 12.9k]
  ------------------
  310|       |      // don't fail for a cert/key mismatch, just free current private key
  311|       |      // (when switching to a different cert & key, first this function should
  312|       |      // be used, then |ssl_set_pkey|.
  313|      0|      cert->privatekey.reset();
  314|      0|      break;
  315|  12.9k|    case leaf_cert_and_privkey_ok:
  ------------------
  |  Branch (315:5): [True: 12.9k, False: 0]
  ------------------
  316|  12.9k|      break;
  317|  12.9k|  }
  318|       |
  319|  12.9k|  cert->x509_method->cert_flush_cached_leaf(cert);
  320|       |
  321|  12.9k|  if (cert->chain != nullptr) {
  ------------------
  |  Branch (321:7): [True: 12.6k, False: 214]
  ------------------
  322|  12.6k|    CRYPTO_BUFFER_free(sk_CRYPTO_BUFFER_value(cert->chain.get(), 0));
  323|  12.6k|    sk_CRYPTO_BUFFER_set(cert->chain.get(), 0, buffer.release());
  324|  12.6k|    return true;
  325|  12.6k|  }
  326|       |
  327|    214|  cert->chain.reset(sk_CRYPTO_BUFFER_new_null());
  328|    214|  if (cert->chain == nullptr) {
  ------------------
  |  Branch (328:7): [True: 0, False: 214]
  ------------------
  329|      0|    return false;
  330|      0|  }
  331|       |
  332|    214|  if (!PushToStack(cert->chain.get(), std::move(buffer))) {
  ------------------
  |  Branch (332:7): [True: 0, False: 214]
  ------------------
  333|      0|    cert->chain.reset();
  334|      0|    return false;
  335|      0|  }
  336|       |
  337|    214|  return true;
  338|    214|}
_ZN4bssl21ssl_cert_parse_pubkeyEPK6cbs_st:
  480|  22.7k|UniquePtr<EVP_PKEY> ssl_cert_parse_pubkey(const CBS *in) {
  481|  22.7k|  CBS buf = *in, tbs_cert;
  482|  22.7k|  if (!ssl_cert_skip_to_spki(&buf, &tbs_cert)) {
  ------------------
  |  Branch (482:7): [True: 0, False: 22.7k]
  ------------------
  483|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_CANNOT_PARSE_LEAF_CERT);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  484|      0|    return nullptr;
  485|      0|  }
  486|       |
  487|  22.7k|  return UniquePtr<EVP_PKEY>(EVP_parse_public_key(&tbs_cert));
  488|  22.7k|}
_ZN4bssl34ssl_compare_public_and_private_keyEPK11evp_pkey_stS2_:
  491|  14.7k|                                        const EVP_PKEY *privkey) {
  492|  14.7k|  if (EVP_PKEY_is_opaque(privkey)) {
  ------------------
  |  Branch (492:7): [True: 0, False: 14.7k]
  ------------------
  493|       |    // We cannot check an opaque private key and have to trust that it
  494|       |    // matches.
  495|      0|    return true;
  496|      0|  }
  497|       |
  498|  14.7k|  switch (EVP_PKEY_cmp(pubkey, privkey)) {
  ------------------
  |  Branch (498:11): [True: 0, False: 14.7k]
  ------------------
  499|  14.7k|    case 1:
  ------------------
  |  Branch (499:5): [True: 14.7k, False: 0]
  ------------------
  500|  14.7k|      return true;
  501|      0|    case 0:
  ------------------
  |  Branch (501:5): [True: 0, False: 14.7k]
  ------------------
  502|      0|      OPENSSL_PUT_ERROR(X509, X509_R_KEY_VALUES_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  503|      0|      return false;
  504|      0|    case -1:
  ------------------
  |  Branch (504:5): [True: 0, False: 14.7k]
  ------------------
  505|      0|      OPENSSL_PUT_ERROR(X509, X509_R_KEY_TYPE_MISMATCH);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  506|      0|      return false;
  507|      0|    case -2:
  ------------------
  |  Branch (507:5): [True: 0, False: 14.7k]
  ------------------
  508|      0|      OPENSSL_PUT_ERROR(X509, X509_R_UNKNOWN_KEY_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  509|      0|      return false;
  510|  14.7k|  }
  511|       |
  512|      0|  assert(0);
  513|      0|  return false;
  514|  14.7k|}
_ZN4bssl26ssl_cert_check_private_keyEPKNS_4CERTEPK11evp_pkey_st:
  516|  13.3k|bool ssl_cert_check_private_key(const CERT *cert, const EVP_PKEY *privkey) {
  517|  13.3k|  if (privkey == nullptr) {
  ------------------
  |  Branch (517:7): [True: 2.68k, False: 10.6k]
  ------------------
  518|  2.68k|    OPENSSL_PUT_ERROR(SSL, SSL_R_NO_PRIVATE_KEY_ASSIGNED);
  ------------------
  |  |  441|  2.68k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  519|  2.68k|    return false;
  520|  2.68k|  }
  521|       |
  522|  10.6k|  if (cert->chain == nullptr ||
  ------------------
  |  Branch (522:7): [True: 328, False: 10.3k]
  ------------------
  523|  10.6k|      sk_CRYPTO_BUFFER_value(cert->chain.get(), 0) == nullptr) {
  ------------------
  |  Branch (523:7): [True: 479, False: 9.83k]
  ------------------
  524|    807|    OPENSSL_PUT_ERROR(SSL, SSL_R_NO_CERTIFICATE_ASSIGNED);
  ------------------
  |  |  441|    807|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  525|    807|    return false;
  526|    807|  }
  527|       |
  528|  9.83k|  CBS cert_cbs;
  529|  9.83k|  CRYPTO_BUFFER_init_CBS(sk_CRYPTO_BUFFER_value(cert->chain.get(), 0),
  530|  9.83k|                         &cert_cbs);
  531|  9.83k|  UniquePtr<EVP_PKEY> pubkey = ssl_cert_parse_pubkey(&cert_cbs);
  532|  9.83k|  if (!pubkey) {
  ------------------
  |  Branch (532:7): [True: 0, False: 9.83k]
  ------------------
  533|      0|    OPENSSL_PUT_ERROR(X509, X509_R_UNKNOWN_KEY_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  534|      0|    return false;
  535|      0|  }
  536|       |
  537|  9.83k|  return ssl_compare_public_and_private_key(pubkey.get(), privkey);
  538|  9.83k|}
SSL_CTX_set_signed_cert_timestamp_list:
  956|  2.95k|                                           size_t list_len) {
  957|  2.95k|  return set_signed_cert_timestamp_list(ctx->cert.get(), list, list_len);
  958|  2.95k|}
SSL_CTX_set_ocsp_response:
  970|  18.5k|                              size_t response_len) {
  971|  18.5k|  ctx->cert->ocsp_response.reset(
  972|  18.5k|      CRYPTO_BUFFER_new(response, response_len, nullptr));
  973|  18.5k|  return ctx->cert->ocsp_response != nullptr;
  974|  18.5k|}
ssl_cert.cc:_ZN4bsslL13buffer_up_refEPK16crypto_buffer_st:
  145|  4.82k|static CRYPTO_BUFFER *buffer_up_ref(const CRYPTO_BUFFER *buffer) {
  146|  4.82k|  CRYPTO_BUFFER_up_ref(const_cast<CRYPTO_BUFFER *>(buffer));
  147|  4.82k|  return const_cast<CRYPTO_BUFFER *>(buffer);
  148|  4.82k|}
ssl_cert.cc:_ZN4bsslL27check_leaf_cert_and_privkeyEP16crypto_buffer_stP11evp_pkey_st:
  231|  12.9k|    CRYPTO_BUFFER *leaf_buffer, EVP_PKEY *privkey) {
  232|  12.9k|  CBS cert_cbs;
  233|  12.9k|  CRYPTO_BUFFER_init_CBS(leaf_buffer, &cert_cbs);
  234|  12.9k|  UniquePtr<EVP_PKEY> pubkey = ssl_cert_parse_pubkey(&cert_cbs);
  235|  12.9k|  if (!pubkey) {
  ------------------
  |  Branch (235:7): [True: 0, False: 12.9k]
  ------------------
  236|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_DECODE_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  237|      0|    return leaf_cert_and_privkey_error;
  238|      0|  }
  239|       |
  240|  12.9k|  if (!ssl_is_key_type_supported(EVP_PKEY_id(pubkey.get()))) {
  ------------------
  |  Branch (240:7): [True: 0, False: 12.9k]
  ------------------
  241|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_UNKNOWN_CERTIFICATE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  242|      0|    return leaf_cert_and_privkey_error;
  243|      0|  }
  244|       |
  245|       |  // An ECC certificate may be usable for ECDH or ECDSA. We only support ECDSA
  246|       |  // certificates, so sanity-check the key usage extension.
  247|  12.9k|  if (EVP_PKEY_id(pubkey.get()) == EVP_PKEY_EC &&
  ------------------
  |  |  178|  12.9k|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|  25.8k|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (247:7): [True: 0, False: 12.9k]
  ------------------
  248|  12.9k|      !ssl_cert_check_key_usage(&cert_cbs, key_usage_digital_signature)) {
  ------------------
  |  Branch (248:7): [True: 0, False: 0]
  ------------------
  249|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_UNKNOWN_CERTIFICATE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  250|      0|    return leaf_cert_and_privkey_error;
  251|      0|  }
  252|       |
  253|  12.9k|  if (privkey != NULL &&
  ------------------
  |  Branch (253:7): [True: 4.94k, False: 7.95k]
  ------------------
  254|       |      // Sanity-check that the private key and the certificate match.
  255|  12.9k|      !ssl_compare_public_and_private_key(pubkey.get(), privkey)) {
  ------------------
  |  Branch (255:7): [True: 0, False: 4.94k]
  ------------------
  256|      0|    ERR_clear_error();
  257|      0|    return leaf_cert_and_privkey_mismatch;
  258|      0|  }
  259|       |
  260|  12.9k|  return leaf_cert_and_privkey_ok;
  261|  12.9k|}
ssl_cert.cc:_ZN4bsslL21ssl_cert_skip_to_spkiEPK6cbs_stPS0_:
  438|  22.7k|static bool ssl_cert_skip_to_spki(const CBS *in, CBS *out_tbs_cert) {
  439|       |  /* From RFC 5280, section 4.1
  440|       |   *    Certificate  ::=  SEQUENCE  {
  441|       |   *      tbsCertificate       TBSCertificate,
  442|       |   *      signatureAlgorithm   AlgorithmIdentifier,
  443|       |   *      signatureValue       BIT STRING  }
  444|       |
  445|       |   * TBSCertificate  ::=  SEQUENCE  {
  446|       |   *      version         [0]  EXPLICIT Version DEFAULT v1,
  447|       |   *      serialNumber         CertificateSerialNumber,
  448|       |   *      signature            AlgorithmIdentifier,
  449|       |   *      issuer               Name,
  450|       |   *      validity             Validity,
  451|       |   *      subject              Name,
  452|       |   *      subjectPublicKeyInfo SubjectPublicKeyInfo,
  453|       |   *      ... } */
  454|  22.7k|  CBS buf = *in;
  455|       |
  456|  22.7k|  CBS toplevel;
  457|  22.7k|  if (!CBS_get_asn1(&buf, &toplevel, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (457:7): [True: 0, False: 22.7k]
  ------------------
  458|  22.7k|      CBS_len(&buf) != 0 ||
  ------------------
  |  Branch (458:7): [True: 0, False: 22.7k]
  ------------------
  459|  22.7k|      !CBS_get_asn1(&toplevel, out_tbs_cert, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (459:7): [True: 0, False: 22.7k]
  ------------------
  460|       |      // version
  461|  22.7k|      !CBS_get_optional_asn1(
  ------------------
  |  Branch (461:7): [True: 0, False: 22.7k]
  ------------------
  462|  22.7k|          out_tbs_cert, NULL, NULL,
  463|  22.7k|          CBS_ASN1_CONSTRUCTED | CBS_ASN1_CONTEXT_SPECIFIC | 0) ||
  ------------------
  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
                        CBS_ASN1_CONSTRUCTED | CBS_ASN1_CONTEXT_SPECIFIC | 0) ||
  ------------------
  |  |  202|  22.7k|#define CBS_ASN1_CONTEXT_SPECIFIC (0x80u << CBS_ASN1_TAG_SHIFT)
  |  |  ------------------
  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  ------------------
  ------------------
  464|       |      // serialNumber
  465|  22.7k|      !CBS_get_asn1(out_tbs_cert, NULL, CBS_ASN1_INTEGER) ||
  ------------------
  |  |  215|  22.7k|#define CBS_ASN1_INTEGER 0x2u
  ------------------
  |  Branch (465:7): [True: 0, False: 22.7k]
  ------------------
  466|       |      // signature algorithm
  467|  22.7k|      !CBS_get_asn1(out_tbs_cert, NULL, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (467:7): [True: 0, False: 22.7k]
  ------------------
  468|       |      // issuer
  469|  22.7k|      !CBS_get_asn1(out_tbs_cert, NULL, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (469:7): [True: 0, False: 22.7k]
  ------------------
  470|       |      // validity
  471|  22.7k|      !CBS_get_asn1(out_tbs_cert, NULL, CBS_ASN1_SEQUENCE) ||
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (471:7): [True: 0, False: 22.7k]
  ------------------
  472|       |      // subject
  473|  22.7k|      !CBS_get_asn1(out_tbs_cert, NULL, CBS_ASN1_SEQUENCE)) {
  ------------------
  |  |  222|  22.7k|#define CBS_ASN1_SEQUENCE (0x10u | CBS_ASN1_CONSTRUCTED)
  |  |  ------------------
  |  |  |  |  196|  22.7k|#define CBS_ASN1_CONSTRUCTED (0x20u << CBS_ASN1_TAG_SHIFT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  193|  22.7k|#define CBS_ASN1_TAG_SHIFT 24
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (473:7): [True: 0, False: 22.7k]
  ------------------
  474|      0|    return false;
  475|      0|  }
  476|       |
  477|  22.7k|  return true;
  478|  22.7k|}
ssl_cert.cc:_ZL30set_signed_cert_timestamp_listPN4bssl4CERTEPKhm:
  942|  2.95k|                                          size_t list_len) {
  943|  2.95k|  CBS sct_list;
  944|  2.95k|  CBS_init(&sct_list, list, list_len);
  945|  2.95k|  if (!ssl_is_sct_list_valid(&sct_list)) {
  ------------------
  |  Branch (945:7): [True: 2.42k, False: 533]
  ------------------
  946|  2.42k|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SCT_LIST);
  ------------------
  |  |  441|  2.42k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  947|  2.42k|    return 0;
  948|  2.42k|  }
  949|       |
  950|    533|  cert->signed_cert_timestamp_list.reset(
  951|    533|      CRYPTO_BUFFER_new(CBS_data(&sct_list), CBS_len(&sct_list), nullptr));
  952|    533|  return cert->signed_cert_timestamp_list != nullptr;
  953|  2.95k|}

_ZN4bssl23SSLCipherPreferenceListD2Ev:
  729|  22.7k|SSLCipherPreferenceList::~SSLCipherPreferenceList() {
  730|  22.7k|  OPENSSL_free(in_group_flags);
  731|  22.7k|}
_ZN4bssl23SSLCipherPreferenceList4InitENSt3__110unique_ptrI19stack_st_SSL_CIPHERNS_8internal7DeleterEEENS_4SpanIKbEE:
  734|  22.7k|                                   Span<const bool> in_group_flags_arg) {
  735|  22.7k|  if (sk_SSL_CIPHER_num(ciphers_arg.get()) != in_group_flags_arg.size()) {
  ------------------
  |  Branch (735:7): [True: 0, False: 22.7k]
  ------------------
  736|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  737|      0|    return false;
  738|      0|  }
  739|       |
  740|  22.7k|  Array<bool> copy;
  741|  22.7k|  if (!copy.CopyFrom(in_group_flags_arg)) {
  ------------------
  |  Branch (741:7): [True: 0, False: 22.7k]
  ------------------
  742|      0|    return false;
  743|      0|  }
  744|  22.7k|  ciphers = std::move(ciphers_arg);
  745|  22.7k|  size_t unused_len;
  746|  22.7k|  copy.Release(&in_group_flags, &unused_len);
  747|  22.7k|  return true;
  748|  22.7k|}
_ZN4bssl24ssl_cipher_is_deprecatedEPK13ssl_cipher_st:
  775|   251k|bool ssl_cipher_is_deprecated(const SSL_CIPHER *cipher) {
  776|   251k|  return cipher->id == TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ||
  ------------------
  |  |  411|   502k|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0x0300C027
  ------------------
  |  Branch (776:10): [True: 11.8k, False: 239k]
  ------------------
  777|   251k|         cipher->algorithm_enc == SSL_3DES;
  ------------------
  |  |  566|   239k|#define SSL_3DES 0x00000001u
  ------------------
  |  Branch (777:10): [True: 11.5k, False: 227k]
  ------------------
  778|   251k|}
_ZN4bssl22ssl_create_cipher_listEPNSt3__110unique_ptrINS_23SSLCipherPreferenceListENS_8internal7DeleterEEEbPKcb:
 1136|  32.2k|                            bool strict) {
 1137|       |  // Return with error if nothing to do.
 1138|  32.2k|  if (rule_str == NULL || out_cipher_list == NULL) {
  ------------------
  |  Branch (1138:7): [True: 0, False: 32.2k]
  |  Branch (1138:27): [True: 0, False: 32.2k]
  ------------------
 1139|      0|    return false;
 1140|      0|  }
 1141|       |
 1142|       |  // We prefer ECDHE ciphers over non-PFS ciphers. Then we prefer AEAD over
 1143|       |  // non-AEAD. The constants are masked by 0xffff to remove the vestigial 0x03
 1144|       |  // byte from SSL 2.0.
 1145|  32.2k|  static const uint16_t kAESCiphers[] = {
 1146|  32.2k|      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 & 0xffff,
  ------------------
  |  |  442|  32.2k|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0x0300C02B
  ------------------
 1147|  32.2k|      TLS1_CK_ECDHE_RSA_WITH_AES_128_GCM_SHA256 & 0xffff,
  ------------------
  |  |  446|  32.2k|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0x0300C02F
  ------------------
 1148|  32.2k|      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 & 0xffff,
  ------------------
  |  |  443|  32.2k|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0x0300C02C
  ------------------
 1149|  32.2k|      TLS1_CK_ECDHE_RSA_WITH_AES_256_GCM_SHA384 & 0xffff,
  ------------------
  |  |  447|  32.2k|#define TLS1_CK_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0x0300C030
  ------------------
 1150|  32.2k|  };
 1151|  32.2k|  static const uint16_t kChaChaCiphers[] = {
 1152|  32.2k|      TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 & 0xffff,
  ------------------
  |  |  453|  32.2k|#define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 0x0300CCA9
  ------------------
 1153|  32.2k|      TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 & 0xffff,
  ------------------
  |  |  452|  32.2k|#define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 0x0300CCA8
  ------------------
 1154|  32.2k|      TLS1_CK_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 & 0xffff,
  ------------------
  |  |  454|  32.2k|#define TLS1_CK_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 0x0300CCAC
  ------------------
 1155|  32.2k|  };
 1156|  32.2k|  static const uint16_t kLegacyCiphers[] = {
 1157|  32.2k|      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  396|  32.2k|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_128_CBC_SHA 0x0300C009
  ------------------
 1158|  32.2k|      TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  408|  32.2k|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA 0x0300C013
  ------------------
 1159|  32.2k|      TLS1_CK_ECDHE_PSK_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  299|  32.2k|#define TLS1_CK_ECDHE_PSK_WITH_AES_128_CBC_SHA          0x0300C035
  ------------------
 1160|  32.2k|      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  397|  32.2k|#define TLS1_CK_ECDHE_ECDSA_WITH_AES_256_CBC_SHA 0x0300C00A
  ------------------
 1161|  32.2k|      TLS1_CK_ECDHE_RSA_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  409|  32.2k|#define TLS1_CK_ECDHE_RSA_WITH_AES_256_CBC_SHA 0x0300C014
  ------------------
 1162|  32.2k|      TLS1_CK_ECDHE_PSK_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  300|  32.2k|#define TLS1_CK_ECDHE_PSK_WITH_AES_256_CBC_SHA          0x0300C036
  ------------------
 1163|  32.2k|      TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 & 0xffff,
  ------------------
  |  |  411|  32.2k|#define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0x0300C027
  ------------------
 1164|  32.2k|      TLS1_CK_RSA_WITH_AES_128_GCM_SHA256 & 0xffff,
  ------------------
  |  |  373|  32.2k|#define TLS1_CK_RSA_WITH_AES_128_GCM_SHA256 0x0300009C
  ------------------
 1165|  32.2k|      TLS1_CK_RSA_WITH_AES_256_GCM_SHA384 & 0xffff,
  ------------------
  |  |  374|  32.2k|#define TLS1_CK_RSA_WITH_AES_256_GCM_SHA384 0x0300009D
  ------------------
 1166|  32.2k|      TLS1_CK_RSA_WITH_AES_128_SHA & 0xffff,
  ------------------
  |  |  317|  32.2k|#define TLS1_CK_RSA_WITH_AES_128_SHA 0x0300002F
  ------------------
 1167|  32.2k|      TLS1_CK_PSK_WITH_AES_128_CBC_SHA & 0xffff,
  ------------------
  |  |  295|  32.2k|#define TLS1_CK_PSK_WITH_AES_128_CBC_SHA                0x0300008C
  ------------------
 1168|  32.2k|      TLS1_CK_RSA_WITH_AES_256_SHA & 0xffff,
  ------------------
  |  |  324|  32.2k|#define TLS1_CK_RSA_WITH_AES_256_SHA 0x03000035
  ------------------
 1169|  32.2k|      TLS1_CK_PSK_WITH_AES_256_CBC_SHA & 0xffff,
  ------------------
  |  |  296|  32.2k|#define TLS1_CK_PSK_WITH_AES_256_CBC_SHA                0x0300008D
  ------------------
 1170|  32.2k|      SSL3_CK_RSA_DES_192_CBC3_SHA & 0xffff,
  ------------------
  |  |  145|  32.2k|#define SSL3_CK_RSA_DES_192_CBC3_SHA 0x0300000A
  ------------------
 1171|  32.2k|  };
 1172|       |
 1173|       |  // Set up a linked list of ciphers.
 1174|  32.2k|  CIPHER_ORDER co_list[OPENSSL_ARRAY_SIZE(kAESCiphers) +
 1175|  32.2k|                       OPENSSL_ARRAY_SIZE(kChaChaCiphers) +
 1176|  32.2k|                       OPENSSL_ARRAY_SIZE(kLegacyCiphers)];
 1177|   710k|  for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(co_list); i++) {
  ------------------
  |  |  221|   710k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1177:22): [True: 677k, False: 32.2k]
  ------------------
 1178|   677k|    co_list[i].next =
 1179|   677k|        i + 1 < OPENSSL_ARRAY_SIZE(co_list) ? &co_list[i + 1] : nullptr;
  ------------------
  |  |  221|   677k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1179:9): [True: 645k, False: 32.2k]
  ------------------
 1180|   677k|    co_list[i].prev = i == 0 ? nullptr : &co_list[i - 1];
  ------------------
  |  Branch (1180:23): [True: 32.2k, False: 645k]
  ------------------
 1181|   677k|    co_list[i].active = false;
 1182|   677k|    co_list[i].in_group = false;
 1183|   677k|  }
 1184|  32.2k|  CIPHER_ORDER *head = &co_list[0];
 1185|  32.2k|  CIPHER_ORDER *tail = &co_list[OPENSSL_ARRAY_SIZE(co_list) - 1];
  ------------------
  |  |  221|  32.2k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
 1186|       |
 1187|       |  // Order AES ciphers vs ChaCha ciphers based on whether we have AES hardware.
 1188|       |  //
 1189|       |  // TODO(crbug.com/boringssl/29): We should also set up equipreference groups
 1190|       |  // as a server.
 1191|  32.2k|  size_t num = 0;
 1192|  32.2k|  if (has_aes_hw) {
  ------------------
  |  Branch (1192:7): [True: 32.2k, False: 0]
  ------------------
 1193|   129k|    for (uint16_t id : kAESCiphers) {
  ------------------
  |  Branch (1193:22): [True: 129k, False: 32.2k]
  ------------------
 1194|   129k|      co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1195|   129k|      assert(co_list[num - 1].cipher != nullptr);
 1196|   129k|    }
 1197|  32.2k|  }
 1198|  96.8k|  for (uint16_t id : kChaChaCiphers) {
  ------------------
  |  Branch (1198:20): [True: 96.8k, False: 32.2k]
  ------------------
 1199|  96.8k|    co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1200|  96.8k|    assert(co_list[num - 1].cipher != nullptr);
 1201|  96.8k|  }
 1202|  32.2k|  if (!has_aes_hw) {
  ------------------
  |  Branch (1202:7): [True: 0, False: 32.2k]
  ------------------
 1203|      0|    for (uint16_t id : kAESCiphers) {
  ------------------
  |  Branch (1203:22): [True: 0, False: 0]
  ------------------
 1204|      0|      co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1205|      0|      assert(co_list[num - 1].cipher != nullptr);
 1206|      0|    }
 1207|      0|  }
 1208|   451k|  for (uint16_t id : kLegacyCiphers) {
  ------------------
  |  Branch (1208:20): [True: 451k, False: 32.2k]
  ------------------
 1209|   451k|    co_list[num++].cipher = SSL_get_cipher_by_value(id);
 1210|   451k|    assert(co_list[num - 1].cipher != nullptr);
 1211|   451k|  }
 1212|  32.2k|  assert(num == OPENSSL_ARRAY_SIZE(co_list));
 1213|      0|  static_assert(OPENSSL_ARRAY_SIZE(co_list) + NumTLS13Ciphers() ==
 1214|  32.2k|                    OPENSSL_ARRAY_SIZE(kCiphers),
 1215|  32.2k|                "Not all ciphers are included in the cipher order");
 1216|       |
 1217|       |  // If the rule_string begins with DEFAULT, apply the default rule before
 1218|       |  // using the (possibly available) additional rules.
 1219|  32.2k|  const char *rule_p = rule_str;
 1220|  32.2k|  if (strncmp(rule_str, "DEFAULT", 7) == 0) {
  ------------------
  |  Branch (1220:7): [True: 4.39k, False: 27.8k]
  ------------------
 1221|  4.39k|    if (!ssl_cipher_process_rulestr(SSL_DEFAULT_CIPHER_LIST, &head, &tail,
  ------------------
  |  | 1541|  4.39k|#define SSL_DEFAULT_CIPHER_LIST "ALL"
  ------------------
  |  Branch (1221:9): [True: 0, False: 4.39k]
  ------------------
 1222|  4.39k|                                    strict)) {
 1223|      0|      return false;
 1224|      0|    }
 1225|  4.39k|    rule_p += 7;
 1226|  4.39k|    if (*rule_p == ':') {
  ------------------
  |  Branch (1226:9): [True: 504, False: 3.88k]
  ------------------
 1227|    504|      rule_p++;
 1228|    504|    }
 1229|  4.39k|  }
 1230|       |
 1231|  32.2k|  if (*rule_p != '\0' &&
  ------------------
  |  Branch (1231:7): [True: 21.4k, False: 10.8k]
  ------------------
 1232|  32.2k|      !ssl_cipher_process_rulestr(rule_p, &head, &tail, strict)) {
  ------------------
  |  Branch (1232:7): [True: 9.55k, False: 11.8k]
  ------------------
 1233|  9.55k|    return false;
 1234|  9.55k|  }
 1235|       |
 1236|       |  // Allocate new "cipherstack" for the result, return with error
 1237|       |  // if we cannot get one.
 1238|  22.7k|  UniquePtr<STACK_OF(SSL_CIPHER)> cipherstack(sk_SSL_CIPHER_new_null());
 1239|  22.7k|  Array<bool> in_group_flags;
 1240|  22.7k|  if (cipherstack == nullptr ||
  ------------------
  |  Branch (1240:7): [True: 0, False: 22.7k]
  ------------------
 1241|  22.7k|      !in_group_flags.Init(OPENSSL_ARRAY_SIZE(kCiphers))) {
  ------------------
  |  |  221|  22.7k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1241:7): [True: 0, False: 22.7k]
  ------------------
 1242|      0|    return false;
 1243|      0|  }
 1244|       |
 1245|       |  // The cipher selection for the list is done. The ciphers are added
 1246|       |  // to the resulting precedence to the STACK_OF(SSL_CIPHER).
 1247|  22.7k|  size_t num_in_group_flags = 0;
 1248|   482k|  for (CIPHER_ORDER *curr = head; curr != NULL; curr = curr->next) {
  ------------------
  |  Branch (1248:35): [True: 459k, False: 22.7k]
  ------------------
 1249|   459k|    if (curr->active) {
  ------------------
  |  Branch (1249:9): [True: 200k, False: 259k]
  ------------------
 1250|   200k|      if (!sk_SSL_CIPHER_push(cipherstack.get(), curr->cipher)) {
  ------------------
  |  Branch (1250:11): [True: 0, False: 200k]
  ------------------
 1251|      0|        return false;
 1252|      0|      }
 1253|   200k|      in_group_flags[num_in_group_flags++] = curr->in_group;
 1254|   200k|    }
 1255|   459k|  }
 1256|       |
 1257|  22.7k|  UniquePtr<SSLCipherPreferenceList> pref_list =
 1258|  22.7k|      MakeUnique<SSLCipherPreferenceList>();
 1259|  22.7k|  if (!pref_list ||
  ------------------
  |  Branch (1259:7): [True: 0, False: 22.7k]
  |  Branch (1259:7): [True: 0, False: 22.7k]
  ------------------
 1260|  22.7k|      !pref_list->Init(
  ------------------
  |  Branch (1260:7): [True: 0, False: 22.7k]
  ------------------
 1261|  22.7k|          std::move(cipherstack),
 1262|  22.7k|          MakeConstSpan(in_group_flags).subspan(0, num_in_group_flags))) {
 1263|      0|    return false;
 1264|      0|  }
 1265|       |
 1266|  22.7k|  *out_cipher_list = std::move(pref_list);
 1267|       |
 1268|       |  // Configuring an empty cipher list is an error but still updates the
 1269|       |  // output.
 1270|  22.7k|  if (sk_SSL_CIPHER_num((*out_cipher_list)->ciphers.get()) == 0) {
  ------------------
  |  Branch (1270:7): [True: 10.4k, False: 12.3k]
  ------------------
 1271|  10.4k|    OPENSSL_PUT_ERROR(SSL, SSL_R_NO_CIPHER_MATCH);
  ------------------
  |  |  441|  10.4k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1272|  10.4k|    return false;
 1273|  10.4k|  }
 1274|       |
 1275|  12.3k|  return true;
 1276|  22.7k|}
SSL_get_cipher_by_value:
 1355|   677k|const SSL_CIPHER *SSL_get_cipher_by_value(uint16_t value) {
 1356|   677k|  SSL_CIPHER c;
 1357|       |
 1358|   677k|  c.id = 0x03000000L | value;
 1359|   677k|  return reinterpret_cast<const SSL_CIPHER *>(bsearch(
 1360|   677k|      &c, kCiphers, OPENSSL_ARRAY_SIZE(kCiphers), sizeof(SSL_CIPHER),
  ------------------
  |  |  221|   677k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
 1361|   677k|      ssl_cipher_id_cmp_void));
 1362|   677k|}
SSL_CIPHER_get_min_version:
 1456|  17.5k|uint16_t SSL_CIPHER_get_min_version(const SSL_CIPHER *cipher) {
 1457|  17.5k|  if (cipher->algorithm_mkey == SSL_kGENERIC ||
  ------------------
  |  |  554|  35.0k|#define SSL_kGENERIC 0x00000008u
  ------------------
  |  Branch (1457:7): [True: 0, False: 17.5k]
  ------------------
 1458|  17.5k|      cipher->algorithm_auth == SSL_aGENERIC) {
  ------------------
  |  |  561|  17.5k|#define SSL_aGENERIC 0x00000008u
  ------------------
  |  Branch (1458:7): [True: 0, False: 17.5k]
  ------------------
 1459|      0|    return TLS1_3_VERSION;
  ------------------
  |  |  648|      0|#define TLS1_3_VERSION 0x0304
  ------------------
 1460|      0|  }
 1461|       |
 1462|  17.5k|  if (cipher->algorithm_prf != SSL_HANDSHAKE_MAC_DEFAULT) {
  ------------------
  |  |  582|  17.5k|#define SSL_HANDSHAKE_MAC_DEFAULT 0x1
  ------------------
  |  Branch (1462:7): [True: 9.55k, False: 7.95k]
  ------------------
 1463|       |    // Cipher suites before TLS 1.2 use the default PRF, while all those added
 1464|       |    // afterwards specify a particular hash.
 1465|  9.55k|    return TLS1_2_VERSION;
  ------------------
  |  |  647|  9.55k|#define TLS1_2_VERSION 0x0303
  ------------------
 1466|  9.55k|  }
 1467|  7.95k|  return SSL3_VERSION;
  ------------------
  |  |  644|  7.95k|#define SSL3_VERSION 0x0300
  ------------------
 1468|  17.5k|}
SSL_CIPHER_get_bits:
 1529|   259k|int SSL_CIPHER_get_bits(const SSL_CIPHER *cipher, int *out_alg_bits) {
 1530|   259k|  if (cipher == NULL) {
  ------------------
  |  Branch (1530:7): [True: 0, False: 259k]
  ------------------
 1531|      0|    return 0;
 1532|      0|  }
 1533|       |
 1534|   259k|  int alg_bits, strength_bits;
 1535|   259k|  switch (cipher->algorithm_enc) {
 1536|  69.5k|    case SSL_AES128:
  ------------------
  |  |  567|  69.5k|#define SSL_AES128 0x00000002u
  ------------------
  |  Branch (1536:5): [True: 69.5k, False: 189k]
  ------------------
 1537|   107k|    case SSL_AES128GCM:
  ------------------
  |  |  569|   107k|#define SSL_AES128GCM 0x00000008u
  ------------------
  |  Branch (1537:5): [True: 38.4k, False: 220k]
  ------------------
 1538|   107k|      alg_bits = 128;
 1539|   107k|      strength_bits = 128;
 1540|   107k|      break;
 1541|       |
 1542|  62.7k|    case SSL_AES256:
  ------------------
  |  |  568|  62.7k|#define SSL_AES256 0x00000004u
  ------------------
  |  Branch (1542:5): [True: 62.7k, False: 196k]
  ------------------
 1543|   102k|    case SSL_AES256GCM:
  ------------------
  |  |  570|   102k|#define SSL_AES256GCM 0x00000010u
  ------------------
  |  Branch (1543:5): [True: 39.9k, False: 219k]
  ------------------
 1544|   142k|    case SSL_CHACHA20POLY1305:
  ------------------
  |  |  571|   142k|#define SSL_CHACHA20POLY1305 0x00000020u
  ------------------
  |  Branch (1544:5): [True: 39.5k, False: 219k]
  ------------------
 1545|   142k|      alg_bits = 256;
 1546|   142k|      strength_bits = 256;
 1547|   142k|      break;
 1548|       |
 1549|  8.96k|    case SSL_3DES:
  ------------------
  |  |  566|  8.96k|#define SSL_3DES 0x00000001u
  ------------------
  |  Branch (1549:5): [True: 8.96k, False: 250k]
  ------------------
 1550|  8.96k|      alg_bits = 168;
 1551|  8.96k|      strength_bits = 112;
 1552|  8.96k|      break;
 1553|       |
 1554|      0|    default:
  ------------------
  |  Branch (1554:5): [True: 0, False: 259k]
  ------------------
 1555|      0|      assert(0);
 1556|      0|      alg_bits = 0;
 1557|      0|      strength_bits = 0;
 1558|   259k|  }
 1559|       |
 1560|   259k|  if (out_alg_bits != NULL) {
  ------------------
  |  Branch (1560:7): [True: 0, False: 259k]
  ------------------
 1561|      0|    *out_alg_bits = alg_bits;
 1562|      0|  }
 1563|   259k|  return strength_bits;
 1564|   259k|}
ssl_cipher.cc:_ZN4bsslL26ssl_cipher_process_rulestrEPKcPPNS_15cipher_order_stES4_b:
  953|  25.8k|                                       CIPHER_ORDER **tail_p, bool strict) {
  954|  25.8k|  const char *l, *buf;
  955|  25.8k|  bool in_group = false, has_group = false;
  956|  25.8k|  size_t j, buf_len;
  957|  25.8k|  char ch;
  958|       |
  959|  25.8k|  l = rule_str;
  960|  71.0k|  for (;;) {
  961|  71.0k|    ch = *l;
  962|       |
  963|  71.0k|    if (ch == '\0') {
  ------------------
  |  Branch (963:9): [True: 16.8k, False: 54.2k]
  ------------------
  964|  16.8k|      break;  // done
  965|  16.8k|    }
  966|       |
  967|  54.2k|    int rule;
  968|  54.2k|    if (in_group) {
  ------------------
  |  Branch (968:9): [True: 2.33k, False: 51.9k]
  ------------------
  969|  2.33k|      if (ch == ']') {
  ------------------
  |  Branch (969:11): [True: 494, False: 1.83k]
  ------------------
  970|    494|        if (*tail_p) {
  ------------------
  |  Branch (970:13): [True: 300, False: 194]
  ------------------
  971|    300|          (*tail_p)->in_group = false;
  972|    300|        }
  973|    494|        in_group = false;
  974|    494|        l++;
  975|    494|        continue;
  976|    494|      }
  977|       |
  978|  1.83k|      if (ch == '|') {
  ------------------
  |  Branch (978:11): [True: 624, False: 1.21k]
  ------------------
  979|    624|        rule = CIPHER_ADD;
  ------------------
  |  |  480|    624|#define CIPHER_ADD 1
  ------------------
  980|    624|        l++;
  981|    624|        continue;
  982|  1.21k|      } else if (!OPENSSL_isalnum(ch)) {
  ------------------
  |  Branch (982:18): [True: 262, False: 952]
  ------------------
  983|    262|        OPENSSL_PUT_ERROR(SSL, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
  ------------------
  |  |  441|    262|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  984|    262|        return false;
  985|    952|      } else {
  986|    952|        rule = CIPHER_ADD;
  ------------------
  |  |  480|    952|#define CIPHER_ADD 1
  ------------------
  987|    952|      }
  988|  51.9k|    } else if (ch == '-') {
  ------------------
  |  Branch (988:16): [True: 827, False: 51.0k]
  ------------------
  989|    827|      rule = CIPHER_DEL;
  ------------------
  |  |  482|    827|#define CIPHER_DEL 3
  ------------------
  990|    827|      l++;
  991|  51.0k|    } else if (ch == '+') {
  ------------------
  |  Branch (991:16): [True: 533, False: 50.5k]
  ------------------
  992|    533|      rule = CIPHER_ORD;
  ------------------
  |  |  483|    533|#define CIPHER_ORD 4
  ------------------
  993|    533|      l++;
  994|  50.5k|    } else if (ch == '!') {
  ------------------
  |  Branch (994:16): [True: 2.78k, False: 47.7k]
  ------------------
  995|  2.78k|      rule = CIPHER_KILL;
  ------------------
  |  |  481|  2.78k|#define CIPHER_KILL 2
  ------------------
  996|  2.78k|      l++;
  997|  47.7k|    } else if (ch == '@') {
  ------------------
  |  Branch (997:16): [True: 7.67k, False: 40.1k]
  ------------------
  998|  7.67k|      rule = CIPHER_SPECIAL;
  ------------------
  |  |  484|  7.67k|#define CIPHER_SPECIAL 5
  ------------------
  999|  7.67k|      l++;
 1000|  40.1k|    } else if (ch == '[') {
  ------------------
  |  Branch (1000:16): [True: 1.32k, False: 38.7k]
  ------------------
 1001|  1.32k|      assert(!in_group);
 1002|      0|      in_group = true;
 1003|  1.32k|      has_group = true;
 1004|  1.32k|      l++;
 1005|  1.32k|      continue;
 1006|  38.7k|    } else {
 1007|  38.7k|      rule = CIPHER_ADD;
  ------------------
  |  |  480|  38.7k|#define CIPHER_ADD 1
  ------------------
 1008|  38.7k|    }
 1009|       |
 1010|       |    // If preference groups are enabled, the only legal operator is +.
 1011|       |    // Otherwise the in_group bits will get mixed up.
 1012|  51.5k|    if (has_group && rule != CIPHER_ADD) {
  ------------------
  |  |  480|  1.23k|#define CIPHER_ADD 1
  ------------------
  |  Branch (1012:9): [True: 1.23k, False: 50.3k]
  |  Branch (1012:22): [True: 211, False: 1.02k]
  ------------------
 1013|    211|      OPENSSL_PUT_ERROR(SSL, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
  ------------------
  |  |  441|    211|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1014|    211|      return false;
 1015|    211|    }
 1016|       |
 1017|  51.3k|    if (is_cipher_list_separator(ch, strict)) {
  ------------------
  |  Branch (1017:9): [True: 11.5k, False: 39.8k]
  ------------------
 1018|  11.5k|      l++;
 1019|  11.5k|      continue;
 1020|  11.5k|    }
 1021|       |
 1022|  39.8k|    bool multi = false;
 1023|  39.8k|    uint32_t cipher_id = 0;
 1024|  39.8k|    CIPHER_ALIAS alias;
 1025|  39.8k|    bool skip_rule = false;
 1026|       |
 1027|       |    // When adding, exclude deprecated ciphers by default.
 1028|  39.8k|    alias.include_deprecated = rule != CIPHER_ADD;
  ------------------
  |  |  480|  39.8k|#define CIPHER_ADD 1
  ------------------
 1029|       |
 1030|  42.3k|    for (;;) {
 1031|  42.3k|      ch = *l;
 1032|  42.3k|      buf = l;
 1033|  42.3k|      buf_len = 0;
 1034|   211k|      while (OPENSSL_isalnum(ch) || ch == '-' || ch == '.' || ch == '_') {
  ------------------
  |  Branch (1034:14): [True: 164k, False: 47.0k]
  |  Branch (1034:37): [True: 2.14k, False: 44.9k]
  |  Branch (1034:50): [True: 442, False: 44.4k]
  |  Branch (1034:63): [True: 2.09k, False: 42.3k]
  ------------------
 1035|   168k|        ch = *(++l);
 1036|   168k|        buf_len++;
 1037|   168k|      }
 1038|       |
 1039|  42.3k|      if (buf_len == 0) {
  ------------------
  |  Branch (1039:11): [True: 5.06k, False: 37.3k]
  ------------------
 1040|       |        // We hit something we cannot deal with, it is no command or separator
 1041|       |        // nor alphanumeric, so we call this an error.
 1042|  5.06k|        OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|  5.06k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1043|  5.06k|        return false;
 1044|  5.06k|      }
 1045|       |
 1046|  37.3k|      if (rule == CIPHER_SPECIAL) {
  ------------------
  |  |  484|  37.3k|#define CIPHER_SPECIAL 5
  ------------------
  |  Branch (1046:11): [True: 7.04k, False: 30.2k]
  ------------------
 1047|  7.04k|        break;
 1048|  7.04k|      }
 1049|       |
 1050|       |      // Look for a matching exact cipher. These aren't allowed in multipart
 1051|       |      // rules.
 1052|  30.2k|      if (!multi && ch != '+') {
  ------------------
  |  Branch (1052:11): [True: 27.9k, False: 2.34k]
  |  Branch (1052:21): [True: 25.9k, False: 2.03k]
  ------------------
 1053|   637k|        for (j = 0; j < OPENSSL_ARRAY_SIZE(kCiphers); j++) {
  ------------------
  |  |  221|   637k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (1053:21): [True: 611k, False: 25.4k]
  ------------------
 1054|   611k|          const SSL_CIPHER *cipher = &kCiphers[j];
 1055|   611k|          if (rule_equals(cipher->name, buf, buf_len) ||
  ------------------
  |  Branch (1055:15): [True: 276, False: 611k]
  ------------------
 1056|   611k|              rule_equals(cipher->standard_name, buf, buf_len)) {
  ------------------
  |  Branch (1056:15): [True: 209, False: 611k]
  ------------------
 1057|    485|            cipher_id = cipher->id;
 1058|    485|            break;
 1059|    485|          }
 1060|   611k|        }
 1061|  25.9k|      }
 1062|  30.2k|      if (cipher_id == 0) {
  ------------------
  |  Branch (1062:11): [True: 29.7k, False: 485]
  ------------------
 1063|       |        // If not an exact cipher, look for a matching cipher alias.
 1064|   453k|        for (j = 0; j < kCipherAliasesLen; j++) {
  ------------------
  |  Branch (1064:21): [True: 442k, False: 10.5k]
  ------------------
 1065|   442k|          if (rule_equals(kCipherAliases[j].name, buf, buf_len)) {
  ------------------
  |  Branch (1065:15): [True: 19.2k, False: 423k]
  ------------------
 1066|  19.2k|            alias.algorithm_mkey &= kCipherAliases[j].algorithm_mkey;
 1067|  19.2k|            alias.algorithm_auth &= kCipherAliases[j].algorithm_auth;
 1068|  19.2k|            alias.algorithm_enc &= kCipherAliases[j].algorithm_enc;
 1069|  19.2k|            alias.algorithm_mac &= kCipherAliases[j].algorithm_mac;
 1070|       |
 1071|       |            // When specifying a combination of aliases, if any aliases
 1072|       |            // enables deprecated ciphers, deprecated ciphers are included. This
 1073|       |            // is slightly different from the bitmasks in that adding aliases
 1074|       |            // can increase the set of matched ciphers. This is so that an alias
 1075|       |            // like "RSA" will only specifiy AES-based RSA ciphers, but
 1076|       |            // "RSA+3DES" will still specify 3DES.
 1077|  19.2k|            alias.include_deprecated |= kCipherAliases[j].include_deprecated;
 1078|       |
 1079|  19.2k|            if (alias.min_version != 0 &&
  ------------------
  |  Branch (1079:17): [True: 390, False: 18.8k]
  ------------------
 1080|  19.2k|                alias.min_version != kCipherAliases[j].min_version) {
  ------------------
  |  Branch (1080:17): [True: 196, False: 194]
  ------------------
 1081|    196|              skip_rule = true;
 1082|  19.0k|            } else {
 1083|  19.0k|              alias.min_version = kCipherAliases[j].min_version;
 1084|  19.0k|            }
 1085|  19.2k|            break;
 1086|  19.2k|          }
 1087|   442k|        }
 1088|  29.7k|        if (j == kCipherAliasesLen) {
  ------------------
  |  Branch (1088:13): [True: 10.5k, False: 19.2k]
  ------------------
 1089|  10.5k|          skip_rule = true;
 1090|  10.5k|          if (strict) {
  ------------------
  |  Branch (1090:15): [True: 1.88k, False: 8.71k]
  ------------------
 1091|  1.88k|            OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|  1.88k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1092|  1.88k|            return false;
 1093|  1.88k|          }
 1094|  10.5k|        }
 1095|  29.7k|      }
 1096|       |
 1097|       |      // Check for a multipart rule.
 1098|  28.3k|      if (ch != '+') {
  ------------------
  |  Branch (1098:11): [True: 25.8k, False: 2.58k]
  ------------------
 1099|  25.8k|        break;
 1100|  25.8k|      }
 1101|  2.58k|      l++;
 1102|  2.58k|      multi = true;
 1103|  2.58k|    }
 1104|       |
 1105|       |    // Ok, we have the rule, now apply it.
 1106|  32.8k|    if (rule == CIPHER_SPECIAL) {
  ------------------
  |  |  484|  32.8k|#define CIPHER_SPECIAL 5
  ------------------
  |  Branch (1106:9): [True: 7.04k, False: 25.8k]
  ------------------
 1107|  7.04k|      if (buf_len != 8 || strncmp(buf, "STRENGTH", 8) != 0) {
  ------------------
  |  Branch (1107:11): [True: 1.06k, False: 5.97k]
  |  Branch (1107:27): [True: 500, False: 5.47k]
  ------------------
 1108|  1.56k|        OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|  1.56k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1109|  1.56k|        return false;
 1110|  1.56k|      }
 1111|  5.47k|      if (!ssl_cipher_strength_sort(head_p, tail_p)) {
  ------------------
  |  Branch (1111:11): [True: 0, False: 5.47k]
  ------------------
 1112|      0|        return false;
 1113|      0|      }
 1114|       |
 1115|       |      // We do not support any "multi" options together with "@", so throw away
 1116|       |      // the rest of the command, if any left, until end or ':' is found.
 1117|  6.93k|      while (*l != '\0' && !is_cipher_list_separator(*l, strict)) {
  ------------------
  |  Branch (1117:14): [True: 4.94k, False: 1.98k]
  |  Branch (1117:28): [True: 1.45k, False: 3.49k]
  ------------------
 1118|  1.45k|        l++;
 1119|  1.45k|      }
 1120|  25.8k|    } else if (!skip_rule) {
  ------------------
  |  Branch (1120:16): [True: 17.6k, False: 8.19k]
  ------------------
 1121|  17.6k|      ssl_cipher_apply_rule(cipher_id, &alias, rule, -1, in_group, head_p,
 1122|  17.6k|                            tail_p);
 1123|  17.6k|    }
 1124|  32.8k|  }
 1125|       |
 1126|  16.8k|  if (in_group) {
  ------------------
  |  Branch (1126:7): [True: 570, False: 16.2k]
  ------------------
 1127|    570|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_COMMAND);
  ------------------
  |  |  441|    570|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1128|    570|    return false;
 1129|    570|  }
 1130|       |
 1131|  16.2k|  return true;
 1132|  16.8k|}
ssl_cipher.cc:_ZN4bsslL24is_cipher_list_separatorEcb:
  675|  56.2k|static bool is_cipher_list_separator(char c, bool is_strict) {
  676|  56.2k|  if (c == ':') {
  ------------------
  |  Branch (676:7): [True: 11.2k, False: 45.0k]
  ------------------
  677|  11.2k|    return true;
  678|  11.2k|  }
  679|  45.0k|  return !is_strict && (c == ' ' || c == ';' || c == ',');
  ------------------
  |  Branch (679:10): [True: 34.2k, False: 10.7k]
  |  Branch (679:25): [True: 2.17k, False: 32.0k]
  |  Branch (679:37): [True: 1.34k, False: 30.7k]
  |  Branch (679:49): [True: 256, False: 30.4k]
  ------------------
  680|  56.2k|}
ssl_cipher.cc:_ZN4bsslL11rule_equalsEPKcS1_m:
  684|  1.66M|static bool rule_equals(const char *rule, const char *buf, size_t buf_len) {
  685|       |  // |strncmp| alone only checks that |buf| is a prefix of |rule|.
  686|  1.66M|  return strncmp(rule, buf, buf_len) == 0 && rule[buf_len] == '\0';
  ------------------
  |  Branch (686:10): [True: 67.8k, False: 1.59M]
  |  Branch (686:46): [True: 19.6k, False: 48.1k]
  ------------------
  687|  1.66M|}
ssl_cipher.cc:_ZN4bsslL24ssl_cipher_strength_sortEPPNS_15cipher_order_stES2_:
  911|  5.47k|                                     CIPHER_ORDER **tail_p) {
  912|       |  // This routine sorts the ciphers with descending strength. The sorting must
  913|       |  // keep the pre-sorted sequence, so we apply the normal sorting routine as
  914|       |  // '+' movement to the end of the list.
  915|  5.47k|  int max_strength_bits = 0;
  916|  5.47k|  CIPHER_ORDER *curr = *head_p;
  917|   112k|  while (curr != NULL) {
  ------------------
  |  Branch (917:10): [True: 106k, False: 5.47k]
  ------------------
  918|   106k|    if (curr->active &&
  ------------------
  |  Branch (918:9): [True: 54.7k, False: 51.9k]
  ------------------
  919|   106k|        SSL_CIPHER_get_bits(curr->cipher, NULL) > max_strength_bits) {
  ------------------
  |  Branch (919:9): [True: 5.53k, False: 49.2k]
  ------------------
  920|  5.53k|      max_strength_bits = SSL_CIPHER_get_bits(curr->cipher, NULL);
  921|  5.53k|    }
  922|   106k|    curr = curr->next;
  923|   106k|  }
  924|       |
  925|  5.47k|  Array<int> number_uses;
  926|  5.47k|  if (!number_uses.Init(max_strength_bits + 1)) {
  ------------------
  |  Branch (926:7): [True: 0, False: 5.47k]
  ------------------
  927|      0|    return false;
  928|      0|  }
  929|  5.47k|  OPENSSL_memset(number_uses.data(), 0, (max_strength_bits + 1) * sizeof(int));
  930|       |
  931|       |  // Now find the strength_bits values actually used.
  932|  5.47k|  curr = *head_p;
  933|   112k|  while (curr != NULL) {
  ------------------
  |  Branch (933:10): [True: 106k, False: 5.47k]
  ------------------
  934|   106k|    if (curr->active) {
  ------------------
  |  Branch (934:9): [True: 54.7k, False: 51.9k]
  ------------------
  935|  54.7k|      number_uses[SSL_CIPHER_get_bits(curr->cipher, NULL)]++;
  936|  54.7k|    }
  937|   106k|    curr = curr->next;
  938|   106k|  }
  939|       |
  940|       |  // Go through the list of used strength_bits values in descending order.
  941|   937k|  for (int i = max_strength_bits; i >= 0; i--) {
  ------------------
  |  Branch (941:35): [True: 932k, False: 5.47k]
  ------------------
  942|   932k|    if (number_uses[i] > 0) {
  ------------------
  |  Branch (942:9): [True: 7.08k, False: 925k]
  ------------------
  943|  7.08k|      ssl_cipher_apply_rule(/*cipher_id=*/0, /*alias=*/nullptr, CIPHER_ORD, i,
  ------------------
  |  |  483|  7.08k|#define CIPHER_ORD 4
  ------------------
  944|  7.08k|                            false, head_p, tail_p);
  945|  7.08k|    }
  946|   932k|  }
  947|       |
  948|  5.47k|  return true;
  949|  5.47k|}
ssl_cipher.cc:_ZN4bsslL21ssl_cipher_apply_ruleEjPKNS_15cipher_alias_stEiibPPNS_15cipher_order_stES5_:
  792|  24.7k|                                  CIPHER_ORDER **tail_p) {
  793|  24.7k|  CIPHER_ORDER *head, *tail, *curr, *next, *last;
  794|  24.7k|  const SSL_CIPHER *cp;
  795|  24.7k|  bool reverse = false;
  796|       |
  797|  24.7k|  if (cipher_id == 0 && strength_bits == -1 && alias->min_version == 0 &&
  ------------------
  |  Branch (797:7): [True: 24.2k, False: 485]
  |  Branch (797:25): [True: 17.1k, False: 7.08k]
  |  Branch (797:48): [True: 16.1k, False: 963]
  ------------------
  798|  24.7k|      (alias->algorithm_mkey == 0 || alias->algorithm_auth == 0 ||
  ------------------
  |  Branch (798:8): [True: 428, False: 15.7k]
  |  Branch (798:38): [True: 215, False: 15.5k]
  ------------------
  799|  16.1k|       alias->algorithm_enc == 0 || alias->algorithm_mac == 0)) {
  ------------------
  |  Branch (799:8): [True: 197, False: 15.3k]
  |  Branch (799:37): [True: 0, False: 15.3k]
  ------------------
  800|       |    // The rule matches nothing, so bail early.
  801|    840|    return;
  802|    840|  }
  803|       |
  804|  23.8k|  if (rule == CIPHER_DEL) {
  ------------------
  |  |  482|  23.8k|#define CIPHER_DEL 3
  ------------------
  |  Branch (804:7): [True: 329, False: 23.5k]
  ------------------
  805|       |    // needed to maintain sorting between currently deleted ciphers
  806|    329|    reverse = true;
  807|    329|  }
  808|       |
  809|  23.8k|  head = *head_p;
  810|  23.8k|  tail = *tail_p;
  811|       |
  812|  23.8k|  if (reverse) {
  ------------------
  |  Branch (812:7): [True: 329, False: 23.5k]
  ------------------
  813|    329|    next = tail;
  814|    329|    last = head;
  815|  23.5k|  } else {
  816|  23.5k|    next = head;
  817|  23.5k|    last = tail;
  818|  23.5k|  }
  819|       |
  820|  23.8k|  curr = NULL;
  821|   510k|  for (;;) {
  822|   510k|    if (curr == last) {
  ------------------
  |  Branch (822:9): [True: 23.8k, False: 486k]
  ------------------
  823|  23.8k|      break;
  824|  23.8k|    }
  825|       |
  826|   486k|    curr = next;
  827|   486k|    if (curr == NULL) {
  ------------------
  |  Branch (827:9): [True: 0, False: 486k]
  ------------------
  828|      0|      break;
  829|      0|    }
  830|       |
  831|   486k|    next = reverse ? curr->prev : curr->next;
  ------------------
  |  Branch (831:12): [True: 6.77k, False: 480k]
  ------------------
  832|   486k|    cp = curr->cipher;
  833|       |
  834|       |    // Selection criteria is either a specific cipher, the value of
  835|       |    // |strength_bits|, or the algorithms used.
  836|   486k|    if (cipher_id != 0) {
  ------------------
  |  Branch (836:9): [True: 9.57k, False: 477k]
  ------------------
  837|  9.57k|      if (cipher_id != cp->id) {
  ------------------
  |  Branch (837:11): [True: 9.12k, False: 453]
  ------------------
  838|  9.12k|        continue;
  839|  9.12k|      }
  840|   477k|    } else if (strength_bits >= 0) {
  ------------------
  |  Branch (840:16): [True: 144k, False: 333k]
  ------------------
  841|   144k|      if (strength_bits != SSL_CIPHER_get_bits(cp, NULL)) {
  ------------------
  |  Branch (841:11): [True: 80.5k, False: 63.5k]
  ------------------
  842|  80.5k|        continue;
  843|  80.5k|      }
  844|   333k|    } else {
  845|   333k|      if (!(alias->algorithm_mkey & cp->algorithm_mkey) ||
  ------------------
  |  Branch (845:11): [True: 12.1k, False: 321k]
  ------------------
  846|   333k|          !(alias->algorithm_auth & cp->algorithm_auth) ||
  ------------------
  |  Branch (846:11): [True: 4.76k, False: 316k]
  ------------------
  847|   333k|          !(alias->algorithm_enc & cp->algorithm_enc) ||
  ------------------
  |  Branch (847:11): [True: 21.2k, False: 295k]
  ------------------
  848|   333k|          !(alias->algorithm_mac & cp->algorithm_mac) ||
  ------------------
  |  Branch (848:11): [True: 3.04k, False: 292k]
  ------------------
  849|   333k|          (alias->min_version != 0 &&
  ------------------
  |  Branch (849:12): [True: 17.5k, False: 274k]
  ------------------
  850|   292k|           SSL_CIPHER_get_min_version(cp) != alias->min_version) ||
  ------------------
  |  Branch (850:12): [True: 9.56k, False: 7.95k]
  ------------------
  851|   333k|          (!alias->include_deprecated && ssl_cipher_is_deprecated(cp))) {
  ------------------
  |  Branch (851:12): [True: 251k, False: 31.5k]
  |  Branch (851:42): [True: 23.3k, False: 227k]
  ------------------
  852|  74.1k|        continue;
  853|  74.1k|      }
  854|   333k|    }
  855|       |
  856|       |    // add the cipher if it has not been added yet.
  857|   323k|    if (rule == CIPHER_ADD) {
  ------------------
  |  |  480|   323k|#define CIPHER_ADD 1
  ------------------
  |  Branch (857:9): [True: 228k, False: 94.4k]
  ------------------
  858|       |      // reverse == false
  859|   228k|      if (!curr->active) {
  ------------------
  |  Branch (859:11): [True: 223k, False: 5.27k]
  ------------------
  860|   223k|        ll_append_tail(&head, curr, &tail);
  861|   223k|        curr->active = true;
  862|   223k|        curr->in_group = in_group;
  863|   223k|      }
  864|   228k|    }
  865|       |
  866|       |    // Move the added cipher to this location
  867|  94.4k|    else if (rule == CIPHER_ORD) {
  ------------------
  |  |  483|  94.4k|#define CIPHER_ORD 4
  ------------------
  |  Branch (867:14): [True: 67.9k, False: 26.4k]
  ------------------
  868|       |      // reverse == false
  869|  67.9k|      if (curr->active) {
  ------------------
  |  Branch (869:11): [True: 57.1k, False: 10.7k]
  ------------------
  870|  57.1k|        ll_append_tail(&head, curr, &tail);
  871|  57.1k|        curr->in_group = false;
  872|  57.1k|      }
  873|  67.9k|    } else if (rule == CIPHER_DEL) {
  ------------------
  |  |  482|  26.4k|#define CIPHER_DEL 3
  ------------------
  |  Branch (873:16): [True: 6.11k, False: 20.3k]
  ------------------
  874|       |      // reverse == true
  875|  6.11k|      if (curr->active) {
  ------------------
  |  Branch (875:11): [True: 1.35k, False: 4.76k]
  ------------------
  876|       |        // most recently deleted ciphersuites get best positions
  877|       |        // for any future CIPHER_ADD (note that the CIPHER_DEL loop
  878|       |        // works in reverse to maintain the order)
  879|  1.35k|        ll_append_head(&head, curr, &tail);
  880|  1.35k|        curr->active = false;
  881|  1.35k|        curr->in_group = false;
  882|  1.35k|      }
  883|  20.3k|    } else if (rule == CIPHER_KILL) {
  ------------------
  |  |  481|  20.3k|#define CIPHER_KILL 2
  ------------------
  |  Branch (883:16): [True: 20.3k, False: 0]
  ------------------
  884|       |      // reverse == false
  885|  20.3k|      if (head == curr) {
  ------------------
  |  Branch (885:11): [True: 12.7k, False: 7.64k]
  ------------------
  886|  12.7k|        head = curr->next;
  887|  12.7k|      } else {
  888|  7.64k|        curr->prev->next = curr->next;
  889|  7.64k|      }
  890|       |
  891|  20.3k|      if (tail == curr) {
  ------------------
  |  Branch (891:11): [True: 1.21k, False: 19.1k]
  ------------------
  892|  1.21k|        tail = curr->prev;
  893|  1.21k|      }
  894|  20.3k|      curr->active = false;
  895|  20.3k|      if (curr->next != NULL) {
  ------------------
  |  Branch (895:11): [True: 19.1k, False: 1.21k]
  ------------------
  896|  19.1k|        curr->next->prev = curr->prev;
  897|  19.1k|      }
  898|  20.3k|      if (curr->prev != NULL) {
  ------------------
  |  Branch (898:11): [True: 7.64k, False: 12.7k]
  ------------------
  899|  7.64k|        curr->prev->next = curr->next;
  900|  7.64k|      }
  901|  20.3k|      curr->next = NULL;
  902|  20.3k|      curr->prev = NULL;
  903|  20.3k|    }
  904|   323k|  }
  905|       |
  906|  23.8k|  *head_p = head;
  907|  23.8k|  *tail_p = tail;
  908|  23.8k|}
ssl_cipher.cc:_ZN4bsslL14ll_append_tailEPPNS_15cipher_order_stES1_S2_:
  690|   280k|                           CIPHER_ORDER **tail) {
  691|   280k|  if (curr == *tail) {
  ------------------
  |  Branch (691:7): [True: 1.68k, False: 278k]
  ------------------
  692|  1.68k|    return;
  693|  1.68k|  }
  694|   278k|  if (curr == *head) {
  ------------------
  |  Branch (694:7): [True: 147k, False: 131k]
  ------------------
  695|   147k|    *head = curr->next;
  696|   147k|  }
  697|   278k|  if (curr->prev != NULL) {
  ------------------
  |  Branch (697:7): [True: 131k, False: 147k]
  ------------------
  698|   131k|    curr->prev->next = curr->next;
  699|   131k|  }
  700|   278k|  if (curr->next != NULL) {
  ------------------
  |  Branch (700:7): [True: 278k, False: 0]
  ------------------
  701|   278k|    curr->next->prev = curr->prev;
  702|   278k|  }
  703|   278k|  (*tail)->next = curr;
  704|   278k|  curr->prev = *tail;
  705|   278k|  curr->next = NULL;
  706|   278k|  *tail = curr;
  707|   278k|}
ssl_cipher.cc:_ZN4bsslL14ll_append_headEPPNS_15cipher_order_stES1_S2_:
  710|  1.35k|                           CIPHER_ORDER **tail) {
  711|  1.35k|  if (curr == *head) {
  ------------------
  |  Branch (711:7): [True: 0, False: 1.35k]
  ------------------
  712|      0|    return;
  713|      0|  }
  714|  1.35k|  if (curr == *tail) {
  ------------------
  |  Branch (714:7): [True: 1.04k, False: 311]
  ------------------
  715|  1.04k|    *tail = curr->prev;
  716|  1.04k|  }
  717|  1.35k|  if (curr->next != NULL) {
  ------------------
  |  Branch (717:7): [True: 311, False: 1.04k]
  ------------------
  718|    311|    curr->next->prev = curr->prev;
  719|    311|  }
  720|  1.35k|  if (curr->prev != NULL) {
  ------------------
  |  Branch (720:7): [True: 1.35k, False: 0]
  ------------------
  721|  1.35k|    curr->prev->next = curr->next;
  722|  1.35k|  }
  723|  1.35k|  (*head)->prev = curr;
  724|  1.35k|  curr->next = *head;
  725|  1.35k|  curr->prev = NULL;
  726|  1.35k|  *head = curr;
  727|  1.35k|}
ssl_cipher.cc:_ZL22ssl_cipher_id_cmp_voidPKvS0_:
 1337|  2.64M|static int ssl_cipher_id_cmp_void(const void *in_a, const void *in_b) {
 1338|  2.64M|  return ssl_cipher_id_cmp(reinterpret_cast<const SSL_CIPHER *>(in_a),
 1339|  2.64M|                           reinterpret_cast<const SSL_CIPHER *>(in_b));
 1340|  2.64M|}
ssl_cipher.cc:_ZL17ssl_cipher_id_cmpPK13ssl_cipher_stS1_:
 1327|  2.64M|                                       const SSL_CIPHER *b) {
 1328|  2.64M|  if (a->id > b->id) {
  ------------------
  |  Branch (1328:7): [True: 871k, False: 1.77M]
  ------------------
 1329|   871k|    return 1;
 1330|   871k|  }
 1331|  1.77M|  if (a->id < b->id) {
  ------------------
  |  Branch (1331:7): [True: 1.09M, False: 677k]
  ------------------
 1332|  1.09M|    return -1;
 1333|  1.09M|  }
 1334|   677k|  return 0;
 1335|  1.77M|}

_ZN4bssl19ssl_nid_to_group_idEPti:
  322|  5.94k|bool ssl_nid_to_group_id(uint16_t *out_group_id, int nid) {
  323|  33.1k|  for (const auto &group : kNamedGroups) {
  ------------------
  |  Branch (323:26): [True: 33.1k, False: 5.28k]
  ------------------
  324|  33.1k|    if (group.nid == nid) {
  ------------------
  |  Branch (324:9): [True: 656, False: 32.4k]
  ------------------
  325|    656|      *out_group_id = group.group_id;
  326|    656|      return true;
  327|    656|    }
  328|  33.1k|  }
  329|  5.28k|  return false;
  330|  5.94k|}
_ZN4bssl20ssl_name_to_group_idEPtPKcm:
  332|  6.35k|bool ssl_name_to_group_id(uint16_t *out_group_id, const char *name, size_t len) {
  333|  36.7k|  for (const auto &group : kNamedGroups) {
  ------------------
  |  Branch (333:26): [True: 36.7k, False: 5.77k]
  ------------------
  334|  36.7k|    if (len == strlen(group.name) &&
  ------------------
  |  Branch (334:9): [True: 2.38k, False: 34.3k]
  ------------------
  335|  36.7k|        !strncmp(group.name, name, len)) {
  ------------------
  |  Branch (335:9): [True: 382, False: 2.00k]
  ------------------
  336|    382|      *out_group_id = group.group_id;
  337|    382|      return true;
  338|    382|    }
  339|  36.3k|    if (strlen(group.alias) > 0 && len == strlen(group.alias) &&
  ------------------
  |  Branch (339:9): [True: 30.5k, False: 5.77k]
  |  Branch (339:36): [True: 941, False: 29.6k]
  ------------------
  340|  36.3k|        !strncmp(group.alias, name, len)) {
  ------------------
  |  Branch (340:9): [True: 198, False: 743]
  ------------------
  341|    198|      *out_group_id = group.group_id;
  342|    198|      return true;
  343|    198|    }
  344|  36.3k|  }
  345|  5.77k|  return false;
  346|  6.35k|}
_ZN4bssl19ssl_group_id_to_nidEt:
  348|  3.70k|int ssl_group_id_to_nid(uint16_t group_id) {
  349|  19.5k|  for (const auto &group : kNamedGroups) {
  ------------------
  |  Branch (349:26): [True: 19.5k, False: 2.93k]
  ------------------
  350|  19.5k|    if (group.group_id == group_id) {
  ------------------
  |  Branch (350:9): [True: 774, False: 18.7k]
  ------------------
  351|    774|      return group.nid;
  352|    774|    }
  353|  19.5k|  }
  354|  2.93k|  return NID_undef;
  ------------------
  |  |   85|  2.93k|#define NID_undef 0
  ------------------
  355|  3.70k|}

_ZN10ssl_ctx_stC2EPK13ssl_method_st:
  540|  4.83k|      aes_hw_override_value(false) {
  541|  4.83k|  CRYPTO_MUTEX_init(&lock);
  542|  4.83k|  CRYPTO_new_ex_data(&ex_data);
  543|  4.83k|}
_ZN10ssl_ctx_stD2Ev:
  545|  4.83k|ssl_ctx_st::~ssl_ctx_st() {
  546|       |  // Free the internal session cache. Note that this calls the caller-supplied
  547|       |  // remove callback, so we must do it before clearing ex_data. (See ticket
  548|       |  // [openssl.org #212].)
  549|  4.83k|  SSL_CTX_flush_sessions(this, 0);
  550|       |
  551|  4.83k|  CRYPTO_free_ex_data(&g_ex_data_class_ssl_ctx, this, &ex_data);
  552|       |
  553|  4.83k|  CRYPTO_MUTEX_cleanup(&lock);
  554|  4.83k|  lh_SSL_SESSION_free(sessions);
  555|  4.83k|  x509_method->ssl_ctx_free(this);
  556|  4.83k|}
SSL_CTX_new:
  558|  4.83k|SSL_CTX *SSL_CTX_new(const SSL_METHOD *method) {
  559|  4.83k|  if (method == NULL) {
  ------------------
  |  Branch (559:7): [True: 0, False: 4.83k]
  ------------------
  560|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_NULL_SSL_METHOD_PASSED);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  561|      0|    return nullptr;
  562|      0|  }
  563|       |
  564|  4.83k|  UniquePtr<SSL_CTX> ret = MakeUnique<SSL_CTX>(method);
  565|  4.83k|  if (!ret) {
  ------------------
  |  Branch (565:7): [True: 0, False: 4.83k]
  ------------------
  566|      0|    return nullptr;
  567|      0|  }
  568|       |
  569|  4.83k|  ret->cert = MakeUnique<CERT>(method->x509_method);
  570|  4.83k|  ret->sessions = lh_SSL_SESSION_new(ssl_session_hash, ssl_session_cmp);
  571|  4.83k|  ret->client_CA.reset(sk_CRYPTO_BUFFER_new_null());
  572|  4.83k|  if (ret->cert == nullptr ||
  ------------------
  |  Branch (572:7): [True: 0, False: 4.83k]
  ------------------
  573|  4.83k|      ret->sessions == nullptr ||
  ------------------
  |  Branch (573:7): [True: 0, False: 4.83k]
  ------------------
  574|  4.83k|      ret->client_CA == nullptr ||
  ------------------
  |  Branch (574:7): [True: 0, False: 4.83k]
  ------------------
  575|  4.83k|      !ret->x509_method->ssl_ctx_new(ret.get())) {
  ------------------
  |  Branch (575:7): [True: 0, False: 4.83k]
  ------------------
  576|      0|    return nullptr;
  577|      0|  }
  578|       |
  579|  4.83k|  if (!SSL_CTX_set_strict_cipher_list(ret.get(), SSL_DEFAULT_CIPHER_LIST) ||
  ------------------
  |  | 1541|  4.83k|#define SSL_DEFAULT_CIPHER_LIST "ALL"
  ------------------
  |  Branch (579:7): [True: 0, False: 4.83k]
  ------------------
  580|       |      // Lock the SSL_CTX to the specified version, for compatibility with
  581|       |      // legacy uses of SSL_METHOD.
  582|  4.83k|      !SSL_CTX_set_max_proto_version(ret.get(), method->version) ||
  ------------------
  |  Branch (582:7): [True: 0, False: 4.83k]
  ------------------
  583|  4.83k|      !SSL_CTX_set_min_proto_version(ret.get(), method->version)) {
  ------------------
  |  Branch (583:7): [True: 0, False: 4.83k]
  ------------------
  584|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_INTERNAL_ERROR);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  585|      0|    return nullptr;
  586|      0|  }
  587|       |
  588|  4.83k|  return ret.release();
  589|  4.83k|}
SSL_CTX_up_ref:
  591|  9.66k|int SSL_CTX_up_ref(SSL_CTX *ctx) {
  592|  9.66k|  CRYPTO_refcount_inc(&ctx->references);
  593|  9.66k|  return 1;
  594|  9.66k|}
SSL_CTX_free:
  596|  14.4k|void SSL_CTX_free(SSL_CTX *ctx) {
  597|  14.4k|  if (ctx == NULL ||
  ------------------
  |  Branch (597:7): [True: 0, False: 14.4k]
  ------------------
  598|  14.4k|      !CRYPTO_refcount_dec_and_test_zero(&ctx->references)) {
  ------------------
  |  Branch (598:7): [True: 9.66k, False: 4.83k]
  ------------------
  599|  9.66k|    return;
  600|  9.66k|  }
  601|       |
  602|  4.83k|  ctx->~ssl_ctx_st();
  603|  4.83k|  OPENSSL_free(ctx);
  604|  4.83k|}
_ZN6ssl_stC2EP10ssl_ctx_st:
  618|  4.83k|      enable_early_data(ctx->enable_early_data) {
  619|  4.83k|  CRYPTO_new_ex_data(&ex_data);
  620|  4.83k|}
_ZN6ssl_stD2Ev:
  622|  4.83k|ssl_st::~ssl_st() {
  623|  4.83k|  CRYPTO_free_ex_data(&g_ex_data_class_ssl, this, &ex_data);
  624|       |  // |config| refers to |this|, so we must release it earlier.
  625|  4.83k|  config.reset();
  626|  4.83k|  if (method != NULL) {
  ------------------
  |  Branch (626:7): [True: 4.83k, False: 0]
  ------------------
  627|  4.83k|    method->ssl_free(this);
  628|  4.83k|  }
  629|  4.83k|}
SSL_new:
  631|  4.83k|SSL *SSL_new(SSL_CTX *ctx) {
  632|  4.83k|  if (ctx == nullptr) {
  ------------------
  |  Branch (632:7): [True: 0, False: 4.83k]
  ------------------
  633|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_NULL_SSL_CTX);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  634|      0|    return nullptr;
  635|      0|  }
  636|       |
  637|  4.83k|  UniquePtr<SSL> ssl = MakeUnique<SSL>(ctx);
  638|  4.83k|  if (ssl == nullptr) {
  ------------------
  |  Branch (638:7): [True: 0, False: 4.83k]
  ------------------
  639|      0|    return nullptr;
  640|      0|  }
  641|       |
  642|  4.83k|  ssl->config = MakeUnique<SSL_CONFIG>(ssl.get());
  643|  4.83k|  if (ssl->config == nullptr) {
  ------------------
  |  Branch (643:7): [True: 0, False: 4.83k]
  ------------------
  644|      0|    return nullptr;
  645|      0|  }
  646|  4.83k|  ssl->config->conf_min_version = ctx->conf_min_version;
  647|  4.83k|  ssl->config->conf_max_version = ctx->conf_max_version;
  648|       |
  649|  4.83k|  ssl->config->cert = ssl_cert_dup(ctx->cert.get());
  650|  4.83k|  if (ssl->config->cert == nullptr) {
  ------------------
  |  Branch (650:7): [True: 0, False: 4.83k]
  ------------------
  651|      0|    return nullptr;
  652|      0|  }
  653|       |
  654|  4.83k|  ssl->config->verify_mode = ctx->verify_mode;
  655|  4.83k|  ssl->config->verify_callback = ctx->default_verify_callback;
  656|  4.83k|  ssl->config->custom_verify_callback = ctx->custom_verify_callback;
  657|  4.83k|  ssl->config->retain_only_sha256_of_client_certs =
  658|  4.83k|      ctx->retain_only_sha256_of_client_certs;
  659|  4.83k|  ssl->config->permute_extensions = ctx->permute_extensions;
  660|  4.83k|  ssl->config->aes_hw_override = ctx->aes_hw_override;
  661|  4.83k|  ssl->config->aes_hw_override_value = ctx->aes_hw_override_value;
  662|  4.83k|  ssl->config->tls13_cipher_policy = ctx->tls13_cipher_policy;
  663|       |
  664|  4.83k|  if (!ssl->config->supported_group_list.CopyFrom(ctx->supported_group_list) ||
  ------------------
  |  Branch (664:7): [True: 0, False: 4.83k]
  |  Branch (664:7): [True: 0, False: 4.83k]
  ------------------
  665|  4.83k|      !ssl->config->alpn_client_proto_list.CopyFrom(
  ------------------
  |  Branch (665:7): [True: 0, False: 4.83k]
  ------------------
  666|  4.83k|          ctx->alpn_client_proto_list) ||
  667|  4.83k|      !ssl->config->verify_sigalgs.CopyFrom(ctx->verify_sigalgs)) {
  ------------------
  |  Branch (667:7): [True: 0, False: 4.83k]
  ------------------
  668|      0|    return nullptr;
  669|      0|  }
  670|       |
  671|  4.83k|  if (ctx->psk_identity_hint) {
  ------------------
  |  Branch (671:7): [True: 0, False: 4.83k]
  ------------------
  672|      0|    ssl->config->psk_identity_hint.reset(
  673|      0|        OPENSSL_strdup(ctx->psk_identity_hint.get()));
  674|      0|    if (ssl->config->psk_identity_hint == nullptr) {
  ------------------
  |  Branch (674:9): [True: 0, False: 0]
  ------------------
  675|      0|      return nullptr;
  676|      0|    }
  677|      0|  }
  678|  4.83k|  ssl->config->psk_client_callback = ctx->psk_client_callback;
  679|  4.83k|  ssl->config->psk_server_callback = ctx->psk_server_callback;
  680|       |
  681|  4.83k|  ssl->config->channel_id_enabled = ctx->channel_id_enabled;
  682|  4.83k|  ssl->config->channel_id_private = UpRef(ctx->channel_id_private);
  683|       |
  684|  4.83k|  ssl->config->signed_cert_timestamps_enabled =
  685|  4.83k|      ctx->signed_cert_timestamps_enabled;
  686|  4.83k|  ssl->config->ocsp_stapling_enabled = ctx->ocsp_stapling_enabled;
  687|  4.83k|  ssl->config->handoff = ctx->handoff;
  688|  4.83k|  ssl->quic_method = ctx->quic_method;
  689|       |
  690|  4.83k|  if (!ssl->method->ssl_new(ssl.get()) ||
  ------------------
  |  Branch (690:7): [True: 0, False: 4.83k]
  ------------------
  691|  4.83k|      !ssl->ctx->x509_method->ssl_new(ssl->s3->hs.get())) {
  ------------------
  |  Branch (691:7): [True: 0, False: 4.83k]
  ------------------
  692|      0|    return nullptr;
  693|      0|  }
  694|       |
  695|  4.83k|  return ssl.release();
  696|  4.83k|}
_ZN4bssl10SSL_CONFIGC2EP6ssl_st:
  710|  4.83k|      permute_extensions(false) {
  711|  4.83k|  assert(ssl);
  712|  4.83k|}
_ZN4bssl10SSL_CONFIGD2Ev:
  714|  4.83k|SSL_CONFIG::~SSL_CONFIG() {
  715|  4.83k|  if (ssl->ctx != nullptr) {
  ------------------
  |  Branch (715:7): [True: 4.83k, False: 0]
  ------------------
  716|  4.83k|    ssl->ctx->x509_method->ssl_config_free(this);
  717|  4.83k|  }
  718|  4.83k|}
SSL_free:
  720|  4.83k|void SSL_free(SSL *ssl) {
  721|  4.83k|  Delete(ssl);
  722|  4.83k|}
SSL_CTX_set_options:
 1449|  5.11k|uint32_t SSL_CTX_set_options(SSL_CTX *ctx, uint32_t options) {
 1450|  5.11k|  ctx->options |= options;
 1451|  5.11k|  return ctx->options;
 1452|  5.11k|}
SSL_CTX_clear_options:
 1454|  2.92k|uint32_t SSL_CTX_clear_options(SSL_CTX *ctx, uint32_t options) {
 1455|  2.92k|  ctx->options &= ~options;
 1456|  2.92k|  return ctx->options;
 1457|  2.92k|}
SSL_CTX_get_options:
 1459|  3.94k|uint32_t SSL_CTX_get_options(const SSL_CTX *ctx) { return ctx->options; }
SSL_CTX_set_mode:
 1473|  3.29k|uint32_t SSL_CTX_set_mode(SSL_CTX *ctx, uint32_t mode) {
 1474|  3.29k|  ctx->mode |= mode;
 1475|  3.29k|  return ctx->mode;
 1476|  3.29k|}
SSL_CTX_clear_mode:
 1478|  5.84k|uint32_t SSL_CTX_clear_mode(SSL_CTX *ctx, uint32_t mode) {
 1479|  5.84k|  ctx->mode &= ~mode;
 1480|  5.84k|  return ctx->mode;
 1481|  5.84k|}
SSL_CTX_get_mode:
 1483|  3.30k|uint32_t SSL_CTX_get_mode(const SSL_CTX *ctx) { return ctx->mode; }
SSL_CTX_set_session_id_context:
 1549|  2.59k|                                   size_t sid_ctx_len) {
 1550|  2.59k|  return set_session_id_context(ctx->cert.get(), sid_ctx, sid_ctx_len);
 1551|  2.59k|}
SSL_CTX_check_private_key:
 1734|  8.41k|int SSL_CTX_check_private_key(const SSL_CTX *ctx) {
 1735|  8.41k|  return ssl_cert_check_private_key(ctx->cert.get(),
 1736|  8.41k|                                    ctx->cert->privatekey.get());
 1737|  8.41k|}
SSL_CTX_get_max_cert_list:
 1799|  1.55k|size_t SSL_CTX_get_max_cert_list(const SSL_CTX *ctx) {
 1800|  1.55k|  return ctx->max_cert_list;
 1801|  1.55k|}
SSL_CTX_set_max_cert_list:
 1803|  1.14k|void SSL_CTX_set_max_cert_list(SSL_CTX *ctx, size_t max_cert_list) {
 1804|  1.14k|  if (max_cert_list > kMaxHandshakeSize) {
  ------------------
  |  Branch (1804:7): [True: 847, False: 301]
  ------------------
 1805|    847|    max_cert_list = kMaxHandshakeSize;
 1806|    847|  }
 1807|  1.14k|  ctx->max_cert_list = (uint32_t)max_cert_list;
 1808|  1.14k|}
SSL_CTX_set_max_send_fragment:
 1821|  4.88k|int SSL_CTX_set_max_send_fragment(SSL_CTX *ctx, size_t max_send_fragment) {
 1822|  4.88k|  if (max_send_fragment < 512) {
  ------------------
  |  Branch (1822:7): [True: 333, False: 4.55k]
  ------------------
 1823|    333|    max_send_fragment = 512;
 1824|    333|  }
 1825|  4.88k|  if (max_send_fragment > SSL3_RT_MAX_PLAIN_LENGTH) {
  ------------------
  |  |  233|  4.88k|#define SSL3_RT_MAX_PLAIN_LENGTH 16384
  ------------------
  |  Branch (1825:7): [True: 4.48k, False: 405]
  ------------------
 1826|  4.48k|    max_send_fragment = SSL3_RT_MAX_PLAIN_LENGTH;
  ------------------
  |  |  233|  4.48k|#define SSL3_RT_MAX_PLAIN_LENGTH 16384
  ------------------
 1827|  4.48k|  }
 1828|  4.88k|  ctx->max_send_fragment = (uint16_t)max_send_fragment;
 1829|       |
 1830|  4.88k|  return 1;
 1831|  4.88k|}
SSL_CTX_sess_number:
 1861|  4.94k|size_t SSL_CTX_sess_number(const SSL_CTX *ctx) {
 1862|  4.94k|  MutexReadLock lock(const_cast<CRYPTO_MUTEX *>(&ctx->lock));
 1863|  4.94k|  return lh_SSL_SESSION_num_items(ctx->sessions);
 1864|  4.94k|}
SSL_CTX_sess_set_cache_size:
 1866|  2.29k|unsigned long SSL_CTX_sess_set_cache_size(SSL_CTX *ctx, unsigned long size) {
 1867|  2.29k|  unsigned long ret = ctx->session_cache_size;
 1868|  2.29k|  ctx->session_cache_size = size;
 1869|  2.29k|  return ret;
 1870|  2.29k|}
SSL_CTX_sess_get_cache_size:
 1872|  7.18k|unsigned long SSL_CTX_sess_get_cache_size(const SSL_CTX *ctx) {
 1873|  7.18k|  return ctx->session_cache_size;
 1874|  7.18k|}
SSL_CTX_set_tlsext_ticket_keys:
 1910|  1.90k|int SSL_CTX_set_tlsext_ticket_keys(SSL_CTX *ctx, const void *in, size_t len) {
 1911|  1.90k|  if (in == NULL) {
  ------------------
  |  Branch (1911:7): [True: 480, False: 1.42k]
  ------------------
 1912|    480|    return 48;
 1913|    480|  }
 1914|  1.42k|  if (len != 48) {
  ------------------
  |  Branch (1914:7): [True: 1.16k, False: 259]
  ------------------
 1915|  1.16k|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_TICKET_KEYS_LENGTH);
  ------------------
  |  |  441|  1.16k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1916|  1.16k|    return 0;
 1917|  1.16k|  }
 1918|    259|  auto key = MakeUnique<TicketKey>();
 1919|    259|  if (!key) {
  ------------------
  |  Branch (1919:7): [True: 0, False: 259]
  ------------------
 1920|      0|    return 0;
 1921|      0|  }
 1922|    259|  const uint8_t *in_bytes = reinterpret_cast<const uint8_t *>(in);
 1923|    259|  OPENSSL_memcpy(key->name, in_bytes, 16);
 1924|    259|  OPENSSL_memcpy(key->hmac_key, in_bytes + 16, 16);
 1925|    259|  OPENSSL_memcpy(key->aes_key, in_bytes + 32, 16);
 1926|       |  // Disable automatic key rotation for manually-configured keys. This is now
 1927|       |  // the caller's responsibility.
 1928|    259|  key->next_rotation_tv_sec = 0;
 1929|    259|  ctx->ticket_key_current = std::move(key);
 1930|    259|  ctx->ticket_key_prev.reset();
 1931|    259|  return 1;
 1932|    259|}
SSL_CTX_set1_group_ids:
 1953|  4.92k|                           size_t num_group_ids) {
 1954|  4.92k|  auto span = MakeConstSpan(group_ids, num_group_ids);
 1955|  4.92k|  return check_group_ids(span) && ctx->supported_group_list.CopyFrom(span);
  ------------------
  |  Branch (1955:10): [True: 1.99k, False: 2.93k]
  |  Branch (1955:35): [True: 1.99k, False: 0]
  ------------------
 1956|  4.92k|}
SSL_CTX_set1_groups:
 1986|  8.67k|int SSL_CTX_set1_groups(SSL_CTX *ctx, const int *groups, size_t num_groups) {
 1987|  8.67k|  return ssl_nids_to_group_ids(&ctx->supported_group_list,
 1988|  8.67k|                               MakeConstSpan(groups, num_groups));
 1989|  8.67k|}
SSL_CTX_set1_groups_list:
 2036|  5.99k|int SSL_CTX_set1_groups_list(SSL_CTX *ctx, const char *groups) {
 2037|  5.99k|  return ssl_str_to_group_ids(&ctx->supported_group_list, groups);
 2038|  5.99k|}
SSL_CTX_set_cipher_list:
 2114|  20.2k|int SSL_CTX_set_cipher_list(SSL_CTX *ctx, const char *str) {
 2115|  20.2k|  const bool has_aes_hw = ctx->aes_hw_override ? ctx->aes_hw_override_value
  ------------------
  |  Branch (2115:27): [True: 0, False: 20.2k]
  ------------------
 2116|  20.2k|                                               : EVP_has_aes_hardware();
 2117|  20.2k|  return ssl_create_cipher_list(&ctx->cipher_list, has_aes_hw, str,
 2118|  20.2k|                                false /* not strict */);
 2119|  20.2k|}
SSL_CTX_set_strict_cipher_list:
 2121|  11.9k|int SSL_CTX_set_strict_cipher_list(SSL_CTX *ctx, const char *str) {
 2122|  11.9k|  const bool has_aes_hw = ctx->aes_hw_override ? ctx->aes_hw_override_value
  ------------------
  |  Branch (2122:27): [True: 0, False: 11.9k]
  ------------------
 2123|  11.9k|                                               : EVP_has_aes_hardware();
 2124|  11.9k|  return ssl_create_cipher_list(&ctx->cipher_list, has_aes_hw, str,
 2125|  11.9k|                                true /* strict */);
 2126|  11.9k|}
SSL_CTX_enable_signed_cert_timestamps:
 2188|  12.7k|void SSL_CTX_enable_signed_cert_timestamps(SSL_CTX *ctx) {
 2189|  12.7k|  ctx->signed_cert_timestamps_enabled = true;
 2190|  12.7k|}
SSL_CTX_enable_ocsp_stapling:
 2199|  10.2k|void SSL_CTX_enable_ocsp_stapling(SSL_CTX *ctx) {
 2200|  10.2k|  ctx->ocsp_stapling_enabled = true;
 2201|  10.2k|}
SSL_CTX_set_alpn_protos:
 2323|  2.95k|                            size_t protos_len) {
 2324|       |  // Note this function's return value is backwards.
 2325|  2.95k|  auto span = MakeConstSpan(protos, protos_len);
 2326|  2.95k|  if (!span.empty() && !ssl_is_valid_alpn_list(span)) {
  ------------------
  |  Branch (2326:7): [True: 2.48k, False: 471]
  |  Branch (2326:24): [True: 2.18k, False: 298]
  ------------------
 2327|  2.18k|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_ALPN_PROTOCOL_LIST);
  ------------------
  |  |  441|  2.18k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 2328|  2.18k|    return 1;
 2329|  2.18k|  }
 2330|    769|  return ctx->alpn_client_proto_list.CopyFrom(span) ? 0 : 1;
  ------------------
  |  Branch (2330:10): [True: 769, False: 0]
  ------------------
 2331|  2.95k|}
SSL_CTX_get0_privatekey:
 2521|  1.99k|EVP_PKEY *SSL_CTX_get0_privatekey(const SSL_CTX *ctx) {
 2522|  1.99k|  if (ctx->cert != NULL) {
  ------------------
  |  Branch (2522:7): [True: 1.99k, False: 0]
  ------------------
 2523|  1.99k|    return ctx->cert->privatekey.get();
 2524|  1.99k|  }
 2525|       |
 2526|      0|  return NULL;
 2527|  1.99k|}
SSL_CTX_set_quiet_shutdown:
 2544|   136k|void SSL_CTX_set_quiet_shutdown(SSL_CTX *ctx, int mode) {
 2545|   136k|  ctx->quiet_shutdown = (mode != 0);
 2546|   136k|}
SSL_CTX_get_quiet_shutdown:
 2548|  27.3k|int SSL_CTX_get_quiet_shutdown(const SSL_CTX *ctx) {
 2549|  27.3k|  return ctx->quiet_shutdown;
 2550|  27.3k|}
SSL_is_dtls:
 2883|  9.66k|int SSL_is_dtls(const SSL *ssl) { return ssl->method->is_dtls; }
SSL_CTX_set_retain_only_sha256_of_client_certs:
 2996|  4.24k|void SSL_CTX_set_retain_only_sha256_of_client_certs(SSL_CTX *ctx, int enabled) {
 2997|  4.24k|  ctx->retain_only_sha256_of_client_certs = !!enabled;
 2998|  4.24k|}
SSL_CTX_set_grease_enabled:
 3000|  1.46k|void SSL_CTX_set_grease_enabled(SSL_CTX *ctx, int enabled) {
 3001|  1.46k|  ctx->grease_enabled = !!enabled;
 3002|  1.46k|}
ssl_lib.cc:_ZL22set_session_id_contextPN4bssl4CERTEPKhm:
 1536|  2.59k|                                   size_t sid_ctx_len) {
 1537|  2.59k|  if (sid_ctx_len > sizeof(cert->sid_ctx)) {
  ------------------
  |  Branch (1537:7): [True: 1.72k, False: 869]
  ------------------
 1538|  1.72k|    OPENSSL_PUT_ERROR(SSL, SSL_R_SSL_SESSION_ID_CONTEXT_TOO_LONG);
  ------------------
  |  |  441|  1.72k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1539|  1.72k|    return 0;
 1540|  1.72k|  }
 1541|       |
 1542|    869|  static_assert(sizeof(cert->sid_ctx) < 256, "sid_ctx too large");
 1543|    869|  cert->sid_ctx_length = (uint8_t)sid_ctx_len;
 1544|    869|  OPENSSL_memcpy(cert->sid_ctx, sid_ctx, sid_ctx_len);
 1545|    869|  return 1;
 1546|  2.59k|}
ssl_lib.cc:_ZL15check_group_idsN4bssl4SpanIKtEE:
 1942|  4.92k|static bool check_group_ids(Span<const uint16_t> group_ids) {
 1943|  4.92k|  for (uint16_t group_id : group_ids) {
  ------------------
  |  Branch (1943:26): [True: 3.70k, False: 1.99k]
  ------------------
 1944|  3.70k|    if (ssl_group_id_to_nid(group_id) == NID_undef) {
  ------------------
  |  |   85|  3.70k|#define NID_undef 0
  ------------------
  |  Branch (1944:9): [True: 2.93k, False: 774]
  ------------------
 1945|  2.93k|      OPENSSL_PUT_ERROR(SSL, SSL_R_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |  441|  2.93k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1946|  2.93k|      return false;
 1947|  2.93k|    }
 1948|  3.70k|  }
 1949|  1.99k|  return true;
 1950|  4.92k|}
ssl_lib.cc:_ZL21ssl_nids_to_group_idsPN4bssl5ArrayItEENS_4SpanIKiEE:
 1969|  8.67k|                                  Span<const int> nids) {
 1970|  8.67k|  Array<uint16_t> group_ids;
 1971|  8.67k|  if (!group_ids.Init(nids.size())) {
  ------------------
  |  Branch (1971:7): [True: 0, False: 8.67k]
  ------------------
 1972|      0|    return false;
 1973|      0|  }
 1974|       |
 1975|  9.33k|  for (size_t i = 0; i < nids.size(); i++) {
  ------------------
  |  Branch (1975:22): [True: 5.94k, False: 3.38k]
  ------------------
 1976|  5.94k|    if (!ssl_nid_to_group_id(&group_ids[i], nids[i])) {
  ------------------
  |  Branch (1976:9): [True: 5.28k, False: 656]
  ------------------
 1977|  5.28k|      OPENSSL_PUT_ERROR(SSL, SSL_R_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |  441|  5.28k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 1978|  5.28k|      return false;
 1979|  5.28k|    }
 1980|  5.94k|  }
 1981|       |
 1982|  3.38k|  *out_group_ids = std::move(group_ids);
 1983|  3.38k|  return true;
 1984|  8.67k|}
ssl_lib.cc:_ZL20ssl_str_to_group_idsPN4bssl5ArrayItEEPKc:
 2000|  5.99k|                                 const char *str) {
 2001|       |  // Count the number of groups in the list.
 2002|  5.99k|  size_t count = 0;
 2003|  5.99k|  const char *ptr = str, *col;
 2004|  22.7k|  do {
 2005|  22.7k|    col = strchr(ptr, ':');
 2006|  22.7k|    count++;
 2007|  22.7k|    if (col) {
  ------------------
  |  Branch (2007:9): [True: 16.7k, False: 5.99k]
  ------------------
 2008|  16.7k|      ptr = col + 1;
 2009|  16.7k|    }
 2010|  22.7k|  } while (col);
  ------------------
  |  Branch (2010:12): [True: 16.7k, False: 5.99k]
  ------------------
 2011|       |
 2012|  5.99k|  Array<uint16_t> group_ids;
 2013|  5.99k|  if (!group_ids.Init(count)) {
  ------------------
  |  Branch (2013:7): [True: 0, False: 5.99k]
  ------------------
 2014|      0|    return false;
 2015|      0|  }
 2016|       |
 2017|  5.99k|  size_t i = 0;
 2018|  5.99k|  ptr = str;
 2019|  6.35k|  do {
 2020|  6.35k|    col = strchr(ptr, ':');
 2021|  6.35k|    if (!ssl_name_to_group_id(&group_ids[i++], ptr,
  ------------------
  |  Branch (2021:9): [True: 5.77k, False: 580]
  ------------------
 2022|  6.35k|                              col ? (size_t)(col - ptr) : strlen(ptr))) {
  ------------------
  |  Branch (2022:31): [True: 3.74k, False: 2.60k]
  ------------------
 2023|  5.77k|      OPENSSL_PUT_ERROR(SSL, SSL_R_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |  441|  5.77k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
 2024|  5.77k|      return false;
 2025|  5.77k|    }
 2026|    580|    if (col) {
  ------------------
  |  Branch (2026:9): [True: 361, False: 219]
  ------------------
 2027|    361|      ptr = col + 1;
 2028|    361|    }
 2029|    580|  } while (col);
  ------------------
  |  Branch (2029:12): [True: 361, False: 219]
  ------------------
 2030|       |
 2031|    219|  assert(i == count);
 2032|      0|  *out_group_ids = std::move(group_ids);
 2033|    219|  return true;
 2034|  5.99k|}

_ZN4bssl25ssl_is_key_type_supportedEi:
   75|  19.6k|bool ssl_is_key_type_supported(int key_type) {
   76|  19.6k|  return key_type == EVP_PKEY_RSA || key_type == EVP_PKEY_EC ||
  ------------------
  |  |  175|  19.6k|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|  39.2k|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
                return key_type == EVP_PKEY_RSA || key_type == EVP_PKEY_EC ||
  ------------------
  |  |  178|      0|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|  19.6k|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  |  Branch (76:10): [True: 19.6k, False: 0]
  |  Branch (76:38): [True: 0, False: 0]
  ------------------
   77|  19.6k|         key_type == EVP_PKEY_ED25519;
  ------------------
  |  |  179|      0|#define EVP_PKEY_ED25519 NID_ED25519
  |  |  ------------------
  |  |  |  | 4199|      0|#define NID_ED25519 949
  |  |  ------------------
  ------------------
  |  Branch (77:10): [True: 0, False: 0]
  ------------------
   78|  19.6k|}
SSL_CTX_use_PrivateKey:
  447|  6.72k|int SSL_CTX_use_PrivateKey(SSL_CTX *ctx, EVP_PKEY *pkey) {
  448|  6.72k|  if (pkey == NULL) {
  ------------------
  |  Branch (448:7): [True: 0, False: 6.72k]
  ------------------
  449|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  450|      0|    return 0;
  451|      0|  }
  452|       |
  453|  6.72k|  return ssl_set_pkey(ctx->cert.get(), pkey);
  454|  6.72k|}
SSL_CTX_set_signing_algorithm_prefs:
  636|  5.86k|                                        size_t num_prefs) {
  637|  5.86k|  return set_sigalg_prefs(&ctx->cert->sigalgs, MakeConstSpan(prefs, num_prefs));
  638|  5.86k|}
SSL_CTX_set1_sigalgs:
  702|  7.90k|int SSL_CTX_set1_sigalgs(SSL_CTX *ctx, const int *values, size_t num_values) {
  703|  7.90k|  Array<uint16_t> sigalgs;
  704|  7.90k|  if (!parse_sigalg_pairs(&sigalgs, values, num_values)) {
  ------------------
  |  Branch (704:7): [True: 6.67k, False: 1.23k]
  ------------------
  705|  6.67k|    return 0;
  706|  6.67k|  }
  707|       |
  708|  1.23k|  if (!SSL_CTX_set_signing_algorithm_prefs(ctx, sigalgs.data(),
  ------------------
  |  Branch (708:7): [True: 280, False: 950]
  ------------------
  709|  1.23k|                                           sigalgs.size()) ||
  710|  1.23k|      !SSL_CTX_set_verify_algorithm_prefs(ctx, sigalgs.data(),
  ------------------
  |  Branch (710:7): [True: 0, False: 950]
  ------------------
  711|    950|                                          sigalgs.size())) {
  712|    280|    return 0;
  713|    280|  }
  714|       |
  715|    950|  return 1;
  716|  1.23k|}
SSL_CTX_set1_sigalgs_list:
  890|  7.89k|int SSL_CTX_set1_sigalgs_list(SSL_CTX *ctx, const char *str) {
  891|  7.89k|  Array<uint16_t> sigalgs;
  892|  7.89k|  if (!parse_sigalgs_list(&sigalgs, str)) {
  ------------------
  |  Branch (892:7): [True: 7.19k, False: 698]
  ------------------
  893|  7.19k|    return 0;
  894|  7.19k|  }
  895|       |
  896|    698|  if (!SSL_CTX_set_signing_algorithm_prefs(ctx, sigalgs.data(),
  ------------------
  |  Branch (896:7): [True: 377, False: 321]
  ------------------
  897|    698|                                           sigalgs.size()) ||
  898|    698|      !SSL_CTX_set_verify_algorithm_prefs(ctx, sigalgs.data(),
  ------------------
  |  Branch (898:7): [True: 0, False: 321]
  ------------------
  899|    377|                                          sigalgs.size())) {
  900|    377|    return 0;
  901|    377|  }
  902|       |
  903|    321|  return 1;
  904|    698|}
SSL_CTX_set_verify_algorithm_prefs:
  926|  2.56k|                                       size_t num_prefs) {
  927|  2.56k|  return set_sigalg_prefs(&ctx->verify_sigalgs,
  928|  2.56k|                          MakeConstSpan(prefs, num_prefs));
  929|  2.56k|}
ssl_privkey.cc:_ZN4bsslL23get_signature_algorithmEt:
  128|  3.04k|static const SSL_SIGNATURE_ALGORITHM *get_signature_algorithm(uint16_t sigalg) {
  129|  32.7k|  for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(kSignatureAlgorithms); i++) {
  ------------------
  |  |  221|  32.7k|#define OPENSSL_ARRAY_SIZE(array) (sizeof(array) / sizeof((array)[0]))
  ------------------
  |  Branch (129:22): [True: 31.0k, False: 1.68k]
  ------------------
  130|  31.0k|    if (kSignatureAlgorithms[i].sigalg == sigalg) {
  ------------------
  |  Branch (130:9): [True: 1.35k, False: 29.6k]
  ------------------
  131|  1.35k|      return &kSignatureAlgorithms[i];
  132|  1.35k|    }
  133|  31.0k|  }
  134|  1.68k|  return NULL;
  135|  3.04k|}
ssl_privkey.cc:_ZN4bsslL12ssl_set_pkeyEPNS_4CERTEP11evp_pkey_st:
   80|  6.72k|static bool ssl_set_pkey(CERT *cert, EVP_PKEY *pkey) {
   81|  6.72k|  if (!ssl_is_key_type_supported(EVP_PKEY_id(pkey))) {
  ------------------
  |  Branch (81:7): [True: 0, False: 6.72k]
  ------------------
   82|      0|    OPENSSL_PUT_ERROR(SSL, SSL_R_UNKNOWN_CERTIFICATE_TYPE);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
   83|      0|    return false;
   84|      0|  }
   85|       |
   86|  6.72k|  if (cert->chain != nullptr &&
  ------------------
  |  Branch (86:7): [True: 6.09k, False: 639]
  ------------------
   87|  6.72k|      sk_CRYPTO_BUFFER_value(cert->chain.get(), 0) != nullptr &&
  ------------------
  |  Branch (87:7): [True: 4.91k, False: 1.17k]
  ------------------
   88|       |      // Sanity-check that the private key and the certificate match.
   89|  6.72k|      !ssl_cert_check_private_key(cert, pkey)) {
  ------------------
  |  Branch (89:7): [True: 0, False: 4.91k]
  ------------------
   90|      0|    return false;
   91|      0|  }
   92|       |
   93|  6.72k|  cert->privatekey = UpRef(pkey);
   94|  6.72k|  return true;
   95|  6.72k|}
ssl_privkey.cc:_ZL16set_sigalg_prefsPN4bssl5ArrayItEENS_4SpanIKtEE:
  595|  8.43k|static bool set_sigalg_prefs(Array<uint16_t> *out, Span<const uint16_t> prefs) {
  596|  8.43k|  if (!sigalgs_unique(prefs)) {
  ------------------
  |  Branch (596:7): [True: 2.58k, False: 5.84k]
  ------------------
  597|  2.58k|    return false;
  598|  2.58k|  }
  599|       |
  600|       |  // Check for invalid algorithms, and filter out |SSL_SIGN_RSA_PKCS1_MD5_SHA1|.
  601|  5.84k|  Array<uint16_t> filtered;
  602|  5.84k|  if (!filtered.Init(prefs.size())) {
  ------------------
  |  Branch (602:7): [True: 0, False: 5.84k]
  ------------------
  603|      0|    return false;
  604|      0|  }
  605|  5.84k|  size_t added = 0;
  606|  5.84k|  for (uint16_t pref : prefs) {
  ------------------
  |  Branch (606:22): [True: 3.31k, False: 4.16k]
  ------------------
  607|  3.31k|    if (pref == SSL_SIGN_RSA_PKCS1_MD5_SHA1) {
  ------------------
  |  | 1076|  3.31k|#define SSL_SIGN_RSA_PKCS1_MD5_SHA1 0xff01
  ------------------
  |  Branch (607:9): [True: 277, False: 3.04k]
  ------------------
  608|       |      // Though not intended to be used with this API, we treat
  609|       |      // |SSL_SIGN_RSA_PKCS1_MD5_SHA1| as a real signature algorithm in
  610|       |      // |SSL_PRIVATE_KEY_METHOD|. Not accepting it here makes for a confusing
  611|       |      // abstraction.
  612|    277|      continue;
  613|    277|    }
  614|  3.04k|    if (get_signature_algorithm(pref) == nullptr) {
  ------------------
  |  Branch (614:9): [True: 1.68k, False: 1.35k]
  ------------------
  615|  1.68k|      OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|  1.68k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  616|  1.68k|      return false;
  617|  1.68k|    }
  618|  1.35k|    filtered[added] = pref;
  619|  1.35k|    added++;
  620|  1.35k|  }
  621|  4.16k|  filtered.Shrink(added);
  622|       |
  623|       |  // This can happen if |prefs| contained only |SSL_SIGN_RSA_PKCS1_MD5_SHA1|.
  624|       |  // Leaving it empty would revert to the default, so treat this as an error
  625|       |  // condition.
  626|  4.16k|  if (!prefs.empty() && filtered.empty()) {
  ------------------
  |  Branch (626:7): [True: 1.27k, False: 2.88k]
  |  Branch (626:25): [True: 270, False: 1.00k]
  ------------------
  627|    270|    OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    270|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  628|    270|    return false;
  629|    270|  }
  630|       |
  631|  3.89k|  *out = std::move(filtered);
  632|  3.89k|  return true;
  633|  4.16k|}
ssl_privkey.cc:_ZL14sigalgs_uniqueN4bssl4SpanIKtEE:
  573|  8.43k|static bool sigalgs_unique(Span<const uint16_t> in_sigalgs) {
  574|  8.43k|  if (in_sigalgs.size() < 2) {
  ------------------
  |  Branch (574:7): [True: 4.65k, False: 3.77k]
  ------------------
  575|  4.65k|    return true;
  576|  4.65k|  }
  577|       |
  578|  3.77k|  Array<uint16_t> sigalgs;
  579|  3.77k|  if (!sigalgs.CopyFrom(in_sigalgs)) {
  ------------------
  |  Branch (579:7): [True: 0, False: 3.77k]
  ------------------
  580|      0|    return false;
  581|      0|  }
  582|       |
  583|  3.77k|  qsort(sigalgs.data(), sigalgs.size(), sizeof(uint16_t), compare_uint16_t);
  584|       |
  585|  34.1k|  for (size_t i = 1; i < sigalgs.size(); i++) {
  ------------------
  |  Branch (585:22): [True: 32.9k, False: 1.19k]
  ------------------
  586|  32.9k|    if (sigalgs[i - 1] == sigalgs[i]) {
  ------------------
  |  Branch (586:9): [True: 2.58k, False: 30.4k]
  ------------------
  587|  2.58k|      OPENSSL_PUT_ERROR(SSL, SSL_R_DUPLICATE_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|  2.58k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  588|  2.58k|      return false;
  589|  2.58k|    }
  590|  32.9k|  }
  591|       |
  592|  1.19k|  return true;
  593|  3.77k|}
ssl_privkey.cc:_ZL16compare_uint16_tPKvS0_:
  561|   395k|static int compare_uint16_t(const void *p1, const void *p2) {
  562|   395k|  uint16_t u1 = *((const uint16_t *)p1);
  563|   395k|  uint16_t u2 = *((const uint16_t *)p2);
  564|   395k|  if (u1 < u2) {
  ------------------
  |  Branch (564:7): [True: 152k, False: 242k]
  ------------------
  565|   152k|    return -1;
  566|   242k|  } else if (u1 > u2) {
  ------------------
  |  Branch (566:14): [True: 193k, False: 49.7k]
  ------------------
  567|   193k|    return 1;
  568|   193k|  } else {
  569|  49.7k|    return 0;
  570|  49.7k|  }
  571|   395k|}
ssl_privkey.cc:_ZL18parse_sigalg_pairsPN4bssl5ArrayItEEPKim:
  669|  7.90k|                               size_t num_values) {
  670|  7.90k|  if ((num_values & 1) == 1) {
  ------------------
  |  Branch (670:7): [True: 602, False: 7.30k]
  ------------------
  671|    602|    return false;
  672|    602|  }
  673|       |
  674|  7.30k|  const size_t num_pairs = num_values / 2;
  675|  7.30k|  if (!out->Init(num_pairs)) {
  ------------------
  |  Branch (675:7): [True: 0, False: 7.30k]
  ------------------
  676|      0|    return false;
  677|      0|  }
  678|       |
  679|  8.27k|  for (size_t i = 0; i < num_values; i += 2) {
  ------------------
  |  Branch (679:22): [True: 7.04k, False: 1.23k]
  ------------------
  680|  7.04k|    const int hash_nid = values[i];
  681|  7.04k|    const int pkey_type = values[i+1];
  682|       |
  683|  7.04k|    bool found = false;
  684|  83.4k|    for (const auto &candidate : kSignatureAlgorithmsMapping) {
  ------------------
  |  Branch (684:32): [True: 83.4k, False: 6.07k]
  ------------------
  685|  83.4k|      if (candidate.pkey_type == pkey_type && candidate.hash_nid == hash_nid) {
  ------------------
  |  Branch (685:11): [True: 1.39k, False: 82.0k]
  |  Branch (685:47): [True: 967, False: 429]
  ------------------
  686|    967|        (*out)[i / 2] = candidate.signature_algorithm;
  687|    967|        found = true;
  688|    967|        break;
  689|    967|      }
  690|  83.4k|    }
  691|       |
  692|  7.04k|    if (!found) {
  ------------------
  |  Branch (692:9): [True: 6.07k, False: 967]
  ------------------
  693|  6.07k|      OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|  6.07k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  694|  6.07k|      ERR_add_error_dataf("unknown hash:%d pkey:%d", hash_nid, pkey_type);
  695|  6.07k|      return false;
  696|  6.07k|    }
  697|  7.04k|  }
  698|       |
  699|  1.23k|  return true;
  700|  7.30k|}
ssl_privkey.cc:_ZL18parse_sigalgs_listPN4bssl5ArrayItEEPKc:
  737|  7.89k|static bool parse_sigalgs_list(Array<uint16_t> *out, const char *str) {
  738|       |  // str looks like "RSA+SHA1:ECDSA+SHA256:ecdsa_secp256r1_sha256".
  739|       |
  740|       |  // Count colons to give the number of output elements from any successful
  741|       |  // parse.
  742|  7.89k|  size_t num_elements = 1;
  743|  7.89k|  size_t len = 0;
  744|  99.5k|  for (const char *p = str; *p; p++) {
  ------------------
  |  Branch (744:29): [True: 91.7k, False: 7.89k]
  ------------------
  745|  91.7k|    len++;
  746|  91.7k|    if (*p == ':') {
  ------------------
  |  Branch (746:9): [True: 5.73k, False: 85.9k]
  ------------------
  747|  5.73k|      num_elements++;
  748|  5.73k|    }
  749|  91.7k|  }
  750|       |
  751|  7.89k|  if (!out->Init(num_elements)) {
  ------------------
  |  Branch (751:7): [True: 0, False: 7.89k]
  ------------------
  752|      0|    return false;
  753|      0|  }
  754|  7.89k|  size_t out_i = 0;
  755|       |
  756|  7.89k|  enum {
  757|  7.89k|    pkey_or_name,
  758|  7.89k|    hash_name,
  759|  7.89k|  } state = pkey_or_name;
  760|       |
  761|  7.89k|  char buf[kMaxSignatureAlgorithmNameLen];
  762|       |  // buf_used is always < sizeof(buf). I.e. it's always safe to write
  763|       |  // buf[buf_used] = 0.
  764|  7.89k|  size_t buf_used = 0;
  765|       |
  766|  7.89k|  int pkey_type = 0, hash_nid = 0;
  767|       |
  768|       |  // Note that the loop runs to len+1, i.e. it'll process the terminating NUL.
  769|  55.5k|  for (size_t offset = 0; offset < len+1; offset++) {
  ------------------
  |  Branch (769:27): [True: 54.8k, False: 698]
  ------------------
  770|  54.8k|    const unsigned char c = str[offset];
  771|       |
  772|  54.8k|    switch (c) {
  773|  4.49k|      case '+':
  ------------------
  |  Branch (773:7): [True: 4.49k, False: 50.3k]
  ------------------
  774|  4.49k|        if (state == hash_name) {
  ------------------
  |  Branch (774:13): [True: 323, False: 4.17k]
  ------------------
  775|    323|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    323|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  776|    323|          ERR_add_error_dataf("+ found in hash name at offset %zu", offset);
  777|    323|          return false;
  778|    323|        }
  779|  4.17k|        if (buf_used == 0) {
  ------------------
  |  Branch (779:13): [True: 195, False: 3.97k]
  ------------------
  780|    195|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    195|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  781|    195|          ERR_add_error_dataf("empty public key type at offset %zu", offset);
  782|    195|          return false;
  783|    195|        }
  784|  3.97k|        buf[buf_used] = 0;
  785|       |
  786|  3.97k|        if (strcmp(buf, "RSA") == 0) {
  ------------------
  |  Branch (786:13): [True: 1.38k, False: 2.59k]
  ------------------
  787|  1.38k|          pkey_type = EVP_PKEY_RSA;
  ------------------
  |  |  175|  1.38k|#define EVP_PKEY_RSA NID_rsaEncryption
  |  |  ------------------
  |  |  |  |  114|  1.38k|#define NID_rsaEncryption 6
  |  |  ------------------
  ------------------
  788|  2.59k|        } else if (strcmp(buf, "RSA-PSS") == 0 ||
  ------------------
  |  Branch (788:20): [True: 337, False: 2.25k]
  ------------------
  789|  2.59k|                   strcmp(buf, "PSS") == 0) {
  ------------------
  |  Branch (789:20): [True: 1.45k, False: 803]
  ------------------
  790|  1.79k|          pkey_type = EVP_PKEY_RSA_PSS;
  ------------------
  |  |  176|  1.79k|#define EVP_PKEY_RSA_PSS NID_rsassaPss
  |  |  ------------------
  |  |  |  | 4039|  1.79k|#define NID_rsassaPss 912
  |  |  ------------------
  ------------------
  791|  1.79k|        } else if (strcmp(buf, "ECDSA") == 0) {
  ------------------
  |  Branch (791:20): [True: 460, False: 343]
  ------------------
  792|    460|          pkey_type = EVP_PKEY_EC;
  ------------------
  |  |  178|    460|#define EVP_PKEY_EC NID_X9_62_id_ecPublicKey
  |  |  ------------------
  |  |  |  | 1886|    460|#define NID_X9_62_id_ecPublicKey 408
  |  |  ------------------
  ------------------
  793|    460|        } else {
  794|    343|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    343|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  795|    343|          ERR_add_error_dataf("unknown public key type '%s'", buf);
  796|    343|          return false;
  797|    343|        }
  798|       |
  799|  3.63k|        state = hash_name;
  800|  3.63k|        buf_used = 0;
  801|  3.63k|        break;
  802|       |
  803|  2.30k|      case ':':
  ------------------
  |  Branch (803:7): [True: 2.30k, False: 52.4k]
  ------------------
  804|  2.30k|        OPENSSL_FALLTHROUGH;
  ------------------
  |  |  227|  2.30k|#define OPENSSL_FALLTHROUGH [[clang::fallthrough]]
  ------------------
  805|  6.44k|      case 0:
  ------------------
  |  Branch (805:7): [True: 4.13k, False: 50.6k]
  ------------------
  806|  6.44k|        if (buf_used == 0) {
  ------------------
  |  Branch (806:13): [True: 2.46k, False: 3.98k]
  ------------------
  807|  2.46k|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|  2.46k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  808|  2.46k|          ERR_add_error_dataf("empty element at offset %zu", offset);
  809|  2.46k|          return false;
  810|  2.46k|        }
  811|       |
  812|  3.98k|        buf[buf_used] = 0;
  813|       |
  814|  3.98k|        if (state == pkey_or_name) {
  ------------------
  |  Branch (814:13): [True: 1.36k, False: 2.62k]
  ------------------
  815|       |          // No '+' was seen thus this is a TLS 1.3-style name.
  816|  1.36k|          bool found = false;
  817|  17.6k|          for (const auto &candidate : kSignatureAlgorithmNames) {
  ------------------
  |  Branch (817:38): [True: 17.6k, False: 1.16k]
  ------------------
  818|  17.6k|            if (strcmp(candidate.name, buf) == 0) {
  ------------------
  |  Branch (818:17): [True: 198, False: 17.4k]
  ------------------
  819|    198|              assert(out_i < num_elements);
  820|      0|              (*out)[out_i++] = candidate.signature_algorithm;
  821|    198|              found = true;
  822|    198|              break;
  823|    198|            }
  824|  17.6k|          }
  825|       |
  826|  1.36k|          if (!found) {
  ------------------
  |  Branch (826:15): [True: 1.16k, False: 198]
  ------------------
  827|  1.16k|            OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|  1.16k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  828|  1.16k|            ERR_add_error_dataf("unknown signature algorithm '%s'", buf);
  829|  1.16k|            return false;
  830|  1.16k|          }
  831|  2.62k|        } else {
  832|  2.62k|          if (strcmp(buf, "SHA1") == 0) {
  ------------------
  |  Branch (832:15): [True: 499, False: 2.12k]
  ------------------
  833|    499|            hash_nid = NID_sha1;
  ------------------
  |  |  372|    499|#define NID_sha1 64
  ------------------
  834|  2.12k|          } else if (strcmp(buf, "SHA256") == 0) {
  ------------------
  |  Branch (834:22): [True: 227, False: 1.89k]
  ------------------
  835|    227|            hash_nid = NID_sha256;
  ------------------
  |  | 2993|    227|#define NID_sha256 672
  ------------------
  836|  1.89k|          } else if (strcmp(buf, "SHA384") == 0) {
  ------------------
  |  Branch (836:22): [True: 572, False: 1.32k]
  ------------------
  837|    572|            hash_nid = NID_sha384;
  ------------------
  |  | 2998|    572|#define NID_sha384 673
  ------------------
  838|  1.32k|          } else if (strcmp(buf, "SHA512") == 0) {
  ------------------
  |  Branch (838:22): [True: 983, False: 339]
  ------------------
  839|    983|            hash_nid = NID_sha512;
  ------------------
  |  | 3003|    983|#define NID_sha512 674
  ------------------
  840|    983|          } else {
  841|    339|            OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    339|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  842|    339|            ERR_add_error_dataf("unknown hash function '%s'", buf);
  843|    339|            return false;
  844|    339|          }
  845|       |
  846|  2.28k|          bool found = false;
  847|  14.7k|          for (const auto &candidate : kSignatureAlgorithmsMapping) {
  ------------------
  |  Branch (847:38): [True: 14.7k, False: 356]
  ------------------
  848|  14.7k|            if (candidate.pkey_type == pkey_type &&
  ------------------
  |  Branch (848:17): [True: 6.50k, False: 8.24k]
  ------------------
  849|  14.7k|                candidate.hash_nid == hash_nid) {
  ------------------
  |  Branch (849:17): [True: 1.92k, False: 4.58k]
  ------------------
  850|  1.92k|              assert(out_i < num_elements);
  851|      0|              (*out)[out_i++] = candidate.signature_algorithm;
  852|  1.92k|              found = true;
  853|  1.92k|              break;
  854|  1.92k|            }
  855|  14.7k|          }
  856|       |
  857|  2.28k|          if (!found) {
  ------------------
  |  Branch (857:15): [True: 356, False: 1.92k]
  ------------------
  858|    356|            OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    356|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  859|    356|            ERR_add_error_dataf("unknown pkey:%d hash:%s", pkey_type, buf);
  860|    356|            return false;
  861|    356|          }
  862|  2.28k|        }
  863|       |
  864|  2.12k|        state = pkey_or_name;
  865|  2.12k|        buf_used = 0;
  866|  2.12k|        break;
  867|       |
  868|  43.8k|      default:
  ------------------
  |  Branch (868:7): [True: 43.8k, False: 10.9k]
  ------------------
  869|  43.8k|        if (buf_used == sizeof(buf) - 1) {
  ------------------
  |  Branch (869:13): [True: 200, False: 43.6k]
  ------------------
  870|    200|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|    200|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  871|    200|          ERR_add_error_dataf("substring too long at offset %zu", offset);
  872|    200|          return false;
  873|    200|        }
  874|       |
  875|  43.6k|        if (OPENSSL_isalnum(c) || c == '-' || c == '_') {
  ------------------
  |  Branch (875:13): [True: 39.6k, False: 4.05k]
  |  Branch (875:35): [True: 984, False: 3.07k]
  |  Branch (875:47): [True: 1.26k, False: 1.80k]
  ------------------
  876|  41.8k|          buf[buf_used++] = c;
  877|  41.8k|        } else {
  878|  1.80k|          OPENSSL_PUT_ERROR(SSL, SSL_R_INVALID_SIGNATURE_ALGORITHM);
  ------------------
  |  |  441|  1.80k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  879|  1.80k|          ERR_add_error_dataf("invalid character 0x%02x at offest %zu", c,
  880|  1.80k|                              offset);
  881|  1.80k|          return false;
  882|  1.80k|        }
  883|  54.8k|    }
  884|  54.8k|  }
  885|       |
  886|    698|  assert(out_i == out->size());
  887|      0|  return true;
  888|  7.89k|}

SSL_CTX_flush_sessions:
 1298|  9.18k|void SSL_CTX_flush_sessions(SSL_CTX *ctx, uint64_t time) {
 1299|  9.18k|  TIMEOUT_PARAM tp;
 1300|       |
 1301|  9.18k|  tp.ctx = ctx;
 1302|  9.18k|  tp.cache = ctx->sessions;
 1303|  9.18k|  if (tp.cache == NULL) {
  ------------------
  |  Branch (1303:7): [True: 0, False: 9.18k]
  ------------------
 1304|      0|    return;
 1305|      0|  }
 1306|  9.18k|  tp.time = time;
 1307|  9.18k|  MutexWriteLock lock(&ctx->lock);
 1308|  9.18k|  lh_SSL_SESSION_doall_arg(tp.cache, timeout_doall_arg, &tp);
 1309|  9.18k|}

_ZN4bssl13SSLTranscriptC2Ev:
  147|  9.66k|SSLTranscript::SSLTranscript() {}
_ZN4bssl13SSLTranscriptD2Ev:
  149|  9.66k|SSLTranscript::~SSLTranscript() {}
_ZN4bssl13SSLTranscript4InitEv:
  151|  4.83k|bool SSLTranscript::Init() {
  152|  4.83k|  buffer_.reset(BUF_MEM_new());
  153|  4.83k|  if (!buffer_) {
  ------------------
  |  Branch (153:7): [True: 0, False: 4.83k]
  ------------------
  154|      0|    return false;
  155|      0|  }
  156|       |
  157|  4.83k|  hash_.Reset();
  158|  4.83k|  return true;
  159|  4.83k|}

_ZN4bssl30ssl_protocol_version_from_wireEPtt:
   31|  31.3k|bool ssl_protocol_version_from_wire(uint16_t *out, uint16_t version) {
   32|  31.3k|  switch (version) {
   33|    621|    case TLS1_VERSION:
  ------------------
  |  |  645|    621|#define TLS1_VERSION 0x0301
  ------------------
  |  Branch (33:5): [True: 621, False: 30.7k]
  ------------------
   34|  1.29k|    case TLS1_1_VERSION:
  ------------------
  |  |  646|  1.29k|#define TLS1_1_VERSION 0x0302
  ------------------
  |  Branch (34:5): [True: 672, False: 30.6k]
  ------------------
   35|  2.00k|    case TLS1_2_VERSION:
  ------------------
  |  |  647|  2.00k|#define TLS1_2_VERSION 0x0303
  ------------------
  |  Branch (35:5): [True: 716, False: 30.6k]
  ------------------
   36|  2.49k|    case TLS1_3_VERSION:
  ------------------
  |  |  648|  2.49k|#define TLS1_3_VERSION 0x0304
  ------------------
  |  Branch (36:5): [True: 486, False: 30.8k]
  ------------------
   37|  2.49k|      *out = version;
   38|  2.49k|      return true;
   39|       |
   40|    473|    case DTLS1_VERSION:
  ------------------
  |  |  650|    473|#define DTLS1_VERSION 0xfeff
  ------------------
  |  Branch (40:5): [True: 473, False: 30.8k]
  ------------------
   41|       |      // DTLS 1.0 is analogous to TLS 1.1, not TLS 1.0.
   42|    473|      *out = TLS1_1_VERSION;
  ------------------
  |  |  646|    473|#define TLS1_1_VERSION 0x0302
  ------------------
   43|    473|      return true;
   44|       |
   45|    514|    case DTLS1_2_VERSION:
  ------------------
  |  |  651|    514|#define DTLS1_2_VERSION 0xfefd
  ------------------
  |  Branch (45:5): [True: 514, False: 30.8k]
  ------------------
   46|    514|      *out = TLS1_2_VERSION;
  ------------------
  |  |  647|    514|#define TLS1_2_VERSION 0x0303
  ------------------
   47|    514|      return true;
   48|       |
   49|  27.8k|    default:
  ------------------
  |  Branch (49:5): [True: 27.8k, False: 3.48k]
  ------------------
   50|  27.8k|      return false;
   51|  31.3k|  }
   52|  31.3k|}
_ZN4bssl27ssl_method_supports_versionEPKNS_19SSL_PROTOCOL_METHODEt:
   76|  3.48k|                                 uint16_t version) {
   77|  10.3k|  for (uint16_t supported : get_method_versions(method)) {
  ------------------
  |  Branch (77:27): [True: 10.3k, False: 987]
  ------------------
   78|  10.3k|    if (supported == version) {
  ------------------
  |  Branch (78:9): [True: 2.49k, False: 7.87k]
  ------------------
   79|  2.49k|      return true;
   80|  2.49k|    }
   81|  10.3k|  }
   82|    987|  return false;
   83|  3.48k|}
SSL_CTX_set_min_proto_version:
  337|  13.9k|int SSL_CTX_set_min_proto_version(SSL_CTX *ctx, uint16_t version) {
  338|  13.9k|  return set_min_version(ctx->method, &ctx->conf_min_version, version);
  339|  13.9k|}
SSL_CTX_set_max_proto_version:
  341|  30.4k|int SSL_CTX_set_max_proto_version(SSL_CTX *ctx, uint16_t version) {
  342|  30.4k|  return set_max_version(ctx->method, &ctx->conf_max_version, version);
  343|  30.4k|}
ssl_versions.cc:_ZN4bsslL19get_method_versionsEPKNS_19SSL_PROTOCOL_METHODE:
   70|  3.48k|    const SSL_PROTOCOL_METHOD *method) {
   71|  3.48k|  return method->is_dtls ? Span<const uint16_t>(kDTLSVersions)
  ------------------
  |  Branch (71:10): [True: 0, False: 3.48k]
  ------------------
   72|  3.48k|                         : Span<const uint16_t>(kTLSVersions);
   73|  3.48k|}
ssl_versions.cc:_ZN4bsslL15set_min_versionEPKNS_19SSL_PROTOCOL_METHODEPtt:
  142|  13.9k|                            uint16_t version) {
  143|       |  // Zero is interpreted as the default minimum version.
  144|  13.9k|  if (version == 0) {
  ------------------
  |  Branch (144:7): [True: 5.50k, False: 8.47k]
  ------------------
  145|  5.50k|    *out = method->is_dtls ? DTLS1_VERSION : TLS1_VERSION;
  ------------------
  |  |  650|      0|#define DTLS1_VERSION 0xfeff
  ------------------
                  *out = method->is_dtls ? DTLS1_VERSION : TLS1_VERSION;
  ------------------
  |  |  645|  11.0k|#define TLS1_VERSION 0x0301
  ------------------
  |  Branch (145:12): [True: 0, False: 5.50k]
  ------------------
  146|  5.50k|    return true;
  147|  5.50k|  }
  148|       |
  149|  8.47k|  return set_version_bound(method, out, version);
  150|  13.9k|}
ssl_versions.cc:_ZN4bsslL17set_version_boundEPKNS_19SSL_PROTOCOL_METHODEPtt:
  130|  31.3k|                              uint16_t version) {
  131|  31.3k|  if (!api_version_to_wire(&version, version) ||
  ------------------
  |  Branch (131:7): [True: 27.8k, False: 3.48k]
  ------------------
  132|  31.3k|      !ssl_method_supports_version(method, version)) {
  ------------------
  |  Branch (132:7): [True: 987, False: 2.49k]
  ------------------
  133|  28.8k|    OPENSSL_PUT_ERROR(SSL, SSL_R_UNKNOWN_SSL_VERSION);
  ------------------
  |  |  441|  28.8k|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  134|  28.8k|    return false;
  135|  28.8k|  }
  136|       |
  137|  2.49k|  *out = version;
  138|  2.49k|  return true;
  139|  31.3k|}
ssl_versions.cc:_ZN4bsslL15set_max_versionEPKNS_19SSL_PROTOCOL_METHODEPtt:
  153|  30.4k|                            uint16_t version) {
  154|       |  // Zero is interpreted as the default maximum version.
  155|  30.4k|  if (version == 0) {
  ------------------
  |  Branch (155:7): [True: 7.60k, False: 22.8k]
  ------------------
  156|  7.60k|    *out = method->is_dtls ? DTLS1_2_VERSION : TLS1_3_VERSION;
  ------------------
  |  |  651|      0|#define DTLS1_2_VERSION 0xfefd
  ------------------
                  *out = method->is_dtls ? DTLS1_2_VERSION : TLS1_3_VERSION;
  ------------------
  |  |  648|  15.2k|#define TLS1_3_VERSION 0x0304
  ------------------
  |  Branch (156:12): [True: 0, False: 7.60k]
  ------------------
  157|  7.60k|    return true;
  158|  7.60k|  }
  159|       |
  160|  22.8k|  return set_version_bound(method, out, version);
  161|  30.4k|}
ssl_versions.cc:_ZN4bsslL19api_version_to_wireEPtt:
  118|  31.3k|static bool api_version_to_wire(uint16_t *out, uint16_t version) {
  119|       |  // Check it is a real protocol version.
  120|  31.3k|  uint16_t unused;
  121|  31.3k|  if (!ssl_protocol_version_from_wire(&unused, version)) {
  ------------------
  |  Branch (121:7): [True: 27.8k, False: 3.48k]
  ------------------
  122|  27.8k|    return false;
  123|  27.8k|  }
  124|       |
  125|  3.48k|  *out = version;
  126|  3.48k|  return true;
  127|  31.3k|}

SSL_CTX_use_certificate:
  751|  12.9k|int SSL_CTX_use_certificate(SSL_CTX *ctx, X509 *x) {
  752|  12.9k|  check_ssl_ctx_x509_method(ctx);
  753|  12.9k|  return ssl_use_certificate(ctx->cert.get(), x);
  754|  12.9k|}
SSL_CTX_get0_certificate:
  793|  6.36k|X509 *SSL_CTX_get0_certificate(const SSL_CTX *ctx) {
  794|  6.36k|  check_ssl_ctx_x509_method(ctx);
  795|  6.36k|  MutexWriteLock lock(const_cast<CRYPTO_MUTEX*>(&ctx->lock));
  796|  6.36k|  return ssl_cert_get0_leaf(ctx->cert.get());
  797|  6.36k|}
SSL_CTX_set0_chain:
  860|  34.5k|int SSL_CTX_set0_chain(SSL_CTX *ctx, STACK_OF(X509) *chain) {
  861|  34.5k|  check_ssl_ctx_x509_method(ctx);
  862|  34.5k|  return ssl_cert_set0_chain(ctx->cert.get(), chain);
  863|  34.5k|}
SSL_CTX_set1_chain:
  865|  10.2k|int SSL_CTX_set1_chain(SSL_CTX *ctx, STACK_OF(X509) *chain) {
  866|  10.2k|  check_ssl_ctx_x509_method(ctx);
  867|  10.2k|  return ssl_cert_set1_chain(ctx->cert.get(), chain);
  868|  10.2k|}
SSL_CTX_add1_chain_cert:
  891|  10.6k|int SSL_CTX_add1_chain_cert(SSL_CTX *ctx, X509 *x509) {
  892|  10.6k|  check_ssl_ctx_x509_method(ctx);
  893|  10.6k|  return ssl_cert_add1_chain_cert(ctx->cert.get(), x509);
  894|  10.6k|}
SSL_CTX_clear_chain_certs:
  917|  34.5k|int SSL_CTX_clear_chain_certs(SSL_CTX *ctx) {
  918|  34.5k|  check_ssl_ctx_x509_method(ctx);
  919|  34.5k|  return SSL_CTX_set0_chain(ctx, NULL);
  ------------------
  |  | 5440|  34.5k|#define SSL_CTX_set0_chain SSL_CTX_set0_chain
  ------------------
  920|  34.5k|}
SSL_CTX_clear_extra_chain_certs:
  922|  28.3k|int SSL_CTX_clear_extra_chain_certs(SSL_CTX *ctx) {
  923|  28.3k|  check_ssl_ctx_x509_method(ctx);
  924|  28.3k|  return SSL_CTX_clear_chain_certs(ctx);
  ------------------
  |  | 5425|  28.3k|#define SSL_CTX_clear_chain_certs SSL_CTX_clear_chain_certs
  ------------------
  925|  28.3k|}
SSL_CTX_get0_chain_certs:
  961|  6.43k|int SSL_CTX_get0_chain_certs(const SSL_CTX *ctx, STACK_OF(X509) **out_chain) {
  962|  6.43k|  check_ssl_ctx_x509_method(ctx);
  963|  6.43k|  MutexWriteLock lock(const_cast<CRYPTO_MUTEX*>(&ctx->lock));
  964|  6.43k|  if (!ssl_cert_cache_chain_certs(ctx->cert.get())) {
  ------------------
  |  Branch (964:7): [True: 0, False: 6.43k]
  ------------------
  965|      0|    *out_chain = NULL;
  966|      0|    return 0;
  967|      0|  }
  968|       |
  969|  6.43k|  *out_chain = ctx->cert->x509_chain;
  970|  6.43k|  return 1;
  971|  6.43k|}
SSL_CTX_add_client_CA:
 1210|  3.63k|int SSL_CTX_add_client_CA(SSL_CTX *ctx, X509 *x509) {
 1211|  3.63k|  check_ssl_ctx_x509_method(ctx);
 1212|  3.63k|  if (!add_client_CA(&ctx->client_CA, x509, ctx->pool)) {
  ------------------
  |  Branch (1212:7): [True: 0, False: 3.63k]
  ------------------
 1213|      0|    return 0;
 1214|      0|  }
 1215|       |
 1216|  3.63k|  ssl_crypto_x509_ssl_ctx_flush_cached_client_CA(ctx);
 1217|  3.63k|  return 1;
 1218|  3.63k|}
ssl_x509.cc:_ZN4bsslL26ssl_crypto_x509_cert_clearEPNS_4CERTE:
  262|  19.3k|static void ssl_crypto_x509_cert_clear(CERT *cert) {
  263|  19.3k|  ssl_crypto_x509_cert_flush_cached_leaf(cert);
  264|  19.3k|  ssl_crypto_x509_cert_flush_cached_chain(cert);
  265|       |
  266|  19.3k|  X509_free(cert->x509_stash);
  267|  19.3k|  cert->x509_stash = nullptr;
  268|  19.3k|}
ssl_x509.cc:_ZN4bsslL25ssl_crypto_x509_cert_freeEPNS_4CERTE:
  270|  9.66k|static void ssl_crypto_x509_cert_free(CERT *cert) {
  271|  9.66k|  ssl_crypto_x509_cert_clear(cert);
  272|  9.66k|  X509_STORE_free(cert->verify_store);
  273|  9.66k|}
ssl_x509.cc:_ZN4bsslL24ssl_crypto_x509_cert_dupEPNS_4CERTEPKS0_:
  275|  4.83k|static void ssl_crypto_x509_cert_dup(CERT *new_cert, const CERT *cert) {
  276|  4.83k|  if (cert->verify_store != nullptr) {
  ------------------
  |  Branch (276:7): [True: 0, False: 4.83k]
  ------------------
  277|      0|    X509_STORE_up_ref(cert->verify_store);
  278|      0|    new_cert->verify_store = cert->verify_store;
  279|      0|  }
  280|  4.83k|}
ssl_x509.cc:_ZN4bsslL39ssl_crypto_x509_cert_flush_cached_chainEPNS_4CERTE:
  242|  74.7k|static void ssl_crypto_x509_cert_flush_cached_chain(CERT *cert) {
  243|  74.7k|  sk_X509_pop_free(cert->x509_chain, X509_free);
  244|  74.7k|  cert->x509_chain = nullptr;
  245|  74.7k|}
ssl_x509.cc:_ZN4bsslL38ssl_crypto_x509_cert_flush_cached_leafEPNS_4CERTE:
  237|  32.2k|static void ssl_crypto_x509_cert_flush_cached_leaf(CERT *cert) {
  238|  32.2k|  X509_free(cert->x509_leaf);
  239|  32.2k|  cert->x509_leaf = nullptr;
  240|  32.2k|}
ssl_x509.cc:_ZN4bsslL40ssl_crypto_x509_hs_flush_cached_ca_namesEPNS_13SSL_HANDSHAKEE:
  422|  4.83k|static void ssl_crypto_x509_hs_flush_cached_ca_names(SSL_HANDSHAKE *hs) {
  423|  4.83k|  sk_X509_NAME_pop_free(hs->cached_x509_ca_names, X509_NAME_free);
  424|  4.83k|  hs->cached_x509_ca_names = nullptr;
  425|  4.83k|}
ssl_x509.cc:_ZN4bsslL23ssl_crypto_x509_ssl_newEPNS_13SSL_HANDSHAKEE:
  427|  4.83k|static bool ssl_crypto_x509_ssl_new(SSL_HANDSHAKE *hs) {
  428|  4.83k|  hs->config->param = X509_VERIFY_PARAM_new();
  429|  4.83k|  if (hs->config->param == nullptr) {
  ------------------
  |  Branch (429:7): [True: 0, False: 4.83k]
  ------------------
  430|      0|    return false;
  431|      0|  }
  432|  4.83k|  X509_VERIFY_PARAM_inherit(hs->config->param, hs->ssl->ctx->param);
  433|  4.83k|  return true;
  434|  4.83k|}
ssl_x509.cc:_ZN4bsslL31ssl_crypto_x509_ssl_config_freeEPNS_10SSL_CONFIGE:
  441|  4.83k|static void ssl_crypto_x509_ssl_config_free(SSL_CONFIG *cfg) {
  442|  4.83k|  sk_X509_NAME_pop_free(cfg->cached_x509_client_CA, X509_NAME_free);
  443|  4.83k|  cfg->cached_x509_client_CA = nullptr;
  444|  4.83k|  X509_VERIFY_PARAM_free(cfg->param);
  445|  4.83k|}
ssl_x509.cc:_ZN4bsslL18ssl_cert_set_chainEPNS_4CERTEP13stack_st_X509:
  202|  44.7k|static bool ssl_cert_set_chain(CERT *cert, STACK_OF(X509) *chain) {
  203|  44.7k|  UniquePtr<STACK_OF(CRYPTO_BUFFER)> new_chain;
  204|       |
  205|  44.7k|  if (cert->chain != nullptr) {
  ------------------
  |  Branch (205:7): [True: 39.2k, False: 5.55k]
  ------------------
  206|  39.2k|    new_chain.reset(sk_CRYPTO_BUFFER_new_null());
  207|  39.2k|    if (!new_chain) {
  ------------------
  |  Branch (207:9): [True: 0, False: 39.2k]
  ------------------
  208|      0|      return false;
  209|      0|    }
  210|       |
  211|       |    // |leaf| might be NULL if it's a “leafless” chain.
  212|  39.2k|    CRYPTO_BUFFER *leaf = sk_CRYPTO_BUFFER_value(cert->chain.get(), 0);
  213|  39.2k|    if (!PushToStack(new_chain.get(), UpRef(leaf))) {
  ------------------
  |  Branch (213:9): [True: 0, False: 39.2k]
  ------------------
  214|      0|      return false;
  215|      0|    }
  216|  39.2k|  }
  217|       |
  218|  44.7k|  for (X509 *x509 : chain) {
  ------------------
  |  Branch (218:19): [True: 10.2k, False: 44.7k]
  ------------------
  219|  10.2k|    if (!new_chain) {
  ------------------
  |  Branch (219:9): [True: 173, False: 10.0k]
  ------------------
  220|    173|      new_chain = new_leafless_chain();
  221|    173|      if (!new_chain) {
  ------------------
  |  Branch (221:11): [True: 0, False: 173]
  ------------------
  222|      0|        return false;
  223|      0|      }
  224|    173|    }
  225|       |
  226|  10.2k|    UniquePtr<CRYPTO_BUFFER> buffer = x509_to_buffer(x509);
  227|  10.2k|    if (!buffer ||
  ------------------
  |  Branch (227:9): [True: 0, False: 10.2k]
  |  Branch (227:9): [True: 0, False: 10.2k]
  ------------------
  228|  10.2k|        !PushToStack(new_chain.get(), std::move(buffer))) {
  ------------------
  |  Branch (228:9): [True: 0, False: 10.2k]
  ------------------
  229|      0|      return false;
  230|      0|    }
  231|  10.2k|  }
  232|       |
  233|  44.7k|  cert->chain = std::move(new_chain);
  234|  44.7k|  return true;
  235|  44.7k|}
ssl_x509.cc:_ZN4bsslL18new_leafless_chainEv:
  188|    614|static UniquePtr<STACK_OF(CRYPTO_BUFFER)> new_leafless_chain(void) {
  189|    614|  UniquePtr<STACK_OF(CRYPTO_BUFFER)> chain(sk_CRYPTO_BUFFER_new_null());
  190|    614|  if (!chain ||
  ------------------
  |  Branch (190:7): [True: 0, False: 614]
  ------------------
  191|    614|      !sk_CRYPTO_BUFFER_push(chain.get(), nullptr)) {
  ------------------
  |  Branch (191:7): [True: 0, False: 614]
  ------------------
  192|      0|    return nullptr;
  193|      0|  }
  194|       |
  195|    614|  return chain;
  196|    614|}
ssl_x509.cc:_ZN4bsslL14x509_to_bufferEP7x509_st:
  174|  33.7k|static UniquePtr<CRYPTO_BUFFER> x509_to_buffer(X509 *x509) {
  175|  33.7k|  uint8_t *buf = NULL;
  176|  33.7k|  int cert_len = i2d_X509(x509, &buf);
  177|  33.7k|  if (cert_len <= 0) {
  ------------------
  |  Branch (177:7): [True: 0, False: 33.7k]
  ------------------
  178|      0|    return 0;
  179|      0|  }
  180|       |
  181|  33.7k|  UniquePtr<CRYPTO_BUFFER> buffer(CRYPTO_BUFFER_new(buf, cert_len, NULL));
  182|  33.7k|  OPENSSL_free(buf);
  183|       |
  184|  33.7k|  return buffer;
  185|  33.7k|}
ssl_x509.cc:_ZN4bsslL27ssl_crypto_x509_ssl_ctx_newEP10ssl_ctx_st:
  495|  4.83k|static bool ssl_crypto_x509_ssl_ctx_new(SSL_CTX *ctx) {
  496|  4.83k|  ctx->cert_store = X509_STORE_new();
  497|  4.83k|  ctx->param = X509_VERIFY_PARAM_new();
  498|  4.83k|  return (ctx->cert_store != nullptr && ctx->param != nullptr);
  ------------------
  |  Branch (498:11): [True: 4.83k, False: 0]
  |  Branch (498:41): [True: 4.83k, False: 0]
  ------------------
  499|  4.83k|}
ssl_x509.cc:_ZN4bsslL28ssl_crypto_x509_ssl_ctx_freeEP10ssl_ctx_st:
  501|  4.83k|static void ssl_crypto_x509_ssl_ctx_free(SSL_CTX *ctx) {
  502|  4.83k|  ssl_crypto_x509_ssl_ctx_flush_cached_client_CA(ctx);
  503|  4.83k|  X509_VERIFY_PARAM_free(ctx->param);
  504|  4.83k|  X509_STORE_free(ctx->cert_store);
  505|  4.83k|}
ssl_x509.cc:_ZN4bsslL46ssl_crypto_x509_ssl_ctx_flush_cached_client_CAEP10ssl_ctx_st:
  490|  8.46k|static void ssl_crypto_x509_ssl_ctx_flush_cached_client_CA(SSL_CTX *ctx) {
  491|  8.46k|  sk_X509_NAME_pop_free(ctx->cached_x509_client_CA, X509_NAME_free);
  492|  8.46k|  ctx->cached_x509_client_CA = nullptr;
  493|  8.46k|}
ssl_x509.cc:_ZN4bsslL25check_ssl_ctx_x509_methodEPK10ssl_ctx_st:
  168|   147k|static void check_ssl_ctx_x509_method(const SSL_CTX *ctx) {
  169|   147k|  assert(ctx == NULL || ctx->x509_method == &ssl_crypto_x509_method);
  170|   147k|}
ssl_x509.cc:_ZL19ssl_use_certificatePN4bssl4CERTEP7x509_st:
  729|  12.9k|static int ssl_use_certificate(CERT *cert, X509 *x) {
  730|  12.9k|  if (x == NULL) {
  ------------------
  |  Branch (730:7): [True: 0, False: 12.9k]
  ------------------
  731|      0|    OPENSSL_PUT_ERROR(SSL, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  441|      0|  ERR_put_error(ERR_LIB_##library, 0, reason, __FILE__, __LINE__)
  ------------------
  732|      0|    return 0;
  733|      0|  }
  734|       |
  735|  12.9k|  UniquePtr<CRYPTO_BUFFER> buffer = x509_to_buffer(x);
  736|  12.9k|  if (!buffer) {
  ------------------
  |  Branch (736:7): [True: 0, False: 12.9k]
  ------------------
  737|      0|    return 0;
  738|      0|  }
  739|       |
  740|  12.9k|  return ssl_set_cert(cert, std::move(buffer));
  741|  12.9k|}
ssl_x509.cc:_ZL18ssl_cert_get0_leafPN4bssl4CERTE:
  775|  6.36k|static X509 *ssl_cert_get0_leaf(CERT *cert) {
  776|  6.36k|  if (cert->x509_leaf == NULL &&
  ------------------
  |  Branch (776:7): [True: 4.54k, False: 1.82k]
  ------------------
  777|  6.36k|      !ssl_cert_cache_leaf_cert(cert)) {
  ------------------
  |  Branch (777:7): [True: 0, False: 4.54k]
  ------------------
  778|      0|    return NULL;
  779|      0|  }
  780|       |
  781|  6.36k|  return cert->x509_leaf;
  782|  6.36k|}
ssl_x509.cc:_ZL24ssl_cert_cache_leaf_certPN4bssl4CERTE:
  758|  4.54k|static int ssl_cert_cache_leaf_cert(CERT *cert) {
  759|  4.54k|  assert(cert->x509_method);
  760|       |
  761|  4.54k|  if (cert->x509_leaf != NULL ||
  ------------------
  |  Branch (761:7): [True: 0, False: 4.54k]
  ------------------
  762|  4.54k|      cert->chain == NULL) {
  ------------------
  |  Branch (762:7): [True: 1.25k, False: 3.28k]
  ------------------
  763|  1.25k|    return 1;
  764|  1.25k|  }
  765|       |
  766|  3.28k|  CRYPTO_BUFFER *leaf = sk_CRYPTO_BUFFER_value(cert->chain.get(), 0);
  767|  3.28k|  if (!leaf) {
  ------------------
  |  Branch (767:7): [True: 1.70k, False: 1.58k]
  ------------------
  768|  1.70k|    return 1;
  769|  1.70k|  }
  770|       |
  771|  1.58k|  cert->x509_leaf = X509_parse_from_buffer(leaf);
  772|  1.58k|  return cert->x509_leaf != NULL;
  773|  3.28k|}
ssl_x509.cc:_ZL19ssl_cert_set0_chainPN4bssl4CERTEP13stack_st_X509:
  799|  34.5k|static int ssl_cert_set0_chain(CERT *cert, STACK_OF(X509) *chain) {
  800|  34.5k|  if (!ssl_cert_set_chain(cert, chain)) {
  ------------------
  |  Branch (800:7): [True: 0, False: 34.5k]
  ------------------
  801|      0|    return 0;
  802|      0|  }
  803|       |
  804|  34.5k|  sk_X509_pop_free(chain, X509_free);
  805|  34.5k|  ssl_crypto_x509_cert_flush_cached_chain(cert);
  806|  34.5k|  return 1;
  807|  34.5k|}
ssl_x509.cc:_ZL19ssl_cert_set1_chainPN4bssl4CERTEP13stack_st_X509:
  809|  10.2k|static int ssl_cert_set1_chain(CERT *cert, STACK_OF(X509) *chain) {
  810|  10.2k|  if (!ssl_cert_set_chain(cert, chain)) {
  ------------------
  |  Branch (810:7): [True: 0, False: 10.2k]
  ------------------
  811|      0|    return 0;
  812|      0|  }
  813|       |
  814|  10.2k|  ssl_crypto_x509_cert_flush_cached_chain(cert);
  815|  10.2k|  return 1;
  816|  10.2k|}
ssl_x509.cc:_ZL20ssl_cert_append_certPN4bssl4CERTEP7x509_st:
  818|  10.6k|static int ssl_cert_append_cert(CERT *cert, X509 *x509) {
  819|  10.6k|  assert(cert->x509_method);
  820|       |
  821|      0|  UniquePtr<CRYPTO_BUFFER> buffer = x509_to_buffer(x509);
  822|  10.6k|  if (!buffer) {
  ------------------
  |  Branch (822:7): [True: 0, False: 10.6k]
  ------------------
  823|      0|    return 0;
  824|      0|  }
  825|       |
  826|  10.6k|  if (cert->chain != NULL) {
  ------------------
  |  Branch (826:7): [True: 10.1k, False: 441]
  ------------------
  827|  10.1k|    return PushToStack(cert->chain.get(), std::move(buffer));
  828|  10.1k|  }
  829|       |
  830|    441|  cert->chain = new_leafless_chain();
  831|    441|  if (!cert->chain ||
  ------------------
  |  Branch (831:7): [True: 0, False: 441]
  |  Branch (831:7): [True: 0, False: 441]
  ------------------
  832|    441|      !PushToStack(cert->chain.get(), std::move(buffer))) {
  ------------------
  |  Branch (832:7): [True: 0, False: 441]
  ------------------
  833|      0|    cert->chain.reset();
  834|      0|    return 0;
  835|      0|  }
  836|       |
  837|    441|  return 1;
  838|    441|}
ssl_x509.cc:_ZL24ssl_cert_add1_chain_certPN4bssl4CERTEP7x509_st:
  851|  10.6k|static int ssl_cert_add1_chain_cert(CERT *cert, X509 *x509) {
  852|  10.6k|  if (!ssl_cert_append_cert(cert, x509)) {
  ------------------
  |  Branch (852:7): [True: 0, False: 10.6k]
  ------------------
  853|      0|    return 0;
  854|      0|  }
  855|       |
  856|  10.6k|  ssl_crypto_x509_cert_flush_cached_chain(cert);
  857|  10.6k|  return 1;
  858|  10.6k|}
ssl_x509.cc:_ZL26ssl_cert_cache_chain_certsPN4bssl4CERTE:
  934|  6.43k|static int ssl_cert_cache_chain_certs(CERT *cert) {
  935|  6.43k|  assert(cert->x509_method);
  936|       |
  937|  6.43k|  if (cert->x509_chain != nullptr ||
  ------------------
  |  Branch (937:7): [True: 1.34k, False: 5.08k]
  ------------------
  938|  6.43k|      cert->chain == nullptr ||
  ------------------
  |  Branch (938:7): [True: 679, False: 4.40k]
  ------------------
  939|  6.43k|      sk_CRYPTO_BUFFER_num(cert->chain.get()) < 2) {
  ------------------
  |  Branch (939:7): [True: 1.60k, False: 2.80k]
  ------------------
  940|  3.63k|    return 1;
  941|  3.63k|  }
  942|       |
  943|  2.80k|  UniquePtr<STACK_OF(X509)> chain(sk_X509_new_null());
  944|  2.80k|  if (!chain) {
  ------------------
  |  Branch (944:7): [True: 0, False: 2.80k]
  ------------------
  945|      0|    return 0;
  946|      0|  }
  947|       |
  948|  21.3k|  for (size_t i = 1; i < sk_CRYPTO_BUFFER_num(cert->chain.get()); i++) {
  ------------------
  |  Branch (948:22): [True: 18.5k, False: 2.80k]
  ------------------
  949|  18.5k|    CRYPTO_BUFFER *buffer = sk_CRYPTO_BUFFER_value(cert->chain.get(), i);
  950|  18.5k|    UniquePtr<X509> x509(X509_parse_from_buffer(buffer));
  951|  18.5k|    if (!x509 ||
  ------------------
  |  Branch (951:9): [True: 0, False: 18.5k]
  |  Branch (951:9): [True: 0, False: 18.5k]
  ------------------
  952|  18.5k|        !PushToStack(chain.get(), std::move(x509))) {
  ------------------
  |  Branch (952:9): [True: 0, False: 18.5k]
  ------------------
  953|      0|      return 0;
  954|      0|    }
  955|  18.5k|  }
  956|       |
  957|  2.80k|  cert->x509_chain = chain.release();
  958|  2.80k|  return 1;
  959|  2.80k|}
ssl_x509.cc:_ZL13add_client_CAPNSt3__110unique_ptrI22stack_st_CRYPTO_BUFFERN4bssl8internal7DeleterEEEP7x509_stP21crypto_buffer_pool_st:
 1160|  3.63k|                         CRYPTO_BUFFER_POOL *pool) {
 1161|  3.63k|  if (x509 == NULL) {
  ------------------
  |  Branch (1161:7): [True: 0, False: 3.63k]
  ------------------
 1162|      0|    return 0;
 1163|      0|  }
 1164|       |
 1165|  3.63k|  uint8_t *outp = NULL;
 1166|  3.63k|  int len = i2d_X509_NAME(X509_get_subject_name(x509), &outp);
 1167|  3.63k|  if (len < 0) {
  ------------------
  |  Branch (1167:7): [True: 0, False: 3.63k]
  ------------------
 1168|      0|    return 0;
 1169|      0|  }
 1170|       |
 1171|  3.63k|  UniquePtr<CRYPTO_BUFFER> buffer(CRYPTO_BUFFER_new(outp, len, pool));
 1172|  3.63k|  OPENSSL_free(outp);
 1173|  3.63k|  if (!buffer) {
  ------------------
  |  Branch (1173:7): [True: 0, False: 3.63k]
  ------------------
 1174|      0|    return 0;
 1175|      0|  }
 1176|       |
 1177|  3.63k|  int alloced = 0;
 1178|  3.63k|  if (*names == nullptr) {
  ------------------
  |  Branch (1178:7): [True: 0, False: 3.63k]
  ------------------
 1179|      0|    names->reset(sk_CRYPTO_BUFFER_new_null());
 1180|      0|    alloced = 1;
 1181|       |
 1182|      0|    if (*names == NULL) {
  ------------------
  |  Branch (1182:9): [True: 0, False: 0]
  ------------------
 1183|      0|      return 0;
 1184|      0|    }
 1185|      0|  }
 1186|       |
 1187|  3.63k|  if (!PushToStack(names->get(), std::move(buffer))) {
  ------------------
  |  Branch (1187:7): [True: 0, False: 3.63k]
  ------------------
 1188|      0|    if (alloced) {
  ------------------
  |  Branch (1188:9): [True: 0, False: 0]
  ------------------
 1189|      0|      names->reset();
 1190|      0|    }
 1191|      0|    return 0;
 1192|      0|  }
 1193|       |
 1194|  3.63k|  return 1;
 1195|  3.63k|}

TLS_method:
  228|  4.83k|const SSL_METHOD *TLS_method(void) {
  229|  4.83k|  static const SSL_METHOD kMethod = {
  230|  4.83k|      0,
  231|  4.83k|      &kTLSProtocolMethod,
  232|  4.83k|      &ssl_crypto_x509_method,
  233|  4.83k|  };
  234|  4.83k|  return &kMethod;
  235|  4.83k|}

curve25519.c:fiat_25519_carry_mul:
  133|   141k|static FIAT_25519_FIAT_INLINE void fiat_25519_carry_mul(fiat_25519_tight_field_element out1, const fiat_25519_loose_field_element arg1, const fiat_25519_loose_field_element arg2) {
  134|   141k|  fiat_25519_uint128 x1;
  135|   141k|  fiat_25519_uint128 x2;
  136|   141k|  fiat_25519_uint128 x3;
  137|   141k|  fiat_25519_uint128 x4;
  138|   141k|  fiat_25519_uint128 x5;
  139|   141k|  fiat_25519_uint128 x6;
  140|   141k|  fiat_25519_uint128 x7;
  141|   141k|  fiat_25519_uint128 x8;
  142|   141k|  fiat_25519_uint128 x9;
  143|   141k|  fiat_25519_uint128 x10;
  144|   141k|  fiat_25519_uint128 x11;
  145|   141k|  fiat_25519_uint128 x12;
  146|   141k|  fiat_25519_uint128 x13;
  147|   141k|  fiat_25519_uint128 x14;
  148|   141k|  fiat_25519_uint128 x15;
  149|   141k|  fiat_25519_uint128 x16;
  150|   141k|  fiat_25519_uint128 x17;
  151|   141k|  fiat_25519_uint128 x18;
  152|   141k|  fiat_25519_uint128 x19;
  153|   141k|  fiat_25519_uint128 x20;
  154|   141k|  fiat_25519_uint128 x21;
  155|   141k|  fiat_25519_uint128 x22;
  156|   141k|  fiat_25519_uint128 x23;
  157|   141k|  fiat_25519_uint128 x24;
  158|   141k|  fiat_25519_uint128 x25;
  159|   141k|  fiat_25519_uint128 x26;
  160|   141k|  uint64_t x27;
  161|   141k|  uint64_t x28;
  162|   141k|  fiat_25519_uint128 x29;
  163|   141k|  fiat_25519_uint128 x30;
  164|   141k|  fiat_25519_uint128 x31;
  165|   141k|  fiat_25519_uint128 x32;
  166|   141k|  fiat_25519_uint128 x33;
  167|   141k|  uint64_t x34;
  168|   141k|  uint64_t x35;
  169|   141k|  fiat_25519_uint128 x36;
  170|   141k|  uint64_t x37;
  171|   141k|  uint64_t x38;
  172|   141k|  fiat_25519_uint128 x39;
  173|   141k|  uint64_t x40;
  174|   141k|  uint64_t x41;
  175|   141k|  fiat_25519_uint128 x42;
  176|   141k|  uint64_t x43;
  177|   141k|  uint64_t x44;
  178|   141k|  uint64_t x45;
  179|   141k|  uint64_t x46;
  180|   141k|  uint64_t x47;
  181|   141k|  uint64_t x48;
  182|   141k|  uint64_t x49;
  183|   141k|  fiat_25519_uint1 x50;
  184|   141k|  uint64_t x51;
  185|   141k|  uint64_t x52;
  186|   141k|  x1 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[4]) * UINT8_C(0x13)));
  187|   141k|  x2 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[3]) * UINT8_C(0x13)));
  188|   141k|  x3 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[2]) * UINT8_C(0x13)));
  189|   141k|  x4 = ((fiat_25519_uint128)(arg1[4]) * ((arg2[1]) * UINT8_C(0x13)));
  190|   141k|  x5 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[4]) * UINT8_C(0x13)));
  191|   141k|  x6 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[3]) * UINT8_C(0x13)));
  192|   141k|  x7 = ((fiat_25519_uint128)(arg1[3]) * ((arg2[2]) * UINT8_C(0x13)));
  193|   141k|  x8 = ((fiat_25519_uint128)(arg1[2]) * ((arg2[4]) * UINT8_C(0x13)));
  194|   141k|  x9 = ((fiat_25519_uint128)(arg1[2]) * ((arg2[3]) * UINT8_C(0x13)));
  195|   141k|  x10 = ((fiat_25519_uint128)(arg1[1]) * ((arg2[4]) * UINT8_C(0x13)));
  196|   141k|  x11 = ((fiat_25519_uint128)(arg1[4]) * (arg2[0]));
  197|   141k|  x12 = ((fiat_25519_uint128)(arg1[3]) * (arg2[1]));
  198|   141k|  x13 = ((fiat_25519_uint128)(arg1[3]) * (arg2[0]));
  199|   141k|  x14 = ((fiat_25519_uint128)(arg1[2]) * (arg2[2]));
  200|   141k|  x15 = ((fiat_25519_uint128)(arg1[2]) * (arg2[1]));
  201|   141k|  x16 = ((fiat_25519_uint128)(arg1[2]) * (arg2[0]));
  202|   141k|  x17 = ((fiat_25519_uint128)(arg1[1]) * (arg2[3]));
  203|   141k|  x18 = ((fiat_25519_uint128)(arg1[1]) * (arg2[2]));
  204|   141k|  x19 = ((fiat_25519_uint128)(arg1[1]) * (arg2[1]));
  205|   141k|  x20 = ((fiat_25519_uint128)(arg1[1]) * (arg2[0]));
  206|   141k|  x21 = ((fiat_25519_uint128)(arg1[0]) * (arg2[4]));
  207|   141k|  x22 = ((fiat_25519_uint128)(arg1[0]) * (arg2[3]));
  208|   141k|  x23 = ((fiat_25519_uint128)(arg1[0]) * (arg2[2]));
  209|   141k|  x24 = ((fiat_25519_uint128)(arg1[0]) * (arg2[1]));
  210|   141k|  x25 = ((fiat_25519_uint128)(arg1[0]) * (arg2[0]));
  211|   141k|  x26 = (x25 + (x10 + (x9 + (x7 + x4))));
  212|   141k|  x27 = (uint64_t)(x26 >> 51);
  213|   141k|  x28 = (uint64_t)(x26 & UINT64_C(0x7ffffffffffff));
  214|   141k|  x29 = (x21 + (x17 + (x14 + (x12 + x11))));
  215|   141k|  x30 = (x22 + (x18 + (x15 + (x13 + x1))));
  216|   141k|  x31 = (x23 + (x19 + (x16 + (x5 + x2))));
  217|   141k|  x32 = (x24 + (x20 + (x8 + (x6 + x3))));
  218|   141k|  x33 = (x27 + x32);
  219|   141k|  x34 = (uint64_t)(x33 >> 51);
  220|   141k|  x35 = (uint64_t)(x33 & UINT64_C(0x7ffffffffffff));
  221|   141k|  x36 = (x34 + x31);
  222|   141k|  x37 = (uint64_t)(x36 >> 51);
  223|   141k|  x38 = (uint64_t)(x36 & UINT64_C(0x7ffffffffffff));
  224|   141k|  x39 = (x37 + x30);
  225|   141k|  x40 = (uint64_t)(x39 >> 51);
  226|   141k|  x41 = (uint64_t)(x39 & UINT64_C(0x7ffffffffffff));
  227|   141k|  x42 = (x40 + x29);
  228|   141k|  x43 = (uint64_t)(x42 >> 51);
  229|   141k|  x44 = (uint64_t)(x42 & UINT64_C(0x7ffffffffffff));
  230|   141k|  x45 = (x43 * UINT8_C(0x13));
  231|   141k|  x46 = (x28 + x45);
  232|   141k|  x47 = (x46 >> 51);
  233|   141k|  x48 = (x46 & UINT64_C(0x7ffffffffffff));
  234|   141k|  x49 = (x47 + x35);
  235|   141k|  x50 = (fiat_25519_uint1)(x49 >> 51);
  236|   141k|  x51 = (x49 & UINT64_C(0x7ffffffffffff));
  237|   141k|  x52 = (x50 + x38);
  238|   141k|  out1[0] = x48;
  239|   141k|  out1[1] = x51;
  240|   141k|  out1[2] = x52;
  241|   141k|  out1[3] = x41;
  242|   141k|  out1[4] = x44;
  243|   141k|}
curve25519.c:fiat_25519_to_bytes:
  514|  11.7k|static FIAT_25519_FIAT_INLINE void fiat_25519_to_bytes(uint8_t out1[32], const fiat_25519_tight_field_element arg1) {
  515|  11.7k|  uint64_t x1;
  516|  11.7k|  fiat_25519_uint1 x2;
  517|  11.7k|  uint64_t x3;
  518|  11.7k|  fiat_25519_uint1 x4;
  519|  11.7k|  uint64_t x5;
  520|  11.7k|  fiat_25519_uint1 x6;
  521|  11.7k|  uint64_t x7;
  522|  11.7k|  fiat_25519_uint1 x8;
  523|  11.7k|  uint64_t x9;
  524|  11.7k|  fiat_25519_uint1 x10;
  525|  11.7k|  uint64_t x11;
  526|  11.7k|  uint64_t x12;
  527|  11.7k|  fiat_25519_uint1 x13;
  528|  11.7k|  uint64_t x14;
  529|  11.7k|  fiat_25519_uint1 x15;
  530|  11.7k|  uint64_t x16;
  531|  11.7k|  fiat_25519_uint1 x17;
  532|  11.7k|  uint64_t x18;
  533|  11.7k|  fiat_25519_uint1 x19;
  534|  11.7k|  uint64_t x20;
  535|  11.7k|  fiat_25519_uint1 x21;
  536|  11.7k|  uint64_t x22;
  537|  11.7k|  uint64_t x23;
  538|  11.7k|  uint64_t x24;
  539|  11.7k|  uint64_t x25;
  540|  11.7k|  uint8_t x26;
  541|  11.7k|  uint64_t x27;
  542|  11.7k|  uint8_t x28;
  543|  11.7k|  uint64_t x29;
  544|  11.7k|  uint8_t x30;
  545|  11.7k|  uint64_t x31;
  546|  11.7k|  uint8_t x32;
  547|  11.7k|  uint64_t x33;
  548|  11.7k|  uint8_t x34;
  549|  11.7k|  uint64_t x35;
  550|  11.7k|  uint8_t x36;
  551|  11.7k|  uint8_t x37;
  552|  11.7k|  uint64_t x38;
  553|  11.7k|  uint8_t x39;
  554|  11.7k|  uint64_t x40;
  555|  11.7k|  uint8_t x41;
  556|  11.7k|  uint64_t x42;
  557|  11.7k|  uint8_t x43;
  558|  11.7k|  uint64_t x44;
  559|  11.7k|  uint8_t x45;
  560|  11.7k|  uint64_t x46;
  561|  11.7k|  uint8_t x47;
  562|  11.7k|  uint64_t x48;
  563|  11.7k|  uint8_t x49;
  564|  11.7k|  uint8_t x50;
  565|  11.7k|  uint64_t x51;
  566|  11.7k|  uint8_t x52;
  567|  11.7k|  uint64_t x53;
  568|  11.7k|  uint8_t x54;
  569|  11.7k|  uint64_t x55;
  570|  11.7k|  uint8_t x56;
  571|  11.7k|  uint64_t x57;
  572|  11.7k|  uint8_t x58;
  573|  11.7k|  uint64_t x59;
  574|  11.7k|  uint8_t x60;
  575|  11.7k|  uint64_t x61;
  576|  11.7k|  uint8_t x62;
  577|  11.7k|  uint64_t x63;
  578|  11.7k|  uint8_t x64;
  579|  11.7k|  fiat_25519_uint1 x65;
  580|  11.7k|  uint64_t x66;
  581|  11.7k|  uint8_t x67;
  582|  11.7k|  uint64_t x68;
  583|  11.7k|  uint8_t x69;
  584|  11.7k|  uint64_t x70;
  585|  11.7k|  uint8_t x71;
  586|  11.7k|  uint64_t x72;
  587|  11.7k|  uint8_t x73;
  588|  11.7k|  uint64_t x74;
  589|  11.7k|  uint8_t x75;
  590|  11.7k|  uint64_t x76;
  591|  11.7k|  uint8_t x77;
  592|  11.7k|  uint8_t x78;
  593|  11.7k|  uint64_t x79;
  594|  11.7k|  uint8_t x80;
  595|  11.7k|  uint64_t x81;
  596|  11.7k|  uint8_t x82;
  597|  11.7k|  uint64_t x83;
  598|  11.7k|  uint8_t x84;
  599|  11.7k|  uint64_t x85;
  600|  11.7k|  uint8_t x86;
  601|  11.7k|  uint64_t x87;
  602|  11.7k|  uint8_t x88;
  603|  11.7k|  uint64_t x89;
  604|  11.7k|  uint8_t x90;
  605|  11.7k|  uint8_t x91;
  606|  11.7k|  fiat_25519_subborrowx_u51(&x1, &x2, 0x0, (arg1[0]), UINT64_C(0x7ffffffffffed));
  607|  11.7k|  fiat_25519_subborrowx_u51(&x3, &x4, x2, (arg1[1]), UINT64_C(0x7ffffffffffff));
  608|  11.7k|  fiat_25519_subborrowx_u51(&x5, &x6, x4, (arg1[2]), UINT64_C(0x7ffffffffffff));
  609|  11.7k|  fiat_25519_subborrowx_u51(&x7, &x8, x6, (arg1[3]), UINT64_C(0x7ffffffffffff));
  610|  11.7k|  fiat_25519_subborrowx_u51(&x9, &x10, x8, (arg1[4]), UINT64_C(0x7ffffffffffff));
  611|  11.7k|  fiat_25519_cmovznz_u64(&x11, x10, 0x0, UINT64_C(0xffffffffffffffff));
  612|  11.7k|  fiat_25519_addcarryx_u51(&x12, &x13, 0x0, x1, (x11 & UINT64_C(0x7ffffffffffed)));
  613|  11.7k|  fiat_25519_addcarryx_u51(&x14, &x15, x13, x3, (x11 & UINT64_C(0x7ffffffffffff)));
  614|  11.7k|  fiat_25519_addcarryx_u51(&x16, &x17, x15, x5, (x11 & UINT64_C(0x7ffffffffffff)));
  615|  11.7k|  fiat_25519_addcarryx_u51(&x18, &x19, x17, x7, (x11 & UINT64_C(0x7ffffffffffff)));
  616|  11.7k|  fiat_25519_addcarryx_u51(&x20, &x21, x19, x9, (x11 & UINT64_C(0x7ffffffffffff)));
  617|  11.7k|  x22 = (x20 << 4);
  618|  11.7k|  x23 = (x18 * (uint64_t)0x2);
  619|  11.7k|  x24 = (x16 << 6);
  620|  11.7k|  x25 = (x14 << 3);
  621|  11.7k|  x26 = (uint8_t)(x12 & UINT8_C(0xff));
  622|  11.7k|  x27 = (x12 >> 8);
  623|  11.7k|  x28 = (uint8_t)(x27 & UINT8_C(0xff));
  624|  11.7k|  x29 = (x27 >> 8);
  625|  11.7k|  x30 = (uint8_t)(x29 & UINT8_C(0xff));
  626|  11.7k|  x31 = (x29 >> 8);
  627|  11.7k|  x32 = (uint8_t)(x31 & UINT8_C(0xff));
  628|  11.7k|  x33 = (x31 >> 8);
  629|  11.7k|  x34 = (uint8_t)(x33 & UINT8_C(0xff));
  630|  11.7k|  x35 = (x33 >> 8);
  631|  11.7k|  x36 = (uint8_t)(x35 & UINT8_C(0xff));
  632|  11.7k|  x37 = (uint8_t)(x35 >> 8);
  633|  11.7k|  x38 = (x25 + (uint64_t)x37);
  634|  11.7k|  x39 = (uint8_t)(x38 & UINT8_C(0xff));
  635|  11.7k|  x40 = (x38 >> 8);
  636|  11.7k|  x41 = (uint8_t)(x40 & UINT8_C(0xff));
  637|  11.7k|  x42 = (x40 >> 8);
  638|  11.7k|  x43 = (uint8_t)(x42 & UINT8_C(0xff));
  639|  11.7k|  x44 = (x42 >> 8);
  640|  11.7k|  x45 = (uint8_t)(x44 & UINT8_C(0xff));
  641|  11.7k|  x46 = (x44 >> 8);
  642|  11.7k|  x47 = (uint8_t)(x46 & UINT8_C(0xff));
  643|  11.7k|  x48 = (x46 >> 8);
  644|  11.7k|  x49 = (uint8_t)(x48 & UINT8_C(0xff));
  645|  11.7k|  x50 = (uint8_t)(x48 >> 8);
  646|  11.7k|  x51 = (x24 + (uint64_t)x50);
  647|  11.7k|  x52 = (uint8_t)(x51 & UINT8_C(0xff));
  648|  11.7k|  x53 = (x51 >> 8);
  649|  11.7k|  x54 = (uint8_t)(x53 & UINT8_C(0xff));
  650|  11.7k|  x55 = (x53 >> 8);
  651|  11.7k|  x56 = (uint8_t)(x55 & UINT8_C(0xff));
  652|  11.7k|  x57 = (x55 >> 8);
  653|  11.7k|  x58 = (uint8_t)(x57 & UINT8_C(0xff));
  654|  11.7k|  x59 = (x57 >> 8);
  655|  11.7k|  x60 = (uint8_t)(x59 & UINT8_C(0xff));
  656|  11.7k|  x61 = (x59 >> 8);
  657|  11.7k|  x62 = (uint8_t)(x61 & UINT8_C(0xff));
  658|  11.7k|  x63 = (x61 >> 8);
  659|  11.7k|  x64 = (uint8_t)(x63 & UINT8_C(0xff));
  660|  11.7k|  x65 = (fiat_25519_uint1)(x63 >> 8);
  661|  11.7k|  x66 = (x23 + (uint64_t)x65);
  662|  11.7k|  x67 = (uint8_t)(x66 & UINT8_C(0xff));
  663|  11.7k|  x68 = (x66 >> 8);
  664|  11.7k|  x69 = (uint8_t)(x68 & UINT8_C(0xff));
  665|  11.7k|  x70 = (x68 >> 8);
  666|  11.7k|  x71 = (uint8_t)(x70 & UINT8_C(0xff));
  667|  11.7k|  x72 = (x70 >> 8);
  668|  11.7k|  x73 = (uint8_t)(x72 & UINT8_C(0xff));
  669|  11.7k|  x74 = (x72 >> 8);
  670|  11.7k|  x75 = (uint8_t)(x74 & UINT8_C(0xff));
  671|  11.7k|  x76 = (x74 >> 8);
  672|  11.7k|  x77 = (uint8_t)(x76 & UINT8_C(0xff));
  673|  11.7k|  x78 = (uint8_t)(x76 >> 8);
  674|  11.7k|  x79 = (x22 + (uint64_t)x78);
  675|  11.7k|  x80 = (uint8_t)(x79 & UINT8_C(0xff));
  676|  11.7k|  x81 = (x79 >> 8);
  677|  11.7k|  x82 = (uint8_t)(x81 & UINT8_C(0xff));
  678|  11.7k|  x83 = (x81 >> 8);
  679|  11.7k|  x84 = (uint8_t)(x83 & UINT8_C(0xff));
  680|  11.7k|  x85 = (x83 >> 8);
  681|  11.7k|  x86 = (uint8_t)(x85 & UINT8_C(0xff));
  682|  11.7k|  x87 = (x85 >> 8);
  683|  11.7k|  x88 = (uint8_t)(x87 & UINT8_C(0xff));
  684|  11.7k|  x89 = (x87 >> 8);
  685|  11.7k|  x90 = (uint8_t)(x89 & UINT8_C(0xff));
  686|  11.7k|  x91 = (uint8_t)(x89 >> 8);
  687|  11.7k|  out1[0] = x26;
  688|  11.7k|  out1[1] = x28;
  689|  11.7k|  out1[2] = x30;
  690|  11.7k|  out1[3] = x32;
  691|  11.7k|  out1[4] = x34;
  692|  11.7k|  out1[5] = x36;
  693|  11.7k|  out1[6] = x39;
  694|  11.7k|  out1[7] = x41;
  695|  11.7k|  out1[8] = x43;
  696|  11.7k|  out1[9] = x45;
  697|  11.7k|  out1[10] = x47;
  698|  11.7k|  out1[11] = x49;
  699|  11.7k|  out1[12] = x52;
  700|  11.7k|  out1[13] = x54;
  701|  11.7k|  out1[14] = x56;
  702|  11.7k|  out1[15] = x58;
  703|  11.7k|  out1[16] = x60;
  704|  11.7k|  out1[17] = x62;
  705|  11.7k|  out1[18] = x64;
  706|  11.7k|  out1[19] = x67;
  707|  11.7k|  out1[20] = x69;
  708|  11.7k|  out1[21] = x71;
  709|  11.7k|  out1[22] = x73;
  710|  11.7k|  out1[23] = x75;
  711|  11.7k|  out1[24] = x77;
  712|  11.7k|  out1[25] = x80;
  713|  11.7k|  out1[26] = x82;
  714|  11.7k|  out1[27] = x84;
  715|  11.7k|  out1[28] = x86;
  716|  11.7k|  out1[29] = x88;
  717|  11.7k|  out1[30] = x90;
  718|  11.7k|  out1[31] = x91;
  719|  11.7k|}
curve25519.c:fiat_25519_subborrowx_u51:
   92|  58.7k|static FIAT_25519_FIAT_INLINE void fiat_25519_subborrowx_u51(uint64_t* out1, fiat_25519_uint1* out2, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   93|  58.7k|  int64_t x1;
   94|  58.7k|  fiat_25519_int1 x2;
   95|  58.7k|  uint64_t x3;
   96|  58.7k|  x1 = ((int64_t)(arg2 - (int64_t)arg1) - (int64_t)arg3);
   97|  58.7k|  x2 = (fiat_25519_int1)(x1 >> 51);
   98|  58.7k|  x3 = (x1 & UINT64_C(0x7ffffffffffff));
   99|  58.7k|  *out1 = x3;
  100|  58.7k|  *out2 = (fiat_25519_uint1)(0x0 - x2);
  101|  58.7k|}
curve25519.c:fiat_25519_cmovznz_u64:
  116|  11.7k|static FIAT_25519_FIAT_INLINE void fiat_25519_cmovznz_u64(uint64_t* out1, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  117|  11.7k|  fiat_25519_uint1 x1;
  118|  11.7k|  uint64_t x2;
  119|  11.7k|  uint64_t x3;
  120|  11.7k|  x1 = (!(!arg1));
  121|  11.7k|  x2 = ((fiat_25519_int1)(0x0 - x1) & UINT64_C(0xffffffffffffffff));
  122|  11.7k|  x3 = ((fiat_25519_value_barrier_u64(x2) & arg3) | (fiat_25519_value_barrier_u64((~x2)) & arg2));
  123|  11.7k|  *out1 = x3;
  124|  11.7k|}
curve25519.c:fiat_25519_value_barrier_u64:
   42|  23.5k|static __inline__ uint64_t fiat_25519_value_barrier_u64(uint64_t a) {
   43|  23.5k|  __asm__("" : "+r"(a) : /* no inputs */);
   44|  23.5k|  return a;
   45|  23.5k|}
curve25519.c:fiat_25519_addcarryx_u51:
   66|  58.7k|static FIAT_25519_FIAT_INLINE void fiat_25519_addcarryx_u51(uint64_t* out1, fiat_25519_uint1* out2, fiat_25519_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   67|  58.7k|  uint64_t x1;
   68|  58.7k|  uint64_t x2;
   69|  58.7k|  fiat_25519_uint1 x3;
   70|  58.7k|  x1 = ((arg1 + arg2) + arg3);
   71|  58.7k|  x2 = (x1 & UINT64_C(0x7ffffffffffff));
   72|  58.7k|  x3 = (fiat_25519_uint1)(x1 >> 51);
   73|  58.7k|  *out1 = x2;
   74|  58.7k|  *out2 = x3;
   75|  58.7k|}
curve25519.c:fiat_25519_carry_square:
  252|  2.98M|static FIAT_25519_FIAT_INLINE void fiat_25519_carry_square(fiat_25519_tight_field_element out1, const fiat_25519_loose_field_element arg1) {
  253|  2.98M|  uint64_t x1;
  254|  2.98M|  uint64_t x2;
  255|  2.98M|  uint64_t x3;
  256|  2.98M|  uint64_t x4;
  257|  2.98M|  uint64_t x5;
  258|  2.98M|  uint64_t x6;
  259|  2.98M|  uint64_t x7;
  260|  2.98M|  uint64_t x8;
  261|  2.98M|  fiat_25519_uint128 x9;
  262|  2.98M|  fiat_25519_uint128 x10;
  263|  2.98M|  fiat_25519_uint128 x11;
  264|  2.98M|  fiat_25519_uint128 x12;
  265|  2.98M|  fiat_25519_uint128 x13;
  266|  2.98M|  fiat_25519_uint128 x14;
  267|  2.98M|  fiat_25519_uint128 x15;
  268|  2.98M|  fiat_25519_uint128 x16;
  269|  2.98M|  fiat_25519_uint128 x17;
  270|  2.98M|  fiat_25519_uint128 x18;
  271|  2.98M|  fiat_25519_uint128 x19;
  272|  2.98M|  fiat_25519_uint128 x20;
  273|  2.98M|  fiat_25519_uint128 x21;
  274|  2.98M|  fiat_25519_uint128 x22;
  275|  2.98M|  fiat_25519_uint128 x23;
  276|  2.98M|  fiat_25519_uint128 x24;
  277|  2.98M|  uint64_t x25;
  278|  2.98M|  uint64_t x26;
  279|  2.98M|  fiat_25519_uint128 x27;
  280|  2.98M|  fiat_25519_uint128 x28;
  281|  2.98M|  fiat_25519_uint128 x29;
  282|  2.98M|  fiat_25519_uint128 x30;
  283|  2.98M|  fiat_25519_uint128 x31;
  284|  2.98M|  uint64_t x32;
  285|  2.98M|  uint64_t x33;
  286|  2.98M|  fiat_25519_uint128 x34;
  287|  2.98M|  uint64_t x35;
  288|  2.98M|  uint64_t x36;
  289|  2.98M|  fiat_25519_uint128 x37;
  290|  2.98M|  uint64_t x38;
  291|  2.98M|  uint64_t x39;
  292|  2.98M|  fiat_25519_uint128 x40;
  293|  2.98M|  uint64_t x41;
  294|  2.98M|  uint64_t x42;
  295|  2.98M|  uint64_t x43;
  296|  2.98M|  uint64_t x44;
  297|  2.98M|  uint64_t x45;
  298|  2.98M|  uint64_t x46;
  299|  2.98M|  uint64_t x47;
  300|  2.98M|  fiat_25519_uint1 x48;
  301|  2.98M|  uint64_t x49;
  302|  2.98M|  uint64_t x50;
  303|  2.98M|  x1 = ((arg1[4]) * UINT8_C(0x13));
  304|  2.98M|  x2 = (x1 * 0x2);
  305|  2.98M|  x3 = ((arg1[4]) * 0x2);
  306|  2.98M|  x4 = ((arg1[3]) * UINT8_C(0x13));
  307|  2.98M|  x5 = (x4 * 0x2);
  308|  2.98M|  x6 = ((arg1[3]) * 0x2);
  309|  2.98M|  x7 = ((arg1[2]) * 0x2);
  310|  2.98M|  x8 = ((arg1[1]) * 0x2);
  311|  2.98M|  x9 = ((fiat_25519_uint128)(arg1[4]) * x1);
  312|  2.98M|  x10 = ((fiat_25519_uint128)(arg1[3]) * x2);
  313|  2.98M|  x11 = ((fiat_25519_uint128)(arg1[3]) * x4);
  314|  2.98M|  x12 = ((fiat_25519_uint128)(arg1[2]) * x2);
  315|  2.98M|  x13 = ((fiat_25519_uint128)(arg1[2]) * x5);
  316|  2.98M|  x14 = ((fiat_25519_uint128)(arg1[2]) * (arg1[2]));
  317|  2.98M|  x15 = ((fiat_25519_uint128)(arg1[1]) * x2);
  318|  2.98M|  x16 = ((fiat_25519_uint128)(arg1[1]) * x6);
  319|  2.98M|  x17 = ((fiat_25519_uint128)(arg1[1]) * x7);
  320|  2.98M|  x18 = ((fiat_25519_uint128)(arg1[1]) * (arg1[1]));
  321|  2.98M|  x19 = ((fiat_25519_uint128)(arg1[0]) * x3);
  322|  2.98M|  x20 = ((fiat_25519_uint128)(arg1[0]) * x6);
  323|  2.98M|  x21 = ((fiat_25519_uint128)(arg1[0]) * x7);
  324|  2.98M|  x22 = ((fiat_25519_uint128)(arg1[0]) * x8);
  325|  2.98M|  x23 = ((fiat_25519_uint128)(arg1[0]) * (arg1[0]));
  326|  2.98M|  x24 = (x23 + (x15 + x13));
  327|  2.98M|  x25 = (uint64_t)(x24 >> 51);
  328|  2.98M|  x26 = (uint64_t)(x24 & UINT64_C(0x7ffffffffffff));
  329|  2.98M|  x27 = (x19 + (x16 + x14));
  330|  2.98M|  x28 = (x20 + (x17 + x9));
  331|  2.98M|  x29 = (x21 + (x18 + x10));
  332|  2.98M|  x30 = (x22 + (x12 + x11));
  333|  2.98M|  x31 = (x25 + x30);
  334|  2.98M|  x32 = (uint64_t)(x31 >> 51);
  335|  2.98M|  x33 = (uint64_t)(x31 & UINT64_C(0x7ffffffffffff));
  336|  2.98M|  x34 = (x32 + x29);
  337|  2.98M|  x35 = (uint64_t)(x34 >> 51);
  338|  2.98M|  x36 = (uint64_t)(x34 & UINT64_C(0x7ffffffffffff));
  339|  2.98M|  x37 = (x35 + x28);
  340|  2.98M|  x38 = (uint64_t)(x37 >> 51);
  341|  2.98M|  x39 = (uint64_t)(x37 & UINT64_C(0x7ffffffffffff));
  342|  2.98M|  x40 = (x38 + x27);
  343|  2.98M|  x41 = (uint64_t)(x40 >> 51);
  344|  2.98M|  x42 = (uint64_t)(x40 & UINT64_C(0x7ffffffffffff));
  345|  2.98M|  x43 = (x41 * UINT8_C(0x13));
  346|  2.98M|  x44 = (x26 + x43);
  347|  2.98M|  x45 = (x44 >> 51);
  348|  2.98M|  x46 = (x44 & UINT64_C(0x7ffffffffffff));
  349|  2.98M|  x47 = (x45 + x33);
  350|  2.98M|  x48 = (fiat_25519_uint1)(x47 >> 51);
  351|  2.98M|  x49 = (x47 & UINT64_C(0x7ffffffffffff));
  352|  2.98M|  x50 = (x48 + x36);
  353|  2.98M|  out1[0] = x46;
  354|  2.98M|  out1[1] = x49;
  355|  2.98M|  out1[2] = x50;
  356|  2.98M|  out1[3] = x39;
  357|  2.98M|  out1[4] = x42;
  358|  2.98M|}
curve25519.c:fiat_25519_sub:
  431|  11.7k|static FIAT_25519_FIAT_INLINE void fiat_25519_sub(fiat_25519_loose_field_element out1, const fiat_25519_tight_field_element arg1, const fiat_25519_tight_field_element arg2) {
  432|  11.7k|  uint64_t x1;
  433|  11.7k|  uint64_t x2;
  434|  11.7k|  uint64_t x3;
  435|  11.7k|  uint64_t x4;
  436|  11.7k|  uint64_t x5;
  437|  11.7k|  x1 = ((UINT64_C(0xfffffffffffda) + (arg1[0])) - (arg2[0]));
  438|  11.7k|  x2 = ((UINT64_C(0xffffffffffffe) + (arg1[1])) - (arg2[1]));
  439|  11.7k|  x3 = ((UINT64_C(0xffffffffffffe) + (arg1[2])) - (arg2[2]));
  440|  11.7k|  x4 = ((UINT64_C(0xffffffffffffe) + (arg1[3])) - (arg2[3]));
  441|  11.7k|  x5 = ((UINT64_C(0xffffffffffffe) + (arg1[4])) - (arg2[4]));
  442|  11.7k|  out1[0] = x1;
  443|  11.7k|  out1[1] = x2;
  444|  11.7k|  out1[2] = x3;
  445|  11.7k|  out1[3] = x4;
  446|  11.7k|  out1[4] = x5;
  447|  11.7k|}
curve25519.c:fiat_25519_add:
  406|  11.7k|static FIAT_25519_FIAT_INLINE void fiat_25519_add(fiat_25519_loose_field_element out1, const fiat_25519_tight_field_element arg1, const fiat_25519_tight_field_element arg2) {
  407|  11.7k|  uint64_t x1;
  408|  11.7k|  uint64_t x2;
  409|  11.7k|  uint64_t x3;
  410|  11.7k|  uint64_t x4;
  411|  11.7k|  uint64_t x5;
  412|  11.7k|  x1 = ((arg1[0]) + (arg2[0]));
  413|  11.7k|  x2 = ((arg1[1]) + (arg2[1]));
  414|  11.7k|  x3 = ((arg1[2]) + (arg2[2]));
  415|  11.7k|  x4 = ((arg1[3]) + (arg2[3]));
  416|  11.7k|  x5 = ((arg1[4]) + (arg2[4]));
  417|  11.7k|  out1[0] = x1;
  418|  11.7k|  out1[1] = x2;
  419|  11.7k|  out1[2] = x3;
  420|  11.7k|  out1[3] = x4;
  421|  11.7k|  out1[4] = x5;
  422|  11.7k|}
curve25519.c:fiat_25519_from_bytes:
  730|  47.0k|static FIAT_25519_FIAT_INLINE void fiat_25519_from_bytes(fiat_25519_tight_field_element out1, const uint8_t arg1[32]) {
  731|  47.0k|  uint64_t x1;
  732|  47.0k|  uint64_t x2;
  733|  47.0k|  uint64_t x3;
  734|  47.0k|  uint64_t x4;
  735|  47.0k|  uint64_t x5;
  736|  47.0k|  uint64_t x6;
  737|  47.0k|  uint64_t x7;
  738|  47.0k|  uint64_t x8;
  739|  47.0k|  uint64_t x9;
  740|  47.0k|  uint64_t x10;
  741|  47.0k|  uint64_t x11;
  742|  47.0k|  uint64_t x12;
  743|  47.0k|  uint64_t x13;
  744|  47.0k|  uint64_t x14;
  745|  47.0k|  uint64_t x15;
  746|  47.0k|  uint64_t x16;
  747|  47.0k|  uint64_t x17;
  748|  47.0k|  uint64_t x18;
  749|  47.0k|  uint64_t x19;
  750|  47.0k|  uint64_t x20;
  751|  47.0k|  uint64_t x21;
  752|  47.0k|  uint64_t x22;
  753|  47.0k|  uint64_t x23;
  754|  47.0k|  uint64_t x24;
  755|  47.0k|  uint64_t x25;
  756|  47.0k|  uint64_t x26;
  757|  47.0k|  uint64_t x27;
  758|  47.0k|  uint64_t x28;
  759|  47.0k|  uint64_t x29;
  760|  47.0k|  uint64_t x30;
  761|  47.0k|  uint64_t x31;
  762|  47.0k|  uint8_t x32;
  763|  47.0k|  uint64_t x33;
  764|  47.0k|  uint64_t x34;
  765|  47.0k|  uint64_t x35;
  766|  47.0k|  uint64_t x36;
  767|  47.0k|  uint64_t x37;
  768|  47.0k|  uint64_t x38;
  769|  47.0k|  uint64_t x39;
  770|  47.0k|  uint8_t x40;
  771|  47.0k|  uint64_t x41;
  772|  47.0k|  uint64_t x42;
  773|  47.0k|  uint64_t x43;
  774|  47.0k|  uint64_t x44;
  775|  47.0k|  uint64_t x45;
  776|  47.0k|  uint64_t x46;
  777|  47.0k|  uint64_t x47;
  778|  47.0k|  uint8_t x48;
  779|  47.0k|  uint64_t x49;
  780|  47.0k|  uint64_t x50;
  781|  47.0k|  uint64_t x51;
  782|  47.0k|  uint64_t x52;
  783|  47.0k|  uint64_t x53;
  784|  47.0k|  uint64_t x54;
  785|  47.0k|  uint64_t x55;
  786|  47.0k|  uint64_t x56;
  787|  47.0k|  uint8_t x57;
  788|  47.0k|  uint64_t x58;
  789|  47.0k|  uint64_t x59;
  790|  47.0k|  uint64_t x60;
  791|  47.0k|  uint64_t x61;
  792|  47.0k|  uint64_t x62;
  793|  47.0k|  uint64_t x63;
  794|  47.0k|  uint64_t x64;
  795|  47.0k|  uint8_t x65;
  796|  47.0k|  uint64_t x66;
  797|  47.0k|  uint64_t x67;
  798|  47.0k|  uint64_t x68;
  799|  47.0k|  uint64_t x69;
  800|  47.0k|  uint64_t x70;
  801|  47.0k|  uint64_t x71;
  802|  47.0k|  x1 = ((uint64_t)(arg1[31]) << 44);
  803|  47.0k|  x2 = ((uint64_t)(arg1[30]) << 36);
  804|  47.0k|  x3 = ((uint64_t)(arg1[29]) << 28);
  805|  47.0k|  x4 = ((uint64_t)(arg1[28]) << 20);
  806|  47.0k|  x5 = ((uint64_t)(arg1[27]) << 12);
  807|  47.0k|  x6 = ((uint64_t)(arg1[26]) << 4);
  808|  47.0k|  x7 = ((uint64_t)(arg1[25]) << 47);
  809|  47.0k|  x8 = ((uint64_t)(arg1[24]) << 39);
  810|  47.0k|  x9 = ((uint64_t)(arg1[23]) << 31);
  811|  47.0k|  x10 = ((uint64_t)(arg1[22]) << 23);
  812|  47.0k|  x11 = ((uint64_t)(arg1[21]) << 15);
  813|  47.0k|  x12 = ((uint64_t)(arg1[20]) << 7);
  814|  47.0k|  x13 = ((uint64_t)(arg1[19]) << 50);
  815|  47.0k|  x14 = ((uint64_t)(arg1[18]) << 42);
  816|  47.0k|  x15 = ((uint64_t)(arg1[17]) << 34);
  817|  47.0k|  x16 = ((uint64_t)(arg1[16]) << 26);
  818|  47.0k|  x17 = ((uint64_t)(arg1[15]) << 18);
  819|  47.0k|  x18 = ((uint64_t)(arg1[14]) << 10);
  820|  47.0k|  x19 = ((uint64_t)(arg1[13]) << 2);
  821|  47.0k|  x20 = ((uint64_t)(arg1[12]) << 45);
  822|  47.0k|  x21 = ((uint64_t)(arg1[11]) << 37);
  823|  47.0k|  x22 = ((uint64_t)(arg1[10]) << 29);
  824|  47.0k|  x23 = ((uint64_t)(arg1[9]) << 21);
  825|  47.0k|  x24 = ((uint64_t)(arg1[8]) << 13);
  826|  47.0k|  x25 = ((uint64_t)(arg1[7]) << 5);
  827|  47.0k|  x26 = ((uint64_t)(arg1[6]) << 48);
  828|  47.0k|  x27 = ((uint64_t)(arg1[5]) << 40);
  829|  47.0k|  x28 = ((uint64_t)(arg1[4]) << 32);
  830|  47.0k|  x29 = ((uint64_t)(arg1[3]) << 24);
  831|  47.0k|  x30 = ((uint64_t)(arg1[2]) << 16);
  832|  47.0k|  x31 = ((uint64_t)(arg1[1]) << 8);
  833|  47.0k|  x32 = (arg1[0]);
  834|  47.0k|  x33 = (x31 + (uint64_t)x32);
  835|  47.0k|  x34 = (x30 + x33);
  836|  47.0k|  x35 = (x29 + x34);
  837|  47.0k|  x36 = (x28 + x35);
  838|  47.0k|  x37 = (x27 + x36);
  839|  47.0k|  x38 = (x26 + x37);
  840|  47.0k|  x39 = (x38 & UINT64_C(0x7ffffffffffff));
  841|  47.0k|  x40 = (uint8_t)(x38 >> 51);
  842|  47.0k|  x41 = (x25 + (uint64_t)x40);
  843|  47.0k|  x42 = (x24 + x41);
  844|  47.0k|  x43 = (x23 + x42);
  845|  47.0k|  x44 = (x22 + x43);
  846|  47.0k|  x45 = (x21 + x44);
  847|  47.0k|  x46 = (x20 + x45);
  848|  47.0k|  x47 = (x46 & UINT64_C(0x7ffffffffffff));
  849|  47.0k|  x48 = (uint8_t)(x46 >> 51);
  850|  47.0k|  x49 = (x19 + (uint64_t)x48);
  851|  47.0k|  x50 = (x18 + x49);
  852|  47.0k|  x51 = (x17 + x50);
  853|  47.0k|  x52 = (x16 + x51);
  854|  47.0k|  x53 = (x15 + x52);
  855|  47.0k|  x54 = (x14 + x53);
  856|  47.0k|  x55 = (x13 + x54);
  857|  47.0k|  x56 = (x55 & UINT64_C(0x7ffffffffffff));
  858|  47.0k|  x57 = (uint8_t)(x55 >> 51);
  859|  47.0k|  x58 = (x12 + (uint64_t)x57);
  860|  47.0k|  x59 = (x11 + x58);
  861|  47.0k|  x60 = (x10 + x59);
  862|  47.0k|  x61 = (x9 + x60);
  863|  47.0k|  x62 = (x8 + x61);
  864|  47.0k|  x63 = (x7 + x62);
  865|  47.0k|  x64 = (x63 & UINT64_C(0x7ffffffffffff));
  866|  47.0k|  x65 = (uint8_t)(x63 >> 51);
  867|  47.0k|  x66 = (x6 + (uint64_t)x65);
  868|  47.0k|  x67 = (x5 + x66);
  869|  47.0k|  x68 = (x4 + x67);
  870|  47.0k|  x69 = (x3 + x68);
  871|  47.0k|  x70 = (x2 + x69);
  872|  47.0k|  x71 = (x1 + x70);
  873|  47.0k|  out1[0] = x39;
  874|  47.0k|  out1[1] = x47;
  875|  47.0k|  out1[2] = x56;
  876|  47.0k|  out1[3] = x64;
  877|  47.0k|  out1[4] = x71;
  878|  47.0k|}

x25519_ge_scalarmult_base_adx:
  626|  11.7k|void x25519_ge_scalarmult_base_adx(uint8_t h[4][32], const uint8_t a[32]) {
  627|  11.7k|  signed char e[64];
  628|  11.7k|  signed char carry;
  629|       |
  630|   387k|  for (unsigned i = 0; i < 32; ++i) {
  ------------------
  |  Branch (630:24): [True: 376k, False: 11.7k]
  ------------------
  631|   376k|    e[2 * i + 0] = (a[i] >> 0) & 15;
  632|   376k|    e[2 * i + 1] = (a[i] >> 4) & 15;
  633|   376k|  }
  634|       |  // each e[i] is between 0 and 15
  635|       |  // e[63] is between 0 and 7
  636|       |
  637|  11.7k|  carry = 0;
  638|   752k|  for (unsigned i = 0; i < 63; ++i) {
  ------------------
  |  Branch (638:24): [True: 740k, False: 11.7k]
  ------------------
  639|   740k|    e[i] += carry;
  640|   740k|    carry = e[i] + 8;
  641|   740k|    carry >>= 4;
  642|   740k|    e[i] -= carry << 4;
  643|   740k|  }
  644|  11.7k|  e[63] += carry;
  645|       |  // each e[i] is between -8 and 8
  646|       |
  647|  11.7k|  ge_p3_4 r = {{0}, {1}, {1}, {0}};
  648|   387k|  for (unsigned i = 1; i < 64; i += 2) {
  ------------------
  |  Branch (648:24): [True: 376k, False: 11.7k]
  ------------------
  649|   376k|    ge_precomp_4 t;
  650|   376k|    table_select_4(&t, i / 2, e[i]);
  651|   376k|    ge_p3_add_p3_precomp_4(&r, &r, &t);
  652|   376k|  }
  653|       |
  654|  11.7k|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  655|  11.7k|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  656|  11.7k|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/true);
  657|  11.7k|  inline_x25519_ge_dbl_4(&r, &r, /*skip_t=*/false);
  658|       |
  659|   387k|  for (unsigned i = 0; i < 64; i += 2) {
  ------------------
  |  Branch (659:24): [True: 376k, False: 11.7k]
  ------------------
  660|   376k|    ge_precomp_4 t;
  661|   376k|    table_select_4(&t, i / 2, e[i]);
  662|   376k|    ge_p3_add_p3_precomp_4(&r, &r, &t);
  663|   376k|  }
  664|       |
  665|       |  // fe4 uses saturated 64-bit limbs, so converting to bytes is just a copy.
  666|       |  // Satisfy stated precondition of fiat_25519_from_bytes; tests pass either way
  667|  11.7k|  fe4_canon(r.X, r.X);
  668|  11.7k|  fe4_canon(r.Y, r.Y);
  669|  11.7k|  fe4_canon(r.Z, r.Z);
  670|  11.7k|  fe4_canon(r.T, r.T);
  671|  11.7k|  static_assert(sizeof(ge_p3_4) == sizeof(uint8_t[4][32]), "");
  672|  11.7k|  OPENSSL_memcpy(h, &r, sizeof(ge_p3_4));
  673|  11.7k|}
curve25519_64_adx.c:fiat_cmovznz_u64:
  137|  12.9M|static inline void fiat_cmovznz_u64(uint64_t* out1, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  138|  12.9M|  fiat_uint1 x1;
  139|  12.9M|  uint64_t x2;
  140|  12.9M|  uint64_t x3;
  141|  12.9M|  x1 = (!(!arg1));
  142|  12.9M|  x2 = ((fiat_int1)(0x0 - x1) & UINT64_C(0xffffffffffffffff));
  143|  12.9M|  x3 = ((fiat_value_barrier_u64(x2) & arg3) | (fiat_value_barrier_u64((~x2)) & arg2));
  144|  12.9M|  *out1 = x3;
  145|  12.9M|}
curve25519_64_adx.c:fiat_value_barrier_u64:
   10|  25.9M|static __inline__ uint64_t fiat_value_barrier_u64(uint64_t a) {
   11|  25.9M|  __asm__("" : "+r"(a) : /* no inputs */);
   12|  25.9M|  return a;
   13|  25.9M|}
curve25519_64_adx.c:fe4_sub:
  199|  3.14M|static void fe4_sub(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
  200|  3.14M|  uint64_t x1;
  201|  3.14M|  uint64_t x2;
  202|  3.14M|  fiat_uint1 x3;
  203|  3.14M|  uint64_t x4;
  204|  3.14M|  uint64_t x5;
  205|  3.14M|  fiat_uint1 x6;
  206|  3.14M|  uint64_t x7;
  207|  3.14M|  uint64_t x8;
  208|  3.14M|  fiat_uint1 x9;
  209|  3.14M|  uint64_t x10;
  210|  3.14M|  uint64_t x11;
  211|  3.14M|  fiat_uint1 x12;
  212|  3.14M|  uint64_t x13;
  213|  3.14M|  uint64_t x14;
  214|  3.14M|  fiat_uint1 x15;
  215|  3.14M|  uint64_t x16;
  216|  3.14M|  fiat_uint1 x17;
  217|  3.14M|  uint64_t x18;
  218|  3.14M|  fiat_uint1 x19;
  219|  3.14M|  uint64_t x20;
  220|  3.14M|  fiat_uint1 x21;
  221|  3.14M|  uint64_t x22;
  222|  3.14M|  uint64_t x23;
  223|  3.14M|  fiat_uint1 x24;
  224|  3.14M|  x1 = (arg2[0]);
  225|  3.14M|  fiat_subborrowx_u64(&x2, &x3, 0x0, (arg1[0]), x1);
  226|  3.14M|  x4 = (arg2[1]);
  227|  3.14M|  fiat_subborrowx_u64(&x5, &x6, x3, (arg1[1]), x4);
  228|  3.14M|  x7 = (arg2[2]);
  229|  3.14M|  fiat_subborrowx_u64(&x8, &x9, x6, (arg1[2]), x7);
  230|  3.14M|  x10 = (arg2[3]);
  231|  3.14M|  fiat_subborrowx_u64(&x11, &x12, x9, (arg1[3]), x10);
  232|  3.14M|  fiat_cmovznz_u64(&x13, x12, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  233|  3.14M|  fiat_subborrowx_u64(&x14, &x15, 0x0, x2, x13);
  234|  3.14M|  fiat_subborrowx_u64(&x16, &x17, x15, x5, 0x0);
  235|  3.14M|  fiat_subborrowx_u64(&x18, &x19, x17, x8, 0x0);
  236|  3.14M|  fiat_subborrowx_u64(&x20, &x21, x19, x11, 0x0);
  237|  3.14M|  fiat_cmovznz_u64(&x22, x21, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  238|  3.14M|  fiat_subborrowx_u64(&x23, &x24, 0x0, x14, x22);
  239|  3.14M|  out1[0] = x23;
  240|  3.14M|  out1[1] = x16;
  241|  3.14M|  out1[2] = x18;
  242|  3.14M|  out1[3] = x20;
  243|  3.14M|}
curve25519_64_adx.c:fiat_subborrowx_u64:
  103|  28.7M|static inline void fiat_subborrowx_u64(uint64_t* out1, fiat_uint1* out2, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
  104|  28.7M|#if defined(__has_builtin)
  105|  28.7M|#  if __has_builtin(__builtin_ia32_subborrow_u64)
  106|  28.7M|#    define subborrow64 __builtin_ia32_subborrow_u64
  107|  28.7M|#  endif
  108|  28.7M|#endif
  109|  28.7M|#if defined(subborrow64)
  110|  28.7M|  long long unsigned int t;
  111|  28.7M|  *out2 = subborrow64(arg1, arg2, arg3, &t);
  ------------------
  |  |  106|  28.7M|#    define subborrow64 __builtin_ia32_subborrow_u64
  ------------------
  112|  28.7M|  *out1 = t;
  113|       |#elif defined(_M_X64)
  114|       |  long long unsigned int t;
  115|       |  *out2 = _subborrow_u64(arg1, arg2, arg3, &t); // NOTE: edited after generation
  116|       |  *out1 = t;
  117|       |#else
  118|       |  *out1 = arg2 - arg3 - arg1;
  119|       |  *out2 = (arg2 < arg3) | ((arg2 == arg3) & arg1);
  120|       |#endif
  121|  28.7M|#undef subborrow64
  122|  28.7M|}
curve25519_64_adx.c:fe4_add:
  154|  3.14M|static void fe4_add(uint64_t out1[4], const uint64_t arg1[4], const uint64_t arg2[4]) {
  155|  3.14M|  uint64_t x1;
  156|  3.14M|  fiat_uint1 x2;
  157|  3.14M|  uint64_t x3;
  158|  3.14M|  fiat_uint1 x4;
  159|  3.14M|  uint64_t x5;
  160|  3.14M|  fiat_uint1 x6;
  161|  3.14M|  uint64_t x7;
  162|  3.14M|  fiat_uint1 x8;
  163|  3.14M|  uint64_t x9;
  164|  3.14M|  uint64_t x10;
  165|  3.14M|  fiat_uint1 x11;
  166|  3.14M|  uint64_t x12;
  167|  3.14M|  fiat_uint1 x13;
  168|  3.14M|  uint64_t x14;
  169|  3.14M|  fiat_uint1 x15;
  170|  3.14M|  uint64_t x16;
  171|  3.14M|  fiat_uint1 x17;
  172|  3.14M|  uint64_t x18;
  173|  3.14M|  uint64_t x19;
  174|  3.14M|  fiat_uint1 x20;
  175|  3.14M|  fiat_addcarryx_u64(&x1, &x2, 0x0, (arg1[0]), (arg2[0]));
  176|  3.14M|  fiat_addcarryx_u64(&x3, &x4, x2, (arg1[1]), (arg2[1]));
  177|  3.14M|  fiat_addcarryx_u64(&x5, &x6, x4, (arg1[2]), (arg2[2]));
  178|  3.14M|  fiat_addcarryx_u64(&x7, &x8, x6, (arg1[3]), (arg2[3]));
  179|  3.14M|  fiat_cmovznz_u64(&x9, x8, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  180|  3.14M|  fiat_addcarryx_u64(&x10, &x11, 0x0, x1, x9);
  181|  3.14M|  fiat_addcarryx_u64(&x12, &x13, x11, x3, 0x0);
  182|  3.14M|  fiat_addcarryx_u64(&x14, &x15, x13, x5, 0x0);
  183|  3.14M|  fiat_addcarryx_u64(&x16, &x17, x15, x7, 0x0);
  184|  3.14M|  fiat_cmovznz_u64(&x18, x17, 0x0, UINT8_C(0x26)); // NOTE: clang 14 for Zen 2 uses sbb, and
  185|  3.14M|  fiat_addcarryx_u64(&x19, &x20, 0x0, x10, x18);
  186|  3.14M|  out1[0] = x19;
  187|  3.14M|  out1[1] = x12;
  188|  3.14M|  out1[2] = x14;
  189|  3.14M|  out1[3] = x16;
  190|  3.14M|}
curve25519_64_adx.c:fiat_addcarryx_u64:
   62|  28.3M|static inline void fiat_addcarryx_u64(uint64_t* out1, fiat_uint1* out2, fiat_uint1 arg1, uint64_t arg2, uint64_t arg3) {
   63|       |// NOTE: edited after generation
   64|  28.3M|#if defined(__has_builtin)
   65|  28.3M|#  if __has_builtin(__builtin_ia32_addcarryx_u64)
   66|  28.3M|#    define addcarry64 __builtin_ia32_addcarryx_u64
   67|  28.3M|#  endif
   68|  28.3M|#endif
   69|  28.3M|#if defined(addcarry64)
   70|  28.3M|  long long unsigned int t;
   71|  28.3M|  *out2 = addcarry64(arg1, arg2, arg3, &t);
  ------------------
  |  |   66|  28.3M|#    define addcarry64 __builtin_ia32_addcarryx_u64
  ------------------
   72|  28.3M|  *out1 = t;
   73|       |#elif defined(_M_X64)
   74|       |  long long unsigned int t;
   75|       |  *out2 = _addcarry_u64(arg1, arg2, arg3, out1);
   76|       |  *out1 = t;
   77|       |#else
   78|       |  arg2 += arg1;
   79|       |  arg1 = arg2 < arg1;
   80|       |  uint64_t ret = arg2 + arg3;
   81|       |  arg1 += ret < arg2;
   82|       |  *out1 = ret;
   83|       |  *out2 = arg1;
   84|       |#endif
   85|  28.3M|#undef addcarry64
   86|  28.3M|}
curve25519_64_adx.c:fe4_mul:
   14|  5.41M|static inline void fe4_mul(fe4 out, const fe4 x, const fe4 y) { fiat_curve25519_adx_mul(out, x, y); }
curve25519_64_adx.c:fe4_sq:
   15|   188k|static inline void fe4_sq(fe4 out, const fe4 x) { fiat_curve25519_adx_square(out, x); }
curve25519_64_adx.c:fe4_canon:
  306|  47.0k|static void fe4_canon(uint64_t out1[4], const uint64_t arg1[4]) {
  307|  47.0k|  uint64_t x1;
  308|  47.0k|  fiat_uint1 x2;
  309|  47.0k|  uint64_t x3;
  310|  47.0k|  fiat_uint1 x4;
  311|  47.0k|  uint64_t x5;
  312|  47.0k|  fiat_uint1 x6;
  313|  47.0k|  uint64_t x7;
  314|  47.0k|  fiat_uint1 x8;
  315|  47.0k|  uint64_t x9;
  316|  47.0k|  uint64_t x10;
  317|  47.0k|  uint64_t x11;
  318|  47.0k|  uint64_t x12;
  319|  47.0k|  uint64_t x13;
  320|  47.0k|  fiat_uint1 x14;
  321|  47.0k|  uint64_t x15;
  322|  47.0k|  fiat_uint1 x16;
  323|  47.0k|  uint64_t x17;
  324|  47.0k|  fiat_uint1 x18;
  325|  47.0k|  uint64_t x19;
  326|  47.0k|  fiat_uint1 x20;
  327|  47.0k|  uint64_t x21;
  328|  47.0k|  uint64_t x22;
  329|  47.0k|  uint64_t x23;
  330|  47.0k|  uint64_t x24;
  331|  47.0k|  fiat_subborrowx_u64(&x1, &x2, 0x0, (arg1[0]), UINT64_C(0xffffffffffffffed));
  332|  47.0k|  fiat_subborrowx_u64(&x3, &x4, x2, (arg1[1]), UINT64_C(0xffffffffffffffff));
  333|  47.0k|  fiat_subborrowx_u64(&x5, &x6, x4, (arg1[2]), UINT64_C(0xffffffffffffffff));
  334|  47.0k|  fiat_subborrowx_u64(&x7, &x8, x6, (arg1[3]), UINT64_C(0x7fffffffffffffff));
  335|  47.0k|  fiat_cmovznz_u64(&x9, x8, x1, (arg1[0]));
  336|  47.0k|  fiat_cmovznz_u64(&x10, x8, x3, (arg1[1]));
  337|  47.0k|  fiat_cmovznz_u64(&x11, x8, x5, (arg1[2]));
  338|  47.0k|  fiat_cmovznz_u64(&x12, x8, x7, (arg1[3]));
  339|  47.0k|  fiat_subborrowx_u64(&x13, &x14, 0x0, x9, UINT64_C(0xffffffffffffffed));
  340|  47.0k|  fiat_subborrowx_u64(&x15, &x16, x14, x10, UINT64_C(0xffffffffffffffff));
  341|  47.0k|  fiat_subborrowx_u64(&x17, &x18, x16, x11, UINT64_C(0xffffffffffffffff));
  342|  47.0k|  fiat_subborrowx_u64(&x19, &x20, x18, x12, UINT64_C(0x7fffffffffffffff));
  343|  47.0k|  fiat_cmovznz_u64(&x21, x20, x13, x9);
  344|  47.0k|  fiat_cmovznz_u64(&x22, x20, x15, x10);
  345|  47.0k|  fiat_cmovznz_u64(&x23, x20, x17, x11);
  346|  47.0k|  fiat_cmovznz_u64(&x24, x20, x19, x12);
  347|  47.0k|  out1[0] = x21;
  348|  47.0k|  out1[1] = x22;
  349|  47.0k|  out1[2] = x23;
  350|  47.0k|  out1[3] = x24;
  351|  47.0k|}
curve25519_64_adx.c:table_select_4:
  590|   752k|                                  const signed char b) {
  591|   752k|  uint8_t bnegative = constant_time_msb_w(b);
  592|   752k|  uint8_t babs = b - ((bnegative & b) << 1);
  593|       |
  594|   752k|  uint8_t t_bytes[3][32] = {
  595|   752k|      {constant_time_is_zero_w(b) & 1}, {constant_time_is_zero_w(b) & 1}, {0}};
  596|   752k|#if defined(__clang__)
  597|   752k|  __asm__("" : "+m" (t_bytes) : /*no inputs*/);
  598|   752k|#endif
  599|   752k|  static_assert(sizeof(t_bytes) == sizeof(k25519Precomp[pos][0]), "");
  600|  6.76M|  for (int i = 0; i < 8; i++) {
  ------------------
  |  Branch (600:19): [True: 6.01M, False: 752k]
  ------------------
  601|  6.01M|    constant_time_conditional_memxor(t_bytes, k25519Precomp[pos][i],
  602|  6.01M|                                     sizeof(t_bytes),
  603|  6.01M|                                     constant_time_eq_w(babs, 1 + i));
  604|  6.01M|  }
  605|       |
  606|   752k|  static_assert(sizeof(t_bytes) == sizeof(ge_precomp_4), "");
  607|       |
  608|       |  // fe4 uses saturated 64-bit limbs, so converting from bytes is just a copy.
  609|   752k|  OPENSSL_memcpy(t, t_bytes, sizeof(ge_precomp_4));
  610|       |
  611|   752k|  fe4 xy2d_neg = {0};
  612|   752k|  fe4_sub(xy2d_neg, xy2d_neg, t->xy2d);
  613|   752k|  constant_time_conditional_memcpy(t->yplusx, t_bytes[1], sizeof(fe4),
  614|   752k|                                   bnegative);
  615|   752k|  constant_time_conditional_memcpy(t->yminusx, t_bytes[0], sizeof(fe4),
  616|   752k|                                   bnegative);
  617|   752k|  constant_time_conditional_memcpy(t->xy2d, xy2d_neg, sizeof(fe4), bnegative);
  618|   752k|}
curve25519_64_adx.c:ge_p3_add_p3_precomp_4:
  568|   752k|ge_p3_add_p3_precomp_4(ge_p3_4 *r, const ge_p3_4 *p, const ge_precomp_4 *q) {
  569|   752k|  fe4 A, B, C, YplusX, YminusX, D, X3, Y3, Z3, T3;
  570|       |  // Transcribed from a Coq function proven against affine coordinates.
  571|       |  // https://github.com/mit-plv/fiat-crypto/blob/a36568d1d73aff5d7accc79fd28be672882f9c17/src/Curves/Edwards/XYZT/Precomputed.v#L38-L56
  572|   752k|  fe4_add(YplusX, p->Y, p->X);
  573|   752k|  fe4_sub(YminusX, p->Y, p->X);
  574|   752k|  fe4_mul(A, YplusX, q->yplusx);
  575|   752k|  fe4_mul(B, YminusX, q->yminusx);
  576|   752k|  fe4_mul(C, q->xy2d, p->T);
  577|   752k|  fe4_add(D, p->Z, p->Z);
  578|   752k|  fe4_sub(X3, A, B);
  579|   752k|  fe4_add(Y3, A, B);
  580|   752k|  fe4_add(Z3, D, C);
  581|   752k|  fe4_sub(T3, D, C);
  582|   752k|  fe4_mul(r->X, X3, T3);
  583|   752k|  fe4_mul(r->Y, Y3, Z3);
  584|   752k|  fe4_mul(r->Z, Z3, T3);
  585|   752k|  fe4_mul(r->T, X3, Y3);
  586|   752k|}
curve25519_64_adx.c:inline_x25519_ge_dbl_4:
  544|  47.0k|static void inline_x25519_ge_dbl_4(ge_p3_4 *r, const ge_p3_4 *p, bool skip_t) {
  545|       |  // Transcribed from a Coq function proven against affine coordinates.
  546|       |  // https://github.com/mit-plv/fiat-crypto/blob/9943ba9e7d8f3e1c0054b2c94a5edca46ea73ef8/src/Curves/Edwards/XYZT/Basic.v#L136-L165
  547|  47.0k|  fe4 trX, trZ, trT, t0, cX, cY, cZ, cT;
  548|  47.0k|  fe4_sq(trX, p->X);
  549|  47.0k|  fe4_sq(trZ, p->Y);
  550|  47.0k|  fe4_sq(trT, p->Z);
  551|  47.0k|  fe4_add(trT, trT, trT);
  552|  47.0k|  fe4_add(cY, p->X, p->Y);
  553|  47.0k|  fe4_sq(t0, cY);
  554|  47.0k|  fe4_add(cY, trZ, trX);
  555|  47.0k|  fe4_sub(cZ, trZ, trX);
  556|  47.0k|  fe4_sub(cX, t0, cY);
  557|  47.0k|  fe4_sub(cT, trT, cZ);
  558|  47.0k|  fe4_mul(r->X, cX, cT);
  559|  47.0k|  fe4_mul(r->Y, cY, cZ);
  560|  47.0k|  fe4_mul(r->Z, cZ, cT);
  561|  47.0k|  if (!skip_t) {
  ------------------
  |  Branch (561:7): [True: 11.7k, False: 35.2k]
  ------------------
  562|  11.7k|    fe4_mul(r->T, cX, cY);
  563|  11.7k|  }
  564|  47.0k|}

